Server, information processing system, and information processing method
By managing the operation of autonomous vehicles through servers, the problem of allowing updates to the control program in autonomous vehicles has been solved, enabling safe updates to the control program even when the driver is not in the vehicle, ensuring functionality and safety.
Patent Information
- Authority / Receiving Office
- CN · China
- Patent Type
- Patents(China)
- Current Assignee / Owner
- TOYOTA JIDOSHA KK
- Filing Date
- 2022-09-14
- Publication Date
- 2026-05-12
AI Technical Summary
In autonomous vehicles, how to obtain permission to update the control program when the driver is not in the passenger compartment has become a challenge, and existing technologies have not been able to effectively solve this problem.
The operation of autonomous vehicles is managed by a server. Input devices, output devices, communication devices, and processors are used to control the update conditions of the program and update them after the certified operation manager is certified. This includes the management of conditions such as time, period, function, and disclaimers.
It enables the proper updating of control programs in autonomous vehicles, ensuring functionality and safety while avoiding unnecessary updates and functional limitations.
Smart Images

Figure CN116032957B_ABST
Abstract
Description
Technical Field
[0001] This disclosure relates to servers and information processing methods, and more specifically, to a server for managing the operation of autonomous vehicles, an information processing system having the server, and an information processing method by which the server manages information related to the operation of autonomous vehicles. Background Technology
[0002] Japanese Patent Application Publication No. 2018-132979 discloses a software update system for managing updates to software of a control device installed in a vehicle. This system updates the software via wireless communication (so-called OTA (Over-The-Air)). Summary of the Invention
[0003] When updating the software of electrical devices such as personal computers and smartphones, user permission is usually required. Similarly, for updates to the control programs of control devices installed in vehicles, prior user permission is considered.
[0004] The inventors of this invention focused on aspects that may arise in autonomous vehicles, such as: In conventional vehicles, the driver is inside the passenger compartment, and therefore permission to update the control program is obtained from the driver. On the other hand, autonomous vehicles can be managed from outside the vehicle. That is, in autonomous vehicles, the operator may not be inside the passenger compartment. Therefore, how to obtain permission to update the control program may become a problem. No research on this situation has been conducted in Japanese Patent Application Publication No. 2018-132979.
[0005] This disclosure was made to solve the above-mentioned problems, and its purpose is to properly update the control program of the control device installed in an autonomous vehicle.
[0006] (1) One aspect of this disclosure involves a server managing the operation of an autonomous vehicle. The autonomous vehicle is configured to obtain a control program from a control center via wireless communication from a control device mounted on the autonomous vehicle. The server comprises: an input device for accepting operations from an operation manager who manages the operation of the autonomous vehicle from outside the vehicle; an output device for providing information to the operation manager; a communication device configured to communicate with at least one of the autonomous vehicle and the control center; and a processor for controlling the input device, the output device, and the communication device. If an updateable control program exists, the processor controls the output device to notify the operation manager of the update conditions for the control program. If the input device accepts an operation from the operation manager allowing the update of the control program, the processor controls the communication device to notify at least one of the autonomous vehicle and the control center that the update of the control program is permitted.
[0007] (2) The server also has an authentication device, which is configured as an authentication operation manager. The processor controls the output device to prompt the operation manager authenticated by the authentication device with update conditions.
[0008] (3) The processor controls the input device to enable the operation of the operator who is certified by the authentication device, and not to accept the operation of the operator who is not certified by the authentication device.
[0009] (4) Update conditions include conditions related to the time required for updating the control program.
[0010] (5) Update conditions include conditions related to the period during which the control program can be updated.
[0011] (6) The server manages the operation of multiple vehicles, each equipped with multiple control devices. The update conditions include conditions for determining the vehicle from the multiple vehicles to which the control program is to be updated, and conditions for determining the control device from the multiple control devices equipped on the vehicle to which the control program is to be updated.
[0012] (7) Update conditions include conditions related to the functions of the autonomous vehicle updated by the control program.
[0013] (8) Update conditions include conditions related to the functionality of autonomous vehicles that are restricted along with updates to the control program.
[0014] (9) The updated conditions include conditions related to the control center’s exemptions from liability for adverse events that may arise as a result of the updates to the control procedures.
[0015] (10) The information processing system of another aspect of this disclosure includes the aforementioned server and autonomous vehicle.
[0016] (11) If at least one of the autonomous vehicle and the control center receives a notification that the control program can be updated, the autonomous vehicle obtains the control program from the control center; on the other hand, if at least one of the autonomous vehicle and the control center receives a notification that the control program cannot be updated, the autonomous vehicle does not obtain the control program from the control center.
[0017] (12) In another aspect of the information processing method of this disclosure, a server manages information related to the operation of an autonomous vehicle. The autonomous vehicle is configured to obtain control programs from a control device mounted on the autonomous vehicle via wireless communication from a control center. The information processing method includes steps 1 and 2. Step 1 is as follows: if a control program that can be updated exists, the server prompts an operation manager who manages the operation of the autonomous vehicle from outside the autonomous vehicle with the conditions for updating the control program. Step 2 is as follows: if the operation manager performs an operation that allows the control program to be updated, the server notifies at least one of the autonomous vehicle and the control center that the update of the control program is permitted.
[0018] According to this disclosure, the control program of the control device installed in an autonomous vehicle can be updated appropriately. Attached Figure Description
[0019] The features, advantages, and technical and industrial significance of exemplary embodiments of the present invention will now be described with reference to the accompanying drawings, in which the same reference numerals show the same elements, and wherein:
[0020] Figure 1 This is a diagram showing the general structure of the information processing system in this embodiment.
[0021] Figure 2 It is a block diagram representing the typical hardware structure of a vehicle.
[0022] Figure 3 It is a block diagram representing a typical hardware structure of a server.
[0023] Figure 4 It is a functional block diagram representing the functional structure of the server related to the update of the control program.
[0024] Figure 5 This is a functional block diagram representing the functional structure of the server related to the start of driving after the control program is updated.
[0025] Figure 6 This is the first flowchart used to illustrate the process performed by the information processing system.
[0026] Figure 7 This is an example of an image displayed on the monitor before asking the operations manager whether the control program can be updated.
[0027] Figure 8 This is an example of an image displayed on the monitor when asking the operations manager if the control program can be updated.
[0028] Figure 9 This is the second flowchart used to illustrate the process performed by the information processing system.
[0029] Figure 10 This is an example of an image displayed on a monitor before a remote observer is asked whether the vehicle can begin driving.
[0030] Figure 11 This is an example of an image displayed on a monitor when a remote observer is asked whether the vehicle can begin driving. Detailed Implementation
[0031] Hereinafter, embodiments of the present disclosure will be described in detail with reference to the accompanying drawings. It should be noted that the same or equivalent parts in the drawings are labeled with the same reference numerals, and their descriptions will not be repeated.
[0032] [Implementation Method]
[0033] <Outline Structure of an Information Processing System>
[0034] Figure 1 This is a diagram showing the general structure of the information processing system according to this embodiment. The information processing system 100 includes a server 1, a control center 2, and multiple vehicles 3A, 3B, and 3C. Hereinafter, for ease of explanation, any one of vehicles 3A, 3B, and 3C will be referred to as vehicle 3. It should be noted that... Figure 1 The image shows 3 vehicles, but the number of vehicles can be any value.
[0035] Server 1 could be, for example, the company server of the operator (bus operator, taxi operator, ride-sharing service operator, etc.) that manages the operation of vehicle 3. Server 1 could also be a shared server shared by multiple operators, including the operator in question. Server 1 could also be a cloud server provided by a cloud server management company.
[0036] Server 1 is used by the operation manager of vehicle 3 and also by the remote monitor of vehicle 3. The operation manager is, for example, an employee working in the entity managing the operation of vehicle 3 who has the authority to update the control program of vehicle 3 (a so-called superior manager). The remote monitor is an employee who remotely monitors vehicle 3 and performs its operations appropriately (an so-called operator). The operation manager and the remote monitor are usually different individuals, but they can also be the same person. In this example, we will assume that the operation manager and the remote monitor are different individuals.
[0037] Control center 2 provides ECU (Electronic Control Unit) 31 (see reference) installed in vehicle 3. Figure 2 The server of the operator (e.g., a vehicle manufacturer) controlling the program.
[0038] Each vehicle 3 is an autonomous vehicle. Each vehicle 3 is used for the services provided by the aforementioned operator. The type (model) of vehicle 3 is appropriately selected based on the services provided by the operator. In this example, vehicle 3 is a bus. Server 1, control center 2, and each vehicle 3 are connected to each other via a wired or wireless network NW in a manner that enables them to communicate with each other.
[0039] <Vehicle Hardware Structure>
[0040] Figure 2 This is a block diagram representing a typical hardware structure of vehicle 3. Vehicle 3 includes an ECU 31, an autonomous driving system 32, a sensor group 33, a navigation system 34, and a DCM (Data Communication Module) 35. The ECU 31, autonomous driving system 32, sensor group 33, navigation system 34, and DCM 35 are interconnected via wired in-vehicle networks such as CAN (Controller Area Network) and Ethernet (registered trademark).
[0041] ECU 31 includes a processor 311 and a memory 312. Memory 312 includes ROM (Read Only Memory) 312A, RAM (Random Access Memory) 312B, and flash memory 312C. The processor 311 controls the overall operation of vehicle 3 by executing control programs. Memory 312 stores the software executed by the processor 311. In particular, flash memory 312C stores control programs that are updated via OTA. It should be noted that flash memory 312C can also be other rewritable non-volatile memory.
[0042] The ECU 31 controls the equipment based on signals from the sensor group 33, etc., to bring the vehicle 3 into the desired state. The ECU 31 coordinates with the automatic driving system 32 while outputting commands to control various systems. These systems are not shown in the figures, but may include braking systems, steering systems, powertrain systems (e.g., electric parking brake system, parking lock system, gear shifting device, electric generator), and body systems (e.g., turn indicators, horn, windshield wipers), etc.
[0043] ECU 31 sends various information indicating the status of vehicle 3 to server 1 via DCM 35, or sends various requests to server 1. Additionally, ECU 31 receives instructions or notifications from server 1 via DCM 35. Furthermore, in this embodiment, ECU 31 receives (downloads) a control program from control center 2 via DCM 35, and installs the downloaded control program into memory 312 at an appropriate time. Then, ECU 31 activates the installed control program at an appropriate time. It should be noted that ECU 31 can also be functionally divided into multiple ECUs. In the example described later (see...), ... Figure 8 In this context, ECU31 includes the camera ECU.
[0044] The autonomous driving system 32 is configured to enable autonomous driving of the vehicle 3. Autonomous driving refers to control that performs the actions of the vehicle 3 without relying on the driving operations of the driver of the vehicle 3 (driverless). In this example, the autonomous driving system 32 is configured to perform fully autonomous driving of the vehicle 3. However, autonomous driving may also include control that assists the driver of the vehicle 3 in driving operations such as acceleration, deceleration, and steering (manned driving). The autonomous driving system 32 may also be part of the ECU 31.
[0045] Sensor group 33 includes sensors configured to detect the external conditions of vehicle 3, and sensors (not shown) configured to detect information corresponding to the driving state of vehicle 3, as well as steering operation, acceleration operation, and braking operation. Specifically, sensor group 33 may include, for example, a camera, radar, lidar (LIDAR: Laser Imaging Detection and Ranging), vehicle speed sensor, acceleration sensor, and yaw rate sensor (not shown).
[0046] The navigation system 34 includes a GPS (Global Positioning System) receiver (not shown). The GPS receiver determines the position of the vehicle 3 based on radio waves from artificial satellites (not shown). The navigation system 34 uses the position information of the vehicle 3 determined by the GPS receiver to perform navigation processing for the vehicle 3.
[0047] DCM35 is an in-vehicle communication module. DCM35 is configured to enable bidirectional data communication between ECU31 and server 1, and also to enable bidirectional data communication between ECU31 and control center 2.
[0048] <Server Hardware Structure>
[0049] Figure 3This is a block diagram representing a typical hardware structure of server 1. Server 1 includes a processor 11, memory 12, keyboard 13, mouse 14, camera 15, monitor 16, and communication interface (IF) 17. Memory 12 includes ROM 121, RAM 122, and HDD (Hard Disk Drive) 123. Processor 11, memory 12, keyboard 13, mouse 14, camera 15, monitor 16, and communication IF 17 are interconnected via a bus.
[0050] Processor 11 controls the overall operation of server 1. Memory 12 stores the operating system and applications executed by processor 11. Keyboard 13 and mouse 14 accept user input. Camera 15 captures images of the operator of server 1. In this embodiment, the operator of server 1 is the operation manager or remote monitor of vehicle 3. Display 16 displays various information to the operator of server 1. Communication IF 17 is configured to communicate with control center 2 and each vehicle 3.
[0051] It should be noted that at least one of the keyboard 13 and mouse 14 is equivalent to the "input device" of this disclosure. The "input device" may also be an operating terminal, touchpad, microphone, etc., specifically for vehicle operation management. At least one of the display 16 and communication IF 17 is equivalent to the "output device" of this disclosure. The "output device" may also be, for example, a speaker. At least one of the keyboard 13, mouse 14, and camera 15 is equivalent to the "authentication device" of this disclosure.
[0052] <Control program update>
[0053] When updating the software of electrical devices such as personal computers and smartphones, user permission is usually required. However, since Vehicle 3, as an autonomous vehicle, is operated and managed from outside the vehicle, the operator is not inside the passenger compartment. Therefore, obtaining permission to update the control program may become a challenge.
[0054] In this embodiment, when an updateable control program exists, server 1 (processor 11) displays the update conditions for the control program on display 16. Then, if the administrator allows the control program update via keyboard 13 or mouse 14, server 1 notifies control center 2 and / or vehicle 3 of the permission to update the control program. Control center 2 and vehicle 3, upon receiving the permission notification, perform the control program update via over-the-air (OTA) communication. Thus, even if vehicle 3 is unmanned, the control program can be updated appropriately.
[0055] <Functional Structure of a Server>
[0056] Figure 4This is a functional block diagram showing the functional structure of server 1 related to the update of the control program. Server 1 includes a communication unit 41, a processing unit 42, an input unit 43, a display unit 44, and a camera unit 45. The processing unit 42 is a functional block implemented by the processor 11 executing the operating system and application programs stored in the memory 12. The processing unit 42 includes a communication control unit 421, a notification unit 422, an operation receiving unit 423, an image generation unit 424, a storage unit 425, and an authentication unit 426.
[0057] The communication unit 41 communicates with external entities (control center 2 and / or vehicle 3). More specifically, the communication unit 41 receives update conditions for the control program of the ECU 31 of vehicle 3 from external entities. Details regarding the update conditions will be described later. Additionally, the communication unit 41 sends a notification to the external entity indicating whether the vehicle 3's operations manager, having confirmed the update conditions for the control program, approves (allows / rejects) the update. It should be noted that the communication unit 41 corresponds to... Figure 3 The communication IF17.
[0058] The communication control unit 421 controls communication with the outside world via the communication unit 41. The communication control unit 421 outputs the update conditions of the control program received by the communication unit 41 to the image generation unit 424, or sends the notification generated by the notification unit 422 to the outside world from the communication unit 41.
[0059] The operation receiving unit 423 outputs the input operation from the vehicle 3's operation manager to the input unit 43 to the notification unit 422 or the authentication unit 426. More specifically, the operation receiving unit 423 outputs the result of the operation manager's selection of whether to approve the update of the control program (in the example described later, the result of the button / no button operation) to the notification unit 422. The operation receiving unit 423 can also output the password entered by the operation manager to the authentication unit 426. It should be noted that the input unit 43 corresponds to... Figure 3 The keyboard 13 or mouse 14.
[0060] The image generation unit 424 generates an image representing the update conditions of the control program received by the communication control unit 421. Additionally, the image generation unit 424 generates an image for the operation manager, who has confirmed the update conditions, to choose whether to approve the control program update. The display unit 44 displays the image generated by the image generation unit 424 to the operation manager. It should be noted that the display unit 44 corresponds to... Figure 3 The monitor is 16.
[0061] The imaging unit 45 captures images of the vehicle 3's operation manager and outputs the captured images to the authentication unit 426. It should be noted that the imaging unit 45 corresponds to... Figure 3 Camera 15.
[0062] Storage unit 425 stores data used for authenticating the operation manager of vehicle 3. The authentication method for the operation manager is not particularly limited and can employ a variety of known methods. In this example, storage unit 425 stores facial recognition data used for the operation manager. Storage unit 425 can also store data used for other biometric authentication methods (fingerprint authentication, iris authentication, voice authentication, etc.). Storage unit 425 can also store passwords set by the operation manager.
[0063] The authentication unit 426 authenticates the operation manager based on the image captured by the imaging unit 45 and the feature data stored in the storage unit 425. The authentication unit 426 can also authenticate the operation manager based on the password entered into the input unit 43 and the password stored in the storage unit 425. The authentication unit 426 outputs the authentication result to the notification unit 422.
[0064] If the authentication unit 426 verifies that the operation server 1 is a pre-registered, legitimate operation administrator, the notification unit 422 generates a notification indicating whether the operation administrator approves the control program update. More specifically, if the operation administrator approves the control program update (presses the "Yes" button), the notification unit 422 generates a control program update approval notification. Conversely, if the operation administrator disapproves the control program update (presses the "No" button), the notification unit 422 generates a control program update rejection notification. The notification generated by the notification unit 422 is output to the communication control unit 421, and then sent externally from the communication unit 41.
[0065] Figure 5 This is a functional block diagram showing the functional structure of server 1 related to the start of driving after the control program is updated. Server 1 includes a communication unit 51, a processing unit 52, an input unit 53, and a display unit 54. Like processing unit 42, processing unit 52 is a functional block implemented by processor 11 executing the operating system and application programs stored in memory 12. Processing unit 52 includes a communication control unit 521, a notification unit 522, an operation receiving unit 523, and an image generation unit 524.
[0066] Communication unit 51 communicates with external systems. Communication unit 51 receives changes to the control program from external systems. Details regarding these changes will be described later. Additionally, communication unit 41 sends a notification to the external system indicating whether the remote monitor of vehicle 3, having confirmed the changes to the control program, approves (rejects / prohibits) the commencement of driving (re-starting driving) of vehicle 3. It should be noted that communication unit 51 corresponds to... Figure 3 The communication IF17.
[0067] The communication control unit 521 controls communication with the outside world via the communication unit 51. The communication control unit 521 outputs changes to the control program received by the communication unit 51 to the image generation unit 524, or sends notifications generated by the notification unit 522 from the communication unit 51 to the outside world.
[0068] The operation receiving unit 523 outputs the input operation from the remote monitor of vehicle 3 to the input unit 53 to the notification unit 522. More specifically, the operation receiving unit 523 outputs the result of the remote monitor's selection of whether to approve the update of the control program (the operation result of the yes / no button) to the notification unit 522.
[0069] The image generation unit 524 generates an image representing the changes to the control program received by the communication control unit 521. Additionally, the image generation unit 524 generates an image for a remote observer who has confirmed the changes to choose whether to approve the start of driving of vehicle 3 after the control program update. The display unit 54 displays the image generated by the image generation unit 524 to the remote observer. It should be noted that the display unit 54 corresponds to... Figure 3 The monitor is 16.
[0070] The notification unit 522 generates a notification indicating whether the remote monitor approves the start of vehicle 3's operation. More specifically, if the remote monitor approves the start of vehicle 3's operation (presses the "Yes" button), the notification unit 522 generates a permission notification for the start of vehicle 3's operation. Conversely, if the remote monitor disapproves the start of vehicle 3's operation (presses the "No" button), the notification unit 522 generates a prohibition notification for the start of vehicle 3's operation. The notification generated by the notification unit 522 is output to the communication control unit 521, and then sent externally from the communication unit 51.
[0071] <Processing Flow>
[0072] Figure 6 This is the first flowchart used to illustrate the process performed by the information processing system 100. Figure 6 and the following Figure 9 The flowchart shown is executed, for example, at predetermined time intervals. The left side shows the process executed by server 1, and the right side shows the process executed by control center 2. The process on the right can also be executed by vehicle 3. This is because control center 2 and vehicle 3 can communicate with each other, so notifications from server 1 can reach vehicle 3 via control center 2, and vice versa. Each step is implemented by software processing, but can also be implemented by hardware (electrical circuits). Hereinafter, each step will be referred to as "S".
[0073] In S21, the control center 2 determines whether there is a control program that can be updated for the ECU 31 of the vehicle 3. If there is a control program that can be updated (YES in S21), the control center 2 notifies the server 1 of this. At this time, the control center 2 also notifies the server 1 of the update conditions for the control program (described later) (S22).
[0074] If a notification is received from control center 2, server 1 uses camera 15 to detect the operator of server 1 (S11). Then, server 1 authenticates whether the operator of server 1 is a pre-registered, legitimate operations manager (S12). If the operator of server 1 is authenticated (YES in S13), server 1 displays the update conditions of the control program on display 16 (S14). Server 1 queries the operations manager whether the control program can be updated. Then, server 1 processes the operations performed by the operations manager related to whether the control program can be updated (S15).
[0075] Figure 7 This diagram illustrates an example of the image displayed on display 16 before inquiring with the operations manager about updating the control program. Before inquiring with the operations manager, the driving status of multiple vehicles 3 (buses in this example) under the management of server 1 is displayed on the operations management screen of display 16. More specifically, it displays the time, the route name of vehicle 3, the identification number of vehicle 3, and the status of vehicle 3 (delay relative to the time specified in the timetable, decrease in SOC (State of Charge), etc.). Additionally, a map showing the current position of each vehicle 3 on its route is displayed on display 16.
[0076] Figure 8 This diagram illustrates an example of an image displayed on monitor 16 when a request is made to the operations administrator to update the control program. When the request is made to the operations administrator, in Figure 7 The screen displayed shows a dialog box. This dialog box includes, for example, information about the vehicle identified as the target (vehicle 3, vehicle 1 in this example), information about the target ECU (camera ECU), a brief description of the control program update (including additional video codec format support), disclaimers in case of defects in the updated control program (no specific details), and functional limitations associated with the control program update (no specific details). Additionally, the dialog box may display, for example, the scheduled update period for the control program (from 6 PM today to 8 AM the next day) and the time required for the update (approximately 5 minutes).
[0077] Based on the above update conditions, server 1 queries the vehicle 3's operation manager to determine whether to allow the control program update. In this example, if the operation manager clicks the "Yes" button, the control program update is allowed. Conversely, if the operation manager clicks the "No" button, the control program update is denied. It should be noted that the operation manager can click the "Detailed Confirmation" button to confirm the more detailed information regarding each update condition and determine whether to allow or deny the update.
[0078] Refer again Figure 6 If the operation manager has authorized an update of the control program (YES in S16), server 1 notifies control center 2 that the update is permitted (S18). If control center 2 receives the notification of permission (YES in S23), it coordinates with vehicle 3 and performs an over-the-air (OTA) update of the control program (S24) if the conditions suitable for the update are met (e.g., vehicle 3, having completed its service, returns to the garage and is parked). That is, the control program is downloaded from control center 2 to vehicle 3 and installed in the flash memory 312C of ECU 31.
[0079] On the other hand, if the operations manager performs an operation to deny the update of the control program (NO in S16), server 1 notifies control center 2 of the denial of the control program update (S17). Upon receiving the notification of denial of update (NO in S23), control center 2 does not perform an OTA update of the control program. Although not illustrated, control center 2 does not perform the update of the control program even if an operation to allow the update of the control program is not performed within the specified time.
[0080] Figure 9 This is the second flowchart illustrating the processes performed by the information processing system 100. These processes are based on... Figure 6 The first flowchart shown is executed after the control procedure is updated.
[0081] In S41, vehicle 3 determines whether the conditions for starting its operation are met. For example, if the start time of operation for vehicle 3, which is parked in the garage after the control program update, is approaching, vehicle 3 determines that the conditions for starting its operation are met. If the conditions for starting vehicle 3 are met (YES in S41), vehicle 3 notifies server 1 of the changes to the control program (S42). This notification is made to a remote monitor who is different from the operation manager.
[0082] If a notification is received from vehicle 3, server 1 displays the changes to the control program on display 16 (S31). Server 1 then queries the remote monitor to determine whether vehicle 3 can begin driving after the control program update. Server 1 then performs operations related to whether vehicle 3 can begin driving based on the remote monitor's instructions (S32).
[0083] Figure 10 This diagram illustrates an example of an image displayed on display 16 before a remote observer is asked whether vehicle 3 can begin driving. Before asking the remote observer, the diagram displays the operating status of vehicle 3 (in this example, the timetable time for each stop, and the actual time), the condition of vehicle 3 (e.g., speed), the switching of driving mode of vehicle 3, the operation of vehicle 3 (door opening and closing, emergency stop, etc.), and an image of the interior of vehicle 3.
[0084] Figure 11 This diagram illustrates an example of an image displayed on display 16 when a remote monitor is asked whether vehicle 3 can begin driving. When asking a remote monitor, in Figure 10 The screen shown displays a dialog box. The dialog box displays, for example, information about the vehicle identified as the target (vehicle 3, vehicle 1 in this example), information about the ECU (camera ECU) identified as the target, a brief description of the updated control program (additional video codec format support), disclaimers in case of defects in the updated control program (no specific details), and functional limitations associated with the control program update (no specific details).
[0085] In addition, the changes to the control program are displayed in the dialog box (the number of images captured by the vehicle-mounted camera has increased). Preferably, the remote monitor is notified in a way that allows a comparison of the functions of the control program before and after the update. Furthermore, it is preferable to specifically notify the remote monitor of information used when monitoring vehicle 3.
[0086] After displaying the aforementioned changes, server 1 queries the remote monitor of vehicle 3 to determine whether to permit vehicle 3 to operate after the control program update. In this example, if the remote monitor clicks the "Yes" button, vehicle 3 is permitted to operate. Conversely, if the remote monitor clicks the "No" button, vehicle 3 is prohibited from operating. It should be noted that the remote monitor can click the "Detailed Confirmation" button to determine whether to permit / prohibit operation based on more detailed information about the changes.
[0087] Refer again Figure 9If a remote monitor grants permission for vehicle 3 to begin driving (YES in S33), server 1 notifies vehicle 3 of the driving start permission (S35). If vehicle 3 receives the driving start permission notification (YES in S43), it begins driving (S44). For example, vehicle 3 activates the control program installed in the flash memory 312C of ECU 31 and begins driving.
[0088] On the other hand, if the remote monitor performs an operation to prohibit vehicle 3 from starting to drive (NO in S33), server 1 notifies vehicle 3 that vehicle 3 is prohibited from starting to drive (S34). Upon receiving the notification that vehicle 3 is prohibited from starting to drive (NO in S43), vehicle 3 does not start to drive and remains in standby mode.
[0089] As described above, in this embodiment, if there is an updateable control program for the ECU 31 of vehicle 3, the control center 2 (which may also be vehicle 3) queries the server 1 to inquire whether the control program can be updated. The server 1, having received the inquiry, replies to the control center 2 (which may also be vehicle 3) with the result of the operation performed by the operations manager related to whether the control program can be updated (allow / deny). Therefore, even if a person with the authority to update the control program is not riding in vehicle 3, they can still control the program. Thus, according to this embodiment, the control program of the ECU 31 installed in vehicle 3 can be appropriately updated.
[0090] Furthermore, in this embodiment, after updating the control program of the ECU 31 of vehicle 3, vehicle 3, along with the changes to the control program (changes to the control, operation, and functions of vehicle 3), queries server 1 to determine whether vehicle 3 can begin driving. Server 1, upon receiving the query, responds to vehicle 3 with the result of the operation performed by the remote monitor (permission / prohibition) related to whether driving can begin. Thus, a remote monitor who is not riding in vehicle 3 can start driving vehicle 3 based on knowledge of the changes to the control program. Therefore, according to this embodiment, vehicle 3 with the updated control program can be operated appropriately.
[0091] The embodiments disclosed herein should be considered illustrative rather than restrictive in all respects. The scope of this disclosure is set forth not by the description of the above embodiments but by the claims, and is intended to include all modifications within the meaning and scope equivalent to the claims.
Claims
1. A server for managing the operation of autonomous vehicles, wherein, The autonomous vehicle is configured to obtain control programs from the control device mounted on the autonomous vehicle via wireless communication from the control center. The server has the following features: The input device accepts operations from an external operator who manages the operation of the autonomous vehicle. The output device provides information to the operation manager. The communication device is configured to communicate with at least one of the autonomous vehicle and the control center; as well as The processor controls the input device, the output device, and the communication device. If an updateable control program exists, the processor controls the output device to notify the operations manager of the update requirements for the control program. When the input device receives an operation from the operations manager authorizing an update to the control program, the processor controls the communication device to notify at least one of the autonomous vehicle and the control center that the update to the control program is permitted. After the control program is updated, the changes to the control program are communicated to a remote monitor (different from the operation manager) who is remotely monitoring the autonomous vehicle. The remote monitor is then asked whether they approve the start of the autonomous vehicle's operation after the control program update. If the remote monitor grants permission for the autonomous vehicle to start driving, the autonomous vehicle is notified of the permission to start driving. If the remote monitor does not grant permission for the autonomous vehicle to start driving, the autonomous vehicle is notified that it is prohibited from starting driving.
2. The server according to claim 1, wherein, It also includes an authentication device configured to authenticate the operation manager. The processor controls the output device to prompt the update conditions to the operation manager authenticated by the authentication device.
3. The server according to claim 2, wherein, The processor controls the input device to allow operations by the operation manager that have been certified by the authentication device to be accepted, while operations by operators that have not been certified by the authentication device are not accepted.
4. The server according to any one of claims 1 to 3, wherein, The update conditions include conditions related to the time required to update the control program.
5. The server according to any one of claims 1 to 3, wherein, The update conditions include conditions related to the period during which the control program can be updated.
6. The server according to any one of claims 1 to 3, wherein, The server manages the operation of multiple vehicles, each equipped with multiple control devices. The update conditions include conditions for determining the vehicle from the plurality of vehicles to which the control program is to be updated, and conditions for determining the control device from the plurality of control devices mounted on the vehicle to which the control program is to be updated.
7. The server according to any one of claims 1 to 3, wherein, The update conditions include conditions related to the functions of the autonomous vehicle updated by the control program.
8. The server according to any one of claims 1 to 3, wherein, The update conditions include conditions related to the functions of the autonomous vehicle that are restricted as a result of updates to the control program.
9. The server according to any one of claims 1 to 3, wherein, The update conditions include conditions related to the control center's disclaimers regarding potential adverse events that may arise as a result of the update to the control procedures.
10. An information processing system, wherein, This information processing system has the following features: The server according to any one of claims 1 to 9; and The autonomous vehicle.
11. The information processing system according to claim 10, wherein, If at least one of the autonomous vehicle and the control center receives a notification allowing the update of the control program, the autonomous vehicle retrieves the control program from the control center; on the other hand, If at least one of the autonomous vehicle and the control center receives a notification that the update of the control program is rejected, the autonomous vehicle will not obtain the control program from the control center.
12. An information processing method, wherein a server manages information related to the operation of an autonomous vehicle, wherein, The autonomous vehicle is configured to obtain control programs from the control device mounted on the autonomous vehicle via wireless communication from the control center. The information processing method includes the following steps: If the control program is available for updating, the server prompts the operation manager who manages the operation of the autonomous vehicle from outside the autonomous vehicle with the conditions for updating the control program. as well as If the operations manager grants permission to update the control program, the server notifies at least one of the autonomous vehicle and the control center that the update is permitted. After the control program is updated, the changes to the control program are communicated to a remote monitor (different from the operation manager) who is remotely monitoring the autonomous vehicle. The remote monitor is then asked whether they approve the start of the autonomous vehicle's operation after the control program update. If the remote monitor grants permission for the autonomous vehicle to start driving, the autonomous vehicle is notified of the permission to start driving. If the remote monitor does not grant permission for the autonomous vehicle to start driving, the autonomous vehicle is notified that it is prohibited from starting driving.