Relay method and relay device

WO2026163367A1PCT designated stage Publication Date: 2026-08-06NISSAN MOTOR CO LTD
View PDF 0 Cites 0 Cited by

Patent Information

Authority / Receiving Office
WO · WO
Patent Type
Applications
Current Assignee / Owner
NISSAN MOTOR CO LTD
Filing Date
2025-01-31
Publication Date
2026-08-06

Smart Images

  • Figure JP2025003133_06082026_PF_FP_ABST
    Figure JP2025003133_06082026_PF_FP_ABST
Patent Text Reader

Abstract

This relay method is executed by a controller (21) provided in a gateway (20) that relays communication between a plurality of ECUs (30, 40, 50) connected to a vehicle-mounted network. The controller (21) verifies communication in the vehicle-mounted network on the basis of a first white list, and determines whether the amount of data communicated in the vehicle-mounted network increases. When it is determined that the amount of data communicated in the vehicle-mounted network increases, the controller (21) verifies the communication in the vehicle-mounted network on the basis of a second white list in which data permitting communication is more limited than in the first white list.
Need to check novelty before this filing date? Find Prior Art

Description

Relay Method and Relay Device

[0001] The present invention relates to a relay method and a relay device.

[0002] In recent years, various electronic control units (ECUs) have been installed in automobiles. These electronic control units are connected to each other via an in-vehicle network such as a CAN (Controller Area Network), and can cooperate with each other by communicating with each other. An in-vehicle network is provided with a relay device that relays communication between electronic control units. When the relay device processes a large amount of data in a short time, data transfer leakage may occur.

[0003] Patent Document 1 discloses an in-vehicle network system that suppresses communication failures and data delays. In this in-vehicle network system, when the occurrence frequency of an error occurring in a bus to which a plurality of control units are connected reaches a first degree or more, the communication speed of any one of the plurality of control units is reduced.

[0004] Japanese Unexamined Patent Application Publication No. 2018-074257

[0005] However, if the communication speed is reduced, there is a problem that the desired functions of the electronic control unit cannot be realized.

[0006] An object of the present invention is to provide a relay method and a relay device that can realize the functions of each electronic control unit by performing reliable data communication in an in-vehicle network.

[0007] A relay method according to an aspect of the present invention includes verifying communication in an in-vehicle network based on a first whitelist, and when it is determined that the data amount in the in-vehicle network increases, switching to a second whitelist in which data permitting communication is more restricted than the first whitelist, and verifying communication in the in-vehicle network based on the second whitelist.

[0008] According to one aspect of the present invention, reliable data communication can be performed in an in-vehicle network, thereby enabling the proper realization of the functions of each electronic control unit.

[0009] Figure 1 is a block diagram showing the configuration of the vehicle communication system according to this embodiment. Figure 2 is a diagram illustrating the first whitelist and the second whitelist in comparison. Figure 3 is a flowchart showing the flow of the relay method in this embodiment. Figure 4 is a diagram illustrating the switching from the first whitelist to the second whitelist. Figure 5 is a diagram illustrating the switching from the first whitelist to the second whitelist.

[0010] The following description will refer to the drawings and explain a vehicle communication system to which the relay method and relay device according to this embodiment are applied.

[0011] As shown in Figure 1, the vehicle communication system 10 is a system mounted on a vehicle, in which multiple ECUs (Electronic Control Units) connected to an in-vehicle network communicate with each other. Specifically, the vehicle communication system 10 comprises a gateway 20 and multiple ECUs. The gateway 20 and each ECU are connected to a communication bus and constitute a network. In Figure 1, three ECUs 30, 40, and 50 are shown as examples of multiple ECUs, but the system is not limited to these.

[0012] In the following explanation, the in-vehicle network is assumed to be Ethernet®. Furthermore, the in-vehicle network is logically segmented using VLANs. Note that the in-vehicle network may also be a network compliant with a communication protocol other than Ethernet.

[0013] Gateway 20 is a relay device that relays (transfers) data between each ECU 30, 40, and 50. Gateway 20 is implemented using an electronic control unit (ECU). A communication bus is connected to Gateway 20. In addition, external devices (not shown), such as a vehicle diagnostic device, can be connected to Gateway 20. External devices can communicate with each ECU 30, 40, and 50 via the communication bus.

[0014] The gateway 20 comprises a controller 21 and a communication circuit 25. The controller 21 is composed of a microcomputer equipped with a CPU, memory, input / output interface, etc. The CPU reads various computer programs stored in memory and executes various instructions contained in the programs. By executing programs, the controller 21 functions as one of the multiple information processing circuits provided by the gateway 20. In this embodiment, an example is shown in which the multiple information processing circuits provided by the gateway 20 are realized by software. Of course, it is also possible to configure the information processing circuits by preparing dedicated hardware to execute each of the information processing processes shown below. Alternatively, the multiple information processing circuits may be configured with individual hardware.

[0015] The controller 21 includes a first verification unit 22, a second verification unit 23, and a switching unit 24 as multiple information processing circuits.

[0016] The first and second verification units 22 and 23 verify communication in the in-vehicle network based on a whitelist. Specifically, communication data is structured as frames. When the first and second verification units 22 and 23 receive a frame from a certain EUC, they analyze the frame's header information and obtain the necessary information. If the obtained information matches the whitelist, the first and second verification units 22 and 23 forward the frame to the next destination. On the other hand, if the obtained information does not match the whitelist, the first and second verification units 22 and 23 discard the frame or generate an alarm.

[0017] As shown in Figure 2, the whitelist is a list that defines the header information of frames that are permitted to be forwarded, and the header information includes the source port ID, destination port ID, source MAC address, etc. The first verification unit 22 forwards frames based on the first whitelist. The second verification unit 23 forwards frames based on the second whitelist. The second whitelist restricts the frames that are permitted to communicate more than the first whitelist. For example, the first whitelist contains header information for 256 items, while the second whitelist contains header information for 2 items. Furthermore, the second whitelist includes a static whitelist in which header information is pre-registered, and a dynamic whitelist in which header information is dynamically registered according to the frame being communicated. The second whitelist shown in Figure 2 is a static whitelist. Thus, the whitelist is a list in which identification information is registered to identify frames that are permitted to communicate in an in-vehicle network.

[0018] The switching unit 24 normally selects the first verification unit 22. The switching unit 24 monitors the amount of data communicated over the in-vehicle network and determines whether this amount of data will increase or not. If the switching unit 24 determines that the amount of data communicated over the in-vehicle network will increase, it selects the second verification unit 23. The switching of the first and second verification units 22 and 23 by the switching unit 24 results in a switch from the first whitelist to the second whitelist.

[0019] As shown in Figure 1, the communication circuit 25 is a circuit for communicating with each of the ECUs 30, 40, and 50. The communication circuit 25 transmits and receives frames.

[0020] A vehicle is equipped with multiple ECUs, each suited to a specific function or application. The three ECUs 30, 40, and 50 shown in Figure 1 are representative examples of the multiple ECUs installed in a vehicle.

[0021] The external communication ECU 30 is an ECU that communicates with external devices located outside the vehicle. For example, the external communication ECU 30 is an IVI ECU that controls IVI equipment that handles information such as a car navigation system. The IVI ECU can communicate with an external server (not shown) via a dedicated line and also has the function of updating map information and various applications.

[0022] The first and second internal ECUs 40 and 50 are ECUs that control processing within the vehicle. For example, the first internal ECU 40 is a meter ECU and controls the meter display to display various information on the meter display. The second internal ECU 50 is a map ECU and generates high-precision map information corresponding to a route based on route information and high-precision map information acquired from the external communication ECU (IVIE ECU) 30. The second internal ECU 50 transmits the generated high-precision map information to the external communication ECU 30.

[0023] Each ECU 30, 40, and 50 is equipped with a controller and a communication circuit. The controller consists of a microcomputer equipped with a CPU, memory, input / output interfaces, etc. The communication circuit transmits and receives frames.

[0024] Referring to Figure 3, the relay method according to this embodiment will be described. The process shown in the flowchart of Figure 3 is periodically executed by the controller 21 of the gateway 20.

[0025] First, the controller 21 determines whether a predetermined communication event has occurred (S10). Here, the predetermined communication event is an event predetermined as high-speed data communication, and one example is a request and response performed between ECUs prior to high-speed data communication. For example, as shown in Figure 4, when displaying map data shown on an IVI device on a meter display, communication takes place between the external communication ECU 30 and the first internal ECU 40 via the gateway 20. When a display operation is performed by the user, a request and response are executed between the external communication ECU 30 and the first internal ECU 40. When the controller 21 determines that a request and response have been executed (S10: YES), it selects the second verification unit 23 as the verification unit to verify the communication. As a result, the second whitelist is applied to the verification of the communication (S11). At this time, the second verification unit 23 forwards the frame based on a static second whitelist prepared in advance in response to the communication event that occurred. As shown in Figure 4, the first whitelist is applied during the first period Ta1 when requests and responses are made, and the second whitelist is applied during the second period Ta2 following the first period Ta1.

[0026] If no predetermined communication event has occurred (S10: NO), the controller 21 monitors communication in the in-vehicle network and determines whether the data transfer rate is at the specified transfer rate, whether the load on the controller 21 (CPU) is above the specified load, or whether the remaining capacity of the controller 21's buffer (memory area) is below the specified value (S12, S13, S14). These determinations are made to determine whether the amount of data communicated in the in-vehicle network is increasing. If it is determined that any of these conditions are met (YES in any of S12, S13, or S14), the controller 21 checks the number of frames for each VLAN (S15). For example, the controller 21 checks the number of frames for a unit of time, for example, the most recent 2 seconds.

[0027] The controller 21 determines whether the number of frames in any VLAN exceeds the upper limit (S16). As shown in Figure 5, when the second internal ECU 50 transmits map data to an external server via the external communication ECU 30, communication takes place between the second internal ECU 50 and the external communication ECU 30 via the gateway 20. At this time, the number of frames may increase dynamically because the amount of map data differs depending on the region.

[0028] If the number of frames exceeds the upper limit (S16: YES), the controller 21 registers the header information of the most recently received frame into the second whitelist, which is a dynamic whitelist (S17). The controller 21 then switches the verification unit that verifies the communication from the first verification unit 22 to the second verification unit 23. As a result, the second whitelist is applied to the verification of the communication (S18, see Figure 5). At this time, the second verification unit 23 verifies the frames based on the dynamic second whitelist in which the header information has been registered. As shown in Figure 5, in the first period Ta1, when the number of frames does not exceed the upper limit, the first whitelist is applied, and in the second period Ta2, when the number of frames exceeds the upper limit, the whitelist is switched and the second whitelist is applied.

[0029] In contrast, if none of the conditions in steps S12, S13, and S14 apply (all of S12, S13, and S14 are NO), or if the number of frames does not exceed the upper limit of frames (S16: NO), the controller 21 selects the first verification unit 22 as the verification unit for verifying the communication. As a result, the first whitelist is applied to the verification of the communication (S19).

[0030] In this relay method of the embodiment, the controller 21 verifies communication in the in-vehicle network based on the first whitelist, and when it determines that the amount of data transmitted in the in-vehicle network is increasing, it switches from the first whitelist to the second whitelist and verifies communication in the in-vehicle network based on the second whitelist.

[0031] According to this method, if it is determined that the amount of data in the in-vehicle network will increase, communication verification is performed using a second whitelist. The number of header information entries in the second whitelist is less than the number of header information entries in the first whitelist. Therefore, the processing load on the controller 21 can be reduced, allowing for reliable data communication. And because reliable data communication can be performed, the functions of each ECU can be realized.

[0032] In the relay method of this embodiment, the controller 21 determines that the amount of data increases when a predetermined communication event occurs as high-speed data communication.

[0033] This method allows for accurate determination of data volume increases by detecting communication events associated with high-speed data communication. This enables appropriate switching to the second whitelist.

[0034] In the relay method of this embodiment, the second whitelist is a static whitelist in which header information is pre-registered.

[0035] This method allows the header information necessary for high-speed data communication to be pre-registered in the second whitelist. This reduces the processing load on the gateway 20 while enabling the necessary high-speed data communication, thereby realizing the functions of each ECU.

[0036] In the relay method of this embodiment, the controller 21 determines that the amount of data will increase when the number of frames (amount of data) per unit time communicated in the in-vehicle network exceeds the upper limit number of frames (upper limit of data).

[0037] This method allows for the appropriate detection of data volume increases, even when the number of frames transmitted in the in-vehicle network changes dynamically. This enables the appropriate switching to the second whitelist.

[0038] In the relay method of this embodiment, the controller 21 registers header information in a dynamic whitelist based on the frame forwarded (relayed) by the gateway 20. In this case, the second whitelist to be switched from the first whitelist is this dynamic whitelist.

[0039] This method allows header information related to communications with increased data volume to be registered in the second whitelist. This reduces the processing load on the gateway 20 while enabling necessary data communication, thereby realizing the functionality of each ECU.

[0040] In the relay method of this embodiment, the controller 21 determines whether the number of frames per unit time exceeds the upper limit of frames when the data transfer rate is equal to or greater than the specified transfer rate, the load on the controller 21 is equal to or greater than the specified load, or the remaining capacity of the memory area of ​​the controller 21 is equal to or less than the specified value.

[0041] This configuration allows for a comparison with the upper limit on the number of frames after understanding the trend of increasing data volume. As a result, it is not necessary to constantly perform a comparison with the upper limit on the number of frames, thus reducing the processing load on the controller 21.

[0042] The gateway 20 of this embodiment includes a communication circuit 25 for sending and receiving data, and a controller 21. This controller 21 performs the relay method described above.

[0043] In this configuration, if it is determined that the amount of data in the in-vehicle network is increasing, communication control is implemented using the second whitelist. The number of header information entries in the second whitelist is less than the number of header information entries in the first whitelist. This reduces the processing load on the controller 21, allowing for reliable data communication. Reliable data communication enables the realization of the functions of each ECU.

[0044] As described above, embodiments of the present invention have been described. However, the descriptions and drawings forming a part of this disclosure should not be understood as limiting the present invention. Various alternative embodiments, examples, and operation techniques will be apparent to those skilled in the art from this disclosure.

[0045] 10: Vehicle communication system, 20: Gateway, 21: Controller, 22: First verification unit, 23: Second verification unit, 24: Switching unit, 25: Communication circuit, 30: External communication ECU, 40: First internal ECU, 50: Second internal ECU

Claims

1. A relay method performed by a controller in a relay device that relays communication between a plurality of electronic control devices connected to an in-vehicle network, comprising: verifying communication in the in-vehicle network based on a first whitelist in which identification information for identifying data that is permitted to be communicated in the in-vehicle network is registered; determining whether the amount of data communicated in the in-vehicle network will increase; and, if it is determined that the amount of data communicated in the in-vehicle network will increase, switching from the first whitelist to a second whitelist in which the data permitted to be communicated is more restricted than in the first whitelist; and verifying communication in the in-vehicle network based on the second whitelist.

2. The relay method according to claim 1, wherein it is determined that the amount of data increases when a predetermined communication event occurs as high-speed data communication.

3. The relay method according to claim 2, wherein the second whitelist to be switched from the first whitelist is a static whitelist in which the identification information is pre-registered.

4. The relay method according to claim 1, wherein it is determined that the amount of data will increase when the amount of data per unit time communicated in the in-vehicle network exceeds the upper limit of data.

5. The relay method according to claim 4, wherein the identification information is registered in a dynamic whitelist based on data communicated in the in-vehicle network, and the second whitelist to be switched from the first whitelist is the dynamic whitelist in which the identification information is registered.

6. The relay method according to claim 4 or 5, which determines whether the amount of data per unit time exceeds the upper limit of data when the data transfer speed is equal to or greater than the specified transfer speed, the load on the controller is equal to or greater than the specified load, or the remaining capacity of the memory area of ​​the controller is equal to or less than the specified value.

7. A relay device for relaying communication between a plurality of electronic control devices connected to an in-vehicle network, comprising: a communication circuit for transmitting and receiving data; and a controller, wherein the controller verifies communication in the in-vehicle network based on a first whitelist in which identification information for identifying data permitted to be communicated in the in-vehicle network is registered; determines whether the amount of data transmitted in the in-vehicle network will increase; and, if it determines that the amount of data transmitted in the in-vehicle network will increase, switches from the first whitelist to a second whitelist in which the data permitted to be communicated is more restricted than in the first whitelist; and verifies communication in the in-vehicle network based on the second whitelist.