Hierarchical fail-safe redundant architecture and process for single data bus mobile devices
By employing a layered fault-safe redundancy architecture and multi-channel communication, combined with privileged operation modes and monitoring mechanisms, the problem of erroneous execution of privileged commands in autonomous driving systems has been solved, ensuring the legitimacy and security of privileged commands and improving system reliability.
Patent Information
- Authority / Receiving Office
- CN · China
- Patent Type
- Applications(China)
- Current Assignee / Owner
- TOMAHAWK ROBOTICS CO LTD
- Filing Date
- 2024-07-15
- Publication Date
- 2026-05-29
Smart Images

Figure CN122122528A_ABST
Abstract
Description
[0001] Cross-references to related applications
[0002] This application claims U.S. priority to U.S. Patent Application No. 18 / 353,866, filed July 17, 2023. The contents of the foregoing application are incorporated herein by reference in their entirety. Background Technology
[0003] Stable and reliable robotic systems are becoming increasingly common. This has contributed to the recent advancements and proliferation of unmanned systems technology, including land-based, air-based, and / or sea-based systems. Various control methods are available for controlling unmanned systems, sometimes referred to as unmanned vehicles. Some unmanned vehicles enable users to execute privileged commands (e.g., ammunition commands). While privileged commands are necessary in certain situations, it is important that these commands are not executed unintentionally (e.g., due to operator error or software malfunction). Summary of the Invention
[0004] Therefore, this paper describes a method and system for a hierarchical fault-safe redundancy system and architecture for privileged operation execution. A command execution system can be used to perform the operations described herein. The command execution system can reside on a mobile device, which can be connected to a vehicle controller, for example, via a physical connection such as a Universal Serial Bus (USB) connection. The physical connection can have multiple channels. For example, USB connectivity can be enabled to connect through different interfaces corresponding to different channels. This architecture allows privileged commands (e.g., ammunition commands, self-destruct commands, payload release commands, etc.) to be initiated on one channel and completed on another, thereby preventing unintentional execution, whether due to operator error or software error.
[0005] In some embodiments, the command execution system may receive commands from the vehicle controller, process these commands (e.g., translate them into commands that the vehicle can execute), and send these commands to the vehicle (e.g., via radio signals or another suitable signal). For example, the command execution system may receive vehicle manipulation commands from the vehicle controller via a first channel. As described above, the command execution system may reside on a mobile device connected to the vehicle controller via a physical connection having a first channel and a second channel. That is, conventional vehicle operation / manipulation commands may be received via the first channel (e.g., using a first interface). The command execution system may send vehicle manipulation commands to the vehicle (e.g., to an unmanned vehicle) for execution. For example, the command execution system may receive commands from the vehicle controller to maneuver an aircraft forward. The command execution system may translate this command into specific propeller operations and send the command to the vehicle (e.g., via radio broadcast, cellular connection, or another suitable connection).
[0006] The command execution system can continue processing manipulation commands for the vehicle until a privileged operation is required. Therefore, the command execution system can use an input mechanism associated with the mobile device to receive the first privileged command. For example, the first privileged command could be an operator dragging a slider on the mobile device (e.g., a touchscreen displaying an interactive slider image). In another example, the first privileged command could be a specific gesture or combination of touches on the touchscreen.
[0007] In some embodiments, the command execution system may determine that a first privileged command (e.g., a first ammunition command) corresponds to the first input in a sequence of inputs for performing a privileged operation (e.g., ammunition operation). For example, a slider may be the first input in a sequence required to initiate a firing command from an unmanned vehicle. This sequence may be indicated by a slider (or another suitable input on the mobile device) in combination with input from the vehicle controller. In another example, a privileged command may be a command to release a load (e.g., using magnetic holding). The load may be a heavy object that could pose a danger to people and objects. Therefore, releasing the load may be a privileged operation.
[0008] The command execution system can then initiate / enable a privileged operating mode. In some embodiments, the command execution system can initiate a privileged operating mode based on receiving a first privileged command, causing the privileged operating mode to enable privileged operation using the vehicle controller. For example, the privileged operating mode can enable a command to fire ammunition for a weapon coupled to the vehicle. In another example, the privileged operating mode can enable a sabotage command or another type of command requiring robust fail-safe mechanisms.
[0009] In some embodiments, the command execution system can enable a privileged operating mode by initializing monitoring of a second channel so that the remaining sequence required to initiate a firing command can be received through that second channel. For example, the command execution system can monitor the second channel for a second privileged command (e.g., a second ammunition command) from a vehicle controller based on determining that a first privileged command (e.g., a first ammunition command) corresponds to a first input in an input sequence for performing a privileged operation (e.g., an ammunition operation). Thus, the command execution system can monitor the second channel for an input or combination of inputs from the vehicle controller instructing the vehicle to fire a vehicle-mounted weapon or one of its vehicle-mounted weapons.
[0010] When the command execution system monitors the second channel, it can receive a second privileged command from the vehicle controller via the second channel. For example, the second privileged command could be a single button press or a combination of button presses on the vehicle controller. In some embodiments, the second privileged command could be a combination of pressing a button followed by pressing a single button. In still other embodiments, the privileged command could be a combination of button presses, followed by a single button press, while the original combination of button presses continues to be applied.
[0011] In some embodiments, the privileged mode may be enabled only for a predetermined time period (e.g., 15 seconds, 30 seconds, 1 minute, etc.). That is, to prevent accidental execution of privileged operations, the command execution system may disable the privileged operation mode if the input sequence is not completed in time. Therefore, in some embodiments, the command sequence will need to restart from the first privileged operation.
[0012] In some embodiments, privileged mode can be disabled if an incorrect command is entered as a second privileged command. For example, when the command execution system enters privileged mode, it may receive a second execution command that includes a combination and / or sequence of inputs. If the input combination and / or sequence does not match a privileged operation, the command execution system may disable privileged mode. In some embodiments, the command execution system may prompt the user to enter a first privileged command to initiate privileged mode.
[0013] The command execution system can determine that the second privileged command corresponds to the second input in a sequence of inputs used to perform a privileged operation. For example, the command execution system can compare the inputs within the second privileged command to determine whether those inputs match a specific predetermined privileged operation. In some embodiments, one or more predetermined privileged commands may exist (e.g., ammunition command – fire weapon – self-destruct command and / or another suitable command).
[0014] When a command execution system determines that an input sequence corresponds to a specific privileged command, it can send that command to a delivery vehicle (e.g., an aerial drone equipped with mounted weapons). In other words, based on determining that a second privileged command corresponds to a second input in an input sequence for performing a privileged operation, the command execution system can send a request to the delivery vehicle to perform the privileged operation. For example, the command execution system can send an ammunition command (e.g., fire a weapon) to an aerial drone.
[0015] In some embodiments, it may be necessary to encrypt privileged commands based on permissions granted to a specific mobile device. The command execution system may use a file or another mechanism to determine whether a mobile device has permission to perform a privileged operation. If so, the mobile device will be able to encrypt the privileged operation before transmitting it to the vehicle. That is, in some embodiments, the vehicle may only accept encrypted privileged operations.
[0016] Various other aspects, features, and advantages of the system will become apparent from the detailed description and accompanying drawings. It should also be understood that the foregoing general description and the following detailed description are exemplary and do not limit the scope of this disclosure. As used in the specification and claims, the singular forms “a,” “an,” and “the” include plural indicators unless the context clearly specifies otherwise. Additionally, as used in the specification and claims, the term “or” means “and / or” unless the context clearly specifies otherwise. Furthermore, as used in the specification, “a portion” means a part or all (i.e., the entire portion) of a given item (e.g., data) unless the context clearly specifies otherwise. Attached Figure Description
[0017] Figure 1 An illustrative system for layered fault-safe redundancy for privileged operation execution is shown according to one or more embodiments of the present disclosure.
[0018] Figure 2 Example mobile devices and controllers prior to privileged operation are shown according to one or more embodiments of this disclosure.
[0019] Figure 3 Excerpts of data structures for identifying ammunition commands and other privileged commands according to one or more embodiments of this disclosure are shown.
[0020] Figure 4 This illustrates a combination of inputs received from an operator constituting a second privileged command according to one or more embodiments of this disclosure.
[0021] Figure 5 This invention illustrates how dedicated hardware can be used to generate commands from a vehicle controller according to one or more embodiments of the present disclosure.
[0022] Figure 6 A computing device according to one or more embodiments of the present disclosure is shown.
[0023] Figure 7 This is a flowchart of an operation for detecting errors caused by motion received from an inertial input device, according to one or more embodiments of the present disclosure. Detailed Implementation
[0024] In the following description, numerous specific details are set forth for illustrative purposes in order to provide a thorough understanding of the disclosed embodiments. However, those skilled in the art will understand that the embodiments can be practiced without these specific details or with equivalent arrangements. In other instances, well-known models and devices are shown in block diagram form to avoid unnecessarily obscuring the disclosed embodiments. It should also be noted that the methods and systems disclosed herein are also applicable to applications unrelated to source code programming.
[0025] Figure 1 This is an example of an environment 100 for a layered fault-safe redundancy system and architecture for privileged operation execution. Environment 100 includes a command execution system 102, a vehicle controller 106, and vehicles 108a-108n (e.g., unmanned vehicles) residing on a mobile device 104. Vehicles 108a-108n may be connected to the mobile device via a network 150. The command execution system 102 can execute instructions from the layered fault-safe redundancy system. The command execution system 102 may include software, hardware, firmware, or a combination of these. For example, the command execution system 102 may reside on a mobile device (e.g., a mobile smartphone, tablet computer, computer system, or another suitable mobile device) that uses the network 150 to send commands to one or more vehicles (e.g., unmanned vehicles). In some embodiments, one or more components of the command execution system 102 may reside on other suitable devices.
[0026] Vehicle controller 106 may be a controller device connected to mobile device 104. Vehicle controller 106 may include multiple input devices (e.g., buttons, joysticks, switches, levers, etc.). Vehicle controller 106 may receive controller input from an operator. For example, operation may involve pressing a button and / or using a joystick to control an unmanned aerial vehicle. In some embodiments, mobile device 104 may slide into vehicle controller 106. Mobile device and vehicle controller may be connected via a physical connection (e.g., a Universal Serial Bus (USB) connection). The physical connection may be divided into two or more channels. In some embodiments, each channel may be created based on the interface type used by the mobile device. For example, a first channel may correspond to a USB Human Interface Device (HID), which enables user input devices (e.g., keyboards, mice, and / or other controllers) to communicate with the mobile device. A second channel may correspond to a USB Communication Device Class (CDC) serial interface, which is a communication class that enables interfacing with mobile devices using a network-type interface.
[0027] In some embodiments, the vehicle controller can connect to mobile devices via a wireless network connection. For example, the wireless network connection could be a Wi-Fi connection or a Bluetooth connection. Other wireless network connections can be used, as long as they support two communication channels. In some embodiments, a point-to-point wireless connection may be used only.
[0028] Network 150 may be a wireless local area network, a wireless wide area network (e.g., the Internet), or a combination of both. Vehicles 108a-108n may be unmanned vehicles, including air vehicles, land vehicles, and / or sea vehicles. In some embodiments, the vehicle may be a manned vehicle that can be controlled by a vehicle controller.
[0029] Command execution system 102 can receive vehicle control commands from vehicle controllers at mobile devices via a first channel. As described above, the mobile device can be connected to the vehicle controller via a physical connection having a first channel and a second channel. The controller can be a vehicle controller that enables an operator to control one or more vehicles (e.g., unmanned vehicles).
[0030] In some embodiments, command execution system 102 may use communication subsystem 112 to receive vehicle control commands. Communication subsystem 112 may include software components, hardware components, or a combination of both. For example, communication subsystem 112 may include a USB adapter coupled to software to drive the adapter. The USB adapter may be built into a mobile device hosting command execution system 102. Communication subsystem 112 may receive control commands from vehicle controller 106. In some embodiments, communication subsystem 112 may receive vehicle control commands via a USB HID interface corresponding to a first channel. That is, vehicle controller 106 may be connected to the mobile device as a human-machine interface device.
[0031] In some embodiments, the communication subsystem 112 can receive vehicle control requests via a wireless connection supporting multiple channels. For example, the communication subsystem 112 may include a network controller and / or a Bluetooth controller. Therefore, the communication subsystem 112 can connect to the vehicle controller using a point-to-point Wi-Fi connection and / or a point-to-point Bluetooth connection. In some embodiments, each connection may allow multiple connection channels. In some embodiments, the first channel may be a Wi-Fi connection, while the second channel may be a Bluetooth connection, and vice versa.
[0032] Vehicle control commands can be interactions between the operator and one or more joysticks, one or more buttons, etc. The communication subsystem 112 can pass control commands or pointers to control commands in memory to the command processing subsystem 114.
[0033] Command processing subsystem 114 may include software components, hardware components, or a combination of both. For example, command processing subsystem 114 may include software components that access data in memory and / or storage devices, and may use one or more processors to perform its operations. Command processing subsystem 114 may receive control commands, perform the necessary processing, and then transmit the control commands to a vehicle (e.g., an unmanned vehicle). For example, a control command may be a command to move an unmanned aerial vehicle forward. Therefore, command processing subsystem 114 may use communication subsystem 112 to transmit commands (e.g., via network 150) to one or more vehicles 108a-108n. Command execution system 102 may continue to receive control commands, process those commands, and transmit those commands to one or more vehicles (e.g., unmanned vehicles).
[0034] Command execution system 102 can receive a first privileged command using an input mechanism associated with the mobile device (e.g., via communication subsystem 112). For example, Figure 2 An example mobile device and controller are shown before privileged operation. Figure 2As shown, systems 200 and 220 illustrate a combination of a mobile device and a vehicle controller. The mobile device is shown sliding into a vehicle controller (e.g., vehicle controller 106). Vehicle controller 106 may include a plurality of actuators 203 (e.g., buttons, joysticks, etc.) for receiving input from an operator. As described above, the mobile device can receive input (e.g., via USB connection) enabling the vehicle controller to control a vehicle (e.g., an autonomous vehicle) via the mobile device (e.g., mobile device 104). The mobile device may include a touchscreen interface or another type of interface. When an operator wants to initiate a privileged command, the operator can actuate the input device on the vehicle controller. The vehicle controller can signal to the mobile device via a first channel (e.g., via a USB HID interface) that a privileged operation has been requested. In response, the mobile device can generate a prompt 206 for display. The input mechanism may be a touchscreen on the mobile device. The mobile device can receive input as a first privileged command.
[0035] In some embodiments, the command execution system 102 may use an input mechanism associated with a mobile device to receive a first ammunition command. The first ammunition command may be a fire command to initiate the firing of a weapon mounted on an unmanned vehicle. Figure 2 As shown, the first ammunition command can be a gesture input performed by the operator on prompt 206. When the gesture (e.g., sliding a finger on a slider) is completed, the mobile device can interpret the gesture as the first ammunition command, or more generally, the first privileged command. As mentioned above, privileged operations do not necessarily involve ammunition commands. The first privileged command (e.g., the first ammunition command) can be part of a privileged operation (e.g., ammunition operation).
[0036] Upon receiving a first privileged command, it can be processed by the input processing subsystem 116. The input processing subsystem 116 may include software components, hardware components, or a combination of both. For example, the input processing subsystem 116 may include software components that access data in memory and / or storage devices, and its operation may be performed using one or more processors. That is, based on the receipt of the first privileged command, the input processing subsystem 116 may initiate a privileged operation mode. The privileged operation mode can be enabled by the vehicle controller. For example, the input processing subsystem 116 may signal the command execution system 102 via a second channel to notify of an expected additional privileged command from the vehicle controller. In some embodiments, the input processing subsystem 116 may signal the command processing subsystem 114 to initiate monitoring of the second channel. For example, as described above, the second channel may be a USB CDC serial interface. Therefore, the command processing subsystem 114 may begin monitoring the interface to obtain further commands from the vehicle controller.
[0037] As described above, in some embodiments, the mobile device can connect to the vehicle controller via one or more wireless connections (e.g., Wi-Fi and / or Bluetooth). In these embodiments, the command execution system 102 can communicate with the vehicle controller via a single channel (e.g., a Wi-Fi channel or a Bluetooth channel) (e.g., via the communication subsystem 112). Upon receiving a first privileged command, the command execution system can (e.g., via the communication subsystem 112) establish a second channel (e.g., a second Wi-Fi channel or a second Bluetooth channel) for communicating with the vehicle controller. In some embodiments, the first channel can be a Wi-Fi channel, and the second channel can be a Bluetooth channel, or vice versa.
[0038] As described above, in some embodiments, the privileged command may be an ammunition command for launching a weapon on a vehicle (e.g., an unmanned vehicle). Therefore, the input processing subsystem 116 may determine that the first ammunition command corresponds to the first input in an input sequence for performing an ammunition operation. For example, when the input processing subsystem 116 receives operator input (e.g., a gesture via a slider associated with cue 206), the input processing subsystem 116 may compare the input (e.g., a combination of cue and gesture) with a predetermined command. For example, the cue may indicate “arm”, and the gesture may indicate “complete”. Therefore, the input may indicate “arming complete”. This indication may be compared with pre-stored commands. Therefore, based on determining that the input matches the first command in a predetermined command sequence, the input processing subsystem 116 may determine that the input sequence has been initiated.
[0039] Once command execution system 102 (e.g., via input processing subsystem 116) determines that an ammunition command (or another suitable privileged command) has been received, command execution system 102 (e.g., via command processing subsystem 114) can initiate a privileged operating mode. This may include monitoring for other ammunition commands (e.g., fire commands, self-destruct commands, etc.) on the second channel. In some embodiments, based on determining that the first ammunition command corresponds to a first input in an input sequence for performing ammunition operations, command execution system 102 (e.g., via command processing subsystem 114) may monitor the second channel for a second ammunition command from the vehicle controller.
[0040] Figure 3An excerpt of data structure 300 for identifying ammunition commands and other privileged commands is shown. Name field 303 may store a command identifier, and value field 306 may store the corresponding command sequence. Therefore, when input processing subsystem 116 detects input on a mobile device, it can compare that input with the first command within each sequence to determine whether a specific sequence (e.g., a firing sequence) should be initiated. In some embodiments, sequence initiation can be the same for all privileged commands. Therefore, a comparison within the sequence can occur when a "second privileged command" is received.
[0041] Command processing subsystem 114 can detect and process commands from the vehicle controller via the second channel. Command processing subsystem 114 can determine that the received command is another privileged command. For example, when command execution system 102 is in privileged operation mode, commands from the vehicle controller can be received via the second channel. As mentioned above, the second channel can be a USB CDC serial interface in a wired environment. In another example, in a wireless environment, commands can be received via a second Wi-Fi channel, a second Bluetooth channel, etc. When a command is received, command processing subsystem 114 can, for example, connect the command to... Figure 3 The command sequence shown is compared to determine if the received command is a second privileged command. If the command matches one or more commands in the command sequence, the command processing subsystem 114 can determine that the command is a second privileged command. Therefore, the command processing subsystem 114 can receive the second privileged command from the vehicle controller via the second channel. As described above, the second privileged command can be an ammunition command, for example, for launching a weapon mounted on a vehicle.
[0042] In some embodiments, the command processing subsystem 114 may accept privileged commands only for a predetermined amount of time prior to deactivating the privileged mode. This enables the prevention of accidental execution when an operator mistakenly identifies the privileged operating mode as a regular operating mode. Specifically, the command processing subsystem 114 may determine that a second privileged command has not been received within a predetermined threshold time. For example, when the privileged mode is activated, the command processing subsystem 114 may start a timer and / or generate a timestamp indicating when the privileged mode has been activated. The command processing subsystem 114 may then determine (e.g., based on the timer or timestamp) when a predetermined time (e.g., 10 seconds, 30 seconds, 1 minute, etc.) expires.
[0043] Once the timeout period has expired, the command processing subsystem 114 can execute specific actions related to disabling the privileged mode. Therefore, based on the determination that no second privileged command has been received within a predetermined time threshold, the command processing subsystem 114 can stop monitoring the second channel. For example, the command processing subsystem 114 can ignore any commands detected from the second channel. In some embodiments, the command processing subsystem 114 can notify the operator that the privileged mode has been disabled due to the timer expiring. For example, the command execution system 102 can generate an indication displayed on the mobile device that the privileged mode has been disabled. Additionally or alternatively, the command execution system 102 (e.g., via the command processing subsystem 114) can generate a prompt displayed on the mobile device to execute a first privileged command. For example, the command execution system 102 can generate... Figure 2 The prompt 206 is provided for display.
[0044] When a command is received while the device is in privileged mode, command execution system 102 can (e.g., via command processing subsystem 114) determine whether the command is one of a sequence of commands for performing a privileged operation (e.g., an operation such as firing ammunition for a weapon). Specifically, command processing subsystem 114 can determine whether a second privileged command corresponds to a second input in an input sequence for performing a privileged operation. For example, command processing subsystem 114 can compare the received command with commands in value field 306 to determine whether the received command is one of the commands for a specific privileged operation. In some embodiments, command processing subsystem 114 can compare both the first and second privileged commands with a command sequence to determine whether the combination matches a specific command sequence.
[0045] As mentioned above, Figure 3 Each command sequence (each field of value field 306) may include two or more commands that together form a privileged operation. For example, command processing subsystem 114 may determine whether a second ammunition command corresponds to a second input in an input sequence used to perform an ammunition operation. That is, a particular ammunition command can be identified as part of a privileged or ammunition operation. For example, as Figure 3 As shown, one of the privileged operations (e.g., ammunition command) can be a "fire" operation (e.g., instructing a vehicle to fire its weapon). If a second ammunition command matches a "fire" operation, or a combination of the first and second ammunition commands matches a "fire" operation, then the command processing subsystem 114 can identify that the desired operation is a "fire" operation and perform processing to instruct the vehicle to fire its weapon.
[0046] In some embodiments, the command execution system 102 may use the following operations to determine whether a second privileged command corresponds to a second input in an input sequence for performing privileged operations. Specifically, the command execution system 102 may determine whether a privileged operation mode has been activated. For example, upon receiving a first privileged command, the command execution system 102 may, for instance, set a flag in memory indicating that a privileged operation mode has been activated. Once the privileged mode is activated, the command execution system 102 may receive one or more commands via a second channel.
[0047] The command execution system 102 can determine whether multiple inputs within a second privileged command, received via a second channel, match a privileged operation. Figure 4 A vehicle controller 400 is shown, illustrating a combination of inputs received from an operator that constitute a second privileged command. For example, the second privileged command may include a combination of pressing buttons 403 and 406, followed by pressing button 409 simultaneously with pressing buttons 403 and 406. In some embodiments, the second privileged command may include multiple commands. For example, the combination of pressing buttons 403 and 406 may be part of a privileged command (e.g., in an input sequence for an ammunition command), and the combination of pressing button 409 with buttons 403 and 406 may be another part of a privileged command. Thus, a privileged command may have multiple subcommands, which can be used for comparison with a command sequence, e.g., such as... Figure 3 As shown.
[0048] Then, the command execution system 102 can determine that the second privileged command corresponds to the second input in the input sequence based on determining that (1) a privileged operation mode has been activated and (2) multiple inputs in the second privileged command match the privileged operation. In some embodiments, the command execution system 102 can first determine that a privileged mode has been activated, and then also determine that multiple inputs correspond to the second privileged command (e.g., a combination of a first privileged command and a second privileged command (or subcommand)). In some embodiments, those determinations can be performed in parallel.
[0049] In some embodiments, command execution system 102 may determine that the second privileged command corresponds to a second input in an input sequence for performing a privileged operation. Command execution system 102 may receive multiple signals from vehicle controller via a second channel indicating that a combination of input devices has been actuated. For example, signals may be received via a USB CDC serial interface. In some embodiments, signals may be received via a second wireless channel, as described above. The signals may correspond to button presses or combinations of button presses. For example, an operator may press buttons 403 and 406 on vehicle controller together. Vehicle controller may transmit those button presses to the mobile device via the second channel.
[0050] The operator can press button 409 while holding down buttons 403 and 406. Therefore, the mobile device can receive an additional signal from the vehicle controller via the second channel, indicating that the additional input device has been activated, while the combination of input devices is being activated. The additional signal can indicate that both the combination of input devices and the additional input device have been activated.
[0051] Then, command execution system 102 can determine that the combination of actuated input devices corresponds to a first portion of the input sequence, and that an additional input device actuated together with the combination of input devices corresponds to a second portion of the input sequence. As described in this invention, the second privileged command may include subcommands that can be used to identify matching privileged operations (e.g., ammunition operations). Once a match is determined, command execution system 102 can generate one or more instructions constituting the privileged operation.
[0052] In some embodiments, each privileged mode activation may allow only one privileged operation (e.g., ammunition operation). Therefore, command execution system 102 can determine that the combination of input devices is no longer actuated (e.g., the operator releases a button), and based on this determination, command execution system 102 can disengage / disable the privileged operation mode. For example, in these embodiments, once an ignition command has been sent to the vehicle, it would be necessary to restart the privileged operation mode in order to send another privileged command.
[0053] The command execution system 102 can receive one or more inputs from the operator from the vehicle controller. Figure 5 This demonstrates how to use dedicated hardware to generate commands from the vehicle controller. Figure 5 A high-reliability circuit 500 device is shown to ensure positive activation upon button press to indicate electronic arming / disarming and "go-live" button presses. The circuit system 500 is designed to mitigate parasitic transients, button debounce circuit coupling, user button variability, button failure, and other issues. Input device 503 allows operation via button 403 (…). Figure 4 The input device 506 can be triggered by the operator pressing button 406. Figure 4 The input device can be triggered by pressing button 409. Each input device can be coupled to a monitor designed to ensure proper operation during privileged operation modes. During normal operation, a monitor may not be required. Additionally, input devices 503 and 506 are connected to AND gate 512, enabling simultaneous pressing for effective operation. Input device 509 can be triggered by the operator pressing button 409. Figure 4The dedicated hardware device 514 receives all input signals and sends them to the mobile device (e.g., via the second channel if in privileged operation mode, and via the first channel if in normal operation mode).
[0054] When command execution system 102 determines that a second privileged command or a combination of a first privileged command and a second privileged command matches a privileged operation, command execution system 102 can cause a vehicle (e.g., an unmanned vehicle) to execute the command. Therefore, based on determining that the second privileged command corresponds to a second input in an input sequence for executing a privileged operation, command execution system 102 can send a request to the vehicle to execute the privileged operation. For example, command processing subsystem 114 can identify a privileged operation based on the second privileged command or a combination of the first privileged command and the second privileged command. In some embodiments, command processing subsystem 114 can use... Figure 3 The data structure in the data structure is used to perform the identification. For example, the command processing subsystem 114 can match the command sequence in the value field 306 with a second privileged command or a combination of a first privileged command and a second privileged command. As described above, the privileged operation can be an ammunition operation. Therefore, the command processing subsystem 114 can send a request to the unmanned vehicle to perform the ammunition operation based on determining that the second ammunition command corresponds to a second input in the input sequence for performing the ammunition operation.
[0055] In some embodiments, before executing a privileged operation, command processing subsystem 114 may determine whether the mobile device has permission / privilege to execute a privileged command. For example, the mobile device may require a specific government license to execute a privileged command. Therefore, command processing subsystem 114 may determine whether the mobile device is permitted to execute a privileged operation based on a privilege file upon receiving a second privileged command. For example, a government license may be a privilege file that includes data (e.g., code) for determining whether the mobile device has permission to execute a privileged operation and / or enter a privileged mode. In some embodiments, the privilege file may include data that encrypts the privileged command before sending the command to a vehicle, such that the vehicle can only execute privileged commands encrypted with the correct data (e.g., the correct key that may be stored in the privilege file). Therefore, based on the determination that the mobile device is permitted to execute a privileged operation, command processing subsystem 114 may generate an encrypted privileged operation by encrypting the privileged operation using an encryption function (e.g., an encryption function using a key from the privilege file). In some embodiments, the privilege file may include an API for generating an encrypted privileged command to be sent to a vehicle. Once the privileged operation is encrypted, command execution system 102 may (e.g., via communications subsystem 112) send the encrypted privileged command to the vehicle.
[0056] In some embodiments, command processing subsystem 114 may determine that a second privileged command or a combination of a first privileged command and a second privileged command does not match a privileged operation. For example, the second privileged command or a combination of a first privileged command and a second privileged command does not match any command sequence in value field 306. Therefore, command execution system 102 may (e.g., using command processing subsystem 114) determine that the second privileged command does not correspond to a second input in the input sequence used to perform the privileged operation. As discussed above, based on the determination that the second privileged command does not correspond to a second input in the input sequence used to perform the privileged operation, command processing subsystem 114 may stop monitoring the second channel. Alternatively or additionally, command processing subsystem 114 may disable privileged mode and place the system (e.g., mobile device and vehicle controller) in normal mode to execute manipulation and other types of commands.
[0057] In some embodiments, the command processing subsystem 114 may prompt the user to restart the privileged operation mode. Specifically, the command processing subsystem 114 may determine that the input sequence used to perform the privileged operation has been corrupted. For example, if the command processing subsystem 114 determines that a command not matching the command in the sequence used for the privileged operation has been received, the command processing subsystem 114 may determine that the privileged operation has been corrupted. In another example, if the command processing subsystem 114 determines that a combination of a first privileged command and a second privileged command does not match the command in the sequence used for the privileged operation, the command processing subsystem 114 may determine that the privileged operation has been corrupted.
[0058] Based on the determination that the input sequence used to perform the privileged operation has been corrupted, the command processing subsystem 114 may prompt the user to re-execute the first privileged command using an input mechanism associated with the mobile device. For example, the command processing subsystem 114 may generate a prompt 206 (e.g., a slider) for display. In some embodiments, the command processing subsystem 114 may generate another interactive image for display to receive input that re-enables the privileged mode.
[0059] Computing environment
[0060] Figure 6 An example computing system is illustrated that can be used according to some embodiments of the present disclosure. In some cases, computing system 600 is referred to as a computer system. The computing system may be part of mobile device 104. Those skilled in the art will understand that these terms are used interchangeably. Figure 6 The components can be used to perform actions related to... Figures 1 to 5Some or all of the operations discussed herein. Furthermore, various parts of the systems and methods described herein may include or be executed on one or more computer systems similar to computing system 600. Additionally, the processes and modules described herein may be executed by one or more processing systems similar to computing system 600.
[0061] Computing system 600 may include one or more processors (e.g., processors 610a-610n) coupled to system memory 620, input / output (I / O) device interface 630, and network interface 640 via I / O interface 650. The processor may include a single processor or multiple processors (e.g., a distributed processor). The processor may be any suitable processor capable of executing or otherwise performing instructions. The processor may include a central processing unit (CPU) that executes program instructions to perform arithmetic, logical, and I / O operations of computing system 600. The processor may execute code that creates an execution environment for the program instructions (e.g., processor firmware, protocol stack, database management system, operating system, or a combination thereof). The processor may include a programmable processor. The processor may include a general-purpose or special-purpose microprocessor. The processor may receive instructions and data from memory (e.g., system memory 620). Computing system 600 may be a single-processor system including one processor (e.g., processor 610a) or a multiprocessor system including any number of suitable processors (e.g., 610a-610n). Multiple processors may be employed to provide parallel or sequential execution of one or more portions of the techniques described herein. The processes described herein, such as logical flows, can be executed by one or more programmable processors that execute one or more computer programs to perform functions by manipulating input data and generating corresponding outputs. The processes described herein can be executed by dedicated logic circuits, and the devices can also be implemented as dedicated logic circuits, such as FPGAs (Field-Programmable Gate Arrays) or ASICs (Application-Specific Integrated Circuits). The computing system 600 may include multiple computing devices (e.g., a distributed computer system) to implement various processing functions.
[0062] I / O device interface 630 can provide an interface for connecting one or more I / O devices 660 to computer system 600. I / O devices may include devices that receive input (e.g., from a user) or output information (e.g., to a user). I / O devices 660 may include, for example, graphical user interfaces presented on a display (e.g., a cathode ray tube (CRT) or liquid crystal display (LCD) monitor), pointing devices (e.g., a computer mouse or trackball), keyboards, keypads, touchpads, scanning devices, voice recognition devices, gesture recognition devices, printers, audio speakers, microphones, cameras, etc. I / O devices 660 can be connected to computer system 600 via wired or wireless connections. I / O devices 660 can be connected to computer system 600 from remote locations. For example, I / O devices 660 located on a remote computer system can be connected to computer system 600 via a network and network interface 640.
[0063] Network interface 640 may include a network adapter that provides a connection between computer system 600 and a network. Network interface 640 may facilitate data exchange between computer system 600 and other devices connected to the network. Network interface 640 may support wired or wireless communication. The network may include electronic communication networks such as the Internet, local area network (LAN), wide area network (WAN), cellular communication network, etc.
[0064] System memory 620 may be configured to store program instructions 670 or data 680. Program instructions 670 may be executed by a processor (e.g., one or more of processors 610a to 610n) to implement one or more embodiments of the present invention. Program instructions 670 may include modules for implementing one or more technologies described herein with respect to various processing modules. Program instructions may include computer programs (which are referred to in some forms as programs, software, software applications, scripts, or code). Computer programs may be written in programming languages, including compiled or interpreted languages, or declarative or procedural languages. Computer programs may include units suitable for use in a computing environment, including as standalone programs, modules, components, or subroutines. Computer programs may or may not correspond to files in a file system. Programs may be stored as a portion of a file containing other programs or data (e.g., one or more scripts stored in a markup language document), in a single file dedicated to the program in question, or in multiple coordinating files (e.g., files storing one or more modules, subroutines, or code portions). Computer programs can be deployed to execute on one or more computer processors located locally at a site or distributed across multiple remote sites interconnected by a communication network.
[0065] System memory 620 may include a tangible program carrier on which program instructions are stored. The tangible program carrier may include a non-transitory computer-readable storage medium. A non-transitory computer-readable storage medium may include a machine-readable storage device, a machine-readable storage substrate, a memory device, or any combination thereof. A non-transitory computer-readable storage medium may include non-volatile memory (e.g., flash memory, ROM, PROM, EPROM, EEPROM), volatile memory (e.g., random access memory (RAM), static random access memory (SRAM), synchronous dynamic RAM (SDRAM)), mass storage memory (e.g., CD-ROM and / or DVD-ROM, hard disk drive), etc. System memory 620 may include a non-transitory computer-readable storage medium that may have program instructions stored thereon, which can be executed by a computer processor (e.g., one or more of processors 610a-610n) to cause the operation of the subjects and functions described herein. Memory (e.g., system memory 620) may include a single memory device and / or multiple memory devices (e.g., distributed memory devices).
[0066] I / O interface 650 can be configured to coordinate I / O traffic between processors 610a-610n, system memory 620, network interface 640, I / O devices 660, and / or other peripheral devices. I / O interface 650 can perform protocol, timing, or other data transformations to convert data signals from one component (e.g., system memory 620) into a format suitable for use by another component (e.g., processors 610a-610n). I / O interface 650 may include support for devices attached via various types of peripheral buses, such as the Peripheral Component Interconnect (PCI) bus standard or variants of the Universal Serial Bus (USB) standard.
[0067] Embodiments of the techniques described herein can be implemented using a single instance of computer system 600 or multiple computer systems 600 configured to host different portions or instances of the embodiments. Multiple computer systems 600 can provide parallel or sequential processing / execution of one or more portions of the techniques described herein.
[0068] Those skilled in the art will understand that computer system 600 is merely illustrative and not intended to limit the scope of the techniques described herein. Computer system 600 may include any combination of devices or software capable of performing or otherwise providing the performance of the techniques described herein. For example, computer system 600 may include or be a combination of cloud computing systems, data centers, server racks, servers, virtual servers, desktop computers, laptop computers, tablet computers, server equipment, client devices, mobile phones, personal digital assistants (PDAs), mobile audio or video players, game consoles, in-vehicle computers, global positioning systems (GPS), etc. Computer system 600 may also be connected to other devices not shown, or may operate as a standalone system. Furthermore, in some embodiments, the functionality provided by the illustrated components may be combined in fewer components or distributed across other components. Similarly, in some embodiments, the functionality of some of the illustrated components may not be provided, or additional functionality may be provided.
[0069] Operating procedures
[0070] Figure 7 This is a flowchart 700 for detecting errors caused by motion received from an inertial input device. Figure 7 The operation can be used with regard to Figure 6 The components described. In some embodiments, the command execution system 102 may include one or more components of the computing system 600. At 702, the command execution system 102 receives vehicle control commands via a first channel and sends the vehicle control commands to the vehicle. The command execution system 102 may receive vehicle control commands via I / O device interface 630 through I / O device 660 (via a wired USB connection) or via point-to-point wireless connection using network interface 640. The command execution system 102 may send control commands to the vehicle via network 150 using network interface 640.
[0071] At 704, command execution system 102 receives a first privileged command using an input mechanism associated with the mobile device. Command execution system 102 can receive the first privileged command using one or more I / O devices 660 via I / O device interface 630. At 706, command execution system 102 initiates a privileged operating mode. Command execution system 102 can use one or more processors 610a, 610b, and / or 610n to execute this command.
[0072] At 708, command execution system 102 receives a second privileged command from the vehicle controller via a second channel. Command execution system 102 may receive the second privileged command via a second channel of I / O device(s)60(s) through I / O device interface 630 (e.g., via a wired USB connection) or via a second channel of a point-to-point wireless connection using network interface 640. At 710, command execution system 102 determines whether the second privileged command corresponds to a second input in the input sequence for performing a privileged operation. Command execution system 102 may perform this determination using one or more processors 610a, 610b, and / or 610n. At 712, command execution system 102 sends a request to the vehicle to perform a privileged operation. Command execution system 102 may send the request to the vehicle via network 150 using network interface 640.
[0073] Although the invention has been described in detail for illustrative purposes based on embodiments currently considered to be the most practical and preferred, it should be understood that such details are for that purpose only, and the invention is not limited to the disclosed embodiments, but rather is intended to cover modifications and equivalent arrangements within the scope of the appended claims. For example, it should be understood that the invention contemplates that, to the extent possible, one or more features of any embodiment may be combined with one or more features of any other embodiment.
[0074] The embodiments described above are presented for illustrative purposes and not for limitation, and this disclosure is limited only by the appended claims. Furthermore, it should be noted that the features and limitations described in any embodiment can be applied to any other embodiment herein, and flowcharts or examples associated with one embodiment can be combined with any other embodiment in a suitable manner, performed in a different order, or performed in parallel. Additionally, the systems and methods described herein can be performed in real time. It should also be noted that the above systems and / or methods can be applied to other systems and / or methods, or used according to other systems and / or methods.
[0075] The present invention will be better understood by referring to the following examples:
[0076] 1. A method comprising: receiving a vehicle manipulation command at a vehicle controller via a first channel at a mobile device, wherein the mobile device is connected to the vehicle controller via a physical connection having a first channel and a second channel; transmitting the vehicle manipulation command to a vehicle; receiving a first privileged command using an input mechanism associated with the mobile device; activating a privileged operation mode based on receiving the first privileged command, wherein the privileged operation mode enables privileged operation using the vehicle controller; receiving a second privileged command from the vehicle controller via a second channel; determining whether the second privileged command corresponds to a second input in an input sequence for performing the privileged operation; and sending a request to the vehicle to perform the privileged operation based on determining that the second privileged command corresponds to a second input in an input sequence for performing the privileged operation.
[0077] 2. As in any of the foregoing embodiments, further comprising: determining that a second privileged command has not been received within a predetermined time threshold; and based on determining that a second privileged command has not been received within the predetermined time threshold: stopping monitoring of the second channel; and generating a prompt for displaying on the mobile device that executes the first privileged command.
[0078] 3. As in any of the foregoing embodiments, further comprising: determining that the second privileged command does not correspond to the second input in the input sequence for performing the privileged operation; and stopping monitoring the second channel based on determining that the second privileged command does not correspond to the second input in the input sequence for performing the privileged operation.
[0079] 4. As in any of the foregoing embodiments, further comprising: determining that the input sequence for performing the privileged operation has been corrupted; and based on determining that the input sequence for performing the privileged operation has been corrupted, prompting the user to re-execute the first privileged command using an input mechanism associated with the mobile device.
[0080] 5. As in any of the foregoing embodiments, wherein: receiving a vehicle control command includes receiving a vehicle control command via a Universal Serial Bus human-machine interface device interface; and receiving a second privileged command includes: receiving a second privileged command via a Universal Serial Bus communication device class interface.
[0081] 6. As in any of the foregoing embodiments, further comprising: based on receiving a second privilege command, determining whether the mobile device is allowed to perform a privileged operation based on a privilege file; and based on determining that the mobile device is allowed to perform a privileged operation, generating an encrypted privileged operation by encrypting the privileged operation using an encryption function.
[0082] 7. As in any of the foregoing embodiments, wherein sending a request to the vehicle to perform privileged operations includes privileged operations involving transmission encryption.
[0083] 8. As in any of the foregoing embodiments, wherein initiating the privileged operation mode further includes monitoring the second channel in response to a second privileged command from the vehicle controller based on receiving a first privileged command.
[0084] 9. As in any of the foregoing embodiments, wherein determining whether the second privileged command corresponds to the second input in the input sequence for performing a privileged operation further comprises: determining whether a privileged operation mode has been activated; determining whether multiple inputs within the second privileged command match a privileged operation based on the second privileged command received via the second channel; and determining that the second privileged command corresponds to the second input in the input sequence based on determining that (1) the privileged operation mode has been activated and (2) multiple inputs within the second privileged command match a privileged operation.
[0085] 10. As in any of the foregoing embodiments, wherein determining that the second privileged command corresponds to a second input in the input sequence for performing a privileged operation further comprises: receiving, via a second channel, a plurality of signals indicating that a combination of input devices has been actuated from a vehicle controller; while the combination of input devices is being actuated, receiving via the second channel an additional signal indicating that an additional input device has been actuated from a vehicle controller, wherein the additional signal indicates that both the combination of input devices and the additional input device have been actuated; determining that the actuated combination of input devices corresponds to a first portion of the input sequence, and that the additional input device actuated together with the combination of input devices corresponds to a second portion of the input sequence; and generating one or more instructions including the privileged operation.
[0086] 11. As in any of the foregoing embodiments, further comprising: determining that the combination of input devices is no longer actuated; and exiting the privileged operation mode based on determining that the combination of input devices is no longer actuated.
[0087] 12. A tangible, non-transitory, machine-readable medium storing instructions that, when executed by a data processing apparatus, cause the data processing apparatus to perform operations including any one of embodiments 1 to 11.
[0088] 13. A system comprising: one or more processors; and a memory storing instructions that, when executed by the processor, cause the processor to perform operations including any one of embodiments 1 to 11.
[0089] 14. A system comprising components for performing any one of embodiments 1 to 11.
[0090] 15. A system comprising cloud-based circuitry for performing any one of embodiments 1 to 11.
Claims
1. A system for providing fail-safe redundancy via a single data bus, the system comprising: A vehicle controller, the vehicle controller including a plurality of input devices, wherein the vehicle controller receives controller input from an operator; and A mobile device connected to the vehicle controller via a Universal Serial Bus (USB) connection, the USB connection having a first channel connected using a first interface and a second channel connected using a second interface, wherein the mobile device wirelessly transmits commands to the unmanned vehicle, the mobile device comprising: One or more processors; and One or more non-transitory computer-readable storage media storing instructions that, when executed by the one or more processors, cause the one or more processors to perform operations, the operations including: Receive vehicle control commands for operating the unmanned vehicle from the vehicle controller via the first channel; Transmit the vehicle control commands to the unmanned vehicle; The first privileged command is received using an input mechanism associated with the mobile device; Determine that the first privileged command corresponds to the first input in the input sequence used to perform the privileged operation; Based on determining that the first privileged command corresponds to the first input in the input sequence for performing the privileged operation, the second channel is monitored for the second privileged command from the vehicle controller; Receive the second privileged command from the vehicle controller via the second channel; Determine whether the second privileged command corresponds to the second input in the input sequence used to perform the privileged operation; and Based on determining that the second privileged command corresponds to the second input in the input sequence for performing the privileged operation, a request to perform the privileged operation is sent to the unmanned vehicle.
2. A method for providing fault-safe redundancy via a single data bus, the method comprising: The mobile device receives vehicle control commands from the vehicle controller via a first channel, wherein the mobile device is connected to the vehicle controller via a physical connection having the first channel and a second channel; Transmit the vehicle control commands to the vehicle; The first privileged command is received using an input mechanism associated with the mobile device; Based on receiving the first privileged command, a privileged operation mode is initiated, wherein the privileged operation mode enables privileged operation using the vehicle controller; Receive a second privileged command from the vehicle controller via the second channel; Determine whether the second privileged command corresponds to the second input in the input sequence used to perform the privileged operation; as well as Based on determining that the second privileged command corresponds to the second input in the input sequence for performing the privileged operation, a request is sent to the vehicle to perform the privileged operation.
3. The method according to claim 2, further comprising: It is determined that the second privileged command has not been received within the predetermined time threshold; and Based on the determination that the second privileged command has not been received within the predetermined time threshold: Stop monitoring the second channel; as well as Generate a prompt for display on the mobile device to execute the first privileged command.
4. The method according to claim 2, further comprising: Determine that the second privileged command does not correspond to the second input in the input sequence used to perform the privileged operation; and Based on the determination that the second privileged command does not correspond to the second input in the input sequence used to perform the privileged operation, monitoring of the second channel is stopped.
5. The method according to claim 2, further comprising: It was determined that the input sequence used to perform the privileged operation had been corrupted; and Based on the determination that the input sequence used to perform the privileged operation has been corrupted, the user is prompted to re-execute the first privileged command using the input mechanism associated with the mobile device.
6. The method according to claim 2, wherein: Receiving the vehicle control command includes receiving the vehicle control command via a Universal Serial Bus human-machine interface device interface; and Receiving the second privileged command includes receiving the second privileged command through a Universal Serial Bus communication device class interface.
7. The method according to claim 2, further comprising: Based on receiving the second privilege command, determine whether the mobile device is allowed to perform the privileged operation based on the privilege file; as well as Based on the determination that the mobile device is allowed to perform the privileged operation, an encrypted privileged operation is generated by encrypting the privileged operation using an encryption function.
8. The method according to claim 7, wherein, Sending the request to the vehicle to perform the privileged operation includes transmitting the encrypted privileged operation.
9. The method according to claim 2, wherein, Activating the privileged operation mode further includes: monitoring the second channel in response to the second privileged command from the vehicle controller based on receiving the first privileged command.
10. The method according to claim 2, wherein, Determining whether the second privileged command corresponds to the second input in the input sequence for performing the privileged operation further includes: Determine whether the privileged operation mode has been activated; Based on the second privileged command received via the second channel, determine whether multiple inputs within the second privileged command match the privileged operation; and Based on the determination that (1) the privileged operation mode has been activated and (2) the plurality of inputs within the second privileged command match the privileged operation, it is determined that the second privileged command corresponds to the second input in the input sequence.
11. The method according to claim 2, wherein, Determining that the second privileged command corresponds to the second input in the input sequence for performing the privileged operation further includes: Receive, via the second channel, multiple signals indicating that a combination of input devices has been actuated from the vehicle controller; While the combination of the input devices is being activated, an additional signal indicating that the additional input device has been activated is received from the vehicle controller via the second channel, wherein the additional signal indicates that both the combination of the input devices and the additional input device have been activated; The combination of actuated input devices is determined to correspond to a first portion of the input sequence, and the additional input device actuated together with the combination of input devices corresponds to a second portion of the input sequence; and Generate one or more instructions that include the privileged operation.
12. The method of claim 11, further comprising: It is determined that the combination of the input devices is no longer actuated; and Based on the determination that the combination of input devices is no longer actuated, the privileged operation mode is exited.
13. One or more non-transitory computer-readable media, including instructions for detecting errors caused by motion received from an inertial input device, the instructions, when executed by one or more processors, causing the one or more processors to perform operations including: The mobile device receives vehicle control commands from the vehicle controller via a first channel, wherein the mobile device is connected to the vehicle controller via a physical connection having the first channel and a second channel; Transmit the vehicle control commands to the vehicle; The first privileged command is received using an input mechanism associated with the mobile device; Based on receiving the first privileged command, a privileged operation mode is initiated, wherein the privileged operation mode enables privileged operation using the vehicle controller; Receive a second privileged command from the vehicle controller via the second channel; Determine that the second privileged command corresponds to the second input in the input sequence used to perform the privileged operation; as well as Based on determining that the second privileged command corresponds to the second input in the input sequence for performing the privileged operation, a request is sent to the vehicle to perform the privileged operation.
14. One or more non-transitory computer-readable media according to claim 13, wherein, The instruction also causes the one or more processors to: It has been determined that the second privileged command has not been received within the predetermined time threshold; and Based on the determination that the second privileged command has not been received within the predetermined time threshold: Stop monitoring the second channel; as well as Generate a prompt for display on the mobile device to execute the first privileged command.
15. One or more non-transitory computer-readable media according to claim 13, wherein, The instruction also causes the one or more processors to: It is determined that the second privileged command does not correspond to the second input in the input sequence used to perform the privileged operation; and Based on the determination that the second privileged command does not correspond to the second input in the input sequence used to perform the privileged operation, monitoring of the second channel is stopped.
16. One or more non-transitory computer-readable media according to claim 13, wherein, The instruction also causes the one or more processors to: It has been determined that the input sequence used to perform the privileged operation has been corrupted; and Based on the determination that the input sequence used to perform the privileged operation has been corrupted, the user is prompted to re-execute the first privileged command using the input mechanism associated with the mobile device.
17. One or more non-transitory computer-readable media according to claim 13, wherein, The instruction also causes the one or more processors to: Receiving the vehicle control command includes receiving the vehicle control command via a Universal Serial Bus human-machine interface device interface; and Receiving the second privileged command includes receiving the second privileged command through a Universal Serial Bus communication device class interface.
18. One or more non-transitory computer-readable media according to claim 13, wherein, The instruction also causes the one or more processors to: Based on receiving the second privilege command, determine whether the mobile device is allowed to perform the privileged operation based on the privilege file; as well as Based on the determination that the mobile device is allowed to perform the privileged operation, an encrypted privileged operation is generated by encrypting the privileged operation using an encryption function.
19. One or more non-transitory computer-readable media according to claim 18, wherein, The instructions for sending the request to the vehicle to perform the privileged operation also cause the one or more processors to send the encrypted privileged operation.
20. One or more non-transitory computer-readable media according to claim 13, wherein, The instructions for initiating the privileged operating mode also cause the one or more processors to monitor the second channel in response to the second privileged command from the vehicle controller based on the receipt of the first privileged command.