MOBILE OBJECT MANAGEMENT DEVICE, MOBILE OBJECT MANAGEMENT SYSTEM, AND METHOD FOR DISABLEING REMOTE CONTROL FUNCTION
The mobile object management device addresses security risks in remote-controlled vehicles by disabling vulnerable functions based on acquired vulnerability information, enhancing security and preventing unauthorized use.
Patent Information
- Application Number
- JP2023065478
- Authority / Receiving Office
- JP · JP
- Patent Type
- Patents
- Current Assignee / Owner
- Filing Date
- 2023-04-13
- Publication Date
- 2025-10-28
- Estimated Expiration
- 2043-04-13
AI Technical Summary
There is a risk of remote control functions being exploited due to vulnerabilities in vehicles after shipment, posing security threats during autonomous driving operations.
A mobile object management device that acquires vulnerability information and instructs vehicles with identified vulnerabilities to disable their remote control functions, using correspondence data to identify affected vehicles and execute disablement processes based on predefined conditions.
Prevents misuse of remote control functions in vehicles by disabling them when vulnerabilities are detected, ensuring secure operation and reducing the risk of unauthorized access.
Smart Images

Figure 0007761021000001 
Figure 0007761021000002 
Figure 0007761021000003
Abstract
Description
[Technical Field]
[0001] The present disclosure relates to a mobile object management device, a mobile object management system, and a method for disabling a remote control function. [Background technology]
[0002] For example, Patent Document 1 discloses a vehicle running method in a manufacturing system for manufacturing vehicles, in which a vehicle is run by remote control from the end of an assembly line of the manufacturing system to a parking lot of the manufacturing system. [Prior art documents] [Patent documents]
[0003] [Patent Document 1] Special Publication No. 2017-538619 Summary of the Invention [Problem to be solved by the invention]
[0004] There is a demand for remote-controlled autonomous driving to be used even after the vehicle is used in a factory where the vehicle is manufactured, for example, for transporting the vehicle at intermediate points after it is shipped from the factory, loading the vehicle onto a ship, etc., and for businesses that use autonomous driving at the shipping destination. However, if a vulnerability in the remote control function, such as a security hole, is discovered, there is a possibility that the remote control function of the vehicle after it is shipped may be exploited. [Means for solving the problem]
[0005] The present disclosure can be realized in the following forms.
[0006] (1) According to one aspect of the present disclosure, there is provided a mobile object management device for managing a plurality of mobile objects having a remote control function that move by remote control, the mobile object management device including: an information acquisition unit for acquiring vulnerability information regarding vulnerabilities in the remote control function; and a disable instruction unit for instructing the mobile objects having the vulnerability identified using the vulnerability information to disable the remote control function. According to this form of mobile object management device, the remote control function of a mobile object having a vulnerability can be disabled based on the acquired vulnerability information, thereby suppressing or preventing the remote control function of the mobile object from being misused after shipment. (2) The mobile object management device of the above aspect may further include a correspondence data storage unit that stores correspondence data between identification information of the mobile object and program information related to the remote control function provided in the mobile object. When the program information having the vulnerability is identified using the acquired vulnerability information, the disable instruction unit may use the stored correspondence data to extract the identification information of the mobile object having the identified program information, and instruct the mobile objects corresponding to the extracted identification information to disable the remote control function. According to the mobile object management device of this embodiment, vulnerable mobile objects can be identified by a simple process using the correspondence data. (3) The mobile object management device of the above aspect may further include an identifying unit that identifies the program information having the vulnerability using the acquired vulnerability information. According to the mobile object management device of this aspect, it is possible to extract multiple mobile objects having vulnerabilities at an earlier stage than when program information having vulnerabilities is manually identified. (4) In the mobile object management device of the above aspect, the information acquisition unit may further acquire the vulnerability information by analyzing data including at least one of text and images via the Internet. According to the mobile object management device of this aspect, it is possible to automatically acquire vulnerability information and to expand the range of vulnerability information acquired. (5) The mobile object management device of the above embodiment may further include a notification unit that issues a notification to the extracted mobile object having the vulnerability to prompt the mobile object to at least one of disable the remote control function and take measures to eliminate the vulnerability. According to this type of mobile management device, the remote control function can be disabled and measures to address the vulnerability can be implemented, thereby quickly eliminating the risk caused by the vulnerability of the remote control function. (6) In the mobile management device of the above form, after issuing an instruction to disable the remote control function, a disablement execution unit may be further provided which executes a disablement process to disable the remote control function when a predetermined execution condition is met. According to the mobile object management device of this aspect, the timing at which the remote control function is disabled can be set to any timing at which the execution condition is met. (7) In the mobile body management device of the above form, the execution condition may be that the mobile body is equipped with a mobile body communication unit for receiving radio waves for remote control and the disabling execution unit, and the radio waves for remote control that were detected by the mobile body that received an instruction to disable the remote control function are no longer detected. According to the mobile object management device of this embodiment, radio waves for wireless communication used for remote control of the mobile object can be used as an execution condition as so-called geofencing. (8) In the mobile object management device of the above aspect, the execution condition may be that the mobile object that has received the instruction to disable the remote control function has been stopped. According to the mobile object management device of this aspect, it is possible to suppress or prevent the invalidation process from being executed while the mobile object is moving under remote control. (9) In the mobile object management device of the above aspect, the execution condition may be that the mobile object is not using the remote control function. According to the mobile object management device of this aspect, it is possible to suppress or prevent the invalidation process from being executed while the mobile object is moving under remote control. (10) In the mobile object management device of the above aspect, the execution condition may be that the moving speed of the mobile object that has received the instruction to disable the remote control function is equal to or less than a predetermined reference speed. According to the mobile object management device of this aspect, it is possible to disable the remote control function when the movement of the mobile object is at or below the reference speed. (11) In the mobile object management device of the above aspect, the execution condition may be that all personnel on board the mobile object have disembarked. According to the mobile object management device of this aspect, it is possible to suppress or prevent the remote control from being disabled when a person is on board a mobile object that is moving under remote control. (12) In the mobile object management device of the above aspect, the mobile object may be a vehicle that can be driven by the remote control within a factory during a manufacturing process of the vehicle. According to the mobile object management device of this embodiment, it is possible to suppress or prevent the misuse of the remote control function of a mobile object in the manufacturing process in a factory. (13) In the mobile management device of the above form, the vulnerability information may be at least one of information regarding security holes in the remote control function, information regarding hacking of the remote control function, information regarding program defects related to the remote control function, information regarding computer viruses that affect the remote control function, and information regarding distrust of the remote control function. (14) According to another aspect of the present disclosure, there is provided a mobile object management system for managing a plurality of mobile objects having a remote control function that move by remote control, the mobile object management system including: a disablement execution unit that is provided in the mobile object and that executes a disablement process to disable the remote control function, an information acquisition unit that acquires vulnerability information regarding vulnerabilities in the remote control function, and a disablement instruction unit that uses the acquired vulnerability information to instruct the disablement execution unit of a mobile object that has been extracted as having the vulnerability to disable the remote control function. According to this form of mobile object management system, the remote control function of a vulnerable mobile object can be disabled based on the acquired vulnerability information, thereby suppressing or preventing the remote control function of the mobile object from being misused. The present disclosure can also be realized in various forms other than a mobile object management device and a mobile object management system, such as a mobile object, a server, a mobile object management method, a mobile object manufacturing method, a mobile object control method, a mobile object management device control method, a computer program for implementing these control methods, a non-transitory recording medium on which the computer program is recorded, etc. [Brief explanation of the drawings]
[0007] [Figure 1] FIG. 1 is an explanatory diagram showing the configuration of a mobile object management system according to a first embodiment. [Figure 2] FIG. 2 is a block diagram showing the functional configuration of the vehicle management device according to the first embodiment. [Figure 3] FIG. 2 is an explanatory diagram showing an outline of correspondence data. [Figure 4] FIG. 2 is a block diagram showing the functional configuration of a remote control device. [Figure 5] FIG. 1 is an explanatory diagram showing an overview of automatic driving of a vehicle by remote control of a remote automatic driving system. [Figure 6] FIG. 2 is a block diagram showing the internal functional configuration of the ECU. [Figure 7] 4 is a flowchart showing a method for disabling remote control according to the first embodiment. [Figure 8] 10 is a flowchart showing a method for disabling remote control according to the second embodiment. [Figure 9] FIG. 11 is an explanatory diagram showing the configuration of execution conditions used in the remote control disabling method according to the third embodiment. [Figure 10] 10 is a flowchart showing a method for disabling remote control according to the fourth embodiment. [Figure 11] FIG. 11 is a block diagram showing the functional configuration of a vehicle management device according to a fifth embodiment. [Figure 12] 13 is a flowchart showing a method for disabling remote control according to the fifth embodiment. DETAILED DESCRIPTION OF THE INVENTION
[0008] A. First embodiment: FIG. 1 is an explanatory diagram showing the configuration of a mobile object management system 700 according to the first embodiment. The mobile object management system 700 includes a mobile object management device 500 and a remote control device 300. The mobile object management device 500 manages mobile objects that have a remote control function. The "remote control function" refers to a function that automatically moves a mobile object by remote control.
[0009] A "mobile body" refers to an object that can move. FIG. 1 shows vehicles 100p, 100q, 100r, 100s, 100t, and 100u as examples of mobile bodies. When vehicles 100p, 100q, 100r, 100s, 100t, and 100u are not distinguished from one another, they are collectively referred to as "vehicles 100." In the example of FIG. 1, multiple vehicles 100 are shown, but the vehicle management device 500 may manage a single vehicle 100.
[0010] In this embodiment, the vehicle 100 may be, for example, a passenger car, a truck, a bus, or a construction vehicle. The vehicle 100 may be, for example, various vehicles such as automobiles, such as motorcycles and four-wheeled vehicles, or trains. Furthermore, the mobile object is not limited to vehicles, but may also include ships, aircraft, robots, linear motor cars, and the like. In this disclosure, the terms "vehicle" and "car" may be appropriately replaced with "mobile object," and the terms "traveling" and "running" may be appropriately replaced with "moving." In the following description, the mobile object management system 700 may also be referred to as the "vehicle management system 700," and the mobile object management device 500 may also be referred to as the "vehicle management device 500." In this specification, the term "vehicle" refers to both completed products and semi-finished or work-in-progress products in the middle of production.
[0011] 2 is a block diagram showing the functional configuration of a vehicle management device 500 according to the first embodiment. The vehicle management device 500 includes a CPU 510 as a central processing unit, a storage device 520, and a management device communication unit 590, which are interconnected via an internal bus, an interface circuit, etc. The management device communication unit 590 is a circuit for communicating with the vehicle 100, the remote control device 300, the information providing device 400, etc. via a network, etc.
[0012] The storage device 520 is, for example, a RAM, a ROM, a HDD (hard disk drive), an SSD (solid state drive), etc. The storage device 520 functions as a correspondence data storage unit that stores the correspondence data 522.
[0013] FIG. 3 is an explanatory diagram showing an overview of the correspondence data 522. As shown in FIG. 3, the correspondence data 522 defines the correspondence between the vehicle identification information of the vehicle 100 and program information related to the remote control function provided in the vehicle 100. "Vehicle identification information" refers to various information that can individually identify the vehicle 100. The vehicle identification information includes, for example, ID information assigned to each vehicle 100, such as a VIN (Vehicle Identification Number), specification information of the vehicle 100, such as the model, color, and shape, and production management information of the vehicle 100, such as the name of the process in progress. The vehicle identification information can be acquired, for example, via short-range wireless communication from an RF-ID (Radio Frequency-Identification) tag or the like attached to the vehicle 100.
[0014] "Program information related to the remote control function" refers to information related to a computer's OS or software program for implementing the remote control function, such as version information of the remote control program. By referencing the correspondence data 522, the vehicle management device 500 can manage, for each vehicle identification information, the enabled / disabled state of the remote control function of the vehicle 100 and program information related to the remote control function of the vehicle 100. The correspondence data 522 may further include information related to vulnerabilities of the remote control function, such as the "presence or absence of vulnerabilities" shown in FIG. 3. The correspondence data 522 may also include information related to the remote control implementation schedule, such as whether the owner of the vehicle 100 plans to remotely control the vehicle 100 to automatically drive the vehicle 100. The remote control implementation schedule can be used, for example, to determine whether to disable remote control.
[0015] 2, various programs for realizing the functions provided in this embodiment are further stored in the storage device 520. When the computer programs stored in the storage device 520 are executed by the CPU 510, the CPU 510 functions as an information acquisition unit 512, an invalidation instruction unit 514, a notification unit 516, and the like. However, some or all of these functions may be configured by hardware circuits.
[0016] The information acquisition unit 512 acquires vulnerability information related to vulnerabilities in the remote control function. In this embodiment, as shown in FIG. 1 , the information acquisition unit 512 acquires vulnerability information from the remote control device 300, the information providing device 400, the vehicle 100, and the like. "Vulnerability information" refers to information related to vulnerabilities in the remote control function or the likelihood of such vulnerabilities. A vulnerability in the remote control function refers to a security flaw caused by, for example, a program defect in the OS or software of a computer used to implement the remote control function. The vulnerability information may include at least one of information related to security holes in the remote control function, information related to hacking of the remote control function, information related to program defects related to the remote control function, information related to computer viruses that affect the remote control function, and information related to distrust of the remote control function.
[0017] "Information regarding security holes in the remote control function" includes, for example, information regarding the existence or possibility of a security hole in the remote control program 224, and information regarding the existence or possibility of a security hole in a program, etc., of a device, etc., that is used to realize the remote control function, such as an ECU (Electronic Control Unit) provided in the vehicle 100. "Information regarding hacking of the remote control function" includes information regarding the fact that the remote control program or a device, etc., that is used to realize the remote control function has been hacked, or the possibility of this. "Information regarding defects in the program related to the remote control function" includes information regarding the existence or possibility of a defect in the program, such as the remote control program or ECU, etc.
[0018] "Information regarding computer viruses that affect remote control functions" includes information regarding the discovery or potential discovery of computer viruses that may affect remote control programs or devices used to activate remote control functions. "Information regarding distrust of remote control functions" includes the above information as well as information regarding growing distrust of remote control functions among the general public, such as customers and general consumers, or the potential risk of this. "Information regarding distrust of remote control functions" may include, for example, information published in the mass media, such as newspapers or television, that increases or is likely to increase the public's anxiety about remote control functions.
[0019] The disable instruction unit 514 instructs a vehicle 100 having a vulnerability to disable the remote control function. Whether or not a vehicle 100 has a vulnerability can be determined using vulnerability information. In this embodiment, whether or not a vehicle 100 has a vulnerability is determined, for example, manually by a user of the vehicle management device 500 that has acquired the vulnerability information or a predetermined worker. Furthermore, whether or not a vehicle 100 has a vulnerability is determined, for example, for each piece of program information related to the remote control function. In this embodiment, the disable instruction unit 514 references the correspondence data 522 and extracts, as a vehicle 100 having a vulnerability, a vehicle 100 having vehicle identification information associated with program information determined to have a vulnerability. The disable instruction unit 514 does not disable the remote control function of a vehicle 100 that does not have a vulnerability, such as the vehicle 100s shown in FIG. 1, due to differences in version information of the remote control program, etc.
[0020] The notification unit 516 issues a notification to the vehicle 100 having the extracted vulnerability. More specifically, the notification unit 516 issues a notification to prompt the vehicle 100 to take measures to disable the remote control function or to take measures to eliminate the vulnerability of the remote control function.
[0021] Returning to FIG. 1 , the remote control device 300 remotely controls the vehicle 100 to automatically travel. The remote control device 300 is installed, for example, at each base where remote control of the vehicle 100 is performed. Examples of bases where remote control is performed include a factory FC that manufactures the vehicle 100p, a dealer DL for the vehicle 100q, and a business operator CR that uses the vehicle 100u to provide services.
[0022] In the factory FC, the remote control device 300 transports the vehicle 100p using remotely controlled automatic driving during the manufacturing process of the vehicle 100p, for example. Transporting the vehicle 100p using remotely controlled automatic driving is also called "self-driving transport." Self-driving transport of the vehicle 100p can reduce or prevent human-caused accidents while the vehicle 100p is traveling. In the dealership DL, the remotely controlled automatic driving of the vehicle 100q is used for automatic parking in the parking lot within the dealership DL, demonstrations for customers, and the like. In the business operator CR, the remotely controlled automatic driving of the vehicle 100u is used for businesses such as a mobility service business (MaaS: Mobility as a Service).
[0023] The remote control device 300 is communicably connected to the vehicle management device 500. The remote control device 300 can provide vulnerability information acquired for each base to the vehicle management device 500. In this embodiment, vulnerabilities or potential vulnerabilities in the remote control function are identified for each base by a user or administrator of the remote control device 300, and are manually provided to the vehicle management device 500 by these persons. By collecting vulnerability information for each base, vulnerability information for multiple vehicles 100 that are managed by the vehicle management device 500 can be efficiently acquired.
[0024] In this embodiment, the vehicle management system 700 further includes an information providing device 400. The information providing device 400 is communicatively connected to the vehicle management device 500. The information providing device 400 is used by an information provider WH to acquire vulnerability information from the information provider WH. The information provider WH is, for example, a white hat hacker. The information provider WH analyzes the remote control program of the vehicle 100 and provides the vulnerability information obtained to the vehicle management device 500 via the information providing device 400. The configuration of the information providing device 400 is similar to that of the remote control device 300, except that the information providing device 400 does not have a remote control function, and therefore detailed description thereof will be omitted.
[0025] Vulnerability information can also be provided by vehicles 100 supplied to general consumers, such as vehicles 100r, 100s, and 100t. For example, the vehicle 100 detects unauthorized access to an ECU mounted on the vehicle 100 as vulnerability information. The vehicle 100 that detects vulnerability information provides the vulnerability information to the vehicle management device 500 via communication equipment dedicated to the vehicle 100.
[0026] 4 is a block diagram showing the functional configuration of the remote control device 300. The remote control device 300 includes a CPU 310 as a central processing unit, a storage device 320, and a remote communication unit 390, which are interconnected via an internal bus, an interface circuit, etc. The remote communication unit 390 is a circuit for communicating with the vehicle management device 500, the vehicle 100, other remote control devices 300, the information providing device 400, etc. via a network, etc.
[0027] The storage device 320 is, for example, a RAM, a ROM, an HDD (hard disk drive), an SSD (solid state drive), etc. The acquired vulnerability information 322 may be stored in a readable / writable area of the storage device 320. The storage device 320 also stores various programs for realizing the functions provided in this embodiment. When the computer programs stored in the storage device 320 are executed by the CPU 310, the CPU 310 functions as a remote control unit 312, an information providing unit 314, etc. However, some or all of these functions may be configured by hardware circuits.
[0028] The remote control unit 312 executes automatic driving of the vehicle 100 by remote control. More specifically, the remote control unit 312 transmits a control signal requesting remote control to the vehicle 100 via the remote communication unit 390. When the vehicle 100 accepts the request for remote control, the ECU of the vehicle 100 realizes driving control in accordance with the control signal, and as a result, the vehicle 100 drives automatically. The information providing unit 314 provides the acquired vulnerability information 322 to the vehicle management device 500, etc.
[0029] FIG. 5 is an explanatory diagram showing an overview of the autonomous driving of the vehicle 100 under the remote control of a remote autonomous driving system 600 including a remote control device 300. FIG. 5 schematically shows the remote autonomous driving system 600 in the factory FC, one of the bases shown in FIG. 1. The factory FC is equipped with a manufacturing process for the vehicle 100, a road RT on which the vehicle 100 can travel, and a parking lot PA. The manufacturing process for the vehicle 100 includes an inspection process 60 and an assembly process (not shown). The assembly process is, for example, a process of assembling parts into a vehicle body. The road RT may include, for example, a transport section for the vehicle 100 connecting between processes, as well as a transport section for the vehicle 100 connecting the inspection process 60 to the parking lot PA. After completing the inspection process 60, the vehicle 100 is completed as a product and automatically drives to the parking lot PA under the remote control of the remote autonomous driving system 600.
[0030] The vehicle 100 includes a vehicle communication unit 190, a power receiving device 150, a battery 120, a PCU 130, a motor 140, and an ECU 200. The vehicle communication unit 190 is a wireless communication device, such as a dongle, mounted on the vehicle 100. The vehicle communication unit 190 has a communication function for communicating using CAN (Controller Area Network) communication, which can be used for controlling the vehicle 100, and diagnosis communication, which can be used for fault diagnosis. CAN communication is a communication standard that enables multi-directional transmission and reception. Diagnosis communication is a communication standard that enables one-to-one correspondence between requests and responses. The vehicle communication unit 190 performs wireless communication with devices external to the vehicle 100, such as a mobile object management device 500 and a remote control device 300, connected to a network 72, via an access point 70 in a factory FC, for example.
[0031] The power receiving device 150 converts AC power supplied from an external power supply device or the like into DC power using a rectifier and supplies the DC power to the battery 120 as a load. The battery 120 is, for example, a rechargeable secondary battery such as a lithium-ion battery or a nickel-metal hydride battery. The battery 120 is, for example, a high-voltage battery of several hundred volts, and stores power used for propelling the vehicle 100. When the power supplied to the power receiving device 150 from the external power supply device and the regenerative power generated by the motor 140 are supplied to the battery 120, the battery 120 is charged.
[0032] The motor 140 is, for example, an AC synchronous motor, and functions as both an electric motor and a generator. When the motor 140 functions as an electric motor, the motor 140 is driven using the electric power stored in the battery 120 as a power source. The output of the motor 140 is transmitted to the wheels via a reduction gear and an axle. When the vehicle 100 is decelerating, the motor 140 functions as a generator that uses the rotation of the wheels and generates regenerative electric power. A PCU (Power Control Unit) 130 is electrically connected between the motor 140 and the battery 120. The PCU 130 is controlled by the ECU 200, and controls the exchange of electric power between the battery 120 and the motor 140.
[0033] 6 is a block diagram showing the internal functional configuration of ECU 200. ECU 200 is mounted on vehicle 100 and executes various controls of vehicle 100. ECU 200 includes a storage device 220 such as an HDD (hard disk drive), an SSD (solid state drive), an optical recording medium, or a semiconductor memory, and a CPU 210 as a central processing unit.
[0034] The storage device 220 stores an execution condition 222. The execution condition 222 is a condition for the invalidation execution unit 214 to execute the invalidation process. The execution condition 222 is used after a invalidation instruction from the invalidation instruction unit 514 is detected. That is, the invalidation execution unit 214 executes the invalidation process when the execution condition 222 is satisfied after the invalidation instruction is detected. In this embodiment, the execution condition 222 is that the vehicle 100 has been stopped. Note that the invalidation execution unit 214 may execute the invalidation process when a invalidation instruction is detected without using the execution condition 222.
[0035] The storage device 220 stores various programs for realizing functions provided in this embodiment. The CPU 210 executes the various computer programs stored in the storage device 220 to realize various functions, such as the invalidation execution unit 214 and the driving control unit 212. For example, the remote control program 224 shown in FIG. 6 is a computer program that causes the CPU 210 to realize the function of the driving control unit 212. The remote control program 224 includes program information 225 related to the remote control function, including version information of the remote control program 224. The program information 225 may differ depending on the shipping destination of the vehicle 100, such as the country of destination, the model of the vehicle 100, devices and parts installed in the vehicle 100, the specifications of the vehicle 100, and the like. In this case, whether or not a vehicle 100 has a vulnerability will differ from vehicle to vehicle.
[0036] The driving control unit 212 executes driving control of the vehicle 100. "Driving control" includes adjustment of acceleration, speed, and steering angle. In driving control by remote control, the driving control unit 212 controls each actuator mounted on the vehicle 100 in accordance with a remote control request received from the remote control device 300 via the vehicle communication unit 190.
[0037] The invalidation execution unit 214 performs a invalidation process to invalidate the driving control of the vehicle 100 by remote control. "Invalidating driving control by remote control" means that, among the functions of the driving control unit 212, the function of executing driving control in accordance with a remote control request is lost. The invalidation execution unit 214 performs the invalidation process when it receives an instruction to execute the invalidation process from the invalidation instruction unit 514 of the mobile object management device 500, or when the execution condition 222 is set and the execution condition 222 is further satisfied. When the invalidation execution unit 214 executes the invalidation process, the driving control unit 212 transitions to a state in which it invalidates the control request of the remote control. By invalidating driving control by remote control, it is possible to prevent a third party from running the vehicle 100 by unauthorized remote control.
[0038] Disabling remote control includes reversible disabling, which allows a disabled remote control to be restored to a valid state when a predetermined condition is met, and irreversible disabling, which cannot be restored. Reversible disabling can be achieved, for example, by encrypting a program that performs the function of executing remote control according to remote control, among the functions of the operation control unit 212, and making it decryptable only by a person with predetermined authority. Irreversible disabling can be achieved, for example, by deleting the program that performs the function of executing remote control according to remote control, or by physically disconnecting the program or hardware having the function. From the perspective of enhanced security, it is preferable to irreversibly disable remote control if it will not be executed in the future. Furthermore, even if remote control will be executed in the future, it is preferable to reversibly disable remote control until it is executed. In this embodiment, the disabling execution unit 214 executes irreversible disabling as the disabling process. However, the disabling execution unit 214 may also execute reversible disabling. From the viewpoint of strengthening security, it is preferable that the ECU 200 further includes a secure microcomputer equipped with an FPGA (Field Programmable Gate Array) and a flash memory, an HSM (Hardware Security Module), and the like.
[0039] Returning to FIG. 5, the remote automated driving system 600 includes a vehicle detector and a remote control device 300. The vehicle detector detects vehicle information including at least one of an image of the vehicle 100 and the position of the vehicle 100. The detected vehicle information is used for remote control by the remote automated driving system 600. The "vehicle information" may further include the traveling direction or orientation of the vehicle 100. The traveling direction or orientation of the vehicle 100 can be obtained, for example, by detecting the shape of the vehicle 100 or parts of the vehicle 100. However, the traveling direction or orientation of the vehicle 100 may also be estimated by obtaining only the position of the vehicle 100 using the vehicle detector and using changes in the vehicle 100 over time.
[0040] In this embodiment, the vehicle detector is a camera 80. The camera 80 is communicably connected to the remote control device 300 via wireless or wired communication. The camera 80 has an imaging unit, such as a CCD (Charge Coupled Device) image sensor or a CMOS (Complementary Metal Oxide Semiconductor) image sensor, and an optical system.
[0041] The camera 80 is fixed at a position where it can capture images of the road RT and the vehicle 100 traveling on the road RT, and acquires images of the vehicle 100 as vehicle information. In the example of FIG. 5, the camera 80 acquires images of the road RT and the vehicle 100 in the parking lot PA from above. The number of cameras 80 is set to a number that can capture the entire road RT and parking lot PA, taking into account the angle of view of the camera 80. The images acquired by the camera 80 can be analyzed to acquire various vehicle information that can be used for remote control, such as the relative position of the vehicle 100 with respect to the road RT and the orientation of the vehicle 100. By using the images from the camera 80 installed in the factory FC, the vehicle 100 can be autonomously driven by remote control without using detectors mounted on the vehicle 100, such as cameras, millimeter-wave radar, or LiDAR (Light Detection and Ranging). However, detectors mounted on the vehicle 100 may be used auxiliary for purposes such as collision prevention during remote control. Note that the vehicle detector does not need to acquire an image of the vehicle 100 as long as it can acquire the position of the vehicle 100. In this case, the vehicle detector may be any of various detectors that can detect the position of the vehicle 100 instead of an image of the vehicle 100, such as a LiDAR, an infrared sensor, a laser sensor, an ultrasonic sensor, or a millimeter-wave radar.
[0042] A reference driving route along which the vehicle 100 should travel when remotely controlled is preset on the road RT. The remote control unit 312 acquires images of the road RT and the vehicle 100 captured by the camera 80 via wireless communication with the vehicle 100 via the access point 70. The remote control unit 312 analyzes the acquired images at predetermined time intervals while causing the ECU 200 to execute driving control of the vehicle 100. When the remote control unit 312 requests remote control of the vehicle 100, the remote control unit 312 successively adjusts the relative position of the vehicle 100 with respect to the reference route, thereby enabling the vehicle 100 to travel along the reference route. The remote control unit 312 can also remotely control the vehicle 100 to stop at a parking spot in a parking lot PA.
[0043] 7 is a flowchart showing a method for disabling remote control according to the first embodiment. This flow starts, for example, when the vehicle administration device 500 is started.
[0044] In step S20, the information acquisition unit 512 acquires vulnerability information from reports from the vehicle 100, the remote control device 300, the information providing device 400, etc. In step S22, the user of the vehicle management device 500 analyzes the acquired vulnerability information and determines whether or not to disable the remote control function. Whether or not to disable the remote control function is determined based on whether or not the acquired vulnerability information poses a threat to the remote control of the vehicle 100, or the level of the threat. If it is determined not to disable the remote control function (S22: NO), the disablement instruction unit 514 ends this flow. As a result, the remote control function of the vehicle 100 is not disabled. If it is determined to disable the remote control function (S22: YES), the disablement instruction unit 514 proceeds to step S30.
[0045] In step S30, program information 225 having a vulnerability is identified from among the remote control programs 224. Identifying the program information 225 means, for example, identifying a version of the remote control program 224 that has a vulnerability from among the remote control programs 224. In this embodiment, the program information 225 is identified manually by a user of the vehicle management device 500 or the like. Note that the program information 225 may also be identified by a user of the remote control device 300, the information providing device 400, or the vehicle 100. In this case, step S30 can be omitted.
[0046] In step S40, the invalidation instruction unit 514 refers to the correspondence data 522 and extracts vehicles 100 having a vulnerability from the vehicle identification information associated with the identified program information 225. That is, the invalidation instruction unit 514 extracts all vehicles 100 having the identified program information 225. In the example of the correspondence data 522 shown in Fig. 3, the vehicles 100 corresponding to the vehicle identification information ID1 and ID2 having the program information 225 of version V1 determined to have a vulnerability are extracted as vehicles 100 having a vulnerability.
[0047] In step S50, the notification unit 516 issues a notification urging the driver of the vehicle 100 to take measures to disable the remote control function or to eliminate the vulnerability of the remote control function. The notification unit 516 issues a notification to the driver of the vehicle 100, for example, by displaying a screen on a display provided in the vehicle 100 or by audio through an audio device provided in the vehicle 100. The notification unit 516 may issue a notification urging the driver to bring the vehicle 100 to a base such as a dealership DL, a notification urging the driver to update software for the remote control program 224 or the ECU 200, and a notification that the remote control function will be disabled. The notification unit 516 may not only notify the driver of the vehicle 100, but also the manager of the vehicle 100, the manager of the base such as the dealership DL, the remote control device 300, etc.
[0048] In step S60, the invalidation instruction unit 514 transmits a command signal to execute invalidation processing to all vehicles 100 having vehicle identification information determined to have a vulnerability. In step S70, upon receiving the command signal to execute invalidation processing, the invalidation execution unit 214 waits for the execution condition 222 to be met. In this embodiment, the execution condition 222 is that the vehicle 100 has been stopped. "Stopping the vehicle 100" includes turning off the ignition of the vehicle 100, turning off the power of the vehicle 100, stopping or stopping the vehicle 100, etc. Note that stopping the vehicle 100 includes both stopping the vehicle 100 by automatic driving using remote control and stopping the vehicle 100 by manual driving.
[0049] If the vehicle 100 is not stopped (S70: NO), the disablement execution unit 214 waits for the vehicle 100 to stop. If the vehicle 100 is stopped (S70: YES), the disablement execution unit 214 proceeds to step S80. In step S80, the disablement execution unit 214 executes a disablement process to irreversibly disable the remote control function, and then ends this flow. In the example of FIG. 5, if a command signal for the disablement process is received while the vehicle 100 is traveling, the disablement process is executed when the vehicle 100 is parked in a parking lot PA. Note that the remote control function of the vehicle 100 whose remote control function has been disabled can be restored by updating the remote control program 224 or software such as the ECU 200 at a base such as a dealer DL, updating to software provided by the vehicle management device 500, replacing hardware such as the ECU 200, or the like.
[0050] As described above, the vehicle management device 500 of this embodiment includes an information acquisition unit 512 for acquiring vulnerability information related to vulnerabilities in the remote control function, and a disable instruction unit 514 for instructing vehicles 100 having vulnerabilities extracted using the vulnerability information to disable the remote control function. Based on the acquired vulnerability information, the remote control function of the vehicle 100 having the vulnerability can be disabled, thereby suppressing or preventing misuse of the remote control function of the vehicle 100 after shipment.
[0051] The vehicle management device 500 of this embodiment further includes a correspondence data storage unit that stores correspondence data 522 between the identification information of the vehicle 100 and the program information 225 related to the remote control function provided in the vehicle 100. When program information 225 having a vulnerability is identified, the disable instruction unit 514 uses the stored correspondence data 522 to extract all vehicle identification information corresponding to the multiple vehicles 100 having the identified program information 225. The disable instruction unit 514 instructs the vehicles 100 corresponding to all of the extracted identification information to disable the remote control function. By a simple process of using the correspondence data 522, multiple vehicles 100 having a vulnerability can be identified. Furthermore, the remote control functions of the identified multiple vehicles 100 can be disabled at once.
[0052] The vehicle management device 500 of this embodiment further includes a notification unit 516. The notification unit 516 issues a notification to vehicles 100 that have the extracted vulnerability, urging them to disable the remote control function and take measures to resolve the vulnerability. By urging them to disable the remote control function and take measures to resolve the vulnerability, risks caused by vulnerabilities in the remote control function can be quickly resolved.
[0053] The vehicle management device 500 of this embodiment further includes a disablement execution unit 214. After receiving an instruction to disable the remote control function, the disablement execution unit 214 executes a disablement process to disable the remote control function when a predetermined execution condition 222 is met. The timing at which the remote control function is disabled can be set to the timing at which the execution condition 222 is met.
[0054] According to the vehicle management device 500 of this embodiment, the execution condition 222 is that the vehicle 100 that has received the instruction to disable the remote control function is stopped. By satisfying the execution condition 222 while the vehicle 100 is stopped, it is possible to suppress or prevent the execution of the disablement process while the vehicle 100 is traveling under remote control.
[0055] The vehicle management device 500 of this embodiment manages vehicles 100p that can be driven by remote control within a factory FC during the manufacturing process of the factory FC that manufactures the vehicle 100. Therefore, it is possible to suppress or prevent the remote control function of the vehicle 100 during manufacturing from being misused.
[0056] B. Second embodiment: 8 is a flowchart showing a method for disabling remote control according to the second embodiment. The method for disabling remote control according to the second embodiment differs from the first embodiment in that step S70 is replaced with step S70b, but other configurations are the same as those of the first embodiment. In step S70b, the content of execution condition 222 differs from that of step S70.
[0057] In the first embodiment, an example was shown in which the execution condition 222 is the stopping of the vehicle 100. In contrast, in the present embodiment, the execution condition 222 is set when the traveling speed of the vehicle 100 that has received the instruction to disable the remote control function, i.e., the vehicle speed, becomes equal to or lower than a predetermined reference speed. The reference speed can be set arbitrarily. For example, the reference speed can be set to a speed slower than the cruising speed or average speed of the vehicle 100 during autonomous driving by remote control. The reference speed may also be a speed at which the vehicle 100, for which remote control has been disabled, can safely stop. According to the method for disabling remote control of the present embodiment, for example, even if the vehicle 100 receives a disabling command signal while self-propelled, the vehicle 100 can be safely stopped.
[0058] C. Third embodiment: 9 is an explanatory diagram showing the configuration of an execution condition 222 used in the method for disabling remote control according to the third embodiment. In this embodiment, the execution condition 222 is set when the remote control radio waves that had been detected by the vehicle 100 that received the instruction to disable the remote control function are no longer detected.
[0059] 9, each of the multiple access points 70 used for remote control forms a communication area WA in which wireless communication is possible. The communication area WA is configured to include a route RT along which the vehicle 100 automatically travels under remote control within a base such as a factory FC. In contrast, no communication area WA is provided in an area OA outside the factory FC.
[0060] In the example of Fig. 9, when vehicle 100 is automatically traveling by remote control on road RT within factory FC, it receives radio waves for wireless communication from access point 70. Therefore, in this case, execution condition 222 is not met. In contrast, as shown for vehicle 100c in Fig. 9, when vehicle 100c moves from within factory FC to area OA by, for example, manual traveling, it leaves communication area WA. As a result, the radio waves for wireless communication that had been detected by vehicle communication unit 190 of vehicle 100 are no longer detected, and execution condition 222 is met.
[0061] As described above, according to the vehicle management device 500 of this embodiment, the execution condition 222 is met when the radio waves for remote control that were detected by the vehicle 100 that received the instruction to disable the remote control function are no longer detected. Therefore, the radio waves for wireless communication used for remote control of the vehicle 100 can be used as so-called geofencing for the execution condition 222.
[0062] D. Fourth embodiment: 10 is a flowchart showing a method for disabling remote control according to the fourth embodiment. The method for disabling remote control according to the fourth embodiment differs from the first embodiment in that step S70 is replaced with step S70d, but other configurations are the same as those of the first embodiment. In step S70d, the content of execution condition 222 differs from that of step S70.
[0063] In this embodiment, the execution condition 222 is that all personnel aboard the vehicle 100 that received the instruction to disable the remote control function have disembarked. The number of personnel aboard the vehicle 100 can be detected or counted using a sensor or the like provided on the vehicle 100. According to the remote control disabling method configured in this manner, it is possible to suppress or prevent the remote control from being disabled while personnel are aboard the vehicle 100 that is running automatically under remote control.
[0064] E. Fifth embodiment: 11 is a block diagram showing the functional configuration of a vehicle management device 500e according to the fifth embodiment. The vehicle management device 500e of the present embodiment differs in that the CPU 510 functions as an information acquisition unit 512e instead of the information acquisition unit 512, and also functions as an identification unit 517. The rest of the configuration is the same as that of the vehicle management device 500 of the first embodiment.
[0065] As in the above embodiments, the information acquisition unit 512e has a function of acquiring vulnerability information from reports from the vehicle 100, the remote control device 300, the information providing device 400, etc. The information acquisition unit 512e also has a crawler function and a web scraper function that acquires vulnerability information by crawling and analyzing websites and SNSs (Social Networking Services) on the Internet.
[0066] The identifying unit 517 analyzes the acquired vulnerability information and determines whether to disable the remote control function. Whether to disable the remote control function can be determined, for example, by referring to determination criteria pre-stored in the storage device 520. The determination criteria, for example, specify a correspondence between the vulnerability information and the presence or absence of a threat to the remote control of the vehicle 100 or the level of the threat. If the identifying unit 517 determines that the acquired vulnerability information poses a threat to the remote control or if the level of the threat is greater than a reference value, the identifying unit 517 determines to disable the remote control function. If the identifying unit 517 determines to disable the remote control function, it identifies the program information 225 that has a vulnerability. Note that whether to disable the remote control function may be determined manually by an operator or the like who checks the acquired vulnerability information.
[0067] 12 is a flowchart showing a method for disabling remote control according to the fifth embodiment. The method for disabling remote control according to the fifth embodiment differs from the method for disabling remote control according to the first embodiment in that it further includes steps S10 and S32 and includes steps S20e and S22e instead of steps S20 and S22, but otherwise has the same configuration as the first embodiment.
[0068] In step S10, the information acquisition unit 512e moves between websites by following links within the websites, and analyzes (parses) the websites. The information acquisition unit 512e analyzes data including at least character data and image data, such as text data, HTML, CSS, JavaScript (registered trademark), image data, video data, and audio data of the websites. In step S20e, the information acquisition unit 512e acquires vulnerability information as the analysis result of the websites. The information acquisition unit 512e may further acquire vulnerability information through reports from the vehicle 100, the remote control device 300, the information providing device 400, etc.
[0069] In step S22e, the identifying unit 517 analyzes the acquired vulnerability information and determines whether to disable the remote control function. If the identifying unit 517 determines to disable the remote control function (S22e: YES), the process proceeds to step S32. In step S32, the identifying unit 517 refers to the acquired vulnerability information among the remote control programs 224 and identifies the program information 225 having a vulnerability.
[0070] As described above, the vehicle management device 500e of this embodiment includes the identification unit 517 that uses the acquired vulnerability information to identify vulnerable program information 225. Therefore, compared to manually identifying vulnerable program information 225, it is possible to extract vulnerable vehicles 100 earlier.
[0071] According to the vehicle management device 500e of this embodiment, the information acquisition unit 512 further acquires vulnerability information by analyzing data including at least one of text and images via the Internet. Therefore, vulnerability information can be acquired automatically, and the range of vulnerability information acquisition can be expanded to include websites on the Internet.
[0072] F. Other Embodiments: (F1) In the above first embodiment, an example was shown in which the remote control unit 312 was provided in the remote control device 300. However, all or part of the functions of the remote control unit 312 may be provided in the vehicle management device 500.
[0073] (F2) In the above embodiments, an example was shown in which the correspondence data 522 is stored in the storage device 520 of the vehicle management device 500. However, in cases where it is easy to identify the vehicle 100 to be disabled, for example, because there are only a few types of program information 225 in the remote control program 224, the correspondence data 522 may be omitted. Even with a vehicle management device 500 configured in this manner, the same effects as in the first embodiment can be obtained.
[0074] (F3) In the first embodiment, an example was shown in which the vehicle management device 500 includes the notification unit 516. However, the notification unit 516 may be omitted. In this case, it is preferable to disable the remote control function of the vehicle 100 early, for example, by shortening the period until the execution condition 222 is satisfied.
[0075] (F4) In the above embodiments, an example was shown in which the disablement execution unit 214 executes the disablement process to disable the remote control function when the execution condition 222 is met. However, the execution condition 222 may be omitted. In this case, the remote control function of the vehicle 100 is disabled, for example, by receiving a disablement instruction from the disablement instruction unit 514. According to the vehicle management device 500 configured in this manner, by simplifying the process, it is possible to quickly disable the remote control function of a vehicle 100 that has a vulnerability.
[0076] (F5) In the first embodiment, an example was shown in which the execution condition 222 is met when the vehicle 100 is stopped. In contrast, the execution condition 222 may be met when the vehicle 100 is not using the remote control function. The vehicle management device 500 configured in this manner can suppress or prevent the execution of the disabling process while the vehicle 100 is autonomously traveling by remote control. Furthermore, it can instantly disable the remote control function of the vehicle 100 when remote control is not being executed.
[0077] The control and methods described herein may be implemented by a special-purpose computer configured with a processor and memory programmed to perform one or more functions embodied in a computer program. Alternatively, the control unit and methods described herein may be implemented by a special-purpose computer configured with a processor comprising one or more dedicated hardware logic circuits. Alternatively, the control unit and methods described herein may be implemented by one or more special-purpose computers configured with a processor and memory programmed to perform one or more functions in combination with a processor configured with one or more hardware logic circuits. Furthermore, the computer program may be stored in a computer-readable non-transitory tangible storage medium as instructions executed by a computer.
[0078] The present disclosure is not limited to the above-described embodiments and can be realized in various configurations without departing from the spirit thereof. For example, the technical features in the embodiments corresponding to the technical features in each aspect described in the Summary of the Invention section can be appropriately replaced or combined to solve some or all of the above-described problems or achieve some or all of the above-described effects. Furthermore, if a technical feature is not described as essential in this specification, it can be appropriately deleted. [Explanation of symbols]
[0079] 60...inspection process, 70...access point, 72...network, 80...camera, 100, 100c, 100p, 100q, 100r, 100s, 100t, 100u...vehicle, 120...battery, 130...PCU, 140...motor, 150...power receiving device, 190...vehicle communication unit, 200...ECU, 210...CPU, 212...driving control unit, 214...disabling execution unit, 220...storage device, 222...execution condition, 224...remote control program, 225...program information, 300...remote control device, 310...CPU, 312...remote control unit, 3 14...information providing unit, 320...storage device, 322...vulnerability information, 390...remote communication unit, 400...information providing device, 500, 500e...mobile management device, 510...CPU, 512, 512e...information acquisition unit, 514...disable instruction unit, 516...alarm unit, 517...identification unit, 520...storage device, 522...correspondence data, 590...management device communication unit, 600...remote automatic driving system, 700...mobile management system, CR...operator, DL...dealer, FC...factory, OA...area, PA...parking lot, RT...roadway, WA...communication area, WH...information provider
Claims
1. A mobile object management device that manages a plurality of mobile objects having a remote control function that move by remote control, an information acquisition unit for acquiring vulnerability information regarding vulnerabilities in the remote control function; a correspondence data storage unit that stores correspondence data between the identification information of the mobile object and program information related to the remote control function provided in the mobile object; and a disable instruction unit that, when the program information having the vulnerability is identified using the acquired vulnerability information, extracts the identification information of the mobile body having the identified program information using the stored correspondence data, and instructs the mobile body corresponding to the extracted identification information to disable the remote control function. Mobile management device.
2. The mobile object management device according to claim 1 , further comprising: an identifying unit that identifies the program information having the vulnerability using the acquired vulnerability information.
3. The mobile object management device according to claim 1, the information acquisition unit further acquires the vulnerability information by analyzing data including at least one of text and images via the Internet. Mobile management device.
4. The mobile object management device of claim 1, further comprising an alarm unit that issues an alarm to the extracted mobile object having the vulnerability to prompt the mobile object to at least one of disable the remote control function and take measures to resolve the vulnerability.
5. 2. The mobile management device according to claim 1, further comprising a disabling execution unit that, after issuing an instruction to disable the remote control function, executes a disabling process to disable the remote control function when a predetermined execution condition is met.
6. The mobile object management device according to claim 5, the execution condition is that a mobile body is equipped with a mobile communication unit for receiving radio waves for remote control and the disabling execution unit, and the radio waves for remote control that had been detected by the mobile body that received the instruction to disable the remote control function are no longer detected; Mobile management device.
7. The mobile object management device according to claim 5 , wherein the execution condition is that the mobile object that has received the instruction to disable the remote control function has been stopped.
8. The mobile object management device according to claim 5 , wherein the execution condition is that the mobile object is not using the remote control function.
9. The mobile object management device according to claim 5 , wherein the execution condition is that the moving speed of the mobile object that has received the instruction to disable the remote control function is equal to or less than a predetermined reference speed.
10. The mobile object management device according to claim 1 , wherein the mobile object is a vehicle that can be driven by the remote control within a factory during a manufacturing process of the vehicle.
11. The mobile management device of claim 1, wherein the vulnerability information is at least one of information regarding security holes in the remote control function, information regarding hacking of the remote control function, information regarding program defects related to the remote control function, information regarding computer viruses that affect the remote control function, and information regarding distrust of the remote control function.
12. A mobile object management device for managing a plurality of mobile objects having a remote control function that move by remote control, comprising: an information acquisition unit for acquiring vulnerability information regarding vulnerabilities in the remote control function; a disable instruction unit that instructs the mobile object having the vulnerability extracted using the vulnerability information to disable the remote control function; a disablement execution unit that executes a disablement process to disable the remote control function when a predetermined execution condition is met after the instruction to disable the remote control function is given, The execution condition is that all personnel on board the vehicle have disembarked.
13. A mobile object management system for managing a plurality of mobile objects having a remote control function that move by remote control, a disabling unit provided in the mobile object and configured to execute a disabling process to disable the remote control function; an information acquisition unit for acquiring vulnerability information regarding vulnerabilities in the remote control function; a correspondence data storage unit that stores correspondence data between the identification information of the mobile object and program information related to the remote control function provided in the mobile object; and a disable instruction unit that, when the program information having the vulnerability is identified using the acquired vulnerability information, extracts the identification information of the mobile body having the identified program information using the stored correspondence data, and instructs the disable execution unit of the mobile body corresponding to the extracted identification information to disable the remote control function. Mobile management system.
14. 1. A method for disabling remote control functions of a plurality of mobile objects having remote control functions that move by remote control, comprising: preparing correspondence data between identification information of the mobile object and program information relating to the remote control function provided in the mobile object; acquiring vulnerability information regarding vulnerabilities in the remote control function; When the program information having the vulnerability is identified using the acquired vulnerability information, extracting the identification information of the mobile object having the identified program information using the correspondence data; instructing the mobile object corresponding to the extracted identification information to disable the remote control function; How to disable remote control features.
Citation Information
Patent Citations
Remote controller
JP2006316434A
Security operation management system, method and program
JP2008197877A
Information processing system
JP2017167916A
Method for operating a vehicle and method for operating a manufacturing system
JP2017538619A
Information processing system
JP2023035334A