METHOD FOR OPERATING A VEHICLE, DEVICE AND VEHICLE
Patent Information
- Application Number
- DE502020013484
- Authority / Receiving Office
- DE · DE
- Patent Type
- Patents
- Current Assignee / Owner
- Priority Date
- 2019-11-26
- Filing Date
- 2020-11-10
- Publication Date
- 2026-09-03
- Estimated Expiration
- 2040-11-10
AI Technical Summary
Existing vehicle security systems are vulnerable to unauthorized use after the access element is left inside the vehicle, allowing theft or unauthorized operation.
A method that monitors the presence of an assigned authorization element during vehicle operation, transitioning to a secure state if it is not detected, and temporarily modifies performance parameters such as speed and torque to hinder unauthorized use, while ensuring minimal disruption to authorized users.
Significantly impedes unauthorized vehicle use by reducing performance parameters, yet maintains comfort and safety for authorized drivers, thereby enhancing security without compromising usability.
Description
[0001] The present application relates to a method for operating a vehicle, a device and a vehicle.
[0002] For vehicles, so-called keyless access systems are available, in which the vehicle user gains access to the vehicle by carrying an access element, without having to activate the access element. After successful access control and starting the engine, the vehicle can also be used if the access element is not or no longer present in the vehicle.
[0003] EP0610902A2 discloses an anti-theft device for a motor vehicle, in which a personal identification device is worn by an authorized operator of the motor vehicle and includes means for identifying their location near the motor vehicle. A vehicle control unit attached to the motor vehicle has a first and a second state with means that enable the operation of the motor vehicle when the control unit is in the first state, and with means that prevent the operation of the motor vehicle when the control unit is in the second state, and with means that return the control unit to the second state when the identification device has been removed from the vicinity of the motor vehicle. US20180186334A1 discloses a motor vehicle management system that provides theft prevention based on contextual information.The vehicle management platform includes sensor devices that can provide input data to determine the context of the vehicle and its operator. This context can include the vehicle's location information and the operator's identity. Based on the operator's permissions, the system can determine whether the vehicle's context violates the identified operator's permissions.
[0004] One task is to make it more difficult for a vehicle to be used without authorization.
[0005] This problem is solved by a method for operating a vehicle, a device, and a vehicle according to the independent claims. Further embodiments and advantages are the subject of the dependent claims.
[0006] A procedure for operating a vehicle, for example a motor vehicle, is specified.
[0007] The procedure monitors the presence of an assigned authorization element in the vehicle during operation. Specifically, the monitoring for the presence of the assigned authorization element takes place while driving, including after the engine has been started.
[0008] An assigned authorization element is generally defined as an item that a user of the vehicle to which the authorization element belongs can carry and that is capable of sending an authorization signal to a vehicle control unit. For example, the authorization element may be part of a key fob or a key fob itself. In other words, the assigned authorization element represents an "electronic key" for authorization to use the vehicle, such as access to the vehicle's interior and / or trunk, and / or starting the engine. Multiple authorization elements can be assigned to a single vehicle, for example, to one or more persons authorized by the vehicle owner.
[0009] In this procedure, the vehicle operates in a secure state if no assigned authorization element is detected. The vehicle can therefore be switched from a normal state to the secure state if the check for an assigned authorization element is unsuccessful. In other words, the secure state represents an operating mode that reacts to a deviation from the normal state.
[0010] In this procedure, at least one performance parameter of the vehicle is modified, at least temporarily, while the vehicle is in a secure state. A performance parameter is generally defined as a parameter that has a direct or indirect influence on the vehicle's performance. Specifically, the at least one performance parameter is modified in such a way that the vehicle's performance in the secure state is reduced compared to its performance in the normal state. Thus, in the secure state, the vehicle is placed, at least temporarily, in a state where its performance is deliberately reduced. For example, the performance parameter directly or indirectly influences the vehicle's forward motion. For instance, a performance parameter might be reduced, at least temporarily, to a value of no more than 70% of its original value.For example, after a predetermined time has elapsed since the start of the backup state, say after one minute, the value is between 40% and 60% (inclusive), approximately 50% of the original value in the normal state. Subsequently, at least one performance parameter can be further reduced, for example to a maximum of 20% or a maximum of 10. %.
[0011] In this process, an authorization code changes over time. An assigned authorization element therefore does not continuously send the same authorization code, but rather one that changes over time. This makes it more difficult for unauthorized individuals to simulate an assigned authorization element.
[0012] In at least one embodiment of the method for operating a vehicle, the presence of an assigned authorization element is monitored during vehicle operation, and the vehicle is operated in a secure state if no assigned authorization element is detected. In the secure state, at least one performance parameter of the vehicle is modified, at least temporarily.
[0013] Even after the vehicle is started, a check is performed to see if an assigned authorization element is present inside the vehicle. If the vehicle is used by an unauthorized person who does not possess an assigned authorization element, progress can be significantly hampered by placing the vehicle in a secure state, especially compared to a vehicle with a conventional vehicle security system, where an unauthorized person can use a vehicle with the engine running without restrictions as long as the engine is not switched off. In the worst-case scenario, the vehicle could be driven quickly and over long distances to a location safe for the unauthorized user and / or across national borders.
[0014] According to at least one embodiment of the method, at least one performance parameter is throttled depending on the time elapsed since the start of the safety state. For example, the performance parameter is throttled at least temporarily in a ramp-like manner. The throttling is, for instance, stepless or at least occurs in such small steps that the vehicle does not brake abruptly. This prevents the throttling of the performance parameter from posing a danger to the vehicle or other road users.
[0015] According to at least one embodiment of the method, the at least one performance parameter is throttled with a lower absolute value in a first stage of the security state than in a second stage that follows the first. In case of doubt, the specified slopes refer to the average slopes in the respective stages. The first stage begins, for example, immediately at the start of the security state, i.e., at the point in time when no associated authorization element is recognized.
[0016] Preferably, no or no significant modification, in particular no throttling of at least one performance parameter, occurs in the first stage. The first stage thus represents a waiting period during which driving is possible without restriction or at least largely without restriction. If the recognition of the assigned authorization element was unsuccessful due to a short-term disruption in data transmission, and this disruption is rectified within the first stage, the vehicle can be returned from the secure state to the normal state without any reduction in driving comfort for the authorized driver. For example, the duration of the first stage is between 5 seconds and 1 minute. The secure state can also have more than two stages, with the slope of the performance parameter varying between each stage.
[0017] According to at least one embodiment of the method, a notification is issued to the driver during the security state that the authorization element is not recognized. This notification is expediently issued during the first stage of the security state. The driver can then check for possible reasons for the failure to recognize the authorization element and, if necessary, rectify them.
[0018] According to at least one embodiment of the method, the presence of the associated authorization element is monitored repeatedly during vehicle operation. For example, the monitoring is performed continuously or at regular intervals, such as between 0.1 and 30 seconds. The shorter the interval between two checks, the faster the vehicle can be brought into the secured state.
[0019] According to at least one embodiment of the method, a pairing attempt is made between an authorization control unit of the vehicle and the assigned authorization element to monitor the presence of the associated authorization element, in particular by means of a wireless connection. For example, the wireless connection is established via radio, such as in the kHz or MHz range, Bluetooth, Near Field Communication (NFC), or WLAN (Wireless Local Area Network).
[0020] According to at least one embodiment of the method, the at least one performance parameter is a parameter that influences the vehicle's engine control. For example, the performance parameter is the vehicle's maximum speed or maximum torque. In the safety state, the engine's power output can therefore be selectively electronically limited.
[0021] For example, the maximum speed is reduced, at least temporarily, to a value between 40 and 80 km / h inclusive, preferably between 50 and 70 km / h inclusive. If the authorization element is not recognized, the driver can move to a safe location, such as a nearby parking lot. At the same time, the reduced maximum speed is so low that traveling longer distances is impossible or at least severely restricted.
[0022] According to at least one embodiment of the method, two or more performance parameters of the vehicle are modified, in particular throttled, in the secure state. For example, the maximum speed and maximum torque are throttled. The modification of the performance parameters can be carried out over different periods of the secure state and / or with different gradients.
[0023] According to at least one embodiment of the method, the vehicle switches from the secured state to its normal state when the assigned authorization element is recognized again. The authorized driver can then use the vehicle again with its original full functionality.
[0024] Furthermore, a device is specified that is configured to perform the method described above. The device includes a control unit comprising means for executing the method. For example, the method is implemented as a computer program, wherein the execution of the computer program by the device causes the vehicle, and in particular the device itself, to execute the method. The device is connected to an authorization control unit of the vehicle via a data link.
[0025] According to at least one embodiment of the device, the device is either the vehicle's engine control unit or is connected to a vehicle's engine control unit via a data link. This allows for particularly direct intervention in the vehicle's performance, especially the engine's performance. This further hinders unauthorized use of the vehicle.
[0026] Furthermore, a vehicle equipped with a device described above is specified.
[0027] According to one embodiment of the vehicle, the associated authorization element is designed to grant a driver access to the vehicle without requiring any handling, and in particular to enable its operation. "Without handling" in this context means that the driver only needs to carry the associated authorization element to use the vehicle. This provides the driver with extremely convenient access to the vehicle, while simultaneously making it considerably more difficult for unauthorized persons to use and, in particular, to move around the vehicle after it has been stolen.
[0028] Further designs and advantages will become apparent from the following description of the exemplary embodiments in conjunction with the figures.
[0029] They show: Figure 1an illustration of the operating principle of a procedure using an exemplary process; Figure 2 a schematic representation of a functional logic for a method according to an exemplary embodiment; Figure 3 a schematic representation of a functional logic for a method according to an exemplary embodiment; and Figure 4 An exemplary embodiment of a vehicle with a device for carrying out the method.
[0030] The figures are schematic representations and therefore not to scale. Individual elements may be exaggerated for clarity and / or understanding.
[0031] In Figure 1An exemplary sequence of a described procedure is shown, in which a logical signal S with the signal values 1 or 0, a maximum speed VMAX in km / h and a maximum torque MMAX in Nm are each plotted as a function of time t in seconds.
[0032] The signal S represents the result of checking for the presence of an assigned authorization element, where, for example, the signal value 1 represents a successful check and the signal value 0 represents an unsuccessful check.
[0033] At time t=0, an assigned authorization element is recognized. Accordingly, a normal state 20 exists. At a first time 201, no assigned authorization element is recognized anymore. The signal S drops from the original signal value 1 to 0.
[0034] At this first point in time 201, a change occurs to a security state 21. In the first stage 211 of security state 21, the driver of the vehicle receives, for example, a notification that no assigned authorization element has been recognized. However, within the first stage 211, there is no intervention in the vehicle's performance parameters, so the driver can continue driving without restrictions for a short time, in the example shown for 10 seconds. In particular, the driver would not experience any reduction in comfort if the assigned authorization element was only briefly not recognized correctly due to a malfunction and this malfunction ends during the duration of the first stage 211.
[0035] In a second stage 212 of the safety state 21, both the maximum speed VMAX and the maximum torque MMAX are reduced in a ramp-like manner. This ramp-like reduction of the maximum speed VMAX prevents abrupt braking of the vehicle and the associated potential danger to the driver or other road users. For example, the maximum speed is reduced to 60 km / h.
[0036] The maximum torque MMAX is reduced in two ramp-like steps. After the first ramp, for example at time t = 30 s, the maximum torque is at a non-zero lower threshold value 213, for example approximately 100 Nm, which is high enough for the driver to accelerate out of a dangerous situation. During the second ramp, for example between t = 90 s and t = 100 s, the maximum torque MMAX is continuously reduced to 0, so that the vehicle's engine no longer provides any positive acceleration.
[0037] In security state 21, particularly after the first stage 211 has ended, the vehicle's performance is significantly restricted. Even if an unauthorized person has managed to gain access to the vehicle and start the engine, the recurring monitoring for the presence of an assigned authorization element during the journey ensures that the vehicle switches to security state and that driving away from the scene of the theft is severely restricted.
[0038] At the same time, it is ensured that an authorized driver can still move the vehicle to a safe location despite the vehicle's reduced performance if their assigned authorization element is no longer recognized due to a malfunction.
[0039] Furthermore, in Figure 1 This case illustrates that an assigned authorization element is recognized again.
[0040] At a second point in time, 202, the check for the recognition of an assigned authorization element is successful, and the signal S accordingly rises to the assigned original signal value of 1. A change from security state 21 to normal state 20 occurs. The maximum speed VMAX and the maximum torque MMAX can then be increased back to their original levels. This is expediently done in such a way that no sudden acceleration or abrupt increase in the vehicle's speed occurs that would be unintentional to the driver. For example, the maximum speed VMAX and the maximum torque MMAX are increased gradually. The magnitude of this increase can also be greater than during the change from normal state 20 to security state 21.
[0041] Naturally, various modifications to the exemplary process can be made without deviating from the basic idea of the present application. For example, only one performance parameter, such as only the maximum speed or only the maximum torque, or even another performance parameter, can be modified.
[0042] The magnitude of the power parameter(s) in safety state 21 and the slope of the power parameter(s) can also differ. For example, the slope may not be constant, but may vary at least temporarily depending on the time.
[0043] Furthermore, a modification of one or more performance parameters can also occur in the first stage 211 of the security state 21. However, it is advantageous for the absolute slope of the performance parameter to be smaller in the first stage 211 than in the subsequent second stage 212.
[0044] The duration of the first stage 211 can also be varied, for example, between 5 seconds and 1 minute. It is also conceivable to omit the first stage 211 altogether.
[0045] In Figure 2 This illustrates a functional logic in which the maximum speed is modified as a performance parameter in the backup state.
[0046] The function logic receives as variable inputs a status of the authorization recognition 31 and a time 32 since the start of the security state. The time 32 since the start of the security state is fed to a characteristic field 51. The status of the authorization recognition 31 is fed to a status check 52. Furthermore, the function logic receives parameters for the maximum speed in the normal state 41, a positive gradient factor 43, and a negative gradient factor 44.
[0047] The output shows a maximum speed of 61. If the authorization detection status 31 is positive, the maximum speed of 61 corresponds to the maximum speed of 41 in the normal state.
[0048] Otherwise, i.e., in the backup state, the maximum speed is modified as a function of the time 32 since the beginning of the backup state using the maximum value image 51 and the gradient image 53.
[0049] In Figure 3 A corresponding functional logic is shown, in which the maximum torque is modified as a performance parameter in the secured state.
[0050] This functional logic essentially corresponds to that associated with Figure 2 described functional logic. In contrast, the functional logic receives a motor speed 33 as an additional variable input.
[0051] Furthermore, instead of the maximum speed, the maximum torque 42 in the normal state is specified as a parameter. The function logic outputs a maximum torque 62, which, depending on the status of the recognition of an assigned authorization element, is either the maximum torque in the normal state or a reduced maximum torque.
[0052] In Figure 4 Figure 1 shows an embodiment of a vehicle 10 with a device 1, wherein the device is configured to perform the method described above. For example, the device 1 is an engine control unit of the vehicle 10 or the device is in a data connection to the engine control unit of the vehicle.
[0053] Device 1 is in a data connection with an authorization control unit 101, which monitors the presence of an assigned authorization element 3 in the interior of the vehicle 10 and sends a corresponding signal to the device. Such authorization verification systems are also referred to as keyless entry or comfort access.
[0054] If no assigned authorization element 3 is detected during the operation of the vehicle, the driver of the vehicle can be informed of this, for example by a corresponding notice on a display device 102 in the driver's field of vision.
[0055] The assigned authorization element 3,For example, in the form of a key fob or a mobile electronic device, it is specifically designed to allow an authorized driver of vehicle 10 to access the interior of vehicle 10 and start the engine without any handling, i.e., simply by carrying it. For this purpose, a pairing takes place between the assigned authorization element 3 and the authorization control unit. An authorization code accepted by the authorization control unit 101 can change over time to increase the security of the authorization check.
[0056] Overall, the described method and such a device can significantly hinder unauthorized use of the vehicle without restricting the operating comfort of an authorized driver. Reference symbol list
[0057] 1 Device 10 Vehicle 101 Authorization control unit 102 Display device 20 Normal state 201 First time point 202 Second time point 21 Security state 211 First stage 212 Second stage 213 Lower threshold 31 Authorization recognition status 32 Time since the start of the security state 33 Engine speed 41 Maximum speed in normal state 42 Maximum torque in normal state 43 Positive gradient factor 44 Negative gradient factor 51 Characteristic map / line 52 Status check 53 Gradient images 61 Maximum speed 62 Maximum torque
Claims
1. Method for operating a vehicle (10), in which during operation of the vehicle a presence of an associated authorisation element (3) in the vehicle is monitored and the vehicle is operated in a secured state (21) when no associated authorisation element is detected, wherein in the secured state at least one performance parameter of the vehicle is at least temporarily modified, wherein an authorisation code changes with time.
2. Method according to claim 1, in which the at least one performance parameter is throttled in dependence on a time duration since beginning of the secured state.
3. Method according to claim 1 or 2, in which the at least one performance parameter is throttled in a first stage (211) of the secured state with a smaller gradient in absolute value than in a second stage (212) temporally following the first stage.
4. Method according to one of the preceding claims, in which during the secured state a notification is output to a driver of the vehicle that the authorisation element is not detected.
5. Method according to one of the preceding claims, in which the monitoring of the presence of the associated authorisation element is carried out recurrently during operation of the vehicle.
6. Method according to one of the preceding claims, in which for monitoring the presence of the associated authorisation element a pairing attempt between an authorisation control unit of the vehicle and the associated authorisation element is effected by means of a wireless connection.
7. Method according to one of the preceding claims, in which the performance parameter is a maximum speed or a maximum torque of the vehicle.
8. Method according to one of the preceding claims, in which two or more performance parameters of the vehicle are throttled in the secured state.
9. Method according to one of the preceding claims, in which the performance parameter is throttled at most down to a lower threshold value (213) up to a predetermined time duration since beginning of the secured state.
10. Method according to one of the preceding claims, in which a change from the secured state to a normal state of the vehicle occurs when the associated authorisation element is detected again.
11. Apparatus (1) with a control unit comprising means for executing a method according to one of the preceding claims, wherein the apparatus (1) is in a data connection with an authorisation control unit (101).
12. Apparatus according to claim 11, wherein the apparatus (1) is an engine control unit of the vehicle (10) or is in a data connection to an engine control unit of the vehicle (10).
13. Vehicle (10) with an apparatus (1) according to one of claims 11 or 12.
14. Vehicle (10) according to claim 13, additionally comprising the authorisation element (3), wherein the authorisation element (3) is configured to enable a driver to access the vehicle (10) without manual handling, in particular to enable vehicle operation.