Vehicle

By designing a multi-path redundancy structure in the vehicle, the problem of control instability caused by command path failure of the autonomous driving kit is solved, realizing the stability and safety of autonomous driving, and ensuring that the vehicle can safely decelerate or stop when multiple paths fail.

CN121777957APending Publication Date: 2026-04-03TOYOTA JIDOSHA KK
View PDF 1 Cites 0 Cited by

Patent Information

Application Number
CN202511420964.6
Authority / Receiving Office
CN · China
Patent Type
Applications(China)
Current Assignee / Owner
Priority Date
2024-10-01
Filing Date
2025-09-30
Publication Date
2026-04-03

AI Technical Summary

Technical Problem

Existing technologies cannot guarantee the stability of autonomous driving control and adequate failure protection when the command path function from the autonomous driving kit to the vehicle system fails, especially when multiple paths fail.

Method used

A multi-path redundancy structure was designed, including a first path, a second path, and a third path. The system continues to receive instructions from the autonomous driving suite through the unfailed paths and performs automatic deceleration control when all paths fail to ensure the vehicle stops safely.

Benefits of technology

It improves the stability and safety of autonomous driving control, and realizes appropriate failure protection in the case of multipath failure, ensuring that the vehicle can safely decelerate or stop.

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure CN121777957A_ABST
    Figure CN121777957A_ABST
Patent Text Reader

Abstract

The invention provides a vehicle. A vehicle includes a vehicle control interface box and a vehicle system. The vehicle control interface box comprises a first control device and a second control device. The vehicle system is configured so as to be able to receive a command from the automatic driving kit through each of a first path via the first control device and a second path via the second control device. The vehicle system continues automatic driving on the basis of a command from the automatic driving kit received through a path other than the path in which the function has failed when only one of the plurality of paths has failed in the automatic driving process. The vehicle system executes automatic deceleration control for controlling the brake device so as to decelerate the vehicle when both the first route and the second route fail in function during automatic driving.
Need to check novelty before this filing date? Find Prior Art

Description

Technical Field

[0001] This disclosure relates to a vehicle capable of carrying an autonomous driving kit. Background Technology

[0002] Japanese Patent Application Publication No. 2024-106017 discloses a vehicle capable of being equipped with an autonomous driving kit. This vehicle includes a vehicle control interface box and a vehicle system. The vehicle system is configured to receive instructions from the autonomous driving kit via multiple paths. Summary of the Invention

[0003] The autonomous driving kit described in Japanese Patent Application Publication No. 2024-106017 selects a path that is not affected by the failure of any function among multiple paths and sends commands through the selected path when any function among multiple paths fails. Based on this control, autonomous driving based on commands from the autonomous driving kit can continue even when any function among multiple paths fails, by using a path that is not affected by the failure of commands. However, if a function fails along the command path from the autonomous driving kit to the vehicle system, continuing autonomous driving based on commands from the autonomous driving kit is not necessarily preferred. Furthermore, Japanese Patent Application Publication No. 2024-106017 does not provide sufficient research on control when all paths fail.

[0004] This disclosure is an invention made to solve the above-mentioned problems, and its purpose is to simultaneously achieve stability of autonomous driving control based on instructions from an autonomous driving kit and appropriate fail-safe protection related to autonomous driving control.

[0005] According to this disclosure, the vehicle shown below may be provided.

[0006] (First item) The vehicle is configured to be capable of carrying an autonomous driving suite. The vehicle includes a vehicle control interface box and a vehicle system. The vehicle control interface box includes a first control device and a second control device. The vehicle system includes a braking device for decelerating the vehicle. The vehicle system is configured to receive instructions from the autonomous driving suite via each of multiple paths. The multiple paths include a first path via the first control device and a second path via the second control device. The vehicle system is configured to continue autonomous driving based on instructions received from the autonomous driving suite via paths other than the failed path, should only one of the multiple paths fail during autonomous driving. Furthermore, the vehicle system is configured to perform automatic deceleration control by controlling the braking device to decelerate the vehicle when both the first and second paths fail during autonomous driving.

[0007] If only one of the multiple paths (command paths) from the autonomous driving suite to the vehicle system fails, this is likely an intermittent failure. There is also a possibility that a transient functional failure caused by a momentary voltage drop or noise may be mistakenly detected as a constant functional failure. Therefore, in the above structure, in such cases, the vehicle system continues autonomous driving based on commands received from the autonomous driving suite through other paths that are not in a state of functional failure. Because autonomous driving based on commands from the autonomous driving suite can continue, the stability of autonomous driving control is improved.

[0008] On the other hand, if functional failures occur in two or more paths, the likelihood of this being a non-random failure increases. Therefore, in the above structure, if both the first and second paths fail during autonomous driving, the vehicle system executes the aforementioned automatic deceleration control. This provides appropriate failure protection related to autonomous driving control. Even assuming all paths fail, the vehicle system can execute pre-defined automatic deceleration control. Furthermore, the first and second paths are respectively controlled by a first control device and a second control device. These first and second control devices facilitate the detection of functional failures associated with each of the first and second paths.

[0009] Path failure from the autonomous driving suite to the vehicle system refers to a situation where the vehicle loses the ability to transmit instructions received from the autonomous driving suite to the vehicle system via that path. For example, a path failure occurs when a communication line along the path is broken. A path failure also occurs when a malfunction in the autonomous driving suite and / or the vehicle control interface box along the path prevents instructions from the autonomous driving suite from being transmitted to the vehicle system. Furthermore, a malfunction in the vehicle system's receiving function, preventing it from receiving instructions from the autonomous driving suite, also constitutes a path failure.

[0010] (Second item) In the vehicle described in the first item, the vehicle system further includes a third control device and a fourth control device for controlling the braking device. The first path is the path from the autonomous driving suite through the first control device to the third control device. The second path is the path from the autonomous driving suite through the second control device to the fourth control device.

[0011] In the above structure, the third control device in the first path and the fourth control device in the second path control the braking device respectively. Therefore, even if both the first and second paths fail, the automatic deceleration control described above can be executed via the third or fourth control device. Even if one of the control devices malfunctions, the braking device can still be controlled via the control device of the other device.

[0012] (Third item) In the vehicle described in the second item, the multiple paths also include a third path where instructions from the autonomous driving suite pass through the second control device to the third control device. If the first path is not malfunctioning, the third control device controls the braking device based on instructions received from the autonomous driving suite via the first path. If the first path is malfunctioning, and neither the second nor the third path is malfunctioning, the third control device controls the braking device based on instructions received from the autonomous driving suite via the third path.

[0013] In the above structure, if the first path is not malfunctioning, the third control unit controls the braking device based on instructions received from the autonomous driving suite via the first path. Furthermore, if only the first path fails, the third control unit controls the braking device based on instructions received from the autonomous driving suite via the third path. Even if the first path fails, the third control unit can continue autonomous driving control (braking device control) based on instructions from the autonomous driving suite. This improves the stability of autonomous driving control.

[0014] (Fourth item) In the vehicle described in the third item, if both the first path and the third path fail, the third control device or the fourth control device performs automatic deceleration control.

[0015] In the above structure, the automatic deceleration control described above is executed not only when both the first and second paths fail, but also when both the first and third paths fail. Thus, the stability of autonomous driving control based on instructions from the autonomous driving suite and appropriate fail-safe protection related to autonomous driving control can be achieved simultaneously.

[0016] (Fifth item) In any of the vehicles described in items one through four, the first control device is configured to determine whether communication between the autonomous driving suite and the first control device is functionally disabled, and output the result of the determination to the vehicle system. The second control device is configured to determine whether communication between the autonomous driving suite and the second control device is functionally disabled, and output the result of the determination to the vehicle system.

[0017] Based on the above structure, the vehicle system becomes easier to detect functional failures associated with each of the first and second paths.

[0018] (Sixth item) In the vehicle described in any of items one through five, the vehicle control interface box is configured to switch between active and inactive automatic deceleration control based on a request from the autonomous driving suite. The vehicle system is configured to perform automatic deceleration control only when it is active.

[0019] When the user (person) has control over the vehicle, since the user can drive the vehicle, automatic deceleration control can be omitted even if both the first and second paths are malfunctioning. For example, since the vehicle can be driven manually by the user even when the autonomous driving suite is not installed or is not functioning, automatic deceleration control can also be omitted. Therefore, in the above structure, the vehicle control interface box switches between enabling and disabling automatic deceleration control based on requests from the autonomous driving suite. With this structure, when the vehicle control interface box and the autonomous driving suite can communicate, it becomes easy to appropriately set the enabling / disabling of automatic deceleration control via the autonomous driving suite. The autonomous driving suite can also request the enabling or disabling of automatic deceleration control based on the level of autonomous driving. The level of autonomous driving is defined, for example, according to the Society of Automotive Engineers (SAE) standard J 3016.

[0020] (Seventh item) In the vehicle described in the sixth item, the vehicle control interface box is configured to prohibit the switching of the effective / ineffective automatic deceleration control during the automatic driving process.

[0021] If the activation / deactivation of automatic deceleration control is switched during autonomous driving, there is a possibility that the autonomous driving control may become unstable. Therefore, as mentioned above, by disabling the switching of the activation / deactivation of automatic deceleration control during autonomous driving, the stability of autonomous driving control can be improved.

[0022] (Eighth item) In any of the vehicles described in items one through seven, the vehicle system is configured to continue automatic deceleration control during the execution of automatic deceleration control without receiving new instructions from the automatic driving suite until the vehicle comes to a stop.

[0023] Based on the above structure, the vehicle system can slow down the vehicle to a stop through automatic deceleration control without receiving new instructions from the autonomous driving suite. This provides appropriate fail-safe protection related to autonomous driving control.

[0024] (Item 9) In any of the vehicles described in Items 1 to 8, when the vehicle system sends a deceleration command requesting the vehicle to decelerate, and when it is determined that both the first path and the second path are functionally ineffective, the braking device is controlled in the automatic deceleration control in such a way that the deceleration of the vehicle is close to the greater of the deceleration requested by the deceleration command and the pre-defined speed.

[0025] According to the above structure, the vehicle can be decelerated at a deceleration greater than or equal to a predetermined deceleration. Furthermore, in this structure, if the deceleration requested by the autonomous driving suite is greater than the predetermined deceleration when both the first and second paths are deemed to have failed, the vehicle is decelerated at the deceleration requested by the autonomous driving suite. Therefore, autonomous driving control (control of the braking device) based on instructions from the autonomous driving suite continues, thereby improving the stability of autonomous driving control.

[0026] (Item 10) In any of the vehicles described in Items 1 through 9, the vehicle system further includes a vehicle drive unit for accelerating the vehicle. When the autonomous driving suite sends an acceleration command requesting acceleration of the vehicle, if it is determined that both the first path and the second path are functionally inoperable, in the automatic deceleration control, after controlling the vehicle drive unit in a manner that makes the vehicle's acceleration zero, the vehicle system controls the braking device in a manner that makes the vehicle's deceleration close to a pre-defined deceleration.

[0027] According to the above structure, in an accelerating vehicle, the vehicle system sequentially controls the vehicle drive and braking devices, thereby enabling the vehicle to decelerate appropriately.

[0028] The above and other objects, features, aspects and advantages of the present invention will become clear from the following detailed description of the invention as understood in conjunction with the accompanying drawings. Attached Figure Description

[0029] Figure 1This diagram illustrates the general structure of a vehicle according to an embodiment of the present disclosure.

[0030] Figure 2 To indicate Figure 1 The diagram shows the detailed contents of the vehicle's systems.

[0031] Figure 3 For use in Figure 1 The diagram illustrates the path from the autonomous driving suite to the vehicle system within the vehicle.

[0032] Figure 4 For use in Figure 3 The diagram illustrates an example of the structure of the braking control unit.

[0033] Figure 5 This is a flowchart illustrating the processes performed at the start of autonomous driving in the autonomous driving method according to embodiments of this disclosure.

[0034] Figure 6 To indicate and Figure 5 The flowchart shown details the process of enabling / disabling automatic deceleration control in the workflow.

[0035] Figure 7 To indicate and pass Figure 2 The flowchart shown is a process related to the autonomous driving control performed by the vehicle control interface box.

[0036] Figure 8 To indicate and pass Figure 2 The flowchart shown is related to the processing of autonomous driving control performed by the autonomous driving kit.

[0037] Figure 9 For use in passing Figure 2 The diagram illustrates the processing performed on the base vehicle shown.

[0038] Figure 10 To indicate and pass Figure 2 The flowchart shows the driving control processes performed on the base vehicle.

[0039] Figure 11 To indicate Figure 9 The flowchart details the automatic deceleration control process.

[0040] Figure 12 To indicate Figure 5 The flowchart of the first modified example of the processing flow is shown.

[0041] Figure 13 To indicate Figure 5 The flowchart for the second modified example of the processing flow is shown.

[0042] Figure 14 To indicate Figure 4 The diagram shows an example of a modified structure.

[0043] Figure 15 To indicate Figure 3 The diagram shows a first example of a modified structure.

[0044] Figure 16 To indicate Figure 3 The diagram shows a second modified example of the structure. Detailed Implementation

[0045] Hereinafter, embodiments of the present disclosure will be described in detail with reference to the accompanying drawings. Furthermore, identical or equivalent parts in the drawings will be labeled with the same reference numerals and will not be described again.

[0046] Figure 1 This diagram illustrates the general structure of the vehicle according to an embodiment of this disclosure. (Refer to...) Figure 1 Vehicle 1 includes a VP (Vehicle Platform) 100 and an ADK (Autonomous Driving Kit) 200. The VP100 includes a Vehicle Control Interface Box (hereinafter referred to as "VCIB") 110 and a base vehicle 120. By adding the VCIB 110 to the base vehicle 120, a VP100 with a detachable ADK 200 is formed. The VCIB 110 is configured to communicate with both the base vehicle 120 and the ADK 200 via a communication bus. The VCIB 110 can also function as a gateway. Vehicle 1 is completed by installing the ADK 200 onto the VP100. In this embodiment, the ADK 200 is installed on the roof of the base vehicle 120. However, the installation location of the ADK 200 can be appropriately changed.

[0047] The base vehicle 120 is, for example, a commercially available xEV (electric vehicle). In this embodiment, a BEV (electric vehicle) is used as the base vehicle 120. However, it is not limited to this; the base vehicle 120 may also be an xEV other than a BEV. The base vehicle 120 includes a comprehensive control manager 130, an HMI (Human Machine Interface) 150, various systems for controlling the base vehicle 120, and various sensors (wheel speed sensors 127A, 127B, steering angle sensor 127C, camera 129A, radar sensors 129B, 129C, etc.). The comprehensive control manager 130 functions as a control device. The comprehensive control manager 130 comprehensively controls various systems related to the operation of the base vehicle 120 based on the detection results of the on-board sensors. The HMI 150 includes an input device and a notification device. Examples of notification devices include a display and a speaker. The HMI 150 may also include a touch panel display.

[0048] Figure 2 A diagram showing the detailed components of the system for vehicle 1. (Refer to...) Figure 1 and Figure 2 ADK200 includes an autonomous driving system (hereinafter referred to as "ADS") 210 for implementing autonomous driving of vehicle 1. ADS210 includes a computer component (hereinafter referred to as "ADSCOM") 211, an identification sensor 212, an attitude sensor 213, a sensor cleaner 216, and an HMI 218 (Human Machine Interface).

[0049] ADSCOM 211 includes computer modules (hereinafter referred to as "ADC") 211A and 211B. ADC 211A and 211B each have a processor and a storage device for storing autonomous driving software utilizing the API described later, and are configured such that the autonomous driving software can be executed by the processor. The identification sensor 212 includes a sensor that acquires information representing the external environment of the vehicle 1 (hereinafter also referred to as "environmental information"). The identification sensor 212 may also include at least one of a camera, millimeter-wave radar, and lidar. The attitude sensor 213 acquires information related to the attitude of the vehicle 1 (hereinafter also referred to as "attitude information"). The attitude sensor 213 may also include various sensors that detect the acceleration, angular velocity, and position of the vehicle 1. The HMI 218 includes an input device and a notification device.

[0050] The base vehicle 120 includes a braking system 121, a steering system 122, a transmission system 123, an active safety system 125, and a body system 126. In this embodiment, each system includes an electronic control unit (hereinafter also referred to as "ECU").

[0051] In vehicle 1, the control system related to the actions (driving, stopping, turning) of vehicle 1 is redundant. Although details will be described later, ADCs 211A and 211B issue instructions to the main system and the sub-system, respectively. VCIB 110 includes a VCI control unit 111A (hereinafter referred to as "VCI-1") for the main system and a VCI control unit 111B (hereinafter referred to as "VCI-2") for the sub-system. VCI control units 111A and 111B can also be computers equipped with processors and storage devices. VCI control units 111A and 111B can communicate directly with each system or via... Figure 1 The integrated control manager 130 shown communicates with the system.

[0052] The braking system 121 includes a braking device, an operating unit (e.g., a brake pedal) that accepts braking operations from the user, a brake control unit 121A (hereinafter referred to as "Brake1"), and a brake control unit 121B (hereinafter referred to as "Brake2"). The steering system 122 includes a steering device, an operating unit that accepts steering operations from the user, and steering control units 122A and 122B. The transmission system 123 includes a shifting device (not shown), an EPB device 123A, a P-Lock device 123B, and a propulsion system 123C. "EPB (Electric Parking Brake)" refers to the electric parking brake, and "P-Lock (Parking Lock)" refers to the parking lock.

[0053] The gear shifting device determines the shift position and switches the propulsion direction and transmission mode of the base vehicle 120 according to the determined shift position. The gear shifting device includes a transmission mechanism and an operating unit that receives shift operations from the user. The propulsion system 123C includes a vehicle drive unit, an operating unit that receives acceleration operations from the user (e.g., accelerator pedal), and a propulsion control unit that controls the vehicle drive unit. The vehicle drive unit applies a propulsive force to the wheels in the propulsion direction indicated by the shift position. The base vehicle 120 accelerates by this propulsive force. The vehicle drive unit includes a battery and a driving motor that receives power from the battery.

[0054] EPB device 123A may include, for example, a parking brake mechanism, an electric actuator, and an operating unit (e.g., an EPB switch) for accepting EPB requests from users. EPB device 123A may also be configured to apply braking force to the wheels via an electric actuator (e.g., a motor) to fix (secure) the wheels. P-Lock device 123B may include, for example, a parking lock mechanism, an actuator, and an operating unit (e.g., a manual brake lever) for accepting parking operations from users. P-Lock device 123B may also be configured to mechanically fix the rotational position of the transmission output shaft via a parking lock pawl that can be driven by an actuator.

[0055] Figure 3 This diagram illustrates the path (command path) from the autonomous driving suite to the vehicle system.

[0056] Reference Figure 3 ADC211A and ADC211B are connected together via communication line L1 in a manner enabling mutual communication. VCI control unit 111A and VCI control unit 111B are connected together via communication line L2 in a manner enabling mutual communication. ADC211A and VCI control unit 111A are connected together via communication line L11 in a manner enabling mutual communication. VCI control unit 111A and brake control unit 121A are connected together via communication line L12 in a manner enabling mutual communication. ADC211B and VCI control unit 111B are connected together via communication line L21 in a manner enabling mutual communication. VCI control unit 111B and brake control unit 121B are connected together via communication line L22 in a manner enabling mutual communication. VCI control unit 111A and brake control unit 121B are connected together via communication line L31 in a manner enabling mutual communication. The VCI control unit 111B and the braking control unit 121A are connected together via communication line L32 in a manner that enables them to communicate with each other.

[0057] The main power supply 180A supplies power to the VCI control unit 111A and the brake control unit 121A, respectively. The auxiliary power supply 180B supplies power to the VCI control unit 111B and the brake control unit 121B, respectively. The main power supply 180A and the auxiliary power supply 180B each output power with a voltage lower than that of the drive battery (not shown). In this embodiment, the VCI control unit 111A, VCI control unit 111B, brake control unit 121A, and brake control unit 121B correspond to an example of the "first control device," "second control device," "third control device," and "fourth control device" disclosed herein, respectively.

[0058] The braking system 121 is configured to receive commands from the ADK200 via multiple paths. In this embodiment, the braking system 121 is configured to receive commands from the ADK200 via a first path, a second path, and a third path, respectively.

[0059] The first path is the path via the VCI control unit 111A; more specifically, it is the path from the ADK200, via the VCI control unit 111A, to the brake control unit 121A. Figure 3 The first path includes ADC211A, communication line L11, VCI control unit 111A, communication line L12, and braking control unit 121A, and will malfunction if at least one of them malfunctions.

[0060] The second path is the path via the VCI control unit 111B; more specifically, it is the path from the ADK200, via the VCI control unit 111B, to the brake control unit 121B. Figure 3 The second path includes ADC211B, communication line L21, VCI control unit 111B, communication line L22, and braking control unit 121B, and will malfunction if at least one of them malfunctions.

[0061] The third path is the path from ADK200 to brake control unit 121A via VCI control unit 111B. The third path includes ADC211B, communication line L21, VCI control unit 111B, communication line L32, and brake control unit 121A, and will malfunction if at least one of them malfunctions.

[0062] In this embodiment, the first path corresponds to the main system, and the second and third paths correspond to the auxiliary systems. During periods when the main system (first path) is functioning normally, the braking system 121 uses the main system to execute automatic driving control based on instructions from ADK200. If the main system malfunctions, the braking system 121 uses the auxiliary system to execute automatic driving control based on instructions from ADK200. Specifically, if the main system malfunctions but the auxiliary system is functioning normally, the braking system 121 uses the third path to execute automatic driving control based on instructions from ADK200. Furthermore, if both the main system and the auxiliary system malfunction during automatic driving, the braking system 121 executes automatic deceleration control. Automatic deceleration control is vehicle control that controls the braking device to decelerate the vehicle. The braking system 121 executes automatic deceleration control regardless of the presence or absence of instructions from ADK200. Even if the instruction path from ADK200 to the braking system 121 remains after the failure of both the main system and the auxiliary system during automatic driving, automatic deceleration control will still be executed. For example, if both the first and second paths fail, automatic deceleration control will still be executed even if the third path does not fail. Automatic deceleration control will be executed regardless of whether both the first and second paths or both the first and third paths fail. If the sub-system fails due to a malfunction in one of the braking control units 121A and 121B, automatic deceleration control will be executed through the other braking control unit that has not failed. In the following text, the situation where both the main system and the sub-system fail will be referred to as "dual system failure."

[0063] In the braking system 121, the braking device is controlled by brake control units 121A and 121B respectively. The braking device is configured to decelerate the vehicle 1. The braking device may also be a hydraulic disc brake. The braking device functions as a service brake, used not only when parked but also while driving. The braking device may also have a brake holding function. In the manually driven vehicle 1, the brake control units 121A or 121B control the braking device according to the braking operation performed by the user (driver). The braking device applies braking force to the wheels of the vehicle 1. For example, the user decelerates the moving vehicle 1 by pressing the brake pedal, thereby bringing the vehicle 1 to a stop.

[0064] Figure 4 This diagram illustrates an example of the structure of each of the brake control units 121A and 121B. Figure 4In the example shown, brake control units 121A and 121B respectively include motion managers 141A and 141B and brake ECUs 142A and 142B. They function as control devices. VCI control unit 111A can be controlled by... Figure 3 The communication lines L2, L11, L12, and L31 shown are configured to communicate with the VCI control unit 111B, the ADC 211A, and the motion managers 141A and 141B, respectively. The VCI control unit 111B is configured to communicate via... Figure 3 The communication lines L2, L21, L22, and L32 shown are configured to communicate with VCI control unit 111A, ADC 211B, and motion managers 141A and 141B, respectively. Furthermore, the VCI control unit 111B is configured to communicate with... Figure 2 The P-Lock device 123B shown communicates directly with the steering control units 122A and 122B. The VCI control unit 111B can prevent the moving vehicle 1 from colliding through steering control, or suppress the movement of the vehicle 1 parked on a slope through stationary control.

[0065] VCI control unit 111A requests automatic driving control from motion manager 141A according to instructions from ADC 211A. Motion manager 141A requests the necessary controls (e.g., acceleration control, deceleration control, steering control, gear shifting control, or parking control) from the system corresponding to the requested automatic driving control. Brake ECU 142A controls the braking device according to the request from motion manager 141A. Furthermore, VCI control unit 111A can also request deceleration control from motion manager 141B.

[0066] The VCI control unit 111B requests automatic driving control from the motion manager 141A according to instructions from the ADC 211B. Furthermore, the VCI control unit 111B requests deceleration control from the motion manager 141B as needed. For example, in the event of a malfunction in the brake control unit 121A, the VCI control unit 111B may also request deceleration control from the motion manager 141B. The brake ECU 142B controls the braking device based on the requests from the motion manager 141B.

[0067] In this embodiment, communication between ADK200 and VCIB110 uses signals defined by the API (Application Program Interface) (API signals). ADK200 is configured to process various signals defined by the API. ADK200 outputs various commands to VCIB110 according to the API. Hereinafter, these various commands output from ADK200 to VCIB110 will be referred to as "API commands". Furthermore, ADK200 receives various signals from VCIB110 indicating the state of the base vehicle 120 according to the API. Hereinafter, these various signals received by ADK200 from VCIB110 will be referred to as "API states". Both API commands and API states are equivalent to API signals.

[0068] In this implementation, ADK200 uses the API commands described below.

[0069] The Vehicle Mode command is an API command that requests a switch from Automatic or Assist mode to Manual mode. Automatic, Assist, and Manual modes will be described later. The Propulsion Direction command is an API command that requests a change in the shift position (R / D). The Acceleration command is an API command that indicates the vehicle's acceleration. The Acceleration command requests acceleration (+) and deceleration (-) relative to the direction indicated by the Propulsion Direction state described later. The Front Wheel Steering Angle command is an API command that requests the steering of the vehicle's front wheels. The Fix command is an API command that requests the application or deactivation of fixation.

[0070] The above describes some of the API commands used in vehicle 1. VCIB110 receives various API commands from ADK200. When VCIB110 receives an API command from ADK200, it converts the API command into a signal form that can be executed by the control device of the base vehicle 120. Hereinafter, the API command converted into a signal form that can be executed by the control device of the base vehicle 120 will be referred to as an "internal instruction". When VCIB110 receives an API command from ADK200, it outputs the internal instruction corresponding to that API command to the base vehicle 120.

[0071] Next, the API status will be explained. The ADK200 uses, for example, the API status described below to understand the status of the base vehicle 120.

[0072] The vehicle mode state (hereinafter referred to as "VEMDST") is the API state representing the vehicle mode state. Vehicle modes include manual mode, automatic mode, and assisted mode. Manual mode is a vehicle mode in which the vehicle is under the control of the user (human) and no intervention (driving assistance) by the autonomous driving suite is allowed. Assisted mode is a vehicle mode in which the vehicle is under the control of the user (human) and intervention (driving assistance) by the autonomous driving suite is allowed. Automatic mode is a vehicle mode in which the vehicle platform (including the base vehicle) is under the control of the autonomous driving suite. In the initial state (when the vehicle system starts), the vehicle mode is manual mode. VEMDST represents the corresponding value "0", "1", and "2" when the current vehicle mode is manual mode, automatic mode, or assisted mode, respectively. In the following text, driving in manual mode is referred to as "manual driving", driving in assisted mode is referred to as "assisted autonomous driving", and driving in automatic mode is referred to as "fully autonomous driving". In addition, assisted autonomous driving and fully autonomous driving are sometimes included together and referred to as "autonomous driving".

[0073] The forward direction state is the API state indicating the current shift position. The travel direction state is the API state indicating the vehicle's travel direction. The travel direction state outputs a value of "0" when the vehicle is moving forward, a value of "1" when the vehicle is moving backward, and a value of "2" (Standstill: stationary state) when all four wheels are at a speed of "0" for a certain period of time. The vehicle speed state is the API state indicating the vehicle's longitudinal speed. The vehicle speed state outputs the absolute value of the vehicle speed. The stationary state is the API state indicating the stationary state (e.g., the respective states of EPB device 123A and P-Lock device 123B).

[0074] The main system failure status (hereinafter referred to as "main system ST") indicates whether the main system is functionally failed. When the main system is not functionally failed, the main system ST displays "1"; when the main system is functionally failed, the main system ST displays "0". The secondary system failure status (hereinafter referred to as "secondary system ST") indicates whether the secondary system is functionally failed. When the secondary system is not functionally failed, the secondary system ST displays "1"; when the secondary system is functionally failed, the secondary system ST displays "0". In this embodiment, if at least one of the second path and the third path is functionally failed, the secondary system ST displays "0". The initial values ​​of both the main system ST and the secondary system ST are "1". In the following text, the main system ST and the secondary system ST are sometimes included together and collectively referred to as "system ST".

[0075] The automatic deceleration failure protection status (hereinafter referred to as "Automatic Deceleration ST") indicates whether automatic deceleration control is present or absent when the dual-system function fails. When automatic deceleration control is enabled (effective) during dual-system function failure, i.e., automatic deceleration control is executed when the dual-system function fails, Automatic Deceleration ST displays "1". When automatic deceleration control is disabled (ineffective), i.e., automatic deceleration control is not executed when the dual-system function fails, Automatic Deceleration ST displays "0". The initial value of Automatic Deceleration ST is "0".

[0076] The above describes some of the API states used in vehicle 1. VCIB 110 receives various sensor detection values ​​and state identification results from the base vehicle 120, and outputs various API states representing the state of the base vehicle 120 to ADK 200. VCIB 110 acquires API states with values ​​set to represent the state of the base vehicle 120, and outputs the acquired API states to ADK 200. Various API states are stored, for example, in the respective storage devices of VCI control units 111A and 111B, and are updated sequentially.

[0077] In this implementation, the user can request a change of vehicle mode to VCIB110 via HMI150. Hereinafter, a request to change from manual mode to assisted mode, or from manual mode to automatic mode, is referred to as an "automatic driving start request." A request to change from assisted mode or automatic mode to manual mode is referred to as an "automatic driving end request." A request to change from assisted mode to automatic mode is referred to as a "driving level upgrade request." A request to change from automatic mode to assisted mode is referred to as a "driving level down request." Furthermore, driving level upgrade requests and driving level down requests are sometimes collectively referred to as "driving level change requests."

[0078] The following text primarily illustrates examples of vehicle 1 being driven in various modes when there are people inside the vehicle. However, vehicle 1 can also operate in a fully autonomous driving mode when no one is inside.

[0079] When the VCIB110 receives a request to initiate autonomous driving or a request to change the driving level, it executes... Figure 5 The processing flow shown is F1. Figure 5 This is a flowchart illustrating the processes performed in vehicle 1 at the start of autonomous driving. "S" in the flowchart represents a step.

[0080] In process flow F1, VCIB110 uses the main system in S11 to request ADK200 to begin automatic driving (assisted automatic driving or fully automatic driving) initiated by the user. Furthermore, VCIB110 performs a function failure check related to the main system. In the following S12, VCIB110 determines whether the main system is functioning normally (not in a state of functional failure). Specifically, VCI control unit 111A... Figure 3 The communication line L11 shown sends a first request signal to ADC211A requesting the start of the aforementioned autonomous driving. VCI control unit 111A can also determine that the master system is not malfunctioning if it receives a response from ADC211A to the first request signal (refer to S42 or S43 described later). VCI control unit 111A can also determine that the master system is malfunctioning if it does not receive a response from ADC211A even after a predetermined time has elapsed since the transmission of the first request signal. However, if the current value of the master system ST in S11 is "0", VCIB110 determines that the master system is malfunctioning in S12 without sending the first request signal. The master system ST can be updated during manual driving (refer to...). Figure 9 The processing flow shown is F6.

[0081] If the main system is determined to be functioning normally ("Yes" in S12), VCIB110 sets the main system ST to "1" in S13, and then the process proceeds to S20. The subsequent processing after S20 will be described later. On the other hand, if the main system is determined to be malfunctioning ("No" in S12), VCIB110 sets the main system ST to "0" in S14, and then the process proceeds to S15.

[0082] In S15, VCIB110 uses the sub-system to request ADK200 to begin automatic driving initiated by the user. Furthermore, VCIB110 performs a function failure check related to the sub-system. In the following S16, VCIB110 determines whether the sub-system is functioning correctly (not in a state of functional failure). Specifically, the VCI control unit 111B... Figure 3The communication line L21 shown sends a second request signal to ADC211B requesting the start of the aforementioned automatic driving. VCI control unit 111B can also determine that the sub-system is not malfunctioning if it receives a response from ADC211B to the second request signal (refer to S42 or S43 described later). VCI control unit 111B can also determine that the sub-system is malfunctioning if a predetermined time has elapsed since the transmission of the second request signal and no response has been received from ADC211B. However, if the current value of the sub-system ST is "0" in S15, VCIB110 determines that the sub-system is malfunctioning in S16 without sending the second request signal. The sub-system ST can be updated during manual driving (refer to...). Figure 9 The processing flow shown is F6.

[0083] If the subsystem is determined to be normal ("Yes" in S16), after VCIB110 sets the subsystem ST to "1" in S17, the process proceeds to S18. In S18, it is determined whether the user has requested an upgrade to the autopilot level. If VCIB110 receives a request from the user to start autopilot or upgrade the driving level, it is determined to be "Yes" in S18, and the process proceeds to S32. In S32, VCIB110 informs the user of the meaning of being unable to respond to the request. For example, VCIB110 may also display a message on HMI150 indicating that the autopilot level cannot be upgraded due to a system malfunction. In this case, the autopilot requested by the user will not start, and the process flow F1 ends. That is, the request from the user is rejected. On the other hand, if VCIB110 receives a request from the user to downgrade the driving level, it is determined to be "No" in S18, and the process proceeds to S20. The processing after S20 will be described later.

[0084] If it is determined that both the primary system and the secondary system are malfunctioning (in S16, this is "No"), after VCIB110 sets the secondary system ST to "0" in S19, the process proceeds to S33. In S33, VCIB110 notifies the base vehicle 120 of the dual-system malfunction. For example, VCI control unit 111A can also notify brake control unit 121A or 121B via communication lines L12 or L31. Furthermore, VCI control unit 111B can also notify brake control unit 121B or 121A via communication lines L22 or L32. When the notification in S33 is executed, process flow F1 ends.

[0085] ADK200 initiates assisted or fully autonomous driving based on a request from VCIB110. Specifically, ADK200 executes processing flow F2 upon receiving a first request signal (S11) or a second request signal (S15) from VCIB110.

[0086] In processing flow F2, ADK200 determines in S41 whether the autonomous driving request initiated from VCIB110 is an autonomous driving system under human control. Specifically, assisted autonomous driving is equivalent to autonomous driving under human control. Assisted autonomous driving is, for example, equivalent to Level 1 or 2 autonomous driving as defined by the standard "SAE J3016". Fully automated driving is equivalent to autonomous driving under the control of the autonomous driving suite. Fully automated driving is, for example, equivalent to Level 4 or 5 autonomous driving as defined by the standard "SAE J3016". If ADK200 receives a first request signal or a second request signal requesting assisted autonomous driving, it is determined to be "yes" in S41, and the process proceeds to S42. On the other hand, if ADK200 receives a first request signal or a second request signal requesting fully automated driving, it is determined to be "no" in S41, and the process proceeds to S43.

[0087] Additionally, ADK200 can also be configured to perform Level 3 autonomous driving as defined by standard "SAE J3016" upon request from VCIB110. Regarding Level 3 autonomous driving, ADK200 can also determine in S41, based on the details of the autonomous driving control, whether control sovereignty belongs to the user (driver) or the autonomous driving suite.

[0088] In S42, ADK200 requests VCIB110 to disable automatic deceleration (i.e., disable automatic deceleration control when the dual-system function is disabled). For example, if ADC211A receives the first request signal, ADC211A uses the master system to send a third request signal to VCI control unit 111A requesting automatic deceleration to be disabled. This is thus determined as "yes" in S12. Furthermore, if ADC211B receives the second request signal, ADC211B uses the slave system to send a third request signal to VCI control unit 111B requesting automatic deceleration to be disabled. This is thus determined as "yes" in S16.

[0089] In S43, ADK200 requests VCIB110 to enable automatic deceleration (i.e., to enable automatic deceleration control when the dual-system function is disabled). For example, if ADC211A receives the first request signal, ADC211A uses the master system to send a fourth request signal to VCI control unit 111A requesting automatic deceleration to be enabled. This is then determined to be "yes" in S12. Furthermore, if ADC211B receives the second request signal, ADC211B uses the slave system to send a fourth request signal to VCI control unit 111B requesting automatic deceleration to be enabled. This is then determined to be "yes" in S16.

[0090] VCIB110 performs the processing described in S20 above based on the third or fourth request signal received from ADK200. Specifically, VCIB110 performs the following... Figure 6 The processing flow is shown below. Figure 6 A flowchart illustrating the details of S20.

[0091] Reference Figure 6 In S21, VCIB110 determines whether vehicle 1 is in manual driving mode. If VCIB110 receives a request to start automatic driving, vehicle 1 is in manual driving mode since automatic driving has not yet started. In this case, it is determined to be "yes" in S21, and the process proceeds to S22. In S22, VCIB110 updates the automatic deceleration ST according to the request from ADK200. Specifically, when VCIB110 receives a third request signal from ADK200, VCIB110 sets the automatic deceleration ST to "0". When VCIB110 receives a fourth request signal from ADK200, VCIB110 sets the automatic deceleration ST to "1". Thus, VCIB110 is configured to switch between active and inactive automatic deceleration control based on the request from ADK200. When the automatic deceleration ST is updated in S22, the process proceeds to S23.

[0092] Furthermore, when VCIB110 receives a driving level change request, vehicle 1 is in autonomous driving mode. In this case, it is determined as "no" in S21, and without executing the processing in S22, the process proceeds to S23. Thus, VCIB110 is configured to prohibit the switching between active and inactive automatic deceleration control during autonomous driving.

[0093] In S23, VCIB110 uses Figure 3The communication lines L11, L12, L21, L22, L31, and L32 shown are not in a state of functional failure and respectively send the automatic deceleration ST to ADK200 and braking system 121.

[0094] In the following S24, VCIB110 uses communication lines L11, L12, L21, L22, L31, L32 ( Figure 3 The communication lines that are not in a state of functional failure transmit system ST (main system ST and sub-system ST) to ADK200 and braking system 121 respectively.

[0095] when Figure 6 When the process shown in S24 is executed, the processing flow F1 ( Figure 5 The process ends at S20 and proceeds to S31. See again... Figure 5 In S31, VCIB110 configures VEMDST according to the user's requested autopilot, requests ADK200 to initiate the user-requested autopilot, and begins the process described below. Figure 7 The diagram illustrates the automated driving control. Specifically, when a user requests assisted automated driving, VCIB110 changes the value of VEMDST from "0" or "1" to "2" and sends the changed VEMDST to ADK200 and the base vehicle 120, respectively. When a user requests fully automated driving, VCIB110 changes the value of VEMDST from "0" or "2" to "1" and sends the changed VEMDST to both ADK200 and the base vehicle 120, respectively. By sending the changed VEMDST to ADK200, VCIB110 requests ADK200 to initiate the automated driving (assisted or fully automated driving) requested by the user.

[0096] After sending the third or fourth request signal in S42 or S43 as described above, ADK200 determines in S44 whether a request to start autonomous driving has been received from VCIB110 (S31). If ADK200 receives a request to start autonomous driving from VCIB110, it is determined to be "yes" in S44, and the process proceeds to S45. If VCIB110 has executed the processing of S31 in processing flow F1, it is determined to be "yes" in S44. In S45, ADK200 begins control related to the autonomous driving (user-requested autonomous driving) requested from VCIB110. Specifically, ADK200 begins the process described below. Figure 8The automatic driving control is shown. On the other hand, if ADK200 does not receive a request to start automatic driving from VCIB110 even after a predetermined time has elapsed since the transmission of the third or fourth request signal, it is determined as "No" in S44. For example, if process flow F1 ends without VCIB110 performing the processing in S31, it is determined as "No" in S44. In this case, process flow F2 ends without performing the processing in S45.

[0097] Figure 7 This is a flowchart illustrating the processes related to the automatic driving control performed via VCIB110. VCIB110... Figure 5 The process of S31 begins. Figure 7 The processing flow shown is F3. Additionally, in the process of... Figure 5 In the event of a change in the level of autonomous driving as per S31, VCIB110 terminates the currently executing autonomous driving control (processing flow F3) and restarts the control related to the requested autonomous driving (processing flow F3).

[0098] Reference Figure 7 In process flow F3, VCIB110 requests driving commands related to autonomous driving from ADK200 using the main system in S51. Furthermore, VCIB110 performs a function failure check related to the main system. In the following S52, VCIB110 determines whether the main system is functioning normally (not in a state of functional failure). Specifically, VCI control unit 111A... Figure 3 The communication line L11 shown transmits a fifth request signal, requesting driving commands related to autonomous driving, along with various API states indicating the state of vehicle 1 to ADC 211A. Among the transmitted API states is VEMDST. VCI control unit 111A can also receive a response from ADC 211A to the fifth request signal (see description below). Figure 8 In the case of S74), it is determined that the main system is not in a functional failure state. The VCI control unit 111A can also determine that the main system is in a functional failure state if a predetermined time has elapsed since the transmission of the fifth request signal and no response has been received from the ADC211A. However, if the current value of the main system ST is "0" in S51, the VCIB110 determines that the main system is in a functional failure state in S52 without transmitting the fifth request signal.

[0099] When VCIB110 receives a driving command from ADK200 through the main system, it is determined that the main system is normal ("Yes" in S52), and processing proceeds to S57. In S57, VCIB110 sends internal instructions corresponding to the received driving command (API commands related to autonomous driving) to the base vehicle 120. As a result, the base vehicle 120 executes autonomous driving control based on the instructions from ADK200 (see...). Figure 10 In this embodiment, when the main system (first path) is not malfunctioning, the VCI control unit 111A uses the main system to receive a driving command from the ADC 211A, for example, a command related to deceleration control, and sends the driving command to the brake control unit 121A. Thus, the brake control unit 121A controls the braking device based on the driving command received from the ADC 211A via the main system. When the processing in S57 is executed, the process proceeds to S58.

[0100] On the other hand, if the main system is determined to be malfunctioning ("No" in S52), after VCIB110 sets the main system ST to "0" in S54, the process proceeds to S55. In S55, VCIB110 uses the secondary system to request driving commands related to automatic driving from ADK200. Furthermore, VCIB110 performs a malfunction determination related to the secondary system. In the following S56, VCIB110 determines whether the secondary system is functioning normally (in a non-malfunctioning state). Specifically, the VCI control unit 111B... Figure 3 The communication line L21 shown transmits a sixth request signal, requesting driving commands related to autonomous driving, along with various API states indicating the state of vehicle 1, to ADC 211B. Among the transmitted API states is VEMDST. VCI control unit 111B can also receive a response from ADC 211B to the sixth request signal (see description below). Figure 8 In the case of S74), it is determined that the subsystem is not in a functional failure state. The VCI control unit 111B can also determine that the subsystem is in a functional failure state if a predetermined time has elapsed since the transmission of the sixth request signal and no response has been received from the ADC211B. However, in S55, if the current value of the subsystem ST is "0", the VCIB110 determines that the subsystem is in a functional failure state in S56 without transmitting the sixth request signal.

[0101] When VCIB110 receives a driving command from ADK200 via the sub-system, it is determined that the sub-system is functioning normally (S56: Yes), and processing proceeds to S57. In S57, VCIB110 sends internal instructions corresponding to the received driving command (API command related to autonomous driving) to the base vehicle 120. Consequently, the base vehicle 120 executes autonomous driving control based on the instructions from ADK200 (see...). Figure 10 In this embodiment, when the main system (first path) is malfunctioning but the sub-systems (second and third paths) are not malfunctioning, the VCI control unit 111B uses the third path to receive a driving command from the ADC 211B containing, for example, instructions related to deceleration control, and sends the driving command to the brake control unit 121A. Thus, the brake control unit 121A controls the braking device based on the driving command received from the ADC 211B via the third path. Therefore, even if the main system malfunctions, the brake control unit 121A can continue to perform automatic driving control (control of the braking device) based on the driving command from the ADK 200. When the processing in S57 is executed, the process proceeds to S58.

[0102] In S58, VCIB110 determines whether to terminate autonomous driving. For example, if VCIB110 receives a request to terminate autonomous driving, it is determined to be "yes" in S58, and the process proceeds to S61. In S61, VCIB110 changes the value of VEMDST from "1" or "2" to "0", and sends the changed VEMDST to ADK200 and the base vehicle 120 respectively. By sending the changed VEMDST to ADK200, VCIB110 requests ADK200 to terminate the autonomous driving initiated by the user. Then, in S62, VCIB110 sets the automatic deceleration ST to "0" and sends the automatic deceleration ST to the base vehicle 120. When the process in S62 is executed, the process flow F3 ends. On the other hand, if VCIB110 does not receive a request to terminate autonomous driving, it is determined to be "no" in S58, and the process returns to the first step (S51). Thus, autonomous driving control continues.

[0103] When it is determined that not only the main system is malfunctioning but also the secondary system is malfunctioning (in S56, this is "No"), VCIB110 executes processes S63 and S64. The processes in S63 and S64 are respectively related to... Figure 5 The processes S19 and S33 shown are the same. When the process of S64 is executed, the process flow F3 ends.

[0104] Figure 8 This is a flowchart illustrating the processes related to the automatic driving control performed via ADK200. ADK200... Figure 5 The processing of S45 began. Figure 8 The processing flow shown is F4. Additionally, in the process of... Figure 5 In the event that the S45 process changes the level of autonomous driving, the ADK200 terminates the currently executing autonomous driving control (processing flow F4) and restarts the control related to the requested autonomous driving (processing flow F4).

[0105] Reference Figure 8 In processing flow F4, ADK200 determines in S71 whether a driving command has been requested from VCIB110. If ADK200 receives either the fifth or sixth request signal described above, it is determined to be "yes" in S71, and the process proceeds to S72. On the other hand, if ADK200 does not receive either the fifth or sixth request signal described above, it is determined to be "no" in S71, and the process proceeds to S75.

[0106] In S72, ADK200 identifies the vehicle mode of vehicle 1 based on VEMDST and creates a driving plan corresponding to the vehicle mode (assisted mode or automatic mode). Specifically, ADK200 creates a driving plan for autonomous driving based on the detection results of various sensors (e.g., environmental information and attitude information) and the API state obtained from VCIB110. The driving plan is data representing the behavior of vehicle 1 as the target within a predetermined period. ADK200 can also calculate the behavior (attitude, etc.) of vehicle 1 and create a driving plan suitable for the state of vehicle 1 and the external environment. In the following S73, ADK200 determines the API commands (driving commands such as propulsion direction command, acceleration command, front wheel steering angle command, stationary command, etc.) for executing the control requested according to the created driving plan (e.g., acceleration control, deceleration control, steering control, parking control, and parking control). The driving command is equivalent to a driving instruction from ADK200 to the vehicle system (the system of the base vehicle 120). ADK200 can also calculate the physical quantities (acceleration, tire steering angle, etc.) requested for control according to the driving plan, and determine the driving commands based on the calculation results. In the following S74, ADK200 sends the determined driving commands to VCIB110.

[0107] Upon receiving the fifth request signal from the VCI control unit 111A, the ADC211A executes the processes described in S72 to S74. The ADC211A then sends the driving command determined in the aforementioned manner to the VCI control unit 111A via the main system. Thus, in Figure 7 In step S52, it is determined to be "yes". Furthermore, when the ADC211B receives the sixth request signal from the VCI control unit 111B, the ADC211B executes the processes described in S72 to S74. The ADC211B sends the driving command determined in the above manner to the VCI control unit 111B via the subsystem. Thus, in Figure 7 In S56, it is judged as "yes". When the process in S74 is executed, the process proceeds to S75.

[0108] In S75, ADK200 determines whether to terminate autonomous driving. For example, if ADK200 receives a request to terminate autonomous driving from VCIB110 (S61), it is determined to be "yes" in S75, and process flow F4 ends. On the other hand, if ADK200 does not receive a request to terminate autonomous driving from VCIB110 (S61), it is determined to be "no" in S75, and the process returns to the first step (S71). Thus, autonomous driving control continues.

[0109] Figure 9 This diagram illustrates the process performed by the base vehicle 120. The base vehicle 120 repeatedly executes process flow F5 during periods when automatic deceleration control (S90) is not performed. Process flow F5 is controlled by multiple control devices (e.g., provided by the base vehicle 120) Figures 1 to 4 The integrated control manager 130 shown and the control devices of each system are executed.

[0110] Reference Figure 9 In process F5, the base vehicle 120 checks in S81 whether it has received a notification of dual-system function failure from VCIB110. Figure 5 S33 or Figure 7 The system performs a judgment in S64. If the base vehicle 120 receives a notification of dual system function failure ("Yes" in S81), the process proceeds to S88. On the other hand, if the base vehicle 120 does not receive a notification of dual system function failure ("No" in S81), the process proceeds to S82.

[0111] In S82, the base vehicle 120 requests system STs (main system ST and sub-system ST) from VCIB110. Furthermore, the base vehicle 120 performs function failure checks related to the main system and sub-system.

[0112] In detail, the braking control unit 121A via Figure 3 The communication lines L12 and L32 respectively request system ST from VCI control units 111A and 111B. If the braking control unit 121A receives system ST from VCI control units 111A and 111B respectively, it determines that communication lines L12 and L32 are not functionally disabled. If the braking control unit 121A fails to receive system ST from at least one of VCI control units 111A and 111B, it determines that the corresponding path (at least one of communication lines L12 and L32) is functionally disabled.

[0113] Furthermore, the braking control unit 121B via Figure 3 The communication lines L31 and L22 requested system ST from VCI control units 111A and 111B, respectively. If the braking control unit 121B receives system ST from VCI control units 111A and 111B, it determines that communication lines L31 and L22 are not functionally disabled. Conversely, if the braking control unit 121B fails to receive system ST from at least one of VCI control units 111A and 111B, it determines that the corresponding path (at least one of communication lines L31 and L22) is functionally disabled.

[0114] When the braking control unit 121A or 121B receives a system ST from VCIB110, the braking control unit 121A or 121B performs a function failure determination related to the main system and the sub-system based on the received system ST. For example, in the case of a failure in the communication line L11, the main system ST displays "0" ( Figure 5 S14 or Figure 7 (S54). Furthermore, in the event of a failure in the L21 communication line function, the subsystem ST displays "0" ( Figure 5 S19 or Figure 7 (S63).

[0115] In this embodiment, the VCI control unit 111A determines whether the communication between the ADC211A and the VCI control unit 111A is in a state of functional failure. Figure 5 (S12), and outputs the result of the determination (main system ST) to the base vehicle 120 according to the request from the base vehicle 120 (S82). In addition, the VCI control unit 111B determines whether the communication between the ADC211B and the VCI control unit 111B is in a functional failure state (S12). Figure 5In step S16), the system determines the result of the determination (subsystem ST) and outputs it to the base vehicle 120 upon request from the base vehicle 120 (S82). With this structure, the base vehicle 120 can easily detect functional failures associated with each of the first and second paths. Furthermore, not limited to the above method, each of the VCI control units 111A and 111B can also spontaneously send system ST to the base vehicle 120.

[0116] In the following S83, the base vehicle 120 identifies the vehicle mode of vehicle 1 based on VEMDST and determines whether vehicle 1 is in autonomous driving mode. If VEMDST shows "0", it is determined as "no" in S83, and the process proceeds to S831. If VEMDST shows "1" or "2", it is determined as "yes" in S83, and the process proceeds to S841.

[0117] In S831, the base vehicle 120 determines whether the communication between VCIB110 and the base vehicle 120 is deemed to be malfunctioning in S82. For example, if at least one of the communication lines L12, L22, L31, and L32 is deemed to be malfunctioning, the determination is "yes" in S831, and the process proceeds to S832. On the other hand, if none of the communication lines L12, L22, L31, and L32 is deemed to be malfunctioning, the determination is "no" in S831, and the process returns to the initial step (S81).

[0118] In S832, the base vehicle 120 notifies the VCIB 110 of the result of the function failure determination in S82. Specifically, the base vehicle 120 uses a communication line that is not functionally failed to send function failure information to the VCIB 110, indicating which of the communication lines L12, L22, L31, and L32 is functionally failed. In the following S833, the base vehicle 120 informs the user that autonomous driving is prohibited. For example, the base vehicle 120 may also display a message on the HMI 150 indicating that autonomous driving cannot be performed due to a system malfunction. When the processing in S833 is executed, the processing returns to S81.

[0119] VCIB110 is executed repeatedly while vehicle 1 is in manual driving mode. Figure 9 The processes shown are S101 to S103. Specifically, when vehicle 1 begins manual driving, VCIB110 begins... Figure 9The processing flow F6 is shown. In processing flow F6, VCIB110 determines whether it received functional failure information from base vehicle 120 in S101 (S832). If VCIB110 receives functional failure information (yes in S101), VCIB110 updates system ST in S102 based on the received functional failure information. For example, if communication line L12 fails, the main system ST is set to "0". Furthermore, if at least one of communication lines L22 and L32 fails, the secondary system ST is set to "0".

[0120] In the next step, S103, VCIB110 determines whether autonomous driving has commenced. If manual driving continues (in S103, this is "No"), processing returns to S101. On the other hand, for example, when passing through... Figure 5 If the processing in S31 has already started autonomous driving (in S103 it is "Yes"), the processing flow F6 ends.

[0121] In S841, the base vehicle 120 determines whether the main system is deemed to be malfunctioning in S82. For example, a malfunction in at least one of communication lines L11 and L12 indicates a malfunction in the main system. If the main system is deemed not to be malfunctioning ("No" in S841), the base vehicle 120 receives driving commands from ADK200 via the main system in S851 (see reference). Figure 7 S57 and Figure 8 (S74) and saves the driving command along with the receiving time in the storage device. Then, the processing returns to S81.

[0122] On the other hand, if the main system is determined to be malfunctioning (yes in S841), the base vehicle 120 determines in S842 whether the secondary system is also determined to be malfunctioning. For example, at least one of communication lines L21, L22, and L32 being malfunctioning refers to the secondary system being malfunctioning. If the secondary system is determined not to be malfunctioning (no in S842), the base vehicle 120 receives driving commands from ADK200 via the secondary system in S852 (see reference). Figure 7 S57 and Figure 8 (S74) and saves the driving command along with the receiving time in the storage device. Then, the processing returns to S81.

[0123] In this embodiment, the base vehicle 120 is described below. Figure 10The processing flow F7 shown executes automatic driving control based on instructions obtained in S851 or S852. Figure 10 A flowchart illustrating the processes related to driving control performed via the base vehicle 120. The base vehicle 120 and... Figure 9 The processing flow shown is repeated in parallel by F5. Figure 10 The processing flow shown is F7.

[0124] Reference Figure 10 In processing flow F7, the base vehicle 120 determines in S201 whether VEMDST displays "1". If VEMDST displays "1" (which is "yes" in S201), the base vehicle 120 executes in S202 based on... Figure 9 The automatic driving control is performed based on the driving commands obtained from S851 or S852. Thus, fully automatic driving of vehicle 1 is executed. For example, if the aforementioned driving commands include commands related to deceleration control, the braking system 121 adjusts the braking device (based on commands from ADK200) Figure 3 The ADK200 takes over control. Control in this automated driving system is held by the ADK200. When the process in S202 is executed, the process returns to the initial step (S201).

[0125] If VEMDST does not show "1" (in S201, it is "No"), the base vehicle 120 obtains user operations related to driving the vehicle 1 in S203. Specifically, the base vehicle 120 obtains operation quantities for various operating parts (accelerator operation quantity, brake operation quantity, steering operation quantity, etc.) and change operations (gear shifting, etc.) related to manual driving of the vehicle 1. Then, in the next step S204, the base vehicle 120 determines whether VEMDST shows "2". If VEMDST shows "0" (in S204, it is "No"), the base vehicle 120 executes manual driving control based on the user operations obtained in S203 in S205. For example, the vehicle drive unit, braking unit, steering unit, gear shifting unit, etc. are controlled according to the user operations. Thus, manual driving of the vehicle 1 is executed. When the processing in S205 is executed, the processing returns to S201.

[0126] If VEMDST indicates "2" (or "Yes" in S204), the base vehicle 120 in S206, based on the user operation obtained in S203 and... Figure 9The driving instructions obtained from S851 or S852 are used to execute automatic driving control. Thus, assisted automatic driving of vehicle 1 is executed. Control in this automatic driving is held by the user (human). Instructions from ADK200 are processed as instructions to assist user operation. When the processing in S206 is executed, processing returns to S201.

[0127] Refer again Figure 9 If it is determined that not only the main system but also the secondary system is malfunctioning (yes in S842), the process proceeds to S88. Thus, S88 is executed when both systems are malfunctioning. In S88, the base vehicle 120 determines whether the automatic deceleration ST displays "1". If the automatic deceleration ST displays "0" (no in S88), the process proceeds to S86. In S86, the base vehicle 120 informs the user that an abnormality has occurred in the automatic driving system. For example, the base vehicle 120 may also display a message informing the user of the automatic driving system abnormality on the HMI 150.

[0128] If the automatic deceleration ST indicates "1" ("Yes" in S88), the process proceeds to S89. An automatic deceleration ST indicating "1" means that automatic deceleration control is active. The base vehicle 120 only performs automatic deceleration control when automatic deceleration control is active (S90). In this embodiment, when automatic driving ends, the automatic deceleration ST becomes "0" (…). Figure 7 (S62). Furthermore, the automatic deceleration ST is only changed upon request from ADK200 when vehicle 1 is in manual driving mode. Figure 6 (S22). Furthermore, the ADK200 only requests automatic deceleration to be activated when fully autonomous driving begins. Figure 5 (S43). Therefore, the automatic deceleration ST indicates that "1" refers to the situation where vehicle 1 is in fully automated driving mode. In the event of a dual-system failure when the user (driver) has control, the user can continue driving vehicle 1. Thus, movement of vehicle 1 beyond the user's intention can be suppressed.

[0129] After the base vehicle 120 notifies the VCIB 110 of the start of automatic deceleration control in S89, automatic deceleration control begins in S90. Figure 11 A flowchart illustrating the details of S90.

[0130] refer to Figure 11In S91, the base vehicle 120 acquires the acceleration or deceleration (hereinafter referred to as "Vx") requested from ADK200 in the event of a dual-system function failure. Vx is displayed according to the internal command corresponding to the latest acceleration command received by the base vehicle 120 from VCIB110. Vx is displayed as a positive value (+) when acceleration is requested, and as a negative value (-) when deceleration is requested.

[0131] In the following S92, the base vehicle 120 determines whether Vx is greater than 0. Vx greater than 0 indicates that both the main system and the auxiliary system are malfunctioning when ADK200 is sending an acceleration command requesting vehicle 1 to accelerate. If Vx is greater than 0 ("yes" in S92), the base vehicle 120, in S93, adjusts the vehicle drive mechanism to make the acceleration of vehicle 1 zero. Figure 2 The braking system 121 is controlled. Therefore, propulsion is not applied to the wheels of vehicle 1. In the next S94, the braking system 121 ( Figure 2 The braking device is controlled in a manner that brings the deceleration of vehicle 1 close to a predetermined deceleration (hereinafter referred to as "target deceleration"). In S94, the control of the braking device is performed by the braking control unit 121A. However, in the event of a malfunction in the braking control unit 121A, the braking control unit 121B controls the braking device instead. The target deceleration is, for example, set to a value that complies with traffic regulations. The base vehicle 120 can also bring the deceleration of vehicle 1 close to the target deceleration at a rate of change less than a predetermined rate of change, so that the rate of change of vehicle 1's deceleration does not become excessive. In this way, the collapse of cargo caused by sudden deceleration can be suppressed. When the deceleration of vehicle 1 reaches the target deceleration, the base vehicle 120 maintains the deceleration of vehicle 1 at the target deceleration.

[0132] When Vx is below 0 ("No" in S92), the base vehicle 120 determines in S95 whether Vx is greater than the target deceleration (negative value). Then, if Vx is greater than the target deceleration but below 0 ("Yes" in S95), the process proceeds to S94 without executing the process in S93. The base vehicle 120 uses the process in S94 to bring the deceleration of vehicle 1 closer to the target deceleration. On the other hand, if Vx is below the target deceleration ("No" in S95), the braking system 121 controls the braking device in S96 to bring the deceleration of vehicle 1 closer to Vx. The control of the braking device in S96 is executed by the braking control unit 121A. However, if the braking control unit 121A malfunctions, the braking control unit 121B controls the braking device instead. When the deceleration of vehicle 1 reaches Vx, the base vehicle 120 maintains the deceleration of vehicle 1 at Vx. Thus, if ADK200 is sending a deceleration command requesting vehicle 1 to slow down, and it is determined that both the primary and secondary systems are malfunctioning, the braking system 121 controls the braking device to make the deceleration of vehicle 1 approach the greater of the deceleration requested by the deceleration command (Vx) and the pre-defined deceleration (target deceleration). Furthermore, regarding deceleration, the smaller the value of Vx (increasing towards the negative side), the greater the deceleration represented by Vx.

[0133] When process S94 is executed, processing proceeds to S97. When process S96 is executed, processing proceeds to S98. In each of S97 and S98, the base vehicle 120 determines whether vehicle 1 has reached a stopped state. If the determination is "no" in S97, processing returns to S94. Then, processes S94 and S97 are executed repeatedly until vehicle 1 reaches a stopped state. If the determination is "no" in S98, processing returns to S96. Then, processes S96 and S98 are executed repeatedly until vehicle 1 reaches a stopped state. Thus, the base vehicle 120 begins automatic deceleration control through any one of processes S93, S94, and S96, and continues automatic deceleration control (S94 or S96) during the execution of automatic deceleration control without receiving new instructions from ADK200 until vehicle 1 reaches a stopped state. Furthermore, the steering control of vehicle 1 during the execution of automatic deceleration control is arbitrary. The base vehicle 120, for example, can also release the torque on the steering wheel to return the steering angle to the midpoint.

[0134] When vehicle 1 is brought to a stop state by automatic deceleration control (yes in S97 or S98), the process proceeds to S99. In S99, base vehicle 120 requests VCIB110 to switch to manual mode. Based on this request, VCIB110 recognizes the end of automatic deceleration control. Then, VCIB110 sets the vehicle mode of vehicle 1 to manual mode according to the request from base vehicle 120 and sets VEMDST to "0". When the process in S99 is executed, Figure 9 The process flow F5 shown ends at S90, and the process flow F5 ends.

[0135] As explained above, in this embodiment, VP100 corresponds to an example of a "vehicle capable of carrying an autonomous driving kit" as disclosed herein. VP100 includes VCIB110 and a base vehicle 120. The system built into the base vehicle 120 corresponds to an example of a "vehicle system" as disclosed herein. VP100 performs... Figures 5 to 7 as well as Figures 9 to 11 The processes shown are as follows. The ADK200 installed on the VP100 executes processes F2 and F4. Figure 5 , Figure 8 In this embodiment, each process is performed by executing a program stored in one or more memories using one or more processors. However, these processes can also be performed solely by hardware (circuit) without using software.

[0136] If, during the autonomous driving process of vehicle 1, only one of the multiple paths fails, the base vehicle 120 continues autonomous driving based on commands received from ADK200 via paths other than the failed path (see [link]). Figure 7 Furthermore, in the event that both the first and second paths fail during the autonomous driving process of vehicle 1, the base vehicle 120 executes automatic deceleration control. Figure 9 (S90 in the example). With such control, it is possible to simultaneously achieve stability of automatic driving control based on instructions from ADK200 and appropriate failure protection related to automatic driving control.

[0137] The VCIB110 can also obtain ADK200 specification information from the ADK200 installed on the VP100. Alternatively, the user can input ADK200 specification information into the VCIB110 via HMI150 or 218. The specification information, for example, indicates the types of automated driving that the ADK200 can perform. The VCIB110 can also set VEMDST based on the specification information obtained from the ADK200 or from the user. The VCIB110 can also be configured not to set a value for VEMDST corresponding to types of automated driving that the ADK200 cannot perform.

[0138] Figure 12 To indicate Figure 5 The flowchart for the first modified example of processing flow F2 is shown. Figure 12 In the illustrated modified example, ADK200 replaces processing flow F2 and executes processing flow F2A. Furthermore, ADK200 is configured to only execute assisted autonomous driving and assisted autonomous driving in fully autonomous driving. Processing flow F2A omits S41 and S43 (…). Figure 5 Except for S42, the rest is the same as the processing flow F2. ADK200 requests automatic deceleration shutdown from VCIB110 in S42. Therefore, in Figure 6 In S22, the automatic deceleration ST is set to "0". Furthermore, the VCIB110 sets VEMDST to "0" or "2" based on the ADK200 specifications, and does not set VEMDST to "1". Therefore, through... Figure 10 The processing flow F7 shown here will then appropriately execute manual driving (S205) or assisted automatic driving (S206).

[0139] Figure 13 To indicate Figure 5 The flowchart for the second modified example of processing flow F2 is shown. Figure 13 In the illustrated modified example, ADK200 replaces process flow F2 and executes process flow F2B. Furthermore, ADK200 is configured to only execute assisted autonomous driving and fully autonomous driving within fully autonomous driving. Process flow F2B omits S41 and S42 (…). Figure 5 Except for step S43, the process is the same as F2. ADK200 requests automatic deceleration to be activated from VCIB110. Therefore, in... Figure 6 In S22, the automatic deceleration ST is set to "1". Furthermore, the VCIB110 sets VEMDST to "0" or "1" based on the ADK200 specifications, and does not set VEMDST to "2". Therefore, through... Figure 10 The processing flow F7 shown here will enable manual driving (S205) or fully automated driving (S202) to be performed appropriately.

[0140] When an autonomous driving kit, developed separately from the vehicle (VP100), is installed on the vehicle, the autonomous driving kit does not necessarily have to have the functions envisioned by the vehicle manufacturer. As mentioned above, obtaining the specifications of the autonomous driving kit through the vehicle (VP100) allows for the appropriate use of various types of autonomous driving kits for autonomous driving.

[0141] Brake1 and Brake2 do not necessarily have to have different structures. Figure 14 To indicate Figure 4 The diagram shows an example of a modified structure. In this modified example, the braking system replaces the brake control unit 121B. Figure 4 The system includes a brake control unit 121C. The brake control unit 121C has the same structure as the brake control unit 121A. The brake control unit 121C includes a motion manager 141C and a brake ECU 142C. The motion manager 141C and the brake ECU 142C perform the same functions as the motion manager 141A and the brake ECU 142A, respectively. Thus, the brake control unit (Brake1) on the first path and the brake control unit (Brake2) on the second path can also have the same structure.

[0142] Figure 15 To indicate Figure 3 The diagram shows a first variation of the structure. Figure 15 In the example of the alteration shown, communication lines L31 and L32 are omitted. Figure 3 In this modified example, there is no third path. The first path (path 170A) is equivalent to the primary system, and the second path (path 170B) is equivalent to the secondary system.

[0143] The functions of Brake1 and Brake2 can also be integrated into a single control unit. Furthermore, in the ADK200, the functions of ADC211A and 211B can also be integrated into a single control unit. Figure 16 To indicate Figure 3 The diagram shows a second modified example of the structure. Figure 16 In the modified example shown, the base vehicle replaces brake control units 121A and 121B with a control device (brake control unit 121D) having these functions. Furthermore, the automated driving kit involved in this modified example replaces ADCs 211A and 211B with a control device (ADC 211D) having these functions. Figure 16 In the modified example shown, the braking control unit 121D and the ADC211D are respectively included in both the first path (path 170A) and the second path (path 170B).

[0144] While embodiments of the invention have been described, it should be understood that the embodiments disclosed herein are illustrative rather than restrictive in all respects. The scope of the invention is defined by the claims and is intended to include all modifications within the meaning and scope equivalent to the claims.

Claims

1. A vehicle capable of being equipped with an autonomous driving suite, wherein, The vehicle is equipped with a vehicle control interface box and a vehicle system. The vehicle control interface box includes a first control device and a second control device. The vehicle system includes a braking device that decelerates the vehicle. The vehicle system is configured to receive instructions from the autonomous driving suite via each of multiple paths. The plurality of paths includes a first path via the first control device and a second path via the second control device. The vehicle system is configured such that, In the event that only one of the multiple paths fails during autonomous driving, autonomous driving continues based on instructions received from the autonomous driving suite via paths other than the failed path. In the event that both the first path and the second path fail during autonomous driving, automatic deceleration control is performed to control the braking device in a manner that slows down the vehicle.

2. The vehicle as claimed in claim 1, wherein, The vehicle system also includes a third control device and a fourth control device for controlling the braking device. The first path is the path from the autonomous driving kit, through the first control device, to the third control device. The second path is the path from the autonomous driving kit to the fourth control device via the second control device.

3. The vehicle as claimed in claim 2, wherein, The plurality of paths also includes a third path where instructions from the autonomous driving suite travel through the second control device to the third control device. If the first path is not functionally disabled, the third control device controls the braking device based on instructions received from the autonomous driving suite via the first path, and... When the first path is malfunctioning, and neither the second nor the third path is malfunctioning, the third control device controls the braking device based on instructions received from the autonomous driving suite via the third path.

4. The vehicle as claimed in claim 3, wherein, If both the first path and the third path fail, the third control device or the fourth control device shall execute the automatic deceleration control.

5. The vehicle as described in any one of claims 1 to 4, wherein, The first control device is configured to determine whether the communication between the autonomous driving suite and the first control device is malfunctioning, and to output the result of the determination to the vehicle system. The second control device is configured to determine whether the communication between the autonomous driving kit and the second control device is in a state of functional failure, and output the result of the determination to the vehicle system.

6. The vehicle as described in any one of claims 1 to 4, wherein, The vehicle control interface box is configured to toggle the activation / deactivation of the automatic deceleration control based on requests from the autonomous driving suite. The vehicle system is configured to perform the automatic deceleration control only when the automatic deceleration control becomes effective.

7. The vehicle as claimed in claim 6, wherein, The vehicle control interface box is configured to prevent the switching of the automatic deceleration control from being active / inactive during autonomous driving.

8. The vehicle as described in any one of claims 1 to 4, wherein, The vehicle system is configured to continue the automatic deceleration control during its execution without receiving new instructions from the autonomous driving suite, until the vehicle comes to a stop.

9. The vehicle as claimed in claim 8, wherein, When the autonomous driving suite is sending a deceleration command requesting the vehicle to slow down, if it is determined that both the first path and the second path are functionally ineffective, the vehicle system controls the braking device in the automatic deceleration control in a manner that makes the deceleration of the vehicle close to the greater of the deceleration requested by the deceleration command and the pre-defined speed.

10. The vehicle as claimed in claim 9, wherein, The vehicle system also includes a vehicle drive unit that accelerates the vehicle. When the autonomous driving suite is sending an acceleration command requesting the vehicle to accelerate, and if it is determined that both the first path and the second path are functionally ineffective, in the automatic deceleration control, after controlling the vehicle drive device to make the vehicle's acceleration zero, the vehicle deceleration is controlled to approach a pre-defined deceleration.

Citation Information

Patent Citations

  • Vehicle platform, vehicle control interface box, and automatic driving system

    JP2024106017A