Testing device and testing procedure

By treating the trajectory of a moving object as a separate lane, the collision risk assessment system reduces processor load and excessive reactions, enhancing the validity of risk assessments for vehicles in traffic scenarios.

DE112023005541T5Pending Publication Date: 2026-04-09DENSO CORP
View PDF 2 Cites 0 Cited by

Patent Information

Authority / Receiving Office
DE · DE
Patent Type
Applications
Current Assignee / Owner
Filing Date
2023-09-26
Publication Date
2026-04-09

AI Technical Summary

Technical Problem

Existing collision risk assessment systems for vehicles frequently result in excessive reactions and increased processing load when dealing with moving objects in the same lane, particularly in traffic jams or densely populated areas, leading to inefficiencies and potential safety issues.

Method used

A testing apparatus and procedure that treats the trajectory of a moving object passing through a lane as a separate lane, adjusting collision risk assessment conditions to reduce processor load and minimize excessive vehicle reactions.

Benefits of technology

This approach improves the validity of collision risk assessments by reducing processor load and the frequency of excessive vehicle reactions, ensuring more appropriate responses to moving objects in the same lane.

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure 00000035_0000
    Figure 00000035_0000
  • Figure 00000036_0000
    Figure 00000036_0000
  • Figure 00000037_0000
    Figure 00000037_0000
Patent Text Reader

Abstract

An RSS unit (53), functioning as a testing device, is equipped with a processor (53b) and is used in the operation of a vehicle (1). The processor (53b) assumes the trajectory of an expected journey of a motorcycle (SO1), which is a moving object capable of passing through a vehicle lane (LA) in which a vehicle (1) is present, to include the inside of the vehicle lane (LA), and checks the risk of a collision between the vehicle (1) and the motorcycle (SO1) by treating the travel path (DR) containing the region occupied by the trajectory as a separate vehicle lane, distinct from the vehicle lane (LA) in which the vehicle (1) is present.
Need to check novelty before this filing date? Find Prior Art

Description

Cross-reference to a related registration

[0001] The present application claims priority from Japanese patent application No. 2023-001415, which was filed on January 9, 2023. The complete disclosures of all the above-mentioned applications are incorporated herein by reference. Technical field

[0002] The present disclosure relates to the driving of a vehicle. State of the art

[0003] In the disclosure of patent literature 1, a processor predicts the trajectory of a moving object near a vehicle and determines whether a risk value, indicating a collision risk between the vehicle and the moving object, exceeds a predefined risk threshold. The processor then generates information for determining a safe driving condition for the vehicle based on the finding that the collision risk exceeds the risk threshold. For example, in determining the risk, if a detected distance between the vehicle and the moving object is less than a minimum safety distance, the vehicle is deemed unsafe. Literature from the state of the art, patent literature

[0004] Patent literature 1: US 2021 / 0009121 A Brief description of the invention

[0005] For example, on a road during a traffic jam, on a road in developing countries or densely populated areas, and so on, a moving object, such as a motorcycle, bicycle, pedestrian, or the like, may pass through or cross the same lane as the lane in which the vehicle is traveling. In such a scenario, if the collision risk with the moving object is determined under the same conditions as for a normal vehicle, there is a concern that, for example, excessive vehicle reactions may occur frequently. There is also a concern that a processing load related to the collision risk with the moving object will be increased.

[0006] One purpose of disclosing this description is to provide a testing apparatus and a testing procedure for improving the validity of a handling of a moving object traveling through a lane.

[0007] An embodiment disclosed herein includes a test device used for driving a vehicle, which contains at least one processor. The processor is configured to assume a trajectory along which the movement of a moving object passing through a lane in which the vehicle is located is predicted, such that the trajectory includes an inside of the lane, and to check for a collision risk between the vehicle and the moving object by treating at least a portion of a region occupied or claimed by the trajectory as a separate lane apart from the lane in which the vehicle is located.

[0008] Another aspect of the disclosed embodiment is a method for checking the collision risk of a vehicle, executed by at least one processor, which includes: assuming a trajectory along which the movement of a moving object passing through a lane in which the vehicle is present is predicted, such that the trajectory includes an inside of the lane; and checking the collision risk between the vehicle and the moving object by treating at least a part of a region occupied or claimed by the trajectory as a separate lane apart from the lane in which the vehicle is present.

[0009] In these aspects, a region occupied by the trajectory of a moving object passing through a lane containing a vehicle is treated as a separate lane. This allows for the appropriate processing of predicted behavior from the passing moving object, while reducing the processor load caused by handling situations where many moving objects are in the same lane within a traffic jam. It also reduces the frequency of excessive vehicle reactions that can result from risk assessment. In this way, the validity of collision risk assessments for moving objects passing through a lane can be improved.

[0010] Another aspect of the disclosed embodiments includes a test device used for driving a vehicle, which contains at least one processor. The processor is configured to perform the following: checking for a collision risk between the vehicle and another road user; determining whether to execute an appropriate response, including braking, if it is determined that the collision risk is higher than a preset threshold; modifying a condition for determining the collision risk such that it determines the collision risk is higher when the other road user is in the same lane as the vehicle, compared to when the other road user is in a separate lane; and assuming a moving object passing through a lane in which the vehicle is present is the other road user.and a treatment in which the collision risk of the moving object is determined to be in a separate lane apart from the lane in which the vehicle is present, even if the moving object is present in the lane in which the vehicle is present.

[0011] With this aspect, a condition for determining the collision risk with respect to a passing, moving object is one that determines the collision risk to be lower, in the same way as other road users present in a lane separate from the vehicle. Consequently, since the possibility of determining that the collision risk is higher than a preset threshold becomes low, it becomes difficult to reach a situation where an appropriate reaction, including braking, is warranted. Therefore, it is possible to reduce the frequency of excessive reactions to the passing, moving object. In this way, when checking the collision risk with the moving object passing through a lane, the validity for the moving object can be improved.

[0012] The reference numerals in parentheses in the claims indicate by way of example a correspondence with the sections of the embodiments to be described later and are not intended to limit the technical scope. Brief description of the drawings Fig. Figure 1 is a diagram that represents a schematic configuration of a driving system. Fig. Figure 2 is a diagram that represents a hardware configuration of the driving system. Fig. Figure 3 is a diagram representing a longitudinal safety distance. Fig. Figure 4 is a diagram that represents an expression for the longitudinal safety distance. Fig. Figure 5 is a diagram representing the longitudinal safety distance. Fig. Figure 6 is a diagram that represents the expression for the longitudinal safety distance. Fig. Figure 7 is a diagram representing a lateral safety distance. Fig. Figure 8 is a diagram that represents an expression for the lateral safety distance. Fig. Figure 9 is a diagram that represents a lane-based coordinate system. Fig. Figure 10 is a flowchart that represents a process through the driving system. Fig. Figure 11 is a diagram that illustrates an example of a scenario in which a passing, moving object is present. Fig. Figure 12 is a diagram representing an expression related to an assumption of a route. Fig. Figure 13 is a diagram representing an expression related to the assumption of the route. Fig. Figure 14 is a diagram that illustrates the example of the scenario in which the passing, moving object is present. Fig. Figure 15 is a diagram representing an expression related to the assumption of the route. Fig. Figure 16 is a diagram that illustrates the example of the scenario in which the passing, moving object is present. Fig. Figure 17 is a diagram that illustrates the example of the scenario in which the passing, moving object is present. Fig. Figure 18 is a diagram that represents an example of a scenario in which a passing, moving object is assumed. Fig. Figure 19 is a diagram that illustrates the example of the scenario in which the passing, moving object is assumed. Fig. Figure 20 is a flowchart that represents the process carried out by the driving system. Fig. Figure 21 is a diagram that represents the schematic configuration of the driving system. Fig. Figure 22 is a diagram that represents the schematic configuration of the driving system. Fig. Figure 23 is a state transition diagram that represents a state transition of a vehicle. Fig. Figure 24 is a diagram that illustrates the example of the scenario in which the passing, moving object is assumed. Fig. Figure 25 is a diagram that illustrates the example of the scenario in which the passing, moving object is assumed. Fig. Figure 26 is a diagram that illustrates the example of the scenario in which the passing, moving object is present. Fig. Figure 27 is a diagram illustrating an example of the scenario in which the passing, moving object is present. Description of embodiments.

[0013] Several embodiments are described below based on the drawings. Duplicate descriptions can be avoided by assigning the same reference numerals to the corresponding elements in each embodiment. If only part of a configuration is described in each embodiment, the configurations of the other embodiments described above can be applied to the other parts of the configuration. Not only the combinations of configurations explicitly illustrated in the description of each embodiment, but also the configurations of several embodiments can be partially combined, even if they are not explicitly illustrated, provided that there is no problem with the combination.

[0014] In the following multiple embodiments, content from “Safety First for Automated Driving” Tech.Rep., 2019, by Aptiv, Audi, Baidu, BMW, Continental, Daimler, FCA, here, Infineon, Intel and Volkswagen; content from “On a formal model of safe and scalable self-driving cars”, arXiv:1708.06374, 2017, by S. Shalev-Shwartz, S. Shammah and A. Shashua; content from “The Safety Force Field” Technical Report, 2019, by David Nister, Hon-Leung Lee, Julia Ng, Yizhou Wang; and content from IEEE 2846-2022 are incorporated by reference in their entirety. First embodiment

[0015] A driving system 2 of a first embodiment, which is in Fig. 1 and Fig. As illustrated in Figure 2, a function related to driving a moving object is implemented. Part or all of the driving system 2 is mounted in the moving object. The moving object, which is a target to be processed by the driving system 2, is a vehicle 1. This vehicle 1 can be referred to as an ego vehicle or own vehicle, a host vehicle, or the like. The vehicle 1 can be configured to communicate directly or indirectly with another vehicle or the like via a communication infrastructure. The other vehicle is, in some cases, referred to as a target vehicle.

[0016] Vehicle 1 could, for example, be a road user capable of manually driving a four-wheeled car or truck. Vehicle 1 could also be capable of automated driving. Driving levels are classified according to a range or similar of tasks performed by a driver among all dynamic driving tasks (DDTs). The level of automated driving is defined, for example, in SAE J3016. At levels 0 to 2, the driver performs some or all of the DDTs. Levels 0 to 2 can be classified as manual driving. Level 0 indicates that driving is not automated. Level 1 indicates that the driving system 2 assists the driver. Level 2 indicates that driving is partially automated.

[0017] At Level 3 or higher, the driving system 2 performs all DDTs while it is engaged or intervening. Levels 3 to 5 can be classified as automated driving. A system capable of performing driving at Level 3 or higher can be called an automated driving system. A vehicle equipped with an automated driving system, or a vehicle capable of performing driving at Level 3 or higher, can be called an automated vehicle (AV). Level 3 indicates conditionally automated driving. Level 4 indicates highly automated driving. Level 5 indicates fully automated driving.

[0018] Driving system 2, which is not capable of performing Level 3 or higher driving but is capable of performing at least one of the levels, Level 1 and Level 2, may be referred to as a driver assistance system. In the following, where there is little need to specify, in particular, the achievable level of automated driving, the automated driving system or the driver assistance system may simply be referred to as driving system 2. Driving system overview

[0019] The architecture of driving system 2 is selected to enable an efficient process for ensuring the safety of the intended functionality (SOTIF). For example, the architecture of driving system 2 can be configured based on a sense-plan-act model. The sense-plan-act model includes a sense element, a planning element, and an action element as its main system elements. These elements interact with each other. The sense element can be replaced by perception, the planning element by assessment, and the action element by control.

[0020] In such a driving system 2, a detection function, a planning function, and an action function are implemented at a functional level (in other words, from a functional perspective). At a technical level (in other words, from a technical perspective), at least several sensors corresponding to the detection function, at least one processing system corresponding to the planning function, and several motion actuators corresponding to the action function are implemented.

[0021] In particular, a sensing unit 10, as a functional block for realizing the sensing function primarily using multiple sensors, a processing system that processes the sensing information from the multiple sensors, and a processing system that generates an environmental model based on information from the multiple sensors can be implemented in the driving system 2. A planning unit 20 and an RSS 26, as functional blocks that realize the planning function primarily using a processing system 50, can be implemented in the driving system 2. An action unit 30, as a functional block for realizing the action function primarily using multiple motion actuators 60 and at least one processing system that outputs an operating signal from the multiple motion actuators 60, can be implemented in the driving system 2.

[0022] The data acquisition unit 10 can be implemented as a data acquisition system, serving as a subsystem designed to be distinguishable from the planning unit 20 and the action unit 30. The planning unit 20 can also be implemented as a subsystem within a planning system, designed to be distinguishable from the data acquisition unit 10 and the action unit 30. The planning system can also include the RSS 26. The action unit 30 can be implemented as a subsystem within an action system, designed to be distinguishable from the data acquisition unit 10 and the planning unit 20. The data acquisition system, the planning system, and the action system can be independent components. The term "system" can be replaced here by a module, a unit, a device, or the like.

[0023] Furthermore, several human-machine interface (HMI) devices 70 can be installed in the vehicle 1. The HMI device 70 implements a human-machine interaction, which is an interaction between an occupant (including a driver) of the vehicle 1 and the driving system 2. Some of the several HMI devices 70 that implement an operating input function for the occupant can be part of the sensing unit 10. Some of the several HMI devices 70 that implement an information presentation function can be part of the action unit 30. Meanwhile, the function implemented by the HMI device 70 can be provided as a function independent of the sensing function, the planning function, and the action function.

[0024] The acquisition unit 10 serves as the acquisition function, providing localization (for example, a position estimate) of a road user, such as vehicle 1 and another vehicle. Acquisition unit 10 acquires information about the external environment, the internal environment, and the vehicle state of vehicle 1, as well as the state of the driving system 2. Acquisition unit 10 combines the acquired information to generate an environment model. This environment model can be referred to as a world model. Planning unit 20 applies a purpose and a driving guideline to the environment model generated by acquisition unit 10 in order to derive a control action. Action unit 30 executes the control action derived by planning unit 20. Overview of the physical structure

[0025] An example of a physical setup of the driving system 2 is given using Fig. 2 described. The driving system 2 contains the multiple sensors, the multiple motion actuators 60, the multiple HMI devices 70, at least one processing system 50, and the like. These elements can communicate with each other via one or both of the connections, wireless connection and wired connection. These elements may be able to communicate with each other, for example, via an in-vehicle network, such as a CAN (registered trademark). These elements are described with reference to Fig. 2 described in more detail.

[0026] The multiple sensors include one or more outdoor environment sensors 41. The multiple sensors can include at least one type among one or more indoor environment sensors 42, one or more communication systems 43 and a map database (DB) 44.

[0027] The external environment sensor 41 can detect a target object present in the external environment of the vehicle 1. Examples of external environment sensors 41 that have a target object detection type include, for example, a camera, a laser beam detection and rangefinder (LiDAR), a millimeter-wave radar, an ultrasonic sonar, and the like. Typically, a combination of several types of external environment sensors 41 can be mounted to monitor each direction of the vehicle 1's forward, lateral, and reverse movements.

[0028] As an example of the mounting of the external environment sensor 41, the Ego vehicle or own vehicle 1 can be mounted with several cameras (for example, 11 cameras) that are configured to monitor each of the directions, forward direction, front-side direction, side direction and rear-side direction, reverse direction, of vehicle 1.

[0029] As another assembly example, several cameras (for example, four cameras) configured to monitor a front, a side, and a rear of vehicle 1, several millimeter wave radars (for example, five millimeter wave radars) configured to monitor the front, front-side, side, and rear of vehicle 1, and the LiDAR configured to monitor the front of vehicle 1 can be mounted in vehicle 1.

[0030] Furthermore, the external environment sensor 41 can detect a state of the atmosphere or a weather condition in the external environment of the vehicle 1. The external environment sensor 41, which has a state detection type, is, for example, an outside air temperature sensor, a temperature sensor, a rain sensor, or the like.

[0031] The interior environment sensor 42 can detect a specific physical quantity (hereinafter referred to as a physical motion quantity) related to vehicle movement within the interior environment of the vehicle 1. Examples of the interior environment sensor 42 having a physical motion detection type include a velocity sensor, an accelerometer, a gyroscope, and the like. The interior environment sensor 42 can also detect the state of an occupant within the interior environment of the vehicle 1. Examples of the interior environment sensor 42 having an occupant detection type include an actuator sensor, a driver monitoring sensor and a system thereof, a biometric sensor, a seat sensor, an in-vehicle device sensor, and the like.In particular, examples of the actuator sensor include an accelerator pedal sensor, a brake sensor, a steering sensor and the like, which detect an operating state of the occupant in relation to the motion actuator 60, which is related to a motion control of the vehicle 1.

[0032] Communication system 43 obtains communication data that can be used in vehicle system 2 via wireless communication. Communication system 43 can receive a positioning signal from an artificial satellite of a global navigation satellite system (GNSS) located in the external environment of vehicle 1. A communication device that has a positioning function in communication system 43 is, for example, a GNSS receiver or the like.

[0033] The communication system 43 can send and receive a communication signal to an external system 96 located in the external environment of the vehicle 1. A communication device that has a V2X type in the communication system 43 is, for example, a dedicated short-range communication (DSRC) device, a cellular V2X (C-V2X) device, or the like. Examples of communication with the V2X system located in the external environment of the vehicle 1 include communication with another vehicle's communication system (V2V), communication with infrastructure such as a communication device embedded in a traffic light or roadside device (V2I), communication with a pedestrian's mobile terminal or device (V2P), communication with a network such as a cloud server (V2N), and the like.An architecture for V2X communication that includes V2I communication can use an architecture defined in ISO21217, ETSI TS 102 940-943, IEEE 1609 or similar standards.

[0034] Furthermore, the communication system 43 can send and receive a communication signal to and from the interior environment of the vehicle 1, for example, with a mobile terminal 91, such as a smartphone, that is present in the vehicle. A communication device that has a terminal communication type in the communication system 43 is, for example, a Bluetooth device (registered trademark), a Wi-Fi device (registered trademark), an infrared communication device, or the like.

[0035] Map DB 44 is a database that stores map data which can be used in the driving system 2. Map DB 44 is configured with at least one type of non-volatile tangible storage medium, for example, semiconductor memory, magnetic medium, optical medium, and the like. Map DB 44 can contain a database of a navigation unit that navigates a route of vehicle 1 to a destination. Map DB 44 can contain a database of a probe data map (PD map) generated using probe data collected from each vehicle. Map DB 44 can contain a database of a high-resolution map primarily used for an automated driving system.The map database 44 can contain a parking map database that includes specific parking information, for example, parking framework information used for automated parking or parking assistance.

[0036] The map database 44, suitable for the vehicle system 2, obtains and stores the latest map data, for example, by communicating with a map server via the communication system 43 with a V2X type. The map data is converted into two-dimensional or three-dimensional data that characterizes the external environment of the vehicle 1. The map data can include, for example, road data representing at least one type of road structure, shape, surface condition, and standard carriageway, defined by position coordinates. The map data can also include marking data representing at least one type of, for example, a traffic sign, a road indicator, a position coordinate, and a shape of a lane marking, and the like, affixed to a road.The marker data contained in the map data can represent, for example, a traffic sign, an arrow marking, a lane marking, a stop line, a direction sign, a directional light, a business sign, and a change in a road's line pattern among target objects. The map data can contain structural data representing, for example, at least one type of position coordinate, a shape, and the like of a building and a traffic light facing the road. The marker data contained in the map data can represent, for example, a street light, a road edge, a reflective panel, a pole, and the like among the target objects.

[0037] The motion actuator 60 is capable of controlling vehicle movement based on an input control signal. The motion actuator 60, which has a driving type, is a powertrain that includes, for example, at least one type of internal combustion engine, a drive motor, and the like. The motion actuator 60, which has a braking type, is, for example, a brake actuator. The motion actuator 60, which has a steering type, is, for example, a steering system.

[0038] The HMI device 70 can be an operating input device capable of receiving input from a driver to transmit the will or intention of the vehicle occupant 1, including the driver, to the driving system 2. The HMI device 70, which has an operating input type, is, for example, an accelerator pedal, a brake pedal, a gearshift lever, a steering wheel, a turn signal lever, a mechanical switch, a touch panel (such as a navigation unit), or the like. Among these, the accelerator pedal controls the powertrain, which serves as the motion actuator 60. The brake pedal controls the brake actuator, which serves as the motion actuator 60. The steering wheel controls a steering actuator, which serves as the motion actuator 60.

[0039] The HMI device 70 can be an information presentation device that presents information, such as visual, audible, tactile, and the like, to the occupants of the vehicle 1, including the driver. An example of a visual information presentation type of HMI device 70 is a combination display, a graphic display, the navigation unit, a center information display (CID), a head-up display (HUD), a lighting unit, or the like. An example of an audible information presentation type of HMI device 70 is a loudspeaker, a buzzer, or the like.The HMI device 70, which has a skin information presentation type, is, for example, a steering wheel vibration unit, a driver's seat vibration unit, a steering wheel reaction force unit, an accelerator pedal reaction force unit, a brake pedal reaction force unit, an air conditioning unit, or the like.

[0040] The HMI device 70 can implement an HMI function in cooperation with a mobile terminal 91, such as a smartphone, by communicating with the terminal via the communication system 43. For example, the HMI device 70 can present information obtained from the smartphone to the occupants, including the driver. For example, an operating input from the smartphone can be used as an alternative to an operating input into the HMI device 70.

[0041] At least one processing system 50 is provided. For example, the processing system 50 can be an integrated processing system that executes a process related to the acquisition function, a process related to the planning function, and a process related to the action function in an integrated manner. In this case, the integrated processing system 50 can further execute a process related to the HMI device 70, and an HMI-dedicated processing system can be provided separately. For example, the HMI-dedicated processing system can be an integrated cockpit system that integrally executes a process related to each HMI device 70.

[0042] For example, the processing system 50 can be configured to include each of the processing units, at least one processing unit corresponding to the process related to the capture function, at least one processing unit corresponding to the process related to the planning function, and at least one processing unit corresponding to the process related to the action function.

[0043] The processing system 50 includes a communication interface for an outside and is connected to at least one type of element related to the process carried out by the processing system 50, under each sensor, motion actuator 60, HMI device 70 and the like, via at least one type of, for example, a local area network (LAN), a cable harness, an internal bus and a wireless communication circuit.

[0044] The processing system 50 is configured to include at least one dedicated computer 51. The processing system 50 can combine multiple dedicated computers 51 to perform a function, such as the data acquisition function, the planning function, and the action function.

[0045] For example, the dedicated computer 51, which forms the processing system 50, can be an integrated ECU that integrates a driving function of the vehicle 1. The dedicated computer 51, which forms the processing system 50, can be a determination ECU that determines a DDT. The dedicated computer 51, which forms the processing system 50, can be a monitoring ECU that monitors the driving of the vehicle. The dedicated computer 51, which forms the processing system 50, can be an evaluation ECU that evaluates the driving of the vehicle. The dedicated computer 51, which forms the processing system 50, can be a navigation ECU that navigates a route for the vehicle 1.

[0046] The dedicated computer 51, which forms the processing system 50, can be a tracking ECU or localization device ECU that estimates the position of the vehicle 1. The dedicated computer 51, which forms the processing system 50, can be an image processing ECU that processes image data detected by the external environment sensor 41. The dedicated computer 51, which forms the processing system 50, can be an actuator ECU that controls the motion actuator 60 of the vehicle 1. The dedicated computer 51, which forms the processing system 50, can be an HMI control unit (HCU) that integrally controls the HMI devices 70. The dedicated computer 51, which forms the processing system 50, can be at least one external computer, which sets up an external center or a mobile terminal 91, which, for example, enables communication via the communication system 43.

[0047] The dedicated computer 51, which forms the processing system 50, contains at least one memory 51a and at least one processor 51b. The memory 51a can be, for example, at least one type of non-volatile tangible storage medium, such as semiconductor memory, magnetic medium, optical medium, and the like, which does not temporarily store a program, data, and the like that can be read by the processor 51b. Furthermore, a rewritable volatile storage medium, such as random-access memory (RAM), can be provided as the memory 51a. The processor 51b contains, for example, at least one type of central processing unit (CPU), graphics processing unit (GPU), and reduced instruction set computer (RISC) CPU as a single core.

[0048] The dedicated computer 51, which forms the processing system 50, can be a system on a chip (SoC) in which a memory, a processor and an interface are integrally realized on one chip, or the SoC can be provided as an element of the dedicated computer 51.

[0049] The processing system 50 can contain at least one database for executing a dynamic driving task. The database can, for example, contain a non-volatile tangible storage medium of at least one type of semiconductor memory, magnetic medium, and optical medium, and an interface for accessing the storage medium.

[0050] The database can be a scenario database (hereinafter referred to as "Scenario DB") 59. The database can be a rule database (hereinafter referred to as "Rule DB") 58. At least one of the databases, Scenario DB 59 and Rule DB 58, cannot be provided in the processing system 50, but can be provided independently in the driving system 2. At least one of the databases, Scenario DB 59 and Rule DB 58, can be provided in the external system 96 and configured to be accessible from the processing system 50 via the communication system 43.

[0051] Scenario DB 59 contains a scenario catalog that stores several scenarios used to drive vehicle 1. Driving system 2, for example, can apply the situation in which vehicle 1 finds itself to a scenario selected from several scenarios or a combination of several scenarios. Scenario DB 59 can store multiple scenarios, each containing at least one of the following types: functional scenario, logical scenario, and concrete scenario. The functional scenario defines a qualitative scenario structure at the highest level. The logical scenario is obtained by assigning a quantitative parameter range to a structured functional scenario. The concrete scenario defines a boundary of a safety determination to distinguish between a safe and an unsafe state.

[0052] Rule DB 58 stores a rule set used for driving vehicle 1. The rule set can contain multiple rules. Furthermore, the rule set can include a priority level structure for a set of rules, determined based on their relative importance among the multiple rules. The rule set can be an implementation of guidelines for strategic driving of vehicle 1.

[0053] The multiple rules may include rules based on laws, regulations, and a combination thereof. The multiple rules may include rules based on a preference unaffected by laws, regulations, or the like. The multiple rules may include rules based on movement patterns derived from past experience. The multiple rules may include rules based on a characterization of a movement environment. The multiple rules may include rules based on ethical concerns. The multiple rules may include rules based on a fundamental principle of a safety model described below (for example, the five principles of an RSS model).

[0054] The processing system 50 can also include at least one recording device 55 that records at least one of the information, acquisition information, planning information, and action information, of the driving system 2. The recording device 55 can include at least one storage medium 55c with a large capacity. The storage medium 55c can be at least one type of non-volatile tangible storage medium, such as a semiconductor memory, a magnetic medium, or an optical medium.

[0055] The storage medium 55c can be mounted on a substrate in a form that is not easily removable or interchangeable, and in this form, for example, an embedded multimedia card (eMMC) or the like using flash memory can be used. At least one of the storage media 55c can be in a form that is removable and interchangeable with respect to the recording device 55, and in this form, for example, an SD card or the like can be used.

[0056] The recording device 55 may have a function for selecting information to be recorded from among the acquisition information, the planning information, and the action information. In this case, the recording device 55 may include a dedicated computer.

[0057] The dedicated computer provided in the recording device 55 has at least one memory 55a and at least one processor 55b. The memory 55a can be, for example, at least one type of non-volatile tangible storage medium, such as semiconductor memory, magnetic medium, optical medium, and the like, which does not temporarily store a program, data, and the like that can be read by the processor 55b. Furthermore, for example, a rewritable volatile storage medium, such as random-access memory (RAM), can be provided as the memory 55a. The processor 55b includes, for example, at least one type of central processing unit (CPU), graphics processing unit (GPU), and reduced instruction set computer (RISC) CPU as a single core.

[0058] The dedicated computer can be a system on a chip (SoC), in which a memory, a processor and an interface are integrally implemented on one chip, or the SoC can be provided as an element of the dedicated computer.

[0059] The recording device 55 can access the storage medium 55c and perform a recording in accordance with a data write command from the driving system 2. The recording device 55 can determine information flowing through the vehicle's internal network, access the storage medium 55c, and perform a recording based on a determination by the processor 55b provided in the recording device 55.

[0060] The recording device 55 cannot be provided in the processing system 50, but can be provided independently in the driving system 2. The recording device 55 can be provided in the external system 96 and configured to be accessible from the processing system 50 via the communication system 43.

[0061] Furthermore, the processing system 50 can contain at least one RSS unit 53.

[0062] The RSS unit 53 can be an aspect of the onboard implementation of response-sensitive safety (RSS) as a safety model. The RSS unit 53 can be an onboard testing device for the planning function implemented by the dedicated computer 51.

[0063] The RSS unit 53 can primarily be configured with a dedicated computer that has at least one memory 53a and at least one processor 53b. The memory 53a can, for example, be at least one type of non-volatile tangible storage medium, such as semiconductor memory, magnetic medium, optical medium, and the like, which does not temporarily store a program, data, and the like that can be read by the processor 53b. Furthermore, a rewritable volatile storage medium, such as random-access memory (RAM), can be provided as the memory 53a. The processor 53b contains, for example, at least one type of central processing unit (CPU), graphics processing unit (GPU), and reduced-instruction-set computer (RISC) CPU as a single core.

[0064] The dedicated computer can be a system on a chip (SoC), in which a memory, a processor and an interface are integrally implemented on one chip, or the SoC can be provided as an element of the dedicated computer. Overview of the logical structure

[0065] Next, an example of a logical structure of the drive system 2 will be given with reference to Fig. The detection unit 10 receives sensor data detected by each sensor. A receiving function can be implemented by a sensor data receiving unit 12, which is a sub-unit in which the detection function is further classified. The detection unit 10 individually processes the sensor data from the external environment sensor 41 and implements an external perception function for detecting a traffic sign, another road user, or the like. The sensor data can be data provided, for example, by a millimeter-wave radar, a sonar, or a LiDAR. The detection unit 10 can generate relative position data of an object, including its direction, size, and distance in relation to the vehicle 1, from raw data detected by the external environment sensor 41.

[0066] The sensor data can be image data, provided, for example, by a camera or LiDAR. The acquisition unit 10 processes the image data and extracts an object reflected within the field of view of a camera or similar device. The object extraction can include an estimate of the object's direction, size, and distance relative to the vehicle 1. The object extraction can also include, for example, a classification of the object using semantic segmentation.

[0067] The acquisition unit 10 performs a localization of the vehicle 1. The acquisition unit 10 obtains global position data of the vehicle 1 from, for example, a GNSS receiver as the communication system 43. In addition, the acquisition unit 10 integrates at least one of the following information—information from the map database 44, position information of an object detected using the external environment sensor 41, and position information of the object detected as a result of sensor fusion, as described below—with the global position data to estimate the position of the vehicle 1 on a map.

[0068] The sensing unit 10 integrates the sensor data from each external environment sensor 41, localization information, and V2X information obtained through V2X communication. This enables the sensing unit 10 to specify the number, type, and relative position of other road users near the vehicle 1. The sensing unit 10 specifies a static structure of a road near the vehicle 1 based on road target object information perceived by the external environment sensor 41. The static structure of the road includes, for example, the curvature of a curve, the number of lanes, and any free space or open area.

[0069] In this way, the acquisition unit 10 generates an environment model containing the surroundings of vehicle 1. An environment model generation function can be implemented as a sub-block by a model extraction unit 11, in which the acquisition function is further classified. The environment model can be provided to the planning unit 20 and the RSS 26. The environment model can be an external environment model specialized for a specific external environment.

[0070] The sensing unit 10 can have a function for processing sensor data detected by each interior environment sensor 42 and for perceiving a vehicle state. The vehicle state can include a state of a physical motion variable of the vehicle 1, detected by a speed sensor, an accelerometer, a gyroscope, or the like. The vehicle state can include at least one type of state, the state of an occupant (including a driver), the state of the motion actuator 60, the operating state of the driver with respect to the motion actuator 60, and the state of the HMI devices 70. The environment model can be an overarching model obtained by combining or linking information about the interior environment, the vehicle state, the state of the driving system 2, and the like, in addition to the external environment.

[0071] Planning unit 20 obtains the environmental model generated by the detection unit 10, the vehicle's state, or similar information, and performs an environmental assessment based on this. Specifically, planning unit 20 can estimate the current situation of vehicle 1 by interpreting the environmental model. This situation could be an operational situation. Planning unit 20 can predict the actions of other road users by interpreting the environmental model. Planning unit 20 can interpret the environmental model and predict the trajectory of other road user objects. Planning unit 20 can also interpret an environmental model and predict a potential hazard.

[0072] Planning unit 20 can also interpret the environment model and determine the scenario in which vehicle 1 is currently located. This scenario determination can involve selecting at least one scenario in which vehicle 1 is currently located from a catalog of scenarios built into scenario database 59.

[0073] Furthermore, the planning unit 20 can estimate a driver's intention based on at least one of the following information: predicted action, predicted object trajectory, predicted potential hazard and scenario determination, as well as the vehicle state, including the operating state of the HMI device 70.

[0074] Planning unit 20 plans the driving of vehicle 1 based on at least one of the following information: estimated position of vehicle 1 on a map, determination of the environment, driver intent estimate, and functional constraint.

[0075] Planning Unit 20 implements a route planning function, a behavior planning function, and a trajectory planning function. The route planning function is a function for planning at least one of the following: route to a destination and lane plan at a medium distance, based on estimated position information for vehicle 1 on the map. The route planning function can further include a function for determining at least one of the requirements: lane change requirement and delay requirement, based on the lane plan at a medium distance. The route planning function can be a mission and route planning function within a strategic function, or it can be a function for outputting a mission plan and a route plan.

[0076] The behavior planning function is a function for planning the behavior of vehicle 1 based on at least one of the following: route to a destination planned by the route planning function, lane plan at medium distance, lane change request, deceleration request, environment determination, driver intent estimation, and functional constraint. The behavior planning function may include a function for generating a condition related to a state transition of vehicle 1. This condition may correspond to a trigger condition. The behavior planning function may also include a function for determining a state transition of an application implementing a DDT (Dealer Deployment Task) and may further include a function for determining a state transition of a driving action based on the condition.The behavior planning function can include a function for determining a constraint related to the longitudinal path of vehicle 1 and a constraint related to the lateral path of vehicle 1, based on information about these state transitions. The behavior planning function can be a strategic behavior plan within a DDT function or it can output a strategic behavior.

[0077] The trajectory planning function is used to plan a vehicle trajectory based on the defined environment, longitudinal constraints on the vehicle's path, and lateral constraints on the vehicle's path. The trajectory planning function may include a function for generating a path plan. This path plan may include a speed plan, or the speed plan may be generated independently of the path plan. The trajectory planning function may also include a function for generating multiple path plans and selecting an optimal path plan from among them, or a function for switching between path plans. Furthermore, the trajectory planning function may include a function for generating backup data of the generated path plan.The trajectory planning function can be a trajectory planning function within the DDT function, or it can output a trajectory plan.

[0078] Furthermore, Planning Unit 20 can manage a mode of Driving System 2 or an automated driving mode. Managing the automated driving mode can, for example, include managing the state of an automated driving level. Managing the automated driving level can include switching between manual and automated driving, that is, transferring authorization between the driver and Driving System 2—in other words, managing the takeover. Planning Unit 20 can monitor the state of each subsystem within Driving System 2 and determine a system defect (for example, an error, an unstable operating state, a system failure, or a breakdown).

[0079] Planning Unit 20 can determine the mode based on a driver's intention, based on an intent estimate of the driver. Planning Unit 20 can define a restriction of a function related to driving, based on at least one of the following information: sensor abnormality (or sensor failure) signal output by each sensor, application state transition information, and trajectory plan.

[0080] Planning unit 20 can have a function for determining the constraint relating to the longitudinal path of vehicle 1 and the constraint relating to the lateral path of vehicle 1, in addition to the functional constraint relating to driving. In this case, as described above, planning unit 20 plans a behavior and plans a trajectory according to this constraint.

[0081] Action unit 30 obtains the trajectory plan (for example, path plan and velocity plan) from planning unit 20. Furthermore, action unit 30 obtains information about a suitable response from RSS 26. This information about the suitable response can constitute a requirement for action unit 30 to execute the suitable response. The requirement to execute the suitable response can be a constraint requirement.

[0082] If there is no request from RSS 26, the action unit 30 controls a movement of vehicle 1 based on the trajectory plan through the planning unit 20. The action unit 30 generates accelerator pedal request information, shift request information, brake request information and steering request information that correspond to the trajectory plan and outputs the accelerator pedal request information, the shift request information, the brake request information and the steering request information to the motion actuator 60.

[0083] Action Unit 30 applies the appropriate response to the trajectory plan when requested by RSS 26. Applying the appropriate response may involve applying a constraint requested by RSS to the trajectory plan. One function of applying the RSS constraint can be implemented by an RSS constraint application Unit 31, which is a sub-block where the action function is further classified. Action Unit 30 generates accelerator pedal request information, shift request information, brake request information, and steering request information, corresponding to a plan following the application of the request from RSS 26, and outputs this information to the motion actuator 60.A function of generating such a request to the motion actuator 60 can be implemented by an actuator request generation unit 32 as a sub-block in which the action function is further classified.

[0084] The action unit 30 can have a function of directly obtaining a vehicle state perceived by the detection unit 10, for example at least one of the quantities, current speed, acceleration and yaw rate, of the vehicle 1 from the detection unit 10 and of reflecting the vehicle state in the motion control of the vehicle 1.

[0085] Furthermore, the action unit 30 can contain an HMI output unit 33 as a sub-block in which the action function is further classified. The HMI output unit 33 can be configured independently of the action unit 30 with regard to hardware and / or software.

[0086] The HMI output unit 33 can output information to an occupant of vehicle 1, including a driver, based on at least one of the following information: environment determination, driver intent estimation, application state transition, trajectory plan, functional constraint, and appropriate responses via the RSS 26. The HMI output unit 33 can manage vehicle interaction. It can generate a notification request based on a vehicle interaction management state and control an information presentation function of the HMI devices 70. Furthermore, the HMI output unit 33 can generate a control request for a windshield wiper, a sensor cleaning device, a headlight, and an air conditioning system installed in vehicle 1 and control these devices. Security model and its implementation

[0087] Driving system 2 can implement a safety model for automated driving. The safety model is a model used to demonstrate the absence of an unacceptable risk within a specific operational design domain (ODD). The safety model can be, for example, a safety driving model, a safety-related model, or a formal model. The RSS model, for instance, can be used as the safety model. However, other models, such as a more generalized model or a complex model obtained by combining several models, can also be used.

[0088] For example, the RSS model uses five rules (five principles). The first rule is "Don't rear-end someone." The second rule is "Don't cut in recklessly." The third rule is "The right of way is given, not taken." The fourth rule is "Respect other people's space; you must." The fifth rule is "If you can avoid an accident without causing another, you must do so."

[0089] Based on the five rules, especially the first and second, a safety envelope can be defined. For example, the safety envelope can represent a longitudinal safety distance and a lateral safety distance in relation to the other road user, or it can represent a condition or concept for calculating these safety distances. The safety distance is an example of a geometric approach.

[0090] A longitudinal safety distance d min can be a distance at which a rear-end collision does not occur if a preceding vehicle OV1, traveling at a speed v f drives, with maximum deceleration a max , brake brakes and stops, even if a following vehicle (for example, vehicle 1) has a reaction time ρ and a maximum acceleration a max, accel accelerated and then with a minimal delay a min, brake brakes and stops, as it says in Fig. 3 is shown.

[0091] d brake, front , which is in expressions 1 and 4 in Fig. The number 4 indicates a stopping distance of the vehicle ahead, OV1. d reaction , which is in expressions 2 and 4 in Fig. A space marked 4 indicates a clear driving distance for the following vehicle. brake, rear , which is in expressions 3 and 4 in Fig. The number marked 4 indicates a braking distance of the following vehicle. As shown in expression 4 in Fig. If marked 4, the safety distance d min a distance equal to the stopping distance of the vehicle OV1 in front plus the free driving distance of the following vehicle minus the braking distance of the following vehicle.

[0092] The longitudinal safety distance d min can be a distance at which a head-on collision does not occur, even if two vehicles 1 and OV2 are approaching each other at their respective speeds v1 and v2, with the predetermined reaction time ρ and the maximum acceleration a max, accel , accelerate and then with the minimum delay a min, brake braking and stopping, as it is in Fig. 5 is shown.

[0093] d reaction, 1 , which is in expression 5 in Fig. If marked with 6, vehicle 1 has a free passage. brake, 1 , which is in expression 6 in Fig. The number marked 6 indicates a braking distance of the vehicle 1. d reaction, 2 , which is in expression 7 in Fig. The number marked 6 indicates a free driving distance for vehicle OV2. d brake, 2 , which is in expression 8 in Fig. The distance marked 6 is a braking distance of vehicle OV2. As shown in expression 9 in Fig. If marked with 6, the safety distance d min be a sum of the free driving distance of vehicle 1, the braking distance of vehicle 1, a free driving distance of vehicle OV2 and the braking distance of vehicle OV2.

[0094] The lateral safety distance d min can be a distance at which a minimum distance µ is ensured and a collision does not occur, even if two vehicles 1 and OV3 are driving side by side at the respective lateral speeds v1 and v2, with the predetermined reaction time ρ and the maximum acceleration a max , accel, accelerate and then decelerate laterally with maximum deceleration a min, brake brakes, as it is in Fig. 7 is shown.

[0095] d reaction, 1 , which is in expression 10 in Fig. The number 8 indicates a free driving distance for vehicle 1. d brake, 1 , which is in expression 11 in Fig. The number marked 8 indicates a braking distance of the vehicle 1. d reaction, 2 , which is in expression 12 in Fig. The number marked 8 indicates a free driving distance for vehicle OV3. d brake, 2 , which is in expression 13 in Fig. The distance marked 8 is a braking distance of the vehicle OV3. As shown in expression 14 in Fig. As shown in figure 8, the safety distance d min be a sum of the free driving distance of vehicle 1, the braking distance of vehicle 1, a free driving distance of vehicle OV3 and the braking distance of vehicle OV3.

[0096] A coordinate system used in the safety model can be a lane-based coordinate system. As it is in Fig. As shown in Figure 9, this coordinate system processes the movement of vehicle 1 in one direction along a lane LA by defining a centerline of lane LA, that is, a lane axis ALA along a curve of the road. Alternatively, to define a longitudinal axis and a transverse axis for each road user, a road user-based coordinate system can be used. This coordinate system is based on the road user's center of gravity and defines an ordinate and an abscissa depending on the road user's direction of travel.

[0097] The RSS 26, implemented in the driving system 2, is arranged in parallel to the planning unit 20, for example, with respect to a structure, and performs a calculation process. Specifically, the RSS 26 obtains an environmental model, sensor data, or the like from the acquisition unit 10, assesses a risk based on this information, and outputs a corresponding response to the action unit 30. As described in Fig. As shown in Figure 1, the RSS 26 can contain a situation extraction unit 27, a situation check unit 28 and a reaction unit 29 as sub-blocks in which its function is further classified.

[0098] The situation extraction unit 27 extracts a situation based on information obtained from the acquisition unit 10. Data characterizing the situation (hereinafter referred to as situation data) may include a list of objects present near vehicle 1 (hereinafter referred to as environment objects). The environment object may include another road user. The situation data may contain data indicating a potential conflict between vehicle 1 and the environment object. In this case, the situation data may include a probability of presence and an uncertainty regarding the position, orientation, and speed of vehicle 1 and the environment object. The situation extraction unit 27 can extract multiple situations. The situation may be a traffic situation. The situation may be selected from a set of considered situations.

[0099] The situation check unit 28 checks whether the situation extracted by the situation extraction unit 27 is a safe or a hazardous situation. The situation check unit 28 performs at least one of the following checks: a check using the geometric approach described above and a risk check using another methodology. If the risk check is performed, a safety envelope may refer to an allowable collision risk.

[0100] The risk assessment can include an examination of an estimated result of the collision risk between vehicle 1 and the surrounding object. The collision risk can include a collision risk over time and can include a peak collision risk. The collision risk can be expressed as a probability of collision. This means that uncertainty can be taken into account in the risk assessment.

[0101] If the safety envelope is violated, the situation check unit 28 determines that a situation is a hazardous situation as a test objective. When the situation check unit 28 performs the risk check, it can compare the estimated collision risk value with a threshold of permissible collision risk. If the estimated collision risk value is below the threshold of permissible collision risk, the situation check unit 28 can determine that the situation is a safe situation as a test objective. If the estimated collision risk value exceeds the threshold of permissible collision risk, the situation check unit 28 can determine that the situation is a hazardous situation as a test objective. That is, if there is no violation of the safety envelope, the situation check unit 28 determines that the situation is a safe situation as a test objective.This risk threshold can be, for example, a longitudinal safety distance and a lateral safety distance.

[0102] The situation assessment unit 28 can establish a hypothesis about the environmental object and assess a risk based on that hypothesis. Multiple hypotheses can be used in this case. The hypothesis can be or include an assumption about reasonably predictable behavior. The hypothesis can be a prediction derived from this assumption, and can include the prediction derived from this assumption.

[0103] This means that there is a possibility that an assumed kinematic value is influenced by an acceptable risk level. The acceptable risk level or risk threshold can be determined in advance by at least one of the bodies, government agency, standards body, and approval organization of the driving system 2. The acceptable risk level or risk threshold can also be determined in advance by a developer of the driving system 2.

[0104] Situation Check Unit 28 can refer to a rule set stored in rule database 58 to determine the permissible risk level. Situation Check Unit 28 can improve the estimation accuracy by incorporating the rules of the rule set into an algorithm for calculating the risk value.

[0105] Fig. Figure 10 presents an example of a processing procedure for deriving and defining an assumption. This process is implemented, for example, by the execution of a program stored in memory 53a by processor 53b of RSS unit 53. A series of processes in steps S11 to S15 is executed for each predetermined regular time interval or based on a predetermined trigger. The predetermined trigger can be, for example, the latest situation data provided to situation check unit 28 by situation extraction unit 27.

[0106] In the first step, S11, a scenario is specified into which vehicle 1 is currently entering. Specifying the scenario can, for example, involve selecting one from a catalog of scenarios stored in scenario database 59. One scenario can be selected. Multiple scenarios can be selected. A more complex situation can be represented by combining multiple scenarios. After the process in S11, the process proceeds to S12.

[0107] S12 to S15 are iterative processes for each scenario. In S12, a relevant scene and a road user are specified and described in detail as dynamic elements. After the process in S12, the process continues to S13.

[0108] S13 to S15 are iteration processes for each road user. In S13, kinematic properties responsible for a road user's movement are specified. After the process in S13, the process continues to S14.

[0109] S14 to S15 are iterative processes for each kinematic property. In S14, based on the scenarios specified in S11, it is assessed whether the kinematic properties are safety-relevant. This assessment is performed by checking whether there is a possibility that a particular property could cause a movement of another road user, which is a movement for vehicle 1. If the kinematic property is not safety-relevant, it is excluded from the application of the scenario specified in S11. After the process in S14, the process continues to S15.

[0110] In S15, an assumption about the reasonably predictable behavior of the other road user is generated for the scenarios specified in S11. This assumption can be defined by establishing a boundary line within which the behavior of the other road user in a specific driving situation can fall within a reasonably predictable range. After the process in S15, the process is looped back to S12, S13, and S14 and repeated, depending on the remaining processing state of the other scenario, the road user, and the kinematic properties. Once the process is complete for all scenarios, the sequence of processes ends.

[0111] The assumption can be a function of time that changes during a specified scenario. Alternatively, the assumption can remain unchanged during the specified scenario. A minimal set of assumptions about the other road user can be defined.

[0112] The minimum set can include one or more properties according to a scenario, under a reasonably foreseeable maximum assumed longitudinal speed that other road users might exhibit, a reasonably foreseeable maximum assumed lateral speed that other road users might exhibit, a reasonably foreseeable maximum assumed longitudinal acceleration that other road users ahead of the vehicle might exhibit, a reasonably foreseeable maximum assumed lateral acceleration that other road users might exhibit, a reasonably foreseeable minimum assumed longitudinal deceleration that other road users traveling in the opposite direction to or following the vehicle might exhibit, and a reasonably foreseeable minimum assumed lateral deceleration that other road users might exhibit.a reasonably foreseeable maximum assumed direction of travel angle that other road users could indicate, a reasonably foreseeable maximum assumed rate of change in the direction of travel angle that other road users could indicate, a reasonably foreseeable maximum assumed longitudinal position sway that other road users could indicate, and a reasonably foreseeable maximum assumed reaction time that other road users could indicate.

[0113] The values ​​of these assumptions can differ depending on the road user category. For example, an assumption value can be modified depending on whether the road user is a vulnerable road user (VRU). The assumption value can be adjusted based on at least one of the following factors: different road surface conditions and weather-related environmental conditions reasonably expected within an operating area. The assumption value can also be adjusted based on at least one of the following differences: differences in road traffic law for each country and differences in driving habits for each region.

[0114] The reaction unit 29 derives a suitable reaction based on a test result from the situation check unit 28. The suitable reaction can only be provided to the action unit 30 if it is determined that the situation is hazardous. The suitable reaction may be a limitation of a control command of the motion actuator 60. The suitable reaction may be a reaction to return the vehicle 1 to a safe state. Even if several unrelated hazardous situations are checked, the actions to be taken by the vehicle 1 must be integrated into a single action. Consequently, in this case, the reaction unit 29 resolves any potential conflict between the suitable reactions for these situations and transmits the suitable reaction to the action unit 30.

[0115] Furthermore, the RSS 26 can sequentially store at least one of the following—data characterizing the situation, the result of an assessment of the situation, and a derived appropriate response—in the storage medium 55c using the recording device 55 or the like. The RSS 26 can transmit at least one of the following—data characterizing the situation, the result of an assessment of the situation, and a derived appropriate response—to the external system 96 using the communication system 43 and accumulate at least one of the above in a storage medium 96a of the external system 96.

[0116] Furthermore, RSS 26 can execute an output in a prioritized manner to maintain due care for other road users. RSS 26 can also support an emergency maneuver. The emergency maneuver can be a minimum risk maneuver (MRM) or a DDT fallback / substitute plan. The emergency maneuver can be executed when the appropriate response to a potentially hazardous situation does not sufficiently reduce the risk if the hazardous situation actually occurs.

[0117] Furthermore, RSS 26 can distinguish between an initiator of a hazardous scenario and a responder of a hazardous scenario. RSS 26 can differentiate between an action recommended for the initiator and an action recommended for the responder. This means that if vehicle 1 is the initiator, RSS 26 derives an appropriate response according to the action recommended for the initiator, and if vehicle 1 is the responder, RSS 26 derives an appropriate response according to the action recommended for the responder. reaction to the passing, moving object

[0118] RSS 26 can assist in responding to a passing, moving object. Typically, a (four-wheeled) motor vehicle (including a so-called passenger car) occupies approximately one lane per width. In contrast, the passing, moving object may be narrower in width than the motor vehicle and may pass the motor vehicle in the same lane.

[0119] In particular, the moving object passing through could be, for example, a motorcycle (car), a bicycle, a small (autonomous) guided vehicle, or a person. The person could be, for example, a pedestrian, a runner, or a scooter rider. This means that the moving object passing through could be a vehicle. The moving object passing through could be a VRU (Vehicle Reconnaissance Unit).

[0120] There are several scenarios in which a response to the passing, moving object should be considered. These scenarios can be stored in scenario database 59 and can be candidates for selection when RSS 26 specifies a scenario.

[0121] The scenario in which a reaction to the passing moving object is to be considered can include a scenario on a motorway, including a highway, and can also include a scenario on a general road. The scenario involving a reaction to the passing moving object can include a scenario with a traffic jam and a scenario without a traffic jam. Typically, it is likely that the passing moving object will occur during a traffic jam. Therefore, during a traffic jam, a motorcycle can be considered the passing moving object. On the other hand, if there is no traffic jam, it can be determined, depending on the situation, whether the passing moving object is the passing moving object.During a non-existent traffic jam, if the motorcycle is traveling in the middle of a lane, there is a possibility that the motorcycle is not the moving object passing through. During a non-existent traffic jam, there is a possibility that a bicycle is the moving object passing through.

[0122] In the Fig. In example 11, vehicle 1 is traveling behind a preceding vehicle OV4 in the same lane LA. Furthermore, in a region near the end of the road, a motorcycle SO1 is traveling in the same direction as vehicle 1 and the preceding vehicle OV4 in the same lane LA. In this scenario, the motorcycle SO1 corresponds to a passing, moving object, and this object also corresponds to a VRU.

[0123] In this scenario, a dynamic element is as follows: Motorcycle SO1 moves longitudinally in front of and / or behind vehicle 1 on the road. A vehicle (the preceding vehicle OV4) also moves longitudinally in front of and / or behind vehicle 1 on the road. This scenario provides scenery with a speed limit sign and no pedestrian crossing. The representation of road users in this scenario is that there is no collision between vehicle 1 and other road users.

[0124] Situational Analysis Unit 28 of RSS 26 can determine a route DR assumed for the motorcycle SO1. Determining this route DR may be included in an assumption, described above, about reasonably foreseeable behavior of the other road user, or it may be performed as a preliminary process to executing the assumption of that behavior. Determining the route DR may or may not be included in the minimal set of assumptions described above.

[0125] The route DR assumed for motorcycle SO1 can be determined based on reasonably predictable behavior of motorcycle SO1. For example, a distance from the end of the road to the vehicle OV4 ahead in a direction perpendicular to the lane axis direction D1 along the lane axis ALA (lane width direction D2) is defined as d vw defined. If d vw > d threshOnce determined, the situation check unit 28 can virtually define the route DR, which has a width w. This means that if there is a space through which the motorcycle SO1 travels between the preceding vehicle OV1 and the end of the road, it is predicted that the motorcycle SO1 will continue along a trajectory that passes through this space.

[0126] For example, d thresh a sum from the safety distance d min, lat between vehicle 1 and motorcycle SO1, a side width w VRU of the motorcycle SO1 and a distance d to be provided between the motorcycle SO1 and the end of the road, which is designed in the form of a wall surface. VRU, wall be, as it is in expression 15 in Fig. It is marked 12.

[0127] For example, d thresh be determined as stated in expressions 16 to 19 in Fig. 12 is marked. d VRUIn expressions 16 to 19, the distance to be provided between the motorcycle SO1, which is a VRU, and the end of the road is a value that is suitably determined depending on the road shape and other surroundings. In expression 17, d ego A parameter that is defined according to the type of vehicle 1. For example, if vehicle 1 is a large vehicle, such as a truck, a larger value is assigned than if vehicle 1 is a small vehicle. In expression 18, d (v ego, lat ) a parameter that is determined according to a longitudinal speed of vehicle 1. In expression 19, d (v VRU, lat ) a parameter that is determined according to a longitudinal speed of the motorcycle SO1, which is the VRU.

[0128] The assumed width w of the route DR can be determined by subtracting d. min, lat from d vw calculated as shown in expression 20 in Fig. Expression 20 can be applied if expressions 15 and 16 are assumed. The width w can be specified as in expressions 21 to 23 in Fig. Expression 21 is marked 13. Expression 21 can be applied if expression 17 is accepted. Expression 22 can be applied if expression 18 is accepted. Expression 23 can be applied if expression 19 is accepted.

[0129] Furthermore, the width w need not be a constant value, but can vary depending on the longitudinal position. For example, the width w of the space on the side of vehicle 1 can differ from the width w of the space on the side of the preceding vehicle OV1.

[0130] The assumed route DR can be treated as a region occupied by the trajectory of motorcycle SO1. The assumed route DR can be treated as a lane separate from lane LA, in which vehicle 1 is traveling. This allows vehicle 1 and motorcycle SO1 to be treated as traveling in separate lanes when assessing the collision risk. Therefore, since vehicle 1 is traveling in the current lane LA along the lane axis ALA, a longitudinal risk assessment between vehicle 1 and motorcycle SO1, that is, a longitudinal safety distance assessment, can be omitted or simplified. In other words, a detailed longitudinal determination can be omitted or simplified when assessing a hazardous situation. This means that the amount orThe size of the calculation process in RSS unit 53 can be reduced, and as a result, a delay in the calculation process can be reduced or a load on a hardware resource can be reduced.

[0131] Simplifying the longitudinal safety distance check can be a simplification of the longitudinal safety distance check of the other road user, who is treated as traveling in the same lane. For example, simplifying the longitudinal safety distance check can mean using an approximate or assumed value for part or all of a substitute value of a parameter, such as acceleration, reaction time, or the like, in the calculation of the safety distance indicated in expressions 1 to 4, instead of an exact value detected or perceived by sensors 41 and 42 or obtained through V2X communication. For example, the assumed value can be obtained by referring to a value stored in a database or table stored on a storage medium, such as memory 53a.Simplifying the longitudinal safety distance check can mean simplifying the expression itself used to calculate the safety distance, for example by changing some variables to constants.

[0132] In the Fig. In the example shown in Figure 14, the route DR of a moving object passing through a two-lane road is defined. This means that a region occupied by the trajectory of the motorcycle SO1 is defined along a dividing line that separates the two lanes LA1 and LA2 in the same direction. The situation check unit 28 can virtually define the route DR, which has a width w, if d vvdefined as a distance between other vehicles OV5 and OV6 traveling parallel to each other in one direction (lane width direction D2), perpendicular to the lane axis direction D1 along the lane axis ALA, and d vv > d thresh is determined.

[0133] In this example, for instance, d thresh be determined as stated in expressions 24 to 26 in Fig. 15 is marked. In expression 25, d ego a parameter that is suitably determined according to the type of each vehicle on lane LA1, in which vehicle 1 is located, and the two lanes LA1 and LA2. In expression 25, “d other “A parameter that is determined according to the type of each vehicle on lane LA2, in which vehicle 1 is not present, of the two lanes LA1 and LA2. In expression 26, d(v ego) a parameter that is determined according to the speed of the vehicle in lane LA1. In expression 26, d(v other ) a parameter that is determined according to the speed of the vehicle in lane LA2. In expression 26, d(v VRU ) a parameter that is set according to the speed of a motorcycle SO2, which is a VRU.

[0134] In the Fig. In the example shown in Figure 16, the route DR of a passing, moving object across the oncoming lanes LA1 and LA2 on a single-lane road is defined. A scenario in which a passing, moving object (for example, a motorcycle SO3) travels between the oncoming lanes LA1 and LA2 can be immediately determined as a potentially hazardous situation or a hazardous situation if each vehicle in each lane LA1 and LA2 is traveling at or above a certain speed. Meanwhile, in a situation where both lanes LA1 and LA2 are in a traffic jam and the vehicles in both lanes LA1 and LA2 are stopped or traveling at an ultra-low speed, the situation can be determined to be non-hazardous.In this case, the route DR can be set for the passing, moving object.

[0135] In the Fig. In example 17, a motorcycle SO4 is traveling as a passing, moving object on a two-lane road across the two lanes LA1 and LA2, and the vehicles OV7 and OV8 are in front of the motorcycle SO4 near a dividing line between the two lanes, and there is no room to pass. For example, it is assumed that there is room to pass at one end of the road in a region in front of the motorcycle SO4.

[0136] A first route, DR1, can be defined such that it includes a space for passage across the two lanes LA1 and LA2, where the motorcycle SO4 is currently located. A second route, DR2, can be defined such that it includes a space for passage located at one end of the road in front of the motorcycle SO4. The first route, DR1, and the second route, DR2, can be regions occupied exclusively by a trajectory of the motorcycle SO4. For the motorcycle SO4 to move from the first route, DR1, to the second route, DR2, it is necessary for the motorcycle SO4 to pass through a trajectory that includes lane LA1 (a dashed line segment TR in the Fig. 17) crosses in front of vehicle 1. In other words, it is predicted that the motorcycle SO4 will move from the first route DR1 to the second route DR2, which passes through the trajectory that crosses lane LA1.

[0137] While motorcycle SO4 is crossing lane LA1, vehicle 1 and motorcycle SO4 may overlap longitudinally, potentially leading to a collision. During this time, a longitudinal risk assessment, i.e., a longitudinal safety distance assessment, is performed between vehicle 1 and motorcycle SO4. In this way, the passing, moving object may move in a direction that does not necessarily correspond to the actual lane. RSS 26 of the existing embodiment reflects the directional flexibility of other road users when determining the route DR.

[0138] In the Fig. In the example shown in Figure 18, vehicle 1 attempts to turn left from its current lane LA and, for example, head towards a parking space at the side of the road. There is no sidewalk between the parking space and lane LA. There are finite areas SR1 and SR2 in front of and behind vehicle 1, respectively, which can each be detected by sensors. These areas can encompass both a finite angular range and a finite distance range. These areas SR1 and SR2 can be defined, for example, within an operational area. A following vehicle OV9 is behind vehicle 1, and vehicle 1's view is limited by the following vehicle OV9. Due to this limited view, a blinding area OA is formed on both sides of the following vehicle OV9.

[0139] RSS 26 assumes that there is a possibility that virtual objects SO5 and SO6 appear as passing, moving objects from at least one of the areas, area excluding areas SR1 and SR2 that can be detected by the sensors, and obscured area OA. In the example in Fig. 18. In particular, it is assumed that a passing, moving object, such as a motorcycle, bicycle, pedestrian, or the like, is present outside the area SR1 that can be detected by the sensor, in front of vehicle 1, and may appear within the area SR1 at any time. At that time, assuming that vehicle 1 is visible to the virtual object SO5, it is assumed that the virtual object SO5 is moving laterally (or in the lane width direction D2) away from vehicle 1 along a road end within lane LA in order to avoid a collision with vehicle 1.

[0140] Behind vehicle 1, it is assumed that a passing, moving object, such as a motorcycle, a bicycle, a pedestrian or the like, is present in the obscured area OA and may appear behind vehicle 1 at any time within the area SR2 that can be detected by the sensor.

[0141] The kinematic properties of these virtual objects SO5 and SO6 can be determined based on the predicted, reasonably foreseeable behavior of another road user who is actually perceived. This means that the virtual objects SO5 and SO6, together with the other road user who is actually present in the sequence of processes S11 to S15, can be determined. Fig. 10 are perceived and can be processed.

[0142] It is assumed that the trajectories along which the travel of these virtual objects SO5 and SO6 is predicted are within the same lane LA as vehicle 1. In a region occupied by the trajectory, the travel route DR is determined for the passing, moving object. RSS 26 also supports the handling of a collision risk between the virtual objects SO5 and SO6 and vehicle 1. The travel routes DR assumed for these virtual objects SO5 and SO6 can be treated as a lane separate from the lane LA in which vehicle 1 is traveling. Therefore, a longitudinal risk check between vehicle 1 and these virtual objects SO5 and SO6, that is, a longitudinal safety distance check, can be omitted or simplified.

[0143] In the Fig. In example 19, a sidewalk SW is provided at the edge of the roadway of lane LA, in which vehicle 1 is traveling. Meanwhile, the sidewalk SW in front of vehicle 1 is blocked by an obstacle OO. The obstacle OO could be, for example, a parked car or a mass of snow accumulated on a road by snow removal.

[0144] RSS 26 assumes that a moving object enters lane LA from sidewalk SW to avoid obstruction OO. This moving object can be a pedestrian SO7. Trajectories along which pedestrian SO7 is predicted to walk within lane LA are assumed to be within the same lane LA as vehicle 1. A passage PR for the moving object is defined in a region occupied by the trajectory. RSS 26 also supports the risk of collision between pedestrian SO7 and vehicle 1. The passage PR assumed for pedestrian SO7 can be treated as a lane separate from lane LA, in which vehicle 1 is traveling.Therefore, a longitudinal risk assessment between vehicle 1 and these pedestrians SO7, i.e., a longitudinal safety distance assessment, can be omitted or simplified.

[0145] The results processed by RSS 26 regarding the passing, moving object can be displayed. Driving system 2 (for example, action unit 30 and HMI output unit 33) can display the assumed behavior of the road user near vehicle 1 on various information presentation devices in an overhead view mode, providing an overview of the proximity of vehicle 1. Driving system 2 (for example, action unit 30 and HMI output unit 33) can overlay the assumed passing, moving object onto an image that simulates the shape of the road near vehicle 1 and display the result on the information presentation device.Furthermore, the driving system 2 (for example, the action unit 30 and the HMI output unit 33) can overlay the defined route DR or the passage PR of the moving object on this image and display the result on the information presentation device.

[0146] Furthermore, the driving system 2 (for example, the action unit 30 and the HMI output unit 33) can display at least one of the parameters, longitudinal position, longitudinal velocity, longitudinal acceleration, longitudinal deceleration, lateral position, lateral velocity, lateral acceleration and lateral deceleration, which is assumed for the moving object passing through or walking along the route DR or the passage PR, in conjunction with the route DR or the passage PR on the information presentation device.If a virtual, passing, moving object is assumed, the driving system 2 (for example, the action unit 30 and the HMI output unit 33) can display at least one of the parameters, longitudinal position, longitudinal velocity, longitudinal acceleration, longitudinal deceleration, lateral position, lateral velocity, lateral acceleration and lateral deceleration, assumed for the virtual, passing or walking, moving object, in conjunction with the driving route DR or the passage PR on the information presentation device.

[0147] The virtual, passing, moving object can be displayed in a display mode to distinguish it from the passing, moving object actually detected by the detection unit 10. For example, the virtual, passing, moving object can be displayed in at least one of the following display modes: lower luminance mode, lower chromaticity mode, and higher transmittance mode for a scene (for example, a transparent display) compared to an actually detected passing, moving object. The virtual, passing, moving object can be distinguished from the actually detected passing, moving object by being displayed in a flashing manner.

[0148] The result of the process by the RSS 26 with respect to the passing, moving object can be generated and recorded as data. The driving system 2 (for example, the RSS 26 and the action unit 30) can record the assumed behavior for the road user near the vehicle 1 into the storage medium 55c via the recording device 55. The driving system 2 (for example, the RSS 26 and the action unit 30) can record information about the assumed behavior for the passing, moving object into the storage medium 55c via the recording device 55. The driving system 2 (for example, the RSS 26 and the action unit 30) can record information about the determined route DR or the passage PR of the passing, moving object into the storage medium 55c via the recording device 55.

[0149] More precisely, the driving system 2 (for example, the RSS 26 and the action unit 30) can record at least one of the parameters—longitudinal position, longitudinal velocity, longitudinal acceleration, longitudinal deceleration, lateral position, lateral velocity, lateral acceleration, and lateral deceleration—assumed for the moving object traveling or walking along the route DR or passage, in conjunction with the route DR or passage PR, into the storage medium 55c by the recording device 55. If the virtual moving object...If a moving object is assumed to be passing through, the driving system 2 (for example, the RSS 26 and the action unit 30) can record at least one of the parameters assumed for the virtual moving object passing through—longitudinal position, longitudinal velocity, longitudinal acceleration, longitudinal deceleration, lateral position, lateral velocity, lateral acceleration, and lateral deceleration—in conjunction with the route DR or the passage PR through the recording device 55 into the storage medium 55c. A parameter recorded here, such as the longitudinal velocity, can itself contain a minimal set of assumptions about the other road user. Process flow

[0150] Next, an example of a reaction processing procedure for a passing or walking, moving object is given by RSS 26 with reference to Fig. The reaction processing procedure includes a verification procedure. This process is implemented, for example, by the processor 53b of the RSS unit 53 executing a program stored in memory 53a. A series of processes from steps S21 to S26 is executed for each predetermined regular time interval or based on a predetermined trigger.

[0151] In S21, the situation extraction unit 27 obtains situation data from the acquisition unit 10. After the process in S21, the process moves to S22.

[0152] In S22, the situation extraction unit 27 extracts a positional relationship between a road and another vehicle or the like. That is, a situation is extracted. The situation extraction unit 27 also makes an assumption about the passing, moving object. Here, the passing, moving object includes a passing, moving object that is actually perceived by the detection unit 10, and a virtual passing, moving object. After the process in S22, the process continues to S23.

[0153] In S23, the situation extraction unit 27 determines the route DR or the passage PR of the moving, passing object based on a predicted trajectory of the moving, passing object. After the process in S23, the process proceeds to S24.

[0154] In S24, the situation check unit 28 assesses the risk to the moving object passing through. This risk assessment can be omitted or simplified by treating the defined route DR or the defined passage PR as a lane separate from vehicle 1. After the process in S24, the process proceeds to S25.

[0155] In S25, the situation assessment unit 28 determines whether the risk perceived by the passing, moving object is permissible. If the determination result is yes, the sequence of processes is terminated. If the determination result is no, the process proceeds to S26.

[0156] In S26, reaction unit 29 derives a suitable response to reduce the risk to the moving object passing through. Reaction unit 29 outputs the derived suitable response to action unit 30. After the process in S26, the sequence of processes is terminated.

[0157] In the first embodiment described above, a region occupied by the trajectory of a moving object traveling through lanes LA and LA1, in which vehicle 1 is present, is treated as a separate lane, distinct from lanes LA and LA1, in a risk assessment. This allows for the appropriate processing of predicted behavior of the passing moving object while reducing the load on processor 53b caused by processing a situation where many moving objects are in the traffic jam in the same lane. It is thus possible to reduce the frequency of excessive reactions by vehicle 1 that might result from the risk assessment.In this way, when checking for a collision risk with the moving object traveling through lanes LA and LA1, the validity of a handling procedure for the moving object can be improved.

[0158] In the first embodiment, even if the moving object is assumed to be within lanes LA and LA1 where vehicle 1 is located, the region occupied by its trajectory is treated as a separate lane during the risk assessment. This eliminates or simplifies the longitudinal safety distance check between vehicle 1 and the moving object. Such an omission or simplification can reliably reduce the load on processor 53b. It avoids a situation where vehicle 1 performs an unnecessary delay response at a specific timing point when the vehicle-to-vehicle longitudinal distance becomes extremely small, which can inevitably occur during passage.

[0159] In the first embodiment, a virtual, moving object is assumed to exist in the obscured area OA, generated due to the limited visibility of vehicle 1. This makes it possible to predict the risk of a collision with the moving object passing through, which is not actually visible to vehicle 1, at an early stage.

[0160] In the first embodiment, it is assumed that the virtual, moving object is outside an area that can be detected by a sensor provided on the vehicle 1. This makes it possible to predict a collision risk with the passing, moving object, which is not actually visible to the vehicle 1, at an early stage.

[0161] In the first embodiment, if a moving object is assumed to be passing through an end section of lanes LA and LA1 where vehicle 1 is located, and if the distance in the lane width direction D2 between the end section and vehicle 1 or another moving object is greater than a predetermined distance, the virtual trajectory DR assumed for the moving object is defined. This DR is a region of predetermined width that is treated as a lane separate from lanes LA and LA1 where vehicle 1 is located. That is, a trajectory is predicted depending on whether there is a space through which the moving object can pass. Therefore, the validity of handling the moving object can be improved. Second embodiment

[0162] As it is in Fig. Figure 21 shows a second embodiment, a modification example of the first embodiment. The second embodiment is described with a focus on a difference from the first embodiment.

[0163] In the second embodiment, an RSS with a specialized risk assessment function can be installed without deriving a suitable response. In this example, a risk assessment unit 126 can be configured as a functional block in the driving system 2, separate from the detection unit 10, the planning unit 120, and the action unit 130.

[0164] The risk assessment unit 126 obtains situational data from the detection unit 10. The risk assessment unit 126 extracts a situation from the situational data and assumes a safety-related object. This object can include at least one of the following: moving objects, a moving object actually detected by the detection unit 10, and a virtual moving object.

[0165] The risk assessment unit 126 checks for a risk to the assumed object and outputs a test result to the planning unit 20. To check the risk here, an RSS model 127, which is implemented in the risk assessment unit 126, for example, in the form of a program, can be used. The risk assessment can be carried out in the same way as in the first embodiment. The test result can include a determination of whether the risk is permissible. The test result can include a numerical value for a safety envelope or a safety distance, which is used by the RSS model 127 in its calculation.

[0166] Planning unit 120 plans the driving of vehicle 1 according to the test result obtained by risk assessment unit 126. Planning unit 120 can make an overarching determination based on the situation data obtained by acquisition unit 10 and the test result to plan the driving of vehicle 1. Alternatively, planning unit 120 can plan the driving of vehicle 1 based on the situation data obtained by acquisition unit 10 and modify the plan if risk assessment unit 126 notifies it of the presence of an impermissible risk. Action unit 130 does not need to apply any restriction of the RSS, but simply implements a trajectory plan obtained by planning unit 120 through motion actuator 60 as is.

[0167] In the second embodiment, the risk assessment unit 126 can be implemented by the RSS unit 53 in the same way as in the first embodiment. The risk assessment unit 126 can be implemented by the dedicated computer 51 of the processing system 50. The hardware that implements the function of the risk assessment unit 126 corresponds to a test device. Third embodiment

[0168] As it is in Fig. Figure 22 shows a third embodiment, a modification example of the first embodiment. The third embodiment is described with a focus on a difference from the first embodiment.

[0169] In the third embodiment, an RSS can be specifically mounted for a recording function, and not for use in deriving a driving and action of the vehicle 1, for use in subsequent verification and a validity check of the driving system 2. In this example, a risk assessment unit 226 and a recording unit 228 can be configured as functional blocks in the driving system 2, separate from the acquisition unit 10, the planning unit 220, and the action unit 230.

[0170] The risk assessment unit 226 obtains situational data from the acquisition unit 10. The risk assessment unit 226 assumes a safety-related object and performs a risk assessment using the RSS model 227 in the same manner as in the second embodiment. The risk assessment unit 226 provides an assessment result to the recording unit 228.

[0171] The recording unit 228 organizes the processing result by the planning unit 220 and the test result by the risk assessment unit 226 and performs a recording sequentially or periodically. The recording can be on the onboard storage medium 55c. The recording can be off-board, that is, on the storage medium 96a of the external system 96, by transmitting the recording data through the communication system 43.

[0172] The recording unit 228 can generate data that conforms to the data format of a data storage system for automated driving (DSSAD) if the processing result is organized by the planning unit 220 and the verification result by the risk verification unit 226. If the DSSAD data format does not support recording the risk verification result, an extended data format suitable for recording the risk verification result can be used. Alternatively, if the DSSAD data format does not support recording the risk verification result, the risk verification result can be generated as separate, dedicated data.

[0173] In the third embodiment, the risk assessment unit 226 can be implemented by the RSS unit 53 in the same way as in the first embodiment. The risk assessment unit 226 can be implemented by the dedicated computer 51 of the processing system 50. The hardware that implements the function of the risk assessment unit 226 corresponds to a test device.

[0174] A in Fig. The setup shown in Figure 22 can be used for a simulation in a prior verification and validity check of the driving system 2. In this case, the hardware that makes up the setup in Figure 22 must be used for a simulation in a prior verification and validity check of the driving system 2. Fig. 22 is implemented, but not installed in vehicle 1. This means that all processes can be executed on a computer for simulation. In this case, the simulation computer corresponds to an external testing facility. Such a simulation can be performed publicly by a certification body that certifies the driving system 2. Fourth embodiment

[0175] A fourth embodiment is a modification example of the first embodiment. The fourth embodiment is described with a focus on one difference from the first embodiment.

[0176] In the fourth embodiment, an algorithm of a state transition for vehicle 1 in response to a passing, moving object treats the passing, moving object as if it were traveling on a separate lane, thereby reducing the frequent occurrence of excessive reactions by vehicle 1.

[0177] As it is in Fig. Figure 23 shows the state transition of vehicle 1, which is used to calculate the appropriate response. Four states transition into one another: safe M1, laterally in danger M2, longitudinally in danger M3, and in danger in both (i.e., laterally and longitudinally) M4. Longitudinal response M5, longitudinal stop M6, lateral response M7, and lateral stop M8 are states after the execution of an appropriate response, which includes braking, has been initiated.

[0178] States M1 to M4 can transition into one another, based on a longitudinal safety distance and a lateral safety distance. Specifically, if the current longitudinal distance to another road user (hereinafter referred to as the current longitudinal distance) is greater than the longitudinal safety distance, and the current lateral distance to the other road user (hereinafter referred to as the current lateral distance) is greater than the lateral safety distance, the state is safe (M1). If the current longitudinal distance is greater than the longitudinal safety distance and the current lateral distance is equal to or less than the lateral safety distance, the state is laterally at risk (M2). If the current longitudinal distance is equal to or less than the longitudinal safety distance and the current lateral distance is greater than the lateral safety distance, the state is longitudinally at risk (M3).If the current longitudinal distance is equal to or less than the longitudinal safety distance, and the current lateral distance is equal to or less than the lateral safety distance, the condition in both is hazardous (M4). The state transitions described here are state transitions for the other road user in a separate lane (for example, an adjacent lane).

[0179] In other words, safety M1 is a state in which the risk of collision between vehicle 1 and the other road user is lower than a preset threshold in both the longitudinal and lateral directions. Lateral danger M2 is a state in which the risk of a longitudinal collision is lower than a preset threshold and the risk of a side collision is higher than a preset threshold. Longitudinal danger M3 is a state in which the risk of a side collision is lower than the preset threshold and the risk of a longitudinal collision is higher than the preset threshold. Both danger M4 is a state in which the risk of collision is higher than the preset threshold in both the longitudinal and lateral directions.

[0180] The transition from both dangerous states M4 to longitudinal response M5 and lateral response M6 occurs when a condition for transition to each of the states M5 and M6 is specified. For example, if the elapse time of a dangerous longitudinal state is equal to or longer than the elapse time of a dangerous lateral state and is longer than a reaction time, the state transitions to longitudinal response M5 and an appropriate response, including braking, is initiated. Similarly, if the elapse time of a dangerous lateral state is equal to or longer than the elapse time of a dangerous longitudinal state and is longer than a reaction time, the state transitions to lateral response M7 and an appropriate response, including braking, is initiated.

[0181] If, during longitudinal response M5, the current longitudinal distance is restored to a state where it is longer than the longitudinal safety distance, the state becomes laterally in danger M2. If, during longitudinal response M5, a determination for a longitudinal stop is executed and it is determined that the vehicle should be stopped, the state becomes longitudinal stop M6. If the vehicle 1 is stopped and the current longitudinal distance is restored to a state where it is longer than the longitudinal safety distance, the state becomes laterally in danger M2.

[0182] If, during the side response M7, the current lateral distance is returned to a state where it is greater than the lateral safety distance, the state becomes longitudinally in danger M3. If, during the side response M7, a determination for a side stop is executed and it is determined that the vehicle should be stopped, the state becomes side stop M8. If, due to a side stop of vehicle 1 (for example, stopping a lane change or the like), the current lateral distance is returned to a state where it is greater than the lateral safety distance, the state becomes longitudinally in danger M3.

[0183] This means that the transition to the longitudinal stop M6 and the lateral stop M8 can correspond to a DDT replacement plan. The stop determination, such as the determination for a longitudinal stop and the determination for a lateral stop, can be carried out by planning unit 20 instead of RSS 26.

[0184] Next, a state transition for another road user traveling in the same lane as vehicle 1 is described, which differs from a state transition for the other road user in a separate lane (for example, an adjacent lane). When the other road user is traveling in the same lane as vehicle 1, a lateral state is always considered unsafe, i.e., dangerous, regardless of the ratio between the current lateral distance and the lateral safety distance. Therefore, vehicle 1 essentially transitions between two states: laterally dangerous (M2) and both dangerous (M4), passing through states M1 to M4, in which a suitable reaction, including braking, is not performed.

[0185] Therefore, if a passing moving object traveling in the same lane as vehicle 1 is treated as traveling in the same lane, the condition will definitely become dangerous in both situations (M4) when it travels side-by-side, overtakes, or is overtaken. Consequently, not only does the calculation of the transition conditions to the side-to-side response (M7) and the side-to-side response (M9) frequently occur, but also the execution of an appropriate response, which includes braking. Therefore, RSS 26 avoids such a situation by treating the passing moving object as if it were traveling in a separate lane. In this case, a region occupied by a trajectory of the passing moving object may or may not be designated as the separate lane (DR).

[0186] With the fourth embodiment described above, if a collision risk is determined to be a hazardous condition in both the longitudinal and lateral directions, it is determined whether an appropriate response, including braking, is required. Even if it is assumed that a passing, moving object is located in a lane occupied by vehicle 1, a region occupied by a trajectory is treated as a separate lane, thus reducing the possibility of the condition being determined to be hazardous in both the longitudinal and lateral directions. Therefore, it is possible to reduce the frequency of excessive reactions to the passing, moving object.

[0187] In the fourth embodiment, for another road user in a separate lane, apart from the lane in which vehicle 1 is located, it is determined that the lateral direction is in a dangerous state when a predetermined condition is met. Conversely, for another road user in the same lane as the lane in which vehicle 1 is located, a collision risk is assessed using an algorithm that determines the dangerous lateral state. By treating the passing, moving object as being in a separate lane, it is possible to avoid an unconditional determination that the lateral direction is in a dangerous state. In this way, it is possible to reduce the frequent occurrence of excessive reactions to the passing, moving object.

[0188] In the fourth embodiment, a condition for determining the collision risk with respect to a passing, moving object is a condition that determines that the collision risk is lower, in the same way as for another road user present in a lane separate from the vehicle. Consequently, since the possibility of determining that the collision risk is higher than a preset threshold is reduced, it becomes difficult to reach a situation where an appropriate response, including braking, is required. Therefore, it is possible to reduce the frequency of excessive reactions to the passing, moving object. In this way, when checking the collision risk with the moving object passing through a lane, the validity for the moving object can be improved.

[0189] The fourth embodiment assesses both a longitudinal collision risk and a side collision risk. The determination of whether an appropriate response is required is made when the collision risk is found to exceed a preset threshold in both the longitudinal and lateral directions. Furthermore, a condition for determining the side collision risk is modified between the longitudinal and lateral directions depending on how the other road user handles the lane.

[0190] The handling of the lane of the passing, moving object is such that, even if the passing, moving object is present in the lane in which vehicle 1 is present, for the purpose of determining the side-collision risk, the passing, moving object is treated as being in a separate lane apart from the lane in which vehicle 1 is present. Therefore, it is possible to reduce the frequency of excessive reactions to the passing, moving object.

[0191] In the fourth embodiment, if the other road user is in a lane separate from vehicle 1, a condition for determining the side-collision risk is whether the lateral distance between vehicle 1 and the other road user is greater than the lateral safety distance. Conversely, if the other road user is in the same lane as vehicle 1, the side-collision risk is determined to be higher than a preset threshold. After modifying the conditions in this way, the passing, moving object is treated as being in a separate lane from the lane in which vehicle 1 is located, thus reducing the frequency of excessive reactions to the passing, moving object. Other embodiments

[0192] Although several embodiments are described above, the present disclosure is not to be construed as being limited to these embodiments and may be applied to various embodiments and combinations within a scope that does not deviate from the essence of the present disclosure.

[0193] In yet another embodiment, the RSS 26 can improve the accuracy of the assumption of a passing, moving object by using information received by the communication system 43 via V2X communication from at least one of the transmitters, another vehicle and roadside device. The situation extraction unit 27 can obtain and use at least one of the pieces of information via V2X communication: information about an object outside the areas SR1 and SR2 that can be detected by the sensor, and information about an object in the obscured area OA.

[0194] For example, if information is obtained that a moving object is present outside the areas SR1 and SR2 that can be detected by the sensor and in the obscured area OA, the RSS 26 can determine the route DR of the moving object based on the information that the moving object is present. Conversely, if information is obtained that no moving object is present outside the areas SR1 and SR2 that can be detected by the sensor and in the obscured area OA, the RSS 26 must not assume a virtual moving object in the area where no moving object is present.

[0195] In yet another embodiment, the RSS 26 can also be used in the Fig. 24 scenarios are supported. In one in Fig. In the example shown in Figure 24, vehicle 1 attempts to turn right from its current lane LA1, crossing into the oncoming lane LA2, and head towards a parking space at the side of the road. There is no sidewalk between the parking space and lane LA2. The oncoming lane LA2 is congested. Vehicle 1 attempts to turn right through a gap in the queue of vehicles in the congestion on the oncoming lane LA2. In front of vehicle 1, there is a finite area SR1 that can be detected by a sensor. This area SR1 can encompass both a finite angular range and a finite distance range.On the oncoming lane LA2, a stopped oncoming vehicle OV10 is present in the area SR1 that can be detected by the sensor, and the oncoming vehicle OV10 restricts the field of vision of vehicle 1. Due to this restricted field of vision, the obscured area OA is formed on the opposite side of vehicle 1, over the oncoming vehicle OV10.

[0196] RSS 26 assumes that there is a possibility that another road user may emerge from the obscured area OA. In the example in Fig. 24. In particular, it is assumed that a virtual object SO8, such as a motorcycle, bicycle, pedestrian, or other moving object passing through, is present in the obscured area OA and may appear at any time within the area SR1, which can be detected by a sensor, on the rear of vehicle 1. A trajectory along which the travel of the virtual object SO8 is predicted is assumed to be within the oncoming lane LA2. Within a region occupied by the trajectory, the travel route DR of the virtual object SO8 is determined. RSS 26 also assists in the event of a collision risk between the virtual object SO8 and vehicle 1.

[0197] In yet another embodiment, the RSS 26 can also be applied to a Fig. The RSS 26 can react to the scenario depicted in section 25. In this scenario, vehicle 1 is traveling behind a large vehicle OV11, which is another large road user, in lane LA. The large vehicle OV11 could be, for example, a truck, a trailer, a bus, or the like. As a result, most of the area SR1 that can be detected by a sensor is blocked in front of vehicle 1, forming the obscured area OA. In this case, the RSS 26 can assume that a virtual object SO9, such as the VRU of a motorcycle or a small vehicle, is traveling further ahead in front of the large vehicle OV11. The RSS 26 can assume the possibility that the virtual object SO9 will emerge from the obscured area OA at any time if the large vehicle OV11 attempts to overtake the virtual object SO9. The RSS 26 can assume that the virtual object SO9 is a passing, moving object, such as a motorcycle.According to such an assumption, RSS 26 can define as the route DR a region occupied by a trajectory assumed for the virtual object SO9 when the large vehicle OV11 overtakes the virtual object SO9.

[0198] In yet another embodiment, the RSS 26 can also be used in a Fig. 26 scenarios are supported. As in Fig. As shown in Figure 26, a passing, moving object is an emergency vehicle (EV). The emergency vehicle (EV) could be, for example, an ambulance, a fire engine, a police car, or the like. For example, it is assumed that while vehicle 1 is traveling in the current lane LA1, the emergency vehicle (EV), traveling in the oncoming lane LA2, weaves between vehicles and crosses lane LA1 to overtake another vehicle (OV12) conducting an emergency evacuation or clearing operation in the same lane LA2. In this case, RSS 26 can treat the emergency vehicle (EV) as a passing, moving object and generate the assumed route DR for the emergency vehicle (EV). This means that RSS 26 can also assist in the event of a collision risk between the emergency vehicle (EV) and vehicle 1.

[0199] In yet another embodiment, the RSS 26 can also be used in a Fig. 27. This scenario is one in which vehicle 1 is on a multi-lane road (for example, a road with three or more lanes in each direction) with one lane free. For example, as shown in Fig. Figure 27 shows vehicle 1 in lane LA1 at one end of a three-lane road. The middle lane LA2 is empty, and another vehicle, OV13, is ahead, while a motorcycle, SO10, is behind in lane LA3 at the other end. Vehicle 1 attempts to change lanes to the middle lane LA2 by activating its turn signal, and motorcycle SO10 also attempts to move laterally toward the middle lane LA2 to overtake vehicle OV13.

[0200] In such a scenario, upon detecting the lane change of vehicle 1, RSS 26 can assume a trajectory for motorcycle SO10 of passing between the preceding vehicle OV13 and vehicle 1 after the lane change. RSS 26 can then determine the route DR for motorcycle SO10 within a region occupied by this trajectory. In this way, RSS 26 can also provide support for a collision risk assumed after vehicle 1 changes lanes.

[0201] When supporting the various scenarios described in the first to third embodiments and other embodiments, it is not necessary, when RSS 26 assumes or determines that another road user is a passing, moving object, to assume the trajectory and define the route DR to treat the passing, moving object as existing in a separate lane. That is, in the various scenarios, the condition for the state transition in the fourth embodiment can be defined under the premise that the passing, moving object exists in a separate lane.

[0202] In yet another embodiment, the generation of the route DR by assuming a moving object passing through it can be achieved using a safety model other than the RSS model. For example, the driving system 2 can implement a safety force field (SFF) model.

[0203] For example, if a stressed set of a moving, passing object is calculated by a spatiotemporal analysis in the SFF model, the driving system 2 can determine the trajectory DR of the moving, passing object. The stressed set can be defined as a spatiotemporal volume between a safety procedure plan and a maximum braking plan. The maximum braking plan can be calculated by using a reasonably predictable longitudinal deceleration assumed to be the minimum.

[0204] Driving system 2 can compute a spacetime claimed by the moving object as an agent by limiting the spacetime to a region of the driving route DR defined for the moving object. This means that by omitting or simplifying the spatiotemporal analysis outside the driving route DR region, the processing load for calculating the claimed set can be reduced.

[0205] In yet another embodiment, the RSS unit 53 can be integrated with the dedicated computer 51. In yet another embodiment, the RSS unit 53 can be provided independently of the processing system 50 and configured to monitor the operation of the processing system 50 externally.

[0206] The in Fig. 11, Fig. 14, Fig. 16 to Fig. 19 and Fig.The 23 scenarios shown are intended to be applied to countries or regions where people drive on the left side of a road, and it is possible to reverse the left and right sides of these scenarios and apply the scenarios to countries or regions where people drive on the right side of a road.

[0207] The processing unit and its method described in this disclosure can be implemented by a specialized computer containing a processor programmed to perform one or more functions carried out by computer programs. Alternatively, the device and its method according to this disclosure can be implemented by a dedicated hardware logic circuit. Alternatively, the device and its method according to this disclosure can be implemented by one or more dedicated computers containing a combination of a processor executing a computer program and one or more hardware logic circuits. The computer program can also be stored on a computer-readable and non-volatile tangible storage medium as an instruction to be executed by a computer. Description of terms

[0208] The following describes terms related to this disclosure. This description is contained in the embodiments of this disclosure.

[0209] A road user can be a person using a road that includes a sidewalk and other adjacent spaces. Road users can include pedestrians, cyclists, other road users, and vehicles (for example, a car driven by a person or a vehicle equipped with an automated driving system).

[0210] A dynamic driving task (DDT) can be a real-time operational function and a strategic real-time function for operating a vehicle in traffic.

[0211] An automated driving system can be a set of hardware and software capable of continuously executing all DDTs, regardless of whether a restriction to a specific operating range exists.

[0212] Safety of the intended functionality (SOTIF) can mean the absence of an unreasonable risk caused by functional inadequacy for an intended function or its implementation.

[0213] A driving policy can be a strategy and a rule that define a control action at a vehicle level.

[0214] A scenario can be a description of the temporal relationships between multiple scenes in a series, including goals and values ​​in a specific situation influenced by actions and events. The scenario can also be a description of successive activities in time series, incorporating a vehicle as a primary object, its entire external environment, and its interactions in the process of performing a specific driving task.

[0215] A triggering condition can be a specific condition of a scenario that acts as a trigger for a response, which is a response of a subsequent system and contributes to an inability to prevent, detect, and reduce dangerous behavior and reasonably foreseeable indirect misuse.

[0216] An appropriate response may be an action that is significant to avoid and improve a dangerous situation in a reasonably foreseeable scenario in which other safety-related objects are operating within an assumption area.

[0217] The operational design domain (ODD) can be a specific condition designed in such a way that a given (automated) driving system functions.

[0218] The safety-related model can be a representation of a safety-related aspect of driving based on assumptions about the reasonably predictable behavior of another road user. Safety-related models can be an onboard or external safety testing or analysis device, a mathematical model, a set of more conceptual rules, a set of scenario-based behaviors, or a combination thereof.

[0219] A formal model can be a model that is represented in a formal representation used for system performance verification.

[0220] A safety envelope can be a set of constraints and conditions designed for an (automated) driving system to act as a target for a constraint or control mechanism to maintain operation at an acceptable level of risk. The safety envelope can be a general concept used to address all the principles upon which driving policy may be based. According to this concept, an ego vehicle, or own vehicle, operated by the (automated) driving system can have one or more boundaries around itself.

[0221] A reaction time can be the time required for the road user to perceive a specific stimulus and initiate a response (braking, steering, accelerating, stopping, or the like) in a given scenario.

[0222] A situation is a factor that can influence the behavior of a system and can include traffic conditions, weather, and the behavior of the ego vehicle or one's own vehicle.

[0223] A dangerous situation can represent an increased risk of a potential breach of the safety envelope and also represents an increased level of risk present in the DDT.

[0224] Reasonably predictable can mean being technically reliable and having a credible or measurable probability of occurrence.

[0225] A vulnerable road user (VRU) can be a road user who is not in a vehicle, such as a car, public transport vehicle, or train. The VRU can be an unprotected road user, such as a motorcyclist, cyclist, pedestrian, or a person with a disability or reduced mobility and orientation.

[0226] A minimum risk maneuver (MRM) can be a function of an automated driving system to transfer a vehicle between a nominal condition and a minimum risk condition (MRC).

[0227] A DDT backup plan can be a response by a driver or an automated system to either execute a DDT or transition to a minimum-risk condition after a failure occurs or upon detection of a functional deficiency or potentially hazardous behavior. The DDT backup plan can be a procedure for transitioning control from autonomous to control by a driver or another system, using takeover / backup plan states and associated use cases. Revelation of technical ideas

[0228] The present disclosure provides several technical features, which are described below. Some points may be written in a multi-dependent form, with subsequent points referring to the preceding point as an alternative. The terms described in the multi-dependent form define several technical ideas. Technical Idea 1

[0229] A test device used for driving a vehicle (1) includes at least one processor (53b). The processor is configured to perform the following: assuming a trajectory along which the movement of a moving object (SO1, SO2, SO3, SO4, SO5, SO6, SO7, SO8, SO9, SO10, EV) passing through a lane (LA, LA1) in which the vehicle is present is predicted, such that the trajectory includes an inside of the lane; and checking for a collision risk between the vehicle and the moving object by treating at least a part of a region (DR, DR1, DR2, TR) occupied or used by the trajectory as a separate lane apart from the lane in which the vehicle is present. Technical Idea 2

[0230] Test device according to technical idea 1, in which the processor is configured to further perform the following: determining whether a suitable reaction, which includes braking, is to be performed when it is determined for the collision risk that both a longitudinal direction and a lateral direction are in a hazardous condition, and in which testing reduces the possibility that it is determined that both the longitudinal direction and the lateral direction are in a hazardous condition by treating the region occupied or claimed by the trajectory as the separate lane, even when it is assumed that the moving object is in the lane in which the vehicle is located. Technical Idea 3

[0231] Test device according to technical idea 2, in which, in the testing for another road user who is present in a separate lane apart from the lane in which the vehicle is present, it is determined without restriction that the lateral direction has the dangerous condition when a predetermined condition is met, and for the other road user who is present in the same lane as the lane in which the vehicle is present, the collision risk is tested using an algorithm that determines that the lateral direction has the dangerous condition. Technical Idea 4

[0232] Test device according to technical idea 1, in which, by treating the region occupied by the trajectory as the separate lane, even if it is assumed that the moving object is on the lane where the vehicle is located, a test of a longitudinal safety distance between the vehicle and the moving object is simplified. Technical Idea 5

[0233] Test device according to technical idea 1, in which, in the testing by treating the region occupied by the trajectory as the separate lane, even if it is assumed that the moving object is on the lane on which the vehicle is located, a test of a longitudinal safety distance between the vehicle and the moving object is omitted. Technical Idea 6

[0234] Test apparatus according to one of technical ideas 1 to 5, in which the moving object is a virtual moving object assumed to be in a hidden area (OA) created due to the limited visibility of the vehicle. Technical Idea 7

[0235] Test apparatus according to one of technical ideas 1 to 5, in which the moving object is a virtual moving object that is outside an area that can be detected by a sensor provided in the vehicle. Technical Idea 8

[0236] Test apparatus according to one of technical ideas 1 to 6, in which further a determination of a virtual route assumed for the moving object is performed, which is the region with a predetermined width, treated as a separate lane apart from the lane in which the vehicle is located, when it is assumed that the moving object is at an end section of the lane in which the vehicle is located and a distance in a lane width direction (D2) between the end section and the vehicle or another moving object is greater than a predetermined distance. Technical Idea 9

[0237] A test device used for driving a vehicle (1) includes at least one processor (53b). The processor is configured to perform: assuming a moving object (SO1, SO2, SO3, SO4, SO5, SO6, SO7, SO8, SO9, SO10, EV) passing through a lane (LA, LA1) in which the vehicle is present; and checking for a collision risk between the vehicle and the moving object by treating the moving object as being in a separate lane apart from the lane in which the vehicle is present, even if the moving object is present in the lane in which the vehicle is present.

[0238] This technical idea makes it possible to improve the validity of handling a moving object traveling through the lane. Technical Idea 10

[0239] A storage medium for storing data relating to the driving of a vehicle (1), which is processed by a driving system (1), stores: information about the behavior of a moving, passing object (SO1, SO2, SO3, SO4, SO5, SO6, SO7, SO8, SO9, SO10, EV) passing through a proximity or environment of the vehicle assumed by the driving system; and information about a region (DR, DR1, DR2, TR) occupied by a trajectory predicted for the passing, moving object, which is determined by the driving system, in association or connection with each other.

[0240] With this technical idea, it is easier for the driving system to verify and check the validity of the assumption about the passing, moving object. Technical Idea 11

[0241] A method for generating vehicle-related data (1) by at least one processor (51b, 53b) comprises: specifying kinematic properties related to the behavior of a passing, moving object (SO1, SO2, SO3, SO4, SO5, SO6, SO7, SO8, SO9, SO10, EV) passing through a proximity or surrounding area of ​​the vehicle; defining a region (DR, DR1, DR2, TR) occupied by a trajectory predicted for the passing, moving object; and generating data in which the kinematic properties and the region are mapped to each other.

[0242] With this technical idea, it is easier for the driving system to verify and check the validity of the assumption about the passing, moving object. Technical Idea 12

[0243] The procedure according to technical idea 9 further includes: storing the data and information about a suitable response, which are calculated by treating the region as a separate lane, in association or connection with each other. Technical Idea 13

[0244] A system for displaying a visual information presentation type using an information presentation device (70) includes: at least one processor (51b). The processor is configured to: cause the information presentation device to display a moving object (SO1, SO2, SO3, SO4, SO5, SO6, SO7, SO8, SO9, SO10, EV) passing through a proximity or surrounding area of ​​the vehicle; and cause the information presentation device to display an image obtained by superimposing a trajectory and a travel route (DR) along which the moving object is predicted to travel onto an image in which the moving object is displayed. Technical Idea 14

[0245] A driving system used to drive a vehicle (1) includes: a sensor (41, 42, 43, 44); a computer (51) that obtains sensor data from the sensor, generates an environment model of the vehicle's proximity or surroundings based on the sensor data, plans the driving of the vehicle using the environment model, and controls a motion actuator (60) of the vehicle based on the plan; and an RSS unit (53) that implements an RSS model and checks for a collision risk of the vehicle.The RSS unit is configured to: obtain the environment model from the computer; assume a trajectory based on the environment model along which it is predicted that a passing moving object (SO1, SO2, SO3, SO4, SO5, SO6, SO7, SO8, SO9, SO10, EV) passing through a lane (LA, LA1) in which the vehicle is present will travel such that the trajectory includes an inside of the lane; check the collision risk between the vehicle and the passing moving object by examining at least a portion of a region (DR, DR1, DR2, TR) occupied by the trajectory.is used as a separate lane apart from the lane in which the vehicle is located; to derive an appropriate response when a collision risk value exceeds a preset risk value; and to generate a request to the vehicle's motion actuator (60) by applying the appropriate response to the plan.

[0246] This technical idea makes it possible to improve the validity of handling a moving object traveling through the lane. Technical Idea 15

[0247] A driving procedure used to drive a vehicle (1) includes: generating an environment model by obtaining sensor data from a sensor (41, 42, 43, 44) of the vehicle; planning the driving of the vehicle using the environment model; assuming, based on the environment model, a trajectory along which it is predicted that a passing moving object (SO1, SO2, SO3, SO4, SO5, SO6, SO7, SO8, SO9, SO10, EV) passing through a lane (LA, LA1) in which the vehicle is present will travel such that the trajectory includes an inside of the lane; checking for a collision risk between the vehicle and the passing moving object by considering at least a portion of a region (DR, DR1, DR2, TR) occupied by the trajectory.is used as a separate lane apart from the lane in which the vehicle is located; deriving an appropriate response when a collision risk value exceeds a preset risk value; generating a request to a motion actuator (60) of the vehicle by applying the appropriate response to the plan; and controlling the motion actuator.

[0248] This technical idea makes it possible to improve the validity of handling a moving object traveling through the lane. Technical Idea 16

[0249] A test device used for driving a vehicle (1) includes: at least one processor (53b). The processor is configured to perform: a check for a collision risk between the vehicle and another road user; a determination of whether to execute an appropriate response, which includes braking, when it is determined that the collision risk is higher than a preset threshold; a modification of a condition for determining the collision risk such that it is determined that the collision risk is higher when the other road user is in the same lane as the vehicle, compared to when the other road user is in a lane separate from the vehicle; a presumption of a moving object (SO1, SO2, SO3, SO4, SO5, SO6, SO7, SO8, SO9, SO10, EV) passing through a lane (LA, LA1) in which the vehicle is present, as the other road user;and a treatment in which the collision risk of the moving object is determined to be in a separate lane apart from the lane in which the vehicle is present, even if the moving object is present in the lane in which the vehicle is present. QUOTES INCLUDED IN THE DESCRIPTION

[0000] This list of documents cited by the applicant was automatically generated and is included solely for the reader's convenience. The list is not part of the German patent or utility model application. The DPMA accepts no liability for any errors or omissions. Cited patent literature

[0000] JP 2023-001415

[0001] US 2021 / 0009121 A

[0004] Cited non-patent literature

[0000] “Safety First for Automated Driving” Tech.Rep., 2019

[0014] On a formal model of safe and scalable self-driving cars", arXiv:1708.06374, 2017.

[0014] S. Shalev-Shwartz, S. Shammah and A. Shashua, contents of “The Safety Force Field” Technical Report, 2019. by David Nister, Hon-Leung Lee, Julia Ng, Yizhou Wang, contents of IEEE 2846-2022

[0014] ISO21217, ETSI TS 102 940-943, IEEE 1609

[0033]

Claims

[1] Test device used for driving a vehicle (1), the test device comprising: at least one processor (53b), where the processor is configured to execute: an assumption of a trajectory along which the movement of a moving object (SO1, SO2, SO3, SO4, SO5, SO6, SO7, SO8, SO9, SO10, EV) passing through a lane (LA, LA1) in which the vehicle is present is predicted, such that the trajectory includes an inside of the lane; and a check for a collision risk between the vehicle and the moving object by treating at least part of a region (DR, DR1, DR2, TR) occupied by the trajectory as a separate lane apart from the lane in which the vehicle is located. [2] Test apparatus according to claim 1, wherein the processor is configured to further perform: a determination of whether an appropriate response, including braking, is to be carried out when the collision risk is determined to have a dangerous condition in both a longitudinal and a lateral direction, and In the examination, the possibility that it will be determined that both the longitudinal and lateral directions exhibit the hazardous condition is reduced by treating the region occupied by the trajectory as the separate lane, even if it is assumed that the moving object is on the lane in which the vehicle is present. [3] Test device according to claim 2, wherein in the testing for another road user who is present in a separate lane apart from the lane in which the vehicle is present it is determined that the lateral direction has the dangerous condition when a predetermined condition is met, and for the other road user who is present in the same lane as the lane in which the vehicle is present, the collision risk is tested using an algorithm that determines that the lateral direction has the dangerous condition. [4] Test device according to claim 1, wherein the testing is simplified by treating the region occupied by the trajectory as the separate lane, even when it is assumed that the moving object is on the lane on which the vehicle is located. [5] Test device according to claim 1, wherein in the testing by treating the region occupied by the trajectory as the separate lane, even if it is assumed that the moving object is on the lane on which the vehicle is present, a test of a longitudinal safety distance between the vehicle and the moving object is omitted. [6] Test apparatus according to claim 1, wherein the moving object is a virtual moving object assumed to be in a hidden area (OA) created due to the limited visibility of the vehicle. [7] Test device according to claim 1, wherein the moving object is a virtual moving object that is outside an area that can be detected by a sensor provided in the vehicle. [8] Test device according to claim 1, further comprising defining a virtual route assumed for the moving object, which is the region with a predetermined width, treated as a separate lane apart from the lane on which the vehicle is located, when it is assumed that the moving object is at an end section of the lane on which the vehicle is located and a distance in a lane width direction (D2) between the end section and the vehicle or another moving object is greater than a predetermined distance. [9] Test procedure for a vehicle collision risk (1) executed by at least one processor (53b), wherein the test procedure comprises: an assumption of a trajectory along which the movement of a moving object (SO1, SO2, SO3, SO4, SO5, SO6, SO7, SO8, SO9, SO10, EV) passing through a lane (LA, LA1) in which the vehicle is present is predicted, such that the trajectory includes an inside of the lane; and a check of the collision risk between the vehicle and the moving object by treating at least part of a region (DR, DR1, DR2, TR) occupied by the trajectory as a separate lane apart from the lane in which the vehicle is located. [10] Test device used for driving a vehicle (1), the test device comprising: at least one processor (53b), where the processor is configured to execute: an assessment of the risk of collision between the vehicle and another road user; Determining whether to execute an appropriate response, which includes braking, when it is determined that the risk of collision is higher than a preset threshold; a change to a condition for determining the collision risk such that it is determined that the collision risk is higher when the other road user is in the same lane as the vehicle than when the other road user is in a lane separate from the vehicle; an assumption that a moving object (SO1, SO2, SO3, SO4, SO5, SO6, SO7, SO8, SO9, SO10, EV) is passing through a lane (LA, LA1) in which the vehicle is present, as the other road user; and a treatment in which determining the collision risk of the moving object as being on a separate lane apart from the lane in which the vehicle is present, even if the moving object is present on the lane in which the vehicle is present. [11] Test device according to claim 10, wherein Checking the collision risk includes checking both the collision risk in a longitudinal direction and the collision risk in a lateral direction. Determining whether the appropriate response should be carried out is performed when it is determined that the collision risk is higher than the preset threshold in both the longitudinal and lateral directions. Changing the condition for determining the collision risk is a change to a condition for determining the collision risk in the lateral direction, and The treatment is a treatment in which the lateral collision risk of the moving object is present on the separate lane apart from the lane in which the vehicle is present, even if the moving object is present on the lane in which the vehicle is present. [12] Test device according to claim 11, wherein in changing the condition for determining the collision risk, If the other road user is present in the lane separate from the vehicle, the condition is modified by setting a condition for determining the lateral collision risk based on whether a lateral distance between the vehicle and the other road user is greater than a lateral safety distance, and If the other road user is present in the same lane as the vehicle, the condition is changed in such a way that it is determined that the risk of collision in the lateral direction is higher than the preset threshold.

Citation Information

Patent Citations

  • JAPANISCHENPATENTANMELDUNGNR.2023-001415

  • Systems, devices, and methods for predictive risk-aware driving

    US20210009121A1