User equipment, base station and communication method
Patent Information
- Application Number
- JP2024533181
- Authority / Receiving Office
- JP · JP
- Patent Type
- Patents
- Current Assignee / Owner
- Filing Date
- 2022-07-11
- Publication Date
- 2025-12-22
- Estimated Expiration
- 2042-07-11
Smart Images

Figure 0007789925000001 
Figure 0007789925000002 
Figure 0007789925000003
Abstract
Description
[Technical Field]
[0001] The present invention relates to a user equipment, a base station and a communication method. [Background technology]
[0002] The Third Generation Partnership Project (3GPP) has standardized a technology that enables two user devices in a cellular communication system to communicate via a sidelink using vehicle-to-everything (V2X) communication. Patent Document 1 proposes a technology in which a user device installed in a vehicle evaluates the safety of the surrounding environment and transmits a warning message to nearby vehicles if it determines that there is a threat. [Prior art documents] [Patent documents]
[0003] [Patent Document 1] US Patent Application Publication No. 2020 / 0312142 Summary of the Invention [Problem to be solved by the invention]
[0004] With the technology described in Patent Document 1, it is difficult to determine the reliability of a warning message. An object of some aspects of the present invention is to provide a technology that enables the reliability of a traffic condition message to be determined. [Means for solving the problem]
[0005] According to some embodiments, a user equipment is provided on board a vehicle, the vehicle Certified for A user equipment is provided, comprising: a transmitting means for transmitting a message including a first information element representing a driving automation level and a second information element representing a traffic situation detected by the vehicle to a surrounding communication device via a side link. [Effects of the Invention]
[0006] Some aspects of the present invention allow the reliability of traffic condition messages to be determined.
[0007] Other features and advantages of the present invention will become apparent from the following description taken in conjunction with the accompanying drawings, in which the same or similar elements are designated by the same reference numerals. [Brief explanation of the drawings]
[0008] The accompanying drawings, which are incorporated in and constitute a part of the specification, illustrate embodiments of the invention and, together with the description, serve to explain the principles of the invention. [Figure 1] FIG. 1 is a schematic diagram illustrating an example configuration of a vehicle according to some embodiments. [Figure 2] FIG. 1 is a schematic diagram illustrating an example of the configuration of a communication system according to some embodiments. [Figure 3] FIG. 10 is a block diagram illustrating an example of the configuration of a management server according to some embodiments. [Figure 4] FIG. 1 is a block diagram illustrating an example configuration of a base station according to some embodiments. [Figure 5] FIG. 1 is a block diagram illustrating an example configuration of a user equipment according to some embodiments. [Figure 6] FIG. 10 is a sequence diagram illustrating an example of operation of a communication system according to some embodiments. [Figure 7] FIG. 10 is a diagram illustrating an example of a public key list according to some embodiments. [Figure 8] FIG. 10 illustrates fields of a traffic condition message according to some embodiments. [Figure 9] FIG. 10 is a flow diagram illustrating an example of the operation of a management server according to some embodiments. [Figure 10] FIG. 10 is a flow diagram illustrating an example operation of a base station according to some embodiments. [Figure 11] FIG. 10 is a flow diagram illustrating an example operation of a user equipment according to some embodiments. [Figure 12] FIG. 10 is a flow diagram illustrating another example operation of user equipment according to some embodiments. [Figure 13]FIG. 10 is a flow diagram illustrating another example operation of user equipment according to some embodiments. DETAILED DESCRIPTION OF THE INVENTION
[0009] Hereinafter, the embodiments will be described in detail with reference to the accompanying drawings. Note that the following embodiments do not limit the scope of the invention as claimed, and not all combinations of features described in the embodiments are necessarily essential to the invention. Two or more of the features described in the embodiments may be combined in any desired manner. Furthermore, the same reference numerals are used to designate identical or similar components, and redundant descriptions will be omitted.
[0010] FIG. 1 is a block diagram of a vehicle 1 according to an embodiment of the present invention. In FIG. 1, the vehicle 1 is shown generally in plan view and side view. As an example, the vehicle 1 is a four-wheeled sedan-type passenger car. The vehicle 1 may be such a four-wheeled vehicle, or may be a two-wheeled vehicle or another type of vehicle.
[0011] The vehicle 1 includes a vehicle control device 2 (hereinafter simply referred to as the control device 2) that controls the vehicle 1. The control device 2 includes multiple ECUs (Electronic Control Units) 20 to 29 that are communicatively connected via an in-vehicle network. Each ECU includes a processor such as a CPU (Central Processing Unit), a memory such as a semiconductor memory, an interface with external devices, etc. The memory stores programs executed by the processor and data used by the processor for processing, etc. Each ECU may include multiple processors, memories, interfaces, etc. For example, the ECU 20 includes a processor 20a and a memory 20b. The processor 20a executes instructions included in a program stored in the memory 20b, thereby performing processing by the ECU 20. Alternatively, the ECU 20 may include a dedicated integrated circuit such as an ASIC (Application Specific Integrated Circuit) or an FPGA (Field Programmable Gate Array) for performing processing by the ECU 20. The same applies to the other ECUs.
[0012] The following describes the functions and the like that are handled by each of the ECUs 20 to 29. The number of ECUs and the functions that they are responsible for can be designed as appropriate, and they can be subdivided or integrated more than in this embodiment.
[0013] The ECU 20 executes control related to the automatic driving of the vehicle 1. In the automatic driving, the ECU 20 automatically controls at least one of the steering and acceleration / deceleration of the vehicle 1. The automatic driving by the ECU 20 may include automatic driving that does not require driving operation by the driver (also called automatic driving), and automatic driving that assists driving operation by the driver (also called driving assistance).
[0014] The ECU 21 controls the electric power steering device 3. The electric power steering device 3 includes a mechanism for steering the front wheels in response to a driver's driving operation (steering operation) on the steering wheel 31. The electric power steering device 3 also includes a motor that generates driving force to assist the steering operation and automatically steer the front wheels, a sensor that detects the steering angle, etc. When the driving state of the vehicle 1 is autonomous driving, the ECU 21 automatically controls the electric power steering device 3 in response to instructions from the ECU 20, and controls the traveling direction of the vehicle 1.
[0015] ECUs 22 and 23 control detection units 41 to 43 that detect the surrounding conditions of vehicle 1 and process information on the detection results. Furthermore, ECU 22 controls detection unit 44 that detects the state of the driver of vehicle 1 and processes information on the detection results. Detection unit 41 is a camera that captures images ahead of vehicle 1 (hereinafter, may be referred to as camera 41), and in this embodiment, is attached to the front side of the roof of vehicle 1, on the inside of the front windshield. By analyzing the images captured by camera 41, it is possible to extract the contours of targets and lane markings (white lines, etc.) on the road.
[0016] The detection unit 42 is a LIDAR (Light Detection and Ranging) (hereinafter may be referred to as LIDAR 42) that detects targets around the vehicle 1 and measures the distance to the targets. In the present embodiment, five LIDARs 42 are provided, one at each corner of the front of the vehicle 1, one at the rear center, and one on each side of the rear. The detection unit 43 is a millimeter-wave radar (hereinafter may be referred to as RADAR 43) that detects targets around the vehicle 1 and measures the distance to the targets. In the present embodiment, five RADARs 43 are provided, one at the front center of the vehicle 1, one at each front corner, and one at each rear corner.
[0017] The detection unit 44 is a camera that captures images of the interior of the vehicle 1 (particularly the driver). By analyzing the images captured by the camera 44, the EUC 22 can identify the driver's state (for example, the direction of the driver's line of sight, whether the driver is dozing, etc.).
[0018] The ECU 22 controls one camera 41 and each lidar 42 and processes information on the detection results. The ECU 23 controls the other camera 41 and each radar 43 and processes information on the detection results. By providing two sets of devices that detect the surrounding conditions of the vehicle 1, the reliability of the detection results can be improved, and by providing different types of detection units such as a camera, lidar, and radar, the surrounding environment of the vehicle 1 can be analyzed from multiple perspectives.
[0019] The ECU 24 controls the gyro sensor 5, the GNSS (Global Navigation Satellite System) sensor 24b, and the communication device 24c, and processes information on the detection results or communication results. The gyro sensor 5 detects the rotational motion of the vehicle 1. The path of the vehicle 1 can be determined based on the detection results of the gyro sensor 5, the wheel speed, etc. The GNSS sensor 24b detects the current position of the vehicle 1. The communication device 24c wirelessly communicates with a server that provides map information and traffic information to acquire this information. The ECU 24 can access a database 24a that stores map information, and the ECU 24 performs tasks such as searching for a route from the current location to a destination. The ECU 24, the database 24a, and the GNSS sensor 24b constitute a so-called navigation device.
[0020] The ECU 25 includes a communication device 25a for vehicle-to-vehicle communication. The communication device 25a performs wireless communication with other vehicles in the vicinity and exchanges information between the vehicles.
[0021] The ECU 26 controls the power plant 6. The power plant 6 is a mechanism that outputs driving force to rotate the drive wheels of the vehicle 1, and includes, for example, an engine and a transmission. The ECU 26 controls the output of the engine in response to the driver's driving operation (accelerator operation or acceleration operation) detected by an operation detection sensor 7a provided on the accelerator pedal 7A, for example, and switches the gear position of the transmission based on information such as the vehicle speed detected by a vehicle speed sensor 7c. When the vehicle 1 is in an autonomous driving state, the ECU 26 automatically controls the power plant 6 in response to instructions from the ECU 20, and controls the acceleration and deceleration of the vehicle 1.
[0022] The ECU 27 controls lighting devices (headlights, taillights, etc.) including turn signals 8. In the example of Fig. 1, the turn signals 8 are provided at the front, door mirrors, and rear of the vehicle 1.
[0023] The ECU 28 controls the input / output device 9. The input / output device 9 outputs information to the driver and receives information input from the driver. The audio output device 91 notifies the driver of information by audio. The display device 92 notifies the driver of information by displaying an image. The display device 92 is, for example, arranged on the surface of the driver's seat and forms an instrument panel or the like. Note that, although audio and display are exemplified here, information may also be notified by vibration or light. Information may also be notified by a combination of two or more of audio, display, vibration, or light. Furthermore, the combination or the notification mode may be changed depending on the level of the information to be notified (for example, urgency). The input device 93 is a group of switches arranged in a position operable by the driver and used to issue instructions to the vehicle 1, but may also include an audio input device.
[0024] The ECU 29 controls the brake device 10 and a parking brake (not shown). The brake device 10 is, for example, a disc brake device provided on each wheel of the vehicle 1, and applies resistance to the rotation of the wheel to slow down or stop the vehicle 1. The ECU 29 controls the operation of the brake device 10 in response to a driving operation (brake operation) by the driver detected by an operation detection sensor 7b provided on the brake pedal 7B, for example. When the driving state of the vehicle 1 is autonomous, the ECU 29 automatically controls the brake device 10 in response to an instruction from the ECU 20, and controls the deceleration and stopping of the vehicle 1. The brake device 10 and the parking brake can also be operated to maintain the stopped state of the vehicle 1. Furthermore, if the transmission of the power plant 6 is equipped with a parking lock mechanism, this can also be operated to maintain the stopped state of the vehicle 1.
[0025] An example configuration of a wireless communication system 200 according to some embodiments will be described with reference to Fig. 2. The wireless communication system 200 may comply with a communication standard standardized by 3GPP. This communication standard may be, for example, a fourth generation (4G) standard, a fifth generation (5G) standard, or another standard.
[0026] The wireless communication system 200 includes a core network 210, multiple base stations 220a-220b, and multiple user equipments 230a-230c. The core network 210 includes a management server 211. In the example of FIG. 2, the wireless communication system 200 includes two base stations 220a-220b, but the number of base stations is not limited to this. Similarly, the number of user equipments 230a-230c included in the wireless communication system 200 is not limited to the example of FIG. 2. Hereinafter, the multiple base stations 220a-220b will be collectively referred to as base station 220. Unless otherwise specified, a description of the base station 220 applies to each of the base stations 220a-220b. Similarly, the multiple user equipments 230a-230c will be collectively referred to as user equipment 230.
[0027] The core network 210 is a network configured by multiple devices for providing communication services to the user equipment 230. Specifically, the core network 210 enables communication between two user equipments 230 and communication between the user equipment 230 and other communication devices connected to an external network (e.g., the Internet). The core network 210 may be an evolved packet core (EPC) conforming to the 4G standard, a 5G core (5GC) conforming to the 5G standard, or another core network. The management server 211 manages information related to the user equipments 230. Details of this information will be described later. In the example of FIG. 2, the management server 211 is included in the core network 210. Alternatively, the management server 211 may be connected to the core network 210 from outside.
[0028] The base station 220 is a device that relays communications between the core network 210 and the user equipment 230. The base station 220 may be an eNodeB conforming to the 4G standard, a gNodeB conforming to the 5G standard, or another base station. Typically, the core network 210 and the base station 220 are connected by wire. The base station 220 and the user equipment 230 are connected by wireless. In the example of FIG. 2, the base station 220a is connected to the user equipment 230a and 230b, and the base station 220b is connected to the user equipment 230b. In other words, the base station 220a serves the user equipment 230a and 230b, and the base station 220b serves the user equipment 230b.
[0029] The user equipment 230 is a communication device that can use the communication services provided by the core network 210. In the example of FIG. 2, the user equipment 230a is an in-vehicle device installed in a vehicle 231, and the user equipments 230b and 230c are mobile devices carried by users. The type of user equipment is not limited to this and may be, for example, an IoT (Internet of Things) device. The vehicle 231 may have the same configuration as the vehicle 1, and the user equipment 230a may be the communication device 24c of the vehicle 1.
[0030] Furthermore, the user equipment 230 may be capable of sidelink communication. Sidelink communication is direct wireless communication between two nearby user equipments 230. For example, user equipment 230a and user equipment 230b communicate via a sidelink 232 (wireless communication link). The sidelink 232 may conform to the PC5 interface. The user equipment 230 (UE) may act as a client in a V2X application.
[0031] 3, an example of the hardware configuration of the management server 211 will be described. The management server 211 includes a processor 301, a memory 302, a communication interface (I / F) 303, and a storage device 304.
[0032] The processor 301 is a general-purpose processing circuit for executing the overall operation of the management server 211. The management server 211 may include only a single processor 301, or may include multiple processors 301. The processor 301 may be realized by, for example, a CPU (Central Processing Unit).
[0033] The memory 302 is a circuit for storing data and computer programs used in the operation of the management server 211. The management server 211 may include only a single memory 302, or may include multiple memories 302. The memory 302 may be realized by combining a non-volatile storage medium such as a read-only memory (ROM) with a volatile storage medium such as a random access memory (RAM). Operations by the management server 211 may be performed, for example, by the processor 301 executing a program read into the memory 302.
[0034] The communication I / F 303 is a device for communicating with other communication devices. The communication I / F 303 may be realized by, for example, a network card if wired communication is performed, or may be realized by, for example, an antenna and a signal processing circuit if wireless communication is performed.
[0035] The storage device 304 is a device for storing information used in the operation of the management server 211. The storage device 304 may be realized by a hard disk drive (HDD) or a solid state drive (SSD). The storage device 304 stores a public key list 305. Details of the public key list 305 will be described later. In the example of FIG. 3, the storage device 304 stores the public key list 305, but instead, the public key list 305 may be stored in an external device (for example, a database server), and the processor 301 may acquire the public key list 305 from this external device.
[0036] An example of the hardware configuration of the base station 220 will be described with reference to Fig. 4. The base station 220 has a processor 401, a memory 402, a communication I / F 403, and a wireless I / F 404. The processor 401 is a general-purpose processing circuit for executing the overall operation of the base station 220. The base station 220 may include only a single processor 401, or may include multiple processors 401. The processor 401 may be realized by, for example, a CPU.
[0037] The memory 402 is a circuit for storing data and computer programs used in the operation of the base station 220. The base station 220 may include only a single memory 402, or may include multiple memories 402. The memory 402 may be realized by combining a non-volatile storage medium such as a ROM with a volatile storage medium such as a RAM. Operations by the base station 220 may be performed, for example, by the processor 401 executing a program read into the memory 402.
[0038] The communication I / F 403 is a device for communicating with the core network 210. The communication I / F 403 may be realized, for example, by a network card if wired communication is performed, or may be realized, for example, by an antenna and a signal processing circuit if wireless communication is performed. The wireless I / F 404 is a device for communicating with the user equipment 230. The wireless I / F 404 may be realized, for example, by an antenna and a signal processing circuit.
[0039] An example of the hardware configuration of the user equipment 230 will be described with reference to Fig. 5. The user equipment 230 has a processor 501, a memory 502, a wireless I / F 503, and a subscriber identity module (SIM) 504. The processor 501 is a general-purpose processing circuit for executing the overall operation of the user equipment 230. The user equipment 230 may include only a single processor 501, or may include multiple processors 501. The processor 501 may be realized by, for example, a CPU.
[0040] The memory 502 is a circuit for storing data and computer programs used in the operation of the user device 230. The user device 230 may include only a single memory 502, or may include multiple memories 502. The memory 502 may be realized by combining a non-volatile storage medium such as a ROM with a volatile storage medium such as a RAM. Operations of the user device 230 may be performed, for example, by the processor 501 executing a program read into the memory 502.
[0041] The wireless I / F 503 is a device for communicating with the base station 220. The wireless I / F 503 may be realized by, for example, an antenna and a signal processing circuit. The wireless I / F 503 may also be used to communicate with other user equipment via a sidelink.
[0042] The SIM 504 is a module that stores information used by the core network 210 to identify a subscriber. The SIM 504 may be provided by a Universal Subscriber Identity Module (UICC) or may be an eSIM. The SIM 504 stores identification information 505 and a private key 506. The identification information 505 is information for uniquely identifying the user equipment 230. The identification information 505 may be an International Mobile Subscriber Identity (IMSI) or other identification information. The private key 506 is a key used to encrypt and decrypt data together with a public key that forms a pair. The private key 506 may be assigned to the user equipment 230 by the core network 210. In this case, the public key that forms a pair with the private key 506 may be stored in the core network 210.
[0043] An example of the overall operation flow of the wireless communication system 200 will be described with reference to Fig. 6. The management server 211 transmits the public key list 305 to the base station 220a in S601, and transmits the public key list 305 to the base station 220b in S602. In this manner, the management server 211 transmits the same public key list 305 to each of the multiple base stations 220. The management server 211 may transmit the public key list 305 to any one of the multiple base stations 220 first. The public key list 305 is a list of public keys that form pairs with private keys 506 stored in each of the multiple user devices 230.
[0044] An example of the public key list 305 will be described with reference to FIG. 7. The public key list 305 has a plurality of records. Each of the plurality of records in the public key list 305 includes information represented in columns 701 to 703 for an individual user device 230. Column 701 represents identification information of the individual user device 230. The identification information represented in column 701 may be the same as the identification information 505 stored in the SIM 504 of the user device 230. Column 702 represents a public key paired with a private key 506 stored in the individual user device 230. Column 703 represents information on the geographical area in which the individual user device 230 is located. Column 703 may be represented by an identifier uniquely assigned to each geographical area.
[0045] The geographical area represented in column 730 may be the coverage area of the base station 220. Alternatively, the geographical area may be an area set independently of the coverage area of the base station 220. For example, the geographical area may be set based on an area defined by roads. Information representing the geographical area may be managed by the management server 211, or may be managed by a server different from the management server 211. The user equipment 230 may acquire information representing the geographical area from the server that manages the geographical area and determine which of multiple geographical areas the user equipment 230 is located in based on this information. The current location of the user equipment 230 may be identified based on measurement results from a positioning sensor or may be identified based on a positional relationship with the base station 220. For example, if the user equipment 230 has a positioning sensor, or if an apparatus (e.g., the vehicle 231) on which the user equipment 230 is mounted has a positioning sensor (e.g., the GNSS sensor 24b), the user equipment 230 may identify the current location of the user equipment 230 based on measurement results from these positioning sensors.
[0046] The management server 211 may add a record for the user device 230 to the public key list 305 every time a private key 506 is assigned to the user device 230. Furthermore, when the private key 506 of the user device 230 is changed, the management server 211 may update the public key list 305 so as to update the public key represented in column 702. Furthermore, the management server 211 may receive information representing the geographical area in which the user device 230 is located from the user device 230, and update the geographical area information represented in column 703 based on this information. The user device 230 may report its current geographical area to the management server 211 every time the geographical area in which it is currently located changes.
[0047] The management server 211 may include in the public key list 305 records of only user devices 230 that satisfy certain conditions. For example, the certain condition may be that the user device 230 is installed in a vehicle with a certain level of autonomous driving. The autonomous driving level may be, for example, a level defined by the Society of Automotive Engineers (SAE). The SAE defines six levels, from level 0 to level 5, as follows: Level 0 does not provide autonomous driving; Level 1 provides driving assistance in limited situations; Level 1 driving assistance requires the driver to hold the steering wheel and monitor the surroundings; Level 2 provides partial driving automation, where the vehicle drives autonomously in limited situations; Level 2 autonomous driving does not require the driver to hold the steering wheel but requires monitoring the surroundings; Level 3 provides conditional driving automation, where the vehicle drives autonomously in limited situations; Level 3 autonomous driving does not require the driver to hold the steering wheel or monitor the surroundings. At level 4, a high degree of driving automation is achieved, with the vehicle driving autonomously in limited situations. At level 4, the driver is not required to keep the steering wheel or monitor the surroundings, and the driver does not need to pay attention to driving behavior. At level 5, full driving automation is achieved, with the vehicle driving autonomously in any situation. At level 5, the driver is not required to keep the steering wheel or monitor the surroundings, and the driver does not need to pay attention to driving behavior. At levels 0 to 2, the vehicle is driven primarily by a human (driver), and at levels 3 to 5, the vehicle is the main driver. The autonomous driving level may be a level certified for the vehicle by a certification body (for example, a national body, the Ministry of Land, Infrastructure, Transport and Tourism in Japan).
[0048] For example, the specific condition may be that the user equipment 230 is installed in a vehicle with an autonomous driving level of level 2 or higher. In this case, if the user equipment 230 is installed in a vehicle with an autonomous driving level of level 1 or lower, or if the user equipment 230 is not installed in a vehicle, a record for the user equipment 230 is not created in the public key list 305. Therefore, the public keys for these user equipments 230 are not transmitted from the management server 211 to the base station 220. Alternatively, the specific condition may be that the user equipment 230 is installed in a vehicle with an autonomous driving level of another level or higher. Whether the user equipment 230 is installed in a vehicle with a predetermined autonomous driving level may be determined based on the model of the vehicle and the certification result by a certification organization.
[0049] Returning to the description of FIG. 6, the base station 220a transmits a public key partial list 710 (described below) to the user equipment 230a in S603, and transmits the public key partial list 710 to the user equipment 230b in S604. In this way, the base station 220a transmits the same public key partial list 710 to each of the multiple user equipment 230 that it serves. The base station 220b transmits a public key partial list 720 (described below) to the user equipment 230c in S605. In this way, the base station 220b transmits the same public key partial list 720 to each of the multiple user equipment 230 that it serves. The base station 220 may transmit the public key partial list to any one of the multiple user equipment 230 that it serves first.
[0050] Referring again to FIG. 7, examples of public key partial lists 710 and 720 will be described. Public key partial lists 710 and 720 are lists generated by extracting some records from public key list 305. Therefore, public key partial lists 710 and 720 may have the same columns 701 to 703 as public key list 305. Public key partial list 710 is a list generated by extracting records from public key list 305 that have a geographical area (e.g., "GeoID1") included in the coverage of base station 220a. Public key partial list 720 is a list generated by extracting records from public key list 305 that have a geographical area (e.g., "GeoID2") included in the coverage of base station 220b. Public key partial lists 710 and 720 may be different from each other, or may partially overlap.
[0051] 6, in S606, the user equipment 230a mounted on the vehicle 231 transmits a traffic condition message 800 (described later) to the user equipment 230b via the sidelink 232. The traffic condition message 800 is a message indicating the traffic condition detected by the vehicle 231.
[0052] 8, an example of the format of a traffic condition message 800 will be described. The traffic condition message 800 includes information elements 801 to 804. Each of the information elements 801 to 804 is stored in a separate field of the traffic condition message 800.
[0053] The information element 801 represents the autonomous driving level of the vehicle 231 equipped with the user device 230a. As described above, the autonomous driving level may be a level defined by the SAE or a level certified by a certification body. The information element 801 may be a numerical value representing the autonomous driving level, or may be a binary flag indicating that the autonomous driving level satisfies a predetermined condition (e.g., level 2 or higher). The information element 802 represents the identification information 505 of the user device 230a.
[0054] The information element 803 represents a traffic situation detected by the vehicle 231. This traffic situation may include a situation related to the vehicle 231, a situation around the vehicle 231, or both. The situation around the vehicle 231 may be, for example, the situation of traffic participants around the vehicle 231 (e.g., automobiles, bicycles, pedestrians), the road condition around the vehicle 231 (e.g., fallen objects, potholes), or the situation of installed objects around the vehicle 231 (e.g., traffic lights, guardrails). The situation around the vehicle 231 may be identified by the ECU of the vehicle 231 based on the detection results of the detection units 41 to 43 of the vehicle 231, for example. The situation related to the vehicle 231 may include the situation of the driver of the vehicle 231 (e.g., dozing, being drunk), and a situation related to the acceleration / deceleration or steering of the vehicle 231 (e.g., sudden start or stop, lane departure), etc. The situation regarding the vehicle 231 may be identified by the ECU of the vehicle 231 based on, for example, the detection results of the detection unit 44 of the vehicle 231, or the detection results of a wheel speed sensor and a steering angle sensor.
[0055] The traffic situation represented by the information element 803 may include, for example, a traffic condition that poses a safety threat and therefore requires attention. Such a traffic condition that requires attention may be, for example, the driver of the vehicle 231 falling asleep or being drunk, or a vehicle around the vehicle 231 suddenly accelerating or leaving its lane. The information element 803 may be encrypted using the private key 506 stored in the user equipment 230a, or may be in plain text.
[0056] The information element 804 is an information element obtained by encrypting the information element 801 with the private key 506 of the user equipment 230a. That is, the information element 804 represents the encrypted autonomous driving level. In this way, the traffic condition message 800 includes the autonomous driving level in plaintext as the information element 801 and the encrypted autonomous driving level as the information element 804. Alternatively, the traffic condition message 800 may include only one of the information element 801 and the information element 804.
[0057] An example of the operation of the management server 211 will be described with reference to Fig. 9. In the method of Fig. 9, the management server 211 communicates with the base station 220. The method of Fig. 9 may be performed by the processor 301 of the management server 211 executing a computer program read into the memory 302 of the management server 211. Alternatively, some or all of the steps of the method of Fig. 9 may be performed by a dedicated circuit such as an application specific integrated circuit (ASIC). The method of Fig. 9 may be started in response to the management server 211 being booted up.
[0058] In S901, the management server 211 transmits the public key list 305 to each of the multiple base stations 220. As described above, the public key list 305 includes public keys that are paired with private keys (e.g., private key 506) stored in a communication device (e.g., user equipment 230a) mounted on a vehicle (e.g., vehicle 231) having a predetermined autonomous driving level.
[0059] In S902, the management server 211 determines whether the condition for updating the public key list 305 is met. If it is determined that the condition is met ("YES" in S902), the management server 211 transitions the process to S903, and otherwise ("NO" in S902), repeats S902. The conditions for updating the public key list 305 may include, for example, that a private key has been assigned to a user device 230 installed in a vehicle having a predetermined autonomous driving level, that the information in column 703 of an existing record (i.e., the geographical area information) has been updated, etc.
[0060] In S903, the management server 211 updates the public key list 305, returns the process to S901, and transmits the updated public key list 305 to each base station 220. In this way, the public key list 305 reflecting the latest status is provided to each base station 220.
[0061] An example of the operation of the base station 220 will be described with reference to Fig. 10. In the method of Fig. 10, the base station 220 communicates with the management server 211 and the user equipment 230. The method of Fig. 10 may be performed by the processor 401 of the base station 220 executing a computer program read into the memory 402 of the base station 220. Alternatively, some or all of the steps of the method of Fig. 10 may be performed by a dedicated circuit such as an ASIC. The method of Fig. 10 may be started in response to the base station 220 starting up.
[0062] In S1001, the base station 220 determines whether or not it has received the public key list 305 from the management server 211. If it is determined that it has received the public key list 305 ("YES" in S1001), the base station 220 transitions the process to S1002, and otherwise ("NO" in S1001), it repeats S1001.
[0063] In S1002, the base station 220 generates a public key sublist from the public key list 305. Specifically, the base station 220 identifies a geographic area included in its coverage and extracts records from the public key list 305 that match this geographic area.
[0064] In S1003, the base station 220 transmits the generated public key partial list to the user equipment it serves. The base station 220 then returns to S1001 and waits to receive an updated public key list 305. In S1003, the base station 220 transmits, from the plurality of public keys included in the public key list 305, public keys of user equipment 230 located within the geographic area served by the base station 220 to the user equipment 230 within the geographic area served by the base station 220. For example, if user equipment 230a and user equipment 230b are located in the same geographic area, the public key partial list including the public key of user equipment 230a is transmitted to both user equipment 230a and user equipment 230b. Meanwhile, the base station 220 does not transmit, from the plurality of public keys included in the public key list 305, public keys of user equipment 230 not located within the geographic area served by the base station 220 to the user equipment 230 within the geographic area served by the base station 220. For example, if user equipment 230a and user equipment 230b are located in the same geographic area, the public keys of user equipment 230 that are not included in this geographic area are not transmitted to either user equipment 230a or user equipment 230b.
[0065] An example of the operation of the user equipment 230 will be described with reference to Fig. 11. In the method of Fig. 11, the user equipment 230 communicates with the base station 220. The method of Fig. 11 may be performed by the processor 501 of the user equipment 230 executing a computer program read into the memory 502 of the user equipment 230. Alternatively, some or all of the steps of the method of Fig. 11 may be performed by a dedicated circuit such as an ASIC. The method of Fig. 11 may be started in response to the user equipment 230 being powered on.
[0066] In S1101, the user equipment 230 determines whether or not it has received a public key partial list from the base station 220. If it is determined that it has received a public key partial list ("YES" in S1101), the user equipment 230 transitions the process to S1102, and otherwise ("NO" in S1101) repeats S1101.
[0067] In S1102, the user device 230 stores the public key portion list in the memory 502 so that it can be used in subsequent processing. If a public key portion list is already stored in the memory 502, the user device 230 may overwrite the original public key portion list with the new public key portion list. The user device 230 then returns to S1101 and waits to receive an updated public key portion list.
[0068] An example of the operation of the user equipment 230a installed in the vehicle 231 will be described with reference to FIG. 12. In the method of FIG. 12, the user equipment 230a communicates with another user equipment 230. The method of FIG. 12 may be performed by the processor 501 of the user equipment 230a executing a computer program read into the memory 502 of the user equipment 230a. Alternatively, some or all of the steps of the method of FIG. 12 may be performed by a dedicated circuit such as an ASIC. The method of FIG. 12 may be started in response to the user equipment 230a being started. The method of FIG. 12 may be performed in parallel with the method of FIG. 11.
[0069] In S1201, the user equipment 230a acquires traffic conditions related to or around the vehicle 1. An example of the acquired traffic conditions may be the same as the traffic conditions described with reference to FIG.
[0070] In S1202, the user equipment 230a determines whether the traffic situation satisfies the notification condition. If the user equipment 230a determines that the traffic situation satisfies the notification condition ("YES" in S1202), the process proceeds to S1202, and otherwise ("NO" in S1202), the process proceeds to S1201. The notification condition is a condition under which the user equipment 230a transmits a traffic situation message 800 to another user equipment. This notification condition may be that the traffic situation acquired in S1201 is a traffic situation requiring a warning. Alternatively, this notification condition may be that the traffic situation acquired in S1201 satisfies another predetermined condition.
[0071] In S1203, the user equipment 230a generates a traffic condition message 800. For example, the user equipment 230a reads the autonomous driving level from the vehicle 1 and encrypts it using the private key 506. The user equipment 230a also encrypts the traffic condition using the private key 506. Then, the user equipment 230a generates the traffic condition message 800 by including necessary information in each field.
[0072] In S1204, the user equipment 230a transmits a traffic condition message to the surrounding user equipment 230b via the side link 232. Thereafter, the user equipment 230a returns the process to S1201 and repeats S1201 to S1204.
[0073] An example of the operation of the user equipment 230 will be described with reference to Fig. 13. In the method of Fig. 13, the user equipment 230 communicates with another user equipment 230. The method of Fig. 13 may be performed by the processor 501 of the user equipment 230 executing a computer program read into the memory 502 of the user equipment 230. Alternatively, some or all of the steps of the method of Fig. 13 may be performed by a dedicated circuit such as an ASIC. The method of Fig. 13 may be started in response to the user equipment 230 being powered on. The method of Fig. 13 may be performed in parallel with the method of Fig. 11 and the method of Fig. 12.
[0074] In S1301, the user equipment 230 determines whether or not a traffic condition message has been received via a sidelink from a surrounding user equipment 230. If it is determined that a traffic condition message has been received ("YES" in S1301), the user equipment 230 transitions to S1302, and otherwise ("NO" in S1301), repeats S1301.
[0075] In S1302, the user equipment 230 determines whether the received traffic condition message is trustworthy. If the user equipment 230 determines that the traffic condition message is trustworthy (YES in S1302), the process proceeds to S1303, and otherwise (NO in S1302), the user equipment 230 repeats S1301.
[0076] For example, the user equipment 230 may determine that the traffic condition message is reliable if the autonomous driving level indicated in the information element 801 of the traffic condition message 800 satisfies a predetermined condition (for example, level 2 or higher). For example, if the autonomous driving level is level 2 or higher, it is considered that the detection accuracy of the vehicle that detected the traffic condition included in the traffic condition message is high. Therefore, the user equipment 230 can perform processing by trusting the traffic condition included in the traffic condition message 800.
[0077] Additionally or alternatively, the user device 230 identifies a record having identification information that matches the information element 802 of the traffic condition message 800 from among the multiple records included in the public key partial list obtained by the method of Fig. 11. The user device 230 may decrypt the information element 804 of the traffic condition message 800 using the public key of the identified record, and determine that the traffic condition message is trustworthy if the decryption result matches the information element 801 of the traffic condition message 800. In this way, if the decryption result of the information element 804 matches the information element 801, it is considered that the information element 801 (i.e., the autonomous driving level) has not been tampered with.
[0078] Additionally or alternatively, user equipment 230 may determine that traffic condition message 800 is trustworthy if it can decrypt information element 803 of traffic condition message 800 using the public key obtained in the manner of Figure 11. It is believed that information element 803 (i.e., the traffic condition) has not been tampered with.
[0079] In S1303, the user equipment 230 performs an action based on the traffic condition message. This action may be any action, including a preset action. For example, the user equipment 230 may issue an alert to the user. If the user equipment 230 is installed in a vehicle, the user equipment 230 may provide the vehicle with the traffic condition information included in the traffic condition message, and the vehicle may perform an action based on the traffic condition (e.g., an action to avoid a risk factor). On the other hand, if the traffic condition message 800 is determined to be unreliable, the user equipment 230 may discard the traffic condition message 800. Then, the user equipment 230 returns the process to S1301 and waits for reception of a new traffic condition message.
[0080] As described above, in S1302, the user equipment 230 uses the public keys of the surrounding user equipment 230 to decrypt information elements of the traffic condition message 800 obtained from the surrounding user equipment 230. The user equipment 230 that generates the traffic condition message 800 (i.e., uses the private key 506) is likely to be located in the same geographic area as the user equipment 230 that uses the public key. Therefore, the base station 220 does not include unnecessary public keys in the public key partial list. This reduces communication volume compared to providing the entire public key list 305.
[0081] In the above embodiment, the public key partial lists 710, 720 include geographic area information (column 703). Alternatively, the public key partial lists 710, 720 may not include geographic area information (column 703).
[0082] <Summary of the embodiment> <Item 1> A user device (230a) mounted on a vehicle (231), A user equipment having a transmission means for transmitting a message (800) including a first information element (801) representing the autonomous driving level of the vehicle and a second information element (803) representing a traffic situation detected by the vehicle to a surrounding communication device (230b) via a side link (232). According to this item, the message includes the automation level of the vehicle in which the user equipment that generated the message is installed, so that it is possible to determine how reliable the traffic situation represented by the message is. <Item 2> the message further includes a third information element (802) representing an identity of the user equipment; item 1. The user equipment according to claim 1. This item allows the user equipment that generated the message to be uniquely identified. <Item 3> the message further includes a fourth information element (804) obtained by encrypting the first information element using a private key (506) stored in the user equipment; item 3. A user device according to claim 1 or 2. This item makes it possible to determine whether the autonomous driving level has been tampered with, thereby more effectively determining how reliable the traffic situation represented by the message is. <Item 4> the second information element is encrypted by a private key (506) stored in the user equipment; item 4. A user equipment according to any one of claims 1 to 3. This item makes it possible to determine whether the traffic situation has been tampered with, and therefore makes it possible to more effectively determine how reliable the traffic situation represented by the message is. <Item 5> The traffic situation represented by the second information element includes a traffic situation requiring attention. item 5. A user equipment according to any one of claims 1 to 4. This item allows the user to determine how reliable the traffic situation requiring attention is. <Item 6> A user device (230b), A user equipment having a receiving means for receiving a message (800) including a first information element (801) representing the autonomous driving level of a vehicle (231) and a second information element (803) representing a traffic situation detected by the vehicle from a surrounding communication device (230a) mounted on the vehicle via a side link (232). According to this item, the message includes the automation level of the vehicle in which the user equipment that generated the message is installed, so that it is possible to determine how reliable the traffic situation represented by the message is. <Item 7> The receiving means further receives from the base station (220) a public key paired with a private key (506) stored in a user device (231a) installed in a vehicle (231) having a predetermined autonomous driving level. item 6. The user equipment according to claim 6. This item allows encrypted information elements contained in received messages to be decrypted. <Item 8> the message further includes a third information element (802) representing an identification of the communication device; item 6 or 7. A user device according to claim 6 or 7. This item allows the user equipment that generated the message to be uniquely identified. <Item 9> The message further includes a fourth information element (804) obtained by encrypting the first information element using a private key (506) stored in the communication device. item 9. A user equipment according to any one of claims 6 to 8. This item makes it possible to determine whether the autonomous driving level has been tampered with, thereby more effectively determining how reliable the traffic situation represented by the message is. <Item 10> the second information element is encrypted using a private key (506) stored in the communication device; item 10. A user equipment according to any one of claims 6 to 9. This item makes it possible to determine whether the traffic situation has been tampered with, and therefore makes it possible to more effectively determine how reliable the traffic situation represented by the message is. <Item 11> The traffic situation represented by the second information element includes a traffic situation requiring attention. item 11. A user equipment according to any one of claims 6 to 10. This item allows the user to determine how reliable the traffic situation requiring attention is. <Item 12> A base station (220), A base station including a transmitting means for transmitting a public key paired with a private key stored in a communication device mounted on a vehicle having a predetermined autonomous driving level to a user device. This item allows the user equipment to decrypt encrypted information elements contained in messages received. <Item 13> The base station further comprises a receiving means for receiving from a management server (211) a list (305) including a plurality of records, each of the plurality of records including a public key (702) paired with a private key stored in an individual communication device, and information (703) representing a geographic area in which the individual communication device is located; The transmitting means transmitting public keys of communication devices located within a geographic area served by the base station from among the plurality of public keys included in the list to user equipment within the geographic area served by the base station; not transmitting public keys of the plurality of public keys included in the list for communication devices that are not located within a geographic area served by the base station to user equipment within the geographic area served by the base station; item 13. The base station according to claim 12. This item reduces the amount of data transmitted from the base station to the user equipment. <Item 14> A communication method performed by a user device (230a) mounted on a vehicle (231), comprising: A communication method comprising transmitting a message (800) including a first information element (801) representing the autonomous driving level of the vehicle and a second information element (803) representing a traffic situation detected by the vehicle to a surrounding communication device (230b) via a side link (232). According to this item, the message includes the automation level of the vehicle in which the user equipment that generated the message is installed, so that it is possible to determine how reliable the traffic situation represented by the message is. <Item 15> A communication method performed by a user equipment (230b), comprising: A communication method comprising receiving a message (800) including a first information element (801) representing an autonomous driving level of a vehicle (231) and a second information element (803) representing a traffic situation detected by the vehicle from a surrounding communication device (230a) mounted on the vehicle via a side link (232). According to this item, the message includes the automation level of the vehicle in which the user equipment that generated the message is installed, so that it is possible to determine how reliable the traffic situation represented by the message is. <Item 16> A communication method performed by a base station (220), comprising: A communication method comprising transmitting a public key paired with a private key stored in a communication device mounted on a vehicle having a predetermined level of autonomous driving to a user device.
[0083] The invention is not limited to the above-described embodiment, and various modifications and variations are possible within the scope of the gist of the invention.
Claims
1. A user device mounted on a vehicle, 1. A user equipment comprising: a transmitting means for transmitting a message to a surrounding communication device via a side link, the message including a first information element representing a level of autonomous driving certified for the vehicle and a second information element representing a traffic situation detected by the vehicle.
2. The user equipment of claim 1 , wherein the message further includes a third information element representing an identification of the user equipment.
3. The user equipment of claim 1 , wherein the message further includes a fourth information element obtained by encrypting the first information element with a private key stored in the user equipment.
4. The user equipment of claim 1 , wherein the second information element is encrypted with a private key stored in the user equipment.
5. The user equipment according to claim 1 , wherein the traffic situation represented by the second information element includes a traffic situation requiring attention.
6. A user equipment, 1. A user equipment comprising: receiving means for receiving a message from a surrounding communication device mounted on the vehicle via a side link, the message including a first information element representing a level of autonomous driving certified for the vehicle and a second information element representing a traffic situation detected by the vehicle.
7. 7. The user equipment according to claim 6, wherein the receiving means further receives from the base station a public key that forms a pair with a private key stored in the user equipment installed in a vehicle that has been certified for a predetermined autonomous driving level.
8. The user equipment of claim 6 , wherein the message further includes a third information element representing an identification of the communication device.
9. The user equipment of claim 6 , wherein the message further includes a fourth information element obtained by encrypting the first information element with a private key stored in the communication device.
10. The user equipment of claim 6 , wherein the second information element is encrypted with a private key stored in the communication device.
11. The user equipment according to claim 6 , wherein the traffic situation represented by the second information element includes a traffic situation requiring attention.
12. A communication method performed by a user equipment installed in a vehicle, comprising:
1. A communication method comprising: transmitting, via a sidelink to a surrounding communication device, a message including a first information element representing a level of autonomous driving certified for the vehicle and a second information element representing a traffic situation detected by the vehicle.
13. 1. A communication method performed by a user equipment, comprising:
1. A communication method comprising receiving, via a sidelink, a message from a surrounding communication device mounted on a vehicle, the message including a first information element representing a level of autonomous driving certified for the vehicle and a second information element representing a traffic situation detected by the vehicle.
Citation Information
Patent Citations
Public key distribution system and public key distribution method
JP2008060789A
System and a Method for Improving Road Safety and / or Management
US20200312142A1
Information generation device, information generation method, and program for information generation device
WO2019065229A1