Mobile control device, mobile body, and control program
The movement control device addresses the safety concerns of vehicle control instructions from third-party applications by analyzing the driving state and determining the safety of control instructions, ensuring the moving body's safety even when controlled by third-party applications.
Patent Information
- Application Number
- JP2022055483
- Authority / Receiving Office
- JP · JP
- Patent Type
- Patents
- Current Assignee / Owner
- Filing Date
- 2022-03-30
- Publication Date
- 2025-05-27
- Estimated Expiration
- 2042-03-30
AI Technical Summary
Existing vehicle control technologies cannot ensure the safety of vehicle control instructions from third-party applications, as they do not differentiate between legitimate and unauthorized control instructions, and fail to assess the safety of control instructions in relation to the vehicle's driving state.
A movement control device that includes an analysis unit to assess the current driving state of a moving body and a determination unit to evaluate the safety of control instructions from third-party applications. This device ensures that only safe control instructions are executed, thereby maintaining the safety of the moving body.
The solution effectively ensures the safety of the moving body by preventing unsafe control instructions from third-party applications from being executed, even when enabling control by such applications.
Smart Images

Figure 0007683521000001 
Figure 0007683521000002 
Figure 0007683521000003
Abstract
Description
Technical Field
[0001] The present invention relates to a movement control device, a moving body, and a control program.
Background Art
[0002] In recent years, there has been an increase in vehicles that enable connection of applications manufactured by a third party, a so-called third party, different from vehicle manufacturers, to a vehicle system. Such applications by third parties are, for example, CarPlay of Apple and Automotive Android of Google.
[0003] The above applications use vehicle data to provide various services such as entertainment and fault diagnosis. For such services, for example, when registering the user's vehicle as a delivery destination of luggage, there may be a case where the application controls the vehicle, such as a service (in-car delivery) where a delivery person opens the trunk of the vehicle and puts in the luggage. The control targets by the application are, in addition to opening and closing of the trunk, for example, opening and closing of windows and doors, and turning on and off of lights and hazards. Even if a control instruction for the vehicle is output from such an application manufactured by a third party, the safety of the vehicle must be ensured.
[0004] Here, Patent Document 1 describes a vehicle control device that notifies a processing server of a rule that defines whether or not a communication frame received in a vehicle-side communication unit is illegal when a processing server receives an installation request for an application program.
[0005] Patent Document 2 describes an acceleration suppression device that switches output signals indicating an accelerator opening degree and a brake pedal force to suppress acceleration when a state in which there is a suspicion that the physical and mental state of a driver is poor continues longer than a time determination value and it is determined that the driving state is a dangerous driving state.
[0006] Patent Document 3 describes a control device that compares the depression amount by a vehicle accelerator signal when the vehicle starts, the depression force of the accelerator pedal during vehicle travel, and a predetermined threshold value to determine whether the accelerator pedal has been mispressed, and performs control such as suppressing the acceleration of the vehicle when a mispress is detected.
Prior Art Documents
Patent Documents
[0007]
Patent Document 1
Patent Document 2
Patent Document 3
Summary of the Invention
Problems to be Solved by the Invention
[0008] The vehicle control device described in Patent Document 1 is a countermeasure against unauthorized control due to a cyber attack on the vehicle. On the other hand, control instructions from an application manufactured by a third party are legitimate control instructions and not unauthorized control instructions, so the vehicle control device described in Patent Document 1 cannot handle them.
[0009] Also, Patent Documents 2 and 3 are for preventing sudden acceleration of the vehicle due to misoperation of the accelerator pedal and brake pedal, and are aimed at ensuring the safety of the vehicle, but do not judge the safety of vehicle control instructions from an application manufactured by a third party.
[0010] As described above, vehicle control instructions from an application manufactured by a third party may be output to the vehicle regardless of the driving state of the vehicle. Also, the above-mentioned conventional technologies cannot judge the safety of vehicle control instructions from such an application.
[0011] In view of the above background, an object of the present invention is to provide a movement control device, a moving body, and a control program that can ensure the safety of the moving body while enabling control of the moving body by an application.
Means for Solving the Problems
[0012] The present invention employs the following technical means to solve the above problems. The claims and the reference numerals in parentheses described in this section are an example showing the correspondence relationship with the specific means described in the embodiments described later as one aspect, and do not limit the technical scope of the present invention.
[0013] A movement control device (12) according to an aspect of the present invention includes an analysis unit (20) that analyzes the current driving state of a moving body (10), and a determination unit (24) that determines whether a control instruction from an application (18) is safe in the current driving state. When it is determined by the determination unit that it is safe, the control instruction is output to the control target, and when it is determined by the determination unit that it is not safe, the control instruction is not output to the control target.
[0014] According to this configuration, when it is determined that the control instruction from the application is not safe with respect to the current driving state of the moving body, the control of the moving body based on the control instruction is not performed. Therefore, this configuration can ensure safety even when controlling the moving body by an application manufactured by a third party.
[0015] A moving body according to an aspect of the present invention includes the movement control device described above.
[0016] A control program according to an aspect of the present invention is a control program for causing a computer included in a moving body to function as an analysis unit that analyzes the current driving state of the moving body and a determination unit that determines whether a control instruction from an application is safe in the current driving state. When it is determined by the determination unit that it is safe, the control instruction is output to the control target, and when it is determined by the determination unit that it is not safe, the control instruction is not output to the control target.
Effect of the Invention
[0017] According to the present invention, even if the control of the moving body by the application is enabled, the safety of the moving body can be ensured.
Brief Description of the Drawings
[0018]
Figure 1
Figure 2
Figure 3
Figure 4
Figure 5
Figure 6
Modes for Carrying Out the Invention
[0019] Hereinafter, embodiments of the present invention will be described with reference to the drawings. Note that the embodiments described below show an example of implementing the present invention, and do not limit the present invention to the specific configurations described below. In implementing the present invention, specific configurations according to the embodiments may be appropriately adopted.
[0020] In the present embodiment, an example of the moving body will be described as a vehicle, but it is not limited thereto. The moving body may be, for example, a motorcycle, a heavy machine operated at a work site, an aircraft, or the like.
[0021] FIG. 1 is a functional block diagram of an application instruction output control device 12 which is one of the control devices provided in the vehicle 10 according to the present embodiment.
[0022] The application instruction output control device 12 is one of the electronic control units (ECUs: Electronics Control Unit) mounted on the vehicle 10. The application instruction output control device 12 transmits and receives various data to and from the vehicle sensor 14, the CAN (Controller Area Network) 16, and the third-party application (hereinafter referred to as "third-party app").
[0023] The vehicle sensor 14 is configured to include a plurality of types of sensors mounted on the vehicle 10. The vehicle sensor 14 includes a vehicle speed sensor and an inertial sensor for detecting the driving state of the vehicle 10, an in-vehicle camera for detecting the state of the driver and driving operations, a pedal sensor, and a steering sensor. Further, the vehicle sensor 14 includes an out-vehicle camera, a millimeter-wave radar, and a lidar used for driving assistance or autonomous driving.
[0024] The CAN 16 communicates between the application instruction output control device 12 and other ECUs etc. mounted on the vehicle 10.
[0025] The third-party app 18 of the present embodiment is, as an example, application software manufactured by a third party different from the manufacturer of the vehicle 10. The third-party app 18 outputs an application instruction, which is a control instruction for the vehicle 10, to the application instruction output control device 12. In the following description, the control instruction from the third-party app 18 is referred to as an application instruction.
[0026] The application instruction is, for example, on / off of the air conditioner, adjustment of the seat position, on / off of the wiper, opening / closing of the door, opening / closing of the window, opening / closing of the trunk, on / off of the entertainment function, on / off of the agent dialogue function, on / off of the light, on / off of the hazard lamp, etc.
[0027] The app instruction may be output when a user operates, via a touch panel display or the like provided in the vehicle 10, a third-party app 18 installed in the vehicle 10, or may be output from the third-party app 18 by communicating between the vehicle 10 and a mobile terminal device such as a smartphone owned by the user.
[0028] Note that the third-party app 18 of the present embodiment may have a function that operates independently and is not related to the control of the vehicle 10. This function is, for example, a playback function for music, video, etc., a navigation function, or the like. These functions are executed when the user operates the third-party app 18.
[0029] The app instruction output control device 12 has a function of determining the safety of the app instruction output by the third-party app 18. The app instruction output control device 12 of the present embodiment includes a driving state analysis unit 20, a driving state management unit 22, and a safety determination unit 24.
[0030] The driving state analysis unit 20 analyzes the current driving state of the vehicle 10. The driving state of the vehicle 10 analyzed by the driving state analysis unit 20 is a scene of a predetermined series of driving actions and indicates the control state of the vehicle 10.
[0031] As an example, the control state of the vehicle 10 includes a driving mode and a running state. The driving mode is, for example, a left turn, a right turn, acceleration, a route change, a reverse, a straight drive, etc. The running state is, for example, normal running at a speed of 20 km / h or more and less than 80 km / h, high-speed running at a speed of 80 km / h or more, slow running at a speed of less than 20 km / h, idling, stopping, etc. Note that the control state of the vehicle 10 is determined based on the output value of the vehicle sensor 14, the output value of the ECU obtained via the CAN 16, etc. In the following description, the output value of the vehicle sensor 14 and the output value of the ECU are collectively referred to as vehicle data.
[0032] In addition, the current driving state of the vehicle 10 also includes the driving environment of the vehicle 10. The driving environment of the vehicle 10 is, for example, the weather and location, etc. The weather is, for example, sunny, rainy, snowy, strong wind, etc. The location is a highway, a slope, a speed limit, etc. Note that the driving environment of the vehicle 10 is determined based on data output from a vehicle sensor 14 or an external server that communicates with the vehicle 10, etc.
[0033] The driving state management unit 22 registers the classification content of the driving state for analyzing the current driving state of the vehicle 10 described above, the risk score to be described later, etc. The registration here includes the storage and update of setting contents and setting values.
[0034] The safety determination unit 24 determines whether the control instruction from the third - party application 18 is safe in the current driving state of the vehicle 10. Then, when it is determined by the safety determination unit 24 that it is safe, the application instruction output control device 12 outputs the application instruction to the control target, and when it is determined by the safety determination unit 24 that it is not safe, the application instruction output control device 12 does not output the application instruction to the control target.
[0035] The application instruction is output directly to the control target via the CAN 16 or to the responsible ECU for controlling the control target. Note that the output application instruction is appropriately subjected to command conversion.
[0036] FIG. 2 is a flowchart showing the flow of the driving state analysis process executed by the driving state management unit 22 of the present embodiment. The driving state analysis process is repeatedly executed, for example, when the start button of the vehicle 10 is turned on. Note that the driving state analysis process is executed by a program stored in a storage medium. By executing this program, the method corresponding to the program is executed.
[0037] FIG. 2 determines, as an example, which of a left turn, idling, or the turn signal being off the control state of the vehicle 10 corresponds to. Other control states of the vehicle 10 are determined by a process similar to the process shown in FIG. 2.
[0038] First, in step 100, it is determined whether the vehicle 10 is in motion. If the determination is affirmative, the process proceeds to step 102 to start the left turn determination. On the other hand, if the determination is negative, the process proceeds to step 126 to start the idling determination.
[0039] In step 104, which is reached from step 102, it is determined whether the steering angle has changed to the left. If the determination is affirmative, the process proceeds to step 106; if the determination is negative, the process proceeds to step 108.
[0040] In step 106, the left turn counter C L indicating that the steering angle is to the left is incremented by one, and the process proceeds to step 110.
[0041] In step 108, the left turn counter C L is set to 0 to reset the left turn counter C L and the process proceeds to step 100.
[0042] In step 110, it is determined whether the turn signal is on. If the determination is affirmative, the process proceeds to step 112; if the determination is negative, the process proceeds to step 118.
[0043] In step 112, the turn signal off counter C NW indicating that the turn signal is off is set to 0 to reset the turn signal off counter C NW and the process proceeds to step 114.
[0044] In step 114, it is determined whether the left turn counter C L is 5 or more. If the determination is affirmative, the process proceeds to step 116; if the determination is negative, the process moves to step 100.
[0045] In step 116, it is determined that the control state of the vehicle 10 is in the left turn state, and the process proceeds to step 100.
[0046] In step 118 which is entered when a negative determination is made in step 110, the turn signal off counter C NW is incremented by one and the process proceeds to steps 114 and 120.
[0047] In step 120, the determination of the turn signal being off is started. In the next step 122, it is determined whether the turn signal off counter C NW is 5 or more. If the determination is affirmative, the process proceeds to step 124, and if the determination is negative, the process moves to step 100.
[0048] In step 124, it is determined that the control state of the vehicle 10 is the turn signal off state, and the process proceeds to step 100.
[0049] In step 126 which is entered when a negative determination is made in step 100, the idling determination is started. In the next step 128, the idling counter C I indicating that the vehicle is in the idling state is incremented by one and the process proceeds to step 130.
[0050] In step 130, it is determined whether the idling counter C I is 5 or more. If the determination is affirmative, the process proceeds to step 132, and if the determination is negative, the process moves to step 100.
[0051] In step 132, it is determined that the control state of the vehicle 10 is the idling state, and the process proceeds to step 100.
[0052] As described above, the driving state analysis process of the present embodiment analyzes the current driving state based on pre-classified driving states. That is, in the example of FIG. 2, steps 102 to 118 are the left turn determination, steps 120 to 124 are the turn signal on determination, and steps 126 to 132 are the idling determination, etc., and the driving states are pre-classified. The current driving state is determined as to which of the thus-classified driving states it belongs to. Thereby, the driving state analysis process can determine the current driving state simply and accurately.
[0053] In addition, the driving state analysis process of the present embodiment analyzes which driving state the driving state of the vehicle 10 is based on whether the same control is continuously performed. Specifically, the left turn counter C L , the turn signal off counter C NW , and the idling counter C I By incrementing or resetting the counters that serve as the criteria for determining the driving state, it is determined whether the same control is continuously performed. As a result, the driving state analysis process can analyze the driving state of the vehicle 10 simply and in real time.
[0054] Note that each determination by the driving state analysis process is performed at a predetermined time interval such as every 1 second. As a result, the incrementing or resetting of the counter is performed at 1-second intervals, and it can be determined whether the same control is continuously performed. Note that a shorter determination interval may be required for determining the driving state related to the driving control. For this reason, the determination interval is determined based on the output frequency of the observation target.
[0055] Also, although the threshold value for determining which driving state the current driving state corresponds to is set to 5 for each counter, this is just an example, and other values may be used, and the threshold value may differ according to each driving state. Also, the process of FIG. 2 is just an example, and a process of resetting the counter or other processes may be appropriately included.
[0056] Note that the classified driving states, the above threshold values, etc. are stored in the driving state management unit 22. Also, if the application instruction output control device 12 of the present embodiment can determine the control state of the vehicle 10, it may perform other processes different from the driving state analysis process described with reference to FIG. 2.
[0057] Figure 3 is a flowchart showing the flow of the control permission determination process executed by the application instruction output control device 12 of the present embodiment. The control permission determination process is repeatedly executed while the start button of the vehicle 10 is turned on. Note that the control permission determination process is executed by a program stored in a storage medium. By executing this program, the method corresponding to the program is executed.
[0058] First, in step 200, the driving state analysis unit 20 acquires vehicle data from the vehicle sensor 14 and the CAN 16.
[0059] In the next step 202, the driving state analysis unit 20 performs a driving state analysis process of the vehicle 10.
[0060] In the next step 204, the safety determination unit 24 determines whether an application instruction has been output from the third-party application 18. If the determination is affirmative, the process proceeds to step 206. If the determination is negative, the process returns to step 200, and the acquisition of vehicle data and the determination of the driving state are repeated.
[0061] In step 206, the safety determination unit 24 performs a safety determination to determine whether the application instruction output from the third-party application 18 is safe for the current driving state of the vehicle 10.
[0062] In the next step 208, it is determined whether control based on the application instruction can be implemented based on the result of the safety determination. If the determination is affirmative, the process proceeds to step 210. If the determination is negative, the process proceeds to step 212.
[0063] In step 210, the safety determination unit 24 outputs an application instruction to the control target via the CAN 16 and proceeds to step 200. As a result, the vehicle 10 performs control based on the application instruction.
[0064] In step 212, the safety determination unit 24 notifies the user via the third-party application 18 that control based on the application instruction cannot be implemented, and returns to step 200.
[0065] Here, the safety determination in step 206 will be described. The safety determination unit 24 of the present embodiment determines safety based on the degree of risk according to the control target for which the application instruction is output and the current driving state of the vehicle 10.
[0066] The degree of risk in the present embodiment is calculated based on set values (hereinafter referred to as "risk scores") set for each control target according to the driving state of the vehicle 10. FIG. 4 is a risk matrix showing the risk scores. As shown in FIG. 4, the risk scores are set for each control state and driving environment, which are the driving states of the vehicle 10, for the control target. As an example, they are set in increments of 0.1 between 0 and 1. Note that the risk scores shown in FIG. 4 are only examples, and they are also set according to other control targets and other driving states.
[0067] Then, when the sum of the risk scores corresponding to the control target for which the application instruction is output and the current driving state of the vehicle 10 is equal to or greater than a predetermined value, the safety determination unit 24 determines that it is not safe. This predetermined value is, for example, 1.
[0068] In the example of FIG. 4, when an application instruction indicating that the air conditioner is turned on is output from the third-party application 18 while the vehicle 10 is running, the sum of the risk scores is 0 and less than 1. Therefore, the safety determination unit 24 determines that the application instruction is safe.
[0069] On the other hand, when the vehicle 10 is stopped and an application instruction to close the door is output from the third-party application 18 in a rainy and sloping driving environment, the sum of the risk scores is 1 (0.5 + 0.3 + 0.2) and is 1 or more. Therefore, the safety determination unit 24 determines that the application instruction is not safe.
[0070] Also, for combinations of control targets and driving states with a high degree of risk, such as opening and closing the door while driving, 1 is set as the risk score.
[0071] Figs. 5 and 6 are schematic diagrams showing specific examples of control by the third-party application 18 of the present embodiment.
[0072] Fig. 5 shows the flow when the trunk is unlocked to have the delivery to the user delivered to the trunk of the vehicle 10.
[0073] First, when the user's smartphone receives a delivery notice from the delivery company, the third-party application 18 outputs trunk unlocking as an application instruction. As a result of performing driving state analysis, the application instruction output control device 12 outputs an application command to the responsible ECU via CAN 16, assuming that the trunk unlocking control can be performed because the vehicle 10 is stopped. When the trunk unlocking is completed, the responsible ECU outputs information indicating the completion of implementation to the third-party application 18. Then, the third-party application 18 notifies the user's smartphone of the completion of trunk unlocking.
[0074] Fig. 6 shows the flow when the user sets the opening of the sunroof for regular ventilation.
[0075] First, the user sets to open the sunroof at a predetermined timing for regular ventilation. The third-party application 18 outputs an application instruction to open the sunroof at the set timing. As a result of performing driving state analysis, the application instruction output control device 12 determines that the vehicle 10 is running and the weather is rainy, so the sunroof opening control cannot be performed, and notifies the third-party application 18 that it is not possible to perform. In response to this, the third-party application 18 notifies the user that the sunroof cannot be opened.
[0076] As described above, when the application instruction output control device 12 of the present embodiment determines that the application instruction, which is a control instruction from the third-party application 18, is not safe for the current driving state of the vehicle 10, it does not perform the control of the vehicle 10 based on the application instruction. Therefore, the application instruction output control device 12 of the present embodiment can ensure safety even when enabling the control of the vehicle 10 by the third-party application 18.
[0077] As described above, the present invention has been described using the above embodiments. However, the technical scope of the present invention is not limited to the scope described in the above embodiments. Various changes or improvements can be made to the above embodiments without departing from the gist of the invention, and the forms with such changes or improvements are also included in the technical scope of the present invention.
[0078] The application installed in the moving body such as the vehicle 10 of the above embodiment has been described as being manufactured by a third party. However, the present invention is not limited to this, and the application may be manufactured by the manufacturer of the moving body such as the vehicle 10.
[0079] Each function provided by the application instruction output control device 12 of the above embodiment can also be provided by software and the hardware that executes it, software only, hardware only, or a combined combination thereof. When such a function is provided by an electronic circuit as hardware, each function can also be provided by a digital circuit including a number of logic circuits or an analog circuit.
[0080] Each processor such as the ECU of the above embodiment may have a configuration including at least one arithmetic core such as a CPU (Central Processing Unit) and a GPU (Graphics Processing Unit). Further, the processor may have a configuration further including an FPGA (Field-Programmable Gate Array) and an IP core having other dedicated functions.
[0081] The form of the storage medium that is adopted as the storage unit in the above embodiment and stores each program related to the data storage method of the present disclosure may be appropriately changed. For example, the storage medium is not limited to the configuration provided on the circuit board, and may be provided in the form of a memory card or the like, inserted into the slot portion, and electrically connected to the bus of the computer. Further, the storage medium may be an optical disk and a hard disk drive or the like that serve as a copy base of the program to the computer.
[0082] The control unit and its method in this embodiment may be realized by a dedicated computer that configures a processor programmed to execute one or more functions embodied by a computer program. Alternatively, the device and its method described in this embodiment may be realized by a dedicated hardware logic circuit. Or, the device and its method described in this embodiment may be realized by one or more dedicated computers configured by a combination of a processor that executes a computer program and one or more hardware logic circuits. Also, the computer program may be stored in a computer-readable non-transitory tangible recording medium as instructions to be executed by a computer.
[0083] Also, the processing flow described in the above embodiment is also an example, and unnecessary steps may be deleted, new steps may be added, or the processing order may be changed within the scope not departing from the gist of the present invention.
Explanation of Reference Numerals
[0084] 10 ··· Vehicle, 12 ··· Application Instruction Output Control Device, 18 ··· Third-Party Application, 20 ··· Driving State Analysis Unit, 24 ··· Safety Determination Unit
Claims
1. An analysis unit (20) that analyzes the current driving state of a moving body (10); A determination unit (24) that determines whether a control instruction from an application (18) is safe in the current driving state; Comprising: When it is determined by the determination unit that it is safe, the control instruction is output to a control target, and when it is determined by the determination unit that it is not safe, the control instruction is not output to the control target; The determination unit determines safety based on the degree of risk based on the control target to which the control instruction is output and the current driving state; A moving body control device (12).
2. The moving body control device according to claim 1, wherein the application is manufactured by a third party.
3. The moving body control device according to claim 1 or claim 2, wherein the degree of risk is calculated based on a set value set for each control target according to the driving state of the moving body.
4. The driving state is the control state of the moving body and the driving environment of the moving body, The set value is set for each driving state, The determination unit determines that it is not safe when the sum of the set values corresponding to the control target to which the control instruction is output and the current driving state of the moving body is equal to or greater than a predetermined value. The moving body control device according to claim 3.
5. The moving body control device according to any one of claims 1 to 4, wherein the analysis unit analyzes the current driving state based on a pre-classified driving state.
6. The moving body control device according to any one of claims 1 to 5, wherein the analysis unit analyzes the current driving state based on whether the same control is being continuously performed.
7. A moving body comprising the moving body control device according to any one of claims 1 to 6.
8. A control program for causing a computer included in a moving body to Function as an analysis unit that analyzes the current driving state of the moving body, A determination unit that determines whether a control instruction from an application is safe in the current driving state, Wherein, when it is determined by the determination unit that it is safe, the control instruction is output to a control target, and when it is determined by the determination unit that it is not safe, the control instruction is not output to the control target, The determination unit determines safety based on the degree of risk based on the control target to which the control instruction is output and the current driving state; Control program.
Citation Information
Patent Citations
On-vehicle information terminal
JP2006031203A
Vehicle remote controlling device
JP2006231964A
Monitoring device for vehicle
JP2010231415A
Communication device
JP2020077233A
Vehicle pedal erroneous stepping correspondence control device
JP2021030882A