Vehicle platform

By receiving trunk operation commands from the autonomous driving system through the vehicle control interface box, the trunk door can be opened and closed, solving the problem of unexpected trunk door actions during autonomous driving and improving the user experience.

CN115871702BActive Publication Date: 2026-05-15TOYOTA JIDOSHA KK +1
View PDF 3 Cites 0 Cited by

Patent Information

Authority / Receiving Office
CN · China
Patent Type
Patents(China)
Current Assignee / Owner
TOYOTA JIDOSHA KK
Filing Date
2022-09-26
Publication Date
2026-05-15

AI Technical Summary

Technical Problem

During autonomous driving, the tailgate may move at unexpected times, causing inconvenience and noise issues.

Method used

The system receives trunk operation commands from the Automated Driving System (ADS) via the Vehicle Control Interface Box (VCIB), controls the opening and closing of the trunk door, ensures actions are performed at moments anticipated by the user, and suppresses erroneous actions by setting a one-second continuous request condition.

Benefits of technology

It effectively suppresses unexpected movements of the trunk door, improves user experience, and ensures the appropriateness and consistency of the actions.

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure CN115871702B_ABST
    Figure CN115871702B_ABST
Patent Text Reader

Abstract

The present disclosure provides a vehicle platform. A body system determines whether an entry door of all seats or an entry door of rear seats is unlocked (S1). When a determination of "Yes" is made, the body system determines whether a trunk operation command received by a VCB from an ADK (ADS) indicates an "open / close request" of a trunk door (S3). When a determination of "Yes" is made, the body system determines whether it has been receiving the "open / close request" for one second (S5). When a determination of "Yes" is made, the body system starts an operation of the trunk door (S7).
Need to check novelty before this filing date? Find Prior Art

Description

[0001] This non-provisional application is based on Japanese Patent Application No. 2021-157663, filed with the Japan Patent Office on September 28, 2021, the entire contents of which are incorporated herein by reference. Technical Field

[0002] This disclosure relates to a vehicle platform configured to allow autonomous driving. Background Technology

[0003] Recently, technologies for autonomous driving of vehicles have been developed. For example, Japanese Patent Publication No. 2018-132015 discloses a vehicle comprising: a power system that centrally manages the vehicle's power; a power supply system that centrally manages the power supply to various on-board devices; and an autonomous driving system that centrally implements autonomous driving control of the vehicle. Summary of the Invention

[0004] During autonomous driving, the trunk (rear door) can be opened / closed automatically based on commands from the autonomous driving system. In this case, it is not expected that the trunk will move at a time that is not desired by the user.

[0005] This disclosure is made to address the above problems, and its purpose is to prevent the trunk door from moving at times that are not desired by the user during autonomous driving.

[0006] According to one aspect of this disclosure, a vehicle platform is capable of installing an autonomous driving system. The vehicle platform includes a vehicle and a vehicle control interface box that interfaces between the vehicle and the autonomous driving system. The vehicle includes an entrance door and a trunk door. When the entrance door is unlocked, the vehicle receives a trunk operation command from the autonomous driving system, received by the vehicle control interface box, requesting action on the trunk door.

[0007] According to another aspect of this disclosure, a vehicle platform includes an autonomous driving system for creating driving plans, a vehicle for implementing vehicle control based on commands from the autonomous driving system, and a vehicle control interface box for interfacing between the vehicle and the autonomous driving system. The vehicle includes an entrance door and a trunk door. When the entrance door is unlocked, the vehicle receives a trunk operation command from the autonomous driving system, received by the vehicle control interface box, requesting action on the trunk door.

[0008] When the entry door is unlocked, the user can anticipate that the trunk door may be opened. According to the configuration, the vehicle receives a trunk operation command when the entry door is unlocked. Therefore, the trunk door can be opened at a moment when the user can anticipate its operation.

[0009] In one embodiment, the vehicle accepts the trunk operation command when the access door to the rear seats is unlocked.

[0010] When the rear seat access door is unlocked, the user can further anticipate that the trunk lid may be opened. According to this configuration, since the vehicle receives the trunk operation command when the rear seat access door is unlocked, the trunk lid can be opened at a moment when the user can anticipate the trunk lid's movement.

[0011] In one embodiment, the trunk operation command includes a first request for opening / closing the trunk door. While the vehicle remains accepting the first request for one second, the vehicle activates the trunk door.

[0012] According to the configuration, by setting the condition for the trunk to operate continuously for one second, it is possible to suppress erroneous operation of the trunk door due to noise or other reasons.

[0013] In one embodiment, the trunk operation command includes a second request indicating no further request. When the vehicle accepts the second request while the trunk door is in operation, the vehicle allows the trunk door operation to continue.

[0014] According to the configuration, the trunk door can be opened appropriately.

[0015] In one embodiment, when the vehicle accepts the first request after accepting the second request while the trunk door is in operation, the vehicle stops the operation of the trunk door.

[0016] According to the configuration, the trunk door can be opened appropriately.

[0017] In one embodiment, when the vehicle stops the operation of the tailgate, and subsequently when the vehicle restarts the tailgate according to the tailgate operation command, the vehicle controls the tailgate to perform an action opposite to the action before it stopped.

[0018] When the trunk lid is reopened after it has stopped, it is likely desirable to perform the opposite action to the action performed before it stopped. According to the configuration described, when the trunk lid is reopened, the control performs the opposite action to the action performed before it stopped, thus improving user convenience.

[0019] In one embodiment, the autonomous driving system transmits the first request until the trunk door is fully opened or closed.

[0020] According to the configuration, it is possible to prevent the process from ending when the trunk door is not in a fully open or closed state.

[0021] The foregoing and other objects, features, aspects and advantages of this disclosure will become more apparent when taken in conjunction with the accompanying drawings and the following detailed description of this disclosure. Attached Figure Description

[0022] Figure 1 A diagram illustrating an outline of a vehicle according to an embodiment of the present disclosure.

[0023] Figure 2 To show in more detail Figure 1 The diagram shows the configuration of ADK (ADS) and VP.

[0024] Figure 3 A diagram illustrating the side view of the base vehicle.

[0025] Figure 4 This is a diagram used to illustrate the commands for operating the trunk.

[0026] Figure 5 A flowchart illustrating the steps involved in the process of opening / closing the trunk door.

[0027] Figure 6 A flowchart illustrating the steps of the processing performed simultaneously with the trunk door opening.

[0028] Figure 7 A diagram illustrating the overall structure of an Autono-MaaS vehicle.

[0029] Figure 8 A diagram illustrating the system architecture of an Autono-MaaS vehicle.

[0030] Figure 9 A diagram illustrating a typical workflow in ADS.

[0031] Figure 10 A graph illustrating the relationship between the front wheel steering angle rate limit and speed.

[0032] Figure 11 This is the state machine diagram for power mode.

[0033] Figure 12 A diagram showing the details of the gear shift sequence.

[0034] Figure 13 To illustrate a fixed order.

[0035] Figure 14 A diagram illustrating the static sequence.

[0036] Figure 15 The state machine diagram represents the autonomous state.

[0037] Figure 16 A diagram illustrating the authentication process. Detailed Implementation

[0038] Embodiments of this disclosure will now be described in detail with reference to the accompanying drawings. Identical or corresponding elements in the drawings have been assigned the same reference numerals, and their descriptions will not be repeated.

[0039] <Overall Configuration>

[0040] Figure 1 A diagram illustrating a general outline of a vehicle 10 according to an embodiment of the present disclosure. (Refer to...) Figure 1 The vehicle 10 includes an autonomous driving kit (hereinafter referred to as "ADK") 200 and a vehicle platform (hereinafter referred to as "VP") 120. The ADK 200 is configured to be attached to (or mounted on) the VP 120. The ADK 200 and the VP 120 are configured to communicate with each other via a vehicle control interface box 111 (described later) mounted on the VP 120.

[0041] The VP 120 is capable of performing autonomous driving based on control requests (commands) from the ADK 200. Although Figure 1 The VP120 and ADK 200 are shown in a position far apart from each other, but ADK 200 is actually attached to the roof or other parts of the base vehicle 100 (described later) included in the VP120. ADK 200 can also be removed from the VP120. When ADK 200 is not attached, the VP120 can be driven by the user. In this case, the VP120 performs driving control in manual mode (driving control based on user operation).

[0042] ADK 200 includes an automated driving system (hereinafter referred to as "ADS") 202 for automated driving of vehicle 10. For example, ADS 202 creates a driving plan for vehicle 10. Then, ADS 202 outputs various commands (control requests) to VP 120 for vehicle 10 to drive according to the created driving plan, based on application programming interfaces (APIs) defined for each command. ADS 202 receives various signals from VP 120 indicating the state (vehicle state) of VP 120, based on APIs defined for each signal. ADS 202 then reflects the received vehicle state in the creation of the driving plan. The detailed configuration of ADS 202 will be described later.

[0043] VP 120 includes a base vehicle 100 and a vehicle control interface box (hereinafter referred to as "VCIB") 111.

[0044] The base vehicle 100 performs various types of vehicle control based on control requests from ADK 200 (ADS 202). The base vehicle 100 includes various systems and sensors for controlling the vehicle. Specifically, the base vehicle 100 includes an integrated control manager 115, a braking system 121, a steering system 122, a powertrain system 123, an active safety system 125, a body system 126, wheel speed sensors 127A and 127B, a pinion angle sensor 128, a camera 129A, and radar sensors 129B and 129C.

[0045] The integrated control manager 115 includes a processor and a memory, and integrates the control of the systems involved in the operation of the vehicle (braking system 121, steering system 122, powertrain system 123, active safety system 125, and body system 126).

[0046] The braking system 121 is configured to control braking devices disposed in each wheel. The braking devices include, for example, a disc brake system (not shown) that is operated using hydraulic pressure regulated by an actuator.

[0047] Wheel speed sensors 127A and 127B are connected to braking system 121. Wheel speed sensor 127A detects the rotational speed of the front wheels and outputs its detected value to braking system 121. Wheel speed sensor 127B detects the rotational speed of the rear wheels and outputs its detected value to braking system 121.

[0048] The braking system 121 generates braking commands to the braking equipment based on a specified control request output from ADK 200 via VCIB 111 and the integrated control manager 115. The braking system 121 then controls the braking equipment based on the generated braking commands. The integrated control manager 115 is capable of calculating the vehicle speed (vehicle speed) based on the rotational speed of each wheel.

[0049] The steering system 122 is configured to control the steering angle of the vehicle's steering wheel using a steering device. The steering device includes, for example, rack and pinion electric power steering (EPS) that allows adjustment of the steering angle via an actuator.

[0050] The pinion angle sensor 128 is connected to the steering system 122. The pinion angle sensor 128 detects the rotation angle (pinion angle) of the pinion gear connected to the rotating shaft of the actuator included in the steering device and outputs its detected value to the steering system 122.

[0051] The steering system 122 generates steering commands to the steering device based on the specified control requests output from the ADK 200 via the VCIB 111 and the integrated control manager 115. The steering system 122 then controls the steering device based on the generated steering commands.

[0052] The powertrain system 123 controls an electronic parking brake (EPB) system located in at least one wheel of a plurality of wheels, a parking lock (P lock) system located in the transmission of the base vehicle 100, and a propulsion system including a shifting device for selecting a shift range. See below for further details. Figure 2 Describe the detailed configuration of powertrain system 123.

[0053] The active safety system 125 uses camera 129A and radar sensors 129B and 129C to detect obstacles (pedestrians, bicycles, parked vehicles, utility poles, etc.) in front of or behind the vehicle. Based on the distance between the vehicle 10 and the obstacle and the direction of the vehicle 10's movement, the active safety system 125 determines whether a collision with the obstacle is possible. Then, when the active safety system 125 determines that a collision is possible, it outputs a braking command to the braking system 121 via the integrated control manager 115 to increase the vehicle's braking force.

[0054] The body system 126 is configured to control various devices such as turn indicators, headlights, hazard warning lights, horn, front wipers, and rear wipers (not shown), for example, based on the driving state or environment of the vehicle 10. The body system 126 controls these various devices according to specified control requests output from the ADK 200 via VCIB 111 and the integrated control manager 115. The body system 126 is also configured to control the opening and closing device of the tailgate (rear door) (described later). The body system 126 controls the opening and closing device to open the tailgate according to specified control requests output from the ADK 200 via VCIB 111 and the integrated control manager 115.

[0055] VCIB 111 is configured to communicate with ADS 202 of ADK 200 via Controller Area Network (CAN). VCIB 111 receives various control requests from ADS 202, or outputs the status of VP 120 to ADS 202 by executing the prescribed APIs defined for each communication signal. When VCIB 111 receives a control request from ADS 202, it outputs a control command corresponding to the control request to the corresponding system via Integrated Control Manager 115. VCIB 111 obtains various types of information about the base vehicle 100 from various systems via Integrated Control Manager 115 and outputs the status of the base vehicle 100 as the vehicle status to ADS 202.

[0056] Vehicle 10 can be used as one of the features of a Mobility as a Service (MaaS) system. In addition to vehicle 10, the MaaS system further includes, for example, a data server and a Mobility Service Platform (MSPF) (both not shown).

[0057] MSPF is an integrated platform that connects various mobility services. Mobility services related to autonomous driving connect to MSPF. In addition to mobility services related to autonomous driving, mobility services provided by ride-sharing companies, car-sharing companies, car rental companies, taxi companies, and insurance companies can connect to MSPF. Depending on the service content, various mobility services can utilize the various functionalities provided by MSPF by using APIs published on MSPF.

[0058] VP 120 further includes a data communication module (DCM) (not shown) as a communication interface (I / F) for wireless communication with the data server of the MaaS system. The DCM outputs various types of vehicle information, such as speed, location, or autonomous driving status, to the data server. The DCM receives various types of data from autonomous driving-related mobility services via MSPF and the data server for managing the operation of autonomous vehicles, including vehicle 10, within the mobility services.

[0059] MSPF publishes APIs for using various types of data regarding vehicle status and vehicle control required for ADK development. By using the APIs published on MSPF, various mobility services can utilize various functions provided by MSPF, depending on their service content. For example, mobility services related to autonomous driving can obtain operational control data of autonomous vehicles communicating with a data server or information stored in a data server from MSPF using the APIs published on MSPF. Mobility services related to autonomous driving can also send data to MSPF for managing autonomous vehicles, including vehicle 10, using the APIs.

[0060] Figure 2 To show in further detail Figure 1 The diagram shows the configuration of the ADK 200 (ADS 202) and VP 120. (Refer to...) Figure 2 The ADK 200's ADS 202 includes a computing component 210, a human-machine interface (HMI) system 230, a sensor 260 for sensing, a sensor 270 for posture, and a sensor cleaner 290.

[0061] The computing component 210 includes communication modules 210A and 210B. Communication modules 210A and 210B are configured to communicate with VCIB 111. During autonomous driving of vehicle 10, computing component 210 obtains information about the environment surrounding the vehicle, as well as the attitude, behavior, and position of vehicle 10, from various sensors (described later), and obtains the vehicle state from VP 120 via VCIB 111, and sets the next action of vehicle 10 (acceleration, deceleration, or turning). Then, computing component 210 outputs various commands to VP 120's VCIB 111 to implement the set next action.

[0062] The HMI 230 presents information to the user and accepts user input during autonomous driving, during driving requiring user intervention, or during the transition between autonomous driving and driving requiring user intervention. The HMI 230 is configured to connect to input and output devices (not shown), such as the touch panel display provided in VP 120.

[0063] The sensor 260 for sensing is a sensor that senses the environment around the vehicle. The sensor 260 for sensing includes at least one of, for example, laser imaging detection and ranging (LIDAR), millimeter-wave radar, and camera.

[0064] LIDAR refers to a distance measurement device that measures distance based on the time interval from the emission of a pulsed laser beam (infrared) to the return of the laser beam reflected by the object. Millimeter-wave radar is a distance measurement device that measures the distance or direction to an object by emitting short-wavelength radio waves towards it and detecting the radio waves returning from the object. A camera, for example, is positioned behind the rearview mirror inside the vehicle compartment and is used to capture images of the area in front of vehicle 10. As a result of image processing of the images or video images captured by the camera by an artificial intelligence (AI) or image processing processor, it is possible to identify another vehicle, obstacle, or person in front of vehicle 10. Information obtained by the sensing sensor 260 is output to the computing component 210.

[0065] The attitude sensor 270 is a sensor that detects the attitude, behavior, or position of the vehicle 10. The attitude sensor 270 includes, for example, an inertial measurement unit (IMU) and a global positioning system (GPS).

[0066] The IMU detects, for example, the acceleration of vehicle 10 in the forward, lateral, and vertical directions, as well as the angular velocities of vehicle 10 in the roll, pitch, and yaw directions. GPS detects the position of vehicle 10 based on information received from multiple GPS satellites orbiting the Earth. Information obtained by the attitude sensor 270 is output to the computing unit 210.

[0067] Sensor cleaner 290 removes dirt adhering to various sensors. Sensor cleaner 290, for example, uses a cleaning solution or wipe to remove dirt adhering to camera lenses or parts that emit laser beams or radio waves.

[0068] VCIB 111 includes VCIB 111A and VCIB 111B. Each of VCIB 111A and VCIB 111B includes an Electronic Control Unit (ECU). The ECU includes a processor such as a Central Processing Unit (CPU) (not shown) and memory (Read-Only Memory (ROM) and Random Access Memory (RAM)). Programs executable by the processor are stored in the ROM. The processor performs various types of processing according to the programs stored in the ROM.

[0069] VCIB 111A and VCIB 111B are communicatively connected to communication modules 210A and 210B of ADS 202, respectively. VCIB 111A and VCIB 111B are also communicatively connected to each other. Although VCIB 111B is functionally equivalent to VCIB 111A, it differs in some respects from the multiple systems that it connects to that make up VP 120.

[0070] VCIB 111A and VCIB 111B each relay control requests and vehicle status between ADS 202 and VP 120. A more specific description will be given, representatively focusing on VCIB 111A. VCIB 111A receives various control requests output from ADS 202 according to the APIs defined for each control request. VCIB 111A then generates a command corresponding to the received control request and outputs the command to the system of the base vehicle 100 corresponding to the control request. In this embodiment, the control request received from ADS 202 includes a trunk operation command instructing the base vehicle 100 to open / close its trunk door (rear door).

[0071] VCIB 111A receives vehicle information from various systems of VP 120 and sends information indicating the vehicle status of VP 120 to ADS 202 according to the API defined for each vehicle status. The information indicating the vehicle status to be sent to ADS 202 may be the same information as the vehicle information provided from various systems of VP 120, or it may be information extracted from the vehicle information for processing performed by ADS 202.

[0072] Because VCIB 111A and VCIB 111B provide functional equivalents related to the operation of at least one system (e.g., braking or steering system), the control system between ADK 200 and VP 120 is redundant. Therefore, when a certain type of failure occurs in a part of the system, the function of VP 120 (turning or stopping) can be maintained by appropriately switching or disconnecting the failed control system between the control systems.

[0073] Braking system 121 includes braking systems 121A and 121B. Steering system 122 includes steering systems 122A and 122B. Powertrain system 123 includes EPB system 123A, P lock system 123B, and propulsion system 124.

[0074] VCIB 111A is communicatively connected to braking system 121A, steering system 122A, EPB system 123A, P lock system 123B, propulsion system 124, and body system 126 via a communication bus. VCIB 111B is communicatively connected to braking system 121B, steering system 122B, and P lock system 123B via a communication bus.

[0075] Braking systems 121A and 121B are configured to control multiple braking devices disposed in the wheels. Braking system 121B may be functionally equivalent to braking system 121A, or one of braking systems 121A and 121B may be configured to independently control the braking force of each wheel during vehicle travel, while the other of braking systems 121A and 121B may be configured to control the braking force so that the same braking force is generated in the wheels during vehicle travel.

[0076] Braking systems 121A and 121B each generate braking commands to the braking device based on control requests received from ADS 202 via VCIB 111. For example, braking systems 121A and 121B control the braking device based on braking commands generated in one of the braking systems, and control the braking device based on braking commands generated in the other braking system when a fault occurs in that braking system.

[0077] Steering systems 122A and 122B are configured to control the steering angle of the steering wheel of vehicle 10 using steering equipment. Steering system 122B is functionally similar to steering system 122A.

[0078] Steering systems 122A and 122B each generate steering commands to the steering device based on control requests received from ADS 202 via VCIB 111. For example, steering systems 122A and 122B control the steering device based on steering commands generated in one of the steering systems, and, in the event of a fault in that steering system, control the steering device based on steering commands generated in the other steering system.

[0079] EPB system 123A is configured to control EPB. EPB is separate from the braking device and the wheels are secured by the operation of an actuator. For example, EPB secures the wheels by actuating a drum brake for a parking brake located in at least one of a plurality of wheels, or by actuating the braking device to secure the wheels using an actuator capable of adjusting the hydraulic pressure to be supplied to the braking device separately from braking systems 121A and 121B.

[0080] EPB system 123A controls the EPB based on control requests received from ADS 202 via VCIB 111.

[0081] The P-lock system 123B is configured to control the P-lock device. The P-lock device assembles a protrusion (the position of which is adjusted by an actuator) located at the end of the parking lock pawl into the teeth of a gear (locking gear) that is configured to connect with a rotating element in the transmission of the base vehicle 100. The rotation of the transmission output shaft is thus fixed and the wheels are fixed.

[0082] The P lock system 123B controls the P lock device according to control requests received from the ADS 202 via the VCIB 111. When the control request from the ADS 202 includes a request to set the shift gear to Park (P), the P lock system 123B activates the P lock device, and when the control request includes a request to set the shift gear to a shift gear other than P, it deactivates the P lock device.

[0083] The propulsion system 124 is configured to switch gears using a shifting device and control the driving force of the vehicle 10 generated by the drive source in the direction of movement of the vehicle 10. Switchable gears include, for example, P (Park), neutral (N), drive (D), and reverse (R). The drive source includes, for example, an electric generator and an engine.

[0084] The propulsion system 124 controls the shifting device and drive source according to the control request received from ADS 202 via VCIB 111.

[0085] The active safety system 125 is communicatively connected to the braking system 121A. As described above, the active safety system 125 detects obstacles (obstacles or people) in front of the vehicle using a camera 129A and a radar sensor 129B, and when it determines that there is a possibility of collision based on the distance to the obstacle, it outputs a braking command to the braking system 121A to increase braking force.

[0086] The body system 126 controls various devices based on control requests (control commands) received from the ADS 202 via the VCIB 111. These devices include, for example, turn indicators, headlights, hazard warning lights, a horn, front wipers, and rear wipers. Additionally, the devices include opening and closing mechanisms for the tailgate. Figure 3 In other words, the body system 126 controls the opening and closing devices for the trunk door based on control requests received from the ADS 202 via the VCIB 111 and the integrated control manager 115.

[0087] For example, autonomous driving is performed when the user selects the autonomous mode as the autonomous state through operation of the HMI 230 in vehicle 10. During autonomous driving, ADS 202 initially creates a driving plan as described above. Examples of driving plans include plans to continue straight, plans to turn left / right at designated intersections on the predetermined driving path, and plans to change driving lanes.

[0088] ADS 202 calculates the controllable physical quantities (acceleration, deceleration, and wheel steering angle) required for the operation of vehicle 10 based on the created driving plan. ADS 202 segments the physical quantities for each execution cycle of the API. ADS 202 outputs control requests representing the segmented physical quantities to VCIB 111 via the API. Furthermore, ADS 202 obtains the vehicle state (actual direction of movement and stationary state) from VP 120 and recreates a driving plan reflecting the obtained vehicle state. ADS 202 thus enables autonomous driving of vehicle 10.

[0089] Figure 3 The diagram schematically shows a side view of the base vehicle 100. The base vehicle 100 includes a front seat door 161, a rear seat door 162, a front seat door locking device 165, a rear seat door locking device 166, a trunk door (rear door) 170, and an opening and closing device 175.

[0090] The front seat door locking device 165 is configured to switch the front seat door 161 between a locked state and an unlocked state. The rear seat door locking device 166 is configured to switch the rear seat door 162 between a locked state and an unlocked state. The front seat door locking device 165 and the rear seat door locking device 166 are activated according to control signals from the body system 126.

[0091] The tailgate (rear door) 170 is provided as the rear door of the base vehicle 100. The tailgate 170 is provided with an opening and closing device 175. For example, the opening and closing device 175 includes an actuator and opens and closes the tailgate 170 according to a control signal from the body system 126. Figure 3 The trunk door 170 is shown fully closed by solid lines. Figure 3 The trunk door 170 is shown fully open by the dashed line.

[0092] <Opening and closing the trunk>

[0093] As described above, the control request received by VCIB 111 from ADS 202 includes a trunk operation command requesting the opening / closing of the trunk door 170 of the base vehicle 100. The trunk operation command is converted by VCIB 111 into a corresponding control command and sent to the body system 126 via the integrated control manager 115. The body system 126 controls the opening / closing device 175 to activate the trunk door 170 according to the trunk operation command (control command).

[0094] Figure 4 This is a diagram used to illustrate the commands for operating the trunk. Figure 4 This displays the possible values, descriptions, and remarks for the trunk operation commands.

[0095] The trunk operation command uses any one of the values ​​0, 1, 2, and 3. Value 0 represents "no request." Although described in detail later, value 0 is set to maintain (continue) the current action. Value 1 represents "open / close request." An open / close request is a request for action on the trunk door 170 (opening / closing device 175). Values ​​2 and 3 represent "hold." Although values ​​2 and 3 are not used in this embodiment, they can be set and used as appropriate.

[0096] When VCIB 111 receives a trunk operation command from ADK 200 (ADS 202), it generates a control command corresponding to the value indicated in the trunk operation command and outputs the control command to the base vehicle 100. The integrated control manager 115 of the base vehicle 100 outputs the control command received from VCIB 111 to the body system 126. When the trunk operation command indication value is 0, VCIB 111 generates a control command indicating "no request" and outputs the control command to the body system 126. When the trunk door request indication value is 1, VCIB 111 generates a control command indicating "open / close request" and outputs the control command to the body system 126. Specifically, the control command output from VCIB 111 is provided to the body system 126 via the integrated control manager 115.

[0097] The body system 126 receives the trunk operation command (control command) when all the doors of the seats in vehicle 10 are unlocked, or when the rear door of vehicle 10 is unlocked. In other words, the body system 126 receives the trunk operation command (control command) when at least the rear door is unlocked. The body system 126 does not receive the trunk operation command (control command) unless the rear door is unlocked.

[0098] When the received trunk operation command indicates "no request", the body system 126 maintains (continues) the current operation. Specifically, when the body system 126 receives a trunk operation command indicating "no request" while the trunk door 170 is fully closed or open, it maintains the state of the trunk door 170 (fully closed or open) without activating the opening and closing device 175.

[0099] When the body system 126 receives a trunk operation command indicating an "open / close request" while the trunk door 170 is fully closed or open, its control device 175 causes the trunk door 170 to change to the opposite state. Specifically, for example, when the body system 126 receives a trunk operation command indicating an "open / close request" while the trunk door 170 is fully closed, its control device 175 causes the trunk door 170 to change to the fully open state. For example, when the body system 126 receives a trunk operation command indicating an "open / close request" while the trunk door 170 is fully open, its control device 175 causes the trunk door 170 to change to the fully closed state. When the body system 126 holds the trunk operation command indicating an open / close request (action request) for 1 second, it begins the operation of the trunk door 170 (opening / closing device 175).

[0100] When ADK 200 (ADS 202) outputs the trunk operation command for the first time, it continues to output the trunk operation command until the trunk door 170 is fully opened or closed.

[0101] Even when ADK 200 requests a "no request" trunk operation command when performing an action to open or close the trunk door 170, the body system 126 controls the opening / closing device 175 to allow the operation of the trunk door 170 (opening or closing action) to continue until the trunk door 170 is fully open or closed. In other words, even when the trunk operation command changes from "open / close request" to "no request" during the opening or closing action of the trunk door 170, the body system 126 allows the operation of the trunk door 170 (opening or closing action) to continue. More specifically, even when the trunk operation command changes from "open / close request" to "no request" during the opening action of the trunk door 170, the body system 126 allows the opening action of the trunk door 170 to continue. Even when the trunk operation command changes from "open / close request" to "no request" during the closing action of the trunk door 170, the body system 126 allows the closing action of the trunk door 170 to continue.

[0102] When the trunk operation command changes from "open / close request" to "no request" during the opening or closing action of the trunk door 170, and then the trunk operation command further changes from "no request" to "open / close request", the body system 126 controls the opening and closing device 175 to suspend the action of the trunk door 170.

[0103] When ADK 200 (ADS 202) pauses the operation of the trunk door 170, it changes the trunk operation command to, for example, "no request".

[0104] When the body system 126 pauses the operation of the tailgate 170 and then restarts it, it controls the tailgate 170 to perform the opposite action. Specifically, when the body system 126 holds a tailgate operation command indicating an "open / close request" for 1 second while the operation of the tailgate 170 remains stopped, the body system 126 controls the opening / closing device 175 to perform the opposite action (reverse action) to the action before the tailgate 170 stopped. More specifically, when the tailgate 170 was in an open position before the operation stopped, the body system 126 controls the opening / closing device 175 to make the tailgate 170 close as the opposite action. When the tailgate 170 was in a closed position before the operation stopped, the body system 126 controls the opening / closing device 175 to make the tailgate 170 open as the opposite action.

[0105] Figure 5This is a flowchart illustrating the steps involved in the processing related to the opening / closing of the tailgate 170. When the body system 126 receives a tailgate operation command (control command) when the tailgate 170 is fully closed or open, the process begins with the body system 126. Figure 5 The processing in the flowchart. Although Figure 5 The processing in the flowchart is described as being performed by the body system 126 via software, but some or all of it may be performed by hardware (circuit) manufactured in the body system 126.

[0106] In S1, the body system 126 determines whether all seat doors or the rear seat doors are unlocked. In other words, the body system 126 determines whether at least the rear seat doors are unlocked. Unless the rear seat doors are unlocked ("No" in S1), the body system 126 does not accept the trunk operation command and terminates the process without activating the trunk door 170. When at least the rear seat doors are unlocked ("Yes" in S1), the body system 126 proceeds to S3.

[0107] In S3, the body system 126 receives a trunk operation command. Subsequently, the body system 126 determines whether the received trunk operation command indicates an "open / close request." Specifically, the body system 126 determines the content of the trunk operation command based on the control command received from the VCIB 111 via the integrated control manager 115. In other words, the body system 126 determines whether the trunk operation command received by the VCIB 111 from the ADS 202 indicates an "open / close request" based on the control command from the VCIB 111. If the trunk operation command is not an "open / close request" ("no" in S3), the body system 126 exits processing without activating the trunk door 170 (opening / closing device 175). In other words, when the trunk operation command indicates "no request," the body system 126 exits processing without activating the trunk door 170. When the trunk operation command indicates "open / close request" ("yes" in S3), the body system 126 causes the processing to proceed to S5.

[0108] In S5, the body system 126 determines whether it continues to receive the "open / close request" for 1 second. If the body system 126 does not continue to receive the "open / close request" for 1 second ("No" in S5), it continuously waits to receive the "open / close request" for 1 second. When the body system 126 continues to receive the "open / close request" for 1 second ("Yes" in S5), the body system 126 proceeds to S7. If the trunk operation command is lost before the body system 126 continues to receive the "open / close request" for 1 second, the process can be terminated.

[0109] In S7, the body system 126 controls the opening and closing device 175 based on the state of the tailgate 170. (Refer to...) Figure 6 Describe the details of the processing in S7.

[0110] Figure 6 A flowchart illustrating the steps of processing performed simultaneously with the operation of the trunk door 170.

[0111] In S70, the body system 126 initiates the operation of the tailgate 170. Specifically, when the tailgate 170 is in a fully closed state before the operation begins, the body system 126 controls the opening and closing device 175 to fully open the tailgate 170. When the tailgate 170 is in a fully open state before the operation begins, the body system 126 controls the opening and closing device 175 to fully close the tailgate 170.

[0112] In S71, the body system 126 determines whether the trunk door 170 has been fully opened or closed. Specifically, when the body system 126 controls the opening / closing device 175 to fully open the trunk door 170, it determines whether the trunk door 170 has been fully opened (the opening / closing device 175 has moved to the fully open position). When the body system 126 controls the opening / closing device 175 to fully close the trunk door 170, it determines whether the trunk door 170 has been fully closed (the opening / closing device 175 has moved to the fully closed position). When the body system 126 determines that the trunk door 170 has not been fully opened or closed ("No" in S71), it proceeds to S72. When the body system 126 determines that the trunk door 170 has been fully opened or closed ("Yes" in S71), it proceeds to S78.

[0113] In S72, the body system 126 controls the opening and closing device 175 to continue the operation of the tailgate 170.

[0114] In S73, the body system 126 determines whether the trunk operation command has changed from "open / close request" to "no request". The body system 126 determines the content of the trunk operation command based on the control command received from VCIB 111 via the integrated control manager 115. When the body system 126 determines that the trunk operation command has changed from "open / close request" to "no request" ("yes" in S73), the body system 126 returns the process to S71 and allows the operation of the trunk door 170 to continue. When the body system 126 determines that the trunk operation command has not changed from "open / close request" to "no request" ("no" in S73), it proceeds to S74.

[0115] In S74, the body system 126 determines whether the trunk operation command has changed from "no request" to "open / close request". When the body system 126 determines that the trunk operation command has not yet changed from "no request" to "open / close request" ("no" in S74), that is, when the body system 126 continues to receive "open / close request", it returns the process to S71 and allows the operation of the trunk door 170 to continue. When the body system 126 determines that the trunk operation command has changed from "no request" to "open / close request" ("yes" in S74), it proceeds to S75.

[0116] In S75, the body system 126 controls the opening and closing device 175 to pause the operation of the tailgate 170. When the ADS 202 pauses the operation of the tailgate 170, it outputs, for example, a tailgate operation command indicating "no request".

[0117] In S76, the body system 126 determines whether it has maintained the trunk operation command indicating "open / close request" for one second. If the body system 126 has not maintained the trunk operation command indicating "open / close request" for one second ("No" in S76), it continues to pause the trunk door 170. If the body system 126 has maintained the trunk operation command indicating "open / close request" for one second ("Yes" in S76), it proceeds to S77.

[0118] In S77, the body system 126 controls the opening and closing device 175 to cause the tailgate 170 to perform the opposite action (reverse action) to the action before the action stopped. Subsequently, the body system 126 returns the processing to S71.

[0119] In S78, since the tailgate 170 has been fully opened or closed, the body system 126 exits control of the opening / closing device 175 and completes the operation of the tailgate 170. In this case, the body system 126 or the integrated control manager 115 can provide a signal to the VCIB 111 indicating that the tailgate 170 has been fully opened or closed. Subsequently, the VCIB 111 can notify the ADK 200 (ADS 202) that the tailgate 170 has been fully opened or closed, allowing the ADS 202 to exit the output of tailgate operation commands.

[0120] As described above, in this embodiment, the base vehicle 100 (body system 126) receives a trunk operation command (control command) from the ADK 200 (ADS 202) when at least the rear seat doors are unlocked. If the rear seat doors are not unlocked, the base vehicle 100 (body system 126) does not receive the trunk operation command (control command). By receiving the trunk operation command (control command) when at least the rear seat doors are unlocked, it is possible to prevent the trunk door 170 from being opened and closed at times that are not desired by the user of the vehicle 10.

[0121] When the base vehicle 100 (body system 126) holds a trunk operation command (control command) indicating an "open / close request" for one second, it begins to operate the trunk door 170 (opening / closing device 175). By setting the continuous receipt of the "open / close request" for one second as a condition for the operation of the trunk door 170, unintentional operation of the trunk door 170 due to noise, etc., can be suppressed. The duration of receiving the "open / close request" as a condition for the operation of the trunk door 170 is not limited to one second, but can be set as appropriate. The duration of receiving the "open / close request" can be set to a period shorter than, equal to, or longer than one second.

[0122] When the base vehicle 100 (body system 126) restarts the tailgate 170 after it has been paused, its control opening and closing device 175 causes the tailgate 170 to perform the opposite action (reverse action) to the action before it was paused. When the tailgate 170 is paused, it is likely that the opposite action will be the next action. By controlling the tailgate 170 to perform the opposite operation after it has been paused, user convenience can be improved.

[0123] [Example]

[0124] Toyota vehicle platform API specifications

[0125] Version 1.1

[0126] Revision history

[0127]

[0128] Table of contents

[0129] 1. Introduction

[0130] 1.1. Purpose of this specification

[0131] 1.2. Target Vehicle

[0132] 1.3. Definition of Terms

[0133] 2. Structure

[0134] 2.1. Overall Structure of Autono-MaaS Vehicles

[0135] 2.2. System Architecture of Autono-MaaS Vehicles

[0136] 3. Application Interface

[0137] 3.1. Typical Use of API

[0138] 3.2. APIs for Vehicle Motion Control

[0139] 3.2.1. List of APIs used for vehicle motion control

[0140] 3.2.2. Details of each API used for vehicle motion control

[0141] 3.3. APIs for Body Control

[0142] 3.3.1. List of APIs used for vehicle body control

[0143] 3.3.2. Details of each API used for body control

[0144] 3.4. API for Power Control

[0145] 3.4.1. List of APIs for Power Control

[0146] 3.4.2. Details of each API used for power control

[0147] 3.5. API for Fault Notification

[0148] 3.5.1. List of APIs used for fault notification

[0149] 3.5.2. Details of each API used for fault notification

[0150] 3.6. APIs for Security

[0151] 3.6.1. List of APIs for Security

[0152] 3.6.2. Details of each API used for security

[0153] 4. API Guidelines for Controlling Toyota Vehicles

[0154] 4.1. APIs for Vehicle Motion Control

[0155] 4.1.1. List of APIs used for vehicle motion control

[0156] 4.1.2. Detailed API Guide for Vehicle Motion Control

[0157] 4.2. APIs for Body Control

[0158] 4.2.1. List of APIs used for vehicle body control

[0159] 4.3. API for Power Control

[0160] 4.3.1. List of APIs for Power Control

[0161] 4.4. API for Fault Notification

[0162] 4.4.1. List of APIs used for fault notification

[0163] 4.5. APIs for Security

[0164] 4.5.1. List of APIs for Security

[0165] 4.5.2. Detailed Guidelines for Secure APIs

[0166] 1. Introduction

[0167] 1.1. Purpose of this specification

[0168] This document is the API specification for the vehicle control interface used in Autono-MaaS vehicles, and includes an overview of the API, usage instructions, and precautions.

[0169] 1.2. Target Vehicle

[0170] This specification applies to Autono-MaaS vehicles as defined by the [Architecture Specification for Toyota Vehicle Platform with Autonomous Driving System].

[0171] 1.3. Definition of Terms

[0172] Table 1. Definitions of Terms

[0173]

[0174] 2. Structure

[0175] 2.1. Overall Structure of Autono-MaaS Vehicles

[0176] This shows the overall structure of an Autono-MaaS vehicle. Figure 7 ).

[0177] 2.2. System Architecture of Autono-MaaS Vehicles

[0178] exist Figure 8 The system architecture is shown in the diagram.

[0179] 3. Application Interface

[0180] 3.1. Typical Use of API

[0181] This section describes typical uses of the API.

[0182] The typical workflow of an API is as follows ( Figure 9 The following example assumes CAN for physical communication.

[0183] 3.2. APIs for Vehicle Motion Control

[0184] This section describes the API used for vehicle motion control.

[0185] 3.2.1. List of APIs used for vehicle motion control

[0186] 3.2.1.1. Input

[0187] Table 3. Input APIs for Vehicle Motion Control

[0188]

[0189] *Response time in VP based on the request from ADK

[0190] 3.2.1.2. Output

[0191] Table 4. Output APIs for Vehicle Motion Control

[0192]

[0193]

[0194]

[0195] 3.2.2. Details of each API used for vehicle motion control

[0196] 3.2.2.1. Direction of Advance Command

[0197] Request to change gear from forward (D) to reverse (R), or from reverse to forward.

[0198] value

[0199] value describe Remark 0 No request 2 R Shift to reverse (R) 4 D Shift to D gear other reserve

[0200] Remark

[0201] • Available only when vehicle mode status = "Autonomous Mode".

[0202] • Available only when the vehicle is stationary (direction of travel = "stationary").

[0203] • Available only when braking is applied.

[0204] 3.2.2.2. Fixed Commands

[0205] Request to open / close wheel lock

[0206] value

[0207] The following table shows the cases where EPB and P files are used for fixing.

[0208]

[0209] Remark

[0210] This API is used to park the vehicle.

[0211] • Available only when vehicle mode status = "Autonomous Mode".

[0212] • It can only be changed when the vehicle is stationary (direction of travel = "stationary").

[0213] • It can only be changed when braking is applied.

[0214] 3.2.2.3. Static Command

[0215] Request to apply / disappear brake holding function

[0216] value

[0217] value describe Remark 0 No request 1 Already applied Allows brake holding function. 2 Released

[0218] Remark

[0219] This API is used to select whether the brake hold function is enabled.

[0220] • Available only when vehicle mode status = "Autonomous Mode".

[0221] • Continue to use the acceleration command (deceleration request) until the stationary state changes to "applied".

[0222] 3.2.2.4. Acceleration Command

[0223] Request acceleration

[0224] value

[0225] Estimated maximum deceleration to estimated maximum acceleration [m / s] 2 ]

[0226] Remark

[0227] • Available only when vehicle mode status = "Autonomous Mode".

[0228] • Acceleration (+) and deceleration (-) requests based on the propulsion direction and state direction.

[0229] • The upper / lower limits will be based on the estimated maximum deceleration and the estimated maximum acceleration change.

[0230] • When the requested acceleration is greater than the estimated maximum acceleration, the request is set to the estimated maximum acceleration.

[0231] • When the requested deceleration is greater than the estimated maximum deceleration, the request is set to the estimated maximum deceleration.

[0232] • When the driver is operating the vehicle (over-control), the requested acceleration may not be achieved.

[0233] • When PCS is working simultaneously, VP should be selected as the minimum acceleration (maximum deceleration).

[0234] 3.2.2.5. Front wheel steering angle command

[0235] value

[0236] value describe Remark — [Unit: radians]

[0237] Remark

[0238] • Available only when vehicle mode status = "Autonomous Mode".

[0239] Left represents a positive value (+). Right represents a negative value (-).

[0240] • When the vehicle is traveling in a straight line, the front wheel steering angle is set to a value (0).

[0241] • This request is set to a value relative to the current one to prevent the accumulation of misalignment in the "front wheel steering angle".

[0242] The requested value should be set within the front wheel steering angle rate limit.

[0243] • When the driver is operating the vehicle (over-control), the requested front wheel steering angle may not be achieved.

[0244] 3.2.2.6. Vehicle Mode Command

[0245] Request a change from manual mode to autonomous mode, or vice versa.

[0246] value

[0247]

[0248] Remark

[0249] N / A

[0250] 3.2.2.7. High Dynamic Commands

[0251] If ADK is to improve VP's braking response performance * The high dynamics command should be set to "high".

[0252] *Response time in VP based on the request from ADK

[0253] value

[0254] value describe Remark 0 No request 1 high 2-3 reserve

[0255] Remark

[0256] N / A

[0257] 3.2.2.8. Propulsion Direction Status

[0258] Current shift status

[0259] value

[0260] value describe Remark 0 reserve 1 P 2 R 3 N 4 D 5 reserve 6 Invalid value

[0261] Remark

[0262] • If VP is unaware of the current shift state, this output is set to "invalid value".

[0263] 3.2.2.9. Fixed State

[0264] Each fixed system state

[0265] value

[0266] The following table shows the cases where EPB and P files are used for fixing.

[0267]

[0268] Remark

[0269] ·N / A

[0270] 3.2.2.10. Stationary state

[0271] static state

[0272] value

[0273] value describe Remark 0 Released 1 Already applied 2 reserve 3 Invalid value

[0274] Remark

[0275] ·N / A

[0276] 3.2.2.11. Estimate the gliding acceleration

[0277] With the throttle valve closed, the acceleration calculated in VP is taken into account factors such as slope and road load.

[0278] value

[0279] [Unit: meters per second] 2 ]

[0280] Remark

[0281] • When the propulsion direction is “D”, the acceleration in the forward direction is shown as a positive value.

[0282] • When the forward direction is “R”, the acceleration in the backward direction is shown as a positive value.

[0283] 3.2.2.12. Estimating the maximum acceleration

[0284] With the throttle valve fully open, the acceleration calculated in VP is taken into account factors such as slope and road load.

[0285] value

[0286] [Unit: meters per second] 2 ]

[0287] Remark

[0288] • When the propulsion direction is “D”, the acceleration in the forward direction is shown as a positive value.

[0289] • When the forward direction is “R”, the acceleration in the backward direction is shown as a positive value.

[0290] 3.2.2.13. Estimate the maximum deceleration

[0291] When braking in VP is requested to be at its maximum, the maximum deceleration calculated in VP is taken into account factors such as gradient and road load.

[0292] value

[0293] [Unit: meters per second] 2 ]

[0294] Remark

[0295] • When the propulsion direction is “D”, the deceleration in the forward direction is shown as a negative value.

[0296] • When the forward direction is “R”, the deceleration in the backward direction is shown as a negative value.

[0297] 3.2.2.14. Front wheel steering angle

[0298] value

[0299] value describe Remark Minimum value Invalid value other [Unit: radians]

[0300] Remark

[0301] Left represents a positive value (+). Right represents a negative value (-).

[0302] The signal will show an invalid value until the VP is able to calculate the correct value or when the sensor is invalid / malfunctioning.

[0303] 3.2.2.15. Front wheel steering angular rate

[0304] Front wheel steering angle rate

[0305] value

[0306] value describe Remark Minimum value Invalid value other [Unit: radians]

[0307] Remark

[0308] Left represents a positive value (+). Right represents a negative value (-).

[0309] The signal will display an invalid value until VP can calculate the correct value or the current wheel steering angle shows a minimum value.

[0310] 3.2.2.16. Front wheel steering rate limit

[0311] Front wheel steering rate limit

[0312] value

[0313] [Unit: radians / second]

[0314] Remark

[0315] From Table 5 below and Figure 10 The speed-steering angle rate mapping shown calculates this limit.

[0316] A) When at low speed or at a stop, use a fixed value (0.751 [radians / second]).

[0317] B) At higher speeds, use 3.432 m / s 3 The steering angle rate is calculated from the vehicle speed.

[0318] Table 5. Vehicle Speed-Steering Angle Rate Mapping Chart

[0319] Speed ​​[km / h] 0.0 36.0 40.0 67.0 84.0 Front wheel steering angle rate limit [radians / second] 0.751 0.751 0.469 0.287 0.253

[0320] 3.2.2.17. Estimate the maximum lateral acceleration

[0321] value

[0322] [Unit: meters per second] 2 (Fixed value: 3.432)

[0323] Remark

[0324] • Maximum lateral acceleration limited by VP

[0325] 3.2.2.18. Estimating the maximum lateral acceleration rate

[0326] value

[0327] [Unit: meters per second] 3 (Fixed value: 3.432)

[0328] Remark

[0329] • Maximum lateral acceleration rate limited by VP

[0330] 3.2.2.19. Accelerator pedal intervention

[0331] This signal indicates whether the accelerator pedal has been pressed by the driver (intervention).

[0332] value

[0333] value describe Remark 0 Unpressed 1 It has been suppressed 2 Exceeding autonomous acceleration

[0334] Remark

[0335] • When the accelerator pedal is positioned above a predetermined threshold, the signal is set to "pressed".

[0336] • When the requested acceleration calculated from the position of the accelerator pedal is higher than the requested acceleration from the ADS, the signal is set to “exceed autonomous acceleration”.

[0337] 3.2.2.20. Brake pedal intervention

[0338] This signal indicates whether the driver has pressed the brake pedal (intervention).

[0339] value

[0340] value describe Remark 0 Unpressed 1 It has been suppressed 2 Exceeding autonomous deceleration

[0341] Remark

[0342] • When the brake pedal position is above a predetermined threshold, the signal is set to "pressed".

[0343] • When the requested deceleration calculated from the position of the brake pedal is higher than the requested deceleration from the ADS, the signal is set to “exceed autonomous deceleration”.

[0344] 3.2.2.21. Steering wheel intervention

[0345] This signal indicates whether the driver has intervened by operating the steering wheel.

[0346] value

[0347] value describe Remark 0 Not rotated 1 ADS works in collaboration with drivers 2 Only by human driver

[0348] Remark

[0349] • In “Steering wheel intervention = 1”, the EPS system works in cooperation with the human driver to drive the steering, taking into account the intentions of the human driver.

[0350] • In "Steering intervention = 2", the steering request from ADS was not implemented, taking into account the intentions of the human driver. (Steering will be driven by the human driver.)

[0351] 3.2.2.22. Gear shift lever intervention

[0352] This signal indicates whether the driver is controlling the gear shift lever (intervention).

[0353] value

[0354] value describe Remark 0 closure 1 Open Controlled (moved to any gear)

[0355] Remark

[0356] ·N / A

[0357] 3.2.2.23. Wheel speed pulse (front left), wheel speed pulse (front right), wheel speed pulse (rear left), wheel speed pulse (rear right)

[0358] value

[0359]

[0360] Remark

[0361] • Integrate the pulse value at the moment of pulse descent.

[0362] The wheel speed sensor outputs 96 pulses per rotation.

[0363] • The wheel speed pulse will be updated regardless of whether the wheel speed sensor is invalid or malfunctioning.

[0364] • When “1” is subtracted from the pulse value showing “0”, the value changes to “0×FF”. When “1” is added to the pulse value showing “0×FF”, the value changes to “0”.

[0365] • The rotation direction is determined after the ECU is started, and the pulse value will be increased when the rotation direction is "forward".

[0366] • When forward rotation is detected, the pulse value will be increased.

[0367] • When backward rotation is detected, the pulse value will be subtracted.

[0368] 3.2.2.24. Wheel rotation direction (front left), wheel rotation direction (front right), wheel rotation direction (rear left), wheel rotation direction (rear right)

[0369] value

[0370] value describe Remark 0 forward 1 backward 2 reserve 3 Invalid value The sensor is malfunctioning.

[0371] Remark

[0372] • Determine the rotation direction after VP is turned on and set it to "forward".

[0373] 3.2.2.25. Direction of travel

[0374] Direction of movement of the vehicle

[0375] value

[0376] value describe Remark 0 forward 1 backward 2 still 3 Undefined

[0377] Remark

[0378] • When the speed of all four wheels is “0” at a constant time, the signal indicates “stationary”.

[0379] • When shifting gears immediately after the vehicle has started, it can be "undefined".

[0380] 3.2.2.26. Vehicle speed

[0381] Estimated longitudinal speed of the vehicle

[0382] value

[0383] value describe Remark Maximum value in transmitted bits Invalid value The sensor is malfunctioning. other Speed ​​[unit: meters per second]

[0384] Remark

[0385] • The signal value is positive when both the forward and backward directions are in motion.

[0386] 3.2.2.27. Longitudinal acceleration

[0387] Estimated longitudinal acceleration of the vehicle

[0388] value

[0389] value describe Remark Minimum value in transmitted bits Invalid value The sensor is malfunctioning. other <![CDATA[Acceleration [Unit: m / s 2 >

[0390] Remark

[0391] • Acceleration (+) and deceleration (-) values ​​based on the pulse direction and state direction.

[0392] 3.2.2.28. Lateral acceleration

[0393] lateral acceleration of the vehicle

[0394] value

[0395] value describe Remark Minimum value in transmitted bits Invalid value The sensor is malfunctioning. other <![CDATA[Acceleration [Unit: m / s 2 >

[0396] Remark

[0397] Positive values ​​indicate counter-clockwise rotation. Negative values ​​indicate clockwise rotation.

[0398] 3.2.2.29. Yaw rate

[0399] yaw rate sensor value

[0400] value

[0401] value describe Remark Minimum value in transmitted bits Invalid value The sensor is malfunctioning. other Yaw rate [unit: degrees / second]

[0402] Remark

[0403] Positive values ​​indicate counter-clockwise rotation. Negative values ​​indicate clockwise rotation.

[0404] 3.2.2.30. Sliding Detection

[0405] Tire slippage / sharp turn / skid detection

[0406] value

[0407] value describe Remark 0 No sliding 1 slide 2 reserve 3 Invalid value

[0408] Remark

[0409] • This signal is considered "slippery" when any of the following systems are already running.

[0410] -ABS (Anti-lock Braking System)

[0411] -TRC (Traction Control)

[0412] -VSC (Vehicle Stability Control)

[0413] -VDIM (Vehicle Dynamics Integrated Management)

[0414] 3.2.2.31. Vehicle Mode Status

[0415] Autonomous mode or manual mode

[0416] value

[0417] value describe Remark 0 Manual mode The mode starts from manual mode. 1 Autonomous mode

[0418] Remark

[0419] • The initial state is set to "manual mode".

[0420] 3.2.2.32. Automation Ready

[0421] This signal indicates whether the vehicle can switch to autonomous mode.

[0422] value

[0423]

[0424]

[0425] Remark

[0426] ·N / A

[0427] 3.2.2.33. Fault Status of VP Function in Autonomous Mode

[0428] This signal is used to indicate whether the VP function has certain fault modes when the vehicle is operating in autonomous mode.

[0429] value

[0430] value describe Remark 0 No fault 1 Fault 3 invalid The status has not yet been determined.

[0431] Remark

[0432] ·N / A

[0433] 3.2.2.34. PCS Alarm Status

[0434] value

[0435] value describe Remark 0 normal 1 alarm Request an alert from the PCS system. 3 Unavailable

[0436] Remark

[0437] N / A

[0438] 3.2.2.35. PCS Preparation Status

[0439] Pre-filling state as preparation for PCS braking

[0440] value

[0441] value describe Remark 0 normal 1 start up 3 Unavailable

[0442] Remark

[0443] • “Start” is a state that prepares the braking actuator for the PCS to shorten the delay from when the PCS issues a deceleration request.

[0444] • When the value changes to “Start” during the vehicle mode state = “Autonomous Mode”, “ADS / PCS Disruption Status” displays “ADS”.

[0445] 3.2.2.36. PCS Braking / PCS Braking Holding Status

[0446] value

[0447] value describe Remark 0 normal 1 PCS braking 2 PCS Braking Hold 7 Unavailable

[0448] Remark

[0449] N / A

[0450] 3.2.2.37. ADS / PCS Mediation Status

[0451] Mediation status

[0452] value

[0453] value describe Remark 0 No request 1 ADS ADS 2 PCS PCS braking or PCS braking hold 3 Invalid value

[0454] Remark

[0455] • When the acceleration requested by the PCS system in VP is less than the acceleration requested by ADS, the state is set to "PCS".

[0456] • When the acceleration requested by the PCS system in VP is greater than the acceleration requested by ADS, the state is set to "ADS".

[0457] 3.3 APIs for Body Control

[0458] 3.3.1. List of APIs used for vehicle body control

[0459] 3.3.1.1. Input

[0460] Table 6. Input APIs for Body Control

[0461]

[0462]

[0463] 3.3.1.2. Output

[0464] Table 7. Output APIs for Body Control

[0465]

[0466]

[0467]

[0468] 3.3.2. Details of each API used for body control

[0469] 3.3.2.1. Turning signal command

[0470] Request to control steering signal

[0471] value

[0472] value describe Remark 0 closure 1 right Right flash on 2 Left Left flash on 3 reserve

[0473] Remark

[0474] ·N / A

[0475] 3.3.2.2.Headlight command

[0476] Request to control headlights

[0477] value

[0478] value describe Remark 0 No request Keep the current mode 1 Taillight mode request Side light mode 2 Headlamp mode request Low beam mode 3 Autonomous mode request Autonomous mode 4 High beam mode request High beam mode 5 Close Mode Request 6-7 reserve

[0479] Remark

[0480] • This command is invalid when the headlight mode of the combination switch is "off" or the autonomous mode is "on".

[0481] • Driver's actions take precedence over this command.

[0482] 3.3.2.3. Hazard Warning Light Command

[0483] Request to control hazard warning lights

[0484] value

[0485] value describe Remark 0 No request 1 Open

[0486] Remark

[0487] • Driver's actions take precedence over this command.

[0488] • The hazard warning lights will turn on upon receiving the "on" command.

[0489] 3.3.2.4. Horn Mode Command

[0490] Requests for selecting the on and off times per cycle

[0491] value

[0492] value describe Remark 0 No request 1 Mode 1 Open time: 250 milliseconds; Close time: 750 milliseconds 2 Mode 2 Open time: 500 milliseconds; Close time: 500 milliseconds 3 Mode 3 reserve 4 Mode 4 reserve 5 Mode 5 reserve 6 Mode 6 reserve 7 Mode 7 reserve

[0493] Remark

[0494] N / A

[0495] 3.3.2.5. Horn Cycle Command

[0496] Request to select the number of cycles to turn on and off

[0497] value

[0498] 0-7[-]

[0499] Remark

[0500] N / A

[0501] 3.3.2.6. Continuous Horn Command

[0502] Request to turn the speaker on / off

[0503] value

[0504] value describe Remark 0 No request 1 Open

[0505] Remark

[0506] • This command has higher priority than the 3.3.2.4 Horn Mode and 3.3.2.5 Horn Cycle commands.

[0507] • The speaker will "turn on" simultaneously upon receiving the "turn on" command.

[0508] 3.3.2.7. Windshield wiper command

[0509] Request to control the windshield wipers

[0510] value

[0511]

[0512]

[0513] Remark

[0514] This command is effective when the windshield wiper mode of the combination switch is set to "Off" or "Auto".

[0515] • Driver input takes precedence over this command.

[0516] • Maintain windshield wiper mode while receiving the command.

[0517] • Erasing speed in fixed intermittent mode.

[0518] 3.3.2.8. Rear windshield wiper command

[0519] Request to control rear windshield wipers

[0520] value

[0521] value describe Remark 0 Close Mode Request 1 Low frequency mode request 2 reserve 3 Intermittent mode request 4-7 reserve

[0522] Remark

[0523] • Driver input takes precedence over this command.

[0524] • Maintain windshield wiper mode while receiving the command.

[0525] • Erasing speed in fixed intermittent mode.

[0526] 3.3.2.9. HVAC (First Line) Operation Commands

[0527] Start / stop the first line of air conditioning control request

[0528] value

[0529] value describe Remark 0 No request 1 Open 2 closure

[0530] Remark

[0531] ·N / A

[0532] 3.3.2.10. HVAC (Second Line) Operation Commands

[0533] Start / stop the second line of air conditioning control request

[0534] value

[0535] value describe Remark 0 No request 1 Open 2 closure

[0536] Remark

[0537] ·N / A

[0538] 3.3.2.11. Target Temperature (first command on the left)

[0539] Request to set the target temperature in the left front region

[0540] value

[0541] value describe Remark 0 No request 60 to 85 [unit: degrees Fahrenheit] (in increments of 1.0 degrees Fahrenheit) Target temperature

[0542] Remark

[0543] • When Celsius is used in VP, the value should be set to Celsius.

[0544] 3.3.2.12. Target Temperature (first command on the right)

[0545] Request to set the target temperature in the right front region

[0546] value

[0547] value describe Remark 0 No request 60 to 85 [unit: degrees Fahrenheit] (in increments of 1.0 degrees Fahrenheit) Target temperature

[0548] Remark

[0549] • When Celsius is used in VP, the value should be set to Celsius.

[0550] 3.3.2.13. Target Temperature (second from the left) command

[0551] Request to set the target temperature in the left rear region

[0552] value

[0553] value describe Remark 0 No request 60 to 85 [unit: degrees Fahrenheit] (in increments of 1.0 degrees Fahrenheit) Target temperature

[0554] Remark

[0555] • When Celsius is used in VP, the value should be set to Celsius.

[0556] 3.3.2.14. Target Temperature (second from the right) command

[0557] Request to set the target temperature in the right rear region.

[0558] value

[0559] value describe Remark 0 No request 60 to 85 [unit: degrees Fahrenheit] (in increments of 1.0 degrees Fahrenheit) Target temperature

[0560] Remark

[0561] • When Celsius is used in VP, the value should be set to Celsius.

[0562] 3.3.2.15. HVAC Fan (First Line) Command

[0563] Request to set the fan level of the front AC

[0564] value

[0565] value describe Remark 0 No request 1 to 7 (maximum) Fan level

[0566] Remark

[0567] • To switch the fan level to 0 (off), you should transmit "HVAC (first line) operation command = off".

[0568] • To switch the fan level to automatic, you should send the command "HVAC (first line) operation = turn on".

[0569] 3.3.2.16. HVAC Fan (Second Line) Command

[0570] Request for AC fan level after configuration

[0571] value

[0572] value describe Remark 0 No request 1 to 7 (maximum) Fan level

[0573] Remark

[0574] • To switch the fan level to 0 (off), you should transmit "HVAC (second line) operation command = off".

[0575] • To switch the fan level to automatic, you should send the command "HVAC (second line) operation = turn on".

[0576] 3.3.2.17. Air Exit (First Line) Command

[0577] Request to set the first line of air outlet mode

[0578] value

[0579] value describe Remark 0 No operation 1 upper body Airflow to the upper body 2 upper body / feet Airflow to the upper body and feet 3 feet Airflow to the feet 4 Foot / Defogger Airflow to the feet and windshield defroster

[0580] Remark

[0581] ·N / A

[0582] 3.3.2.18. Air Exit (Second Line) Command

[0583] Request to set the air outlet mode in the second row

[0584] value

[0585] value describe Remark 0 No operation 1 upper body Airflow to the upper body 2 upper body / feet Airflow to the upper body and feet 3 feet Air flows towards the feet.

[0586] Remark

[0587] ·N / A

[0588] 3.3.2.19. Air Circulation Command

[0589] Request to set air circulation mode

[0590] value

[0591] value describe Remark 0 No request 1 Open 2 closure

[0592] Remark

[0593] ·N / A

[0594] 3.3.2.20. AC Mode Commands

[0595] Request to configure AC mode

[0596] value

[0597] value describe Remark 0 No request 1 Open 2 closure

[0598] Remark

[0599] ·N / A

[0600] 3.3.2.21. Turning signal status

[0601] value

[0602] value describe Remark 0 closure 1 Left 2 right 3 invalid

[0603] Remark

[0604] N / A

[0605] 3.3.2.22. Headlight Status

[0606] value

[0607] value describe Remark 0 closure 1 taillight 2 Low beam 3 reserve 4 High beams 5-6 reserve 7 invalid

[0608] Remark

[0609] N / A

[0610] 3.3.2.23. Hazard warning light status

[0611] value

[0612] value describe Remark 0 closure 1 Danger warning 2 reserve 3 invalid

[0613] Remark

[0614] N / A

[0615] 3.3.2.24. Horn Status

[0616] value

[0617] value describe Remark 0 closure 1 Open 2 reserve 3 invalid

[0618] Remark

[0619] When the 3.3.2.4 horn mode command is activated, the horn status is "1" even during periods when the mode is off in some modes.

[0620] 3.3.2.25. Windshield wiper status

[0621] value

[0622] value describe Remark 0 closure 1 low frequency 2 High frequency 3 Intermittent 4-5 reserve 6 Fault 7 invalid

[0623] Remark

[0624] N / A

[0625] 3.3.2.26. Rear windshield wiper status

[0626] value

[0627]

[0628]

[0629] Remark

[0630] N / A

[0631] 3.3.2.27. HVAC (first line) status

[0632] value

[0633] value describe Remark 0 closure 1 Open

[0634] Remark

[0635] ·N / A

[0636] 3.3.2.28. HVAC (Second line) Status

[0637] value

[0638] value describe Remark 0 closure 1 Open

[0639] Remark

[0640] ·N / A

[0641] 3.3.2.29. Target Temperature (first one on the left) Status

[0642] value

[0643] value describe Remark 0 low temperature coldest 60 to 85 [unit: degrees Fahrenheit] Target temperature 100 high temperature hottest FFh unknown

[0644] Remark

[0645] • When Celsius is used in VP, the value should be set to Celsius.

[0646] 3.3.2.30. Target Temperature (first one on the right) Status

[0647] value

[0648] value describe Remark 0 low temperature coldest 60 to 85 [unit: degrees Fahrenheit] Target temperature 100 high temperature hottest FFh unknown

[0649] Remark

[0650] • When Celsius is used in VP, the value should be set to Celsius.

[0651] 3.3.2.31. Target Temperature (Second from the left) Status

[0652] value

[0653] value describe Remark 0 low temperature coldest 60 to 85 [unit: degrees Fahrenheit] Target temperature 100 high temperature hottest FFh unknown

[0654] Remark

[0655] • When Celsius is used in VP, the value should be set to Celsius.

[0656] 3.3.2.32. Target Temperature (Second from the Right) Status

[0657] value

[0658] value describe Remark 0 low temperature coldest 60 to 85 [unit: degrees Fahrenheit] Target temperature 100 high temperature hottest FFh unknown

[0659] Remark

[0660] • When Celsius is used in VP, the value should be set to Celsius.

[0661] 3.3.2.33. HVAC Fan (First Line) Status

[0662] value

[0663] value describe Remark 0 closure 1 to 7 Fan level 8 Undefined

[0664] Remark

[0665] ·N / A

[0666] 3.3.2.34. HVAC Fan (Second Row) Status

[0667] value

[0668]

[0669]

[0670] Remark

[0671] ·N / A

[0672] 3.3.2.35. Air outlet (first line) status

[0673] value

[0674] value describe Remark 0 Close all 1 upper body Airflow to the upper body 2 upper body / feet Airflow to the upper body and feet 3 feet Air flows towards the feet. 4 Foot / Defogger Airflow towards the feet and windshield defroster operation 5 Demister Windshield defroster 7 Undefined

[0675] Remark

[0676] ·N / A

[0677] 3.3.2.36. Air outlet (second line) status

[0678] value

[0679] value describe Remark 0 Close all 1 upper body Airflow to the upper body 2 upper body / feet Airflow to the upper body and feet 3 feet Air flows towards the feet. 7 Undefined

[0680] Remark

[0681] ·N / A

[0682] 3.3.2.37. Air circulation status

[0683] value

[0684] value describe Remark 0 closure 1 Open

[0685] Remark

[0686] ·N / A

[0687] 3.3.2.38. AC Mode Status

[0688] value

[0689] value describe Remark 0 closure 1 Open

[0690] Remark

[0691] ·N / A

[0692] 3.3.2.39. Seat Occupancy (First Seat on the Right) Status

[0693] value

[0694] value describe Remark 0 Unoccupied 1 Already occupied 2 Undecided In the event that the ignition device is off or communication with the seat sensors is interrupted. 3 Fault

[0695] Remark

[0696] • When there is luggage on the seat, the signal can be set to "occupied".

[0697] 3.3.2.40. Seatbelt (first one on the left) status

[0698] value

[0699] value describe Remark 0 Fastened 1 Untie 2 Undecided If the sensor does not work after the ignition device is turned on. 3 Switch malfunction

[0700] Remark

[0701] N / A

[0702] 3.3.2.41. Seatbelt (first one on the right) status

[0703] value

[0704] value describe Remark 0 Fastened 1 Untie 2 Undecided If the sensor does not work after the ignition device is turned on. 3 Switch malfunction

[0705] Remark

[0706] N / A

[0707] 3.3.2.42. Seatbelt (second one from the left) status

[0708] value

[0709] value describe Remark 0 Fastened 1 Untie 2 Undecided If the sensor does not work after the ignition device is turned on. 3 reserve

[0710] Remark

[0711] • Cannot detect sensor malfunction

[0712] 3.3.2.43. Seatbelt (second one from the right) status

[0713] value

[0714] value describe Remark 0 Fastened 1 Untie 2 Undecided If the sensor does not work after the ignition device is turned on. 3 reserve

[0715] Remark

[0716] • Cannot detect sensor malfunction

[0717] 3.3.2.44. Seatbelt (third one from the left) status

[0718] value

[0719] value describe Remark 0 Fastened 1 Untie 2 Undecided If the sensor does not work after the ignition device is turned on. 3 reserve

[0720] Remark

[0721] • Cannot detect sensor malfunction

[0722] 3.3.2.45. Seatbelt (third center seatbelt) status

[0723] value

[0724] value describe Remark 0 Fastened 1 Untie 2 Undecided If the sensor does not work after the ignition device is turned on. 3 reserve

[0725] Remark

[0726] • Cannot detect sensor malfunction

[0727] 3.3.2.46. Seatbelt (third one from the right) status

[0728] value

[0729] value describe Remark 0 Fastened 1 Untie 2 Undecided If the sensor does not work after the ignition device is turned on. 3 reserve

[0730] Remark

[0731] • Cannot detect sensor malfunction

[0732] 3.4. API for Power Control

[0733] 3.4.1. List of APIs for Power Control

[0734] 3.4.1.1. Input

[0735] Table 8. Input APIs for Power Control

[0736]

[0737]

[0738] 3.4.1.2. Output

[0739] Table 9. Output APIs for Power Control

[0740] Signal name describe redundancy Power mode status The current power mode status of VP N / A

[0741] 3.4.2. Details of each API used for power control

[0742] 3.4.2.1. Power Mode Command

[0743] Request to control power mode

[0744] value

[0745] value describe Remark 0 No request 1 sleep Turn off the vehicle 2 wake Open VCIB 3 reserve Reserved for data expansion 4 reserve Reserved for data expansion 5 reserve Reserved for data expansion 6 drive Start the vehicle

[0746] Remark

[0747] ·exist Figure 11 The state machine diagram for the power mode is shown below.

[0748] [Sleep]

[0749] Vehicle power off. In this mode, the main battery does not supply power to any system, and the VCIB and other VP ECUs do not start.

[0750] [wake]

[0751] The VCIB is activated by the auxiliary battery. In this mode, ECUs other than the VCIB are not activated, except for some vehicle electronic ECUs.

[0752] [Driving Mode]

[0753] Vehicle powered on. In this mode, the main battery supplies power to the entire VP, and all VP ECUs, including the VCIB, are activated.

[0754] 3.4.2.2. Power Mode Status

[0755] value

[0756] value describe Remark 0 reserve 1 sleep 2 wake 3 reserve 4 reserve 5 reserve 6 drive 7 unknown This means that an unhealthy condition may occur.

[0757] Remark

[0758] After executing the sleep sequence, VCIB will continuously transmit [sleep] as the power mode state for 3000 [milliseconds]. Then, VCIB will shut down.

[0759] • While the VCIB is transmitting [sleep], the ADS will stop transmitting signals to the VCIB.

[0760] 3.5. API for Fault Notification

[0761] 3.5.1. List of APIs used for fault notification

[0762] 3.5.1.1. Input

[0763] Table 10. Input APIs for Fault Notification

[0764]

[0765]

[0766] 3.5.1.2. Output

[0767] Table 11. Output APIs for Fault Notification

[0768] Signal name describe redundancy Request for ADS operation Already applied Impact detection signal N / A Performance degradation of the braking system Already applied Performance degradation of propulsion system N / A Performance degradation of the shift control system N / A Performance degradation of fixed systems Already applied Deterioration of steering system performance Already applied Power system performance degradation Already applied Performance degradation of communication systems Already applied

[0769] 3.5.2. Details of each API used for fault notification

[0770] 3.5.2.1. Requests for ADS Operations

[0771] value

[0772] value describe Remark 0 No request 1 Maintenance required 2 Need to return to the garage 3 Need to stop immediately other reserve

[0773] Remark

[0774] This signal indicates the expected behavior of ADS in response to a fault occurring in VP.

[0775] 3.5.2.2. Impact detection signal

[0776] value

[0777] value describe Remark 0 normal 5 Collision detection with airbags deployed 6 Collision detection with high-voltage circuit off 7 Invalid value other reserve

[0778] Remark

[0779] • When a collision detection event is generated, 50 signals are transmitted consecutively every 100 milliseconds. If the collision detection state changes before the signal transmission is complete, a higher priority signal is transmitted.

[0780] Priority: Collision detection > Normal

[0781] Regardless of the normal response during a collision, a 5-second transmission is required because a disconnect voltage request should be sent to the vehicle damage assessment system within 5 seconds after a collision in an HV vehicle.

[0782] The transmission interval is 100 milliseconds within the allowed delay time (1 second) for fuel cut-off action, enabling data to be transmitted more than 5 times.

[0783] In this situation, a momentary power outage should be considered.

[0784] 3.5.2.3. Performance deterioration of the braking system

[0785] value

[0786] value describe Remark 0 normal — 1 Degradation detected —

[0787] Remark

[0788] ·N / A

[0789] 3.5.2.4. Performance degradation of the propulsion system

[0790] value

[0791] value describe Remark 0 normal — 1 Degradation detected —

[0792] Remark

[0793] ·N / A

[0794] 3.5.2.5. Performance degradation of the shift control system

[0795] value

[0796] value describe Remark 0 normal — 1 Degradation detected —

[0797] Remark

[0798] ·N / A

[0799] 3.5.2.6. Performance degradation of fixed systems

[0800] value

[0801] value describe Remark 0 normal — 1 Degradation detected —

[0802] Remark

[0803] ·N / A

[0804] 3.5.2.7. Performance degradation of the steering system

[0805] value

[0806]

[0807]

[0808] Remark

[0809] ·N / A

[0810] 3.5.2.8. Performance degradation of the power supply system

[0811] value

[0812] value describe Remark 0 normal — 1 Degradation detected —

[0813] Remark

[0814] ·N / A

[0815] 3.5.2.9. Performance degradation of communication systems

[0816] value

[0817] value describe Remark 0 normal — 1 Degradation detected —

[0818] Remark

[0819] ·N / A

[0820] 3.6. APIs for Security

[0821] 3.6.1. List of APIs for Security

[0822] 3.6.1.1. Input

[0823] Table 12. Input APIs for Security

[0824]

[0825] 3.6.1.2. Output

[0826] Table 13. Output APIs for Security

[0827]

[0828]

[0829] 3.6.2. Details of each API used for security

[0830] 3.6.2.1. Door lock (front) command, door lock (rear) command

[0831] value

[0832] value describe Remark 0 No request 1 locking Not supported in Toyota VP 2 Unlock 3 reserve

[0833] Remark

[0834] • If ADK requests to unlock the front, then both front doors will be unlocked.

[0835] • If ADK requests to unlock the rear, then unlock the second row of doors and the trunk door.

[0836] • If ADK requests to lock any door, the “Central Door Lock Command” should be used.

[0837] (The functionality for individual locks is not supported in Toyota VP.)

[0838] 3.6.2.2. Central door lock command

[0839] Request to control all door locks

[0840] value

[0841] value describe Remark 0 No request 1 Lock (All) 2 Unlock (all) 3 reserve

[0842] Remark

[0843] ·N / A

[0844] 3.6.2.3. Device authentication signature first word, device authentication signature second word, device authentication signature third word, device authentication signature fourth word, device authentication seed first word, device authentication seed second word

[0845] The first word of the device authentication signature exists in the first to eighth bytes of the signature.

[0846] The second word of the device authentication signature is present in bytes nine through sixteen of the signature.

[0847] The third word of the device authentication signature is located in bytes seventeen through twenty-four of the signature.

[0848] The fourth word of the device authentication signature is located in bytes 25 through 32 of the signature.

[0849] The first word of the device authentication seed exists in the first to eighth bytes of the seed.

[0850] The second word of the device authentication seed exists in bytes nine through sixteen of the seed.

[0851] 3.6.2.4. Door lock (first one on the left) status

[0852] value

[0853]

[0854]

[0855] Remark

[0856] ·N / A

[0857] 3.6.2.5. Door lock (first one on the right) status

[0858] value

[0859] value describe Remark 0 reserve 1 locking 2 Unlock 3 invalid

[0860] Remark

[0861] ·N / A

[0862] 3.6.2.6. Door lock (second from the left) status

[0863] value

[0864] value describe Remark 0 reserve 1 locking 2 Unlock 3 invalid

[0865] Remark

[0866] ·N / A

[0867] 3.6.2.7. Door lock (second from the right) status

[0868] value

[0869] value describe Remark 0 reserve 1 locking 2 Unlock 3 invalid

[0870] Remark

[0871] ·N / A

[0872] 3.6.2.8. Door lock status of all departments

[0873] value

[0874] value describe Remark 0 reserve 1 Lock all 2 Unlock any door 3 invalid

[0875] Remark

[0876] • "Any door unlocked" if any door is unlocked.

[0877] • When all departments are locked down, “all departments are locked down”.

[0878] 3.6.2.9. Alarm System Status

[0879] value

[0880]

[0881]

[0882] Remark

[0883] ·N / A

[0884] 3.6.2.9.1. Short-range odometer

[0885] The counter is incremented in short increments by the freshness value management main ECU.

[0886] value

[0887] 0-FFFFh

[0888] Remark

[0889] This value is used to create the freshness value.

[0890] For more details, please refer to other materials [Toyota's MAC module specifications].

[0891] 3.6.2.9.2. Reset the counter

[0892] This counter is periodically incremented by the main ECU, which manages the freshness value.

[0893] value

[0894] 0-FFFFFh

[0895] Remark

[0896] This value is used to create the freshness value.

[0897] For more details, please refer to other materials [Toyota's MAC module specifications].

[0898] 3.6.2.10. The first door on the left is open.

[0899] The current open / closed status of the first door on the left side of the vehicle platform.

[0900] value

[0901]

[0902]

[0903] Remark

[0904] N / A

[0905] 3.6.2.11. The first door on the right is open.

[0906] The current open / closed status of the first door on the right.

[0907] value

[0908] value describe Remark 0 reserve 1 Open 2 closure 3 invalid

[0909] Remark

[0910] N / A

[0911] 3.6.2.12. The second door on the left is open.

[0912] The current status of the second door on the left (open / closed).

[0913] value

[0914] value describe Remark 0 reserve 1 Open 2 closure 3 invalid

[0915] Remark

[0916] N / A

[0917] 3.6.2.13. The second door on the right is open.

[0918] The current open / closed status of the second door on the right.

[0919] value

[0920] value describe Remark 0 reserve 1 Open 2 closure 3 invalid

[0921] Remark

[0922] N / A

[0923] 3.6.2.14. Trunk Status

[0924] Current trunk door open / closed status

[0925] value

[0926] value describe Remark 0 reserve 1 Open 2 closure 3 invalid

[0927] Remark

[0928] N / A

[0929] 3.6.2.15. Engine hood open

[0930] Current engine hood open / closed status

[0931] value

[0932] value describe Remark 0 reserve 1 Open 2 closure 3 invalid

[0933] Remark

[0934] N / A

[0935] 4. API Guidelines for Controlling Toyota Vehicles

[0936] This section details how to use the API for Toyota vehicles.

[0937] 4.1. API for Vehicle Motion Control

[0938] 4.1.1. List of APIs used for vehicle motion control

[0939] The input and output APIs for vehicle motion control are shown in Tables 14 and 15, respectively. Usage guidelines for some APIs appear in the following sections as indicated in each table.

[0940] 4.1.1.1. Input

[0941] Table 14. Input APIs for Vehicle Motion Control

[0942]

[0943]

[0944] *Response time in VP based on the request from ADK

[0945] 4.1.1.2. Output

[0946] Table 15. Input APIs for Vehicle Motion Control

[0947]

[0948]

[0949]

[0950] 4.1.2. API Details for Vehicle Motion Control

[0951] 4.1.2.1. Pulse Direction Command

[0952] For values ​​and notes, please refer to section 3.2.2.1.

[0953] Figure 12 The detailed shift sequence is shown.

[0954] The acceleration command requests initial deceleration and a vehicle stop. When the driving direction is set to "Stand," any gear can be requested via the propulsion direction command. Figure 13 In Chinese, “D” → “R”.

[0955] The acceleration command needs to be used to request deceleration until the gear shift is complete.

[0956] After changing gears, you can select to accelerate or decelerate based on the acceleration command.

[0957] When the vehicle is in autonomous mode, it does not accept driver gear shifting.

[0958] 4.1.2.2. Fixed Commands

[0959] For values ​​and notes, please refer to 3.2.2.2.

[0960] Figure 14 This shows how to enable / disable pinned features.

[0961] An acceleration command is used to request deceleration to bring the vehicle to a stop. When the vehicle speed reaches zero, the stationary function is activated by the stationary command = "Applied". The acceleration command is set to decelerate until the stationary state is set to "Applied".

[0962] When deactivating the fixed function, it is necessary to request the fixed command = "deactivated" and at the same time set the acceleration command to decelerate until the fixed status is confirmed = "deactivated".

[0963] After the fixed function is disabled, the vehicle can be accelerated / decelerated based on the acceleration command.

[0964] 4.1.2.3. Static Command

[0965] For values ​​and notes, please refer to 3.2.2.3.

[0966] When the stationary command is set to "applied", the brake holding function can be prepared for use, and the brake holding function is activated while the vehicle is stationary, with the acceleration command set to deceleration (<0). The stationary state then changes back to "applied". Conversely, when the stationary command is set to "deactivated", the brake holding function is deactivated.

[0967] Figure 14 The static sequence is shown.

[0968] To bring the vehicle to a stop, an acceleration command is used to request deceleration.

[0969] When the vehicle comes to a temporary stop, the driving direction changes to "stationary". Even during the "stationary state = applied" period, deceleration will be requested via an acceleration command.

[0970] If you want the vehicle to move forward, the acceleration command is set to accelerate (>0). Then the brake holding function is released and the vehicle is accelerated.

[0971] 4.1.2.4. Speed-up command

[0972] For values ​​and notes, please refer to 3.2.2.4.

[0973] The following shows what the vehicle does when the accelerator pedal is pressed.

[0974] When the accelerator pedal is engaged, select either 1) the maximum acceleration value calculated based on the accelerator pedal travel, or 2) the maximum acceleration value input from the ADK acceleration command. The ADK can determine which value to select by checking the engagement of the accelerator pedal.

[0975] The following shows what the vehicle does when the brake pedal is operated.

[0976] The vehicle's deceleration value is the sum of 1) the value calculated based on the brake pedal travel and 2) the value requested by ADK.

[0977] 4.1.2.5. Front wheel steering angle command

[0978] For values ​​and notes, please refer to 3.2.2.5.

[0979] The following shows how to use the front wheel steering angle command.

[0980] The front wheel steering angle command is set to a value relative to the front wheel steering angle.

[0981] For example, when the front wheel steering angle is 0.1 radians and the vehicle is traveling straight;

[0982] If ADK wants to go straight, the front wheel steering angle command will be set to 0 + 0.1 = 0.1 [radians].

[0983] If ADK requests a steering angle of -0.3 radians, the front wheel steering angle command will be set to -0.3 + 0.1 = -0.2 radians.

[0984] The following illustrates how the vehicle behaves when the driver operates the steering mechanism.

[0985] Choose the maximum value from 1) the value calculated based on the driver's steering wheel operation, or 2) the value requested by ADK.

[0986] Note that if the driver applies strong pressure to the steering wheel, the driver will not accept the front wheel steering angle command. This situation can be detected by intervening through the steering wheel indicator.

[0987] 4.1.2.6. Vehicle Mode Command

[0988] exist Figure 15 The diagram shows the state machine for mode transitions in Autono-MaaS vehicles.

[0989] The description of each state is shown below.

[0990]

[0991] The descriptions for each conversion are shown below.

[0992]

[0993]

[0994] 4.2. APIs for Body Control

[0995] 4.2.1. List of APIs used for vehicle body control

[0996] 4.2.1.1. Input

[0997] Table 16. Input APIs for Body Control

[0998]

[0999]

[1000] 4.2.1.2. Output

[1001] Table 17. Output APIs for Body Control

[1002]

[1003]

[1004]

[1005] 4.3. API for Power Control

[1006] 4.3.1. List of APIs for Power Control

[1007] 4.3.1.1. Input

[1008] Table 18. Input APIs for Power Control

[1009] Signal name describe redundancy User Guide Power mode command Commands to control the power mode of VP N / A —

[1010] 4.3.1.2. Output

[1011] Table 19. Output APIs for Power Control

[1012] Signal name describe redundancy User Guide Power mode status The current power mode status of VP N / A —

[1013] 4.4. API for Fault Notification

[1014] 4.4.1. List of APIs used for fault notification

[1015] 4.4.1.1. Input

[1016] Table 20. Input APIs for Fault Notification

[1017] Signal name describe redundancy User Guide N / A — — —

[1018] 4.4.1.2. Output

[1019] Table 21. Output APIs for Fault Notification

[1020] Signal name describe redundancy User Guide Request for ADS operation — Already applied — Impact detection signal — N / A — Performance degradation of the braking system — Already applied — Performance degradation of propulsion system — N / A — Performance degradation of the shift control system — N / A — Performance degradation of fixed systems — Already applied — Deterioration of steering system performance Already applied — Power system performance degradation Already applied — Performance degradation of communication systems Already applied —

[1021] 4.5. APIs for Security

[1022] 4.5.1. List of APIs for Security

[1023] The input and output APIs for security are shown in Tables 22 and 23, respectively. Usage guidelines for some APIs appear in the following sections as indicated in each table.

[1024] 4.5.1.1. Input

[1025] Table 22. Input APIs for Security

[1026]

[1027]

[1028] 4.5.1.2. Output

[1029] Table 23. Output APIs for Security

[1030]

[1031]

[1032] 4.5.2. Detailed Guidelines for Secure APIs

[1033] 4.5.2.1. Device Authentication Protocol

[1034] When VCIB is started from "sleep" mode, the application device is authenticated.

[1035] After successful authentication, VCIB is able to begin communicating with ADK.

[1036] exist Figure 16 The authentication process is shown in the authentication process diagram.

[1037] Certification Standards

[1038] project specification Notes Encryption Algorithm AES FIPS 197 Key length 128-bit — Block cipher mode of operation CBC SP 800-38A Hash Algorithm SHA-256 FIPS 180-4 Seed length 128-bit — Signature length 256-bit —

[1039] Although embodiments of this disclosure have been described, it should be understood that the embodiments disclosed herein are illustrative and not restrictive in all respects. The scope of this disclosure is defined by the terminology of the claims and is intended to include any modifications within the equivalent scope and meaning of the terminology of the claims.

Claims

1. A vehicle platform on which an autonomous driving system can be installed, the vehicle platform comprising: vehicle; as well as A vehicle control interface box, which provides an interface connection between the vehicle and the autonomous driving system, wherein... The vehicle includes an entrance door and a rear trunk door, and When the entrance door is unlocked, the vehicle receives a trunk operation command from the autonomous driving system via the vehicle control interface box, requesting the operation of the trunk door. When the access door to the rear seats is locked, the vehicle does not accept the trunk operation command.

2. The vehicle platform according to claim 1, wherein When the access door to the rear seats is unlocked, the vehicle accepts the trunk operation command.

3. The vehicle platform according to claim 1 or 2, wherein The trunk operation command includes a first request for the trunk door to be opened / closed, and When the vehicle remains accepting the first request for one second, the vehicle opens the trunk door.

4. The vehicle platform according to claim 3, wherein The trunk operation command includes a second request indicating no further request, and When the vehicle accepts the second request while the trunk door is in operation, the vehicle allows the operation of the trunk door to continue.

5. The vehicle platform according to claim 4, wherein When the vehicle accepts the first request after accepting the second request while the trunk door is in operation, the vehicle stops the operation of the trunk door.

6. The vehicle platform according to claim 5, wherein When the vehicle stops the operation of the tailgate, and subsequently when the vehicle restarts the tailgate according to the tailgate operation command, the vehicle controls the tailgate to perform the opposite action to the action before it stopped.

7. A vehicle platform, comprising: An autonomous driving system that creates a driving plan; The vehicle, which performs vehicle control according to commands from the autonomous driving system; as well as A vehicle control interface box, which provides an interface connection between the vehicle and the autonomous driving system, wherein... The vehicle includes an entrance door and a rear trunk door, and When the entrance door is unlocked, the vehicle receives a trunk operation command from the autonomous driving system via the vehicle control interface box, requesting the operation of the trunk door. When the access door to the rear seats is locked, the vehicle does not accept the trunk operation command.

8. The vehicle platform according to claim 7, wherein When the access door to the rear seats is unlocked, the vehicle accepts the trunk operation command.

9. The vehicle platform according to claim 7, wherein The trunk operation command includes a first request for the trunk door to be opened / closed, and When the vehicle remains accepting the first request for one second, the vehicle opens the trunk door.

10. The vehicle platform according to claim 9, wherein The autonomous driving system transmits the first request until the trunk door is fully opened or closed.

11. The vehicle platform according to claim 9 or 10, wherein The trunk operation command includes a second request indicating no further request, and When the vehicle accepts the second request while the trunk door is in operation, the vehicle allows the operation of the trunk door to continue.

12. The vehicle platform according to claim 11, wherein When the vehicle accepts the first request after accepting the second request while the trunk door is in operation, the vehicle stops the operation of the trunk door.

13. The vehicle platform according to claim 12, wherein When the vehicle stops the operation of the tailgate, and subsequently when the vehicle restarts the tailgate according to the tailgate operation command, the vehicle controls the tailgate to perform the opposite action to the action before it stopped.