Control apparatus, control method, and storage medium

The control device addresses the challenge of safely managing user application control requests by using state-based judgment to ensure vehicle safety and user value through a control device with acquisition and judgment units.

JP2026003717APending Publication Date: 2026-01-14PANASONIC AUTOMOTIVE SYST CO LTD
View PDF 1 Cites 0 Cited by

Patent Information

Application Number
JP2024101725
Authority / Receiving Office
JP · JP
Patent Type
Applications
Current Assignee / Owner
Filing Date
2024-06-25
Publication Date
2026-01-14

AI Technical Summary

Technical Problem

Existing technologies fail to appropriately determine whether to permit control requests from user applications to vehicle devices, potentially compromising vehicle safety or reducing user value due to unsafe or inappropriate operations.

Method used

A control device that includes a first acquisition unit for acquiring control requests from user applications, a second acquisition unit for acquiring vehicle state information, and a judgment unit to determine whether to grant control requests based on the vehicle's state, ensuring safe execution of user application commands.

Benefits of technology

The solution allows for more appropriate determination of user application control requests, enhancing vehicle safety by preventing unsafe operations and maintaining user value.

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure 2026003717000001_ABST
    Figure 2026003717000001_ABST
Patent Text Reader

Abstract

To provide a control device and the like capable of more appropriately determining whether or not to permit a control request from a user application to a vehicle device.SOLUTION: A control device 30 is mounted on a vehicle 1 including a vehicle device, and includes a first acquisition part 31 for acquiring a control request of the vehicle device from a user application, a second acquisition part 32 for acquiring a vehicle state of the vehicle 1, and a determination part 33 for determining propriety of the control request on the basis of the vehicle state.SELECTED DRAWING: Figure 1
Need to check novelty before this filing date? Find Prior Art

Description

[Technical Field]

[0001] The present disclosure relates to a control device, a control method, and a program to be mounted on a vehicle. [Background technology]

[0002] Patent Document 1 discloses a technique that, when various types of applications can be executed on a vehicle device, can prevent unnecessary execution of applications that are not required for the intended use of the vehicle. [Prior art documents] [Patent documents]

[0003] [Patent Document 1] Japanese Patent Application Laid-Open No. 2014-233998 Summary of the Invention [Problem to be solved by the invention]

[0004] In this case, it is assumed that a user application issues a control request to a vehicle device. In this case, it is necessary to determine whether to permit the control request from the user application to the vehicle device. However, it is desirable to make this determination more appropriately.

[0005] Therefore, the present disclosure provides a control device, a control method, and a program that can more appropriately determine whether to permit a control request from a user application to a vehicle device. [Means for solving the problem]

[0006] A control device according to one embodiment of the present disclosure is a control device mounted on a vehicle, and includes a first acquisition unit that acquires a control request from a user application to a vehicle device of the vehicle, a second acquisition unit that acquires a vehicle state of the vehicle, and a judgment unit that judges whether or not to grant the control request based on the vehicle state.

[0007] A control method according to one aspect of the present disclosure is a control method executed by a control device installed in a vehicle, which obtains a control request from a user application to a vehicle device of the vehicle, obtains the vehicle state of the vehicle, and determines whether or not to grant the control request based on the vehicle state.

[0008] A program according to one aspect of the present disclosure is a program for causing a computer to execute the above control method. [Effects of the Invention]

[0009] According to one aspect of the present disclosure, it is possible to realize a control device or the like that can more appropriately determine whether to permit a control request from a user application to a vehicle device. [Brief explanation of the drawings]

[0010] [Figure 1] FIG. 1 is a block diagram showing the configuration of a vehicle including a control device according to an embodiment. [Figure 2] FIG. 2 is a flowchart showing the operation of the control device according to the embodiment. DETAILED DESCRIPTION OF THE INVENTION

[0011] (Background to this disclosure) Before describing the embodiments of the present disclosure, the background to the present disclosure will be described.

[0012] In the future, it is expected that functions will be able to be added to vehicles by user applications, as with smartphones. In other words, it is expected that control of vehicle devices will be released to user applications. The released functions may not be functions that are directly related to the life or death of vehicle occupants. Hereinafter, applications (application programs) will also be referred to as apps, and user applications will also be referred to as user apps.

[0013] A user application is an application that is different from an application (system application) that is pre-installed in a vehicle. User applications include, for example, applications that become executable by a user operation (or contract), and applications installed by a user. A user application may be, for example, an application that can execute functions with higher performance than those that a system application can execute. A user application is an application that controls a vehicle device that is the target of control of a system application, instead of the system application or together with the system application.

[0014] When such user applications are used, it is desirable to safely control vehicle devices from the user applications. However, depending on the vehicle's state, such as when driving or passing through an intersection, the vehicle may be in a dangerous state. Furthermore, such user applications may include applications that perform operations not intended by the manufacturer or applications that are difficult to control. Allowing all control requests from such user applications to vehicle devices may compromise the safety of the vehicle. Denying all control requests from such user applications to vehicle devices may reduce the user value provided by the user applications. Therefore, it is desirable to allow control requests from user applications when appropriate and deny control requests from user applications when inappropriate. In other words, it is desirable to more appropriately determine whether to allow control requests from user applications to vehicle devices. However, Patent Document 1 does not disclose such a technology.

[0015] Therefore, the present inventors have conducted extensive research into a control device etc. that can more appropriately determine whether to permit a control request from a user application to a vehicle device, and have devised the following control device etc. Specifically, the present inventors have devised a control device etc. that can permit or block a control request from a user application to a vehicle device depending on the vehicle state.

[0016] Hereinafter, the embodiments will be specifically described with reference to the drawings.

[0017] The embodiments described below are all comprehensive or specific examples. The numerical values, shapes, components, component placement and connection configurations, steps, and step order shown in the following embodiments are merely examples and are not intended to limit the present disclosure. Furthermore, among the components in the following embodiments, components not described in independent claims are described as optional components.

[0018] Furthermore, each figure is a schematic diagram and is not necessarily an exact illustration. Therefore, for example, the scales of the figures do not necessarily match. Furthermore, in each figure, substantially the same components are given the same reference numerals, and redundant explanations are omitted or simplified.

[0019] Furthermore, in this specification, numerical values ​​and numerical ranges are not expressions that express only the strict meaning, but are expressions that mean that they include a substantially equivalent range, for example, a difference of about several percent (or about 10%).

[0020] Furthermore, in this specification, ordinal numbers such as "first" and "second" do not refer to the number or order of components unless otherwise specified, but are used for the purpose of avoiding confusion and distinguishing between components of the same type.

[0021] (Embodiment) The control device according to this embodiment will be described below with reference to FIGS.

[0022] [1. Control device configuration] First, the configuration of a vehicle having a control device according to this embodiment will be described with reference to Fig. 1. Fig. 1 is a block diagram showing the configuration of a vehicle 1 including a control device 30 according to this embodiment. Note that Fig. 1 shows an exemplary functional configuration of the control device 30, and the functional configuration of the control device 30 is not limited to that shown in Fig. 1.

[0023] 1, the vehicle 1 includes an ECU (Electronic Control Unit) 100, a first vehicle device 200A, and a second vehicle device 200B. The number of vehicle devices included in the vehicle 1 is not limited to two, and may be one or more.

[0024] The ECU 100 is an in-vehicle ECU mounted on the vehicle 1, and controls vehicle devices (equipment) equipped in the vehicle 1. The ECU 100 is a device including, for example, a processor (microprocessor), digital circuits such as memory, analog circuits, communication circuits, etc. The memory is a ROM (Read Only Memory), RAM (Random Access Memory), etc., and can store a control program (computer program) executed by the processor. For example, the processor operates in accordance with the control program (computer program), causing the ECU 100 to realize various functions. This control program includes the above-mentioned user application.

[0025] Note that a plurality of ECUs 100 are mounted on the vehicle 1. For example, the plurality of ECUs 100 can communicate with each other via an in-vehicle communication network (more specifically, a bus to which each of the ECUs 100 is connected). At least one of the plurality of ECUs 100 may have the configuration shown in FIG. 1.

[0026] The ECU 100 may be an ECU (a so-called zone ECU) that is arranged in the vehicle 1 and controls vehicle devices in the area where it is arranged, or may be a central ECU that integrates multiple ECUs (a so-called integrated ECU).The integrated ECU is an ECU that integrates functions that were previously separated and installed in multiple ECUs in order to solve the problem of increasing development time or cost as in-vehicle systems become more complex, and is an ECU that uses virtualization technology to operate multiple virtual computers (virtual machines: VMs) on one ECU.

[0027] The ECU 100 functions as a control device that controls vehicle devices by executing installed user applications. The ECU 100 includes a first processing unit 10A, a second processing unit 10B, a vehicle behavior monitoring unit 20, and a control device 30. The number of user applications included in the ECU 100 is not limited to two, but may be one or more. The ECU 100 also includes a system application (not shown). Hereinafter, the system application will also be referred to as a system app. The system app may be included in the above-mentioned control program. The ECU 100 may further include a processing unit (not shown) that executes the system app.

[0028] The first processing unit 10A and the second processing unit 10B are processing units that execute user applications different from system applications. Specifically, the first processing unit 10A is a processing unit that executes a "first user application" shown in Fig. 1, and the second processing unit 10B is a processing unit that executes a "second user application" shown in Fig. 1.

[0029] The user application is, for example, an application created by a business operator different from the manufacturer of the system application. The first processing unit 10A and the second processing unit 10B are configured to be able to control the vehicle devices of the vehicle 1 by executing the user application. The first processing unit 10A and the second processing unit 10B output a control request to the control device 30 to request control of the vehicle devices of the vehicle 1, and can control the vehicle devices when the control request is permitted by the control device 30. The control request includes identification information (e.g., ID) indicating the vehicle device to be controlled and the control content.

[0030] The first processing unit 10A and the second processing unit 10B are applications that control different vehicle devices, but may be applications that control a common vehicle device. Hereinafter, an example will be described in which the first processing unit 10A controls the first vehicle device 200A and the second processing unit 10B controls the second vehicle device 200B.

[0031] In this way, the ECU 100 according to this embodiment is configured to allow the user application to run.

[0032] The vehicle behavior monitoring unit 20 has a function of monitoring the behavior of the vehicle, and monitors the vehicle state including the vehicle behavior. The vehicle behavior monitoring unit 20 may monitor the vehicle state by acquiring sensing data from multiple sensors mounted on the vehicle 1. Examples of the multiple sensors include, but are not limited to, a speed sensor, an acceleration sensor, a position sensor (e.g., a GPS (Global Positioning System) sensor), a steering angle sensor, a camera, an obstacle sensor, and an illuminance sensor. The camera may be a camera that captures images inside the vehicle 1, or a camera that captures images outside the vehicle 1. The obstacle sensor is, for example, a sensor that detects obstacles around the vehicle 1 using LiDAR (Light Detection And Ranging) or the like, but is not limited to this. The illuminance sensor may measure the illuminance outside the vehicle, or the illuminance inside the vehicle.

[0033] The vehicle behavior monitoring unit 20 acquires, from a plurality of sensors, at least one of the speed, position, steering angle, traveling direction, and surrounding environment of the vehicle 1 as the vehicle state. The vehicle behavior monitoring unit 20 may also acquire (e.g., identify) whether the vehicle 1 is traveling at a low speed, a high speed, or a stopped state based on the speed. A low speed may, for example, mean traveling at a speed below a threshold, and a high speed may, for example, mean traveling at a speed equal to or greater than the threshold. The vehicle behavior monitoring unit 20 may also acquire (e.g., identify) whether the vehicle 1 is traveling at a predetermined point or a predetermined area based on the location. The vehicle behavior monitoring unit 20 can, for example, identify whether the vehicle 1 is passing through an intersection or crossing a pedestrian crossing based on the location.

[0034] The vehicle behavior monitoring unit 20 may also acquire (for example, identify) as the vehicle state whether the vehicle 1 is traveling around a curve or going straight, based on the steering angle. The vehicle behavior monitoring unit 20 may also acquire (for example, identify) as the vehicle state whether the vehicle 1 is moving forward or backward, based on the traveling direction. The vehicle behavior monitoring unit 20 may also acquire (for example, identify) as the vehicle state whether the surroundings of the vehicle 1 are dark, based on the illuminance value of an illuminance sensor. The vehicle behavior monitoring unit 20 may also acquire (for example, identify) as the vehicle state whether the vehicle 1 is in parking mode, based on the shift lever. The vehicle behavior monitoring unit 20 may also acquire as the vehicle state the current driving mode of the vehicle 1. Examples of driving modes include an autonomous driving mode and a follow-up driving mode using adaptive cruise control (ACC). The parking mode may also be included in the driving mode. The vehicle behavior monitoring unit 20 may also acquire as the vehicle state whether the vehicle 1 is in autonomous driving or ACC operation.

[0035] The control device 30 determines whether to permit a control request from the first processing unit 10A or the second processing unit 10B based on the vehicle state. The control device 30 includes a first acquisition unit 31, a second acquisition unit 32, and a determination unit 33. Note that, hereinafter, a control request output by the first processing unit 10A executing a first user application will also be referred to as a control request from the first user application, and a control request output by the second processing unit 10B executing a second user application will also be referred to as a control request from the second user application.

[0036] The first acquisition unit 31 is a communication interface that acquires control requests for vehicle devices from the first user application and the second user application. For example, the first acquisition unit 31 acquires a control request for the first vehicle device 200A from the first user application and a control request for the second vehicle device 200B from the second user application, but is not limited to this. The first acquisition unit 31 is configured to include, for example, a communication circuit (or a communication module).

[0037] The second acquisition unit 32 is a communication interface that acquires the vehicle state of the vehicle 1 from the vehicle behavior monitoring unit 20. The second acquisition unit 32 acquires, for example, the vehicle state of the vehicle 1 at the time when the first acquisition unit 31 acquires a control request. The second acquisition unit 32 is configured to include, for example, a communication circuit (or a communication module).

[0038] The determination unit 33 determines whether to permit the control request acquired by the first acquisition unit 31 based on the vehicle state acquired by the second acquisition unit 32. The determination unit 33 determines whether to permit the control request based on whether the vehicle 1 will be in a dangerous state (for example, a dangerous state for the vehicle 1 to travel) if the control request is executed in the vehicle state. For example, the determination unit 33 determines not to permit the control request when it is predicted that the vehicle 1 will be in a dangerous state if the control request is executed in the vehicle state.

[0039] Furthermore, the determination unit 33 is configured to be able to determine whether the control request acquired by the first acquisition unit 31 is a control request from a user application or a system application. For example, when the user application does not have a predetermined authority (e.g., system authority) and the system application has the predetermined authority (e.g., system authority), the determination unit 33 may distinguish whether the control request is from a user application or a system application depending on whether the control request is output from an application that has the predetermined authority. When the control request is from a system application, the determination unit 33 permits the control request regardless of the vehicle state.

[0040] The first vehicle device 200A and the second vehicle device 200B are in-vehicle devices communicatively connected to the ECU 100 via an in-vehicle communication network and controlled by the ECU 100. The first vehicle device 200A and the second vehicle device 200B are physical devices mounted on the vehicle 1. The first vehicle device 200A and the second vehicle device 200B are lights (e.g., headlights), display devices, electronic mirrors, interior lights, etc. The display devices may be, for example, a display device included in a car navigation system or a rearview monitor. The first vehicle device 200A and the second vehicle device 200B may also be power windows, air conditioners, locking / unlocking devices, audio equipment, etc. The first vehicle device 200A and the second vehicle device 200B may be a common in-vehicle device or may be different in-vehicle devices.

[0041] [2. Operation of the control device] Next, the operation of the control device 30 configured as above will be described with reference to Fig. 2. Fig. 2 is a flowchart showing the operation (control method) of the control device 30 according to this embodiment.

[0042] 2, the first acquisition unit 31 determines whether a control request for a vehicle device has been acquired from a user application (S10). If the first acquisition unit 31 has acquired a control request from the first user application or the second user application, the first acquisition unit 31 determines YES in step S10. If the first acquisition unit 31 has acquired a control request from a system application, the first acquisition unit 31 determines NO in step S10. If the determination in step S10 is NO, the process returns to step S10 and continues.

[0043] Next, when it is determined that the first acquisition unit 31 has acquired a control request for a vehicle device from the user application (YES in S10), that is, when the first acquisition unit 31 has acquired a control request for a vehicle device from the user application, the second acquisition unit 32 acquires the vehicle state of the vehicle 1 from the vehicle behavior monitoring unit 20 (S20). Note that the vehicle state is not limited to being acquired as a trigger when the first acquisition unit 31 acquires a control request from the user application, and may be acquired, for example, periodically or when the vehicle state changes.

[0044] Next, the determination unit 33 determines whether or not the control request for the vehicle device is safe in the vehicle state (for example, the current vehicle state) acquired by the second acquisition unit 32 (S30). The determination unit 33 determines whether or not the vehicle 1 will be in a dangerous state (i.e., whether or not it is safe) if the control request for the vehicle device is executed in the vehicle state. A dangerous state for the vehicle 1 includes, for example, a state in which the vehicle 1 is in a dangerous state.

[0045] Here, a specific example of the determination by the determination unit 33 as to whether it is safe or not will be illustrated.

[0046] For example, when the vehicle state includes a state in which the vehicle 1 is traveling and the control request from the user application includes switching the headlamp beam of the vehicle 1, the determination unit 33 determines that switching the headlamp beam will put the vehicle 1 in a dangerous state and determines not to permit the control request. Switching the headlamp beam includes switching from one high beam to the other low beam. For example, when the speed of the vehicle 1 is equal to or greater than a threshold and the control request from the user application includes switching the headlamp beam of the vehicle 1, the determination unit 33 determines not to permit the control request. For example, when the control request from the user application is to switch the headlamp beam of the vehicle 1, the determination unit 33 may determine that it is unsafe if the vehicle 1 is traveling at high speed, and may determine that it is safe if the vehicle 1 is traveling at low speed.

[0047] Furthermore, for example, when the vehicle state includes a state in which the vehicle is reversing and the control request from the user application includes a request to superimpose a display on the rearview monitor of the vehicle 1, the determination unit 33 determines that the superimposed display will put the vehicle 1 in a dangerous state and determines not to permit the control request. Superimposing a display on the rearview monitor includes, for example, superimposing a pop-up on the rearview monitor while the vehicle is reversing. For example, when the control request from the user application includes a request to superimpose a display on the rearview monitor of the vehicle 1, the determination unit 33 may determine that it is unsafe when the vehicle 1 is reversing and may determine that it is safe when the vehicle 1 is not reversing.

[0048] Furthermore, for example, if the vehicle state includes a state in which the vehicle is traveling in a dark environment and the control request from the user application includes a request to turn on the interior lights of the vehicle 1, the determination unit 33 determines that turning on the interior lights would make it difficult to see ahead and therefore put the vehicle 1 in a dangerous state, and determines not to permit the control request. Whether the environment is dark can be determined based on the illuminance value measured by the illuminance sensor. In this way, the surrounding environment of the vehicle 1 is also included in the vehicle state. For example, if the control request from the user application includes a request to turn on the interior lights of the vehicle 1, the determination unit 33 may determine that the vehicle 1 is unsafe when traveling in a dark environment and that the vehicle 1 is safe when traveling in a bright environment.

[0049] Furthermore, for example, when the vehicle state includes a state in which the vehicle is moving and the control request from the user application includes displaying an image to the driver of the vehicle 1, the determination unit 33 determines that displaying an image will distract the driver and put the vehicle 1 in a dangerous state, and determines not to permit the control request. For example, when the control request from the user application includes displaying an image to the driver of the vehicle 1, the determination unit 33 may determine that it is unsafe when the vehicle 1 is moving and that it is safe when the vehicle 1 is stopped. Note that the image may be a moving image or a still image.

[0050] Furthermore, for example, if the vehicle 1 has an electronic mirror that can switch between an image display function and a mirror function, and the vehicle state includes being in motion and the control request from the user application includes turning on the mirror function of the electronic mirror, the determination unit 33 determines that the vehicle 1 will be in a dangerous state due to a lack of awareness of the road ahead, and determines not to permit the control request. The mirror function is a function that displays an image captured by an in-vehicle camera on the electronic mirror. For example, it is used when a passenger checks their appearance. For example, if the control request from the user application includes turning on the mirror function of the electronic mirror, the determination unit 33 may determine that it is unsafe when the vehicle 1 is in motion and that it is safe when the vehicle 1 is stopped.

[0051] The method of the determination unit 33 is not particularly limited. For example, the determination unit 33 may make the above determination based on a table in which vehicle states and control requests are associated with whether it is safe (i.e., whether to permit the control request). The table is created in advance and stored in a storage unit (not shown) included in the vehicle 1. The storage unit may be realized, for example, by a semiconductor memory, a HDD, or the like, but is not limited to these. Furthermore, for example, the determination unit 33 may make the above determination by inputting the acquired vehicle state and control request into a machine learning model that has been trained by machine learning using the vehicle state and control request as input data and whether it is safe as correct answer data.

[0052] Next, when the determination unit 33 determines that the vehicle device control request is safe in the vehicle state (YES in S30), that is, when the determination unit 33 determines that the vehicle 1 is safe, it determines to permit the vehicle device control request (S40) and outputs the control request to the vehicle device to be controlled. For example, the determination unit 33 transfers the control request to the vehicle device to be controlled.

[0053] As a result, if the vehicle 1 is safe, the control request from the user application is executed in the vehicle device to be controlled. This makes it possible to improve the user value provided by the user application while ensuring the safety of the vehicle 1. Note that a determination of YES in step S30 means that the vehicle 1 is determined to be safe.

[0054] Furthermore, when the determination unit 33 determines that the control request for the vehicle device is not safe in the vehicle state (NO in S30), that is, when the determination unit 33 determines that the vehicle 1 is not safe (unsafe), the determination unit 33 determines that the control request for the vehicle device is not permitted (S50) and does not output the control request to the vehicle device to be controlled. In other words, the determination unit 33 prohibits the output of the control request to the vehicle device to be controlled.

[0055] In this way, the control device 30 can stop the control request from the user application to the vehicle device if necessary depending on the vehicle state of the vehicle 1. If the vehicle 1 is in a dangerous state, the control request from the user application is not executed, so the safety of the vehicle 1 can be ensured.

[0056] (Other embodiments) Although the control device according to one or more aspects has been described above based on the embodiments, the present disclosure is not limited to these embodiments. As long as it does not deviate from the spirit of the present disclosure, various modifications conceivable by a person skilled in the art to the present embodiments and embodiments constructed by combining components of different embodiments may also be included in the present disclosure.

[0057] For example, in the above embodiment, an example has been described in which the vehicle 1 includes one ECU 100, but the vehicle 1 may include a plurality of ECUs 100. For example, the first processing unit 10A included in the first ECU may control a vehicle device that is a control target of a second ECU different from the first ECU via the control device 30. For example, a user application may be capable of controlling a vehicle device that is a control target of a second ECU different from the first ECU in which the user application is installed.

[0058] In addition, in the above embodiment, the judgment unit 33 may store a control request that has been determined to be disallowed in a memory unit (not shown), and when the vehicle state transitions to a state in which the stored control request is allowed, the judgment unit 33 may allow the control request and execute it in the corresponding vehicle device.

[0059] Furthermore, in the above embodiment, the determination unit 33 determines whether the result in step S30 is YES or NO. However, this is not limiting and the determination may be YES, NO, or a restricted mode. The restricted mode is, for example, a mode in which execution of a control request is restricted. For example, when the determination unit 33 determines not to permit a control request from a user application and a specific condition is met, the determination unit 33 may determine to permit execution of the control request with restrictions. For example, when the vehicle 1 is backing up and a rearview is displayed in part of the rearview monitor, and the control request from the user application includes superimposing a display on the rearview monitor of the vehicle 1, the determination unit 33 may determine to superimpose the display on an area of ​​the rearview monitor other than the area where the rearview is displayed. An example of a specific condition is when the rearview is displayed only in part of the display screen of the rearview monitor, for example, there is an empty area in the display area of ​​the rearview monitor. Furthermore, superimposing a display on an area other than the area where the rearview is displayed is an example of executing a control request with restrictions. Furthermore, for example, when it is determined that a control request from a user application is permitted, if a specific condition is satisfied, the determination unit 33 may determine that execution of the control request is permitted with restrictions.

[0060] In the above embodiments, each component may be configured with dedicated hardware, or may be realized by executing a software program suitable for each component. Each component may be realized by a program execution unit such as a CPU or processor reading and executing a software program recorded on a recording medium such as a hard disk or semiconductor memory.

[0061] The order in which the steps in the flowchart are executed is merely an example for specifically explaining the present disclosure, and an order other than the above may be used. Also, some of the steps may be executed simultaneously (in parallel) with other steps, or some of the steps may not be executed.

[0062] The division of functional blocks in the block diagram is an example, and multiple functional blocks may be realized as a single functional block, one functional block may be divided into multiple blocks, or some functions may be moved to another functional block.Furthermore, the functions of multiple functional blocks having similar functions may be processed in parallel or in time-sharing by a single piece of hardware or software.

[0063] Furthermore, the control device 30 according to the above embodiment may be realized as a single device or may be realized by multiple devices. When the control device 30 is realized by multiple devices, the components of the control device 30 may be distributed among the multiple devices in any manner. When the control device 30 is realized by multiple devices, the communication method between the multiple devices is not particularly limited, and may be wireless communication or wired communication. Furthermore, wireless communication and wired communication may be combined between the devices.

[0064] Furthermore, each component described in the above embodiments may be implemented as software or, typically, as an LSI, which is an integrated circuit. These components may be individually integrated into a single chip, or some or all of them may be integrated into a single chip. While LSI is used here, it may also be referred to as an IC, system LSI, super LSI, or ultra LSI depending on the level of integration. Furthermore, the integration method is not limited to LSI; it may be implemented using a dedicated circuit (a general-purpose circuit that executes a dedicated program) or a general-purpose processor. It is also possible to use a field programmable gate array (FPGA), which can be programmed after LSI fabrication, or a reconfigurable processor, which allows the connection or settings of circuit cells within an LSI to be reconfigured. Furthermore, if an integrated circuit technology that can replace LSI emerges due to advances in semiconductor technology or a derivative technology, that technology may naturally be used to integrate the components.

[0065] A system LSI is an ultra-multifunctional LSI manufactured by integrating multiple processing units on a single chip, and is specifically a computer system consisting of a microprocessor, ROM, RAM, etc. The ROM stores computer programs. The system LSI achieves its functions when the microprocessor operates in accordance with the computer programs.

[0066] Another aspect of the present disclosure may be a computer program that causes a computer to execute each of the characteristic steps included in the control method shown in FIG.

[0067] Furthermore, for example, the program may be a program to be executed by a computer. Another aspect of the present disclosure may be a computer-readable non-transitory recording medium on which such a program is recorded. For example, such a program may be recorded on a recording medium and distributed or circulated. For example, the distributed program may be installed in a device having another processor, and the program may be executed by the processor, thereby causing the device to perform each of the above processes.

[0068] (Addendum) The above description of the embodiments discloses the following techniques.

[0069] (Technology 1) The control device 30 is a control device mounted on a vehicle, and includes a first acquisition unit that acquires a control request from a user application to a vehicle device of the vehicle, a second acquisition unit that acquires a vehicle state of the vehicle, and a judgment unit that judges whether or not the control request is acceptable based on the vehicle state.

[0070] This allows the determination of whether to permit a control request from a user application to a vehicle device to be made based on the vehicle state, thereby making it possible to more appropriately determine whether to permit a control request from a user application to a vehicle device, for example, compared to when vehicle information is not used.

[0071] (Technology 2) The determination unit is the control device 30 of the first technique that determines whether or not the control request is valid based on whether or not the vehicle will be in a dangerous state if the control request is executed in the vehicle state.

[0072] This allows the determination of whether to permit a control request from a user application depending on whether the vehicle will be in a dangerous state. Therefore, for example, not permitting a control request can prevent the vehicle from being in a dangerous state, so it is possible to more appropriately determine whether to permit a control request from a user application to a vehicle device.

[0073] (Technology 3) The determination unit is the control device 30 of Technique 2 that determines not to permit the control request when executing the control request in the vehicle state would put the vehicle in a dangerous state.

[0074] This makes it possible to more reliably ensure the safety of the vehicle 1, since a control request is not permitted if the vehicle is in a dangerous state.

[0075] (Technology 4) The vehicle state includes at least one of the speed, position, steering angle, traveling direction, surrounding environment, and driving mode of the vehicle, according to the control device 30 of any one of the techniques 1 to 3.

[0076] This allows the determination of whether to permit a control request from a user application using information obtainable from sensors mounted on the vehicle, such as at least one of the vehicle's speed, position, steering angle, traveling direction, surrounding environment, and driving mode. This makes it possible to more appropriately determine whether to permit a control request from a user application to a vehicle device while minimizing the complexity of the vehicle configuration.

[0077] (Technology 5) The user application is a control device 30 according to any one of techniques 1 to 4, which is an application different from the application pre-installed in the vehicle.

[0078] This makes it possible to more appropriately determine whether to permit a control request from an application other than the application pre-installed in the vehicle.

[0079] (Technology 6) The control device 30 is any one of techniques 1 to 5, wherein, when the vehicle state is in motion and the control request includes switching the beam of the vehicle's headlights, the judgment unit judges that the control request is not permitted.

[0080] This allows the control request for switching the headlamp beam to be executed when the vehicle is safe, thereby ensuring vehicle safety and improving user value through user applications.

[0081] (Technology 7) The control device 30 is any one of techniques 1 to 6, wherein if the speed of the vehicle is equal to or greater than a threshold and the control request includes switching the beam of the vehicle's headlights, the judgment unit judges that the control request is not permitted.

[0082] This allows the control request for switching the headlamp beam to be executed when the vehicle is safe, thereby ensuring vehicle safety and improving user value through user applications.

[0083] (Technology 8) The control device 30 is any one of techniques 1 to 7, wherein, when the vehicle state is in reverse and the control request includes superimposing a display on a rearview monitor of the vehicle, the judgment unit judges that the control request is not permitted.

[0084] This allows the control request to superimpose a display on the rearview monitor to be executed when the vehicle is safe, thereby improving the user value provided by the user application while ensuring the safety of the vehicle.

[0085] (Technology 9) The control device 30 is any one of techniques 1 to 8, wherein if the vehicle state is traveling in a dark environment and the control request includes turning on the interior lights of the vehicle, the judgment unit judges that the control request is not permitted.

[0086] This allows a control request to turn on the interior lights of the vehicle to be executed when the vehicle is safe, thereby improving the user value provided by the user application while ensuring the safety of the vehicle.

[0087] (Technology 10) The control device 30 is any one of techniques 1 to 9, wherein if the vehicle state is in motion and the control request includes displaying an image to the driver of the vehicle, the judgment unit determines that the control request is not permitted.

[0088] This allows the control request to display an image to the driver of the vehicle to be executed when the vehicle is safe, thereby ensuring the safety of the vehicle and improving the user value provided by the user application.

[0089] (Technology 11) The control device 30 is any one of techniques 1 to 10, in which the vehicle has an electronic mirror that can switch between an image display function and a mirror function, the vehicle state is moving, and if the control request includes turning on the mirror function of the electronic mirror, the judgment unit judges that the control request is not permitted.

[0090] This allows the control request to turn on the mirror function of the electronic mirror to be executed when the vehicle is safe, thereby ensuring the safety of the vehicle and improving the user value provided by the user application.

[0091] (Technology 12) A control method executed by a control device mounted on a vehicle, the control method acquiring a control request to a vehicle device of the vehicle from a user application, acquiring a vehicle state of the vehicle, and determining whether or not to grant the control request based on the vehicle state.

[0092] This provides the same effects as the above-described control device.

[0093] (Technology 13) This is a program for executing the control method of Technology 12.

[0094] This provides the same effects as the above-described control device.

[0095] These general or specific aspects may be realized as a system, a method, an integrated circuit, a computer program, or a non-transitory recording medium such as a computer-readable CD-ROM, or as any combination of the system, method, integrated circuit, computer program, or recording medium. The program may be pre-stored in the recording medium, or may be supplied to the recording medium via a wide area communication network including the Internet. [Industrial Applicability]

[0096] The present disclosure is useful for a control device or the like mounted on a vehicle. [Explanation of symbols]

[0097] 1 vehicle 10A First processing section 10B Second processing section 20 Vehicle Behavior Monitoring Department 30 Control device 31 First acquisition part 32 Second acquisition part 33 Judgment Department 100 ECU 200A First vehicle device 200B Second vehicle device

Claims

1. A control device mounted on a vehicle, a first acquisition unit that acquires a control request from a user application to a vehicle device of the vehicle; a second acquisition unit that acquires a vehicle state of the vehicle; a determination unit that determines whether or not the control request is valid based on the vehicle state. Control device.

2. The determination unit determines whether or not the control request is valid based on whether or not the vehicle will be in a dangerous state if the control request is executed in the vehicle state. The control device according to claim 1 .

3. The determination unit determines not to permit the control request when the vehicle would be in a dangerous state if the control request is executed in the vehicle state. The control device according to claim 2 .

4. The vehicle state includes at least one of the speed, position, steering angle, traveling direction, surrounding environment, and driving mode of the vehicle. The control device according to any one of claims 1 to 3.

5. The user application is an application different from the application pre-installed in the vehicle. The control device according to any one of claims 1 to 3.

6. When the vehicle state is in motion and the control request includes switching the beam of the headlights of the vehicle, the determination unit determines that the control request is not permitted. The control device according to any one of claims 1 to 3.

7. When the speed of the vehicle is equal to or greater than a threshold and the control request includes switching the beam of the headlights of the vehicle, the determination unit determines that the control request is not permitted. The control device according to any one of claims 1 to 3.

8. When the vehicle state is reverse driving and the control request includes superimposing a display on a rearview monitor of the vehicle, the determination unit determines that the control request is not permitted. The control device according to any one of claims 1 to 3.

9. When the vehicle state is that the vehicle is traveling in a dark environment and the control request includes turning on an interior light of the vehicle, the determination unit determines that the control request is not permitted. The control device according to any one of claims 1 to 3.

10. When the vehicle state is a moving vehicle and the control request includes displaying an image to a driver of the vehicle, the determination unit determines that the control request is not permitted. The control device according to any one of claims 1 to 3.

11. The vehicle has an electronic mirror that can switch between an image display function and a mirror function, When the vehicle state is a driving state and the control request includes turning on the mirror function of the electronic mirror, the determination unit determines that the control request is not permitted. The control device according to any one of claims 1 to 3.

12. A control method executed by a control device mounted on a vehicle, obtaining a control request from a user application to a vehicle device of the vehicle; Acquire a vehicle status of the vehicle; Determine whether the control request is valid or not based on the vehicle state. Control method.

13. A program for causing a computer to execute the control method according to claim 12.

Citation Information

Patent Citations

  • Device for vehicle, communication system, and application execution method

    JP2014233998A