Authentication device and authentication method

By adjusting the collision risk judgment conditions in the processor and assuming that the track of the moving body in the lane is part of the lane, the problems of high load and frequent over-response in the prior art are solved, and more reasonable handling of the moving body and safe driving are achieved.

CN120476066APending Publication Date: 2025-08-12DENSO CORP
View PDF 2 Cites 0 Cited by

Patent Information

Application Number
CN202380090614.0
Authority / Receiving Office
CN · China
Patent Type
Applications(China)
Current Assignee / Owner
Priority Date
2023-01-09
Filing Date
2023-09-26
Publication Date
2025-08-12

AI Technical Summary

Technical Problem

When there are motorcycles, bicycles, pedestrians and other moving bodies in the lane where the vehicle is traveling, it is difficult for the prior art to reasonably handle the tracks of these moving bodies, resulting in high processor load and frequent over-response of the vehicle, affecting driving safety.

Method used

By assuming in the processor that the tracks of these moving bodies are part of the included lane, the collision risk judgment conditions are adjusted so that they are processed differently from the lane of the vehicle, so as to reasonably handle the behavior of the moving bodies and reduce the load on the processor, and suppress excessive response.

Benefits of technology

It improves the handling suitability of moving bodies in the lane, reduces processor load, suppresses excessive response of the vehicle, and improves driving safety.

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure CN120476066A_ABST
    Figure CN120476066A_ABST
Patent Text Reader

Abstract

The invention relates to a confirmation device and a confirmation method. An RSS unit (53) as a confirmation device is provided with a processor (53b) for driving a vehicle (1). A processor (53b) executes the following: assuming that a trajectory on which a motorcycle (SO1), which is predicted to be a moving body that travels within a lane (LA) in which a vehicle (1) is present, will travel, is included within the lane (LA); and confirming the risk of collision between the vehicle (1) and the motorcycle (SO1) on the basis of processing a travel road (DR), which is a region occupied by the track, as a lane different from the lane (LA) in which the vehicle (1) is present.
Need to check novelty before this filing date? Find Prior Art

Description

[0001] CROSS-REFERENCE TO RELATED APPLICATIONS

[0002] This application is based on Japanese Patent Application No. 2023-1415 filed in Japan on January 9, 2023, and the contents of the basic application are incorporated herein by reference in their entirety. Technical Field

[0003] The disclosure of this specification relates to driving a vehicle. Background Art

[0004] In Patent Document 1, a processor predicts the trajectory of a moving object around the vehicle and determines whether a risk value indicating the risk of collision between the vehicle and the moving object exceeds a predefined risk threshold. Based on the determination that the collision risk exceeds the risk threshold, the processor generates information used to determine the vehicle's safe driving state. For example, in this risk-related determination, if the detected distance between the vehicle and the moving object falls below a minimum safe distance, the vehicle is determined to be unsafe.

[0005] Patent Document 1: U.S. Patent Application Publication No. 2021 / 0009121

[0006] Furthermore, on roads in congested conditions, emerging countries, and densely populated areas, for example, mobile objects such as motorcycles, bicycles, and pedestrians may sometimes travel in the same lane as a vehicle. In such scenarios, if the collision risk with a mobile object is determined using the same conditions as for a normal vehicle, there is a concern that excessive vehicle responses may occur frequently. Furthermore, there is a concern that the processing load associated with the collision risk of the mobile object may increase. Summary of the Invention

[0007] One of the objectives of the disclosure of this specification is to provide a confirmation device and a confirmation method that improve the appropriateness of handling a mobile object traveling across a lane.

[0008] One method disclosed herein is a device for confirming driving of a vehicle (1) having at least one processor (53b), wherein:

[0009] The above processor performs the following:

[0010] Assuming that the trajectory of the mobile body predicted to travel through the lane where the vehicle exists is included in the lane; and

[0011] The risk of collision between the vehicle and the moving object is confirmed after treating at least a portion of the area occupied by the track as a lane different from the lane in which the vehicle is present.

[0012] In addition, another disclosed method is a method for determining a collision risk of a vehicle executed by at least one processor, comprising:

[0013] Assuming that the trajectory of a mobile object predicted to travel within a lane where a vehicle exists is included in the lane; and

[0014] The risk of collision between the vehicle and the moving object is confirmed after treating at least a portion of the area occupied by the track as a lane different from the lane in which the vehicle is present.

[0015] According to these methods, the area occupied by the trajectory of a mobile object traveling through a lane occupied by a vehicle is treated as a lane separate from the lane occupied by the vehicle. This allows for the proper handling of the predicted behavior of the traveling mobile object and reduces the processor load caused by handling the congestion of many mobile objects in the same lane. Furthermore, it can suppress the frequent occurrence of excessive vehicle responses that may result from risk identification. This improves the appropriateness of handling of the mobile object when identifying the risk of collision with the mobile object traveling through the lane.

[0016] In addition, another disclosed method is a device for confirming driving of a vehicle, comprising at least one processor, wherein:

[0017] The processor performs the following:

[0018] Identify the collision risk between the vehicle and other road users;

[0019] If it is determined that the collision risk is higher than a predetermined threshold, determining whether to execute an appropriate response including braking;

[0020] When the other road user is in the same lane as the vehicle, the collision risk is determined to be higher than when the other road user is in a different lane from the vehicle;

[0021] As other road users, it is assumed that there is a moving object traveling in the lane where the vehicle exists; and

[0022] Even if a moving object exists in a lane where a vehicle exists, in the judgment of the collision risk, it is treated as if the moving object exists in a lane different from the lane where the vehicle exists.

[0023] According to this method, the collision risk assessment for a passing mobile object is based on the condition that the collision risk is judged to be lower, similar to that for other road users in a different lane from the vehicle. As a result, the probability of the collision risk being judged to be higher than a preset threshold is low, making it difficult to determine whether to take an appropriate response, including braking. This can prevent the frequent occurrence of excessive responses to passing mobile objects. This improves the appropriateness of handling of such mobile objects when determining the collision risk with them in a lane.

[0024] In addition, the reference numerals in parentheses included in the claims and the like are provided for illustrative purposes only to indicate the correspondence with parts of the embodiments described later, and are not intended to limit the technical scope. BRIEF DESCRIPTION OF THE DRAWINGS

[0025] Figure 1 This is a diagram showing a schematic configuration of a driving system.

[0026] Figure 2 This is a diagram showing the hardware configuration of the driving system.

[0027] Figure 3 This is a diagram used to illustrate the longitudinal safety distance.

[0028] Figure 4 This is a diagram showing a calculation formula related to the longitudinal safety distance.

[0029] Figure 5 This is a diagram used to illustrate the longitudinal safety distance.

[0030] Figure 6 This is a diagram showing a calculation formula related to the longitudinal safety distance.

[0031] Figure 7 This is a diagram for explaining the lateral safety distance.

[0032] Figure 8 This is a diagram showing a calculation formula related to the lateral safety distance.

[0033] Figure 9 This is a diagram showing the coordinate system of lane references.

[0034] Figure 10 This is a flowchart illustrating processing by the driving system.

[0035] Figure 11 This is a diagram showing an example of a scene in which a moving object is passing.

[0036] Figure 12 This is a diagram showing calculation formulas related to assumptions about the travel route.

[0037] Figure 13This is a diagram showing calculation formulas related to assumptions about the travel route.

[0038] Figure 14 This is a diagram showing an example of a scene in which a moving object is passing.

[0039] Figure 15 This is a diagram showing calculation formulas related to assumptions about the travel route.

[0040] Figure 16 This is a diagram showing an example of a scene in which a moving object is passing.

[0041] Figure 17 This is a diagram showing an example of a scene in which a moving object is passing.

[0042] Figure 18 This is a diagram showing an example of a scene in which a moving object is assumed to pass through.

[0043] Figure 19 This is a diagram showing an example of a scene in which a moving object is assumed to pass through.

[0044] Figure 20 This is a flowchart illustrating processing by the driving system.

[0045] Figure 21 This is a diagram showing a schematic configuration of a driving system.

[0046] Figure 22 This is a diagram showing a schematic configuration of a driving system.

[0047] Figure 23 It is a state transition diagram showing the state transition of the vehicle.

[0048] Figure 24 This is a diagram showing an example of a scene in which a moving object is assumed to pass through.

[0049] Figure 25 This is a diagram showing an example of a scene in which a moving object is assumed to pass through.

[0050] Figure 26 This is a diagram showing an example of a scene in which a moving object is passing.

[0051] Figure 27 This is a diagram showing an example of a scene in which a moving object is passing. DETAILED DESCRIPTION

[0052] Hereinafter, a plurality of embodiments will be described based on the accompanying drawings. In addition, sometimes, repeated descriptions are omitted by marking corresponding components in each embodiment with the same reference numerals. When only a portion of a structure is described in each embodiment, the structure of other embodiments previously described can be applied to the other parts of the structure. In addition, not only the combinations of structures explicitly described in the description of each embodiment, but also the structures of multiple embodiments can be partially combined with each other even if not explicitly described, as long as there is no particular hindrance in the combination.

[0053] In the following multiple embodiments, the contents of “Safety First for Automated Driving” Tech.Rep., 2019. by Aptiv, Audi, Baidu, BMW, Continental, Daimler, FCA, here, Infineon, Intel, and Volkswagen, “On a formal model of safe and scalable self-driving cars,” arXiv:1708.06374, 2017. by S. Shalev-Shwartz, S. Shammah, and A. Shashua, and “The Safety Force Field” Technical report, 2019. by David Nister, Hon-Leung Lee, Julia Ng, and Yizhou Wang, and the contents of IEEE 2846-2022 are cited as a whole by reference.

[0054] (First embodiment)

[0055] Figure 1 、 2 The driving system 2 of the first embodiment shown implements functions related to driving a mobile object. A portion or all of the driving system 2 is mounted on the mobile object. The mobile object processed by the driving system 2 is a vehicle 1. Vehicle 1 may be referred to as a host vehicle, a host vehicle, or the like. Vehicle 1 may also be configured to communicate directly or indirectly via a communication infrastructure with other vehicles, etc. These other vehicles may be referred to as target vehicles.

[0056] Vehicle 1 can be, for example, a four-wheeled car or truck, which can be driven manually by a road user. Vehicle 1 can also be capable of automated driving. Driving is graded based on the extent to which the driver performs all dynamic driving tasks (DDT). Automated driving levels are defined, for example, by SAE J3016. In levels 0 to 2, the driver performs part or all of the DDT. Levels 0 to 2 can also be classified as so-called manual driving. Level 0 indicates that driving is not automated. Level 1 indicates that the driving system 2 assists the driver. Level 2 indicates that driving is partially automated.

[0057] At Level 3 and above, the driving system 2 performs all DDT while engaged. Levels 3 to 5 can also be categorized as so-called automated driving. Systems capable of performing Level 3 and above driving are referred to as automated driving systems. Vehicles equipped with automated driving systems, or vehicles capable of performing Level 3 and above driving, are referred to as automated vehicles (AVs). Level 3 indicates conditional driving automation. Level 4 indicates highly automated driving. Level 5 indicates fully automated driving.

[0058] Furthermore, a driving system 2 that is incapable of driving at levels 3 or higher but capable of driving at least one of levels 1 and 2 may be referred to as a driving assistance system. Hereinafter, when there is little need to specifically specify the achievable level of autonomous driving, the autonomous driving system or driving assistance system may be referred to simply as the driving system 2.

[0059] <Drive System Overview>

[0060] The architecture of driving system 2 is selected to enable efficient SOTIF (safety of the intended functionality) processes. For example, the architecture of driving system 2 can be based on a sense-plan-act model. The sense-plan-act model includes detection, planning, and action elements as key system elements. These elements interact with each other. Here, "detection" can be replaced by "perception," "planning" by "judgment," and "action" by "control."

[0061] In such a driving system 2, at a functional level (in other words, from a functional perspective), a detection function, a planning function, and an action function are implemented. At a technical level (in other words, from a technical perspective), at least a plurality of sensors corresponding to the detection function, at least one processing system corresponding to the planning function, and a plurality of motion actuators 60 corresponding to the action function are implemented.

[0062] Specifically, the driving system 2 can be configured as a detection unit 10, a functional module implementing a detection function, mainly composed of multiple sensors, a processing system that processes the detection information from the multiple sensors, and a processing system that generates an environment model based on the information from the multiple sensors. The driving system 2 can be configured as a planning unit 20 and RSS 26, functional modules implementing a planning function, mainly composed of the processing system 50. The driving system 2 can be configured as an action unit 30, a functional module implementing an action function, mainly composed of multiple motion actuators 60 and at least one processing system that outputs motion signals for the multiple motion actuators 60.

[0063] Here, the detection unit 10 can also be implemented as a detection system as a subsystem that is distinguishable from the planning unit 20 and the action unit 30. The planning unit 20 can also be implemented as a planning system as a subsystem that is distinguishable from the detection unit 10 and the action unit 30. The planning system can also include RSS26. The action unit 30 can also be implemented as an action system as a subsystem that is distinguishable from the detection unit 10 and the planning unit 20. The detection system, the planning system, and the action system can also be configured as independent components. The so-called system here can also be replaced by a module, a unit, a device, etc.

[0064] Furthermore, vehicle 1 may be equipped with multiple HMI (Human Machine Interface) devices 70. HMI devices 70 enable interaction between vehicle 1 occupants (including the driver) and driving system 2, also known as human-machine interaction. The portion of HMI devices 70 that implements occupant input functions may also be part of detection unit 10. The portion of HMI devices 70 that implements information presentation functions may also be part of action unit 30. Alternatively, the functions implemented by HMI devices 70 may be positioned as independent of the detection, planning, and action functions.

[0065] The detection unit 10 is responsible for detecting functions including the positioning (e.g., estimated position) of vehicle 1 and other road users. The detection unit 10 detects the external environment, internal environment, vehicle status, and the status of the driving system 2 of vehicle 1. The detection unit 10 fuses the detected information to generate an environmental model. This environmental model can also be called a world model. The planning unit 20 applies its objectives and driving policy to the environmental model generated by the detection unit 10 to derive control actions. The action unit 30 executes the control actions derived by the planning unit 20.

[0066] <Physical Architecture Overview>

[0067] use Figure 2 , an example of the physical architecture of the driving system 2 is described. The driving system 2 includes a plurality of sensors, a plurality of motion actuators 60, a plurality of HMI devices 70, and at least one processing system 50. These components can communicate with each other through one or both of wireless connections and wired connections. These components can also communicate with each other through an in-vehicle network based on CAN (registered trademark), etc. Figure 2 These components will be described in more detail.

[0068] The plurality of sensors include one or more external environment sensors 41 . The plurality of sensors may also include at least one of one or more internal environment sensors 42 , one or more communication systems 43 , and a map DB (database) 44 .

[0069] The external environment sensor 41 can also detect objects in the environment outside the vehicle 1. Examples of target-detecting external environment sensors 41 include cameras, LiDAR (Light Detection and Ranging / Laser Imaging Detection and Ranging), millimeter-wave radar, and ultrasonic sonar. Typically, a combination of multiple external environment sensors 41 is installed to monitor the front, sides, and rear of the vehicle 1.

[0070] As an example of mounting the external environment sensor 41 , the vehicle 1 may be equipped with a plurality of cameras (eg, eleven cameras) configured to monitor the front, front side, side, rear side, and rear directions of the vehicle 1 .

[0071] As another example of installation, the vehicle 1 may also be equipped with multiple cameras (for example, four cameras) configured to monitor the front, sides and rear of the vehicle 1 respectively, multiple millimeter-wave radars (for example, five millimeter-wave radars) configured to monitor the front, front sides, sides and rear of the vehicle 1 respectively, and a LiDAR configured to monitor the front of the vehicle 1.

[0072] Furthermore, the external environment sensor 41 may detect the state of the atmosphere or the state of the weather in the external environment of the vehicle 1. Examples of the state detection type external environment sensor 41 include an outside air temperature sensor, a temperature sensor, and a raindrop sensor.

[0073] The internal environment sensor 42 can also detect specific physical quantities related to the vehicle's motion in the internal environment of the vehicle 1 (hereinafter referred to as motion physical quantities). Examples of the motion physical quantity detection type of internal environment sensor 42 include a velocity sensor, an acceleration sensor, a gyroscope sensor, and the like. The internal environment sensor 42 can also detect the state of the occupants in the internal environment of the vehicle 1. Examples of the occupant detection type of internal environment sensor 42 include actuator sensors, sensors and systems for monitoring the driver, biometric sensors, seat sensors, and in-vehicle equipment sensors. In particular, the actuator sensors include acceleration sensors, brake sensors, steering sensors, and the like that detect the occupant's operating state of the motion actuator 60 associated with the motion control of the vehicle 1.

[0074] Communication system 43 acquires communication data usable by driving system 2 through wireless communication. Communication system 43 can also receive positioning signals from GNSS (Global Navigation Satellite System) satellites located outside vehicle 1. Positioning-type communication equipment in communication system 43 is, for example, a GNSS receiver.

[0075] The communication system 43 can also transmit and receive communication signals with an external system 96 existing in the external environment of the vehicle 1. The V2X type communication equipment in the communication system 43 is, for example, a DSRC (dedicated short range communications) communicator, a cellular V2X (C-V2X) communicator, etc. Examples of communication with the V2X system existing in the external environment of the vehicle 1 include communication with the communication systems of other vehicles (V2V), communication with infrastructure equipment such as communicators installed in traffic lights or roadside equipment (V2I), communication with pedestrians' mobile terminals (V2P), and communication with networks such as cloud servers (V2N). The architecture of V2X communication including V2I communication can adopt the architecture specified by ISO21217, ETSI TS102 940-943, IEEE 1609, etc.

[0076] Furthermore, the communication system 43 can also transmit and receive communication signals with a mobile terminal 91 located within the interior of the vehicle 1, such as a smartphone. Examples of terminal communication devices in the communication system 43 include Bluetooth (registered trademark) devices, Wi-Fi (registered trademark) devices, and infrared communication devices.

[0077] The map DB 44 is a database storing map data that can be used in the driving system 2. The map DB 44 is configured as, for example, a non-transitory tangible storage medium including at least one of a semiconductor memory, a magnetic medium, and an optical medium. The map DB 44 may also include a database of a navigation unit that navigates the driving route to the destination of the vehicle 1. The map DB 44 may also include a database of a PD map generated using probe data (PD) collected from each vehicle. The map DB 44 may also include a database of high-precision maps with a high level of accuracy that are mainly used for the purpose of an autonomous driving system. The map DB 44 may also include a database of a parking lot map that contains detailed parking lot information, such as parking box information, and is used for the purpose of automatic parking or parking assistance.

[0078] The map database 44 for the driving system 2 acquires and stores the latest map data, for example, through communication with a map server via the V2X communication system 43. Map data is digitized in two or three dimensions as data representing the external environment of the vehicle 1. For example, the map data may include road data representing at least one of the following: the location coordinates, shape, road surface conditions, and standard runway. For example, the map data may also include identification data representing at least one of the following: the location coordinates and shape of road signs, road markings, and dividing lines attached to the road. The identification data included in the map data may also represent landmarks such as traffic signs, arrows, lane markings, stop lines, directional signs, landmark beacons, commercial signs, and changes in road line patterns. The map data may also include structure data representing at least one of the following: the location coordinates and shape of buildings and traffic lights facing the road. The identification data included in the map data may also represent landmarks such as streetlights, road edges, reflectors, and utility poles.

[0079] The motion actuator 60 can control the vehicle's motion based on an input control signal. A driving-type motion actuator 60 is, for example, a powertrain including at least one of an internal combustion engine and a drive motor. A braking-type motion actuator 60 is, for example, a brake actuator. A steering-type motion actuator 60 is, for example, a steering gear.

[0080] The HMI device 70 can be an operation input device that transmits the intentions or thoughts of the occupants, including the driver, of the vehicle 1 to the driving system 2 and can input the driver's operations. Examples of operation input-type HMI devices 70 include an accelerator pedal, brake pedal, gear lever, steering wheel, turn signal stalk, mechanical switches, and a touch panel on a navigation unit. The accelerator pedal controls the powertrain, which is a motion actuator 60. The brake pedal controls the brake actuator, which is a motion actuator 60. The steering wheel controls the steering actuator, which is a motion actuator 60.

[0081] The HMI device 70 may be an information presentation device that presents visual information, auditory information, skin sensory information, and other information to the occupants of the vehicle 1, including the driver. Examples of HMI devices 70 that present visual information include a combination meter, a graphic meter, a navigation unit, a CID (center information display), a HUD (head-up display), and a lighting unit. Examples of HMI devices 70 that present auditory information include a speaker and a buzzer. Examples of HMI devices 70 that present skin sensory information include a steering wheel vibration unit, a driver's seat vibration unit, a steering wheel reaction force unit, an accelerator pedal reaction force unit, a brake pedal reaction force unit, and an air conditioning unit.

[0082] Furthermore, the HMI device 70 can communicate with a mobile terminal 91, such as a smartphone, via the communication system 43 to implement HMI functions that collaborate with the terminal. For example, the HMI device 70 can present information acquired from the smartphone to passengers, including the driver. Furthermore, for example, operation inputs to the smartphone can be considered an alternative to operation inputs to the HMI device 70.

[0083] At least one processing system 50 is provided. For example, the processing system 50 may be a comprehensive processing system that comprehensively performs processing related to the detection function, the planning function, and the action function. In this case, the comprehensive processing system 50 may also perform processing related to the HMI device 70, or a separate processing system dedicated to the HMI may be provided. For example, the HMI-dedicated processing system may be an integrated cockpit system that comprehensively performs processing related to each HMI device 70.

[0084] In addition, for example, the processing system 50 may also have a structure that includes at least one processing unit corresponding to processing related to the detection function, at least one processing unit corresponding to processing related to the planning function, and at least one processing unit corresponding to processing related to the action function.

[0085] The processing system 50 has an external communication interface, for example, connected to at least one element associated with processing based on the processing system 50, such as each sensor, motion actuator 60, and HMI device 70, via at least one of a LAN (Local Area Network), a wiring harness, an internal bus, and a wireless communication circuit.

[0086] The processing system 50 is configured to include at least one dedicated computer 51. The processing system 50 may also combine multiple dedicated computers 51 to realize functions such as detection, planning, and action.

[0087] For example, the dedicated computer 51 constituting the processing system 50 may be an integrated ECU that integrates the driving functions of the vehicle 1. The dedicated computer 51 constituting the processing system 50 may also be a determination ECU that determines DDT. The dedicated computer 51 constituting the processing system 50 may also be a monitoring ECU that monitors the driving of the vehicle. The dedicated computer 51 constituting the processing system 50 may also be an evaluation ECU that evaluates the driving of the vehicle. The dedicated computer 51 constituting the processing system 50 may also be a navigation ECU that guides the driving route of the vehicle 1.

[0088] Furthermore, the dedicated computer 51 constituting the processing system 50 may be a locator ECU that estimates the position of the vehicle 1. The dedicated computer 51 constituting the processing system 50 may be an image processing ECU that processes image data detected by the external environment sensor 41. The dedicated computer 51 constituting the processing system 50 may be an actuator ECU that controls the motion actuator 60 of the vehicle 1. The dedicated computer 51 constituting the processing system 50 may be an HCU (HMI Control Unit) that comprehensively controls the HMI device 70. The dedicated computer 51 constituting the processing system 50 may be, for example, at least one external computer installed in an external center or mobile terminal 91 that can communicate via the communication system 43.

[0089] The dedicated computer 51 constituting the processing system 50 has at least one memory 51a and at least one processor 51b. The memory 51a may be at least one non-temporary physical storage medium such as a semiconductor memory, a magnetic medium, and an optical medium, which non-temporarily stores programs and data readable by the processor 51b. Furthermore, the memory 51a may be provided with a rewritable volatile storage medium such as a RAM (Random Access Memory). The processor 51b may include at least one of a CPU (Central Processing Unit), a GPU (Graphics Processing Unit), and a RISC (Reduced Instruction Set Computer)-CPU as its core.

[0090] The dedicated computer 51 constituting the processing system 50 may be a SoC (System on a Chip) in which a memory, a processor, and an interface are integrated into one chip, or the dedicated computer 51 may include an SoC as a component.

[0091] Furthermore, the processing system 50 may also include at least one database for executing dynamic driving tasks. The database may be configured to include, for example, at least one non-transitory physical storage medium such as a semiconductor memory, a magnetic medium, or an optical medium, and an interface for accessing the storage medium.

[0092] The database may be a scenario database (hereinafter referred to as scenario DB) 59. The database may be a rule database (hereinafter referred to as rule DB) 58. At least one of scenario DB 59 and rule DB 58 may be independently provided in driving system 2 instead of being provided in processing system 50. At least one of scenario DB 59 and rule DB 58 may be provided in external system 96 and accessible from processing system 50 via communication system 43.

[0093] The scenario DB 59 has a scenario directory that stores multiple scenarios for driving the vehicle 1. The driving system 2 can, for example, adapt the situation of the vehicle 1 to one or a combination of multiple scenarios selected from the multiple scenarios. The scenario DB 59 can store multiple scenarios including at least one of a functional scenario, a logical scenario, and a concrete scenario. The functional scenario defines the top-level qualitative scenario structure. The logical scenario is a scenario that assigns a quantitative parameter range to the structured functional scenario. The concrete scenario defines the boundary of the safety judgment that distinguishes between a safe state and an unsafe state.

[0094] The rule DB 58 stores a set of rules used in driving the vehicle 1. A rule set may include multiple rules. A rule set may also include a set of rule priorities based on the relative importance of the multiple rules. A rule set may also be implemented as a guideline for strategic driving of the vehicle 1.

[0095] A plurality of rules can comprise laws (lows), regulations (regulations) and rules based on their combination. A plurality of rules can also comprise rules based on preferences (preference) that are not influenced by laws, regulations, etc. A plurality of rules can also comprise rules based on sports behavior according to past experience. A plurality of rules can comprise rules based on the characteristics of the sports environment. A plurality of rules can comprise rules based on ethical concerns. A plurality of rules can comprise rules based on the basic principles of the safety model described later (for example, the five principles of the RSS model).

[0096] Furthermore, the processing system 50 may also include at least one recording device 55 for recording at least one of the detection information, planning information, and action information of the driving system 2. The recording device 55 may include at least one large-capacity storage medium 55c. The storage medium 55c may be, for example, at least one non-transitory physical storage medium such as a semiconductor memory, a magnetic medium, or an optical medium.

[0097] The storage medium 55c may be mounted on the substrate in a manner that is not easily removable or replaceable. For example, an eMMC (embedded Multi Media Card) using flash memory may be used. At least one of the storage media 55c may be removable and replaceable relative to the recording device 55. For example, an SD card may be used in this manner.

[0098] The recording device 55 may also have a function of selecting information to be recorded among the detection information, plan information, and action information. In this case, the recording device 55 may also have a dedicated computer.

[0099] The dedicated computer provided in the recording device 55 includes at least one memory 55a and at least one processor 55b. The memory 55a may be at least one non-temporary physical storage medium such as a semiconductor memory, a magnetic medium, or an optical medium, which non-temporarily stores programs and data readable by the processor 55b. Furthermore, the memory 55a may include a rewritable volatile storage medium such as a RAM (Random Access Memory). The processor 55b may include at least one of a CPU (Central Processing Unit), a GPU (Graphics Processing Unit), and a RISC (Reduced Instruction Set Computer)-CPU as its core.

[0100] A dedicated computer may be a SoC (System on a Chip) in which a memory, a processor, and an interface are integrated into one chip, or may include an SoC as a component of the dedicated computer.

[0101] The recording device 55 may also access the storage medium 55c and perform recording based on a data write command from the driving system 2. The recording device 55 may also identify information flowing through the in-vehicle network and access the storage medium 55c and perform recording based on the judgment of the processor 55b provided in the recording device 55.

[0102] The recording device 55 may not be provided in the processing system 50 but may be provided independently in the driving system 2 . The recording device 55 may be provided in the external system 96 and may be accessible from the processing system 50 via the communication system 43 .

[0103] Furthermore, the processing system 50 may also include at least one RSS unit 53 .

[0104] The RSS unit 53 may be one form of onboard implementation of RSS (Responsibility Sensitive Safety) as a safety model. The RSS unit 53 may be an onboard checker for planned functions implemented by the dedicated computer 51 .

[0105] The RSS unit 53 may also be configured primarily as a dedicated computer having at least one memory 53a and at least one processor 53b. The memory 53a may be at least one non-temporary physical storage medium such as a semiconductor memory, a magnetic medium, or an optical medium that non-temporarily stores programs and data readable by the processor 53b. Furthermore, the memory 53a may be a rewritable volatile storage medium such as a RAM (Random Access Memory). The processor 53b may include at least one of a CPU (Central Processing Unit), a GPU (Graphics Processing Unit), and a RISC (Reduced Instruction Set Computer)-CPU as its core.

[0106] A dedicated computer may be a SoC (System on a Chip) in which a memory, a processor, and an interface are integrated into one chip, or may include an SoC as a component of the dedicated computer.

[0107] Logical Architecture Overview

[0108] Next, use Figure 1 , an example of the logical architecture in the driving system 2 is described. The detection unit 10 receives sensor data detected by each sensor. The receiving function can be implemented by the sensor data receiving unit 12, which is a sub-block that further classifies the detection function. The detection unit 10 processes the sensor data of the external environment sensor 41 independently to implement an external recognition function of identifying road signs, other road users, etc. The sensor data can be, for example, data provided from millimeter wave radar, sonar, LiDAR, etc. The detection unit 10 can also generate relative position data of an object including the direction, size and distance of the object relative to the vehicle 1 based on the raw data detected by the external environment sensor 41.

[0109] The sensor data may be, for example, image data provided by a camera, LiDAR, or the like. The detection unit 10 processes the image data to extract objects within the field of view of the camera or the like. Object extraction may also include estimating the direction, size, and distance of the object relative to the vehicle 1. Object extraction may also include, for example, classifying the object using semantic segmentation.

[0110] The detection unit 10 also performs positioning of the vehicle 1. The detection unit 10 obtains global position data of the vehicle 1 from, for example, a GNSS receiver serving as the communication system 43. Furthermore, the detection unit 10 combines the global position data with at least one of information from the map database 44, position information of objects identified using the external environment sensor 41, and position information of objects identified through sensor fusion (described later), to estimate the position of the vehicle 1 on the map.

[0111] The detection unit 10 integrates sensor data from each external environment sensor 41, positioning information, and V2X information acquired through V2X communication. This allows the detection unit 10 to determine the number, type, and relative positions of other road users around the vehicle 1. Based on the road landmark information identified by the external environment sensors 41, the detection unit 10 determines the static structure of the road around the vehicle 1. Examples of this static structure include curve curvature, the number of lanes, and available space.

[0112] In this way, the detection unit 10 generates an environmental model encompassing the surrounding environment of the vehicle 1. The environmental model generation function can be implemented by the model extraction unit 11, which further categorizes the detection function. The environmental model can be provided to the planning unit 20 and the RSS 26. Alternatively, the environmental model can be an external environment model specific to the external environment.

[0113] Furthermore, the detection unit 10 may also have the function of processing the sensor data detected by each internal environment sensor 42 to identify the vehicle state. The vehicle state may also include the state of the vehicle 1's motion physical quantities detected by speed sensors, acceleration sensors, gyroscope sensors, and the like. Furthermore, the vehicle state may include at least one of the states of the occupants including the driver, the state of the motion actuator 60, the state of the driver's operation of the motion actuator 60, and the state of the HMI device 70. The environmental model may also be a comprehensive model that incorporates information on the internal environment, the vehicle state, the state of the driving system 2, and so forth, in addition to the external environment.

[0114] The planning unit 20 acquires the environmental model and vehicle status generated by the detection unit 10 and makes environmental decisions based on these data. Specifically, the planning unit 20 may interpret the environmental model to estimate the current state of the vehicle 1. This state may also refer to the operational situation. The planning unit 20 may also interpret the environmental model to predict the behavior of other road users. The planning unit 20 may also interpret the environmental model to predict the trajectory of objects belonging to other road users. Furthermore, the planning unit 20 may interpret the environmental model to predict potential hazards.

[0115] In addition, the planning unit 20 may interpret the environmental model and perform a judgment related to the scene that the vehicle 1 is currently in. The judgment related to the scene may also be to select at least one scene that the vehicle 1 is currently in from the scene list constructed in the scene DB 53.

[0116] Furthermore, the planning unit 20 may estimate the driver's intention based on at least one of the predicted action, the predicted trajectory of the object, the predicted potential danger, a scene-related judgment, and the vehicle state including the operating state of the HMI device 70 .

[0117] The planning unit 20 plans driving of the vehicle 1 based on at least one of estimated information on the position of the vehicle 1 on a map, judgment on the environment, estimated intention of the driver, and limitations of functions.

[0118] The planning unit 20 implements route planning, behavior planning, and trajectory planning functions. The route planning function plans at least one of a route to a destination and a lane plan for a medium distance based on estimated information about the vehicle 1's position on a map. The route planning function may also include determining at least one of a lane change request and a deceleration request based on the lane plan for the medium distance. The route planning function may be a mission / route planning function within a strategic function, or may be a function that outputs a mission plan and a route plan.

[0119] The behavior planning function is a function for planning the behavior of the vehicle 1 based on at least one of the route to the destination planned by the route planning function, the lane plan for the middle distance, the lane change request and the deceleration request, the judgment about the environment, the estimation of the driver's intention, and the functional restrictions. The behavior planning function may also include a function for generating conditions related to the state transition of the vehicle 1. The conditions related to the state transition of the vehicle 1 may also be equivalent to triggering conditions. The behavior planning function may also include a function for determining the state transition of the application that implements the DDT and the state transition of the driving action based on the conditions. The behavior planning function may also include a function for determining the longitudinal restrictions related to the path of the vehicle 1 and the lateral restrictions related to the path of the vehicle 1 based on the information of these state transitions. The behavior planning function may be a tactical behavior plan in the DDT function, or a function for outputting tactical behavior.

[0120] The track planning function is a function of planning the driving track of vehicle 1 based on judgments about the environment, longitudinal restrictions related to the path of vehicle 1, and lateral restrictions related to the path of vehicle 1. The track planning function may also include a function of generating a path plan. The path plan may include a speed plan, or a speed plan may be generated as a plan independent of the path plan. The track planning function may also include a function of generating multiple path plans and selecting the best path plan from multiple path plans, or a function of switching path plans. The track planning function may also include a function of generating backup data of the generated path plan. The track planning function may be a track planning function in the DDT function, or a function of outputting a track plan.

[0121] Furthermore, the planning unit 20 may also manage the driving system 2 mode and the autonomous driving mode. The management of the autonomous driving mode may also include, for example, managing the status of the autonomous driving level. The management of the autonomous driving level may also include managing the switch between manual and autonomous driving, that is, the transfer of authority between the driver and the driving system 2, or in other words, the management of takeover. The planning unit 20 may also monitor the status of each subsystem in the driving system 2 and determine whether the system is functioning properly (e.g., errors, unstable operation, system failure, or malfunction).

[0122] The planning unit 20 may also determine a mode based on the driver's intention based on the driver's intention estimation. The planning unit 20 may also set restrictions on driving-related functions based on at least one of sensor abnormality (or sensor failure) signals output from each sensor, application state transition information, and a trajectory plan.

[0123] Furthermore, the planning unit 20 may have a function of determining longitudinal restrictions related to the path of the vehicle 1 and lateral restrictions related to the path of the vehicle 1 in addition to determining restrictions on driving-related functions. In this case, the planning unit 20 plans the behavior and the trajectory based on these restrictions as described above.

[0124] The action unit 30 obtains the trajectory plan (e.g., the path plan and the speed plan) from the planning unit 20. The action unit 30 obtains information related to a proper response from the RSS 26. The information related to the proper response may be a request for the action unit 30 to execute the proper response. The request to execute the proper response may be a restricted request.

[0125] In the absence of a request from the RSS 26 , the action unit 30 controls the motion of the vehicle 1 based on the trajectory plan of the planning unit 20 . The action unit 30 generates acceleration request information, shift request information, braking request information, and steering request information corresponding to the trajectory plan, and outputs them to the motion actuator 60 .

[0126] When a request is received from RSS 26, action unit 30 applies an appropriate response to the trajectory plan. Application of the appropriate response may involve applying the restrictions requested from RSS to the trajectory plan. The function of applying RSS restrictions can be implemented by RSS restriction application unit 31, a sub-block further categorized as an action function. Action unit 30 generates acceleration request information, shift request information, braking request information, and steering request information corresponding to the plan after applying the request from RSS 26, and outputs them to motion actuator 60. The function of generating such requests to motion actuator 60 can be implemented by actuator request generation unit 32, a sub-block further categorized as an action function.

[0127] Furthermore, the action unit 30 may also have a function of directly acquiring the vehicle state recognized by the detection unit 10 , such as at least one of the current speed, acceleration, and yaw rate of the vehicle 1 , and reflecting the state in the motion control of the vehicle 1 .

[0128] Furthermore, the action unit 30 may include an HMI output unit 33 as a sub-block obtained by further classifying the action functions. The HMI output unit 33 may be a structure independent of the action unit 30 in terms of one or both of hardware and software.

[0129] The HMI output unit 33 may also output information to the occupants of vehicle 1, including the driver, based on at least one of environmental assessments, estimated driver intent, application state transitions, trajectory plans, function limitations, and information regarding appropriate responses based on RSS 26. The HMI output unit 33 may also manage vehicle interactions. Based on the status of vehicle interaction management, the HMI output unit 33 may also generate notification requests to control information presentation functions within the HMI device 70. Furthermore, the HMI output unit 33 may generate control requests for wipers, sensor washers, headlights, and air conditioning systems installed in vehicle 1 to control these devices.

[0130] <Security Model and Its Implementation>

[0131] Driving system 2 can be equipped with an autonomous driving safety model. A safety model is a model used to verify that no unacceptable risks exist within a specific operational design domain (ODD). For example, a safety model can be equivalent to a safety driving model, a safety-related model, or a formal model. While the RSS model can be used as a safety model, other models, more general models, or composite models combining multiple models can also be used.

[0132] For example, the RSS model uses five rules (five principles). The first rule is "Do not hit someone from behind." The second rule is "Do not cut-inrecklessly." The third rule is "Right-of-way is given, not taken." The fourth rule is "Be careful of area anotherone, you must do it." The fifth rule is "If you can avoid an accident without causing another one, you must do it."

[0133] A safety envelope can also be defined based on the five rules, particularly the first and second rules. For example, the safety envelope can refer to the longitudinal and lateral safety distances relative to other road users, as well as the conditions or concepts used to calculate these safety distances. Safety distance can be considered an example of a geometric approach.

[0134] like Figure 3 As shown, the longitudinal safety distance d min The distance can be set as follows: When the leading vehicle OV1 is traveling at a speed of v f Driving at maximum deceleration a max,brake When braking to stop, even if the following vehicle (for example, vehicle 1) has a response time ρ and a maximum acceleration a max,accel Accelerate and then decelerate at minimum a min,breke Apply the brakes to stop the vehicle and avoid rear-end collision.

[0135] here, Figure 4 The calculation formula 1 and 4 show d brake,front is the stopping distance of the preceding vehicle OV1. Figure 4 The calculation formula 2 and 4 show d reaction is the idle distance of the following vehicle. Figure 4 The calculation formula 3 and 4 show d brake,rear is the braking distance of the following vehicle. Figure 4 As shown in the calculation formula 4, the safety distance d min It can be the distance obtained by adding the stopping distance of the preceding vehicle OV1 to the idling distance of the following vehicle and subtracting the braking distance of the following vehicle.

[0136] In addition, if Figure 5 As shown, the longitudinal safety distance d min The following distance can be set: when two vehicles 1 and OV2 are traveling toward each other at respective speeds v1 and v2, even with a predetermined reaction time ρ and maximum acceleration a max,accel Accelerate and then decelerate at minimum a min,breke The distance within which the vehicle can be stopped without a head-on collision even if the brakes are applied.

[0137] here, Figure 6 The calculation formula 5 shows d reaction,1 is the idling distance of vehicle 1. Figure 6 The calculation formula 6 shows d brake,1 is the braking distance of vehicle 1. Figure 6 The calculation formula 7 shows d reaction,2 is the idling distance of vehicle OV2. Figure 6 The calculation formula 8 shows d brake,2is the braking distance of vehicle OV2. Figure 6 As shown in formula 9, the safety distance d min It can be the sum of the idling distance of vehicle 1, the braking distance of vehicle 1, the idling distance of vehicle OV2, and the braking distance of vehicle OV2.

[0138] like Figure 7 As shown, the lateral safety distance d min The following distance can be set: when two vehicles 1 and OV3 are traveling adjacent to each other at lateral speeds v1 and v2 respectively, even if the reaction time ρ and maximum acceleration a are specified, max,accel Accelerate and then decelerate at maximum speed a min,breke The vehicle is decelerated in the lateral direction, and a minimum distance μ is maintained to prevent collision.

[0139] here, Figure 8 The calculation formula 10 shows d reaction,1 is the idling distance of vehicle 1. Figure 8 The calculation formula 11 shows d brake,1 is the braking distance of vehicle 1. Figure 8 The calculation formula 12 shows d reaction,2 It is the idling distance of vehicle OV3. Figure 8 The calculation formula 13 shows d brake,2 is the braking distance of vehicle OV3. Figure 8 As shown in formula 14, the safety distance d min It can be the sum of the idling distance of vehicle 1, the braking distance of vehicle 1, the idling distance of vehicle OV3, and the braking distance of vehicle OV3.

[0140] Here, the coordinate system used in the safety model can be a coordinate system based on the lane. Figure 9 As shown, this coordinate system addresses the movement of vehicle 1 along lane LA by defining the centerline of lane LA, i.e., lane axis ALA, which follows the curve of the road. On the other hand, a coordinate system based on the road user can be used to define the longitudinal and lateral axes of each road user. This coordinate system uses the road user's center of gravity as a reference, and defines the longitudinal and lateral coordinates based on the road user's azimuth.

[0141] The RSS 26 installed in the driving system 2 is configured in parallel with the planning unit 20 in terms of architecture and performs calculation processing. Specifically, the RSS 26 obtains the environmental model, sensor data, etc. from the detection unit 10, evaluates the risk based on this information, and outputs a response corresponding to the risk to the action unit 30. Figure 1 As shown, the RSS 26 may include a status extraction unit 27, a status confirmation unit 28, and a response unit 29 as sub-blocks obtained by further classifying the functions of the RSS 26.

[0142] The situation extraction unit 27 extracts the situation based on the information obtained from the detection unit 10. The data representing the situation (hereinafter referred to as the situation data) may include a list of objects (hereinafter referred to as surrounding objects) existing around the vehicle 1. The surrounding objects may include other road users. The situation data may include data representing a potential conflict between the vehicle 1 and the surrounding objects. In this case, the situation data only needs to include the uncertainty of the existence probability, position, direction, and speed of the vehicle 1 and the surrounding objects. The situation extraction unit 27 may also extract multiple situations. The situation may be a traffic situation. The situation can be selected from a series of possible situations.

[0143] Situation confirmation unit 28 confirms whether the situation extracted by situation extraction unit 27 is a safe situation or a dangerous situation. Situation confirmation unit 28 performs at least one of the above-described geometric method and risk assessment using other methodologies. When risk assessment is performed, the safety envelope may represent the permissible collision risk.

[0144] Risk determination can also include confirming the estimated collision risk between vehicle 1 and surrounding objects. The collision risk can include both time-varying collision risk and peak collision risk. The collision risk can be expressed as a probability of collision. In other words, uncertainty can be considered in risk determination.

[0145] In the event of a violation of the safety envelope, the situation confirmation unit 28 determines that the situation of the object being confirmed is a dangerous situation. When the situation confirmation unit 28 performs risk confirmation, the situation confirmation unit 28 may compare the threshold value of the allowed collision risk with the estimated collision risk value. The situation confirmation unit 28 may determine that the situation of the object being confirmed is a safe situation if the estimated collision risk value is lower than the threshold value of the allowed collision risk. The situation confirmation unit 28 may determine that the situation of the object being confirmed is a dangerous situation if the estimated collision risk value exceeds the threshold value of the allowed collision risk. That is, the situation confirmation unit 28 determines that the situation of the object being confirmed is a safe situation if there is no violation of the safety envelope. The risk threshold value may be, for example, a longitudinal safety distance or a lateral safety distance.

[0146] The situation confirmation unit 28 may also establish hypotheses regarding surrounding objects and confirm risks based on these hypotheses. In this case, multiple hypotheses may be used. A hypothesis may be an assumption regarding reasonably foreseeable behavior, or a hypothesis that includes such an assumption. Furthermore, a hypothesis may be a prediction derived from the hypothesis, or a hypothesis that includes a prediction derived from the hypothesis.

[0147] That is, the assumed kinematic values may be affected by the permissible risk level. The permissible risk level and risk threshold may be pre-specified by at least one of a government agency, a standardization agency, and the approval period of the driving system 2. The permissible risk level and risk threshold may also be pre-set by the developer of the driving system 2.

[0148] Furthermore, the situation confirmation unit 28 may determine the permissible risk level by referring to a rule set stored in the rule DB 58. The situation confirmation unit 28 may also improve estimation accuracy by incorporating the rules of the rule set into the risk value calculation algorithm.

[0149] Figure 10 An example of a processing method for deriving and defining assumptions is shown in FIG. This processing is achieved, for example, by processor 53b of RSS unit 53 executing a program stored in memory 53a. The series of steps S11 to S15 is executed at predetermined regular intervals or based on a predetermined trigger. The predetermined trigger may be, for example, the provision of the latest status data from status extraction unit 27 to status confirmation unit 28.

[0150] Initially, in S11, the scene currently encountered by vehicle 1 is determined. This determination may involve selecting a scene from a directory of scenes stored in scene DB 59. A single scene may be selected. Alternatively, multiple scenes may be selected. A combination of multiple scenes may also be used to represent more complex situations. After S11, the process proceeds to S12.

[0151] S12 to S15 are repeated processes for each scene. In S12, the relevant scene and the road user as a dynamic element are determined and described in detail. After the processing of S12, the process proceeds to S13.

[0152] S13 to S15 are repeated processes for each road user. In S13, the kinematic properties that control the movement of the road user are determined. After the processing of S13, the process proceeds to S14.

[0153] S14-15 are repeated processes for each kinematic characteristic. In S14, the kinematic characteristic is evaluated based on the scenario determined in S11 to determine whether it is relevant to safety. This evaluation is performed by determining whether a certain characteristic represents the movement of another road user and whether it is likely to cause movement relative to vehicle 1. If a kinematic characteristic is not relevant to safety, it is removed from application to the scenario determined in S11. After S14, the process proceeds to S15.

[0154] In S15, a hypothesis is generated regarding the reasonably foreseeable behavior of other road users for the scenario identified in S11. This hypothesis is defined by setting boundaries for the reasonably foreseeable range of behavior of other road users in the identified driving conditions. After S15, the process returns to S12, S13, and S14 and repeats, depending on the remaining status of the processing for other scenarios, road users, and kinematic characteristics. When processing is complete for all scenarios, the series of processes ends.

[0155] The assumptions may be a function of time that changes during the determined scenario. Alternatively, the assumptions may not change during the determined scenario. Here, a minimum set of assumptions about other road users may be defined.

[0156] The minimum set may be one or more of the following characteristics corresponding to the scenario: a reasonably foreseeable maximum assumed longitudinal velocity other road users could exhibit, a reasonably foreseeable maximum assumed lateral velocity other road users could exhibit, a reasonably foreseeable maximum assumed longitudinal acceleration other road users could exhibit ahead of the vehicle, a reasonably foreseeable maximum assumed lateral acceleration other road users could exhibit, a reasonably foreseeable minimum assumed longitudinal deceleration other road users could exhibit in the opposite direction of the vehicle or behind the vehicle, a reasonably foreseeable minimum assumed lateral deceleration other road users could exhibit, and a reasonably foreseeable maximum assumed heading other road users could exhibit. angle), reasonably foreseeable maximum assumed heading angle rate change other road users could exhibit, reasonably foreseeable maximum assumed lateral position fluctuation other road users could exhibit, and reasonably foreseeable maximum assumed reaction time other road users could exhibit.foreseeablemaximum assumed response time other road users could exhibit).

[0157] These assumed values can vary depending on the type of road user. For example, the assumed values can be modified based on whether the road user is a vulnerable road user (VRU) or another type of user. Furthermore, the assumed values can be adjusted based on at least one of various road conditions reasonably expected within the operational design area and environmental conditions related to weather. Furthermore, the assumed values can be adjusted based on at least one of differences in road traffic laws between countries and differences in traffic habits within each region.

[0158] Response unit 29 derives an appropriate response based on the confirmation result of situation confirmation unit 28. An appropriate response may be provided to action unit 30 only when the situation is determined to be dangerous. An appropriate response may be a restriction on the control command for motion actuator 60. An appropriate response may be one designed to return vehicle 1 to a safe state. Even when multiple unrelated dangerous situations are confirmed, the actions that vehicle 1 should take must be combined into a single action. Therefore, in this case, response unit 29 resolves potential conflicts between appropriate responses to these situations and transmits the appropriate response to action unit 30.

[0159] Furthermore, the RSS 26 may sequentially store at least one of the data representing the status, the result of the status confirmation, and the derived appropriate response in the storage medium 55c using the recording device 55 or the like. The RSS 26 may also transmit at least one of the data representing the status, the result of the status confirmation, and the derived appropriate response to the external system 96 using the communication system 43, and store the data in the storage medium 96a of the external system 96.

[0160] Furthermore, RSS26 can prioritize outputs to maintain its obligation to warn other road users. Furthermore, RSS26 can assist with emergency operations. These emergency operations can be either minimal risk maneuvers (MRM) or DDT fallbacks. Emergency operations can be executed when a dangerous situation actually arises even if appropriate responses are taken based on a potentially dangerous situation, and the risk is not adequately mitigated.

[0161] Furthermore, RSS 26 can distinguish between the initiator of a dangerous scenario and the responder of a dangerous scenario. RSS 26 can distinguish between actions recommended for the initiator and actions recommended for the responder. Specifically, if vehicle 1 is the initiator, RSS 26 derives an appropriate response corresponding to the action recommended for the initiator. If vehicle 1 is the responder, RSS 26 derives an appropriate response corresponding to the action recommended for the responder.

[0162] <Response to moving objects>

[0163] RSS26 can also support handling of passing vehicles. Typically, a four-wheeled vehicle (including so-called passenger cars) occupies a lane entirely. In contrast, a passing vehicle can be narrower than a vehicle in width and can pass between vehicles in the same lane.

[0164] Specifically, examples of passing mobile objects include motorcycles, bicycles, small (autonomous) transport vehicles, and humans. Examples of humans include pedestrians, runners, and skateboarders. In other words, passing mobile objects may correspond to passing vehicles. Furthermore, passing mobile objects may correspond to VRUs.

[0165] There are several scenarios in which the response to a passing moving object should be considered. These scenarios can be stored in the scenario DB 59 and become candidates to be selected when the RSS 26 identifies a scenario.

[0166] Scenarios that should be considered for dealing with moving bodies that pass through may include scenarios on dedicated automobile roads including expressways, and scenarios on general roads. Scenarios that should be considered for dealing with moving bodies that pass through may include scenarios during traffic jams and scenarios during non-traffic jams. Typically, VRUs are more likely to pass through during traffic jams. Therefore, during traffic jams, motorcycles can be considered to correspond to moving bodies that pass through. On the other hand, during non-traffic jams, whether a VRU is equivalent to a moving body that pass through can be determined based on the situation. During non-traffic jams, a motorcycle may not be equivalent to a moving body that pass through when it is traveling in the center of a lane. During non-traffic jams, a bicycle may be equivalent to a moving body that pass through.

[0167] exist Figure 11 In the example shown, vehicle 1 is traveling behind preceding vehicle OV4 in the same lane LA. Furthermore, in an area near the road end within the same lane LA, motorcycle SO1 is traveling in the same direction as vehicle 1 and preceding vehicle OV4. In this scenario, motorcycle SO1 acts as a passing vehicle and also as a VRU.

[0168] In this scenario, the dynamic elements are as follows: On the road, motorcycle SO1 is moving longitudinally in front of and / or behind vehicle 1. On the road, a vehicle (preceding vehicle OV4) is moving longitudinally in front of and / or behind vehicle 1. In this scenario, the background is a speed limit sign and no crosswalk. In this scenario, the road user representation is that there is no collision between vehicle 1 and other road users.

[0169] Here, the situation confirmation unit 28 of the RSS 26 may also set an assumed travel route DR for the motorcycle SO1. The setting of the travel route DR may be included in the aforementioned assumptions regarding the reasonably foreseeable behavior of other road users, or may be performed as a pre-processing step for implementing the behavioral assumptions. The setting of the travel route DR may or may not be included in the aforementioned minimum set of assumptions.

[0170] The assumed travel path DR for the motorcycle SO1 can be set based on the reasonably foreseeable behavior of the motorcycle SO1. For example, in the direction perpendicular to the lane axis direction D1 along the lane axis ALA (lane width direction D2), the distance from the road end to the preceding vehicle OV4 is set to d vw Therefore, the status confirmation unit 28 can vw >d thresh If the condition holds, a virtually set travel road DR has a width of w. That is, if there is a space between the preceding vehicle OV1 and the road end for the motorcycle SO1 to pass through, the motorcycle SO1 is predicted to continue traveling along a trajectory passing through the space.

[0171] For example, Figure 12 As shown in formula 15, d thresh It can be the safe distance d between vehicle 1 and motorcycle SO1 min,lat , the lateral width w of the motorcycle SO1 VRU , and the margin d that should exist between the motorcycle SO1 and the end of the road formed into a wall shape VRU,wall The harmony.

[0172] In addition, for example, Figure 12 Set d as shown in equations 16 to 19 thresh Here, calculate d in equations 16 to 19. VRU This is the margin that should exist between the motorcycle SO1 as the VRU and the road end, and is a value that is appropriately set according to the road shape and other environments. ego is a parameter set according to the type of vehicle 1. For example, if the vehicle 1 is a large vehicle such as a truck, a larger value is set than if it is a small vehicle. ego,lat) is a parameter set according to the longitudinal speed of the vehicle 1. Calculation formula 19 d(v VRU,lat ) is a parameter set according to the longitudinal speed of the motorcycle SO1 serving as the VRU.

[0173] like Figure 13 As shown in the calculation formula 20, the width w of the assumed driving road DR can be d vw Subtract d min,lat When using formulas 15 and 16, you can use formula 20. Figure 13 The width w is set as shown in equations 21 to 23. When equation 17 is used, equation 21 can be applied. When equation 18 is used, equation 22 can be applied. When equation 19 is used, equation 23 can be applied.

[0174] Furthermore, the width w may not be a constant value, but may vary depending on the longitudinal position. For example, the width w may be different between the lateral space of the vehicle 1 and the lateral space of the preceding vehicle OV1.

[0175] The assumed travel path DR can be treated as an area exclusively occupied by the motorcycle SO1's trajectory. The assumed travel path DR can be treated as a lane different from the lane LA in which vehicle 1 is traveling. Thus, when determining collision risk, vehicle 1 and motorcycle SO1 can be treated as traveling in different lanes. Therefore, since vehicle 1 is traveling in the current lane LA along lane axis ALA, determining the longitudinal risk between vehicle 1 and motorcycle SO1, i.e., determining the longitudinal safety distance, can be omitted or simplified. In other words, detailed longitudinal determinations can be omitted or simplified in the evaluation of dangerous situations. This reduces the amount of computational processing in RSS unit 53, resulting in reduced computational processing delays and reduced load on hardware resources.

[0176] The simplification of the longitudinal safety distance confirmation may be the simplification of the longitudinal safety distance confirmation for other road users who are treated as traveling in the same lane. The simplification of the longitudinal safety distance confirmation may be, for example, the use of approximate values and assumed values for some or all of the values substituted for parameters such as acceleration and response time in the calculation of the safety distance shown in calculation formulas 1 to 4, instead of the precise values detected and recognized by sensors 41 and 42 or obtained through V2X communication. For example, the assumed values can be obtained by referring to the values stored in a database or table stored in a storage medium such as memory 53a. The simplification of the longitudinal safety distance confirmation may also be the simplification of the calculation formula itself for calculating the safety distance, for example, by changing some variables to constants.

[0177] exist Figure 14 In the example shown, on a two-lane road on each side, the traveling path DR for the passing vehicle is set so as to straddle the two lanes LA1 and LA2. That is, the area exclusively occupied by the track of the motorcycle SO1 is set along the dividing line between the two lanes, straddling the two lanes LA1 and LA2 in the same direction. When the distance between the other vehicles OV5 and OV6 running parallel in a direction perpendicular to the lane axis direction D1 along the lane axis ALA (lane width direction D2) is set as d vv When d vv >d thresh If the condition is satisfied, the situation confirmation unit 28 virtually sets a travel road DR of width w.

[0178] In this case, for example, Figure 15 Set d as shown in equations 24 to 26. thresh Calculate d in Equation 25 ego It is a parameter that is appropriately set according to the type of each vehicle in the lane LA1 where the vehicle 1 is located in the two lanes LA1 and LA2. other It is a parameter set according to the type of each vehicle in the two lanes LA1 and LA2, and the vehicle 1 is not in the lane LA2. ego ) is a parameter set according to the speed of the vehicle in lane LA1. Calculate d(v other ) is a parameter set according to the speed of the vehicle in lane LA2. VRU ) is a parameter set according to the speed of the motorcycle SO2 serving as the VRU.

[0179] exist Figure 16 In the example shown, a driving path DR for a passing vehicle is set on a single-lane road on each side, straddling the opposing lanes LA1 and LA2. In a scenario where a passing vehicle (e.g., a motorcycle SO3) is traveling between the opposing lanes LA1 and LA2, it is possible to immediately determine that a potentially dangerous or hazardous situation exists if the vehicles in each lane LA1 or LA2 are traveling at a speed exceeding a certain level. However, there are also cases where a situation is determined to be non-hazardous, such as a traffic jam in both lanes LA1 and LA2, with vehicles in both lanes stopped or traveling at extremely low speeds. In such cases, a driving path DR for the passing vehicle can be set.

[0180] exist Figure 17The example shown shows a situation where a motorcycle SO4, a moving vehicle, is traveling on a two-lane road, straddling the two lanes LA1 and LA2. However, vehicles OV7 and OV8 in front of motorcycle SO4 are located close to the dividing line between the two lanes, leaving no room for them to pass through. Furthermore, it is assumed that there is room for them to pass through, for example, in the area in front of motorcycle SO4, near the road end.

[0181] Here, the first driving road DR1 can be set to include the space between the two lanes LA1 and LA2 where the motorcycle SO4 currently exists. Furthermore, the second driving road DR2 can be set to include the space in front of the motorcycle SO4 and located at the end of the road. The first driving road DR1 and the second driving road DR2 can be said to be areas exclusively occupied by the track of the motorcycle SO4. Here, in order for the motorcycle SO4 to move from the first driving road DR1 to the second driving road DR2, it is necessary to pass the track that crosses the lane LA1 in front of the vehicle 1 ( Figure 17 In other words, the motorcycle SO4 is predicted to move from the first traveling road DR1 to the second traveling road DR2 via the track crossing the lane LA1.

[0182] While motorcycle SO4 is crossing lane LA1, there is a possibility that vehicle 1 and motorcycle SO4 may overlap longitudinally and collide. Therefore, during this period, a longitudinal risk check, or longitudinal safety distance check, is performed between vehicle 1 and motorcycle SO4. As such, a crossing vehicle may move in a direction that may not be appropriate for the actual lane. The RSS 26 of this embodiment reflects the directional flexibility of other road users in the setting of the travel route DR.

[0183] exist Figure 18 In the example shown, vehicle 1 is turning left from its current lane LA, for example, to a roadside parking lot. It is assumed that there is no sidewalk between the roadside parking lot and lane LA. Limited ranges SR1 and SR2 that can be detected by sensors exist in front of and behind vehicle 1, respectively. These ranges can include both limited angle ranges and limited distance ranges. These ranges SR1 and SR2 can be, for example, ranges specified in the operational design area. Furthermore, a following vehicle OV9 exists behind vehicle 1, and the field of view of vehicle 1 is limited by the following vehicle OV9. Due to the limited field of view, an obstruction area OA is formed on both sides of the following vehicle OV9.

[0184] Here, RSS26 assumes that virtual objects SO5 and SO6 as traveling moving bodies may appear from at least one of the ranges SR1 and SR2 detectable by the sensor and the occlusion area OA. Figure 18In this example, specifically, assume that a passing object, such as a motorcycle, bicycle, or pedestrian, exists outside range SR1 detectable by sensors in front of vehicle 1, and that this passing object could appear within range SR1 at any time. In this case, assuming that vehicle 1 is visible from virtual object SO5, virtual object SO5 is assumed to approach vehicle 1 along the road edge within lane LA, which is offset laterally (or in lane width direction D2) from vehicle 1, to avoid collision with vehicle 1.

[0185] Behind the vehicle 1 , it is assumed that a passing moving object such as a motorcycle, bicycle, or pedestrian exists in the occlusion area OA, and the passing moving object may appear at any time within the range SR2 detectable by the sensor behind the vehicle 1 .

[0186] The kinematic characteristics of these virtual objects SO5 and SO6 can be set based on the predicted and reasonably foreseeable behavior, similar to those of other road users that are actually identified. Figure 10 The process is performed together with other road users actually recognized in a series of processes from S11 to S15.

[0187] Furthermore, the trajectory predicted for these virtual objects SO5 and SO6 is assumed to be within the same lane LA as vehicle 1. Furthermore, a travel path DR for the moving object is set within the area occupied by the trajectory. RSS 26 also supports collision risk between the virtual objects SO5 and SO6 and vehicle 1. The assumed travel path DR for these virtual objects SO5 and SO6 can be treated as a lane different from the lane LA in which vehicle 1 is traveling. Therefore, the longitudinal risk confirmation, i.e., the longitudinal safety distance confirmation, between vehicle 1 and these virtual objects SO5 and SO6 can be omitted or simplified.

[0188] exist Figure 19 In the example shown, a sidewalk SW is provided on the side of the road in lane LA in which vehicle 1 is traveling. However, in front of vehicle 1, sidewalk SW is blocked by an obstacle OO. Obstacle OO may be, for example, a parked car or a pile of snow accumulated by snow removal.

[0189] Here, RSS26 assumes a passing moving body that enters lane LA in order to avoid obstacle OO from sidewalk SW. The so-called passing moving body here can be a pedestrian SO7. Moreover, the track predicted for these pedestrians SO7 to pass through lane LA is assumed to be in the same lane LA as vehicle 1. Moreover, in the area occupied by the track, a path PR for the passing moving body is set. RSS26 also supports the collision risk between pedestrians SO7 and vehicle 1. The path PR assumed for these pedestrians SO7 can be treated as a lane different from the lane LA in which vehicle 1 is traveling. Therefore, the longitudinal risk confirmation between vehicle 1 and these pedestrians SO7, that is, the longitudinal safety distance confirmation, can be omitted or simplified.

[0190] The results of processing the passing moving body by RSS26 can be displayed. The driving system 2 (e.g., the action unit 30, the HMI output unit 33) can also display the assumed behavior of traffic participants around the vehicle 1 on various information presentation devices by providing an overhead view of the surroundings of the vehicle 1. The driving system 2 (e.g., the action unit 30, the HMI output unit 33) can also superimpose the assumed passing moving body on an image that simulates the shape of the road around the vehicle 1 and display it on the information presentation device. The driving system 2 (e.g., the action unit 30, the HMI output unit 33) can also further superimpose the set driving road DR and passage PR of the passing moving body on this image and display it on the information presentation device.

[0191] Furthermore, the driving system 2 (e.g., the action unit 30, the HMI output unit 33) may associate at least one of the longitudinal position, longitudinal velocity, longitudinal acceleration, longitudinal deceleration, lateral position, lateral velocity, lateral acceleration, and lateral deceleration assumed for a passing vehicle traveling on the driving road DR and the passage PR with the driving road DR and the passage PR, and display the associated information on the information presentation device. When a virtual passing vehicle is assumed, the driving system 2 (e.g., the action unit 30, the HMI output unit 33) may associate at least one of the longitudinal position, longitudinal velocity, longitudinal acceleration, longitudinal deceleration, lateral position, lateral velocity, lateral acceleration, and lateral deceleration assumed for the virtual passing vehicle with the driving road DR and the passage PR, and display the associated information on the information presentation device.

[0192] Alternatively, a virtual passing moving object may be displayed in a manner that allows it to be distinguished from an actual passing moving object detected by the detection unit 10. For example, the virtual passing moving object may be displayed using at least one of a display method that reduces brightness, a display method that reduces chromaticity, and a display method that increases transparency relative to the background (e.g., a see-through display) compared to the actual detected passing moving object. The virtual passing moving object may also be displayed by flashing to distinguish it from the actual detected passing moving object.

[0193] Furthermore, the results of processing by RSS 26 regarding the passing mobile object can be generated and recorded as data. The driving system 2 (e.g., RSS 26, action unit 30) can record the assumed behavior of traffic participants around vehicle 1 via recording device 55 to storage medium 55c. The driving system 2 (e.g., RSS 26, action unit 30) can record information related to the assumed behavior of the passing mobile object via recording device 55 to storage medium 55c. The driving system 2 (e.g., RSS 26, action unit 30) can record information about the set travel route DR and path PR of the passing mobile object via recording device 55 to storage medium 55c.

[0194] More specifically, the driving system 2 (e.g., the RSS 26, the action unit 30) may associate at least one of the longitudinal position, longitudinal velocity, longitudinal acceleration, longitudinal deceleration, lateral position, lateral velocity, lateral acceleration, and lateral deceleration assumed for a passing vehicle traveling on the driving road DR and the passage PR with the driving road DR and the passage PR, and record the associated information in the storage medium 55c via the recording device 55. When a virtual passing vehicle is assumed, the driving system 2 (e.g., the RSS 26, the action unit 30) may associate at least one of the longitudinal position, longitudinal velocity, longitudinal acceleration, longitudinal deceleration, lateral position, lateral velocity, lateral acceleration, and lateral deceleration assumed for the virtual passing vehicle with the driving road DR and the passage PR, and record the associated information in the storage medium 55c via the recording device 55. The parameters recorded here, such as the longitudinal velocity, may include the minimum set of assumptions regarding other road users.

[0195] <Processing Flow>

[0196] Next, use Figure 20 An example of a method for handling a moving object based on RSS 26 will be described. This method includes a confirmation method. This process is implemented, for example, by processor 53b of RSS unit 53 executing a program stored in memory 53a. The series of steps S21 to S26 is executed at predetermined regular intervals or based on a predetermined trigger.

[0197] In S21, the situation extraction unit 27 acquires situation data from the detection unit 10. After the processing of S21, the process proceeds to S22.

[0198] In S22, the situation extraction unit 27 extracts the positional relationship between the road and other vehicles. In other words, it extracts the situation. The situation extraction unit 27 also makes assumptions about passing objects. These passing objects include both actual passing objects identified by the detection unit 10 and virtual passing objects. After S22, the process proceeds to S23.

[0199] In S23, the situation extraction unit 27 sets the travel path DR and the path PR of the passing moving body based on the trajectory predicted in the passing moving body. After the processing of S23, the process proceeds to S24.

[0200] In S24, the situation confirmation unit 28 confirms the risk to the passing moving object. This risk confirmation is omitted or simplified by treating the set travel road DR and passage PR as a different lane from the vehicle 1. After the processing in S24, the process proceeds to S25.

[0201] In S25, the situation confirmation unit 28 determines whether the risk of identifying the passing moving object is acceptable. If "yes", the series of processes ends. If "no", the process proceeds to S26.

[0202] In S26, the response unit 29 derives an appropriate response for reducing the risk of the passing moving object. The response unit 29 outputs the derived appropriate response to the action unit 30. The series of processes ends with the process of S26.

[0203] According to the first embodiment described above, during risk confirmation, the area occupied by the trajectory of a mobile object passing through lanes LA and LA1, where vehicle 1 is located, is treated as a lane separate from lanes LA and LA1, where vehicle 1 is located. This allows for rational processing of the predicted behavior of the passing mobile object and reduces the load on processor 53b caused by processing a large number of mobile objects congested within the same lane. Furthermore, it is possible to suppress the frequent occurrence of excessive responses by vehicle 1 that could result from risk confirmation. This improves the appropriateness of the processing of the mobile object when confirming the risk of collision with the mobile object passing through lanes LA and LA1.

[0204] Furthermore, according to the first embodiment, during risk confirmation, even if the mobile object is assumed to be within lanes LA or LA1 where vehicle 1 is present, the area occupied by its track is treated as another lane, thereby omitting or simplifying the confirmation of the longitudinal safety distance between vehicle 1 and the mobile object. This omission or simplification can reliably reduce the load on processor 53b. Furthermore, it can avoid unnecessary deceleration of vehicle 1 in response to the timing when the longitudinal inter-vehicle distance becomes extremely small, which is inevitable during crossing.

[0205] Furthermore, according to the first embodiment, a virtual moving object is assumed in the blocked area OA caused by the restricted field of view of the vehicle 1. This allows for early prediction of the risk of collision with a passing moving object that is not actually visible from the vehicle 1.

[0206] Furthermore, according to the first embodiment, a virtual moving object is assumed outside the range detectable by the sensors provided on the vehicle 1. This allows for early prediction of the risk of collision with a moving object that is not actually visible from the vehicle 1.

[0207] Furthermore, according to the first embodiment, when a mobile object is assumed to pass through the end of lanes LA or LA1 where vehicle 1 is present, and the distance between the end and vehicle 1 or another mobile object in the lane width direction D2 is greater than a predetermined distance, a virtual travel path DR is set for the mobile object. This virtual travel path DR is an area of a predetermined width that is treated as a lane different from lanes LA or LA1 where vehicle 1 is present. In other words, trajectory prediction is performed based on the space in which the mobile object is present. This improves the appropriateness of the handling of the mobile object.

[0208] (Second embodiment)

[0209] like Figure 21 As shown, the second embodiment is a modified example of the first embodiment. The second embodiment will be described focusing on the differences from the first embodiment.

[0210] In the second embodiment, RSS can be implemented as a dedicated risk confirmation function instead of deriving an appropriate response. In this example, the risk confirmation unit 126 can be built into the driving system 2 as a functional module separate from the detection unit 10, planning unit 120, and action unit 130.

[0211] The risk confirmation unit 126 obtains the situation data from the detection unit 10. The risk confirmation unit 126 extracts the situation from the situation data and assumes an object related to safety. The object here can include at least one of an actual passing moving object detected by the detection unit 10 and a virtual passing moving object.

[0212] The risk confirmation unit 126 determines the risk associated with the assumed object and outputs the confirmation result to the planning unit 20. This risk confirmation can utilize, for example, an RSS model 127 installed in the risk confirmation unit 126 as a program. Risk confirmation can be performed in the same manner as in the first embodiment. The confirmation result can include a determination of whether the risk is permissible. The confirmation result can also include the safety envelope and safety distance values used by the RSS model 127 in its calculations.

[0213] The planning unit 120 plans the driving of the vehicle 1 based on the confirmation results received from the risk confirmation unit 126. The planning unit 120 can comprehensively assess the status data received from the detection unit 10 and the confirmation results to plan the driving of the vehicle 1. Alternatively, the planning unit 120 can plan the driving of the vehicle 1 based on the status data received from the detection unit 10 and revise the plan if the risk confirmation unit 126 notifies it of the existence of an unacceptable risk. The action unit 130 does not need to apply RSS constraints and can directly implement the trajectory plan received from the planning unit 120 through the motion actuator 60.

[0214] In the second embodiment, the risk confirmation unit 126 may be realized by the RSS unit 53 similar to the first embodiment. The risk confirmation unit 126 may also be realized by the dedicated computer 51 of the processing system 50. The hardware that realizes the function of the risk confirmation unit 126 corresponds to the confirmation device.

[0215] (Third embodiment)

[0216] like Figure 22 As shown, the third embodiment is a modified example of the first embodiment. The third embodiment will be described focusing on the differences from the first embodiment.

[0217] In the third embodiment, RSS can be used not for deriving the driving and behavior of vehicle 1, but instead for a dedicated recording function for subsequent verification and suitability confirmation of driving system 2. In this example, a risk confirmation unit 226 and a recording unit 228 are built into driving system 2 as functional modules separate from the detection unit 10, planning unit 220, and action unit 230.

[0218] The risk confirmation unit 226 acquires the status data from the detection unit 10. Similar to the second embodiment, the risk confirmation unit 226 assumes an object related to safety and confirms the risk using the RSS model 227. The risk confirmation unit 226 provides the confirmation result to the recording unit 228.

[0219] The recording unit 228 organizes the processing results of the planning unit 220 and the confirmation results of the risk confirmation unit 226, and records them sequentially or periodically. The recording may also be to the vehicle-mounted storage medium 55c. Alternatively, the recording may be off-vehicle, that is, to the storage medium 96a of the external system 96 by transmitting the recorded data via the communication system 43.

[0220] The recording unit 228 can also generate data in the DSSAD (Data Storage System for Automated Driving) format when organizing the processing results from the planning unit 220 and the confirmation results from the risk confirmation unit 226. If the DSSAD format does not support recording risk confirmation results, an extended data format suitable for recording risk confirmation results can be used. If the DSSAD format does not support recording risk confirmation results, the risk confirmation results can be generated as dedicated data.

[0221] In the third embodiment, the risk confirmation unit 226 may be realized by the RSS unit 53 similar to the first embodiment. The risk confirmation unit 226 may also be realized by the dedicated computer 51 of the processing system 50. The hardware that realizes the function of the risk confirmation unit 226 corresponds to the confirmation device.

[0222] Figure 22 The architecture shown can also be used for simulations, which are simulations in the preliminary verification and suitability confirmation of the driving system 2. In this case, the implementation Figure 22 The hardware for the architecture may not be installed on vehicle 1. In other words, all processing may be performed on a simulation computer. In this case, the simulation computer serves as an off-vehicle verification device. Such simulations may also be publicly conducted by the certification body that certifies driving system 2.

[0223] (Fourth embodiment)

[0224] The fourth embodiment is a modified example of the first embodiment. The fourth embodiment will be described focusing on differences from the first embodiment.

[0225] In the fourth embodiment, in the algorithm for the state transition of the vehicle 1 with respect to the passing moving object, the frequent occurrence of excessive responses of the vehicle 1 is suppressed by processing that the passing moving object is traveling in another lane.

[0226] like Figure 23 The figure shows the state transitions of vehicle 1 used to calculate an appropriate response. Here, the four states of safe M1, lateral danger M2, longitudinal danger M3, and longitudinal and lateral danger M4 transition to each other. Furthermore, longitudinal response M5, longitudinal stop M6, lateral response M7, and lateral stop M8 are states after the appropriate response, including braking, has begun.

[0227] States M1 to M4 can be transformed into each other based on the longitudinal safety distance and the lateral safety distance. In detail, when the current longitudinal distance to other road users (hereinafter referred to as the longitudinal current distance) is greater than the longitudinal safety distance, and the current lateral distance to other road users (hereinafter referred to as the lateral current distance) is greater than the lateral safety distance, the state is safe M1. When the longitudinal current distance is greater than the longitudinal safety distance, and the lateral current distance is less than the lateral safety distance, the state is a lateral danger state M2. When the longitudinal current distance is less than the longitudinal safety distance, and the lateral current distance is greater than the lateral safety distance, the state is a longitudinal danger state M3. When the longitudinal current distance is less than the longitudinal safety distance, and the lateral current distance is less than the lateral safety distance, the state is a longitudinal and lateral danger state M4. The state transition described here is a state transition relative to other road users existing in other lanes (such as adjacent lanes).

[0228] In other words, safe state M1 can be described as a state where the risk of collision between vehicle 1 and other road users is lower than a preset threshold in both the longitudinal and lateral directions. Laterally dangerous state M2 can be described as a state where the longitudinal risk of collision is lower than a preset threshold, but the lateral risk of collision is higher than a preset threshold. Longitudinal dangerous state M3 can be described as a state where the lateral risk of collision is lower than a preset threshold, but the longitudinal risk of collision is higher than a preset threshold. Longitudinal and lateral dangerous state M4 can be described as a state where the risk of collision is higher than a preset threshold in both the longitudinal and lateral directions.

[0229] The transition from the longitudinal and transverse dangerous state M4 to the longitudinal response M5 and transverse response M6 is based on the conditions for transitioning to the respective states M5 and M6. For example, if the longitudinal dangerous state duration is longer than the transverse dangerous state duration and longer than the reaction time, the state transitions to the longitudinal response M5, initiating appropriate responses including braking. For example, if the transverse dangerous state duration is longer than the longitudinal dangerous state duration and longer than the reaction time, the state transitions to the transverse response M7, initiating appropriate responses including braking.

[0230] If the longitudinal current distance returns to a state greater than the longitudinal safety distance during longitudinal response M5, the state becomes a lateral dangerous state M2. If the longitudinal stop determination is performed during longitudinal response M5 and it is determined that the vehicle should stop, the state becomes a longitudinal stop M6. If the longitudinal current distance returns to a state greater than the longitudinal safety distance due to the vehicle 1 stopping, the state becomes a lateral dangerous state M2.

[0231] If the current lateral distance returns to a state greater than the lateral safety distance during lateral response M7, the state becomes a longitudinal dangerous state M3. If M7 performs a lateral stop determination during lateral response and determines that a stop is necessary, the state becomes a lateral stop M8. If the current lateral distance returns to a state greater than the lateral safety distance due to a lateral stop of the vehicle 1 (e.g., aborting a lane change), the state becomes a longitudinal dangerous state M3.

[0232] Furthermore, the transition to the longitudinal stop M6 and the lateral stop M8 may also correspond to the DDT backup. The longitudinal stop determination, the lateral stop determination, and other stop determinations may be executed by the planning unit 20 instead of the RRS 26 .

[0233] Next, we will explain the difference between the state transitions with respect to other road users traveling in the same lane as vehicle 1 and the state transitions with respect to other road users in other lanes (e.g., adjacent lanes). When other road users are traveling in the same lane as vehicle 1, the lateral direction is always considered unsafe, i.e., dangerous, regardless of the relationship between the current lateral distance and the lateral safety distance. Therefore, vehicle 1 is essentially in two states, the lateral danger state M2 and the longitudinal and transverse danger state M4, among states M1 to M4 where no appropriate response, including braking, is being executed.

[0234] Therefore, if a passing vehicle traveling in the same lane as vehicle 1 is treated as a vehicle traveling in the same lane, the vehicle will steadily enter a dangerous longitudinal and transverse state M4 during parallel driving, lane change, or acceleration. Consequently, not only will the calculation of transition conditions to longitudinal response M7 and lateral response M9 frequently occur, but appropriate responses, including braking, will also frequently be executed. RSS 26, therefore, avoids this situation by treating the passing vehicle as traveling in a different lane. When this processing is performed, the area occupied by the passing vehicle's trajectory may or may not be set to the travel road DR of a different lane.

[0235] According to the fourth embodiment described above, when a collision risk is identified as a dangerous state in both the longitudinal and lateral directions, a determination is made as to whether an appropriate response, including braking, should be executed. Furthermore, even if a passing object is assumed to be within the lane where vehicle 1 is located, the area occupied by the track is treated as a separate lane, thereby reducing the likelihood of determining a dangerous state in both the longitudinal and lateral directions. Consequently, the frequent occurrence of excessive responses to passing objects can be suppressed.

[0236] Furthermore, according to the fourth embodiment, for other road users in a lane different from the one in which vehicle 1 is located, a lateral danger state is determined if specified conditions are met. On the other hand, for other road users in the same lane as vehicle 1, a collision risk is confirmed using an algorithm that determines a lateral danger state. Furthermore, by treating a passing vehicle as a vehicle in a different lane, unconditional lateral danger state determinations are avoided. This prevents frequent excessive responses to passing vehicles.

[0237] Furthermore, according to the fourth embodiment, the collision risk assessment for a passing mobile object is based on the condition that the collision risk is judged to be lower, similar to that for other road users in a different lane from the vehicle. As a result, the likelihood of the collision risk being judged to be higher than a preset threshold is low, making it difficult to determine whether to execute an appropriate response, including braking. This can prevent the frequent occurrence of excessive responses to passing mobile objects. This improves the appropriateness of handling of such mobile objects when determining the collision risk with them in a lane.

[0238] Furthermore, according to the fourth embodiment, longitudinal and lateral collision risks are separately determined. Furthermore, if the collision risk in both the longitudinal and lateral directions is determined to be higher than a preset threshold, a determination is made as to whether an appropriate response should be taken. Furthermore, the conditions for determining the lateral collision risk, either longitudinal or lateral, are modified based on the lane behavior of other road users.

[0239] Here, in handling the lane of a passing object, even if a passing object is in the lane where vehicle 1 is located, the lateral collision risk is determined as if the passing object is in a lane different from the lane where vehicle 1 is located. This can suppress the frequent occurrence of excessive responses to passing objects.

[0240] Furthermore, according to the fourth embodiment, when another road user is in a different lane from vehicle 1, the lateral collision risk determination condition is whether the lateral distance between vehicle 1 and the other road user is greater than the lateral safety distance. On the other hand, when another road user is in the same lane as vehicle 1, the lateral collision risk is determined to be higher than a preset threshold. By treating the situation as a passing object in a different lane from the one in which vehicle 1 is present based on this modified condition, it is possible to suppress the frequent occurrence of excessive responses to passing objects.

[0241] (Other Embodiments)

[0242] Although a plurality of embodiments have been described above, the present disclosure is not limited to these embodiments and can be applied to various embodiments and combinations within the scope not departing from the gist of the present disclosure.

[0243] In other embodiments, RSS 26 may also use information received by communication system 43 from at least one of other vehicles and roadside equipment via V2X communication to improve the accuracy of the estimated traveling object. The situation extraction unit 27 may obtain and use at least one of information related to objects outside sensor-detectable ranges SR1 and SR2 and information related to objects in obstruction area OA via V2X communication.

[0244] For example, when the RSS 26 receives information that a passing object exists outside the sensor-detectable ranges SR1 and SR2 and in the obstruction area OA, the RSS 26 may set the travel path DR for the passing object based on the information that the passing object exists. On the other hand, when the RSS 26 receives information that a passing object does not exist outside the sensor-detectable ranges SR1 and SR2 and in the obstruction area OA, the RSS 26 may not assume a virtual passing object in an area where no passing object exists.

[0245] In addition, in other embodiments, RSS26 may also correspond to Figure 24 The scene shown. Figure 24 In the example shown, vehicle 1 is about to turn right from the current lane LA1 across the opposite lane LA2, for example, to a roadside parking lot. It is assumed that there is no sidewalk between the roadside parking lot and lane LA2. Here, the opposite lane LA2 is in a traffic jam. Vehicle 1 is about to turn right through a gap in the traffic jam in the opposite lane LA2. In front of vehicle 1, there is a limited range SR1 that can be detected by sensors. This range SR1 can include both a limited angular range and a limited distance range. Within the range SR1 that can be detected by sensors in the opposite lane LA2, there is a stopped opposite vehicle OV10, and the field of view of vehicle 1 is limited by this opposite vehicle OV10. Due to the limited field of view, an obstruction area OA is formed on the side opposite to vehicle 1 across from the opposite vehicle OV10.

[0246] Here, RSS26 assumes that other road users may emerge from the occlusion area OA. Figure 24Specifically, in this example, it is assumed that a virtual object SO8, such as a motorcycle, bicycle, or pedestrian, is present in the occlusion area OA. This virtual object SO8 may appear at any time within the sensor detection range SR1 behind vehicle 1. Furthermore, the predicted trajectory of virtual object SO8 is assumed to be within the oncoming lane LA2. Furthermore, the travel path DR of virtual object SO8 is set within the area occupied by the trajectory. RSS 26 also supports the collision risk between virtual object SO8 and vehicle 1.

[0247] In addition, in other embodiments, RSS26 may also correspond to Figure 25 The scenario shown. In this scenario, in lane LA, vehicle 1 is following a large vehicle OV11, which is another road user of larger size. The large vehicle OV11 may be, for example, a truck, a trailer, a bus, etc. As a result, most of the range SR1 that can be detected by the sensor in front of vehicle 1 becomes the blocked area OA. In this case, RSS26 may also assume that a virtual object SO9 such as a VRU such as a motorcycle and a small vehicle such as a small vehicle are traveling further ahead of the large vehicle OV11. RSS26 may also assume that if the large vehicle OV11 changes lanes to overtake the virtual object SO9, the virtual object SO9 may appear from the blocked area OA at any time. RSS26 may also assume that the virtual object SO9 is a moving object such as a motorcycle. Under such an assumption, RSS26 may set the area occupied by the assumed track of the virtual object SO9 as the driving road DR when the large vehicle OV11 changes lanes to overtake the virtual object SO9.

[0248] In addition, in other embodiments, RSS26 may also correspond to Figure 26 The scene shown. Figure 26 As shown, the passing vehicle is an emergency vehicle EV. This emergency vehicle EV can be, for example, an ambulance, fire truck, or police car. For example, assume that vehicle 1 is traveling in lane LA1. An emergency vehicle EV traveling in the opposing lane LA2 changes lanes to overtake vehicle OV12, which is in the same lane LA2 and is making an emergency avoidance move. This vehicle then enters lane LA1. In this case, RSS 26 can also treat the emergency vehicle EV as a passing vehicle and generate a hypothetical travel path DR for the emergency vehicle EV. This means that RSS 26 also supports the collision risk between the emergency vehicle EV and vehicle 1.

[0249] In addition, in other embodiments, RSS26 may also correspond to Figure 27 The scene shown in FIG. This scene is a scene in which vehicle 1 is on a multi-lane road (for example, a road with more than three lanes on each side) with vacant lanes. Figure 27As shown, on a three-lane road, vehicle 1 is traveling in lane LA1 at one end, leaving the center lane LA2 empty. In lane LA3 at the other end, a preceding vehicle OV13 and a motorcycle SO10 following the preceding vehicle OV13 are traveling. Furthermore, vehicle 1 activates its turn signal and changes lanes to the center lane LA2. Meanwhile, motorcycle SO10 also attempts to change lanes and overtake the preceding vehicle OV13, moving laterally toward the center lane LA2.

[0250] In such a scenario, RSS 26 can also assume a trajectory that passes between the preceding other vehicle OV13 and the vehicle 1 after the lane change, as the assumed trajectory for the motorcycle SO10 that detects the lane change of vehicle 1. Furthermore, RSS 26 can set the motorcycle SO10's travel path DR within the area occupied by this trajectory. In this way, RSS 26 can also support the assumed collision risk after the lane change of vehicle 1.

[0251] In supporting the various scenarios described in the first through third embodiments and other embodiments, the RSS 26 may assume and identify other road users as passing vehicles and assume their trajectories without setting a travel road DR for treating them as passing vehicles in other lanes. In other words, in various scenarios, the state transition conditions of the fourth embodiment may be set based on the assumption that a passing vehicle exists in another lane.

[0252] In other embodiments, other safety models other than the RSS model may be used to generate the travel route DR assuming a traveling moving body. For example, the driving system 2 may also implement an SFF (Safety Force Field) model.

[0253] For example, by calculating the claimed set of a moving object through spatiotemporal analysis in the SFF model, the driving system 2 can also set the travel path DR of the moving object. Here, the claimed set can be defined as the size of the spacetime between the safe process timeline and the maximum braking timeline. The maximum braking timeline can be calculated using the minimum assumed longitudinal deceleration that is reasonably foreseeable.

[0254] The driving system 2 can calculate the spacetime claimed by the traveling object as an agent, limited to the travel route DR set for the traveling object. In other words, by omitting or simplifying the spacetime analysis outside the travel route DR, the processing load for calculating the claim set can be reduced.

[0255] In other embodiments, the RSS unit 53 may be integrated with the dedicated computer 51. In other embodiments, the RSS unit 53 may be provided independently of the processing system 50 so that the operation of the processing system 50 can be monitored from the outside.

[0256] in addition, Figure 11 、 14 The scenarios shown in 16 to 19 and 23 are assumed to be applied to countries or regions where traffic flows on the left side of the road. However, the scenarios can be reversed and applied to countries or regions where traffic flows on the right side of the road.

[0257] The control unit and method described in the present disclosure may also be implemented by a special-purpose computer, which constitutes a processor programmed to execute one or more functions embodied by a computer program. Alternatively, the device and method described in the present disclosure may also be implemented by a dedicated hardware logic circuit. Alternatively, the device and method described in the present disclosure may also be implemented by one or more special-purpose computers, which are composed of a combination of a processor that executes a computer program and one or more hardware logic circuits. In addition, the computer program may also be stored in a computer-readable non-temporary tangible recording medium as an instruction executed by a computer.

[0258] (Explanation of terms)

[0259] The following describes terms related to the disclosure of this specification. This description is included in the embodiment of this specification.

[0260] A road user is a person who uses a road, including sidewalks and other adjacent spaces. A road user may also include pedestrians, cyclists, other VRUs, and vehicles (e.g., cars driven by humans or vehicles equipped with autonomous driving systems).

[0261] A dynamic driving task (DDT) may be a real-time operational and tactical function used to operate a vehicle in traffic.

[0262] An automated driving system may be an integrated hardware and software that can continuously execute overall DDT regardless of whether it is limited to a specific operational design area.

[0263] SOTIF (safety of the intended functionality) can be the absence of unreasonable risks due to inadequacy of the intended functionality or its implementation.

[0264] A driving policy may be a strategy and rules that define control actions at the vehicle level.

[0265] A scenario is a description of the temporal relationships between several scenarios within a series of scenarios, including goals and values under specific circumstances influenced by actions and events. A scenario is a description of a continuous time sequence of activities that integrates the vehicle as the subject, its entire external environment, and their interactions during the execution of a specific driving task.

[0266] A triggering condition may be a specific condition of a scenario that functions as an opportunity for a subsequent system reaction that results in an inability to prevent, detect, and mitigate dangerous behavior or reasonably foreseeable consequential misuse.

[0267] A proper response may be an action that is important to avoid or ameliorate a hazardous situation in a reasonably foreseeable scenario where other safety-related objects behave within the assumed range.

[0268] An operational design domain (ODD) may be a specific condition under which a given (autonomous) driving system is designed to function.

[0269] A safety-related model can be a representation of safety-related aspects of driving behavior based on assumptions about the reasonably foreseeable behavior of other road users. It can also be an onboard or off-board safety verification or analysis device, a mathematical model, a more conceptual set of rules, a scenario-based set of behaviors, or a combination thereof.

[0270] A formal model may be a model represented by a formal expression used in system performance verification.

[0271] A safety envelope can be a set of constraints and conditions designed to govern or control the actions of an (autonomous) driving system, in order to maintain operation within acceptable risk levels. The safety envelope can be a general concept used to describe the full range of principles that a driving strategy can be based on, according to which the vehicle, under the control of an (autonomous) driving system, can have one or more boundaries around it.

[0272] Reaction time can be the time it takes for a road user to perceive a specific stimulus and start to execute a response (braking, steering, accelerating, stopping, etc.) in a given scenario.

[0273] Situations may be important factors that may affect the behavior of the system, and may include traffic conditions, weather, and the behavior of the host vehicle.

[0274] A hazardous situation may be an increased risk for a potential violation of the safety envelope and also represent an increased level of risk present in the DDT.

[0275] Reasonably foreseeable means that it is technically reliable and has a reliable or measurable occurrence rate.

[0276] Vulnerable road users (VRUs) are road users who are not riding in passenger cars, public transportation, trains, etc. VRUs can be motorcyclists, cyclists, pedestrians, people with disabilities, or people with limited mobility, among other unprotected road users.

[0277] A minimal risk maneuver (MRM) may be a function of an automated driving system that transitions a vehicle between a nominal state and a minimal risk condition (MRC).

[0278] DDT fallback can be a response from the driver or the autonomous system to either execute DDT or transition to a minimal-risk state after a failure occurs, a malfunction is detected, or a potentially dangerous behavior is detected. DDT fallback can be a method of transferring control from autonomous to driver- or other system-based control, using takeover / fallback states and associated use cases.

[0279] (Disclosure of technical ideas)

[0280] This specification discloses multiple technical concepts described in the following items. Some items are described in a multiple-dependent form, where subsequent items selectively reference previous items. These items described in a multiple-dependent form define multiple technical concepts.

[0281] Technical Concept 1

[0282] A confirmation device is provided, comprising at least one processor (53b), and is used for driving a vehicle (1), wherein:

[0283] The above processor performs the following:

[0284] The trajectory of the mobile object (SO1, SO2, SO3, SO4, SO5, SO6, SO7, SO8, SO9, SO10, EV) predicted to travel through the lane (LA, LA1) where the above-mentioned vehicle exists is assumed to be included in the above-mentioned lane; and

[0285] The collision risk between the vehicle and the moving object is confirmed after treating at least a portion of the area (DR, DR1, DR2, TR) occupied by the track as a lane different from the lane in which the vehicle is present.

[0286] Technical Thought 2

[0287] According to the confirmation device of technical idea 1,

[0288] The processor further executes the following: if it is determined that both longitudinal and lateral directions are dangerous in the collision risk, determining whether to perform an appropriate response including braking;

[0289] In the above confirmation, even if the moving object is assumed to be in the lane where the vehicle exists, the area occupied by the track is treated as the other lane, thereby reducing the possibility of determining that both the longitudinal and lateral directions are in a dangerous state.

[0290] Technical Thought 3

[0291] According to the confirmation device of technical idea 2,

[0292] In the above confirmation, for other road users in a lane different from the lane where the above vehicle exists, it is judged that the lateral direction is in a dangerous state when the specified conditions are met. For other road users in the same lane as the lane where the above vehicle exists, the above collision risk is confirmed using an algorithm that unconditionally judges that the lateral direction is in a dangerous state.

[0293] Technical Concept 4

[0294] According to the confirmation device of technical idea 1,

[0295] In the above confirmation, even if the moving object is assumed to be in the lane where the vehicle exists, the area occupied by the track is treated as the other lane, thereby simplifying the confirmation of the longitudinal safety distance between the vehicle and the moving object.

[0296] Technical Thought 5

[0297] According to the confirmation device of technical idea 1,

[0298] In the above confirmation, even if the moving object is assumed to be in the lane where the vehicle exists, the area occupied by the track is treated as the other lane, thereby omitting confirmation of the longitudinal safety distance between the vehicle and the moving object.

[0299] Technical Thought 6

[0300] The confirmation device according to any one of technical ideas 1 to 5, wherein:

[0301] The moving object is a virtual moving object assumed in an occlusion area (OA) caused by the limitation of the field of view of the vehicle.

[0302] Technical Thought 7

[0303] The confirmation device according to any one of technical ideas 1 to 5, wherein:

[0304] The moving object is a virtual moving object assumed outside a range detectable by the sensor provided on the vehicle.

[0305] Technical Thought 8

[0306] The confirmation device according to any one of technical concepts 1 to 6, wherein:

[0307] Also execute the following:

[0308] When the above-mentioned moving body is assumed at the end of the lane where the above-mentioned vehicle exists, and when the distance in the lane width direction (D2) between the above-mentioned end and the above-mentioned vehicle or other moving body is greater than the prescribed distance, a virtual driving road assumed for the above-mentioned moving body is set, and the virtual driving road is the above-mentioned area of the prescribed width treated as a lane different from the lane where the above-mentioned vehicle exists.

[0309] Technical Thought 9

[0310] A confirmation device is provided, comprising at least one processor (53b), and is used for driving a vehicle (1), wherein:

[0311] The above processor performs the following:

[0312] Assume that there are moving bodies (SO1, SO2, SO3, SO4, SO5, SO6, SO7, SO8, SO9, SO10, EV) traveling in the lane (LA, LA1) where the above-mentioned vehicle exists; and

[0313] Even if the moving object is in the lane where the vehicle is present, the collision risk between the vehicle and the moving object is confirmed, treating the moving object as being in a lane different from the lane where the vehicle is present.

[0314] According to this technical concept, the appropriateness of the processing for a moving object that crosses a lane can be improved.

[0315] Technical Thought 10

[0316] A storage medium is a storage medium for storing data related to driving of a vehicle (1) processed by a driving system (1), wherein the following information is stored in association with each other:

[0317] Information on the behavior of passing moving objects (SO1, SO2, SO3, SO4, SO5, SO6, SO7, SO8, SO9, SO10, EV) passing around the vehicle, as assumed by the driving system; and

[0318] The driving system has set information related to the area (DR, DR1, DR2, TR) occupied by the trajectory predicted for the traveling object.

[0319] According to this technical concept, it is easy to verify and confirm the appropriateness of the assumption made by the driving system regarding the traveling moving object.

[0320] Technical Thought 11

[0321] A method for generating data related to driving of a vehicle (1) by at least one processor (51b, 53b), comprising:

[0322] Determining kinematic characteristics related to the behavior of the passing moving objects (SO1, SO2, SO3, SO4, SO5, SO6, SO7, SO8, SO9, SO10, EV) passing around the vehicle;

[0323] Setting the area (DR, DR1, DR2, TR) occupied by the trajectory predicted for the traveling object; and

[0324] Data in which the kinematic characteristics and the regions are associated are generated.

[0325] According to this technical concept, it is easy to verify and confirm the appropriateness of the assumptions made by the driving system regarding the traveling moving object.

[0326] Technical Thought 12

[0327] The method according to technical idea 9 further comprises:

[0328] The data is stored in association with information related to an appropriate response calculated by treating the area as another lane.

[0329] Technical Thought 13

[0330] A system is provided, comprising at least one processor (51b), and using a visual information presentation type information presentation device (70) for display, wherein:

[0331] For the above processors,

[0332] The mobile objects (SO1, SO2, SO3, SO4, SO5, SO6, SO7, SO8, SO9, SO10, EV) passing around the vehicle are displayed on the information presentation device.

[0333] The track and the travel route (DR) along which the moving object is predicted to travel are superimposed on the image showing the moving object and displayed on the information presentation device.

[0334] Technical Thought 14

[0335] A driving system is a driving system for driving a vehicle (1), comprising:

[0336] Sensors (41, 42, 43, 44);

[0337] The computer (51) acquires sensor data from the sensor, generates an environmental model of the vehicle's surroundings based on the sensor data, plans driving of the vehicle using the environmental model, and controls a motion actuator (60) of the vehicle based on the plan; and

[0338] The RSS unit (53) is a unit equipped with an RSS model, which confirms the collision risk of the above-mentioned vehicle.

[0339] The above RSS unit does the following:

[0340] Obtain the environment model from the above computer,

[0341] Based on the above environment model, the trajectory of the passing vehicles (SO1, SO2, SO3, SO4, SO5, SO6, SO7, SO8, SO9, SO10, EV) predicted to pass through the lane (LA, LA1) where the above vehicle exists is assumed to be included in the above lane.

[0342] The risk of collision between the vehicle and the passing moving object is determined based on treating at least a portion of the area (DR, DR1, DR2, TR) occupied by the track as a lane different from the lane in which the vehicle is located.

[0343] If the collision risk exceeds a predetermined risk value, an appropriate response is derived.

[0344] Applying the appropriate response to the plan generates a request to a motion actuator (60) of the vehicle.

[0345] According to this technical concept, the appropriateness of the processing for a moving object that crosses a lane can be improved.

[0346] Technical Thought 15

[0347] A driving method is a driving method for driving a vehicle (1), wherein:

[0348] Acquire sensor data from the sensors (41, 42, 43, 44) of the above-mentioned vehicle and generate an environment model,

[0349] Using the above environment model to plan the driving of the above vehicle,

[0350] Based on the above environment model, the trajectory of the passing vehicles (SO1, SO2, SO3, SO4, SO5, SO6, SO7, SO8, SO9, SO10, EV) predicted to pass through the lane (LA, LA1) where the above vehicle exists is assumed to be included in the above lane.

[0351] The risk of collision between the vehicle and the passing moving object is determined based on treating at least a portion of the area (DR, DR1, DR2, TR) occupied by the track as a lane different from the lane in which the vehicle is located.

[0352] If the collision risk exceeds a predetermined risk value, an appropriate response is derived.

[0353] applying said appropriate response to said plan to generate a request to said vehicle's motion actuator (60),

[0354] Control the above-mentioned motion actuator.

[0355] According to this technical concept, the appropriateness of the processing for a moving object that crosses a lane can be improved.

[0356] Technical Thought 16

[0357] A confirmation device is provided, comprising at least one processor (53b), and is used for driving a vehicle (1), wherein:

[0358] The above processor performs the following:

[0359] Identify the collision risk between the above-mentioned vehicle and other road users;

[0360] If it is determined that the collision risk is higher than a predetermined threshold, determining whether to execute an appropriate response including braking;

[0361] When the other road user is in the same lane as the vehicle, the condition for determining the collision risk is changed so that the collision risk is determined to be higher than when the other road user is in a different lane from the vehicle;

[0362] As the other road users, it is assumed that there are moving objects (SO1, SO2, SO3, SO4, SO5, SO6, SO7, SO8, SO9, SO10, EV) traveling in the lane (LA, LA1) where the vehicle exists; and

[0363] Even if the moving object is present in the lane where the vehicle is present, in the judgment of the collision risk, it is treated as if the moving object is present in a lane different from the lane where the vehicle is present.

Claims

1. A confirmation device comprising at least one processor (53b) for driving a vehicle (1), wherein: The above processor performs the following: The trajectory of the mobile object (SO1, SO2, SO3, SO4, SO5, SO6, SO7, SO8, SO9, SO10, EV) predicted to travel through the lane (LA, LA1) where the above-mentioned vehicle exists is assumed to be included in the above-mentioned lane; and The collision risk between the vehicle and the moving object is confirmed after treating at least a portion of the area (DR, DR1, DR2, TR) occupied by the track as a lane different from the lane in which the vehicle is present.

2. The confirmation device according to claim 1, wherein: The processor further executes the following: if it is determined that both longitudinal and lateral directions are dangerous in the collision risk, determining whether to perform an appropriate response including braking; During the confirmation, even if the moving object is assumed to be in the lane where the vehicle exists, the area occupied by the track is treated as the other lane, thereby reducing the possibility of determining that both the longitudinal and lateral directions are dangerous.

3. The confirmation device according to claim 2, wherein: When performing the above-mentioned confirmation, for other road users in a lane different from the lane where the above-mentioned vehicle exists, it is judged that the lateral situation is dangerous if the specified conditions are met. For other road users in the same lane as the lane where the above-mentioned vehicle exists, the above-mentioned collision risk is confirmed using an algorithm that judges that the lateral situation is dangerous.

4. The confirmation device according to claim 1, wherein: During the confirmation, even if the moving object is assumed to be in the lane where the vehicle exists, the area occupied by the track is treated as the other lane, thereby simplifying the confirmation of the longitudinal safety distance between the vehicle and the moving object.

5. The confirmation device according to claim 1, wherein: During the confirmation, even if the moving object is assumed to be in the lane where the vehicle exists, the area occupied by the track is treated as the other lane, thereby omitting the confirmation of the longitudinal safety distance between the vehicle and the moving object.

6. The confirmation device according to claim 1, wherein: The moving object is a virtual moving object assumed in an occlusion area (OA) caused by the limitation of the field of view of the vehicle.

7. The confirmation device according to claim 1, wherein: The moving object is a virtual moving object assumed outside a range detectable by the sensor provided on the vehicle.

8. The confirmation device according to claim 1, wherein: Also execute the following: When the above-mentioned moving body is assumed at the end of the lane where the above-mentioned vehicle exists, and when the distance in the lane width direction (D2) between the above-mentioned end and the above-mentioned vehicle or other moving body is greater than the prescribed distance, a virtual driving road assumed for the above-mentioned moving body is set, and the virtual driving road is the above-mentioned area of the prescribed width treated as a lane different from the lane where the above-mentioned vehicle exists.

9. A method for confirming the collision risk of a vehicle (1) executed by at least one processor (53b), wherein: Include: The trajectory of the mobile object (SO1, SO2, SO3, SO4, SO5, SO6, SO7, SO8, SO9, SO10, EV) predicted to travel through the lane (LA, LA1) where the above-mentioned vehicle exists is assumed to be included in the above-mentioned lane; and The collision risk between the vehicle and the moving object is confirmed after treating at least a portion of the area (DR, DR1, DR2, TR) occupied by the track as a lane different from the lane in which the vehicle is present.

10. A confirmation device comprising at least one processor (53b) for driving a vehicle (1), wherein: The above processor performs the following: Identify the collision risk between the above-mentioned vehicle and other road users; If it is determined that the collision risk is higher than a predetermined threshold, determining whether to execute an appropriate response including braking; When the other road user is in the same lane as the vehicle, the condition for determining the collision risk is changed so that the collision risk is determined to be higher than when the other road user is in a different lane from the vehicle; As the other road users, it is assumed that there are moving objects (SO1, SO2, SO3, SO4, SO5, SO6, SO7, SO8, SO9, SO10, EV) traveling in the lane (LA, LA1) where the vehicle exists; and Even if the moving object is present in the lane where the vehicle is present, in the judgment of the collision risk, it is treated as if the moving object is present in a lane different from the lane where the vehicle is present.

11. The confirmation device according to claim 10, wherein: The aforementioned confirmation of the collision risk includes separately confirming the aforementioned longitudinal collision risk and the aforementioned lateral collision risk. Regarding the above judgment on whether to execute an appropriate response, the judgment is made when it is judged that the above collision risk is higher than a preset threshold value in both the longitudinal and lateral directions. The above-mentioned change in the conditions for judging the collision risk is to change the conditions for judging the above-mentioned lateral collision risk. The above processing is to treat the moving object as being in a lane different from the lane where the vehicle is present, even if the moving object is present in the lane where the vehicle is present, in the determination of the lateral collision risk.

12. The confirmation device according to claim 11, wherein: The above-mentioned changed conditions for judging the collision risk are: when the above-mentioned other road users are in a lane different from the above-mentioned vehicle, whether the lateral distance between the above-mentioned vehicle and the above-mentioned other road users is greater than the lateral safety distance is used as a condition for judging the above-mentioned lateral collision risk; when the above-mentioned other road users are in the same lane as the above-mentioned vehicle, the conditions are changed so as to judge that the above-mentioned lateral collision risk is higher than a pre-set threshold.

Citation Information

Patent Citations

  • Sintered ore and method for producing the same, and sintered ore for hydrogen reduction and method for producing the same

    JP2023001415A

  • Systems, devices, and methods for predictive risk-aware driving

    US20210009121A1