Integrated communication system and vehicle-mounted communication system

The integrated communication system addresses resource insufficiencies in vehicles by connecting in-vehicle and external control units via a virtual private network, enabling efficient application migration and reducing communication delays.

WO2026094965A1PCT designated stage Publication Date: 2026-05-07DENSO CORP
View PDF 0 Cites 0 Cited by

Patent Information

Authority / Receiving Office
WO · WO
Patent Type
Applications
Current Assignee / Owner
DENSO CORP
Filing Date
2025-10-29
Publication Date
2026-05-07

AI Technical Summary

Technical Problem

The increasing demand for application execution platforms that can deploy applications across vehicles with different electronic control unit specifications, combined with improved computing and battery performance in vehicles, highlights the potential insufficiency of computing and power resources within vehicles, particularly in power-isolated systems.

Method used

An integrated communication system that connects in-vehicle and external control units via a virtual private network, allowing applications to be moved between these units using a unified communication protocol, thereby optimizing resource utilization and reducing communication delays.

Benefits of technology

The system effectively addresses resource shortages by enabling seamless application migration and communication across vehicles, ensuring consistent operation and reducing delays through a unified communication protocol.

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure JP2025038013_07052026_PF_FP_ABST
    Figure JP2025038013_07052026_PF_FP_ABST
Patent Text Reader

Abstract

An integrated communication system (1) comprises a vehicle-mounted control device (20), an out-of-vehicle control device (10), integrated networks (6, 7), and vehicle-mounted service providing units (85, 86, 201). The integrated networks connect the vehicle-mounted control device and the out-of-vehicle control device via a virtual private network. The vehicle-mounted service providing units are installed in the vehicle-mounted control device to provide services related to the vehicle. The vehicle-mounted control device is provided with vehicle-mounted request units (20, 68, 69, 70, 203, 204). The vehicle-mounted request units receive service usage requests from vehicle-mounted applications installed in the vehicle, and provide services received from the vehicle-mounted service providing units to the vehicle-mounted applications.
Need to check novelty before this filing date? Find Prior Art

Description

Integrated Communication System and In-Vehicle Communication System Cross - Reference to Related Applications

[0001] This international application claims the benefit of Japanese Patent Application No. 2024 - 191920, filed with the Japan Patent Office on October 31, 2024, the entire disclosure of which is incorporated herein by reference.

[0002] The present disclosure relates to an integrated communication system and an in - vehicle communication system that communicate between the inside and outside of a vehicle.

[0003] Patent Document 1 describes a container migration system including a first computer and a second computer capable of constructing a container by container virtualization technology, and migrating the container constructed on the first computer to the second computer.

[0004] Japanese Unexamined Patent Application Publication No. 2017 - 27496

[0005] With the improvement of the communication bandwidth of the wide - area network, it is expected that a physical infrastructure environment will be established where computing resources can be utilized without being aware of communication time and communication delay between the cloud and the vehicle. Also, in the era of SDV (Software - Defined Vehicle), the need for an application execution platform that enables application development without considering vehicle types, such that the same application can be deployed to vehicle models with different specifications of electronic control units, is expected to increase.

[0006] As a result of the inventors' detailed study, while the computing performance of the electronic control units mounted on the vehicle and the performance of the in - vehicle battery are improving, due to the reduction of vehicle costs and the characteristic that the vehicle is a power - isolated system, there is a concern that computing resources and power resources may be insufficient in the vehicle, and this problem has been found.

[0007] The present disclosure suppresses the shortage of computing resources and power resources in the vehicle.

[0008] One aspect of the present disclosure is an integrated communication system including an in - vehicle control device mounted on a vehicle, an out - vehicle control device installed outside the vehicle, an integrated network, and an in - vehicle service providing unit.

[0009] The integrated network connects the in-vehicle control unit and the external control unit via a virtual private network.

[0010] The in-vehicle service provider unit is installed in the in-vehicle control unit and configured to provide services related to the vehicle.

[0011] The in-vehicle control device includes an in-vehicle requirements unit.

[0012] The in-vehicle request unit receives service usage requests from in-vehicle applications installed in the vehicle, transmits a communication frame corresponding to the service usage request to the in-vehicle service provision unit using a predetermined communication protocol that includes the application layer of the OSI reference model, receives the service from the in-vehicle service provision unit using the predetermined communication protocol, and provides the received service to the in-vehicle application.

[0013] The external control device includes an external request unit.

[0014] The external request unit receives service usage requests from external applications installed outside the vehicle, transmits a communication frame corresponding to the service usage request to the in-vehicle service provider unit via an integrated network using a predetermined communication protocol, receives the service from the in-vehicle service provider unit using the predetermined communication protocol, and provides the received service to the external application.

[0015] The integrated communication system of this disclosure, configured in this manner, can provide services from in-vehicle and external applications to a vehicle using an in-vehicle control unit and an external control unit connected to each other by a virtual private network. Therefore, the integrated communication system of this disclosure can move applications installed in the in-vehicle control unit to the external control unit, thereby suppressing shortages of computing and power resources in the vehicle. Furthermore, since the integrated communication system of this disclosure can communicate with in-vehicle and external applications using the same predetermined communication protocol, communication delays can be suppressed, and applications can operate regardless of whether they are installed in the in-vehicle control unit or the external control unit.

[0016] Another aspect of this disclosure is an in-vehicle communication system comprising an in-vehicle control unit, an integrated network, and an in-vehicle service provision unit.

[0017] When the in-vehicle service provider receives a first service request from an in-vehicle application installed in the vehicle using a predetermined communication protocol that includes the application layer of the OSI reference model, it transmits the service corresponding to the first service request to the in-vehicle application using the predetermined communication protocol.

[0018] When the in-vehicle service provider receives a request to use a second service from an external application installed outside the vehicle using a predetermined communication protocol, it transmits the service corresponding to the request to the external application using the predetermined communication protocol.

[0019] The in-vehicle communication system of this disclosure is a system that is included in the integrated communication system of this disclosure, and can achieve the same effects as the integrated communication system of this disclosure.

[0020] This is a block diagram showing the configuration of an integrated communication system. This is a block diagram showing the L2 tunnel section. This is a block diagram showing the configuration of the cloud-based ECU and the in-vehicle ECU of the first embodiment. This is a sequence diagram showing the procedure for the application of the first embodiment to read vehicle information. This is a block diagram showing the configuration of the cloud, vehicle, and application. This is a sequence diagram showing the procedure for installing the application. This is a sequence diagram showing the procedure for uninstalling the application. This is a sequence diagram showing the procedure for dynamically changing the placement of the application. This is a block diagram showing the configuration of the cloud-based ECU and the in-vehicle ECU of the second embodiment. This is a sequence diagram showing the procedure for the application of the second embodiment to read vehicle information. This is a diagram showing the configuration of the central ECU and peripheral ECUs. This is a block diagram showing the configuration of a port-based VLAN.

[0021] [First Embodiment] A first embodiment of the present disclosure will be described below with reference to the drawings.

[0022] As shown in Figure 1, the integrated communication system 1 of this embodiment is configured to enable data communication between multiple vehicles and the cloud via a wide-area wireless communication network (NW).

[0023] The integrated communication system 1 includes a first vehicle LAN 2, a second vehicle LAN 2, ..., and an Nth vehicle LAN 2. N is an integer of 2 or more. LAN stands for Local Area Network.

[0024] The i-th vehicle LAN2 is a LAN constructed for the i-th vehicle and comprises a gateway device 5, a core VLAN 6, a third-party VLAN 7, a cloud-based ECU 10, multiple in-vehicle ECUs 20, and a placement control ECU 30. i is an integer from 1 to N. VLAN stands for Virtual Local Area Network. ECU stands for Electronic Control Unit.

[0025] The cloud-based ECU 10 comprises a core control unit 11 and a third-party control unit 12.

[0026] The core control unit 11 controls the vehicle using an application manufactured by the OEM. OEM stands for Original Equipment Manufacturer. The core control unit 11 includes the core application execution environment 64 of the cloud-based ECU 10, which will be described later.

[0027] The third-party control unit 12 controls the vehicle using an application manufactured by a third party. The third-party control unit 12 includes a third-party application execution environment 65 for the cloud-based ECU 10, which will be described later. The third party is a third party other than the vehicle owner and the OEM. The third-party control unit 12 is isolated from the main control unit 11 by a DMZ. DMZ stands for DeMilitarized Zone.

[0028] The in-vehicle ECU 20 comprises a core control unit 21 and a third-party control unit 22.

[0029] The core control unit 21 controls the vehicle using an application manufactured by the OEM. The core control unit 21 includes a core application execution environment 64 for the in-vehicle ECU 20, which will be described later.

[0030] The third-party control unit 22 controls the vehicle using an application manufactured by a third party. The third-party control unit 22 includes a third-party application execution environment 65 for the in-vehicle ECU 20, which will be described later. The third-party control unit 22 is isolated from the main control unit 21 by a DMZ.

[0031] The placement control ECU 30 includes a load balancing transfer control unit 31, which will be described later.

[0032] The core VLAN 6 connects the core control unit 11 and multiple core control units 21 to enable data communication between them.

[0033] The VLAN 7 for third parties connects the third-party control unit 12, multiple third-party control units 22, and load balancing transfer control unit 31 to enable data communication between them.

[0034] The core VLAN 6 and third-party VLAN 7 are connected to gateway device 5. Gateway device 5 is further connected to other gateway devices 5.

[0035] The gateway device 5 controls data relay so that access from a third-party VLAN 7 of one vehicle to the main VLAN 6 of another vehicle is not possible.

[0036] As shown in Figure 2, the cloud is equipped with an internal cloud network 41, a gateway / virtual private network (hereinafter referred to as VPN) device 42, and a communication device 43. The vehicle is equipped with an ECU network 51, a gateway / VPN device 52, and a communication device 53. VPN stands for Virtual Private Network.

[0037] The cloud internal network 41 is connected to the gateway / VPN device 42, and the gateway / VPN device 42 is connected to the communication device 43.

[0038] The ECU network 51 is connected to the gateway / VPN device 52, and the gateway / VPN device 52 is connected to the communication device 53.

[0039] Communication device 43 and communication device 53 are connected to each other via a wide-area wireless communication network NW, enabling them to communicate data with each other.

[0040] L2 tunneling is performed between the cloud and the vehicle using L2 extension technology, and a VLAN is built at L3. The L2 tunnel section is the communication path between gateway / VPN device 42 and gateway / VPN device 52. IKEv2 / IPsec and L2TP over IPsec are basically used for L2 extension. This enables dedicated L2 lines, encryption of the tunnel section, and entity authentication (gateway authentication).

[0041] The gateway / VPN devices 42 and 52 are equipped with VPN functionality and DHCP server functionality. DHCP stands for Dynamic Host Configuration Protocol.

[0042] As shown in Figure 3, the cloud-based ECU 10 and the in-vehicle ECU 20 include an ECU-based vehicle information database 61, a database processing unit 62, a processing communication unit 63, a core application execution environment 64, a third-party application execution environment 65, an application transfer processing unit 66, a computing resource monitoring unit 67, an API 68, a vehicle information-ECU map 69, a transmission / reception unit 70, an FW / WAF / IPS 71, a virtual switch 72, and a physical NIC 73. API stands for Application Programming Interface. FW stands for Firewall. WAF stands for Web Application Firewall. IPS stands for Intrusion Prevention System. NIC stands for Network Interface Card.

[0043] The ECU's internal vehicle information database 61 stores vehicle information generated or acquired by its own device (i.e., the cloud-based ECU 10 or the in-vehicle ECU 20).

[0044] The database processing unit 62 executes processing for storing vehicle information in the in-ECU vehicle information database 61 and processing for providing the vehicle information stored in the in-ECU vehicle information database 61.

[0045] The processing communication unit 63 includes a vehicle control unit 63a that executes various processes for controlling the vehicle and a vehicle control information communication unit 63b that executes processing for communicating vehicle control information used for controlling the vehicle.

[0046] The core application execution environment 64 includes a plurality of core applications 81 and a plurality of virtual network interfaces 82. The core application 81 is an application manufactured by the OEM. A virtual network interface 82 is connected to the core application 81.

[0047] The third-party application execution environment 65 includes a plurality of third-party applications 83, a plurality of virtual network interfaces 84, a shared database 85, a database processing unit 86, and a virtual network interface 87. The third-party application execution environment 65 is isolated from the core application execution environment 64 by a third-party DMZ.

[0048] The third-party application 83 is an application manufactured by a third party. A virtual network interface 84 is connected to the third-party application 83.

[0049] The shared database 85 stores vehicle information for use by the third-party application 83.

[0050] When the database processing unit 86 receives vehicle information managed on the core side from the database processing unit 62, it executes processing for storing the received vehicle information in the shared database 85. The database processing unit 86 also executes processing for providing the vehicle information stored in the shared database 85. A virtual network interface 87 is connected to the database processing unit 86.

[0051] The application transfer processing unit 66 performs processing to transfer third-party applications 83 between multiple in-vehicle ECUs 20 and between the in-vehicle ECUs 20 and the cloud.

[0052] The computing resource monitoring unit 67 monitors the CPU usage, power consumption, and memory usage of its own device.

[0053] API 68 provides access control for the core application 81 and third-party applications 83 to acquire and provide vehicle information.

[0054] The Vehicle Information-ECU Map 69 links vehicle information to the ECU that holds that information. Since the ECU to which vehicle information belongs differs for each vehicle model number, the Vehicle Information-ECU Map 69 is created for each vehicle model number.

[0055] The transmitting / receiving unit 70 performs the processes of forming TCP / IP frames and HTTP frames, and transmitting and receiving communication frames using the HTTP protocol. TCP / IP is an abbreviation for Transmission Control Protocol / Internet Protocol. HTTP is an abbreviation for Hyper Text Transfer Protocol. The HTTP protocol is the application layer communication protocol of the OSI reference model. OSI is an abbreviation for Open Systems Interconnection.

[0056] FW / WAF / IPS71 is software or hardware for protecting the internal network from unauthorized access. The FW uses a stateful architecture and allows packets originating from the core network (i.e., core VLAN 6) to be sent to and responded to the shared database 85, but does not allow packets originating from the third-party network (i.e., third-party VLAN 7) to pass through.

[0057] The virtual switch 72 performs routing between the core VLAN 6 and the third-party VLAN 7, and performs appropriate route switching to match the VLAN assigned to the packet.

[0058] The physical NIC 73 is a device for connecting its own device to the core VLAN 6 and the third-party VLAN 7. In this embodiment, the physical NIC 73 forms tagged VLANs on the same physical line.

[0059] In this embodiment, the cloud-based ECU 10 and the in-vehicle ECU 20, respectively, filter packets using a stateful inspection firewall and route switching via a virtual switch to prevent access to the core control unit 11 and core control unit 21.

[0060] For example, packet filtering settings are configured as follows:

[0061] Access between the core application 81 and the database processing unit 62 is permitted.

[0062] Access between the processing communication unit 63 and the database processing unit 62 is permitted.

[0063] Access between the processing communication unit 63 and the core application 81 is permitted.

[0064] Access between multiple core applications 81 is permitted.

[0065] Access between the core control units 11 and 21 and the core VLAN 6 is permitted.

[0066] Access between the ECU's vehicle information database 61 and database processing unit 62 and the shared database 85 is permitted.

[0067] Access between the third-party application 83 and the database processing unit 86 is permitted.

[0068] Access between the third-party VLAN 7 and the database processing unit 86 is permitted. In other words, the shared database 85 is made available to other ECUs.

[0069] Access between multiple third-party applications 83 is permitted. However, once network access is granted, access control between applications is performed via API.

[0070] Access between third-party application 83 and third-party VLAN 7 is permitted.

[0071] Access other than that described above is not permitted. Therefore, access from third-party control units 12 and 22 to the main control units 11 and 21 is basically not possible.

[0072] Next, we will explain the procedure by which a third-party application 83 reads vehicle information from a shared database 85 within the same in-vehicle ECU 20.

[0073] As shown in Figure 4, among the multiple in-vehicle ECUs 20, one in-vehicle ECU 20 is designated as the first in-vehicle ECU 20A, and another in-vehicle ECU 20, different from the first in-vehicle ECU 20A, is designated as the second in-vehicle ECU 20B.

[0074] As shown in process P1, the third-party application 83 of the first in-vehicle ECU 20A sends an information request.

[0075] The API 68, vehicle information-ECU map 69, and transmission / reception unit 70 of the first in-vehicle ECU 20A identify the requested vehicle information and the destination of the information request based on the received information request, and create a communication frame corresponding to the received information request. Then, as shown in process P2, the transmission / reception unit 70 sends the created communication frame as a database read request to the database processing unit 86 of the first in-vehicle ECU 20A.

[0076] The database processing unit 86 of the first in-vehicle ECU 20A reads the vehicle information identified by the received base read request from the shared database 85 of the first in-vehicle ECU 20A. As shown in process P3, the database processing unit 86 transmits a database read response containing the read vehicle information to the transmitting / receiving unit 70 of the first in-vehicle ECU 20A.

[0077] When the transmitting / receiving unit 70 of the first in-vehicle ECU 20A receives a database read response, it provides the vehicle information contained in the database read response to the third-party application 83 of the first in-vehicle ECU 20A, as shown in process P4. In order to provide vehicle information to the third-party application 83 of the first in-vehicle ECU 20A in this way, the transmitting / receiving unit 70 manages the correspondence between information requests and the source of the information requests in order to provide vehicle information from the shared database 85 to the third-party application 83 that made the information request among the multiple third-party applications 83.

[0078] Next, we will describe the procedure by which a third-party application 83 reads vehicle information from a shared database 85 in another in-vehicle ECU 20.

[0079] As shown in process P11, the third-party application 83 of the first in-vehicle ECU 20A sends an information request.

[0080] The API 68, vehicle information-ECU map 69, and transmission / reception unit 70 of the first in-vehicle ECU 20A identify the requested vehicle information and the destination of the information request based on the received information request, and create a communication frame corresponding to the received information request. Then, as shown in processing P12, the transmission / reception unit 70 sends the created communication frame as a database read request to the database processing unit 86 of the second in-vehicle ECU 20B.

[0081] The database processing unit 86 of the second in-vehicle ECU 20B reads the vehicle information identified by the received database read request from the shared database 85 of the second in-vehicle ECU 20B. As shown in process P13, the database processing unit 86 transmits a database read response containing the read vehicle information to the transmitting / receiving unit 70 of the first in-vehicle ECU 20A.

[0082] When the transmitting / receiving unit 70 of the first in-vehicle ECU 20A receives a database read response, it provides the vehicle information contained in the database read response to the third-party application 83 of the first in-vehicle ECU 20A, as shown in process P14.

[0083] Alternatively, a third-party application 83 of the cloud-equipped ECU 10 may send an information request to obtain vehicle information from the shared database 85 of the second in-vehicle ECU 20B.

[0084] For example, when a third-party application 83 of the cloud-enabled ECU 10 sends an information request, the API 68, vehicle information-ECU map 69, and transmission / reception unit 70 of the cloud-enabled ECU 10 identify the requested vehicle information and the destination of the information request based on the received information request, and create a communication frame corresponding to the received information request. Then, the transmission / reception unit 70 of the cloud-enabled ECU 10 sends the created communication frame as a database read request to the database processing unit 86 of the second in-vehicle ECU 20B.

[0085] The database processing unit 86 of the second in-vehicle ECU 20B reads the vehicle information identified by the received database read request from the shared database 85 of the second in-vehicle ECU 20B. The database processing unit 86 then sends a database read response containing the read vehicle information to the transmitting / receiving unit 70 of the cloud-equipped ECU 10.

[0086] When the transmitting / receiving unit 70 of the cloud-equipped ECU 10 receives a database read response, it provides the vehicle information contained in the database read response to the third-party application 83 of the cloud-equipped ECU 10.

[0087] As shown in Figure 5, the cloud is equipped with an application store 101 and an application distribution unit 102.

[0088] The application store 101 is a repository of third-party applications and applications developed by OEMs, and has the function of receiving installation and uninstallation instructions from users and sending installation and uninstallation requests to the application distribution unit 102.

[0089] The application distribution unit 102 receives installation and uninstallation requests from the application store 101 and sends installation and uninstallation requests to the vehicle.

[0090] The load balancing transfer control unit 31 of the placement control ECU 30 comprises a transfer control unit 111 and a load balancing management unit 112.

[0091] The transfer control unit 111 receives an installation request from the application distribution unit 102 during the initial application installation and issues application acquisition and installation instructions to the application transfer processing unit 66 of the in-vehicle ECU 20 determined by the load balancing management unit 112. During relocation, the transfer control unit 111 issues application transfer instructions and application acceptance instructions to the source ECU and destination ECU determined by the load balancing management unit 112, respectively. The transfer control unit 111 is located inside the vehicle to enable application relocation within the vehicle even if communication with the cloud is interrupted.

[0092] The load balancing management unit 112 monitors the computing resource data held by the computing resource monitoring unit 67 of each in-vehicle ECU 20 within the vehicle, and performs database creation and statistical processing of the computing resource data. When a destination query is received, the load balancing management unit 112 determines the destination ECU for the application using a certain algorithm based on the computing resource data. The load balancing management unit 112 has a map that matches APIs with communication destination vehicle information and calculates the ECU destination candidate with the optimal communication efficiency from the group of APIs used described in the application manifest stored in the application. The load balancing management unit 112 also considers other factors and calculates whether to prioritize lower-ranking candidates from the computing resource data. The load balancing management unit 112 also manages the deployment locations of applications (i.e., which application is deployed to which ECU). The load balancing management unit 112 may also store external device information indicating the external devices of each ECU. External devices include cameras, G sensors, GPS sensors, and voice microphones. To enable application relocation when communication between the cloud and the vehicle is interrupted, the load balancing management unit 112 may be located on the vehicle side. Alternatively, assuming that the computing environment stabilizes once deployed, the load balancing management unit 112 may be located on the cloud side, so that relocation is only possible when the application is updated or added, i.e., when communication with the cloud is possible.

[0093] The load information used by the load balancing management unit 112 includes, for example, time-series data for each ECU, such as the startup time for each application, CPU time usage, memory usage, and the amount of communication data at the communication destination. It also includes data obtained by statistically processing the time-series data, the frequency of application startup, and the presence or absence of external devices.

[0094] The core application 81 and the third-party application 83 include, for example, an executable file 121, as well as generated data 122, a configuration file 123, and a snapshot 124. In other words, the core application 81 and the third-party application 83 contain information that allows them to be restarted after the transfer, even if they are in the middle of execution.

[0095] The cloud also includes an application transfer processing unit 104 that has the same functionality as the application transfer processing unit 66, and a computing resource monitoring unit 105 that has the same functionality as the computing resource monitoring unit 67.

[0096] Next, we will explain how the load balancing management unit 112 determines the deployment and relocation destinations of applications.

[0097] The load balancing management unit 112 determines the deployment destination and relocation destination by applying the deployment policy settings described later, based on the load information of the ECU and network and the information of the application manifest described later.

[0098] The load balancing management unit 112 optimizes computing resources within the allocation to the third-party control unit 22, based on the allocation of computing resources between the core control unit 21 and the third-party control unit 22, according to the following algorithm. In other words, the load balancing management unit 112 does not allow requests from the third-party control unit 22 to interfere with the computing resources of the core control unit 21, which have been secured in advance by guaranteeing the operation of the core control unit 21.

[0099] The load information used by the load balancing management unit 112 includes the average CPU load of each in-vehicle ECU 20, CPU usage rate for each application, average memory usage rate of each in-vehicle ECU 20, memory usage rate for each application, swap occurrences of each in-vehicle ECU 20, and communication load between ECUs for each application. The above load information may be instantaneous values ​​or time statistics.

[0100] Load information also includes requests from the computing resource monitoring unit 67 of the in-vehicle ECU 20, the mounting and exterior devices of each in-vehicle ECU 20, and communication log information from switches.

[0101] The application manifest declares the types and frequency of APIs referenced, as well as RAM / ROM size requirements. The application manifest is used during application distribution to determine the external devices to be used, whether vehicle control (writing to the vehicle) is required, and the frequency requirements for vehicle information updates (reading).

[0102] The load balancing management unit 112 determines the priority of delivery candidates based on policy settings. The policy settings may be configured by the OEM according to the vehicle model or product line.

[0103] The policy settings may, for example, combine communication efficiency optimization and ECU computing resource optimization, as shown below.

[0104] When distributing an application, the load balancing management unit 112 refers to the API type (reference or update) and frequency information declared in the application manifest.

[0105] The load balancing management unit 112 refers to the application manifest and, if the application refers to the output information of the external device, preferentially assigns the application to the in-vehicle ECU 20 equipped with the external device. This is to reduce the amount of relay communication.

[0106] The load balancing management unit 112 refers to the application manifest and prioritizes placing the application on the in-vehicle ECU 20 closest to the vehicle information it is responsible for among the group of candidate in-vehicle ECUs 20 for distribution. This is to reduce the amount of relay communication.

[0107] The load balancing management unit 112 refers to the application manifest and, when an application performs vehicle control (update), assigns the application to the in-vehicle ECU 20 rather than the cloud. This is to ensure that the system functions even in the event of a communication interruption. Furthermore, because responsiveness to control commands is particularly important, priority is given to assigning the application to the in-vehicle ECU 20 that receives the commands.

[0108] The load balancing management unit 112 prioritizes assigning applications to the in-vehicle ECU 20 rather than the cloud when the vehicle information reference frequency exceeds a certain threshold. This is to ensure functionality even in the event of a communication interruption.

[0109] The load balancing management unit 112 prioritizes assigning applications to the cloud when the application does not perform vehicle control (updates) and the frequency of vehicle information references is below a certain threshold. This is because it works even when communication is interrupted.

[0110] The load balancing management unit 112 refers to the application manifest and, if the application does not perform vehicle control and the RAM / ROM usage is higher than the standard value, preferentially assigns the application to the cloud. However, if the resource usage of the destination ECU is high due to an already deployed application, the load balancing management unit 112 places the application on the ECU with a lower candidate ranking.

[0111] When an application is transferred, the load balancing management unit 112 considers moving an application to the destination in-vehicle ECU 20 if that application is consuming a large portion of the communication bandwidth in a particular ECU section. This is to optimize the amount of relay communication.

[0112] The load balancing management unit 112 considers moving an application to an in-vehicle ECU 20 with a high surplus resource ratio if the ECU where the application is installed does not have sufficient resources (for example, a certain CPU time fraction / number of calculation steps, amount of memory).

[0113] The load balancing management unit 112 considers moving an application to an in-vehicle ECU 20 with a high surplus resource ratio if the application is monopolizing or requesting a large portion of the CPU and memory of a particular ECU.

[0114] When the load balancing management unit 112 receives an installation request for an application that performs vehicle control (update), it considers moving existing applications that do not perform vehicle control to another in-vehicle ECU 20 or to the cloud.

[0115] Next, we will explain the procedure for performing load monitoring.

[0116] As shown in process P21 of Figure 6, the load balancing management unit 112 of the placement control ECU 30 transmits a load information request to the computing resource monitoring unit 67 of the first on-board ECU 20A.

[0117] When the computing resource monitoring unit 67 of the first in-vehicle ECU 20A receives a load information request, it transmits the load information to the load distribution management unit 112 of the placement control ECU 30, as shown in process P22.

[0118] As shown in process P23, the load balancing management unit 112 of the placement control ECU 30 transmits a load information request to the computing resource monitoring unit 67 of the second on-board ECU 20B.

[0119] When the computing resource monitoring unit 67 of the second in-vehicle ECU 20B receives a load information request, it transmits the load information to the load distribution management unit 112 of the placement control ECU 30, as shown in process P24.

[0120] As shown in processing P25, the load balancing management unit 112 of the placement control ECU 30 performs database creation of load information and statistical processing of computing resource data based on the received load information.

[0121] Next, we will explain the procedure for installing the application.

[0122] When the cloud application store 101 receives an installation instruction from a user, for example, it sends an installation request to the cloud application distribution unit 102, as shown in process P31.

[0123] When the application distribution unit 102 receives an installation request from the application store 101, it sends the installation request to the transfer control unit 111 of the placement control ECU 30, as shown in process P32.

[0124] When the transfer control unit 111 of the placement control ECU 30 receives an installation request from the application distribution unit 102, it queries the load balancing management unit 112 of the placement control ECU 30 for the distribution destination of the application that is the subject of the installation request, as shown in process P33.

[0125] As shown in process P34, the load balancing management unit 112 of the placement control ECU 30 determines the distribution destination of the application targeted for installation in response to an inquiry from the transfer control unit 111. In Figure 6, the distribution destination is the second in-vehicle ECU 20B.

[0126] As shown in process P35, the load balancing management unit 112 transmits destination information indicating the determined destination to the transfer control unit 111.

[0127] When the transfer control unit 111 receives destination information, it sends an application distribution and installation instruction to the application distribution unit 102 in the cloud and the application transfer processing unit 66 of the second in-vehicle ECU 20B, as shown in processes P36 and P37, instructing them to distribute and install the application to the destination.

[0128] When the application transfer processing unit 66 of the second in-vehicle ECU 20B receives an application distribution and installation instruction, it determines whether or not the application can be installed, as shown in process P38. Here, it is assumed that the application transfer processing unit 66 of the second in-vehicle ECU 20B has determined that the application can be installed.

[0129] The application transfer processing unit 66 of the second in-vehicle ECU 20B, having determined that application installation is possible, sends a standby notification to the transfer control unit 111 of the placement control ECU 30 and the application distribution unit 102 of the cloud, as shown in processes P39 and P40.

[0130] Then, the application transfer processing unit 66 of the second in-vehicle ECU 20B waits until the application is delivered, as shown in process P41.

[0131] Upon receiving the standby notification, the application distribution unit 102 distributes the application to the application transfer processing unit 66 of the second in-vehicle ECU 20B, as shown in process P42.

[0132] When an application is delivered, the application transfer processing unit 66 of the second in-vehicle ECU 20B executes an installation process to install the delivered application, as shown in process P43, and after the installation process is completed, it starts the installed application.

[0133] Then, as shown in processes P44 and P45, the application transfer processing unit 66 of the second in-vehicle ECU 20B sends an installation completion notification to the transfer control unit 111 of the placement control ECU 30 and the application distribution unit 102 of the cloud.

[0134] Upon receiving the installation completion notification, the application distribution unit 102 sends the installation completion notification to the application store 101, as shown in process P46.

[0135] Upon receiving the installation completion notification, the transfer control unit 111 of the placement control ECU 30 transmits the installation completion notification to the load balancing management unit 112, as shown in process P46.

[0136] Upon receiving the installation completion notification, the load balancing management unit 112 registers the location of the application corresponding to the installation completion notification (i.e., the second in-vehicle ECU 20B), as shown in process P48.

[0137] Next, we will explain the procedure for uninstalling the application.

[0138] When the cloud application store 101 receives an uninstallation instruction from a user, for example, it sends an uninstallation request to the cloud application distribution unit 102, as shown in process P51 of Figure 7.

[0139] When the application distribution unit 102 receives an uninstall request from the application store 101, it sends the uninstall request to the transfer control unit 111 of the placement control ECU 30, as shown in process P52.

[0140] When the transfer control unit 111 of the placement control ECU 30 receives an uninstall request from the application distribution unit 102, it queries the load balancing management unit 112 of the placement control ECU 30 for the placement location of the application to be uninstalled, as shown in process P53.

[0141] As shown in process P54, the load balancing management unit 112 of the placement control ECU 30 confirms the placement location of the application subject to the uninstallation request in response to an inquiry from the transfer control unit 111. In Figure 7, the placement location is the second on-board ECU 20B.

[0142] As shown in process P55, the load balancing management unit 112 transmits the confirmed placement location information to the transfer control unit 111.

[0143] When the transfer control unit 111 receives the placement location information, it sends an uninstallation instruction to the application transfer processing unit 66 of the second in-vehicle ECU 20B, instructing it to uninstall the application, as shown in process P56.

[0144] When the application transfer processing unit 66 of the second in-vehicle ECU 20B receives an uninstallation instruction, it determines whether or not the application targeted by the uninstallation instruction can be uninstalled, as shown in process P57. Here, it is assumed that the application transfer processing unit 66 of the second in-vehicle ECU 20B has determined that the application can be uninstalled.

[0145] The application transfer processing unit 66 of the second in-vehicle ECU 20B, having determined that it is possible to uninstall the application, executes the process of uninstalling the application, as shown in process P58.

[0146] When the application uninstallation is complete, the application transfer processing unit 66 of the second in-vehicle ECU 20B sends an uninstallation completion notification to the transfer control unit 111 of the placement control ECU 30, as shown in process P59.

[0147] Upon receiving the uninstallation completion notification, the transfer control unit 111 of the placement control ECU 30 transmits the uninstallation completion notification to the load balancing management unit 112, as shown in process P60.

[0148] Upon receiving the uninstallation completion notification, the load balancing management unit 112 registers the uninstalled application for deletion, as shown in process P61.

[0149] Furthermore, the transfer control unit 111 of the placement control ECU 30 sends an uninstallation completion notification to the cloud application distribution unit 102, as shown in process P62.

[0150] Upon receiving the uninstallation completion notification, the application distribution unit 102 sends the uninstallation completion notification to the application store 101, as shown in process P63.

[0151] Next, we will explain the procedure for determining the placement location of the third-party application 83.

[0152] As shown in process P71 of Figure 8, the load balancing management unit 112 of the placement control ECU 30 transmits a load information request to the computing resource monitoring unit 67 of the first on-board ECU 20A.

[0153] When the computing resource monitoring unit 67 of the first in-vehicle ECU 20A receives a load information request, it transmits the load information to the load distribution management unit 112 of the placement control ECU 30, as shown in process P72.

[0154] As shown in process P73, the load balancing management unit 112 of the placement control ECU 30 transmits a load information request to the computing resource monitoring unit 67 of the second on-board ECU 20B.

[0155] When the computing resource monitoring unit 67 of the second in-vehicle ECU 20B receives a load information request, it transmits the load information to the load distribution management unit 112 of the placement control ECU 30, as shown in process P74.

[0156] As shown in process P75, the load balancing management unit 112 of the placement control ECU 30 re-determines the placement position of the application based on the received load information. In Figure 8, it is assumed that, as a result of the re-determining of the placement position, a decision was made to move the application placed on the first in-vehicle ECU 20A to the second in-vehicle ECU 20B.

[0157] Next, we will describe the procedure for dynamically changing the deployment of the third-party application 83.

[0158] The load balancing management unit 112 of the placement control ECU 30, upon re-determining the placement location, sends an application placement change instruction to the transfer control unit 111 of the placement control ECU 30, as shown in process P81. The trigger for the application placement change instruction may be set by the load balancing management unit 112, or by an administrator via the cloud side.

[0159] When the transfer control unit 111 of the placement control ECU 30 receives an application placement change instruction from the application distribution unit 102, it sends an application transfer request to the application transfer processing units 66 of the first in-vehicle ECU 20A and the second in-vehicle ECU 20B, as shown in processes P82 and P83.

[0160] When the application transfer processing unit 66 of the first in-vehicle ECU 20A receives an application transfer request, it determines whether or not the application subject to the application placement change instruction can be transferred, as shown in process P84. Here, it is assumed that the application transfer processing unit 66 of the first in-vehicle ECU 20A has determined that the application can be transferred.

[0161] When the application transfer processing unit 66 of the second in-vehicle ECU 20B receives an application transfer request, it determines whether or not it is possible to install the application that is the target of the application placement change instruction, as shown in processing P85. Here, it is assumed that the application transfer processing unit 66 of the second in-vehicle ECU 20B has determined that it is possible to install the application.

[0162] As shown in process P86, the application transfer processing unit 66 of the first in-vehicle ECU 20A transmits an acknowledgment to the transfer control unit 111 of the placement control ECU 30 indicating that the application can be transferred.

[0163] As shown in process P87, the application transfer processing unit 66 of the second in-vehicle ECU 20B transmits an acknowledgment to the transfer control unit 111 of the placement control ECU 30 indicating that the application can be installed.

[0164] When the transfer control unit 111 of the placement control ECU 30 receives acknowledgments from the first in-vehicle ECU 20A and the second in-vehicle ECU 20B, it sends a transfer start instruction to the application transfer processing unit 66 of the first in-vehicle ECU 20A and the second in-vehicle ECU 20B, as shown in processing P88 and P89.

[0165] When the application transfer processing unit 66 of the first in-vehicle ECU 20A receives a transfer start instruction, it executes a process to stop the application to be transferred, as shown in process P90.

[0166] When the application transfer processing unit 66 of the second in-vehicle ECU 20B receives a transfer start instruction, it waits until the application is transferred, as shown in process P91.

[0167] Once the application stopping process is complete, the application transfer processing unit 66 of the first in-vehicle ECU 20A transfers the stopped application to the application transfer processing unit 66 of the second in-vehicle ECU 20B, as shown in process P92.

[0168] When an application is transferred, the application transfer processing unit 66 of the second in-vehicle ECU 20B transmits an acknowledgment that the application has been transferred to the application transfer processing unit 66 of the first in-vehicle ECU 20A and the transfer control unit 111 of the placement control ECU 30, as shown in processes P93 and P94.

[0169] When the application transfer processing unit 66 of the second in-vehicle ECU 20B receives an acknowledgment, it executes an installation process to install the transferred application, as shown in process P95, and after the installation process is completed, it starts the installed application.

[0170] When the application transfer processing unit 66 of the first in-vehicle ECU 20A receives an acknowledgment from the application transfer processing unit 66 of the second in-vehicle ECU 20B, it transmits an acknowledgment indicating that the transfer was successful to the transfer control unit 111 of the placement control ECU 30, as shown in process P96.

[0171] The application transfer processing unit 66 of the first in-vehicle ECU 20A deletes the transferred application after sending an acknowledgment, as shown in processing P97.

[0172] After deleting the application, the application transfer processing unit 66 of the first in-vehicle ECU 20A sends an acknowledgment to the transfer control unit 111 of the placement control ECU 30, indicating that the deletion was successful, as shown in process P98.

[0173] The application transfer processing unit 66 of the second in-vehicle ECU 20B, after starting the installed application, sends an acknowledgment to the transfer control unit 111 of the placement control ECU 30 indicating that the application has been successfully restarted, as shown in process P99.

[0174] The integrated communication system 1 configured in this way includes an in-vehicle ECU 20 mounted on the vehicle, a cloud-based ECU 10 installed outside the vehicle, a core VLAN 6 and a third-party VLAN 7, a shared database 85 and a database processing unit 86.

[0175] VLAN 6 for the core system and VLAN 7 for third parties connect the in-vehicle ECU 20 and the cloud-based ECU 10 via a virtual private network.

[0176] The shared database 85 and the database processing unit 86 are mounted on the in-vehicle ECU 20 and configured to provide vehicle information. Hereinafter, the shared database 85 and the database processing unit 86 will be collectively referred to as the in-vehicle service provision unit.

[0177] The in-vehicle ECU 20 includes an API 68, a vehicle information-ECU map 69, and a transmitting / receiving unit 70. Hereinafter, the API 68, vehicle information-ECU map 69, and transmitting / receiving unit 70 of the in-vehicle ECU 20 will be collectively referred to as the in-vehicle request unit.

[0178] The in-vehicle request unit receives information requests from third-party applications 83 (hereinafter referred to as in-vehicle applications) installed in the vehicle, transmits a communication frame corresponding to the information request to the in-vehicle service provider unit using the HTTP protocol of the application layer of the OSI reference model, receives vehicle information from the in-vehicle service provider unit using the HTTP protocol, and provides the received vehicle information to the in-vehicle application.

[0179] The cloud-enabled ECU 10 includes an API 68, a vehicle information-ECU map 69, and a transmitting / receiving unit 70. Hereinafter, the API 68, vehicle information-ECU map 69, and transmitting / receiving unit 70 of the cloud-enabled ECU 10 will be collectively referred to as the external request unit.

[0180] The external request unit receives information requests from third-party applications 83 (hereinafter referred to as "external applications") installed outside the vehicle, transmits a communication frame corresponding to the information request to the in-vehicle service provider unit via the HTTP protocol using a VLAN 7 for third parties, receives vehicle information from the in-vehicle service provider unit via the HTTP protocol, and provides the received vehicle information to the external applications.

[0181] Such an integrated communication system 1 can provide services to the vehicle from in-vehicle applications and external applications using an in-vehicle ECU 20 and a cloud-based ECU 10 that are interconnected by a virtual private network. Therefore, the integrated communication system 1 can move applications installed on the in-vehicle ECU 20 to the cloud-based ECU 10, thereby preventing shortages of computing and power resources in the vehicle. Furthermore, since the integrated communication system 1 can communicate with in-vehicle applications and external applications using the same HTTP protocol, communication delays can be suppressed, and applications can operate regardless of whether they are installed on the in-vehicle ECU 20 or the cloud-based ECU 10.

[0182] Furthermore, the cloud-enabled ECU 10 includes a third-party application execution environment 65 capable of running multiple third-party applications 83.

[0183] The in-vehicle ECU 20 includes a third-party application execution environment 65 capable of running multiple third-party applications 83.

[0184] The transmitting and receiving units 70 of the cloud-equipped ECU 10 and the in-vehicle ECU 20 manage the correspondence between information requests and the source of the information requests in order to provide vehicle information from the shared database 85 to the third-party application 83 that made the information request, among a plurality of third-party applications 83.

[0185] Furthermore, the API 68, vehicle information-ECU map 69, and transmission / reception unit 70 are provided in each of the multiple in-vehicle ECUs 20 installed in the vehicle.

[0186] Furthermore, multiple in-vehicle applications, multiple external applications, an in-vehicle request unit, and an external request unit are connected to a third-party VLAN 7 that spans the inside and outside of the vehicle, and are isolated from each other so as not to be accessible to the core control unit 21, which is mounted on the vehicle and configured to control the vehicle's operation.

[0187] The in-vehicle service provision unit can provide services based on information provided by the core control unit 21 to multiple in-vehicle applications and multiple external applications connected to the third-party VLAN 7, and is accessible from the third-party VLAN 7 and the core control unit 21.

[0188] Such an integrated communication system 1 can isolate third-party applications 83 from the core control unit 21, which is responsible for controlling the vehicle's movement.

[0189] Furthermore, multiple in-vehicle applications, multiple external applications, an in-vehicle request unit, and an external request unit are connected to a third-party VLAN 7. In addition, a core control unit 11 and a core control unit 21, which are mounted outside the vehicle and configured to control the vehicle's operation, are connected to a core VLAN 6, which spans between the inside and outside of the vehicle and is a different VLAN from the third-party VLAN 7. Such an integrated communication system 1 can isolate third-party applications 83 from the core control units 11 and 21, which are responsible for controlling the vehicle's operation.

[0190] Furthermore, for each of the multiple vehicles from the first to the Nth, a third-party VLAN 7 is established that spans the inside and outside of the vehicle, and is isolated from the core control unit 11 and core control unit 21 so that they cannot access each other. The third-party VLAN 7 of the first vehicle is also isolated from the core control unit 11 and core control unit 21 of the second to the Nth vehicles so that they cannot access each other. Such an integrated communication system 1 can isolate third-party applications 83 of other vehicles from the core control unit 11 and core control unit 21, which are responsible for controlling the driving of the vehicles.

[0191] The integrated communication system 1 also includes a deployment control ECU 30 configured to control the deployment of applications. The deployment control ECU 30 prioritizes deploying the target application 83 (hereinafter referred to as the target application) to the application execution environment closest to the source of information used in the processing performed by the target application 83, and / or to the destination of information transmitted from the target application, among the third-party application execution environment 65 in the cloud and the third-party application execution environments 65 of the multiple in-vehicle ECUs 20. Such an integrated communication system 1 can reduce the time required for applications to communicate information.

[0192] Furthermore, the deployment control ECU 30 identifies an application execution environment where the target application can be deployed (hereinafter referred to as the "application-deployable environment") based on the resource usage status of each application execution environment, including the third-party application execution environment 65 in the cloud and the third-party application execution environments 65 of the multiple in-vehicle ECUs 20, and deploys the target application to the identified application-deployable environment. Such an integrated communication system 1 can suppress situations in which the target application cannot be executed due to insufficient resources.

[0193] Furthermore, the deployment control ECU 30 identifies an application deployment environment based on the resource usage status of each application execution environment, including the cloud's third-party application execution environment 65 and the third-party application execution environments 65 of the multiple in-vehicle ECUs 20. From the identified application deployment environments, the ECU 30 moves the target application to an application execution environment closer to the source of information used in the processing performed by the target application, and / or closer to the destination of information transmitted from the target application, compared to the application execution environment where the target application is currently deployed. Such an integrated communication system 1 can suppress situations where the target application cannot be executed due to insufficient resources.

[0194] In the embodiments described above, the in-vehicle ECU 20 corresponds to an in-vehicle control device, the cloud-based ECU 10 corresponds to an external control device, the core VLAN 6 and third-party VLAN 7 correspond to an integrated network, and the in-vehicle ECU 20, core VLAN 6, and third-party VLAN 7 correspond to an in-vehicle communication system.

[0195] Furthermore, an information request corresponds to a service usage request, the HTTP protocol corresponds to a specified communication protocol, and vehicle information corresponds to a service.

[0196] Furthermore, the third-party application execution environment 65 of the in-vehicle ECU 20 corresponds to the in-vehicle application execution environment, the third-party application execution environment 65 of the cloud-equipped ECU 10 corresponds to the external application execution environment, and the core control unit 21 corresponds to the in-vehicle core control unit.

[0197] Furthermore, gateway / VPN device 52 corresponds to an in-vehicle gateway device, gateway / VPN device 42 corresponds to an external gateway device, third-party VLAN 7 corresponds to the first VLAN, core control unit 11 corresponds to an external core control unit, and core VLAN 6 corresponds to the second VLAN.

[0198] Furthermore, the placement control ECU 30 corresponds to the placement control unit, information requests transmitted from the in-vehicle application correspond to the first service usage request, and information requests transmitted from the external application correspond to the second service usage request.

[0199] [Second Embodiment] A second embodiment of the present disclosure will be described below with reference to the drawings. In the second embodiment, the parts that differ from the first embodiment will be described. Common components will be denoted by the same reference numerals.

[0200] The integrated communication system 1 of the second embodiment differs from the first embodiment in that the configurations of the cloud-based ECU 10 and the in-vehicle ECU 20 have been changed.

[0201] As shown in Figure 9, the cloud-based ECU 10 and in-vehicle ECU 20 of the second embodiment differ from the first embodiment in that they are equipped with a SOME / IP server 201 and a virtual network interface 202 instead of a shared database 85 and a database processing unit 86. SOME / IP is an abbreviation for Scalable service-Oriented Middleware over IP.

[0202] The cloud-based ECU 10 and in-vehicle ECU 20 of the second embodiment differ from the first embodiment in that they are equipped with a SOME / IP client 203 and a transceiver 204 instead of a vehicle information-ECU map 69 and a transceiver 70.

[0203] The cloud-based ECU 10 and in-vehicle ECU 20 of the second embodiment differ from those of the first embodiment in that they include a SOME / IP server management unit 205.

[0204] The SOME / IP server 201 communicates with the SOME / IP client 203 in accordance with the SOME / IP protocol and provides various services to the SOME / IP client 203. A virtual network interface 202 is connected to the SOME / IP server 201. The SOME / IP server 201 is isolated from the core application execution environment 64 by a third-party DMZ.

[0205] The SOME / IP client 203, in response to an information request received from the third-party application 83, communicates with the SOME / IP server 201 in accordance with the SOME / IP protocol, accesses the SOME / IP server 201, obtains vehicle information from the SOME / IP server 201, and provides it to the third-party application 83. The SOME / IP protocol is a communication protocol that includes the application layer of the OSI reference model.

[0206] The transmitting / receiving unit 204 performs the process of forming a communication frame according to the SOME / IP protocol and the process of sending and receiving the communication frame using the SOME / IP protocol.

[0207] The SOME / IP server management unit 205 converts the information stored in the ECU's vehicle information database 61 into service information provided by the SOME / IP server 201 and registers it with the SOME / IP server 201.

[0208] In the second embodiment, for example, packet filtering settings are configured as follows.

[0209] Access between the SOME / IP server management unit 205 and the SOME / IP server 201 is permitted.

[0210] Access between the core application 81 and the database processing unit 62 is permitted.

[0211] Access between the processing communication unit 63 and the database processing unit 62 is permitted.

[0212] Access between the processing communication unit 63 and the core application 81 is permitted.

[0213] Access between multiple core applications 81 is permitted.

[0214] Access between the third-party application 83 and the SOME / IP server 201 is permitted.

[0215] Access between the third-party VLAN 7 and SOME / IP server 201 is permitted.

[0216] Access other than that described above is not permitted. Therefore, access from third-party control units 12 and 22 to the main control units 11 and 21 is basically not possible.

[0217] Next, we will explain the procedure for registering updated vehicle information.

[0218] When vehicle information stored in the ECU's vehicle information database 61 is updated, the SOME / IP server management unit 205 of the first in-vehicle ECU 20A registers the updated vehicle information with the SOME / IP server 201 of the first in-vehicle ECU 20A, as shown in process P101 of Figure 10.

[0219] When vehicle information is updated, the SOME / IP server 201 of the first in-vehicle ECU 20A sends an acknowledgment to the SOME / IP server management unit 205 of the first in-vehicle ECU 20A indicating that the vehicle information has been updated, as shown in process P102.

[0220] Next, we will explain the procedure by which the third-party application 83 reads vehicle information from the SOME / IP server 201.

[0221] As shown in process P111, the third-party application 83 sends an information request requesting to obtain vehicle information from the second in-vehicle ECU 20B.

[0222] As shown in processing P112, the API 68, SOME / IP client 203, and transceiver 70 of the first in-vehicle ECU 20A communicate with the SOME / IP server 201 of the second in-vehicle ECU 20B in accordance with the SOME / IP protocol in response to an information request, thereby accessing the SOME / IP server 201 of the second in-vehicle ECU 20B and obtaining vehicle information from the SOME / IP server 201 of the second in-vehicle ECU 20B.

[0223] The integrated communication system 1 configured in this way includes an in-vehicle ECU 20 mounted on the vehicle, a cloud-based ECU 10 installed outside the vehicle, a core VLAN 6 and a third-party VLAN 7, and a SOME / IP server 201.

[0224] VLAN 6 for the core system and VLAN 7 for third parties connect the in-vehicle ECU 20 and the cloud-based ECU 10 via a virtual private network.

[0225] The SOME / IP server 201 is installed in the in-vehicle ECU 20 and configured to provide vehicle information. Hereinafter, the SOME / IP server 201 will be referred to as the in-vehicle service provider unit.

[0226] The in-vehicle ECU 20 includes a SOME / IP client 203 and a transceiver unit 204. Hereinafter, the SOME / IP client 203 and the transceiver unit 204 of the in-vehicle ECU 20 will be collectively referred to as the in-vehicle request unit.

[0227] The in-vehicle request unit receives information requests from third-party applications 83 (hereinafter referred to as in-vehicle applications) installed in the vehicle, transmits a communication frame corresponding to the information request to the in-vehicle service provision unit using the SOME / IP protocol which includes the application layer of the OSI reference model, receives vehicle information from the in-vehicle service provision unit using the SOME / IP protocol, and provides the received vehicle information to the in-vehicle application.

[0228] The cloud-enabled ECU 10 includes a SOME / IP client 203 and a transceiver unit 204. Hereinafter, the SOME / IP client 203 and the transceiver unit 204 of the cloud-enabled ECU 10 will be collectively referred to as the external request unit.

[0229] The external request unit receives information requests from third-party applications 83 (hereinafter referred to as "external applications") installed outside the vehicle, transmits a communication frame corresponding to the information request to the in-vehicle service provider unit via a third-party VLAN 7 using the SOME / IP protocol, receives vehicle information from the in-vehicle service provider unit using the SOME / IP protocol, and provides the received vehicle information to the external applications.

[0230] Such an integrated communication system 1 can provide services to the vehicle from in-vehicle applications and external applications using an in-vehicle ECU 20 and a cloud-based ECU 10 that are interconnected via a virtual private network. Therefore, the integrated communication system 1 can move applications installed on the in-vehicle ECU 20 to the cloud-based ECU 10, thereby preventing shortages of computing and power resources in the vehicle. Furthermore, since the integrated communication system 1 can communicate with in-vehicle applications and external applications using the same SOME / IP protocol, communication delays can be suppressed.

[0231] In the embodiments described above, the SOME / IP protocol corresponds to a predetermined communication protocol.

[0232] Although one embodiment of the present disclosure has been described above, the present disclosure is not limited to the above embodiment and can be implemented in various modified forms.

[0233] [Modification 1] In the above embodiment, a configuration was shown in which a plurality of in-vehicle ECUs 20 are equipped with either a shared database 85 or a SOME / IP server 201. However, as shown in Figure 11, the plurality of in-vehicle ECUs 20 may be configured in the first, second, third, fourth, fifth, and sixth configurations described later.

[0234] The first configuration is one in which applications are deployed on both the central ECU and peripheral ECUs, and both the central ECU and peripheral ECUs are equipped with both a SOME / IP server 201 and a shared database 85.

[0235] The second configuration is one in which applications are deployed on both the central ECU and peripheral ECUs, and both the central ECU and peripheral ECUs are equipped only with SOME / IP server 201.

[0236] The third configuration is one in which applications are deployed on both the central ECU and peripheral ECUs, and both the central ECU and peripheral ECUs are equipped only with a shared database 85.

[0237] The fourth configuration is one in which the application is deployed only on the central ECU, and both the central ECU and the peripheral ECUs are equipped with both the SOME / IP server 201 and the shared database 85.

[0238] The fifth configuration is one in which the application is deployed only on the central ECU, and both the central ECU and peripheral ECUs are equipped only with SOME / IP server 201.

[0239] The sixth configuration is one in which the application is deployed only on the central ECU, and both the central ECU and peripheral ECUs are equipped only with a shared database 85.

[0240] Note that Figure 11 shows a configuration limited to the ECU within the vehicle. However, the application may also be placed on an ECU installed in the cloud.

[0241] As a seventh configuration, applications may be deployed only on peripheral ECUs, and both the central ECU and peripheral ECUs may be equipped with both the SOME / IP server 201 and the shared database 85.

[0242] As an eighth configuration, applications may be deployed only on peripheral ECUs, and both the central ECU and peripheral ECUs may be equipped only with SOME / IP servers 201.

[0243] As a ninth configuration, applications may be deployed only on peripheral ECUs, and both the central ECU and peripheral ECUs may be equipped only with a shared database 85.

[0244] [Modification 2] In the above embodiment, the in-vehicle ECU 20 was connected to the core VLAN 6 and the third-party VLAN 7 by forming a tag VLAN on the same physical line. However, as shown in Figure 12, the in-vehicle ECU 20 may be connected to the core VLAN 6 and the third-party VLAN 7 using a port-based VLAN that connects separate physical lines to each of the separate physical NICs 73.

[0245] [Modified Example 3] In the above embodiment, the application was shown to request the provision of vehicle information. However, the application may also request the provision of various services.

[0246] [Modification 4] In the above embodiment, the in-vehicle ECU 20 is shown to be equipped with either a shared database 85 or a SOME / IP server 201. However, the in-vehicle ECU 20 may be equipped with both a shared database 85 and a SOME / IP server 201.

[0247] In this case, when the third-party application 83 sends an information request, the vehicle information-ECU map 69 and the SOME / IP client 203 identify the information provider corresponding to the information request.

[0248] When the vehicle information - ECU map 69 identifies the information provider, the transmitting / receiving unit 70 sends a communication frame to the information provider using the HTTP protocol.

[0249] When the SOME / IP client 203 identifies the information provider, the transmitting / receiving unit 204 sends a communication frame to the information provider using the SOME / IP protocol. The SOME / IP client 203 dynamically associates information with the information provider after system startup using the discovery process defined by SOME / IP.

[0250] In such an integrated communication system 1, the cloud-based ECU 10 and the in-vehicle ECU 20 each support communication using multiple predetermined communication protocols (i.e., the HTTP protocol and the SOME / IP protocol).

[0251] Then, the vehicle information-ECU map 69 and the transceiver 70 identify the information provider corresponding to the information request received from the third-party application 83, and transmit a communication frame of a predetermined communication protocol (i.e., the HTTP protocol) associated with the identified information provider.

[0252] Furthermore, the SOME / IP client 203 and the transceiver 204 identify the information provider corresponding to the information request received from the third-party application 83, and transmit a communication frame of a predetermined communication protocol (i.e., the SOME / IP protocol) associated with the identified information provider.

[0253] [Modification 5] In the above embodiment, an application deployment environment is identified based on the resource usage status of the application execution environment, and the target application is deployed to the identified application deployment environment.

[0254] However, resources for the third-party application execution environment 65 and resources for the core control unit 21, which is configured to control the vehicle's operation, may be separated. For example, within the in-vehicle ECU 20, computing resources for the third-party application execution environment 65 may be set to a CPU usage of, for example, 30%, and computing resources for the core control unit 21 may be set to a CPU usage of, for example, 50%.

[0255] In this case, the placement control ECU 30 may further identify an application-deployable environment for each of the multiple third-party application execution environments 65 based on the resources for the application execution environment and the resource usage status in the application execution environment, and then deploy the target application to the identified application-deployable environment. Such an integrated communication system 1 can suppress the occurrence of situations where the target application cannot be executed due to insufficient resources.

[0256] [Modification 6] In the above embodiment, as shown in Figure 1, the load balancing transfer control unit 31 is connected to the third-party VLAN 7. However, the load balancing transfer control unit 31 may be connected to the core VLAN 6, or it may be connected to both the core VLAN 6 and the third-party VLAN 7.

[0257] The ECUs 10, 20, 30 and their methods described in this disclosure may be implemented by a dedicated computer provided by configuring a processor and memory programmed to perform one or more functions embodied by a computer program. Alternatively, the ECUs 10, 20, 30 and their methods described in this disclosure may be implemented by a dedicated computer provided by configuring a processor by one or more dedicated hardware logic circuits. Alternatively, the ECUs 10, 20, 30 and their methods described in this disclosure may be implemented by one or more dedicated computers configured by a combination of a processor and memory programmed to perform one or more functions and a processor configured by one or more hardware logic circuits. Furthermore, the computer program may be stored as instructions executed by the computer on a computer-readable non-transitional tangible recording medium. The methods for implementing the functions of each part included in the ECUs 10, 20, 30 do not necessarily need to include software, and all of their functions may be implemented using one or more hardware components.

[0258] Multiple functions of one component in the above embodiment may be realized by multiple components, or one function of one component may be realized by multiple components. Furthermore, multiple functions of multiple components may be realized by one component, or one function realized by multiple components may be realized by one component. Also, some parts of the configuration of the above embodiment may be omitted. Furthermore, at least some parts of the configuration of the above embodiment may be added to or replaced with the configuration of other above embodiments.

[0259] In addition to the ECUs 10, 20, and 30 described above, this disclosure can also be realized in various forms, such as a system comprising the ECUs 10, 20, and 30, a program for causing the computer to function as the ECUs 10, 20, and 30, a non-transitional physical recording medium such as semiconductor memory on which this program is recorded, and a management method. [Technical Concept Disclosed in This Specification] [Item 1] The vehicle comprises: an in-vehicle control device (20) mounted on a vehicle; an external control device (10) installed outside the vehicle; an integrated network (6, 7) connecting the in-vehicle control device and the external control device via a virtual private network; and an in-vehicle service provision unit (85, 86, 201) mounted on the in-vehicle control device and configured to provide services related to the vehicle, wherein the in-vehicle control device includes an in-vehicle request unit (20, 68, 69, 70, 203, 204) configured to receive a service usage request from an in-vehicle application mounted on the vehicle, transmit a communication frame corresponding to the service usage request to the in-vehicle service provision unit using a predetermined communication protocol including the application layer of the OSI reference model, receive a service from the in-vehicle service provision unit using the predetermined communication protocol, and provide the received service to the in-vehicle application, and the external control device is An integrated communication system (1) comprising an external request unit (10, 68, 69, 70, 203, 204) configured to receive a service usage request from an external application mounted on the outside of the vehicle, transmit a communication frame corresponding to the service usage request to the in-vehicle service provision unit via the integrated network using the predetermined communication protocol, receive a service from the in-vehicle service provision unit using the predetermined communication protocol, and provide the received service to the external application.

[0260] [Item 2] An integrated communication system as described in Item 1, wherein the in-vehicle control device and the external control device each support communication of a plurality of predetermined communication protocols, and the in-vehicle request unit and the external request unit each identify a service provider that is the source of a service corresponding to the service usage request received from the in-vehicle application and the external application, and transmit the communication frame of the predetermined communication protocol associated with the identified service provider.

[0261] [Item 3] An integrated communication system according to Item 1 or Item 2, wherein the in-vehicle control device further comprises an in-vehicle application execution environment (20, 65) capable of executing a plurality of the in-vehicle applications, the external control device further comprises an external application execution environment (10, 65) capable of executing a plurality of the external applications, the in-vehicle request unit manages the correspondence between the service use request and the requester of the service use request in order to provide the service from the in-vehicle service provider to the in-vehicle application that made the service use request among the plurality of the in-vehicle applications, and the external request unit manages the correspondence between the service use request and the requester of the service use request in order to provide the service from the in-vehicle service provider to the external application that made the service use request among the plurality of the external applications.

[0262] [Item 4] An integrated communication system as described in any one of Items 1 to 3, wherein the in-vehicle request unit is an integrated communication system provided in each of the plurality of in-vehicle control devices mounted on the vehicle.

[0263] [Item 5] An integrated communication system according to any one of Items 1 to 4, wherein a plurality of in-vehicle applications, a plurality of external applications, an in-vehicle request unit, and an external request unit are connected to a VLAN (7) that spans between the inside and outside of the vehicle, and are isolated from mutual access with respect to an in-vehicle core control unit (21) that is mounted on the vehicle and configured to control the vehicle's operation, and the in-vehicle service provision unit is capable of providing services based on information provided by the in-vehicle core control unit to a plurality of in-vehicle applications and a plurality of external applications connected to the VLAN, and is accessible from the VLAN and the in-vehicle core control unit.

[0264] [Item 6] An integrated communication system as described in Item 5, wherein an on-board gateway device (52) mounted on the vehicle and an external gateway device (42) installed outside the vehicle are connected via L2 extension to form a virtual private network, and the VLAN is constructed at L3.

[0265] [Item 7] An integrated communication system as described in Item 5, wherein a plurality of in-vehicle applications, a plurality of external applications, an in-vehicle request unit, and a VLAN connected to the external request unit constitute a first VLAN (7), and the external core control unit (11) mounted outside the vehicle and configured to control the vehicle's movement, and the in-vehicle core control unit are connected to a second VLAN (6) which spans between the inside and outside of the vehicle and is a VLAN different from the first VLAN.

[0266] [Item 8] An integrated communication system as described in any one of Items 1 to 7, wherein a VLAN is constructed spanning the inside and outside of each of the multiple vehicles, with each of the main control units (11, 21) configured to control the driving of the vehicle being isolated from each other in an inaccessible manner, and one of the multiple vehicles is designated as the first vehicle, and the VLAN of the first vehicle is isolated from the main control units of the other vehicles, which are vehicles other than the first vehicle, in an inaccessible manner.

[0267] [Item 9] An integrated communication system according to any one of Items 1 to 8, further comprising a placement control unit (30) configured to control the placement of applications, wherein, among the application execution environments that execute the application, the application execution environment mounted outside the vehicle is designated as an external application execution environment (10, 65), and the application execution environment mounted inside the vehicle is designated as an in-vehicle application execution environment (20, 65), and the placement control unit places the target application in priority to the application execution environment closest to the source of information used in the processing executed by the target application, and / or the application execution environment closest to the destination of information transmission from the target application, among the external application execution environment and a plurality of in-vehicle application execution environments.

[0268] [Item 10] An integrated communication system as described in Item 9, wherein the placement control unit further identifies an application-deployable environment, which is an application execution environment where the target application can be placed, based on the resource usage status of each of the application execution environments, from among the external application execution environment and a plurality of in-vehicle application execution environments, and places the target application in the identified application-deployable environment.

[0269] [Item 11] An integrated communication system according to Item 9 or Item 10, wherein the placement control unit further identifies an application-deployable environment, which is an application execution environment where the target application can be deployed, from among the external application execution environment and a plurality of in-vehicle application execution environments, based on the resource usage status of each of the application execution environments, and moves the target application to an application execution environment that is closer to the source of information used in the processing performed by the target application, and / or to the destination of information transmission from the target application, compared with the application execution environment where the target application is currently deployed, from among the identified application-deployable environments.

[0270] [Item 12] An integrated communication system as described in any one of Items 9 to 11, wherein the resources for the application execution environment and the resources for the core control unit configured to control the driving of the vehicle are separated, and the placement control unit further identifies an application-deployable environment, which is an application execution environment where the target application can be placed, based on the resources for the application execution environment and the resource usage status in the application execution environment for each of the plurality of application execution environments, and places the target application in the identified application-deployable environment. [Item 13] An in-vehicle communication system comprising: an in-vehicle control device (20) mounted on a vehicle; an integrated network (6, 7) connecting the in-vehicle control device and an external control device (10) installed outside the vehicle via a virtual private network; and an in-vehicle service provision unit (85, 86, 201) mounted on the in-vehicle control device and configured to provide services related to the vehicle, wherein the in-vehicle service provision unit, upon receiving a first service usage request from an in-vehicle application mounted on the vehicle via a predetermined communication protocol including the application layer of the OSI reference model, transmits the service corresponding to the first service usage request to the in-vehicle application via the predetermined communication protocol; and upon receiving a second service usage request from an external application mounted outside the vehicle via the predetermined communication protocol, transmits the service corresponding to the second service usage request to the external application via the predetermined communication protocol.

Claims

1. The system comprises an in-vehicle control device (20) mounted on the vehicle, an external control device (10) installed outside the vehicle, an integrated network (6, 7) connecting the in-vehicle control device and the external control device via a virtual private network, and an in-vehicle service provision unit (85, 86, 201) mounted on the in-vehicle control device and configured to provide services related to the vehicle, wherein the in-vehicle control device includes an in-vehicle request unit (20, 68, 69, 70, 203, 204) configured to receive a service usage request from an in-vehicle application mounted on the vehicle, transmit a communication frame corresponding to the service usage request to the in-vehicle service provision unit using a predetermined communication protocol including the application layer of the OSI reference model, receive a service from the in-vehicle service provision unit using the predetermined communication protocol, and provide the received service to the in-vehicle application, and the external control device is An integrated communication system (1) comprising an external request unit (10, 68, 69, 70, 203, 204) configured to receive a service usage request from an external application mounted on the outside of the vehicle, transmit a communication frame corresponding to the service usage request to the in-vehicle service provision unit via the integrated network using the predetermined communication protocol, receive a service from the in-vehicle service provision unit using the predetermined communication protocol, and provide the received service to the external application.

2. An integrated communication system according to claim 1, wherein the in-vehicle control device and the external control device each correspond to communication of a plurality of predetermined communication protocols, and the in-vehicle request unit and the external request unit each identify a service provider that is a provider of a service corresponding to the service usage request received from the in-vehicle application and the external application, and transmit the communication frame of the predetermined communication protocol associated with the identified service provider.

3. An integrated communication system according to claim 1 or claim 2, wherein the in-vehicle control device further comprises an in-vehicle application execution environment (20, 65) capable of executing a plurality of the in-vehicle applications, the external control device further comprises an external application execution environment (10, 65) capable of executing a plurality of the external applications, the in-vehicle request unit manages the correspondence between the service use request and the requester of the service use request in order to provide the service from the in-vehicle service provision unit to the in-vehicle application that made the service use request among the plurality of the in-vehicle applications, and the external request unit manages the correspondence between the service use request and the requester of the service use request in order to provide the service from the in-vehicle service provision unit to the external application that made the service use request among the plurality of the external applications.

4. An integrated communication system according to claim 1 or claim 2, wherein the in-vehicle request unit is an integrated communication system provided in each of the plurality of in-vehicle control devices mounted on the vehicle.

5. An integrated communication system according to claim 1 or claim 2, wherein a plurality of in-vehicle applications, a plurality of external applications, an in-vehicle request unit and an external request unit are connected to a VLAN (7) that spans between the inside and outside of the vehicle, and are isolated from an in-vehicle core control unit (21) that is mounted on the vehicle and configured to control the driving of the vehicle, and the in-vehicle service provision unit is capable of providing services based on information provided by the in-vehicle core control unit to a plurality of in-vehicle applications and a plurality of external applications connected to the VLAN, and the integrated communication system is accessible from the VLAN and the in-vehicle core control unit.

6. An integrated communication system according to claim 5, wherein an on-board gateway device (52) mounted on the vehicle and an off-board gateway device (42) installed outside the vehicle are connected via L2 extension to form a virtual private network, and the VLAN is constructed at L3.

7. An integrated communication system according to claim 5, wherein a plurality of in-vehicle applications, a plurality of external applications, an in-vehicle request unit, and a VLAN connected to the external request unit constitute a first VLAN (7), and an external core control unit (11) mounted outside the vehicle and configured to control the vehicle's movement, and the in-vehicle core control unit are connected to a second VLAN (6) which spans between the inside and outside of the vehicle and is a VLAN different from the first VLAN.

8. An integrated communication system according to claim 1 or claim 2, wherein for each of the plurality of vehicles, a VLAN is constructed spanning the inside and outside of the vehicle, which is mutually inaccessible to the core control units (11, 21) configured to control the driving of the vehicle, and one of the plurality of vehicles is designated as the first vehicle, and the VLAN of the first vehicle is mutually inaccessible to the core control units of the other vehicles, which are the vehicles other than the first vehicle.

9. An integrated communication system according to claim 1 or claim 2, further comprising a placement control unit (30) configured to control the placement of an application, wherein, among the application execution environments that execute the application, the application execution environment mounted outside the vehicle is designated as an external application execution environment (10, 65), and the application execution environment mounted inside the vehicle is designated as an in-vehicle application execution environment (20, 65), and the placement control unit places the target application in priority to the application execution environment closest to the source of information used in the processing executed by the target application, and / or the application execution environment closest to the destination of information transmission from the target application, among the external application execution environment and a plurality of in-vehicle application execution environments.

10. An integrated communication system according to claim 9, wherein the placement control unit further identifies an application-deployable environment, which is an application execution environment on which the target application can be placed, based on the resource usage status of each of the application execution environments, from among the external application execution environment and a plurality of in-vehicle application execution environments, and places the target application in the identified application-deployable environment.

11. An integrated communication system according to claim 9, wherein the placement control unit further identifies an application-deployable environment, which is an application execution environment where the target application can be deployed, from among the external application execution environment and a plurality of in-vehicle application execution environments, based on the resource usage status of each of the application execution environments, and moves the target application to an application execution environment that is closer to the source of information used in the processing performed by the target application, and / or to the destination of information transmission from the target application, compared with the application execution environment where the target application is currently deployed, from among the identified application-deployable environments.

12. An integrated communication system according to claim 9, wherein the resources for the application execution environment and the resources for the core control unit configured to control the driving of the vehicle are separated, and the placement control unit further identifies an application-deployable environment, which is an application execution environment where the target application can be placed, based on the resources for the application execution environment and the resource usage status in the application execution environment, for each of the plurality of application execution environments, and places the target application in the identified application-deployable environment.

13. An in-vehicle communication system comprising: an in-vehicle control device (20) mounted on a vehicle; an integrated network (6, 7) connecting the in-vehicle control device and an external control device (10) installed outside the vehicle via a virtual private network; and an in-vehicle service provision unit (85, 86, 201) mounted on the in-vehicle control device and configured to provide services related to the vehicle, wherein the in-vehicle service provision unit, upon receiving a first service usage request from an in-vehicle application mounted on the vehicle via a predetermined communication protocol including the application layer of the OSI reference model, transmits the service corresponding to the first service usage request to the in-vehicle application via the predetermined communication protocol; and upon receiving a second service usage request from an external application mounted outside the vehicle via the predetermined communication protocol, transmits the service corresponding to the second service usage request to the external application via the predetermined communication protocol.