Communication system, vehicle-mounted device, management device, service management program, and resource management program
The communication system facilitates vehicle functional upgrades by managing resource allocation and service execution between in-vehicle and management devices, reducing the need for hardware changes and associated costs.
Patent Information
- Authority / Receiving Office
- WO · WO
- Patent Type
- Applications
- Current Assignee / Owner
- Filing Date
- 2025-08-21
- Publication Date
- 2026-04-02
AI Technical Summary
The increasing sophistication and diversification of vehicle functions necessitate more frequent updates, leading to higher costs for upgrading vehicle configurations.
A communication system comprising an in-vehicle device and a management device that allocates resources to execute services without changing the vehicle's configuration, allowing for functional upgrades by transmitting service execution requests, resource allocation, and release requests between the devices.
This configuration reduces the cost required to update vehicle functionality by enabling service execution and resource management without altering the vehicle's hardware.
Smart Images

Figure JP2025029344_02042026_PF_FP_ABST
Abstract
Description
Communication system, in-vehicle device, management device, service management program, and resource management program
[0001] The present disclosure relates to a communication system, an in-vehicle device, a management device, a service management program, and a resource management program. This application claims priority based on Japanese Patent Application No. 2024-164968 filed on September 24, 2024, and incorporates all of its disclosure herein.
[0002] Patent Document 1 (Japanese Unexamined Patent Application Publication No. 2022-174678) discloses the following technology. That is, an information processing apparatus receives a request for a first update regarding a first vehicle from a user terminal, and when the first update is a hardware update, presents to the user terminal to perform the first update at a store, and when the first update is a software update, presents to the user terminal to perform the first update by wireless communication, and includes a control unit that executes these operations.
[0003] Japanese Unexamined Patent Application Publication No. 2022-174678 Japanese Unexamined Patent Application Publication No. 2022-181596 Japanese Unexamined Patent Application Publication No. 2022-114164
[0004] The communication system of the present disclosure includes an in-vehicle device mounted on a vehicle and a management device. The in-vehicle device transmits a service execution request regarding the vehicle to the management device. The management device allocates resources used to execute the service based on the execution request received from the in-vehicle device. The management device executes the service using the allocated resources. The management device transmits the execution result of the service to the in-vehicle device. The in-vehicle device controls the in-vehicle equipment of the vehicle using the execution result received from the management device. The in-vehicle device transmits a resource release request to the management device. The management device receives the release request from the in-vehicle device and releases the resources.
[0005] One aspect of this disclosure can be implemented not only as a communication system having such characteristic processing, but also as a step-based method for such characteristic processing, or as a semiconductor integrated circuit that implements part or all of the communication system.
[0006] One aspect of this disclosure can be realized not only as an in-vehicle device equipped with such characteristic processing, but also as a step-based method for such characteristic processing, or as a semiconductor integrated circuit that realizes part or all of the in-vehicle device.
[0007] One aspect of this disclosure can be realized not only as a management device equipped with such characteristic processing, but also as a step-based method for such characteristic processing, or as a semiconductor integrated circuit that realizes part or all of the management device.
[0008] Figure 1 is a diagram showing an example of the configuration of a communication system according to an embodiment of the present disclosure. Figure 2 is a diagram showing an example of the configuration of an in-vehicle system according to an embodiment of the present disclosure. Figure 3 is a diagram showing an example of the configuration of an in-vehicle relay device according to an embodiment of the present disclosure. Figure 4 is a diagram showing an example of the configuration of a resource management server according to an embodiment of the present disclosure. Figure 5 is a diagram showing an example of the configuration of an edge server according to an embodiment of the present disclosure. Figure 6 is a diagram illustrating an example of a service performed by an edge server in a communication system according to an embodiment of the present disclosure. Figure 7 is a flowchart defining an example of the operation procedure when an in-vehicle relay device according to an embodiment of the present disclosure controls in-vehicle equipment. Figure 8 is a flowchart defining an example of the operation procedure when an in-vehicle relay device according to an embodiment of the present disclosure controls in-vehicle equipment. Figure 9 is a flowchart defining an example of the operation procedure when a resource management server according to an embodiment of the present disclosure allocates resources. Figure 10 is a flowchart defining an example of the operation procedure when a resource management server according to an embodiment of the present disclosure allocates resources. Figure 11 is a flowchart defining an example of the operation procedure when an edge server according to an embodiment of the present disclosure performs a service. Figure 12 is a flowchart showing an example of the operation procedure when an edge server according to an embodiment of the present disclosure performs a process to stop the execution of a service. Figure 13 is a diagram showing an example of the processing sequence of each device in a communication system according to an embodiment of the present disclosure. Figure 14 is a diagram showing an example of the processing sequence of each device in a communication system according to an embodiment of the present disclosure.
[0009] Conventionally, technologies have been developed to manage how vehicle configurations are updated.
[0010] [Problems this disclosure aims to solve] In order to upgrade the functions of a vehicle, it is sometimes necessary to update the hardware and other configurations of the vehicle. In recent years, with the increasing sophistication and diversification of vehicle functions, it is expected that the frequency of such updates will increase. In this case, the cost required to upgrade the functions of the vehicle will increase.
[0011] This disclosure was made to solve the aforementioned problems and aims to provide a communication system, in-vehicle device, management device, service management program, and resource management program that can reduce the cost required for updating the functionality of a vehicle.
[0012] [Effects of this disclosure] This disclosure can reduce the costs required to update the functions of a vehicle.
[0013] [Description of Embodiments of the Disclosure] First, the contents of embodiments of the Disclosure will be listed and described. (1) A communication system according to an embodiment of the Disclosure comprises an in-vehicle device mounted on a vehicle and a management device, wherein the in-vehicle device transmits a request to the management device to perform a service relating to the vehicle, the management device allocates resources to perform the service based on the request received from the in-vehicle device, the management device performs the service using the allocated resources, the management device transmits the result of the service to the in-vehicle device, the in-vehicle device controls the in-vehicle equipment of the vehicle using the result received from the management device, the in-vehicle device transmits a request to release the resources to the management device, and the management device receives the release request from the in-vehicle device and releases the resources.
[0014] In this configuration, where a management device executes vehicle-related services and uses the results of those services to control in-vehicle equipment, the functionality of the services can be upgraded without changing the vehicle's configuration. Therefore, the cost required to update vehicle functionality can be reduced.
[0015] (2) In the above (1), the management device may transmit information regarding the services that can be executed by the management device to the in-vehicle device.
[0016] For example, if resources are insufficient, the management device may not be able to execute the service. With the configuration described above, it is possible to understand the services to be provided according to the resource status at the time of a service execution request.
[0017] (3) In (1) or (2) above, the management device may transmit information to the in-vehicle device indicating whether or not the service can be performed.
[0018] This configuration allows for notification of whether a service can be executed based on factors such as the feasibility of resource allocation and the success or failure of authentication.
[0019] (4) In any of (1) to (3) above, the management device may transmit to the in-vehicle device information indicating the source from which the software used to perform the service is downloaded and incorporated into the in-vehicle device.
[0020] With this configuration, for example, in a vehicle where resources are sufficient but necessary software is not installed, the service can be performed more reliably by downloading that software.
[0021] (5) In any of (1) to (4) above, the in-vehicle device may transmit the vehicle information, which indicates the status of the vehicle and is used to generate the execution result, which is control information for controlling the in-vehicle equipment, to the management device, and the management device may generate the control information using the vehicle information received from the in-vehicle device.
[0022] This configuration allows for the generation of more appropriate control information based on the vehicle's state, enabling the operation of in-vehicle equipment.
[0023] (6) In the above (5), if the in-vehicle device is a service relating to the automatic driving of the vehicle or a service for avoiding obstacles while the vehicle is in motion, it may transmit at least one of the vehicle's location information and vehicle speed information to the management device as vehicle information.
[0024] This configuration allows for the generation of more appropriate control information based on the vehicle's position or speed, enabling the operation of in-vehicle equipment that supports autonomous driving services or obstacle avoidance services.
[0025] (7) In the case of (5) above, if the service is a service for unlocking the doors of the vehicle, the in-vehicle device may transmit at least one of the following to the management device as vehicle information: location information of the vehicle, information indicating the power status of the vehicle, and information indicating the open / closed state of the doors.
[0026] This configuration allows for the generation of more appropriate control information based on the vehicle's location, power status, or door status, enabling the operation of in-vehicle equipment that supports the door unlocking service.
[0027] (8) In any of (1) to (7) above, the in-vehicle device may transmit resource-related information used for resource allocation by the management device, which indicates the hardware configuration of the vehicle, to the management device, and the management device may use the resource-related information received from the in-vehicle device to allocate the resources.
[0028] This configuration allows for more appropriate resource allocation according to the vehicle's hardware configuration.
[0029] (9) In the above (8), if the hardware configuration indicated by the resource-related information is insufficient for the hardware configuration required to perform the service, the management device may obtain data corresponding to the insufficient hardware configuration from equipment outside the vehicle and transmit the obtained data to the in-vehicle device.
[0030] With this configuration, even if the vehicle lacks the necessary hardware configuration to perform the service, the service can be performed more reliably using data acquired from the management device without changing the hardware configuration.
[0031] (10) In any of the above (1) to (9), the management device may perform authentication processing of the execution request.
[0032] This configuration allows for the determination of whether a service execution request is a legitimate execution request, thereby improving the security of the communication system.
[0033] (11) In any of (1) to (10) above, the management device may include a first device that has the resources and uses the resources to perform the service, and a second device that allocates the resources, and the first device may transmit the execution result of the service to the in-vehicle device.
[0034] This configuration allows the functions of the management device to be distributed among multiple devices, thereby optimizing the overall system processing.
[0035] (12) In any of the above (1) to (11), the management device may perform authentication processing of the release request.
[0036] This configuration allows for the determination of whether a resource release request is a legitimate release request, thereby improving the security of the communication system.
[0037] (13) An in-vehicle device according to an embodiment of the present disclosure is an in-vehicle device mounted on a vehicle, comprising: a transmitting unit that transmits a request to a management device for the execution of a service relating to the vehicle; a receiving unit that receives the result of the execution of the service from the management device; and a control unit that controls the in-vehicle equipment of the vehicle using the result of the execution received by the receiving unit, wherein the transmitting unit transmits a request to the management device for the release of resources used to execute the service.
[0038] In this configuration, where a management device executes vehicle-related services and uses the results of those services to control in-vehicle equipment, the functionality of the services can be upgraded without changing the vehicle's configuration. Therefore, the cost required to update vehicle functionality can be reduced.
[0039] (14) The management device according to the embodiment of the present disclosure is a management device that communicates with an in-vehicle device mounted on a vehicle, and comprises: a communication unit that receives a request to execute a service relating to the vehicle from the in-vehicle device; a resource allocation unit that allocates resources to be used to execute the service based on the execution request received by the communication unit; and a service execution unit that executes the service using the resources allocated by the resource allocation unit and transmits the execution result of the service to the in-vehicle device, wherein the communication unit receives a request to release the resources from the in-vehicle device, and the management device further comprises a resource release unit that releases the resources when the communication unit receives the release request.
[0040] In this configuration, where the management device executes vehicle-related services and transmits the results of those services to the in-vehicle device, the functionality of the services can be upgraded without requiring any changes to the vehicle's configuration. Therefore, the cost required to update the vehicle's functionality can be reduced.
[0041] (15) The service management program according to the embodiment of the present disclosure is a service management program used in an in-vehicle device installed in a vehicle, and is a program that causes a computer to function as a transmitting unit that transmits a request to a management device for the execution of a service relating to the vehicle, a receiving unit that receives the result of the execution of the service from the management device, and a control unit that controls the in-vehicle equipment of the vehicle using the result of the execution received by the receiving unit, wherein the transmitting unit transmits a request to the management device for the release of resources used to execute the service.
[0042] In this configuration, where a management device executes vehicle-related services and uses the results of those services to control in-vehicle equipment, the functionality of the services can be upgraded without changing the vehicle's configuration. Therefore, the cost required to update vehicle functionality can be reduced.
[0043] (16) The resource management program according to an embodiment of the present disclosure is a resource management program used in a management device that communicates with an in-vehicle device mounted on a vehicle, and causes a computer to function as a communication unit that receives a service execution request related to the vehicle from the in-vehicle device, a resource allocation unit that allocates resources used to execute the service based on the execution request received by the communication unit, and a service execution unit that executes the service using the resources allocated by the resource allocation unit and transmits the execution result of the service to the in-vehicle device. The communication unit receives a resource release request from the in-vehicle device, and the program further causes the computer to function as a resource release unit that releases the resources when the communication unit receives the release request.
[0044] Thus, by configuring the management device to execute a service related to the vehicle and transmit the execution result of the service to the in-vehicle device, the service function can be upgraded without changing the configuration in the vehicle. Therefore, the cost required for updating the functions of the vehicle can be reduced.
[0045] Hereinafter, embodiments of the present disclosure will be described with reference to the drawings. In the drawings, the same or corresponding parts are denoted by the same reference numerals and their description will not be repeated. Also, at least a part of the embodiments described below may be arbitrarily combined.
[0046] [Communication System] FIG. 1 is a diagram showing an example of the configuration of a communication system according to an embodiment of the present disclosure. Referring to FIG. 1, the communication system 501 includes a resource management server 170, a plurality of edge servers 180, and one or more in-vehicle systems 301. The in-vehicle system 301 is mounted on the vehicle 1. The resource management server 170 and the edge server 180 are provided outside the vehicle 1. The edge server 180 is an example of a first device included in the management device. The resource management server 170 is an example of a second device included in the management device.
[0047] Figure 2 is a diagram showing an example of the configuration of an in-vehicle system according to an embodiment of the present disclosure. Referring to Figure 2, the in-vehicle system 301 includes an in-vehicle relay device 101 and a plurality of in-vehicle devices 202. The in-vehicle relay device 101 is an example of an in-vehicle device.
[0048] The in-vehicle devices 202 include an in-vehicle ECU (Electronic Control Unit), sensors, actuators, a navigation device, a human machine interface, and a camera, etc. The in-vehicle ECU includes a TCU (Telematics Communication Unit), an engine ECU, an autonomous driving ECU, a steering ECU, a brake ECU, and a door lock ECU, etc.
[0049] The in-vehicle relay device 101 and the plurality of in-vehicle devices 202 constitute an in-vehicle network 401. The plurality of in-vehicle devices 202 are connected to the in-vehicle relay device 101 via a CAN (Controller Area Network) bus 51 that conforms to the CAN standard, for example.
[0050] In the example shown in Figure 2, the in-vehicle system 301 includes in-vehicle devices 202A, 202B, 202C, and 202D which are in-vehicle devices 202. Also, in the example shown in Figure 2, CAN buses 51A and 51B are provided as the CAN bus 51.
[0051] The in-vehicle devices 202A and 202B are connected to the in-vehicle relay device 101 via the CAN bus 51A. The in-vehicle devices 202C and 202D are connected to the in-vehicle relay device 101 via the CAN bus 51B.
[0052] The in-vehicle relay device 101 is, for example, a gateway device. The in-vehicle relay device 101 performs a relay process for relaying data transmitted and received between the in-vehicle devices 202. s
[0053] For example, each in-vehicle device 202 transmits a CAN frame containing various information, such as information to assist the automated driving performed by the vehicle 1 and information used for entertainment (described later), and a CAN-ID (Identifier) indicating the type of data, to another in-vehicle device 202 or the in-vehicle relay device 101. The in-vehicle relay device 101 relays the CAN frame received from one in-vehicle device 202 to another in-vehicle device 202. The in-vehicle relay device 101 also creates a CAN frame containing the above-mentioned various information and CAN-ID, and transmits the created CAN frame to the destination in-vehicle device 202.
[0054] Furthermore, the in-vehicle system 301 is not limited to a configuration in which two CAN buses 51 are provided; it may also be configured to have one or three or more CAN buses 51.
[0055] Furthermore, the in-vehicle relay device 101 and the in-vehicle equipment 202 may be configured to perform communication in accordance with communication protocols such as CAN FD (CAN with Flexible Data Rate), Ethernet (registered trademark), FlexRay (registered trademark), MOST (Media Oriented System Transport) (registered trademark), LIN (Local Interconnect Network), and CXPI (Clock Extension Peripheral Interface) (registered trademark), in addition to or instead of communication in accordance with the CAN standard.
[0056] In the example shown in Figure 2, the in-vehicle devices 202A, 202B, and 202C are the TCU, vehicle speed sensor, and navigation system, respectively. Hereinafter, the in-vehicle devices 202A, 202B, and 202C will also be referred to as TCU202A, vehicle speed sensor 202B, and navigation system 202C, respectively.
[0057] Referring to Figures 1 and 2, the TCU 202A communicates with the resource management server 170 and the edge server 180, for example, via the wireless base station device 161.
[0058] More specifically, the TCU202A communicates wirelessly with the wireless base station equipment 161 in accordance with communication standards such as LTE (Long Term Evolution) (registered trademark) or 5G.
[0059] Specifically, when the TCU202A receives a CAN frame containing various information from the in-vehicle relay device 101, it transmits a wireless signal containing the said information to the wireless base station device 161.
[0060] When the wireless base station device 161 receives a wireless signal from the TCU 202A, it transmits various information contained in the received wireless signal to the resource management server 170 via an external network 151 such as the Internet.
[0061] Furthermore, when the wireless base station device 161 receives an IP packet from the resource management server 170 or edge server 180 via the external network 151, it includes the received IP packet in a wireless signal and transmits it to the TCU 202A.
[0062] When the TCU202A receives a radio signal containing IP packets from the resource management server 170 or edge server 180 via the radio base station device 161, it acquires the IP packets from the received radio signal, stores the acquired IP packets in one or more CAN frames, and transmits them to the in-vehicle relay device 101.
[0063] The vehicle speed sensor 202B measures the vehicle speed of vehicle 1, for example, periodically or irregularly, and transmits the vehicle speed information indicating the measurement result to the on-board relay device 101.
[0064] The navigation device 202C receives input from the user of vehicle 1 regarding the vehicle's departure point, destination, and planned departure time. Upon receiving the input of the departure point, destination, and planned departure time, the navigation device 202C creates route information indicating the planned route A from the departure point to the destination, one or more waypoints between the departure point and the destination, the planned departure time, and the planned arrival time, which is the time the vehicle is expected to arrive at the destination.
[0065] The navigation device 202C then transmits the created route information to the in-vehicle relay device 101.
[0066] Furthermore, the navigation device 202C transmits location information indicating the position of vehicle 1 to the in-vehicle relay device 101, for example, periodically or irregularly.
[0067] [In-vehicle relay device] Figure 3 is a diagram showing an example of the configuration of an in-vehicle relay device according to an embodiment of the present disclosure. Referring to Figure 3, the in-vehicle relay device 101 comprises a relay unit 11, a processing unit 12, and a storage unit 13. The processing unit 12 includes a service management unit 21 and a control unit 22. One or both of the relay unit 11 and the processing unit 12 are implemented by a processing circuit including, for example, one or more processors. The storage unit 13 is, for example, a non-volatile memory included in the processing circuit. The service management unit 21 is an example of a transmission unit and an example of a reception unit.
[0068] (Relay Unit) The relay unit 11 receives a CAN frame transmitted from a certain in-vehicle device 202. The relay unit 11 then checks whether the received CAN frame is a CAN frame that its own in-vehicle relay device 101 should receive.
[0069] The storage unit 13 stores, for example, a reception list L indicating the CAN-IDs included in the CAN frames that its in-vehicle relay device 101 should receive. The reception list L is registered in the storage unit 13 by the manufacturer of the vehicle 1 when the vehicle 1 is shipped.
[0070] When the relay unit 11 receives a CAN frame, it checks whether the CAN-ID contained in the CAN frame is registered in the reception list L by referring to the reception list in the storage unit 13.
[0071] The relay unit 11 discards a CAN frame if the CAN-ID contained in the received CAN frame is not registered in the reception list L.
[0072] On the other hand, the relay unit 11 performs relay processing if the CAN-ID included in the received CAN frame is registered in the reception list L and the destination of the CAN frame is the in-vehicle equipment 202. Also, if the relay unit 11 outputs the CAN frame to the processing unit 12 if the CAN-ID included in the received CAN frame is registered in the reception list L and the destination of the CAN frame is its own in-vehicle relay device 101.
[0073] More specifically, for example, the storage unit 13 stores a routing table that shows the correspondence between a CAN-ID, the device to which the CAN frame is sent, and the CAN bus 51 (hereinafter also referred to as the "destination bus") to which the destination device is connected. The routing table is registered in the storage unit 13 by the manufacturer of the vehicle 1 when the vehicle 1 is shipped.
[0074] For example, if the relay unit 11 has a CAN-ID included in a CAN frame received from the in-vehicle device 202 registered in the reception list L, it refers to the routing table in the storage unit 13 to confirm the destination device corresponding to that CAN-ID.
[0075] When the relay unit 11 confirms that the destination device of the received CAN frame is the in-vehicle device 202, it refers to the routing table to identify the destination bus corresponding to that destination device. The relay unit 11 then outputs the received CAN frame to the identified destination bus.
[0076] Meanwhile, when the relay unit 11 confirms that the destination device of the received CAN frame is its own in-vehicle relay device 101, it outputs various information contained in the CAN frame to the service management unit 21.
[0077] Specifically, for example, when the relay unit 11 receives a CAN frame containing route information from the navigation device 202C, it outputs the route information to the service management unit 21.
[0078] For example, the storage unit 13 stores vehicle identification information (hereinafter also referred to as "vehicle ID (Identifier)") for identifying vehicle 1.
[0079] When the service management unit 21 receives route information from the relay unit 11, it sends the route information, including the vehicle ID stored in the storage unit 13, to the resource management server 170.
[0080] [Resource Management Server and Edge Server] Referring again to Figure 1, each edge server 180 executes one or more services S. Specifically, the edge server 180 executes services S such as an autonomous driving service, an obstacle avoidance service, and a door unlocking service related to the autonomous driving of vehicle 1.
[0081] In this embodiment, for example, the autonomous driving services performed by the edge server 180 are the LKAS (Lane Keeping Assist System) service and the ACC (Adaptive Cruise Control) service. The LKAS service is a service to prevent vehicle 1 from deviating from the driving lane in which it is traveling. The ACC service is a service to ensure that the distance between vehicle 1 and other vehicles located in front of it (hereinafter also referred to as "vehicles ahead") is above a certain value.
[0082] The obstacle avoidance service is a service that avoids obstacles while vehicle 1 is in motion. The door unlocking service is a service that unlocks the doors of vehicle 1 while it is parked or stopped.
[0083] For example, the edge server 180 generates control information for controlling the in-vehicle equipment 202. The edge server 180 then transmits the generated control information to the in-vehicle relay device 101 as the execution result of service S.
[0084] For example, the resource management server 170 creates service information indicating the service S corresponding to the driving area of vehicle 1. Specifically, the resource management server 170 creates service information regarding the service S that the edge server 180 can execute when vehicle 1 is traveling along the planned route A. The resource management server 170 then transmits the created service information to the in-vehicle relay device 101 via the TCU 202A.
[0085] Furthermore, the resource management server 170 allocates resources R that the edge server 180 uses to execute service S. Resources R include processing power and data collection functions necessary to execute service S.
[0086] (Resource Management Server) Figure 4 is a diagram showing an example of the configuration of a resource management server according to an embodiment of the present disclosure. Referring to Figure 4, the resource management server 170 includes a communication unit 31, a service information creation unit 32, an authentication unit 33, a resource allocation unit 34, a resource release unit 35, and a storage unit 36. Some or all of the communication unit 31, the service information creation unit 32, the authentication unit 33, the resource allocation unit 34, and the resource release unit 35 are implemented by a processing circuit including, for example, one or more processors. The storage unit 36 is, for example, a non-volatile memory included in the processing circuit.
[0087] Referring to Figures 1 and 4, the communication unit 31 communicates with the TCU 202A by, for example, sending and receiving various information via the external network 151 and the wireless base station device 161.
[0088] When the communication unit 31 receives route information from the in-vehicle relay device 101 via the TCU 202A, it outputs the received route information to the service information creation unit 32.
[0089] <Service Information> The service information creation unit 32 creates service information using the route information received from the communication unit 31.
[0090] For example, the storage unit 36 stores a service table that shows the correspondence between the points the vehicle 1 passes through and the service S. The service table is pre-registered in the storage unit 36 by, for example, the administrator of the resource management server 170.
[0091] When the service information creation unit 32 receives route information from the communication unit 31, it refers to the service table in the storage unit 36 and confirms the service S corresponding to each of the one or more passing points indicated by the route information.
[0092] The service information creation unit 32 then creates service information indicating the one or more services S that have been confirmed and the vehicle ID included in the route information received from the communication unit 31, and outputs the created service information to the communication unit 31. The service information creation unit 32 also saves the created service information to the storage unit 36.
[0093] When the communication unit 31 receives service information from the service information creation unit 32, it creates an IP packet P1 containing the service information, which includes the IP address of the resource management server 170 and the IP address of vehicle 1 corresponding to the vehicle ID indicated by the service information as the source IP address and destination IP address, respectively. The communication unit 31 then transmits the created IP packet P1 to the TCU 202A.
[0094] When TCU202A receives an IP packet P1 from the resource management server 170, it transmits the service information contained in the received IP packet to the in-vehicle relay device 101.
[0095] The in-vehicle relay device 101 may be configured to transmit type information indicating the type of service S corresponding to the current location of the vehicle 1 to the resource management server 170 instead of route information received from the navigation device 202C. In this case, the resource management server 170 does not transmit service information to the in-vehicle relay device 101, but instead allocates resources R corresponding to the type of service S indicated by the type information received from the in-vehicle relay device 101.
[0096] <Service S execution request and resource-related information> Referring again to Figure 3, in the in-vehicle relay device 101, when the relay unit 11 receives service information from the TCU 202A, it outputs the received service information to the service management unit 21.
[0097] For example, the service management unit 21 sends a request to execute service S related to the vehicle 1 on which its in-vehicle relay device 101 is installed, along with authentication information B1 and resource-related information, to the resource management server 170.
[0098] Authentication information B1 is information used in the authentication process C1 of the service execution request by the resource management server 170. Authentication information B1 includes, for example, identification information for identifying the user of vehicle 1 (hereinafter also referred to as "user ID") and a password.
[0099] Resource-related information is, for example, information used by the resource management server 170 to allocate resource R, and is information indicating the hardware configuration Hw1 of vehicle 1. Specifically, resource-related information indicates the processing capacity, storage capacity and type of in-vehicle equipment 202 in the in-vehicle network 401.
[0100] The processing capacity of the in-vehicle device 202 is, for example, the processing capacity of the CPU (Central Processing Unit) or MPU (Micro Processing Unit) in the in-vehicle device 202. Specifically, the processing capacity of the in-vehicle device 202 is indicated by a numerical value with units such as MIPS (Million Instructions Per Second) or FLOPS (Floating-point Operations Per Second).
[0101] The storage capacity is, for example, the data storage capacity that the in-vehicle device 202 can provide, and is the capacity of the storage of the in-vehicle device 202, such as RAM (Random Access Memory), ROM (Read Only Memory), or HDD (Hard Disk Drive). Specifically, the storage capacity of the in-vehicle device 202 is indicated by a numerical value with units such as bytes. In addition to information regarding the hardware configuration Hw1 of the vehicle 1, or instead of information regarding the hardware configuration Hw1, resource-related information may also include other information such as information indicating the type of vehicle 1 and information indicating the modification history of the vehicle 1.
[0102] For example, the storage unit 13 stores authentication information B1 and resource-related information. When the service management unit 21 receives service information from the relay unit 11, it transmits the type of service S indicated by the service information, the execution request for the service S, and the execution request information including authentication information B1, resource-related information, and vehicle ID stored in the storage unit 13 to the resource management server 170 via the relay unit 11 and the TCU 202A.
[0103] Referring again to Figure 4, in the resource management server 170, when the communication unit 31 receives execution request information from the in-vehicle relay device 101 via the TCU 202A, it outputs the received execution request information to the authentication unit 33.
[0104] <Authentication process for execution request> For example, the authentication unit 33 performs authentication process C1 for the execution request of service S. More specifically, for example, when the authentication unit 33 receives execution request information from the communication unit 31, it performs authentication process C1 using the authentication information B1 contained in the execution request information.
[0105] If the authentication process C1 is successful, the authentication unit 33 outputs authentication success information Q1, which indicates that the authentication process C1 was successful, to the resource allocation unit 34, including the vehicle ID and resource-related information contained in the execution request information received from the communication unit 31.
[0106] On the other hand, if the authentication process C1 fails, the authentication unit 33 transmits authentication failure information F1, indicating that the authentication process C1 has failed, to the in-vehicle relay device 101 via the communication unit 31 and TCU 202A.
[0107] <Resource Allocation> Based on the service execution request for service S received from the in-vehicle relay device 101, the resource allocation unit 34 allocates resources R that the edge server 180 will use to execute service S.
[0108] More specifically, for example, the resource allocation unit 34 allocates resource R using resource-related information.
[0109] Specifically, for example, when the resource allocation unit 34 receives authentication success information Q1 from the authentication unit 33, it obtains service information from the storage unit 36 that indicates the same vehicle ID as the vehicle ID included in the authentication success information Q1.
[0110] For example, the storage unit 36 stores hardware information indicating the hardware configuration Hw1 of the vehicle 1 necessary for the execution of each service S.
[0111] When the resource allocation unit 34 obtains service information from the storage unit 36, it refers to the hardware information in the storage unit 36 and identifies the hardware configuration Hw1 corresponding to each of the one or more services S indicated by the obtained service information.
[0112] The resource allocation unit 34 then compares each identified hardware configuration Hw1 with the hardware configuration indicated by the resource-related information included in the authentication success information Q1 received from the authentication unit 33 (hereinafter also referred to as "hardware configuration Hw2").
[0113] The resource allocation unit 34 determines that if hardware configuration Hw2 does not satisfy hardware configuration Hw1, it will allocate resource R to the service S corresponding to hardware configuration Hw1.
[0114] Then, the resource allocation unit 34 identifies the resources R that are insufficient for the execution of service S based on the comparison result between the identified hardware configuration Hw1 and hardware configuration Hw2.
[0115] When the resource allocation unit 34 identifies a resource R that is insufficient for the execution of service S, it checks whether the identified resource R can be allocated.
[0116] For example, the storage unit 36 stores a resource management table that shows the correspondence W between the type of resource R and the ID of the edge server 180 (hereinafter also referred to as "server ID"). In addition to the correspondence W, the resource management table includes a determination flag that indicates whether or not the resource R has already been allocated.
[0117] If resource R is not allocated, the value of the identification flag corresponding to resource R in the resource management table is set to a value indicating that resource R is not allocated, for example, "zero". If resource R is allocated, the value of the identification flag corresponding to resource R in the resource management table is set to a value indicating that resource R is allocated, for example, "1".
[0118] When the resource allocation unit 34 identifies a missing resource R, it checks whether the value of the discrimination flag corresponding to that resource R is "zero" by referring to the resource management table in the storage unit 36.
[0119] For example, if the value of the discrimination flag corresponding to the insufficient resource R is "zero", the resource allocation unit 34 determines that the resource R can be allocated and checks the server ID corresponding to the resource R by referring to the resource management table.
[0120] The resource allocation unit 34 then outputs to the communication unit 31 resource information indicating the type of resource R identified, along with the confirmed server ID and the vehicle ID included in the authentication success information Q1 received from the authentication unit 33. The resource allocation unit 34 also associates the type of resource R identified with the acquired service information and stores it in the storage unit 36.
[0121] On the other hand, the resource allocation unit 34 determines that resource R cannot be allocated, i.e., the edge server 180 cannot execute service S, if the value of the discrimination flag corresponding to the insufficient resource R is "1". The resource allocation unit 34 then outputs execution failure information to the communication unit 31, indicating that the edge server 180 cannot execute service S and the vehicle ID included in the authentication success information Q1 received from the authentication unit 33.
[0122] When the communication unit 31 receives resource information from the resource allocation unit 34, it creates an IP packet P2 containing the resource information, which includes the IP address of the resource management server 170 and the IP address of the edge server 180 corresponding to the server ID indicated by the resource information as the source IP address and destination IP address, respectively. The communication unit 31 then sends the created IP packet P2 to the destination edge server 180.
[0123] When the communication unit 31 receives information that cannot be executed from the resource allocation unit 34, it creates an IP packet P3 containing the resource information, which includes the IP address of the resource management server 170 and the IP address of vehicle 1 corresponding to the vehicle ID indicated by the information that cannot be executed as the source IP address and destination IP address, respectively. The communication unit 31 then sends the created IP packet P3 to the TCU 202A.
[0124] On the other hand, the resource allocation unit 34 determines that if hardware configuration Hw2 satisfies hardware configuration Hw1, it will not allocate resource R for service S corresponding to hardware configuration Hw1. In other words, the resource allocation unit 34 determines that the edge server 180 does not need to execute service S.
[0125] (Updating the resource management table) When the resource allocation unit 34 confirms the server ID corresponding to the resource R that is lacking for the execution of service S, it performs an update process N1 to update the resource management table. Specifically, for example, the resource allocation unit 34 updates the value of the discrimination flag corresponding to the resource R in the resource management table in the storage unit 36 from "zero" to "1".
[0126] (Transmission of information on whether or not execution is possible) For example, the resource allocation unit 34 transmits information indicating whether or not the edge server 180 can execute service S to the in-vehicle relay device 101 via the communication unit 31 and TCU 202A.
[0127] More specifically, if the hardware configuration Hw2 does not satisfy the hardware configuration Hw1, the resource allocation unit 34 outputs executable information to the communication unit 31 indicating that the edge server 180 will execute service S and the vehicle ID included in the authentication success information Q1 received from the authentication unit 33.
[0128] Furthermore, if the hardware configuration Hw2 satisfies the hardware configuration Hw1, the resource allocation unit 34 outputs non-execution information to the communication unit 31 indicating that the edge server 180 does not need to execute service S, and the vehicle ID included in the authentication success information Q1 received from the authentication unit 33.
[0129] Furthermore, when the communication unit 31 receives executable information from the resource allocation unit 34, it creates an IP packet P4 containing the executable information, which includes the IP address of the resource management server 170 and the IP address of the edge server 180 corresponding to the vehicle ID indicated by the executable information as the source IP address and destination IP address, respectively. The communication unit 31 then sends the created IP packet P4 to the TCU 202A.
[0130] When the communication unit 31 receives information that does not need to be executed from the resource allocation unit 34, it creates an IP packet P5 containing the information that does not need to be executed, and which includes the IP address of the resource management server 170 and the IP address of vehicle 1 corresponding to the vehicle ID indicated by the information that does not need to be executed as the source IP address and destination IP address, respectively. The communication unit 31 then sends the created IP packet P5 to the TCU 202A.
[0131] Referring again to Figure 2, when TCU 202A receives IP packet P3 from resource management server 170, it transmits the non-executable information contained in the received IP packet P3 to the navigation device 202C via the in-vehicle relay device 101. Also, when TCU 202A receives IP packet P4 from resource management server 170, it transmits the executable information contained in the received IP packet P4 to the navigation device 202C via the in-vehicle relay device 101. Also, when TCU 202A receives IP packet P5 from resource management server 170, it transmits the non-executable information contained in the received IP packet P5 to the navigation device 202C via the in-vehicle relay device 101.
[0132] When the navigation device 202C receives information that cannot be executed, can be executed, or does not need to be executed from the TCU 202A via the in-vehicle relay device 101, it performs notification processing based on the information that cannot be executed, can be executed, or does not need to be executed.
[0133] Specifically, for example, if the navigation device 202C receives information that the service cannot be executed from the TCU 202A, it displays a screen on its own display unit indicating that the edge server 180 cannot execute service S. Also, if the navigation device 202C receives information that the service can be executed from the TCU 202A, it displays a screen on its own display unit indicating that the edge server 180 will execute service S. Also, if the navigation device 202C receives information that the service does not need to be executed from the TCU 202A, it displays a screen on its own display unit indicating that the edge server 180 does not need to execute service S.
[0134] (Edge Server) Figure 5 shows an example of the configuration of an edge server according to an embodiment of the present disclosure. Referring to Figure 5, the edge server 180 comprises a communication unit 41, a service execution unit 42, and a storage unit 43. One or both of the communication unit 41 and the service execution unit 42 are implemented by a processing circuit including one or more processors, for example. The storage unit 43 is, for example, a non-volatile memory included in the processing circuit.
[0135] When the communication unit 41 receives resource information from the resource management server 170 via the external network 151, it outputs the received resource information to the service execution unit 42.
[0136] (Service execution unit) The service execution unit 42 executes the service S using the resource R allocated by the resource management server 170.
[0137] More specifically, for example, the service execution unit 42 executes service S using resource R of the type indicated by the resource information received from the communication unit 41. In this embodiment, for example, the service execution unit 42 executes service S by using the data collection function of various sensors as resource R.
[0138] Figure 6 is a diagram illustrating an example of a service performed by an edge server in a communication system according to an embodiment of the present disclosure.
[0139] In the example shown in Figure 6, the communication system 501 includes edge servers 180A, 180B, and 180C, which are edge servers 180.
[0140] Edge server 180A performs LKAS service and ACC service. Edge servers 180B and 180C perform obstacle avoidance service and door unlocking service, respectively.
[0141] <LKAS Service and ACC Service> For example, if the hardware configuration Hw2 indicated by the resource-related information included in the execution request information received from the in-vehicle relay device 101 does not satisfy the hardware configuration Hw1 required for the execution of the LKAS service, the resource management server 170 allocates the data collection function H11 required for the execution of the LKAS service as resource R to the edge server 180A.
[0142] Furthermore, if the hardware configuration Hw2 indicated by the resource-related information included in the execution request information received from the in-vehicle relay device 101 does not satisfy the hardware configuration Hw1 required for the execution of the ACC service, the resource management server 170 allocates the data collection function H12 required for the execution of the ACC service as resource R to the edge server 180A.
[0143] In this embodiment, for example, the types of data required to execute the LKAS service and the types of data required to execute the ACC service are the same. Specifically, the data required to execute the LKAS service and the ACC service are the location information of the vehicle 1, the vehicle speed information of the vehicle 1, and information indicating the detection results of a roadside sensor (not shown). However, the types of data required to execute the LKAS service and the types of data required to execute the ACC service may be different.
[0144] In the resource management server 170, when the resource allocation unit 34 allocates collection functions H11 and H12 to the edge server 180A, it sends resource information E1 indicating that the allocated resource R is the collection functions H11 and H12, along with the server ID of the edge server 180A and the vehicle ID included in the authentication success information Q1 received from the authentication unit 33, to the edge server 180A.
[0145] Referring to Figures 5 and 6, in the edge server 180A, when the service execution unit 42 receives resource information E1 from the resource management server 170 via the communication unit 41, it requests the in-vehicle relay device 101 to transmit vehicle information, which indicates the status of vehicle 1 and is used to generate control information.
[0146] More specifically, for example, the service execution unit 42 transmits data request information indicating the type of vehicle information to be used for generating control information to the in-vehicle relay device 101 via the communication unit 41.
[0147] Specifically, the service execution unit 42 creates data request information (hereinafter also referred to as "data request information D1") indicating a request to transmit location information and vehicle speed information as vehicle information, and the vehicle ID indicated by resource information E1. The service execution unit 42 then outputs the created data request information D1 to the communication unit 41.
[0148] When the communication unit 41 receives data request information D1 from the service execution unit 42, it creates an IP packet P6 containing the data request information D1, which includes the IP address of the edge server 180A and the IP address of vehicle 1 corresponding to the vehicle ID indicated by the data request information D1 as the source IP address and destination IP address, respectively. The communication unit 41 then transmits the created IP packet P6 to the TCU 202A.
[0149] When TCU202A receives an IP packet P6 from edge server 180A, it transmits the data request information D1 contained in the received IP packet P6 to the in-vehicle relay device 101.
[0150] Referring again to Figure 3, for example, if the in-vehicle relay device 101 sends a service execution request S to the resource management server 170 that is a request for the execution of the LKAS service and the ACC service, it sends at least one of the location information and vehicle speed information to the edge server 180A as vehicle information used to generate control information. In this embodiment, the in-vehicle relay device 101 sends both the location information and vehicle speed information to the edge server 180A as said vehicle information.
[0151] More specifically, in the in-vehicle relay device 101, when the service management unit 21 receives data request information D1 from the TCU 202A via the relay unit 11, it transmits location information and vehicle speed information to the edge server 180A via the TCU 202A.
[0152] Specifically, after receiving data request information D1, the service management unit 21 transmits location information from the navigation device 202C to the edge server 180A via the TCU 202A each time it receives location information.
[0153] Furthermore, after receiving data request information D1, the service management unit 21 transmits the vehicle speed information from the vehicle speed sensor 202B to the edge server 180A via the TCU 202A each time it receives vehicle speed information.
[0154] Referring again to Figures 5 and 6, the edge server 180A communicates with one or more roadside sensors installed on a highway. These roadside sensors periodically detect objects on the road and transmit roadside sensor information K1 indicating the detection result to the edge server 180A.
[0155] In the edge server 180A, for example, the storage unit 43 stores map information for a region that includes the location indicated by the location information transmitted from the in-vehicle relay device 101.
[0156] When the service execution unit 42 receives location information from the in-vehicle relay device 101 via the communication unit 41, it uses the received location information and the map information stored in the storage unit 43 to determine whether or not the vehicle 1 is traveling on a highway.
[0157] When the service execution unit 42 determines that vehicle 1 is traveling on a highway, it executes LKAS service and ACC service based on the information received from the in-vehicle relay device 101 after determining that vehicle 1 is traveling on a highway, specifically location information and vehicle speed information, as well as roadside sensor information K1 received from the roadside sensor.
[0158] The edge server 180A transmits the execution results of the LKAS service and the ACC service to the in-vehicle relay device 101.
[0159] More specifically, for example, in the edge server 180A, the service execution unit 42 includes authentication information B2 in the control information (hereinafter also referred to as "control information G1"), which is the result of executing the LKAS service, and transmits it to the in-vehicle relay device 101 via the communication unit 41 and TCU 202A. The control information G1 is information for controlling an in-vehicle device 202 that should be operated to prevent the vehicle 1 from deviating from the driving lane. Here, the in-vehicle device 202 is assumed to be a steering ECU.
[0160] Authentication information B2 is information used in the authentication process C11 of control information by the in-vehicle relay device 101. Authentication information B2 includes, for example, the server ID of the edge server 180 and the password. Authentication information B2 is stored in the storage unit 36.
[0161] Furthermore, for example, the service execution unit 42 includes authentication information B2 in the control information (hereinafter also referred to as "control information G2"), which is the result of executing the ACC service, and transmits it to the in-vehicle relay device 101 via the communication unit 41 and TCU 202A. The control information G2 is information for controlling an in-vehicle device 202 that should be operated to maintain a certain distance from the vehicle ahead. Here, the in-vehicle device 202 is assumed to be a brake ECU.
[0162] Referring again to Figures 2 and 3, in the in-vehicle relay device 101, for example, the control unit 22 performs the control information authentication process C11.
[0163] More specifically, for example, when the control unit 22 receives control information from the edge server 180A via the TCU 202A and relay unit 11, it performs authentication processing C11 of the received control information using the authentication information B2 contained in the control information.
[0164] When the control unit 22 confirms that the authentication process C11 for the control information is successful, it determines that the edge server 180 that sent the control information is a legitimate edge server 180.
[0165] On the other hand, if the control information authentication process C11 fails, the control unit 22 determines that the edge server 180 that is the source of the control information is an unauthorized edge server 180 (hereinafter also referred to as the "unauthorized server"). The control unit 22 then sends authentication failure information F11, indicating that the edge server 180 that is the source of the control information is an unauthorized server, to the navigation device 202C via the relay unit 11.
[0166] When the navigation device 202C receives authentication failure information F11 from the in-vehicle relay device 101, it performs notification processing based on the received stop information. Specifically, for example, the navigation device 202C displays a screen on its own display unit indicating that the edge server 180, the source of the control information, is an unauthorized server.
[0167] Furthermore, the control unit 22 may be configured to determine that the edge server 180 is a malicious server if the control information received from the edge server 180 satisfies predetermined conditions. In this case, for example, the storage unit 13 stores operating range information for each service S, indicating the operating range of the in-vehicle equipment 202 corresponding to the service S during execution of the service S. The in-vehicle equipment 202 includes actuators that drive the brake pedal and EPS (Electric Power Steering), etc. If the operating range when the in-vehicle equipment 202 is operated according to the received control information falls outside the operating range indicated by the operating range information in the storage unit 13, the control unit 22 determines that the edge server 180 that sent the control information is a malicious server.
[0168] The control unit 22 controls the in-vehicle equipment 202 of the vehicle 1 using control information received from the edge server 180 via the TCU 202A and relay unit 11.
[0169] More specifically, for example, if the authentication process C11 of the control information G1 is successful, the control unit 22 transmits the control information G1 to the steering ECU via the relay unit 11.
[0170] When the steering ECU receives control information G1 from the in-vehicle relay device 101, it operates according to the received control information G1.
[0171] Furthermore, if the authentication process C11 of the control information G2 is successful, the control unit 22 transmits the control information G2 to the brake ECU via the relay unit 11.
[0172] When the brake ECU receives control information G2 from the in-vehicle relay device 101, it operates according to the received control information G2.
[0173] <Obstacle Avoidance Service> Referring again to Figures 5 and 6, for example, if the hardware configuration Hw2 indicated by the resource-related information included in the execution request information received from the in-vehicle relay device 101 does not satisfy the hardware configuration Hw1 required for the execution of the obstacle avoidance service, the resource management server 170 allocates the data collection function H2 required for the execution of the obstacle avoidance service as resource R to the edge server 180B.
[0174] In this embodiment, for example, the data required to perform the obstacle avoidance service includes the location information of vehicle 1, the vehicle speed information of vehicle 1, information indicating the detection result of a roadside sensor installed at the intersection CS, the location information of another vehicle 1 entering the intersection CS, and the vehicle speed information of the other vehicle 1.
[0175] In the resource management server 170, when the resource allocation unit 34 allocates the collection function H2 to the edge server 180B, it sends resource information E2 indicating that the allocated resource R is the collection function H2, along with the server ID of the edge server 180B and the vehicle ID included in the authentication success information Q1 received from the authentication unit 33, to the edge server 180B.
[0176] In the edge server 180B, when the service execution unit 42 receives resource information E2 from the resource management server 170 via the communication unit 41, it creates data request information (hereinafter also referred to as "data request information D2") indicating a request to transmit location information and vehicle speed information as vehicle information, and the vehicle ID indicated in resource information E2. The service execution unit 42 then outputs the created data request information D2 to the communication unit 41.
[0177] When the communication unit 41 receives data request information D2 from the service execution unit 42, it creates an IP packet P6 containing the data request information D2, which includes the IP address of the edge server 180B and the IP address of vehicle 1 corresponding to the vehicle ID indicated in the data request information D2 as the source IP address and destination IP address, respectively. The communication unit 31 then transmits the created IP packet P6 to the TCU 202A.
[0178] When TCU202A receives an IP packet P6 from the edge server 180B, it transmits the data request information D2 contained in the received IP packet P6 to the in-vehicle relay device 101.
[0179] Referring again to Figure 3, for example, if the in-vehicle relay device 101 sends a service execution request S to the resource management server 170 that is a request to execute an obstacle avoidance service, it sends at least one of the location information and vehicle speed information to the edge server 180B as vehicle information used to generate control information. In this embodiment, the in-vehicle relay device 101 sends both the location information and vehicle speed information to the edge server 180B as the vehicle information.
[0180] More specifically, in the in-vehicle relay device 101, when the service management unit 21 receives data request information D2 from the TCU 202A via the relay unit 11, it transmits location information and vehicle speed information to the edge server 180B via the TCU 202A.
[0181] Specifically, after receiving data request information D2, the service management unit 21 transmits location information from the navigation device 202C to the edge server 180B via the TCU 202A each time it receives location information.
[0182] Furthermore, after receiving data request information D2, the service management unit 21 transmits the vehicle speed information from the vehicle speed sensor 202B to the edge server 180B via the TCU 202A each time it receives vehicle speed information.
[0183] Referring again to Figures 5 and 6, the edge server 180B communicates with one or more roadside sensors installed around the intersection CS. These roadside sensors periodically detect objects on the road and transmit roadside sensor information K2 indicating the detection result to the edge server 180B.
[0184] In the edge server 180B, for example, the storage unit 43 stores map information for a region that includes the location indicated by the location information transmitted from the in-vehicle relay device 101.
[0185] When the service execution unit 42 receives location information from the in-vehicle relay device 101 via the communication unit 41, it uses the received location information and the map information stored in the storage unit 43 to determine whether or not the vehicle 1 is passing through intersection CS.
[0186] When the service execution unit 42 determines that vehicle 1 is passing through an intersection CS, it executes an obstacle avoidance service based on the information received from the in-vehicle relay device 101 after determining that vehicle 1 is passing through an intersection CS, specifically, location information and vehicle speed information, roadside sensor information K2 received from roadside sensors installed at the intersection CS, and location information and vehicle speed information of other vehicles 1 around the intersection CS.
[0187] The edge server 180B transmits the results of the obstacle avoidance service to the in-vehicle relay device 101.
[0188] More specifically, for example, in the edge server 180B, the service execution unit 42 transmits warning information to the in-vehicle relay device 101 via the TCU 202A indicating that an obstacle has been detected at the intersection CS, as a result of executing the obstacle avoidance service.
[0189] Referring again to Figures 2 and 3, in the in-vehicle relay device 101, when the service management unit 21 receives warning information from the edge server 180B via the TCU 202A and relay unit 11, it transmits the received warning information to the navigation device 202C via the relay unit 11.
[0190] When the navigation device 202C receives warning information from the in-vehicle relay device 101, it performs notification processing based on the received warning information. Specifically, for example, the navigation device 202C displays a screen on its display unit indicating that an obstacle has been detected at the intersection CS being passed through.
[0191] The edge server 180B may also be configured to transmit control information to the in-vehicle relay device 101, in addition to or instead of warning information, to control the vehicle 1's movement in order to avoid obstacles, as a result of executing the obstacle avoidance service. In this case, the in-vehicle relay device 101 transmits the control information received from the edge server 180B to in-vehicle equipment 202 such as the steering ECU.
[0192] <Door unlocking service> Referring again to Figures 5 and 6, for example, if the hardware configuration Hw2 indicated by the resource-related information included in the execution request information received from the in-vehicle relay device 101 does not satisfy the hardware configuration Hw1 required for the execution of the door unlocking service, the resource management server 170 allocates the data collection function H3 required for the execution of the door unlocking service as resource R to the edge server 180C.
[0193] In this embodiment, for example, the data required to perform the door unlocking service includes location information of vehicle 1, power information indicating the power status of vehicle 1, door information indicating the open / closed state of the vehicle 1's doors, and image information showing the facial image of the vehicle 1's occupant. The power information is, for example, information indicating the state of the vehicle 1's ignition power supply.
[0194] In the resource management server 170, when the resource allocation unit 34 allocates the collection function H3 to the edge server 180C, it sends resource information E3 indicating that the allocated resource R is the collection function H3, along with the server ID of the edge server 180C and the resource-related information and vehicle ID included in the authentication success information Q1 received from the authentication unit 33, to the edge server 180C.
[0195] In the edge server 180C, when the service execution unit 42 receives resource information E3 from the resource management server 170 via the communication unit 41, it creates data request information D3 indicating a request to transmit location information, power information, and door information, as well as the vehicle ID indicated by resource information E3. The service execution unit 42 then outputs the created data request information D3 to the communication unit 41.
[0196] When the communication unit 41 receives data request information D3 from the service execution unit 42, it creates an IP packet P7 containing the data request information D3, which includes the IP address of the edge server 180C and the IP address of vehicle 1 corresponding to the vehicle ID indicated in the data request information D3 as the source IP address and destination IP address, respectively. The communication unit 31 then transmits the created IP packet P7 to the TCU 202A.
[0197] When TCU202A receives an IP packet P7 from the edge server 180C, it transmits the data request information D3 contained in the received IP packet P7 to the in-vehicle relay device 101.
[0198] Referring again to Figure 3, for example, if the in-vehicle relay device 101 sends a service execution request S to the resource management server 170 that is a door unlocking service execution request, it sends at least one of the location information, power information, and door information to the edge server 180C as vehicle information used to generate control information. In this embodiment, the in-vehicle relay device 101 sends all of the location information, power information, and door information to the edge server 180C as said vehicle information.
[0199] More specifically, when the service management unit 21 receives data request information D3 from the TCU 202A via the relay unit 11, it periodically transmits location information, power information, and door information to the edge server 180C via the relay unit 11 and the TCU 202A.
[0200] Referring again to Figures 5 and 6, in the edge server 180C, the service execution unit 42 determines whether or not vehicle 1 is parked.
[0201] More specifically, for example, when the service execution unit 42 receives power information from the in-vehicle relay device 101 via the communication unit 41, it checks whether the ignition power state indicated by the received power information is in the off state.
[0202] The service execution unit 42 determines that vehicle 1 is not parked if the ignition power supply is in the ON state.
[0203] On the other hand, the service execution unit 42 determines that vehicle 1 is parked if the ignition power supply is in the off state.
[0204] For example, the storage unit 43 stores map information for a region that includes the location indicated by the location information transmitted from the in-vehicle relay device 101.
[0205] If the service execution unit 42 determines that vehicle 1 is parked, it uses the location information received from the in-vehicle relay device 101 immediately after determining that vehicle 1 is parked, and the map information stored in the storage unit 43, to identify the location of the parking lot where vehicle 1 is parked.
[0206] For example, if the hardware configuration Hw2 indicated by the resource-related information received by the resource management server 170 from the in-vehicle relay device 101 is insufficient for the hardware configuration Hw1 required to perform the door unlocking service, the edge server 180C will acquire data corresponding to the missing hardware configuration from equipment outside the vehicle 1. The edge server 180C will then transmit the acquired data to the in-vehicle relay device 101.
[0207] More specifically, for example, in the edge server 180C, the service execution unit 42 identifies the location of the parking lot where vehicle 1 is parked, and then checks whether or not vehicle 1 is equipped with a camera that captures facial images of the occupants of vehicle 1.
[0208] Specifically, the service execution unit 42 checks whether a camera is mounted on the vehicle 1 by referring to resource-related information contained in resource information E3 received from the resource management server 170.
[0209] If a camera is not mounted on the vehicle 1, the service execution unit 42 acquires image information from peripheral equipment located outside the vehicle 1, such as a camera installed in a parking lot.
[0210] For example, the edge server 180C communicates with a camera installed in the parking lot where vehicle 1 is parked. When the camera detects a person at a target location in the parking lot, it transmits image information showing the face of the detected person to the edge server 180C.
[0211] The edge server 180C is not limited to a camera installed in the parking lot; it may also be a communication terminal device carried by the occupant of vehicle 1, and may be configured to communicate with a communication terminal device including a camera. In this case, for example, when the occupant of vehicle 1 unlocks the door of vehicle 1 while it is parked, they take a picture of their face using the communication terminal device. The communication terminal device transmits image information showing the face image to the edge server 180C.
[0212] When the service execution unit 42 receives image information from a camera installed in the parking lot via the communication unit 41, it checks whether the door open / closed state, as indicated by the door information received from the in-vehicle relay device 101 immediately after receiving the image information, is in the closed state.
[0213] On the other hand, if a camera is mounted on the vehicle 1, the service execution unit 42 checks whether the door open / closed state indicated by the door information received from the in-vehicle relay device 101 is in the closed state immediately after identifying the location of the parking lot.
[0214] Then, if the door is in the closed state, the service execution unit 42 performs the door unlocking service.
[0215] The edge server 180C transmits the results of the door unlocking service to the in-vehicle relay device 101.
[0216] More specifically, for example, in the edge server 180B, the service execution unit 42 transmits control information (hereinafter also referred to as "control information G3"), which is the result of executing the door unlocking service, to the in-vehicle relay device 101 via the communication unit 41 and the TCU 202A. The control information G3 is information for controlling the in-vehicle equipment 202 that should be operated to unlock the doors of the vehicle 1. In this case, the in-vehicle equipment 202 is the door lock ECU.
[0217] For example, when the service execution unit 42 acquires image information from a camera installed in the parking lot, it transmits the image information, authentication information B2, and the vehicle ID of vehicle 1 to the in-vehicle relay device 101 in the control information G3.
[0218] Furthermore, for example, if a camera is mounted on the vehicle 1, the service execution unit 42 transmits the authentication information B2 and the vehicle ID of the vehicle 1, along with the control information G3, to the in-vehicle relay device 101.
[0219] Referring again to Figure 3, in the in-vehicle relay device 101, when the control unit 22 receives control information G3 from the edge server 180C via the TCU 202A and relay unit 11, it performs facial recognition of the occupant of the vehicle 1.
[0220] For example, the memory unit 13 stores passenger information that shows the facial images of the passengers of the vehicle 1. If the control unit 22 receives control information G3 from the edge server 180C and includes image information, it calculates the similarity between the facial image shown in the image information and the facial image shown in the passenger information stored in the memory unit 13.
[0221] On the other hand, if the control information G3 received from the edge server 180C does not contain image information, the control unit 22 calculates the similarity between the face image shown in the image information received from the camera mounted on the vehicle 1 and the face image shown in the passenger information stored in the storage unit 13.
[0222] The control unit 22 determines that face recognition has failed if the calculated similarity is below the threshold. On the other hand, the control unit 22 determines that face recognition has succeeded if the calculated similarity is equal to or greater than the threshold.
[0223] When the control unit 22 determines that facial recognition has been successful, it performs authentication processing C11 on the control information G3 received from the edge server 180C. If the authentication processing C11 of the control information G3 is successful, the control unit 22 transmits the control information G3 to the door lock ECU via the relay unit 11.
[0224] When the door lock ECU receives control information G3 from the in-vehicle relay device 101, it operates according to the received control information G3. That is, the door lock ECU unlocks the doors of vehicle 1.
[0225] (Resource release request) Referring again to Figures 2 and 3, in the in-vehicle relay device 101, the service management unit 21 sends a resource release request for resource R to the resource management server 170.
[0226] More specifically, for example, the service management unit 21 determines whether the conditions for terminating the provision of service S (hereinafter also referred to as "termination conditions") are met. Termination conditions include when the user of vehicle 1 wishes to terminate the provision of service S, and when vehicle 1 moves from within the service area of service S to outside the service area. In the following explanation, we will assume that the termination condition is when the user of vehicle 1 wishes to terminate the provision of service S.
[0227] For example, the navigation device 202C receives input indicating a desire to terminate the provision of service S. Upon receiving this input, the navigation device 202C transmits termination information indicating the desire to terminate the provision of service S to the in-vehicle relay device 101.
[0228] In the in-vehicle relay device 101, when the service management unit 21 receives termination information from the navigation device 202C via the relay unit 11, it determines that the termination conditions have been met. The service management unit 21 then sends a release request information, including a request to release resource R, authentication information B1, and the vehicle ID stored in the storage unit 13, to the resource management server 170 via the relay unit 11 and the TCU 202A.
[0229] (Authentication process for release request) Referring again to Figure 4, in the resource management server 170, when the communication unit 31 receives release request information from the in-vehicle relay device 101 via the TCU 202A, it outputs the received release request information to the authentication unit 33.
[0230] For example, the authentication unit 33 performs authentication processing C2 for a release request. More specifically, for example, when the authentication unit 33 receives release request information from the communication unit 31, it performs authentication processing C2 using the authentication information B1 contained in the release request information.
[0231] If the authentication process C2 is successful, the authentication unit 33 outputs authentication success information Q2, which indicates that the authentication process C2 was successful, to the resource release unit 35, including the vehicle ID included in the release request information received from the communication unit 31.
[0232] On the other hand, if the authentication process C2 fails, the authentication unit 33 transmits authentication failure information F2, indicating that the authentication process C2 has failed, to the in-vehicle relay device 101 via the communication unit 31 and TCU 202A.
[0233] (Release of Resource R) The resource release unit 35 receives a request to release resource R from the in-vehicle relay device 101 via the communication unit 31 and releases resource R.
[0234] More specifically, for example, when the resource release unit 35 receives authentication success information Q2 from the communication unit 31, it obtains service information from the storage unit 36 that indicates the same vehicle ID as the vehicle ID included in the authentication success information Q2.
[0235] When the resource release unit 35 obtains service information from the storage unit 36, it releases the resource R indicated by the obtained service information.
[0236] More specifically, for example, when the resource release unit 35 obtains service information from the storage unit 36, it refers to the resource management table in the storage unit 36 to identify the service ID corresponding to the resource indicated by the obtained service information.
[0237] The resource release unit 35 then sends stop request information indicating a request to stop the execution of service S to the edge server 180 of the identified service ID via the communication unit 31.
[0238] Furthermore, for example, when the resource release unit 35 obtains service information from the storage unit 36, it performs an update process N2 to update the resource management table in the storage unit 36. Specifically, for example, the resource release unit 35 updates the value of the discrimination flag corresponding to the resource R indicated by the service information in the resource management table from "1" to "zero". In this way, the resource release unit 35 releases the resource R corresponding to the release request received from the in-vehicle relay device 101, making the resource R available for use in other vehicles 1.
[0239] (Stopping Service Execution) Referring again to Figure 5, in the edge server 180, when the service execution unit 42 receives stop request information from the resource management server 170 via the communication unit 41, it stops the execution of service S in accordance with the received stop request information.
[0240] [Operation Flow] Next, the operation flow of each device in the communication system according to the embodiment of this disclosure will be explained with reference to the drawings.
[0241] Figures 7 and 8 are flowcharts illustrating an example of the operation procedure when an in-vehicle relay device according to an embodiment of the present disclosure controls in-vehicle equipment.
[0242] Referring to Figures 7 and 8, first, the in-vehicle relay device 101 waits to receive route information from the navigation device 202C (NO in step ST101).
[0243] Then, when the in-vehicle relay device 101 receives route information from the navigation device 202C (YES in step ST101), it includes the vehicle ID stored in the storage unit 13 in the received route information and transmits it to the resource management server 170 via the TCU 202A (step ST102).
[0244] Next, the in-vehicle relay device 101 waits to receive service information from the resource management server 170 (NO in step ST103).
[0245] Then, when the in-vehicle relay device 101 receives service information from the resource management server 170 (YES in step ST103), it sends execution request information, including the execution request for service S, authentication information B1, and resource-related information, to the resource management server 170 via the TCU 202A (step ST104).
[0246] Next, the in-vehicle relay device 101 awaits the reception of data request information or control information from the edge server 180 (NO in step ST105 or NO in step ST107).
[0247] Then, when the in-vehicle relay device 101 receives data request information from the edge server 180 (YES in step ST105), it transmits vehicle information indicating the status of vehicle 1, of the type indicated by the received data request information, to the edge server 180 via the TCU 202A (step ST106), and waits to receive new data request information or control information from the edge server 180 (NO in step ST105 or NO in step ST107).
[0248] Furthermore, the in-vehicle relay device 101 receives control information from the edge server 180, and if the authentication process C11 of the received control information is successful (YES in step ST107 and YES in step ST108), it uses the control information to control the in-vehicle device 202. For example, as described above, the in-vehicle relay device 101 transmits the received control information to the in-vehicle device 202 (step ST109).
[0249] Next, the in-vehicle relay device 101 determines whether or not the termination conditions for terminating the provision of service S are met (step ST110).
[0250] Then, if the in-vehicle relay device 101 determines that the termination conditions are met (YES in step ST110), it sends a request to release resource R and release request information including authentication information B1 to the resource management server 170 via the TCU 202A (step ST111), and waits to receive new route information from the navigation device 202C (NO in step ST101).
[0251] On the other hand, if the authentication process C11 of the received control information fails (NO in step ST108), the in-vehicle relay device 101 sends authentication failure information F11 to the navigation device 202C indicating that the edge server 180, the source of the control information, is an unauthorized server (step ST112), and waits to receive new route information from the navigation device 202C (NO in step ST101).
[0252] Figures 9 and 10 are flowcharts illustrating an example of the operation procedure when a resource management server according to an embodiment of this disclosure allocates resources.
[0253] Referring to Figures 9 and 10, first, the resource management server 170 waits for the reception of route information from the in-vehicle relay device 101 (NO in step ST201).
[0254] Then, when the resource management server 170 receives route information from the in-vehicle relay device 101 (YES in step ST201), it creates service information indicating the service S that the edge server 180 can execute. For example, as described above, the resource management server 170 creates service information using the route information received from the in-vehicle relay device 101 and the service table stored in the storage unit 36 (step ST202).
[0255] Next, the resource management server 170 transmits the created service information to the in-vehicle relay device 101 via the TCU 202A (step ST203).
[0256] Next, the resource management server 170 waits for the receipt of execution request information from the in-vehicle relay device 101 (NO in step ST204).
[0257] Then, when the resource management server 170 receives execution request information from the in-vehicle relay device 101 (YES in step ST204), it performs authentication processing C1 for the execution request of service S included in the received execution request information (step ST205).
[0258] Next, if the authentication process C1 is successful (YES in step ST206), the resource management server 170 checks whether the hardware configuration Hw2 of vehicle 1, indicated by the resource-related information included in the received execution request information, satisfies the hardware configuration Hw1 required for the execution of service S, indicated by the created service information (step ST207).
[0259] Then, if the hardware configuration Hw2 does not satisfy the hardware configuration Hw1 (NO in step ST207), the resource management server 170 determines whether it is possible to allocate resource R to execute service S. For example, as described above, the resource management server 170 checks whether the value of the discrimination flag corresponding to resource R is "zero" by referring to the resource management table in the storage unit 36 (step ST208).
[0260] Then, if the resource management server 170 determines that it is possible to allocate resource R (YES in step ST208), it allocates resource R (step ST209).
[0261] Next, the resource management server 170 sends resource information indicating the type of resource R that has been allocated, along with the server ID of the edge server 180 corresponding to that resource R and the vehicle ID included in the execution request information received from the in-vehicle relay device 101, to the edge server 180 (step ST210).
[0262] Next, the resource management server 170 transmits executable information to the in-vehicle relay device 101 via the TCU 202A indicating that the edge server 180 will execute service S (step ST211). Steps ST210 and ST211 may be executed in any order or in parallel.
[0263] Next, the resource management server 170 awaits the reception of release request information from the in-vehicle relay device 101 (NO in step ST212).
[0264] Then, when the resource management server 170 receives release request information from the in-vehicle relay device 101 (YES in step ST212), it performs authentication processing C2 for the release request of resource R included in the received release request information (step ST213).
[0265] Next, if the authentication process C2 is successful (YES in step ST214), the resource management server 170 releases resource R. For example, as described above, the resource management server 170 updates the discrimination flag corresponding to the resource R to be released in the resource management table in the storage unit 13 to a value indicating that resource R is not allocated. The resource management server 170 also sends a stop request information to the edge server 180 requesting the cessation of the execution of service S (step ST215).
[0266] On the other hand, if the authentication process C1 fails (NO in step ST206), the resource management server 170 sends authentication failure information F1 indicating that the authentication process C1 has failed to the in-vehicle relay device 101 via the TCU 202 (step ST216), and waits to receive new route information from the in-vehicle relay device 101 (NO in step ST201).
[0267] Furthermore, if the hardware configuration Hw2 satisfies the hardware configuration Hw1 (YES in step ST207), the resource management server 170 sends non-execution information to the in-vehicle relay device 101 via the TCU 202A indicating that the edge server 180 does not need to execute service S (step ST217), and waits to receive new route information from the in-vehicle relay device 101 (NO in step ST201).
[0268] Furthermore, if the resource management server 170 determines that resource R cannot be allocated (NO in step ST208), it sends an execution failure information to the in-vehicle relay device 101 via the TCU 202A indicating that the edge server 180 cannot execute service S (step ST218), and waits to receive new route information from the in-vehicle relay device 101 (NO in step ST201).
[0269] Furthermore, if authentication process C2 fails (NO in step ST214), the resource management server 170 sends authentication failure information F2 indicating that authentication process C2 has failed to the in-vehicle relay device 101 via the TCU 202 (step ST219), and waits to receive new route information from the in-vehicle relay device 101 (NO in step ST201).
[0270] Figure 11 is a flowchart that shows an example of the operation procedure when an edge server according to the embodiment of this disclosure performs a service.
[0271] Referring to Figure 11, first, the edge server 180 waits to receive resource information from the resource management server 170 (NO in step ST301).
[0272] Next, when the edge server 180 receives resource information from the resource management server 170 (YES in step ST301), it sends data request information to the in-vehicle relay device 101 indicating a request to transmit vehicle information to be used for generating control information, according to the resource R indicated by the received resource information, i.e., the data collection function (step ST302).
[0273] Next, the edge server 180 waits to receive vehicle information from the in-vehicle relay device 101 (NO in step ST303).
[0274] Next, the edge server 180 receives vehicle information from the in-vehicle relay device 101 (YES in step ST303), and if the resource R allocated by the resource management server 170 is the data collection function H3 necessary for executing the door unlocking service (YES in step ST304), it checks whether a camera is installed in the vehicle 1 (step ST305).
[0275] Then, if a camera is mounted on the vehicle 1 (YES in step ST305), the edge server 180 executes service S using the vehicle information received from the in-vehicle relay device 101. For example, as described above, the edge server 180 generates control information using the vehicle information (step ST306).
[0276] Next, the edge server 180 transmits the execution result of service S, i.e., the generated control information, to the in-vehicle relay device 101 via the TCU 202A (step ST307), and waits to receive new resource information from the resource management server 170 (NO in step ST301).
[0277] On the other hand, if the camera is not installed in the vehicle 1 (NO in step ST305), the edge server 180 acquires image information showing the faces of the passengers in the vehicle 1 from a camera installed outside the vehicle 1 (step ST308), and executes service S using the vehicle information received from the in-vehicle relay device 101 (step ST309).
[0278] Next, the edge server 180 transmits the generated control information and acquired image information to the in-vehicle relay device 101 via the TCU 202A (step ST310), and waits to receive new resource information from the resource management server 170 (NO in step ST301).
[0279] Furthermore, if the edge server 180 receives vehicle information from the in-vehicle relay device 101 (YES in step ST303) and the resource R allocated by the resource management server 170 is not the collection function H3 (NO in step ST304), it executes service S using the vehicle information (step ST306).
[0280] Figure 12 is a flowchart that shows an example of the operation procedure when an edge server according to the embodiment of this disclosure performs a process to stop the execution of a service.
[0281] Referring to Figure 12, first, the edge server 180 waits for the reception of a stop request information from the resource management server 170 (NO in step ST401).
[0282] Then, when the edge server 180 receives a stop request information from the resource management server 170 (YES in step ST401), it stops the execution of service S (step ST402).
[0283] Figures 13 and 14 show an example of the processing sequence of each device in a communication system according to an embodiment of the present disclosure.
[0284] Referring to Figures 13 and 14, first, the navigation device 202C transmits route information to the in-vehicle relay device 101 (step ST501).
[0285] Next, the in-vehicle relay device 101 transmits the route information received from the navigation device 202C to the resource management server 170 (step ST502).
[0286] Next, when the resource management server 170 receives route information from the in-vehicle relay device 101, it creates service information indicating the services S that the edge server 180 can execute (step ST503).
[0287] Next, the resource management server 170 transmits the created service information to the in-vehicle relay device 101 (step ST504).
[0288] Next, when the in-vehicle relay device 101 receives service information from the resource management server 170, it sends execution request information to the resource management server 170, including the execution request for service S indicated by the received service information, authentication information B1, and vehicle ID (step ST505).
[0289] Next, when the resource management server 170 receives execution request information from the in-vehicle relay device 101, it performs authentication processing C1 for the execution request of service S included in the received execution request. Here, we assume that authentication processing C1 is successful (step ST506).
[0290] Next, if the authentication process C1 is successful, the resource management server 170 allocates the resources R to be used to execute the service S (step ST507).
[0291] Next, the resource management server 170 sends resource information E1 indicating the type of resource R allocated to the edge server 180A (step ST508).
[0292] Next, when the edge server 180A receives resource information E1 from the resource management server 170, it sends data request information D1 to the in-vehicle relay device 101 indicating that it requests the transmission of vehicle information, specifically location information and vehicle speed information, to be used for generating control information (step ST509).
[0293] Next, when the in-vehicle relay device 101 receives data request information D1 from the edge server 180A, it transmits location information and vehicle speed information to the edge server 180A (step ST510).
[0294] Next, the edge server 180A performs the LKAS service and the ACC service (step ST511).
[0295] Next, the edge server 180A transmits control information G1 for controlling the steering ECU to the in-vehicle relay device 101 as an execution result of the LKAS service (step ST512).
[0296] Furthermore, the edge server 180A transmits control information G2 for controlling the brake ECU to the in-vehicle relay device 101 as an execution result of the ACC service (step ST513).
[0297] Next, when the in-vehicle relay device 101 receives control information G1 from the edge server 180A, it transmits the received control information G1 to the steering ECU (step ST514).
[0298] Furthermore, when the in-vehicle relay device 101 receives control information G2 from the edge server 180A, it transmits the received control information G2 to the brake ECU (step ST515).
[0299] Next, when the steering ECU receives control information G1 from the in-vehicle relay device 101, it operates according to the received control information G1 (step ST516).
[0300] Furthermore, when the brake ECU receives control information G2 from the in-vehicle relay device 101, it operates according to the received control information G2 (step ST517).
[0301] Next, the navigation device 202C transmits termination information to the in-vehicle relay device 101 indicating that it wishes to terminate the provision of LKAS service and ACC service (step ST518).
[0302] Next, when the in-vehicle relay device 101 receives termination information from the navigation device 202C, it determines that the termination conditions for terminating the provision of LKAS service and ACC service are met (step ST519).
[0303] Next, the in-vehicle relay device 101 sends a request to release resource R and release request information including the vehicle ID to the resource management server 170 (step ST520).
[0304] Next, the resource management server 170 performs authentication processing C2 for the resource R release request. Here, we assume that authentication processing C2 is successful (step ST521).
[0305] Next, if the authentication process C2 is successful, the resource management server 170 releases resource R. For example, as described above, the resource management server 170 performs an update process N2 in the resource management table in the storage unit 36, updating the discrimination flag corresponding to the resource R to be released to a value indicating that resource R is not allocated (step ST522).
[0306] Furthermore, the resource management server 170 sends a stop request information to the edge server 180A requesting the cessation of the LKAS service and the ACC service (step ST523).
[0307] Next, when the edge server 180A receives a stop request information from the resource management server 170, it stops the execution of the LKAS service and the ACC service (step ST524).
[0308] Incidentally, it is desirable to make effective use of the resource R used to perform service S related to vehicle 1. As described above, by configuring the resource management server 170 to release resource R in accordance with a release request from the in-vehicle relay device 101, resource R can be used for the period necessary to perform service S. This makes it possible to effectively utilize the shared resource among each vehicle 1.
[0309] In the communication system 501 according to the embodiment of this disclosure, the resource management server 170 is configured to transmit service information indicating a service S that the edge server 180 can execute to the in-vehicle relay device 101, but the invention is not limited to this configuration. The resource management server 170 may be configured not to transmit service information. In this case, for example, the in-vehicle relay device 101 uses information such as route information received from the navigation device 202C to determine the type of service S it wishes to execute. The in-vehicle relay device 101 then includes information indicating the determined type of service S in the execution request information and transmits it to the resource management server 170.
[0310] Furthermore, in the communication system 501 according to the embodiment of this disclosure, the resource management server 170 is configured to send executable information to the in-vehicle relay device 101 indicating that the edge server 180 will execute service S if the hardware configuration Hw2 does not satisfy the hardware configuration Hw1, but the invention is not limited to this configuration. The resource management server 170 may be configured not to send executable information to the in-vehicle relay device 101.
[0311] Furthermore, in the communication system 501 according to the embodiment of this disclosure, the in-vehicle relay device 101 is configured to transmit vehicle information used to generate control information for controlling the in-vehicle equipment 202 to the edge server 180, but the invention is not limited to this configuration. The in-vehicle relay device 101 may be configured not to transmit the vehicle information to the edge server 180. In this case, the edge server 180 generates the control information using information other than the vehicle information.
[0312] Furthermore, in the communication system 501 according to the embodiment of this disclosure, the in-vehicle relay device 101 is configured to transmit information regarding the hardware configuration Hw1 of the vehicle 1 to the resource management server 170 as resource-related information used for resource allocation R by the resource management server 170, but it is not limited to this configuration. The in-vehicle relay device 101 may also be configured to transmit information regarding the software configuration of the vehicle 1 to the resource management server 170 as resource-related information.
[0313] Furthermore, while the communication system 501 according to the embodiment of this disclosure is configured such that the resource management server 170 performs authentication processing C1 for service execution requests, it is not limited to this configuration. The resource management server 170 may be configured not to perform authentication processing C1.
[0314] Furthermore, while the communication system 501 according to the embodiment of this disclosure is configured such that the resource management server 170 performs authentication processing C2 for resource R release requests, it is not limited to this configuration. The resource management server 170 may be configured not to perform authentication processing C2.
[0315] Furthermore, although the communication system 501 according to the embodiment of this disclosure is described as having separate devices for the resource management server 170 and the edge server 180, it is not limited to this. The edge server 180 may be included in the resource management server 170.
[0316] Furthermore, some or all of the functions of the resource management server 170 according to the embodiment of this disclosure may be provided by cloud computing. That is, the resource management server 170 according to the embodiment of this disclosure may be a cloud server composed of multiple servers.
[0317] Furthermore, some or all of the functions of the edge server 180 according to the embodiment of this disclosure may be provided by cloud computing. That is, the edge server 180 according to the embodiment of this disclosure may be a cloud server composed of multiple servers.
[0318] [Modification] In the communication system 501 according to the embodiment of the present disclosure, the resource management server 170 is configured to send non-execution information to the in-vehicle relay device 101 indicating that the edge server 180 does not need to execute service S if the hardware configuration Hw2 satisfies the hardware configuration Hw1, but the system is not limited to this. The resource management server 170 may also be configured to check whether the software used to execute service S is incorporated into the in-vehicle device 202 corresponding to service S if the hardware configuration Hw2 satisfies the hardware configuration Hw1.
[0319] Referring again to Figure 3, in the modified example, in the in-vehicle relay device 101, the storage unit 13 stores device information indicating the type of application, which is software installed on each in-vehicle device 202.
[0320] When the service management unit 21 receives service information from the relay unit 11, it sends the execution request information, which includes the execution request for service S, authentication information B1, and resource-related information, as well as device information stored in the storage unit 13, to the resource management server 170 via the relay unit 11 and the TCU 202A.
[0321] Referring again to Figure 4, in this modified example, the resource management server 170 transmits download information to the in-vehicle relay device 101 indicating the download source of the software used to execute service S and which is incorporated into the in-vehicle device 202.
[0322] For example, in the resource management server 170, if the authentication process C1 of the service execution request C1 is successful, the authentication success information Q1 is output to the resource allocation unit 34 via the communication unit 31, including the vehicle ID, resource-related information, and equipment information contained in the execution request information received from the in-vehicle relay device 101.
[0323] When the resource allocation unit 34 receives authentication success information Q1 from the authentication unit 33, it obtains service information from the storage unit 36 that indicates the same vehicle ID as the vehicle ID included in the authentication success information Q1.
[0324] The resource allocation unit 34 checks whether the application necessary to execute the service S is installed on the in-vehicle device 202 if the hardware configuration Hw2 indicated by the resource-related information included in the authentication success information Q1 received from the authentication unit 33 satisfies the hardware configuration Hw1 corresponding to the service S indicated by the service information obtained from the storage unit 36.
[0325] For example, the storage unit 36 stores application information for each service S, indicating the type of application required to execute that service S.
[0326] If the hardware configuration Hw2 satisfies the hardware configuration Hw1, the resource allocation unit 34 refers to the application corresponding to the service S indicated by the acquired service information by the storage unit 36 (hereinafter also referred to as "application Ap").
[0327] The resource allocation unit 34 then checks whether the application Ap is registered in the device information included in the authentication success information Q1 received from the authentication unit 33.
[0328] If application Ap is registered in the device information, the resource allocation unit 34 transmits non-executable information to the in-vehicle relay device 101 via the communication unit 31 and TCU 202A. In this case, the resource allocation unit 34 may be configured not to transmit non-executable information to the in-vehicle relay device 101.
[0329] On the other hand, if the application Ap is not registered in the device information, the resource allocation unit 34 transmits download information to the in-vehicle relay device 101 via the communication unit 31 and TCU 202A.
[0330] Specifically, for example, the resource allocation unit 34 transmits to the in-vehicle relay device 101 as download information, which includes a URL (Uniform Resource Locator) indicating the download source of application Ap, the ID of the in-vehicle device 202 from which application Ap should be downloaded (hereinafter also referred to as "device ID"), and the vehicle ID included in the authentication success information Q1 received from the authentication unit 33.
[0331] Referring again to Figure 2, when the in-vehicle relay device 101 receives download information from the resource management server 170 via the TCU 202A, it transmits URL information indicating the URL included in the received download information to the in-vehicle device 202 with the device ID included in the download information.
[0332] When the in-vehicle device 202 receives URL information from the in-vehicle relay device 101, it accesses the URL indicated by the received URL information via the TCU 202A and the external network 151 to download the application Ap.
[0333] The embodiments described above should be considered in all respects to be illustrative and not restrictive. The scope of the present invention is indicated by the claims rather than the above description, and all modifications within the meaning and scope of the claims are intended to be included.
[0334] Each process (each function) in the above-described embodiment is implemented by a processing circuit including one or more processors. The processing circuit may consist of an integrated circuit, etc., which combines one or more memories, various analog circuits, and various digital circuits in addition to the one or more processors. The one or more memories store programs (instructions) that cause the one or more processors to execute each of the above processes. The one or more processors may execute each of the above processes according to the programs read from the one or more memories, or they may execute each of the above processes according to logic circuits that have been designed in advance to execute each of the above processes. The above-mentioned processor may be various processors suitable for computer control, such as a CPU (Central Processing Unit), GPU (Graphics Processing Unit), DSP (Digital Signal Processor), FPGA (Field Programmable Gate Array), and ASIC (Application Specific Integrated Circuit). Furthermore, multiple physically separated processors may cooperate with each other to perform the above-mentioned processes. For example, processors installed in multiple physically separated computers may cooperate with each other via a network such as a LAN (Local Area Network), WAN (Wide Area Network), and the Internet to perform the above-mentioned processes. The above program may be installed on the above memory via the above network from an external server device, or it may be distributed on a recording medium such as a CD-ROM (Compact Disc Read Only Memory), DVD-ROM (Digital Versatile Disc Read Only Memory), or semiconductor memory, and then installed on the above memory from the above recording medium.
[0335] The above description includes the following features: [Addendum 1] A service management method in a communication system comprising an in-vehicle device mounted on a vehicle and a management device, the service management method comprising: the steps of: the in-vehicle device transmitting a service execution request relating to the vehicle to the management device; the management device allocating resources to be used to execute the service based on the execution request received from the in-vehicle device; the management device executing the service using the allocated resources; the management device transmitting the service execution result to the in-vehicle device; the in-vehicle device controlling the in-vehicle equipment of the vehicle using the execution result received from the management device; the in-vehicle device transmitting a resource release request to the management device; and the management device receiving the release request from the in-vehicle device and releasing the resources.
[0336] [Note 2] A service management method for an in-vehicle device installed in a vehicle, comprising: sending a service execution request relating to the vehicle to a management device; receiving the service execution result from the management device; controlling the in-vehicle equipment of the vehicle using the received execution result; and sending a request to the management device to release resources used to execute the service.
[0337] [Note 3] A resource management method for a management device that communicates with an in-vehicle device installed in a vehicle, comprising: receiving a request to execute a service relating to the vehicle from the in-vehicle device; allocating resources to be used to execute the service based on the received execution request; executing the service using the allocated resources and transmitting the execution result of the service to the in-vehicle device; receiving a request to release the resources from the in-vehicle device; and receiving the release request and releasing the resources.
[0338] [Note 4] An in-vehicle device mounted on a vehicle, comprising a processing circuit, wherein the processing circuit transmits a request to a management device to perform a service relating to the vehicle, receives the result of performing the service from the management device, controls the in-vehicle equipment of the vehicle using the received result, and transmits a request to the management device to release resources used to perform the service.
[0339] [Note 5] A management device that communicates with an in-vehicle device mounted on a vehicle, comprising a processing circuit, the processing circuit receiving a request to execute a service relating to the vehicle from the in-vehicle device, allocating resources to be used to execute the service based on the received execution request, executing the service using the allocated resources, transmitting the execution result of the service to the in-vehicle device, receiving a request to release the resources from the in-vehicle device, and releasing the resources upon receiving the release request.
[0340] 1 Vehicle 11 Relay Unit 12 Processing Units 13, 36, 43 Storage Units 21 Service Management Unit 22 Control Units 31, 41 Communication Unit 32 Service Information Creation Unit 33 Authentication Unit 34 Resource Allocation Unit 35 Resource Release Unit 42 Service Execution Units 51, 51A, 51B CAN Bus 101 In-vehicle Relay Device 151 External Network 161 Wireless Base Station Device 170 Resource Management Server 180, 180A, 180B, 180C Edge Server 202, 202A, 202B, 202C, 202D In-vehicle Equipment 301 In-vehicle System 501 Communication System
Claims
1. A communication system comprising an in-vehicle device mounted on a vehicle and a management device, wherein the in-vehicle device transmits a request to the management device to perform a service relating to the vehicle; the management device allocates resources to perform the service based on the request received from the in-vehicle device; the management device performs the service using the allocated resources; the management device transmits the result of the service to the in-vehicle device; the in-vehicle device controls the in-vehicle equipment of the vehicle using the result received from the management device; the in-vehicle device transmits a request to release the resources to the management device; and the management device receives the release request from the in-vehicle device and releases the resources.
2. The communication system according to claim 1, wherein the management device transmits information regarding the services that can be executed by the management device to the in-vehicle device.
3. The communication system according to claim 1 or 2, wherein the management device transmits information to the in-vehicle device indicating whether or not the service can be performed.
4. The communication system according to any one of claims 1 to 3, wherein the management device transmits to the in-vehicle device information indicating the download source of the software used to perform the service, the software which is incorporated into the in-vehicle device.
5. The communication system according to any one of claims 1 to 4, wherein the in-vehicle device transmits the vehicle information, which indicates the status of the vehicle and is used to generate control information for controlling the in-vehicle equipment, which is the execution result, to the management device, and the management device generates the control information using the vehicle information received from the in-vehicle device.
6. The communication system according to claim 5, wherein the in-vehicle device transmits at least one of the vehicle's location information and vehicle speed information to the management device as vehicle information when the service is a service relating to the autonomous driving of the vehicle or a service relating to the avoidance of obstacles while the vehicle is in motion.
7. The communication system according to claim 5, wherein, if the service is a service for unlocking the doors of the vehicle, the in-vehicle device transmits at least one of the following to the management device as vehicle information: location information of the vehicle, information indicating the power status of the vehicle, and information indicating the open / closed state of the doors.
8. The communication system according to any one of claims 1 to 7, wherein the in-vehicle device transmits resource-related information, which is used for the allocation of the resources by the management device and indicates the hardware configuration of the vehicle, to the management device, and the management device uses the resource-related information received from the in-vehicle device to allocate the resources.
9. The communication system according to claim 8, wherein if the hardware configuration indicated by the resource-related information is insufficient for the hardware configuration required to perform the service, the management device obtains data corresponding to the insufficient hardware configuration from equipment outside the vehicle and transmits the obtained data to the in-vehicle device.
10. The communication system according to any one of claims 1 to 9, wherein the management device performs authentication processing of the execution request.
11. The communication system according to any one of claims 1 to 10, wherein the management device includes a first device that has the resources and uses the resources to perform the service, and a second device that allocates the resources, the first device transmits the execution result of the service to the in-vehicle device.
12. The communication system according to any one of claims 1 to 11, wherein the management device performs authentication processing of the release request.
13. An in-vehicle device mounted on a vehicle, comprising: a transmitting unit that transmits a request to a management device for the execution of a service relating to the vehicle; a receiving unit that receives the result of the execution of the service from the management device; and a control unit that controls the in-vehicle equipment of the vehicle using the result of the execution received by the receiving unit, wherein the transmitting unit transmits a request to the management device for the release of resources used to execute the service.
14. A management device for communicating with an in-vehicle device mounted on a vehicle, comprising: a communication unit that receives a request to execute a service relating to the vehicle from the in-vehicle device; a resource allocation unit that allocates resources to execute the service based on the execution request received by the communication unit; and a service execution unit that executes the service using the resources allocated by the resource allocation unit and transmits the execution result of the service to the in-vehicle device, wherein the communication unit receives a request to release the resources from the in-vehicle device, and the management device further comprises a resource release unit that releases the resources when the communication unit receives the release request.
15. A service management program used in an in-vehicle device installed in a vehicle, wherein the program causes a computer to function as: a transmitting unit that transmits a request to a management device for the execution of a service related to the vehicle; a receiving unit that receives the result of the execution of the service from the management device; and a control unit that controls the in-vehicle equipment of the vehicle using the result of the execution received by the receiving unit, the transmitting unit being a service management program that transmits a request to the management device for the release of resources used to execute the service.
16. A resource management program used in a management device that communicates with an in-vehicle device mounted on a vehicle, wherein the program causes a computer to function as: a communication unit that receives a request to execute a service related to the vehicle from the in-vehicle device; a resource allocation unit that allocates resources to execute the service based on the execution request received by the communication unit; and a service execution unit that executes the service using the resources allocated by the resource allocation unit and transmits the execution result of the service to the in-vehicle device, wherein the communication unit receives a request to release the resources from the in-vehicle device, and the computer further functions as: a resource release unit that releases the resources when the communication unit receives the release request.
Citation Information
Patent Citations
Method and system for automated session resources cleanup in distributed client / Server environment
JP2002324047A
System and method for providing services to vehicles
US20200351630A1
System framework for software and hardware configuration determination for vehicle applications with cloud and edge computing
US20240289165A1
Data transmission device, driving assistance device, resource control method, and computer program
WO2024018748A1