INFORMATION PROCESSING SYSTEM, INFORMATION PROCESSING METHOD AND PROGRAM
The information processing system addresses the challenge of log data detection in fault management by using revealing request messages and policies to selectively expose log data, enhancing data acquisition efficiency and integration across components.
Patent Information
- Application Number
- DE102025110489
- Authority / Receiving Office
- DE · DE
- Patent Type
- Applications
- Current Assignee / Owner
- Priority Date
- 2024-03-22
- Filing Date
- 2025-03-18
- Publication Date
- 2025-09-25
AI Technical Summary
Conventional fault management systems struggle to suitably detect log data items, leading to inefficiencies in data acquisition and integration across components developed by different providers.
An information processing system with a message processor, log storage, and revealing executor that utilize revealing request messages, revealing policy data, and execution identification information to selectively expose log data items within specified ranges, ensuring appropriate data acquisition and integration across components.
The system effectively acquires and integrates log data items, reducing unnecessary processing and resource consumption while maintaining data confidentiality and enabling efficient error analysis and recovery.
Smart Images

Figure 00000000_0000_ABST
Abstract
Description
[Technical field]
[0001] The present disclosure relates to an information processing system and the like that performs processing of log data items. [General state of the art]
[0002] Typically, a fault management system is proposed that obtains log information as log data items from multiple devices. Specifically, when a fault occurs in a specific function of a device, the fault management system obtains log information of a protocol type corresponding to the device type and the function in which the fault occurs. [List of citations][Patent literature]
[0003] [PTL 1] Japanese Patent No. 7069956 [Summary of the invention][Technical problem]
[0004] However, a technical problem with an information processing system that is a conventional fault management system is that the information processing system may not capture log data elements appropriately.
[0005] Therefore, the present disclosure provides an information processing system and the like that can appropriately acquire log data items. [Solution to the problem]
[0006] An information handling system according to one aspect of the present disclosure comprises: a first component; and a second component, wherein the first component comprises: a message handler that sends to the second component a disclosure request message specifying a request range in which disclosure of a log data item is requested, wherein the second component comprises: a log store in which one or more log data items are stored; and a disclosure executor, and wherein the disclosure executor: receives the disclosure request message from the first component; identifies the log data item corresponding to the disclosure request message from the one or more log data items stored in the log store;determines a disclosable range of the identified log data item based on a disclosure policy data item that specifies, as a disclosure policy, a policy regarding the disclosure of the identified log data item; and sends a disclosure log data item to the first component if the identified log data item includes the disclosure log data item to be disclosed in a disclosure range that lies within the determined disclosable range and also within the request range specified in the disclosure request message;
[0007] General or specific aspects of the present disclosure may be implemented by an apparatus, a method, an integrated circuit, a computer program, a computer-readable recording medium such as a compact disc read-only memory (CD-ROM), or any particular combination thereof. [Advantageous effects of the invention]
[0008] The information processing system according to the present disclosure may appropriately capture log data items.
[0009] Additional advantages and advantageous effects of an aspect of the present disclosure will become apparent from the description and drawings. The advantages and / or advantageous effects may be provided by embodiments and features described and illustrated in the description and drawings. However, not all functions are required. [Brief description of the drawings] [ Fig. 1] Fig. 1 is a diagram showing an example of the configuration of a communication system in Embodiment 1. [ Fig. 2] Fig. 2 is a diagram showing an example of the configuration of an information processing system in Embodiment 1. [ Fig. 3] Fig. 3 is a diagram for describing a technical problem to be solved in Embodiment 1. [ Fig. 4] Fig. 4 is a diagram illustrating an example of processing related to a piece of log data performed between two components in Embodiment 1. [ Fig. 5A] Fig. 5A is a diagram illustrating an example of a series of processes performed by a plurality of components in Embodiment 1. [ Fig. 5B] Fig. 5B is a diagram illustrating another example of a series of processes performed by a plurality of components in Embodiment 1. [ Fig. 6] Fig. 6 is a diagram illustrating yet another example of a series of processes performed by a plurality of components in Embodiment 1. [ Fig. 7] Fig. 7 is a diagram illustrating an example of the configurations of a high-ranking component and a plurality of low-ranking components in Embodiment 1. [ Fig. 8] Fig. 8 is a diagram illustrating a specific example of a high-ranking component and a low-ranking component in Embodiment 1. [ Fig. 9] Fig. 9 is a sequence diagram illustrating an example of a processing operation of a high-ranking component and a low-ranking component in Embodiment 1. [ Fig. 10] Fig. 10 is a diagram illustrating an example of response information sent from an ID response unit of a low-ranked component to a high-ranked component in Embodiment 1. [ Fig. 11] Fig. 11 is a diagram illustrating an example of a disclosure request message in Embodiment 1. [ Fig. 12] Fig. 12 is a diagram illustrating an example of a disclosure policy data item in Embodiment 1. [ Fig. 13] Fig. 13 is a diagram for describing an example of a processing operation of a disclosure processor in Embodiment 1. [ Fig. 14] Fig. 14 is a diagram illustrating another example of the disclosure policy data item in Embodiment 1. [ Fig. 15] Fig. 15 is a diagram for describing another example of the processing operation of the disclosure processor in Embodiment 1. [ Fig. 16] Fig. 16 is a sequence diagram illustrating an example of a processing operation of a high-ranking component and a low-ranking component in Embodiment 1. [ Fig. 17] Fig. 17 is a diagram illustrating an example of an update message to be received by a policy updater in Embodiment 1. [ Fig. 18] Fig. 18 is a diagram illustrating an example of an update rule referred to by the policy updater in Embodiment 1. [ Fig. 19] Fig. 19 is a sequence diagram illustrating an example of a processing operation of a policy update source and the policy updater in Embodiment 1. [ Fig. 20] Fig. 20 is a diagram illustrating an example of a series of processes performed by a plurality of components including a middle-class component in Embodiment 2. [ Fig. 21] Fig. 21 is a diagram illustrating an example of the configurations of a high-ranking component and a plurality of middle-ranking components in Embodiment 2. [ Fig. 22] Fig. 22 is a sequence diagram illustrating an example of a processing operation of a high-ranking component, a medium-ranking component, and a low-ranking component in Embodiment 2. [Description of embodiments]
[0010] An information handling system according to a first aspect of the present disclosure comprises: a first component; and a second component, wherein the first component comprises: a message handler that sends to the second component a disclosure request message specifying a request range in which disclosure of a log data item is requested, wherein the second component comprises: a log store in which one or more log data items are stored; and a disclosure executor, and wherein the disclosure executor: receives the disclosure request message from the first component; identifies the log data item corresponding to the disclosure request message from the one or more log data items stored in the log store;determines a disclosable range of the identified log data item based on a disclosure policy data item that specifies, as a disclosure policy, a policy regarding the disclosure of the identified log data item; and sends a disclosure log data item to the first component if the identified log data item includes the disclosure log data item to be disclosed in a disclosure range that lies within the determined disclosable range and also within the request range specified in the disclosure request message. Note that the first component is also referred to as a high-class component, and the second component is also referred to as a medium- or low-class component.
[0011] When the second component receives the disclosure request message from the first component, the second component can send the disclosure protocol data item to the first component. Thus, the disclosure protocol data item is specified in the disclosure scope that is within the disclosable scope based on the disclosure policy data item and also within the requirement scope specified in the disclosure request message. That is, when using the disclosure policy data item, the second component can disclose the disclosure protocol data item in the disclosure scope that is narrower than the requirement scope specified in the disclosure request message.As a result, the second component can disclose the disclosure log data item in the disclosure range according to the need for the log data item, without disclosing a log data item that satisfies the entire requirement range specified in the disclosure request message, and without rejecting the disclosure of a log data item. For example, it is possible to disclose a disclosure log data item in a disclosure range required for debugging. Accordingly, the second component can reduce the risk of technology leakage, and the first component can appropriately acquire log data items.It should be noted that if there is no disclosure scope that is within the disclosable scope based on the disclosure policy data element and is also within the request scope specified in the disclosure request message, the second component does not need to send a disclosure protocol data element and can reject a request with the disclosure request message.
[0012] In the information processing system according to a second aspect of the present disclosure, it is possible for the first component to further comprise: an extractor that extracts first execution identification information from input information for identifying the log data item to be requested, wherein the message handler further generates the disclosure request message including the first execution identification information extracted by the extractor, and the disclosure executor of the second component identifies, as the log data item corresponding to the disclosure request message, a log data item to which second execution identification information corresponding to the first execution identification information has been added from the one or more log data items stored in the log memory.It should be noted that the second aspect may depend on the first aspect. Furthermore, the first execution identification information may be identical to the second execution identification information. If the first execution identification information is linked to the second execution identification information, the first execution identification information may be different from the second execution identification information.
[0013] Thus, by sending the disclosure request message including the first execution identification information, the first component can send the designation of a protocol data item to the second component that is to be requested for disclosure. Using the first execution identification information, the second component can appropriately identify a protocol data item requested by the first component.
[0014] The information processing system according to a third aspect of the present disclosure may include: three or more components including the first component and the second component, wherein the first component further comprises: a list generator that (i) sends the first execution identification information to each of the plurality of components including the second component among the three or more components, and (ii) generates a list indicating the one or more components including the second component based on a response result from one or more components each including a protocol data item to which the second execution identification information has been added according to the first execution identification information, and wherein the message processor: the disclosure request message specifying each of the one or more components as an access destination,that are specified on the list. Please note that the third aspect may depend on the second aspect.
[0015] Accordingly, before transmitting the disclosure request message, a list is generated indicating the one or more components each containing the protocol data item to which the second execution identification information has been added. Each of the one or more components specified on the list is designated as the access destination of the disclosure request message, that is, the destination of the disclosure request message. Thus, it is possible to transmit the disclosure request message to appropriate destinations, thereby making the transmission of the disclosure request message efficient. That is, it is possible to reduce unnecessary processing, such assending a disclosure request message to a component other than components each including a protocol data item to which the second execution identification information has been added, to cause the other component to execute the processing according to the disclosure request message.
[0016] In the information processing system according to a fourth aspect of the present disclosure, it is possible for the second component to further include: a distributor that sends the disclosure request message received from the disclosure executor to another component, excluding the second component, among the one or more components when the one or more components include the other component as an access target. Note that the fourth aspect may depend on the third aspect.
[0017] Accordingly, the disclosure request message can be distributed from the first component to the other component via the second component. As a result, the first component can also receive the disclosure log data item from the other component, thus making it possible to effectively capture log data items.
[0018] In the information processing system according to a fifth aspect of the present disclosure, it is possible for the second component to further comprise: a policy store in which one or more disclosure policy data items are stored, wherein the one or more disclosure log data items correspond to the one or more log data items stored in the log store; and a policy updater that updates the one or more disclosure policy data items, and wherein the one or more disclosure policy data items comprise the disclosure policy data item corresponding to the identified log data item. It should be noted that the fifth aspect may depend on any one of the first to fourth aspects.
[0019] Accordingly, the one or more disclosure policy data items stored in the policy storage are updated, and it is thus possible to appropriately adjust a disclosure range of the disclosure policy data item.
[0020] In the information processing system according to a sixth aspect of the present disclosure, it is possible for the second component to further comprise: a processing executor that obtains the second execution identification information corresponding to a request from the first component each time the request is received from the first component and executes the processing according to the request, and each time the processing corresponding to the request is executed, the processing executor (i) adds the second execution identification information corresponding to the request to a piece of log data indicating a result of the processing corresponding to the request, and (ii) stores the piece of log data to which the second execution identification information has been added in the log memory.It should be noted that the sixth aspect may depend on any of the first through fifth aspects. For example, the processing performed by the processing executor in response to a request from the first component may be processing performed in response to an API (Application Programming Interface) call from the first component. Furthermore, the processing may be performed in response to a request in a form other than an API.
[0021] Accordingly, for each request from the first component, the log storage of the second component stores the log data item to which the second execution identification information corresponding to the request is added. Furthermore, the second execution identification information is information obtained from the first component. For example, the first component executes the processing and requests the second component to perform other processing required for the processing. At this time, the first component may cause the second component to add the second execution identification information sent from the first component to a log data item of the other processing corresponding to the request.Therefore, the first component may use the second execution identification information to identify a log data item of a set of processes executing together with the second component.
[0022] In the information processing system according to a seventh aspect of the present disclosure, it is possible for the second component to further comprise: a protocol encryptor that generates an encrypted disclosure protocol data item by encrypting the identified protocol data item or encrypting the disclosure protocol data item, wherein the disclosure executor sends the disclosure protocol data item by sending the encrypted disclosure protocol data item; and wherein the first component further comprises: a protocol decryptor that decrypts the encrypted disclosure protocol data item when the first component receives the encrypted disclosure protocol data item. Note that the seventh aspect may depend on any one of the first to sixth aspects.
[0023] Accordingly, the disclosure log data item is encrypted by the second component and sent to the first component. Therefore, it is possible to increase the confidentiality of the disclosure policy data item. For example, the disclosure log data item that has been encrypted is sent from the second component to the first component via another component as the encrypted disclosure log data item. In such a case, the content of the encrypted disclosure policy data item can be prevented from being decrypted by the other component.
[0024] In the information processing system according to an eighth aspect of the present disclosure, it is possible for the disclosure policy data item to specify the disclosure scope, which includes a condition clause and an execution clause, wherein the condition clause specifies a condition for disclosing the identified log data item, the execution clause specifies a first execution mode, which is a mode of disclosing the identified log data item, wherein the disclosure request message specifies: one or more request details for disclosing the identified log data item; and a second execution mode, which is a mode for disclosing the identified log data item, and wherein the disclosure executor of the second component further identifies, as the disclosure log data item, a log data item,which (i) is to be disclosed according to at least one request detail that satisfies the condition specified by the condition clause, from the one or more request details, and (ii) in a portion of the second execution mode specified in the disclosure request message, wherein the portion overlaps with the first execution mode specified by the execution clause. It should be noted that the eighth aspect may depend on any of the first to seventh aspects. For example, the request details of the disclosure request message may be a request source of the log data item, a request reason for the log data item, a disclosure target of the log data item, or the like. The second execution mode of the disclosure request message may, for example, be a disclosure class for the request,a disclosure period, or the like. The condition for the disclosure policy data element may be, for example, a request source of the log data element, a disclosure target of the log data element, a request reason for the log data element, or the like. Furthermore, the first execution mode of the disclosure policy data element may be, for example, a disclosure class, a disclosure period, or the like.
[0025] Accordingly, the disclosure protocol data item is disclosed according to the one or more request details that satisfy the condition specified in the disclosure policy data item, among the one or more request details specified in the disclosure request message, and in the portion that is different from the second execution mode specified in the disclosure request message and overlaps with the first execution mode specified by the disclosure protocol data item. Therefore, it is possible to restrict a request with the request details and the second execution mode specified in the disclosure request message according to the condition and the first execution mode specified by the disclosure protocol data item. Therefore, it is possible to appropriately restrict the disclosure of a protocol data item.
[0026] In the information processing system according to a ninth aspect of the present disclosure, when the execution clause specifies application to an external system outside the information processing system instead of the first execution mode, the disclosure executor of the second component may query the external system as to whether or not to disclose the log data item in the second execution mode. Note that the ninth aspect may depend on the eighth aspect.
[0027] Accordingly, if the external system permits disclosure of the log data item in the second execution mode, it is possible to disclose a disclosure log data item in the form of disclosure of the log data item in the second execution mode. Conversely, if the external system does not permit disclosure of the log data item in the second execution mode, it is possible to prohibit disclosure of the log data item in the second execution mode, that is, the disclosure of the disclosure log data item. Therefore, it is possible to appropriately control the disclosure of a log data item with an external system.
[0028] The information processing system according to a tenth aspect of the present disclosure may include: three or more components including the first component and the second component, wherein the first component further comprises: an aggregator that aggregates two or more disclosure log data items and outputs the two or more aggregated disclosure log data items when the aggregator receives the two or more disclosure log data items from two or more components, including the second component, among the three or more components. Note that the tenth aspect may depend on any one of the first to ninth aspects.
[0029] Accordingly, the two or more disclosure log data items are aggregated and output. This makes it possible, for example, to display the disclosure log data items on a display in a clear manner. For example, it is possible to easily analyze a fault or troubleshoot a fault by referring to the disclosure log data items.
[0030] An information processing device according to a first aspect of the present disclosure comprises: an extractor that extracts first execution identification information for identifying a piece of protocol data to be requested from input information; a list generator that (i) sends the first execution identification information to each of a plurality of external devices, and (ii) generates a list indicating the one or more external devices based on a response result from one or more external devices, each including a piece of protocol data to which second execution identification information corresponding to the first execution identification information has been added, and one or more messages among the plurality of external devices;and a message processor that sends a disclosure request message indicating a request range in which disclosure of the log data item is requested to at least one of the one or more external devices specified on the list, the disclosure request message including the first execution identification information extracted by the extractor and specifying the one or more external devices specified on the list as access targets. For example, the information processing device corresponds to the first component described above, and the external device corresponds to the second component described above.
[0031] Accordingly, the information processing device can obtain a protocol data item according to the request range from at least one of the one or more external devices by sending the disclosure request message to the at least one external device. By sending the disclosure request message including the first execution identification information, the information processing device can send the name of a protocol data item to be requested for disclosure to the external device. With the first execution identification information, the external device can appropriately identify a protocol data item requested by the information processing device.Furthermore, before transmitting the disclosure request message, the list indicating the one or more external devices each containing the protocol data item to which the second execution identifier information has been added is generated. Each of the one or more external devices specified on the list is designated as the access destination of the disclosure request message, that is, the destination of the disclosure request message. Thus, it is possible to transmit the disclosure request message to appropriate destinations, thereby making the transmission of the disclosure request message efficient. That is, it is possible to reduce unnecessary processing, such asSending a disclosure request message to an external device other than the external devices each including a piece of protocol data to which the second execution identification information has been added, to cause the other external device to execute the processing according to the disclosure request message. Therefore, it is possible to appropriately acquire protocol data items.
[0032] An information processing device according to a second aspect of the present disclosure comprises: a log storage in which one or more log data items are stored; and a disclosure executor, wherein the disclosure executor: receives, from an external device, a disclosure request message indicating a request range in which disclosure of a log data item is requested; identifies the log data item according to the disclosure request message among the one or more log data items stored in the log storage; determines a discloseable range of the identified log data item based on a disclosure policy data item indicating, as a disclosure policy, a policy for disclosing the identified log data item;and sends a disclosure protocol data item to the external device if the identified protocol data item includes the disclosure protocol data item to be disclosed in a disclosure range that is within the determined disclosure range and also within the request range specified in the disclosure request message. For example, the information processing device corresponds to the second component described above, and the external device corresponds to the first component described above.
[0033] When the information processing device receives the disclosure request message from the external device, the information processing device can send the disclosure protocol data item to the external device. Thus, the disclosure protocol data item is specified in the disclosure range that is within the disclosable range based on the disclosure policy data item and also within the requirement range specified in the disclosure request message. That is, when using the disclosure policy data item, the information processing device can disclose the disclosure protocol data item in the disclosure range that is narrower than the requirement range specified in the disclosure request message.As a result, the information processing device can disclose the disclosure log data item in the disclosure range according to the need for the log data item, without disclosing a log data item that satisfies the entire requirement range specified in the disclosure request message, and without rejecting the disclosure of a log data item. For example, it is possible to disclose a disclosure log data item in a disclosure range required for troubleshooting. Accordingly, the external device can appropriately acquire log data items.It is noted that if there is no disclosure range that is within the disclosable range based on the disclosure policy data item and also within the request range specified in the disclosure request message, the information processing device does not need to send a disclosure protocol data item.
[0034] An information processing device according to a third aspect of the present disclosure comprises: a message handler that sends a first disclosure request message to a first external device, indicating a request range in which disclosure of a log data item is requested; a log storage in which one or more log data items are stored; and a disclosure executor, wherein the disclosure executor: receives a second disclosure request message from a second external device, indicating the request range; identifies the log data item corresponding to the second disclosure request message from the one or more log data items stored in the log storage;determines a disclosable range of the identified log data item based on a disclosure policy data item that specifies, as a disclosure policy, a policy regarding the disclosure of the identified log data item; and sends a disclosure log data item to the second external device if the identified log data item includes the disclosure log data item to be disclosed in a disclosure range that lies within the determined disclosable range and also within the request range specified in the second disclosure request message. For example, the information processing device corresponds to a component that includes both the function of the first component described above and the function of the second component described above.
[0035] Thus, the information processing apparatus can produce the same advantageous effects as the above-described information processing apparatus according to the second aspect and can request a log data item from the first external device in the same manner as the above-described information processing apparatus according to the first aspect.
[0036] In the following, certain exemplary embodiments are described in detail with reference to the accompanying drawings.
[0037] The following embodiments are specific examples of the present disclosure. The numerical values, shapes, materials, elements, arrangement and connection configuration of the elements, steps, the order of steps, etc., described in the following embodiments are merely examples and are not intended to limit the present disclosure.
[0038] Of the elements in the following embodiments, those not described in any of the independent claims, which represent the broadest concept of the present disclosure, are described as optional elements. Furthermore, the diagrams are schematic representations and therefore not necessarily drawn to scale. In the diagrams, the same structural elements are designated by the same reference numerals. (Embodiment 1)
[0039] Fig. 1 is a diagram showing an example of the configuration of a communication system in the present embodiment.
[0040] A communication system 1000 in the present embodiment is, for example, a system that analyzes or corrects a fault. The communication system 1000 includes an information processing system 100, a server 200, and a fault correction device 300.
[0041] The information processing system 100 is, for example, a system provided in the vehicle V. The information processing system 100 includes a plurality of components 1. Each of the components 1 is a unit, device, or apparatus that executes processing corresponding to this component 1 and stores a piece of log data about the executed processing. A piece of log data indicates, for example, an input, an output, and a processing status when the processing is executed.
[0042] The server 200 is connected to the information processing system 100 via a communications network Nt. The server 200 receives one or more log data items from the information processing system 100 via the communications network NT. For example, the server 200 performs processing based on the one or more log data items, such as analyzing an error or troubleshooting a problem with the information processing system 100.
[0043] For example, the troubleshooting device 300 is connected to the information handling system 100 and receives one or more log data items aggregated by the information handling system 100. As with the server 200, the troubleshooting device 300 performs processing based on the one or more log data items, such as analyzing a fault or troubleshooting a fault with respect to the information handling system 100.
[0044] It is noted that the configuration of the communication system 1000 described in Fig. 1 is merely exemplary. The communication system 1000 may have a different configuration as long as the configuration includes the information processing system 100.
[0045] Fig. 2 is a diagram illustrating an example of the configuration of the information processing system 100 in the present embodiment.
[0046] The information processing system 100 includes a communication module 11, in-vehicle infotainment (IVI) 12, a gateway 13, three domain controllers 14 to 16, and six electronic control units (ECUs) 17 to 22 as components 1. The information processing system 100 may include an on-board diagnostics (OBD) 30.
[0047] The majority of the components 1 contained in the information processing system 100, i.e. the communication module 11, the IVI 12, the gateway 13, the three domain controllers 14 to 16 and the six control units 17 to 22, each contain a protocol memory 2.
[0048] The log memory 2 is a recording medium for storing a piece of log data about the processing executed in component 1 and including such a log memory 2. That is, the log memory 2 stores one or more pieces of log data. The log memory 2 is, for example, a hard disk, a random access memory (RAM), a read-only memory (ROM), a semiconductor memory, or the like. Note that this log memory 2 can be either volatile or non-volatile.
[0049] It is noted that the configuration of the information processing system 100 shown in Fig. 2 is merely exemplary. The information processing system 100 may have a different configuration as long as the configuration includes the plurality of components 1. Furthermore, the information processing system 100 may have a virtualized rather than a physical configuration. That is, each of the plurality of components 1 may be configured as a virtual machine. Furthermore, the vehicle V including such an information processing system 100 may be configured as a software-defined vehicle (SDV).
[0050] Fig. 3 is a diagram for describing a technical problem to be solved in the present embodiment.
[0051] For example, in the information processing system 100, the constituent element group a1 including OBD 30 and gateway 13 is developed by vendor A. Furthermore, in the information processing system 100, the constituent element group a2 including three domain controllers 14 to 16 is developed by vendor B. In the information processing system 100, the constituent element group a3 including two ECUs 17 and 18 is developed by vendor C, the constituent element group a4 including two ECUs 19 and 20 is developed by vendor D, and the constituent element group a5 including two ECUs 21 and 22 is developed by vendor E. As can be seen from the above, the information processing system 100 may include a plurality of constituent element groups developed by different vendors.
[0052] In such a case, if each of the components 1 included in the information processing system 100 is configured as a conventional component, it is not easy to send and receive log data items among the plurality of constituent element groups. That is, the conventional component may constantly refuse to send a log data item to another component developed by a vendor other than a vendor of the conventional component. For example, if a component 1 acquires multiple log data items generated when a series of processes are executed by the plurality of constituent element groups for debugging, it may not be possible to acquire the majority of log data items.Alternatively, it may not be possible to capture all log data items because sending all log data items takes a long time, consumes processing resources, or is costly.
[0053] Therefore, in an information handling system 100 in the present embodiment, upon receiving a request for a log data item from another component 1, component 1 sends its log data item to the other component 1 according to a disclosure policy data item.
[0054] Fig. 4 is a diagram illustrating an example of processing related to a piece of protocol data performed between two components 1 in the present embodiment.
[0055] For example, the processing of a log data item d is performed between two components 1 of the plurality of components 1 included in the information processing system 100, that is, between the high-class component 1a and the low-class component 1b. That is, the information processing system 100 in the present embodiment includes the high-class component 1a and the low-class component 1b. The high-class component 1a is also referred to as the first component, and the low-class component 1b is also referred to as the second component.
[0056] Specifically, the high-ranking component 1a sends a disclosure request message m to the low-ranking component 1b. Upon receiving such a disclosure request message m, the low-ranking component 1b refers to the disclosure policy data item p stored by the low-ranking component 1b. The low-ranking component 1b then sends to the high-ranking component 1a a disclosure policy specified by the disclosure policy data item p and the log data item d corresponding to the disclosure request message m. The sent log data item d may be stored in the log storage 2 of the low-ranking component 1b or may be a log data item processed from a log data item stored in the log storage 2.It should be noted that the log data element d is also called the disclosure log data element.
[0057] Upon receiving the log data item d from the low-ranked component 1b, the high-ranked component 1a displays this log data item d on the display 40.
[0058] For example, the display 40 may be a display disposed on an instrument panel of the vehicle V and controlled by the IVI 12, or may be a display of the troubleshooting device 300. By obtaining a plurality of log data items d, the high-class component 1a may aggregate the plurality of log data items d and display the plurality of log data items d in aggregate on the display 40.
[0059] Fig. 5A, Fig. 5B and Fig. 6 are diagrams each illustrating an example of the series of processes performed by the plurality of components 1 in the present embodiment.
[0060] For example, as in Fig. 5A, the gateway 13 calls a function of the domain controller 14 via an application programming interface (API) to execute a process. As a result, the domain controller 14 executes a process corresponding to the called function. The domain controller 14 then sends a result of the process to the gateway 13, and using the result of the process, the gateway 13 can execute another process. Accordingly, the series of processes is executed by the gateway 13 and the domain controller 14. In the example of Fig. 5A, gateway 13 executes the process as high-class component 1a, and domain controller 14 executes the process as low-class component 1b. Domain controller 14 belongs to a layer directly below gateway 13.
[0061] As in Fig. As illustrated in Figure 5B, gateway 13 can call a function of each of the plurality of domain controllers 14, 15, and 16 via an API. In this case, domain controllers 14, 15, and 16 belong to the same tier directly under gateway 13.
[0062] As in Fig. 6 illustrates, in order to execute a process, domain controller 14 calls a function of domain controller 15 via an API. As a result, domain controller 15 executes a process corresponding to the called function. To execute a process, domain controller 15 can call a function of domain controller 14 via an API. That is, the call to an API can be executed bidirectionally. Accordingly, the series of processes is executed by domain controllers 14 and 15. In the example of Fig. 6, each of the domain controllers 14 and 15 executes the process as high-class component 1a and low-class component 1b.
[0063] In the present embodiment, when processing is performed by each of the components 1, a piece of log data corresponding to a result of the processing is stored in the log memory 2 of that component 1. Furthermore, when executing the above-mentioned process series, each of the plurality of components 1 that executes the process series stores a piece of log data relating to a process executed by that component 1 in the log memory 2. At this time, the plurality of components 1 store the log data items in the log memories 2 after adding execution identification items associated with each other among the various components 1 to the log data items. For example, the execution identification information may be information that is the same or identical among the plurality of components 1.
[0064] Fig. 7 is a diagram illustrating an example of the configurations of the high-ranking component 1a and a plurality of low-ranking components 1b in the present embodiment.
[0065] The high-class component 1a includes the protocol storage 2, a disclosure requester 110, a processing executor 131a, an ID generator 132, an ID adder 133, and a protocol decryptor 142.
[0066] The ID generator 132 generates the above-mentioned execution identification information and outputs the execution identification information to the ID adder 133. The ID adder 133 receives the execution identification information from the ID generator 132 and outputs the execution identification information to the processing executor 131a. In addition, upon receiving a piece of log data from the processing executor 131a, the ID adder 133 adds the execution identification information generated by the ID generator 132 to the log data. The ID adder 133 then stores the log data to which the execution identification information has been added in the log memory 2. Note that the execution identification information generated by the ID generator 132 and added to the log data by the ID adder 133 is also referred to as second execution identification information.
[0067] The processing executor 131a executes a process included in the above-mentioned series of processes and calls a function of the low-ranking component 1b via an API. At this time, the processing executor 131a obtains the execution identification information generated by the ID generator 132 via the ID adder 133 and outputs the execution identification information to the low-ranking component 1b. Furthermore, the processing executor 131a executes a process based on the result of the process after receiving a result of a process by the function as a response from the low-ranking component 1b through the call via the API. Such a call through an API can be performed for a plurality of low-ranking components 1b. Accordingly, the series of processes is executed.The processing executor 131a then outputs a log data item of the process executed by the processing executor 131a to the ID adder 133.
[0068] Disclosure requester 110 requests low-level component 1b to disclose a log data item. Disclosure requester 110 includes ID extractor 111, list generator 112, message processor 113, and log aggregator 114.
[0069] The ID extractor 111 is an extractor that receives input information from the fault manager 302 and extracts execution identification information from the input information. Note that the execution identification information extracted by the ID extractor 111 is also referred to as first execution identification information when distinguishing the execution identification information from the second execution identification information generated by the ID generator 132, as mentioned above. The first execution identification information is information for identifying a piece of log data to be requested.For example, the error recovery device 300 includes the error identifier 301, which designates an error according to a user input, and the error manager 302, which outputs, as input information, information about the designated error through the error identifier 301 to the high-level component 1a. The input information includes execution identification information related to the specified error. The ID extractor 111 extracts the execution identification information and outputs the execution identification information to the list generator 112.
[0070] The list generator 112 sends the execution identification information (i.e., first execution identification information) to a plurality of low-ranked components 1b included in the information processing system 100. Accordingly, the list generator 112 queries each of these components 1 as to whether these components 1 store a log data item to which the execution identification information has been added. That is, the list generator 112 queries whether the component 1 stores a log data item to which the second execution identification information corresponding to the first execution identification information extracted by the ID extractor 111 has been added. For example, the second execution identification information is identical to the first execution identification information.It should be noted that the second execution identification information may differ from the first execution identification information, as long as the mapping between the second execution identification information and the first execution identification information is defined. The list generator 112 then generates a list indicating one or more low-ranked components 1b that respond by storing the protocol data item and outputs the list to the message processor 113.
[0071] That is, in the present embodiment, the information processing system 100 includes three or more components 1, including the high-ranking component 1a and the low-ranking component 1b. The list generator 112 sends the execution identification information to each of a plurality of components 1, including the low-ranking component 1b. Next, the list generator 112 generates a list indicating the one or more components 1 based on a response result from one or more components 1, each including a piece of log data to which the execution identification information has been added, among the plurality of components 1.In other words, the list generator 112 sends the first execution identification information to each of the plurality of components 1 including the low-ranked component 1b, and generates a list indicating one or more components 1 including the component 1b among the plurality of components 1 based on a response result from one or more components 1 each including a piece of log data to which the second execution identification information corresponding to the first execution identification information has been added.
[0072] The message processor 113 generates the disclosure request message m indicating a request range in which disclosure of a piece of protocol data is requested, and sends the disclosure request message m to the low-ranked components 1b. Specifically, after receiving the generated list from the list generator 112, the message processor 113 generates the above-mentioned disclosure request message m indicating the request range in which disclosure of the piece of protocol data is requested, and sends the disclosure request message m to the low-ranked components 1b in the list. That is, the message processor 113 generates the disclosure request message m including the execution identification information (i.e., the first execution identification information) extracted by the ID extractor 111.In addition, the message processor 113 sends the disclosure request message m specifying as the access target each of one or more components 1 specified on the list.
[0073] Upon receiving protocol data elements d corresponding to this disclosure request message m from one or more low-class components 1b, the message processor 113 outputs these protocol data elements d to the protocol aggregator 114. Note that protocol data elements d sent by low-class components 1b responding to the disclosure request message m are protocol data elements that determine such low-class components 1b as disclosed and are also referred to as disclosure protocol data elements.
[0074] The log aggregator 114 receives one or more log data items d from the message processor 113 and aggregates them. If one or more log data items d of such one or more log data items d have been encrypted, the log aggregator 114 instructs the log decryptor 142 to decrypt these encrypted log data items d and receives decrypted log data items d from the log decryptor 142. In the present embodiment, when the log aggregator 114 receives log data items d from two or more components 1, including the low-ranked component 1b, the log aggregator 114 aggregates such two or more log data items d and outputs aggregated two or more log data items d, as seen above. For example, the log aggregator 114 aggregates such log data items d and outputs aggregated log data items d to the display 40.When a log data item to which the execution identification information extracted by the ID extractor 111 has been added is stored in the log storage 2 of the high-ranking component 1a, the log aggregator 114 obtains the log data item from the log storage 2. That is, when a log data item to which the second execution identification information corresponding to the first execution identification information extracted by the ID extractor 111 has been added is stored in the log storage 2 of the high-ranking component 1a, the log aggregator 114 obtains the log data item from the log storage 2.The log aggregator 114 then aggregates the log data item obtained from the log memory 2 together with one or more log data items d obtained from the message processor 113 and outputs a plurality of log data items in aggregate to the display 40.
[0075] The protocol decryptor 142 receives encrypted protocol data items d from the protocol aggregator 114, decrypts such protocol data items d, and outputs decrypted protocol data items d to the protocol aggregator 114. That is, when the high-class component 1a receives encrypted disclosure protocol data items, ie, encrypted protocol data items d, the protocol decryptor 142 decrypts the encrypted disclosure protocol data items.
[0076] The low-class component 1b includes the log store 2, the disclosure executor 120, the processing executor 131b, the log encryptor 141, and the policy updater 150.
[0077] The processing executor 131b executes a process corresponding to the function in response to a call to a function through an API from the high-ranking component 1a, and forwards, for example, a result of the process to the high-ranking component 1a. The processing executor 131b then stores a piece of log data of the process executed by the processing executor 131b in the log storage 2 of the low-ranking component 1b. Here, when the call is executed through an API, the processing executor 131b obtains execution identification information (i.e., second execution identification information) from the high-ranking component 1a along with the call. Therefore, the processing executor 131b adds the execution identification information from the high-ranking component 1a to the piece of log data and stores the piece of log data in the log storage 2.
[0078] If the execution identification information from the high-ranking component 1a includes a time at which the high-ranking component 1a executes a process, the processing executor 131b may replace the time with a time at which the processing executor 131b executes the process. Alternatively, the processing executor 131b may add to the log data item not only the execution identification information (ie, the second execution identification information) but also another type of identification information unique to the low-ranking component 1b.
[0079] As apparent from the above, for each request through an API from the high-level component 1a, the processing executor 131b obtains second execution identification information corresponding to the request from the high-level component 1a and executes a process according to the request. Each time the process corresponding to the request is executed, the processing executor 131b adds the second execution identification information corresponding to the request to a log data item indicating a result of the process corresponding to the request. The processing executor 131b further stores, in the log storage 2 of the low-level component 1b, the log data item to which the second execution identification information has been added.
[0080] The protocol encryptor 141 encrypts some or all of one or more protocol data items stored in the protocol storage 2. For example, if one or more protocol data items corresponding to the disclosure request message m are identified by the disclosure processor 122, the protocol encryptor 141 encrypts the identified one or more protocol data items stored in the protocol storage 2. Furthermore, the protocol encryptor 141 encrypts disclosure protocol data items corresponding to the identified one or more protocol data items. Accordingly, the protocol encryptor 141 generates the encrypted disclosure protocol data items.Note that the protocol encryptor 141 may encrypt the disclosure protocol data item using an encryption key stored jointly with Component 1, which is a requestor of the protocol data item (i.e., high-level Component 1a). Note that shared key cryptography or the like may be used to encrypt the disclosure protocol data item so that only a specific Component 1 can perform decryption, or to prevent spoofing.
[0081] The disclosure executor 120 includes an ID response unit 121, the disclosure processor 122, and the policy storage 123. Upon receiving a query from the list generator 112 of the high-ranking component 1a, the ID response unit 121 responds to the query. That is, the ID response unit 121 receives execution identification information from the list generator 112 and receives a query as to whether a log data item to which the execution identification information has been added is stored. In other words, the ID response unit 121 receives first execution identification information from the list generator 112 and receives a query as to whether a log data item to which second execution identification information corresponding to the first execution identification information has been added is stored.The ID response unit 121 then searches the log storage 2 for the log data item to which the execution identification information (ie, the second execution identification information) has been added. If the log data item is present in the log storage 2, the ID response unit 121 responds to the query by sending component identification information for identifying the low-ranked component 1b, including the ID response unit 121, to the list generator 112.
[0082] The policy storage 123 is a recording medium on which the disclosure policy data item p containing a policy regarding the disclosure of a log data item stored in the log storage 2 of the low-class component 1b is stored. That is, the policy storage 123 stores one or more disclosure policy data items p corresponding to one or more log data items stored in the log storage 2. When one or more log data items corresponding to the disclosure request message m are identified by the disclosure processor 122, such one or more disclosure policy data items p include one or more disclosure policy data items p corresponding to the identified log data items. The policy storage 123 is, for example, a hard disk drive, a RAM, a ROM, or a semiconductor memory, or the like.It should be noted that the policy memory 123 may be either volatile or non-volatile.
[0083] When the disclosure processor 122 receives the disclosure request message m from the message processor 113 of the high-ranking component 1a, the disclosure processor 122 searches the log storage 2 for a log data item requested with such a disclosure request message m. That is, the disclosure processor 122 receives the disclosure request message m from the high-ranking component 1a and identifies a log data item corresponding to this disclosure request message m from one or more log data items stored in the log storage 2 of the low-ranking component 1b.Specifically, the disclosure processor 122 identifies, as the log data item corresponding to the disclosure request message m, a log data item to which second execution identification information corresponding to the first execution identification information included in the disclosure request message m has been added from one of the one or more log data items stored in the log storage 2 of the low-class component 1b.
[0084] The disclosure processor 122 then obtains the disclosure policy data element p corresponding to the identified log data element from the policy store 123. The disclosure processor 122 then determines a disclosable scope of the log data element based on the disclosure policy data element p. That is, the disclosure processor 122 determines the disclosable scope of the identified log data element based on the disclosure policy data element p, which, as a disclosure policy, specifies a policy regarding the disclosure of the identified log data element.Furthermore, the disclosure processor 122 sends a disclosure protocol data item to the high-class component 1a if the identified protocol data item includes the disclosure protocol data item to be disclosed in a disclosure protocol range that is within the specific disclosure protocol and also within a request range specified in the disclosure request message m. The disclosure processor 122 may use some or all of the identified protocol data items, as mentioned above, as disclosure protocol data items and may generate disclosure protocol data items from the protocol data items. If a disclosure protocol data item is encrypted by the protocol encryptor 141, the disclosure processor 122 sends the disclosure protocol data item by sending an encrypted disclosure protocol data item.
[0085] The policy updater 150 updates one or more disclosure policy data items p stored in the policy store 123.
[0086] As mentioned above, the present embodiment uses types of execution identification information such as the first execution identification information and the second execution identification information. Accordingly, it is possible to restrict components 1 and log data items related to a fault that the debugging device 300 focuses on. Note that the execution identification information may consist of a sequence ID or a combination of the process name and time range.
[0087] Fig. Figure 8 is a diagram showing a specific example of the high-ranking component 1a and the low-ranking component 1b.
[0088] For example, the high-class component 1a is component 1 named "Domain Controller 001." The low-class component 1b is component 1 named "Door Sensor ECU 001."
[0089] For example, log storage 2 of the low-class component 1b stores log data items, including two types of disclosure log data items. These two types of disclosure log data items are a "low" disclosure class disclosure log data item and a "high" disclosure class disclosure log data item. These disclosure log data items each contain the same sequence number "240102122244" as execution identification information and each contain the same date and time "02 / 01 / 2024 02:24:02.383." Meanwhile, the "high" disclosure class disclosure log data item contains a key and value that each contain more detailed information than the "low" disclosure class disclosure log data item.It should be noted that the disclosure log data element of the "low" disclosure class can be generated from the disclosure log data element of the "high" disclosure class.
[0090] Fig. Figure 9 is a sequence diagram showing an example of a processing operation of the high-class component 1a and the low-class component 1b.
[0091] First, when starting debugging, the ID extractor 111 of the high-level component 1a designates a set of processes as a debugging target (step S1). The debugging target may be designated by the debugging device 300. Furthermore, the debugging target may be a set of processes that have experienced an error, a set of processes that respond slowly, a set of processes that fail, a set of processes that have experienced an abnormal event, or the like. Alternatively, a specific debugging target may be designated by a person performing debugging who simply wants to check whether the set of processes is running normally, even if the set of processes is no different from a normal set of processes.ID extractor 111 also extracts execution identification information about the specific debug target from the above-mentioned input information (step S2).
[0092] The list generator 112 then sends the execution identification information to the low-ranking component 1b to query this low-ranking component 1b (step S3). When the ID response unit 121 receives the execution identification information from the high-ranking component 1a, the ID response unit 121 checks whether a piece of log data to which the execution identification information has been added is stored in the log memory 2 of the low-ranking component 1b (step S4). That is, the ID response unit 121 checks whether a piece of log data stored in the log memory 2 contains the execution identification information.
[0093] In other words, the ID response unit 121 searches the log storage 2 for a log data item to which the execution identification information has been added. If log data items are stored in a log file, the ID response unit 121 searches the log file for the log data item to which the execution identification information has been added.
[0094] Here, the ID response unit 121 checks whether a piece of log data contains the execution identification information. At this time, the ID response unit 121 sends to the high-ranking component 1a the response information k1 containing a result of the check and component identification information, that is, identification information of the low-ranking component 1b including this ID response unit 121 (i.e., identification information of its own component) (step S5). Note that the result of the check indicates that the piece of log data identified with the component identification information in the low-ranking component 1b contains the above-mentioned execution identification information, that is, indicates that this identified low-ranking component 1b contains the piece of log data including the execution identification information.
[0095] The list generator 112 receives the response information k1 from the low-ranked component 1b. The list generator 112 then generates the above-mentioned list. The list contains the component identification information included in the received response information k1. Note that when the list generator 112 receives response information k1 from each of a plurality of low-ranked components 1b, the list indicates a plurality of component identification information.
[0096] The message processor 113 then adds to the access targets a low-class component 1b identified with one or more component identification information items specified on the list (step S6). That is, the message processor 113 adds to the access targets each of one or more low-class components 1b corresponding to the execution identification information extracted in step S2. The access targets are targets of the disclosure request message m. The message processor 113 then sends the disclosure request message m to the access targets (step S7).
[0097] The disclosure processor 122 of the low-ranking component 1b receives the disclosure request message m from the high-ranking component 1a (step S8). The disclosure processor 122 further checks whether the component identification information on the low-ranking component 1b, including this disclosure processor 122, is set to the access targets of this disclosure request message m. If the component identification information is set, the disclosure processor 122 identifies a protocol data item corresponding to this disclosure request message m (step S9). Furthermore, the disclosure processor 122 reads a disclosure policy data item p corresponding to the identified protocol data item from the policy storage 123 and determines a disclosable range indicated by the disclosure policy data item p (step S10).Subsequently, the disclosure processor 122 identifies a disclosure log data item based on a request range of the disclosure request message m and the disclosable range (step S11) and sends the disclosure log data item to the high-ranking component 1a (step S12). As a result, the high-ranking component 1a receives the disclosure log data item from the low-ranking component 1b (step S13). Accordingly, the disclosure log data item is disclosed.
[0098] That is, the disclosure log data item is displayed from the high-ranking component 1a on the above-mentioned display 40. When the high-ranking component 1a receives a plurality of disclosure log data items from a plurality of low-ranking components 1b, the plurality of disclosure log data items are displayed on the display 40. At this time, the plurality of disclosure log data items are displayed in an integrated or aggregated manner. For example, the plurality of disclosure log data items may be displayed arranged in a time order in a table format. The plurality of disclosure log data items may be output so that they can be attached to an email, or they may be output in a file format.The display of the received disclosure log data item is not limited to the display of a primary log data item and may be the display of a result or the like obtained by analyzing the log data item.
[0099] Fig. 10 is a diagram showing an example of response information k1 sent from the ID response unit 121 of the low-ranked component 1b to the high-ranked component 1a.
[0100] In step S5 in Fig. 9 sends the ID response unit 121 sends, for example, the Fig. 10 to the high-ranking component 1a. The response information k1 indicates component identification information for identifying the low-ranking component 1b, including the ID response unit 121, and indicates the presence or absence of data. The presence or absence of data is the result of the above-mentioned check. Specifically, the presence or absence of data means whether a piece of log data, to which second execution identification information corresponding to the first execution identification information has been added, is stored in the log storage 2 of the low-ranking component 1b. Note that the "presence" of the presence or absence of data means that the piece of log data is stored.
[0101] Fig. 11 is a diagram showing an example of a disclosure request message m.
[0102] The disclosure request message m includes the name of an access target, execution identification information, first request information m1, and second request information m2. The execution identification information is first execution identification information. In a concrete example, the name of the access target is the name of component 1 "Door Sensor ECU 001," and the execution identification information (e.g., sequence ID) is "240102122244." The first request information m1 and the second request information m2 each indicate a request range in which disclosure of a protocol data item is requested.
[0103] When a log data item corresponding to the disclosure request message m is identified, the first request information m1 specifies one or more request details for disclosing the identified log data item. The one or more request details include, for example, a requester, a reason for the request, and a disclosure target. The requester is the name of a company, device, person, or the like requesting disclosure. A specific example of the request source is "XXX Co." The reason for the request is a reason for requesting disclosure. A specific example of the reason for the request is "troubleshooting." The disclosure target is a disclosure target of the log data item. For example, the disclosure target is component 1. A specific example of the disclosure target is component 1 named "Domain Controller 001."
[0104] The second request information m2 indicates a second execution mode, which is a mode requested for the disclosure of the identified log data item. The second execution mode includes, for example, a request disclosure class and a disclosure period. The request disclosure class is a class or a disclosure class requested for an amount of information contained in the log data item to be disclosed. The request disclosure class "high" means that the requested amount of information is large, and the request disclosure class "low" means that the requested amount of information is smaller than the amount of information referred to by the request disclosure class "high."Note that the disclosure requirement class can be viewed as the abstraction class requested for the log data item to be disclosed. In this case, a "high" disclosure requirement class means that detailed and concrete disclosure of a log data item is requested, and a "low" disclosure requirement class means that a more abstract or simplified log data item is requested than the log data item with the "high" disclosure requirement class. The disclosure period is the disclosure period requested for the log data item. In the example of . Fig. 11, the second requirement information m2 indicates the requirement disclosure class “high” and the disclosure period “48 h”.
[0105] It is noted that the disclosure request message m in Fig. 11 is sent, for example, from the high-class component 1a to the low-class component 1b, as in Fig. 8 illustrates.
[0106] Fig. Figure 12 is a diagram illustrating an example of a disclosure policy data element p.
[0107] For example, the policy storage 123 stores a disclosure policy data item p indicating a first disclosure policy as shown in (a) in Fig. 12, and stores the disclosure policy data item p indicating a second disclosure policy as shown in (b) in Fig. 12. As apparent from the above, the disclosure policy data item p specifies disclosure policies. Note that the policy storage 123 may store another disclosure policy data item p that specifies a different disclosure policy than the first and second disclosure policies.
[0108] The disclosure policy data element p contains policy identification information for identifying a disclosure policy and contains a disclosable range. The disclosable range includes a condition clause and an execution clause. That is, the disclosure policy data element p in the present embodiment specifies the disclosable range, which includes the condition clause and the execution clause. When a protocol data element corresponding to the disclosure request message m is identified, the condition clause specifies a condition for disclosing the identified protocol data element. For example, the condition clause specifies a requester, a disclosure target, a reason for a request, and the like as conditions. The execution clause specifies a first execution mode, which is a mode of disclosing the identified protocol data element.For example, the execution clause specifies a disclosure class, a disclosure period, and the like as the first execution mode. The disclosure class of the execution clause is a class permitted for a set of information contained in the log data item. The disclosure period of the execution clause is a disclosure period permitted for the log data item.
[0109] In a concrete example, as in (a) in Fig. As shown in Figure 12, the disclosure policy data element p contains the policy identification information "Policy 001." The condition clause of this disclosure policy data element p specifies the requester "XXX Co., YYY Co." as the condition, the disclosure target "Domain Controller 001," and the reason for a request as "Troubleshooting." The execution clause of this disclosure policy data element p specifies the disclosure class "High" and the disclosure period "24 hours" as the first execution mode.
[0110] It is noted that such disclosure policy data items p are linked in advance to a log data item stored in the log storage 2 of the low-class component 1b.
[0111] The disclosure processor 122 of the disclosure executor 120 identifies, as a disclosure protocol data item, a protocol data item that is to be disclosed (i) according to one or more request details that satisfy a condition specified in the condition clause among the one or more request details specified in the disclosure request message, and (ii) in a portion that is of a second execution mode specified by the request information m2 in the disclosure request message m and overlaps with the first execution mode specified by the execution clause.That is, a disclosure range of the protocol data item to be disclosed is restricted to a range within which the requirement range specified in the disclosure request message m overlaps with the disclosable range specified by the disclosure policy data item p. The one or more requirement details specified in the disclosure request message m are restricted to the condition in the disclosure policy data item p, and the second execution mode in the disclosure request message m is restricted to the first execution mode in the disclosure policy data item p.
[0112] Fig. Figure 13 is a diagram describing an example of a processing operation of a Disclosure Processor 122.
[0113] As mentioned above, upon receiving the disclosure request message m, the disclosure processor 122 identifies a protocol data item corresponding to this disclosure request message m. The disclosure processor 122 then obtains the disclosure policy data item p corresponding to the identified protocol data item from the policy store 123. For example, the disclosure processor 122 obtains the disclosure policy data item p as shown in (a) in Fig. 12. Based on this disclosure policy data element p, the disclosure processor 122 determines a disclosable portion of the protocol data element, e.g., the condition clause and the execution clause in (a) in Fig. 12. The disclosure processor 122 also determines a disclosure scope that is within the disclosable scope defined by the condition clause and the execution clause and also within the request scope specified in disclosure request message m
[0114] In particular, the disclosure processor 122 determines whether one or more request details specified by the request information m1 in the disclosure request message m satisfy a condition specified by the condition clause in the disclosure policy data element p. In the example in Fig. 11, the request information m1 specifies as the one or more request details the requestor “XXX Co.”, the reason for a request “Troubleshooting,” and the disclosure target “Domain Controller 001.” In the case of the one or more request details specified in (a) Fig. In the example shown in Figure 12, the condition clause specifies, as a condition, the requester "XXX Co., YYY Co.," the disclosure target "Domain Controller 001," and the reason for a request "Troubleshooting." In this case, the requester, the disclosure target, and the reason for a request specified in the request information m1 are included in the requester, the disclosure target, and the reason for a request specified in the condition clause, respectively. Therefore, the disclosure processor 122 determines that all the request details specified in the request information m1 in the disclosure request message m satisfy the condition specified in the condition clause in the disclosure policy data element p. In this case, the disclosure processor 122 determines the disclosure target "Domain Controller 001" specified by the request information m1 in the disclosure request message m as part of the disclosure scope.
[0115] Next, the disclosure processor 122 identifies a portion of a second execution mode specified by the request information m2 in the disclosure request message m and overlapping with a first execution mode specified by the execution clause in the disclosure policy data element p. Specifically, the disclosure processor 122 determines either a request disclosure class specified in the request information m2 or a disclosure class specified in the execution clause, whichever is lower. The disclosure processor 122 determines either a disclosure period specified in the request information m2 or a disclosure period specified in the execution clause, whichever is shorter. In the example of Fig. 11, the requirement information m2 indicates the requirement disclosure class “high” and the disclosure period “48 h”. In the example in (a) in Fig. 12, the execution clause specifies the disclosure class "high" and the disclosure period "24 hours." In this case, the disclosure processor 122 determines the disclosure class "high" and the disclosure period "24 hours" as part of the disclosure scope.
[0116] That is, the disclosure processor 122 determines the disclosure target "domain controller 001" specified by the request information m1 in the disclosure request message m, and the disclosure class "high" and the disclosure period "24 hours" as the disclosure scope of the log data item. In other words, a disclosure log data item to be disclosed within the disclosure scope is identified.
[0117] It should be noted that in the above example, the value in (a) in Fig. 12 is obtained. In contrast, in the case where the disclosure policy data item p shown in (b) is obtained in Fig. 12, the disclosure target is not determined in the disclosure area. That is, the disclosure target and the reason for a request contained in the request information m1 in the disclosure request message m, as shown in Fig. 11, in a disclosure objective and a reason for a requirement under a conditional clause set out in (b) in Fig. 12 are not included. Therefore, the disclosure processor 122 determines that the request details specified in the request information m1 in the disclosure request message m do not satisfy the condition specified in the condition clause in the disclosure policy data item p. In this case, the disclosure processor 122 does not recognize the disclosure target "Domain Controller 001" specified by the request information m1 in the disclosure request message m as part of the disclosure scope. As a result, no disclosure scope is determined, and the transmission of a disclosure policy data item is prohibited.
[0118] In the above example, the disclosure class specified in the execution clause of the disclosure policy data element p is, as in (a) in Fig. 12, high. If, however, the disclosure class is "low," the disclosure processor 122 determines the "low" disclosure class as part of the disclosure range.
[0119] In the present embodiment, the first execution mode and the second execution mode are each defined with two parameters such as the disclosure class and the disclosure period. However, the first execution mode and the second execution mode may each be defined with a different parameter. Alternatively, a different parameter may be added as a parameter to define each of the first execution mode and the second execution mode. When such a parameter is added, the disclosure range of the disclosure log data item can also be determined based on the magnitude of the parameter, as is the case with the disclosure class and the disclosure period. That is, the disclosure range can be determined based on either the parameter in the first execution mode or the parameter in the second execution mode, whichever is smaller or shorter.Alternatively, methods for determining the disclosure scope based on a parameter may be enabled according to the one or more request details indicated by the request information m1 in the disclosure request message m. For example, the disclosure request information m1 in the disclosure request message m indicates the requester "XXX Co.", which is selected from the requester "XXX Co., YYYY Co" indicated in the disclosure policy data item p, as shown in (a) in FIG. Fig. 12. In such a case, the disclosure processor 122 determines the disclosure range based on one of the parameters, whichever is smaller or shorter, as in the above-mentioned case. In contrast, the request information m1 in the disclosure request message m indicates the requester "YYY Co.", which is selected from the requester "XXX Co., YYY Co" specified in the disclosure policy data element p, as in (a) in Fig. 12. In such a case, unlike the above-mentioned case, the disclosure processor 122 may determine the disclosure scope, for example, based on a parameter included in the execution clause in the disclosure policy data item p. In the case of changing the methods for determining the disclosure scope based on the requester or the like specified in the disclosure request message m, a scheme such as public key cryptography may be incorporated for at least one of the disclosure request message m or the disclosure policy data item p to prevent a forged requester.
[0120] Fig. Figure 14 is a diagram illustrating another example of a disclosure policy data element p.
[0121] The disclosure class contained in the execution clause in the disclosure policy data element p can be “Application Required”, as in the example in Fig. 14. If the disclosure class "Application Required" is specified in the execution clause in disclosure policy data element p, disclosure processor 122 queries an external system whether the request disclosure class specified in request information m2 should be used. The external system may be a server 200 or, for example, a system managed by a development provider of the low-class component 1b, including this disclosure processor 122.
[0122] That is, in the case where the execution clause in the disclosure policy data item p specifies an application to the external system outside the information processing system 100 instead of the first execution mode, the disclosure processor 122 queries the external system whether the protocol data item should be disclosed in the second execution mode (e.g., the request disclosure class) specified in the request information m2.
[0123] Fig. Figure 15 is a diagram describing another example of a Disclosure Processor 122 processing operation.
[0124] As mentioned above, the disclosure processor 122 determines either the request disclosure class specified in the request information m2 or the disclosure class specified in the execution clause, whichever is lower. If the disclosure class specified in the execution clause is "application required," the disclosure class "application required" is defined as lower than the disclosure class "low," as defined in Fig. 15. Therefore, in this case, the disclosure processor 122 determines that the disclosure class is "application required," regardless of whether the request disclosure class is "high" or "low." As a result, the disclosure processor 122 applies the request disclosure class specified in the request information m2 to the external system. In other words, the disclosure processor 122 queries the external system whether to adopt the request disclosure class.
[0125] Alternatively, the disclosure processor 122 may query the external system for the disclosure class specified in the execution clause. Upon receiving the disclosure class specified in the execution clause as a response from an external system, the disclosure processor 122 determines, in this case, either the received disclosure class or the request disclosure class specified in the request information m2, whichever is lower, as the disclosure class that determines the disclosure scope of the protocol data item.
[0126] Fig. Figure 16 is a sequence diagram showing another example of the processing operation of the high-class component 1a and the low-class component 1b. It should be noted that Fig. 16 is a sequence diagram of the case where the disclosure class “Application Required” is specified in the execution clause in the disclosure policy data element p.
[0127] As in the example shown in Fig. As shown in Figure 9, the high-ranking component 1a and the low-ranking component 1b perform the processing of steps S1 to S10. Here, the disclosure class specified in the execution clause included in the disclosable range determined in step S10 is "Application Required." As a result, the disclosure processor 122 of the low-ranking component 1b applies the request disclosure class specified in the disclosure request message m to the external system (step S11a). Specifically, the disclosure processor 122 notifies the external system of the request disclosure class. Alternatively, the disclosure processor 122 notifies the external system of the combination of the request disclosure class and the name or component identification information of the high-ranking component 1a.
[0128] The external system receives the application for the request disclosure class (step S21). The external system then determines whether to use the request disclosure class and notifies the low-ranked component 1b of the determination result (step S22). The disclosure processor 122 of the low-ranked component 1b receives notification of the above-mentioned determination result from the external system. If the determination result indicates that the request disclosure class is used, that is, the application is accepted, the disclosure processor 122 identifies a piece of protocol data to be disclosed within the disclosure range specified by the request disclosure class as a disclosure protocol data item. For example, if the request disclosure class is "high," a disclosure protocol data item of the "high" disclosure class is identified.The disclosure processor 122 then sends the disclosure protocol data item to the high-class component 1a (step S12). The high-class component 1a receives the disclosure protocol data item from the low-class component 1b (step S13). If the external system determines in step S22 that the request disclosure class is not used, i.e., the application is not accepted, the disclosure processor 122 does not send any disclosure protocol data item in step S12.
[0129] In the above example, the result of the determination in step S22 is reported by the external system to the low-class component 1b. However, the result of the determination may be reported to the high-class component 1a instead of the low-class component 1b. In this case, in step S11a, the low-class component 1b may primarily respond to the high-class component 1a. In a specific example, in step S11a, the low-class component 1b sends the application of the request disclosure class to the external system and additionally sends the disclosure protocol data item corresponding to the request disclosure class to the external system. In step S22, the external system determines to permit the application and then sends a result of the determination and the disclosure protocol data item to the high-class component 1a rather than to the low-class component 1b.
[0130] In the above example, the request disclosure class is applied in the second execution mode. However, not only the request disclosure class but also the disclosure period can be applied to the external system.
[0131] Fig. 17 is a diagram illustrating an example of an update message to be received by the policy updater 150.
[0132] For example, a policy update source sends an update message p1 which is Fig. 17, to the policy updater 150. The policy update source may, for example, be component 1 included in information handling system 100, troubleshooting device 300, server 200, or the like. The policy updater 150 receives such an update message p1.
[0133] For example, the update message p1 includes update source identification information, policy identification information, modification data, an issue time, and a date and time of expiration. The update source identification information is identification information for identifying the policy update source. A specific example of the update source identification information is "XXX Server." The policy identification information is identification information for identifying the disclosure policy data item p that needs to be updated according to the update message p1. A specific example of the policy identification information is "Policy 001." The modification data is new data that is modified or updated in the disclosure policy data item p.As a specific example, the change data is a new disclosure target "in-vehicle infotainment (IVI)" or the entire new disclosure protocol data item p. The output time is a time at which the update message p1 is output or generated, or a time at which the disclosure policy data item p is updated and output according to the update message p1. As a specific example, the output time is "02 / 02 / 2024 12:00:00." The expiration date and time are the expiration date and time of the update message p1. A specific example of the expiration date and time is "05 / 02 / 2024 12:00:00."
[0134] Fig. 18 is a diagram illustrating an example of an update rule p2 to which the policy updater 150 refers.
[0135] The update rule p2 is data that specifies one or more rules for updating the disclosure policy data item p. For example, the one or more rules include a first rule, a second rule, and a third rule. The first rule specifies update source identification information for one or more policy update sources that can update the disclosure policy data item p (e.g., "XXX Server, YYY"). The second rule specifies that the expiration date and time of the update message p1 for updating the disclosure policy data item p are later than a current time. The third rule specifies that the issue time of the update message p1 for updating the disclosure policy data item p is later than the issue time of the update message p1 used to update the current disclosure policy data item p.Please note that the first rule, the second rule, and the third rule are merely examples. A different rule can be specified in update rule p2.
[0136] Fig. 19 is a sequence diagram illustrating an example of a processing operation of a policy update source and the policy updater 150.
[0137] First, the policy update source sends the update message p1 to the policy updater 150 (step S31). The policy updater 150 receives this update message p1 (step S32). Referring to the update rule p2, the policy updater 150 determines whether it is possible to update the disclosure policy data item p according to this update message p1.
[0138] For example, the policy updater 150 determines whether the update source identification information in the update message p1 corresponds to the first rule in the update rule p2, that is, whether the update source identification information is specified in the first rule. The policy updater 150 also determines whether the expiration date and time in the update message p1 correspond to the second rule in the update rule p2, that is, whether the expiration date and time are later than the current time. The policy updater 150 also determines whether the issue time in the update message p1 corresponds to the third rule in the update rule p2, that is, whether the issue time is later than the issue time of the update message p1 used to update the current disclosure policy data item p.If it is determined that the update message p1 conforms to at least one of the first rule, the second rule, or the third rule, the policy updater 150 updates the disclosure policy data item p identified by the policy identification information in this update message (step 33). That is, the policy updater 150 replaces all or part of the disclosure policy data item p with the change data in the update message p1. For example, if the change data is the disclosure target "IVI," the policy updater 150 replaces the disclosure target "Domain Controller 001" in the disclosure policy data item p before the update with "IVI."If the change data is a new disclosure protocol data item p itself, the policy updater 150 replaces the previous disclosure policy data item p with the new disclosure policy data item p before the update.
[0139] The policy updater 150 then sends update result information indicating a result of the update in step S33 to the policy update source (step S34). The policy update source receives the update result information (step S35). Accordingly, the policy update source can determine whether the update has been performed based on the update result information. Note that the processing of steps S34 and S35 is not required. Alternatively, in step S34, the policy updater 150 may send the update result information to the component 1, a system, or another device as the policy update source.
[0140] In the above example, the disclosure policy data item p is updated if the update message p1 conforms to at least one of the first, second, and third rules. However, the disclosure policy data item p may be updated if the update message p1 conforms to each of the first rule, the second rule, and the third rule. Alternatively, the disclosure policy data item p may be updated if the update message p1 conforms to any one of a rule group including one or more rules, or to a rule group including the other one or more rules. For example, the disclosure policy data item p may be updated if the update message p1 conforms to any one of a rule group including the first and second rules, or to a rule group including the third rule.Note that an update message p1 corresponding to a rule group means that this update message p1 matches all of one or more rules contained in the rule group. How rules are sorted into rule groups, which rules should be included in a rule group, the number of rule groups, etc., can be defined in any way. A logical expression itself, a control structure (IF statement, etc.) in a program can be defined as a rule.
[0141] The first rule may specify a plurality of update source identification information items and the priorities of the update source identification information items. For example, the policy updater 150 receives update messages p1 from a plurality of policy update sources. That is, a conflict between updates occurs. In such a case, the policy updater 150 identifies, according to the first rule, a policy update source corresponding to the highest priority among the priorities of the update source identification information items among the policy update sources. The policy updater 150 may then update the disclosure policy data item p based on the update message p1 sent from the identified policy update source.Alternatively, the policy updater 150 identifies the update message p1 that indicates the most recent issuance time or the most distant expiration date and time among these update messages p1. The policy updater 150 can then update the disclosure policy data item p based on the identified update message p1.
[0142] As described above, in the present embodiment, the disclosure executor 120 of the low-ranking component 1b receives the disclosure request message m from the high-ranking component 1a and identifies a protocol data item corresponding to this disclosure request message m. The disclosure executor 120 then determines a discloseable range of the identified protocol data item based on the disclosure policy data item p related to the identified protocol data item. Furthermore, the disclosure executor 120 sends a disclosure protocol data item to the high-ranking component 1a if the identified protocol data item includes the disclosure protocol data item to be disclosed in a disclosure range that is within the determined discloseable range and also within a request range specified in the disclosure request message m.
[0143] When the low-ranking component 1b receives the disclosure request message m from the high-ranking component 1a, the low-ranking component 1b can send a disclosure protocol data item to the high-ranking component 1a. Thus, the disclosure protocol data item is disclosed in a disclosure range that is within the disclosable range based on the disclosure policy data item p and also within the requirement range specified in the disclosure request message m. That is, using the disclosure policy data item p, the low-ranking component 1b can disclose the disclosure protocol data item in the disclosure range that is narrower than the requirement range specified in the disclosure request message m.Consequently, the low-class component 1b can disclose a disclosure log data item in a disclosure range according to the need for a log data item, without disclosing a log data item that satisfies the entire requirement range specified in the disclosure request message m, and without refusing to disclose a log data item. For example, it is possible to disclose a disclosure log data item in a disclosure range required for debugging. Accordingly, the low-class component 1b can reduce the risk of technology leakage, and the high-class component 1a can appropriately acquire log data items. Furthermore, it is possible to reduce the time, consumption of processing resources, etc. required for acquiring log data items.It is noted that if there is no disclosure scope that lies within a disclosable scope based on the disclosure policy data element p and also lies within a request scope specified in the disclosure request message m, the low-class component 1b does not need to send a disclosure protocol data element and may reject a request with the disclosure request message m.
[0144] In the present embodiment, since the disclosure request message m containing first execution identification information is transmitted, the high-ranking component 1a can transmit to the low-ranking component 1b the designation of a log data item to be requested for disclosure. With the first execution identification information, the low-ranking component 1b can appropriately identify a log data item requested by the high-ranking component 1a.
[0145] In the present embodiment, before transmitting the disclosure request message m, a list is created that includes one or more components 1, each of which includes a piece of protocol data to which a second execution identification information has been added. Each of the one or more components 1 specified in the list is designated as the access destination of the disclosure request message m, that is, the destination of the disclosure request message m. Thus, it is possible to transmit the disclosure request message m to appropriate destinations, thereby making the transmission of such a disclosure request message m efficient. That is, it is possible to reduce unnecessary processing, such assending the disclosure request message m to a component 1 other than the components 1 each containing a protocol data item to which second execution identification information has been added, to cause the other component 1 to execute the processing corresponding to the disclosure request message m.
[0146] In the present embodiment, one or more disclosure policy data items p stored in the policy storage 123 are updated, and thus it is possible to appropriately adjust the disclosure range of a disclosure log data item.
[0147] In the present embodiment, for each request from the high-ranking component 1a, the log storage 2 of the low-ranking component 1b stores a piece of log data to which second execution identification information corresponding to the request has been added. Moreover, the second execution identification information is information obtained from the high-ranking component 1a. For example, the high-ranking component 1a executes the processing and requests the low-ranking component 1b to perform other processing required for the processing. At this time, the high-ranking component 1a can cause the low-ranking component 1b to add second execution identification information sent from the high-ranking component 1a to a piece of log data of the other processing corresponding to the request.Therefore, the high-ranking component 1a can identify a log data item of a series of processes that are executed together with the low-ranking component 1b using the second execution identification information.
[0148] In the present embodiment, a disclosure protocol data item is encrypted by the low-class component 1b and sent to the high-class component 1a. Therefore, it is possible to increase the confidentiality of the disclosure policy data item. For example, the disclosure protocol data item that has been encrypted is sent as an encrypted disclosure protocol data item from the low-class component 1b to the high-class component 1a via another component 1. In such a case, the content of the encrypted disclosure policy data item can be prevented from being decrypted by the other component 1.
[0149] In the present embodiment, a disclosure protocol data item is disclosed according to one or more request details that satisfy a condition specified in the disclosure policy data item p, among one or more request details specified by the disclosure request message m, and in a portion that is different from a second execution mode specified in the disclosure request message m and overlaps with a first execution mode specified by the disclosure policy data item p. For this reason, it is possible to limit a request having a request detail and a second execution mode specified in the disclosure request message m according to a condition, and a first execution mode specified by the disclosure policy data item p. Consequently, it is possible to appropriately limit the disclosure of a protocol data item.
[0150] In the present embodiment, when an execution clause in the disclosure policy data item p indicates application to an external system outside the information processing system 100, the disclosure executor 120 of the low-ranking component 1b queries the external system whether to disclose a protocol data item in a second execution mode specified in the disclosure request message m. Therefore, in the case where the external system permits disclosure of the protocol data item in the second execution mode, it is possible to disclose a disclosure protocol data item in the form of disclosing the protocol data item in the second execution mode.Conversely, if the external system does not permit the disclosure of the log data element in the second execution mode, it is possible to prevent the disclosure of the log data element in the second execution mode, i.e., the disclosure of the disclosure log data element. Therefore, it is possible to appropriately control the disclosure of a log data element with an external system.
[0151] In the present embodiment, when the log aggregator 114 receives a disclosure log data item from each of two or more components 1, the log aggregator 114 aggregates two or more disclosure log data items and outputs the aggregated two or more disclosure log data items. Therefore, it is possible, for example, to display the disclosure log data items on a display in a clear manner. For example, it is possible to easily perform error analysis or troubleshooting by referring to the disclosure log data items. (Embodiment 2)
[0152] In Embodiment 1, a series of processes are performed by the high-ranking component 1a and the low-ranking component 1b. In contrast, in the present embodiment, a series of processes are performed by the high-ranking component 1a, the low-ranking component 1b, and an additional medium-ranking component.
[0153] Fig. Figure 20 is a diagram illustrating an example of a series of processes performed by a plurality of components 1, including the middle-classed component.
[0154] For example, as in Fig. As shown in Figure 20, the series of processes is performed by the gateway 13 corresponding to the high-class component 1a, the ECU 17 corresponding to the low-class component 1b, and the domain controller 14 corresponding to the middle-class component. Specifically, the gateway 13 calls a function of the domain controller 14 via an API to execute a process. As a result, the domain controller 14 executes a process corresponding to the called function. At this time, the domain controller 14 calls a function of the ECU 17 via an API. That is, the gateway 13 serves as the high-class component 1a to request the domain controller 14 to execute a process. In addition, the domain controller 14 receiving the request serves as a middle-class component to request the ECU 17 corresponding to the low-class component 1b to perform a process.Accordingly, the series of processes is performed by the gateway 13, the domain controller 14 and the ECU 17.
[0155] It is noted that gateway 13, which corresponds to the high-class component 1a, can call functions of a plurality of middle-class components via APIs, and the middle-class components can call functions of a plurality of low-class components 1b via APIs.
[0156] Fig. 21 is a diagram illustrating an example of the configurations of the high-class component 1a and the plurality of middle-class components in the present embodiment.
[0157] Each of the middle-classed components 1c is component 1 included in the information processing system 100, executes a process in response to a call via an API from the high-classed component 1a, and calls a function of the low-classed component 1b via an API to execute the process.
[0158] This middle-class component 1c includes the constituent elements of the low-class component 1b of Embodiment 1 and further includes a distributor 160. Therefore, the middle-class component 1c can be referred to as a second component.
[0159] The processing executor 131b of the middle-class component 1c executes a process similar to the process executed by the processing executor 131b in Embodiment 1 and calls a function of the low-class component 1b via an API. In response to the call from the middle-class component 1c, the low-class component 1b executes a process corresponding to the called function, as in the call from the high-class component 1a. As a result, the processing executor 131b of the middle-class component 1c receives a response to the call from the low-class component 1b and responds to the high-class component 1a.
[0160] The distributor 160 distributes data or information. That is, the distributor 160 sends data or information sent from the high-class component 1a and received from the disclosure executor 120 to the low-class component 1b. For example, when the ID response unit 121 of the disclosure executor 120 receives execution identification information (i.e., first execution identification information) from the high-class component 1a, the distributor 160 sends the execution identification information to the low-class component 1b. When the disclosure processor 122 of the disclosure executor 120 receives the disclosure request message m from the high-class component 1a, the distributor 160 sends this disclosure request message m to the low-class component 1b.For example, a different component identification information item from the component identification information item relating to the middle-class component 1c, including this distributor 160, is set as the access destination in this disclosure request message m. In such a case, the distributor 160 may send such a disclosure request message m to the low-class component 1b identified by the different component identification information. Note that the component identification information item relating to the middle-class component 1c, including this distributor 160, may also be set as the access destination.
[0161] That is, the disclosure request message m sent from the high-ranking component 1a specifies, as an access target, each of one or more components 1 specified on a list generated by the list generator 112. If the one or more components 1 include, as an access target, any component 1 other than the middle-ranking component 1c, the distributor 160 sends the disclosure request message m received from the disclosure executor 120 to this component 1.
[0162] On the other hand, the distributor 160 receives data or information sent from the low-class component 1b and sends the data or information to the high-class component 1a via the disclosure executor 120. For example, after receiving the above-mentioned response information k1 from the ID response unit 121 of the low-class component 1b, the distributor 160 sends this response information k1 to the high-class component 1a via the disclosure executor 120. Furthermore, after receiving a disclosure log data item from the disclosure processor 122 of the low-class component 1b, the distributor 160 sends the disclosure log data item to the high-class component 1a via the disclosure executor 120.
[0163] Note that the middle-class component 1c in the present embodiment also executes the process executed by the low-class component 1b in Embodiment 1. The low-class component 1b in the present embodiment communicates with the high-class component 1a via the middle-class component 1c to execute a process similar to that executed by the low-class component 1b in Embodiment 1.
[0164] Fig. Figure 22 is a sequence diagram showing an example of a processing operation of the high-class component 1a, the medium-class component 1c, and the low-class component 1b.
[0165] First, the high-ranking component 1a performs the processing of steps S1 and S2 as in Embodiment 1 when starting the debugging. The list generator 112 then sends the execution identification information to the middle-ranking component 1c to query this middle-ranking component 1c (step S3a). When the ID response unit 121 of the middle-ranking component 1c receives the execution identification information from the high-ranking component 1a, the distributor 160 of the middle-ranking component 1c sends the execution identification information to the low-ranking component 1b (step S3b). Accordingly, the query for the execution identification information is also made to the low-ranking component 1b.
[0166] After receiving the execution identification information from the middle-class component 1c, the low-class component 1b executes the processing of steps S4 and S5 as in Embodiment 1. It is noted that in step S5, the ID response unit 121 of the low-class component 1b sends the response information k1 to the middle-class component 1c.
[0167] The distributor 160 of the middle-class component 1c receives the response information k1 from the low-class component 1b (step S31). The distributor 160 then outputs this response information k1 to the ID response unit 121 of the middle-class component 1c. After receiving the response information k1 from this low-class component 1b, the ID response unit 121 of the middle-class component 1c performs processing in the middle-class component 1c similar to steps S4 and S5 performed in the low-class component 1b (steps S4a and S5a).
[0168] That is, the ID response unit 121 of the middle-class component 1c checks whether a piece of log data to which the execution identification information sent from the high-class component 1a has been added is stored in the log memory 2 of the middle-class component 1c (step S4a). That is, the ID response unit 121 checks whether a piece of log data stored in the log memory 2 contains the execution identification information. Here, the ID response unit 121 checks whether a piece of log data contains the execution identification information. At this time, the ID response unit 121 sends to the high-class component 1a the response information k1 containing a result of the check and component identification information, that is, identification information about the middle-class component 1c including this ID response unit 121 (i.e.,Identification information about its own component) (step S5a). In step S5A, the ID response unit 121 jointly transmits the response information k1 from the low-ranked component 1b received in step S31 and the response information k1 from the above-mentioned medium-ranked component 1c to the high-ranked component 1a.
[0169] After receiving the above-mentioned response information k1, the high-class component 1a performs the processing of steps S6 and S7 as in Embodiment 1. Note that in step S7, the message handler 113 of the high-class component 1a sends the disclosure request message m to the middle-class component 1c included in the access destination.
[0170] The disclosure processor 122 of the middle-class component 1c receives this disclosure request message m from the high-class component 1a. The distributor 160 of the middle-class component 1c then sends this disclosure request message m to the low-class component 1b included in the access destination (step S7a).
[0171] The disclosure processor 122 of the low-ranking component 1b receives this disclosure request m from the middle-ranking component 1c and performs disclosure permission processing according to the disclosure request message m and the disclosure policy data p (step S32). In step S32, similar processing to steps S8 to S11 in Embodiment 1 is performed. The disclosure processor 122 of the low-ranking component 1b then sends a disclosure protocol data identified in the processing of step S32 to the middle-ranking component 1c (step S12).
[0172] The distributor 160 of the medium-classified component 1c receives the disclosure protocol data item from the low-classified component 1b (step S33). The distributor 160 then outputs the disclosure protocol data item to the disclosure processor 122 of the medium-classified component 1c. After receiving the disclosure policy data item, the disclosure processor 122 of the medium-classified component 1c performs processing in the medium-classified component 1c similar to the processing of step S32 in the low-classified component 1b (step S34). Therefore, a disclosure protocol data item is identified in the medium-classified component 1c.The disclosure processor 122 of the medium-classified component 1c then sends the disclosure log data item in the low-classified component 1b received in step S33 and the disclosure log data item in the medium-classified component 1c identified in step S34 to the high-classified component 1a.
[0173] As a result, the high-ranking component 1a of the middle-ranking component 1c receives the disclosure log data item in the low-ranking component 1b and the disclosure log data item in the middle-ranking component 1c (step S13).
[0174] Note that in step S12, the low-ranking component 1b may encrypt the disclosure log data item with a shared key and send an encrypted disclosure log data item generated by the encryption to the middle-ranking component 1c. The shared key is an encryption key stored jointly with the high-ranking component 1a. The shared key is not stored in the middle-ranking component 1c.
[0175] Accordingly, even if the medium-classified component 1c receives a disclosure log data item in the low-classified component 1b (i.e., an encrypted disclosure log data item) in step S33, it is possible to prevent the disclosure log data item from being decrypted by the medium-classified component 1c. Alternatively, the low-classified component 1b may send the disclosure log data item to the high-classified component 1a via another medium-classified component 1c in step S12. The other medium-classified component 1c is Component 1, which belongs to the same disclosure class as the low-classified component 1b.
[0176] In the above-mentioned example, there is a middle-ranked component 1c between the high-ranked component 1a and the low-ranked component 1b. However, the number of such middle-ranked components 1c may be more than one. In the above-mentioned example, the number of layers of component 1 is three. That is, the high-ranked component 1a, the middle-ranked component 1c, and the low-ranked component 1b constitute the three layers. However, the number of layers may be four or more. In this case, the number of layers of middle-ranked components 1c may be more than one. If the middle-ranked component 1c exists in one of the plurality of layers, the low-ranked component 1b may exist in the same layer as the middle-ranked component 1c. Furthermore, the configuration of the layer may be determined dynamically.This means that the structure of the majority of components 1 can be one, in which layers cannot be defined, resulting in a so-called network-like topology. In this case, which of the components 1 serves as the high-class component 1a and which of the components 1 serves as the low-class component 1b can be determined dynamically based on certain designations, such as an API call relationship, or which of the components 1 is used for debugging.
[0177] As described above, in the present embodiment, the middle-class component 1c includes the distributor 160. Accordingly, the disclosure request message m can be distributed from the high-class component 1a to the low-class component 1b via the middle-class component. As a result, the high-class component 1a can receive a disclosure log data item not only from the middle-class component 1c but also from the low-class component 1b, and thus, it is possible to effectively acquire log data items.
[0178] The high-class component 1a in Embodiments 1 and 2 is an information processing device including the ID extractor 111, the list generator 112, and the message processor 113. The ID extractor 111 extracts first execution identification information from input information to identify a piece of protocol data to be requested. The list generator 112 sends the first execution identification information to each of a plurality of external devices, and based on a response result from one or more external devices, each including a piece of protocol data to which second execution identification information corresponding to the first execution identification information has been added, generates a list indicating the one or more external devices among the plurality of external devices.The message processor 113 sends the disclosure request message m, which specifies a request range in which disclosure of the protocol data item is requested, to at least one of the one or more external devices specified on the list. The disclosure request message m includes the first execution identification information extracted by the ID extractor 111 and specifies the one or more external devices specified on the list as access targets. Each external device corresponds, for example, to a second component or low-class component 1b.
[0179] Accordingly, the information processing device can obtain a piece of protocol data according to a request range from at least one of the one or more external devices by sending the disclosure request message m to the at least one external device. By sending the disclosure request message m including the first execution identification information, the information processing device can send the name of a piece of protocol data to be requested for disclosure to the external device. With the first execution identification information, the external device can appropriately identify a piece of protocol data requested by the information processing device.In addition, before transmitting the disclosure request message m, the list indicating the one or more external devices each containing a piece of protocol data to which the second execution identifier information has been added is generated. Each of the one or more external devices specified on the list is set as an access destination of the disclosure request message, that is, as a destination of the disclosure request message. Thus, it is possible to transmit the disclosure request message to appropriate destinations, making the transmission of the disclosure request message efficient. That is, it is possible to reduce unnecessary processing such asSending a disclosure request message to an external device other than the external devices each including a piece of protocol data to which the second execution identification information has been added, to cause the other external device to execute the processing according to the disclosure request message. Therefore, it is possible to appropriately acquire protocol data items.
[0180] The low-class component 1b or the medium-class component 1c in Embodiments 1 and 2 is an information processing device including the log storage 2 and the disclosure executor 120. The log storage 2 stores one or more pieces of log data. The disclosure executor 120 receives, from an external device, the disclosure request message m indicating a request range in which disclosure of a piece of log data is requested, and identifies the piece of log data corresponding to the disclosure request message m among the one or more pieces of log data stored in the log storage 2.Next, the disclosure executor 120 determines a disclosable range of the identified protocol data item based on the disclosure policy data item p, which, as a disclosure policy, specifies a policy regarding the disclosure of the identified protocol data item. The disclosure executor 120 then sends a disclosure protocol data item to the external device if the identified protocol data item includes the disclosure protocol data item to be disclosed in a disclosure range that is within the determined disclosable range and also within a request range specified in the disclosure request message m. For example, the external device corresponds to a first component or high-class component 1a.
[0181] When the information processing device receives the disclosure request message m from the external device, the information processing device can send the disclosure protocol data to the external device. Thus, the disclosure protocol data is disclosed within a disclosure range that is within the disclosable range based on the disclosure policy data p and also within the requirement range specified in the disclosure request message m. That is, using the disclosure policy data p, the information processing device can disclose the disclosure protocol data in the disclosure range that is narrower than the requirement range specified in the disclosure request message m.Therefore, the information processing device can disclose a disclosure log data item in a disclosure range according to the need for the log data item, without disclosing a log data item that satisfies the entire requirement range specified in the disclosure request message m, and without rejecting the disclosure of a log data item. For example, it is possible to disclose a disclosure log data item in a disclosure range required for troubleshooting. Accordingly, the external device can appropriately acquire log data items.It is noted that when there is no disclosure range that is within the disclosable range based on the disclosure policy data p and also within a request range specified in the disclosure request message m, the information processing apparatus does not need to send a disclosure protocol data.
[0182] Component 1 in Embodiments 1 and 2 may be an information processing device that includes both a function of high-level component 1a and a function of low-level component 1b or medium-level component 1c. Such an information processing device includes message processor 113, log storage 2, and disclosure executor 120. Message processor 113 sends a first disclosure request message m to a first external device, specifying a request range in which disclosure of a log data item is requested. Log storage 2 stores one or more log data items.The disclosure executor 120 receives the second disclosure request m indicating a request range from a second external device, and identifies the log data item corresponding to the second disclosure request m among one or more log data items stored in the log storage 2. Next, the disclosure executor 120 determines a discloseable range of the identified log data item based on the disclosure policy data item p indicating, as a disclosure policy, a policy regarding disclosure of the identified log data item.The disclosure executor 120 then sends a disclosure protocol data item to the second external device if the identified protocol data item includes the disclosure protocol data item to be disclosed in a disclosure range that is within the determined disclosable range and also within a request range specified in the second disclosure request message m.
[0183] Accordingly, it is possible to exhibit the same actions and effects as those of the above-mentioned low-class component 1b and to request a protocol data item from the first external device as in the high-class component 1a. (Other embodiment)
[0184] Although the information processing systems according to one or more aspects of the present disclosure have been described based on Embodiments 1 and 2, the present disclosure is not limited to these embodiments. Those skilled in the art will readily understand that embodiments achieved by making various modifications to the above embodiments, or embodiments achieved by selectively combining Embodiments 1 and 2, without materially departing from the scope of the present disclosure, may fall within one or more aspects of the present disclosure.
[0185] In Embodiments 1 and 2 described above, the disclosure class is expressed in two classes: "low" and "high." However, the disclosure class may be expressed in three or more classes. In this case, too, the disclosure scope is limited to either the request disclosure class specified in the disclosure request message m or the disclosure class specified in the disclosure policy data element p, whichever is smaller.
[0186] In Embodiments 1 and 2 described above, the execution identification information is distributed. The distribution of the execution identification information can be performed pseudo-like. For example, when performing the series of processes using an API, the processing executor 131a of the high-ranking component 1a and the processing executor 131b of the low-ranking component 1b or the middle-ranking component 1c add API information, including a time at which the API is called, a parameter of the API, and the API type, to their log data items as second execution identification information. With this API information, the log data item in the high-ranking component 1a and the log data item of the low-ranking component 1b or the middle-ranking component 1c are linked to each other.In this case, ID response unit 121 receives from list generator 112 a query about the log data item to which the API information has been added, as a query about a log data item to which the first execution identification information has been added. ID response unit 121 then compares the retrieved API information with the API information items in the log data items stored in log memories 2, searching for a log data item to which the retrieved API information has been added.Likewise, the disclosure processor 122 performs a comparison between the API information included in the disclosure request message m and the API information items in the log data items stored in the log memories 2, and thereby determines a log data item to which the API information included in the disclosure request message m has been added.
[0187] In Embodiments 1 and 2 described above, the first execution identification information and the second execution identification information do not need to correspond one-to-one. For example, if the first execution identification information indicates a time at which processing is performed, there may be a plurality of functions or APIs that can be executed during a period including the time. A candidate for the functions or APIs that may have been called may be used as the second execution identification information. That is, a time at which a function or API is executed during the period may be used as the second execution identification information.
[0188] For example, if the type of an API called by the low-ranking component 1b indicates which of the low-ranking components 1b was called, the high-ranking component 1a may simply generate the above-mentioned list specifying one or more low-ranking components 1b without querying one or more low-ranking components 1b.
[0189] It should be noted that in the embodiments described above, each of the constituent elements may be configured with dedicated hardware or implemented by executing a software program suitable for the constituent element. Each constituent element may be implemented by a program executor such as a central processing unit (CPU) or a processor that reads and executes a software program recorded in a recording medium such as a hard disk or a semiconductor memory. Here, a program implementing a device such as each component 1 or a system in the embodiments described above causes a computer to execute the sequence diagrams shown in the Fig. 9, Fig. 16, Fig. 19 and Fig. 22 steps included.
[0190] It should be noted that the present disclosure may also include the following embodiments. (1) Each of one or more devices described above may specifically be a computer system, including, for example, a microprocessor, ROM (read-only memory) and RAM (random access memory), a hard disk, a display unit, a keyboard, a mouse, etc. A computer program is located in the RAM or hard disk. The microprocessor operates according to the computer program to cause each of the one or more devices described above to perform its function. Here, the computer program includes combinations of instruction codes for issuing instructions to the computer to perform predetermined functions. (2) Part or all of the constituent elements in each of the one or more devices described above can be implemented in a single large-scale integration (LSI). The system LSI is a multifunctional LSI in which multiple elements are integrated into a single chip. An example of such a system LSI is a computer system that includes a microprocessor, a ROM, a random access memory (RAM), and the like. The microprocessor operates according to the computer program to cause the system LSI to perform its function. (3) Part or all of the constituent elements included in each of the one or more devices described above may be integrated into an integrated circuit (IC) card or a single module that can be attached to and detached from the device. The IC card or module is a computer system that includes a microprocessor, a ROM, a RAM, etc. The IC card or module may include the super multifunction LSI described above. The microprocessor operates according to the computer program to cause the IC card or module to perform its function. The IC card or module may be tamper-proof. (4) The present disclosure may be the methods described above. These methods may be a computer program executed by a computer or digital signals constituting the computer program.
[0191] The present disclosure may be a computer-readable recording medium on which the computer program or the digital signals are recorded. Examples of the computer-readable recording medium include a flexible disk, a hard disk, a compact disc-read-only memory (CD-ROM), a magneto-optical disk (MO), a digital versatile disc (DVD), a DVD-ROM, a DVD-RAM, a BD (Blu-ray (registered trademark) Disc), and a semiconductor memory. The present disclosure may be the digital signals recorded on the recording medium.
[0192] The present disclosure may be implemented by sending the computer program or the digital signals via an electrical communication line, a wired or wireless communication line, a network represented by the Internet, a data transmission, and the like.
[0193] It is also possible to record the program or digital signals on the recording medium to be transmitted or to transmit them via a network or the like so that the program or digital signals can be executed by another independent computer system. [Industrial applicability]
[0194] The information processing system according to the present disclosure is applicable, for example, to a system, a device, or the like that collects log data items for troubleshooting. [List of reference symbols] 1 component 1a high-class component (first component) 1b low-class component (second component) 2 log storage 11 Communication module 12 IVI 13 Gateway 14, 15, 16 domain controllers 17, 18, 19, 20, 21, 22 ECU 30 OBD 40 ad 100 Information processing system 110 Disclosure Requesters 111 ID Extractor (Extractor) 112 list creators 113 message processors 114 Protocol Aggregator (Aggregator) 120 Disclosure Executors 121 ID Response Unit 122 Disclosure Processors 123 Policy Storage 131a, 131b Processing exporter 132 ID generators 133 ID adder 141 Protocol Encryptors 142 protocol decryptors 150 policy updaters 200 servers 300 Troubleshooting Device 301 Error Identifier 302 Error Manager 1000 communication system a1, a2, a3, a4, a5 stock element group d Protocol data element k1 Response information m Disclosure Request Message Nt communication network p Disclosure Policy Data p1 update message p2 update rule QUOTES CONTAINED IN THE DESCRIPTION
[0000] This list of documents submitted by the applicant was generated automatically and is included solely for the convenience of the reader. This list is not part of the German patent or utility model application. The DPMA assumes no liability for any errors or omissions. Cited patent literature
[0000] JP 7069956
[0003]
Claims
[1] Information processing system comprising: a first component; and a second component, where the first component includes: a message handler that sends to the second component a disclosure request message specifying a request range in which disclosure of a protocol data element is requested, the second component includes: a log store in which one or more log data items are stored; and a disclosure executor, and where the disclosure maker: receives the disclosure request message from the first component; identifies the log data element corresponding to the disclosure request message from the one or more log data elements stored in the log store; determines a disclosable scope of the identified log data element based on a disclosure log data element that specifies, as a disclosure policy, a policy regarding the disclosure of the identified log data element; and sends a disclosure protocol data element to the first component if the identified protocol data element comprises the disclosure protocol data element to be disclosed in a disclosure scope that is within the disclosable disclosure scope and also within the request scope specified in the disclosure request message. [2] Information processing system according to claim 1, wherein: the first component further includes: an extractor that extracts first execution identification information from input information to identify the protocol data item to be requested; the message processor further generates the disclosure request message, including the first execution identification information extracted by the extractor, and the disclosure executor of the second component identifies, as the log data item corresponding to the disclosure request message, a log data item to which second execution identification information corresponding to the first execution identification information has been added from the one or more log data items stored in the log storage. [3] Information processing system according to claim 2, comprising: three or more components, including the first and second components, wherein the first component further includes: a list generator that (i) sends the first execution identification information to each of a plurality of components, including the second component, from the three or more components, and (ii) generates a list indicating the one or more components, including the second component, based on a response result from one or more components, each including a protocol data item to which the second execution identification information corresponding to the first execution identification information has been added, from the plurality of components, and where the message processor: the disclosure request message, which specifies as the access target each of the one or more components specified on the list. [4] The information processing system of claim 3, wherein the second component further comprises: a distributor that sends the disclosure request message received from the disclosure executor to a component other than the second component of the one or more components if the one or more components include the other component as an access target. [5] Information processing system according to claim 1, wherein the second component further includes: a policy store in which one or more disclosure policy data items are stored, wherein the one or more disclosure policy data items correspond to the one or more log data items stored in the log store; and a policy updater that updates the one or more disclosure log data elements, and the one or more disclosure log data elements comprise the disclosure log data element corresponding to the identified log data element. [6] Information processing system according to claim 3, wherein the second component further includes: a processing executor that receives from the first component the second execution identification information corresponding to a request each time the request is received from the first component and executes the processing according to the request, and each time processing corresponding to the request is executed, the processing executor (i) adds the second execution identification information corresponding to the request to a log data item indicating a result of the processing corresponding to the request, and (ii) stores in the log storage the log data item to which the second execution identification information has been added. [7] Information processing system according to claim 1, wherein the second component further includes: a log encryptor that generates an encrypted disclosure log data item by encrypting the identified log data item or encrypting the disclosure log data item; the disclosure executor sends the disclosure log data item by sending the encrypted disclosure log data item, and the first component further includes: a protocol decryptor that decrypts the encrypted disclosure protocol data item when the first component receives the encrypted disclosure protocol data item. [8] Information processing system according to claim 1, wherein the disclosure policy data element specifies the disclosable scope, which includes a condition clause and an execution clause, the condition clause specifies a condition for the disclosure of the identified log data element, the execution clause specifies a first execution mode, which is a mode of disclosure of the identified protocol data element, the disclosure request message specifies: one or more request details for disclosure of the identified log data element; and a second execution mode, which is a mode requested for disclosure of the identified log data element, and the disclosure executor of the second component further identifies, as a disclosure protocol data item, a protocol data item to be disclosed (i) according to at least one request detail that satisfies the condition specified in the condition clause, under the one or more request details specified in the disclosure request message, and (ii) in a portion of the second execution mode specified in the disclosure request message, the portion overlapping with the first execution mode specified by the condition clause. [9] Information processing system according to claim 8, wherein if the execution clause specifies an application to an external system outside the information processing system instead of the first execution mode, the disclosure executor of the second component queries the external system whether the log data item should be disclosed in the second execution mode. [10] Information processing system according to claim 1, comprising: three or more components, including the first and second components, wherein the first component further includes: an aggregator that aggregates two or more disclosure log data items and outputs the two or more aggregated disclosure log data items when the aggregator receives the two or more disclosure log data items from two or more components, including the second component, among the three or more components. [11] Information processing device comprising: an extractor that extracts first execution identification information from input information to identify a protocol data item to be requested; a list generator that (i) sends the first execution identification information to each of a plurality of external devices and (ii) generates a list indicating the one or more external devices among the plurality of external devices based on a response result from one or more external devices each including a piece of protocol data to which second execution identification information corresponding to the first execution identification information has been added; and a message handler that sends a disclosure request message specifying a request range in which disclosure of the protocol data item is requested to at least one of the one or more external devices specified on the list, wherein the disclosure request message includes the first execution identification information extracted by the extractor and specifies one or more external devices specified on the list as access targets. [12] Information processing device comprising: a log store in which one or more log data items are stored; and a disclosure executor, where the disclosure executor: receives from an external device a disclosure request message specifying a request scope in which disclosure of a protocol data item is requested; identifies the log data element corresponding to the disclosure request message from the one or more log data elements stored in the log store; determines a disclosable scope of the identified log data element based on a disclosure log data element that specifies, as a disclosure policy, a policy regarding the disclosure of the identified log data element; and sends a disclosure protocol data item to the external device if the identified protocol data item comprises the disclosure protocol data item to be disclosed in a disclosure scope that is within the disclosable disclosure scope and also within the request scope specified in the disclosure request message. [13] Information processing device comprising: a message handler that sends a first disclosure request message to a first external device specifying a request range in which disclosure of a protocol data item is requested; a log store in which one or more log data items are stored; and a disclosure executor, where the disclosure executor: receives a second disclosure request message indicating the request scope from a second external device; identifies the log data element corresponding to the second disclosure request message from the one or more log data elements stored in the log store; determines a disclosable scope of the identified log data element based on a disclosure log data element that specifies, as a disclosure policy, a policy regarding the disclosure of the identified log data element; and sends a disclosure protocol data item to the second external device if the identified protocol data item comprises the disclosure protocol data item to be disclosed in a disclosure range that is within the discloseable disclosure range and also within the request range specified in the second disclosure request message. [14] An information processing method performed by a first component and a second component, the information processing method comprising: Sending a disclosure request message specifying a request scope in which disclosure of a log data item is requested from the first component to the second component; receiving the disclosure request message from the first component by the second component; identifying, by the second component, the log data element corresponding to the disclosure request message from one or more log data elements stored in a log store; Determining, by the second component, a disclosable range of the identified log data element based on a disclosure log data element that specifies, as a disclosure policy, a policy regarding the disclosure of the identified log data element; and Sending a disclosure protocol data item from the second component to the first component if the identified protocol data item comprises a disclosure protocol data item to be disclosed in a disclosure scope that is within the disclosable disclosure scope and also within the request scope specified in the disclosure request message. [15] Program that causes a computer to execute: Extracting first execution identification information from input information to identify a protocol data item to be requested; Sending the first execution identification information to each of a plurality of external devices; Generating a list based on a response result from one or more external devices each including a protocol data item to which second execution identification information has been added among the plurality of external devices, the list indicating the one or more external devices; and Sending a disclosure request message specifying a request range in which disclosure of the protocol data item is requested to at least one of the one or more external devices specified on the list, wherein the disclosure request message includes the first execution identification information extracted and specifies the one or more external devices specified on the list as access targets. [16] Program that causes a computer to execute: Receiving a disclosure request message from an external device specifying a request scope in which disclosure of a protocol data item is requested; identifying the log data element corresponding to the disclosure request message from one or more log data elements stored in the log store; Determining a disclosable range of the identified log data element based on a disclosure log data element that specifies, as a disclosure policy, a policy regarding the disclosure of the identified log data element; and Sending a disclosure protocol data item to the external device if the identified protocol data item comprises the disclosure protocol data item to be disclosed in a disclosure scope that is within the disclosable disclosure scope and also within the request scope specified in the disclosure request message.
Citation Information
Patent Citations
JAPANISCHESPATENTNR.7069956