Processing device, processing method, processing procedure, processing system
Patent Information
- Authority / Receiving Office
- CN · China
- Patent Type
- Patents(China)
- Current Assignee / Owner
- Filing Date
- 2022-01-25
- Publication Date
- 2026-08-11
AI Technical Summary
[0006]但是,在专利文献1所公开的技术中,设想在主车辆中难以确保自动驾驶中的驾驶精度的情况
[0049] Based on these first to ninth methods, in the main mobile unit of autonomous driving, feedback information is fed back from a remote center to the main mobile unit based on scenario information representing a scenario where the safety envelope, representing the safety of the functions intended according to the driving strategy, is violated. Thus, in the main mobile unit, the appropriateness of the judgment regarding the violation of the safety envelope can be identified based on the feedback information, which serves as a third-party assessment. Therefore, driving accuracy in autonomous driving can be ensured in the main mobile unit.
Smart Images

Figure CN116940971B_ABST
Abstract
Description
[0001] Cross-reference to related applications
[0002] This application is based on Japanese Patent Application No. 2021-15885, filed in Japan on February 3, 2021, by reference in its entirety to the contents of the base application. Technical Field
[0003] This disclosure relates to processing techniques for performing driving-related processes of a main mobile body. Background Technology
[0004] The technology disclosed in Patent Document 1 plans driving control related to the navigation actions of the main vehicle based on detection information related to the internal and external environment of the main vehicle. Therefore, when a potential accident liability is determined based on a safety model of the driving strategy and detection information, constraints are imposed on the driving control.
[0005] Patent Document 1: Japanese Patent No. 6708793
[0006] However, the technology disclosed in Patent Document 1 envisions a situation where it is difficult to ensure driving accuracy in autonomous driving within the main vehicle. Summary of the Invention
[0007] The present disclosure addresses the problem of providing a processing device for ensuring driving accuracy in autonomous driving. Another problem of the present disclosure is to provide a processing method for ensuring driving accuracy in autonomous driving. Yet another problem of the present disclosure is to provide a processing procedure for ensuring driving accuracy in autonomous driving. Still another problem of the present disclosure is to provide a processing system for ensuring driving accuracy in autonomous driving.
[0008] The technical means of this disclosure used to solve the problem will be described below.
[0009] The first aspect of this disclosure is a processing device including a processor for performing driving-related processes of a main mobile body capable of communicating with a remote center.
[0010] The processor is configured to perform the following processes:
[0011] Monitoring safety envelope violations in autonomous driving main moving body, where the aforementioned safety envelope violations are violations of the safety envelope that is set according to the driving strategy to ensure the safety of the intended functions;
[0012] If a security envelope violation is determined to have occurred, scenario information representing the scenario of the security envelope violation is generated and sent to the remote center; and
[0013] Retrieve feedback information based on scenario information from the remote center.
[0014] The second aspect of this disclosure is a processing method executed by a processor for performing driving-related processes of a primary mobile body capable of communicating with a remote center, comprising:
[0015] Monitoring safety envelope violations in autonomous driving main moving body, where the aforementioned safety envelope violations are violations of the safety envelope that is set according to the driving strategy to ensure the safety of the intended functions;
[0016] If a security envelope violation is determined to have occurred, scenario information representing the scenario of the security envelope violation is generated and sent to the remote center; and
[0017] Retrieve feedback information based on scenario information from the remote center.
[0018] The third aspect of this disclosure includes a storage medium containing a processor that executes commands for performing driving-related processes of a main mobile body capable of communicating with a remote center.
[0019] The command includes:
[0020] The processor monitors for violations of the safety envelope in the main moving body of the autonomous driving system. These violations are violations of the safety envelope that are set according to the driving strategy to ensure the safety of the intended functions.
[0021] When the processor determines that a security envelope violation has occurred, it generates scenario information representing the scenario of the security envelope violation and sends it to the remote center; and
[0022] This enables the processor to obtain feedback information based on scene information from a remote center.
[0023] The fourth aspect of this disclosure is a processing device including a processor, which performs driving-related processing of the main mobile body in a remote center capable of communicating with the main mobile body.
[0024] The processor is configured to perform the following processes:
[0025] Scene information representing a violation of the safety envelope is obtained from the autonomous driving main vehicle; the aforementioned safety envelope violation is a violation of the safety envelope of the intended function set according to the driving strategy; and
[0026] Generate feedback information based on scene information feedback and send it to the main mobile body.
[0027] The fifth aspect of this disclosure is a processing method executed by a processor to perform driving-related processing of the main mobile body in a remote center capable of communicating with the main mobile body, comprising:
[0028] Scene information representing a violation of the safety envelope is obtained from the autonomous driving main vehicle; the aforementioned safety envelope violation is a violation of the safety envelope of the intended function set according to the driving strategy; and
[0029] Generate feedback information based on scene information feedback and send it to the main mobile body.
[0030] The sixth aspect of this disclosure is stored in a storage medium for performing driving-related processing of the main mobile body in a remote center capable of communicating with the main mobile body, and includes a processor for executing commands.
[0031] The command includes:
[0032] The processor obtains scene information from the autonomous driving master vehicle representing a scenario where a safety envelope violation has occurred. This safety envelope violation is a violation of the safety envelope that defines the intended safety of the functions according to the driving strategy.
[0033] The processor generates feedback information based on scene information feedback, which is then sent to the main moving body.
[0034] The seventh aspect of this disclosure is a processing system comprising a first processor for the main mobile body and a second processor for the remote center, for performing driving-related processing of a main mobile body capable of communicating with a remote center.
[0035] The first processor is configured to perform the following processing:
[0036] Monitoring safety envelope violations in the autonomous driving main moving body, wherein the aforementioned safety envelope violations are violations of the safety envelope that is set according to the driving strategy to ensure the safety of the intended functions; and
[0037] If a security envelope violation is determined to have occurred, scenario information representing the scenario of the security envelope violation is generated and sent from the primary mobile unit to the remote center.
[0038] The second processor is configured to perform the following processing:
[0039] Generate feedback information based on scene information feedback to send from the remote center to the main mobile body.
[0040] The eighth aspect of this disclosure is a processing method executed through the cooperation of a first processor of the main mobile unit and a second processor of the remote center for performing driving-related processing of a main mobile unit capable of communicating with a remote center, comprising:
[0041] Monitoring safety envelope violations in autonomous driving main moving body, where the aforementioned safety envelope violations are violations of the safety envelope that is set according to the driving strategy to ensure the safety of the intended functions;
[0042] If a security envelope violation is determined to have occurred, scenario information representing the scenario of the security envelope violation is generated and sent from the primary mobile unit to the remote center; and
[0043] Generate feedback information based on scene information feedback to send from the remote center to the main mobile body.
[0044] The ninth aspect of this disclosure is for performing driving-related processing of a main mobile body capable of communicating with a remote center, and includes a processor storing at least one of a first storage medium of the main mobile body and a second storage medium of the remote center, and comprising commands that cause a first processor of the main mobile body and a second processor of the remote center to cooperate in execution.
[0045] The command instructs the first processor of the primary mobile unit and the second processor of the remote center to perform the following processing:
[0046] Monitoring safety envelope violations in autonomous driving main moving body, where the aforementioned safety envelope violations are violations of the safety envelope that is set according to the driving strategy to ensure the safety of the intended functions;
[0047] If a security envelope violation is determined to have occurred, scenario information representing the scenario of the security envelope violation is generated and sent from the primary mobile unit to the remote center; and
[0048] Generate feedback information based on scene information feedback to send from the remote center to the main mobile body.
[0049] Based on these first to ninth methods, in the main mobile unit of autonomous driving, feedback information is fed back from a remote center to the main mobile unit based on scenario information representing a scenario where the safety envelope, representing the safety of the functions intended according to the driving strategy, is violated. Thus, in the main mobile unit, the appropriateness of the judgment regarding the violation of the safety envelope can be identified based on the feedback information, which serves as a third-party assessment. Therefore, driving accuracy in autonomous driving can be ensured in the main mobile unit. Attached Figure Description
[0050] Figure 1 This is a descriptive table indicating the explanation of the terms used in this disclosure.
[0051] Figure 2 This is a descriptive table indicating the explanation of the terms used in this disclosure.
[0052] Figure 3 This is a descriptive table indicating the explanation of the terms used in this disclosure.
[0053] Figure 4 This is a table of definitions indicating the terms used in this disclosure.
[0054] Figure 5 This is a table of definitions indicating the terms used in this disclosure.
[0055] Figure 6 This is a block diagram illustrating the processing system of the first embodiment.
[0056] Figure 7 This is a schematic diagram illustrating the driving environment of the main vehicle used in the first embodiment.
[0057] Figure 8 This is a block diagram illustrating the processing system of the first embodiment.
[0058] Figure 9 This is a block diagram illustrating the processing system of the first embodiment.
[0059] Figure 10 This is a schematic diagram illustrating an example of a lane structure according to the first embodiment.
[0060] Figure 11 This is a flowchart illustrating the processing method of the first embodiment.
[0061] Figure 12 This is an explanatory table describing the processing method of the first embodiment.
[0062] Figure 13 This is a flowchart illustrating the processing method of the second embodiment.
[0063] Figure 14 This is a flowchart illustrating the processing method of the second embodiment.
[0064] Figure 15 This is a flowchart illustrating the processing method of the second embodiment.
[0065] Figure 16 This is a flowchart illustrating the processing method of the third embodiment.
[0066] Figure 17 This is a flowchart illustrating the processing method of the third embodiment.
[0067] Figure 18 This is a flowchart illustrating the processing method of the fourth embodiment.
[0068] Figure 19 This diagram illustrates the processing method of the fourth embodiment.
[0069] Figure 20 This is a block diagram representing the functional blocks of the fifth embodiment.
[0070] Figure 21 This is a flowchart illustrating the processing method of the fifth embodiment.
[0071] Figure 22 This is a block diagram illustrating the processing system of the sixth embodiment.
[0072] Figure 23 This is a block diagram illustrating the processing system of the seventh embodiment.
[0073] Figure 24 This is a block diagram illustrating the processing system of the eighth embodiment.
[0074] Figure 25 This is a block diagram illustrating the processing system of the eighth embodiment.
[0075] Figure 26 This is a block diagram illustrating the processing system of the eighth embodiment.
[0076] Figure 27 This is a block diagram illustrating the processing system of the ninth embodiment.
[0077] Figure 28 This is a block diagram illustrating the processing system of the tenth embodiment.
[0078] Figure 29 This is a block diagram illustrating a modified example of the processing system according to the tenth embodiment. Detailed Implementation
[0079] Hereinafter, several embodiments of the present disclosure will be described based on the accompanying drawings. Additionally, there are instances where repeated descriptions are omitted by using the same reference numerals for corresponding components in each embodiment. Furthermore, even when only a portion of the structure is described in each embodiment, the structures of other previously described embodiments can be applied to the remaining parts of that structure. Moreover, not only combinations of structures explicitly shown in the descriptions of each embodiment are possible, but structures of multiple embodiments can be partially combined with each other even if not explicitly shown, provided that such combinations do not present any particular obstacle.
[0080] Figures 1-5 A description of the terminology associated with the various embodiments of this disclosure is provided. However, the definitions of the terminology are not limited to... Figures 1-5 The description shown is intended to be interpreted in a way that does not depart from the spirit of this disclosure.
[0081] (First Implementation)
[0082] Figure 6 The processing system 1 of the first embodiment shown performs driving-related processing (hereinafter referred to as driving-related processing) of the main mobile body. The main mobile body that the processing system 1 is responsible for performing driving-related processing is... Figure 6 , Figure 7 The main vehicle 2 is shown. From the perspective of the main vehicle 2, the main vehicle 2 can be considered as its own vehicle.
[0083] In the main vehicle 2, autonomous driving is implemented. Autonomous driving is categorized based on the degree of occupant manual intervention during Dynamic Driving Tasks (DDTs). Autonomous driving can be achieved by the system performing autonomous driving control of all DDTs during operation, such as conditional driving automation, high driving automation, or full driving automation. Autonomous driving can also be achieved in high driving assistance controls, such as driver assistance or partial driving automation, where the driver, as an occupant, performs some or all of the DDTs. Autonomous driving can also be achieved through any one, combination, or switching between these autonomous driving controls and high driving assistance controls.
[0084] Mounted on main vehicle 2 Figure 6 , Figure 8 The sensor system 5, communication system 6, map database 7, and information display system 4 are shown. The sensor system 5 acquires sensor data that can be used by the processing system 1 by detecting the external and internal boundaries of the main vehicle 2. For this purpose, the sensor system 5 is composed of an external sensor 50 and an internal boundary sensor 52.
[0085] The external sensor 50 can detect objects present outside the host vehicle 2. The external sensor 50, of the object detection type, is at least one of the following: a camera, LiDAR (Light Detection and Ranging / Laser Imaging Detection and Ranging), lidar, millimeter-wave radar, and ultrasonic sonar. The external sensor 50 can also detect the state of the atmosphere outside the host vehicle 2. The external sensor 50, of the atmosphere detection type, is at least one of the following: an external air temperature sensor and a humidity sensor.
[0086] The interior boundary sensor 52 can detect specific physical quantities (hereinafter referred to as motion physical quantities) related to vehicle motion within the interior boundary of the main vehicle 2. The interior boundary sensor 52 of the physical quantity detection type is, for example, at least one of a speed sensor, an acceleration sensor, and a gyroscope sensor. The interior boundary sensor 52 can also detect the state of the occupants within the interior boundary of the main vehicle 2. The interior boundary sensor 52 of the occupant detection type is, for example, at least one of an actuator sensor, a driver state monitor, a bio-sensor, a seating sensor, and an in-vehicle equipment sensor. Here, in particular, as an actuator sensor, at least one of an accelerator sensor, a brake sensor, and a steering control sensor is used to detect the occupant's operating state related to the motion actuator of the main vehicle 2.
[0087] Communication system 6 acquires communication data that can be utilized by processing system 1 via wireless communication. Communication system 6 can receive positioning signals from GNSS (Global Navigation Satellite System) satellites located outside the main vehicle 2. Positioning-type communication system 6 may be, for example, a GNSS receiver. Communication system 6 can also transmit and receive communication signals with V2X systems located outside the main vehicle 2. V2X-type communication system 6 may be, for example, at least one of DSRC (Dedicated Short Range Communications) communicators and cellular V2X (C-V2X) communicators. Communication system 6 can also transmit and receive communication signals with terminals located inside the main vehicle 2. Terminal communication-type communication system 6 may be, for example, at least one of Bluetooth devices, Wi-Fi devices, and infrared communication devices.
[0088] like Figure 9 As shown, such a communication system 6 can be constructed with at least one communication device 6a as its main body. In this case, the communication device 6a is configured to include at least one dedicated computer. Furthermore, in this case, each dedicated computer constituting the communication device 6a has at least one memory 60 and a processor 62. Here, the memory 60 and processor 62 of the communication device 6a are based on the memory 10 and processor 12 of the processing device 1a described later.
[0089] Figure 6 , Figure 8 The map DB7 shown stores map data that can be used by the processing system 1. The map DB7 may include, for example, at least one non-transitory tangible storage medium such as semiconductor memory, magnetic media, and optical media. The map DB7 may also be a DB of a locator that estimates the self-state quantities of the main vehicle 2, including its own position. The map DB may also be a DB of a navigation unit that navigates the driving path of the main vehicle 2. The map DB7 can also be constructed by combining multiple types of DBs.
[0090] Map DB7 acquires and stores the latest map data, for example, through communication with an external center via a V2X-type communication system 6. The map data, representing the driving environment of the main vehicle 2, is digitized in two or three dimensions. As three-dimensional map data, high-precision map digital data can be used. The map data may include, for example, road data representing at least one of the following: the location coordinates, shape, and road surface condition of road structures. The map data may also include, for example, label data representing at least one of the following: the location coordinates and shape of road signs, road markings, and lane markings attached to the road. The label data included in the map data may also represent landmarks such as traffic signs, arrow markings, lane markings, stop lines, directional signs, landmark beacons, rectangular signs, commercial signs, or variations in road line patterns. The map data may also include, for example, structural data representing at least one of the following: the location coordinates and shape of buildings and traffic lights facing the road. The label data included in the map data may also represent landmarks such as streetlights, road edges, reflectors, utility poles, or the back of road signs.
[0091] The information prompting system 4 provides occupant information, including the driver, to the main vehicle 2. The information prompting system 4 comprises a visual prompting unit, an auditory prompting unit, and a skin-sensory prompting unit. The visual prompting unit provides the information by stimulating the occupant's vision. The visual prompting unit is, for example, at least one of a HUD (Head-up Display), MFD (Multi-Function Display), instrument cluster, navigation unit, and luminous unit. The auditory prompting unit provides the information by stimulating the occupant's hearing. The auditory prompting unit is, for example, at least one of a speaker, buzzer, and vibration unit. The skin-sensory prompting unit provides the information by stimulating the occupant's skin sensation. The skin sensation stimulated by the skin-sensory prompting unit includes, for example, at least one of touch, temperature, and wind. The skin-sensory prompting unit is, for example, at least one of a steering wheel vibration unit, a driver's seat vibration unit, a steering wheel reaction force unit, an accelerator pedal reaction force unit, a brake pedal reaction force unit, and an air conditioning unit.
[0092] like Figure 6As shown, the processing system 1 is constructed by including a processing device 1a of the main vehicle 2 and a processing device 8a of the remote center 8. Here, the processing system 1 may also be constructed by including at least the communication system 6 of the sensor system 5, communication system 6, map DB7, and information prompting system 4 in the main vehicle 2. The processing device 1a is connected to the sensor system 5, communication system 6, map DB7, and information prompting system 4, for example, via at least one of a LAN (Local Area Network), wiring harness, internal bus, and wireless communication line. The processing device 1a is constructed by including at least one dedicated computer. The dedicated computer constituting the processing device 1a may be an integrated ECU (Electronic Control Unit) that integrates the driving control of the main vehicle 2. The dedicated computer constituting the processing device 1a may also be a determination ECU that determines the DDT in the driving control of the main vehicle 2. The dedicated computer constituting the processing device 1a may also be a monitoring ECU that monitors the driving control of the main vehicle 2. The dedicated computer constituting the processing device 1a may also be an evaluation ECU that evaluates the driving control of the main vehicle 2.
[0093] The dedicated computer constituting processing device 1a can also be a navigation ECU that navigates the driving path of the main vehicle 2. The dedicated computer constituting processing device 1a can also be a locator ECU that estimates its own state variables, including the position of the main vehicle 2. The dedicated computer constituting processing device 1a can also be an actuator ECU that controls the motion actuators of the main vehicle 2. The dedicated computer constituting processing device 1a can also be an HCU (HMI (Human Machine Interface) Control Unit) that controls information prompts in the main vehicle 2. The dedicated computer constituting processing device 1a can also be, for example, at least one external computer, such as a mobile terminal capable of communication via communication system 6.
[0094] Each dedicated computer constituting the processing device 1a has at least one memory 10 and a processor 12. The memory 10 is a non-transitory tangible storage medium, such as semiconductor memory, magnetic media, and optical media, that non-transitory stores computer-readable programs and data. The processor 12 includes, for example, at least one of the following as its core: CPU (Central Processing Unit), GPU (Graphics Processing Unit), and RISC (Reduced Instruction Set Computer) – CPU.
[0095] The processor 12 executes multiple commands contained in a processing program stored as software in the memory 10. Thus, the processing device 1a constructs functional blocks for performing driving-related processing of the main vehicle 2. In this way, in the processing device 1a, the processing program stored in the memory 10 for performing driving-related processing of the main vehicle 2 constructs functional blocks by causing the processor 12 to execute multiple commands. Figure 8 As shown, the functional blocks constructed by the processing device 1a include a detection block 100, a planning block 120, a risk monitoring block 140, and a control block 160.
[0096] Detection block 100 acquires sensor data from the external sensor 50 and the internal sensor 52 of sensor system 5. Detection block 100 acquires communication data from communication system 6. Detection block 100 acquires map data from map DB7. Detection block 100 detects the internal and external environment of the main vehicle 2 by fusing these acquired data as inputs. Through the detection of the internal and external environment, detection block 100 generates detection information to be given to the subsequent planning block 120 and risk monitoring block 140. In this way, when generating detection information, detection block 100 acquires data from sensor system 5 and communication system 6, and identifies or understands the meaning of the acquired data. It can be said that it integrates the acquired data to grasp the overall situation including the external conditions of the main vehicle 2, its own situation in the external environment, and the internal conditions of the main vehicle 2. Detection block 100 can provide substantially the same detection information to planning block 120 and risk monitoring block 140. Detection block 100 can also provide different detection information to planning block 120 and risk monitoring block 140.
[0097] The detection information generated by detection block 100 describes the detected state for each scene in the driving environment of the main vehicle 2. Detection block 100 can generate object detection information by detecting objects in the external environment of the main vehicle 2, including road users, obstacles, and structures. Object detection information can represent at least one of the following: distance to the object, relative velocity of the object, relative acceleration of the object, and estimated state based on object tracking detection. Object detection information can also further represent the type identified or determined based on the detected object's state. Detection block 100 can also generate driving path detection information by detecting the current and future driving paths of the main vehicle 2. Driving path detection information can represent at least one of the following states: road surface, lane, road end, and free space.
[0098] Detection block 100 can also generate detection information for its own state quantity by estimating the location of the main vehicle 2's own state quantity, including its own position. Simultaneously with the detection information for its own state quantity, detection block 100 can also generate update information for map data related to the main vehicle 2's driving path and feed this update information back to map DB7. Detection block 100 can also generate detection information for identifiers associated with the main vehicle 2's driving path. Identification information for identifiers can, for example, represent the state of at least one of signs, lane markings, and traffic lights. Identification information for identifiers can also further represent traffic rules identified or determined based on the state of the identifiers. Detection block 100 can also generate detection information for weather conditions in each driving scenario of the main vehicle 2. Detection block 100 can also generate detection information for each driving scenario of the main vehicle 2 at that time.
[0099] Planning block 120 acquires detection information from detection block 100. Planning block 120 plans the driving control of the main vehicle 2 based on the acquired detection information. In the driving control plan, control commands related to the navigation actions of the main vehicle 2 and the driver's assistance actions are generated. That is, planning block 120 implements the DDT function, which generates control commands as motion control requests for the main vehicle 2. The control commands generated by planning block 120 may include control parameters for controlling the motion actuators of the main vehicle 2. The motion actuators that become the output objects of the control commands can include at least one of the following: an internal combustion engine, an electric motor, and powertrains, braking systems, and steering mechanisms.
[0100] Planning block 120 can also generate control commands in a manner suitable for the driving strategy by using a driving strategy and a safety model described according to its safety. The driving strategy upon which the so-called safety model is based may be defined, for example, by a vehicle-level safety strategy based on Safety of the Intended Functionality (SOTIF). In other words, the safety model is described by modeling the SOTIF based on a driving strategy that becomes the implementation of the vehicle-level safety strategy. Planning block 120 can also train the safety model by a machine learning algorithm that backpropagates the driving control results to the safety model. The safety model used for training may be, for example, at least one learning model such as deep learning based on neural networks such as DNN (Deep Neural Network) and reinforcement learning. Here, the so-called safety model can be defined either as the safety-related models themselves, which exhibit the safety-related aspects of driving actions based on assumptions that can be reasonably predicted for other road users, or as the models that constitute a part of the safety-related models. Such a safety model can be constructed, for example, in at least one of the following forms: a mathematical model that formulates vehicle-level safety, and a computer program that performs processing based on the mathematical model.
[0101] Planning block 120 can also plan the future path of the main vehicle 2 via driving control before generating control commands. To navigate the main vehicle 2 based on detection information, path planning can be performed, for example, through simulation or other computations. That is, planning block 120 can implement a DDT (Direct Targeting) function, which plans the path as a tactical action of the main vehicle 2. Planning block 120 can also further plan an appropriate track for the main vehicle 2 along the planned path based on the acquired detection information before generating control commands. That is, planning block 120 can also implement a DDT function, which plans the track of the main vehicle 2. The track planned by planning block 120 can, for example, specify at least one of the following as motion physical quantities related to the main vehicle 2, such as driving position, speed, acceleration, and yaw rate, in a time series. The time series track planning constructs a future driving scheme based on the navigation of the main vehicle 2. Planning block 120 can also generate a track based on a plan using a safety model. In this case, a cost function can be applied to the generated track, and the safety model can be trained using a machine learning algorithm based on the result of this calculation.
[0102] Planning block 120 can also plan adjustments to the autonomous driving level in the master vehicle 2 based on the acquired detection information. Adjustments to the autonomous driving level can also include handover between autonomous and manual driving. Based on the settings of the Operational Design Domain (ODD) for executing autonomous driving, the handover between autonomous and manual driving can be implemented in scenarios accompanying entry into or exit from that ODD. In the exit scenario from the ODD, i.e., the handover scenario from autonomous to manual driving, an unreasonable situation deemed to pose an unreasonable risk based on a safety model can be cited as a use case. In this use case, planning block 120 can also plan a DDT rollback where the driver, acting as a rollback candidate, performs a minimum-risk operation on the master vehicle 2 to move it to a minimum-risk state.
[0103] The adjustment of the autonomous driving level may also include the downgrading of the primary vehicle 2. In the downgrading scenario, an unreasonable situation can be cited as an example, where a safety model determines that there is an unreasonable risk due to the handover to manual driving. In this case, planning block 120 may also plan a DDT rollback to move the primary vehicle 2 to the minimum risk state through autonomous driving and autonomous stopping. The DDT rollback to move the primary vehicle 2 to the minimum risk state can be implemented not only in adjustments to reduce the autonomous driving level, but also in adjustments to maintain the autonomous driving level and downgrade it, such as in MRM (Minimum Risk Maneuver). In the DDT rollback to move the primary vehicle 2 to the minimum risk state, the visibility of the transition situation can be increased, for example, through at least one of lighting, horn sounds, signals, and gestures.
[0104] Risk monitoring block 140 acquires detection information from detection block 100. Based on the acquired detection information, risk monitoring block 140 monitors the main vehicle 2 and other moving targets 3 in each scenario (see reference). Figure 7 Risk monitoring block 140 performs risk monitoring based on detection information in a time-series manner to ensure the SOTIF of the main vehicle 2 for the target moving body 3. The target moving body 3 envisioned in the risk monitoring is other road users existing in the driving environment of the main vehicle 2. The target moving body 3 includes, for example, non-vulnerable road users such as cars, trucks, motorcycles, and bicycles, and vulnerable road users such as pedestrians. Animals may also be included in the target moving body 3.
[0105] The risk monitoring block 140 sets a safety envelope in the main vehicle 2 to ensure SOTIF (Safety in Context of Context) based on the detection information acquired for each scenario, such as a vehicle-level safety strategy. The risk monitoring block 140 can also use a safety model based on the aforementioned driving strategy to set a safety envelope between the main vehicle 2 and the target moving body 3. The safety model used to set the safety envelope can also be designed to comply with accident liability rules to avoid potential accident liability caused by unreasonable risks or misuse by road users. In other words, the safety model can also be designed to ensure that the main vehicle 2 complies with accident liability rules based on the driving strategy. Examples of such a safety model include, for instance, the responsibility-sensitive safety model disclosed in Patent Document 1.
[0106] The so-called safety envelope here can also be defined as a set of constraints and conditions designed to constrain or control the system's actions in order to maintain operation within an acceptable level of risk. Such a safety envelope can serve as a margin in the physical basis surrounding each road user, including the main vehicle 2 and the target moving body 3, for example, by setting a margin related to at least one of the following physical quantities: distance, speed, and acceleration. For example, in setting the safety envelope, a safe distance can be envisioned based on a safety model for the main vehicle 2 and the target moving body 3, assumed to be based on a driving strategy, and according to a profile related to at least one physical quantity. The safe distance defines the boundary of the physical basis margin around the main vehicle 2 for the predicted motion of the target moving body 3. The reaction time of the road user until an appropriate response is performed can also be considered when envisioning the safe distance. The safe distance can also be envisioned to comply with accident liability rules. For example, in scenarios with lane structures such as lanes, a safe distance can be calculated to avoid the risk of rear-end collisions and frontal collisions longitudinally to the main vehicle 2, and a safe distance can be calculated to avoid the risk of side collisions laterally to the main vehicle 2. On the other hand, in scenarios where there is no lane structure, the safe distance to avoid the risk of track collision in any direction of the main vehicle 2 can be calculated.
[0107] The risk monitoring block 140 can also determine the relative motion between the main vehicle 2 and the target moving body 3 in each scenario before setting the aforementioned safety envelope. For example, in scenarios with lane structures such as lanes, it can determine the risk of rear-end collisions and frontal collisions in the longitudinal direction, and the risk of side collisions in the lateral direction. In these longitudinal and lateral situation determinations, the state variables related to the main vehicle 2 and the target moving body 3 can be transformed into a coordinate system based on straight lanes. On the other hand, in scenarios without lane structures, it can determine the risk of collisions with the main vehicle 2 in any direction. Furthermore, for the above situation determination function, at least a portion can be performed by the detection block 100, and the situation determination results can be given to the risk monitoring block 140 as detection information.
[0108] The risk monitoring block 140 performs a safety determination between the main vehicle 2 and the target moving body 3 based on a set safety envelope and the detection information acquired for each scenario. Specifically, the risk monitoring block 140 determines safety by testing whether there is a violation of the safety envelope in the driving scenario between the main vehicle 2 and the target moving body 3, as interpreted based on the detection information. If a safe distance is assumed in the setting of the safety envelope, a determination of no safety envelope violation can be made if the actual distance between the main vehicle 2 and the target moving body 3 exceeds this safe distance. Conversely, a determination of a safety envelope violation can be made if the actual distance between the main vehicle 2 and the target moving body 3 is below the safe distance.
[0109] In the event of a determination that a safety envelope has been violated, the risk monitoring block 140 can calculate, through simulation, a reasonable plan for providing the appropriate action to the master vehicle 2 as a suitable response. In simulating the reasonable plan, the actions to be taken at each transition state can be estimated as constraints on the master vehicle 2 (described in detail later). In setting the actions, a limit value can be calculated on at least one assumed physical quantity of motion given to the master vehicle 2, thus limiting that physical quantity of motion as a constraint on the master vehicle 2.
[0110] The risk monitoring block 140 can also directly calculate the limit value for compliance with accident liability rules based on the profile related to at least one motion physical quantity, using a safety model for the main vehicle 2 and the target moving body 3, which is based on a driving strategy. It can be said that the calculation of the direct limit value is itself both the setting of the safety envelope and the setting of constraints on driving control. Therefore, it is possible to determine that there is no violation of the safety envelope if a real value closer to the safe side than the limit value is detected. On the other hand, it is possible to determine that there is a violation of the safety envelope if a real value deviates from the limit value.
[0111] The risk monitoring block 140 may store at least one of the following evidence information in the memory 10: detection information used to set the security envelope, determination information indicating the determination result of the security envelope, detection information affecting the determination result, and simulation scheme. The memory 10 storing the evidence information may be installed inside the main vehicle 2, or, for example, in an external center outside the main vehicle 2, depending on the type of dedicated computer constituting the processing device 1a. The evidence information may be stored unencrypted, encrypted, or hashed before storage. At least the storage of evidence information is performed when a security envelope violation is determined. Of course, the storage of evidence information may also be performed when no security envelope violation is determined. Evidence information indicating no security envelope violation can be effectively used as a lagging indicator at the time of storage and can also be effectively used as a forward indicator for the future.
[0112] Control block 160 obtains control commands from planning block 120. Control block 160 obtains decision information related to the safety envelope from risk monitoring block 140. That is, control block 160 implements the DDT function to control the movement of the main vehicle 2. If control block 160 obtains decision information indicating no safety envelope violation, it executes the planned driving control of the main vehicle 2 according to the control commands.
[0113] In contrast, when control block 160 receives a determination that there is a violation of the safety envelope, it imposes constraints on the driving control of the planned main vehicle 2 based on the determination information and the driving strategy. These constraints on driving control can be functional restrictions, degraded constraints, or different constraints. Driving control is constrained by limiting control commands. If a reasonable scenario is simulated by risk monitoring block 140, control block 160 can also limit control commands based on that scenario. In this case, if a limit value is set for the motion physical quantities of the main vehicle 2, the control parameters of the motion actuators included in the control commands can also be modified based on that limit value.
[0114] In target moving body 3 Figure 7The target vehicle 3a shown can also be equipped with the processing device 1a, sensor system 5, communication system 6, map DB7, and information prompting system 4 of the main vehicle 2. In this case, from the perspective of the remote center 8, the main vehicle 2 can be considered as the "first main mobile body," and the target vehicle 3a, which becomes another main vehicle 2, can be considered as the "second main mobile body." Furthermore, in this case, the processing system 1 can also be constructed by including at least the communication system 6 from the sensor system 5, communication system 6, map DB7, and information prompting system 4 of the target vehicle 3a.
[0115] like Figure 6 The remote center 8 shown is primarily constructed with at least one of the following: a cloud server and an edge server, which together with the processing unit 8a has a communication system 8b. The communication system 8b forms at least a part of a V2X system capable of communicating with the communication system 6 of the host vehicle 2. The communication system 8b can also communicate with the communication system 6 installed on the target vehicle 3a. The processing unit 8a is connected to the communication system 8b via at least one of a wired communication line and a wireless communication line. The processing unit 8a includes at least one dedicated computer. The processing unit 8a can perform output control processing, such as displaying information related to road users including the host vehicle 2 who can communicate via the communication system 8b, to the operator of the remote center 8. The processing unit 8a can also perform input control processing, such as receiving feedback from the operator of the remote center 8 to the communicable road users.
[0116] Each dedicated computer constituting the processing device 8a has at least one memory 80 and a processor 82. The memory 80 and processor 82 of the processing device 8a are relative to the memory 10 and processor 12 of the processing device 1a. The processor 82 executes multiple commands contained in a processing program stored as software in the memory 80. Thus, the processing device 8a constructs functional blocks for performing driving-related processing of the main vehicle 2 in cooperation with the processing device 1a. The processing device 8a may also construct functional blocks for performing driving-related processing of the target vehicle 3a in cooperation with the processing device 1a in the case of the target vehicle 3a.
[0117] In this way, in processing device 8a, the processing program stored in memory 80 for performing driving-related processing of the main vehicle 2, etc., constructs a functional block by causing processor 82 to execute multiple commands. From the perspective of the processing system 1 as a whole, this can be considered as the processing programs stored in memory 10 and 80 respectively constructing functional blocks of each device 1a and 8a by causing processors 12 and 82 to cooperate in executing commands. At this time, in the case where the processing system 1 is constructed by including a communication device 6a constituting the communication system 6 in the main vehicle 2, etc., the processing programs stored in memory 10, 80, and 60 respectively can also cause processors 12, 62, and 82 to cooperate in executing commands.
[0118] On the other hand, from the perspective of the processing system 1 as a whole, the processors 12 and 82 can also cooperate in executing commands by the processing program stored in one of the memories 10 and 80 (especially the memory 80 of the cloud server) to construct the functional blocks of each device 1a and 8a. At this time, in the case where the processing system 1 is constructed by including the communication device 6a constituting the communication system 6 in the main vehicle 2, etc., the processors 12, 62, and 82 can also cooperate in executing commands by the processing program stored in one of the memories 10 and 80 and the processing program stored in the memory 60.
[0119] In either case, the processor 12 and memory 10 of the main vehicle 2 are respectively equivalent to the "first processor" and the "first storage medium", and the processor 82 and memory 80 of the remote center 8 are respectively equivalent to the "second processor" and the "second storage medium".
[0120] like Figure 9 As shown, the functional block constructed by the processing device 8a includes a central management block 880. The central management block 880 manages the traffic environment where multiple road users, including the main vehicle 2, exist. The central management block 880 can also acquire scene information related to the driving scenarios of the communicable road users in real time through the communication system 8b and utilize it for traffic environment management. The central management block 880 can also send feedback information to the communicable road users in real time or afterward through the communication system 8b in order to manage the traffic environment based on scene information. Figure 9 This illustrates an example of the exchange of necessary information between a central management block 880 constructed by the processing unit 8a of the remote center 8 and a risk monitoring block 140 constructed by the processing unit 1a of the main vehicle 2 via communication systems 8b and 6.
[0121] The details of the first embodiment will be described below.
[0122] exist Figure 10In the first embodiment shown, a lane structure Ls is envisioned that divides the lanes. The lane structure Ls uses the direction of lane extension as the longitudinal direction to restrict the movement of the main vehicle 2 and the target moving body 3. The lane structure Ls also uses the width direction or arrangement direction of the lanes as the lateral direction to restrict the movement of the main vehicle 2 and the target moving body 3.
[0123] For example, when the target moving body 3 is the target vehicle 3a, the driving strategy between the main vehicle 2 and the target moving body 3 in the lane structure Ls is specified as follows (1) to (5). In addition, the forward direction based on the main vehicle 2 refers to, for example, the direction of travel on the turning circle at the current steering angle of the main vehicle 2, the direction of travel on a straight line passing through the center of gravity of the vehicle that is orthogonal to the axle of the main vehicle 2, or the direction of travel on the axis from the front camera module in the sensor system 5 of the main vehicle 2 to the FOE (Focus of Expansion) of the camera.
[0124] (1) A vehicle does not rear-end a vehicle traveling in front.
[0125] (2) Vehicles shall not forcibly insert themselves between other vehicles.
[0126] (3) Even when a vehicle has priority, it shall give way to other vehicles as appropriate.
[0127] (4) Drive carefully when the vehicle is in a position with poor visibility.
[0128] (5) Regardless of whether the vehicle is at fault or the fault lies with the other party, if the accident can be prevented by the vehicle itself, then reasonable action should be taken.
[0129] Based on the driving strategy model, and considering the safety model for modeling SOTIF, the actions of road users that would not lead to unreasonable situations are considered as appropriate and reasonable actions to be taken. Unreasonable situations between the main vehicle 2 and the target moving body 3 in the lane structure Ls refer to frontal collisions, rear-end collisions, and side collisions. When the target moving body 3 relative to the main vehicle 2 is the target vehicle 3a, reasonable actions in the event of a frontal collision include, for example, braking on vehicles traveling in the wrong direction. Similarly, when the target moving body 3 relative to the main vehicle 2 is the target vehicle 3a, reasonable actions in the event of a rear-end collision include, for example, not applying excessive emergency braking to vehicles traveling in front, and, given this situation, avoiding rear-end collisions with vehicles traveling behind. And, when the target moving body 3 relative to the main vehicle 2 is the target vehicle 3a, reasonable actions in the event of a side collision include, for example, steering parallel vehicles in opposite directions toward their respective separation directions. Regardless of whether it is a curved lane structure Ls or an uneven lane structure Ls, when assuming reasonable action, the state variables related to the main vehicle 2 and the target moving body 3 are converted into a longitudinal and lateral orthogonal coordinate system defined by the assumed straight and planar lane structure Ls.
[0130] A safety model can be designed based on accident liability rules where the moving body that fails to take reasonable action bears responsibility for the accident. Under the accident liability rules in the lane structure Ls, the safety model used to monitor the risk between the main vehicle 2 and the target moving body 3 sets a safety envelope for the main vehicle 2 to avoid potential accident liability through reasonable action. Therefore, the risk monitoring block 140 of the processing device 1a, under normal overall conditions, determines whether there is a violation of the safety envelope by comparing the safe distance based on the safety model with the actual distance between the main vehicle 2 and the target moving body 3 for each driving scenario. In the case of a violation of the safety envelope, the risk monitoring block 140 simulates a scheme for giving reasonable action to the main vehicle 2. Through simulation, the risk monitoring block 140 sets, for example, a limit value related to at least one of speed and acceleration, as a constraint on driving control in the control block 160.
[0131] In the first embodiment, execution is carried out through the cooperation of multiple functional blocks. Figure 11The flowchart shown illustrates a processing method for performing driving-related processing. Regardless of whether it is autonomous driving or manual driving as planned by planning block 120, the processing method of the first embodiment is repeatedly executed without interference from one party to the other. Here, each "S" in the processing method represents multiple steps executed by multiple commands contained in the processing program of at least one of the memories stored in memories 10 and 80. Furthermore, when the processing system 1 is constructed by including a communication device 6a constituting the communication system 6 in the main vehicle 2, etc., each "S" in the processing method represents not only the processing program of at least one of the memories stored in memories 10 and 80, but also multiple steps executed by multiple commands contained in the processing program stored in memory 60.
[0132] In S100 of the processing method, the risk monitoring block 140 monitors for safety envelope violations related to the SOTIF safety envelope set according to the driving strategy in a master vehicle 2 selected by the planning block 120 during both autonomous and manual driving. If the risk monitoring block 140 determines in S100 that no safety envelope violation has occurred (i.e., there is no safety envelope violation), this phase of the processing method ends. Conversely, if the risk monitoring block 140 determines in S100 that a safety envelope violation has occurred (i.e., there is a safety envelope violation), the processing method proceeds to S110.
[0133] In processing step S110, risk monitoring block 140 generates scenario information Is representing a safety envelope violation scenario, i.e., a violation scenario, occurring in the selected autonomous or manual driving master vehicle 2, and sends it from master vehicle 2 to remote center 8 via communication system 6. Scenario information Is can be information at the time of the safety envelope violation. From the viewpoint of EDR (Event Data Recorder), scenario information Is can also include information before and after the time of the safety envelope violation. Scenario information Is includes status information Ia generated based on detection information from detection block 100 and representing the state of the safety envelope violation.
[0134] Status information Ia, for example, represents Figure 12The actual value of at least one of the speed and acceleration / deceleration of the main vehicle 2 shown is used as a motion physical quantity that violates the safety envelope limit value set by the risk monitoring block 140. The motion physical quantity represented by the condition information Ia also considers the longitudinal and lateral differences on the lane structure Ls. Condition information Ia may, for example, represent at least one of the following: its own state quantity including position (i.e., position estimate), vector, cumulative travel distance, cumulative travel time, load weight, tire condition including wear, maintenance status, operating status of the driving actuator, and vehicle type, as the state of the main vehicle 2 in the violation scenario. Condition information Ia may also include images or videos captured by a camera acting as an external sensor 50 within the main vehicle 2.
[0135] The status information Ia may represent, for example, at least one of path, track, control parameters, and autonomous driving level (including the case where manual driving is set to level 0), as the planning status in the planning block 120 of the master vehicle 2 under the violation scenario. The planning status of the path represented by the status information Ia may include, for example, planning results related to at least one of the route to the destination and the driving lane in the multiple lane structure. The status information Ia in manual driving may represent, for example, at least one of the driving trend including driving score before the violation scenario, driving distance history, driving time history, safety envelope violation history, and physical state, as the state of the driver operating the master vehicle 2 under the violation scenario.
[0136] The situation information Ia may represent, for example, at least one of position, distance, velocity, acceleration / deceleration, relative velocity, relative acceleration, and estimated state including these vectors, as well as type, as the state of the target moving body 3 in the violation scenario. If the target moving body 3 is a vulnerable road user, the situation information Ia may also represent at least one of the following: age and physical condition of a person who is at least a part of that road user.
[0137] Status information Ia can also represent risk type, for example, as the relative state between the main vehicle 2 and the target moving body 3. The risk type represented by status information Ia can be found in a safety model where the safety envelope is defined as the criterion for determining a violation of the safety envelope. Figure 12Such conditions include, for example, rear-end collision risk, frontal collision risk, side collision risk, intersection risk, blind spot risk, and at least one of these detailed conditions. Condition information Ia can represent, for example, at least one of the following road conditions: traffic rules, signs, road structure, location, section, road surface condition, light / darkness, construction conditions, traffic congestion, the presence of obstacles including falling objects, roadside structures, and blind spots caused by such structures or types of moving objects, as a violation scenario. Here, "type of moving object" refers to the distinction between vehicles such as cars, trucks, and buses. Condition information Ia, representing road conditions, can include map data associated with the road conditions. Condition information Ia can also represent at least one of the following: the time of the violation scenario, the time period of the violation scenario including day / night differences, and the weather conditions (i.e., weather) of the violation scenario.
[0138] In S110, the risk monitoring block 140 can also determine factors that violate the security envelope. In this case, the scenario information Is can include factor information Ib representing that factor. Figure 12 As shown, factor information Ib can be generated for at least one party (i.e., self-responsibility and other-responsibility) in the main vehicle 2 and the target moving body 3 that is determined to have violated the safety envelope. Factor information Ib can be generated to identify miscontrol in automated driving or misjudgment in manual driving as a factor that is judged to cause an unreasonable risk of violating the safety envelope, for example, operation timing, inter-vehicle distance, traffic priority, speed, etc. Factor information Ib can also be generated to identify driving strategies not followed due to safety envelope violations in automated driving or manual driving as a factor that is judged to cause an unreasonable risk of violating the safety envelope. Furthermore, Figure 12 The results of determining the driving strategy that was violated in the driving strategy of the above-mentioned numbered (1) to (5) when the target moving body 3 is the target vehicle 3a are illustrated.
[0139] In S110, the scene information Is generated by the risk monitoring block 140, after authentication of the user ID containing the authentication key by the remote center 8, can be uploaded to the remote center 8 according to the transmission control in the communication system 6 (processor 62 of the communication device 6a) operated by the risk monitoring block 140. In S110, the risk monitoring block 140 can also store the generated scene information Is in the memory 10. The scene information Is can be stored in the memory 10 in association with a timestamp representing the generation time of the risk monitoring block 140, thereby accumulating scene information Is at multiple times in the memory 10. When storing the scene information Is in the memory 10, it can also be encrypted or hashed. If the stored scene information Is is hashed, the hash value constituting part of the scene information Is can also be sent to the remote center 8.
[0140] In the case of target vehicle 3a, which is assumed to be another master vehicle 2 from the perspective of remote center 8, in S110, risk monitoring block 140 can also perform the generation of scenario information Is and the transmission control from target vehicle 3a through communication system 6. In this hypothetical case, scenario information Is becomes a scenario representing a violation of the safety envelope that occurs in target vehicle 3a, i.e., information about the violation scenario.
[0141] exist Figure 11 In S120 of the processing method shown, the central management block 880 obtains scene information Is uploaded from the risk monitoring block 140 from the selected master vehicle 2 (either autonomous or manual driving) via the communication system 8b. In the case of the target vehicle 3a, which is conceived as another master vehicle 2 from the perspective of the remote center 8, the central management block 880 also obtains scene information Is from the target vehicle 3a via the communication system 8b in S120.
[0142] In S120, the central management block 880 can also store the acquired scene information Is in the memory 80. The scene information Is can also be stored in the memory 80 in association with a timestamp representing the generation time of the risk monitoring block 140 or the acquisition time of the central management block 880, thereby accumulating scene information Is at multiple times in the memory 80. When storing the scene information Is in the memory 80, it can also be encrypted or hashed. If the scene information Is is encrypted at the acquisition time, the encrypted scene information Is can also be stored in the memory 80 after decryption. If the scene information Is is a hash value at the acquisition time, the hash value can also be temporarily stored in the memory 80. When the scene information Is stored in the memory 80 is used in S130 (described later), the hash value can be compared with the hash value of the scene information Is stored in the memory 10 on the processing device 1a side to securely acquire the scene information Is.
[0143] In processing step S130, the central management block 880 generates feedback information If to be sent to the master vehicle 2 based on the acquired scene information Is, and sends it from the remote center 8 to the master vehicle 2 via the communication system 8b. The feedback information If can also be generated for onboard verification and validation in the master vehicle 2. The feedback information If can also be generated based on the concept of a feedback loop between the master vehicle 2 and the remote center 8. Alternatively, the feedback information If can be generated in real-time based on the acquired scene information Is in response to its acquisition. In S130, the central management block 880 can also perform statistical analysis processing, including summary processing, on the scene information Is stored in the memory 80 at multiple times. In this case, the feedback information If can be generated retrospectively based on the output of the statistical analysis processing. For example, the generation of the retrospective feedback information If can be performed at least once per day, week, month, or every specified number of trips (i.e., runs).
[0144] The scene information Is stored in memory 80 may also be deleted in response to the generation or transmission of feedback information If. For example, the scene information Is stored in memory 80 may be deleted as a trigger for at least one of the following: a set period, an operator's instruction, or a period during which a violation of the safety envelope in the same scene or location does not occur.
[0145] The feedback information If includes auxiliary information Ic, which indicates driving assistance content for the main vehicle 2 based on scenario information Is. Auxiliary information Ic may represent a permission instruction from the risk monitoring block 140 to restrict driving control settings that constitute a planned violation of the safety envelope in the main vehicle 2. The permission instruction for the restriction represented by auxiliary information Ic may, for example, be set to allow at least one of the following: speed limit of the main vehicle 2, and acceleration / deceleration limit. Auxiliary information Ic may also represent a change instruction for setting parameters or learning parameters in the safety model that define the safety envelope as the criterion for determining a violation of the safety envelope in the main vehicle 2.
[0146] The auxiliary information Ic can also represent an update instruction or parameter adjustment instruction from the detection block 100 of the main vehicle 2, such as an update instruction or parameter adjustment instruction from at least one of the detection algorithms related to fusion, object detection, driving path detection, sign detection, and localization. The auxiliary information Ic can also represent an adjustment instruction from at least one of the internal parameters and external parameters of the sensor system 5 of the main vehicle 2.
[0147] The auxiliary information Ic can also represent a change instruction performed by the planning block 120 of the main vehicle 2, for example, related to at least one of the following: path, track, automatic driving level (including the case where manual driving is assumed to be level 0), operating design area, and control parameters, for moving to a state of minimum risk. The path change instruction represented by the auxiliary information Ic can, for example, include the selection result of determining the route to the destination and the driving lane in a multi-lane structure as having fewer safety envelope violations. The control parameter change instruction represented by the auxiliary information Ic can, for example, be set to at least one of the following: planned speed limit, acceleration / deceleration limit, intervention with the brakes, intervention with steering, intervention with automatic cruise control, and intervention with traction control. In this case, the setting of the change instruction can, for example, be executed based on at least one of the control parameters inherent to or specific to at least one of the following: types of moving bodies with more safety envelope violations, weather conditions with more safety envelope violations, and time periods with more safety envelope violations. For the main vehicle 2 in manual driving, the auxiliary information Ic can represent a warning instruction to the driver that causes a safety envelope violation. The auxiliary information Ic for the manually driven master vehicle 2 can also represent the intervention command of the master vehicle 2's planning block 120 for autonomous driving.
[0148] In S130, the central management block 880 can determine the factors that violate the security envelope based on the scenario information Is. In this case, the feedback information If... Figure 12 As shown, it can also include factor information Ib representing that factor. Factor information Ib can be generated according to S110 described above. Compared to the risk monitoring block 140 constructed by the processing device 1a of the main vehicle 2, the central management block 880 constructed by the processing device 8a of the remote center 8 can generate factor information Ib through high-precision and comprehensive factor analysis (including the statistical analysis described above). This is because the degree of freedom in computer design is increased in the processing device 8a (especially the cloud server main processing device 8a) compared to the processing device 1a. In addition, in the central management block 880 of the processing device 8a, when information about vehicles that have fallen into an unreasonable risk state is uploaded, it is possible to provide a third-party perspective by integrating this information to determine which vehicle is liable for the accident.
[0149] In the feedback information If, which includes factor information Ib, the auxiliary information Ic can be associated with the factor represented by factor information Ib to indicate the auxiliary content represented by auxiliary information Ic. In one specific example, the auxiliary content for a safety envelope violation due to speeding could be an instruction to limit the acceleration or deceleration of the main vehicle 2 through constraint settings or a driving control plan. In other specific examples, the auxiliary content for a safety envelope violation due to miscontrol or misjudgment of cross-timing could be an instruction to limit the acceleration or deceleration of the main vehicle 2, or to intervene in braking, or to intervene in steering, or to intervene in steering control, through constraint settings or a driving control plan.
[0150] The feedback information If, which includes factor information Ib, may also include scene information Is obtained by the central management block 880, confirming factors determined by the central management block 880, such as images. For the manually driven master vehicle 2, the scene information Is confirming factors may include, for example, images of merging scenes at short-distance merging points or entry scenes into blind spots at the end of traffic congestion, where the driver is forced to violate the safety envelope.
[0151] In S130, the feedback information If generated by the central management block 880, after authentication of the user ID containing the authentication key by the remote center 8, can be sent to the master vehicle 2 according to the control of the communication system 8b by the central management block 880. The timing of sending the feedback information If can be controlled in real time or after the fact to prevent security envelope violations, based on the generation timing of the feedback information If described above. The timing of sending the feedback information If can also be controlled to respond to requests from the master vehicle 2, as described later. Alternatively, if the feedback information If is generated or sent after the fact, or sent in response to a request from the master vehicle 2, after the execution of S130, the processing method may not move to S140 or S150 in this process, and the transition may be implemented as needed.
[0152] In S130, the central management block 880 can also store the generated feedback information If in the memory 80. The feedback information If can be stored in the memory 80 in association with a timestamp representing the generation time of the central management block 880, thereby accumulating feedback information If at multiple times in the memory 80. The feedback information If can also be stored in the memory 80 after encryption or hashing. The feedback information If stored in the memory 80 can be deleted in response to the generation or transmission of the feedback information If. For example, the feedback information If stored in the memory 80 can be deleted by triggering at least one of the following: a set period, an operator's instruction, or a period during which no generation occurs due to a violation of the security envelope in the same scene or location.
[0153] In the case of target vehicle 3a, which is assumed to be another master vehicle 2 from the perspective of remote center 8, in S130, the central management block 880 can also perform the generation of feedback information If and the control of sending it to target vehicle 3a through communication system 8b. In this hypothetical example, the feedback information If becomes information fed back to target vehicle 3a based on scene information Is. In addition, the feedback information If in this hypothetical example is generated to distribute at least one of the following to each vehicle: locations with a high probability of safety envelope violation, factors of safety envelope violation, and auxiliary content to avoid safety envelope violation.
[0154] exist Figure 11 In S140 of the processing method shown, the risk monitoring block 140 obtains the feedback information If downloaded from the central management block 880 in the selected master vehicle 2 (either autonomous or manual driving) according to the receiving control in the communication system 6 (processor 62 of the communication device 6a). The feedback information If can also be obtained by sending a real-time or post-event transmission from the central management block 880 regarding a safety envelope violation occurring in the master vehicle 2. For example, the feedback information If can also be obtained by sending a transmission from the central management block 880 in response to a request from the master vehicle 2 at any time or within a specified range on the path. In the case of the target vehicle 3a, which is conceived as another master vehicle 2 from the perspective of the remote center 8, in S140, the risk monitoring block 140 similarly obtains the feedback information If sent from the central management block 880 to the target vehicle 3a via the communication system 6.
[0155] In S140, the risk monitoring block 140 may also store the acquired feedback information If in the memory 10. The feedback information If can be stored in the memory 10 in association with the timestamps of the generation time of the representation center management block 880 or the acquisition time of the risk monitoring block 140, accumulating feedback information If at multiple times in the memory 10. The feedback information If may also be encrypted or hashed when stored in the memory 10. If the feedback information If is encrypted at the acquisition time, the encrypted feedback information If may also be stored in the memory 10 after decryption. If the feedback information If is a hash value at the acquisition time, the hash value may also be temporarily stored in the memory 10. When the hash value stored in the memory 10 is used in S150 (described later) for the feedback information If, the feedback information If can be securely retrieved by comparing it with the hash value of the feedback information If stored in the memory 80 on the processing device 8a side.
[0156] The risk monitoring block 140 in S140 can also delete the scene information Is stored in the memory 10 upon receiving feedback information If, either upon receiving it or after using the feedback information If in S150. The risk monitoring block 140 in S140 can also use at least one of the following as a trigger to delete the scene information Is stored in the memory 80: a set period, or a period during which a security envelope violation does not occur in the same scene or at the same location.
[0157] In processing step S150, at least one of the risk monitoring block 140, detection block 100, and planning block 120 executes an application selected based on the acquired feedback information If. In S150, the block in the risk monitoring block 140, detection block 100, and planning block 120 corresponding to the auxiliary content represented by the auxiliary information Ic contained in the feedback information If may also execute an application to implement the auxiliary content. In this case, if the feedback information If also contains at least one of factor information Ib and scenario information Is, the corresponding block of the auxiliary content can reflect this at least one piece of information in the execution of the application. Specifically, if the auxiliary information Ic in the feedback information If represents a permission instruction for driving control constraints related to a violation of the planned safety envelope, in S150, the risk monitoring block 140 imposes constraints on the driving control executed by the control block 160.
[0158] In S150, the risk monitoring block 140 may also execute an application capable of identifying the appropriateness of a security envelope violation determination based on feedback information If. The appropriateness identification based on application execution in S150 can also be considered a verification of the security envelope violation determination. The execution of the application in S150 can be implemented in real-time in response to the acquisition of feedback information If, or the acquired information If can be stored in memory 10 and implemented retroactively. Upon completion of S150, this current phase of the processing method ends. However, the execution of the application in S150, which is a retroactive process, can be carried over to a later phase, and this phase of the processing method ends. Furthermore, the application in S150 is not only a dedicated inspection application, but also an application implementing the aforementioned auxiliary content, and includes applications for secondary or indirect identification.
[0159] Furthermore, the technology disclosed in Patent Document 1, as previously described, is based on the premise that the master vehicle's judgment is appropriate when restricting driving control in autonomous driving. Therefore, if the master vehicle's judgment is incorrect, this misjudgment will affect the driving accuracy in autonomous driving. Additionally, the technology disclosed in Patent Document 1 focuses on restricting driving control within the master vehicle's autonomous driving concept. Therefore, safety during manual driving within the master vehicle is entrusted to the driver. Moreover, the technology disclosed in Patent Document 1 is based on the premise that the master vehicle's judgment is appropriate when restricting driving control. Therefore, even when the technology disclosed in Patent Document 1 is applied during manual driving, if the driver's judgment in the master vehicle is incorrect, this misjudgment will also affect safety.
[0160] In contrast, according to the first embodiment described above, regardless of whether it is autonomous driving or manual driving, feedback information If is fed back from the remote center 8 to the main vehicle 2 based on scenario information Is representing a scenario where the SOTIF safety envelope is violated according to the driving strategy. Therefore, in the main vehicle 2, the appropriateness of the determination regarding the safety envelope violation can be identified based on the feedback information If, which serves as a third-party judgment. Thus, in the main vehicle 2, driving accuracy in autonomous driving can be ensured, and safety in manual driving can be improved. Furthermore, when the target vehicle 3a is considered as another main vehicle 2 from the perspective of the remote center 8, driving accuracy in autonomous driving and safety in manual driving can also be ensured similarly in the target vehicle 3a, which acts as a "second main moving body".
[0161] (Second Implementation)
[0162] The second embodiment is a variation of the first embodiment. Hereinafter, the second embodiment will be described focusing on the differences between the driving association processing in autonomous driving and that in the first embodiment. Therefore, the driving association processing in autonomous driving described in the second embodiment can be set as a step corresponding to the driving association processing in the first embodiment or executed in parallel with it, or it can be executed in place of the driving association processing in the first embodiment.
[0163] like Figure 13 As shown, in the processing method of the second embodiment, the risk monitoring block 140 in S200, corresponding to S100, executes a monitoring subroutine for the autonomous driving master vehicle 2. For example... Figure 14As shown, in S201 of the monitoring subroutine, the risk monitoring block 140 monitors for safety envelope violations in the main vehicle 2 according to S100. If the risk monitoring block 140 determines in S201 that there is no safety envelope violation, the current process of the monitoring subroutine and its processing method ends. On the other hand, if the risk monitoring block 140 determines in S201 that there is a safety envelope violation, the monitoring subroutine proceeds to S402.
[0164] In S202, the risk monitoring block 140 determines whether the frequency of security envelope violations is outside the allowable range. The allowable range, which serves as the criterion for determining the frequency, can be set below the upper limit of the number of consecutive security envelope violations allowed. Alternatively, the allowable range can be set below the upper limit of the number of security envelope violations allowed within a set time period. When the risk monitoring block 140 determines in S202 that the frequency is within the allowable range, the current operation of the monitoring subroutine and the processing method ends. Conversely, when the risk monitoring block 140 determines in S202 that the frequency is outside the allowable range, the current operation of the monitoring subroutine ends, and the processing method moves to... Figure 13 S210 is shown.
[0165] In S210, corresponding to S110 in the processing method, the risk monitoring block 140 generates at least situation information Ia, which serves as scenario information Is representing a violation scenario in the master vehicle 2 of the autonomous driving system. The risk monitoring block 140 in S210 generates situation information Ia to represent a high-frequency violation scenario where the frequency of safety envelope violations exceeds the permissible range. In this second embodiment, from the perspective of the remote center 8, S200 and S210 are also executed in the target vehicle 3a, which is assumed to be another master vehicle 2. However, the permissible range that serves as the determination criterion for the frequency of violations in the risk monitoring block 140 of the target vehicle 3a can be set, for example, according to the independent settings of each vehicle, to be the same or different from the range in the risk monitoring block 140 of the master vehicle 2.
[0166] In S220 and S230, which correspond to S120 and S130 respectively in the processing method, the central management block 880 executes the first management subroutine and the second management subroutine sequentially. For example... Figure 15 As shown, in S221 of the first management subroutine, the central management block 880 obtains scene information Is representing high-frequency violation scenarios from the autonomous driving master vehicle 2 in accordance with S120.
[0167] In S222 of the first management subroutine, the central management block 880 determines whether it has also obtained scene information Is representing a high-frequency violation scenario from the target vehicle 3a of the autonomous driving system according to S120. At this time, the target vehicle 3a, which becomes the object of obtaining scene information Is, is defined as other road users in the surrounding area that exist within the set range, relative to the main vehicle 2, which is equivalent to the "first moving body", and is equivalent to the "second moving body".
[0168] When the central management block 880 determines in S222 that it has acquired scenario information Is indicating a high-frequency violation scenario, the first management subroutine ends and moves to S231 of the second management subroutine. That is, S231 is executed for the high-frequency violation scenario of the master vehicle 2 when the frequency of the safety envelope violation in the target vehicle 3a is also outside the allowable range. In S231, the central management block 880 generates at least auxiliary information Ic as feedback information If to the master vehicle 2 based on the acquired scenario information Is. The central management block 880 generates auxiliary information Ic in S231 to indicate a change instruction to exclude the driving area of the specific violation scenario from the ODD in the autonomous driving of the master vehicle 2. By completing the execution of S231, the current process of the second management subroutine ends, and the processing method moves to Figure 13 S140 is shown.
[0169] like Figure 15 As shown, when the central management block 880 determines in S222 that scenario information Is indicating a high-frequency violation scenario has not been acquired, the first management subroutine ends and moves to S232 of the second management subroutine. That is, S232 is executed for the high-frequency violation scenario of the main vehicle 2 when the frequency of safety envelope violations in the target vehicle 3a is within the allowable range. In S232, the central management block 880 generates at least auxiliary information Ic as feedback information If to the main vehicle 2 based on the acquired scenario information Is. The central management block 880 in S232 can generate auxiliary information Ic to indicate a stop command such as MRM to stop the main vehicle 2. If the main vehicle 2 is a service vehicle such as a bus or taxi managed and operated by the remote center 8, the auxiliary information Ic can also indicate a stop operation command to make it face the inspection in the service plant. By completing the execution of S232, the current process of the second management subroutine ends, and the processing method moves to Figure 13 S140 is shown. Furthermore, the sending, storage, and deletion of scene information Is and feedback information If are performed according to the first embodiment. In the processing method of the second embodiment, S140 for acquiring feedback information If and S150 for executing the aforementioned application based on feedback information If are implemented in both the main vehicle 2 and the target vehicle 3a.
[0170] In the second embodiment described above, steps S220 and S230, which exchange the relationship between the main vehicle 2 and the target vehicle 3a from the perspective of the remote center 8, can also be executed in parallel. According to the second embodiment, the appropriateness of the determination regarding a violation of the safety envelope can also be identified by the risk monitoring block 140 in autonomous driving based on the instructions represented by the auxiliary information Ic in the feedback information If. Therefore, the second embodiment is particularly advantageous in ensuring driving accuracy in autonomous driving.
[0171] (Third Implementation)
[0172] The third embodiment is a variation of the first embodiment. Hereinafter, the third embodiment will be described focusing on the differences between the driving association processing in autonomous driving and that in the first embodiment. Therefore, the driving association processing in autonomous driving described in the third embodiment can be set as a step in the driving association processing of at least one of the first and second embodiments, or can be executed in parallel with it, or can be executed in place of the driving association processing of the first embodiment.
[0173] like Figure 16 As shown, in S300, corresponding to S100 in the processing method of the third embodiment, the risk monitoring block 140 monitors the safety envelope violation between the target vehicle 3a, which is conceived as another master vehicle 2, and the autonomous driving master vehicle 2 from the perspective of the remote center 8. In S310, corresponding to S110 in the processing method, the risk monitoring block 140 generates at least situation information Ia, as scenario information Is representing a specific violation scenario occurring between the master vehicle 2 and the target vehicle 3a. In S310, the risk monitoring block 140 sets the latest current constraints for the driving that violates the safety envelope represented by the generated situation information Ia before it is generated. In this third embodiment, S300 and S310 are also executed in the target vehicle 3a that constitutes the specific violation scenario.
[0174] In the processing method, within S320 and S330, which correspond to S120 and S130 respectively, the central management block 880 executes the first management subroutine and the second management subroutine sequentially. For example... Figure 17 As shown, in S321 of the first management subroutine, the central management block 880 determines whether the scene information Is representing a specific violation scenario has been obtained from the autonomous driving master vehicle 2 in accordance with S120.
[0175] If, in S321, the central management block 880 determines that it has not obtained scene information Is indicating a specific violation scenario from the master vehicle 2, the first management subroutine moves to S322. That is, if it is determined in the master vehicle 2 that no safety envelope violation has occurred with the target vehicle 3a, S322 is executed. In S322, the central management block 880 determines whether it has obtained scene information Is indicating a specific violation scenario from the autonomous driving target vehicle 3a according to S120. At this time, the target vehicle 3a, which is the object of obtaining scene information Is, is defined relative to the master vehicle 2, which is equivalent to the "first moving body," as other road users existing in the surrounding area within a set range, and thus equivalent to the "second moving body." Furthermore, if, in S322, the central management block 880 also determines that it has not obtained scene information Is indicating a specific violation scenario from the target vehicle 3a, the current process of the first management subroutine and the processing method ends.
[0176] When the central management block 880 determines in S322 that it has obtained scenario information Is representing a specific violation scenario from the target vehicle 3a, the first management subroutine ends and moves to S331 of the second management subroutine. That is, if the target vehicle 3a is determined to have generated a specific violation scenario involving a safety envelope violation with the master vehicle 2, and the master vehicle 2 is determined not to have generated a safety envelope violation with the target vehicle 3a, S331 is executed. In S331, the central management block 880 generates at least auxiliary information Ic as feedback information If based on the obtained scenario information Is.
[0177] In S331, the central management block 880 generates auxiliary information Ic to indicate an instruction for the main vehicle 2 to make a determination of no safety envelope violation, regardless of the specific violation scenario in which a determination of safety envelope violation is made in the target vehicle 3a. The instruction indicated by the auxiliary information Ic may be at least one of the following: a rollback instruction that reverts to a minimum risk state by setting constraints or a driving control plan, or a change instruction that alters the path of the driving control plan. Specifically, the rollback instruction may be at least one of the following: a reduction in the level of automated driving including handover to manual driving, and MRM (Manual Management System). In the case where the main vehicle 2 is a service vehicle such as a bus or taxi managed and operated by the remote center 8, the auxiliary information Ic may also indicate the operation service provided to the main vehicle 2 according to the rollback instruction or path change instruction from the remote center 8.
[0178] The central management block 880 in S331 can generate auxiliary information Ic to indicate a notification instruction to the master vehicle 2 to indicate no safety envelope violation for the target vehicle 3a that has been determined to have violated the safety envelope. The central management block 880 in S331 can also generate auxiliary information Ic to indicate an instruction to allow the restriction on driving that violates the safety envelope, set by the risk monitoring block 140 in S310, in the target vehicle 3a that has been determined to have violated the safety envelope. The central management block 880 in S331 can also generate auxiliary information Ic to indicate a rollback instruction or path change instruction for the target vehicle 3a that has been determined to have violated the safety envelope, in accordance with the above-mentioned master vehicle 2 situation. With the completion of S331, the current process of the second management subroutine ends, and the processing method moves to... Figure 16 S140 is shown.
[0179] like Figure 17 As shown, when the central management block 880 determines in S321 that it has obtained scene information Is indicating a specific violation scenario from the main vehicle 2, the first management subroutine moves to S323. That is, if it is determined in the main vehicle 2 that a safety envelope violation has occurred with the target vehicle 3a, S323 is executed. In S323, the central management block 880 determines whether it has also obtained scene information Is indicating a specific violation scenario from the target vehicle 3a according to S120. At this time, the target vehicle 3a, which is the object of obtaining scene information Is, is defined relative to the main vehicle 2, which is equivalent to a "first moving body", as another road user existing in the surrounding area within the set range and constituting a specific violation scenario, and is equivalent to a "second moving body".
[0180] When the central management block 880 determines in S323 that it has not obtained scenario information Is representing a specific violation scenario from the target vehicle 3a, the first management subroutine ends and moves to S332 of the second management subroutine. That is, if the master vehicle 2 is determined to have generated a specific violation scenario involving a safety envelope violation with the target vehicle 3a, and the target vehicle 3a is determined not to have generated a safety envelope violation with the master vehicle 2, S332 is executed. In S332, the central management block 880 generates at least auxiliary information Ic as feedback information If based on the obtained scenario information Is. At this time, according to S331, which exchanges the relationship between the master vehicle 2 and the target vehicle 3a, the generation of auxiliary information Ic is executed. Thus, by completing the execution of S332, the current process of the second management subroutine ends, and the processing method moves to... Figure 16 S140 is shown.
[0181] like Figure 17As shown, when the central management block 880 determines in S323 that scenario information Is indicating a specific violation scenario has also been obtained from the target vehicle 3a, the first management subroutine ends and moves to S333 of the second management subroutine. That is, when a specific violation scenario is determined to have occurred in the main vehicle 2, indicating a violation of the safety envelope between the main vehicle and the target vehicle 3a, and a violation of the safety envelope between the main vehicle and the target vehicle 3a is also determined to have occurred in the target vehicle 3a, S333 is executed. In S333, the central management block 880 generates at least auxiliary information Ic as feedback information If based on the obtained scenario information Is. The central management block 880 generates auxiliary information Ic in S333 to indicate an allowance instruction for driving restrictions related to the safety envelope violation set by the risk monitoring block 140 of S310 in each of the main vehicle 2 and the target vehicle 3a. By completing the execution of S333, the current process of the second management subroutine ends, and the processing method moves to Figure 16 S140 is shown. Furthermore, the sending, storage, and deletion of scene information Is and feedback information If are respectively performed according to the first embodiment. In the processing method of the third embodiment, S140 for acquiring feedback information If and S150 for executing an application based on feedback information If are implemented in both the main vehicle 2 and the target vehicle 3a.
[0182] In the third embodiment described above, S320 and S330, which exchange the relationship between the main vehicle 2 and the target vehicle 3a from the perspective of the remote center 8, can also be executed in parallel. On the other hand, from the perspective of the remote center 8, if scene information Is from one of the multiple vehicles including the main vehicle 2 and the target vehicle 3a is obtained in S321, the acquisition of scene information Is from other vehicles can be determined in S323. In the latter case, the execution of S322 and S331 can be omitted by executing S332 and S333, which replace the relationship between the main vehicle 2 and the target vehicle 3a with the relationship between this one vehicle and other vehicles. According to the third embodiment described above, the appropriateness of the determination of safety envelope violation can also be identified by the risk monitoring block 140 in autonomous driving based on the instructions represented by the auxiliary information Ic in the feedback information If. Therefore, the third embodiment is particularly advantageous for ensuring driving accuracy in autonomous driving.
[0183] (Fourth Implementation)
[0184] The fourth embodiment is a variation of the first embodiment. Hereinafter, the fourth embodiment will be described focusing on the differences between the driving association processing in manual driving and that in the first embodiment. Therefore, the driving association processing in manual driving described in the fourth embodiment can be set as a step corresponding to the driving association processing in the first embodiment or executed in parallel with it, or it can be executed in place of the driving association processing in the first embodiment.
[0185] like Figure 18 As shown, in S400, corresponding to S100, in the processing method of the fourth embodiment, the risk monitoring block 140 monitors for violations of the safety envelope in the manually driven master vehicle 2. Figure 19 As shown, the risk monitoring block 140 in S400 can determine that a safety envelope violation has occurred when the actual value of the moving physical quantity deviates from the constraint setting limit value R1.
[0186] In S410, corresponding to S110 in the processing method, the risk monitoring block 140 generates at least situation information Ia, which serves as scenario information Is representing a violation scenario in the manually driven master vehicle 2. In S410, the risk monitoring block 140 generates situation information Ia in a manner that represents the driver's state in the master vehicle 2 required for calculating driving scores in association with safety envelope violations. The driver's state required for driving scores includes, for example, at least one of the following: driving trends including previous violation scenarios, driving distance history, driving time history, and safety envelope violation history. The situation information Ia required for driving scores represents, for example, at least one of the following: load weight, tire condition including wear, maintenance status, operating status of driving actuators, and type of moving body, serving as the state of the master vehicle 2 for judging the driver's negligence.
[0187] The risk monitoring block 140 in S410 can also generate representations such as Figure 19 The situation information Ia includes at least one of the following: time, location, and estimated positioning value, indicating a violation scenario where the moving physical quantity deviates from the limit values R1 to R3 as shown. The risk monitoring block 140 in S410 can, for example... Figure 19 If the distance of the deviation of the physical quantity of motion from the limit values R1 to R3 within the violation interval Δs is outside the set range, status information Ia representing the track (i.e., trajectory) of the main vehicle 2 within that violation interval Δs in the map data is generated. The risk monitoring block 140 in S410 can also, as... Figure 19 When the length of the violation time Δt of the shown motion physical quantity deviating from the limit values R1 to R3 is outside the set range, status information Ia representing the violation time Δt is generated. Furthermore, the set range that serves as the criterion for judging the violation interval Δs and the violation time Δt can be set to a range below or less than a threshold. Additionally, Figure 19Examples are shown where the moving physical quantity deviates from the upper limit limit R1 between time t1 and t2, deviates from the changed upper limit limit R2 between time t2 and t3, and deviates from the lower limit limit R3 after time t4.
[0188] like Figure 18 As shown, in S420 corresponding to S120 in the processing method, the central management block 880 obtains scene information Is from the manually driven master vehicle 2 through the communication system 8b. In S430 corresponding to S130 in the processing method, the central management block 880 generates at least score information Id, which serves as feedback information If to the master vehicle 2 based on the obtained scene information Is. The score information Id represents the driving score of the driver of the master vehicle 2. The central management block 880 determines the driving score based on the scene information Is. The driving score can be represented by a numerical value or a level, serving as an objective indicator for evaluating the driver operating the master vehicle 2.
[0189] The central management block 880 in S430 generates auxiliary information Ic as feedback information If, representing a recommended manual driving instruction to avoid a violation of the safety envelope. Examples of the recommended manual driving instructions represented by the auxiliary information Ic include, for instance, advancing the braking timing for a longitudinally forward target vehicle 3a, or shortening the parallel driving time with a lateral target vehicle 3a. The central management block 880 in S430 may also generate at least one of factor information Ib representing a factor of a safety envelope violation, and scenario information Is confirming that factor, as feedback information If associated with the auxiliary information Ic representing the recommended manual instruction.
[0190] In the processing method of the fourth embodiment, S140, which acquires feedback information If, and S150, which executes the application based on the feedback information If, are implemented in the main vehicle 2. Alternatively, S400, S410, S420, S430, S140, and S150 of the processing method can also be implemented in the target vehicle 3a, which may be another main vehicle 2 from the perspective of the remote center 8. In this hypothetical example, in the central management block 880 of S420 and S430, scene information Is of safety envelope violation can be accumulated and summarized in the memory 80 from the perspective of each vehicle 2, 3a, and at least one of the drivers of each of these vehicles 2, 3a, and the driving score can be calculated through statistical analysis of the summarized results.
[0191] In the fourth embodiment described above, the sending, storage, and deletion of the scene information Is and the feedback information If are performed according to the first embodiment. Therefore, in S140, feedback information If containing at least the score information Id is obtained. According to the fourth embodiment, by using the driving score represented by the score information Id in the feedback information If, the driver in manual driving can also identify the appropriateness of the judgment regarding a violation of the safety envelope. Therefore, the fourth embodiment is particularly beneficial for improving safety in manual driving.
[0192] (Fifth Implementation)
[0193] The fifth embodiment is a variation of the first embodiment. Hereinafter, the fifth embodiment will be described focusing on the differences between the driving association processing in manual driving and that in the first embodiment. Therefore, the driving association processing in manual driving described in the fifth embodiment can be set as a corresponding step in the driving association processing of at least one of the first and fourth embodiments, or can be executed in parallel with it, or can be executed in place of the driving association processing of the first embodiment.
[0194] like Figure 20 As shown, in the fifth embodiment, the remote center 8 of the processing system 1 can communicate with the service center 9 via the communication system 8b. The service center 9 is managed by a service provider that offers services related to road users including the main vehicle 2. The services provided by the service center 9 include at least one of the following: urban planning services, road maintenance services, map information services, operation management services, traffic management services, vehicle insurance services, ride-sharing services, and car-sharing services.
[0195] Service center 9 includes a processing unit 9a and a communication system 9b, which are structured similarly to remote center 8. The processing unit 9a acquires information provided from remote center 8 via communication system 9b, either in cooperation with a processing program in remote center 8 or through the execution of a part of or different independent programs therein. Service center 9 effectively uses the information provided from remote center 8 for the services of the service provider.
[0196] Therefore, as Figure 21As shown, in S530, corresponding to S130, in the processing method of the fifth embodiment, the central management block 880 generates public information Io to be disclosed to the service center 9 based on at least one of the scene information Is and the feedback information If. The public information Io can be generated to disclose to the service center 9, which provides services such as urban planning, road maintenance, map information, operation management, or traffic management, locations with a high probability of security envelope violation. The public information Io can also be generated, for example, to disclose to the service center 9, which provides vehicle insurance services, information that serves as a review criterion for vehicle insurance.
[0197] Public information Io can also be generated, for example, to disclose to service centers 9 providing ride-sharing or car-sharing services the factors that violate the safety envelope associated with each driver in manual driving. In this case, public information Io can also be generated to further disclose auxiliary content matching the factors. In a specific example of auxiliary content matching the factors, in the case of a misjudgment of the factor being oncoming vehicle priority, the result of the path retrieval is provided as public information Io by searching for a path that does not require protrusion into the oncoming lane and has less road stopping. In other specific examples of auxiliary content matching the factors, in the case of a misjudgment of the factor being intersection timing, the result of the path retrieval is provided as public information Io by searching for a path through an intersection controlled by a traffic light system.
[0198] In the processing method of the fifth embodiment, S100, S110, S120, and S530 can also be executed according to S400, S410, S420, and S430 of the fourth embodiment. In S530 according to S430, if the public information Io generated as described above discloses auxiliary content based on factors of safety envelope violation, a driving score can also be calculated for each driver. In a specific example of auxiliary content matching factors, public information Io for selecting drivers with higher driving scores is provided to the service center 9 providing ride-sharing services.
[0199] According to this fifth embodiment, public information Io for the service center 9 is generated based on at least one of scenario information Is related to a violation of the safety envelope and feedback information If. Therefore, the fifth embodiment, combined with the participation of the service provider, is conducive to improving safety in manual driving.
[0200] (Sixth Implementation Method)
[0201] The sixth embodiment is a variation of the first embodiment. However, the sixth embodiment can also be combined with the second to fifth embodiments.
[0202] like Figure 22As shown, in the control block 6160 of the sixth embodiment, the process of obtaining determination information related to the safety envelope from the risk monitoring block 140 is omitted. Therefore, the planning block 6120 of the sixth embodiment obtains the determination information related to the safety envelope from the risk monitoring block 140. If the planning block 6120 obtains determination information indicating no safety envelope violation, it plans the driving control of the main vehicle 2 according to the planning block 120. On the other hand, if the planning block 6120 obtains determination information indicating a safety envelope violation, it imposes a constraint on the driving control based on the determination information during the stage of planning the driving control according to the planning block 120. That is, the planning block 6120 restricts the planned driving control. In either case, the control block 6160 executes the driving control of the main vehicle 2 planned by the planning block 6120.
[0203] In this sixth embodiment of the processing method, for example, if the auxiliary information Ic in the feedback information If indicates a change instruction for setting parameters or learning parameters in the safety model, the risk monitoring block 140 can execute the change instruction in S150. Based on the above, in the sixth embodiment, according to the principles of the first embodiment, driving accuracy in autonomous driving can be ensured, and safety in manual driving can be improved.
[0204] (Seventh Implementation)
[0205] The seventh embodiment is a variation of the first embodiment. However, the seventh embodiment can also be combined with the second to fifth embodiments.
[0206] like Figure 23 As shown, in the control block 7160 of the seventh embodiment, the processing of obtaining determination information related to the safety envelope from the risk monitoring block 7140 is omitted. Therefore, the risk monitoring block 7140 of the seventh embodiment obtains information indicating the result of the driving control performed on the main vehicle 2 by the control block 7160. The risk monitoring block 7140 evaluates the driving control by performing a safety determination based on the safety envelope on the result of the driving control.
[0207] In this seventh embodiment, for example, if the auxiliary information Ic in the feedback information If indicates a change instruction for setting parameters or learning parameters in the safety model, the risk monitoring block 140 can also execute the change instruction in S150. These setting parameters and learning parameters can be changed either through verification and validation at a remote center 8, or based on the concept of a feedback loop. In summary, in the seventh embodiment, based on the principles of the first embodiment, driving accuracy in autonomous driving can be ensured, and safety in manual driving can be improved.
[0208] (Eighth Implementation Method)
[0209] The eighth embodiment is a variation of the first embodiment. However, the eighth embodiment can also be combined with the second to fifth embodiments.
[0210] like Figures 24-26 As shown, in the eighth embodiment, a test block 8180 for driving control of the test processing device 1a, for example, for safety approval, is added. The test block 8180 is given functions based on the detection block 100 and the risk monitoring block 140. It can also be achieved by... Figure 24 The processing device 1a shown executes a test program appended to the processing program used to construct blocks 100, 120, 140, and 160 to construct test block 8180. Alternatively, it can be constructed by... Figure 25 , 26 As shown, the test processing device 1b, different from the processing device 1a, executes a test processing program different from the processing program for constructing blocks 100, 120, 140, and 160 to construct test block 8180. Figure 25 In the example, the testing processing device 1b can be constructed from at least one dedicated computer having a memory 10 and a processor 12, which is connected to the processing device 1a for testing driving control (the case of connection via communication system 6 is omitted). Figure 26 In the example, the processing device 8a of the remote center 8 is used instead of the testing processing device 1b.
[0211] In this eighth embodiment, by testing the processing method of the processing system 1 and the processing device 1a according to the principle of the first embodiment, driving accuracy in automatic driving can be ensured, and safety in manual driving can be improved.
[0212] (Ninth Implementation)
[0213] The ninth embodiment is a variation of the sixth embodiment. However, the ninth embodiment can also be combined with the second to fifth embodiments.
[0214] like Figure 27As shown, in the processing apparatus 1a of the ninth embodiment, the function of the risk monitoring block 140 is incorporated into the planning block 9120 as a risk monitoring sub-block 9140. Therefore, when the risk monitoring sub-block 9140 obtains determination information indicating no safety envelope violation, the planning block 9120 of the ninth embodiment plans the driving control of the main vehicle 2 according to the planning block 120. On the other hand, when the risk monitoring sub-block 9140 obtains determination information indicating a safety envelope violation, the planning block 9120 imposes constraints on the driving control based on the determination information during the stage of planning the driving control according to the planning block 120. That is, the planning block 9120 restricts the planned driving control. In either case, the driving control of the main vehicle 2 planned by the planning block 9120 is executed by the control block 6160.
[0215] In this ninth embodiment, for example, if the auxiliary information Ic in the feedback information If indicates a change instruction for setting parameters or learning parameters in the safety model, the risk monitoring sub-block 9140 can execute the change instruction in S150. In summary, in the ninth embodiment, based on the principles of the first embodiment, driving accuracy in autonomous driving can be ensured, and safety in manual driving can be improved.
[0216] (Tenth Implementation)
[0217] The tenth embodiment is a variation of the first embodiment.
[0218] like Figure 28 As shown, the processing system 1 of the tenth embodiment is constructed by including processing devices 1a respectively mounted on the main vehicle 2 and the target vehicle 3a. Here, the processing system 1 of the tenth embodiment can also be constructed by including at least the communication system 6 among the sensor system 5, communication system 6, map DB 7, and information prompting system 4 in each vehicle 2 and 3a. In this case, communication between the communication devices 6a constituting the communication system 6 in each vehicle 2 and 3a can be realized directly, for example, through V2V communication, indirectly through a remote center such as a cloud server, or through a mesh network composed of multiple vehicles including vehicles 2 and 3a. In such a tenth embodiment, from the perspective of the vehicle 2 as the main moving body, vehicle 3a is equivalent to the target moving body, but from the opposite perspective, for the vehicle 3a as the main moving body, vehicle 2 is equivalent to the target moving body.
[0219] In the processing device 1a of each vehicle 2, 3a in the tenth embodiment, the processing programs stored in each memory 10 for performing driving-related processing according to each of these vehicles 2, 3a cause each processor 12 to execute commands, and function blocks are constructed independently. From the perspective of the processing system 1 as a whole, this can be seen as the processors 12 of each vehicle 2, 3a cooperatively executing commands by the processing programs stored in the memory 10 of each vehicle 2, 3a, thus constructing function blocks according to these vehicles 2, 3a. At this time, in the case where the processing system 1 is constructed with each vehicle 2, 3a including a communication device 6a, the processing programs stored in the memory 10, 60 of each vehicle 2, 3a can also cause the processors 12, 62 of each vehicle 2, 3a to cooperatively execute commands. In each of these vehicles 2, 3a in this tenth embodiment, the risk monitoring block 10140 constructed in each processing device 1a incorporates the function of the central management block 880 as a target management sub-block 10880.
[0220] Therefore, in the processing method of the tenth embodiment, when S100, 110, S140, and S150 are executed by the risk monitoring block 140 of vehicle 2, S120 and S130 can be executed by the target management sub-block 10880 of vehicle 3a. In S120 under this condition, the target management sub-block 10880 can acquire scene information Is from vehicle 2 in vehicle 3a according to the receive control in the processor 62 of communication device 6a, and store it in memory 10. In addition, in S130 under this condition, the target management sub-block 10880 can also generate feedback information If in a manner that includes at least auxiliary information Ic as information Ic, Ib, Is that can be acquired in vehicle 3a. Furthermore, in S130 under this condition, the target management sub-block 10880 can send the generated feedback information If to vehicle 2 in vehicle 3a according to the transmit control in the processor 62 of communication device 6a, and store it in memory 10.
[0221] On the other hand, when S100, 110, S140, and S150 are executed by the risk monitoring block 140 of vehicle 3a, S120 and S130 can also be executed by the target management sub-block 10880 of vehicle 2 in the processing method of the tenth embodiment. In S120 in this case, the target management sub-block 10880 can acquire scene information Is from vehicle 3a in vehicle 2 according to the receive control in the processor 62 of communication device 6a, and store it in memory 10. In addition, in S130 in this case, the target management sub-block 10880 can also generate feedback information If in a manner that includes at least auxiliary information Ic as information Ic, Ib, Is that can be acquired in vehicle 2. Furthermore, in S130 in this case, the target management sub-block 10880 can send the generated feedback information If to vehicle 3a in vehicle 2 according to the transmit control in the processor 62 of communication device 6a, and store it in memory 10.
[0222] Furthermore, in any case, in the processing method of the tenth embodiment, for example, if the auxiliary information Ic from one of the vehicles 3a and 2, which serves as feedback information If, indicates a change instruction for setting parameters or learning parameters in the safety model, the risk monitoring sub-block 10140 of the other vehicle 3a and 2 can also execute the change instruction in S150. In summary, in the tenth embodiment, regardless of which of the vehicles 2 and 3a becomes the main moving body relative to the target moving body of the other, driving accuracy in autonomous driving can be ensured according to the principles of the first embodiment, and safety in manual driving can be improved. Additionally, this tenth embodiment can also be combined with the second to ninth embodiments.
[0223] In a further variation of the tenth embodiment described above, such as Figure 29 As shown, unlike the risk monitoring block 140 of the first embodiment which does not incorporate the functions of the central management block 880, a target management block 10880a may be constructed in the processing device 1a of each vehicle 2, 3a. This target management block 10880a is used to implement the functions of the target management sub-block 10880. Furthermore, this variation of the tenth embodiment can also be combined with the second to ninth embodiments.
[0224] (Other implementation methods)
[0225] The above describes several embodiments, but this disclosure is not limited to these embodiments and can be applied to various embodiments and combinations without departing from the spirit of this disclosure.
[0226] In the variations, the dedicated computer constituting at least one of devices 1a, 8a, and 6a may also include digital and / or analog circuits as a processor. Here, the term "digital circuit" refers to at least one of ASIC (Application Specific Integrated Circuit), FPGA (Field Programmable Gate Array), SOC (System on a Chip), PGA (Programmable Gate Array), and CPLD (Complex Programmable Logic Device). Furthermore, such a digital circuit may also have a memory storing a program.
[0227] In addition to the above description, the processing apparatus 1a of the above-described embodiments and modifications can also be implemented as a semiconductor device (e.g., a semiconductor chip) having at least one processor 12 and one memory 10. Furthermore, the processing apparatus 8a of the above-described embodiments and modifications can also be implemented as a semiconductor device (e.g., a semiconductor chip) having at least one processor 82 and one memory 80. Additionally, the communication apparatus 6a of the above-described embodiments and modifications can also be implemented as a semiconductor device (e.g., a semiconductor chip) having at least one processor 62 and one memory 60.
[0228] (Postscript)
[0229] The technical features of the above-described embodiments can be summarized as follows.
[0230] (Technical Feature 1)
[0231] Technical feature 1 is a processing device (1a) that includes a processor (12) for performing driving-related processing of a main mobile body (2, 3a) capable of communicating with a remote center (8). The processor is configured to perform the following processing: monitoring for safety envelope violations in the autonomous driving main mobile body, wherein the safety envelope violation is a violation of the safety envelope of the expected function set according to the driving strategy; generating scene information representing the scene of the safety envelope violation and sending it to the remote center when a safety envelope violation is determined to have occurred; and obtaining feedback information based on the scene information feedback from the remote center.
[0232] (Technical Feature 2)
[0233] In technical feature 1, the remote center can communicate with the target mobile body (3a, 2), wherein the target mobile body is different from the main mobile body. The generated scene information includes: generating scene information under high-frequency violation scenarios, wherein the high-frequency violation scenario is a scenario in which the frequency of safety envelope violation in the main mobile body is outside the allowable range. The obtained feedback information includes: in the high-frequency violation scenario in which the frequency of safety envelope violation in the target mobile body is also outside the allowable range, obtaining feedback information based on the scene information feedback, so as to exclude the driving area of the high-frequency violation scenario from the operation design area in autonomous driving.
[0234] (Technical Feature 3)
[0235] In technical feature 2, the main mobile body manages the operation service through a remote center and obtains feedback information including: in high-frequency violation scenarios where the frequency of security envelope violations in the target mobile body is within the allowable range, obtaining feedback information based on scenario information to stop the operation service.
[0236] (Technical Feature 4)
[0237] In any one of technical features 1 to 3, the remote center is able to communicate with the target mobile body (3a, 2), wherein the target mobile body is different from the main mobile body, and the generated scenario information includes: in a specific violation scenario in which a safety envelope violation occurs in the main mobile body, setting constraints on the driving of the safety envelope violation represented by the generated scenario information, and obtaining feedback information includes: in a specific violation scenario in which a safety envelope violation also occurs in the target mobile body, obtaining feedback information based on the scenario information feedback to allow constraints.
[0238] (Technical Feature 5)
[0239] In technical feature 4, the primary mobile body manages the operation service through the remote center and obtains feedback information including: in a specific violation scenario in which a security envelope violation occurs in the target mobile body, and in the case where no security envelope violation occurs in the primary mobile body, obtaining feedback information based on scenario information feedback, so as to provide operation services based on instructions from the remote center.
[0240] (Technical Feature 6)
[0241] In any one of technical features 1 to 5, generating scene information includes: storing the generated scene information in the storage medium (10) of the main mobile body, and obtaining feedback information includes: deleting the scene information from the storage medium in response to obtaining the feedback information.
[0242] (Technical Feature 7)
[0243] Technical feature 7 is a processing method executed by the processor (12) for performing driving-related processing of a main mobile body (2, 3a) capable of communicating with a remote center (8), comprising: monitoring for safety envelope violations in the autonomous driving main mobile body, wherein the safety envelope violation is a violation of the safety envelope of the expected function set according to the driving strategy; generating scene information representing the scene of the safety envelope violation and sending it to the remote center when a safety envelope violation is determined to have occurred; and obtaining feedback information based on the scene information feedback from the remote center.
[0244] (Technical Feature 8)
[0245] Technical feature 8 is a processing program stored in storage medium (10) for performing driving-related processing of a master mobile body (2, 3a) capable of communicating with a remote center (8), and includes commands for a processor (12) to execute, the commands including: causing the processor to monitor for safety envelope violations in the master mobile body that are violations of the safety envelope of the intended functions set according to the driving strategy; causing the processor to generate scene information representing the scene of the safety envelope violation and send it to the remote center when it is determined that a safety envelope violation has occurred; and causing the processor to obtain feedback information based on the scene information feedback from the remote center.
[0246] (Technical Feature 9)
[0247] Technical feature 9 is a processing device (8a) that includes a processor (82) for performing driving-related processing of the main mobile body in a remote center (8) capable of communicating with the main mobile body (2, 3a). The processor is configured to perform the following processing: obtaining scene information from the main mobile body that is driving autonomously, representing a scenario of a safety envelope violation, wherein the safety envelope violation is a violation of the safety envelope of the expected function set according to the driving strategy; and generating feedback information based on the scene information feedback to send to the main mobile body.
[0248] (Technical Feature 10)
[0249] In technical feature 9, the remote center can communicate with the first mobile body (2) and the second mobile body (3a) as the main mobile body to obtain scene information, including: obtaining scene information from the first mobile body and also obtaining scene information from the second mobile body. The generation of feedback information includes: in the case of a high-frequency violation scenario where the frequency of safety envelope violation in the first mobile body is outside the allowable range, and in the case where the frequency of safety envelope violation in the second mobile body is also outside the allowable range, generating feedback information based on scene information feedback to exclude the driving area of the high-frequency violation scenario from the operation design area of the autonomous driving of the first mobile body and the second mobile body respectively.
[0250] (Technical Feature 11)
[0251] In technical feature 10, the remote center manages the operation service of the first mobile body and generates feedback information including: in high-frequency violation scenarios, when the frequency of security envelope violations in the second mobile body is within an acceptable range, generating feedback information based on scenario information feedback to stop the operation service of the first mobile body.
[0252] (Technical Feature 12)
[0253] In any one of technical features 9 to 11, the remote center is able to communicate with the first mobile body (2) and the second mobile body (3a) as the main mobile body, and to obtain scene information including: if scene information is obtained from the first mobile body, scene information is also obtained from the second mobile body, and to generate feedback information including: if a specific violation scenario of safety envelope violation occurs in the first mobile body, and a safety envelope violation also occurs in the second mobile body, feedback information based on scene information feedback is generated to allow constraints on driving settings for safety envelope violation in each of the first and second mobile bodies.
[0254] (Technical Feature 13)
[0255] In technical feature 12, the remote center manages the operation services of the first mobile body and generates feedback information including: when a specific violation scenario of security envelope violation occurs in the second mobile body, but no security envelope violation occurs in the first mobile body, generating feedback information based on scenario information feedback, so that the first mobile body provides operation services according to instructions from the remote center.
[0256] (Technical Feature 14)
[0257] In any of technical features 9 to 13, generating feedback information includes generating feedback information in response to the acquisition of scene information.
[0258] (Technical Feature 15)
[0259] In any one of technical features 9 to 14, acquiring scene information includes: accumulating scene information acquired at multiple times in a storage medium (80) at a remote center, and generating feedback information includes: generating feedback information based on statistical analysis of scene information stored in the storage medium at multiple times.
[0260] (Technical Feature 16)
[0261] In technical feature 15, generating feedback information includes: in response to the generation or transmission of feedback information, deleting scene information at multiple time points from the storage medium.
[0262] (Technical Feature 17)
[0263] Technical feature 17 is a processing method executed by a processor (82) for performing driving-related processing of the main mobile body in a remote center (8) capable of communicating with the main mobile body (2, 3a), comprising: obtaining scene information from the autonomous driving main mobile body representing a scenario of a safety envelope violation, wherein the safety envelope violation is a violation of the safety envelope of the expected function set according to the driving strategy; and generating feedback information based on the scene information feedback to send to the main mobile body.
[0264] (Technical Feature 18)
[0265] Technical feature 18 is a processing program stored in a storage medium (80) for performing driving-related processing of the main mobile body (2, 3a) in a remote center (8) capable of communicating with the main mobile body (2, 3a), and containing commands for a processor (82) to execute, the commands including: causing the processor to obtain scene information from the main mobile body that represents a scenario of a safety envelope violation, the safety envelope violation being a violation of the safety envelope of the expected functions set according to the driving strategy; and causing the processor to generate feedback information based on the scene information feedback to send to the main mobile body.
[0266] (Technical Feature 19)
[0267] Technical feature 19 is a processing system (1) that includes a first processor (12) of the main mobile body and a second processor (82) of the remote center for performing driving-related processing of a main mobile body (2, 3a) capable of communicating with a remote center (8). The first processor is configured to perform the following processing: monitoring for safety envelope violations in the main mobile body that are autonomous driving, the safety envelope violations being violations of the safety envelope of the expected functions set according to the driving strategy; and, if a safety envelope violation is determined to have occurred, generating scene information representing the scene of the safety envelope violation and sending it from the main mobile body to the remote center. The second processor is configured to perform the following processing: generating feedback information based on scene information feedback and sending it from the remote center to the main mobile body.
[0268] (Technical Feature 20)
[0269] Technical feature 20 is a processing method, a processing method executed collaboratively by a first processor (12) of the main mobile body and a second processor (82) of the remote center in order to perform driving-related processing of a main mobile body (2, 3a) capable of communicating with a remote center (8), comprising: monitoring for safety envelope violations in the main mobile body that is autonomously driving, wherein the safety envelope violation is a violation of the safety envelope of the expected function set according to the driving strategy; generating scene information representing the scene of the safety envelope violation and sending it from the main mobile body to the remote center when a safety envelope violation is determined to have occurred; and generating feedback information based on the scene information feedback and sending it from the remote center to the main mobile body.
[0270] (Technical Feature 21)
[0271] Technical feature 21 is a processing program that, in order to perform related processing, is stored in at least one of a first storage medium (10) of the main mobile body and a second storage medium (80) of the remote center, and includes commands that cause a first processor (12) of the main mobile body and a second processor (82) of the remote center to cooperate in executing the following processing: monitoring for safety envelope violations in the autonomous driving main mobile body, wherein the safety envelope violation is a violation of the safety envelope of the expected function set according to the driving strategy; generating scene information representing the scene of the safety envelope violation and sending it from the main mobile body to the remote center when it is determined that a safety envelope violation has occurred; and generating feedback information based on the scene information feedback and sending it from the remote center to the main mobile body.
[0272] (Technical Feature 22)
[0273] Technical feature 22 is a communication device (6a) configured to communicate with a remote center (8) and to perform driving-related processing of the main mobile body (2, 3a) in cooperation with any of the processing devices (1a) in technical features 1 to 6. The processor includes a processor configured to perform the following processing: sending scene information to the remote center when the processing device determines that a safety envelope violation has occurred in the main mobile body of autonomous driving; and receiving feedback information from the remote center.
[0274] (Technical Feature 23)
[0275] Technical feature 23 is a communication device (6a) configured to communicate with a remote center (8) and include a processor (62) for performing driving-related processing of the main mobile body (2, 3a). The processor is configured to perform the following processing: in the event of a safety envelope violation in the main mobile body operating in autonomous driving, sending scene information indicating the scenario of the safety envelope violation to the remote center, wherein the safety envelope violation is a violation of the safety envelope of the expected function set according to the driving strategy; and receiving feedback information based on the scene information feedback from the remote center.
[0276] (Technical Feature 24)
[0277] Technical feature 24 is a processing method for performing driving-related processing of a master mobile body (2, 3a) in a communication device (6a) capable of communicating with a remote center (8), and the processing method executed by the processor (62) includes: in the event of a safety envelope violation occurring in the master mobile body of autonomous driving, sending scene information indicating a scenario of a safety envelope violation to the remote center, wherein the safety envelope violation is a violation of the safety envelope of the expected function set according to the driving strategy; and receiving feedback information based on the scene information feedback from the remote center.
[0278] (Technical Feature 25)
[0279] Technical feature 25 is a processing program stored in a storage medium (60) for performing driving-related processing of the main mobile body (2, 3a) in a communication device (6a) capable of communicating with a remote center (8), and includes commands for a processor (62) to execute, the commands including: sending scenario information indicating a scenario of safety envelope violation to the remote center in the event of a safety envelope violation in the main mobile body of autonomous driving, wherein the safety envelope violation is a violation of the safety envelope of the expected function set according to the driving strategy; and receiving feedback information based on scenario information feedback from the remote center.
[0280] (Technical Feature 26)
[0281] Technical feature 26 is a processing system (1) that includes a processor (12, 62) for performing driving-related processing of a master mobile body (2, 3a) capable of communicating with a remote center (8). The processor is configured to perform the following processing: monitoring for safety envelope violations in the master mobile body that are violations of the safety envelope of the expected functions set according to the driving strategy; sending scene information indicating the scene of the safety envelope violation to the remote center when a safety envelope violation is determined to have occurred; and receiving feedback information based on the scene information feedback from the remote center.
[0282] (Technical Feature 27)
[0283] Technical feature 27 is a processing method executed by a processor (12, 62) for performing driving-related processing of a primary mobile body (2, 3a) capable of communicating with a remote center (8), comprising: monitoring for safety envelope violations in the autonomous driving primary mobile body, wherein the safety envelope violation is a violation of the safety envelope of the expected function set according to the driving strategy; sending scene information indicating the scene of the safety envelope violation to the remote center when a safety envelope violation is determined to have occurred; and receiving feedback information based on the scene information feedback from the remote center.
[0284] (Technical Feature 28)
[0285] Technical feature 28 is a processing program stored in a storage medium (10, 60) for performing driving-related processing of a master mobile body (2, 3a) capable of communicating with a remote center (8), and includes commands for a processor (12, 62) to execute, the commands including: causing the processor to monitor for safety envelope violations in the master mobile body that are violations of the safety envelope of the intended functions set according to the driving strategy; causing the processor to send scene information indicating the scene of the safety envelope violation to the remote center when it is determined that a safety envelope violation has occurred; and causing the processor to receive feedback information based on the scene information feedback from the remote center.
[0286] (Technical Feature 29)
[0287] Technical feature 29 is a processing device (1a) that includes a processor (12) for performing driving-related processing of a master mobile body (2, 3a) capable of communicating with a target mobile body (3a, 2). The processor is configured to perform the following processing: monitoring for safety envelope violations in the master mobile body that are violations of the safety envelope of the expected functions set according to the driving strategy; generating scene information representing the scene of the safety envelope violation and sending it to the target mobile body when a safety envelope violation is determined to have occurred; and obtaining feedback information based on the scene information feedback from the target mobile body.
[0288] (Technical Feature 30)
[0289] Technical feature 30 is a processing method executed by a processor (12) for performing driving-related processing of a master mobile body (2, 3a) capable of communicating with a target mobile body (3a, 2), comprising: monitoring for safety envelope violations in the master mobile body that is an violation of a safety envelope that is set according to the safety of the expected function based on the driving strategy; generating scene information representing the scene of the safety envelope violation and sending it to the target mobile body if a safety envelope violation is determined to have occurred; and obtaining feedback information based on the scene information feedback from the target mobile body.
[0290] (Technical Feature 31)
[0291] Technical feature 31 is a processing program stored in a storage medium (10) for performing driving-related processing of a master mobile body (2, 3a) capable of communicating with a target mobile body (3a, 2), and containing commands for a processor (12) to execute, the commands including: causing the processor to monitor for safety envelope violations in the master mobile body that are autonomous driving, the safety envelope violations being violations of the safety envelope of the expected functions set according to the driving strategy; causing the processor to generate scene information representing the scene of the safety envelope violation and send it to the target mobile body when it is determined that a safety envelope violation has occurred; and causing the processor to obtain feedback information based on the scene information feedback from the target mobile body.
[0292] (Technical Feature 32)
[0293] Technical feature 32 is a communication device (6a) configured to communicate with a target mobile body (3a, 2) and to cooperate with the processing device (1a) of technical feature 29 to perform driving-related processing of the main mobile body (2, 3a), and includes a processor (62) configured to perform the following processing: sending scene information to the target mobile body when the processing device determines that a safety envelope violation has occurred in the main mobile body of autonomous driving; and receiving feedback information from the target mobile body.
[0294] (Technical Feature 33)
[0295] Technical feature 33 is a communication device (6a) configured to communicate with a target mobile body (3a, 2) and include a processor (62) for performing driving-related processing with the main mobile body (2, 3a). The processor is configured to perform the following processing: in the event of a safety envelope violation in the main mobile body operating in autonomous driving, sending scene information indicating a scenario of a safety envelope violation to the target mobile body, wherein the safety envelope violation is a violation of the safety envelope of the expected function set according to the driving strategy; and receiving feedback information based on scene information feedback from the target mobile body.
[0296] (Technical Feature 34)
[0297] Technical feature 34 is a processing method executed by a processor (62) for performing driving-related processing of a master mobile body (2, 3a) in a communication device (6a) capable of communicating with a target mobile body (3a, 2). The processing method includes: sending scene information indicating a scenario of a safety envelope violation to the target mobile body in the event of a safety envelope violation occurring in the master mobile body that is driving autonomously, wherein the safety envelope violation is a violation of the safety envelope of the expected function set according to the driving strategy; and receiving feedback information based on the scene information feedback from the target mobile body.
[0298] (Technical Feature 35)
[0299] Technical feature 35 is a processing program stored in a storage medium (60) for performing driving-related processing of the master mobile body (2, 3a) in a communication device (6a) capable of communicating with the target mobile body (3a, 2), and includes commands for a processor (62) to execute, the commands including: sending scene information indicating a safety envelope violation to the target mobile body in the event of a safety envelope violation in the master mobile body of autonomous driving, wherein the safety envelope violation is a violation of the safety envelope of the expected function set according to the driving strategy; and receiving feedback information from the target mobile body based on scene information feedback.
[0300] (Technical Feature 36)
[0301] Technical feature 36 is a processing system (1) that includes a processor (12, 62) for performing driving-related processing of a master mobile body (2, 3a) capable of communicating with a target mobile body (3a, 2). The processor is configured to perform the following processing: monitoring for safety envelope violations in the master mobile body that are violations of the safety envelope of the expected functions set according to the driving strategy; sending scene information indicating the scene of the safety envelope violation to the target mobile body when a safety envelope violation is determined to have occurred; and receiving feedback information based on the scene information feedback from the target mobile body.
[0302] (Technical Feature 37)
[0303] Technical feature 37 is a processing method executed by a processor (12, 62) for performing driving-related processing of a master mobile body (2, 3a) capable of communicating with a target mobile body (3a, 2), comprising: monitoring for safety envelope violations in the master mobile body that are violations of the safety envelope of the expected functions set according to the driving strategy; sending scene information indicating the scene of the safety envelope violation to the target mobile body when a safety envelope violation is determined to have occurred; and receiving feedback information based on the scene information feedback from the target mobile body.
[0304] (Technical Feature 38)
[0305] Technical feature 38 is a processing program stored in a storage medium (10, 60) for performing driving-related processing of a master mobile body (2, 3a) capable of communicating with a target mobile body (3a, 2), and containing commands for a processor (12, 62) to execute, the commands including: causing the processor to monitor for safety envelope violations in the master mobile body that are violations of the safety envelope of the expected functions set according to the driving strategy; causing the processor to send scene information indicating the scene of the safety envelope violation to the target mobile body when it determines that a safety envelope violation has occurred; and causing the processor to receive feedback information from the target mobile body based on the scene information feedback.
[0306] (Technical Feature 39)
[0307] Technical feature 39 is a processing device (1a) that includes a processor (12) for performing driving-related processing of a target mobile body (3a, 2) capable of communicating with a target mobile body (2, 3a). The processor is configured to perform the following processing: obtaining scene information from the target mobile body that is driving autonomously, representing a scenario of a safety envelope violation, wherein the safety envelope violation is a violation of the safety envelope of the expected function set according to the driving strategy; and generating feedback information based on the scene information feedback to send to the target mobile body.
[0308] (Technical Feature 40)
[0309] Technical feature 40 is a processing method for performing driving-related processing of a target mobile body (3a, 2) in a master mobile body (3a, 2) capable of communicating with a target mobile body (2, 3a), and the processing method executed by a processor (12) includes: obtaining scene information from the target mobile body that is driving autonomously, representing a scenario of a safety envelope violation, wherein the safety envelope violation is a violation of the safety envelope of the expected function set according to the driving strategy; and generating feedback information based on the scene information feedback to send to the target mobile body.
[0310] (Technical Feature 41)
[0311] Technical feature 41 is a processing program stored in storage medium (10) for performing driving-related processing of a target mobile body (3a, 2) capable of communicating with the target mobile body (2, 3a), and includes commands for a processor (12) to execute, the commands including: causing the processor to obtain scene information from the target mobile body for autonomous driving, representing a scenario of a safety envelope violation, the safety envelope violation being a violation of the safety envelope of the expected function set according to the driving strategy; and causing the processor to generate feedback information based on the scene information feedback to send to the target mobile body.
[0312] (Technical Feature 42)
[0313] Technical feature 42 is a communication device (6a) configured to communicate with a target mobile body (2, 3a) and to perform driving-related processing of the target mobile body in cooperation with the processing device (1a) of technical feature 39 in the main mobile body (3a, 2), and includes a processor (62) configured to perform the following processing: receiving scene information from the target mobile body of autonomous driving indicating a scenario of safety envelope violation; and sending feedback information to the target mobile body.
[0314] (Technical Feature 43)
[0315] Technical feature 43 is a communication device (6a) configured to communicate with a target mobile body (2, 3a) and include a processor (62) for performing driving-related processing of the target mobile body in a main mobile body (3a, 2). The processor is configured to perform the following processing: receiving scene information from the target mobile body that indicates a scenario of safety envelope violation, wherein the safety envelope violation is a violation of the safety envelope of the expected function set according to the driving strategy; and sending feedback information based on the scene information feedback to the target mobile body.
[0316] (Technical Feature 44)
[0317] Technical feature 44 is a processing method for performing driving-related processing of a target mobile body (3a, 2) in a communication device (6a) of a master mobile body (3a, 2) capable of communicating with the target mobile body (2, 3a), and the processing method executed by a processor (62) includes: receiving scene information from the target mobile body that is driving autonomously, indicating a scenario of a safety envelope violation, wherein the safety envelope violation is a violation of the safety envelope of the expected function set according to the driving strategy; and sending feedback information based on the scene information feedback to the target mobile body.
[0318] (Technical Feature 45)
[0319] Technical feature 45 is a processing program stored in a storage medium (60) for performing driving-related processing of a target mobile body (3a, 2) in a communication device (6a) of a master mobile body (3a, 2) capable of communicating with the target mobile body (2, 3a), and containing commands for a processor (62) to execute, the commands including: causing the processor to receive scene information from the target mobile body in autonomous driving, indicating a scenario of a safety envelope violation, the safety envelope violation being a violation of the safety envelope of the expected function set according to the driving strategy; and causing the processor to send feedback information based on the scene information feedback to the target mobile body.
[0320] (Technical Feature 46)
[0321] Technical feature 46 is a processing system (1) that includes a processor (12, 62) for performing driving-related processing of a target mobile body (3a, 2) capable of communicating with a target mobile body (2, 3a). The processor is configured to perform the following processing: receiving scene information from the target mobile body that indicates a scenario of safety envelope violation, wherein the safety envelope violation is a violation of the safety envelope of the expected function set according to the driving strategy; and sending feedback information based on the scene information feedback to the target mobile body.
[0322] (Technical Feature 47)
[0323] Technical feature 47 is a processing method for performing driving-related processing of a target mobile body (3a, 2) in a master mobile body (3a, 2) capable of communicating with a target mobile body (2, 3a), and the processing method executed by a processor (12, 62) includes: receiving scene information from the target mobile body that is autonomously driving, indicating a scenario of a safety envelope violation, wherein the safety envelope violation is a violation of the safety envelope of the expected function set according to the driving strategy; and sending feedback information based on the scene information feedback to the target mobile body.
[0324] (Technical Feature 48)
[0325] Technical feature 48 is a processing program stored in a storage medium (10, 60) for performing driving-related processing of a target mobile body (3a, 2) capable of communicating with the target mobile body (2, 3a), and containing commands for a processor (12, 62) to execute, the commands including: causing the processor to receive scene information from the target mobile body for autonomous driving, indicating a scenario of a safety envelope violation, the safety envelope violation being a violation of the safety envelope of the expected functions set according to the driving strategy; and causing the processor to send feedback information based on the scene information feedback to the target mobile body.
Claims
1. A processing apparatus comprising a processor for performing driving-related processing of a primary mobile body capable of communicating with a remote center, wherein... The processor described above is configured to perform the following processes: In the aforementioned main moving body of autonomous driving, a violation of the safety envelope is a violation of the safety envelope that is set according to the driving strategy to ensure the safety of the intended functions. If a security envelope violation is determined to have occurred, scenario information representing the scenario of the security envelope violation is generated and sent to the remote center; and Retrieve feedback information based on the scenario information from the aforementioned remote center. The aforementioned remote center is capable of communicating with the target mobile body, wherein the target mobile body is different from the aforementioned main mobile body. Generating the aforementioned scenario information includes: generating scenario information under high-frequency violation scenarios, wherein the aforementioned high-frequency violation scenarios are scenarios in which the frequency of occurrence of the aforementioned security envelope violation in the aforementioned main moving body is outside the allowable range. Obtaining the aforementioned feedback information includes: in high-frequency violation scenarios where the frequency of occurrence of the aforementioned safety envelope violation in the aforementioned target moving body is also outside the allowable range, obtaining the aforementioned feedback information based on the aforementioned scenario information feedback, so as to exclude the driving area of the aforementioned high-frequency violation scenario from the operation design area in autonomous driving.
2. The processing apparatus according to claim 1, wherein, The aforementioned main mobile unit manages and operates services through the aforementioned remote center. Obtaining the aforementioned feedback information includes: in high-frequency violation scenarios where the frequency of the aforementioned security envelope violation in the aforementioned target moving body is within an acceptable range, obtaining the aforementioned feedback information based on the aforementioned scenario information in order to stop the aforementioned operating service.
3. The processing apparatus according to claim 1 or 2, wherein, Generating the aforementioned scene information includes storing the generated scene information in the storage medium of the aforementioned main mobile body. Obtaining the above feedback information includes: in response to obtaining the above feedback information, deleting the above scenario information from the above storage medium.
4. A processing apparatus comprising a processor for performing driving-related processing of a primary mobile body capable of communicating with a remote center, wherein... The processor described above is configured to perform the following processes: In the aforementioned main moving body of autonomous driving, a violation of the safety envelope is a violation of the safety envelope that is set according to the driving strategy to ensure the safety of the intended functions. If a security envelope violation is determined to have occurred, scenario information representing the scenario of the security envelope violation is generated and sent to the remote center; and Retrieve feedback information based on the scenario information from the aforementioned remote center. The aforementioned remote center is capable of communicating with the target mobile body, wherein the target mobile body is different from the aforementioned main mobile body. The generation of the aforementioned scenario information includes: under a specific violation scenario in which the aforementioned safety envelope violation occurs in the aforementioned main moving body, the aforementioned driving setting constraints on the aforementioned safety envelope violation represented by the generated scenario information. Obtaining the aforementioned feedback information includes: in the aforementioned specific violation scenario where the aforementioned security envelope violation also occurs in the aforementioned target moving body, obtaining the aforementioned feedback information based on the aforementioned scenario information feedback, so as to allow the aforementioned constraints.
5. The processing apparatus according to claim 4, wherein, The aforementioned main mobile unit manages and operates services through the aforementioned remote center. Obtaining the aforementioned feedback information includes: in a specific violation scenario in which the aforementioned security envelope violation occurs in the aforementioned target mobile body, and in the case where the aforementioned security envelope violation does not occur in the aforementioned main mobile body, obtaining the aforementioned feedback information based on the aforementioned scenario information feedback, so as to provide the aforementioned operational service based on the instructions from the aforementioned remote center.
6. The processing apparatus according to claim 4 or 5, wherein, Generating the aforementioned scene information includes storing the generated scene information in the storage medium of the aforementioned main mobile body. Obtaining the above feedback information includes: in response to obtaining the above feedback information, deleting the above scenario information from the above storage medium.
7. A processing method, executed by a processor, for performing driving-related processing of a primary mobile body capable of communicating with a remote center, comprising: In the aforementioned main moving body of autonomous driving, a violation of the safety envelope is a violation of the safety envelope that is set according to the driving strategy to ensure the safety of the intended functions. If a security envelope violation is determined to have occurred, scenario information representing the scenario of the security envelope violation is generated and sent to the remote center; and Retrieve feedback information based on the scenario information from the aforementioned remote center. The aforementioned remote center is capable of communicating with the target mobile body, wherein, The target moving body mentioned above is different from the main moving body mentioned above. Generating the aforementioned scenario information includes: generating scenario information under high-frequency violation scenarios, wherein the aforementioned high-frequency violation scenarios are scenarios in which the frequency of occurrence of the aforementioned security envelope violation in the aforementioned main moving body is outside the allowable range. Obtaining the aforementioned feedback information includes: in high-frequency violation scenarios where the frequency of occurrence of the aforementioned safety envelope violation in the aforementioned target moving body is also outside the allowable range, obtaining the aforementioned feedback information based on the aforementioned scenario information feedback, so as to exclude the driving area of the aforementioned high-frequency violation scenario from the operation design area in autonomous driving.
8. A processing method, executed by a processor, for performing driving-related processing of a primary mobile body capable of communicating with a remote center, comprising: In the aforementioned main moving body of autonomous driving, a violation of the safety envelope is a violation of the safety envelope that is set according to the driving strategy to ensure the safety of the intended functions. If a security envelope violation is determined to have occurred, scenario information representing the scenario of the security envelope violation is generated and sent to the remote center; and Retrieve feedback information based on the scenario information from the aforementioned remote center. The aforementioned remote center is capable of communicating with the target mobile body, wherein, The target moving body mentioned above is different from the main moving body mentioned above. The generation of the aforementioned scenario information includes: under a specific violation scenario in which the aforementioned safety envelope violation occurs in the aforementioned main moving body, the aforementioned driving setting constraints on the aforementioned safety envelope violation represented by the generated scenario information. Obtaining the aforementioned feedback information includes: in the aforementioned specific violation scenario where the aforementioned security envelope violation also occurs in the aforementioned target moving body, obtaining the aforementioned feedback information based on the aforementioned scenario information feedback, so as to allow the aforementioned constraints.
9. A storage medium storing a processing program, said processing program being stored in the storage medium for performing driving-related processing of a main mobile body capable of communicating with a remote center, and comprising commands for a processor to execute, wherein, The above commands include: The processor is configured to monitor for violations of the safety envelope in the aforementioned main moving body during autonomous driving, where such violations are violations of the safety envelope that are intended to ensure the safety of the functions defined by the driving strategy. If the processor determines that a security envelope violation has occurred, it generates scenario information representing the scenario of the security envelope violation and sends it to the remote center; and The processor is then instructed to obtain feedback information from the remote center based on the scenario information. The aforementioned remote center is capable of communicating with the target mobile body, wherein the target mobile body is different from the aforementioned main mobile body. Generating the aforementioned scenario information includes: causing the processor to generate the aforementioned scenario information under high-frequency violation scenarios, wherein the aforementioned high-frequency violation scenarios are scenarios in which the frequency of occurrence of the aforementioned security envelope violation in the aforementioned main mobile body is outside the allowable range. Obtaining the aforementioned feedback information includes: in high-frequency violation scenarios where the frequency of the aforementioned safety envelope violation by the aforementioned processor in the aforementioned target moving body is also outside the allowable range, obtaining the aforementioned feedback information based on the aforementioned scenario information feedback, so as to exclude the driving area of the aforementioned high-frequency violation scenario from the operation design area in autonomous driving.
10. A storage medium storing a processing program, said processing program being stored in the storage medium for performing driving-related processing of a main mobile body capable of communicating with a remote center, and comprising commands for a processor to execute, wherein, The above commands include: The processor is configured to monitor for violations of the safety envelope in the aforementioned main moving body during autonomous driving, where such violations are violations of the safety envelope that are intended to ensure the safety of the functions defined by the driving strategy. If the processor determines that a security envelope violation has occurred, it generates scenario information representing the scenario of the security envelope violation and sends it to the remote center; and The processor is then instructed to obtain feedback information from the remote center based on the scenario information. The aforementioned remote center is capable of communicating with the target mobile body, wherein the target mobile body is different from the aforementioned main mobile body. The generation of the aforementioned scenario information includes: under a specific violation scenario in which the processor causes the aforementioned safety envelope violation in the aforementioned main moving body, the aforementioned driving setting constraints on the aforementioned safety envelope violation represented by the generated scenario information. Obtaining the aforementioned feedback information includes: in the specific violation scenario where the processor also causes the aforementioned security envelope violation in the aforementioned target moving body, obtaining the aforementioned feedback information based on the aforementioned scenario information feedback, so as to allow the aforementioned constraints.
11. A processing apparatus comprising a processor for performing driving-related processing of a primary mobile body in a remote center capable of communicating with the primary mobile body, wherein... The processor described above is configured to perform the following processes: Scene information representing a violation of the safety envelope is obtained from the aforementioned main mobile body of autonomous driving. The violation of the safety envelope is a violation of the safety envelope of the expected function set according to the driving strategy. as well as Feedback information based on the aforementioned scenario information is generated and sent to the aforementioned main mobile body. The aforementioned remote center is capable of communicating with the first mobile body and the second mobile body, which are the aforementioned main mobile bodies. Obtaining the aforementioned scene information includes: if the scene information is obtained from the first moving body, also obtaining the scene information from the second moving body. The generation of the above feedback information includes: in the case of a high-frequency violation scenario where the frequency of the above safety envelope violation in the first mobile body is outside the allowable range, and in the case where the frequency of the above safety envelope violation in the second mobile body is also outside the allowable range, generating the above feedback information based on the above scenario information feedback, so as to exclude the driving area of the above high-frequency violation scenario from the operation design area of the autonomous driving of the first mobile body and the second mobile body respectively.
12. The processing apparatus according to claim 11, wherein, The aforementioned remote center manages the operational services of the aforementioned first mobile unit. Generating the above feedback information includes: in the above high-frequency violation scenario, when the frequency of the above security envelope violation in the above second mobile body is within an allowable range, generating the above feedback information based on the above scenario information feedback, so as to stop the above operation service of the above first mobile body.
13. The processing apparatus according to claim 11 or 12, wherein, The generation of the above feedback information includes: generating the above feedback information in response to obtaining the above scenario information.
14. The processing apparatus according to claim 11 or 12, wherein, Obtaining the aforementioned scenario information includes: storing the scenario information acquired at multiple times in the storage medium of the aforementioned remote center. The generation of the above feedback information includes: generating the above feedback information based on statistical analysis of the above scene information at the above multiple times stored in the above storage medium.
15. The processing apparatus according to claim 14, wherein, Generating the above feedback information includes: in response to the generation or transmission of the above feedback information, deleting the above scene information at the above multiple times from the above storage medium.
16. A processing apparatus comprising a processor for performing driving-related processing of a primary mobile body in a remote center capable of communicating with the primary mobile body, wherein... The processor described above is configured to perform the following processes: Scene information representing a violation of the safety envelope is obtained from the aforementioned main mobile body of autonomous driving. The violation of the safety envelope is a violation of the safety envelope of the expected function set according to the driving strategy. as well as Feedback information based on the aforementioned scenario information is generated and sent to the aforementioned main mobile body. The aforementioned remote center is capable of communicating with the first mobile body and the second mobile body, which are the aforementioned main mobile bodies. Obtaining the aforementioned scene information includes: if the scene information is obtained from the first moving body, also obtaining the scene information from the second moving body. The generation of the above feedback information includes: when a specific violation scenario of the above safety envelope violation occurs in the first mobile body, and the above safety envelope violation also occurs in the second mobile body, generating the above feedback information based on the scenario information feedback, so as to allow the restriction of the above driving settings for the above safety envelope violation in each of the first mobile body and the second mobile body.
17. The processing apparatus according to claim 16, wherein, The aforementioned remote center manages the operational services of the aforementioned first mobile unit. The generation of the above feedback information includes: when a specific violation scenario of the above security envelope violation occurs in the above second mobile body, and when the above security envelope violation does not occur in the above first mobile body, generating the above feedback information based on the above scenario information feedback, so that the above first mobile body provides the above operation service according to the instructions from the above remote center.
18. The processing apparatus according to claim 16 or 17, wherein, The generation of the above feedback information includes: generating the above feedback information in response to obtaining the above scenario information.
19. The processing apparatus according to claim 16 or 17, wherein, Obtaining the aforementioned scenario information includes: storing the scenario information acquired at multiple times in the storage medium of the aforementioned remote center. The generation of the above feedback information includes: generating the above feedback information based on statistical analysis of the above scene information at the above multiple times stored in the above storage medium.
20. The processing apparatus according to claim 19, wherein, Generating the above feedback information includes: in response to the generation or transmission of the above feedback information, deleting the above scene information at the above multiple times from the above storage medium.
21. A processing method, executed by a processor, for performing driving-related processing of the main mobile body in a remote center capable of communicating with the main mobile body, comprising: Scene information representing a violation of the safety envelope is obtained from the aforementioned main moving body in autonomous driving. This safety envelope violation is a violation of the safety envelope that defines the intended safety of the functions according to the driving strategy. Feedback information based on the aforementioned scenario information is generated and sent to the aforementioned main mobile body. Obtaining the aforementioned scene information includes: if the scene information is obtained from the first moving body, which is the primary moving body, the scene information is also obtained from the second moving body, which is the primary moving body. The generation of the above feedback information includes: in the case of a high-frequency violation scenario where the frequency of the above safety envelope violation in the first mobile body is outside the allowable range, and in the case where the frequency of the above safety envelope violation in the second mobile body is also outside the allowable range, generating the above feedback information based on the above scenario information feedback, so as to exclude the driving area of the above high-frequency violation scenario from the operation design area of the autonomous driving of the first mobile body and the second mobile body respectively.
22. A processing method, executed by a processor, for performing driving-related processing of the main mobile body in a remote center capable of communicating with the main mobile body, comprising: Scene information representing a violation of the safety envelope is obtained from the aforementioned main moving body in autonomous driving. This safety envelope violation is a violation of the safety envelope that defines the intended safety of the functions according to the driving strategy. Feedback information based on the aforementioned scenario information is generated and sent to the aforementioned main mobile body. Obtaining the aforementioned scene information includes: if the scene information is obtained from the first moving body, which is the primary moving body, the scene information is also obtained from the second moving body, which is the primary moving body. The generation of the above feedback information includes: when a specific violation scenario of the above safety envelope violation occurs in the first mobile body, and the above safety envelope violation also occurs in the second mobile body, generating the above feedback information based on the scenario information feedback, so as to allow the restriction of the above driving settings for the above safety envelope violation in each of the first mobile body and the second mobile body.
23. A storage medium storing a processing program, the processing program being stored in the storage medium for executing driving-related processing of the main mobile body in a remote center capable of communicating with the main mobile body, and comprising commands for a processor to execute, wherein... The above commands include: The processor obtains scene information from the main mobile body of the autonomous driving system, which represents a scenario where the safety envelope is violated. The violation of the safety envelope is a violation of the safety envelope of the intended function set according to the driving strategy. as well as The processor generates feedback information based on the scenario information and sends it to the main mobile body. Obtaining the aforementioned scene information includes: enabling the processor to obtain the aforementioned scene information from the second mobile body, which is also the primary mobile body, when the processor has already obtained the aforementioned scene information from the first mobile body, which is also the primary mobile body. Generating the aforementioned feedback information includes: generating the aforementioned feedback information based on the aforementioned scenario information feedback when the frequency of the aforementioned safety envelope violation in the first mobile body is outside the allowable range, and when the frequency of the aforementioned safety envelope violation in the second mobile body is also outside the allowable range, so as to exclude the driving area of the aforementioned high-frequency violation scenario from the operation design area of the respective first mobile body and the second mobile body in the autonomous driving.
24. A storage medium storing a processing program, the processing program being stored in the storage medium for executing driving-related processing of the main mobile body in a remote center capable of communicating with the main mobile body, and comprising commands for a processor to execute, wherein... The above commands include: The processor obtains scene information from the main mobile body of the autonomous driving system, which represents a scenario where the safety envelope is violated. The violation of the safety envelope is a violation of the safety envelope of the intended function set according to the driving strategy. as well as The processor generates feedback information based on the scenario information and sends it to the main mobile body. Obtaining the aforementioned scene information includes: enabling the processor to obtain the aforementioned scene information from the second mobile body, which is also the primary mobile body, when the processor has already obtained the aforementioned scene information from the first mobile body, which is also the primary mobile body. The generation of the above feedback information includes: when a specific violation scenario of the above safety envelope violation occurs in the first mobile body, and the above safety envelope violation also occurs in the second mobile body, the processor generates the above feedback information based on the scenario information feedback, so as to allow the restriction of the above driving settings for the above safety envelope violation in each of the first mobile body and the second mobile body.
25. A processing system comprising a first processor of the main mobile unit and a second processor of the remote center for performing driving-related processing of a main mobile unit capable of communicating with a remote center, wherein... The aforementioned first processor is configured to execute: In the aforementioned main moving body of autonomous driving, a violation of the safety envelope is a violation of the safety envelope that is set according to the driving strategy to ensure the safety of the intended functions. as well as If a security envelope violation is determined to have occurred, scenario information representing the scenario of the security envelope violation is generated and sent from the main mobile body to the remote center. The aforementioned second processor is configured to execute: Feedback information based on the aforementioned scenario information is generated and sent from the aforementioned remote center to the aforementioned main mobile entity. The aforementioned remote center is capable of communicating with the target mobile body, wherein the target mobile body is different from the aforementioned main mobile body. Generating the aforementioned scenario information includes: generating scenario information under high-frequency violation scenarios, wherein the aforementioned high-frequency violation scenarios are scenarios in which the frequency of occurrence of the aforementioned security envelope violation in the aforementioned main moving body is outside the allowable range. Obtaining the aforementioned feedback information includes: in high-frequency violation scenarios where the frequency of occurrence of the aforementioned safety envelope violation in the aforementioned target moving body is also outside the allowable range, obtaining the aforementioned feedback information based on the aforementioned scenario information feedback, so as to exclude the driving area of the aforementioned high-frequency violation scenario from the operation design area in autonomous driving.
26. A processing system comprising a first processor of the main mobile unit and a second processor of the remote center for performing driving-related processing of a main mobile unit capable of communicating with a remote center, wherein... The aforementioned first processor is configured to execute: In the aforementioned main moving body of autonomous driving, a violation of the safety envelope is a violation of the safety envelope that is set according to the driving strategy to ensure the safety of the intended functions. as well as If a security envelope violation is determined to have occurred, scenario information representing the scenario of the security envelope violation is generated and sent from the main mobile body to the remote center. The aforementioned second processor is configured to execute: Feedback information based on the aforementioned scenario information is generated and sent from the aforementioned remote center to the aforementioned main mobile entity. The aforementioned remote center is capable of communicating with the target mobile body, wherein the target mobile body is different from the aforementioned main mobile body. The generation of the aforementioned scenario information includes: under a specific violation scenario in which the aforementioned safety envelope violation occurs in the aforementioned main moving body, the aforementioned driving setting constraints on the aforementioned safety envelope violation represented by the generated scenario information. Obtaining the aforementioned feedback information includes: in the aforementioned specific violation scenario where the aforementioned security envelope violation also occurs in the aforementioned target moving body, obtaining the aforementioned feedback information based on the aforementioned scenario information feedback, so as to allow the aforementioned constraints.
27. A processing method for performing driving-related processing of a primary mobile unit capable of communicating with a remote center, wherein the processing method is executed through the cooperation of a first processor of the primary mobile unit and a second processor of the remote center, comprising: In the aforementioned main moving body of autonomous driving, a violation of the safety envelope is a violation of the safety envelope that is set according to the driving strategy to ensure the safety of the intended functions. as well as If it is determined that the above-mentioned security envelope violation has occurred, scenario information representing the scenario of the security envelope violation is generated and sent from the above-mentioned main mobile body to the above-mentioned remote center. as well as Feedback information based on the aforementioned scenario information is generated and sent from the aforementioned remote center to the aforementioned main mobile entity. The aforementioned remote center is capable of communicating with the target mobile body, wherein the target mobile body is different from the aforementioned main mobile body. Generating the aforementioned scenario information includes: generating scenario information under high-frequency violation scenarios, wherein the aforementioned high-frequency violation scenarios are scenarios in which the frequency of occurrence of the aforementioned security envelope violation in the aforementioned main moving body is outside the allowable range. Obtaining the aforementioned feedback information includes: in high-frequency violation scenarios where the frequency of occurrence of the aforementioned safety envelope violation in the aforementioned target moving body is also outside the allowable range, obtaining the aforementioned feedback information based on the aforementioned scenario information feedback, so as to exclude the driving area of the aforementioned high-frequency violation scenario from the operation design area in autonomous driving.
28. A processing method for performing driving-related processing of a primary mobile unit capable of communicating with a remote center, wherein the processing method is executed through the cooperation of a first processor of the primary mobile unit and a second processor of the remote center, comprising: In the aforementioned main moving body of autonomous driving, a violation of the safety envelope is a violation of the safety envelope that is set according to the driving strategy to ensure the safety of the intended functions. as well as If it is determined that the above-mentioned security envelope violation has occurred, scenario information representing the scenario of the security envelope violation is generated and sent from the above-mentioned main mobile body to the above-mentioned remote center. as well as Feedback information based on the aforementioned scenario information is generated and sent from the aforementioned remote center to the aforementioned main mobile entity. The aforementioned remote center is capable of communicating with the target mobile body, wherein the target mobile body is different from the aforementioned main mobile body. The generation of the aforementioned scenario information includes: under a specific violation scenario in which the aforementioned safety envelope violation occurs in the aforementioned main moving body, the aforementioned driving setting constraints on the aforementioned safety envelope violation represented by the generated scenario information. Obtaining the aforementioned feedback information includes: in the aforementioned specific violation scenario where the aforementioned security envelope violation also occurs in the aforementioned target moving body, obtaining the aforementioned feedback information based on the aforementioned scenario information feedback, so as to allow the aforementioned constraints.
29. A storage medium storing a processing program, the processing program being stored in at least one of a first storage medium of the main mobile body and a second storage medium of the remote center for performing driving-related processing of a main mobile body capable of communicating with a remote center, and comprising commands for cooperating execution by a first processor of the main mobile body and a second processor of the remote center, wherein... The above command causes the first processor and the second processor to perform the following processing: In the aforementioned main moving body of autonomous driving, a violation of the safety envelope is a violation of the safety envelope that is set according to the driving strategy to ensure the safety of the intended functions. If it is determined that the above-mentioned security envelope violation has occurred, scenario information representing the scenario of the security envelope violation is generated and sent from the above-mentioned main mobile body to the above-mentioned remote center. as well as Feedback information based on the aforementioned scenario information is generated and sent from the aforementioned remote center to the aforementioned main mobile entity. The aforementioned storage medium is at least one of the first storage medium of the aforementioned main mobile unit and the second storage medium of the aforementioned remote center. The aforementioned remote center is capable of communicating with the target mobile body, wherein the target mobile body is different from the aforementioned main mobile body. Generating the aforementioned scenario information includes: generating scenario information under high-frequency violation scenarios, wherein the aforementioned high-frequency violation scenarios are scenarios in which the frequency of occurrence of the aforementioned security envelope violation in the aforementioned main moving body is outside the allowable range. Obtaining the aforementioned feedback information includes: in high-frequency violation scenarios where the frequency of occurrence of the aforementioned safety envelope violation in the aforementioned target moving body is also outside the allowable range, obtaining the aforementioned feedback information based on the aforementioned scenario information feedback, so as to exclude the driving area of the aforementioned high-frequency violation scenario from the operation design area in autonomous driving.
30. A storage medium storing a processing program, the processing program being stored in at least one of a first storage medium of the main mobile body and a second storage medium of the remote center for performing driving-related processing of a main mobile body capable of communicating with a remote center, and comprising commands for cooperating execution by a first processor of the main mobile body and a second processor of the remote center, wherein... The above command causes the first processor and the second processor to perform the following processing: In the aforementioned main moving body of autonomous driving, a violation of the safety envelope is a violation of the safety envelope that is set according to the driving strategy to ensure the safety of the intended functions. If it is determined that the above-mentioned security envelope violation has occurred, scenario information representing the scenario of the security envelope violation is generated and sent from the above-mentioned main mobile body to the above-mentioned remote center. as well as Feedback information based on the aforementioned scenario information is generated and sent from the aforementioned remote center to the aforementioned main mobile entity. The aforementioned storage medium is at least one of the first storage medium of the aforementioned main mobile unit and the second storage medium of the aforementioned remote center. The aforementioned remote center is capable of communicating with the target mobile body, wherein the target mobile body is different from the aforementioned main mobile body. The generation of the aforementioned scenario information includes: under a specific violation scenario in which the aforementioned safety envelope violation occurs in the aforementioned main moving body, the aforementioned driving setting constraints on the aforementioned safety envelope violation represented by the generated scenario information. Obtaining the aforementioned feedback information includes: in the aforementioned specific violation scenario where the aforementioned security envelope violation also occurs in the aforementioned target moving body, obtaining the aforementioned feedback information based on the aforementioned scenario information feedback, so as to allow the aforementioned constraints.
Citation Information
Patent Citations
Semiconductor device
JP2021015885A
Remote monitoring system and an autonomous runninig vehicle and remote monitoring method
US20190137999A1