Automobile computer, application starting method, and program
The onboard computer system addresses inefficiencies by differentiating between high-level and low-level applications, ensuring safe and efficient resource allocation by warning users of potential interference, thus maintaining safety requirements.
Patent Information
- Application Number
- PCT/JP2025/013664
- Authority / Receiving Office
- WO · WO
- Patent Type
- Applications
- Current Assignee / Owner
- Priority Date
- 2024-04-05
- Filing Date
- 2025-04-03
- Publication Date
- 2025-10-09
AI Technical Summary
Existing in-vehicle computers handle vehicle applications uniformly regardless of their safety levels, leading to potential inefficiencies and failure to meet safety requirements when conflicts arise.
An onboard computer system that distinguishes between high-level and low-level applications, using a determination unit to allocate resources and warn users if launching a new application would interfere with high-level operations, ensuring safety and efficiency.
Ensures safe and efficient operation of vehicle applications by prioritizing high-level applications, preventing resource shortages that could compromise safety.
Smart Images

Figure JP2025013664_09102025_PF_FP_ABST
Abstract
Description
In-vehicle computer, application startup method and program CROSS-REFERENCE TO RELATED APPLICATIONS
[0001] This international application claims priority based on Japanese Patent Application No. 2024-061400, filed with the Japan Patent Office on April 5, 2024, the entire contents of which are incorporated herein by reference.
[0002] FIELD OF THE DISCLOSURE The present disclosure relates to launching applications by an on-board computer.
[0003] The in-vehicle computer described in Patent Document 1 below installs a vehicle application with a conflict table attached, and when it receives a request to execute the vehicle application, it determines whether or not a conflict exists between the vehicle application and another vehicle application based on the conflict table. If the in-vehicle computer determines that a conflict exists, it does not execute the vehicle application, or, even if it executes the vehicle application, it does not allow access to the resource that is the subject of the conflict.
[0004] Patent No. 6809551
[0005] Vehicle applications include applications that require a high level of safety and applications that require a low level of safety. As a result of detailed consideration by the inventors, it has been found that if, as in the case of the above-mentioned on-board computer, conflicts between vehicle applications are uniformly determined and handled regardless of whether the required level of safety of the vehicle application is high or low, the required level of safety may not be met or resources may be allocated inefficiently.
[0006] One aspect of the present disclosure provides a technique that allows vehicle applications to be launched safely and efficiently.
[0007] An onboard computer according to one aspect of the present disclosure has installed thereon vehicle applications including one or more high-level applications that require a first required safety level as a required safety level, and one or more low-level applications that require a second required safety level that is lower than the first required safety level. The onboard computer includes a computing resource, a determination unit, and a warning unit. The computing resource is configured to be allocated to the operation of the vehicle applications. The determination unit is configured to determine whether launching the scheduled application will cause a shortage of computing resources and hinder the operation of the currently running high-level application, based on the processing load and required safety level of a scheduled application that is a newly scheduled vehicle application to be launched and the processing load and required safety level of each of the currently running vehicle applications. The warning unit is configured to output a warning to a user to stop launching the scheduled application, if the determination unit determines that the operation of the high-level application will be hindered.
[0008] In one aspect of the present disclosure, a vehicle-mounted computer has a high-level application and a low-level application installed. If the operation of the high-level application is interrupted, the safety requirement level may not be met. On the other hand, if the operation of a low-level application that is currently running is interrupted, the safety requirement level is unlikely to be interrupted. If the launch of a scheduled application is canceled in order to prioritize not interrupting the operation of the high-level application, the efficiency of use of computing resources may decrease. Therefore, the vehicle-mounted computer determines whether launching a new application will interrupt the operation of the high-level application, and if it determines that the operation of the high-level application will be interrupted, outputs a warning to the user. Thus, the vehicle-mounted computer can launch vehicle applications safely and efficiently.
[0009] Another aspect of the present disclosure is a method for launching an application, in which an on-board computer has installed thereon vehicle applications including one or more high-level applications that require a first level of safety level as a required safety level, and one or more low-level applications that require a second level of safety level that is lower than the first level, determines whether launching the scheduled application will interfere with the operation of the currently running high-level application based on the processing load and safety requirement level of the scheduled application, which is a vehicle application that is scheduled to be newly launched, and the processing load and safety requirement level of each of the currently running vehicle applications, and if it determines that the operation of the high-level application will be interfered with, warns the user to cancel the launch of the scheduled application.
[0010] By executing the application launch method according to another aspect of the present disclosure, the same effects as those of the above-described vehicle-mounted computer can be achieved.
[0011] A program according to yet another aspect of the present disclosure causes an onboard computer having installed thereon vehicle applications including one or more high-level applications that require a first level of safety level as a required safety level, and one or more low-level applications that require a second level of safety level that is lower than the first level, to determine whether launching the scheduled application will interfere with the operation of the currently running high-level application based on the processing load and required safety level of the scheduled application, which is a vehicle application that is scheduled to be newly launched, and the processing load and required safety level of each of the currently running vehicle applications, and if it is determined that the operation of the high-level application will be interfered with, to warn the user to cancel the launch of the scheduled application.
[0012] When the program according to yet another aspect of the present disclosure is executed by an in-vehicle computer, the same effect as that of the in-vehicle computer described above is achieved.
[0013] 1 is a block diagram showing the configuration of a system according to the first to seventh embodiments. FIG. 2 is a block diagram showing the configuration of a server device according to the first to seventh embodiments. FIG. 3 is a block diagram showing the configuration of an ECU according to the first to seventh embodiments. FIG. 4 is a table associating an average processing load, a maximum processing load, and a processing load pattern ID with an application ID according to the first to fifth embodiments. FIG. 5 is a table associating the type of processing load pattern with a processing load pattern identifier according to the first to fifth embodiments. FIG. 6 is a flowchart showing the startup process of an application executed by an ECU according to the first embodiment. FIG. 7 is a flowchart showing the startup process of an application executed by an ECU according to the second embodiment. FIG. 8 is a flowchart showing the startup process of an application executed by an ECU according to the third embodiment. FIG. 9 is a flowchart showing the startup process of an application executed by an ECU according to the fourth embodiment. FIG. 10 is a flowchart showing the startup process of an application executed by an ECU according to the fifth embodiment. FIG. 11 is a flowchart showing the startup process of an application executed by an ECU according to the sixth embodiment. FIG. 12 is a table associating the average CPU computation load, maximum CPU computation load, average extra-vehicle communication load, maximum extra-vehicle communication load, average memory usage, maximum memory usage, and processing load pattern ID with an application ID according to the sixth embodiment. FIG. 13 is a block diagram showing the configuration of an ECU according to the seventh embodiment. FIG. 14 is a flowchart showing the startup process of an application executed by an ECU according to the seventh embodiment.
[0014] 1 to 3, the configuration of a system 200 according to this embodiment and first to sixth embodiments described below will be described. The system 200 includes an electronic control unit (hereinafter, referred to as ECU) 10 and a server device 50.
[0015] 2, the server device 50 includes a server control unit 500, a server communication unit 540, and a storage device 550. The server communication unit 540 performs wireless communication with the ECU 10 via a wide area communication network.
[0016] The storage device 550 stores various vehicle applications developed and registered by software developers. Software developers include third parties. Third parties are companies other than original equipment manufacturers (OEMs).
[0017] Vehicle applications are installed and executed in various ECUs mounted in various vehicles to realize various vehicle functions. The computing capabilities of the various ECUs mounted in the vehicle are determined by the OEM manufacturer, and basic applications are pre-installed. The basic vehicle functions are realized by the various ECUs executing the basic applications. When a vehicle user wants to realize a function other than the basic vehicle functions, the vehicle user purchases a vehicle application that realizes the desired function from the server device 50 and downloads it to the ECU. Examples of vehicle applications include an inter-vehicle distance measurement application, an application for avoiding pedestrians running out into the road, and a navigation application.
[0018] Vehicle applications include vehicle applications requiring a high Automotive Safety Level (hereinafter referred to as "ASIL") (hereinafter referred to as "high-level applications") and vehicle applications requiring a low ASIL (hereinafter referred to as "low-level applications"). ISO 26262 (i.e., the functional safety standard) specifies four grades of vehicle safety levels, from A (lowest) to D (highest), and five levels of quality management (QM), which does not require a safety level to be met by ASIL. High-level applications require an ASIL of B level or higher. Low-level applications require an ASIL of A level or lower, or are QM. Each vehicle application is assigned a required ASIL level.
[0019] 4 and 5, the storage device 550 also stores a processing load table and a processing load pattern classification table for vehicle applications registered by software developers. The processing load table associates, for each vehicle application, application identification information (hereinafter referred to as ID) for identifying the vehicle application with an average processing load value, a maximum processing load value, and a processing load pattern ID. The processing load pattern classification table associates a processing load pattern with a processing load pattern ID.
[0020] The average processing load value is the average magnitude of the load from the start to the end of execution of the vehicle software. In other words, the average processing load value is the average amount of consumption of the computational resources 30 during execution of the vehicle software. The maximum processing load value is the maximum instantaneous load during execution of the vehicle software. In other words, the maximum processing load value is the maximum instantaneous amount of consumption of the computational resources 30 during execution of the vehicle software. The average processing load value and the maximum processing load value are registered in the server device 50 by the developer of the vehicle application.
[0021] The processing load pattern corresponds to a situation in which the processing volume (i.e., the amount of computational resources consumed) in the processing of the vehicle software increases. The situation in which the processing volume of the vehicle software increases varies depending on the type of vehicle software. The processing load pattern is registered in the server device 50 by the developer of the vehicle application.
[0022] For example, the processing load pattern of a vehicle application that performs image recognition, such as an inter-vehicle distance measurement application and an application for avoiding pedestrians running out into the road, is an image processing pattern. In the image processing pattern, the processing amount per unit time increases as the number of objects (i.e., processing targets) in an image increases. Therefore, in the image processing pattern, the processing amount increases or decreases depending on the traffic or road conditions around the vehicle. For example, in the image processing pattern, the processing amount is higher when the vehicle is moving than when the vehicle is parked. Also, in the image processing pattern, the processing amount is higher when the vehicle is moving on a road in an urban area than when the vehicle is moving on a highway. Also, in the image processing pattern, the processing amount is higher when the road is congested than when the road is clear.
[0023] Furthermore, the processing load pattern of vehicle applications that use map data, such as navigation applications, is a map reading pattern. In the map reading pattern, when the vehicle approaches the boundary of the map data currently being used, storage access occurs to read the next map data, and the processing volume increases. In other words, in the map reading pattern, the processing volume increases or decreases depending on the location where the vehicle is traveling. More specifically, in the map data reading pattern, when the vehicle reaches a specific location, the processing volume increases compared to before reaching the specific location.
[0024] Furthermore, the processing load pattern of a vehicle application that uploads vehicle data to the server device 50, such as a data collection application, is a data transmission / reception pattern. In the data transmission / reception pattern, the processing amount increases when a wireless connection to a Wi-Fi (registered trademark) spot is established in order to transmit vehicle data. That is, in the data transmission / reception pattern, the processing amount increases or decreases depending on the wireless communication environment. More specifically, in the data transmission / reception pattern, the processing amount increases when there is a wireless connection compared to when there is no wireless connection.
[0025] The server control unit 500 includes a CPU 510 and a memory 520. The server control unit 500 realizes various functions by the CPU 510 executing various programs stored in the memory 520. As shown in FIG. 1 , in this embodiment, the server control unit 500 has the function of an application distribution management unit 51.
[0026] The application distribution management unit 51 manages the distribution of vehicle applications. Specifically, when the application distribution management unit 51 receives an instruction to download a specific vehicle application from a user via the ECU 10, the application distribution management unit 51 transmits the specific vehicle application together with the corresponding maximum processing load value and average processing load value to the ECU 10 and instructs the ECU 10 to install the application. The application distribution management unit 51 may transmit a processing load pattern to the ECU 10 in addition to the maximum processing load value and average processing load value.
[0027] The ECU 10 is mounted on a vehicle. As shown in Fig. 3, the ECU 10 includes an ECU control unit 100, an ECU communication unit 130, and a vehicle IF unit 140. The vehicle IF unit 140 is connected to various in-vehicle devices via a vehicle network. The ECU communication unit 130 performs wireless communication with a server device 50 via a wide-area communication network. In the first to sixth embodiments, the ECU 10 corresponds to the in-vehicle computer of the present disclosure.
[0028] The ECU control unit 100 includes a CPU 110 and a memory 120. As shown in Fig. 1, vehicle applications downloaded from the server device 50 via the ECU communication unit 130 are installed in the memory 120. In the first to sixth embodiments, a first application 11, a second application 12, and a third application 13 are installed in the memory 120.
[0029] The first application 11 and the second application 12 are high-level applications. The third application 13 is a low-level application. Note that one or three or more high-level applications may be installed in the memory 120, or multiple low-level applications may be installed.
[0030] The ECU control unit 100 realizes various functions by the CPU 110 executing various programs stored in the memory 120. In this embodiment, the ECU control unit 100 has the function of an operating system (hereinafter referred to as OS) 20, and the OS 20 has the function of a process management unit 21. The process management unit 21 has the function of a scheduler 22.
[0031] The OS 20 installs the received vehicle application upon receiving an installation instruction for the vehicle application from the application distribution management unit 51. Furthermore, upon receiving an instruction from the user to start the vehicle application, the OS 20 allocates the computational resources 30 to the vehicle application and starts and executes the vehicle application. The computational resources 30 are hardware resources required for processing the vehicle application, and include the CPU 110, the memory 120, a communication bus for the ECU communication unit 130, etc.
[0032] In detail, the process management unit 21 receives an instruction to start a vehicle application, creates a plurality of processes for processing the vehicle application, and allocates a computing resource 30 to each of the plurality of processes. The scheduler 22 determines the execution order of the plurality of processes created by the process management unit 21, and allocates a computing resource 30. The scheduler 22 schedules the vehicle applications to be executed in parallel so that they are always executed even if a wait occurs. The scheduler 22 also schedules high-level applications so that they are executed with priority over low-level applications.
[0033] When multiple vehicle applications are executed in parallel, the OS 20 allocates the computational resources 30 to the multiple vehicle applications. As described above, vehicle applications include high-level applications and low-level applications. When a new high-level application is launched while a low-level application is running, the OS 20 may preferentially allocate the computational resources 30 to the high-level application. When the computational resources 30 allocated to the low-level application are insufficient, the OS 20 may allow the operation of the low-level application to be delayed and / or stopped as the situation progresses. When a new low-level application is launched while a high-level application or a low-level application is running, the OS 20 may preferentially allocate the computational resources 30 to the currently running high-level application or low-level application. When the computational resources 30 allocated to the newly launched low-level application are insufficient, the OS 20 may allow the operation of the newly launched low-level application to be delayed and / or stopped as the situation progresses.
[0034] However, if a new high-level application is started while another high-level application is running, there is a possibility that the ASIL requirements will not be met if the computational resources 30 become insufficient while the two high-level applications are running, causing a delay in the operation of one or both of the high-level applications. For example, if the high-level application is related to the running, steering, or stopping of the vehicle, delays in the operation of the high-level application must be avoided.
[0035] Therefore, when the OS 20 receives a new instruction to launch another high-level application while a high-level application is running, the OS 20 determines before launching the new high-level application whether launching the new high-level application will interfere with the operation of the currently running high-level application. If the OS 20 determines that launching the new high-level application will interfere with the operation of the currently running high-level application, the OS 20 warns the user to cancel the launch of the new high-level application. If the user abandons the launch of the new high-level application, the operation of the currently running high-level application is not interrupted, and the ASIL requirements are satisfied. As described above, the vehicle application installed by the user does not realize basic vehicle functions, but realizes additional functions. Therefore, if the user does not want to launch the new high-level application, the user can deal with the issue on their own without relying on additional functions.
[0036] 6, a description will be given of an application startup process executed by the ECU control unit 100 according to the first embodiment. In particular, the description will be given of a process performed when the ECU control unit 100 receives an instruction from the user to start the first application 11 while the second application 12 and the third application 13 are running.
[0037] In S10, the ECU control unit 100 reads out a processing load value A of the first application 11 to be launched from the memory 120. The processing load value A is a load measured in advance according to a predetermined standard. The predetermined standard may be, for example, an actual load value during operation, an average value over a predetermined period, a maximum value over a predetermined period, or the like, but is not limited to this.
[0038] Next, in S20, the ECU control unit 100 reads out the processing load values of the second and third applications 12, 13 that are currently running from the memory 120. The processing load values of the second and third applications are loads that have been measured in advance according to the same standard as the processing load value A or a different standard. The different standard is a standard that is suitable for combination with the standard for the processing load value A. Then, the ECU control unit 100 sums up the processing load values read out in S20 to calculate a total value B.
[0039] Next, in S30, the ECU control unit 100 adds the processing load value A to the total value B to calculate the total value C.
[0040] Next, in S40, the ECU control unit 100 determines whether the total value C exceeds a tolerance value D. The tolerance value D corresponds to the maximum available amount of the computational resources 30. If the ECU control unit 100 determines that the total value C is equal to or less than the tolerance value D, the ECU control unit 100 proceeds to the process of S50, and if the ECU control unit 100 determines that the total value C exceeds the tolerance value D, the ECU control unit 100 proceeds to the process of S60.
[0041] In S50, the ECU control unit 100 permits the start of the first application 11 that is scheduled to be started, and ends this process. That is, the ECU control unit 100 starts the first application 11 and ends this process.
[0042] In S60, the ECU control unit 100 determines that starting the first application 11 will interfere with the operation of the running second application 12. The ECU control unit 100 then warns the user to stop starting the first application 11, and ends this process. Specifically, the ECU control unit 100 outputs a warning from a display or speaker mounted on the vehicle.
[0043] <1-3. Effects> According to the first embodiment described above in detail, the following effects are achieved.
[0044] (1) The ECU 10 determines whether starting a new high-level application will interfere with the operation of the high-level application, and if it determines that the operation of the high-level application will be interfered with, outputs a warning to the user. Thus, the ECU 10 can launch vehicle applications safely and efficiently.
[0045] (2. Second Embodiment) <2-1. Differences from First Embodiment> The second embodiment has the same basic configuration as the first embodiment, so the differences will be described below. Note that the same reference numerals as in the first embodiment indicate the same configuration, and reference is made to the preceding description.
[0046] In the first embodiment described above, the ECU control unit 100 executes the application startup process shown in FIG. 6 , but in the second embodiment, instead of the application startup process shown in FIG. 6 , the ECU control unit 100 executes the application startup process shown in FIG. 7 .
[0047] 7, a description will be given of the application startup process executed by the ECU 10 according to the second embodiment. In particular, the description will be given of the process when the ECU control unit 100 receives an instruction from the user to start the first application 11 while the second application 12 and the third application 13 are running.
[0048] In S100 , the ECU control unit 100 reads from the memory 120 the maximum processing load value A of the first application 11 that is scheduled to be started.
[0049] Next, in S110, the ECU control unit 100 reads out the average processing load values of the second and third applications 12, 13 that are currently running from the memory 120. Then, the ECU control unit 100 sums up the average processing load values read out in S110 to calculate a sum value B.
[0050] Subsequently, in S120, the ECU control unit 100 adds the maximum processing load value A to the total value B to calculate the total value C.
[0051] Subsequently, in steps S130 to S150, the ECU control unit 100 executes the same processes as in steps S40 to S60.
[0052] 2-3. Effects According to the second embodiment described above in detail, the effect (1) of the first embodiment described above is achieved, and further, the following effects are achieved.
[0053] (2) The ECU 10 determines whether or not a shortage of the computational resources 30 has occurred using a sum C of the sum B of the average load values of the vehicle applications currently in operation and the maximum load value A of the vehicle application scheduled to be started. By using the sum C, the ECU 10 can accurately estimate the maximum consumption of the computational resources 30 when the vehicle application scheduled to be started is started. Consequently, the ECU 10 can accurately determine whether or not the operation of the high-level application will be hindered.
[0054] (3. Third Embodiment) <3-1. Differences from First Embodiment> The third embodiment has the same basic configuration as the first embodiment, so the differences will be described below. Note that the same reference numerals as in the first embodiment indicate the same configuration, and reference is made to the preceding description.
[0055] In the first embodiment described above, the ECU control unit 100 executes the application startup process shown in FIG. 6 , but in the third embodiment, instead of the application startup process shown in FIG. 6 , the ECU control unit 100 executes the application startup process shown in FIG. 8 .
[0056] 8, a description will be given of the application startup process executed by the ECU 10 according to the third embodiment. In particular, the description will be given of the process when the ECU control unit 100 receives an instruction from the user to start the first application 11 while the second application 12 and the third application 13 are running.
[0057] In S200, the ECU control unit 100 reads from the memory 120 the maximum processing load value A1 and the average processing load value A2 of the first application 11 that is scheduled to be started.
[0058] Next, in S210, the ECU control unit 100 reads from the memory 120 the maximum processing load values and average processing load values of the second and third applications 12 and 13 that are currently running. The ECU control unit 100 then calculates all combinations (N) of the maximum processing load values and average processing load values of the second and third applications 12 and 13. The ECU control unit 100 then calculates total values B1 to BN by adding up the processing load values of the N combinations. Specifically, the ECU control unit 100 calculates total value B1 by adding the maximum processing load value of the second application 12 to the maximum processing load value of the third application 13. The ECU control unit 100 calculates total value B2 by adding the maximum processing load value of the second application 12 to the average processing load value of the third application 13. The ECU control unit 100 calculates total value B3 by adding the average processing load value of the second application 12 to the maximum processing load value of the third application 13. The ECU control unit 100 adds the average processing load value of the third application 13 to the average processing load value of the second application 12 to calculate a sum B4.
[0059] Next, in S220, the ECU control unit 100 adds the maximum processing load value A1 or the average processing load value A2 to each of the total values B1 to BN to calculate 2N total values C1 to C(2N). Specifically, the ECU control unit 100 adds the maximum processing load value A1 to each of the total values B1 to B4 to calculate total values C1 to C4. Furthermore, the ECU control unit 100 adds the average processing load value A2 to each of the total values B1 to B4 to calculate total values C5 to C8.
[0060] Next, in S230, the ECU control unit 100 calculates the number K of total values that are greater than the allowable value D among the total values C1 to C8. K is an integer between 0 and 8.
[0061] Next, in S240, the ECU control unit 100 determines whether the number K exceeds a preset reference value X. The reference value X is set as the ratio of the total values C1 to C(2N) to the number 2N. If the ECU control unit 100 determines that the number K is equal to or less than the reference value X, the process proceeds to S250. If the ECU control unit 100 determines that the number K exceeds the reference value X, the process proceeds to S260.
[0062] Subsequently, in S250 and S260, the ECU control unit 100 executes the same processes as in S50 and S60.
[0063] <3-3. Effects> According to the third embodiment described above, in addition to the effect (1) of the first embodiment described above, the following effects are also achieved.
[0064] (3) By considering all combinations of the average load values and maximum load values of the vehicle applications currently in operation, the ECU 10 can accurately estimate the maximum consumption of the computing resources 30 when the vehicle application to be started is started. As a result, the ECU 10 can accurately determine whether the operation of the high-level application will be hindered.
[0065] (4. Fourth Embodiment) <4-1. Differences from the First Embodiment> The basic configuration of the fourth embodiment is similar to that of the first embodiment, and therefore differences will be described below. Note that the same reference numerals as those in the first embodiment indicate the same configuration, and reference is made to the preceding description.
[0066] In the first embodiment described above, the ECU control unit 100 executed the application startup process shown in FIG. 6 , but in the fourth embodiment, instead of the application startup process shown in FIG. 6 , the ECU control unit 100 executes the application startup process shown in FIG. 9 .
[0067] 9, a description will be given of the application startup process executed by the ECU 10 according to the fourth embodiment. In particular, the description will be given of the process when the ECU control unit 100 receives an instruction from the user to install and start the first application 11 while the second application 12 and the third application 13 are running.
[0068] In S300 , when the first application 11 is installed, the ECU control unit 100 acquires the corresponding processing load pattern from the server device 50 and stores it in the memory 120 .
[0069] Next, in S310 , the ECU control unit 100 reads the maximum processing load value A and the processing load pattern of the first application 11 from the memory 120 .
[0070] Next, in S320, the ECU control unit 100 calculates a total value B1 by adding up the average processing load values of the vehicle applications that are running and have a processing load pattern different from that of the first application 11.
[0071] For example, if the processing load patterns of the first and third applications 11, 13 are image processing load patterns and the processing load pattern of the second application 12 is a map reading pattern, the ECU control unit 100 calculates the average processing load value of the second application 12 as the sum B1. If the processing load patterns of the first to third applications 11 to 13 are all the same, the ECU control unit 100 calculates the sum B1 to be 0.
[0072] Next, in S330, ECU control unit 100 calculates a total value B2 by adding up the maximum processing load values of the vehicle applications that are running and have the same processing load pattern as the first application.
[0073] For example, if the processing load patterns of the first and third applications 11, 13 are image processing load patterns and the processing load pattern of the second application 12 is a map reading pattern, the ECU control unit 100 calculates the maximum processing load value of the third application 13 as the sum value B2. If the processing load patterns of the second and third applications 12, 13 are different from the processing load pattern of the first application 11, the ECU control unit 100 calculates the sum value B2 to be 0.
[0074] Subsequently, in S340, the ECU control unit 100 calculates a total value C by adding the total value B2 and the maximum processing load value A to the total value B1.
[0075] Subsequently, in steps S350 to S370, the ECU control unit 100 executes the same processes as in steps S40 to S60.
[0076] <4-3. Effects> According to the fourth embodiment described above, in addition to the effect (4) of the first embodiment described above, the following effects are also achieved.
[0077] (4) When the processing load patterns of the vehicle application scheduled to be started and the vehicle application currently in operation are different, the loads of the vehicle application scheduled to be started and the vehicle application currently in operation increase at different times. Therefore, the average processing load values of each of the currently in operation vehicle applications are summed to calculate a total value B1. When the processing load patterns of the vehicle application scheduled to be started and the vehicle application currently in operation are the same, the loads of the vehicle application scheduled to be started and the vehicle application currently in operation increase at the same time. Therefore, the maximum processing load values of each of the currently in operation vehicle applications are summed to calculate a total value B2. The ECU 10 can accurately determine whether a shortage of computing resources 30 has occurred based on the total values B1, B2, and the maximum processing load value A of the vehicle application scheduled to be started. Consequently, the ECU 10 can accurately determine whether the operation of a high-level application is being hindered.
[0078] (5. Fifth Embodiment) <5-1. Differences from the First Embodiment> The fifth embodiment has the same basic configuration as the first embodiment, so the differences will be described below. Note that the same reference numerals as in the first embodiment indicate the same configuration, and reference is made to the preceding description.
[0079] In the first embodiment described above, the ECU control unit 100 executed the application startup process shown in FIG. 6 , but in the fifth embodiment, instead of the application startup process shown in FIG. 6 , the ECU control unit 100 executes the application startup process shown in FIG. 10 .
[0080] 5-2. Processing> The application startup process executed by the ECU 10 according to the fifth embodiment will be described with reference to the flowchart in Fig. 10. In particular, the process will be described when the ECU control unit 100 receives an instruction from the user to start the first application 11 while the second application 12 and the third application 13 are running.
[0081] In steps S400 to S420, the ECU control unit 100 executes the same processes as in steps S10 to S30.
[0082] In S430, the ECU control unit 100 determines whether the total value C exceeds the allowable value D. If the ECU control unit 100 determines that the total value C is equal to or less than the allowable value D, the ECU control unit 100 proceeds to the processing of S460, and if the ECU control unit 100 determines that the total value C exceeds the allowable value D, the ECU control unit 100 proceeds to the processing of S440.
[0083] In S440, the ECU control unit 100 determines whether or not a low-level application is running. If the ECU control unit 100 determines that a low-level application is running, the process proceeds to S450. If the ECU control unit 100 determines that a low-level application is not running, the process proceeds to S470.
[0084] In S450, the ECU control unit 100 notifies the user via the display and speaker installed in the vehicle that the operation of the low-level application may be delayed and / or may stop as a result.
[0085] Subsequently, in S460 and S470, the ECU control unit 100 executes the same processes as in S50 and S60.
[0086] <5-3. Effects> According to the fifth embodiment described above, in addition to the effect (1) of the first embodiment described above, the following effects are also achieved.
[0087] (5) The ECU 10 can give priority to the startup of a high-level application that is scheduled to be started by allowing the operation of the low-level application to be delayed and / or stopped as the situation unfolds.
[0088] (6. Sixth Embodiment) <6-1. Differences from the First Embodiment> The sixth embodiment has the same basic configuration as the first embodiment, so the differences will be described below. Note that the same reference numerals as in the first embodiment indicate the same configuration, and reference is made to the preceding description.
[0089] In the first embodiment described above, the ECU control unit 100 executed the application startup process shown in FIG. 6 , but in the sixth embodiment, instead of the application startup process shown in FIG. 6 , the ECU control unit 100 executes the application startup process shown in FIG. 11 .
[0090] Furthermore, the storage device 550 according to the sixth embodiment stores a processing load table shown in FIG. 12 instead of the processing load table shown in FIG. 4 . In the processing load table according to the sixth embodiment, the processing load of the computational resource 30 is subdivided into processing loads of each of a plurality of elements (i.e., individual hardware) included in the computational resource 30. In the sixth embodiment, the computational resource 30 includes elements such as a CPU 110, a memory 120, and a communication bus, and the processing load of the computational resource 30 is subdivided into a processing load of the CPU 110, a processing load of the memory 120, and a processing load of the communication bus. When the application distribution management unit 51 receives an instruction from a user to download a specific vehicle application via the ECU 10, it transmits the specific application together with various corresponding processing loads to the ECU 10.
[0091] Specifically, the processing load table associates an application ID with an average CPU calculation load, a maximum CPU calculation load, an average external vehicle communication load, a maximum external vehicle communication load, an average memory usage, a maximum memory usage, and a processing load pattern ID.
[0092] 11, a description will be given of an application startup process executed by the ECU 10 according to the sixth embodiment. In particular, the description will be given of a process performed when the ECU control unit 100 receives an instruction from the user to start the first application 11 while the second application 12 and the third application 13 are running.
[0093] In S500, the ECU control unit 100 reads the CPU calculation load value Aa, the exterior-vehicle communication load value Ab, and the memory usage amount Ac of the first application 11 to be started from the memory 120. The load value of each element may be an average value or a maximum value.
[0094] Next, in S510, the ECU control unit 100 reads from the memory 120 the CPU calculation load values, the exterior-vehicle communication load values, and the memory usage amounts of the second and third applications 12 and 13 that are currently running. The load values of each element may be average values or maximum values. The ECU control unit 100 then sums the CPU calculation load values read in S510 to calculate a total value Ba, and sums the exterior-vehicle communication load values read in S510 to calculate a total value Bb. The ECU control unit 100 also sums the memory usage amounts read in S510 to calculate a total value Bc.
[0095] Next, the ECU control unit 100 adds the load value read out in S500 and the total value calculated in S510 for each element. Specifically, the ECU control unit 100 adds the CPU calculation load value Aa to the total value Ba to calculate the total value Ca, and adds the exterior communication load value Ab to the total value Bb to calculate the total value Cb. Furthermore, the ECU control unit 100 adds the memory usage amount Ac to the total value Bc to calculate the total value Cc.
[0096] Next, the ECU control unit 100 determines, for each element, whether the total value calculated in S520 exceeds a tolerance value. Specifically, the ECU control unit 100 determines whether the total value Ca exceeds a tolerance value Da. The tolerance value Da corresponds to the maximum available amount of CPU computing power. The ECU control unit 100 also determines whether the total value Cb exceeds a tolerance value Db. The tolerance value Db corresponds to the maximum available amount of the communication bus. The ECU control unit 100 also determines whether the total value Cc exceeds a tolerance value Dc. The tolerance value Dc corresponds to the maximum available amount of memory 120.
[0097] If the ECU control unit 100 determines that all of the total values Ca, Cb, and Cc are less than or equal to the corresponding allowable values Da, Db, and Dc, it proceeds to processing of S540, and if it determines that any of the total values Ca, Cb, and Cc exceeds the corresponding allowable values Da, Db, and Dc, it proceeds to processing of S550.
[0098] Subsequently, in S540 and S550, the ECU control unit 100 executes the same processes as in S50 and S60.
[0099] 6-3. Effects According to the sixth embodiment described above, in addition to the effect (1) of the first embodiment described above, the following effects are also achieved.
[0100] (6) Since the occurrence of resource shortage is determined for each element included in the computational resources 30, it is possible to determine with higher accuracy whether the operation of a high-level application will be hindered.
[0101] (7. Seventh Embodiment) <7-1. Differences from the First Embodiment> The seventh embodiment has the same basic configuration as the first embodiment, so the differences will be described below. Note that the same reference numerals as in the first embodiment indicate the same configuration, and reference is made to the preceding description.
[0102] While the system 200 according to the first embodiment includes the ECU 10, the system 200 according to the seventh embodiment includes an ECU 101 instead of the ECU 10. As shown in FIG. 13 , the ECU 101 includes an ECU control unit 102, an ECU communication unit 130, and a vehicle IF unit 140. The ECU control unit 102 includes a first core 103a and a second core 103b. The first core 103a includes a CPU 110a and a memory 120a, and the second core 103b includes a CPU 110b and a memory 120b. Each vehicle application is executed using the computational resources of the first core 103a or the computational resources of the second core 103a, and it is determined whether the application is executed by the first core 103a or the second core 103b. The vehicle application executed by the first core 103a does not share computational resources with the vehicle application executed by the second core 103b. In this embodiment, the CPU 110a and the memory 120a correspond to a first resource, and the CPU 110b and the memory 120b correspond to a second resource.
[0103] Furthermore, the storage device 550 according to the seventh embodiment stores the processing load table shown in Fig. 15 instead of the processing load table shown in Fig. 4. The processing load table according to the seventh embodiment associates an average processing load, a maximum processing load, a processing load pattern ID, and an active core number with an application ID.
[0104] In addition, in the first embodiment, the ECU control unit 100 executed the application startup process shown in Figure 6, but in the seventh embodiment, instead of the application startup process shown in Figure 6, the ECU control unit 100 executes the application startup process shown in Figure 14.
[0105] 14, a description will be given of an application startup process executed by the first core 103a according to the seventh embodiment. In particular, the description will be given of a process that is performed when the first core 103a receives an instruction from a user to start the first application 11 while the first core 103a is executing the second application 12 and while the second core 103b is executing the third application 13.
[0106] In S600, the first core 103a executes the same process as in S10.
[0107] Next, in S610, the first core 103a extracts, from the running vehicle applications, vehicle applications that share computational resources with the first application 11. If there is no vehicle application that shares computational resources with the first application 11, no vehicle application is extracted. Here, the first core 103a extracts the second application 12 from the running second and third applications 12, 13.
[0108] Next, in S620, the first core 103a reads from the memory 120a the processing load value of each of the vehicle applications extracted in S610. The first core 103a then sums the read processing load values to calculate a total value B. In this case, since the only vehicle application extracted by the first core 103a is the second application 12, the first core 103a calculates the average processing load value or maximum processing load value of the second application 12 as the total value B. Note that if no vehicle application is extracted in S610, the first core 103a calculates the total value B as 0.
[0109] Next, in steps S630 to S660, the first core 103a executes the same processes as in steps S30 to S60.
[0110] <7-3. Effects> According to the seventh embodiment described above, in addition to the effect (1) of the first embodiment described above, the following effects are also achieved.
[0111] (7) The ECU 101 determines whether a shortage of computing resources occurs among vehicle applications executed by the same core. Therefore, the ECU 101 can determine whether the operation of a high-level application is hindered among vehicle applications competing for computing resources.
[0112] (8. Other Embodiments) (a) In the first to seventh embodiments, when the ECU control unit 100 and the first core 103a receive a user instruction to start a high-level application, they determine before the start whether the operation of the currently running high-level application will be interrupted. However, the present disclosure is not limited to this. When the ECU control unit 100 and the first core 103a receive a user instruction to start a low-level application, they may determine before the start whether the operation of the currently running high-level application will be interrupted. That is, when the first application 11 is a low-level application, the ECU control unit 100 and the first core 103a may execute the flowcharts of FIGS. 6 to 11 and 14.
[0113] (b) In the first to seventh embodiments, the processing load table does not have to include a processing load pattern ID, and the storage device 550 does not have to store a processing load pattern classification table. In this case, in the fourth embodiment, the ECU 10 may determine, by simulation or the like, a situation in which the processing load of the installed vehicle software increases, and determine the processing load pattern of the vehicle software.
[0114] (c) In the seventh embodiment, the ECU control unit 102 includes the first core 103a and the second core 103b, but may include three or more cores.
[0115] (d) The ECU control unit 100, the first core 103a, and the method described herein may be implemented by a dedicated computer configured by configuring a processor and memory programmed to execute one or more functions embodied in a computer program. Alternatively, the ECU control unit 100, the first core 103a, and the method described herein may be implemented by a dedicated computer configured by configuring a processor with one or more dedicated hardware logic circuits. Alternatively, the ECU control unit 100, the first core 103a, and the method described herein may be implemented by one or more dedicated computers configured by combining a processor and memory programmed to execute one or more functions with a processor configured with one or more hardware logic circuits. Furthermore, the computer program may be stored as instructions executed by a computer on a computer-readable non-transitory tangible recording medium. The method for implementing the functions of each unit included in the ECU control unit 100 and the first core 103a does not necessarily need to include software; all of the functions may be implemented using one or more hardware.
[0116] (e) Multiple functions possessed by one component in the above embodiments may be realized by multiple components, or one function possessed by one component may be realized by multiple components. Also, multiple functions possessed by multiple components may be realized by one component, or one function realized by multiple components may be realized by one component. Also, part of the configuration of the above embodiments may be omitted. Also, at least part of the configuration of the above embodiments may be added to or substituted for the configuration of another of the above embodiments.
[0117] (f) In addition to the above-mentioned on-board computer, the present disclosure can also be realized in various forms, such as a system that includes the on-board computer as a component, a program for causing a computer to function as the on-board computer, a non-transient physical recording medium such as a semiconductor memory on which the program is recorded, and a method for launching an application.
Claims
1. An on-board computer (10, 101) having installed thereon vehicle applications including one or more high-level applications (11, 12) that require a first safety level as a required safety level, and one or more low-level applications (13) that require a second safety level that is lower than the first level, the on-board computer comprising: a computing resource (30) configured to be allocated to the operation of the vehicle applications; a determination unit (100, 103a, 103b) configured to determine whether a shortage of the computing resources will occur due to the launch of the scheduled application, based on the processing load and the required safety level of a scheduled application that is the vehicle application scheduled to be newly launched, and the processing load and the required safety level of each of the operating applications that are the vehicle applications currently in operation, and a warning unit (100, 103a, 103b) configured to output a warning to a user to stop the launch of the scheduled application when the determination unit determines that the operation of the high-level application will be impeded.
2. The vehicle-mounted computer according to claim 1, wherein the determination unit (100, 103a, 103b) is configured to determine whether operation of the high-level application is hindered when the scheduled application is the high-level application and the operating application is the high-level application.
3. The vehicle-mounted computer according to claim 1, wherein the determination unit (100, 103a, 103b) is configured to determine whether operation of the high-level application will be hindered when the scheduled application is the low-level application and the operating application is the high-level application.
4. The vehicle-mounted computer of claim 1, wherein the judgment unit (100, 103a, 103b) is configured to: calculate a second total value by adding the maximum processing load value of the scheduled application to a first total value obtained by adding up the average processing load values of each of the operating applications; and determine that operation of the high-level application is hindered if the second total value exceeds the allowable value of the computing resources.
5. The vehicle-mounted computer of claim 1, wherein the judgment unit (100, 103a, 103b) is configured to: calculate all combinations of processing load values for each of the operating applications, the processing load values being average processing load values or maximum processing load values; calculate a total value for each of the combinations; calculate a first total value by adding the average processing load value of the scheduled application to the total value for each of the combinations; calculate a second total value by adding the maximum processing load value of the scheduled application to the total value for each of the combinations; calculate the number of each of the first total values and each of the second total values that exceed the allowable value of the computing resources; and judge that operation of the high-level application is hindered if the number exceeds a predetermined standard value.
6. The vehicle-mounted computer of claim 1, wherein each of the vehicle applications is assigned a processing load pattern corresponding to a situation in which the processing load increases, and the judgment unit (100, 103a, 103b) is configured to: calculate a first total value by summing up the maximum processing load values of each of the operating applications that have the same processing load pattern as the scheduled application, calculate a second total value by summing up the average processing load values of each of the operating applications that have a processing load pattern different from that of the scheduled application, calculate a third total value by summing up the first total value, the second total value, and the maximum processing load value of the scheduled application, and judge that operation of the high-level application is hindered if the third total value exceeds the allowable value of the computing resources.
7. The vehicle-mounted computer according to claim 1, wherein the determination unit (100, 103a, 103b) is configured to, when the operating application includes the low-level application, allow the operation of the low-level application to be delayed and / or stopped as the situation requires, and give priority to the startup of the high-level application.
8. The vehicle-mounted computer of claim 1, wherein the judgment unit (100, 103a, 103b) is configured to: subdivide the processing load into processing loads for each of a plurality of elements (110, 120); for each of the plurality of elements, determine whether a shortage of computing resources will occur based on the processing load and safety requirement level of the scheduled application and the processing load and safety requirement level of each of the operating applications; and determine that operation of the high-level application will be hindered if it is determined that a shortage of computing resources will occur in at least one of the plurality of elements.
9. The on-board computer according to claim 1, wherein the computing resources (30) include a first resource (110a, 120a) and a second resource (110b, 120b), the vehicle applications (11, 12, 13) include a first application group and a second application group, and further comprising: a first core (103a) configured to execute the first application group using the first resource; and a second core (103b) configured to execute the second application group using the second resource, and the determination unit (103a, 103b) is configured to determine whether operation of the high-level application included in the first application group that is currently running will be hindered when the scheduled application is included in the first application group.
10. An application launch method in which an on-board computer (10, 101) is installed with vehicle applications including one or more high-level applications (11, 12) that require a first safety level as a required safety level, and one or more low-level applications (13) that require a second safety level that is lower than the first level, determines whether launching the scheduled application will interfere with the operation of the currently running high-level application based on the processing load and the required safety level of a scheduled application that is a vehicle application scheduled to be newly launched, and the processing load and the required safety level of each of the vehicle applications that are currently running, and warns the user to cancel the launch of the scheduled application if it is determined that the operation of the high-level application will be interfered with.
11. A program that causes an onboard computer (10, 101) having installed thereon vehicle applications including one or more high-level applications (11, 12) that require a first safety level as a required safety level, and one or more low-level applications (13) that require a second safety level that is lower than the first level, to determine whether launching the scheduled application will interfere with the operation of the currently running high-level application based on the processing load and required safety level of a scheduled application that is a vehicle application that is scheduled to be newly launched, and the processing load and required safety level of each of the vehicle applications that are currently running, and if it is determined that the operation of the high-level application will be interfered with, to warn the user to stop launching the scheduled application.
Citation Information
Patent Citations
On-vehicle equipment, computer device and operation control method of application
JP2003222523A
Load control device, load control method and vehicle slip suppression device
JP2008024165A
Mobility service provision method, mobility service provision system, server device, edge device and program
JP2023117140A
In-car-use multi-application execution device
WO2011055581A1