Driving system, processing method, and processing program

The described processing method addresses the challenge of notifying other road users of a vehicle's return to normal operation after an emergency stop, thereby enhancing their response ability and ensuring safer road interactions.

JP2025089441AActive Publication Date: 2025-06-12DENSO CORP
View PDF 4 Cites 0 Cited by

Patent Information

Application Number
JP2025048531
Authority / Receiving Office
JP · JP
Patent Type
Applications
Current Assignee / Owner
Priority Date
2022-03-15
Filing Date
2025-03-24
Publication Date
2025-06-12
Estimated Expiration
2043-02-10

AI Technical Summary

Technical Problem

Existing driving systems struggle to effectively notify other road users of a vehicle's return to normal operation after an emergency stop, leading to difficulties in responding appropriately.

Method used

A processing method executed by a processor to determine the return of a host moving body's operation from an emergency state and notify external road users of this return, enhancing their response ability.

Benefits of technology

The method improves the response ability of other road users by ensuring they are notified of a vehicle's return to normal operation, facilitating safer interactions on the road.

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure 2025089441000001_ABST
    Figure 2025089441000001_ABST
Patent Text Reader

Abstract

To provide a processing method for contributing to improvement in responsiveness of an other-road user.SOLUTION: A processing method, which is implemented with a processor to perform processing related to driving of a host moving object with a driving system, includes: determining driving recovery from an emergency operation of the host moving object when the emergency operation is performed by the driving system; and notifying an outside of the host moving object about the driving recovery.SELECTED DRAWING: Figure 4
Need to check novelty before this filing date? Find Prior Art

Description

Technical Field

[0001] The present disclosure relates to a technology for performing processing related to driving a host moving body in a driving system.

Background Art

[0002] In the technology disclosed in Patent Document 1, after a vehicle as a host moving body stops due to an emergency operation of a driving system, when a release switch is pressed, the vehicle can resume running.

Prior Art Documents

Patent Documents

[0003]

Patent Document 1

Summary of the Invention

Problems to be Solved by the Invention

[0004] However, in the technology disclosed in Patent Document 1, if a vehicle that has been emergently operated suddenly resumes running, it may be difficult for other road users outside the vehicle to respond appropriately.

[0005] An object of the present disclosure is to provide a processing method that contributes to improving the response ability of other road users. Another object of the present disclosure is to provide a driving system that contributes to improving the response ability of other road users. Still another object of the present disclosure is to provide a processing program that contributes to improving the response ability of other road users.

Means for Solving the Problems

[0006] Hereinafter, the technical means of the present disclosure for solving the problems will be described. Note that the reference numerals in parentheses described in the claims and this column indicate the correspondence with the specific means described in the embodiments to be described in detail later, and do not limit the technical scope of the present disclosure.

[0007] The first aspect of the present disclosure is A processing method executed by a processor (12) for performing processing related to the operation of a host moving body (2) in an operation system (DS), Determining the return of the operation of the host moving body from the emergency operation by the operation system, Including notifying the outside of the host moving body of the return of the operation.

[0008] The second aspect of the present disclosure is An operation system (DS) having a processor (12) and performing processing related to the operation of a host moving body (2), Determining the return of the operation of the host moving body from the emergency operation by the operation system, Configured to execute notifying the outside of the host moving body of the return of the operation.

[0009] The third aspect of the present disclosure is A processing program stored in a storage medium (10) and including instructions executed by a processor (12) for performing processing related to the operation of a host moving body (2) in an operation system (DS), The instructions are Causing to determine the return of the operation of the host moving body from the emergency operation by the operation system, Including causing to notify the outside of the host moving body of the return of the operation.

[0010] In these first to third aspects, the return of the operation of the host moving body from the emergency operation by the operation system is determined. Therefore, according to the first to third aspects, the return of the operation of the host moving body is notified outside the host moving body. According to this, other road users existing in the external environment of the host moving body to be notified can take corresponding actions according to the notification with respect to the return of the operation of the host moving body that has been emergently operated. Therefore, it is possible to contribute to improving the response ability of other road users.

Brief Description of the Drawings

[0011]

Figure 1

Figure 2

Figure 3

Figure 4

Figure 5

Figure 6

Figure 7

Figure 8

Figure 9

Figure 10

Figure 11

Modes for Carrying Out the Invention

[0012] Hereinafter, a plurality of embodiments of the present disclosure will be described with reference to the drawings. In each embodiment, the corresponding components may be denoted by the same reference numerals, and redundant descriptions may be omitted. Further, when only a part of the configuration is described in each embodiment, the configuration of other embodiments described previously can be applied to other parts of the configuration. Furthermore, not only the combinations of configurations explicitly shown in the description of each embodiment, but also the configurations of a plurality of embodiments can be partially combined with each other as long as there is no problem with the combination.

[0013] (First Embodiment) The driving system DS of the first embodiment shown in FIG. 1 is configured to include a processing system 1 in order to perform processing related to the driving of a host moving body (hereinafter referred to as driving processing). Part or all of the driving system DS is mounted on the host moving body.

[0014] The host moving body that is the object of driving processing in the driving system DS is the host vehicle 2 shown in FIG. 2. The host vehicle 2 is a road user capable of performing autonomous driving, such as an automobile or a truck, for example. The host vehicle 2 may be referred to as an ego-vehicle. The driving in the host vehicle 2 is classified according to the task range performed by the driver, who is a passenger in the driver's seat, among all dynamic driving tasks (DDT). Here, the driver who can be responsible for DDT by manual operation of the host vehicle 2 according to the autonomous driving level is a vehicle operator and can also be said to be a vehicle user.

[0015] The automated driving level is defined, for example, in SAE J3016 etc. Specifically, at levels 0 to 2, the driver performs part or all of the DDT. Levels 0 to 2 may be classified as so-called manual driving. Level 0 indicates that the driving is not automated. Level 1 indicates that the driving system DS assists the driver. Level 2 indicates that the driving is partially automated. At levels 3 and above, while the driving system DS is engaged, the driving system DS performs all of the DDT. Levels 3 to 5 may be classified as so-called automated driving. A driving system DS capable of executing driving at levels 3 and above may be referred to as an automated driving system. Level 3 indicates that the driving is conditionally automated. Level 4 indicates that the driving is highly automated. Level 5 indicates that the driving is fully automated. A driving system DS that is unable to execute driving at levels 3 and above and is capable of executing at least one of the driving at levels 1 and 2 may be referred to as a driving assistance system. Hereinafter, in the case where there is no circumstance for specifying the maximum achievable automated driving level, it is assumed that the automated driving system or the driving assistance system is included in the driving system DS.

[0016] For such a host vehicle 2, another road user 3 is a road user other than the host vehicle 2 existing in the external environment in which the host vehicle 2 travels. The other road user 3 includes, for example, non-vulnerable road users such as automobiles, trucks, motorcycles, and bicycles, and vulnerable road users such as pedestrians. The other road user 3 may further include animals.

[0017] In the physical architecture shown in FIG. 1, the driving system DS has the actuator system 4, the sensor system 5, the communication system 6, the map database (DB) 7, the information interface (IF) system 8, and the processing system 1 as physical components. However, the driving system DS only needs to include at least the processing system 1 as its physical component, and at least one of the physical components belonging to the actuator system 4, the sensor system 5, the communication system 6, the map DB 7, and the information IF system 8 may be replaced by a physical component belonging to the host vehicle 2.

[0018] The actuator system 4 is configured to be able to control the operation of the host vehicle 2 based on the input control signal. The actuator system 4 may be at least one type of power train actuator such as, for example, an internal combustion engine and a motor generator motor. The actuator system 4 may be at least one type of braking actuator such as, for example, a brake unit. The actuator system 4 may be at least one type of steering actuator such as, for example, a power steering unit.

[0019] The sensor system 5 acquires sensor data that can be used by the driving system DS by detecting the external environment and the internal environment of the host vehicle 2. For this purpose, the sensor system 5 includes an external environment sensor 50 and an internal environment sensor 52.

[0020] The external environment sensor 50 may detect an object existing in the external environment of the host vehicle 2. The external environment sensor 50 of the object detection type is at least one of, for example, a camera, LiDAR (light detection and ranging / laser imaging detection and ranging), a laser radar, a millimeter wave radar, and an ultrasonic sonar. The external environment sensor 50 of the object detection type is typically implemented by combining multiple types so as to be able to sense the front, side, and rear directions of the host vehicle 2. The external environment sensor 50 may detect the state of the atmosphere in the external environment of the host vehicle 2. The external environment sensor 50 of the atmosphere detection type is at least one of, for example, an outside air temperature sensor and a humidity sensor.

[0021] The internal environment sensor 52 may detect a specific physical quantity related to vehicle movement (hereinafter referred to as a movement physical quantity) in the internal environment of the host vehicle 2. The internal environment sensor 52 of the movement physical quantity detection type is at least one of, for example, a speed sensor, an acceleration sensor, and a gyro sensor. The internal environment sensor 52 may detect the state of an occupant boarding the host vehicle 2. The internal environment sensor 52 of the occupant detection type is at least one of, for example, an actuator sensor, a driver status monitor (registered trademark), a biological sensor, a seating sensor, and an in-vehicle device sensor. Here, examples of the actuator sensor include at least one of, for example, a start switch, an accelerator sensor, a brake sensor, and a steering sensor that detect the operation state of an occupant related to the actuator system 4 of the host vehicle 2.

[0022] The communication system 6 acquires communication data that can be used in the driving system DS by wireless communication. The communication system 6 may receive a positioning signal from an artificial satellite of GNSS (Global Navigation Satellite System) existing in the external environment of the host vehicle 2. The communication system 6 of the positioning type is, for example, a GNSS receiver or the like. The communication system 6 may transmit and receive communication signals to and from a V2X system existing in the external environment of the host vehicle 2. The communication system 6 of the V2X type is at least one of, for example, a DSRC (Dedicated Short Range Communications) communication device, a cellular V2X (C-V2X) communication device, and the like. Here, as communication with the V2X system, at least one of communication with the communication systems of other vehicles that are other road users 3 (V2V), communication with infrastructure facilities such as communication devices installed in traffic lights (V2I), communication with the mobile terminals of pedestrians who are other road users 3 (V2P), and communication with a cloud network or a mesh network (V2N) and the like can be mentioned. The communication system 6 may transmit and receive communication signals to and from a mobile terminal existing in the internal environment of the host vehicle 2. The communication system 6 of the terminal communication type is at least one of, for example, a Bluetooth (registered trademark) device, a Wi-Fi (registered trademark) device, and an infrared communication device.

[0023] The map DB 7 stores map data that can be used by the driving system DS. The map DB 7 is configured to include at least one type of non-transitory tangible storage medium such as a semiconductor memory, a magnetic medium, and an optical medium. The map DB 7 may be a DB of a locator that estimates the self-state quantity of the host vehicle 2 including the self-position. The map DB may be a DB of a navigation unit that navigates the driving route of the host vehicle 2. The map DB 7 may be constructed by a combination of multiple types of DBs.

[0024] The map DB 7 acquires and stores the latest map data through communication with an external center via, for example, a V2X type communication system 6. The map data is digitized in two dimensions or three dimensions as data representing the driving environment of the host vehicle 2. As the three-dimensional map data, digital data of a high-precision map may be adopted. The map data may include road data representing at least one of, for example, the position coordinates, shape, and road surface condition of the road structure. The map data may include sign data representing at least one of the position coordinates and shape of, for example, road signs, road markings, and lane markings attached to the road. The sign data included in the map data may represent, among landmarks, for example, traffic signs, arrow markings, lane markings, stop lines, direction signs, landmark beacons, rectangular signs, business signs, or changes in the line pattern of the road. The map data may include structure data representing at least one of the position coordinates and shape of, for example, buildings and traffic lights facing the road. The sign data included in the map data may represent, among landmarks, for example, street lights, the edge of the road, reflectors, poles, or the back side of road signs.

[0025] The information IF system 8 mediates the transmission of information related to driving processes between the passengers including the driver of the host vehicle 2 and the driving system DS. For this purpose, the information IF system 8 includes an HMI (human machine interface) device 80.

[0026] The HMI device 80 may be configured to be able to detect operations for inputting the intentions of the passengers in the host vehicle 2 to the driving system DS. The HMI device 80 of the operation detection type is at least one of, for example, a push switch, a lever switch, and a touch panel. The HMI device 80 of the operation detection type may be replaced by an actuator sensor or the like as the internal environment sensor 52 among the sensor systems 5. The HMI device 80 may be configured to be able to detect gestures for inputting the intentions of the passengers in the host vehicle 2 to the driving system DS. The HMI device 80 of the gesture detection type may be replaced by a driver status monitor or the like as the internal environment sensor 52 among the sensor systems 5.

[0027] The HMI device 80 may present notification information rather than stimulating the vision of the passengers in the host vehicle 2. The HMI device 80 of the visual information presentation type is at least one of, for example, a HUD (head-up display), a CID (center information display), an MFD (multi function display), a combination meter, a navigation unit, and an illumination unit. The HMI device 80 may present notification information by stimulating the hearing of the passengers. The HMI device 80 of the auditory information presentation type is at least one of, for example, a speaker, a buzzer, and a vibration unit. The HMI device 80 may present notification information by stimulating the sense of skin of the passengers. The HMI device 80 of the skin sensation information presentation type is at least one of, for example, a vibration unit of the steering wheel, a vibration unit of the driver's seat, a reaction force unit of the steering wheel, a reaction force unit of the accelerator pedal, a reaction force unit of the brake pedal, and an air conditioning unit.

[0028] The information IF system 8 mediates the transmission of notification information related to driving processing between other road users 3 existing outside the host vehicle 2 and the driving system DS. For this purpose, the information IF system 8 includes an external notification unit 82.

[0029] The external notification unit 82 may present notification information by stimulating the vision of a human such as a pedestrian as another road user 3 or a human boarding another vehicle as another road user 3 in the external environment of the host vehicle 2. The external notification unit 82 of the visual information presentation type is at least one of, for example, a hazard lamp, a direction indicator lamp, a lighting lamp, a projection lamp, an electronic sticker, and an external display unit. Here, the electronic sticker as the external notification unit 82 may be a dedicated sticker for autonomous driving that indicates that the host vehicle 2 is, for example, an autonomous vehicle or in the process of autonomous driving. The external notification unit 82 may present notification information by stimulating the hearing of a human such as a pedestrian as another road user 3 or a human boarding another vehicle as another road user 3 in the external environment of the host vehicle 2. The external notification unit 82 of the auditory information presentation type is at least one of, for example, an electronic horn, a speaker, and a buzzer.

[0030] The processing system 1 is connected to the actuator system 4, the sensor system 5, the communication system 6, the map DB 7, and the information IF system 8 via at least one of, for example, a LAN (local area network), a wire harness, an internal bus, and a wireless communication line. The processing system 1 is configured to include at least one dedicated computer.

[0031] The dedicated computer that constitutes the processing system 1 may be an integrated ECU (electronic control unit) that integrates the driving control of the host vehicle 2. The dedicated computer that constitutes the processing system 1 may be a detection ECU that processes sensor data detected in the driving control of the host vehicle 2. The dedicated computer that constitutes the processing system 1 may be a recognition ECU that performs recognition in the driving control of the host vehicle 2. The dedicated computer that constitutes the processing system 1 may be a determination ECU that determines and plans the DDT in the driving control of the host vehicle 2. The dedicated computer that constitutes the processing system 1 may be a monitoring ECU that monitors the driving control of the host vehicle 2. The dedicated computer that constitutes the processing system 1 may be an evaluation ECU that evaluates the driving control of the host vehicle 2.

[0032] The dedicated computer that constitutes the processing system 1 may be a navigation ECU that navigates the driving route of the host vehicle 2. The dedicated computer that constitutes the processing system 1 may be a locator ECU that estimates the self-state quantity including the self-position of the host vehicle 2. The dedicated computer that constitutes the processing system 1 may be an actuator ECU that controls the actuator system 4. The dedicated computer that constitutes the processing system 1 may be an HCU (HMI control unit) that controls the HMI device 80. The dedicated computer that constitutes the processing system 1 may be a memory ECU that controls data storage. The dedicated computer that constitutes the processing system 1 may be at least one external computer that constructs an external center or a mobile terminal that can communicate via, for example, the communication system 6.

[0033] The dedicated computer that constitutes the processing system 1 has at least one memory 10 and at least one processor 12. The memory 10 is at least one type of non-transitory tangible storage medium, such as a semiconductor memory, a magnetic medium, and an optical medium, that non-temporarily stores programs and data readable by the computer. The processor 12 includes at least one type, such as a CPU (central processing unit), a GPU (graphics processing unit), and a RISC (reduced instruction set computer)-CPU, as a core.

[0034] The memory 10 may be a storage device that selectively accumulates data by selecting at least one of recognition information, determination information, monitoring information, and control information in the operation system DS. The memory 10 may be a volatile memory medium, such as a RAM (random access memory), that temporarily stores data of at least one of recognition information, determination information, monitoring information, and control information in the operation system DS. The memory 10 may be a database for executing DDT in the operation system DS.

[0035] The memory 10 may be mounted on the board in a non-removable and non-replaceable manner. Examples of this configuration include an eMMC (embedded multi media card) using a flash memory. The memory 10 may be configured to be removable and replaceable. Examples of this configuration include an SD card. The memory 10 may implement the dedicated computer that constitutes the processing system 1 by an SoC (system on a chip) integrated into one chip together with the processor 12 and the input / output IF.

[0036] Processor 12 executes a plurality of instructions included in a processing program stored in memory 10 as software. As a result, the operation system DS including the processing system 1 constructs a plurality of functional blocks for performing the driving process of the host vehicle 2. In this way, in the operation system DS, in order to perform the driving process of the host vehicle 2 mainly by the processing system 1, the processing program stored in the memory 10 causes the processor 12 to execute a plurality of instructions, thereby constructing a plurality of functional blocks. The plurality of functional blocks constructed in the operation system DS in this way include a recognition block 100, a determination block 120, and a control block 140, as shown as a functional architecture in FIG. 3.

[0037] The recognition block 100 acquires sensor data from the sensor system 5. The recognition block 100 acquires communication data from the communication system 6. The recognition block 100 acquires map data from the map DB 7. The recognition block 100 individually processes these acquired data and then fuses them to recognize the internal and external environment of the host vehicle 2. In generating the recognition information, the recognition block 100 acquires data from the sensor system 5, the communication system 6, and the map DB 7, understands or grasps the meaning of the acquired data, and recognizes the external environment of the host vehicle 2 and its own situation therein, as well as the overall situation including the internal environment of the host vehicle 2, by fusing the acquired data. Based on the recognition of the internal and external environment, the recognition block 100 generates the recognition information to be provided to the determination block 120.

[0038] The recognition information generated by the recognition block 100 describes the state detected for each scene in the driving environment of the host vehicle 2. The recognition block 100 may generate recognition information of an object by detecting (sensing) an object including other road users 3, obstacles, and structures in the external environment of the host vehicle 2. The recognition information of the object may represent at least one of, for example, a separation distance, a moving direction, a relative speed, a relative acceleration, a size, an estimated state by following detection, etc. The recognition information of the object may represent the classification of the object recognized based on the state of the object clustered by, for example, semantic segmentation. The recognition block 100 may generate recognition information of the road by detecting the road on which the host vehicle 2 is currently and will drive in the future. The recognition information of the road may represent at least one type of static structure among, for example, a road surface, a lane, a road edge, and a free space.

[0039] The recognition block 100 may generate recognition information of the self-state quantity by localization that presumptively recognizes the self-state quantity including the self-position of the host vehicle 2. The recognition block 100 may simultaneously generate update data of map data regarding the road of the host vehicle 2 with the recognition information of the self-state quantity, and feedback the update data to the map DB 7. The recognition block 100 may generate recognition information of the sign by detecting a sign associated with the road of the host vehicle 2. The recognition information of the sign may represent at least one type of state among, for example, a traffic sign, a lane line, and a traffic signal. The recognition information of the sign may further represent a traffic rule recognized or specified from the state of the sign. The recognition block 100 may generate recognition information of the weather condition for each scene in which the host vehicle 2 drives by detecting the weather condition. The recognition block 100 may generate recognition information of the time for each driving scene of the host vehicle 2 by detecting the time.

[0040] The determination block 120 acquires recognition information from the recognition block 100. Based on the acquired recognition information, the determination block 120 predicts the future actions of other road users 3 with respect to the host vehicle 2 in time series. The predicted future actions may include risk actions of other road users 3 that can foresee potential risks with the host vehicle 2. The predicted future actions may be the future trajectories of other road users 3. Here, the future trajectory may be predicted so as to define at least one type of motion physical quantity related to other road users 3 in time series, such as position, speed, acceleration, yaw rate, and direction of motion, etc.

[0041] As basic processing for predicting the future actions of other road users 3, the determination block 120 may interpret the driving environment in which the host vehicle 2 is located. At this time, the determination block 120 may interpret the intention and actions based on the classification of other road users 3 which are dynamic objects, or may interpret the classifiable driving situations. Here, the interpretation of the intention and actions of other road users 3 is, for example, the interpretation such as the lane change probability. The interpretation of the driving situation is, for example, the interpretation such as traffic rules and traffic jam situations. Such environmental interpretation as the basis for action prediction may be at least partially executed by the recognition block 100, and the interpretation result as recognition information may be given to the determination block 120.

[0042] The determination block 120 plans a route for the host vehicle 2 to travel in the future by driving control. That is, the determination block 120 realizes the DDT function of planning a route as a strategic function of the host vehicle 2. Based on the recognition information obtained by estimating the self-position of the host vehicle 2, the determination block 120 may plan at least one of the route to the destination and the lane. At this time, based on the planned lane, the determination block 120 may plan at least one of a lane change request and a deceleration request.

[0043] Based on both the planned route and lane, and the predicted future behavior of other road users 3, the determination block 120 plans the future behavior of the host vehicle 2. That is, the determination block 120 realizes the DDT function by planning the tactical behavior of the host vehicle 2. The behavior planning function by the determination block 120 may include a function of generating transition conditions related to the state transition of the host vehicle 2. The transition conditions related to the state transition of the host vehicle 2 may correspond to triggering conditions. Therefore, the behavior planning function may include a function of determining the state transition of the application that realizes DDT and further the state transition of the driving behavior based on the generated transition conditions.

[0044] Based on the predicted future behavior of other road users 3, the determination block 120 plans the future trajectory to be given to the host vehicle 2 along the planned route. That is, the determination block 120 realizes the DDT function by planning the future trajectory for the host vehicle 2 to travel as a path plan. The future trajectory planned by the determination block 120 may define at least one of, for example, position, speed, acceleration, yaw rate, and direction of motion, etc. as the kinematic physical quantities related to the host vehicle 2 in a time series. The defined time-series trajectory plan will construct the scenario of the future travel of the host vehicle 2 by navigation. Therefore, the trajectory plan may include a function of selecting or switching the optimal path plan from among a plurality of path plans.

[0045] Based on at least one type among, for example, intention estimation information and biometric information as recognition information about the driver in the recognition block 100, the determination block 120 may determine the transition of the driving mode by the driving system DS according to the driver's intention. Based on at least one type among, for example, intention estimation information and biometric information as recognition information about the driver in the recognition block 100, the determination block 120 may determine whether the driver has a disability. By monitoring the driving system DS, the determination block 120 may determine whether there is a failure in each of the physical components 1, 4 to 8. Based on at least one type among the driving mode transition determination result, the driver disability determination result, the driving system DS failure determination result, the future route planning result, the future behavior planning result, and the future trajectory planning result, etc., the determination block 120 may set restrictions on the functions related to the driving of the host vehicle 2.

[0046] The determination block 120 may plan the adjustment of the autonomous driving level in the host vehicle 2. The adjustment of the autonomous driving level may include the takeover / handover of DDT transferred between the driving system DS and the driver due to the transition of the driving mode between autonomous driving and manual driving. The takeover between autonomous driving and manual driving may be realized in a scenario associated with entry into or exit from the operational design domain (ODD) for executing autonomous driving. For example, in the exit scenario from the ODD, that is, the takeover scenario from autonomous driving to manual driving, an unreasonable situation determined to have an unreasonable risk is cited as a use case. In this use case, the determination block 120 may plan a DDT fallback for the driver who becomes a fallback standby user to transition the host vehicle 2 to the minimal risk condition (MRC) by manual driving.

[0047] The adjustment of the autonomous driving level planned by the determination block 120 may include the degraded driving of the host vehicle 2. In the scenario of degraded driving, an unreasonable situation in which an unreasonable risk exists depending on the handover to manual driving is cited as a use case. In this use case, the determination block 120 may plan its best effort to transition the host vehicle 2 to the MRC by autonomous driving and autonomous stop in order to minimize the hazards or risks of an accident. In such best effort, in addition to the adjustment of lowering the autonomous driving level, as an adjustment of maintaining the autonomous driving level, for example, an emergency operation such as DDT fallback or minimum risk manoeuvre (MRM) to reach the MRC as a safe state may be planned. At this time, for example, among various sensory stimuli and communications, notification associated with the emergency operation may be planned so as to enhance the visibility of the transition status to the MRC for the inside and outside of the host vehicle 2 by at least one type using the information IF system 8 or the communication system 6.

[0048] The determination block 120 further plans the driving control of the host vehicle 2 according to at least the route plan, the behavior plan, the trajectory plan, and the driving level plan among the plans described above. In the plan of driving control, control commands regarding the navigation operation and the driver assistance operation of the host vehicle 2 are generated as control actions. That is, the determination block 120 realizes the DDT function of planning the control actions that become the motion control requirements of the host vehicle 2. The control commands generated by the determination block 120 may include control parameters for controlling the actuator system 4. Such a control plan may be performed by the control block 140 prior to the driving control described later.

[0049] In the control plan, the decision block 120 may plan a control action that complies with the driving policy by using a safety model described according to the driving policy and its safety. Here, the driving policy that the safety model follows is defined based on a vehicle-level safety strategy (VLSS) that guarantees the safety of the intended functionality (SOTIF). In other words, the safety model is described by following the driving policy that implements the VLSS and by modeling the SOTIF.

[0050] The safety model may be defined in the safety-related models themselves, which represent the safety-related aspects of driving behavior based on assumptions about the reasonably foreseeable actions of other road users 3, or may be defined in models that constitute a part of the safety-related models. Such a safety model may be constructed in at least one form, such as a mathematical model that formulates vehicle-level safety and a computer program that executes processing according to the mathematical model. Therefore, the decision block 120 may train the safety model by a machine learning algorithm that backpropagates the driving control result by the subsequent control block 140 to the safety model. As the safety model to be trained, at least one learning model among deep learning by a neural network such as a DNN (deep neural network) and reinforcement learning may be used.

[0051] The control block 140 acquires a control command from the determination block 120. The control block 140 controls the operation of the host vehicle 2 according to the planned control command. That is, the control block 140 realizes the DDT function by giving a control action to the host vehicle 2. At this time, the control block 140 may utilize, for vehicle control, recognition information such as vehicle motion regarding the host vehicle 2 by acquiring it from the recognition block 100 or via the determination block 120. Further, when the determination block 120 has planned notification, the control block 140 may output the notification by controlling at least one of the information IF system 8 and the communication system 6.

[0052] In the first embodiment, a flow of a processing method for performing the driving process of the host vehicle 2 according to the flowchart shown in FIG. 4 (hereinafter referred to as a processing flow) is repeatedly executed by the cooperation of the plurality of blocks 100, 120, 140. Here, the processing flow of the first embodiment is started, for example, in a situation where the host vehicle 2 is controlled to the level 3 automatic driving state by the driving system DS. In the following description, each "S" of the processing flow means a plurality of steps executed by a plurality of instructions included in the processing program.

[0053] In S100, the determination block 120 determines whether an emergency operation to transition the host vehicle 2 in the nominal state to the MRC by the driving system DS is necessary. At this time, the determination block 120 monitors whether an emergency condition has been satisfied as a trigger condition for the emergency operation. Here, the nominal state may be defined as a state in which the host vehicle 2 is released from, for example, a failure, a functional insufficiency, or a potentially dangerous behavior and is being nominally operated by the driving system DS. In other words, the emergency condition may be defined as a condition that requires the execution of an emergency operation in the host vehicle 2 due to, for example, a malfunction, a functional insufficiency, or a potentially dangerous behavior.

[0054] Specifically, the emergency condition determined by S100 is established when a failure occurs in at least one physical element or functional block in the driving system DS and a failure occurs in the handover of DDT to the driver. Here, the failure of the physical element in the driving system DS may be a malfunction such as a reduction in the detection range or field of view of the external environment sensor 50 included in the sensor system 5. The failure of the functional block in the driving system DS may be a malfunction such as a reduction in the recognition range by the recognition block 100. The failure in the handover may be a malfunction such that, for example, the driver's handover intention is not detected within a specific time frame by the HMI device 80 or the internal environment sensor 52 in response to the handover request notified to the driver by the HMI device 80 in response to the occurrence of a failure in the physical element or functional block. The failure in the handover may be a malfunction such that, for example, a biological state of the driver that is inappropriate for the handover is detected by the HMI device 80 or the internal environment sensor 52 in response to the occurrence of a failure in the physical element or functional block, regarding at least one of posture, line of sight, and consciousness. Examples of such a biological state inappropriate for the handover include looking away from the driver's line of sight from the traveling direction of the host vehicle 2, such as a sidelong glance.

[0055] When the emergency condition is established in S100, the processing flow proceeds to S101. In S101, the determination block 120 plans a control action that gives an emergency operation to transition to the MRC. At this time, the control action that gives the emergency operation is at least one of, for example, deceleration within the lane, emergency stop within the lane, autonomous stop after autonomous driving within the lane, and escape outside the lane, as an appropriate response or fault reaction. In S101 like this, the control block 140 gives the control action of the emergency operation planned by the determination block 120 to the host vehicle 2.

[0056] In S101, the determination block 120 may further plan to notify an emergency operation in accordance with the planned control action. The notification plan at this time may include generating notification data for notifying the driver in the host vehicle 2 from the HMI device 80 among the information IF systems 8 of an emergency operation. The notification plan may include generating notification data for notifying a person outside the host vehicle 2 from the external notification unit 82 among the information IF systems 8 of an emergency operation. The notification plan may include generating notification data for notifying an emergency operation to an external center by, for example, broadcast, etc., which is transmitted from the communication system 6 outside the host vehicle 2. In such S101, the control block 140 outputs the notification data of the emergency operation planned by the determination block 120 in the host vehicle 2.

[0057] In S102 following S101, the determination block 120 determines whether it is necessary to resume driving from the emergency operation of the host vehicle 2 that has been emergently operated by the driving system DS. At this time, the determination block 120 monitors whether a return condition is satisfied in which at least a part of the emergency conditions is eliminated. Specifically, the driving resume determined by S102 uses, at least as a trigger condition, the elimination of a failure in the handover of DDT to the driver in the first embodiment. That is, the return conditions determined by S102 include a complete return condition that is satisfied when both the failures of the driving system DS and the handover are eliminated, and a driver-priority return condition that is satisfied when the failure of the driving system DS continues and the failure of the handover to the driver is eliminated.

[0058] Here, the elimination of a failure in the driving system DS may be determined by the full recovery of all the capabilities or functions of the driving system DS. The elimination of a failure during takeover may be determined, for example, by the detection by the HMI device 80 or the internal environment sensor 52 of the biometric state of the driver that conforms to the takeover, such as the posture, line of sight, or consciousness. The elimination of a failure during takeover may be determined, for example, by the detection by the HMI device 80 or the internal environment sensor 52 of the driver's takeover intention within a specific time frame with respect to the takeover request notified to the driver by the HMI device 80.

[0059] Incidentally, after the host vehicle 2 stops according to the control action in S101, it is assumed that the start switch of the host vehicle 2 is turned off by the driver or the driving system DS (for example, the determination block 120 or the like). Therefore, although not shown, the state of the start switch is monitored at each start timing of S102, and in response to the turning off of the start switch, the execution of the current process flow is terminated.

[0060] In S102, when the complete recovery condition in which each failure of the driving system DS and the takeover is eliminated is satisfied, the process flow proceeds to S103. In S103, the determination block 120 plans the control action for the complete recovery by determining the complete recovery of returning the driving system DS to the nominal state as the resumption of driving of the host vehicle 2 emergency-operated by the driving system DS. That is, in the first embodiment, the nominal state is the recovery state in which the driving system DS is transitioned from the emergency operation state. Thus, in S103, the control block 140 gives the host vehicle 2 the return of the driving system DS to the nominal state by the control action planned by the determination block 120.

[0061] In S103, the determination block 120 further plans to notify a complete recovery in which the automatic driving in the nominal state is restarted by the operation system DS in accordance with the operation recovery by the planned control action. The notification plan at this time may include generation of notification data for notifying the driver in the host vehicle 2 from the HMI device 80 among the information IF systems 8 of the complete recovery. The notification plan may include generation of notification data for notifying a person outside the host vehicle 2 from the external notification unit 82 among the information IF systems 8 of the complete recovery. The notification plan may include generation of notification data for notifying the complete recovery to an external center by, for example, broadcast or the like transmitted from the communication system 6 to the outside of the host vehicle 2. The notification plan may include generation of notification data for notifying the complete recovery to the mobile terminal of another road user 3 by, for example, broadcast or the like transmitted from the communication system 6 to the outside of the host vehicle 2. In such S103, the control block 140 outputs the notification data of the complete recovery planned by the determination block 120 in the host vehicle 2.

[0062] Here, the notification of the complete recovery to the outside of the host vehicle 2 may be executed in response to the determination block 120 generating notification data that can be output to enable visual stimulation. At this time, the notification of the complete recovery by visual stimulation may be realized by the flashing of the external notification unit 82 such as a hazard lamp or the like. The notification of the complete recovery to the outside of the host vehicle 2 may be executed in response to the determination block 120 generating notification data that can be output to enable auditory stimulation. At this time, the notification of the complete recovery by auditory stimulation may be realized by the operation of the external notification unit 82 such as an electronic horn or the like. In any case of these visual stimulation and auditory stimulation, the notification of the complete recovery may be performed, for example, toward the rear or the like outside the host vehicle 2 with directivity to other road users 3 who need the notification.

[0063] On the other hand, in S102, when the driver-priority return condition is satisfied, where the failure in the driving system DS continues and the failure in the handover to the driver is resolved, the processing flow proceeds to S104. In S104, the determination block 120 plans the control action for the driver-priority return by determining to prioritize the handover of DDT to the driver as the driving return of the host vehicle 2 emergently operated by the driving system DS. At this time, the control action for the driver-priority return may be to maintain the emergency operation by the actuator system 4 until the handover request is notified to the driver by the HMI device 80 and at least the driver's intention to take over is detected by the HMI device 80. The control action for the driver-priority return may be to maintain the manual driving state by the driver to whom DDT has been handed over when the driver's intention to take over has been detected or after it has been detected. In such S104, the control block 140 gives the driving return that hands over DDT to the driver according to the control action planned by the determination block 120 to the host vehicle 2.

[0064] In S104, the determination block 120 further plans the notification of the driver-priority return in which manual driving is started by the driver to whom DDT has been handed over in accordance with the driving return by the planned control action. The notification plan at this time may include the generation of notification data for notifying the driver-priority return from the external notification unit 82 among the information IF systems 8 to a person outside the host vehicle 2. The notification plan may include the generation of notification data for notifying the driver-priority return to an external center, for example, by broadcast, which is transmitted from the communication system 6 outside the host vehicle 2. The notification plan may include the generation of notification data for notifying the driver-priority return to the mobile terminal of another road user 3, for example, by broadcast, which is transmitted from the communication system 6 outside the host vehicle 2. In such S104, the control block 140 outputs the notification data of the driver-priority return planned by the determination block 120 in the host vehicle 2.

[0065] Here, the notification of the driver-priority return to the outside of the host vehicle 2 may be executed in response to the determination block 120 generating notification data that can output visual stimuli. At this time, the notification of the driver-priority return by visual stimuli may be realized by setting the blinking pattern of the external notification unit 82, such as a hazard lamp, to a pattern different from or common to the case of a complete return. The notification of the driver-priority return to the outside of the host vehicle 2 may be executed in response to the determination block 120 generating notification data that can output auditory stimuli. At this time, the notification of the driver-priority return by auditory stimuli may be realized by setting the operation pattern of the external notification unit 82, such as an electronic horn, to a pattern different from or common to the case of a complete return. In either case of these visual and auditory stimuli, the notification of the driver-priority return may be performed, with directivity to other road users 3 who require the notification, toward the outside of the host vehicle 2, such as the rear.

[0066] In the above, when the execution of S103 is completed, the current execution of the processing flow ends. On the other hand, when the execution of S104 is completed, the processing flow returns to S102 so that the control of the driving return continues until a complete return. However, in S104 when it is repeated after the return from S104 to S102, the planning and execution of the notification may be omitted when the time elapsed since the execution of the earliest S104 in the repetition exceeds or reaches the set time. Also, in S103 when the complete return condition is satisfied after the return from S104 to S102, the planning and execution of the notification may be omitted.

[0067] In the first embodiment described so far, the driving return of the host vehicle 2 that has been emergently operated by the driving system DS is determined. Therefore, according to the first embodiment, the driving return of the host vehicle 2 is notified outside the host vehicle 2. According to this, other road users 3 existing in the external environment of the notified host vehicle 2 can take corresponding actions according to the notification with respect to the driving return of the emergently operated host vehicle 2. Therefore, it is possible to contribute to the improvement of the response ability of other road users 3.

[0068] (Second Embodiment) The second embodiment is a modification of the first embodiment. The processing flow according to the second embodiment is started in a situation where the host vehicle 2 is controlled to the level 3 automatic driving state by the driving system DS.

[0069] As shown in FIG. 5, in the processing flow of the second embodiment, S202, which replaces S102, is executed following S101. Specifically, the driving return determined by S202 takes at least one of the elimination of the failure in the handover to the driver of the DDT and the elimination of the failure in the driving system DS as a trigger condition. That is, in addition to the complete return condition and the driver-priority return condition according with the first embodiment, the return condition determined by S202 further includes a system-priority return condition that is established when the failure in the handover to the driver continues and the failure in the driving system DS is eliminated.

[0070] Therefore, in S202, when the system-priority return condition that the failure in the handover to the driver continues and the failure in the driving system DS is eliminated is established in the second embodiment, the processing flow shifts to S205. In addition, when one of the complete return condition and the driver-priority return condition is established in S202, the processing flow shifts to the step corresponding to the one of S103 and S104, so the description is omitted hereinafter.

[0071] In S205, the determination block 120 plans the control action of the system-priority recovery by determining the system-priority recovery that prioritizes the recovery of the driving system DS over the handover to the driver without a handover to the driver as the driving recovery from the emergency operation of the host vehicle 2 by the driving system DS. In such a second embodiment, in addition to the nominal state of the full recovery destination according to S103, a state in which the nominal operation is restricted or degraded so that the handover to the driver is suspended or stopped (hereinafter referred to as a quasi-nominal state) becomes the recovery state for transitioning the driving system DS from the emergency operation state. Thereby, in S205, the control block 140 gives the driving return of the driving system DS to the quasi-nominal state by the control action planned by the determination block 120 to the host vehicle 2.

[0072] In S205, the determination block 120 further plans the notification of the system-priority recovery in which the automatic driving in the quasi-nominal state is started by the driving system DS in accordance with the driving return by the planned control action. The notification plan at this time may include the generation of notification data for notifying the driver in the host vehicle 2 of the system-priority recovery from the HMI device 80 among the information IF systems 8. The notification plan may include the generation of notification data for notifying a person outside the host vehicle 2 of the system-priority recovery from the external notification unit 82 among the information IF systems 8. The notification plan may include the generation of notification data for notifying the external center of the system-priority recovery by, for example, broadcast or the like transmitted from the communication system 6 to the outside of the host vehicle 2. The notification plan may include the generation of notification data for notifying the mobile terminal of the other road user 3 of the system-priority recovery by, for example, broadcast or the like transmitted from the communication system 6 to the outside of the host vehicle 2. In such S205, the control block 140 outputs the notification data of the system-priority recovery planned by the determination block 120 in the host vehicle 2.

[0073] Here, the notification of the system priority return to the outside of the host vehicle 2 may be executed in response to the determination block 120 generating notification data that can output visual stimuli. At this time, the notification of the system priority return by visual stimuli may be realized by setting the blinking pattern of the external notification unit 82 such as a hazard lamp to a different pattern or a common pattern from each case of full return and driver priority return. The notification of the driver priority return to the outside of the host vehicle 2 may be executed in response to the determination block 120 generating notification data that can output auditory stimuli. At this time, the notification of the system priority return by auditory stimuli may be realized by setting the operation pattern of the external notification unit 82 such as an electronic horn to a different pattern or a common pattern from each case of full return and driver priority return. In any case of these visual stimuli and auditory stimuli, the notification of the system priority return may be performed, for example, toward the rear outside the host vehicle 2 with directivity to other road users 3 who need the notification.

[0074] In the above, when the execution of S205 is completed, the processing flow returns to S102 so that the control of the driving return continues until the full return. However, in S205 when it is repeated after the return from S205 to S102, the planning and execution of the notification may be omitted when the time elapsed from the execution of the earliest S205 in the repetition exceeds the set time or becomes equal to or more than the set time. Also, in S205 when the full return condition is satisfied after the return from S205 to S102, the planning and execution of the notification may be omitted. Also in such a second embodiment, it is possible to contribute to the improvement of the response ability of other road users 3 based on the principle similar to that of the first embodiment.

[0075] (Third Embodiment) The third embodiment is a modification of the first embodiment. The processing flow according to the third embodiment is started, for example, in a situation where the host vehicle 2 is controlled to the level 3 automatic driving state by the driving system DS.

[0076] As shown in Fig. 6, in the processing flow of the third embodiment, S302, which replaces S102, is executed following S101. Specifically, the driving return determined by S302 uses only the elimination of failures in the handover of DDT to the driver as a trigger condition. That is, the driver-priority return condition described in the first embodiment will be included as the only return condition by S302 in the third embodiment.

[0077] Therefore, in the processing flow of the third embodiment, the execution of S103 is omitted, while the processing of S104 according to the establishment condition by S302 is executed with driver-priority return as the only driving return. Also in such a second embodiment, based on the principle similar to that of the first embodiment, it is possible to contribute to the improvement of the response ability of other road users 3.

[0078] (Fourth Embodiment) The fourth embodiment is a modification of the second embodiment. The processing flow according to the fourth embodiment is started, for example, in a situation where the host vehicle 2 is controlled to the level 3 automatic driving state by the driving system DS.

[0079] As shown in Fig. 7, in the processing flow of the fourth embodiment, S402, which replaces S202, is executed following S101. Specifically, the driving return determined by S402 uses at least the elimination of failures in the driving system DS as a trigger condition. That is, the return condition by S402 will include the complete return condition described in the first embodiment and the system-priority return condition described in the second embodiment.

[0080] Therefore, in the processing flow of the fourth embodiment, the execution of S104 is omitted, while the processing of S103 or S205 according to the establishment condition by S402 is executed. Also in such a fourth embodiment, based on the principle similar to that of the first embodiment, it is possible to contribute to the improvement of the response ability of other road users 3.

[0081] (Fifth Embodiment) The fifth embodiment is a modification of the fourth embodiment. The processing flow according to the fifth embodiment is started, for example, in a situation where the host vehicle 2 is controlled by the driving system DS to be in a level 4 or 5 automated driving state.

[0082] As shown in FIG. 8, in the processing flow according to the fifth embodiment, S500 and S502, which respectively replace S100 and S402, are executed. Specifically, the emergency operation determined by S500 uses only the occurrence of a failure in at least one physical element or functional block in the driving system DS as a trigger condition. That is, the occurrence of a failure in the physical element or functional block described in the first embodiment is included as the only condition for executing an emergency operation in the emergency condition determined by S500.

[0083] The driving resume determined by S502 after executing S100 in response to S500 uses only the elimination of a failure in the driving system DS as a trigger condition. That is, the complete system resume condition that is satisfied when the failure in the driving system DS is eliminated is included as the only resume condition by S502.

[0084] Therefore, in the processing flow of the fifth embodiment, the execution of S205 is omitted. On the other hand, according to the establishment condition by S502, the process of S103 is executed with the complete system resume equivalent to the complete resume as the only driving resume. However, the notification plan in this S103 may include the generation of notification data for notifying the driver in the host vehicle 2 having a manual driving function or the passengers in the host vehicle 2 having no manual function from the HMI device 80 among the information IF systems 8 of the complete system resume. Also in such a fifth embodiment, it is possible to contribute to improving the response ability of other road users 3 based on the principle similar to that of the first embodiment.

[0085] (Sixth Embodiment) The sixth embodiment is a modification of the first embodiment. The processing flow according to the sixth embodiment is started, for example, in a situation where the host vehicle 2 is controlled by the driving system DS to be in a level 3 automated driving state.

[0086] As shown in FIG. 9, in the processing flow according to the sixth embodiment, in S102, when the complete recovery condition that the failure of the driving system DS is resolved and the failure of the handover to the driver is resolved is satisfied, the processing flow proceeds to S6103.

[0087] In S6103, the determination block 120 determines whether or not a factor that requires restriction of the transition of the driving system DS to the nominal state as an external environmental factor of the host vehicle 2 has occurred even when each failure of the driving system DS and the handover has been resolved. Specifically, the external environmental factors determined by S6103 may be incidents that occur in the surrounding external environment of the host vehicle 2 and hinder the running of the vehicle 2, such as traffic accidents, natural disasters, road construction, the presence of a broken-down vehicle, the priority passage of an emergency vehicle, a system request from a police station or a fire station, driving restrictions, or the remaining of a fallen object. Here, the external environmental factors may be recognized by the recognition block 100 based on communication data from the external center 9a that also serves as the dedicated computer of the processing system 1 outside the host vehicle 2 shown in FIG. 10, or from an external center 9a different from the processing system 1, and determined by the determination block 120.

[0088] If a negative determination is made in S6103, that is, if the restriction of the transition of the driving system DS to the nominal state due to external environmental factors is not required, the processing flow proceeds to S103 based on the determination of complete recovery. Thereby, in S103, the determination block 120 plans the control action and notification of complete recovery as in the first embodiment for the driving recovery of the host vehicle 2 that has been emergently operated by the driving system DS.

[0089] On the other hand, when an affirmative determination is made in S6103, that is, when the transition of the driving system DS to the nominal state is restricted due to external environmental factors of the host vehicle 2, the processing flow shifts to S104 by changing the determination from full recovery to driver-priority recovery. As a result, in S104, the determination block 120 plans the control action and notification of driver-priority recovery as the driving recovery of the host vehicle 2 emergently operated by the driving system DS in the same manner as in the first embodiment.

[0090] However, in S104 of the sixth embodiment, as shown in FIG. 10, notification data for notifying driver-priority recovery for cooperation is generated for a control command given from the external center 9a communicating with the host vehicle 2 to the infrastructure unit 9b in the surrounding external environment of the vehicle 2. This means that the control command given from the external center 9a to the infrastructure unit 9b with the occurrence of external environmental factors, and the notification itself and / or the control action in driver-priority recovery to be notified by the notification data cooperate with each other in an interlocking manner.

[0091] Here, in the case of the traffic signal 9bs, the infrastructure unit 9b may control its lighting state to, for example, a state where traffic guidance is possible so as to cooperate with the notification and / or control action in the driver-priority recovery of the host vehicle 2 according to external environmental factors in accordance with the control command from the external center 9a. In the case of the digital signage 9bd, the infrastructure unit 9b may control the display content such as recommended actions so as to cooperate with the notification and / or control action in the driver-priority recovery of the host vehicle 2 according to external environmental factors in accordance with the control command from the external center 9a. In the case of the infrastructure camera 9bc, the infrastructure unit 9b may control its imaging state such as zoom setting so as to cooperate with the notification and / or control action in the driver-priority recovery of the host vehicle 2 according to external environmental factors in accordance with the control command from the external center 9a.

[0092] In S104 of the sixth embodiment, notification data for notifying driver-priority return may be generated as control requirement given from an external center 9a communicating with the host vehicle 2 to a mobile terminal of another road user 3 in the surrounding external environment of the host vehicle 2 for cooperation, for notifying driver-priority return for cooperation. In this case, in the mobile terminal, in accordance with the control requirement from the external center 9a, display content such as recommended actions may be controlled so as to cooperate with notification and / or control actions in driver-priority return of the host vehicle 2 according to external environmental factors.

[0093] In S104 of the sixth embodiment, notification data for notifying driver-priority return where full return is restricted by external environmental factors may be generated from the HMI device 80 among the information IF systems 8 to the driver in the host vehicle 2. At this time, the notification data may be output so as to enable visual stimulation or may be output so as to enable auditory stimulation.

[0094] Note that, as shown in the modification example in FIG. 11, the sixth embodiment described above may also be applied to the second embodiment.

[0095] (Other embodiments) Although a plurality of embodiments have been described above, the present disclosure is not construed as being limited to those embodiments, and can be applied to various embodiments and combinations without departing from the gist of the present disclosure.

[0096] In the modification, the dedicated computer that constitutes the processing system 1 may have at least one of a digital circuit and an analog circuit as a processor. Here, the digital circuit is, for example, at least one type among ASIC (application specific integrated circuit), FPGA (field programmable gate array), SOC (system on a chip), PGA (programmable gate array), and CPLD (complex programmable logic device). Further, such a digital circuit may have a memory storing a program.

[0097] In the modification, the driver who is an operator among the passengers in the host vehicle 2 may be replaced by a remote operator or a remote driver who remotely operates the host vehicle 2 at an external center. The host moving body to which the driving system DS and the processing system 1 are applied may be an autonomous driving robot capable of carrying luggage or collecting information by autonomous driving or remote driving in the modification related to the fifth embodiment. In addition to the above, the processing system 1 according to each embodiment and modification may be implemented in the form of a processing circuit (for example, a processing ECU, etc.) or a semiconductor device (for example, a semiconductor chip, etc.) configured to be mountable on a host moving body and having at least one of the processor 12 and the memory 10.

[0098] (Explanation of Terms) The terms related to the present disclosure will be explained below. This explanation is included in the embodiments of the present disclosure.

[0099] A road user may be a human who uses a road including a sidewalk and other adjacent spaces. The road user may be an active road user or a user of an adjacent road for the purpose of moving from one place to another.

[0100] Other road users may be vulnerable or non-vulnerable road users who do not perform the role of an automated vehicle.

[0101] The dynamic driving task (DDT) may be a real-time operating function and a tactical function for operating a vehicle in traffic.

[0102] The behavior of the host vehicle may be an interpretation of the vehicle movement in the traffic situation. Here, the vehicle movement may be the vehicle state and its dynamics captured in terms of physical quantities (e.g., speed, acceleration, etc.).

[0103] A scenario may be a description of the temporal relationship between some of the scenes within a series of scenes, including the goals and values in a specific situation affected by actions and events. A scenario may be a description of a continuous time-series activity that integrates the host vehicle, all of its external environments, and their interactions in the process of performing a specific driving task.

[0104] A situation is a factor that can affect the behavior of the system and may include the traffic situation, weather, and the behavior of the host vehicle.

[0105] A triggering condition may be a subsequent reaction of the system and may be a specific condition of the scenario that functions as a trigger for a reaction that contributes to the inability to prevent, detect, and mitigate dangerous behavior and reasonably foreseeable indirect misuse.

[0106] The operational design domain (ODD) may be specific conditions under which a given (automated) driving system is designed to function. The operational design domain may be operating conditions specifically designed for a given (automated) driving system or feature to function, including, but not limited to, environmental, geographical, and time restrictions, and / or the presence or absence of specific traffic or road characteristics.

[0107] The automated driving system may be an integrated set of hardware and software that can continuously execute the overall DDT regardless of whether it is limited to a specific ODD.

[0108] The safety of the intended functionality (SOTIF) may be the absence of undue risks resulting from functional inadequacies of the intended function or its implementation.

[0109] The driving policy may be a strategy and rules that define control actions at the vehicle level.

[0110] The vehicle level SOTIF strategy (VLSS) may be a set of requirements for the functions under development used to assist SOTIF-related design, verification, and validation activities.

[0111] An unreasonable risk may be a risk that is judged unacceptable in a particular situation according to reasonable social and moral concepts.

[0112] Safety-related models may be representations of safety-related aspects of driving behavior based on assumptions about the reasonably foreseeable behavior of other road users. Safety-related models may be on-board or off-board safety verification or safety analysis devices, mathematical models, more conceptual sets of rules, scenario-based sets of behavior, or combinations thereof.

[0113] A proper response may be an action that resolves a dangerous situation when other road users are acting according to assumptions about their reasonably foreseeable behavior.

[0114] The safe state may be a reasonably safe operating mode.

[0115] The minimal risk condition (MRC) may be the state of the vehicle to reduce the risk when a given trip cannot be completed. The minimal risk state may be the state of the vehicle brought by the user or the (automatic) driving system after performing the minimal risk manoeuvre to reduce the risk of collision when a given trip cannot be completed.

[0116] The minimal risk manoeuvre (MRM) may be a function of the (automatic) driving system that transitions between the nominal state and the minimal risk state.

[0117] The DDT fallback may be the response by the driver or the (automatic) driving system to perform a transition to DDT or MRC after the occurrence of a fault or the detection of functional inadequacy, or upon detection of potentially dangerous behavior.

[0118] The emergency manoeuvre may be an operation performed for the purpose of avoiding or reducing a collision in the event that the vehicle is in danger of collision.

[0119] The takeover may be the transfer of the driving task between the (automatic) driving system and the driver.

[0120] The driver may be the user who performs some or all of the DDT and / or DDT fallback of a specific vehicle in real time. The remote driver may be a driver who can operate the vehicle but is not sitting in a position where they can manually operate the in-vehicle brake, accelerator, steering, and transmission gear selection input devices.

[0121] The operator may be a designated person who has received appropriate training and authorization to operate the motor vehicle. A remote operator may be an operator who can operate the vehicle regardless of the presence or absence of direct vision, although not sitting in a position where they can manually operate the in-vehicle brake, accelerator, steering, and gear selection input device of the transmission.

[0122] (Addendum) This specification discloses a plurality of technical ideas listed below and combinations thereof.

[0123] (Technical Idea 1) A processing method executed by a processor (12) to perform processing related to the operation of a host moving body (2) in an operation system (DS), judging the return of driving of the host moving body from the emergency operation by the operation system, and notifying the return of driving outside the host moving body, the processing method comprising the above.

[0124] (Technical Idea 2) The judgment of the return of driving includes judging the return of driving by taking over to the operator of the host moving body, in the processing method according to Technical Idea 1.

[0125] (Technical Idea 3) The judgment of the return of driving includes judging the return of driving by taking over when the failure in the operation system continues and the failure in taking over to the operator in the host moving body is resolved, in the processing method according to Technical Idea 2.

[0126] (Technical Idea 4) The judgment of the return of driving includes judging the return of driving by transitioning the operation system to a recovery state from the emergency operation, in the processing method according to any one of Technical Ideas 1 to 3.

[0127] (Technical idea 5) The determination of the driving return includes, when the failure of the driving system is resolved and the failure of the handover to the operator in the host mobile body is resolved, determining the driving return by the transition of the driving system to the recovery state, as described in the processing method of Technical Idea 4.

[0128] (Technical idea 6) The determination of the driving return also includes, even when the failure of the driving system is resolved and the failure of the handover to the operator in the host mobile body is resolved, but the transition of the driving system to the recovery state is restricted by external environmental factors of the host mobile body, determining the driving return by the handover, as described in the processing method of Technical Idea 5.

[0129] (Technical idea 7) The determination of the driving return also includes, when the failure continues in the handover to the operator in the host mobile body and the failure of the driving system is resolved, determining the driving return by the transition of the driving system to the restricted or degraded recovery state, as described in any one of Technical Ideas 4 to 6.

[0130] (Technical idea 8) The notification of the driving return includes generating notification data for notifying the driving return by transmitting it outside the host mobile body, as described in any one of Technical Ideas 1 to 7.

[0131] (Technical idea 9) The notification of the driving return also includes generating notification data for notifying the driving return for cooperation with respect to a control command given from an external center (9a) communicating with the host mobile body to an infrastructure unit (9b) around the host mobile body, as described in any one of Technical Ideas 1 to 8.

[0132] (Technical idea 10) The notification of the driving return includes generating notification data for notifying the driving return by being output so as to be visually stimulable outside the host moving body, and the processing method according to any one of technical ideas 1 to 9 described above.

[0133] (Technical idea 11) The notification of the driving return includes generating notification data for notifying the driving return by being output so as to be aurally stimulable outside the host moving body, and the processing method according to any one of technical ideas 1 to 10 described above.

[0134] Note that the above-described technical ideas 1 to 11 may be realized in each form of a system and a program.

Explanation of symbols

[0135] 1: Processing system, 2: Host vehicle, 9a: External center, 9b: Infrastructure unit, 10: Memory, 12: Processor, DS: Driving system

Claims

1. A processing method executed by a processor (12) to perform processing related to the operation of a host mobile unit (2) in a driving system (DS), comprising: determining whether the host moving body, which has been operated in an emergency by the operating system, has returned to operation from the emergency operation; and notifying an outside of the host vehicle of the return to driving.

2. The decision to return to operation is made as follows: The method of claim 1 , further comprising determining said return to operation by handing over to an operator of said host vehicle.

3. The decision to return to operation is made as follows: The processing method according to claim 2 , further comprising: determining, when the fault in the operating system continues and the fault in the host mobile unit that prevents a handover to an operator is resolved, whether or not the operation is to be resumed by the handover.

4. The decision to return to operation is made as follows: The processing method according to any one of claims 1 to 3, further comprising determining the return to operation by transitioning the operation system to a recovery state from the emergency operation.

5. The decision to return to operation is made as follows: The processing method according to claim 4 , further comprising: determining whether to resume operation by transitioning the operating system to the recovery state when a fault in the operating system is resolved and a fault in handover to an operator in the host mobile body is resolved.

6. The decision to return to operation is made as follows: The processing method described in claim 5, further comprising: determining to return to operation by handover when an external environmental factor of the host mobile body restricts the transition of the operating system to the recovery state even when a fault in the operating system is resolved and a fault in the handover to an operator in the host mobile body is resolved.

7. The decision to return to operation is made as follows: The processing method of claim 4, further comprising: determining whether to resume operation by transitioning the operating system to a restricted recovery state when a failure in handover to an operator in the host mobile unit persists and the failure in the operating system is resolved.

8. The notification of the return to operation is The processing method according to any one of claims 1 to 3, further comprising generating notification data for notifying the return to driving by being transmitted outside the host mobile body.

9. The notification of the return to operation is The processing method according to any one of claims 1 to 3, further comprising generating notification data for notifying an infrastructure unit (9b) in the vicinity of the host mobile body of the return to operation in order to cooperate with a control command given from an external center (9a) communicating with the host mobile body to the infrastructure unit (9b) in the vicinity of the host mobile body.

10. The notification of the return to operation is The processing method according to any one of claims 1 to 3, further comprising generating notification data that notifies the return to driving by being outputted in a visually stimulating manner outside the host vehicle.

11. The notification of the return to operation is The processing method according to any one of claims 1 to 3, further comprising generating notification data that notifies the return to driving by being output in an auditory stimulable manner outside the host vehicle.

12. A driving system (DS) having a processor (12) and performing processing related to driving of a host mobile unit (2), determining whether the host moving body, which has been operated in an emergency by the operating system, has returned to operation from the emergency operation; and notifying an outside of the host vehicle of the return to driving.

13. A processing program including instructions stored in a storage medium (10) and executed by a processor (12) to perform processing related to the operation of a host vehicle (2) in a driving system (DS), The instruction: determining whether or not the host moving body, which has been operated in an emergency by the operating system, has returned to operation after the emergency operation; and notifying an outside of the host vehicle of the return to driving.

Citation Information

Patent Citations

  • Vehicle control device and vehicle control method

    JP2019021229A

  • Vehicle control system

    JP2020164017A

  • Vehicle control device, vehicle control method, and program

    JP2021049872A

  • Copying machine

    JP1988031975A