Context-Aware Safety Features for Vehicle Operating Systems
Context-aware safety features in vehicle operating systems dynamically adapt to operational contexts, improving safety and user experience by avoiding unnecessary protective modes and conserving resources.
Patent Information
- Application Number
- JP2025507843
- Authority / Receiving Office
- JP · JP
- Patent Type
- Applications
- Current Assignee / Owner
- Priority Date
- 2022-08-15
- Filing Date
- 2023-08-10
- Publication Date
- 2025-10-28
AI Technical Summary
Vehicle operating systems statically restrict access to features based on safety concerns, which are difficult to override and do not adapt to changing operational contexts, potentially leading to unnecessary entry into protective modes and user frustration.
Implement a context-aware safety feature in vehicle operating systems that dynamically adapts operational characteristics based on factors like occupant usage, presence, weather, and vehicle state to promote safety without unnecessary power consumption.
Enhances user experience by avoiding unnecessary protective modes while ensuring operator and passenger safety, particularly in extreme conditions, and conserving vehicle resources.
Smart Images

Figure 2025535638000001_ABST
Abstract
Description
[Technical Field]
[0001] This application claims priority to U.S. Provisional Application No. 63 / 371,445, filed August 15, 2022, entitled "CONTEXT AWARE SAFETY FEATURES FOR VEHICLE OPERATING SYSTEMS," and U.S. Provisional Application No. 63 / 371,451, filed August 15, 2022, entitled "SINGLE-INSTANCE MULTI-USER SUPPORT FOR VEHICLE OPERATING SYSTEMS," each of which is incorporated by reference herein as if set forth in its entirety. [Background technology]
[0002] A vehicle head unit (sometimes referred to as an infotainment system) may be configured to execute a vehicle operating system to facilitate control of vehicle systems, such as heating, ventilation, and air conditioning (HVAC) systems, lighting systems, and seat control systems (including heating and / or cooling, seat adjustment, etc.), as well as entertainment (e.g., music, video, images, etc.), information, navigation, and voice communications, to provide a few examples. Vehicle operating systems may generally restrict access to certain features to avoid and / or reduce distraction to the vehicle operator. These safety restrictions may be hard-coded (or, in other words, statically coded) into the vehicle operating system to meet specific safety concerns and are often difficult to override, despite changes in operational context. Summary of the Invention
[0003] In general, various aspects of the techniques described in this disclosure are directed to context-aware safety features for vehicle operating systems. Rather than statically determining when a protective mode of operation may apply regardless of context, various aspects of the techniques described in this disclosure may enable one or more instances of a vehicle operating system to determine the operational context in which the vehicle is currently operating, and based on the operational context, may enable the vehicle operating system to enter a protective mode of operation that dynamically adapts one or more operational features of the vehicle operating system to promote safety for the vehicle operator.
[0004] The operational context may include usage of the instance of the vehicle operating system by one or more occupants of the vehicle, the presence of one or more occupants in the vehicle, the weather conditions in which the vehicle is currently operating, and the operational state of the vehicle (e.g., whether the vehicle has been in an accident, the battery level in a hybrid electric vehicle and / or all-electric vehicle, etc.). In response to these different aspects of the operational context, the vehicle operating system (e.g., in the case of an all-electric vehicle) may reduce power consumption by one or more displays (e.g., by reducing the brightness or powering off such displays), currently running applications (e.g., by entering a night mode or other panic mode that reduces current processing and / or display requirements), etc.
[0005] In this regard, various aspects of the present techniques may improve the operation of the vehicle head unit itself by dynamically entering a protective operating mode to potentially improve the safety level associated with operating the vehicle. For example, in the context of battery life, the vehicle operating system may disable or reduce the operation of displays to preserve battery life so that the vehicle may reach its intended destination without depleting the battery powering the vehicle, which may improve safety, particularly when weather conditions might otherwise pose a significant risk to the health of the operator and / or passengers (e.g., when it is very cold or hot outside the vehicle's controlled environment). Thus, various aspects of the present techniques described in this disclosure may provide improvements to the operation of the vehicle itself in terms of providing safety to the operator and / or passengers (which may include the “operator” in the context of an autonomous vehicle).
[0006] Furthermore, by dynamically entering a protected mode of operation only when certain conditions are met (or, in other words, when the operational context allows for entry into the protected mode of operation), various aspects of the present techniques may reduce erroneous entry into a protected mode of operation in operational contexts that do not allow for entry into such a protected mode of operation. By avoiding unnecessary entry into unauthorized protected modes of operation, the vehicle operating system may improve the user experience while still potentially addressing operator and / or passenger safety in several different ways.
[0007] In one example, the disclosure describes a method that includes executing, by a vehicle head unit of a vehicle, an instance of a vehicle operating system; determining, by the instance of the vehicle operating system, an operational context in which the vehicle is currently operating; and entering, by the instance of the vehicle operating system and based on the operational context, a protective operating mode in which the vehicle operating system dynamically adapts one or more operational characteristics of the vehicle operating system to promote safety of an operator of the vehicle.
[0008] In another example, the present disclosure describes a computing device, the computing device comprising: a memory configured to store an instance of a vehicle operating system; and one or more processors for executing the instance of the vehicle operating system, wherein the instance of the vehicle operating system is configured to determine an operational context in which the vehicle is currently operating; and, based on the operational context, to enter a protective operating mode in which the vehicle operating system dynamically adapts one or more operational characteristics of the vehicle operating system to promote safety of an operator of the vehicle.
[0009] In another example, the present disclosure describes a non-transitory computer-readable storage medium having stored thereon instructions that, when executed, cause one or more processors to execute an instance of a vehicle operating system, determine, by the instance of the vehicle operating system, an operational context in which the vehicle is currently operating, and enter a protective operating mode in which, by the instance of the vehicle operating system and based on the operational context, the vehicle operating system dynamically adapts one or more operational characteristics of the vehicle operating system to promote safety of an operator of the vehicle.
[0010] In another example, the present disclosure describes an apparatus that includes means for executing an instance of a vehicle operating system, means for determining an operational context in which the vehicle is currently operating, and means for entering a protective operational mode based on the operational context, in which the vehicle operating system dynamically adapts one or more operational characteristics of the vehicle operating system to promote safety of an operator of the vehicle.
[0011] The details of one or more embodiments are set forth in the accompanying drawings and the description below. Other features, objects, and advantages will be apparent from the description, drawings, and claims. [Brief explanation of the drawings]
[0012] [Figure 1] FIG. 1 is a block diagram illustrating an example computing system configured to provide a single-instance, multi-user vehicle operating system in accordance with various aspects of the techniques described in this disclosure. [Figure 2] FIG. 1 illustrates an example vehicle including a computing system configured to execute a vehicle operating system that operates in accordance with various aspects of the single-instance multi-user techniques described in this disclosure. [Figure 3] 10A-10C illustrate different interaction models with multiple displays, including interactions occurring via a single-instance multi-user model and a multi-instance multi-user model, in accordance with the vehicle operating system techniques described in this disclosure. [Figure 4] FIG. 1 illustrates an exemplary vehicle including a vehicle head unit configured to control audio content in accordance with various aspects of the single-instance multi-user vehicle operating system techniques described in this disclosure. [Figure 5] FIG. 1 illustrates audio controls in a single-instance, multi-user vehicle operating system in accordance with various aspects of the techniques described in this disclosure. [Figure 6] FIG. 1 illustrates audio controls in a single-instance, multi-user vehicle operating system in accordance with various aspects of the techniques described in this disclosure. [Figure 7] 2 is a flowchart illustrating an example operation of the computing system shown in FIG. 1 when executing a vehicle operating system configured to perform various aspects of the safety techniques described in this disclosure. DETAILED DESCRIPTION OF THE INVENTION
[0013] 1 is a block diagram illustrating an exemplary computing system configured to provide a single-instance, multi-user vehicle operating system in accordance with various aspects of the techniques described in this disclosure. As shown in the example of FIG. 1, computing system 100 includes computing device 102. Although described with respect to a vehicle, computing system 100 may be utilized in different contexts, including a standalone computing system (including a laptop computer, a desktop computer, a workstation, etc.), a gaming system, a mobile phone (including a so-called "smart phone"), a media system (including a streaming media system), an audio / visual (A / V) receiver, a television (including a so-called "smart television"), a smart speaker, a smart watch, a thermostat (including a so-called "smart thermostat"), smart glasses, or any other computing system.
[0014] In any event, computing device 102 is an example of a vehicle computing device, such as a vehicle head unit. Figure 1 shows only one particular example of computing device 102, and many other examples of computing device 102 may be used in other cases, and may include a subset of the components included in exemplary computing device 102, or may include additional components not shown in Figure 1.
[0015] 1, computing device 102 includes presence-sensitive display 112, one or more processors 140, one or more communication units 142, one or more input components 144, one or more output components 146, and one or more storage devices 148, as well as a communication channel 149. Communication channel 149 may interconnect (physically, communicatively, and / or operatively) each of components 112, 140, 142, 146, and / or 148 for inter-component communication, thereby enabling components 112, 140, 142, 146, and 148 to communicate with one another. In some examples, communication channel 149 may include a system bus, a network connection, one or more inter-process communication data structures, or any other component for communicating data (also referred to as information). Although shown as including components 112, 140, 142, 146, and 148, vehicle head unit 102 may include other components or fewer components than those shown, and components such as these may be included in other control units, such as a telematic control unit (TCU).
[0016] One or more communication units 142 of computing device 102 may communicate with external devices by transmitting and / or receiving data. For example, computing device 102 may use one or more of communication units 142 to transmit and / or receive radio signals over a wireless network, such as a cellular wireless network. In some examples, communication unit 142 may transmit and / or receive satellite signals over a satellite network, such as a Global Positioning System (GPS) network. Examples of communication units 142 include a network interface card (e.g., an Ethernet card), an optical transceiver, a radio frequency transceiver, a GPS receiver, or any other type of device capable of transmitting and / or receiving information. Other examples of communication units 142 may include shortwave radios (e.g., NFC, BLUETOOTH (including BLE)), GPS, 3G, 4G, 5G, and WIFI radios, universal serial bus (USB) controllers, etc., that are included in mobile devices.
[0017] One or more input components 144 of computing device 102 may receive input. Examples of input include, but are not limited to, tactile input, audio input, kinematic input, optical input, etc. In one example, the input components 144 of computing device 102 include a mouse, keyboard, touchpad, voice response system, video camera, buttons, scroll wheels, dials, control pad, microphone (or, in other words, audio capture device), or any other type of device for detecting input from a human or machine. The input component 144 may include a camera. In some examples, the input component 144 may be a presence-sensitive input component, which may include a presence-sensitive screen, a touch-sensitive screen, etc., separate from the presence-sensitive display 112.
[0018] One or more output components 146 of computing device 102 may generate output. Examples of output include haptic output, audio output, and video output. The output components 146 of computing device 102, in some examples, include a presence-sensitive screen (possibly separate from the presence-sensitive display 112), a sound card, a video graphics adapter card, speakers, a cathode ray tube (CRT), a monitor, a liquid crystal display (LCD), an organic light-emitting diode (OLED), or any other type of device for generating tactile, audio, and / or visual output to a human or machine.
[0019] In some examples, the presence-sensitive display 112 of the computing device 102 may include functionality of the input component 144 and / or the output component 146. In the example of FIG. 1, the presence-sensitive display 112 may include a presence-sensitive input (PSI) component 104 (“PSI component 104”), such as a presence-sensitive screen or a touch-sensitive screen. In some examples, the presence-sensitive input component 104 may detect objects on and / or near the presence-sensitive input component. As an example of range, the presence-sensitive input component 104 may detect an object, such as a finger or stylus, within two inches of the presence-sensitive input component 104. The presence-sensitive input component 104 may determine the location (e.g., (x, y) coordinates) of the presence-sensitive input component where the object was detected. In another example of a range, the presence-sensitive input component 104 may detect an object no more than two inches from the presence-sensitive input component 104, although other ranges are also possible. The presence-sensitive input component 104 may use capacitive, inductive, and / or optical recognition techniques to determine the location of the presence-sensitive input component 104 selected by a user's finger.
[0020] In some examples, presence-sensitive display 112 may also provide output to the user using tactile, audio, or video cues, as described with respect to output component 146. For example, presence-sensitive display 112 may include display component 103 that displays a graphical user interface. Display component 103 may be any type of output component that provides visual output, as described with respect to output component 146. While presence-sensitive display 112 is shown as an integrated component of computing device 102, in some examples, presence-sensitive display 112 may be an external component that shares a data or information path with other components of computing device 102 to send and / or receive inputs and outputs. For example, presence-sensitive display 112 may be an embedded component of computing device 102 that is located within and physically connected to the external packaging of computing device 102 (e.g., an in-vehicle screen mounted on the dashboard of a vehicle). In other examples, presence sensitive display 112 may be an external component of computing device 102 (e.g., a monitor, projector, etc. that shares a wired and / or wireless data path with the vehicle's electronic control unit) that is located outside of and physically separate from the packaging of computing device 102. In some examples, presence sensitive display 112, when located outside of and physically separate from the packaging of computing device 102, may be implemented by two separate components: a presence sensitive input component 104 for receiving input and a display component 103 for providing output.
[0021] One or more storage devices 148 in computing device 102 may store information for processing during operation of computing device 102 (e.g., computing device 102 may store data accessed by operating systems (OS) 160A and 160B during execution on computing device 102). As shown in the example of FIG. 1, one or more storage devices 148 may store a first instance of operating system 160A (OS160A) and a second instance of operating system 160B (OS160B). In some examples, storage device 148 includes temporary memory, meaning that the primary purpose of one or more storage devices 148 is not long-term storage. Storage device 148 of computing device 102 may be configured for short-term storage of information as volatile memory; therefore, stored content may not be retained when power is turned off. Examples of volatile memory include random access memory (RAM), dynamic random access memory (DRAM), static random access memory (SRAM), and other forms of volatile memory known in the art.
[0022] Storage device 148, in some examples, also includes one or more computer-readable storage media. Storage device 148, in some examples, includes one or more non-transitory computer-readable storage media. Storage device 148 may generally be configured to store larger amounts of information than can be stored by volatile memory. Storage device 148 may further be configured for long-term storage of information as non-volatile memory space, where information may be retained even after power on / off cycles. Examples of non-volatile memory include magnetic hard disks, optical disks, flash memory, or forms of electrically programmable memory (EPROM) or electrically erasable programmable memory (EEPROM). Storage device 148 may store program instructions and / or information (e.g., data) associated with OS 160A and / or 160B. Storage device 148 may include memory (not shown for ease of illustration) configured to store data or other information associated with OS 160A and OS 160B.
[0023] One or more processors 140 may implement functions and / or execute instructions associated with computing device 102. Examples of processor 140 include an application processor, a display controller, an auxiliary processor, one or more sensor hubs, and any other hardware configured to function as a processor, processing unit, or processing device. OS 160A and / or 160B may be operable (or, in other words, may be executed) by processor 140 to perform various actions, operations, or functions of computing device 102. That is, OS 160A and / or OS 160B may form executable bytecode that, when executed, causes processor 140 to perform particular operations (and thereby causes computing device 102 to become a specific-purpose computer that performs particular operations) in accordance with various aspects of the techniques described herein. For example, processor 140 of computing device 102 may receive and execute instructions stored by storage device 148 that cause processor 140 to perform the operations described herein caused by OS 160A and / or OS 160B. These instructions, when executed by processor 140 , may cause computing device 102 to store information in storage device 148 .
[0024] As noted above, computing system 100 may be integrated into or otherwise included within a vehicle, which may include one or more of a bicycle, a tricycle, a unicycle, a motorcycle, an automobile, agricultural machinery (such as a tractor or combine harvester), construction machinery (such as a dump truck or crane), military vehicles or equipment (such as a tank or weapon), a truck, a semi-tractor (or, in other words, a semi-trailer), aviation equipment (such as an airplane), nautical equipment (such as a boat, carrier, submarine), or any other type of vehicle.
[0025] Computing device 102 (as mentioned above, referred to as vehicle head unit 102, and sometimes also referred to as infotainment system 102) may be configured to run a vehicle operating system, such as one or more of OS 160A and 160B (and thus may also be referred to as vehicle OS 160A-VOS 160A- and VOS 160B), to provide some examples, to facilitate control of vehicle systems such as the heating, ventilation, and air conditioning (HVAC) system, lighting system, and seat control system (including heating and / or cooling, seat adjustment, etc.), as well as control of entertainment (music, video, images, etc.), information, navigation, and voice calls. In some examples, the vehicle operating system may allow a single user profile at a time to immediately access a given instance of the vehicle operating system, where the single user profile is typically the operator of the vehicle.
[0026] This vehicle operating system may be referred to as a single-instance, single-user vehicle operating system. That is, the single instance of the vehicle operating system allows only a single user profile to access the single instance of the vehicle operating system, and may require a user profile switch, where the single user profile is replaced with another single user profile. In this regard, only a single user profile may access the single instance of the vehicle operating system at any time.
[0027] To allow for multiple concurrent user profiles, processor 140 may run another instance of the vehicle operating system, which may require additional and / or more powerful processors (which are typically more expensive). However, enabling efficient communication between both instances of the vehicle operating system may be difficult, and as a result, users associated with multiple user profiles may not be able to share content between each other, thereby limiting the user experience.
[0028] Thus, although a vehicle operating system instance may support multiple user profiles, the vehicle operating system instance may allow only a single user profile of the multiple user profiles to access (or in other words, "log in") the vehicle operating system instance. The vehicle operating system instance may limit access to a single user profile so that a vehicle operator is not distracted by the behavior of other user profiles while operating the vehicle.
[0029] According to various aspects of the techniques described in this disclosure, computing system 100 may implement a single instance of a vehicle operating system, such as VOS 160A and / or 160B (“VOS 160”), that provides concurrent multi-user support. Rather than limiting access to a single user profile for a single instance of VOS 160, the single instance of VOS 160 described in this disclosure may allow multiple user profiles to access the single instance of VOS 160. As vehicles begin to integrate more and more displays, such as supporting presence-sensitive displays 150A-150N (sometimes referred to as “displays 150”) within the vehicle's cabin, more users may securely interface with VOS 160 without distracting the vehicle operator (without considering that the operator may either have a limited view of or no direct view of these displays 150, which in some examples may be located behind the operator for rear-seat passengers). Thus, multiple users associated with multiple user profiles may access VOS 160 and interact with computing device 102 to control various functions provided by computing device 102, such as entertainment, information, navigation, and voice calls, as well as various vehicle systems (which may depend, to some extent, on the multiple user locations within the vehicle).
[0030] Users may also interface with VOS 160 to collaboratively coordinate activities among the users, such as sharing content among the users, reviewing content viewed by other users of the users, controlling audio playback among the users (e.g., changing audio playback volume, adjusting playlists, etc.), exchanging messages among the users, collaborating among the users on navigation direction, etc. In some examples, the users may use gestures, such as swipe gestures, pinch gestures, and tap gestures, to direct such content sharing, which may enable intuitive control of sharing among the users.
[0031] 1, the computing device 102 may interface with a display 150, which may be similar to or substantially similar to the presence-sensitive display 112. However, rather than being integrated into the computing device 102 as is the presence-sensitive display 112, the display 150 may be communicatively coupled (wired or wirelessly) to the computing device 102, integrated into the overall vehicle cabin, or separate from the vehicle. That is, the display 150 may also represent, in some examples, a tablet, a smartphone, a laptop, a portable gaming device, a portable video device, or any other device capable of interfacing with the computing device 102 to present a user interface associated with the VOS 160 (and / or applications executing within the application space presented by the VOS 160, which may be separate from the privileged kernel space in which the VOS 160 executes to facilitate interaction between the applications and underlying hardware, such as the components 112 and 140-148).
[0032] In either case, processor 140 may execute an instance of a vehicle operating system, such as VOS 160A or VOS 160B, which facilitates concurrent access by multiple user profiles, shown in the example of FIG. 1 as user profiles (UPs) 161A-161N ("UP 161") for VOS 160A and UPs 163A-163N ("UP 163") for VOS 160B. UPs 161 / 163 may each define a set of access rights (or, in other words, privileges), preferences (e.g., for user interface, VOS 160 settings, etc.), and other user-specific configuration data or information. While UPs 161 / 163 may each be associated with different users, UPs 161 and 163 may contain user profiles for the same user. For example, UPs 161A and 163A may be associated with the same user.
[0033] The processor 140 may, for example, execute the VOS 160A and authorize multiple user profiles of the UP 161 to interface with the VOS 160A. To authorize multiple user profiles of the UP 161, each of the users may register with the VOS 160A by entering a username (associated with a given one of the UPs 161) and a password to log in to the VOS 160A. Alternatively, logging in to the VOS 160A may be enabled by any other method, such as scanning a quick response (QR) code with a smartphone camera, entering a personal identification number (PIN), performing a biometric process (e.g., a fingerprint scan, a retina scan, etc.), facial recognition, or any other method for registering a given user profile of the UP 161 with the VOS 160A. The VOS 160A may compare the entered information with authentication information stored in the UP 160A to authorize (or, in other words, authenticate) each of the multiple user profiles of the UP 161 to interface with the VOS 160A.
[0034] Although discussed with respect to authentication, the VOS 160A may also allow a guest user profile (as one of the UPs 161) for which authorization is provided without requiring any authentication. In this regard, the guest user profile may provide a limited experience (compared to an authenticated UP 161) in terms of maintaining preferences, applications, etc. across different sessions, but still enable the functionality described below with respect to sharing content, etc., between multiple UPs 161.
[0035] In either case, VOS 160A may present multiple user interfaces across multiple displays (e.g., display 112 and one or more of display 150) communicatively coupled to computing device 102. For an authenticated UP of UP 161, VOS 160A may present a unique user interface for each authenticated UP that maintains preferences in terms of application organization, user interface theme, various VOS 160A settings (e.g., with respect to notifications, accessibility, display configuration in terms of brightness, resolution, orientation, etc., and any other type of OS settings). In either case, each of the multiple user interfaces is associated with one or more of UPs 161.
[0036] VOS 160A may then interface with multiple users associated with multiple UPs of UP 161 via multiple user interfaces to allow multiple users to interface with VOS 160A to control functionality associated with computing device 102. This functionality may include controlling navigation, modifying content playback, changing user interface settings, controlling HVAC settings, sharing content between UPs 161, and other functionality described in more detail below.
[0037] In some examples, processor 140 may represent a high-processing-power processor (which may be referred to as “processor 140A”) and a low-processing-power processor (which may be referred to as “processor 140B”). In some examples, processor 140 may represent a processor with variable processing power having two or more different operating voltages that enable high processing power at a high voltage and low processing power at a low voltage. In this sense, a single processor may represent both processor 140A and processor 140B that switch between different processing modes (e.g., between a high processing mode and a low processing mode) to facilitate power conservation. Processor 140A may provide additional processor cores compared to processor 140B (or, in examples where a single processor switches between processing modes, enable additional cores in the high processing mode compared to the low processing mode).
[0038] Processor 140A may execute VOS 160A, and processor 140B may execute VOS 160B. Processor 140A may execute VOS 160A for tasks requiring higher processing, such as gaming, video conferencing, navigation, and other processor-intensive tasks / applications. Processor 140B may execute VOS 160B for tasks requiring lower processing, such as streaming audio, making phone calls, viewing images, text messaging, or other less processor-intensive tasks / applications.
[0039] In some examples, processor 140A may execute VOS 160A in parallel with processor 140B executing VOS 160B. In examples of parallel execution of VOS 160A and 160B, VOS 160A may present an interface through which VOS 160B may communicate with VOS 160A to facilitate various functions of computing device 102. This interface may represent an application programming interface that VOS 160B may invoke to facilitate inter-VOS communication between VOS 160A and VOS 160B to cooperatively facilitate support for functions provided by computing device 102.
[0040] Utilizing processors of different processing power may facilitate energy consumption. Furthermore, installing a high-power processor 140 capable of all of the functions supported by the computing device 102 may be costly, and the low-power processor 140 may allow a manufacturer to upgrade over time to add additional processors with higher (and / or possibly lower) processing power. Providing a framework for inter-VOS communication may allow a manufacturer to upgrade over time without having to configure a separate inter-VOS communication interface to facilitate access to the features of the computing device 102, which are described in more detail below.
[0041] As further shown in the example of FIG. 1 , computing device 102 may also interface with supporting audio capture devices 152A-152N (“supporting audio capture devices 152” or “audio capture devices 152”). Each of audio capture devices 152 may represent a microphone or other transducer configured to capture audio data representative of a sound field. Supporting audio capture devices 152 may also be referred to as “microphones 152.” In some examples, audio capture devices 152 may be integrated throughout one or more zones of the vehicle cabin that includes computing device 102. These zones may include an operator zone, one or more front passenger zones, and one or more rear passenger zones. As described in more detail below, these microphones 152 may capture (or, in other words, record, detect, or otherwise sense) audio data that VOS 160 may use to adjust audio playback as well as to support additional functionality provided by computing device 102.
[0042] In this way, various aspects of the present technique may promote a better user experience when traveling within a vehicle while still addressing safety concerns due to distracting the vehicle operator. As a result of allowing multiple UPs 161 / 163 to access VOS 160A / 160B, VOS 160A / 160B may tailor the user experience to each individual UP 161 / 163, allowing each individual UP to apply its own preferences. The VOS 160A / 160B system may also allow multiple users to coordinate activities (as described above) that may enhance the user experience while traveling within the vehicle. Given that additional displays 150 (which may be separate from the vehicle head unit 102's main display, e.g., presence-sensitive display 112) may be located within the vehicle cabin where the vehicle operator cannot directly view the content being presented, VOS 160A / 160B may grant increased permissions in terms of access to content, potentially limiting any distractions to the operator.
[0043] Additionally, vehicle operating systems may generally restrict access to certain features to avoid and / or reduce distraction to the vehicle operator. These safety restrictions may be hard-coded (or, in other words, statically coded) into the vehicle operating system to meet specific safety concerns and are often difficult to override, despite changes in operational context. Given that standard infotainment systems generally include only a single display, or in some cases, two or three different displays all associated with the same single-access user profile, the vehicle operating system may include these safety restrictions.
[0044] In the context of multiple user profiles having concurrent access to a single instance of a vehicle operating system, various safety restrictions may not address the operating context in which the vehicle operating system resides, because these safety restrictions may allow only the operator to invoke certain safety features that would otherwise facilitate more proactive safety measures that could help both the operator and one or more passengers in an emergency or other situation. As a result, the vehicle operating system may restrict functionality to the operator even when such functionality would otherwise be extended to one or more passengers in that context. Furthermore, the vehicle operating system may enter a protected operating mode even when the context does not permit this protected operating mode, potentially resulting in a frustrating user experience with the vehicle operating system (which may result in wasted processing resources, such as processing cycles, memory consumption, bus bandwidth consumption, and associated power consumption).
[0045] According to various aspects of the techniques described in this disclosure, VOS 160A may provide context-aware safety features. Rather than statically determining when a protective mode of operation may apply regardless of context, various aspects of the techniques described in this disclosure may enable VOS 160A and / or VOS 160B (“VOS 160”) to determine the operational context in which the vehicle is currently operating and, based on the operational context, may enable VOS 160 to enter a protective mode of operation that dynamically adapts one or more operational features of VOS 160 to promote vehicle operator safety.
[0046] The operational context may include usage of the instance of the vehicle operating system by one or more occupants of the vehicle, the presence of one or more occupants in the vehicle, the weather conditions in which the vehicle is currently operating, and the operational state of the vehicle (e.g., whether the vehicle has been in an accident, the battery level in hybrid electric vehicles and / or fully electric vehicles, etc.). In response to these different aspects of the operational context, the VOS 160 may (e.g., in the case of fully electric vehicles) reduce power consumption by presence-sensitive displays 112, 150 (e.g., by reducing the brightness or powering off such displays), currently running applications (e.g., by transitioning to a night mode or other panic mode that reduces current processing and / or display requirements), etc.
[0047] During operation, processor 140 of computing device 102 may execute an instance of a vehicle operating system (e.g., VOS 160A). VOS 160A may determine an operational context in which the vehicle is currently operating. VOS 160A may interface with any number of different vehicle sensors to determine the operational context, such as speed sensors, global positioning system (GPS) sensors, occupancy sensors (e.g., which may sense weight on a seat), cameras, microphones, weather sensors (e.g., humidity, moisture, temperature, etc.), accelerometers, gyroscopes, infrared sensors, seat belt sensors, tire pressure sensors, or any other sensors capable of communicating with computing device 102 (such sensors may be represented by input components 144 and / or output components 146).
[0048] To determine the operational context, VOS 160A may perform one or more of the following: determine usage of VOS 160A by one or more occupants in the vehicle; determine the presence of one or more occupants in the vehicle (e.g., via occupancy sensors, cameras, microphones, etc.); determine the weather conditions in which the vehicle is currently operating; and determine the operational state of the vehicle. VOS 160A may also determine the state of occupant interaction status elements (e.g., physical buttons located within the vehicle cabin out of reach of the vehicle operator, such as on a passenger door).
[0049] VOS 160A may enter a protective operating mode based on the operating context in which the vehicle operating system dynamically adapts one or more operating characteristics of the vehicle operating system to promote safety for the operator of the vehicle. For example, VOS 160A may enter a protective operating mode in which VOS 160A dynamically adjusts the vehicle's power settings to reduce power consumption of the battery (e.g., either a hybrid electric vehicle or a fully electric vehicle) that powers the vehicle.
[0050] As described above, VOS 160A may present multiple user interfaces across multiple displays 150 communicatively coupled to vehicle head unit 102, each of the multiple user interfaces being associated with one or more of multiple user profiles. VOS 160A, in this context, may disable one or more of displays 150 based on one or more of the usage of the instance of the vehicle operating system, the presence of one or more occupants of the vehicle, weather conditions, and the operating state of the vehicle.
[0051] In this way, various aspects of the present technique may address issues with multiple displays 112 / 150, where a multi-display configuration is likely to use more power because the monitor is one of the most power-consuming modules. Powering the displays 112 / 150 may be adjusted according to ambient conditions (as represented by the operational context). The VOS 160 may manage power for single and multiple displays 112 / 150 with respect to usage, user presence, weather conditions, battery life, etc., to dynamically switch power settings. Switching power settings may conserve power in harsh conditions, such as colder temperatures, yet keep all displays powered in case of an emergency to help passengers report an accident / problem.
[0052] In some cases, as described above, the vehicle's operating conditions include battery life. VOS 160A may enter a protective operating mode and suggest disabling one or more of displays 112 / 150 based on weather conditions and battery life. That is, if it is very cold outside (e.g., below zero degrees Celsius), the battery may not perform optimally (compared to warmer temperatures), thereby resulting in a significant reduction in battery life that may reduce the driving range of a hybrid electric vehicle or all-electric vehicle. As a result, VOS 160A may disable certain displays 112 / 150 or limit the operation of displays 112 / 150 to extend battery life so that the operator / passenger may reach their intended destination without having to stop to recharge the battery (or in the event that a charger is unavailable and the battery is depleted, leaving them stranded).
[0053] Additionally or alternatively, VOS 160A may enter an emergency mode in which one or more applications executed by the vehicle operating system run in a limited access mode to preserve battery life based on one or more of weather conditions and battery life. In this example, VOS 160A may run in emergency mode to run applications in a so-called "dark mode" in which the display is dimmed or adapted to present applications primarily using dark colors that consume less power, run applications that resemble a low-power processor state, or otherwise reduce application execution (or in some cases stop execution of certain power-intensive applications, such as streaming video applications) to conserve the life of the battery powering the vehicle.
[0054] VOS 160A may determine the operating condition as an emergency condition in which the safety of the vehicle is compromised. Utilizing the vehicle sensors described above, VOS 160A may determine that the vehicle has experienced a collision or other accident that reduces the safe operation of the vehicle (e.g., a tire blowout via a tire pressure sensor). In these cases, rather than disabling all of displays 112 / 150, VOS 160A may enable all of displays 112 / 150 based on the emergency condition to allow multiple user profiles to report vehicle emergency conditions.
[0055] In this manner, various aspects of the present technique may address various issues when driving in dangerous or extreme external conditions to conserve any vehicle resources (such as batteries) as much as possible. Examples of dangerous or extreme external conditions are driving an all-electric vehicle on roads that may be inadvisable and shut down on low battery (e.g., dangerous roads) and / or driving an all-electric vehicle on low battery when external temperatures (very cold or very hot) may be deemed end-of-life critical. The VOS 160 may include an automobile display service that runs all entertainment apps in emergency mode (or even shuts them down) when the vehicle's conditions and current circumstances (external temperature or driving on a dangerous road / area) are not ideal. The VOS 160 may disable the passenger display 150 or any other associated entertainment hardware and may limit the operator display 112 to running and showing only critical applications (e.g., as dictated by an emergency mode access control list (ACL)).
[0056] Alternatively, or in conjunction with the above example, VOS 160 may enter a protective mode of operation by disabling all audio playback by computing device 102 based on an emergency condition. In this example, VOS 160 may potentially lower the audio to allow the vehicle operator to better focus on the emergency condition. In some examples, VOS 160 may disable all audio controls except for audio controls related to the emergency condition.
[0057] VOS 160 may automatically communicate the status of the vehicle operator during an emergency condition. VOS 160 may report the operator's status to emergency services, private security services, etc. VOS 160 may then transfer audio control of VOS 160 to one or more passengers based on the vehicle operator's status. That is, if the vehicle operator becomes incapacitated, VOS 160 may transfer audible control of VOS 160 to one or more passengers so that one or more passengers can act on the operator's behalf to contact emergency services. In other words, VOS 160 may enable one or more passengers to initiate an emergency telephone call to emergency services.
[0058] The VOS 160 may include a service that allows a signal to be sent from the OEM as an emergency signal. This signal is used to disable all sounds in the vehicle and override control of non-emergency audio use cases. This emergency service may also be used to signal if the driver becomes incapacitated and potentially transfer control of the audio system to another user in the vehicle. This may automatically allow the other user to generally control the main cabin emergency system. Thus, if the driver becomes incapacitated, the user may place a phone call.
[0059] As described below, vehicle head unit 102 may be located in a center console of the front dashboard of the vehicle and includes a main display 112 through which a vehicle operator interfaces with vehicle head unit 102. VOS 160 may determine whether the vehicle operator or one or more occupants of the vehicle are using the main display 112 of vehicle head unit 102. VOS 160 may then, in response to determining that one or more occupants of the vehicle are using the main display 112, disable a protective mode of operation to allow the one or more occupants to interface with VOS 160 via the main display 112.
[0060] VOS 160 may determine whether one or more occupants of the vehicle are using main display 112, at least in part, by determining the speed of the vehicle, determining the occupancy of one or more occupants, and determining the state of a passenger interaction status element. VOS 160 may then disable the protective mode of operation based on one or more of the speed of the vehicle, the occupancy of one or more occupants, and the state of the passenger interaction status element to allow the one or more occupants to interface with VOS 160 via main display 112. The passenger interaction status element may include a physical button located out of reach of the vehicle operator.
[0061] In other words, various aspects of the techniques described in this disclosure include a vehicle head unit 102, a speed sensor, an occupancy sensor, and an additional button (passenger UX button) to request removal of the restrictions. Speed sensor: Using this sensor, the vehicle head unit 102 can identify whether the car is parked or moving. Occupancy sensor: Using this sensor, the vehicle head unit 102 can identify whether an occupant is actually sitting in the passenger seat. Passenger UX button: This button needs to be located out of reach of the driver and in most cases can be located in the passenger door control panel.
[0062] The algorithm to apply this policy is as follows: When the car starts, it should check the status of the passenger UX button, if the button is initially on, it can be assumed that the button is broken and this restriction removal will no longer work. -When the car is moving and the head unit is showing some kind of UX. When the button is off, the head unit will apply the car's UX restrictions by definition. If the button is on and the occupancy sensor indicates that a passenger is present, the vehicle head unit 102 may lift the car's UX restrictions (or apply some kind of timeout) while the button is on.
[0063] As described above, VOS 160 may determine an emergency condition in which the safety of the vehicle is compromised. In response to determining the emergency condition, VOS 160 may present a panic mode user interface that includes a panic button for automatically requesting emergency services. In response to receiving input corresponding to the selection of the panic button, VOS 160 may initiate communication with emergency services.
[0064] In this way, the displays 112 / 150 enter panic mode after a car accident. Panic mode represents the easiest way to call for help. An example of panic mode is when all displays show a single "panic" button that, when pressed, automatically calls for help (e.g., the car calls 911, with or without an automated message).
[0065] Upon determining the operating context, VOS 160 may determine that the vehicle is entering a potentially unsafe operating context that requires additional attention from the vehicle operator. In response to entering the potentially unsafe operating context, VOS 160 may enter a protective operating mode by entering a protective operating mode in which VOS 160 lowers the volume of audio playback by the vehicle head unit. In some cases, when configured to determine that the vehicle is entering a potentially unsafe operating context, VOS 160 may determine, as an example, that the vehicle is overtaking another vehicle by crossing into an oncoming lane. Thus, when the vehicle detects a stressful situation (e.g., another vehicle approaching in the opposite direction while crossing), it may lower the volume of the display or any other entertainment that may be distracting.
[0066] In this regard, various aspects of the present techniques may improve the operation of the vehicle head unit 102 itself by dynamically entering a protective operating mode to potentially improve the safety level associated with operating the vehicle. For example, in the context of battery life, the VOS 160 may disable or reduce the operation of the displays 112 / 150 to preserve battery life so that the vehicle may reach its intended destination without depleting the battery powering the vehicle, which may improve safety, particularly when weather conditions might otherwise pose a significant risk to the health of the operator and / or passengers (e.g., when it is very cold or hot outside the vehicle's controlled environment). Thus, various aspects of the present techniques described in this disclosure may provide improvements to the operation of the vehicle itself in terms of providing safety to the operator and / or passengers (which may include the “operator” in the context of an autonomous vehicle).
[0067] Furthermore, by dynamically entering a protected mode of operation only when certain conditions are met (or, in other words, when the operational context allows for entry into the protected mode of operation), various aspects of the present techniques may reduce erroneous entry into a protected mode of operation in operational contexts that do not allow for entry into such a protected mode of operation. By avoiding unnecessary entry into unauthorized protected modes of operation, VOS 160 may improve the user experience while still potentially addressing operator and / or passenger safety in several different ways.
[0068] 2 is a diagram illustrating an example vehicle including a computing system configured to execute a vehicle operating system that operates in accordance with various aspects of the single-instance multi-user techniques described in this disclosure. As shown in the example of FIG. 2, the interior (sometimes referred to as the “cabin”) of a vehicle 200 may include a computing system in the form of a vehicle head unit 202, which represents an example of a computing device 102.
[0069] In the example of FIG. 2 , vehicle head unit 202 is integrated into a generally central portion (e.g., a center console) of front dashboard 220. Vehicle head unit 202 includes display 212, which may represent an example of presence-sensitive display 112. Vehicle 200 may also include displays 250A, 250B, and 250C, which may represent examples of display 150 described above with respect to FIG. 1 . Display 250A is integrated into the passenger side of front dashboard 220. Although not shown in the example of FIG. 2 , a display similar to display 250A may be integrated into the operator side of front dashboard 220. Displays 250B and 250C are integrated into the rear passenger compartment of the vehicle cabin (i.e., in the headrests of the front seats in the example of FIG. 2 ) on both the operator side (display 250B) and the passenger side (display 250C).
[0070] As described above, VOS 160A may interface with a first user (a front passenger) via a first user interface (e.g., presented by display 250A) associated with a first user profile (e.g., UP 161A) to interact with content presented (e.g., presented by display 250B, etc.) by a second user interface associated with a second user profile (e.g., UP 161B) of the plurality of UPs 161. In some examples, VOS 160A may interface with the first user to one or more of viewing or beginning playback of content presented by the second user interface in the first user interface.
[0071] VOS 160A may also interface with the first user to control audio playback through the second user interface presented by display 250B. VOS 160A may interface with the first user via the first user interface presented by display 250A to change the audio volume associated with audio playback through the second user interface presented by display 250B.
[0072] VOS 160A may also interface with a first user to enable a first user and a second user (e.g., a rear passenger on the operator's side) to collaboratively interact with content presented by a second user interface presented by display 250B. In this example, VOS 160A may interface with a first user to enable the first user and the second user to collaboratively contribute to audio playback by the second user interface (e.g., by collaborating on building an audio playlist). VOS 160A may also interface with a first user to enable the first user and the second user to collaboratively contribute to a multi-user activity presented by the second user interface, as another example, such a multi-user activity may include a navigation activity in which both the first user and the second user contribute to navigation of vehicle 200, including a multi-player video game presented by vehicle head unit 202 and / or the second user interface.
[0073] Although shown as multiple physical displays 212 / 250, various aspects of the present technique may operate with respect to a single physical display (or multiple physical displays) having separate, logically separated displays (or so-called virtual displays). That is, the single physical display 212 / 250 may be logically divided (e.g., via software) to appear (from the perspective of an instance of VOS 160) as two separate physical displays. In this regard, a single physical display may represent multiple different displays, with displays 212 / 250 each representing a logically separate virtual display.
[0074] In this regard, various aspects of the techniques described herein include: Parents want to see what their kids are watching. If a parent or driver wants to control the volume of the child's display, If two or more passengers want to contribute to a shared playlist, If two or more passengers wish to interact on the same content (e.g. multi-player), This may enable several different use cases, including:
[0075] The following use cases demonstrate the techniques: Mirror can display content when running on Android Auto. Allowing drivers and passengers to mirror the content of their displays; and Allowing the driver or passenger to send inputs (such as key, rotary, d-pad, touch, etc. events) to the other passenger's display; may be enabled if
[0076] In other words, various aspects of the techniques described herein may address problems associated with enabling mobile apps to interact with each other (same or different apps) across multiple users concurrently on a single Android instance. As such, these techniques may enable backseat-to-operator interaction to add waypoints to navigation and / or operator-to-backseat (e.g., children) interaction to play videos.
[0077] VOS 160A may also interface with a first user (a front passenger) of the plurality of users via a first user interface associated with UP 161A to share content presented by the first user interface with a second user interface of the plurality of user interfaces associated with UP 161B. For example, VOS 160A may receive a gesture at a first user interface, illustratively presented by display 250A, indicating that content presented by the first user interface is to be shared with a second user interface, illustratively presented by display 250B. The gesture may include one or more of a swipe gesture, a pinch gesture, a tap gesture, or any other gesture associated with using a presence-sensitive display such as display 250A.
[0078] VOS 160A may, in some cases, be configured to present an animation in the first user interface indicating the start of the shared content. Additionally or alternatively, VOS 160A may play audio indicating the start of the shared content. In some examples, when VOS 160A plays audio indicating the start of the shared content, it may play spatialized audio to reflect the position of the first user interface relative to the position of the second user interface.
[0079] In this regard, various aspects of the present techniques may use advanced user interface techniques to make cross-view interactions more immersive, such as screen sharing. Based on the positional relationships between passenger zones within a vehicle, the techniques may: Send content from one display to another using gestures (swipes, clicks, etc.) Use animation to visualize interactions and Use spatial audio to indicate the position of moving content for a more immersive experience; may be possible.
[0080] 3 illustrates different interaction models with multiple displays, including interactions that occur via a single-instance multi-user model and a multi-instance multi-user model, in accordance with the vehicle operating system techniques described in this disclosure. As discussed in this disclosure, vehicle displays, such as displays 212 and 250, are evolving from an operator-centric to a whole-car experience, where occupants can: Personalized curated experiences during your commute, · Joint experiences for enjoying family trips and Shared experiences in ride-sharing environments and can have:
[0081] Original equipment manufacturers (OEMs) may recognize these needs and are building vehicles to provide these experiences to users. These are no longer considered premium experiences, but rather desirable vehicle values.
[0082] In this regard, the user can: Navigation - Allows the driver to add stops from the display for an ongoing trip and Entertainment - Playing and controlling videos or games for kids in the back seat to keep them engaged and entertained; Access to uniquely curated apps, content, and data for user entertainment and / or productivity; and Personalization - Control your seat settings, HVAC controls, and alerts for your seat. For a seamless and immersive experience like this, you may want a parallel experience across displays.
[0083] OEMs are considering following user interaction models based on their predictions of user behavior. There are three types of interaction models: 1. The In-Vehicle Infotainment (IVI) display is the primary controller of content on the Front Seat Entertainment (FSE) and Rear Seat Entertainment (RSE); a.FSE and RSE have minimal controls for audio, play / pause, on / off, etc. 2. The IVI screen is mirrored across the FSE / RSE, and the passenger display cannot select content or controls. 3. Content can be shared across all screens, with each screen having its own individual controls; (shown in the example in Figure 3).
[0084] In a multi-display scenario, the following user personas exist: Driver: Interact with the cluster and IVI screens to drive and interact with other screens in the car Front seat passengers: Assisting drivers with navigation and passenger content using FSE Rear seat passengers: Interact with the RSE for content, controls and suggestions to the driver for navigation ·guest: For temporary rides, you want to access some apps on the passenger display FIG. 4 illustrates an exemplary vehicle including a vehicle head unit configured to control audio content in accordance with various aspects of the single-instance multi-user vehicle operating system techniques described in this disclosure. In the example of FIG. 4, vehicle 400 may represent an example of vehicle 200 (shown in FIG. 2) in which vehicle head unit 202 enables privacy and sharing among different audio zones 404A-404D ("audio zones 404") within vehicle 400. Audio zone 404A may represent a front seat operator side zone (also referred to as "front operator zone 404A"). Audio zone 404B may represent a front seat passenger side zone (also referred to as "front passenger zone 404B"). Audio zone 404C may represent an operator side rear passenger zone, and audio zone 404D may represent a passenger side rear passenger zone.
[0085] In each of audio zones 404, vehicle 200 may include a respective one of audio capture devices 452A-452D (“audio capture device 452”) and a respective one of speakers 454A-454D (“speaker 454”). Audio capture device 452 may represent an example of audio capture device 152. Both audio capture device 452 and speaker 454 may represent transducers capable of converting sound pressure into electrical signals representative of a sound field, in the example of audio capture device 452, and converting electrical signals representative of a sound field into a corresponding sound field, in the example of speaker 454.
[0086] Although described as having a single one of the audio capture devices 452 and a single one of the speakers 454 within each of the audio zones 404, each of the audio zones 404 may include more or fewer audio capture devices 452 and more or fewer speakers 454. Furthermore, although described as being transducers, any type of device capable of capturing audio data (converted from electrical signals captured by the audio capture devices 452) and recreating a sound field from the electrical signals (converted from the audio data) may be utilized in one or more of the audio zones 404. Furthermore, while four audio zones 404 are shown in the example of FIG. 4, the vehicle 400 may include more or fewer audio zones 404.
[0087] In either case, VOS 160A may interface with multiple users to control audio playback within one or more of the cabin zones 404 of the vehicle 400 that includes the vehicle head unit 202. VOS 160A may, for example, interface with multiple users to control audio volume within a single one of the cabin zones 404. As another example, VOS 160A may interface with multiple users to control the focus of audio playback within at least one of the cabin zones 404.
[0088] As such, various aspects of the present technique may provide a central audio control service for all users (e.g., driver and / or passengers) in parallel to control audio settings (volume up / down, mute, unmute, or any other control). To facilitate this control, VOS 160A may include: - Manage controls independently for each user within each audio zone, Managing the focus of other users in separate zones; - Taking into account current safety limitations, - Taking into account the current user role (driver, passenger, passenger with disabilities, rear seat passenger) and A service for managing audio controls (e.g., volume, mute, settings, ducking, pause, etc.) may be provided to provide a
[0089] Additionally, one or more of the audio capture devices 452 may capture audio data (other terms for audio zones 404) representing the sound field in each of the one or more zones 404. Based on the audio data representing the sound field occurring in each of the zones 404, VOS 160A may determine that a first user of multiple users in a first zone (e.g., zone 404C) of the one or more zones is speaking in an attempt to vocally interface with vehicle head unit 202. VOS 160A may adjust audio playback in zone 404 based on the audio data representing the sound field occurring in each of the zones 404.
[0090] In regard to adjusting the audio playback, VOS 160A may determine a noise level based on audio data representing the sound field occurring in each of zones 404. VOS 160A may then adjust the audio playback in one or more of zones 404 based on the noise level.
[0091] In this regard, various aspects of the present technique may address ways to enable multi-microphone support for VOS 160A. VOS 160A uses audio data captured by audio capture device 452 to: Use the microphone to know which user is speaking and adjust the volume control by recognizing the user; Mapping to the display being used, Providing better assistant responses to users (utterances), Detecting the noise level per user (around the user's respective area) and performing necessary audio modifications to the audio playback for comfortable audio listening; It also combines individual user audio information to determine the noise level inside the car and adjust the speakers for a better listening experience. may be determined and / or performed.
[0092] 5 and 6 are diagrams illustrating audio control in a single-instance, multi-user vehicle operating system in accordance with various aspects of the techniques described in this disclosure. In some cases, vehicle operating systems are limited in scope in that they can only send audio from one zone to another for that particular application's unique identifier (UID). Various aspects of the techniques described in this disclosure allow a zone 404 to: Sharing media audio from passengers to the main cabin; Providing a mechanism for occupants not in the main cabin to request audio playback to the main zone (e.g., operator zone 404A); Providing a mechanism for the driver to allow audio playback within the main zone; and Providing a mechanism for sharing audio focus between two different zones; Disable volume controls that are controlled by anyone other than the vehicle owner; This allows audio to be shared throughout the vehicle cabin.
[0093] For example, a passenger listening to media in a rear seat entertainment (RSE) zone (e.g., one of zones 404C or 404D) may send the audio to the main cabin to allow everyone in the vehicle to hear the audio. When a passenger in the rear seat RSE chooses to send audio to the main cabin, the operator (or main cabin user) maintains control over allowing audio playback and retains control over volume and other audio settings.
[0094] Figure 5 shows an overview of the current audio architecture. Audio zones 404 are defined in the configuration and are used to set up audio routing for each audio zone 404. Each audio zone 404 is defined as a collection of volume groups, each group containing a set of devices that are controlled for volume changes in the volume group. Each device can have different audio contexts routed to it. The vehicle audio service can use the routing information for each audio zone to define a set of audio mixes that VOS 160A can use to configure audio routing for each zone 404.
[0095] Referring now to Figure 6, a configuration setup between a vehicle audio service and a vehicle occupant zone service is shown. For audio, the vehicle audio service may read a mapping of audio zones (audioZoneId) to occupant zone Ids (occupantZoneId) from the configuration. This information may be sent to the vehicle occupant zone service to set up the occupant zone configuration during initialization. The occupant zone service may maintain information about the occupant zone configuration and display port mapping, which may be read from different configuration information.
[0096] The car audio service may register a VehicleOccupantZoneCallback with the occupant zone service. VOS160A may detect the following changes in the vehicle occupant zone: Activating the display and Change the audio configuration and · User allocation of occupancy zones; Passenger start and - Passenger suspension and may trigger this service.
[0097] When the audio service receives the onOccupantZoneConfigChanged signal from the callback, the audio service of VOS160A does the following: Unloading previous user settings and Remove previous user audio policy routing and Loading new user audio settings and Setting up audio policy routing for new users; -Resetting audio focus mapping for new users and To do so, users may be automatically assigned to corresponding audio zones.
[0098] The audio service of VOS 160A may use the audio focus mapping to determine where incoming focus requests should be assigned.
[0099] To allow passengers to send audio to the main cabin, several things are required: · To meet the focus requirements in the main cabin; Routing passenger audio to the main cabin; and must be in place. Once the focus request has successfully changed from the occupant's own audio zone within the vehicle 400, audio routing can occur. If audio playback has not yet started, the focus process will automatically request focus within the main cabin zone according to rules already set regarding audio usage priorities (e.g., audio for media is denied on a current phone call).
[0100] The passenger can request to send audio to the main cabin, and a prompt will pop up for the driver to accept. Alternatively, the driver can enable automatic acceptance of the passenger to play audio. If accepted, the audio focus request can be forwarded to the main cabin as needed, and playback can begin. If not accepted, the passenger can be prompted with a message.
[0101] Since one goal of the feature is to play media from the occupant in the main cabin, the occupant's focus request can be limited to media only. Focus requests for other sounds (e.g., alarms, calls, notifications, etc.) should stay within the occupant's respective zone. For media focus requests, the logic is as follows: Sending a temporary focus loss to the passenger's media app; Requesting focus for passenger media apps in the main cabin; If the focus request is granted, sending the focus gain; If the sound (emergency, phone call) is not allowed due to its high priority, Set the focus request as deferred focus, Once the higher priority focus is completed, the focus is granted, Alternative: Sending focus back to the user zone, and It could be something like this.
[0102] If a user ID is used, the possible driver for audio routing may be user ID device affinity routing, which is as follows: Locate your primary vehicle interior media device (preferably a separate, high-quality device); Resetting passenger device affinity to share cabin media devices; And so on, it can be further utilized to transmit passenger audio to the main cabin.
[0103] Additionally, multi-zone audio (MZA) may facilitate audio playback by various users, all playing audio in each of the individual audio zones 404. This may allow users in the main cabin to play media or any other sound, and users in the rear entertainment system to also play media in their respective zones. This potentially allows OEMs to design complex audio infotainment systems that can tailor each occupant's experience within the vehicle 400.
[0104] Example use cases include: In the car, the driver can play music and rear seat users can play their own music / media; Rear seat passengers can control the volume of their own music without affecting the driver's music playback. - First-party music apps launched in the rear seat can play sound in the rear seat without any modification; Includes:
[0105] One mechanism used for MZA is based on dynamic audio policies, specifically using UID / userId-based routing. This allows audio policies to define routing based on audio attribute usage, UID, or userId. This allows applications or services to take advantage of the automatic routing of audio configured by dynamic audio policies. However, APIs exist that can be used to route audio outside of the assigned audio device. This can have some impact inside the vehicle, as applications can send audio to specific zones without user permission, for example: A rear seat entertainment (RSE) application from User A sends audio directly to the driver user's output device in the main cabin. An RSE application from user A sends audio directly to a different RSE output device assigned to user B. This may raise some driver safety concerns if unwanted audio reaches the primary vehicle cabin and may distract the primary driver.
[0106] One possible goal of this aspect of the technique is to allow current dynamic audio policies to continue to function, but also to allow users (and their respective applications / services) to restrict audio playback to play outside of their assigned set of zones, regardless of the mechanism used to select a device for audio playback. A potential benefit for users in cars is that they can constantly listen to audio in their cars in a private and consistent manner.
[0107] Dynamic audio policies may provide a mechanism to configure the devices a user can use for automatic routing via the audio policy API. This audio policy API may either be used or extended to restrict applications that use audio routing on a set of preferred devices to route audio outside the limits of the audio policy user allocation. This may limit "forced" routing of devices defined within the audio policy.
[0108] 7 is a flowchart illustrating an example operation of the computing system shown in FIG. 1 when executing a vehicle operating system configured to perform various aspects of the safety techniques described in this disclosure. As described above, processor 140 of computing device 102 may execute 700 an instance of a vehicle operating system (e.g., VOS 160A). VOS 160A may determine 702 an operational context in which the vehicle is currently operating. VOS 160A may interface with any number of different vehicle sensors to determine the operational context, such as speed sensors, global positioning system (GPS) sensors, occupancy sensors (e.g., which may sense weight on a seat), cameras, microphones, weather sensors (e.g., humidity, moisture, temperature, etc.), accelerometers, gyroscopes, infrared sensors, seat belt sensors, tire pressure sensors, or any other sensors capable of communicating with computing device 102 (such sensors may be represented by input components 144 and / or output components 146).
[0109] To determine the operational context, VOS 160A may perform one or more of the following: determine usage of VOS 160A by one or more occupants in the vehicle; determine the presence of one or more occupants in the vehicle (e.g., via occupancy sensors, cameras, microphones, etc.); determine the weather conditions in which the vehicle is currently operating; and determine the operational state of the vehicle. VOS 160A may also determine the state of occupant interaction status elements (e.g., physical buttons located within the vehicle cabin out of reach of the vehicle operator, such as on a passenger door).
[0110] VOS 160A may enter a protective mode of operation based on the operational context in which the vehicle operating system dynamically adapts one or more operational characteristics of the vehicle operating system to promote safety for the vehicle operator (704). For example, VOS 160A may enter a protective mode of operation in which VOS 160A dynamically adjusts the vehicle's power settings to reduce power consumption of a battery (e.g., either a hybrid electric vehicle or a fully electric vehicle) that powers the vehicle.
[0111] In this manner, the techniques described above may enable the following examples. Example 1. A method comprising: executing, by a vehicle head unit of a vehicle, an instance of a vehicle operating system; determining, by the instance of the vehicle operating system, an operational context in which the vehicle is currently operating; and entering, by the instance of the vehicle operating system and based on the operational context, a protective operating mode in which the vehicle operating system dynamically adapts one or more operational characteristics of the vehicle operating system to promote safety of an operator of the vehicle.
[0112] Example 2. The method of example 1, wherein entering the protective operating mode includes entering the protective operating mode in which the vehicle operating system dynamically adjusts power settings of the vehicle to reduce power consumption of a battery powering the vehicle.
[0113] Example 3. The method of any combination of Examples 1 and 2, wherein determining the operational context includes one or more of determining usage of the instance of the vehicle operating system by one or more occupants in the vehicle, determining the presence of the one or more occupants in the vehicle, determining weather conditions in which the vehicle is currently operating, and determining the operational state of the vehicle.
[0114] Example 4. The method of Example 3, wherein the instance of the vehicle operating system facilitates concurrent access by multiple user profiles, the method further including presenting, by the instance of the vehicle operating system, multiple user interfaces across multiple displays communicatively coupled to the vehicle head unit, each of the multiple user interfaces associated with one or more of the multiple user profiles, and wherein entering the protected operating mode includes disabling one or more of the multiple displays based on one or more of the usage of the instance of the vehicle operating system, the presence of the one or more occupants of the vehicle, the weather conditions, and the operational state of the vehicle.
[0115] Example 5. The method of example 4, wherein the one or more occupants of the vehicle are associated with at least one of the plurality of user profiles.
[0116] Example 6. The method of any combination of Examples 3-5, wherein the instance of the vehicle operating system facilitates concurrent access by multiple user profiles, and the operational state of the vehicle includes battery life, and the method further includes presenting, by the instance of the vehicle operating system, multiple user interfaces across multiple displays communicatively coupled to the vehicle head unit, each of the multiple user interfaces being associated with one or more of the multiple user profiles, and entering the protective operational mode includes disabling one or more of the multiple displays based on the weather conditions and the battery life.
[0117] Example 7. The method according to any combination of Examples 3-6, wherein the instance of the vehicle operating system facilitates concurrent access by multiple user profiles, and the operational state of the vehicle includes battery life, and the method further includes presenting, by the instance of the vehicle operating system, multiple user interfaces across multiple displays communicatively coupled to the vehicle head unit, each of the multiple user interfaces being associated with one or more of the multiple user profiles, and entering the protective operating mode includes entering an emergency mode in which one or more applications executed by the vehicle operating system execute in a limited access mode to preserve the battery life based on one or more of the weather conditions and the battery life.
[0118] Example 8. The method according to any combination of Examples 3 to 7, wherein determining the operational state of the vehicle includes determining an emergency condition in which safety of the vehicle is compromised, the method further includes presenting, by the instance of the vehicle operating system, a plurality of user interfaces across a plurality of displays communicatively coupled to the vehicle head unit, each of the plurality of user interfaces being associated with one or more of a plurality of user profiles, and entering the protective operational mode includes enabling all of the plurality of displays based on the emergency condition to enable the plurality of user profiles to report the emergency condition of the vehicle.
[0119] Example 9. A method according to any combination of Examples 3 to 8, wherein determining the operating state of the vehicle includes determining an emergency condition in which the safety of the vehicle is compromised, and entering the protective operating mode includes disabling all audio playback by the vehicle head unit based on the emergency condition.
[0120] Example 10. A method according to any combination of Examples 3 to 9, wherein determining the operating state of the vehicle includes determining an emergency state in which the safety of the vehicle is compromised, and entering the protective operating mode includes disabling all audio controls except for audio controls related to the emergency state.
[0121] Example 11. The method according to any combination of Examples 3 to 10, wherein determining the operating state of the vehicle includes determining an emergency state in which safety of the vehicle is compromised, and entering the protective operating mode includes automatically communicating the state of the operator of the vehicle during the emergency state, and transferring audio control of the vehicle operating system to the one or more occupants based on the state of the operator of the vehicle.
[0122] Example 12. The method of example 11, wherein transferring the audio control of the vehicle operating system enables the one or more occupants to initiate an emergency telephone call to emergency services.
[0123] Example 13. The method of any combination of Examples 3 to 12, wherein the vehicle head unit is located in a center console of the front dashboard of the vehicle and includes a main display through which the operator of the vehicle interfaces with the vehicle head unit, and determining the usage status of the instance of the vehicle operating system includes determining whether the operator of the vehicle or the one or more occupants of the vehicle are using the main display of the vehicle head unit, and entering the protected operating mode includes, in response to determining that the one or more occupants of the vehicle are using the main display, disabling the protected operating mode to allow the one or more occupants to interface with the vehicle operating system via the main display.
[0124] Example 14. The method of example 13, wherein determining whether the one or more occupants of the vehicle are using the main display includes one or more of determining the speed of the vehicle, determining the occupancy of the one or more occupants, and determining the state of an occupant interaction status element.
[0125] Example 15. The method of Example 14, wherein entering the protective mode of operation includes disabling the protective mode of operation based on one or more of the speed of the vehicle, the occupancy of the one or more passengers, and the state of the passenger interaction status element to allow the one or more passengers to interface with the vehicle operating system via the main display.
[0126] Example 16. A method according to any combination of Examples 14 and 15, wherein the occupant interaction status element includes a physical button located in a position on the vehicle that is out of reach of the operator.
[0127] Example 17. A method according to any combination of Examples 3 to 16, wherein determining the operating state of the vehicle includes determining an emergency state in which the safety of the vehicle is compromised, and entering the protective operating mode includes presenting a panic mode user interface including a panic button for automatically requesting emergency services, and initiating communication with the emergency services in response to receiving input corresponding to selection of the panic button.
[0128] Example 18. The method of any combination of Examples 1 to 17, wherein determining the operational context includes determining that the vehicle is entering a potentially unsafe operational context requiring additional attention by the operator of the vehicle, and entering the protective operational mode includes, in response to entering the potentially unsafe operational context, the vehicle operating system entering the protective operational mode to reduce the volume of audio playback by the vehicle head unit.
[0129] Example 19. The method of Example 18, wherein determining that the vehicle is potentially entering the potentially unsafe operating context includes determining that the vehicle is overtaking another vehicle by crossing into an oncoming lane.
[0130] Example 20. The method of any combination of Examples 1-19, wherein the instance of the vehicle operating system facilitates concurrent access by multiple user profiles, the method further comprising: authorizing, by the instance of the vehicle operating system, the multiple user profiles to interface with the instance of the vehicle operating system; presenting, by the instance of the vehicle operating system, multiple user interfaces across multiple displays communicatively coupled to the vehicle head unit, each of the multiple user interfaces being associated with one or more of the multiple user profiles; and interfacing with multiple users associated with the one or more of the multiple user profiles via the multiple user interfaces to enable the multiple users to interface with the instance of the vehicle operating system for purposes of controlling functionality associated with the vehicle head unit.
[0131] Example 21. The method of Example 20, wherein the instance of the vehicle operating system includes a first instance of the vehicle operating system, and the method further includes executing a second instance of the vehicle operating system, the first instance of the vehicle operating system including an interface for communicating with the second instance of the vehicle operating system to facilitate concurrent access by the multiple user profiles.
[0132] Example 22. The method of Example 21, wherein the vehicle head unit includes a high processing power processor that executes the first instance of the vehicle operating system, and the vehicle head unit includes a low processing power processor that executes the second instance of the vehicle operating system, the high processing power processor providing more processing power than the low processing power processor.
[0133] Example 23. A method according to any combination of Examples 20 and 21, wherein the plurality of displays are arranged around the cabin of the vehicle including the vehicle head unit.
[0134] Example 24. A method according to any combination of Examples 20 to 23, wherein the plurality of displays includes two or more of a first display integrated into the operator side of the front dashboard of the vehicle cabin including the vehicle head unit, a second display integrated into the center console of the front dashboard, a third display integrated into the passenger side of the front dashboard, and a fourth display integrated into the rear passenger compartment of the vehicle cabin.
[0135] Example 25. A method according to any combination of Examples 20 to 24, wherein the plurality of displays includes one or more computing devices associated with at least one of the plurality of users who is an occupant of a vehicle including the vehicle head unit.
[0136] Example 26. A computing device including a memory configured to store an instance of a vehicle operating system and one or more processors for executing the instance of the vehicle operating system, wherein the instance of the vehicle operating system is configured to determine an operational context in which the vehicle is currently operating, and based on the operational context, to enter a protective operating mode in which the vehicle operating system dynamically adapts one or more operational characteristics of the vehicle operating system to promote safety of an operator of the vehicle.
[0137] Example 27. The computing device of Example 26, wherein the instance of the vehicle operating system is configured to enter the protective operating mode in which the vehicle operating system dynamically adjusts power settings of the vehicle to reduce power consumption of a battery powering the vehicle.
[0138] Example 28. A computing device described in any combination of Examples 26 and 27, wherein the instance of the vehicle operating system is configured to perform one or more of: determining usage of the instance of the vehicle operating system by one or more occupants in the vehicle; determining the presence of the one or more occupants in the vehicle; determining weather conditions in which the vehicle is currently operating; and determining the operating state of the vehicle.
[0139] Example 29. The computing device of Example 28, wherein the instance of the vehicle operating system facilitates concurrent access by multiple user profiles, the instance of the vehicle operating system is further configured to present multiple user interfaces across multiple displays communicatively coupled to the vehicle head unit, each of the multiple user interfaces being associated with one or more of the multiple user profiles, and the instance of the vehicle operating system is configured to disable one or more of the multiple displays based on one or more of the usage of the instance of the vehicle operating system, the presence of the one or more occupants of the vehicle, the weather conditions, and the operational state of the vehicle.
[0140] Example 30. The computing device of Example 29, wherein the one or more occupants of the vehicle are associated with at least one of the plurality of user profiles.
[0141] Example 31. A computing device described in any combination of Examples 28 to 30, wherein the instance of the vehicle operating system facilitates parallel access by multiple user profiles, the operating conditions of the vehicle include battery life, the instance of the vehicle operating system is further configured to present multiple user interfaces across multiple displays communicatively coupled to the vehicle head unit, each of the multiple user interfaces being associated with one or more of the multiple user profiles, and the instance of the vehicle operating system is configured to disable one or more of the multiple displays based on the weather conditions and the battery life.
[0142] Example 32. A computing device described in any combination of Examples 28 to 31, wherein the instance of the vehicle operating system facilitates concurrent access by multiple user profiles, the operating conditions of the vehicle include battery life, the instance of the vehicle operating system is further configured to present multiple user interfaces across multiple displays communicatively coupled to the vehicle head unit, each of the multiple user interfaces being associated with one or more of the multiple user profiles, and entering the protective operating mode includes entering an emergency mode in which one or more applications executed by the vehicle operating system run in a limited access mode to preserve the battery life based on one or more of the weather conditions and the battery life.
[0143] Example 33. A computing device described in any combination of Examples 28 to 32, wherein the instance of the vehicle operating system is configured to determine an emergency condition that compromises the safety of the vehicle, and the instance of the vehicle operating system is further configured to present a plurality of user interfaces across a plurality of displays communicatively coupled to the vehicle head unit, each of the plurality of user interfaces being associated with one or more of a plurality of user profiles, and the instance of the vehicle operating system is configured to enable all of the plurality of displays based on the emergency condition to enable the plurality of user profiles to report the emergency condition of the vehicle.
[0144] Example 34. A computing device described in any combination of Examples 28 to 33, wherein the instance of the vehicle operating system is configured to determine an emergency condition that compromises the safety of the vehicle, and the instance of the vehicle operating system is configured to disable all audio playback by the vehicle head unit based on the emergency condition.
[0145] Example 35. A computing device described in any combination of Examples 28 to 34, wherein the instance of the vehicle operating system is configured to determine an emergency condition in which the safety of the vehicle is compromised, and the instance of the vehicle operating system is configured to disable all audio controls except for audio controls related to the emergency condition.
[0146] Example 36. A computing device described in any combination of Examples 28 to 35, wherein the instance of the vehicle operating system is configured to determine an emergency condition in which the safety of the vehicle is compromised, the instance of the vehicle operating system is configured to automatically communicate the status of the operator of the vehicle during the emergency condition, and is configured to transfer audio control of the vehicle operating system to the one or more occupants based on the status of the operator of the vehicle.
[0147] Example 37. The computing device of Example 36, wherein the instance of the vehicle operating system is configured to transfer the audio control of the vehicle operating system to enable the one or more occupants to initiate an emergency telephone call to emergency services.
[0148] Example 38. A computing device described in any combination of Examples 28 to 37, wherein the vehicle head unit is located in a center console of the front dashboard of the vehicle and includes a main display through which the operator of the vehicle interfaces with the vehicle head unit, the instance of the vehicle operating system is configured to determine whether the operator of the vehicle or the one or more occupants of the vehicle are using the main display of the vehicle head unit, and the instance of the vehicle operating system is configured, in response to determining that the one or more occupants of the vehicle are using the main display, to disable the protected operating mode to allow the one or more occupants to interface with the vehicle operating system via the main display.
[0149] Example 39. The computing device of Example 38, wherein the instance of the vehicle operating system is configured to perform one or more of determining the speed of the vehicle, determining the occupancy of the one or more passengers, and determining the state of a passenger interaction status element.
[0150] Example 40. The computing device of Example 39, wherein the instance of the vehicle operating system is configured to disable the protective operating mode based on one or more of the speed of the vehicle, the occupancy of the one or more passengers, and the state of the passenger interaction status element to allow the one or more passengers to interface with the vehicle operating system via the main display.
[0151] Example 41. A computing device described in any combination of Examples 39 and 40, wherein the occupant interaction status element includes a physical button located out of reach of the operator of the vehicle.
[0152] Example 42. A computing device described in any combination of Examples 28 to 41, wherein the instance of the vehicle operating system is configured to determine an emergency condition in which the safety of the vehicle is compromised, the instance of the vehicle operating system is configured to present a panic mode user interface including a panic button for automatically requesting emergency services, and in response to receiving input corresponding to selection of the panic button, initiate communication with the emergency services.
[0153] Example 43. A computing device described in any combination of Examples 26 to 42, wherein the instance of the vehicle operating system is configured to determine that the vehicle has entered a potentially unsafe operating context requiring additional attention by the operator of the vehicle, and in response to entering the potentially unsafe operating context, the vehicle operating system is configured to enter the protective operating mode that reduces the volume of audio playback by the vehicle head unit.
[0154] Example 44. The computing device of Example 43, wherein the instance of the vehicle operating system is configured to determine that the vehicle is overtaking another vehicle by crossing into an oncoming lane.
[0155] Example 45. A computing device described in any combination of Examples 26 to 44, wherein the instance of the vehicle operating system includes a first instance of the vehicle operating system, and the one or more processors are further configured to execute a second instance of the vehicle operating system, and the first instance of the vehicle operating system includes an interface for communicating with the second instance of the vehicle operating system to facilitate parallel access by the multiple user profiles.
[0156] Example 46. The computing device of Example 45, wherein the one or more processors include a high processing power processor that executes the first instance of the vehicle operating system, and the one or more processors include a low processing power processor that executes the second instance of the vehicle operating system, the high processing power processor providing greater processing power than the low processing power processor.
[0157] Example 47. A computing device described in any combination of Examples 45 and 46, wherein the multiple displays are arranged around the cabin of the vehicle including the vehicle head unit.
[0158] Example 48. A computing device described in any combination of Examples 45 to 47, wherein the multiple displays include two or more of: a first display integrated into the operator side of the front dashboard of the vehicle cabin including the vehicle head unit; a second display integrated into the center console of the front dashboard; a third display integrated into the passenger side of the front dashboard; and a fourth display integrated into the rear passenger compartment of the vehicle cabin.
[0159] Example 49. A computing device described in any combination of Examples 45 to 48, wherein the plurality of displays includes one or more computing devices associated with at least one of the plurality of users who is an occupant of a vehicle including the vehicle head unit.
[0160] Example 50. A non-transitory computer-readable storage medium having stored thereon instructions that, when executed, cause one or more processors to execute an instance of a vehicle operating system, cause the instance of the vehicle operating system to determine an operational context in which the vehicle is currently operating, and cause the instance of the vehicle operating system and, based on the operational context, to enter a protective operating mode in which the vehicle operating system dynamically adapts one or more operational characteristics of the vehicle operating system to promote safety for an operator of the vehicle.
[0161] In one or more examples, the functions described may be implemented in hardware, software, firmware, or any combination thereof. If implemented in software, the functions may be stored on or transmitted as one or more instructions or code on a computer-readable medium and executed by a hardware-based processing unit. Computer-readable media may include computer-readable storage media, which correspond to tangible media, such as data storage media, or communication media, including any medium that facilitates transfer of a computer program from one place to another, for example, according to a communications protocol. In this manner, computer-readable media may generally correspond to (1) tangible computer-readable storage media that is non-transitory, or (2) a communication medium, such as a signal or carrier wave. Data storage media may be any available medium that can be accessed by one or more computers or one or more processors to retrieve instructions, code, and / or data structures for implementing the techniques described in this disclosure. A computer program product may include a computer-readable medium.
[0162] By way of example, and not limitation, such computer-readable storage media may include RAM, ROM, EEPROM, CD-ROM, or other optical disk storage, magnetic disk storage, or other magnetic storage devices, flash memory, or any other storage medium that can be used to store desired program code in the form of instructions or data structures and that can be accessed by a computer. Also, any connection is properly referred to as a computer-readable medium. For example, if instructions are transmitted from a website, server, or other remote source using coaxial cable, fiber optic cable, twisted pair, digital subscriber line (DSL), or wireless technologies such as infrared, radio, and microwave, the coaxial cable, fiber optic cable, twisted pair, DSL, or wireless technologies such as infrared, radio, and microwave are included within the definition of medium. However, it should be understood that computer-readable storage media and data storage media do not include connections, carrier waves, signals, or other transitory media; instead, these media are intended to cover non-transitory, tangible storage media. Disks and discs that may be used include compact discs (CDs), laser discs, optical discs, digital versatile discs (DVDs), floppy disks, and Blu-ray discs, Ultra Blu-ray discs, etc. Disks typically reproduce data magnetically, while discs reproduce data optically using lasers. Combinations of the above should also be included within the scope of computer-readable media.
[0163] The instructions may be executed by one or more processors, such as one or more digital signal processors (DSPs), general-purpose microprocessors, application-specific integrated circuits (ASICs), field-programmable logic arrays (FPGAs), or other equivalent integrated or discrete logic circuitry. Accordingly, the term "processor" as used may refer to any of the foregoing structures or any other structure suitable for implementing the described techniques. Furthermore, in some aspects, the described functionality may be provided in dedicated hardware and / or software modules. The techniques may also be implemented entirely in one or more circuits or logic elements.
[0164] The techniques of this disclosure may be implemented in a variety of devices or apparatuses, including a wireless handset, an integrated circuit (IC), or a set of ICs (e.g., a chipset). This disclosure describes various components, modules, or units to highlight functional aspects of devices configured to implement the disclosed techniques, but does not necessarily require realization by different hardware units. Rather, as described above, the various units may be combined into a hardware unit or provided by a collection of interoperable hardware units, including one or more processors as described above, in combination with appropriate software and / or firmware.
[0165] Various examples have been described. These and other embodiments are within the scope of the following claims.
Claims
1. executing, by a vehicle head unit of the vehicle, an instance of a vehicle operating system; determining, by the instance of the vehicle operating system, an operational context in which the vehicle is currently operating; entering, by the instance of the vehicle operating system and based on the operational context, a protected operating mode in which the vehicle operating system dynamically adapts one or more operational characteristics of the vehicle operating system to promote safety of an operator of the vehicle.
2. 2. The method of claim 1, wherein entering the protective operating mode includes entering the protective operating mode in which the vehicle operating system dynamically adjusts power settings of the vehicle to reduce power consumption of a battery powering the vehicle.
3. Determining the operational context includes: determining usage of the instance of the vehicle operating system by one or more occupants within the vehicle; determining the presence of the one or more occupants within the vehicle; determining weather conditions in which the vehicle is currently operating; determining an operational state of the vehicle; 3. The method of claim 1, comprising one or more of:
4. the instance of the vehicle operating system facilitating concurrent access by multiple user profiles; The method further includes presenting, by the instance of the vehicle operating system, a plurality of user interfaces across a plurality of displays communicatively coupled to the vehicle head unit, each of the plurality of user interfaces associated with one or more of the plurality of user profiles; 4. The method of claim 3, wherein entering the protected mode of operation includes disabling one or more of the plurality of displays based on one or more of the usage of the instance of the vehicle operating system, the presence of the one or more occupants of the vehicle, the weather conditions, and the operational state of the vehicle.
5. The method of claim 4 , wherein the one or more occupants of the vehicle are associated with at least one of the plurality of user profiles.
6. the instance of the vehicle operating system facilitating concurrent access by multiple user profiles; the operating conditions of the vehicle include battery life; The method further includes presenting, by the instance of the vehicle operating system, a plurality of user interfaces across a plurality of displays communicatively coupled to the vehicle head unit, each of the plurality of user interfaces associated with one or more of the plurality of user profiles; The method of any one of claims 3 to 5, wherein entering the protective operating mode includes disabling one or more of the plurality of displays based on the weather conditions and the battery life.
7. the instance of the vehicle operating system facilitating concurrent access by multiple user profiles; the operating conditions of the vehicle include battery life; The method further includes presenting, by the instance of the vehicle operating system, a plurality of user interfaces across a plurality of displays communicatively coupled to the vehicle head unit, each of the plurality of user interfaces associated with one or more of the plurality of user profiles; 7. The method of claim 3, wherein entering the protective operating mode includes entering an emergency mode in which one or more applications executed by the vehicle operating system run in a restricted access mode to preserve the battery life based on one or more of the weather conditions and the battery life.
8. determining the operational state of the vehicle includes determining an emergency state in which safety of the vehicle is compromised; The method further includes presenting, by the instance of the vehicle operating system, a plurality of user interfaces across a plurality of displays communicatively coupled to the vehicle head unit, each of the plurality of user interfaces being associated with one or more of a plurality of user profiles; 8. The method of claim 3, wherein entering the protected mode of operation includes enabling all of the plurality of displays based on the emergency condition to allow the plurality of user profiles to report the emergency condition of the vehicle.
9. determining the operational state of the vehicle includes determining an emergency state in which safety of the vehicle is compromised; The method of any one of claims 3 to 8, wherein entering the protective mode of operation includes disabling all audio playback by the vehicle head unit based on the emergency condition.
10. determining the operational state of the vehicle includes determining an emergency state in which safety of the vehicle is compromised; The method of any one of claims 3 to 9, wherein entering the protective mode of operation includes disabling all audio controls except for audio controls related to the emergency condition.
11. determining the operational state of the vehicle includes determining an emergency state in which safety of the vehicle is compromised; Entering the protected mode of operation includes: automatically communicating the status of the operator of the vehicle during the emergency condition; transferring audio control of the vehicle operating system to the one or more occupants based on the state of the operator of the vehicle; The method according to any one of claims 3 to 10, comprising:
12. 12. The method of claim 11, wherein transferring the audio control of the vehicle operating system enables the one or more occupants to initiate an emergency telephone call to emergency services.
13. the vehicle head unit is located within a center console of a front dashboard of the vehicle and includes a main display through which the operator of the vehicle interfaces with the vehicle head unit; determining the usage of the instance of the vehicle operating system includes determining whether the operator of the vehicle or the one or more occupants of the vehicle are using the main display of the vehicle head unit; 13. The method of claim 3, wherein entering the protected mode of operation includes, in response to determining that the one or more occupants of the vehicle are using the main display, disabling the protected mode of operation to allow the one or more occupants to interface with the vehicle operating system via the main display.
14. determining the operational context includes determining that the vehicle is entering a potentially unsafe operational context requiring further attention by the operator of the vehicle; 14. The method of claim 1, wherein entering the protected mode of operation comprises, in response to entering the potentially unsafe operating context, entering the protected mode of operation in which the vehicle operating system reduces a volume of audio playback by the vehicle head unit.
15. the instance of the vehicle operating system facilitating concurrent access by multiple user profiles; The method further comprises: authorizing, by the instance of the vehicle operating system, the plurality of user profiles to interface with the instance of the vehicle operating system; presenting, by the instance of the vehicle operating system, a plurality of user interfaces across a plurality of displays communicatively coupled to the vehicle head unit, each of the plurality of user interfaces associated with one or more of the plurality of user profiles, the method further comprising: and interfacing with a plurality of users associated with the one or more of the plurality of user profiles via the plurality of user interfaces to enable the plurality of users to interface with the instance of the vehicle operating system for the purpose of controlling functionality associated with the vehicle head unit.
16. a memory configured to store an instance of a vehicle operating system; one or more processors configured to execute the instance of the vehicle operating system; The instance of the vehicle operating system: determining an operational context in which the vehicle is currently operating; 11. A computing device configured to enter a protective operating mode in which the vehicle operating system dynamically adapts one or more operating characteristics of the vehicle operating system based on the operational context to promote safety of an operator of the vehicle.
17. 17. The computing device of claim 16, wherein the instance of the vehicle operating system is configured to enter the protected operating mode in which the vehicle operating system dynamically adjusts power settings of the vehicle to reduce power consumption of a battery powering the vehicle.
18. The instance of the vehicle operating system: determining usage of the instance of the vehicle operating system by one or more occupants within the vehicle; determining the presence of the one or more occupants within the vehicle; determining weather conditions in which the vehicle is currently operating; determining an operational state of the vehicle; 18. A computing device according to claim 16 or 17, configured to execute one or more of the following:
19. the instance of the vehicle operating system facilitating concurrent access by multiple user profiles; the instance of the vehicle operating system is further configured to present a plurality of user interfaces across a plurality of displays communicatively coupled to the computing device, each of the plurality of user interfaces being associated with one or more of the plurality of user profiles; 20. The computing device of claim 18, wherein the instance of the vehicle operating system is configured to disable one or more of the plurality of displays based on one or more of the usage of the instance of the vehicle operating system, the presence of the one or more occupants of the vehicle, the weather conditions, and the operational state of the vehicle.
20. 1. A non-transitory computer-readable storage medium having instructions stored thereon, comprising: The instructions, when executed, cause one or more processors to: running an instance of a vehicle operating system; causing the instance of the vehicle operating system to determine an operational context in which the vehicle is currently operating; A non-transitory computer-readable storage medium that causes the instance of the vehicle operating system, and based on the operational context, to enter a protected operating mode in which the vehicle operating system dynamically adapts one or more operational characteristics of the vehicle operating system to promote safety of an operator of the vehicle.
Citation Information
Patent Citations
Signal receiver
JP1994252862A
On-vehicle control device
JP2006347299A
Onboard device control apparatus
JP2009234466A
Travel controlling device and travel controlling method
JP2016196285A
Display system in a vehicle and a method for control thereof
US20200139812A1