Status diagnostic system and status diagnostic method

The state diagnosis system enhances the identification of event factors in edge systems by processing log data with analysis models and factor scenarios, addressing the limitations of existing systems in handling multiple contributing factors.

JP2025095879APending Publication Date: 2025-06-26HITACHI LTD
View PDF 1 Cites 0 Cited by

Patent Information

Application Number
JP2023212254
Authority / Receiving Office
JP · JP
Patent Type
Applications
Current Assignee / Owner
Filing Date
2023-12-15
Publication Date
2025-06-26

AI Technical Summary

Technical Problem

Existing fault diagnosis systems for edge systems, such as automobiles and robots, struggle to identify the causes of unexpected events involving multiple factors, including software operation, environmental conditions, and hardware abnormalities.

Method used

A state diagnosis system and method that processes log data from edge systems to identify factors contributing to events by using analysis models and factor scenario data, which includes safety analysis results and scenarios representing data states and non-safe actions that trigger events.

Benefits of technology

Improves the ability to identify factors contributing to events in edge systems, including those related to environmental conditions, reducing the time and cost associated with analyzing safety control functions and enhancing customer trust through early product improvements.

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure 2025095879000001_ABST
    Figure 2025095879000001_ABST
Patent Text Reader

Abstract

To provide a status diagnostic system and a status diagnostic method capable of improving the capability of identifying the cause of an event involving multiple factors including environmental conditions, in an edge system.SOLUTION: A status diagnostic system performs a cause determination process to identify a cause scenario that triggered a safety control function, and identify a component in which a trigger non-safe action occurred. The cause determination process includes collating pre-processed edge log data, for each item of cause scenario data, and extracting, when an item matches, time information from time stamp included in the matched edge log data. The cause determination process includes calculating, for each cause scenario, a matching degree from the number of matched occurrence condition items. The cause determination process includes collating a cause scenario having an item that matches the edge log data, with safety analysis model information, on the basis of a signal name of the trigger signal name of the non-safe action, and identifying a component that outputs the non-safe action.SELECTED DRAWING: Figure 1
Need to check novelty before this filing date? Find Prior Art

Description

Technical Field

[0001] The present invention relates to a state diagnosis system and a state diagnosis method.

Background Art

[0002] In recent years, edge systems such as automobiles and robots perform advanced automatic control while recognizing and judging the surrounding environment based on sensor information. In addition, due to various requirements for automation functions, the complexity of edge systems including software is increasing. Therefore, in addition to functional safety design, as an effort to ensure safety and maintain quality throughout the life cycle, a technology capable of monitoring and diagnosing the health state of the entire edge system, including the situation of the usage environment, is required. However, there has been a problem that it is difficult to identify the cause of an unexpected event in which a plurality of factors such as software operation and environmental conditions are related in addition to hardware abnormalities.

[0003] As a prior art in this technical field, there is Patent No. 5181479 (Patent Document 1). In this document, it is described that "in a fault diagnosis system using a Bayesian network, computer components existing as physical entities are classified for fault diagnosis and defined as hardware models (models of hardware) which are the classified units. Also, a program in which procedures and instructions for controlling a computer are summarized is classified for fault diagnosis and defined as a software model (model of software) which is the classified unit. Then, in the control means, the defined hardware model and software model are configured on the same Bayesian network, and hardware inspection result information which is information of the result of executing a program for detecting an abnormality from the viewpoint of hardware is reflected in software inspection result information which is information of the result of executing a program for detecting an abnormality from the viewpoint of software, and a predetermined fault diagnosis program is executed. Therefore, an abnormality caused by hardware and an abnormality caused by software for controlling the operation of the hardware can be diagnosed integrally." A fault diagnosis system capable of factor analysis other than hardware is proposed.

Prior Art Documents

Patent Documents

[0004]

Patent Document 1

Summary of the Invention

Problems to be Solved by the Invention

[0005] In the fault diagnosis system described in Patent Document 1, while factor analysis regarding software becomes possible, the nodes of the Bayesian network do not include information on environmental conditions, and there is a possibility that factor candidates of events related to a plurality of factors including environmental conditions cannot be specified.

[0006] The present invention has been made in view of the above problems. That is, one of the objects of the present invention is to provide a state diagnosis system and a state diagnosis method capable of improving the possibility of identifying the factors of an event that has occurred in relation to a plurality of factors including environmental conditions in an edge system.

Means for Solving the Problems

[0007] In order to solve the above problems, the state diagnosis apparatus of the present invention includes an arithmetic unit and a storage unit, and has a computer that processes a plurality of log data acquired at a plurality of time points transmitted from an edge system including a plurality of subsystems to perform state diagnosis of the edge system. In the storage unit, analysis models for each of the subsystems, which are safety analysis results for the edge system, and factor scenario data including a plurality of factor scenarios corresponding to the analysis models, each of which represents the state of a plurality of data items and a factor scenario indicated by a non-safe action of data that triggers the occurrence of an event, are stored. The arithmetic unit stores the plurality of log data in the storage unit, detects the occurrence of a specific event from the plurality of log data, selects a subsystem of the edge system related to the occurrence of the specific event from the content of the specific event, extracts a plurality of factor scenarios corresponding to the selected subsystem from the factor scenario data stored in the storage unit based on the selected subsystem, for each of the plurality of extracted factor scenarios, extracts data having the same data items as the data items included in each of the plurality of extracted factor scenarios from the log data, performs a collation process of collating whether the content of the same data item matches between each of the plurality of factor scenarios and the data having the same data item extracted, identifies one or more factor scenarios that satisfy a predetermined condition based on the collation result, and identifies a factor occurrence site that is a factor causing the occurrence of the specific event based on the identified factor scenario and the analysis model corresponding to the identified subsystem.

[0008] The state diagnosis method of the present invention includes an arithmetic unit and a storage device, and processes a plurality of log data acquired at a plurality of time points transmitted from an edge system including a plurality of subsystems to perform state diagnosis of the edge system. A computer is used. In the storage device, an analysis model for each of the subsystems, which is a safety analysis result for the edge system, and a plurality of factor scenarios including the states of a plurality of data items corresponding to the analysis model and factors indicated by non-safe actions of data that trigger the occurrence of events are stored. The arithmetic unit stores the plurality of log data in the storage device, detects the occurrence of a specific event from the plurality of log data, selects a subsystem of the edge system related to the occurrence of the specific event from the content of the specific event, and based on the selected subsystem, extracts a plurality of factor scenarios corresponding to the subsystem from the factor scenario data stored in the storage device. For each of the plurality of extracted factor scenarios, data having the same data item as the data item included in each of the plurality of extracted factor scenarios is extracted from the log data, and a collation process is performed to check whether the content of the same data item matches between each of the plurality of factor scenarios and the data having the same data item extracted. Based on the collation result, one or more factor scenarios that satisfy a predetermined condition are specified, and based on the specified factor scenarios and the analysis model corresponding to the specified subsystems, a factor occurrence site that causes the specific event to occur is specified.

Advantages of the Invention

[0009] According to the present invention, it is possible to improve the possibility of identifying the factors of an event related to a plurality of factors including environmental conditions in an edge system. Note that the effects described here are not necessarily limited, and any of the effects described in the present disclosure may be applicable.

Brief Description of the Drawings

[0010]

Figure 1

Figure 2

Figure 3

Figure 4

Figure 5A

Figure 5B

Figure 5C

Figure 6

Figure 7

Figure 8

Figure 9

Embodiments for Carrying Out the Invention

[0011] <Summary of the Present Invention> First, to facilitate understanding of the present invention, an overview of the present invention will be described. As a safety analysis method comparable to conventional FTA / FMEA, "STAMP / STPA (Systems-Theoretic Accident Model and Processes: Accident model based on system theory / STAMP based Process Analysis: Safety analysis method based on accident model)" is known. In "STAMP / STPA", by focusing on the interaction of input / output information between components that realize subsystems (functions) and analyzing potential hazards, there is a feature that hazard occurrence factors including software and environmental impacts that are often overlooked in the past are also extracted.

[0012] The present invention aims to provide a state diagnosis system and a state diagnosis method that can handle events where it has been difficult to identify the cause in the past. This is achieved by having, in advance as a database, information on hazard occurrence factors (factor scenarios) obtained from safety analysis using "STAMP / STPA", and collating this with the operation log data constantly collected from the edge system. This allows for the identification of the activation factors of safety control functions triggered by complex factors such as software and the environment, not just hardware failures. In particular, it can identify the activation factors based on improper control actions occurring between components. By providing a state diagnosis solution for edge systems for edge system manufacturers and maintenance providers, it reduces the time and cost associated with analyzing the causes of safety control functions that have been triggered in unexpected situations, and can improve customer trust by leading to early product improvements.

[0013] According to the present invention, it is possible to extract the factors of safety control functions activated by complex factors such as software and the environment, not limited to hardware failures. In particular, it is possible to identify the activation factors based on improper control actions occurring between components. By providing a state diagnosis solution for edge systems for edge system manufacturers and maintenance providers, it reduces the time and cost associated with analyzing the causes of safety control functions that have been triggered in unexpected situations, and can improve customer trust by leading to early product improvements.

[0014] <<Embodiment>> Hereinafter, a first embodiment of this system will be described. A configuration example of the state diagnosis system according to Example 1 of the present invention is shown in FIG. 1.

[0015] This system is composed of an edge system 200 to be diagnosed and a diagnostic cloud server 100 that can communicate with the edge system 200 to be diagnosed via a network 10. A computer 110 included in the diagnostic cloud server 100 collects edge log data 1 from the edge system 200 in real time and performs state diagnosis.

[0016] The edge log data 1 includes, in addition to the timestamp information at the time of data collection, external / internal sensor data of the edge system 200, system error information, component identification information of the edge system 200, internal register information including setting system information, and operation status information inside the system that can recognize the activation of safety control functions. Note that the data communication between the edge system 200 and the diagnostic cloud server 100 is always encrypted, and it is assumed that the edge log data 1 can be transferred at high speed while ensuring security.

[0017] The computer 110 included in the diagnostic cloud server 100 is composed of a communication device 101 for communicating with the edge system 200, a processor 102 for executing a state diagnosis program, and a storage device 104 for storing various log data and a database for diagnosis. In the storage device 104, an area for storing the edge log data 1 collected from the edge system 200 and the safety analysis database 2 is prepared, and the collected edge log data 1 is stored in the storage device 104 in real time.

[0018] The processing contents of the state diagnosis program executed by the processor 102 of the computer 110 include an edge log data collection and storage process 4, a subsystem selection process 5, a determination log data extraction process 6, a hardware failure detection process 7, a cause scenario extraction process 8, and a cause determination process 9.

[0019] The configuration of the safety analysis database 2 is shown in FIG. 2. The safety analysis database 2 stores a safety analysis model 21 and cause scenario data 22 in units of subsystems used in the "STAMP / STPA" safety analysis. Ideally, models and scenario data for all functions and subsystems of the edge system 200 are stored.

[0020] For example, when the edge system 200 is a system mounted on a vehicle, examples of functions and subsystems include an electronic parking brake (EPB) function, ACC (Adaptive Cruise Control), LKA (Lane Keeping Assist System), and the like.

[0021] Since "STAMP / STPA" is implemented in units of system functions or subsystems, the safety analysis model 21 associated with the subsystem (function) and the information of the cause scenario data 22 are stored using the subsystem name (function name) as a label. The function may be referred to as a "subsystem". When safety analysis is performed on the entire system, there is one model and one scenario data respectively.

[0022] An example of the safety analysis model 21 is shown in FIG. 3. It is a control structure created to perform "STAMP / STPA" safety analysis for the edge system 200, and is hereinafter referred to as the safety analysis model 21. It is composed of the main components and peripheral components necessary to realize the subsystem, and the input / output information between the components. The information of this model is created in a data description language such as the DOT language used to express the structure information indicating the connection between nodes in plain text. In the example of FIG. 3, a model related to the electronic parking brake (EPB) function of the vehicle is shown, and the ECU (a) is the main component. In "STAMP / STPA", based on this model, it is analyzed what unexpected events may occur when each input / output information is regarded as an unsafe state one by one. In this example, the signal indicating the brake instruction output from the ECU (a) to the vehicle body is described as an unsafe action.

[0023] An example of cause scenario data 22 is shown in Fig. 4. In the "STAMP / STPA" safety analysis method, based on the safety analysis model 21 shown in Fig. 3, scenarios that may cause unexpected events can be extracted. Fig. 4 is information created based on the analysis and extraction of scenarios for the occurrence of unexpected events for the safety analysis model 21 of the electronic parking brake function shown in Fig. 3, and is here called cause scenario data 22. This scenario data is created in units of functions or subsystems of the edge system 200. The cause scenario data 22 is composed of a scenario No., items of hazard occurrence conditions, and items of unsafe actions. One row in the table represents the information of one piece of cause scenario data (referred to as a "cause scenario"). The items included in the occurrence conditions are omitted in the figure but are the same as the input / output data described in the safety analysis model 21. Also, for the unsafe action (UCA: Unsafe Control Action) of each scenario, the signal name that triggers the ultimately unsafe event under the condition where all the contents of the occurrence conditions are met and the unsafe type of that signal are shown. The types of unsafe types are indicated by four types: there is an unnecessary input (P), there is no required input (NP), the input is too long / too short (D), and the input is too long / too short (T). For example, the unsafe action of scenario No. 1 can be regarded as "the ON signal of the brake instruction is incorrectly input although it is originally unnecessary."

[0024] In addition, each item of the generation conditions of this scenario data includes ID information for linking with the corresponding edge log data 1 and preprocessing code information for data conversion by aligning the edge log data 1 with the content of the generation condition item. The ID information uses, for example, the address information assigned to the edge log data 1. The preprocessing of the edge log data 1 means that, for example, the content of item 1 (vehicle speed) in the table is binary values of "running" and "stopped", while the edge log data 1 is obtained as continuously changing speed information. Therefore, it is necessary to convert the edge log data 1 into binary values of "running" and "stopped". Also, for item 3 (EPB switch state), since the edge log data 1 itself is also obtained as binary values of "ON" and "OFF", preprocessing is not required. In FIG. 4, only "0: no processing" and "1: binarization" are shown as the preprocessing code, but a preprocessing code is set according to the content of the generation condition item.

[0025] The processing flow of the state diagnosis program of this system is shown in FIG. 5A. When the edge system 200 is activated (S01), recognition of the connection with the diagnostic cloud server 100 via the network 10 is made (S02), and collection and storage of the edge log data 1 are started by the edge log data collection and storage process 4 of the processor 102 (S03). The collected edge log data 1 is stored in the storage device 104 in real time.

[0026] Also, in the edge log data collection and storage process 4, the edge log data 1 is monitored, and the presence or absence of status information indicating the activation of the safety control function is detected as a specific event included in the edge log data 1 (S04). The safety control function is a function that is activated to shift to a safe state when some malfunction or unexpected event occurs in the subsystem. For example, when an unexpected abnormality or danger is detected in the automatic driving system of a vehicle, the automatic driving control is interrupted, the control of the vehicle is transferred to the driver, or the vehicle is automatically guided to a safe area and stopped, etc. If there is no control information in the edge log data 1, data collection and storage are repeated again (S03). If the activation of the safety control function is detected, the edge log data 1 is transferred to the subsystem selection process 5, the determination log data extraction process 6, and the hardware failure detection process 7 to execute the subsequent processes.

[0027] Next, in the subsystem selection process 5, based on the information of the safety control function detected in S04, the relevant subsystem (or function) is selected (S05). As one means of the selection method, the flag information indicating the activation of the safety control function is the code information that uniquely indicates the subsystem (or function) in advance, and the subsystem (or function) may be selected from the flag information. Also, a configuration may be adopted in which setting information indicating the mutual relationship is held in advance inside the subsystem selection process 5. Also, a plurality of subsystems (or functions) may be selected as the subsystems (or functions) related to the safety control function.

[0028] Next, in the cause scenario extraction process 8, based on the subsystem information selected in the subsystem selection process 5, the safety analysis model 21 and the cause scenario data 22 of the corresponding subsystem are read from the safety analysis database 2 (S06).

[0029] Next, in the determination log data extraction process 6, based on the ID information of the occurrence condition items included in the cause scenario data 22 selected and read in S05 and S06, the corresponding data is extracted from the edge log data 1 (S07). Here, the range of the edge log data 1 used for this diagnosis may be the data in any time period before the activation of the safety control function, or the data in the time periods before and after the activation.

[0030] Next, the extracted edge log data 1 executes preprocessing according to the preprocessing code of the occurrence condition items included in the cause scenario data 22. For example, when the preprocessing code is "0", [no preprocessing], and when the code is "1", processing such as binarization (if the value of the edge log data 1 is 0, it is set to "0", and if it is 0 or more, it is set to "1") is performed (S08).

[0031] Next, in the cause determination process 9, the cause scenario that caused the activation of the safety control function is identified, and the component that caused the non - safety action that triggered it is identified (S09). First, for each item of the cause scenario data 22, it is compared with the edge log data 1 preprocessed in S08. If there is a matching item, the time information is also extracted from the timestamp included in the matching edge log data 1. Next, for each cause scenario, the matching rate is calculated from the number of matching occurrence condition items. Next, for the cause scenario with an item that matches the edge log data 1, based on the signal name described in the trigger signal name of the non - safety action, it is compared with the safety analysis model information to identify the component that outputs the non - safety action. In the case of cause scenario No.1 in Figure 4, the trigger signal is "brake instruction", and in the safety analysis model 21, ECU(a) is the component that causes the non - safety action.

[0032] Next, in the hardware failure detection process 7, information related to hardware failures included in the edge log data 1 is extracted. For example, the presence or absence of error codes within the edge system 200 is checked, and the error status registers inside sensors and processors are read to confirm whether an error flag is set. Also, the presence or absence of fault diagnosis codes prepared for each vehicle is confirmed (S10).

[0033] Next, the results obtained from the diagnostic processes of S05 to S10 are output (S11). FIG. 5B shows an example of a screen configuration showing the output results of this status diagnostic system. The information 109 to be output consists of a field for displaying a list of factor scenarios that were the causes for activating the safety control function, and a field indicating the presence or absence of hardware failures. The content of the factor scenario indicates the component name where a non-safe action is occurring, the content of the non-safe action, the occurrence time, and the coincidence rate with the occurrence conditions. If there are multiple scenarios with data matches, all scenarios may be displayed, or a limited range such as only the top 10 may be displayed, or only scenarios with a coincidence rate above a threshold may be displayed. In the field indicating hardware failures, the component name and error content where hardware abnormalities are suspected are output as information detected from the edge log data 1. The user of this status diagnostic system identifies the cause of an unexpected event based on the information in the above two fields.

[0034] Note that when a part of the hardware configuration is changed or upgraded during operation, new safety analysis models 21 and factor scenario data 22 may be created and additionally stored in the storage device 104. Also, as shown in FIG. 5C, only the safety analysis model 21 may be added, and the factor scenario data 22 may be automatically generated by utilizing AI technology etc. (see FIG. 5C).

[0035] Here, a modified example of the processing flow of the state diagnosis program in FIG. 5A will be described. FIG. 6 shows an example of the safety analysis model 212 according to a modified example of the present invention. In S09 of the processing flow of the state diagnosis program described above, a component causing a non-safe action is identified. For example, the non-safe action in Scenario No. N-1 of the factor scenario data 22 shown in FIG. 4 is an unnecessary input of vehicle speed information. In this way, the component causing the non-safe action may be identified as a peripheral component (ECU (b) in this example) instead of the main component ECU (a). In such a case, the process returns to process S5 of the processing flow, re-selects the safety analysis model 212 (FIG. 6) and the factor scenario data 22 in which ECU (b) is the main component, and executes the diagnosis process from S06 to S10 again to identify a factor scenario in which ECU (b) may output unnecessary vehicle speed information. In this way, by hierarchically and repeatedly searching the safety analysis model 212, a component causing a non-safe action may be identified.

[0036] An example of the hardware configuration of the computer 110 included in the diagnostic cloud server 100 is shown in FIG. 7. The computer 110 includes a communication device 101, a processor 102, a storage device 104, a ROM (Read Only Memory) 105, and a RAM (Random Access Memory) 106, and these are connected via a data bus 103.

[0037] The computer 110 can store or read programs such as an OS (Operating System), middleware, and application programs on this hardware, and various processes can be executed by the processor 102 executing these programs.

[0038] The processor 102 is an arithmetic unit that reads various programs stored in the ROM 105 and the RAM 106 and executes processing corresponding to each program. Note that the processor 102 includes a microprocessor, a CPU (Central Processing Unit), a GPU (Graphics Processing Unit), an FPGA (Field Programmable Gate Array), or other semiconductor devices capable of performing arithmetic operations.

[0039] The communication device 101 consists of a NIC (Network Interface Card) or the like. The communication device 101 communicates with the edge system 200 or other server devices connected to the same network 10 by at least one of wired communication and wireless communication. For this communication, packet communication using TCP / IP (Transmission Control Protocol / Internet Protocol) is adopted, but it is not limited to this, and communication using other protocols such as UDP (User Datagram Protocol) may also be adopted.

[0040] As a storage medium for storing various information, the ROM 105 is a non-volatile recording medium, and the RAM 106 is a volatile storage medium. In addition to the HDD (Hard Disk Drive), the storage device 104 may be a flash memory, a hard disk, an SSD (Solid State Drive), or a USB (Universal Serial Bus) memory. The diagnostic cloud server 100 is also provided with a UI (User Interface Device) 107 consisting of a keyboard, a mouse, a touch panel, a display, a voice input device such as a microphone, etc. Further, it may be provided with a display device 108 (display unit 108) such as a display and a printer.

[0041] Note that the hardware configuration of the diagnostic cloud server 100 is not limited to the example described above, and some of the components described above may be omitted or other components may be included. Further, the diagnostic cloud server 100 may be various information processing devices such as a cloud computer, a personal computer, a notebook computer, a tablet computer, and a smartphone.

[0042] A configuration example of the edge system 200 is shown in FIG. 8. The edge system is assumed to be a moving body such as a vehicle, a robot, a railway vehicle, an aircraft, a drone, or an infrastructure / industrial control device. As an example of the edge system, an example of a connected vehicle that travels while exchanging various information by communicating with the diagnostic cloud server 100 is shown. The vehicle system includes a sensor group 202 including a camera and LIDAR (Light Detection And Racing), a plurality of ECUs (Electronic Control Unit) 203, and a communication device 201, and these are connected via a data bus 204 inside the vehicle. The ECU 203 is composed of a processor 205, a plurality of electronic components, a sensor 206, and a storage device 207, and performs vehicle control processing in cooperation with other ECUs.

[0043] In addition to the information of the sensor 206 inside the ECU (for example, a temperature and humidity sensor or a gyro sensor) and the sensor (such as a temperature sensor) inside the processor 205, it not only stores and holds the register information, arithmetic processing data, control status information, and internal error information of the processor 205, but also can be transmitted to a server outside the vehicle via the communication device 201.

[0044] Further, the edge system 200 is designed for safety in accordance with the functional safety standards in that field. In the automotive system shown in FIG. 8, a safety design is performed in accordance with the functional safety standard (ISO26262). In the safety design, the risks and occurrence conditions of malfunction events potentially present in the system, including the usage environment, are analyzed by a plurality of methods. For the risks (malfunction events) obtained by the analysis, a fundamental countermeasure or a design is made so that the operation continues safely even if they occur.

[0045] Furthermore, each component, function, processing means, etc. of the edge system 200 (edge-side processor system) may be implemented in hardware by designing some or all of them, for example, using an integrated circuit. Also, the edge system 200 (edge-side processor system) can implement some or all of each function by software, or can be implemented by the cooperation of software and hardware. Also, the edge system 200 (edge-side processor system) may use hardware having a fixed circuit, or may use hardware with at least some circuits being changeable.

[0046] Also, the databases and various types of information in the memory resources described below may be in a data structure other than a file or a database as long as it is an area capable of storing data. Also, one program may serve the roles of multiple programs. Also, the reverse may be true. That is, one or more programs may perform the processing of each program shown in the figure.

[0047] The program executed by the edge system 200 (edge-side processor system) may be stored in a non-volatile storage medium readable by the edge system 200 (edge-side processor system). The program stored in the non-volatile storage medium may be directly read by the edge system 200 (edge-side processor system), but a processor system for program distribution may read the program from the medium and then transmit (distribute) the program from the processor system for program distribution to the edge system 200 (edge-side processor system). Examples of the non-volatile storage medium include the non-volatile memory described as a memory resource, but other optical disk media may also be used.

[0048] Unless otherwise specified, it is assumed that the user's operations on the diagnostic cloud server 100 side (for example, input of information, output, and execution instructions for processing, etc.) are performed via the UI 107.

[0049] Moreover, some or all of the functions, processing means, etc. on the diagnosis cloud server 100 side may be realized by, for example, hardware, or may be realized by the cooperation of software and hardware.

[0050] In addition, the system can also be realized by a user (operator) implementing some or all of the functions and processes realized by each program of the diagnosis cloud server 100.

[0051] Note that the databases and various types of information in the memory resources described below may be in a data structure other than files or databases, as long as they are areas capable of storing data. Also, one program may serve the roles of multiple programs, and vice versa. That is, one or more programs may perform the processing of each program shown in the figures.

[0052] Note that the program executed on the diagnosis cloud server 100 may be stored in a non-volatile storage medium that can be read by the processor 102, or the processor 102 may directly read the program stored in the non-volatile storage medium. A processor system for program distribution may read the program from the medium and then transmit (distribute) the program from the processor system for program distribution to the processor 102.

[0053] FIG. 9 is a diagram showing an example of a service form to which this system is applied, which is a service form for a manufacturing company (OEM) and a dealer maintenance company. In this service, a data management operator provides a paid service to the dealer maintenance company and the manufacturing company (OEM) for vehicle operation status data, factors data during downtime, maintenance inventory prediction data inferred from downtime information. Thereby, the data management operator can obtain the merit of obtaining income from the usage fee of the service.

[0054] In addition, the dealer maintenance company can perform preventive maintenance and maintenance in advance, including parts procurement, based on the inventory prediction data and downtime factor data of users and fleet operators, thus obtaining the advantages of reducing man-hours and costs.

[0055] In addition, the manufacturing company (OEM) can monitor and analyze the operation data history and downtime factors. In addition to early quality improvement, it can notify vehicle users of recalls and service campaigns at appropriate times, thus obtaining the advantage of improving customer credit.

[0056] In addition, individual users and fleet operators can receive service recommendations related to maintenance (recommended maintenance content, information on maintenance companies with immediate inventory, etc.) from the data management company, and by performing maintenance at appropriate times, they can obtain the advantage of improving the operation rate (lifespan) of the vehicles they own.

[0057] In this way, according to this system, many advantages can be provided to stakeholders such as data management companies, dealer maintenance companies, manufacturing companies (OEMs), and users (operators).

[0058] Note that the computer related to such an edge-side processor system and a server-side processor system may function as a program distribution server that distributes a program in the memory resource to another computer so that the program can be executed by the other computer.

[0059] Furthermore, the present invention is not limited to the above-described embodiments and modifications, and various modifications are included within the scope of the same technical idea. For example, the above-described embodiments have been described in detail for easy understanding of the present invention, and are not necessarily limited to those having all the configurations described. Also, a part of the configuration of one embodiment can be replaced with the configuration of another embodiment, and the configuration of another embodiment can be added to the configuration of one embodiment. Also, for a part of the configuration of each embodiment, addition, deletion, or replacement with other configurations is possible.

[0060] Also, in the above description, the control lines and information lines show those considered necessary for explanation, and not necessarily all the control lines and information lines on the product are shown. In reality, it is reasonable to consider that almost all the components are interconnected.

Explanation of Reference Numerals

[0061] 1... Edge log data, 2... Safety analysis database, 4... Edge log data collection and storage process, 5... Subsystem selection process, 6... Judgment log data extraction process, 7... Hardware failure detection process, 8... Factor scenario extraction process, 9... Factor judgment process, 10... Network, 21, 212... Safety analysis model, 22... Factor scenario data, 100... Diagnostic cloud server, 101, 201... Communication device, 102, 205... Processor, 103, 204... Data bus, 104, 207... Storage device, 105... ROM, 106... RAM, 107... UI, 108... Display device, 200... Edge system, 202... Sensor group, 203... ECU, 206... Sensor

Claims

1. A state diagnosis device having a computer that includes an arithmetic unit and a storage device and processes a plurality of log data acquired at a plurality of time points transmitted from an edge system including a plurality of subsystems to perform state diagnosis of the edge system, wherein the storage device stores an analysis model for each of the subsystems, which is a safety analysis result for the edge system, and a plurality of factor scenario data including the states of a plurality of data items corresponding to the analysis model and factor scenarios indicated by non-safe actions of data that trigger the occurrence of events, the arithmetic unit, stores the plurality of log data in the storage device, when detecting the occurrence of a specific event from the plurality of log data, identifies the subsystem of the edge system related to the occurrence of the specific event from the content of the specific event, extracts a plurality of factor scenarios corresponding to the subsystem from the factor scenario data stored in the storage device based on the identified subsystem, for each of the plurality of extracted factor scenarios, extracts data having the same data items as those included in each of the plurality of extracted factor scenarios from the log data, and performs a collation process of collating whether the content of the same data items matches between each of the plurality of factor scenarios and the data having the same data items, and identifies one or more factor scenarios that satisfy a predetermined condition based on the collation result, identifies a factor occurrence site that is a factor causing the specific event based on the identified factor scenario and the analysis model corresponding to the identified subsystem, configured as, a state diagnosis device.

2. In the state diagnosis device according to Claim 1, the arithmetic unit, in the collation process, calculates a coincidence rate of the content of the data items between the factor scenario data and the data having the same data items extracted, and identifies one or more factor scenarios that satisfy the predetermined condition based on the calculated coincidence rate, configured as, a state diagnosis device.

3. In the state diagnosis device according to Claim 2, the arithmetic unit, as the predetermined condition, identifies a plurality of factor scenarios that satisfy that the coincidence rate is within a predetermined ranking of the top positions, configured as, a state diagnosis device.

4. In the state diagnosis device according to Claim 2, the arithmetic unit, As the predetermined condition, identify one or more factor scenarios that satisfy the condition that the matching rate is equal to or higher than a predetermined threshold value. configured as a state diagnosis device.

5. In the state diagnosis device according to claim 1, the arithmetic unit In the identified factor scenario, if the component causing the non-safe action is not a main component of the analysis model, reselect factor scenario data including an analysis model in which the component causing the non-safe action is a main component and a plurality of factor scenarios corresponding to the analysis model, Perform the collation process again using the plurality of factor scenarios of the reselected factor scenario data, and based on the collation result, re-identify one or more factor scenarios that satisfy a predetermined condition, Based on the re-identified factor scenario and the reselected analysis model, identify the factor occurrence site that is the cause of the specific event occurring. configured as a state diagnosis device.

6. In the state diagnosis device according to claim 1, the arithmetic unit Based on an analysis model input from the outside, create a plurality of factor scenarios corresponding to the analysis model, and store factor scenario data including the input analysis model and the created plurality of factor scenarios in the storage device. configured as a state diagnosis device.

7. In the state diagnosis device according to claim 1, the arithmetic unit Extract information related to hardware failures included in the log data, and perform hardware diagnosis to identify the hardware failure site. configured as a state diagnosis device.

8. In the state diagnosis device according to claim 1, the arithmetic unit Output the identified factor scenario and information indicating the factor occurrence site that is the cause of the specific event occurring to an external device. configured as a state diagnosis device.

9. In the state diagnosis device according to claim 7, the arithmetic unit Output information indicating the identified factor scenario and the factor occurrence site that is the cause of the specific event occurring, and information indicating the hardware failure site identified by the hardware diagnosis to an external device. configured as a state diagnosis device.

10. A state diagnosis method using a computer that includes an arithmetic unit and a storage device and processes a plurality of log data acquired at a plurality of time points transmitted from an edge system including a plurality of subsystems to perform state diagnosis of the edge system, wherein the storage device stores an analysis model for each of the subsystems, which is a safety analysis result for the edge system, and a plurality of factor scenario data including the states of a plurality of data items corresponding to the analysis model and factor scenarios indicated by non-safe actions of data that trigger the occurrence of events, by the arithmetic unit, store a plurality of the log data in the storage device, when detecting the occurrence of a specific event from a plurality of the log data, identify the subsystem of the edge system related to the occurrence of the specific event from the content of the specific event, extract a plurality of factor scenarios corresponding to the subsystem from the factor scenario data stored in the storage device based on the identified subsystem, for each of the plurality of extracted factor scenarios, extract data having the same data items as the data items included in each of the plurality of extracted factor scenarios from the log data, and perform a collation process of collating whether the contents of the same data items match between each of the plurality of factor scenarios and the data having the same data items extracted, and identify one or more factor scenarios that satisfy a predetermined condition based on the collation result, identify a factor occurrence site that is a factor for the occurrence of the specific event based on the identified factor scenario and the analysis model corresponding to the identified subsystem, state diagnosis method.

Citation Information

Patent Citations

  • Anteikitoritsukedai

    JP1976081479A