On-vehicle information processing device, information processing system, and information processing method
The in-vehicle information processing device addresses the challenge of integrating new communication devices by simulating communication and updating the routing map only when it meets specific standards, thereby preventing malfunctions and ensuring efficient communication within vehicle networks.
Patent Information
- Application Number
- PCT/JP2024/039811
- Authority / Receiving Office
- WO · WO
- Patent Type
- Applications
- Current Assignee / Owner
- Priority Date
- 2023-11-15
- Filing Date
- 2024-11-08
- Publication Date
- 2025-05-22
AI Technical Summary
The integration of new in-vehicle communication devices into vehicle networks can lead to increased communication volume and delays, making it difficult to predict and prevent malfunctions.
An in-vehicle information processing device that detects new communication devices, creates a routing map, verifies communication through simulation, and updates the map only if the verification is positive, thereby minimizing potential issues.
This solution effectively suppresses the occurrence of malfunctions and communication-related problems by ensuring that the routing map is updated only when it meets predetermined communication standards.
Smart Images

Figure JP2024039811_22052025_PF_FP_ABST
Abstract
Description
In-vehicle information processing device, information processing system, and information processing method
[0001] The present disclosure relates to an in-vehicle information processing device, an information processing system, and an information processing method that perform processing related to communication within a vehicle.
[0002] Patent document 1 proposes an information management system in which an in-vehicle device acquires a service ID related to an added function and transmits it to a server, the server acquires service information for the function corresponding to the service ID, determines the changes to be made to the routing table based on the service information for multiple functions including the acquired service information, and executes the changes to the routing table.
[0003] JP 2018-152758 A
[0004] For example, a new in-vehicle communication device may be added to a network related to vehicle communication in order to add a function to the vehicle. An in-vehicle relay device that relays data transmission and reception between the in-vehicle communication devices in this network needs to update a routing map (routing table) to determine a relay destination for data related to the new in-vehicle communication device. After the routing map is updated and the in-vehicle communication device starts relaying data related to the new in-vehicle communication device, an increase in communication volume or communication delays may occur in the vehicle network. In recent years, the variety of added functions and types of in-vehicle communication devices has increased, making it difficult to verify in advance whether these additions will cause an increase in communication volume or communication delays.
[0005] The present disclosure has been made in consideration of the above circumstances, and its purpose is to provide an in-vehicle information processing device, an information processing system, and an information processing method that are expected to suppress the occurrence of problems, etc., caused by adding a new in-vehicle communication device to a vehicle network.
[0006] The in-vehicle information processing device of this embodiment includes a detection unit that detects connection of an in-vehicle communication device to a network within the vehicle, a creation unit that creates a routing map to determine the relay destination of data sent and received on the network when connection of the in-vehicle communication device is detected, a verification unit that verifies communication on the network using the created routing map through simulation, and an update unit that updates the routing map when a positive verification result is obtained.
[0007] The present application can be realized not only as a device having such characteristic processing units, but also as a method having such characteristic processing steps, or as a computer program for causing a computer to execute such steps, or as a semiconductor integrated circuit that realizes part or all of these devices, or as other devices or systems that include these devices.
[0008] Based on the above, it is expected that the occurrence of problems and the like caused by adding a new in-vehicle communication device to the vehicle network can be suppressed.
[0009] FIG. 1 is a schematic diagram for explaining an example of the configuration of an information processing system according to the present embodiment. FIG. 2 is a block diagram showing an example of the configuration of an integrated ECU according to the present embodiment. FIG. 3 is a schematic diagram for explaining the procedure of a function expansion process performed by the information processing system according to the present embodiment. FIG. 4 is a schematic diagram showing an example of a routing map. FIG. 5 is a flowchart showing an example of the procedure of a process performed by the verification device according to the present embodiment. FIG. 6 is a schematic diagram for explaining an overview of a simulation performed in the information processing system according to the present embodiment. FIG. 7 is a schematic diagram for explaining an example of a network model generated by a model generation unit. FIG. 8 is a schematic diagram showing an example of the configuration of a use case DB. FIG. 9 is a schematic diagram showing an example of a scenario. FIG. 10 is a schematic diagram showing an example of an operation log 7. FIG. 11 is a flowchart showing an example of the procedure of a simulation verification process performed by the verification device according to the present embodiment.
[0010] [Description of Embodiments of the Present Disclosure] First, embodiments of the present disclosure will be listed and described. At least some of the embodiments described below may be combined in any combination.
[0011] (1) The in-vehicle information processing device according to this aspect includes a detection unit that detects the connection of an in-vehicle communication device to a network within the vehicle, a creation unit that creates a routing map for determining a relay destination for data transmitted and received over the network when the connection of the in-vehicle communication device is detected, a verification unit that verifies communication over the network using the created routing map through simulation, and an update unit that updates the routing map when a positive verification result is obtained.
[0012] In this aspect, an in-vehicle information processing device updates a routing map for determining a data relay destination in a network within a vehicle. When the in-vehicle information processing device detects a connection of a new in-vehicle communication device to the network, the in-vehicle information processing device creates a new routing map including information for relaying data from or to the in-vehicle communication device. The in-vehicle information processing device verifies, by simulation, network communication when the created routing map is applied. If a positive verification result is obtained by the simulation, the in-vehicle information processing device updates the old routing map with the newly created routing map. By performing verification by simulation before updating the routing map, it is expected that problems and the like will be prevented from occurring after updating the routing map.
[0013] (2) It is preferable that the verification unit verify, by the simulation, whether a load factor or a communication delay in the network when the in-vehicle communication device is added satisfies a predetermined condition.
[0014] In this aspect, the in-vehicle information processing device performs a simulation to verify whether the network load rate or communication delay when a new in-vehicle information processing device is added satisfies a predetermined condition. The predetermined condition may be, for example, that the load rate or communication delay does not exceed a level that may cause a malfunction in the vehicle's functions. The predetermined condition may be determined in advance by, for example, a designer or administrator of the information processing system according to this embodiment. This is expected to prevent the in-vehicle information processing device from causing malfunctions such as an increase in the load rate or communication delay after updating the routing map.
[0015] (3) It is preferable that the system further includes an acquisition unit that acquires information about the in-vehicle communication device connected to the network, a transmission unit that transmits the acquired information to an external device, and a reception unit that receives update information for the routing map transmitted by the external device in response to the transmission of the information, and that the creation unit creates the routing map based on the received update information.
[0016] In this aspect, the in-vehicle information processing device acquires information (e.g., device identification information) about the in-vehicle communication device connected to the network and transmits the acquired information to the external device. The external device stores various information about devices or functions that can be added to the vehicle in a database. The external device acquires routing map update information about the newly connected in-vehicle communication device from the database based on the information received from the in-vehicle information processing device and transmits it to the in-vehicle information processing device. The update information includes, for example, information to be added to the routing map in order to correctly relay data from or to the in-vehicle communication device. The in-vehicle information processing device that receives the update information creates a new routing map based on the update information. This allows the in-vehicle information processing device to create an appropriate routing map even when a wide variety of in-vehicle communication devices can be connected to the vehicle network.
[0017] (4) When a negative verification result is obtained, it is preferable that the update unit updates the routing map and thins out relays according to the priority of the data.
[0018] In this aspect, if a negative verification result is obtained by the simulation, the in-vehicle information processing device updates the old routing map with a newly created routing map and thins out relays according to the priority of the data. For example, if the priority of data to be relayed is lower than a predetermined threshold, the in-vehicle information processing device can thin out data by discarding the data without relaying it with a predetermined probability. As a result, if updating the routing map is likely to cause a malfunction, the in-vehicle information processing device can reduce the amount of communication by thinning out relays, thereby preventing the occurrence of a malfunction.
[0019] (5) It is preferable that the system comprises a model generation unit that generates a model of the network, a scenario generation unit that generates a scenario for the simulation, and a scenario execution unit that inputs and outputs data to the model according to the scenario, and that the verification unit performs verification based on the data input and output to the model and the internal state of the model.
[0020] In this aspect, the information processing device generates a model of a network to be simulated and a simulation scenario, and performs a simulation by inputting and outputting data to and from the model according to the scenario. The information processing device performs verification based on input and output data to and from the model and the internal state of the model. This makes it possible for the information processing device to widely verify the behavior of a network to which a new in-vehicle communication device has been added through simulations using various scenarios.
[0021] (6) It is preferable that the vehicle is provided with a configuration database that stores configuration information of the on-board communication devices and communication lines installed in the vehicle, and the model generation unit generates the model based on the configuration information stored in the configuration database and the configuration information of the on-board communication devices connected to the network.
[0022] In this aspect, the information processing device includes a configuration database that stores the configuration of the on-board communication device and communication lines installed in the vehicle, etc. Based on the information stored in the configuration database and the configuration information of the on-board communication device newly connected to the vehicle network, the information processing device is expected to generate a model to be used in a simulation for verification, for example, by adding a model of the added on-board communication device to a model of an existing network configuration.
[0023] (7) It is preferable that the vehicle is provided with an operation database that stores the correspondence between the vehicle's operations and the events that occur during each operation, and the scenario generation unit generates the scenario that defines events that occur in chronological order based on the information stored in the operation database and the configuration information of the vehicle-mounted communication device connected to the network.
[0024] In this aspect, the information processing device includes an operation database that stores correspondence between vehicle operations and events that occur during each operation. The information processing device generates a scenario that defines events that occur in chronological order based on the information stored in the operation database and configuration information of an in-vehicle communication device that has been newly connected to the vehicle network. This allows the information processing device to perform simulations that correspond to various vehicle operations.
[0025] (8) It is preferable that the scenario defines events that occur in a chronological order in the network, and that the scenario execution unit generates data to be input to the model based on the chronological events defined in the scenario, inputs the generated data to the model, acquires the data that the model outputs in response to the input of the data, and the internal state of the model when the data is output, and stores the acquired data and internal state.
[0026] In this aspect, the information processing device generates data to be input to a model based on a time-series event defined in a scenario, inputs the generated data to the model, acquires data output by the model and the internal state of the model, and stores the acquired information. This allows the information processing device to be expected to perform a simulation of a vehicle network using the model and the scenario.
[0027] (9) It is preferable that the verification unit calculates the load rate or communication delay related to communication on the network based on the data and internal state stored by the scenario execution unit, and determines whether the simulation result is positive or negative depending on whether the calculated load rate or communication delay satisfies a predetermined standard.
[0028] In this aspect, the information processing device calculates a load factor or a communication delay related to network communication based on the output data and internal state information of the model stored as a result of the simulation, and can determine whether the result of the simulation is positive or negative depending on whether the calculated load factor or communication delay satisfies a predetermined standard.
[0029] (10) The information processing system of this aspect includes an in-vehicle relay device having a relay unit that relays data transmission and reception between multiple communication lines that constitute an in-vehicle network, a detection unit that detects connection of the in-vehicle communication device to the network within the vehicle, a creation unit that, when connection of the in-vehicle communication device is detected, creates a routing map for the in-vehicle relay device that relays data transmission and reception on the network to determine the relay destination of the data, a verification unit that verifies communication of the network using the created routing map by simulation, and an in-vehicle information processing device having an update unit that, when a positive verification result is obtained, updates the routing map held by the in-vehicle relay device to the created routing map.
[0030] In this aspect, similar to the aspect (1), it is expected that problems such as malfunctions occurring after updating the routing map can be suppressed.
[0031] (11) In the information processing method of this aspect, an in-vehicle information processing device detects a connection of an in-vehicle communication device to a network within the vehicle, and when the connection of the in-vehicle communication device is detected, creates a routing map to determine the relay destination of data sent and received on the network, verifies communication on the network using the created routing map by simulation, and if a positive verification result is obtained, updates the routing map.
[0032] In this aspect, similar to the aspect (1), it is expected that problems such as malfunctions occurring after updating the routing map can be suppressed.
[0033] [Details of the embodiment of the present disclosure] Specific examples of information processing systems according to the embodiment of the present disclosure will be described below with reference to the drawings. The present disclosure is not limited to these examples, but is defined by the claims, and is intended to include all modifications within the meaning and scope of the claims.
[0034] <System Configuration> FIG. 1 is a schematic diagram illustrating an example configuration of an information processing system according to this embodiment. The information processing system according to this embodiment includes multiple devices mounted on a vehicle 1, such as an integrated ECU (Electronic Control Unit) 10, a meter ECU 51, a brake ECU 52, an expansion IF (Interface) 53, and an exterior communication device 54. These multiple devices are connected via multiple communication lines 71-74 arranged within the vehicle 1 to form an in-vehicle network capable of transmitting and receiving data to and from each other. In the illustrated example, four communication lines 71-74 are connected to the integrated ECU 10, with the meter ECU 51 connected to communication line 71, the brake ECU 52 connected to communication line 72, the expansion IF 53 connected to communication line 73, and the exterior communication device 54 connected to communication line 74. Note that in the illustrated example, two devices are connected to each of the communication lines 71-74, but three or more devices may be connected to each of the communication lines 71-74.
[0035] The integrated ECU 10 according to this embodiment integrates the functions of three devices into a single device: a gateway 11 that relays data transmission and reception; an ADAS (Advanced Driver Assistance Systems)-ECU 12 that performs processing related to driving assistance; and a verification device 13 that performs verification related to communication. In other words, the integrated ECU 10 includes a virtual gateway 11, ADAS-ECU 12, and verification device 13. The gateway 11 and the ADAS-ECU 12 are connected via a virtual communication line 75, and the gateway 11 and the verification device 13 are connected via a virtual communication line 76. In this diagram, the virtual function blocks and communication lines are indicated by dashed lines. The gateway 11, the ADAS-ECU 12, and the verification device 13 may be mounted on the vehicle 1 as separate devices.
[0036] The integrated ECU 10 can transmit and receive data to and from the meter ECU 51, the brake ECU 52, the expansion IF 53, and the exterior communication device 54 via these communication lines 71 to 74. The meter ECU 51, the brake ECU 52, the expansion IF 53, and the exterior communication device 54 can each transmit and receive data to and from the integrated ECU 10. The integrated ECU 10 also relays data transmission and reception between the four communication lines 71 to 74. This allows the meter ECU 51, the brake ECU 52, the expansion IF 53, and the exterior communication device 54 to transmit and receive data to and from each other via the integrated ECU 10.
[0037] The meter ECU 51 controls various meters provided near the driver's seat of the vehicle 1. The meter ECU 51 controls the meters based on various information within the vehicle 1 obtained via the in-vehicle network. For example, the meter ECU 51 controls the display of a speedometer based on information on the traveling speed of the vehicle 1 obtained via the in-vehicle network. Furthermore, for example, the meter ECU 51 controls the display of a tachometer based on information on the number of revolutions or rotation speed of the engine of the vehicle 1 obtained via the in-vehicle network.
[0038] The brake ECU 52 controls the brakes of the vehicle 1. For example, the brake ECU 52 activates the brakes in response to the driver's operation of a foot brake or a parking brake provided at the driver's seat of the vehicle 1. Information regarding the presence or absence of an operation of the foot brake or the parking brake and the amount of operation may be input directly to the brake ECU 52 or may be provided to the brake ECU 52 via an in-vehicle network. Furthermore, for example, the brake ECU 52 activates the brakes in response to a command provided from the ADAS-ECU 12 via the in-vehicle network.
[0039] The expansion IF 53 is used to connect an expansion ECU 61 that will handle a function when, for example, adding a function to the vehicle 1. In this example, the expansion IF 53 is connected to a communication line 73, and has a connection terminal or a slot for connecting the expansion ECU 61. When the expansion IF 53 detects that the expansion ECU 61 has been connected, it notifies the integrated ECU 10 of the connection detection via the communication line 73.
[0040] The expansion ECU 61 is configured to be detachable from the expansion IF 53, and when attached to the expansion IF 53, it is connected to a communication line 73 of the vehicle 1 and can communicate via the communication line 73. The expansion ECU 61 may be configured to perform any expansion function of the vehicle 1. In this example, the expansion ECU 61 has a sensor 62 that detects obstacles and the like present outside the vehicle 1, and performs processing to periodically obtain detection results of the sensor 62 and transmit them to other devices within the vehicle 1. This allows the vehicle 1 to be provided with additional functions, such as monitoring the surroundings of the vehicle 1 or avoiding obstacles, using the sensor 62.
[0041] The exterior communication device 54 is a device that communicates with various devices installed outside the vehicle 1 by wireless communication, such as via a mobile phone communication network or a wireless local area network (LAN). In this embodiment, the exterior communication device 54 communicates with a server device 3 installed outside the vehicle 1. The exterior communication device 54 is connected to the integrated ECU 10 via a communication line 74, and transmits data from the integrated ECU 10 to the server device 3 and provides data from the server device 3 to the integrated ECU 10.
[0042] The server device 3 according to this embodiment stores information about various devices mounted on the vehicle 1 in a database, and distributes programs, data, etc. required by the various devices mounted on the vehicle 1. For example, when a new extension ECU 61 is connected to the network of the vehicle 1, information about the extension ECU 61 is transmitted from the vehicle 1 to the server device 3. Upon receiving this information, the server device 3 transmits programs, data, etc. for using the extension ECU 61 to the vehicle 1.
[0043] The gateway 11, which is virtually provided within the integrated ECU 10, relays data between a plurality of communication lines, namely, the communication lines 71 to 74 and the communication lines 75 and 76. In the information processing system according to this embodiment, an ID is assigned to data to be transmitted and received, and the gateway 11 has a routing map in which the ID assigned to the data is associated with the communication line through which the data should be relayed. When the gateway 11 receives data from any of the communication lines, it refers to the routing map based on the ID assigned to the data, and transmits the data from the communication line set as the relay destination in the routing map, thereby relaying the data between the plurality of communication lines.
[0044] The ADAS-ECU 12 is a device that realizes driving assistance or automatic driving by controlling the driving of the vehicle 1 based on information obtained from various sensors mounted on the vehicle 1. For example, the ADAS-ECU 12 measures the distance to the vehicle ahead using a sensor mounted on the vehicle 1, and controls the accelerator and brake of the vehicle 1 so that the vehicle 1 drives while maintaining a constant inter-vehicle distance. Note that the control performed by the ADAS-ECU 12 is not limited to control for maintaining an inter-vehicle distance, and may be control related to various driving assistance or automatic driving.
[0045] The verification device 13 is a device that verifies whether the extension ECU 61 can be connected when the extension ECU 61 is attached to the extension IF 53 and connected to the communication line 73. In the information processing system according to this embodiment, when the extension ECU 61 is connected to the communication line 73, the gateway 11 needs to update the routing map used to determine the data relay destination. This is necessary, for example, to relay data transmitted by the extension ECU 61 to other devices and to relay data transmitted from other devices to the extension ECU 61. When the extension ECU 61 is connected, the verification device 13 creates a new routing map and verifies communication within the vehicle 1 using the new routing map through a simulation. When a positive verification result is obtained through the simulation (for example, a verification result indicating that no abnormalities or the like will occur), the verification device 13 updates the routing map held by the gateway 11 to the new routing map.
[0046] 2 is a block diagram showing an example of the configuration of the integrated ECU 10 according to this embodiment. The integrated ECU 10 according to this embodiment is configured to include a processing unit (processor) 21, a memory unit (storage) 22, and a communication unit (transceiver) 23. The processing unit 21 is configured using an arithmetic processing device such as a CPU (Central Processing Unit) or an MPU (Micro-Processing Unit). The processing unit 21 can perform various processes by reading and executing a program 22a stored in the memory unit 22. In this embodiment, the processing unit 21 performs processes related to three devices: the gateway 11, the ADAS-ECU 12, and the verification device 13.
[0047] The storage unit 22 is configured using a non-volatile memory element such as a flash memory or an EEPROM (Electrically Erasable Programmable Read Only Memory). The storage unit 22 stores various programs executed by the processing unit 21 and various data required for the processing of the processing unit 21. In this embodiment, the storage unit 22 stores a program 22a executed by the processing unit 21, a routing map 22b used by the gateway 11 to determine a data relay destination, and verification information 22c required when the verification device 13 performs verification.
[0048] The program (program product) 22a may be written to the storage unit 22 during the manufacturing stage of the integrated ECU 10, for example, or may be distributed by a remote server device or the like and acquired by the integrated ECU 10 via communication, or the integrated ECU 10 may read a program recorded on a recording medium 99 such as a memory card or an optical disk and store it in the storage unit 22, or a writing device may read a program recorded on the recording medium 99 and write it to the storage unit 22 of the integrated ECU 10. The program 22a may be provided in the form of distribution via a network or in the form of being recorded on the recording medium 99.
[0049] The routing map 22b is information used when the integrated ECU 10 performs relay processing as the gateway 11. In the information processing system according to this embodiment, data transmitted and received over the network of the vehicle 1 is assigned an ID for identifying the type of data, etc. The routing map 22b is information indicating, for example, the correspondence between the ID assigned to the data and the communication lines 71 to 76 through which the data with this ID should be transmitted. When the gateway 11 receives data over any of the communication lines 71 to 76, it can obtain the ID assigned to the received data and obtain from the routing map 22b which communication line 71 to 76 is the relay destination corresponding to this ID.
[0050] The verification information 22c is information used when the integrated ECU 10 performs verification processing as the verification device 13. The verification information 22c may include, for example, information such as the network configuration of the vehicle 1, the ID, period, and size of data transmitted by each device, and the ID of data required by each device. The verification information 22c includes information necessary and sufficient for the verification device 13 to simulate communication over the network of the vehicle 1. Furthermore, when a new extension ECU 61 is connected, information about the extension ECU 61 is acquired from the server device 3 and added to and stored in the verification information 22c. The verification device 13 reads out the verification information 22c, reproduces the network of the vehicle 1 in a simulation environment, and verifies whether or not a problem occurs in communication when a newly created routing map is applied.
[0051] In this embodiment, the integrated ECU 10 has four communication units 23. Each communication unit 23 is connected to one of communication lines 71 to 74 and communicates with other devices via these communication lines 71 to 74. The communication units 23 transmit and receive data according to a communication protocol such as a Controller Area Network (CAN) or Ethernet (registered trademark). Each communication unit 23 may be configured using an integrated circuit (IC) such as a CAN controller or an Ethernet switch. The communication units 23 transmit the digital data provided by the processing unit 21 by converting the digital data into an electrical signal and outputting the electrical signal to the communication lines 71 to 74. The communication units 23 sample and acquire the potentials of the communication lines 71 to 74, converting the electrical signals on the communication lines into digital data, and providing the converted data to the processing unit 21 as received data. Note that, although the integrated ECU 10 has four communication units 23 in this example, the number is not limited thereto, and the integrated ECU 10 may have three or fewer or five or more communication units 23.
[0052] In the integrated ECU 10 of this embodiment, the processing unit 21 reads and executes a program 22a stored in the storage unit 22, whereby a gateway processing unit 21a, an ADAS processing unit 21b, a verification processing unit 21c, and the like are realized as software functional units in the processing unit 21. The gateway processing unit 21a of the processing unit 21 performs processing equivalent to the virtual gateway 11 described above, the ADAS processing unit 21b performs processing equivalent to the ADAS-ECU 12, and the verification processing unit 21c performs processing equivalent to the verification device 13.
[0053] The gateway processing unit 21a receives data transmitted by other devices via the communication lines 71 to 76 and transmits the received data from the appropriate communication line 71 to 76, thereby relaying the transmission and reception of data between the communication lines 71 to 76. The gateway processing unit 21a determines the relay destination of the data based on the ID included in the received data by referring to the routing map 22b stored in the storage unit 22. Furthermore, when the communication protocols of the data relay source and relay destination are different, the gateway processing unit 21a may convert the data to be relayed into a format suitable for each communication protocol.
[0054] The ADAS processing unit 21b performs processing related to driving assistance or automatic driving of the vehicle 1. For example, the ADAS processing unit 21b controls the accelerator and brake of the vehicle 1 to maintain a constant inter-vehicle distance. For example, the ADAS processing unit 21b warns the driver when a vehicle ahead, photographed by a camera, suddenly brakes. For example, the ADAS processing unit 21b performs control to activate the brakes to stop the vehicle 1 when a collision with a vehicle ahead or an obstacle cannot be avoided by warning the driver. These controls by the ADAS processing unit 21b are merely examples and are not limited to these. The ADAS processing unit 21b may perform any control related to driving assistance or automatic driving.
[0055] When an extension ECU 61 is attached to the extension IF 53 and connected to the network of the vehicle 1, the verification processing unit 21c generates a new routing map 22b and verifies communication using the generated routing map 22b. The verification processing unit 21c acquires information such as a device ID from the newly connected extension ECU 61 and transmits it to the server device 3 outside the vehicle 1, requesting transmission of information necessary for verifying the extension ECU 61. In response to this request, the server device 3 acquires information necessary for verifying the extension ECU 61 from a database and transmits it to the integrated ECU 10. The verification processing unit 21c acquires the information from the server device 3 and adds it to the verification information 22c in the storage unit 22 for storage.
[0056] Next, the verification processing unit 21c creates a new routing map corresponding to the new extended ECU 61 based on the routing map 22b stored in the storage unit 22 and the verification information 22c acquired from the server device 3. The verification information 22c stores, for example, the ID of data transmitted by the extended ECU 61 in association with the ID of a device that is to receive the data. The verification information 22c also stores, for example, the ID of data required by the extended ECU 61. Based on the verification information 22c, the verification processing unit 21c can determine to which of the communication lines 71 to 76 the data transmitted by the extended ECU 61 should be relayed. The verification processing unit 21c also determines which of the data transmitted by devices already installed in the vehicle 1, such as the meter ECU 51 and the brake ECU 52, should be relayed to the communication line 73 to which the extended ECU 61 is connected. The verification processing unit 21c creates a new routing map based on the determined relay destination.
[0057] In this embodiment, the routing map is created by the verification processing unit 21c (verification device 13), but this is not limitative. The routing map may be created by the gateway processing unit 21a (gateway 11) or another processing unit (another device).
[0058] Next, the verification processing unit 21c verifies the validity of the newly created routing map through a simulation. The verification information 22c includes information such as the network configuration of the vehicle 1, the ID, period, and size of data transmitted by each device, and the ID of data required by each device. Based on this verification information 22c, the verification processing unit 21c constructs a virtual network of the vehicle 1 to be simulated in a simulation environment. The verification processing unit 21c performs a simulation in which each device transmits and receives data in the virtual network at the period and size set in the verification information 22c. In the simulation, the verification processing unit 21c measures the amount and frequency of data transmitted and received on the network of the vehicle 1, thereby calculating values such as the communication load on each communication line 71 to 76 or the maximum delay time for each piece of data. The verification processing unit 21c determines the validity of the new routing map by determining whether these calculated values satisfy predetermined conditions. If a positive verification result (a verification result that satisfies the specified conditions) is obtained, the verification processing unit 21c updates the routing map 22b by overwriting the routing map 22b stored in the memory unit 22 with a new routing map and storing it.
[0059] On the other hand, if a negative verification result (a verification result that does not satisfy the predetermined condition) is obtained, the verification processing unit 21c performs verification, for example, by simulation, of a case where data relay by the gateway processing unit 21a (gateway 11) is thinned, and determines whether the predetermined condition is satisfied. In the information processing system according to this embodiment, an ID attached to each piece of data transmitted and received indicates the type of the data and its priority. The data ID is, for example, a numerical value with a predetermined number of digits, and the lower the value, the higher the priority. The verification processing unit 21c performs verification of a case where data is thinned in order of lowest priority, and determines data that needs to be thinned to satisfy the predetermined condition. Methods for thinning data relay may include, for example, discarding data without relaying once every predetermined number of times, or discarding data without relaying with a predetermined probability. The verification processing unit 21c notifies the gateway processing unit 21a (gateway 11) of the ID of data determined to need to be thinned, and causes the gateway processing unit 21a to thin out data with this ID and relay it thereafter.
[0060] In the present embodiment, if a negative verification result is obtained by the simulation, the verification processing unit 21c reduces the relaying of data by the gateway 11, but this is not limited to this. For example, the verification processing unit 21c may reduce the frequency of data transmission to one or more devices connected to the network of the vehicle 1. Furthermore, for example, the verification processing unit 21c may display a message on the display of the vehicle 1 that rejects the connection of the newly connected extension ECU 61, without updating the routing map 22b.
[0061] After the verification of the simulation and the updating of the routing map 22b are completed, the verification processing unit 21c notifies the server device 3 of this fact and transmits information such as the updated network configuration and routing map of the vehicle 1 to the server device 3. The server device 3 receives this information and stores the received information in a database in association with the identification information of the vehicle 1, etc. The server device 3 also determines whether or not the programs of each device installed in the vehicle 1 need to be updated due to the addition of the extension ECU 61, and if it determines that an update is necessary, transmits the update program to the vehicle 1. The integrated ECU 10 appropriately transmits the update program from the server device 3 to each device that requires it, and causes each device to update its program.
[0062] <Function Expansion Processing> Figure 3 is a schematic diagram illustrating the procedure of the function expansion processing performed by the information processing system according to this embodiment. In the information processing system according to this embodiment, a user or the like connects an expansion ECU 61 to the expansion IF 53 that constitutes the network of the vehicle 1, thereby expanding the functions of the vehicle 1. When the expansion IF 53 detects that the expansion ECU 61 has been connected, it notifies the verification device 13 of the integrated ECU 10 of this fact. At this time, the expansion IF 53 acquires information such as an ID from the expansion ECU 61 and transmits this information to the verification device 13 along with a connection detection notification. The notification data transmitted by the expansion IF 53 is received by the verification device 13 via the communication line 73, the gateway 11 of the integrated ECU 10, and the communication line 76.
[0063] Upon receiving the notification from the extension IF 53, the verification device 13 acquires the ID of the extension ECU 61 contained in the notification. The verification device 13 notifies the server device 3 by transmitting the acquired ID. The data including the ID transmitted by the verification device 13 at this time is received by the server device 3 provided outside the vehicle 1 via the communication line 76, the gateway 11, the communication line 74, and the external communication device 54.
[0064] In the information processing system according to this embodiment, the server device 3 stores information about various devices that may be additionally connected to the vehicle 1 in a database. The information stored in the database may include, for example, information such as the ID, size, and transmission cycle of data transmitted by the device, as well as information such as the ID of data required by the device. When the server device 3 receives notification of the ID of an additionally connected extension ECU 61 from the vehicle 1, it reads information stored in the database corresponding to the ID and transmits the read information to the vehicle 1 that transmitted the ID. The information transmitted by the server device 3 is received by the verification device 13 via the vehicle 1's external communication device 54, the communication line 74, the gateway 11 of the integrated ECU 10, and the communication line 76.
[0065] The verification device 13, which receives information from the server device 3, creates a new routing map based on the received information. Fig. 4 is a schematic diagram showing an example of a routing map. The routing map shown in the upper part of Fig. 4 stores information such as "type," "ID," "relay source," "relay destination," and "thinning out" in association with each other. "Type" is the type of information included in the data transmitted and received over the network of the vehicle 1, and types such as "mileage," "vehicle speed," "speed warning," or "abnormal water temperature" may be set. However, "type" information does not have to be included in the routing map.
[0066] The "ID" in the routing map is identification information attached to the data being transmitted and received. The "ID" is also used as information indicating the priority of the data, with a smaller value indicating a higher priority. For example, if the CAN communication protocol is used in the network of the vehicle 1, a CAN-ID may be used as the "ID." In this example, a hexadecimal number is set as the "ID."
[0067] Information identifying multiple communication lines connected to the gateway 11 is set in the "relay source" and "relay destination" of the routing map. In this example, "communication lines 71 to 76" are written as identification information for the communication lines, using the symbols shown in FIG. 1. The "relay source" refers to the communication lines 71 to 76 from which the gateway 11 receives its data, and the "relay destination" refers to the communication lines 71 to 76 from which the gateway 11 transmits that data. For example, data with an "ID" of "0B2" and a "type" of "mileage" is transmitted to the gateway 11 from a device connected to the "relay source" "communication line 72," and the gateway 11 that receives this data then transmits it from the "relay destination" "communication line 71."
[0068] The "thinning out" field of the routing map is set to either "yes" or "no" to indicate whether or not to perform thinning out of the corresponding data. The gateway 11 performs thinning out of the data for which the "thinning out" field of the routing map is set to "yes" by reducing the frequency of relaying.
[0069] The lower part of FIG. 4 shows an example of a new routing map created by the verification device 13 by adding the extension ECU 61 to the routing map shown in the upper part of FIG. 4. In this example, the addition of the extension ECU 61 adds three types of data to be transmitted and received over the in-vehicle network: "sonar data," "auto-brake request," and "obstacle warning request." Upon receiving notification of the addition of the extension ECU 61, the server device 3 transmits, for example, "sonar data" with an "ID" of "501" from the extension ECU 61 and transmits information indicating that the ADAS-ECU 12 will use this data to the verification device 13. The verification device 13 can add the "sonar data" information shown in the lower part of FIG. 4 to the routing map shown in the upper part of FIG. 4 based on the information from the server device 3 and the network configuration of the vehicle 1 (the extension ECU 61 is connected to the communication line 73 and the ADAS-ECU 12 is connected to the communication line 75).
[0070] In this example, the addition of the extension ECU 61 also adds auto-brake and obstacle warning functions to the vehicle 1. In connection with this function addition, the server device 3 transmits, for example, "auto-brake request" data with an "ID" of "0B2" from the ADAS-ECU 12, and transmits information indicating that the brake ECU 52 will use this data to the verification device 13. The server device 3 also transmits, for example, "obstacle warning request" data with an "ID" of "202" from the ADAS-ECU 12, and transmits information indicating that the meter ECU 51 will use this data to the verification device 13. Based on this information from the server device 3 and the network configuration of the vehicle 1, the verification device 13 can add the "auto-brake request" and "obstacle warning request" information shown in the lower part of FIG. 4 to the routing map shown in the upper part of FIG. 4.
[0071] In this example, the verification device 13 creates a new routing map by adding information to an existing routing map, but this is not limiting. The verification device 13 may create a new routing map by changing some or all of the information contained in an existing routing map, or may create a new routing map by deleting some of the information contained in an existing routing map. The verification device 13 may create a new routing map by appropriately combining addition, modification, and deletion of information from an existing routing map, or may create a new routing map from scratch without using an existing routing map.
[0072] The verification device 13, which has created a new routing map based on information received from the server device 3 in response to the addition of the extension ECU 61, performs a simulation to verify communication in the in-vehicle network when the created new routing map is applied, as shown in FIG. 3 . At this time, the verification device 13 performs a simulation of communication in the in-vehicle network using verification information 22c stored in the storage unit 22. The verification information 22c may include, for example, information on which devices are connected to each of the communication lines 71 to 76 constituting the network of the vehicle 1, the communication speeds of each of the communication lines 71 to 76, and the ID, period, and size of data transmitted by each device. The information transmitted from the server device 3 also includes similar information necessary for simulation verification regarding data transmitted and received by the extension ECU 61 and data added to the in-vehicle network in response to the addition of functions based on the extension ECU 61. The verification device 13 adds the information received from the server device 3 to the verification information 22c in the storage unit 22 and stores it.
[0073] The verification device 13 reproduces the network of the vehicle 1 in, for example, a simulation environment based on information about the network configuration of the vehicle 1 included in the verification information 22c. The verification device 13 simulates, for example, the flow of data when each device in the reproduced network transmits data at a period and size specified in the verification information 22c. The verification device 13 calculates, for example, the proportion of time during which data is being transmitted and received on each communication line 71 to 76 relative to the total time of the simulation as the communication load factor, and calculates the average value of the communication load factors of the multiple communication lines 71 to 76 as the average load factor. The verification device 13 determines whether the calculated average load factor satisfies a predetermined condition (for example, 70% or less).
[0074] Furthermore, for each piece of data transmitted and received over the network of the vehicle 1, the verification device 13 calculates the delay time from when the data is transmitted from a transmitting device until when the data is received by a receiving device. The verification device 13 calculates this delay time for all data transmitted and received in the simulation and obtains the longest delay time as the maximum delay time. The verification device 13 determines whether this maximum delay time satisfies a predetermined condition (e.g., 3 milliseconds or less). Note that the network characteristic values calculated by the verification device 13 through the simulation are not limited to the average load rate or maximum delay time described above. The verification device 13 may calculate various characteristic values, such as the amount of data transmitted and received over each communication line 71-76 or the frequency of arbitration occurring when multiple devices simultaneously transmit data over each communication line 71-76. The verification device 13 may perform any condition determination on the calculated characteristic values.
[0075] If a positive verification result is obtained by a simulation using the newly created routing map, the verification device 13 transmits the new routing map to the gateway 11. Upon receiving the new routing map from the verification device 13, the gateway 11 updates the routing map 22b by overwriting the previous routing map 22b with the new routing map. Note that in the information processing system according to this embodiment, both the verification device 13 and the gateway 11 exist within the integrated ECU 10. Therefore, if the verification device 13 can rewrite the routing map 22b stored in the storage unit 22, the verification device 13 may update the routing map 22b.
[0076] After updating the routing map 22b, the gateway 11 transmits information such as the updated routing map 22b and the network configuration of the vehicle 1 to the server device 3 to notify the server device 3 that the routing map 22b has been updated. The information transmitted by the gateway 11 is received by the server device 3 via the communication line 74 and the exterior communication device 54. Upon receiving this information, the server device 3 stores the received information in a database in association with information such as an ID that identifies the vehicle 1. The database of the server device 3 stores information such as the network configuration of the vehicle 1, the types of devices installed in the vehicle 1, and the versions of programs installed in each device. Based on the information received from the gateway 11, the server device 3 determines whether a program update (or installation, etc.) is required for one or more devices installed in the vehicle 1. If it is determined that an update is required, the server device 3 reads an update program from the database, etc., and transmits it to the vehicle 1. The update program transmitted by the server device 3 is received by the gateway 11 via the exterior communication device 54 of the vehicle 1 and the communication line 74. The gateway 11 transmits the update program received from the server device 3 to the device that requires it, and causes the program to be updated.
[0077] 3, if a negative verification result is obtained by a simulation using a newly created routing map, the verification device 13 may, for example, perform a further simulation to determine data for which relaying should be thinned. The verification device 13 sets "thinning out" in the routing map for the data for which thinning out has been determined to be performed to "yes" and transmits this routing map to the gateway 11. Furthermore, if a negative verification result is obtained, the verification device 13 may, for example, not update the routing map, but instead cause the meter ECU 51 to display a warning message or the like and prompt the user to remove the extension ECU 61, for example.
[0078] In the routing map shown in the lower part of Figure 4, a negative verification result was obtained through simulation, and it was decided to perform thinning processing on two pieces of data, "Water Temperature Abnormality" and "Sonar Data," which have large "ID" values (low priority), and "Thinning" is set to "Yes."
[0079] 5 is a flowchart illustrating an example of a processing procedure performed by the verification device 13 according to the present embodiment. The verification device 13 according to the present embodiment determines whether or not connection of the extension ECU 61 to the extension IF 53 has been detected based on the presence or absence of a notification from the extension IF 53 (step S1). If connection of the extension ECU 61 has not been detected (S1: NO), the verification device 13 waits until connection of the extension ECU 61 has been detected (S1: YES). If connection of the extension ECU 61 has been detected (S1: YES), the verification device 13 acquires information, such as the ID of the connected extension ECU 61, from information transmitted from the extension IF 53 (step S2). The verification device 13 transmits the information, such as the ID, acquired in step S2 to the server device 3 via the external communication device 54, thereby requesting information about the extension ECU 61 from the server device 3 (step S3).
[0080] The verification device 13 receives the information transmitted from the server device 3 in response to the request of step S3 via the exterior communication device 54 (step S4). The verification device 13 adds some or all of the information received in step S4 to the verification information 22c in the storage unit 22 and stores the added information (step S5). The verification device 13 creates a new routing map based on the current routing map 22b stored in the storage unit 22 and the information acquired in step S4 (step S6). The verification device 13 reads the verification information 22c stored in the storage unit 22 to verify the routing map created in step S6 (step S7). The verification device 13 builds a network for the vehicle 1 in a simulation environment based on the verification information 22c read in step S7, and verifies the accuracy of the newly created routing map by simulating communication in accordance with the routing map created in step S6 (step S8).
[0081] The verification device 13 determines whether a positive verification result was obtained by the simulation verification in step S8 (step S9). If a positive verification result was obtained (S9: YES), the verification device 13 updates the routing map used by the gateway 11 by sending the routing map created in step S6 to the gateway 11 (step S11), and ends the process. On the other hand, if a positive verification result was not obtained (S9: NO), i.e., if a negative verification result was obtained, the verification device 13, for example, repeats the simulation to determine data to be thinned out from relaying by the gateway 11, and sets the gateway 11 to thin out data relaying (step S10). Thereafter, the verification device 13 updates the routing map (step S11), and ends the process.
[0082] <Summary> In the information processing system according to the present embodiment configured as described above, when the verification device 13 of the integrated ECU 10 detects the connection of the extension ECU 61 to the network within the vehicle 1, the gateway 11 creates a routing map for determining the data relay destination. The verification device 13 verifies network communication according to the created routing map by simulation, and updates the routing map 22b when a positive verification result is obtained. This is expected to prevent the information processing system from causing communication problems or the like when the extension ECU 61 is added to the network of the vehicle 1.
[0083] In the information processing system according to the present embodiment, the verification device 13 calculates communication characteristics, such as the average load factor or the maximum delay time of transmitted and received data, for each of the communication lines 71 to 76 of the network when the extension ECU 61 is added. The verification device 13 verifies whether these calculated values satisfy predetermined conditions. This is expected to prevent the information processing system from causing communication problems, etc., due to an increase in the average load factor or the maximum delay time caused by the addition of the extension ECU 61.
[0084] Furthermore, in the information processing system according to this embodiment, the verification device 13 acquires information such as an ID relating to an extension ECU 61 that has been newly connected to the network of the vehicle 1 and transmits the information to the server device 3 provided outside the vehicle 1. In response to this, the verification device 13 receives information for updating the routing map transmitted from the server device 3, and creates a routing map based on the received information. This eliminates the need for the information processing system to store information relating to the wide variety of devices that may be added to the network of the vehicle 1 within the vehicle 1.
[0085] Furthermore, in the information processing system according to this embodiment, if a negative verification result is obtained by the simulation, the routing map is updated and data relay by the gateway 11 is thinned out in accordance with the priority of the data. As a result, in the case where the addition of the extension ECU 61 may result in an increase in the amount of communication on the network within the vehicle 1, the information processing system is expected to suppress the increase in the amount of communication by thinning out the relay by the gateway 11.
[0086] In the present embodiment, the gateway 11 and the verification device 13 are mounted on the vehicle 1 as a single device (integrated ECU 10), but the present invention is not limited to this. The gateway 11 and the verification device 13 may be mounted on the vehicle 1 as separate devices. The server device 3 provided outside the vehicle 1 is configured to hold information necessary for creating a routing map and performing verification by simulation, but the present invention is not limited to this. Such information may be held by any device within the vehicle 1, such as the verification device 13 or the gateway 11. Furthermore, the verification device 13 may acquire such information via a recording medium, such as a memory card or an optical disk.
[0087] 6 is a schematic diagram for explaining an outline of a simulation performed in the information processing system according to this embodiment. In the information processing system according to this embodiment, the verification device 13 (verification processing unit 21c) provided in the integrated ECU 10 mounted on the vehicle 1 performs verification by simulation.
[0088] The verification device 13 includes a model generation unit 131, a scenario generation unit 132, a scenario execution unit 133, etc. The verification device 13 also includes a vehicle DB (database) 141 and a use case DB 142 that store information necessary for performing a simulation. In this embodiment, the verification device 13 is a device virtually provided within the integrated ECU 10, and the model generation unit 131, the scenario generation unit 132, and the scenario execution unit 133 are functional blocks provided in the verification processing unit 21c of the processing unit 21 of the integrated ECU 10 shown in Figure 2. The information stored in the vehicle DB 141 and the use case DB 142 corresponds to the verification information 22c in the storage unit 22 of the integrated ECU 10 shown in Figure 2.
[0089] The model generation unit 131 performs processing to generate a network model 145 to be used in the simulation based on information stored in the vehicle DB 141 and information obtained from the server device 3. Here, the model generation unit 131 generates a network model 145 having a configuration in which the additional device is connected to the existing network of the vehicle 1, based on the configuration of the existing on-board devices and communication lines, etc. stored in the vehicle DB 141 and information on the additional device obtained from the server device 3. The vehicle DB 141 is a database that stores the configuration of the communication devices and communication lines, etc., installed in the vehicle 1. For example, the vehicle DB 141 stores the configuration of the vehicle 1 shown in FIG. 1 , such as the integrated ECU 10, the meter ECU 51, the brake ECU 52, the extension IF 53, the external communication device 54, and the communication lines 71 to 74. For example, in the case of the vehicle 1 shown in FIG. 1 , the information obtained from the server device 3 includes information on the configuration of the extension ECU 61 connected to the extension IF 53 and information on an updated routing map accompanying the addition of the extension ECU 61.
[0090] The scenario generation unit 132 performs processing to generate a simulation scenario 146 based on the information stored in the vehicle DB 141, the information stored in the use case DB 142, and the information obtained from the server device 3. The use case DB 142 is an operation database that stores correspondence between various operations performed in the vehicle 1 and events that occur during each of these operations.
[0091] The scenario execution unit 133 executes the scenario 146 to perform a simulation based on the network model 145 generated by the model generation unit 131 and the scenario 146 generated by the scenario generation unit 132. The scenario execution unit 133, for example, inputs input data according to the scenario 146 to the network model 145 and acquires output data output by the network model 145 in accordance with this input data. The scenario execution unit 133 manages the time in the simulation and executes the scenario 146 by repeatedly inputting and outputting data to the network model 145 as time passes. The scenario execution unit 133 also acquires information such as the internal state of the network model 145 that changes as the scenario is executed. The scenario execution unit 133 outputs this information obtained by executing the scenario 146 as an operation log 147.
[0092] The verification device 13 calculates the load factor, delay time, etc. of the network model 145 based on the operation log 147 output by the scenario execution unit 133, and determines whether these calculated values satisfy predetermined criteria. The verification device 13 determines that a positive verification result has been obtained if the calculated values satisfy the criteria, and determines that a negative verification result has been obtained if the criteria are not satisfied.
[0093] 7 is a schematic diagram illustrating an example of a network model 145 generated by the model generation unit 131. The illustrated network model 145 illustrates a portion of a model of the configuration of the vehicle 1 shown in FIG. 1. The illustrated network model 145 includes, for example, a virtual gateway that virtually reproduces the gateway 11 of the vehicle 1, and virtual ECUs that virtually reproduce the meter ECU 51, brake ECU 52, etc. The network model 145 includes information on virtual communication devices such as these virtual gateways and virtual ECUs, and virtual communication lines connecting them.
[0094] Information such as the number of communication ports, the type of communication port, the amount of memory installed, and the CPU processing capacity is set for the virtual communication device of the network model 145. Furthermore, the internal state of the virtual communication device, such as status information such as the power supply state, the presence or absence of a failure, the passage of time, and the CPU state, is managed.
[0095] Furthermore, each virtual communication device is set to perform an operation in the simulation. In the network model 145 of FIG. 7 , the operation of the virtual gateway is illustrated by functional blocks. In the virtual gateway of this example, for example, the receiving unit receives data transmitted from a virtual ECU and stores it in a receiving buffer. The relay unit acquires the data from the receiving buffer, determines a relay destination according to a routing map, stores the data in a relay buffer, and when the time to transmit arrives, acquires the data from the relay buffer and stores it in a transmitting buffer. The transmitting unit transmits the data stored in the transmitting buffer in sequence. The contents of the receiving buffer, relay buffer, and transmitting buffer of the illustrated virtual gateway are treated as internal state information of the virtual gateway in the simulation.
[0096] 8 is a schematic diagram showing an example of the configuration of the use case DB 142. The use case DB 142 according to this embodiment is a database that stores information such as "use cases," "prerequisites," and "occurring events" in association with each other. "Use cases" are operations that can be performed in the vehicle 1, and are classified into types such as "when adding a function," "when connecting the battery," "unlocking from outside the vehicle while parked," "when starting the engine," "when starting to drive," and "when stopping the engine, getting out of the vehicle, and locking the vehicle."
[0097] The "preconditions" are information indicating the state of the vehicle 1 when the operation of the "use case" is performed, and the conditions that are the preconditions for simulating this "use case" are stored. For example, the "preconditions" for "when adding a function" are "all existing devices: powered on, initialization completed" and "additional devices: powered off, initialization not completed." Also, for example, the "preconditions" for "when connecting a battery" are "all existing devices: powered off, initialization not completed."
[0098] "Occurring events" is information that lists multiple events included in the operation of a "use case" in chronological order. "Occurring events" when "function is added" may include events such as "added device: power on," "added device: initialization start," "added device: initialization complete," "all existing devices: periodic transmission start," and "added device: device registration sequence start." Furthermore, "occurring events" when "battery is connected" may include events such as "all existing devices: power on," "all existing devices: initialization start," "all existing devices: initialization complete," and "all existing devices: periodic transmission start."
[0099] The scenario generation unit 132 of the verification device 13 according to this embodiment generates scenarios for performing simulations for all "use cases" registered in the use case DB 142. For example, for one "use case," the scenario generation unit 132 can generate a scenario by generating instructions for setting the internal state of the network model 145 so as to satisfy the "preconditions," and time-series input data for the network model 145 for generating each event stored in time series in the "occurring event." The scenario generation unit 132 can also generate input data for events based on the structures of the network and each device stored in the vehicle DB 141.
[0100] 9 is a schematic diagram showing an example of a scenario 146. The scenario 146 generated by the scenario generation unit 132 according to this embodiment is a scenario in which information for multiple steps is arranged in chronological order, with one step being an association of information such as "time," "event type," "source," "destination," "ID," and "data length."
[0101] The "time" of scenario 146 is the time in the simulation managed by the scenario execution unit 133, and the event of this step occurs at the corresponding time in the simulation. The "event type" is the type of event that occurs in this step, and various event types such as "CAN transmission" or "user interrupt" can be set. The "source" can be set to the ID of the device that transmits data over the communication line in communication. The "destination" can be set to the ID of the device that receives data in communication. The "ID" is the ID assigned to the data that is transmitted and received, and in the case of CAN communication, a CAN-ID can be used. The "data length" is the length of the data that is transmitted and received, and can be set to a numerical value in units such as bytes.
[0102] The scenario execution unit 133 of the verification device 13 manages the time in the simulation, the state of each device included in the network, etc., and performs the simulation by executing, step by step, events set in the scenario 146 generated by the scenario generation unit 132. The scenario execution unit 133 generates input data for the network model 145 generated by the model generation unit 131, based on information for one step of the scenario 146. The scenario execution unit 133 inputs the generated data to the network model 145 and acquires data output by the network model 145 in response to this. The scenario execution unit 133 also acquires the internal state of the network model 145 at this time. The scenario execution unit 133 stores the acquired information such as the output data and internal state as an operation log 147.
[0103] 10 and 11 are schematic diagrams showing examples of the operation log 147. Fig. 10 shows the operation log 147 related to the communication bus included in the network model 145, and Fig. 11 shows the operation log 147 related to the communication device included in the network model 145. In this embodiment, the operation log 147 related to the communication bus and the operation log 147 related to the communication device are generated separately, but this is not limitative, and the operation logs 147 of the communication bus and the communication device may be combined into one.
[0104] In the operation log related to the communication bus, information such as "time," "communication bus," "operation," and "ID" is stored in association with each other. "Time" is the time in the simulation and corresponds to "time" in the scenario 146. "Communication bus" may be set with the ID of the communication bus included in the network model 145. "Operation" may store information such as "start" or "end" as the operating state of the communication bus. "ID" is the ID assigned to data transmitted and received on the communication line.
[0105] In the operation log related to a communication device, information such as "time," "communication device," "operation," and "ID" is stored in association with each other. "Time" is the time in the simulation and corresponds to "time" in the scenario 146. "Communication device" may be set to the ID of a communication device included in the network model 145. "Operation" may store information such as "sending" or "receiving" as the operating status of the communication device. "ID" is the ID assigned to data sent and received by the communication device.
[0106] In this embodiment, the scenario 146 generated by the scenario generation unit 132 includes, for example, information for simulating all use cases stored in the use case DB 142. The scenario execution unit 133 executes all events included in the scenario 146 and simulates all use cases for the network model 145. The operation log 147 output by the scenario execution unit 133 may include information such as output data of the network model 145 or the internal state of devices included in the network model 145 for all steps included in the scenario 146.
[0107] The verification device 13 calculates the network load factor or communication delay based on the operation log 147 obtained as a result of the simulation. For example, for each communication bus included in the network model 145, the verification device 13 calculates the proportion of the time during which data was transmitted and received on the communication bus relative to the total simulation time, and can determine the highest proportion or the average of multiple proportions among all communication buses as the network load factor. Furthermore, for example, the verification device 13 can calculate the time (delay time) from when all data transmitted and received in the simulation is transmitted at the source to when it is received at the destination, and can determine the network communication delay as the maximum or average of multiple delay times calculated for all data.
[0108] The verification device 13 determines whether the calculated load rate or communication delay satisfies a predetermined standard, thereby determining whether the result of the simulation verification is positive or negative. For example, the verification device 13 determines a positive result when the load rate is 70% or less, and a negative result when the load rate exceeds 70%. For example, the verification device 13 determines a positive result when the communication delay is 3 milliseconds or less, and a negative result when the communication delay exceeds 3 milliseconds. Note that the value calculated by the verification device 13 based on the operation log 147 may be something other than the load rate or communication delay. The above-described thresholds of a load rate of 70% and a communication delay of 3 milliseconds are merely examples and are not limiting. The designer or administrator of the information processing system according to this embodiment may predetermine appropriate values.
[0109] 12 is a flowchart showing an example of the procedure of the simulation verification process performed by the verification device 13 according to this embodiment. The model generation unit 131 of the verification device 13 according to this embodiment acquires information about the additional device obtained from the server device 3 (step S31). The model generation unit 131 also acquires information about the vehicle 1 stored in the vehicle DB 141, such as information about the devices and communication lines that make up the network of the vehicle 1 (step S32). The model generation unit 131 generates a network model 145 for performing simulation verification based on the information acquired in steps S31 and S32 (step S33).
[0110] The scenario generation unit 132 of the verification device 13 also acquires the use cases stored in the use case DB 142 (step S34). The scenario generation unit 132 generates a simulation verification scenario 146 based on the information acquired in steps S31 and S32 and the use cases acquired in step S34 (step S35).
[0111] The scenario execution unit 133 of the verification device 13 acquires information for one step from the scenario 146 generated in step S35 (step S36). The scenario execution unit 133 inputs input data generated based on the information acquired in step S36 to the network model 145 generated in step S33 (step S37). The scenario execution unit 133 acquires information such as data output by the network model 145 in accordance with the data input in step S37 and the internal state of the network model 145 at that time (step S38). The scenario execution unit 133 records the information acquired in step S38 as an operation log 147 (step S39).
[0112] The scenario execution unit 133 determines whether or not processing has been completed for all steps included in the scenario 146 (step S40). If processing has not been completed for all steps (S40: NO), the scenario execution unit 133 returns the processing to step S36, obtains information about the next step from the scenario 146, and repeats the same processing.
[0113] If processing has been completed for all steps of the scenario 146 (S40: YES), the verification device 13 calculates the network load factor and communication delay based on the operation log 147 recorded in step S39 (step S41). The verification device 13 compares the load factor and communication delay values calculated in step S41 with predetermined standards (step S42). The verification device 13 outputs a positive or negative verification result based on the comparison result of step S42 (step S43), and ends processing.
[0114] As described above, in the information processing system according to the present embodiment, the verification device 13 of the integrated ECU 10 verifies the communication of the network of the vehicle 1 by simulation, and updates the routing map if a positive verification result is obtained. This enables the information processing system to verify in detail the communication when the extension ECU 61 is added to the network of the vehicle 1 by simulation, and is expected to prevent the occurrence of communication-related problems and the like.
[0115] In the present embodiment, information regarding the network configuration of vehicle 1 is stored in vehicle DB 141, but this is not limiting, and a generated network model 145 may be stored in vehicle DB 141. Verification device 13 can update network model 145 stored in vehicle DB 141 by adding a model for newly added equipment, and can perform verification by simulation using updated network model 145.
[0116] The in-vehicle information processing device includes a computer including a microprocessor, ROM, RAM, etc. The processing unit such as the microprocessor may read and execute computer programs including some or all of the steps of the sequence diagrams or flowcharts shown in Figures 3 and 5 from storage units such as ROM and RAM. The computer programs of these multiple devices can be installed from an external server device, etc. Furthermore, these computer programs are distributed in a state where they are stored on recording media such as CD-ROM, DVD-ROM, and semiconductor memory.
[0117] The embodiments disclosed herein are to be considered as illustrative in all respects and not restrictive. The scope of the present disclosure is defined by the claims, not by the above meaning, and is intended to include all modifications within the meaning and scope of the claims.
[0118] <Notes> (Note 1) A computer program that causes a computer mounted on a vehicle to execute the following processes: detect connection of an in-vehicle communication device to a network within the vehicle; when connection of the in-vehicle communication device is detected, create a routing map for determining a relay destination of data transmitted and received on the network; verify communication on the network using the created routing map by simulation; and when a positive verification result is obtained, update the routing map.
[0119] 1 Vehicle (information processing system) 3 Server device 10 Integrated ECU (on-vehicle information processing device, computer) 11 Gateway (on-vehicle relay device) 12 ADAS-ECU 13 Verification device (on-vehicle information processing device, computer) 21 Processing unit 21a Gateway processing unit 21b ADAS processing unit 21c Verification processing unit (detection unit, creation unit, verification unit, update unit, acquisition unit, transmission unit, reception unit) 22 Storage unit 22a Program (computer program) 22b Routing map 22c Verification information 23 Communication unit 51 Meter ECU 52 Brake ECU 53 Expansion IF 54 External communication device 61 Expansion ECU (on-vehicle communication device) 62 Sensors 71 to 76 Communication line 99 Recording medium 131 Model generation unit 132 Scenario generation unit 133 Scenario execution unit 141 Vehicle DB (Configuration Database) 142 Use Case DB (Operation Database) 145 Network Model 146 Scenario 147 Operation Log
Claims
1. An in-vehicle information processing device comprising: a detection unit that detects connection of an in-vehicle communication device to a network within a vehicle; a creation unit that creates a routing map for determining a relay destination of data transmitted and received on the network when connection of the in-vehicle communication device is detected; a verification unit that verifies communication on the network using the created routing map through simulation; and an update unit that updates the routing map when a positive verification result is obtained.
2. The in-vehicle information processing device according to claim 1, wherein the verification unit verifies, by the simulation, whether a load factor or a communication delay in the network when the in-vehicle communication device is added satisfies a predetermined condition.
3. The in-vehicle information processing device of claim 1, further comprising: an acquisition unit that acquires information relating to the in-vehicle communication device connected to the network; a transmission unit that transmits the acquired information to an external device; and a receiving unit that receives update information for the routing map transmitted by the external device in response to the transmission of the information, wherein the creation unit creates the routing map based on the received update information.
4. The in-vehicle information processing device according to claim 1, wherein the update unit updates the routing map and thins out relays according to data priority when a negative verification result is obtained.
5. An in-vehicle information processing device as described in claim 1, comprising: a model generation unit that generates a model of the network; a scenario generation unit that generates a scenario for the simulation; and a scenario execution unit that inputs and outputs data to the model according to the scenario, wherein the verification unit performs verification based on the data input and output to the model and the internal state of the model.
6. The in-vehicle information processing device according to claim 5, further comprising a configuration database that stores configuration information of the in-vehicle communication devices and communication lines mounted on the vehicle, and the model generation unit generates the model based on the configuration information stored in the configuration database and the configuration information of the in-vehicle communication devices connected to the network.
7. An in-vehicle information processing device as described in claim 5, further comprising an action database that stores correspondence between the vehicle's actions and events that occur during each action, and the scenario generation unit generates the scenario that defines events that occur in chronological order based on information stored in the action database and configuration information of an in-vehicle communication device connected to the network.
8. The in-vehicle information processing device of claim 5, wherein the scenario defines events occurring in a time series on the network, and the scenario execution unit generates data to be input to the model based on the time series events defined in the scenario, inputs the generated data to the model, acquires data output by the model in response to the input of the data and the internal state of the model when the data is output, and stores the acquired data and internal state.
9. The in-vehicle information processing device according to claim 8, wherein the verification unit calculates a load factor or communication delay related to communication in the network based on the data and the internal state stored in the scenario execution unit, and determines whether the simulation result is positive or negative depending on whether the calculated load factor or communication delay satisfies a predetermined standard.
10. An information processing system comprising: an in-vehicle relay device having a relay unit that relays data transmission and reception between multiple communication lines that constitute an in-vehicle network; a detection unit that detects connection of the in-vehicle communication device to a network within the vehicle; a creation unit that creates a routing map for the in-vehicle relay device that relays data transmission and reception on the network to determine a relay destination of data when connection of the in-vehicle communication device is detected; a verification unit that verifies communication of the network using the created routing map by simulation; and an update unit that updates the routing map held by the in-vehicle relay device to the created routing map when a positive verification result is obtained.
11. An information processing method, in which an in-vehicle information processing device detects a connection of an in-vehicle communication device to a network within the vehicle, and when the connection of the in-vehicle communication device is detected, creates a routing map for determining a relay destination of data transmitted and received on the network, verifies communication on the network using the created routing map by simulation, and when a positive verification result is obtained, updates the routing map.
Citation Information
Patent Citations
Network monitoring system and monitoring method, and program
JP2005006235A
On-vehicle communication system and on-vehicle relay device
JP2014193654A
Information management system, on-vehicle device, server, and routing table changing method
JP2018152758A
Vehicle control device, vehicle network designing device, communication method, and program
WO2020145334A1
Onboard device, information processing method, and program
WO2022230423A1