Tire pressure monitoring device that enforces range restrictions on communications
Patent Information
- Authority / Receiving Office
- JP · JP
- Patent Type
- Patents
- Current Assignee / Owner
- Filing Date
- 2021-12-13
- Publication Date
- 2026-08-14
Smart Images

Figure 0007905180000001 
Figure 0007905180000002 
Figure 0007905180000003
Abstract
Description
Technical Field
[0001] The present disclosure relates to a tire monitoring system and a method of operating the same. In an example, the present disclosure relates to an aircraft tire monitoring system such as an aircraft tire pressure monitoring system.
Background Art
[0002] Checking tire pressure is an important part of vehicle maintenance. To ensure that the tire exhibits the performance as intended by the manufacturer, the tire pressure should be maintained at a predetermined pressure. Incorrect tire pressure is likely to cause tire defects, perhaps rupture, and damage to the vehicle and / or loss of control. Since the tires of an aircraft landing gear are exposed to high speeds, the pressure is checked regularly, perhaps once a day or more frequently. Manual checking of tire pressure is time-consuming, so reducing this time is beneficial.
[0003] Automating tire pressure measurement has been proposed by attaching a sensing device to a wheel that can be wirelessly commanded to provide a measurement of tire pressure. This can reduce the required time compared to manually reading the measurement, but since the wireless channel is transmitted simultaneously outside the aircraft, security measures such as an encryption key are required.
Summary of the Invention
[0004] According to a first aspect, a tire monitoring device for use in a tire monitoring system is provided. The tire monitoring device includes a wireless interface having a ranging function and a processor. The processor is configured to receive a command via the wireless interface from a second device of the tire monitoring system, determine the distance to the second device, and execute the command if the distance to the second device is less than a predetermined threshold.
[0005] According to a second embodiment, a tire monitoring device for use in a tire monitoring system is provided. The tire monitoring device comprises a wireless interface having a range determination function and a processor. The processor is configured to receive data from a second device of the tire monitoring system via the wireless interface, determine the distance to the second device, and reject data if the distance to the second device exceeds a predetermined threshold. Optionally, the processor is configured to receive a command from a third device of the tire monitoring system via the wireless interface, determine the distance to the third device, and execute the command if the distance to the third device is less than a predetermined threshold.
[0006] The tire monitoring system is optionally configured to be mounted on the wheels of an aircraft.
[0007] According to the third embodiment, a tire monitoring system is provided that includes a plurality of tire monitoring devices, each having or not having optional features, as described above.
[0008] The tire monitoring system optionally includes a control device equipped with a wireless communication interface that has a range determination function.
[0009] A fourth aspect provides a method for a wireless tire monitoring device. The method comprises receiving a command from a second device of a tire monitoring system via a wireless interface, determining the distance to the second device, and executing the command if the distance to the second device is less than a predetermined threshold.
[0010] According to a fifth aspect, a method for a wireless tire monitoring device is provided. The method comprises receiving data from a second device of a tire monitoring system via a wireless interface, determining the distance to the second device, and rejecting the data if the distance to the second device exceeds a predetermined threshold. Optionally, the method further comprises receiving a command from a third device of the tire monitoring system via a wireless interface, determining the distance to the third device, and executing the command if the distance to the third device is less than a predetermined threshold.
[0011] Optionally, in any of the above embodiments, the wireless interface is equipped with an ultra-wideband (UWB) interface.
[0012] In any of the above configurations, the predetermined threshold is 40m or less. [Brief explanation of the drawing]
[0013] [Figure 1] This shows a schematic diagram of a tire monitoring system according to the first example of the invention.
[0014] [Figure 2] Figure 1 shows a schematic diagram of a tire monitoring device for use in the example shown.
[0015] [Figure 3] Figure 1 shows a schematic diagram of the control device used in the example shown.
[0016] [Figure 4] Figure 1 shows a schematic diagram of the configuration device for use in the example shown.
[0017] [Figure 5] This shows a schematic diagram of a tire pressure sensor network installed on an aircraft.
[0018] [Figure 6]It shows a flowchart of a tire pressure confirmation process that can be used with the example of FIG. 1.
[0019] [Figure 7] It shows a flowchart of a tire pressure confirmation process that can be used with the tire monitoring device of FIG. 2.
[0020] [Figure 8] It shows a flowchart of a process for forcing a communication range for received commands or data.
Best Mode for Carrying Out the Invention
[0021] In the following description, for purposes of explanation, numerous specific details of one example are set forth. References to "one example" or similar phrases in the specification mean that the particular features, structures, or characteristics described in connection with that example are included in at least one example, but not necessarily in other examples.
[0022] The methods and systems described herein relate to the operation of sensor networks in aircraft, such as networks of tire monitoring devices. In the examples described herein, references to "aircraft" include all types of aircraft, such as fixed-wing aircraft, such as military or commercial airplanes, or unmanned aerial vehicles (UAVs), and rotary-wing aircraft, such as helicopters.
[0023] According to the example herein, a tire monitoring device forming part of a tire monitoring system provides an indication of the status of the tire monitoring device itself. For example, the indication of status can be provided by a light having a color that gives information about the status. Verification of the status shown in the tire monitoring device is provided as an input to a control device, which can compare it in the control device with status data received from the tire monitoring device itself. In this way, various human factors in the use of the system can be addressed. When the input is from a user of the system, it means that the user has to pay attention not only to the information displayed on the control device but also to the indicators of the device itself. This can be important when the indicators of the tire monitoring device are guaranteed to a desired Design Assurance Level (DAL), but the indicators of the control device are not. It can also address human error factors such as seeing the wrong aircraft when several are very close. As a further advantage, an error can be identified when the user input does not match what is displayed on the device itself.
[0024] In some examples, when the status of the display instrument of the tire monitoring device is verified by an input (i.e., when it is determined that both the display instrument of the tire monitoring device and the input represent the same status), the display instrument of the tire monitoring device can switch off. This can result in power savings since there is no need to operate the display instrument for a long time. For example, the display instrument can be a high-intensity LED to enable viewing even in bright sunlight. An example of a high-intensity LED is the Vishay TLCR5200, a red LED available commercially from Vishay. This LED has a typical luminous intensity of 4,000 mcd but consumes 135 mW, so useful energy savings can be achieved by stopping operation earlier than the overall system timeout. Such energy savings can be particularly useful when the power supply of the tire monitoring device has a finite energy capacity such as a battery, as it directly affects the life of the tire monitoring device.
[0025] [Example: Tire monitoring system] Figure 1 shows a schematic diagram of a tire monitoring system, which in this case is a pressure sensor system according to the first example. The system comprises multiple tire monitoring devices 10, control devices 12, and component devices 14, all of which are arranged to communicate via wireless communication. The tire monitoring devices are mounted on each wheel of a vehicle, which in this case is an aircraft (see Figure 5, which will be described in more detail below). The control device 12 is separate from the tire pressure sensor 10 and may be a dedicated control device that functions only in the tire pressure sensor system, or it may be a computing device that can be used for purposes other than those in the tire pressure sensor system. Examples of computing devices include mobile devices such as laptops, tablets, mobile phones, and wireless communication devices.
[0026] The wireless communication in the tire pressure sensor system shown in Figure 1 can use a local area network or a personal area network and can take any suitable form, including centralized and wireless mesh systems. In a centralized system, a single device is configured as the master device for coordinating communications, or one or more additional wireless access points, gateways, or controllers (not shown) can be used. In some examples, the tire monitoring device 10, the control device 12, and the component devices 14 can all communicate using the same wireless technology and form a single network. In other examples, one or more of the tire monitoring device 10, the control device 12, and the component devices 14 can be isolated from other elements of the system. Such isolation can be provided in software, for example, by providing a suitable firewall and / or by using different network IDs and encryption keys. Such isolation can also be provided in hardware, for example, by different wireless communication technologies. Hardware isolation and software isolation can be combined. For example, in the system shown in Figure 1, the control device communicates with the tire sensing device using a different wireless communication technology than the component devices, which can improve the security of the system.
[0027] Figure 2 shows a schematic diagram of a tire monitoring device 10 for use in the tire pressure sensor system of Figure 1. The tire monitoring device 10 is configured to be mounted on a wheel, for example, by a mechanical connection to an opening on the wheel that provides access to the tire. The tire monitoring device 10 includes a processor 200, a wireless communication interface 202, a display instrument 204, a power supply 206, a pressure sensor 208, a temperature sensor 209, a first storage 210, and a second storage 211.
[0028] The processor 200 may be any suitable processing unit comprising a microprocessor having one or more processing cores. In use, the processor 200 can coordinate and control other components and operate to read computer program instructions and data from and / or write to storage 210 and 211. The processor may be optimized for low-power operation, or in some examples may have at least one processing core that is optimized for low-power operation.
[0029] The wireless communication interface 202 is connected to the processor 200 and is used to send and receive data to and from other devices in the tire pressure sensor system. In this example, the wireless communication interface includes two transceivers 212 and 214 that use different wireless technologies. The first transceiver 212 is provided for communication over relatively long distances of up to about 50m or about 100m. For example, the first transceiver can use a communication standard appropriate for mobile devices, such as IEEE 802.15.1, IEEE 802.15.4, or IEEE 802.11 (Wi-Fi) based on either the 2.4GHz or 5GHz Industrial Scientific Medical (ISM) band or the In-Aircraft Data Communications (WAIC) standard. The first transceiver also includes an encryption module for encrypting transmitted data and decrypting received data, for example, in accordance with the Advanced Encryption Standard (AES) using a pre-shared key. The second transceiver 214 is provided for communication over relatively short distances. For example, the second transceiver 214 can use standards compliant with IEEE 802.15, RFID, or Near Field Communication (NFC), such as IEEE 802.15.4. The second transceiver can operate at distances of less than 5m, less than 3m, less than 1m, less than 50cm, less than 25cm, less than 10cm, less than 5cm, or less than 1cm, or requires contact between devices to operate. Similar to the first transceiver 212, the second transceiver also includes an encryption module for encrypting transmitted data and decrypting received data.
[0030] In some cases, a single wireless transceiver can be provided in the wireless communication interface. In this case, the single transceiver can be used for relatively short-range or relatively long-range communication, or the range can be adjusted if necessary (for example, by controlling the transmit power).
[0031] The indicator instrument 204 is connected to the processor 200 and controlled by the processor 200 to provide an indicator to the user of the tire pressure sensor system. In this example, the indicator instrument is an LED, but in other examples, the indicator instrument is another form of light, a display such as an LCD or electronic ink display, or any other form of visual indicator. In other examples, the indicator instrument is an audible indicator instrument such as a buzzer, a sound-emitting device, a speaker, or any other sound-generating component. In further examples, the indicator instrument may comprise both audible and visual indicator components. The indicator instrument provides at least a first and second indicator, e.g., a first and second color of emitted light. Further indicators, such as a lit light or a flashing light, may also be provided. The tire monitoring device has a housing (not shown), and the indicator instrument 204 may provide an indicator outside the housing, e.g., an LED may be mounted outside the housing or mounted so as to be visible through the housing, or sound may be emitted from inside the housing.
[0032] Power source 206 provides power to the elements of the sensing device. Power source 206 may be a battery, such as a lithium battery. In this example, the power source is a lithium battery with enough power to keep the sensor running normally for about 2-3 years. In other examples, the power source may include, for example, a power harvesting system that captures vibration and / or electromagnetic radiation, which is used to charge a capacitor or battery and then supply power to the device.
[0033] In use, wireless sensing devices can spend much of their operating life in "sleep" or low-power mode, with most components other than the processor and wireless communication interface deprived of power. This helps conserve battery life. For example, a tire monitoring device can be in low-power mode by default, waiting to detect commands to measure or report tire pressure. Displaying tire pressure values is requested relatively infrequently, perhaps once every 10 days, 5 days, 3 days, or even once a day, which can provide useful power savings. In other examples, pressure is sensed more frequently, for example, every 10 minutes, 15 minutes, 20 minutes, 30 minutes, every hour, or every 2 hours, and can be saved for use in trend monitoring.
[0034] The pressure sensor 208 is connected to the processor 200 and may be any suitable sensor for measuring pressure, such as a capacitive sensor. Similarly, the temperature sensor 209 is connected to the processor 200 and may be any suitable sensor for measuring temperature, such as a thermocouple. The temperature sensor 209 may be positioned to measure the temperature of the wheel, or to directly measure the temperature of the gas inside the tire. If the temperature sensor 209 measures the temperature of the wheel, this temperature can be processed to determine the temperature of the gas in the tire. For example, an algorithm or a lookup table can be used.
[0035] The connections of the pressure sensor 208 and the temperature sensor 209 to the processor 200 may be digital, providing digital representations of the measured pressure and / or temperature from analog-to-digital converters (ADCs) in the sensors themselves. Alternatively, the connections may be analog, in which case the processor may include an ADC to sample the received signals. Including both a pressure sensor and a temperature sensor is useful for determining temperature-compensated pressure values. While this example includes both a pressure sensor and a temperature sensor, other examples may include only a pressure sensor, or include additional sensors.
[0036] This example includes two storage elements 210 and 211. In this example, storage 210 is a rewritable non-volatile storage that can hold data without requiring applied power, such as flash memory. Other examples may include volatile storage that is kept powered by a power supply, or a combination of read-only storage and rewritable storage. Storage 210 is connected to the processor 200 and is used to store both computer program instructions for execution by the processor and data such as data from the pressure sensor 208 or data received via the wireless communication interface 202. In some examples, storage 210 can store a history of pressure and / or temperature readings sensed by the pressure sensor 208 and the temperature sensor 209. For example, it can store readings from the past 10 days, and when the storage is full, the newest data replaces the oldest data.
[0037] Storage 211 is a secure storage device with restricted write and / or read access, accessible, for example, only to a specific process running on processor 200. Configuration data, such as wireless encryption keys, can be stored in storage 211. In other examples, only a single storage device may be provided, or storage devices 210 and 211 may be provided in a single physical device by logically partitioning storage devices 210 and 211.
[0038] Figure 3 shows a schematic diagram of the control device 12 for use in the example shown in Figure 1. The control device 12 includes a processor 300, a display 302, an input system 304, a power supply 306, a wireless interface 308, storage 310, and a wired communication interface 312. In this example, the control device is a mobile device such as a mobile phone or tablet computer.
[0039] The processor 300 is any suitable processing unit, such as a multipurpose microprocessor, a system-on-a-chip, or a system-in-package, and may include one or more processing cores. The processor 300 is connected to a display 302, such as an LCD, OLED, or e-ink display, to display information to the user of the control unit.
[0040] In this example, the input system 304 includes a touchscreen interface, allowing the user to interact with the control device by touching user interface elements on the screen. In addition to the touchscreen, the input system 304 may include one or more buttons, along with other input devices such as a microphone for speech recognition and a camera for image input. Other examples may not include a touchscreen interface.
[0041] In this example, the control device is powered by power supply 306, which is a rechargeable lithium-ion battery. Other examples may use alternative power sources such as other battery technologies, a mains power source (commercial power), or energy harvesting such as solar power.
[0042] A wireless interface 308 is included in the control unit 12 for communicating with other devices in the tire pressure sensor system. In this example, a single wireless interface 308 is provided, configured to communicate with the tire monitoring device 10. Relatively long-range wireless communication technologies can be used, such as wireless communication technologies compliant with IEEE 802.15.1, IEEE 802.15.4, or IEEE 802.11. This allows the control unit 12 to exchange information with the tire monitoring device from a relatively long distance.
[0043] In other examples, the control unit can be provided with multiple wireless communication interfaces or transceivers operating with different wireless technologies, such as IEEE 802.15.1, IEEE 802.15.4, IEEE 802.11 (Wi-Fi_33), WAIC, RFID, and at least two of NFC. For example, the control unit may have two transceivers, one of which has a longer communication range than the other.
[0044] Storage 310 includes non-volatile elements such as flash memory and volatile elements such as RAM. The non-volatile elements are used to store operating system software and application software. In this example, the control unit boots standard operating system software and has application software to communicate with the tire pressure sensor system. To restrict access to the tire pressure sensor network, the application software can be provided from a secure source, not generally available, and / or may require credentials to be entered before operation.
[0045] A wired communication interface 312 is provided for connection to the computing system. The wired communication interface 312 can be a serial data connection such as Universal Serial Bus (USB), a parallel data connection, or a network connection such as Ethernet®. The wired communication interface 312 allows the control unit to transmit values and / or other status information read from the tire monitoring device to the computing system, for example, to store long-term trends and assist in fleet management. Alternatively, or additionally, a wireless communication interface 308 can be used for communication with the computing system. In some examples, the control unit may not include a wired communication interface.
[0046] Figure 4 shows a schematic diagram of the configuration device 14 for use in the example shown in Figure 1. The configuration device 14 contains substantially the same elements as the control device 12. That is, it includes a processor 400, a display 402, an input system 404, a power supply 406, a wireless interface 408, storage 410, and a wired communication interface 412, which are substantially the same as those described above with respect to the control device unless otherwise stated below. In this example, the configuration device is a mobile device, but is limited to operating only with the tire monitoring system. For example, the configuration device may be a computing device or tablet capable of running software for exchanging information with the tire monitoring system.
[0047] In this example, the wireless communication interface 408 of the configuration device is a relatively short-range communication system such as IEEE 802.15.1, IEEE 802.15.4, NFC, or RFID. This allows the configuration device to act as an additional authentication factor when configuring the tire monitoring device, for example, the tire monitoring device only needs to respond to configuration commands received from the configuration device, or only needs to respond to configuration commands received from the control device after receiving commands from the configuration device.
[0048] In other examples, the configuration may include multiple wireless communication interfaces or transceivers. For example, as discussed above, the configuration may include transceivers for relatively short-distance communication and transceivers for relatively long-distance communication, such as transceivers compliant with IEEE 802.11.
[0049] The wired communication interface 412 of the configuration device can be used to provide information to the configuration device in a secure manner, for example, allowing several encryption keys to be updated via a wired interface such as a serial data connection rather than a wireless interface.
[0050] In some examples, the configuration device 14 can be omitted and replaced by the control unit 12. The control unit 12 may be equipped with a short-range wireless communication interface, such as a wireless communication interface compliant with IEEE 802.15.1, IEEE 802.15.4, RFID, or NFC. Application software may be installed on the control unit, thereby enabling the control unit to also function as an additional authentication factor, perhaps through maintaining an encryption key accessible only with appropriate credentials, to control the operation of the short-range wireless communication interface for sending configuration commands. In these examples, separate application software may be provided on the control unit, and this software can be run so that the control unit functions as a configuration device.
[0051] Figure 5 shows a schematic diagram of a tire pressure sensor network installed on an aircraft. The aircraft 500 comprises a fuselage 510, wings 520, main landing gear 530, and nose gear 540. In one example, the aircraft 500 is equipped with a sensor network relating to any of the examples described herein. The aircraft 500 can be used in conjunction with any of the methods described herein. In one example, multiple radio nodes are distributed at various locations around the aircraft 500. For example, they are distributed on the main landing gear 530 and nose gear 540, the wings 520, and the fuselage 510. Tire monitoring devices are installed on each wheel of the main landing gear 530 and nose gear 540.
[0052] In one example, the tire monitoring device 10 also communicates with the cockpit system to provide tire pressure information to the pilot in the cockpit. In these examples, the cockpit console can also function as a control device.
[0053] [Example of a tire pressure check process] Figure 6 shows a flowchart of the tire pressure verification process that can be used with the example in Figure 1. First, in block 602, the user starts the tire monitoring and control application on the control unit 12. During the initialization of the application, it is confirmed that the wireless communication interface 308 for communication with the monitoring device is operational on the control unit, and if it is not operational, the user is prompted to activate it.
[0054] Next, in block 604, the control unit investigates nearby tire monitoring devices. For example, the control unit may send out a probe via a wireless communication interface, thereby causing any nearby tire monitoring device to respond with an index of a vehicle identifier, such as the tail identifier of the aircraft to which the tire monitoring device is attached. This investigation may include establishing direct point-to-point contact with each tire monitoring device, or contact via a network of tire monitoring devices, for example, through an access point, master device, or any other device in a mesh network. The investigation may include bringing the tire monitoring devices from low-power mode to an active state. The investigation may include using a secure network key to communicate with the sensor network.
[0055] Depending on the communication distance and location, tire monitoring devices associated with two or more vehicles can be detected. For example, several aircraft may be in the same hangar near the control device. Next, in block 606, it is determined whether the identifier should be automatically selected without requiring the use of input. For example, an application may store a configuration option for whether the identifier should be automatically selected or not. If automatic selection is not requested, the process proceeds to block 608. If automatic selection is requested, the process proceeds to block 612. In some examples, block 606 is not included. In these examples, the process can continue with manual or automatic selection as described below.
[0056] For manual selection, in block 608, the control unit displays the identifier of the detected vehicle. In block 610, input of the selected identifier from, for example, the user's selection of a desired identifier is received.
[0057] For automatic selection, in block 612, the vehicle identifier is automatically selected from the identifiers indicated in the received responses. This can be done in various ways. For example, if each nearby tire monitor responds individually to the control unit, at least two responses may be from tire monitors associated with the same vehicle identifier. In this case, the vehicle identifier associated with the largest number of responses is likely to be the vehicle closest to the control unit for which pressure measurement is requested, and this may be automatically selected. In another example, the vehicle identifier of the tire monitor closest to the control unit, for example, the response with the maximum value of the Received Signal Strength Index (RSSI), may be selected. In yet another example, all detected tire monitors may be associated with the same vehicle identifier, in which case it is selected.
[0058] Next, in block 614, a command is sent to the tire monitoring device corresponding to the selected identifier to cause it to read the pressure and report it to the control device. For example, the tire monitoring device may perform a process as described below with reference to Figure 7.
[0059] The response is received from the tire monitoring device in block 616 and displayed on the control unit in block 618. The pressure display may include a numerical value and either or both a status indicator such as "OK" or "Low Pressure".
[0060] In block 620, the received data can be verified to ensure data integrity. Then the process terminates.
[0061] During the process shown in Figure 6, communication between the control unit and the sensor device can be secured by encryption using, for example, a network key. The network key for communication with the control unit may be different from the network key used for communication between the sensor devices in order to enhance the security of the system.
[0062] Security can be enhanced by using wireless communication technology with limited transmission distance when exchanging security keys. For example, the 802.11 (Wi-Fi) standard allows communication over distances exceeding 50m in line-of-sight space. In some cases, when transmitting encryption keys, security can be enhanced by reducing the transmission power compared to transmitting the encrypted data itself, or by using short-range technologies such as NFC or RFID, which require closer proximity for the initial key exchange process. Distance-limiting technologies can also be introduced, and when combined with ultra-wideband wireless communication, this allows for secure measurement of the distance between communication devices, ensuring that information is being exchanged within a secure vicinity of the devices. This will be further discussed with reference to Figure 8 below.
[0063] Figure 7 shows a flowchart of the tire pressure verification process that the tire monitoring device of Figure 2 can use. This process is provided to provide additional assurance and fault tolerance in pressure measurements from the system, for example, to monitor for misoperation or errors in the control device. Through this process, the monitoring device uses its display instrument to provide an indicator of tire pressure status that is independent of the control device. In some examples, the tire pressure status indicator provided by the monitoring device may have a higher Design Assurance Level (DAL) than the indicator provided by the control device. For example, the control device can be used to initiate tire pressure measurement and provide a convenient means for the user to understand the measurement results, but it cannot have a DAL guarantee, while the operation of the monitoring device to provide an indicator using the monitoring device's display instrument can guarantee a Design Assurance Level B. This allows the system to operate with a wide range of control devices, as no DAL guarantee is required for those devices, but it still ensures that the system as a whole meets the required safety standards. Similarly, in some examples, the monitoring device may have a higher Security Assurance Level (SAL) than the control device.
[0064] First, in block 702, the tire monitoring device receives a command from the control unit via a wireless communication interface to check the pressure. In response, in block 704, the processor uses a pressure sensor to measure the pressure in the tire. The measured pressure is then compared to a reference pressure in block 706 to determine whether the tire pressure is low. In this example, low pressure occurs when the pressure sensed by the pressure sensor is less than 89% of the reference pressure. In other examples, low pressure can be determined when the measured pressure is less than 95%, less than 90%, or less than 85% of the reference pressure. In further examples, low pressure can be determined when the measured pressure is at least about 207 kPa (about 30 psi) lower than the reference pressure. In other examples, low pressure can be determined when the measured pressure is at least about 138 kPa (about 20 psi), or about 69 kPa (about 10 psi), lower than the reference pressure. If low pressure is detected, the execution proceeds to block 708; otherwise, it proceeds to block 712.
[0065] In block 708, the processor uses an indicator instrument to show the defect status, for example, by providing a red light that remains illuminated for a predetermined period of time. The predetermined period may be, for example, 5 minutes, 2 minutes, 1 minute, or 30 seconds. The processor also uses a wireless communication interface again to transmit indicators of the defect to other tire monitoring devices in block 712.
[0066] In block 712, the processor checks whether a message indicating any defect has been received via the wireless communication interface from another tire monitoring device. Such a message indicating a defect may be received directly, via another tire monitoring device, or via a hub or access point. In this example, such a message indicating a defect is received without prior request, following the receipt of the command in block 704. In other examples, a message indicating a defect may be received in response to a status query sent by a tire monitoring device to another tire monitoring device. Once a message indicating any defect is received, execution proceeds to block 714, where the processor uses an indicator instrument to display the defect status. For example, the indicator indicating a defect may be the same as the one used in block 708. In other examples, the indicator indicating a defect may be different from the one used in block 708, and may be a second indicator indicating a defect, such as a red light that flashes for a predetermined period of time. By using a second indicator indicating a defect, the tire monitoring device can indicate a defect in another tire and that its own measured pressure is not low.
[0067] If no message indicating a defect is received in block 712, the execution process proceeds to block 716, where the processor provides an indicator of "OK" using an indicator instrument. For example, an indicator of "OK" is provided by providing a green light that remains lit for a predetermined time. The predetermined time may be, for example, 5 minutes, 2 minutes, 1 minute, or 30 seconds. In this way, an indicator of "OK" is given only when all tire monitoring devices determine that the pressure of the tire associated with them is not low and that they have not received any indicators of a defect from other tire monitoring devices.
[0068] Finally, in block 718, the measured tire pressure data is transmitted to the control unit in response to a command. This data may further include information such as the stored reference pressure, determined status, and wheel position. The transmission of additional information allows for verification of the correct operation of the tire monitoring device and confirmation that the configuration data stored in storage has not changed or has been set correctly. Transmission in block 718 can be made directly to the control unit 12, or to other tire monitoring devices 10 for transfer, or to an access point or other wireless node.
[0069] In the method shown in Figure 7, the tire pressure status is checked by the tire monitoring device itself. A defect in any sensor will cause all sensors to indicate a defect. In this way, the tire monitoring device can be guaranteed according to the required DAL and / or SAL using the indicators of the tire monitoring device itself, without requiring the control device to also be guaranteed.
[0070] In other examples, instead of transmitting an indicator of a defect in block 710, all tire monitors may instead transmit their own measured pressure to other tire monitors. The received pressures may then be independently checked by each independent tire monitor to determine whether a defect exists. This allows for monitoring, for example, a defect in a sensor that does not indicate a low-pressure condition when the stored reference pressure is incorrect.
[0071] In a further example, when block 706 determines that the tire pressure is not low, the tire monitoring device may send an "OK" status notification. Such an example can provide assurance that all sensors are working correctly, as the absence of data from one of the other tire monitoring devices indicates a malfunction or defect in that device.
[0072] While the above process describes using a general-purpose mobile device as a control unit, the control unit may also be a dedicated device provided specifically for use with tire monitoring systems, or more generally, for use with vehicles. This can improve security as it allows for a higher level of control.
[0073] While the process described above describes the use of a light-based indicator instrument, other examples may utilize other indicator instruments such as displays and / or audio components. For example, instead of simply displaying the color that is lit or flashing, a display can also display information about the measured pressure itself. Even when both audio and visual indicator instruments are provided, some indicators may not require the use of both. For example, an "OK" indicator may only require a visual indicator instrument, with the audio indicator only activating when there is a defect.
[0074] [Distance restrictions for enhanced security] The use of wireless communication can increase security risks because wireless channels are more easily accessible to third parties. Encrypting messages exchanged between devices in a tire monitoring system makes it more difficult for unauthorized devices to eavesdrop or inject malicious commands or data without knowledge of the encryption key. As mentioned above, limiting the communication distance can also improve security. Such limitations in distance can be inherent in wireless communication protocols; for example, NFC and RFID typically operate within a range of less than 30 cm. Other wireless communication protocols, such as WiFi or the 802.11 protocol, can have a range of about 50 m in line-of-sight space, and this range will be smaller if the transmission power is limited. Nevertheless, even if transmission power limits the communication range, it does not present a clearly defined boundary. The range can be extended, for example, by using directional antennas to increase sensitivity.
[0075] In this embodiment, a distance criterion is used in the tire monitoring device. When communication begins, the range or distance to the communicating device is determined and evaluated against the distance criterion. If the range is greater than the threshold distance, communication is stopped, and no received commands or data are processed. Alternatively, received commands or data can only be processed when the range is less than the threshold distance. For typical use of tire monitoring systems, appropriate threshold distances are 40m, 30m, or 25m. Security against malicious attacks is improved because physical proximity is enforced.
[0076] Shorter threshold distances can be used for special types of commands, such as configuration commands and / or encryption key exchange. In this case, the distance threshold may be, for example, 1m, 50cm, 25cm, or 5cm.
[0077] Any suitable technique can be used to determine the range. The radio communication protocol itself may include ranging techniques. For example, ultra-wideband (UWB) communication includes range determination as part of the protocol stack. The range or distance is preferably determined actively using time-of-flight measurements, along with the exchange of range data between the transmitter and receiver, as defined in IEEE 802.15.4a or IEEE 802.15.4z.
[0078] Herein, we describe an example of using enforced distance limits to improve the security of the tire pressure checking process, such as the method described with reference to Figure 7. This method can be used in block 702 to determine whether to execute or implement a command received via the wireless interface, or whether to process or reject data received from other sensors, such as a message indicating a defect in block 712.
[0079] Figure 8 shows an example method that can be used to enforce distance limits. First, in block 802, the tire monitoring device receives commands and / or data via a wireless interface from other devices in the tire monitoring system. This may be from other tire monitoring devices (such as for the received data) or control devices (such as for the commands). In this example, the data is received via a UWB wireless interface.
[0080] Next, in block 804, the distance to the second device is determined. Any suitable distance measurement technique can be used. For example, a time-of-flight method in which the devices exchange distance measurement data, calculate the time of flight, and calculate the distance provides distance measurements that are difficult to find comparable to.
[0081] Once the distance is determined, block 806 determines whether the distance is shorter than a predetermined distance threshold. If the distance is shorter than the threshold, the execution process proceeds to block 808, where commands are executed or data is processed appropriately. If the distance exceeds the threshold, the method terminates in block 810. In some examples, before the method terminates in block 810, an alarm may be provided, such as by flashing an indicator instrument, or the tire monitoring device may indicate that a potentially invalid command or data has been received.
[0082] It should be noted that, as used here, the term "or" should be interpreted as meaning "and / or" unless otherwise specified.
[0083] The above examples should be understood as examples of the invention. It should be understood that any feature described in relation to any one example can be used alone, in combination with other features described, in combination with one or more features of any other example, or in combination with any combination of any other example. Furthermore, equivalents and modifications not described above can also be adopted without departing from the scope of the invention as defined in the accompanying claims.
Claims
1. A tire monitoring device configured to be mounted on the wheel of an aircraft and for use in a tire monitoring system, A wireless interface having a distance determination function, It is a processor, The system receives a command via the wireless interface from a wireless transmission from the second device of the tire monitoring system. In response to receiving the command, the distance to the second device is determined, which is the distance between the second device and the wireless interface. A tire monitoring device comprising a processor configured to execute the command if the distance to the second device is less than a predetermined threshold.
2. A tire monitoring device configured to be mounted on the wheel of an aircraft and for use in a tire monitoring system, A wireless interface having a distance determination function, It is a processor, The system receives data via the wireless interface from a wireless transmission from the second device of the tire monitoring system. In response to the reception of the aforementioned data, the distance to the second device is determined, which is the distance between the second device and the wireless interface. A tire monitoring device comprising a processor configured to reject the data if the distance to the second device exceeds a predetermined threshold.
3. The aforementioned processor, The third device of the tire monitoring system receives a command via the wireless interface. The distance to the third device is determined to be the length between the third device and the wireless interface. The tire monitoring device according to claim 2, which is configured to operate according to the command when the distance to the third device is less than a predetermined threshold.
4. The tire monitoring device according to claim 1, 2, or 3, wherein the wireless interface is an ultra-wideband (UWB) interface.
5. The tire monitoring device according to any one of claims 1 to 4, wherein the predetermined threshold is 40 m or less.
6. A tire monitoring device according to any one of claims 1 to 5, configured to be mounted on the wheel of an aircraft.
7. A tire monitoring system comprising a plurality of tire monitoring devices as described in any one of claims 1 to 6.
8. The tire monitoring system according to claim 7, further comprising a control device having a wireless communication interface having a distance determination function.
9. A method for a wireless tire monitoring device mounted on the wheel of an aircraft and equipped with a wireless interface, Receiving commands wirelessly from the second device via a wireless interface, In response to receiving the command, the wireless tire monitoring device determines the distance to the second device, which is the distance between the second device and the wireless interface. A method comprising the wireless tire monitoring device operating according to the command when the distance to the second device is less than a predetermined threshold.
10. A method for a wireless tire monitoring device mounted on the wheel of an aircraft and equipped with a wireless interface, Receiving data wirelessly from the second device via a wireless interface, In response to receiving the aforementioned data, the wireless tire monitoring device determines the distance to the second device, which is the distance between the second device and the wireless interface. A method comprising the wireless tire monitoring device rejecting the data if the distance to the second device exceeds a predetermined threshold.
11. Receiving commands from a third device via the wireless interface, In response to receiving the command, the wireless tire monitoring device determines the distance to the third device, which is the distance between the third device and the wireless interface. The method according to claim 10, wherein the wireless tire monitoring device operates according to the command when the distance to the third device is less than a predetermined threshold.
12. The method according to claim 9, 10, or 11, wherein the wireless interface comprises an ultra-wideband (UWB) interface.
13. The method according to any one of claims 9 to 12, wherein the predetermined threshold is 40 m or less.
Citation Information
Patent Citations
Method for operating a tire pressure monitoring unit
DE102017131302A1
Wheel position detection device and tire pneumatic pressure detection device provided with it
JP2007015491A
Receiver, communication device, and controller using it
JP2007142790A
Communication method
JP2007329537A
Wheel position-detecting transmitter / receiver, wheel position detection device and tire pressure detection device
JP2009053089A