In-vehicle device, service provision method, and service provision program

By using the onboard unit's collaborative control section and stop judgment section to switch the vehicle control system's actions based on vehicle status and user input information, the problem of user inconvenience caused by toll-related factors is solved, and the convenience of service use is improved.

CN121399010APending Publication Date: 2026-01-23DENSO CORP
View PDF 2 Cites 0 Cited by

Patent Information

Application Number
CN202480039405.8
Authority / Receiving Office
CN · China
Patent Type
Applications(China)
Current Assignee / Owner
Priority Date
2023-06-14
Filing Date
2024-06-07
Publication Date
2026-01-23

AI Technical Summary

Technical Problem

If a service provider needs to discontinue service due to factors related to charges, it may impair user convenience.

Method used

The collaboration control unit of the on-board unit enables collaboration between the service application and the functional blocks of the vehicle control system. The stop judgment unit determines the pre-set stop conditions and switches the actions of the vehicle control system based on the vehicle status and user input information to avoid stopping the service indiscriminately.

Benefits of technology

This improves the convenience for users to use services under the influence of pricing factors and avoids the inconvenience caused by a blanket cessation of services.

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure CN121399010A_ABST
    Figure CN121399010A_ABST
Patent Text Reader

Abstract

The invention relates to an in-vehicle device, a service providing method, and a service providing program. The in-vehicle device (4) constitutes a vehicle control system (2) together with a plurality of electronic control devices (5-7). The in-vehicle device is provided with a cooperation control unit (40). The cooperation control unit is provided with a use stop determination unit (S30) and a use control unit (S40-S70, S100-S120). A use stop determination unit determines whether or not a use stop condition is satisfied, the use stop condition indicating that use of the functional interface needs to be stopped due to a factor related to charge generated by using the service application (SA1) and / or the functional interface (37). The use control unit switches the operation of the vehicle control system on the basis of the function interface information relating to the function interface for which the use stop condition is established, the vehicle state information, and the user input information.
Need to check novelty before this filing date? Find Prior Art

Description

[0001] Cross-reference to related applications

[0002] This international application claims priority to Japanese Patent Application No. 2023-097691, filed on June 14, 2023, with the Japanese Patent Office, the entire contents of which are incorporated herein by reference. Technical Field

[0003] This disclosure relates to onboard devices for providing services to vehicles, methods for providing services, and procedures for providing services. Background Technology

[0004] Patent Document 1 describes a vehicle comprising a control unit that operates the vehicle based on operating information received from a management server, a management unit that manages the vehicle's cabin where users receive services from a service provider, and an interface unit that establishes a correspondence between the service information provided by the service provider and the cabin.

[0005] Patent Document 1: Japanese Patent Application Publication No. 2020-98610

[0006] As described in Patent Document 1, when a service provider provides services to a vehicle, there may be situations where it is necessary to obtain vehicle-related information from the vehicle that is the object of the service, or to cause the vehicle to perform a prescribed action or process.

[0007] Thus, when a service provider uses a vehicle by obtaining vehicle information or by causing the vehicle to perform specified actions or processes, it is expected that the service provider will be charged for such use.

[0008] The inventors' detailed research revealed the following issue: if the use of the service provider is to be stopped due to factors related to charges (e.g., usage fees exceeding the limit), a blanket cessation of such use could potentially impair the convenience of users utilizing the services provided by the service provider. Summary of the Invention

[0009] This disclosure improves the convenience for users utilizing the service.

[0010] One aspect of this disclosure is that it is mounted in a vehicle, connected to multiple electronic control devices via an in-vehicle network, and together with the multiple electronic control devices constitutes an in-vehicle device for a vehicle control system.

[0011] The in-vehicle device of the present disclosure has a cooperative control section configured to realize cooperation between a service application configured to provide a service to a vehicle and a control system function block configured to control the vehicle. The control system function block has a function interface configured to convert an access request transmitted from the service application in a form independent of the vehicle into a form dependent on the vehicle. The cooperative control section is configured to relay the access request transmitted from the service application to the control system function block.

[0012] The cooperative control section has a use stop judgment section and a use control section.

[0013] The use stop judgment section is configured to judge whether a use stop condition, which indicates that use of the function interface needs to be stopped due to a factor related to a charge generated by use of at least one of the service application and the function interface, is satisfied.

[0014] The use control section is configured to switch an operation of the vehicle control system based on function interface information related to the function interface for which the use stop condition is satisfied, vehicle state information indicating a state of the vehicle, and user input information input by a user using the vehicle.

[0015] The in-vehicle device of the present disclosure configured as described above switches the operation of the vehicle control system based on the function interface information, the vehicle state information, and the user input information. Thus, the in-vehicle device of the present disclosure can suppress generation of a situation in which the user cannot use the service because use of the function interface is stopped in all cases where use of the function interface needs to be stopped due to the factor related to the charge, and thus can improve convenience of the user using the service.

[0016] Another aspect of the present disclosure is a service providing method executed by an in-vehicle device mounted on a vehicle, connected to a plurality of electronic control devices via an in-vehicle network, and configured to constitute a vehicle control system together with the plurality of electronic control devices.

[0017] The in-vehicle device has a cooperative control section configured to realize cooperation between a service application and a control system function block. The control system function block has a function interface. The cooperative control section is configured to relay an access request transmitted from the service application to the control system function block.

[0018] In the service providing method of the present disclosure, the cooperative control section judges whether a use stop condition, which indicates that use of the function interface needs to be stopped due to a factor related to a charge generated by use of at least one of the service application and the function interface, is satisfied. In addition, the cooperative control section switches an operation of the vehicle control system based on function interface information related to the function interface for which the use stop condition is satisfied, vehicle state information indicating a state of the vehicle, and user input information input by a user using the vehicle.

[0019] The service provision method disclosed herein is executed by the vehicle-mounted device of this disclosure, and by executing this method, the same effect as the vehicle-mounted device of this disclosure can be obtained.

[0020] Another aspect of this disclosure is a computer of an onboard device mounted in a vehicle, connected to multiple electronic control devices via an onboard network, and constituting a vehicle control system together with the multiple electronic control devices, serving as a functional interface, a cooperative control unit, a stop determination unit, and a service provider that functions using the control unit.

[0021] A computer controlled by the service provider of this disclosure can form part of the vehicle-mounted device of this disclosure and can achieve the same effect as the vehicle-mounted device of this disclosure. Attached Figure Description

[0022] Figure 1 It is a block diagram representing the structure of a service delivery system.

[0023] Figure 2 This is a block diagram showing the structure of an ECU.

[0024] Figure 3 This is a diagram showing the order in which charges are processed.

[0025] Figure 4 This is a diagram showing the order in which API contracts were signed.

[0026] Figure 5 This is a block diagram representing the destination sent by the first API using a stop request.

[0027] Figure 6 This is a block diagram representing the destination sent by the second API using a stop request.

[0028] Figure 7 This is a flowchart representing the first half of the API's control processing.

[0029] Figure 8 This is a flowchart representing the latter part of the API's control processing. Detailed Implementation

[0030] The following and appendix Figure 1 The embodiments of this disclosure will now be described.

[0031] like Figure 1 As shown, the service providing system 1 of this embodiment includes a vehicle control system 2 and a server 3.

[0032] The vehicle control system 2 is mounted on the vehicle and has the function of communicating with the server 3 via the wide area wireless communication network NW.

[0033] The server 3 has a function of performing data communication with the vehicle control system 2 via a wide area wireless communication network NW. In the server 3, an application store accessible via the wide area wireless communication network NW or the Internet is provided.

[0034] The vehicle on which the vehicle control system 2 is mounted can have an automatic driving function in addition to a manual driving function. The vehicle can also be a hybrid vehicle having an engine and an electric motor as a travel drive source. The vehicle is not limited to a vehicle having an automatic driving function and a hybrid vehicle, and can be a vehicle having only a manual driving function, or a vehicle having only an engine or only an electric motor as a travel drive source. Hereinafter, the vehicle on which the vehicle control system 2 is mounted will be simply referred to as a vehicle.

[0035] The vehicle control system 2 is provided with one ECU 4, a plurality of ECUs 5, a plurality of ECUs 6, a vehicle exterior communication device 7, and a vehicle interior communication network 8. The ECU is an abbreviation for Electronic Control Unit.

[0036] The ECU 4 achieves control in which cooperation is obtained as a whole of the vehicle by overall coordination of the plurality of ECUs 5.

[0037] The ECUs 5 are provided per domain divided according to functions in the vehicle, and mainly execute control of the plurality of ECUs 6 existing in the domain. Each ECU 5 is connected to the subordinate ECUs 6 via a lower layer network (for example, CAN) independently provided respectively. CAN is an abbreviation for Controller Area Network. CAN is a registered trademark. The domain is, for example, a powertrain, a vehicle body, a chassis, and a cockpit, and the like.

[0038] The ECUs 6 connected to the ECU 5 belonging to the domain of the powertrain include, for example, an ECU 6 that controls an engine, an ECU 6 that controls a motor, an ECU 6 that controls a battery, and the like.

[0039] The ECUs 6 connected to the ECU 5 belonging to the domain of the vehicle body include, for example, an ECU 6 that controls an air conditioner, an ECU 6 that controls a door, and the like.

[0040] The ECUs 6 connected to the ECU 5 belonging to the domain of the chassis include, for example, an ECU 6 that controls a brake, an ECU 6 that controls a steering wheel, and the like.

[0041] The ECUs 6 connected to the ECU 5 belonging to the domain of the cockpit include, for example, an ECU 6 that controls an instrument and a display of a navigation device 100, an ECU 6 that controls an input device operated by an occupant of the vehicle, and the like.

[0042] The vehicle exterior communication device 7 performs data communication with the server 3 via the wide area wireless communication network NW.

[0043] The in-vehicle communication network 8 has a CAN FD and an Ethernet. The Ethernet is a registered trademark. The CAN FD is an abbreviation of CAN with Flexible Data Rate: a CAN of variable rate. The CAN FD is connected to the ECU 4, the ECUs 5, and the external communication device 7 by a bus. The Ethernet is connected to the ECU 4, the ECUs 5, and the external communication device 7 independently.

[0044] The ECU 4 is an electronic control device constituted mainly of a microcomputer having a CPU 4a, a ROM 4b, a RAM 4c, and the like. Various functions of the microcomputer are realized by the CPU 4a executing a program stored in a non-transitory recording medium. In this example, the ROM 4b corresponds to the non-transitory recording medium in which the program is stored. In addition, by the execution of the program, a method corresponding to the program is executed. Furthermore, a part or all of the functions executed by the CPU 4a can also be constituted in hardware by one or a plurality of ICs or the like. In addition, the number of microcomputers constituting the ECU 4 can be one or a plurality.

[0045] The ECU 4 also has a flash ROM 4d. The flash ROM 4d is a non-volatile memory capable of rewriting the stored contents.

[0046] The ECUs 5, 6, and the external communication device 7 are the same as the ECU 4, and are electronic control devices constituted mainly of a microcomputer having a CPU, a ROM, a RAM, and the like. In addition, the number of microcomputers constituting the ECUs 5, 6, and the external communication device 7 can be one or a plurality. The ECU 5 coordinates one or more ECUs 6. The ECU 4 coordinates one or more ECUs 5, or coordinates the ECUs 5, 6, and the external communication device 7 as a whole of the vehicle.

[0047] Hereinafter, without particularly distinguishing the ECU 4, the ECUs 5, 6, and the external communication device 7, they are described as the in-vehicle devices 4 to 7.

[0048] The server 3 has a control section 11, a communication section 12, and a storage section 13.

[0049] The control unit 11 is an electronic control device centered around a microcomputer including a CPU 11a, ROM 11b, and RAM 11c. Various functions of the microcomputer are implemented by the CPU 11a executing programs stored on a non-transitional physical recording medium. In this example, the ROM 11b is equivalent to the non-transitional physical recording medium storing the program. Furthermore, by executing this program, methods corresponding to the program are executed. In addition, some or all of the functions executed by the CPU 11a can be configured in hardware using one or more ICs. Furthermore, the number of microcomputers constituting the control unit 11 can be one or more.

[0050] The communication unit 12 communicates with the vehicle control system 2 via a wide-area wireless communication network NW. The storage unit 13 is a storage device for storing various types of data.

[0051] The service providing system 1 also includes a service provider terminal device 9. The service provider terminal device 9 is a device managed by the service provider SV (hereinafter referred to as the service provider SV), and is, for example, a personal computer.

[0052] The service provider terminal device 9 includes a control unit 15, a communication unit 16, a storage unit 17, a display unit 18, and an operation input unit 19.

[0053] The control unit 15 is an electronic control device centered on a microcomputer equipped with a CPU, ROM, and RAM.

[0054] The communication unit 16 communicates with the vehicle control system 2 and the server 3 via a wide-area wireless communication network NW. The storage unit 17 is a storage device for storing various types of data. The display unit 18 includes a display device (not shown) that displays various images on its screen. The operation input unit 19 outputs input operation information to determine the input operations performed by the user via a keyboard and mouse (not shown).

[0055] The service provision system 1 also includes a mobile terminal device 10. The mobile terminal device 10 is an information processing terminal (e.g., a smartphone or tablet) carried by the driver of the vehicle (i.e., the user US described below). The mobile terminal device 10 has the function of communicating data with the vehicle control system 2 via a wide area wireless communication network NW.

[0056] like Figure 2 As shown, the ECU4 includes a real-time processing unit 20 and an application processing unit 30 (hereinafter referred to as the application processing unit 30). When the ECU4 has multiple CPUs 4a, the real-time processing unit 20 and the application processing unit 30 can be implemented by processing executed by the same CPU, or they can be implemented by processing executed by different CPUs.

[0057] The real-time processing unit 20 collaborates with the vehicle-mounted devices 5-7 connected via CAN FD to perform vehicle control and other tasks requiring real-time performance. The application processing unit 30 collaborates with the vehicle-mounted devices 5-7 connected via Ethernet to perform various applications (e.g., entertainment applications) requiring high processing power.

[0058] The application processing unit 30 has the function of transmitting instructions such as those based on various application programs to the real-time processing unit 20. The real-time processing unit 20 has the function of transmitting information such as that collected from the ECU, etc., via CAN FD to the application processing unit 30. Thus, the real-time processing unit 20 and the application processing unit 30 cooperate to achieve various functions.

[0059] The software of Vehicle Control System 2 is built according to AUTOSAR. AUTOSAR is an architecture for autonomous driving, short for Automotive Open System Architecture. AUTOSAR is a registered trademark. AUTOSAR provides communication between software components (hereinafter referred to as SW-C) installed to implement various applications, as well as cloud connectivity and security-related functions. SW-C is componentized software to implement a specific function. An application contains more than one SW-C. Furthermore, the software of Vehicle Control System 2 does not necessarily need to be built according to AUTOSAR.

[0060] Each device belonging to the vehicle control system 2, namely ECU4, ECU5, ECU6, and the external communication device 7, has a platform. The platform provides an environment for executing SW-C, which is described in a hardware-independent form.

[0061] The platform has a runtime environment (hereinafter referred to as RTE) and basic software (hereinafter referred to as BSW). RTE is the interface connecting SW-C and each other, as well as between SW-C and BSW. BSW is the layer connecting the hardware and SW-C, including the OS, drivers, middleware, etc. The functionality of BSW is divided into small modules, and the functionality of each module is provided to SW-C through API. API is an abbreviation for Application Programming Interface.

[0062] Hereinafter, the platform provided by the real-time processing unit 20 will be referred to as the first platform 21 (hereinafter referred to as the first PF21), and the platform provided by the application processing unit 30 will be referred to as the second platform 31 (hereinafter referred to as the second PF31).

[0063] The real-time processing unit 20 includes a system control function block group 22, which is a collection of service applications (hereinafter referred to as service applications) that operate on the first PF 21. A service application is an application that accepts requests from clients, processes them, and returns results.

[0064] The control system function block group 22 has an API that accepts commands related to vehicle motion. It is an application group used to coordinate the commands received by the API to achieve matching vehicle control. The control system function block group 22 outputs various commands to the on-board devices 5-7, which are located in the entities that execute the control based on the commands, via the in-vehicle communication network 8.

[0065] The first PF21 includes a conversion gateway 211. The conversion gateway 211 has the function of converting communication frames received by the real-time processing unit 20 via CAN FD into Ethernet form and providing them to the application processing unit 30. In addition, the conversion gateway 211 has the function of converting communication frames in Ethernet form provided by the application processing unit 30 into CAN FD form.

[0066] The application processing unit 30 includes a hypervisor 32 that executes software on multiple virtual machines. Alternatively, the hypervisor 32 may be omitted.

[0067] The application processing unit 30 has a service system function block group 33, which is a collection of service applications that operate on the second PF31.

[0068] Service system functional block group 33 is a collection of service applications. Each service application has more than one SW-C. Service applications are provided not only by vehicle manufacturers that produce vehicles, but also by third parties. Third parties providing service applications can be, for example, data providers that offer services by collecting data from vehicles.

[0069] The second PF31 includes a control system function block group 35, a data system function block group 36, and an API gateway 40.

[0070] The control system function block group 35 is a collection of programs that receive APIs related to vehicle control from the service system function block group 33. The control system function block group 35 includes an API group 37 consisting of multiple APIs, which converts API access requests from the service system function block group 33, which are expressed in a vehicle-independent form, into API access requests expressed in a vehicle-dependent form, and provides them to the real-time processing unit 20. The term "vehicle-independent form" refers to a form common to all vehicles (i.e., incorporating different forms for different vehicle types). The term "vehicle-dependent form" refers to a form inherent to the vehicle.

[0071] The control system function block group 35 includes motion system APIs for controlling vehicle movement and other non-motion system APIs. API access requests received by the motion system APIs are forwarded to the control system function block group 35, and then forwarded from the control system function block group 35 to the on-board devices 5-7 that perform request-based control via the in-vehicle communication network 8. API access requests received by the non-motion system APIs are forwarded to the on-board devices 5-7 that perform request-based control via the in-vehicle communication network 8.

[0072] The data system function block group 36 is a collection of programs equipped with an API for processing and accumulating vehicle data acquired and stored by the real-time processing unit 20. The data system function block group 36 has the function of abstracting vehicle data, which is presented in a vehicle-dependent form and supplied from the real-time processing unit 20, into a vehicle-independent form and accumulating it. The data system function block group 36 may also have an API that provides the function of sending specified vehicle data to an ECU, etc., via Ethernet. In particular, when the destination is an external communication device 7, the external communication device 7 can also upload the received vehicle data to the cloud.

[0073] Furthermore, communication with other vehicle-mounted devices 5-7 via the control system function block group 35 is not limited to CAN FD; Ethernet or other communication methods can also be used. Additionally, communication with other vehicle-mounted devices 5-7 via the data system function block group 36 is not limited to Ethernet; CAN FD or other communication methods can also be used.

[0074] API gateway 40 is constructed using the functionality of the Virtual Function Bus (hereinafter referred to as VFB). VFB is middleware that enables communication between SW-Cs and between SW-Cs and BSWs without considering hardware or communication protocols; it is also called a software bus. Communication between SW-Cs refers to accessing APIs provided by SW-Cs to other SW-Cs, while communication between SW-Cs and BSWs refers to accessing APIs provided by SW-Cs to the control system function block group 35 and the data system function block group 36.

[0075] In other words, SW-C accesses various APIs via API Gateway 40 and utilizes the functionality provided by the accessed APIs to achieve the desired functionality.

[0076] When using an API, SW-C sends an API access request. The API access request includes at least the application ID of the SW-C service application that is the source of the request, and information indicating the API that is the destination of the request, namely the API-ID.

[0077] like Figure 3As shown, an application store 14 is set up on server 3. As indicated by arrow L1, application store 14 has the function of registering a first service application SA1 created by service provider SV with application store 14 based on an application submitted by service provider SV using service provider terminal device 9 to access application store 14. The first service application SA1 registered with application store 14 is published on the website of application store 14.

[0078] Additionally, as shown by arrow L2, the app store 14 has the function of registering the API used by the first service application SA1 with the app store 14 based on the application of the service provider SV.

[0079] If user US purchases the first service application SA1 from the website of app store 14, then as shown by arrow L3, the first service application SA1 will be installed in the ECU4 of user US's vehicle.

[0080] As indicated by arrow L4, if the first service application SA1 sends an API access request to the API gateway 40, the API gateway 40, as indicated by arrow L5, forwards the API access request to the control system function block group 35. The control system function block group 35, as described above, converts the API access request into a vehicle-dependent API access request and provides it to the real-time processing unit 20.

[0081] As shown by arrow L6, API Gateway 40 sends statistical access logs to App Store 14, which include the number of API usages and the amount of communication data accompanying the API usages, taking into account the completion status of API access requests.

[0082] Based on the statistical access logs received from API Gateway 40, App Store 14 calculates the API usage fee incurred due to the first service application SA1 utilizing the API, and requests the API usage fee from Service Provider SV. As shown by arrow L7, Service Provider SV pays the requested API usage fee to App Store 14.

[0083] App Store 14 calculates the usage fee for the first service application SA1 based on its usage and requests the usage fee from user US. User US, as shown by arrow L8, pays the requested usage fee to App Store 14. App Store 14, as shown by arrow L9, transfers the usage fee paid by user US to service provider SV.

[0084] In addition, as shown by arrow L10, there is also a situation where if the first service application SA1 sends an API access request to the API gateway 40, the API gateway 40 will forward the API access request to the second service application SA2, which provides a different service than the first service application SA1.

[0085] Next, we will explain the order in which service providers (SVs) sign API utilization contracts.

[0086] like Figure 4 As shown in P1, the service provider SV accesses the application store 14 to apply for the registration of the service application to be published and the registration of the API to be used.

[0087] As shown in P2, the application store 14 reviews whether the service application requested by the service provider SV can access the control system function block group 35.

[0088] If the applied service application has access to the control system function block group 35, the application store 14 prompts the service provider SV to use the API charging method as shown in P3.

[0089] As shown in Table TB1, the application store 14 stores API policy information, including API ID, reliability, and charging method, for each applied API in the storage department 13.

[0090] In Table TB1, the API with API-ID API1 has a reliability rating of "High" and is charged on a per-call basis. The API with API-ID API2 has a reliability rating of "Low" and is charged on a per-month basis.

[0091] APIs with a reliability setting of "high" accept API access requests from service applications with high reliability and reject API access requests from service applications with low reliability.

[0092] APIs with a reliability setting of "low" will accept API access requests even for services with low reliability.

[0093] "Pay-per-call" is a billing method where the cost accumulates based on the number of API access requests. "Monthly fixed fee" is a billing method where a fixed fee is charged each month, regardless of the number of API access requests.

[0094] As shown in process P4, the service provider SV notifies the app store 14 of its agreement to the terms of the contract for using the API-based charging method as prompted. Consequently, as shown in process P5, the app store 14 publishes the service application requested by the service provider SV on its website.

[0095] The app store 14 stores information about the service applications published to the website (hereinafter referred to as application publishing information) and information about the APIs approved for the service applications published to the website (hereinafter referred to as API approval information) in the storage unit 13.

[0096] The application information is shown in Table TB2. Each published service application includes an application ID, the service application's function name, the service application's pricing method, and the service provider ID. The application ID is used to identify the service application. The service provider ID is used to identify the provider of the service application.

[0097] In table TB2, the service application with application ID APP1 has the function name "Comfort Air Conditioning", the charging method is "Usage Time", and the service provider ID is "Dev1". The service application with application ID APP2 has the function name "Road Service", the charging method is "Monthly Fixed Amount", and the service provider ID is "Dev1".

[0098] The "usage time" pricing method is a method where fees are accumulated based on the usage time of the service application. The "monthly fixed fee" pricing method is a method where a fixed fee is charged each month, regardless of the usage time of the service application.

[0099] API approval information is shown in Table TB3, which includes an API-ID and an application ID for each approved API.

[0100] Table TB3 shows that the API with API-ID API1 is called by the service application with application ID APP1, and the API with API-ID API2 is called by the service application with application ID APP2.

[0101] Next, we will explain how to stop using the API due to factors related to fees.

[0102] like Figure 5 As shown, API gateway 40 determines whether the contract period for API utilization has expired. Furthermore, if the contract period for API utilization has expired, as indicated by arrows L11, L12, and L13, API gateway 40 sends a first API utilization stop request to control system function block group 35, first service application SA1, and second service application SA2, indicating the intention to stop utilizing the API whose contract period has expired. The first API utilization stop request includes an API-ID identifying the API for which the cessation of utilization is requested.

[0103] like Figure 6As shown, app store 14 determines whether user US is in arrears on the usage fee of the first service application SA1, and whether service provider SV is in arrears on the API usage fee. Furthermore, if it is determined that user US is in arrears on the usage fee of the first service application SA1, or if it is determined that service provider SV is in arrears on the API usage fee, app store 14, as indicated by arrow L21, sends a second API usage termination request to the first service application SA1, stating that API usage is being terminated due to arrears. The second API usage termination request includes an API-ID identifying the API for which usage termination is requested.

[0104] If the first service application SA1 receives the second API utilization stop request, it will send the second API utilization stop request to the API gateway 40 as shown by arrow L22.

[0105] If API gateway 40 receives a second API utilization stop request, it sends the second API utilization stop request to control system function block group 35 and second service application SA2 as shown by arrows L23 and L24.

[0106] In addition, API gateway 40 determines whether the user US's usage fee for the first service application SA1 exceeds the charging limit set by the user US. Furthermore, API gateway 40 determines whether the first service application SA1's usage fee for the API exceeds the charging limit set by the service provider SV.

[0107] Furthermore, if it is determined that the usage fee of the first service application SA1 exceeds the charging limit, or if it is determined that the API usage fee exceeds the charging limit, the API gateway 40 sends a third API usage stop request to the control system functional block group 35, the first service application SA1, and the second service application SA2, indicating that the API usage is being stopped due to exceeding the charging limit. The third API usage stop request includes the API-ID identifying the API for which usage is being stopped.

[0108] Furthermore, API gateway 40 determines whether there are insufficient resources for performing the processing corresponding to the API. If it is determined that there are insufficient resources for performing the processing corresponding to the API, API gateway 40 sends a fourth API utilization stop request to control system function block group 35, first service application SA1, and second service application SA2, indicating that the utilization of the API due to insufficient resources should be stopped. The fourth API utilization stop request includes an API-ID identifying the API that is the object for which utilization stop is requested.

[0109] Next, the sequence of API utilization control processes executed by API Gateway 40 will be explained. API utilization control processes are processes that are repeatedly executed during the actions of ECU4.

[0110] If the API is executed using control processing, then as follows: Figure 7 As shown, in S10, API Gateway 40 (hereinafter referred to as APIGW40) determines whether there is API utilization and stops prediction.

[0111] Specifically, APIGW40 determines that there is an API usage stoppage prediction when it receives API usage stoppage prediction information from the app store 14. The API usage stoppage prediction information includes a list of service applications that cannot be used due to API usage stoppage, the reason for API usage stoppage, the time of API usage stoppage (e.g., "API will stop in X minutes"), precautions based on API usage stoppage, and the possibility of additional charges.

[0112] In addition, APIGW40 determines that API usage termination is predicted when the API usage contract expires, the service application usage fee exceeds the charging limit, the API usage fee exceeds the charging limit, or the resources for performing the processing corresponding to the API are insufficient. After a preset standby time has elapsed since the determination of API usage termination prediction, APIGW40 sends the aforementioned first, third, and fourth API usage termination requests.

[0113] Here, in the absence of an API usage stoppage prediction, APIGW40 repeats the process in S10, thus remaining in standby until an API usage stoppage prediction is made. Furthermore, if an API usage stoppage prediction is made, APIGW40 notifies the user (US) and service provider (SV) in S20 of the application service termination. In addition to terminating the application service, APIGW40 also notifies the user (US) and service provider (SV) of a list of applications that cannot be used due to API usage stoppage, the reason for the API usage stoppage, the time of the API usage stoppage, points to note regarding the API usage stoppage, and any additional charges incurred.

[0114] Specifically, when passengers are present in the vehicle, the APIGW40 notifies the user (US) to suspend the application service, for example, by displaying a message on the navigation device 100. Furthermore, the APIGW40 determines the presence of passengers in the vehicle by detecting whether passengers are seated on each of the multiple seats located on the seats within the passenger compartment, based on the detection results of multiple seating sensors installed on the seats themselves.

[0115] APIGW40 notifies user US's mobile terminal device 10 to cease service when there are no passengers in the vehicle. Furthermore, the user US's mobile terminal device 10's phone number or email address is pre-registered in ECU4.

[0116] APIGW40 notifies the service provider terminal device 9 of the service provider SV to stop the service application.

[0117] In step S30, APIGW40 determines whether it is a time to stop API usage. Specifically, APIGW40 determines that it is a time to stop API usage if it receives the second API usage stop request from the application store 14. Additionally, APIGW40 determines that it is a time to stop API usage if the first, third, or fourth API usage stop requests are sent.

[0118] Here, when the API usage is not scheduled to stop, APIGW40 repeats the process in S30, thus remaining in standby until the time for stopping API usage becomes reached. Furthermore, if the time for stopping API usage becomes reached, APIGW40, in S40, determines whether there are any circumstances that would preclude allowing API usage to stop for the API that is required to be stopped (hereinafter referred to as the stopped API). Specifically, APIGW40 determines whether there are any circumstances that would preclude allowing API usage to stop for the stopped API by referring to a disallowance setting table, which pre-sets disallowance information indicating the possibility of disallowance for multiple APIs. The disallowance setting table is stored in the flash memory ROM4d.

[0119] APIs that do not have circumstances that would preclude their use from being stopped include, for example, APIs for information collection systems, APIs for improving the space inside train carriages, and APIs for entertainment systems.

[0120] For APIs that should not be allowed to stop being used, such as APIs directly related to driving operations, autonomous driving system APIs, and advanced driver assistance system APIs, etc., can be listed.

[0121] Here, if there are no circumstances that would preclude API utilization from stopping for the stopped API, APIGW40 proceeds to S120. On the other hand, if there are circumstances that would preclude API utilization from stopping, APIGW40 determines in S50 whether the vehicle is in motion. Specifically, APIGW40 determines that the vehicle is in motion if the vehicle's speed is above a preset driving determination speed (e.g., 3 km / h).

[0122] Here, when the vehicle is in motion, APIGW40 moves to S70. On the other hand, when the vehicle is not in motion, APIGW40 determines in S60 whether the vehicle is stationary. Specifically, APIGW40 determines that the vehicle is stationary if the vehicle's speed is less than a preset stopping determination speed (e.g., 3 km / h) and the gear is in drive or neutral.

[0123] Here, if the vehicle is stationary, APIGW40 moves to S90. On the other hand, if the vehicle is not stationary, APIGW40 determines that the vehicle is parked and moves to S110.

[0124] If moved to S70, then as follows Figure 8 As shown, APIGW40 prohibits API access to the stopped API. This results in additional charges for continued API access. These additional charges are calculated separately from the regular charges. Furthermore, the charges can be borne by either the user (US) or the service provider (SV). For example, if the excess is due to the user's (US) fault, the user may bear the cost; if the excess is unavoidable due to security considerations, the service provider may bear the cost.

[0125] In S80, APIGW40 notifies both the user (US) and the service provider (SV) that API usage of the targeted API has been stopped, and terminates the API usage control process. Specifically, if passengers are present in the vehicle, APIGW40 notifies the user (US) that API usage of the targeted API has been stopped, for example, through a display on the navigation device 100. If no passengers are present in the vehicle, APIGW40 notifies the user (US)'s mobile terminal device 10 that API usage of the targeted API has been stopped. APIGW40 also notifies the service provider (SV)'s service provider terminal device 9 that API usage of the targeted API has been stopped.

[0126] If moved to S90, APIGW40 will function the same as S20, notifying the user (US) and service provider (SV) to cease service applications.

[0127] In step S100, APIGW40 determines whether user US has permitted API usage to stop based on input operations performed by user US via the aforementioned input device mounted on the vehicle. Specifically, if the user input information output by the input device indicates permission to stop API usage based on the user US's input operation via the aforementioned input device, APIGW40 determines that user US has permitted API usage to stop. Conversely, if the user input information indicates rejection of API usage to stop, APIGW40 determines that user US has not permitted API usage to stop. Furthermore, if the input device does not output any user input information even after a preset standby time, APIGW40 determines that user US has not permitted API usage to stop.

[0128] Here, if user US has not permitted API usage to stop, APIGW40 terminates API usage control processing. This results in additional charges for continued API usage. These additional charges are calculated separately from the regular charges.

[0129] If moved to S110, APIGW40 determines whether a vehicle user is boarding. Specifically, APIGW40 determines that a vehicle user is boarding if there is a seat occupied by more than one passenger, based on the detection results of multiple seating sensors.

[0130] Here, if the vehicle user is riding in the vehicle, APIGW40 moves to S90. On the other hand, if the vehicle user is not riding in the vehicle, APIGW40 stops API usage for the stopped object API in S120.

[0131] In S130, APIGW40, similar to S20, notifies the user (US) and service provider (SV) to stop the service application and terminates API utilization control processing.

[0132] The ECU4 configured in this way is mounted on the vehicle and connected to multiple vehicle-mounted devices 5 to 7 via the in-vehicle communication network 8, and together with the multiple vehicle-mounted devices 5 to 7, it constitutes the vehicle control system 2.

[0133] ECU4 includes an API gateway 40. The API gateway 40 is configured to enable cooperation between a first service application SA1, configured to provide services to the vehicle, and a control system function block group 35, configured to control the vehicle. The control system function block group 35 includes an API group 37. The API group 37 is configured to convert API access requests sent from the first service application SA1 in a vehicle-independent form into a vehicle-dependent form. The API gateway 40 is configured to forward API access requests sent from the first service application SA1 to the control system function block group 35.

[0134] API gateway 40 is configured to determine whether a pre-set usage stop condition is met, the usage stop condition indicating that the usage of API group 37 needs to be stopped due to factors related to charges arising from the use of at least one of the first service application SA1 and API group 37.

[0135] API gateway 40 is configured to switch the actions of vehicle control system 2 based on API disallowed information (APIs) indicating that a stop condition has been met, vehicle status information indicating the vehicle's status, and user input information (US input from the vehicle's user). Furthermore, although control system function block group 35 and data system function block group 36 both possess APIs, the switching of vehicle control system 2 based on API disallowed information applies to control system function block group 35, but not to data system function block group 36.

[0136] This ECU4 switches the vehicle control system 2's actions based on API disallowed information, vehicle status information, and user input information. Therefore, ECU4 can prevent situations where API usage is invariably stopped due to toll-related factors, thus preventing users (US) from using the service and improving the convenience for users (US) using the service.

[0137] The vehicle status information includes driving status information indicating the vehicle's driving status and passenger presence information indicating the presence or absence of passengers in the vehicle. Furthermore, the API gateway 40 is configured to switch the operation of the vehicle control system 2 by determining whether to prohibit or allow API usage based on API disallow information, vehicle status information, and user input information. Thus, the ECU 4 can determine whether to prohibit or allow API usage based at least on whether the vehicle is driving and whether there are passengers in the vehicle.

[0138] API Gateway 40 is configured to prohibit API access if it determines, based on API disallow information, that there is a possibility that API access should be stopped, and if it determines, based on driving status information, that the vehicle is in motion. Therefore, ECU4 can suppress situations where necessary services cannot be used while the vehicle is in motion, thus further improving the convenience for users (US) who wish to access the services.

[0139] API gateway 40 is configured to allow API usage to stop when, based on API disallow information, it is determined that there is a possibility that API usage should not be allowed to stop; based on driving status information, it is determined that the vehicle is stationary; and based on user input information, it is determined that user US has allowed API usage to stop. Therefore, ECU4 can stop API usage when user US has allowed API usage to stop while the vehicle is stationary. That is, it stops API usage when user US determines that API usage is unnecessary. Thus, even when API usage is stopped, ECU4 can prevent situations where services needed by user US cannot be used, further improving the convenience for user US in using the service.

[0140] API gateway 40 is configured to allow the use of functional interfaces to cease when, based on API disallow information, it is determined that there is a possibility that API usage should be stopped; based on driving status information, it is determined that the vehicle is parked; based on passenger presence information, it is determined that there are passengers in the vehicle; and based on user input information, it is determined that the user US has allowed the API usage to cease. Thus, ECU4 can stop API usage when the user US has allowed the API usage to cease while the vehicle is parked. That is, if the user US determines that API usage is unnecessary, API usage is stopped. Therefore, even when API usage is stopped, ECU4 can prevent situations where services needed by the user US cannot be used, further improving the convenience for the user US in using the services.

[0141] API gateway 40 is configured to allow the use of functional interfaces to cease when, based on API disallow information, it is determined that there is a possibility that API access should be stopped; based on driving status information, it is determined that the vehicle is parked; and based on passenger presence information, it is determined that there are no passengers in the vehicle. Thus, ECU4 can stop API access when the vehicle is parked and there are no passengers in the vehicle. That is, if there is no user US in the vehicle using the service, API access is stopped. Therefore, even when API access is stopped, ECU4 can prevent situations where the service required by user US cannot be accessed, further improving the convenience for user US using the service.

[0142] API Gateway 40 is configured to allow API usage to be stopped when it is determined, based on API disallowed information, that there is no possibility that API usage should be stopped. That is, for APIs that would not pose a problem for user US even if usage is stopped, usage is stopped based on factors related to charges. In this way, ECU4 stops the use of APIs that would not pose a problem for user US even if usage is stopped, thus preventing situations where users US cannot access the services they need, further improving the convenience for users US in accessing services.

[0143] Furthermore, the API gateway 40 is configured to determine whether a pre-defined usage stop prediction condition indicating a possibility of stopping API usage is met. Moreover, if the usage stop prediction condition is met, the API gateway 40 is configured to notify the user US to stop using the first service application SA1 that the API is being used. Thus, the ECU4 enables the user US to recognize the possibility that the first service application SA1 cannot be used.

[0144] Furthermore, the API gateway 40 is configured to notify the user US using the navigation device 100 installed in the vehicle when passengers are present, and to notify the user US using a mobile terminal device 10 pre-registered with the user US when no passengers are present. Thus, the ECU4 can suppress situations where the user US cannot recognize and stop using the first service application SA1.

[0145] In the embodiments described above, ECU4 is equivalent to an in-vehicle device, ECU5, ECU6 and external communication device 7 are equivalent to multiple electronic control devices, and in-vehicle communication network 8 is equivalent to an in-vehicle network.

[0146] In addition, the first service application SA1 is equivalent to a service application, the control system function block group 35 is equivalent to a control system function block, the API gateway 40 is equivalent to a collaborative control unit, and the API group 37 is equivalent to a function interface.

[0147] In addition, S30 is equivalent to the processing of the stop judgment unit, the judgment condition of S30 is equivalent to the stop condition, S40 to S70 and S100 to S120 are equivalent to the processing of the control unit, and the API disallow information is equivalent to the function interface information.

[0148] In addition, S10 is equivalent to the processing of the prediction and judgment unit, the judgment condition of S10 is equivalent to the use of the stop prediction condition, S20 is equivalent to the processing of the notification unit, the navigation device 100 is equivalent to the first notification device, and the mobile terminal device 10 is equivalent to the second notification device.

[0149] The above describes one embodiment of the present disclosure, but the present disclosure is not limited to the above embodiment and can be implemented in various modifications.

[0150] [Variation Example 1]

[0151] In the above implementation, a method is shown to determine whether there is a situation where it is inappropriate to allow API usage to stop based on API disallow information indicating the presence or absence of disallowable possibilities. However, instead of determining the presence or absence of disallowable possibilities, it is also possible to determine whether there is a situation where it is inappropriate to allow API usage to stop based on the level of disallowable possibility (e.g., 0, 1, 2, 3, ...).

[0152] [Modification Example 2]

[0153] The above embodiments illustrate a method for prohibiting API utilization from stopping while the vehicle is in motion. However, it is also possible to allow API utilization to continue by prohibiting it, stopping API utilization when it is safe to do so. Additionally, if the vehicle has autonomous driving capabilities, it can automatically reverse and stop API utilization.

[0154] [Modification Example 3]

[0155] In the above embodiments, such as Figure 7 The diagram illustrates how the process S110 is executed. However, the process S110 can also be skipped. That is, in S60, if the vehicle is not stopped, APIGW40 can also move to S120. Thus, ECU4 can stop API utilization as early as possible.

[0156] [Variation Example 4]

[0157] In the above embodiments, a method is shown to determine whether the vehicle is driving, stationary, or parked based on the vehicle's speed and gear. However, the driving status of the vehicle can also be determined using information from the navigation device 100.

[0158] [Variation Example 5]

[0159] The above implementation illustrates a method for stopping API usage based on factors related to charges. However, it is also possible to control the stopping of API usage for all APIs used by security-related service applications at the same time.

[0160] [Variation Example 6]

[0161] The above implementation illustrates a method for stopping API usage based on factors related to charges. However, API usage can also be stopped by disabling or forcibly terminating the service application during startup.

[0162] The ECU4 and method described in this disclosure can also be implemented by a special-purpose computer consisting of a processor and memory programmed to perform one or more functions embodied in a computer program. Alternatively, the ECU4 and method described in this disclosure can also be implemented by a special-purpose computer consisting of a processor composed of one or more special-purpose hardware logic circuits. Alternatively, the ECU4 and method described in this disclosure can also be implemented by one or more special-purpose computers, which are configured by a combination of a processor and memory programmed to perform one or more functions and a processor composed of one or more hardware logic circuits. Furthermore, the computer program can also be stored as instructions executable by a computer on a computer-readable non-transitional tangible recording medium. The method for implementing the functions of the various parts included in the ECU4 does not necessarily require software; all its functions can be implemented using one or more hardware components.

[0163] Multiple functions of a single component in the above embodiments can be achieved through multiple components, or a single function of a single component can be achieved through multiple components. Alternatively, multiple functions of multiple components can be achieved through a single component, or a single function achieved by multiple components can be achieved through a single component. Furthermore, a portion of the structure in the above embodiments can be omitted. Additionally, at least a portion of the structure in the above embodiments can be added to or replaced with the structure of other above embodiments.

[0164] In addition to the ECU4 described above, this disclosure can also be implemented in various ways, such as a system that includes the ECU4 as a component, a program for enabling a computer to function as the ECU4, a non-transitional physical recording medium such as a semiconductor memory that records the program, and a service provision method.

[0165] [The technical concepts disclosed in this specification]

[0166] [Project 1]

[0167] An in-vehicle device (4) is mounted on a vehicle and connected to multiple electronic control devices (5-7) via an in-vehicle network (8), and together with the multiple electronic control devices constitutes a vehicle control system (2), comprising:

[0168] The cooperative control unit (40) is configured to enable cooperation between the service application (SA1) and the control system function block (35), wherein the service application is configured to provide services to the vehicle and the control system function block is configured to control the vehicle.

[0169] The above-mentioned control system functional blocks include:

[0170] The functional interface (37) is configured to convert access requests sent from the aforementioned service application in a vehicle-independent form into a vehicle-dependent form.

[0171] The aforementioned collaborative control unit is configured to forward the access request sent from the aforementioned service application to the aforementioned control system function block.

[0172] The aforementioned collaborative control unit possesses:

[0173] The stop determination unit (S30) is configured to determine whether a pre-set use stop condition is met. This use stop condition indicates that use of the aforementioned function interface needs to be stopped due to factors related to charges incurred from using at least one of the service application and the aforementioned function interface; and

[0174] The control unit (S40-S70, S100-S120) is configured to switch the operation of the vehicle control system based on the function interface information related to the function interface that is established by the stop condition, the vehicle status information indicating the state of the vehicle, and the user input information using the user input of the vehicle.

[0175] [Project 2]

[0176] According to the vehicle-mounted device described in Project 1, among which,

[0177] The aforementioned vehicle status information includes driving status information indicating the vehicle's driving status, and passenger presence information indicating the presence or absence of passengers in the vehicle.

[0178] The aforementioned control unit is configured to switch the operation of the vehicle control system by deciding whether to disable or enable the use of the aforementioned function interface based on the aforementioned function interface information, the aforementioned vehicle status information, and the aforementioned user input information.

[0179] [Project 3]

[0180] According to the vehicle-mounted device described in Project 2, among which,

[0181] The aforementioned utilization control unit is configured to prohibit the utilization of the aforementioned function interface from stopping when it is determined, based on the aforementioned function interface information, that there is a possibility that the utilization should not be stopped, and when it is determined, based on the aforementioned driving status information, that the vehicle is in motion.

[0182] [Project 4]

[0183] According to the vehicle-mounted device described in Project 2 or Project 3, among which,

[0184] The aforementioned utilization control unit is configured to allow the utilization of the aforementioned function interface to stop when, based on the aforementioned function interface information, it is determined that there is a possibility that the utilization should not be stopped, and based on the aforementioned driving status information, it is determined that the vehicle is stopped, and based on the aforementioned user input information, it is determined that the user has allowed the utilization of the aforementioned function interface to stop, thereby allowing the utilization of the aforementioned function interface to stop.

[0185] [Project 5]

[0186] According to any one of items 2 to 4, the vehicle-mounted device, among which,

[0187] The aforementioned control unit is configured to allow the use of the aforementioned function interface to be stopped when, based on the aforementioned function interface information, it is determined that there is a possibility that the use should not be stopped; based on the aforementioned driving status information, it is determined that the vehicle is parked; based on the aforementioned passenger presence information, it is determined that there are passengers in the vehicle; and based on the aforementioned user input information, it is determined that the user has allowed the use of the aforementioned function interface to be stopped.

[0188] [Project 6]

[0189] According to any one of items 2 to 5, the vehicle-mounted device, among which,

[0190] The aforementioned control unit is configured to allow the use of the aforementioned function interface to stop when, based on the aforementioned function interface information, it is determined that there is a possibility that the use should not be stopped, and based on the aforementioned driving status information, it is determined that the vehicle is parked, and based on the aforementioned passenger presence information, it is determined that there are no passengers in the vehicle.

[0191] [Project 7]

[0192] According to any one of items 2 to 6, the vehicle-mounted device, among which,

[0193] The aforementioned utilization control unit is configured to allow the utilization of the aforementioned functional interface to be stopped when it is determined, based on the aforementioned functional interface information, that there is no possibility that the utilization should not be stopped.

[0194] [Project 8]

[0195] According to any one of items 2 to 7, the vehicle-mounted device, among which,

[0196] The aforementioned collaborative control unit also possesses:

[0197] The prediction and judgment unit (S10) is configured to determine whether a pre-set usage stop prediction condition is met, wherein the usage stop prediction condition indicates the possibility of stopping the use of the aforementioned functional interface; and

[0198] The notification unit (S20) is configured to notify the user to stop using the service application that uses the aforementioned function interface when the prediction and judgment unit determines that the aforementioned stop prediction condition is met.

[0199] [Project 9]

[0200] According to the vehicle-mounted device described in Project 8, among which,

[0201] The notification unit is configured such that when the passenger is present in the vehicle, a first notification device (100) installed in the vehicle is used to notify the user, and when the passenger is not present in the vehicle, a second notification device (10) pre-registered with the user is used to notify the user.

[0202] [Project 10]

[0203] A service provision method is a service provision method performed by an on-board device (4), which is mounted on a vehicle and connected to multiple electronic control devices (5-7) via an on-board network (8), and together with the multiple electronic control devices, constitutes a vehicle control system (2).

[0204] The aforementioned vehicle-mounted device includes:

[0205] The cooperative control unit (40) is configured to enable cooperation between the service application (SA1) and the control system function block (35), wherein the service application is configured to provide services to the vehicle and the control system function block is configured to control the vehicle.

[0206] The above-mentioned control system functional blocks include:

[0207] The functional interface (37) is configured to convert access requests sent from the aforementioned service application in a vehicle-independent form into a vehicle-dependent form.

[0208] The aforementioned collaborative control unit is configured to forward the access request sent from the aforementioned service application to the aforementioned control system function block.

[0209] The aforementioned collaboration control unit determines whether a pre-set usage stop condition is met. This usage stop condition indicates that the use of the aforementioned function interface needs to be stopped due to factors related to charges incurred from using at least one of the aforementioned service application and the aforementioned function interface.

[0210] The aforementioned cooperative control unit switches the operation of the vehicle control system based on the functional interface information related to the functional interface that is established by the stop condition, the vehicle status information indicating the status of the vehicle, and the user input information using the user input of the vehicle.

[0211] [Project 11]

[0212] A service provider

[0213] The computer of the vehicle-mounted device (4), which is mounted on a vehicle and connected to multiple electronic control devices (5-7) via the vehicle network (8) and together with the multiple electronic control devices constitutes the vehicle control system (2), performs the following functions:

[0214] The functional interface (37) is configured to convert access requests sent from the service application (SA1) and presented in a vehicle-independent form into a vehicle-dependent form, wherein the service application is configured to provide services to the vehicle.

[0215] The collaboration control unit (40) is configured to enable collaboration between the service application and the control system function block (35), and is configured to forward the access request sent from the service application to the control system function block, which is configured to have the function interface and control the vehicle.

[0216] The stop determination unit (S30) is configured to determine whether a pre-set use stop condition is met. This use stop condition indicates that use of the aforementioned function interface needs to be stopped due to factors related to charges incurred from using at least one of the service application and the aforementioned function interface; and

[0217] The control unit (S40-S70, S100-S120) is configured to switch the operation of the vehicle control system based on the function interface information related to the function interface that is established by the stop condition, the vehicle status information indicating the state of the vehicle, and the user input information using the user input of the vehicle.

Claims

1. A vehicle-mounted device (4) is mounted on a vehicle and connected to multiple electronic control devices (5-7) via a vehicle network (8), and together with the multiple electronic control devices constitutes a vehicle control system (2), wherein, have: The cooperation control unit (40) is configured to enable cooperation between the service application (SA1) and the control system function block (35), wherein the service application is configured to provide services to the vehicle. The above-mentioned control system functional blocks include: The functional interface (37) is configured to convert access requests sent from the aforementioned service application in a vehicle-independent form into a vehicle-dependent form. The aforementioned collaborative control unit is configured to forward the access request sent from the aforementioned service application to the aforementioned control system function block. The aforementioned collaborative control unit possesses: The stop determination unit (S30) is configured to determine whether a pre-set use stop condition is met. The use stop condition indicates that the use of the above-mentioned function interface needs to be stopped due to factors related to charges arising from the use of at least one of the above-mentioned service application and the above-mentioned function interface. as well as The control unit (S40-S70, S100-S120) is configured to switch the operation of the vehicle control system based on the function interface information related to the function interface that is established by the stop condition, the vehicle status information indicating the state of the vehicle, and the user input information using the user input of the vehicle.

2. The vehicle-mounted device according to claim 1, wherein, The aforementioned vehicle status information includes driving status information indicating the vehicle's driving status, and passenger presence information indicating the presence or absence of passengers in the vehicle. The aforementioned control unit is configured to switch the operation of the vehicle control system by deciding whether to disable or enable the use of the aforementioned function interface based on the aforementioned function interface information, the aforementioned vehicle status information, and the aforementioned user input information.

3. The vehicle-mounted device according to claim 2, wherein, The aforementioned control unit is configured to prohibit the use of the aforementioned function interface from stopping when it is determined, based on the aforementioned function interface information, that there is a possibility that the use may not be stopped, and when it is determined, based on the aforementioned driving status information, that the vehicle is in motion.

4. The vehicle-mounted device according to claim 2 or 3, wherein, The aforementioned control unit is configured to allow the use of the aforementioned function interface to stop when, based on the aforementioned function interface information, it is determined that there is a possibility that the use of the aforementioned function interface may not be allowed to stop; based on the aforementioned driving status information, it is determined that the aforementioned vehicle is stopped; and based on the aforementioned user input information, it is determined that the aforementioned user has allowed the use of the aforementioned function interface to stop; and so on.

5. The vehicle-mounted device according to claim 2 or 3, wherein, The aforementioned control unit is configured to allow the use of the aforementioned function interface to stop when, based on the aforementioned function interface information, it is determined that there is a possibility that the use of the aforementioned function interface may not be allowed to stop; based on the aforementioned driving status information, it is determined that the aforementioned vehicle is parked; based on the aforementioned passenger presence information, it is determined that the aforementioned passenger is present in the aforementioned vehicle; and based on the aforementioned user input information, it is determined that the aforementioned user has allowed the use of the aforementioned function interface to stop, thereby allowing the use of the aforementioned function interface to stop.

6. The vehicle-mounted device according to claim 2 or 3, wherein, The aforementioned control unit is configured to allow the use of the aforementioned function interface to stop when it is determined, based on the aforementioned function interface information, that there is a possibility that the use may not be allowed to stop, and based on the aforementioned driving status information, it is determined that the vehicle is parked, and based on the aforementioned passenger presence information, it is determined that there are no passengers in the vehicle.

7. The vehicle-mounted device according to claim 2 or 3, wherein, The aforementioned utilization control unit is configured to allow the utilization of the aforementioned functional interface to be stopped when it is determined, based on the aforementioned functional interface information, that there is no possibility that the utilization cannot be stopped at the aforementioned functional interface.

8. The vehicle-mounted device according to claim 2 or 3, wherein, The aforementioned collaborative control unit also possesses: The prediction and judgment unit (S10) is configured to determine whether a pre-set use stop prediction condition is met, which indicates the possibility of stopping the use of the above-mentioned function interface. as well as The notification unit (S20) is configured to notify the user to stop using the service application that uses the aforementioned function interface when the prediction and judgment unit determines that the aforementioned stop prediction condition is met.

9. The vehicle-mounted device according to claim 8, wherein, The notification unit is configured such that when the passenger is present in the vehicle, a first notification device (100) installed in the vehicle is used to notify the user, and when the passenger is not present in the vehicle, a second notification device (10) pre-registered with the user is used to notify the user.

10. A service provision method performed by an on-board device (4), the on-board device being mounted on a vehicle and connected to multiple electronic control devices (5-7) via an on-board network (8), and constituting a vehicle control system (2) together with the multiple electronic control devices, wherein, The aforementioned vehicle-mounted device includes: The cooperative control unit (40) is configured to enable cooperation between the service application (SA1) and the control system function block (35), wherein the service application is configured to provide services to the vehicle and the control system function block is configured to control the vehicle. The above-mentioned control system functional blocks include: The functional interface (37) is configured to convert access requests sent from the aforementioned service application in a vehicle-independent form into a vehicle-dependent form. The aforementioned collaborative control unit is configured to forward the access request sent from the aforementioned service application to the aforementioned control system function block. The aforementioned collaboration control unit determines whether a pre-set usage stop condition is met. This usage stop condition indicates that the use of the aforementioned function interface needs to be stopped due to factors related to charges incurred from using at least one of the aforementioned service application and the aforementioned function interface. The aforementioned cooperative control unit switches the operation of the vehicle control system based on the functional interface information related to the functional interface that is established by the stop condition, the vehicle status information indicating the status of the vehicle, and the user input information using the user input of the vehicle.

11. A service provider, wherein, The computer of the vehicle-mounted device (4), which is mounted on a vehicle and connected to multiple electronic control devices (5-7) via the vehicle network (8) and together with the multiple electronic control devices constitutes the vehicle control system (2), performs the following functions: The functional interface (37) is configured to convert access requests sent from the service application (SA1) and presented in a vehicle-independent form into a vehicle-dependent form, wherein the service application is configured to provide services to the vehicle. The collaboration control unit (40) is configured to enable collaboration between the service application and the control system function block (35), and is configured to forward the access request sent from the service application to the control system function block, which is configured to have the function interface and control the vehicle. The stop determination unit (S30) is configured to determine whether a pre-set use stop condition is met. The use stop condition indicates that the use of the above-mentioned function interface needs to be stopped due to factors related to charges arising from the use of at least one of the above-mentioned service application and the above-mentioned function interface. as well as The control unit (S40-S70, S100-S120) is configured to switch the vehicle control system based on the function interface information related to the function interface that is established by the stop condition, the vehicle status information indicating the state of the vehicle, and the user input information using the user input of the vehicle.

Citation Information

Patent Citations

  • Vehicle and service management device

    JP2020098610A

  • Game machine

    JP2023097691A