Robotic control systems, methods, devices, media, and products

CN122807867APending Publication Date: 2026-09-25FAW MOLD TECHNOLOGY (CHANGCHUN) CO LTD
View PDF 0 Cites 0 Cited by

Patent Information

Application Number
CN202610911678.8
Authority / Receiving Office
CN · China
Patent Type
Applications(China)
Current Assignee / Owner
Filing Date
2026-06-23
Publication Date
2026-09-25

AI Technical Summary

Technical Problem

[0003]然而,看门狗定时器接收到不合法的喂狗报文时,仍会直接执行计数器清零,恶意篡改、伪造报文可绕过监护机制,存在设备失控安全隐患

Benefits of technology

[0008]第五方面,本发明实施例还提供了一种计算机程序产品,包括计算机程序,所述计算机程序在被处理器执行时实现如本发明实施例中任一所述的机器人控制方法。

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure CN122807867A_ABST
    Figure CN122807867A_ABST
Patent Text Reader

Abstract

The application discloses a kind of robot control system, method, equipment, medium and product.The system includes: robot, first server and second server;First server is used to send dog feeding message to second server;Second server is used to, based on first communication framework, dog feeding message is sent to robot;Robot dog feeding message verification unit is used to carry out security verification to dog feeding message, in response to dog feeding message passing security verification, send zero pulse signal to watchdog timer unit of robot;Watchdog timer unit is used to carry out counter zero operation.The technical scheme of the present application solves the problem that the security of the watchdog timer of the robot needs to be improved at present, the security of the dog feeding message can be checked by a special dog feeding message verification unit, and the counter is only zeroed under the condition that the message passes the security check, preventing malicious tampering with fake messages from affecting device operation and ensuring safe operation of the device.
Need to check novelty before this filing date? Find Prior Art

Description

Technical Field

[0001] The embodiments of the present invention relate to the field of robotics technology, and in particular to a robot control system, method, device, medium and product. Background Technology

[0002] Currently, the safety triggering of traditional robots mainly relies on the watchdog timer of the robot's hardware, which periodically detects heartbeat signals to determine whether the robot is in normal operating condition.

[0003] However, when the watchdog timer receives an illegal "feed the dog" message, it will still directly clear the counter. Malicious tampering or forgery of messages can bypass the monitoring mechanism, posing a security risk of device loss of control. Summary of the Invention

[0004] This invention provides a robot control system, method, device, medium, and product to address the issue of insufficient security in current robot watchdog timers. A dedicated watchdog message verification unit can perform security checks on watchdog messages, and the counter is reset only if the message passes the security check. This prevents malicious tampering and forgery of messages from affecting device operation and ensures safe device operation.

[0005] In a first aspect, embodiments of the present invention provide a robot control system, the system comprising: Robot, first server, and second server; The first server is used to send a dog-feeding message to the second server; The second server is used to send dog-feeding messages to the robot based on the first communication framework, which is a real-time audio and video communication framework built on the WebRTC network real-time communication protocol. The robot includes a dog-feeding message verification unit and a watchdog timing unit; The watchdog message verification unit is used to perform security verification on the watchdog message. In response to the watchdog message passing the security verification, a clear pulse signal is sent to the watchdog timer unit. The security verification includes identity verification and message integrity verification. The watchdog timer unit is used to reset the counter based on the reset pulse signal. Secondly, embodiments of the present invention provide a robot control method, the method comprising: The first server sends a dog-feeding message to the second server; The dog-feeding message is sent to the robot via the second server based on the first communication framework, which is a real-time audio and video communication framework built on the WebRTC network real-time communication protocol. The robot's watchdog message verification unit performs security verification on the watchdog message. In response to the watchdog message passing the security verification, a clear pulse signal is sent to the robot's watchdog timer unit. The security verification includes identity verification and message integrity verification. The watchdog timer unit performs a counter reset operation based on the reset pulse signal.

[0006] Thirdly, embodiments of the present invention also provide an electronic device, the electronic device comprising: At least one processor; and A memory communicatively connected to the at least one processor; wherein, The memory stores a computer program that can be executed by the at least one processor, which enables the at least one processor to perform the robot control method according to any embodiment of the present invention.

[0007] Fourthly, embodiments of the present invention also provide a computer-readable storage medium storing computer instructions, which are used to cause a processor to execute and implement the robot control method described in any embodiment of the present invention.

[0008] Fifthly, embodiments of the present invention also provide a computer program product, including a computer program that, when executed by a processor, implements the robot control method as described in any of the embodiments of the present invention.

[0009] In this embodiment of the invention, a first server is used to send a watchdog message to a second server; the second server is used to send the watchdog message to the robot based on a first communication framework, which is a real-time audio and video communication framework built on the WebRTC network real-time communication protocol; the robot includes a watchdog message verification unit and a watchdog timer unit; the watchdog message verification unit is used to perform security verification on the watchdog message, and in response to the watchdog message passing the security verification, it sends a reset pulse signal to the watchdog timer unit, the security verification including identity verification and message integrity verification; the watchdog timer unit is used to reset the counter according to the reset pulse signal. The technical solution of this embodiment of the invention solves the problem that the security of the current robot watchdog timer needs to be improved. It can perform security verification of the watchdog message through a dedicated watchdog message verification unit, and only execute the counter reset when the message passes the security verification, preventing malicious tampering and forgery of messages from affecting device operation and ensuring the safe operation of the device. Attached Figure Description

[0010] To more clearly illustrate the technical solutions of the embodiments of the present invention, the accompanying drawings used in the embodiments will be briefly introduced below. It should be understood that the following drawings only show some embodiments of the present invention and should not be regarded as a limitation on the scope. For those skilled in the art, other related drawings can be obtained based on these drawings without creative effort.

[0011] Figure 1 A schematic diagram of a robot control system provided in an embodiment of the present invention; Figure 2 This is a schematic diagram of another robot control system provided in an embodiment of the present invention; Figure 3 An alarm diagram illustrating a robot control method provided in an embodiment of the present invention; Figure 4 A schematic diagram of a robot control process provided in an embodiment of the present invention; Figure 5 A flowchart of a robot control method provided in an embodiment of the present invention; Figure 6 A flowchart illustrating yet another robot control method provided in this embodiment of the invention; Figure 7 This is a schematic diagram of the structure of an electronic device provided in an embodiment of the present invention. Detailed Implementation

[0012] The present invention will now be described in further detail with reference to the accompanying drawings and embodiments. It should be understood that the specific embodiments described herein are merely illustrative of the invention and not intended to limit it. Furthermore, it should be noted that, for ease of description, the accompanying drawings show only the parts relevant to the present invention, and not all of the structures.

[0013] It should be noted that similar reference numerals and letters in the following figures indicate similar items; therefore, once an item is defined in one figure, it does not need to be further defined and explained in subsequent figures. Furthermore, in the description of this invention, terms such as "first," "second," etc., are used only for distinguishing descriptions and should not be construed as indicating or implying relative importance. The acquisition, storage, use, and processing of data in the technical solutions of this application all comply with relevant laws and regulations.

[0014] It should be noted that in the embodiments of this application, certain software, components, models and other existing solutions in the industry may be mentioned. These should be regarded as exemplary and are only intended to illustrate the feasibility of implementing the technical solution of this application. However, it does not mean that the applicant has used or necessarily used the relevant content of the solution.

[0015] Figure 1This is a schematic diagram of a robot control system provided in an embodiment of the present invention. This embodiment can be applied to robot control scenarios.

[0016] like Figure 1 As shown, the robot control system includes: robot 110, first server 120 and second server 130.

[0017] The first server 120 is used to send a watchdog message to the second server 130; the second server 130 is used to send the watchdog message to the robot 110 based on a first communication framework, which is a real-time audio and video communication framework built on the WebRTC network real-time communication protocol; the robot 110 includes a watchdog message verification unit 111 and a watchdog timer unit 112; the watchdog message verification unit 111 is used to perform security verification on the watchdog message, and in response to the watchdog message passing the security verification, it sends a reset pulse signal to the watchdog timer unit 112, the security verification including identity verification and message integrity verification; the watchdog timer unit 112 is used to perform a counter reset operation according to the reset pulse signal.

[0018] The first server 120 can be a server-side device that deploys a cloud-based intelligent agent for robot motion task control. The intelligent agent is responsible for allocating and scheduling the robot to perform business tasks such as shopping guides and mobile operations, and sending dog-feeding messages to the robot.

[0019] In this embodiment, the first server 120 does not communicate directly with the robot 110, but sends messages to the robot 110 through a relay device, namely the second server 130.

[0020] The second server 130 sends the "feed the dog" message to the robot 110 based on the first communication framework. The first communication framework is a real-time audio and video communication framework built on the WebRTC network real-time communication protocol, specifically the LiveKit WebRTC framework. This framework uses a WiFi link for data transmission and communication. WebRTC (Web Real-Time Communication) is an open protocol that supports real-time audio and video communication between browsers and applications. LiveKit is an open-source real-time communication server framework based on WebRTC, used in this embodiment to carry the audio, video, and data channels between the robot and the cloud-based intelligent agent. The "feed the dog" message, or "feed the dog" frame, is transmitted through the Data Channel (DC), a bidirectional, low-latency data transmission channel provided by WebRTC.

[0021] The watchdog message verification unit 111 runs on a high-priority firmware process on the robot's MCU (Microcontroller Unit). It is responsible for receiving watchdog messages and performing security checks on them, such as serial number monotonicity check and HMAC-SHA256 authentication. After successful authentication, it sends a clear pulse signal to the watchdog timer unit 112. Its scheduling priority is higher than that of ordinary application processes and it is strictly isolated from the user-mode logic of the operating system.

[0022] HMAC-SHA256 (Hash-based Message Authentication Code with SHA-256) is used to verify the integrity of dog-feed frames and the identity of the sender, preventing replay attacks.

[0023] The watchdog timer unit 112 can be a WDT (Watchdog Timer), a pure hardware timer. If a reset pulse signal is not received within the preset feeding cycle, a safety response is triggered. In the safety response state, the robot 110 decelerates, stops, and starts the safety mode. The preset feeding cycle T_wd is, for example, 20 ms. If a reset pulse signal is not received for a preset number of consecutive times, it is determined to be a timeout. For example, if the preset number of times is 3, then if a reset pulse signal is not received within 60 ms, a timeout is determined. After the timeout, the robot's motion execution core is locked, prohibiting the robot from performing any motion actions. The preset feeding cycle is frozen in the factory configuration and cannot be modified during operation.

[0024] The watchdog timer unit 112 only receives the clear pulse signal from the feed message verification unit 111 and does not parse any data content. The write enable signal of the clear register of the watchdog timer unit 112 is gated by the verification completion flag bit of the feed message verification unit 111 at the hardware logic level. Clear instructions from any other software path are rejected by the hardware. This constraint is implemented through the internal logic of the chip and cannot be modified by software configuration.

[0025] The dog-feed message contains a monotonically increasing sequence number, a timestamp accurate to UTC (Coordinated Universal Time) milliseconds, and an HMAC-SHA256 signature based on a pre-shared key, which is used to prevent replay attacks and forgery.

[0026] During the counter clearing process, the watchdog timer unit 112 does not accept any trigger signals from the network layer, such as ICE (Interactive Connectivity Establishment) connection status, MQTT heartbeat, HTTP polling, etc. Specifically, the watchdog message verification unit 111 returns an error for all illegal clearing paths and does not send a clearing pulse signal to the watchdog timer unit 112. Furthermore, the ICE status register and the clearing register of the watchdog timer unit 112 are not directly connected by a bus. The write enable of the clearing pulse signal is jointly implemented by hardware logic gating rather than software switch control. The above settings changes must be approved by both hardware and firmware change control processes and do not depend on software configuration.

[0027] HMAC-SHA256 calculations must be performed on an MCU that supports hardware acceleration, such as an AES / SHA coprocessor, to ensure that the calculation latency is completed within a T_wd=20ms period; the target hardware platform must verify in factory testing that the latency of a single HMAC-SHA256 calculation is ≤2ms.

[0028] The technical solution of this embodiment involves a first server sending a watchdog message to a second server; the second server then sends the watchdog message to the robot based on a first communication framework, which is a real-time audio and video communication framework built on the WebRTC network real-time communication protocol. The robot includes a watchdog message verification unit and a watchdog timer unit. The watchdog message verification unit performs security verification on the watchdog message and sends a reset pulse signal to the watchdog timer unit in response to the watchdog message passing security verification. The security verification includes identity verification and message integrity verification. The watchdog timer unit performs a counter reset operation based on the reset pulse signal. This embodiment of the invention solves the problem of insufficient security for current robot watchdog timers. It allows for security verification of watchdog messages through a dedicated watchdog message verification unit, resetting the counter only when the message passes security verification, preventing malicious tampering and forgery of messages from affecting device operation, and ensuring safe device operation.

[0029] Figure 2 This is a schematic diagram of a robot control system provided in an embodiment of the present invention. This embodiment can be applied to robot control scenarios.

[0030] like Figure 2As shown, the robot control system includes: a robot 210, a first server 220, and a second server 230. The second server 230 includes a first alarm unit 231 and a second alarm unit 232. The first server 220 is used to send a dog-feeding message to the second server 230. The second server 230 is used to send the dog-feeding message to the robot 210 based on a first communication framework, which is based on WebRTC. A real-time audio and video communication framework is constructed using a network real-time communication protocol. The robot 210 includes a dog-feeding message verification unit 211 and a watchdog timer unit 212. The dog-feeding message verification unit 211 performs security verification on the dog-feeding message. In response to the dog-feeding message passing security verification, it sends a reset pulse signal to the watchdog timer unit 212. The security verification includes identity verification and message integrity verification. The watchdog timer unit 212 performs a counter reset operation based on the reset pulse signal. A first alarm unit 231 determines the interactive connection establishment status of the robot through interactive connection establishment status detection. If the interactive connection establishment status is abnormal, it sends an interactive connection establishment status abnormality alarm to a first server. A second alarm unit 232 detects at least one communication indicator during the communication process with the robot, obtains the communication indicator detection result, and sends a communication quality abnormality alarm to the first server in response to at least one communication indicator detection result not meeting preset normal communication conditions. The communication indicator includes at least one of latency and packet loss rate.

[0031] ICE (Interactive Connectivity Establishment) is a protocol used by WebRTC for network traversal and connection negotiation; ICE connection jitter refers to the phenomenon of repeated disconnections or reconnections caused by network fluctuations.

[0032] The first alarm unit 231 determines the robot's interactive connection establishment status through interactive connection establishment status detection. For example... Figure 3 As shown, when the interactive connection establishment status is DISCONNECTED or FAILED, an interactive connection establishment status exception alarm is sent to the robot business bus of the first server. The interactive connection establishment status exception alarm can be the robot.alert.agent_disconnected event, and no robot body actuator operation is executed.

[0033] The second alarm unit 232 performs at least one communication indicator detection on the communication process with the robot. The communication indicator can be a LiveKit QoS indicator, and obtains the communication indicator detection result. In response to the fact that at least one communication indicator detection result does not meet the preset normal communication conditions, such as end-to-end latency > 200 ms for 3 s, or packet loss rate > 5%, etc., a communication quality abnormality alarm is sent to the robot service bus of the first server. The communication quality abnormality alarm can be a robot.alert.transport_degraded event.

[0034] In an alternative implementation, the first server 220 is further configured to: In response to an alarm indicating an abnormal interactive connection establishment status or an abnormal communication quality, stop issuing new motion tasks to the robot.

[0035] like Figure 2 As shown, upon receiving an alarm indicating an abnormal interactive connection establishment status or a communication quality abnormality, the components that subscribe to the `robot.alert.*` events (i.e., those triggering the alarm) on the first server can control the robot according to the alarm policy. For example, the session management component stops accepting new session requests and freezes existing sessions, but prohibits calling the robot's emergency stop; the motion orchestration component stops issuing new high-level motion intentions, such as the navigation motion intention `NAVIGATE` and the robotic arm operation motion intention `MANIPULATE`, but prohibits directly writing them into the robot's motion execution core; the display component can display robot abnormality messages such as "Robot connection abnormal, please wait for recovery." Once the alarm is cleared, such as after a successful ICE reconnection, all components automatically resume normal operation without manual intervention.

[0036] In an alternative implementation, the first server 220 is further configured to: In response to an abnormal alarm in the interactive connection establishment status, a dog-feeding message is sent to the robot via a second communication framework; the second communication framework includes at least one of a wired Ethernet direct link and a cellular 4G link.

[0037] During the interactive connection establishment status abnormal alarm, the dog feed frame is switched to the backup gRPC (Google Remote Procedure Call) channel for transmission. This backup channel is directly connected via an independent physical link, such as the wired Ethernet between the robot body and the intelligent body board of the first server, and is physically isolated from the WiFi link used by LiveKit WebRTC. Therefore, the ICE jitter of the WiFi link does not affect the availability of the backup channel, and the WDT counter does not time out.

[0038] In one alternative implementation, in response to receiving an interactive connection establishment status abnormality alarm or a communication quality abnormality alarm, the first server cannot invoke the robot's hardware emergency stop application programming interface.

[0039] Interactive connection establishment status abnormality alarms or communication quality abnormality alarms must not call the hardware emergency stop application programming interface, i.e., the hardware emergency stop API, such as hardware_estop() or equivalent interfaces, through any IPC (Inter-Process Communication) or RPC (Remote Procedure Call) interface.

[0040] Existing systems cannot distinguish between two different types of faults: brief network jitter at the ICE layer, lasting 1-3 seconds, self-healing, and not affecting substantive security functions, and genuine continuous communication loss, which exceeds the security response time limit and requires a security shutdown. Using the same emergency stop response for both types of faults leads to a situation where jitter-induced emergency stops result in overprotection, and reconnection mechanisms mask the underlying faults, leading to insufficient protection. This embodiment, by forcibly isolating the ICE state from the WDT security chain, prevents network layer reconnection jitter from triggering an ontology emergency stop, significantly improving service continuity. The ontology WDT only accepts deterministic dog-feed frame triggers, meeting the deterministic requirements of security protocols for security trigger inputs and supporting security authentication. A clear unidirectional data flow ensures that network alarms only flow to the software degradation path, prohibiting reverse triggering of the ontology hardware interface, achieving an auditable security boundary. Network anomalies are handled autonomously by the agent-side software, and ontology security decisions are made solely by the hardware WDT, ensuring clear and verifiable responsibilities.

[0041] In this embodiment, the technical solution involves a first server sending a dog-feeding message to a second server; the second server then sends the dog-feeding message to the robot based on a first communication framework, which is WebRTC-based. A real-time audio and video communication framework is constructed using a network real-time communication protocol. The robot includes a dog-feeding message verification unit and a watchdog timing unit. The dog-feeding message verification unit performs security verification on the dog-feeding message. In response to the dog-feeding message passing security verification, it sends a reset pulse signal to the watchdog timing unit. The security verification includes identity verification and message integrity verification. The watchdog timing unit is used to reset the counter according to the reset pulse signal. The second server also includes: a first alarm unit, used to determine the interactive connection establishment status of the robot through interactive connection establishment status detection. If the interactive connection establishment status is abnormal, it sends an interactive connection establishment status abnormality alarm to the first server. A second alarm unit is used to detect at least one communication indicator during the communication process with the robot, obtain the communication indicator detection result, and send a communication quality abnormality alarm to the first server if the detection result of at least one communication indicator does not meet the preset normal communication conditions. The communication indicator includes at least one of latency and packet loss rate. The technical solution of this invention addresses the problem of insufficient security of current robot watchdog timers. It can verify the security of watchdog messages through a dedicated watchdog message verification unit, and only reset the counter when the message passes the security verification. This prevents malicious tampering and forgery of messages from affecting device operation, ensuring safe device operation. Furthermore, in the event of network quality problems or abnormal interactive connection establishment status, it only triggers software degradation and will not cause the robot to stop abruptly, thus ensuring operational safety and robot service experience.

[0042] In a specific example of robot control, the robot control process is as follows: Figure 4 As shown, the robot system communication is divided into two independent paths: the robot body safety chain is dominated by hardware WDT and the network reachability awareness chain is dominated by ICE / QoS status. A mandatory unidirectional data flow is established between the two to prevent network events from affecting the body safety decision.

[0043] In this robot control example, a simulated ICE disconnection event verifies that the body actuator did not generate an emergency stop action within 60ms. Simulated ICE repeated jittering, with three disconnections / reconnections within 1 second, verifies that the body movement was not interrupted and alarm events were correctly issued. A simulated 60ms cessation of real dog-feeding frame transmission verifies that the WDT correctly triggered the safety response, and the ICE status did not affect this triggering.

[0044] A commercial service robot is deployed in a large shopping mall and uses LiveKitWebRTC to communicate with a cloud-based intelligent agent. There are areas in the environment with unstable WiFi signals, and the ICE experiences a brief disconnection every 30-60 seconds (automatically reconnecting after about 1-3 seconds).

[0045] Before adopting this method: Every time ICE disconnection triggered an emergency stop, the robot would suddenly stop during the shopping guide, resulting in a poor user experience and frequent sudden stops causing wear and tear on the mechanical joints. After adopting this method, the ICE disconnection event is mapped to robot.alert.agent_disconnected, only triggering software degradation and suspending the acceptance of new shopping guide tasks.

[0046] The Watchdog Feeding Frames (WDT) are continuously sent by the WatchdogFeedScheduler on the agent side, with a 20ms cycle. During brief ICE disconnections, the feeding frames are switched to a backup gRPC channel for transmission. This backup channel is connected to an independent physical link, so ICE jitter on the WiFi link does not affect the availability of the backup channel, and the WDT counter does not time out. After a successful ICE reconnection, the system resumes normal operation, and the robot does not experience any abrupt stops throughout the process. In the event of a genuine communication failure, the feeding frames cannot be delivered, and the WDT triggers a safety shutdown after 60ms, unaffected by the ICE reconnection status.

[0047] If the system does not use LiveKit but uses other WebRTC implementations, such as MediaSoup, the ICE state one-way mapping principle remains unchanged; only the monitoring interface is replaced.

[0048] The backup channel for the dog-feeding frame can also use MQTT over TCP, or a local UnixSocket can be used when the agent and the host are deployed on the same machine. It should be noted that the UnixSocket solution is only suitable for deployments where the agent process and the host motion core run on the same computing platform. Its isolation guarantee differs from that of external physical links, effectively preventing accidental emergency stops triggered by remote network disconnections. However, the dog-feeding frame and ICE communication share the same local hardware platform. If additional protection against local platform-level failures, such as MCU restarts, is required, a separate hardware WDT must be used to directly respond to local heartbeat timeouts. In remote deployment scenarios, the backup channel must use a network medium physically independent of the primary channel, such as a wired Ethernet or cellular link.

[0049] The WDT trigger threshold, including the dog feeding cycle T_wd and the preset timeout number N, can be configured before leaving the factory, but it is frozen once deployed, and changes must go through the change control process.

[0050] Figure 5 This is a flowchart of a robot control method provided in an embodiment of the present invention. This embodiment can be applied to robot control scenarios.

[0051] like Figure 5 As shown, the robot control method includes the following steps: S310, send a dog-feeding message to the second server through the first server.

[0052] S320: The dog-feeding message is sent to the robot via the second server based on the first communication framework.

[0053] The first communication framework is a real-time audio and video communication framework built on the WebRTC network real-time communication protocol.

[0054] S330: The robot's watchdog message verification unit performs security verification on the watchdog message. In response to the watchdog message passing the security verification, a clear pulse signal is sent to the robot's watchdog timer unit.

[0055] Security verification includes authentication and message integrity verification.

[0056] S340: The watchdog timer unit performs a counter reset operation based on the reset pulse signal.

[0057] The technical solution of this embodiment involves sending a watchdog message to a second server via a first server; the second server then sends the watchdog message to the robot via a first communication framework, which is a real-time audio and video communication framework built on the WebRTC network real-time communication protocol; the robot's watchdog message verification unit performs security verification on the watchdog message; in response to the watchdog message passing security verification, a reset pulse signal is sent to the robot's watchdog timer unit; the security verification includes identity verification and message integrity verification; and the watchdog timer unit resets the counter according to the reset pulse signal. This embodiment solves the problem of insufficient security for current robot watchdog timers. It allows for security verification of watchdog messages through a dedicated watchdog message verification unit, resetting the counter only when the message passes security verification, preventing malicious tampering and forgery of messages from affecting device operation, and ensuring safe device operation.

[0058] Figure 6 This is a flowchart of a robot control method provided in an embodiment of the present invention. This embodiment belongs to the same inventive concept as the robot control method in the above embodiments, and further describes the abnormal alarm process.

[0059] like Figure 6 As shown, the robot control method in this embodiment includes the following steps: S410, send a dog-feeding message to the second server through the first server.

[0060] S420: The dog-feeding message is sent to the robot via the second server based on the first communication framework.

[0061] The first communication framework is a real-time audio and video communication framework built on the WebRTC network real-time communication protocol.

[0062] S430: The robot's watchdog message verification unit performs security verification on the watchdog message. In response to the watchdog message passing the security verification, a clear pulse signal is sent to the robot's watchdog timer unit.

[0063] Security verification includes authentication and message integrity verification.

[0064] S440 uses a watchdog timer unit to clear the counter based on a clear pulse signal.

[0065] S450: The first alarm unit of the second server determines the interactive connection establishment status of the robot through interactive connection establishment status detection. If the interactive connection establishment status is abnormal, an abnormal interactive connection establishment status alarm is sent to the first server.

[0066] S460. The second alarm unit of the second server performs at least one communication indicator detection on the communication process with the robot, obtains the communication indicator detection result, and sends a communication quality abnormality alarm to the first server in response to the fact that the at least one communication indicator detection result does not meet the preset normal communication conditions.

[0067] Among them, communication metrics include at least one of latency metrics and packet loss rate.

[0068] In one alternative implementation, the first server stops issuing new motion tasks to the robot in response to an alarm indicating an abnormal interactive connection establishment status or a communication quality abnormality.

[0069] In one alternative implementation, in response to an abnormal status alarm during interactive connection establishment, a first server sends a dog-feeding message to the robot via a second communication framework; the second communication framework includes at least one of a wired Ethernet direct link and a cellular 4G link.

[0070] In one alternative implementation, in response to receiving an interactive connection establishment status abnormality alarm or a communication quality abnormality alarm, the first server cannot invoke the robot's hardware emergency stop application programming interface.

[0071] The technical solution of this embodiment involves sending a dog-feeding message to a second server via a first server; the second server then sends the dog-feeding message to the robot based on a first communication framework, which is a real-time audio and video communication framework built on the WebRTC network real-time communication protocol; the robot's dog-feeding message verification unit performs security verification on the dog-feeding message, and in response to the dog-feeding message passing security verification, a reset pulse signal is sent to the robot's watchdog timer unit, the security verification including identity verification and message integrity verification; the watchdog timer unit performs a counter reset operation according to the reset pulse signal; the second server's first alarm unit determines the robot's interactive connection establishment status through interactive connection establishment status detection, and sends an interactive connection establishment status abnormality alarm to the first server if the interactive connection establishment status is abnormal; the second server's second alarm unit detects at least one communication indicator in the communication process with the robot, obtains the communication indicator detection result, and sends a communication quality abnormality alarm to the first server if the at least one communication indicator detection result does not meet the preset normal communication conditions. The technical solution of this invention addresses the problem of insufficient security of current robot watchdog timers. It can verify the security of watchdog messages through a dedicated watchdog message verification unit, and only reset the counter when the message passes the security verification. This prevents malicious tampering and forgery of messages from affecting device operation, ensuring safe device operation. Furthermore, in the event of network quality problems or abnormal interactive connection establishment status, it only triggers software degradation and will not cause the robot to stop abruptly, thus ensuring operational safety and robot service experience.

[0072] Figure 7 A schematic diagram of an electronic device 10, which can be used to implement embodiments of the present invention, is shown. The electronic device is intended to represent various forms of digital computers, such as laptop computers, desktop computers, workstations, personal digital assistants, servers, blade servers, mainframe computers, and other suitable computers. The electronic device can also represent various forms of mobile devices, such as personal digital processors, cellular phones, smartphones, wearable devices (e.g., helmets, glasses, watches, etc.), and other similar computing devices. The components shown herein, their connections and relationships, and their functions are merely illustrative and are not intended to limit the implementation of the invention described and / or claimed herein.

[0073] like Figure 7As shown, the electronic device 10 includes at least one processor 11 and a memory, such as a read-only memory (ROM) 12 or a random access memory (RAM) 13, communicatively connected to the at least one processor 11. The memory stores computer programs executable by the at least one processor. The processor 11 can perform various appropriate actions and processes based on the computer program stored in the ROM 12 or loaded from storage unit 18 into the RAM 13. The RAM 13 can also store various programs and data required for the operation of the electronic device 10. The processor 11, ROM 12, and RAM 13 are interconnected via a bus 14. An input / output (I / O) interface 15 is also connected to the bus 14.

[0074] Multiple components in electronic device 10 are connected to I / O interface 15, including: input unit 16, such as keyboard, mouse, etc.; output unit 17, such as various types of displays, speakers, etc.; storage unit 18, such as disk, optical disk, etc.; and communication unit 19, such as network card, modem, wireless transceiver, etc. Communication unit 19 allows electronic device 10 to exchange information / data with other devices through computer networks such as the Internet and / or various telecommunications networks.

[0075] Processor 11 can be a variety of general-purpose and / or special-purpose processing components with processing and computing capabilities. Some examples of processor 11 include, but are not limited to, a central processing unit (CPU), a graphics processing unit (GPU), various special-purpose artificial intelligence (AI) computing chips, various processors running machine learning model algorithms, a digital signal processor (DSP), and any suitable processor, controller, microcontroller, etc. Processor 11 performs the various methods and processes described above, such as robot control methods.

[0076] In some embodiments, the robot control method may be implemented as a computer program tangibly contained in a computer-readable storage medium, such as storage unit 18. In some embodiments, part or all of the computer program may be loaded and / or mounted on electronic device 10 via ROM 12 and / or communication unit 19. When the computer program is loaded into RAM 13 and executed by processor 11, one or more steps of the robot control method described above may be performed. Alternatively, in other embodiments, processor 11 may be configured to execute the robot control method by any other suitable means (e.g., by means of firmware).

[0077] Various embodiments of the systems and techniques described above herein can be implemented in digital electronic circuit systems, integrated circuit systems, field-programmable gate arrays (FPGAs), application-specific integrated circuits (ASICs), application-specific standard products (ASSPs), system-on-a-chip (SoCs), complex programmable logic devices (CPLDs), computer hardware, firmware, software, and / or combinations thereof. These various embodiments may include implementations in one or more computer programs that can be executed and / or interpreted on a programmable system including at least one programmable processor, which may be a dedicated or general-purpose programmable processor, capable of receiving data and instructions from a storage system, at least one input device, and at least one output device, and transmitting data and instructions to the storage system, the at least one input device, and the at least one output device.

[0078] Computer programs used to implement the methods of the present invention may be written in any combination of one or more programming languages. These computer programs may be provided to a processor of a general-purpose computer, a special-purpose computer, or other programmable data processing device, such that when executed by the processor, the computer programs cause the functions / operations specified in the flowcharts and / or block diagrams to be performed. The computer programs may be executed entirely on a machine, partially on a machine, or as a standalone software package, partially on a machine and partially on a remote machine, or entirely on a remote machine or server.

[0079] In the context of this invention, a computer-readable storage medium can be a tangible medium that may contain or store a computer program for use by or in conjunction with an instruction execution system, apparatus, or device. A computer-readable storage medium may include, but is not limited to, electronic, magnetic, optical, electromagnetic, infrared, or semiconductor systems, apparatus, or devices, or any suitable combination thereof. Alternatively, a computer-readable storage medium may be a machine-readable signal medium. More specific examples of machine-readable storage media include electrical connections based on one or more wires, portable computer disks, hard disks, random access memory (RAM), read-only memory (ROM), erasable programmable read-only memory (EPROM or flash memory), optical fibers, portable compact disk read-only memory (CD-ROM), optical storage devices, magnetic storage devices, or any suitable combination thereof.

[0080] To provide interaction with a user, the systems and techniques described herein can be implemented on an electronic device having: a display device (e.g., a CRT (cathode ray tube) or LCD (liquid crystal display) monitor) for displaying information to the user; and a keyboard and pointing device (e.g., a mouse or trackball) through which the user provides input to the electronic device. Other types of devices can also be used to provide interaction with the user; for example, feedback provided to the user can be any form of sensory feedback (e.g., visual feedback, auditory feedback, or tactile feedback); and input from the user can be received in any form (including sound input, voice input, or tactile input).

[0081] The systems and technologies described herein can be implemented in computing systems that include backend components (e.g., as data servers), or middleware components (e.g., application servers), or frontend components (e.g., user computers with graphical user interfaces or web browsers through which users can interact with implementations of the systems and technologies described herein), or any combination of such backend, middleware, or frontend components. The components of the system can be interconnected via digital data communication of any form or medium (e.g., communication networks). Examples of communication networks include local area networks (LANs), wide area networks (WANs), blockchain networks, and the Internet.

[0082] A computing system can include clients and servers. Clients and servers are generally located far apart and typically interact through communication networks. The client-server relationship is created by computer programs running on the respective computers and having a client-server relationship with each other. The server can be a cloud server, also known as a cloud computing server or cloud host, which is a hosting product within the cloud computing service system to address the shortcomings of traditional physical hosts and VPS services, such as high management difficulty and weak business scalability.

[0083] It should be understood that the various forms of processes shown above can be used, with steps reordered, added, or deleted. For example, the steps described in this invention can be executed in parallel, sequentially, or in different orders, as long as the desired result of the technical solution of this invention can be achieved, and this is not limited herein.

[0084] This invention also provides a computer program product, including a computer program that, when executed by a processor, implements the robot control method provided in any embodiment of this application.

[0085] In implementing the computer program product, computer program code for performing the operations of this invention can be written in one or more programming languages ​​or a combination thereof. Programming languages ​​include object-oriented programming languages ​​such as Java, Smalltalk, and C++, as well as conventional procedural programming languages ​​such as C or similar languages. The program code can be executed entirely on the user's computer, partially on the user's computer, as a standalone software package, partially on the user's computer and partially on a remote computer, or entirely on a remote computer or server. In cases involving remote computers, the remote computer can be connected to the user's computer via any type of network—including a local area network (LAN) or a wide area network (WAN)—or can be connected to an external computer (e.g., via the Internet using an Internet service provider).

[0086] It should be understood that the various forms of processes shown above can be used, with steps reordered, added, or deleted. For example, the steps described in this invention can be executed in parallel, sequentially, or in different orders, as long as the desired result of the technical solution of this invention can be achieved, and this is not limited herein.

[0087] The specific embodiments described above do not constitute a limitation on the scope of protection of this invention. Those skilled in the art should understand that various modifications, combinations, sub-combinations, and substitutions can be made according to design requirements and other factors. Any modifications, equivalent substitutions, and improvements made within the spirit and principles of this invention should be included within the scope of protection of this invention.

Claims

1. A robot control system, characterized in that, include: Robot, first server, and second server; The first server is used to send a dog-feeding message to the second server; The second server is used to send the dog-feeding message to the robot based on the first communication framework, wherein the first communication framework is a real-time audio and video communication framework built on the WebRTC network real-time communication protocol; The robot includes a dog-feeding message verification unit and a watchdog timing unit; The watchdog message verification unit is used to perform security verification on the watchdog message. In response to the watchdog message passing the security verification, a clear pulse signal is sent to the watchdog timer unit. The security verification includes identity verification and message integrity verification. The watchdog timer unit is used to perform a counter reset operation based on the reset pulse signal.

2. The system according to claim 1, characterized in that, The second server also includes: The first alarm unit is used to determine the interactive connection establishment status of the robot through interactive connection establishment status detection, and to send an interactive connection establishment status abnormality alarm to the first server if the interactive connection establishment status is abnormal.

3. The system according to claim 2, characterized in that, The second server also includes: The second alarm unit is used to detect at least one communication indicator during the communication process with the robot, obtain the communication indicator detection result, and send a communication quality abnormality alarm to the first server in response to at least one of the communication indicator detection results not meeting the preset normal communication conditions. The communication metrics include at least one of latency metrics and packet loss rate.

4. The system according to claim 3, characterized in that, The first server is also used for: In response to an alarm indicating an abnormal interactive connection establishment status or an alarm indicating an abnormal communication quality, the issuance of new motion tasks to the robot is stopped.

5. The system according to claim 2, characterized in that, The first server is also used for: In response to the abnormal alarm of the established interactive connection status, the dog-feeding message is sent to the robot through the second communication framework; The second communication framework includes at least one of a wired Ethernet direct link and a cellular 4G link.

6. The system according to claim 3, characterized in that, In response to receiving an alarm indicating an abnormal interactive connection establishment status or an alarm indicating an abnormal communication quality, the first server shall not invoke the robot's hardware emergency stop application programming interface.

7. A robot control method, characterized in that, include: The first server sends a dog-feeding message to the second server; The second server sends the dog-feeding message to the robot based on the first communication framework, which is a real-time audio and video communication framework built on the WebRTC network real-time communication protocol. The robot performs security verification on the dog-feeding message through the dog-feeding message verification unit. In response to the dog-feeding message passing the security verification, a clear pulse signal is sent to the watchdog timer unit of the robot. The security verification includes identity verification and message integrity verification. The watchdog timer unit performs a counter reset operation based on the reset pulse signal.

8. An electronic device, characterized in that, It includes at least one processor; and a memory communicatively connected to the at least one processor; wherein the memory stores a computer program executable by the at least one processor, the computer program being executed by the at least one processor to enable the at least one processor to perform the robot control method of claim 7.

9. A computer-readable storage medium, characterized in that, The computer-readable storage medium stores computer instructions that are used to cause a processor to execute the robot control method of claim 7.

10. A computer program product, comprising a computer program, characterized in that, When the computer program is executed by the processor, it implements the robot control method as described in claim 7.