SDN Network System and SDN Controller
The SDN network system addresses the risk of communication errors after updating settings by using a test data transmission process to determine error-free communication paths, ensuring normal network function and data integrity.
Patent Information
- Application Number
- JP2022175586
- Authority / Receiving Office
- JP · JP
- Patent Type
- Patents
- Current Assignee / Owner
- Filing Date
- 2022-11-01
- Publication Date
- 2025-06-03
- Estimated Expiration
- 2042-11-01
AI Technical Summary
In SDN network systems, when a new device is connected and communication settings are updated, there is a risk of communication errors occurring immediately after the update, leading to potential network dysfunction.
An SDN network system and controller that include a transmission process for sending test data, a determination process to assess communication errors, and a permission process to allow data transmission only when no communication errors are detected in the determination process.
Ensures that the SDN network functions normally by confirming the absence of communication errors in the normal path after updating communication settings, thereby preventing data transmission errors and maintaining network integrity.
Smart Images

Figure 0007687323000001 
Figure 0007687323000002 
Figure 0007687323000003
Abstract
Description
Technical Field
[0001] The present invention relates to an SDN network system and an SDN controller.
Background Art
[0002] Patent Document 1 describes an SDN (Software Defined Network) network system capable of changing communication settings of a network. The SDN network system includes a plurality of SDN switches and an SDN controller that changes communication settings of each SDN switch.
Prior Art Documents
Patent Documents
[0003]
Patent Document 1
Summary of the Invention
Problems to be Solved by the Invention
[0004] In the SDN network system described in Patent Document 1, for example, a new device may be connected. When such a new device is connected, the communication settings of the SDN switch can also be updated. Immediately after the communication settings of the SDN switch are updated, it is not guaranteed that the SDN network functions properly, so there is an unavoidable risk of communication errors occurring.
Means for Solving the Problems
[0005] To solve the above problems, one aspect of the present invention is an SDN network system for a vehicle including an SDN switch and an SDN controller that controls communication settings of the SDN switch, wherein the SDN controller Transmission process for transmitting test data in the communication settingA determination process for determining whether a communication error has occurred, and a permission process for permitting transmission and reception of data other than the test data in the communication setting when it is determined in the determination process that the communication error has not occurred, and the transmission path of the data defined in the communication setting including a path including the SDN switch When taken as a normal path, the transmission process includes a first test process of transmitting the test data from the SDN controller to the SDN switch via the normal path. In the determination process, on the condition that no communication error is detected in the normal path by the first test process, it is determined that no communication error has occurred in the communication setting. This is an SDN network system.
[0006] To solve the above problems, one aspect of the present invention is an SDN controller that controls the communication setting of an SDN switch, Transmission process for transmitting test data in the communication setting A determination process for determining whether a communication error has occurred, and a permission process for permitting transmission of data other than the test data in the communication setting when it is determined in the determination process that the communication error has not occurred, and the transmission path of the data defined in the communication setting including a path including the SDN switch When taken as a normal path, the transmission process includes a first test process of transmitting the test data from the SDN controller to the SDN switch via the normal path. In the determination process, on the condition that no communication error is detected in the normal path by the first test process, it is determined that no communication error has occurred in the communication setting. This is an SDN controller.
[0007] According to each of the above configurations, in the determination process, it can be confirmed that no communication error has occurred in communication via the normal path. And after ensuring that no communication error has occurred in communication via the normal path, that is, ensuring that communication can be normally performed via the normal path, transmission of data other than the test data is permitted. Therefore, at the stage of sending data other than the test data after updating the communication setting, it can be ensured that the SDN network functions normally via the normal path of the communication setting.
Brief Description of the Drawings
[0008]
Figure 1
Figure 2
Figure 3
Figure 4
Mode for Carrying Out the Invention
[0009] (One Embodiment) Hereinafter, an embodiment of an SDN network system will be described. Hereinafter, a communication system including a vehicle having an SDN network system and a server will be described with reference to the drawings.
[0010] <Overview of the Communication System> As shown in FIG. 1, the communication system 10 includes a plurality of vehicles 20 and a server 30. Each vehicle 20 has a vehicle control device 21, a communication device 22, and an operation terminal 23. The vehicle control device 21 controls each device of the vehicle 20. Details of the vehicle control device 21 will be described later.
[0011] The communication device 22 is connected to the server 30 via an external communication line network 40. The external communication line network 40 is a wireless communication line network such as a mobile phone line network, for example. Therefore, the vehicle 20 and the server 30 can communicate with each other via the external communication line network 40.
[0012] The operation terminal 23 is a terminal operated by a user of the vehicle 20. The operation terminal 23 is, for example, a touch display. The operation terminal 23 displays an image indicating information input from the vehicle control device 21. Further, the operation terminal 23 inputs information indicated by being operated by the user to the vehicle control device 21.
[0013] Although illustration is omitted, the server 30 has a CPU and a ROM. The CPU of the server 30 executes the program stored in the ROM. Thereby, the server 30 transmits campaign information and a delivery package toward the vehicle 20.
[0014] <Overview of the vehicle control device> As shown in FIG. 2, the vehicle control device 21 includes a master ECU 21A and a plurality of physical ECUs 21B. The master ECU 21A and each physical ECU 21B are connected by a communication line. Although illustration is omitted, the master ECU 21A and each physical ECU 21B each have a CPU and a ROM. And these ECUs execute the program stored in the ROM. The physical ECU 21B controls the hard devices connected to each physical ECU 21B. The hard devices are, for example, an engine, a brake, a motor, and the like.
[0015] The master ECU 21A has an SDN network system 50. The SDN network system 50 includes an SDN controller 51 and a plurality of SDN switches 53.
[0016] The SDN controller 51 controls the communication settings of each SDN switch 53. Specifically, the SDN controller 51 determines the data communication path on the network of the SDN network system 50. The SDN controller 51 determines a new data communication path, for example, when a new physical ECU 21B is connected. That is, the SDN controller 51 dynamically controls the communication settings. In addition, the SDN controller 51 transmits path information indicating the data communication path and the like to each SDN switch 53. Thereby, the SDN controller 51 centrally manages the communication settings of each SDN switch 53. In addition, the SDN controller 51 transmits the data to be transferred by the SDN switch 53.
[0017] The SDN switch 53 transfers data on the network of the SDN network system 50. Specifically, based on the path information received from the SDN controller 51, it updates the rules for data transfer stored in its own flow table. Then, the SDN switch 53 transfers the data received from the SDN controller 51 to the appropriate physical ECU 21B based on the updated rules.
[0018] Also, the SDN controller 51 can execute a download process to download updated software from a server 30 outside the vehicle 20. Then, the SDN controller 51 installs and activates the updated software downloaded in the download process. Through these series of processes, the SDN controller 51 becomes capable of executing new updated software.
[0019] <Regarding a series of processes for OTA> The server 30 transmits campaign information to the communication device 22 of the vehicle 20. When the communication device 22 of the vehicle 20 receives the campaign information, the communication device 22 outputs the campaign information to the vehicle control device 21. When the campaign information is input, the vehicle control device 21 executes an update program via OTA (Over The Air). Note that the campaign information is information indicating an event for software update for the vehicles 20 in the market.
[0020] As shown in FIG. 3, when the vehicle control device 21 starts a series of processes of the update program via OTA, it first performs the process of step S11. In step S11, the vehicle control device 21 requests approval for the installation of the updated software from the user of the vehicle 20. Specifically, the vehicle control device 21 outputs an installation approval message indicating whether installation is allowed to the operation terminal 23. The installation approval message is, for example, a message such as "Do you want to apply the new software?" Then, the vehicle control device 21 advances the process to step S12.
[0021] On the other hand, after the operation terminal 23 receives the installation approval message from the vehicle control device 21, when an operation indicating approval is performed by the user, the operation terminal 23 executes the installation approval processing program. When the operation terminal 23 starts the installation approval processing program, it performs step S30. In step S30, the operation terminal 23 executes the installation approval process. In the installation approval process, the operation terminal 23 outputs information indicating the user's approval to the vehicle control device 21. Thereby, the operation terminal 23 ends the installation approval processing program.
[0022] In step S12, the vehicle control device 21 determines whether approval has been obtained. The vehicle control device 21 determines whether approval has been obtained based on whether information indicating the user's approval has been input from the operation terminal 23. When information indicating the user's approval has not been input from the operation terminal 23 (S12: NO), the vehicle control device 21 repeats the process of step S12. On the other hand, when information indicating the user's approval has been input from the operation terminal 23 (S12: YES), the vehicle control device 21 advances the process to step S13.
[0023] In step S13, the vehicle control device 21 performs the distribution package transmission request process. In the distribution package transmission request process, the vehicle control device 21 transmits information indicating a request for a distribution package to the server 30 via the communication device 22. Thereafter, the vehicle control device 21 advances the process to step S14.
[0024] On the other hand, when the server 30 receives information indicating a request for a distribution package from the communication device 22, the server 30 executes the distribution package transmission program. When the server 30 starts the distribution package transmission program, it performs step S40. In step S40, the server 30 transmits the distribution package to the communication device 22. Thereby, the server 30 ends the distribution package transmission program.
[0025] In step S14, the vehicle control device 21 determines whether the communication device 22 has downloaded the distribution package. When the communication device 22 has not downloaded the distribution package (S14: NO), the vehicle control device 21 repeats the process of step S14. On the other hand, when the communication device 22 has downloaded the distribution package (S14: YES), the vehicle control device 21 advances the process to step S15.
[0026] In step S15, the vehicle control device 21 installs the distribution package downloaded by the communication device 22. Note that the distribution package is a series of data sets transferred from the server 30 to the vehicle 20 at once. The distribution package includes, in addition to the main body of the update software, display information of the HMI (Human Machine Interface), package information, security information, etc. Further, the distribution package includes network information of the SDN network system 50. That is, the distribution package includes communication settings of each SDN switch 53. When the vehicle control device 21 downloads the distribution package, the SDN controller 51 downloads the communication settings of each SDN switch 53 in the distribution package. Also, when the vehicle control device 21 installs the update software in the distribution package, the SDN controller 51 installs the communication settings of each SDN switch 53 in the distribution package. After that, the vehicle control device 21 advances the process to step S16.
[0027] In step S16, the vehicle control device 21 requests the user of the vehicle 20 for approval to activate the installed update software. Specifically, the vehicle control device 21 outputs an activation approval message indicating whether activation is acceptable to the operation terminal 23. The activation approval message is, for example, a message such as "The update time is approximately XX minutes, but restarting is not possible during that time. Is that okay?" After that, the vehicle control device 21 advances the process to step S17.
[0028] On the other hand, after the activation approval message is input from the vehicle control device 21 to the operation terminal 23, when an operation indicating approval is performed by the user, the operation terminal 23 executes an activation approval processing program. When the operation terminal 23 starts the activation approval processing program, it performs step S50. In step S50, the operation terminal 23 executes the activation approval process. In the activation approval process, the operation terminal 23 outputs information indicating the user's approval to the vehicle control device 21. Thereby, the operation terminal 23 ends the activation approval processing program.
[0029] In step S17, the vehicle control device 21 determines whether approval has been obtained. The vehicle control device 21 determines whether approval has been obtained based on whether information indicating the user's approval has been input from the operation terminal 23. When information indicating the user's approval has not been input from the operation terminal 23 (S17: NO), the vehicle control device 21 repeats the process of step S17. On the other hand, when information indicating the user's approval has been input from the operation terminal 23 (S17: YES), the vehicle control device 21 advances the process to step S18.
[0030] In step S18, the vehicle control device 21 activates the installed updated software. Thereby, the vehicle control device 21 becomes capable of controlling the vehicle 20 based on the information of the activated updated software. Also, when the vehicle control device 21 activates the updated software, the SDN controller 51 activates new communication settings for each SDN switch 53. After that, the vehicle control device 21 advances the process to step S19.
[0031] In step S19, the vehicle control device 21 performs an update completion process. In the update completion process, the vehicle control device 21 outputs information indicating that the software update based on the current campaign information has been completed to the operation terminal 23. Specifically, the vehicle control device 21 outputs an update completion message indicating that the software update has been completed to the operation terminal 23. The update completion message is, for example, a message such as "The update to the new software has been completed." After that, the vehicle control device 21 advances the process to step S20.
[0032] On the other hand, after the update completion message is input from the vehicle control device 21 to the operation terminal 23, when an operation indicating confirmation is performed by the user, the operation terminal 23 executes a confirmation processing program. When starting the confirmation processing program, the operation terminal 23 performs step S60. In step S60, the operation terminal 23 executes a confirmation process. In the confirmation process, the operation terminal 23 outputs information indicating that the user has confirmed to the vehicle control device 21. Thereby, the operation terminal 23 ends the confirmation processing program.
[0033] In step S20, the vehicle control device 21 determines whether it has been confirmed. The vehicle control device 21 determines whether it has been confirmed based on whether information indicating that the user has confirmed is input from the operation terminal 23. When information indicating that the user has confirmed is not input from the operation terminal 23 (S20: NO), the vehicle control device 21 repeats the process of step S20. On the other hand, when information indicating that the user has confirmed is input from the operation terminal 23 (S20: YES), the vehicle control device 21 ends the series of processes.
[0034] <Regarding a series of processes for communication error determination> As described above, when the vehicle control device 21 activates the updated software based on the campaign information, the SDN controller 51 updates the communication settings of each SDN switch 53. As a result, the path information such as the transfer destination of the data of each SDN switch 53 is updated. Then, when the SDN controller 51 updates the communication settings of each SDN switch 53, the vehicle control device 21 executes the test program stored in the ROM.
[0035] As shown in FIG. 4, when the vehicle control device 21 starts the test program, the SDN controller 51 first performs step S81. In step S81, the SDN controller 51 performs transmission processing. In the transmission processing, the SDN controller 51 transmits test data to each SDN switch 53.
[0036] The transmission processing includes a first test process, a second test process, a third test process, and a fourth test process. When performing the transmission processing, the SDN controller 51 performs all of these four processes. Here, the communication settings of each SDN switch 53 define the format of the data to be transmitted, the path to the destination physical ECU 21B, and the traffic volume when transmitting data to the destination physical ECU 21B. Note that the traffic volume referred to here is the amount of data transmitted per unit time.
[0037] Hereinafter, the data transfer path defined by the communication settings is regarded as the normal path. That is, the normal path is the path through which the data should be transmitted when the SDN 53 switch sends the data. Also, the path of the data not defined by the communication settings is regarded as the abnormal path. The abnormal path is the path through which the data should not be transmitted when the SDN switch 53 sends the data. Therefore, the abnormal path is different from the normal path.
[0038] Furthermore, the traffic volume of the data defined in the communication settings is regarded as the normal traffic volume. That is, the normal traffic volume is the traffic volume that the SDN switch 53 should send to the destination physical ECU 21B for the predetermined data defined in the communication settings. Also, the traffic volume of the data not defined in the communication settings is regarded as the abnormal traffic volume. That is, the abnormal traffic volume is the traffic volume that the SDN switch 53 should not send to the destination physical ECU 21B for the predetermined data defined in the communication settings.
[0039] Among the four test processes, the first test process is a process of transmitting test data from the SDN controller 51 to the SDN switch 53 through the normal path. The second test process is a process of transmitting test data from the SDN controller 51 to the SDN switch 53 through the abnormal path. The third test process is a process of transmitting the test data from the SDN controller 51 to the SDN switch 53 with the traffic volume of the test data being the abnormal traffic volume. The fourth test process is a process of transmitting the test data from the SDN controller 51 to the SDN switch 53 with the traffic volume of the test data being the normal traffic volume. When the SDN controller 51 transmits test data to the SDN switch 53, the SDN switch 53 transfers the test data to the physical ECU 21B.
[0040] Step S81 is roughly classified into step S81A, step S81B, and step S81C. In step S81A, the SDN controller 51 sets the traffic volume of the first test data as the normal traffic volume and transmits the first test data through the normal path. That is, step S81A functions as the first test process and the fourth test process.
[0041] Also, in step S81B, the SDN controller 51 performs the second test process. Specifically, the SDN controller 51 sets the traffic volume of the second test data as the normal traffic volume and transmits the second test data through the abnormal path.
[0042] Also, in step S81C, the SDN controller 51 performs a third test process. Specifically, the SDN controller 51 sets the traffic volume of the third test data as the abnormal traffic volume and transmits the third test data through the normal path. When the processes of steps S81A to S81C are completed, the SDN controller 51 finishes the process of step S81. Then, the SDN controller 51 proceeds with the process to step S82.
[0043] On the other hand, when the SDN switch 53 receives test data from the SDN controller 51, it performs the process of step S91. In step S91, the SDN switch 53 detects whether there is an abnormality in each of the first to third test data transmitted by the transmission process. Specifically, the SDN switch 53 detects whether there is an abnormality by comparing the test data with the access control list. The access control list is a list indicating signals that can be transmitted to each physical ECU 21B. On this access control list, for each type of connected hardware device, the signals that can be transmitted and the traffic volume that can be transmitted are individually set. Therefore, when the types of the physical ECUs 21B are different, the signals that can be transmitted and the traffic volume that can be transmitted may be different. The access control list is stored in advance in the ROM of the vehicle control device 21.
[0044] The SDN switch 53 compares the received test data with the access control list. When the path information of the test data is different from the path information of the access control list, the SDN switch 53 detects that there is a communication error in the abnormal path for the path information of the test data. On the other hand, when the path information of the test data matches the path information of the access control list, the SDN switch 53 detects that there is no communication error in the normal path for the path information of the test data.
[0045] In addition, when the traffic volume of the test data exceeds the traffic volume of the access control list, the SDN switch 53 detects that there is a communication error with an abnormal traffic volume for the traffic volume of the test data. When the traffic volume of the test data is less than or equal to the traffic volume of the access control list, the SDN switch 53 detects that there is no communication error with a normal traffic volume for the traffic volume of the test data.
[0046] After detecting whether there is a communication error for each test data received from the SDN controller 51, the SDN switch 53 proceeds with the process to step S92. In step S92, the SDN switch 53 transmits information indicating a communication error to the SDN controller 51. The information indicating a communication error is information indicating whether there is a communication error for each test data determined by the SDN switch 53 in step S91. More specifically, the information indicating a communication error is information indicating whether there is a communication error regarding the path information of the test data and whether there is a communication error regarding the traffic volume of the test data. That is, the information indicating a communication error includes information indicating that there is no communication error. In addition, the information indicating a communication error includes information indicating whether the presence or absence of a communication error is information regarding either the path information or the traffic volume. Thereafter, the SDN switch 53 ends this series of processes.
[0047] By the way, in step S82, the SDN controller 51 receives information indicating a communication error from the SDN switch 53. Thereafter, the SDN controller 51 proceeds with the process to step S83.
[0048] In step S83, the SDN controller 51 performs a determination process. In the determination process, it is determined whether a communication error has occurred in the communication by the transmission process. Specifically, the SDN controller 51 determines that no communication error has occurred in the communication settings when the following conditions are met. The first condition is that no communication error on the normal path is detected by the first test process. The second condition is that a communication error on the abnormal path is detected by the second test process. The third condition is that a communication error with an abnormal traffic volume is detected by the third test process. The fourth condition is that no communication error with a normal traffic volume is detected by the fourth test process. The SDN controller 51 determines that no communication error has occurred in the communication settings based on the above four conditions. And when the SDN controller 51 does not satisfy even one of the above four conditions, it determines that a communication error has occurred.
[0049] When it is determined that a communication error has occurred in the communication by the transmission process (S83: YES), the SDN controller 51 advances the process to step S84. In step S84, the SDN controller 51 performs an abnormality notification process. In the abnormality notification process, the SDN controller 51 outputs information indicating that the communication settings of each SDN switch 53 are abnormal to the operation terminal 23. Then, the SDN controller 51 ends a series of processes.
[0050] On the other hand, when it is determined that no communication error has occurred in the communication by the transmission process (S83: NO), the SDN controller 51 advances the process to step S85. In step S85, a permission process is performed. In the permission process, the SDN controller 51 permits the transmission and reception of data other than test data in the communication settings. Then, the SDN controller 51 advances the process to step S86.
[0051] In step S86, the SDN controller 51 performs normal notification processing. In the normal notification processing, the SDN controller 51 outputs information indicating that the communication settings are normal to the operation terminal 23. Note that the normal notification processing is executed in combination with the update completion processing that outputs information indicating that the above-described software update has been completed. In response to this, the operation terminal 23 displays together the information indicating that the software update has been completed and the information indicating that the communication settings are normal. Thereby, the SDN controller 51 ends a series of processes.
[0052] (Operation of the Embodiment) According to the above embodiment, when software is updated by OTA, the communication settings of the SDN switch 53 are updated. And when the communication settings are updated, the SDN controller 51 starts a test program. Thereby, the SDN controller 51 performs transmission processing including first to fourth test processes. And the SDN controller 51 determines whether a communication error has occurred in the updated communication settings based on the information indicating a communication error from the SDN switch 53.
[0053] (Effect of the Embodiment) (1) According to the above embodiment, in the determination process in step S83, the SDN controller 51 determines that no communication error has occurred in the communication settings on the condition that no communication error in the normal path is detected by the first test process. And when it is determined that no communication error has occurred in the communication settings, the SDN controller 51 performs permission processing in step S84. Therefore, after ensuring that no communication error has occurred in communication on the normal path, that is, ensuring that communication can be normally performed on the normal path, the transmission and reception of data other than test data are permitted. Therefore, at the stage of sending data other than test data after the update of the communication settings, it can be ensured that the network of the SDN network system 50 functions normally on the normal path of the communication settings.
[0054] (2) According to the above embodiment, in the determination process in step S83, the SDN controller 51 determines that no communication error has occurred in the communication setting on the condition that a communication error on the abnormal path has been detected by the second test process. Therefore, it is possible to ensure that signals are not transmitted and received on an abnormal path that should not function with the updated communication setting. Therefore, with the updated communication setting, communication on the normal path can be accurately handled as correct communication, and communication on the abnormal path can be accurately handled as communication with an error.
[0055] (3) According to the above embodiment, in the determination process in step S83, the SDN controller 51 further has the following conditions for determining that no communication error has occurred in the communication setting. These conditions are that a communication error with an abnormal traffic volume has been detected by the third test process and that no communication error with a normal traffic volume has been detected by the fourth test process. Therefore, it is possible to ensure that data can be transmitted and received with an appropriate traffic volume with the updated communication setting.
[0056] (4) According to the above embodiment, the SDN controller 51 updates the communication setting when software is updated by OTA. Then, when the communication setting is updated, the SDN controller 51 executes the transmission process and the subsequent determination process. Therefore, the SDN controller 51 starts the test program at an early timing after the communication setting is updated. Therefore, it is possible to prevent the time from becoming long from when the communication setting is updated until it is determined whether a communication error has occurred in the communication setting.
[0057] (5) According to the above embodiment, the SDN controller 51 executes the normal notification process after the permission process. Further, the operation terminal 23 displays information indicating that the communication setting is normal in response to this. Therefore, the user of the vehicle 20 can surely grasp that there is no problem with the communication setting.
[0058] (Other Embodiments) The above-described embodiment can be implemented with the following modifications. The above-described embodiment and the following modification examples can be implemented in combination with each other within a technically consistent range.
[0059] <Regarding a series of processes for determining communication errors> · In the transmission process, the SDN controller 51 performs the process of step S81A, which combines the first test process and the fourth test process, but is not limited thereto. The SDN controller 51 may transmit test data in the fourth test process as a process separate from the first test process. Also, if it is possible to distinguish between a communication error caused by the data transmission path and a communication error caused by the data traffic volume, as the fourth test process, the SDN controller 51 may transmit test data with a normal traffic volume to an abnormal path, for example.
[0060] · In the transmission process, the SDN controller 51 may omit the third test process and the fourth test process. In this case, in the determination process, the SDN controller 51 will make a determination regardless of the traffic volume.
[0061] · Also, in the transmission process, the SDN controller 51 may omit the second test process. In this case, in the determination process, the SDN controller 51 will make a determination regardless of the communication error regarding the abnormal path. Thus, in the transmission process, the SDN controller 51 only needs to execute at least the first test process. And in the determination process, the SDN controller 51 may determine that no communication error has occurred in the communication setting on the condition that no communication error is detected in the normal path.
[0062] ·In the above-described embodiment, the SDN switch 53 detected whether there was an abnormality in the test data by comparing it with the access control list, but it is not limited to this. For example, when the physical ECU 21B that transfers the test data from the SDN switch 53 performs filtering of the test data, it may detect a communication error. Filtering is a process of determining whether the data conforms to a predetermined data type and traffic volume. Then, by the physical ECU 21B transmitting a signal indicating the communication error to the SDN controller 51 of the master ECU 21A, the SDN controller 51 can confirm whether a communication error has been detected in the test data.
[0063] ·Also, for example, when performing a test process based on test data of traffic volume, the SDN controller 51 may confirm whether it is normal or abnormal as follows. Specifically, by comparing the data transmission delay, throughput, etc. when transmitting test data with abnormal traffic volume and when transmitting test data with normal traffic volume, it can be confirmed whether it is normal or abnormal. That is, in the case of test data with abnormal traffic volume, compared with the case of test data with normal traffic volume, the data transmission and reception delay occurs or the data transmission and reception throughput reaches the upper limit and changes. In this case, the SDN controller 51 can determine that it is normal if it is transmitting test data with abnormal traffic volume, and determine that it is abnormal if it is transmitting test data with normal traffic volume.
[0064] ·The timing at which the SDN controller 51 starts executing the test program is not limited to the timing triggered by software update via OTA. For example, the SDN controller 51 may execute the transmission process when the power of the vehicle 20 is turned on. When the power of the vehicle 20 is off, there is a possibility that new hardware devices are connected or changed. Therefore, by executing the test program when the power of the vehicle 20 is turned on, the SDN controller 51 can determine the presence or absence of a communication error before the vehicle 20 starts running.
[0065] · Also, for example, when the SDN controller 51 receives a signal for switching the electronic control unit provided in the vehicle 20 to a drivable state, it may execute transmission processing. The electronic control unit is, for example, the physical ECU 21B. Although the physical ECU 21B is in a non-drivable state at the time of shipment of the vehicle 20, it may be switched to a drivable state by a dealer or the like by paying an additional fee or the like after the vehicle 20 is out of the warehouse. In such a case, the communication settings may be changed by newly driving the physical ECU 21B. Therefore, when receiving a signal for switching the physical ECU 21B to a drivable state from a dealer or the like, the SDN controller 51 executes a test program. Thereby, when the new physical ECU 21B wakes up, it is possible to determine the presence or absence of a communication error in the communication settings. Note that the signal for switching the electronic control unit to a drivable state may also be referred to as a wake-up signal or the like, for example.
[0066] <Regarding a series of processes for OTA> · After step S18, the vehicle control device 21 may perform a permission determination process for determining whether or not the permission process in step S85 in the above-described test program has been performed. And in the permission determination process, when the permission process has been performed, the vehicle control device 21 may proceed with the process to step S19. Further, in step S19, a signal indicating that the communication settings notified in the normal notification process in step S86 are normal may also be transmitted to the operation terminal 23. On the other hand, in the permission determination process, when the permission process has not been performed within a predetermined time period determined in advance, the vehicle control device 21 may perform a process of outputting information indicating that the update is incomplete to the operation terminal 23 instead of the update completion process. In this case, as a condition for performing step S19, it is a condition that the permission process has been executed by executing the test program. And in the update completion process, a signal indicating that the communication settings are normal is also transmitted to the operation terminal 23. Therefore, the user who checks the operation terminal 23 can confirm at once that the software update has been completed and that the communication settings are normal.
[0067] <Others> · The vehicle 20 is not limited to constituting the communication system 10. As in the above-described modification example, it is not limited to the case where the vehicle 20 is performing software update by OTA, and a test program may be executed.
[0068] · The vehicle control device 21 may be configured as circuitry including one or more processors that execute various processes according to a computer program (software). Note that the vehicle control device 21 may be configured as circuitry including one or more dedicated hardware circuits such as application specific integrated circuits (ASICs) that execute at least a part of the various processes, or a combination thereof. The processor includes a CPU and memories such as a RAM and a ROM. The memory stores program codes or instructions configured to cause the CPU to execute processes. The memory, that is, the computer-readable medium includes any available medium that can be accessed by a general-purpose or dedicated computer.
[0069] · In the transmission process, the SDN controller 51 may execute at least one process selected from the first test process to the fourth test process. Further, the types of test processes executed by the SDN controller 51 in the transmission process are not limited to the first test process to the fourth test process. It may be appropriately determined according to the content of the communication setting in the flow table.
[0070] <Related Technical Ideas> The technical ideas that can be grasped from the above-described embodiments and modification examples will be described. <Appendix 1> An SDN network system for a vehicle, comprising an SDN switch and an SDN controller that controls communication settings of the SDN switch, wherein the SDN controller performs a transmission process of transmitting test data, and a determination process of determining whether a communication error has occurred in the transmission process with the communication setting. When it is determined in the determination process that the communication error has not occurred, a permission process for permitting transmission and reception of data other than the test data in the communication setting is executed. When the transmission path of the data defined in the communication setting is a normal path, The transmission process includes a first test process of transmitting the test data from the SDN controller to the SDN switch through the normal path. In the determination process, on the condition that no communication error is detected in the normal path by the first test process, it is determined that no communication error has occurred in the communication setting. SDN network system.
[0071] <Appendix 2> When the transmission path of the data not defined in the communication setting is an abnormal path, The transmission process includes a second test process of transmitting the test data from the SDN controller to the SDN switch through the abnormal path. In the determination process, on the condition that a communication error in the abnormal path is detected by the second test process, it is determined that no communication error has occurred in the communication setting. The SDN network system according to <Appendix 1>.
[0072] <Appendix 3> When the traffic volume of the data defined in the communication setting is a normal traffic volume and the traffic volume of the data not defined in the communication setting is an abnormal traffic volume, The transmission process includes a third test process of transmitting the test data from the SDN controller to the SDN switch with the traffic volume of the test data being the abnormal traffic volume, and a fourth test process of transmitting the test data from the SDN controller to the SDN switch with the traffic volume of the test data being the normal traffic volume. In the determination process, on the condition that the communication error at the abnormal traffic volume is detected by the third test process and the communication error at the normal traffic volume is not detected by the fourth test process, it is determined that no communication error has occurred in the communication setting. The SDN network system according to <Appendix 1> or <Appendix 2>.
[0073] <Appendix 4> When the power of the vehicle is turned on, the SDN controller executes the transmission process. The SDN network system according to any one of <Appendix 1> to <Appendix 3>.
[0074] <Appendix 5> When the SDN controller receives a signal for switching to a state in which an electronic control device provided in the vehicle can be driven, the SDN controller executes the transmission process. The SDN network system according to any one of <Appendix 1> to <Appendix 3>.
[0075] <Appendix 6> The SDN controller is capable of executing a download process for downloading updated software from a server outside the vehicle, When the SDN controller activates the updated software downloaded in the download process, the SDN controller executes the transmission process. The SDN network system according to any one of <Appendix 1> to <Appendix 3>.
[0076] <Appendix 7> After the permission process, the SDN controller executes a normal notification process for outputting a signal indicating that the communication setting is normal. The SDN network system according to <Appendix 6>.
[0077] <Appendix 8> An SDN network system for a vehicle, comprising an SDN switch and an SDN controller for controlling the SDN switch. The SDN controller executes a transmission process for transmitting test data, a determination process for determining whether a communication error has occurred in the communication settings by the transmission process, and a permission process for permitting the transmission and reception of data other than the test data in the communication settings when it is determined in the determination process that no communication error has occurred. SDN network system.
[0078] <Appendix 9> An SDN controller for controlling the communication settings of an SDN switch, executes a transmission process for transmitting test data, a determination process for determining whether a communication error has occurred in the transmission process in the communication settings, and a permission process for permitting the transmission of data other than the test data in the communication settings when it is determined in the determination process that no communication error has occurred. SDN controller.
Explanation of Signs
[0079] 10... Communication system 20... Vehicle 21... Vehicle control device 21A... Master ECU 21B... Physical ECU 22... Communication device 23... Operating terminal 30... Server 50... SDN network system 51... SDN controller 53... SDN switch
Claims
1. An SDN network system for a vehicle, comprising an SDN switch and an SDN controller that controls the communication settings of the SDN switch, wherein the SDN controller performs a determination process for determining whether a communication error has occurred during a transmission process in which test data in the communication settings is transmitted, and when it is determined in the determination process that no communication error has occurred, performs a permission process for permitting the transmission and reception of data other than the test data in the communication settings, when a path including the SDN switch, which is the data transmission path defined in the communication settings, is regarded as a normal path, the transmission process includes a first test process for transmitting the test data through the normal path and a test process for setting the traffic volume of the test data based on the traffic volume of the data defined in the communication settings and transmitting the test data to the SDN switch, in the determination process, it is determined whether a communication error has occurred in the communication settings according to whether there is a communication error in the test process, and it is determined that no communication error has occurred in the communication settings on the condition that no communication error in the normal path is detected by the first test process SDN network system.
2. The SDN controller executes the transmission process, and in the first test process, transmits the test data from the SDN controller to the SDN switch through the normal path The SDN network system according to claim 1.
3. when a data transmission path not defined in the communication settings is regarded as an abnormal path, the transmission process includes a second test process for transmitting the test data through the abnormal path and in the determination process, it is determined that no communication error has occurred in the communication settings on the condition that a communication error in the abnormal path is detected by the second test process The SDN network system according to claim 1.
4. The SDN controller executes the transmission process, and in the second test process, transmits the test data from the SDN controller to the SDN switch through the abnormal path The SDN network system according to claim 3.
5. When the traffic volume of the data defined in the communication setting is regarded as the normal traffic volume and the traffic volume of the data not defined in the communication setting is regarded as the abnormal traffic volume, the transmission process includes a third test process of transmitting the test data from the SDN controller to the SDN switch with the traffic volume of the test data being the abnormal traffic volume, and a fourth test process of transmitting the test data from the SDN controller to the SDN switch with the traffic volume of the test data being the normal traffic volume. In the determination process, on the condition that the communication error at the abnormal traffic volume is detected by the third test process and the communication error at the normal traffic volume is not detected by the fourth test process, it is determined that no communication error has occurred in the communication setting. The SDN network system according to claim 2.
6. The SDN controller executes the transmission process when the power of the vehicle is turned on. The SDN network system according to claim 2.
7. The SDN controller executes the transmission process when receiving a signal for switching to a state where an electronic control device included in the vehicle can be driven. The SDN network system according to claim 2.
8. The SDN controller is capable of executing a download process of downloading updated software from a server outside the vehicle. The SDN controller executes the transmission process when activating the updated software downloaded in the download process. The SDN network system according to claim 2.
9. The SDN controller executes a normal notification process of outputting a signal indicating that the communication setting is normal after the permission process. The SDN network system according to claim 8.
10. An SDN controller for controlling the communication setting of an SDN switch, a determination process of determining whether a communication error has occurred in a transmission process in which test data in the communication setting is transmitted, and a permission process of permitting the transmission of data other than the test data in the communication setting when it is determined in the determination process that no communication error has occurred. When the data transmission path defined in the communication setting, which includes the SDN switch, is regarded as the normal path, the transmission process includes a first test process of transmitting the test data through the normal path, and a test process of setting the traffic volume of the test data based on the traffic volume of the data defined in the communication setting and transmitting the test data to the SDN switch. In the determination process, according to whether there is a communication error in the test process, it is determined whether a communication error has occurred in the communication setting. On the condition that no communication error in the normal path is detected by the first test process, it is determined that no communication error has occurred in the communication setting. SDN controller.
Citation Information
Patent Citations
Verification device and verification method
JP2017028629A
Setting device, communication system, method for setting update of communication device, and program
JP2017169044A
OTA master, update control method, and update control program
JP2022154449A
Vehicle network apparatus and operation method thereof
US20200014620A1