Vehicle verification system

By distributing vehicle composition information and building virtual models, the problem of centralized storage of vehicle status data being vulnerable to attacks is solved, thus improving security and accuracy.

CN121773404APending Publication Date: 2026-03-31ASTEMO LTD
View PDF 1 Cites 0 Cited by

Patent Information

Authority / Receiving Office
CN · China
Patent Type
Applications(China)
Current Assignee / Owner
Filing Date
2023-09-07
Publication Date
2026-03-31

AI Technical Summary

Technical Problem

In existing technologies, vehicle status data is centrally stored in a central ECU or gateway ECU, which is vulnerable to security attacks that could lead to the complete loss of vehicle information, affecting the security and accuracy of the virtual model.

Method used

Multiple first and second electronic control devices are used to store vehicle configuration information in a distributed manner. Some configuration information is sent to the back-end server to build a virtual model to evaluate vehicle performance, thus avoiding centralized storage of overall information.

Benefits of technology

This reduces the risk of the vehicle's overall configuration information being read by security attacks, while also building a high-precision virtual model to ensure the security and accuracy of vehicle performance evaluation.

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure CN121773404A_ABST
    Figure CN121773404A_ABST
Patent Text Reader

Abstract

The purpose of the present invention is to provide a vehicle verification system capable of constructing a virtual model of a vehicle while reducing the risk that constituent information of the entire vehicle is read due to a security attack. To this end, a vehicle verification system (1) for evaluating the performance of a vehicle (2) is provided with: a rear-end server (3) disposed outside the vehicle (2); a plurality of first electronic control devices (4) that are mounted on the vehicle (2) and that store configuration information of the vehicle (2) in a distributed manner; and a second electronic control device (5) that is mounted on the vehicle (2), receives partial configuration information, which is a part of the configuration information of the vehicle (2), from the plurality of first electronic control devices (4), and transmits the partial configuration information to a rear-end server (3) that stores the configuration information of the vehicle (2). And a performance evaluation unit (5) that updates the stored configuration information of the vehicle (2) using the partial configuration information received from the second electronic control device (5), constructs a virtual model of the vehicle (2) using the updated configuration information of the vehicle (2), and evaluates the performance of the vehicle (2) using the virtual model.
Need to check novelty before this filing date? Find Prior Art

Description

Technical Field

[0001] This invention relates to the retention of data from electronic control devices or systems comprised of electronic control devices mounted on vehicles, as well as systems located inside or outside vehicles and verified through vehicle simulation. Background Technology

[0002] Existing technical literature, for example, includes patent literature 1, which discloses a technology that can efficiently and accurately verify the impact of vehicle changes or additions of components or software updates.

[0003] Existing technical documents

[0004] Patent documents

[0005] Patent Document 1: Japanese Patent Application Publication No. 2023-13183 Summary of the Invention

[0006] The problem the invention aims to solve

[0007] Patent document 1 discloses the following technology: acquiring data related to the vehicle's state, using this data to construct a virtual model, and verifying the effects of adding or changing components with high precision through virtual simulation using the virtual model. However, since the vehicle state-related data used to construct the virtual model is aggregated in one place (central ECU or gateway ECU) and sent to a parsing server, there is a risk that the entire vehicle state could be read if the information sent to the parsing server for constructing the virtual model or the information stored in the central ECU or gateway ECU is read by a security attack.

[0008] The present invention was made in view of the above-mentioned problems, and its object is to provide a vehicle verification system that can reduce the risk of the overall composition information of the vehicle being read due to security attacks, and can construct a virtual model of the vehicle.

[0009] Technical means to solve the problem

[0010] To achieve the above objectives, the present invention provides a vehicle verification system for evaluating vehicle performance. The vehicle verification system comprises: a backend server configured externally to the vehicle; a plurality of first electronic control devices mounted on the vehicle, which disperse and store the vehicle's configuration information; and a second electronic control device mounted on the vehicle, which receives partial configuration information as part of the vehicle's configuration information from the plurality of first electronic control devices and sends the partial configuration information to the backend server. The backend server stores the vehicle's configuration information, updates the stored vehicle configuration information using the partial configuration information received from the second electronic control device, constructs a virtual model of the vehicle using the updated vehicle configuration information, and evaluates the vehicle's performance using the virtual model.

[0011] Invention Effects

[0012] According to the present invention, a virtual model of a vehicle can be constructed while reducing the risk of the overall vehicle configuration information being read by a security attack. Other issues, configurations, and effects not described above will be clarified through the following description of embodiments. Attached Figure Description

[0013] Figure 1 This is a diagram illustrating a vehicle verification system according to a first embodiment of the present invention.

[0014] Figure 2 This is a diagram illustrating an example of the configuration information of the various components of the vehicle in the first embodiment of the present invention.

[0015] Figure 3 This is a flowchart illustrating the processing of the vehicle verification system according to the first embodiment of the present invention.

[0016] Figure 4 This is a flowchart illustrating a first variation of the processing of the vehicle verification system according to the first embodiment of the present invention.

[0017] Figure 5 This is a flowchart illustrating a second variation of the processing of the vehicle verification system according to the first embodiment of the present invention.

[0018] Figure 6 This is a diagram illustrating a vehicle verification system according to a second embodiment of the present invention.

[0019] Figure 7 This is a diagram illustrating an example of the historical and performance information of various components of the vehicle in the second embodiment of the present invention.

[0020] Figure 8 This is a flowchart illustrating the processing of the vehicle verification system according to the second embodiment of the present invention.

[0021] Figure 9 This is a diagram illustrating a vehicle verification system according to a third embodiment of the present invention.

[0022] Figure 10 This is a flowchart illustrating the processing of the vehicle verification system according to the third embodiment of the present invention. Detailed Implementation

[0023] Hereinafter, embodiments of the present invention will be described with reference to the accompanying drawings. In the drawings, equivalent components are given the same reference numerals, and repeated descriptions are omitted.

[0024] Example 1

[0025] Figure 1 This is a diagram illustrating a vehicle verification system according to a first embodiment of the present invention. Figure 1 In the system, vehicle verification system 1 includes vehicle 2 and backend server 3 (such as parsing server, verification server, cloud server, etc.).

[0026] Vehicle 2 may include, for example, multiple electronic control units 4 (e.g., domain ECU, area ECU, hereinafter referred to as local ECU), which are distributed in each area (physical location) and domain (function); and electronic control unit 5 (e.g., central gateway, communication control unit, etc., hereinafter referred to as central ECU), which communicates between the local ECU 4 and the outside of the vehicle.

[0027] The local ECU 4 includes a terminal change extraction unit 4a, a configuration information storage unit 4b, and a configuration information transmission unit 4c. The terminal change extraction unit 4a extracts information (change information) when a component connected to the local ECU 4 (other electronic control devices, actuators, sensors, etc., hereinafter referred to as connecting components) changes. The configuration information storage unit 4b stores the configuration information of the local ECU 4 and updates the stored configuration information of the local ECU 4 using the change information extracted by the terminal change extraction unit 4a. The configuration information transmission unit 4c transmits the updated configuration information of the local ECU 4 to the back-end server 3 via the central ECU 5.

[0028] The central ECU 5 has a configuration information receiving unit 5a and a configuration information external transmission unit 5b. The configuration information receiving unit 5a receives configuration information from the configuration information transmission unit 4c of the local ECU 4. The configuration information external transmission unit 5b transmits the configuration information of the local ECU 4 received by the configuration information receiving unit 5a to the back-end server 3. However, the central ECU 5 does not summarize, record, or synthesize the configuration information of the local ECU 4. This prevents the storage of the overall configuration information of the vehicle in a specific ECU.

[0029] The backend server 3 includes a configuration information receiving unit 3a, a configuration information storage unit 3b, a virtual model construction unit 3c, and an impact verification unit 3d. The configuration information receiving unit 3a receives configuration information from the local ECU 4 from the configuration information external transmission unit 5b. The configuration information storage unit 3b stores configuration information of the vehicle 2 and updates the stored configuration information of the vehicle 2 using the configuration information of the local ECU 4 received by the configuration information receiving unit 3a. The virtual model construction unit 3c uses the configuration information of the vehicle 2 stored in the configuration information storage unit 3b to construct a virtual model (digital twin) of the vehicle 2. The impact verification unit 3d evaluates the performance of the vehicle 2 using the virtual model and verifies the impact of changes to the configuration information of the vehicle 2.

[0030] Figure 2 This diagram illustrates an example of the component configuration information for vehicle 2. The vehicle body configuration information includes the ID. The ECU configuration information includes the ID, design (SoC, memory, communication line type, etc.), SW (App, BSW / MW, OS), and connection relationships (connection component ID, communication line ID). The communication line configuration information includes the ID, type (Ethernet, CAN, etc.), bandwidth, and connection relationship (connection component ID). The sensor configuration information includes the ID, sensor type, control cycle, output data volume, and connection relationship (connection component ID). The actuator configuration information includes the ID, actuator type, control cycle, input data volume, and connection relationship (connection component ID). The application software (App) configuration information includes the ID, installation type, required processing power, control cycle, ASIL, safety level, and version information. The base software (BSW) / middleware (MW) configuration information includes the ID, required processing power, and version information. The OS configuration information includes the ID, required processing power, and version information.

[0031] Figure 3 This is a flowchart illustrating the processing of the vehicle verification system 1 in this embodiment. In this process, if the change to the connection component is invalid, the user is advised to restore the connection component to its state before the change.

[0032] First, in vehicle 2, the connection components of local ECU4 are changed (step S100).

[0033] After step S100, the terminal change extraction unit 4a of the local ECU4 extracts the change information of the connection component (step S101).

[0034] After step S101, the configuration information storage unit 4b of the local ECU4 updates the stored configuration information of the local ECU4 using the change information of the connection components (step S102).

[0035] After step S102, the configuration information sending unit 4c of the local ECU4 sends the updated configuration information of the local ECU4 to the central ECU5 (step S103).

[0036] After step S103, the external transmission unit 5b of the central ECU 5 sends the updated configuration information of the local ECU 4 to the back-end server 3 (step S104).

[0037] After step S104, the configuration information storage unit 4b of the backend server 3 uses the updated configuration information of the local ECU 4 to update the stored configuration information of the vehicle 2 (step S105).

[0038] After step S105, the virtual model construction unit 3c of the backend server 3 uses the updated composition information of vehicle 2 to construct a virtual model (step S106).

[0039] After step S106, the impact verification unit 3d of the backend server 3 uses a virtual model to verify the impact caused by the change of the connection component (step S107).

[0040] After step S107, the impact verification unit 3d of the backend server 3 determines whether the change to the connection component is valid based on the verification result of step S107 (step S108). The validity of the change to the connection component here means, for example, that the change to the connection component will not impair the performance of the vehicle 2.

[0041] If the determination result in step S108 is "no", the user is advised to restore the connection component changed in step S100 to its state before the change (step S109), and the process returns to step S100.

[0042] If the determination result in step S108 is "yes", the process ends.

[0043] Figure 4 This is a flowchart illustrating a first variation of the processing of the vehicle verification system 1 in this embodiment. In this process, if the change to the connection component is invalid, the user is advised to change to another connection component different from the changed one. Figure 4 In the middle, steps S100 to S108 and Figure 3 Since they are the same, the explanation is omitted.

[0044] If the determination result in step S108 is "no", the virtual model construction unit 3c of the backend server 3 assumes that other connection components (other connection components) different from the connection components changed in step S100 have been changed, and reconstructs the virtual model (step S110).

[0045] After step S110, the impact verification unit 3d of the backend server 3 uses the reconstructed virtual model to re-verify the impact caused by the change of the connection component (step S111).

[0046] After step S111, the impact verification unit 3d of the backend server 3 determines whether the change of the connection component is valid based on the result of the re-verification in step S111 (step S112).

[0047] If the determination result in step S112 is "no", return to step S110.

[0048] If the determination result in step S112 is "yes", the user is advised to change other connection components that were assumed to have been changed in step S110 (step S113), and the process ends.

[0049] Figure 5 This is a flowchart illustrating a second variation of the processing of the vehicle verification system 1 in this embodiment. In this process, when a change to the connection component is invalid, the software associated with the changed connection component is changed. Figure 5 In the middle, steps S100 to S108 and Figure 3 Since they are the same, the explanation is omitted.

[0050] If the determination result in step S108 is "no", the virtual model construction unit 3c of the backend server 3 changes the software associated with the connection component that was changed in step S100, and reconstructs the virtual model (step S114).

[0051] After step S114, the impact verification unit 3d of the backend server 3 uses the reconstructed virtual model to re-verify the impact caused by the change of the connection component (step S115).

[0052] After step S115, the impact verification unit 3d of the backend server 3 determines whether the change of the connection component in step S100 is valid based on the result of the re-verification in step S115 (step S116).

[0053] If the determination result in step S116 is "no", return to step S114.

[0054] If the determination result in step S116 is "yes", the backend server 3 will send the associated software that was changed in step S114 to vehicle 2, update the associated software of vehicle 2 (step S117), and end the process.

[0055] (Summarize)

[0056] In a first embodiment, a vehicle verification system 1 for evaluating the performance of vehicle 2 includes: a backend server 3 configured externally to vehicle 2; a plurality of first electronic control devices 4 mounted on vehicle 2 and storing configuration information of vehicle 2 in a distributed manner; and a second electronic control device 5 configured on vehicle 2, which receives partial configuration information (configuration information of local ECU 4) as part of the configuration information of vehicle 2 from the plurality of first electronic control devices 4 and sends the partial configuration information to the backend server 3, wherein the backend server 3 stores the configuration information of vehicle 2, updates the stored configuration information of vehicle 2 using the partial configuration information received from the second electronic control device 5, constructs a virtual model of vehicle 2 using the updated configuration information of vehicle 2, and evaluates the performance of vehicle 2 using the virtual model.

[0057] According to the first embodiment with the configuration described above, since the overall vehicle configuration information is not stored in a specific electronic control device, and the information sent from vehicle 2 to backend server 3 is limited to a portion of the vehicle 2 configuration information (partial configuration information), a virtual model of vehicle 2 can be constructed while reducing the risk of the overall vehicle configuration information being read due to a security attack. As a result, further security attacks and misuse of information can be prevented.

[0058] Furthermore, in this embodiment, multiple first electronic control devices 4 send information about changes in the vehicle 2's configuration information to the second electronic control device 5 as the partial configuration information. Therefore, since the information sent from the second electronic control device 5 to the backend server 3 is limited to the changes in the overall vehicle configuration information, the risk of the overall vehicle configuration information being read can be further reduced.

[0059] Example 2

[0060] The second embodiment of the present invention will be described focusing on the differences from the first embodiment.

[0061] Figure 6 This is a diagram illustrating the vehicle verification system 1 of this embodiment. Figure 6 In this configuration, the local ECU4 has a terminal status extraction unit 4d to replace the terminal change extraction unit 4a. Figure 1 (As shown). The terminal status extraction unit 4D extracts the historical and performance information of each component. The historical and performance information of each component is equivalent to the degradation information of each component.

[0062] Figure 7This diagram illustrates an example of the historical and performance information of various components of vehicle 2. The vehicle body's historical and performance information includes mileage, IGN ON / OFF time, and maintenance information. The ECU's historical and performance information includes start / stop time, average CPU utilization, maximum CPU utilization, average memory utilization, maximum memory utilization, average power consumption, maximum power consumption, average temperature, maximum temperature, performance degradation information, and error logs. The communication line's historical and performance information includes bandwidth usage, average latency, maximum latency, packet loss rate, bit error rate, and performance degradation information. The sensor's historical and performance information includes output data, access frequency, and wear / depletion status. The actuator's historical and performance information includes input data, input frequency, abrupt changes in input, and wear / depreciation status. The application software (App)'s historical and performance information includes data corresponding to the application software to be verified, update information, and error logs. The base software (BSW) / middleware (MW) and operating system (OS)'s historical and performance information includes update information.

[0063] Figure 8 This is a flowchart illustrating the processing of the vehicle verification system 1 in this embodiment. In this process, the user is advised to replace the connection component based on its deterioration status.

[0064] First, the terminal status extraction unit 4d of the local ECU4 extracts the historical and performance information of the connection components (step S200).

[0065] After step S200, the configuration information storage unit 4b of the local ECU4 stores the history and performance information of the connection components (step S201).

[0066] After step S201, the configuration information sending unit 4c of the local ECU4 sends the configuration information, history, and performance information of the connection components of the local ECU4 to the central ECU5 (step S202).

[0067] After step S202, the external vehicle information transmission unit 5b of the central ECU5 sends the configuration information, history, and performance information of the connection components of the local ECU4 to the back-end server 3 (step S203).

[0068] After step S203, the configuration information storage unit 4b of the back-end server 3 uses the configuration information and history and performance information of the connection components of the local ECU 4 to update the stored configuration information of the vehicle 2 (step S204).

[0069] After step S204, the virtual model building unit 3c of the backend server 3 uses the updated composition information of vehicle 2 to generate a virtual model (step S205).

[0070] After step S205, the impact verification unit 3d of the backend server 3 uses a virtual model to verify the impact caused by the degradation of the connection components (step S206).

[0071] After step S206, the impact verification unit 3d of the backend server 3 determines whether the connection component needs to be replaced based on the verification result of step S206 (step S207).

[0072] If the determination result in step S207 is "no", the process ends.

[0073] If the determination result in step S207 is "yes", the user is advised to replace the component (step S208), and the process ends.

[0074] (Summarize)

[0075] In the second embodiment, the second electronic control device 5 obtains degradation information (history, performance information) of components connected to the multiple first electronic control devices 4 from the multiple first electronic control devices 4, and sends the degradation information together with the partial configuration information to the back-end server 3. The back-end server 3 uses the degradation information received from the second electronic control device 5 to update the stored configuration information of the vehicle 2.

[0076] In the second embodiment configured as described above, similar to the first embodiment, a virtual model of vehicle 2 can be constructed while reducing the risk of the overall vehicle configuration information being read due to a security attack. Furthermore, by updating the configuration information, history, and performance information (deterioration information) of the connection components of the local ECU 4 to the configuration information of vehicle 2 stored in the backend server 3, and using the updated configuration information of vehicle 2 to construct a virtual model of vehicle 2, the impact of the degradation of the connection components can be verified.

[0077] Example 3

[0078] The third embodiment of the present invention will be described focusing on its differences from the first embodiment.

[0079] Figure 9 This is a diagram illustrating the vehicle verification system 1 of this embodiment. Figure 9 In the process, the local ECU 4 includes an information storage unit 4b and a software update request unit 4e. The central ECU 5 includes an update request receiving unit 5c and an update request external transmission unit 5d. The back-end server 3 has a software update request receiving unit 3e to replace the information receiving unit 3a. Figure 1 (As shown).

[0080] Figure 10This is a flowchart illustrating the processing of the vehicle verification system 1 in this embodiment. In this process, the updated software, which has already been verified using a virtual model, is sent from the backend server 3 to the vehicle 2, thereby updating the software of the vehicle 2.

[0081] First, the software update request unit 4e of the local ECU4 sends the configuration information of the local ECU4 and a software update request to the central ECU5 (step S300). The software update request mentioned here is the software update request included in the configuration information of the local ECU4.

[0082] After step S300, the external transmission unit 5d of the central ECU5 sends the configuration information of the local ECU4 and the software update request to the back-end server 3 (step S301).

[0083] After step S301, the software update request receiving unit 3e of the backend server 3 confirms the software update information contained in the configuration information of the local ECU 4 (step S302).

[0084] After step S302, it is determined whether there is a software update (step S303). If the determination result in step S303 is "no", the process ends.

[0085] If the determination result in step S303 is "yes", determine whether the verification of using the virtual model has been completed for the updated software (step S304).

[0086] If the determination result in step S304 is "yes", the backend server 3 sends the software update to vehicle 2 to update the software of vehicle 2 (step S305) and ends the process.

[0087] If the determination result in step S304 is "no", the virtual model construction unit 3c of the backend server 3 uses the configuration information of vehicle 2 stored in the configuration information storage unit 4b to generate a virtual model (step S306).

[0088] After step S306, the impact verification unit 3d of the backend server 3 uses a virtual model to verify the impact of the updated software (step S307).

[0089] After step S307, based on the verification results of the impact of the software update, it is determined whether the software update is effective (step S308).

[0090] If the determination result in step S308 is "yes", proceed to step S305.

[0091] If the determination result in step S308 is "no", the updated software is corrected (step S308), and the process returns to step S306.

[0092] (Summarize)

[0093] In the third embodiment, multiple first electronic control devices 4 send software update requests to a second electronic control device 5. The software update requests are used to request updates to the software included in the partial component information. When the software update request is received from multiple first electronic control devices 4, the second electronic control device 5 sends the software update request and the partial component information together to a backend server 3. The backend server 3 receives the partial component information and the software update request, and if there is an updated version of the software included in the partial component information, the updated software that has been verified using the virtual model is sent to the vehicle 2.

[0094] In the third embodiment configured as described above, similarly to the first embodiment, a virtual model of vehicle 2 can be constructed while reducing the risk of the overall vehicle configuration information being read due to a security attack. Furthermore, the software of the first electronic control device 4 can be updated using updated software that has already been validated using the virtual model of vehicle 2.

[0095] Furthermore, the present invention is not limited to the above embodiments, but includes various modifications. For example, the above embodiments are detailed examples provided for ease of understanding and explanation of the present invention, and are not necessarily limited to having all the described configurations. Additionally, a portion of the configuration of one embodiment may be replaced with the configuration of another embodiment, or the configuration of another embodiment may be added to the configuration of one embodiment. Furthermore, for a portion of the configuration of each embodiment, other configurations may be added, deleted, or replaced. Furthermore, the above-described configurations, functions, processing units, processing means, etc., may also be implemented in hardware, for example, by designing part or all of them using integrated circuits. Additionally, the above-described configurations, functions, etc., may also be implemented in software by having a processor interpret and execute programs that implement their respective functions. The programs, tables, files, and other information implementing the functions may be stored in recording devices such as memory, hard disks, SSDs (Solid State Drives), or recording media such as IC cards, SD cards, DVDs, etc.

[0096] Symbol Explanation

[0097] 1…Vehicle verification system, 2…Vehicle, 3…Back-end server, 3a…Information receiving unit, 3b…Information storage unit, 3c…Virtual model construction unit, 3d…Impact verification unit, 3e…Software update request receiving unit, 4…Local ECU (first electronic control unit), 4a…Terminal change extraction unit, 4b…Information storage unit, 4c…Information sending unit, 4d…Terminal status extraction unit, 4e…Software update request unit, 5…Central ECU (second electronic control unit), 5a…Information receiving unit, 5b…Information sending unit outside the vehicle, 5c…Update request receiving unit, 5d…Update request sending unit outside the vehicle.

Claims

1. A vehicle verification system that evaluates performance of a vehicle, the vehicle verification system characterized by comprising: a back-end server configured outside the vehicle; a plurality of first electronic control devices mounted on the vehicle and storing configuration information of the vehicle in a decentralized manner; and a second electronic control device mounted on the vehicle, receiving partial configuration information that is part of the configuration information of the vehicle from the plurality of first electronic control devices, and transmitting the partial configuration information to the back-end server, the back-end server storing the configuration information of the vehicle, updating the stored configuration information of the vehicle using the partial configuration information received from the second electronic control device, constructing a virtual model of the vehicle using the updated configuration information of the vehicle, and evaluating performance of the vehicle using the virtual model.

2. The vehicle verification system according to claim 1, characterized in that the plurality of first electronic control devices transmit information of a changed portion in the configuration information of the vehicle to the second electronic control device as the partial configuration information.

3. The vehicle verification system according to claim 1, characterized in that the second electronic control device receives degradation information of components connected to the plurality of first electronic control devices from the plurality of first electronic control devices, and transmits the degradation information to the back-end server together with the partial configuration information, the back-end server updates the stored configuration information of the vehicle using the degradation information received from the second electronic control device.

4. The vehicle verification system according to claim 1, characterized in that the plurality of first electronic control devices transmit a software update request to the second electronic control device, the software update request being for requesting update of software included in the partial configuration information, the second electronic control device transmits the software update request to the back-end server together with the partial configuration information in a case where the software update request is received from the plurality of first electronic control devices, the back-end server receives the partial configuration information and the software update request, and in a case where there is an updated version of the software included in the partial configuration information, i.e., updated software, transmits the updated software for which verification is completed using the virtual model to the vehicle. ​ ​ ​ ​ ​ ​ ​ ​ ​ ​

Citation Information

Patent Citations

  • Information processing system, information processing apparatus, information processing method, program, and recording medium

    JP2023013183A