Data collection system, on-vehicle device, data collection method, and program

The data collection system efficiently manages and arbitrates shadow mode applications on vehicles, addressing hardware limitations by prioritizing operations and ensuring data integrity through a centralized management system.

WO2025164506A1PCT designated stage Publication Date: 2025-08-07DENSO CORP
View PDF 4 Cites 0 Cited by

Patent Information

Application Number
PCT/JP2025/002105
Authority / Receiving Office
WO · WO
Patent Type
Applications
Current Assignee / Owner
Priority Date
2024-01-31
Filing Date
2025-01-23
Publication Date
2025-08-07

AI Technical Summary

Technical Problem

Existing systems face challenges in effectively running multiple shadow mode applications on vehicles due to hardware limitations, risking the loss of important data.

Method used

A data collection system with an application distribution unit, application management unit, situation data collection unit, and shadow arbitration unit, which manages and arbitrates the operation of multiple shadow mode applications based on vehicle situation and resource availability, ensuring efficient execution without affecting vehicle control.

Benefits of technology

Enables efficient data collection using shadow mode applications, prioritizing high-priority operations, and reliably collecting data even for low-priority applications, reducing processing load and ensuring data integrity in critical driving scenarios.

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure JP2025002105_07082025_PF_FP_ABST
    Figure JP2025002105_07082025_PF_FP_ABST
Patent Text Reader

Abstract

An application management unit (41) sets shadow mode applications distributed by an application distribution unit (51) so as to be executable by an on-vehicle device or a vehicle equipped with the on-vehicle device. A status data collection unit (42) collects status data indicating the status of the vehicle. A shadow arbitration unit (43) arbitrates operations of the plurality of shadow mode applications by using arbitration data and the status data.
Need to check novelty before this filing date? Find Prior Art

Description

Data collection system, on-board device, data collection method, and program CROSS-REFERENCE TO RELATED APPLICATIONS

[0001] This international application claims priority based on Japanese Patent Application No. 2024-012933, filed with the Japan Patent Office on January 31, 2024, the entire contents of which are incorporated herein by reference.

[0002] The present disclosure relates to techniques for collecting data from vehicles.

[0003] Patent Document 1 describes a system that collects data from a plurality of on-board devices mounted on a plurality of vehicles.

[0004] JP 2023-84379 A

[0005] Shadow mode is a known method for collecting data from vehicles that is necessary for application development and improvement. Shadow mode is a mechanism for detecting differences between a running application (hereinafter referred to as a production application) and an application (hereinafter referred to as a shadow mode app) that achieves similar results through different processing based on the same input as the running application (hereinafter referred to as a production application) without activating it. Activation refers to the execution of actual vehicle control based on the processing results. It is assumed that multiple shadow mode apps will be run in parallel, such as running multiple shadow mode apps for one running app or running a shadow mode app for each of multiple production apps.

[0006] However, due to the limited hardware resources of a vehicle, it is not always possible to run all shadow mode apps simultaneously, which creates the risk of important data being missed.

[0007] One aspect of the present disclosure provides a technique for effectively running multiple shadow mode apps.

[0008] One aspect of the present disclosure is a data collection system including an application distribution unit, an application management unit, a situation data collection unit, and a shadow arbitration unit.

[0009] The application distribution unit is configured to distribute to the in-vehicle device a shadow mode application that operates based on input equivalent to that of a production application without affecting vehicle control, and arbitration data including information necessary for starting the shadow mode application. The application management unit is configured to set the shadow mode application distributed by the application distribution unit to a state that is executable in the in-vehicle device or a vehicle equipped with the in-vehicle device. The situation data collection unit is configured to collect situation data that indicates the situation of the vehicle. The shadow arbitration unit is configured to arbitrate the operation of multiple shadow mode applications using the arbitration data and the situation data.

[0010] With this configuration, multiple shadow mode applications can be effectively run depending on the vehicle situation.

[0011] One aspect of the present disclosure is an in-vehicle device including an application management unit, a situation data collection unit, and a shadow arbitration unit.

[0012] With this configuration, the device can be used as an in-vehicle device in the above-described data collection system, and the same effects as those of the above-described data collection system can be obtained.

[0013] One aspect of the present disclosure is a data collection method implemented by a computer functioning as an in-vehicle device, including setting a shadow mode application that operates based on inputs equivalent to those of a production application without affecting vehicle control to a state where it can be executed on the in-vehicle device or a vehicle equipped with the in-vehicle device, collecting situation data indicating the status of the vehicle, and mediating the operation of multiple shadow mode applications using mediation data and the situation data that include information necessary to launch the shadow mode application.

[0014] By carrying out such a method, it is possible to obtain the same effect as that of the above-mentioned in-vehicle device.

[0015] One aspect of the present disclosure is a program that causes a computer installed in an in-vehicle device to function as an application management unit, a situation data collection unit, and a shadow arbitration unit.

[0016] By executing such a program, it is possible to obtain the same effects as the above-mentioned in-vehicle device.

[0017] 1 is a block diagram showing the configuration of a data collection system. FIG. 2 is a block diagram showing the configuration of a data collection device. FIG. 3 is a block diagram showing the configuration of a center. FIG. 4 is a functional block diagram showing the functional configuration of the center and a data collection device. FIG. 5 is an explanatory diagram illustrating a shadow mode application and a scene in which the shadow mode application is started. FIG. 6 is an explanatory diagram illustrating the contents of arbitration data. FIG. 7 is an explanatory diagram illustrating driving scene data, vehicle state data, and operation logs belonging to situation data. FIG. 8 is a flowchart of arbitration processing executed by a shadow arbitration unit. FIG. 9 is a flowchart of logic determination processing.

[0018] Hereinafter, embodiments of the present disclosure will be described with reference to the drawings.

[0019] [1. Configuration] A first embodiment of the present disclosure will be described below with reference to the drawings.

[0020] As shown in FIG. 1, the data collection system 1 of this embodiment includes a plurality of data collection devices 2 and a center 3 .

[0021] The data collection device 2 is mounted on a vehicle and has a function of performing data communication with the center 3 via a wide area wireless communication network NW.

[0022] The center 3 is a device that manages the data collection system 1. The center 3 has a function of performing data communication with a plurality of data collection devices 2 via a wide area wireless communication network NW.

[0023] 2, the data collection device 2 includes a control unit 11, a CAN communication unit 12, a storage unit 13, and a communication unit 14. CAN is an abbreviation for Controller Area Network.

[0024] The control unit 11 is an electronic control device mainly composed of a microcomputer including a CPU 111, a ROM 112, a RAM 113, etc. Various functions of the microcomputer are realized by the CPU 111 executing a program stored in a non-transitory tangible recording medium. In this example, the ROM 112 corresponds to the non-transitory tangible recording medium storing the program. Furthermore, the execution of this program results in the execution of a method corresponding to the program. Note that some or all of the functions executed by the CPU 111 may be configured as hardware using one or more ICs, etc. Furthermore, the number of microcomputers constituting the control unit 11 may be one or more.

[0025] The CAN communication unit 12 is connected to a plurality of ECUs via communication lines so as to be able to communicate data with them, and transmits and receives data according to the CAN communication protocol. Specifically, the plurality of ECUs connected to the CAN communication unit 12 include an engine ECU that controls the engine, a brake ECU that controls the brakes, a steering ECU that controls the steering, a suspension ECU that controls the suspension, and an ECU that controls the on / off of lights. In Fig. 2, only ECUs 16, 17, and 18 are shown as ECUs connected to the CAN communication unit 12. ECU stands for Electronic Control Unit.

[0026] The storage unit 13 is a storage device for storing various data.

[0027] The communication unit 14 performs data communication with the center 3 via the wide area wireless communication network NW.

[0028] As shown in FIG. 3, the center 3 includes a control unit 31, a communication unit 32, and a storage unit 33.

[0029] The control unit 31 is an electronic control device mainly composed of a microcomputer including a CPU 311, a ROM 312, a RAM 313, etc. Various functions of the microcomputer are realized by the CPU 311 executing a program stored in a non-transitory tangible recording medium. In this example, the ROM 312 corresponds to the non-transitory tangible recording medium storing the program. Furthermore, the execution of this program executes a method corresponding to the program. Note that some or all of the functions executed by the CPU 311 may be configured as hardware using one or more ICs, etc. Furthermore, the number of microcomputers constituting the control unit 31 may be one or more.

[0030] The communication unit 32 performs data communication with a plurality of data collection devices 2 via the wide area wireless communication network NW.

[0031] The storage unit 33 is a storage device for storing various data.

[0032] 4, the center 3 includes an application distribution unit 51 and a data collection unit 52 as functional blocks realized by the CPU 311 executing a program stored in the ROM 312. The center 3 includes an application database (hereinafter referred to as application DB) 53 and a collected data database (hereinafter referred to as collected data DB) 54 in the storage unit 33. The functional blocks of the center 3 may be distributed and arranged in multiple servers connected to the wide-area wireless communication network NW.

[0033] The application DB 53 stores an application storage unit 531 and an arbitration data storage unit 532 .

[0034] The app storage unit 531 stores a shadow mode application (hereinafter, a shadow mode app). A shadow mode app is an app that uses inputs equivalent to those of an application actually running in the vehicle (hereinafter, a production app) and performs processing different from that of the production app to achieve similar processing results. Shadow mode is a mechanism in which a shadow mode app is executed in parallel with a production app, and the shadow mode app is not activated, but a difference from the production app is detected. Activation means that vehicle control is actually performed based on the processing results of the app. In other words, the shadow mode app executes processing without affecting vehicle control. Multiple shadow mode apps may be run for one running app, or a shadow mode app may be run for each of multiple production apps.

[0035] The input for a shadow mode app is determined for each shadow mode app. For example, if a shadow mode app for an operational app that detects targets using the detection results of a millimeter-wave radar and the detection results of an in-vehicle camera as input is a millimeter-wave radarless app that detects targets using the detection results of the in-vehicle camera as input, the detection results of the in-vehicle camera are determined as the input for this shadow mode app.

[0036] Shadow mode applications include, for example, a rain sensorless application, a millimeter wave radarless application, an ADAS sensor low resolution application, and a fuel consumption prediction application, as shown in FIG.

[0037] The rain sensorless app is an app that realizes the same functions as a rain sensor installed in a vehicle using other in-vehicle devices such as an in-vehicle camera or radar sensor, thereby, for example, eliminating the need for a rain sensor. The millimeter-wave radarless app is an app that realizes the same functions as a millimeter-wave radar installed in a vehicle using other in-vehicle devices such as an in-vehicle camera, thereby, for example, eliminating the need for a rain sensor. The ADAS sensor resolution reduction app is an app that reduces the processing load related to ADAS by replacing the high-resolution sensors used in ADAS with processing using low-resolution sensors. The fuel economy prediction app is an app that predicts fuel economy from various data obtained from a vehicle. The above-mentioned shadow mode app is distributed to vehicles equipped with target sensors, etc., and collects data in a state where the actual detection values ​​of the sensors can be compared with the processing results of the shadow mode app. The collected data is used for developing new apps, improving app performance, etc.

[0038] The arbitration data storage unit 532 stores arbitration data. The arbitration data is data used to determine which shadow mode application to run from among multiple shadow mode applications in a vehicle to which the shadow mode applications are distributed. The arbitration data may include, for example, an arbitration data ID, an application ID, an operation priority, an operation scene, a CPU usage rate, and a memory usage amount, as shown in FIG. 6 .

[0039] The arbitration data ID is data that uniquely identifies the arbitration data. The app ID is data that uniquely identifies the shadow mode app linked to the arbitration data ID. The operation priority is data that indicates the priority of the shadow mode app. The operation priority may be specified, for example, from 1 to 5, with 1 indicating the highest priority and 5 indicating the lowest priority. The operation scene indicates a driving scene in which the shadow mode app is to be operated. The driving scene is data that indicates the surrounding conditions in which the vehicle is traveling. The operation scene may be selected from a plurality of predefined driving scenes. Specifically, as shown in FIG. 5 , the operation scene may be defined using weather, time, location, etc. Furthermore, depending on the type of shadow mode app, it may be defined to be operated constantly regardless of the driving scene. The CPU usage is the CPU usage expected when the shadow mode app is operating. The memory usage is the memory usage expected for the operation of the shadow mode app. Hereinafter, the CPU usage and memory usage indicated in the arbitration data are collectively referred to as the "estimated resource usage."

[0040] In response to a request from the data collection device 2 , the application distribution unit 51 distributes the shadow mode application and arbitration data stored in the application DB 53 to the data collection device 2 .

[0041] The data collection unit 52 collects data from the data collection device 2 to which the shadow mode application is distributed.

[0042] The log DB 54 stores the data collected by the data collection unit 52 .

[0043] [3. Vehicle-Side Functional Configuration] The data collection device 2 includes an application management unit 41, a situation data collection unit 42, a shadow arbitration unit 43, an application execution unit 44, and a data upload unit 47 as functional blocks realized by the CPU 111 executing a program stored in the ROM 112. The data collection device 2 may further include a difference determination unit 45 and a verification data collection unit 46. The data collection device 2 may further include a situation data storage unit 48 and a verification data storage unit 49 in the storage unit 13.

[0044] Note that some of the functional blocks of the data collection device 2 (for example, the application execution unit 44) may be distributed among the ECUs 16 to 18. That is, some of the functional blocks may be realized by the CPUs of the ECUs 16 to 18 executing programs.

[0045] The application management unit 41 transmits a request to acquire a shadow mode application to the center 3, and installs the shadow mode application distributed from the center 3 so that it can be executed by the application execution unit 44. The application management unit 41 provides the shadow mode application and arbitration data distributed from the center 3 to the shadow arbitration unit 43.

[0046] The situation data collection unit 42 extracts pre-specified data from the data transmitted and received over the CAN bus via the CAN communication unit 12, and stores the extracted data in the situation data storage unit 48. The situation data collection unit 42 may not only store the collected data as is, but also store data interpreted from a combination of multiple pieces of data, etc.

[0047] The situation data storage unit 48 stores resource situation data 481, vehicle state data 482, driving scene data 483, application operation log 484, etc. in chronological order.

[0048] The resource status data 481 is data indicating the resource usage status of each of the data collection devices 2 or ECUs 16 to 18 (hereinafter referred to as application-implemented ECUs) in which a shadow mode application is installed. The resource status data 481 may include, for example, CPU usage rate and memory usage.

[0049] The vehicle state data 482 is data indicating the behavior of the vehicle, the driver's operation of the vehicle, etc. The vehicle state data 482 may include, for example, the vehicle speed, accelerator opening, brake strength, steering angle, wiper operation, headlamp operation, etc. As shown in Fig. 7 , the vehicle state data 482 is stored in the situation data storage unit 48 in association with the time at which the data was acquired and an index that uniquely identifies the vehicle state data 482 acquired at that time.

[0050] The driving scene data 483 is data used to identify the environment and surrounding conditions in which the vehicle is driving, i.e., the driving scene. The driving scene data 483 may include road type, roadway R, presence or absence of surrounding vehicles, rainfall, illuminance, etc. The road type and roadway R may be set based on the vehicle position and map data corresponding to the vehicle position. The presence or absence of surrounding vehicles may be set based on detection results from an on-board camera or a perimeter monitoring radar. The rainfall and illuminance may be set based on detection results from a dedicated rainfall sensor or illuminance sensor. Like the vehicle state data 482, the driving scene data 483 is stored in the situation data storage unit 48 in association with the time at which the data was acquired and an index that uniquely identifies the driving scene data 483 acquired at that time.

[0051] The application operation log 484 is data indicating logs of operating applications and shadow mode applications linked to the operating applications (hereinafter referred to as operation logs). The operation log includes extraction results, calculation results, determination results, and the like obtained by executing the applications. As shown in FIG. 7 , the application operation log 484 is stored in the situation data storage unit 48 in association with the time at which the log was acquired, an index that uniquely identifies the application operation log 484 acquired at that time, an index of the driving scene data 483 acquired at the time closest to that time, and an index of the vehicle state data 482 acquired at the time closest to that time.

[0052] The application operation log 484 may include operation status information for each shadow mode application. The operation status information may include information indicating the time when the operation scene of the shadow mode application matches the driving scene, and information indicating whether the shadow mode application was actually launched when the operation scene of the shadow mode application matches the driving scene. In other words, the operation status information may include information indicating the operation frequency of each shadow mode application.

[0053] The shadow arbitration unit 43 determines which shadow mode application to launch from among the shadow mode applications that are executable by the application execution unit 44, based on the situation data stored in the situation data storage unit 48 and the arbitration data acquired together with the shadow mode application.

[0054] The shadow arbitration unit 43 includes a logic determination unit 431 and an AI determination unit 432. The logic determination unit 431 deterministically determines shadow mode apps to be launched according to preset logic. The AI ​​determination unit 432 determines shadow mode apps to be launched using an AI model. The AI ​​model is generated by machine learning a neural network using arbitration data and situation data as input, so as to output execution priorities of shadow mode apps to be executed depending on the situation indicated by the arbitration data and situation data.

[0055] Note that in a certain situation, if there is a shadow mode app that you want to ensure is running, the desired shadow mode app will not necessarily be selected when you use the AI ​​determination unit 432. Therefore, in a situation where there is a shadow mode app that you want to ensure is running, you should use the logic determination unit 431, which makes a selection according to a clear logic, and if you only need to make the optimal selection depending on the situation, you should use the AI ​​determination unit 432.

[0056] The application execution unit 44 starts and stops applications that perform vehicle control, etc. The application execution unit 44 installs shadow mode applications acquired from the center 3 so that they are executable, and starts and stops the installed shadow mode applications in accordance with instructions from the shadow arbitration unit 43. Applications other than shadow mode applications that are currently running are active applications. The application execution unit 44 chronologically collects logs of active applications and logs of shadow mode applications currently running in accordance with instructions from the shadow arbitration unit 43, and stores them as an application operation log 484 in the situation data storage unit 48.

[0057] Note that a running shadow mode application is configured to be terminated when a predetermined termination condition is met, in addition to being forcibly terminated by an instruction from the shadow arbitration unit 43. The termination condition may be, for example, that the driving scene matches a stopping scene, that the operating time reaches a preset time, or that the collection of necessary verification data is completed.

[0058] The difference determination unit 45 compares the log of the production application with the operation log of the shadow mode application linked to the production application, and if a significant difference is detected, instructs the verification data collection unit 46 to collect verification data.

[0059] In accordance with instructions from the difference determination unit 45, the verification data collection unit 46 acquires verification data determined for each application from the situation data storage unit 48 during a collection period determined for each application, and stores the verification data in the verification data storage unit 49.

[0060] The verification data includes data required for verifying the difference between the logs. Specifically, as shown in FIG. 7 , the verification data may include vehicle state data 482, driving scene data 483, vehicle state data 483, and an application operation log 484. Note that FIG. 7 illustrates an example in which the shadow mode application is a rainfall estimation shadow mode application, and two shadow mode applications are operated for one operational application. In this case, the application operation log 484 displays data in a format that allows comparison between the log of the operational application and the logs of each shadow mode application.

[0061] The data upload unit 47 uploads the verification data stored in the verification data storage unit 48 to the center 3 .

[0062] 4. Processing Next, the arbitration processing executed by the shadow arbitration unit 43 will be described with reference to the flowchart of FIG.

[0063] The arbitration process is repeatedly executed while the data collection device 2 is running.

[0064] In S110, the shadow arbitration unit 43 acquires the driving scene data 483 representing the current driving scene from the situation data storage unit 48.

[0065] In S120, the shadow arbitration unit 43 refers to the arbitration data related to the stopped shadow mode apps and extracts shadow mode apps (hereinafter referred to as stopped arbitration target apps) whose current driving scene matches the operating scene indicated in the arbitration data.

[0066] In S130, the shadow arbitration unit 43 references the application operation log 484 and other information related to the active shadow mode applications to extract active shadow mode applications that are subject to arbitration (hereinafter, active arbitration target applications). Specifically, all active shadow mode applications, excluding those that meet the following exclusion conditions, are active arbitration target applications. The exclusion conditions may include at least one of the following: the shadow mode application is currently collecting verification data from the verification data collection unit 46; and the elapsed time since launching is less than a predetermined lower limit. Furthermore, the exclusion conditions may include the operation priority being equal to or greater than a predetermined value (i.e., a relatively low priority). Hereinafter, stopped arbitration target applications and active arbitration target applications are collectively referred to as arbitration target applications.

[0067] In S140, the shadow arbitration unit 43 determines whether or not a stopped arbitration target application was extracted in S120, and if a stopped arbitration target application was extracted, the process proceeds to S150, and if a stopped arbitration target application was not extracted, the process ends.

[0068] In S150, the shadow arbitration unit 43 acquires the arbitration data and the operation status information included in the application operation log 484 for each of the arbitration target applications extracted in S120 and S130.

[0069] In S160, the shadow arbitration unit 43 determines whether any stopped arbitration target applications exist that have an operation priority set to 1 included in the arbitration data. If any stopped arbitration target applications exist that have an operation priority set to 1, the shadow arbitration unit 43 proceeds to S170; if no stopped arbitration target applications exist, the shadow arbitration unit 43 proceeds to S180.

[0070] In S170, the shadow arbitration unit 43 determines whether there is a stopped arbitration target app among the stopped arbitration target apps for which a preset rescue condition is met. If there is, the process proceeds to S180. If there is not, the process proceeds to S190. The rescue condition may include, for example, that the operation priority is set to 2 or higher and the operation frequency calculated from the operation status information is equal to or less than a predetermined value. The operation frequency may be, for example, the number of times an app is extracted as a stopped arbitration target app and actually launched within a certain period of time. The rescue condition may also include the number of consecutive times that an app is extracted as a stopped arbitration target app but is not actually launched, being equal to or greater than a predetermined value.

[0071] In S180, the shadow arbitration unit 43 executes arbitration by the logic determination unit 431, and then the process proceeds to S200.

[0072] In S190, the shadow arbitration unit 43 executes arbitration by the AI ​​determination unit 432, and then proceeds to S200.

[0073] In both S180 and S190, an execution list is generated that lists stopped shadow mode applications that should be started, and a non-execution list is generated that lists running shadow mode applications that should be stopped.

[0074] In S200, the shadow arbitration unit 43 outputs an instruction to the application execution unit 44 to stop the shadow mode applications that are running and are shown in the non-execution list.

[0075] In S210, the shadow arbitration unit 43 outputs an instruction to the application execution unit 44 to start the shadow mode application that is stopped and is shown in the execution list, and then ends the process.

[0076] The arbitration performed by the AI ​​determination unit 432 in S190 uses a machine-learned AI model. Inputs to the AI ​​model may include operation priorities and estimated resource usage amounts for all arbitration target apps, as well as operation status information included in the app operation log 484. Further, inputs to the AI ​​model may include current vehicle state data 482 and current resource status data 481. The AI ​​model is configured to output an execution list and a non-execution list.

[0077] Next, the arbitration process by the logic determination unit 431 executed in the above-mentioned S180 will be described with reference to the flowchart of FIG.

[0078] When this process starts, in S310, the shadow arbitration unit 43 determines whether there is an unprocessed stopped arbitration target application in the processes of S320 to S380 described below. If the shadow arbitration unit 43 determines that there is an unprocessed stopped arbitration target application, it proceeds to S320. If the shadow arbitration unit 43 determines that there is no unprocessed stopped arbitration target application, it terminates the process.

[0079] In S320, the shadow arbitration unit 43 selects one startup candidate from among the stopped arbitration target applications that have not yet been processed. Here, the selection is made in descending order of operational priority. If there are multiple stopped arbitration target applications with the same operational priority, the selection is made in descending order of expected resource usage.

[0080] In S330, the shadow arbitration unit 43 determines whether the startup candidate can be executed by comparing the estimated resource usage of the shadow mode application that has been selected as the startup candidate with the current resource status data 481. If the shadow arbitration unit 43 determines that there are resources available to execute the startup candidate and that the startup candidate can be executed, it proceeds to S380. If the shadow arbitration unit 43 determines that there are insufficient resources and that the startup candidate cannot be executed, it proceeds to S340.

[0081] In S340, the shadow arbitration unit 43 determines whether or not there is an active application to be arbitrated. If there is an active application to be arbitrated, the process proceeds to S350; if there is no active application to be arbitrated, the process ends.

[0082] In S350, the shadow arbitration unit 43 selects one candidate to stop from among the running arbitration target applications. Specifically, a running arbitration target application with a higher operational priority value (i.e., a lower priority) than the launch candidate may be set as a low-priority application, and the low-priority application with the lowest operational priority among the low-priority applications may be set as the candidate to stop. Furthermore, if there are multiple low-priority applications with the lowest operational priority, the low-priority application with the largest estimated resource usage may be set as the candidate to stop.

[0083] In S360, the shadow arbitration unit 43 determines whether stopping the running shadow mode app selected as a candidate to be stopped will resolve the resource shortage that would occur when starting the stopped shadow mode app selected as a candidate to be started. If the shadow arbitration unit 43 determines that the resource shortage will be resolved, it proceeds to S370. If the shadow arbitration unit 43 determines that the resource shortage will not be resolved, it terminates the process. Note that if the resource shortage is not resolved, the same process may be repeated until the resource shortage is resolved by selecting multiple haltable apps as candidates to be stopped, or until there are no haltable apps that are candidates to be stopped.

[0084] In S370, the shadow arbitration unit 43 adds the candidate to be stopped to the non-execution list, and excludes the candidate to be stopped from the applications to be arbitrated, and then proceeds to S380.

[0085] In S380, the shadow arbitration unit 43 adds the startup candidate to the non-execution list, removes the startup candidate from the applications to be arbitrated, and returns the process to S310.

[0086] 5. Correspondence of Terminology The data collection device 2 of this embodiment corresponds to the in-vehicle device in this disclosure.

[0087] 6. Effects According to the embodiment described above in detail, the following effects are achieved.

[0088] (6a) According to the data collection system 1, the data collection device 2 can switch the shadow mode app to be operated depending on the driving scene. Therefore, data collection using the shadow mode app can be efficiently performed while reducing the processing load on the vehicle required to execute the shadow mode app. Furthermore, the collected data can be used to improve the performance of various applications and develop new applications.

[0089] (6b) In the data collection device 2, operation priorities are assigned to shadow mode apps, and shadow mode apps with higher operation priorities are set to be launched preferentially. This prevents data from being missed in important driving scenes where high-priority shadow mode apps are launched.

[0090] (6c) The data collection device 2 includes a logic determination unit 431 that makes deterministic determinations and an AI determination unit 432 that makes determinations using an AI model, and if there are shadow mode apps that you want to be sure to launch, arbitrate the shadow mode apps using the logic determination unit 431. Therefore, by including, for example, shadow mode apps that repeatedly lose arbitration as shadow mode apps that you want to be sure to launch, it is possible to reliably collect data even for shadow mode apps with low operation priority.

[0091] 7. Other Embodiments Although the embodiments of the present disclosure have been described above, the present disclosure is not limited to the above-described embodiments and can be implemented in various modifications.

[0092] (7a) In the above embodiment, the shadow arbitration unit 43 includes the logic determination unit 431 and the AI ​​determination unit 432, but it may include only one of them.

[0093] (7b) In the above embodiment, when a new shadow mode application cannot be launched due to a resource shortage, the resource shortage is resolved by stopping a running shadow mode application with a low operation priority. However, when a resource shortage occurs, the launch of a new shadow mode application may be prevented.

[0094] (7c) In the above embodiment, the data collection device 2 may omit the difference determination unit 45, the verification data collection unit 46, and the verification data storage unit 49. In this case, the data upload unit 47 may be configured to upload the vehicle state data 482, the driving scene data 483, the application operation log 484, and the like, during the period when the shadow mode application is running, to the center 3 regardless of whether there is a difference between the log of the operating application and the log of the shadow application.

[0095] (7d) Multiple functions possessed by one component in the above embodiments may be realized by multiple components, or one function possessed by one component may be realized by multiple components. Also, multiple functions possessed by multiple components may be realized by one component, or one function realized by multiple components may be realized by one component. Also, part of the configuration of the above embodiments may be omitted. Also, at least part of the configuration of the above embodiments may be added to or substituted for the configuration of another of the above embodiments.

[0096] (7e) In addition to the above-described data collection system 1 and the data collection device 2 as an in-vehicle device, the present disclosure can also be realized in various forms, such as a program for causing a computer to function as the data collection device, a non-transient physical recording medium such as a semiconductor memory on which this program is recorded, and a data collection method.

[0097] [8. Technical Concepts Disclosed in the Present Specification] [Item 1] A data collection system comprising: an application distribution unit (51) configured to distribute to an in-vehicle device a shadow mode application that operates based on input equivalent to an operational application without affecting vehicle control, and arbitration data including information necessary for starting the shadow mode application; an application management unit (41) configured to set the shadow mode application distributed by the application distribution unit to a state where it is executable on the in-vehicle device or a vehicle equipped with the in-vehicle device; a situation data collection unit (42) configured to collect situation data indicating the situation of the vehicle; and a shadow arbitration unit (43) configured to arbitrate the operation of a plurality of the shadow mode applications using the arbitration data and the situation data.

[0098] [Item 2] The data collection system according to Item 1, comprising: a difference determination unit (45) configured to determine whether or not there is a difference between a log obtained from the production application and a log obtained from the shadow mode application linked to the production application; and a verification data collection unit (46) configured to collect data necessary to verify the difference when the difference determination unit determines that there is a difference.

[0099] [Item 3] The data collection system according to item 1 or 2, wherein the arbitration data includes an operation scene that operates the shadow mode application, the situation data includes a driving scene that indicates a situation around the vehicle, and the shadow arbitration unit targets the shadow mode application whose operation scene matches the driving scene as a target for arbitration.

[0100] [Item 4] The data collection system according to any one of items 1 to 3, wherein the shadow arbitration unit comprises: a logic determination unit (431) configured to determine the shadow mode application to be run according to a preset logic; and an AI determination unit (432) configured to determine the shadow mode application to be run using an AI model.

[0101] [Item 5] A data collection system according to any one of items 1 to 4, wherein the status data includes operation status information indicating the operation status of each shadow mode application, and the shadow arbitration unit prioritizes operation of the shadow mode application whose operation frequency is equal to or less than a predetermined value in accordance with the operation status information.

[0102] [Item 6] A data collection system according to any one of items 1 to 5, wherein the arbitration data includes estimated resource usage representing the amount of resource usage required when the shadow mode application is operated, and the shadow arbitration unit preferentially operates the shadow mode application with the smaller estimated resource usage.

[0103] [Item 7] The data collection system according to Item 6, wherein the arbitration data includes an operation priority indicating a priority for operating the shadow mode application, and the shadow arbitration unit determines a shadow mode application that is determined to be inexecutable due to a resource shortage based on a comparison between the expected resource usage and the resource status included in the status data as a target application, and determines a running shadow mode application that has a lower operation priority than the target application as a low-priority application, and if stopping the low-priority application will resolve the resource shortage, stops the low-priority application and operates the target application.

[0104] [Item 8] The data collection system according to Item 7, which cites Item 2, wherein the shadow arbitration unit excludes the running shadow mode application that is the target of processing by the verification data collection unit from the shadow mode applications that are to be stopped in order to operate the target app.

[0105] [Item 9] The data collection system according to Item 7 or 8, wherein the shadow arbitration unit excludes the shadow mode applications that are running and whose elapsed time since startup is less than a lower limit time from the shadow mode applications to be stopped in order to operate the target app.

[0106] [Item 10] The data collection system according to any one of items 1 to 9, wherein the shadow arbitration unit launches one shadow mode application for one production application.

[0107] [Item 11] The data collection system according to any one of items 1 to 10, wherein the shadow arbitration unit enables the launch of multiple shadow mode applications for one production application, and the verification data collection unit collects data in a format that allows logs of each shadow mode application to be compared.

Claims

1. A data collection system comprising: an application distribution unit (51) configured to distribute to an in-vehicle device a shadow mode application that operates based on input equivalent to a production application without affecting vehicle control, and arbitration data including information necessary to start the shadow mode application; an application management unit (41) configured to set the shadow mode application distributed by the application distribution unit to a state where it can be executed on the in-vehicle device or a vehicle equipped with the in-vehicle device; a situation data collection unit (42) configured to collect situation data indicating the situation of the vehicle; and a shadow arbitration unit (43) configured to arbitrate the operation of multiple shadow mode applications using the arbitration data and the situation data.

2. A data collection system as described in claim 1, comprising: a difference determination unit (45) configured to determine whether or not there is a difference between the log obtained from the production application and the log obtained from the shadow mode application linked to the production application; and a verification data collection unit (46) configured to collect data necessary to verify the difference when the difference determination unit determines that there is a difference.

3. A data collection system as claimed in claim 1 or claim 2, wherein the arbitration data includes an operation scene that operates the shadow mode application, the situation data includes a driving scene that shows the situation around the vehicle, and the shadow arbitration unit targets the shadow mode application whose operation scene matches the driving scene as the target of arbitration.

4. A data collection system according to claim 1 or 2, wherein the shadow arbitration unit comprises: a logic determination unit (431) configured to determine the shadow mode application to be run according to a preset logic; and an AI determination unit (432) configured to determine the shadow mode application to be run using an AI model.

5. A data collection system as claimed in claim 1 or claim 2, wherein the status data includes operation status information indicating the operation status of each shadow mode application, and the shadow arbitration unit prioritizes the operation of a shadow mode application whose operation frequency is equal to or less than a predetermined value in accordance with the operation status information.

6. A data collection system according to claim 1 or claim 2, wherein the arbitration data includes estimated resource usage representing the amount of resources required when the shadow mode application is operated, and the shadow arbitration unit gives priority to operating the shadow mode application with the smaller estimated resource usage.

7. A data collection system according to claim 6, wherein the arbitration data includes an operation priority indicating the priority of operating the shadow mode application, and wherein the shadow arbitration unit determines that the shadow mode application is unable to run due to a lack of resources based on a comparison between the estimated resource usage and the resource status included in the status data as a target application, and determines that a running shadow mode application having a lower operation priority than the target application is a low-priority application, and if stopping the low-priority application will resolve the resource shortage, stops the low-priority application and operates the target application.

8. A data collection system as described in claim 7, which cites claim 2, wherein the shadow arbitration unit excludes the running shadow mode application that is the target of processing by the verification data collection unit from the shadow mode applications that are stopped in order to operate the target app.

9. A data collection system according to claim 7, wherein the shadow arbitration unit excludes from the shadow mode applications to be stopped in order to operate the target app those shadow mode applications that are currently running and whose elapsed time since launch is less than a lower limit time.

10. A data collection system according to claim 1 or 2, wherein the shadow arbitration unit launches one shadow mode application for one production application.

11. A data collection system according to claim 1 or 2, wherein the shadow arbitration unit enables the launch of multiple shadow mode applications for one production application, and the verification data collection unit collects data in a format that allows the logs of each shadow mode application to be compared.

12. An in-vehicle device comprising: an application management unit (41) configured to set a shadow mode application that operates without affecting vehicle control based on input equivalent to a production application to a state where it can be executed in the in-vehicle device or a vehicle equipped with the in-vehicle device; a situation data collection unit (42) configured to collect situation data indicating the situation of the vehicle; and a shadow arbitration unit (43) configured to arbitrate the operation of multiple shadow mode applications using arbitration data including information necessary for starting the shadow mode application and the situation data.

13. A data collection method implemented by a computer functioning as an in-vehicle device, comprising: setting a shadow mode application, which operates based on input equivalent to that of a production application without affecting vehicle control, to a state in which it can be executed in the in-vehicle device or a vehicle equipped with the in-vehicle device; collecting situation data indicating the situation of the vehicle; and arbitrating the operation of multiple shadow mode applications using the situation data and arbitration data containing information necessary to start the shadow mode application.

14. A program for causing a computer mounted on an in-vehicle device to function as: an application management unit configured to set a shadow mode application that operates based on input equivalent to that of a production application without affecting vehicle control to a state where it can be executed in the in-vehicle device or a vehicle equipped with the in-vehicle device; a situation data collection unit configured to collect situation data indicating the situation of the vehicle; and a shadow arbitration unit configured to arbitrate the operation of multiple shadow mode applications using arbitration data including information necessary to start the shadow mode application and the situation data.

Citation Information

Patent Citations

  • Method and device for solving dual-computer cluster split brain

    CN105472022A

  • Manager, electronic control unit, system, control method, control program, and vehicle

    JP2022131355A

  • Self configuring peer to peer inter process messaging system

    US20040006603A1

  • Terminal device, process management method and process management program

    WO2012127596A1