Mobile robot, server, mobile robot control system, and mobile robot control method

JPWO2024057870A5Pending Publication Date: 2025-05-23
View PDF 0 Cites 0 Cited by

Patent Information

Application Number
JP2024546815
Authority / Receiving Office
JP · JP
Patent Type
Applications
Filing Date
2025-03-05
Publication Date
2025-05-23

AI Technical Summary

Technical Problem

Existing mobile robot control systems face challenges in reliably moving mobile robots to a safe area when abnormalities are detected, particularly due to cybersecurity issues and the risk of remote hijacking, which can lead to harm to the surrounding environment.

Method used

A mobile robot control system that includes a determination unit to assess the reliability of autonomous movement functions and a control unit to move the robot to a safe area based on acquired information, with additional features for alert generation and remote control UI to ensure safe operation even when autonomous movement is unreliable.

Benefits of technology

The system effectively prevents mobile robots from moving to unsafe areas and reduces the risk of harm to the environment by reliably moving them to a safe location, even when autonomous movement functions are compromised.

✦ Generated by Eureka AI based on patent content.
Patent Text Reader

Abstract

A mobile robot (100), which is capable of autonomous movement, is provided with: a reliability determination unit (156) that determines reliability regarding an autonomous travel function (130) of the mobile robot (100); a safe area acquisition unit (154) that acquires information regarding a safe area where the mobile robot (100) can stop; and a control unit (110) that moves the mobile robot (100) to the safe area on the basis of the information regarding the safe area if an abnormality in the mobile robot (100) is detected during autonomous movement of the mobile robot (100) and the safe area acquisition unit (154) determines that the autonomous travel function (130) is reliable.
Need to check novelty before this filing date? Find Prior Art

Description

Mobile robot, server, mobile robot control system, and mobile robot control method

[0001] The present disclosure relates to a mobile robot, a server, a mobile robot control system, and a mobile robot control method.

[0002] Due to factors such as labor shortages and increased logistics, the spread of self-driving trucks and autonomous delivery robots is expected and becoming increasingly important. Unlike conventional industrial robots that operate in predetermined environments such as factories, these mobile robots are designed to operate in a variety of environments, including public roads. Systems are being considered and prepared to address situations where autonomous control of mobile robots is difficult, remote monitoring by remote operators to enable efficient operation of mobile robots, and fleet management systems to manage the status of remotely controlled robots and multiple robots. Utilizing these systems will expand the remote work market and make it possible to provide jobs to people who are unable to work due to physical reasons, location, working hours, or other issues, thereby contributing to resolving many issues.

[0003] However, cybersecurity issues remain for mobile robots. For example, there have been reported cases of remote intrusion into in-vehicle networks and unauthorized control of automobiles. There have also been cases of attacks on ships, where spoofed signals were sent to the Global Positioning System (GPS) of a ship's system to guide the ship.

[0004] When an abnormality is detected in such a mobile robot, it is desirable for the mobile robot to move to a safe area where safety is ensured and the robot will not adversely affect the surrounding environment, and stop there.

[0005] Prior Art Document 1 discloses a method in which, when a mobile robot detects an abnormality, it autonomously travels to a safe area and stops there.

[0006] Japanese Patent Application Laid-Open No. 2020-115397

[0007] When an abnormality is detected in a mobile robot, it is desirable to move the mobile robot to a safe area more reliably. The technology of Patent Document 1 leaves room for improvement in terms of more reliably moving the mobile robot to a safe area.

[0008] Therefore, the present disclosure provides a mobile robot, a server, a mobile robot control system, and a mobile robot control method that can more reliably move the mobile robot to a safe area when an abnormality is detected in the mobile robot.

[0009] A mobile robot according to one aspect of the present disclosure is a mobile robot capable of autonomous movement, and includes a first judgment unit that judges the reliability of the autonomous movement function of the mobile robot, a first information acquisition unit that acquires information regarding a safe area where the mobile robot can stop, and a first control unit that, when an abnormality in the mobile robot is detected while the mobile robot is moving autonomously and the first judgment unit judges that the autonomous movement function is reliable, moves the mobile robot to the safe area based on the information regarding the safe area.

[0010] A server according to one aspect of the present disclosure is a server communicatively connected to an autonomously movable mobile robot, and includes a second judgment unit that judges the reliability of the autonomous movement function of the mobile robot, a second information acquisition unit that acquires information regarding a safe area where the mobile robot can stop, and a second control unit that, when an abnormality in the mobile robot is detected during the autonomous movement of the mobile robot and the second judgment unit judges that the autonomous movement function is reliable, moves the mobile robot to the safe area based on the information regarding the safe area.

[0011] A mobile robot control system according to one aspect of the present disclosure is a mobile robot control system comprising a mobile robot capable of autonomous movement and a server communicatively connected to the mobile robot, and further comprising a judgment unit that judges the reliability of the autonomous movement function of the mobile robot, an information acquisition unit that acquires information about a safe area where the mobile robot can stop, and a control unit that, when an abnormality in the mobile robot is detected during the autonomous movement of the mobile robot and the judgment unit judges that the autonomous movement function is reliable, moves the mobile robot to the safe area based on the information about the safe area.

[0012] A mobile robot control method according to one aspect of the present disclosure is a mobile robot control method for controlling a mobile robot capable of autonomous movement, wherein if an abnormality in the mobile robot is detected while the mobile robot is moving autonomously and it is determined that the autonomous movement function of the mobile robot is reliable, the mobile robot is moved to a safe area based on information regarding a safe area where the mobile robot can stop.

[0013] According to one aspect of the present disclosure, it is possible to realize a mobile robot or the like that can more reliably move the mobile robot to a safe area when an abnormality is detected in the mobile robot.

[0014] FIG. 1 is a diagram illustrating the overall configuration of a mobile robot control system according to an embodiment. FIG. 2 is a block diagram illustrating the functional configuration of a mobile robot according to an embodiment. FIG. 3 is a block diagram illustrating the functional configuration of a management server according to an embodiment. FIG. 4 is a block diagram illustrating the functional configuration of a monitoring server according to an embodiment. FIG. 5 is a block diagram illustrating the functional configuration of a remote control terminal according to an embodiment. FIG. 6 is a sequence diagram illustrating the operation of a mobile robot control system when autonomous traveling according to an embodiment. FIG. 7 is a sequence diagram illustrating the operation of a mobile robot control system when remotely controlled traveling according to an embodiment. FIG. 8 is a diagram illustrating an example of a first remote-piloting UI according to an embodiment. FIG. 9 is a sequence diagram illustrating the operation of a mobile robot control system when an abnormality is detected according to an embodiment. FIG. 10 is a first sequence diagram illustrating the operation of a mobile robot control system when a safe area has not been identified according to an embodiment. FIG. 11 is a diagram illustrating an example of a safe area identification UI according to an embodiment. FIG. 12 is a second sequence diagram illustrating the operation of a mobile robot control system when a safe area has not been identified according to an embodiment. FIG. 13 is a diagram illustrating an example of a second remote-piloting UI according to an embodiment. FIG. 14 is a first sequence diagram illustrating the operation of a mobile robot control system when the autonomous traveling function reliability is NG according to an embodiment. Fig. 15 is a diagram showing an example of an emergency stop failure notification UI according to an embodiment. Fig. 16 is a second sequence diagram showing the operation of the mobile robot control system when the autonomous traveling function reliability is NG according to an embodiment. Fig. 17 is a flowchart showing the operation of the mobile robot according to an embodiment.

[0015] (Background to the Disclosure) As described in the "Background Art" section, cybersecurity issues exist for mobile robots. For example, with mobile robots, it is necessary not only to ensure the security of the control network, control applications, control devices, and sensors within the mobile robot, but also to consider the unreliability of the surrounding environment in which the mobile robot operates and the possibility of physical access by malicious third parties. It is also necessary to consider the security of external devices that access the mobile robot, such as servers and terminals running client applications. As such, mobile robots face a variety of security risks. Furthermore, security risks for mobile robots include not only the risks of information theft and service failures in conventional IT (Information Technology) systems, but also potential impacts on people, objects, and the environment near the robot.

[0016] When a mobile robot is attacked by cybersecurity or other threats, it is necessary to ensure the security of the mobile robot's control network, control applications, control devices, sensors, etc., as well as external devices that access the mobile robot, such as servers and terminals running client applications. Control systems are also required to guide the mobile robot to a safe state so that the mobile robot itself does not adversely affect the surrounding environment. For example, if a mobile robot detects an abnormality while moving halfway across a crosswalk, if the robot stops, it will block the roadway, disrupting the movement of cars, trucks, motorcycles, and other vehicles on the roadway and risking an accident. Furthermore, if a mobile robot detects an abnormality while moving through a corridor in a commercial building and stops, it will block the passageway, disrupting the movement of people and goods within the building. If a fire or other disaster were to occur at the same time, there is a risk of losing the safety of people and goods.

[0017] Furthermore, according to the method of Patent Document 1, if a mobile robot detects an abnormality, it can autonomously move to a safe area and stop there, but no measures are taken in the event that the system is unreliable, and there is a possibility that the control of the mobile robot may be remotely hijacked while the mobile robot is moving to the safe area, causing harm to the surrounding environment. For example, if the control of the mobile robot is remotely hijacked and the mobile robot moves into a subway entrance installed on the sidewalk, the mobile robot may fall down the stairs, or the mobile robot may be illegally remotely controlled toward a dangerous area. As such, the method of Patent Document 1 leaves room for improvement in terms of more reliably moving the mobile robot to a safe area.

[0018] Therefore, the inventors of the present application have conducted extensive research into how to more reliably stop a mobile robot in a safe area, and have devised the mobile robot described below.

[0019] A mobile robot according to a first aspect of the present disclosure is a mobile robot capable of autonomous movement, and includes a first judgment unit that judges the reliability of the autonomous movement function of the mobile robot, a first information acquisition unit that acquires information regarding a safe area where the mobile robot can stop, and a first control unit that, when an abnormality in the mobile robot is detected while the mobile robot is moving autonomously and the first judgment unit judges that the autonomous movement function is reliable, moves the mobile robot to the safe area based on the information regarding the safe area.

[0020] This allows the mobile robot to move to the safe area when the autonomous movement function is reliable, and prevents the mobile robot from moving to a location other than the safe area when its control is hijacked. Therefore, the mobile robot can move to the safe area more reliably than when it moves to the safe area when its autonomous movement function is unreliable.

[0021] Also, for example, a mobile robot according to a second aspect of the present disclosure may be the mobile robot according to the first aspect, and the first control unit may stop the mobile robot on the spot if the abnormality is detected during the autonomous movement of the mobile robot and the first judgment unit judges that the autonomous movement function is unreliable.

[0022] This makes it possible to prevent the mobile robot from causing harm to the surrounding environment, for example by remotely taking over the operation of the mobile robot.

[0023] Furthermore, for example, a mobile robot according to a third aspect of the present disclosure may be a mobile robot according to the first or second aspect, and may further include a first UI generation unit that generates a first alert UI for issuing an alert in a server communicatively connected to the mobile robot when the abnormality is detected during the autonomous movement of the mobile robot and the first judgment unit determines that the autonomous movement function is unreliable.

[0024] In this way, the first alert UI generated by the mobile robot is presented on the server, thereby notifying the remote operator of the mobile robot that the autonomous movement function is unreliable. If the remote operator who received the notification takes action to move the mobile robot to a safe area, the mobile robot may be able to move to the safe area even in a state in which the autonomous movement function is unreliable.

[0025] Furthermore, for example, a mobile robot according to a fourth aspect of the present disclosure may be the mobile robot according to any one of the first to third aspects, and further include a second UI generation unit in a server communicatively connected to the mobile robot that generates a remote control UI to be used for remotely controlling the mobile robot when the abnormality is detected during the autonomous movement of the mobile robot and the first judgment unit determines that the autonomous movement function is unreliable, and the first control unit may move the mobile robot to the safe area based on input of the remote control UI in the server.

[0026] In this way, the first remote control UI generated by the mobile robot is presented on the server, allowing the remote operator of the mobile robot to remotely control the mobile robot. When the remote operator remotely controls the mobile robot to move to the safe area, the mobile robot may be able to move to the safe area even when its autonomous movement function is unreliable.

[0027] Furthermore, for example, a mobile robot according to a fifth aspect of the present disclosure is the mobile robot according to the fourth aspect, wherein the remote control UI, in addition to using remote control, has a suspicious behavior reporting function that reports suspicious behavior when the suspicious behavior is confirmed in relation to the movement of the mobile robot, and the first control unit may stop the mobile robot on the spot when input to the suspicious behavior reporting function of the remote control UI is recognized while the mobile robot is being moved based on input to the remote control UI on the server.

[0028] This makes it possible to stop a mobile robot on the spot if the mobile robot behaves suspiciously while being remotely controlled.

[0029] Furthermore, for example, a mobile robot according to a sixth aspect of the present disclosure may be a mobile robot according to the fifth aspect, and the second UI generation unit may further generate a second alert UI for notifying the user of the suspicious behavior when input to the suspicious behavior reporting function of the remote control UI is recognized.

[0030] In this way, the second alert UI generated by the mobile robot is presented on the server, thereby notifying the remote operator of the mobile robot of the input of the suspicious behavior reporting function. By the remote operator receiving the notification, the mobile robot can be stopped on the spot, thereby preventing the mobile robot from causing harm to the surrounding environment even if the autonomous movement function becomes unreliable during movement.

[0031] Furthermore, for example, a mobile robot according to a seventh aspect of the present disclosure may be a mobile robot according to any of the first to sixth aspects, wherein the mobile robot has an autonomous movement function and a function other than the autonomous movement function, and the first judgment unit may judge that the autonomous movement function is reliable if no attack related to the autonomous movement function is detected.

[0032] This allows the mobile robot to move to a safe area if no attack on its autonomous movement function is detected.

[0033] Furthermore, for example, a mobile robot according to an eighth aspect of the present disclosure may be a mobile robot according to any one of the first to seventh aspects, and further include a first memory unit that stores a destination of the mobile robot, and the first judgment unit may judge that the autonomous movement function is reliable if no tampering with the destination is detected.

[0034] This allows the mobile robot to move to the safe area if no tampering with the destination is detected, that is, if the safe area is unlikely to be tampered with.

[0035] Also, for example, a mobile robot according to a ninth aspect of the present disclosure may be the mobile robot according to any one of the first to eighth aspects, further comprising an abnormality detection unit that detects the abnormality.

[0036] This allows the mobile robot to move to a safe area when it detects an abnormality in its own device.

[0037] In addition, a server according to a tenth aspect of the present disclosure is a server communicatively connected to an autonomously movable mobile robot, and includes a second judgment unit that judges the reliability of the autonomous movement function of the mobile robot, a second information acquisition unit that acquires information regarding a safe area where the mobile robot can stop, and a second control unit that, when an abnormality in the mobile robot is detected while the mobile robot is moving autonomously and the second judgment unit judges that the autonomous movement function is reliable, moves the mobile robot to the safe area based on the information regarding the safe area.

[0038] This allows the mobile robot to move to the safe area when the autonomous movement function is reliable, thereby preventing the mobile robot from moving to a location other than the safe area when its control is hijacked. Thus, the server can move the mobile robot to the safe area more reliably than when the autonomous movement function is unreliable.

[0039] Also, for example, a server according to an eleventh aspect of the present disclosure may be the server according to the tenth aspect, and the second control unit may stop the mobile robot on the spot if the abnormality is detected during the autonomous movement of the mobile robot and the second judgment unit determines that the autonomous movement function is unreliable.

[0040] This makes it possible to prevent the mobile robot from causing harm to the surrounding environment, for example by remotely taking over the operation of the mobile robot.

[0041] Furthermore, for example, a server according to a twelfth aspect of the present disclosure may be a server according to the tenth or eleventh aspect, and may further include a third UI generation unit that generates a third alert UI for notifying an alert when the abnormality is detected during the autonomous movement of the mobile robot and the second judgment unit determines that the autonomous movement function is unreliable.

[0042] Thus, by presenting the first alert UI, it is possible to notify the remote operator of the mobile robot that the autonomous movement function is unreliable. If the remote operator who has received the notification takes action to move the mobile robot to a safe area, it may be possible to move the mobile robot to a safe area even when the autonomous movement function is unreliable.

[0043] Furthermore, for example, a server according to a thirteenth aspect of the present disclosure may be a server according to any of the tenth to twelfth aspects, further including a fourth UI generation unit that generates a remote control UI to be used for remotely controlling the mobile robot when the abnormality is detected during the autonomous movement of the mobile robot and the second judgment unit determines that the autonomous movement function is unreliable, and the second control unit may move the mobile robot to the safe area based on input from the remote control UI.

[0044] Thus, by presenting the first remote control UI, the remote operator of the mobile robot can remotely control the mobile robot. When a remote control input for moving to a safe area is received from the remote operator, it may be possible to move the mobile robot to the safe area even when the autonomous movement function is unreliable.

[0045] Furthermore, for example, a server according to a fourteenth aspect of the present disclosure is a server according to the thirteenth aspect, wherein the remote control UI, in addition to using remote control, has a suspicious behavior reporting function that reports suspicious behavior when the suspicious behavior is confirmed regarding the movement of the mobile robot, and the second control unit may stop the mobile robot on the spot when input to the suspicious behavior reporting function of the remote control UI is recognized while the mobile robot is being moved based on input from the remote control UI.

[0046] This makes it possible to stop a mobile robot on the spot if the mobile robot behaves suspiciously while being remotely controlled.

[0047] Also, for example, a server according to a fifteenth aspect of the present disclosure may be a server according to the fourteenth aspect, and the fourth UI generation unit may further generate a fourth alert UI for notifying of the suspicious behavior when input to the suspicious behavior reporting function of the remote control UI is recognized.

[0048] As a result, the fourth alert UI is presented to notify the remote operator of the mobile robot of the input of the suspicious behavior reporting function. The remote operator who receives the notification can stop the mobile robot on the spot, thereby preventing the mobile robot from causing harm to the surrounding environment even if the autonomous movement function becomes unreliable while moving.

[0049] Furthermore, for example, a server according to a sixteenth aspect of the present disclosure may be a server according to any of the tenth to fifteenth aspects, wherein the mobile robot has an autonomous movement function and a function other than the autonomous movement function, and the second judgment unit may judge that the autonomous movement function is unreliable if no attack related to the autonomous movement function is detected.

[0050] This allows the server to move the mobile robot to a safe area if no attack on the autonomous movement function is detected.

[0051] Also, for example, a server according to a seventeenth aspect of the present disclosure may be a server according to any of the tenth to sixteenth aspects, and further include a second memory unit that stores a destination of the mobile robot, and the second judgment unit may judge that the autonomous movement function is reliable if no tampering with the destination is detected.

[0052] This allows the server to move the mobile robot to the safe area if no tampering with the destination is detected, that is, if the safe area is unlikely to be tampered with.

[0053] Also, for example, a server according to an eighteenth aspect of the present disclosure may be a server according to any one of the tenth to seventeenth aspects, further comprising an anomaly detection unit that detects the anomaly.

[0054] This allows the server to move the mobile robot to a safe area when it detects an abnormality.

[0055] A mobile robot control system according to a nineteenth aspect of the present disclosure is a mobile robot control system including a mobile robot capable of autonomous movement and a server communicatively connected to the mobile robot, the system including: a determination unit that determines reliability of the autonomous movement function of the mobile robot; an information acquisition unit that acquires information about a safe area where the mobile robot can stop; and a control unit that, if an abnormality of the mobile robot is detected during the autonomous movement of the mobile robot and the determination unit determines that the autonomous movement function is reliable, moves the mobile robot to the safe area based on the information about the safe area. A mobile robot control method according to a twentieth aspect of the present disclosure is a mobile robot control method for controlling a mobile robot capable of autonomous movement, the system including: if an abnormality of the mobile robot is detected during the autonomous movement of the mobile robot and the determination unit determines that the autonomous movement function of the mobile robot is reliable, moves the mobile robot to the safe area based on information about the safe area where the mobile robot can stop.

[0056] This provides the same effect as the mobile robot or server described above.

[0057] These general or specific aspects may be realized as a system, a method, an integrated circuit, a computer program, or a non-transitory recording medium such as a computer-readable CD-ROM, or as any combination of the system, method, integrated circuit, computer program, or recording medium. The program may be pre-stored in the recording medium, or may be supplied to the recording medium via a wide area communication network including the Internet.

[0058] Mobile robots and the like according to embodiments of the present disclosure will be described below with reference to the drawings. Each of the embodiments described below represents a preferred specific example of the present disclosure. In other words, the numerical values, shapes, materials, components, component arrangements and connection configurations, steps, and step order shown in the following embodiments are examples of the present disclosure and are not intended to limit the present disclosure. The present disclosure is defined by the claims. Therefore, among the components in the following embodiments, components not recited in the independent claims that represent the superordinate concept of the present disclosure are not necessarily required to achieve the objectives of the present disclosure, but are described as components that constitute more preferred embodiments.

[0059] Furthermore, each figure is a schematic diagram and is not necessarily an exact illustration. Therefore, for example, the scales of the figures do not necessarily match. Furthermore, in each figure, substantially the same components are given the same reference numerals, and redundant explanations are omitted or simplified.

[0060] Furthermore, in this specification, numerical values ​​and numerical ranges are not expressions that express only the strict meaning, but are expressions that mean that they also include a substantially equivalent range, for example, a difference of about several percent (or about 10%).

[0061] Furthermore, in this specification, ordinal numbers such as "first" and "second" do not refer to the number or order of components unless otherwise specified, but are used for the purpose of avoiding confusion and distinguishing between components of the same type.

[0062] (Embodiments) Hereinafter, a mobile robot control method, etc., including a method for identifying a safe area in a mobile robot and a method for moving the mobile robot to the safe area when the system is unreliable, will be described. Also, for example, below, a mobile robot, etc., will be described that stops the mobile robot in a safe place when a security abnormality is detected in a mobile robot control system.

[0063] [1 Overall Configuration of Mobile Robot Control System 1] FIG. 1 is a diagram showing the overall configuration of a mobile robot control system 1 according to an embodiment.

[0064] 1, the mobile robot control system 1 is an information processing system for monitoring mobile robots 100a, 100b, and 100c, and includes the mobile robots 100a, 100b, and 100c, a network 200, a management server 300, a monitoring server 400, and a remote control terminal 500. Because the mobile robots 100a, 100b, and 100c have the same configuration, they will hereinafter be referred to collectively as the mobile robot 100. The management server 300, the monitoring server 400, and the remote control terminal 500 are external to the mobile robot 100 and are located remotely from the mobile robot 100.

[0065] The mobile robot 100 is an autonomously mobile body, and may be, but is not limited to, a robot or vehicle capable of autonomous travel, or an air vehicle capable of autonomous flight (e.g., a drone). The mobile robot 100 may be capable of performing a predetermined service. Examples of the predetermined service include, but are not limited to, a home delivery service, a collection and delivery service, and a people transportation service. The mobile robot 100 may also be capable of traveling on roads or sidewalks.

[0066] The mobile robot 100 notifies the management server 300 and the monitoring server 400 of the robot status, such as the control status, position information, and security alerts of the mobile robot 100, via the network 200. The number of mobile robots 100 provided in the mobile robot control system 1 is not limited to three, but may be one or more. Furthermore, the mobile robots 100 provided in the mobile robot control system 1 may include multiple types of mobile objects (e.g., robots, vehicles, aircraft, etc.).

[0067] The network 200 may include the Internet or a dedicated line. The network 200 connects the mobile robot 100, the management server 300, the monitoring server 400, and the remote control terminal 500 so that they can communicate with each other. The communication method between the mobile robot 100, the management server 300, the monitoring server 400, and the remote control terminal 500 is not particularly limited, and may be wireless communication or wired communication. Furthermore, wireless communication and wired communication may be combined between the devices.

[0068] The management server 300 receives the robot status of the mobile robot 100 from the mobile robot 100 and provides an interface to the remote operator of the mobile robot 100 for managing whether the mobile robot 100 is operating properly. When the mobile robot 100 requires remote control, the management server 300 generates a remote control UI (UI stands for user interface) used for remote control and transmits the remote control UI to the remote control terminal 500 via the network 200. The remote operator corresponds to the remote operator described above and remotely monitors the mobile robot 100 and remotely controls (operates) it as necessary.

[0069] The monitoring server 400 is a server that mainly monitors whether a security incident has occurred in the mobile robot 100, and provides an interface for receiving security alerts from the mobile robot 100 and analyzing and responding to the security operation center or the security incident response team. The monitoring server 400 may provide the interface for analysis and response to the remote control terminal 500, for example.

[0070] The remote control terminal 500 displays the received remote control UI on a monitor or the like, receives instructions from the remote operator from the remote control UI, and transmits the remote control instructions to the mobile robot 100 via the network 200 and the management server 300, thereby remotely controlling the mobile robot 100. Note that the remote control terminal 500 may transmit the remote control instructions directly to the mobile robot 100 without going through the management server 300.

[0071] [2. Configuration of Mobile Robot 100] FIG. 2 is a block diagram showing the functional configuration of the mobile robot 100 according to the embodiment.

[0072] 2 , the mobile robot 100 includes a control unit 110, a communication unit 112, a memory unit 116, an external sensor 132, a self-position estimation unit 134, a drive unit 138, an obstacle detection unit 136, a detection unit 150, a safe area acquisition unit 154, and a reliability determination unit 156. The unit including the external sensor 132, the self-position estimation unit 134, the obstacle detection unit 136, and the drive unit 138 is also referred to as an autonomous driving function 130 (autonomous driving function unit) that enables the mobile robot 100 to drive autonomously. The autonomous driving function 130 is an example of an autonomous movement function. The mobile robot 100 includes a CPU (Central Processing Unit), memory, etc., and the CPU executes programs stored in the memory to realize each function of the mobile robot 100.

[0073] The control unit 110 is a control device that controls each component of the mobile robot 100, and specifically, relays communications between and controls the autonomous driving function 130, the communication unit 112, the memory unit 116, the detection unit 150, and the safe area acquisition unit 154. Furthermore, if an abnormality in the mobile robot 100 is detected while the mobile robot 100 is autonomously driving, or if an abnormality in the mobile robot 100 is detected and the reliability determination unit 156 determines that the autonomous driving function 130 is reliable, the control unit 110 may control the drive unit 138 to move the mobile robot 100 to the safe area based on information about the safe area. Furthermore, if an abnormality in the mobile robot 100 is detected while the mobile robot 100 is autonomously traveling and the safe area acquisition unit 154 is unable to acquire information regarding the safe area, or if an abnormality in the mobile robot 100 is detected and the reliability determination unit 156 determines that the autonomous traveling function 130 is unreliable, the control unit 110 may control the drive unit 138 to stop the mobile robot 100 on the spot. The control unit 110 is an example of a first control unit.

[0074] The communication unit 112 mainly communicates with the management server 300 and the monitoring server 400. The communication unit 112 communicates data with the management server 300 and the monitoring server 400 via the network 200. The communication unit 112 is configured to include a communication circuit (communication module).

[0075] The storage unit 116 stores destination information indicating the destination of the mobile robot 100, map information of an area including the destination of the mobile robot 100, etc. The storage unit 116 is realized by, for example, but is not limited to, a semiconductor memory. The storage unit 116 is an example of a first storage unit.

[0076] The external sensor 132 acquires surrounding information including the state of the surroundings of the mobile robot 100. The external sensor 132 is, for example, a camera (e.g., a visible light camera), a laser range finder, a GPS sensor, etc. The visible light camera acquires surrounding video of the mobile robot 100. The laser range finder acquires point cloud information of the surroundings of the mobile robot 100, etc. The GPS sensor acquires location information including the current latitude, longitude, and altitude of the mobile robot 100. In addition, surrounding video from the visible light camera and point cloud information from the laser range finder may be analyzed using AI or the like to acquire object information about people, motorcycles, automobiles, and other objects present around the mobile robot 100, or generate three-dimensional information about the surrounding structure and add it to the surrounding information.

[0077] In this way, the surrounding information may include sensor information acquired by a sensor mounted on the mobile robot 100 or current position information of the mobile robot 100, or may include video information acquired by a camera mounted on the mobile robot 100. The surrounding information may also include map information previously stored in the management server 300. The surrounding information may also include objects around the mobile robot 100, the condition of the road on which the mobile robot 100 is moving, etc.

[0078] The self-position estimation unit 134 analyzes position information and the like in the external world information acquired by the external world sensor 132 to estimate the current position of the mobile robot 100. The current position may be a relative position or an absolute position.

[0079] The obstacle detection unit 136 identifies and detects obstacles that may hinder driving by analyzing external information (e.g., object information) acquired by the external sensor 132. For example, the obstacle detection unit 136 may identify an object that exists on a driving path during autonomous driving as an obstacle.

[0080] The drive unit 138 analyzes the current position estimated by the self-position estimation unit 134 and the obstacles detected by the obstacle detection unit 136, and actually operates propulsion functions such as wheels and propellers to move the mobile robot 100. At this time, the drive unit 138 moves the mobile robot 100 along a route to the destination, and if it determines that an obstacle exists on the route, it controls the robot to drive in a way that avoids the obstacle and ultimately arrives at the destination. For actual driving, in addition to propulsion functions such as tires and propellers and a steering system, electrical power such as a motor and a storage battery, engine-related power such as an engine and a fuel tank, etc. are required, but a detailed description of the drive will be omitted as it is not the essence of this disclosure.

[0081] The detection unit 150 monitors the entire interior of the mobile robot 100 to check for any cyberattacks against the mobile robot 100, and if a cyberattack is detected, transmits the attack information to the monitoring server 400 via the network 200. It can also be said that the detection unit 150 determines whether or not a cyberattack against the mobile robot 100 has occurred, and if it determines that a cyberattack has occurred, transmits the attack information to the monitoring server 400 via the network 200. The attack information includes, for example, information indicating the presence of a cyberattack and whether the cyberattack was detected inside or outside the autonomous driving function 130. The detection unit 150 is an example of an anomaly detection unit. Note that any known technology may be used as the method by which the detection unit 150 determines whether or not a cyberattack has occurred.

[0082] The safe area acquisition unit 154 acquires information about the safe area closest to the current location. For example, when the detection unit 150 detects an abnormality in the mobile robot 100 while the mobile robot 100 is autonomously traveling, the safe area acquisition unit 154 acquires information about a safe area that is identified based on the situation around the mobile robot 100 and in which the mobile robot 100 can stop (e.g., make an emergency stop). The situation around the mobile robot 100 may be any information that allows acquisition of information about the safe area, and may be the situation around the mobile robot 100 when an abnormality is detected, or the situation around the mobile robot 100 when no abnormality is detected (e.g., before an abnormality is detected). The safe area may be an area in which the mobile robot 100 does not adversely affect the surrounding environment and the safety of the mobile robot 100 is ensured, or may be an area in which the mobile robot 100 can stop safely (e.g., make an emergency stop). The safe area acquisition unit 154 is an example of a first information acquisition unit.

[0083] The reliability determination unit 156 determines whether the mobile robot 100 and the autonomous driving function 130 are in a reliable state for movement (e.g., driving) based on the attack information acquired by the detection unit 150 or the destination information stored in the memory unit 116. The reliability determination unit 156 determines, for example, the reliability of the autonomous driving function 130 of the mobile robot 100. If the attack information includes information indicating the presence of a cyberattack on the autonomous driving function 130, the reliability determination unit 156 determines that the autonomous driving function 130 is in an unreliable state for movement, and if the attack information includes information indicating the presence of a cyberattack on another function (another functional unit) other than the autonomous driving function 130, the reliability determination unit 156 determines that the autonomous driving function 130 is in a reliable state for movement. In this way, the reliability determination unit 156 may determine that the autonomous driving function 130 is unreliable when an attack on the autonomous driving function 130 is detected.

[0084] Furthermore, the reliability determination unit 156 may determine whether the autonomous driving function 130 is reliable depending on whether tampering of the destination information is detected. If tampering of the destination indicated by the destination information is detected, the reliability determination unit 156 may determine that the autonomous driving function 130 is unreliable, and if tampering of the destination is not detected, the reliability determination unit 156 may determine that the autonomous driving function 130 is reliable. The reliability determination unit 156 is an example of a first determination unit.

[0085] [3. Configuration of Management Server 300] FIG. 3 is a block diagram showing the functional configuration of the management server 300 according to the embodiment.

[0086] 3, the management server 300 includes a control unit 310, a communication unit 312, a storage unit 314, a robot management unit 320, and a UI generation unit 330. The management server 300 includes a CPU, memory, etc., and the CPU executes programs stored in the memory to realize the various functions of the management server 300.

[0087] The control unit 310 is a control device that controls each component of the management server 300 , and specifically controls the communication unit 312 , the storage unit 314 , the robot management unit 320 , and the UI generation unit 330 .

[0088] The communication unit 312 mainly communicates with the mobile robot 100 and the remote control terminal 500. For example, the communication unit 312 transmits robot management information from the robot management unit 320 to the mobile robot 100, and transmits various UIs generated by the UI generation unit 330 to the remote control terminal 500 via the network 200. The communication unit 312 is configured to include a communication circuit (communication module).

[0089] The storage unit 314 stores various UIs generated by the UI generation unit 330. The storage unit 314 is realized by, for example, a semiconductor memory, but is not limited to this.

[0090] The robot manager 320 manages control information for the mobile robot 100. The control information includes, for example, commands for operating the mobile robot 100.

[0091] The UI generation unit 330 generates various UIs. For example, when an abnormality is detected during the autonomous traveling of the mobile robot 100 and the safe area acquisition unit 154 fails to acquire information about the safe area, or the reliability determination unit 156 determines that the autonomous traveling function 130 is unreliable, the UI generation unit 330 may generate an alert UI (an example of a third alert UI) for issuing an alert on a server (e.g., the management server 300) communicatively connected to the mobile robot 100. The UIs generated by the UI generation unit 330 will be described later. The UI generation unit 330 is an example of a third UI generation unit.

[0092] [4. Configuration of Monitoring Server 400] FIG. 4 is a block diagram showing the functional configuration of the monitoring server 400 according to the embodiment.

[0093] 4, the monitoring server 400 includes a control unit 410, a communication unit 412, a storage unit 414, an analysis unit 416, and a UI generation unit 418. The monitoring server 400 includes a CPU, a memory, and the like, and the functions of the monitoring server 400 are realized by the CPU executing programs stored in the memory.

[0094] The control unit 410 is a control device that controls each component of the monitoring server 400 , and specifically controls a communication unit 412 , a storage unit 414 , an analysis unit 416 , and a UI generation unit 418 .

[0095] The communication unit 412 mainly communicates with the remote control terminal 500. For example, the communication unit 412 transmits various UIs generated by the UI generation unit 418 to the remote control terminal 500 via the network 200. The communication unit 412 is configured to include a communication circuit (communication module).

[0096] The storage unit 414 stores various UIs generated by the UI generation unit 418 and log information of the mobile robot 100 received by the communication unit 412. The log information includes the control state of the mobile robot 100, position information, and robot status such as security alerts. The storage unit 314 is realized by, for example, but is not limited to, a semiconductor memory.

[0097] The analysis unit 416 analyzes the log information of the mobile robot 100 stored in the memory unit 414 to detect abnormalities in the mobile robot 100. The analysis unit 416 analyzes the log information from each of the mobile robots 100a to 100c to detect abnormalities in each of the mobile robots 100a to 100c.

[0098] The UI generation unit 418 generates various UIs.

[0099] 5 is a block diagram showing the functional configuration of the remote control terminal 500 according to the embodiment. The remote control terminal 500 may be a stationary device such as a personal computer (PC), or may be a portable device such as a smartphone.

[0100] 5, the remote control terminal 500 has a control unit 510, a communication unit 512, a presentation unit 514, an input unit 516, and a storage unit 518. The remote control terminal 500 has a CPU, a memory, etc., and the CPU executes a program stored in the memory to realize each function of the remote control terminal 500.

[0101] The control unit 510 is a control device that controls each component of the remote control terminal 500 , and specifically controls the communication unit 512 , the presentation unit 514 , the input unit 516 , and the storage unit 518 .

[0102] The communication unit 512 mainly includes a communication circuit (communication module) for communicating with the management server 300 and the monitoring server 400 .

[0103] The presentation unit 514 presents various UIs received from the management server 300 or the monitoring server 400. The presentation unit 514 includes a display panel such as a liquid crystal panel, for example.

[0104] The input unit 516 accepts input (operation) from the remote operator. For example, the input unit 516 accepts input corresponding to the UI presented by the presentation unit 514. The input unit 516 is realized by a joystick, a touch panel that accepts touch operations, a sound collection device that accepts voice input, an imaging device that accepts input by gestures, etc.

[0105] The storage unit 518 stores various UIs and the like received from the management server 300 or the monitoring server 400. The storage unit 518 is realized by, for example, a semiconductor memory, but is not limited to this.

[0106] 6 is a sequence diagram showing the operation of the mobile robot control system 1 (a method for controlling a mobile robot) when the mobile robot 100 autonomously travels according to an embodiment. Specifically, FIG. 6 is a sequence diagram showing the operation of the mobile robot control system 1 when the mobile robot 100 autonomously travels to a destination.

[0107] (S100) The management server 300 transmits the destination information (destination) stored in the memory unit 314 to the mobile robot 100 via the communication unit 312.

[0108] (S110) The mobile robot 100 receives destination information from the management server 300 via the communication unit 112, and moves the mobile robot 100 based on the destination received by the drive unit 138 and the self-position estimated by the self-position estimation unit 134.

[0109] (S120) When the mobile robot 100 arrives at its destination, the mobile robot 100 stops (normally stops) and notifies the management server 300 that it has arrived. The mobile robot 100 then performs post-processing appropriate to the service. For example, if the service is a delivery service that delivers bread from a bakery to an end user's home, the mobile robot 100 notifies the end user of the arrival of the mobile robot 100. When the end user leaves the home and approaches the mobile robot 100, the mobile robot 100 notifies the end user of the unlock code for the cargo compartment of the mobile robot 100. When the end user enters the unlock code into the unlock code input unit for the cargo compartment, opens the door of the cargo compartment, removes the bread, and closes the door of the cargo compartment, the mobile robot 100 sends a thank-you message to the end user, notifies the management server 300 that it has received the delivery, and begins moving toward its base. When the mobile robot 100 arrives at its base, the series of delivery services is completed.

[0110] [7 Remotely Controlled Travel Sequence] Figure 7 is a sequence diagram showing the operation of the mobile robot control system 1 (mobile robot control method) when remotely controlled traveling according to an embodiment is performed. Using Figure 7, a case will be described in which the mobile robot 100 switches from autonomous traveling to remotely controlled traveling while traveling autonomously to a destination. For example, if a planned route to a destination includes a crosswalk, and the mobile robot 100 arrives before the crosswalk while traveling autonomously, it may ask the remote controller to determine whether to cross the crosswalk. In this case, the remote controller determines whether to cross the crosswalk based on confirmation of whether the traffic light is green, whether crossing is possible, whether there are any obstacles on the crosswalk, and the status of cars, motorcycles, etc. traveling on the road and approaching the crosswalk.

[0111] It is also possible for the management server 300 or the obstacle detection unit 136 of the mobile robot 100 to automatically perform crossing judgment by analyzing the video of the mobile robot 100's surroundings. On the other hand, depending on the performance and resolution of the sensor, it may be necessary to ask the remote operator for judgment. When the crossing judgment is performed and it is determined that crossing is possible, the mobile robot 100 may return to autonomous driving and move across the crosswalk autonomously, or it may move across the crosswalk while still being remotely controlled. It is also possible that there may be cases where the remote operator is required to make the crossing judgment and move across the crosswalk by remote control due to laws and regulations.

[0112] The sequence of remotely controlled traveling will be described below. Note that, in the following, operations similar to those shown in Fig. 6 are denoted by the same reference numerals as in Fig. 6, and descriptions thereof will be omitted or simplified.

[0113] (S100) This has been explained in the previous section, so it will not be explained here.

[0114] (S110) This has been explained in the previous section, so it will not be explained here.

[0115] (S200) When the mobile robot 100 reaches a state requiring remote control while autonomously traveling, the control unit 110 of the mobile robot 100 detects that remote control is necessary. The control unit 110 determines whether remote control and traveling are necessary based on, for example, the current position, surrounding information acquired by the external sensor 132, and the self-position estimated by the self-position estimation unit 134. If the control unit 110 determines that remote control is necessary, the mobile robot 100 stops autonomous traveling and stops on the spot or reduces its traveling speed (slows down). Furthermore, the control unit 110 requests remote control from the management server 300. Note that, although the mobile robot 100 determines the need for remote control, the management server 300 may also be configured to make the determination.

[0116] (S210) When the robot management unit 320 of the management server 300 receives a remote control request from the mobile robot 100 via the communication unit 312, the UI generation unit 330 generates a first remote control UI. The first remote control UI may be, for example, a UI that displays an image of the area around the crosswalk and has a button for confirming whether or not it is possible to cross the crosswalk.

[0117] FIG. 8 is a diagram illustrating an example of a first remote control UI according to an embodiment. Reference numeral U100 denotes the entire UI area displayed on the monitor. Reference numeral U110 denotes a first display area that displays an image in front of the mobile robot 100. The external sensor 132 of the mobile robot 100 receives an image from a visible light camera or the like and displays it in the first display area U110, allowing the remote operator to check the surroundings of the mobile robot 100. Reference numeral U112 denotes an area that displays an image to the left of the mobile robot 100. Reference numeral U114 denotes an area that displays an image to the right of the mobile robot 100. Reference numeral U116 denotes an area that displays an image behind the mobile robot 100. The second display area U112, the third display area U114, and the fourth display area U116 are implemented, similarly to the first display area U110, through cooperation with the external sensor 132 of the mobile robot 100. It should be noted that "forward" refers to, for example, the direction in which the mobile robot 100 moves, and "backward" refers to, for example, the direction opposite to the direction in which the mobile robot 100 moves.

[0118] The first button U120 is a button for instructing the mobile robot 100 to move forward. Similarly, the second button U122 is a button for instructing backward movement, the third button U124 is a button for instructing leftward movement, and the fourth button U126 is a button for instructing rightward movement. The remote operator can remotely control the mobile robot 100 by pressing these buttons. Note that although these buttons for remote control instructions are arranged on the screen of the entire UI area U100, remote control instructions may be given not on the screen of the entire UI area U100 but on a different device connected to the remote control terminal 500. For example, a video game controller, an operating device for a flight simulator, or the like can be used as a device for remote control.

[0119] The fifth button U130 is a button for specifying that crossing is permitted. When the mobile robot 100 is stopped in front of a crosswalk, the remote operator checks the images of the mobile robot 100 in the first display area U110, the second display area U112, the third display area U114, and the fourth display area U116, confirms that there are no dangerous situations, such as a car or motorcycle approaching from a distance, and presses the fifth button U130 if they determine that there are no safety issues. This allows the mobile robot 100 to move. In this case, the mobile robot 100 may continue moving by remote control, or the remote control may be terminated and the mobile robot 100 may move autonomously.

[0120] Referring again to FIG. 7, the description continues.

[0121] (S220) When the remote control terminal 500 receives the first remote control UI from the management server 300, it displays the first remote control UI on the presentation unit 514 (e.g., a monitor) and asks the remote controller for a decision. When the remote controller uses the first remote control UI to input that it is possible to cross the crosswalk (e.g., the remote controller operates the fifth button U130), the remote control terminal 500 transmits a remote control instruction, in this case a notification that it is possible to cross the crosswalk, to the mobile robot 100.

[0122] (S230) When the mobile robot 100 receives a remote control instruction from the remote control terminal 500, in this case a notification that crossing is possible, via the management server 300, the mobile robot 100 starts remote-controlled traveling.

[0123] (S111) When the mobile robot 100 has finished traveling across the crosswalk, it switches to autonomous traveling and resumes autonomous traveling.

[0124] (S120) This has been explained in the previous section, so it will not be explained here.

[0125] 9 is a sequence diagram showing the operation of the mobile robot control system 1 (a method for controlling a mobile robot) when an abnormality is detected according to an embodiment. Using FIG. 9, a sequence will be described in which, while the mobile robot 100 is autonomously traveling to a destination, an abnormality is detected, a safe area is identified, the reliability of the autonomous traveling function is determined, and the mobile robot 100 moves to the safe area by autonomous traveling.

[0126] (S100) This has been explained in the previous section, so it will not be explained here.

[0127] (S110) This has been explained in the previous section, so it will not be explained here.

[0128] (S300) If the detection unit 150 of the mobile robot 100 detects unauthorized access to the system of the mobile robot 100, for example, unauthorized login to an account, during autonomous driving, the mobile robot 100, for example, stops autonomous driving and stops on the spot or moves slowly. Furthermore, the detection unit 150 notifies the safe area acquisition unit 154 of an abnormal state. Note that "detecting" means that the occurrence of unauthorized access becomes apparent, for example, that the unauthorized access is detected. For example, "detecting unauthorized access" means that the occurrence of unauthorized access becomes apparent, for example, that the detection unit 150 detects unauthorized access.

[0129] (S400) The safe area acquisition unit 154 attempts to acquire information about the safe area based on the surrounding information acquired by the external sensor 132. If the information about the safe area is acquired, the reliability determination unit 156 is notified.

[0130] (S411) The reliability determination unit 156 determines whether the current position of the mobile robot 100 estimated by the self-position estimation unit 134 is within the safe area. If it is determined that the current position is within the safe area, the process proceeds to step S130 (see, for example, FIG. 17 described later). If it is determined that the current position is outside the safe area, the process proceeds to step S500.

[0131] (S500) The reliability determination unit 156 determines whether the autonomous driving function 130 is reliable for performing autonomous driving based on the autonomous driving function 130 and the abnormal state. If it is determined that the autonomous driving function 130 is reliable, the control unit 110 instructs the drive unit 138 to autonomously drive to a safe area.

[0132] (S600) The driving unit 138 moves to a safe area by autonomous driving.

[0133] (S130) When the robot moves to the safe area, post-processing is performed, such as notifying the management server 300 that an emergency stop has been made in the safe area.

[0134] 9. First Sequence for Failure to Identify Safe Area Figure 10 is a first sequence diagram showing the operation of the mobile robot control system 1 (mobile robot control method) when a safe area fails to be identified according to an embodiment. Using Figure 10, we will explain a sequence in which, if an abnormality is detected while the mobile robot 100 is autonomously traveling to a destination and the mobile robot 100 fails to identify a safe area, the management server 300 or the remote control terminal 500 identifies a safe area, and then the reliability of the autonomous traveling function 130 of the mobile robot 100 is determined and the mobile robot 100 moves to the safe area by autonomous traveling. Note that, below, operations similar to those shown in Figure 9 are denoted by the same reference numerals as in Figure 9, and descriptions thereof will be omitted or simplified.

[0135] (S100) This has been explained in the previous section, so it will not be explained here.

[0136] (S110) This has been explained in the previous section, so it will not be explained here.

[0137] (S300) This has been explained in the previous text, so it will not be explained here.

[0138] (S410) The safe area acquisition unit 154 attempts to acquire information about the safe area based on the surrounding information acquired by the external sensor 132. If the information about the safe area cannot be acquired, the safe area acquisition unit 154 notifies the management server 300 of the failure to acquire information about the safe area.

[0139] (S420) The UI generation unit 330 of the management server 300 receives the failure to acquire information regarding the safe area via the communication unit 312, generates a safe area identification UI to be used to acquire (identify) the safe area, and sends it to the remote control terminal 500.

[0140] 11 is a diagram illustrating an example of a safe area specification UI according to an embodiment of the present invention. The safe area specification UI illustrated in FIG. 11 is an example of a remote control UI used to specify information related to a safe area.

[0141] U200 is the entire UI area displayed on the monitor. The fifth display area U210 is an area that displays an image in front of the mobile robot 100. The fifth display area U210 is displayed by receiving an image from a visible light camera or the like using the external environment sensor 132 of the mobile robot 100. The fifth display area U210 is displayed by the external environment sensor 132 of the mobile robot 100. The remote operator can specify a safe area by using a pointer or the like to designate a point that can be determined to be a safe area in the image displayed in the fifth display area U210. The sixth display area U212 is an area that displays an image to the left of the mobile robot 100. The seventh display area U214 is an area that displays an image to the right of the mobile robot 100. The eighth display area U216 is an area that displays an image behind the mobile robot 100. Like the fifth display area U210, the sixth display area U212, the seventh display area U214, and the eighth display area U216 are realized by linking with the external environment sensor 132 of the mobile robot 100, for example.

[0142] The time information U220 indicates the playback time of the surrounding video. The sixth button U222 is a button for shifting the playback time of the video forward. Similarly, the seventh button U224 is a button for shifting the playback time of the video backward. A safe area is searched for by displaying the surrounding video stored in the management server 300 in the entire UI area U200. If there is no safe area in the currently displayed video, the safe area can be searched for in surrounding video from a different time by going back further in time or by shifting the playback time of the video forward or backward.

[0143] In this way, the UI generation unit 330 generates a safety area identification UI used to acquire information about the safe area based on the surrounding information of the mobile robot 100. The safety area identification UI shown in Fig. 11 is an example of an acquisition UI.

[0144] Referring again to FIG. 10, the description continues.

[0145] (S430) The presentation unit 514 of the remote control terminal 500 receives the safe area identification UI via the communication unit 512 and presents the received safe area UI to the remote operator. The input unit 516 also acquires input from the remote operator in response to the presented safe area identification UI. When a safe area is identified, information about the safe area is transmitted to the mobile robot 100.

[0146] (S411) The reliability determination unit 156 determines whether the current position of the mobile robot 100 estimated by the self-position estimation unit 134 is within the safe area. If the reliability determination unit 156 determines that the current position is within the safe area, the process proceeds to step S130 (see FIG. 17 described later). On the other hand, if the reliability determination unit 156 determines that the current position is outside the safe area, the process proceeds to step S500.

[0147] (S500) This has been explained in the previous text, so it will not be repeated here.

[0148] (S600) This has been explained in the previous text, so it will not be explained here.

[0149] (S130) This has been explained in the previous section, so it will not be explained here.

[0150] 12 is a second sequence diagram showing the operation of the mobile robot control system 1 (mobile robot control method) when a safe area has not been identified according to the embodiment. Using FIG. 12 , a sequence will be described in which, if an abnormality is detected while the mobile robot 100 is autonomously traveling to a destination and the mobile robot 100 fails to identify a safe area, the management server 300 or the remote control terminal 500 also fails to identify a safe area, and the mobile robot 100 searches for a safe area and moves to the safe area by remote-controlled traveling.

[0151] (S100) This has been explained in the previous section, so it will not be explained here.

[0152] (S110) This has been explained in the previous section, so it will not be explained here.

[0153] (S300) This has been explained in the previous text, so it will not be explained here.

[0154] (S410) This has been explained in the previous section, so it will not be explained here.

[0155] (S420) This has been explained in the previous text, so it will not be explained here.

[0156] (S431) The presentation unit 514 of the remote control terminal 500 receives the safe area identification UI via the communication unit 512 and presents the received safe area UI to the remote operator. The input unit 516 also acquires input for the safe area identification UI from the remote operator. If the safe area identification fails, the control unit 510 notifies the management server 300 of information indicating the failure to acquire the safe area.

[0157] (S440) The UI generation unit 330 of the management server 300 receives the failure to obtain a safe area via the communication unit 312, generates a second remote control UI for searching for a safe area while driving by remote control, and sends it to the remote control terminal 500.

[0158] FIG. 13 is a diagram illustrating an example of a second remote-control UI according to an embodiment. U300 is the entire UI area displayed on the monitor. A ninth display area U310 is an area displaying an image in front of the mobile robot 100. The external sensor 132 of the mobile robot 100 receives an image from a visible light camera or the like and displays it in the ninth display area U310, allowing the remote operator to check the surroundings of the mobile robot 100. A tenth display area U312 is an area displaying an image to the left of the mobile robot 100. An eleventh display area U314 is an area displaying an image to the right of the mobile robot 100. A twelfth display area U316 is an area displaying an image behind the mobile robot 100. Like the ninth display area U310, the tenth display area U312, the eleventh display area U314, and the twelfth display area U316 are realized by linking with the external sensor 132 of the mobile robot 100.

[0159] The eighth button U320 is a button for instructing the mobile robot 100 to move forward. Similarly, the ninth button U322 is a button for instructing backward movement, the tenth button U324 is a button for instructing leftward movement, and the eleventh button U326 is a button for instructing rightward movement. The remote operator can remotely control the mobile robot 100 by pressing these buttons. Note that although these buttons for remote control instructions are arranged on the screen of the entire UI area U300, remote control instructions may be given not on the screen of the entire UI area U300 but on a different device connected to the remote control terminal 500. For example, a video game controller, a flight simulator operating device, or the like can be used as a remote control device.

[0160] The twelfth button U330 is a button for issuing an instruction to switch to autonomous driving. The remote operator checks the images of the front, back, left, and right of the mobile robot 100 using the eighth button U320, the ninth button U322, the tenth button U324, and the eleventh button U326, identifies a safe area, and then presses the twelfth button U330, which causes the mobile robot 100 to switch to autonomous driving and begin moving.

[0161] The thirteenth button U340 is a button for notifying an abnormal state. The remote operator compares inputs from the eighth button U320, the ninth button U322, the tenth button U324, and the eleventh button U326, with the information about the surroundings of the mobile robot 100 in the ninth display area U310, the tenth display area U312, the eleventh display area U314, and the twelfth display area U316, and if the remote operator recognizes an abnormal state, the remote operator notifies the management server 300 and the mobile robot 100 of the abnormal state by pressing the thirteenth button U340.

[0162] In addition to remote control, the second remote control UI may also have a suspicious behavior reporting function (e.g., a thirteenth button U340) that reports suspicious behavior when it is detected during the movement of the mobile robot 100. In this case, the control unit 110 may stop the mobile robot 100 on the spot if an input from the suspicious behavior reporting function of the second remote control UI is recognized (detected) while the mobile robot 100 is being moved based on input from the second remote control UI on the server. If a suspicious behavior is detected during the movement of the mobile robot 100 (e.g., movement by remote control), for example, if unauthorized control is being performed, the mobile robot 100 may be stopped on the spot (e.g., emergency stop). Note that pressing the thirteenth button U340 that notifies of an abnormal state is an example of a recognition (detection) of an input from the suspicious behavior reporting function of the remote control UI. Related operations will be described in the explanation of FIG. 17 below.

[0163] If an input to the suspicious operation reporting function of the remote control UI is recognized, the UI generation unit 330 may further generate a fourth alert UI for notifying the remote operator of the suspicious operation. The fourth alert UI is presented to the remote operator by the presentation unit 514. The UI generation unit 330 is an example of a fourth UI generation unit.

[0164] Referring again to FIG. 12, the description continues.

[0165] (S450) The presentation unit 514 of the remote control terminal 500 receives the second remote control UI via the communication unit 512 and presents the received second remote control UI to the remote operator. The input unit 516 also acquires input for the presented second remote control UI from the remote operator. When operation information is input via the input unit 516, the control unit 510 transmits the operation information to the mobile robot 100. When information regarding the safe area information is input, the control unit 510 transmits the information regarding the safe area information to the mobile robot 100.

[0166] (S460) When the driving unit 138 of the mobile robot 100 receives the operation information from the remote control terminal 500, it moves the mobile robot 100 in accordance with the operation information. It can also be said that the control unit 110 controls the driving unit 138 to move the mobile robot 100 based on the information input to the remote control UI in the server. Note that even during this movement, the second remote control UI receives and updates external sensor information, etc., allowing the remote operator to visually confirm the environment around the mobile robot 100 in real time.

[0167] Furthermore, when the safe area acquisition unit 154 receives information about the safe area based on information input to the remote-control UI, the mobile robot 100 may continue traveling by remote control or may switch to autonomous traveling. Fig. 12 shows a flow for continuing traveling by remote control, but when switching to autonomous traveling, the reception of operation information may be stopped and the driving unit 138 may travel autonomously with the safe area as the destination.

[0168] (S130) This has been explained in the previous section, so it will not be explained here.

[0169] 14 is a first sequence diagram showing the operation of the mobile robot control system 1 (a method for controlling a mobile robot) when the reliability of the autonomous traveling function is NG according to an embodiment. Using FIG. 14 , a sequence will be described in which an abnormality is detected while the mobile robot 100 is traveling autonomously to a destination, a safe area is identified, and if the reliability of the autonomous traveling function is judged to be unreliable, the mobile robot 100 stops on the spot.

[0170] (S100) This has been explained in the previous section, so it will not be explained here.

[0171] (S110) This has been explained in the previous section, so it will not be explained here.

[0172] (S300) This has been explained in the previous text, so it will not be explained here.

[0173] (S400) This has been explained in the previous text, so it will not be explained here.

[0174] (S411) The reliability determination unit 156 determines whether the current position of the mobile robot 100 estimated by the self-position estimation unit 134 is within the safe area. If the reliability determination unit 156 determines that the current position is within the safe area, the process proceeds to step S130 (see FIG. 17 described later). On the other hand, if the reliability determination unit 156 determines that the current position is outside the safe area, the process proceeds to step S510.

[0175] (S510) The reliability determination unit 156 determines whether the autonomous driving function 130 is reliable for performing autonomous driving based on the abnormal state of the autonomous driving function 130. If the reliability determination unit 156 determines that the abnormal state may affect the autonomous driving function 130 and that the autonomous driving function 130 is unreliable, the process proceeds to step S140.

[0176] (S140) Unable to move to a safe area, the mobile robot 100 stops on the spot. The mobile robot 100 notifies the management server 300 of the emergency stop failure. The management server 300 generates an emergency stop failure notification UI and transmits it to the remote control terminal 500. The remote control terminal 500 presents the emergency stop failure notification UI. Generally, the emergency stop failure notification UI includes an alert indicating an emergency situation and a display of contact means for on-call service or a contact function.

[0177] This allows a rushing worker (operator) to arrive shortly at the mobile robot 100 stopped in the unsafe area and transport it, thereby avoiding a dangerous situation.

[0178] FIG. 15 is a diagram showing an example of an emergency stop failure notification UI according to an embodiment. U400 is the entire UI area displayed on the monitor. The explanation area U410 is an area that explains the status of the mobile robot 100. The fourteenth button U420 is a notification button. When the fourteenth button U420 is pressed, a contracted emergency service provider or the like is automatically contacted, and a worker is dispatched from the emergency service provider waiting area nearest to the location where the mobile robot 100 is stopped to move the mobile robot 100 to a safe area. The worker transports the mobile robot 100 and moves it to a safe area. The contact area U430 displays contact information for the police and the like. The remote operator takes safety precautions for the environment around the mobile robot 100 by contacting the police and the like.

[0179] 16 is a second sequence diagram showing the operation of the mobile robot control system 1 (mobile robot control method) when the reliability of the autonomous traveling function is NG according to the embodiment. Using FIG. 16 , a sequence will be described in which, while the mobile robot 100 is traveling autonomously to a destination, an abnormality is detected, a safe area is identified, and if the reliability of the autonomous traveling function is determined to be unreliable, the management server 300 and the remote control terminal 500 search for a safe area and the mobile robot moves to the safe area by remote control.

[0180] (S100) This has been explained in the previous section, so it will not be explained here.

[0181] (S110) This has been explained in the previous section, so it will not be explained here.

[0182] (S300) This has been explained in the previous text, so it will not be explained here.

[0183] (S400) This has been explained in the previous text, so it will not be explained here.

[0184] (S411) The reliability determination unit 156 determines whether the current position of the mobile robot 100 estimated by the self-position estimation unit 134 is within the safe area. If it is determined that the current position is within the safe area, the process proceeds to step S130 (see FIG. 17 described later). If it is determined that the current position is outside the safe area, the process proceeds to step S511.

[0185] (S511) The reliability determination unit 156 determines whether the autonomous driving function 130 can be trusted to perform autonomous driving based on the abnormal state of the autonomous driving function 130, based on the detection result of the detection unit 150. If the reliability determination unit 156 determines that the abnormal state may affect the autonomous driving function 130 and that the autonomous driving function 130 is unreliable, it notifies the management server 300 that the reliability determination is NG.

[0186] (S520) When the UI generation unit 330 of the management server 300 receives a reliability judgment NG via the communication unit 312, it generates a second remote control UI for searching for a safe area while traveling by remote control and transmits it to the remote control terminal 500. In this way, if an abnormality is detected in the mobile robot 100 while the mobile robot 100 is traveling autonomously and the reliability judgment unit 156 determines that the autonomous traveling function 130 is unreliable, the UI generation unit 330 generates a second remote control UI (an example of a remote control UI) to be used for remotely controlling the mobile robot 100 in a server (e.g., the management server 300) communicatively connected to the mobile robot 100. The UI generation unit 330 functions as a third UI generation unit.

[0187] (S530) The presentation unit 514 of the remote control terminal 500 receives the second remote control UI via the communication unit 512 and presents the received second remote control UI to the remote operator. The input unit 516 also acquires input from the remote operator regarding the presented second remote control UI. When operation information is input, the control unit 510 transmits the operation information to the mobile robot 100. When information regarding safe area information is input, the control unit 510 transmits the information regarding the safe area information to the mobile robot 100.

[0188] (S540) When the driving unit 138 of the mobile robot 100 receives the operation information from the remote control terminal 500, it moves the mobile robot 100 in accordance with the operation information. It can also be said that the control unit 110 moves the mobile robot 100 to a safe area based on input from the second remote control UI in the server. Even during this movement, the second remote control UI continues to receive and update external sensor information, allowing the remote operator to visually confirm the environment surrounding the mobile robot 100 in real time.

[0189] Furthermore, when the information about the safe area is received, the mobile robot 100 may continue traveling by remote control or may switch to autonomous traveling. Fig. 16 shows the flow when continuing traveling by remote control, but when switching to autonomous traveling, the reception of the operation information may be stopped and the driving unit 138 may travel autonomously with the safe area as the destination.

[0190] (S130) This has been explained in the previous section, so it will not be explained here.

[0191] 13 Overall Flowchart of Mobile Robot 100 FIG. 17 is a flowchart showing the operation of the mobile robot 100 (a method for controlling a mobile robot) according to an embodiment.

[0192] (S110) This has been explained in the previous section, so it will not be explained here.

[0193] (S120) This has been explained in the previous section, so it will not be explained here.

[0194] (S130) This has been explained in the previous section, so it will not be explained here.

[0195] (S140) This has been explained in the previous section, so it will not be explained here.

[0196] (S300) If the detection unit 150 of the mobile robot 100 detects unauthorized access to the system of the mobile robot 100, for example, unauthorized login to an account, during autonomous driving (YES in S300), it notifies the safe area acquisition unit 154 of this as an abnormal state, and proceeds to step S400 / S410. If no abnormality is detected (NO in S300), the process proceeds to step S120, where post-processing is performed. Note that the determination in step S300 may be performed at predetermined time intervals during the autonomous driving of the mobile robot 100, and if all determinations at the predetermined time intervals are NO, the process may proceed to step S120.

[0197] (S400 / S410) The safe area acquisition unit 154 attempts to acquire information about the safe area based on the surrounding information acquired by the external sensor 132. If the safe area acquisition unit 154 is able to acquire information about the safe area (YES in S400 / S410), the process proceeds to step S411. On the other hand, if the safe area acquisition unit 154 is unable to acquire information about the safe area (NO in S400 / S410), the safe area acquisition unit 154 notifies the management server 300 of the failure to acquire information about the safe area, and the process proceeds to step S900.

[0198] (S411) The reliability determination unit 156 determines whether the current position of the mobile robot 100 estimated by the self-position estimation unit 134 is within the safe area. If the current position of the mobile robot 100 is within the safe area (YES in S411), the mobile robot 100 stops on the spot and proceeds to step S130. If the current position of the mobile robot 100 is outside the safe area (NO in S411), the process proceeds to step S500 / S510.

[0199] (S500 / S510) The reliability determination unit 156 determines whether the autonomous driving function 130 is reliable for performing autonomous driving based on the abnormal state of the autonomous driving function 130. If the reliability determination unit 156 determines that the autonomous driving function 130 is reliable (for example, in the case of step S500), the reliability determination unit 156 instructs the drive unit 138 to autonomously drive to a safe area, and the process proceeds to step S600. Also, if the reliability determination unit 156 determines that the abnormal state may affect the autonomous driving function 130 and that the autonomous driving function 130 is unreliable (for example, in the case of step S511), the reliability determination unit 156 notifies the management server 300 of a reliability determination NG, and the process proceeds to step S540.

[0200] (S540) This has been explained in the previous text, so it will not be explained here.

[0201] (S600) This has been explained in the previous text, so it will not be explained here.

[0202] (S900) When the UI generation unit 330 of the management server 300 receives a notification via the communication unit 312 that the management server 300 has failed to acquire information about the safe area, the UI generation unit 330 generates a safety area identification UI used to identify the safe area and transmits it to the remote control terminal 500. The presentation unit 514 of the remote control terminal 500 receives the safety area identification UI via the communication unit 512 and presents it on a monitor or the like. The input unit 516 also acquires input to the safety area identification UI from the remote operator. If the safe area is identified as a result (YES in S900), the UI generation unit 330 transmits information about the safe area to the mobile robot 100, and the process proceeds to step S411. On the other hand, if the management server 300 has failed to identify the safe area (NO in S900), the UI generation unit 330 notifies the management server 300 that the safe area acquisition was unsuccessful, and the process proceeds to step S540.

[0203] (S910) During remote-controlled traveling in step S540, the remote controller compares the surrounding information presented on the second remote control UI with the remote control instructions entered into the second remote control UI, and if the result indicates that there is a suspicious state in the movement of the mobile robot 100, the remote controller presses the thirteenth button U340, which notifies the mobile robot 100 of an abnormal state. When the thirteenth button U340, which notifies the mobile robot 100 of an abnormal state, is pressed (YES in S910), the second remote control UI notifies the management server 300 and the mobile robot 100 of the abnormal state, and the process proceeds to step S140. When there is no suspicious state in the movement of the mobile robot 100, the thirteenth button U340, which notifies the mobile robot 100 of an abnormal state, is not pressed (NO in S910), and the remote-controlled traveling continues.

[0204] 14. Effects of the Embodiments The mobile robot control method according to the embodiments makes it possible to analyze the cause of a security anomaly detected in a robot system based on the current control state of the robot, and to select a safe control mode, which is effective in realizing a safe robot system.

[0205] [15 Other Embodiments] At least a part of the functional configuration of the mobile robot 100 according to the above-described embodiments may be realized by the management server 300 or the monitoring server 400. Below, an example in which at least a part of the functional configuration of the mobile robot 100 is provided by the management server 300 will be described.

[0206] The control unit 310 may be capable of executing at least a part or all of the functions of the control unit 110. When the control unit 310 is capable of executing at least a part or all of the functions of the control unit 110, the control unit 310 is an example of a second control unit. Furthermore, the storage unit 314 may store at least a part or all of the information stored in the storage unit 116. When the storage unit 314 stores at least a part or all of the information stored in the storage unit 116, the storage unit 314 is an example of a second storage unit.

[0207] The management server 300 may also be capable of executing at least a part or all of the functions of the detection unit 150. A processing unit provided in the management server 300 and capable of executing at least a part or all of the functions of the detection unit 150 is an example of an anomaly detection unit. The management server 300 may also be capable of executing at least a part or all of the functions of the safety area acquisition unit 154. A processing unit provided in the management server 300 and capable of executing at least a part or all of the functions of the safety area acquisition unit 154 is an example of a second information acquisition unit. The management server 300 may also be capable of executing at least a part or all of the functions of the reliability determination unit 156. A processing unit provided in the management server 300 and capable of executing at least a part or all of the functions of the reliability determination unit 156 is an example of a second determination unit.

[0208] For example, when an abnormality in the mobile robot 100 is detected while the mobile robot 100 is autonomously traveling, or when an abnormality in the mobile robot 100 is detected and the second determination unit determines that the autonomous traveling function 130 is reliable, the control unit 310 functioning as the second control unit may transmit control information to the mobile robot 100 via the communication unit 312 to control the drive unit 138 to move the mobile robot 100 to the safe area based on information about the safe area. Also, when an abnormality is detected while the mobile robot 100 is autonomously traveling and the second information acquisition unit cannot acquire information about the safe area, the control unit 310 functioning as the second control unit may stop the mobile robot 100 on the spot, or may move the mobile robot based on information input to a remote control UI in the server.

[0209] Furthermore, at least a part of the functional configuration of the management server 300 or the monitoring server 400 according to the above-described embodiment may be realized by the mobile robot 100. In the following, an example in which at least a part of the functional configuration of the management server 300 is provided in the mobile robot 100 will be described.

[0210] The mobile robot 100 may be capable of executing at least a part or all of the functions of the UI generation unit 330. The processing unit included in the mobile robot 100 and capable of executing at least a part or all of the functions of the UI generation unit 330 is an example of a first UI generation unit, or an example of both the first UI generation unit and the second UI generation unit.

[0211] If an abnormality is detected during the autonomous driving of the mobile robot 100 and the first judgment unit determines that the autonomous driving function 130 is unreliable, or if an abnormality is detected and the first information acquisition unit is unable to acquire information regarding the safe area, the first UI generation unit generates a first alert UI for issuing an alert on a server (e.g., management server 300) that is communicatively connected to the mobile robot 100, and transmits the generated first alert UI to the management server 300 via the communication unit 112.

[0212] When an abnormality is detected during the autonomous driving of the mobile robot 100 and the first determination unit determines that the autonomous driving function 130 is unreliable, the second UI generation unit generates a remote control UI to be used for remotely controlling the mobile robot 100 in a server (e.g., the management server 300) communicatively connected to the mobile robot 100, and transmits the generated remote control UI to the management server 300 via the communication unit 112. In addition to being used for remote control, the remote control UI generated by the second UI generation unit may further have a suspicious operation reporting function that reports suspicious operation when suspicious operation is confirmed regarding the movement of the mobile robot 100.

[0213] [Other Modifications] While the present disclosure has been described based on the above-described embodiments, it goes without saying that the present disclosure is not limited to the above-described embodiments. The following cases are also included in the present disclosure.

[0214] (1) In the above embodiment, no specific services or applications are specified for the robot system, but any robot may be the target. For example, the robot may be an autonomous vehicle, a marine system, a mobility robot such as a drone, or a robot that performs a specific task, such as an industrial robot or a humanoid robot. Examples of industrial robots include agricultural machinery used in agriculture and construction machinery used in construction.

[0215] (2) In the above embodiment, the robot has two control methods, autonomous control and remote control, but it is not necessary to have two control means. For example, it is sufficient to have at least two control means, such as remote control and autonomous control. Furthermore, the control means are not limited to these two. For example, the robot may have a cooperative control mode in which it operates in cooperation with other robots, or a control mode in which it operates according to commands from a control center.

[0216] (3) In the above embodiment, the mobile robot control system has been described in which the functions are separated into a management server and a monitoring server. However, the functions of the management server and the monitoring server may be integrated.

[0217] (4) In the above embodiment, a remote operator remotely controls the mobile robot control system, but there may be a person other than the remote operator who monitors the mobile robot control system. For example, this may be a role called a system administrator or system operator, and the alert notifications described in the above embodiment may be sent to the system administrator or system operator.

[0218] (5) Each device in the above embodiments is specifically a computer system comprising a microprocessor, ROM, RAM, hard disk unit, display unit, keyboard, mouse, etc. A computer program is recorded in the RAM or hard disk unit. Each device achieves its function by the microprocessor operating in accordance with the computer program. Here, the computer program is composed of a combination of multiple instruction codes that indicate commands to a computer to achieve a predetermined function.

[0219] (6) In each of the above embodiments, some or all of the constituent elements may be configured from a single system LSI (Large Scale Integration). A system LSI is an ultra-multifunctional LSI manufactured by integrating multiple components on a single chip, and specifically, is a computer system configured to include a microprocessor, ROM, RAM, etc. A computer program is recorded in the RAM. The system LSI achieves its functions by the microprocessor operating in accordance with the computer program.

[0220] Furthermore, each of the components constituting each of the above-described devices may be individually integrated into a single chip, or some or all of them may be integrated into a single chip.

[0221] Although the term "system LSI" is used here, it may also be called an IC, LSI, super LSI, or ultra LSI depending on the level of integration. Furthermore, the method of integration is not limited to LSI, and may be realized using a dedicated circuit or a general-purpose processor. It is also possible to use a field programmable gate array (FPGA), which can be programmed after LSI manufacturing, or a reconfigurable processor, which allows the connections and settings of circuit cells within the LSI to be reconfigured.

[0222] Furthermore, if an integrated circuit technology that can replace LSI emerges due to advances in semiconductor technology or other derivative technologies, it is natural that such technology may be used to integrate functional blocks. The application of biotechnology, etc. is also a possibility.

[0223] (7) Some or all of the components constituting each of the above devices may be configured as an IC card or a standalone module that can be attached to each device. The IC card or module is a computer system composed of a microprocessor, ROM, RAM, etc. The IC card or module may include the above-mentioned ultra-multifunctional LSI. The IC card or module achieves its functions when the microprocessor operates according to a computer program. The IC card or module may be tamper-resistant.

[0224] (8) The present disclosure may be embodied as any of the methods described above. It may also be embodied as a computer program that causes a computer to implement these methods, or as a digital signal comprising the computer program. For example, one aspect of the present disclosure may be a computer program that causes a computer to execute each of the characteristic steps included in the mobile robot control method shown in any of Figures 6, 7, 9, 10, 12, 14, 16, and 17.

[0225] The present disclosure may also be a computer program or a digital signal recorded on a computer-readable recording medium, such as a flexible disk, a hard disk, a CD-ROM, an MO, a DVD, a DVD-ROM, a DVD-RAM, a BD (Blu-ray (registered trademark) Disc), a semiconductor memory, etc. Alternatively, the present disclosure may be a digital signal recorded on such a recording medium.

[0226] Furthermore, the present disclosure may involve transmitting the computer program or the digital signal via a telecommunications line, a wireless or wired communication line, a network such as the Internet, data broadcasting, or the like.

[0227] The present disclosure may also be a computer system having a microprocessor and a memory, the memory storing the computer program, and the microprocessor operating in accordance with the computer program.

[0228] The program or the digital signal may also be implemented by another independent computer system by recording it on the recording medium and transferring it, or by transferring it via the network or the like.

[0229] (9) The order in which the steps in the flowchart are executed is merely an example for specifically explaining the present disclosure, and an order other than the above may be used. Also, some of the steps may be executed simultaneously (in parallel) with other steps, or some of the steps may not be executed.

[0230] (10) The division of functional blocks in the block diagram is an example, and multiple functional blocks may be realized as a single functional block, one functional block may be divided into multiple blocks, or some functions may be moved to another functional block. Furthermore, the functions of multiple functional blocks having similar functions may be processed in parallel or in time-sharing by a single piece of hardware or software.

[0231] (11) The above-described embodiments and modifications may be combined. Furthermore, as long as they do not deviate from the spirit of the present disclosure, various modifications conceivable by a person skilled in the art may be made to the present embodiments, and embodiments constructed by combining components of different embodiments may also be included in the present disclosure.

[0232] The present disclosure is useful in ensuring safety in a mobile robot control system when a security abnormality occurs while the mobile robot is moving.

[0233] 1 Mobile robot control system 100, 100a, 100b, 100c Mobile robot 110, 310, 410, 510 Control unit 112, 312, 412, 512 Communication unit 116, 314, 414, 518 Memory unit 130 Autonomous driving function 132 External sensor 134 Self-position estimation unit 136 Obstacle detection unit 138 Driving unit 150 Detection unit (abnormality detection unit) 154 Safe area acquisition unit (first information acquisition unit) 156 Reliability judgment unit (first judgment unit) 200 Network 300 Management server 320 Robot management unit 330 UI generation unit (third UI generation unit, fourth UI generation unit) 400 Monitoring server 416 Analysis unit 418 UI generation unit 500 Remote control terminal 514 Presentation unit 516 Input unit

Claims

1. A mobile robot capable of autonomous movement, a first determination unit that determines reliability of an autonomous movement function of the mobile robot; a first information acquisition unit that acquires information about a safe area where the mobile robot can stop; a first control unit that moves the mobile robot to the safety area based on information about the safety area when an abnormality in the mobile robot is detected during the autonomous movement of the mobile robot and the first determination unit determines that the autonomous movement function is reliable. Mobile robot.

2. the first control unit, when the abnormality is detected during the autonomous movement of the mobile robot and the first determination unit determines that the autonomous movement function is unreliable, stops the mobile robot on the spot. The mobile robot of claim 1 .

3. and a first UI generating unit configured to generate a first alert UI for notifying an alert in a server communicably connected to the mobile robot when the abnormality is detected during the autonomous movement of the mobile robot and the first determination unit determines that the autonomous movement function is unreliable. The mobile robot according to claim 2.

4. a second UI generation unit that generates a remote control UI to be used for remotely controlling the mobile robot in a server communicably connected to the mobile robot when the abnormality is detected during the autonomous movement of the mobile robot and the first determination unit determines that the autonomous movement function is unreliable, The first control unit moves the mobile robot to the safety area based on an input of the remote control UI in the server. The mobile robot according to claim 2.

5. The remote control UI has a suspicious behavior reporting function for reporting a suspicious behavior when a suspicious behavior is confirmed regarding the movement of the mobile robot in addition to the use of remote control, the first control unit, when moving the mobile robot based on the input of the remote control UI in the server, stops the mobile robot on the spot when an input of the suspicious operation report function of the remote control UI is recognized.

5. The mobile robot according to claim 4.

6. The second UI generation unit further generates a second alert UI for notifying the suspicious operation when an input of the suspicious operation report function of the remote control UI is recognized.

6. The mobile robot according to claim 5.

7. the mobile robot has an autonomous movement function and a function other than the autonomous movement function, The first determination unit determines that the autonomous movement function is trustworthy when an attack on the autonomous movement function is not detected. The mobile robot according to any one of claims 1 to 5.

8. Further, a first storage unit that stores a destination of the mobile robot, The first determination unit determines that the autonomous movement function is reliable when no tampering with the destination is detected. The mobile robot according to any one of claims 1 to 5.

9. Further, an abnormality detection unit that detects the abnormality is provided. The mobile robot according to any one of claims 1 to 5.

10. A server communicably connected to an autonomously movable mobile robot, A second determination unit that determines reliability of an autonomous movement function of the mobile robot; a second information acquisition unit that acquires information about a safe area where the mobile robot can stop; and a second control unit that, when an abnormality in the mobile robot is detected during the autonomous movement of the mobile robot and the second determination unit determines that the autonomous movement function is reliable, moves the mobile robot to the safety area based on information regarding the safety area. server.

11. the second control unit, when the abnormality is detected during the autonomous movement of the mobile robot and the second determination unit determines that the autonomous movement function is unreliable, stops the mobile robot on the spot. The server of claim 10.

12. and a third UI generating unit configured to generate a third alert UI for notifying an alert when the abnormality is detected during the autonomous movement of the mobile robot and the second determination unit determines that the autonomous movement function is unreliable. The server of claim 11.

13. a fourth UI generation unit that generates a remote control UI to be used for remote control of the mobile robot when the abnormality is detected during the autonomous movement of the mobile robot and the second determination unit determines that the autonomous movement function is unreliable, The second control unit moves the mobile robot to the safety area based on an input of the remote control UI. The server of claim 11.

14. The remote control UI has a suspicious behavior reporting function for reporting a suspicious behavior when a suspicious behavior is confirmed regarding the movement of the mobile robot in addition to the use of remote control, the second control unit, when moving the mobile robot based on the input of the remote control UI, stops the mobile robot on the spot when an input of the suspicious operation report function of the remote control UI is recognized. The server of claim 13.

15. The fourth UI generation unit further generates a fourth alert UI for notifying the suspicious operation when an input of the suspicious operation report function of the remote control UI is recognized. The server of claim 14.

16. the mobile robot has an autonomous movement function and a function other than the autonomous movement function, The second determination unit determines that the autonomous movement function is trustworthy when an attack on the autonomous movement function is not detected. The server according to any one of claims 10 to 14.

17. Further, a second storage unit is provided for storing a destination of the mobile robot, The second determination unit determines that the autonomous movement function is reliable when no tampering with the destination is detected. The server according to any one of claims 10 to 14.

18. Further, an abnormality detection unit that detects the abnormality is provided. The server according to any one of claims 10 to 14.

19. A mobile robot control system including a mobile robot capable of autonomously moving and a server communicatively connected to the mobile robot, A determination unit for determining reliability of an autonomous movement function of the mobile robot; an information acquisition unit that acquires information about a safe area where the mobile robot can stop; a control unit that, when an abnormality in the mobile robot is detected during the autonomous movement of the mobile robot and the determination unit determines that the autonomous movement function is reliable, moves the mobile robot to the safety area based on information regarding the safety area. Mobile robot control system.

20. A method for controlling a mobile robot capable of autonomous movement, comprising: when an abnormality in the mobile robot is detected during the autonomous movement of the mobile robot and the autonomous movement function of the mobile robot is determined to be reliable, moving the mobile robot to a safety area based on information regarding the safety area where the mobile robot can stop. A method for controlling a mobile robot.