STARTING SYSTEM AND STARTING METHOD FOR A WORK MACHINE
The control system for work machines enables secure operator authentication by using a starter signal unit and gateway function controller to authenticate operators based on past data, ensuring secure startup even when the management device is not activated, thus preventing unauthorized operation.
Patent Information
- Application Number
- JP2021161099
- Authority / Receiving Office
- JP · JP
- Patent Type
- Patents
- Current Assignee / Owner
- Filing Date
- 2021-09-30
- Publication Date
- 2025-09-10
- Estimated Expiration
- 2041-09-30
AI Technical Summary
Work machines may fail to authenticate operators due to asynchronous startup times of components, particularly when the management device storing authentication information is not activated.
A control system with a starter signal unit and a gateway function controller that stores authentication information, allowing operator authentication even when the management device is not activated, using a monitor controller to perform simple authentication based on past data and updating authentication when the gateway function controller is operational.
Ensures operator authentication is possible even if the management device is not activated, preventing unauthorized operation and ensuring secure startup by using past authentication data until the gateway function controller is fully operational.
Smart Images

Figure 0007737278000001 
Figure 0007737278000002 
Figure 0007737278000003
Abstract
Description
[Technical Field]
[0001] The present disclosure relates to a starting system for a work machine and a method for starting a work machine. [Background technology]
[0002] A single work machine is not limited to being operated by a single operator, but can be operated by multiple operators. However, it is necessary to prevent the work machine from being operated by unauthorized users. For this reason, work machines are known that have a function to authenticate the operator who operates them (see, for example, Patent Document 1). [Prior art documents] [Patent documents]
[0003] [Patent Document 1] Japanese Patent Application Laid-Open No. 2015-164847 Summary of the Invention [Problem to be solved by the invention]
[0004] A work machine is equipped with multiple components, including a management device that stores authentication information for multiple operators. When the work machine starts up, each of the multiple components equipped on the work machine also starts up, but the startup times are not the same. As a result, even if the authentication device used to authenticate the operator is running, authentication may not be possible because the management device that stores the authentication information is not running. An object of the present disclosure is to provide a work machine activation system and a work machine activation method that enable authentication of an operator even when a management device that stores authentication information is not activated. [Means for solving the problem]
[0005] According to one aspect of the present invention, a start-up system for a work machine includes a management device that stores authentication information for authenticating multiple operators who are capable of operating a work machine, and an authentication device that authenticates operators who operate the work machine, the authentication device including a memory unit that stores the authentication information of operators who have been authenticated in the past, and an authentication unit that authenticates the operators based on the authentication information stored in the memory unit when the management device is not started. [Effects of the Invention]
[0006] According to the above aspect, the activation system for a work machine can authenticate the operator even if the management device that stores the authentication information is not activated. [Brief explanation of the drawings]
[0007] [Figure 1] 1 is a schematic diagram showing the configuration of a work machine according to a first embodiment. [Figure 2] FIG. 2 is a diagram showing the internal configuration of a driver's cab according to the first embodiment. [Figure 3] 1 is a schematic block diagram showing a hardware configuration of a control system according to a first embodiment. [Figure 4] FIG. 2 is a schematic block diagram showing the software configuration of a starter signal unit, a gateway function controller, and a monitor controller according to the first embodiment. [Figure 5] FIG. 3 is a sequence diagram showing an example of a start-up operation of a work machine performed by the control system in the first embodiment. [Figure 6] 10 is a flowchart showing a simplified authentication process for an operator before the gateway function controller according to the first embodiment is started up. [Figure 7] 4 is an example of a display screen of a touch panel in the simplified authentication process according to the first embodiment. [Figure 8] 10 is a flowchart showing an authentication process of an operator after the gateway function controller according to the first embodiment is started up. [Figure 9]4 is an example of a display screen of a touch panel in the authentication process according to the first embodiment. [Figure 10] 10 is a flowchart showing an authentication process of an operator after the first hardware of the gateway function controller according to the second embodiment is started up. [Figure 11] FIG. 1 is a schematic block diagram illustrating the configuration of a computer according to at least one embodiment. DETAILED DESCRIPTION OF THE INVENTION
[0008] First Embodiment Hereinafter, the embodiments will be described in detail with reference to the drawings.
[0009] <Configuration of work machine 100> FIG. 1 is a schematic diagram showing the configuration of a work machine 100 according to a first embodiment. The work machine 100 operates at a construction site and works on a construction target such as earth and sand. The work machine 100 according to the first embodiment is, for example, a hydraulic excavator. The work machine 100 includes a traveling body 110, a revolving body 120, a work implement 130, and a cab 140. The work machine 100 according to the first embodiment authenticates the operator by communicating with an operator terminal 300, such as a smartphone carried by the operator, via Bluetooth Low Energy (Bluetooth is a registered trademark). In other embodiments, the work machine 100 and the operator terminal 300 may communicate using a short-range wireless communication method other than BLE, such as Bluetooth (registered trademark) or Zigbee (registered trademark). The work machine 100 also receives master data used for operator authentication from a remote server device 500 via wide-area communication such as the Internet. This allows the work machine 100 to perform authentication processing using the latest master data, even if the available operators change.
[0010] The master data stored in the server device 500 is data that associates, for each operator, an operator ID, a password, a display name, information indicating the operation authority of the work machine 100, operation setting data, and a Bluetooth (registered trademark) device address. The operation setting data is data used when controlling the hydraulic circuit. The information indicating the operation authority makes it possible to identify whether or not an operator has the operation authority of the work machine 100, the contents that can be set on the monitor, etc. The operation setting data is also data that represents the relationship between the operation amount and the control amount. The operation setting data may be, for example, a weight value for the control amount, or a function that represents the relationship between the operation amount and the control amount.
[0011] The running body 110 supports the work machine 100 so that it can travel. The running body 110 includes two endless tracks 111 provided on the left and right, and two travel motors 112 for driving the endless tracks 111, respectively. The rotating body 120 is supported by the running body 110 so as to be able to rotate around a rotation center. The work implement 130 is hydraulically driven. The work implement 130 is supported on the front part of the rotating body 120 so that it can be driven in the vertical direction. The operator's cab 140 is a space where an operator sits and operates the work machine 100. The operator's cab 140 is provided on the left front part of the rotating body 120. Here, the portion of the revolving unit 120 to which the work implement 130 is attached is referred to as the front portion. Furthermore, with respect to the revolving unit 120, the portion opposite the front portion is referred to as the rear portion, the left portion as the left portion, and the right portion as the right portion.
[0012] <Configuration of rotating body 120> The swing body 120 includes an engine 121 , a hydraulic pump 122 , a control valve 123 , a swing motor 124 , and a fuel injection device 125 . The engine 121 is a prime mover that drives the hydraulic pump 122. The engine 121 is provided with a starter motor 1211. The engine 121 is started by the rotation of the starter motor 1211. The hydraulic pump 122 is a variable displacement pump driven by the engine 121. The hydraulic pump 122 supplies hydraulic oil via a control valve 123 to each actuator (a boom cylinder 131C, an arm cylinder 132C, a bucket cylinder 133C, a traveling motor 112, and a swing motor 124). The control valve 123 controls the flow rate of the hydraulic oil supplied from the hydraulic pump 122 . The swing motor 124 is driven by hydraulic oil supplied from a hydraulic pump 122 via a control valve 123 to swing the swing body 120 . The fuel injector 125 injects fuel into the engine 121 .
[0013] <Configuration of work machine 130> The work implement 130 includes a boom 131, an arm 132, a bucket 133, a boom cylinder 131C, an arm cylinder 132C, and a bucket cylinder 133C.
[0014] The base end of the boom 131 is attached to the rotating body 120 via a boom pin. The arm 132 connects the boom 131 and the bucket 133. The base end of the arm 132 is attached to the tip of the boom 131 via an arm pin. The bucket 133 includes a blade for digging up earth and sand and a storage section for storing the excavated earth and sand. The base end of the bucket 133 is attached to the tip of the arm 132 via a bucket pin.
[0015] The boom cylinder 131C is a hydraulic cylinder for operating the boom 131. A base end of the boom cylinder 131C is attached to the revolving body 120. A tip end of the boom cylinder 131C is attached to the boom 131. The arm cylinder 132C is a hydraulic cylinder for driving the arm 132. A base end of the arm cylinder 132C is attached to the boom 131. A tip end of the arm cylinder 132C is attached to the arm 132. The bucket cylinder 133C is a hydraulic cylinder for driving the bucket 133. A base end of the bucket cylinder 133C is attached to the arm 132. A tip end of the bucket cylinder 133C is attached to a link member connected to the bucket 133.
[0016] <Configuration of the driver's cab 140> A door 141 for an operator to board is provided on the left side of the operator's cab 140. The door 141 is provided with a lock actuator 1411 for locking the door 141 and a door switch 1412 for unlocking the door.
[0017] FIG. 2 is a diagram showing the internal configuration of the operator's cab 140 according to the first embodiment. A driver's seat 142, an operating device 143, a rotary switch 144, and a touch panel 145D are provided inside the driver's cab 140. The rotary switch 144 is a switch that takes four positions when rotated: OFF, ACC (accessory), IG (ignition), and ST (start). When the rotary switch 144 is released from the ST position, it automatically returns to the IG position by a spring mechanism (not shown).
[0018] The operation device 143 is a device for driving the traveling body 110, the revolving body 120, and the work machine 130 through manual operation by an operator. The operation device 143 includes a left operation lever 143LO, a right operation lever 143RO, a left foot pedal 143LF, a right foot pedal 143RF, a left travel lever 143LT, and a right travel lever 143RT.
[0019] The left operating lever 143LO is provided on the left side of the driver's seat 142. The right operating lever 143RO is provided on the right side of the driver's seat 142.
[0020] The left operation lever 143LO is an operation mechanism for performing the swing operation of the swing unit 120 and the excavation / dumping operation of the arm 132. Specifically, when the operator of the work machine 100 tilts the left operation lever 143LO forward, the arm 132 performs the dumping operation. When the operator of the work machine 100 tilts the left operation lever 143LO rearward, the arm 132 performs the excavation operation. When the operator of the work machine 100 tilts the left operation lever 143LO to the right, the swing unit 120 swings to the right. When the operator of the work machine 100 tilts the left operation lever 143LO to the left, the swing unit 120 swings to the left. Note that in other embodiments, when the left operation lever 143LO is tilted forward or backward, the swing unit 120 may swing to the right or left, and when the left operation lever 143LO is tilted left or right, the arm 132 may perform the excavation or dumping operation.
[0021] The right operating lever 143RO is an operating mechanism for performing an excavation / dumping operation of the bucket 133 and a raising / lowering operation of the boom 131. Specifically, when the operator of the work machine 100 tilts the right operating lever 143RO forward, a lowering operation of the boom 131 is performed. Conversely, when the operator of the work machine 100 tilts the right operating lever 143RO rearward, a raising operation of the boom 131 is performed. Conversely, when the operator of the work machine 100 tilts the right operating lever 143RO to the right, a dumping operation of the bucket 133 is performed. Conversely, when the operator of the work machine 100 tilts the right operating lever 143RO to the left, an excavation operation of the bucket 133 is performed. Note that in other embodiments, when the right operating lever 143RO is tilted in the forward / backward direction, the bucket 133 may perform a dumping operation or an excavation operation, and when the right operating lever 143RO is tilted in the left / right direction, the boom 131 may perform a raising or lowering operation.
[0022] The left foot pedal 143LF is located on the left side of the floor in front of the driver's seat 142. The right foot pedal 143RF is located on the right side of the floor in front of the driver's seat 142. The left travel lever 143LT is pivotally supported by the left foot pedal 143LF, and is configured so that tilting the left travel lever 143LT and pressing down the left foot pedal 143LF are linked. The right travel lever 143RT is pivotally supported by the right foot pedal 143RF, and is configured so that tilting the right travel lever 143RT and pressing down the right foot pedal 143RF are linked.
[0023] The left foot pedal 143LF and left travel lever 143LT correspond to the rotational drive of the left crawler belt of the traveling body 110. Specifically, when the operator of the work machine 100 pushes the left foot pedal 143LF or the left travel lever 143LT forward, the left crawler belt rotates in the forward direction. Conversely, when the operator of the work machine 100 pushes the left foot pedal 143LF or the left travel lever 143LT backward, the left crawler belt rotates in the reverse direction.
[0024] The right foot pedal 143RF and the right traveling lever 143RT correspond to the rotational drive of the right crawler belt of the traveling body 110. Specifically, when the operator of the work machine 100 pushes the right foot pedal 143RF or the right traveling lever 143RT forward, the right crawler belt rotates in the forward direction. Conversely, when the operator of the work machine 100 pushes the right foot pedal 143RF or the right traveling lever 143RT backward, the right crawler belt rotates in the reverse direction.
[0025] Configuration of Control System 145 Fig. 3 is a schematic block diagram showing the hardware configuration of a control system 145 according to the first embodiment. In Fig. 3, solid lines represent power lines, dashed lines represent signal lines, and dashed lines represent wireless communication. The control system 145 includes a power supply unit 201, a starter signal unit 202, a gateway function controller 203, a monitor controller 204, a control controller 205, an engine controller 206, and a wide area communication controller 207. The starter signal unit 202, the gateway function controller 203, the monitor controller 204, the control controller 205, and the engine controller 206 are connected to one another via an internal network of the work machine 100 such as a Controller Area Network (CAN) or Ethernet (registered trademark).
[0026] The power supply unit 201 supplies electrical energy to each device that constitutes the control system 145 . The starter signal unit 202 receives signal inputs from the door switch 1412, the rotary switch 144, the operator terminal 300, and the monitor controller 204. Based on the input signals, the starter signal unit 202 outputs a start signal or a drive signal to the gateway function controller 203, the monitor controller 204, the control controller 205, the engine controller 206, the wide area communication controller 207, the lock actuator 1411, or the starter motor 1211. A controller to which a start signal is input is started and operates by electrical energy supplied by the power supply unit 201. Note that the starter signal unit 202 always operates by receiving electrical energy from the power supply unit 201, even when the other controllers are in a stopped state. On the other hand, when the working machine 100 is not started, the starter signal unit 202 may be configured so that only the BLE communication unit 221 (described later) is in an activated state, and the other components are in a stopped state, or may be activated intermittently.
[0027] The gateway function controller 203 relays communications between controllers such as the starter signal unit 202, monitor controller 204, control controller 205, and engine controller 206. In particular, the gateway function controller 203 stores operator authentication master data received by the wide area communication controller 207 from the server device via the wide area communication network, and transmits the data to other components connected via the internal network. In other words, the gateway function controller 203 is an example of a management device that stores authentication information for authenticating multiple operators who are permitted to operate the work machine 100. Monitor controller 204 controls the display on touch panel 145D included in control system 145 and notifies the occurrence of a touch operation on touch panel 145D. Note that control system 145 according to another embodiment may include a monitor without a touch input function, such as an LCD (Liquid Crystal Display), and physical buttons, instead of touch panel 145D. In this case, monitor controller 204 controls the display on the monitor and notifies the occurrence of a press of a physical button. The control controller 205 acquires various data related to the hydraulic equipment that controls the operation of the work implement 130 using sensors (not shown), and outputs control signals for controlling the hydraulic equipment in accordance with the operation of the operation device 143. In other words, the control controller 205 controls the drive of the boom cylinder 131C, arm cylinder 132C, bucket cylinder 133C, travel motor 112, swing motor 124, etc. In other words, the control controller 205 is an example of a vehicle body control device. The engine controller 206 acquires various data related to the engine 121 using sensors (not shown) and controls the engine 121 by instructing the fuel injection device 125 on the amount of fuel injection. The wide area communication controller 207 has a function of communicating via a wide area communication network. The wide area communication controller 207 receives master data used for authenticating an operator from a server device via communication via the wide area communication network. The wide area communication controller 207 is activated intermittently at a predetermined cycle (for example, every 24 hours) and receives data from the server device 500.
[0028] The control system 145 has a function of performing login processing for the operator in the cab 140 by operating the touch panel 145D. For example, the control system 145 may be equipped with a controller that performs login processing, or the starter signal unit 202, gateway function controller 203, and monitor controller 204 may have the function of performing login processing. Specifically, the control system 145 displays an operator ID selection screen on the touch panel 145D via the monitor controller 204, and accepts the selection of the operator ID. If the selected operator ID indicates an operator who is close to the work machine 100 and has operation authority, the control system 145 authenticates that the operator in the cab 140 is an operator who has operation authority. The monitor controller 204 is an example of an authentication device that authenticates the operator of the work machine 100.
[0029] FIG. 4 is a schematic block diagram showing the software configuration of the starter signal unit 202, gateway function controller 203, and monitor controller 204 according to the first embodiment. The starter signal unit 202 includes a BLE communication unit 221 , a network communication unit 222 , a signal input unit 223 , an operator memory unit 224 , a proximity detection unit 225 , a startup unit 226 , and a state memory unit 227 .
[0030] The BLE communication unit 221 operates as a BLE central and communicates with the operator terminal 300. The BLE communication unit 221 searches for an operator terminal 300 with which it can communicate, and receives an advertising packet from the discovered operator terminal 300. The advertising packet includes a device address that identifies the operator terminal 300 and a machine ID that indicates the work machine 100 to be started. The advertising packet is encrypted using key data exchanged with the starter signal unit 202 during pairing. The BLE communication unit 221 decrypts the advertising packet using key data stored in the operator memory unit 224.
[0031] The network communication unit 222 communicates with other controllers via the in-vehicle network. The signal input unit 223 receives signal inputs from the door switch 1412 and the rotary switch 144 .
[0032] The operator storage unit 224 is data that associates, for each operator who has the authority to operate the work machine 100, the device address of the operator terminal 300 operated by that operator with key data. Hereinafter, an operator who has the authority to operate the work machine 100 will also be referred to as a specific operator.
[0033] The proximity detection unit 225 determines whether or not a specific operator is present in the vicinity of the work machine 100 based on whether or not the BLE communication unit 221 has already paired with the operator terminal 300 that is the source of the advertising packet. In other words, the proximity detection unit 225 detects that the specific operator has approached the work machine 100. Specifically, when the BLE communication unit 221 decodes the advertising packet and establishes a connection with the operator terminal 300, the proximity detection unit 225 determines that the specific operator is in proximity to the work machine 100. The proximity detection unit 225 records the device address of the operator terminal 300 in the state storage unit 227 as the proximity state of the specific operator.
[0034] The starting unit 226 outputs a starting signal or a driving signal to the gateway function controller 203, the monitor controller 204, the control controller 205, the engine controller 206, the lock actuator 1411, or the starter motor 1211. The state storage unit 227 stores the device address of the operator terminal 300.
[0035] The gateway function controller 203 includes a master receiving section 231 , a master storage section 232 , a master output section 233 , and a start notification section 234 .
[0036] The master receiving unit 231 receives the latest master data via the wide area communication controller 207 and updates the master data stored in the master storage unit 232 . The master storage unit 232 stores master data. The master data is data that associates, for each operator, an operator ID, a password, a display name, information indicating operation authority indicating whether or not the operator has operation authority for the work machine 100, operation setting data, and a device address.
[0037] The master output unit 233 transmits, from the master data stored in the master storage unit 232, authentication master data made up of an operator ID, a password, a display name, and information indicating operation authority, which indicates whether or not the operator has the authority to operate the work machine 100, to the starter signal unit 202 and the monitor controller 204. The master output unit 233 also transmits operation setting data associated with the operator ID of the operator who is logged in in the master storage unit 232 to the control controller 205. This allows the operation setting data of the operator on board to be reflected in the control controller 205.
[0038] When the gateway function controller 203 is started up by the start signal received from the starter signal unit 202, the start notification section 234 outputs a start notification indicating the completion of start up via the internal network.
[0039] The monitor controller 204 includes a communication unit 241 , a display control unit 242 , an acquisition unit 243 , a storage unit 244 , and an authentication unit 245 . The communication unit 241 performs communication via an internal network. The display control unit 242 causes the touch panel 145D to display a screen for authenticating the operator. For example, the display control unit 242 causes the touch panel 145D to display a selection screen for a list of operators. The acquisition unit 243 acquires input information for authentication from the operator via the touch panel 145D.
[0040] The storage unit 244 stores input information acquired from the operator when the authentication process by the authentication unit 245 is successful. The storage unit 244 may hash the input information before storing it. The storage unit 244 is a storage area provided in a non-volatile memory. The authentication unit 245 authenticates the operator based on the input information acquired by the acquisition unit 243. The authentication unit 245 authenticates the operator by checking the input information in the gateway function controller 203. However, if the startup of the gateway function controller 203 has not been completed, the authentication unit 245 authenticates the operator by checking the past input information stored in the storage unit 244 against the input information acquired by the acquisition unit 243.
[0041] Operator terminal 300 The operator terminal 300 functions as a BLE peripheral by executing a pre-installed startup program for the work machine 100. When the startup program is executed, the operator terminal 300 displays a list of the work machines 100 and accepts from the operator the selection of the work machine 100 to be started. When the operator terminal 300 accepts the selection of the work machine 100, it starts transmitting an advertisement packet that includes the device address and the machine ID of the selected work machine 100.
[0042] Operation of Control System 145 Here, the startup operation of the work machine 100 when an operator (specified operator) who has the authority to operate the work machine 100 gets on board the work machine 100 will be described. The control system 145 is an example of a startup system for the work machine 100. Figure 5 is a sequence diagram showing an example of the startup operation of the work machine 100 by the control system 145 in the first embodiment.
[0043] When the operator operates the operator terminal 300 and executes the startup program, a list of work machines 100 is displayed and the operator selects the work machine 100 to be started (step S1). When the operator terminal 300 accepts the selection of the work machine 100, it transmits an advertisement packet including the device address and the machine ID of the selected work machine 100 (step S2).
[0044] The starter signal unit 202 receives the advertising packet and, when it determines that a specific operator is in the vicinity, transmits a start signal to the gateway function controller 203 (step S3). This causes the gateway function controller 203 to start up (step S4). However, since the gateway function controller 203 starts up after power-on through processes such as executing a boot program and reading and starting the OS, it may take some time for the start-up to be completed.
[0045] When the operator reaches the work machine 100, he or she presses the door switch 1412 to open the door 141. As a result, the starter signal unit 202 receives a signal indicating ON from the door switch 1412 (step S5). After confirming that the specific operator is in the vicinity, the starter signal unit 202 drives the lock actuator 1411 to unlock the door 141 (step S6).
[0046] When the operator enters the cab 140 and sets the rotary switch 144 to the ACC position, the starter signal unit 202 receives a signal indicating ACC from the rotary switch 144 (step S7). After confirming the proximity of the specific operator, the starter signal unit 202 drives the lock actuator 1411 to unlock the door 141. After confirming the proximity of the specific operator, the starter signal unit 202 transmits an activation signal to the monitor controller 204 (step S8). This activates the monitor controller 204 (step S9).
[0047] The monitor controller 204 outputs a signal to the touch panel 145D to display the operator list screen (step S10). As a result, the monitor controller 204 displays the operator list screen on the touch panel 145D. However, at this time, if the startup of the gateway function controller 203 has not been completed, the monitor controller 204 executes a simple authentication process. Note that if the rotary switch 144 is in the ACC position, the engine 121 is not started. In other words, the starter signal unit 202 displays the operator list screen while the engine 121 is stopped. The monitor controller 204 accepts the selection of one operator ID from the operator list screen by the operator's operation (step S11).
[0048] The starter signal unit 202 confirms that the selected operator ID indicates a specific operator, and transmits a start signal to the control controller 205 (step S12). This starts the control controller 205 (step S13). Note that in another embodiment, the starter signal unit 202 may start the control controller 205 at the same timing as the monitor controller 204, step S9.
[0049] When the operator places the rotary switch 144 in the IG position, the starter signal unit 202 receives a signal indicating IG from the rotary switch 144 (step S14). The starter signal unit 202 transmits a start signal to the engine controller 206 (step S15). This starts the engine controller 206 (step S16).
[0050] When the operator places the rotary switch 144 in the ST position, the starter signal unit 202 receives a signal indicating ST from the rotary switch 144 (step S17). The starter signal unit 202 drives the starter motor 1211 (step S18). This starts the engine 121, and the working machine 100 becomes operable.
[0051] As described above, the gateway function controller 203 takes longer to start up than other devices, so by activating it on the condition that a specific operator is in the vicinity, the timing at which the gateway function controller 203 completes its activation can be accelerated.
[0052] <Authentication process> Here, the authentication process for the operator on board the work machine 100 by the control system 145 according to the first embodiment will be described. When the operator aboard the work machine 100 turns the rotary switch 144 to the ACC position, the signal input section 223 of the starter signal unit 202 receives input of a signal indicating ACC from the rotary switch 144. When the signal indicating ACC is input, the activation section 226 transmits an activation signal to the monitor controller 204.
[0053] When the monitor controller 204 is started up, the communication unit 241 transmits an arrival confirmation signal via the internal network to confirm whether or not the startup of the gateway function controller 203 has been completed. If the gateway function controller 203 is started up, the startup notification unit 234 of the gateway function controller 203 returns an ACK of the arrival confirmation signal. On the other hand, if the gateway function controller 203 is not started up, the communication unit 241 cannot receive the ACK of the arrival confirmation signal.
[0054] Fig. 6 is a flowchart showing the simple authentication process of the operator before the start of the gateway function controller 203 according to the first embodiment. Fig. 7 is an example of a display screen of the touch panel 145D in the simple authentication process according to the first embodiment. If the start-up of the gateway function controller 203 is not complete, the authentication unit 245 displays an operator selection screen D11 as shown in Fig. 7. The operator selection screen D11 displays the display name of the last authenticated operator stored in the storage unit 244 in a selectable manner, and displays a message indicating that other operators are being loaded. By touching the last authenticated operator here, a password input screen D12 for that operator is displayed (step S101). The acquisition unit 243 acquires a password from the operator via the touch panel 145D (step S102).
[0055] The authentication unit 245 performs authentication processing for the operator by comparing the password acquired in step S102 with the password stored in the storage unit 244 (step S103). If the password acquired in step S102 matches the password stored in the storage unit 244 (step S103: YES), the authentication unit 245 determines that the simple authentication of the operator has been successful. The display control unit 242 displays a login completion screen D13 on the touch panel 145D. The communication unit 241 outputs a completion notification of the simple authentication of the operator to the control controller 205 (step S104). When the control controller 205 receives the completion notification of the simple authentication, it uses the operation setting data recorded in a non-volatile memory (not shown) during the previous operation without initializing it.
[0056] This allows the control controller 205 to perform control based on the operation setting data at the time of the previous authentication. By recording the operation setting data at the time of the previous authentication in a non-volatile memory (not shown), the control controller 205 can reflect the operation setting data even when the startup of the gateway function controller 203 has not been completed.
[0057] On the other hand, if the password acquired in step S102 does not match the password stored in storage unit 244 (step S103: NO), monitor controller 204 returns the process to step S102 and continues the authentication process using the password.
[0058] However, although the input information stored in the storage unit 244 was successfully authenticated at the previous startup, it may not be the latest authentication information. For example, the master data stored in the server device 500 may have been updated between the previous startup and the current startup.
[0059] Fig. 8 is a flowchart showing the authentication process of an operator after the start-up of the gateway function controller 203 according to the first embodiment. Fig. 9 is an example of a display screen of the touch panel 145D in the authentication process according to the first embodiment. When the communication unit 241 of the monitor controller 204 receives a startup notification from the startup notification unit 234 of the gateway function controller 203, it executes the authentication process shown below. If the monitor controller 204 is currently executing the simple authentication shown in Fig. 6 above, the monitor controller 204 stops the simple authentication and executes the authentication process shown below.
[0060] The communication unit 241 acquires a list of operators who are able to operate the work machine 100 from the gateway function controller 203 (step S201). Next, the display control unit 242 generates a signal for displaying an operator list screen D21 for accepting selection of an operator ID based on the received list, and outputs the signal to the touch panel 145D (step S202). The operator list screen D21 includes the multiple operator IDs received from the gateway function controller 203. As a result, the touch panel 145D accepts selection of one operator from the multiple operators. The acquisition unit 243 acquires the operator ID from the operator via the touch panel 145D (step S203).
[0061] The communication unit 241 receives information about the operator terminal 300 connected in step S2 from the starter signal unit 202, and acquires an operator ID associated with the device address of the operator terminal 300 from the gateway function controller 203 (step S204). The authentication unit 245 determines whether the operator ID acquired by the acquisition unit 243 in step S203 matches the operator ID acquired in step S204 (step S205). If the operator ID acquired in step S203 matches the operator ID acquired in step S204 (step S205: YES), the authentication unit 245 determines that the authentication of the operator has been successful.
[0062] If the operator authentication is successful, the authentication unit 245 reads the operator ID acquired in step S203 and the password associated with the operator ID from the list received in step S201, and stores them in the storage unit 244 (step S206). Next, the authentication unit 245 determines whether the operator has already been authenticated by the simplified authentication shown in FIG. 6 (step S207). If the operator has not been authenticated by the simplified authentication (step S207: NO), the display control unit 242 causes the touch panel 145D to display an authentication success screen D22. Furthermore, the communication unit 241 outputs an instruction to the gateway function controller 203 to transmit operation setting data related to the authenticated operator ID (step S208). As a result, the gateway function controller 203 transmits the operation setting data related to the authenticated operator ID to the control controller 205. Then, the control controller 205 can perform control based on the operation setting data related to the authenticated operator ID. Then, the monitor controller 204 ends the authentication process.
[0063] On the other hand, if authentication has been performed using simplified authentication (step S207: YES), the display control unit 242 displays a reflection confirmation screen D23 on the touch panel 145D, which indicates that the operator's confirmation has been successful and includes a button for selecting whether or not to reflect the latest operation setting data, and accepts an input as to whether or not to reflect the operation setting data (step S209). Operation of this button is possible only when there has been no input from any of the operation devices 143 of the work machine 100. When the button for reflecting the latest operation setting data is pressed (step S209: YES), the communication unit 241 outputs an instruction to the gateway function controller 203 to send the operation setting data related to the authenticated operator ID (step S208). As a result, the latest operation setting data is reflected in the control controller 205. Note that by accepting button operation only when there has been no operation, it is possible to prevent the operation setting data from being changed during operation of the work machine 100, causing a sudden change in operation. On the other hand, if a button indicating that the latest operation setting data is not to be reflected is pressed (step S209: NO), the monitor controller 204 ends the authentication process.
[0064] If authentication of the operator fails in step S205 (step S205: NO), the authentication unit 245 determines whether the operator has been authenticated by the simplified authentication shown in Fig. 6 (step S210). If simplified authentication has not been performed (step S210: NO), the monitor controller 204 returns the process to step S203 and continues the authentication process.
[0065] On the other hand, if simplified authentication has been performed (step S210: YES), there is a possibility that the operator on board the work machine 100 is an unauthorized operator. Therefore, the display control unit 242 causes the touch panel 145D to display a warning screen D24 urging the work machine 100 to stop (step S211), and ends the processing. In other words, the display control unit 242 is an example of a warning unit. At this time, the monitor controller 204 may output an instruction to a speaker (not shown) to emit a warning sound inside the cab 140 and outside the work machine 100.
[0066] Actions and Effects Thus, according to the first embodiment, the control system 145 comprises a gateway function controller 203 that stores master data for authenticating a plurality of operators who are able to operate the work machine 100, and a monitor controller 204 that authenticates operators who operate the work machine 100. The monitor controller 204 stores a combination of operator ID and password of previously authenticated operators as authentication information, and when the gateway function controller 203 is not running, authenticates the operator based on the stored authentication information. This allows the control system 145 to authenticate the operator even when the gateway function controller 203 is not running.
[0067] Furthermore, when the gateway function controller 203 is activated, the control system 145 according to the first embodiment displays an authentication screen that allows the selection of multiple operators. In other words, the control system 145 accepts the selection of one operator from multiple operators and authenticates the operator by determining whether or not the selected operator is an operator in the vicinity of the work machine 100. Because it is difficult for an outsider who does not have the operating authority to recognize a specific operator in the vicinity, the control system 145 can prevent unauthorized logins with simple logic.
[0068] In the control system 145 according to the first embodiment, when the gateway function controller 203 is started after authentication has been performed based on past input information stored in the monitor controller 204, authentication is performed again based on the master data stored in the gateway function controller 203. The past input information stored in the monitor controller 204 is not the latest authentication information. For example, the operator's authority may have changed in the server device 500 between the previous startup of the work machine 100 and the current startup. Therefore, by performing authentication again based on the master data stored in the gateway function controller 203, it is possible to prevent use by an unauthorized user, such as an operator whose authority has changed between the previous startup and the current startup.
[0069] The monitor controller 204 according to the first embodiment stores authentication information of the most recently authenticated operator among a plurality of operators. This allows the monitor controller 204 to realize authentication before the start of the gateway function controller 203 while minimizing the amount of nonvolatile memory used. Furthermore, the control controller 205 stores the operation setting data of the most recently authenticated operator among a plurality of operators in a nonvolatile manner. In other words, the control controller 205 can retain the operation setting data of the most recently authenticated operator by not initializing the operation setting data at the time of the previous authentication at the time of start-up. This allows the control controller 205 to reflect the settings of the authenticated operator while minimizing the amount of nonvolatile memory used.
[0070] Second Embodiment According to the control system 145 of the first embodiment, the monitor controller 204 stores authentication information of the last authenticated operator and performs simple authentication processing. In contrast to this, in the second embodiment, the gateway function controller 203 stores authentication information of the last authenticated operator and performs simple authentication processing. Specifically, the gateway function controller 203 includes two pieces of hardware: first hardware included in the master storage unit 232, and second hardware that starts up earlier than the first hardware, and the second hardware stores authentication information of the last authenticated operator in the second hardware and performs simple authentication processing. Furthermore, the authentication processing after startup of the first hardware is performed by the first hardware. Furthermore, the control system 145 of the second embodiment performs authentication using a password in both the simple authentication processing and the authentication processing.
[0071] The second hardware of the gateway function controller 203 according to the second embodiment has already been activated when the monitor controller 204 is activated in step S9 shown in Fig. 5. When the monitor controller 204 acquires a password in step S102 of Fig. 6, it transmits the password to the second hardware of the gateway function controller 203, and the second hardware performs authentication processing in step S103. If the authentication is successful, the second hardware outputs a notification of completion of simple authentication to the monitor controller 204 and the control controller 205.
[0072] FIG. 10 is a flowchart showing the authentication process of an operator after the first hardware of the gateway function controller 203 according to the second embodiment is started up. When the first hardware of the gateway function controller 203 starts up, the control system 145 executes the authentication process described below.
[0073] The communication unit 241 of the monitor controller 204 acquires a list of operators who are able to operate the work machine 100 from the gateway function controller 203 (step S401). Next, the display control unit 242 generates a signal for displaying an operator list screen D21 based on the received list, and outputs it to the touch panel 145D (step S402). The acquisition unit 243 acquires an operator ID from the operator via the touch panel 145D (step S403). The communication unit 241 transmits the acquired operator ID to the first hardware of the gateway function controller 203.
[0074] Next, the first hardware of the gateway function controller 203 acquires the password (step S404). Specifically, the first hardware acquires the password in the following procedure. The first hardware sends a password request to the second hardware. If the second hardware has already acquired the password in simple authentication, the first hardware can acquire the password from the second hardware. On the other hand, if the second hardware has not acquired the password, the second hardware sends information indicating that the password has not been acquired to the first hardware. Upon receiving the information indicating that the password has not been acquired, the first hardware sends a password request to the monitor controller 204. Upon receiving the password request, the monitor controller 204 displays the password input screen D12 shown in FIG. 7 and acquires the password from the operator. This allows the first hardware to acquire the password from the monitor controller 204.
[0075] The first hardware determines whether the combination of the operator ID acquired in step S403 and the password acquired in step S404 is recorded in the master storage unit 232 (step S405). If the combination of the operator ID and password matches the information stored in the master storage unit 232 (step S405: YES), the first hardware determines that the authentication of the operator has been successful.
[0076] If the authentication of the operator is successful, the first hardware transmits the combination of the device address, operator ID, and password associated with the authenticated operator from the master storage unit 232 to the second hardware. The second hardware records the information received from the first hardware (step S406). Next, the first hardware determines whether the operator has already been authenticated by simple authentication by the second hardware (step S407). If authentication by simple authentication has not been performed (step S407: NO), the first hardware transmits an instruction to the monitor controller 204 to display the authentication success screen D22 shown in FIG. 9. Furthermore, the first hardware outputs an instruction to the gateway function controller 203 to transmit operation setting data associated with the authenticated operator ID (step S408).
[0077] On the other hand, if authentication has been performed using simple authentication (step S407: YES), the first hardware transmits to the monitor controller 204 an instruction to display the reflection confirmation screen D23 shown in Fig. 9. The monitor controller 204 determines whether the button on the reflection confirmation screen D23 pressed by the operator is a button for reflecting the operation setting data (step S409). When the monitor controller 204 accepts pressing of the button for reflecting the latest operation setting data (step S409: YES), the first hardware outputs to the gateway function controller 203 an instruction to transmit the operation setting data related to the authenticated operator ID (step S408). On the other hand, when the button for not reflecting the latest operation setting data is pressed (step S409: NO), the control system 145 ends the authentication process.
[0078] If authentication of the operator fails in step S405 (step S405: NO), the first hardware determines whether the operator has been authenticated by simple authentication by the second hardware (step S410). If simple authentication has not been performed (step S410: NO), the control system 145 returns to step S403 and continues the authentication process.
[0079] On the other hand, if simple authentication has been performed (step S410: YES), the first hardware transmits an instruction to display the warning screen D24 shown in FIG. 9 to the monitor controller 204 (step S411), and ends the process.
[0080] Other Embodiments Although one embodiment has been described in detail above with reference to the drawings, the specific configuration is not limited to the above, and various design modifications are possible. That is, in other embodiments, the order of the above-described processes may be changed as appropriate. Furthermore, some processes may be executed in parallel. The starter signal unit 202 according to the above-described embodiment may be configured by a single computer, or the configuration of the starter signal unit 202 may be divided among multiple computers that work together to function as the starter signal unit 202. For example, within the starter signal unit 202, the function of outputting a start signal and the function of authenticating an operator may be implemented in separate computers. Some of the computers that make up the starter signal unit 202 may be mounted inside the work machine 100, and other computers may be provided outside the work machine 100.
[0081] In the control system 145 according to the embodiment described above, some of the components that make up the control system 145 may be mounted inside the work machine 100, and other components may be provided outside the work machine 100.
[0082] The operator terminal 300 according to the embodiment described above is a terminal capable of executing an application program, such as a smartphone, but is not limited to this. For example, the operator terminal 300 according to another embodiment may be a key fob that only has the function of outputting a predetermined advertising packet. Note that when the operator terminal 300 is a key fob, it is not possible to accept the selection of a work machine 100 to be started by an application program. In this case, of the work machines 100 that have received an advertising packet, all of those for which the operator ID included in the advertising packet is set as a specific operator may be started.
[0083] The monitor controller 204 according to the embodiment described above stores the authentication information of the last authenticated operator, but is not limited to this. For example, the monitor controller 204 according to other embodiments may store the authentication information of two or more operators. For example, the monitor controller 204 may always store the authentication information of the most recent three operators. Also, for example, the monitor controller 204 may store authentication information related to an operator who frequently uses the work machine 100.
[0084] According to the control system 145 of the first embodiment, the monitor controller 204 stores the authentication information of the last authenticated single operator and performs the simple authentication process. According to the control system 145 of the second embodiment, the second hardware of the gateway function controller 203 stores the authentication information of the last authenticated single operator and performs the simple authentication process. In contrast, in the control system 145 of other embodiments, a controller other than the monitor controller 204 that starts up earlier than the gateway function controller 203 including the master storage unit 232 may store the authentication information, and the controller may perform the simple authentication process.
[0085] The monitor controller 204 according to the embodiment described above outputs a warning urging the operator to stop using the work machine 100 when the authentication shown in Fig. 8 fails despite the operator having been authenticated by the simplified authentication shown in Fig. 6, but is not limited to this. For example, the monitor controller 204 according to another embodiment may cause the control controller 205 to stop outputting a control signal when the authentication shown in Fig. 8 fails despite the operator having been authenticated by the simplified authentication shown in Fig. 6. In other words, the monitor controller 204 may be equipped with a stop control unit that stops the work machine 100.
[0086] Furthermore, although the monitor controller 204 according to the above-described embodiment performs authentication using a password as simple authentication, this is not limited to this. For example, the monitor controller 204 according to another embodiment may obtain a device address included in a BLE advertisement packet from the starter signal unit 202 via an internal network and perform simple authentication by matching the device address. Furthermore, the monitor controller 204 according to another embodiment may perform biometric authentication.
[0087] The work machine 100 according to the embodiment described above is a hydraulic excavator, but is not limited to this in other embodiments. For example, the work machine according to other embodiments may be another work machine such as a dump truck, a wheel loader, or a motor grader.
[0088] <Computer Configuration> FIG. 11 is a schematic block diagram illustrating the configuration of a computer according to at least one embodiment. Each device (such as the starter signal unit 202, gateway function controller 203, monitor controller 204, and control controller 205) included in the control system 145 described above is implemented in a computer 900. The computer 900 includes a processor 910, a main memory 930, a storage 950, and an interface 970. The operation of each of the processing units described above is stored in the storage 950 in the form of a program. The processor 910 reads the program from the storage 950, loads it into the main memory 930, and executes the above-described processing in accordance with the program. The processor 910 also allocates storage areas in the main memory 930 corresponding to each of the storage units described above in accordance with the program. Examples of the processor 910 include a CPU (Central Processing Unit), a GPU (Graphic Processing Unit), and a microprocessor.
[0089] The program may be for realizing some of the functions to be performed by the computer 900. For example, the program may be combined with other programs already stored in storage or other programs implemented in other devices to perform the functions. In other embodiments, the computer 900 may include a custom LSI (Large Scale Integrated Circuit) such as a PLD (Programmable Logic Device) in addition to or instead of the above configuration. Examples of PLDs include PAL (Programmable Array Logic), GAL (Generic Array Logic), CPLD (Complex Programmable Logic Device), and FPGA (Field Programmable Gate Array). In this case, some or all of the functions realized by the processor 910 may be realized by the integrated circuit. Such an integrated circuit is also an example of a processor.
[0090] Examples of storage 950 include a magnetic disk, a magneto-optical disk, an optical disk, and a semiconductor memory. Storage 950 may be an internal medium directly connected to the bus of computer 900, or an external medium connected to computer 900 via interface 970 or a communication line. Furthermore, when this program is distributed to computer 900 via a communication line, computer 900 that receives the program may load the program into main memory 930 and execute the above-described processing. In at least one embodiment, storage 950 is a non-transitory tangible storage medium.
[0091] The program may also be a program for realizing some of the above-described functions. Furthermore, the program may be a so-called differential file (differential program) that realizes the above-described functions in combination with another program already stored in storage 950. [Explanation of symbols]
[0092] 100...Work machine 110...Traveling body 111...Crawler 112...Travel motor 120...Swinging body 121...Engine 1211...Starter motor 122...Hydraulic pump 123...Control valve 124...Swing motor 125...Fuel injection device 130...Working machine 131...Boom 131C...Boom cylinder 132...Arm 132C...Arm cylinder 133...Bucket 133C...Bucket cylinder 140...Operator's cab 141...Door 1411...Lock actuator 1412...Door switch 142...Operator's seat 143...Operating device 143LF...Left foot pedal 143LO...Left operating lever 143LT...Left travel lever 143RF...Right foot pedal 143RO...Right operating lever 143RT...Right travel lever 144...Rotary switch 145...Control system 145D...touch panel 201...power supply unit 202...starter signal unit 203...gateway function controller 204...monitor controller 205...control controller 206...engine controller 207...wide area communication controller 221...BLE communication unit 222...network communication unit 223...signal input unit 224...operator memory unit 225...proximity detection unit 226...startup unit 227...state memory unit 231...master receiving unit 232...master memory unit 233...master output unit 234...startup notification unit 241...communication unit 242...display control unit 243...acquisition unit 244...memory unit 245...authentication unit 300...operator terminal 500...server device 900...computer 910...processor 930...main memory 950...storage 970...interface
Claims
1. a management device that stores authentication information for authenticating a plurality of operators who are permitted to operate the work machine; an authentication device that authenticates an operator who operates the work machine; Equipped with The authentication device a storage unit that stores the authentication information of operators who have been authenticated in the past; an authentication unit that authenticates the operator based on the authentication information stored in the storage unit when the management device is not running; A starting system for a work machine comprising:
2. The storage unit stores the authentication information of the last authenticated operator.
2. The starting system for a work machine according to claim 1.
3. The storage unit stores the authentication information of two or more operators who have been authenticated in the past.
3. A starting system for a work machine according to claim 1 or 2.
4. The authentication device a display control unit that displays an authentication screen for receiving input information for authenticating the previously authenticated operator when the management device is not running; The starting system for a work machine according to any one of claims 1 to 3, comprising:
5. the authentication information includes a password; The display control unit accepts a password by inputting it on the authentication screen.
5. A starting system for a work machine according to claim 4.
6. the display control unit displays an authentication screen that receives input information for authenticating the plurality of operators when the management device is running; The authentication unit authenticates the operator based on the authentication information stored in the management device when the management device is running.
6. A starting system for a work machine according to claim 4 or claim 5.
7. The authentication unit authenticates the operator based on input information acquired via internal communication of the work machine and the authentication information stored in the storage unit. A starting system for a work machine according to any one of claims 1 to 6.
8. When the management device is started after authentication based on the authentication information stored in the storage unit, the authentication unit authenticates the authenticated operator based on the authentication information stored in the management device. A starting system for a work machine according to any one of claims 1 to 7.
9. The authentication device a warning unit that outputs a warning when authentication based on the authentication information stored in the management device fails after authentication based on the authentication information stored in the storage unit; 9. A starting system for a work machine according to claim 8.
10. The authentication device a stop control unit that stops the work machine when authentication based on the authentication information stored in the management device fails after authentication based on the authentication information stored in the storage unit 10. A starting system for a work machine according to claim 8 or claim 9.
11. a vehicle body control device for controlling a vehicle body of the work machine, the management device stores the authentication information and operation setting data for each of the plurality of operators; The vehicle body control device controls the vehicle body based on the operation setting data related to the authenticated operator. A starting system for a work machine according to any one of claims 1 to 10.
12. A method for starting a work machine that includes a management device that stores authentication information for authenticating a plurality of operators, and an authentication device that authenticates the operators, comprising: When the management device is not running, the authentication device authenticates the operator based on the authentication information of previously authenticated operators stored in a storage unit. A method for starting a work machine having the above-mentioned features.
Citation Information
Patent Citations
Locked function releasing apparatus for display and construction equipment
JP2002070084A
Starting control system
JP2013185502A
Construction machine management system
JP2015164847A
Construction machine replacement article management system
JP2017008524A
Work machine
JP2020158997A