Server, information processing system, and information processing method
Through the coordination of remote monitoring of servers and the coordination of control program updates, the problem of driving judgment after the driver is not in the car room in autonomous driving vehicles is solved, and safe and reliable driving start is achieved.
Patent Information
- Application Number
- CN202211039492.6
- Authority / Receiving Office
- CN · China
- Patent Type
- Patents(China)
- Current Assignee / Owner
- Priority Date
- 2021-10-26
- Filing Date
- 2022-08-29
- Publication Date
- 2025-07-22
- Estimated Expiration
- 2042-08-29
AI Technical Summary
In autonomous driving vehicles, the driver is not in the car room. How to determine whether the control program can be safely driven after the update has become a problem, and the existing technology has not effectively solved it.
Monitor the autonomous vehicle through the server, the remote monitor operates the input device, the output device prompts the control program to change content, and notifies the vehicle to allow driving after the remote monitor allows it, so as to coordinate remote monitoring and control program updates.
It realizes that the driving of autonomous vehicles is properly started after the control program is updated to ensure safety and reliability.
Smart Images

Figure CN116032956B_ABST
Abstract
Description
Technical Field
[0001] The present disclosure relates to a server and an information processing method, and more particularly to a server for managing the operation of an autonomous vehicle, an information processing system including the server, and an information processing method for managing information related to the operation of an autonomous vehicle using the server. Background Art
[0002] Japanese Unexamined Patent Application Publication No. 2018-132979 discloses a software update system for managing updates of software of a control device mounted on a vehicle. This system updates software through wireless communication (so-called OTA (Over The Air)). Summary of the Invention
[0003] The inventors of the present disclosure have focused on the following problem that may occur after an update of a control program of a control device mounted on a vehicle. In a conventional vehicle, since the driver is in the vehicle interior, the driver can judge whether it is possible to start the vehicle operation on the basis of confirming how the control program is changed. On the other hand, an autonomous vehicle can be monitored from the outside of the autonomous vehicle. That is, in an autonomous vehicle, the driver is not necessarily in the vehicle interior. Therefore, it may be a problem how to judge whether it is possible to start the vehicle operation after the update of the control program. Regarding such a situation, no research has been conducted in Japanese Unexamined Patent Application Publication No. 2018-132979.
[0004] The present disclosure has been made to solve the above problems, and an object of the present disclosure is to appropriately start the operation of an autonomous vehicle after an update of a control program of a control device mounted on the autonomous vehicle.
[0005] (1) A server according to an aspect of the present disclosure monitors an autonomous vehicle. The autonomous vehicle is configured to obtain a control program of a control device mounted on the autonomous vehicle from a control center through wireless communication. The server includes: an input device that receives an operation of a remote monitor who monitors the autonomous vehicle from the outside of the autonomous vehicle; an output device that presents information to the remote monitor; a communication device configured to be able to communicate with the autonomous vehicle; and a processor that controls the input device, the output device, and the communication device. When the control program of the autonomous vehicle is updated, the processor controls the output device so that the server presents the change content of the control program to the remote monitor. When the input device has received an operation of the remote monitor permitting the autonomous vehicle to travel according to the updated control program, the processor controls the communication device to notify the autonomous vehicle of the permission to travel.
[0006] (2) The processor controls the output device to present the functions of the autonomous vehicle before the update of the control program and the functions of the autonomous vehicle after the update of the control program to the remote monitor in a comparable manner.
[0007] (3) The processor controls the output device to prompt the remote monitor with the changed content related to the information used by the remote monitor when monitoring the autonomous vehicle.
[0008] (4) The server manages the operation of multiple vehicles each equipped with multiple control devices. The changed content includes information for determining the vehicle in which the control program is updated among the multiple vehicles, and conditions for determining the control device in which the control program is updated among the multiple control devices mounted on the vehicle.
[0009] (5) The information processing system according to another aspect of the present disclosure includes the above server and the autonomous vehicle.
[0010] (6) The autonomous vehicle waits for a notification of permission to drive from the server and then starts driving.
[0011] (7) An information processing method according to still another aspect of the present disclosure uses a server to monitor an autonomous vehicle. The autonomous vehicle is configured to obtain the control program of the control device mounted on the autonomous vehicle from a control center via wireless communication. The information processing method includes a first step and a second step. The first step is as follows: when the control program of the autonomous vehicle is updated, the server prompts the remote monitor who monitors the autonomous vehicle from outside the autonomous vehicle with the changed content of the control program. The second step is as follows: when the remote monitor performs an operation to permit the autonomous vehicle to drive according to the updated control program, a notification of permission to drive is sent to the autonomous vehicle.
[0012] According to the present disclosure, it is possible to appropriately start the driving of the autonomous vehicle after the update of the control program of the control device mounted on the autonomous vehicle. BRIEF DESCRIPTION OF THE DRAWINGS
[0013] The features, advantages, and technical and industrial significance of the exemplary embodiments of the present invention will be described below with reference to the accompanying drawings, in which the same reference numerals denote the same elements, and:
[0014] Figure 1 is a diagram showing the schematic structure of the information processing system of the present embodiment.
[0015] Figure 2 is a block diagram showing the typical hardware structure of a vehicle.
[0016] Figure 3 is a block diagram showing the typical hardware structure of a server.
[0017] Figure 4 is a functional block diagram showing the functional structure of the server related to the update of the control program.
[0018] Figure 5 is a functional block diagram showing the functional structure of a server related to the updated start of driving of a control program.
[0019] Figure 6 is the first flow chart for explaining the flow of processing executed by the information processing system.
[0020] Figure 7 is a diagram showing an example of an image displayed on a display before asking a running manager whether a control program can be updated.
[0021] Figure 8 is a diagram showing an example of an image displayed on a display when asking a running manager whether a control program can be updated.
[0022] Figure 9 is the second flow chart for explaining the flow of processing executed by the information processing system.
[0023] Figure 10 is a diagram showing an example of an image displayed on a display before asking a remote monitor whether the vehicle can start driving.
[0024] Figure 11 is a diagram showing an example of an image displayed on a display when asking a remote monitor whether the vehicle can start driving. Detailed Description of the Embodiment
[0025] Hereinafter, embodiments of the present disclosure will be described in detail with reference to the drawings. In addition, the same or corresponding parts in the drawings are given the same reference numerals, and their description will not be repeated.
[0026] [Embodiment]
[0027] <Schematic Structure of Information Processing System>
[0028] Figure 1 is a diagram showing the schematic structure of the information processing system according to the present embodiment. The information processing system 100 includes a server 1, a control center 2, and a plurality of vehicles 3A, 3B, 3C. Hereinafter, for the sake of convenience of explanation, any one of the vehicles 3A, 3B, 3C will be described as the vehicle 3. In addition, Figure 1 three vehicles 3 are shown, but the number of vehicles 3 is an arbitrary value.
[0029] The server 1 is, for example, the company server of an operator (bus operator, taxi operator, carpooling service operator, etc.) that manages the operation of the vehicle 3. The server 1 may also be a shared server shared by a plurality of operators including the operator. The server 1 may also be a cloud server provided by a cloud server management company.
[0030] Server 1 is used by the operator of the operation of vehicle 3 and also by the remote monitor of vehicle 3. The operator, for example, refers to a staff member (so-called upper-level manager) who has the authority to update the control program of vehicle 3 and works for an enterprise that manages the operation of vehicle 3. The remote monitor refers to a staff member (so-called operator) who remotely monitors vehicle 3 and appropriately operates vehicle 3. The operator and the remote monitor are usually different people, but they can also be the same person. In this example, the situation where the operator and the remote monitor are the same person is assumed for explanation.
[0031] The control center 2 is a server of an operator (such as a vehicle manufacturer) that provides a control program for the ECU (Electronic Control Unit) 31 (refer to Figure 2 ) mounted on vehicle 3.
[0032] Each vehicle 3 is an autonomous vehicle. Each vehicle 3 is used for the service provided by the above operator. The type (model) of vehicle 3 is appropriately selected according to the service provided by the operator. In this example, vehicle 3 is a bus. Server 1, control center 2, and each vehicle 3 are connected to be able to communicate with each other via a wired or wireless network NW.
[0033] <Hardware Structure of Vehicle>
[0034] Figure 2 is a block diagram showing a typical hardware structure of vehicle 3. Vehicle 3 includes an ECU 31, an autonomous driving system 32, a sensor group 33, a navigation system 34, and a DCM (Data Communication Module) 35. The ECU 31, autonomous driving system 32, sensor group 33, navigation system 34, and DCM 35 are interconnected by a wired in-vehicle network such as CAN (Controller Area Network) or Ethernet (registered trademark).
[0035] The ECU 31 includes a processor 311 and a memory 312. The memory 312 includes a ROM (Read Only Memory) 312A, a RAM (Random Access Memory) 312B, and a flash memory 312C. The processor 311 controls the overall operation of vehicle 3 by executing a control program. The memory 312 stores software executed by the processor 311. In particular, the flash memory 312C stores a control program updated by OTA. In addition, the flash memory 312C can also be other rewritable non-volatile memories.
[0036] The ECU 31 controls the device class in such a way that the vehicle 3 becomes a desired state based on signals from the sensor group 33 and the like. While coordinating with the autonomous driving system 32, the ECU 31 outputs instructions for controlling various systems. Although the various systems are not shown, they may include a brake system, a steering system, a power transmission system (e.g., an electric parking brake system, a parking lock system, a shift device, an electric generator), a body system (e.g., a direction indicator, a horn, a wiper), etc.
[0037] The ECU 31 sends various information indicating the state of the vehicle 3 to the server 1 or sends various requests to the server 1 via the DCM 35. In addition, the ECU 31 receives instructions or notifications from the server 1 via the DCM 35. In addition to this, in the present embodiment, the ECU 31 receives (downloads) a control program from the control center 2 via the DCM 35 and installs the downloaded control program in the memory 312 at an appropriate timing. Then, the ECU 31 activates the installed control program at an appropriate timing. In addition, the ECU 31 may be divided into multiple ECUs for each function. In the example described later (refer to Figure 8 ), the ECU 31 includes a camera ECU.
[0038] The autonomous driving system 32 is configured to be able to achieve autonomous driving of the vehicle 3. Autonomous driving means that the operation of the vehicle 3 is performed without depending on the driving operation of the driver of the vehicle 3 (driverless). In this example, the autonomous driving system 32 is configured to be able to perform fully autonomous driving of the vehicle 3. However, autonomous driving may also include control that supports the driving operation of the driver of the vehicle 3 during operations such as acceleration, deceleration, and steering of the vehicle 3 (driver-assisted). The autonomous driving system 32 may also be a part of the ECU 31.
[0039] The sensor group 33 includes sensors configured to detect the external condition of the vehicle 3 and sensors configured to detect information corresponding to the driving state of the vehicle 3 and steering operations, accelerator operations, and brake operations (not shown). Specifically, the sensor group 33 may include, for example, a camera, a radar, a LIDAR (Laser Imaging Detection and Ranging), a vehicle speed sensor, an acceleration sensor, a yaw rate sensor (not shown).
[0040] The navigation system 34 includes a GPS (Global Positioning System) receiver (not shown). The GPS receiver determines the position of the vehicle 3 based on radio waves from artificial satellites (not shown). The navigation system 34 performs navigation processing of the vehicle 3 using the position information of the vehicle 3 determined by the GPS receiver.
[0041] DCM35 is a vehicle communication module. DCM35 is configured to enable bidirectional data communication between ECU31 and server 1, and to enable bidirectional data communication between ECU31 and control center 2.
[0042] <Hardware Structure of Server>
[0043] Figure 3 It is a block diagram showing a typical hardware structure of server 1. Server 1 includes a processor 11, a memory 12, a keyboard 13, a mouse 14, a camera 15, a display 16, and a communication interface (IF) 17. Memory 12 includes a ROM 121, a RAM 122, and an HDD (Hard Disk Drive) 123. The processor 11, the memory 12, the keyboard 13, the mouse 14, the camera 15, the display 16, and the communication IF 17 are interconnected using a bus.
[0044] Processor 11 controls the overall operation of server 1. Memory 12 stores an operating system and application programs executed by processor 11. Keyboard 13 and mouse 14 receive user input. Camera 15 captures the operator of server 1. In the present embodiment, the operator of server 1 is the vehicle 3 operation manager or remote monitor. Display 16 displays various information to the operator of server 1. Communication IF 17 is configured to enable communication with control center 2 and each vehicle 3.
[0045] In addition, at least one of keyboard 13 and mouse 14 corresponds to the "input device" of the present disclosure. The "input device" may also be an operation terminal dedicated to vehicle operation management, a touch panel, a microphone, etc. At least one of display 16 and communication IF 17 corresponds to the "output device" of the present disclosure. The "output device" may also be a speaker, for example. At least one of keyboard 13, mouse 14, and camera 15 corresponds to the "authentication device" of the present disclosure.
[0046] <Travel after Update of Control Program>
[0047] In a conventional manned vehicle, since the driver is in the vehicle interior, the driver can judge whether it is possible to start the vehicle operation based on confirming how the control program is changed. On the other hand, vehicle 3 as an autonomous vehicle is monitored from outside vehicle 3, and there is no driver in the vehicle interior. Therefore, how to judge whether it is possible to start vehicle 3 operation after the update of the control program may become a problem.
[0048] In this embodiment, after the update of the control program, the server 1 (processor 11) displays the changed content of the control program on the display 16. Then, when the remote monitor operates the keyboard 13 or the mouse 14 to permit the vehicle 3 with the updated control program to travel, the server 1 notifies the vehicle 3 of the permission to travel. The vehicle 3 waits to receive the notification of the permission to travel from the server 1 and then starts to travel. Thus, even when there is no one in the vehicle 3, the vehicle 3 can start to travel appropriately after the update of the control program.
[0049] <Functional Structure of Server>
[0050] Figure 4 FIG. is a functional block diagram showing the functional structure of the server 1 related to the update of the control program. The server 1 includes a communication unit 41, an arithmetic processing unit 42, an input unit 43, a display unit 44, and a photographing unit 45. The arithmetic processing unit 42 is a functional block implemented by the processor 11 executing the operating system and application programs stored in the memory 12. The arithmetic processing unit 42 includes a communication control unit 421, a notification unit 422, an operation reception unit 423, an image generation unit 424, a storage unit 425, and an authentication unit 426.
[0051] The communication unit 41 communicates with the outside (the control center 2 and / or the vehicle 3). More specifically, the communication unit 41 receives the update condition of the control program of the ECU 31 of the vehicle 3 from the outside. The details of the update condition will be described later. In addition, the communication unit 41 sends a notification indicating whether the operation manager of the vehicle 3 who has confirmed the update condition of the control program permits the update of the control program (agree / refuse) to the outside. In addition, the communication unit 41 corresponds to Figure 3 the communication IF17.
[0052] The communication control unit 421 controls the communication with the outside via the communication unit 41. The communication control unit 421 outputs the update condition of the control program received by the communication unit 41 to the image generation unit 424, or sends the notification generated by the notification unit 422 from the communication unit 41 to the outside.
[0053] The operation reception unit 423 outputs the input operation performed by the operation manager of the vehicle 3 on the input unit 43 to the notification unit 422 or the authentication unit 426. More specifically, the operation reception unit 423 outputs the result of whether the operation manager selects to permit the update of the control program (in the example described later, the operation result of the yes button / no button) to the notification unit 422. The operation reception unit 423 can also output the password input by the operation manager to the authentication unit 426. In addition, the input unit 43 corresponds to Figure 3 the keyboard 13 or the mouse 14.
[0054] The image generation unit 424 generates an image representing the update condition of the control program received by the communication control unit 421. In addition, the image generation unit 424 generates an image for the operation manager who has confirmed the update condition to select whether to allow the update of the control program. The display unit 44 displays the image generated by the image generation unit 424 for the operation manager. In addition, the display unit 44 corresponds to Figure 3 the display 16.
[0055] The imaging unit 45 images the operation manager of the vehicle 3 and outputs the captured image to the authentication unit 426. In addition, the imaging unit 45 corresponds to Figure 3 the camera 15.
[0056] The storage unit 425 stores data for authenticating the operation manager of the vehicle 3. The authentication method of the operation manager is not particularly limited, and various known methods can be adopted. In this example, the storage unit 425 stores the feature amounts for face authentication of the operation manager. The storage unit 425 may also store data for other biometric authentications (fingerprint authentication, iris authentication, voice authentication, etc.). The storage unit 425 may also store the password set by the operation manager.
[0057] The authentication unit 426 authenticates the operation manager based on the image captured by the imaging unit 45 and the feature amounts stored in the storage unit 425. The authentication unit 426 may also authenticate the operation manager based on the password input to the input unit 43 and the password stored in the storage unit 425. The authentication unit 426 outputs the authentication result to the notification unit 422.
[0058] When the authentication unit 426 authenticates that the operator of the operation server 1 is a legitimate operation manager registered in advance, the notification unit 422 generates a notification indicating whether the operation manager allows the update of the control program. More specifically, when the operation manager performs an operation to allow the update of the control program (when the button is pressed), the notification unit 422 generates an update approval notification for the control program. On the other hand, when the operation manager performs an operation not to allow the update of the control program (when the no button is pressed), the notification unit 422 generates an update rejection notification for the control program. The notification generated by the notification unit 422 is output to the communication control unit 421 and sent from the communication unit 41 to the outside.
[0059] Figure 5It is a functional block diagram showing the functional structure of server 1 related to the updated start of driving of the control program. Server 1 includes a communication unit 51, an arithmetic processing unit 52, an input unit 53, and a display unit 54. Similar to arithmetic processing unit 42, arithmetic processing unit 52 is a functional block implemented by a processor 11 executing an operating system and application programs stored in a memory 12. Arithmetic processing unit 52 includes a communication control unit 521, a notification unit 522, an operation reception unit 523, and an image generation unit 524.
[0060] Communication unit 51 conducts communication with the outside. Communication unit 51 receives the change content of the control program from the outside. The details of the change content will be described later. In addition, communication unit 41 sends a notification indicating whether a remote monitor of vehicle 3 who has confirmed the change content of the control program permits (permits / forbids) the start of driving (restart of driving) of vehicle 3 to the outside. In addition, communication unit 51 corresponds to Figure 3 communication IF17.
[0061] Communication control unit 521 controls communication with the outside via communication unit 51. Communication control unit 521 outputs the change content of the control program received by communication unit 51 to image generation unit 524, or sends the notification generated by notification unit 522 from communication unit 51 to the outside.
[0062] Operation reception unit 523 outputs the input operation performed by the remote monitor of vehicle 3 to input unit 53 to notification unit 522. More specifically, operation reception unit 523 outputs the result of whether the remote monitor selects to permit the start of driving of vehicle 3 (the operation result of the yes button / no button) to notification unit 522.
[0063] Image generation unit 524 generates an image representing the change content of the control program received by communication control unit 521. In addition, image generation unit 524 generates an image for the remote monitor who has confirmed the change content to select whether to permit the start of driving of vehicle 3 after the update of the control program. Display unit 54 displays the image generated by image generation unit 524 for the remote monitor. In addition, display unit 54 corresponds to Figure 3 monitor 16.
[0064] Notification unit 522 generates a notification indicating whether the remote monitor permits the start of driving of vehicle 3. More specifically, in the case where the remote monitor performs an operation to permit the start of driving of vehicle 3 (the case where the yes button is pressed), notification unit 522 generates a permission notification for the start of driving of vehicle 3. On the other hand, in the case where the remote monitor performs an operation not to permit the start of driving of vehicle 3 (the case where the no button is pressed), notification unit 522 generates a prohibition notification for the start of driving of vehicle 3. The notification generated by notification unit 522 is output to communication control unit 521 and sent from communication unit 51 to the outside.
[0065] <Processing Flow>
[0066] Figure 6 It is the first flow chart for explaining the processing flow executed by the information processing system 100. Figure 6 And as described later Figure 9 The flow charts shown, for example, are executed at a predetermined time interval. The processing executed by the server 1 is shown on the left, and the processing executed by the control center 2 is shown on the right. The processing on the right can also be executed by the vehicle 3. This is because the control center 2 and the vehicle 3 can communicate with each other, so the notification from the server 1 can reach the vehicle 3 via the control center 2 and can reach the control center 2 via the vehicle 3. Each step is implemented by software processing, but can also be implemented by hardware (circuit). Hereinafter, the steps are described as "S".
[0067] In S21, the control center 2 determines whether there is a control program that can be updated for the ECU 31 of the vehicle 3. When there is a control program that can be updated (Yes in S21), the control center 2 notifies the server 1 of this fact. At this time, the control center 2 also notifies the server 1 of the update conditions of the control program (described later) (S22).
[0068] When receiving the notification from the control center 2, the server 1, for example, uses the camera 15 to detect the operator of the server 1 (S11). Then, the server 1 authenticates whether the operator of the server 1 is a registered legitimate operation manager (S12). When the operator of the server 1 is authenticated (Yes in S13), the server 1 displays the update conditions of the control program on the display 16 (S14). The server 1 asks the operation manager whether the control program can be updated. Then, the server 1 accepts the operation performed by the operation manager regarding whether the control program can be updated (S15).
[0069] Figure 7 It is a diagram showing an example of the image displayed on the display 16 before asking the operation manager whether the control program can be updated. Before asking the operation manager, the driving status of each of the multiple vehicles 3 (buses in this example) under the management of the server 1 is displayed on the operation management screen of the display 16. More specifically, the time, the name of the driving route of the vehicle 3, the identification number of the vehicle 3, and the status of the vehicle 3 (such as being late compared to the time specified in the schedule, and the decrease in SOC (State Of Charge)) are displayed. In addition, a map showing the current location on the driving route of each vehicle 3 is displayed on the display 16.
[0070] Figure 8This is a diagram showing an example of the image displayed on the monitor 16 when asking the operation manager whether the control program can be updated. When asking the operation manager, a dialog box is displayed on the Figure 7 screen shown. In the dialog box, for example, information for determining the vehicle 3 (vehicle No. 1 in this example) as the object, information for determining the ECU (camera ECU) as the object, a simple explanation of the update content of the control program (responding to the addition of the dynamic image codec format), disclaimers in the case of
[0071] malfunctions in the updated control program (none in particular), and function limitations associated with the update of the control program (none in particular) are displayed. In addition, in the dialog box, for example, the scheduled update period of the control program (from 18:00 today to 8:00 the next day) and the time required for the update of the control program (about 5 minutes) are displayed.
[0072] Based on the display of the above update conditions, the server 1 asks the operation manager of the vehicle 3 whether to agree to the update of the control program. In this example, when the operation manager clicks the "Yes" button, the update of the control program is agreed (permitted). On the other hand, when the operation manager clicks the "No" button, the update of the control program is rejected (prohibited). In addition, the operation manager can judge the consent / rejection of the update based on the confirmation of the more detailed content of each update condition by clicking the "Details Confirmation" button.
[0073] Refer again to Figure 6 . When the operation manager has performed an operation to agree to the update of the control program (yes in S16), the server 1 notifies the control center 2 of the consent to the update of the control program (S18). When the control center 2 receives the notification of the consent to the update (yes in S23), and when the conditions suitable for the update of the control program are met (for example, when the vehicle 3 that has ended the service provision returns to the garage and parks), it executes the update (OTA) of the control program while coordinating with the vehicle 3 (S24). That is, the control program is downloaded from the control center 2 to the vehicle 3 and installed in the flash memory 312C of the ECU 31.
[0074] On the other hand, when the operation manager has performed an operation to reject the update of the control program (no in S16), the server 1 notifies the control center 2 of the rejection of the update of the control program (S17). The control center 2 does not execute the update (OTA) of the control program when it receives the notification of the rejection of the update (no in S23). Although not shown, when the operation to agree to the update of the control program is not performed within the time limit, the control center 2 also does not execute the update of the control program.
[0075] Figure 9This is the second flowchart for explaining the process executed by the information processing system 100. The processes executed by the server 1 are shown on the left side, and the processes executed by the vehicle 3 are shown on the right side. A part of the processes on the right side may also be executed by the control center 2. These processes are executed after updating the control program in accordance with Figure 6 the first flowchart shown.
[0076] In S41, the vehicle 3 determines whether the driving start condition of the vehicle 3 is satisfied. For example, when the start time is approaching for the vehicle 3 parked in the garage after the update of the control program, the vehicle 3 determines that the driving start condition of the vehicle 3 is satisfied. When the driving start condition of the vehicle 3 is satisfied (Yes in S41), the vehicle 3 notifies the server 1 of the change content of the control program (S42). This notification is made to a remote monitor different from the operation manager.
[0077] When receiving the notification from the vehicle 3, the server 1 displays the change content of the control program on the display 16 (S31). The server 1 asks the remote monitor whether it is possible to start the driving of the vehicle 3 after the update of the control program. Then, the server 1 accepts the operation performed by the remote monitor regarding whether it is possible to start the driving of the vehicle 3 (S32).
[0078] Figure 10 This is a diagram showing an example of the image displayed on the display 16 before asking the remote monitor whether it is possible to start the driving of the vehicle 3. Before asking the remote monitor, the operation status of the vehicle 3 as the object (in this example, the schedule time and actual time of each station), the status of the vehicle 3 (such as speed), the switching of the driving mode of the vehicle 3, the operations of the vehicle 3 (door opening / closing, emergency stop, etc.) are displayed, and the image inside the vehicle 3 is also displayed.
[0079] Figure 11 This is a diagram showing an example of the image displayed on the display 16 when asking the remote monitor whether it is possible to start the driving of the vehicle 3. When asking the remote monitor, a dialog box is displayed on the Figure 10 screen shown. In the dialog box, for example, the information for identifying the vehicle 3 as the object (car No. 1 in this example), the information for identifying the ECU as the object (camera ECU), a simple explanation of the update content of the control program (response to the addition of the dynamic image codec format), the disclaimer in the case of a malfunction in the updated control program (none in particular), and the function limitations associated with the update of the control program (none in particular) are displayed.
[0080] In addition, in the dialog box, the changed content of the control program is displayed (the number of screens showing the images captured by the in-vehicle camera is increased from a maximum of 2 screens to a maximum of 4 screens). In this way, it is preferable to present the functions before the update of the control program and the functions after the update of the control program to the remote monitor in a comparable manner. Also, regarding the information used by the remote monitor when monitoring the vehicle 3, it is preferably presented specifically to the remote monitor.
[0081] On the basis of displaying the above-mentioned changed content, the server 1 asks the remote monitor of the vehicle 3 whether to permit the driving of the vehicle 3 after the update of the control program. In this example, when the remote monitor clicks the "Yes" button, the driving of the vehicle 3 is permitted. On the other hand, when the remote monitor clicks the "No" button, the driving of the vehicle 3 is prohibited. In addition, by clicking the "Details Confirmation" button, the remote monitor can judge the permission / prohibition of driving on the basis of confirming more detailed content of the changed content.
[0082] Refer again to Figure 9 , when an operation to permit the start of driving of the vehicle 3 is performed by the remote monitor (Yes in S33), the server 1 notifies the vehicle 3 of the permission to start driving (S35). When the vehicle 3 receives the notification of the permission to start driving (Yes in S43), it starts driving (S44). For example, the vehicle 3 activates the control program in the flash memory 312C installed in the ECU 31 and starts driving.
[0083] On the other hand, when an operation to prohibit the start of driving of the vehicle 3 is performed by the remote monitor (No in S33), the server 1 notifies the vehicle 3 of the prohibition of starting driving (S34). When the vehicle 3 receives the notification of the prohibition of starting driving (No in S43), it does not start driving and waits.
[0084] As described above, in the present embodiment, when there is a control program that can be updated for the ECU 31 of the vehicle 3, the control center 2 (or the vehicle 3) asks the server 1 whether the control program can be updated. The server 1 that has received the inquiry answers the operation result (approval / rejection) of the operation manager related to whether the control program can be updated to the control center 2 (or the vehicle 3). Thereby, for example, even if a person having the update authority of the control program is not on board the vehicle 3, the control program can be updated. Therefore, according to the present embodiment, the control program installed in the ECU 31 of the vehicle 3 can be appropriately updated.
[0085] Furthermore, in the present embodiment, after the update of the control program of the ECU 31 of the vehicle 3, the vehicle 3 asks the server 1 about the change content of the control program (the change points of the control, operation, function, etc. of the vehicle 3) and asks whether it is possible to start the driving of the vehicle 3. The server 1 that has received the inquiry answers the vehicle 3 with the operation result (permission / forbidden) of the remote monitor related to whether it is possible to start driving. Thus, the remote monitor who is not aboard the vehicle 3 can start the driving of the vehicle 3 on the basis of grasping the change content of the control program. Therefore, according to the present embodiment, the vehicle 3 after the update of the control program can be operated appropriately.
[0086] The embodiment disclosed herein should be considered illustrative in all respects and not restrictive. The scope of the present disclosure is shown not by the description of the above embodiment but by the claims, and is intended to include all modifications within the meaning and scope equivalent to the claims.
Claims
1. A server, which is a server of an operator that monitors and manages the operation of an autonomous vehicle, wherein the autonomous vehicle is configured to obtain a control program of a control device mounted on the autonomous vehicle from a control center through wireless communication, and the server includes: an input device that accepts operations of a remote monitor who monitors the autonomous vehicle from outside the autonomous vehicle; an output device that presents information to the remote monitor; a communication device configured to be able to communicate with the autonomous vehicle; and a processor that controls the input device, the output device, and the communication device, wherein when the start time of operation of the autonomous vehicle parked in a garage approaches after the control program is updated, the processor controls the output device so that the server presents the change content of the control program to the remote monitor; and when the input device accepts an operation of the remote monitor permitting the autonomous vehicle to travel according to the updated control program, the processor controls the communication device to notify the autonomous vehicle of permission to travel.
2. The server according to claim 1, wherein the processor controls the output device to present the functions of the autonomous vehicle before the update of the control program and the functions of the autonomous vehicle after the update of the control program to the remote monitor in a comparable manner.
3. The server according to claim 1 or 2, wherein the processor controls the output device to present the change content related to the information used by the remote monitor when monitoring the autonomous vehicle to the remote monitor.
4. The server according to claim 1 or 2, wherein the server manages the operations of multiple vehicles each mounted with multiple control devices, and the change content includes information for determining the vehicle in which the control program is updated from among the multiple vehicles, and conditions for determining the control device in which the control program is updated from among the multiple control devices mounted on the vehicle.
5. An information processing system, comprising: the server according to any one of claims 1 to 4; and the autonomous vehicle.
6. The information processing system according to claim 5, wherein the autonomous vehicle waits to receive a notification of permission to travel from the server and then starts to travel.
7. An information processing method, which uses a server of an operator that monitors and manages the operation of an autonomous vehicle to monitor the autonomous vehicle, wherein the autonomous vehicle is configured to obtain a control program of a control device mounted on the autonomous vehicle from a control center through wireless communication, and the information processing method includes: a step in which, when the start time of operation of the autonomous vehicle parked in a garage approaches after the control program is updated, the server presents the change content of the control program to a remote monitor who monitors the autonomous vehicle from outside the autonomous vehicle; and When the remote monitor has performed an operation to permit the autonomous vehicle to travel in accordance with the updated control program, a step of notifying the autonomous vehicle of the permitted travel.
Citation Information
Patent Citations
Software update system, and server
JP2018132979A
Vehicle control apparatus, vehicle, vehicle control method, and storage medium
CN109398357A