Vehicle platform, vehicle control interface box, and autonomous driving system

By introducing a vehicle control interface box into the vehicle platform to transmit driver input signals, the problem of failure when the autonomous driving system controls the vehicle's power mode is solved, ensuring system stability and safety.

CN115871706BActive Publication Date: 2026-03-20TOYOTA JIDOSHA KK
View PDF 4 Cites 0 Cited by

Patent Information

Authority / Receiving Office
CN · China
Patent Type
Patents(China)
Current Assignee / Owner
Filing Date
2022-09-27
Publication Date
2026-03-20

AI Technical Summary

Technical Problem

When an autonomous driving system controls the vehicle's power mode, the transition of the vehicle's power state may lead to unexpected malfunctions, and existing technologies cannot effectively prevent such malfunctions from occurring.

Method used

By introducing a vehicle control interface box into the vehicle platform, an interface is provided to transmit signals input by the driver, ensuring that the autonomous driving system can recognize and respond to the driver's intention to switch the vehicle's power state, thus avoiding inconsistencies between the power mode and the autonomous driving system's control.

Benefits of technology

It effectively prevents unexpected malfunctions caused by power state transitions in the vehicle platform, ensuring that the autonomous driving system can respond to driver input in a timely manner, and improving the stability and safety of the system.

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure CN115871706B_ABST
    Figure CN115871706B_ABST
Patent Text Reader

Abstract

The present disclosure relates to a vehicle platform, a vehicle control interface box, and an autonomous driving system. When a power state of a vehicle transitions while the autonomous driving system is controlling a power mode of the vehicle platform regardless of the control by the autonomous driving system, the autonomous driving system is notified that the transition is caused by a driver input. A VP (120) is configured to enable an ADS (202) to be installed thereon. The VP (120) includes a base vehicle (100) and a VCIB (111). The VCIB (111) provides an interface between the base vehicle (100) and the ADS (202). The VCIB (111) then provides a signal (S1) to the ADS (202) indicating a driver input on a start / stop button (130) for switching between start and off of the base vehicle (100).
Need to check novelty before this filing date? Find Prior Art

Description

[0001] This non-temporary application is based on Japanese Patent Application No. 2021-157538 filed on September 28, 2021 with the Japan Patent Office, the entire contents of which are incorporated herein by reference. TECHNICAL FIELD

[0002] The present disclosure relates to a vehicle platform configured to enable an autonomous driving system to be installed thereon, a vehicle control interface box that provides an interface between the vehicle platform and the autonomous driving system installed on the vehicle platform, and the autonomous driving system configured to be able to be installed on the vehicle platform. BACKGROUND

[0003] Japanese Patent Application Publication No. 2018-132015 discloses a vehicle that includes an autonomous driving system. The vehicle includes a power system, a power supply system, and the autonomous driving system. The power system manages power of the vehicle in a centralized manner. The power supply system manages charging or discharging of a battery installed on the vehicle and power supply to various in-vehicle devices in a centralized manner. The autonomous driving system performs autonomous driving control of the vehicle in a centralized manner. An engine ECU of the power system, a power supply ECU of the power supply system, and an autonomous driving ECU of the autonomous driving system are communicatively connected to each other through an in-vehicle network. SUMMARY

[0004] An autonomous driving system developed by an autonomous driving system developer can be externally attached to a vehicle. In this case, autonomous driving is performed under vehicle control according to a command from the externally attached autonomous driving system.

[0005] In such a vehicle, an interface for various commands and signals exchanged between the externally attached autonomous driving system and the vehicle is important. When a driver input (an operation of a user) for switching between start and stop of the vehicle is provided while the externally attached autonomous driving system is controlling the power mode of the vehicle platform, the power state of the vehicle is transitioned regardless of the control of the autonomous driving system. Therefore, an unexpected malfunction can be caused.

[0006] The present disclosure is made to solve the above problem, and aims to prevent an unexpected malfunction from being caused in the vehicle platform when the power state of the vehicle is transitioned regardless of the control of the autonomous driving system while the autonomous driving system is controlling the power mode of the vehicle platform on which the autonomous driving system is installed.

[0007] Another object of the present disclosure is to prevent an unexpected malfunction from occurring in a vehicle control interface box that provides an interface between a vehicle platform and an autonomous driving system when a power state of the vehicle is converted while the autonomous driving system installed on the vehicle platform is controlling a power mode of the vehicle platform regardless of the control of the autonomous driving system.

[0008] Another object of the present disclosure is to prevent an unexpected malfunction from occurring in an autonomous driving system when a power state of a vehicle is converted while the autonomous driving system installed on a vehicle platform is controlling a power mode of the vehicle platform regardless of the control of the autonomous driving system.

[0009] The vehicle platform in the present disclosure is configured to enable an autonomous driving system to be installed thereon. The vehicle platform includes a vehicle and a vehicle control interface box. The vehicle control interface box provides an interface between the vehicle and the autonomous driving system. The vehicle control interface box provides a signal indicating a driver input on a button to the autonomous driving system, the driver input on the button being used to switch between start and stop of the vehicle.

[0010] With the above configuration, the signal indicating the driver input on the button is transmitted to the autonomous driving system. The signal indicates that the conversion of the power state of the vehicle has been caused by the driver input. Thus, the autonomous driving system can be informed that the conversion of the power state of the vehicle has been caused by the driver input.

[0011] The vehicle control interface box in the present disclosure provides an interface between a vehicle included in a vehicle platform in which an autonomous driving system can be installed and the autonomous driving system. The vehicle control interface box includes a processor and a memory. A program executed by the processor is stored in the memory. The processor provides a signal indicating a driver input on a button to the autonomous driving system according to the program, the driver input on the button being used to switch between start and stop of the vehicle.

[0012] The autonomous driving system in the present disclosure is configured to be able to be installed on a vehicle platform. The vehicle platform includes a vehicle and a vehicle control interface box that provides an interface between the vehicle and the autonomous driving system. The autonomous driving system includes a computing component and a communication module. The communication module communicates with the vehicle control interface box. The computing component is programmed to receive, through the communication module, a signal indicating a driver input on a button from the vehicle control interface box, the driver input on the button being used to switch between start and stop of the vehicle.

[0013] When the computing component receives the signal indicating the driver input more than a prescribed number of times within a prescribed period of time, the computing component can determine that the button is being held.

[0014] With the above configuration, the vehicle platform can inform the autonomous driving system that the button is being held.

[0015] The foregoing and other objects, features, aspects and advantages of the present disclosure will become more apparent from the following detailed description of the present disclosure when taken in conjunction with the accompanying drawings. BRIEF DESCRIPTION OF DRAWINGS

[0016] Figure 1 is a diagram showing an outline of a vehicle 10 according to an embodiment of the present disclosure.

[0017] Figure 2 is a diagram showing a configuration of an ADK (ADS) and a VP in more detail. Figure 1

[0018] Figure 3 is a diagram illustrating values that a driver input signal can take.

[0019] Figure 4 is a diagram showing an exemplary change in the value of a driver input signal.

[0020] Figure 5 is a flowchart showing an exemplary process performed in association with pressing of a start / stop button.

[0021] Figure 6 is a diagram showing switching of the value of a driver input signal SS when a driver presses a start / stop button more than a prescribed number of times within a prescribed period of time while the start / stop button is being held.

[0022] Figure 7 is a diagram showing an exemplary process performed in association with holding of a start / stop button.

[0023] Figure 8 is a diagram showing the overall structure of an Autono-Maas vehicle.

[0024] Figure 9 is a diagram showing the system architecture of an Autono-Maas vehicle.

[0025] Figure 10 is a diagram showing a typical workflow in an ADS.

[0026] Figure 11 is a diagram showing the relationship between a front wheel steering angle rate limit and speed.

[0027] Figure 12 is a state machine diagram of a power mode.

[0028] Figure 13 is a diagram showing details of a shift change order.

[0029] Figure 14 is a diagram showing a fixed order.

[0030] ​Figure 15 is a diagram showing a stop sequence.

[0031] Figure 16 is a state machine diagram of an automatic state.

[0032] Figure 17 is a diagram showing an authentication process. DETAILED DESCRIPTION

[0033] Embodiments of the present disclosure will be described in detail below with reference to the accompanying drawings. Like or corresponding elements have the same reference numbers assigned and description thereof will not be repeated.

[0034] [Embodiment]

[0035] Figure 1 is a diagram showing an outline of the vehicle 10 according to an embodiment of the present disclosure. Referring to Figure 1 , the vehicle 10 includes an autonomous driving kit (hereinafter denoted as "ADK") 200 and a vehicle platform (hereinafter denoted as "VP") 120. The ADK 200 is configured to be attachable to (mountable on) the VP 120. The ADK 200 and the VP 120 are configured to communicate with each other through a vehicle control interface box 111 (to be described later) mounted on the VP 120.

[0036] The VP 120 can perform autonomous driving according to a control request (command) from the ADK 200. Although Figure 1 shows that the VP 120 and the ADK 200 are in a position away from each other, the ADK 200 is actually attached to a roof or the like of a base vehicle 100 (to be described later) included in the VP 120. The ADK 200 can also be detached from the VP 120. When the ADK 200 is not attached, the VP 120 can travel by driving of a driver (user). In this case, the VP 120 performs travel control in a manual mode (travel control according to operation of the user).

[0037] The ADK 200 includes an autonomous driving system (hereinafter denoted as "ADS") 202 for autonomous driving of the vehicle 10 (the base vehicle 100). For example, the ADS 202 creates a driving plan of the vehicle 10. Then, the ADS 202 outputs various commands (control requests) for the vehicle 10 to travel according to the created driving plan to the VP 120 according to an application program interface (API) defined for each command. The ADS 202 receives various signals indicating a state (vehicle state) of the VP 120 from the VP 120 according to an API defined for each signal. Then, the ADS 202 reflects the received vehicle state in creation of the driving plan. The detailed configuration of the ADS 202 will be described later.

[0038] The VP 120 includes the base vehicle 100 and a vehicle control interface box (hereinafter denoted as "VCIB") 111.

[0039] The base vehicle 100 performs various types of vehicle control in accordance with control requests from the ADK 200 (the ADS 202). The base vehicle 100 includes various systems for controlling the vehicle and various sensors. Specifically, the base vehicle 100 includes an integrated control manager 115, a brake system 121, a steering system 122, a powertrain system 123, an active safety system 125, a body system 126, wheel speed sensors 127A and 127B, a pinion angle sensor 128, a camera 129A, and radar sensors 129B and 129C.

[0040] The integrated control manager 115 includes a processor and a memory, and integrally controls systems involved in the operation of the vehicle (the brake system 121, the steering system 122, the powertrain system 123, the active safety system 125, and the body system 126).

[0041] The brake system 121 is configured to control brake devices provided in the respective wheels. The brake devices include, for example, a disc brake system (not shown) that operates with hydraulic pressure adjusted by an actuator.

[0042] The wheel speed sensors 127A and 127B are connected to the brake system 121. The wheel speed sensor 127A detects the rotational speed of the front wheels, and outputs its detection value to the brake system 121. The wheel speed sensor 127B detects the rotational speed of the rear wheels, and outputs its detection value to the brake system 121.

[0043] The brake system 121 generates a brake command to the brake devices in accordance with a prescribed control request output from the ADK 200 through the VCIB 111 and the integrated control manager 115. The brake system 121 then controls the brake devices based on the generated brake command. The integrated control manager 115 can calculate the speed (vehicle speed) of the vehicle based on the rotational speeds of the respective wheels.

[0044] The steering system 122 is configured to control the steering angle of the steering wheel of the vehicle with a steering device. The steering device includes, for example, a rack-and-pinion electric power steering (EPS) that allows the steering angle to be adjusted by an actuator.

[0045] The pinion angle sensor 128 is connected to the steering system 122. The pinion angle sensor 128 detects the rotational angle (pinion angle) of a pinion gear coupled to a rotational shaft of the actuator included in the steering device, and outputs its detection value to the steering system 122.

[0046] The steering system 122 generates a steering command to a steering device in accordance with a prescribed control request output from the ADK 200 through the VCIB 111 and the integrated control manager 115. Then, the steering system 122 controls the steering device on the basis of the generated steering command.

[0047] The powertrain system 123 controls an electronic parking brake (EPB) system provided in at least one of the plurality of wheels, a parking lock (P-lock) system provided in a transmission of the base vehicle 100, and a propulsion system including a shift device for selecting a shift range. The detailed configuration of the powertrain system 123 will be described later with reference to Figure 2

[0048] The active safety system 125 detects an obstacle (pedestrian, bicycle, parked vehicle, utility pole, etc.) in front of or behind the vehicle using the camera 129A and the radar sensors 129B and 129C. The active safety system 125 determines whether the vehicle 10 is likely to collide with the obstacle on the basis of the distance between the vehicle 10 and the obstacle and the moving direction of the vehicle 10. Then, when the active safety system 125 determines that there is a possibility of collision, it outputs a brake command to the brake system 121 through the integrated control manager 115 so as to increase the braking force of the vehicle.

[0049] The body system 126 is configured to control components such as a direction indicator, a horn, and a wiper (none of which is shown) in accordance with, for example, the running state of the vehicle 10 or the environment around the vehicle 10. The body system 126 controls the respective components in accordance with a prescribed control request output from the ADK 200 through the VCIB 111 and the integrated control manager 115.

[0050] The VCIB 111 is configured to communicate with the ADS 202 of the ADK 200 through a controller area network (CAN). The VCIB 111 receives various control requests from the ADS 202 or outputs the state of the VP 120 to the ADS 202 by executing a prescribed API defined for each communication signal. When the VCIB 111 receives a control request from the ADS 202, it outputs a control command corresponding to the control request to the system corresponding to the control command through the integrated control manager 115. The VCIB 111 obtains various types of information about the base vehicle 100 from the respective systems through the integrated control manager 115 and outputs the state of the base vehicle 100 to the ADS 202 as a vehicle state.

[0051] The vehicle 10 can be applied as one of the constituent elements of a mobile as a service (MaaS) system. The MaaS system further includes, in addition to the vehicle 10, for example, a data server and a mobility service platform (MSPF) (none of which is shown).

[0052] ​The MSPF is an integrated platform to which various mobility services are connected. Mobility services related to autonomous driving are connected to the MSPF. In addition to mobility services related to autonomous driving, mobility services provided by a ride-sharing company, a car-sharing company, a car rental company, a taxi company, and an insurance company can be connected to the MSPF. According to service contents, various mobility services including mobility services can use various functions provided by the MSPF by using APIs published on the MSPF.

[0053] The VP 120 further includes a data communication module (DCM) (not shown) as a communication interface (I / F) to wirelessly communicate with a data server of the MaaS system. The DCM outputs various types of vehicle information such as speed, position, or autonomous driving status to the data server. The DCM receives various types of data from mobility services related to autonomous driving through the MSPF and the data server for managing travel of autonomous driving vehicles including the vehicle 10 in the mobility services.

[0054] The MSPF publishes APIs for using various types of data on vehicle status and vehicle control required for developing the ADK. By using the APIs published on the MSPF, various mobility services can use various functions provided by the MSPF according to service contents. For example, mobility services related to autonomous driving can obtain operation control data of autonomous driving vehicles communicating with the data server or information stored in the data server from the MSPF by using the APIs published on the MSPF. Mobility services related to autonomous driving can transmit data for managing autonomous driving vehicles including the vehicle 10 to the MSPF by using the APIs.

[0055] Figure 2 is a diagram further illustrating Figure 1 the configuration of the ADK 200 (ADS 202) and the VP 120 shown in FIG. 1. Referring to Figure 2 , the ADS 202 of the ADK 200 includes a computing component 210, a human-machine interface (HMI) 230, a sensor 260 for perception, a sensor 270 for pose, and a sensor cleaner 290.

[0056] The computing component 210 includes a memory and a processor, and communication modules 210A and 210B. Programs executable by the processor are stored in the memory. The processor performs various types of processing according to the programs stored in the memory. The communication modules 210A and 210B are configured to communicate with the VCIB 111. During autonomous driving of the vehicle 10, the computing component 210 obtains information indicating the environment around the vehicle and information indicating the posture, behavior, and position of the vehicle 10 from various sensors (to be described later), and obtains the vehicle state from the VP 120 through the VCIB 111 and sets the next operation (acceleration, deceleration, or turning) of the vehicle 10. Then, the computing component 210 outputs various commands for implementing the set next operation to the VCIB 111 in the VP 120. The computing component 210 is configured to control the power mode of the VP 120 while the ADK 200 is attached to the VP 120. While the power mode of the VP 120 is not necessarily the same as the power state of the base vehicle 100, it is consistent with the power state of the base vehicle 100 in the absence of a driver input on the start / stop button 130 (to be described later).

[0057] The HMI system 230 presents information to the user and accepts the user's operation during autonomous driving, during driving requiring the user's operation, or when transitioning between autonomous driving and driving requiring the user's operation. The HMI 230 is configured to be connected to input and output devices (not shown), such as a touch panel display provided in the VP 120.

[0058] The sensor for perception 260 is a sensor that perceives the environment around the vehicle. The sensor for perception 260 includes, for example, at least one of a laser imaging detection and ranging (LIDAR), a millimeter wave radar, and a camera.

[0059] The LIDAR refers to a distance measuring device that measures a distance based on the period of time until the laser beam reflected by an object returns from the emitted pulsed laser beam (infrared ray). The millimeter wave radar is a distance measuring device that measures the distance or direction to an object by emitting a short-wavelength radio wave to the object and detecting the radio wave returned from the object. The camera is arranged, for example, at the rear side of the interior rearview mirror in the cabin, and is used to take an image of the front of the vehicle 10. As a result of image processing of the image or video image taken by the camera by an artificial intelligence (AI) or image processing processor, another vehicle, an obstacle, or a person in front of the vehicle 10 can be recognized. The information obtained by the sensor for perception 260 is output to the computing component 210.

[0060] The sensor for posture 270 is a sensor that detects the posture, behavior, or position of the vehicle 10. The sensor for posture 270 includes, for example, an inertial measurement unit (IMU) and a global positioning system (GPS).

[0061] The IMU detects, for example, acceleration in the front-rear direction, the lateral direction, and the up-down direction of the vehicle 10, and angular velocity in the roll direction, the pitch direction, and the yaw direction of the vehicle 10. The GPS detects the position of the vehicle 10 based on information received from a plurality of GPS satellites orbiting the earth. Information obtained by the sensors for posture 270 is output to the computing component 210.

[0062] The sensor cleaner 290 removes dirt attached to various sensors. The sensor cleaner 290 removes dirt attached to the lens of the camera or the portion from which a laser beam or radio wave is emitted, for example, with a cleaning solution or a wiper.

[0063] The VCIB 111 provides an interface between the base vehicle 100 and the ADS 200. The VCIB 111 includes a VCIB 111A and a VCIB 111B. Each of the VCIB 111A and 111B includes an electronic control unit (ECU). The ECU includes a processor such as a central processing unit (CPU) and a memory (read only memory (ROM) and random access memory (RAM)) that are not shown. A program executable by the processor is stored in the ROM. The processor performs various types of processing according to the program stored in the ROM.

[0064] The VCIB 111A and 111B are communicably connected to the communication modules 210A and 210B of the ADS 202, respectively. The VCIB 111A and 111B are also communicably connected to each other. Although the VCIB 111B is functionally equivalent to the VCIB 111A, it is partially different in terms of the plurality of systems that make up the VP 120 connected to the VCIB.

[0065] The VCIB 111A and 111B each relay control requests and vehicle states between the ADS 202 and the VP 120. A specific description of the VCIB 111A will be given representatively. The VCIB 111A receives various control requests output from the ADS 202 according to an API defined for each control request. Then, the VCIB 111A generates a command corresponding to the received control request, and outputs the command to the system of the base vehicle 100 corresponding to the control request. The control request (control command) received by the VCIB 111A from the ADS 202 includes a power mode command that controls the power mode of the VP 120 provided by the ADS 202. The ADS 202 is able to control the power mode of the VP 120 based on this power mode command.

[0066] The VCIB 111A receives vehicle information provided from the respective systems of the VP 120, and transmits (provides) information (signals) indicating the vehicle state of the VP 120 to the ADS 202 according to the API defined for the respective vehicle states. The information indicating the vehicle state can be the same information as the vehicle information provided from the respective systems of the VP 120, or can be information extracted from the vehicle information for processing performed by the ADS 202. In the present embodiment, the vehicle state transmitted from the VCIB 111 to the ADS 202 includes the state of the start / stop button 130 (to be described later). The vehicle state can include the power state of the base vehicle 100.

[0067] Since the VCIB 111A and 111B are provided with the same functions as those related to the operation of at least one system (e.g., the brake or steering system), the control system between the ADK 200 and the VP 120 is redundant. Therefore, when a certain type of failure occurs in a part of the system, it is possible to maintain the function (turning or stopping) of the VP 120 by appropriately switching or disconnecting the control system in which the failure has occurred between the control systems.

[0068] The brake system 121 includes the brake system 121A and 121B. The steering system 122 includes the steering system 122A and 122B. The powertrain system 123 includes the EPB system 123A, the P-lock system 123B, and the propulsion system 124.

[0069] The VCIB 111A is communicatively connected to the brake system 121A, the steering system 122A, the EPB system 123A, the P-lock system 123B, the propulsion system 124, the body system 126, and the start / stop button 130 through a communication bus. The VCIB 111B is communicatively connected to the brake system 121B, the steering system 122B, the P-lock system 123B, and the start / stop button 130 through a communication bus.

[0070] The brake systems 121A and 121B are configured to control a plurality of brake devices provided in the wheels. The brake system 121B can be functionally equivalent to the brake system 121A, or one of the brake systems 121A and 121B can be configured to independently control the brake force of the wheels during vehicle travel, and the other of the brake systems 121A and 121B can be configured to control the brake force such that the same brake force is generated in the wheels during vehicle travel.

[0071] The brake systems 121A and 121B each generate a brake command to the brake device in accordance with a control request received from the ADS 202 through the VCIB 111. For example, the brake systems 121A and 121B control the brake device based on a brake command generated in one of the brake systems, and when a failure occurs in that brake system, control the brake device based on a brake command generated in the other brake system.

[0072] The steering systems 122A and 122B are configured to control a steering angle of a steering wheel of the vehicle 10 with a steering device. The steering system 122B is similar in function to the steering system 122A.

[0073] The steering systems 122A and 122B each generate a steering command to the steering device in accordance with a control request received from the ADS 202 through the VCIB 111. For example, the steering systems 122A and 122B control the steering device based on a steering command generated in one of the steering systems, and when a failure occurs in that steering system, control the steering device based on a steering command generated in the other steering system.

[0074] The EPB system 123A is configured to control an EPB. The EPB is provided separately from the brake device, and fixes a wheel by operation of an actuator. For example, the EPB activates a drum brake for setting a parking brake in at least one of the plurality of wheels with an actuator to fix the wheel, or activates the brake device with an actuator capable of adjusting hydraulic pressure to be supplied to the brake device separately from the brake systems 121A and 121B to fix the wheel.

[0075] The EPB system 123A controls the EPB in accordance with a control request received from the ADS 202 through the VCIB 111.

[0076] The P-lock system 123B is configured to control a P-lock device. The P-lock device fits a protrusion provided at a tip of a parking lock pawl, whose position is adjusted by an actuator, into a tooth of a gear (lock gear) provided to be coupled with a rotating element in a transmission of the base vehicle 100. Rotation of an output shaft of the transmission is thus fixed and the wheels are fixed.

[0077] The P-lock system 123B controls the P-lock device in accordance with a control request received from the ADS 202 through the VCIB 111. When the control request from the ADS 202 includes a request to set a shift range to a parking range (P range), the P-lock system 123B activates the P-lock device, and when the control request includes a request to set the shift range to a shift range other than the P range, it deactivates the P-lock device.

[0078] The propulsion system 124 is configured to switch a shift range with a shift device, and control a driving force of the vehicle 10 in a moving direction of the vehicle 10, which is generated by a driving source. The switchable shift range includes, for example, a parking range (P range), a neutral range (N range), a forward travel range (D range), and a reverse travel range (R range). The driving source includes, for example, a motor generator and an engine.

[0079] The propulsion system 124 controls the shift device and the driving source in accordance with a control request received from the ADS 202 through the VCIB 111.

[0080] The active safety system 125 is communicatively connected to the brake system 121A. As described above, the active safety system 125 detects an obstacle (an obstacle or a person) in front of the vehicle by using the camera 129A and the radar sensor 129B, and when it determines that there is a possibility of collision based on a distance to the obstacle, it outputs a brake command to the brake system 121A so as to increase a brake force.

[0081] The body system 126 controls components such as a direction indicator, a horn, or a wiper in accordance with a control request received from the ADS 202 through the VCIB 111.

[0082] The start / stop button 130 is a button (switch) for switching between an on / off of the base vehicle 100 (in other words, switching a power state of the base vehicle 100). The start / stop button 130 is also called a “power switch” or an “ignition switch”. The start / stop button 130 is mounted on the base vehicle 100 as a button to be pressed down by a driver (a user).

[0083] The state of the start / stop button 130 includes an on state and an off state. The on state refers to a state in which the driver presses down the start / stop button 130 (a pressed-down state). In other words, the on state refers to a state in which there is a driver input on the button. The off state refers to a state in which the driver does not press down the start / stop button 130 (a not-pressed-down state). In other words, the off state refers to a state in which there is no driver input on the button. The signal SA represents the state of the start / stop button 130, and it is supplied from the start / stop button 130 to the VCIB 111. Specifically, when the start / stop button 130 is in the on state, the signal SA is at an H level (a logic high). When the start / stop button 130 is in the off state, the signal SA is at an L level (a logic low).

[0084] In the present embodiment, it is assumed that the vehicle 10 (base vehicle 100) is in an exemplary automated driving of so-called level 4 or less. It is assumed that during such automated driving, the driver input (pressing) on the start / stop button 130 is enabled. Therefore, the driver input provided based on the driver's intention causes the conversion (change) of the power state of the base vehicle 100. Therefore, the power state of the base vehicle 100 can be converted regardless of the control of the ADS 202 while the ADS 202 is controlling the power mode of the VP 120.

[0085] On the other hand, it is assumed that during the automated driving (full driving automation) of the vehicle 10 of so-called level 5, the driver input on the start / stop button 130 is disabled. In other words, the start / stop button 130 is held (i.e., suspended). Therefore, during the full driving automation of the vehicle 10, the driver input does not cause the conversion of the power state of the base vehicle 100. An example of the start / stop button 130 being held will be described later in a modification of the embodiment.

[0086] For example, when the autonomous mode (automated driving mode) is selected as the automatic state by the user's operation of the HMI 230 in the vehicle 10 configured as above, automated driving is performed. During the automated driving, the ADS 202 initially creates a driving plan as described above. Examples of the driving plan include a plan to continue straight ahead, a plan to turn left / right at a prescribed intersection on a prescribed travel path, and a plan to change a travel lane.

[0087] The ADS 202 calculates controllable physical quantities (acceleration, deceleration, and wheel steering angle) required for the operation of the vehicle 10 in accordance with the created driving plan. The ADS 202 divides the physical quantities for each execution cycle time of the API. The ADS 202 outputs a control request indicating the divided physical quantities to the VCIB 111 through the API. Further, the ADS 202 obtains the vehicle state (actual moving direction of the vehicle and fixed state of the vehicle) from the VP 120, and again creates a driving plan reflecting the obtained vehicle state. The ADS 202 thus allows the automated driving of the vehicle 10.

[0088] When the ADS 202 (ADK 200) is externally attached to the VP 120, the automated driving of the vehicle 10 (base vehicle 100) is performed under the vehicle control according to the command from the computing component 210 of the ADS 202.

[0089] When a driver input (pressing the start / stop button 130) for switching between start and stop of the base vehicle 100 is provided while the ADS 202 is controlling the power mode of the VP 120, the power state of the base vehicle 100 can be transitioned regardless of the control of the ADS 202. Thus, the power mode of the VP 120 becomes inconsistent with the power state of the base vehicle 100, thus possibly causing an unexpected malfunction. Therefore, it is desirable to inform the ADS 202 that the transition of the power state of the base vehicle 100 has been caused by the driver input (i.e., the transition is based on the driver’s intention).

[0090] The VCIB 111 according to the present embodiment provides the driver input signal SS indicating the state of the start / stop button 130 to the ADS 202. Specifically, the processor of the VCIB 111 provides the driver input signal SS to the ADS 202 according to a program stored in the memory of the VCIB 111. The computing component 210 of the ADS 202 is programmed to receive the driver input signal SS from the VCIB 111 through the communication modules 210A and 210B.

[0091] The driver input signal SS includes a signal SO and a signal SI. The signal SO represents the absence of a driver input (pressing) on the start / stop button 130. The signal SI represents a driver input on the start / stop button 130. In the present embodiment, for simplicity of description, it is assumed that the driver input signal SS is identical to the signal SA provided from the start / stop button 130 to the VCIB 111. Specifically, at the L level, the signal SO is identical to the signal SA, and at the H level, the signal SI is identical to the signal SA.

[0092] According to the above configuration, when a driver input on the start / stop button 130 is provided, the signal SI is sent to the ADS 202. The signal SI indicates that the transition of the power state of the base vehicle 100 has been caused by the driver input on the start / stop button 130. Thus, the ADS 202 can be informed that the transition of the power state of the base vehicle 100 has been caused by the driver input.

[0093] Figure 3 is a graph illustrating values that the driver input signal SS can take. Referring to Figure 3 , the driver input signal SS can take any one of 0 to 2. These values are set by the VCIB 111.

[0094] The value 0 represents the off (unpressed state) of the start / stop button 130. When the driver input signal SS has the value 0, the driver input signal SS is the signal SO.

[0095] The value 1 indicates the ON (pressed state) of the start / stop button 130. When the driver input signal SS has the value 1, the driver input signal SS is the signal SI.

[0096] The value 2 indicates that some trouble has occurred in the power supply of the VP 120. In the following description, it is assumed that such trouble does not occur, and the value of the driver input signal SS is set to either of 0 and 1.

[0097] Figure 4 is a graph showing an exemplary change in the value of the driver input signal SS. In Figure 4 , the ordinate indicates the value of the driver input signal SS, and the abscissa indicates time.

[0098] Referring to Figure 4 , in the time period from time to to time tl, the start / stop button 130 is in the OFF state. Therefore, the driver input signal SS has the value 0 (signal SO).

[0099] When the driver presses the start / stop button 130 at time tl (ON operation), the state of the start / stop button 130 is switched from the OFF state to the ON state. Therefore, the value of the driver input signal SS is switched from 0 to 1.

[0100] In the time period from time tl to time t2, the driver presses the start / stop button 130. In this time period, the value of the driver input signal SS is kept at 1 (signal SI).

[0101] When the start / stop button 130 is thus pressed, the driver can desire to switch the power supply state of the base vehicle 100. Therefore, the driver input signal SS having the value 1 (signal SI) indicates that the driver desires to switch the power supply state of the base vehicle 100.

[0102] When the signal SI is provided, the ADS 202 can estimate the power supply state of the base vehicle 100 desired by the driver and control the power supply mode of the VP 120 so as to be consistent with the estimated power supply state. For example, when the signal SI is provided while the base vehicle 100 is in the Ready-ON state in which the power supply has been turned on, the ADS 202 estimates that the driver desires to turn the power supply state of the base vehicle 100 into the power OFF state. The power OFF state refers to a state in which each system (ECU) of the base vehicle 100 is turned off. Then, the ADS 202 controls the power supply mode of the VP 120 to the Sleep mode so as to be consistent with the power supply state (power OFF state) of the base vehicle 100 resulting from the switching.

[0103] When the driver no longer presses the start / stop button 130 at time t2, the state of the start / stop button 130 switches from the on state to the off state. As a result, the value of the driver input signal SS switches from 1 to 0. Thereafter, in this example, the value of the driver input signal SS remains at 0 (signal SO).

[0104] Figure 5 is a flowchart illustrating exemplary processing performed in association with the pressing of the start / stop button 130.

[0105] With reference to Figure 5 , the processor of the VCIB 111 determines whether the start / stop button 130 has been turned on, in accordance with the signal SA from the start / stop button 130 (step S10). Specifically, the processor determines whether the signal SA provided to the VCIB 111 from the start / stop button 130 is at the L level or the H level.

[0106] When the start / stop button 130 is off (NO in step S10), the processor of the VCIB 111 provides the signal SO to the ADS 202 indicating the absence of a driver input on the start / stop button 130 (step S15). In this embodiment, the signal SO is the same as the signal SA at the L level, and is provided to the ADS 202 during the time period from time to to time tl and the time period after time t2. Figure 4

[0107] When the start / stop button 130 is on (YES in step S10), the processor of the VCIB 111 provides the signal SI to the ADS 202 indicating a driver input on the start / stop button 130 (step S20). In this embodiment, the signal SI is the same as the signal SA at the H level, and is provided to the ADS 202 during the time period from time tl to time t2. Figure 4

[0108] The computing component 210 of the ADS 202 receives the signal SO or the signal SI from the VCIB 111 through the communication modules 210A and 210B (step S40). Which of these signals the computing component 210 receives differs depending on the result of the processing in step S10.

[0109] When the ADS 202 receives the signal SI in step S40, it can control the power mode of the VP 120 so as to be consistent with the power state of the base vehicle 100 resulting from the transition.

[0110] ​​As described above, the VP 120 according to this embodiment includes a base vehicle 100 and a VCIB 111. The VCIB 111 provides the ADS 202 with a signal S1 indicating driver input on the start / stop button 130.

[0111] Using the above configuration, when driver input (pressing) is provided on the start / stop button 130, signal S1 is sent to ADS 202. Signal S1 indicates that the power state of the base vehicle 100 has been changed due to driver input. Therefore, when the power state of the base vehicle 100 changes while ADS 202 is controlling the power mode of VP 120, regardless of ADS 202's control, ADS 202 can be notified that the power state of the base vehicle 100 has been changed due to driver input. Then, ADS 202 can determine that the power state of the base vehicle 100 has been changed due to driver input.

[0112] Inconsistency between the power mode of VP 120 and the power state of the base vehicle 100 could lead to unexpected malfunctions. Conversely, in this embodiment, even if they are inconsistent, ADS 202 is able to determine that a change in the power state of the base vehicle 100 has been caused by driver input (i.e., based on the driver's intention). Then, for example, ADS 202 can execute various types of control (e.g., controlling to change the power mode of VP 120 so that its power mode matches the power state of the base vehicle 100, if the driver's intention has the highest priority) to prevent the aforementioned malfunctions.

[0113] Furthermore, ADS 202 can confirm, based on the above determination results, that there are no security issues, such as unauthorized intrusion into the power status of the base vehicle 100 from outside the vehicle 10.

[0114] [Variations on the Implementation]

[0115] While ADS 202 is controlling the power mode of VP 120, the start / stop button 130 can be held (suspended) so that the power state of the base vehicle 100 is not affected by driver input on the start / stop button 130 (e.g., during fully automated driving). At this time, the computing component 210 of ADS 202 is preferably able to determine that the start / stop button 130 is held.

[0116] In the above embodiment, assume the value of the driver input signal SS ( Figure 3 The value SS is set to any one of 0 to 2 (more specifically, 0 or 1). The value to which the driver input signal SS is set does not indicate whether the start / stop button 130 is held.

[0117] In this modification, when the computing component 210 of the ADS 202 receives the signal S1 more than the prescribed number of times within the prescribed period of time, it is determined that the start / stop button 130 is held, which will be described in detail below.

[0118] Figure 6 is a diagram of the switching of the value of the driver input signal SS when the driver presses the start / stop button 130 more than the prescribed number of times within the prescribed period of time while the start / stop button 130 is being held.

[0119] Referring to Figure 6 In the period of time from time t10 to time tl l, the start / stop button 130 is off. Therefore, the value of the driver input signal SS remains at 0 (signal SO).

[0120] When the driver presses the start / stop button 130 at time tl l (on operation), the value of the driver input signal SS switches from 0 to 1 (signal SO switches to signal S l). On the other hand, in this example, the start / stop button 130 is being held. Therefore, despite the driver pressing the start / stop button 130, the power state of the base vehicle 100 does not change (change).

[0121] During the period of time from time tl l to time t12, the driver is performing the on operation, and at time t12, the operation ends (signal S l switches to signal SO). During this period, the power state of the base vehicle 100 does not change.

[0122] In this example, the driver also attempts to change the power state of the base vehicle 100 with his / her own intention after time t12. Specifically, during the period of time from time t12 to time t14 and during the period of time from time t14 to time t16, the driver repeatedly presses the start / stop button 130 as during the period of time from time t10 to time t12. Therefore, the VCB 111 receives the signal S l three times within the prescribed period of time PP (corresponding to N times in the diagram). In this embodiment, the prescribed number of times is assumed to be two times. Therefore, three times is greater than the prescribed number of times.

[0123] The computing component 210 of the ADS 202 determines that it has received the signal S l more than the prescribed number of times within the prescribed period of time PP. Then, the computing component 210 determines that the reason it repeatedly receives the signal S l is that the driver input on the start / stop button 130 is repeatedly provided without changing the power state of the base vehicle 100. Then, the computing component 210 determines that the start / stop button 130 is being held.

[0124] Figure 7 is a diagram showing an example process performed in association with the start / stop button 130 being held.

[0125] Referring to Figure 7 , the computing component 210 of the ADS 202 determines whether it has received the signal S1 above the prescribed number of times within the prescribed period of time PP (step S105).

[0126] When the computing component 210 has not received the signal S1 above the prescribed number of times (NO in step S105), it exits the processing in Figure 7 . When the computing component 210 has received the signal S1 above the prescribed number of times (YES in step S105), it determines that the start / stop button 130 is being held (step S110).

[0127] As described above, in this modification, when the computing component 210 of the ADS 202 has received the signal S1 above the prescribed number of times within the prescribed period of time PP, it determines that the start / stop button 130 is being held.

[0128] The VP 120 is thus able to notify the ADS 202 that the start / stop button 130 is being held. Even when the driver input signal SS does not have another value (a value other than 0 or 1 in Figure 3 ) indicating whether the start / stop button 130 is being held, the computing component 210 can determine that the start / stop button 130 is being held.

[0129] [Example]

[0130] API Specification for Toyota Vehicle Platform

[0131] Version 1.1

[0132] Revision History

[0133]

[0134] Table of Contents

[0135] 1. Introduction

[0136] 1.1. Purpose of this Specification

[0137] 1.2. Target Vehicle

[0138] 1.3. Definition of Terms

[0139] 2. Architecture

[0140] 2.1. Overall Architecture of Autono-MaaS Vehicle

[0141] 2.2. System Architecture of Autono-MaaS Vehicle

[0142] 3. Application Interface

[0143] 3.1. Typical use of the API

[0144] 3.2. API for vehicle motion control

[0145] 3.2.1. List of APIs for vehicle motion control

[0146] 3.2.2. Details of each API for vehicle motion control

[0147] 3.3. API for body control

[0148] 3.3.1. List of APIs for body control

[0149] 3.3.2. Details of each API for body control

[0150] 3.4. API for power supply control

[0151] 3.4.1. List of APIs for power supply control

[0152] 3.4.2. Details of each API for power supply control

[0153] 3.5. API for fault notification

[0154] 3.5.1. List of APIs for fault notification

[0155] 3.5.2. Details of each API for fault notification

[0156] 3.6. API for safety

[0157] 3.6.1. List of APIs for safety

[0158] 3.6.2. Details of each API for safety

[0159] 4. API guide for controlling Toyota vehicles

[0160] 4.1. API for vehicle motion control

[0161] 4.1.1. List of APIs for vehicle motion control

[0162] 4.1.2. Detailed guide for APIs for vehicle motion control

[0163] 4.2. API for body control

[0164] 4.2.1. List of APIs for body control

[0165] 4.3. API for power supply control

[0166] 4.3.1. API List for Power Control

[0167] 4.4. API for Fault Notification

[0168] 4.4.1. API List for Fault Notification

[0169] 4.5. API for Security

[0170] 4.5.1. API List for Security

[0171] 4.5.2. API Detail Guide for Security

[0172] 1. Introduction

[0173] 1.1. Purpose of this Specification

[0174] This document is an API specification for vehicle control interface for Autono-MaaS vehicles, and contains an overview, usage, and notes for the API.

[0175] 1.2. Target Vehicle

[0176] This specification applies to Autono-MaaS vehicles defined by [Architecture Specification for Toyota Vehicle Platform with Automated Driving System].

[0177] 1.3. Definition of Terms

[0178] Table 1. Definition of terms

[0179]

[0180] 2. Structure

[0181] 2.1. Overall Structure of Autono-MaaS Vehicle

[0182] The overall structure of the Autono-MaaS vehicle is shown in Figure 8 .

[0183] 2.2. System Structure of Autono-MaaS Vehicle

[0184] The system architecture is shown in Figure 9 .

[0185] 3. Application Interface

[0186] 3.1. Typical Usage of API

[0187] In this section, typical usage of the API is described.

[0188] The typical workflow of the API is as follows Figure 10). The following example assumes CAN for physical communication.

[0189] 3.2. API for vehicle motion control

[0190] In this section, the API for vehicle motion control is described.

[0191] 3.2.1. API list for vehicle motion control

[0192] 3.2.1.1. Inputs

[0193] Table 3. Input APIs for vehicle motion control

[0194]

[0195] * Reaction time in VP depending on the request from the ADK

[0196] 3.2.1.2. Outputs

[0197] Table 4. Output APIs for vehicle motion control

[0198]

[0199]

[0200]

[0201] 3.2.2. Details of each API for vehicle motion control

[0202] 3.2.2.1. Propulsion direction command

[0203] Request to change the gear from forward (D) to reverse (R), or from reverse to forward

[0204] Value

[0205] Value Description Comment 0 No request 2 R Shift to R 4 D Shift to D Other Reserved

[0206] Remark

[0207] • Available only when the vehicle mode status = "Autonomous mode".

[0208] • Available only when the vehicle is at a standstill (travel direction = "still").

[0209] • Available only when the application of the brakes.

[0210] 3.2.2.2. Fix command

[0211] Request to open / close wheel locks

[0212] Value

[0213] The following table shows EPB and P range for immobilization.

[0214]

[0215] Remark

[0216] • This API is used to make the vehicle park.

[0217] • Available only when vehicle mode status = "Autonomous Mode".

[0218] • Can be changed only when the vehicle is stopped (travel direction = "Still").

[0219] • Can be changed only when the application of the brakes.

[0220] 3.2.2.3. Still Command

[0221] Request application / release of brake hold function

[0222] Value

[0223] Value Description Comment 0 No request 1 Applied Brake hold function allowed. 2 Released

[0224] Remark

[0225] • This API is used to select whether to allow the state of the brake hold function.

[0226] • Available only when vehicle mode status = "Autonomous Mode".

[0227] • A continue acceleration command (deceleration request) is required until the still state becomes "Applied".

[0228] 3.2.2.4. Acceleration Command

[0229] Request acceleration

[0230] Value

[0231] Estimated maximum deceleration to estimated maximum acceleration [m / s 2 ]

[0232] Remark

[0233] • Available only when vehicle mode status = "Autonomous Mode".

[0234] • Acceleration (+) and deceleration (-) requests based on the travel direction status direction.

[0235] • Upper / lower limits will vary based on the estimated maximum deceleration and the estimated maximum acceleration.

[0236] • When a request for acceleration greater than the estimated maximum acceleration is requested, the request is set to the estimated maximum acceleration.

[0237] • When the requested deceleration is greater than the estimated maximum deceleration, the request is set to the estimated maximum deceleration.

[0238] • When the driver is operating the vehicle (over-control), the requested acceleration may not be achieved.

[0239] • When PCS is working simultaneously, VP should be selected with minimum acceleration (maximum deceleration).

[0240] 3.2.2.5. Front wheel steering angle command

[0241] value

[0242] Value Description Comment - [Units: Radians]

[0243] Remark

[0244] • Available only when vehicle mode status = "Autonomous Mode".

[0245] Left represents a positive value (+). Right represents a negative value (-).

[0246] • When the vehicle is traveling in a straight line, the front wheel steering angle is set to a value (0).

[0247] • This request is set to a value relative to the current one to prevent the accumulation of misalignment in the "front wheel steering angle".

[0248] The requested value should be set within the front wheel steering angle rate limit.

[0249] • When the driver is operating the vehicle (over-control), the requested front wheel steering angle may not be achieved.

[0250] 3.2.2.6. Vehicle Mode Command

[0251] Request a change from manual mode to autonomous mode, or vice versa.

[0252] value

[0253]

[0254] Remark

[0255] N / A

[0256] 3.2.2.7. High Dynamic Commands

[0257] If ADK is to improve VP's braking response performance * The high dynamics command should be set to "high".

[0258] *Response time in VP based on the request from ADK

[0259] Value

[0260] Value Description Comment 0 No request 1 High 2-3 Reserved

[0261] Comment

[0262] N / A

[0263] 3.2.2.8. Propulsion direction state

[0264] Current shift state

[0265] Value

[0266]

[0267]

[0268] Comment

[0269] • If the VP is not aware of the current shift state, this output is set to "invalid value".

[0270] 3.2.2.9. Fixed state

[0271] Each fixed system state

[0272] Value

[0273] The following table shows the EPB and P-gear for the case of fixation.

[0274]

[0275] Comment

[0276] • N / A

[0277] 3.2.2.10. Stationary state

[0278] Stationary state

[0279] Value

[0280]

[0281]

[0282] Comment

[0283] • N / A

[0284] 3.2.2.11. Estimated coasting acceleration

[0285] Acceleration calculated in the VP taking into account the slope, the road load, etc. in the case of throttle closure.

[0286] Value

[0287] [Units: meters / second2 ]

[0288] NOTE

[0289] • When the propulsion direction state is "D", the acceleration in the forward direction shows a positive value.

[0290] • When the propulsion direction state is "R", the acceleration in the backward direction shows a positive value.

[0291] 3.2.2.12. Estimating maximum acceleration

[0292] The maximum acceleration calculated in VP considering the slope, road load, etc. in the case where the throttle is fully open.

[0293] Value

[0294] [Units: m / s 2 ]

[0295] NOTE

[0296] • When the propulsion direction state is "D", the acceleration in the forward direction shows a positive value.

[0297] • When the propulsion direction state is "R", the acceleration in the backward direction shows a positive value.

[0298] 3.2.2.13. Estimating maximum deceleration

[0299] The maximum deceleration calculated in VP considering the slope, road load, etc. in the case where the brake is requested as maximum in VP.

[0300] Value

[0301] [Units: m / s 2 ]

[0302] NOTE

[0303] • When the propulsion direction state is "D", the deceleration in the forward direction shows a negative value.

[0304] • When the propulsion direction state is "R", the deceleration in the backward direction shows a negative value.

[0305] 3.2.2.14. Front wheel steering angle

[0306] Value

[0307] Value Description Comment Minimum value Invalid value Other [Units: Radians]

[0308] NOTE

[0309] • Left is positive (+). Right is negative (-).

[0310] • This signal will show an invalid value until the VP is able to calculate the correct value or when the sensor is invalid / faulty.

[0311] 3.2.2.15. Front wheel steering angle rate

[0312] Front wheel steering angle rate

[0313] Value

[0314] Value Description Comment Minimum value Invalid value Other [Units: Radians]

[0315] Remark

[0316] • Left is positive (+). Right is negative (-).

[0317] • This signal will show an invalid value until the VP is able to calculate the correct value or when the front wheel steering angle shows a minimum value.

[0318] 3.2.2.16. Front wheel steering angle rate limit

[0319] Limit of front wheel steering angle rate

[0320] Value

[0321] [Units: rad / s]

[0322] Remark

[0323] This limit is calculated from the "vehicle speed - steering angle rate" map shown in Table 5 and Figure 11 A) At low speed or at standstill, a fixed value (0.751 [rad / s]) is used.

[0324] B) At higher speed, the 3.432 m / s 3 steering angle rate is calculated from the vehicle speed.

[0325]

[0326] Table 5. "Speed - Steering Angle Rate" map

[0327] Speed [km / h] 0.0 36.0 40.0 67.0 84.0 Front wheel steering angle rate limit [rad / s] 0.751 0.751 0.469 0.287 0.253

[0328] 3.2.2.17. Estimated maximum lateral acceleration

[0329] Value

[0330] [Units: m / s 2 ](fixed value: 3.432)

[0331] Remark

[0332] • Maximum lateral acceleration defined for the VP

[0333] ​3.2.2.18. Estimate maximum lateral jerk

[0334] Value

[0335] [Units: m / s 3 ](Fixed value: 3.432)

[0336] Remark

[0337] • Maximum lateral jerk defined for VP

[0338] 3.2.2.19. Accelerator pedal intervention

[0339] This signal shows whether the accelerator pedal is depressed (intervention) by the driver.

[0340] Value

[0341] Value Description Comment 0 Not depressed 1 Depressed 2 Exceeded autonomous acceleration

[0342] Remark

[0343] • This signal is set to "depressed" when the position of the accelerator pedal is above a defined threshold.

[0344] • This signal is set to "overshoot autonomous acceleration" when the requested acceleration calculated from the position of the accelerator pedal is higher than the requested acceleration from the ADS.

[0345] 3.2.2.20. Brake pedal intervention

[0346] This signal shows whether the brake pedal is depressed (intervention) by the driver.

[0347] Value

[0348] Value Description Comment 0 Not depressed 1 Depressed 2 Exceeded autonomous deceleration

[0349] Remark

[0350] • This signal is set to "depressed" when the position of the brake pedal is above a defined threshold.

[0351] • This signal is set to "overshoot autonomous deceleration" when the requested deceleration calculated from the position of the brake pedal is higher than the requested deceleration from the ADS.

[0352] 3.2.2.21. Steering wheel intervention

[0353] This signal shows whether the steering wheel is operated (intervention) by the driver.

[0354] Value

[0355] Value Description Comment 0 Not turned 1 ADS works in cooperation with the driver 2 Only through the human driver

[0356] Remark

[0357] • In "steering wheel intervention = 1", the EPS system drives the steering in cooperation with the human driver, taking into account the human driver's intention.

[0358] • In "steering wheel intervention = 2", the steering request from the ADS is not implemented, taking into account the human driver's intention. (The steering will be driven by the human driver.)

[0359] 3.2.2.22. Shift lever intervention

[0360] This signal shows whether the shift lever is controlled by the driver (intervention).

[0361] Value

[0362] Value Description Comment 0 Off 1 On Controlled (move to any gear)

[0363] Remark

[0364] • N / A

[0365] 3.2.2.23. Wheel speed pulse (front left), wheel speed pulse (front right), wheel speed pulse (rear left), wheel speed pulse (rear right)

[0366] Value

[0367]

[0368] Remark

[0369] • The pulse value is integrated at the moment of the pulse drop.

[0370] This wheel speed sensor outputs 96 pulses by a single rotation.

[0371] • The wheel speed pulse will be updated regardless of the wheel speed sensor being invalid / faulty.

[0372] • When "1" is subtracted from the pulse value showing "0", the value changes to "0x FF". When "1" is added to the pulse value showing "0x FF", the value changes to "0".

[0373] • Until the rotation direction is determined after the ECU is started, the pulse value will be increased when the rotation direction is "forward".

[0374] • When forward rotation is detected, the pulse value will be increased.

[0375] • When backward rotation is detected, the pulse value will be decreased.

[0376] 3.2.2.24. Wheel rotation direction (front left), wheel rotation direction (front right), wheel rotation direction (rear left), wheel rotation direction (rear right)

[0377] Value

[0378] Value Description Comment 0 Forward 1 Reverse 2 Reserved 3 Invalid value Sensor invalid.

[0379] Comment

[0380] • Until the rotation direction is determined after VP is opened, set "Forward".

[0381] 3.2.2.25. Travel direction

[0382] Direction of movement of the vehicle

[0383] Value

[0384] Value Description Comment 0 Forward 1 Reverse 2 Stationary 3 Undefined

[0385] Comment

[0386] • This signal shows "Stationary" when the four wheel speed values are "0" at a constant time.

[0387] • Can be "Undefined" when the shift is changed just after the vehicle starts.

[0388] 3.2.2.26. Vehicle speed

[0389] Estimated longitudinal speed of the vehicle

[0390] Value

[0391] Value Description Comment Maximum value in transmission Invalid value Sensor invalid. Other Speed [Units: m / s]

[0392] Comment

[0393] • The value of this signal is positive when both the forward direction and the backward direction.

[0394] 3.2.2.27. Longitudinal acceleration

[0395] Estimated longitudinal acceleration of the vehicle

[0396] Value

[0397] Value Description Comment Minimum value in transmission Invalid value Sensor invalid. Other acceleration [unit: m / s 2 ]]]>

[0398] Comment

[0399] • Acceleration (+) and deceleration (-) values based on the direction of the pulse direction status.

[0400] 3.2.2.28. Lateral acceleration

[0401] Lateral acceleration of the vehicle

[0402] Value

[0403] Value Description Comment Minimum value in transmission Invalid value Sensor invalid. Other acceleration [unit: m / s 2 ]]]>

[0404] NOTE

[0405] • Positive values indicate counterclockwise. Negative values indicate clockwise.

[0406] 3.2.2.29. Yaw rate

[0407] Sensor value of yaw rate

[0408] Value

[0409] Value Description Comment Minimum value in transmission Invalid value Sensor invalid. Other Yaw rate [Units: deg / s]

[0410] NOTE

[0411] • Positive values indicate counterclockwise. Negative values indicate clockwise.

[0412] 3.2.2.30. Slip detection

[0413] Detection of tire hydroplaning / swerve / slip

[0414] Value

[0415]

[0416]

[0417] NOTE

[0418] • This signal is judged as "slip" when any of the following systems have been activated.

[0419] - ABS (Anti-lock Braking System)

[0420] - TRC (Traction Control)

[0421] - VSC (Vehicle Stability Control)

[0422] - VDIM (Vehicle Dynamics Integrated Management)

[0423] 3.2.2.31. Vehicle mode status

[0424] Autonomous mode or manual mode

[0425] Value

[0426] Value Description Comment 0 Manual mode Mode starts in manual mode. 1 Autonomous mode

[0427] NOTE

[0428] • The initial state is set to "manual mode".

[0429] 3.2.2.32. Automation readiness

[0430] This signal indicates whether the vehicle is able to change to autonomous mode

[0431] Value

[0432] Value Description Comment 0 Not ready for autonomous mode 1 Ready for autonomous mode 3 Invalid State not yet determined.

[0433] Comment

[0434] • N / A

[0435] 3.2.2.33. Fault state of VP function in autonomous mode

[0436] This signal is used to show whether the VP function has certain fault modes when the vehicle is working in autonomous mode.

[0437] Value

[0438] Value Description Comment 0 No fault 1 Fault 3 Invalid State not yet determined.

[0439] Comment

[0440] • N / A

[0441] 3.2.2.34. PCS warning state

[0442] Value

[0443] Value Description Comment 0 Normal 1 Alert Request alert from PCS system 3 Not available

[0444] Comment

[0445] N / A

[0446] 3.2.2.35. PCS preparation state

[0447] Precharge state as preparation for PCS braking

[0448] Value

[0449] Value Description Comment 0 Normal 1 Start 3 Not available

[0450] Comment

[0451] • "Start" is the state in which the PCS prepares the brake actuator to shorten the delay from the deceleration request issued by the PCS.

[0452] • When the value becomes "Start" during the vehicle mode state = "Autonomous mode", the "ADS / PCS mediation state" shows "ADS".

[0453] 3.2.2.36. PCS braking / PCS braking hold state

[0454] Value

[0455] Value Description Comment 0 Normal 1 PCS braking 2 PCS brake hold 7 Not available

[0456] Comment

[0457] N / A

[0458] 3.2.2.37. ADS / PCS Mediation State

[0459] Mediation State

[0460] Value

[0461]

[0462]

[0463] Remark

[0464] • When the acceleration requested by the PCS system in the VP is less than the acceleration requested by the ADS, the state is set to "PCS".

[0465] • When the acceleration requested by the PCS system in the VP is greater than the acceleration requested by the ADS, the state is set to "ADS".

[0466] 3.3 APIs for Body Control

[0467] 3.3.1. List of APIs for Body Control

[0468] 3.3.1.1. Inputs

[0469] Table 6. Input APIs for vehicle body control

[0470]

[0471]

[0472] 3.3.1.2. Outputs

[0473] Table 7. Output APIs for vehicle body control

[0474]

[0475]

[0476] 3.3.2. Details of each API for Body Control

[0477] 3.3.2.1. Turn Signal Command

[0478] Request to control the turn signal

[0479] Value

[0480] Value Description Comment 0 Off 1 Right Right turn signal on 2 Left Left turn signal on 3 Reserved

[0481] Remark

[0482] • N / A

[0483] 3.3.2.2. Headlamp command

[0484] Request to control headlamps

[0485] Value

[0486] Value Description Comment 0 No request Keep current mode 1 Taillight mode request Side light mode 2 Headlight mode request Low beam mode 3 Autonomous mode request Autonomous mode 4 High beam mode request High beam mode 5 Off mode request 6-7 Reserved

[0487] Remarks

[0488] • This command is invalid when the combination switch headlamp mode = "off" or autonomous mode = "on".

[0489] • Driver operation takes precedence over this command.

[0490] 3.3.2.3. Hazard warning lights command

[0491] Request to control hazard warning lights

[0492] Value

[0493] Value Description Comment 0 No request 1 On

[0494] Remarks

[0495] • Driver operation takes precedence over this command.

[0496] • Hazard warning lights are turned on at the same time as the "on" command is received.

[0497] 3.3.2.4. Horn mode command

[0498] Request to select the mode of on and off times per cycle

[0499] Value

[0500] Value Description Comment 0 No request 1 Mode 1 On time: 250 ms Off time: 750 ms 2 Mode 2 On time: 500 ms Off time: 500 ms 3 Mode 3 Reserved 4 Mode 4 Reserved 5 Mode 5 Reserved 6 Mode 6 Reserved 7 Mode 7 Reserved

[0501] Remarks

[0502] N / A

[0503] 3.3.2.5. Horn cycle command

[0504] Request to select the number of on and off cycles

[0505] Value

[0506] 0-7 [-]

[0507] Remarks

[0508] N / A

[0509] 3.3.2.6. Continuous horn command

[0510] Request to turn horn on / off

[0511] value

[0512] Value Description Comment 0 No request 1 On

[0513] Remark

[0514] • This command has higher priority than the 3.3.2.4 Horn Mode and 3.3.2.5 Horn Cycle commands.

[0515] • The speaker will "turn on" simultaneously upon receiving the "turn on" command.

[0516] 3.3.2.7. Windshield wiper command

[0517] Request to control the windshield wipers

[0518] value

[0519]

[0520]

[0521] Remark

[0522] This command is valid when the windshield wiper mode of the combination switch is set to "Off" or "Auto".

[0523] • Driver input takes precedence over this command.

[0524] • Maintain windshield wiper mode while receiving the command.

[0525] • Erasing speed in fixed intermittent mode.

[0526] 3.3.2.8. Rear windshield wiper command

[0527] Request to control rear windshield wipers

[0528] value

[0529] Value Description Comment 0 Off mode request 1 Low frequency mode request 2 Reserved 3 Intermittent mode request 4-7 Reserved

[0530] Remark

[0531] • Driver input takes precedence over this command.

[0532] • Maintain windshield wiper mode while receiving the command.

[0533] • Erasing speed in fixed intermittent mode.

[0534] 3.3.2.9. HVAC (First Line) Operation Commands

[0535] Start / stop the first line of air conditioning control request

[0536] Value

[0537]

[0538]

[0539] Comment

[0540] • N / A

[0541] 3.3.2.10. HVAC (2nd row) operation command

[0542] Request to start / stop 2nd row air conditioning control

[0543] Value

[0544] Value Description Comment 0 No request 1 On 2 Off

[0545] Comment

[0546] • N / A

[0547] 3.3.2.11. Target temperature (left side first) command

[0548] Request to set target temperature in left front zone

[0549] Value

[0550] Value Description Comment 0 No request 60 to 85 [Units: Fahrenheit] (change by 1.0 Fahrenheit) Target temperature

[0551] Comment

[0552] • In case Celsius is used in VP, the value should be set in Celsius.

[0553] 3.3.2.12. Target temperature (right side first) command

[0554] Request to set target temperature in right front zone

[0555] Value

[0556] Value Description Comment 0 No request 60 to 85 [Units: Fahrenheit] (change by 1.0 Fahrenheit) Target temperature

[0557] Comment

[0558] • In case Celsius is used in VP, the value should be set in Celsius.

[0559] 3.3.2.13. Target temperature (left side second) command

[0560] Request to set target temperature in left rear zone

[0561] Value

[0562] Value Description Comment 0 No request 60 to 85 [Units: Degrees Fahrenheit] (in 1.0 degree Fahrenheit increments) Target Temperature

[0563] Remark

[0564] • When Celsius is used in VP, the value should be set to Celsius.

[0565] 3.3.2.14. Target Temperature (second from the right) command

[0566] Request to set the target temperature in the right rear region.

[0567] value

[0568] Value Description Comments 0 No Request 60 to 85 [Units: Degrees Fahrenheit] (in 1.0 degree Fahrenheit increments) Target Temperature

[0569] Remark

[0570] • When Celsius is used in VP, the value should be set to Celsius.

[0571] 3.3.2.15. HVAC Fan (First Line) Command

[0572] Request to set the fan level of the front AC

[0573] value

[0574] Value Description Comments 0 No Request 1 to 7 (max) Fan Level

[0575] Remark

[0576] • To switch the fan level to 0 (off), you should transmit "HVAC (first line) operation command = off".

[0577] • To switch the fan level to automatic, you should send the command "HVAC (first line) operation = turn on".

[0578] 3.3.2.16. HVAC Fan (Second Line) Command

[0579] Request for AC fan level after configuration

[0580] value

[0581] Value Description Comments 0 No Request 1 to 7 (max) Fan Level

[0582] Remark

[0583] • To switch the fan level to 0 (off), you should transmit "HVAC (second line) operation command = off".

[0584] • To switch the fan level to automatic, you should send the command "HVAC (second line) operation = turn on".

[0585] 3.3.2.17. Air Exit (First Line) Command

[0586] Request to set first row air outlet mode

[0587] Value

[0588] Value Description Comments 0 No Operation 1 Upper Body Air Flow Direction Upper Body 2 Upper Body / Feet Air Flow Direction Upper Body and Feet 3 Feet Air Flow Direction Feet 4 Feet / Defroster Air Flow Direction Feet and Windshield Defroster

[0589] Comment

[0590] N / A

[0591] 3.3.2.18. Air outlet (second row) command

[0592] Request to set second row air outlet mode

[0593] Value

[0594] Value Description Comments 0 No Operation 1 Upper Body Air Flow Direction Upper Body 2 Upper Body / Feet Air Flow Direction Upper Body and Feet 3 Feet Air Flow Direction Feet.

[0595] Comment

[0596] N / A

[0597] 3.3.2.19. Air cycle command

[0598] Request to set air cycle mode

[0599] Value

[0600]

[0601]

[0602] Comment

[0603] N / A

[0604] 3.3.2.20. AC mode command

[0605] Request to set AC mode

[0606] Value

[0607] Value Description Comments 0 No Request 1 On 2 Off

[0608] Comment

[0609] N / A

[0610] 3.3.2.21. Turn signal status

[0611] Value

[0612] Value Description Comments 0 Off 1 Left 2 Right 3 Invalid

[0613] Comment

[0614] N / A

[0615] 3.3.2.22. Headlamp status

[0616] Value

[0617] Value Description Comments 0 Off 1 Taillights 2 Low Beam 3 Reserved 4 High Beam 5-6 Reserved 7 Invalid

[0618] Comment

[0619] N / A

[0620] 3.3.2.23. Hazard warning lamp status

[0621] Value

[0622] Value Description Comments 0 Off 1 Hazard Warning 2 Reserved 3 Invalid

[0623] Comment

[0624] N / A

[0625] 3.3.2.24. Horn status

[0626] Value

[0627]

[0628]

[0629] Comment

[0630] The horn status is "1" even in the presence of an off period in some patterns, in case the 3.3.2.4 Horn mode command is initiated.

[0631] 3.3.2.25. Front windshield wiper status

[0632] Value

[0633] Value Description Comments 0 Off 1 Low Frequency 2 High Frequency 3 Intermittent 4-5 Reserved 6 Fault 7 Invalid

[0634] Comment

[0635] N / A

[0636] 3.3.2.26. Rear windshield wiper status

[0637] Value

[0638]

[0639]

[0640] Comment

[0641] N / A

[0642] 3.3.2.27. HVAC (first row) status

[0643] Value

[0644] Value Description Comments 0 Off 1 On

[0645] NOTE

[0646] N / A

[0647] 3.3.2.28. HVAC (second row) status

[0648] Value

[0649] Value Description Comments 0 Off 1 On

[0650] NOTE

[0651] N / A

[0652] 3.3.2.29. Target temperature (left-most first) status

[0653] Value

[0654]

[0655]

[0656] NOTE

[0657] • In cases where Celsius is used in the VP, the value should be set to Celsius.

[0658] 3.3.2.30. Target temperature (right-most first) status

[0659] Value

[0660] Value Description Comments 0 Low Temperature Coldest 60 to 85 [Units: Degrees Fahrenheit] Target Temperature 100 High Temperature Warmest FFh Unknown

[0661] NOTE

[0662] • In cases where Celsius is used in the VP, the value should be set to Celsius.

[0663] 3.3.2.31. Target temperature (left-most second) status

[0664] Value

[0665] Value Description Comments 0 Low Temperature Coldest 60 to 85 [Units: Degrees Fahrenheit] Target Temperature 100 High Temperature Warmest FFh Unknown

[0666] NOTE

[0667] • In cases where Celsius is used in the VP, the value should be set to Celsius.

[0668] 3.3.2.32. Target temperature (right-most second) status

[0669] Value

[0670] Value Description Comments 0 Low Temperature Coldest 60 to 85 [Units: Degrees Fahrenheit] Target Temperature 100 High Temperature Warmest FFh Unknown

[0671] NOTE

[0672] • In case Celsius is used in VP, the value shall be set in Celsius.

[0673] 3.3.2.33. HVAC fan (first row) status

[0674] Value

[0675] Value Description Comments 0 Off 1 to 7 Fan Level 8 Undefined

[0676] NOTE

[0677] • N / A

[0678] 3.3.2.34. HVAC fan (second row) status

[0679] Value

[0680] Value Description Comments 0 Off 1 to 7 Fan Level 8 Undefined

[0681] NOTE

[0682] • N / A

[0683] 3.3.2.35. Air outlet (first row) status

[0684] Value

[0685] Value Description Comments 0 All Off 1 Upper Body Air Flow Direction Upper Body 2 Upper Body / Feet Air Flow Direction Upper Body and Feet 3 Feet Air Flow Direction Feet. 4 Feet / Defroster Air Flow Direction Feet and Windshield Defroster is Operating 5 Defroster Windshield Defroster 7 Undefined

[0686] NOTE

[0687] • N / A

[0688] 3.3.2.36. Air outlet (second row) status

[0689] Value

[0690] Value Description Comments 0 All Off 1 Upper Body Air Flow Direction Upper Body 2 Upper Body / Feet Air Flow Direction Upper Body and Feet 3 Feet Air Flow Direction Feet. 7 Undefined

[0691] NOTE

[0692] • N / A

[0693] 3.3.2.37. Air circulation status

[0694] Value

[0695] Value Description Comments 0 Off 1 On

[0696] NOTE

[0697] • N / A

[0698] 3.3.2.38. AC mode status

[0699] Value

[0700] Value Description Comments 0 Off 1 On

[0701] Note

[0702] • N / A

[0703] 3.3.2.39. Seat Occupied (right first) status

[0704] Value

[0705] Value Description Comments 0 Unoccupied 1 Occupied 2 Undecided In the event the ignition is off or communication with the seat sensor is interrupted 3 Fault

[0706] Note

[0707] • This signal can be set to "Occupied" when there is luggage on the seat.

[0708] 3.3.2.40. Seat Belt (left first) status

[0709] Value

[0710] Value Description Comments 0 Buckled 1 Unbuckled 2 Undecided In the event the sensor is not working after the ignition is turned on 3 Switch Fault

[0711] Note

[0712] N / A

[0713] 3.3.2.41. Seat Belt (right first) status

[0714] Value

[0715] Value Description Comments 0 Buckled 1 Unbuckled 2 Undecided In the event the sensor is not working after the ignition is turned on 3 Switch Fault

[0716] Note

[0717] N / A

[0718] 3.3.2.42. Seat Belt (left second) status

[0719] Value

[0720]

[0721]

[0722] Note

[0723] • Sensor failure cannot be detected

[0724] 3.3.2.43. Seat Belt (right second) status

[0725] Value

[0726] Value Description Comments 0 Buckled 1 Unbuckled 2 Undecided In the event the sensor is not working after the ignition is turned on 3 Reserved

[0727] Note

[0728] • Cannot detect sensor failure

[0729] 3.3.2.44. Seat belt (left third) status

[0730] Value

[0731] Value Description Comments 0 Buckled 1 Unbuckled 2 Undecided In the event the sensor is not working after the ignition is turned on 3 Reserved

[0732] Remarks

[0733] • Cannot detect sensor failure

[0734] 3.3.2.45. Seat belt (center third) status

[0735] Value

[0736] Value Description Comments 0 Buckled 1 Unbuckled 2 Undecided In the event the sensor is not working after the ignition is turned on 3 Reserved

[0737] Remarks

[0738] • Cannot detect sensor failure

[0739] 3.3.2.46. Seat belt (right third) status

[0740] Value

[0741] Value Description Comments 0 Buckled 1 Unbuckled 2 Undecided In the event the sensor is not working after the ignition is turned on 3 Reserved

[0742] Remarks

[0743] • Cannot detect sensor failure

[0744] 3.4. APIs for power control

[0745] 3.4.1. List of APIs for power control

[0746] 3.4.1.1. Inputs

[0747] Table 8. Input APIs for Power Control

[0748] Signal Name Description Redundancy Power Mode Command Command to control the power mode of the VP N / A

[0749] 3.4.1.2. Outputs

[0750] Table 9. Output APIs for Power Control

[0751] Signal Name Description Redundancy Power Mode Status Status of the current power mode of the VP N / A

[0752] 3.4.2. Details of each API for power control

[0753] 3.4.2.1. Power mode command

[0754] Request to control power mode

[0755] Value

[0756] Value Description Comments 0 No Request 1 Sleep Turn the vehicle off 2 Wake Up Turn the VCIB on 3 Reserved Reserved for data expansion 4 Reserved Reserved for data expansion 5 Reserved Reserved for data expansion 6 Drive Start the vehicle

[0757] Remark

[0758] • After performing the sleep sequence, the VCIB will continuously transmit [Sleep] as the power mode state for 3000 [milliseconds]. And subsequently, the VCIB will shut down. Figure 12

[0759] [Sleep]

[0760] Vehicle power off state. In this mode, the main battery does not supply power to each system, and neither the VCIB nor other VP ECUs are activated.

[0761] [Wake up]

[0762] VCIB is woken up by the auxiliary battery. In this mode, ECUs other than the VCIB are not woken up, except for some body electronics ECUs.

[0763] [Drive mode]

[0764] Vehicle power on state. In this mode, the main battery supplies power to the entire VP, and all VP ECUs including the VCIB are woken up.

[0765] 3.4.2.2. Power mode state

[0766] Value

[0767] Value Description Comments 0 Reserved 1 Sleep 2 Wake Up 3 Reserved 4 Reserved 5 Reserved 6 Drive 7 Unknown This means that an unhealthy condition may occur.

[0768] Remark

[0769] • After performing the sleep sequence, the VCIB will continuously transmit [Sleep] as the power mode state for 3000 [milliseconds]. And subsequently, the VCIB will shut down.

[0770] • While the VCIB is transmitting [Sleep], the ADS will stop transmitting signals to the VCIB.

[0771] 3.5. API for fault notification

[0772] 3.5.1. List of APIs for fault notification

[0773] 3.5.1.1. Inputs

[0774] Table 10. Input APIs for Fault Notification

[0775] Signal name describe redundancy N / A N / A N / A

[0776] 3.5.1.2. Outputs

[0777] ​ Table 11. Output APIs for Fault Notification

[0778] Signal name describe redundancy Request for ADS operation Already applied Impact detection signal N / A Performance degradation of the braking system Already applied Performance degradation of propulsion system N / A Performance degradation of the shift control system N / A Performance degradation of fixed systems Already applied Deterioration of steering system performance Already applied Power system performance degradation Already applied Performance degradation of communication systems Already applied

[0779] 3.5.2. Details of each API for fault notification

[0780] 3.5.2.1. Request for ADS operation

[0781] Value

[0782] value describe Remark 0 No request 1 Maintenance required 2 Need to return to the garage 3 Need to stop immediately other reserve

[0783] Remark

[0784] • This signal shows the behavior expected from the ADS in accordance with the fault occurring in the VP.

[0785] 3.5.2.2. Impact detection signal

[0786] Value

[0787]

[0788]

[0789] Remark

[0790] • When the event of generating the impact detection, the signal is transmitted 50 times continuously every 100 [milliseconds]. If the impact detection state is changed before the signal transmission is completed, the signal of high priority is transmitted.

[0791] Priority: Impact detection > Normal

[0792] • The signal is transmitted for 5 seconds regardless of the normal response at the time of impact, because the request for disconnecting voltage should be transmitted to the vehicle damage judgment system for 5 seconds or less after the impact in the HV vehicle.

[0793] The transmission interval is 100 milliseconds within the fuel cut action delay allowance time (1 second), so that data can be transmitted 5 times or more.

[0794] In this case, instantaneous power failure should be considered.

[0795] 3.5.2.3. Performance degradation of brake system

[0796] Value

[0797] value describe Remark 0 normal — 1 Degradation detected —

[0798] Remark

[0799] • N / A

[0800] 3.5.2.4. Performance degradation of propulsion system

[0801] Value

[0802] value describe Remark 0 normal — 1 Degradation detected —

[0803] Comment

[0804] • N / A

[0805] 3.5.2.5. Performance degradation of shift control system

[0806] Value

[0807] value describe Remark 0 normal — 1 Degradation detected —

[0808] Comment

[0809] • N / A

[0810] 3.5.2.6. Performance degradation of fixed system

[0811] Value

[0812] value describe Remark 0 normal — 1 Degradation detected —

[0813] Comment

[0814] • N / A

[0815] 3.5.2.7. Performance degradation of steering system

[0816] Value

[0817] value describe Remark 0 normal — 1 Degradation detected —

[0818] Comment

[0819] • N / A

[0820] 3.5.2.8. Performance degradation of power supply system

[0821] Value

[0822] value describe Remark 0 normal — 1 Degradation detected —

[0823] Comment

[0824] • N / A

[0825] 3.5.2.9. Performance degradation of communication system

[0826] Value

[0827] value describe Remark 0 normal — 1 Degradation detected —

[0828] Comment

[0829] • N / A

[0830] 3.6. APIs for safety

[0831] 3.6.1. API List for Security

[0832] 3.6.1.1. Inputs

[0833] Table 12. Input APIs for Security

[0834]

[0835]

[0836] 3.6.1.2. Outputs

[0837] Table 13. Output APIs for Security

[0838]

[0839]

[0840] 3.6.2. Details for Each API for Security

[0841] 3.6.2.1. Door Lock (Front) Command, Door Lock (Rear) Command

[0842] Value

[0843] value describe Remark 0 No request 1 locking Not supported in Toyota VP 2 Unlock 3 reserve

[0844] Notes

[0845] • If ADK requests to unlock front side, then unlock both front doors.

[0846] • If ADK requests to unlock rear side, then unlock second row doors and trunk door.

[0847] • If ADK requests to lock any door, then "Central Door Lock Command" should be used.

[0848] (The functionality for locking individual locks is not supported in the Toyota VP.)

[0849] 3.6.2.2. Central Door Lock Command

[0850] Request to control all door locks

[0851] Value

[0852] value describe Remark 0 No request 1 Lock (All) 2 Unlock (all) 3 reserve

[0853] Notes

[0854] • N / A

[0855] 3.6.2.3. Device Authentication Signature First Word, Device Authentication Signature Second Word, Device Authentication Signature Third Word, Device Authentication Signature Fourth Word, Device Authentication Seed First Word, Device Authentication Seed Second Word

[0856] The Device Authentication Signature First Word is present in the first byte to the eighth byte of the signature.

[0857] The Device Authentication Signature Second Word is present in the ninth byte to the sixteenth byte of the signature.

[0858] The Device Authentication Signature Third Word is present in the seventeenth byte to the twenty-fourth byte of the signature.

[0859] The Device Authentication Signature Fourth Word is present in the twenty-fifth byte to the thirty-second byte of the signature.

[0860] The Device Authentication Seed First Word is present in the first byte to the eighth byte of the seed.

[0861] The Device Authentication Seed Second Word is present in the ninth byte to the sixteenth byte of the seed.

[0862] 3.6.2.4. Door Lock (Left Side First) Status

[0863] Value

[0864] value describe Remark 0 reserve 1 locking 2 Unlock 3 invalid

[0865] Note

[0866] • N / A

[0867] 3.6.2.5. Door Lock (Right Side First) Status

[0868] Value

[0869] value describe Remark 0 reserve 1 locking 2 Unlock 3 invalid

[0870] Note

[0871] • N / A

[0872] 3.6.2.6. Door Lock (Left Side Second) Status

[0873] Value

[0874] value describe Remark 0 reserve 1 locking 2 Unlock 3 invalid

[0875] Note

[0876] • N / A

[0877] 3.6.2.7. Door Lock (Right Side Second) Status

[0878] Value

[0879]

[0880]

[0881] NOTE

[0882] • N / A

[0883] 3.6.2.8. Door lock status of all doors

[0884] Value

[0885] value describe Remark 0 reserve 1 Lock all 2 Unlock any door 3 invalid

[0886] NOTE

[0887] • In case of any door unlocked, "Any door unlocked".

[0888] • In case of all doors locked, "All locked".

[0889] 3.6.2.9. Alarm system status

[0890] Value

[0891] value describe Remark 0 All Alert The alarm system is not activated. 1 alert The alarm system was activated but no alarm was issued. 2 start up The alarm system is activated, and the alarm beeps. 3 invalid

[0892] NOTE

[0893] • N / A

[0894] 3.6.2.9.1. Short range odometer

[0895] This counter is increased by the Freshness Value Management Master ECU in short ranges.

[0896] Value

[0897] 0 - FFFFh

[0898] NOTE

[0899] • This value is used to create a Freshness Value.

[0900] • For details, refer to Other Material [Specification of Toyota's MAC Module].

[0901] 3.6.2.9.2. Reset counter

[0902] This counter is increased periodically by the Freshness Value Management Master ECU.

[0903] Value

[0904] 0 - FFFFFh

[0905] NOTE

[0906] • This value is used to create a Freshness Value.

[0907] • For details, refer to Other Material [Specification of Toyota's MAC Module].

[0908] 3.6.2.10. Left first door open state

[0909] Current left first door open / close state of the vehicle platform

[0910] Value

[0911] value describe Remark 0 reserve 1 Open 2 closure 3 invalid

[0912] Remark

[0913] N / A

[0914] 3.6.2.11. Right first door open state

[0915] Current right first door open / close state

[0916] Value

[0917] value describe Remark 0 reserve 1 Open 2 closure 3 invalid

[0918] Remark

[0919] N / A

[0920] 3.6.2.12. Left second door open state

[0921] Current left second door open / close state

[0922] Value

[0923] value describe Remark 0 reserve 1 Open 2 closure 3 invalid

[0924] Remark

[0925] N / A

[0926] 3.6.2.13. Right second door open state

[0927] Current right second door open / close state

[0928] Value

[0929] value describe Remark 0 reserve 1 Open 2 closure 3 invalid

[0930] Remark

[0931] N / A

[0932] 3.6.2.14. Trunk state

[0933] Current trunk door open / close state

[0934] Value

[0935] value describe Remark 0 reserve 1 Open 2 closure 3 invalid

[0936] NOTE

[0937] N / A

[0938] 3.6.2.15. Hood open state

[0939] Current hood open / close state

[0940] Value

[0941]

[0942]

[0943] NOTE

[0944] N / A

[0945] 4. API guide to control Toyota vehicles

[0946] This section details the way to use the APIs for Toyota vehicles

[0947] 4.1. APIs for vehicle motion control

[0948] 4.1.1. List of APIs for vehicle motion control

[0949] The input and output APIs for vehicle motion control are shown in Tables 14 and 15, respectively. The usage guide for some APIs appears in the following sections as indicated in each table.

[0950] 4.1.1.1. Inputs

[0951] Table 14 Input APIs for Vehicle Motion Control

[0952]

[0953]

[0954] * Reaction time in VP according to the request from ADK

[0955] 4.1.1.2. Outputs

[0956] Table 15. Input APIs for Vehicle Motion Control

[0957]

[0958]

[0959] 4.1.2. API details for vehicle motion control

[0960] 4.1.2.1. Pulse direction command

[0961] For values and remarks see 3.2.2.1

[0962] Figure 13 Detailed shift sequence is shown.

[0963] The acceleration command requests first deceleration and the vehicle is parked. When the travel direction is set to "standstill", any gear can be requested by the propulsion direction command. (In Figure 13 , "D" -> "R").

[0964] A deceleration is required by the acceleration command until the shift is completed.

[0965] After the gear change, acceleration / deceleration can be selected based on the acceleration command.

[0966] While the vehicle mode status = autonomous mode, no shift lever operation by the driver is accepted.

[0967] 4.1.2.2. Immobilizer command

[0968] For values and remarks see 3.2.2.2.

[0969] Figure 14 How to activate / deactivate the immobilizer function is shown.

[0970] A deceleration is requested by the acceleration command to park the vehicle. When the vehicle speed is zero, the immobilizer function is activated by the immobilizer command = "applied". The acceleration command is set to deceleration until the immobilizer status is set to "applied".

[0971] When the immobilizer function is deactivated, the immobilizer command = "released" is required and at the same time the acceleration command is set to deceleration until the immobilizer status = "released" is confirmed.

[0972] After the immobilizer function is deactivated, acceleration / deceleration can be performed on the vehicle based on the acceleration command.

[0973] 4.1.2.3. Standstill command

[0974] For values and remarks see 3.2.2.3.

[0975] With the standstill command set to "applied", the brake hold function can be prepared for use and activated in the state that the vehicle is parked and the acceleration command is set to deceleration (<0). And then the standstill status changes to "applied". On the other hand, with the standstill command set to "released", the brake hold function is deactivated.

[0976] Figure 15 The stationary sequence is shown.

[0977] To make the vehicle stop, a deceleration is requested by the acceleration command.

[0978] When the vehicle is temporarily stopped, the driving direction is changed to "stationary". Even during the stationary state = "applied", a deceleration is requested by the acceleration command.

[0979] If the vehicle is to be made to move forward, the acceleration command is set to acceleration (> 0). Subsequently, the brake hold function is released and the vehicle is accelerated.

[0980] 4.1.2.4. Acceleration command

[0981] For values and remarks see 3.2.2.4.

[0982] The following shows what the vehicle does when the accelerator pedal is operated.

[0983] The maximum acceleration value of 1) calculated from the accelerator pedal travel, or 2) input from the ADK is selected in the case of operating the accelerator pedal. The ADK can see which value is selected by checking the intervention of the accelerator pedal.

[0984] The following shows what the vehicle does when the brake pedal is operated.

[0985] The deceleration value of the vehicle is the sum of 1) a value calculated from the brake pedal travel, and 2) a value requested by the ADK.

[0986] 4.1.2.5. Front wheel steering angle command

[0987] For values and remarks see 3.2.2.5.

[0988] The following shows how the front wheel steering angle command is used.

[0989] The front wheel steering angle command is set to the relative value of the front wheel steering angle.

[0990] For example, in the case of the front wheel steering angle = 0.1 [radians] and the vehicle is straight ahead;

[0991] If the ADK wants to go straight ahead, the front wheel steering angle command will be set to 0 + 0.1 = 0.1 [radians].

[0992] If the ADK requests steering -0.3 [radians], the front wheel steering angle command will be set to -0.3 + 0.1 = -0.2 [radians].

[0993] The following shows what the vehicle does when the driver operates the steering device.

[0994] The maximum value is picked from 1) the value calculated from the steering wheel operation by the driver, or 2) the value requested by the ADK.

[0995] Note that if the driver strongly operates the steering wheel, the front wheel steering angle command is not accepted. This condition can be found by the steering wheel flag intervention.

[0996] 4.1.2.6. Vehicle mode command

[0997] The state machine of the mode transition of the Autono-MaaS vehicle is shown in Figure 16

[0998] The explanation of each state is shown as follows.

[0999]

[1000] The explanation of each transition is shown as follows.

[1001]

[1002]

[1003] 4.2. API for body control

[1004] 4.2.1. List of API for body control

[1005] 4.2.1.1. Inputs

[1006] Table 16. Input APIs for Body Control

[1007]

[1008]

[1009] 4.2.1.2. Outputs

[1010] Table 17. Output APIs for Body Control

[1011]

[1012]

[1013]

[1014] 4.3. API for power control

[1015] 4.3.1. List of API for power control

[1016] 4.3.1.1. Inputs

[1017] Table 18. Input APIs for Power Control ​

[1018] Signal name describe redundancy User Guide Power mode command Commands to control the power mode of VP N / A —

[1019] 4.3.1.2. Output

[1020] Table 19. Output APIs for Power Control

[1021] Signal name describe redundancy User Guide Power mode status The current power mode status of VP N / A —

[1022] 4.4. API for Fault Notification

[1023] 4.4.1. API List for Fault Notification

[1024] 4.4.1.1. Input

[1025] Table 20. Input APIs for Fault Notification

[1026] Signal name describe redundancy User Guide N / A — — —

[1027] 4.4.1.2. Output

[1028] Table 21. Output APIs for Fault Notification

[1029] Signal name describe redundancy User Guide Request for ADS operation — Already applied — Impact detection signal — N / A — Performance degradation of the braking system — Already applied — Performance degradation of propulsion system — N / A — Performance degradation of the shift control system — N / A — Performance degradation of fixed systems — Already applied — Deterioration of steering system performance Already applied — Power system performance degradation Already applied — Performance degradation of communication systems Already applied —

[1030] 4.5. API for Security

[1031] 4.5.1. API List for Security

[1032] The input and output APIs for security are shown in Table 22 and Table 23, respectively. Usage guidelines for some APIs appear in the following sections as indicated in each table.

[1033] 4.5.1.1. Input

[1034] Table 22. Input APIs for Security

[1035]

[1036]

[1037] 4.5.1.2. Output

[1038] Table 23. Output APIs for Security

[1039]

[1040]

[1041] 4.5.2. API Detail Guidelines for Security

[1042] 4.5.2.1. Device Authentication Protocol

[1043] Device authentication is applied when the VCIB is started from the "sleep" mode.

[1044] After the authentication is successful, the VCIB can start communicating with the ADK.

[1045] In Figure 17 The authentication process is shown in the authentication process.

[1046] Authentication specification

[1047] project specification Notes Encryption Algorithm AES FIPS 197 key length 128-bit — Block cipher mode of operation CBC SP 800-38A Hash Algorithm SHA-256 FIPS 180-4 Seed length 128-bit — Signature length 256 bits —

[1048] While embodiments of the present disclosure have been described, it is to be understood that the embodiments disclosed herein are illustrative and not restrictive, and that the scope of the present disclosure is defined by the terms of the claims and intended to include any modifications within the scope and meaning of the terms of the claims.

Claims

1. An autonomous driving system configured to be mounted on a vehicle platform, the vehicle platform including a vehicle and a vehicle control interface box providing an interface between the vehicle and the autonomous driving system, the autonomous driving system comprising: Computing components; as well as The communication module communicates with the vehicle control interface box, wherein... The computing component is programmed to receive signals from the vehicle control interface box via the communication module, whereby the driver input on the indicator button is used to switch between starting and stopping the vehicle. In the absence of driver input on the button, the vehicle's power state is consistent with the power mode of the vehicle platform. When the driver input is provided, the power state is switched regardless of the power mode; and Upon receiving the signal, the computing component controls the power mode in a manner that makes the power mode consistent with the converted power state.

2. The autonomous driving system according to claim 1, wherein When the computing component receives the signal instructing the driver to input more than a specified number of times within a specified time period, the computing component determines that the button is held.

Citation Information

Patent Citations

  • Automatic operation controller

    JP2018132015A

  • Management system and management method

    JP2021157538A

  • Vehicle

    CN113200036A

  • Remote control device for vehicle

    JP1999348686A