Layered fail-safe redundancy architecture and process for use with single data bus mobile devices

JP2026529514APending Publication Date: 2026-09-01トマホーク ロボティクス インコーポレイテッド
View PDF 0 Cites 0 Cited by

Patent Information

Application Number
JP2026502290
Authority / Receiving Office
JP · JP
Patent Type
Applications
Current Assignee / Owner
Priority Date
2023-07-17
Filing Date
2024-07-15
Publication Date
2026-09-01

AI Technical Summary

Benefits of technology

【0015】 システムの様々な他の態様、特徴、および利点は、詳細な説明および添付の図面を通して明らかになるであろう。前述の一般的な説明および以下の詳細な説明の両方は例であり、本開示の範囲を限定するものではないことも理解されたい。本明細書および特許請求の範囲において使用される場合、単数形の「a」、「an」、および「the」は、文脈が他に明確に指示しない限り、複数の指示対象を含む。加えて、本明細書および特許請求の範囲において使用される場合、「または」という用語は、文脈が他に明確に指示しない限り、「および/または」を意味する。さらに、本明細書において使用される場合、「一部分」は、文脈が他に明確に指示しない限り、所与の項目(例えば、データ)の一部または全体(すなわち、部分全体)を指す。

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure 2026529514000001_ABST
    Figure 2026529514000001_ABST
Patent Text Reader

Abstract

This specification describes methods and systems for layered fail-safe redundant systems and architectures for privileged operation execution. The system may receive vehicle operation commands from a controller via a first channel. Upon receiving user input to initiate a privileged mode for executing privileged commands, the system may receive privileged commands via a second channel. Based on the privileged operation mode and privileged commands, the system may identify the privileged operation to be performed by the vehicle. The system may then send a request to the vehicle to perform the privileged operation.
Need to check novelty before this filing date? Find Prior Art

Description

Technical Field

[0001] CROSS-REFERENCE TO RELATED APPLICATIONS This application claims the benefit of priority in the United States of U.S. Patent Application No. 18 / 353,866 filed on July 17, 2023. The contents of the aforementioned application are incorporated herein by reference in their entirety.

Background Art

[0002] Background Stable and highly reliable robotic systems are becoming increasingly common. This has contributed to the recent advancement and popularization of unmanned system technology including ground-based systems, air-based systems, and / or sea-based systems. Various control methods are available for controlling unmanned systems, which are sometimes referred to as unmanned vehicles. Some unmanned vehicles allow users to execute privileged commands (e.g., weapon-related commands). While privileged commands are required in certain situations, it is important to prevent these commands from being inadvertently executed (e.g., due to operator error or software error).

Summary of Invention

Means for Solving the Problems

[0003] Summary Accordingly, this specification describes methods and systems for layered fail-safe redundancy systems and architectures for privileged operation execution. A command execution system may be used to perform the operations described herein. The command execution system may reside on a mobile device that can be connected to a vehicle controller via a physical connection, such as a Universal Serial Bus (USB) connection. The physical connection may have multiple channels. For example, a USB connection may be made possible by connecting via different interfaces corresponding to different channels. This architecture allows privileged commands (e.g., weapon-related commands, destruction commands, payload release commands, etc.) to be initiated via one channel and completed via another channel, thereby preventing inadvertent execution, whether due to operator error or software error.

[0004] In some embodiments, the command execution system may receive commands from a vehicle controller, process those commands (e.g., convert them into commands that the vehicle can execute), and transmit those commands to the vehicle (e.g., via a radio signal or another suitable signal). For example, the command execution system may receive vehicle control commands from the vehicle controller via a first channel. As described above, the command execution system may reside on a mobile device connected to the vehicle controller via a physical connection having a first channel and a second channel. That is, normal vehicle operation / control commands may be received via the first channel (e.g., using the first interface). The command execution system may transmit vehicle control commands to the vehicle (e.g., an unmanned vehicle) for execution. For example, the command execution system may receive a command from the vehicle controller to steer an aircraft forward. The command execution system may convert the command into a specific propeller operation and transmit the command to the vehicle (e.g., via a radio broadcast, cellular connection, or another suitable connection).

[0005] The command execution system may continue processing vehicle control commands until a privileged action is required. Therefore, the command execution system may receive a first privileged command using an input mechanism associated with a mobile device. For example, the first privileged command may be the operator dragging a slider on a mobile device (e.g., a touchscreen displaying an interactive slider image). In another example, the first privileged command may be a specific gesture or combination of touches on a touchscreen.

[0006] In some embodiments, the command execution system may determine that a first privileged command (e.g., a first weapon-related command) corresponds to a first input in an input sequence for executing a privileged operation (e.g., a weapon-related operation). For example, a slider may be the first input in a sequence required to initiate a launch command from an unmanned vehicle. The sequence may be indicated by a slider (or another suitable input on a mobile device) combined with an input from a vehicle controller. In another example, the privileged command may be a command to release a payload (e.g., held using magnetic force). The payload may be a heavy object that could be dangerous to people and objects. Therefore, releasing the payload may be a privileged operation.

[0007] The command execution system may then initiate / enable a privileged operation mode. In some embodiments, the command execution system may initiate a privileged operation mode based on receiving a first privileged command, such that the privileged operation mode enables a privileged operation using the vehicle controller. For example, the privileged operation mode may enable a weapons-related command to fire a weapon mounted on the vehicle. In another example, the privileged operation mode may enable a destructive command, or another type of command that requires a robust failsafe mechanism.

[0008] In some embodiments, the command execution system may enable a privileged operation mode by initializing monitoring of a second channel so that the remainder of the sequence required to initiate a firing command can be received through that second channel. For example, the command execution system may monitor the second channel for a second privileged command (e.g., a second weapon-related command) from the vehicle controller based on determining that a first privileged command (e.g., a first weapon-related command) corresponds to a first input in the input sequence for executing a privileged operation (e.g., a weapon-related operation). Thus, the command execution system may monitor the second channel for inputs or combinations of inputs from the vehicle controller that command the vehicle to fire an onboard weapon or one of its onboard weapons.

[0009] When the command execution system monitors the second channel, it may receive a second privileged command from the vehicle controller via the second channel. For example, the second privileged command may be a single button press or a combination of button presses on the vehicle controller. In some embodiments, the second privileged command may be a combination of button presses followed by a single button press. In even more embodiments, the privileged command may be a combination of button presses followed by a single button press while the original combination of buttons remains pressed.

[0010] In some embodiments, the privileged mode may be enabled only for a predetermined time period (e.g., 15 seconds, 30 seconds, 1 minute, etc.). That is, to prevent accidental execution of privileged operations, the command execution system may disable the privileged operation mode if the input sequence is not completed in a timely manner. Therefore, in some embodiments, the command sequence must be resumed from the first privileged operation.

[0011] In some embodiments, privileged mode may be disabled if an incorrect command is entered as a second privileged command. For example, when a command execution system enters privileged mode, the command execution system may receive a second execution command containing a combination and / or sequence of inputs. If that combination and / or sequence of inputs does not match privileged behavior, the command execution system may disable privileged mode. In some embodiments, the command execution system may prompt the user to enter a first privileged command to initiate privileged mode.

[0012] The command execution system may determine that a second privileged command corresponds to a second input in an input sequence for performing a privileged operation. For example, the command execution system may compare the inputs in a second privileged command to determine whether those inputs match a particular predetermined privileged operation. In some embodiments, there may be one or more predetermined privileged commands (e.g., weapon-related commands for firing a weapon, destruction commands, and / or other appropriate commands).

[0013] If the command execution system determines that an input sequence corresponds to a particular privileged command, the command execution system may transmit that command to a vehicle (e.g., an aerial drone with mounted weapons). That is, based on the determination that a second privileged command corresponds to a second input in an input sequence for performing a privileged action, the command execution system may transmit a request to the vehicle to perform a privileged action. For example, the command execution system may transmit a weapons-related command (e.g., to fire a weapon) to an aerial drone.

[0014] In some embodiments, privileged commands may need to be encrypted based on permissions granted to a particular mobile device. The command execution system may use a file or another mechanism to determine whether the mobile device has permission to perform a privileged operation. If so, the mobile device is enabled to encrypt the privileged operation before sending it to the vehicle. That is, in some embodiments, the vehicle may only accept encrypted privileged operations.

[0015] Various other aspects, features, and advantages of the system will become apparent through the detailed description and accompanying drawings. It should also be understood that both the general description above and the detailed description below are examples and do not limit the scope of this disclosure. Where used herein and in the claims, the singular “a,” “an,” and “the” refer to multiple subjects unless the context otherwise explicitly indicates. In addition, where used herein and in the claims, the term “or” means “and / or” unless the context otherwise explicitly indicates. Furthermore, where used herein, “part” refers to part or all (i.e., the whole part) of a given item (e.g., data) unless the context otherwise explicitly indicates. [Brief explanation of the drawing]

[0016] [Figure 1] Figure 1 shows an exemplary system for layered fail-safe redundancy for privileged operation execution, according to one or more embodiments of the present disclosure.

[0017] [Figure 2] Figure 2 shows an exemplary mobile device and controller prior to privileged operation according to one or more embodiments of the present disclosure.

[0018] [Figure 3]FIG. 3 is a diagram illustrating an excerpt of a data structure for identifying weapon-related commands and other privileged commands, in accordance with one or more embodiments of the present disclosure.

[0019] [Figure 4] FIG. 4 is a diagram illustrating a combination of inputs received from an operator that constitute a second privileged command, in accordance with one or more embodiments of the present disclosure.

[0020] [Figure 5] FIG. 5 is a diagram illustrating how commands from a vehicle controller may be generated using dedicated hardware, in accordance with one or more embodiments of the present disclosure.

[0021] [Figure 6] FIG. 6 is a diagram illustrating a computing device, in accordance with one or more embodiments of the present disclosure.

[0022] [Figure 7] FIG. 7 is a flowchart of operations for detecting motion-induced errors received from an inertial input device, in accordance with one or more embodiments of the present disclosure. MODE FOR CARRYING OUT THE INVENTION

[0023] Detailed Description In the following description, for purposes of explanation, numerous specific details are set forth to provide a thorough understanding of the disclosed embodiments. It will be appreciated by those skilled in the art, however, that the embodiments may be practiced without these specific details or with an equivalent arrangement. In other instances, well-known models and devices are shown in block diagram form in order to avoid unnecessarily obscuring the disclosed embodiments. It is also to be noted that the methods and systems disclosed herein are also suitable for applications unrelated to source code programming.

[0024] Figure 1 shows an example of an environment 100 for a layered fail-safe redundancy system and architecture for privileged operation execution. Environment 100 includes a command execution system 102 residing on a mobile device 104, a vehicle controller 106, and vehicles 108a-108n (e.g., unmanned vehicles). Vehicles 108a-108n may be connected to the mobile device via a network 150. The command execution system 102 can execute instructions of the layered fail-safe redundancy system. The command execution system 102 may include software, hardware, firmware, or a combination of the three. For example, the command execution system 102 may reside on a mobile device (e.g., a mobile smartphone, electronic tablet, computer system, or another suitable mobile device) that uses the network 150 to send commands to one or more vehicles (e.g., unmanned vehicles). In some embodiments, one or more components of the command execution system 102 may reside on other suitable devices.

[0025] The vehicle controller 106 may be a controller device connected to the mobile device 104. The vehicle controller 106 may include multiple input devices (e.g., buttons, joysticks, switches, levers, etc.). The vehicle controller 106 may receive controller input from an operator. For example, a certain action may involve pressing a button and / or using a joystick to control an unmanned aerial vehicle. In some embodiments, the mobile device 104 may be slid into the vehicle controller 106. The mobile device and the vehicle controller may be connected via a physical connection (e.g., a Universal Serial Bus (USB) connection). The physical connection may be divided into two or more channels. In some embodiments, each channel may be created based on the type of interface used by the mobile device. For example, a first channel may correspond to a USB Human Interface Device (HID) that allows a user input device (e.g., a keyboard, mouse, and / or other controller) to communicate with the mobile device. A second channel may correspond to a USB Communication Device Class (CDC) serial interface, which is a communication class that enables interfacing with the mobile device using a network-style interface.

[0026] In some embodiments, the vehicle controller may be connected to a mobile device via a wireless network connection. For example, the wireless network connection may be a Wireless Fidelity (Wi-Fi) connection or a Bluetooth® connection. Other wireless network connections may be used, as long as two communication channels are supported by the wireless connection. In some embodiments, only a point-to-point wireless connection may be used.

[0027] Network 150 may be a wireless local area network, a wireless wide area network (e.g., the Internet), or a combination of the two. Vehicles 108a-108n may be unmanned vehicles, including aerial vehicles, land vehicles, and / or sea vehicles. In some embodiments, the vehicles may be manned vehicles that can be controlled by a vehicle controller.

[0028] The command execution system 102 can receive vehicle operation commands from the vehicle controller on the mobile device via the first channel. As described above, the mobile device may be connected to the vehicle controller via a physical connection having the first channel and the second channel. The controller may be a vehicle controller that enables an operator to control one or more vehicles (e.g., unmanned vehicles).

[0029] In some embodiments, the command execution system 102 may receive vehicle control commands using a communication subsystem 112. The communication subsystem 112 may include software components, hardware components, or a combination of both. For example, the communication subsystem 112 may include a USB adapter coupled with software for driving the adapter. The USB adapter may be incorporated into a mobile device hosting the command execution system 102. The communication subsystem 112 may receive control commands from the vehicle controller 106. In some embodiments, the communication subsystem 112 may receive vehicle control commands via a USB HID interface corresponding to a first channel. That is, the vehicle controller 106 may be connected to the mobile device as a human interface device.

[0030] In some embodiments, the communication subsystem 112 may receive vehicle operation requests via a wireless connection that supports multiple channels. For example, the communication subsystem 112 may include a network controller and / or a Bluetooth® controller. Thus, the communication subsystem 112 may be connected to the vehicle controller using a point-to-point Wi-Fi connection and / or a point-to-point Bluetooth® connection. In some embodiments, each connection may enable multiple connection channels. In some embodiments, the first channel may be a Wi-Fi connection, the second channel may be a Bluetooth® connection, or vice versa.

[0031] Vehicle control commands may also be interactions between the operator and one or more joysticks, one or more buttons, etc. The communication subsystem 112 may pass control commands, or pointers to control commands in memory, to the command processing subsystem 114.

[0032] The command processing subsystem 114 may include software components, hardware components, or a combination of both. For example, the command processing subsystem 114 may include software components that access data in memory and / or storage, and may use one or more processors to perform its operations. The command processing subsystem 114 may receive control commands, perform the necessary processing, and then transmit the control commands to a vehicle (e.g., an unmanned vehicle). For example, the control command may be a command to move forward on an unmanned aerial vehicle. Thus, the command processing subsystem 114 may use the communication subsystem 112 to transmit commands (e.g., via the network 150) to one or more vehicles 108a-108n. The command execution system 102 may continue receiving control commands, processing those commands, and transmitting those commands to one or more vehicles (e.g., unmanned vehicles).

[0033] The command execution system 102 may receive a first privileged command (e.g., via the communication subsystem 112) using an input mechanism associated with the mobile device. For example, Figure 2 shows an exemplary mobile device and controller prior to a privileged operation. As shown in Figure 2, systems 200 and 220 show combinations of a mobile device and a vehicle controller. The mobile device is shown as being slid into the vehicle controller (e.g., vehicle controller 106). The vehicle controller 106 may include a number of actuators 203 (e.g., buttons, joysticks, etc.) for receiving input from the operator. As described above, the mobile device may receive input (e.g., via a USB connection) that enables the vehicle controller to control the vehicle (e.g., an unmanned vehicle) via the mobile device (e.g., mobile device 104). The mobile device may include a touchscreen interface or another type of interface. When the operator desires to initiate a privileged command, the operator may activate an input device on the vehicle controller. The vehicle controller may signal to the mobile device (e.g., via a USB HID interface) via a first channel that a privileged operation has been requested. In response, the mobile device may generate prompt 206 for display. The input mechanism may be a touchscreen on the mobile device. The mobile device may receive input as a first privileged command.

[0034] In some embodiments, the command execution system 102 may receive a first weapon-related command using an input mechanism associated with a mobile device. The first weapon-related command may be the initiation of a firing command for firing a weapon mounted on an unmanned vehicle. As shown in Figure 2, the first weapon-related command may also be a gesture input by an operator on prompt 206. Once the gesture (e.g., sliding a finger across a slider) is completed, the mobile device may interpret the gesture as a first weapon-related command, or more generally, a first privileged command. As described above, a privileged operation does not necessarily have to be accompanied by a weapon-related command. A first privileged command (e.g., a first weapon-related command) may be part of a privileged operation (e.g., a weapon-related operation).

[0035] When a first privileged command is received, it can be processed by the input processing subsystem 116. The input processing subsystem 116 may include software components, hardware components, or a combination of both. For example, the input processing subsystem 116 may include software components that access data in memory and / or storage and may use one or more processors to perform its operations. That is, based on the receipt of the first privileged command, the input processing subsystem 116 may enter a privileged operation mode. The privileged operation mode may enable privileged operation using the vehicle controller. For example, the input processing subsystem 116 may signal to the command execution system 102 that further privileged commands are expected from the vehicle controller via a second channel. In some embodiments, the input processing subsystem 116 may signal to the command processing subsystem 114 to begin monitoring the second channel. For example, as described above, the second channel may be a USB CDC serial interface. Thus, the command processing subsystem 114 can begin monitoring its interface for further commands from the vehicle controller.

[0036] As described above, in some embodiments, the mobile device may be connected to the vehicle controller via one or more wireless connections (e.g., Wi-Fi and / or Bluetooth®). In these embodiments, the command execution system 102 may communicate with the vehicle controller (e.g., via the communication subsystem 112) via a single channel (e.g., one Wi-Fi channel or one Bluetooth® channel). When a first privileged command is received, the command execution system may establish a second channel (e.g., a second Wi-Fi channel or a second Bluetooth® channel) for communication with the vehicle controller (e.g., via the communication subsystem 112). In some embodiments, the first channel may be a Wi-Fi channel, the second channel may be a Bluetooth® channel, or vice versa.

[0037] As described above, in some embodiments, the privileged command may be a weapon-related command for firing a weapon mounted on a vehicle (e.g., an unmanned vehicle). Thus, the input processing subsystem 116 may determine that the first weapon-related command corresponds to the first input in an input sequence for performing a weapon-related action. For example, when the input processing subsystem 116 receives an operator input (e.g., a gesture via a slider associated with a prompt 206), the input processing subsystem 116 may compare the input (e.g., a combination of a prompt and a gesture) with a predetermined command. For example, the prompt may indicate "arm" and the gesture may indicate "completed". Thus, the input may indicate "arm complete". This instruction may be compared with a pre-stored command. Thus, based on determining that the input matches the first command in a predetermined sequence of commands, the input processing subsystem 116 may determine that the input sequence has been initiated.

[0038] When the command execution system 102 determines that a weapon-related command (or another appropriate privileged command) has been received (for example, via the input processing subsystem 116), the command execution system 102 may initiate a privileged operation mode (for example, via the command processing subsystem 114). This may include monitoring a second channel for other weapon-related commands (e.g., a fire command, a destroy command, etc.). In some embodiments, based on the determination that a first weapon-related command corresponds to a first input in an input sequence for performing a weapon-related operation, the command execution system 102 may monitor a second channel for a second weapon-related command from a vehicle controller (for example, via the command processing subsystem 114).

[0039] Figure 3 shows an excerpt of a data structure 300 for identifying weapon-related commands and other privileged commands. The name field 303 may store a command identifier, and the value field 306 may store the corresponding command sequence. Thus, when the input processing subsystem 116 detects input on a mobile device, it may compare the input to a first command in each sequence to determine whether a particular sequence (e.g., a firing sequence) should be initiated. In some embodiments, the sequence initiation may be the same for all privileged commands. Thus, the comparison within a sequence may occur when a "second privileged command" is received.

[0040] The command processing subsystem 114 may detect and process commands from the vehicle controller via a second channel. The command processing subsystem 114 may determine that a received command is another privileged command. For example, while the command execution system 102 is in privileged operation mode, commands from the vehicle controller may be received via the second channel. As described above, the second channel may be a USB CDC serial interface in a wired environment. In another example, in a wireless environment, commands may be received via a second Wi-Fi channel, a second Bluetooth® channel, etc. Once a command is received, the command processing subsystem 114 may determine that the received command is a second privileged command, for example, by comparing the command with the command sequence shown in Figure 3. If the command matches one or more of the command sequences, the command processing subsystem 114 may determine that the command is a second privileged command. Thus, the command processing subsystem 114 may receive a second privileged command from the vehicle controller via the second channel. As described above, the second privileged command may be, for example, a weapons-related command for firing a weapon mounted on the vehicle.

[0041] In some embodiments, the command processing subsystem 114 may accept privileged commands only for a predetermined period of time before the privileged mode is deactivated. This prevents accidental execution if the operator mistakes the privileged operating mode for the normal operating mode. In particular, the command processing subsystem 114 may determine that a second privileged command was not received within a predetermined threshold time. For example, when the privileged mode is activated, the command processing subsystem 114 may start a timer and / or generate a timestamp indicating the time the privileged mode was activated. The command processing subsystem 114 may then determine (for example, based on the timer or timestamp) when the predetermined time (e.g., 10 seconds, 30 seconds, 1 minute, etc.) has expired.

[0042] When the time expires, the command processing subsystem 114 may perform certain actions related to disabling privileged mode. Thus, based on the determination that no second privileged command was received within a predetermined threshold time, the command processing subsystem 114 may stop monitoring the second channel. For example, the command processing subsystem 114 may ignore any commands detected from the second channel. In some embodiments, the command processing subsystem 114 may notify the operator that privileged mode has been disabled due to the timer expiring. For example, the command execution system 102 may generate an indication that privileged mode has been disabled for display on a mobile device. Additionally or alternatively, the command execution system 102 may (e.g., via the command processing subsystem 114) generate a prompt for executing a first privileged command for display on a mobile device. For example, the command execution system 102 may generate the prompt 206 in Figure 2 for display.

[0043] When a command is received while the device is in privileged mode, the command execution system 102 may determine (for example, via the command processing subsystem 114) whether the command is one of the commands in a sequence for performing a privileged operation (e.g., a weapon-related operation such as firing a weapon). In particular, the command processing subsystem 114 may determine whether a second privileged command corresponds to a second input in an input sequence for performing a privileged operation. For example, the command processing subsystem 114 may determine whether the received command is one of the commands for a particular privileged operation by comparing the received command with a command in the value field 306. In some embodiments, the command processing subsystem 114 may compare both the first and second privileged commands with a command sequence to determine whether the combination matches a particular command sequence.

[0044] As described above, each command sequence (each value field 306) in Figure 3 may contain two or more commands that together form a privileged operation. For example, the command processing subsystem 114 may determine whether a second weapon-related command corresponds to a second input in an input sequence for performing a weapon-related operation. That is, a particular weapon-related command may be identified as a privilege or as part of a weapon-related operation. For example, as shown in Figure 3, one of the privileged operations (e.g., a weapon-related command) may be a "fire" operation (e.g., ordering a vehicle to fire its weapon). If the second weapon-related command matches a "fire" operation, or if the combination of the first and second weapon-related commands matches a "fire" operation, the command processing subsystem 114 may identify that the desired operation is a "fire" operation and perform the process of ordering the vehicle to fire its weapon.

[0045] In some embodiments, the command execution system 102 may use the following operations to determine whether a second privileged command corresponds to a second input in an input sequence for performing a privileged operation. In particular, the command execution system 102 may determine whether a privileged operation mode has been initiated. For example, when a first privileged command is received, the command execution system 102 may set a flag in memory, for example, to indicate that a privileged operation mode has been initiated. Once a privileged mode has been initiated, the command execution system 102 may receive one or more commands through a second channel.

[0046] The command execution system 102 may determine, based on a second privileged command received via a second channel, whether multiple inputs within the second privileged command match a privileged operation. Figure 4 shows a vehicle controller 400 showing combinations of inputs received from an operator that constitute a second privileged command. For example, the second privileged command may include pressing a combination of buttons 403 and 406, and then pressing button 409 while buttons 403 and 406 are pressed. In some embodiments, the second privileged command may include multiple commands. For example, the combination of pressing buttons 403 and 406 may be part of a privileged command (e.g., within an input sequence of a weapon-related command), and pressing button 409 in combination with buttons 403 and 406 may be another part of a privileged command. Thus, a privileged command may have multiple subcommands, which can be used for comparison with a command sequence, as shown, for example, in Figure 3.

[0047] Next, the command execution system 102 may determine that the second privileged command corresponds to the second input in the input sequence, based on both (1) the determination that a privileged operation mode has been initiated and (2) the determination that multiple inputs in the second privileged command coincide with a privileged operation. In some embodiments, the command execution system 102 may first determine that a privileged mode has been initiated, and then determine that multiple inputs also correspond to the second privileged command (e.g., the first privileged command combined with a second privileged command (or subcommand)). In some embodiments, these determinations may be made in parallel.

[0048] In some embodiments, the command execution system 102 may determine, using the following operation, that a second privileged command corresponds to a second input in an input sequence for performing a privileged operation. The command execution system 102 may receive a number of signals from the vehicle controller via a second channel indicating that a combination of input devices has been activated. For example, the signals may be received via a USB CDC serial interface. In some embodiments, the signals may be received via a second wireless channel, as described above. The signals may correspond to a button press or a combination of button presses. For example, an operator may press both button 403 and button 406 on the vehicle controller. The vehicle controller may transmit these button presses to a mobile device via the second channel.

[0049] The operator may press button 409 while holding down buttons 403 and 406. Thus, the mobile device may receive an additional signal from the vehicle controller via a second channel indicating that an additional input device has been activated while the combination of input devices is activated. The additional signal may indicate that both the input device and the combination of the additional input device have been activated.

[0050] The command execution system 102 may then determine that the combination of input devices being activated corresponds to a first part of an input sequence, and that additional input devices operating with the combination of input devices correspond to a second part of the input sequence. As described herein, the second privileged command may include subcommands that can be used to identify a matching privileged operation (e.g., a weapon-related operation). Once a match is determined, the command execution system 102 may generate one or more instructions that constitute the privileged operation.

[0051] In some embodiments, only one privileged operation (e.g., a weapon-related operation) may be permitted per privileged mode activation. Thus, the command execution system 102 may determine that a combination of input devices is no longer activated (e.g., the operator has released the button), and based on this determination, the command execution system 102 may deactivate / disable the privileged operation mode. For example, in these embodiments, once a firing command is sent to the vehicle, the privileged operation mode needs to be reactivated to send another privileged command.

[0052] The command execution system 102 may receive one or more inputs from the vehicle controller and the operator. Figure 5 shows how commands from the vehicle controller may be generated using dedicated hardware. Figure 5 shows a highly reliable circuit 500 device to ensure that a positive activation of a button press occurs to command electronic armament / disarming and pressing the "start operation" button. The circuit 500 is designed to mitigate pseudo-transient phenomena, button bounce circuit coupling, user button variability, button failure, and other challenges. Input device 503 may be triggered by the operator pressing button 403 (Figure 4), and input device 506 may be triggered by the operator pressing button 406 (Figure 4). Each input device may be coupled with a supervisor designed to ensure proper operation during privileged operation modes. During normal operation, a supervisor may not be necessary. In addition, input devices 503 and 506 are connected to an AND gate 512, which enables efficient simultaneous press operation. The input device 509 may be activated by the operator pressing button 409 (Figure 4). A special hardware device 514 receives all input signals and transmits them to the mobile device (for example, via the second channel in privileged operating mode and via the first channel during normal operating mode).

[0053] If the command execution system 102 determines that a second privileged command or a combination of a first privileged command and a second privileged command matches a privileged operation, the command execution system 102 may cause a vehicle (e.g., an unmanned vehicle) to execute the command. Therefore, based on determining that a second privileged command corresponds to a second input in an input sequence for executing a privileged operation, the command execution system 102 may send a request to the vehicle to execute a privileged operation. For example, the command processing subsystem 114 may identify a privileged operation based on a second privileged command or on a combination of a first privileged command and a second privileged command. In some embodiments, the command processing subsystem 114 may perform the identification using the data structure shown in Figure 3. For example, the command processing subsystem 114 may match a command sequence in the value field 306 with a second privileged command or a combination of a first privileged command and a second privileged command. As described above, the privileged operation may be a weapon-related operation. Therefore, the command processing subsystem 114 may send a request to the unmanned vehicle to perform a weapon-related operation, based on its determination that the second weapon-related command corresponds to the second input in the input sequence for performing a weapon-related operation.

[0054] In some embodiments, before executing a privileged operation, the command processing subsystem 114 can determine whether the mobile device has the authorization / privilege to execute a privileged command. For example, the mobile device may require a specific government license to execute a privileged command. Therefore, based on receiving a second privileged command, the command processing subsystem 114 may determine, based on a privilege file, whether the mobile device is authorized to execute a privileged operation. For example, the government license may be a privilege file containing data (e.g., code) for determining whether the mobile device has authorization to execute a privileged operation and / or enter a privileged mode. In some embodiments, the privilege file may contain data for encrypting a privileged command before sending it to the vehicle, so that the vehicle can only execute privileged commands encrypted using the correct data (e.g., the correct key which may be stored in the privilege file). Therefore, based on determining that the mobile device is authorized to execute a privileged operation, the command processing subsystem 114 may generate an encrypted privileged operation by encrypting the privileged operation using an encryption function (e.g., an encryption function which uses a key from the privilege file). In some embodiments, the privilege file may contain an API for generating encrypted privileged commands to be sent to the vehicle. When privileged operations are encrypted, the command execution system 102 can send encrypted privileged commands to the vehicle (for example, via the communication subsystem 112).

[0055] In some embodiments, the command processing subsystem 114 may determine that a second privileged command or a combination of a first privileged command and a second privileged command does not correspond to a privileged operation. For example, a second privileged command or a combination of a first privileged command and a second privileged command does not correspond to any command sequence in the value field 306. Thus, the command execution system 102 may determine (e.g., using the command processing subsystem 114) that the second privileged command does not correspond to a second input in the input sequence for performing a privileged operation. Based on the determination, as described above, that the second privileged command does not correspond to a second input in the input sequence for performing a privileged operation, the command processing subsystem 114 may stop monitoring the second channel. Alternatively or additionally, the command processing subsystem 114 may disable the privileged mode and return the system (e.g., mobile devices and vehicle controllers) to normal mode for piloting and executing other types of commands.

[0056] In some embodiments, the command processing subsystem 114 may prompt the user to resume the privileged operation mode. In particular, the command processing subsystem 114 may determine that the input sequence for performing a privileged operation has been interrupted. For example, if the command processing subsystem 114 determines that a command that does not match a command in the sequence of privileged operations has been received, the command processing subsystem 114 may determine that the privileged operation has been interrupted. In another example, if the command processing subsystem 114 determines that the combination of a first privileged command and a second privileged command does not match a command in the sequence of privileged operations, the command processing subsystem 114 may determine that the privileged operation has been interrupted.

[0057] Based on determining that the input sequence for executing a privileged operation has been interrupted, the command processing subsystem 114 may prompt the user to execute the first privileged command again using an input mechanism associated with the mobile device. For example, the command processing subsystem 114 may generate a prompt 206 (e.g., a slider) for display. In some embodiments, the command processing subsystem 114 may generate another interactive image for display to receive input to re-enable privileged mode.

[0058] Computing environment Figure 6 shows an exemplary computing system that may be used according to some embodiments of the present disclosure. In some cases, the computing system 600 is referred to as a computer system. The computing system may also be part of the mobile device 104. Those skilled in the art will understand that these terms may be used interchangeably. The components of Figure 6 may be used to perform some or all of the operations described in relation to Figures 1 to 5. Furthermore, various parts of the systems and methods described herein may include, or be performed on, one or more computer systems similar to the computing system 600. Furthermore, the processes and modules described herein may be performed by one or more processing systems similar to those of the computing system 600.

[0059] The computing system 600 may include one or more processors (e.g., processors 610a to 610n) coupled to system memory 620, input / output (I / O) device interface 630, and network interface 640 via I / O interface 650. The processor may include a single processor or multiple processors (e.g., distributed processors). The processor may be any suitable processor capable of executing instructions or otherwise performing actions. The processor may include a central processing unit (CPU) that executes program instructions to perform arithmetic, logical, and I / O operations of the computing system 600. The processor may execute code that creates an execution environment for program instructions (e.g., processor firmware, protocol stack, database management system, operating system, or a combination thereof). The processor may include a programmable processor. The processor may include a general-purpose or dedicated microprocessor. The processor may receive instructions and data from memory (e.g., system memory 620). The computing system 600 may be a uniprocessor system including one processor (e.g., processor 610a) or a multiprocessor system including any number of suitable processors (e.g., 610a to 610n). Multiple processors may be used to provide parallel or sequential execution of one or more parts of the techniques described herein. Processes such as logic flows described herein may be performed by one or more programmable processors executing one or more computer programs to perform a function by manipulating input data and producing corresponding outputs. Processes described herein may also be performed by dedicated logic circuits such as FPGAs (field-programmable gate arrays) or ASICs (application-specific integrated circuits), and the devices may also be implemented as dedicated logic circuits. The computing system 600 may include multiple computing devices (e.g., a distributed computer system) for performing various processing functions.

[0060] The I / O device interface 630 may provide an interface for connecting one or more I / O devices 660 to the computer system 600. I / O devices may include devices that receive input (e.g., from a user) or output information (e.g., to a user). I / O devices 660 may include, for example, a graphical user interface presented on a display (e.g., a cathode ray tube (CRT) or liquid crystal display (LCD) monitor), a pointing device (e.g., a computer mouse or trackball), a keyboard, a keypad, a touchpad, a scanning device, a voice recognition device, a gesture recognition device, a printer, an acoustic speaker, a microphone, a camera, and the like. I / O devices 660 may be connected to the computer system 600 via wired or wireless connections. I / O devices 660 may be connected to the computer system 600 from a remote location. For example, I / O devices 660 located on a remote computer system may be connected to the computer system 600 via a network and the network interface 640.

[0061] The network interface 640 may include a network adapter that provides connectivity for the computer system 600 to a network. The network interface 640 may facilitate data exchange between the computer system 600 and other devices connected to the network. The network interface 640 may support wired or wireless communication. The network may include electronic communication networks such as the Internet, a local area network (LAN), a wide area network (WAN), or a cellular communication network.

[0062] System memory 620 may be configured to store program instructions 670 or data 680. Program instructions 670 may be executable by a processor (e.g., one or more of processors 610a to 610n) to implement one or more embodiments of the technique. Program instructions 670 may include a module of computer program instructions for implementing one or more techniques described herein with respect to various processing modules. Program instructions may include computer programs (known in certain forms as programs, software, software applications, scripts, or code). Computer programs may be written in a programming language, including compiled or interpreted languages, or declarative or procedural languages. Computer programs may include standalone programs, modules, components, or subroutines, units suitable for use in a computing environment. Computer programs may or may not correspond to files in a file system. A program may be stored in part of a file that holds other programs or data (e.g., one or more scripts stored in a markup language document), in a single file dedicated to the program in question, or in multiple coordinated files (e.g., a file storing one or more modules, subprograms, or parts of code). Computer programs can be deployed to run on one or more computer processors, either locally located at a single site or distributed across multiple remote sites and interconnected by a communication network.

[0063] The system memory 620 may include a tangible program carrier having stored program instructions. The tangible program carrier may include a non-temporary computer-readable storage medium. The non-temporary computer-readable storage medium may include a machine-readable storage device, a machine-readable storage substrate, a memory device, or any combination thereof. The non-temporary computer-readable storage medium may include non-volatile memory (e.g., flash memory, ROM, PROM, EPROM, EEPROM), volatile memory (e.g., random access memory (RAM), static random access memory (SRAM), synchronous dynamic RAM (SDRAM)), mass storage memory (e.g., CD-ROM and / or DVD-ROM, hard drive), etc. The system memory 620 may include a non-temporary computer-readable storage medium in which program instructions can be stored, which are executable by a computer processor (e.g., one or more of processors 610a to 610n) to cause the subject and functional operations described herein. The memory (e.g., system memory 620) may include a single memory device and / or multiple memory devices (e.g., distributed memory devices).

[0064] The I / O interface 650 may be configured to coordinate I / O traffic between processors 610a–610n, system memory 620, network interface 640, I / O device 660, and / or other peripheral devices. The I / O interface 650 may perform protocol, timing, or other data conversions to convert data signals from one component (e.g., system memory 620) into a format suitable for use by another component (e.g., processors 610a–610n). The I / O interface 650 may include support for devices attached via various types of peripheral buses, such as Peripheral Interconnect (PCI) bus standards or variations of the Universal Serial Bus (USB) standard.

[0065] Embodiments of the techniques described herein may be implemented using a single instance of computer system 600, or using multiple computer systems 600 configured to host different parts or instances of the embodiments. Multiple computer systems 600 may provide parallel or sequential processing / execution of one or more parts of the techniques described herein.

[0066] Those skilled in the art will understand that computer system 600 is merely illustrative and not intended to limit the scope of the techniques described herein. Computer system 600 may include any combination of devices or software that may implement or otherwise provide implementations of the techniques described herein. For example, computer system 600 may include, or be a combination thereof, a cloud computing system, a data center, a server rack, a server, a virtual server, a desktop computer, a laptop computer, a tablet computer, a server device, a client device, a mobile phone, a personal data assistant (PDA), a mobile audio or video player, a game console, an in-vehicle computer, a Global Positioning System (GPS), etc. Computer system 600 may also be connected to other devices not shown or may operate as a standalone system. Furthermore, the functions provided by the illustrated components may, in some embodiments, be combined into fewer components or distributed among additional components. Similarly, in some embodiments, some functions of the illustrated components may not be provided, or other additional functions may be available.

[0067] Operation flow Figure 7 is a flowchart 700 of the operation for detecting motion induction errors received from an inertial input device. The operation in Figure 7 may use the components described in relation to Figure 6. In some embodiments, the command execution system 102 may include one or more components of the computing system 600. In 702, the command execution system 102 receives vehicle control commands via a first channel and transmits vehicle control commands to the vehicle. The command execution system 102 may receive vehicle control commands via I / O device interface 630 (via a wired USB connection) via I / O device(s) 660, or via a point-to-point wireless connection using network interface 640. The command execution system 102 may transmit control commands to the vehicle using network interface 640 via network 150.

[0068] In 704, the command execution system 102 receives a first privileged command using an input mechanism associated with the mobile device. The command execution system 102 may use one or more I / O devices 660 through the I / O device interface 630 to receive the first privileged command. In 706, the command execution system 102 enters a privileged operation mode. The command execution system 102 may use one or more processors 610a, 610b, and / or 610n to carry out the generation.

[0069] In 708, the command execution system 102 receives a second privileged command from the vehicle controller via a second channel. The command execution system 102 may receive the second privileged command via a second channel of an I / O device 660 (for example, via a wired USB connection) through the I / O device interface 630, or via a second channel of a point-to-point wireless connection using the network interface 640. In 710, the command execution system 102 determines whether the second privileged command corresponds to a second input in an input sequence for performing a privileged operation. The command execution system 102 may use one or more processors 610a, 610b, and / or 610n to perform the decision. In 712, the command execution system 102 sends a request to the vehicle for performing a privileged operation. The command execution system 102 may send the request to the vehicle using the network interface 640 via the network 150.

[0070] While the present invention is described in detail for illustrative purposes based on what is currently considered to be the most practical and preferred embodiment, such details are for that purpose only, and it should be understood that the present invention is not limited to the disclosed embodiments, but rather intended to cover modifications and equivalent configurations within the scope of the appended claims. For example, it should be understood that, wherever possible, the present invention is intended to allow one or more features of any embodiment to be combined with one or more features of any other embodiment.

[0071] The embodiments described herein are presented for illustrative purposes only, not limitation, and this disclosure is limited only by the appended claims. Furthermore, it should be noted that features and limitations described in any one embodiment may apply to any other embodiment herein, and that a flowchart or example relating to one embodiment may be combined with any other embodiment in an appropriate manner, in a different order, or in parallel. Furthermore, the systems and methods described herein may be implemented in real time. It should also be noted that the systems and / or methods described herein may apply to or be used in accordance with other systems and / or methods.

[0072] This technology will be better understood by referring to the embodiments listed below. 1. A method comprising: receiving a vehicle operation command from a vehicle controller in a mobile device via a first channel, wherein the mobile device is connected to the vehicle controller via a physical connection having a first channel and a second channel; transmitting a vehicle operation command to a vehicle; receiving a first privileged command using an input mechanism associated with the mobile device; and initiating a privileged operation mode based on receiving the first privileged command, wherein the privileged operation mode enables a privileged operation using the vehicle controller; receiving a second privileged command from the vehicle controller via a second channel; determining whether the second privileged command corresponds to a second input in an input sequence for performing a privileged operation; and transmitting a request to the vehicle for performing a privileged operation based on determining that the second privileged command corresponds to a second input in an input sequence for performing a privileged operation. 2. Any of the prior embodiments, further comprising determining that a second privileged command was not received within a predetermined threshold time, stopping monitoring of the second channel based on the determination that a second privileged command was not received within a predetermined threshold time, and generating a prompt for display on the mobile device to execute a first privileged command. 3. Any of the prior embodiments, further comprising determining that the second privileged command does not correspond to a second input in the input sequence for performing a privileged operation, and ceasing monitoring of the second channel based on the determination that the second privileged command does not correspond to a second input in the input sequence for performing a privileged operation. 4. Any of the prior embodiments further comprising determining that an input sequence for performing a privileged operation has been interrupted, and, based on the determination that an input sequence for performing a privileged operation has been interrupted, prompting the user to re-execute the first privileged command using an input mechanism associated with the mobile device. 5. Any of the preceding embodiments, in which receiving a vehicle control command includes receiving a vehicle control command via a Universal Serial Bus Human Interface device interface, and receiving a second privileged command includes receiving a second privileged command via a Universal Serial Bus Communication Device Class Interface. 6. Any of the prior embodiments, further comprising determining, based on a privileged file, whether the mobile device is authorized to perform a privileged operation based on receiving a second privileged command, and, based on determining that the mobile device is authorized to perform a privileged operation, generating an encrypted privileged operation by encrypting the privileged operation using an encryption function. 7. Any of the prior embodiments in which sending a request to the vehicle to perform a privileged operation includes sending an encrypted privileged operation. 8. Any of the prior embodiments, further comprising initiating a privileged operating mode based on receiving a first privileged command, and monitoring a second channel for a second privileged command from a vehicle controller. 9. Any of the prior embodiments, further comprising determining whether a second privileged command corresponds to a second input in an input sequence for performing a privileged operation, determining whether a privileged operation mode has been initiated, determining whether multiple inputs in a second privileged command match a privileged operation based on a second privileged command received via a second channel, and determining whether a second privileged command corresponds to a second input in an input sequence based on both (1) determining that a privileged operation mode has been initiated and (2) determining that multiple inputs in a second privileged command match a privileged operation. 10. Any of the preceding embodiments, further comprising determining that a second privileged command corresponds to a second input in an input sequence for performing a privileged operation, receiving a plurality of signals from a vehicle controller via a second channel indicating that a combination of input devices has been activated, and while the combination of input devices is activated, receiving an additional signal from the vehicle controller via the second channel indicating that an additional input device has been activated, the additional signal indicating that both the combination of input devices and the additional input device have been activated, determining that the activated combination of input devices corresponds to a first part of the input sequence, and that the additional input device activated together with the combination of input devices corresponds to a second part of the input sequence, and generating one or more instructions that include a privileged operation. 11. Any of the prior embodiments further comprising determining that the combination of input devices is no longer operational, and releasing the privileged operating mode based on the determination that the combination of input devices is no longer operational. 12. A tangible, non-temporary, machine-readable medium that, when executed by a data processing device, stores instructions causing the data processing device to perform an operation including one of the operations of Embodiments 1 to 11. 13. A system comprising one or more processors and a memory that stores instructions, when executed by the processors, causing the processors to perform an operation including any of the operations of Embodiments 1 to 11. 14. A system comprising means for carrying out any of embodiments 1 to 11. 15. A system comprising a cloud-based circuit for implementing any of embodiments 1 to 11.

Claims

1. A system for providing fail-safe redundancy via a single data bus, wherein the system is A vehicle controller having multiple input devices, wherein the vehicle controller receives controller input from an operator, A mobile device connected to the vehicle controller via a universal serial bus connection having a first channel connected using a first interface and a second channel connected using a second interface, the mobile device comprising a mobile device that wirelessly transmits commands to an unmanned vehicle, the mobile device One or more processors, One or more non-temporary computer-readable storage media for storing instructions and The instruction, when executed by one or more processors, causes the one or more processors to perform an operation, and the operation is The system receives vehicle control commands from the vehicle controller for controlling the unmanned vehicle via the first channel, Transmitting the aforementioned vehicle control command to the unmanned vehicle, Using the input mechanism associated with the mobile device, to receive a first privileged command, Determining whether the first privileged command corresponds to a first input in the input sequence for executing a privileged operation, Based on determining that the first privileged command corresponds to the first input in the input sequence for executing the privileged operation, the second channel is monitored for a second privileged command from the vehicle controller, Receiving the second privileged command from the vehicle controller via the second channel, Determining whether the second privileged command corresponds to the second input in the input sequence for executing the privileged operation, Based on determining that the second privileged command corresponds to the second input in the input sequence for performing the privileged operation, a request to perform the privileged operation is transmitted to the unmanned vehicle. A system that includes this.

2. A method for providing fail-safe redundancy via a single data bus, the method being: The mobile device receives vehicle operation commands from a vehicle controller via a first channel, wherein the mobile device is connected to the vehicle controller via a physical connection having the first channel and a second channel. The above vehicle control command is transmitted to the vehicle, Using the input mechanism associated with the mobile device, to receive a first privileged command, Based on receiving the first privileged command, a privileged operation mode is initiated, wherein the privileged operation mode enables privileged operation using the vehicle controller, Receiving a second privileged command from the vehicle controller via the second channel, Determining whether the second privileged command corresponds to a second input in the input sequence for executing a privileged operation, Based on determining that the second privileged command corresponds to the second input in the input sequence for performing the privileged operation, a request to perform the privileged operation is transmitted to the vehicle. Methods that include...

3. It is determined that the second privileged command was not received within a predetermined threshold time, Based on the determination that the second privileged command was not received within the predetermined threshold time, To stop monitoring the second channel, and To generate a prompt on the mobile device for displaying the first privileged command, The method according to claim 2, further comprising:

4. Determining that the second privileged command does not correspond to the second input in the input sequence for executing the privileged operation, Based on the determination that the second privileged command does not correspond to the second input in the input sequence for performing the privileged operation, monitoring of the second channel is stopped. The method according to claim 2, further comprising:

5. Determining that the input sequence for executing the privileged operation has been interrupted, Based on determining that the input sequence for performing the privileged operation has been interrupted, prompt the user to re-execute the first privileged command using the input mechanism associated with the mobile device. The method according to claim 2, further comprising:

6. Receiving the vehicle control command includes receiving the vehicle control command via a Universal Serial Bus Human Interface Device Interface, The method according to claim 2, wherein receiving the second privileged command includes receiving the second privileged command via a Universal Serial Bus communication device class interface.

7. Based on receiving the second privileged command, it is determined, based on the privileged file, whether the mobile device is permitted to perform the privileged operation, Based on determining that the mobile device is authorized to perform the privileged operation, an encrypted privileged operation is generated by encrypting the privileged operation using an encryption function. The method according to claim 2, further comprising:

8. The method according to claim 7, wherein transmitting the request for performing the privileged operation to the vehicle includes transmitting the encrypted privileged operation.

9. The method according to claim 2, wherein initiating the privileged operation mode further comprises monitoring the second channel for the second privileged command from the vehicle controller based on receiving the first privileged command.

10. Determining whether the second privileged command corresponds to the second input in the input sequence for executing the privileged operation is: To determine whether the privileged operating mode has been initiated, Based on the second privileged command received via the second channel, it is determined whether multiple inputs within the second privileged command match the privileged operation. (1) determining that the privileged operation mode has been initiated, and (2) determining that the plurality of inputs in the second privileged command correspond to the second input in the input sequence, based on both of these: The method according to claim 2, further comprising:

11. Determining that the second privileged command corresponds to the second input in the input sequence for executing the privileged operation means The vehicle controller receives multiple signals via the second channel indicating that a combination of input devices has been activated, While the combination of input devices is activated, the vehicle controller receives an additional signal via the second channel indicating that an additional input device has been activated, the additional signal indicating that both the combination of input devices and the additional input device have been activated. Determining that the combination of input devices being operated corresponds to a first part of the input sequence, and that the additional input device operating together with the combination of input devices corresponds to a second part of the input sequence, To generate one or more instructions that include the aforementioned privileged operation. The method according to claim 2, further comprising:

12. Determining that the aforementioned combination of input devices is no longer in operation, Based on the determination that the aforementioned combination of input devices is no longer in operation, the privileged operation mode is released. The method according to claim 11, further comprising:

13. One or more non-temporary computer-readable media containing instructions for detecting motion induction errors received from an inertial input device, wherein when the instructions are executed by the one or more processors, the one or more processors cause the one or more processors to perform an action, and the action is The mobile device receives vehicle operation commands from a vehicle controller via a first channel, wherein the mobile device is connected to the vehicle controller via a physical connection having the first channel and a second channel. The above vehicle control command is transmitted to the vehicle, Using the input mechanism associated with the mobile device, to receive a first privileged command, Based on receiving the first privileged command, a privileged operation mode is initiated, wherein the privileged operation mode enables privileged operation using the vehicle controller, Receiving a second privileged command from the vehicle controller via the second channel, Determining that the second privileged command corresponds to a second input in the input sequence for executing a privileged operation, Based on determining that the second privileged command corresponds to the second input in the input sequence for performing the privileged operation, a request to perform the privileged operation is transmitted to the vehicle. One or more non-temporary computer-readable media, including [the specified text].

14. The instruction further causes one or more processors to Determining that the second privileged command was not received within a predetermined threshold time, Based on the determination that the second privileged command was not received within the predetermined threshold time, To stop monitoring the second channel, and To generate a prompt on the mobile device for displaying the first privileged command, One or more non-temporary computer-readable media according to claim 13, which perform the following actions.

15. The instruction further causes one or more processors to Determining that the second privileged command does not correspond to the second input in the input sequence for executing the privileged operation, Based on the determination that the second privileged command does not correspond to the second input in the input sequence for performing the privileged operation, monitoring of the second channel is stopped. One or more non-temporary computer-readable media according to claim 13, which perform the following actions.

16. The instruction further causes one or more processors to Determining that the input sequence for executing the privileged operation has been interrupted, Based on determining that the input sequence for performing the privileged operation has been interrupted, prompt the user to re-execute the first privileged command using the input mechanism associated with the mobile device. One or more non-temporary computer-readable media according to claim 13, which perform the following actions.

17. The instruction further causes one or more processors to Receiving the vehicle control command, which includes receiving the vehicle control command via a Universal Serial Bus Human Interface Device Interface, Receiving the second privileged command, which includes receiving the second privileged command via a Universal Serial Bus communication device class interface One or more non-temporary computer-readable media according to claim 13, which perform the following actions.

18. The instruction further causes one or more processors to Based on receiving the second privileged command, it is determined, based on the privileged file, whether the mobile device is permitted to perform the privileged operation, Based on determining that the mobile device is authorized to perform the privileged operation, an encrypted privileged operation is generated by encrypting the privileged operation using an encryption function. One or more non-temporary computer-readable media according to claim 13, which perform the following actions.

19. The instruction for transmitting the request for performing the privileged operation to the vehicle further causes one or more processors to transmit the cryptographic privileged operation, according to one or more non-temporary computer-readable media of claim 18.

20. The instruction for initiating the privileged operation mode further causes one or more processors to monitor the second channel for a second privileged command from the vehicle controller based on receiving the first privileged command, one or more non-temporary computer-readable media according to claim 13.