Control device, control system, and control method

The control device with dual hypervisors and a communication control unit effectively manages communication volumes to prevent network overload, allowing simultaneous application and evaluation/verification operations in integrated ECU systems.

JP2026076337APending Publication Date: 2026-05-11PANASONIC AUTOMOTIVE SYST CO LTD
View PDF 1 Cites 0 Cited by

Patent Information

Authority / Receiving Office
JP · JP
Patent Type
Applications
Current Assignee / Owner
PANASONIC AUTOMOTIVE SYST CO LTD
Filing Date
2026-02-17
Publication Date
2026-05-11

AI Technical Summary

Technical Problem

Existing systems struggle to perform application communication and evaluation/verification communication simultaneously without straining the network's communication capacity, particularly in integrated ECU environments.

Method used

A control device with a first and second hypervisor, connected via a gateway, that includes a communication control unit to dynamically manage the volume of application and evaluation/verification communication based on execution status and network capacity, prioritizing application communication when congestion is detected, and interrupting or restarting virtual machines as needed to maintain network capacity.

Benefits of technology

Enables simultaneous performance of application and evaluation/verification communication without overburdening the network, ensuring efficient operation and uninterrupted application communication by managing communication volumes and suspending or restarting virtual machines as necessary.

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure 2026076337000001_ABST
    Figure 2026076337000001_ABST
Patent Text Reader

Abstract

This invention provides a control device that can simultaneously perform application-based communication and evaluation / verification-based communication without straining the network's communication capacity. [Solution] A control device comprising a first hypervisor that generates a first virtual machine and a second hypervisor that generates a second virtual machine and communicates with the first hypervisor via a gateway includes a communication control unit that, while the first virtual machine and the second virtual machine are running, dynamically limits at least one of the communication volume for application communication and the communication volume for evaluation and verification based on the execution status of application communication performed between the first hypervisor and the second hypervisor, the execution status of evaluation and verification communication performed between the first hypervisor and the second hypervisor, and the communication capacity of the gateway.
Need to check novelty before this filing date? Find Prior Art

Description

Technical Field

[0001] The present disclosure relates to a control device, a control system, and a control method.

Background Art

[0002] Recently, in the trend of using an integrated ECU that integrates a plurality of ECUs, there has been an increasing need to evaluate and verify a virtual machine (VM) that operates across a plurality of ECUs. For example, Patent Document 1 discloses an example in which a virtualization infrastructure spanning a plurality of ECUs is constructed by transferring a context and a working memory of a virtual CPU indicating an execution state and execution content of the virtual CPU managed on a memory by a hypervisor to physically different ECUs using a general-purpose network.

Prior Art Documents

Patent Documents

[0005] This disclosure aims to provide a control device that can simultaneously perform application communication and evaluation / verification communication without straining the network's communication capacity. [Means for solving the problem]

[0006] The control device according to this disclosure is a vehicle-mountable control device comprising a first hypervisor that controls the execution of a first virtual machine, and a second hypervisor that controls the execution of a second virtual machine and communicates with the first hypervisor via a gateway, and includes a communication control unit that limits at least one of the communication volume of the application communication and the communication volume of the evaluation / verification communication based on the execution status of application communication performed between the first hypervisor and the second hypervisor and the execution status of evaluation / verification communication performed between the first hypervisor and the second hypervisor. [Effects of the Invention]

[0007] According to the control device, control system, and control method described herein, application communication and evaluation / verification communication can be performed simultaneously without straining the network's communication capacity. [Brief explanation of the drawing]

[0008] [Figure 1] Figure 1 is a block diagram showing an example of a schematic configuration of a vehicle control system. [Figure 2] Figure 2 is a functional block diagram showing an example of the functional configuration of the hypervisor included in a vehicle control system. [Figure 3] Figure 3 shows an overview of the communication control performed by the hypervisor in the first embodiment. [Figure 4] Figure 4 is a flowchart showing an example of the processing flow performed by the hypervisor in the first embodiment. [Figure 5]Figure 5 is a block diagram showing an example of a schematic configuration of a vehicle control system according to the second embodiment. [Figure 6] Figure 6 is a block diagram showing an example of a schematic configuration of a vehicle control system according to the third embodiment. [Modes for carrying out the invention]

[0009] (First embodiment) Hereinafter, various embodiments of the vehicle control system according to this disclosure will be described with reference to the drawings.

[0010] (Outline configuration of the vehicle control system) First, the general configuration of the vehicle control system according to all embodiments described below will be explained. The vehicle control system 10a is a system that is mounted on a vehicle and performs desired vehicle control by coordinating the operation of an infotainment system, such as a car navigation system, and an ITS system (Intelligent In Transportation Systems).

[0011] Figure 1 will be used to illustrate the schematic configuration of the vehicle control system 10a. Figure 1 is a block diagram showing an example of the schematic configuration of a vehicle control system.

[0012] The vehicle control system 10a comprises machine 12a and machine 12b, gateway 20, CPU(1) 24a, CPU(2) 24b, and CPU(3) 24c.

[0013] Machine 12a is an example of an information processing device that constitutes an infotainment system such as a car navigation system. Machine 12a is an example of a control device in this disclosure. Machine 12b is an example of an information processing device that constitutes an ITS (Intelligent Transportation System). Machine 12b is an example of a control device in this disclosure. Machine 12a and machine 12b may be physically separated, or they may exist within a single ECU or CPU.

[0014] Machine 12a comprises a virtual ECU VM(1) 14a, a virtual ECU VM(2) 14b, and a hypervisor 16a.

[0015] Virtual ECU VM(1)14a and Virtual ECU VM(2)14b are virtual machines that execute various applications running on machine 12a and perform evaluation and verification related to the operation of said applications. Here, evaluation and verification refers to processes that output trace data including various operation logs and timestamps related to the operating status of machine 12a. Virtual ECU VM(1)14a and Virtual ECU VM(2)14b are examples of the first virtual machine in this disclosure.

[0016] Note that virtual ECU VM(1)14a and virtual ECU VM(2)14b may run on different operating systems (OS). Also, there is no limit to the number of virtual ECU VMs that machine 12a has.

[0017] Hypervisor 16a is software for virtualizing a computer. Hypervisor 16a creates virtual computers, virtual ECU VM(1)14a and virtual ECU VM(2)14b, within the physical machine. Hypervisor 16a is an example of the first hypervisor in this disclosure.

[0018] The hypervisor 16a includes a memory (2-1) 18a, a memory (2-2) 18b, and a memory (2-3) 18c. The memory (2-1) 18a, the memory (2-2) 18b, and the memory (2-3) 18c are memory areas that divide the main memory device (e.g., RAM) included in the machine 12a.

[0019] The memory (2-1) 18a is a memory area that stores data (e.g., programs) and the like for operating the virtual ECU VM (2) 14b with the CPU (1) 24a. The memory (2-2) 18b is a memory area that stores data and the like for operating the virtual ECU VM (2) 14b with the CPU (2) 24b. The memory (2-3) 18c is a memory area that stores data and the like for operating the virtual ECU VM (2) 14b with the CPU (3) 24c.

[0020] The CPU (1) 24a, the CPU (2) 24b, and the CPU (3) 24c operate the virtual ECU VM (1) 14a and the virtual ECU VM (2) 14b by cooperating with the hypervisor 16a, respectively.

[0021] The machine 12b includes a virtual ECU VM (3) 14c, a virtual ECU VM (4) 14d, and a hypervisor 16b.

[0022] The virtual ECU VM (3) 14c and the virtual ECU VM (4) 14d are virtual machines that execute various applications, evaluations, verifications, etc. operating on the machine 12b. Note that the virtual ECU VM (3) 14c and the virtual ECU VM (4) 14d are an example of the second virtual machine in the present disclosure. Also, the machine 12b may include the virtual ECU VM (2) 14b shown in FIG. 1. The virtual ECU VM (2) 14b included in the machine 12b is the one transferred from the virtual ECU VM (2) 14b included in the machine 12a to the machine 12b. Thus, by transferring the virtual ECU VM between different machines, the virtual ECU VM (2) 14b can be operated on the hypervisor 16b. Thereby, the computing power of the virtual ECU VM (2) 14b can be enhanced.

[0023] Note that virtual ECU VM(3)14c and virtual ECU VM(4)14d may run on different operating systems. Also, there is no limit to the number of virtual ECU VMs that machine 12b has.

[0024] Hypervisor 16b is software for virtualizing a computer. Hypervisor 16b creates virtual computers, virtual ECU VM(3)14c and virtual ECU VM(4)14d, within the physical machine. In the example in Figure 1, VM(2)14b is also created. Note that hypervisor 16b is an example of a second hypervisor in this disclosure.

[0025] The hypervisor 16b is equipped with memory (2-3) 18c. Memory (2-3) 18c is transferred from the hypervisor 16a. Memory (2-3) 18c is a memory area that stores data and other information for virtually running the virtual ECU VM(2) 14b, which was equipped on machine 12a, on machine 12b, as shown by the dotted line in Figure 1. In this way, by running the virtual ECU VM(2) 14b on machine 12b, the computing power of the virtual ECU VM(2) 14b can be increased.

[0026] Gateway 20 controls communication between machine 12a and machine 12b. The specific communication method implemented by gateway 20 is not specified. Gateway 20 is equipped with a control mechanism 22. The control mechanism 22 monitors the amount of data flowing between machine 12a and machine 12b. Furthermore, if the total amount of data flowing between machine 12a and machine 12b, i.e., the sum of the amount of application communication C1 and the amount of evaluation / verification communication C2, exceeds a predetermined percentage of the gateway 20's communication capacity, the control mechanism 22 outputs a congestion control signal indicating that the gateway 20's communication capacity is being strained. If gateway 20 is configured as, for example, a LAN (Local Area Network), the control mechanism 22 is, for example, a hub. If gateway 20 is configured as, for example, a CAN (Control Area Network), the control mechanism 22 is, for example, a VIP (Vehicle Interface Processor).

[0027] In the vehicle control system 10a, hypervisors 16a and 16b communicate with each other via gateway 20 using application communication C1 to execute applications provided by the vehicle control system 10a.

[0028] Furthermore, hypervisors 16a and 16b communicate with each other via gateway 20 for evaluation and verification purposes, C2, to evaluate and verify the operating status of applications executed by machines 12a and 12b and the virtual ECU when the vehicle control system 10a is operating. In addition to evaluation, verification, analysis, and processing in the experimental environment, the vehicle control system 10a may also perform monitoring and diagnosis of its operating status when installed in a vehicle or other product.

[0029] In this embodiment, an example of applying the control device of this disclosure to a vehicle control system 10a is described, but the scope of application of the control device is not limited to in-vehicle use, and it can be applied to general embedded devices such as home appliances, for example.

[0030] (Hypervisor functional configuration) The functional configuration of the hypervisor 16a will be explained using Figure 2. Figure 2 is a functional block diagram showing an example of the functional configuration of the hypervisor provided in the vehicle control system. Although the functional configuration of the hypervisor 16a is explained here, the hypervisor 16b has the same functional configuration as the hypervisor 16a.

[0031] The hypervisor 16a implements the operation control unit 31, information transfer unit 32, communication capacity acquisition unit 33, communication volume determination unit 34, communication control unit 35, application execution unit 36, and evaluation / verification execution unit 37 shown in Figure 2 as functional components by executing the programs stored in memory (2-1) 18a, memory (2-2) 18b, and memory (2-3) 18c on CPU (1) 24a, CPU (2) 24b, and CPU (3) 24c, respectively.

[0032] The operation control unit 31 controls the startup, interruption, and restart of virtual ECU VM(1)14a and virtual ECU VM(2)14b. In other words, the operation control unit 31 performs virtual power on / off, virtual interruption, and restart of the virtual machines.

[0033] Furthermore, the operation control unit 31 monitors whether the application operation and the evaluation / verification operation have been completed.

[0034] The information transfer unit 32 transfers the virtual CPU context for evaluation and verification from hypervisor 16a to hypervisor 16b before starting virtual ECU VM(1)14a, virtual ECU VM(2)14b, virtual ECU VM(3)14c, and virtual ECU VM(4)14d. The virtual CPU context is the execution state and execution content of the virtual CPU managed in memory by the hypervisor, and is also called parity data in Patent Document 1. The information transfer unit 32 is an example of a transfer unit in this disclosure.

[0035] The communication capacity acquisition unit 33 acquires the communication capacity of the gateway 20.

[0036] The communication volume determination unit 34 determines whether the sum of the communication volume of application communication C1 and evaluation / verification communication C2 between hypervisor 16a and hypervisor 16b during the startup of virtual ECU VM(1)14a, virtual ECU VM(2)14b, virtual ECU VM(3)14c, and virtual ECU VM(4)14d is putting a strain on the communication capacity of gateway 20.

[0037] More specifically, the communication volume determination unit 34 determines whether the communication capacity of gateway 20 is being strained by comparing the sum of the communication volume of application communication C1 and the communication volume of evaluation / verification communication C2 with the communication capacity of gateway 20 acquired by the communication capacity acquisition unit 33. Alternatively, the communication volume determination unit 34 may determine that the communication capacity of gateway 20 is being strained when it receives a congestion control signal output by the control mechanism 22. Further details will be described later (see Figure 3).

[0038] Furthermore, the communication volume determination unit 34 monitors the amount of unsent data among the data that should be transmitted between the hypervisor 16a and the hypervisor 16b.

[0039] While the first virtual machines, virtual ECU VM(1)14a and virtual ECU VM(2)14b, and the second virtual machines, virtual ECU VM(3)14c and virtual ECU VM(4)14d, are running, the communication control unit 35 dynamically limits at least one of the communication volume of application communication C1 and evaluation / verification communication C2, based on the execution status of application communication C1 performed between hypervisor 16a and hypervisor 16b, the execution status of evaluation / verification communication C2 performed between hypervisor 16a and hypervisor 16b, and the communication capacity of gateway 20. For example, based on the determination result of the communication volume determination unit 34, the communication volume of application communication C1 and the communication volume of evaluation / verification communication C2 are controlled so that the sum of the communication volume of application communication C1 and the communication volume of evaluation / verification communication C2 does not exceed the communication capacity of gateway 20.

[0040] More specifically, when the communication control unit 35 receives a congestion control signal output by the control mechanism 22, it prioritizes the communication of the application communication C1 by limiting the amount of communication of the evaluation / verification communication C2.

[0041] Furthermore, if the amount of untransmitted data between hypervisor 16a and hypervisor 16b exceeds a predetermined value, the communication control unit 35 interrupts the operation of the first virtual machines, virtual ECU VM(1)14a and virtual ECU VM(2)14b, and the second virtual machines, virtual ECU VM(3)14c and virtual ECU VM(4)14d, and backports the untransmitted data between hypervisor 16a and hypervisor 16b. Backporting here refers to the operation of sending data back from one virtual ECU context or device context to another, from a machine that holds more recent data. Note that the conditions for interrupting the operation of the first and second virtual machines are not limited to the amount of untransmitted data between hypervisor 16a and hypervisor 16b exceeding a predetermined value, and the conditions for interrupting operation may be set as appropriate.

[0042] Furthermore, the communication control unit 35 restarts the operation of the first virtual machines, virtual ECU VM(1)14a and virtual ECU VM(2)14b, and the second virtual machines, virtual ECU VM(3)14c and virtual ECU VM(4)14d, when the amount of untransmitted data between hypervisor 16a and hypervisor 16b falls below a predetermined value. Note that the conditions for restarting the operation of the first and second virtual machines are not limited to when the amount of untransmitted data between hypervisor 16a and hypervisor 16b falls below a predetermined value, and the conditions for restarting operation may be set as appropriate.

[0043] The application execution unit 36 ​​causes the virtual ECU VM(1)14a, virtual ECU VM(2)14b, virtual ECU VM(3)14c, and virtual ECU VM(4)14d to execute the application.

[0044] The evaluation and verification execution unit 37 causes virtual ECU VM(1)14a, virtual ECU VM(2)14b, virtual ECU VM(3)14c, and virtual ECU VM(4)14d to perform evaluation and verification related to the operation of the vehicle control system 10a.

[0045] (Overview of communication control) Figure 3 illustrates the overview of communication control performed by the hypervisor 16a. Figure 3 is a diagram illustrating the overview of communication control performed by the hypervisor in the first embodiment.

[0046] At time ta, machine 12a starts the hypervisor 16a. Then, the information transfer unit 32 of the hypervisor 16a sends (transfers) the virtual CPU context to the hypervisor 16b before virtual ECU VM(1)14a, virtual ECU VM(2)14b, virtual ECU VM(3)14c, and virtual ECU VM(4)14d start up.

[0047] At time tb, once the transmission of the virtual CPU context is complete, the operation control unit 31 of the hypervisor 16a starts virtual ECU VM(1)14a, virtual ECU VM(2)14b, virtual ECU VM(3)14c, and virtual ECU VM(4)14d. The communication volume determination unit 34 of the hypervisor 16a then determines whether the sum of the communication volume of application communication C1 and evaluation / verification communication C2 between the hypervisor 16a and the hypervisor 16b is putting pressure on the communication capacity of the gateway 20. The communication control unit 35 of the hypervisor 16a then controls the communication so that the sum of the communication volume of application communication C1 and evaluation / verification communication C2 does not exceed the communication capacity of the gateway 20. Specifically, when the virtual ECU VM under evaluation is running, the communication control unit 35 of the hypervisor 16a reduces the communication volume of evaluation / verification communication C2 and prioritizes application communication C1.

[0048] Then, at time tc, if it is determined that the untransmitted data related to the evaluation / verification communication C2 exceeds a predetermined value, the operation control unit 31 of the hypervisor 16a temporarily suspends the operation of the ECU VM under evaluation by stopping the timing operation. Then, while the operation of the ECU VM under evaluation is suspended, the communication control unit 35 communicates the data that has not been backported between the hypervisor 16a and the hypervisor 16b.

[0049] Furthermore, if it is determined at time td that the untransmitted data related to the evaluation / verification communication C2 has fallen below a predetermined value, the operation control unit 31 of the hypervisor 16a restarts the timing operation. The communication control unit 35 then instructs the hypervisor 16a to repeatedly perform the communication control that was performed between time tb and time tc.

[0050] (Process flow performed by the hypervisor) Figure 4 illustrates the processing flow performed by the hypervisor 16a. Figure 4 is a flowchart showing an example of the processing flow performed by the hypervisor in the first embodiment. The hypervisor 16b works in cooperation with the hypervisor 16a to perform the same processing as shown in Figure 4.

[0051] The operation control unit 31 starts the hypervisor 16a (step S11).

[0052] The information transfer unit 32 transfers the virtual CPU context and memory contents from the hypervisor 16a to the hypervisor 16b (step S12).

[0053] The operation control unit 31 starts up virtual ECU VM(1)14a and virtual ECU VM(2)14b (step S13).

[0054] The communication control unit 35 alternately executes application communication C1 and evaluation / verification communication C2 (step S14).

[0055] The operation control unit 31 determines whether the application operation and evaluation / verification operation have been completed (step S15). If it is determined that the application operation and evaluation / verification operation have been completed (step S15: Yes), the hypervisor 16a terminates the process shown in Figure 4. On the other hand, if it is not determined that the application operation and evaluation / verification operation have been completed (step S15: No), the process proceeds to step S16.

[0056] If, in step S15, it is determined that the application operation and evaluation / verification operation have not been completed, the communication volume determination unit 34 determines whether it has received a congestion control signal from the gateway 20 (step S16). If it is determined that a congestion control signal has been received from the gateway 20 (step S16: Yes), the process proceeds to step S17. On the other hand, if it is determined that a congestion control signal has not been received from the gateway 20 (step S16: No), the process returns to step S14.

[0057] In step S16, if it is determined that a congestion control signal has been received from the gateway 20, the communication control unit 35 performs communication control that prioritizes application operation (step S17).

[0058] The communication volume determination unit 34 determines whether the amount of untransmitted evaluation / verification data is greater than or equal to a predetermined value after a predetermined time has elapsed since receiving the congestion control signal (step S18). If it is determined that the amount of untransmitted evaluation / verification data is greater than or equal to a predetermined value (step S18: Yes), the process proceeds to step S19. On the other hand, if it is not determined that the amount of untransmitted evaluation / verification data is greater than or equal to a predetermined value (step S18: No), the process returns to step S14.

[0059] In step S18, if it is determined that the amount of untransmitted evaluation and verification data exceeds a predetermined value, the operation control unit 31 suspends the operation of virtual ECU VM(1)14a and virtual ECU VM(2)14b (step S19).

[0060] The communication control unit 35 performs backport of untransmitted evaluation and verification data (step S20).

[0061] The communication volume determination unit 34 determines whether the amount of unsent evaluation / verification data is less than a predetermined value (step S21). If it is determined that the amount of unsent evaluation / verification data is less than a predetermined value (step S21: Yes), the process proceeds to step S22. On the other hand, if it is not determined that the amount of unsent evaluation / verification data is less than a predetermined value (step S21: No), the process returns to step S20.

[0062] In step S21, if it is determined that the amount of untransmitted evaluation and verification data is less than a predetermined value, the operation control unit 31 restarts the operation of virtual ECU VM(1)14a and virtual ECU VM(2)14b (step S22). Then, the process returns to step S14 and the above-described process is repeated.

[0063] (Effects of the first embodiment) As described above, the machine 12a (control device) according to the first embodiment includes a hypervisor 16a (first hypervisor) that generates virtual ECU VM(1) 14a (first virtual machine) and virtual ECU VM(2) 14b (first virtual machine), and virtual ECU VM(3) 14c (second virtual machine) and virtual ECU that communicate with the first hypervisor via gateway 20. A control device that can be mounted on a vehicle, comprising a hypervisor 16b (second hypervisor) that generates VM(4)14d (second virtual machine), and a communication control unit 35 that, while the first virtual machine and the second virtual machine are running, dynamically limits at least one of the communication volume of application communication C1 and evaluation / verification communication C2 based on the execution status of application communication C1 performed between hypervisor 16a and hypervisor 16b, the execution status of evaluation / verification communication C2 performed between hypervisor 16a and hypervisor 16b, and the communication capacity of gateway 20. Therefore, application communication and evaluation / verification communication can be performed simultaneously without putting a strain on the network's communication capacity.

[0064] Furthermore, in the machine 12a (control device) according to the first embodiment, the communication control unit 35 controls the amount of communication for application communication C1 and the amount of communication for evaluation / verification C2 performed between the hypervisor 16a (first hypervisor) and the hypervisor 16b (second hypervisor) during startup of the virtual ECU VM(1) 14a (first virtual machine), virtual ECU VM(3) 14c (second virtual machine), and virtual ECU VM(4) 14d (second virtual machine), if the sum of the communication volume of application communication C1 and evaluation / verification communication C2 performed between the hypervisor 16a (first hypervisor) and the hypervisor 16b (second hypervisor) is putting pressure on the communication capacity of the gateway 20, so that the sum of the communication volume of application communication C1 and evaluation / verification communication C2 does not exceed the communication capacity of the gateway 20.Therefore, application communication and evaluation / verification communication can be performed simultaneously without putting pressure on the network's communication capacity.

[0065] Furthermore, in the machine 12a (control device) according to the first embodiment, the communication control unit 35 determines whether the communication capacity of the gateway 20 is being strained based on a congestion control signal indicating that the communication volume of the gateway 20 has exceeded a threshold. Therefore, it is possible to easily determine whether the communication capacity of the gateway 20 is being strained.

[0066] Furthermore, in the machine 12a (control device) according to the first embodiment, the communication control unit 35 prioritizes application communication C1 when it acquires a congestion control signal. In this case, the application executed by the virtual ECU does not need to consider the congestion control signal. Therefore, the communication capacity can be controlled without affecting the operation of application communication C1.

[0067] Furthermore, the machine 12a (control device) according to the first embodiment further includes an information transfer unit 32 (transfer unit) that transfers the execution state and execution content of the virtual CPUs for evaluation and verification from the hypervisor 16a (first hypervisor) to the hypervisor 16b (second hypervisor) before starting the virtual ECU VM(1) 14a (first virtual machine), virtual ECU VM(2) 14b (first virtual machine), virtual ECU VM(3) 14c (second virtual machine), and virtual ECU VM(4) 14d (second virtual machine). Therefore, information for evaluation and verification can be shared between the hypervisor 16a and the hypervisor 16b.

[0068] Furthermore, in the machine 12a (control device) according to the first embodiment, the communication control unit 35 interrupts the operation of virtual ECU VM(1) 14a, virtual ECU VM(2) 14b (first virtual machine) and virtual ECU VM(3) 14c, virtual ECU VM(4) 14d (second virtual machine) when the amount of untransmitted data between hypervisor 16a (first hypervisor) and hypervisor 16b (second hypervisor) exceeds a predetermined value, and transmits the untransmitted data between hypervisor 16a (first hypervisor) and hypervisor 16b (second hypervisor). Therefore, when untransmitted data for evaluation and verification communication C2 accumulates, the operation of the first virtual machine and the second virtual machine is interrupted, allowing untransmitted data to be sent and received without affecting the operation of application communication C1.

[0069] Furthermore, in the machine 12a (control device) according to the first embodiment, the communication control unit 35 restarts the operation of virtual ECU VM(1) 14a, virtual ECU VM(2) 14b (first virtual machine) and virtual ECU VM(3) 14c, virtual ECU VM(4) 14d (second virtual machine) when the amount of untransmitted data between hypervisor 16a (first hypervisor) and hypervisor 16b (second hypervisor) falls below a predetermined value. Therefore, since normal communication operation can be easily restarted, the operating state can be evaluated and verified over a long period of time, even when application communication C1 and evaluation / verification communication C2 are operated continuously.

[0070] (Second embodiment) Next, a second embodiment, the vehicle control system 10b, will be described.

[0071] (Outline configuration of the vehicle control system) The schematic configuration of the vehicle control system 10b will be explained using Figure 5. Figure 5 is a block diagram showing an example of the schematic configuration of the vehicle control system according to the second embodiment. Note that, for the sake of simplicity, Figure 5 omits CPU(1)24a, CPU(2)24b, and CPU(3)24c shown in Figure 1. The internal structure of the gateway 20 is also omitted.

[0072] In typical embedded systems, all devices used by a hypervisor reside under the control of that hypervisor. Therefore, a specific device can only be controlled by that specific hypervisor. The vehicle control system 10b of this embodiment has a function that allows the hypervisor to virtually create a device if that specific device does not exist under the control of a hypervisor that executes processing using that device.

[0073] The general configuration of the vehicle control system 10b is almost the same as the general configuration of the vehicle control system 10a described in the first embodiment, but it differs in that it has the function of virtually creating devices used by the hypervisor under the hypervisor.

[0074] In Figure 5, device (A) 19a exists under hypervisor 16a, and device (B) 19b exists under hypervisor 16b. Devices (A) 19a and (B) 19b include devices used for evaluation and verification, such as serial ports. In addition, devices include input / output devices such as displays and speakers, and communication devices such as Wi-Fi and Bluetooth®.

[0075] In this case, since device (A) 19a does not exist under the hypervisor 16b, the hypervisor 16b cannot use device (A) 19a.

[0076] In the vehicle control system 10b, the hypervisor 16b has the function of virtually generating device (A) 19a under its control. In Figure 5, device (A) 19a, which is virtually formed under the hypervisor 16b, is shown with a dotted line to indicate that it is a virtual device.

[0077] In Figure 5, memory (2-A) 18d is a memory area that stores data for the virtual ECU VM(2) 14b to use device (A) 19a. The hypervisor 16a transfers memory (2-3) 18c and memory (2-A) 18d to the hypervisor 16b, thereby enabling the hypervisor 16b to execute processing using device (A) 19a, which it has virtually created under its control.

[0078] Furthermore, since device (A) 19a, which is generated under the hypervisor 16b, is a virtual device, when the hypervisor 16b performs processing using device (A) 19a, it sends back usage data of device (A) 19a to the hypervisor 16b by performing evaluation and verification communication C3. In order to prevent the amount of communication generated at that time from overwhelming the network capacity, communication between the hypervisor 16a and the hypervisor 16b is managed by the communication control method described in the first embodiment.

[0079] In this way, the hypervisor 16b operates as if device (A) 19a were under its control.

[0080] (Hypervisor functional configuration) Next, the functional configuration of the hypervisors 16a and 16b provided in the vehicle control system 10b will be described. Both hypervisors 16a and 16b include a virtual device generation unit 38 (not shown) in addition to the functional configuration shown in Figure 2.

[0081] The virtual device generation unit 38 virtually generates a device if there is no device to be used by the virtual CPU context under the hypervisor 16a (first hypervisor) or hypervisor 16b (second hypervisor) that receives the virtual CPU context. Note that the virtual device generation unit 38 is an example of a generation unit in this disclosure.

[0082] (Effects of the second embodiment) As described above, the machine 12b (control device) according to the second embodiment further includes a virtual device generation unit 38 (generation unit) that virtually generates a device under the hypervisor 16b (second hypervisor) if there is no device under the hypervisor 16b that receives the execution state and execution content of the virtual CPU for evaluation and verification. Therefore, even if there is no device under the hypervisors 16a and 16b that the hypervisors 16a and 16b use when processing, processing can be executed as if such a device existed.

[0083] (Third embodiment) Next, a third embodiment, the vehicle control system 10c, will be described.

[0084] (Outline configuration of the vehicle control system) The schematic configuration of the vehicle control system 10c will be explained using Figure 6. Figure 6 is a block diagram showing an example of the schematic configuration of the vehicle control system according to the third embodiment. Note that, for the sake of simplicity, Figure 6 omits CPU(1)24a, CPU(2)24b, and CPU(3)24c shown in Figure 1. The internal structure of the gateway 20 is also omitted.

[0085] The hypervisor 16a of the vehicle control system 10c has the ability to delegate the execution of some of its functions to a VM host 15, which is an example of a virtual machine.

[0086] Specifically, the VM host 15 performs some of the functions of the hypervisor 16a, such as virtual power on / off of machine 12a, virtual suspension and resumption of operation, and communication control based on congestion control signals obtained from gateway 20, which were previously performed by the hypervisor 16a in the first and second embodiments.

[0087] Furthermore, the VM host 15 may collect information from the virtual ECU VM(1) 14a instead of the hypervisor 16a, for example. That is, the VM host 15 may perform information communication C4 from the virtual ECU VM(1) 14a to the VM host 15 via the hypervisor 16a.

[0088] The VM host 15 may also perform information communication C4 from the virtual ECU VM(2) 14b via the hypervisor 16a to collect information from the virtual ECU VM(2) 14b.

[0089] Furthermore, in the vehicle control system 10c, machine 12b may be equipped with a virtual machine having the same functions as the VM host 15.

[0090] (Hypervisor functional configuration) Next, the functional configuration of the hypervisor 16a provided in the vehicle control system 10c will be described. In all cases, the hypervisor 16a delegates some of the functions of the functional configuration shown in Figure 2 to the VM host 15. The functional configuration of the hypervisor 16a differs depending on which parts of the functions are delegated to the VM host 15. For example, if the functions of the communication control unit 35 are delegated to the VM host 15, the hypervisor 16a has a functional configuration that is the same as the functional configuration shown in Figure 2, but with the communication control unit 35 removed. Also, if the functions of the communication volume determination unit 34 and the communication control unit 35 are delegated to the VM host 15, the hypervisor 16a has a functional configuration that is the same as the functional configuration shown in Figure 2, but with the communication volume determination unit 34 and the communication control unit 35 removed.

[0091] The hypervisor 16a includes an information transmission / reception unit 39 (not shown) which has an information transmission / reception function for performing information communication C4 with the VM host 15, and an information transmission / reception function for performing information communication C4 with the VM host 15 via the hypervisor 16a from the virtual ECU VM(1) 14a.

[0092] By providing VM host 15, if changes (e.g., specification changes) occur in hypervisor 16a, these can be addressed with minimal effort by simply modifying VM host 15. Furthermore, virtual ECU VM(1)14a and virtual ECU VM(2)14b are not affected by malfunctions in VM host 15.

[0093] On the other hand, providing the VM host 15 necessitates information communication C4, which may increase overhead and slow down operation. However, the amount of overhead can be reduced, for example, by hardware support mechanisms, so the benefits of providing the VM host 15 outweigh the drawbacks.

[0094] (Effects of the third embodiment) As described above, the machine 12a (control device) according to the third embodiment includes a VM host 15 (virtual machine) that performs some of the processing performed by the hypervisor 16a by communicating with the hypervisor 16a. Therefore, modification work such as specification changes can be performed without making any changes to the hypervisor 16a, and can be handled with minimal effort.

[0095] Although embodiments of the present invention have been described above, these embodiments are presented as examples only and are not intended to limit the scope of the invention. This novel embodiment can be implemented in various other forms. Furthermore, various omissions, substitutions, and modifications can be made without departing from the spirit of the invention. Moreover, this embodiment is included in the scope and spirit of the invention, as well as in the claims of the invention and its equivalents.

[0096] Furthermore, this disclosure may take the following form.

[0097] (1) A vehicle-mountable control device comprising a first hypervisor that controls the execution of a first virtual machine, and a second hypervisor that controls the execution of a second virtual machine and communicates with the first hypervisor via a gateway, The system includes a communication control unit that, while the first virtual machine and the second virtual machine are being started, dynamically limits at least one of the traffic volume of the application communication and the traffic volume of the evaluation / verification communication based on the status of application communication performed between the first hypervisor and the second hypervisor, the status of evaluation / verification communication performed between the first hypervisor and the second hypervisor, and the communication capacity of the gateway. Control device. (2) The communication control unit, If, during the startup of the first virtual machine and the second virtual machine, the sum of the traffic volume of application communications and evaluation / verification communications performed between the first hypervisor and the second hypervisor puts a strain on the gateway's communication capacity, the traffic volume of application communications and evaluation / verification communications is controlled so that the sum of the traffic volume of application communications and evaluation / verification communications does not exceed the gateway's communication capacity. The control device described in (1) above. (3) The communication control unit determines whether the communication capacity of the gateway is being strained based on a congestion control signal indicating that the communication volume of the gateway has exceeded a threshold. The control device described in (1) or (2) above. (4) The communication control unit, When the aforementioned congestion control signal is obtained, the application communication is given priority. The control device described in (3) above. (5) The system further includes a transfer unit that, before starting the first virtual machine and the second virtual machine, transfers the execution state and execution content of the evaluation and verification virtual CPU from the first hypervisor to the second hypervisor. The control device according to any one of (1) to (4) above. (6) If, under the second hypervisor that receives the execution status and execution details of the virtual CPU for evaluation and verification, there is no device used by the virtual CPU, the second hypervisor further includes a generation unit that virtually creates the device. The control device according to any one of (1) to (5) above. (7) The communication control unit, If the amount of untransmitted data between the first hypervisor and the second hypervisor exceeds a predetermined value, the operation of the first virtual machine and the second virtual machine is interrupted to transmit the untransmitted data between the first hypervisor and the second hypervisor. The control device according to any one of (1) to (6) above. (8) The communication control unit, When the amount of untransmitted data between the first hypervisor and the second hypervisor falls below a predetermined value, the operation of the first virtual machine and the second virtual machine is restarted. The control device described in (7) above. (9) The control device is The system includes a virtual machine that performs some of the processing performed by the first hypervisor by communicating with the first hypervisor. The control device according to any one of (1) to (8) above. (10) A control system that can be mounted on a vehicle, comprising a first hypervisor that controls the execution of a first virtual machine, and a second hypervisor that controls the execution of a second virtual machine that communicates with the first hypervisor via a gateway, The system includes a communication control unit that, while the first virtual machine and the second virtual machine are being started, dynamically limits at least one of the traffic volume of the application communication and the traffic volume of the evaluation / verification communication based on the status of application communication performed between the first hypervisor and the second hypervisor, the status of evaluation / verification communication performed between the first hypervisor and the second hypervisor, and the communication capacity of the gateway. Control system. (11) A control method performed by a control device that can be mounted on a vehicle, comprising a first hypervisor that controls the execution of a first virtual machine, and a second hypervisor that controls the execution of a second virtual machine and communicates with the first hypervisor via a gateway, During the startup of the first virtual machine and the second virtual machine, a communication control process is performed to dynamically limit at least one of the traffic volume of the application communication and the traffic volume of the evaluation / verification communication, based on the execution status of application communication between the first hypervisor and the second hypervisor, the execution status of evaluation / verification communication between the first hypervisor and the second hypervisor, and the communication capacity of the gateway. Control method. [Explanation of symbols]

[0098] 10a, 10b, 10c Vehicle control system 12a, 12b Machine (control device) 14a Virtual ECU VM(1) (First Virtual Machine) 14b Virtual ECU VM(2) (First virtual machine) 14c Virtual ECU VM(3) (Second Virtual Machine) 14d Virtual ECU VM(4) (Second virtual machine) 15 VM hosts (virtual machines) 16a Hypervisor (First hypervisor) 16b Hypervisor (Second hypervisor) 20 Gateways 22 Control mechanism 31 Operation Control Unit 32 Information Transfer Unit (Transfer Unit) 33 Communication capacity acquisition unit 34 Communication amount determination unit 35 Communication Control Unit 36 Application Execution Unit 37 Evaluation and Verification Execution Department 38. Virtual Device Generation Unit (Generation Unit) 39 Information transmission and reception unit C1 Application Communication C2, C3 Evaluation and Verification Communication C4 Information and Communication

Claims

1. A control device that can be mounted on a vehicle, comprising a first hypervisor that controls the execution of a first virtual machine, and a second hypervisor that controls the execution of a second virtual machine and communicates with the first hypervisor via a gateway, The system includes a communication control unit that limits at least one of the traffic volume of application communication and the traffic volume of evaluation / verification communication, based on the execution status of application communication performed between the first hypervisor and the second hypervisor and the execution status of evaluation / verification communication performed between the first hypervisor and the second hypervisor. Control device.

2. The communication control unit, If, during the startup of the first virtual machine and the second virtual machine, the sum of the traffic volume of application communications and evaluation / verification communications performed between the first hypervisor and the second hypervisor puts a strain on the gateway's communication capacity, the traffic volume of application communications and evaluation / verification communications is controlled so that the sum of the traffic volume of application communications and evaluation / verification communications does not exceed the gateway's communication capacity. The control device according to claim 1.

3. The communication control unit determines whether the communication capacity of the gateway is being strained based on a congestion control signal indicating that the communication volume of the gateway has exceeded a threshold. The control device according to claim 2.

4. The communication control unit, When the aforementioned congestion control signal is obtained, the application communication is given priority. The control device according to claim 3.

5. The system further includes a transfer unit that, before starting the first virtual machine and the second virtual machine, transfers the execution state and execution content of the evaluation and verification virtual CPU from the first hypervisor to the second hypervisor. The control device according to claim 1.

6. If, under the second hypervisor that receives the execution state and execution details of the virtual CPU for evaluation and verification, there is no device used by the virtual CPU, the second hypervisor further includes a generation unit that virtually creates the device. The control device according to claim 5.

7. The communication control unit, If the amount of untransmitted data between the first hypervisor and the second hypervisor exceeds a predetermined value, the operation of the first virtual machine and the second virtual machine is interrupted to transmit the untransmitted data between the first hypervisor and the second hypervisor. The control device according to claim 1.

8. The communication control unit, When the amount of untransmitted data between the first hypervisor and the second hypervisor falls below a predetermined value, the operation of the first virtual machine and the second virtual machine is restarted. The control device according to claim 7.

9. The control device is The system includes a virtual machine that performs some of the processing performed by the first hypervisor by communicating with the first hypervisor. The control device according to claim 1.

10. The communication control unit limits at least one of the communication volume for application communication and the communication volume for evaluation and verification communication based on the execution status of application communication performed between the first hypervisor and the second hypervisor, the execution status of evaluation and verification communication performed between the first hypervisor and the second hypervisor, and the communication capacity of the gateway. The control device according to claim 1.

11. A control system that can be mounted on a vehicle, comprising a first hypervisor that controls the execution of a first virtual machine, and a second hypervisor that controls the execution of a second virtual machine and communicates with the first hypervisor via a gateway, The system includes a communication control unit that limits at least one of the traffic volume of application communication and the traffic volume of evaluation / verification communication, based on the execution status of application communication performed between the first hypervisor and the second hypervisor and the execution status of evaluation / verification communication performed between the first hypervisor and the second hypervisor. Control system.

12. A control method performed by a control device that can be mounted on a vehicle, comprising a first hypervisor that controls the execution of a first virtual machine, and a second hypervisor that controls the execution of a second virtual machine and communicates with the first hypervisor via a gateway, Based on the execution status of application communication performed between the first hypervisor and the second hypervisor, and the execution status of evaluation and verification communication performed between the first hypervisor and the second hypervisor, a communication control process is performed to limit at least one of the communication volume of the application communication and the communication volume of the evaluation and verification communication. Control method.