Communication control device, communication control method, and communication control program
The communication control device and method address network setting-induced errors by restoring settings to their previous state upon detection, maintaining uninterrupted communication.
Patent Information
- Application Number
- JP2025196752
- Authority / Receiving Office
- JP · JP
- Patent Type
- Applications
- Current Assignee / Owner
- Filing Date
- 2025-11-17
- Publication Date
- 2026-01-23
AI Technical Summary
After changing network settings, communication devices may experience errors, leading to communication disruptions.
A communication control device and method that includes a setting unit to manage network changes, an output unit to notify of completion, and a control unit to restore settings to their previous state upon detecting a communication error.
Prevents communication errors by reverting network settings to their previous state when errors occur, ensuring seamless communication.
Smart Images

Figure 2026012566000001_ABST
Abstract
Description
[Technical Field]
[0001] The present invention relates to a communication control device, a communication control method, and a communication control program. [Background technology]
[0002] The use of Software Defined Networking (SDN), which changes the network configuration by software settings without changing the hardware configuration, is increasing. For example, Patent Document 1 discloses a setting device that contributes to updating the settings of communication devices that make up a network while the network is running. [Prior art documents] [Patent documents]
[0003] [Patent Document 1] Japanese Patent Application Laid-Open No. 2017-169044 Summary of the Invention [Problem to be solved by the invention]
[0004] After changing the network settings, when a communication device connected to the network checks continuity with a communication partner, normal communication may not be possible, resulting in a communication error.
[0005] The present invention has been made in consideration of the above points, and aims to provide a communication control device, a communication control method, and a communication control program that prevent a communication error from occurring when a communication error occurs after changing network settings. [Means for solving the problem]
[0006] A communication control device according to a first aspect of the present invention comprises a setting unit that performs processing related to changing network settings, an output unit that outputs a notification that the change in the network settings has been completed to a communication device connected to the network, and a control unit that, when a communication error regarding communication on the network is received from the communication device that communicates in accordance with the change in the network settings based on the notification, performs processing to restore the changed network settings to their state before the change.
[0007] According to the first aspect of the present invention, if a communication error occurs after changing the network settings, the communication error can be prevented from occurring by returning the network settings to the state before they were changed.
[0008] A communication control device according to a second aspect of the present invention is a communication control device according to the first aspect, wherein the control unit determines that the change in the network settings is valid if no communication error is received from the communication device for a predetermined period of time after the change in the network settings.
[0009] According to the second aspect of the present invention, if no communication abnormality is detected after the network settings are changed, the change in the network settings is deemed to be valid, and the network can be controlled.
[0010] A communication control device according to a third aspect of the present invention is the communication control device according to the second aspect, wherein the control unit notifies an external device that the change in the network setting is valid.
[0011] According to the third aspect of the present invention, it is possible to make an external device recognize that a change in network settings is valid.
[0012] A communication control device according to a fourth aspect of the present invention is a communication control device according to any one of the first to third aspects, wherein the control unit performs processing for a communication device connected to the network that has made a change to the network settings that caused a communication error from the communication device, to restore the network settings to the state they were in before the change.
[0013] According to the fourth aspect of the present invention, it is possible to minimize the extent to which network settings are returned to their pre-change state.
[0014] A communication control device according to a fifth aspect of the present invention is a communication control device according to any one of the first to fourth aspects, wherein the communication error is at least one of the following: inability to confirm continuity with the communication device of the communication destination; inability to communicate at a specified cycle; inability to communicate using a specified protocol; and inability to communicate because a specified port is not open.
[0015] According to the fifth aspect of the present invention, a predetermined communication-disabled state can be determined as a communication error.
[0016] A communication control device according to a sixth aspect of the present invention is a communication control device according to any one of the first to fifth aspects, wherein the control unit requests a server that distributed software that caused a change in the network settings to restore the software to its pre-update state.
[0017] According to the sixth aspect of the present invention, it is possible to roll back the software to a state in which no communication error occurs.
[0018] A communication control device according to a seventh aspect of the present invention is a communication control device according to any of the first to sixth aspects, and further includes a monitoring unit that periodically monitors whether or not a communication error has been notified from a communication device connected to the network, and the control unit performs processing for the communication device whose network settings are to be changed to restore the network settings to the state before the change in settings, in response to detection of a communication error notification by the monitoring unit.
[0019] According to the seventh aspect of the present invention, occurrence of a communication error is monitored, and if a communication error occurs as a result of the monitoring, the network settings can be returned to the state before they were changed.
[0020] A communication control device according to an eighth aspect of the present invention is the communication control device according to any one of the first to seventh aspects, wherein the network is an in-vehicle network established in a vehicle.
[0021] According to the eighth aspect of the present invention, when a communication abnormality occurs in a communication device connected to an in-vehicle network, the network settings can be returned to the state before they were changed.
[0022] A ninth aspect of the present invention relates to a communication control method in which a processor performs processing related to changing network settings, notifies a communication device connected to the network that the change in network settings has been completed, and when a communication error regarding communication on the network is received from the communication device that communicates in accordance with the change in network settings based on the notification, performs processing to change the changed network settings back to the state before the change.
[0023] According to the ninth aspect of the present invention, if a communication error occurs after changing the network settings, the communication error can be prevented from occurring by returning the network settings to the state before they were changed.
[0024] A communication control program according to a tenth aspect of the present invention causes a computer to perform processing related to changing network settings, notify a communication device connected to the network that the change in network settings has been completed, and, upon receiving a communication error regarding communication on the network from the communication device that communicates in accordance with the change in network settings based on the notification, perform processing to change the changed network settings back to the state before the change.
[0025] According to the tenth aspect of the present invention, if a communication error occurs after changing the network settings, the communication error can be prevented from occurring by returning the network settings to the state they were in before they were changed. [Effects of the Invention]
[0026] According to the present invention, a communication control device, a communication control method, and a communication control program can be provided that, if a communication error occurs after changing network settings, prevents the communication error by restoring the network settings to their previous state. [Brief explanation of the drawings]
[0027] [Figure 1] 1 is a diagram showing a schematic configuration of a communication system according to an embodiment of the present invention; [Figure 2] FIG. 2 is a block diagram showing a hardware configuration of an ECU. [Figure 3] FIG. 2 is a block diagram illustrating an example of a functional configuration of an ECU. [Figure 4] FIG. 2 is a block diagram showing a hardware configuration of an ECU. [Figure 5] FIG. 2 is a block diagram illustrating an example of a functional configuration of an ECU. [Figure 6] FIG. 2 is a sequence diagram illustrating the operation of each device in the communication system. DETAILED DESCRIPTION OF THE INVENTION
[0028] An example of an embodiment of the present invention will be described below with reference to the drawings. The same reference numerals are used throughout the drawings to designate identical or equivalent components and parts. The dimensional proportions of the drawings are exaggerated for illustrative purposes and may differ from the actual proportions.
[0029] FIG. 1 is a diagram showing a schematic configuration of a communication system according to this embodiment. The communication system shown in FIG. 1 has a configuration in which a vehicle 1 and an OTA (Over The Air) server 20 are connected via a network 30. The vehicle 1 has an antenna 2 and an in-vehicle network, which is an example of a network of the present invention, including ECUs (Electronic Control Units) 10, 200A, 200B, 200C, and 200D, and switches 210A and 210B. The ECUs 10, 200A, 200B, 200C, and 200D and the switches 210A and 210B are connected via Ethernet (registered trademark). Note that the number of ECUs and switches is not limited to the example shown in FIG. 1, and the connection configuration between the ECUs and the switches is not limited to the example shown in FIG. 1.
[0030] The ECU 10 is an ECU that controls the entire in-vehicle network. The ECU 10 communicates with the OTA server 20 via an antenna 2, and exchanges various data with the OTA server 20. The ECUs 200A, 200B, 200C, and 200D are ECUs that control various parts of the vehicle 1. For example, the ECUs 200A, 200B, 200C, and 200D control the operation of devices mounted on the vehicle 1, such as the engine, motor, brakes, camera, and lights.
[0031] Furthermore, the ECU 10 changes the configuration of the in-vehicle network through software settings using SDN technology, without changing the hardware configuration of the in-vehicle network. In other words, when changing the configuration of the in-vehicle network, instead of plugging and unplugging cables or individually configuring each switch 210A, 210B, the switches 210A, 210B are operated under software control using OpenFlow or the like. In detail, the ECU 10 sets the destination of packets transmitted from each ECU to the switches 210A, 210B under software control. The switches 210A, 210B pass or discard packets based on the settings made by the ECU 10.
[0032] The OTA server 20 is a server for updating software for each ECU of the vehicle 1. When an update occurs to the software stored in each ECU of the vehicle 1, the OTA server 20 transmits the updated software to the vehicle 1. When updating the software stored in each ECU of the vehicle 1, the OTA server 20 may automatically transmit the software to the vehicle 1, or the OTA server 20 may transmit the software to the vehicle 1 based on an instruction from a user in the vehicle 1.
[0033] When software of an ECU connected to the in-vehicle network is updated, the updated software may specify new communication with another ECU on the in-vehicle network. For example, as a result of updating software in ECU 200A, ECU 200A may start new communication with ECU 200C via switches 210A and 210B. When software of an ECU connected to the in-vehicle network is updated, ECU 10 changes the communication settings of switches 210A and 210B.
[0034] However, as a result of the software update, there is a possibility that an ECU may experience a communication error. For example, consider a case where software is updated so that ECU 200A starts communication with ECU 200D, and the communication settings of switches 210A and 210B are changed by ECU 10, but communication is not possible even after ECU 200A performs a continuity test with ECU 200D. In such a case, ECU 200A notifies ECU 10 that a communication error has occurred in communication with ECU 200D.
[0035] Therefore, if an ECU in which a communication error has occurred is found as a result of changing the communication settings of the switches 210A and 210B by software, the ECU 10 according to this embodiment returns the communication settings of the switches 210A and 210B to their previous states. The ECU 10 then instructs the OTA server 20 to roll back the software. If an ECU in which a communication error has occurred is found, the ECU 10 according to this embodiment can prevent the ECU from causing a communication error by returning the communication settings of the switches 210A and 210B to their previous states.
[0036] Next, a description will be given of the hardware configuration of the ECU 10. FIG.
[0037] 2, the ECU 10 includes a CPU (Central Processing Unit) 11, a ROM (Read Only Memory) 12, a RAM (Random Access Memory) 13, a storage 14, a first communication interface (I / F) 15, and a second communication interface 16. Each component is connected to each other via a bus 19 so as to be able to communicate with each other.
[0038] The CPU 11 is a central processing unit that executes various programs and controls various components. That is, the CPU 11 reads programs from the ROM 12 or the storage 14 and executes the programs using the RAM 13 as a work area. The CPU 11 controls the above components and performs various arithmetic processing in accordance with the programs recorded in the ROM 12 or the storage 14. In this embodiment, the ROM 12 or the storage 14 stores a communication control program that controls communication of the in-vehicle network of the vehicle 1.
[0039] The ROM 12 stores various programs and various data. The RAM 13 temporarily stores programs or data as a working area. The storage 14 is configured with a storage device such as a flash memory and stores various programs including an operating system and various data.
[0040] The first communication interface 15 is an interface for communicating with the OTA server 20, and uses a wireless communication standard such as 4G, 5G, or Wi-Fi (registered trademark). The second communication interface 16 is an interface for communicating with other devices such as the ECUs 200A to 200D, and uses a wired communication standard such as Ethernet (registered trademark).
[0041] When executing the above communication control program, the ECU 10 uses the above hardware resources to realize various functions. The functional configuration realized by the ECU 10 will be described below.
[0042] FIG. 3 is a block diagram showing an example of the functional configuration of the ECU 10. As shown in FIG.
[0043] 3, the ECU 10 has, as its functional components, an acquisition unit 101, a setting unit 102, a control unit 103, a monitoring unit 104, an output unit 105, and a storage unit 106. Each functional component is realized by the CPU 11 reading and executing a communication control program stored in the ROM 12 or the storage 14. Note that the functions of the acquisition unit 101, the setting unit 102, the control unit 103, the monitoring unit 104, the output unit 105, and the storage unit 106 may be realized in multiple ECUs.
[0044] The acquisition unit 101 acquires data from the OTA server 20 and the ECUs 200A to 200D of the in-vehicle network. In particular, when an update occurs to the software executed in the ECUs 200A to 200D, the acquisition unit 101 acquires new software from the OTA server 20. Furthermore, when necessary in response to an update of the software in the ECUs 200A to 200D, the acquisition unit 101 acquires data for changing the communication settings of the switches 210A and 210B.
[0045] The setting unit 102 performs software-based communication settings for the in-vehicle network. For example, if necessary in response to a software update of the ECUs 200A to 200D, the setting unit 102 changes the communication settings of the switches 210A and 210B. That is, the setting unit 102 changes the configuration of the in-vehicle network through software settings. The changes in communication settings performed by the setting unit 102 include, for example, setting a path that enables communication with a communication partner of the ECU 200, opening or closing a port, setting the priority of packets to be passed, setting the size of a packet queue, setting a bandwidth, and setting packet filtering. For example, when the ECU 200D is newly added to the in-vehicle network, the setting unit 102 performs settings on the switches 210A and 210B for the other ECUs 200A to 200C that communicate with the ECU 200D so that they can communicate with the ECU 200D.
[0046] The switches 210A and 210B hold communication settings in the form of a table, for example, and refer to the table to process frames or packets flowing through the in-vehicle network.
[0047] The control unit 103 controls the operation of the ECU 10 and the in-vehicle network. In particular, when an update occurs to the software executed in the ECUs 200A to 200D, the control unit 103 controls the output unit 105 to output the new software acquired by the acquisition unit 101. Furthermore, when necessary in response to the update of the software in the ECUs 200A to 200D, the control unit 103 controls the output unit 105 to output data required for the change processing of the communication settings in the setting unit 102 to the switches 210A and 210B.
[0048] The monitoring unit 104 monitors the communication status in the in-vehicle network. Specifically, the monitoring unit 104 monitors whether a communication error has been notified from each ECU connected to the in-vehicle network.
[0049] The output unit 105 outputs data to the OTA server 20 and each device in the in-vehicle network. The output of data from the output unit 105 is performed under the control of the control unit 103.
[0050] The storage unit 106 stores various information such as information referenced during operation of the ECU 10 and information used to control the in-vehicle network. In particular, the storage unit 106 stores the communication settings before the change so that, if a communication error occurs in an ECU in the in-vehicle network after the communication settings of the switches 210A and 210B have been changed, the communication settings of the switches 210A and 210B can be restored to their original state.
[0051] After software is updated for at least one of ECUs 200A to 200D and the communication settings of switches 210A and 210B are changed, a communication error may occur in an ECU in the in-vehicle network. When the monitoring unit 104 confirms that the occurrence of the communication error has been notified, it notifies the control unit 103 that an ECU 200 in which a communication error is occurring is present in the in-vehicle network. When the control unit 103 confirms that an ECU 200 in which a communication error is occurring is present in the in-vehicle network due to the software update and the change in the communication settings, it requests the OTA server 20 to perform a rollback to restore the updated software to the software before the update. Then, upon receiving the rollback instruction from the OTA server 20, the control unit 103 reads the communication settings before the change stored in the storage unit 106 and performs control to restore the communication settings of switches 210A and 210B to their original states.
[0052] The control unit 103 may determine that the change in the in-vehicle network setting is valid when a notification of the occurrence of a communication error is not received from the ECU 200 for a predetermined time after the change in the in-vehicle network setting for the switches 210A and 210B. Then, the control unit 103 may notify the OTA server 20 that the change in the in-vehicle network is valid. By receiving the notification from the vehicle 1 that the change in the in-vehicle network is valid, the OTA server 20 can know that the software update has been completed successfully.
[0053] 3, when an ECU that is not the target of the network setting change causes a communication error, the ECU 10 can restore the communication settings of the switches 210A and 210B that are the target of the network setting change to the settings before the change. By restoring the communication settings of the switches 210A and 210B to the settings before the change, the ECU 10 can prevent the ECU that is not the target of the network setting change from causing a communication error.
[0054] Next, a description will be given of the hardware configuration of ECUs 200A to 200D. In the following, ECUs 200A to 200D will be collectively referred to as ECU 200. FIG.
[0055] 4, the ECU 200 includes a CPU 201, a ROM 202, a RAM 203, a storage 204, and a communication interface (I / F) 205. Each component is connected via a bus 209 so as to be able to communicate with each other.
[0056] The CPU 201 is a central processing unit that executes various programs and controls each component. That is, the CPU 201 reads programs from the ROM 202 or storage 204 and executes the programs using the RAM 203 as a work area. The CPU 201 controls the above components and performs various arithmetic processing in accordance with the programs recorded in the ROM 202 or storage 204.
[0057] The ROM 202 stores various programs and various data. The RAM 203 temporarily stores programs or data as a working area. The storage 204 is configured with a storage device such as a flash memory, and stores various programs including an operating system, and various data.
[0058] The communication interface 205 is an interface for communicating with other devices such as the ECU 10 and other ECUs 200, and uses a wired communication standard such as Ethernet (registered trademark), for example.
[0059] When executing the above communication control program, the ECU 200 uses the above hardware resources to realize various functions. The functional configuration realized by the ECU 200 will be described below.
[0060] FIG. 5 is a block diagram showing an example of the functional configuration of the ECU 200. As shown in FIG.
[0061] 5, the ECU 200 has, as functional components, an acquisition unit 211, a control unit 212, an output unit 213, and a storage unit 214. Each functional component is realized by the CPU 201 reading and executing a program stored in the ROM 202 or the storage 204.
[0062] The acquisition unit 211 acquires data from the ECU 10 in the in-vehicle network and other ECUs 200. In particular, the acquisition unit 211 acquires new software from the ECU 10 when software executed in the ECU 200 is updated.
[0063] The control unit 212 controls the operation of the ECU 200. In particular, when an update occurs to the software executed by the ECU 200, the control unit 212 performs a process of updating the software of the ECU 200 itself with the new software acquired by the acquisition unit 211. Furthermore, when a communication error occurs between the control unit 212 and the ECU 200, which is the communication partner, the control unit 212 notifies the ECU 200 that a communication error has occurred.
[0064] The output unit 213 outputs data to the ECU 10 of the in-vehicle network and other ECUs 200. The output of data from the output unit 213 is performed under the control of the control unit 212.
[0065] The storage unit 214 stores various information such as information referenced during operation of the ECU 10 and information used to control the in-vehicle network. In particular, the storage unit 214 stores software executed by the ECU 200 and data referenced by the software.
[0066] Next, the operation of the communication system will be described.
[0067] 6 is a sequence diagram illustrating the operation of each device in the communication system. In the ECU 10, the CPU 11 reads out a communication control program from the ROM 12 or the storage 14, loads it into the RAM 13, and executes it, thereby performing communication control processing.
[0068] The sequence diagram shown in Fig. 6 illustrates the operation of each device when software executed in ECU 200 of the in-vehicle network is updated and the communication settings of switches 210A and 210B are changed in accordance with the software update. Fig. 6 is a sequence diagram assuming a case where, before the software update, communication is started between ECU 200A and ECU 200C by the communication settings of switches 210A and 210B.
[0069] When updating software executed in ECU 200 of the in-vehicle network, first, in step S101, OTA server 20 transmits software data to vehicle 1. The software data transmitted from OTA server 20 is first acquired by ECU 10. ECU 10 outputs the software data acquired from OTA server 20 to ECU 200 to be updated. Here, it is assumed that ECUs 200A and 200C are the targets of software update. In steps S102 and S104, ECU 10 outputs the software data to ECUs 200A and 200C to be updated. In step S103, ECU 200A updates its software using the software data transmitted from ECU 10. Similarly, ECU 200C updates its software using the software data transmitted from ECU 10 in step S105.
[0070] Furthermore, in order to update the communication settings of switches 210A and 210B in response to the software update, ECU 10 outputs new communication setting information in step S106. In step S107, switches 210A and 210B update the communication settings using the communication setting information sent from ECU 10. For example, by updating the software of ECUs 200A and 200C, ECU 10 updates the communication settings of switches 210A and 210B so as to enable communication between ECU 200A and ECU 200C.
[0071] By updating the communication settings of switches 210A and 210B, communication between ECU 200A and ECU 200C should become possible. Therefore, ECU 200A checks continuity with ECU 200C in step S108. However, there may be cases where communication between ECU 200A and ECU 200C is not possible due to, for example, an error in the communication settings of switches 210A and 210B. ECU 200A notifies ECU 10 that a communication error has occurred with ECU 200C in step S109.
[0072] When ECU 10 receives the notification of the occurrence of the communication error sent from ECU 200A, in step S110, ECU 10 updates the software for ECUs 200A and 200C and changes the communication settings of switches 210A and 210B, and then transmits to OTA server 20 a notification that the communication error has occurred as a result. When transmitting the notification of the occurrence of the communication error to OTA server 20, ECU 10 also transmits a reason code, which is information about the cause of the communication error. The reason code information indicates which ECU caused the communication error and what type of communication error it is. The content of the communication error, in detail, includes the content of a frame or packet that was sent to a communication partner but did not receive a response from the communication partner. The content of the communication error is, for example, at least one of the following: inability to confirm continuity with the communication device of the communication partner; inability to communicate at a predetermined period; inability to communicate using a predetermined protocol; and inability to communicate because a predetermined port is not open.
[0073] Upon receiving the notification that a communication error has occurred, the OTA server 20 transmits a rollback instruction to the vehicle 1 in step S111. Rollback refers to returning the software to the state before the update. When the rollback instruction is transmitted from the OTA server 20, the ECUs 200A and 200C use the data of the software before the update that they have stored to return the software to the state before the update.
[0074] When the ECU 10 receives the rollback instruction from the OTA server 20, it outputs the rollback instruction to the ECU 200 that is the target of rollback. In this example, the ECUs 200A and 200C are the targets of software rollback. In steps S112 and S114, the ECU 10 outputs the rollback instruction to the ECUs 200A and 200C that are the targets of software rollback. In step S113, the ECU 200A rolls back the software based on the instruction from the ECU 10. Similarly, in step S115, the ECU 10 rolls back the software based on the instruction from the ECU 10. In addition to rolling back the software, in step S116, the ECU 10 instructs the switches 210A and 210B to return the communication settings to the states before the change. In step S117, the switches 210A and 210B return the communication settings to the states before the change.
[0075] When the OTA server 20 receives the occurrence of a communication error and the reason code from the ECU 10, the OTA server 20 transmits new software to the vehicle 1 that has been modified based on the content of the reason code so that the communication error does not occur. The distribution targets of the modified software are not limited to the ECUs 200A and 200C, and may also include the ECU 200D that is unrelated to the communication error. The flow from the transmission of software from the OTA server 20 to the software update in the ECU 200 is similar to the above-described steps S101 to S105, and therefore a detailed description thereof will be omitted. Furthermore, the ECU 10 executes a process for updating the communication settings of the switches 210A and 210B in response to the software update.
[0076] As described above, according to the embodiment of the present invention, if an ECU causes a communication error after changing the network settings, the communication settings of the switch whose network settings are to be changed can be restored to the state before the change. By restoring the communication settings of the switch whose network settings are to be changed to the state before the change, the ECU 10 can prevent the ECU from causing a communication error.
[0077] In the above-described embodiment, the OTA server 20 distributes software. However, if the OTA server 20 does not distribute software, when the ECU 10 detects a communication abnormality by the ECU 200, the ECU 10 executes a process to return the communication settings of the switches 210A and 210B to the state before the change.
[0078] The present invention can also be applied to changing communication settings when a new ECU is connected to an in-vehicle network, so that the newly connected ECU can communicate with other ECUs. While the above-described embodiment illustrates an example of changing communication settings in an in-vehicle network that is a network established within a vehicle, the present invention is not limited to this example. The present invention can be applied to any network whose configuration is changed by software settings.
[0079] In the above embodiments, the communication control process executed by the CPU after reading the software (program) may be executed by various processors other than the CPU. Examples of such processors include programmable logic devices (PLDs) such as field-programmable gate arrays (FPGAs), whose circuit configuration can be changed after fabrication, and dedicated electrical circuits such as application-specific integrated circuits (ASICs), which are processors with circuit configurations specifically designed to execute specific processes. The communication control process may be executed by one of these processors, or by a combination of two or more processors of the same or different types (e.g., multiple FPGAs, or a combination of a CPU and an FPGA). The hardware structure of these processors is, more specifically, an electrical circuit that combines circuit elements such as semiconductor devices.
[0080] In addition, in each of the above embodiments, the communication control processing program is described as being pre-stored (installed) in a ROM or storage, but this is not limiting. The program may be provided in a form recorded on a non-transitory recording medium such as a CD-ROM (Compact Disk Read Only Memory), a DVD-ROM (Digital Versatile Disk Read Only Memory), or a USB (Universal Serial Bus) memory. The program may also be downloaded from an external device via a network. [Explanation of symbols]
[0081] 1 vehicle 2 antennas 10 ECU 20 OTA Server 30 Network 200A, 200B, 200C, 200D ECU 210A, 210B Switches
Claims
1. a setting unit that performs processing related to changing network settings; an output unit that outputs a notification that the change of the network settings has been completed to a communication device connected to the network; a control unit that, when receiving a communication error regarding communication on the network from the communication device that performs communication according to the change in the network setting based on the notification, performs processing to return the changed network setting to a state before the change; Equipped with The control unit requests a server that distributed the software that caused the change in the network settings to restore the software to a state before the update.
2. The communication control device according to claim 1 , wherein the control unit determines that the change in the network settings is valid when no communication error is received from the communication device for a predetermined time after the change in the network settings.
3. The communication control device according to claim 2 , wherein the control unit notifies an external device that the change in the network settings is valid.
4. The control unit performs processing for a communication device connected to the network that has made a change to the network settings that caused a communication error from the communication device, to restore the network settings to the state before the change.
5. The communication control device according to any one of claims 1 to 4, wherein the communication error is at least one of the following: inability to confirm continuity with the communication device of the communication destination; inability to communicate at a specified cycle; inability to communicate using a specified protocol; and inability to communicate because a specified port is not open.
6. a monitoring unit that periodically monitors whether or not a communication error has been notified from a communication device connected to the network; A communication control device as described in any one of claims 1 to 5, wherein the control unit performs processing to restore the network settings of the communication device whose network settings are to be changed to a state before the change in response to detection of a communication error notification by the monitoring unit.
7. The communication control device according to any one of claims 1 to 6, wherein the network is an in-vehicle network.
8. The processor: Performs processing related to changes in network settings, notifying a communication device connected to the network that the change in the network settings has been completed; When a communication error regarding the network communication is received from the communication device that performs communication according to the change in the network settings based on the notification, a process is performed to return the changed network settings to the state before the change, and a request is made to the server that distributed the software that caused the change in the network settings to return the software to the state before the update. A communication control method for executing a process.
9. On the computer, Performs processing related to changes in network settings, notifying a communication device connected to the network that the change in the network settings has been completed; When a communication error regarding the network communication is received from the communication device that performs communication according to the change in the network settings based on the notification, a process is performed to return the changed network settings to the state before the change, and a request is made to the server that distributed the software that caused the change in the network settings to return the software to the state before the update. A communication control program that executes processing.
Citation Information
Patent Citations
Setting device, communication system, method for setting update of communication device, and program
JP2017169044A