SDN network system and SDN subcontroller

The SDN subcontroller in the SDN network system takes over control when the primary controller fails, reliably maintaining network communication by detecting abnormal states and switching control entities.

JP7764836B2Active Publication Date: 2025-11-06TOYOTA JIDOSHA KK
View PDF 4 Cites 0 Cited by

Patent Information

Application Number
JP2022175587
Authority / Receiving Office
JP · JP
Patent Type
Patents
Current Assignee / Owner
Filing Date
2022-11-01
Publication Date
2025-11-06
Estimated Expiration
2042-11-01

AI Technical Summary

Technical Problem

In SDN network systems, if the SDN controller enters an abnormal state, communication becomes impossible, necessitating a reliable method to determine and address this abnormality.

Method used

An SDN network system with an SDN subcontroller that takes over control of communication settings when the SDN controller fails to send a live notification within a specified period, triggered by a switch request from the SDN switch.

Benefits of technology

Ensures reliable determination of the SDN controller's abnormal state, allowing the SDN subcontroller to maintain network communication even if the primary controller fails, preventing unnecessary switches and ensuring prompt recovery.

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure 0007764836000001
    Figure 0007764836000001
  • Figure 0007764836000002
    Figure 0007764836000002
  • Figure 0007764836000003
    Figure 0007764836000003
Patent Text Reader

Abstract

To determine with high reliability that a software defined network (SDN) controller is in an abnormal state.SOLUTION: In step S71, a software defined network (SDN) controller executes survival notification processing. In the survival notification processing, the SDN controller transmits a first survival notification S1 to an SDN sub controller. In the survival notification processing, the SDN controller transmits a second survival notification S2 to an SDN switch. In step S93, the SDN switch performs switching request processing. In the switching request processing, the SDN switch transmits a switching request D1 indicating a request to switch a control main body of communication settings to the SDN sub controller, on the condition that the second survival notification S2 cannot be received within a first specified period. In step S84, the SDN sub controller executes switching processing to start controlling communication settings, on the condition that the first survival notification cannot be received within the first specified period and that the switching request D1 has been received.SELECTED DRAWING: Figure 4
Need to check novelty before this filing date? Find Prior Art

Description

[Technical Field]

[0001] The present invention relates to an SDN network system and an SDN subcontroller. [Background technology]

[0002] Patent Document 1 describes a Software Defined Network (SDN) network system that is capable of changing network communication settings. The SDN network system includes multiple SDN switches and an SDN controller that changes the settings of each SDN switch. [Prior art documents] [Patent documents]

[0003] [Patent Document 1] Japanese Patent Application Laid-Open No. 2017-169044 Summary of the Invention [Problem to be solved by the invention]

[0004] In the SDN network system described in Patent Document 1, if the SDN controller goes into an abnormal state, there is a risk that communication in the SDN network system will become impossible. Therefore, there is a need for a technology that can reliably determine whether the SDN controller is in an abnormal state. [Means for solving the problem]

[0005] In order to solve the above problem, one aspect of the present invention is an SDN network system for a vehicle comprising an SDN switch, an SDN controller that controls communication settings of the SDN switch, and an SDN subcontroller that can control the communication settings of the SDN switch, wherein the SDN controller executes a live notification process to send a live notification to the SDN switch and the SDN subcontroller indicating that it is functioning normally, the SDN switch executes a switch request process to send a switch request to the SDN subcontroller indicating a request to switch the control entity of the communication settings, on the condition that it is unable to receive the live notification within a predetermined specified period, and the SDN subcontroller executes a switch process to start control of the communication settings, on the condition that it is unable to receive the live notification within the specified period and that it has received the switch request.

[0006] In order to solve the above problem, one aspect of the present invention is an SDN subcontroller that can control the communication settings of an SDN switch instead of an SDN controller that controls the communication settings of the SDN switch, and that executes a switching process to start control of the communication settings under the condition that it cannot receive a survival notification from the SDN controller indicating that it is normal, and that it receives a switching request from the SDN switch indicating that it requests a switching of the control entity of the communication settings.

[0007] According to the above configurations, the SDN subcontroller is aware that the SDN controller has entered an abnormal state through both communication with the SDN switch and communication with the SDN controller. Therefore, it can reliably determine that the SDN controller is in an abnormal state. Even if the SDN controller enters an abnormal state, the SDN subcontroller can control the communication settings of the SDN switch. [Brief explanation of the drawings]

[0008] [Figure 1]FIG. 1 is a schematic diagram showing a communication system. [Figure 2] FIG. 2 is a schematic diagram showing a vehicle control device. [Figure 3] FIG. 3 is a diagram showing the flow of a series of processes for updating via OTA. [Figure 4] FIG. 4 is a diagram showing the flow of a series of processes for switching the control entity. [Figure 5] FIG. 5 is a diagram showing the flow of signals for switching the control entity. DETAILED DESCRIPTION OF THE INVENTION

[0009] (One embodiment) An embodiment of an SDN network system will be described below. The following describes a communication system including a vehicle having an SDN network system and a server, with reference to the drawings.

[0010] <Communication System Overview> 1, the communication system 10 includes a plurality of vehicles 20 and a server 30. Each vehicle 20 includes a vehicle control device 21, a communication device 22, and an operation terminal 23. The vehicle control device 21 controls each device of the vehicle 20. Details of the vehicle control device 21 will be described later.

[0011] The communication device 22 is connected to the server 30 via an external communication network 40. The external communication network 40 is a wireless communication network such as a mobile phone network. Therefore, the vehicle 20 and the server 30 can communicate information with each other via the external communication network 40.

[0012] The operation terminal 23 is a terminal operated by a user of the vehicle 20. The operation terminal 23 is, for example, a touch display. The operation terminal 23 displays an image showing information input from the vehicle control device 21. The operation terminal 23 also inputs information shown by operation by the user to the vehicle control device 21.

[0013] Although not shown, the server 30 has a CPU and a ROM. The CPU of the server 30 executes a program stored in the ROM. This causes the server 30 to transmit campaign information and a distribution package to the vehicle 20.

[0014] <Vehicle control device overview> As shown in Fig. 2, the vehicle control device 21 includes a master ECU 21A and a plurality of physical ECUs 21B. The master ECU 21A and each physical ECU 21B are connected via a communication line. Although not shown, the master ECU 21A and each physical ECU 21B each include a CPU and a ROM. These ECUs execute programs stored in the ROM. The physical ECU 21B controls hardware devices connected to each physical ECU 21B. The hardware devices include, for example, an engine, a brake, and a motor.

[0015] The master ECU 21A has an SDN network system 50. The SDN network system 50 includes an SDN controller 51, an SDN sub-controller 52, and a plurality of SDN switches 53.

[0016] The SDN controller 51 controls the communication settings of each SDN switch 53. Specifically, the SDN controller 51 determines a data communication path on the network of the SDN network system 50. The SDN controller 51 determines a new data communication path, for example, when a new physical ECU 21B is connected. In other words, the SDN controller 51 dynamically controls the communication settings. The SDN controller 51 also transmits route information indicating the data communication path to each SDN switch 53. In this way, the SDN controller 51 centrally manages the communication settings of each SDN switch 53. The SDN controller 51 also transmits data to be transferred by the SDN switch 53.

[0017] Similar to the SDN controller 51, the SDN sub - controller 52 can control the communication settings of each SDN switch 53. And the SDN sub - controller 52 can control the data communication path on the network of the SDN network system 50 instead of the SDN controller 51. Note that the SDN sub - controller 52 may be a device of the same type as the SDN controller 51, or it may be a device with other functions in addition to the communication setting control function.

[0018] The SDN switch 53 performs data transfer on the network of the SDN network system 50. Specifically, based on the path information received from the SDN controller 51, it updates the rules for data transfer stored in its own flow table. And the SDN switch 53 transfers the data received from the SDN controller 51 to the appropriate physical ECU 21B based on the updated rules.

[0019] Also, the SDN controller 51 can execute a download process to download updated software from a server 30 outside the vehicle 20. And the SDN controller 51 installs and activates the updated software downloaded in the download process. Through these series of processes, the SDN controller 51 can execute new updated software.

[0020] <Regarding a series of processes about OTA> The server 30 transmits campaign information to the communication device 22 of the vehicle 20. When the communication device 22 of the vehicle 20 receives the campaign information, the communication device 22 outputs the campaign information to the vehicle control device 21. When the campaign information is input, the vehicle control device 21 executes an update program by OTA (Over The Air). Note that the campaign information is information indicating an event for performing software update on the vehicle 20 in the market.

[0021] As shown in FIG. 3, when the vehicle control device 21 starts a series of processes for an OTA update program, it first performs the process of step S11. In step S11, the vehicle control device 21 requests approval for installation of the update software from the user of the vehicle 20. Specifically, the vehicle control device 21 outputs an installation approval message to the operation terminal 23 indicating whether or not installation is permitted. The installation approval message is, for example, a message that asks, "Do you want to apply the new software?" Then, the vehicle control device 21 proceeds to the process of step S12.

[0022] On the other hand, after an installation consent message is input from the vehicle control device 21, when the user performs an operation indicating consent, the operation terminal 23 executes an installation consent processing program. When the operation terminal 23 starts the installation consent processing program, it performs step S30. In step S30, the operation terminal 23 executes the installation consent processing. In the installation consent processing, the operation terminal 23 outputs information indicating the user's consent to the vehicle control device 21. As a result, the operation terminal 23 terminates the installation consent processing program.

[0023] In step S12, the vehicle control device 21 determines whether or not consent has been given. The vehicle control device 21 determines whether or not consent has been given based on whether or not information indicating the user's consent has been input from the operation terminal 23. When information indicating the user's consent has not been input from the operation terminal 23 (S12: NO), the vehicle control device 21 repeats the processing of step S12. On the other hand, when information indicating the user's consent has been input from the operation terminal 23 (S12: YES), the vehicle control device 21 proceeds to the processing of step S13.

[0024] In step S13, the vehicle control device 21 performs a distribution package transmission request process. In the distribution package transmission request process, the vehicle control device 21 transmits information indicating a request for a distribution package to the server 30 via the communication device 22. Thereafter, the vehicle control device 21 proceeds to step S14.

[0025] On the other hand, when information indicating a distribution package request is input from the communication device 22, the server 30 executes a distribution package transmission program. When the distribution package transmission program starts, the server 30 performs step S40. In step S40, the vehicle control device 21 transmits the distribution package to the communication device 22. This causes the server 30 to terminate the distribution package transmission program.

[0026] In step S14, the vehicle control device 21 determines whether the communication device 22 has downloaded the distribution package. If the communication device 22 has not downloaded the distribution package (S14: NO), the vehicle control device 21 repeats the process of step S14. On the other hand, if the communication device 22 has downloaded the distribution package (S14: YES), the vehicle control device 21 proceeds to step S15.

[0027] In step S15, the vehicle control device 21 installs the distribution package downloaded by the communication device 22. The distribution package is a series of data sets transferred from the server 30 to the vehicle 20 at one time. In addition to the update software itself, the distribution package includes display information for an HMI (Human Machine Interface), package information, security information, and the like. The distribution package also includes network information for the SDN network system 50. That is, the distribution package includes communication settings for each SDN controller 51. When the vehicle control device 21 downloads the distribution package, the SDN controller 51 downloads the communication settings for each SDN switch 53 in the distribution package. When the vehicle control device 21 installs the update software in the distribution package, the SDN controller 51 installs the communication settings for each SDN switch 53 in the distribution package. After that, the vehicle control device 21 proceeds to step S16.

[0028] In step S16, the vehicle control device 21 requests the user of the vehicle 20 to consent to the activation of the installed update software. Specifically, the vehicle control device 21 outputs to the operation terminal 23 an activation consent message indicating whether or not activation is permitted. The activation consent message is, for example, a message stating, "The update will take approximately XX minutes, and you will not be able to restart the vehicle during that time. Is this OK?" The vehicle control device 21 then proceeds to step S17.

[0029] On the other hand, after an activation consent message is input from the vehicle control device 21, when the user performs an operation indicating consent, the operation terminal 23 executes an activation consent processing program. When the operation terminal 23 starts the activation consent processing program, it performs step S50. In step S50, the operation terminal 23 executes activation consent processing. In the activation consent processing, the operation terminal 23 outputs information indicating the user's consent to the vehicle control device 21. As a result, the operation terminal 23 terminates the activation consent processing program.

[0030] In step S17, the vehicle control device 21 determines whether or not consent has been given. The vehicle control device 21 determines whether or not consent has been given based on whether or not information indicating the user's consent has been input from the operation terminal 23. When information indicating the user's consent has not been input from the operation terminal 23 (S17: NO), the vehicle control device 21 repeats the processing of step S17. On the other hand, when information indicating the user's consent has been input from the operation terminal 23 (S17: YES), the vehicle control device 21 proceeds to the processing of step S18.

[0031] In step S18, the vehicle control device 21 activates the installed update software. As a result, the vehicle control device 21 becomes able to control the vehicle 20 based on the information of the activated update software. Furthermore, when the vehicle control device 21 activates the update software, the SDN controller 51 activates new communication settings of each SDN switch 53. Thereafter, the vehicle control device 21 proceeds to step S19.

[0032] In step S19, the vehicle control device 21 performs an update completion process. In the update completion process, the vehicle control device 21 outputs, to the operation terminal 23, information indicating that the software update based on the current campaign information has been completed. Specifically, the vehicle control device 21 outputs, to the operation terminal 23, an update completion message indicating that the software update has been completed. The update completion message is, for example, a message stating, "Update to new software has been completed." Thereafter, the vehicle control device 21 proceeds to step S20.

[0033] On the other hand, after the update completion message is input from the vehicle control device 21, when the user performs an operation indicating confirmation, the operation terminal 23 executes a confirmation processing program. When the operation terminal 23 starts the confirmation processing program, it performs step S60. In step S60, the operation terminal 23 executes the confirmation processing. In the confirmation processing, the operation terminal 23 outputs information indicating that the user has confirmed to the vehicle control device 21. As a result, the operation terminal 23 ends the confirmation processing program.

[0034] In step S20, the vehicle control device 21 determines whether confirmation has been made. The vehicle control device 21 determines whether confirmation has been made based on whether information indicating that the user has confirmed has been input from the operation terminal 23. When information indicating that the user has confirmed has not been input from the operation terminal 23 (S20: NO), the vehicle control device 21 repeats the processing of step S20. On the other hand, when information indicating that the user has confirmed has been input from the operation terminal 23 (S20: YES), the vehicle control device 21 ends the series of processes.

[0035] <About switching of control entity> As described above, when the vehicle control device 21 activates update software based on campaign information, the SDN controller 51 updates the communication settings of each SDN switch 53. Then, when the SDN controller 51 updates the communication settings of each SDN switch 53, the vehicle control device 21 executes the SDN controller switching program stored in the ROM.

[0036] 4, when the vehicle control device 21 starts the SDN controller switching program, the SDN controller 51 performs step S71. In step S71, the SDN controller 51 performs an alive notification process. In the alive notification process, the SDN controller 51 transmits an alive notification to the SDN switch 53 and the SDN sub-controller 52, indicating that the SDN controller 51 is functioning normally.

[0037] As shown in Figure 5, when these alive notifications are distinguished based on their destination, the alive notification sent to the SDN subcontroller 52 is referred to as the first alive notification S1, and the alive notification sent to the SDN switch 53 is referred to as the second alive notification S2.

[0038] The SDN controller 51 ends the alive notification process after sending the first alive notification S1 to the SDN subcontroller 52 and the second alive notification S2 to the SDN switch 53. At this time, the SDN controller 51 also sends the second alive notification S2 to all SDN switches 53 in the SDN network system 50.

[0039] Furthermore, as described above, when the vehicle control device 21 activates update software based on campaign information, the vehicle control device 21 executes the SDN sub-controller switching program stored in the ROM.

[0040] 4, when the vehicle control device 21 starts the SDN sub-controller switching program, the SDN sub-controller 52 first executes the process of step S81. In step S81, the SDN sub-controller 52 executes sub-alive notification processing. In the sub-alive notification processing, the SDN sub-controller 52 transmits an active notification to the SDN switch 53, indicating that the SDN sub-controller 52 is functioning normally. Thereafter, the SDN sub-controller 52 proceeds to the process of step S82.

[0041] As shown in FIG. 5, when distinguishing from the first alive notification S1 and the second alive notification S2 in the above-mentioned alive notification processing, the alive notification sent from the SDN subcontroller 52 to the SDN switch 53 is referred to as the third alive notification S3.

[0042] In step S82, the SDN subcontroller 52 determines whether or not the first alive notification S1 has been received. Specifically, the SDN subcontroller 52 waits to receive the first alive notification S1 for a first specified period from the time when the vehicle control device 21 activates the update software based on the campaign information. That is, the SDN subcontroller 52 waits to receive the first alive notification S1 for a first specified period from the time when the SDN controller 51 executes the alive notification process. Then, if the first alive notification S1 is received within the first specified period (S82: YES), the SDN subcontroller 52 ends this series of processes. On the other hand, if the first alive notification S1 is not received within the first specified period (S82: NO), the SDN subcontroller 52 proceeds to step S83.

[0043] Incidentally, when the vehicle control device 21 activates the updated software based on the campaign information, the vehicle control device 21 executes the SDN switch switching program stored in the ROM.

[0044] When the vehicle control device 21 starts the SDN switch switching program, the SDN switch 53 first executes the process of step S91. Note that the following process is executed in parallel by all SDN switches 53. In step S91, the SDN switch 53 determines whether or not it has received the second alive notification S2. Specifically, the SDN switch 53 waits to receive the second alive notification S2 for a first specified period from the time when the vehicle control device 21 activates the update software based on the campaign information. In other words, the SDN switch 53 waits to receive the second alive notification S2 for a first specified period from the time when the SDN controller 51 executes the alive notification process. Then, when the second alive notification S2 is received within the first specified period (S91: YES), the SDN switch 53 ends the current series of processes. On the other hand, when the second alive notification S2 is not received within the first specified period (S91: NO), the SDN switch 53 advances the process to step S92.

[0045] In step S92, the SDN switch 53 determines whether or not the third alive notification S3 has been received. Specifically, the SDN switch 53 waits for a second specified period from the time when the vehicle control device 21 activates the update software based on the campaign information to receive the third alive notification S3. The second specified period is, for example, the same period as the first specified period described above. If the third alive notification S3 has not been received within the second specified period (S92: NO), the SDN switch 53 ends this series of processes. On the other hand, if the third alive notification S3 has been received within the second specified period (S92: YES), the SDN switch 53 proceeds to step S93.

[0046] In step S93, the SDN switch 53 performs a switching request process. In the switching request process, the SDN switch 53 transmits a switching request D1 indicating a request to switch the control entity of its own communication settings to the SDN subcontroller 52. Thereafter, the SDN switch 53 ends this series of processes.

[0047] Meanwhile, after processing step S82, the SDN subcontroller 52 executes processing step S83. In step S83, the SDN subcontroller 52 determines whether or not a majority of switching requests D1 have been received. Specifically, after processing step S82, the SDN subcontroller 52 waits for a predetermined third specified period to receive switching requests D1. Then, the SDN subcontroller 52 calculates the number of switching requests D1 received during the third specified period. Next, the SDN subcontroller 52 compares the number of received switching requests D1 with the number of SDN switches 53 in the SDN network system 50. Then, the SDN subcontroller 52 determines whether or not the number of received switching requests D1 is a majority of the SDN switches 53.

[0048] In this way, when it is determined that the majority of the switching requests D1 have not been received (S83: NO), the SDN subcontroller 52 ends the current series of processes. On the other hand, when it is determined that the majority of the switching requests D1 have been received (S83: YES), the process proceeds to step S84.

[0049] In step S84, the SDN subcontroller 52 performs a switching process. In the switching process, the SDN subcontroller 52 starts controlling the communication settings of the SDN switch 53. That is, the SDN subcontroller 52 performs the switching process on the condition that it has not received the second presence notification S2 during the first specified period and that it has received a switching request D1. Particularly in this embodiment, as a result of the switching process, the SDN subcontroller 52 becomes the main controller of communication settings of all SDN switches 53, instead of the SDN controller 51. Furthermore, once the SDN subcontroller 52 starts controlling the communication settings of the SDN switch 53, the SDN switch 53 no longer accepts control from the SDN controller 51. Thereafter, the SDN subcontroller 52 ends the series of processes.

[0050] (Operation of the embodiment) According to the above embodiment, in the SDN network system 50, the SDN controller 51 controls the communication settings of the SDN switch 53. However, when an OTA software update is activated, the settings and the like may change, causing the SDN controller 51 to be unable to function normally, i.e., to enter an abnormal state. At such a time, when certain conditions are met in the SDN network system 50, the control entity is switched to the SDN sub-controller 52.

[0051] (Effects of the embodiment) (1) According to the above embodiment, the SDN subcontroller 52 executes the switching process on the condition that it has not received the second status notification S2 within the first specified period and has received the switching request D1. Therefore, the SDN subcontroller 52 knows that the SDN controller 51 has stopped functioning normally through both communication with the SDN switch 53 and communication with the SDN controller 51. Therefore, it can reliably determine that the SDN controller 51 has stopped functioning normally. Even if the SDN controller 51 goes into an abnormal state, the SDN subcontroller 52 can still control the SDN network system 50.

[0052] (2) According to the above embodiment, the SDN subcontroller 52 executes the switching process on the condition that it has not received the second alive notification S2 and has received the switching request D1 from a majority of the SDN switches 53. In this situation where the switching request D1 is being sent from a majority of the SDN switches 53, it is unlikely that an abnormality has occurred in a specific SDN switch 53 and that the switching request D1 has been sent erroneously from that SDN switch 53. In other words, if the switching request D1 is being sent from a majority of the SDN switches 53, it is highly likely that an abnormality has occurred in the SDN controller 51. Therefore, the above switching process prevents the control entity of the SDN switch 53 from being unnecessarily switched to the SDN subcontroller 52.

[0053] (3) According to the above embodiment, the SDN controller 51 executes a status notification process when an OTA software update is activated. Therefore, in the SDN network system 50, a series of processes related to switching of the control entity is started promptly after the communication settings are updated. This prevents a long time from elapsed until the control entity is switched when the SDN controller 51 goes into an abnormal state due to the communication settings being updated.

[0054] (4) According to the above embodiment, the SDN switch 53 performs the switching request process on the condition that the third alive notification S3 is received. That is, the SDN switch 53 transmits the switching request D1 when the SDN subcontroller 52 is functioning normally. This prevents the control entity of the SDN switch 53 from being switched to an SDN subcontroller 52 that is in an abnormal state.

[0055] (Other embodiments) The above embodiment can be modified as follows: The above embodiment and the following modifications can be combined with each other within the scope of technical compatibility.

[0056] <About switching of control entity> In the above embodiment, the condition for the SDN subcontroller 52 to execute the switching process is that it has received switching requests D1 from a majority of the SDN switches 53, but this is not limited to this. For example, the SDN subcontroller 52 may execute the switching process on the condition that it has received switching requests D1 from a predetermined number of SDN switches 53 or more. In this case, the predetermined number is not limited to half the number of SDN switches 53. Specifically, when the number of SDN switches 53 is 10, the predetermined number may be 2.

[0057] Furthermore, for example, in the heartbeat notification process, the SDN controller 51 transmits to the SDN subcontroller 52, separately from the second heartbeat notification S2, information indicating the number of controlled switches, which is the number of SDN switches 53 being controlled by the SDN controller 51. In this case, the SDN subcontroller 52 may execute the switching process when the following three conditions are satisfied. The first condition is that the second heartbeat notification S2 is not received within a first specified period. The second condition is that a switching request D1 is received from at least one SDN switch 53. The third condition is that the number of controlled switches is smaller than a predetermined specified number, which is a value smaller than the total number of SDN switches 53. The specified number is, for example, half of the SDN switches 53. In this case, the SDN subcontroller 52 executes the switching process on the condition that the number of SDN switches 53 being controlled by the SDN controller 51 among the multiple SDN switches 53 is smaller than the specified number. In other words, the SDN subcontroller 52 starts control when the SDN controller 51 can control less than half of the multiple SDN switches 53. Therefore, it is possible to reliably determine an abnormal state in which the SDN controller 51 can control only some of the SDN switches 53. In such an abnormal state, the control entity can be switched to the SDN subcontroller 52.

[0058] Furthermore, for example, in the heartbeat notification process, the SDN controller 51 transmits to the SDN subcontroller 52 information indicating an ID that identifies the SDN switch 53 under the control of the SDN controller 51. In this case, the SDN subcontroller 52 may execute the switching process when the following three conditions are met. The first condition is that the second heartbeat notification S2 is not received within a first specified period. The second condition is that the switching request D1 is received. The third condition is that the ID of the SDN switch 53 that transmitted the received switching request D1 is not included in the information indicating the received ID. According to these conditions, when the SDN switch 53 transmits the switching request D1 and the SDN controller 51 is not controlling the SDN switch 53, the SDN subcontroller 52 executes the switching process. In other words, the SDN subcontroller 52 executes the switching process in response to the switching request D1 from an SDN switch 53 that the SDN controller 51 cannot control. Therefore, when the SDN controller 51 recognizes that it is not in control and the SDN switch 53 recognizes that it is not in control, the SDN sub-controller 52 executes the switching process. Therefore, it can be determined with higher reliability that the SDN controller 51 is not functioning normally.

[0059] Furthermore, as in the modified example described above, when a signal separate from the alive signal is transmitted during the alive notification process, the SDN subcontroller 52 may identify the number of controlled switches or their IDs based on the signal received during the previous alive notification process. If the SDN controller 51 enters an abnormal state, not only will it be unable to transmit the first alive notification S1 to the SDN subcontroller 52, but it may also be unable to transmit such a signal to the SDN subcontroller 52. Even in such a case, switching can be performed under the conditions described in the modified example described above.

[0060] Furthermore, for example, the switching process may be executed on the condition that the second presence notification S2 is not received and at least one switching request D1 is received. In other words, the number of received switching requests D1, the ID of the SDN controller 51 that sent the switching request D1, etc. may not be used as the execution condition for the switching process.

[0061] In the above embodiment, the SDN switch 53 executes the switching request process on the condition that the third alive notification S3 has been received, but the switching request process may be executed regardless of the third alive notification S3. In this case, the SDN sub-controller 52 does not need to execute the sub alive notification process.

[0062] In the above embodiment, when the SDN subcontroller 52 executes the switching process, the SDN subcontroller 52 becomes the control entity of all the SDN switches 53. However, this is not limited to this. For example, among the SDN switches 53, only the control entity of the SDN switch 53 that sent the switching request D1 may be switched to the SDN subcontroller 52. Also, for example, the SDN subcontroller 52 may exchange the switching request D1 with each of the multiple SDN switches 53. That is, the SDN switch 53 performs the switching request process by associating the switching request D1 with information indicating an ID unique to the SDN switch 53 itself. In this case, when the SDN subcontroller 52 receives the switching request D1, it may execute the switching process only for the SDN switch 53 having the ID associated with the switching request D1.

[0063] Furthermore, for example, when the SDN switch 53 receives the switching request D1, the SDN switch 53 may permit switching of the control entity to the SDN subcontroller 52 on the condition that the second alive notification S2 has not been received.

[0064] <When to start the series of processes for switching the control entity> The timing at which the SDN controller 51 starts executing the SDN controller switching program is not limited to the timing triggered by an OTA software update. For example, the SDN controller 51 may execute the presence notification process when the vehicle 20 is powered on. While the vehicle 20 is powered off, a hardware device may be newly connected or changed. Therefore, by executing the SDN controller switching program when the vehicle 20 is powered on, the control entity of the SDN switch 53 may be changed before the vehicle 20 starts moving.

[0065] Furthermore, for example, the SDN controller 51 may execute the alive notification process upon receiving a signal for switching an electronic control unit (ECU) included in the vehicle 20 to a drivable state. The ECU 21B may be, for example, the physical ECU 21B. The physical ECU 21B is in a non-drivable state when the vehicle 20 is shipped. However, after the vehicle 20 leaves the warehouse, the physical ECU 21B may be switched to a drivable state by a dealer or the like, for example, upon payment of an additional fee. In such a case, communication settings may be changed by newly operating the physical ECU 21B. Therefore, upon receiving a signal for switching the physical ECU 21B to a drivable state from a dealer or the like, the SDN controller 51 executes an SDN controller switching program. As a result, when the new physical ECU 21B is woken up, the control entity of the SDN switch 53 may be changed. Note that the signal for switching the ECU to a drivable state may also be referred to as, for example, a wake-up signal.

[0066] Furthermore, for example, when the SDN controller 51 detects that a new hardware device has been connected to the vehicle control device 21, the SDN controller 51 may execute the presence notification process. Furthermore, for example, the SDN controller 51 may periodically execute the alive notification process at a predetermined frequency. By periodically executing the alive notification process, it is possible to periodically detect whether the SDN controller 51 is functioning normally. The frequency may be set to, for example, once an hour.

[0067] <Other> The vehicle 20 is not limited to being a component of the communication system 10. As in the above-described modified example, the vehicle 20 is not limited to being subjected to an OTA software update, and the vehicle control device 21 may execute each switching program.

[0068] The vehicle control device 21 may be configured as a circuit including one or more processors that execute various processes according to a computer program (software). The vehicle control device 21 may also be configured as a circuit including one or more dedicated hardware circuits, such as an application-specific integrated circuit (ASIC), that execute at least some of the various processes, or a combination thereof. The processor includes a CPU and memory such as RAM and ROM. The memory stores program code or instructions configured to cause the CPU to execute processes. The memory, i.e., computer-readable medium, includes any available medium that can be accessed by a general-purpose or dedicated computer. [Explanation of symbols]

[0069] 10. Communication Systems 20...Vehicle 21...Vehicle control device 21A...Master ECU 21B…Physical ECU 22...Communication equipment 23...Operation terminal 30...Server 50...SDN network system 51...SDN controller 52...SDN subcontroller 53...SDN switch

Claims

1. An SDN network system for a vehicle, comprising: an SDN switch; an SDN controller that controls communication settings of the SDN switch; and an SDN sub-controller that can control the communication settings of the SDN switch, The SDN controller executes a heartbeat notification process to send heartbeat notifications to the SDN switch and the SDN sub-controller, indicating that the SDN controller is functioning normally; the SDN switch executes a switching request process to transmit a switching request indicating a request to switch the control entity of the communication setting to the SDN subcontroller, on the condition that the alive notification cannot be received within a predetermined specified period; The SDN subcontroller executes a switching process to start controlling the communication settings on the condition that the heartbeat notification is not received within the specified period and the switching request is received. SDN network system.

2. a plurality of the SDN switches; In the alive notification process, the SDN controller transmits, to the SDN subcontroller, information indicating the number of controlled switches, which is the number of the SDN switches being controlled by the SDN controller, separately from the alive notification; The SDN subcontroller executes the switching process under the conditions that the alive notification cannot be received within the specified period, that the switching request has been received from at least one of the SDN switches, and that the number of controlled switches is smaller than a predetermined specified number that is a value smaller than the total number of the SDN switches. The SDN network system according to claim 1 .

3. a plurality of the SDN switches; In the alive notification process, the SDN controller transmits, to the SDN subcontroller, information indicating an ID that identifies the SDN switch being controlled by the SDN controller, separately from the alive notification; The SDN subcontroller executes the switching process under the conditions that the alive notification cannot be received within the specified period, the switching request has been received, and the ID of the SDN switch that has transmitted the received switching request is not included in the information indicating the received ID. The SDN network system according to claim 1 .

4. a plurality of the SDN switches; The SDN subcontroller executes the switching process on the condition that the alive notification is not received within the specified period and the switching request is received from a majority of the SDN switches. The SDN network system according to claim 1 .

5. The SDN controller executes the presence notification process when the power supply of the vehicle is turned on. The SDN network system according to any one of claims 1 to 4.

6. The SDN controller executes the alive notification process when it receives a signal for switching an electronic control unit provided in the vehicle to a drivable state. The SDN network system according to any one of claims 1 to 4.

7. The SDN controller is capable of executing a download process for downloading update software from a server external to the vehicle; The SDN controller executes the presence notification process when the updated software downloaded in the download process is activated. The SDN network system according to any one of claims 1 to 4.

8. The SDN controller periodically executes the heartbeat notification process at a predetermined frequency. The SDN network system according to any one of claims 1 to 4.

9. An SDN subcontroller capable of controlling communication settings of the SDN switch in place of an SDN controller that controls communication settings of the SDN switch, A switching process for starting control of the communication settings is executed on the condition that an alive notification indicating that the SDN controller itself is normal is not received from the SDN controller, and a switching request indicating a request to switch the control entity of the communication settings is received from the SDN switch. SDN subcontroller.

Citation Information

Patent Citations

  • Communication system and service restoration method in communication system

    JP2015138987A

  • Setting device, communication system, method for setting update of communication device, and program

    JP2017169044A

  • Multi-master selection in software-defined networks

    JP2017502627A

  • Multi-Master Selection in a Software Defined Network

    US20150195162A1