Vehicle operation

By using distributed ledger and private-key-public-key signature technology, vehicle identity is verified and consensus is established, which solves the risk of road accidents caused by sensor output errors and improves the security and reliability of autonomous vehicle operation.

CN115691190BActive Publication Date: 2025-12-16NOKIA TECHNOLOGIES OY
View PDF 3 Cites 0 Cited by

Patent Information

Application Number
CN202211446171.8
Authority / Receiving Office
CN · China
Patent Type
Patents(China)
Current Assignee / Owner
Priority Date
2017-05-18
Filing Date
2018-05-15
Publication Date
2025-12-16
Estimated Expiration
2038-05-15

AI Technical Summary

Technical Problem

Incorrect sensor outputs can lead to road accident risks during autonomous vehicle operation, and current technologies are unable to effectively mitigate such risks.

Method used

By using a distributed ledger to record vehicle radio transmissions, vehicle identity is verified and consensus is established to control vehicle operation. Private-public key pair signatures are used to ensure the security and reliability of data transmission, and vehicle operation is controlled based on sensor output information from other vehicles.

Benefits of technology

It reduces the risk of road accidents caused by sensor failure or external interference, and improves the safety and reliability of autonomous vehicle operation.

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure CN115691190B_ABST
    Figure CN115691190B_ABST
Patent Text Reader

Abstract

A technique includes controlling operation of a first vehicle based at least in part on information regarding one or more sensor outputs of one or more other vehicles recovered from one or more radio transmissions each verifiable as a radio transmission of a vehicle included in a record of authenticated vehicles.
Need to check novelty before this filing date? Find Prior Art

Description

[0001] This application is a divisional application of patent application no. 201880044259.2, filed May 15, 2018, which claims priority from patent application no. 2017205077.2, filed May 18, 2017, and has the same title, “Vehicle Operation”. BACKGROUND

[0002] One or more operations of a vehicle can be autonomously (including semi-autonomously) controlled based on output of one or more sensors. The inventors of the present application have found that false sensor output (e.g., caused by sensor malfunction or one or more external disturbances) leads to road accidents; and there is a need for a technique to reduce the risk of such road accidents. SUMMARY

[0003] Herein, there is provided a method comprising: controlling operation of a first vehicle based at least in part on information about one or more sensor outputs of one or more other vehicles recovered from one or more radio transmissions each verifiable as a radio transmission of a vehicle included in a record of authenticated vehicles.

[0004] According to one embodiment, the record of authenticated vehicles comprises a local copy of a distributed ledger stored in a memory at the first vehicle, or a copy of a distributed ledger stored in a remote memory accessible by the first vehicle via a communications network.

[0005] According to one embodiment, the method further comprises: controlling addition of one or more new blocks to a blockchain based at least in part on the information about the one or more sensor outputs.

[0006] According to one embodiment, the method further comprises: for each radio transmission verifiable as a radio transmission of a vehicle recorded on the distributed ledger, controlling addition of a new block to the blockchain.

[0007] According to one embodiment, the method further comprises: for a batch of radio transmissions each verifiable as a radio transmission of a vehicle recorded on the distributed ledger, controlling addition of a new block to the blockchain.

[0008] According to an embodiment, the method further comprises controlling addition of one or more new blocks to a blockchain based on information about one or more sensor outputs of one or more other vehicles recovered from the one or more radio transmissions, each verifiable as the radio transmission of the vehicle included in the record of the authenticated vehicles; and wherein the controlling the operation of the first vehicle comprises identifying consensus among the one or more authenticated vehicles regarding one or more external conditions from the information about the one or more sensor outputs.

[0009] According to an embodiment, the consensus among the one or more authenticated vehicles regarding one or more external conditions comprises consensus on how to cooperatively travel in a traffic system.

[0010] Herein, there is provided a method comprising: controlling a radio transmission of data from a vehicle, the data comprising information about a sensor output, wherein controlling the radio transmission comprises: creating a digital signature of at least a part of the data using a private key of a private-public key pair, the corresponding public key of the private key being included in a record of authenticated public keys.

[0011] According to an embodiment, the record of authenticated public keys is included in a distributed ledger.

[0012] Herein, there is provided an apparatus comprising: a processor and a memory including computer program code, wherein the memory and the computer program code are configured to, with the processor, cause the apparatus to: control an operation of a first vehicle based at least in part on information about one or more sensor outputs of one or more other vehicles recovered from one or more radio transmissions, each verifiable as a radio transmission of a vehicle included in a record of authenticated vehicles.

[0013] According to an embodiment, the record of authenticated vehicles comprises a local copy of a distributed ledger stored in a memory at the first vehicle, or a copy of a distributed ledger stored in a remote memory accessible by the first vehicle via a communication network.

[0014] According to an embodiment, the memory and the computer program code are further configured to, with the processor, cause the apparatus to: control addition of one or more new blocks to a blockchain based at least in part on the information about the one or more sensor outputs.

[0015] According to an embodiment, the memory and the computer program code are further configured to, with the processor, cause the apparatus to: for each radio transmission verifiable as a radio transmission of a vehicle recorded on the distributed ledger, control addition of a new block to the blockchain.

[0016] According to an embodiment, the memory and the computer program code are further configured to, with the processor, cause the apparatus to: for a batch of radio transmissions each verifiable as a radio transmission of a vehicle recorded on the distributed ledger, control addition of new blocks to the blockchain.

[0017] According to an embodiment, the memory and the computer program code are further configured to, with the processor, cause the apparatus to: control addition of one or more new blocks to the blockchain based on information about one or more sensor outputs of one or more other vehicles recovered from one or more radio transmissions each verifiable as a radio transmission of the vehicle included in the record of the authenticated vehicles; and identify consensus among the one or more authenticated vehicles regarding one or more external conditions from the information about the one or more sensor outputs.

[0018] According to an embodiment, the consensus among the one or more authenticated vehicles regarding one or more external conditions comprises consensus on how to cooperatively travel in a traffic system.

[0019] Thus, there is provided an apparatus comprising: a processor and a memory including computer program code, wherein the memory and the computer program code are configured to, with the processor, cause the apparatus to: control radio transmission of data from a vehicle, the data comprising information about a sensor output, and create a digital signature of at least a part of the data using a private key of a private-public key pair, a corresponding public key of the private key being included in a record of authenticated public keys.

[0020] According to an embodiment, the record of authenticated public keys is included in a distributed ledger.

[0021] Herein, there is provided an apparatus comprising: means for controlling operation of a first vehicle based at least in part on information about one or more sensor outputs of one or more other vehicles recovered from one or more radio transmissions each verifiable as a radio transmission of a vehicle included in a record of authenticated vehicles.

[0022] Herein, there is provided an apparatus comprising: means for controlling radio transmission of data from a vehicle, the data comprising information about a sensor output, wherein controlling the radio transmission comprises creating a digital signature of at least a part of the data using a private key of a private-public key pair, a corresponding public key of the private key being included in a record of authenticated public keys.

[0023] Herein, there is provided a computer program product comprising program code means which, when loaded into a computer, control the computer to: control operation of a first vehicle based at least in part on information about sensor output of one or more other vehicles recovered from one or more radio transmissions each verifiable as a radio transmission of a vehicle included in a record of authenticated vehicles.

[0024] Herein, there is provided a computer program product comprising program code means which, when loaded into a computer, control the computer to: control radio transmission of data from a vehicle, the data comprising information about sensor output, and create a digital signature of at least a part of the data using a private key of a private-public key pair, the corresponding public key of the private key being included in a record of authenticated public keys. BRIEF DESCRIPTION OF DRAWINGS

[0025] Embodiments of the application will be described below, by way of example only, and with reference to the accompanying drawings in which:

[0026] Figure 1 An example of a plurality of vehicles in the vicinity of a vision-based traffic control signal system, such as a set of traffic lights, is shown;

[0027] Figure 2 An example of an apparatus for use at a vehicle in Figure 1 is shown;

[0028] Figure 3a An example of a set of operations at a vehicle in Figure 1 is shown;

[0029] Figure 3b Another example of a set of operations at a vehicle in Figure 1 is shown;

[0030] Figure 4 An example of a set of node processor operations relating to adding a vehicle to a record of authenticated vehicles is shown;

[0031] Figure 5 An extension of a sidechain blockchain record at a vehicle based on sensor output information received from other authenticated vehicles is shown; and

[0032] Figure 6 An extension of a mainchain blockchain record based on a sidechain blockchain record is shown. DETAILED DESCRIPTION

[0033] Example embodiments of the application are described by way of example only, with reference to making operational decisions about how to proceed at a junction served by a traffic control signal system, but the same techniques are equally applicable to making other kinds of operational decisions.

[0034] Referring to Figure 1 A plurality of vehicles 2, such as automated, semi-automated, or traditional (i.e., manually operated) vehicles, are operating in the vicinity of a road intersection 4 being served by a traffic control signal system 6. The traffic control signal system can include vision-based control signal devices, such as traffic lights that emit different colors of light, each color indicating a respective signal, such as green for “go” and red for “stop.”

[0035] Figure 2 A schematic diagram showing an example of an apparatus for each vehicle 2 is shown. One or more processors 10 operating in accordance with program code stored at one or more memory devices 12 control operation of one or more actuators 14, the operation of which determines the speed and direction of the vehicle, such as brakes, steering, speed controls, etc., or any combination thereof. The apparatus also includes one or more sensors 16, the output of which is saved in memory 12 and can be used as input to the one or more processors 10 to control operation of the actuators 14. For example, the one or more sensors 16 can include one or more video or still image cameras configured to capture visual data about the environment of the vehicle, from which the one or more processors 10 can make determinations, such as image recognition, for example, about the color of a traffic light, the type of traffic sign, or the type of object (such as a vehicle, pedestrian, or animal) in the vicinity of the vehicle, for example. Additionally, the one or more sensors 16 can include one or more positioning sensors, such as a global navigation satellite system (GNSS) sensor, an acceleration sensor, a compass sensor, a speed sensor, a microphone, a LIDAR (light detection and ranging) sensor, a radar sensor, a brake sensor, a steering angle sensor, any vehicle component-specific sensor, or any combination thereof.

[0036] The one or more processors 10 also control the generation, transmission, and reception of radio signals via the one or more radio transceiver devices 18. The radio transceiver devices 18 can include radio frequency (RF) front ends 20 and antennas 22. The RF front ends 20 can include one or more analog and / or digital transceivers, filters, duplexers, and antenna switches. Also, the combination of the radio transceiver 18 and the one or more processors 10 also recovers data / information from radio signals, e.g., arriving at the vehicle 2 from other vehicles. The one or more processors 10 can include a baseband processor that is dedicated to (i) controlling the generation and transmission of radio signals that convey data generated by another processor 10 and (ii) recovering data from radio transmissions received via the radio transceiver device 18 for use by another processor 10. The apparatus can include separate one or more radio transceivers and separate baseband processors for each of a variety of different radio communication technologies, including, e.g., one or more cellular radio technologies, such as LTE (Long Term Evolution), 4G (Fourth Generation mobile networks), or 5G (Fifth Generation mobile networks), V2V (Vehicle to Vehicle), V2X (Vehicle to Everything), Bluetooth, WiFi (Wireless Fidelity), or any combination thereof.

[0037] The one or more processors 10 also control the generation, communication, and presentation of video and / or audio user interface signals with one or more rendering devices, such as a vehicle infotainment system, a HUD (Head-Up Display), a dashboard display, or an external display device, or any combination thereof, in order to render information to a user of the vehicle 2 related to control of the vehicle 2.

[0038] The one or more processors 10 can be implemented as separate chips or combined into a single chip. The memory 12 can be implemented as one or more chips. The memory 12 can include both read-only memory and random access memory. The above elements can be provided on one or more circuit boards.

[0039] It is to be understood that the above Figure 2 The illustrated apparatus can include other elements not directly related to the embodiments of the application described in the following detailed description.

[0040] Alternatively, Figure 2 A schematic diagram is shown of an example of a mobile communication device, such as a mobile phone, tablet computer, navigation device, laptop computer, still / video camera device, or any combination thereof, or an On-Board Diagnostics (OBD) device, or any combination thereof. The mobile communication device or OBD device can be wired or wirelessly connected to the system of the vehicle 2, e.g., mirroring the content of the device to the system, and providing the same functionality as described for the vehicle 2.

[0041] All operations described below as being performed by the one or more processors 10 follow program code stored at the memory 12.

[0042] Figure 3a One example of operations at the one or more processors 10 according to an example embodiment of the application is shown. Figure 2

[0043] In response to the processor 10 making a determination (see steps 300 and 302 of Figure 3) about the current state of traffic for a particular location, system and / or situation (e.g. the traffic control signal system 6) based on output of one or more sensors 16, the processor controls storage of the determination result in the memory 12, and additionally controls transmission of the determination result via the one or more radio transceivers 18 (step 304 of Figure 3). Figure 3a Figure 3a

[0044] For example, the determination result can take the form shown below, which includes: (i) a unique vehicle identifier, for example a public key in a private-public key pair; (ii) information about one or more observations (determinations) based on sensor output, such as for example the state of a traffic signal at a road intersection uniquely identified by location coordinates; and (iii) information about the current location of the vehicle at the time of making the observation. Additionally, the determination result can include one or more unique sensor identifiers for each sensor data transmitted, for example an identifier for a positioning sensor and / or a camera sensor.

[0045]

[0046] As mentioned above, the vehicle 2 has a unique vehicle identifier number which is recorded in a distributed ledger (e.g. a blockchain) stored in the vehicle 2 as an authenticated identifier; and the radio transmission is made in a way that it can be verified as coming from a vehicle recorded on the distributed ledger as an authenticated vehicle. For example, the radio transmission can include a digital signature, for example in cleartext, of some or all of the data, the digital signature being transmitted by the radio transmission using a private key in a private-public key pair for which the public key is recorded on the distributed ledger in association with the vehicle identifier (as mentioned above, the vehicle identifier itself can be the public key). Additionally or alternatively, a private key in a possible additional private-public key pair can be used for digitally signing transactions and communications, with the corresponding public key in that pair acting as or being directly associated with the vehicle identifier. For example, the private key(s) can be securely incorporated into the processor 10 and / or the memory 12 at the time of manufacture.

[0047] ​​​In one example embodiment, in response to the processor 10 making a determination about the current state of the output of one or more sensors 16, the processor controls storage of the determination result in the memory 12, and additionally controls transmission of the determination result via the one or more radio transceivers 18, as a supplement or alternative to steps 300 and 302 of the current state of the traffic being determined Figure 3a Figure 3a

[0048] Figure 3b Another example is shown for the operation of the vehicle 2 in Figure 1 Figure 2 at the one or more processors 10 of the vehicle 2 in

[0049] In conjunction with the one or more radio transceivers 18, the one or more processors 10 recover data from one or more radio transmissions made by one or more other vehicles 2 in the vicinity of the road intersection 4 (step 306 of the method). For each data message recovered from the one or more radio transmissions, the processor 10 looks for a vehicle identifier in the message; checks whether the vehicle identifier is an identifier recorded on the distributed ledger stored in another vehicle 2; obtains a public key for the vehicle identifier recorded on the distributed ledger; and checks whether a digital signature is consistent with the plaintext and the public key (step 308 of the method). If the digital signature is verified, the processor treats the data message as a message from a trusted vehicle, and stores the contents of the message in the memory 12 (step 310 of the method). On the other hand, if the digital signature is not consistent with the plaintext and the public key (i.e. the digital signature cannot be verified), the processor discards the message (step 312 of the method). Figure 3b Figure 3a Figure 3b Figure 3b

[0050] According to one option, the local memory 12 can include a local copy of a recent version of the distributed ledger (e.g. updated at the start of the day before any driving operation of the autonomous vehicle 2 is started); and the processor 10 uses this local copy to check whether a vehicle identifier indicated in a message is an identifier recorded on the distributed ledger, and to obtain a public key for the vehicle identifier recorded on the distributed ledger. According to another option, the processor 10 controls generation and transmission of a message via the one or more transceiver devices 18, the message requesting this information from a remote memory (not shown) located outside the vehicle 2, such as a distributed ledger, via e.g. a radio access network.

[0051] ​​​​​​​In this way, the memory 12 becomes populated with information from a plurality of trusted vehicles in the vicinity of the road junction 4 about the current state of traffic with respect to a particular location, system and / or situation (e.g. the traffic control signal system 6). The processor 10 determines a consensus about the state of traffic with respect to a particular location, system and / or situation (e.g. the traffic control signal system 6) from this information stored in the memory 12, and controls the operation of one or more actuators 14 based on the determined consensus, even if the determined consensus happens to be inconsistent with the output of the vehicle’s own sensors 16 Figure 3b Step 314 of the method of Figure 3.

[0052] In situations where only authenticated vehicles are permitted to use the road junction 4, and each authenticated vehicle is typically configured to operate in accordance with a consensus about the state of the traffic control signal, the consensus does not even have to be consistent with the actual state of the traffic control signal. For example, if all vehicles using the road junction at the same time follow a consensus indicating “go” for the east-west direction and “stop” for the north-south direction, the vehicles can still safely cross the road junction in the east-west direction (i.e. contrary to the actual state of the traffic control signal) even if the actual state of the traffic control signal indicates “go” for vehicles in the north-south direction and “stop” for vehicles in the east-west direction.

[0053] In another example, based on the system described in Figure 3a and 3b an autonomous vehicle can operate with the traffic control signal system 6 at the road junction 4 without any visible traffic lights.

[0054] In this case, sensors for traditional traffic lights and signs can be removed from road intersections (e.g., road intersection 4), with one or more autonomous vehicles operating in coordination at, for example, road intersection 4 based on consensus established between the one or more vehicles and one or more fixed control points. In such a traffic system, the one or more control points need not be blockchain nodes - the one or more control points can be equipped with signal devices configured for local and independent operation without needing to participate in the consensus process. However, in another embodiment, one or more control points (such as an intersection, e.g., a road intersection, a pedestrian crossing, or a railway crossing, etc.) can include one or more fixed traffic nodes of its own local blockchain, thereby establishing consensus for one or more proximate vehicles and the one or more control points. These fixed traffic nodes can observe nearby traffic and thereby send transactions to the local chain. To increase security in the event of any malicious attack on the fixed traffic nodes, the fixed traffic nodes can also be recorded as authenticated nodes on the same distributed ledger (or another distributed ledger) (e.g., nodes that have been authenticated by a government agency), so that the consensus votes of these fixed traffic nodes can be verified by means of digital signatures using public keys recorded on the distributed ledger. These fixed traffic nodes can participate in the consensus mechanism differently than the vehicle nodes. For example, the votes of the fixed traffic nodes can simply determine the consensus that the vehicles are to follow (regardless of how many other vehicle nodes can vote differently), or the votes of the fixed traffic nodes can have greater weight than the votes of the vehicle nodes, such that more than a majority of vehicle nodes is needed to establish a consensus opposite to the votes of the fixed traffic nodes. More functionality can be incorporated into the fixed traffic nodes, such as the ability to mine information into the distributed ledger. The fixed traffic nodes include one or more functions and elements similar to the examples of the apparatus shown. Figure 2

[0055] In another example, the same techniques described with respect to Figure 3a and 3b can be used to establish consensus among vehicles with respect to an order of arrival at a road intersection, the order of arrival indicating which vehicle has priority for the road intersection.

[0056] In another example, in the case of a traditional vehicle (where a human user fully controls operation of the vehicle) or a semi-autonomous vehicle (where a human user partially monitors control of the vehicle's operation by one or more processors), information about the consensus can be communicated to the user of the vehicle via one or more presentation devices. In the case of a fully autonomous vehicle, the consensus can not need to be communicated to the user of the vehicle. Instead, the one or more processors automatically control operation of the vehicle based on the consensus itself, by controlling operation of, for example, brakes, steering, speed controls, etc., or any combination thereof, without the need for monitoring or intervention by the user of the vehicle.​

[0057] The above mentioned distributed ledger and the main distributed ledger can be permissioned ledgers taking the form of a blockchain for which the addition of a new block, e.g. the output of a sensor, the current state of traffic or an established consensus, requires the approval of a predetermined number of legal entities recorded in one or more blocks of the blockchain upon authentication of the legal entities. A secure and reliable vote on the addition of a new block to the blockchain can for example be implemented by using a public-private key pair, the public key of which is recorded in one or more existing blocks of the blockchain and each legal entity can verify by means of the public-private key pair whether a vote is a vote of another legal entity having voting rights.

[0058] One example of an authentication scheme is an origin authentication scheme according to which an origin block of the blockchain identifies an administrator of the blockchain. The origin block can comprise a smart contract specifying that no new administrator can be added. Alternatively, the origin block can comprise a smart contract allowing the addition of a new administrator and / or the removal of an existing administrator under one or more conditions, such as the approval of a majority of existing administrators. Again, a secure and reliable vote on the addition of a new block to the blockchain can for example be implemented by using a public-private key pair, the public key of which has been recorded in one or more existing blocks of the blockchain and each administrator can verify by means of the public-private key pair whether a vote is a vote of another administrator having voting rights.

[0059] Another example of an authentication scheme is a hierarchical authentication scheme according to which the blockchain designates a collaboration of government agencies as top-level administrators, each of which has the right to add a new block to the blockchain to nominate one or more selected entities as an authentication agency having the right to add and / or remove vehicles from the record of authenticated vehicles.

[0060] Yet another example of an authentication scheme is a user-invitation-based authentication scheme in which only invited users are allowed to add and / or remove vehicles from the record of authenticated vehicles. For example, a vehicle manufacturer can establish a public blockchain for which the administration is private. Each vehicle manufacturer can control one or more private keys that enable them to add and / or remove vehicles from the record of authenticated vehicles. According to a variant, a government agency controls private keys whose public keys are recorded in one or more blocks of the blockchain as keys granting the right to administer any aspect of the blockchain, and vehicle manufacturers control private keys whose public keys are recorded as keys having limited rights, such as the right to add and / or remove vehicles from the record of authenticated vehicles.

[0061] Consensus on the extension of the blockchain can be achieved by using a majority or Byzantine fault tolerant consensus mechanism. Such consensus mechanisms are energy efficient and ensure that only parties interested in the proper functioning of the system can participate in the maintenance of the blockchain.

[0062] Figure 4 A set of operations at a processor of a node associated with, for example, an automobile manufacturer, the processor of the node controlling a private key whose public key counterpart is recorded on the blockchain as being authorized to add vehicles to and / or remove vehicles from a record of authenticated vehicles, is shown. The node processor controls the generation and sending of one or more digitally signed messages to other authentication nodes in the blockchain network, the messages publishing one or more transactions involving one or more public keys associated with one or more respective unique vehicle identifiers Figure 4 Step 400). The digital signature is created from all or part of the plaintext of the message using a private key controlled by the node processor, the public key counterpart of the private key being recorded on the blockchain as being associated with a node having the authority to add vehicles to and / or remove vehicles from the record of authenticated vehicles. Each authentication node receiving the digitally signed message checks the validity of the certificate by verifying that the digital signature is consistent with the plaintext of the message and the public key of the identified sender of the message recorded on the blockchain. If the verification is successful, the certificate is considered valid and the authentication node issues a digitally signed message indicating that the certificate(s) is valid and constitutes a vote for the authentication to be added to the distributed ledger. When a sufficient number of authentication nodes have verified the certificate(s) (i.e. have voted in favor of adding the authentication to the blockchain) to comply with the consensus conditions listed in one or more existing blocks of the blockchain, there is consensus to extend the blockchain to a new block of authenticated vehicle identifiers and associated public keys Figure 4 Step 402).

[0063] According to one example embodiment, all observations received at the vehicle from trusted vehicles (i.e. all observations in received messages signed with a private key whose public key counterpart is recorded on the distributed ledger) are recorded in a new block of the local blockchain maintained by the processor 10 of the vehicle. Figure 5 One implementation example is shown in Figure 4. Majority proof Figure 5The "proof" (in the sense of a "proof-of-stake" consensus mechanism) includes a Merkle tree of observations received from other autonomous vehicles. Each observation serves as a consensus vote, as well as a record of the observation in the form of a blockchain, where each block is linked to a previous block by a one-way function such as a hash function, which serves as an immutable record of consensus on the operation of the vehicle. Observations can be bundled into blocks based on timestamps. Alternatively, each observation is recorded in a respective block of the blockchain. In Figure 5 In the "observation hash" is a hash of the current state of the local ledger; for example, the hash value can be computed by updating the key values based on the observations found in the "proof" Merkle tree. The method for updating the observation tree can be predefined in the ledger code itself, or accomplished via a smart contract.

[0064] The record of observations maintained by each trusted vehicle in a separate blockchain can later be linked into the main chain of the distributed ledger that forms the record of public keys of the certified vehicles. In Figure 6 An implementation example is shown in FIG. 1. The main chain of the distributed ledger can include blocks that record the Merkle hash generated from the Merkle tree of the separate blockchain (side chain) maintained by multiple trusted vehicles. In different embodiments, blocks from the local blockchain rather than the entire chain itself are added to the main chain. Figure 6 Also shown in the same main chain of the distributed ledger are records of the above-mentioned certification transactions involving the certification of vehicle identifiers and their associated public keys. The "certification hash" is a field of the blocks of the main chain of the distributed ledger and contains the Merkle hash of all certification transactions. A different field of the blocks, called the "side chain hash," contains the Merkle hash of all side chains that are linked to the main chain of the distributed ledger.

[0065] The record of information on the observations of the operation of the vehicles (in the form of a blockchain or the like) can be helpful in identifying sensor systems that are persistently problematic in autonomous vehicles, e.g., one or more problematic or faulty sensors in the vehicle, and / or one or more problematic or faulty vehicles in the system. One or more blocks of the main chain of the distributed ledger can record one or more smart contracts that specify on the blockchain the revocation of the record of certification of any vehicle identifier and / or any sensor identifier (and associated public key), where the record of observations maintained by each vehicle together indicates poor performance or a fault in the sensor (e.g., as evidenced by observations that are inconsistent with the consensus). This can facilitate the removal of faulty vehicles from the road until they are repaired to address the faults evidenced by the record of observations.

[0066] The combination of (i) the above-described observation records in the form of independent blockchains on each of the trustworthy vehicles and (ii) the above-described establishment of links between the independent blockchains and the main chain of the distributed ledger makes it virtually impossible for any vehicle to change its observation record without being detected.

[0067] The embodiments of the application have been described above with respect to the example of establishing a consensus regarding the status of a traffic signal at a traffic intersection. However, the same techniques are also applicable to, for example, (a) establishing a consensus regarding which of a plurality of vehicles at a traffic intersection (road crossing) enjoys priority to proceed at the traffic intersection (road crossing), (b) establishing a consensus regarding which of a plurality of vehicles in a traffic lane is permitted to have another vehicle outside the lane join in front of it in the lane (e.g., to move between lanes of a multi-lane highway / motorway); (c) establishing a consensus regarding how to interpret other traffic signals or signs; and (d) establishing a consensus regarding reporting of traffic accidents or other abnormal situations (such as a malfunctioning sensor).

[0068] Autonomous vehicles generally follow a predetermined route, which can include any number of control points (e.g., traffic signals, intersections, etc.), at each of which a local chain is established among the vehicles entering. This local chain can establish an order in which the vehicles travel at the control point. The control point can be considered a pause in the operation of the autonomous vehicles along the predetermined route. At each control point, the blockchain determines when this pause can end, and the vehicles can again travel along the determined route. There is no limit to the rate at which vehicles traverse the control point; however many vehicles arrive at the control point in a unit of time, the arrival of the vehicles at the control point can be treated as a discrete event, and the consensus protocol described above can be effective. The consensus blockchain can supplement existing traffic rules. In the case of control points that have options regarding the order of travel of multiple vehicles, the decision process can be expedited by prior negotiation. Regardless of whether the control point is at the location of a traffic signal, intersection, etc., each control point is treated by the vehicles as a trigger for a particular driving procedure. For example, the function of a traffic light that indicates vehicle operation (i.e., whether to travel) or a traffic sign such as a stop sign or yield sign can be emulated in the consensus technique using blockchain mentioned above. In the case of the consensus technique described above, the vehicles also take into account the consensus (in addition to or instead of their own observation of the traffic light state). Thus, the consensus technique using blockchain mentioned above resolves potential conflicts between two or more vehicles by reaching a consensus regarding the order of travel of the vehicles at locations where cooperation between the vehicles is required. There can still be a need to rely on the sensor output of the vehicles themselves. For example, in the case where the sensor output of a vehicle indicates that another vehicle is not adhering to the established consensus, the autonomous vehicle can decide to take action that violates the consensus (e.g., not travel even though the established consensus indicates priority for that vehicle) in order to avoid an accident. The other vehicle or the operator of the other vehicle that is observed to not adhere to the consensus can be penalized to incentivize use of the protocol.

[0069] A computer program code product adapted in a suitable way can be used to implement various embodiments when loaded into a computer. The program code product for providing the operation can be stored on a carrier or storage medium, such as a carrier disc, card or tape, and provided by means of the carrier or storage medium. One possibility is to download the program code product via a data network. The implementation can be provided by suitable software in a server. In addition, the carrier or storage medium can be a non-transitory computer-readable storage medium carrying one or more sequences of one or more instructions which, when executed by one or more processors, cause an apparatus or system to perform at least in accordance with the program code product.

[0070] The example embodiments of the invention can be practiced alone or in any combination to provide additional features and / or more complex systems as necessary to ensure proper solutions for a wide and complex range of problems.

[0071] Example embodiments of the application can be practiced in various components such as integrated circuit modules. The design of integrated circuits is by nature a highly automated process. Complex and powerful software tools are available for converting a logic level design into a semiconductor circuit design ready to be etched and formed on a semiconductor substrate.

[0072] Programs, such as those provided by Synopsys, Inc. of Mountain View, California and Cadence Design, of San Jose, California automatically route conductors and locate components on a semiconductor chip using well-established rules of design as well as libraries of pre-stored design modules. Once the design for a semiconductor circuit has been completed, the resultant design, in a standardized electronic format (e.g., Opus, GDSII, or the like) can be transmitted to a semiconductor fabrication facility or "fab" for fabrication.

[0073] In addition to the modifications mentioned above, it will be apparent to those skilled in the art that various other modifications can be made within the scope of the present application.

Claims

1. A method for operating a vehicle, comprising: The operation of a first vehicle at a specific location is controlled, at least in part, based on information from one or more sensor outputs of one or more trusted vehicles near or at the specific location, the information being recovered from one or more radio transmissions from one or more vehicles included in a record that can be verified as originating from an authenticated vehicle. Wherein, if the digital signature of the information is verified, the information is considered to originate from a trusted vehicle; including the following steps: Based on the information from multiple trusted vehicles near or at the specific location, determine the current state of traffic at the specific location; A consensus is reached to determine the current state of traffic at the specific location, wherein the operation of one or more actuators of the first vehicle is controlled based on the determination of the consensus, and wherein information received from the one or more trusted vehicles is stored in the memory of the first vehicle for use in determining the consensus. The operation of one or more of the actuators determines the speed and direction of the first vehicle.

2. The method of claim 1, wherein the record of the certified vehicle includes a local copy of a distributed ledger stored in the memory of the first vehicle, or a copy of a distributed ledger stored in a remote memory accessible by the first vehicle via a communication network, wherein the distributed ledger is in the form of a blockchain.

3. The method according to claim 2, further comprising: The addition of one or more new blocks to the blockchain is controlled, based at least in part on the information output by the one or more sensors of one or more other trusted vehicles.

4. The method according to claim 3, comprising: For each radio transmission that can be verified as a radio transmission made by a vehicle recorded as an authenticated vehicle on the distributed ledger, control adds a new block to the blockchain.

5. The method according to claim 3, comprising: For each radio transmission that can be verified as a radio transmission made by a vehicle recorded as an authenticated vehicle on the distributed ledger, control adds a new block to the blockchain.

6. The method of claim 2, comprising: Based on information recovered from one or more radio transmissions of the vehicle included in the record for each verifiable certified vehicle, regarding sensor outputs of one or more other trusted vehicles, control is used to add one or more new blocks to the blockchain; and The operation of controlling the first vehicle includes: identifying a consensus among the one or more certified vehicles regarding one or more external conditions from the information output by the one or more sensors.

7. The method of claim 6, wherein the consensus among the one or more certified vehicles regarding one or more external conditions comprises: A consensus on how to coordinate transportation within a transportation system.

8. A device for operating a vehicle, comprising: The device comprises at least one processor and at least one memory, the at least one memory including computer program code, wherein the at least one memory and the computer program code are configured together with the at least one processor to enable the device to: The operation of a first vehicle at a specific location is controlled, at least in part, based on information from one or more sensor outputs of one or more trusted vehicles near or at the specific location, the information being recovered from one or more radio transmissions from one or more vehicles included in a record that can be verified as originating from an authenticated vehicle. Wherein, if the digital signature of the information is verified, the information is considered to originate from a trusted vehicle; including the following steps: Based on the information from multiple trusted vehicles near or at the specific location, determine the current state of traffic at the specific location; A consensus is reached to determine the current state of traffic at the specific location, wherein the operation of one or more actuators of the first vehicle is controlled based on the determination of the consensus, and wherein information received from the one or more trusted vehicles is stored in the memory of the first vehicle for use in determining the consensus. The operation of one or more of the actuators determines the speed and direction of the first vehicle.

9. The apparatus of claim 8, wherein the record of the authenticated vehicle comprises a local copy of a distributed ledger stored in the memory of the first vehicle, or a copy of a distributed ledger stored in a remote memory accessible by the first vehicle via a communication network, wherein the distributed ledger is in the form of a blockchain.

10. The apparatus of claim 9, wherein the at least one memory and the computer program code are configured, together with the at least one processor, to further enable the apparatus to: The addition of one or more new blocks to the blockchain is controlled, based at least in part on the information output by the one or more sensors of one or more other trusted vehicles.

11. The apparatus of claim 10, wherein the at least one memory and the computer program code are configured, together with the at least one processor, to control the addition of a new block to the blockchain for each radio transmission verifiable as a radio transmission made by a vehicle recorded as an authenticated vehicle on the distributed ledger.

12. The apparatus of claim 10, wherein the at least one memory and the computer program code are configured, together with the at least one processor, to control the addition of a new block to the blockchain for each radio transmission verifiable as a radio transmission made by a vehicle recorded as an authenticated vehicle on the distributed ledger.

13. The apparatus of claim 9, wherein the at least one memory and the computer program code are configured to, together with the at least one processor, enable the apparatus to: Based on information recovered from one or more radio transmissions of the vehicle included in the records of each verifiable certified vehicle, regarding sensor outputs of one or more other trusted vehicles, control is exercised to add one or more new blocks to the blockchain; and The operation of controlling the first vehicle includes: From the information output by the one or more sensors, identify a consensus among the one or more certified vehicles regarding one or more external conditions.

14. The apparatus of claim 13, wherein the consensus among the one or more certified vehicles regarding one or more external conditions comprises: A consensus on how to coordinate transportation within a transportation system.

15. A non-transient computer-readable storage medium carrying one or more sequences of one or more instructions, said one or more sequences of instructions causing a device to perform the method as described in any one of claims 1 to 7 when executed by one or more processors.

Citation Information

Patent Citations

  • Driving support system and on-vehicle information processing apparatus

    JP2016143092A

  • Consensus system and method for adding data to a blockchain

    US20170075941A1

  • Method for operating a central server and method for handling a rule chart

    WO2016055560A1