Priority determination system, priority determination method, and program

The system dynamically adjusts task priorities by monitoring and recalculating risk values based on updated situation data, addressing the issue of static priority assignments in existing systems.

JP7811069B2Active Publication Date: 2026-02-04PANASONIC AUTOMOTIVE SYST CO LTD
View PDF 5 Cites 0 Cited by

Patent Information

Application Number
JP2022172040
Authority / Receiving Office
JP · JP
Patent Type
Patents
Current Assignee / Owner
Filing Date
2022-10-27
Publication Date
2026-02-04
Estimated Expiration
2042-10-27

AI Technical Summary

Technical Problem

Existing priority determination systems fail to account for changes in the status of mobile objects after initial data acquisition, leading to inaccurate task priority assignments.

Method used

A system that continuously monitors the status of mobile objects and recalculates risk values and task priorities based on updated situation data, incorporating a priority determination unit and a status change notification management unit to ensure accurate task prioritization.

Benefits of technology

Enables dynamic adjustment of task priorities in response to changes in the status of mobile objects, ensuring timely and effective handling of anomalies.

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure 0007811069000004
    Figure 0007811069000004
  • Figure 0007811069000005
    Figure 0007811069000005
  • Figure 0007811069000006
    Figure 0007811069000006
Patent Text Reader

Abstract

To provide a priority determination system capable of appropriately determining priorities of tasks in accordance with changes in a state of movable body.SOLUTION: A priority determination system 10 comprises: an abnormality acquisition unit 11 for acquiring a plurality of pieces of abnormal data; a state acquisition unit 12 for acquiring a plurality of pieces of state data; a risk value calculation unit 14 for calculating a risk value; a priority determination unit 15 for determining a priority for each task on the basis of the risk value; an output unit 17 for performing output on the basis of a result of the determination; and a state change notification management unit 16 for determining whether or not each of the plurality of pieces of abnormal data is state change notification target data. The state change notification management unit 16 requests a movable body 100 corresponding to an abnormal data piece determined as the state change notification target data to notify post-change state data. The risk value calculation unit 14 re-calculates a risk value on the basis of the post-change state data. The priority determination unit 15 re-determines a priority of the task on the basis of the re-calculated risk value.SELECTED DRAWING: Figure 1
Need to check novelty before this filing date? Find Prior Art

Description

[Technical Field]

[0001] The present disclosure relates to a priority determination system, a priority determination method, and a program. [Background technology]

[0002] Prior art priority determination systems have been disclosed that calculate a risk value for an abnormality based not only on the content of the abnormality in a mobile object but also on the status of the mobile object, and determine the priority of tasks for dealing with the abnormality based on this risk value (for example, Patent Document 1). For example, even if the same attack is carried out on multiple mobile objects, the risk value will differ depending on the status of the attacked mobile object, i.e., the priority of tasks determined based on the risk value will also differ, making it easier to determine which task should be executed for which abnormality in which mobile object. [Prior art documents] [Patent documents]

[0003] [Patent Document 1] Patent Publication No. 2021-149260 Summary of the Invention [Problem to be solved by the invention]

[0004] However, the priority determination system disclosed in the above-mentioned Patent Document 1 does not assume that the risk value will be revised even if a change in the status of the mobile object occurs after the status data of the mobile object has been acquired. For example, if the mobile object's driving status is "stopped" when an abnormality occurs, a low risk value is calculated, and the priority of the task to deal with the abnormality is determined to be low, and the task is placed in a waiting state for assignment to an analyst. Then, suppose the driving status of the mobile object changes to "driving." In this case, the risk of the abnormality increases, but the priority of the task remains low, and the task remains in a waiting state for assignment to an analyst.

[0005] Therefore, the present disclosure provides a priority determination system and the like that can appropriately determine the priority of a task in accordance with changes in the situation of a moving object. [Means for solving the problem]

[0006] A priority determination system according to one aspect of the present disclosure includes an abnormality acquisition unit that acquires a plurality of abnormality data indicating an abnormality for each of a plurality of moving bodies, a situation acquisition unit that acquires a plurality of situation data indicating a situation for each of the plurality of moving bodies, a risk value calculation unit that calculates a risk value indicating a risk of an abnormality for each of the plurality of abnormality data based on the situation data for the corresponding moving body, a priority determination unit that determines a priority for each task to deal with an abnormality indicated by each of the plurality of abnormality data based on the risk value for each of the plurality of abnormality data, an output unit that outputs based on the result of the determination, and a priority determination unit that determines a priority for each of the plurality of abnormality data for the corresponding moving body. and a situation change notification management unit that determines whether the abnormal data is data that requires notification of the changed situation data when a change in situation occurs, and the situation change notification management unit requests the mobile body corresponding to the abnormal data that has been determined to be data that requires notification of the changed situation data when a change in situation occurs, and when the changed situation data is obtained, the risk value calculation unit recalculates the risk value of the abnormal data of the corresponding mobile body based on the changed situation data, and the priority determination unit re-determines the priority of the task to deal with the abnormality indicated by the abnormal data of the corresponding mobile body based on the recalculated risk value.

[0007] Furthermore, a priority determination method according to one aspect of the present disclosure includes the steps of: acquiring a plurality of abnormality data indicating abnormalities for each of a plurality of moving bodies; acquiring a plurality of situation data indicating the status of each of the plurality of moving bodies; calculating a risk value indicating the risk of an abnormality for each of the plurality of abnormality data based on the situation data of the corresponding moving body; determining a priority for each task for dealing with the abnormality indicated by each of the plurality of abnormality data based on the risk value for each of the plurality of abnormality data; outputting based on the results of the determination; determining whether each of the plurality of abnormality data is situation change notification target data that requires the corresponding moving body to notify the changed situation data if a change in status occurs; requesting the moving body corresponding to the abnormality data determined to be situation change notification target data to notify the changed situation data if a change in status occurs; when the changed situation data is acquired, recalculating the risk value for the abnormality data for the corresponding moving body based on the changed situation data; and re-determining the priority of the task for dealing with the abnormality indicated by the abnormality data of the corresponding moving body based on the recalculated risk value.

[0008] A program according to one aspect of the present disclosure is a program for causing a computer to execute the priority determination method described above. [Effects of the Invention]

[0009] A priority determination system according to an aspect of the present disclosure can appropriately determine the priority of a task in accordance with changes in the status of a moving object. [Brief explanation of the drawings]

[0010] [Figure 1] 1 is a configuration diagram illustrating an example of a priority determination system according to an embodiment. [Figure 2] FIG. 10 is a diagram illustrating an example of an incident management table for each mobile object. [Figure 3] FIG. 2 is a sequence diagram showing an example of the flow of operations between the priority determination system and a moving body according to an embodiment. [Figure 4] 10 is a flowchart illustrating an example of an operation of the priority determination system according to the embodiment. [Figure 5] FIG. 10 is a diagram illustrating an example of abnormality data and situation data. [Figure 6] FIG. 10 is a diagram illustrating an example of vehicle model information. [Figure 7] FIG. 10 is a diagram showing an example of a magnification for each situation data item for correcting a basic risk value. [Figure 8] FIG. 10 is a diagram illustrating an example of status change notification target data. [Figure 9] 10 is a flowchart illustrating an example of an operation of a moving body in the embodiment regarding a situation change notification. [Figure 10] FIG. 10 is a diagram for explaining a method for determining a change in a situation for each item of the situation. [Figure 11] 10 is a flowchart showing an example of an operation of the priority determination system in the embodiment when in a status change notification standby state. DETAILED DESCRIPTION OF THE INVENTION

[0011] (Embodiment) Hereinafter, a priority determination system according to an embodiment will be described with reference to the drawings.

[0012] Fig. 1 is a configuration diagram showing an example of a priority determination system 10 according to an embodiment. Fig. 1 also shows a mobile object 100 (e.g., an automobile) communicatively connected to the priority determination system 10, and a display 201 and a keyboard 202 used by an analyst or the like who deals with anomalies. Note that there are multiple mobile objects 100 communicatively connected to the priority determination system 10, but Fig. 1 shows only one mobile object 100.

[0013] Each of the multiple mobile bodies 100 that are communicatively connected to the priority determination system 10 is a vehicle such as an automobile equipped with an in-vehicle network such as a CAN (Controller Area Network), and is a connected car that is capable of wireless communication with the priority determination system 10, etc.

[0014] The mobile object 100 includes an abnormality notification unit 101 and a situation notification unit 102. For example, when an abnormality such as an external attack, fraud, or failure occurs in the in-vehicle network or an ECU (Electronic Control Unit) connected to the in-vehicle network, the abnormality notification unit 101 transmits abnormality data indicating the abnormality to the priority determination system 10. Note that the abnormality notification unit 101 may transmit log data in the in-vehicle network to an abnormality detection server or the like that detects abnormalities, and the abnormality data indicating the abnormality detected based on the log data may be transmitted from the abnormality detection server or the like to the priority determination system 10. Furthermore, the situation notification unit 102 transmits situation data indicating its own situation to the priority determination system 10. For example, the situation notification unit 102 may transmit situation data to the priority determination system 10 constantly or at specific timings. Furthermore, as will be described in detail later, the situation notification unit 102 has a function of transmitting situation data after a change in its own situation to the priority determination system 10.

[0015] An analyst monitors the mobile object 100 using a terminal such as a security operation center (SOC). For example, the terminal collects anomaly information from multiple mobile objects 100 (e.g., hundreds or thousands), analyzes the anomaly when it is detected, and notifies a security incident response team (SIRT) or the like. For example, the terminal is capable of using software such as security information and event management (SIEM). The priority determination system 10 is expected to function as a server system in conjunction with a SIEM or security orchestration automation and response (SOAR). As described below, the priority determination system 10 outputs to the terminal a result of determining the priority of a task for dealing with anomalies. The analyst can effectively execute a task from among the numerous tasks for dealing with anomalies occurring in numerous mobile objects 100 in accordance with the output. The terminal is capable of wired or wireless communication with the priority determination system 10. For example, a display 201 and a keyboard 202 are connected to the terminal.

[0016] The priority determination system 10 is a computer, such as a server, for determining the priority of tasks performed by an analyst. The priority determination system 10 includes a processor, a memory, a communication interface, and the like. The memory may be a read-only memory (ROM) or a random access memory (RAM), and may store a program executed by the processor. The priority determination system 10 includes an abnormality acquisition unit 11, a status acquisition unit 12, an incident management unit 13, a risk value calculation unit 14, a priority determination unit 15, a status change notification management unit 16, an output unit 17, and an input unit 18. The abnormality acquisition unit 11, the status acquisition unit 12, the incident management unit 13, the risk value calculation unit 14, the priority determination unit 15, the status change notification management unit 16, the output unit 17, and the input unit 18 are realized by a processor or the like that executes a program stored in memory. The components constituting the priority determination system 10 may be distributed across multiple servers.

[0017] The abnormality acquisition unit 11 acquires a plurality of abnormality data. Each of the plurality of abnormality data indicates an abnormality in each of the plurality of moving objects 100. For example, the abnormality acquisition unit 11 acquires the plurality of abnormality data from the plurality of moving objects 100 (or an abnormality detection server, etc.) via a communication interface, etc., provided in the priority determination system 10.

[0018] The situation acquisition unit 12 acquires multiple pieces of situation data. Each piece of situation data indicates the situation of each of the multiple mobile objects 100. For example, the situation acquisition unit 12 acquires the multiple pieces of situation data from the multiple mobile objects 100, a roadside device, a server, or the like via a communication interface or the like provided in the priority determination system 10. For example, each piece of situation data includes at least one of the following information: type information indicating the type (e.g., vehicle type) of the mobile object 100; location information indicating the location of the mobile object 100; traffic information at a location corresponding to the location information; driving state information indicating the driving state of the mobile object 100; driving assistance state information indicating the driving assistance state of the mobile object 100; and charging / discharging state information indicating the charging / discharging state of the mobile object 100. For example, the situation acquisition unit 12 may acquire the location information, driving state information, driving assistance state information, and charging / discharging state information from the mobile object 100, or may acquire type information or anomaly occurrence status (e.g., prevalent attacks) managed by the server from a server, or may acquire traffic information at a location where an anomaly occurred in the mobile object 100 from a roadside device. Each of the plurality of situation data may be a combination of the above information with information from other servers or the like.

[0019] The incident management unit 13 manages the multiple abnormality data and situation data acquired by the abnormality acquisition unit 11 and the situation acquisition unit 12. For example, the incident management unit 13 manages the abnormality data and situation data for each mobile body 100. Furthermore, for example, the incident management unit 13 manages the risk values ​​calculated by the risk value calculation unit 14 (described later) in association with the corresponding abnormality data.

[0020] FIG. 2 is a diagram showing an example of an incident management table for each mobile object 100. As shown in FIG.

[0021] 2, the incident management unit 13 manages the abnormality type, driving state, location, driving assistance state, charging / discharging state, vehicle type, and risk value for each mobile unit 100 in an incident management table. For example, the incident management unit 13 manages that, for mobile unit A, an abnormality in the driving dysfunction system has occurred, the mobile unit is driving, located in an urban area, is in a semi-automated driving state, is not charging / discharging, is vehicle type A, and the risk value of the abnormality in the driving dysfunction system in the current situation of mobile unit A is 800. Also, for example, the incident management unit 13 manages that, for mobile unit B, an abnormality in the theft system has occurred, the mobile unit is stopped, located in an urban area, is in a manual driving state, is charging, is vehicle type B, and the risk value of the abnormality in the theft system in the current situation of mobile unit B is 400.

[0022] The risk value calculation unit 14 calculates a risk value indicating the risk of an abnormality for each of the multiple abnormality data based on the situation data of the corresponding mobile object 100. For example, the risk value calculation unit 14 calculates the risk value based on the abnormality data (e.g., abnormality type) and situation data (e.g., driving state, location, driving assistance state, charge / discharge state, and vehicle type) in an incident management table such as that shown in FIG. 2, which is managed by the incident management unit 13. For example, the risk value calculation unit 14 calculates the risk value each time abnormality data or situation data is acquired. Details of the risk value calculation unit 14 will be described later.

[0023] The priority determination unit 15 determines the priority of each task for dealing with an abnormality indicated by each of the plurality of abnormal data based on the risk value of each of the plurality of abnormal data. For example, the priority determination unit 15 determines the priority of each task based on the risk value of each of the plurality of abnormal data and a predetermined index value for each task, such as at least one of the rate at which risk is reduced by executing each task and the time required to execute each task. For example, the priority determination unit 15 determines the priority of each task based on the risk value of each of the plurality of abnormal data and the predetermined index values ​​for each task, such as the rate at which risk is reduced by executing each task and the time required to execute each task. Details of the priority determination unit 15 will be described later. Note that the predetermined index value for each task may also be a value indicating the load on each task or a value indicating the degree of impact on risk. For example, the priority determination unit 15 performs the above determination periodically, each time a task is executed, each time an abnormality is detected, or each time a risk value is calculated.

[0024] Although not shown, the priority determination system 10 may store rules used by the risk value calculation unit 14 when calculating risk values ​​and rules used by the priority determination unit 15 when determining priorities. Details of these rules will be described later.

[0025] Although not shown, the priority determination system 10 may also store a correspondence between anomalies indicated by each of the plurality of anomaly data and one or more tasks for dealing with the anomalies. The priority determination system 10 may also store, for each task, the proportion of risk that will be reduced by performing the task (also referred to as the risk value allocation rate) and the expected response time required to complete the task. These details will be described later.

[0026] The status change notification management unit 16 determines whether or not each of the plurality of abnormal data is status change notification target data that requires notification of changed status data in the event of a change in status to the corresponding mobile object 100. Details of the status change notification management unit 16 will be described later.

[0027] The output unit 17 outputs to a terminal such as an SOC (such as a display 201) based on the result of the priority determination by the priority determination unit 15. The output unit 17 transmits the result of the priority determination to the terminal such as an SOC via a communication interface or the like provided in the priority determination system 10. Details of the output from the output unit 17 will be described later.

[0028] Information that the abnormality has been dealt with (in other words, that a task for dealing with the abnormality has been executed) is input to the input unit 18 via a terminal (such as the keyboard 202) of an SOC or the like. The input unit 18 acquires information that the abnormality has been dealt with via a communication interface or the like provided in the priority determination system 10.

[0029] Next, the flow of operations between the priority determination system 10 and the moving object 100 will be described with reference to FIG.

[0030] 3 is a sequence diagram showing an example of the flow of operations between the priority determination system 10 according to the embodiment and the moving object 100. Here, moving objects A and B are shown as the moving objects 100.

[0031] First, a plurality of moving objects 100 including moving objects A and B each transmit abnormality data and situation data to the priority determination system 10 (steps S101A and S101B). As a result, the priority determination system 10 acquires a plurality of abnormality data and a plurality of situation data.

[0032] Next, the priority determination system 10 uses the acquired plurality of abnormality data and plurality of situation data to calculate a risk value, determine the priority, and determine whether or not a situation change notification is required (step S102).

[0033] Next, the priority determination system 10 outputs the result of the priority determination to the display 201 (step S103), which allows the analyst to execute tasks starting from the highest priority.

[0034] Next, the priority determination system 10 transmits a request to start status change notification (also called a status change notification start request) to the moving body 100 (e.g., moving body A) that requires status change notification (step S104). As a result, moving body A transitions to a state in which it monitors status changes (also called a status change monitoring state).

[0035] When the moving object A detects the occurrence of a change in the situation (step S105), it notifies the priority determination system 10 of the change in the situation (step S106).

[0036] Next, the priority determination system 10 recalculates the risk value using the notified changed situation data, and re-determines the priority (step S107).

[0037] Next, the priority determination system 10 outputs the result of the re-determined priority determination to the display 201 (step S108). For example, if the priority of a task that was low at the time of step S103 becomes high, the analyst can execute the task with priority.

[0038] When the handling of the incident (abnormality) of the moving object A is completed (step S109), for example, when the input unit 18 receives an input indicating that the handling of the incident of the moving object A is completed, the priority determination system 10 transmits a request to the moving object A to stop the status change notification (also referred to as a status change notification stop request) (step S110). As a result, the moving object A cancels the status change monitoring state.

[0039] If there is another change in the status of the mobile object A before the incident of the mobile object A is dealt with in step S109, the process is repeated from step S105.

[0040] Next, the operation of the priority determination system 10 will be described with reference to FIG.

[0041] FIG. 4 is a flowchart showing an example of the operation of the priority determination system 10 according to the embodiment.

[0042] First, the abnormality acquisition unit 11 acquires a plurality of abnormality data items indicating abnormalities in each of the plurality of moving objects 100 (step S11). For example, there are many moving objects 100 monitored by a terminal such as a SOC, and accordingly, the abnormality acquisition unit 11 acquires a large amount of abnormality data items.

[0043] Next, the status acquisition unit 12 acquires a plurality of status data indicating the status of each of the plurality of moving objects 100 (step S12). For example, there are many moving objects 100 monitored by a terminal such as a SOC, and accordingly, the status acquisition unit 12 acquires a large amount of status data. Specific examples of the abnormality data and the status data will be described with reference to FIG. 5.

[0044] 5 is a diagram showing an example of abnormality data and situation data, which are acquired from a moving body A among the plurality of moving bodies 100. In FIG.

[0045] For example, as shown in Fig. 5, the abnormality data acquired from mobile body A includes information indicating an abnormality of the type "Driving Function Impairment System" designated as "XXXX." Furthermore, the situation data acquired from mobile body A includes information indicating, for example, that the driving state of mobile body A at the time the abnormality occurred was "driving," the location was an "urban area," the driving assistance state was "semi-autonomous driving," the charging / discharging state was "not charging / discharging," and the type (vehicle type) was "vehicle type A."

[0046] Fig. 6 is a diagram showing an example of information about vehicle types, where (a) of Fig. 6 is a diagram showing an example of information about vehicle type A, and (b) of Fig. 6 is a diagram showing an example of information about vehicle type B.

[0047] As shown in Figure 6(a), "Vehicle Type A" is a vehicle with a market volume of 5,000 units, a vehicle with an estimated damage amount in the event of a problem that is less than the previous period's profits, and a vehicle used for business purposes. As shown in Figure 6(b), "Vehicle Type B" is a vehicle with a market volume of 20,000 units, a vehicle with an estimated damage amount in the event of a problem that is greater than the previous period's profits, and a vehicle used for home use.

[0048] Next, the risk value calculation unit 14 calculates an abnormality risk value for each of the multiple abnormality data based on the situation data of the corresponding mobile object 100 (step S13). For example, the risk value calculation unit 14 first determines a basic risk value for each of the multiple abnormality data. The basic risk value is a value calculated according to the type of abnormality, and can be determined (e.g., calculated) using, for example, a score value obtained by SIEM or a score value obtained by CTI (Cyber ​​Threat Intelligence). The risk value calculated by the risk value calculation unit 14 is, for example, a value obtained by correcting the basic risk value determined according to the type of abnormality using the situation data of the corresponding mobile object 100. For example, the larger the risk value obtained by correcting the basic risk value, the greater the risk of the abnormality. Here, the magnification for correcting the basic risk value will be described with reference to FIG. 7.

[0049] Fig. 7 is a diagram showing an example of a magnification for each situation data for correcting the basic risk value. Note that Fig. 7(b) shows the magnification of the situation data indicating the situation of the item subject to situation change notification. The item subject to situation change notification will be described later.

[0050] For example, as shown in Figure 7(a), the priority determination system 10 stores a rule that corrects the basic risk value of an abnormality occurring in a mobile body 100 of a vehicle type with a "market volume of less than 1,000 vehicles" by 1.0 times, a rule that corrects the basic risk value of an abnormality occurring in a mobile body 100 of a vehicle type with a "market volume of 1,000 to 10,000 vehicles" by 1.2 times, and a rule that corrects the basic risk value of an abnormality occurring in a mobile body 100 of a vehicle type with a "market volume of 10,000 or more vehicles" by 2.0 times. Since the market volume of mobile bodies 100 of a vehicle type with a "market volume of less than 1,000 vehicles" is small and the impact of an abnormality occurring in such a vehicle type is small, the basic risk value of an abnormality occurring in a mobile body 100 of a vehicle type with a "market volume of less than 1,000 vehicles" is not corrected significantly. On the other hand, since the number of vehicles in the market for mobile units 100 is large, and the impact of an abnormality occurring in a vehicle with a market volume of 10,000 or more vehicles is large, the basic risk value of an abnormality occurring in a vehicle with a market volume of 10,000 or more vehicles is significantly adjusted.

[0051] Furthermore, for example, as shown in FIG. 7(a), the priority determination system 10 stores a rule for correcting the basic risk value of an abnormality occurring in a mobile body 100 of a vehicle type with an "estimated damage amount less than previous period's profit" by a factor of 1.0, and a rule for correcting the basic risk value of an abnormality occurring in a mobile body 100 of a vehicle type with an "estimated damage amount equal to or greater than previous period's profit" by a factor of 2.0. Since the estimated damage of a mobile body 100 of a vehicle type with an "estimated damage amount less than previous period's profit" is small, the basic risk value of an abnormality occurring in a mobile body 100 of a vehicle type with an "estimated damage amount less than previous period's profit" is not corrected significantly. On the other hand, since the estimated damage of a mobile body 100 of a vehicle type with an "estimated damage amount equal to or greater than previous period's profit" is large, the basic risk value of an abnormality occurring in a mobile body 100 of a vehicle type with an "estimated damage amount equal to or greater than previous period's profit" is corrected significantly.

[0052] These correction values ​​(multipliers) may be stored in association with the vehicle type, or may be stored in association with the number of vehicles on the market or the estimated damage amount, etc. When the correction values ​​are stored in association with the number of vehicles on the market or the estimated damage amount, etc., the vehicle type and the number of vehicles on the market or the estimated damage amount, etc. for each vehicle type may be stored in the priority determination system 10 as intermediate values, or may be obtained by making an inquiry from the priority determination system 10 to an external system.

[0053] 7A, the priority determination system 10 stores a rule for correcting the basic risk value of an abnormality occurring in a mobile object 100 that is a "domestic vehicle" by 1.0 times, a rule for correcting the basic risk value of an abnormality occurring in a mobile object 100 that is a "commercial vehicle" by 1.2 times, and a rule for correcting the basic risk value of an abnormality occurring in a mobile object 100 that is an "emergency vehicle" by 2.0 times. Since the mobile object 100 that is a "domestic vehicle" is used less frequently, the probability of a problem occurring even if an abnormality occurs is low, and therefore the basic risk value of an abnormality occurring in the mobile object 100 that is a "domestic vehicle" is not corrected as much. Since the mobile object 100 that is a "commercial vehicle" is used more frequently, the probability of a problem occurring even if an abnormality occurs is high, and therefore the basic risk value of an abnormality occurring in the mobile object 100 that is a "commercial vehicle" is corrected more than the basic risk value of an abnormality occurring in the mobile object 100 that is a "domestic vehicle". Since the mobile object 100 that is an "emergency vehicle" is a vehicle of high social importance, the basic risk value of an abnormality occurring in the mobile object 100 that is an "emergency vehicle" is corrected as much.

[0054] Furthermore, for example, as shown in FIG. 7(b), the priority determination system 10 stores a rule that corrects the basic risk value of an abnormality occurring in a mobile body 100 located in a "rural area" by a factor of 1.0, and stores a rule that corrects the basic risk value of an abnormality occurring in a mobile body 100 located in an "urban area" by a factor of 2.0. Because rural areas have few people and little traffic, the basic risk value of an abnormality occurring in a mobile body 100 located in a "rural area" is not corrected significantly. Because urban areas have many people and heavy traffic, the basic risk value of an abnormality occurring in a mobile body 100 located in an "urban area" is corrected significantly.

[0055] Furthermore, for example, as shown in FIG. 7(b), the priority determination system 10 stores a rule that corrects the basic risk value of an abnormality that occurs in a "stopped" mobile body 100 by a factor of 1.0, and stores a rule that corrects the basic risk value of an abnormality that occurs in a "moving" mobile body 100 by a factor of 2.0. Because a "stopped" mobile body 100 is stopped and is unlikely to become dangerous even if an abnormality occurs, the basic risk value of an abnormality that occurs in a "stopped" mobile body 100 is not corrected significantly. Because a "moving" mobile body 100 is moving and is likely to become dangerous if an abnormality occurs, the basic risk value of an abnormality that occurs in a "moving" mobile body 100 is corrected significantly.

[0056] Furthermore, for example, as shown in FIG. 7(b), the priority determination system 10 stores a rule for correcting the basic risk value of an abnormality occurring in a "manually driven" mobile body 100 by 1.0 times, a rule for correcting the basic risk value of an abnormality occurring in a "semi-automated" mobile body 100 by 1.2 times, and a rule for correcting the basic risk value of an abnormality occurring in a "fully automated" mobile body 100 by 1.5 times. Because the "manually driven" mobile body 100 is manually driven and is unlikely to become dangerous even if an abnormality occurs, the basic risk value of an abnormality occurring in the "manually driven" mobile body 100 is not significantly corrected. Because the "semi-automated" or "fully automated" mobile body 100 is automatically driven and is likely to become dangerous if an abnormality occurs, the basic risk value of an abnormality occurring in the "semi-automated" or "fully automated" mobile body 100 is significantly corrected.

[0057] 7(b), the priority determination system 10 stores a rule for correcting the basic risk value of an abnormality occurring in a mobile body 100 that is “not charging or discharging” by 1.0 times, a rule for correcting the basic risk value of an abnormality occurring in a mobile body 100 that is “discharging” by 1.2 times, and a rule for correcting the basic risk value of an abnormality occurring in a mobile body 100 that is “V2X discharging” or “charging” by 1.5 times. Because the mobile body 100 that is “not charging or discharging” is not being charged or discharged and is therefore unlikely to become dangerous even if an abnormality occurs, the basic risk value of an abnormality occurring in the mobile body 100 that is “not charging or discharging” is not corrected significantly. Because the mobile body 100 that is “discharging,” “V2X discharging,” or “charging” is being charged or discharged and is therefore likely to become dangerous if an abnormality occurs, the basic risk value of an abnormality occurring in the mobile body 100 that is “discharging,” “V2X discharging,” or “charging” is corrected significantly.

[0058] For example, if the mobile body 100 in which the abnormality occurred is, as shown in Figure 5, in motion (multiplier 2.0), located in an urban area (multiplier 2.0), operating in semi-autonomous mode (multiplier 1.2), not charging or discharging (multiplier 1.0), and the vehicle model is vehicle model A (i.e., as shown in Figure 6(a), the number of vehicles on the market is 5,000 (multiplier 1.2), the estimated damage amount is less than the previous period's profit (multiplier 1.0), and the vehicle is a commercial vehicle (multiplier 1.2)), the risk value can be calculated as follows:

[0059] Risk value = Base risk value x 2.0 x 2.0 x 1.2 x 1.0 x 1.2 x 1.0 x 1.2 In this way, the risk value calculation unit 14 calculates the risk value of an abnormality for each of the plurality of abnormality data by correcting the basic risk value using the situation data of the corresponding mobile object 100 (mobile object 100 in which an abnormality has occurred).

[0060] Next, the priority determination unit 15 determines the priority of each task for dealing with each of the plurality of abnormal data based on the risk value of each of the plurality of abnormal data calculated by the risk value calculation unit 14 (step S14).

[0061] For example, if the abnormality occurring in the mobile object 100 is "unauthorized communication in IVI (In Vehicle Infotainment)," the following tasks are predefined to deal with the abnormality: "User Notification" to notify the user of the mobile object 100 of the abnormality; "Connection Disconnection" to disconnect the IVI from the in-vehicle network; "Detailed Analysis" to analyze the abnormality in detail; and "Permanent Patch Distribution" to distribute a program or the like that addresses the abnormality. In other words, the priority determination system 10 stores a correspondence relationship between an abnormality and a task to deal with the abnormality. Each task is also associated with a risk value allocation rate and an expected response time.

[0062] The risk reduction rate by executing "User Notification" is 0.10 (10%), and if the expected response time required to complete "User Notification" is 1 second, the risk value of "Unauthorized communication via IVI" can be reduced by 10% by taking 1 second to execute "User Notification".

[0063] The risk reduction rate by executing "Connection cutoff" is 0.40 (40%), and if the expected response time required to complete "Connection cutoff" is 10 seconds, the risk value of "Unauthorized communication via IVI" can be reduced by 40% by taking 10 seconds to execute "Connection cutoff".

[0064] The percentage of risk mitigated by performing "Detailed Analysis" is 0.10 (10%), and if the expected response time required to complete "Detailed Analysis" is 3600 seconds, the risk value of "Unauthorized communication in IVI" can be reduced by 10% by performing "Detailed Analysis" for 3600 seconds.

[0065] The percentage of risk mitigated by performing "permanent patch distribution" is 0.40 (40%), and if the expected response time required to complete "permanent patch distribution" is 60 seconds, performing "permanent patch distribution" over 60 seconds can reduce the risk value of "unauthorized communication via IVI" by 40%.

[0066] For example, the priority of each task is determined to be higher for a task that reduces risk by a larger percentage when executed, and higher for a task that takes less time to execute. In other words, the priority determination unit 15 increases the priority of a task that can reduce risk significantly in a short amount of time. For example, the priority determination system 10 stores rules that can be expressed by the following priority calculation formula, and the priority determination unit 15 determines the priority of each task by substituting the risk value allocation rate and the expected response time into the calculation formula. In the following formulas 1 and 2, rv dec is the reduction in risk value, rv is the risk value, r ratio is the distribution rate of the risk value, p is the importance of the task (it is desirable that the more important the task, the higher the execution priority, so p can also be considered the priority of the task), α is the tuning weight, t est is the expected response time.

[0067]

number

[0068]

number

[0069] In the above formula, if the risk value allocation rate and expected response time are extremely small or extremely large, the priority of the task will change significantly, so the following formula may be used to determine the priority. In the following formula 3, α is 1 or more.

[0070]

number

[0071] However, for example, "permanent patch distribution," a task for dealing with "unauthorized communication in IVI," can only be executed after "detailed analysis" is completed. Therefore, the priority determination system 10 stores a rule that prevents the priority of "permanent patch distribution" from being higher than the priority of "detailed analysis." For example, by adjusting the tuning weight depending on the task, the priority of a specific task can be lowered or raised.

[0072] For example, the priority determination system 10 stores correspondences between various abnormalities and one or more tasks in addition to "unauthorized communication via IVI," and the priority determination unit 15 can determine the priority of each task by referring to these correspondences for various abnormalities. Note that although multiple tasks are associated with "unauthorized communication via IVI," there may be an abnormality that is associated with only one task.

[0073] In this way, the priority determination unit 15 determines the priority of each task based on the risk value calculated by the risk value calculation unit 14. Specifically, the priority determination unit 15 assigns a higher priority to a task whose execution reduces the risk to a greater extent (in other words, the priority of a task whose execution reduces the risk to a lesser extent), and also assigns a higher priority to a task whose execution takes less time (in other words, the priority of a task whose execution takes longer).

[0074] Then, the output unit 17 outputs based on the result of the determination by the priority determination unit 15 (step S15). For example, the output unit 17 outputs an alert to the display 201 as an output based on the result of the determination, urging the analyst to execute tasks starting with the highest priority, and the display 201 displays the alert. The output unit 17 may output the alert to a speaker or the like, which may output the alert as audio. This allows the analyst to execute tasks starting with the highest priority. The priority determination and output based on the result of the determination may be performed when a new abnormality is detected, periodically, when the priority is re-determined, or a combination of these.

[0075] Next, the status change notification management unit 16 determines whether each of the plurality of abnormal data is status change notification target data, which requires that the corresponding mobile object 100 be notified of the changed status data when a change in status occurs (step S16). For example, the status change notification management unit 16 determines that a specific type of abnormal data among the plurality of abnormal data is status change notification target data.

[0076] Fig. 8 is a diagram showing an example of situation change notification target data. Fig. 8 shows abnormal data related to driving function failure, abnormal data related to screen lock, and abnormal data related to charge / discharge control failure as situation change notification target data, and shows abnormal data related to information leakage and abnormal data related to theft as abnormal data that is not situation change notification target data. Fig. 8 also shows, for each situation change notification target data, the situation items that need to be notified when a change occurs (also referred to as situation change notification target items).

[0077] For example, the situation change notification management unit 16 determines that the specific types of abnormal data among the plurality of abnormal data include abnormal data related to driving function failure, abnormal data related to screen lock, and abnormal data related to charge / discharge control failure, as data subject to situation change notification. The specific types of abnormal data are data that may change the risk due to an abnormality when the situation of the mobile object 100 changes, in other words, data that may change the calculated risk value and, ultimately, the determined priority.

[0078] For example, if a driving dysfunction system abnormality that affects driving functions to the extent that safe driving is threatened occurs in the mobile body 100, the risk due to the abnormality may change if the location, driving state, or driving assistance state of the mobile body 100 changes. For example, if the location of the mobile body 100 is in a "rural area" when the abnormality occurs, the risk due to the abnormality is low, but if the location changes to an "urban area" after a while, the risk due to the abnormality becomes high. For this reason, the situation change notification management unit 16 determines that the driving dysfunction system abnormality data is situation change notification target data that requires the corresponding mobile body 100 (specifically, the mobile body 100 that transmitted the abnormality data) to be notified of the changed situation data if a situation change occurs.

[0079] Furthermore, for example, if a screen lock-related abnormality occurs in the mobile object 100, such that the screen of an in-vehicle information device such as a car navigation system is locked and becomes inoperable, the risk due to the abnormality may change if the traveling state of the mobile object 100 changes. For example, if the mobile object 100 is "stopped" when the abnormality occurs, the risk due to the abnormality is low, but if the state changes to "traveling" after a while, the risk due to the abnormality increases. For this reason, the status change notification management unit 16 determines that the screen lock-related abnormality data is status change notification target data that requires the corresponding mobile object 100 to be notified of the changed status data if a status change occurs.

[0080] Furthermore, for example, if the mobile object 100 has an abnormality in the charge / discharge control system that causes an abnormality (e.g., overcurrent) in the battery charge / discharge control, and the charge / discharge state of the mobile object 100 changes, the risk due to the abnormality may change. For example, if the mobile object 100 is "not discharging" when the abnormality occurs, the risk due to the abnormality is low, but if the state changes to "charging" after a while, the risk due to the abnormality increases. For this reason, the status change notification management unit 16 determines that the abnormality data in the charge / discharge control system is status change notification target data that requires the corresponding mobile object 100 to be notified of the changed status data if a status change occurs.

[0081] For example, if a theft-related abnormality such as forced unlocking occurs in the mobile object 100, the risk due to the abnormality is unlikely to change even if the situation of the mobile object 100 changes. For this reason, the situation change notification management unit 16 determines that the abnormality data related to the charge / discharge control failure is not subject to situation change notification, which requires the corresponding mobile object 100 to be notified of the changed situation data when the situation changes.

[0082] If the status change notification management unit 16 determines that each of the plurality of abnormal data is not status change notification target data (No in step S16), the status change notification management unit 16 ends the process.

[0083] When the status change notification management unit 16 determines that any of the plurality of abnormal data is status change notification target data (Yes in step S16), it requests the mobile object 100 corresponding to the abnormal data determined to be status change notification target data to notify the mobile object 100 of the changed status data if a status change occurs; in other words, it transmits a status change notification start request (step S17). The status change notification start request is information indicating an instruction to notify the mobile object 100 of the changed status data if a status change occurs. For example, the status change notification management unit 16 determines a status item corresponding to a specific type of abnormal data, and requests the mobile object 100 corresponding to the abnormal data determined to be status change notification target data to notify the mobile object 100 of the changed status data if a status change occurs for that item.

[0084] For example, by referring to the correspondence between the type of abnormality and the status item (item for which status change notification is to be made) as shown in Fig. 8, the status change notification management unit 16 determines that the status items corresponding to the abnormal data related to driving dysfunction as a specific type of abnormal data are "location," "driving state," and "driving assistance state," and requests the mobile body 100 corresponding to the abnormal data to notify the changed status data when there is a change in the status of the "location," "driving state," or "driving assistance state." As a result, the mobile body 100 that receives the request can monitor the "location," "driving state," and "driving assistance state" of the mobile body 100, and when any of the "location," "driving state," and "driving assistance state" changes, notify the priority determination system 10 of the changed "location," "driving state," or "driving assistance state."

[0085] 8, the status change notification management unit 16 determines that the status item corresponding to the screen lock-related abnormal data as a specific type of abnormal data is the "driving status," and requests the mobile object 100 corresponding to the abnormal data to notify the changed status data when there is a change in the "driving status." This allows the mobile object 100 that receives the request to monitor the "driving status" of the mobile object 100, and when the "driving status" changes, to notify the priority determination system 10 of the changed "driving status."

[0086] 8, the status change notification management unit 16 determines the status item corresponding to the abnormal data of the charge / discharge control failure system as a specific type of abnormal data to be "charge / discharge state," and requests the mobile object 100 corresponding to the abnormal data to notify the changed status data when there is a change in the status of the "charge / discharge state." As a result, the mobile object 100 that receives the request can monitor the "charge / discharge state" of the mobile object 100, and when the "charge / discharge state" changes, notify the priority determination system 10 of the changed "charge / discharge state."

[0087] Then, the priority determination system 10 transitions to a state of waiting for a status change notification from the moving object 100 that has transmitted the status change notification start request (step S18).

[0088] The processing in step S11 and the processing in step S12 may be performed in reverse order or in parallel. Furthermore, the processing in steps S16 to S18 may be performed after steps S11 and S12, and may be performed before step S13, step S14, or step S15.

[0089] Furthermore, the specific types of abnormalities, items subject to status change notification, and combinations thereof are not limited to those shown in Fig. 8. For example, the specific types of abnormalities, items subject to status change notification, and combinations thereof can be increased or changed as appropriate.

[0090] FIG. 9 is a flowchart showing an example of the operation of the moving object 100 according to the embodiment regarding a situation change notification.

[0091] The status notification unit 102 determines whether it is in a status change monitoring state (step S21), and if it is not in a status change monitoring state (No in step S21), it determines whether it has received a status change notification start request (step S22). If it has received a status change notification start request (Yes in step S22), the status notification unit 102 transitions to a status change monitoring state (step S23), and if it has not received a status change notification start request (No in step S22), it repeats the process from step S21.

[0092] If the status notification unit 102 is in the status change monitoring state (Yes in step S21), it determines whether or not a status change notification stop request has been received (step S24). If the status notification unit 102 has not received a status change notification stop request (No in step S24), it determines whether or not a status change that requires notification has occurred (step S25). Here, a method for determining a status change in the moving object 100 will be described with reference to FIG. 10.

[0093] FIG. 10 is a diagram for explaining a method for determining a change in a situation for each situation item.

[0094] For example, whether the location has changed from rural to urban can be determined based on population density information obtained from administrative district information. Also, whether the location has changed to urban can be determined based on traffic light density, intersection density, store density, number of lanes, etc. obtained from map data.

[0095] For example, whether the traveling state has changed from stopped to traveling can be determined based on the change in the travel distance over a certain period of time.

[0096] For example, whether the driving assistance state has changed to manual driving / semi-automated driving / fully automated driving can be determined based on changes in the operating status of the driving assistance function.

[0097] For example, whether the charge / discharge state has changed to not charging / discharging / V2X discharging / charging can be determined based on the change in the charge / discharge state of the moving object.

[0098] If no change in the situation that requires notification has occurred (No in step S25), the situation notification unit 102 performs the process again from step S21. If a change in the situation that requires notification has occurred (Yes in step S25), the situation notification unit 102 notifies the priority determination system 10 of the situation after the change (step S26), and performs the process again from step S21.

[0099] When the status notification unit 102 receives a status change notification stop request (Yes in step S24), it cancels the status change monitoring state (step S27).

[0100] FIG. 11 is a flowchart showing an example of the operation of the priority determination system 10 according to the embodiment when it is in a state of waiting for a status change notification.

[0101] The incident management unit 13 determines whether an event has been acquired (step S31). For example, the event is a response completion event from an analyst or a situation change notification event from the mobile object 100 (specifically, an event indicating that situation data after the change has been acquired). If the incident management unit 13 has not acquired an event (No in step S31), it performs the process from step S31 again.

[0102] When the incident management unit 13 acquires a situation change notification event (Yes (situation change notification) in step S31), that is, when changed situation data is acquired, the risk value calculation unit 14 recalculates the risk value of the abnormal data of the corresponding mobile body 100 based on the changed situation data (step S32). For example, if the risk value of abnormal data related to driving dysfunction of a mobile body 100 in a traveling state of "stopped" was calculated as 400 based on a multiplier of 1.0 for "stopped," and situation data indicating that the traveling state has changed to "moving" is acquired from the mobile body 100, the risk value calculation unit 14 recalculates the risk value of the abnormal data of the mobile body 100 to 800 based on a multiplier of 2.0 for "moving."

[0103] Next, based on the recalculated risk value, the priority determination unit 15 re-determines the priority of the task for dealing with the abnormality indicated by the abnormality data of the corresponding mobile body 100 (step S33). For example, the priority determination unit 15 increases the priority of the task for dealing with the abnormality indicated by the abnormality data of the driving dysfunction system of the mobile body 100 that transmitted the situation data indicating that the driving state has changed from "stopped" to "driving."

[0104] Then, the output unit 17 outputs based on the result of the determination by the priority determination unit 15 (step S34). For example, the output unit 17 can output a determination result that is different from the previously output determination result, and can cause a task with a higher priority to be executed depending on the situation of the moving body 100.

[0105] On the other hand, when the incident management unit 13 acquires a handling completion event (Yes (handling completion event) in step S31), specifically, when handling of an abnormality indicated by a specific type of abnormal data in the mobile object 100 that transmitted the status change notification start request has been performed, the status change notification management unit 16 stops notifying the mobile object 100 corresponding to the abnormal data determined to be status change notification target data of the changed status data, in other words, sends a status change notification stop request (step S35). The status change notification stop request is information indicating an instruction to stop notifying the changed status data when a status change occurs.

[0106] As described above, for the data subject to status change notification among the plurality of abnormal data, the corresponding mobile object 100 notifies the changed status data when a status change occurs. Therefore, even if a status change occurs in the mobile object 100 after the status data of the mobile object 100 has been acquired once, the risk value according to the status after the change is recalculated, and the priority of the task is re-determined. Therefore, the priority of the task can be appropriately determined according to the change in the status of the mobile object 100.

[0107] (Other embodiments) As described above, the embodiments have been described as examples of the technology according to the present disclosure. However, the technology according to the present disclosure is not limited to these, and can be applied to embodiments in which appropriate modifications, substitutions, additions, omissions, etc. are made. For example, the following modifications are also included in one embodiment of the present disclosure.

[0108] For example, in the above embodiment, an example has been described in which the components constituting the priority determination system 10 are arranged on a server, but this is not limited thereto. For example, the abnormality acquisition unit 11, the status acquisition unit 12, the incident management unit 13, the risk value calculation unit 14, and the status change notification management unit 16 may be arranged on the mobile object 100. In this case, the mobile object 100 on which these components are arranged may acquire status data from a server that compiles status data of each of the multiple mobile objects 100, or each of the multiple mobile objects 100 may share its own status data. Furthermore, the priority determination unit 15 may be arranged on the mobile object 100. For example, the priority of the determined task (the importance of the task) may be added to the information constituting the alert, and the mobile object 100 on which the priority determination unit 15 is arranged may notify the alert to a server or the like. In addition, the mobile body 100 in which the priority determination unit 15 is located may inquire of a server that stores task definitions about tasks to deal with abnormalities, risk value allocation rates, expected response times, etc., or each of multiple mobile bodies 100 may share this information.

[0109] Furthermore, for example, in the above embodiment, an example has been described in which the priority of each task is determined based on both the risk value of each of the multiple abnormal data items and the rate at which the risk is reduced by executing each task and the time required to execute each task, as shown in the above formulas 1 to 3. However, this is not limiting. For example, the priority of each task may be determined based on the risk value of each of the multiple abnormal data items and either the rate at which the risk is reduced by executing each task or the time required to execute each task.

[0110] Furthermore, for example, the priority determination system 10 may process, among a plurality of abnormal data, abnormal data in which the abnormality occurs in a location close to each other as one abnormal data.

[0111] Furthermore, for example, in the above embodiment, an example has been described in which a terminal such as an SOC is capable of wired or wireless communication with the priority determination system 10, and the priority determination system 10 (output unit 17) outputs the priority determination result to the display 201 or the like of the terminal, but this is not limiting. For example, the determined priority of each task may be provided to an automation tool such as SOAR, and tasks may be automatically processed based on the determined priority.

[0112] Furthermore, for example, the functions of the priority determination system 10 may be implemented in an automation tool such as SOAR, and an output based on the result of the priority determination may be performed from the automation tool.

[0113] Furthermore, for example, in the above embodiment, an example has been described in which the status change notification management unit 16 determines a status item corresponding to a specific type of abnormal data, and requests the mobile object 100 corresponding to the abnormal data determined to be status change notification target data to notify the changed status data when a change in the status of that item occurs, but this is not limited to this. For example, the status change notification management unit 16 does not have to determine a status item corresponding to a specific type of abnormal data, and may request the mobile object 100 corresponding to the abnormal data determined to be status change notification target data to notify the changed status data when a change in the status of any item occurs.

[0114] Furthermore, for example, in the above embodiment, an example has been described in which the status change notification management unit 16 stops notifying the mobile object 100 corresponding to the abnormal data determined to be status change notification target data of the changed status data when an abnormality indicated by a specific type of abnormal data has been addressed, but this is not limited to this. For example, even when an abnormality indicated by a specific type of abnormal data has been addressed, the status change notification management unit 16 does not have to stop notifying the mobile object 100 corresponding to the abnormal data determined to be status change notification target data of the changed status data. For example, the mobile object 100 may automatically cancel the status change monitoring state over time, etc.

[0115] Furthermore, for example, the moving body 100 is not limited to a vehicle, but may also be a train, an aircraft (for example, an unmanned aircraft), a ship, or the like.

[0116] The present disclosure can be realized not only as the priority determination system 10 but also as a priority determination method including steps (processing) performed by each component of the priority determination system 10.

[0117] As shown in FIGS. 4 and 11, the priority determination method includes acquiring a plurality of abnormality data indicating an abnormality for each of a plurality of moving objects (step S11), acquiring a plurality of situation data indicating the status of each of the plurality of moving objects (step S12), calculating an abnormality risk value for each of the plurality of abnormality data based on the situation data of the corresponding moving object (step S13), determining a priority for each task for dealing with the abnormality indicated by each of the plurality of abnormality data based on the risk value for each of the plurality of abnormality data (step S14), and outputting the result of the determination (step S15). The method includes determining whether the abnormal data is a status change notification target data that requires the mobile body to notify the changed status data if a change in status occurs (step S16), requesting the mobile body corresponding to the abnormal data determined to be a status change notification target data to notify the changed status data if a change in status occurs (step S17), and when the changed status data is obtained, recalculating the risk value of the abnormal data of the corresponding mobile body based on the changed status data (step S32), and re-determining the priority of the task to deal with the abnormality indicated by the abnormal data of the corresponding mobile body based on the recalculated risk value (step S33).

[0118] For example, the steps in the priority determination method may be executed by a computer (computer system), and the present disclosure can be realized as a program for causing a computer to execute the steps included in the priority determination method.

[0119] Furthermore, the present disclosure can be realized as a non-transitory computer-readable recording medium, such as a CD-ROM, on which the program is recorded.

[0120] For example, when the present disclosure is realized as a program (software), each step is performed by running the program using hardware resources such as a computer's CPU, memory, input / output circuits, etc. In other words, each step is performed by the CPU acquiring data from memory or input / output circuits, etc., performing calculations on the data, and outputting the calculation results to memory or input / output circuits, etc.

[0121] Furthermore, each of the components included in the priority determination system 10 of the above embodiment may be realized as a dedicated or general-purpose circuit.

[0122] Furthermore, each of the components included in the priority determination system 10 of the above-described embodiment may be realized as an LSI (Large Scale Integration) which is an integrated circuit (IC).

[0123] Furthermore, the integrated circuit is not limited to an LSI, but may be realized by a dedicated circuit or a general-purpose processor. A programmable FPGA (Field Programmable Gate Array) or a reconfigurable processor in which the connections and settings of circuit cells within the LSI can be reconfigured may also be used.

[0124] Furthermore, if an integrated circuit technology that can replace LSI emerges due to advances in semiconductor technology or other derivative technologies, it is natural that each component included in the priority determination system 10 may be integrated into an integrated circuit using that technology.

[0125] In addition, this disclosure also includes forms obtained by making various modifications to the embodiments that a person skilled in the art would think of, and forms realized by arbitrarily combining the components and functions in each embodiment within the scope that does not deviate from the intent of this disclosure.

[0126] (Addendum) The above description of the embodiments discloses the following techniques.

[0127] (Technology 1) An abnormality acquisition unit that acquires a plurality of abnormality data indicating an abnormality for each of a plurality of moving bodies, a situation acquisition unit that acquires a plurality of situation data indicating a situation for each of the plurality of moving bodies, a risk value calculation unit that calculates a risk value indicating a risk of an abnormality for each of the plurality of abnormality data based on the situation data for the corresponding moving body, a priority determination unit that determines a priority for each task to deal with an abnormality indicated by each of the plurality of abnormality data based on the risk value for each of the plurality of abnormality data, an output unit that outputs based on the result of the determination, and a status acquisition unit that determines whether a situation change has occurred for the corresponding moving body for each of the plurality of abnormality data. and a situation change notification management unit that determines whether the abnormal data is situation change notification target data that requires notification of changed situation data when a change in situation occurs, wherein the situation change notification management unit requests the mobile body corresponding to the abnormal data determined to be the situation change notification target data to notify the changed situation data when a change in situation occurs, the risk value calculation unit, when the changed situation data is obtained, recalculates the risk value of the abnormal data of the corresponding mobile body based on the changed situation data, and the priority determination unit re-determines the priority of a task for dealing with an abnormality indicated by the abnormal data of the corresponding mobile body based on the recalculated risk value.

[0128] According to this, for the status change notification target data among the multiple abnormal data, if a status change occurs from the corresponding mobile object, the status data after the change is notified. Therefore, even if a status change occurs in the mobile object after the status data of the mobile object has been acquired once, the risk value according to the status after the change is recalculated and the priority of the task is re-determined. Therefore, the priority of the task can be appropriately determined according to the change in the status of the mobile object.

[0129] (Technology 2) The priority determination system according to Technology 1, wherein the status change notification management unit determines that a specific type of abnormal data among the plurality of abnormal data is the data subject to status change notification.

[0130] For example, depending on the type of anomaly, the risk value may not change even if the situation of the mobile object changes. Therefore, efficient system operation can be achieved by having only the mobile object in which an anomaly that requires monitoring for a change in situation report the changed situation data when the situation changes.

[0131] (Technology 3) The priority determination system described in Technology 2, in which the status change notification management unit determines the status item corresponding to the specific type of abnormal data, and requests the mobile body corresponding to the abnormal data determined to be the data subject to status change notification to notify the changed status data if there is a change in the status of the item.

[0132] For example, depending on the item of the mobile unit's status, the risk value may not change even if there is a change. Therefore, by having the mobile unit monitor only changes in the necessary status items, efficient system operation becomes possible.

[0133] (Technology 4) A priority determination system described in Technology 2 or 3, wherein the status change notification management unit stops notifying the moving body corresponding to the abnormal data determined to be the data subject to status change notification of the changed status data when the abnormality indicated by the specific type of abnormal data is addressed.

[0134] According to this, when the abnormality has been dealt with, it is no longer necessary for the mobile body in which the abnormality occurred to notify the changed situation, and therefore such notification can be stopped.

[0135] (Technology 5) A priority determination system according to any one of technologies 1 to 4, wherein each of the plurality of situation data includes at least one of type information indicating the type of the mobile body, location information indicating the location of the mobile body, traffic information of a point corresponding to the location information, driving state information indicating the driving state of the mobile body, driving assistance state information indicating the driving assistance state of the mobile body, and charging / discharging state information indicating the charging / discharging state of the mobile body.

[0136] This allows at least one of type information, location information, traffic information, driving state information, driving assistance state information, and charge / discharge state information, which may affect the risk of abnormality, to be reflected in the risk value.

[0137] (Technology 6) The priority determination system according to any one of techniques 1 to 5, wherein the risk value is a value obtained by correcting a basic risk value determined according to the type of abnormality using status data of the corresponding mobile body.

[0138] According to this, the basic risk value, which can be easily determined depending on the type of abnormality, is corrected using the situation data, so that the risk value can be easily calculated.

[0139] (Technology 7) The priority determination system according to any one of Techniques 1 to 6, wherein the priority of each task is determined based on the risk value of each of the plurality of abnormal data and a predetermined index value for each task.

[0140] This makes it possible to easily determine the priority of each task based on the risk value of each of the multiple abnormal data and the predetermined index value for each task.

[0141] (Technology 8) A priority determination system according to Technology 7, wherein the predetermined index value for each task is at least one of the rate at which risk is reduced by executing each task and the time required to execute each task.

[0142] This allows a task that reduces risk by a large proportion when executed to have a higher priority, and also allows a task that takes a short time to execute to have a higher priority.

[0143] (Technology 9) A priority determination system described in any of Technologies 1 to 8, wherein the priority determination unit makes the determination periodically, each time a task is performed, each time an abnormality is detected, or each time the risk value is calculated.

[0144] This allows the priority to be determined automatically at these times.

[0145] (Technology 10) A priority determination method that acquires a plurality of abnormality data indicating an abnormality for each of a plurality of moving bodies, acquires a plurality of situation data indicating the situation of each of the plurality of moving bodies, calculates a risk value indicating the risk of an abnormality for each of the plurality of abnormality data based on the situation data of the corresponding moving body, determines a priority for each task for dealing with the abnormality indicated by each of the plurality of abnormality data based on the risk value for each of the plurality of abnormality data, outputs based on the results of the determination, determines whether each of the plurality of abnormality data is situation change notification target data that requires the corresponding moving body to notify the changed situation data if there is a change in the situation, requests the moving body corresponding to the abnormality data determined to be situation change notification target data to notify the changed situation data if there is a change in the situation, recalculates the risk value for the abnormality data of the corresponding moving body based on the changed situation data if the changed situation data is acquired, and re-determines the priority of the task for dealing with the abnormality indicated by the abnormality data of the corresponding moving body based on the recalculated risk value.

[0146] This provides a priority determination method that can appropriately determine the priority of a task in accordance with changes in the state of the moving object.

[0147] (Technology 11) A program for causing a computer to execute the priority determination method described in Technology 10.

[0148] This makes it possible to provide a program that can appropriately determine the priority of tasks in response to changes in the situation of the moving object. [Industrial Applicability]

[0149] The present disclosure is applicable to systems for monitoring vehicles, for example. [Explanation of symbols]

[0150] 10 Priority Judgment System 11 Abnormality acquisition part 12 Status Acquisition Unit 13 Incident Management Department 14 Risk Value Calculation Unit 15 Priority judgment section 16 Status Change Notification Management Department 17 Output section 18 Input section 100 Mobile 101 Abnormality notification section 102 Status Notification Section 201 Display 202 keyboard

Claims

1. an abnormality acquisition unit that acquires a plurality of abnormality data indicating an abnormality in each of the plurality of moving bodies; a situation acquisition unit that acquires a plurality of situation data indicating the respective situations of the plurality of moving bodies; a risk value calculation unit that calculates a risk value indicating a risk of an abnormality for each of the plurality of abnormality data based on the status data of the corresponding mobile object; a priority determination unit that determines a priority for each task for dealing with an abnormality indicated by each of the plurality of abnormal data based on the risk value of each of the plurality of abnormal data; an output unit that outputs based on the result of the determination; a situation change notification management unit that determines whether each of the plurality of abnormal data is data subject to situation change notification, which requires notification of changed situation data to a corresponding mobile body when a situation change occurs, the status change notification management unit requests the mobile object corresponding to the abnormal data determined to be the status change notification target data to notify the mobile object of the changed status data when a status change occurs; when the changed situation data is acquired, the risk value calculation unit recalculates the risk value of the abnormality data of the corresponding moving body based on the changed situation data; The priority determination unit re-determines the priority of a task for dealing with an abnormality indicated by the abnormality data of the corresponding mobile object based on the recalculated risk value. Priority determination system.

2. The status change notification management unit determines that a specific type of abnormal data among the plurality of abnormal data is the status change notification target data. The priority determination system according to claim 1 .

3. The status change notification management unit determines a status item corresponding to the specific type of abnormal data, and requests the mobile object corresponding to the abnormal data determined to be the status change notification target data to notify the mobile object of the changed status data when a status change occurs for the item. The priority determination system according to claim 2 .

4. When the abnormality indicated by the specific type of abnormal data is dealt with, the situation change notification management unit stops notifying the moving body corresponding to the abnormal data determined to be the data subject to the situation change notification of the changed situation data.

4. The priority determination system according to claim 2 or 3.

5. Each of the plurality of situation data includes at least one of type information indicating the type of the mobile body, position information indicating the position of the mobile body, traffic information of a point corresponding to the position information, driving state information indicating the driving state of the mobile body, driving assistance state information indicating the driving assistance state of the mobile body, and charging / discharging state information indicating the charging / discharging state of the mobile body. The priority determination system according to any one of claims 1 to 3.

6. The risk value is a value obtained by correcting a basic risk value determined according to the type of abnormality using the status data of the corresponding mobile unit. The priority determination system according to any one of claims 1 to 3.

7. The priority of each task is determined based on the risk value of each of the plurality of abnormal data and a predetermined index value for each task. The priority determination system according to any one of claims 1 to 3.

8. The predetermined index value for each task is at least one of a rate at which a risk is reduced by executing each task and a time required to execute each task. The priority determination system according to claim 7 .

9. The priority determination unit performs the determination periodically, every time a task is performed, every time an abnormality is detected, or every time the risk value is calculated. The priority determination system according to any one of claims 1 to 3.

10. acquire a plurality of abnormality data indicating abnormalities in each of the plurality of moving bodies; acquiring a plurality of situation data indicating the respective situations of the plurality of moving bodies; calculating a risk value indicating a risk of an abnormality for each of the plurality of abnormality data based on the status data of the corresponding mobile object; determining a priority for each task for dealing with an abnormality indicated by each of the plurality of abnormal data based on the risk value of each of the plurality of abnormal data; outputting an output based on the result of the determination; determining whether each of the plurality of abnormal data is data subject to status change notification, which requires notification of status data after a change in status to the corresponding mobile object when a change in status occurs; requesting the mobile object corresponding to the abnormal data determined to be the data subject to status change notification to notify the mobile object of status change data when a status change occurs; When the changed situation data is acquired, the risk value of the abnormality data of the corresponding mobile body is recalculated based on the changed situation data; Based on the recalculated risk value, the priority of the task for dealing with the abnormality indicated by the abnormality data of the corresponding mobile unit is re-determined. Priority determination method.

11. A program for causing a computer to execute the priority determination method according to claim 10.

Citation Information

Patent Citations

  • Driving operation auxiliary device for vehicle and vehicle furnished with driving operation auxiliary device for vehicle

    JP2006001339A

  • Driving supporting device

    JP2006163637A

  • Vehicle control device and method therefor

    JP2007253904A

  • Vehicle control device and vehicle control method

    JP2020102159A

  • Priority determination system, priority determination method and program

    JP2021149260A