Mobile Body Control Gating for Safe Third-Party Commands

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Existing vehicle control systems fail to ensure safety by allowing control instructions from third-party applications to be executed regardless of the vehicle's operating state, lacking the ability to determine the safety of these instructions.

Innovation Solution

A mobile body control device with an analysis unit to assess the current operating state and a determination unit to evaluate the safety of control instructions from applications, allowing safe instructions to be executed while preventing unsafe ones, ensuring safety even when the mobile body is controllable by third-party applications.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Adaptability or versatility

If control instructions from third-party applications are allowed to be executed without safety verification, then the adaptability and versatility of the mobile body system is improved, but the reliability and safety of the system deteriorates

Engineering Contradiction:
Improveability to integrate third-party applicationsVSAvoidsafety of control instructions
Core Design Contradiction:
Adaptability or versatilityVSReliability

Solution Approach 1:

The patent introduces a safety verification unit as an intermediary component between the application execution unit and the control target. This mediator analyzes control instructions before execution, verifying safety based on the current operating state of the mobile body. The intermediary prevents direct unverified control instructions from reaching the control target, thus maintaining system reliability while allowing third-party application integration.

Inventive Principle:
Principle #24Intermediary (Mediator)

2Reliability

If safety verification of control instructions is implemented, then the reliability and safety of the system is improved, but the device complexity increases

Engineering Contradiction:
Improvesafety of control instructionsVSAvoidcomplexity of control system
Core Design Contradiction:
ReliabilityVSDevice complexity

Solution Approach 1:

The control system is segmented into distinct functional units: an application execution unit that handles third-party applications and a separate safety verification unit that analyzes control instructions. This segmentation allows the safety verification functionality to be added as a modular component rather than integrating it throughout the entire system, thereby limiting the increase in overall device complexity while maintaining improved reliability.

Inventive Principle:
Principle #1Segmentation

3Reliability

If safety verification of control instructions is implemented, then the reliability and safety of the system is improved, but the processing time and productivity deteriorate

Engineering Contradiction:
Improvesafety of control instructionsVSAvoidprocessing time for control instructions
Core Design Contradiction:
ReliabilityVSLoss of time

Solution Approach 1:

The safety verification unit performs preliminary analysis of control instructions before they are executed by the application execution unit. By verifying safety in advance based on the current operating state, the system prevents unsafe instructions from being processed further, thereby avoiding potential safety issues and reducing the need for corrective actions or rejections during execution, which would consume more time.

Inventive Principle:
Principle #10Preliminary action

Data Source

PatentUS20250010868A1Mobile body control device, mobile body, and non-transitory computer readable medium storing control program for mobile body
Publication Date: 2025.01.09 DENSO CORP
  • US20250010868A1 patent drawing
  • US20250010868A1 patent drawing
  • US20250010868A1 patent drawing

AI summary

Disclosed is a technique of controlling a mobile body. In the technique, a current operating state of the mobile body is analyzed, and it is determined whether a control instruction from an application is safe for the current operating state. The control instruction is allowed to be output to a control target based on the control instruction being determined to be safe in the current operating state. The control instruction is prevented from being output to the control target based on the control instruction being determined to be unsafe in the current operating state.