Autonomous driving device, vehicle control method

By having the map management department assess the map data acquisition status and adjust the control plan, the problem of user confusion caused by incomplete or mismatched map data was resolved, thus improving the safety and user experience of autonomous driving.

CN115769287BActive Publication Date: 2026-05-08DENSO CORP
View PDF 8 Cites 0 Cited by

Patent Information

Authority / Receiving Office
CN · China
Patent Type
Patents(China)
Current Assignee / Owner
DENSO CORP
Filing Date
2021-07-06
Publication Date
2026-05-08

AI Technical Summary

Technical Problem

In autonomous driving, incomplete map data or mismatch with the real world makes it impossible to calculate potential accident liability values, affecting the planner's safety assessment and resulting in a poor user experience.

Method used

The map management department determines the map data acquisition status and adjusts the control plan accordingly, providing an autonomous driving device and vehicle control method to ensure that users can perceive the warning signs of autonomous driving interruption and reduce user confusion.

Benefits of technology

By dynamically adjusting the control plan, user confusion caused by incomplete or mismatched map data is reduced, improving the safety and user experience of autonomous driving.

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure CN115769287B_ABST
    Figure CN115769287B_ABST
Patent Text Reader

Abstract

The present application relates to an automatic driving device, a vehicle control method. The automatic driving device (20) is configured to download partial map data corresponding to a current position from a map server (3) and create a control plan. In a case where next area map data, which is partial map data related to entry into a predetermined area within a prescribed time, cannot be acquired due to a poor communication condition or the like, the automatic driving device (20) calculates a map acquisition remaining time. The map acquisition remaining time corresponds to a remaining time until a timing at which the next area map data is actually needed when automatic driving is continued. The automatic driving device (20) plans and executes, as an extraordinary action, a notification to an occupant, a speed suppression process, or the like based on the map acquisition remaining time being less than a prescribed threshold.
Need to check novelty before this filing date? Find Prior Art

Description

[0001] Cross-reference to related applications

[0002] This application is based on Japanese Patent Application No. 2020-117903, filed in Japan on July 8, 2020, the contents of which are incorporated herein by reference in their entirety. Technical Field

[0003] This disclosure relates to techniques for using map data to generate control plans for autonomous vehicles. Background Technology

[0004] Patent document 1 discloses the following structure: In autonomous driving, a mathematical formula model called RSS (Responsibility Sensitive Safety) model and map data are used to generate a vehicle driving plan, in other words, a control plan.

[0005] In the RSS model, the planner, as a functional module for developing control plans, uses map data to calculate the potential accident liability value for each of the multiple control plans, and adopts the control plan whose potential accident liability value is within the allowable range. The potential accident liability value is a parameter representing the degree of responsibility of the vehicle in the event of an accident between the vehicle and surrounding vehicles. The potential accident liability value takes into account whether the inter-vehicle distance between the vehicle and surrounding vehicles is shorter than a safe distance determined based on road structure, etc.

[0006] Patent Document 1: International Publication No. 2018 / 115963

[0007] The RSS model assumes that vehicles possess map data. It assumes that if vehicles maintain up-to-date map data for all areas, it's unlikely that incomplete maps, such as missing or degraded data, would prevent the calculation of potential accident liability values. However, from the perspectives of data capacity and communication frequency, it's difficult for vehicles to consistently maintain up-to-date map data for all areas.

[0008] For this reason, it is assumed that the vehicle downloads and uses a partial map structure from the map server each time, relating to a local area corresponding to its current location. However, in the process of downloading and using partial maps, situations may arise where, due to communication errors, download errors, system processing errors, etc., partial map data for the area required for calculating potential accident liability values ​​cannot be obtained.

[0009] Furthermore, there may be situations where the map data distributed by the map server does not match the real-world environment due to changes in the environment. In cases where map data is unavailable or does not match the real world, the planner cannot calculate appropriate potential accident liability values. Moreover, because a planner using the RSS model cannot quantitatively evaluate the safety of each control plan when potential accident liability values ​​cannot be calculated, there are concerns that autonomous driving may not be able to continue.

[0010] On the other hand, it is assumed that ordinary users are unaware of the map acquisition status used for autonomous driving in vehicles. Therefore, interruptions in autonomous driving based on incomplete map data may be undesirable to users, or in other words, unexpected. As a result, it may confuse users. Summary of the Invention

[0011] This disclosure is made in light of this situation, and its purpose is to provide an autonomous driving device and vehicle control method that can reduce user confusion and anxiety.

[0012] As an example, an autonomous driving device for achieving this purpose is an autonomous driving device that uses map data to create a control plan that enables the vehicle to drive autonomously, comprising: a map management unit that determines the map data acquisition status; and a control plan unit that uses the map data to create a control plan, wherein the control plan unit is configured to modify the content of the control plan according to the map data acquisition status determined by the map management unit.

[0013] Based on the above structure, the control plan, or in other words, the vehicle's behavior, changes according to the map acquisition status. Therefore, users can perceive warning signs of a potential interruption in autonomous driving based on whether the vehicle's behavior is consistent with normal conditions. As a result, it reduces user confusion and anxiety.

[0014] Furthermore, the vehicle control method for achieving the above objectives is a vehicle control method executed by at least one processor for enabling a vehicle to drive autonomously using map data, comprising:

[0015] The map management step determines the map data acquisition status; and the control plan step uses the map data to create a vehicle control plan, wherein the control plan step is configured to modify the content of the control plan based on the map data acquisition status determined in the map management step.

[0016] Based on the method described above, the same effect as disclosing information about autonomous driving devices can reduce concerns that confuse users.

[0017] Furthermore, the reference numerals in parentheses in the claims indicate the correspondence between specific units described in the embodiments described later as an example, and do not limit the technical scope of this disclosure. Attached Figure Description

[0018] Figure 1 This is a diagram schematically representing the overall structure of the autonomous driving system 100.

[0019] Figure 2 This is a diagram used to illustrate the structure of the vehicle-mounted system 1.

[0020] Figure 3 This is an example of an icon image representing the status of map data acquisition.

[0021] Figure 4 This is a diagram used to illustrate the structure of the automatic driving device 20.

[0022] Figure 5 This diagram is used to explain the work of the map management department, F5.

[0023] Figure 6 This diagram is used to explain the operation of the matching determination unit F51.

[0024] Figure 7 This is a flowchart used to explain the operation of the matching determination unit F51.

[0025] Figure 8 This is a flowchart explaining how to handle situations where a map is not acquired.

[0026] Figure 9 This is a flowchart used to illustrate how to handle mismatches.

[0027] Figure 10 This diagram illustrates the work of the control planning department F7 in situations where the concept of urgency is applied.

[0028] Figure 11 This is a diagram representing variations of the content of extraordinary actions at each urgency level.

[0029] Figure 12 This is a flowchart used to explain the procedures for ending an emergency operation.

[0030] Figure 13 This is a diagram illustrating an example of a process that uses saved map data.

[0031] Figure 14 This is a diagram illustrating an example of a process where map data is re-downloaded if the saved map data contradicts the real world.

[0032] Figure 15 This is another example of a process that uses saved map data.

[0033] Figure 16 This is a diagram illustrating an example of a process that changes the upper limit speed setting used to control the plan based on whether the map data used for control is saved.

[0034] Figure 17 This is a diagram illustrating an example of the processing flow for determining the matching results between notification map data and the real world.

[0035] Figure 18 This is a diagram illustrating an example of a process flow that changes control based on the distance from which a real-time map can be created.

[0036] Figure 19 This diagram illustrates an example of a process that executes a handover request based on approaching or distributing a restricted area. Detailed Implementation

[0037] The implementation of the automated driving device of this disclosure will be described with reference to the accompanying drawings. Furthermore, the following description will use an area where left-hand traffic is permitted as an example. In areas where right-hand traffic is permitted, appropriate modifications can be made, such as reversing the left and right directions in the following description. The content of this disclosure can be appropriately modified and implemented to comply with the laws and customs of the areas where the automated driving system 100 is used.

[0038] Hereinafter, embodiments of the present disclosure will be described using the accompanying drawings. Figure 1 This is a diagram illustrating an example of the schematic structure of the autonomous driving system 100 of this disclosure. (See diagram for example.) Figure 1 As shown, the autonomous driving system 100 includes an in-vehicle system 1 and a map server 3 built into the vehicle Ma. The in-vehicle system 1 wirelessly communicates with the map server 3 to download local high-precision map data, i.e., partial map data, from the map server 3 for autonomous driving and navigation.

[0039] The vehicle system 1 can be mounted on any road-going vehicle, Ma, which can be a four-wheeled car, a two-wheeled car, a three-wheeled car, etc. Motorized bicycles can also be included in two-wheeled vehicles. Vehicle Ma can be a privately owned vehicle, or a shared vehicle or service vehicle. Service vehicles include taxis, scheduled buses, and ride-sharing buses. Vehicle Ma can also be a driverless robot taxi or a driverless bus. Vehicle Ma can also be configured to be remotely operated by an external operator in the event of difficulties with autonomous driving. Here, the operator refers to a person with the authority to remotely control the vehicle from outside the vehicle, such as a designated center. The operator can also include the concept of a driver / driver's seat passenger. Furthermore, the operator can also be a server or software capable of determining driving operations appropriate to the scenario based on artificial intelligence.

[0040] <About map data>

[0041] Here, we will first explain the map data held by map server 3. The map data is equivalent to map data that represents the road structure with a precision that can be used for autonomous driving, as well as the position coordinates of ground objects placed along the road.

[0042] Map data includes node data, link data, and surface feature data. Node data consists of various data such as node ID (with a unique number assigned to each node on the map), node coordinates, node name, node type, and link ID (description of the link connecting to the node).

[0043] Link data refers to road sections, or links, that connect nodes to each other. Link data consists of various data, including a link ID (a unique identifier for each link), link length (representing the link's length), link orientation, link travel time, link shape information (hereinafter, link shape), coordinates of the starting and ending nodes of the link, and road attributes. Link shape can also be represented by a coordinate column showing the coordinates of the two ends of the link and the shape interpolation points representing the shape between the two ends. Link shape is equivalent to road shape. Link shape can also be represented by a cubic spline curve. Road attributes include road name, road type, road width, lane number information (representing the number of lanes), speed limit, etc. Link data can also be described in detail by each lane. Map data can also contain road link data, which is equivalent to a collection of link data for road units with lanes traveling in the same direction, and lane link data, which is equivalent to lower-level link data for each lane. Link data can be subdivided not only by road sections but also by lanes.

[0044] The ground feature data includes boundary line data and landmark data. Boundary line data includes the boundary line ID for each boundary line and a set of coordinate points representing the location. Boundary line data includes pattern information such as dashed lines, solid lines, and road studs. Boundary line data is associated with lane information such as lane IDs and link IDs under lane levels. Landmarks are ground features that can be used as markers to determine the location of a vehicle on a map. Landmarks include prescribed three-dimensional structures positioned along roads. Three-dimensional structures positioned along roads include, for example, guardrails, curbs, trees, utility poles, road signs, and traffic lights. Road signs include directional signs, road name signs, and other guiding signs. Furthermore, road ends and boundary lines can also be included in landmarks. Landmark data indicates the location and type of each landmark. The shape and location of each ground feature are represented by a set of coordinate points. Points of Interest (POI) data represents the location and type of above-ground features that affect vehicle travel plans, such as branching points, merging points, speed limit change points, lane change points, traffic congestion zones, construction zones, intersections, tunnels, and toll plazas. POI data includes both type and location information.

[0045] Map data can also be 3D map data containing point sets of feature points of road shapes and structures. 3D map data is equivalent to map data that uses 3D coordinates to represent the positions of road ends, lane dividers, road signs, and other ground features. Furthermore, 3D maps can also be generated based on captured images using REM (Road Experience Management). Additionally, map data can include driving trajectory models. Driving trajectory models are trajectory data generated by statistically aggregating the driving trajectories of multiple vehicles. For example, a driving trajectory model is generated by averaging the driving trajectories of each lane. A driving trajectory model is essentially data representing the reference driving trajectory used in autonomous driving.

[0046] Map data may contain both static and quasi-static map information. Static map information refers to information about road networks, road shapes, road surface displays, structures such as guardrails, and buildings—topographical features that are unlikely to change. Static map information can also be understood as information about topographical features that require updates within one week to one month. Static map information is also known as the base map. Quasi-static map information, for example, is information that requires updates within one hour to several hours. Road construction information, traffic control information, traffic congestion information, and wide-area weather information are equivalent to quasi-static map information. For example, the map data processed by map server 3 includes both static and quasi-static map information. Of course, map server 3 may also process only static map information.

[0047] Map server 3 possesses all map data corresponding to the entire map-covered area. However, all map data is divided into multiple smaller blocks for management. Each smaller block represents map data for a different region. For example, as... Figure 1 As shown, map data is stored in units of rectangular blocks, each 2km square, dividing the map's coverage area. Furthermore, Figure 1 The dashed lines conceptually represent the boundaries of map tiles. A map tile is equivalent to the sub-concept of the smaller tiles mentioned above.

[0048] Each map tile is assigned information representing the real-world region it corresponds to. This information includes latitude, longitude, and altitude. Additionally, each map tile is assigned a unique ID (hereinafter, tile ID). Map tiles are associated with the tile IDs of adjacent regions, i.e., neighboring tile IDs. Neighboring tile IDs may be used to determine the next area's map data, etc. The map data for each small tile, or each map tile, is a part of the overall map coverage area; in other words, it is local map data. A map tile is equivalent to a portion of the map data. Map server 3 distributes partial map data corresponding to the location of vehicle system 1 based on requests from vehicle system 1.

[0049] The shape of map tiles is not limited to a 2km square rectangle. They can also be 1km or 4km square rectangles. Additionally, map tiles can be hexagonal, circular, etc. Each map tile can also be configured to partially overlap with adjacent map tiles. The map coverage area can be the entire country where vehicles are used, or it can be just a portion of the region. For example, the map coverage area could be only an area where autonomous driving by regular vehicles is permitted, or a region providing autonomous driving mobility services.

[0050] Furthermore, the size and shape of multiple map tiles can be inconsistent. For example, map tiles in rural areas, where the density of map features such as landmarks is relatively sparse, can be set larger than map tiles in urban areas, where the density of map features such as landmarks is relatively high. For example, rural map tiles could be 4km square rectangles, while urban map tiles could be 1km or 0.5km square rectangles. Here, urban areas refer to areas with a population density above a certain value, or areas with a concentration of offices and commercial facilities. Rural areas can be areas other than urban areas. Rural areas can also be replaced with rural areas.

[0051] Furthermore, the method of segmenting all map data can also be specified based on the data size. In other words, the map coverage area can be segmented and managed using a range defined by the data size. In this case, each small patch is set to have a data size smaller than a specified value. This method ensures that the data size in a single distribution is below a certain value.

[0052] <Schematic structure of vehicle system 1>

[0053] Here, use Figure 2 The structure of vehicle-mounted system 1 will be described. Figure 2 The in-vehicle system 1 shown is used in vehicles capable of autonomous driving (hereinafter, autonomous vehicles). For example... Figure 2 As shown, the vehicle system 1 includes a surrounding monitoring sensor 11, a vehicle status sensor 12, a locator 13, a V2X onboard unit 14, an HMI system 15, a driving actuator 16, a running recorder 17, and an autonomous driving device 20. Furthermore, HMI in the component names stands for Human Machine Interface. V2X stands for Vehicle to X (Everything), referring to communication technology that connects vehicles to various things.

[0054] The various devices or sensors constituting the vehicle system 1 described above are connected as nodes to a communication network constructed within the vehicle, namely the in-vehicle network Nw. Nodes connected to the in-vehicle network Nw can communicate with each other. Furthermore, specific devices can also be configured to communicate directly without going through the in-vehicle network Nw. For example, the automatic driving device 20 and the operation recording device 17 can also be directly electrically connected via a dedicated line. Additionally, in Figure 2 The in-vehicle network (Nw) is configured as a bus topology, but is not limited to this. Network topologies can also be mesh, star, ring, etc. The network shape can be appropriately modified. Standards for in-vehicle networks (Nw) can include various standards such as Controller Area Network (CAN: registered trademark), Ethernet (Ethernet is a registered trademark), and FlexRay (registered trademark).

[0055] Hereinafter, the vehicle equipped with the vehicle system 1 will also be referred to as vehicle Ma, and the occupant sitting in the driver's seat of vehicle Ma (i.e., the driver's seat occupant) will also be referred to as the user. Furthermore, the front-rear, left-right, and up-down directions in the following description are defined based on vehicle Ma. Specifically, the front-rear direction corresponds to the long side direction of vehicle Ma. The left-right direction corresponds to the width direction of vehicle Ma. The up-down direction corresponds to the height direction of the vehicle. According to other viewpoints, the up-down direction corresponds to the direction perpendicular to a plane parallel to the front-rear and left-right directions.

[0056] This vehicle (Ma) simply needs to be a vehicle capable of autonomous driving. The degree of autonomous driving (hereinafter, automation level) can vary, for example, as defined by the Society of Automotive Engineers (SAE International). For instance, in SAE's definition, automation levels are divided into levels 0 through 5 as follows.

[0057] Level 0 is the level where the system does not intervene and the driver performs all driving tasks. Driving tasks include, for example, steering and acceleration / deceleration. Level 0 is equivalent to the so-called fully manual driving level. Level 1 is the level where the system assists with either steering or acceleration / deceleration. Level 2 refers to the level where the system assists with multiple aspects of steering and acceleration / deceleration. Levels 1 and 2 are equivalent to the so-called driver assistance levels.

[0058] Level 3 refers to a level where the system performs all driving operations within the Operational Design Domain (ODD), but in emergencies, operational authority is transferred from the system to the driver. The ODD, for example, defines an area where conditions allow for automated driving, such as driving on a highway. At Level 3, the driver / occupant is required to respond quickly to a request for driving over from the system. Alternatively, an operator outside the vehicle can take over driving operations instead of the driver / occupant. Level 3 is equivalent to conditional automated driving. Level 4 is a level where the system can perform all driving tasks except in specific situations such as roads that are unmanageable or extreme environments. Level 4 is equivalent to a level where the system performs all driving tasks within the ODD. Level 4 is equivalent to highly automated driving. Level 5 is a level where the system can perform all driving tasks in all environments. Level 5 is equivalent to fully automated driving. Levels 3-5 are equivalent to automated driving. Levels 3-5 can also be referred to as autonomous driving levels that automatically execute all controls involved in vehicle operation.

[0059] The level of "automatic driving" as used in this disclosure can be equivalent to, for example, level 3 or level 4 or higher. The following explanation will use the example of the vehicle Ma performing at least level 3 or higher of automatic driving. Furthermore, the level of automation for the driving mode of the vehicle Ma can be switched. For example, it is possible to switch between automatic driving mode at level 3 or higher, driving assistance mode at levels 1-2, and manual driving mode at level 0.

[0060] The perimeter monitoring sensor 11 is a sensor that monitors the surroundings of the vehicle. The perimeter monitoring sensor 11 is configured to detect the presence and location of specified objects. These objects include, for example, moving bodies such as pedestrians and other vehicles. Other vehicles include bicycles, motorized bicycles, and motorcycles. Furthermore, the perimeter monitoring sensor 11 is also configured to detect specified ground objects and obstacles. Ground objects detected by the perimeter monitoring sensor 11 include road ends, road markings, and three-dimensional structures along the road. Road markings refer to paint applied to the road surface for traffic control and regulation. Examples include lane dividers, pedestrian crossings, stop lines, lane dividers, safety zones, and traffic control arrows. Lane dividers are also called lane markings or lane markers. Lane dividers also include lane lines defined by road studs such as vibration strips and road spikes. As mentioned above, three-dimensional structures along the road include, for example, guardrails, road signs, and traffic lights. In other words, the perimeter monitoring sensor 11 is preferably configured to detect ground objects. Here, obstacles refer to three-dimensional objects existing on the road that impede the passage of vehicles. Obstacles include accident vehicles, debris from accident vehicles, etc. Additionally, obstacle categories may include lane-limiting materials and equipment such as arrow signs, traffic cones, and guide boards; construction sites; parked vehicles; and the end of traffic congestion. The surrounding monitoring sensor 11 can also be configured to detect road debris such as tires that have detached from vehicles.

[0061] As a peripheral surveillance sensor 11, for example, a peripheral surveillance camera, millimeter-wave radar, LiDAR, sonar, etc., can be used. LiDAR is short for Light Detection and Ranging or Laser Imaging Detection and Ranging. Furthermore, millimeter-wave radar is a device that detects the relative position and relative velocity of an object relative to the vehicle Ma by transmitting millimeter waves or quasi-millimeter waves in a specified direction and analyzing the received data of the reflected waves returned by the object. For example, millimeter-wave radar generates data representing the received intensity and relative velocity for each detection direction and each distance, or data representing the relative position of the detected object and the received intensity as detection results. LiDAR is a device that generates three-dimensional point data representing the position of the reflection point in each detection direction by illuminating a laser.

[0062] A perimeter surveillance camera is an onboard camera configured to capture images of the vehicle's exterior in a specified direction. The perimeter surveillance camera includes a front camera positioned on the upper part of the interior side of the windshield, the front grille, etc., to capture images of the area in front of the vehicle. The front camera uses a detector, for example, to detect the aforementioned objects, where the detector employs CNN (Convolutional Neural Network), DNN (Deep Neural Network), or similar methods.

[0063] Alternatively, the object recognition processing based on the observation data generated by the peripheral monitoring sensors 11 can be performed by an ECU (Electronic Control Unit) other than the sensors in the autonomous driving device 20. The autonomous driving device 20 may also possess some or all of the object recognition functions of the peripheral monitoring sensors 11, such as a front-facing camera or millimeter-wave radar. In this case, the various peripheral monitoring sensors 11 can provide observation data such as image data and ranging data to the autonomous driving device 20 as detection result data.

[0064] The vehicle status sensor 12 is a group of sensors that detects state quantities related to the driving control of the vehicle Ma. The vehicle status sensor 12 includes a vehicle speed sensor, a steering input sensor, an acceleration sensor, and a yaw rate sensor. The vehicle speed sensor detects the vehicle speed. The steering input sensor detects the vehicle's steering angle. The acceleration sensor detects the vehicle's longitudinal acceleration, lateral acceleration, and other accelerations. The acceleration sensor can also detect deceleration as a negative acceleration. The yaw rate sensor detects the vehicle's angular velocity. Furthermore, the types of sensors used by the onboard system 1 as the vehicle status sensor 12 can be appropriately designed; it is not necessary to have all of the aforementioned sensors.

[0065] The locator 13 is a device that generates high-precision location information for the vehicle Ma by combining multiple pieces of information for composite positioning. The locator 13 is configured, for example, using a GNSS receiver. A GNSS receiver is a device that sequentially detects its current position by receiving navigation signals transmitted from positioning satellites constituting a GNSS (Global Navigation Satellite System). For example, if the GNSS receiver can receive navigation signals from four or more positioning satellites, it outputs the positioning result every 100 milliseconds. GNSS types that can be used include GPS, GLONASS, Galileo, IRNSS, QZSS, Beidou, etc.

[0066] The locator 13 sequentially determines the position of its vehicle Ma by combining the positioning results from the GNSS receiver with the output of the inertial sensor. For example, in situations where the GNSS receiver cannot receive GNSS signals, such as in a tunnel, the locator 13 uses yaw rate and vehicle speed for dead reckoning (i.e., autonomous navigation). The yaw rate used for dead reckoning can be calculated using SfM technology via a forward-facing camera, or it can be detected by a yaw rate sensor. The locator 13 can also use the output of an accelerometer or gyroscope sensor for dead reckoning. The vehicle position is represented, for example, by three-dimensional coordinates of latitude, longitude, and altitude. The located vehicle position information is output to the in-vehicle network Nw, which is used by the autonomous driving device 20, etc.

[0067] Furthermore, the locator 13 can also be configured to perform positioning processing. Positioning processing refers to the process of determining the detailed location of the vehicle Ma by comparing the coordinates of landmarks determined based on images captured by surrounding surveillance cameras such as a front-facing camera with the coordinates of landmarks registered in map data. Landmarks include, for example, traffic signs, traffic lights, utility poles, commercial signs, and other three-dimensional structures along the road. Additionally, the locator 13 can also be configured to determine a lane ID, which identifies the lane in which the vehicle Ma is traveling, based on the distance from the end of the road detected by a front-facing camera or millimeter-wave radar. The lane ID, for example, indicates which lane the vehicle Ma is traveling in from the left or right end of the road. The autonomous driving device 20 may also possess some or all of the functions of the locator 13. The lane in which the vehicle Ma is traveling can be referred to as the vehicle lane.

[0068] The V2X vehicle-to-everything (V2X) unit 14 is a device for enabling wireless communication between the vehicle Ma and other devices. Furthermore, in V2X, "V" refers to the vehicle Ma, and "X" may refer to various entities other than the vehicle Ma, such as pedestrians, other vehicles, road equipment, networks, servers, etc. The V2X vehicle-to-everything (V2X) unit 14 includes a wide-area communication unit and a narrow-area communication unit as communication modules. The wide-area communication unit is a communication module used to implement wireless communication conforming to a prescribed wide-area wireless communication standard. Here, the wide-area wireless communication standard can be, for example, various standards such as LTE (Long Term Evolution), 4G, and 5G. In addition to communication via a wireless base station, the wide-area communication unit can also be configured to enable direct, in other words, wireless communication with other devices without a base station, in a manner conforming to the wide-area wireless communication standard. That is, the wide-area communication unit can also be configured to implement cellular V2X. The vehicle Ma, by equipping itself with the V2X vehicle-to-everything (V2X) unit 14, becomes a connected vehicle capable of connecting to the Internet. For example, the autonomous driving device 20, in cooperation with the V2X onboard unit 14, downloads the latest partial map data corresponding to the current location of the vehicle Ma from the map server 3. The V2X onboard unit 14 is equivalent to a wireless communication device.

[0069] The narrow-range communication unit of the V2X vehicle-to-everything (V2X) device 14 is a communication module used to directly communicate wirelessly with other mobile entities and roadside equipment located around the vehicle Ma, based on a narrow-range communication standard that limits the communication distance to within a few hundred meters. These other mobile entities are not limited to vehicles but can include pedestrians, bicycles, etc. The narrow-range communication standard can be various standards such as WAVE (Wireless Access in Vehicular Environment) and DSRC (Dedicated Short Range Communications). The narrow-range communication unit broadcasts vehicle information about the vehicle Ma to surrounding vehicles at a predetermined transmission period and receives vehicle information from other vehicles. The vehicle information includes vehicle ID, current location, direction of travel, speed, the status of the direction indicator, and a timestamp.

[0070] HMI system 15 is a system that provides an input interface for accepting user operations and an output interface for providing information to the user. HMI system 15 includes a display 151 and an HCU (HMI Control Unit) 152. In addition to the display 151, other means of providing information to the user may include a speaker, a vibrator, or a lighting device (such as an LED).

[0071] Display 151 is a device for displaying images. Display 151 may be, for example, a central display located in the center of the dashboard in the vehicle width direction. Display 151 is capable of full-color display and can be implemented using liquid crystal displays, OLED (Organic Light Emitting Diode) displays, plasma displays, etc. Furthermore, the HMI system 15 may also include a head-up display (HUD) that projects a virtual image onto a portion of the windshield in front of the driver's seat as display 151. Display 151 may also be an instrument cluster display.

[0072] HCU152 is a structure that centrally controls the information prompts to the user. HCU152 is implemented using processors such as CPU (Central Processing Unit) and GPU (Graphics Processing Unit), RAM, and flash memory. HCU152 controls the display screen of display 151 based on control signals input from the autonomous driving device 20 and signals from input devices not shown. For example, based on a request from the autonomous driving device 20, HCU152 displays on display 151 the following: Figure 3 The map icon 80 shown represents the acquisition status of a portion of the map data. Figure 3 (A) shows an example of the Map Not Acquired icon 80A, indicating a state where partial map data could not be downloaded. Figure 3 (B) shows an example of the map acquisition icon 80B, indicating that the download of part of the map data was successful. Figure 3 (C) shows an example of a map acquisition icon 80C representing the download of partial map data. The destination displayed by map icon 80 can be, for example, the upper corner of the display 151.

[0073] The driving actuator 16 is a type of actuator used for driving. The driving actuator 16 may include, for example, a brake actuator as a braking device, an electronic throttle, and a steering actuator. The steering actuator may also include an EPS (Electric Power Steering) motor. The driving actuator 16 is controlled by the automatic driving device 20. Furthermore, a steering control ECU for steering control, a power unit control ECU for acceleration / deceleration control, and a brake ECU may be sandwiched between the automatic driving device 20 and the driving actuator.

[0074] The operation recording device 17 is a device that records data representing at least one aspect of the conditions inside and outside the vehicle while the vehicle is in motion. The conditions inside the vehicle while the vehicle is in motion can include the operating state of the autonomous driving device 20 and the state of the driver and passenger. The data representing the operating state of the autonomous driving device 20 also includes the recognition results of the surrounding environment in the autonomous driving device 20, the driving plan, and the calculation results of the target control quantities of each driving actuator. Additionally, images capturing the display screen of the display 151, i.e., screenshots, can also be included in the recording. The data to be recorded is acquired from the autonomous driving device 20, the surrounding monitoring sensor 11, and other ECUs and sensors mounted on the vehicle via the in-vehicle network Nw, etc. When a predetermined recording event occurs, the operation recording device 17 records various data within a predetermined time period before and after the time of the event. Recording events can include, for example, the transfer of driving operation privileges, the exit of the ODD, the implementation of emergency actions (described later), changes in the automation level, and the execution of MRM (Minimum Risk Maneuver). For example, if the autonomous driving device 20 performs an emergency action, the operation recording device 17 saves data that can determine the portion of map data acquired at that moment. This data, which can determine the portion of map data acquired, includes, for example, block IDs, version information, and acquisition time. The data can be recorded on a non-volatile storage medium installed in the vehicle Ma, or on an external server.

[0075] The autonomous driving device 20 controls the driving actuator 16 based on detection results from surrounding monitoring sensors 11, etc., to perform part or all of the driving operations in place of the driver or passenger via an ECU (Electronic Control Unit). Here, as an example, the autonomous driving device 20 is configured to perform up to automation level 5 and to switch between operating modes corresponding to each automation level. For convenience, the operating modes corresponding to automation levels N (N = 0 to 5) will also be referred to as Level N modes. For example, Level 3 mode refers to the operating mode that implements control equivalent to automation level 3.

[0076] The following explanation assumes that the vehicle operates in an automation level of 3 or higher. In a driving mode of 3 or higher, the automatic driving system 20 automatically performs steering, acceleration, and deceleration (in other words, braking) of the vehicle, causing the vehicle Ma to travel along the road to the destination set by the driver or operator. In addition to user operation, the driving mode is automatically switched due to system limits, ODD exit, etc.

[0077] The autonomous driving device 20 is primarily composed of a computer including a processing unit 21, RAM 22, memory 23, a communication interface 24, and a bus connecting them. The processing unit 21 is hardware for computational processing in conjunction with RAM 22. The processing unit 21 has a structure that includes at least one processing core such as a CPU. The processing unit 21 executes various processes to implement the functions of the functional units described later by accessing RAM 22. The memory 23 has a structure including a non-volatile storage medium such as flash memory. The memory 23 stores an autonomous driving program, which is a program executed by the processing unit 21. The processing unit 21 executing the autonomous driving program is equivalent to executing the method corresponding to the autonomous driving program as a vehicle control method. The communication interface 24 is a circuit for communicating with other devices via the vehicle's internal network Nw. The communication interface 24 can be implemented using analog circuit elements, ICs, etc. Detailed information about the autonomous driving device 20 will be described later.

[0078] <Regarding the structure of the automatic driving device 20>

[0079] Here, use Figure 4 The functions and operation of the autonomous driving device 20 are explained. The autonomous driving device 20 provides corresponding services by executing the autonomous driving program stored in the storage 23. Figure 4 The functions of the various functional modules shown are as follows: Specifically, the autonomous driving device 20 includes a vehicle location acquisition unit F1, a sensor information acquisition unit F2, a vehicle status acquisition unit F3, a map acquisition unit F4, a map management unit F5, a driving environment recognition unit F6, a control planning unit F7, and a control signal output unit F8 as functional modules. The map management unit F5 includes a matching determination unit F51 as a sub-function, and the control planning unit F7 includes a responsibility value calculation unit F71, a safe distance setting unit F72, and an action decision unit F73 as sub-functions. Additionally, the autonomous driving device 20 includes a map holding unit M1.

[0080] The vehicle position acquisition unit F1 obtains the current position coordinates of the vehicle Ma from the locator 13. Furthermore, the vehicle position acquisition unit F1 can also be configured to read the latest vehicle position information stored in a non-volatile memory as the current position information after the vehicle's driving power is turned on. The latest position calculation result stored in the memory corresponds to the end point of the previous trip, i.e., the parking position. A trip refers to a series of movements from when the driving power is turned on to when it is turned off. In addition, to perform the above processing, the automatic driving device 20 can preferably be configured to store the vehicle position information observed at the time of parking in a non-volatile memory as a shutdown process after parking. Here, the driving power is the power supply used for vehicle operation; in the case of a gasoline vehicle, it refers to the ignition power supply. Furthermore, in the case of an electric vehicle or a hybrid vehicle, the system main relay corresponds to the driving power supply.

[0081] The sensor information acquisition unit F2 acquires the detection results (i.e., sensor information) from the surrounding monitoring sensor 11. The sensor information includes the position and speed of other moving objects, ground objects, obstacles, etc., existing around the vehicle Ma. For example, it includes the distance between the vehicle Ma and vehicles traveling in front of it, and the speed of those vehicles. The vehicles in front can include not only those traveling in the same lane as the vehicle but also vehicles traveling in adjacent lanes. That is, "in front" is not limited to the direction directly in front of the vehicle Ma but can also include vehicles diagonally in front. Additionally, the sensor information includes the lateral distance to the end of the road, the lane ID, and the offset from the center line of the lane. The vehicle status acquisition unit F3 acquires the vehicle Ma's speed, acceleration, yaw rate, etc., from the vehicle status sensor 12.

[0082] The map acquisition unit F4 obtains partial map data corresponding to the current location of the vehicle Ma by wirelessly communicating with the map server 3 via the V2X vehicle-to-everything (V2X) device 14. For example, the map acquisition unit F4 requests and obtains partial map data related to roads that the vehicle Ma is scheduled to pass through within a specified time from the map server 3. The partial map data obtained from the map server 3 is stored, for example, in the map storage unit M1. The map storage unit M1 is configured to use non-volatile memory or the like, so that the data is retained even when the driving power supply is set to be off. The map storage unit M1 is implemented, for example, using a portion of the storage area of ​​the memory 23.

[0083] Furthermore, the map holding unit M1 can also be implemented using a portion of the storage area provided by RAM 22. Even assuming that RAM 22 is used to implement the map holding unit M1, data can be retained even when the driving power is off by supplying power to RAM 22 from the vehicle battery. Alternatively, the map holding unit M1 can be configured such that the saved data is lost if the driving power is set to be off. The map holding unit M1 is a non-transferable storage medium.

[0084] For convenience, the portion of map data containing the current location is referred to as the current area map data, and the coverage area of ​​the current area map data is further recorded as the current map range or the current area. The portion of map data used next is referred to as the next area map data. The next area map data corresponds to the portion of map data adjacent to the current area map data on the direction of travel of the vehicle Ma. The next area map data corresponds to the portion of map data related to the area to be entered within a specified time. The next area map data can also be determined based on a predetermined driving route. The coverage area of ​​the next area map data is also recorded as the next map range or the next area. Furthermore, in cases where adjacent portions of map data overlap, the current map range (current area) and the next map range (next area) may partially overlap.

[0085] The map management unit F5 manages the acquisition and retention of map data corresponding to the vehicle's direction of travel or predetermined travel path. For example, the map management unit F5 manages some map data acquired by the map acquisition unit F4 and map data stored in the map retention unit M1. As an example, the map management unit F5 is configured such that all map data in the map retention unit M1 is deleted at least when the driving power supply is disconnected.

[0086] Furthermore, given the capacity of the map holding unit M1, various rules can be applied to the storage rules of the map data downloaded by the map acquisition unit F4. For example, even when the capacity of the map holding unit M1 is relatively small, the map management unit F5 can delete a portion of the map data after the vehicle Ma has left an area, or after it has moved more than a specified distance away. Based on this structure, the autonomous driving device 20 can be implemented using the relatively small-capacity map holding unit M1. That is, the implementation cost of the autonomous driving device 20 can be reduced.

[0087] Furthermore, the map management unit F5 can also be configured to periodically delete map data downloaded to the map storage unit M1 after a predetermined time (e.g., 1 day) from the time of download. It can also be configured to cache map data for commonly used roads such as commuter routes and school routes in the map storage unit M1 as much as possible. For example, it can also be configured to retain map data for commonly used roads as long as the available space is not below a predetermined value. The retention period for downloaded map data can also be changed according to the attributes of the data. For example, static map data can be stored in the map storage unit M1 until a certain amount is reached. On the other hand, for example, dynamic map data such as construction information can also be periodically deleted after the area corresponding to the dynamic map data has passed.

[0088] Furthermore, the map management unit F5 calculates, for example, the remaining time before the control planning unit F7 begins using the map data for the next area, as the start time Tmx for using the next map area. The timing for starting to use the map data for the next area can be, for example, when the vehicle Ma leaves the current map area. When configured to start using the map data for the next area after leaving the current map area, the map management unit F5 calculates the remaining time until exiting the current map area based on the current position and speed of the vehicle Ma, as the start time Tmx for using the next map area. Figure 5 It is a conceptual representation of the work of the map management department F5 at the start time of the next map use. Figure 5 The "L" shown represents the distance from the current location to the exit point of the current map range. The next map is determined using the start time Tmx, for example, based on the value obtained by dividing the distance L by the vehicle speed V.

[0089] Furthermore, the timing for starting the use of map data in the next area can also be based on entering the next map area. When the configuration is such that the use of map data in the next area begins when the vehicle Ma enters the next map area, the map management unit F5 can calculate the start time Tmx for using the next map based on the current position of the vehicle Ma, the next map area information, and the vehicle's speed. Alternatively, the timing for starting the use of map data in the next area can be set as either a location located in front of the vehicle Ma at a predetermined map reference distance from the vehicle Ma that is outside the current map area or within the next map area. The map reference distance is preferably set to be sufficiently long than the safety distance described later. For example, the map reference distance can be set to 1.5 times the safety distance. Alternatively, the map reference distance can be a fixed value, such as 200m. The higher the driving speed, the longer the map reference distance can be set. Furthermore, the map reference distance can be changed according to the road type. For example, the map reference distance for dedicated motor vehicle roads can be set longer than the map reference distance for general roads.

[0090] Map Management Department F5 notifies Control Planning Department F7 of the map data acquisition status, including whether map data for the next area has been acquired. For example, if the next map usage start time Tmx is less than the specified preparation period and the next area map data cannot be acquired, Map Management Department F5 outputs the next map usage start time Tmx as the remaining map acquisition time Tmg to Control Planning Department F7. The remaining map acquisition time Tmg is equivalent to the remaining time until the next area map data is needed when formulating the control plan. The status of needing the next area map data when formulating the control plan includes the use of the next area map data when calculating the potential accident liability value described later. The status of needing the next area map data also includes exiting the current map area and entering the next map area.

[0091] Furthermore, the remaining map acquisition time Tmg can also be set to the value obtained by subtracting a predetermined margin time from the next map usage start time Tmx. The margin time, for example, takes into account communication delays, post-received processing delays, etc., and can be set to, for example, 5 seconds. The remaining map acquisition time Tmg can be a time shorter than the next map usage start time Tmx. Alternatively, the remaining map acquisition time Tmg can also be the same as the next map usage start time Tmx. The structure disclosed herein can be implemented by replacing the remaining map acquisition time Tmg with the next map usage start time Tmx. Additionally, if the next map usage start time Tmx is longer than the predetermined preparation period, and the next area map data has already been acquired, the remaining map acquisition time Tmg can be set to a sufficiently large value and output.

[0092] Additionally, if the map management unit F5 cannot acquire map data for the next area before the start time Tmx for using the next map is less than the preparation period, it can request the V2X vehicle-mounted unit 14 to prioritize communication for acquiring map data for the next area. This request can also be implemented via the map acquisition unit F4. The preparation period is, for example, 2 minutes, and is preferably set to be longer than the first time Th1 described later.

[0093] The matching determination unit F51 determines whether the map data matches the real world by comparing the content shown in the current area map data acquired by the map acquisition unit F4 with the sensing information from the surrounding monitoring sensors 11. For example... Figure 6 As shown, for example, if a vehicle Mb is detected crossing lane divider Ln1, and a stationary object Obt is detected in the lane where vehicle Mb is traveling, the matching determination unit F51 determines that the map data does not match the real world. The avoidance action of vehicle Mb and the detection of the stationary object Obt can be detected, for example, based on sensor information such as the recognition results from the forward camera. Furthermore, as a premise, it is assumed that the object is not registered in the map data. Figure 6 The map shows information about stationary objects (Obts) on the road. Examples of stationary objects include parked vehicles, road construction, lane restrictions, and fallen debris. If this quasi-static information is not reflected in the map data, a mismatch between the map data and the real world may occur.

[0094] In this scenario, if a vehicle ahead performs a lane change or other evasive maneuver within a section of the map where straight travel is permitted, the matching determination unit F51 determines that the map does not match the real world. Here, "straight travel" refers to driving along the road in the previously used lane without changing lanes or other changes in driving position. Straight travel is not limited to actions that require maintaining a steering angle of 0°.

[0095] Furthermore, the so-called avoidance action refers to vehicle behavior for avoiding obstacles, such as changing the driving position. Changing the driving position here refers to changing the vehicle's lateral position on the road. Changing the driving position includes not only lane changes, but also actions such as moving the vehicle closer to either the left or right corner within the same lane, and driving across lane dividers. Moreover, to clearly distinguish it from a typical lane change, the avoidance action is preferably a change in driving position / steering maneuver accompanied by deceleration and subsequent acceleration. For example, a change in driving position accompanied by deceleration, or a change in driving position accompanied by deceleration to below a predetermined speed, can be considered an avoidance action. Furthermore, the above description of avoidance actions represents the concept of avoidance action assumed in this disclosure. Whether a change in driving position as an avoidance action has been performed can be determined based on the driving trajectory of the vehicle ahead based on sensor information, the operating history of the direction indicator, etc.

[0096] Furthermore, if multiple vehicles ahead are detected continuously swerving to avoid a road segment on the map that allows straight-ahead travel, the matching determination unit F51 may determine that the map data does not match the real world. Additionally, it may also determine that the map data does not match the real world based on inconsistencies between the feature information shown in the map data and the feature information shown in the sensor data. Moreover, the matching determination unit F51 may also determine that the map does not match the real world if the driving positions of surrounding vehicles are outside the road area shown in the map data.

[0097] Figure 7 This is a diagram illustrating an example of a matching determination method performed by the matching determination unit F51. Figure 7 The matching determination process shown includes step S101, which determines whether the driving position of the vehicle ahead has exceeded the lane, and step S102, which determines whether a stationary object not registered in the map data has been detected. If the driving position of the vehicle ahead is detected to be beyond the lane (S101 "Yes"), and a stationary object not registered in the map is detected (S102 "Yes"), the matching determination unit F51 determines that the map data does not match the real world (S103). Alternatively, either step S101 or step S102 can be omitted. If step S101 is omitted, the process can begin from step S102.

[0098] The driving environment recognition unit F6 identifies the environment surrounding the vehicle Ma, i.e., the surrounding environment, based on the detection results from the surrounding monitoring sensor 11. This surrounding environment includes not only static environmental factors such as the current location, driving lane, road type, speed limit, and relative positions of objects on the ground, but also the positions and speeds of other moving objects, as well as the shapes and sizes of surrounding objects. Other moving objects include other vehicles such as cars, pedestrians, and bicycles.

[0099] The driving environment recognition unit F6 preferably distinguishes and identifies whether the surrounding objects detected by the surrounding monitoring sensor 11 are moving or stationary. Furthermore, it is preferable to also distinguish and identify the type of surrounding objects. Regarding the type of surrounding objects, for example, pattern matching can be performed on images captured by the surrounding monitoring camera to distinguish and identify the type. Regarding the type, for example, structures such as guardrails, road debris, pedestrians, bicycles, motorcycles, and cars can be distinguished and identified. In the case of a car, the type of surrounding object can be identified as vehicle type, model, etc. Whether a surrounding object is moving or stationary can be identified based on its type. For example, if the type of surrounding object is a structure or road debris, it can be identified as a stationary object. If the type of surrounding object is a pedestrian, bicycle, motorcycle, or car, it can be identified as a moving object. In addition, objects with a low probability of immediate movement, such as parked vehicles, can also be identified as stationary objects. It can be determined whether a vehicle is parked based on whether it has stopped and whether the brake lights are not illuminated, etc., according to image recognition.

[0100] The driving environment recognition unit F6 can also identify the position and type of objects existing around the vehicle by acquiring detection results from each of the multiple peripheral monitoring sensors 11 and combining these detection results complementaryly. The position and speed of the peripheral objects can be relative positions and relative speeds based on the vehicle's Ma, or absolute positions and absolute speeds based on the ground.

[0101] Furthermore, the driving environment recognition unit F6 can also identify the location, type, and illumination status of road markings and landmarks around the vehicle based on the detection results of the surrounding monitoring sensors 11 and map data. Additionally, the driving environment recognition unit F6 can use at least one of the detection results of the surrounding monitoring sensors 11 and map data to determine the relative position and shape of the left and right dividing lines of the lane currently being traveled by the vehicle Ma, as well as the road ends, as boundary information related to the boundary of the driving road. Furthermore, the data obtained by the driving environment recognition unit F6 from each surrounding monitoring sensor 11 may not be parsed results, but rather observation data such as image data. In this case, the driving environment recognition unit F6 determines the surrounding environment, including the position and shape of the left and right dividing lines or road ends, based on the observation data from various surrounding monitoring sensors 11.

[0102] In addition, the driving environment recognition unit F6 can also use information about other vehicles received from other vehicles by the V2X vehicle-to-everything (V2X) unit 14, and traffic information received from roadside equipment via inter-vehicle communication, to determine the surrounding environment. The traffic information that can be obtained from the roadside equipment can include road construction information, traffic restriction information, traffic congestion information, weather information, speed limits, traffic light illumination status, illumination cycle, etc.

[0103] The control planning unit F7 uses the driving environment and map data determined by the driving environment recognition unit F6 to generate a driving plan, or control plan, for the vehicle Ma to drive autonomously via automatic driving. For example, the control planning unit F7 performs path search processing to generate a recommended path from the vehicle's current location to the destination, serving as a medium- to long-term driving plan. Additionally, the control planning unit F7 generates driving plans for lane changing, driving in the center of the lane, following the vehicle ahead, and obstacle avoidance, serving as short-term control plans for driving along the medium- to long-term driving plan.

[0104] As a short-term control plan, the control planning unit F7 may generate a path at a certain distance from or in the center of the identified driving boundary line, or a path following the behavior or trajectory of the identified preceding vehicle. If the vehicle's driving road is a single-lane multi-lane road, the control planning unit F7 may generate a lane change plan candidate for the adjacent lane. If an obstacle is identified in front of the vehicle Ma based on sensor information or map data, the control planning unit F7 may generate a driving plan to pass to the side of the obstacle. If an obstacle is identified in front of the vehicle Ma based on sensor information or map data, the control planning unit F7 may generate a deceleration plan to stop near the obstacle. The control planning unit F7 may also generate a structure for a driving plan determined to be optimal through machine learning or other methods.

[0105] The control planning unit F7 calculates one or more planning candidates as candidates for short-term driving plans. Each planning candidate differs in acceleration / deceleration, jerk, steering input, and timing of various controls. That is, the short-term driving plan may include acceleration / deceleration schedule information for speed adjustments along the calculated path. Planning candidates can also be path candidates. The action decision unit F73 selects the plan with the lowest potential accident liability value calculated by the liability value calculation unit F71 (described later) from among the multiple control plans as the final execution plan. Furthermore, map data is used, for example, to determine the drivable area based on the number of lanes and road width, or to set steering input and target speed based on the curvature of the road ahead. Additionally, map data is also used for calculations of safe distances based on road structure and traffic rules, and for calculations of potential accident liability values.

[0106] The responsibility value calculation unit F71 is a structure that evaluates the safety of the driving plan generated by the control planning unit F7. As an example, the responsibility value calculation unit F71 evaluates safety based on whether the distance between the vehicle and surrounding objects (hereinafter, object distance) is above the set value of the safety distance set by the safety distance setting unit F72.

[0107] For example, if vehicle Ma is traveling on any of the planned candidate routes as specified by the control planning department F7, and an accident occurs while vehicle Ma is traveling on such a candidate route, the liability value calculation department F71 determines a potential accident liability value that indicates the degree of liability of vehicle Ma. The potential accident liability value is determined by comparing the inter-vehicle distance and safe distance between vehicle Ma and surrounding vehicles when vehicle Ma is traveling on a planned candidate route.

[0108] The lower the liability level, the smaller the potential liability value for an accident. Therefore, the potential liability value decreases the more safely the vehicle (Ma) is driven. For example, if a safe following distance is maintained, the potential liability value is relatively small. However, if the vehicle (Ma) undergoes rapid acceleration or deceleration, the potential liability value may be relatively large.

[0109] Furthermore, the liability value calculation unit F71 can set a lower potential accident liability value when the vehicle Ma is driving in accordance with traffic rules. In other words, whether or not the route follows the traffic rules at the vehicle's location can also be used as a factor influencing the potential accident liability value. To determine whether the vehicle Ma is driving in accordance with traffic rules, the liability value calculation unit F71 can have a structure to obtain the traffic rules of the location where the vehicle Ma is traveling. The traffic rules of the location where the vehicle Ma is traveling can be obtained from a predefined database, or by analyzing images captured by cameras around the vehicle Ma and detecting signs, traffic lights, road markings, etc., to obtain the traffic rules for the current location. Traffic rules can also be included in map data.

[0110] The safety distance setting unit F72 is a structure that dynamically sets the safety distance used in the responsibility value calculation unit F71, corresponding to the driving environment. The safety distance is a distance that serves as a benchmark for evaluating the safety between objects. As a safety distance, there are longitudinal safety distances (the safety distance to the vehicle ahead) and lateral safety distances (the safety distance in the left and right directions). A mathematical formula model includes a model for determining these two types of safety distances. The safety distance setting unit F72 uses a mathematical formula model that formulates the concept of safe driving to calculate the longitudinal and lateral safety distances, and sets the calculated values ​​as the safety distance at that moment. The safety distance setting unit F72 uses at least information about the vehicle's acceleration (Ma) and other behaviors to calculate and set the safety distance. Various models can be used as methods for calculating the safety distance, so a detailed explanation of the calculation method is omitted here. Furthermore, as a mathematical formula model for calculating the safety distance, for example, the RSS (Responsibility Sensitive Safety) model can be used. Additionally, the SFF (Safety Force Field, registered trademark) model can also be used as a mathematical formula model for calculating the safety distance. Hereinafter, the safe distance calculated by the safe distance setting unit F72 using the above-described mathematical formula model will also be recorded as the standard value dmin of the safe distance. The safe distance setting unit F72 is configured to set the safe distance to be longer than the standard value dmin based on the determination result of the matching determination unit F51.

[0111] Furthermore, the aforementioned mathematical model does not guarantee the complete absence of accidents, but rather ensures that, within a safe distance, appropriate collision avoidance actions will prevent the vehicle from becoming liable for an accident. An example of appropriate collision avoidance actions is braking with reasonable force. Reasonable braking could include, for example, braking at the maximum achievable deceleration of the vehicle. The safe distance calculated by the mathematical model can be described as the minimum distance that should be maintained between the vehicle and the obstacle to avoid close proximity.

[0112] As described above, the action decision unit F73 determines the structure of the final execution plan among multiple control plans based on the potential accident liability value calculated by the liability value calculation unit F71. Furthermore, the control planning unit F7, which is also the action decision unit F73, determines the final execution plan based on the remaining time Tmg obtained from the map input from the map management unit F5. The processing of actions based on the remaining time Tmg obtained from the map, i.e., the handling of situations where the map is not obtained, will be described later.

[0113] The control signal output unit F8 is a structure that outputs a control signal corresponding to the control plan determined by the action decision unit F73 to the driving actuator 16 and / or HCU 151, which are the controlled objects. For example, in the case of predetermined deceleration, a control signal for achieving the planned deceleration is output to the brake actuator and electronic throttle. In addition, a control signal for displaying map icons corresponding to the acquisition status of partial map data is output to the HCU 151. Furthermore, when a predetermined recording event occurs, the output signal of the control signal output unit F8 can be recorded by the operation recording device 17.

[0114] Furthermore, in the event of an emergency, the autonomous driving device 20 outputs data indicating the acquisition status of partial map data to the operation recording device 17. This partial map data acquisition status includes the IDs of the map tiles that can be acquired. Additionally, whether the matching determination unit F51 determines that the map data does not match the real world is also output as data indicating the partial map data acquisition status.

[0115] <Handling of Map Not Being Obtained>

[0116] Here, use Figure 8 The flowchart shown illustrates the handling of map acquisition failures performed by the Control Planning Department F7. Figure 8 The flowchart shown is executed at a predetermined period (e.g., every 500 milliseconds) during the execution of a specified application that utilizes map data, such as autonomous driving. The specified application, besides applications performing autonomous driving, can include ACC (Adaptive Cruise Control), LTC (Lane Trace Control), navigation applications, etc. Furthermore, this process can be omitted if the map management department notifies you via F5 that map data for the next area has been acquired; that is, if map data for the next area has already been acquired.

[0117] First, in step S201, the remaining map acquisition time Tmg is obtained from the map management unit F5, and step S202 is executed. In step S202, it is determined whether the remaining map acquisition time Tmg is less than a predetermined first time Th1. If the remaining map acquisition time Tmg is less than the first time Th1, step S202 is affirmatively determined and the process moves to step S204. On the other hand, if the remaining map acquisition time Tmg is greater than or equal to the first time Th1, step S202 is negatively determined and the process moves to step S203. Furthermore, if map data for the next area has already been acquired, step S202 is also negatively determined and the process moves to S203. The first time Th1 used in this determination functions as a threshold parameter for determining whether a first extraordinary action, described later, needs to be implemented. The first time Th1 is set to, for example, 60 seconds. In addition, the first time Th1 may also be, for example, 45 seconds, 90 seconds, 100 seconds, etc.

[0118] In step S203, control is performed as is normally performed. That is, a control plan based on potential accident liability values ​​is executed from among multiple planning candidates for autonomous driving toward the destination.

[0119] In step S204, it is determined whether the remaining map acquisition time Tmg is less than a predetermined second time Th2. The second time Th2 is set to be longer than 0 seconds and shorter than the first time Th1. The second time Th2 used in this determination functions as a threshold parameter for determining whether a second extraordinary action, described later, needs to be implemented. The second time Th2 is set to, for example, 30 seconds. Alternatively, the second time Th2 may be 20 seconds, 40 seconds, etc. If the remaining map acquisition time Tmg is less than the second time Th2, step S204 is affirmatively determined and the process moves to step S206. On the other hand, if the remaining map acquisition time Tmg is greater than or equal to the second time Th2, step S204 is negatively determined and the process moves to step S205. Furthermore, according to this structure, step S205 is executed when the remaining map acquisition time Tmg is less than the first time Th1 and greater than or equal to the second time Th2.

[0120] In step S205, the execution of the planned first emergency action begins. The first emergency action may be, for example, informing the driver or an operator outside the vehicle that a map needed for continuing autonomous driving is not yet available. For convenience, the process of informing the driver or other personnel that map data for the next area cannot be obtained is also recorded as a map not acquired notification process. As described above, the notification content in the map not acquired notification process can be information indicating that a map needed for continuing autonomous driving is not available. For example, it may also include... Figure 3The map shown in (A) is not displayed on monitor 151 along with the icon 80A and the text or sound message.

[0121] Furthermore, the notification content in the map not acquired notification processing can also be an image or sound message indicating the possibility of impending interruption of autonomous driving due to map incompleteness. This structure is equivalent to notifying the occupants or operators of a partial map data acquisition failure. The medium for this notification can be an image or a sound message. As a result of the map not acquired notification processing, the control signal output unit F8 outputs a control signal to the HCU 152, wherein the control signal instructs the output of an icon image or message image corresponding to the aforementioned content to the display 151. In addition, when executing the map not acquired notification processing as a first emergency action, a control plan selected from multiple planning candidates using standard procedures can be implemented in parallel.

[0122] In step S206, it is determined whether the remaining map acquisition time Tmg is less than a predetermined third time Th3. The third time Th3 is set to be longer than 0 seconds and shorter than the second time Th2. The third time Th3 used in this determination functions as a threshold parameter for determining whether a third extraordinary action, described later, needs to be implemented. The third time Th3 is set to, for example, 10 seconds. Alternatively, the third time Th3 may be 5 seconds, 15 seconds, etc. If the remaining map acquisition time Tmg is less than the third time Th3, step S206 is affirmatively determined and the process moves to step S208. On the other hand, if the remaining map acquisition time Tmg is greater than or equal to the third time Th3, step S206 is negatively determined and the process moves to step S207. Furthermore, according to this structure, step S207 is executed when the remaining map acquisition time Tmg is less than the second time Th2 and greater than or equal to the third time Th3.

[0123] In step S207, the planned second emergency action is executed and begins to be carried out. The second emergency action can be, for example, a process that reduces the vehicle's speed to a predetermined amount lower than a predetermined target speed. For convenience, the process of suppressing the vehicle's speed is also referred to as speed suppression processing. By setting the vehicle's speed to a value lower than the initial planned value, the time until reaching the location where the next area map data is needed can be extended. In other words, the remaining map acquisition time Tmg can be extended. Consequently, the probability of acquiring the next area map data before reaching the location where the next area map data is needed can be increased. Furthermore, if the execution of the speed suppression processing as the second emergency action is decided, a planning candidate based on the execution of the speed suppression processing can be created, and the final deceleration method can be determined based on the potential accident liability value. The deceleration amount as the second emergency action can be, for example, a fixed value such as 5 km / h or 10 km / h. Additionally, the target speed after deceleration can also be a value obtained by multiplying the initially predetermined target speed by a predetermined coefficient less than 1. For example, the target speed after deceleration can be 0.9 times or 0.8 times the initially predetermined target speed. Furthermore, when the current driving lane is an overtaking lane, a lane change can be planned simultaneously with the implementation of a second extraordinary action. Here, a driving lane refers to a lane that is not an overtaking lane. For example, in Japan, lanes other than the right-hand lane are considered driving lanes. In Germany, the right-hand lane is considered a driving lane. The setting of overtaking lanes and driving lanes can be changed to comply with the traffic rules of the area.

[0124] In step S208, the planned third emergency action is executed and begins to be performed. The third emergency action can be, for example, Emergency Stop (MRM). MRM can involve, for example, issuing warnings to the surrounding area while autonomously driving the vehicle to a safe location and stopping. A safe location could be a road shoulder with a width of at least a specified value, or a location designated as an emergency evacuation zone. Alternatively, MRM can involve gradually decelerating and stopping the vehicle within its current lane. The deceleration at this time is preferably, for example, a value of 2 [m / s^2], 3 [m / s^2], or less than 4 [m / s^2]. Of course, in cases where it is necessary to avoid a collision with a vehicle ahead, a deceleration exceeding 4 [m / s^2] can be used. The deceleration during MRM can be dynamically determined and updated sequentially, within a range that allows the vehicle to stop within 10 seconds, taking into account the vehicle's speed at the start of MRM and the distance to following vehicles. Starting MRM is equivalent to initiating deceleration towards an emergency stop.

[0125] <Regarding handling mismatches>

[0126] Here, use Figure 9The flowchart shown illustrates the mismatch response handling performed by the autonomous driving device 20. Figure 9 The flowchart shown is executed at a predetermined period (e.g., every 200 milliseconds) during the execution of specified applications such as autonomous driving and navigation that utilize map data. Furthermore, this process can be integrated with... Figure 8 The map shown is not acquired. The response process is executed independently, in other words, in parallel. In this embodiment, as an example, the mismatch response process includes steps S301 to S306.

[0127] First, in step S301, the sensing information from the surrounding monitoring sensor 11 is acquired and the process moves to step S302. In step S302, the matching determination unit F51 performs a matching determination process. This matching determination process can, for example, provide matching information for users... Figure 7 The flowchart shown illustrates the content. If, as a result of step S302, it is determined that there is a gap between the map and the real world, the process proceeds to step S304. Conversely, if, as a result of step S302, it is not determined that there is a gap between the map and the real world, the process proceeds to step S305.

[0128] Furthermore, a discrepancy between the map and the real world is equivalent to a map-real-world mismatch. This mismatch includes, for example, the presence of unregistered obstacles on the road, or a drivable area on the map that is inaccessible in reality. Additionally, a difference between the road shape shown on the map and the road shape detected by the surrounding monitoring sensor 11 is also an example of a map-real-world mismatch. Here, road shape refers to at least one of the following: number of lanes, curvature, road width, etc. For example, a difference between the road end shape shown on the map and the shape actually observed by the forward camera, or the detection of landmarks not registered in the map data, is also an example of a map-real-world discrepancy. Furthermore, the inability to detect landmarks registered in the map data when there are no other vehicles ahead, i.e., when the forward camera has a wide field of view, is also an example of a map-real-world mismatch. A difference between the color, shape, position, and display content of a sign registered in the map data and the image recognition result is also an example of a map-real-world mismatch.

[0129] In step S304, the safety distance setting unit F72 sets the safety distance setting value dset to be longer than the standard value dmin. For example, the safety distance setting value dset can be set as shown in Formula 1 below.

[0130] dset=dmin+εd…(Formula 1)

[0131] Furthermore, εd in Equation 1 is a parameter equivalent to the amount of extension, which is referred to as the extension distance for convenience. For example, the extension distance εd is a value greater than 0. The extension distance εd can be a fixed value such as 20m or 50m. In addition, the extension distance εd can also be dynamically determined according to the speed and acceleration of the vehicle Ma. For example, the higher the vehicle speed, the longer the extension distance εd can be set. In addition, the extension distance εd can also be set longer if the acceleration of the vehicle Ma is greater or the deceleration is smaller. Furthermore, the extension distance εd can also be adjusted according to the type of road on which the vehicle Ma travels. For example, if the vehicle Ma travels on a general road, the extension distance εd can be set to a smaller value than if the road is a highway or other dedicated motorway.

[0132] Alternatively, the safety distance setting value dset can also be set as shown in Equation 2 below.

[0133] dset=dmin×α…(Formula 2)

[0134] Furthermore, α in Equation 1 is a coefficient used to extend the safety distance, which is called the expansion coefficient for convenience. The expansion coefficient α is a real number greater than 1. The expansion coefficient α can be set to a fixed value such as 1.1 or 1.2. In addition, the expansion coefficient α can also be dynamically determined according to the speed and acceleration of the vehicle Ma. For example, the higher the vehicle speed, the larger the expansion coefficient α can be set. In addition, the expansion coefficient α can also be set to be larger if the acceleration of the vehicle Ma is greater or the deceleration is smaller. Furthermore, the expansion coefficient α can also be adjusted according to the type of road on which the vehicle Ma travels. For example, the expansion coefficient α can be set to a smaller value when the vehicle Ma travels on a general road than when it travels on a highway or other dedicated motor vehicle road. If the processing in step S304 is completed, proceed to step S306.

[0135] In step S305, the standard value dmin calculated based on the mathematical formula model is set as the set value dset for the safe distance, and the process proceeds to step S306. In step S306, the control planning unit F7 creates a control plan that ensures the safe distance determined through the above processing. Furthermore, for the control plan created in step S306, the liability value calculation unit F71 calculates the potential self-liability value, and selects the final action to be executed based on the calculated potential accident liability value.

[0136] <The effects of the above structure>

[0137] Based on the above structure, if the remaining time Tmg for map acquisition is less than a first time, an emergency action is taken, such as notifying the driver and passengers. With this structure, even if autonomous driving is ultimately interrupted due to missing map data, the prior notification reduces concerns about the interruption being unexpected for the user. In other words, it reduces concerns about unexpected, timed interruptions to autonomous driving. Consequently, it reduces user confusion.

[0138] Furthermore, if the remaining map acquisition time Tmg is less than the second time, the vehicle speed is suppressed as an emergency action. This structure extends the time until map data for the next area is needed. As a result, the likelihood of timely acquisition of map data for the next area is increased. Additionally, the user can expect to perceive a negative situation in the system based on the suppression of the vehicle speed compared to normal. In other words, even if autonomous driving ultimately fails due to incomplete map data, concerns that the failure is an unexpected event for the user are reduced. Moreover, in this disclosure, the driver / occupant is notified before implementing the speed suppression as an emergency action. This structure allows the driver / occupant to infer the reason for the speed suppression, thus reducing concerns about user confusion or discomfort caused by the speed suppression.

[0139] Furthermore, according to the above structure, if the remaining map acquisition time Tmg is less than a third time Th3, which is a predetermined threshold, then MRM (Motion Reduction Mechanism) is initiated, meaning deceleration towards stopping begins. This structure reduces concerns about continuing autonomous driving in the absence of map data. Additionally, since MRM is performed within a region where map data is available, it is performed more safely than if MRM were performed without map data.

[0140] Furthermore, based on the above structure, the safety distance can be extended when there is a discrepancy between the map and the real world. This discrepancy is equivalent to a compromised map reliability. In such a situation, the likelihood of misjudging potential accident liability values ​​and other planning candidates increases. Therefore, by temporarily extending the safety distance beyond the standard value dmin, safety can be improved.

[0141] <Supplement to the work of F7 in the Control Planning Department>

[0142] The above discloses the methods for performing emergency actions such as notifying the driver / occupant, slowing down the vehicle, and obtaining the remaining time Tmg based on a map, including MRM. However, the content and combination of these emergency actions are not limited to this. The control planning unit F7 can also be configured to use mapless autonomous driving as an emergency action. Mapless autonomous driving is control that continues autonomous driving without map data provided by the map server 3. Mapless autonomous driving can be, for example, a driving mode that continues driving using a map of the vehicle's surroundings created in real time based on the detection results of the surrounding monitoring sensor 11, i.e., a real-time map. The real-time map can be generated, for example, by Visual SLAM (Simultaneous Localization and Mapping), which is based on camera images. The real-time map can also be created by sensor fusion. The real-time map can also be called a simplified map, a self-made map, or a sensor map. In addition, mapless autonomous driving can also be a driving mode that uses the trajectory of the preceding vehicle as the vehicle's driving trajectory and decelerates in response to vehicles entering or crossing the road detected by the surrounding monitoring sensor 11. Mapless autonomous driving could be an alternative to MRM.

[0143] The control planning unit F7 can also employ mapless autonomous driving as an emergency measure based on surrounding traffic conditions. For example, mapless autonomous driving can be employed when the remaining time Tmg after map acquisition is less than the second time Th2 or the third time Th3, and when other vehicles are present in front, behind, to the left, and to the right of vehicle Ma. This is because it is predicted that maintaining a safe distance from these surrounding vehicles ensures safety when other vehicles are present in front, behind, to the left, and to the right of vehicle Ma. The conditions, or in other words, for employing mapless autonomous driving can be determined based on the vehicle manufacturer's design philosophy. Mapless autonomous driving can be considered an exceptional emergency measure.

[0144] Additionally, as an emergency action, a handover request can be processed. The handover request processing is equivalent to a takeover request in conjunction with the HMI system 15 to the driver or operator to perform driving operations. The handover request processing can be referred to as a handover request. For example, the control planning unit F7 can also be configured to plan and execute a handover request as an emergency action when the remaining time Tmg obtained from the map is less than a second time. Furthermore, the control planning unit F7 can also be configured to extend the safety distance as an emergency action based on the remaining time Tmg obtained from the map being less than a predetermined threshold, such as a second time Th2. The method for extending the safety distance can be the same as in step S304.

[0145] Alternatively, the Control Planning Unit F7 can be configured to calculate the urgency level based on the remaining time Tmg obtained from the map, and execute emergency actions accordingly. The urgency level is a parameter that is set higher the shorter the remaining time Tmg is. For example, the urgency level can be represented by three stages: Level 1 to Level 3. Level 1, for example, could be a state where the remaining time Tmg is less than the first time Th1 and greater than the second time Th2. Level 2, for example, could be a state where the remaining time Tmg is less than the second time Th2 and greater than the third time Th3. Level 3, for example, could be a state where the remaining time Tmg is less than the third time Th3. Figure 10 This diagram summarizes an example of emergency actions for each level of urgency. For instance, in the case of urgency level 1, Control Planning Department F7 plans and executes a notification to the driver or operator as the first emergency action. Furthermore, in the case of urgency level 2, Control Planning Department F7 plans and executes speed suppression measures as the second emergency action. And, in the case of urgency level 3, Control Planning Department F7 plans and executes MRM as the third emergency action.

[0146] Furthermore, the content and combination of emergency actions to be performed based on urgency or the remaining time Tmg obtained from the map can be appropriately modified. For example, such as... Figure 11 As shown, as an emergency action at emergency level 1, the driver or operator can be notified, and a speed suppression measure with a relatively small deceleration amount can be implemented. Conversely, as an emergency action at emergency level 2, a speed suppression measure with a relatively large deceleration amount can be implemented compared to level 1. The deceleration amount of the speed suppression measure at emergency level 1 is smaller than that at emergency level 2. For example, if the deceleration amount of the speed suppression measure at emergency level 1 is set to 5 km / h, the deceleration amount of the speed suppression measure at emergency level 2 can be set to 10 km / h. Furthermore, as an emergency action at emergency level 2, a handover request can also be implemented.

[0147] Furthermore, the urgency level and judgment criteria can be appropriately changed. Urgency can also be judged using five or more stages. Additionally, urgency can be determined not only by obtaining the remaining time (Tmg) from the map but also by considering the surrounding traffic conditions. For example, the urgency level can be set lower in congested traffic conditions compared to non-congested conditions. This is because the concern about drastic changes in the positional relationship with surrounding vehicles is lower in congested traffic conditions. Furthermore, congested traffic conditions refer, for example, to a situation where other vehicles are present in front, behind, to the sides, and the vehicle's speed is below 60 km / h.

[0148] <Regarding the termination conditions of the extraordinary operation>

[0149] Here, use Figure 12 The flowchart shown illustrates the operation of the autopilot device 20 when the emergency operation ends. Figure 12 The flowchart shown is executed at a predetermined period (e.g., every 200 milliseconds) during the execution of specified applications that utilize map data, such as autonomous driving and navigation. Furthermore, this process can operate independently of... Figure 8 The map shown did not receive any response processing. Figure 9 The mismatch response procedures shown are executed sequentially. In this embodiment, as an example, the emergency action termination procedure includes steps S401 to S403. Each step can be executed by the control planning unit F7.

[0150] First, in step S401, it is determined whether an emergency action is being carried out. If no emergency action is being carried out, the process ends. On the other hand, if an emergency action is being carried out, step S401 is affirmatively determined and step S402 is executed.

[0151] In step S402, it is determined whether a predetermined release condition is met. A release condition is a condition used to terminate an emergency action currently being performed. For example, if partial map data necessary for the continuation of autonomous driving, such as map data for the next area, can be obtained—in other words, if the remaining map acquisition time Tmg recovers to a sufficiently large value—the control planning unit F7 determines that the release condition is met. Alternatively, the control planning unit F7 may determine that the release condition is met if the driver or operator performs an operation that grants them the authority to perform driving operations, i.e., an overriding operation. In other words, the release condition may also be met when switching from autonomous driving mode to manual driving mode or driving assistance mode. Furthermore, the release condition may also be met if the vehicle has already stopped.

[0152] If the release condition is determined to be met in step S402, step S403 is executed. Conversely, if the release condition is determined not to be met, the process ends. In this case, emergency actions corresponding to obtaining the remaining time Tmg from the map or the urgency level continue.

[0153] In step S403, the currently executing emergency action is terminated, thus ending the process. For example, if map notification processing is not performed, image display and audio message output are stopped. Additionally, if speed suppression processing is performed, the target speed suppression is lifted, restoring the original target speed. Furthermore, a notification indicating the termination of the emergency action may be given when the emergency action is terminated. Preferably, the termination of the emergency action is communicated to the driver / occupant along with the reason for termination. For example, the notification may also state that the emergency action is terminated while the map data required for autonomous driving, i.e., the map data for the next area, is being acquired.

[0154] The embodiments of this disclosure have been described above, but this disclosure is not limited to the above-described embodiments. Various modifications described below are also included within the technical scope of this disclosure, and various changes and implementations can be made without departing from the spirit of the text, in addition to the following content. For example, the various modifications described below can be appropriately combined and implemented without creating technical contradictions. Furthermore, components that have the same function as the components described in the above embodiments are marked with the same reference numerals, and their descriptions are omitted. Additionally, when only a part of the structure is mentioned, the structure of the previously described embodiments can be applied to other parts.

[0155] <Supplement to Map Data Management Methods>

[0156] As described above, the processing unit 21, which is the map management unit F5, can also be configured to cache map data associated with roads used daily, such as commuting routes and school routes, in the map storage unit M1 as much as possible. Examples of map data associated with roads used daily include map data with block IDs that have been downloaded a certain number of times, and partial map data concerning areas within a certain distance of one's home / workplace / school. Alternatively, the processing unit 21 can be configured not to be limited to roads used daily, and can save downloaded map data until the capacity of the map storage unit M1 is full, or until the validity period appropriately set for each piece of map data expires.

[0157] For convenience, the map data stored in the map holding unit M1 will also be referred to as saved map data. Here, saved map data refers to data that was already stored in the map holding unit M1 at the moment the driving power was turned on. In other words, it refers to map data acquired during a previous trip. Saved map data can be called previously acquired map data. In contrast, map data downloaded from the map server 3 after the driving power is turned on can be called newly acquired map data. Furthermore, saved map data can also be called cached map data depending on its storage format and storage area.

[0158] The processing unit 21 can also be configured to retain map data in the map holding unit M1 even after the driving power is disconnected, actively reusing the map data stored in the map holding unit M1. For example, the processing unit 21 can also be configured to... Figure 13 The processing steps shown are used to determine whether map data needs to be downloaded. Furthermore, Figure 13 The processing flow shown can be triggered by events such as a change in the map data being used or the remaining time before exiting the current area being less than a specified value.

[0159] The processing unit 21, based on the switch of a portion of the map used to create the control plan during movement, refers to the map holding unit M1 and determines whether the map data for the next area is saved in the map holding unit M1 (step S501). For example, the map management unit F5 determines the block ID of the next area based on the adjacent block ID associated with the current area map data and the vehicle's direction of travel. Then, it searches for map data with the block ID of the next area in the map holding unit M1. If map data with the block ID of the next area exists ("Yes" in step S501), the saved portion of the map data is used as the map data for the control plan (step S502).

[0160] Furthermore, if the map data containing the block ID of the next area is not stored in the map holding unit M1 (step S501 is "No"), the processing unit 21 begins the process of downloading the map data of the next area from the map server 3 (step S503). The process of downloading the map data includes, for example, a step of sending a map request signal to the map server 3. The map request signal is a signal requesting the distribution of map data and contains the block ID of the requested portion of the map. That is, S503 is capable of sending a map request signal containing the block ID of the next area and receiving the map data distributed as a response from the map server 3.

[0161] Furthermore, the map request signal can include information that determines which map tile should be distributed by map server 3. For example, it can replace the tile ID or include the vehicle's current location and direction of travel along with the tile ID. In addition, in cases where map data with the tile ID of the next area is not stored, it can include cases where map data with the tile ID of the next area is stored, but the validity period of that data has expired.

[0162] This structure allows for the suppression of communication frequency and volume with map server 3. Furthermore, when reusing saved map data, concerns about the remaining map retrieval time Tmg falling below a predetermined threshold can be reduced. Therefore, concerns about implementing emergency actions can be minimized.

[0163] However, the map data saved may not be the latest version. For example, the shape / color of a commercial sign registered as a landmark on the map may differ from its shape / color in the real world. If the content shown on the map contradicts the real world, the accuracy of its location estimation may deteriorate.

[0164] Based on this situation, it is also possible to... Figure 14 As shown, when using saved map data, the processing unit 21, which is the matching determination unit F51, sequentially determines the matching between the saved map data and the real world (step S601). The processing unit 21 may also continue using the saved map data as long as it determines that the saved map data matches the real world ("Yes" in step S602) (step S603). On the other hand, the processing unit 21 may also re-download a portion of the map data for the current area from the map server 3 based on a determination that the saved map data does not match the real world ("No" in step S602) (step S604). The saved map data corresponding to the current area can be deleted / rewritten after the map data download is complete. Figure 14 The series of processes shown can be implemented periodically, for example, every second, while using saved map data.

[0165] Furthermore, if it is determined that the saved map data does not match the real world, the map management unit F5 can confirm whether the saved map data is the latest version by communicating with the map server 3. This confirmation can be made by sending the version information of the saved map data to the map server 3 or obtaining the latest version information of the map data for the current area from the map server 3. If the saved map data is the latest version, there is no need to re-download it, so step S604 can be omitted. In this case, to improve robustness, control conditions can be changed, such as the aforementioned mismatch handling or speed suppression.

[0166] Furthermore, the processing unit 21, which serves as the matching determination unit F51, may evaluate the matching performance not based on the two stages of whether the saved map data matches the real world, but rather as a percentage from 0% to 100%. Hereinafter, the numerical value representing the matching performance will also be referred to as the matching rate. The matching determination unit F51 may also determine that the saved map data does not match the real world based on a matching rate below a predetermined value. Additionally, to suppress the influence of instantaneous noise, the matching determination unit F51 may also determine that the saved map data does not match the real world based on an evaluation result where the matching rate is below a predetermined value for a sustained predetermined time or longer.

[0167] Furthermore, the map management unit F5 can also be configured to, upon confirming step S501 or step S602, reference the date the map data was acquired and use the condition that the elapsed time from the acquisition date is less than a predetermined threshold when referencing the date the map data was acquired. In other words, the map management unit F5 can also be configured to re-download the map data for that area from the map server 3 if the elapsed time from the acquisition date is greater than or equal to a predetermined threshold when reading a certain piece of map data.

[0168] Alternatively, the processing unit 21 can be configured to perform driving control primarily using map data newly acquired from the map server 3, even in a structure where map data is stored in the map holding unit M1. The processing unit 21 can also be configured to create and execute a control plan using the map data stored in the map holding unit M1 only when partial map data cannot be obtained from the map server 3 due to communication problems or other reasons. Such a structure is equivalent to passively reusing the structure that stores map data.

[0169] Figure 15 This is a flowchart illustrating an example of the operation of the processing unit 21 corresponding to the aforementioned technical concept. Figure 15 The flowchart shown can be executed, for example, when map data for the next area cannot be obtained from map server 3. Figure 15 The processing flow shown, for example, can be combined with... Figure 8 The various processes described above, such as the processes shown, are implemented in parallel, in combination, or by substitution. For example, Figure 15 The processing flow shown can be implemented as a handling method for cases where a negative determination has been made in step S204. Figure 15 The process shown includes steps S701 to S704.

[0170] As in step S701, the processing unit F21 determines whether the remaining map acquisition time Tmg is less than a predetermined cache usage threshold Thx. The cache usage threshold Thx is set to a value longer than the third time Th3, such as 15 seconds or 30 seconds. The cache usage threshold Thx can also be the same as the first time Th1 or the second time Th2 mentioned above. Alternatively, the cache usage threshold Thx can be prepared as a parameter independent of the aforementioned thresholds.

[0171] If the remaining time Tmg for map acquisition is higher than the specified cache usage threshold Thx (No in step S701), the processing unit 21 temporarily terminates. Figure 15 The process is shown below. In this case, the processing unit 21 can re-execute the process if the next area map data is not obtained after a specified time. Figure 15The processing flow is shown below. On the other hand, if the remaining map acquisition time Tmg is less than the specified cache usage threshold Thx ("Yes" in step S701), it is determined whether map data with the block ID of the next area is stored in the map holding unit M1. If part of the map data of the next area is stored in the map holding unit M1 ("Yes" in step S702), the stored part of the map data is used to create a control plan for the next area (step S703). On the other hand, if part of the map data of the next area is not stored in the map holding unit M1 ("No" in step S702), an emergency action corresponding to the remaining map acquisition time Tmg is taken.

[0172] The situation where the remaining map acquisition time Tmg is less than the cache usage threshold Thx corresponds to a situation where partial map data for the next area is needed when creating a control plan. Furthermore, timings such as the remaining map acquisition time Tmg being 0 seconds or the timing of exiting the current area can also correspond to situations where partial map data for the next area is needed when creating a control plan. Additionally, when the processing unit 21 starts using saved map data in step S703, it can also periodically perform the process of downloading the next / current area map data from the map server 3. Moreover, when the next / current area map data can be obtained from the map data due to the restoration of communication status, control can be performed using the map data obtained from the map server 3 instead of saving the map data.

[0173] Furthermore, as mentioned above, when using saved map data, the error in predicting (positioning) one's own location may increase due to the age of the map. Because of this concern, the processing unit 21 can also be configured to operate differently depending on whether it uses saved map data or newly downloaded map data from the map server 3.

[0174] For example, such as Figure 16 As shown, when the saved map data is not used (No in step S801), the processing unit 21 sets the upper limit of the driving speed allowed in the control plan to a standard upper limit corresponding to the type of driving road (step S802). Figure 16 Vmx_set is a parameter representing the upper limit of the allowed driving speed, i.e., the set value of the upper limit speed. Additionally, Vmx_RdTyp is a parameter representing the standard upper limit value corresponding to the type of road. Furthermore, the case where no saved map data is used is equivalent to using partial map data obtained from map server 3 to create a control plan, etc.

[0175] The standard upper limit value is applied to the type of road, such as whether it is a highway or a general road. For example, when the road is a highway, the upper limit value is set to 120 km / h, while when the road is a general road, the upper limit value is set to, for example, 60 km / h. The standard upper limit value for each road type can also be configured to be any value that can be set by the user. In addition, the standard upper limit value can also be applied to the speed limit set for each road. The speed limit can be determined by referring to map data or by image recognition of speed limit signs. Changing the upper limit speed setting used for the control plan is equivalent to changing the control conditions. Furthermore, in order to achieve smooth traffic flow, the standard upper limit value can also be set based on the average speed of surrounding vehicles. The average speed of surrounding vehicles can be calculated based on the speed of vehicles observed by the surrounding monitoring sensor 11 or based on the speed information of other vehicles received by inter-vehicle communication.

[0176] On the other hand, when using saved map data ("Yes" in step S801), the upper limit of the driving speed allowed in the control plan is set to the value obtained by subtracting the prescribed inhibition amount from the standard upper limit value corresponding to the type of driving road (step S803). Figure 16 Vdp in the equation represents the amount of speed reduction. The amount of speed reduction can be a fixed value such as 10 km / h, or it can be a value equivalent to 10% or 20% of the upper limit of the standard corresponding to the road type.

[0177] Based on the above structure, when driving using saved map data, the maximum speed can be suppressed compared to driving using newly acquired map data. Suppressing the driving speed improves robustness, thus reducing concerns about the interruption of autonomous driving control.

[0178] Furthermore, in the matching determination unit F51's structure for calculating the degree of mismatch between map data and the real world—in other words, the matching rate—the processing unit 21 can also change the control conditions based on the matching rate. For example, the lower the matching rate, the greater the suppression amount (Vd). Specifically, when the matching rate is 95% or higher, the suppression amount (Vd) can be set to 0; on the other hand, when the matching rate is 90% or higher but less than 95%, the suppression amount can be set to 5 km / h. Alternatively, when the matching rate is less than 90%, the suppression amount can be set to 10 km / h or higher. For example, when the matching rate is less than 80%, the suppression amount can be set to 15 km / h.

[0179] Furthermore, the processing unit 21 can also be configured to operate in a mode capable of performing automatic overtaking control when the matching rate is above a predetermined threshold, and in a mode prohibiting automatic overtaking when the matching rate is below the threshold. Automatic overtaking control refers to a series of controls including movement into the overtaking lane, acceleration, and return to the driving lane.

[0180] Furthermore, the processing unit 21 can also be configured to use the detection results of the surrounding monitoring sensor 11 more preferentially than map data to create a control plan when the matching rate is below a predetermined threshold. Additionally, the processing unit 21 can also create a plan to follow the preceding vehicle more aggressively when the matching rate is less than the predetermined threshold than when the matching rate is above the predetermined threshold. For example, in a scenario where overtaking control is normally performed, control to follow the preceding vehicle without overtaking can be planned and executed when the matching rate is less than the predetermined threshold. Here, "normally" refers to a matching rate above the predetermined threshold. According to this structure, concerns about sudden acceleration, deceleration, and sharp turns due to incomplete map data can be reduced.

[0181] like Figure 17 As shown, the processing unit 21 may also display an icon image representing the determination result of the matching determination unit F51 on the display 151 (step S902). Furthermore, step S901 represents the step where the matching determination unit F51 determines the matching. The processing unit 21 may also display an image indicating that the map matches reality when it determines that the map data matches reality. The processing unit 21 may also not display an image indicating that the map matches reality when it determines that the map data matches reality. The processing unit 21 may also only display an image indicating its detection result, i.e., an image indicating that a mismatch between the map and reality has been detected, when a mismatch between the map data and reality is detected.

[0182] Furthermore, the processing unit 21 can also display the mismatched area as a specific location when a mismatch is detected between the map data and the real world. For example, if the display 151 is a central display, the processing unit 21 can display an image on the map image overlaid with marker images representing the mismatched area. Additionally, if the display 151 is equipped with a HUD, the processing unit 21 can use the HUD to overlay the marker images representing the mismatched area onto the actual mismatched area. When the autonomous driving device 20 is in Level 3 mode, it is expected that the driver / passenger will be looking ahead. Therefore, by overlaying the mismatched area onto the foreground using the HUD, the driver / passenger can identify the mismatched area without taking their eyes off the road.

[0183] Furthermore, when the processing unit 21 detects a mismatch between map data and the real world, it can notify the driver / occupant of this via a HUD or similar device, and then request the driver / occupant to select a future control policy. Options for the future control policy could include switching to manual driving or continuing automatic driving while maintaining vehicle speed. Switching to manual driving also includes moving to Level 2 or Level 1 mode. Driver / occupant instructions can be obtained, for example, through switch operation, pedal operation, or steering wheel operation. In addition, response instructions to map-reality mismatches can also be obtained based on gaze, posture, and voice recognition. Gaze and posture can be extracted by analyzing images from cameras installed inside the vehicle to capture images of the driver / occupant.

[0184] However, when the autonomous driving device 20 is operating in Level 4 mode, the driver / occupant is not limited to looking ahead. They may also be performing tasks such as operating a smartphone or reading. In such a situation, even if the HUD or central display shows an image requesting input for future control policies, the driver / occupant may not notice it. In Level 4 mode, the driver / occupant's gaze can be guided to the display 151 via vibration, sound, etc., to request the aforementioned mismatch notification and input.

[0185] Furthermore, providing too much or overly detailed information to occupants may annoy them. Therefore, when a mismatch between map data and reality is detected, the notification to occupants may not contain specific details, but simply state that a mismatch has been detected. Additionally, the image displayed in step S902 may show whether a match has been achieved between the map data and reality. Furthermore, frequent mismatch notifications may cause occupants to distrust the system. Therefore, notifications detecting a mismatch between map data and reality may be limited to a predetermined number within a certain time period. Moreover, notifications detecting a mismatch between the map and reality may only be issued as a warning when handling incomplete map operations such as speed suppression or handover requests. Notifications detecting a mismatch between the map and reality may also be stopped during speed suppression, while following the vehicle ahead, or during manual driving.

[0186] <Examples of Workshop Communication Applications>

[0187] For example, the map acquisition unit F4 can be configured to acquire partial map data from the map server 3 based on the principle of data reliability, and to acquire partial map data from surrounding vehicles if the remaining map acquisition time Tmg is less than a predetermined threshold. Alternatively, it can acquire map data for the current / next area from surrounding vehicles by requesting map data for the next area from the surrounding vehicles in cooperation with the V2X vehicle-to-everything (V2X) unit 14. This control of acquiring partial map data from other vehicles via inter-vehicle communication can also be used as an emergency measure.

[0188] This structure reduces concerns about autonomous driving being interrupted in the event of malfunctions in the wide-area communication network or the wide-area communication section of the V2X vehicle-mounted device 14. Furthermore, the map data acquired from surrounding vehicles can be used as temporary map data before obtaining map data from the map server 3. Additionally, it is preferable to attach an electronic certificate guaranteeing the reliability of the map data acquired from surrounding vehicles. The certificate information can include information such as the issuing source and a code guaranteeing reliability.

[0189] Related to the above structure, the vehicles, in other words, the autonomous driving devices 20 of each vehicle, can also be configured to share the freshness information of the map data of the current area or the next area held by themselves through inter-vehicle communication. The freshness information can be download time information or version information. Furthermore, the processing unit 21 can also obtain the map data from another device through inter-vehicle communication if it detects that another device holds map data newer than its own for the current area or the next area. Here, "other devices" refers to autonomous driving devices or driving assistance devices installed in other vehicles. Other devices can be any devices that utilize map data. The term "other device as the communication target" can be replaced with other vehicles or surrounding vehicles. Other vehicles are not limited to vehicles traveling in front of this vehicle, but can also be vehicles located to the side or behind, etc.

[0190] Furthermore, the processing unit 21 can also notify following vehicles of the existence of mismatches caused by construction / lane restrictions, etc., via inter-vehicle communication. Additionally, the processing unit 21 can also obtain information about mismatches detected by preceding vehicles from the vehicles ahead via inter-vehicle communication.

[0191] <Examples of Real-Time Map Applications>

[0192] As described above, the processing unit 21 can also be used as an emergency measure when map data cannot be obtained. It creates a real-time map based on the detection results of the surrounding surveillance sensor 11, and uses this real-time map to create and execute a control plan for continuing autonomous driving. Furthermore, the processing unit 21 can also be configured to change its behavior based on the distance range from which the real-time map can be created, i.e., the map creation distance Dmp. For example, as... Figure 18 As shown, if an instant map can be created up to a distance greater than or equal to the specified function maintenance distance Dth ("Yes" in step T102), the processing unit 21 maintains normal control (step T103). On the other hand, if the map creation distance Dmp is less than the function maintenance distance Dth ("No" in step T102), MRM is executed or the driving speed is suppressed by a specified amount (step T104).

[0193] also, Figure 18 Step T101, as shown, represents the processing step of creating an instant map in real time using the detection results of the surrounding monitoring sensor 11. Step T101 can be executed sequentially, for example, at intervals of 100 milliseconds or 200 milliseconds. The map creation distance Dmp corresponds to the distance at which objects can be detected by the surrounding monitoring sensor 11. The map creation distance Dmp can be set, for example, to the distance at which the left and right lane boundaries of the vehicle can be identified. Alternatively, the map creation distance Dmp can also be the distance at which the left or right ends of the road can be identified.

[0194] The function maintenance distance Dth can be a fixed value, such as 50m, or a variable value determined by the speed. For example, the function maintenance distance Dth can be the distance from the MRM to the stop, i.e., the distance required by the MRM, Dmrm, plus a specified tolerance. The distance required by the MRM, Dmrm, is determined by referring to the equation of motion with constant acceleration, based on the negative acceleration (i.e., deceleration) used in the MRM and the current speed. That is, if the current speed is set to Vo and the deceleration is set to a, then Dmrm is determined by Dmrm = Vo^2 / (2a). Furthermore, the deceleration used in the MRM can also be dynamically determined to bring the device to a complete stop within 10 seconds.

[0195] For processing unit 21, the above-described structure is equivalent to continuing to drive without performing MRM when the real-time map can be created to a distance greater than the distance Dmrm required for MRM. Furthermore, processing unit 21 can also be configured to suppress the speed limit during real-time map usage even if the map creation distance Dmp is greater than the function maintenance distance Dth. The lower the vehicle speed, the shorter the distance Dmrm required for MRM. Therefore, by suppressing the vehicle speed during real-time map usage, the likelihood of performing MRM can be further reduced. Moreover, the scenario of using a real-time map corresponds to a scenario where the map data required for the control plan cannot be received through communication with map server 3.

[0196] <Response to Restricted Filming Areas>

[0197] Depending on the region where this system is used, there may be locations where cameras cannot be pointed, i.e., prohibited areas for photography. Examples of prohibited areas for photography include the interior and surrounding areas of military facilities, military residential areas, airports, harbors, palaces, government facilities, etc. Map server 3 can also distribute the location information of prohibited areas registered by map administrators to each vehicle. Alternatively, if the location information of a prohibited area for photography is obtained from map server 3, processing unit 21 can execute a handover request based on that location information.

[0198] For example, such as Figure 19 As shown, if a prohibited area for photography is detected ahead of the vehicle based on distribution information from map server 3 ("Yes" in step T201), processing unit 21 calculates the remaining time Trmn until reaching the prohibited area (step T202). Then, if the remaining time Trmn until reaching the prohibited area is less than a predetermined threshold Tho ("Yes" in step T203), a handover request is initiated (step T204). Subsequently, if a response is received from the driver / occupant within the predetermined time ("Yes" in step T205), driving authority is transferred to the driver / occupant and notification of this intention is executed (step T206). On the other hand, if no response is received from the driver / occupant even after the predetermined time ("No" in step T205), MRM is executed.

[0199] The threshold Dho for the remaining time Trmn is set to, for example, 20 seconds, which is significantly longer than the standard takeover time. The standard takeover time is the response wait time for handover requests due to dynamic factors such as roadside parking or lane restrictions, and is typically set to, for example, 6, 7, or 10 seconds. The response wait time for handover requests based on approaching prohibited areas is also set to, for example, 15 seconds, which is longer than the standard takeover time.

[0200] Based on the above structure, compared to handover requests based on dynamic factors, it allows for more time to implement permission transfers. Furthermore, while the structure for planned handover based on location information of prohibited shooting areas has been described above, it is assumed that map data near prohibited shooting areas is prohibited from creation and distribution due to laws or regulations. Map server 3 may also distribute location information related to prohibited distribution areas where maps are not prepared due to laws, etc., instead of the prohibited shooting area information. Figure 19 The process can replace the description of a prohibited area for filming with the description of a prohibited area for distribution and implementation. In other words, the processing unit 21 can also be configured to initiate a handover request in a planned manner based on the remaining time / distance before reaching the prohibited area for distribution.

[0201] Furthermore, the processing unit 21 can also display a message indicating that autonomous driving is possible when moving to an area where autonomous driving is possible, such as when leaving a prohibited shooting area or a prohibited distribution area. Moving to an area where autonomous driving is possible corresponds to moving into the ODD (Optical Distribution Controller). Additionally, notifications of the ability to use the autonomous driving function can be delivered via notification tones or sound messages. Alternatively, notifications of autonomous driving capability can be sent by illuminating / flashing light-emitting elements such as LEDs on the steering wheel, or by vibrating the steering wheel. The processing unit 21 can also calculate the remaining distance / time until leaving the prohibited shooting area or the prohibited distribution area, or the remaining distance / time until autonomous driving is possible, and display this information on the HUD (Head-Up Display).

[0202] <Postscript (1)>

[0203] In this disclosure, "extraordinary" refers to a state where the map data required for continuing autonomous driving control is incomplete. In other words, the state where the map data required for continuing autonomous driving control can be obtained is equivalent to the normal state. The state where the map data acquired by the map acquisition unit F4 is incomplete includes, for example, a state where, due to communication delays, it is impossible to acquire map data for the next area, thus including a missing portion of the map dataset required for implementing autonomous driving control; in other words, it includes a missing state. Furthermore, the state where the map data acquired by the map acquisition unit F4 is incomplete also includes a state where there is a gap between the map and the real world. The state where the map data acquired by the map acquisition unit F4 is incomplete also includes a state where the map update time is past a predetermined time, or a state where it is not the latest version. The above structure is equivalent to a structure for performing a prescribed extraordinary action when there is incompleteness in the partial map data acquired by the map acquisition unit F4, including the absence of some data. Furthermore, steps S201 and S302 are equivalent to map management steps. Additionally, at least one of steps S203, S205, S206, S208, and S306 is equivalent to a control planning step. An extraordinary action can also be referred to as an emergency action.

[0204] <Postscript (2)>

[0205] The control unit and method described in this disclosure can be implemented using a dedicated computer, which is configured as a processor programmed to perform one or more functions embodied in a computer program. Alternatively, the apparatus and method described in this disclosure can also be implemented using dedicated hardware logic circuits. Furthermore, the apparatus and method described in this disclosure can also be implemented using one or more dedicated computers, which are composed of a processor executing a computer program and a combination of one or more hardware logic circuits. Additionally, the computer program can be stored as instructions executable by a computer in a computer-readable, non-transitory physical storage medium. In other words, the units and / or functions provided by the autonomous driving device 20 can be provided by software recorded in a physical memory device and a computer executing that software, software only, hardware only, or a combination thereof. Some or all of the functions possessed by the autonomous driving device 20 can also be implemented as hardware. Implementing a function as hardware includes using one or more ICs, etc. The processing unit 21 can also be implemented using an MPU, GPU, or DFP (Data Flow Processor) instead of a CPU. Alternatively, the processing unit 21 can be implemented by combining various computing devices such as a CPU, MPU, and GPU. Furthermore, ECUs can also be implemented using FPGAs (field-programmable gate arrays) or ASICs (application-specific integrated circuits). Various programs can be stored on non-transitory tangible storage media. As the program storage medium, various storage media can be used, such as HDDs (hard-disk drives), SSDs (solid-state drives), EPROMs (erasable programmable ROMs), flash memory, and USB storage devices.

[0206] <Postscript (3)>

[0207] The following structure is also included in this disclosure.

[0208] [Structure (1)]

[0209] An autonomous driving device that uses partial map data to create a control plan, wherein the partial map data is map data of a portion of the overall map-covered area, the autonomous driving device comprising:

[0210] The map acquisition unit (F4) retrieves partial map data corresponding to the vehicle's location from the map server;

[0211] The Map Management Department (F5) determines the acquisition status of certain map data; and

[0212] The Control Planning Department (F7) uses partial map data to create control plans.

[0213] The map management department determines whether it is possible to obtain partial map data of the area where vehicles entered within the specified time, i.e., map data of the next area.

[0214] The Control Planning Department is structured to execute extraordinary actions based on the determination by the Map Management Department that map data for the next area cannot be obtained.

[0215] [Structure (2)]

[0216] According to the automatic driving device described in the above structure (1), wherein,

[0217] If map data for the next area cannot be obtained, calculate the remaining time until map data for the next area is needed.

[0218] When the remaining time before the next area map data is needed is less than a specified threshold, the planned action will be executed.

[0219] [Structure (3)]

[0220] According to the automatic driving device described in the above structure (1), wherein,

[0221] The remaining time until the next area map data is needed is the time until the vehicle exits the area corresponding to the portion of map data corresponding to the vehicle's current location, i.e., the area corresponding to the current area map data.

[0222] [Structure (4)]

[0223] According to the automatic driving device described in the above structure (1), wherein,

[0224] The remaining time until the next area map data is needed is the remaining time until the vehicle enters the area corresponding to the next area map data.

Claims

1. An autonomous driving device that uses map data to create a control plan that enables a vehicle to drive autonomously, comprising: The map management department determines the acquisition status of the aforementioned map data; and The Control Planning Department uses the aforementioned map data to create the aforementioned control plan. The aforementioned control planning department is configured to modify the content of the control plan based on the map data acquisition status determined by the aforementioned map management department. The aforementioned autonomous driving device uses some map data to create the aforementioned control plan, wherein, The map data mentioned above is only a portion of the overall map data for the region covered by the map. The aforementioned autonomous driving device also includes a map acquisition unit, which acquires the aforementioned partial map data corresponding to the location of the vehicle from a map server. The aforementioned map management department determines whether map data for the next area can be obtained. This next area map data refers to a portion of the map data concerning the area entered by the aforementioned vehicle within a specified time. The aforementioned control planning department is structured to plan and execute prescribed emergency actions based on the determination by the aforementioned map management department that map data for the next area cannot be obtained. If the map data for the next area cannot be obtained, the map management department calculates the remaining time for map retrieval, which is determined based on the remaining time until the map data for the next area is needed. The aforementioned control planning department plans the execution of the aforementioned emergency action based on the fact that the remaining time for map acquisition calculated by the aforementioned map management department is less than a specified threshold.

2. The automatic driving device according to claim 1, wherein, The aforementioned control planning department is structured as follows: Based on the fact that the remaining time for map acquisition is less than a predetermined first time, the process of notifying the occupants or operators of prescribed information related to the acquisition status of the aforementioned partial map data is executed as an emergency action. Based on the map above, if the remaining time is less than a predetermined second time, the speed of the vehicle is reduced as an emergency action, wherein the predetermined second time is shorter than the predetermined first time.

3. The automatic driving device according to claim 1 or 2, wherein, The aforementioned control planning department is structured as follows: The urgency level is calculated based on the remaining time obtained from the map above. The content of the aforementioned emergency actions will be modified according to the level of urgency described above.

4. The automatic driving device according to claim 1 or 2, The aforementioned map management department determines whether there are any incomplete parts in the aforementioned map data obtained by the aforementioned map acquisition department. The aforementioned control plan is designed to execute extraordinary actions based on the determination by the aforementioned map management department that certain map data is incomplete.

5. The automatic driving device according to claim 4, wherein, The aforementioned map management unit is configured to determine whether the map data matches the real world based on sensor information provided by monitoring sensors mounted around the aforementioned vehicle. If the aforementioned map data does not match the real world, it is determined that the aforementioned portion of the map data acquired by the map acquisition unit is incomplete.

6. The autonomous driving device according to claim 5, wherein, The aforementioned control plan, created by the control planning department, ensures that the inter-vehicle distance between advancing vehicles is at least a safe distance. Based on the determination by the map management department that some of the map data is incomplete, the control planning department temporarily sets the safety distance to a value larger than the prescribed standard value as an emergency action.

7. The automatic driving device according to claim 5, wherein, The aforementioned map management department determines that the map data does not match the real world under at least one of the following circumstances: Based on the aforementioned sensor information, it is determined that a vehicle ahead of the aforementioned vehicle is crossing the lane divider, and there is a stationary object in the lane in which the aforementioned vehicle is traveling, or Based on the aforementioned sensor information, it was determined that multiple vehicles traveling in the same lane consecutively crossed the lane divider, or The driving positions of surrounding vehicles traveling around the aforementioned vehicles are outside the road area shown in the map data above.

8. The automatic driving device according to claim 1 or 2, wherein, The aforementioned emergency actions include at least one of the following actions: notifying the occupants or operators outside the vehicle that the acquisition of the aforementioned partial map data has failed, increasing the inter-vehicle distance from the vehicle ahead, reducing the driving speed, requesting the occupants or operators to take over driving operations, initiating deceleration toward an emergency stop, requesting the aforementioned partial map data from surrounding vehicles using inter-vehicle communication, and continuing autonomous driving without using the aforementioned map data.

9. The automatic driving device according to claim 8, wherein, The configuration is as follows: when the above-mentioned extraordinary action based on the acquisition status of the above-mentioned map data is carried out, data indicating the acquisition status of the above-mentioned map data is output to the operation recording device, wherein the operation recording device is used to record the conditions inside and outside the vehicle when the vehicle is in motion.

10. The automatic driving device according to claim 1 or 2, wherein, Equipped with at least one processor The processor described above is configured to perform the processing required by the map management department and the control planning department.

11. The automatic driving device according to claim 10, wherein, The processor described above is configured to perform the following processes: The aforementioned partial map data corresponding to the location of the aforementioned vehicle is obtained from the map server via a wireless communication device installed in the aforementioned vehicle; The map data obtained from the map server is saved to the map storage unit, which is a designated storage area that retains the data even when the driving power supply is set to be disconnected. Determine whether the map storage unit contains the aforementioned partial map data concerning the area entered by the aforementioned vehicle within the specified time, i.e., the next area; and When the map storage unit stores the aforementioned partial map data concerning the next area, the process of receiving new map data concerning the next area from the map server is not performed, but the control plan is created using the partial map data stored in the map storage unit.

12. The automatic driving device according to claim 11, wherein, The processor described above is configured to perform the following processes: When creating a control plan using partial map data acquired during a previous driving session and stored in the aforementioned map storage unit, it is determined whether the partial map data matches the real world based on sensing information provided by the surrounding monitoring sensors mounted on the vehicle; and Based on the determination that the aforementioned map data does not match the real world, the aforementioned map data corresponding to the current location is downloaded from the aforementioned map server.

13. The automatic driving device according to claim 10, wherein, The processor described above is configured to perform the following processes: Based on the power supply for driving, the process of downloading the aforementioned partial map data corresponding to the current location and the aforementioned partial map data of the area that the vehicle enters within a specified time, i.e. the next area, is performed from the map server via the wireless communication device mounted on the vehicle. The aforementioned map data obtained from the map server is saved to a map storage unit, which is a designated storage area that retains data even when the driving power supply is set to be disconnected; and When the control plan is created and the aforementioned partial map data of the next region is required, the partial map data of the next region cannot be downloaded after the driving power is turned on. If the partial map data of the next region is stored in the map storage unit, the stored partial map data is used to create the control plan.

14. The automatic driving device according to claim 11, wherein, The processor described above is configured as follows: When creating the control plan using the partial map data obtained from the previous driving time and stored in the map storage unit, and when creating the control plan using the partial map data newly downloaded from the map server, the control conditions are changed.

15. The automatic driving device according to claim 10, wherein, The processor described above is configured to perform the following processes: Based on the sensing information provided by the surrounding monitoring sensors mounted on the aforementioned vehicle, it is determined whether the aforementioned portion of the map data used in the aforementioned control plan matches the real world. as well as An image representing the determination result of whether the aforementioned map data matches the real world will be displayed on the screen.

16. The automatic driving device according to claim 10, wherein, The processor described above is configured to perform the following processes: With the driving power supply turned on, the vehicle attempts to download the aforementioned partial map data corresponding to its current location from the map server via a wireless communication unit mounted on the vehicle. In the absence of downloading the aforementioned partial map data corresponding to the current location, a map representing the driving environment in front of the vehicle, i.e., an instant map, is created in real time based on sensing information provided by the surrounding monitoring sensors mounted on the vehicle. as well as The content of the control plan is modified based on the distance at which the real-time map can be created, i.e., the map creation distance.

17. The automatic driving device according to claim 10, wherein, The processor described above is configured to perform the following processes: The location information of areas where cameras are prohibited from shooting, i.e., areas where shooting is prohibited, or areas where the creation and distribution of maps are prohibited by law or regulations, i.e., areas where distribution is prohibited, is obtained from the map server via the wireless communication device installed in the aforementioned vehicle. Based on the location information of the aforementioned prohibited shooting area or the aforementioned prohibited distribution area obtained from the aforementioned map server, it is determined whether the aforementioned vehicle is approaching the aforementioned prohibited shooting area or the aforementioned prohibited distribution area; as well as Based on the fact that the vehicle is approaching the aforementioned prohibited filming area or the aforementioned prohibited distribution area, a takeover request is made to the driver or passenger or an operator outside the vehicle to take over the driving operation.

18. An autonomous driving device that uses map data to create a control plan that enables a vehicle to drive autonomously, comprising: The map management department determines the acquisition status of the aforementioned map data; and The Control Planning Department uses the aforementioned map data to create the aforementioned control plan. The aforementioned control planning department is configured to modify the content of the control plan based on the map data acquisition status determined by the aforementioned map management department. The aforementioned autonomous driving device uses some map data to create the aforementioned control plan, wherein, The map data mentioned above is only a portion of the overall map data for the region covered by the map. The aforementioned autonomous driving device also includes a map acquisition unit, which acquires the aforementioned partial map data corresponding to the location of the vehicle from a map server. The aforementioned map management department determines whether there are any incomplete parts in the aforementioned map data obtained by the aforementioned map acquisition department. The aforementioned control planning department is structured to execute prescribed emergency actions based on the map management department's determination that certain map data is incomplete. The aforementioned control plan, created by the control planning department, ensures that the inter-vehicle distance between advancing vehicles is at least a safe distance. Based on the map management department's determination that some map data is incomplete, the aforementioned control planning department temporarily sets the safety distance setting to a value larger than the prescribed standard value as an emergency action. The prescribed standard value is a value calculated by the control planning department using a mathematical formula model. The aforementioned map management department determines whether map data for the next area can be obtained. This next area map data refers to a portion of the map data concerning the area entered by the aforementioned vehicle within a specified time. The aforementioned control planning department is structured to plan and execute prescribed emergency actions based on the determination by the aforementioned map management department that map data for the next area cannot be obtained. If the map data for the next area cannot be obtained, the map management department calculates the remaining time for map retrieval, which is determined based on the remaining time until the map data for the next area is needed. The aforementioned control planning department plans the execution of the aforementioned emergency action based on the fact that the remaining time for map acquisition calculated by the aforementioned map management department is less than a specified threshold.

19. A vehicle control method, executed by at least one processor, for enabling a vehicle to drive autonomously using map data, comprising: Map management steps for determining the acquisition status of the aforementioned map data; and The control plan steps for creating the control plan for the aforementioned vehicle using the map data described above. The control plan steps described above modify the content of the control plan based on the map data acquisition status determined in the map management steps described above. The vehicle control method described above uses partial map data to create the control plan, wherein, The map data mentioned above is only a portion of the overall map data for the region covered by the map. The vehicle control method described above also includes a map acquisition step of obtaining the aforementioned partial map data corresponding to the location of the vehicle from a map server. The aforementioned map management steps determine whether map data for the next area can be obtained. This next area map data refers to the aforementioned portion of the map data concerning the area entered by the aforementioned vehicle within the specified time. The aforementioned control plan steps are based on the determination in the aforementioned map management steps that map data for the next area cannot be obtained, in order to plan the execution of prescribed emergency actions. If the map data for the next area cannot be obtained, the remaining time for map retrieval is calculated in the map management step described above. This remaining time is determined based on the time remaining until the map data for the next area is needed. The above control planning steps are based on the fact that the remaining time for map acquisition, calculated in the above map management steps, is less than a specified threshold, to plan the execution of the above extraordinary actions.

20. A vehicle control method, executed by at least one processor, for enabling a vehicle to drive autonomously using map data, comprising: Map management steps for determining the acquisition status of the aforementioned map data; and The control plan steps for creating the control plan for the aforementioned vehicle using the map data described above. The control plan steps described above modify the content of the control plan based on the map data acquisition status determined in the map management steps described above. The vehicle control method described above uses partial map data to create the control plan, wherein, The map data mentioned above is only a portion of the overall map data for the region covered by the map. The vehicle control method described above also includes a map acquisition step of obtaining the aforementioned partial map data corresponding to the location of the vehicle from a map server. The above map management steps determine whether there are any incomplete parts in the map data obtained through the above map acquisition steps. The aforementioned control plan steps are based on the determination in the aforementioned map management steps that some map data is incomplete, and are used to plan the execution of specified emergency actions. The above control plan steps create a control plan that ensures the inter-vehicle distance between the advancing vehicle and the vehicle is at least a safe distance. The aforementioned control plan steps are based on the determination in the aforementioned map management steps that some map data is incomplete. Therefore, the aforementioned safety distance setting is temporarily set to a value larger than the prescribed standard value as an emergency action. The prescribed standard value is a value calculated using a mathematical formula model. The aforementioned map management steps determine whether map data for the next area can be obtained. This next area map data refers to the aforementioned portion of the map data concerning the area entered by the aforementioned vehicle within the specified time. The aforementioned control plan steps are based on the determination by the map management department that map data for the next area cannot be obtained, and are intended to execute the prescribed emergency actions. If the map data for the next region cannot be obtained, the map management steps above calculate the remaining time for map retrieval. This remaining time is determined based on the time remaining until the map data for the next region is needed. The above control plan steps are based on the fact that the remaining time for map acquisition, calculated by the map management department, is less than a specified threshold, in order to plan the execution of the above-mentioned emergency actions.

Citation Information

Patent Citations

  • Underwater concrete placement amount confirmation method and device thereof

    JP2020117903A

  • Navigational system with imposed liability constraints

    WO2018115963A2

  • Navigation system

    JP1998141969A

  • Automatic driving support device and computer program

    JP2019053394A

  • System for building vehicle-to-cloud real-time traffic map for autonomous driving vehicle (ADV)

    JP2019145077A