Security of advanced short-range communication architecture

Modulated active sensor waveforms in autonomous systems verify echoes to ensure secure data transmission, addressing security threats and enhancing the reliability of autonomous operations in vehicles, factories, and homes by isolating trusted data.

JP2025122135APending Publication Date: 2025-08-20ウエストマイヤーポール +2
View PDF 5 Cites 0 Cited by

Patent Information

Application Number
JP2025086953
Authority / Receiving Office
JP · JP
Patent Type
Applications
Current Assignee / Owner
Priority Date
2019-04-03
Filing Date
2025-05-26
Publication Date
2025-08-20

AI Technical Summary

Technical Problem

Existing autonomous systems face security threats from unauthorized code modifications and invalid input data, which compromise the trustworthiness of computing systems, especially in environments beyond connected computing systems, such as autonomous vehicles and robotic systems in factories and homes.

Method used

Modulated active sensor waveforms are used to transmit data within systems, verifying echoes between paired transmitters and receivers to ensure secure communication, isolating trusted data from unauthorized inputs, and establishing secure intra-system and inter-system data links.

Benefits of technology

Enhances the security of autonomous operations by ensuring that only trusted data is processed, preventing unauthorized data from affecting critical systems, thereby improving the reliability and safety of autonomous vehicles, factory operations, and home environments.

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure 2025122135000001_ABST
    Figure 2025122135000001_ABST
Patent Text Reader

Abstract

To enhance security of autonomous actions for robotic systems on roads and in factories, transportable computers in office and home environment.SOLUTION: Modulated active sensor waveforms are used to transport data, within a system, to a decision-making computer, in an autonomous or semi-autonomous operation environment. Modulation creates distinct waveforms when a multitude of in-band signals are present. The waveform content is shared between the paired transmitter and receiver, validating the data content of the echo. Variable data are the modulation pattern, controlled by a processor within the system, matching patterns tests at the receiver select which data enter the critical autonomous processes. Matched echoes are secured controlled communications. Validation of the system's transmitter modulation, at the receiver, enhances security of autonomous actions for robotic systems.SELECTED DRAWING: Figure 1
Need to check novelty before this filing date? Find Prior Art

Description

[Background technology]

[0001] CROSS-REFERENCE TO RELATED APPLICATIONS This invention is based on provisional patent application No. 62 / 828,756, filed April 3, 2019. It is based on the principle of equality and equal opportunity, and we will assert our interests in it.

[0002] In one embodiment, the present invention is a method for securing a system data link between a transmitter and an associated receiver as a co-located pair, where a uniquely modulated waveform transmitted by the transmitter is reflected back to the receiver as an echo.

[0003] Autonomous operation has become commonplace, if not essential, in society, and various threats to computing systems in autonomous operation have become apparent. Computers are interacting with each other in every new application imaginable by humans. The fact that product safety is at a crossroads in various challenges is evident when decisions and actions previously performed by humans are now being performed by robots. The trustworthiness of the computing behind robotic actions is a common theme. Autonomous vehicles on the road are considered safe, but are they truly safe? Are actuators controlled by computer instructions truly secure? Robots are increasingly replacing humans in warehouse operations, especially in newly built facilities. Recent reports indicate that security remains a concern that has not yet been fully resolved.

[0004] Although great progress has been made in securing computers, malicious activity is becoming more apparent. U.S. Patent No. 9,749,342 detects malicious activity on a computing system by monitoring its function with independent external sensors. U.S. Patent No. 10,419,131 measures communications links and requires authentication by authorized users, which isolates the authentication from both the Internet and the computer, preventing malicious activity. Threats and malicious behavior must be addressed in environments beyond the scope of simply connected computing systems, such as autonomous behavior. Computer processing threats to autonomous behavior arise from unauthorized code modifications and invalid input data.

[0005] Fully autonomous vehicles have been discussed for decades and are now in the road testing stage. It has established a global definition of autonomous vehicles, ranging from manual (Level 0 or L0) to fully autonomous (Level 5 or L5) where human interface is no longer present. Many L2 vehicles on the road are driver-assisted vehicles that operate more or less within normal scenarios. L5 geofenced taxi services are available in some cities.

[0006] Industrial robots have a long history, from magnetic tape routes for mail service on office floors that forced humans to be aware of robots to robotic delivery systems.

[0007] Similarly, factories with robotic assistants for difficult tasks (tasks that are difficult in terms of size, weight, or other factors) are also welcomed. In warehouse operations, manual assistants are being replaced by human alternatives.

[0008] In the early days, the shift to robotics was accepted as "normal." For example: Examples include cash dispensers, self-service gas stations, and grocery stores. These examples still involve human interaction with the customer. Limited "pickup" is available in grocery stores, where customers do not shop by walking down the aisles. Some grocery stores also sell products by having a detector / transmitter connected to a computer and moving down the aisles of the store to "check out" products.

[0009] The use of robots in human-centric scenarios is becoming a reality, whether it be in homes, schools, factories, or offices. Securing human-robot interactions to protect humans and other valuable assets is becoming more complex as malicious threats become larger and more prevalent. However, in situations where humans are unaware of their interaction with a robot, such as autonomous operation, and where they may be locked out for authentication purposes, an additional level of security is essential.

[0010] Smaller, more powerful computing systems will be populated by globes, teams of research mesh networks, crowdsourced computing, etc. Large numbers of vehicles will provide the computing power, and most of the time these systems will sit idle. Summary of the Invention [Means for solving the problem]

[0011] Modulated active sensor waveforms are used within systems to transmit data to decision-making computers in autonomous or semi-autonomous operating environments. When multiple in-band signals are present, modulation generates distinct waveforms. The waveform content is shared between paired transmitters and receivers, and the data content of the echoes is verified. The variable data is a modulation pattern controlled by a processor within the system, and matched pattern tests at the receiver select which data enters critical autonomous processes. Matched echoes ensure controlled communication. Verification of the system's transmitter modulation at the receiver improves the security of autonomous operation in roadway and factory robotic systems, as well as portable computers in office and home environments. Secondarily, once secure communications are established, these secure, unused resources can be safely aggregated and reallocated without risk to primary functions.

[0012] In one embodiment, the present invention is a method for securing a system's data link between a transmitter and an associated receiver as a co-located pair. A uniquely modulated waveform transmitted by the transmitter is reflected back to the receiver as an echo. The uniquely modulated waveform is constructed from dynamic data. A matching filter compares a stored copy of the transmitted uniquely modulated waveform with echoes collected by the receiver, accounting for expected variations due to reflections from stationary and moving objects. The matching echoes are from the transmitter, not from secondary sources, and provide secure input for an autonomous algorithm for decision-making.

[0013] In a second embodiment, the present invention is a method for securing multiple data links between multiple independent system transmitters and receivers as correlated pairs of transmitters and receivers associated with each transmitter. Each uniquely modulated waveform transmitted by the transmitter of any pair is reflected back to the paired receiver as an echo. The unique modulated waveforms are constructed from dynamic system data, and a matching filter compares a stored copy of each individual waveform of the uniquely modulated signal transmitted by each transmitter with the collected echoes of the paired receiver, taking into account expected variations due to reflections from stationary and moving objects. The matching echoes are from the paired transmitters associated with the paired receiver, and not from some secondary source. Collectively, the many individual matching pairs are used for decision making. Provide multiple secure inputs to a given algorithm.

[0014] In a third embodiment, the present invention is a method for combining passive and active signals from a single system to form a composite signal, where the active component data is validated by the passive component data, and the active data is passed to an autonomous decision process within the system that provides secure input for the decision-making algorithm. [Brief explanation of the drawings]

[0015] [Figure 1] FIG. 1 shows waveforms of a modulated active sensor used in the method of the present invention. DETAILED DESCRIPTION OF THE INVENTION

[0016] Modulation techniques applied to active short-range radar and LiDAR, as well as similar systems at other wavelengths, create products that offer broader uses beyond radar or LiDAR applications to determine range, relative velocity, and angle to objects.

[0017] The figure shows a modulated active sensor waveform used in the method of the present invention. The waveform is used in a system to communicate data to a decision-making computer in an autonomous or semi-autonomous operating environment. Modulation can be used to create different waveforms that allow for multiple discrete in-band signals to exist.

[0018] The first product is secure intra-system communications used to support autonomous control, where some aspects of the intra-system data represent objects outside the system (radar echoes of the objects). Unlike traditional radar or LiDAR products, the security this waveform represents is used to support the underlying product: vehicle autonomous driving. If the radar or LiDAR data is unreliable, the resulting actions based on those data are also unreliable. Adding modulation validation tests to traditional tests (range, Doppler, angle) ensures that the data is not corrupted. Furthermore, radar or LiDAR data that fails modulation echo pattern tests at the receiver is excluded from the autonomous driving system. The autonomous sensor suite also includes passive sensors as a secondary source of validation to the active sensors.

[0019] The second product is self-contained in-system control without autonomous capabilities. When an entire system, such as a factor, is integrated with modulated radar or LiDAR, further functional benefits arise for ensuring the operation of equipment in a factory. Machine-to-machine or machine-to-human control can be fixed with a single modulated transmitter / receiver pair or multiple modulated transmitter / receiver pairs.

[0020] Another product is the system-to-system transfer of data for situational awareness. When a first vehicle on the road detects the radar or LiDAR of another vehicle, the data message used for modulation may be useful for the first vehicle's nearby movements. As autonomous driving spreads to vehicles on the road, vehicle behavior will be like a flock of birds, where the group's behavior can be predicted. Predicting behavior requires visibility into the current situation and future expectations, and manual signal lights serve as an alert for future actions. Predictions are possible if meaningful data is available from other vehicles and can be shared by machines. With vehicle-to-vehicle (system-to-system) communication enabled, simple things like road hazards can be efficiently shared with vehicles that encounter them. Dedicated Short-Range Communications (DSRC) systems are not actually essential for vehicles. Radar and LiDAR in Collision Avoidance Systems (CAS) iDAR is generic and provides an easy avenue for enhancement by adding new functionality to these ubiquitous elements.

[0021] Secure intra-system communications defines the integrity of data generated by the system, with some aspects representing non-system objects. Radar echoes are data generated by waveforms that originate and terminate within the system, but represent objects not within the system. Securing communications through random modulation prevents spurious / illegible waveforms from falsely indicating range / relative velocity / angle to any object. The modulation is unique and known only to the paired transmitter / receiver and which system processor controlled the data used to generate the modulation sequence.

[0022] Within a system, much communication is data-centric, such as performance telemetry or standard actuator functions (window up / down). Preventing unintended behavior or functional changes in performance as a result of spurious / illegal signals can be eliminated by isolating the data transferred on the modulation link from any other waveforms. Similarly, the waveform modulation between individual transmitters / receivers, or groups of individual paired transmitters / receivers, is unknown except to the transmitters / receivers that generated the data used in the modulation and the system processor, ensuring that spurious / illegal signals cannot induce behavior.

[0023] When all transmitter / receiver pairs are in the system, a new approach for multi-layered protection can be adopted. The operating mechanism (objects on an assembly line) has a human interface, such as a remote control for an overhead crane, which is operated remotely (at a location safe for the human). Through the remote control, the human triggers the remote's transmitter / receiver to transmit a radio signal to several other pairs of transmitter / receivers, and only when the additional pairs activate their signals to each other does the overhead crane execute a command to the overhead crane mechanism. Telemetry of the relative geometric relationships of the operating transmitter / receiver pairs, unique at that time, is contained in their modulation from each other. The factory provides a commercial location service to identify the location of all equipment.

[0024] Insecure inter-system data is also generated by modulated waveforms, but in this scenario the waveform originates outside the system that processed it. Although these data are insecure because the receiving system cannot verify them, they can be useful in describing the environment. A typical example is situational awareness for vehicles on a road.

[0025] In developing a safe process where a computer is operating autonomously, the data input to the computer controlling the autonomous operation must be considered. Isolating trusted data from all other data inputs to the autonomous control system can be achieved using short-range wireless radar or LiDAR systems. The unique modulation of a transmitter / receiver pair allows the receiver to distinguish the signal emanating from that transmitter from all other in-band signals because it has a "copy" of the data used to define the transmitter's modulation. The modulation pattern needs to be changed frequently to prevent other transmitters from using the "copy" to transmit data (intentional tampering).

[0026] Modulating the waveform of an active sensor's transmission allows for echo verification of the data by a paired receiver. Many modulation techniques are known. Radar and LiDAR systems operate with simple waveforms, and in some cases, these waveforms are unmodulated and the echoes are effectively paired with a universal signal. In the case of radar, a universal chirp is essentially a frequency ramp from a start frequency to an end frequency with no amplitude, phase, or other signal modulation. Echoes are checked for time of flight (which determines range), Doppler shift (which defines relative motion), and angle. Li DAR is somewhat different from radar, but has essentially the same range, Doppler, and angle capabilities. A common modulation for LiDAR is pulse position, where the data is the time between pulses (defined by a clock function).

[0027] For data trust, there are two defined environments: the intra-network, where all waveform echoes are confined within the autonomously operating system, and the intra-network, where some waveforms interact with external surfaces outside the autonomously operating system to generate their echoes. When external waveform echoes are allowed, the receiver potentially detects additional in-band signals that perform similar functions for similar systems that share the same outside-world interface. These additional in-band signals from external waveforms can be echoes or unreflected signals (direct line-of-sight between the unknown transmitter and the system receiver).

[0028] An example of a confined scenario is a factory with fixed and mobile machines. Each machine has one or more transmitters / receivers, and data is defined by a local processor built into the machine / factory. Data is transmitted between various trusted nodes in the network. The data has not been tampered with. In this case, the building's relatively large physical dimensions make it susceptible to stray in-band energy, likely from nearby systems using similar technology. Stray signals are intentionally attenuated to avoid detection by the system receivers. Various attenuation solutions are known, including baffling the receivers with wall or window installations.

[0029] Autonomous driving can be limited to a small area, such as the interior of a car, where the vehicle is small compared to a factory, but in a rural road environment there are many other vehicles using the same technology.

[0030] Current radar / LiDAR transmission and reception in Collision Avoidance Systems (CAS) The pair is designed for a range of several hundred meters, which is sufficient for factory setups and is sufficient for automobiles. The corresponding radar and LiDAR are the central transmitter / receiver of the pair, but any other active sensor is also possible.

[0031] A conventional automotive CAS is an example of an exterior surface that generates a wave-shaped reflection.

[0032] Autonomous data trust can be established in systems using wireless transmitters / receivers with changing patterns within the data field, where control over the change patterns is an internal process. In more advanced trust scenarios, groups of transmitter / receiver pairs are very practical. When data trust processes are designed to accommodate diverse changing patterns, the likelihood of catching attempts to inject fraudulent data increases.

[0033] Two types of data patterns are defined: fixed metadata and data (sourced from telemetry collected by the system) patterns. The header and other overhead bits represent metadata. The header / overhead bits are deterministic and provide context for the rest of the message. Unfortunately, these overhead bits are highly deterministic, which means they can generally be copied or predicted as to which changes will occur in the data field. True data bits are uniquely defined for each message. The data bits have a weak relationship from sample to sample and are random enough to make copying previous messages redundant. Also, changes are difficult to predict. More complex relationships between multiple transmitter / receiver pairs can make them unpredictable.

[0034] The modulated waveform check is either emitted from a paired transmitter or The source of the waveform can be quickly isolated as either originating from the paired transmitter or not. This check requires data with sufficient pulse-to-pulse variation to rule out copied pulses that are used as "false echoes." A "false echo" is defined as a waveform sent back to the origin that has the expected attributes of a reflected echo of the original paired transmitter.

[0035] A typical radar chirp in the 76-81 GHz band has a pulse repetition rate of 2 kHz, and can support hundreds of Mbps when modulated using conventional techniques. For reference, a 75 MHz bandwidth in a Dedicated Short-Range Communications (DSRC) system can accommodate data rates of 6-27 Mbps. Industry standards such as DSRC are important for interoperability.

[0036] While much of this document will follow a radar-centric discussion, it applies to both radar and LiDAR, as well as newer forms of photonic communications including light-emitting diodes (LEDs) and ultraviolet and infrared wavelengths.

[0037] In a single transmitter / receiver pair connected to a "central" processor, modulation data representing the contribution of a variable data field defined by the processor (either the central processor in the chipset or a local processor) is used to modulate the chirp. Where the central processor gets the data is not important. Since the chipset does its own processing and is not a "central processor," the processing of matching the transmitted waveform to the received echo is performed "on-chip." This on-chip processor also performs the typical range, Doppler, and angle calculations.

[0038] After the on-chip processor has processed each chirp's four attributes (pattern check, range, Doppler, and angle), it can decode other content in the received signal. Within the pattern is information data. For echoes that meet all four attributes, including modulation matching, these data are sent to the central processor to contribute to any autonomous driving decisions. For waveforms that fail the pattern match filter, the waveform is processed as information that may or may not be useful in some way to the system's computer. The road hazard mentioned above is an example of information data.

[0039] Radar propagates at the speed of light, and echoes return to the receiver in less than a microsecond for most range bins. A complete chirp duration (2 kHz pulse repetition rate) lasts for about 0.5 milliseconds. Detection of the pulse train by the secondary receiver (assuming it is corrupted) is simple, and the response is also simple, containing false echoes of objects farther away than the actual secondary receiver location, which injects corrupted data over time. However, the respective checks fail in Doppler or angle.

[0040] A typical collision avoidance system in an automobile has active sensors covering all directions. While a single sensor can work, using multiple sensors makes false signals impractical. A single rogue radar source at some random distance from a moving vehicle equipped with CAS (modulation) will initially be part of the field-of-regard of several CASs at longer ranges, and as the ranges become closer, some of the previously overlapping fields-of-regard will no longer overlap. Any CAS present in the beam of the rogue radar source may continue to fail some echo tests (range, Doppler, angle) for some of the energy collected by the receiver, even though the pattern test may not function properly. In such a scenario, unless the receiver is in a denial-of-service (DoS) mode triggered by the rogue signal or some additional signal, the original waveform is still being processed. This transmitter / receiver pair is essential for vehicle autonomous operation. If it is critical, the vehicle must take appropriate action to stop the DoS itself.

[0041] A secondary purpose of providing telemetry as modulated data is to provide non-control data as information to a second vehicle without impairing the autonomous operation of either vehicle. Each vehicle can isolate its own radar signal from other sources.

[0042] Telemetry from all Electronic Control Units (ECUs) , which is data that fills the "true data" or variable data in the modulation of waveforms. Data from any sensor, collected at any sampling rate, reports back to the vehicle's main processor via other transmitter / receiver pairs that connect to the main processor (or local slave processors in a cascade system of processors), and becomes the main processor's input for the waveforms of many active sensors.

[0043] In one scenario, many pairs all use the same main computer input to define their modulation. In another scenario, pairs use unique modulations. Raw sensor data is not collected fast enough to fill the available modulation space of many radars.

[0044] A typical road vehicle has 10–20 radars and / or LiDARs supporting autonomous driving. One option is to randomly skip some of the frequency ramps. Another technique is to insert bits collected from external data sources that repeat messages from other data sources, which is crucial for predicting record blockages. When warning data is shared with nearby systems, the chain can alert systems outside of their immediate area of interest. Yet another option is to fill the modulation space with pseudo-randomly generated values. These options are illustrative and should not be considered complete or exhaustive. Not every chirp needs to be modulated; patterns can be created from data within multiple chirps. In practice, CAS radar and LiDAR manufacturers provide performance, and integration contractors, in conjunction with their subsystem suppliers, establish the rules. Most subsystem suppliers defer to integrators (vehicle manufacturers). In the automotive industry, subsystem suppliers use the term electronic control unit (ECU). Similar ECUs are used by many integrators (meaning major vehicle manufacturers) to provide standardization.

[0045] CAS radar and / or LiDAR can be developed for non-autonomous designs, allowing for customization to the market for other functional robots, due to the design flexibility. Within factories with fixed structures and mobile units, extensive controlled systems can be integrated into assembly line operations, with hundreds to thousands of radars operating simultaneously. Selective transmitter / receiver pairs under the control of a local master processor can filter out data based on source identification or waveform pattern, i.e., 100s of different filtering techniques. Nearby machines can allocate regions of the spectrum that are not a concern for other parts of the chirp.

[0046] In a domestic environment, the system master controller can be a computer, and as electronic devices move around the house, the master selects dynamic data structures. No two electronic devices need to be aware of the other's data security.

[0047] On the other hand, when multiple transmitter / receiver pairs are grouped to form a mesh, with more complex requirements for establishing the truth value of the data sources, the waveforms of multiple data sources need to be known.

[0048] For example, vehicles on the road interact with other vehicles and infrastructure such as road signs and traffic lights. (other systems). Connectivity via active sensors, radar, and LiDAR allows for a variety of modulation techniques to securely transfer data within the vehicle. Vehicle-to-vehicle data transfer is by definition insecure. It requires connectivity beyond the secure confines of a single vehicle (system) and is highly secure, ensuring that insecure data is never allowed into the processor controlling the vehicle's actuators.

[0049] Conventional techniques for modulating carrier signals in active systems such as radar and LiDAR provide a simple and effective means for generating testable patterns. For active sensors, these patterns can include fixed data fields similar to Internet Protocol (IP) addresses and unique variable fields before newer unique variable fields replace the previous ones. Once the variable field is created, a copy is provided to the transmit subsystem of the transmitter / receiver pair as echoes are captured, and a second copy is provided to the local receiver subsystem of the transmitter / receiver pair for comparison. The variable portion of the modulated waveform has information content designed to be variable. The pair is typically located within a combined transmit / receive module in the ECU; therefore, both have access to the transmitter data structure contents. Echoes captured by the pair's receiver are compared to the transmitted waveform. Stray echoes from other transmitters may be captured, and some direct line-of-sight waveforms from other transmitters may be detected, but these fail the comparison test and are therefore removed from autonomous processing.

[0050] In a Field-of-Regard, any transmitter pulse can echo back to a paired receiver, providing direct line-of-sight data to the second receiver, or the second receiver can detect echoes from some random surface. The second receiver may or may not have the original waveform to perform a matching test. Whether the receiver is connected to the processor that generated the contents of the variable data field is important to the results that accrue to the data in the variable field.

[0051] A simple way to describe the data test for modulation is to decompose the signal stream by source and receiver.

[0052] When a pair of receivers is collecting the echoes of its pair of transmitters, the receivers have full knowledge of the modulation of each waveform: all data in the echoes is truth data.

[0053] If another (second) receiver collects echoes from the first transmitter of a different transmitter / receiver pair on the same vehicle, two outcomes can occur. If the second receiver has the same waveform, it processes the data as if it came from the paired transmitter. This sequence can have a confusing effect, as the paired second transmitter echo will also be processed. Unless these transmissions are absolutely synchronized, the two waveforms will collide during processing. Even if synchronized, these two waveforms will produce erroneous results due to slight differences in angle relative to the many objects in the echo. If the second receiver is not associated with the first transmitter in the pair, the echo will be processed but will not produce true data.

[0054] In another scenario, a vehicle's receiver may collect waveforms from other vehicles or infrastructure sources that fail multiple data checks. In this case, the metadata is different and the variable data is different. Because these mismatched waveforms do not pass the data checks of the matched waveforms, their contents are passed to a processor, which checks the data fields to obtain information.

[0055] In one automobile (system), many actuators are connected to the ECU (Electronic Control Unit). Each ECU is controlled by a network called a CAN (Connected Area Network). They are connected via a wired system.

[0056] Replacing the CAN and actuator controller interfaces with a wireless CAS-based transmitter / receiver system is the next logical step in in-system security: in-vehicle data fields are under the control of the local CAS processor, which is under the control of the master processor.

[0057] When a transmitter / receiver pair within a single actuator controller transmits and receives data, part of the data field is used as dynamic identification. Self-identification is a simple receiver check of retuned echoes against the content of the transmitted pulse. Because there is no Doppler, there is no frequency change between the echo and the original pulse. Additional checks have interesting value for in-vehicle pulses. First, the self-check can verify that the echo is a copy of the transmitted modulated waveform. Second, the echo must be very short distances from inside the vehicle (removing echoes from distances beyond the vehicle's physical boundaries). Third, the echo must be Doppler-free, and no part of the vehicle is moving relative to other parts of the vehicle. Finally, the angle of the echo is predetermined by design. Some or all of these simple checks fail for waveforms coming from any other transmitter attempting to mimic the echo.

[0058] Beyond these typical checks for radar echoes, additional checks can be established within the vehicle. If the dynamic data field is created from inputs collected by the processor, the processor can share elements of the dynamic data with other nodes, transmitter / receiver pairs, creating a mesh between the nodes. With proper antenna alignment for the mesh nodes, various forward signals (as opposed to echoes) can be collected by the receivers in the mesh. Purely geometric solutions exist that use all of the typical radar tests: range, Doppler, and angle. When shared dynamic data is common, a first transmitter in an ECU becomes a verification node for a second transmitter in a second ECU. Generating the dynamic data field is important for in-vehicle communication systems.

[0059] As mesh nodes activate the dynamic signals of other nodes, each activating an echo of its own pulse, the signal can potentially be captured by unintended receivers. If the waveform's dynamic data content is not rapidly changing, a rogue external node within the perimeter may pass some checks. The rogue node's range may be satisfied for one vehicle node but be incorrect for another; the Doppler is zero and it passes, but the angle is incorrect unless it is aligned with the pair. In a good vehicle design, these self-consistency checks will detect random nodes within the vehicle's mesh of nodes. The local secure processor, communicating with whitelisted addresses within the vehicle, does not generate fixed field data for rogue nodes. By identifying the source using the same techniques of range, angle, and geometry, with varying nodal inputs for each assigned node, rogue signals are found and removed from further processing.

[0060] If the rogue waveform originates from outside the vehicle, several self-integrity checks will fail. First, a rogue source would need to decode the dynamic part of the waveform and reverse engineer the data content. Assuming the vehicle uses the same dynamic data content for many chirps, in principle, a rogue chirp could be decoded by the vehicle's receiver (transmitter) The pattern check can be passed in the receiver component of the paired receiver. However, at the next dynamic pattern change, the paired receiver collects signals as an echo of the paired transmitter's chirp and as a second chirp (not an echo) from the rogue source. These are inconsistent, and the rogue source is flagged. Ideally, the dynamic pattern exists for no more than a few chirps, but even if the pattern persists for thousands of chirps (typically, chirp rates are thousands per second), the rogue source will cause a failure in less than one second. Failure occurs only if subsequent self-consistency checks are also circumvented. Doppler is faked if the rogue chirp source adjusts appropriately to compensate for potential movement of either the rogue source or the vehicle. Similarly, while angles may satisfy one pairing, satisfying multiple pairings is physically impossible.

[0061] What about the vehicle-to-vehicle waveforms that provide communication? A secondary processing step is performed on all receiver test waveforms that fail the vehicle-to-vehicle communication self-consistency check. Dynamic data is valid for the vehicle that generated them, which means the information is valuable.

[0062] Scenario: Driver 1 in the right lane attempts to become the lead vehicle in the center lane.

[0063] Level 4 Society of Automotive Engineers Autonomous Vehicles (humans can still control the vehicle). At level 5, there is no human-controlled interface, steering wheel, or pedals. Autonomy is state-descriptive, but the Collision Avoidance System (CAS) is a group of components including sensors and processors.

[0064] One example is Level 4 autonomous driving by humans, which presents a challenge for other autonomous vehicles.

[0065] Consider 16 vehicles traveling along three lanes of an interstate highway, with 5 in the left lane, 8 in the center lane, and 3 in the right lane.

[0066] The five vehicles in the left lane are positioned behind the other 11 vehicles. The five vehicles in the left lane are traveling faster than the other 11 vehicles. Therefore, the separation distance between the five vehicles in the left lane and the other 11 vehicles is decreasing. In this case, there is an initial separation distance of 3 seconds between the first vehicle in the left lane and the last vehicle in the center lane. This is assumed to correspond to a distance of approximately 250 feet.

[0067] The remaining 11 vehicles were split into eight in the center lane and three in the right lane, all traveling at the same speed. All 16 vehicles had their Active CAS operating independently at Level 4, traveling closely spaced less than one second apart.

[0068] The vehicles are identified as vehicle 1 in the right lane being in the leading position and vehicle 3 being at the end of the line in the right lane.

[0069] There are eight vehicles C1 to C8 in the center lane.

[0070] There are five vehicles L1 to L5 in the left lane.

[0071] The leading vehicle is chronologically first in each lane. The leading vehicles in the center lane and the right lane are parallel to each other, and the spacing between the vehicles in both lanes is substantially the same.

[0072] Each vehicle has 18 active radar units: five mounted on the front bumper, five on the rear bumper, and four on each side of the vehicle. Each radar has a unique identifier. All radars operate in the same single band, 76-81 GHz. All radars are also from the same brand and manufacturer, maximizing signal overlap and producing the highest noise floor. While this example does not use LiDAR or passive cameras, many scenarios include those sensors.

[0073] What does the CAS sensor on each vehicle detect? Pulses (transmissions) are sent out from 18 transmitters on each of the 16 vehicles, for a total of 288 distinct sources. The receiver detects echoes returning from paired transmitters and other pulses from 287 sources (noise) that are not paired with the receiver. Most of the 287 unpaired sources are undetectable by most receivers. For each of the 18 vehicles, a paired input from the radar with modulation originating from the vehicle is analyzed by the CAS as part of the autonomous decision. 270 information data sources are also available, and most of these 270 information data sources are undetectable by most receivers. However, some of the time when a stray pulse is detected is also an opportunity for many multipath strays to occur.

[0074] For the leading vehicle in the right lane: The lead vehicle in the right lane (R1) has no moving vehicles ahead of it. R1's five front bumper radar receivers detect echoes from stationary objects representing roadway infrastructure. These echoes have two potential vehicle sources: the lead vehicle in the right lane and the lead vehicle in the center lane. Apart from radar reflections from these two lead vehicles in the center and right lanes, radar signals emitted by any infrastructure sources are detected. R1 echoes matching these transmitted signals are safe data for autonomous processing; all other signals are considered unsafe and useful as informational data sources. Autonomous operation based on the five forward radars does not imply any action other than maintaining lane control based on predefined locations of fixed infrastructure, road edge detection, etc. However, lane control has side radar input as its primary decision input.

[0075] The R1's side radars provide significantly different inputs to autonomous decision-making. The right radar has a varying appearance due to the changing contours of objects along the right side of the road, vegetation, and man-made structures. A key input to the right radar is the return echo, which indicates where the road surface ends compared to the expected lane edge distance. The left radar generates near-object echoes from vehicles traveling along the center lane. Each of these four radars receives echoes from its own transmitter and a direct signal from the respective center lane vehicle transmitter, which is aligned with the right lane receiver. These radar signals are not aligned, and the beam spread may not be wide enough due to the relatively close proximity of the vehicles. A matched filter distinguishes between these two signals, passing the true, secure echo to autonomous processing and using the center lane vehicle input as information data. Autonomous operation maintains lane-to-lane separation for vehicles relative to lane boundaries. Any driver action that overrides automatic lane control results in a warning based on the vehicle manufacturer's design. An actual manual override should not occur until adjacent vehicles have sufficient clearance to allow a safe transition to manual control.

[0076] R1's five rear bumper radars generate five independent safe inputs to the vehicle 1 transmitter and vehicle 1 receiver pair, and five non-safe receiver inputs from the vehicle 2 transmitter. The non-safe information data should not be used to control actuators within vehicle 1.

[0077] A similar evaluation is logical for each of the 16 vehicles. Uniquely, the vehicle in the left lane, i.e., the vehicle traveling a little faster, has a view to the right front that detects the next cluster of vehicles in the center lane. The vehicles in the right lane are blocked from direct view. However, with the shared information data, the vehicles in the left lane (all of them) are perfectly aware that they are hidden from the vehicles in the right lane that are looking at them.

[0078] Several options exist for lining up vehicles in the right and center lanes. One option is for the other vehicles to travel slower and for the manually driven vehicle to move to the leading position in the center lane. Another option is for all eight vehicles in the center lane to move to the left lane, clearing the center lane for a safe manually driven maneuver. Eight vehicles making a lane change requires knowledge of the left lane usage. Fewer vehicles in the center lane can be moved (possibly the first one or two, or even three), and the remaining vehicles in the center lane will slow down to avoid the impact of switching to manual driving and making the lane change.

[0079] So how quickly can a group of vehicles make a group decision? How does the group understand the decision? How do they execute it? Or can a single vehicle driving itself make the same number of decisions as other vehicles making decisions manually? Curiously, birds may hold the key to the group's movement decision matrix. Birds use their movements as part of their cues, and according to zoologist Wayne Potts, they make predictions by understanding who is near and far within the group.

[0080] When that logic is embedded in a group of Level 5 autonomous vehicles, data on neighboring vehicles is required. This data is referred to as "information data."

[0081] The information data has multiple functions: first, it provides intent information about adjacent vehicles. In this scenario, a driver wanting to change lanes (from right to center) has touched their turn signal or turned the steering wheel to the left.

[0082] The rear radar of every vehicle detects vehicles traveling behind it for one second, which is important for the leading vehicle in the right lane. When a clear lane change is made, the data content of the chirp changes immediately. These data provide a clear message of the vehicle's intended lane change, much like the behavior of a bird searching for an action to take.

[0083] A leading vehicle in the right lane will change chirps on all 18 radars, and the information content section of the data field will reflect the lane change request. The absolute time of each pulse is nominally 0.0005 seconds, and the vehicle will move approximately 1 / 2 inch for each pulse. Therefore, many pulses occur within a few feet of the vehicle moving. Valid input is received as information data, which is reflected in a content change in the data field of the chirp. This allows drivers of other vehicles to be warned of a vehicle moving at high speed on their right side.

[0084] The four driver's side radars of vehicle 1 in the right lane (driving aggressively) send pings to the vehicle in the center lane that is traveling alongside them. Meanwhile, all radars in each vehicle receive new data that is daisy-chained from one vehicle to the next, and a decision is made for each vehicle. The "information data" is what the receivers pick up, but the modulation test fails. The modulation pattern of vehicle 1 fails the modulation pattern checks in the receivers of all the other vehicles. In this example, when the driver of vehicle 1 in the right lane moves the steering wheel, the chirp of his vehicle New dynamic data is generated and the receiver of the vehicle accepts it as true (coming from the transmitter of vehicle 1). However, it is important for vehicle 2 (R2) in the right lane and vehicle 1 (C1) in the center lane to receive these data and acquire the information quickly. These new data are shared in subsequent chirps from other vehicles.

[0085] In practice, the driver of vehicle 1 in the right lane is notified of the presence of a vehicle on the left with a warning sound, light, etc., and the autonomous driving function delays the vehicle's movement from the right lane to the center lane because the driver cannot change lanes as desired. This delay gives the radar time to share a status update.

[0086] Information data is collected by all nearby vehicles, including those not directly visible to the leading vehicle in the right lane, and this information data is retransmitted from the vehicle closest to the leading vehicle in the right lane to the vehicle furthest from it. The autonomous decision-making process of some vehicles triggers a second action, and then a third action.

[0087] Each decision in each of the 15 vehicles involved causes an interruption of autonomously generated action to deal with the ensuing situation.

[0088] Internal communications within a single vehicle are secured by several simultaneous processes. First, the communications system is wireless, which on the surface seems counterintuitive for a wireless means that any remote node can be integrated into the overall system. Second, all communications are intentionally directed inward, which means the outside world cannot receive the actual radio signal well. It is also counterintuitive because if the left side of the vehicle sends a signal toward the right, some of it will escape to the outside. Appropriate baffles on highly directional antennas ensure that the limited-power beam does not propagate far.

[0089] A function within a vehicle typically consists of an actuator that moves a window up or down or increases current to or from an electric motor. A controller is built for each unique function, nominally called an Electronic Control Unit (ECU). With a small transmitter / receiver, these ECU devices can have multiple inputs as triggers to execute commands and send data back to a processor that acts partially as an authenticator or as the main processor that builds the CAS dynamic content.

[0090] With appropriate filtering, the receiver can test simple signal characteristics such as distance, relative velocity, and angle of the signal source. For internal sources, these values are absolutely deterministic: distance is a few feet, granular to the inch, relative velocity is zero, and angle is defined by relative position. Level 4 autonomous vehicles determine critical actuator (brake, steer, acceleration) control based on CAS inputs. In the example above, some vehicles may change lanes. To ensure that the actuators respond only to valid inputs, each actuator has a transmitter / receiver pair with a dedicated wireless link to the source of the command.

[0091] A lane change scenario involves truth data from multiple CAS radars. The actual command to perform an action is sent from a processor that takes in all of these CAS outputs. The central processor knows the location of each CAS, as well as the internal code that formulates the chirp from each transmitter / receiver pair, including the internal dynamic data provided by the processor, meaning the actuators are receiving their commands from a processor that knows all the ECUs.

[0092] A lesser actuator, such as a window up / down actuator, is a toggle switch or It requires human input to move a button. The up / down switch, when touched, activates a CAS transmitter / receiver pair, which in turn floods several associated transmitter / receiver pairs, each of which tests range, speed, and angle, along with the associated new parameter-fixed geometry. This four-way test has only one solution, so an external transmitter / receiver CAS cannot tamper with the window.

Claims

1. 1. A method for securing a data link between a transmitter and a receiver, comprising: Transmitting data to a decision-making computer in an autonomous or semi-autonomous operating environment using the modulated active sensor waveform. A method comprising:

2. 10. The method of claim 1, further comprising using modulation to generate distinct waveforms that permit multiple distinct in-band signals.

3. The method of claim 2 further comprising the step of sharing the individual waveforms between the transmitter and the receiver and verifying the data of the echoes.

4. 2. The method of claim 1, wherein the computer controls the data into a modulation pattern.

5. 5. The method of claim 4, wherein the computer selects a pattern for the receiver and determines data entering the operating environment.

6. 6. The method of claim 5, wherein the selected pattern is a matched echo that is a secure controlled communication.

7. 6. The method of claim 5, wherein the selected pattern is a verification of the modulation of the transmitter.

8. The method of claim 7 , wherein the verification increases the security of the operating environment.

9. 10. The method of claim 9, wherein the verifying step enhances security of robotic systems on roads, in factories, in offices, in homes, and in portable computers.

10. 1. A method for securing a system data link between a transmitter and a receiver as a correlated pair, comprising transmitting a modulated waveform from the transmitter and receiving the waveform at the receiver, the receiver reflecting the waveform as an echo back to the transmitter, the modulated waveform being constructed from dynamic data.

11. 11. The method of claim 10, wherein a stored copy of the transmitted waveform is compared with the echo from the receiver by a matching filter.

12. 12. The method of claim 11, wherein the matching filter takes into account expected changes due to reflections from stationary or moving objects.

13. The method of claim 12 , wherein the matching filter provides a secure input to a decision-making algorithm.

14. A method of securing multiple data links between independent systems having correlated pairs of transmitters and associated receivers, comprising transmitting a modulated waveform from the transmitter of the pair and receiving the waveform at the receiver of the pair, the receiver reflecting the waveform as an echo back to the transmitter, the modulated waveform comprising dynamic data. A method comprising:

15. 15. The method of claim 14, wherein a stored copy of the transmitted waveform is compared with the echo from the receiver by a matching filter.

16. 16. The method of claim 15, wherein the matching filter receives echoes only from the receiver of the first pair.

17. 1. A method for securing a system data link between a transmitter and a receiver as a correlated pair, the method comprising combining passive and active signals from a single system to form a composite signal.

18. 18. The method of claim 17, wherein the passive signal includes data, the active signal includes data, and the data of the active signal is verified by the data of the passive signal.

19. 20. The method of claim 18, including passing the data of the active signal to an autonomous decision-making process.

20. 1. A method of generating information data from an insecure data link between a transmitter of a first system and a receiver of a second system, wherein a modulated waveform transmitted from the first system does not match a stored waveform of the receiver of the second system, the method comprising: processing the inconsistent waveform of the second system to declare the inconsistent waveform as information data; and processing the information data of the second system to alert secure data of the second system of the divergence.

Citation Information

Patent Citations

  • Pre-warning method and vehicular radar system

    CN105445728A

  • Signal interference verification method and radar installation

    JP2006250558A

  • Ladar sensor for dense environment

    JP2016014665A

  • Lidar sensor device

    US20180180715A1

  • Code generating device

    WO2007116890A1