Vehicle control device and vehicle control method

JPWO2024204024A5Active Publication Date: 2025-07-25DENSO CORP
View PDF 0 Cites 0 Cited by

Patent Information

Application Number
JP2025510829
Authority / Receiving Office
JP · JP
Patent Type
Applications
Current Assignee / Owner
Priority Date
2024-03-25
Filing Date
2024-03-25
Publication Date
2025-07-25
Estimated Expiration
2044-03-25

AI Technical Summary

Technical Problem

Third-party service providers, unfamiliar with vehicle control systems, face challenges in accurately assessing the operational state and points for improvement of application software due to the limitations of conventional request acceptance determination technologies.

Method used

A vehicle control device and method that includes an equipment management section, a reception section, and a determination section, which converts standardized first commands from service providers into executable second commands, determines the feasibility of target functions, and provides non-conformity reasons and suggestion information if not feasible, enabling accurate identification of improvement areas.

Benefits of technology

This solution allows third-party service providers to accurately grasp and improve application software quality by providing detailed feedback on non-conformity reasons and necessary requirements, enhancing the functionality and reliability of vehicle-based applications.

✦ Generated by Eureka AI based on patent content.
Patent Text Reader

Abstract

An accepting unit (7) accepts, from a service providing unit (6) that executes application software, a first command that is written in a standardized format and that requests the realization of a target function, which is a function that utilizes vehicle equipment, and converts the first command into a second command written in a format that can be executed by a vehicle. A determining unit (8: 300) determines whether the target function can be realized, and if the target function can be realized, causes an equipment management unit to execute an instruction in accordance with the second command, and if the target function cannot be realized, transmits, to a request source of the first command, suggestion information indicating a requirement necessary for the target function to be determined as capable of being realized, together with a non-conformity reason indicating the reason why the target function cannot be realized.
Need to check novelty before this filing date? Find Prior Art

Description

Vehicle control device and vehicle control method CROSS-REFERENCE TO RELATED APPLICATIONS

[0001] This international application claims priority based on Japanese Patent Application No. 2023-051740, filed with the Japan Patent Office on March 28, 2023, the entire contents of which are incorporated herein by reference.

[0002] The present disclosure relates to a technique for processing requests from application software that realizes services using vehicle functions.

[0003] Patent Document 1 describes a technology in which, when application software (hereinafter referred to as an app) that provides a service using a vehicle function accesses a vehicle function within a vehicle system, it determines whether to accept the request and returns the result of the determination to the requesting app. Traditionally, apps have been provided by so-called OEMs (original equipment manufacturers) such as vehicle manufacturers that are familiar with the features, equipment, and constraints of vehicle control systems. However, in the future, it is expected that a variety of service providers other than OEMs, known as third parties, will enter the market. OEM stands for original equipment manufacturer.

[0004] Japanese Patent Application Laid-Open No. 2006-192967

[0005] However, even after releasing an app to the market, service providers need to continuously check whether the app is functioning as intended and make improvements to further enhance the quality and value of the app. The results of the app approval / disapproval assessment obtained using conventional technology can be useful information for improving the app.

[0006] However, service providers other than OEMs are not necessarily familiar with the features, equipment, restrictions, etc. of vehicle control systems. For this reason, it was found that it was difficult to accurately grasp the operating status of an app or areas requiring improvement based solely on the result of a request acceptance determination for a request from an app.

[0007] The present disclosure provides a technique that makes it easy to obtain information necessary for improving application software, etc.

[0008] A vehicle control device according to one aspect of the present disclosure includes an equipment management unit, a reception unit, and a determination unit. The equipment management unit is configured to perform at least one of controlling vehicle equipment of the vehicle and managing the status of the vehicle equipment. The reception unit is configured to receive a first command from a service providing unit that executes application software and convert the first command into a second command. The first command is written in a standardized format and requests the realization of a target function that utilizes the vehicle equipment. The second command is written in a format executable by the vehicle. The determination unit determines whether the target function can be realized. If the target function can be realized, the determination unit is configured to cause the equipment management unit to execute an instruction in accordance with the second command. If the target function cannot be realized, the determination unit is configured to transmit, to a source of the first command, a non-conformity reason indicating the reason for the impossibility of realization, along with suggestion information indicating requirements necessary for determining that the function is feasible.

[0009] With this configuration, it is possible to accurately grasp the areas of application software that need improvement, which can be used to improve the quality of application programs.

[0010] A vehicle control method according to one aspect of the present disclosure is applied to a vehicle including an equipment management unit configured to perform at least one of controlling vehicle equipment and managing the status of the vehicle equipment. The vehicle control method includes: receiving, from a service providing unit that executes application software, a first command that is written in a standardized format and requests realization of a target function that is a function using vehicle equipment, and converting the first command into a second command that is written in a format that is executable by the vehicle; determining whether the target function can be realized, causing the equipment management unit to execute an instruction in accordance with the second command if the target function can be realized; and notifying a source of the request for the first command of suggestion information that indicates requirements necessary for determining that the target function can be realized, together with a reason for the incompatibility indicating the reason for the incompatibility.

[0011] The vehicle control method provides the same effects as the vehicle control device.

[0012] 1 is a block diagram showing the configuration of a vehicle control system; FIG. 2 is a block diagram showing the configuration of an ECU; FIG. 3 is a block diagram showing the configuration of a center; FIG. 4 is a flowchart showing a first determination process executed by a vehicle service unit; FIG. 5 is a flowchart showing a second determination process executed by a state management unit; FIG. 6 is a sequence diagram showing the flow of basic processes executed in the vehicle control system; and FIG. 7 is a sequence diagram showing the flow of processes when a request from a service providing unit is incompatible in the vehicle control system.

[0013] Hereinafter, embodiments of the present disclosure will be described with reference to the drawings.

[0014] 1 includes an electronic control unit (hereinafter, referred to as ECU) group 100 mounted on a vehicle such as an automobile, and a center 35. The ECU group 100 includes a plurality of ECUs. In this embodiment, the ECU group 100 includes a first ECU 10, a second ECU 15, a third ECU 20, a fourth ECU 25, a fifth ECU 30, and sixth to thirteenth ECUs 41 to 48. The ECUs belonging to the ECU group 100 are connected to each other via in-vehicle communication (i.e., wired communication or wireless communication). The center 35 is provided outside the vehicle and is connected to the ECU group 100 via out-of-vehicle communication (i.e., wireless communication).

[0015] The first ECU 10 has a relay function for in-vehicle communications and realizes coordinated control of the entire vehicle by controlling the second to fifth ECUs 15 to 30. The first ECU 10 also controls communications with the center 35, thereby realizing coordinated control of the entire system including the center 35.

[0016] The first ECU 10 and the third to fifth ECUs 20 to 30 are provided for each domain, which is divided according to the vehicle's function, and mainly control multiple ECUs (i.e., any of the sixth to thirteenth ECUs 41 to 48) that exist within that domain. The domains are, for example, the powertrain, the body, the chassis, and the cockpit.

[0017] The sixth to thirteenth ECUs 41 to 48 control vehicle equipment that is equipment installed in the vehicle. The vehicle equipment may include hardware such as sensors and actuators, various storage devices that store data, and software that realizes certain functions.

[0018] The first ECU 10 and the third to fifth ECUs 20-30 are connected to the sixth to thirteenth ECUs 41-48 via lower-level networks (e.g., CAN) that are individually provided. CAN is an abbreviation for Controller Area Network and is a registered trademark. The first ECU 10 and the third to fifth ECUs 20-30 have the function of centrally managing access rights to the sixth to thirteenth ECUs 41-48 and authenticating users.

[0019] In another embodiment, the vehicle control system 1 may include the ECU group 100, and the center 35 may be omitted. In another embodiment, the number of ECUs belonging to the ECU group 100 may be 14 or more, or 13 or less. In another embodiment, there may be multiple centers 35.

[0020] [1-2. Hardware Configuration] Next, the hardware configuration of each ECU belonging to the ECU group 100 and the center 35 will be described. Each ECU belonging to the ECU group 100 has the same hardware configuration. Therefore, here, the configuration of the first ECU 10 will be described as a representative.

[0021] As shown in FIG. 2 , the first ECU 10 includes a microcomputer 11, a vehicle interface (hereinafter, I / F) 12, and a communication unit 13. The microcomputer 11 includes a CPU 11a, a ROM 11b, and a RAM 11c. The various functions of the first ECU 10 are realized by the CPU 11a executing a program stored in a non-transitory physical recording medium. In this embodiment, the ROM 11b corresponds to the non-transitory physical recording medium storing the program. Furthermore, the execution of this program causes a method corresponding to the program to be performed.

[0022] The vehicle I / F 12 connects to other ECUs and in-vehicle devices via an in-vehicle network or the like, and acquires various information from the other ECUs and in-vehicle devices. The in-vehicle network may include a Controller Area Network (hereinafter, CAN) and Ethernet. CAN is a registered trademark. Ethernet is a registered trademark.

[0023] The communication unit 13 performs data communication with the center 35 etc. via wireless communication over a wide area communication network. However, it is not necessary for all ECUs belonging to the ECU group 100 to have the communication unit 13, and it may be provided in only one or some of the ECUs.

[0024] The method of realizing the various functions of the first ECU 10 is not limited to software, and some or all of the functions may be realized using one or more hardware elements. For example, if the functions are realized by electronic circuits that are hardware, the electronic circuits may be realized by digital circuits including multiple logic circuits, analog circuits, or a combination of these.

[0025] As shown in Figure 3, the center 35 includes a microcomputer 36, a communication unit 37, and a storage unit 38. The microcomputer 36 includes a CPU 36a, a ROM 36b, and a RAM 36c. The various functions of the center 35 are realized by the CPU 36a executing a program stored in a non-transitory physical recording medium. In this embodiment, the ROM 36b corresponds to the non-transitory physical recording medium storing the program. Furthermore, by executing this program, a method corresponding to the program is performed.

[0026] The communication unit 37 performs data communication with the ECU group 100 via a wide area communication network. The storage unit 38 is a storage device for storing vehicle data and the like provided by the ECU group 100.

[0027] The method of realizing the various functions of the center 35 is not limited to software, and some or all of the elements may be realized using one or more pieces of hardware. For example, if the functions are realized by electronic circuits that are hardware, the electronic circuits may be realized by digital circuits including multiple logic circuits, analog circuits, or a combination of these.

[0028] [1-3. Functional Configuration] Returning to Fig. 1, various functions of the vehicle control system 1 will be described. The software architecture of the vehicle control system 1 is hierarchical in four layers. That is, the vehicle control system 1 has the functions of an equipment management unit 9 in the first layer, a status management unit 8 in the second layer, a vehicle service unit 7 in the third layer, and a service provision unit 6 in the fourth layer. These functions of the vehicle control system 1 are shared by each ECU belonging to the ECU group 100 and the center 35.

[0029] The equipment management unit 9 includes a plurality of control units 91 to 99 corresponding to a plurality of types of vehicle equipment, such as an on-board camera, an on-board millimeter-wave radar, brakes, a steering wheel, a display, a speaker, various lights, an on-board air conditioner, and an electric power seat.

[0030] Specifically, the equipment management unit 9 includes a camera control unit 91, a millimeter wave control unit 92, a brake control unit 93, a steering control unit 94, a display control unit 95, a sound control unit 96, a light control unit 97, a Heating Ventilation and Air-Conditioning (hereinafter referred to as HVAC) control unit 98, and a seat control unit 99. The vehicle equipment is individually controlled by the corresponding control unit among the control units 91 to 99.

[0031] The camera control unit 91 controls the exposure of the vehicle-mounted camera and acquires images captured by the vehicle-mounted camera. In this embodiment, the sixth ECU 91 includes the camera control unit 91.

[0032] The millimeter wave control unit 92 controls the on-board millimeter wave radar and acquires the detection results detected by the millimeter wave radar. In this embodiment, the seventh ECU 92 includes the millimeter wave control unit 92.

[0033] The brake control unit 93 controls the brakes. In this embodiment, the eighth ECU 93 includes the brake control unit 93.

[0034] The steering control unit 94 controls the steering. In this embodiment, the ninth ECU 44 includes the steering control unit 94.

[0035] The display control unit 95 controls indicators (for example, meters, warning lights, etc.) In the present embodiment, the tenth ECU 45 includes the display control unit 95.

[0036] The sound control unit 96 controls the speaker to output sounds such as warning sounds, voices, etc. In this embodiment, the eleventh ECU 46 includes the sound control unit 96.

[0037] The light control unit 97 controls various lights mounted on the vehicle. In this embodiment, the fifth ECU 30 includes the light control unit 97.

[0038] The HAVC control unit 98 controls the in-vehicle air conditioner. In this embodiment, the twelfth ECU 47 includes the HAVC control unit 98.

[0039] The seat control unit 99 controls an electric power seat of the vehicle. In this embodiment, the 13th ECU 48 includes the seat control unit 99.

[0040] The equipment management unit 9 operates the vehicle equipment in accordance with the operation instruction from the status management unit 8 and notifies the status management unit 8 of the operation result. For example, if the vehicle equipment is an actuator, the operation result may indicate that the actuator has completed normally or abnormally. If the vehicle equipment is a sensor, the operation result may indicate data detected by the sensor. If the vehicle equipment is a storage device, the result notification may indicate data read from the storage device.

[0041] The equipment management unit 9 may be configured to operate the vehicle equipment in accordance with an operation instruction from the status management unit 8, as well as to autonomously detect the status of the vehicle equipment and notify the status management unit 8 of the status.

[0042] [1-3-2. State Management Unit] The state management unit 8 includes a state recognition unit 81, a motor system equipment control unit 82, a human machine interface (hereinafter referred to as HMI) system state recognition unit 83, and a body system control unit 84. The state management units 8 are classified according to vehicle operations that are likely to be requested by the service providing unit 6, rather than according to implementation means (e.g., control units 91 to 99) that are likely to depend on variations in the vehicle. For example, a state management unit 8 may be provided corresponding to each domain of the vehicle.

[0043] The state recognition unit 81 is responsible for recognizing the situation of the vehicle itself and its surroundings, such as the positions of the vehicle and pedestrians. The state recognition unit 81 controls, for example, vehicle equipment belonging to the camera control unit 91 and the millimeter wave control unit 92. In this embodiment, the third ECU 20 includes the state recognition unit 81.

[0044] The motion system equipment control unit 82 corresponds to the driving system operations of the vehicle, such as turning, running, stopping, etc. The motion system equipment control unit 82 controls, for example, vehicle equipment belonging to a brake control unit 93 and a steering control unit 94. In this embodiment, the first ECU 10 includes the motion system equipment control unit 82.

[0045] The HMI system status recognition unit 83 corresponds to vehicle operations related to the presentation of information to the user. The HMI system status recognition unit 83 controls, for example, vehicle equipment belonging to the display control unit 95 and the sound control unit 96. In this embodiment, the fourth ECU 25 includes the HMI system status recognition unit 83.

[0046] The body system control unit 84 controls the vehicle's body system operations related to the vehicle environment. For example, the body system control unit 84 controls vehicle equipment belonging to a light control unit 97, an HVAC control unit 98, and a seat control unit 99. In this embodiment, the fifth ECU 30 includes the body system control unit 84.

[0047] As shown in FIGS. 6 and 7 , the status management unit 8 includes an equipment status database (hereinafter referred to as equipment status DB) 89 for storing the status of each vehicle equipment detected by the equipment management unit 9. The equipment status DB 89 stores dynamic information and static information. The dynamic information includes information such as whether the vehicle equipment is in a usable state or not, whether the vehicle equipment is malfunctioning or not, etc. The usable state of the vehicle equipment may include, for example, a state in which the power is on, a state in which communication with other ECUs is possible, etc. The static information includes information such as the model number of each vehicle equipment, the specifications of each vehicle equipment, etc.

[0048] When the status management unit 8 receives a request (i.e., a second command) from the vehicle service unit 7, it executes a second determination process S300. The second determination process S300 determines whether the specific vehicle equipment (i.e., target equipment) indicated in the second command and the current scene are compatible with realizing the requested function, and if both are compatible, it instructs the equipment management unit 9 to operate the target equipment. The second determination process S300 will be described in detail later.

[0049] The status management unit 8 has a function of outputting an operation instruction to the equipment management unit 9 and providing the operation result returned from the equipment management unit 9 to the vehicle service unit 7 as a result notification for the second command. The result notification may use individual operation results as they are, or may integrate multiple operation results and convert them into highly abstract data for use.

[0050] For example, the status management unit 8 may receive a request from the vehicle service unit 7 to collect information to understand the status of the vehicle, and may obtain data from a plurality of vehicle equipment as operation results from the equipment management unit 9. If the plurality of data obtained from the vehicle equipment as operation results include "vehicle speed 0 km / h," "shift position P," and "the driver is absent from the vehicle," the data may be converted into data indicating that "the vehicle is in a parked state."

[0051] [1-3-3. Service Providing Unit] The service providing unit 6 executes application software (hereinafter, "apps") 61 to 64 to realize various functions, such as information collection, theft prevention, and remote control, by utilizing the vehicle equipment managed by the equipment management unit 9.

[0052] In this embodiment, the first ECU 10, the second ECU 15, and the center 35 each include a service providing unit 6. The ROM 11b of the first ECU 10 stores apps 61 and 62. The ROM 11b of the second ECU 15 stores an app 63. The ROM 36b of the center 35 stores an app 64.

[0053] Apps 61 to 64 are basically configured to obtain information indicating the vehicle status via vehicle API 71 that constitutes vehicle service unit 7, and to realize the desired function through a series of operations that operate some vehicle equipment via vehicle API 71 depending on the confirmed vehicle status.

[0054] The apps 61 to 64 are not dedicated programs for executing processes suited to a specific vehicle model, a specific grade, or the like, but are general-purpose programs for executing processes suited to many vehicle models, grades, and the like. Therefore, the apps 61 to 64 are written using publicly available modeled vehicle functions so that they can be created without considering the vehicle equipment and performance of individual vehicles. In other words, the apps 61 to 64 can be easily developed by third parties, who are app providers other than OEMs, and the developed apps can be widely released. Therefore, a vehicle user who owns a vehicle equipped with the ECU group 100 can install an app released by a third party into any of the ECU group 100 via a wide-area communication network or the like. Furthermore, the vehicle user can add or modify the apps 61 to 64 as desired.

[0055] In the case of an app used to provide a service that acquires vehicle information from many vehicles and analyzes the vehicle behavior, the driver's driving operations, and the like, a service provider that provides the app may install the app in one of the ECU group 100 with the permission of the vehicle user. Furthermore, when the vehicle API 71 is accessed from an app installed in the center 35 by a service provider or the like, the vehicle user may limit the access authority to each individual vehicle API 71 for each service provider or each app.

[0056] [1-3-4. Vehicle Service Unit] The vehicle service unit 7 includes a vehicle Application Programming Interface (hereinafter, API) 71. The vehicle API 71 is an interface for accessing functions provided by the vehicle. In this embodiment, the first ECU 10 includes the vehicle API 71.

[0057] The vehicle API 71 has a standardized syntax that allows requests to be written without being dependent on a specific vehicle model or grade. When using a function provided by the vehicle API 71, the apps 61 to 64 send a first command to the vehicle API 71. The first command is a command that indicates information necessary for using the vehicle API 71. The first command may include a command indicating the request content, a command such as an argument, a function call, etc. The first command may also include priority information that indicates which command should be processed first. Similar to the apps 61 to 64, the API syntax, i.e., the format of the first command, is written using publicly available modeled vehicle functions so that the app can be created without being aware of the vehicle equipment or performance of each individual vehicle.

[0058] Upon receiving the first command, the vehicle API 71 executes a first determination process S100. In the first determination process S100, the vehicle API 71 determines whether the first command can be accepted from a formal standpoint, such as the format of the first command and the access rights held by the requester of the first command. If the first command can be accepted, the vehicle API 71 converts the first command into a second command written in a format suitable for the model and grade of the target vehicle, and transmits the second command to the status management unit 8. In other words, the vehicle API 71 has a function to convert the first command written in a standard format handled by the service providing unit 6 into a second command written in a vehicle-specific format handled by the status management unit 8 and the equipment management unit 9. The vehicle API 71 also has a function to transfer a result notification, which is a response from the status management unit 8 to the requesting app. Details of the first determination process S100 will be described later.

[0059] The vehicle API 71 includes an authority information DB 711 , a conversion information DB 712 , and an access log DB 713 .

[0060] The authority information DB 711 stores authority information granted to each of the applications 61 to 64 belonging to the service providing unit 6. The authority information is information indicating the content of the access authority granted to each of the applications 61 to 64. The authority information may include the range of accessible functions and data, the period during which access is permitted, and the like.

[0061] The conversion information DB 712 stores format information and conversion information. The format information includes the format of a first command defined as a standard format. The conversion information includes information for converting the first command into a second command in a specific format. The authority information, standard information, and conversion information may be acquired from the center 35 or another external server via a wide area communication network.

[0062] The access log DB 713 stores the access log generated in the first determination process S100.

[0063] [2. Processing] [2-1. First Determination Process] The first determination process S100 executed by the vehicle service unit 7 will be described with reference to the flowchart in Fig. 4. The first determination process S100 is initiated when the vehicle service unit 7 receives a first command, which is a request from the service providing unit 6, via the vehicle API 71. Hereinafter, the app that is the sender of the first command will be referred to as the requesting app.

[0064] The first command describes the function to be realized abstractly without specifying the vehicle equipment or using expressions that depend on the performance of the vehicle equipment. For example, the first command describes the content to turn on the car finder, but does not specify specific matters that depend on each individual vehicle, such as which vehicle equipment to control and how to control it, such as specifying which lights to turn on among multiple lights installed in the vehicle.

[0065] When the first determination process S100 is started, the vehicle service unit 7 performs a format check on the received first command in S110. The format check is performed by comparing the data indicated in the first command with format information that represents the syntax of the indicated API and is stored in the conversion information DB 712.

[0066] In the following S120, the vehicle service unit 7 determines whether the data indicated in the first command conforms to the API syntax as a result of the format check, and if it determines that it conforms, it proceeds to S130, and if it determines that it does not conform, it proceeds to S200.

[0067] In S200, the vehicle service unit 7 transmits a result notification to the request source application indicating that the request is rejected due to format non-compliance, and the process proceeds to S210.

[0068] In S130, the vehicle service unit 7 performs an authority check on the requesting application by comparing the content of the request by the first command with the content of the authority information stored in the authority information DB 711, i.e., the access authority of the requesting application of the first command.

[0069] In the following S140, if the vehicle service unit 7 determines, as a result of the authority check, that the request made by the first command complies with the access authority held by the application that requested the first command, it proceeds to S150; if it determines that the request is incompatible, it proceeds to S190.

[0070] In S190, the vehicle service unit 7 transmits a result notification to the request source application indicating that the request is rejected due to authority incompatibility, and the process proceeds to S210.

[0071] In S150, the vehicle service unit 7 uses the conversion information stored in the conversion information DB 712 to convert the first command into a second command written in a specific format suitable for the vehicle, i.e., a format that can be deciphered by the status management unit 8 and the equipment management unit 9. The second command may specify a specific vehicle equipment to be controlled. If the control object is an actuator, a specific control amount may be specified. If the control object is a storage device, an address to be used for data read / write may be specified.

[0072] In the following S160 , the vehicle service unit 7 transmits the generated second command to the status management unit 8 .

[0073] In the next step S170, the vehicle service unit 7 waits until it receives a result notification, which is a response to the second command sent, from the destination status management unit 8, and upon receiving the result notification, proceeds to step S180.

[0074] In S180, the vehicle service unit 7 transfers the result notification received from the status management unit 8 to the requesting application, and the process proceeds to S210.

[0075] In S210, the vehicle service unit 7 saves the access log in the access log DB 713 and ends the process. The access log is data that associates the content of the result notification acquired or generated in any of S180 to S200 with the content of the first command that was the source of the result notification. Note that the vehicle service unit 7 may save only the access log related to the result notification that rejects the request in the access log DB 713.

[0076] [2-2. Second Determination Process] The second determination process S300 executed by the status management unit 8 will be described with reference to the flowchart shown in Fig. 5. The second determination process S300 is initiated when the status management unit 8 receives a second command, which is a request from the vehicle service unit 7.

[0077] When the second determination process S300 is started, in S310, the status management unit 8 executes an equipment check on the content of the received second command. The equipment check checks whether the vehicle equipment to be controlled (hereinafter, the target equipment) indicated in the second command can realize the request indicated in the second command. Specifically, by referring to information stored in the equipment status DB 89, it checks whether the target equipment exists, whether the target equipment is malfunctioning, whether the target equipment has the ability to realize the request, etc.

[0078] In the following S320, if the status management unit 8 determines that the target equipment is suitable for fulfilling the request as a result of the equipment check, it proceeds to S330, and if it determines that the target equipment is not suitable, it proceeds to S390.

[0079] In S390, the status management unit 8 sends a result notification to the vehicle service unit 7 indicating that the request is rejected due to equipment incompatibility, and including suggestion information, and then ends the processing. The suggestion information is information indicating how to resolve the reason for the equipment incompatibility. For example, if the target equipment does not exist or if the target equipment has insufficient capabilities, the suggestion information may include the model number of equipment that meets the request or the software version that should be applied to the target equipment. Furthermore, if some of the multiple target equipment are malfunctioning, the suggestion information may include information identifying operational vehicle equipment. The suggestion information is generated based on various information stored in the equipment status DB.

[0080] In S330, the status management unit 8 executes a scene check. The scene check checks whether the vehicle situation corresponds to a scene in which the request of the second command can be executed. The scenes in which the request can be executed are limited, for example, for reasons of safety. The scene is estimated, for example, from the status of each vehicle equipment stored in the equipment status DB 89.

[0081] In the following S340, if the state management unit 8 determines as a result of the scene check that the scene complies with the requirements of the second command, it proceeds to S350, and if it determines that the scene does not comply, it proceeds to S380.

[0082] In S380, the status management unit 8 transmits a result notification to the vehicle service unit 7 indicating that the request is rejected due to scene incompatibility and including suggestion information, and ends the process. The suggestion information is information indicating how to resolve the scene incompatibility. The suggestion information may include, for example, information indicating a scene for which the request can be accepted.

[0083] In S350, the status management unit 8 transmits to the equipment management unit 9 a specific command for the target equipment, which is generated based on the second command.

[0084] In the next step S360, the status management unit 8 waits until it receives a response to the transmitted command from the equipment management unit 9, which is the transmission destination, and when it receives a response, it proceeds to step S370.

[0085] In S370, the status management unit 8 generates a result notification according to the response from the equipment management unit 9, transmits the generated result notification to the vehicle service unit 7, and ends the processing. The response from the equipment management unit 9 may indicate the execution result of the command. For example, a response from the equipment management unit 9 to a command to drive an actuator or the like may indicate the success or failure of the operation. Furthermore, a response from the equipment management unit 9 to a command to access data may indicate the success or failure of the data read / write, as well as include the read data, etc.

[0086] 3. Operation 3-1. Basic Operation Next, the basic operation of the vehicle control system 1 will be described with reference to the sequence diagram of FIG.

[0087] The equipment management unit 9 monitors the status of the vehicle equipment and stores the monitoring results in an equipment status DB 89 that can be accessed from the status management unit 8. The monitoring results are repeatedly updated at least every time there is a change in the status.

[0088] As shown in FIG. 6, in S10, the application belonging to the service providing unit 6 uses the vehicle API to send a first command to the vehicle service unit 7 requesting realization of a desired function.

[0089] The vehicle service unit 7 executes a first determination process S100 for the received first command. If the format check and the authority check are both determined to be valid in the first determination process S100, the vehicle service unit 7 transmits a second command converted from the first command using the conversion information to the status management unit 8 in S20.

[0090] The status management unit 8 executes a second determination process S300 for the received second command. If the results of the equipment check and the scene check are both determined to be conforming in the second determination process S300, the status management unit 8 transmits an operation instruction for the target equipment to the equipment management unit 9 in accordance with the second command in S30.

[0091] The equipment management unit 9 operates the target equipment in accordance with the received operation instruction, and in S40 transmits the operation result to the status management unit 8.

[0092] The status management unit 8 generates a result notification according to the operation result, and transmits the result notification to the vehicle service unit 7 in S50.

[0093] In S70, the vehicle service unit 7 transmits the received result notification to the requesting application of the service providing unit 6. In addition, in S80, the vehicle service unit 7 generates an access log that associates the content of the result notification with the content of the first command received in S10, and records the generated access log in the access log DB 713. Note that if the result notification indicates that the request based on the first command has been successfully fulfilled, recording of the access log may be omitted.

[0094] The vehicle service unit 7 executes a log providing process S500 separately from the first determination process S100. In the log providing process S500, when a preset transmission condition is met, the vehicle service unit 7 acquires an access log from the access log DB 713 in S80 and uploads the access log to the center 35 in S90. The transmission condition may include the passage of a certain period of time, the accumulation of access logs reaching a predetermined amount, a request from the center 35, and the like.

[0095] [3-2. Operation When Request is Rejected] With reference to the sequence diagram of FIG. 7, the operation when the first determination process or the second determination process determines that the request is incompatible will be described.

[0096] The vehicle service unit 7 executes a first determination process S100 for the first command received from the service providing unit 6. If the format check or the authority check determines that the command is incompatible in the first determination process S100, the vehicle service unit 7 sends a result notification indicating the reason for the incompatibility in S62 to the requesting application belonging to the service providing unit 6. Furthermore, the vehicle service unit 7 generates an access log in S72 in which the content of the result notification is associated with the first command received in S10, and stores the generated access log in the access log DB 713.

[0097] If the format check or authority check is judged to be conforming in the first judgment process S100, the vehicle service unit 7 transmits a second command to the status management unit 8 in S20.

[0098] The status management unit 8 executes a second determination process for the second command received from the vehicle service unit 7. If the result of the equipment check or the scene check is determined to be non-compliant in the second determination process S300, the status management unit 8 transmits a result notification to the vehicle service unit 7 in S52, which indicates the reason for the non-compliance and includes suggestive information.

[0099] In S64, the vehicle service unit 7 transmits the result notification received from the status management unit 8 to the service providing unit 6 (i.e., the requesting application). In addition, in S74, the vehicle service unit 7 generates an access log in which the content of the result notification is associated with the first command received in S10, and stores the generated access log in the access log DB 713.

[0100] The requesting application may execute a result reflection process S700 to reflect the content of the suggestion information indicated in the received result notification in subsequent processing. In the result reflection process S700, for example, the first command may be retransmitted with the transmission timing or the request content partially changed in accordance with the content of the suggestion information.

[0101] [4. Specific Example] The following describes the operation in a situation where a requesting application transmits a first command to the vehicle service unit 7 requesting activation of all seat heaters in a vehicle having seat heaters in the driver's seat, passenger seat, and rear seats, when the rear seat heater is malfunctioning.

[0102] If the requesting application does not have the authority to request activation of the seat heater, the authority check in the first determination process S100 determines that the request by the first command is incompatible, and a result notification indicating that the request is rejected due to the lack of authority is returned. In this case, since there is no authority in the first place and there is no situation in which the request can be accepted without the authority, suggestion information does not need to be added to the result notification.

[0103] If the first command is determined to be conforming as a result of the format check and authority check by the first determination process S100, the first command is converted into a second command requesting the operation of specific target equipment, and is transmitted to the status management unit 8. The specific target equipment may include, for example, seat heaters for the driver's seat, passenger seat, and rear seats.

[0104] For example, if the seat heaters in the rear seats are malfunctioning, the equipment check in the second determination process S300 determines that the request by the second command is incompatible, and a result notification is sent rejecting the request due to the equipment incompatibility. In this case, the result notification may include suggestion information indicating that the seat heaters in the driver's seat and passenger's seat, which have not been confirmed to be malfunctioning, are operable as part of the equipment range that can accept the request.

[0105] In addition, if the second command is rejected due to a serious failure related to all commands, such as an inability to access the equipment status DB 89, which is the information source for the second judgment process S300, due to a vehicle communication failure, suggestion information indicating areas for improvement for each command does not need to be added.

[0106] Next, an operation will be described in a situation where the request source application transmits a first command requesting door unlocking to the vehicle service unit 7 while the vehicle is traveling.

[0107] The scene check in the second determination process S300 results in a result notification being sent to reject the request for the second command due to the scene being incompatible. In this case, the result notification may be accompanied by suggestion information indicating that the scene in which door unlocking can be performed is when the vehicle is stopped or parked.

[0108] Next, an operation will be described in a situation where the requesting application transmits a first command involving power consumption to the vehicle service unit 7 when the vehicle battery voltage is in a low voltage state.

[0109] The scene check in the second determination process S300 results in a result notification being sent to reject the request for the second command due to the scene incompatibility being the reason for the incompatibility. In this case, the result notification may include, as suggestive information, an acceptable voltage at which the request can be accepted, a predicted time required for the battery voltage to recover to the acceptable voltage, and the like.

[0110] [5. Correspondence of Terminology] In this embodiment, the first determination process S100 of the vehicle service unit 7 corresponds to the reception unit in this disclosure, the second determination process S300 of the status management unit 8 corresponds to the determination unit in this disclosure, and the log provision process S500 of the vehicle service unit 7 corresponds to the log provision unit in this disclosure. Also, the access log DB 713 in this embodiment corresponds to the log storage unit in this disclosure.

[0111] 6. Effects According to the embodiment described above in detail, the following effects are achieved.

[0112] (1) When the vehicle control system 1 rejects a request (i.e., a first command) from the service providing unit 6 via the vehicle API 71, the vehicle control system 1 transmits a result notification to the requesting application that includes, in addition to the reason for the non-conformity that caused the rejection, suggestion information that indicates how to achieve conformity. Therefore, the requesting application can appropriately use the functions provided by the vehicle by correcting the way in which it makes a request to the vehicle API 71 in accordance with the suggestion information.

[0113] (2) The vehicle control system 1 is configured to store an access log, which is information associating the contents of the result notification with the contents of the first command, in the access log DB 713 and provide the access log to a location outside the vehicle as needed. Therefore, by acquiring the access log, a service provider that provides an app can obtain specific information regarding areas in need of improvement in the app, which can be used to improve the quality of the app and increase the value provided by the app. Furthermore, using the access log can also enable the realization of a consulting business aimed at service providers to improve their apps.

[0114] 7. Other Embodiments Although the embodiments of the present disclosure have been described above, the present disclosure is not limited to the above-described embodiments and can be implemented in various modifications.

[0115] (a) In the above embodiment, the vehicle service unit 7 converts the first command into the second command. However, the state management unit 8 may convert the first command into the second command.

[0116] (b) In the above embodiment, the reasons for incompatibility are exemplified as "format incompatibility," "authority incompatibility," "equipment incompatibility," and "scene incompatibility," but may also include, for example, "priority incompatibility," "communication timeout," etc. If the reason for incompatibility is "priority incompatibility," the suggestion information may indicate a priority level that is determined to be compatible.

[0117] (c) In the above embodiment, the first ECU 10, the second ECU 15, and the center 35 each include a service providing unit 6, and the first ECU 10 includes a vehicle service unit 7. Furthermore, the first ECU 10 and the third to fifth ECUs 20 to 30 each include a status management unit 8, and the fifth to thirteenth ECUs 30 to 48 each include an equipment management unit 9. The number of ECUs belonging to the ECU group 100 and the allocation of the functions of the service providing unit 6, vehicle service unit 7, status management unit 8, and equipment management unit 9 to each ECU are not limited to those exemplified in the embodiment, and may be arbitrarily determined.

[0118] (d) Multiple functions possessed by one component in the above embodiments may be realized by multiple components, or one function possessed by one component may be realized by multiple components. Also, multiple functions possessed by multiple components may be realized by one component, or one function realized by multiple components may be realized by one component. Also, part of the configuration of the above embodiments may be omitted. Also, at least part of the configuration of the above embodiments may be added to or substituted for the configuration of another of the above embodiments.

[0119] (e) In addition to the vehicle control device described above, the present disclosure can also be realized in various forms, such as a program for causing a computer to function as a vehicle control device, a non-transient physical recording medium such as a semiconductor memory on which this program is recorded, and a vehicle control method.

[0120] [8. Technical Ideas Disclosed in the Present Specification] [Item 1] A vehicle control device (10) mounted on a vehicle, comprising: an equipment management unit (9) configured to perform at least one of executing control over vehicle equipment of the vehicle and managing the status of the vehicle equipment; a reception unit (7) configured to receive, from a service provision unit (6) that executes application software, a first command that is written in a standardized format and requests realization of a target function that is a function using the vehicle equipment, and convert the first command into a second command that is written in a format that can be executed by the vehicle; and a determination unit (8: S300) configured to determine whether the target function can be realized, and if the target function can be realized, cause the equipment management unit to execute an instruction in accordance with the second command, and if the target function cannot be realized, send suggestion information that indicates requirements necessary for determining that the target function can be realized, together with a non-conformity reason indicating the reason why the target function cannot be realized, to a source of a request for the first command.

[0121] [Item 2] The vehicle control device according to Item 1, wherein the reason for incompatibility includes an equipment incompatibility indicating that the vehicle equipment is incompatible with realizing the target function, a scene incompatibility indicating that a scene identified from the state of the vehicle is incompatible with realizing the target function, and an authority incompatibility indicating that a source of the request for the first command does not have authority to use the target function, and the determination unit is configured to add the suggestion information when the reason for incompatibility is the equipment incompatibility or the scene incompatibility.

[0122] [Item 3] The vehicle control device according to Item 2, wherein, when the reason for non-compliance is the equipment non-compliance, the suggestion information includes information indicating the vehicle equipment that is compatible.

[0123] [Item 4] The vehicle control device according to item 2 or 3, wherein, when the reason for the incompatibility is the scene incompatibility, the suggestion information includes information indicating the scene that is compatible.

[0124] [Item 5] The vehicle control device according to any one of items 1 to 4, further comprising a log storage unit (713) configured to store an access log that associates the reason for non-conformity and the suggestion information generated by the determination unit with information related to the target function that was the subject of the determination.

[0125] [Item 6] The vehicle control device according to Item 5, further comprising a log providing unit (7: S500) configured to read the access log stored in the log storage unit in response to a request from outside the vehicle and provide the access log to a request source.

Claims

1. A vehicle control device (10) mounted on a vehicle, comprising: An equipment management unit (9) configured to perform at least one of execution of control for vehicle equipment possessed by the vehicle and state management of the vehicle equipment; A reception unit (7) configured to receive a first command described in a standardized format and requesting realization of a target function, which is a function using the vehicle equipment, from a service providing unit (6) that executes application software, and convert it into a second command described in a format executable by the vehicle; A determination unit (8: S300) configured to determine whether the target function can be realized, and if it can be realized, cause the equipment management unit to execute an instruction according to the second command, and if it cannot be realized, transmit, together with a non-conformity reason indicating the reason for non-realization, suggestion information indicating requirements necessary for being determined as realizable, to the requester of the first command; Comprising: The non-conformity reasons include equipment non-conformity indicating that the vehicle equipment is not suitable for realizing the target function, scene non-conformity indicating that a scene specified from the state of the vehicle is not suitable for realizing the target function, and authority non-conformity indicating that the requester of the first command does not have the authority to use the target function; The determination unit is configured to add the suggestion information when the non-conformity reason is the equipment non-conformity or the scene non-conformity; Vehicle control device.

2. The vehicle control device according to Claim 1, wherein: When the non-conformity reason is the equipment non-conformity, the suggestion information includes information indicating the vehicle equipment that conforms; Vehicle control device.

3. The vehicle control device according to Claim 1, wherein: When the non-conformity reason is the scene non-conformity, the suggestion information includes information indicating the scene that conforms; Vehicle control device.

4. The vehicle control device according to Claim 1, further comprising: A log storage unit (713) configured to store an access log associating the non-conformity reason and the suggestion information generated by the determination unit with information related to the target function that was the determination target; Vehicle control device.

5. The vehicle control device according to Claim 4, further comprising: A log providing unit (7: S500) configured to read out the access log stored in the log storage unit in response to a request from outside the vehicle and provide it to the requester; Vehicle control device.

6. A vehicle control method for a vehicle including an equipment management unit configured to perform at least one of execution of control for vehicle equipment and state management of the vehicle equipment, receiving, from a service providing unit that executes application software, a first command that is described in a standardized format and requests realization of a target function that is a function using the vehicle equipment, and converting the first command into a second command described in a format executable by the vehicle (S100); determining whether the target function can be realized, and if it can be realized, causing the equipment management unit to execute an instruction according to the second command, and if it cannot be realized, notifying the source of the first command of a non-conformity reason indicating the reason why it cannot be realized and suggestion information indicating requirements necessary for being determined as realizable (S300); including the non-conformity reason includes equipment non-conformity indicating that the vehicle equipment is not suitable for realizing the target function, scene non-conformity indicating that a scene specified from the state of the vehicle is not suitable for realizing the target function, and authority non-conformity indicating that the source of the first command does not have the authority to use the target function; when the non-conformity reason is the equipment non-conformity or the scene non-conformity, adding the suggestion information to the notification to the source of the first command Vehicle control method.