Control mode switching device, control mode switching method, and program

The control mode switching device and method address the challenge of responding to security anomalies in robots by calculating scores for user, robot, and environment abnormalities to switch to safe control modes, ensuring continued safe operation.

JP7719783B2Active Publication Date: 2025-08-06PANASONIC INTELLECTUAL PROPERTY CORP OF AMERICA
View PDF 10 Cites 0 Cited by

Patent Information

Application Number
JP2022546910
Authority / Receiving Office
JP · JP
Patent Type
Patents
Current Assignee / Owner
Priority Date
2020-09-01
Filing Date
2021-07-08
Publication Date
2025-08-06
Estimated Expiration
2041-07-08

AI Technical Summary

Technical Problem

Existing methods for detecting security anomalies in robots operating in public spaces fail to determine the appropriate response to take when an attack is detected, potentially exacerbating damage by simply stopping the robot.

Method used

A control mode switching device and method that assesses user, robot, and environment abnormalities through detection results, calculating a score to switch the control mode to a safe state based on these factors, including remote, manual, and autonomous modes.

Benefits of technology

Enables safe control by dynamically switching modes based on detected abnormalities, minimizing potential damage and ensuring continued safe operation.

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure 0007719783000001
    Figure 0007719783000001
  • Figure 0007719783000002
    Figure 0007719783000002
  • Figure 0007719783000003
    Figure 0007719783000003
Patent Text Reader

Abstract

This control-mode switching device switches a control mode of a robot (10). The control mode includes at least two among a remote control mode, a manual control mode, and an autonomous control mode. In addition, the control-mode switching device comprises: an abnormality detection unit (205) that acquires, on the basis of the control mode and a communication message on a control network in the robot (10), a detection result of at least one abnormality among a user-based abnormality caused by a user control, a robot-based abnormality caused by the control network, an operating-environment-based abnormality caused by an operating environment for the robot (10), and an application-based abnormality caused by an application; and a switch unit (204, 206) that calculates, for each type of the detected abnormality, a score indicating the possibility that the type of said abnormality is a cause of an abnormality occurring in the robot (10), and switches the control mode of the robot (10) on the basis of the calculated score.
Need to check novelty before this filing date? Find Prior Art

Description

[Technical Field]

[0001] The present disclosure relates to a control mode switching device and a control mode switching method for switching the control mode of a robot. [Background technology]

[0002] In recent years, many robotic systems (robots) have come to be used in daily life, and the importance of robots is increasing. In particular, due to the recent labor shortage and the increase in logistics, the spread of self-driving trucks, autonomous delivery robots, etc. is expected.

[0003] Unlike conventional industrial robots that operate in predetermined environments such as factories, such mobility robots are expected to operate in public places such as public roads.

[0004] Robots operating in public places face various security risks, such as unauthorized access and control. Furthermore, security risks associated with robots go beyond the risks of information theft and service failures that exist in conventional IT systems; they can also affect people, objects, and the environment around the robots.

[0005] In such a situation, a method has been disclosed for monitoring whether or not a security anomaly has occurred in, for example, an automobile control network, and taking appropriate measures (see, for example, Patent Document 1). [Prior art documents] [Patent documents]

[0006] [Patent Document 1] Patent No. 6508631 Summary of the Invention [Problem to be solved by the invention]

[0007] However, while the method described in Patent Document 1 can detect the occurrence of an attack on an in-vehicle network, it cannot determine the immediate response that should be taken against the robot being controlled.

[0008] For example, depending on the control state of the robot when an attack is detected, simply stopping the robot may actually increase the damage, so when an attack is detected, it may be necessary to continue controlling the robot in a safe control mode.

[0009] Therefore, the present disclosure provides a control mode switching device and a control mode switching method for continuing safe control. [Means for solving the problem]

[0010] A control mode switching device according to one embodiment of the present disclosure is a control mode switching device that switches the control mode of a robot, the control modes including two or more of a remote control mode controlled by a first user via an external network, a manual control mode controlled by a second user through operation not via the external network, and an autonomous control mode controlled based on sensor information acquired by a sensor provided on the robot. The control mode switching device includes: an acquisition unit that acquires, based on communication messages on a control network within the robot and the control mode, detection results of one or more of a user abnormality caused by control of the first user or the second user, a robot abnormality caused by the control network, an operating environment abnormality caused by the operating environment of the robot, and an application abnormality caused by an application operated by a control device connected to the control network and controlling the robot; and a switching unit that calculates, for each type of detected abnormality based on the acquired detection results, a score indicating the possibility that the type of abnormality is a cause of the occurrence of an abnormality in the robot, and switches the control mode of the robot based on the calculated score.

[0011] A control mode switching method according to one embodiment of the present disclosure is a control mode switching method for switching the control mode of a robot, wherein the control modes include two or more of a remote control mode controlled by a first user via an external network, a manual control mode controlled by a second user through operation not via the external network, and an autonomous control mode controlled based on sensor information acquired by a sensor provided in the robot, and the control mode switching method acquires, based on communication messages on a control network within the robot and the control mode, detection results of one or more of a user abnormality caused by control of the first user or the second user, a robot abnormality caused by the control network, an operating environment abnormality caused by the operating environment of the robot, and an application abnormality caused by an application operated by a control device connected to the control network and controlling the robot, and calculates, for each type of detected abnormality based on the acquired detection results, a score indicating the possibility that the type of abnormality is a cause of the occurrence of an abnormality in the robot, and switches the control mode of the robot based on the calculated score. [Effects of the Invention]

[0012] According to the present disclosure, it is possible to realize a control mode switching device or the like that is capable of continuing safe control. [Brief explanation of the drawings]

[0013] [Figure 1] FIG. 1 is a diagram showing the overall configuration of a robot monitoring system according to an embodiment. [Figure 2] FIG. 2 is a configuration diagram of a robot network installed in a robot according to the embodiment. [Figure 3] FIG. 3 is a configuration diagram of a TCU (Telematic Control Unit) in the embodiment. [Figure 4] FIG. 4 is a configuration diagram of a central ECU (Electronic Control Unit) in the embodiment. [Figure 5] FIG. 5 is a configuration diagram of a user interface ECU in the embodiment. [Figure 6] FIG. 6 is a configuration diagram of an Ethernet (registered trademark, the same applies hereinafter) switch according to the embodiment. [Figure 7] FIG. 7 is a configuration diagram of the autonomous driving ECU in the embodiment. [Figure 8] FIG. 8 is a configuration diagram of a sensor ECU according to the embodiment. [Figure 9] FIG. 9 is a configuration diagram of a fleet management server according to the embodiment. [Figure 10] FIG. 10 is a configuration diagram of a monitoring server according to an embodiment. [Figure 11] FIG. 11 is a configuration diagram of a remote control terminal according to the embodiment. [Figure 12] FIG. 12 is a diagram illustrating an example of an abnormality detection result according to the embodiment. [Figure 13] FIG. 13 is a diagram illustrating an example of a credit score in the embodiment. [Figure 14] FIG. 14 is a diagram showing an example of user information in the embodiment. [Figure 15] FIG. 15 is a diagram showing an example of a control mode in the embodiment. [Figure 16] FIG. 16 is a diagram showing an example of a robot state in the embodiment. [Figure 17] FIG. 17 is a diagram showing an example of account information according to the embodiment. [Figure 18] FIG. 18 is a diagram showing an example of a robot trust score in the embodiment. [Figure 19] FIG. 19 is a diagram showing an example of a user credit score in the embodiment. [Figure 20] FIG. 20 is a diagram showing a control mode switching sequence in response to unauthorized remote control by a user in the embodiment. [Figure 21]FIG. 21 is a diagram showing a control mode switching sequence against an attack by a nearby third party in the embodiment. [Figure 22] FIG. 22 is a flowchart showing the overall abnormality handling process of the central ECU in the embodiment. [Figure 23] FIG. 23 is a flowchart illustrating a credit score update process by the central ECU in the embodiment. [Figure 24] FIG. 24 is a flowchart showing abnormality handling processing by the central ECU in the embodiment. [Figure 25] FIG. 25 is a flowchart showing the control mode switching process of the central ECU in the embodiment. DETAILED DESCRIPTION OF THE INVENTION

[0014] (Background to this disclosure) Before describing the present disclosure, the background to the present disclosure will be described.

[0015] As described in the "Background Art" section, the widespread use of robots such as self-driving trucks and autonomous delivery robots is expected. However, unlike conventional industrial robots that operate in predetermined environments such as factories, these mobility robots are expected to operate in a variety of environments such as public roads, and there remain challenges in achieving fully autonomous control.

[0016] Therefore, in order to respond to situations where autonomous control of robots is difficult and to enable efficient operation of robots, there is a demand for robots that can be remotely monitored or controlled by a remote operator, and fleet management systems that can manage the status of multiple robots.

[0017] By utilizing such technology, it will be possible to expand the remote work market and provide jobs to people who are unable to work due to physical reasons, location, working hours, etc., thereby contributing to resolving many issues.

[0018] On the other hand, there are also cybersecurity issues surrounding robots operating in public spaces. For example, there have been reported cases of remote intrusion into in-vehicle networks and unauthorized control of automobiles. There have also been cases of attacks on ships by sending spoofed signals to the Global Positioning System (GPS) of ship systems to guide them.

[0019] As such, robots operating in public spaces must not only ensure the security of the control network, control applications, control devices, and sensors within the robot, but also take into account the unreliability of the environment in which the robot actually operates and the possibility of physical access by malicious third parties.

[0020] It is also necessary to consider the security of external devices that access the robot, such as servers and terminals on which client applications run.

[0021] Furthermore, with remote-controlled robots, it is expected that an unspecified number of remote operators will control an unspecified number of robots, which will distribute the load among the remote operators and promote efficient sharing of labor by obtaining the necessary labor when needed. In such cases, it is also necessary to take into consideration the possibility of unauthorized control by an unspecified number of remote operators.

[0022] As such, robots operating in public places pose various security risks. Furthermore, security risks associated with robots go beyond the risks of information theft and service failures that exist in conventional IT systems; they can also affect people, objects, and the environment around the robot.

[0023] Security risks for robots operating in public places could lead to physical damage to people, objects, and the environment, so when an attack is detected, it is necessary to immediately transition to a safe state. However, depending on the control state of the robot when an attack is detected, simply stopping the robot may actually exacerbate the damage.

[0024] Therefore, when an attack is detected, a system that can identify the cause of the attack on the robot and continue to control the robot in an appropriate control mode may be required. For example, a system that can continue to control the robot in a safe control mode when an attack is detected may be required.

[0025] Therefore, the inventors of the present application have conducted extensive research into a control mode switching device and a control mode switching method for continuing safe control, and have devised the control mode switching device and the control mode switching method described below.

[0026] A control mode switching device according to one embodiment of the present disclosure is a control mode switching device that switches the control mode of a robot, the control modes including two or more of a remote control mode controlled by a first user via an external network, a manual control mode controlled by a second user through operation not via the external network, and an autonomous control mode controlled based on sensor information acquired by a sensor provided on the robot. The control mode switching device includes: an acquisition unit that acquires, based on communication messages on a control network within the robot and the control mode, detection results of one or more of a user abnormality caused by control of the first user or the second user, a robot abnormality caused by the control network, an operating environment abnormality caused by the operating environment of the robot, and an application abnormality caused by an application operated by a control device connected to the control network and controlling the robot; and a switching unit that calculates, for each type of detected abnormality based on the acquired detection results, a score indicating the possibility that the type of abnormality is a cause of the occurrence of an abnormality in the robot, and switches the control mode of the robot based on the calculated score.

[0027] This makes it possible to switch the control mode depending on the cause of the abnormality based on the detection result of the abnormality in the robot, which is effective for keeping the robot safe. Therefore, it is possible to realize a control mode switching device that can continue safe control.

[0028] Furthermore, for example, the sensor information may include at least one of the robot's position information, acceleration, running speed, and camera images, and the user abnormality may be an abnormality in which, when the control mode is the manual control mode or the remote control mode, the position information deviates from a range previously assumed for control, the acceleration or running speed exceeds a predetermined threshold, or contact or approach with a person or object not previously assumed based on the camera images is detected; the robot abnormality may be an abnormality in which a notification of a failure contained in communication information of the control network or a communication abnormality of the control network is detected; and the operating environment abnormality may be an abnormality in which a discontinuous change or invalid value in the position information, a communication abnormality of the external network, a voltage change in the control network, or disassembly of the robot is detected.

[0029] This makes it possible to detect abnormalities caused by the user, abnormalities caused by the robot, and abnormalities caused by the operating environment, and is effective in switching the control mode appropriately in response to the abnormality.

[0030] Also, for example, the types of abnormalities may include at least two of user, robot, operating environment, and application, and the switching unit may update the user score when the detection result includes the detection of the user abnormality, update the robot score when the detection result includes the detection of the robot abnormality, update the operating environment score when the detection result includes the detection of the operating environment abnormality, and update the application score when the detection result includes the detection of the application abnormality.

[0031] This makes it possible to calculate a score for each candidate cause of the abnormality based on the type of abnormality detected, and effectively switches to an appropriate control mode based on the score.

[0032] Also, for example, updating the score means decreasing the score, and the switching unit may further calculate the score for each of the multiple first users, and when the control mode is the remote control mode and an unauthorized first user whose score is below a first threshold is controlling the robot, at least one of not accepting the control from the unauthorized first user, requesting a change to another first user, or switching the control mode to a control mode other than the remote control mode, and when the robot's score is below a second threshold, switching the control mode to a degenerate mode that limits control of the robot and stops it in a safe state, and when the score of the operating environment is below a third threshold, requesting an alert to be sent to the outside to check the operating environment.

[0033] This makes it possible to determine a method for switching the robot's control mode based on the score value and the current control mode, which is effective in realizing a safer robot.

[0034] Also, for example, when two or more types of scores fall below a predetermined threshold, the switching unit may take action based on each score in the order of priority: the robot's score, the operating environment's score, and the user's score.

[0035] This effectively contributes to the realization of a safety-conscious robot by prioritizing responses to abnormalities caused by the robot that are difficult to deal with safely by simply switching control modes.

[0036] Also, for example, the switching unit may not need to update the user's score if the detection result includes the detection of a user abnormality and any one of the robot's score, the operating environment score, and the application score satisfies a predetermined condition.

[0037] In some cases, a user anomaly may be detected even though it is not caused by the user. In such cases, it is possible to prevent the user's score from being calculated low. In other words, it is possible to calculate the user's score more accurately.

[0038] Further, for example, the applications may include a first application for the remote control mode, a second application for the manual control mode, and a third application for the autonomous control mode, and the detection results may include an abnormality in the first application, an abnormality in the second application, and an abnormality in the third application as the application abnormality, and the switching unit may decrease the score of the first application when an abnormality in the first application is detected, decrease the score of the second application when an abnormality in the second application is detected, decrease the score of the third application when an abnormality in the third application is detected, prohibit the control mode from changing to the remote control mode when the score of the first application is equal to or less than a fourth threshold, prohibit the control mode from changing to the manual control mode when the score of the second application is equal to or less than a fifth threshold, and prohibit the control mode from changing to the autonomous control mode when the score of the third application is equal to or less than a sixth threshold.

[0039] This makes it possible to classify abnormalities inside the robot in detail, allowing the selection of an appropriate (e.g., safe) control mode to switch to, which is effective in improving safety.

[0040] Also, for example, the switching unit may determine whether the robot is in a predetermined control state based on at least one of the sensor information and the state of the robot, and switch the control mode only when the robot is in the predetermined control state.

[0041] This allows the robot to immediately switch control modes while avoiding periods during which unsafe control is being performed, meaning that the robot can switch control modes while remaining safe.

[0042] Furthermore, for example, the switching unit may switch the control mode only when the robot is present within a predetermined range based on the position information of the robot.

[0043] This allows the robot to immediately switch control modes while avoiding periods when control is being performed in areas where safety is a problem, meaning that the control mode can be switched within a range where it can be switched safely.

[0044] Also, for example, the acquisition unit may be realized by an anomaly detection unit that detects one or more of the user anomaly, the robot anomaly, the operating environment anomaly, and the application anomaly based on the communication message and the control mode.

[0045] This allows the control mode switching process to be performed without obtaining a determination result from an external device. For example, even in a poor communication environment, the control mode switching process can be performed more reliably.

[0046] Furthermore, a control mode switching method according to one aspect of the present disclosure is a control mode switching method for switching the control mode of a robot, the control modes including two or more of a remote control mode controlled by a first user via an external network, a manual control mode controlled by a second user through an operation not via the external network, and an autonomous control mode controlled based on sensor information acquired by a sensor provided in the robot, the control mode switching method acquiring detection results of one or more of a user abnormality caused by control of the first user or the second user, a robot abnormality caused by the control network, an operating environment abnormality caused by the operating environment of the robot, and an application abnormality caused by an application operated by a control device connected to the control network and controlling the robot based on a communication message on a control network within the robot and the control mode, calculating a score for each type of detected abnormality based on the acquired detection results, indicating the possibility that the type of abnormality is a cause of the abnormality occurring in the robot, and switching the control mode of the robot based on the calculated score.

[0047] This provides the same effect as the control mode switching device described above.

[0048] These general or specific aspects may be realized as a system, a method, an integrated circuit, a computer program, or a non-transitory recording medium such as a computer-readable CD-ROM, or as any combination of the system, method, integrated circuit, computer program, or recording medium. The program may be pre-stored in the recording medium, or may be supplied to the recording medium via a wide area communication network including the Internet.

[0049] A control mode switching device and a control mode switching method according to embodiments of the present disclosure will be described below with reference to the drawings. Each of the embodiments described below represents a preferred specific example of the present disclosure. In other words, the numerical values, shapes, materials, components, component arrangements and connection configurations, steps, and step order shown in the following embodiments are examples of the present disclosure and are not intended to limit the present disclosure. The present disclosure is defined by the claims. Therefore, among the components in the following embodiments, components not recited in the independent claims that represent the superordinate concept of the present disclosure are not necessarily required to achieve the objectives of the present disclosure, but are described as components that constitute more preferred embodiments.

[0050] Furthermore, each figure is a schematic diagram and is not necessarily an exact illustration. Therefore, for example, the scales and the like do not necessarily match in each figure. Furthermore, in each figure, substantially the same configurations are assigned the same reference numerals, and duplicate explanations are omitted or simplified.

[0051] Furthermore, in this specification, terms indicating relationships between elements such as the same, as well as numerical values and numerical ranges, are not expressions that only express a strict meaning, but also expressions that mean a substantially equivalent range, for example, including a difference of about a few percent (e.g., about 10%).

[0052] (Embodiment) A control mode switching device and a control mode switching method for switching the control mode of a robot that can be controlled by a control device that performs remote, autonomous, or manual control will be described below.

[0053] [1.1 Overall configuration of the robot monitoring system] 1 is a diagram showing the overall configuration of a robot monitoring system according to this embodiment. In FIG. 1, the robot monitoring system includes a robot 10a, a robot 10b, a robot 10c, a network 20, a fleet management server 30, a monitoring server 40, and a remote control terminal 50.

[0054] The robots 10a, 10b, and 10c are robots that perform predetermined tasks in areas including public places such as public roads. Examples include, but are not limited to, self-driving trucks and autonomous delivery robots. The robots 10a, 10b, and 10c are mobile objects that can operate in two or more control modes. The control modes of the robots 10a, 10b, and 10c include two or more of a remote control mode in which the robots are controlled by a first user via an external network, a manual control mode in which the robots are controlled by an operation (e.g., manual operation) from a second user not via an external network, and an autonomous control mode in which the robots 10a, 10b, and 10c are controlled based on sensor information acquired by sensors provided in each of the robots 10a, 10b, and 10c. In this embodiment, the robots 10a, 10b, and 10c have three modes: a remote control mode, a manual control mode, and an autonomous control mode.

[0055] The robots 10a, 10b, and 10c notify the fleet management server 30 and the monitoring server 40 of their robot states, such as their control states, location information, and security alerts, via the network 20. Because the robots 10a, 10b, and 10c have the same configuration, they may be collectively referred to as the robot 10.

[0056] The network 20 connects the robot 10a, the robot 10b, the robot 10c, the fleet management server 30, the monitoring server 40, and the remote control terminal 50 so that they can communicate with each other (for example, wirelessly). The network 20 may include the Internet or a dedicated line. The network 20 is a network that connects the robot 10 with devices external to the robot 10, and is an example of an external network.

[0057] The fleet management server 30 receives the robot status of the robot 10 from the robot 10, and provides the manager of the robot 10 with an interface for managing whether the robot 10 is operating properly.

[0058] The monitoring server 40 is a server that mainly monitors whether any security incidents have occurred in the robot 10, and provides an interface for receiving security alerts from the robot 10 and analyzing and responding to them to a security operation center or a security incident response team.

[0059] The interface for remotely controlling the robot 10 may be provided by the fleet management server 30.

[0060] The remote control terminal 50 is an information processing device for remotely operating the robot 10 operating in a remote operation mode. The remote control terminal 50 generates control signals based on inputs from a remote operator (e.g., accelerator opening, brake pressure, steering angle, etc.) and transmits the control signals to the robot 10 via the network 20, thereby remotely operating the robot 10. The remote operator may, for example, remotely manage the robot 10. The remote operator is an example of a first user. A control mode in which the robot 10 is controlled by the remote operator via the network 20 is an example of a remote control mode.

[0061] [1.2 Robot network configuration] FIG. 2 is a configuration diagram of a robot network system mounted on a robot 10 in this embodiment. In FIG. 2, the robot network system (robot network) includes a TCU (Telematic Control Unit) 100, a central ECU (Electronic Control Unit) 200, a user interface ECU 300, an Ethernet switch 400, an autonomous driving ECU 500, a sensor ECU 600, and an actuator ECU 700. Although omitted in FIG. 2, the robot network may include even more ECUs. The robot network system is an example of a control system. Furthermore, information transmitted and received within the robot network system is an example of a communication message.

[0062] Each ECU is a device that includes, for example, a processor (microprocessor), digital circuits such as memory, analog circuits, and communication circuits. The memory may be a ROM (Read Only Memory), RAM (Random Access Memory), etc., and can store control programs (computer programs) executed by the processor. For example, the ECU realizes various functions by the processor operating in accordance with the control programs. A computer program is composed of a combination of multiple instruction codes for the processor to realize a predetermined function.

[0063] In this embodiment, an example is shown in which each device is connected and communicates via Ethernet (an Ethernet network constructed in accordance with Ethernet), but the robot network is not limited to Ethernet. The robot network may be, for example, a Controller Area Network (CAN) (CAN network), or a network using FlexRay, a dedicated communication line, or wireless communication. In addition, the robot network is a network different from network 20, and is a control network (on-vehicle control network) provided inside (physically inside) the robot 10 to control the robot 10.

[0064] The TCU 100 has a communication interface with a network (external network) outside the robot 10, and has the function of notifying the fleet management server 30 and the monitoring server 40 of analysis reports and the like notified from the central ECU 200 via the network 20.

[0065] The central ECU 200 is an ECU that plays a central role in the robot 10, and various applications run on it to realize the functions of the robot 10.

[0066] The central ECU 200 determines whether the control mode of the robot 10 is remote control, autonomous control, or manual control.

[0067] The central ECU 200 has a function of detecting an abnormality that has occurred in the robot 10, analyzing the abnormality, estimating the cause of the abnormality that has occurred in the robot 10, and switching to a safe control mode according to the current control state of the robot 10. The central ECU 200 may estimate the cause of the abnormality based on, for example, a table in which the abnormality that has occurred (the detected abnormality) is associated with the cause of the abnormality.

[0068] In addition, the central ECU 200 determines the control state of the robot 10 based on the control network information contained in the Ethernet frame received from the Ethernet switch 400, and notifies the TCU 100 of information to be notified to the fleet management server 30.

[0069] Furthermore, the central ECU 200 notifies the TCU 100 of information for notifying the monitoring server 40 of an abnormality that has occurred in the robot 10 .

[0070] The central ECU 200 is an example of a control mode switching device.

[0071] The user interface ECU 300, mainly in the manual control mode, accepts user operations from a user interface for controlling the robot 10 and notifies the central ECU 200 of the operation details for controlling the robot 10, such as the operation details for controlling steering, acceleration / deceleration, etc. Examples of the user interface include an operation device, a touch panel, a USB port, a Wi-Fi (registered trademark, the same applies hereinafter) module, etc. The user is an example of a second user. Control via the user interface ECU 300 is an example of control by operation not via the network 20. A control mode in which the robot 10 is controlled by the user via the user interface ECU 300 (for example, directly controlled) is an example of a manual control mode.

[0072] The Ethernet switch 400 is connected to the central ECU 200, the autonomous driving ECU 500, and the actuator ECU 700 via Ethernet, and transfers Ethernet frames (an example of communication messages) sent from each device to deliver them to the appropriate device.

[0073] The autonomous driving ECU 500 mainly controls the robot 10 when the robot 10 is in autonomous control mode by issuing actuator control commands to the actuator ECU 700 using sensor information contained in the Ethernet frame acquired by the sensor ECU 600.

[0074] The sensor ECU 600 is connected to, for example, a camera that captures images of the periphery of the robot 10, a millimeter-wave radar that detects objects around the robot 10, a speed sensor, an acceleration sensor, or a GPS (Global Positioning System), and notifies other devices of various information included in an Ethernet frame via the Ethernet switch 400. For example, the sensor information includes at least one of the position information, acceleration, running speed, and camera image of the robot 10.

[0075] The actuator ECU 700 controls actuators related to the drive and control of the robot 10, such as a motor and engine for running and flying, and a steering for turning and changing direction.

[0076] Although the present embodiment shows an example in which one sensor ECU 600 and one actuator ECU 700 exist, a plurality of sensor ECUs or a plurality of actuator ECUs may exist on the robot network.

[0077] [1.3 TCU Configuration] 3 is a configuration diagram of the TCU 100 according to this embodiment. In FIG. 3, the TCU 100 includes an external communication unit 101, an application unit 102, an internal communication unit 103, and an intrusion detection unit 104.

[0078] The external communication unit 101 is a communication interface with the network 20, and communicates with the fleet management server 30 and the monitoring server 40, and exchanges information with the application unit 102 regarding the content of the communication.

[0079] The application unit 102 runs an application for notifying the fleet management server 30 or the monitoring server 40 of information regarding the status of the robot 10, and an application for transmitting data to the central ECU 200 based on data received from the network 20.

[0080] The internal communication unit 103 is connected to the central ECU 200 and exchanges Ethernet frames with the application unit 102 .

[0081] The intrusion detection unit 104 is an intrusion detection system (IDS) that monitors the behavior of the application unit 102 to determine whether the application is performing unauthorized operations. For example, the intrusion detection unit 104 monitors the application's CPU (Central Processing Unit) or memory resource usage, communication volume, communication destination, file access permissions, and the launch of unauthorized processes, and monitors whether these values are within reference values. The intrusion detection unit 104 also monitors whether the external communication unit 101 is communicating with an unauthorized access destination, whether malware is included in the communication frame, whether communication volume is increasing above a normal value, etc. If abnormal behavior is observed, the intrusion detection unit 104 requests the application unit 102 to send a security alert in order to notify the application unit 102 of a security alert, and notifies the central ECU 200 of a security abnormality.

[0082] [1.4 Central ECU Configuration] Fig. 4 is a configuration diagram of central ECU 200 in this embodiment. In Fig. 4, central ECU 200 has a communication port unit 201, a host OS (Operating System) unit 202, a guest OS unit 203, a response determination unit 204, an abnormality detection unit 205, a credit score update unit 206, a user management unit 207, an abnormality detection result storage unit 208, a credit score storage unit 209, a user information storage unit 210, and a control mode storage unit 211.

[0083] The communication port unit 201 is connected to and communicates with the TCU 100, the user interface ECU 300, and the Ethernet switch 400. The communication port unit 201 also has a function of transferring communication content to an appropriate network. The communication port unit 201 also transmits and receives information to and from the host OS unit 202.

[0084] The host OS unit 202 is the main operating system (OS) of the central ECU 200, and exchanges information with the communication port unit 201, and notifies the guest OS unit 203 of the communication content. The host OS unit 202 also notifies the response determination unit 204 of the communication content in the same manner.

[0085] The host OS unit 202 periodically notifies the fleet management server 30 and the monitoring server 40 of the status of the robot 10. The status of the robot 10 may include position information, control mode, user information, abnormality detection results, and the like.

[0086] The guest OS unit 203 is an OS on which applications of the central ECU 200 run. Examples of applications running on the central ECU 200 include a manual control application (manual control app) that requests the Ethernet switch 400 to send a control instruction for controlling the robot 10 based on user control information received from the user interface ECU 300, and a remote control application (remote control app) that requests the Ethernet switch 400 to send a control instruction for controlling the robot 10 based on control information of a remote user received from the TCU 100. The guest OS unit 203 is an example of a control device that is connected to a robot network and controls the robot 10. The control device is provided inside the robot 10.

[0087] The response determination unit 204 stores the security alert received from the robot network in the abnormality detection result storage unit 208 .

[0088] Furthermore, when an abnormality occurs in the robot 10, the response determination unit 204 performs processing to switch to a control mode that allows safe control to be continued based on the credit score stored in the credit score storage unit 209 and the control mode of the robot 10 (e.g., the current control mode) stored in the control mode storage unit 211. When an abnormality occurs in the robot 10, the response determination unit 204 makes a determination to switch to a control mode that allows safe control to be continued, for example. The response determination unit 204 switches the control mode of the robot based on the credit score calculated (updated) by the credit score update unit 206. Specifically, when the calculated credit score becomes equal to or less than a predetermined value, the response determination unit 204 changes the control mode of the control mode storage unit 211 according to the type of credit score that has become equal to or less than the predetermined value and the current control mode. Note that the credit score is an example of a score that indicates the possibility of being a cause of the abnormality. Furthermore, changing the control mode of the control mode storage unit 211 is an example of switching the control mode.

[0089] The abnormality detection unit 205 monitors applications running on the guest OS unit 203 and monitors abnormal control based on frames on the control network received from the communication port unit 201. The frames are an example of communication messages.

[0090] In monitoring the applications of the guest OS unit 203, the anomaly detection unit 205 monitors whether the applications are performing unauthorized operations. The anomaly detection unit 205 monitors, for example, the application's CPU or memory resource usage rate, communication volume, communication destination, file access permissions, and the launch of unauthorized processes, and monitors whether they are within reference values.

[0091] In monitoring abnormal control, the abnormality detection unit 205 detects abnormal behavior of the robot 10 related to dangerous control, suspicious control, and the like.

[0092] Examples of abnormal behavior include acceleration exceeding a threshold, activation of a safety mechanism such as an emergency brake, unexpected contact with a person or object by the robot 10, or the robot 10 approaching a person or object to a distance equal to or less than a threshold, deviation from a preset operating route of the robot 10, inconsistency in GPS signals, tampering with the robot 10, disassembly of the robot 10, connection of an unauthorized device to the user interface ECU 300, etc. Tampering with the robot 10 includes, for example, tapping on the internal network (robot network).

[0093] The abnormal behavior may additionally include failure in user authentication, failure in authentication of a communication message, notification of ECU failure information, and the like.

[0094] The anomaly detection unit 205 records the detected anomaly in the anomaly detection result storage unit 208 together with the time of the anomaly detection, and notifies the credit score update unit 206 and the response determination unit 204 that an anomaly has been detected.

[0095] Here, we will explain the abnormalities detected by the abnormality detection unit 205. Through the above-mentioned monitoring, the abnormality detection unit 205 detects one or more of the following abnormalities: a user abnormality caused by control by the first user or the second user, a robot abnormality caused by the control network, an operating environment abnormality caused by the operating environment of the robot 10, and an application abnormality caused by an application operated by a control device that is connected to the control network and controls the robot 10. The abnormality detection unit 205 detects any one of the abnormalities, for example, based on a communication message on the control network within the robot 10 and the current control mode of the robot 10.

[0096] A user abnormality is an abnormality that occurs when the control mode is manual control mode or remote control mode, and the location information deviates from the range of control that is previously assumed, acceleration or driving speed exceeds a predetermined threshold, or contact or approach with a person or object that is not previously assumed based on camera images is detected.

[0097] A robot abnormality is an abnormality detected as either a failure notification included in communication information on the control network or a communication abnormality on the control network.

[0098] An abnormality in the operating environment is an abnormality in which any of the following is detected: a discontinuous change or invalid value in the position information of the robot 10, a communication abnormality in the external network, a voltage change in the control network, or disassembly of the robot 10.

[0099] The anomaly detection unit 205 is an example of an acquisition unit that acquires information about an anomaly by detecting the anomaly. In other words, the acquisition unit is realized by the anomaly detection unit 205 that detects one or more of a user anomaly, a robot anomaly, an operating environment anomaly, and an application anomaly based on a communication message and a control mode.

[0100] In this embodiment, the abnormality detection unit 205 exists inside the central ECU 200, but the function of the abnormality detection unit 205 may be distributed and arranged inside the robot 10, or may be located in the fleet management server 30 or the monitoring server 40. In this case, the communication port unit 201 is an example of an acquisition unit that acquires the detection results of the fleet management server 30 or the monitoring server 40 via the TCU 100.

[0101] The credit score update unit 206 calculates the credit score of an object that is considered to be the cause of an abnormality, based on the abnormality detection result stored in the abnormality detection result storage unit 208 and the control mode stored in the control mode storage unit 211. Objects that are considered to be the cause of an abnormality include, for example, an app (application), a user, a robot, communication, and an operating environment. The app, user, robot, communication, and operating environment are examples of an abnormality object (type of abnormality).

[0102] The trust score is calculated for each application, each user, each device in the robot 10, each communication path, and each operating environment. For example, when only unauthorized control of the route deviation is detected while the robot 10 is being remotely controlled, the trust score update unit 206 determines that the user remotely controlling the robot 10 is not trustworthy and reduces the trust score of the user controlling the robot 10. Furthermore, when a GPS signal inconsistency is detected in addition to unauthorized control of the route deviation, the trust score update unit 206 reduces the trust score of the environment in which the robot 10 is operating and reduces the trust score of the target that is a cause of the detection of an abnormality in the robot 10. The trust score update unit 206 may reduce the trust score of the target that is a cause of the occurrence of an abnormality in the robot 10, i.e., the trust score of the target of the abnormality corresponding to the detected abnormality, based on, for example, a table in which the detected abnormality is associated with the target of the abnormality to be reduced for that abnormality.

[0103] In this way, the credit score update unit 206 calculates the credit score, and if the calculated credit score becomes lower than a predetermined value, notifies the response determination unit 204 that there is a high risk in continuing to control the robot 10 in the current mode. It can also be said that the credit score update unit 206 calculates a credit score for each anomaly target classified based on the detected anomaly, based on the anomaly detection result.

[0104] In the above description, an example has been described in which the credit score update unit 206 decreases the credit score when an abnormality is detected, but the present invention is not limited to this, and the credit score may be increased.

[0105] The above-mentioned response determination unit 204 and credit score update unit 206 are included in a switching unit.

[0106] The user management unit 207 manages users who are logged in to the robot 10. Multiple users can log in to the robot 10, and the logged-in users can use the applications of the robot 10. Each user is given authority to control, monitor, and manage the robot 10 in advance.

[0107] A user who is logged in to the robot 10 and has been granted control rights can remotely control the robot 10, and a user who is logged in to the robot 10 and has been granted monitoring rights can access the sensor information (e.g., camera images) of the robot 10.

[0108] In addition, a user who is logged in to the robot 10 and has been granted administrator privileges will be able to read the abnormality detection results stored in the abnormality detection result storage unit 208, the credit score stored in the credit score storage unit 209, the user information stored in the user information storage unit 210, and the control mode information stored in the control mode storage unit 211, in addition to the control and monitoring rights.

[0109] The user management unit 207 authenticates a user who logs in to the robot 10 and updates the user information stored in the user information storage unit 210 along with the user's authority.

[0110] The abnormality detection result storage unit 208 stores abnormality detection results related to the robot 10. Details of the abnormality detection results stored in the abnormality detection result storage unit 208 will be described later with reference to FIG.

[0111] The credit score holding unit 209 holds a credit score for each object that may be a cause of an abnormality, that is, information such as the likelihood that the object is a cause of an abnormality and the magnitude of the risk, based on the abnormality detection result stored in the abnormality detection result holding unit 208 and the control mode stored in the control mode holding unit 211. Details of the credit scores stored in the credit score holding unit 209 will be described later using FIG. 13.

[0112] The user information storage unit 210 stores information about users who have logged in to the robot 10. Details of the user information stored in the user information storage unit 210 will be described later with reference to FIG.

[0113] The control mode storage unit 211 stores the current control mode of the robot 10. Details of the control modes stored in the control mode storage unit 211 will be described later with reference to FIG.

[0114] [1.5 User Interface ECU Configuration Diagram] 5 is a configuration diagram of the user interface ECU 300 in this embodiment. In FIG. 5, the user interface ECU 300 has a communication port unit 301 and an external device connection unit 302.

[0115] The communication port unit 301 is connected to the central ECU 200 and exchanges messages with the central ECU 200. The communication port unit 301 mainly serves to notify the central ECU 200 of control information received from the external device connection unit 302.

[0116] The external device connection unit 302 is connected to a device or device interface operated by a user who manually controls the robot 10. Examples of externally connected devices include a steering wheel, a controller, a switch, a touch panel, etc. Examples of interfaces for externally connected devices include communication interfaces such as a USB port, a Wi-Fi module, a diagnostic port, and Bluetooth (registered trademark).

[0117] [1.6 Ethernet switch configuration diagram] 6 is a configuration diagram of an Ethernet switch 400 according to this embodiment. In FIG. 6, the Ethernet switch 400 includes a communication port unit 401 and an intrusion detection unit 402.

[0118] The communication port unit 401 has four physical ports, each connected to the central ECU 200, the autonomous driving ECU 500, the sensor ECU 600, and the actuator ECU 700, and transfers frames according to the contents of the received frame.

[0119] Each of the four physical ports also notifies the intrusion detection unit 402 of the received frame in order to monitor the frame.

[0120] The intrusion detection unit 402 is a network IDS (Intrusion Detection System) that monitors frames notified from the communication port unit 401 and checks whether or not unauthorized communication is occurring.

[0121] If it is determined that unauthorized communication is occurring, the intrusion detection unit 402 generates a security alert, requests the communication port unit 401 to transmit the security alert, and notifies the central ECU 200 of the security alert.

[0122] Unauthorized communication can be detected when an address other than a pre-defined address is used, there is an abnormal amount of communication, or the communication pattern matches a predetermined attack pattern.

[0123] [1.7 Autonomous driving ECU configuration diagram] 7 is a configuration diagram of the autonomous driving ECU 500 according to this embodiment. In FIG. 7, the autonomous driving ECU 500 includes a communication port unit 501, an application unit 502, and an application monitoring unit 503.

[0124] The communication port unit 501 is a communication interface that is connected to the Ethernet switch 400 and transmits and receives frames.

[0125] The application unit 502 runs an autonomous control application that operates when the control mode of the robot 10 is the autonomous control mode. The autonomous control application transmits an actuator control instruction frame to the actuator ECU 700 based on the sensor value received from the sensor ECU 600.

[0126] The application monitoring unit 503 monitors the behavior of the application unit 502 and detects security-related events such as the execution of an unauthorized process, detection of abnormal resource usage, access errors of diagnostic commands, and failure to verify a message authentication code included in a frame.

[0127] When an unauthorized security event is detected, the application monitoring unit 503 generates a security alert, requests the communication port unit 501 to transmit the security alert, and notifies the central ECU 200 of the security alert.

[0128] [1.8 Sensor ECU and Actuator ECU Configuration Diagram] Next, a description will be given of the configurations of sensor ECU 600 and actuator ECU 700. The configuration of actuator ECU 700 is basically the same as that of sensor ECU 600, and therefore a description thereof will be omitted. Note that while actuator ECU 700 has the same configuration as sensor ECU 600, there are some configurations with different functions.

[0129] 8 is a configuration diagram of sensor ECU 600 according to this embodiment. In FIG. 8, sensor ECU 600 has a communication port unit 601, an application unit 602, and an external device connection unit 603.

[0130] The communication port unit 601 is a communication interface with the Ethernet switch 400 .

[0131] The application unit 602 configures the sensor information notified from the external device connection unit 603 as an Ethernet frame and issues a transmission request to the communication port unit 601. In the case of the actuator ECU 700, the application unit 602 controls the actuator connected to the external device connection unit 603 based on the sensor information notified from the sensor ECU 600, control instructions notified from the central ECU 200 or the autonomous driving ECU 500, etc.

[0132] The external device connection unit 603 is connected to sensors mounted on the robot 10 that grasp (for example, measure) the surrounding environment and the state of the robot 10, and receives sensor information (for example, measurement results). Examples of the sensors include a traveling speed sensor, an acceleration sensor, a yaw rate sensor, a GPS, a camera, a LiDAR, and a millimeter-wave radar. In the case of the actuator ECU 700, the external device connection unit 603 is connected to an actuator that controls the robot 10. Examples of the actuator include a motor, an engine, and a steering wheel.

[0133] [1.9 Fleet Management Server Configuration Diagram] 9 is a configuration diagram of the fleet management server 30 in this embodiment. In FIG. 9, the fleet management server 30 has a communication unit 31, a fleet management unit 32, a robot status storage unit 33, and an account information storage unit 34.

[0134] The communication unit 31 is connected to the network 20 and is a communication interface for communicating with the robot 10 and the monitoring server 40 .

[0135] The fleet management unit 32 manages the information of the robot 10 received from the communication unit 31. The fleet management unit 32 updates the state of the robot 10 stored in the robot state storage unit 33 in accordance with the control state of the robot 10 received from the communication unit 31.

[0136] In addition, the fleet management unit 32 receives information about the user who is logged in to the robot 10 from the robot 10, and updates the account information stored in the account information storage unit .

[0137] The robot state storage unit 33 stores the state of the robot 10. Details of the robot state stored in the robot state storage unit 33 will be described later with reference to FIG.

[0138] The account information storage unit 34 stores information about users who can access the robot 10. Details of the account information stored in the account information storage unit 34 will be described later with reference to FIG.

[0139] [1.10 Monitoring Server Configuration Diagram] 10 is a configuration diagram of the monitoring server 40 in this embodiment. In FIG. 10, the monitoring server 40 has a communication unit 41, a monitoring unit 42, an analysis interface unit 43, a robot credit score storage unit 44, and a user credit score storage unit 45.

[0140] The communication unit 41 is connected to the network 20 and is a communication interface that communicates with the robot 10 and the fleet management server 30.

[0141] The monitoring unit 42 monitors whether a security incident has occurred in the robot based on the state of the robot 10, security alerts, etc. notified from the robot 10. In addition, the monitoring unit 42 updates the credit score of the robot 10 stored in the robot credit score holding unit 44 and the credit score of the user stored in the user credit score holding unit 45 based on the credit score notified from the robot 10.

[0142] The analysis interface unit 43 is an analysis interface for notifying a security operation center or a security incident response team of a report of a security incident that has occurred when a security incident occurs, or for security analysts to perform detailed analysis.

[0143] The robot credit score holding unit 44 stores the credit score related to the robot 10 based on the credit score notified from the robot 10. Details of the robot credit score stored in the robot credit score holding unit 44 will be described later with reference to FIG. 18.

[0144] The user credit score holding unit 45 stores the credit score related to the user based on the credit score notified from the robot 10. Details of the user credit score stored in the user credit score holding unit 45 will be described later with reference to FIG. 19.

[0145] [1.11 Remote control terminal configuration diagram] 11 is a configuration diagram of a remote control terminal 50 according to this embodiment. In FIG. 11, the remote control terminal 50 includes a communication unit 51, a remote control application unit 52, and a user interface unit 53.

[0146] The communication unit 51 is connected to the network 20 and is a communication interface that communicates with the robot 10 and the fleet management server 30.

[0147] The remote control application unit 52 is an application for remotely controlling the robot 10, and receives user operation details from the user interface unit 53 and notifies the robot 10 of the control details via the communication unit 51.

[0148] The user interface unit 53 provides an interface for the user to control the robot 10. The user interface unit 53 is, for example, a user interface such as a touch panel or a controller.

[0149] [1.12 Example of anomaly detection result] 12 is a diagram showing an example of an abnormality detection result in this embodiment. The abnormality detection result shown in FIG. 12 is stored in the abnormality detection result storage unit 208. The abnormality detection result is not only updated by the abnormality detection unit 205 of the central ECU 200, but can also be updated by a security alert notified from any of the intrusion detection unit 104 of the TCU 100 in the robot 10, the intrusion detection unit 402 of the Ethernet switch 400, and the application monitoring unit 503 of the autonomous driving ECU 500. The abnormality detection result can also be updated by a message notifying of a failure in the robot 10, or the like.

[0150] 12, the abnormality detection result is stored in association with the abnormality detection content, time (e.g., the time of occurrence), and detection device (e.g., the device that detected the abnormality). The time here may be the internal system time measured by central ECU 200, or may be the time included in the security alert.

[0151] FIG. 12 shows that at 10:50:20, the central ECU 200 detected an abnormality in the route deviation, at 10:45:30, the central ECU 200 detected the activation of an emergency brake, and at 10:45:29, the central ECU 200 detected a sudden acceleration or deceleration.

[0152] In the present embodiment, an example has been shown in which the anomaly detection result holds an anomaly detected within the robot 10, but the anomaly does not have to be detected within the robot 10. For example, when an anomaly in the robot 10 is detected on the fleet management server 30, the anomaly detection result may be updated by notifying the robot 10 of a security alert from the fleet management server 30. Similarly, the anomaly detection result may be updated based on a security alert notified from the monitoring server 40.

[0153] [1.13 Credit score example] Fig. 13 is a diagram showing an example of a credit score in this embodiment. The credit score shown in Fig. 13 is stored in the credit score holding unit 209. The credit score is updated, for example, when the credit score update unit 206 updates the anomaly detection result.

[0154] 13, the objects (types of anomalies) that hold the credit scores are classified into apps (applications), users, robots, communications, and operating environments. It is sufficient that the objects are classified into at least one category. It is also possible to determine which object the anomaly falls into based on a table that associates the detected anomaly with the object that caused the anomaly.

[0155] The apps are further classified into a remote control app that runs in the guest OS unit 203 of the central ECU 200, an autonomous control app that runs in the app unit 502 of the autonomous driving ECU 500, and a manual control app that runs in the guest OS unit 203 of the central ECU 200. The remote control app is a first application for the remote control mode and is executed when the control mode of the robot 10 is the remote operation mode. The autonomous control app is a third application for the autonomous control mode and is executed when the control mode of the robot 10 is the autonomous control mode. The manual control app is a second application for the manual control mode and is executed when the control mode of the robot 10 is the manual control mode. For example, the remote control app, the autonomous control app, and the manual control app are executed exclusively.

[0156] A credit score is maintained for each user who accesses and logs into the robot 10.

[0157] The robot 10 is mainly classified into devices related to the control platform of the robot 10, and in FIG. 13, these are classified into a sensor ECU 600 and an actuator ECU 700.

[0158] Communications are further classified into networks within the robot (robot network) and external communications such as network 20.

[0159] The operating environment is classified into the environment in which the robot operates, and in FIG. 13, it is the environment of people or communication infrastructure close to the robot 10 (communication environment).

[0160] In the example of Figure 13, the trust score of the remote control app is 100, the trust score of the autonomous control app is 100, the trust score of the manual control app is 100, the trust score of user A is 80, the trust score of user B is 80, the trust score of the sensor ECU 600 is 100, the trust score of the actuator ECU 700 is 100, the trust score of the robot's internal network (control network) is 100, the trust score of external communication is 100, and the trust score of the person / communication environment is 50.

[0161] The type of abnormality may be an application, a user, a robot, communication, or an operating environment, or may be a remote control application, an autonomous control application, a manual control application, a user A, a user B, a sensor ECU, an actuator ECU, a network within the robot, external communication, or a person / communication environment.

[0162] In addition, the app, user, robot, communication, and operating environment, or the remote control app, autonomous control app, manual control app, user A, user B, sensor ECU, actuator ECU, robot internal network, external communication, and human / communication environment can also be considered types of trust scores.

[0163] The trust score, whose targets are an application and a user, is a score commonly used by the robots 10a to 10c. The target "robot" may also include applications and communications. The initial value of the trust score is set in advance.

[0164] [1.14 Example of user information] Fig. 14 is a diagram showing an example of user information in this embodiment. The user information shown in Fig. 14 is stored in the user information storage unit 210 of the central ECU 200. The user information is stored in such a manner that the ID of the user who has logged in to the robot 10 is associated with the authority of the user.

[0165] FIG. 14 shows an example in which two users are logged in to the robot 10, with user A having control authority and user B having monitoring authority.

[0166] [1.15 Example of control mode] Fig. 15 is a diagram showing an example of a control mode in this embodiment. The control mode shown in Fig. 15 is stored in the control mode storage unit 211 of the central ECU 200. Fig. 15 shows that the control mode of the robot 10 is in a remotely controlled state (remote control mode). For example, the current control mode of the robot 10 is "remote control."

[0167] In this embodiment, the control modes of the robot 10 include a remote control mode in which the robot 10 is remotely controlled, an autonomous control mode in which the robot 10 is autonomously controlled, and a manual control mode in which the robot 10 is manually controlled, but the control modes are not limited to these. Other control modes may include, for example, an emergency control mode.

[0168] 15, the information stored in the control mode storage unit 211 includes only the control mode of the robot 10, but it may also include a state related to the control of the robot 10. The information stored in the control mode storage unit 211 may include, for example, position information of the robot 10, a control state of the robot 10 (running, stopped, etc.), etc. In other words, the control mode storage unit 211 may store position information of the robot 10, a control state of the robot 10, etc.

[0169] [1.16 Example of robot state] Fig. 16 is a diagram showing an example of a robot state in this embodiment. The robot state shown in Fig. 16 is stored in the robot state storage unit 33 of the fleet management server 30. The robot state storage unit 33 stores the states of all robots 10 (robots 10a, 10b, and 10c in the example of Fig. 1) managed by the fleet management server 30.

[0170] 16, the robot 10a is in the remote control mode, has position information of XXX, and is in the sidewalk running state, the robot 10b is in the autonomous control mode, has position information of YYY, and is in the stopped state, and the robot 10c is in the manual control mode, has position information of ZZZ, and is in the stopped state. Note that the robot states shown in FIG. 16 are, for example, the current (e.g., latest) states.

[0171] [1.17 Example of account information] Fig. 17 is a diagram showing an example of account information in this embodiment. The account information shown in Fig. 17 is stored in the account information storage unit 34 of the fleet management server 30. The account information storage unit 34 stores account information of users managed by the fleet management server 30. For example, the account information storage unit 34 stores account information of all users managed by the fleet management server 30.

[0172] The example in FIG. 17 shows that user A is controlling robot 10a, user B is monitoring robot 10a, user C is monitoring robot 10b, and user D is monitoring robot 10c.

[0173] Note that it is not limited to one user controlling or monitoring one robot 10; one user may control or monitor multiple robots 10, or multiple users may control or monitor one robot 10.

[0174] The account information may include not only the user status but also information about the authority granted to the user with respect to the robot 10, connection source information, and the like.

[0175] [1.18 Example of a robot trust score] Fig. 18 is a diagram showing an example of a robot credit score in this embodiment. The robot credit score shown in Fig. 18 is stored in the robot credit score storage unit 44 of the monitoring server 40. The credit score stored in the monitoring server 40 is updated based on the credit score notified by the robot 10. For example, when the credit score shown in Fig. 13 is notified by the robot 10, the credit score of the robot 10 stored in the robot credit score storage unit 44 is updated to the smallest one among the targets excluding the user and the operating environment.

[0176] In the example of FIG. 18, the trust score of the robot 10a is 100, the trust score of the robot 10b is 100, and the trust score of the robot 10c is 50.

[0177] The credit score may be stored in the robot credit score holding unit 44 not for each robot 10 but for each component element of the robot 10 .

[0178] [1.19 Example of user credit score] Fig. 19 is a diagram showing an example of a user credit score in this embodiment. The user credit score shown in Fig. 19 is stored in the user credit score holding unit 45 of the monitoring server 40. The user credit score held in the monitoring server 40 is updated based on the credit score notified by the robot 10. For example, when the credit score shown in Fig. 13 is notified by the robot 10, the credit score of the user stored in the user credit score holding unit 45 is updated to the notified user credit score.

[0179] The example in FIG. 19 shows that user A's credit score is 80, user B's credit score is 80, user C's credit score is 50, and user D's credit score is 20.

[0180] [1.20 Control mode switching sequence for preventing unauthorized remote control by users] Fig. 20 is a diagram showing a control mode switching sequence (control mode switching method) for an unauthorized remote control by a user in this embodiment. Specifically, Fig. 20 is a diagram showing a sequence for switching the control mode of the robot 10a when a legitimate user operating the remote control terminal 50 controls the robot 10a to travel along an unauthorized route.

[0181] (S101) The remote control terminal 50 performs a process of logging in to the robot 10a in response to an operation from a user (remote operator) and starts remote control of the robot 10a. It can also be said that the user operates the remote control terminal 50, logs in to the robot 10a, and starts remote control of the robot 10a.

[0182] (S102) The user management unit 207 of the robot 10a completes user authentication and logs in. Once the login is complete, the user is given control of the robot 10a, and the robot 10a transitions to remote control mode.

[0183] (S103) The robot 10a notifies the fleet management server 30 and the monitoring server 40 of the control mode of the robot 10a and the robot state of the user information (control mode, user information, position information, etc.).

[0184] (S104) The fleet management server 30 updates the robot status stored in the robot status storage unit 33 and the account information stored in the account information storage unit 34 in accordance with the notified robot status.

[0185] (S105) The monitoring server 40 notifies the robot 10a of the credit score of the user who has logged in to the robot 10a, which is stored in the user credit score holding unit 45, in accordance with the notified robot status.

[0186] (S106) The credit score update unit 206 of the robot 10a updates the credit score of the corresponding user stored in the credit score holding unit 209 of the central ECU 200 based on the credit score of the user notified by the monitoring server 40.

[0187] (S107) The user exerts unauthorized control over the robot 10a via the remote control terminal 50. For example, it is assumed that the user controls the robot 10a via the remote control terminal 50 to move beyond an area where control is permitted in advance.

[0188] (S108) The abnormality detection unit 205 of the robot 10a detects (route deviation detection) that the robot 10a has deviated from the predetermined operating route (control route) based on the current location information and the predetermined control area, and notifies the fleet management server 30 and the monitoring server 40 of a security alert.

[0189] (S109) Based on the anomaly detected by the anomaly detection unit 205, which is a deviation from the route, the credit score update unit 206 of the robot 10a reduces the credit score of the user who is the cause of the anomaly. In this way, the credit score update unit 206 reduces the user's credit score when the detection result includes the detection of a user anomaly. Furthermore, the response determination unit 204 may determine to revoke the user's control over the robot 10a when the user's credit score falls below a predetermined value (an example of a first threshold). Note that reducing the score is an example of updating the score.

[0190] (S110) The response determination unit 204 of the robot 10a transitions the control mode from the remote control mode to the autonomous control mode, and notifies the fleet management server 30 and the monitoring server 40 of the updated credit score and the state of the robot 10a in the control mode. Note that the response determination unit 204 may transition the control mode from the remote control mode to the manual control mode in step S110.

[0191] In addition, when there are multiple users, the response judgment unit 204 calculates a credit score for each of the multiple users, and when the control mode is remote control mode and an unauthorized user whose score is below the first threshold is controlling the robot 10a, the response judgment unit 204 may take at least one of the following actions: not accepting control by the unauthorized user, requesting a change to another user, or switching the control mode to a control mode other than remote control mode.

[0192] [1.21 Control mode switching sequence against attacks by a nearby third party] Fig. 21 is a diagram showing a control mode switching sequence (control mode switching method) in response to an attack by a nearby third party in this embodiment. Fig. 21 shows a control mode switching sequence that corresponds to a case where a malicious third party nearby the robot 10a tampers with the position information of the robot 10a and attempts to control the robot 10a fraudulently. It is assumed that the malicious third party nearby the robot 10a has not logged in to the robot 10a.

[0193] (S201) The robot 10a starts autonomous control in the autonomous control mode.

[0194] (S202) The robot 10a notifies the fleet management server 30 and the monitoring server 40 of the state of the control mode.

[0195] (S203) The fleet management server 30 updates the robot status stored in the robot status storage unit 33 based on the notified status of the robot 10a.

[0196] (S204) A malicious third party in the vicinity of the robot 10a tampers with the GPS signal of the robot 10a and illegally controls the robot 10a.

[0197] (S205) The robot 10a detects an abnormality due to a discontinuous change in the GPS signal, a current position based on a falsified GPS signal, and an inconsistency between the current position recognized by a camera or the like, and notifies a security alert to the fleet management server 30 and the monitoring server 40. The operation of step S205 is executed by, for example, the abnormality detection unit 205.

[0198] (S206) The credit score update unit 206 of the robot 10a reduces the credit score of the operating environment based on the abnormality detection result detected by the abnormality detection unit 205. In this way, the credit score update unit 206 reduces the credit score of the operating environment when the detection result includes the detection of an abnormality in the operating environment.

[0199] (S207) When the trust score of the operating environment decreases and falls below a predetermined value (an example of a third threshold), the response determination unit 204 of the robot 10a determines that it is difficult to continue safe autonomous control of the robot 10a, transitions from autonomous control mode to degenerate mode, and notifies the fleet management server 30 and the monitoring server 40 of the status of the robot 10a along with a security alert. The degenerate mode is an autonomous driving mode in which the functions of the robot 10a are limited, in which the robot 10a autonomously travels the minimum necessary distance to an area where it can safely stop, and then stops. Furthermore, when the score of the operating environment falls below a predetermined value (third threshold), the response determination unit 204 may request an alert from an external source (for example, the fleet management server 30 and the monitoring server 40) to check the operating environment.

[0200] (S208) In response to the security alert, the monitoring server 40 logs in to the robot 10a, obtains monitoring rights, and checks the surrounding environment of the robot 10a to confirm that an abnormality has occurred in the operating environment.

[0201] (S209) Upon receiving the notification of the robot status, the fleet management server 30 updates the robot status stored in the robot status storage unit 33.

[0202] 20 and 21, the credit score update unit 206 may decrease the credit score of the robot 10a when the detection result includes the detection of a robot abnormality, and the response determination unit 204 may switch the control mode to a degenerate mode when the credit score of the robot 10a becomes equal to or less than a predetermined value (second threshold). Also, the credit score update unit 206 may decrease the credit score of an application when the detection result includes the detection of an application abnormality, and the response determination unit 204 may switch to a control mode that uses an application other than the application whose credit score becomes equal to or less than the predetermined value when the credit score of the application becomes equal to or less than the predetermined value.

[0203] [1.22 Central ECU abnormality response process overall flowchart] 22 is a flowchart (control mode switching method) showing the entire abnormality response process in the present embodiment by the central ECU 200. FIG. 22 is a flowchart showing the entire process from the detection of an abnormality by the central ECU 200 to the response to the abnormality.

[0204] (S301) The central ECU 200 determines whether an abnormality has been detected or notified. If no abnormality has been detected or notified (No in S301), the central ECU 200 ends the process. If an abnormality has been detected or notified (Yes in S301), the central ECU 200 executes step S302. The detection of an abnormality is determined, for example, by whether the abnormality detection unit 205 has detected an abnormality. The notification of an abnormality is determined, for example, by whether a detection result indicating that an abnormality has been detected is acquired via the TCU 100.

[0205] (S302) The central ECU 200 updates the abnormality detection result stored in the abnormality detection result storage unit 208 based on the detected or notified abnormality.

[0206] (S303) The central ECU 200 updates the credit score stored in the credit score storage unit 209 based on the abnormality detection result stored in the abnormality detection result storage unit 208. Details of the operation of step S303 will be described later with reference to FIG.

[0207] (S304) The central ECU 200 checks whether any of the credit scores stored in the credit score storage unit 209 is equal to or less than a predetermined value (for example, 50). If no credit score is equal to or less than the predetermined value (No in S304), the central ECU 200 ends the processing. If any of the credit scores is equal to or less than the predetermined value (Yes in S304), the central ECU 200 executes step S305.

[0208] (S305) Central ECU 200 performs an abnormality response process based on the credit score that has fallen below the predetermined value and the current control mode, and then ends the process. Details of the operation of step S305 will be described later with reference to FIGS.

[0209] [1.23 Central ECU credit score update flowchart] 23 is a flowchart (control mode switching method) showing the credit score update process of the central ECU 200 in this embodiment. FIG. 23 is a flowchart showing details of the credit score update process of step S303 in FIG. 22 in the central ECU 200.

[0210] (S401) The central ECU 200 determines the type of the detected abnormality. If the detected abnormality is an environmental abnormality, the central ECU 200 executes step S402. If the detected abnormality is an application abnormality, the central ECU 200 executes step S403. If the detected abnormality is a robot abnormality, the central ECU 200 executes step S404. If the detected abnormality is a communication abnormality, the central ECU 200 executes step S405. If the detected abnormality is a user abnormality, the central ECU 200 executes step S406.

[0211] In step S401, the central ECU 200 can also be said to estimate the type (cause of occurrence) of the detected abnormality based on, for example, a table in which the detected abnormality is associated with the type of abnormality corresponding to the abnormality.

[0212] (S402) If the detected abnormality is an environmental abnormality, for example, if an abnormality in the GPS signal, detection of tampering, or blocking of the external communication environment is detected, the trust score update unit 206 of the central ECU 200 decreases the trust score of the operating environment by a predetermined value, for example, 1.

[0213] (S403) If the detected abnormality is an application abnormality, for example, if the application's CPU or memory resource usage, communication volume, communication destination, file access authority, or the launch of an unauthorized process is outside the range of a predetermined rule, the trust score update unit 206 of the central ECU 200 decreases the application's trust score by a predetermined value, for example, by 1. The application's CPU or memory resource usage, communication volume, communication destination, file access authority, or the launch of an unauthorized process may be monitored by the application monitoring unit 503. Furthermore, the abnormality detection unit 205 may determine whether or not the application is outside the range of a predetermined rule. Furthermore, the predetermined rule is that a reference value is satisfied (for example, is equal to or less than a reference value). The reference value is set in advance and stored, for example, in the central ECU 200.

[0214] In this case, the detection result includes, for example, an application abnormality, such as an abnormality in the remote control app (abnormality in the first application), an abnormality in the manual control app (abnormality in the second application), or an abnormality in the autonomous control app (abnormality in the third application). The remote control app, the manual control app, and the autonomous control app are examples of types of abnormality. The trust score update unit 206 decreases the remote control app score when the remote control app is detected, decreases the score of the manual control app when an abnormality in the manual control app is detected, and decreases the score of the autonomous control app when an abnormality in the autonomous control app is detected.

[0215] (S404) If the detected abnormality is a robot abnormality, for example, if a fault code is notified from the ECU, the credit score update unit 206 of the central ECU 200 decreases the credit score of the ECU by a predetermined value, for example, 1.

[0216] (S405) If the detected abnormality is a communication abnormality, for example, if the network IDS notifies the user of an inconsistency in the network traffic volume or communication messages, the credit score update unit 206 of the central ECU 200 decreases the credit score of the network by a predetermined value, for example, 1.

[0217] (S406) If the detected abnormality is a user abnormality, for example, if an abnormality that is thought to have been detected due to user fraud during remote control mode, such as detection of acceleration exceeding a predetermined value, driving control exceeding a predetermined speed, departure from a predetermined area, or activation of a safety mechanism such as an emergency brake, the credit score update unit 206 of the central ECU 200 checks whether there are any objects (abnormalities) other than the user's credit score that have a credit score below a predetermined threshold.

[0218] If there is a trust score below the predetermined value (Yes in S406), the trust score update unit 206 of the central ECU 200 determines that the user abnormality is caused by an object with a low trust score, and terminates the processing. In other words, the user's trust score is not updated. In this way, the trust score update unit 206 does not need to update the user's score if the detection result includes the detection of a user abnormality and any one of the score of the robot 10a, the score of the operating environment, and the score of the application satisfies a predetermined condition. The predetermined condition includes at least one of the score of the robot 10a being below a predetermined value, the score of the operating environment being below a predetermined value, and the score of the application being below a predetermined value.

[0219] If there is no credit score that is equal to or less than the predetermined value (No in S406), the central ECU 200 executes step S407.

[0220] (S407) The credit score update unit 206 of the central ECU 200 decreases the credit score of the corresponding user by a predetermined value, for example, by one.

[0221] In this way, the credit score update unit 206 estimates the cause of the anomaly from the detected anomaly, and reduces the credit score corresponding to the estimated cause of the anomaly.

[0222] 23 is executed, for example, every time an abnormality is detected. In other words, every time an abnormality is detected, one of the credit scores is updated. Note that the determination in step S406 does not necessarily have to be performed.

[0223] [1.24 Central ECU abnormality response flowchart] 24 is a flowchart (control mode switching method) showing the abnormality handling process of the central ECU 200 in this embodiment. FIG. 24 is a flowchart showing details of the abnormality handling process shown in step S305 of FIG.

[0224] (S501) The response determination unit 204 of the central ECU 200 checks the type of credit score that has fallen below the threshold. If the type of credit score that has fallen below the threshold is the environment (for example, the operating environment), the central ECU 200 executes step S502. If the type of credit score that has fallen below the threshold is the app, the central ECU 200 executes step S503. If the type of credit score that has fallen below the threshold is the robot 10a, the central ECU 200 executes step S506. If the type of credit score that has fallen below the threshold is communication, the central ECU 200 executes step S507. If the type of credit score that has fallen below the threshold is the user, the central ECU 200 executes step S508.

[0225] (S502) The response determination unit 204 of the central ECU 200 sends a monitoring request or notification to the fleet management server 30 and the monitoring server 40.

[0226] (S503) The response determination unit 204 of the central ECU 200 prohibits the control mode via the corresponding app (the app whose trust score is below a threshold). For example, the response determination unit 204 of the central ECU 200 determines to prohibit the autonomous control mode if the trust score of the autonomous control app is below a predetermined threshold (sixth threshold), to prohibit the remote control mode if the trust score of the remote control app is below a predetermined threshold (fourth threshold), and to prohibit the manual control mode if the trust score of the manual control app is below a predetermined threshold (fifth threshold). The determination results may be notified to the fleet management server 30 and the monitoring server 40.

[0227] The fourth to sixth threshold values may be the same value or may be different values from each other.

[0228] (S504) The response determination unit 204 of the central ECU 200 checks whether the current control mode stored in the control mode storage unit 211 is prohibited. If the current control mode is prohibited (Yes in S504), the response determination unit 204 executes step S505, and if the current control mode is not prohibited (No in S504), the process ends.

[0229] (S505) The response determination unit 204 of the central ECU 200 switches the control mode and ends the process. Details of the operation of step S505 will be described later with reference to FIG.

[0230] (S506) The response determination unit 204 of the central ECU 200 switches the control mode and ends the process. Details of the operation in step S506 will be described later with reference to FIG.

[0231] (S507) The response determination unit 204 of the central ECU 200 notifies the monitoring server 40 of a security alert requesting analysis of the network abnormality, and then ends the process.

[0232] (S508) The response determination unit 204 of the central ECU 200 determines to revoke the control right of the corresponding user. Specifically, the response determination unit 204 of the central ECU 200 determines to change the authority of the corresponding user to the monitoring right or to prohibit the corresponding user from logging in to the robot 10.

[0233] (S509) The response determination unit 204 of the central ECU 200 switches the control mode or switches to remote control by an alternative user, and ends the process. Details of the operation of switching the control mode in step S509 will be described later with reference to FIG.

[0234] Note that, when two or more types of credit scores are equal to or lower than predetermined thresholds, the response determination unit 204 may take responses based on each score in the following order of priority: the credit score of the robot 10a, the credit score of the operating environment, and the credit score of the user. That is, priorities may be set for the responses to be taken. The priorities are set in advance and stored in the central ECU 200. When the credit score of the robot 10a and the credit score of the user are equal to or lower than predetermined thresholds, the response determination unit 204 may prioritize execution of the process of step S506 over the process of step S508. "Prioritizing execution" includes, for example, executing the process of step S506 before the process of step S508, or executing only the process of step S506 out of steps S506 and S508.

[0235] [1.25 Central ECU control mode switching flowchart] Fig. 25 is a flowchart (control mode switching method) showing the control mode switching process of central ECU 200 in this embodiment. Fig. 25 is a flowchart showing details of the operation of central ECU 200 to switch the control mode in steps S505, S506, and S509 in Fig. 24. The process shown in Fig. 25 is executed in steps S505, S506, and S509 shown in Fig. 24. The operation shown in Fig. 25 is, for example, a common operation in steps S505, S506, and S509.

[0236] (S601) The response determination unit 204 of the central ECU 200 determines whether the current position of the robot 10a is in an area where the control mode can be switched and whether the control mode can be switched. The area where the control mode can be switched is determined in advance, and a location where the robot 10a can stop safely is selected as the area where the control mode can be switched.

[0237] The control mode switchable state is a state in which the robot 10a is under predetermined control and it is not difficult to safely switch the control subject. The predetermined control state is, for example, when the robot 10a is in a running operation (during running control). For example, the control mode switchable state is not when the robot 10a is in a running operation, and the control mode switchable state is when the robot is stopped.

[0238] If the response determination unit 204 of the central ECU 200 determines that the control mode can be switched (Yes in S601), it executes step S602. If the response determination unit 204 of the central ECU 200 determines that the control mode cannot be switched (No in S601), it executes step S606.

[0239] In step S601, it is sufficient to determine whether the current position of the robot 10a is in an area where the control mode can be switched and whether the control mode can be switched based on at least one of the sensor information and the state of the robot 10a. This allows the control mode to be switched only when the robot 10a is in a predetermined control state and when the robot 10a is within a predetermined range.

[0240] (S602) The response determination unit 204 of the central ECU 200 checks whether continued control of the robot 10a is necessary and whether the robot is abnormal (for example, whether the trust score of the robot 10a is equal to or less than a predetermined threshold). If continued control of the robot 10a is not necessary or the robot is abnormal (for example, the trust score of the robot 10a is equal to or less than a predetermined value) (No in S602), the response determination unit 204 executes step S607. If continued control of the robot 10a is necessary and the robot is not abnormal (for example, the trust score of the robot 10a is greater than a predetermined value) (Yes in S602), the response determination unit 204 executes step S603.

[0241] Continuing control of the robot 10a is necessary when the robot 10a is performing a specified task (such as carrying luggage) and interrupting control of the robot 10a would reduce the availability of the service, or when interrupting control of the robot 10a would have an impact on the safety of surrounding people, objects, and the environment.

[0242] (S603) The response determination unit 204 of the central ECU 200 checks whether there is a user abnormality (for example, the trust score of the user who currently has control is equal to or lower than a predetermined value) and whether the control mode is the remote control mode. If there is a user abnormality (for example, the trust score is equal to or lower than a predetermined value) and the control mode is the remote control mode (Yes in S603), the response determination unit 204 executes step S604. If there is no user abnormality (for example, the trust score is higher than a predetermined value) or the control mode is not the remote control mode (No in S603), the response determination unit 204 executes step S608.

[0243] For example, if there is no user abnormality but the remote control mode is active, if there is a user abnormality but the remote control mode is not active, or if there is an application abnormality, the determination in step S603 is No. In other words, if the determination in step S603 is No, there remains a possibility that the abnormality is a user abnormality or an application abnormality.

[0244] (S604) The response determination unit 204 of the central ECU 200 determines whether there is a user to whom control authority can be granted. The response determination unit 204 makes the determination in step S604 based on, for example, at least one of the account information shown in FIG. 17 and the user credit score shown in FIG. 19.

[0245] The user who can be given control rights may be, for example, a user who has already logged in to the robot 10a and has been given monitoring rights, or may be a user who has been newly assigned by the fleet management server 30.

[0246] If there is a user to whom the control right is to be given (Yes in S604), the response determination unit 204 executes step S605. If there is no user to whom the control right is to be given (No in S604), the response determination unit 204 executes step S609.

[0247] (S605) The response determination unit 204 of the central ECU 200 gives the control right to a user who can be given the control right, continues the remote control mode, and then ends the mode. In other words, the response determination unit 204 switches the control right of the robot 10a from the user determined to be abnormal to the user determined to be Yes in step S604 through steps S508 (FIG. 24) and S605. As a result, the user determined to be abnormal can no longer remotely operate the robot 10a. Switching users is also included in switching control modes.

[0248] (S606) The response determination unit 204 of the central ECU 200 shifts the control mode to the degenerate mode, moves the robot 10a to the control mode switchable area, and executes step S602 in a switchable state. For example, the response determination unit 204 executes step S602 after moving the robot 10a to the control mode switchable area and stopping it.

[0249] (S607) The response determination unit 204 of the central ECU 200 stops the robot 10a in a safe area and ends the process. An area where there is no problem even if the robot 10a does not move is selected as the safe area. Stopping the robot 10a in a safe area is also included in switching the control mode.

[0250] (S608) The response determination unit 204 of the central ECU 200 checks whether the current control mode is the remote control mode. The response determination unit 204 makes the determination of step S608 based on, for example, the current control mode stored in the control mode storage unit 211. If the current control mode is the remote control mode (Yes in S608), the response determination unit 204 executes step S609. If the current mode is not the remote control mode (No in S608), the response determination unit 204 executes step S610.

[0251] (S609) The response determination unit 204 of the central ECU 200 switches the control mode to either the autonomous control mode or the manual control mode, whichever is not prohibited, and continues and ends the control. If the determination in step S608 is Yes, the response determination unit 204 switches to a control mode that uses another application, since there is a possibility that an abnormality exists in the remote control application.

[0252] If none of the control modes are prohibited, the response determination unit 204 may switch to a control mode using an app with a higher trust score, or may switch to a control mode that requires a shorter time until control switching. Furthermore, if none of the control modes are prohibited, the response determination unit 204 stops control of the robot 10a. For example, the response determination unit 204 may stop the robot 10a in a safe area, similar to step S607.

[0253] (S610) The response determination unit 204 of the central ECU 200 checks whether the current control mode is the autonomous control mode. The response determination unit 204 makes the determination of step S610 based on, for example, the control mode stored in the control mode storage unit 211. If the current control mode is the autonomous control mode (Yes in S610), the response determination unit 204 executes step S611. If the current control mode is not the autonomous control mode (No in S610), the response determination unit 204 executes step S612.

[0254] (S611) The response determination unit 204 of the central ECU 200 switches the control mode to the remote control mode or the manual control mode and ends the process. If the determination result in step S610 is Yes, the response determination unit 204 switches to a control mode that uses another application because there is a possibility that an abnormality is in the autonomous control application.

[0255] (S612) The response determination unit 204 of the central ECU 200 switches the control mode to the autonomous control mode or the remote control mode and ends the process. If the result of step S610 is No, the response determination unit 204 switches to a control mode that uses another application, since there is a possibility that an abnormality exists in the manual control application.

[0256] [1.26 Effect of the embodiment] The robot control mode switching method according to this embodiment makes it possible to analyze the cause of a security abnormality and select a safe control mode in accordance with the security abnormality detected in the robot system and the current control state of the robot 10. This makes it possible to realize a robot system that can continue safe control even when an abnormality is detected.

[0257] [Other variations] Although the present disclosure has been described based on the above-described embodiments, it goes without saying that the present disclosure is not limited to the above-described embodiments. The following cases are also included in the present disclosure.

[0258] (1) In the above embodiments, no specific services or applications are specified for the robot system, but any robot may be the target. For example, the robot may be an autonomous vehicle, a marine system, a mobility robot such as a drone, or a robot that performs a specific task, such as an industrial robot or a humanoid robot. Furthermore, the robot may be entirely mobile, or only a part of the robot (e.g., a robot arm) may be movable. The robot in this specification also includes non-mobile robots.

[0259] (2) In the above embodiment, the robot has three control methods: autonomous control, manual control, and remote control. However, it is not necessary to have three control means. For example, it is sufficient to have at least two control modes, such as remote control and autonomous control. Furthermore, the control modes are not limited to these three. For example, the robot may have other control modes, such as a cooperative control mode in which it operates in cooperation with other robots, or a control mode in which it operates according to commands from a control center.

[0260] (3) In the above embodiment, an example was shown in which a remote control terminal connected to a robot and authenticated the user, causing the robot to transition to remote control mode. However, user authentication may be performed by a fleet management server. Furthermore, the remote control terminal may control the robot via the fleet management server. This allows the fleet management server to check the user's operation history, thereby improving safety.

[0261] (4) In the above embodiment, the robot monitoring system has been described in which the functions are separated between the fleet management server and the monitoring server. However, the functions of the fleet management server and the monitoring server may be integrated.

[0262] (5) In the above embodiment, the central ECU periodically notifies the fleet management server and the monitoring server of the robot's status. However, the robot's status does not have to be notified periodically. For example, the central ECU may notify the robot's status in response to a request from the fleet management server or the monitoring server, or may notify the robot's status when an event occurs within the robot, such as when a user logs in, when the control mode changes, or when an abnormality is detected. This reduces the amount of communication between the robot and the server.

[0263] (6) In the above embodiment, the response determination unit is located within the robot, but the control mode switching decision may be made on a monitoring server or fleet management server. This makes it possible to make response decisions using area information on the server, the status of nearby robots, and the like. On the other hand, if the decision is made on the robot, immediate control mode switching and switching of the control mode even in situations where communication with the server is difficult may be possible, thereby increasing safety.

[0264] (7) In the above embodiment, an example was shown in which the central ECU has a guest OS section running on a virtual machine using a hypervisor or the like, but the central ECU does not have to be equipped with a hypervisor or virtualization technology.

[0265] (8) In the above embodiment, the central ECU updated the credit score when an abnormality was detected. However, the timing for updating the credit score does not have to be the timing when an abnormality was detected. For example, the credit score may be updated by referring to the abnormality detection result storage unit at predetermined intervals. At this time, the credit score may be updated by comprehensively assessing newly detected abnormality detection results since the last credit score update. For example, if the abnormality detection results simultaneously detect a user's reckless driving and an abnormality in the operating environment, it may be determined that the user's reckless driving abnormality was detected as a result of the abnormality in the operating environment, and the user's credit score may not be reduced due to the user's reckless driving.

[0266] (9) In the above embodiment, the anomaly detection result storage unit stores the anomaly detection details, the time, and the detection device. However, other information may be added to the anomaly detection result. For example, the anomaly detection result may include the severity of the anomaly. The severity may be determined based on the impact of the anomaly on the control of the robot. For example, the severity may be expressed in three levels: severe, medium, and mild. Severe indicates a state in which a serious impact on the control of the robot or the safety of the surrounding area is likely to occur or is occurring, while medium indicates a state in which there is a possibility of an impact on the control of the robot or the safety of the surrounding area. Furthermore, mild may indicate a state in which there is a low possibility of an impact on the control of the robot or the safety of the surrounding area. This makes it possible to respond immediately or to send an alert to the monitoring server depending on the severity of the detected anomaly.

[0267] (10) In the above embodiment, an example was shown in which the credit score corresponding to the detected abnormality is decremented by 1 when updating the credit score, but the method of updating the credit score is not limited to this. For example, as explained in other variant example (9), the decrement value may be changed depending on the severity of the abnormality. For a highly serious abnormality, the decrement may be 10, for a medium abnormality, it may be 5, and for a mild abnormality, it may be 1. The amount of decrement of the credit score (an example of the update amount) may be weighted depending on the severity. Furthermore, the maximum value of the credit score does not have to be 100, and it does not have to be quantified. For example, the credit score may be displayed in stages, such as high, medium, and low.

[0268] (11) In the above embodiment, only examples in which the credit score is updated to decrease have been shown, but a process for increasing the credit score may also be performed. For example, the credit score may be increased by a predetermined value every day, or when the cause of an abnormality is identified by the monitoring server, a process for increasing the credit score of targets that were not the cause of the abnormality may be performed, or when the cause of the abnormality is recovered (for example, when a malicious application installed on a robot is removed), the credit score may be restored (for example, the credit score may be reset or increased). Furthermore, the credit score may be increased when no abnormality is detected for a predetermined period of time.

[0269] (12) In the above embodiment, the user information storage unit stores only information about users who log in from remote control terminals. However, information about users who manually control the robot may also be stored. In this case, the user is authenticated by the robot and performs a login procedure. For example, the user may be authenticated by an item owned by the user, such as an IC card or smartphone, by the user's stored information, such as an ID and password, by the user's biometric information, such as facial recognition or fingerprint recognition, or by a multi-factor authentication method that combines the above. This allows the fleet management server to more effectively manage and control access to the robot, even when the user manually controls the robot from close range, which is effective in improving safety.

[0270] (13) In the above embodiment, the targets for which the credit score is maintained are classified into the app, the user, the robot, the communication, and the operating environment, and then each is further detailed. However, detailed classification is not required, and the classification method is not limited to this. It is sufficient to include two or more of the following: an abnormality caused by the user who remotely controls the robot, an abnormality caused by components in the robot, and an abnormality caused by the operating environment of the robot.

[0271] (14) In the above embodiment, when dangerous control of the robot is detected in the remote control mode, the user's trust score is reduced on the assumption that an abnormality caused by the user has been detected. However, information on the user's control history may also be added to determine whether dangerous control was detected as a result of the user's control. For example, when the robot's control mode is the remote control mode and acceleration exceeding a threshold is detected, the trust score update unit may refer to the user's most recent control history. If the user is not performing any control related to movement, the trust score update unit may determine that the abnormality detected in the robot is unlikely to have been caused by the user's control and that the abnormality is likely to have occurred due to the operating environment, and reduce the trust score of the operating environment. This makes it possible to accurately determine the cause of the abnormality, which is effective in increasing safety through appropriate response.

[0272] (15) In the above embodiment, an example was shown in which a monitoring request and a report were issued when an environmental abnormality occurred, but the response method is not limited to this. For example, in a situation in which the operating environment is unreliable, autonomous control of the robot may be deemed dangerous, and the autonomous control mode may be prohibited.

[0273] (16) In the above embodiment, an example was shown in which a monitoring request was made in response to the detection of an abnormality in the operating environment. However, a request may be made to the remote user to check the operating environment during remote control mode, or the remote operator may notify the user of the presence of an unauthorized third party nearby or an abnormality in the operating environment.

[0274] (17) In the above embodiment, an example was shown in which the control right of the robot was revoked when the user's credit score fell below a predetermined value, but the control right of the robot may be further classified into more detailed categories and some of the control rights may be restricted. For example, by classifying the control of the robot by function, such as the control right related to movement, the control right related to opening and closing doors, etc., only the control right related to movement may be revoked.

[0275] (18) In the above embodiment, the user's credit score is stored in the monitoring server, and when the user logs in, the robot synchronizes the user's credit score to determine the user's control rights. However, for users with low credit scores, the monitoring server may create a revocation list and distribute it to the robot or fleet management server in advance. This makes it possible to immediately eliminate access by unauthorized users, thereby increasing safety.

[0276] (19) In the above embodiment, the response was determined depending on the type of credit score that fell below a predetermined threshold, but the threshold may be different depending on the type of credit score, or each threshold may be different for each robot. This makes it possible to flexibly design the balance between safety and availability depending on the type of robot and operating environment.

[0277] (20) Each device in the above embodiments is specifically a computer system consisting of a microprocessor, ROM, RAM, hard disk unit, display unit, keyboard, mouse, etc. A computer program is recorded in the RAM or hard disk unit. Each device achieves its function when the microprocessor operates in accordance with the computer program. Here, a computer program is composed of a combination of multiple instruction codes that indicate commands to a computer to achieve a predetermined function.

[0278] (21) In each of the above embodiments, some or all of the constituent elements may be configured from a single system LSI (Large Scale Integration). A system LSI is an ultra-multifunctional LSI manufactured by integrating multiple components on a single chip, and specifically, is a computer system configured to include a microprocessor, ROM, RAM, etc. A computer program is recorded in the RAM. The system LSI achieves its functions when the microprocessor operates in accordance with the computer program.

[0279] Furthermore, each of the components constituting each of the above devices may be individually integrated into a single chip, or some or all of them may be integrated into a single chip.

[0280] Although we refer to it as a system LSI here, it may also be called an IC, LSI, super LSI, or ultra LSI depending on the level of integration. Furthermore, the method of integration is not limited to LSI; it can also be realized using dedicated circuits or general-purpose processors. It is also possible to use FPGAs (Field Programmable Gate Arrays), which can be programmed after LSI manufacturing, or reconfigurable processors, which allow the connections and settings of circuit cells within LSI to be reconfigured.

[0281] Furthermore, if an integrated circuit technology that can replace LSI emerges due to advances in semiconductor technology or other derivative technologies, it is natural that such technology may be used to integrate functional blocks. The application of biotechnology, etc. is also a possibility.

[0282] (22) Some or all of the components constituting each of the above devices may be configured as an IC card or a standalone module that can be attached to each device. The IC card or module is a computer system composed of a microprocessor, ROM, RAM, etc. The IC card or module may include the above-mentioned ultra-multifunctional LSI. The IC card or module achieves its functions when the microprocessor operates according to a computer program. This IC card or module may be tamper-resistant.

[0283] (23) The present disclosure may be embodied as the methods described above, a computer program for implementing these methods on a computer, or a digital signal comprising the computer program.

[0284] The present disclosure may also be a computer program or a digital signal recorded on a computer-readable recording medium, such as a flexible disk, a hard disk, a CD-ROM, an MO, a DVD, a DVD-ROM, a DVD-RAM, a BD (Blu-ray (registered trademark) Disc), a semiconductor memory, etc. Alternatively, the present disclosure may be a digital signal recorded on such a recording medium.

[0285] The present disclosure may also be applied to transmitting a computer program or digital signal via a telecommunications line, a wireless or wired communication line, a network such as the Internet, data broadcasting, or the like.

[0286] The present disclosure may also be a computer system including a microprocessor and a memory, the memory storing the computer program, and the microprocessor operating in accordance with the computer program.

[0287] Furthermore, the program or digital signal may be recorded on a recording medium and transferred, or the program or digital signal may be transferred via a network or the like, so that the program or digital signal may be implemented by another independent computer system.

[0288] (24) The division of functional blocks in the block diagram is an example, and multiple functional blocks may be realized as a single functional block, one functional block may be divided into multiple blocks, or some functions may be moved to another functional block. Furthermore, the functions of multiple functional blocks with similar functions may be processed in parallel or time-shared by a single piece of hardware or software.

[0289] Furthermore, the control mode switching device according to the above-described embodiments may be realized as a single device or may be realized by multiple devices. When the control mode switching device is realized by multiple devices, the components of the control mode switching device may be distributed among the multiple devices in any manner. When the control mode switching device is realized by multiple devices, the communication method between the multiple devices is not particularly limited and may be wireless communication or wired communication. Furthermore, wireless communication and wired communication may be combined between the devices. Furthermore, the components of the control mode switching device may be provided in, for example, a fleet management server, a monitoring server, or a remote control terminal.

[0290] (25) The order in which each step in the flowchart is executed is merely an example for specifically explaining the present disclosure, and other orders may be used. Some of the steps may be executed simultaneously (in parallel) with other steps, or some of the steps may not be executed. While steps S505, S506, and S509 have been described as common operations, the present invention is not limited to this example and may be executed in different orders.

[0291] (26) The above-described embodiments and modifications may be combined. For example, the present disclosure may include various modifications that a person skilled in the art may make to the present embodiments, or may include modifications that are constructed by combining components of different embodiments, as long as they do not deviate from the spirit of the present disclosure. [Industrial Applicability]

[0292] The present disclosure is useful in a system for managing robots that move through public spaces. [Explanation of symbols]

[0293] 10, 10a, 10b, 10c robot 20 Network 30 Fleet Management Servers 31, 41, 51 Communications Department 32 Fleet Management Department 33 Robot state storage unit 34 Account information storage unit 40 Monitoring Server 42 Monitoring Department 43 Analysis Interface Section 44 Robot Credit Score Management 45 User credit score maintenance unit 50 Remote Control Terminal 52 Remote control application section 53 User Interface Section 100 TCU 101 External Communications Department 102, 502, 602 App Department 103 Internal Communications Department 104, 402 Intrusion detection unit 200 Central ECU (control mode switching device) 201, 301, 401, 501, 601 Communication port section 202 Host OS Department 203 Guest OS Section 204 Response Judgment Department 205 Abnormality detection unit 206 Credit Score Update Department 207 User Management Department 208 Anomaly detection result storage unit 209 Credit Score Management Department 210 User information storage unit 211 Control mode holding unit 300 User Interface ECU 302, 603 External device connection section 400 Ethernet Switch 500 Autonomous Driving ECU 503 Application Monitoring Department 600 Sensor ECU 700 Actuator ECU

Claims

1. A control mode switching device for switching a control mode of a robot, the control modes include two or more of a remote control mode controlled by a first user via an external network, a manual control mode controlled by an operation from a second user not via the external network, and an autonomous control mode controlled based on sensor information acquired by a sensor provided in the robot; The control mode switching device an acquisition unit that acquires, based on a communication message on a control network within the robot and the control mode, detection results of one or more of a user abnormality caused by control of the first user or the second user, a robot abnormality caused by the control network, an operating environment abnormality caused by an operating environment of the robot, and an application abnormality caused by an application operated by a control device that is connected to the control network and controls the robot; a switching unit that calculates a score for each type of detected abnormality based on the acquired detection results, the score indicating the possibility that the type of abnormality is a cause of the abnormality occurring in the robot, and switches the control mode of the robot based on the calculated score; the types of abnormalities include at least two of a user, a robot, an operating environment, and an application; the switching unit updates the user score when the detection result includes the detection of the user abnormality, updates the robot score when the detection result includes the detection of the robot abnormality, updates the operating environment score when the detection result includes the detection of the operating environment abnormality, and updates the application score when the detection result includes the detection of the application abnormality; updating the score is to decrease the score, The switching unit further calculating the score for each of the plurality of first users, and when the control mode is the remote control mode and an unauthorized first user whose score is equal to or less than a first threshold is controlling the robot, performing at least one of the following: not accepting the control by the unauthorized first user; requesting a change to another first user; or switching the control mode to a control mode other than the remote control mode; When the score of the robot becomes equal to or less than a second threshold, the control mode is switched to a degenerate mode in which control of the robot is limited and the robot is stopped in a safe state; When the score of the operating environment becomes equal to or less than a third threshold, an alert is sent to an external device to check the operating environment. Control mode switching device.

2. the sensor information includes at least one of position information, acceleration, running speed, and camera images of the robot; The user abnormality is an abnormality in which, when the control mode is the manual control mode or the remote control mode, any of the following is detected: the position information deviating from a range that is assumed to be controlled in advance, the acceleration or the traveling speed exceeding a predetermined threshold, and contact with or approach to a person or object that is not assumed in advance based on the camera image. The robot abnormality is an abnormality detected by either a failure notification included in communication information of the control network or a communication abnormality of the control network, The abnormality in the operating environment is an abnormality detected by detecting any one of a discontinuous change or an invalid value in the position information, a communication abnormality in the external network, a voltage change in the control network, and disassembly of the robot. The control mode switching device according to claim 1 .

3. When two or more of the scores are equal to or less than a predetermined threshold, the switching unit takes action based on each score in the order of priority of the robot's score, the operating environment's score, and the user's score.

3. The control mode switching device according to claim 1 or 2.

4. the switching unit does not update the user's score when the detection result includes that an abnormality in the user has been detected and any one of the robot's score, the operating environment score, and the application score satisfies a predetermined condition; The control mode switching device according to any one of claims 1 to 3.

5. the applications include a first application for the remote control mode, a second application for the manual control mode, and a third application for the autonomous control mode; the detection result includes, as the application abnormality, an abnormality of the first application, an abnormality of the second application, and an abnormality of the third application; the switching unit decreases a score of the first application when an abnormality in the first application is detected, decreases a score of the second application when an abnormality in the second application is detected, and decreases a score of the third application when an abnormality in the third application is detected; prohibiting the control mode from being changed to the remote control mode when the score of the first application is equal to or less than a fourth threshold; prohibiting the control mode from being changed to the manual control mode when the score of the second application is equal to or less than a fifth threshold; prohibiting the control mode from being changed to the autonomous control mode when the score of the third application is equal to or less than a sixth threshold. The control mode switching device according to any one of claims 1 to 4.

6. the switching unit determines whether the robot is in a predetermined control state based on at least one of the sensor information and the state of the robot, and switches the control mode only when the robot is in the predetermined control state; The control mode switching device according to any one of claims 1 to 5.

7. the switching unit switches the control mode only when the robot is present within a predetermined range based on the position information of the robot. The control mode switching device according to claim 2 .

8. the acquisition unit is realized by an anomaly detection unit that detects one or more of the user anomaly, the robot anomaly, the operating environment anomaly, and the application anomaly based on the communication message and the control mode; The control mode switching device according to any one of claims 1 to 7.

9. A control mode switching method for switching a control mode of a robot, comprising: the control modes include two or more of a remote control mode controlled by a first user via an external network, a manual control mode controlled by an operation from a second user not via the external network, and an autonomous control mode controlled based on sensor information acquired by a sensor provided in the robot; The control mode switching method includes: Based on the communication message on the control network in the robot and the control mode, obtain detection results of one or more of a user abnormality caused by control of the first user or the second user, a robot abnormality caused by the control network, an operating environment abnormality caused by the operating environment of the robot, and an application abnormality caused by an application operated by a control device connected to the control network and controlling the robot; calculating a score for each type of the detected abnormality based on the acquired detection results, which indicates the possibility that the type of abnormality is a cause of the abnormality occurring in the robot, and switching the control mode of the robot based on the calculated score; the types of abnormalities include at least two of a user, a robot, an operating environment, and an application; The switching includes updating the user score when the detection result includes the detection of the user abnormality, updating the robot score when the detection result includes the detection of the robot abnormality, updating the operating environment score when the detection result includes the detection of the operating environment abnormality, and updating the application score when the detection result includes the detection of the application abnormality; updating the score is to decrease the score, The switching may further include: calculating the score for each of the plurality of first users, and when the control mode is the remote control mode and an unauthorized first user whose score is equal to or less than a first threshold is controlling the robot, performing at least one of the following: not accepting the control by the unauthorized first user; requesting a change to another first user; or switching the control mode to a control mode other than the remote control mode; When the score of the robot becomes equal to or less than a second threshold, the control mode is switched to a degenerate mode in which control of the robot is limited and the robot is stopped in a safe state; When the score of the operating environment becomes equal to or less than a third threshold, an alert is sent to an external device to check the operating environment. Control mode switching method.

10. A program for causing a computer to execute the control mode switching method described in claim 9.

Citation Information

Patent Citations

  • Control mode switching device for self-traveling vehicle

    JP1997258826A

  • Robot system, remote controller, and robot device and its control method

    JP2005144612A

  • Traveling control device of vehicle

    JP2018040426A

  • Automatic driving system

    JP2018180859A

  • Unauthorized communication detection device and unauthorized communication detection program

    JP2019153875A