Electronic control device, management program, management method, and service providing system

The electronic control device with a cooperation control unit effectively manages logs to ensure accurate billing by converting, storing, and transmitting access requests and logs, addressing the challenge of incomplete charging in vehicle service systems.

JP7711848B2Active Publication Date: 2025-07-23DENSO CORP

Patent Information

Application Number
JP2024539129
Authority / Receiving Office
JP · JP
Patent Type
Patents
Current Assignee / Owner
Priority Date
2022-08-03
Filing Date
2023-07-28
Publication Date
2025-07-23
Estimated Expiration
2043-07-28

AI Technical Summary

Technical Problem

Existing systems face challenges in appropriately charging service providers for services rendered to vehicles due to issues with log storage capacity leading to incomplete billing processes.

Method used

An electronic control device with a cooperation control unit that includes a request transfer unit, log creation unit, statistical log creation unit, log transmission unit, and log deletion unit, which converts access requests, creates and stores logs, performs statistical processing, and transmits them to a server for billing, ensuring efficient log management and accurate charging.

Benefits of technology

The solution ensures timely transmission and deletion of logs to prevent storage overflow, enabling accurate billing and preventing situations where service providers are not appropriately charged for their services.

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure 0007711848000001
    Figure 0007711848000001
  • Figure 0007711848000002
    Figure 0007711848000002
  • Figure 0007711848000003
    Figure 0007711848000003
Patent Text Reader

Abstract

An electronic control device (4) comprises a cooperation control unit (40). The cooperation control unit achieves cooperation between a service function block (33) and a control function block (35). The control function block comprises a function interface (37). The function interface converts an access request transmitted from the service function block into a format depending on a vehicle. The cooperation control unit creates an access log indicating an execution state of the access request for each access request and stores the created access log in a first storage unit (4c). The cooperation control unit transmits the access log to a server. When a log deletion condition is satisfied, the cooperation control unit deletes the access log from the first storage unit.
Need to check novelty before this filing date? Find Prior Art

Description

Cross - reference to related applications

[0001] This international application claims priority based on Japanese Patent Application No. 2022 - 123986 filed with the Japan Patent Office on August 3, 2022, and incorporates the entire contents of Japanese Patent Application No. 2022 - 123986 by reference into this international application.

Technical Field

[0002] The present disclosure relates to an electronic control device, a management program, a management method, and a service - providing system for performing management to provide services to a vehicle.

Background Art

[0003] Patent Document 1 describes that a log management device mounted on a vehicle transmits, to a center device installed outside the vehicle, a log generated by a security sensor or a statistical processing result generated by performing statistical processing on a plurality of logs according to a predetermined condition.

Prior Art Documents

Patent Documents

[0004]

Patent Document 1

Summary of the Invention

[0005] When a service provider provides a service to a vehicle, it may be necessary to obtain vehicle information related to the vehicle from the target vehicle to which the service is provided, or to cause the target vehicle to perform a predetermined operation or process.

[0006] As a result of the inventors' detailed examination, when a service provider uses a vehicle by obtaining vehicle information from the vehicle or causing the vehicle to perform a predetermined operation or process, it has been found that there is a problem that it is desirable to appropriately charge the service provider according to the use of the vehicle.

[0007] The present disclosure appropriately transmits logs from a vehicle in order to appropriately charge a service provider that provides services to the vehicle.

[0008] One aspect of the present disclosure is an electronic control device mounted on a vehicle and including a cooperation control unit. The cooperation control unit is configured to realize cooperation between a service system function block configured to provide services to a mounting vehicle, which is a vehicle on which the electronic control device is mounted, and a control system function block configured to control the mounting vehicle.

[0009] The control system function block includes a function interface. The function interface is configured to convert an access request transmitted from the service system function block and expressed in a vehicle-independent format into a vehicle-dependent format.

[0010] The cooperation control unit includes a request transfer unit, a log creation unit, a statistical log creation unit, a statistical transmission unit, a log transmission unit, and a log deletion unit.

[0011] The request transfer unit is configured to transfer an access request transmitted from the service system function block to the control system function block.

[0012] The log creation unit is configured to create an access log indicating the execution status of an access request for each access request transmitted from the service system function block, and store the created access log in a preset first storage unit.

[0013] The statistical log creation unit is configured to perform statistical processing on the execution status of a plurality of access requests, create a statistical access log indicating the result of the statistical processing, and store the created statistical access log in a preset second storage unit.

[0014] The statistical transmission unit is configured to transmit a statistical access log to a server when a preset statistical transmission condition is satisfied. The server is installed outside the vehicle and performs a charging process based on the statistical access log.

[0015] When data communication with the server is possible, the log transmission unit is configured to transmit the access log stored in the first storage unit to the server.

[0016] When a preset log deletion condition is satisfied, the log deletion unit is configured to delete the access log from the first storage unit.

[0017] The electronic control device of the present disclosure configured as described above can transmit the statistical access log and the access log to a server that performs billing processing.

[0018] Furthermore, when data communication with the server is possible, the electronic control device of the present disclosure transmits the access log stored in the first storage unit to the server, and deletes the access log from the first storage unit when the log deletion condition is satisfied. For this reason, the electronic control device of the present disclosure can suppress the occurrence of a situation where new access logs cannot be transmitted to the server because the access logs are stored up to the upper limit of the storage capacity of the first storage unit and new access logs cannot be stored. Thereby, the electronic control device of the present disclosure can suppress the occurrence of a situation where proper billing cannot be performed to a service provider that provides services to the vehicle.

[0019] Another aspect of the present disclosure is a management program for causing a computer of an electronic control device including a cooperation control unit to function as a request transfer unit, a log creation unit, a statistical log creation unit, a statistical transmission unit, a log transmission unit, and a log deletion unit.

[0020] The computer controlled by the management program of the present disclosure can constitute a part of the electronic control device of the present disclosure, and can obtain the same effects as the electronic control device of the present disclosure.

[0021] Yet another aspect of the present disclosure is a management method executed by an electronic control unit including a cooperation control unit configured to realize cooperation between a service system function block and a control system function block configured to control a vehicle equipped with a function interface.

[0022] The management method of the present disclosure transfers an access request transmitted from a service system function block to a control system function block.

[0023] The management method of the present disclosure further creates an access log indicating the execution status of an access request for each access request transmitted from the service system function block, and stores the created access log in a preset first storage unit.

[0024] The management method of the present disclosure further performs statistical processing on the execution status of a plurality of access requests, creates a statistical access log indicating the result of the statistical processing, and stores the created statistical access log in a preset second storage unit.

[0025] The management method of the present disclosure further transmits the statistical access log to a server when a preset statistical transmission condition is satisfied.

[0026] The management method of the present disclosure further transmits the access log stored in the first storage unit to the server when data communication with the server is possible.

[0027] The management method of the present disclosure further deletes the access log from the first storage unit when a preset log deletion condition is satisfied.

[0028] The management method of the present disclosure is a method executed by the electronic control unit of the present disclosure, and by executing this method, the same effects as those of the electronic control unit of the present disclosure can be obtained.

[0029] Another aspect of the present disclosure is an electronic control device mounted on a vehicle and including a cooperation control unit. The cooperation control unit is configured to realize cooperation between a service function block and a control function block configured to control the mounted vehicle with a function interface.

[0030] The cooperation control unit includes a request transfer unit, a log creation unit, a statistical log creation unit, a statistical transmission unit, a log transmission unit, and a log deletion unit.

[0031] The electronic control device of the present disclosure configured as described above can suppress the occurrence of a situation where it becomes impossible to appropriately charge a service provider that provides services to the vehicle.

[0032] Yet another aspect of the present disclosure is a service providing system including an electronic control device mounted on a vehicle and a server configured to be capable of data communication with the electronic control device.

[0033] The electronic control device includes a cooperation control unit. The control function block includes a function interface.

[0034] The cooperation control unit includes a request transfer unit, a log creation unit, a statistical log creation unit, a statistical transmission unit, a log transmission unit, and a log deletion unit.

[0035] The server is configured to calculate an interface usage fee generated by the service function block using the function interface by using the access log and the statistical access log created by the cooperation control unit.

[0036] The service providing system of the present disclosure configured as described above is a system including the electronic control device of the present disclosure and can obtain the same effects as the electronic control device of the present disclosure.

Brief Description of the Drawings

[0037]

Figure 1

Figure 2

Figure 3

Figure 4

Figure 5

Figure 6

Figure 7

Figure 8

Figure 9

Mode for Carrying Out the Invention

[0038] [First Embodiment] The first embodiment of the present disclosure will be described below with reference to the drawings.

[0039] As shown in FIG. 1, the service providing system 1 of the present embodiment includes a vehicle control system 2 and a server 3.

[0040] The vehicle control system 2 is mounted on a vehicle and has a function of performing data communication with the server 3 via a wide area wireless communication network NW.

[0041] The server 3 has a function of performing data communication with the vehicle control system 2 via a wide area wireless communication network NW. An app store accessible via the wide area wireless communication network NW or the Internet is installed in the server 3.

[0042] The vehicle equipped with the vehicle control system 2 may have an automatic driving function in addition to the manual driving function. The vehicle may be a hybrid vehicle having an engine and an electric motor as driving power sources. The vehicle is not limited to a vehicle with an automatic driving function and a hybrid vehicle, and may be a vehicle equipped with only a manual driving function, or a vehicle having only an engine or only an electric motor as a driving power source. Hereinafter, the vehicle equipped with the vehicle control system 2 will be simply referred to as the vehicle.

[0043] The vehicle control system 2 includes one ECU 4, a plurality of ECUs 5, a plurality of ECUs 6, an in-vehicle communication device 7, and an in-vehicle communication network 8. ECU is the abbreviation of Electronic Control Unit.

[0044] By integrating a plurality of ECUs 5, the ECU 4 realizes coordinated control of the entire vehicle.

[0045] The ECU 5 is provided for each domain classified by the functions in the vehicle, and mainly executes the control of a plurality of ECUs 6 existing in that domain. Each ECU 5 is connected to the subordinate ECU 6 via an individually provided lower-layer network (for example, CAN). CAN is the abbreviation of Controller Area Network. CAN is a registered trademark. The domain is, for example, the power train, the body, the chassis, and the cockpit, etc.

[0046] The ECU 6 connected to the ECU 5 belonging to the power train domain includes, for example, an ECU 6 that controls the engine, an ECU 6 that controls the motor, and an ECU 6 that controls the battery, etc.

[0047] The ECU 6 connected to the ECU 5 belonging to the body domain includes, for example, an ECU 6 that controls the air conditioner and an ECU 6 that controls the door, etc.

[0048] The ECU6 connected to the ECU5 belonging to the chassis domain includes, for example, an ECU6 that controls the brakes, an ECU6 that controls the steering, and the like.

[0049] The ECU6 connected to the ECU5 belonging to the cockpit domain includes, for example, an ECU6 that controls the display of the meter and navigation, an ECU6 that controls the input device operated by the vehicle occupants, and the like.

[0050] The vehicle exterior communication device 7 performs data communication with the server 3 via the wide area wireless communication network NW.

[0051] The in-vehicle communication network 8 includes CAN FD and Ethernet. Ethernet is a registered trademark. CAN FD is an abbreviation for CAN with Flexible Data Rate. CAN FD bus-connects the ECU4, each ECU5, and the vehicle exterior communication device 7. Ethernet individually connects between the ECU4, each ECU5, and the vehicle exterior communication device 7.

[0052] The ECU4 is an electronic control device mainly composed of a microcomputer equipped with a CPU4a, a ROM4b, a RAM4c, and the like. Various functions of the microcomputer are realized by the CPU4a executing a program stored in a non-transitory tangible recording medium. In this example, the ROM4b corresponds to the non-transitory tangible recording medium storing the program. Further, by executing this program, a method corresponding to the program is executed. Note that part or all of the functions executed by the CPU4a may be configured hardware-wise by one or a plurality of ICs or the like. Also, the number of microcomputers constituting the ECU4 may be one or plural.

[0053] The ECU4 further includes a flash ROM4d. The flash ROM4d is a rewritable non-volatile memory.

[0054] ECU5, ECU6, and the vehicle external communication device 7 are all electronic control devices centered around a microcomputer equipped with a CPU, ROM, RAM, etc., similar to ECU4. Also, the number of microcomputers constituting ECU5, ECU6, and the vehicle external communication device 7 may be one or more. ECU5 supervises one or more ECU6. ECU4 supervises one or more ECU5, or supervises all of the ECU5, 6 in the vehicle and the vehicle external communication device 7.

[0055] Hereinafter, when not particularly distinguishing ECU4, ECU5, ECU6, and the vehicle external communication device 7, they are referred to as in-vehicle devices 4 to 7.

[0056] The server 3 includes a control unit 11, a communication unit 12, and a storage unit 13.

[0057] The control unit 11 is an electronic control device centered around a microcomputer equipped with a CPU 11a, ROM 11b, RAM 11c, etc. Various functions of the microcomputer are realized by the CPU 11a executing a program stored in a non-transitory tangible recording medium. In this example, the ROM 11b corresponds to the non-transitory tangible recording medium storing the program. Also, by executing this program, the method corresponding to the program is executed. Note that part or all of the functions executed by the CPU 11a may be configured hardware-wise by one or more ICs, etc. Also, the number of microcomputers constituting the control unit 11 may be one or more.

[0058] The communication unit 12 performs data communication with the vehicle control system 2 via the wide area wireless communication network NW. The storage unit 13 is a storage device for storing various data.

[0059] As shown in FIG. 2, the ECU 4 includes a real-time processing unit 20 and an application processing unit 30 (hereinafter referred to as the application processing unit 30). When the ECU 4 includes a plurality of CPUs 4a, the real-time processing unit 20 and the application processing unit 30 may be realized by processes executed by the same CPU, or may be realized by processes executed by different CPUs, respectively.

[0060] The real-time processing unit 20 cooperates with in-vehicle devices 5 to 7 connected via CAN FD to execute vehicle control etc. that requires real-time performance. The application processing unit 30 cooperates with in-vehicle devices 5 to 7 connected via Ethernet to execute various applications (for example, entertainment applications etc.) that require high processing capabilities.

[0061] The application processing unit 30 has a function of transmitting instructions etc. based on the processing of various applications to the real-time processing unit 20. The real-time processing unit 20 has a function of transmitting information etc. collected from the ECU etc. via CAN FD to the application processing unit 30. Thereby, the real-time processing unit 20 and the application processing unit 30 cooperate with each other to realize various functions.

[0062] The software of the vehicle control system 2 is constructed in accordance with AUTOSAR. AUTOSAR is an architecture for autonomous driving and is the abbreviation of Automotive Open System Architecture. AUTOSAR is a registered trademark. AUTOSAR provides functions not only for communication between software components (hereinafter referred to as SW-C) implemented to realize various applications, but also for connection to the cloud and security etc. An SW-C is software that is componentized to realize a certain function. An application program includes one or more SW-Cs. Note that the software of the vehicle control system 2 does not necessarily have to be constructed in accordance with AUTOSAR.

[0063] Each device belonging to the vehicle control system 2, namely, the ECUs 4, 5, 6, and the vehicle external communication device 7, all have a platform. The platform provides an environment for executing SW-Cs described in a hardware-independent format.

[0064] The platform includes a runtime environment (hereinafter, RTE) and basic software (hereinafter, BSW). The RTE is an interface that connects SW-Cs to each other and between SW-Cs and BSW. The BSW is a layer that connects hardware and SW-Cs and includes an OS, drivers, middleware, etc. The functions of the BSW are divided into fine-grained modules, and the functions of each module are provided to SW-Cs via APIs. An API is the abbreviation of Application Programming Interface.

[0065] Hereinafter, the platform included in the real-time processing unit 20 is referred to as the first platform 21 (hereinafter, the first PF 21), and the platform included in the application processing unit 30 is referred to as the second platform 31 (hereinafter, the second PF 31).

[0066] The real-time processing unit 20 includes a control system function block group 22 as a set of service applications (hereinafter, service apps) operating on the first PF 21. A service app is an application that receives a request from a client, processes it, and returns a result.

[0067] The control system function block group 22 includes an API for receiving commands related to the movement of the vehicle, and is a group of applications that centrally manage the commands received by the API to achieve coordinated vehicle control. The control system function block group 22 outputs various commands to in-vehicle devices 5 to 7 where entities that execute control based on the commands exist via the in-vehicle communication network 8.

[0068] The first PF21 includes a conversion gateway 211. The conversion gateway 211 has a function of converting a communication frame received by the real-time processing unit 20 via CAN FD into an Ethernet format and providing it to the application processing unit 30. The conversion gateway 211 also has a function of converting a communication frame in Ethernet format provided from the application processing unit 30 into a CAN FD format.

[0069] The application processing unit 30 includes a hypervisor 32 and executes software on a plurality of virtual machines. Note that the hypervisor 32 may be omitted.

[0070] The application processing unit 30 includes a service function block group 33 as a set of service applications operating on the second PF31.

[0071] The service function block group 33 is a set of service applications. Each service application includes one or more SW-Cs. The service applications are provided not only by the vehicle manufacturer that manufactures the vehicle but also by a third party. Examples of the third party that provides the service applications include data utilization operators that provide services by collecting data from vehicles.

[0072] The second PF31 includes a control function block group 35, a data function block group 36, and an API gateway 40.

[0073] The control function block group 35 is a set of programs having an API for receiving requests related to vehicle control from the service function block group 33. The control function block group 35 includes an API group 37 composed of a plurality of APIs, and converts an API access request from the service function block group 33 expressed in a vehicle-independent format into an API access request expressed in a vehicle-dependent format and provides it to the real-time processing unit 20. The above-mentioned "vehicle-independent format" is a format common to vehicles (that is, a format that absorbs differences in vehicle models). The above-mentioned "vehicle-dependent format" is a format specific to a vehicle.

[0074] Among the APIs provided by the control system function block group 35, there are a motion system API for controlling the movement of the vehicle and non-motion system APIs other than that. The API access request received by the motion system API is transferred to the control system function block group 35, and from the control system function block group 35, it is transferred to in-vehicle devices 5 to 7 that execute control based on the request via the in-vehicle communication network 8. The API access request received by the non-motion system API is transferred to in-vehicle devices 5 to 7 that execute control based on the request via the in-vehicle communication network 8.

[0075] The data system function block group 36 is a set of programs equipped with APIs for handling vehicle data acquired and stored via the real-time processing unit 20. The data system function block group 36 has a function of abstracting and storing vehicle data expressed in a vehicle-dependent format and supplied from the real-time processing unit 20 into a vehicle-independent format. The data system function block group 36 may have an API that provides a function of transmitting specified vehicle data to an ECU or the like via Ethernet. In particular, when the transmission destination is the off-vehicle communication device 7, the off-vehicle communication device 7 may upload the transmitted vehicle data to the cloud.

[0076] Note that the communication with other in-vehicle devices 5 to 7 via the control system function block group 35 is not limited to CAN FD, and Ethernet or other communication means may be used. Also, the communication with other in-vehicle devices 5 to 7 via the data system function block group 36 is not limited to Ethernet, and CAN FD or other communication means may be used.

[0077] The API gateway 40 is configured by utilizing the functions of a virtual function bus (hereinafter referred to as VFB). The VFB is middleware that enables communication between SW-Cs and communication between an SW-C and the BSW without being aware of hardware, communication protocols, etc., and is also called a software bus. Communication between SW-Cs refers to access from an SW-C to an API provided by another SW-C, and communication between an SW-C and the BSW refers to access from an SW-C to an API provided by the control system function block group 35 and the data system function block group 36.

[0078] That is, the SW-C accesses various APIs via the API gateway 40 and realizes a desired function by using the functions provided by the accessed APIs.

[0079] When using an API, the SW-C sends an API access request. The API access request includes at least the app ID of the service app including the SW-C that is the request source and the API-ID which is information indicating the API that is the request destination.

[0080] As shown in FIG. 3, an app store 15 is installed in the server 3. As indicated by the arrow L1, the app store 15 has a function of registering a service app SA manufactured by a service provider SV (hereinafter referred to as service SV) that has accessed the app store 15 using a communication device such as a personal computer based on an application by the service SV. The service app SA registered in the app store 15 is posted on the website of the app store 15.

[0081] Also, as indicated by the arrow L2, the app store 15 has a function of registering the APIs used by the service app SA in the app store 15 based on an application by the service SV.

[0082] When a user US who accesses the website of the app store 15 purchases the service app SA, as indicated by arrow L3, the service app SA is installed in the ECU 4 mounted on the vehicle of the user US.

[0083] As indicated by arrow L4, when the service app SA sends an API access request to the API gateway 40, the API gateway 40 transfers the API access request to the control system function block group 35 as indicated by arrow L5. As described above, the control system function block group 35 converts the API access request into an API access request expressed in a vehicle-dependent format and provides it to the real-time processing unit 20.

[0084] The API gateway 40 sends a statistical access log including the number of API uses taking into account the execution achievement status of the API access request and the amount of communication data associated with the API use to the app store 15 as indicated by arrow L6.

[0085] Based on the statistical access log received from the API gateway 40, the app store 15 calculates the API usage fee generated by the service app SA's use of the API and bills the service provider SV for the API usage fee. As indicated by arrow L7, the service provider SV pays the billed API usage fee to the app store 15.

[0086] The app store 15 calculates the app usage fee of the service app SA based on the usage status of the service app SA and bills the user US for the app usage fee. As indicated by arrow L8, the user US pays the billed app usage fee to the app store 15. As indicated by arrow L9, the app store 15 transfers the app usage fee paid by the user US to the service provider SV.

[0087] Next, the procedure when the service provider SV makes an API usage contract will be described.

[0088] As shown in process P1 of FIG. 4, service provider SV accesses application store 15 and applies for registration of the service applications to be published and registration of the APIs to be used.

[0089] As shown in process P2, application store 15 examines whether the service applications applied for by service provider SV can access control system function block group 35.

[0090] When the applied service applications can access control system function block group 35, application store 15 presents the usage API charging form to service provider SV as shown in process P3.

[0091] As shown in table TB1, application store 15 stores API policy information including API-ID, reliability, and charging form in storage unit 13 for each applied API.

[0092] In table TB1, the reliability of the API with API-ID being API1 is "high", and the charging form is "usage-based per call count"; the reliability of the API with API-ID being API2 is "low", and the charging form is "monthly fixed fee".

[0093] APIs with "high" reliability accept API access requests from service applications with high reliability and reject API access requests from service applications with low reliability.

[0094] APIs with "low" reliability accept API access requests even from service applications with low reliability.

[0095] "Usage-based per call count" is a charging form that adds fees according to the number of API access requests. "Monthly fixed fee" is a charging form that bills a fixed fee regardless of the number of API access requests every month.

[0096] As shown in process P4, service SV notifies app store 15 that it agrees to the contract in the presented usage API billing format. As a result, as shown in process P5, app store 15 publishes the service app applied for by service SV on the website of app store 15.

[0097] App store 15 stores in storage unit 13 the information of the service app to be published on the website (hereinafter referred to as published app information) and the information of the APIs authorized for the service app to be published on the website (hereinafter referred to as API authorization information).

[0098] As shown in table TB2, the published app information includes, for each service app to be published, an app ID, a function name of the service app, a billing format of the service app, and a service provider ID. The app ID is information for identifying the service app. The service provider ID is information for identifying the provider of the service app.

[0099] In table TB2, the function name of the service app with app ID APP1 is "Comfortable Air Conditioning", the billing format is "Usage Time", and the service provider ID is "Dev1". The function name of the service app with app ID APP2 is "Load Service", the billing format is "Monthly", and the service provider ID is "Dev1".

[0100] The billing format of "Usage Time" is a billing format in which fees are added according to the usage time of the service app. The billing format of "Monthly" is a billing format in which a fixed fee independent of the usage time of the service app is billed every month.

[0101] As shown in table TB3, the API authorization information includes, for each API whose usage is authorized, an API-ID and an app ID.

[0102] Table TB3 indicates that the API with API-ID being API1 is called by the service app with app ID being APP1, and the API with API-ID being API2 is called by the service app with app ID being APP2.

[0103] Next, the procedure of the log creation process executed by the API gateway 40 will be described. The log creation process is a process that is repeatedly executed during the operation of the ECU 4.

[0104] When the log creation process is executed, the API gateway 40 (hereinafter referred to as APIGW40) first determines, as shown in FIG. 5, whether an API access request has been received at S10. Here, if no API access request has been received, APIGW40 proceeds to S120. On the other hand, if an API access request has been received, APIGW40 determines at S20 whether the received API access request is executable. For example, APIGW40 determines whether the ECU 4 can communicate with the ECU 6 that executes the process instructed by the API access request. If data communication is possible, APIGW40 determines that the API access request is executable; if data communication is not possible, APIGW40 determines that the API access request is not executable.

[0105] Here, if the API access request is not executable, APIGW40 proceeds to S70. On the other hand, if the API access request is executable, APIGW40 determines at S30 whether the received API access request needs to be transferred to the destination API. For example, if the process instructed by the API access request has already been executed, APIGW40 determines that there is no need to transfer the API access request to the destination API.

[0106] Here, when there is no need to transfer the API access request, APIGW40 migrates to S70. On the other hand, when it is necessary to transfer the API access request, APIGW40 transfers the received API access request to the destination API at S40.

[0107] Then, at S50, APIGW40 determines whether it has received the execution result of the transferred API access request from the API to which the API access request was transferred. Here, if the execution result has not been received, by repeating the process of S50, it waits until the execution result is received.

[0108] When the execution result of the API access request is received, at S60, APIGW40 transfers the execution result received from the API to the service application that is the source of the API access request and migrates to S70.

[0109] When migrating to S70, APIGW40 creates a raw access log for the API access request determined to be received at S10 and stores the created raw access log in RAM4c. Specifically, for the API access request transferred at S40, APIGW40 creates a raw access log including the content of the API access request and the content of the execution result transferred at S60. The raw access log including the content of the execution result is, for example, information such as "At [time], application A called API-B with parameter C, and the result was D". Note that APIGW40 may generate and upload the raw access log when there is an API access request and also generate and upload the raw access log when the execution result is obtained.

[0110] Also, for the API access request not transferred at S40, APIGW40 creates a raw access log including the content of the API access request and the reason for not transferring.

[0111] Next, the APIGW 40 determines at S80 whether data communication with the server 3 is possible. Here, if data communication with the server 3 is not possible, the APIGW 40 proceeds to S100. On the other hand, if data communication with the server 3 is possible, the APIGW 40 uploads the raw access log stored in the RAM 4c at S70 to the server 3 at S90 and proceeds to S100.

[0112] When proceeding to S100, the APIGW 40 creates a statistical access log based on the raw access log stored in the RAM 4c at S70 and stores the created statistical access log in the flash ROM 4d.

[0113] The statistical access log is specified by the app that provides the API, the API, and the source of the API access request. That is, if the number of apps that provide the API is A, the number of APIs is B, and the number of sources of the API access request is C, the number of statistical access logs is A × B × C.

[0114] As shown in FIG. 6, the statistical access log includes an API providing app ID, an API-ID, a calling source app ID, the number of API calls, the number of API execution completions, the number of unnecessary API executions, the number of abnormal API executions, the API communication data volume, the number of execution completions during power-off parking, the number of execution completions during power supply parking, the number of execution completions during parking, and the number of execution completions during driving.

[0115] The API providing app ID is an identifier of the app that provides the API. The API-ID is an identifier of the API. The calling source app ID is an identifier of the app that uses the API.

[0116] The number of API calls is the number of times the service app specified by the calling source app ID makes an API access request.

[0117] The number of API execution completions is the number of times the process corresponding to the API access request is executed and completed.

[0118] The number of times API execution is unnecessary is the number of times the execution of the process has become unnecessary because the process corresponding to the API access request has already been executed.

[0119] The number of abnormal API execution times is the number of times the process corresponding to the API access request was not executed due to an abnormality.

[0120] The API communication data volume is the integrated value of the data volume obtained by the process corresponding to the API access request.

[0121] The number of completed executions during power-off parking is the number of times the process corresponding to the API access request was executed and completed during power-off parking.

[0122] The number of completed executions during power supply parking is the number of times the process corresponding to the API access request was executed and completed during power supply parking.

[0123] The number of completed executions during parking is the number of times the process corresponding to the API access request was executed and completed during parking.

[0124] The number of completed executions during driving is the number of times the process corresponding to the API access request was executed and completed during driving.

[0125] Next, a first specific example of creating a statistical access log will be described.

[0126] Suppose that the door of a vehicle parked without power is in an unlocked state, and a service app sends an API access request instructing door locking to APIGW40. When receiving the API access request, APIGW40 checks the state of the vehicle's door. Since the vehicle's door is in an unlocked state, APIGW40 determines that the transfer of the API access request is necessary, and transfers the received API access request to the destination API. As a result, ECU4 sends a command instructing door locking to ECU6 that controls the door. When receiving the command instructing door locking, ECU6 that controls the door locks the vehicle's door. When the locking of the vehicle's door is completed, ECU6 that controls the door sends an execution result indicating that the vehicle's door has become locked to ECU4. When receiving the above execution result from the destination API, APIGW40 transfers the above execution result to the service app that is the request source. Further, in the statistical access log specified by the API providing app ID, API ID, and call source app ID, APIGW40 increments (i.e., adds 1) the number of API calls and the number of completed API executions, and increments the number of completed executions during parking without power.

[0127] Next, a second specific example of creating a statistical access log will be described.

[0128] Suppose that the door of a vehicle parked with power supply is in a locked state, and a service app sends an API access request instructing door locking to APIGW40. When receiving the API access request, APIGW40 checks the state of the vehicle's door. Since the vehicle's door is in a locked state, APIGW40 determines that the transfer of the API access request is unnecessary, and sends a notification indicating that the instruction for door locking has been normally completed to the service app that is the request source. Further, in the statistical access log, APIGW40 increments the number of API calls and the number of unnecessary API executions.

[0129] Next, a third specific example of creating a statistical access log will be described.

[0130] While the vehicle is parked without power and the door is in the unlocked state, assume that the first service app sends an API access request instructing door locking to APIGW40, and the second service app sends an API access request instructing door unlocking to APIGW40. APIGW40 performs mediation between the first service app and the second service app. Since the second service app has a higher priority than the first service app, APIGW40 sends a notification to the first service app indicating that the instruction to lock the door was not executed due to mediation loss, and increments the API call count and the API execution exception count in the statistical access log of the first service app. Also, since the vehicle door is in the unlocked state, APIGW40 determines that it is unnecessary to transfer the API access request of the second service app, and sends a notification to the second service app indicating that the instruction to unlock the door has ended normally. Furthermore, APIGW40 increments the API call count and the API non-execution count in the statistical access log of the second service app.

[0131] Next, a fourth specific example of creating a statistical access log will be described.

[0132] Assume that while the communication between ECU4 and in-vehicle devices 5 to 7 is interrupted, the service app sends an API access request instructing the acquisition of vehicle speed information to APIGW40. Due to the communication anomaly, APIGW40 sends a notification to the service app that requested it, indicating that the vehicle speed information cannot be acquired due to the communication anomaly. Furthermore, APIGW40 increments the API call count and the API execution exception count in the statistical access log specified by the API providing app ID, the API-ID, and the call source app ID.

[0133] Next, a fifth specific example of creating a statistical access log will be described.

[0134] Suppose that the service app sends an API access request to APIGW40 to instruct the acquisition of vehicle speed information updated every 300 ms. Since more than 300 ms has elapsed since the previous API access request to instruct the acquisition of vehicle speed information, APIGW40 determines that it is necessary to transfer the API access request and transfers the received API access request to the destination API. As a result, ECU4 sends a command to instruct the acquisition of vehicle speed information to ECU6 that controls the engine. When ECU6 that controls the engine acquires the vehicle speed information, it sends the execution result indicating the acquired vehicle speed information to ECU4. When APIGW40 receives the above execution result from the destination API, it transfers the above execution result to the service app that is the request source. Further, in the statistical access log specified by the API providing app ID, API ID, and call source app ID, APIGW40 increments the number of API calls and the number of API execution completions.

[0135] Furthermore, suppose that after 100 ms has elapsed since the previous API access request to instruct the acquisition of vehicle speed information, the service app sends an API access request to instruct the acquisition of vehicle speed information to APIGW40. Since less than 300 ms has elapsed since the previous API access request, APIGW40 determines that it is not necessary to transfer the API access request, sends the vehicle speed information with the same value as the previous time to the service app that is the request source, and increments the number of API calls and the number of API non-execution times in the statistical access log.

[0136] Next, a sixth specific example of creating a statistical access log will be described.

[0137] Suppose a service app sends an API access request instructing the acquisition of surrounding map data to APIGW40. APIGW40 determines that the transfer of the API access request is necessary and transfers the received API access request to the destination API. As a result, ECU4 sends a command instructing the acquisition of surrounding map data to ECU6 that controls the navigation device. When ECU6 that controls the navigation device acquires the surrounding map data, it sends an execution result indicating the acquired surrounding map data to ECU4. When APIGW40 receives the above execution result from the destination API, it transfers the above execution result to the service app that is the request source. Further, APIGW40 increments the number of API calls and the number of API execution completions in the statistical access log specified by the API providing app ID, API-ID, and call source app ID, and adds a value corresponding to the data volume of the surrounding map data to the API communication data volume.

[0138] As shown in FIG. 5, when the process of S100 ends, APIGW40 deletes the raw access log stored in RAM4c in S110 and proceeds to S120.

[0139] When proceeding to S120, APIGW40 determines whether the upload timing has arrived. The upload timing is set to arrive, for example, every 24 hours. The upload timing may be set to arrive, for example, when N API access requests have occurred, or may be set to arrive when the service app SA using the API has ended. In this way, the upload timing may be set to be a longer interval than when sending the raw access log.

[0140] Here, if the upload timing has not arrived, APIGW40 ends the log creation process. On the other hand, if the upload timing has arrived, APIGW40 uploads all the statistical access logs to the server 3 in S130 and ends the log creation process.

[0141] Next, the procedures for user settlement and service provider settlement will be described.

[0142] As shown by the arrow L11 in FIG. 7, the user US uses the service application SA, and as shown by the arrow L12, the service application SA uses the API. Each time the service application SA uses the API, as shown by the process P11, the APIGW 40 updates the statistical access log.

[0143] As shown by the process P12, the app store 15 calculates, for example, every month, the app usage fee generated by the user US using the service application SA, and as shown by the process P13, bills the user US for the calculated app usage fee.

[0144] When the user US pays the app usage fee to the app store 15 as shown by the process P14, as shown by the process P15, the app store 15 settles the app usage fee. After that, as shown by the process P16, the app store 15 transfers the app usage fee to the service provider SV, and as shown by the process P17, notifies the user US of the completion of the settlement.

[0145] When the APIGW 40 uploads the statistical access log as shown by the process P21, the app store 15 calculates, as shown by the process P22, the API usage fee generated by the service application SA using the API based on the statistical access log.

[0146] The app store 15 sets, for each statistical access log specified by the API providing app ID, the API-ID, and the calling source app ID, an execution completion billing coefficient C1, a non-execution billing coefficient C2, an execution anomaly billing coefficient C3, a communication data billing coefficient C4, an execution completion billing coefficient C5 during power-off parking, an execution completion billing coefficient C6 during power supply parking, an execution completion billing coefficient C7 during parking, and an execution completion billing coefficient C8 during driving.

[0147] The execution completion billing coefficient C1 is the billing amount when the number of API execution completions is 1.

[0148] The non-execution charging coefficient C2 is the charging amount when the number of times the API does not need to be executed is 1.

[0149] The abnormal execution charging coefficient C3 is the charging amount when the number of abnormal API executions is 1.

[0150] The communication data charging coefficient C4 is the charging amount per unit communication data volume.

[0151] The execution completion charging coefficient C5 during power-off parking is the charging amount when the number of execution completions during power-off parking is 1.

[0152] The execution completion charging coefficient C6 during charging parking is the charging amount when the number of execution completions during charging parking is 1.

[0153] The execution completion charging coefficient C7 during parking is the charging amount when the number of execution completions during parking is 1.

[0154] The execution completion charging coefficient C8 during driving is the charging amount when the number of execution completions during driving is 1.

[0155] That is, the app store 15 calculates the API usage fee for one statistical access log by multiplying the corresponding coefficient by the number of times or the data volume. Furthermore, the app store 15 calculates the API usage fee for the service app SA by accumulating the API usage fees of all statistical access logs.

[0156] In addition, if there are multiple APIs that operate the same actuator and the arbitration priorities of these multiple APIs are different, the charging coefficient of the API with a higher priority is greater than the charging coefficient of the API with a lower priority.

[0157] Also, the execution completion charging coefficient C5 during power-off parking is greater than the execution completion charging coefficient C6 during charging parking. That is, the charging amount is higher during power-off parking with limited power than during charging parking with power supply.

[0158] Also, the execution completion charging coefficient C7 during parking is greater than the execution completion charging coefficient C8 during driving. That is, the charging amount is higher during parking with limited power than during driving when power is being generated.

[0159] Also, if there are multiple APIs that acquire the same information and the responsiveness of these multiple APIs is different, the charging coefficient of the API with higher responsiveness is greater than the charging coefficient of the API with lower responsiveness.

[0160] Also, the charging coefficient varies according to the quality of the data to be acquired. For example, data that requires know-how such as narrow road scene determination has a large charging coefficient, while simple data such as vehicle speed information has a small charging coefficient. Also, the availability of equipment (e.g., Capability update notification) is free at the time of initial installation, and change notifications are charged. Also, the charging coefficient of an API that acquires multiple data simultaneously, such as timestamped data, is large.

[0161] Also, the app store 15 increases or decreases the usage fee from the API usage fee calculated using the statistical access log according to the content of each raw access log. The app store 15 calculates the API usage fee using the statistical access log, but may dynamically change the calculated API usage fee according to the content of each raw access log. The app store 15 may calculate the API usage fee using only the statistical access log.

[0162] When the calculation of the API usage fee of the service app SA is completed, the app store 15 bills the calculated API usage fee to the service SV as shown in process P23.

[0163] As shown in process P24, when the service SV pays the API usage fee to the app store 15, as shown in process P25, the app store 15 settles the API usage fee. After that, the app store 15 notifies the service SV of the completion of settlement as shown in process P26.

[0164] The ECU 4 of the vehicle control system 2 configured as described above is mounted on the vehicle and includes an API gateway 40. The API gateway 40 is configured to realize cooperation between a service function block group 33 configured to provide services to the vehicle (hereinafter, the mounted vehicle) on which the ECU 4 is mounted and a control function block group 35 configured to control the mounted vehicle.

[0165] The control function block group 35 includes an API group 37. The API group 37 is configured to convert an API access request transmitted from the service function block group 33 and expressed in a vehicle-independent format into a vehicle-dependent format.

[0166] The API gateway 40 is configured to transfer an API access request transmitted from the service function block group 33 to the control function block group 35.

[0167] The API gateway 40 is configured to create a raw access log indicating the execution status of the API access request for each API access request and store the created raw access log in the RAM 4c.

[0168] The API gateway 40 is configured to perform statistical processing on the execution status of a plurality of API access requests, create a statistical access log indicating the result of the statistical processing, and store the created statistical access log in the flash ROM 4d.

[0169] The API gateway 40 is configured to transmit the statistical access log to the server 3 when a preset statistical transmission condition is satisfied. The server 3 is installed outside the vehicle and performs billing processing based on the statistical access log. The statistical transmission condition in the present embodiment is that the upload timing arrives.

[0170] The API gateway 40 is configured to transmit the raw access log stored in the RAM 4c to the server 3 when data communication is possible with the server 3.

[0171] When the preset log deletion condition is satisfied, the API gateway 40 is configured to delete the raw access logs from the RAM 4c. The log deletion condition in this embodiment is that the raw access logs to be deleted have been used for statistical processing to create statistical access logs.

[0172] Such an ECU 4 can transmit the statistical access logs and the raw access logs to the server 3 that performs the charging process. Therefore, the ECU 4 can cause the server 3 to calculate the API usage fees generated by the service function block group 33 using the API group 37 by using the statistical access logs and the raw access logs.

[0173] Then, the server 3 can calculate the API usage fees not only using the statistical access logs whose information volume has decreased after being processed by statistical processing using a plurality of raw access logs, but also using the raw access logs with a large information volume because they show the execution status for each access request. Therefore, the ECU 4 can cause the server 3 to appropriately calculate the API usage fees according to the use of the API group 37.

[0174] Furthermore, when data communication is possible between the ECU 4 and the server 3, the ECU 4 transmits the raw access logs stored in the RAM 4c to the server 3 and deletes the raw access logs from the RAM 4c when the log deletion condition is satisfied. Therefore, the ECU 4 can suppress the occurrence of a situation where new raw access logs cannot be transmitted to the server 3 because new raw access logs cannot be stored due to the raw access logs being stored up to the upper limit of the storage capacity of the RAM 4c. Thereby, the ECU 4 can suppress the occurrence of a situation where it becomes impossible to appropriately charge the service provider that provides services to the vehicle.

[0175] In addition, the RAM 4c includes a volatile memory. Generally, since a volatile memory is less expensive than a non-volatile memory, it is easier to increase the storage capacity for storing raw access logs in a volatile memory than in a non-volatile memory. Therefore, since the RAM 4c included in the ECU 4 is a volatile memory, the ECU 4 can suppress the raw access logs from being stored up to the upper limit of the storage capacity of the RAM 4c, and can further suppress the occurrence of a situation where it becomes impossible to appropriately charge the service provider.

[0176] In addition, the above log deletion condition is that the raw access log to be deleted has been used in the statistical process for creating the statistical access log. Therefore, the ECU 4 can suppress the raw access logs from being stored up to the upper limit of the storage capacity of the RAM 4c, and can further suppress the occurrence of a situation where it becomes impossible to appropriately charge the service provider.

[0177] In the embodiment described above, the ECU 4 corresponds to an electronic control unit, the service system function block group 33 corresponds to a service system function block, the control system function block group 35 corresponds to a control system function block, and the API gateway 40 corresponds to a cooperation control unit.

[0178] In addition, the API group 37 corresponds to a function interface, S40 corresponds to the process as a request transfer unit, the API access request corresponds to an access request, S70 corresponds to the process as a log creation unit, the raw access log corresponds to an access log, and the RAM 4c corresponds to a first storage unit.

[0179] In addition, S100 corresponds to the process as a statistical log creation unit, the flash ROM 4d corresponds to a second storage unit, S120 and S130 correspond to the process as a statistical transmission unit, S80 and S90 correspond to the process as a log transmission unit, and S110 corresponds to the process as a log deletion unit.

[0180] Also, the number of API calls corresponds to the number of calls, the number of API execution completions corresponds to the number of execution completions, the number of unnecessary API executions corresponds to the number of unnecessary executions, and the API communication data volume corresponds to the integrated value of the data volume.

[0181] [Second Embodiment] The second embodiment of the present disclosure will be described below with reference to the drawings. In the second embodiment, parts different from the first embodiment will be described. The same reference numerals are given to the common configurations.

[0182] The service providing system 1 of the second embodiment is different from the first embodiment in that the log creation process is changed.

[0183] The log creation process of the second embodiment is different from the first embodiment in that the processes of S112 and S114 are executed instead of the process of S110.

[0184] That is, as shown in FIG. 8, when the process of S100 ends, the APIGW 40 determines in S112 whether the raw access logs are stored beyond the raw log storage capacity allocated for storing the raw access logs in the RAM 4c.

[0185] Here, when the raw access logs are not stored beyond the raw log storage capacity, the APIGW 40 proceeds to S120. On the other hand, when the raw access logs are stored beyond the raw log storage capacity, the APIGW 40 deletes the excess raw access logs from the RAM 4c in S114 and proceeds to S120. Specifically, the APIGW 40 sequentially deletes the raw access logs in the order of earlier storage timings stored in the RAM 4c until the data volume of the raw access logs stored is equal to or less than the raw log storage capacity.

[0186] In the ECU4 configured as described above, the API gateway 40 is configured to delete the raw access log from the RAM 4c when a preset log deletion condition is satisfied. The log deletion condition in the present embodiment is that the data volume of the raw access log stored in the RAM 4c exceeds a preset raw log storage capacity.

[0187] Such an ECU4 can suppress the occurrence of a situation where the raw access log is deleted from the RAM 4c and not transmitted to the server 3, and can further suppress the occurrence of a situation where it becomes impossible to appropriately charge the service provider.

[0188] In the embodiment described above, S112 and S114 correspond to the processing as the log deletion unit, and the raw log storage capacity corresponds to the deletion determination value.

[0189] As described above, one embodiment of the present disclosure has been described. However, the present disclosure is not limited to the above embodiment and can be implemented with various modifications.

[0190] [Modification Example 1] In the above embodiment, the form in which the API gateway 40 transfers the API access request to the control system function block group 35 is shown. However, the API gateway 40 may transmit the API access request to the service application.

[0191] Specifically, for example, as shown by the arrow L11 in FIG. 9, when the service application SA1 transmits an API access request to the API gateway 40, the API gateway 40 transmits the API access request to the service application SA2 as shown by the arrow L12. The service applications SA1 and SA2 are applications that provide different services.

[0192] The service application SA2 transmits the data requested by the received API access request to the API gateway 40. Then, the API gateway 40 transmits the data received from the service application SA2 to the service application SA1.

[0193] Also, the API gateway 40 creates a raw access log for the API access request received from the service application SA1, and further creates a statistical access log based on this raw access log. As shown by the arrow L13, the API gateway 40 transmits the created statistical access log to the app store 15.

[0194] Note that the service application SA1 corresponds to the first service function block, and the service application SA2 corresponds to the second service function block.

[0195] The ECU 4 and its method described in the present disclosure may be implemented by a dedicated computer provided by configuring a processor and a memory programmed to execute one or more functions embodied by a computer program. Alternatively, the ECU 4 and its method described in the present disclosure may be implemented by a dedicated computer provided by configuring a processor with one or more dedicated hardware logic circuits. Or, the ECU 4 and its method described in the present disclosure may be implemented by one or more dedicated computers configured by a combination of a processor and a memory programmed to execute one or more functions and a processor configured by one or more hardware logic circuits. Also, the computer program may be stored in a computer-readable non-transitory tangible recording medium as instructions to be executed by a computer. The method for realizing the functions of each part included in the ECU 4 does not necessarily have to include software, and all of its functions may be realized using one or more hardware.

[0196] The plurality of functions of one component in the above-described embodiment may be realized by a plurality of components, or one function of one component may be realized by a plurality of components. Further, the plurality of functions of a plurality of components may be realized by one component, or one function realized by a plurality of components may be realized by one component. Further, a part of the configuration of the above-described embodiment may be omitted. Further, at least a part of the configuration of the above-described embodiment may be added to or replaced with the configuration of another above-described embodiment.

[0197] In addition to the above-described ECU 4, the present disclosure can also be realized in various forms such as a system having the ECU 4 as a component, a program for causing a computer to function as the ECU 4, a non-transitory tangible recording medium such as a semiconductor memory storing this program, and a management method.

[0198] [Technical idea disclosed in this specification] [Item 1] An electronic control unit (4) mounted on a vehicle, comprising a cooperation control unit (40) configured to realize cooperation between a service system function block (33) configured to provide a service to a mounting vehicle which is the vehicle on which the electronic control unit is mounted, and a control system function block (35) configured to control the mounting vehicle. The control system function block includes a function interface (37) configured to convert an access request expressed in a vehicle-independent format and transmitted from the service system function block into a vehicle-dependent format. The cooperation control unit includes a request transfer unit (S40) configured to transfer the access request transmitted from the service system function block to the control system function block, and a log creation unit (S70) configured to create an access log indicating an execution status of the access request for each access request transmitted from the service system function block, and store the created access log in a preset first storage unit (4c). A statistical log creation unit (S100) configured to perform statistical processing on the execution status of the plurality of access requests, create a statistical access log indicating the result of the statistical processing, and store the created statistical access log in a preset second storage unit (4d); A statistical transmission unit (S120, S130) configured to transmit the statistical access log to a server that is installed outside the vehicle and performs charging processing based on the statistical access log when a preset statistical transmission condition is satisfied; A log transmission unit (S80, S90) configured to transmit the access log stored in the first storage unit to the server when data communication is possible with the server; A log deletion unit (S110, S112, S114) configured to delete the access log from the first storage unit when a preset log deletion condition is satisfied An electronic control device comprising the above.

[0199] [Item 2] The electronic control device according to Item 1, wherein the statistical transmission condition is set such that when data communication is possible with the server, the transmission interval is longer than the transmission interval at which the log transmission unit transmits the access log to the server.

[0200] [Item 3] The electronic control device according to Item 1 or Item 2, wherein the first storage unit includes a volatile memory.

[0201] [Item 4] The electronic control device according to any one of Items 1 to 3, wherein the log deletion condition is that the access log to be deleted has been used for the statistical processing by the statistical log creation unit.

[0202] [Item 5] The electronic control device according to any one of Items 1 to 3, wherein The log deletion condition is that the data volume of the access log stored in the first storage unit exceeds a preset deletion determination value. An electronic control device.

[0203] [Item 6] The electronic control device according to any one of Items 1 to 5, The statistical access log includes The number of calls, which is the number of times the service function block has sent the access request, The number of execution completions, which is the number of times the process corresponding to the access request has been executed and completed, The number of unnecessary executions, which is the number of times there was no need to execute the process corresponding to the access request, And the integrated value of the data volume obtained by the service function block when the process corresponding to the access request is executed An electronic control device including at least one of.

[0204] [Item 7] The electronic control device according to any one of Items 1 to 6, The log creation unit creates the access log indicating the execution status of the access request transferred by the request transfer unit. An electronic control device.

[0205] [Item 8] The electronic control device according to Item 7, The log creation unit further creates the access log indicating the execution status of the access request not transferred by the request transfer unit. An electronic control device.

[0206] [Item 9] The electronic control device according to any one of Items 1 to 8, The cooperation control unit is configured to transmit the access request to the second service system function block (SA2) when receiving the access request from the first service system function block (SA1) configured to provide a service to the vehicle, where the second service system function block provides a service different from the first service system function block to the vehicle. The log creation unit creates an access log indicating the execution status of the access request transmitted to the second service system function block. The statistical log creation unit is an electronic control unit that creates a statistical access log including the execution status of the access request transmitted to the second service system function block.

[0207] [Item 10] A computer of the electronic control unit including a cooperation control unit (40) configured to realize cooperation between a service system function block (33) configured to provide a service to a vehicle equipped with the electronic control unit (4), and a control system function block (35) configured to control the vehicle equipped with a function interface (37) configured to convert an access request transmitted from the service system function block expressed in a vehicle-independent format into a vehicle-dependent format. A request transfer unit (S40) configured to transfer the access request transmitted from the service system function block to the control system function block. A log creation unit (S70) configured to create an access log indicating the execution status of each access request transmitted from the service system function block and store the created access log in a preset first storage unit (4c). A statistical log creation unit (S100) configured to execute statistical processing on the execution status of a plurality of the access requests, create a statistical access log indicating the result of the statistical processing, and store the created statistical access log in a preset second storage unit (4d). A statistical transmission unit (S120, S130) configured to transmit the statistical access log to a server installed outside the vehicle and performing a charging process based on the statistical access log when a preset statistical transmission condition is satisfied. A log transmission unit (S80, S90) configured to transmit the access log stored in the first storage unit to the server when data communication with the server is possible, and A log deletion unit (S110, S112, S114) configured to delete the access log from the first storage unit when a preset log deletion condition is satisfied. A management program for causing it to function.

[0208] [Item 11] A cooperation control unit (40) configured to realize cooperation between a service function block (33) configured to provide a service to a vehicle equipped with an electronic control unit (4) and a control function block (35) configured to control the vehicle equipped with a function interface (37) configured to convert an access request transmitted from the service function block and expressed in a form independent of the vehicle into a form dependent on the vehicle. A management method executed by the electronic control unit comprising: Transferring the access request transmitted from the service function block to the control function block, For each access request transmitted from the service function block, creating an access log indicating the execution status of the access request, and storing the created access log in a preset first storage unit (4c), Performing statistical processing on the execution status of a plurality of the access requests to create a statistical access log indicating the result of the statistical processing, and storing the created statistical access log in a preset second storage unit (4d), When a preset statistical transmission condition is satisfied, transmitting the statistical access log to a server installed outside the vehicle and performing a charging process based on the statistical access log, When data communication is possible with the server, the access log stored in the first storage unit is transmitted to the server, A management method for deleting the access log from the first storage unit when a preset log deletion condition is satisfied.

[0209] [Item 12] An electronic control unit (4) mounted on a vehicle, A service function block (33) configured to provide a service to the vehicle on which the electronic control unit is mounted, and a function interface (37) configured to convert an access request expressed in a vehicle-independent format and transmitted from the service function block into a vehicle-dependent format, and a cooperation control unit (40) configured to realize cooperation between the control function block (35) configured to control the mounted vehicle. The cooperation control unit, A request transfer unit (S40) configured to transfer the access request transmitted from the service function block to the control function block, For each access request transmitted from the service function block, an access log indicating the execution status of the access request is created, and the created access log is stored in a preset first storage unit (4c). A log creation unit (S70) configured to store, Statistical processing is performed on the execution status of a plurality of the access requests to create a statistical access log indicating the result of the statistical processing, and the created statistical access log is stored in a preset second storage unit (4d). A statistical log creation unit (S100) configured to store, When a preset statistical transmission condition is satisfied, the statistical access log is transmitted to a server installed outside the vehicle and performing a charging process based on the statistical access log. A statistical transmission unit (S120, S130) configured to transmit, When data communication is possible with the server, a log transmission unit (S80, S90) configured to transmit the access log stored in the first storage unit to the server, A log deletion unit (S110, S112, S114) configured to delete the access log from the first storage unit when a preset log deletion condition is satisfied. An electronic control unit comprising the above.

[0210] [Item 13] A service providing system (1) including an electronic control unit (4) mounted on a vehicle and a server (3) configured to be capable of data communication with the electronic control unit, wherein the electronic control unit includes a cooperation control unit (40) configured to realize cooperation between a service system function block (33) configured to provide a service to a mounted vehicle, which is the vehicle on which the electronic control unit is mounted, and a control system function block (35) configured to control the mounted vehicle. The control system function block includes a function interface (37) configured to convert an access request transmitted from the service system function block and expressed in a vehicle-independent format into a vehicle-dependent format. The cooperation control unit includes a request transfer unit (S40) configured to transfer the access request transmitted from the service system function block to the control system function block, a log creation unit (S70) configured to create an access log indicating an execution status of the access request for each access request transmitted from the service system function block and store the created access log in a preset first storage unit (4c), a statistical log creation unit (S100) configured to perform statistical processing on execution statuses of a plurality of the access requests, create a statistical access log indicating a result of the statistical processing, and store the created statistical access log in a preset second storage unit (4d), and a statistical transmission unit (S120, S130) configured to transmit the statistical access log to the server installed outside the vehicle and performing a charging process based on the statistical access log when a preset statistical transmission condition is satisfied. When data communication with the server is possible, a log transmission unit (S80, S90) configured to transmit the access log stored in the first storage unit to the server; A log deletion unit (S110, S112, S114) configured to delete the access log from the first storage unit when a preset log deletion condition is satisfied; and The server is a service providing system configured to calculate an interface usage fee generated by the service system function block using the function interface, using the access log and the statistical access log created by the cooperation control unit.

Claims

1. An electronic control unit (4) mounted on a vehicle, comprising a cooperation control unit (40) configured to realize cooperation between a service system function block (33) configured to provide services to a mounting vehicle which is the vehicle on which the electronic control unit is mounted, and a control system function block (35) configured to control the mounting vehicle. The control system function block includes a function interface (37) configured to convert an access request expressed in a vehicle-independent format and transmitted from the service system function block into a vehicle-dependent format. The cooperation control unit includes a request transfer unit (S40) configured to transfer the access request transmitted from the service system function block to the control system function block, a log creation unit (S70) configured to create an access log indicating an execution status of the access request for each of the access requests transmitted from the service system function block, and store the created access log in a preset first storage unit (4c), a statistical log creation unit (S100) configured to perform statistical processing on execution statuses of a plurality of the access requests, create a statistical access log indicating a result of the statistical processing, and store the created statistical access log in a preset second storage unit (4d), a statistical transmission unit (S120, S130) configured to transmit the statistical access log to a server installed outside the vehicle and performing a charging process based on the statistical access log when a preset statistical transmission condition is satisfied, a log transmission unit (S80, S90) configured to transmit the access log stored in the first storage unit to the server when data communication is possible with the server, and a log deletion unit (S110, S112, S114) configured to delete the access log from the first storage unit when a preset log deletion condition is satisfied. The electronic control unit.

2. The electronic control unit according to Claim 1, wherein the statistical transmission condition is set to be a transmission interval longer than a transmission interval at which the log transmission unit transmits the access log to the server when data communication is possible with the server.

3. The electronic control unit according to Claim 1 or Claim 2, wherein the first storage unit includes a volatile memory.

4. The electronic control device according to claim 1 or claim 2, wherein the log deletion condition is that the access log to be deleted has been used for the statistical processing by the statistical log creation unit.

5. The electronic control device according to claim 1 or claim 2, wherein the log deletion condition is that the data amount of the access log stored in the first storage unit exceeds a preset deletion determination value.

6. The electronic control device according to claim 1 or claim 2, wherein the statistical access log includes the number of calls which is the number of times the service function block has transmitted the access request, the number of execution completions which is the number of times the process corresponding to the access request has been executed and completed, the number of unnecessary executions which is the number of times there was no need to execute the process corresponding to the access request, and the integrated value of the data amount acquired by the service function block when the process corresponding to the access request is executed, and includes at least one of them.

7. The electronic control device according to claim 1 or claim 2, wherein the log creation unit creates the access log indicating the execution status of the access request transferred by the request transfer unit.

8. The electronic control device according to claim 7, wherein the log creation unit further creates the access log indicating the execution status of the access request not transferred by the request transfer unit.

9. The electronic control device according to claim 1 or claim 2, wherein when the cooperation control unit receives an access request from a first service function block (SA1) configured to provide a service to the mounted vehicle to a second service function block (SA2) configured to provide a different service to the mounted vehicle from the first service function block, the cooperation control unit is configured to transmit the access request to the second service function block, the log creation unit creates the access log indicating the execution status of the access request transmitted to the second service function block, and the statistical log creation unit creates the statistical access log including the execution status of the access request transmitted to the second service function block.

10. A computer of the electronic control device, which is equipped with a cooperation control unit (40) configured to realize cooperation between a service system function block (33) configured to provide services to a vehicle equipped with the electronic control device (4), and a control system function block (35) configured to control the vehicle equipped with the above, and having a function interface (37) configured to convert an access request expressed in a vehicle-independent format and transmitted from the service system function block into a vehicle-dependent format. A request transfer unit (S40) configured to transfer the access request transmitted from the service system function block to the control system function block. A log creation unit (S70) configured to create an access log indicating the execution status of the access request for each access request transmitted from the service system function block, and store the created access log in a preset first storage unit (4c). A statistical log creation unit (S100) configured to execute statistical processing on the execution status of a plurality of the access requests, create a statistical access log indicating the result of the statistical processing, and store the created statistical access log in a preset second storage unit (4d). A statistical transmission unit (S120, S130) configured to transmit the statistical access log to a server installed outside the vehicle and performing charging processing based on the statistical access log when a preset statistical transmission condition is satisfied. A log transmission unit (S80, S90) configured to transmit the access log stored in the first storage unit to the server when data communication is possible with the server, and A log deletion unit (S110, S112, S114) configured to delete the access log from the first storage unit when a preset log deletion condition is satisfied. A management program for functioning as such.

11. A management method executed by the electronic control unit configured to realize cooperation between a service system function block (33) configured to provide services to a vehicle equipped with the electronic control unit (4) and a control system function block (35) configured to control the vehicle equipped with the electronic control unit, the control system function block including a function interface (37) configured to convert an access request expressed in a form independent of the vehicle and transmitted from the service system function block into a form dependent on the vehicle, the management method comprising: transferring the access request transmitted from the service system function block to the control system function block; creating an access log indicating the execution status of the access request for each access request transmitted from the service system function block, and storing the created access log in a preset first storage unit (4c); performing statistical processing on the execution statuses of a plurality of the access requests to create a statistical access log indicating the result of the statistical processing, and storing the created statistical access log in a preset second storage unit (4d); transmitting the statistical access log to a server installed outside the vehicle and performing a charging process based on the statistical access log when a preset statistical transmission condition is satisfied; transmitting the access log stored in the first storage unit to the server when data communication with the server is possible; a management method for deleting the access log from the first storage unit when a preset log deletion condition is satisfied.

12. An electronic control unit (4) mounted on a vehicle, comprising: a service system function block (33) configured to provide services to the vehicle equipped with the electronic control unit, and a control system function block (35) configured to control the vehicle equipped with the electronic control unit, the control system function block including a function interface (37) configured to convert an access request expressed in a form independent of the vehicle and transmitted from the service system function block into a form dependent on the vehicle, and a cooperation control unit (40) configured to realize cooperation between the service system function block and the control system function block; the cooperation control unit includes: a request transfer unit (S40) configured to transfer the access request transmitted from the service system function block to the control system function block; For each of the access requests transmitted from the service function block, a log creation unit (S70) configured to create an access log indicating the execution status of the access request and store the created access log in a preset first storage unit (4c); A statistical log creation unit (S100) configured to perform statistical processing on the execution statuses of a plurality of the access requests, create a statistical access log indicating the result of the statistical processing, and store the created statistical access log in a preset second storage unit (4d); A statistical transmission unit (S120, S130) configured to transmit the statistical access log to a server installed outside the vehicle and performing charging processing based on the statistical access log when a preset statistical transmission condition is satisfied; A log transmission unit (S80, S90) configured to transmit the access log stored in the first storage unit to the server when data communication is possible with the server; A log deletion unit (S110, S112, S114) configured to delete the access log from the first storage unit when a preset log deletion condition is satisfied An electronic control device comprising the above.

13. A service providing system (1) comprising an electronic control device (4) mounted on a vehicle and a server (3) configured to be capable of data communication with the electronic control device, The electronic control device includes A cooperation control unit (40) configured to realize cooperation between a service function block (33) configured to provide a service to the vehicle on which the electronic control device is mounted and a control function block (35) configured to control the vehicle on which the electronic control device is mounted, The control function block includes A function interface (37) configured to convert an access request expressed in a vehicle-independent format and transmitted from the service function block into a vehicle-dependent format, The cooperation control unit includes A request transfer unit (S40) configured to transfer the access request transmitted from the service function block to the control function block; For each of the access requests transmitted from the service function block, a log creation unit (S70) configured to create an access log indicating the execution status of the access request and store the created access log in a preset first storage unit (4c); A statistical log creation unit (S100) configured to perform statistical processing on the execution status of the plurality of access requests, create a statistical access log indicating the result of the statistical processing, and store the created statistical access log in a preset second storage unit (4d); A statistical transmission unit (S120, S130) configured to transmit the statistical access log to the server that is installed outside the vehicle and performs billing processing based on the statistical access log when a preset statistical transmission condition is satisfied; A log transmission unit (S80, S90) configured to transmit the access log stored in the first storage unit to the server when data communication is possible with the server; A log deletion unit (S110, S112, S114) configured to delete the access log from the first storage unit when a preset log deletion condition is satisfied; comprising; The server is a service providing system configured to calculate an interface usage fee generated by the service system function block using the access log and the statistical access log created by the cooperation control unit by using the function interface.

Citation Information

Patent Citations

  • Traveling information provision support device for purchase object vehicle and its program

    JP2005044058A

  • Log data collection device, management method for log data, and program

    JP2015060275A

  • Vehicle and computing system

    JP2019079137A

  • API charging system and API charging management method

    JP2021174129A

  • Log management apparatus, and security attack detection and analysis system

    JP2022017889A

Cited By

  • Software usage status investigation system, software usage status investigation device, and software usage status investigation method

    JP7775416B1