Information processing device

The information processing device with a hypervisor allows for analyzing virtual machines in an in-vehicle system by generating a second virtual machine to analyze the first without affecting its operation, maintaining resource allocation, and ensuring real-time performance.

JP7779237B2Active Publication Date: 2025-12-03TOYOTA JIDOSHA KK
View PDF 8 Cites 0 Cited by

Patent Information

Application Number
JP2022188680
Authority / Receiving Office
JP · JP
Patent Type
Patents
Current Assignee / Owner
Filing Date
2022-11-25
Publication Date
2025-12-03
Estimated Expiration
2042-11-25

AI Technical Summary

Technical Problem

Existing techniques for analyzing virtual machines in an in-vehicle system do not allow for analysis to be performed while the virtual machine is operating in the same manner as before, leading to potential disruptions in real-time performance.

Method used

An information processing device with a hypervisor that generates a first virtual machine and a second virtual machine, allocating resources to the first machine and securing an allocation area for the second machine, allowing the second machine to analyze the first machine without straining its resources, and maintaining resource allocation to the first machine during analysis.

Benefits of technology

Enables analysis of virtual machines in an in-vehicle system without disrupting the operation of the first virtual machine, ensuring real-time performance and flexible analysis capabilities.

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure 0007779237000001
    Figure 0007779237000001
  • Figure 0007779237000002
    Figure 0007779237000002
  • Figure 0007779237000003
    Figure 0007779237000003
Patent Text Reader

Abstract

To have an analysis done in a situation in which a virtual machine of an analysis target is working during an analysis in the same manner as the virtual machine was working before the analysis.SOLUTION: An information processor includes: a generation unit for generating a first virtual machine and a second virtual machine for analyzing the first virtual machine; and a control unit for allocating a part of a predetermined resource to the first virtual machine generated by the generation unit and securing an allocation region to allocate to the second virtual machine when the generation unit generates the second virtual machine, in the predetermined resource.SELECTED DRAWING: Figure 1
Need to check novelty before this filing date? Find Prior Art

Description

[Technical Field]

[0001] The present disclosure relates to an information processing device. [Background technology]

[0002] Patent Document 1 discloses a microcomputer that can be debugged without preparing a debugging program. [Prior art documents] [Patent documents]

[0003] [Patent Document 1] Japanese Patent Publication No. 2020-107206 Summary of the Invention [Problem to be solved by the invention]

[0004] The technology of Patent Document 1 sets a virtual machine specialized for debugging as a debug virtual machine, but there is a problem. In case, There is still room for improvement in techniques for analyzing virtual machines.

[0005] Therefore, an object of the present disclosure is to provide an information processing device that can perform analysis in a situation where a virtual machine to be analyzed is operating in the same way as before the analysis. [Means for solving the problem]

[0006] An information processing device according to claim 1 includes: a generation unit capable of generating a first virtual machine and a second virtual machine for analyzing the first virtual machine; and a control unit that allocates a part of predetermined resources to the first virtual machine generated by the generation unit, and secures an allocation area in the predetermined resources to be allocated to the second virtual machine when the second virtual machine is generated by the generation unit. The first virtual machine and the second virtual machine are virtual machines mounted on an in-vehicle system, and when the generation unit acquires a diagnostic code indicating a failure of a predetermined part of the vehicle, the generation unit determines that there is a predetermined malfunction and generates a unique second virtual machine corresponding to the acquired diagnostic code, and when a predetermined time has elapsed since the start of analysis, the generation unit determines that an analysis result obtained by the second virtual machine corresponding to the first diagnostic code analyzing the first virtual machine is insufficient, deletes the second virtual machine generated immediately before, and generates a new second virtual machine corresponding to a second or third different diagnostic code based on the analysis result, and the control unit maintains the amount of the predetermined resources allocated to the first virtual machine even when the generation unit generates the second virtual machine, and the predetermined resources include CPU resources and storage resources, and the control unit allocates, as the CPU resources, a CPU allocation time for each Major Time Frame, which is a predetermined periodic time unit, to the first virtual machine, and allocates, as the storage resources, a portion of storage capacity to the first virtual machine, and when the generation unit generates the second virtual machine, The allocated area is secured in accordance with the CPU allocation time to be allocated to the second virtual machine for each frame, and the allocated area is secured in the storage in accordance with the capacity to be allocated to the second virtual machine. During the allocated CPU allocation time, the second virtual machine performs analysis processing to analyze the first virtual machine, including processing to prepare for analysis such as reading specified data from the first virtual machine and writing specified data to the first virtual machine, processing to actually perform the analysis by analyzing the read data and monitoring the operation of the first virtual machine that wrote the data, and processing based on the access rights granted to the second virtual machine. The information processing device of claim 2 is, in claim 1, wherein the generation unit generates a plurality of the first virtual machines, the plurality of first virtual machines being a virtual machine for body control, a virtual machine for engine control, and a virtual machine for autonomous driving control, and the control unit grants the second virtual machine access authority to the first virtual machine that is to be analyzed among the plurality of first virtual machines.

[0007] In the information processing device according to claim 1, the generation unit is capable of generating a first virtual machine and a second virtual machine for analyzing the first virtual machine. The control unit allocates a portion of predetermined resources to the first virtual machine generated by the generation unit, and reserves an allocation area in the predetermined resources to be allocated to the second virtual machine when the second virtual machine is generated by the generation unit. As a result, in the information processing device, when the second virtual machine is generated, the allocation area reserved in the predetermined resources can be allocated to the second virtual machine, without putting a strain on the predetermined resources allocated to the first virtual machine. Therefore, in the information processing device, it is possible to have the second virtual machine perform analysis while the first virtual machine to be analyzed is operating in the same manner as before the analysis.

[0009] Claim 1 In the information processing device according to the present invention, the generation unit generates a second virtual machine when a predetermined malfunction occurs. This allows the information processing device to cause the second virtual machine to analyze the predetermined malfunction.

[0011] Claim 1 In the information processing device according to the present invention, the control unit maintains the amount of the predetermined resources allocated to the first virtual machine even when the generation unit generates the second virtual machine, thereby allowing the first virtual machine to use part of the allocated predetermined resources during analysis in the same way as before analysis.

[0013] Claim 1 In the information processing device according to the present invention, the first virtual machine and the second virtual machine are virtual machines installed in an in-vehicle system. As a result, the information processing device can have the second virtual machine perform analysis while ensuring real-time performance of the in-vehicle system by having the first virtual machine use similar resources before and during analysis.

[0015] Claim 1In the information processing device according to the present invention, when the analysis result of the second virtual machine analyzing the first virtual machine is insufficient, the generation unit generates a new second virtual machine based on the analysis result, thereby allowing the information processing device to continue analysis by the second virtual machine until the analysis result is sufficient. [Effects of the Invention]

[0016] As described above, the information processing apparatus according to the present disclosure can perform analysis in a state where the virtual machine to be analyzed is operating in the same manner as before the analysis. [Brief explanation of the drawings]

[0017] [Figure 1] 1 is a block diagram showing a schematic configuration of a vehicle according to an embodiment of the present invention; [Figure 2] FIG. 2 is a block diagram showing the functional configuration of a hypervisor according to the present embodiment. [Figure 3] 10 is a flowchart showing the flow of a first process performed in the central ECU. [Figure 4] 10 is a flowchart showing the flow of a second process performed in the central ECU. [Figure 5] FIG. 10 is a diagram illustrating an example of allocation of CPU allocation time to VMs before a second virtual machine is generated. [Figure 6] FIG. 10 is a diagram illustrating an example of allocation of CPU allocation time to VMs after a second virtual machine is generated. DETAILED DESCRIPTION OF THE INVENTION

[0018] Hereinafter, a vehicle 10 according to this embodiment will be described with reference to the drawings. FIG. 1 is a block diagram showing a schematic configuration of a vehicle 10 according to this embodiment.

[0019] 1, a vehicle 10 is equipped with a central ECU (Electronic Control Unit) 20. The central ECU 20 is an example of an "information processing device."

[0020] The central ECU 20 is an ECU that comprehensively controls various ECUs provided in the vehicle 10. The central ECU 20 includes a CPU (Central Processing Unit) 22 and a Hypervisor 24. Although not shown, the central ECU 20 also includes other components such as a ROM (Read Only Memory), a RAM (Random Access Memory), and storage.

[0021] The CPU 22 is a central processing unit that executes various programs and controls each part. That is, the CPU 22 reads a program from a ROM or storage and executes the program using the RAM as a work area.

[0022] The hypervisor 24 is software for virtualizing a computer. The hypervisor 24 virtualizes the CPU 22 to generate a VM (Virtual Machine) 26. In this embodiment, the hypervisor 24 generates a plurality of VMs 26. FIG. 1 shows an example in which three VMs 26, VM0, VM1, and VM2, are generated by the hypervisor 24.

[0023] The hypervisor 24 allocates predetermined resources to each VM 26, making it appear as if the VMs 26 are operating in parallel. The predetermined resources include CPU 22 resources and storage resources. One example of the CPU 22 resources is CPU allocation time. One example of the storage resources is capacity and the maximum number of rewrites allowed for the storage.

[0024] Next, a description will be given of the functional configuration of the hypervisor 24. Fig. 2 is a block diagram showing the functional configuration of the hypervisor 24 according to this embodiment.

[0025] As shown in FIG. 2, the hypervisor 24 has the functions of a generation unit 24A and a control unit 24B.

[0026] The generation unit 24A is capable of generating a plurality of VMs 26. Specifically, the generation unit 24A is capable of generating, as the plurality of VMs 26, a first virtual machine to be analyzed and a second virtual machine for analyzing the first virtual machine. The first virtual machine and the second virtual machine are virtual machines installed in the in-vehicle system of the vehicle 10. The first virtual machine is, for example, a body control virtual machine, an engine control virtual machine, an autonomous driving control virtual machine, etc. Note that the first virtual machine realized in the central ECU 20 is not limited to this, and may be a virtual machine for other purposes.

[0027] Here, the generation unit 24A generates a second virtual machine when a predetermined malfunction occurs. Specifically, the generation unit 24A generates a second virtual machine when it acquires predetermined information or receives a predetermined operation, etc., assuming that a predetermined malfunction has occurred. For example, the generation unit 24A may generate a second virtual machine when it acquires, as the predetermined information, from an external device via a network, information that a malfunction has occurred due to a virtual machine of the same type as the first virtual machine it generated. Furthermore, the generation unit 24A may generate a second virtual machine when it acquires, as the predetermined information, malfunction information indicating a malfunction of a predetermined part of the vehicle 10. The malfunction information is, for example, a diagnostic code. Then, the generation unit 24A generates a unique second virtual machine according to the content of the malfunction that has occurred, for example, the acquired diagnostic code.

[0028] Furthermore, if the analysis result of the second virtual machine analyzing the first virtual machine is insufficient, the generation unit 24A generates a new second virtual machine based on the analysis result. Specifically, if a malfunction is not identified even after a predetermined time has elapsed since the start of the analysis, or if a predetermined operation has been received, the generation unit 24A generates a new second virtual machine as the analysis result is insufficient. For example, if the generation unit 24A has generated a second virtual machine according to a first diagnostic code but the analysis result by the second virtual machine is insufficient, the generation unit 24A generates a new second virtual machine according to another diagnostic code, such as a second or third diagnostic code.

[0029] The control unit 24B allocates a portion of predetermined resources to the first virtual machine generated by the generation unit 24A. For example, the control unit 24B allocates the CPU allocation time for each Major Time Frame to the first virtual machine as a resource of the CPU 22. The control unit 24B also allocates a portion of the storage capacity to the first virtual machine as a storage resource.

[0030] Furthermore, the control unit 24B secures an allocation area in a predetermined resource to be allocated to the second virtual machine when the second virtual machine is generated by the generation unit 24A. For example, the control unit 24B secures an allocation area according to the CPU allocation time to be allocated to the second virtual machine for each Major Time Frame, and secures an allocation area in storage according to the capacity to be allocated to the second virtual machine.

[0031] Here, even if the second virtual machine is generated by the generation unit 24A, the control unit 24B maintains the amount of the predetermined resources allocated to the first virtual machine.

[0032] 3 is a flowchart showing the flow of a first process performed by the central ECU 20. The process in FIG. 3 is performed, for example, during product development of the vehicle 10.

[0033] 3, the hypervisor 24 generates a first virtual machine. Then, the hypervisor 24 proceeds to step S11. As an example, the hypervisor 24 generates a plurality of first virtual machines.

[0034] In step S11, the hypervisor 24 allocates a portion of predetermined resources to the first virtual machine created in step S10. Then, the hypervisor 24 proceeds to step S12.

[0035] In step S12, the hypervisor 24 secures an allocation area to be allocated to the second virtual machine in a predetermined resource when the second virtual machine is generated, and then the hypervisor 24 ends the processing of FIG.

[0036] Fig. 4 is a flowchart showing the flow of a second process performed by the central ECU 20. The process in Fig. 4 is performed when an ignition switch (not shown) or the like is operated to turn on the power of the vehicle 10.

[0037] 4, if a predetermined malfunction has occurred (step S20: YES), the hypervisor 24 proceeds to step S21. On the other hand, if a predetermined malfunction has not occurred (step S20: NO), the hypervisor 24 waits until a predetermined malfunction has occurred.

[0038] In step S21, the hypervisor 24 generates a second virtual machine, and then the hypervisor 24 proceeds to step S22.

[0039] In step S22, the hypervisor 24 allocates to the second virtual machine the predetermined resources secured in the allocation area in step S12 of Fig. 3. Then, the hypervisor 24 proceeds to step S23.

[0040] In step S23, the hypervisor 24 installs the second virtual machine generated in step S21 into the VM 26. As a result, the VM 26 is configured from the first virtual machine and the second virtual machine. The hypervisor 24 then proceeds to step S24. As an example, the hypervisor 24 installs the second virtual machine into the VM 26 by reprogramming. The hypervisor 24 also grants the second virtual machine installed in the VM 26 access authority to the first virtual machine to be analyzed.

[0041] In step S24, if the analysis result obtained by the second virtual machine analyzing the first virtual machine is sufficient (step S24: YES), the hypervisor 24 ends the processing in Fig. 4. On the other hand, if the analysis result is insufficient (step S24: NO), the hypervisor 24 returns to step S21.

[0042] 4 is completed, the malfunction is corrected based on the analysis result by the second virtual machine. The malfunction may be corrected manually or automatically by the central ECU 20 or the like.

[0043] Furthermore, when the process returns from step S24 to step S21, in step S21, the hypervisor 24 deletes the second virtual machine that was created immediately before, and creates a new second virtual machine based on the analysis result.

[0044] Next, an example of allocation of a predetermined resource to the VM 26 before and after the generation of the second virtual machine will be described. An example of allocation of CPU allocation time as a predetermined resource will be described below.

[0045] Fig. 5 is a diagram showing an example of allocation of CPU time allocation to the VM 26 before the second virtual machine is generated. In Fig. 5, the Major Time Frame is set to 1000 µs.

[0046] 5, three first virtual machines VM0, VM1, and VM2 are generated by the hypervisor 24 as the multiple VMs 26. In addition, in FIG. 5, 250 μs is allocated as CPU allocation time to each of the three first virtual machines VM0, VM1, and VM2 in each Major Time Frame.

[0047] 5, an allocation region R is secured for allocation to the second virtual machine for each major time frame. The allocation region R is the region indicated by the dashed line in the figure, and a CPU allocation time of 250 μs is secured, which is calculated by subtracting the 750 μs allocated to the first virtual machine from the major time frame of 1000 μs.

[0048] FIG. 6 is a diagram showing an example of allocation of CPU allocation time to the VM 26 after the second virtual machine is generated.

[0049] 6, a second virtual machine VM3 is generated by the hypervisor 24, and together with VM0, VM1, and VM2, constitutes a plurality of VMs 26. In FIG. 6, similar to before the second virtual machine was generated, 250 μs is allocated as CPU allocation time to each of the three first virtual machines VM0, VM1, and VM2 in each Major Time Frame.

[0050] 6, the second virtual machine VM3 is assigned 250 μs of CPU time allocated in the allocated area R (see FIG. 5) before VM3 is created. VM3 then executes an analysis process to analyze the first virtual machine during the allocated CPU time. The analysis process includes a preparatory process for analysis, such as reading predetermined data from the first virtual machine and writing predetermined data to the first virtual machine, and an actual analysis process, such as analyzing the read data and monitoring the operation of the first virtual machine that wrote the data.

[0051] As described above, in the central ECU 20 according to this embodiment, the hypervisor 24 can generate a first virtual machine and a second virtual machine for analyzing the first virtual machine. The hypervisor 24 allocates a portion of predetermined resources to the generated first virtual machine and reserves an allocation area in the predetermined resources to be allocated to the second virtual machine when the second virtual machine is generated. This allows the central ECU 20 to allocate the allocation area reserved in the predetermined resources to the second virtual machine when the second virtual machine is generated, without putting pressure on the predetermined resources allocated to the first virtual machine. Therefore, the central ECU 20 can cause the second virtual machine to perform analysis while the first virtual machine to be analyzed is operating in the same manner as before the analysis.

[0052] Furthermore, in the central ECU 20 according to this embodiment, the hypervisor 24 generates a second virtual machine when a predetermined malfunction occurs. This allows the central ECU 20 to have the second virtual machine analyze the predetermined malfunction. Furthermore, by generating a second virtual machine when a predetermined malfunction occurs, the central ECU 20 can have the second virtual machine perform flexible analysis according to the malfunction.

[0053] In the central ECU 20 according to this embodiment, the hypervisor 24 maintains the amount of the predetermined resources allocated to the first virtual machine even when the second virtual machine is generated. Furthermore, all information, such as code, required for analysis is allocated to the second virtual machine, so there is no need to change the program of the first virtual machine. These separation functions of the hypervisor 24 allow the central ECU 20 to use a portion of the allocated predetermined resources during analysis, just as they did before analysis.

[0054] Furthermore, in the central ECU 20 according to this embodiment, the first virtual machine and the second virtual machine are virtual machines installed in the in-vehicle system. This allows the central ECU 20 to have the first virtual machine use the same resources before and during analysis, ensuring real-time performance of the in-vehicle system, while having the second virtual machine perform analysis. It is desirable to analyze a malfunction of the in-vehicle system without changing the behavior of the analysis target before and during analysis, and to perform the analysis in the same state as when the malfunction occurred. In contrast, with the above configuration, the central ECU 20 allows the second virtual machine to perform analysis when analyzing a malfunction of the in-vehicle system, while the first virtual machine, which is the analysis target, is operating in the same state as before the analysis.

[0055] In the central ECU 20 according to this embodiment, if the analysis result of the second virtual machine analyzing the first virtual machine is insufficient, the hypervisor 24 generates a new second virtual machine based on the analysis result. This allows the central ECU 20 to continue analysis by the second virtual machine until the analysis result is sufficient.

[0056] (others) In the above embodiment, in each Major Time Frame, the same CPU allocation time is allocated to each of the three first virtual machines VM0, VM1, and VM2. However, this is not limiting, and the CPU allocation time allocated to each of the multiple first virtual machines may be different.

[0057] In the above embodiment, the same CPU time allocation is allocated to each first virtual machine and the second virtual machine in each major time frame. However, this is not limiting, and the CPU time allocation allocated to each first virtual machine and the second virtual machine may be different.

[0058] In the above embodiment, in each Major Time Frame, the allocated area R is secured after the CPU allocation time allocated to each first virtual machine. However, the location where the allocated area R is secured is not limited to this, and the allocated area R can be secured at any location, such as before the CPU allocation time allocated to each first virtual machine or between the CPU allocation times allocated to each first virtual machine.

[0059] In the above embodiment, the analysis process by the second virtual machine is exemplified as reading predetermined data from the first virtual machine and writing predetermined data to the first virtual machine. However, the analysis process is not limited to this, and various processes can be performed based on the access authority granted to the second virtual machine.

[0060] In the above embodiment, the program for executing the processing performed by the hypervisor 24 may be pre-stored (installed) in the ROM or storage of the central ECU 20, or may be provided in a form recorded on a recording medium such as a CD-ROM (Compact Disk Read Only Memory), a DVD-ROM (Digital Versatile Disk Read Only Memory), or a USB (Universal Serial Bus) memory. Moreover, the above program may be downloaded from an external device via a network. [Explanation of symbols]

[0061] 20 Central ECU (information processing unit) 24A generation section 24B Control section

Claims

1. a generating unit capable of generating a first virtual machine and a second virtual machine for analyzing the first virtual machine; a control unit that allocates a portion of a predetermined resource to the first virtual machine generated by the generation unit, and that, when the second virtual machine is generated by the generation unit, secures an allocation area in the predetermined resource to be allocated to the second virtual machine; Equipped with the first virtual machine and the second virtual machine are virtual machines installed in an in-vehicle system, The generation unit When a diagnostic code indicating a failure of a predetermined part of the vehicle is acquired, it is determined that a predetermined malfunction has occurred, and the second virtual machine is generated uniquely according to the acquired diagnostic code; If a malfunction is not identified even after a predetermined time has elapsed since the start of the analysis, the analysis result obtained by the second virtual machine corresponding to the first diagnostic code analyzing the first virtual machine is deemed to be insufficient, and the second virtual machine generated immediately before is deleted, and a new second virtual machine corresponding to a second or third different diagnostic code is generated based on the analysis result; the control unit maintains the amount of the predetermined resources allocated to the first virtual machine even when the second virtual machine is generated by the generation unit; the predetermined resources include CPU resources and storage resources, The control unit Allocating a CPU allocation time for each Major Time Frame, which is a preset periodic time unit, to the first virtual machine as the CPU resource, and allocating a portion of a storage capacity to the first virtual machine as the storage resource; When the second virtual machine is generated by the generation unit, the allocation area according to the CPU allocation time to be allocated to the second virtual machine for each Major Time Frame is secured, and the allocation area according to the capacity to be allocated to the second virtual machine is secured in the storage; During the allocated CPU allocation time, the second virtual machine performs the following analysis processes for analyzing the first virtual machine: a process for preparing for analysis, such as reading predetermined data from the first virtual machine and writing predetermined data to the first virtual machine; a process for actually performing analysis, such as analyzing the read data and monitoring the operation of the first virtual machine that has written the data; and a process based on the access authority granted to the second virtual machine. Information processing device.

2. The generation unit generates a plurality of the first virtual machines, the plurality of first virtual machines are a body control virtual machine, an engine control virtual machine, and an autonomous driving control virtual machine; the control unit grants the second virtual machine access authority to the first virtual machine that is an analysis target among the plurality of first virtual machines; The information processing device according to claim 1 .

Citation Information

Patent Citations

  • Computer system and method for coping with performance disorder of computer system

    JP2016139237A

  • Assignment of resource in virtual machine pool

    JP2018055707A

  • Electronic control unit and electronic control system

    JP2019185130A

  • Microcomputer, debug information output method, and debug system

    JP2020107206A

  • On-vehicle computer, on-vehicle communication system, computer execution method, and computer program

    JP2020173561A