A method for controlling access to a vehicle system, the system to implement, and the vehicle.

JP2026148465APending Publication Date: 2026-09-17TOYOTA JIDOSHA KK
View PDF 0 Cites 0 Cited by

Patent Information

Application Number
JP2026016714
Authority / Receiving Office
JP · JP
Patent Type
Applications
Current Assignee / Owner
Priority Date
2025-03-05
Filing Date
2026-02-04
Publication Date
2026-09-17

Smart Images

  • Figure 2026148465000001_ABST
    Figure 2026148465000001_ABST
Patent Text Reader

Abstract

To provide a method for controlling access to vehicle systems. [Solution] The method includes detecting the status of the vehicle operator using at least one sensor. The method further includes determining whether the vehicle operator is operating the vehicle actively in a normal manner. In response to the determination that the operator is operating the vehicle abnormally, the method further includes restricting access to the vehicle system for all software applications of the first type.
Need to check novelty before this filing date? Find Prior Art

Description

BACKGROUND ART

[0001] During operation of a vehicle, software applications running in the vehicle system access elements of the vehicle system using an application programming interface (API). The API enables the software applications to communicate with the vehicle system even in situations where the software applications are developed by third parties other than the vehicle manufacturer. In many cases, as a result of communication between the software applications and the vehicle system, the vehicle system collects and / or processes information based on instructions received from the software applications. This collection and / or processing consumes resources of the vehicle system. SUMMARY OF THE INVENTION

[0002] Aspects of the present description relate to a method for controlling access to a vehicle system. The method includes detecting a status of an operator of the vehicle using at least one sensor. The method further includes determining whether the operator of the vehicle is actively operating the vehicle in a normal manner. The method further includes, in response to determining that the operator is operating the vehicle in an abnormal manner, restricting access to the vehicle system for all software applications of a first type.

[0003] Aspects of this description relate to a system for controlling access to a vehicle system. The system includes a non-temporary computer-readable medium configured to store instructions. The system further includes a processor connected to the non-temporary computer-readable medium. The processor is configured to execute instructions relating to detecting the status of a vehicle operator using at least one sensor. The processor is configured to execute instructions relating to determining whether the vehicle operator is operating the vehicle actively in a normal manner. In response to the determination that the operator is operating the vehicle in an abnormal manner, the processor is configured to execute instructions relating to restricting access to the vehicle system for all software applications of a first type.

[0004] The aspects of this description relate to a vehicle. The vehicle includes at least one sensor mounted on the vehicle. The vehicle further includes a non-temporary computer-readable medium configured to store instructions. The vehicle further includes a processor connected to the non-temporary computer-readable medium and the at least one sensor. The processor is configured to execute instructions relating to detecting the status of the vehicle operator using the at least one sensor. The processor is configured to execute instructions relating to determining whether the vehicle operator is operating the vehicle actively in a normal manner. In response to the determination that the operator is operating the vehicle in an abnormal manner, the processor is configured to execute instructions relating to restricting access to the vehicle system for all software applications of a first type. [Brief explanation of the drawing]

[0005] The aspects of this disclosure will be best understood by reading the following detailed description together with the accompanying figures. Note that, in accordance with standard industry practice, various features are not depicted to scale. In fact, for clarity in the description, the dimensions of various features may be enlarged or reduced as appropriate.

[0006] [Figure 1]This is a perspective view of a vehicle including a vehicle system according to one embodiment. [Figure 2] This is a flowchart illustrating a method for controlling access to a vehicle system according to some embodiments. [Figure 3] This is a flowchart of the steps of a control method for a vehicle system according to some embodiments. [Figure 4] This is a block diagram of a system for controlling access to a vehicle system, according to one embodiment. [Modes for carrying out the invention]

[0007] The following disclosure provides numerous different embodiments or examples that implement different features of the subject matter provided. Specific examples of components, values, behaviors, materials, arrangements, or similars are described below to simplify the disclosure. Of course, these are merely examples and are not intended to limit the disclosure. Other components, values, behaviors, materials, arrangements, or similars are conceivable. For example, forming a first feature above or on top of a second feature in the following description may include embodiments in which the first and second features are formed in direct contact, or in which additional features may be formed between the first and second features such that the first and second features are not in direct contact. In addition, the disclosure may repeat reference numbers and / or reference letters in various examples. This repetition is for simplification and clarity and does not, in itself, define relationships between the various embodiments and / or configurations described.

[0008] Furthermore, spatially relative terms such as “downward,” “below,” “below,” “above,” “above,” and similar terms may be used herein to facilitate descriptions of the relationship between one element or feature and another, as shown in the figures. Spatially relative terms are intended to encompass different orientations of the device during use or operation, in addition to the orientation depicted in the figures. The device may also have other orientations (90-degree rotation or other orientations), and the spatially relative descriptions used herein may be interpreted accordingly.

[0009] While a vehicle is in operation, numerous software applications, also known as applications, are run by the vehicle system. The execution of these software applications includes the collection and processing of data by the vehicle system. Various types of software applications, including infotainment, communications, notifications, vehicle operation, or other preferred types, are run by the vehicle system. While software applications are running, the processing power of the vehicle system is consumed. While the vehicle is moving, the vehicle system's sharing of processing load with other systems, such as cloud-based systems, is reduced. Therefore, in some cases, the processing power of the vehicle system is limited to the hardware installed within the vehicle. In some cases, due to limited processing power, the execution of certain software applications takes priority. In some cases, processing prioritization gives a lower priority to vehicle operation applications, such as advanced driver-assistance systems (ADAS), than to other applications for short periods. During periods when the operator, also known as the driver, is actively controlling the vehicle, the lower priority for ADAS functions is compensated for by the operator's control. In contrast, in situations where the operator is not actively controlling the vehicle due to factors such as the operator's health or being asleep, a lower priority for ADAS functions increases the risk of vehicle collision.

[0010] To assist in situations where the operator is asleep, incapacitated, or physically disabled, this application provides a method and system for restricting the ability of software applications to access vehicle systems during such situations. The method includes monitoring the operator's condition and determining whether the operator is able to operate the vehicle normally. In response to the determination that the operator is unable to operate the vehicle normally, the method reduces the ability of certain types of software applications to access vehicle systems in order to maximize the amount of processing power available to ADAS functions to help reduce the risk of collisions by the vehicle. Access of software applications to vehicle systems can be controlled using an application programming interface (API) that the vehicle system can control to prevent applications from sending commands to the vehicle system during periods when the operator is unable to operate the vehicle normally.

[0011] In some embodiments, different types of software applications are denied access at different stages of the process. Denying access to different types of software applications at different stages of the process helps maintain passenger comfort in the vehicle for as long as possible while also effectively reducing the risk of vehicle collisions. For example, in some embodiments, communication applications are denied access to the vehicle system later than infotainment applications in the process. Controlling these different types of software applications in different ways can be achieved by having different APIs for different types of software applications and controlling various APIs individually.

[0012] In some embodiments, the method also includes the vehicle system using ADAS functions to stop the vehicle. In some embodiments, the method further includes the vehicle system using ADAS functions to steer the vehicle to a safe place such as the shoulder of the road. When the operator is unable to perform normal operations, during ADAS control of the vehicle, a greater amount of processing power of the vehicle system is available to the ADAS functions to help improve the precision of the ADAS functions that are controlling the movement of the vehicle, by restricting access to other types of software applications.

[0013] Figure 1 is a perspective view of a vehicle 100 according to some embodiments. The vehicle 100 can implement method 200 (Figure 2) or method 300 (Figure 3). In some embodiments, the vehicle 100 can implement method 200 (Figure 2) or method 300 (Figure 3) using a system 400 (Figure 4) mounted on the vehicle. In some embodiments, the vehicle 100 can implement method 200 (Figure 2) or method 300 (Figure 3) based on a command received from a system 400 (Figure 4) that is located away from or detachable from the vehicle 100. In some embodiments where the system 400 (Figure 4) is located away from or detachable from the vehicle 100, the vehicle 100 is configured to receive a command to implement method 200 (Figure 2) or method 300 (Figure 3) either wirelessly or via a wired connection.

[0014] The vehicle 100 includes an infotainment display 105. The vehicle further includes a light sensor 110. The vehicle further includes a touch sensor 115. The vehicle further includes an external sensor 120. The vehicle 100 further includes a vehicle system, for example, system 400 (Figure 4), configured to collect data from one or more of the light sensor 110, the touch sensor 115, or the external sensor 120. The vehicle system can further generate content for display on the infotainment display 105.

[0015] The infotainment display 105 is configured to display information that can be viewed by the occupants of the vehicle 100, including the operator of the vehicle 100. The content of the infotainment display 105 is controllable by the vehicle system. In some embodiments, the infotainment display 105 is controlled to display a notification to the vehicle operator in response to a determination that the vehicle is operating abnormally. In some embodiments, the infotainment display 105 can output audio and visual signals. In some embodiments, the infotainment display 105 is configured to display content from a software application run by the vehicle system. In some embodiments, the infotainment display 105 includes a touchscreen. In some embodiments, the infotainment display 105 is configured to receive voice input using a microphone, input from one or more buttons, or input from other suitable input devices.

[0016] The light sensor 110 is configured to detect at least a portion of the interior of the vehicle 100. The portion of the interior of the vehicle includes the driver's seat of the vehicle 100. The light sensor 110 is configured to capture information indicating the status of the vehicle operator. In some embodiments, the light sensor 110 includes a camera, an infrared (IR) detector, or other suitable photodetector. In some embodiments, the light sensor 110 is configured to capture information such as an image relating to one or more eyes of the vehicle operator. In some embodiments, the light sensor 110 is further configured to capture information relating to the environment outside the vehicle 100. In some embodiments, information relating to the environment outside the vehicle 100 includes the relative location of lane markers, road signs, side walls, traffic lights, other vehicles, or other suitable external elements. In some embodiments, multiple light sensors 110 are mounted on the vehicle.

[0017] The touch sensor 115 is configured to determine whether an operator of the vehicle 100 is in contact with the steering wheel of the vehicle 100. In some embodiments, the touch sensor 115 includes a capacitive touch sensor or other suitable touch sensor. In some embodiments, multiple touch sensors 115 are mounted on the steering wheel.

[0018] External sensor 115 is configured to detect at least a portion of the external environment of vehicle 100. External sensor 120 is configured to capture information indicating the relative position between the vehicle and objects in the external environment of the vehicle. In some embodiments, external sensor 120 includes a camera, an IR detector, a light detection and ranging (LIDAR) detector, or other suitable detector. In some embodiments, information related to the external environment of vehicle 100 includes the relative location of lane markers, road signs, side walls, traffic lights, other vehicles, or other suitable external elements. In some embodiments, multiple external sensors 120 are mounted on the vehicle.

[0019] Vehicle 100 further includes an ADAS system controllable by a vehicle system, for example, system 400 (Figure 4). In some embodiments, the ADAS system includes functions such as adaptive cruise control (ACC), lane tracing assist (LTA), lane change assist (LCA), highway navigation pilot (HNP), city navigation pilot (UNP), or other preferred ADAS functions. Those skilled in the art will understand that one or more of the ADAS functions include the ability to control the speed and steering of vehicle 100. In some embodiments, the ADAS system can perform controls ranging from ADAS level 1 to ADAS level 5.

[0020] A vehicle system, for example, system 400 (Figure 4), is configured to receive information from various sensors in vehicle 100 in order to implement method 200 (Figure 2) or method 300 (Figure 3). The vehicle system is configured to use this information to control access to the processing capabilities of the vehicle system. The vehicle system is further configured to control the ADAS functions of vehicle 100 based on a determined situation regarding the operator of vehicle 100.

[0021] Those skilled in the art will understand that vehicles of different sizes with different controls and functions are within the scope of this description. For example, in some embodiments, vehicle 100 may not include an infotainment display 105, or vehicle 100 may include a head-up display (HUD).

[0022] Figure 2 is a flowchart of method 200 for controlling access to a vehicle system, according to some embodiments. In some embodiments, method 200 is implemented to control access to a vehicle system of vehicle 100 (Figure 1). In some embodiments, method 200 is implemented to control access to a vehicle system other than vehicle 100 (Figure 1). In some embodiments, method 200 is implemented by the vehicle system of vehicle 100 (Figure 1). In some embodiments, method 200 is implemented by a system located away from vehicle 100 (Figure 1), and commands are sent to the vehicle system of vehicle 100 based on the execution of method 200. In some embodiments, method 200 is implemented in relation to method 300 (Figure 3).

[0023] In act 205, the vehicle operator is monitored. In some embodiments, the operator is monitored based on a visually captured image of the operator, such as by optical sensor 110 (FIG. 1). In some embodiments, the operator is monitored based on whether the operator is in contact with the vehicle steering wheel, such as by touch sensor 115 (FIG. 1). In some embodiments, the operator is monitored based on information indicative of movement of the vehicle relative to objects in the environment outside the vehicle, such as by optical sensor 110 (FIG. 1) and / or external sensor 120 (FIG. 1). In some embodiments, the operator is monitored using a combination of a visual image of the operator, contact with the steering wheel, information indicative of vehicle movement relative to an object, or other suitable parameters.

[0024] A system such as a vehicle system of vehicle 100 (FIG. 1) or a remote system, for example, system 400 (FIG. 4), receives information used to monitor the operator. The system analyzes the received information to determine the operator's condition. In some embodiments, the system determines whether the operator's eyes are closed for a period longer than a threshold period, that is, determines whether the operator is asleep. In some embodiments, the system determines whether the operator has not been in contact with the vehicle steering wheel for a period longer than a threshold touch period, that is, determines whether the operator is actively involved in the operation of the vehicle. In some embodiments, the system determines whether relative movement between the vehicle and an object in the environment external to the vehicle exceeds a predetermined tolerance range for a period longer than a threshold movement period. In some embodiments, the magnitude of the threshold movement period is adjusted based on the speed of the vehicle. That is, as the speed of the vehicle increases, the magnitude of the threshold movement period decreases. Monitoring relative movement between the vehicle and an object external to the vehicle can be used to determine whether the vehicle is moving irregularly, indicating an absence of active operation of the vehicle by the operator.

[0025] In operation 210, a decision is made regarding whether the vehicle is operating normally. The decision is made based on a comparison of the received information with one or more thresholds to determine whether the operator is actively operating the vehicle. If the decision is that the vehicle is operating normally, method 200 returns to operation 205. If the decision is that the vehicle is operating abnormally, method 200 proceeds to operation 215.

[0026] In operation 215, an alert is generated to notify the operator of abnormal vehicle behavior. In some embodiments, the alert includes a display in the vehicle, such as on an infotainment display 105 (Figure 1). In some embodiments, the alert includes an audible alert, such as an output from a speaker in the vehicle. In some embodiments, the alert includes a tactile alert at the operator's seat, steering wheel, or another preferred location in the vehicle. In some embodiments, the alert includes transmitting a signal to a mobile device accessible by the operator to cause the mobile device to generate a visual and / or audible notification. In some embodiments, the alert includes a combination of the above notification options or other preferred alerts.

[0027] In operation 220, access to the vehicle systems of a vehicle is restricted for a first type of API. That is, APIs that can be used to enable software applications of a first type to access vehicle systems are controlled to prevent the software applications of the first type from accessing the vehicle systems. In some embodiments, the input-output (IO) ports of the first type of API are disabled by the vehicle systems. In some embodiments, the first type of software application includes infotainment applications such as movies, music, games, or other types of infotainment. In some embodiments, the first type of software application includes navigation applications. In some embodiments, the first type of software application includes all software applications other than communication, operator detection, vehicle performance detection, ADAS, and notification applications. In some cases, maintaining the ability of vehicle occupants to communicate using the vehicle systems allows an operator of the vehicle or another occupant to communicate with a third party such as an emergency service to convey information regarding the vehicle situation or the operator's situation.

[0028] Restriction of access by the first type of software application helps avoid consumption of processing capacity of the vehicle systems by software applications that are primarily used for entertainment or recreation of vehicle occupants. This enables the vehicle systems to allocate a larger portion of processing capacity to software applications related to vehicle control and communication between the vehicle systems and selected permanent entities such as emergency services.

[0029] In operation 225, a decision is made regarding whether the vehicle is operating normally. In some embodiments, operation 225 is performed after a notification period following operation 215 to include the operator's reaction time after the notification as a factor. In some embodiments, the length of the notification period decreases as the vehicle's speed increases. In some embodiments, the notification period ranges from about 3 seconds to about 10 seconds. The decision is made based on a comparison of the received information with one or more thresholds to determine whether the operator is actively operating the vehicle. In response to a decision that the vehicle is operating normally, method 200 proceeds to operation 230, and then to operation 205. In response to a decision that the vehicle is operating abnormally, method 200 proceeds to operation 235.

[0030] In operation 230, the restrictions that limit access to the vehicle system using the first type API are removed. That is, access to the vehicle system is restored to a normal operating state for the vehicle. In some embodiments, a signal is sent to the I / O portion of the first type API to enable communication between the vehicle system and the first type application. After operation 230, method 200 returns to operation 205, and operator monitoring continues.

[0031] In action 235, the vehicle system accesses ADAS functions to initiate vehicle deceleration. Vehicle deceleration helps increase the time the vehicle has to travel to the location where a collision will occur. Vehicle deceleration also reduces the change in momentum for the vehicle's occupants in the event of a collision.

[0032] In operation 240, the vehicle's access to the vehicle system is restricted to second-type APIs. That is, APIs that could be used to enable second-type software applications to access the vehicle system are controlled to prevent second-type software applications from accessing the vehicle system. In some embodiments, the I / O ports of second-type APIs are disabled by the vehicle system. In some embodiments, second-type software applications include communication, operator detection, or notification applications. In some embodiments, second-type software applications include all software applications except vehicle performance detection and ADAS applications.

[0033] Following operation 240, access to both Type 1 and Type 2 software applications is restricted. Restricting access to Type 2 software applications helps prevent the consumption of processing power by software applications not used to control vehicle operation. This allows the vehicle system to allocate more of its processing power to software applications related to vehicle control, such as using ADAS systems to reduce the risk of collisions.

[0034] In operation 250, a decision is made regarding whether the vehicle is operating normally. In some embodiments, operation 250 is performed after the deceleration period following operation 235 to include the operator's reaction time after the start of deceleration as a factor. In some embodiments, the length of the deceleration period decreases as the vehicle's speed increases. In some embodiments, the notification period ranges from about 1 second to about 3 seconds. The decision is made based on a comparison of the received information with one or more thresholds received before the completion of operation 240 to determine whether the operator is actively operating the vehicle. In response to a decision that the vehicle is operating normally, method 200 proceeds to operation 230, and then to operation 205. In response to a decision that the vehicle is operating abnormally, method 200 proceeds to operation 255.

[0035] In operation 255, the vehicle system uses ADAS functions to bring the vehicle to a stop. In some embodiments, the vehicle system further uses ADAS functions to steer the vehicle to a location with a low probability of collision, such as the shoulder, the lane closest to the side of the road, or another suitable location.

[0036] In operation 260, a decision is made regarding whether the vehicle is stopped. The decision is based on vehicle performance information indicating that the vehicle's speed is zero. If the decision is that the vehicle is not stopped, method 200 continues to perform operation 260 until the vehicle is stopped. If the decision is that the vehicle is stopped, method 200 proceeds to operation 265.

[0037] In operation 265, the vehicle is held in the position where the vehicle stopped. In some embodiments, the vehicle is held in the position where the vehicle stopped by the vehicle system putting the vehicle transmission into parking. In some embodiments, the vehicle is held in the position where the vehicle stopped by the vehicle system engaging the vehicle's parking brake or another brake. In some embodiments, the vehicle system maintains the vehicle in the held position until a preset action of the vehicle is performed by the vehicle occupant, such as interaction with the brake pedal, interaction with the infotainment display, or other preferred action detected by the vehicle system.

[0038] In operation 270, any restrictions that limit access to the vehicle system using the second type of API are removed. In some embodiments, restrictions that limit access to the vehicle system using the first type of API are also removed by operation 270. In some embodiments, signals are sent to the second type of API, optionally to the I / O portion of the first type of API, to enable communication between the vehicle system and a software application. The removal of restrictions in operation 270 restores the ability of the vehicle operator and other occupants to communicate with third parties, such as emergency services, regarding the status of the vehicle or the operator.

[0039] In operation 275, additional alerts are provided to the operator and / or third parties. In some embodiments, the alert to the operator is implemented using one or more of the alert options described above with respect to operation 215. In some embodiments, the alert to the operator uses the same process as the alert in operation 215. In some embodiments, the alert to the operator uses a different process than the alert in operation 215. In some embodiments, the content of the alert in operation 215 is different from the content of the alert in operation 240. In some embodiments, the alert in operation 240 also includes an alert to a third party. In some embodiments, the third party includes an emergency service, a designated contact point predetermined by the operator, or another preferred third party. In some embodiments, operation 275 is omitted.

[0040] In some embodiments, the normal operation of the vehicle is restored in response to the detection of a suitable operation by the vehicle system for moving the vehicle from a holding position.

[0041] Those skilled in the art will understand that modifications to Method 200 are within the scope of this description. In some embodiments, Method 200 includes at least one additional action. For example, in some embodiments, Method 200 further includes the activation of a vehicle safety feature, such as the vehicle's hazard lights or horn, during action 255. In some embodiments, at least one of the actions of Method 200 is omitted. For example, in some embodiments, action 275 is omitted. In some embodiments, the order of the actions of Method 200 is changed. For example, in some embodiments, action 250 is performed before action 240.

[0042] Figure 3 is a flowchart of the steps of method 300 for controlling a vehicle system, according to some embodiments. In some embodiments, method 300 is implemented to control access to a vehicle system of vehicle 100 (Figure 1). In some embodiments, method 300 is implemented to control access to a vehicle system other than vehicle 100 (Figure 1). In some embodiments, method 300 is implemented by the vehicle system of vehicle 100 (Figure 1). In some embodiments, method 300 is implemented by a system located away from vehicle 100 (Figure 1), and commands are sent to the vehicle system of vehicle 100 based on the execution of method 300. In some embodiments, method 300 is implemented in relation to method 200 (Figure 2).

[0043] In operation 305, the vehicle operates under normal driving conditions. Normal driving conditions are implemented based on the decision that the operator is actively involved in the vehicle's operation. Under normal driving conditions, all authorized software applications can access the vehicle system using the corresponding APIs. Examples of operation in method 200 (Figure 2) that occur during normal driving conditions include operations 205, 210, and 215 (Figure 2).

[0044] In operation 310, the vehicle operates in a warning level 1 situation. A warning level 1 situation is implemented in response to a decision that the operator is no longer actively involved in the operation of the vehicle for a first period. In a warning level 1 situation, access to the vehicle system is restricted for a first type of software application to avoid the consumption of the vehicle system's processing power by software applications primarily used for the entertainment or customs of the vehicle occupants. This allows the vehicle system to allocate more of its processing power to software applications related to vehicle control and communication between the vehicle system and selected permanent entities such as emergency services. Examples of operation of method 200 (Figure 2) that occur during a warning level 1 situation include operations 220 and 225 (Figure 2).

[0045] In operation 315, the vehicle operates in a warning level 2 situation. A warning level 2 situation is implemented in response to a decision that the operator has ceased to be actively involved in the vehicle's operation for a second period longer than a first period. In a warning level 2 situation, access to both first and second type software applications is restricted. Restricting access to second type software applications helps to avoid the consumption of processing power of the vehicle system by software applications not used to control the vehicle's operation. This allows the vehicle system to allocate more of its processing power to software applications related to vehicle control in order to reduce the risk of collisions using the ADAS system. Examples of operation in method 200 (Figure 2) that occur during a warning level 2 situation include operations 235, 240, and 250 (Figure 2).

[0046] In operation 320, the vehicle operates in a stopped / decelerating state. The stopped / decelerating state is implemented in response to a decision that the operator is no longer actively involved in the vehicle's operation for a third period longer than the second period. In the stopped / decelerating state, only applications targeting vehicle control and vehicle performance detection are permitted to access the vehicle system. Restricting access to the vehicle system to only software applications that control the vehicle and monitor its performance helps maximize the processing power available to control the vehicle to reduce the risk of collisions. Examples of operation in method 200 (Figure 2) that occur during normal driving conditions include operations 255 and 260 (Figure 2).

[0047] In operation 325, the vehicle operates in a vehicle-holding state. The vehicle-holding state is implemented in response to the vehicle stopping after operation 320. In the vehicle-holding state, the vehicle is kept in a stopped state, and access to the vehicle systems is restored for all authorized software applications. Examples of operation of method 200 (Figure 2) that occur during normal driving conditions include operations 265, 270, and 275 (Figure 2).

[0048] Figure 4 is a block diagram of a system 400 that controls access to a vehicle system according to one or more embodiments. The system 400 includes a hardware processor 402 and a non-temporary computer-readable storage medium 404 that stores computer program code 406, i.e., a set of executable instructions encoded in the computer program code 406. The computer-readable storage medium 404 is also encoded in instructions 407 that interface with a manufacturing machine to generate a memory array. The processor 402 is electrically connected to the computer-readable storage medium 404 via a bus 408. The processor 402 is also electrically connected to an input / output (I / O) interface 410 via the bus 408. A network interface 412 is also electrically connected to the processor 402 via the bus 408. The network interface 412 is connected to a network 414, and as a result, the processor 402 and the computer-readable storage medium 404 can connect to external elements via the network 414. The processor 402 is configured to execute computer program code 406 encoded in a computer-readable storage medium 404 in order to enable the system 400 to perform some or all of the operations described in Method 200 (Figure 2), Method 300 (Figure 3), or implemented by the vehicle 100 (Figure 1).

[0049] In some embodiments, the processor 402 is a central processing unit (CPU), a multiprocessor, a distributed processing system, an application-specific integrated circuit (ASIC), and / or a suitable processing unit.

[0050] In some embodiments, the computer-readable storage medium 404 is an electronic, magnetic, optical, electromagnetic, infrared, and / or semiconductor system (or apparatus or device). For example, the computer-readable storage medium 504 includes semiconductor or solid-state memory, magnetic tape, removable computer diskette, random access memory (RAM), read-only memory (ROM), rigid magnetic disk, and / or optical disk. In some embodiments using optical disks, the computer-readable storage medium 504 includes compact disk read-only memory (CD-ROM), compact disk read / write (CD-R / W), and / or digital video disc (DVD).

[0051] In some embodiments, the storage medium 404 stores computer program code 404 configured to cause the system 400 to perform some or all of the operations described in Method 200 (Figure 2), Method 300 (Figure 3), or implemented by the vehicle 100 (Figure 1). In some embodiments, the storage medium 404 also stores information used to perform some or all of the operations described in Method 200 (Figure 2), Method 300 (Figure 3), or implemented by the vehicle 100 (Figure 1), and information generated while performing some or all of the operations described in Method 200 (Figure 2), Method 300 (Figure 3), or implemented by the vehicle 100 (Figure 1), such as operator status data parameter 416, first type API parameter 418, second type API parameter 420, alert option parameter 422, and / or a set of executable instructions to perform some or all of the operations described in Method 200 (Figure 2), Method 300 (Figure 3), or implemented by the vehicle 100 (Figure 1).

[0052] In some embodiments, the storage medium 404 stores instructions 407 that interface with an external device, such as a mobile device. The instructions 407 enable the processor 402 to generate or receive instructions that are readable by the external device during the implementation of some or all of the operations, such as those described in Method 200 (Figure 2), Method 300 (Figure 3), or those implemented by the vehicle 100 (Figure 1).

[0053] The system 400 includes an I / O interface 410, which is connected to external circuitry. In some embodiments, the I / O interface 410 includes a keyboard, keypad, mouse, trackball, trackpad, touchscreen, and / or cursor directional keys for communicating information and commands to the processor 402.

[0054] System 400 also includes a network interface 412 connected to processor 402. The network interface 412 allows system 400 to communicate with a network 414 to which one or more other computer systems are connected. The network interface 412 includes wireless network interfaces such as BLUETOOTH®, WIFI, WiMAX, GPRS, or WCDMA®, or wired network interfaces such as ETHERNET, USB, or IEEE-1394. In some embodiments, some or all of the operations described in Method 200 (Figure 2), Method 300 (Figure 3), or implemented by vehicle 100 (Figure 1) are implemented in two or more systems 400, and information such as operator status, a first type of API, a second type of API, or alert options is exchanged between different systems 400 via the network 414.

[0055] Note 1

[0056] Aspects of this description relate to a method for controlling access to a vehicle system. The method includes detecting the status of a vehicle operator using at least one sensor. The method further includes determining whether the vehicle operator is operating the vehicle actively in a normal manner. In response to the determination that the operator is operating the vehicle abnormally, the method further includes restricting access to the vehicle system for all software applications of a first type.

[0057] Note 2

[0058] The method described in Appendix 1, further comprising sending an alert in response to a determination that the operator is operating the vehicle in an abnormal manner.

[0059] Note 3

[0060] The method according to Appendix 1 or 2, further comprising determining whether the vehicle operator is operating the vehicle in a normal manner after sending an alert.

[0061] Note 4

[0062] The method according to any one of the appendices 1 to 3, further comprising using the vehicle system to control an advanced driver-assistance system (ADAS) to decelerate the vehicle in response to a determination that, after sending an alert, the operator is continuing to operate the vehicle in an abnormal manner.

[0063] Note 5

[0064] The method according to any of the appendices 1 to 4, further comprising, after sending an alert, restricting access to the vehicle system for all software applications of the second type, in response to a determination that the operator is operating the vehicle in an abnormal manner.

[0065] Note 6

[0066] The method according to any one of the appendices 1 to 5, further comprising determining whether the vehicle operator is operating the vehicle in a normal manner after controlling the ADAS to decelerate the vehicle.

[0067] Note 7

[0068] The method according to any one of the appendices 1 to 6, further comprising using the vehicle system to control the ADAS to stop the vehicle in response to a decision that the operator is continuing to operate the vehicle in an abnormal manner, after having controlled the ADAS to slow down the vehicle.

[0069] Note 8

[0070] Aspects of this description relate to a system for controlling access to a vehicle system. The system includes a non-temporary computer-readable medium configured to store instructions. The system further includes a processor connected to the non-temporary computer-readable medium. The processor is configured to execute instructions relating to detecting the status of a vehicle operator using at least one sensor. The processor is configured to execute instructions relating to determining whether the vehicle operator is operating the vehicle actively in a normal manner. In response to the determination that the operator is operating the vehicle in an abnormal manner, the processor is configured to execute instructions relating to restricting access to the vehicle system for all software applications of a first type.

[0071] Note 9

[0072] The system as described in Appendix 8, further configured to execute commands relating to sending an alert in response to a determination that the operator is operating the vehicle in an abnormal manner.

[0073] Note 10

[0074] The system as described in Appendix 8 or 9, wherein the processor is further configured to execute instructions relating to determining whether the vehicle operator is operating the vehicle actively in a normal manner after sending an alert.

[0075] Note 11

[0076] The system as described in any of Annexes 8 to 10, wherein the processor is further configured to execute commands to use the vehicle system to control the advanced driver assistance system (ADAS) to decelerate the vehicle in response to a determination that, after sending an alert, the operator is continuing to operate the vehicle in an abnormal manner.

[0077] Note 12

[0078] The system as described in any of Annexes 8 to 11, wherein the processor is further configured to execute instructions to restrict access to the vehicle system for all second-type software applications, in response to a determination that, after sending an alert, the operator is operating the vehicle in an abnormal manner.

[0079] Note 13

[0080] The system as described in any of Annexes 8 to 12, wherein the processor is further configured to execute instructions relating to determining whether the vehicle operator is operating the vehicle actively in a normal manner after controlling the ADAS to decelerate the vehicle.

[0081] Note 14

[0082] The system as described in any of Annexes 8 to 13, wherein the processor is further configured to execute commands to use the vehicle system to control the ADAS to stop the vehicle, in response to a decision that the operator is continuing to operate the vehicle in an abnormal manner, after having controlled the ADAS to slow down the vehicle.

[0083] Note 15

[0084] The aspects of this description relate to a vehicle. The vehicle includes at least one sensor mounted on the vehicle. The vehicle further includes a non-temporary computer-readable medium configured to store instructions. The vehicle further includes a processor connected to the non-temporary computer-readable medium and the at least one sensor. The processor is configured to execute instructions relating to detecting the status of the vehicle operator using the at least one sensor. The processor is configured to execute instructions relating to determining whether the vehicle operator is operating the vehicle actively in a normal manner. In response to the determination that the operator is operating the vehicle in an abnormal manner, the processor is configured to execute instructions relating to restricting access to the vehicle system for all software applications of a first type.

[0085] Note 16

[0086] The vehicle as described in Appendix 15, further configured to execute commands relating to sending an alert in response to a determination that the operator is operating the vehicle in an abnormal manner.

[0087] Note 17

[0088] The vehicle according to Appendix 15 or 16, wherein the processor is further configured to execute instructions relating to determining whether the vehicle operator is operating the vehicle in a normal manner after sending an alert.

[0089] Note 18

[0090] The processor is further configured to execute commands to use the vehicle system to control the advanced driver assistance system (ADAS) to decelerate the vehicle, in response to a determination that the operator is continuing to operate the vehicle in an abnormal manner, as described in any of the appendices 15 to 17. The processor is further configured to execute commands to restrict access to the vehicle system for all software applications of the second type, in response to a determination that the operator is operating the vehicle in an abnormal manner, as described in any of the appendices 15 to 17.

[0091] Note 19

[0092] The vehicle described in any of Appendix 15-18, wherein the processor is further configured to execute instructions relating to determining whether the vehicle operator is operating the vehicle actively in a normal manner after controlling the ADAS to decelerate the vehicle.

[0093] Note 20

[0094] The vehicle as described in any of Appendix 15-19, wherein the processor is further configured to execute commands to use the vehicle system to control the ADAS to stop the vehicle, after having controlled the ADAS to decelerate the vehicle, in response to a determination that the operator is continuing to operate the vehicle in an abnormal manner.

[0095] The foregoing outlines some features of embodiments so that those skilled in the art may better understand aspects of this disclosure. Those skilled in the art should understand that they may readily use this disclosure as a basis for designing or modifying other processes and structures to perform the same purposes and / or achieve the same advantages as the embodiments incorporated herein. Those skilled in the art should also understand that such equivalent structures do not depart from the spirit and scope of this disclosure, and that they may make various changes, substitutions, and modifications of this specification without departing from the spirit and scope of this disclosure.

Claims

1. A method performed by a processor for controlling access to a vehicle system, the method being: The system will use at least one sensor to detect the status of the vehicle operator, To determine whether the operator of the vehicle is operating the vehicle in a normal manner, In response to the determination that the operator is operating the vehicle in an abnormal manner, access to the vehicle system for all software applications of the first type is restricted. Methods that include...

2. The method according to claim 1, further comprising sending an alert in response to the determination that the operator is operating the vehicle in the abnormal manner.

3. The method according to claim 2, further comprising determining whether the operator of the vehicle is operating the vehicle in the normal manner after sending the alert.

4. The method according to claim 3, further comprising using the vehicle system to control an advanced driver assistance system (ADAS) to decelerate the vehicle in response to a determination that, after sending the alert, the operator is continuing to operate the vehicle in the abnormal manner.

5. The method according to claim 3, further comprising, after sending the alert, restricting access to the vehicle system for all software applications of the second type in response to a determination that the operator is operating the vehicle in the abnormal manner.

6. The method according to claim 4, further comprising controlling the ADAS to decelerate the vehicle, and then determining whether the operator of the vehicle is actively operating the vehicle in the normal manner.

7. The method according to claim 6, further comprising controlling the ADAS to slow down the vehicle, and then using the vehicle system to control the ADAS to stop the vehicle in response to a determination that the operator is continuing to operate the vehicle in the abnormal manner.

8. A system for controlling access to a vehicle system, wherein the system is A non-temporary computer-readable medium configured to store instructions, A processor connected to the aforementioned non-temporary computer-readable medium, The processor is equipped with, The system will use at least one sensor to detect the status of the vehicle operator, To determine whether the operator of the vehicle is operating the vehicle in a normal manner, In response to the determination that the operator is operating the vehicle in an abnormal manner, access to the vehicle system for all software applications of the first type is restricted. A system configured to execute the aforementioned instructions relating to the above.

9. The system according to claim 8, wherein the processor is further configured to execute the command relating to sending an alert in response to the determination that the operator is operating the vehicle in the abnormal manner.

10. The system according to claim 9, wherein the processor is further configured to execute the instructions relating to determining whether the operator of the vehicle is operating the vehicle actively in the normal manner after sending the alert.

11. The system according to claim 10, wherein the processor is further configured to execute the command relating to controlling the advanced driver assistance system (ADAS) using the vehicle system to decelerate the vehicle in response to a determination that the operator is continuing to operate the vehicle in the abnormal manner after sending the alert.

12. The system according to claim 10, wherein the processor is further configured to execute the instruction relating to restricting access to the vehicle system for all second types of software applications in response to a determination that the operator is operating the vehicle in an abnormal manner after sending the alert.

13. The system according to claim 11, wherein the processor is further configured to execute the instructions relating to determining whether the operator of the vehicle is actively operating the vehicle in the normal manner, after controlling the ADAS to decelerate the vehicle.

14. The system according to claim 13, wherein the processor is further configured to control the ADAS to slow down the vehicle, and then, in response to a determination that the operator is continuing to operate the vehicle in the abnormal manner, execute the command relating to controlling the ADAS using the vehicle system to stop the vehicle.

15. A vehicle, and the said vehicle is At least one sensor attached to the vehicle, A non-temporary computer-readable medium configured to store instructions, The non-temporary computer-readable medium and the processor connected to the at least one sensor, The processor is equipped with, The system detects the status of the vehicle operator using information from at least one of the sensors, To determine whether the operator of the vehicle is operating the vehicle in a normal manner, In response to the determination that the operator is operating the vehicle in an abnormal manner, access to the vehicle system for all software applications of the first type is restricted. A vehicle configured to carry out the aforementioned instructions relating to the above.

16. The vehicle according to claim 15, wherein the processor is further configured to execute the command relating to sending an alert in response to the determination that the operator is operating the vehicle in the abnormal manner.

17. The vehicle according to claim 16, wherein the processor is further configured to execute the instructions relating to determining whether the operator of the vehicle is operating the vehicle actively in the normal manner after sending the alert.

18. The aforementioned processor further, After sending the alert, in response to the determination that the operator is continuing to operate the vehicle in the abnormal manner, the vehicle system is used to control the advanced driver assistance system (ADAS) to decelerate the vehicle. After sending the alert, in response to the determination that the operator is operating the vehicle in the abnormal manner, access to the vehicle system for all software applications of the second type is restricted. The vehicle according to claim 17, configured to perform the aforementioned instructions relating to the vehicle.

19. The vehicle according to claim 18, wherein the processor is further configured to execute the instructions relating to determining whether the operator of the vehicle is actively operating the vehicle in the normal manner, after controlling the ADAS to decelerate the vehicle.

20. The vehicle according to claim 19, wherein the processor is further configured to control the ADAS to decelerate the vehicle, and then, in response to a determination that the operator is continuing to operate the vehicle in the abnormal manner, execute the command relating to controlling the ADAS using the vehicle system to stop the vehicle.