Communication systems, in-vehicle devices, management devices, service management programs, and resource management programs
By introducing management devices and the collaborative work of on-vehicle equipment into vehicles, the problem of high costs for vehicle function updates has been solved, and efficient resource utilization and function upgrades have been achieved.
Patent Information
- Authority / Receiving Office
- JP · JP
- Patent Type
- Applications
- Current Assignee / Owner
- Filing Date
- 2024-09-24
- Publication Date
- 2026-04-03
AI Technical Summary
As vehicle functions become more complex and diverse, the frequency of vehicle configuration updates increases, leading to higher update costs.
By coordinating resources between on-vehicle and management devices installed in the vehicle, services are performed and vehicle equipment is controlled, reducing the need for direct updates to vehicle configurations.
This reduces the cost of vehicle function updates while effectively utilizing resources and avoiding the need for hardware replacements.
Smart Images

Figure 2026057795000001_ABST
Abstract
Description
Technical Field
[0001] This disclosure relates to a communication system, an in-vehicle device, a management device, a service management program, and a resource management program.
Background Art
[0002] Conventionally, technologies for managing methods of updating configurations in vehicles have been developed. For example, Patent Document 1 (Japanese Unexamined Patent Application Publication No. 2022-174678) discloses the following technology. That is, an information processing device receives a request for a first update regarding a first vehicle from a user terminal, and when the first update is a hardware update, presents to the user terminal that the first update is to be carried out at a store, and when the first update is a software update, presents to the user terminal that the first update is to be carried out by wireless communication, and includes a control unit that executes the above.
Prior Art Documents
Patent Documents
[0003]
Patent Document 1
Patent Document 2
Patent Document 3
Summary of the Invention
Problems to be Solved by the Invention
[0004] In order to upgrade the functions of a vehicle, it may be necessary to update the configuration such as hardware in the vehicle. In recent years, with the sophistication and diversification of vehicle functions, etc., it is assumed that the frequency of such updates will increase. In this case, the cost required to upgrade the functions of the vehicle increases.
[0005] This disclosure was made to solve the aforementioned problems and aims to provide a communication system, in-vehicle device, management device, service management program, and resource management program that can reduce the cost required for updating the functionality of a vehicle. [Means for solving the problem]
[0006] The communication system of this disclosure comprises an in-vehicle device mounted in a vehicle and a management device, wherein the in-vehicle device transmits a request to the management device to perform a service relating to the vehicle, the management device allocates resources to perform the service based on the request received from the in-vehicle device, the management device performs the service using the allocated resources, the management device transmits the result of the service to the in-vehicle device, the in-vehicle device controls the in-vehicle equipment of the vehicle using the result received from the management device, the in-vehicle device transmits a request to release the resources to the management device, and the management device receives the release request from the in-vehicle device and releases the resources.
[0007] One aspect of this disclosure can be implemented not only as a communication system having such characteristic processing, but also as a step-based method for such characteristic processing, or as a semiconductor integrated circuit that implements part or all of the communication system.
[0008] One aspect of this disclosure can be realized not only as an in-vehicle device equipped with such characteristic processing, but also as a step-based method for such characteristic processing, or as a semiconductor integrated circuit that realizes part or all of the in-vehicle device.
[0009] One aspect of this disclosure can be realized not only as a management device equipped with such characteristic processing, but also as a step-based method for such characteristic processing, or as a semiconductor integrated circuit that realizes part or all of the management device. [Effects of the Invention]
[0010] According to this disclosure, it is possible to reduce the costs required for updating vehicle functions while making effective use of resources. [Brief explanation of the drawing]
[0011] [Figure 1] Figure 1 is a diagram showing an example of the configuration of a communication system according to an embodiment of the present disclosure. [Figure 2] Figure 2 shows an example of the configuration of an in-vehicle system according to an embodiment of the present disclosure. [Figure 3] Figure 3 shows an example of the configuration of an in-vehicle relay device according to an embodiment of the present disclosure. [Figure 4] Figure 4 shows an example of the configuration of a resource management server according to an embodiment of the present disclosure. [Figure 5] Figure 5 shows an example of the configuration of an edge server according to an embodiment of the present disclosure. [Figure 6] Figure 6 is a diagram illustrating an example of a service performed by an edge server in a communication system according to an embodiment of the present disclosure. [Figure 7] Figure 7 is a flowchart illustrating an example of the operation procedure when an in-vehicle relay device according to an embodiment of this disclosure controls in-vehicle equipment. [Figure 8] Figure 8 is a flowchart illustrating an example of the operation procedure when an in-vehicle relay device according to an embodiment of the present disclosure controls in-vehicle equipment. [Figure 9] Figure 9 is a flowchart illustrating an example of the operation procedure when a resource management server according to the embodiment of this disclosure allocates resources. [Figure 10] Figure 10 is a flowchart illustrating an example of the operation procedure when a resource management server according to the embodiment of this disclosure allocates resources. [Figure 11] Figure 11 is a flowchart that shows an example of the operation procedure when an edge server according to the embodiment of this disclosure performs a service. [Figure 12] FIG. 12 is a flowchart defining an example of an operation procedure when an edge server according to an embodiment of the present disclosure performs a process of stopping the execution of a service. [Figure 13] FIG. 13 is a diagram showing an example of a sequence of processes of each device in a communication system according to an embodiment of the present disclosure. [Figure 14] FIG. 14 is a diagram showing an example of a sequence of processes of each device in a communication system according to an embodiment of the present disclosure. **Embodiments for Carrying Out the Invention**
[0012] First, the content of the embodiment of the present disclosure will be listed and described. (1) A communication system according to an embodiment of the present disclosure includes an in-vehicle device mounted on a vehicle and a management device. The in-vehicle device transmits a service execution request related to the vehicle to the management device. The management device allocates resources used to execute the service based on the execution request received from the in-vehicle device. The management device executes the service using the allocated resources. The management device transmits the execution result of the service to the in-vehicle device. The in-vehicle device controls in-vehicle equipment of the vehicle using the execution result received from the management device. The in-vehicle device transmits a resource release request to the management device. The management device receives the release request from the in-vehicle device and releases the resources.
[0013] In this way, by having the management device execute a service related to the vehicle and controlling the in-vehicle equipment using the execution result of the service, the service function can be upgraded without changing the configuration in the vehicle. Therefore, the cost required for updating the functions of the vehicle can be reduced.
[0014] (2) In the above (1), the management device may transmit information related to the service executable in the management device to the in-vehicle device.
[0015] For example, if resources are insufficient, the management device may not be able to execute the service. With the configuration described above, it is possible to understand the services to be provided according to the resource status at the time of a service execution request.
[0016] (3) In the case of (1) or (2) above, the management device may transmit information to the in-vehicle device indicating whether or not the service can be performed.
[0017] This configuration allows for notification of whether a service can be executed based on factors such as the feasibility of resource allocation and the success or failure of authentication.
[0018] (4) In any of (1) to (3) above, the management device may transmit to the in-vehicle device information indicating the source from which to download the software used to perform the service and which is incorporated into the in-vehicle device.
[0019] With this configuration, for example, in a vehicle where resources are sufficient but necessary software is not installed, the service can be performed more reliably by downloading that software.
[0020] (5) In any of (1) to (4) above, the in-vehicle device may transmit the vehicle information, which indicates the status of the vehicle and is used to generate the control information for controlling the in-vehicle equipment, which is the execution result, to the management device, and the management device may generate the control information using the vehicle information received from the in-vehicle device.
[0021] This configuration allows for the generation of more appropriate control information based on the vehicle's state, enabling the operation of in-vehicle equipment.
[0022] (6) In the case of (5) above, if the in-vehicle device is a service relating to the automatic driving of the vehicle or a service for avoiding obstacles while the vehicle is in motion, the in-vehicle device may transmit at least one of the vehicle's location information and vehicle speed information to the management device as vehicle information.
[0023] This configuration allows for the generation of more appropriate control information based on the vehicle's position or speed, enabling the operation of in-vehicle equipment that supports autonomous driving services or obstacle avoidance services.
[0024] (7) In the case of (5) above, if the service is a service for unlocking the doors of the vehicle, the in-vehicle device may transmit at least one of the following to the management device as vehicle information: location information of the vehicle, information indicating the power status of the vehicle, and information indicating the open / closed state of the doors.
[0025] This configuration allows for the generation of more appropriate control information based on the vehicle's location, power status, or door status, enabling the operation of in-vehicle equipment that supports the door unlocking service.
[0026] (8) In any of (1) to (7) above, the in-vehicle device may transmit resource-related information used for resource allocation by the management device, which indicates the hardware configuration of the vehicle, to the management device, and the management device may use the resource-related information received from the in-vehicle device to allocate the resources.
[0027] This configuration allows for more appropriate resource allocation according to the vehicle's hardware configuration.
[0028] (9) In the above (8), if the hardware configuration indicated by the resource-related information is insufficient for the hardware configuration required to perform the service, the management device may obtain data corresponding to the insufficient hardware configuration from equipment outside the vehicle and transmit the obtained data to the in-vehicle device.
[0029] With this configuration, even if the vehicle lacks the necessary hardware configuration to perform the service, the service can be performed more reliably using data acquired from the management device without changing the hardware configuration.
[0030] (10) In any of the above (1) to (9), the management device may perform the authentication process for the execution request.
[0031] This configuration allows for the determination of whether a service execution request is a legitimate execution request, thereby improving the security of the communication system.
[0032] (11) In any of (1) to (10) above, the management device may include a first device that has the resources and uses the resources to perform the service, and a second device that allocates the resources, and the first device may transmit the execution result of the service to the in-vehicle device.
[0033] This configuration allows the functions of the management device to be distributed among multiple devices, thereby optimizing the overall system processing.
[0034] (12) In any of the above (1) to (11), the management device may perform authentication processing of the release request.
[0035] This configuration allows for the determination of whether a resource release request is a legitimate release request, thereby improving the security of the communication system.
[0036] (13) An in-vehicle device according to an embodiment of the present disclosure is an in-vehicle device mounted on a vehicle, comprising: a transmitting unit that transmits a request to a management device for the execution of a service relating to the vehicle; a receiving unit that receives the result of the execution of the service from the management device; and a control unit that controls the in-vehicle equipment of the vehicle using the result of the execution received by the receiving unit, wherein the transmitting unit transmits a request to the management device for the release of resources used to execute the service.
[0037] In this configuration, where a management device executes vehicle-related services and uses the results of those services to control in-vehicle equipment, the functionality of the services can be upgraded without changing the vehicle's configuration. Therefore, the cost required to update vehicle functionality can be reduced.
[0038] (14) A management device according to an embodiment of the present disclosure is a management device that communicates with an in-vehicle device mounted on a vehicle, comprising: a communication unit that receives a request to execute a service relating to the vehicle from the in-vehicle device; a resource allocation unit that allocates resources to be used to execute the service based on the execution request received by the communication unit; and a service execution unit that executes the service using the resources allocated by the resource allocation unit and transmits the execution result of the service to the in-vehicle device, wherein the communication unit receives a request to release the resources from the in-vehicle device, and the management device further comprises a resource release unit that releases the resources when the communication unit receives the release request.
[0039] In this configuration, where the management device executes vehicle-related services and transmits the results of those services to the in-vehicle device, the functionality of the services can be upgraded without requiring any changes to the vehicle's configuration. Therefore, the cost required to update the vehicle's functionality can be reduced.
[0040] (15) The service management program according to the embodiment of the present disclosure is a service management program used in an in-vehicle device installed in a vehicle, and is a program that causes a computer to function as a transmitting unit that transmits a request to a management device for the execution of a service relating to the vehicle, a receiving unit that receives the result of the execution of the service from the management device, and a control unit that controls the in-vehicle equipment of the vehicle using the result of the execution received by the receiving unit, wherein the transmitting unit transmits a request to the management device for the release of resources used to execute the service.
[0041] In this configuration, where a management device executes vehicle-related services and uses the results of those services to control in-vehicle equipment, the functionality of the services can be upgraded without changing the vehicle's configuration. Therefore, the cost required to update vehicle functionality can be reduced.
[0042] (16) The resource management program according to the embodiment of the present disclosure is a resource management program used in a management device that communicates with an in-vehicle device mounted on a vehicle, and is a program that causes a computer to function as a communication unit that receives a request to execute a service relating to the vehicle from the in-vehicle device, a resource allocation unit that allocates resources to execute the service based on the execution request received by the communication unit, and a service execution unit that executes the service using the resources allocated by the resource allocation unit and transmits the execution result of the service to the in-vehicle device, wherein the communication unit receives a request to release the resources from the in-vehicle device, and is a program that causes the computer to function as a resource release unit that releases the resources when the communication unit receives the release request.
[0043] In this configuration, where the management device executes vehicle-related services and transmits the results of those services to the in-vehicle device, the functionality of the services can be upgraded without requiring any changes to the vehicle's configuration. Therefore, the cost required to update the vehicle's functionality can be reduced.
[0044] Embodiments of this disclosure will be described below with reference to the drawings. In the drawings, the same or corresponding parts are denoted by the same reference numerals, and their descriptions will not be repeated. Furthermore, at least some of the embodiments described below may be combined in any way.
[0045] [Communication System] Figure 1 is a diagram showing an example of the configuration of a communication system according to an embodiment of the present disclosure. Referring to Figure 1, the communication system 501 comprises a resource management server 170, a plurality of edge servers 180, and one or more in-vehicle systems 301. The in-vehicle system 301 is mounted on a vehicle 1. The resource management server 170 and the edge servers 180 are located outside the vehicle 1. The edge servers 180 are an example of a first device included in the management device. The resource management server 170 is an example of a second device included in the management device.
[0046] Figure 2 shows an example of the configuration of an in-vehicle system according to an embodiment of the present disclosure. Referring to Figure 2, the in-vehicle system 301 comprises an in-vehicle relay device 101 and a plurality of in-vehicle devices 202. The in-vehicle relay device 101 is an example of an in-vehicle device.
[0047] In-vehicle equipment 202 includes in-vehicle ECUs (Electronic Control Units), sensors, actuators, navigation systems, human-machine interfaces, and cameras. In-vehicle ECUs include TCUs (Telematics Communication Units), engine ECUs, autonomous driving ECUs, steering ECUs, brake ECUs, and door lock ECUs.
[0048] The in-vehicle relay device 101 and the multiple in-vehicle devices 202 constitute an in-vehicle network 401. The multiple in-vehicle devices 202 are connected to the in-vehicle relay device 101, for example, via a CAN bus 51 that conforms to the CAN (Controller Area Network) standard.
[0049] In the example shown in Figure 2, the in-vehicle system 301 includes in-vehicle equipment 202, which consists of in-vehicle equipment 202A, 202B, 202C, and 202D. In addition, in the example shown in Figure 2, CAN buses 51A and 51B are provided as CAN bus 51.
[0050] In-vehicle devices 202A and 202B are connected to the in-vehicle relay device 101 via CAN bus 51A. In-vehicle devices 202C and 202D are connected to the in-vehicle relay device 101 via CAN bus 51B.
[0051] The in-vehicle relay device 101 is, for example, a gateway device. The in-vehicle relay device 101 performs relay processing to relay data transmitted and received between the in-vehicle devices 202.
[0052] For example, each in-vehicle device 202 transmits a CAN frame containing various information, such as information to assist the automated driving performed by the vehicle 1 and information used for entertainment (described later), and a CAN-ID (Identifier) indicating the type of data, to another in-vehicle device 202 or an in-vehicle relay device 101. The in-vehicle relay device 101 relays a CAN frame received from one in-vehicle device 202 to another in-vehicle device 202. The in-vehicle relay device 101 also creates a CAN frame containing the above-mentioned various information and CAN-ID, and transmits the created CAN frame to the destination in-vehicle device 202.
[0053] Furthermore, the in-vehicle system 301 is not limited to a configuration in which two CAN buses 51 are provided; it may also be configured to have one or three or more CAN buses 51.
[0054] Furthermore, the in-vehicle relay device 101 and the in-vehicle equipment 202 may be configured to perform communication in accordance with communication protocols such as CAN FD (CAN with Flexible Data Rate), Ethernet (registered trademark), FlexRay (registered trademark), MOST (Media Oriented System Transport) (registered trademark), LIN (Local Interconnect Network), and CXPI (Clock Extension Peripheral Interface) (registered trademark), in addition to or instead of communication in accordance with the CAN standard.
[0055] In the example shown in Figure 2, in-vehicle equipment 202A, in-vehicle equipment 202B, and in-vehicle equipment 202C are TCU, vehicle speed sensor, and navigation device, respectively. Hereinafter, in-vehicle equipment 202A, in-vehicle equipment 202B, and in-vehicle equipment 202C will also be referred to as TCU202A, vehicle speed sensor 202B, and navigation device 202C, respectively.
[0056] Referring to Figures 1 and 2, the TCU202A communicates with the resource management server 170 and the edge server 180, for example, via the wireless base station device 161.
[0057] More specifically, the TCU202A communicates wirelessly with the wireless base station equipment 161 in accordance with communication standards such as LTE (Long Term Evolution) (registered trademark) or 5G.
[0058] Specifically, when the TCU202A receives a CAN frame containing various information from the in-vehicle relay device 101, it transmits a radio signal containing the said information to the radio base station device 161.
[0059] When the wireless base station device 161 receives a wireless signal from the TCU 202A, it transmits various information contained in the received wireless signal to the resource management server 170 via an external network 151 such as the Internet.
[0060] Furthermore, when the wireless base station device 161 receives an IP packet from the resource management server 170 or edge server 180 via the external network 151, it includes the received IP packet in the wireless signal and transmits it to the TCU 202A.
[0061] When the TCU202A receives a radio signal containing IP packets from the resource management server 170 or edge server 180 via the radio base station device 161, it retrieves the IP packets from the received radio signal, stores the retrieved IP packets in one or more CAN frames, and transmits them to the in-vehicle relay device 101.
[0062] The vehicle speed sensor 202B measures the vehicle speed of vehicle 1, for example, periodically or irregularly, and transmits the vehicle speed information indicating the measurement result to the on-board relay device 101.
[0063] The navigation device 202C accepts input from the user of vehicle 1 regarding the vehicle's departure point, destination, and planned departure time. Upon receiving the input of the departure point, destination, and planned departure time, the navigation device 202C creates route information indicating the planned route A from the departure point to the destination, one or more waypoints between the departure point and the destination, the planned departure time, and the planned arrival time, which is the time the vehicle is expected to arrive at the destination.
[0064] The navigation device 202C then transmits the created route information to the in-vehicle relay device 101.
[0065] Furthermore, the navigation device 202C transmits location information indicating the position of vehicle 1 to the in-vehicle relay device 101, for example, periodically or irregularly.
[0066] [Vehicle-mounted relay device] Figure 3 shows an example of the configuration of an in-vehicle relay device according to an embodiment of the present disclosure. Referring to Figure 3, the in-vehicle relay device 101 comprises a relay unit 11, a processing unit 12, and a storage unit 13. The processing unit 12 includes a service management unit 21 and a control unit 22. One or both of the relay unit 11 and the processing unit 12 are implemented by a processing circuit including, for example, one or more processors. The storage unit 13 is, for example, a non-volatile memory included in the processing circuit. The service management unit 21 is an example of a transmission unit and an example of a reception unit.
[0067] (Relay section) The relay unit 11 receives a CAN frame transmitted from a certain in-vehicle device 202. The relay unit 11 then checks whether the received CAN frame is a CAN frame that its own in-vehicle relay device 101 should receive.
[0068] The storage unit 13 stores, for example, a reception list L indicating the CAN-IDs included in the CAN frames that its in-vehicle relay device 101 should receive. The reception list L is registered in the storage unit 13 by the manufacturer of the vehicle 1 when the vehicle 1 is shipped.
[0069] When the relay unit 11 receives a CAN frame, it checks whether the CAN-ID contained in the CAN frame is registered in the reception list L by referring to the reception list in the storage unit 13.
[0070] The relay unit 11 discards a CAN frame if the CAN-ID contained in the received CAN frame is not registered in the reception list L.
[0071] On the other hand, the relay unit 11 performs relay processing if the CAN-ID included in the received CAN frame is registered in the reception list L and the destination of the CAN frame is the in-vehicle equipment 202. Also, if the relay unit 11 outputs the CAN frame to the processing unit 12 if the CAN-ID included in the received CAN frame is registered in the reception list L and the destination of the CAN frame is its own in-vehicle relay device 101.
[0072] More specifically, for example, the storage unit 13 stores a routing table that shows the correspondence between CAN-IDs, the devices to which CAN frames are transmitted, and the CAN bus 51 (hereinafter also referred to as the "destination bus") to which the destination devices are connected. The routing table is registered in the storage unit 13 by the manufacturer of vehicle 1 when vehicle 1 is shipped, for example.
[0073] For example, if the relay unit 11 has a CAN-ID included in a CAN frame received from the in-vehicle device 202 registered in the reception list L, it refers to the routing table in the storage unit 13 to confirm the destination device corresponding to that CAN-ID.
[0074] When the relay unit 11 confirms that the destination device of the received CAN frame is the in-vehicle device 202, it refers to the routing table to identify the destination bus corresponding to that destination device. The relay unit 11 then outputs the received CAN frame to the identified destination bus.
[0075] Meanwhile, when the relay unit 11 confirms that the destination device of the received CAN frame is its own in-vehicle relay device 101, it outputs various information contained in the CAN frame to the service management unit 21.
[0076] Specifically, for example, when the relay unit 11 receives a CAN frame containing route information from the navigation device 202C, it outputs the route information to the service management unit 21.
[0077] For example, the storage unit 13 stores vehicle identification information (hereinafter also referred to as "vehicle ID (Identifier)") for identifying vehicle 1.
[0078] When the service management unit 21 receives route information from the relay unit 11, it sends the route information, including the vehicle ID stored in the storage unit 13, to the resource management server 170.
[0079] [Resource management server and edge server] Referring again to Figure 1, each edge server 180 executes one or more services S. Specifically, the edge server 180 executes services S such as an autonomous driving service, an obstacle avoidance service, and a door unlocking service related to the autonomous driving of vehicle 1.
[0080] In this embodiment, for example, the autonomous driving services performed by the edge server 180 are the LKAS (Lane Keeping Assist System) service and the ACC (Adaptive Cruise Control) service. The LKAS service is a service to prevent vehicle 1 from deviating from the driving lane in which it is traveling. The ACC service is a service to ensure that the distance between vehicle 1 and other vehicles located in front of it (hereinafter also referred to as "vehicles ahead") is above a certain value.
[0081] The obstacle avoidance service is a service that avoids obstacles while vehicle 1 is in motion. The door unlocking service is a service that unlocks the doors of vehicle 1 while it is parked or stopped.
[0082] For example, the edge server 180 generates control information for controlling the in-vehicle equipment 202. The edge server 180 then transmits the generated control information to the in-vehicle relay device 101 as the execution result of service S.
[0083] For example, the resource management server 170 creates service information indicating the service S corresponding to the driving area of vehicle 1. Specifically, the resource management server 170 creates service information regarding the service S that the edge server 180 can execute when vehicle 1 is traveling along the planned route A. The resource management server 170 then transmits the created service information to the in-vehicle relay device 101 via the TCU 202A.
[0084] Furthermore, the resource management server 170 allocates resources R that the edge server 180 uses to execute service S. Resources R include processing power and data collection functions necessary to execute service S.
[0085] (Resource management server) Figure 4 shows an example of the configuration of a resource management server according to an embodiment of the present disclosure. Referring to Figure 4, the resource management server 170 comprises a communication unit 31, a service information creation unit 32, an authentication unit 33, a resource allocation unit 34, a resource release unit 35, and a storage unit 36. Some or all of the communication unit 31, the service information creation unit 32, the authentication unit 33, the resource allocation unit 34, and the resource release unit 35 are implemented by a processing circuit including, for example, one or more processors. The storage unit 36 is, for example, a non-volatile memory included in the above processing circuit.
[0086] Referring to Figures 1 and 4, the communication unit 31 communicates with the TCU 202A by sending and receiving various information, for example, via the external network 151 and the wireless base station equipment 161.
[0087] When the communication unit 31 receives route information from the in-vehicle relay device 101 via the TCU 202A, it outputs the received route information to the service information creation unit 32.
[0088] <Service Information> The service information creation unit 32 creates service information using the route information received from the communication unit 31.
[0089] For example, the storage unit 36 stores a service table that shows the correspondence between the points that vehicle 1 passes through and the service S. The service table is pre-registered in the storage unit 36 by, for example, the administrator of the resource management server 170.
[0090] When the service information creation unit 32 receives route information from the communication unit 31, it refers to the service table in the storage unit 36 and confirms the service S corresponding to each of the one or more passing points indicated by the route information.
[0091] The service information creation unit 32 then creates service information indicating the one or more services S that have been confirmed and the vehicle ID included in the route information received from the communication unit 31, and outputs the created service information to the communication unit 31. The service information creation unit 32 also saves the created service information to the storage unit 36.
[0092] When the communication unit 31 receives service information from the service information creation unit 32, it creates an IP packet P1 containing the service information, which includes the IP address of the resource management server 170 and the IP address of vehicle 1 corresponding to the vehicle ID indicated by the service information as the source IP address and destination IP address, respectively. The communication unit 31 then sends the created IP packet P1 to the TCU202A.
[0093] When TCU202A receives an IP packet P1 from the resource management server 170, it transmits the service information contained in the received IP packet to the in-vehicle relay device 101.
[0094] Alternatively, the in-vehicle relay device 101 may be configured to send type information indicating the type of service S corresponding to the current location of the vehicle 1 to the resource management server 170 instead of route information received from the navigation device 202C. In this case, the resource management server 170 does not send service information to the in-vehicle relay device 101, but instead allocates a resource R corresponding to the type of service S indicated by the type information received from the in-vehicle relay device 101.
[0095] <Service S execution request and resource-related information> Referring again to Figure 3, in the in-vehicle relay device 101, when the relay unit 11 receives service information from the TCU 202A, it outputs the received service information to the service management unit 21.
[0096] For example, the service management unit 21 sends a request to execute service S related to the vehicle 1 on which its in-vehicle relay device 101 is installed, along with authentication information B1 and resource-related information, to the resource management server 170.
[0097] Authentication information B1 is information used in the authentication process C1 of the service execution request by the resource management server 170. Authentication information B1 includes, for example, identification information for identifying the user of vehicle 1 (hereinafter also referred to as "user ID") and a password.
[0098] Resource-related information is, for example, information used by the resource management server 170 to allocate resource R, and indicates the hardware configuration Hw1 of vehicle 1. Specifically, resource-related information indicates the processing capacity, storage capacity and type of in-vehicle equipment 202 in the in-vehicle network 401.
[0099] The processing power of the in-vehicle device 202 is, for example, the processing power of the CPU (Central Processing Unit) or MPU (Micro Processing Unit) in the in-vehicle device 202. Specifically, the processing power of the in-vehicle device 202 is expressed by a numerical value with units such as MIPS (Million Instructions Per Second) or FLOPS (FLoating-point Operations Per Second).
[0100] The storage capacity is, for example, the amount of data that the in-vehicle device 202 can provide, and is the capacity of the storage of the in-vehicle device 202, such as RAM (Random Access Memory), ROM (Read Only Memory), or HDD (Hard Disk Drive). Specifically, the storage capacity of the in-vehicle device 202 is indicated by a numerical value in units such as bytes. In addition to information about the hardware configuration Hw1 of vehicle 1, or instead of information about the hardware configuration Hw1, resource-related information may also include other information such as information indicating the type of vehicle 1 and information indicating the modification history of vehicle 1.
[0101] For example, the storage unit 13 stores authentication information B1 and resource-related information. When the service management unit 21 receives service information from the relay unit 11, it transmits the type of service S indicated by the service information, the execution request for the service S, and the execution request information including authentication information B1, resource-related information, and vehicle ID stored in the storage unit 13 to the resource management server 170 via the relay unit 11 and TCU202A.
[0102] Referring again to Figure 4, in the resource management server 170, when the communication unit 31 receives execution request information from the in-vehicle relay device 101 via the TCU 202A, it outputs the received execution request information to the authentication unit 33.
[0103] <Authentication process for execution requests> For example, the authentication unit 33 performs authentication processing C1 for the execution request of service S. More specifically, for example, when the authentication unit 33 receives execution request information from the communication unit 31, it performs authentication processing C1 using the authentication information B1 contained in the execution request information.
[0104] If the authentication process C1 is successful, the authentication unit 33 outputs authentication success information Q1, which indicates that the authentication process C1 was successful, to the resource allocation unit 34, including the vehicle ID and resource-related information contained in the execution request information received from the communication unit 31.
[0105] On the other hand, if authentication process C1 fails, the authentication unit 33 transmits authentication failure information F1, indicating that authentication process C1 has failed, to the in-vehicle relay device 101 via the communication unit 31 and TCU202A.
[0106] <Resource allocation> The resource allocation unit 34 allocates resources R that the edge server 180 will use to execute the service S, based on the service execution request for the service S received from the in-vehicle relay device 101.
[0107] More specifically, for example, the resource allocation unit 34 allocates resource R using resource-related information.
[0108] Specifically, for example, when the resource allocation unit 34 receives authentication success information Q1 from the authentication unit 33, it obtains service information from the storage unit 36 that indicates the same vehicle ID as the vehicle ID included in the authentication success information Q1.
[0109] For example, the storage unit 36 stores hardware information indicating the hardware configuration Hw1 of the vehicle 1 necessary for the execution of each service S.
[0110] When the resource allocation unit 34 obtains service information from the storage unit 36, it refers to the hardware information in the storage unit 36 and identifies the hardware configuration Hw1 corresponding to each of the one or more services S indicated by the obtained service information.
[0111] The resource allocation unit 34 then compares each identified hardware configuration Hw1 with the hardware configuration indicated by the resource-related information included in the authentication success information Q1 received from the authentication unit 33 (hereinafter also referred to as "hardware configuration Hw2").
[0112] The resource allocation unit 34 determines that if hardware configuration Hw2 does not satisfy hardware configuration Hw1, it will allocate resource R to the service S corresponding to hardware configuration Hw1.
[0113] Then, the resource allocation unit 34 identifies the resources R that are insufficient for the execution of service S based on the comparison results between the identified hardware configuration Hw1 and hardware configuration Hw2.
[0114] When the resource allocation unit 34 identifies a resource R that is lacking in the execution of service S, it checks whether the identified resource R can be allocated.
[0115] For example, the storage unit 36 stores a resource management table that shows the correspondence W between the type of resource R and the ID of the edge server 180 (hereinafter also referred to as "server ID"). In addition to the correspondence W, the resource management table includes a determination flag that indicates whether or not resource R has already been allocated.
[0116] If resource R is not allocated, the value of the identification flag corresponding to resource R in the resource management table is set to a value indicating that resource R is not allocated, for example, "zero". If resource R is allocated, the value of the identification flag corresponding to resource R in the resource management table is set to a value indicating that resource R is allocated, for example, "1".
[0117] When the resource allocation unit 34 identifies a missing resource R, it checks whether the value of the discrimination flag corresponding to that resource R is "zero" by referring to the resource management table in the storage unit 36.
[0118] For example, if the value of the discrimination flag corresponding to the insufficient resource R is "zero", the resource allocation unit 34 determines that the resource R is available for allocation and checks the server ID corresponding to the resource R by referring to the resource management table.
[0119] The resource allocation unit 34 then outputs to the communication unit 31 resource information indicating the type of resource R identified, along with the confirmed server ID and the vehicle ID included in the authentication success information Q1 received from the authentication unit 33. The resource allocation unit 34 also associates the type of resource R identified with the acquired service information and stores it in the storage unit 36.
[0120] On the other hand, the resource allocation unit 34 determines that resource R cannot be allocated, i.e., the edge server 180 cannot execute service S, if the value of the discrimination flag corresponding to the insufficient resource R is "1". The resource allocation unit 34 then outputs execution failure information to the communication unit 31, indicating that the edge server 180 cannot execute service S and the vehicle ID included in the authentication success information Q1 received from the authentication unit 33.
[0121] When the communication unit 31 receives resource information from the resource allocation unit 34, it creates an IP packet P2 containing the resource information, which includes the IP address of the resource management server 170 and the IP address of the edge server 180 corresponding to the server ID indicated by the resource information as the source IP address and destination IP address, respectively. The communication unit 31 then sends the created IP packet P2 to the destination edge server 180.
[0122] When the communication unit 31 receives information that cannot be executed from the resource allocation unit 34, it creates an IP packet P3 containing the resource information, which includes the IP address of the resource management server 170 and the IP address of vehicle 1 corresponding to the vehicle ID indicated by the information that cannot be executed, as the source IP address and destination IP address, respectively. The communication unit 31 then sends the created IP packet P3 to the TCU 202A.
[0123] On the other hand, the resource allocation unit 34 determines that if hardware configuration Hw2 satisfies hardware configuration Hw1, it will not allocate resource R for service S corresponding to hardware configuration Hw1. In other words, the resource allocation unit 34 determines that the edge server 180 does not need to execute service S.
[0124] (Updating the resource management table) When the resource allocation unit 34 confirms the server ID corresponding to the resource R that is lacking for the execution of service S, it performs an update process N1 to update the resource management table. Specifically, for example, the resource allocation unit 34 updates the value of the discrimination flag corresponding to the resource R in the resource management table in the storage unit 36 from "zero" to "1".
[0125] (Sending information about what can be executed or what does not need to be executed) For example, the resource allocation unit 34 transmits information indicating whether or not the edge server 180 can perform service S to the in-vehicle relay device 101 via the communication unit 31 and TCU 202A.
[0126] More specifically, if the hardware configuration Hw2 does not satisfy the hardware configuration Hw1, the resource allocation unit 34 outputs executable information to the communication unit 31 indicating that the edge server 180 will execute service S and the vehicle ID included in the authentication success information Q1 received from the authentication unit 33.
[0127] Furthermore, the resource allocation unit 34 outputs to the communication unit 31 unnecessary execution information indicating that the edge server 180 does not need to execute service S if hardware configuration Hw2 satisfies hardware configuration Hw1, and the vehicle ID included in the authentication success information Q1 received from the authentication unit 33.
[0128] Furthermore, when the communication unit 31 receives executable information from the resource allocation unit 34, it creates an IP packet P4 containing the executable information, which includes the IP address of the resource management server 170 and the IP address of the edge server 180 corresponding to the vehicle ID indicated by the executable information as the source IP address and destination IP address, respectively. The communication unit 31 then sends the created IP packet P4 to the TCU 202A.
[0129] When the communication unit 31 receives information that does not need to be executed from the resource allocation unit 34, it creates an IP packet P5 containing the information that does not need to be executed, and which includes the IP address of the resource management server 170 and the IP address of vehicle 1 corresponding to the vehicle ID indicated by the information that does not need to be executed as the source IP address and destination IP address, respectively. The communication unit 31 then sends the created IP packet P5 to the TCU 202A.
[0130] Referring again to Figure 2, when TCU202A receives IP packet P3 from resource management server 170, it transmits the non-executable information contained in the received IP packet P3 to the navigation device 202C via the in-vehicle relay device 101. Also, when TCU202A receives IP packet P4 from resource management server 170, it transmits the executable information contained in the received IP packet P4 to the navigation device 202C via the in-vehicle relay device 101. Furthermore, when TCU202A receives IP packet P5 from resource management server 170, it transmits the non-executable information contained in the received IP packet P5 to the navigation device 202C via the in-vehicle relay device 101.
[0131] When the navigation device 202C receives information that cannot be executed, can be executed, or does not need to be executed from the TCU 202A via the in-vehicle relay device 101, it performs notification processing based on the information that cannot be executed, can be executed, or does not need to be executed.
[0132] Specifically, for example, if the navigation device 202C receives information that the service cannot be executed from the TCU 202A, it displays a screen on its own display unit indicating that the edge server 180 cannot execute service S. Also, if the navigation device 202C receives information that the service can be executed from the TCU 202A, it displays a screen on its own display unit indicating that the edge server 180 will execute service S. Furthermore, if the navigation device 202C receives information that the service does not need to be executed from the TCU 202A, it displays a screen on its own display unit indicating that the edge server 180 does not need to execute service S.
[0133] (Edge Server) Figure 5 shows an example of the configuration of an edge server according to an embodiment of the present disclosure. Referring to Figure 5, the edge server 180 comprises a communication unit 41, a service execution unit 42, and a storage unit 43. One or both of the communication unit 41 and the service execution unit 42 are implemented by a processing circuit including, for example, one or more processors. The storage unit 43 is, for example, a non-volatile memory included in the processing circuit.
[0134] When the communication unit 41 receives resource information from the resource management server 170 via the external network 151, it outputs the received resource information to the service execution unit 42.
[0135] (Service Execution Unit) The service execution unit 42 executes service S using resource R allocated by resource management server 170.
[0136] More specifically, for example, the service execution unit 42 executes service S using resource R of the type indicated by the resource information received from the communication unit 41. In this embodiment, for example, the service execution unit 42 executes service S by using the data collection function of various sensors as resource R.
[0137] Figure 6 is a diagram illustrating an example of a service performed by an edge server in a communication system according to an embodiment of the present disclosure.
[0138] In the example shown in Figure 6, the communication system 501 includes edge servers 180A, 180B, and 180C, which are edge servers 180.
[0139] Edge server 180A performs LKAS and ACC services. Edge servers 180B and 180C perform obstacle avoidance and door unlocking services, respectively.
[0140] <LKASサービスおよびACCサービス> For example, if the resource management server 170 determines that the hardware configuration Hw2 indicated by the resource-related information included in the execution request information received from the in-vehicle relay device 101 does not satisfy the hardware configuration Hw1 required for the execution of the LKAS service, it will allocate the data collection function H11 required for the execution of the LKAS service to the edge server 180A as resource R.
[0141] Furthermore, if the hardware configuration Hw2 indicated by the resource-related information included in the execution request information received from the in-vehicle relay device 101 does not satisfy the hardware configuration Hw1 required for the execution of the ACC service, the resource management server 170 allocates the data collection function H12 required for the execution of the ACC service to the edge server 180A as resource R.
[0142] In this embodiment, for example, the types of data required to execute the LKAS service and the types of data required to execute the ACC service are the same. Specifically, the data required to execute the LKAS service and the ACC service are the location information of vehicle 1, the vehicle speed information of vehicle 1, and information indicating the detection results of a roadside sensor (not shown). However, the types of data required to execute the LKAS service and the types of data required to execute the ACC service may be different.
[0143] In the resource management server 170, when the resource allocation unit 34 allocates collection functions H11 and H12 to the edge server 180A, it sends resource information E1 indicating that the allocated resource R is the collection functions H11 and H12, along with the server ID of the edge server 180A and the vehicle ID included in the authentication success information Q1 received from the authentication unit 33, to the edge server 180A.
[0144] Referring to Figures 5 and 6, in the edge server 180A, when the service execution unit 42 receives resource information E1 from the resource management server 170 via the communication unit 41, it requests the in-vehicle relay device 101 to transmit vehicle information that indicates the status of vehicle 1 and is used to generate control information.
[0145] More specifically, for example, the service execution unit 42 transmits data request information indicating the type of vehicle information to be used for generating control information to the in-vehicle relay device 101 via the communication unit 41.
[0146] Specifically, the service execution unit 42 creates data request information (hereinafter also referred to as "data request information D1") which indicates a request to transmit location information and vehicle speed information as vehicle information, and the vehicle ID indicated by resource information E1. The service execution unit 42 then outputs the created data request information D1 to the communication unit 41.
[0147] When the communication unit 41 receives data request information D1 from the service execution unit 42, it creates an IP packet P6 containing the data request information D1, which includes the IP address of the edge server 180A and the IP address of vehicle 1 corresponding to the vehicle ID indicated by the data request information D1 as the source IP address and destination IP address, respectively. The communication unit 41 then sends the created IP packet P6 to the TCU 202A.
[0148] When TCU202A receives an IP packet P6 from the edge server 180A, it transmits the data request information D1 contained in the received IP packet P6 to the in-vehicle relay device 101.
[0149] Referring again to Figure 3, for example, if the in-vehicle relay device 101 sends a service execution request S to the resource management server 170 that is a request for the execution of LKAS service and ACC service, it sends at least one of the location information and vehicle speed information to the edge server 180A as vehicle information used to generate control information. In this embodiment, the in-vehicle relay device 101 sends both the location information and vehicle speed information to the edge server 180A as said vehicle information.
[0150] More specifically, in the in-vehicle relay device 101, when the service management unit 21 receives data request information D1 from the TCU 202A via the relay unit 11, it transmits location information and vehicle speed information to the edge server 180A via the TCU 202A.
[0151] Specifically, after receiving data request information D1, the service management unit 21 transmits location information from the navigation device 202C to the edge server 180A via the TCU 202A each time it receives location information.
[0152] Furthermore, after receiving data request information D1, the service management unit 21 transmits the vehicle speed information from the vehicle speed sensor 202B to the edge server 180A via the TCU 202A each time it receives vehicle speed information.
[0153] Referring again to Figures 5 and 6, the edge server 180A communicates with one or more roadside sensors installed on a highway. These roadside sensors, for example, periodically detect objects on the road and transmit roadside sensor information K1 indicating the detection result to the edge server 180A.
[0154] In the edge server 180A, for example, the storage unit 43 stores map information for a region that includes the location indicated by the location information transmitted from the in-vehicle relay device 101.
[0155] When the service execution unit 42 receives location information from the in-vehicle relay device 101 via the communication unit 41, it uses the received location information and the map information stored in the storage unit 43 to determine whether or not the vehicle 1 is traveling on a highway.
[0156] When the service execution unit 42 determines that vehicle 1 is traveling on a highway, it executes LKAS service and ACC service based on the information received from the in-vehicle relay device 101 after determining that vehicle 1 is traveling on a highway, specifically location information and vehicle speed information, as well as roadside sensor information K1 received from the roadside sensor.
[0157] The edge server 180A transmits the execution results of the LKAS service and the ACC service to the in-vehicle relay device 101.
[0158] More specifically, for example, in the edge server 180A, the service execution unit 42 includes authentication information B2 in the control information (hereinafter also referred to as "control information G1"), which is the result of executing the LKAS service, and transmits it to the in-vehicle relay device 101 via the communication unit 41 and TCU 202A. The control information G1 is information for controlling an in-vehicle device 202 that should be operated to prevent the vehicle 1 from deviating from the driving lane. Here, the in-vehicle device 202 is assumed to be a steering ECU.
[0159] Authentication information B2 is information used in the authentication process C11 of control information by the in-vehicle relay device 101. Authentication information B2 includes, for example, the server ID of the edge server 180 and the password. Authentication information B2 is stored in the storage unit 36.
[0160] Furthermore, for example, the service execution unit 42 includes authentication information B2 in the control information (hereinafter also referred to as "control information G2"), which is the result of executing the ACC service, and transmits it to the in-vehicle relay device 101 via the communication unit 41 and TCU 202A. The control information G2 is information for controlling an in-vehicle device 202 that should be operated to maintain a certain distance from the vehicle ahead. Here, the in-vehicle device 202 is assumed to be a brake ECU.
[0161] Referring again to Figures 2 and 3, in the in-vehicle relay device 101, for example, the control unit 22 performs the control information authentication process C11.
[0162] More specifically, for example, when the control unit 22 receives control information from the edge server 180A via the TCU 202A and relay unit 11, it performs authentication processing C11 of the received control information using the authentication information B2 contained in the control information.
[0163] When the control unit 22 confirms that the authentication process C11 for the control information is successful, it determines that the edge server 180 that sent the control information is a legitimate edge server 180.
[0164] On the other hand, if the control unit 22 fails the authentication process C11 for control information, it determines that the edge server 180 that is the source of the control information is an unauthorized edge server 180 (hereinafter also referred to as the "unauthorized server"). The control unit 22 then sends authentication failure information F11, indicating that the edge server 180 that is the source of the control information is an unauthorized server, to the navigation device 202C via the relay unit 11.
[0165] When the navigation device 202C receives authentication failure information F11 from the in-vehicle relay device 101, it performs notification processing based on the received stop information. Specifically, for example, the navigation device 202C displays a screen on its own display unit indicating that the edge server 180, the source of the control information, is an unauthorized server.
[0166] Furthermore, the control unit 22 may be configured to determine that the edge server 180 is a malicious server if the control information received from the edge server 180 satisfies predetermined conditions. In this case, for example, the storage unit 13 stores operating range information for each service S, indicating the operating range of the in-vehicle equipment 202 corresponding to the service S during execution of the service S. The in-vehicle equipment 202 includes actuators that drive the brake pedal and EPS (Electric Power Steering), etc. If the operating range when the in-vehicle equipment 202 is operated according to the received control information falls outside the operating range indicated by the operating range information in the storage unit 13, the control unit 22 determines that the edge server 180 that sent the control information is a malicious server.
[0167] The control unit 22 controls the in-vehicle equipment 202 of the vehicle 1 using control information received from the edge server 180 via the TCU 202A and relay unit 11.
[0168] More specifically, for example, if the authentication process C11 of the control information G1 is successful, the control unit 22 transmits the control information G1 to the steering ECU via the relay unit 11.
[0169] When the steering ECU receives control information G1 from the in-vehicle relay device 101, it operates according to the received control information G1.
[0170] Furthermore, if the authentication process C11 for the control information G2 is successful, the control unit 22 transmits the control information G2 to the brake ECU via the relay unit 11.
[0171] When the brake ECU receives control information G2 from the in-vehicle relay device 101, it operates according to the received control information G2.
[0172] <Obstacle avoidance service> Referring again to Figures 5 and 6, for example, if the resource management server 170 finds that the hardware configuration Hw2 indicated by the resource-related information included in the execution request information received from the in-vehicle relay device 101 does not satisfy the hardware configuration Hw1 required for the execution of the obstacle avoidance service, it allocates the data collection function H2 required for the execution of the obstacle avoidance service to the edge server 180B as resource R.
[0173] In this embodiment, for example, the data required to perform the obstacle avoidance service includes the location information of vehicle 1, the vehicle speed information of vehicle 1, information indicating the detection result of a roadside sensor installed at the intersection CS, the location information of another vehicle 1 entering the intersection CS, and the vehicle speed information of the other vehicle 1.
[0174] In the resource management server 170, when the resource allocation unit 34 allocates the collection function H2 to the edge server 180B, it sends resource information E2 indicating that the allocated resource R is the collection function H2, along with the server ID of the edge server 180B and the vehicle ID included in the authentication success information Q1 received from the authentication unit 33, to the edge server 180B.
[0175] In the edge server 180B, when the service execution unit 42 receives resource information E2 from the resource management server 170 via the communication unit 41, it creates data request information (hereinafter also referred to as "data request information D2") indicating a request to transmit location information and vehicle speed information as vehicle information, and the vehicle ID indicated in resource information E2. The service execution unit 42 then outputs the created data request information D2 to the communication unit 41.
[0176] When the communication unit 41 receives data request information D2 from the service execution unit 42, it creates an IP packet P6 containing the data request information D1, which includes the IP address of the edge server 180B and the IP address of vehicle 1 corresponding to the vehicle ID indicated by the data request information D2 as the source IP address and destination IP address, respectively. The communication unit 31 then sends the created IP packet P6 to the TCU 202A.
[0177] When TCU202A receives an IP packet P6 from the edge server 180B, it transmits the data request information D2 contained in the received IP packet P6 to the in-vehicle relay device 101.
[0178] Referring again to Figure 3, for example, if the in-vehicle relay device 101 sends a request to the resource management server 170 to execute a service S, it sends at least one of the location information and vehicle speed information to the edge server 180B as vehicle information used to generate control information. In this embodiment, the in-vehicle relay device 101 sends both the location information and vehicle speed information to the edge server 180B as the vehicle information.
[0179] More specifically, in the in-vehicle relay device 101, when the service management unit 21 receives data request information D2 from the TCU 202A via the relay unit 11, it transmits location information and vehicle speed information to the edge server 180B via the TCU 202A.
[0180] Specifically, after receiving data request information D2, the service management unit 21 transmits location information from the navigation device 202C to the edge server 180B via the TCU 202A each time it receives location information.
[0181] Furthermore, after receiving data request information D2, the service management unit 21 transmits the vehicle speed information from the vehicle speed sensor 202B to the edge server 180B via the TCU 202A each time it receives vehicle speed information.
[0182] Referring again to Figures 5 and 6, the edge server 180B communicates with one or more roadside sensors installed around the intersection CS. These roadside sensors periodically detect objects on the road and transmit roadside sensor information K2 indicating the detection result to the edge server 180B.
[0183] In the edge server 180B, for example, the storage unit 43 stores map information for a region that includes the location indicated by the location information transmitted from the in-vehicle relay device 101.
[0184] When the service execution unit 42 receives location information from the in-vehicle relay device 101 via the communication unit 41, it uses the received location information and the map information stored in the storage unit 43 to determine whether or not the vehicle 1 is passing through intersection CS.
[0185] When the service execution unit 42 determines that vehicle 1 is passing through an intersection CS, it performs an obstacle avoidance service based on the information received from the in-vehicle relay device 101 after determining that vehicle 1 is passing through an intersection CS, specifically, location information and vehicle speed information, roadside sensor information K2 received from roadside sensors installed at the intersection CS, and location information and vehicle speed information of other vehicles 1 around the intersection CS.
[0186] The edge server 180B transmits the results of the obstacle avoidance service to the in-vehicle relay device 101.
[0187] More specifically, for example, in the edge server 180B, the service execution unit 42 transmits warning information to the in-vehicle relay device 101 via the TCU 202A indicating that an obstacle has been detected at the intersection CS, as a result of executing the obstacle avoidance service.
[0188] Referring again to Figures 2 and 3, in the in-vehicle relay device 101, when the service management unit 21 receives warning information from the edge server 180B via the TCU 202A and relay unit 11, it transmits the received warning information to the navigation device 202C via the relay unit 11.
[0189] When the navigation device 202C receives warning information from the in-vehicle relay device 101, it performs notification processing based on the received warning information. Specifically, for example, the navigation device 202C displays a screen on its display unit indicating that an obstacle has been detected at the intersection CS being passed through.
[0190] The edge server 180B may also be configured to transmit control information to the in-vehicle relay device 101 in addition to, or instead of, warning information, as a result of executing the obstacle avoidance service, to control the vehicle 1's movement in order to avoid the obstacle. In this case, the in-vehicle relay device 101 transmits the control information received from the edge server 180B to the in-vehicle equipment 202, such as the steering ECU.
[0191] <Door unlocking service> Referring again to Figures 5 and 6, for example, if the resource management server 170 finds that the hardware configuration Hw2 indicated by the resource-related information included in the execution request information received from the in-vehicle relay device 101 does not satisfy the hardware configuration Hw1 required for the execution of the door unlocking service, it assigns the data collection function H3 required for the execution of the door unlocking service to the edge server 180C as resource R.
[0192] In this embodiment, for example, the data required to perform the door unlocking service includes location information of vehicle 1, power information indicating the power status of vehicle 1, door information indicating the open / closed state of the vehicle 1's doors, and image information showing the facial image of the vehicle 1's occupant. The power information is, for example, information indicating the state of the vehicle 1's ignition power supply.
[0193] In the resource management server 170, when the resource allocation unit 34 assigns the collection function H3 to the edge server 180C, it sends resource information E3 indicating that the assigned resource R is the collection function H3, along with the server ID of the edge server 180C and the resource-related information and vehicle ID included in the authentication success information Q1 received from the authentication unit 33, to the edge server 180C.
[0194] In the edge server 180C, when the service execution unit 42 receives resource information E3 from the resource management server 170 via the communication unit 41, it creates data request information D3 indicating a request to transmit location information, power information, and door information, as well as the vehicle ID indicated by resource information E3. The service execution unit 42 then outputs the created data request information D3 to the communication unit 41.
[0195] When the communication unit 41 receives data request information D3 from the service execution unit 42, it creates an IP packet P7 containing the data request information D3, which includes the IP address of the edge server 180C and the IP address of vehicle 1 corresponding to the vehicle ID indicated in the data request information D3 as the source IP address and destination IP address, respectively. The communication unit 31 then sends the created IP packet P7 to the TCU 202A.
[0196] When TCU202A receives an IP packet P7 from the edge server 180C, it transmits the data request information D3 contained in the received IP packet P7 to the in-vehicle relay device 101.
[0197] Referring again to Figure 3, for example, if the in-vehicle relay device 101 sends a service execution request S to the resource management server 170 that is a door unlocking service execution request, it sends at least one of the location information, power information, and door information to the edge server 180C as vehicle information used to generate control information. In this embodiment, the in-vehicle relay device 101 sends all of the location information, power information, and door information to the edge server 180C as said vehicle information.
[0198] More specifically, when the service management unit 21 receives data request information D3 from the TCU 202A via the relay unit 11, it periodically transmits location information, power information, and door information to the edge server 180C via the relay unit 11 and the TCU 202A.
[0199] Referring again to Figures 5 and 6, in the edge server 180C, the service execution unit 42 determines whether or not vehicle 1 is parked.
[0200] More specifically, for example, when the service execution unit 42 receives power information from the in-vehicle relay device 101 via the communication unit 41, it checks whether the ignition power state indicated by the received power information is in the off state.
[0201] The service execution unit 42 determines that vehicle 1 is not parked if the ignition power supply is in the ON state.
[0202] On the other hand, the service execution unit 42 determines that vehicle 1 is parked if the ignition power supply is in the off state.
[0203] For example, the storage unit 43 stores map information for a region that includes the location indicated by the location information transmitted from the in-vehicle relay device 101.
[0204] If the service execution unit 42 determines that vehicle 1 is parked, it uses the location information received from the in-vehicle relay device 101 immediately after determining that vehicle 1 is parked, and the map information stored in the storage unit 43, to identify the location of the parking lot where vehicle 1 is parked.
[0205] For example, if the hardware configuration Hw2 indicated by the resource-related information received by the resource management server 170 from the in-vehicle relay device 101 is insufficient for the hardware configuration Hw1 required to perform the door unlocking service, the edge server 180C will acquire data corresponding to the missing hardware configuration from equipment outside the vehicle 1. The edge server 180C will then transmit the acquired data to the in-vehicle relay device 101.
[0206] More specifically, for example, in the edge server 180C, the service execution unit 42 identifies the location of the parking lot where vehicle 1 is parked, and then checks whether or not vehicle 1 is equipped with a camera that captures facial images of the occupants of vehicle 1.
[0207] Specifically, the service execution unit 42 checks whether a camera is installed on the vehicle 1 by referring to resource-related information contained in resource information E3 received from the resource management server 170.
[0208] If a camera is not mounted on the vehicle 1, the service execution unit 42 acquires image information from peripheral equipment located outside the vehicle 1, such as a camera installed in a parking lot.
[0209] For example, the edge server 180C communicates with a camera installed in the parking lot where vehicle 1 is parked. When the camera detects a person at a target location in the parking lot, it sends image information showing the face of the detected person to the edge server 180C.
[0210] The edge server 180C is not limited to a camera installed in the parking lot; it may also be a communication terminal device carried by the occupant of vehicle 1, and may be configured to communicate with a communication terminal device including a camera. In this case, for example, when the occupant of vehicle 1 unlocks the door of vehicle 1 while it is parked, they use the communication terminal device to take a picture of their own face. The communication terminal device transmits image information showing the face image to the edge server 180C.
[0211] When the service execution unit 42 receives image information from a camera installed in the parking lot via the communication unit 41, it checks whether the door open / closed state, as indicated by the door information received from the in-vehicle relay device 101 immediately after receiving the image information, is in the closed state.
[0212] On the other hand, if a camera is mounted on the vehicle 1, the service execution unit 42 checks whether the door open / closed state indicated by the door information received from the in-vehicle relay device 101 immediately after identifying the parking lot location is in the closed state.
[0213] Then, if the door is in the closed state, the service execution unit 42 performs a door unlocking service.
[0214] The edge server 180C transmits the results of the door unlocking service to the in-vehicle relay device 101.
[0215] More specifically, for example, in the edge server 180B, the service execution unit 42 transmits control information (hereinafter also referred to as "control information G3"), which is the result of executing the door unlocking service, to the in-vehicle relay device 101 via the communication unit 41 and TCU 202A. Control information G3 is information for controlling the in-vehicle equipment 202 that should be operated to unlock the doors of the vehicle 1. In this case, the in-vehicle equipment 202 is the door lock ECU.
[0216] For example, when the service execution unit 42 acquires image information from a camera installed in the parking lot, it transmits the image information, authentication information B2, and the vehicle ID of vehicle 1 to the in-vehicle relay device 101 in the control information G3.
[0217] Furthermore, for example, if a camera is mounted on vehicle 1, the service execution unit 42 transmits the control information G3, including the authentication information B2 and the vehicle ID of vehicle 1, to the in-vehicle relay device 101.
[0218] Referring again to Figure 3, in the in-vehicle relay device 101, when the control unit 22 receives control information G3 from the edge server 180C via the TCU 202A and relay unit 11, it performs facial recognition of the occupant of vehicle 1.
[0219] For example, the memory unit 13 stores passenger information that shows the facial images of the passengers of vehicle 1. If the control unit 22 receives control information G3 from the edge server 180C and includes image information, it calculates the similarity between the facial image shown in the image information and the facial image shown in the passenger information stored in the memory unit 13.
[0220] On the other hand, if the control information G3 received from the edge server 180C does not contain image information, the control unit 22 calculates the similarity between the face image shown in the image information received from the camera mounted on the vehicle 1 and the face image shown in the passenger information stored in the storage unit 13.
[0221] The control unit 22 determines that face recognition has failed if the calculated similarity is below the threshold. On the other hand, the control unit 22 determines that face recognition has succeeded if the calculated similarity is equal to or greater than the threshold.
[0222] When the control unit 22 determines that facial recognition has been successful, it performs authentication processing C11 on the control information G3 received from the edge server 180C. If the authentication processing C11 of the control information G3 is successful, the control unit 22 transmits the control information G3 to the door lock ECU via the relay unit 11.
[0223] When the door lock ECU receives control information G3 from the in-vehicle relay device 101, it operates according to the received control information G3. That is, the door lock ECU unlocks the doors of vehicle 1.
[0224] (Request to release resources) Referring again to Figures 2 and 3, in the in-vehicle relay device 101, the service management unit 21 sends a request to release resource R to the resource management server 170.
[0225] More specifically, for example, the service management unit 21 determines whether the conditions for terminating the provision of service S (hereinafter also referred to as "termination conditions") are met. Termination conditions include when the user of vehicle 1 requests the termination of service S, and when vehicle 1 moves from within the service area of service S to outside the service area. In the following explanation, we will assume that the termination condition is when the user of vehicle 1 requests the termination of service S.
[0226] For example, the navigation device 202C receives input indicating a desire to terminate the provision of service S. Upon receiving this input, the navigation device 202C transmits termination information indicating the desire to terminate the provision of service S to the in-vehicle relay device 101.
[0227] In the in-vehicle relay device 101, when the service management unit 21 receives termination information from the navigation device 202C via the relay unit 11, it determines that the termination conditions have been met. The service management unit 21 then sends a release request information, including a request to release resource R, authentication information B1, and the vehicle ID stored in the storage unit 13, to the resource management server 170 via the relay unit 11 and TCU 202A.
[0228] (Authentication process for release requests) Referring again to Figure 4, in the resource management server 170, when the communication unit 31 receives release request information from the in-vehicle relay device 101 via the TCU 202A, it outputs the received release request information to the authentication unit 33.
[0229] For example, the authentication unit 33 performs authentication processing C2 for a release request. More specifically, for example, when the authentication unit 33 receives release request information from the communication unit 31, it performs authentication processing C2 using the authentication information B1 contained in the release request information.
[0230] If the authentication process C2 is successful, the authentication unit 33 outputs authentication success information Q2, which indicates that the authentication process C2 was successful, along with the vehicle ID included in the release request information received from the communication unit 31, to the resource release unit 35.
[0231] On the other hand, if the authentication process C2 fails, the authentication unit 33 transmits authentication failure information F2, indicating that the authentication process C2 has failed, to the in-vehicle relay device 101 via the communication unit 31 and TCU202A.
[0232] (Release of resource R) The resource release unit 35 receives a request to release resource R from the in-vehicle relay device 101 via the communication unit 31 and releases resource R.
[0233] More specifically, for example, when the resource release unit 35 receives authentication success information Q2 from the communication unit 31, it obtains service information from the storage unit 36 that indicates the same vehicle ID as the vehicle ID included in the authentication success information Q2.
[0234] When the resource release unit 35 obtains service information from the storage unit 36, it releases the resource R indicated by the obtained service information.
[0235] More specifically, for example, when the resource release unit 35 obtains service information from the storage unit 36, it refers to the resource management table in the storage unit 36 to identify the service ID corresponding to the resource indicated by the obtained service information.
[0236] The resource release unit 35 then sends stop request information indicating a request to stop the execution of service S to the edge server 180 of the identified service ID via the communication unit 31.
[0237] Furthermore, for example, when the resource release unit 35 obtains service information from the storage unit 36, it performs an update process N2 to update the resource management table in the storage unit 36. Specifically, for example, the resource release unit 35 updates the value of the discrimination flag corresponding to the resource R indicated by the service information in the resource management table from "1" to "zero". In this way, the resource release unit 35 releases the resource R corresponding to the release request received from the in-vehicle relay device 101, making the resource R available for use in other vehicles 1.
[0238] (Stopping service execution) Referring again to Figure 5, in the edge server 180, when the service execution unit 42 receives stop request information from the resource management server 170 via the communication unit 41, it stops the execution of service S in accordance with the received stop request information.
[0239] [Operation Flow] Next, the operation flow of each device in the communication system according to the embodiment of this disclosure will be explained with reference to the drawings.
[0240] Figures 7 and 8 are flowcharts illustrating an example of the operation procedure when an in-vehicle relay device according to an embodiment of this disclosure controls in-vehicle equipment.
[0241] Referring to Figures 7 and 8, first, the in-vehicle relay device 101 waits for route information to be received from the navigation device 202C (NO in step ST101).
[0242] Then, when the in-vehicle relay device 101 receives route information from the navigation device 202C (YES in step ST101), it includes the vehicle ID stored in the storage unit 13 in the received route information and sends it to the resource management server 170 via the TCU 202A (step ST102).
[0243] Next, the in-vehicle relay device 101 waits for service information to be received from the resource management server 170 (NO in step ST103).
[0244] Then, when the in-vehicle relay device 101 receives service information from the resource management server 170 (YES in step ST103), it sends execution request information, including the execution request for service S, authentication information B1, and resource-related information, to the resource management server 170 via the TCU 202A (step ST104).
[0245] Next, the in-vehicle relay device 101 awaits the reception of data request information or control information from the edge server 180 (NO in step ST105 or NO in step ST107).
[0246] Then, when the in-vehicle relay device 101 receives data request information from the edge server 180 (YES in step ST105), it transmits vehicle information indicating the status of vehicle 1, of the type indicated by the received data request information, to the edge server 180 via the TCU 202A (step ST106), and waits to receive new data request information or control information from the edge server 180 (NO in step ST105 or NO in step ST107).
[0247] Furthermore, the in-vehicle relay device 101 receives control information from the edge server 180, and if the authentication process C11 of the received control information is successful (YES in step ST107 and YES in step ST108), it uses the control information to control the in-vehicle device 202. For example, as described above, the in-vehicle relay device 101 transmits the received control information to the in-vehicle device 202 (step ST109).
[0248] Next, the in-vehicle relay device 101 determines whether or not the termination conditions for terminating the provision of service S are met (step ST110).
[0249] Then, if the in-vehicle relay device 101 determines that the termination conditions are met (YES in step ST110), it sends a release request information including a request to release resource R and authentication information B1 to the resource management server 170 via the TCU 202A (step ST111), and waits to receive new route information from the navigation device 202C (NO in step ST101).
[0250] On the other hand, if the authentication process C11 of the received control information fails (NO in step ST108), the in-vehicle relay device 101 sends authentication failure information F11 to the navigation device 202C indicating that the edge server 180 that sent the control information is an unauthorized server (step ST112), and waits to receive new route information from the navigation device 202C (NO in step ST101).
[0251] Figures 9 and 10 are flowcharts illustrating an example of the operation procedure when a resource management server according to the embodiment of this disclosure allocates resources.
[0252] Referring to Figures 9 and 10, first, the resource management server 170 waits for route information to be received from the in-vehicle relay device 101 (NO in step ST201).
[0253] Then, when the resource management server 170 receives route information from the in-vehicle relay device 101 (YES in step ST201), it creates service information indicating the services S that the edge server 180 can execute. For example, as described above, the resource management server 170 creates service information using the route information received from the in-vehicle relay device 101 and the service table stored in the storage unit 36 (step ST202).
[0254] Next, the resource management server 170 transmits the created service information to the in-vehicle relay device 101 via the TCU 202A (step ST203).
[0255] Next, the resource management server 170 waits for the receipt of execution request information from the in-vehicle relay device 101 (NO in step ST204).
[0256] Then, when the resource management server 170 receives execution request information from the in-vehicle relay device 101 (YES in step ST204), it performs authentication processing C1 for the execution request of service S included in the received execution request information (step ST205).
[0257] Next, if the authentication process C1 is successful (YES in step ST206), the resource management server 170 checks whether the hardware configuration Hw2 of vehicle 1, indicated by the resource-related information included in the received execution request information, satisfies the hardware configuration Hw1 required for the execution of service S, indicated by the created service information (step ST207).
[0258] Then, if the hardware configuration Hw2 does not satisfy the hardware configuration Hw1 (NO in step ST207), the resource management server 170 determines whether it is possible to allocate resource R to execute service S. For example, as described above, the resource management server 170 checks whether the value of the discrimination flag corresponding to resource R is "zero" by referring to the resource management table in the storage unit 36 (step ST208).
[0259] Then, if the resource management server 170 determines that it is possible to allocate resource R (YES in step ST208), it allocates resource R (step ST209).
[0260] Next, the resource management server 170 sends resource information indicating the type of resource R that has been allocated, along with the server ID of the edge server 180 corresponding to that resource R and the vehicle ID included in the execution request information received from the in-vehicle relay device 101, to the edge server 180 (step ST210).
[0261] Next, the resource management server 170 sends executable information to the in-vehicle relay device 101 via the TCU 202A indicating that the edge server 180 will execute service S (step ST211). Steps ST210 and ST211 may be executed in any order or in parallel.
[0262] Next, the resource management server 170 waits for the release request information from the in-vehicle relay device 101 (NO in step ST212).
[0263] Then, when the resource management server 170 receives release request information from the in-vehicle relay device 101 (YES in step ST212), it performs authentication processing C2 for the release request of resource R included in the received release request information (step ST213).
[0264] Next, if the authentication process C2 is successful (YES in step ST214), the resource management server 170 releases resource R. For example, as described above, the resource management server 170 updates the discrimination flag corresponding to the resource R to be released in the resource management table in the storage unit 13 to a value indicating that resource R is not allocated. The resource management server 170 also sends a stop request information to the edge server 180 requesting the cessation of service S (step ST215).
[0265] On the other hand, if authentication process C1 fails (NO in step ST206), the resource management server 170 sends authentication failure information F1 indicating that authentication process C1 has failed to the in-vehicle relay device 101 via the TCU 202 (step ST216), and waits to receive new route information from the in-vehicle relay device 101 (NO in step ST201).
[0266] Furthermore, if the hardware configuration Hw2 satisfies the hardware configuration Hw1 (YES in step ST207), the resource management server 170 sends non-execution information to the in-vehicle relay device 101 via the TCU 202A indicating that the edge server 180 does not need to execute service S (step ST217), and waits to receive new route information from the in-vehicle relay device 101 (NO in step ST201).
[0267] Furthermore, if the resource management server 170 determines that resource R cannot be allocated (NO in step ST208), it sends an execution failure information to the in-vehicle relay device 101 via the TCU 202A indicating that the edge server 180 cannot execute service S (step ST218), and waits for the receipt of new route information from the in-vehicle relay device 101 (NO in step ST201).
[0268] Furthermore, if authentication process C2 fails (NO in step ST214), the resource management server 170 sends authentication failure information F2 indicating that authentication process C2 has failed to the in-vehicle relay device 101 via the TCU 202 (step ST219), and waits to receive new route information from the in-vehicle relay device 101 (NO in step ST201).
[0269] Figure 11 is a flowchart that shows an example of the operation procedure when an edge server according to the embodiment of this disclosure performs a service.
[0270] Referring to FIG. 11, first, the edge server 180 waits for receiving resource information from the resource management server 170 (NO in step ST301).
[0271] Next, when the edge server 180 receives resource information from the resource management server 170 (YES in step ST301), it transmits data request information indicating a request to transmit vehicle information used for generating control information according to the received resource R, that is, the resource indicated by the received resource information, to the in-vehicle relay device 101 according to the data collection function (step ST302).
[0272] Next, the edge server 180 waits for receiving vehicle information from the in-vehicle relay device 101 (NO in step ST303).
[0273] Next, when the edge server 180 receives vehicle information from the in-vehicle relay device 101 (YES in step ST303), and when the resource R allocated by the resource management server 170 is the data collection function H3 necessary for executing the door unlocking service (YES in step ST3'04), it checks whether a camera is mounted on the vehicle 1 (step ST305).
[0274] Then, when a camera is mounted on the vehicle 1 (YES in step ST305), the edge server 180 executes the service S using the vehicle information received from the in-vehicle relay device 101. For example, as described above, the edge server 180 generates control information using the vehicle information (step ST306).
[0275] Next, the edge server 180 transmits the execution result of the service S, that is, the generated control information, to the in-vehicle relay device 101 via the TCU202A (step ST307), and waits for receiving new resource information from the resource management server 170 (NO in step ST301).
[0276] On the other hand, when the camera is not mounted on the vehicle 1 (NO in step ST305), the edge server 180 acquires image information showing the face image of the passenger in the vehicle 1 from a camera provided outside the vehicle 1 (step ST308), and executes the service S using the vehicle information received from the in-vehicle relay device 101 (step ST309).
[0277] Next, the edge server 180 transmits the generated control information and the acquired image information to the in-vehicle relay device 101 via the TCU202A (step ST310), and waits for reception of new resource information from the resource management server 170 (NO in step ST301).
[0278] Also, when the edge server 180 receives vehicle information from the in-vehicle relay device 101 (YES in step ST303), and the resource R allocated by the resource management server 170 is not the collection function H3 (NO in step ST304), the edge server 180 executes the service S using the vehicle information (step ST306).
[0279] FIG. 12 is a flowchart defining an example of an operation procedure when an edge server according to an embodiment of the present disclosure performs a process of stopping the execution of a service.
[0280] Referring to FIG. 12, first, the edge server 180 waits for reception of stop request information from the resource management server 170 (NO in step ST401).
[0281] Then, when the edge server 180 receives the stop request information from the resource management server 170 (YES in step ST401), the edge server 180 stops the execution of the service S (step ST402).
[0282] FIGS. 13 and 14 are diagrams showing an example of a sequence of processes of each device in a communication system according to an embodiment of the present disclosure.
[0283] Referring to Figures 13 and 14, first, the navigation device 202C transmits route information to the in-vehicle relay device 101 (step ST501).
[0284] Next, the in-vehicle relay device 101 transmits the route information received from the navigation device 202C to the resource management server 170 (step ST502).
[0285] Next, when the resource management server 170 receives route information from the in-vehicle relay device 101, it creates service information indicating the services S that the edge server 180 can execute (step ST503).
[0286] Next, the resource management server 170 transmits the created service information to the in-vehicle relay device 101 (step ST504).
[0287] Next, when the in-vehicle relay device 101 receives service information from the resource management server 170, it sends execution request information to the resource management server 170, including the execution request for service S indicated by the received service information, authentication information B1, and vehicle ID (step ST505).
[0288] Next, when the resource management server 170 receives execution request information from the in-vehicle relay device 101, it performs authentication processing C1 for the execution request of service S included in the received execution request. Here, we assume that authentication processing C1 is successful (step ST506).
[0289] Next, if the authentication process C1 is successful, the resource management server 170 allocates the resource R to be used to execute the service S (step ST507).
[0290] Next, the resource management server 170 sends resource information E1, which indicates the type of resource R that has been allocated, to the edge server 180A (step ST508).
[0291] Next, when the edge server 180A receives the resource information E1 from the resource management server 170, it transmits data request information D1 indicating a request to transmit vehicle information, specifically position information and vehicle speed information, used for generating control information, to the in-vehicle relay device 101 (step ST509).
[0292] Next, when the in-vehicle relay device 101 receives the data request information D1 from the edge server 180A, it transmits the position information and the vehicle speed information to the edge server 180A (step ST510).
[0293] Next, the edge server 180A executes the LKAS service and the ACC service (step ST511).
[0294] Next, the edge server 180A transmits control information G1 for controlling the steering ECU to the in-vehicle relay device 101 as a result of the execution of the LKAS service (step ST512).[[ID=第十三条]] [[ID=第十四条]]
[0295] [[ID=第十五条]] ]>Also, the edge server 180A transmits control information G2 for controlling the brake ECU to the in-vehicle relay device 101 as a result of the execution of the ACC service (step ST513).
[0296] Next, when the in-vehicle relay device 101 receives the control information G1 from the edge server 18%A, it transmits the received control information G1 to the steering ECU (step ST514).
[0297] Also, when the in-vehicle relay device 101 receives the control information G2 from the edge server a80A, it transmits the received control information G2 to the brake ECU (step ST515).
[0298] Next, when the steering ECU receives the control information G1 from the in-vehicle relay device 101, it operates according to the received control information G1 (step ST516).<00>
[0299] Furthermore, when the brake ECU receives control information G2 from the in-vehicle relay device 101, it operates according to the received control information G2 (step ST517).
[0300] Next, the navigation device 202C transmits termination information to the in-vehicle relay device 101 indicating that it wishes to terminate the provision of LKAS service and ACC service (step ST518).
[0301] Next, when the in-vehicle relay device 101 receives termination information from the navigation device 202C, it determines that the termination conditions for terminating the provision of LKAS service and ACC service have been met (step ST519).
[0302] Next, the in-vehicle relay device 101 sends a request to release resource R, along with release request information including the vehicle ID, to the resource management server 170 (step ST520).
[0303] Next, the resource management server 170 performs authentication process C2 for the resource R release request. Here, we assume that authentication process C2 is successful (step ST521).
[0304] Next, if the authentication process C2 is successful, the resource management server 170 releases resource R. For example, as described above, the resource management server 170 performs an update process N2 in the resource management table in the storage unit 36, updating the discrimination flag corresponding to the resource R to be released to a value indicating that resource R is not allocated (step ST522).
[0305] Furthermore, the resource management server 170 sends a stop request information to the edge server 180A requesting the cessation of the LKAS service and the ACC service (step ST523).
[0306] Next, when the edge server 180A receives a stop request information from the resource management server 170, it stops the execution of the LKAS service and the ACC service (step ST524).
[0307] Incidentally, it is desirable to make effective use of the resource R used to perform service S related to vehicle 1. As described above, by configuring the resource management server 170 to release resource R in accordance with a release request from the in-vehicle relay device 101, resource R can be used for the period necessary to perform service S. This makes it possible to effectively utilize the shared resource among each vehicle 1.
[0308] In the communication system 501 according to the embodiment of this disclosure, the resource management server 170 is configured to transmit service information indicating the services S that the edge server 180 can execute to the in-vehicle relay device 101, but this is not the only configuration. The resource management server 170 may be configured not to transmit service information. In this case, for example, the in-vehicle relay device 101 uses information such as route information received from the navigation device 202C to determine the type of service S it wishes to execute. The in-vehicle relay device 101 then includes information indicating the determined type of service S in the execution request information and transmits it to the resource management server 170.
[0309] Furthermore, in the communication system 501 according to the embodiment of this disclosure, the resource management server 170 is configured to send executable information to the in-vehicle relay device 101 indicating that the edge server 180 will execute service S if the hardware configuration Hw2 does not satisfy the hardware configuration Hw1, but the invention is not limited to this configuration. The resource management server 170 may be configured not to send executable information to the in-vehicle relay device 101.
[0310] Furthermore, in the communication system 501 according to the embodiment of this disclosure, the in-vehicle relay device 101 is configured to transmit vehicle information used to generate control information for controlling the in-vehicle equipment 202 to the edge server 180, but it is not limited to this configuration. The in-vehicle relay device 101 may be configured not to transmit the vehicle information to the edge server 180. In this case, the edge server 180 generates the control information using information other than the vehicle information.
[0311] Furthermore, in the communication system 501 according to the embodiment of this disclosure, the in-vehicle relay device 101 is configured to transmit information regarding the hardware configuration Hw1 of the vehicle 1 to the resource management server 170 as resource-related information used for the allocation of resource R by the resource management server 170, but it is not limited to this configuration. The in-vehicle relay device 101 may also be configured to transmit information regarding the software configuration of the vehicle 1 to the resource management server 170 as resource-related information.
[0312] Furthermore, while the communication system 501 according to the embodiment of this disclosure is configured such that the resource management server 170 performs authentication processing C1 for service execution requests, it is not limited to this configuration. The resource management server 170 may be configured not to perform authentication processing C1.
[0313] Furthermore, while the communication system 501 according to the embodiment of this disclosure is configured such that the resource management server 170 performs authentication processing C2 for resource R release requests, it is not limited to this configuration. The resource management server 170 may be configured not to perform authentication processing C2.
[0314] Furthermore, although the communication system 501 according to the embodiment of this disclosure is described as having separate devices for the resource management server 170 and the edge server 180, it is not limited to this. The edge server 180 may be included in the resource management server 170.
[0315] Furthermore, some or all of the functions of the resource management server 170 according to the embodiment of this disclosure may be provided by cloud computing. That is, the resource management server 170 according to the embodiment of this disclosure may be a cloud server composed of multiple servers.
[0316] Furthermore, some or all of the functions of the edge server 180 according to the embodiment of this disclosure may be provided by cloud computing. That is, the edge server 180 according to the embodiment of this disclosure may be a cloud server composed of multiple servers.
[0317] [Differentiation] In the communication system 501 according to the embodiment of this disclosure, the resource management server 170 is configured to send non-execution information to the in-vehicle relay device 101 indicating that the edge server 180 does not need to execute service S if hardware configuration Hw2 satisfies hardware configuration Hw1, but it is not limited to this. The resource management server 170 may also be configured to check whether the software used to execute service S is incorporated into the in-vehicle device 202 corresponding to service S if hardware configuration Hw2 satisfies hardware configuration Hw1.
[0318] Referring again to Figure 3, in the modified example, in the in-vehicle relay device 101, the storage unit 13 stores device information indicating the type of application, which is software installed on each in-vehicle device 202.
[0319] When the service management unit 21 receives service information from the relay unit 11, it sends the execution request information, which includes the execution request for service S, authentication information B1, and resource-related information, as well as device information stored in the storage unit 13, to the resource management server 170 via the relay unit 11 and TCU202A.
[0320] Referring again to Figure 4, in the modified example, the resource management server 170 transmits download information to the in-vehicle relay device 101 indicating the download source of the software used to execute service S and to be incorporated into the in-vehicle device 202.
[0321] For example, in the resource management server 170, when the authentication process C1 for the execution request of service S is successful, the authentication success information Q1 is output to the resource allocation unit 34, including the vehicle ID, resource-related information, and equipment information contained in the execution request information received from the in-vehicle relay device 101 via the communication unit 31.
[0322] When the resource allocation unit 34 receives authentication success information Q1 from the authentication unit 33, it obtains service information from the storage unit 36 that indicates the same vehicle ID as the vehicle ID included in the authentication success information Q1.
[0323] The resource allocation unit 34 checks whether the application necessary to execute the service S is installed on the in-vehicle device 202 if the hardware configuration Hw2 indicated by the resource-related information included in the authentication success information Q1 received from the authentication unit 33 satisfies the hardware configuration Hw1 corresponding to the service S indicated by the service information obtained from the storage unit 36.
[0324] For example, the storage unit 36 stores application information for each service S, indicating the type of application required to perform that service S.
[0325] If the hardware configuration Hw2 satisfies the hardware configuration Hw1, the resource allocation unit 34 refers to the application corresponding to the service S indicated by the acquired service information by referring to the application information in the storage unit 36 (hereinafter also referred to as "application Ap").
[0326] The resource allocation unit 34 then checks whether the application Ap is registered in the device information included in the authentication success information Q1 received from the authentication unit 33.
[0327] If application Ap is registered in the device information, the resource allocation unit 34 transmits non-executable information to the in-vehicle relay device 101 via the communication unit 31 and TCU 202A. However, in this case, the resource allocation unit 34 may be configured not to transmit non-executable information to the in-vehicle relay device 101.
[0328] On the other hand, if the application Ap is not registered in the device information, the resource allocation unit 34 transmits download information to the in-vehicle relay device 101 via the communication unit 31 and TCU202A.
[0329] Specifically, for example, the resource allocation unit 34 transmits to the in-vehicle relay device 101 as download information, which includes a URL (Uniform Resource Locater) indicating the download source of application Ap, the ID of the in-vehicle device 202 that should download application Ap (hereinafter also referred to as "device ID"), and the vehicle ID included in the authentication success information Q1 received from the authentication unit 33.
[0330] Referring again to Figure 2, when the in-vehicle relay device 101 receives download information from the resource management server 170 via the TCU 202A, it sends URL information indicating the URL included in the received download information to the in-vehicle device 202 with the device ID included in the download information.
[0331] When the in-vehicle device 202 receives URL information from the in-vehicle relay device 101, it accesses the URL indicated by the received URL information via the TCU 202A and the external network 151 to download the application Ap.
[0332] The embodiments described above should be considered in all respects to be illustrative and not restrictive. The scope of the present invention is indicated by the claims rather than the above description, and all modifications within the meaning and scope equivalent to the claims are intended to be included.
[0333] Each process (each function) of the above-described embodiment is implemented by a processing circuit including one or more processors. The processing circuit may consist of one or more memories, various analog circuits, various digital circuits, and other integrated circuits in addition to the one or more processors. The one or more memories store programs (instructions) that cause the one or more processors to execute each of the above processes. The one or more processors may execute each of the above processes according to the programs read from the one or more memories, or they may execute each of the above processes according to logic circuits that have been pre-designed to execute each of the above processes. The processors may be various processors suitable for computer control, such as a CPU (Central Processing Unit), GPU (Graphics Processing Unit), DSP (Digital Signal Processor), FPGA (Field Programmable Gate Array), and ASIC (Application Specific Integrated Circuit). Furthermore, the physically separated multiple processors may cooperate with each other to execute each of the above processes. For example, the processors installed in each of several physically separate computers may cooperate with each other via a network such as a LAN (Local Area Network), WAN (Wide Area Network), and the Internet to perform the above processes. The program may be installed in the memory via the network from an external server device, or it may be distributed on a recording medium such as a CD-ROM (Compact Disc Read Only Memory), DVD-ROM (Digital Versatile Disk Read Only Memory), and semiconductor memory, and then installed in the memory from the recording medium.
[0334] The above description includes the following features. [Note 1] A service management method in a communication system comprising an in-vehicle device mounted on a vehicle and a management device, The in-vehicle device transmits a request to the management device to perform a service related to the vehicle, The management device, based on the execution request received from the in-vehicle device, performs the following steps: The management device performs the service using the allocated resources, The management device transmits the results of the service execution to the in-vehicle device, The in-vehicle device controls the in-vehicle equipment of the vehicle using the execution result received from the management device, The in-vehicle device sends a request to release the resource to the management device, A service management method comprising the steps of: the management device receiving the release request from the in-vehicle device and releasing the resource.
[0335] [Note 2] A service management method for an in-vehicle device installed in a vehicle, The steps include sending a request to a management device to perform a service related to the aforementioned vehicle, The steps include receiving the execution result of the service from the management device, The steps include controlling the in-vehicle equipment of the vehicle using the received execution result, A service management method comprising the step of sending a request to the management device for the release of resources used to perform the service.
[0336] [Note 3] A resource management method for a management device that communicates with an in-vehicle device installed in a vehicle, The steps include receiving a request from the in-vehicle device to perform a service related to the vehicle, The steps include: allocating resources to be used to execute the service based on the received execution request; The steps include: executing the service using the allocated resources and transmitting the execution result of the service to the in-vehicle device; The steps include receiving a request to release the aforementioned resources from the in-vehicle device, A resource management method comprising the step of receiving the release request and releasing the resource.
[0337] [Note 4] An in-vehicle device installed in a vehicle, Equipped with a processing circuit, The aforementioned processing circuit is A request to perform a service related to the aforementioned vehicle is sent to the management device. The management device receives the execution result of the service, Using the received execution result, the in-vehicle equipment of the vehicle is controlled. An in-vehicle device that sends a request to the management device to release the resources used to perform the aforementioned service.
[0338] [Note 5] A management device that communicates with in-vehicle equipment installed in a vehicle, Equipped with a processing circuit, The aforementioned processing circuit is The in-vehicle device receives a request to perform a service related to the vehicle, Based on the received execution request, the system allocates resources to be used to execute the service. The allocated resources are used to execute the service, and the results of the service execution are transmitted to the in-vehicle device. The vehicle receives a request to release the aforementioned resources from the in-vehicle device. A management device that receives the aforementioned release request and releases the aforementioned resource. [Explanation of Symbols]
[0339] 1 vehicle 11 Relay section 12 Processing Units 13,36,43 Storage section 21 Service Management Department 22 Control Unit 31,41 Communications Department 32 Service Information Creation Department 33. Authentication Department 34 Resource Allocation Section 35 Resource Release Section 42 Service Execution Unit 51, 51A, 51B CAN bus 101 Vehicle-mounted relay device 151 External Network 161 Wireless base station equipment 170 Resource Management Server 180, 180A, 180B, 180C Edge Servers 202,202A,202B,202C,202D Vehicle equipment 301 In-vehicle systems 501 Communication System
Claims
1. Onboard equipment installed in the vehicle, Equipped with a management device, The in-vehicle device transmits a request to the management device to perform a service related to the vehicle. The management device, based on the execution request received from the in-vehicle device, allocates resources to be used to execute the service. The management device executes the service using the allocated resources. The management device transmits the results of the service execution to the in-vehicle device. The in-vehicle device uses the execution results received from the management device to control the in-vehicle equipment of the vehicle. The in-vehicle device transmits a request to release the resource to the management device. The management device is a communication system that receives the release request from the in-vehicle device and releases the resources.
2. The communication system according to claim 1, wherein the management device transmits information regarding the services that can be executed by the management device to the in-vehicle device.
3. The communication system according to claim 1 or 2, wherein the management device transmits information to the in-vehicle device indicating whether or not the service can be performed.
4. The communication system according to claim 1 or 2, wherein the management device transmits to the in-vehicle device information indicating the source from which the software used to perform the service is downloaded to the in-vehicle device.
5. The in-vehicle device transmits to the management device the vehicle information, which indicates the status of the vehicle and is used to generate the execution result, which is control information for controlling the in-vehicle equipment. The communication system according to claim 1 or 2, wherein the management device generates the control information using the vehicle information received from the in-vehicle device.
6. The communication system according to claim 5, wherein the in-vehicle device transmits at least one of the vehicle's location information and vehicle speed information to the management device as vehicle information when the service is a service relating to the autonomous driving of the vehicle or a service relating to avoiding obstacles while the vehicle is in motion.
7. The communication system according to claim 5, wherein, if the service is a service for unlocking the doors of the vehicle, the in-vehicle device transmits at least one of the following to the management device as vehicle information: location information of the vehicle, information indicating the power status of the vehicle, and information indicating the open / closed state of the doors.
8. The in-vehicle device transmits resource-related information, which is used for resource allocation by the management device and indicates the hardware configuration of the vehicle, to the management device. The communication system according to claim 1 or 2, wherein the management device allocates the resources using the resource-related information received from the in-vehicle device.
9. The communication system according to claim 8, wherein if the hardware configuration indicated by the resource-related information is insufficient for the hardware configuration required to perform the service, the management device obtains data corresponding to the insufficient hardware configuration from equipment outside the vehicle and transmits the obtained data to the in-vehicle device.
10. The communication system according to claim 1 or 2, wherein the management device performs authentication processing of the execution request.
11. The aforementioned control device is A first device equipped with the aforementioned resources and performing the service using those resources, It includes a second device for allocating the aforementioned resources, The communication system according to claim 1 or 2, wherein the first device transmits the execution result of the service to the in-vehicle device.
12. The communication system according to claim 1 or 2, wherein the management device performs authentication processing of the release request.
13. An in-vehicle device installed in a vehicle, A transmission unit that transmits a request to a management device to perform a service related to the aforementioned vehicle, A receiving unit that receives the execution results of the service from the management device, The system includes a control unit that controls the in-vehicle equipment of the vehicle using the execution results received by the receiving unit, The transmission unit is an in-vehicle device that transmits a request to the management device for the release of resources used to perform the service.
14. A management device that communicates with in-vehicle equipment installed in a vehicle, A communication unit that receives a request to perform a service related to the vehicle from the in-vehicle device, A resource allocation unit that allocates resources to be used to execute the service based on the execution request received by the communication unit, The system includes a service execution unit that executes the service using the resources allocated by the resource allocation unit and transmits the results of the service execution to the in-vehicle device, The communication unit receives a request to release the resource from the in-vehicle device, The aforementioned control device further, A management device comprising a resource release unit that releases the resource when the communication unit receives the release request.
15. A service management program used in an in-vehicle device installed in a vehicle, Computers, A transmission unit that transmits a request to a management device to perform a service related to the aforementioned vehicle, A receiving unit that receives the execution results of the service from the management device, Using the execution results received by the receiving unit, a control unit controls the in-vehicle equipment of the vehicle. It is a program designed to function as such. The transmission unit is a service management program that sends a request to the management device for the release of resources used to perform the service.
16. A resource management program used in a management device that communicates with an in-vehicle device installed in a vehicle, Computers, A communication unit that receives a request to perform a service related to the vehicle from the in-vehicle device, A resource allocation unit that allocates resources to be used to execute the service based on the execution request received by the communication unit, A service execution unit that executes the service using the resources allocated by the resource allocation unit and transmits the results of the service execution to the in-vehicle device. It is a program designed to function as such. The communication unit receives a request to release the resource from the in-vehicle device, The aforementioned computer is further, When the communication unit receives the release request, the resource release unit releases the resource. A resource management program designed to function as such.
Citation Information
Patent Citations
Device for vehicle, system for vehicle, and external device
JP2022114164A
Information processing device, information processing method, and program
JP2022174678A
Information processing apparatus
JP2022181596A