Information processing device, information processing method, and computer program

The information processing device addresses the challenge of integrating new in-vehicle communication devices by creating and verifying routing maps through simulation, thereby preventing communication-related malfunctions and ensuring network stability.

WO2025105308A1PCT designated stage expired Publication Date: 2025-05-22AUTONETWORKS TECH LTD +3
View PDF 5 Cites 0 Cited by

Patent Information

Application Number
PCT/JP2024/039831
Authority / Receiving Office
WO · WO
Patent Type
Applications
Current Assignee / Owner
Priority Date
2023-11-15
Filing Date
2024-11-08
Publication Date
2025-05-22

Smart Images

  • Figure JP2024039831_22052025_PF_FP_ABST
    Figure JP2024039831_22052025_PF_FP_ABST
Patent Text Reader

Abstract

Provided are an information processing device, an information processing method, and a computer program that can be expected to suppress the occurrence of, inter alia, problems from adding a new onboard communication device to a network of a vehicle. An information processing device as in the present embodiment is provided with: an acquisition unit for acquiring information pertaining to an onboard communication device that has a connection detected with respect to an in-vehicle network; a creation unit for creating a routing map for determination of a relay destination of data transmitted and received over the network by an onboard relay device installed in the vehicle, on the basis of the acquired information; a verification unit for verifying, by simulation, communication of the network using the created routing map; and a transmission unit for transmitting the routing map to the onboard relay device if an affirmative verification result was obtained.
Need to check novelty before this filing date? Find Prior Art

Description

Information processing device, information processing method, and computer program

[0001] The present disclosure relates to an information processing device, an information processing method, and a computer program that perform processing related to communication within a vehicle.

[0002] Patent document 1 proposes an information management system in which an in-vehicle device acquires a service ID related to an added function and transmits it to a server, the server acquires service information for the function corresponding to the service ID, determines the changes to be made to the routing table based on the service information for multiple functions including the acquired service information, and executes the changes to the routing table.

[0003] JP 2018-152758 A

[0004] For example, a new in-vehicle communication device may be added to a network related to vehicle communication in order to add a function to the vehicle. An in-vehicle relay device that relays data transmission and reception between the in-vehicle communication devices in this network needs to update a routing map (routing table) to determine a relay destination for data related to the new in-vehicle communication device. After the routing map is updated and the in-vehicle communication device starts relaying data related to the new in-vehicle communication device, an increase in communication volume or communication delays may occur in the vehicle network. In recent years, the variety of added functions and types of in-vehicle communication devices has increased, making it difficult to verify in advance whether these additions will cause an increase in communication volume or communication delays.

[0005] The present disclosure has been made in consideration of the above circumstances, and its purpose is to provide an information processing device, an information processing method, and a computer program that are expected to suppress the occurrence of problems, etc., caused by adding a new in-vehicle communication device to a vehicle network.

[0006] The information processing device of this embodiment includes an acquisition unit that acquires information regarding an in-vehicle communication device that has detected a connection to a network within the vehicle, a creation unit that creates a routing map based on the acquired information to determine the relay destination of data sent and received over the network by an in-vehicle relay device installed in the vehicle, a verification unit that verifies communication over the network using the created routing map through simulation, and a transmission unit that transmits the routing map to the in-vehicle relay device if a positive verification result is obtained.

[0007] The present application can be realized not only as a device having such characteristic processing units, but also as a method having such characteristic processing steps, or as a computer program for causing a computer to execute such steps, or as a semiconductor integrated circuit that realizes part or all of these devices, or as other devices or systems that include these devices.

[0008] Based on the above, it is expected that the occurrence of problems and the like caused by adding a new in-vehicle communication device to the vehicle network can be suppressed.

[0009] FIG. 1 is a schematic diagram for explaining an example of a configuration of an information processing system according to the present embodiment. FIG. 2 is a block diagram showing an example of a configuration of a server device according to the present embodiment. FIG. 3 is a block diagram showing an example of a configuration of an integrated ECU according to the present embodiment. FIG. 4 is a schematic diagram for explaining the procedure of a function expansion process performed by the information processing system according to the present embodiment. FIG. 5 is a schematic diagram showing an example of a routing map. FIG. 6 is a flowchart showing an example of a process procedure performed by the server device according to the present embodiment. FIG. 7 is a schematic diagram for explaining an overview of a simulation performed in the information processing system according to the present embodiment. FIG. 8 is a schematic diagram for explaining an example of a network model generated by a model generation unit. FIG. 9 is a schematic diagram showing an example of a configuration of a use case DB. FIG. 10 is a schematic diagram showing an example of a scenario. FIG. 11 is a schematic diagram showing an example of an operation log. FIG. 12 is a flowchart showing an example of a procedure of a simulation verification process performed by the server device according to the present embodiment.

[0010] [Description of Embodiments of the Present Disclosure] First, embodiments of the present disclosure will be listed and described. At least some of the embodiments described below may be combined in any combination.

[0011] (1) The information processing device of this aspect includes an acquisition unit that acquires information regarding an in-vehicle communication device that has been detected as being connected to a network within the vehicle, a creation unit that creates a routing map based on the acquired information to determine the relay destination of data sent and received over the network by an in-vehicle relay device installed in the vehicle, a verification unit that verifies communication over the network using the created routing map through simulation, and a transmission unit that transmits the routing map to the in-vehicle relay device when a positive verification result is obtained.

[0012] In this aspect, an information processing device installed outside the vehicle creates a routing map for an in-vehicle relay device to determine a data relay destination in a network within the vehicle. The information processing device acquires information from the vehicle regarding an in-vehicle communication device that has detected a new connection to the network, and creates a new routing map including information for the in-vehicle relay device to relay data from or to the in-vehicle communication device. The information processing device verifies, by simulation, network communication when the created routing map is applied. If a positive verification result is obtained by the simulation, the information processing device transmits the created new routing map to the in-vehicle relay device of the vehicle and updates the old routing map with the newly created routing map. By performing simulation verification before updating the routing map, it is expected that problems and the like that will occur after updating the routing map can be suppressed.

[0013] (2) It is preferable that the verification unit verify, by the simulation, whether a load factor or a communication delay in the network when the in-vehicle communication device is added satisfies a predetermined condition.

[0014] In this aspect, the information processing device performs a simulation to verify whether the load factor or communication delay of the network when a new in-vehicle communication device is added satisfies a predetermined condition. The predetermined condition may be, for example, that the load factor or communication delay does not exceed a level that may cause a malfunction in the vehicle's functions. The predetermined condition may be determined in advance by, for example, a designer or administrator of the information processing system according to this embodiment. This is expected to prevent malfunctions, such as an increase in the load factor or communication delay, from occurring after updating the routing map.

[0015] (3) It is preferable that the vehicle is provided with a database that stores update information for a routing map related to an onboard communication device that can be connected to the network within the vehicle, and that the creation unit creates the routing map based on the update information read from the database based on the information acquired by the acquisition unit.

[0016] In this aspect, an information processing device stores update information for updating a routing map in a database for various onboard communication devices that may be connected to a network within a vehicle. The update information includes, for example, information to be added to the routing map in order to correctly relay data from or to the onboard communication devices. The information processing device reads the update information from the database based on information about the onboard communication devices acquired from the vehicle, and creates a new routing map based on the read update information. This allows the information processing device to create an appropriate routing map even when a wide variety of onboard communication devices may be connected to the vehicle's network.

[0017] (4) When a negative verification result is obtained, it is preferable that the transmitting unit transmits a routing map and causes the vehicle-mounted relay device to thin out relays according to the priority of the data.

[0018] In this aspect, if a negative verification result is obtained by the simulation, the information processing device transmits a newly created routing map for updating to the vehicle and causes the in-vehicle relay device to thin out relays according to the priority of the data. For example, if the priority of data to be relayed is lower than a predetermined threshold, the in-vehicle relay device can thin out data by discarding the data without relaying it with a predetermined probability. As a result, if there is a possibility that updating the routing map will cause a malfunction, the information processing device can reduce the amount of communication by thinning out relays, thereby preventing the occurrence of malfunctions.

[0019] (5) It is preferable that the system comprises a model generation unit that generates a model of the network, a scenario generation unit that generates a scenario for the simulation, and a scenario execution unit that inputs and outputs data to the model according to the scenario, and that the verification unit performs verification based on the data input and output to the model and the internal state of the model.

[0020] In this aspect, the information processing device generates a model of a network to be simulated and a simulation scenario, and performs a simulation by inputting and outputting data to and from the model according to the scenario. The information processing device performs verification based on input and output data to and from the model and the internal state of the model. This makes it possible for the information processing device to widely verify the behavior of a network to which a new in-vehicle communication device has been added through simulations using various scenarios.

[0021] (6) It is preferable that the vehicle is provided with a configuration database that stores configuration information of the on-board communication devices and communication lines installed in the vehicle, and the model generation unit generates the model based on the configuration information stored in the configuration database and the configuration information of the on-board communication devices connected to the network.

[0022] In this aspect, the information processing device includes a configuration database that stores the configuration of the on-board communication device and communication lines installed in the vehicle, etc. Based on the information stored in the configuration database and the configuration information of the on-board communication device newly connected to the vehicle network, the information processing device is expected to generate a model to be used in a simulation for verification, for example, by adding a model of the added on-board communication device to a model of an existing network configuration.

[0023] (7) It is preferable that the vehicle is provided with an operation database that stores the correspondence between the vehicle's operations and the events that occur during each operation, and the scenario generation unit generates the scenario that defines events that occur in chronological order based on the information stored in the operation database and the configuration information of the vehicle-mounted communication device connected to the network.

[0024] In this aspect, the information processing device includes an operation database that stores correspondence between vehicle operations and events that occur during each operation. The information processing device generates a scenario that defines events that occur in chronological order based on the information stored in the operation database and configuration information of an in-vehicle communication device that has been newly connected to the vehicle network. This allows the information processing device to perform simulations that correspond to various vehicle operations.

[0025] (8) It is preferable that the scenario defines events that occur in a chronological order in the network, and that the scenario execution unit generates data to be input to the model based on the chronological events defined in the scenario, inputs the generated data to the model, acquires the data that the model outputs in response to the input of the data, and the internal state of the model when the data is output, and stores the acquired data and internal state.

[0026] In this aspect, the information processing device generates data to be input to a model based on a time-series event defined in a scenario, inputs the generated data to the model, acquires data output by the model and the internal state of the model, and stores the acquired information. This allows the information processing device to be expected to perform a simulation of a vehicle network using the model and the scenario.

[0027] (9) It is preferable that the verification unit calculates the load rate or communication delay related to communication on the network based on the data and internal state stored by the scenario execution unit, and determines whether the simulation result is positive or negative depending on whether the calculated load rate or communication delay satisfies a predetermined standard.

[0028] In this aspect, the information processing device calculates a load factor or a communication delay related to network communication based on the output data and internal state information of the model stored as a result of the simulation, and can determine whether the result of the simulation is positive or negative depending on whether the calculated load factor or communication delay satisfies a predetermined standard.

[0029] (10) In the information processing method of this aspect, an information processing device acquires information regarding an in-vehicle communication device that has detected a connection to a network within the vehicle, and based on the acquired information, creates a routing map for an in-vehicle relay device installed in the vehicle to determine the relay destination of data sent and received on the network, verifies communication on the network using the created routing map by simulation, and if a positive verification result is obtained, sends the routing map to the in-vehicle relay device.

[0030] In this aspect, similar to the aspect (1), it is expected that problems such as malfunctions occurring after updating the routing map can be suppressed.

[0031] (11) The computer program of this aspect causes a computer to acquire information regarding an in-vehicle communication device that has been detected as being connected to a network within the vehicle, create a routing map based on the acquired information for an in-vehicle relay device installed in the vehicle to determine the relay destination of data sent and received on the network, verify communication on the network using the created routing map through simulation, and if a positive verification result is obtained, execute a process of sending the routing map to the in-vehicle relay device.

[0032] In this aspect, similar to the aspect (1), it is expected that problems such as malfunctions occurring after updating the routing map can be suppressed.

[0033] [Details of the embodiment of the present disclosure] Specific examples of information processing systems according to the embodiment of the present disclosure will be described below with reference to the drawings. The present disclosure is not limited to these examples, but is defined by the claims, and is intended to include all modifications within the meaning and scope of the claims.

[0034] <System Configuration> FIG. 1 is a schematic diagram illustrating an example configuration of an information processing system according to this embodiment. The information processing system according to this embodiment includes multiple devices mounted on a vehicle 1, such as an integrated ECU (Electronic Control Unit) 10, a meter ECU 51, a brake ECU 52, an expansion IF (Interface) 53, and an exterior communication device 54. These multiple devices are connected via multiple communication lines 71-74 arranged within the vehicle 1 to form an in-vehicle network capable of transmitting and receiving data to and from each other. In the illustrated example, four communication lines 71-74 are connected to the integrated ECU 10, with the meter ECU 51 connected to communication line 71, the brake ECU 52 connected to communication line 72, the expansion IF 53 connected to communication line 73, and the exterior communication device 54 connected to communication line 74. Note that in the illustrated example, two devices are connected to each of the communication lines 71-74, but three or more devices may be connected to each of the communication lines 71-74.

[0035] The integrated ECU 10 according to this embodiment integrates the functions of two devices, a gateway 11 that relays data transmission and reception, and an ADAS (Advanced Driver Assistance Systems)-ECI 12 that performs processing related to driving assistance, into a single device. In other words, the integrated ECU 10 includes a virtual gateway 11 and ADAS-ECU 12. The gateway 11 and ADAS-ECU 12 are connected via a virtual communication line 75. In this diagram, the virtual function blocks and communication lines are indicated by dashed lines. The gateway 11 and ADAS-ECU 12 may be mounted on the vehicle 1 as separate devices.

[0036] The integrated ECU 10 can transmit and receive data to and from the meter ECU 51, the brake ECU 52, the expansion IF 53, and the exterior communication device 54 via these communication lines 71 to 74. The meter ECU 51, the brake ECU 52, the expansion IF 53, and the exterior communication device 54 can each transmit and receive data to and from the integrated ECU 10. The integrated ECU 10 also relays data transmission and reception between the four communication lines 71 to 74. This allows the meter ECU 51, the brake ECU 52, the expansion IF 53, and the exterior communication device 54 to transmit and receive data to and from each other via the integrated ECU 10.

[0037] The meter ECU 51 controls various meters provided near the driver's seat of the vehicle 1. The meter ECU 51 controls the meters based on various information within the vehicle 1 obtained via the in-vehicle network. For example, the meter ECU 51 controls the display of a speedometer based on information on the traveling speed of the vehicle 1 obtained via the in-vehicle network. Furthermore, for example, the meter ECU 51 controls the display of a tachometer based on information on the number of revolutions or rotation speed of the engine of the vehicle 1 obtained via the in-vehicle network.

[0038] The brake ECU 52 controls the brakes of the vehicle 1. For example, the brake ECU 52 activates the brakes in response to the driver's operation of a foot brake or a parking brake provided at the driver's seat of the vehicle 1. Information regarding the presence or absence of an operation of the foot brake or the parking brake and the amount of operation may be input directly to the brake ECU 52 or may be provided to the brake ECU 52 via an in-vehicle network. Furthermore, for example, the brake ECU 52 activates the brakes in response to a command provided from the ADAS-ECU 12 via the in-vehicle network.

[0039] The expansion IF 53 is used to connect an expansion ECU 61 that will handle a function when, for example, adding a function to the vehicle 1. In this example, the expansion IF 53 is connected to a communication line 73, and has a connection terminal or a slot for connecting the expansion ECU 61. When the expansion IF 53 detects that the expansion ECU 61 has been connected, it notifies the integrated ECU 10 of the connection detection via the communication line 73.

[0040] The expansion ECU 61 is configured to be detachable from the expansion IF 53, and when attached to the expansion IF 53, it is connected to a communication line 73 of the vehicle 1 and can communicate via the communication line 73. The expansion ECU 61 may be configured to perform any expansion function of the vehicle 1. In this example, the expansion ECU 61 has a sensor 62 that detects obstacles and the like present outside the vehicle 1, and performs processing to periodically obtain detection results of the sensor 62 and transmit them to other devices within the vehicle 1. This allows the vehicle 1 to be provided with additional functions, such as monitoring the surroundings of the vehicle 1 or avoiding obstacles, using the sensor 62.

[0041] The exterior communication device 54 is a device that communicates with various devices installed outside the vehicle 1 by wireless communication, such as via a mobile phone communication network or a wireless local area network (LAN). In this embodiment, the exterior communication device 54 communicates with a server device 3 installed outside the vehicle 1. The exterior communication device 54 is connected to the integrated ECU 10 via a communication line 74, and transmits data from the integrated ECU 10 to the server device 3 and provides data from the server device 3 to the integrated ECU 10.

[0042] The gateway 11, which is virtually provided within the integrated ECU 10, relays data among the communication lines 71 to 75. In the information processing system according to this embodiment, an ID is assigned to data to be transmitted and received, and the gateway 11 has a routing map that sets a correspondence between the ID assigned to the data and the communication line through which the data should be relayed. When the gateway 11 receives data from one of the communication lines, it refers to the routing map based on the ID assigned to the data, and transmits the data from the communication line set as the relay destination in the routing map, thereby relaying the data among the multiple communication lines.

[0043] The ADAS-ECU 12 is a device that realizes driving assistance or automatic driving by controlling the driving of the vehicle 1 based on information obtained from various sensors mounted on the vehicle 1. For example, the ADAS-ECU 12 measures the distance to the vehicle ahead using a sensor mounted on the vehicle 1, and controls the accelerator and brake of the vehicle 1 so that the vehicle 1 drives while maintaining a constant inter-vehicle distance. Note that the control performed by the ADAS-ECU 12 is not limited to control for maintaining an inter-vehicle distance, and may be control related to various driving assistance or automatic driving.

[0044] The server device 3 provided outside the vehicle 1 stores information about various devices mounted on the vehicle 1 in a database, and distributes programs, data, etc. required by the various devices mounted on the vehicle 1. For example, when a new extension ECU 61 is connected to the network of the vehicle 1, information about the extension ECU 61 is transmitted from the vehicle 1 to the server device 3. Upon receiving this information, the server device 3 transmits programs, data, etc. for using the extension ECU 61 to the vehicle 1.

[0045] Furthermore, when the extension ECU 61 is mounted on the extension IF 53 of the vehicle 1 and connected to the communication line 73, the server device 3 according to this embodiment performs a process for verifying whether the extension ECU 61 can be connected. In the information processing system according to this embodiment, when the extension ECU 61 is connected to the communication line 73, the gateway 11 needs to update the routing map used to determine the data relay destination. This is necessary, for example, to relay data transmitted by the extension ECU 61 to other devices and to relay data transmitted from other devices to the extension ECU 61. When the server device 3 is notified by the vehicle 1 that the extension ECU 61 has been connected, the server device 3 creates a new routing map and verifies communication within the vehicle 1 using the new routing map through a simulation. When the server device 3 obtains a positive verification result through the simulation (for example, a verification result indicating that no abnormalities or the like will occur), the server device 3 transmits the created routing map to the vehicle 1, thereby updating the routing map held by the gateway 11 of the integrated ECU 10 with the new routing map.

[0046] 2 is a block diagram showing an example of the configuration of the server device 3 according to this embodiment. The server device 3 according to this embodiment is configured to include a processing unit 31, a memory unit (storage) 32, and a communication unit (transceiver) 33. Note that in this embodiment, the processing will be described as being performed by one server device 3, but the processing may be performed in a distributed manner by a plurality of server devices.

[0047] The processing unit 31 is configured using an arithmetic processing device such as a CPU (Central Processing Unit), an MPU (Micro-Processing Unit), a GPU (Graphics Processing Unit), or a quantum processor, and storage devices such as a ROM (Read Only Memory) and a RAM (Random Access Memory). The processing unit 31 reads and executes a program 32a stored in the storage unit 32 to perform various processes, such as a process of communicating with the vehicle 1 to acquire various information, a process of creating a routing map, and a process of verifying communication within the vehicle 1 using the created routing map.

[0048] The storage unit 32 is configured using a large-capacity storage device such as a hard disk or an SSD (Solid State Drive). The storage unit 32 stores various programs executed by the processing unit 31 and various data required for the processing of the processing unit 31. In the present embodiment, the storage unit 32 stores a program 32a executed by the processing unit 31. The storage unit 32 also has an in-vehicle device DB (database) 32b that stores information about various devices that may be mounted on the vehicle 1, and a vehicle DB 32c that stores information such as the network configuration of the vehicle 1.

[0049] In this embodiment, the program (computer program, program product) 32a is provided in a form recorded on a recording medium 99 such as a memory card or an optical disc, and the server device 3 reads the program 32a from the recording medium 99 and stores it in the storage unit 32. However, the program 32a may also be written to the storage unit 32, for example, during the manufacturing stage of the server device 3. Alternatively, the program 32a may be distributed by another remote server device or the like and acquired by the server device 3 via communication. For example, the program 32a may be read from the recording medium 99 by a writing device and written to the storage unit 32 of the server device 3. The program 32a may be provided in a form distributed via a network or in a form recorded on the recording medium 99.

[0050] The in-vehicle device DB 32b is a database that stores information about various devices that can be additionally connected to the vehicle 1. The information stored in the in-vehicle device DB 32b may include, for example, information such as the ID, size, and transmission period of data transmitted by a device, as well as information such as the ID of data required by the device. When the server device 3 receives information including the ID of the additionally connected extension ECU 61 from the vehicle 1, the server device 3 can read out the information stored in the in-vehicle device DB 32b based on the ID and create a routing map.

[0051] The in-vehicle device DB 32b also stores various programs, such as device drivers or application programs, executed by devices that may be mounted on the vehicle 1. When a new extension ECU 61 is added to the network of the vehicle 1, the server device 3 reads out from the in-vehicle device DB 32b the programs executed by the extension ECU 61 and the programs executed by in-vehicle devices that perform processing in cooperation with the extension ECU 61, and transmits these to the vehicle 1.

[0052] The vehicle DB 32c is a database that stores information about the devices installed in the vehicle 1 and the network configuration, etc., associated with identification information such as a vehicle ID, for the vehicle 1 managed by the server device 3. The information stored in the vehicle DB 32c may include, for example, various information such as the number of communication lines 71 to 75 that make up the network of the vehicle 1, identification information for the devices connected to each of the communication lines 71 to 75, information such as the type, size, and transmission cycle of data transmitted by each device, information such as the type and version of the program being executed by each device, information such as the model and owner of the vehicle 1, and information about the routing map used by the gateway 11 of the vehicle 1. The server device 3 can verify communication in the vehicle 1 by simulating it based on the information stored in the vehicle DB 32c.

[0053] The communication unit 33 communicates with various devices via a network N including, for example, the Internet, a wired local area network (LAN), a wireless LAN, or a mobile phone communication network. In the present embodiment, the communication unit 33 communicates with one or more vehicles 1 (external communication devices 54 mounted on the vehicles 1) via the network N. The communication unit 33 transmits data provided by the processing unit 31 to other devices, and provides data received from other devices to the processing unit 31.

[0054] The storage unit 32 may be an external storage device connected to the server device 3. The server device 3 may be a multi-computer including multiple computers, or may be a virtual machine virtually constructed by software. The server device 3 is not limited to the above configuration, and may include, for example, a reading unit that reads information stored in a portable storage medium, an input unit that accepts operation input, or a display unit that displays images.

[0055] In the server device 3 according to this embodiment, the processing unit 31 reads and executes the program 32a stored in the storage unit 32, whereby an information acquisition unit 31a, a routing map creation unit 31b, a verification processing unit 31c, a routing map transmission unit 31d, and the like are realized as software functional units in the processing unit 31. Note that in the figure, functional units involved in processes related to the creation and verification of the routing map of the vehicle 1 are illustrated as functional units of the processing unit 31, and functional units involved in other processes are not illustrated.

[0056] The information acquisition unit 31a performs a process of acquiring various information related to the vehicle 1 by communicating with the external communication device 54 of the vehicle 1 via the communication unit 33. The information acquisition unit 31a acquires various information, such as information related to devices installed in the vehicle 1, information related to the network configuration of the vehicle 1, version information of programs executed by each device, and a routing map used by the gateway 11, and stores the information in the vehicle DB 32c. In addition, in this embodiment, when an extension ECU 61 is newly installed in the extension IF 53 of the vehicle 1, the information acquisition unit 31a performs a process of acquiring information related to the extension ECU 61 from the vehicle 1. The information acquisition unit 31a stores the acquired information related to the extension ECU 61 in the vehicle DB 32c and appropriately changes the already stored information on the network configuration of the vehicle 1.

[0057] The routing map creation unit 31b performs processing to create a routing map to be used by the gateway 11 of the vehicle 1. The routing map creation unit 31b reads information about the extended ECU 61 from the in-vehicle device DB 32b based on information such as the ID of the extended ECU 61 acquired by the information acquisition unit 31a. The information read from the in-vehicle device DB 32b at this time may include, for example, the ID of data transmitted by the extended ECU 61, the ID of a device that should receive the data, and the ID of data required by the extended ECU 61. The routing map creation unit 31b also reads information such as the network configuration of the vehicle 1 and the current routing map stored in the vehicle DB 32c. Based on the read information, the routing map creation unit 31b can determine to which of the communication lines 71 to 75 data transmitted by the extended ECU 61 should be relayed. The routing map creation unit 31b also determines which data, among the data transmitted by devices already installed in the vehicle 1 such as the meter ECU 51 and the brake ECU 52, should be relayed to the communication line 73 to which the extension ECU 61 is connected. The routing map creation unit 31b creates a new routing map based on the determined relay destination. The routing map creation unit 31b can create a new routing map, for example, by adding a condition for relaying data related to the newly added extension ECU 61 to the current routing map.

[0058] The verification processing unit 31c verifies the validity of the routing map created by the routing map creation unit 31b through a simulation. Information stored in the vehicle DB 32c includes, for example, the network configuration of the vehicle 1, the ID, period, and size of data transmitted by each device, and the ID of data required by each device. Based on this information, the verification processing unit 31c constructs a virtual network of the vehicle 1 to be simulated in a simulation environment. The verification processing unit 31c performs a simulation in which each device transmits and receives data at a set period and size in the virtual network. In the simulation, the verification processing unit 31c measures the amount and frequency of data transmitted and received over the network of the vehicle 1, thereby calculating values ​​such as the communication load on each communication line 71-75 or the maximum delay time for each piece of data. The verification processing unit 31c determines the validity of the new routing map by determining whether these calculated values ​​satisfy predetermined conditions.

[0059] The routing map sending unit 31d performs processing to send the new routing map created by the routing map creation unit 31b to the vehicle 1. When a positive verification result (a verification result that satisfies a predetermined condition) is obtained by the verification processing unit 31c, the routing map sending unit 31d sends the new routing map to the vehicle 1, thereby updating the routing map held by the gateway 11 of the vehicle 1 to the new routing map.

[0060] On the other hand, if the verification processing unit 31c obtains a negative verification result (a verification result that does not satisfy the predetermined condition), the verification processing unit 31c performs a simulation verification, for example, of a case where data relay by the gateway 11 of the vehicle 1 is thinned, and determines whether the predetermined condition is satisfied. In the information processing system according to this embodiment, an ID assigned to each piece of transmitted and received data indicates the type and priority of the data. The data ID is, for example, a numerical value with a predetermined number of digits, and the lower the value, the higher the priority. The verification processing unit 31c performs verification of a case where data is thinned, starting with the lowest priority, and determines data that needs to be thinned to satisfy the predetermined condition. Methods for thinning data relay may include, for example, discarding data without relaying once every predetermined number of times, or discarding data without relaying with a predetermined probability. The verification processing unit 31c notifies the vehicle 1 of the ID of data determined to need to be thinned, and causes the gateway 11 of the vehicle 1 to subsequently thin out data with this ID. After the verification processing unit 31c notifies the vehicle 1 of the thinning out of relays, the routing map transmission unit 31d transmits a new routing map to the vehicle 1, thereby updating the routing map of the gateway 11.

[0061] In the present embodiment, if a negative verification result is obtained by the simulation, the verification processing unit 31c reduces the data relay by the gateway 11, but this is not limited to this. For example, the verification processing unit 31c may reduce the frequency of data transmission to one or more devices connected to the network of the vehicle 1. Furthermore, for example, the verification processing unit 31c may display a message on the display of the vehicle 1 that rejects the connection of the newly connected extension ECU 61, without updating the routing map of the gateway 11.

[0062] After the transmission of the routing map is completed, the server device 3 stores the new routing map in the vehicle DB 32c and adds information about the extension ECU 61 to the network configuration of the vehicle 1 stored in the vehicle DB 32c. The server device 3 also determines whether the programs of each device installed in the vehicle 1 need to be updated due to the addition of the extension ECU 61, and if it determines that an update is necessary, transmits the update program to the vehicle 1. The gateway 11 of the vehicle 1 appropriately transmits the update program from the server device 3 to each device that requires it, and causes each device to update its program.

[0063] 3 is a block diagram showing an example of the configuration of the integrated ECU 10 according to this embodiment. The integrated ECU 10 according to this embodiment is configured to include a processing unit (processor) 21, a memory unit (storage) 22, and a communication unit (transceiver) 23. The processing unit 21 is configured using an arithmetic processing device such as a CPU or an MPU. The processing unit 21 can perform various processes by reading and executing a program 22a stored in the memory unit 22. In this embodiment, the processing unit 21 performs processes related to two devices, the gateway 11 and the ADAS-ECU 12.

[0064] The storage unit 22 is configured using a non-volatile memory element such as a flash memory or an EEPROM (Electrically Erasable Programmable Read Only Memory). The storage unit 22 stores various programs executed by the processing unit 21 and various data required for the processing of the processing unit 21. In this embodiment, the storage unit 22 stores a program 22a executed by the processing unit 21 and a routing map 22b used by the gateway 11 to determine a data relay destination.

[0065] The program (program product) 22a may be written to the storage unit 22 during the manufacturing stage of the integrated ECU 10, for example, or may be distributed by a remote server device or the like and acquired by the integrated ECU 10 via communication, or the integrated ECU 10 may read a program recorded on a recording medium 98 such as a memory card or an optical disk and store it in the storage unit 22, or a writing device may read a program recorded on the recording medium 98 and write it to the storage unit 22 of the integrated ECU 10. The program 22a may be provided in the form of distribution via a network or in the form of being recorded on the recording medium 98.

[0066] The routing map 22b is information used when the integrated ECU 10 performs relay processing as the gateway 11. In the information processing system according to this embodiment, data transmitted and received over the network of the vehicle 1 is assigned an ID for identifying the type of data, etc. The routing map 22b is information indicating, for example, the correspondence between the ID assigned to the data and the communication lines 71 to 75 through which the data having this ID should be transmitted. When the gateway 11 receives data over any of the communication lines 71 to 75, it can obtain the ID assigned to the received data and obtain from the routing map 22b which communication line 71 to 75 is the relay destination corresponding to this ID.

[0067] In this embodiment, the integrated ECU 10 has four communication units 23. Each communication unit 23 is connected to one of communication lines 71 to 74 and communicates with other devices via these communication lines 71 to 74. The communication units 23 transmit and receive data according to a communication protocol such as a Controller Area Network (CAN) or Ethernet (registered trademark). Each communication unit 23 may be configured using an integrated circuit (IC) such as a CAN controller or an Ethernet switch. The communication units 23 transmit the digital data provided by the processing unit 21 by converting the digital data into an electrical signal and outputting the electrical signal to the communication lines 71 to 74. The communication units 23 sample and acquire the potentials of the communication lines 71 to 74, converting the electrical signals on the communication lines into digital data, and providing the converted data to the processing unit 21 as received data. Note that, although the integrated ECU 10 has four communication units 23 in this example, the number is not limited thereto, and the integrated ECU 10 may have three or fewer or five or more communication units 23.

[0068] In the integrated ECU 10 of this embodiment, the processing unit 21 reads and executes a program 22a stored in the storage unit 22, whereby a gateway processing unit 21a, an ADAS processing unit 21b, and the like are realized as software functional units in the processing unit 21. The gateway processing unit 21a of the processing unit 21 performs processing equivalent to the virtual gateway 11 described above, and the ADAS processing unit 21b performs processing equivalent to the ADAS-ECU 12.

[0069] The gateway processing unit 21a receives data transmitted by other devices via the communication lines 71 to 75 and transmits the received data from an appropriate communication line 71 to 75, thereby relaying the transmission and reception of data between the communication lines 71 to 75. The gateway processing unit 21a determines the relay destination of the data based on the ID included in the received data by referring to the routing map 22b stored in the storage unit 22. Furthermore, when the communication protocols of the data relay source and relay destination are different, the gateway processing unit 21a may convert the data to be relayed into a format suitable for each communication protocol.

[0070] Furthermore, in this embodiment, when an extension ECU 61 is attached to the extension IF 53 and connected to the network of the vehicle 1, the gateway processing unit 21a transmits information such as an ID related to the extension ECU 61 to the server device 3 and requests the server device 3 to create a new routing map. The gateway processing unit 21a obtains the new routing map transmitted from the server device 3 in response to this request, and updates the routing map 22b by overwriting the routing map 22b stored in the storage unit 22 with the new routing map. Furthermore, when an instruction to thin out data relay is received from the server device 3 together with the new routing map, the gateway processing unit 21a thins out the data relayed after the routing map is updated.

[0071] The ADAS processing unit 21b performs processing related to driving assistance or automatic driving of the vehicle 1. For example, the ADAS processing unit 21b controls the accelerator and brake of the vehicle 1 to maintain a constant inter-vehicle distance. For example, the ADAS processing unit 21b warns the driver when a vehicle ahead, photographed by a camera, suddenly brakes. For example, the ADAS processing unit 21b performs control to activate the brakes to stop the vehicle 1 when a collision with a vehicle ahead or an obstacle cannot be avoided by warning the driver. These controls by the ADAS processing unit 21b are merely examples and are not limited to these. The ADAS processing unit 21b may perform any control related to driving assistance or automatic driving.

[0072] <Function Expansion Processing> Figure 4 is a schematic diagram illustrating the procedure of the function expansion processing performed by the information processing system according to this embodiment. In the information processing system according to this embodiment, a user or the like connects an expansion ECU 61 to the expansion IF 53 that constitutes the network of the vehicle 1, thereby expanding the functions of the vehicle 1. When the expansion IF 53 detects that the expansion ECU 61 has been connected, it notifies the gateway 11 of the integrated ECU 10 of this fact. At this time, the expansion IF 53 acquires information such as an ID from the expansion ECU 61 and transmits this information to the gateway 11 along with a notification of connection detection. The notification data transmitted by the expansion IF 53 is received by the gateway 11 of the integrated ECU 10 via a communication line 73.

[0073] The gateway 11, which has received the notification from the extension IF 53, acquires the ID of the extension ECU 61 contained in the notification. The gateway 11 notifies the server device 3 by transmitting the acquired ID. The data including the ID transmitted by the gateway 11 at this time is received by the server device 3 provided outside the vehicle 1 via the communication line 74 and the external communication device 54.

[0074] The server device 3, which has been notified of the ID of the extension ECU 61 from the gateway 11 of the vehicle 1, reads information associated with this ID from the in-vehicle device DB 32b. The server device 3 also reads information associated with the vehicle 1 that sent the notification from the vehicle DB 32c. Based on the information read from these databases, the server device 3 creates a routing map for the gateway 11 of the vehicle 1 to which the extension ECU 61 has been added.

[0075] 5 is a schematic diagram showing an example of a routing map. The routing map shown in the upper part of FIG. 5 stores information such as "type," "ID," "relay source," "relay destination," and "thinning out" in association with each other. "Type" is the type of information included in data transmitted and received over the network of the vehicle 1, and may be set to types such as "mileage," "vehicle speed," "speed warning," or "abnormal water temperature." However, the routing map does not necessarily include "type" information.

[0076] The "ID" in the routing map is identification information attached to the data being transmitted and received. The "ID" is also used as information indicating the priority of the data, with a smaller value indicating a higher priority. For example, if the CAN communication protocol is used in the network of the vehicle 1, a CAN-ID may be used as the "ID." In this example, a hexadecimal number is set as the "ID."

[0077] Information identifying multiple communication lines connected to the gateway 11 is set in the "relay source" and "relay destination" of the routing map. In this example, "communication lines 71 to 75" are written as identification information for the communication lines, using the symbols shown in FIG. 1. The "relay source" refers to the communication lines 71 to 75 from which the gateway 11 receives its data, and the "relay destination" refers to the communication lines 71 to 75 from which the gateway 11 transmits that data. For example, data with an "ID" of "0B2" and a "type" of "mileage" is transmitted to the gateway 11 from a device connected to the "relay source" "communication line 72," and the gateway 11 that receives this data then transmits it from the "relay destination" "communication line 71."

[0078] The "thinning out" field of the routing map is set to either "yes" or "no" to indicate whether or not to perform thinning out of the corresponding data. The gateway 11 performs thinning out of the data for which the "thinning out" field of the routing map is set to "yes" by reducing the frequency of relaying.

[0079] 5 shows an example of a new routing map created by the server device 3 by adding the extended ECU 61 to the routing map shown in the upper part of Fig. 5. In this example, the addition of the extended ECU 61 adds three types of data to be transmitted and received over the in-vehicle network: "sonar data," "auto-brake request," and "obstacle warning request." When the server device 3 is notified by the gateway 11 of the vehicle 1 that the extended ECU 61 has been added, the server device 3 reads information about the extended ECU 61 from the in-vehicle device DB 32b. In this example, the extended ECU 61 transmits "sonar data" with an "ID" of "501," and the server device 3 reads information from the in-vehicle device DB 32b indicating that the ADAS-ECU 12 will use this data. Based on this information read from the in-vehicle device DB 32b and the network configuration of the vehicle 1 stored in the vehicle DB 32c (the extension ECU 61 is connected to the communication line 73, and the ADAS-ECU 12 is connected to the communication line 75), the server device 3 can add the "sonar data" information shown in the lower part of Figure 5 to the routing map shown in the upper part of Figure 5.

[0080] In this example, the addition of the extension ECU 61 adds auto-brake and obstacle warning functions to the vehicle 1. In connection with this function addition, the server device 3 reads, from the in-vehicle device DB 32b, information indicating that the ADAS-ECU 12 has transmitted, for example, "auto-brake request" data having an "ID" of "0B2" and that the brake ECU 52 will use this data. The server device 3 also reads, from the in-vehicle device DB 32b, information indicating that the ADAS-ECU 12 has transmitted, for example, "obstacle warning request" data having an "ID" of "202" and that the meter ECU 51 will use this data. The server device 3 can add the "auto-brake request" and "obstacle warning request" information shown in the lower part of FIG. 5 to the routing map shown in the upper part of FIG. 5 based on the information read from the in-vehicle device DB 32b and the network configuration of the vehicle 1.

[0081] In this example, the server device 3 creates a new routing map by adding information to an existing routing map, but this is not limited to this. The server device 3 may create a new routing map by changing some or all of the information included in the existing routing map, or may create a new routing map by deleting some of the information included in the existing routing map. The server device 3 may create a new routing map by appropriately combining adding, changing, and deleting information from an existing routing map, or may create a new routing map from scratch without using an existing routing map.

[0082] The server device 3, which has created a new routing map in response to the addition of the extension ECU 61, performs a simulation to verify communication in the in-vehicle network when the new routing map is applied, as shown in FIG. 4 . At this time, the server device 3 performs a simulation of communication in the in-vehicle network using information about the vehicle 1 stored in the vehicle DB 32c and information about each device stored in the in-vehicle device DB 32b. The vehicle DB 32c stores information such as which devices are connected to each of the communication lines 71 to 75 that make up the network of the vehicle 1 and the communication speeds of each of the communication lines 71 to 75. The in-vehicle device DB 32b stores information such as the ID, period, and size of data transmitted by each device mounted on the vehicle 1. The in-vehicle device DB 32b also stores information such as data transmitted and received by the extension ECU 61 and data added to the in-vehicle network in response to the addition of functions based on the extension ECU 61. In this embodiment, the in-vehicle device DB 32b and the vehicle DB 32c contain similar information necessary for performing simulation verification.

[0083] The server device 3 recreates the network of the vehicle 1 in a simulation environment, for example, based on information about the network configuration of the vehicle 1 stored in the vehicle DB 32c. The server device 3 simulates, for example, the flow of data when each device in the recreated network transmits data at a predetermined cycle and size. The server device 3 calculates, for example, the proportion of time during which data is being transmitted and received on each of the communication lines 71 to 75 relative to the total time of the simulation as the communication load factor, and calculates the average value of the communication load factors of the multiple communication lines 71 to 75 as the average load factor. The server device 3 determines whether the calculated average load factor satisfies a predetermined condition (for example, 70% or less).

[0084] Furthermore, for each piece of data transmitted and received over the network of the vehicle 1, the server device 3 calculates the delay time from when the data is transmitted from a transmitting device until when the data is received by a receiving device. The server device 3 calculates this delay time for all data transmitted and received in the simulation and obtains the longest delay time as the maximum delay time. The server device 3 determines whether this maximum delay time satisfies a predetermined condition (e.g., 3 milliseconds or less). Note that the network characteristic values ​​calculated by the server device 3 through the simulation are not limited to the average load rate or maximum delay time described above. The server device 3 may calculate various characteristic values, such as the amount of data transmitted and received over each communication line 71-75, or the frequency of arbitration occurring when multiple devices simultaneously transmit data over each communication line 71-75. The server device 3 may perform any condition determination on the calculated characteristic values.

[0085] If a positive verification result is obtained by a simulation using the newly created routing map, the server device 3 transmits the new routing map to the gateway 11 of the vehicle 1. Upon receiving the new routing map from the server device 3, the gateway 11 updates the routing map 22b by overwriting the previous routing map 22b with the new routing map.

[0086] After updating the routing map 22b, the gateway 11 transmits information such as the updated routing map 22b and the network configuration of the vehicle 1 to the server device 3 to notify the server device 3 that the routing map 22b has been updated. The information transmitted by the gateway 11 is received by the server device 3 via the communication line 74 and the exterior communication device 54. The server device 3, having received this information, associates the received information with information such as an ID that identifies the vehicle 1 and stores the received information in the vehicle DB 32c. The vehicle DB 32c of the server device 3 stores information such as the network configuration of the vehicle 1, the types of devices installed in the vehicle 1, and the versions of programs installed in each device. Based on the information received from the gateway 11, the server device 3 determines whether a program update (or installation, etc.) is required for one or more devices installed in the vehicle 1. If it is determined that an update is required, the server device 3 reads an update program from the in-vehicle device DB 32b and transmits it to the vehicle 1. The update program transmitted by the server device 3 is received by the gateway 11 via the exterior communication device 54 of the vehicle 1 and the communication line 74. The gateway 11 transmits the update program received from the server device 3 to the device that requires it, and causes the program to be updated.

[0087] 4, if a negative verification result is obtained by a simulation using the newly created routing map, the server device 3, for example, performs a further simulation to determine data to be thinned out from relay. The server device 3 sets "thinning out" in the routing map to "yes" for the data for which thinning out has been determined, and transmits this routing map to the gateway 11. Furthermore, if a negative verification result is obtained, the server device 3 may, for example, not update the routing map, but instead cause the meter ECU 51 of the vehicle 1 to display a warning message or the like, and prompt the user of the vehicle 1 to remove the extension ECU 61, for example.

[0088] In the routing map shown in the lower part of Figure 5, a negative verification result was obtained through simulation, and it was decided to perform thinning processing on two pieces of data, "Water Temperature Abnormality" and "Sonar Data," which have large "ID" values ​​(low priority), and "Thinning" is set to "Yes."

[0089] 6 is a flowchart showing an example of a processing procedure performed by the server device 3 according to this embodiment. In the information processing system according to this embodiment, when an extension ECU 61 is connected to the extension IF 53 of the vehicle 1, the gateway 11 of the integrated ECU 10 notifies the server device 3 of the addition of the device, and transmits information such as the ID of the newly connected extension ECU 61. The information acquisition unit 31a of the processing unit 31 according to this embodiment determines whether or not information such as the ID of the newly connected extension ECU 61 has been received from the gateway 11 of the vehicle 1 (step S1). If information such as the ID of the extension ECU 61 has not been received from the gateway 11 (S1: NO), the information acquisition unit 31a waits until information is received.

[0090] When information such as the ID of the extended ECU 61 is received from the gateway 11 (S1: YES), the routing map creation unit 31b of the processing unit 31 reads information about the extended ECU 61 from the in-vehicle device DB 32b based on the information such as the ID acquired in step S1 (step S2). At this time, the routing map creation unit 31b can read information such as the ID of data transmitted by the extended ECU 61, the ID of a device that should receive the data, and the ID of data required by the extended ECU 61 from the in-vehicle device DB 32b. The routing map creation unit 31b also reads information about the vehicle 1 that transmitted the information such as the ID of the extended ECU 61 from the vehicle DB 32c (step S3). At this time, the routing map creation unit 31b can read information such as the network configuration of the vehicle 1 and the current routing map from the vehicle DB 32c.

[0091] Based on the information read in steps S2 and S3, the routing map creation unit 31b can determine to which of the communication lines 71 to 75 the data transmitted by the extension ECU 61 should be relayed, and which of the data transmitted by devices already installed in the vehicle 1, such as the meter ECU 51 and the brake ECU 52, should be relayed to the communication line 73 connected to the extension ECU 61. Based on the determined relay destination, the routing map creation unit 31b creates a new routing map by, for example, adding a condition for relaying data related to the newly added extension ECU 61 to the current routing map (step S4).

[0092] Next, the verification processing unit 31c of the processing unit 31 constructs a network for the vehicle 1 in a simulation environment based on the information read in steps S2 and S3, and verifies the correctness of the newly created routing map by simulating communication according to the routing map created in step S4 (step S5).

[0093] The verification processing unit 31c determines whether a positive verification result is obtained by the simulation verification in step S5 (step S6). If a positive verification result is obtained (S6: YES), the routing map transmission unit 31d of the processing unit 31 transmits the routing map created in step S4 to the gateway 11 of the vehicle 1 (step S8), and ends the processing. On the other hand, if a positive verification result is not obtained (S6: NO), that is, if a negative verification result is obtained, the verification processing unit 31c, for example, repeats the simulation to determine data to be thinned out from relay by the gateway 11, and sets the gateway 11 to thin out data relay (step S7). Thereafter, the routing map transmission unit 31d transmits the routing map created in step S4 to the gateway 11 of the vehicle 1 (step S8), and ends the processing.

[0094] <Summary> In the information processing system according to the present embodiment configured as described above, the server device 3 acquires information about the extension ECU 61 whose connection to the network of the vehicle 1 has been detected, and creates a routing map for the gateway 11 of the vehicle 1 to determine a relay destination based on the acquired information. The server device 3 verifies network communication according to the created routing map by simulation, and if a positive verification result is obtained, transmits the routing map to the gateway 11 of the vehicle 1. This allows the information processing system to update the routing map 22b used by the gateway 11 of the vehicle 1 using the routing map created by the server device 3. By verifying network communication according to the routing map created by the server device 3 in advance by simulation, it is expected that communication problems and the like caused by adding the extension ECU 61 to the network of the vehicle 1 can be suppressed.

[0095] In the information processing system according to the present embodiment, the server device 3 calculates communication characteristics, such as the average load factor and the maximum delay time of transmitted and received data, for each of the communication lines 71 to 75 of the network when the extension ECU 61 is added. The server device 3 then verifies whether these calculated values ​​satisfy predetermined conditions. This is expected to prevent the information processing system from causing communication problems due to an increase in the average load factor or the maximum delay time caused by the addition of the extension ECU 61.

[0096] Furthermore, in the information processing system according to this embodiment, the server device 3 includes an in-vehicle device DB 32b that stores information for updating a routing map related to in-vehicle communication devices that can be connected to the network of the vehicle 1. The server device 3 can obtain information for updating the routing map from the in-vehicle device DB 32b based on information such as the ID of the extension ECU 61 transmitted from the gateway 11 of the vehicle 1, and can create a new routing map based on the obtained information. This makes it possible for the information processing system to accommodate a wide variety of additional devices mounted on the vehicle 1.

[0097] Furthermore, in the information processing system according to this embodiment, if a negative verification result is obtained by the simulation, the routing map is updated and data relay by the gateway 11 is thinned out in accordance with the priority of the data. As a result, in the case where the addition of the extension ECU 61 may result in an increase in the amount of communication on the network within the vehicle 1, the information processing system is expected to suppress the increase in the amount of communication by thinning out the relay by the gateway 11.

[0098] In this embodiment, when the extended ECU 61 is connected to the network of the vehicle 1, the server device 3 provided outside the vehicle 1 performs processes such as creating a routing map and verifying it through simulation, but these processes are not limited to being performed by the server device 3. For example, these processes may be performed by a diagnostic device connected to the vehicle 1 via a communication cable or the like, or an information processing device such as a personal computer, smartphone, or tablet terminal device that is capable of communicating with the vehicle 1.

[0099] 7 is a schematic diagram for explaining an outline of a simulation performed in the information processing system according to this embodiment. In the information processing system according to this embodiment, the verification processing unit 31c of the server device 3 provided outside the vehicle 1 performs verification by simulation.

[0100] The verification processing unit 31c of the server device 3 includes a model generation unit 131, a scenario generation unit 132, a scenario execution unit 133, etc. The verification processing unit 31c also includes an in-vehicle device DB 32b, a vehicle DB 32c, and a use case DB 142 that store information necessary for performing a simulation. In this embodiment, the verification processing unit 31c is a functional block virtually provided in the server device 3, and the model generation unit 131, the scenario generation unit 132, and the scenario execution unit 133 are functional blocks provided in the verification processing unit 31c of the processing unit 31 of the server device 3 shown in FIG. 2. The in-vehicle device DB 32b and the vehicle DB 32c are the same as those shown in FIG. 2, and the use case DB 142 can be provided in the storage unit 32 of the server device 3.

[0101] The model generation unit 131 performs processing to generate a network model 145 to be used in the simulation based on information stored in the vehicle DB 32c about the vehicle 1 to be verified and information stored in the in-vehicle device DB 32b about additional equipment for this vehicle 1. Here, the model generation unit 131 acquires information about the configuration of existing in-vehicle equipment and communication lines etc. installed in the vehicle 1 from the vehicle DB 32c based on the vehicle ID etc. acquired from the vehicle 1 to be verified. Furthermore, the model generation unit 131 acquires information about the configuration of the additional equipment from the in-vehicle device DB 32b based on the information about the additional equipment acquired from the vehicle 1 to be verified. Based on this information acquired from the vehicle DB 32c and the in-vehicle device DB 32b, the model generation unit 131 generates a network model 145 configured such that the additional equipment is connected to the existing network of the vehicle 1 to be inspected.

[0102] The vehicle DB 32c is a database that stores the configuration of communication devices, communication lines, and the like installed in the vehicle 1. The vehicle DB 32c stores the configurations of multiple vehicles 1 that may be the subject of verification by the server device 3, and stores information in association with, for example, a vehicle ID uniquely assigned to each vehicle 1. For example, the vehicle DB 32c stores the configuration of the vehicle 1 shown in FIG. 1 , including the integrated ECU 10, meter ECU 51, brake ECU 52, extension IF 53, external communication device 54, and communication lines 71 to 74. The in-vehicle device DB 32b is a database that stores the configuration of in-vehicle devices that may be added to the vehicle 1, and stores the configurations of multiple in-vehicle devices in association with, for example, the device name, device type, or product number of the in-vehicle device. For example, in the case of the vehicle 1 shown in FIG. 1 , the in-vehicle device DB 32b stores information regarding the configuration of the extension ECU 61 connected to the extension IF 53.

[0103] The scenario generation unit 132 performs processing to generate a simulation scenario 146 based on the information stored in the vehicle DB 32c and the in-vehicle device DB 32b, and the information stored in the use case DB 142. The use case DB 142 is an action database that stores correspondence between various actions performed in the vehicle 1 and events that occur in each of these actions, in association with, for example, the vehicle model of the vehicle 1.

[0104] The scenario execution unit 133 executes the scenario 146 to perform a simulation based on the network model 145 generated by the model generation unit 131 and the scenario 146 generated by the scenario generation unit 132. The scenario execution unit 133, for example, inputs input data according to the scenario 146 to the network model 145 and acquires output data output by the network model 145 in accordance with this input data. The scenario execution unit 133 manages the time in the simulation and executes the scenario 146 by repeatedly inputting and outputting data to the network model 145 as time passes. The scenario execution unit 133 also acquires information such as the internal state of the network model 145 that changes as the scenario is executed. The scenario execution unit 133 outputs this information obtained by executing the scenario 146 as an operation log 147.

[0105] The verification device 13 calculates the load factor, delay time, etc. of the network model 145 based on the operation log 147 output by the scenario execution unit 133, and determines whether these calculated values ​​satisfy predetermined criteria. The verification device 13 determines that a positive verification result has been obtained if the calculated values ​​satisfy the criteria, and determines that a negative verification result has been obtained if the criteria are not satisfied.

[0106] 8 is a schematic diagram illustrating an example of a network model 145 generated by the model generation unit 131. The illustrated network model 145 illustrates a portion of a model of the configuration of the vehicle 1 shown in FIG. 1. The illustrated network model 145 includes, for example, a virtual gateway that virtually reproduces the gateway 11 of the vehicle 1, and virtual ECUs that virtually reproduce the meter ECU 51, brake ECU 52, etc. The network model 145 includes information on virtual communication devices such as these virtual gateways and virtual ECUs, and virtual communication lines connecting them.

[0107] Information such as the number of communication ports, the type of communication port, the amount of memory installed, and the CPU processing capacity is set for the virtual communication device of the network model 145. Furthermore, the internal state of the virtual communication device, such as status information such as the power supply state, the presence or absence of a failure, the passage of time, and the CPU state, is managed.

[0108] Furthermore, each virtual communication device is set to perform an operation in the simulation. In the network model 145 of FIG. 8 , the operation of the virtual gateway is illustrated by functional blocks. In the virtual gateway of this example, for example, the receiving unit receives data transmitted from a virtual ECU and stores it in a receiving buffer. The relay unit acquires the data from the receiving buffer, determines a relay destination according to a routing map, stores the data in a relay buffer, and when the time to transmit arrives, acquires the data from the relay buffer and stores it in a transmitting buffer. The transmitting unit transmits the data stored in the transmitting buffer in sequence. The contents of the receiving buffer, relay buffer, and transmitting buffer of the illustrated virtual gateway are treated as internal state information of the virtual gateway in the simulation.

[0109] 9 is a schematic diagram showing an example of the configuration of the use case DB 142. In the information processing system according to this embodiment, it is possible to perform simulation-based verification for multiple types of vehicles 1, and the use case DB 142 stores information about use cases for each vehicle type of the vehicle 1, for example. However, FIG. 9 shows information about one vehicle type extracted from the information stored in the use case DB 142.

[0110] The use case DB 142 according to the present embodiment is a database that stores information such as "use cases," "prerequisites," and "occurring events" in association with each vehicle model. "Use cases" are operations that can be performed in the vehicle 1, and are classified into types such as "when adding a function," "when connecting the battery," "unlocking from outside the vehicle while parked," "when starting the engine," "when starting to drive," and "when stopping the engine, getting out of the vehicle, and locking the vehicle."

[0111] The "preconditions" are information indicating the state of the vehicle 1 when the operation of the "use case" is performed, and the conditions that are the preconditions for simulating this "use case" are stored. For example, the "preconditions" for "when adding a function" are "all existing devices: powered on, initialization completed" and "additional devices: powered off, initialization not completed." Also, for example, the "preconditions" for "when connecting a battery" are "all existing devices: powered off, initialization not completed."

[0112] "Occurring events" is information that lists multiple events included in the operation of a "use case" in chronological order. "Occurring events" when "function is added" may include events such as "added device: power on," "added device: initialization start," "added device: initialization complete," "all existing devices: periodic transmission start," and "added device: device registration sequence start." Furthermore, "occurring events" when "battery is connected" may include events such as "all existing devices: power on," "all existing devices: initialization start," "all existing devices: initialization complete," and "all existing devices: periodic transmission start."

[0113] The scenario generation unit 132 according to this embodiment generates scenarios for simulating all "use cases" registered in the use case DB 142 for the vehicle 1 to be verified. For example, for one "use case," the scenario generation unit 132 can generate a scenario by generating instructions for setting the internal state, etc. of the network model 145 so as to satisfy the "preconditions," and time-series input data for the network model 145 for generating each event stored in chronological order in the "occurring event." Furthermore, the scenario generation unit 132 can generate input data for the events based on the structures, etc. of the network and each device stored in the vehicle DB 32 c and the in-vehicle device DB 32 b.

[0114] 10 is a schematic diagram showing an example of a scenario 146. The scenario 146 generated by the scenario generation unit 132 according to this embodiment is a scenario in which information for multiple steps is arranged in chronological order, with one step being an association of information such as "time," "event type," "source," "destination," "ID," and "data length."

[0115] The "time" of scenario 146 is the time in the simulation managed by the scenario execution unit 133, and the event of this step occurs at the corresponding time in the simulation. The "event type" is the type of event that occurs in this step, and various event types such as "CAN transmission" or "user interrupt" can be set. The "source" can be set to the ID of the device that transmits data over the communication line in communication. The "destination" can be set to the ID of the device that receives data in communication. The "ID" is the ID assigned to the data that is transmitted and received, and in the case of CAN communication, a CAN-ID can be used. The "data length" is the length of the data that is transmitted and received, and can be set to a numerical value in units such as bytes.

[0116] The scenario execution unit 133 manages the time in the simulation, the state of each device included in the network, etc., and performs the simulation by executing, step by step, events set in the scenario 146 generated by the scenario generation unit 132. The scenario execution unit 133 generates input data for the network model 145 generated by the model generation unit 131, based on information for one step of the scenario 146. The scenario execution unit 133 inputs the generated data to the network model 145 and acquires data output by the network model 145 in response to this. The scenario execution unit 133 also acquires the internal state of the network model 145 at this time. The scenario execution unit 133 stores the acquired information such as the output data and internal state as an operation log 147.

[0117] 11 and 12 are schematic diagrams showing examples of the operation log 147. Fig. 11 shows the operation log 147 related to the communication bus included in the network model 145, and Fig. 12 shows the operation log 147 related to the communication device included in the network model 145. In this embodiment, the operation log 147 related to the communication bus and the operation log 147 related to the communication device are generated separately, but this is not limited to this, and the operation logs 147 of the communication bus and the communication device may be combined into one.

[0118] In the operation log related to the communication bus, information such as "time," "communication bus," "operation," and "ID" is stored in association with each other. "Time" is the time in the simulation and corresponds to "time" in the scenario 146. "Communication bus" may be set with the ID of the communication bus included in the network model 145. "Operation" may store information such as "start" or "end" as the operating state of the communication bus. "ID" is the ID assigned to data transmitted and received on the communication line.

[0119] In the operation log related to a communication device, information such as "time," "communication device," "operation," and "ID" is stored in association with each other. "Time" is the time in the simulation and corresponds to "time" in the scenario 146. "Communication device" may be set to the ID of a communication device included in the network model 145. "Operation" may store information such as "sending" or "receiving" as the operating status of the communication device. "ID" is the ID assigned to data sent and received by the communication device.

[0120] In this embodiment, the scenario 146 generated by the scenario generation unit 132 includes, for example, information for simulating all use cases stored in the use case DB 142. The scenario execution unit 133 executes all events included in the scenario 146 and simulates all use cases for the network model 145. The operation log 147 output by the scenario execution unit 133 may include information such as output data of the network model 145 or the internal state of devices included in the network model 145 for all steps included in the scenario 146.

[0121] The verification processing unit 31c calculates the network load factor or communication delay based on the operation log 147 obtained as a result of the simulation. For example, the verification processing unit 31c calculates, for each communication bus included in the network model 145, the proportion of the time during which data was transmitted and received on the communication bus relative to the total simulation time, and can determine the highest proportion among all communication buses or the average of multiple proportions as the network load factor. Furthermore, for example, the verification processing unit 31c can calculate, for all data transmitted and received in the simulation, the time from when the data is transmitted at the source to when it is received at the destination (delay time), and can determine the network communication delay as the maximum value or average value of multiple delay times calculated for all data.

[0122] The verification processing unit 31c determines whether the calculated load rate or communication delay satisfies a predetermined standard, thereby determining whether the result of the simulation verification is positive or negative. For example, the verification processing unit 31c determines a positive result when the load rate is 70% or less, and a negative result when the load rate exceeds 70%. For example, the verification processing unit 31c determines a positive result when the communication delay is 3 milliseconds or less, and a negative result when the communication delay exceeds 3 milliseconds. Note that the value calculated by the verification processing unit 31c based on the operation log 147 may be something other than the load rate or communication delay. The above-mentioned thresholds of 70% load rate and 3 millisecond communication delay are merely examples and are not limiting. The designer or administrator of the information processing system according to this embodiment may predetermine appropriate values.

[0123] 13 is a flowchart showing an example of the procedure of the simulation verification process performed by the server device 3 according to this embodiment. The model generation unit 131 of the verification processing unit 31c of the server device 3 according to this embodiment acquires information about the additional device stored in the in-vehicle device DB 32b based on the identification information of the additional device obtained from the vehicle 1 (step S31). The model generation unit 131 also acquires information about the vehicle 1 stored in the vehicle DB 141 based on the identification information of the vehicle 1 obtained from the vehicle 1 (step S32), such as information about the devices and communication lines that constitute the network of the vehicle 1. Based on the information acquired in steps S31 and S32, the model generation unit 131 generates a network model 145 for performing simulation verification (step S33).

[0124] The scenario generation unit 132 of the verification processing unit 31c also acquires the use cases stored in the use case DB 142 (step S34). The scenario generation unit 132 generates a simulation verification scenario 146 based on the information acquired in steps S31 and S32 and the use cases acquired in step S34 (step S35).

[0125] The scenario execution unit 133 of the verification processing unit 31c acquires information for one step from the scenario 146 generated in step S35 (step S36). The scenario execution unit 133 inputs input data generated based on the information acquired in step S36 to the network model 145 generated in step S33 (step S37). The scenario execution unit 133 acquires information such as data output by the network model 145 in accordance with the data input in step S37 and the internal state of the network model 145 at that time (step S38). The scenario execution unit 133 records the information acquired in step S38 as an operation log 147 (step S39).

[0126] The scenario execution unit 133 determines whether or not processing has been completed for all steps included in the scenario 146 (step S40). If processing has not been completed for all steps (S40: NO), the scenario execution unit 133 returns the processing to step S36, obtains information about the next step from the scenario 146, and repeats the same processing.

[0127] If processing has been completed for all steps of the scenario 146 (S40: YES), the verification processing unit 31c calculates the network load factor and communication delay based on the operation log 147 recorded in step S39 (step S41). The verification processing unit 31c compares the load factor and communication delay calculated in step S41 with predetermined standards (step S42). The verification processing unit 31c outputs a positive or negative verification result based on the comparison result of step S42 (step S43), and ends processing.

[0128] As described above, in the information processing system according to the present embodiment, the verification processing unit 31c of the server device 3 verifies the communication of the network of the vehicle 1 through simulation, and updates the routing map when a positive verification result is obtained. This enables the information processing system to verify in detail the communication when the extension ECU 61 is added to the network of the vehicle 1 through simulation, and is expected to prevent the occurrence of communication-related problems and the like.

[0129] In the present embodiment, information regarding the network configuration of vehicle 1 is stored in vehicle DB 141, but this is not limiting, and a generated network model 145 may be stored in vehicle DB 141. Verification device 13 can update network model 145 stored in vehicle DB 141 by adding a model for newly added equipment, and can perform verification by simulation using updated network model 145.

[0130] The information processing device includes a computer including a microprocessor, ROM, RAM, etc. The processing unit such as the microprocessor may read and execute a computer program including some or all of the steps of the sequence diagrams or flowcharts shown in Figures 4 and 6 from a storage unit such as ROM or RAM. The computer programs of these multiple devices can each be installed from an external server device, etc. Furthermore, these computer programs are distributed in a state where they are stored on recording media such as CD-ROM, DVD-ROM, and semiconductor memory.

[0131] The embodiments disclosed herein are to be considered as illustrative in all respects and not restrictive. The scope of the present disclosure is defined by the claims, not by the above meaning, and is intended to include all modifications within the meaning and scope of the claims.

[0132] <Notes> (Note 1) An information processing system comprising: an in-vehicle relay device having a relay unit that relays transmission and reception of data between multiple communication lines that constitute a network within the vehicle; an acquisition unit that is provided outside the vehicle and acquires information related to an in-vehicle communication device that has detected a connection to the network; a creation unit that creates a routing map based on the acquired information to determine a relay destination for data transmitted and received over the network by the in-vehicle relay device mounted on the vehicle; a verification unit that simulating communication of the network using the created routing map; and an information processing device having a transmission unit that transmits the routing map to the in-vehicle relay device when a positive verification result is obtained.

[0133] 1 Vehicle (information processing system) 3 Server device (on-vehicle information processing device, computer) 10 Integrated ECU 11 Gateway (on-vehicle relay device) 12 ADAS-ECU 21 Processing unit 21a Gateway processing unit 21b ADAS processing unit 22 Memory unit 22a Program (computer program) 22b Routing map 23 Communication unit 31 Processing unit 31a Information acquisition unit (acquisition unit) 31b Routing map creation unit (creation unit) 31c Verification processing unit (verification unit) 31d Routing map transmission unit (transmission unit) 32 Memory unit 32a Program (computer program) 32b On-vehicle device DB (database) 32c Vehicle DB (configuration database) 33 Communication unit 51 Meter ECU 52 Brake ECU 53 Expansion IF 54 External communication device 61 Expansion ECU (on-vehicle communication device) 62 Sensors 71 to 75 Communication lines 98, 99 Recording medium 131 Model generation unit 132 Scenario generation unit 133 Scenario execution unit 142 Use case DB (operation database) 145 Network model 146 Scenario 147 Operation log

Claims

1. An information processing device comprising: an acquisition unit that acquires information regarding an in-vehicle communication device that has been detected as being connected to a network within a vehicle; a creation unit that creates a routing map based on the acquired information, for an in-vehicle relay device mounted on the vehicle to determine a relay destination for data transmitted and received on the network; a verification unit that verifies communication on the network using the created routing map through a simulation; and a transmission unit that transmits the routing map to the in-vehicle relay device when a positive verification result is obtained.

2. The information processing device according to claim 1, wherein the verification unit verifies, by the simulation, whether a load factor or a communication delay in the network when the in-vehicle communication device is added satisfies a predetermined condition.

3. An information processing device as described in claim 1, further comprising a database that stores update information for a routing map relating to an in-vehicle communication device that can be connected to a network within the vehicle, and the creation unit creates the routing map based on the update information read from the database based on the information acquired by the acquisition unit.

4. The information processing device according to claim 1, wherein, when a negative verification result is obtained, the transmitting unit transmits a routing map and causes the vehicle-mounted relay device to thin out relays according to the priority of data.

5. An information processing device as described in claim 1, comprising: a model generation unit that generates a model of the network; a scenario generation unit that generates a scenario of the simulation; and a scenario execution unit that inputs and outputs data to the model according to the scenario, wherein the verification unit performs verification based on the data input and output to the model and the internal state of the model.

6. An information processing device as described in claim 5, further comprising a configuration database that stores configuration information of an on-board communication device and communication lines mounted on the vehicle, and the model generation unit generates the model based on the configuration information stored in the configuration database and the configuration information of an on-board communication device connected to the network.

7. An information processing device as described in claim 5, further comprising an action database that stores correspondence between the vehicle's actions and events that occur during each action, and the scenario generation unit generates the scenario, which defines events that occur in chronological order, based on information stored in the action database and configuration information of an in-vehicle communication device connected to the network.

8. An information processing device as described in claim 5, wherein the scenario defines events occurring in a time series on the network, and the scenario execution unit generates data to be input to the model based on the time series events defined in the scenario, inputs the generated data to the model, acquires data output by the model in response to the input of the data and the internal state of the model when the data is output, and stores the acquired data and internal state.

9. The information processing device described in claim 8, wherein the verification unit calculates a load factor or communication delay related to communication in the network based on the data and the internal state stored in the scenario execution unit, and determines whether the simulation result is positive or negative depending on whether the calculated load factor or communication delay satisfies a predetermined standard.

10. An information processing method, in which an information processing device acquires information regarding an in-vehicle communication device that has been detected as being connected to a network within the vehicle, creates a routing map based on the acquired information for an in-vehicle relay device mounted on the vehicle to determine a relay destination for data transmitted and received on the network, verifies communication on the network using the created routing map by simulation, and if a positive verification result is obtained, transmits the routing map to the in-vehicle relay device.

11. A computer program that causes a computer to execute the following processes: acquire information regarding an in-vehicle communication device that has been detected as being connected to a network within a vehicle; create a routing map based on the acquired information for an in-vehicle relay device mounted on the vehicle to determine the relay destination of data transmitted and received on the network; verify communication on the network using the created routing map through a simulation; and if a positive verification result is obtained, transmit the routing map to the in-vehicle relay device.

Citation Information

Patent Citations

  • Network monitoring system and monitoring method, and program

    JP2005006235A

  • On-vehicle communication system and on-vehicle relay device

    JP2014193654A

  • Information management system, on-vehicle device, server, and routing table changing method

    JP2018152758A

  • Vehicle control device, vehicle network designing device, communication method, and program

    WO2020145334A1

  • Onboard device, information processing method, and program

    WO2022230423A1