Method for Identifying False Danger Warnings in a Vehicle-to-Vehicle Network and In-Vehicle Electronic Device Using the Same

The method addresses false danger warnings in VANETs by verifying danger warnings through object detection, ensuring vehicle safety and efficiency by reducing unnecessary resource consumption.

JP7717898B2Active Publication Date: 2025-08-04WISTRON CORP
View PDF 7 Cites 0 Cited by

Patent Information

Application Number
JP2024076958
Authority / Receiving Office
JP · JP
Patent Type
Patents
Current Assignee / Owner
Priority Date
2024-01-09
Filing Date
2024-05-10
Publication Date
2025-08-04
Estimated Expiration
2044-05-10

AI Technical Summary

Technical Problem

The Sybil attack in vehicular ad-hoc networks (VANETs) can create false vehicle-to-vehicle (V2V) information, reducing driving safety by affecting vehicle behavior and causing potential losses.

Method used

A method for identifying false danger warnings in a vehicle-to-vehicle network using an in-vehicle electronic device that performs object detection operations to verify the reliability of danger warnings through a second danger warning based on the object detection operation and predetermined conditions, adjusting driving behavior accordingly.

Benefits of technology

This method effectively identifies and prevents incorrect driving actions due to false danger warnings, ensuring vehicle safety while reducing resource consumption by minimizing continuous object comparison, thus improving driving efficiency.

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure 0007717898000001
    Figure 0007717898000001
  • Figure 0007717898000002
    Figure 0007717898000002
  • Figure 0007717898000003
    Figure 0007717898000003
Patent Text Reader

Abstract

To provide a method for identifying false risk warning in an inter-vehicle network, and also to provide a vehicle-mounted electronic device using the method.SOLUTION: A false risk warning identification method in an inter-vehicle network includes: in response to obtaining a first risk warning based on the inter-vehicle network, determining whether a second risk warning corresponding to the first risk warning based on an object detection operation is obtained; in response to determining that the second risk warning is obtained, determining that the first risk warning is trustworthy; in response to determining that the second risk warning is not obtained, determining whether the first risk warning is trustworthy based on the object detection operation; in response to determining that the first risk warning is trustworthy, adjusting a driving behavior based on the first risk warning or the second risk warning; and ignoring the first risk warning in response to determining that the first risk warning is not trustworthy.SELECTED DRAWING: Figure 2
Need to check novelty before this filing date? Find Prior Art

Description

Technical Field

[0001] The present invention relates to a method for identifying false danger warnings, and more particularly, to a method for identifying false danger warnings in a vehicle - to - vehicle network and an in - vehicle electronic device using the same.

Background Art

[0002] A vehicular ad - hoc network (VANET) can perform vehicle - to - everything (V2X) communication that connects vehicles to all things and provide support for advanced road traffic systems. Therefore, the importance of the network security of VANET is increasing day by day.

Summary of the Invention

Problems to be Solved by the Invention

[0003] There are many network attacks that can be carried out via V2X, and the most widespread and serious network attack is the Sybil attack. The Sybil attack can create false vehicle - to - vehicle (V2V) information that can spread via V2X by a hacker identifying and modifying vehicle - related information. For example, in order to affect the driving behavior of a vehicle that receives false vehicle - to - vehicle network data and generates a danger warning message, by forging and spreading a set of non - existent false vehicle - to - vehicle network data, the driving safety of the vehicle is reduced, causing losses to life and property.

Means for Solving the Problems

[0004] The present invention provides a method for identifying false danger warnings in a vehicle - to - vehicle network that can determine whether the first danger warning is reliable based on an object detection operation, a first danger warning based on a vehicle - to - vehicle network, and a second danger warning based on the object detection operation, and an in - vehicle electronic device using the method.

[0005] One embodiment of the present invention provides a method for identifying false danger warnings in an in-vehicle network applied to in-vehicle electronic devices of a vehicle. The in-vehicle electronic device includes a processor and a communication circuit unit. The in-vehicle electronic device is connected to the in-vehicle network via the communication circuit unit. This method includes the following steps. Instruct the advanced driver assistance system of the vehicle to perform an object detection operation. When a first danger warning based on the in-vehicle network is obtained, in response, determine whether a second danger warning based on the object detection operation corresponding to the first danger warning is obtained. The second danger warning is received from the advanced driver assistance system. When it is determined that the second danger warning based on the object detection operation corresponding to the first danger warning is obtained, in response, determine that the first danger warning based on the in-vehicle network is reliable. When it is determined that the second danger warning based on the object detection operation corresponding to the first danger warning has not been obtained, in response, based on the object detection result of the object detection operation and a plurality of predetermined conditions corresponding to the object detection operation, determine whether the first danger warning based on the in-vehicle network is reliable. When it is determined that the first danger warning based on the in-vehicle network is reliable, in response, adjust the driving behavior of the vehicle based on the first danger warning or the second danger warning. When it is determined that the first danger warning based on the in-vehicle network is not reliable, in response, ignore the first danger warning and do not adjust the driving behavior of the vehicle based on the first danger warning.

[0006] Another embodiment of the present invention further provides an in-vehicle electronic device including a communication circuit unit applied to a vehicle and configured to be connected to an inter-vehicle network, a processor coupled to the communication circuit unit, and a storage circuit unit storing a plurality of instructions. When executed by the processor, the plurality of instructions are to instruct the advanced driver assistance system of the vehicle to perform an object detection operation, to obtain a first danger warning based on the inter-vehicle network, and in response thereto, to determine whether a second danger warning based on the object detection operation corresponding to the first danger warning has been obtained, to determine that the second danger warning is received from the advanced driver assistance system, and when it is determined that the second danger warning based on the object detection operation corresponding to the first danger warning has been obtained, in response thereto, to determine that the first danger warning based on the inter-vehicle network is reliable, and when it is determined that the second danger warning based on the object detection operation corresponding to the first danger warning has not been obtained, in response thereto, to determine whether the first danger warning based on the inter-vehicle network is reliable based on the object detection result of the object detection operation and a plurality of predetermined conditions corresponding to the object detection operation, and when it is determined that the first danger warning based on the inter-vehicle network is reliable, in response thereto, to adjust the driving behavior of the vehicle based on the first danger warning or the second danger warning, and when it is determined that the first danger warning based on the inter-vehicle network is unreliable, in response thereto, to ignore the first danger warning and not adjust the driving behavior of the vehicle based on the first danger warning.

Effect of the Invention

[0007] As described above, the method for identifying a false danger warning in a vehicle - to - vehicle network provided by the present invention and the in - vehicle electronic device using the method can determine whether the first danger warning is reliable based on an object detection operation, a first danger warning based on the vehicle - to - vehicle network, and a second danger warning based on the object detection operation. In this way, a false first danger warning can be identified, preventing an incorrect driving action corresponding to the false first danger warning from occurring and ensuring the safety of the vehicle. Further, since it is only verified whether the first danger warning is reliable when the first danger warning is obtained, it is not necessary to continuously perform object comparison in all surrounding environments at all times to avoid a danger warning due to false vehicle - to - vehicle data. Therefore, the resource consumption of the in - vehicle electronic device is reduced and the driving efficiency is improved.

Brief Description of the Drawings

[0008] The accompanying drawings are included to further understand the principles of the present invention, are incorporated herein, and form a part thereof. The drawings illustrate embodiments of the present invention and, together with the description, serve to explain the principles of the present invention.

[0009]

Figure 1

Figure 2

Figure 3

Figure 4A

Figure 4B

Figure 4C

Figure 5A

Figure 5B

Embodiments for Carrying Out the Invention

[0010] Referring to FIG. 1, in this embodiment, vehicle 10 includes an in - vehicle electronic device 100, an advanced driver assistance system (ADAS) 200, and a driving system 300. The in - vehicle electronic device 100 includes a processor 110, a communication circuit unit 120, a connection interface 130, and a memory circuit unit 140. The processor 110 is coupled to the communication circuit unit 120, the connection interface 130, and the memory circuit unit 140. The in - vehicle electronic device 100 can also be referred to as an on - board unit (OBU).

[0011] The advanced driver assistance system 200 includes a plurality of sensors (e.g., cameras, radars, lidars, ultrasonic transceivers, GPS receivers, accelerometers, inertial meters, gyroscopes, etc.) and a logical operation unit (e.g., a processor or an MCU), plans / supports the driving behavior of vehicle 10, and provides corresponding information to the in - vehicle electronic device 100. The driving system 300 is used to control the movement of vehicle 10. Since the advanced driver assistance system (ADAS) 200 and the driving system 300 can also be integrated into the in - vehicle electronic device 100, the in - vehicle electronic device 100 can control all operations of vehicle 10.

[0012] Processor 110 is, for example, a microprogrammed control unit (MCU), a central processing unit (CPU), a programmable microprocessor, or an application specific integrated circuit (ASIC), a programmable logic device (PLD) or other similar device.

[0013] The communication circuit unit 120 is coupled to the processor 110 and is used to transmit and receive data via wireless communication. In this embodiment, the communication circuit unit 120 has a wireless communication circuit module (not shown) and can support one or a combination of a global system for mobile communication (GSM) system, a WiFi (wireless fidelity) system, different generations of mobile communication technologies (e.g., 3G to 6G), and a Bluetooth (registered trademark) communication technology, but the present invention is not limited thereto. The communication circuit unit 120 is configured to be connected to the vehicle-to-vehicle network 400 via a vehicle-to-vehicle (V2V) communication protocol and a vehicle-to-everything (V2X) communication protocol. The vehicle-to-vehicle network 400 is, for example, a vehicular ad-hoc network (VANET). The processor 110 receives data related to surrounding vehicles (e.g., speed, position, driving direction, brakes, loss of stability, etc., such as the vehicle-to-vehicle network data VD shown in FIG. 1) via the vehicle-to-vehicle network 400 and executes a predetermined application to obtain / generate danger warning information WD1 (also referred to as the first danger warning WD1). That is, the first danger warning WD1 based on the vehicle-to-vehicle network 400 is obtained. In one embodiment, the processor 110 can generate the first danger warning WD1 based on the received vehicle-to-vehicle network data VD. It should be noted that in this embodiment, the processor 110 generates the first danger warning WD1 based on the vehicle-to-vehicle network data VD from the vehicle-to-vehicle network 400, but the present invention is not limited thereto. For example, in another embodiment, the processor 110 can also receive the first danger warning WD1 from the vehicle-to-vehicle network 400.

[0014] When the processor 110 determines that the first danger warning WD1 based on the inter-vehicle network 400 is reliable, the processor 110 can generate a corresponding control command CS and send it to the driving system 300 to adjust the driving behavior of the vehicle 10. Further, in another embodiment, when the processor 110 determines that the first danger warning WD1 based on the inter-vehicle network 400 is reliable, the processor 110 notifies the advanced driver assistance system 200, and the advanced driver assistance system 200 generates a corresponding control command CS and sends it to the driving system 300 to adjust the driving behavior of the vehicle 10.

[0015] The connection interface 130 is coupled to the processor 110. The processor 110 is used to establish a data connection with the advanced driver assistance system 200 via the connection interface 130 and transmit and receive data with the advanced driver assistance system 200. For example, the object detection result OD and the danger warning information WD2 (also referred to as the second danger warning) are received from the advanced driver assistance system 200. In one embodiment, the connection interface 130 includes in-vehicle Ethernet.

[0016] In this embodiment, the first danger warning WD1 and the second danger warning WD2 include a forward collision warning (FCW) and a blind spot warning (BSW). However, the present invention is not limited thereto. For example, the first danger warning WD1 and the second danger warning WD2 may further include other types of danger warnings that can be determined by the processor 100 or the advanced driver assistance system 200 based on the object detection operation or the collected sensing data.

[0017] The memory circuit unit 140 is coupled to the processor 110. The memory circuit unit 140 can store data according to the instructions of the processor 110. The data includes data from external sources such as inter-vehicle network data, and at the same time includes internal data and system data. The system data is, for example, software / firmware for processing inter-vehicle network data from the inter-vehicle network, software / firmware for processing object detection data of the vehicle, and the like. The internal data is, for example, object detection data. The memory circuit unit includes any type of hard disk drive (HDD) or non-volatile memory device (e.g., SSD). In one embodiment, the memory circuit unit further includes a memory for temporarily storing a plurality of instructions or data executed by the processor, such as dynamic random access memory (DRAM), static random access memory (SRAM), and the like.

[0018] In one embodiment, the in-vehicle electronic device 100 further includes an input / output unit including an input device and an output device. The input device is, for example, a microphone, a touch pad, a touch panel, a knob, a button, etc., and is used to enable input of data and control of functions that the user wants to operate. The output device is, for example, a monitor, a speaker, etc., but the present invention is not limited thereto. In one embodiment, the input / output unit may be a touch screen, a head-up display, or a head-mounted display.

[0019] Referring to FIG. 2, in step S210, the processor 110 instructs the advanced driver assistance system 200 of the vehicle 10 to perform an object detection operation. In one embodiment, when it is determined that the advanced driver assistance system 200 does not perform the object detection operation, in response thereto, the processor 110 instructs the advanced driver assistance system 200 to perform the object detection operation.

[0020] Next, in step S220, when the first danger warning WD1 based on the inter-vehicle network 400 is obtained, in response thereto, the processor 110 determines whether a second danger warning WD2 based on an object detection operation corresponding to the first danger warning WD1 has been obtained. Here, the second danger warning WD2 is received from the advanced driver assistance system 200. Briefly, when the vehicle-to-vehicle network data VD is received from the vehicle-to-vehicle network 400 and the corresponding first danger warning WD1 is generated (that is, the first danger warning WD1 based on the vehicle-to-vehicle network 400 is obtained), the processor 110 also determines whether to receive / obtain the corresponding second danger warning WD2 from the advanced driver assistance system 200 accordingly. In one embodiment, the time difference between the time when the second danger warning WD2 is obtained and the time when the first danger warning WD1 is obtained must be less than a predetermined time threshold (for example, 5 seconds or other number of seconds).

[0021] Next, in step S230, when it is determined that the second danger warning WD2 based on the object detection operation corresponding to the first danger warning WD1 has been obtained, in response thereto, the processor 110 determines that the first danger warning WD1 based on the vehicle-to-vehicle network 400 is reliable. That is, after the first danger warning WD1 is obtained, when the processor 110 determines that the second danger warning WD2 corresponding to the first danger warning WD1 has also been obtained from the advanced driver assistance system 200 (for example, when both the first danger warning WD1 and the second danger warning WD2 indicate that the same type or direction of danger has occurred around the vehicle 10), the processor 110 trusts this first danger warning WD1. That is, since the second danger warning WD2 transmitted by the advanced driver assistance system 200 is determined based on the collected sensing data, it is more difficult to forge and has higher reliability. Therefore, the processor 110 uses the second danger warning WD2 to verify the first danger warning WD1 (because the first danger warning WD1 may be a danger warning generated based on false information transmitted to the in-vehicle electronic device 100 via the vehicle-to-vehicle network 400).

[0022] More specifically, the step of determining whether a second danger warning WD2 is obtained based on an object detection operation corresponding to a first danger warning WD1 includes the following steps. Determine whether the type of the first danger warning WD1 is the same as the type of the received second danger warning WD2. If it is determined that the type of the first danger warning WD1 is different from the type of the received second danger warning WD2, in response thereto, it is determined that the second danger warning WD2 based on the object detection operation corresponding to the first danger warning WD1 has not been obtained. If it is determined that the type of the first danger warning WD1 is the same as the type of the received second danger warning WD2, in response thereto, determine whether the dangerous object of the first danger warning WD1 corresponds to the dangerous object of the second danger warning WD2. If it is determined that the dangerous object of the first danger warning WD1 corresponds to the dangerous object of the second danger warning WD2, in response thereto, it is determined that the second danger warning WD2 based on the object detection operation corresponding to the first danger warning WD1 has been obtained. If it is determined that the dangerous object of the first danger warning WD1 does not correspond to the dangerous object of the second danger warning WD2, in response thereto, it is determined that the second danger warning WD2 based on the object detection operation corresponding to the first danger warning WD1 has not been obtained.

[0023] Briefly described, when the second danger warning WD2 is obtained before and after the time point when the first danger warning WD1 is obtained, in response thereto, the processor 110 first determines whether the first danger warning WD1 and the second danger warning WD2 belong to the same type (or the same relative position). If they belong, further determine whether the object of the first danger warning WD1 is similar to or the same as the object of the second danger warning WD2. If they are similar or the same, the processor 110 determines that the obtained second danger warning WD2 corresponds to the first danger warning WD1. If any of the above determinations results in a negative result, the processor 110 can determine that the second danger warning WD2 corresponding to the first danger warning WD1 has not been obtained.

[0024] Next, in step S240, if it is determined that the second danger warning WD2 based on the object detection operation corresponding to the first danger warning WD1 has not been obtained, in response thereto, based on the object detection result of the object detection operation and a plurality of predetermined conditions corresponding to the object detection operation, it is determined whether the first danger warning WD1 based on the vehicle - to - vehicle network 400 is reliable. In the present embodiment, the object detection operation includes one or more of a first object detection operation based on image data, a second object detection operation based on point cloud data, and a third object detection operation based on mixed data. The mixed data includes image data and point cloud data. In another embodiment, the mixed data is fused data generated by image data and point cloud data.

[0025] The first object detection operation based on image data (or pixel array) is excellent in determining the area of the first object, but not excellent in determining the relative distance between the first object and the vehicle. In comparison, the second object detection operation based on point cloud data is not very excellent in determining the area of the second object, but is excellent in determining the relative distance between the second object and the vehicle. On the other hand, the third object detection operation based on mixed data has high reliability when determining the area of the third object and the relative distance of the third object, but requires additional sensing data and computing resources to process the fusion operation of image data and point cloud data.

[0026] Specifically, the processor 110 first identifies the type of object detection operation, and based on different types of object detection operations, analyzes the corresponding object detection results using different predetermined conditions to determine whether the first danger warning WD1 based on the vehicle - to - vehicle network 400 is reliable. That is, since the advanced driver assistance system 200 obtains the object detection result based on the collected perception data, it is difficult to forge the object detection result, and the reliability is further enhanced. The processor 110 also performs analysis by using the received object detection result and the corresponding predetermined conditions to determine whether the received object detection result has an object corresponding to the first danger warning WD1, and accordingly, the first danger warning WD1 can be verified (since the first danger warning WD1 may be a danger warning generated based on false information transmitted to the in - vehicle electronic device 100 via the workshop network 400).

[0027] Next, in step S250, if it is determined that the first danger warning WD1 based on the vehicle - to - vehicle network 400 is reliable, in response, the processor 110 adjusts the driving behavior of the vehicle based on the first danger warning WD1 or the second danger warning WD2.

[0028] Specifically, in one embodiment, after determining that the first danger warning information WD1 is reliable based on the second danger warning information WD2 corresponding to the first danger warning information WD1, the processor 110 notifies the advanced driver assistance system 200 that the first danger warning WD1 is reliable. The advanced driver assistance system 200 generates a corresponding control command CS based on the second danger warning WD2, and transmits the generated control command CS to the driving system 300 to adjust the driving behavior of the vehicle. For example, assuming that the first danger warning WD1 and the second danger warning WD2 are forward collision warnings, the driving system 300 is instructed to perform a braking operation, reduce the driving speed, or change lanes using the generated control command CS, and by adjusting the driving behavior of the vehicle 10, the risk events that may correspond to the first danger warning WD1 and the second danger warning WD2 are avoided.

[0029] In another embodiment, after determining that the first danger warning information WD1 is reliable, the processor 110 also generates a corresponding control command CS based on the first danger warning WD1, and transmits the generated control command CS to the driving system 300 to adjust the driving behavior of the vehicle. For example, assuming that the reliable first danger warning WD1 is a forward collision warning, the control command CS is used to instruct the driving system 300 to perform a braking operation, reduce the driving speed, or change lanes, and by adjusting the driving behavior of the vehicle 10, a risk event that may correspond to the first danger warning WD1 is avoided.

[0030] In comparison, in step S260, if it is determined that the first danger warning WD1 based on the vehicle - to - vehicle network 400 is unreliable, in response, the processor 110 ignores the first danger warning WD1 and does not adjust the driving behavior of the vehicle 10 based on the first danger warning WD1. Then, in step S270, the processor 110 reports the first danger warning WD1 to an authentication agency (for example, the authentication agency TA shown in FIG. 5A) via the vehicle - to - vehicle network 400. For example, in one embodiment, the processor 110 reports vehicle - to - vehicle data that generates an unreliable danger warning and / or the unreliable danger warning to the authentication agency TA, and the authentication agency TA can record the data and its source for further monitoring or listing.

[0031] Hereinafter, with reference to FIGS. 3 and 4A - 4C, other processes will be described in detail.

[0032] Referring to FIG. 3, the advanced driver assistance system 200 performs an object detection operation (S310). Next, the processor 110 determines whether a first danger warning WD1 based on the vehicle - to - vehicle network 400 has been obtained (S320). If obtained, the processor 110 then determines whether a second danger warning WD2 based on the object detection operation corresponding to the first danger warning WD1 has been obtained (S330). If obtained, the processor 110 adjusts the driving behavior of the vehicle 10 based on the first danger warning WD1 or the second danger warning WD2 (S380). If not obtained, the processor 110 further identifies the type of the object detection operation (S340). The processor 110 can obtain and identify the result of the executed object detection operation and related information (for example, the object detection result, the type of the object detection operation) from the advanced driver assistance system 200.

[0033] According to the type of the object detection operation, the processor 110 can adopt different analysis methods and judgment methods to determine whether the first danger warning WD1 is reliable. Specifically, when the object detection operation is a first object detection operation based on image data, the processor 110 executes step S350; when the object detection operation is a second object detection operation based on point cloud data, the processor 110 executes step S360; when the object detection operation is a third object detection operation based on mixed data, the processor 110 executes step S370.

[0034] Explaining in more detail with reference to FIG. 4A, when the object detection operation is a first object detection operation based on image data, the step of determining whether the first danger warning WD1 based on the vehicle - to - vehicle network 400 is reliable based on the object detection result of the object detection operation and a plurality of predetermined conditions corresponding to the object detection operation includes steps S351 - S353.

[0035] In step S351, the processor 110 identifies the first object detection result of the first object detection operation, and the first object feature threshold and the first object probability threshold corresponding to the first object detection operation. The first object detection result includes the detected first object, and the first object feature and the first object probability corresponding to the detected first object. Here, the first object feature threshold and the first object probability threshold are a plurality of first predetermined conditions corresponding to the first object detection operation.

[0036] In this embodiment, when the advanced driver assistance system 200 starts the second danger warning WD2 by performing the first object detection operation, the processor 110 can record the object feature value and the object probability value of the target object corresponding to the second danger warning WD2 at that time. Then, by using the recorded history data, the first object feature threshold and the first object probability threshold are trained by a machine learning algorithm, or the first object feature threshold and the first object probability threshold are calculated by statistics (for example, calculating the average or median). The obtained first object feature threshold and the first object probability threshold can be set as a plurality of first predetermined conditions corresponding to the first object detection operation. Further, in one embodiment, different vehicle speeds may be matched with different first object feature thresholds and first object probability thresholds.

[0037] Returning to FIG. 4A, in step S352, the processor 110 determines whether the first object feature is greater than the first object feature threshold.

[0038] Next, in step S353, the processor 110 determines whether the first object probability is greater than the first object probability threshold.

[0039] If it is determined that the first object feature is greater than the first object feature threshold (determined as "YES" in S352) and the first object probability is greater than the first object probability threshold (determined as "YES" in S353), in response thereto, the processor 110 determines that the first danger warning WD1 based on the vehicle - to - vehicle network 400 is reliable.

[0040] On the other hand, if it is determined that the first object feature is not greater than the first object feature threshold (determined as "NO" in S352), or if it is determined that the first object probability is not greater than the first object probability threshold (determined as "NO" in S353), in response thereto, the processor 110 determines that the first danger warning WD1 based on the inter-vehicle network 400 is unreliable.

[0041] Note that, in another embodiment, the execution order of steps S352 and S353 may be reversed (that is, first execute step S353 and then execute step S352). Also, in this embodiment, the first object feature includes the image feature size or the image feature ratio of the detected first object, and the image feature ratio of the detected first object is the ratio between the image feature size of the detected first object and a predetermined image size of the image data. Here, the first object probability is the existence probability of the detected first object.

[0042] The image feature size is, for example, the image area size covered by a bounding box that marks the detected first object. The image area size can be compared with the area size of the image (that is, the predetermined image size) captured by the advanced driver assistance system 200 for the environment of the vehicle 10 to obtain a ratio, that is, the image feature ratio.

[0043] On the other hand, referring to FIG. 4B, when the object detection operation is a second object detection operation based on point cloud data, the step of determining whether the first danger warning WD1 based on the inter-vehicle network 400 is reliable based on the object detection result of the object detection operation and a plurality of predetermined conditions corresponding to the object detection operation includes steps S361 to S363.

[0044] In step S361, the processor 110 identifies the second object detection result of the second object detection operation, and the second object distance threshold and the second object probability threshold corresponding to the second object detection operation. The second object detection result includes the detected second object, the second object distance, and the second object probability corresponding to the detected second object. Here, the second object distance threshold and the second object probability threshold are a plurality of second predetermined conditions corresponding to the second object detection operation.

[0045] In this embodiment, when the advanced driver assistance system 200 starts the second danger warning WD2 by executing the second object detection operation, the processor 110 can record the object distance value and the object probability value of the target object corresponding to the second danger warning WD2 at that time. Then, by using the recorded history data, the second object distance threshold and the second object probability threshold are trained by a machine learning algorithm or calculated statistically.

[0046] Next, in step S362, the processor 110 determines whether the second object distance is less than the second object distance threshold.

[0047] Next, in step S363, the processor 110 determines whether the second object probability is greater than the second object probability threshold.

[0048] If it is determined that the second object distance is less than the second object distance threshold (determined as "YES" in S362) and the second object probability is greater than the second object probability threshold (determined as "YES" in S363), in response thereto, the processor 110 determines that the first danger warning WD1 based on the vehicle - to - vehicle network 400 is reliable.

[0049] If it is determined that the second object distance is not less than the second object distance threshold (determined as "NO" in S362), or if it is determined that the second object probability is not greater than the second object probability threshold (determined as "NO" in S363), in response thereto, the processor 110 determines that the first danger warning WD1 based on the inter-vehicle network 400 is unreliable.

[0050] Note that, in another embodiment, the execution order of steps S362 and S363 may be reversed. Also, in the present embodiment, the second object distance is the distance between the detected second object and the vehicle 10. Here, the second object probability is the probability of the existence of the detected second object.

[0051] On the other hand, referring to FIG. 4C, when the object detection operation is the third object detection operation based on the mixed data, the step of determining whether the first danger warning WD1 based on the inter-vehicle network 400 is reliable based on the object detection result of the object detection operation and a plurality of predetermined conditions corresponding to the object detection operation includes steps S371 to S374.

[0052] In step S371, the processor 110 identifies the third object detection result of the third object detection operation, and the third object feature threshold, the third object distance threshold, and the third object probability threshold corresponding to the third object detection operation. The third object detection result includes the detected third object, and the third object feature, the third object distance, and the third object probability corresponding to the detected third object. The third object feature threshold, the third object distance threshold, and the third object probability threshold are a plurality of third predetermined conditions corresponding to the third object detection operation. Similar to the method of obtaining the above first object feature threshold, the first object probability threshold, the second object distance threshold, and the second object probability threshold, the third object feature threshold, the third object distance threshold, and the third object probability threshold may be obtained by training a machine learning algorithm or calculated statistically.

[0053] Next, in step S372, the processor 110 determines whether the probability of the third object is greater than the third object probability threshold. If it is determined that the probability of the third object is greater than the third object probability threshold (determined as "YES" in S372), in response, the processor 110 executes step S373. If it is determined that the probability of the third object is not greater than the third object probability threshold (determined as "NO" in S372), in response, the processor 110 determines that the first danger warning WD1 based on the inter-vehicle network 400 is unreliable.

[0054] Next, in step S373, the processor 110 determines whether the third object feature is greater than the third object feature threshold. If it is determined that the third object feature is greater than the third object feature threshold (determined as "YES" in S373), in response, the processor 110 determines that the first danger warning WD1 based on the inter-vehicle network 400 is reliable. If it is determined that the third object feature is not greater than the third object feature threshold (determined as "NO" in S373), in response, the processor 110 executes step S374.

[0055] Next, in step S374, the processor 110 determines whether the third object distance is less than the third object distance threshold. If it is determined that the third object distance is less than the third object distance threshold (determined as "YES" in S374), in response, the processor 110 determines that the first danger warning WD1 based on the inter-vehicle network 400 is reliable. If it is determined that the third object distance is not less than the third object distance threshold (determined as "NO" in S374), in response, the processor 110 determines that the first danger warning WD1 based on the inter-vehicle network 400 is unreliable.

[0056] Note that in another embodiment, the execution order of steps S373 and S374 may be reversed. Also, in this embodiment, the third object feature includes the detected image feature size or image feature ratio of the third object. Here, the detected image feature ratio of the third object is the ratio between the detected image feature size of the third object and the planned image size of the image data, and the third object probability is the existence probability of the detected third object.

[0057] In this embodiment, the detected first object, the detected second object, and the detected third object are objects that may cause danger warnings such as a vehicle ahead or a side vehicle in a blind spot, and can also be referred to as the target first object, the target second object, and the target third object. In one embodiment, the detected first object, the detected second object, and the detected third object are also the objects closest to the vehicle.

[0058] Returning to FIG. 3, when it is determined that the first danger warning WD1 based on the vehicle - to - vehicle network 400 is reliable, in response, the processor 110 adjusts the driving behavior of the vehicle based on the first danger warning or the second danger warning (S380). When it is determined that the first danger warning WD1 based on the vehicle - to - vehicle network 400 is unreliable, in response, the processor 110 ignores the first danger warning WD1 and does not adjust the driving behavior of the vehicle 10 based on the first danger warning WD1 (S390). Further, the processor 110 can report the first danger warning WD1 (or the false vehicle - to - vehicle data corresponding to the first danger warning WD1) to the certification authority (S400).

[0059] For example, referring to FIGS. 5A and 5B, a vehicle - to - vehicle network (e.g., VANET) includes three main entities, namely, an on - vehicle unit OBU, a trusted authority TA, and a roadside unit RSU. The OBUs (i.e., in - vehicle units) of vehicles C1 - C3, the trusted authority TA, and the roadside unit RSU each have a wireless communication circuit unit and are connected to the vehicle - to - vehicle network. The trusted authority TA is responsible for approving the roadside unit RSU and the OBUs on the road. The communication between the OBU and the RSU includes vehicle - to - vehicle (V2V) communication and vehicle - to - infrastructure (V2I) communication. Since a fake attack can use the V2V security application to send fake vehicle - to - vehicle network data VD to the OBU within the vehicle - to - vehicle network, the OBU can generate a fake danger warning.

[0060] Furthermore, assume that vehicle C1 is vehicle 10 and the object detection operation executed by the advanced driver assistance system 200 is a first object detection operation based on image data. The camera of the advanced driver assistance system 200 captures an image IMG1 through the field of view FOV. The advanced driver assistance system 200 can execute a first object detection operation on the image IMG1, identify the target first object C2, and mark the target first object C2 using a bounding box BB. Also, the advanced driver assistance system 200 can determine the image feature size or image feature ratio corresponding to the target first object C2 through the image of the bounding box BB or the target first object C2. The image feature ratio of the target first object C2 is, for example, the ratio obtained by dividing the size of the image IMG2 covered by the bounding box BB by the size of the image IMG1. The target first object C2, the corresponding existence probability of the target first object C2 (i.e., the target first object probability), the image feature size or image feature ratio corresponding to the target first object C2 (i.e., the target first object feature), etc. can be packaged as an object detection result OD and sent to the in - vehicle electronic device 100 of vehicle C1.

[0061] In the first example, assume that vehicle C1 executes a first object detection operation and obtains a forward collision warning (first danger warning WD1) based on the vehicle - to - vehicle network 400 indicating that it is likely to collide with the vehicle C2 ahead. At the same time, the advanced driver assistance system 200 of vehicle C1 transmits the object detection result OD corresponding to vehicle C2 and deems that vehicle C2 does not meet the start condition of the forward collision warning of the advanced driver assistance system 200 (the second danger warning WD2 corresponding to vehicle C2 is not transmitted). Further, the advanced driver assistance system 200 of vehicle C1 transmits the object detection result OD corresponding to vehicle C3 and deems that vehicle C3 meets the start condition of the blind - spot warning of the advanced driver assistance system 200. The advanced driver assistance system 200 senses the danger of vehicle C3 located in the blind - spot area through the detection range DR of the BSW and transmits a blind - spot warning (BSW) corresponding to vehicle C3 (the second danger warning WD2 corresponding to vehicle C3) to the in - vehicle electronic device 100 of vehicle C1. That is, the second danger warning transmitted by the advanced driver assistance system 200 of vehicle C1 does not correspond to the first danger warning (the second danger warning is the BSW corresponding to vehicle C3 and does not correspond to the FCW of vehicle C2 warned by the first danger warning).

[0062] In this case (when it is determined as "NO" in S330 because the acquired second danger warning WD2 does not correspond to the first danger warning WD1), vehicle C1 can further identify that the received object detection result OD is based on the first object detection operation of the image data (S340). At this time, vehicle C1 can access a plurality of first predetermined conditions corresponding to the first object detection operation including the first object feature threshold and the first object probability threshold.

[0063] Next, vehicle C1 further determines whether the first danger warning corresponding to vehicle C2 is reliable based on the first object detection result (for example, the image feature ratio of the target first object C2 and the existence probability of the target first object C2) of the first object detection operation based on the image data and the corresponding first predetermined conditions (for example, the first object feature threshold and the first object probability threshold) (S350).

[0064] When the image feature ratio of the target first object C2 is not greater than the first object feature threshold, or when the existence probability of the target first object C2 is not greater than the first object probability threshold, the processor 110 determines that the first danger warning WD1 is unreliable, that is, there is a possibility that the first danger warning WD1 is false. The processor 110 can ignore the first danger warning WD1 (S390). Further, the processor 110 reports the first danger warning WD1 to the certification authority (S400). For example, in one embodiment, the processor 110 further generates a false danger warning report and transmits, via the communication circuit unit 120, the false danger warning report (for example, including false inter-vehicle network data and / or the corresponding generated false danger warning report) to the certification authority TA (S400). As a result, the certification authority TA records the false danger warning and / or the corresponding false inter-vehicle network data VD that occurred in the current inter-vehicle network 400, and the certification authority TA determines whether to register or block this false danger warning / or the corresponding false inter-vehicle network data VD (and its corresponding entity / source) in the blacklist. In this way, the security of the entire inter-vehicle network can be better maintained.

[0065] Conversely, when the image feature ratio of the target first object C2 is greater than the first object feature threshold and the existence probability of the target first object C2 is greater than the first object probability threshold, the processor 110 determines that the first danger warning WD1 is reliable, that is, the first danger warning WD1 is not false. Based on the first danger warning WD1, the processor 110 can adjust the driving behavior of the vehicle C1 (S380). For example, based on the first danger warning WD1, the processor 110 generates a corresponding control command CS and transmits it to the driving system 300 to adjust the driving behavior of the vehicle C1.

[0066] In the second example, assume that vehicle C1 executes a first object detection operation and obtains a forward collision warning (first danger warning WD1) based on the vehicle-to-vehicle network 400 indicating that it is likely to collide with the vehicle C2 (FCW) ahead. On the other hand, at the same time, assume that the advanced driver assistance system 200 of vehicle C1 transmits the object detection result OD corresponding to vehicle C2, and it is considered that vehicle C2 satisfies the start condition of the forward collision warning of the advanced driver assistance system 200. The advanced driver assistance system 200 transmits a forward collision warning (second danger warning) corresponding to vehicle C2 (FCW) to the in-vehicle electronic device 100 of vehicle C1.

[0067] In this case (when it is determined as "YES" in S330 because the acquired second danger warning WD2 corresponds to the first danger warning WD1), the processor 110 of vehicle C1 determines that the first danger warning WD1 corresponding to vehicle C2 is reliable. Thereafter, the processor 110 adjusts the driving behavior of vehicle C1 based on the first danger warning WD1 (S380). For example, since it is notified to the advanced driver assistance system 200 that the first danger warning WD1 is reliable, the advanced driver assistance system 200 can generate a control command CS based on the second danger warning WD2, transmit it to the driving system 300, and adjust the driving behavior of vehicle C1.

[0068] In the third example, assume that vehicle C1 executes a first object detection operation and obtains a forward collision warning (first danger warning WD1) based on the vehicle-to-vehicle network 400 indicating that it is likely to collide with the vehicle C2 (FCW) ahead. On the other hand, at the same time, assume that the advanced driver assistance system 200 of vehicle C1 transmits the object detection result OD corresponding to vehicle C2, and it is considered that vehicle C2 does not satisfy the start condition of the forward collision warning of the advanced driver assistance system 200. The advanced driver assistance system 200 does not transmit a forward collision warning (second danger warning) corresponding to vehicle C2 (FCW) to the in-vehicle electronic device 100 of vehicle C1. That is, the advanced driver assistance system 200 of vehicle C1 does not transmit a second danger warning corresponding to the first danger warning to the processor 110 of vehicle C1.

[0069] In this case (when it is determined as "NO" in S330 because the second danger warning WD2 corresponding to the first danger warning WD1 has not been acquired), the vehicle C1 can further identify the received object detection result OD (S340). Since the subsequent operations are the same as in the first example, they will not be repeatedly described here.

[0070] As can be seen from the above description, the method for identifying false danger warnings in a vehicle - to - vehicle network and the in - vehicle electronic device using the same have the following advantages: (1) Low computational load: The method for identifying false danger warnings in a vehicle - to - vehicle network provided by the present invention does not need to perform additional calculation operations constantly. By using the data provided by the advanced driver assistance system, it is possible to determine whether the first danger warning is a false danger warning.

[0071] (2) Low latency and low power consumption: Since there is no need to perform additional calculation operations constantly, the latency and power consumption of the in - vehicle electronic device 100 can also be reduced.

[0072] (3) High reliability: The method for identifying false danger warnings in a vehicle - to - vehicle network provided by the present invention uses the existing data provided by the original advanced driver assistance system 200, thus avoiding reliability problems caused by standard compliance.

[0073] As described above, the method for identifying false danger warnings in a vehicle - to - vehicle network provided by the present invention and the in - vehicle electronic device using the method can determine whether the first danger warning is reliable based on an object detection operation, a first danger warning based on a vehicle - to - vehicle network, and a second danger warning based on the object detection operation. This method can then identify a false first danger warning, thereby avoiding incorrect driving actions caused by such false warnings and ensuring the safety of the vehicle. Also, since the first danger warning based on the vehicle - to - vehicle network is confirmed to be reliable only after the first danger warning is obtained, it is not necessary to constantly compare objects in all surrounding environments to avoid danger warnings due to false vehicle - to - vehicle data. Therefore, the resource consumption of the in - vehicle electronic device is reduced and the driving efficiency is improved.

Industrial Applicability

[0074] The method for identifying false danger warnings in a vehicle - to - vehicle network and the in - vehicle electronic device using the same can be applied to a traffic system having a vehicular ad - hoc network (VANET) that performs V2X (vehicle - to - everything) communication. In particular, it can improve the security of the VANET of the traffic system.

Explanation of Reference Numerals

[0075] 10 Vehicle 100 In - vehicle electronic device 200 Advanced driver assistance system 300 Driving system 400 Vehicle - to - vehicle network 110 Processor 120 Communication circuit unit 130 Connection interface 140 Memory circuit unit WD1, WD2 Danger warning OD Object detection result Operation steps of the method for identifying false danger warnings in the inter-vehicle network of S210, S220, S230, S240, S250, S260, S270 Other operation step sequences of the method for identifying false danger warnings in the inter-vehicle network of S310, S320, S330, S340, S350, S360, S370, S380, S390, S400 Processing steps of step S350 in Figure 3 of S351, S352, S353 Processing steps of step S360 in Figure 3 of S361, S362, S363 Processing steps of step S370 in Figure 3 of S371, S372, S373, S374 TA authentication agency RSU Road Side Unit C1, C2, C3 Vehicles / objects FCW Forward Collision Warning BSW Blind Spot Warning IMG1, IMG2 Images FOV Field of View BB Bounding Box

Claims

1. A method for identifying a false danger warning in a vehicle - to - vehicle network applied to an in - vehicle electronic device of a vehicle, wherein the in - vehicle electronic device includes a processor and a communication circuit unit, the in - vehicle electronic device is connected to the vehicle - to - vehicle network via the communication circuit unit, instructing the advanced driver assistance system of the vehicle to execute an object detection operation; when a first danger warning based on the vehicle - to - vehicle network is obtained, in response, determining whether a second danger warning based on the object detection operation corresponding to the first danger warning is obtained, wherein the second danger warning is received from the advanced driver assistance system; when it is determined that the second danger warning based on the object detection operation corresponding to the first danger warning is obtained, in response, determining that the first danger warning based on the vehicle - to - vehicle network is reliable; when it is determined that the second danger warning based on the object detection operation corresponding to the first danger warning has not been obtained, in response, based on the object detection result of the object detection operation and a plurality of predetermined conditions corresponding to the object detection operation, determining whether the first danger warning based on the vehicle - to - vehicle network is reliable; when it is determined that the first danger warning based on the vehicle - to - vehicle network is reliable, in response, adjusting the driving behavior of the vehicle based on the first danger warning or the second danger warning; when it is determined that the first danger warning based on the vehicle - to - vehicle network is unreliable, in response, ignoring the first danger warning and not adjusting the driving behavior of the vehicle based on the first danger warning; A method for identifying a false danger warning in a vehicle - to - vehicle network, including the above steps.

2. Determining whether the second danger warning based on the object detection operation corresponding to the first danger warning is obtained includes: determining whether the type of the first danger warning is the same as the type of the received second danger warning; when it is determined that the type of the first danger warning is different from the type of the received second danger warning, in response, determining that the second danger warning based on the object detection operation corresponding to the first danger warning has not been obtained. When it is determined that the type of the first danger warning is the same as the type of the received second danger warning, in response thereto, it is determined whether the dangerous object of the first danger warning corresponds to the dangerous object of the second danger warning, When it is determined that the dangerous object of the first danger warning corresponds to the dangerous object of the second danger warning, in response thereto, it is determined that the second danger warning based on the object detection operation corresponding to the first danger warning has been obtained, When it is determined that the dangerous object of the first danger warning does not correspond to the dangerous object of the second danger warning, in response thereto, it is determined that the second danger warning based on the object detection operation corresponding to the first danger warning has not been obtained, The method for identifying a false danger warning in a vehicle - to - vehicle network according to claim 1, including the above.

3. The object detection operation is a first object detection operation based on image data, a second object detection operation based on point cloud data, a third object detection operation based on mixed data, The method for identifying a false danger warning in a vehicle - to - vehicle network according to claim 1, including one or more of the above operations, wherein the mixed data includes the image data and the point cloud data.

4. Based on the object detection result of the object detection operation and the plurality of predetermined conditions corresponding to the object detection operation, it is determined whether the first danger warning based on the vehicle - to - vehicle network is reliable. When the object detection operation is the first object detection operation based on the image data, it is to identify the first object detection result of the first object detection operation, and a first object feature threshold and a first object probability threshold corresponding to the first object detection operation, wherein the first object detection result includes the detected first object, and a first object feature and a first object probability corresponding to the detected first object, and the first object feature threshold and the first object probability threshold are a plurality of first predetermined conditions corresponding to the first object detection operation. Determining whether the first object feature is greater than the first object feature threshold. Determining whether the first object probability is greater than the first object probability threshold. When it is determined that the first object feature is greater than the first object feature threshold and the first object probability is greater than the first object probability threshold, in response thereto, it is determined that the first danger warning based on the vehicle - to - vehicle network is reliable. When it is determined that the first object feature is not greater than the first object feature threshold, or when it is determined that the first object probability is not greater than the first object probability threshold, in response thereto, it is determined that the first danger warning based on the inter-vehicle network is unreliable. The method for identifying a false danger warning in an inter-vehicle network according to claim 3, including this.

5. An in-vehicle electronic device applied to a vehicle, A communication circuit unit configured to be connected to an inter-vehicle network, A processor connected to the communication circuit unit, A storage circuit unit for storing a plurality of commands, Including, when the plurality of commands are executed by the processor, the in-vehicle electronic device Instructs the advanced driver assistance system of the vehicle to execute an object detection operation. When a first danger warning based on the inter-vehicle network is obtained, in response thereto, it is to determine whether a second danger warning based on the object detection operation corresponding to the first danger warning has been obtained, and the second danger warning is received from the advanced driver assistance system. When it is determined that the second danger warning based on the object detection operation corresponding to the first danger warning has been obtained, in response thereto, it is determined that the first danger warning based on the inter-vehicle network is reliable. When it is determined that the second danger warning based on the object detection operation corresponding to the first danger warning has not been obtained, in response thereto, based on the object detection result of the object detection operation and a plurality of predetermined conditions corresponding to the object detection operation, it is determined whether the first danger warning based on the inter-vehicle network is reliable. When it is determined that the first danger warning based on the inter-vehicle network is reliable, in response thereto, based on the first danger warning or the second danger warning, the driving behavior of the vehicle is adjusted. When it is determined that the first danger warning based on the inter-vehicle network is unreliable, in response thereto, the first danger warning is ignored and the driving behavior of the vehicle is not adjusted based on the first danger warning. An in-vehicle electronic device configured to execute this.

Citation Information

Patent Citations

  • Travel support device for vehicle

    JP2006172053A

  • Information providing device for vehicle

    JP2006195641A

  • Communication apparatus

    JP2013058140A

  • System and method for detecting and removing malicious vehicles in a vehicle communication network

    JP2013503403A

  • Drive assist system, method, and program

    JP2015118500A