Moving device and program for moving device
The system addresses the inconvenience and safety issues of updating mobility assistance programs by allowing for safe and convenient updates, with notifications to users about any travel disruptions during the update process.
Patent Information
- Application Number
- JP2025042025
- Authority / Receiving Office
- JP · JP
- Patent Type
- Applications
- Current Assignee / Owner
- Filing Date
- 2025-03-17
- Publication Date
- 2025-06-05
- Estimated Expiration
- 2038-10-11
AI Technical Summary
Existing methods for updating mobility assistance programs in vehicles are inconvenient and unsafe, as they often require the vehicle to be stopped, which can disrupt the user's experience and pose safety risks.
A system that includes an update program acquisition means and a program update control means, which allows for the acquisition and execution of updates to mobility assistance programs while ensuring the vehicle remains safe and operational, by notifying users of any inability to start traveling or wait for travel to begin during updates.
The system enables safe and convenient updates of mobility assistance programs, ensuring that users are informed of any disruptions and that the vehicle remains operational, thereby enhancing user experience and safety.
Smart Images

Figure 2025085750000001_ABST
Abstract
Description
[Technical field]
[0001] The present invention relates to a mobile device such as an automobile having a plurality of travel modes such as a manual driving mode and an automatic driving mode, and in particular to updating a software program provided in the mobile device. The present invention also relates to a program for the mobile device provided in the mobile device. [Background technology]
[0002] In recent years, automobiles have been equipped with driving assistance functions such as automatic collision prevention assist systems, cruise control systems, and lane keeping assist systems, making them safer and reducing the burden on the driver. Furthermore, development of fully autonomous vehicles is also underway using autonomous driving assistance functions that enable the vehicle to drive autonomously without the driver having to perform any manual driving operations. The driving assistance functions and autonomous driving assistance functions of such automobiles are executed using software programs (hereinafter referred to as mobility assistance programs).
[0003] Meanwhile, mobility assistance programs are usually updated as needed to correct defects, add new functions, etc. In this case, since it is inconvenient to take the automobile to a dealer each time the mobility assistance program is updated, a method is generally used in which the update program is provided to the automobile from a program update server via the Internet.
[0004] However, the mobile driving support program cannot be updated at any time, and it is dangerous to drive while updating the mobile driving support program during its execution. In view of this, Patent Document 1 (JP Patent Publication 11-259284A) discloses that the program can be updated when the program is not in operation.
[0005] However, when using the invention described in Patent Document 1, the operating status of each program must be determined, which complicates management. In addition, even if the vehicle's driving mode (travel mode) is in a mode in which the travel assistance program can be used, there is a risk that the program will be in the process of being updated when the user wishes to use it, making it unavailable, which is inconvenient.
[0006] As an improvement to this problem, for example, Patent Document 2 (JP Patent Publication No. 2007-230317) discloses that when there is a request to rewrite a mobility support program, the vehicle is controlled to a stopped state and then the mobility support program is rewritten. According to the invention described in Patent Document 2, there is no need to determine the operating status of each program, and since the update (rewrite) is performed in a stopped state, it is not an environment in which the mobility support program can be used, so the user will not want to use it and will not feel inconvenienced. [Prior art documents] [Patent documents]
[0007] [Patent Document 1] Japanese Patent Application Publication No. 11-259284 [Patent Document 2] JP 2007-230317 A Summary of the Invention [Problem to be solved by the invention]
[0008] However, when using the invention described in Patent Document 2, whenever a program update notification is received while the vehicle is traveling, the vehicle will be controlled to stop, which is very inconvenient for the driver and passengers.
[0009] The present invention aims to enable updates of mobility assistance programs in a mobile device such as an automobile to be performed safely, with easy management of updates, and at a time convenient for the user. [Means for solving the problem]
[0010] In order to solve the above problems, the present invention provides: an update program acquisition means for acquiring information on an update program for a movement assistance program that supports the movement of the own device; a program update control means for controlling execution of updating the mobility assistance program based on information about the update program acquired by the update program acquisition means; Equipped with The program update control means When it is determined that a request to start traveling for the vehicle has occurred and / or when it is determined that a call request to the vehicle has occurred during the update of the mobility assistance program, a message is issued to notify the vehicle of the inability to start traveling and / or a message is issued to wait for the start of traveling. The present invention provides a mobile device comprising:
[0011] The moving device of the present invention having the above-mentioned configuration has, as a moving mode for moving the device itself, a moving mode that supports the movement by using a moving support program for the moving mode.
[0012] In the mobile device of the present invention, the program update control means controls the mobile device to notify a message that driving cannot be started and / or to wait to start driving when it determines that a request for starting driving has occurred for the vehicle and / or when it determines that a call request for the vehicle has occurred while updating the mobility assistance program.
[0013] Therefore, according to the mobile device of the present invention, when the mobile device is in a stopped state and the mobile assistance program is being updated, if it is determined that a request to start traveling has occurred for the mobile device and / or if it is determined that a call request has occurred for the mobile device, a message is sent to the user that the mobile device cannot start traveling and / or a message is sent to the user that the mobile device is waiting to start traveling. This allows the user who has made the request to start traveling or the call request to recognize that traveling will not start in response to the request to start traveling or the call request, which is convenient. Effect of the Invention
[0014] According to the mobile device of the present invention, if a request to start driving or a call request occurs while the mobility assistance program is being updated, a message is displayed indicating that driving cannot be started and / or a message is displayed indicating that driving must wait before starting, thereby providing a convenient effect for the user as he or she can recognize that driving will not begin in response to the request to start driving or the call request. [Brief description of the drawings]
[0015] [Figure 1] 1 is a block diagram showing an example of the configuration of an electronic control circuit unit of an autonomous vehicle as an embodiment of a transportation device according to the present invention. FIG. [Diagram 2] FIG. 2 is a block diagram for explaining a part of an example of the configuration of an electronic control circuit unit of an autonomous driving vehicle as an embodiment of a transportation device according to the present invention. [Diagram 3] FIG. 11 is a block diagram for explaining another part of the configuration example of the electronic control circuit unit of an autonomous driving vehicle as an embodiment of a transportation device according to the present invention. [Figure 4] FIG. 13 is a diagram for explaining an example of post-disembarkation behavior in an autonomous vehicle as an embodiment of a transportation device according to the present invention. [Diagram 5] FIG. 11 is a flowchart showing an example of the flow of processing operations at the time of disembarking in an autonomously driven vehicle as an embodiment of a transportation device according to the present invention. [Figure 6]FIG. 2 is a diagram for explaining a program update method in an autonomous vehicle as an embodiment of a transportation device according to the present invention. [Figure 7] FIG. 2 is a flowchart showing an example of the flow of a program update operation in an autonomous vehicle as an embodiment of a transportation device according to the present invention. [Figure 8] FIG. 13 is a diagram showing a part of a flowchart illustrating an example of the flow of a program update operation in an autonomous vehicle as an embodiment of a transportation device according to the present invention. [Figure 9] FIG. 13 is a diagram showing a part of a flowchart illustrating an example of the flow of a program update operation in an autonomous vehicle as an embodiment of a transportation device according to the present invention. [Figure 10] FIG. 13 is a diagram showing a part of a flowchart illustrating an example of the flow of a program update operation in an autonomous vehicle as an embodiment of a transportation device according to the present invention. [Figure 11] FIG. 13 is a diagram showing a part of a flowchart illustrating an example of the flow of a program update operation in an autonomous vehicle as an embodiment of a transportation device according to the present invention. [Figure 12] FIG. 13 is a diagram showing a part of a flowchart illustrating an example of the flow of a program update operation in an autonomous vehicle as an embodiment of a transportation device according to the present invention. [Figure 13] FIG. 13 is a diagram showing a part of a flowchart illustrating an example of the flow of a program update operation in an autonomous vehicle as an embodiment of a transportation device according to the present invention. [Figure 14] FIG. 13 is a diagram showing a part of a flowchart illustrating an example of the flow of a program update operation in an autonomous vehicle as an embodiment of a transportation device according to the present invention. [Figure 15] FIG. 13 is a diagram showing a part of a flowchart illustrating an example of the flow of a program update operation in an autonomous vehicle as an embodiment of a transportation device according to the present invention. [Figure 16] FIG. 13 is a diagram showing a part of a flowchart illustrating an example of the flow of a program update operation in an autonomous vehicle as an embodiment of a transportation device according to the present invention. [Figure 17]FIG. 11 is a diagram for explaining another configuration example of an autonomously driven vehicle as an embodiment of a transportation device according to the present invention. [Figure 18] FIG. 13 is a diagram showing an example of an amphibious vehicle as another embodiment of the transportation device according to the present invention. [Figure 19] FIG. 13 is a diagram showing an example of an air-land vehicle as another embodiment of the transportation device according to the present invention. DETAILED DESCRIPTION OF THE PREFERRED EMBODIMENTS
[0016] Hereinafter, an embodiment of the moving device according to the present invention will be described with reference to the drawings. The embodiment of the moving device described below is a case where the moving device is an automobile, and is an autonomous vehicle having two moving modes: a manual driving mode in which the vehicle travels according to manual driving operations by the driver, and an autonomous driving mode in which the vehicle travels autonomously without driving operations by the driver. In the following description, since the moving is the driving of the automobile, the moving mode will be referred to as a driving mode, and the moving support program will be referred to as a driving support program. In addition, the moving mode identification information will be referred to as a driving mode identification information.
[0017] In the embodiment described below, an autonomous vehicle is equipped with a driving assistance program for the manual driving mode that assists the driver in manual driving mode, and a driving assistance program for the autonomous driving mode that assists autonomous driving in the autonomous driving mode. The driving assistance program for the manual driving mode and the driving assistance program for the autonomous driving mode are assigned program identification information that identifies each program and driving mode identification information that indicates which driving mode each program is for.
[0018] An example of a driving support program for the manual driving mode is a program for a power steering system that controls the ease of steering depending on the driving speed of the vehicle, etc. An example of a driving support program for the automatic driving mode is a program for autonomous driving by avoiding obstacles using sensors and cameras, etc.
[0019] The self-driving vehicle of this embodiment is equipped with an automatic collision prevention assist system, a cruise control system, and a lane keep assist system, and is configured to be able to activate these systems in the manual driving mode. These automatic collision prevention assist system, cruise control system, and lane keep assist system operate using driving assistance programs for the respective systems.
[0020] An automatic collision prevention assist system has the function of preventing the vehicle from colliding with an obstacle and stopping the vehicle just before the obstacle. This system is given various names depending on the automobile company, such as an automatic braking system, but in this specification, the name "automatic collision prevention system" will be used.
[0021] In addition, a cruise control system has the function of maintaining a constant distance between the vehicle and other vehicles traveling directly ahead. This system is also known by various names depending on the automobile company, such as auto cruise system or automatic tracking system, but in this specification, the name cruise control system will be used.
[0022] In addition, the lane keep assist system has the function of detecting the white lines on both sides of the driving lane and maintaining driving within those lines on both sides. This system is also called the lane tracing assist system, and although the name varies depending on the automobile company, etc., this specification will use the name lane keep assist system.
[0023] In the autonomous driving mode of the autonomous vehicle of this embodiment, the driving assistance programs for the automatic collision prevention assist system, the cruise control system, and the lane keep assist system are also used to assist autonomous driving. That is, the driving assistance programs for the automatic collision prevention assist system, the cruise control system, and the lane keep assist system are driving assistance programs shared by both the manual driving mode and the autonomous driving mode.
[0024] These driving assistance programs for the shared mode are assigned, as driving mode identification information, identification information indicating that the programs are for a shared mode shared by the manual driving mode and the automatic driving mode, in addition to program identification information for identifying the programs. In this embodiment, the identification information indicating that the programs are for the shared mode is unique identification information indicating that the programs are for the shared mode, but instead, both the driving mode identification information indicating that the programs are for the manual driving mode and the driving mode identification information indicating that the programs are for the automatic driving mode may be assigned as driving mode identification information.
[0025] In addition, in this embodiment, the autonomous vehicle is equipped with a driving assistance program that is also used in manual driving mode, but this invention is also applicable to vehicles that do not have such a driving assistance program in manual driving mode and in which a driving assistance program is used only in autonomous driving mode.
[0026] 1 is a block diagram showing an example of the hardware configuration of an electronic control circuit unit 10 of an autonomous vehicle 1 according to this embodiment. The autonomous vehicle 1 according to this embodiment is an example of an electric vehicle, and is equipped with a battery 11 as a drive source.
[0027] Moreover, the autonomous vehicle 1 of this embodiment has a manual driving mode and an autonomous driving mode in which the vehicle travels autonomously in this embodiment.
[0028] The manual driving mode is a mode in which the vehicle can travel in response to the driver's accelerator pedal operation, brake pedal operation, shift lever operation, and steering operation (handle operation) in the same manner as in a normal vehicle that is not an autonomous vehicle. However, as described above, the autonomous vehicle 1 of this embodiment has a driving support program that is automatically activated in the manual driving mode, and also has a driving support program that executes the functions of an automatic collision prevention assist system, a cruise control system, and a lane keep assist system that are activated by the driver's operation in the manual driving mode. In this example, the vehicle is configured to be able to switch from the manual driving mode to the autonomous driving mode by a predetermined action by the driver.
[0029] In addition, the autonomous driving mode in this embodiment is a mode in which the autonomous vehicle 1 automatically (autonomously) drives while avoiding obstacles without the driver operating the accelerator pedal, the brake pedal, the shift lever, or the steering wheel, and a driving support program for a plurality of autonomous driving modes is used. This autonomous driving mode can be switched to a manual driving mode by a predetermined action by the driver.
[0030] Here, the predetermined action by the driver includes a predetermined operation such as a manual driving operation by the driver, an operation input by the driver via the touch panel 112 described below, and a voice input action by the driver.
[0031] For example, the autonomous vehicle 1 can be switched from running in manual driving mode to the autonomous driving mode by a predetermined operation by the driver of the autonomous vehicle 1 through the touch panel 112 described later or by the driver's voice input, and the autonomous vehicle 1 is configured to automatically return to the manual driving mode if the driver operates the accelerator pedal, brake pedal, shift lever, steering wheel, or the like while running in the autonomous driving mode. Of course, the autonomous vehicle 1 may be configured to automatically return to the manual driving mode when the driver operates a predetermined operation through the touch panel 112 or the driver inputs a voice instruction while running in the autonomous driving mode.
[0032] As described above, in the autonomous driving vehicle 1 of this embodiment, the functions of the autonomous driving mode include the functions of the automatic collision prevention assist system, the cruise control system, the lane keep assist system, etc. In other words, the driving support program that executes the functions of the automatic collision prevention assist system, the cruise control system, and the lane keep assist system is shared between the manual driving mode and the autonomous driving mode.
[0033] As shown in FIG. 1, the electronic control circuit unit 10 is configured with a computer mounted on a control unit 101, and through a system bus 100, the following are connected to the control unit 101: a motor drive control unit 102, a steering drive control unit 103, a manual / automatic driving mode switching control unit 104, a brake drive control unit 105, a radar group 106, a camera group 107, a sensor group 108, a surrounding moving object grasping unit 109, a current position detection unit 110, a display unit 111, a touch panel 112, a car navigation (hereinafter abbreviated as car navigation) function unit 113, a user authentication unit 114, a caller authentication unit 115, a post-dismount behavior setting reception unit 116, a behavior control management unit 117, a non-driving use function unit 118, a program update management control unit 119, a voice input / output unit 120, a clock unit 121, a battery remaining amount detection unit 122, and a wireless communication unit 123.
[0034] A motor drive unit 131 is connected to the motor drive control unit 102. A steering drive unit 132 is connected to the steering drive control unit 103. A manual operation detection unit 133 is connected to the manual / automatic driving mode switching control unit 104, and a brake drive unit 134 is connected to the brake drive control unit 105. A car navigation database 135 is connected to the car navigation function unit 113. A speaker 136 and a microphone 137 are connected to the audio input / output unit 120.
[0035] Under the control of the control unit 101, the motor drive control unit 102 controls the supply of a drive signal to the motor drive unit 131 of the autonomous vehicle 1, which is an electric vehicle of this embodiment, so as to control the start of driving of the autonomous vehicle 1, driving speed control (including brake control and accelerator control), stopping of driving, etc.
[0036] Under the control of the control unit 101, the steering drive control unit 103 controls the supply of a drive control signal to the steering drive unit 132 of the autonomous vehicle 1 of this embodiment, thereby controlling the course change of the autonomous vehicle 1.
[0037] The manual / automatic driving mode switching control unit 104 performs control to switch the driving mode of the autonomous vehicle 1 between a manual driving mode and an autonomous driving mode in response to a driving mode selection operation input via the touch panel 112.
[0038] Note that the input that triggers the manual / automatic driving mode switching control unit 104 to perform control to switch the driving mode of the autonomous vehicle 1 between the manual driving mode and the autonomous driving mode is not limited to a selection operation input via the touch panel 112, and may be a voice input of a switching instruction via the microphone 137. In the case of a voice input, the voice input of the switching instruction via the microphone 137 is recognized by voice, and the recognition result is supplied to the manual / automatic driving mode switching control unit 104. The manual / automatic driving mode switching control unit 104 switches the driving mode based on the received voice recognition result.
[0039] The manual operation detection unit 133 receives operation information of the accelerator pedal operation, brake pedal operation, shift lever operation, and steering operation by the driver, and supplies the manual driving operation information to the manual / automatic driving mode switching control unit 104. When the manual operation detection unit 124 detects a manual driving operation by the driver in the automatic driving mode, the manual / automatic driving mode switching control unit 104 performs control to switch to the manual driving mode.
[0040] When the autonomous vehicle 1 is in manual driving mode, the manual / autonomous driving mode switching control unit 104 supplies manual driving operation information from the manual operation detection unit 133 to the motor drive control unit 102 and the steering drive control unit 103, and controls the motor drive unit 131 and the steering drive unit 132 in accordance with the driver's pedal operation, shift lever operation, and steering operation (handle operation).
[0041] Furthermore, when the autonomous vehicle 1 is in the autonomous driving mode, the manual / autonomous driving mode switching control unit 104 supplies autonomous driving operation information generated by the control unit 101 based on the outputs of the radar group 106, the camera group 107, the sensor group 108, and the surrounding moving object grasping unit 109 to the motor drive control unit 102 and the steering drive control unit 103, as described below, and controls the motor drive unit 131 and the steering drive unit 132 to drive using the autonomous driving operation information, thereby performing autonomous driving. Note that in the autonomous driving mode, the car navigation function unit 113 searches for a route from the current position to a destination (destination) set by the driver or the like, and controls the vehicle to travel along the searched route.
[0042] In the autonomous driving mode, when the driver performs a predetermined operation such as operating the accelerator pedal, brake pedal, shift lever, or steering (handle operation), the manual / autonomous driving mode switching control unit 104 performs mode switching control so that the driving mode of the autonomous vehicle 1 is automatically returned to the manual driving mode based on the detection information of the manual driving operation by the manual operation detection unit 133.
[0043] In the case of a fully autonomous vehicle, since there is only an autonomous driving mode, there is no need for switching control between the manual driving mode and the autonomous driving mode, and neither the manual / autonomous driving mode switching control unit 104 nor the manual operation detection unit 133 exists.
[0044] The brake drive control unit 105, under the control of the control unit 101, controls the supply of a drive control signal to the brake drive unit 134 of the autonomous vehicle 1 of this embodiment, thereby controlling the autonomous vehicle 1 to slow down or stop.
[0045] The radar group 106 is used to measure the distance to people and objects around the autonomous vehicle 1, and consists of one or more laser radars (formally known as LIDAR (Light Detection and Ranging or Laser Imaging Detection and Ranging)) and millimeter wave radars. The laser radar is embedded, for example, near the ceiling or bumper, and the millimeter wave radar is provided, for example, at the front and rear of the vehicle. The vehicle may be equipped with both laser radar and millimeter wave radar, or only one of them. Other radars, such as microwave radar, may also be used. In addition, sonar (not shown) can be used for the same purpose as radar.
[0046] The camera group 107 includes one or more cameras that capture images of the interior of the autonomous vehicle 1, and one or more cameras that capture images of the surroundings outside the vehicle, such as the front, sides, and rear of the autonomous vehicle 1. The cameras that capture images of the interior of the vehicle include cameras that are attached to, for example, a rearview mirror (rearview mirror, room mirror) between the driver's seat and the passenger seat, or to the top of the front window, and capture the behavior of a person (driver) sitting in the driver's seat, as well as cameras for capturing images of passengers (fellow passengers) sitting in the passenger seat or the back seat. The cameras that capture images of the surroundings of the autonomous vehicle 1 include, for example, two cameras (stereo cameras) that are attached to the left and right sides of the rearview mirror and mainly capture the left and right front of the autonomous vehicle 1, cameras that are attached to, for example, door mirrors or fender mirrors of the autonomous vehicle 1 and capture the left and right sides, and a camera that captures the rear of the autonomous vehicle 1.
[0047] The sensor group 108 includes an opening / closing detection sensor for detecting the opening / closing of a door or window, a sensor for detecting the fastening of a seat belt, a seating sensor (e.g., a weight sensor) for detecting that a passenger is seated in a seat such as the driver's seat or the passenger seat, a touch sensor (e.g., a capacitance sensor) for detecting that a person touches the steering wheel of the driver's seat, a human presence sensor (e.g., an infrared sensor) for detecting a person nearby outside the vehicle, and various sensors for acquiring information that assists in automatic driving. The various sensors for acquiring information that assists in automatic driving include, for example, a vibration sensor for detecting vibrations of the vehicle or tires, a rotation speed sensor for detecting the number of rotations of the tires, a geomagnetic sensor for detecting a direction, an acceleration sensor for detecting acceleration, a gyro sensor (gyroscope) for detecting an angle or an angular velocity, and the like. In this embodiment, the sensor group 108 also includes a sensor for detecting the lighting of a right turn signal, a left turn signal (direction indicator), and a hazard lamp (emergency flashing lamp).
[0048] The surrounding moving object grasping unit 109 grasps moving objects (including people) around the vehicle using images captured by the radar group 106, the sensor group 108, and the camera group 107. The surrounding moving object grasping unit 109 grasps surrounding obstacles and moving objects by performing processing based on machine learning such as Bayes' theory and deep learning.
[0049] The current position detection unit 110 receives radio waves from GPS satellites to detect the current position of the vehicle. Since the accuracy of the position detected by radio waves from GPS satellites is poor, the current position detection unit 110 uses not only the information on the current position detected by receiving radio waves from GPS satellites, but also one or more sensors included in the sensor group 108, the radar group 106, and the captured images (also using a navigation function) of the camera group 107, and performs processing based on machine learning such as Bayes' theory and deep learning, thereby detecting and confirming the current position with higher accuracy.
[0050] In the autonomous driving mode, the autonomous vehicle 1 uses the current position detection unit 110 and the surrounding moving object grasping unit 109 to process various information such as position information obtained by receiving radio waves from the radar group 106, the camera group 107, the sensor group 108, and GPS satellites, in other words, information corresponding to information obtained by the human eyes and ears, using machine learning such as Bayes' theory and deep learning, and based on this, the control unit 101 performs intelligent information processing (artificial intelligence) and control (artificial intelligence) such as changing the vehicle's course and avoiding obstacles, to generate autonomous driving operation information.
[0051] Display unit 111 is, for example, an LCD (Liquid Crystal Display). Touch panel 112 is arranged such that a touch sensor capable of touch input with a finger, a touch pen, or the like is superimposed on the display screen of display unit 111 made of an LCD. On the display screen of display unit 111, a display image including software buttons (including character input buttons of a keyboard) is displayed based on the control of control unit 101. Then, when touch panel 112 detects a touch with a finger, a touch pen, or the like on a software button displayed on the display screen, it transmits the touch to control unit 101. Receiving this, control unit 101 is configured to execute a control process corresponding to the software button.
[0052] Domestic maps and route guidance data are stored in advance in car navigation database 135 connected to car navigation function unit 113. Car navigation function unit 113 is a functional unit that provides guidance to assist autonomous vehicle 1 in moving to a specified destination, based on the maps and route guidance data stored in car navigation database 135. In this embodiment, car navigation function unit 113 is configured to perform slightly different processes in manual driving mode and autonomous driving mode.
[0053] That is, in the manual driving mode, the car navigation function unit 113 displays an image on the display screen of the display unit 111 in which the vehicle position detected and confirmed by the current position detection unit 110 is superimposed on a map that clearly displays the route to the destination, and also moves the vehicle position (current position) on the map as the vehicle moves, and provides voice guidance at points where route guidance is necessary, such as intersections and branching points on the route. This is the same as the normal car navigation function.
[0054] On the other hand, in the autonomous driving mode, when the current position of the vehicle is away from the route to the destination, the car navigation function unit 113 notifies the control unit 101 of information on the direction of departure and distance, and when the current position of the vehicle is on the route to the destination, the car navigation function unit 113 notifies the control unit 101 of information instructing the change of the course direction along the route before an intersection or a branch point on the route as the vehicle moves. Based on the information notified from the car navigation function unit 113, the current position confirmation result of the current position detection unit 110 and the recognition result of the surrounding moving object recognition unit 109, the control unit 101 controls the motor drive unit 131 via the motor drive control unit 102 so that the vehicle moves along the route as instructed, and generates autonomous driving operation information for controlling the steering drive unit 132 via the steering drive control unit 103. Therefore, the route guidance to the destination by the car navigation function unit 113 and the control unit 101 in the autonomous driving mode allows the autonomous vehicle 1 to move to the destination even when there are no passengers.
[0055] The user authentication unit 114 performs user authentication using the authentication information of the user stored in the memory unit 114M and the authentication information acquired from the user at that time. Here, the user is mainly the driver, but may be a passenger other than the driver. The autonomous vehicle 1 of this embodiment is capable of autonomous driving in the autonomous driving mode even when the driver is not present.
[0056] In this embodiment, for example, user authentication is performed based on whether or not the face image of the person who has just got off matches the face image of the new user (boarding passenger). For this reason, in this embodiment, the user authentication unit 114 is configured to include an image recognition means.
[0057] In this embodiment, memory unit 114M of user authentication unit 114 stores facial images of disembarking passengers captured by a predetermined camera in camera group 107. In this embodiment, the facial image of the most recent disembarking passenger captured by a camera is overwritten and stored in memory unit 114M as an update to the facial image of the previous disembarking passenger that was stored previously. Of course, the facial image of the previous disembarking passenger may be left as it is without being overwritten. Note that image information of facial images of users (for example, family members, car sharing members, acquaintances, friends, etc.) who are registered as users of autonomous vehicle 1 may be registered and stored in advance in memory unit 114M.
[0058] User authentication can also be performed by the user's voice, in which case the autonomous vehicle 1 picks up the voice of the person getting off with microphone 137 and stores the voice of the person getting off in memory unit 114M. User authentication unit 114 is configured to have a speaker voice recognition function, and performs user authentication by determining whether the stored voice matches or does not match the user's voice picked up by microphone 137.
[0059] User authentication can also be performed using the user's fingerprint. In this case, the autonomous vehicle 1 is provided with a fingerprint reader, the storage unit 114M stores the fingerprint of the person getting off the vehicle, and the user authentication unit 114 is configured to have a fingerprint recognition function, and performs user authentication by determining whether the stored fingerprint matches or does not match the fingerprint of a new user acquired by the fingerprint reader. Veins, irises, voiceprints, and other biometric information can be used for user authentication, and these cases can also be made possible by changing the configuration in a similar manner. Of course, biometric information such as face images, voices, and fingerprints may be stored in combination and used for user authentication.
[0060] Furthermore, user authentication can be performed by the user holding a key to the autonomous vehicle 1.
[0061] In addition, the voice of the latest passenger picked up by the microphone may be overwritten and stored in the memory unit 114M as an update to the voice of the previous passenger who had been stored before, or the voice of the previous passenger may be left without overwriting. This is not limited to the voice of the passenger who has been alighted, and fingerprints, veins, irises, voiceprints, and other biological information may be stored in the same manner.
[0062] The caller authentication unit 115 performs caller authentication using authentication information for the caller stored in the memory unit 115M and authentication information acquired from the caller when the call is received by the wireless communication unit 123. In this embodiment, the caller authentication is performed based on whether the telephone number of the mobile phone terminal of the person who most recently got off the train matches or does not match the telephone number of the mobile phone terminal of the caller.
[0063] In this embodiment, the storage unit 115M of the caller authentication unit 115 stores the telephone number of the mobile phone terminal of the most recent person getting off the train, which is input through the touch panel 112. The telephone number stored in this storage unit 115M is overwritten on the previously stored telephone number, so that it is the telephone number of only the most recent person getting off the train. Of course, the previously stored telephone number may be left as it is without overwriting. Note that an email address may be stored instead of the telephone number of the mobile phone terminal, or a communication application ID may be stored. Of course, these may be stored in combination with the telephone number. In this case, the presence or absence of overwriting of the email address or communication application ID is the same as in the case of the telephone number. Furthermore, the caller may be made to speak, and speaker recognition may be performed.
[0064] The caller authentication unit 115 is configured to, when there is an incoming call from a caller to the wireless communication unit 123, obtain the incoming telephone number, determine whether it matches or does not match the telephone number stored in the memory unit 115M, and perform caller authentication.
[0065] As with the configuration of user authentication section 114, the configuration of caller authentication section 115 is also changed according to differences in the information used as authentication information.
[0066] In this embodiment, the post-disembarking behavior setting reception unit 116 receives a setting of a post-disembarking behavior that the autonomous vehicle 1 should perform when a user, such as a driver or a passenger other than the driver, disembarks, and stores the received setting information in the built-in storage unit 116M. In this embodiment, a list of post-disembarking behaviors registered and stored in advance by the user is stored in the storage unit 116M. The post-disembarking behavior setting reception unit 116 presents the list of post-disembarking behaviors stored in the storage unit 116M to the user, and receives settings of information on the post-disembarking behavior selected and set by the user from the list. Note that the post-disembarking behavior setting reception unit 116 may be provided in a mobile phone terminal, such as a smartphone, of the user that can communicate with the autonomous vehicle 1, in addition to being provided in the autonomous vehicle 1.
[0067] In this case, although not shown in the drawings, each item of the post-disembarking behavior in the post-disembarking behavior list (see FIG. 4 described later) is configured as an icon button, and the user can select and set information of the post-disembarking behavior by operating and instructing each desired icon button on the touch panel 112. Examples of post-disembarking behavior stored in the memory unit 116M and the setting reception process of the post-disembarking behavior setting reception unit 116 will be described later.
[0068] As an input method for setting behavior after getting off the vehicle, each behavior after getting off the vehicle can be read out by voice. The control unit 101 has a voice recognition function for this purpose.
[0069] The behavior control management unit 117 detects and manages the current state of the vehicle (whether it is moving or stopped) and the driving mode of the vehicle while it is moving, and also executes and manages the behavior of the vehicle after the user gets off the vehicle based on the post-dismounting behavior accepted by the post-dismounting behavior setting acceptance unit 116. The behavior control management unit 117 includes a memory unit 117M that stores the post-dismounting behavior accepted by the post-dismounting behavior setting acceptance unit 116 by the user, as well as authentication information and time information for executing the post-dismounting behavior.
[0070] In this embodiment, as shown in FIG. 2, in addition to the memory unit 117M, the behavior control management unit 117 has, as functional means, a driving mode detection means 1171, a vehicle state determination means 1172, a post-dismount behavior execution control means 1173, and a stop duration prediction means 1174.
[0071] The driving mode detection means 1171 detects which of a plurality of driving modes the vehicle has at the current time point while the vehicle is traveling, and in this example, detects whether the driving mode is the manual driving mode or the automatic driving mode. In this example, the driving mode detection means 1171 detects whether the driving mode at the current time point is the manual driving mode or the automatic driving mode from a predetermined operation by the driver via the manual operation detection unit 133, an operation input via the touch panel 112, and a voice instruction input picked up by the microphone 137.
[0072] The vehicle state discrimination means 1172 discriminates whether the vehicle is moving or stopped. Here, the vehicle being stopped includes both stopped and parked. The stop duration is the duration until the stopped state ends. In this embodiment, the vehicle state discrimination means 1172 discriminates whether the vehicle is moving or stopped, regardless of whether the driving mode is a manual driving mode or an automatic driving mode.
[0073] The vehicle state discrimination means 1172 discriminates that the vehicle is stopped when, for example, a state where the speed is zero continues for a predetermined time or more, for example, a waiting time for a traffic light or more, by a traveling speed detection means of the vehicle (not shown). In this case, the vehicle state discrimination means 1172 also has a function of a speed detection means and an image recognition function of a traffic light from an image captured by the camera group 107 (identification of a red light, etc.). The vehicle state discrimination means 1172 may also determine that the vehicle is stopped when it detects that a driver or a passenger has got off the vehicle. In this embodiment, when the vehicle state discrimination means 1172 determines that the vehicle is stopped, the behavior control management unit 117 notifies the program update management control unit 119 of the stopped state of the vehicle. The vehicle state discrimination means 1172 of the behavior control management unit 117 may also notify whether the vehicle is stopped or running when an inquiry is received from the program update management control unit 119.
[0074] The post-alighting behavior execution control means 1173 controls to execute the post-alighting behavior based on the post-alighting behavior accepted by the post-alighting behavior setting acceptance unit 116. This post-alighting behavior includes, as will be described later, a state in which, after alighting, the vehicle travels toward the destination accepted by the post-alighting behavior setting acceptance unit 116, and a state in which the vehicle continues to stop at the location where the passenger alighted.
[0075] The stop duration prediction means 1174 has a function of predicting the stop duration when the host vehicle state determination means 1172 determines that the host vehicle is stopped. In this embodiment, as will be described later, the stop duration prediction means 1174 predicts the stop duration from the post-getting-off behavior set by the user. In this embodiment, information on the stop duration predicted by the stop duration prediction means 1174 is sent when there is an inquiry from the program update management control unit 119.
[0076] In this case, the stopped state duration prediction means 1174 predicts the end time of the stopped state when the stopped state is determined by the host vehicle state determination means 1172. Then, when an inquiry is received from the program update management control unit 119, the stopped state duration prediction means 1174 calculates the time from the time of receipt of the inquiry to the predicted end time as the stopped state duration and responds to the program update management control unit 119.
[0077] The stopped duration prediction means 1174 may predict the end time of the stopped state when it is determined by the vehicle state determination means 1172 that the vehicle is stopped, and automatically notify the program update management control unit 119 of the predicted stopped duration information. In this case, the program update management control unit 119 can predict the stopped duration by itself from the information on the end time of the stopped state received from the behavior control management unit 117.
[0078] In this case, from the viewpoint that when the driver is in the vehicle, the movement of the vehicle is generally controlled according to the control instructions from the driver, in this embodiment, the behavior control management unit 117 executes and manages the control process based on the accepted post-dismount behavior only when the driver is not present in the vehicle after the user dismounts. An example of the behavior control and management by the behavior control management unit 117 will be described in detail later.
[0079] The stop duration can be input from touch panel 112, voice input from microphone 137, or input from a mobile phone terminal such as a smartphone when the alighting passenger gets off, and in this case, the input time is reflected in the prediction of the stop duration in stop duration prediction means 1174. Also, even if not at the time of alighting, if the user is already aware of the length of the stopped time when boarding or while riding, the user may be allowed to input the stop duration (stop duration time) from touch panel 112, voice input from microphone 137, or input from a mobile phone terminal such as a smartphone when boarding or while riding.
[0080] Non-driving use function unit 118 is a function unit for executing functions for uses other than driving of autonomous vehicle 1, such as AV entertainment functions and game functions. Execution of a non-driving use function is started when the user selects and gives an instruction to start the function via touch panel 112, and execution of the function is ended when the user gives an instruction to end the function (including turning off the drive power of autonomous vehicle 1). Non-driving uses such as AV entertainment functions and game functions can be used not only when the host vehicle is stopped, but also when the host vehicle is driving (both when driving in manual driving mode and when driving in autonomous driving mode).
[0081] The program update management control unit 119 connects to a program update server 3 (see FIG. 6) described later through the Internet 2 by the wireless communication unit 123, and performs update processing of the programs of each unit of the autonomous vehicle 1. In the autonomous vehicle 1 of this embodiment, the motor drive control unit 102, the steering drive control unit 103, the manual / autonomous driving mode switching control unit 104, the brake drive control unit 105, the surrounding moving object grasping unit 109, the current position detection unit 110, the car navigation function unit 113, the post-get-out behavior setting acceptance unit 116, the behavior control management unit 117, and the like are functional units for driving purposes, and are each made to operate by a driving assistance program. In addition, the user authentication unit 114, the caller authentication unit 115, and the non-driving purpose function unit 118 are functional units for purposes other than driving, and are each made to operate by a program. The program update management control unit 119 manages and controls updates of all of those programs.
[0082] 3, program update management control unit 119 is provided with a memory unit 119M for managing information about update programs, and is also provided with, as functional means, update notification monitoring means 1191, update inquiry means 1192, update program acquisition means 1193, update program / mode type identification means 1194, and program update control means 1195. The detailed processing function contents and operations of each functional means of program update management control unit 119 will be described in detail later.
[0083] The voice input / output unit 120 takes in voice collected by the microphone 137 and sends it to the system bus 100 for voice recognition processing, for example. Although not shown, the voice input / output unit 120 also has a built-in memory for storing voice message data to be emitted to the outside, and also has a built-in voice synthesizer and DA converter for converting the voice message data read from the memory into an analog voice signal. The voice input / output unit 120 then supplies the voice message selected under the control of the control unit 101 to the speaker 136, so that it is emitted to the outside as voice.
[0084] As described later, the voice messages to be stored include inquiry messages such as "Do you want to set the behavior after getting off the train?", notification messages such as "Authentication completed" and "Authentication failed", and interactive messages for accepting input of the behavior after getting off the train. In addition, notification messages such as "We cannot answer calls because the program is being updated" and "Please wait as the program is being updated" are also prepared.
[0085] The clock unit 121 has a calendar function to provide the year, month, date, day of the week, and current date and time, and also has a timer function to measure time from a specified timing and the remaining update time while a program update is being performed, based on the control of the control unit 101.
[0086] The battery 11 is connected to the battery remaining capacity detection unit 122. The battery remaining capacity detection unit 122 constitutes a driving source remaining capacity detection unit, and in this embodiment, detects the remaining capacity of the battery 11 as a driving source. In this embodiment, the battery remaining capacity detection unit 122 has a function to detect how far or how long the vehicle can be driven with the remaining capacity when the vehicle is used for driving, and also has a function to detect how long the battery 11 can be used continuously with the remaining capacity when the vehicle is used for purposes other than driving. Furthermore, in this embodiment, the battery remaining capacity detection unit 122 has a function to determine whether or not the program can be updated with the remaining capacity of the battery 11.
[0087] The wireless communication unit 123 has a function to connect to a program update server, a surrounding search server for navigation, and the like via the Internet, and also has a function to respond to calls from the user, and in this example has the same functional units as a highly functional mobile phone (smartphone). Therefore, each of the wireless communication units 123 of the autonomously driving vehicle 1 has its own mobile phone number and email address.
[0088] The electronic control circuit unit 10 of the autonomous vehicle 1 is configured as described above. In the above description, the motor drive control unit 102, steering drive control unit 103, manual / autonomous driving mode switching control unit 104, surrounding moving object grasping unit 109, current position detection unit 110, car navigation function unit 113, user authentication unit 114, caller authentication unit 115, post-getting-off behavior setting reception unit 116, behavior control management unit 117, and non-driving use function unit 118 shown in Fig. 1 are each a processing function of a program, and the control unit 101 can realize the program that executes each function as software processing. It goes without saying that not all of the above-mentioned units are configured as processing functions by programs, but some may be configured as hardware components.
[0089] In this embodiment, when autonomous vehicle 1 is stopped, the supply of power to each unit that should be operated only while the vehicle is moving is stopped, but each unit, namely current location detection unit 110, user authentication unit 114, caller authentication unit 115, behavior control management unit 117, and program update management control unit 119, is kept in a standby state and can be started immediately when necessary by control unit 101. When control unit 101 executes all functions by programs, control unit 101 is, of course, always kept in a standby state even when the vehicle is stopped, and can be started in response to various start-up triggers.
[0090] [Example of information stored in the memory unit 116M of the post-disembarkation behavior setting reception unit 116] As described above, the post-disembarking behavior that the user wants to specify is stored in advance in the memory unit 116M of the post-disembarking behavior setting reception unit 116. This post-disembarking behavior can be selected from those registered in advance as defaults in the autonomous vehicle 1 by the automobile company or the like, or can be set and stored by the user. Also, behaviors stored on the cloud on the Internet can be used.
[0091] 4 shows examples of behaviors after getting off the vehicle stored in the storage unit 116M of the behavior setting receiving unit 116 after getting off the vehicle in this embodiment. Each example of behavior after getting off the vehicle will be described.
[0092] "Go to default parking lot" causes the self-driving car 1 to move to a pre-registered default parking lot after the user gets off the car, and the post-disembarkation behavior ends with the move to the parking lot. Here, multiple parking lots can be registered as default parking lots, such as "home parking lot," "company parking lot," and "contract parking lot." Registering a parking lot means storing its location information and the name (type) of the parking lot, such as "home parking lot," "company parking lot," or "contract parking lot." When the user selects and sets "go to default parking lot" as the post-disembarkation behavior, the user also selects and sets the name of the default parking lot.
[0093] When "move to default parking lot" is set as the post-disembarkation behavior, it is predicted that the autonomous vehicle 1 will not be used for a relatively long time, for example, one hour or more, after the user disembarks. Therefore, the function of the stopped duration prediction means of the behavior control management unit 117 predicts this period of time when it is predicted that the autonomous vehicle will not be used as the stopped duration.
[0094] In the "wait until called at a nearby parking lot", the autonomous vehicle 1 searches for a parking lot near the user's drop-off location and waits at that parking lot. After that, when the user makes a call by telephone using a mobile phone terminal through the wireless communication unit 123 of the autonomous vehicle 1, the autonomous vehicle 1 returns to the location where the user got off in response to the call. In this embodiment, the user registers authentication information for the call and authentication information for reboarding when getting off the vehicle. The behavior control management unit 117 stores and holds the registered authentication information in the storage unit 117M together with setting information for behavior after getting off the vehicle. The authentication information for the call and the authentication information for reboarding can also be deleted (erased) when the reboarding is completed.
[0095] In this case, the user is prompted to input the waiting time until the call, and the waiting time is input by the user in the input field for the waiting time, as shown in Fig. 4. The stop duration prediction means 1174 of the behavior control management unit 117 predicts the stop duration from the input waiting time.
[0096] When a user calls the autonomous vehicle 1 via a mobile phone terminal, the behavior control management unit 117 authenticates the caller using the registered authentication information at the time of the call, and only if the authentication is successful, responds to the call and performs movement control to return to the place where the user got off the vehicle. In this embodiment, for example, the telephone number (subscriber number) of the caller's mobile phone terminal is registered as authentication information at the time of the call when the user gets off the vehicle, and when a call is received from the caller, authentication is performed based on whether the caller's telephone number is a registered telephone number.
[0097] When the behavior control management unit 117 of the autonomous vehicle 1 detects that a user has reboarded the vehicle, it authenticates the reboarder using the authentication information registered at the time of reboarding, and controls so that the reboarder is permitted to use the vehicle only if the authentication is successful. In this embodiment, for example, a facial image of the user is registered as authentication information at the time of reboarding when the user disembarks, and when the user reboards the vehicle, authentication is performed based on face recognition using the facial image to determine whether the user is a registered disembarking person.
[0098] The authentication information when calling is not limited to the telephone number of the mobile phone terminal, but may be an email address. Also, a password or ID may be registered, and in communication based on an incoming call from the caller, the password or ID may be sent and authentication may be performed by confirming that the two match. The authentication information when calling may be a combination of a telephone number or email address and the password or ID.
[0099] The authentication information for the re-boarding passenger may be not only a facial image but also biometric information such as a voice (audio), fingerprint, vein, or iris, or may be a password or ID. Also, a combination of these may be used as the authentication information.
[0100] "Wait here" means that autonomous vehicle 1 will wait at the location where the user got off. In this case, the user is prompted to input the waiting time, and the waiting time is set and input by the user in the input field for the waiting time, as shown in Fig. 4. Stop duration prediction means 1174 of behavior control management unit 117 predicts the stop duration from the set and input waiting time.
[0101] Furthermore, in this embodiment, when getting off the vehicle, the user registers authentication information for re-boarding. This authentication information for re-boarding can be the same as that described in the above-mentioned "Wait until called at a nearby parking lot", and in this embodiment, it is a facial image of the user (e.g., the driver). The behavior control management unit 117 stores and holds the registered authentication information in the memory unit 117M together with the setting information of the behavior after getting off the vehicle.
[0102] "Heading to point A" means that the autonomous vehicle 1 autonomously drives to a location specified by the user. Point A is specified by the user when getting off the vehicle. This point A may be set from among points registered in advance, or may be specified, for example, on a map, specified by inputting an address, or specified by an identifiable building name. It may also be a two-dimensional coordinate of latitude and longitude (or a three-dimensional coordinate adding altitude). Furthermore, if point A can be specified by a telephone number, it may be specified by inputting the telephone number. In this case, since it is difficult to predict the duration of the stop, the stop duration prediction means 1174 of the behavior control management unit 117 predicts the stop duration to be, for example, zero.
[0103] In this case of "heading to point A," the reboarding passenger is not limited to the user who disembarked. Therefore, in this embodiment, a password or ID is set as authentication information for the reboarding passenger. The behavior control management unit 117 stores and holds the registered authentication information in the memory unit 117M together with the setting information for behavior after disembarking.
[0104] In the "pick up in response to a call" mode, after the user gets off the vehicle, the autonomous vehicle 1 can operate freely (it can even travel autonomously) until a call is made. When the user makes a call by telephone using a mobile phone terminal through the wireless communication unit 123 of the autonomous vehicle 1, the autonomous vehicle 1 will pick up the user at a location designated by the user in response to the call. In this case, when the user makes a call by telephone to the autonomous vehicle 1, information on the location to be picked up is sent to the autonomous vehicle 1 in the telephone communication. For example, information on the current location determined by a GPS equipped in the user's mobile phone terminal is sent from the user's mobile phone terminal to the autonomous vehicle 1 as information on the location to be picked up. Furthermore, in this case as well, the user is required to register authentication information for the call and authentication information for reboarding when getting off the vehicle. With regard to the authentication information for the call and the authentication information for reboarding, the same processing as in the "wait until called at a nearby parking lot" mode is performed.
[0105] In this case, since it is difficult to predict the duration of the stop, the stop duration prediction means 1174 of the behavior control management unit 117 predicts the stop duration to be zero, for example.
[0106] Furthermore, the call is not limited to telephone communication, but may be made by email or through a communication app.
[0107] "Waiting at point B" means that autonomous vehicle 1 waits at a location specified by the user, waiting for the user to reboard. Point B is specified by the user when getting off the vehicle. This point B may be set from among points registered in advance, or may be specified, for example, on a map, by inputting an address, or by specifying an identifiable building name. It may also be specified as two-dimensional coordinates of latitude and longitude (or three-dimensional coordinates by adding altitude). Furthermore, if point B can be specified by a phone number, it may be specified by inputting the phone number.
[0108] In this case, the user is prompted to input the waiting time, and as shown in Fig. 4, the user sets and inputs the waiting time at point B in the input field for the waiting time. The stop duration prediction means 1174 of the behavior control management unit 117 predicts the stop duration from the set and input waiting time.
[0109] In this case, the authentication information when the user re-boards the vehicle can be the same as that described in the above-mentioned "Waiting in a nearby parking lot until called", and in this embodiment, it is the face image of the user (e.g., the driver). The behavior control management unit 117 stores and holds the registered authentication information in the memory unit 117M together with the setting information of the behavior after getting off the vehicle.
[0110] "Return to drop-off location after a specified time" is the behavior after disembarking that assumes that the user will return (including not moving) to the drop-off location (current location) after a specified time during which the user has performed a specified errand after disembarking. When disembarking, the user can directly set the specified time in the "specified time" input field, as shown in Figure 4, or can input the errand to grasp the "specified time" in that input field. That is, the "specified time" can be set in this case as follows:
[0111] (a) Setting a timer time for the clock unit 121,
[0112] (b) Settings based on voice input through the microphone 137, such as "just a little errand," "toilet," "meal," "concert," "watching a baseball game," "watching a soccer game," "watching a sumo wrestling game," "a few minutes," "about an hour," etc.
[0113] (c) Selection from a list of predetermined events displayed on the display unit 111 etc.
[0114] An example of how the control unit 101 of the autonomous vehicle 1 determines the predetermined time from the input of information for determining the predetermined time of (b) and (c) is shown below. In the case of (b), the word enclosed in " " is input by voice, and the business recognized by voice is displayed in the input field. In the case of (c), the word enclosed in " " is selected from the list, and the selected business is displayed in the input field. In the stop duration prediction means 1174 of the behavior control management unit 117, when a "predetermined time" is set, the "predetermined time" is determined from the time information, and when an "business" is selected and input, the "predetermined time" is determined from the selected "business", and the stop duration is predicted from the determined "predetermined time".
[0115] An example of "business" and a specified time is shown below. - "Toilet" Estimate the time on the side and set the designated time as, for example, 10 minutes. "Watching sumo wrestling" In the case of a tournament, the tournament ends at approximately 6 p.m., so use that end time as a guide to figure out how much time is left from the current time. "Watching baseball" In professional baseball, the standard time is about 3 hours from the start of the game, and in high school baseball, about 2 hours from the start of the game. If there are extra innings, the time is added. For example, you can get the game start time from a specific site via the Internet, and if you can get live broadcasts from a specific site via the Internet, you can find out the game end time. "Watching soccer" First half 45 minutes, halftime 15 minutes, second half 45 minutes, and a little bit of extra time are used as a guide to determine the designated time. If extra time occurs, additional time is added. For example, you can obtain the start time of the game from a designated site via the Internet, and if you also obtain live broadcasts from a designated site via the Internet, you can determine the end time of the game. - "Concert" The end time announced by the organizer is the guideline. When getting off, the passenger inputs the end time, and the scheduled time is understood based on that time. "Watching a Movie" The end time of the movie is fixed. When getting off, the user inputs the end time of the movie, and the designated time is calculated based on that time. "Shopping Center" Based on experience and statistics, a given time is determined, for example, 2 hours. "Department Store" - Based on experience and statistics, a given time is determined, for example, 2 hours. "Mass retailer (home appliances and computers)" A given period of time is understood to be, for example, 1 hour, based on experience and statistics. "Bookstore" - Determine the specified time, for example 30 minutes, based on experience and statistics. "Florist": Determine the specified time, for example 15 minutes, based on experience and statistics. "Small Shop" - Determine the specified time, for example 15 minutes, based on experience and statistics. "Convenience store" Determine the specified time, for example 15 minutes, based on experience and statistics. "Post Office" It depends on the waiting time, but if you are just posting a letter, the designated time is, say, 3 minutes, if you are at the post office counter, say, 10 minutes, if you are at an ATM, say, 5 minutes, and if you are at a savings or insurance counter, say, 20 minutes. "Bank" The designated time depends on the waiting time, but for ATMs, it is, for example, 5 minutes, and for tellers, it is, for example, 20 minutes. If the number of people waiting in line to use the ATM can be known from outside, the number of people can be recognized by recognizing the image taken by the camera, and for example, each person waiting at the ATM can be set to 3 minutes, and the number of people can be multiplied by 3 minutes and added to the designated time. "Cram school" The end time is fixed. When getting off, the user inputs the end time, and the time is used as a guide to determine the specified time, for example, 2 hours. "Restaurant" - For example, set a specific time, such as 30 minutes for lunch and 2 hours for dinner. "Coffee shop" - Understand the designated time, for example 1 hour. "Fishing Pond" - Determine the designated time, for example 2 hours. "Shrines and Temples" - New Year's visits to shrines, etc. For example, set a specific time period as one hour. "Theme park, amusement park, leisure land, amusement park" If you plan to play for a long time, for example, 8 hours, figure out the specified time. If you plan to stay until closing time, you can calculate the specified time from now until closing time. "Museums and art galleries" For large facilities such as the British Museum or the Louvre, the designated time is understood to be, for example, 5 hours or until closing time, while for smaller facilities, the designated time is understood to be, for example, 1 hour. "Zoos and aquariums" Identify a specific time, for example 3 hours. "No Vehicle Entry Area" If you see a sign that says "Please refrain from driving beyond this point," but you want to see beyond that point, get out of your car and go and see for yourself. Know the time limit, for example 15 minutes.
[0116] The specified time determined from the above-mentioned "business" may be largely dependent on the user, and therefore may be customized for each user, or the autonomous vehicle 1 may learn the user's usage history and determine the time.
[0117] Note that autonomous vehicle 1 may determine the predetermined time by judging the TPO (situation, congestion level, etc.). Of course, the presence or absence of a parking space at the location where the user is dropped off may also be a condition for determining the predetermined time. Furthermore, if a post office, bank, restaurant, coffee shop, etc. provides an application that allows the user to know the waiting time, that waiting time can be used to know the predetermined time. In this case, if the application that allows the user to know the waiting time provided by the restaurant, coffee shop, etc. has a function for providing information on the waiting time, autonomous vehicle 1 can receive and know the information on the waiting time via wireless communication unit 123.
[0118] Furthermore, if the waiting time is posted in a place visible from the outside in a restaurant, coffee shop, or the like, autonomous vehicle 1 can grasp the waiting time by performing image recognition on images captured by camera group 107. A user who has grasped the waiting time may input the waiting time to autonomous vehicle 1 via touch panel 112, or by voice via microphone 137.
[0119] In this example, the behavior after getting off is set to "return to the get-off location after a predetermined time", but it can also be set to "return to the get-off location at a predetermined time". In addition, both behaviors after getting off may be prepared.
[0120] "Be at point C after a specified time" is also a behavior after disembarking that assumes that the user will perform a specified errand after disembarking, and moves to another point C that is not the disembarking location (current location) as the point to reboard after the specified time. As with "return to disembarking location after a specified time", when disembarking, the user directly sets the "specified time" or inputs an "errand" to grasp the "specified time", and also sets point C. The stop duration prediction means 1174 of the behavior control management unit 117 grasps the "specified time" from the time information when a "specified time" is set, and grasps the "specified time" from the selected "errand" when an "errand" is selected and input, and predicts the stop duration from the grasped "specified time".
[0121] Point C may be set from among preregistered points, or may be specified on a map, or may be specified by inputting an address, or may be specified by an identifiable building name, etc. It may also be specified by two-dimensional coordinates of latitude and longitude (or three-dimensional coordinates by adding altitude). Furthermore, if point C can be specified by a telephone number, it may be specified by inputting the telephone number.
[0122] When point C is close to the drop-off position (current position), the method of setting the "predetermined time" and the method of grasping the predetermined time in the control unit 101 of the autonomous vehicle 1 are the same as "return to the drop-off position after a predetermined time". When point C is far from the drop-off position (current position) (e.g., 1 km or more), the travel time from the drop-off position (current position) to point C significantly affects the predetermined time. Therefore, the time taken for the predetermined errand alone is not enough to grasp the predetermined time, and it is necessary to add the time taken for travel. Calculating (estimating) the travel time requires inputting at least the information on the means of transportation and the travel distance or travel section by that means. Therefore, when point C is far from the drop-off position (current position), it is preferable for the user to directly set the "predetermined time" when getting off the vehicle.
[0123] Even in this case, the behavior after getting off can be "be at point C at a specified time" instead of "be at point C after a specified time" as in "return to the get-off position after a specified time". Also, both behaviors after getting off can be prepared.
[0124] [Example of processing operation when a user gets off the autonomous vehicle 1 according to the embodiment] Next, an overview of the processing operation of the control unit 101 of the autonomous vehicle 1 when a user who has been on board the autonomous vehicle 1, in this example, the driver, attempts to get off the vehicle will be described.
[0125] In this embodiment, when a user who has been aboard the autonomous vehicle 1, in this example, particularly the driver, attempts to get off the vehicle, the autonomous vehicle 1 inquires of the driver about to get off as to whether or not to set a behavior after getting off. In response to this inquiry, if the driver inputs a setting for a behavior after getting off the vehicle, the autonomous vehicle 1 accepts the setting input for the behavior after getting off the vehicle from the driver, and performs processing according to the behavior after getting off the vehicle that has been accepted after the driver gets off the vehicle.
[0126] Fig. 5 is a flowchart for explaining an example of the flow of processing operations executed by the control unit 101 of the electronic control circuit unit 10 of the autonomous vehicle 1 when the driver gets off the vehicle. Note that the processing of each step in the flowchart of Fig. 5 will be explained assuming that each processing function of the post-getting-off behavior setting acceptance unit 116 and the behavior control management unit 117 is realized as software processing performed by the control unit 101 executing a program.
[0127] The control unit 101 determines whether or not the driver has stopped driving the motor drive unit 131 of the vehicle (step S1). If it is determined in step S1 that the motor drive unit 131 has not been stopped, the control unit 101 continues the control required during driving (step S2), and then returns to step S1.
[0128] When it is determined in step S1 that the drive of motor drive unit 131 has been stopped, it is generally expected that the driver will get off the vehicle, so that control unit 101 displays a message on display unit 111 inquiring whether or not to set behavior after getting off the vehicle, and also emits the message as a sound through speaker 136 (step S3).
[0129] The control unit 101 monitors and determines the answer from the driver to the inquiry in step S3 as to whether or not to set the behavior after getting off (step S4), and when it determines that the driver has responded that he or she will not set the behavior after getting off, ends the processing routine of FIG. 5. In this case, the autonomous vehicle 1 stops the motor drive unit 131 at the position where the driver got off, and turns off the power while maintaining power supply to parts required for processing while stopped. In addition, a predetermined behavior for when the driver does not set the behavior after getting off may be set in advance and executed. The predetermined behavior may be schedule information.
[0130] If it is determined in step S4 that the driver has responded that he or she will set the behavior after disembarking, the control unit 101 displays the behavior after disembarking stored in the memory unit 116M on the display screen of the display unit 111 as a list as shown in FIG. 4 (step S5).
[0131] Next, the control unit 101 monitors the user's input operation via the touch panel 112 and waits for the acceptance of a selection operation of a post-disembarking behavior from the list displayed on the display screen (step S6). When it is determined in this step S6 that a selection operation of a post-disembarking behavior from the list has been accepted, the control unit 101 performs a process for accepting the selected post-disembarking behavior (step S7). The acceptance process of the selected post-disembarking behavior in step S7 will be described in detail later.
[0132] Next, the control unit 101 determines whether the process for accepting the selected behavior after getting off has been completed (step S8), and when it is determined that the process for accepting the selected behavior after getting off has been completed, it stores the selection information of the behavior after getting off selected by the user and the information associated therewith (step S9). If the process for accepting the selected behavior after getting off is not completed within a predetermined time (for example, 10 minutes), it may determine that the user does not set the behavior after getting off, and end the processing routine of FIG. 5. In this case, as described above, the autonomous vehicle 1 stops the motor drive unit 131 at the position where the driver gets off, and turns off the power while maintaining power supply to the parts required for processing during the stop. In addition, a predetermined behavior in the case where the driver does not set the behavior after getting off may be set in advance and executed. The predetermined behavior set in advance may be schedule information.
[0133] Next, the control unit 101 confirms that the user has dismounted using a door sensor or the like, and determines whether or not the driver is present (step S10). The presence or absence of the driver is determined from a seating sensor consisting of a weight sensor, a pressure sensor, or the like provided in the driver's seat, a touch sensor that determines whether or not a person has touched the steering wheel or the touch panel 112, and an image captured by a camera in the camera group 107 for capturing an image of the driver in the driver's seat. Alternatively, the presence or absence of the voice of the driver in the driver's seat collected by the microphone 137 is determined. Then, if the driver is present, the control unit 101 waits for the driver to dismount, and when it is determined in step S10 that the driver has dismounted and is no longer present, the control unit 101 executes the selected post-dismount behavior that has been stored (step S11). In this step S11, when the autonomous vehicle 1 travels and moves, the autonomous vehicle 1 travels autonomously in an autonomous driving mode.
[0134] [Program update summary] As shown in FIG. 6, an autonomous vehicle 1 in this embodiment uses a wireless communication unit 123 to connect to a program update server 3 via the Internet 2, and executes updates of programs installed in the vehicle.
[0135] In this case, the program update server 3 is equipped with a client information storage management unit 31 that stores and manages one or more programs installed in each autonomous vehicle 1 in correspondence with the automobile identification information (corresponding to the mobile device identification information) of each autonomous vehicle 1 (client), and an update program management control unit 32 that manages and controls the provision of update program information to each autonomous vehicle 1. The client information storage management unit 31 also stores connection information (such as a mobile phone number and a URL (Uniform Resource Locator)) for connecting to each autonomous vehicle via the Internet.
[0136] The stored information in client information storage management unit 31 is stored by each autonomous vehicle 1 connecting to program update server 3 via the Internet 2 and registering it in advance as a client. Alternatively, a sales company or manufacturer of autonomous vehicles 1 may store in advance, in client information storage management unit 31 of program update server 3, identification information for one or more installed programs (program identification information) corresponding to the vehicle identification information of each autonomous vehicle 1, and connection information for wirelessly connecting to each autonomous vehicle 1 via wireless communication unit 123.
[0137] Information about the update program is provided to update program management control unit 32 and temporarily stores it. Update program management control unit 32 transmits the temporarily stored information about the update program to client autonomous vehicles 1 that require a program update using the information about the update program, causing the program update to be executed. When the program update is completed, autonomous vehicles 1 notify program update server 3 of the update completion. Upon receiving this update completion notification, program update server 3 grasps the completion of the update program for each autonomous vehicle, and when the provision of the update program to all required autonomous vehicles 1 is completed, it erases the update program from the temporary storage unit, and the program update is completed.
[0138] In this case, there are two ways for the program update server 3 to provide information about the update program to each client's autonomous vehicle 1, as shown in Fig. 6. The first method is a method in which the program update server 3 notifies each client's autonomous vehicle 1 of the existence of an update program by sending an update notification, as shown by the combination of autonomous vehicle 1 and program update server 3 on the left side of Fig. 6, and the information about the update program is downloaded to autonomous vehicles 1 that respond.
[0139] The second method, as shown as the combination of autonomous vehicle 1 and program update server 3 on the right side of Figure 6, is a method in which autonomous vehicle 1 makes an update inquiry to ask whether an update program exists, and the program update server 3 determines in response to this update inquiry whether there is an update program to provide to the autonomous vehicle 1 that made the update inquiry at that time, and if it determines that there is an update program, it provides information about the update program to the autonomous vehicle 1 that made the update inquiry.
[0140] In this embodiment, the information on the update program includes program identification information indicating which software program the update program is, information on the time required to update the program using the update program (update time information), and update program / mode type identification information for identifying the type of the information on the update program. The update program / mode type identification information is identification information for identifying the type of the information on the update program, whether it is for a driving support program or for a program for a purpose other than driving, and, when the information on the update program is for a driving support program, for identifying the type of the information on the update program, whether it is for one of a plurality of driving modes (mobile modes) or for the shared mode.
[0141] In this embodiment, as the update program / mode type identification information, the information on the update program for the program for the non-driving purpose includes a non-driving purpose ID (Identification). In the case of the information on the update program for the driving support program, the manual driving mode ID is included in the program for the manual driving mode, the automatic driving mode ID is included in the program for the automatic driving mode, and the common mode ID is included in the program shared by the manual driving mode and the automatic driving mode, respectively, as the update program / mode type identification information.
[0142] The program update server 3 and the program update management control unit 119 of the autonomously driven vehicle 1 use this update program / mode type identification information to manage information about the update programs of the respective software programs and execute update control processing.
[0143] The above-mentioned first method is executed by the update notification monitoring means 1191, the update program acquisition means 1193, the update program / mode type identification means 1194, and the program update control means 1195, which are among the functional means of the program update management control unit 119 of the autonomous vehicle 1 shown in Figure 3, using the memory unit 119M and in cooperation with the behavior control management unit 117.
[0144] In this embodiment of the first method described above, the update notification monitoring means 1191 of the program update management control unit 119 of the autonomously driven vehicle 1 monitors the reception of an update notification from the program update server 3 via the wireless communication unit 123. Then, when the update notification monitoring means 1191 detects that an update notification has been received from the program update server 3, it starts up the update program acquisition means 1193, downloads information about the update program from the program update server 3, acquires the information about the update program, and temporarily stores the acquired information about the update program in a buffer area of the storage unit 119M.
[0145] When the update program information is acquired by the update program acquisition means 1193, the update program / mode type identification means 1194 is started, and by referring to the update program / mode type identification information included in the update program information, detects whether the acquired update program information is for a program for non-driving purposes or for a driving support program. Then, when it is detected that the acquired update program information is for a driving support program, it further detects whether it is for a manual driving mode, an automatic driving mode, or a shared mode. Then, it passes the detection result to the program update control means 1195.
[0146] When the program update control means 1195 determines from the detection result received from the update program / mode type identification means 1194 that the acquired update program information is for a program for purposes other than driving, it executes the update using the acquired update program information as is. This is because if the program is for purposes other than driving, there is no risk in updating the program even when the vehicle is driving, not just when the vehicle is stopped.
[0147] Next, when the program update control means 1195 determines that the detection result received from the update program / mode type identification means 1194 indicates that the acquired update program information is for a driving assistance program, it queries the vehicle state determination means 1172 of the behavior control management unit 117 to identify whether the vehicle is stopped or driving.
[0148] Then, when the program update control means 1195 determines that the vehicle is stopped, it recognizes the update time from the update time information included in the acquired update program information, queries the stop duration prediction means 1174 of the behavior control management unit 117 to obtain the predicted stop duration, determines whether or not the program can be updated during the stop duration, and if possible, executes the update using the acquired update program. This is because, if the vehicle is stopped, there is no danger in updating the driving assistance program regardless of the driving mode.
[0149] When the program update control means 1195 determines that the driving assistance program cannot be updated during the stop duration, it stores and holds the acquired information about the update program in the memory unit 119M, and executes the update later when the update is possible.
[0150] Next, when the program update control means 1195 determines that the vehicle is not stopped but is driving, it queries the driving mode detection means 1171 of the behavior control management unit 117 to detect whether the driving mode at that time (the time when the update program information is obtained) is manual driving mode or automatic driving mode.
[0151] Then, the program update control means 1195 determines whether or not it is possible to update the corresponding program using the acquired update program information based on the mode type identification result by the update program / mode type identification means 1194 and the detection result by the driving mode detection means 1171 of the behavior control management unit 117, and if it is determined that it is possible, executes the program update.
[0152] That is, when the program update control means 1195 determines that the information of the update program acquired by the update program acquisition means 1193 is for the driving mode detected by the driving mode detection means 1171 based on the detection result of the driving mode detection means 1171 and the identification result of the update program / mode type identification information by the update program / mode type identification means 1194, the program update control means 1195 controls not to update the driving support program regardless of whether the driving support program to be updated is being executed or not. This is because updating the driving support program for the current driving mode is dangerous. The reason why the driving support program to be updated is not updated regardless of whether it is being executed or not is because it is expected to be started in the driving mode even if it is not being executed at the moment, and also to eliminate the need to monitor whether each driving support program is running or not.
[0153] Furthermore, when the program update control means 1195 determines that the information on the update program acquired by the update program acquisition means 1193 is not for the driving mode detected by the driving mode detection means 1171, it performs control to execute an update of the driving support program using the acquired information on the update program. This is because updating a driving support program that is being executed or is scheduled to be executed may make it difficult to maintain safe driving.
[0154] Specifically, when the driving mode of the vehicle at the time when the information on the update program is acquired is the manual driving mode, the program update control means 1195 controls to prohibit the update of the driving support program for the manual driving mode and to execute the update of the driving support program for the automatic driving mode. Also, when the driving mode of the vehicle at the time when the information on the update program is acquired is the automatic driving mode, the program update control means 1195 controls to prohibit the update of the driving support program for the automatic driving mode and to execute the update of the driving support program for the manual driving mode.
[0155] When the information on the update program is for the shared mode, it is determined that the information on the update program is for the current driving mode, regardless of whether the driving mode of the host vehicle at the time when the information on the update program is acquired is the manual driving mode or the automatic driving mode, and therefore updating using the information on the update program is prohibited. Therefore, in the case of this embodiment, when the information on the update program is for the shared mode, updating is possible only when the state of the host vehicle at the time when the information on the update program is acquired is stopped.
[0156] When the program update control means 1195 determines that the driving assistance program cannot be updated while driving, it stores and holds the acquired information about the update program in the memory unit 119M, and executes the update later when the update is possible.
[0157] Next, the second method is executed by update inquiry means 1192, update program acquisition means 1193, update program / mode type identification means 1194, and program update control means 1195, which are among the functional means of program update management control unit 119 of autonomous vehicle 1 shown in Fig. 3, using memory unit 119M and in cooperation with behavior control management unit 117. That is, the second method differs from the first method in that update inquiry means 1192 is used instead of update notification monitoring means 1191.
[0158] In the second method, the update inquiry means 1192 of the program update management control unit 119 of the autonomous vehicle 1 sends an inquiry to the program update server 3 via the wireless communication unit 123 as to whether or not an update program is available when the update notification monitoring means 1191 has not received an update notification from the program update server 3 and no other tasks are being executed.
[0159] When program update server 3 receives this update inquiry, it certifies automatically-driven vehicle 1 of the client that made the update inquiry from its identification information, and client information storage management unit 31 and update program management control unit 32 determine whether or not there is an update program that should be provided to automatically-driven vehicle 1 of the client. Then, when it is determined that there is an update program, update program management control unit 32 transmits information about the update program to automatically-driven vehicle 1 that made the update inquiry, and provides it to the automatically-driven vehicle 1.
[0160] The update program acquisition means 1193 of the program update management control unit 119 acquires information on the update program sent from the program update server. Then, the program update control means 1195 judges whether the acquired information on the update program is updateable or not, and if the update is updateable, executes the update, and if the update is not updateable, stores the acquired information on the update program in the storage unit 119M, and executes the update later when the update is possible.
[0161] In this case, in the second method, when making an update inquiry, an update inquiry is made for all programs without placing any restrictions on the type of program, and information on the update programs is obtained from server 3. The obtained information on the update programs is then processed in the same manner as in the first method described above to determine whether or not the update can be performed, and the update can be performed or information on update programs that cannot be updated at the current time can be stored.
[0162] However, in the second method of this embodiment, particularly when autonomous vehicle 1 makes an update inquiry to server 3, the request is made only to information about update programs that can be updated in autonomous vehicle 1 at that time. In other words, the types of programs for which an update inquiry is made are limited, and only information about update programs for programs that can be updated is obtained.
[0163] In the second method of this embodiment, the state of the vehicle when making the update inquiry is determined to be either stopped or running, and if the vehicle is stopped, an inquiry is made as to whether or not there is information on update programs for all programs, regardless of the update program / mode type identification information. If the vehicle is running when making the update inquiry, the driving mode is identified, and an inquiry is made only about information on update programs for driving modes other than the identified driving mode.
[0164] [Example of program update process flow] Hereinafter, a specific example of the flow of the above-mentioned program update process will be described with reference to a flowchart. In the following explanation of the flowchart, the operation of each step will be described assuming that the control unit 101 executes each functional unit including each functional means of the behavior control management unit 117 and the program update management control unit 119 of the electronic control circuit unit 10 shown in FIG. 1 as software by a program.
[0165] FIG. 7 is a flowchart illustrating the flow of a main routine of the program update process in this embodiment.
[0166] The control unit 101 first determines whether or not an update notification has been received from the program update server 3 (step S21). If it is determined in step S21 that an update notification has been received, the control unit 101 executes an update notification receiving process, which is the process of the first method described above (step S22), and returns to step S21 when the process is completed.
[0167] If it is determined in step S21 that an update notification has not been received, the control unit 101 determines whether or not it is time to send an update inquiry to the program update server 3 to inquire whether an update program is available (step S23). If it is determined in step S23 that it is time to send an update inquiry, the control unit 101 executes the update inquiry process, which is the process of the second method described above (step S24), and returns to step S21 when the process is completed.
[0168] If it is determined in step S23 that it is not time to send an update inquiry, it is determined whether or not the information on the update program acquired from the program update server 3 is stored (step S25). If it is determined in step S25 that the information on the update program is stored, the control unit 101 executes processing on the stored information on the update program (step S26), and when the processing is completed, the process returns to step S21.
[0169] If it is determined in step S25 that the information on the update program is not stored, control unit 101 executes other processes (step S27), and when the processes are completed, returns the process to step S21.
[0170] Next, the detailed flow of the processing operations in steps S22, S24, and S26 in FIG. 7 will be described with reference to the flowcharts in FIG. 8 and subsequent figures.
[0171] <Update Notification Reception Process in Step S22 (corresponding to the First Method)> 8 to 10 show a flowchart for explaining the flow of the update notification receiving process in step S22. As shown in FIG. 7, when the control unit 101 receives a program update notification from the program update server 3 (hereinafter, abbreviated as server 3) in the wireless communication unit 123, the control unit 101 starts the process shown in FIGS. 8 to 10.
[0172] Upon receiving a program update notification from the server 3, the control unit 101 returns a response to the update notification to the server 3 (step S101). Then, information on the update program including program identification information, update program / mode type identification information, and update time information is downloaded from the server 3, and the control unit 101 receives and acquires the information on the update program via the wireless communication unit 123 (step S102).
[0173] Then, the control unit 101 determines whether the update program is for driving support or not from the update program mode type identification information included in the acquired information of the update program (step S103). If it is determined in step S103 that the update program is not for driving support but for a purpose other than driving, the control unit 101 uses the acquired information of the update program to execute an update of the corresponding program for a purpose other than driving (step S104).
[0174] Then, control unit 101 waits for the program update to be completed (step S105), and when it determines that the program update has been completed, it notifies server 3 of the completion of the program update via wireless communication unit 123 (step S106). This program update completion notification includes identification information of autonomous vehicle 1 and identification information of the program for which the update has been completed. Upon receiving this update completion notification, server 3 determines which autonomous vehicle 1 and which program the update has been completed for, and reflects this determination result in the update history information of client information storage management unit 31. Each time server 3 receives an update completion notification, it performs a process of writing the update history information.
[0175] After step S106, the control unit 101 ends this update notification receiving process, and returns the process to the main routine of FIG.
[0176] Furthermore, when it is determined in step S103 that the acquired update program information is for driving support, the control unit 101 determines whether or not the vehicle is stopped (step S107). When it is determined in this step S107 that the vehicle is stopped, the control unit 101 grasps the update time from the update time information included in the acquired update program information (step S108). Next, the control unit 101 acquires information on the stop duration predicted by the function of the stop duration prediction means 1174 of the behavior control management unit 117, and predicts the stop duration from the current time (step S111 in FIG. 9).
[0177] Then, the control unit 101 determines whether or not the driving support program can be updated within the predicted stop duration from the current time based on the update time information and the information on the predicted stop duration from the current time (step S112). When it is determined in step S112 that the driving support program can be updated within the predicted stop duration from the current time, the control unit 101 executes the update of the corresponding driving support program using the acquired update program information (step S113).
[0178] Then, the control unit 101 determines whether the update of the driving assistance program is completed (step S114), and when it determines that the program update is not completed, it determines whether a request to start driving has been made by the driver or passenger (step S116), and when it determines that a request to start driving has been made by the driver or passenger, it displays a message such as "Driving cannot be started because the program is being updated. Please wait" on the display screen of the display unit 111 and notifies the user by emitting a sound from the speaker 136 (step S117). Then, after this step S117, the control unit 101 returns the process to step S114 and repeats the processes from step S114 onwards.
[0179] When it is determined in step S116 that the driver has not issued a request to start driving, the control unit 101 determines whether or not a call request has been received (step S118), and when it is determined that a call request has been received, for example, a message such as "Because the program is being updated, it is not possible to start driving in response to the call. Please wait." is displayed on the display screen of the display unit 111, and a sound is emitted from the speaker 136 to notify the driver (step S119). After step S119, the control unit 101 returns the process to step S114, and repeats the process from step S114 onwards. Also, when it is determined in step S118 that the call request has not been received, the control unit 101 returns the process to step S114, and repeats the process from step S114 onwards.
[0180] Then, when it is determined in step S114 that the update of the driving assistance program is completed, the control unit 101 notifies the server 3 of the completion of the update of the program via the wireless communication unit 123 (step S115). Then, the control unit 101 ends this update notification reception process, and returns the process to the main routine of FIG.
[0181] Furthermore, when it is determined in step S112 that it is not possible to update the driving assistance program within the predicted duration of the stop from the current time point, the control unit 101 stores information about the update program downloaded and acquired from the server 3 in the memory unit 117M (step S120), and then ends this update notification reception process and returns the process to the main routine of FIG. 7.
[0182] Then, when it is determined in step S107 in Fig. 8 that the vehicle is not stopped but is traveling, the control unit 101 identifies which traveling mode the update program is for from the update program / mode type identification information included in the acquired update program information (step S131 in Fig. 10). Then, the control unit 101 determines whether the update program is for the shared mode or not from the identification result in step S131 (step S132), and when it is determined that the update program is for the shared mode, the control unit 101 stores the information of the update program downloaded and acquired from the server 3 in the storage unit 117M (step S133), and then ends this update notification receiving process and returns the process to the main routine in Fig. 7.
[0183] When it is determined in step S132 that the update program is not for the shared mode, the control unit 101 detects the current driving mode by the function of the driving mode detection means 1171 of the behavior control management unit 117 (step S134). Then, the control unit 101 determines whether the acquired information on the update program is for the running driving mode or not, based on the identification result of which driving mode the update program is for in step S131 and the detection result in step S134 (step S135).
[0184] If it is determined in step S135 that the acquired information on the update program is for the running mode being executed, the control unit 101 stores the information on the update program downloaded and acquired from the server 3 in the memory unit 117M (step S136), and then ends this update notification receiving process and returns the process to the main routine of FIG. 7.
[0185] Furthermore, when it is determined in step S135 that the acquired information on the update program is not for the running driving mode, the control unit 101 uses the acquired information on the update program to execute an update of the driving assistance program to be updated (step S137).
[0186] Then, the control unit 101 determines whether the update of the driving support program is completed (step S138), and when it is determined that the update of the program is not completed, it determines whether the driver or the passenger has received an instruction to switch the driving mode (step S140). When it is determined that the driver or the passenger has received an instruction to switch the driving mode, for example, a message "The driving mode cannot be switched because the program is being updated. Please wait." is displayed on the display screen of the display unit 111, and a sound is emitted from the speaker 136 to notify the driver or the passenger (step S141). After this step S141, the control unit 101 returns the process to step S138 and repeats the process from step S138 onwards. Also, when it is determined in step S140 that the driver or the passenger has not received an instruction to switch the driving mode, it returns the process to step S138 and repeats the process from step S138 onwards.
[0187] Then, when it is determined in step S138 that the update of the driving assistance program is completed, the control unit 101 notifies the server 3 of the completion of the update of the program via the wireless communication unit 123 (step S139). Then, the control unit 101 ends this update notification reception process, and returns the process to the main routine of FIG.
[0188] In this embodiment, the autonomous vehicle 1 has only two driving modes, a manual driving mode and an autonomous driving mode, so in steps S140 and S141, when an instruction to switch the driving mode is given, the driving mode after the switch is not identified, and a notification is given that the driving mode cannot be switched because a program is being updated. However, if there are three or more driving modes, the driving mode after the switch is identified, and if the identified driving mode after the switch is for the driving mode in the information of the update program, a notification is given that the driving mode cannot be switched because a program is being updated, and if the identified driving mode after the switch is not for the driving mode in the information of the update program, the switching may be permitted.
[0189] <Update inquiry process in step S24 (corresponding to the second method)> 11 to 13 show a flowchart for explaining the flow of the update inquiry processing in step S24. As shown in FIG. 7, when the control unit 101 determines that it is time to send an update inquiry to the program update server 3, it starts the processing shown in FIGS. 11 to 13.
[0190] First, the control unit 101 determines whether the current state of the vehicle is a stopped state or a moving state (step S151). Then, the control unit 101 determines whether the determined state is a stopped state or not (step S152).
[0191] When it is determined in step S152 that the vehicle is at a stop, since all programs can be updated in the stopped state, the control unit 101 transmits an update inquiry for all programs to the server 3 via the wireless communication unit 123 (step S153). This update inquiry includes the identification information of the vehicle and information indicating that the inquiry is for updating all programs.
[0192] In response to this update inquiry, the server 3 determines whether there is any information about an incomplete update program for the autonomous vehicle 1 of the client that made the update inquiry, and if there is no information about the update program, it sends a notification that there is no update program to the autonomous vehicle 1 that made the update inquiry, and if there is information about the update program, it downloads the information about the update program to the autonomous vehicle 1 that made the inquiry along with a notification that information about the update program exists.
[0193] Therefore, the control unit 101 that sent the update inquiry determines whether or not a notification that there is no update program has been received from the server 3 (step S154), and if it determines that a notification that there is no update program has been received, the control unit 101 ends this update inquiry process and returns the process to the main routine of FIG. 7.
[0194] When it is determined in step S154 that a notification that an update program exists, rather than a notification that an update program is not available, has been received, the control unit 101 downloads the update program information from the server 3 and acquires the update program information (step S155). Next, the control unit 101 determines whether the acquired update program information is a driving assistance program (step S156), and if it is determined that it is a driving assistance program, it determines the update time from the acquired update program information (step S157).
[0195] Then, the control unit 101 predicts the duration of the stoppage by using the function of the stoppage duration prediction means of the behavior control management unit 117 (step S158), and determines whether or not the program can be updated within the predicted duration of the stoppage from the current time point based on the predicted information on the duration of the stoppage and the information on the update time acquired in step S156 (step S159). If it is determined in step S159 that the program can be updated within the predicted duration of the stoppage from the current time point, the control unit 101 uses the acquired information on the update program to execute the update of the corresponding program (step S161 in FIG. 12).
[0196] Also, when it is determined in step S156 that the acquired update program information is not a driving assistance program, the control unit 101 proceeds to step S161 in FIG. 12 and executes an update of the corresponding program using the acquired update program information.
[0197] After step S161, the control unit 101 determines whether or not the program update has been completed (step S162). If it determines that the program update has not been completed, it determines whether or not the program being updated is a driving assistance program (step S163). If it determines that the program is not a driving assistance program but a program for a purpose other than driving, it returns the process to step S162 and repeats the processes from step S162 onwards.
[0198] When it is determined in step S163 that the program being updated is a driving assistance program, the control unit 101 determines whether or not a request to start driving has been made by the driver (step S164), and when it is determined that a request to start driving has been made by the driver, for example, a message "Driving cannot be started because the program is being updated. Please wait" is displayed on the display screen of the display unit 111, and a sound is emitted from the speaker 136 to notify the driver (step S165). Then, after step S165, the control unit 101 returns the process to step S162, and repeats the processes from step S162 onwards.
[0199] When it is determined in step S164 that the driver has not issued a request to start driving, the control unit 101 determines whether or not a call request has been received (step S166), and when it is determined that a call request has been received, for example, a message such as "Because the program is being updated, it is not possible to start driving in response to the call. Please wait." is displayed on the display screen of the display unit 111, and a sound is emitted from the speaker 136 to notify the driver (step S167). Then, after step S167, the control unit 101 returns the process to step S162 and repeats the process from step S162 onwards. Also, when it is determined in step S166 that the call request has not been received, the control unit 101 returns the process to step S162 and repeats the process from step S162 onwards.
[0200] Then, when it is determined in step S162 that the program update is complete, the control unit 101 notifies the server 3 of the program update completion via the wireless communication unit 123 (step S168). Then, the control unit 101 inquires of the server 3 as to whether or not there are any further uncompleted update programs (step S169).
[0201] The control unit 101 acquires a response from the server 3 to the inquiry in step S169, and determines whether or not there is any further uncompleted update program (step S170). If it is determined in step S170 that the response indicates that there is no further update program, the control unit 101 ends this update inquiry process, and returns the process to the main routine in FIG.
[0202] Also, when it is determined in step S170 that a response has been received indicating that a further update program exists, control unit 101 returns the process to step S155 in FIG. 11, and repeats the processes from step S155 onwards.
[0203] 11, when it is determined that the program cannot be updated within the predicted duration of the stop from the current time point, the control unit 101 stores and holds the information on the update program acquired in step S157 (step S160).Then, the control unit 101 shifts the process to step S169 in FIG. 12, and repeats the process from step S169 onward.
[0204] 11, when it is determined that the vehicle is not stopped but is moving, the control unit 101 detects the current driving mode by the function of the driving mode detection means 1171 of the behavior control management unit 117 (step S171 in FIG. 13). Updating of the programs for the detected driving mode and shared mode is not possible in the current driving mode.
[0205] The control unit 101 transmits an update inquiry about the updatable program to the server 3 through the wireless communication unit 123 while the vehicle is traveling in the detected current traveling mode (step S172). In this case, the update inquiry includes the identification information of the vehicle itself and information for identifying the updatable program.
[0206] Here, as information for identifying an updatable program, for example, update program mode type identification information of the update program information of the updatable program is used. For example, when the current driving mode is the manual driving mode, it is possible to update the programs for the automatic driving mode and for uses other than driving, so the update program mode type identification information of the information of those update programs is included in the update inquiry. Also, when the current driving mode is the automatic driving mode, it is possible to update the programs for the manual driving mode and for uses other than driving, so the update program mode type identification information of the information of those update programs is included in the update inquiry. Since the programs for the shared mode cannot be updated in any driving mode, they are not included as updatable programs in the update inquiry.
[0207] In addition, in step S172, the autonomously driven vehicle 1 may notify the server 3 of update program / mode type identification information for information on an update program for a program that cannot be updated, and may notify the server 3 that an inquiry is being made for information on an update program having other update program / mode type identification information.
[0208] In response to the update inquiry in step S172, the server 3 determines whether or not there is information about an update program for a program that is considered to be updatable at that time, and if there is no information about the update program, it sends a notification that there is no update program to the autonomously driven vehicle 1 that made the update inquiry, and if there is information about the update program, it downloads the information about the update program to the autonomously driven vehicle 1 that made the inquiry along with a notification that information about the update program exists.
[0209] Therefore, the control unit 101 that sent the update inquiry determines whether or not a notification that there is no update program has been received from the server 3 (step S173), and if it determines that a notification that there is no update program has been received, the control unit 101 ends this update inquiry process and returns the process to the main routine of FIG. 7.
[0210] If it is determined in step S173 that a notification that an update program exists has been received, rather than a notification that an update program is not available, then control unit 101 downloads the update program information from server 3 and acquires the update program information (step S174). Then, control unit 101 uses the acquired update program information to execute an update of the program to be updated (step S175).
[0211] Then, the control unit 101 determines whether or not the update of the driving assistance program has been completed (step S176), and if it determines that the program update has not been completed, it determines whether or not the program being updated is a driving assistance program (step S178), and if it determines that the program is not a driving assistance program but a program for a purpose other than driving, returns the process to step S176 and repeats the processes from step S176 onwards.
[0212] If it is determined in step S178 that the program being updated is a driving assistance program, the control unit 101 determines whether or not an instruction to switch the driving mode has been received from the driver or passenger (step S179), and if it is determined that an instruction to switch has not been received, the process returns to step S176, and the processes from step S176 onwards are repeated.
[0213] Then, when it is determined in step S179 that an instruction to switch the driving mode has been received from the driver or passenger, the control unit 101 displays a message, for example, "The driving mode cannot be switched because the program is being updated. Please wait" on the display screen of the display unit 111 and notifies the user by emitting a sound from the speaker 136 (step S180). After step S180, the control unit 101 returns the process to step S176 and repeats the processes from step S176 onwards.
[0214] Then, when it is determined in step S176 that the update of the driving assistance program is completed, the control unit 101 notifies the server 3 of the completion of the update of the program via the wireless communication unit 123 (step S177). Then, the control unit 101 shifts the process to step S169 in Fig. 12 and executes the processes from this step S169 onwards.
[0215] <Processing of the stored update program in step S26> 14 to 16 show a flowchart for explaining the flow of processing for the stored update program in step S26. As shown in FIG. 7, the control unit 101 starts the processing shown in FIG. 14 to 16 when it determines that a predetermined timing has come when the control unit 101 has not received an update notification from the server 3 and has not made an update inquiry to the program update server 3. In this case, in this embodiment, the program for use other than driving is updated without any restrictions and is not stored in the storage unit 119M, and in the following description, only the information on the update program for the driving support program is processed. Note that in the example of the following description, it is assumed that the information on the stored update programs is processed in order of oldest to newest, taking into consideration the case where the information on a plurality of update programs is stored in the storage unit 119M.
[0216] The control unit 101 first reads out the oldest update program information from the storage unit 119M (step S181). Then, the control unit 101 grasps the update program / mode type identification information of the read update program information and determines whether the update program information is for the manual operation mode, the automatic operation mode, or the shared mode (step S182).
[0217] Then, the control unit 101 determines whether the read update program information is for the shared mode (step S183). If it is determined in this step S183 that the read update program information is for the shared mode, the control unit 101 determines whether the host vehicle is in a stopped state (step S184).
[0218] If it is determined in step S184 that the vehicle is not stopped but is moving, updating of the program for the common mode is not possible, so the control unit 101 determines whether or not all processing of the update program information stored in the memory unit 119M has been completed (step S185), and if it is determined that all processing has been completed, ends processing of the stored update program information and returns to the main routine of FIG. 7.
[0219] If it is determined in step S185 that all the processing of the update program information stored in storage unit 119M has not been completed and that there is unprocessed information, control unit 101 reads out the next oldest update program information from storage unit 119M (step S186). Then, after step S186, control unit 101 returns the process to step S182 and performs the processes from step S182 onward.
[0220] When it is determined in step S184 that the vehicle is in a stopped state, the update time is ascertained from the read update program information (step S187). Then, the control unit 101 predicts the stopped duration using the function of the stopped duration prediction means of the behavior control management unit 117 (step S188), and determines whether or not the driving support program to be updated can be updated within the predicted stopped duration from the current time point, based on the predicted stopped duration information and the update time information obtained in step S187 (step S189).
[0221] If it is determined in step S189 that the driving support program to be updated cannot be updated within the predicted duration of the stop from the current time, the control unit 101 shifts the process to step S185 and executes the processes from step S185 onward. If it is determined in step S189 that the driving support program to be updated can be updated within the predicted duration of the stop from the current time, the control unit 101 executes the update of the driving support program to be updated using the acquired information on the update program (step S190).
[0222] Then, the control unit 101 determines whether the update of the driving support program has been completed (step S191 in FIG. 15), and if it determines that the update of the driving support program has not been completed, determines whether a request to start driving has been made by the driver or a passenger (step S192), and if it determines that a request to start driving has been made by the driver or a passenger, displays a message such as "Driving cannot be started because the program is being updated. Please wait" on the display screen of the display unit 111 and notifies the user by emitting a sound from the speaker 136 (step S193). Then, after step S193, the control unit 101 returns the process to step S191 and repeats the processes from step S191 onward.
[0223] When it is determined in step S192 that the driver has not issued a request to start driving, the control unit 101 determines whether or not a call request has been received (step S194), and when it is determined that a call request has been received, for example, a message such as "Because the program is being updated, it is not possible to start driving in response to the call. Please wait." is displayed on the display screen of the display unit 111, and a sound is emitted from the speaker 136 to notify the driver (step S195). After step S195, the control unit 101 returns the process to step S191 and repeats the process from step S191 onward. Also, when it is determined in step S194 that the call request has not been received, the control unit 101 returns the process to step S191 and repeats the process from step S191 onward.
[0224] Then, when it is determined in step S191 that the update of the driving support program is completed, the control unit 101 notifies the server 3 of the completion of the update of the driving support program through the wireless communication unit 123 (step S196). Then, the control unit 101 erases the information of the update program of the driving support program for which the update has been completed from the storage unit 119M (step S197). Then, thereafter, the control unit 101 shifts the process to step S185 in Fig. 14 and performs the processes from this step S185 onwards.
[0225] Next, when it is determined in step S183 in Fig. 14 that the read update program information is not for the shared mode, the control unit 101 determines whether the vehicle is stopped or not (step S201 in Fig. 16). When it is determined in this step S201 that the vehicle is stopped, the update is possible regardless of the driving mode, so the control unit 101 shifts the process to step S187 in Fig. 14 and executes the process from this step S187 onwards.
[0226] When it is determined in step S201 that the vehicle is not stopped but is traveling, the control unit 101 detects the traveling mode at that time (step S202). Then, the control unit 101 determines whether the information of the update program read from the storage unit 119M is for the detected traveling mode (step S203).
[0227] In step S203, when it is determined that the information on the update program read from the memory unit 119M is for the detected driving mode, the control unit 101 does not execute the update since it is dangerous to execute the update, and shifts the process to step S185 in FIG. 14, and executes the processes from step S185 onwards.
[0228] Furthermore, when it is determined in step S203 that the information of the update program read from the memory unit 119M is not for the detected driving mode, the control unit 101 executes an update of the driving assistance program using the information of the update program (step S204).
[0229] Then, the control unit 101 determines whether the update of the driving support program is completed (step S205), and when it is determined that the update of the program is not completed, it determines whether the driver or the passenger has received an instruction to switch the driving mode (step S206). When it is determined that the driver or the passenger has received an instruction to switch the driving mode, for example, a message "The driving mode cannot be switched because the program is being updated. Please wait." is displayed on the display screen of the display unit 111, and a sound is emitted from the speaker 136 to notify the driver or the passenger (step S207). After this step S207, the control unit 101 returns the process to step S205 and repeats the process from step S205 onwards. Also, when it is determined in step S206 that the driver or the passenger has not received an instruction to switch the driving mode, it returns the process to step S205 and repeats the process from step S205 onwards.
[0230] Then, when it is determined in step S205 that the update of the driving support program is completed, the control unit 101 notifies the server 3 of the completion of the update of the program through the wireless communication unit 123 (step S208). Then, the control unit 101 erases the information of the update program of the driving support program for which the update has been completed from the storage unit 119M (step S209). Then, after that, the control unit 101 shifts the process to step S185 in FIG. 14 and performs the process of step S185 and subsequent steps.
[0231] In this embodiment, the autonomous vehicle 1 has only two driving modes, a manual driving mode and an autonomous driving mode, so in steps S206 and S207, when an instruction to switch the driving mode is given, the driving mode after the switch is not identified, and a notification is given that the driving mode cannot be switched because a program is being updated. However, if there are three or more driving modes, the driving mode after the switch is identified, and if the identified driving mode after the switch is for the driving mode in the information of the update program, a notification is given that the driving mode cannot be switched because a program is being updated, and if the identified driving mode after the switch is not for the driving mode in the information of the update program, the switching may be permitted.
[0232] As described above, the autonomous vehicle 1 of the above-mentioned embodiment has multiple driving modes, and is able to identify the driving mode being executed not only when the vehicle is stopped but also when the vehicle is driving, and to execute updates of programs for driving modes other than the driving mode being executed.
[0233] Therefore, in the autonomous vehicle 1 of this embodiment, when the driving assistance program is being executed or there is a risk of it being executed, the driving assistance program is not updated, thereby ensuring safety while the vehicle is driving.
[0234] The autonomous vehicle 1 of this embodiment has the advantage that program updates can be managed only by managing the driving mode of the vehicle, and there is no need to determine the operating status of each program. Also, updates can be performed not only when the vehicle is stopped but also when the vehicle is traveling, which increases the number of update opportunities and makes it convenient to perform rapid program updates.
[0235] Furthermore, since the update of the driving assistance program is executed in a driving mode in which the driving assistance program is not used, the user's use of the program for that driving mode is not hindered, which is convenient.
[0236] Therefore, according to the autonomous vehicle 1 of this embodiment, a significant effect is achieved in that the driving assistance program can be updated at an appropriate time while giving top priority to the use of the user.
[0237] [Modifications of the embodiment] In the autonomous vehicle 1 of the embodiment described above, the stopped duration is predicted based on the post-dismounting behavior set by the user of the autonomous vehicle 1. However, the stopped duration is not predicted only based on the post-dismounting behavior set by the user. For example, the stopped duration may be predicted based on the past driving history or stopping history of the autonomous vehicle 1.
[0238] In this case, the electronic control circuit unit 10 of the autonomous vehicle 1 is provided with an application navigation function unit, a history memory, and a history analysis unit.
[0239] The purpose navigation function unit is activated by control unit 101 when a door sensor in sensor group 108 detects the opening or closing of a door and when a camera in camera group 107 detects that a passenger has gotten into the vehicle. When the purpose navigation function unit detects that a passenger has gotten into the vehicle, it inquires of the passenger about the intended use of autonomous vehicle 1 before starting autonomous vehicle 1, and confirms the intended use upon receiving a response from the passenger regarding the intended use.
[0240] Usage is categorized into non-driving uses and driving uses, and in the case of driving uses, a distinction can be made between driving in automatic driving mode and driving in manual driving mode.
[0241] In this embodiment, when the usage purpose is a driving purpose, two types are defined: "a specific destination is set (a known destination purpose)" and "a specific destination is not determined (an undetermined destination purpose)." The usage navigation function unit inquires the passenger which one to select, and also inquires whether the selected driving purpose is to be used in automatic driving mode or manual driving mode.
[0242] When the destination known purpose is selected, the purpose navigation function unit accepts the destination setting from the passenger. When "specify only the travel time to be used" is selected, the purpose navigation function unit has the passenger specify the travel time to be used and accepts it. Instead of specifying the travel time, the travel end time from the current time may be set.
[0243] In this example, the user of the vehicle is registered in advance, and an identification image (e.g., a facial image) of the registered user is stored and registered in the user image information storage unit in association with user identification information (user ID). When the user gets in the vehicle, the identification image (e.g., a facial image) stored in the user image information storage unit is used to perform image recognition of the user who has gotten in and identify the user ID.
[0244] The history memory accumulates information on past uses of the autonomous vehicle 1 by users that is stored and registered in the user image information storage unit, in association with the user ID.
[0245] An example of information stored in the history memory is shown in Fig. 17. As shown in Fig. 17, for pre-registered users, the user name and information on usage history are stored in association with the user ID. In this example, the information on usage history consists of the date and day of use, and the above-mentioned items such as the type of use, content of use, details of use, and time of use.
[0246] As the use type of the usage history, one of the two types, the driving use and the non-driving use, is stored in the history memory. In this case, when the use type is the driving use, it is stored together with information on whether the driving is in the automatic driving mode or the manual driving mode. In the example of FIG. 17, "Driving: Automatic" indicates driving in the automatic driving mode, and "Driving: Manual" indicates driving in the manual driving mode. In this example, whether the driving is in the automatic driving mode or the manual driving mode is determined as the driving mode at the start of driving. Of course, when the driving mode is switched during the trip, the switching may also be recorded as a history.
[0247] In this embodiment, when the use type is a driving use, the use contents are stored as either "use with a specific destination set (destination known)" or "use with no specific destination set (destination undecided)". When the use contents are use with a known destination, the use details store the starting point (current location) and the destination, for example, "home-XX station", as shown in FIG. 17. The starting point (current location) is recorded as the current location at the start of travel detected by the current location detection unit 110. When the use contents are use with no destination set, the use details store the usage time, for example, "return in 30 minutes", the usage end time, for example, "return by 3 p.m", and the attributes of the destination, for example, "to the nearby sea", as shown in FIG. 17.
[0248] Furthermore, when the use type is a use other than driving, the use contents are stored as either "AV / game related" using, for example, the AV entertainment function unit or the game function unit included in the use function unit other than driving 118, or "massage and others" which is a massage use using the massage mechanism drive unit, or other uses. When the use contents are "AV / game related", the use details store which AV entertainment function of the AV entertainment function unit or the game function of the game function unit, for example, "music playback" or "game", as shown in Fig. 17. When the use contents are "massage and others", the use details store, for example, "massage" or "others", as shown in Fig. 17.
[0249] In addition, the history memory may store information on each of the above items as history information for "other users" even for passengers who have not been assigned a user ID, without distinguishing between individual passengers.
[0250] The information stored in the history memory may be made erasable in whole or in part by the user or passenger. However, security is ensured by using the biometric information, ID, password, etc. of the user or passenger so that information other than that of the user or passenger cannot be erased.
[0251] The history analysis unit analyzes the history information stored in the history memory for each user (for each user ID), and detects any habitual uses (hereinafter referred to as habitual uses). The history analysis unit also analyzes not only for each user, but also for uses of multiple users with similar usage patterns and uses common to all users. Furthermore, the frequency of use may also be detected. In this case, habitual uses may be notified by preferentially inquiring. Also, the more frequently used a use is, the higher the presentation order may be, for example, so that the display is prioritized. Here, in this example, for habitual uses, the item "Use details" is targeted in the information stored in the history memory.
[0252] In this embodiment, the history analysis unit detects, for each user or for multiple users, a use (detailed use) that is habitually and repeatedly used on a specific day of the week or a use (detailed use) that is habitually and repeatedly used at a specific time of the day as a habitual use. The detection of habitual use is not limited to this, and may detect, for example, a use (detailed use) that is habitually and repeatedly used during a specific period of the year, such as New Year's Day, Chinese New Year (Spring Festival), Easter, Obon, etc., or on a specific date of a specific month of the year, such as a birthday, Valentine's Day, Halloween, Christmas Eve, Christmas, a founding anniversary, or a death anniversary, etc., as a habitual use, or may detect, as a habitual use, a use (detailed use) that is cyclically and repeatedly used every one to several days. Of course, a use (detailed use) that is habitually and repeatedly used on a specific day of the month, such as eating at a specific restaurant on payday of the month in the case of a monthly salary, may be detected as a habitual use.
[0253] In this embodiment, the history analysis unit can grasp, in the history for each user, the duration of the stop from the end time of the usage time for driving to the start time of the next driving use as the duration of the stop. Therefore, it is also possible to grasp, from the history for each user, the duration of the habitual stop corresponding to the day of the week and the time period. Therefore, when a request for a program update occurs, it is possible to grasp the day of the week and the time period at the time of the occurrence from the history information in the history memory and predict the duration of the stop.
[0254] As described above, in this example, the stop duration prediction means 1174 of the behavior control management unit 117 predicts the stop duration based on the result of analysis of the history information in the history memory by the history analysis unit. Also, the program update management control unit 119 checks the use of the vehicle at the moment of use, and uses the stop duration predicted based on the past history to determine whether or not to update the program while the vehicle is stopped. The other configurations are the same as those of the above-mentioned embodiment.
[0255] [Other Modifications of the Embodiments] In the above embodiment, when it is determined that the driving support program cannot be updated using the acquired update program information, the update program information from the server 3 is stored, and the driving support program is updated using the stored update program information during a later stop duration. However, when it is determined that the driving support program cannot be updated, the server 3 may be notified of this and the update may be rejected, and the driving support program may be updated at a later time based on an update notification from the server 3 or in response to an inquiry to the server 3.
[0256] In this case, the server 3 stores the unexecuted update program for the driving assistance program in association with the identification information of the autonomously driven vehicle, and sends an update notification for the unexecuted update program at the time of the next update notification, or provides information on the unexecuted update program in response to an inquiry from the client's autonomously driven vehicle.
[0257] In the above description of the embodiment, program update management control unit 119 does not take into account the remaining charge of battery 11 of autonomous vehicle 1 when updating the program. However, it may be possible to determine whether or not a program update is possible by taking into account the update time information included in the information about the update program and the remaining battery charge. In other words, when it is determined that the remaining battery charge cannot accommodate the update time, the update is not performed, and the information about the update program is stored in storage unit 119M. At a later point in time, when there is sufficient remaining battery charge, the update is performed as shown in FIGS. 14 to 16 above.
[0258] In the above embodiment, when a driving support program is being updated and a user issues a driving start command, the user is notified that driving cannot be started. However, the user who receives the command can also issue a command to forcibly stop the update of the driving support program. In other words, in this case, when a command to forcibly stop the update of the driving support program is received, the update of the driving support program is interrupted and the information on the update program is stored and held. Then, during the remaining period of the stop, the interrupted update of the driving support program is restarted from the beginning.
[0259] Similarly, a configuration may be adopted in which a user who has been notified that the driving support program cannot be called because it is being updated can receive an instruction to forcibly stop the update of the driving support program. In this case, when an instruction to forcibly stop the update of the driving support program is received, the update of the driving support program is interrupted and information on the update program is stored and held. Then, during the remaining period of the stoppage, the update of the driving support program that was interrupted is restarted from the beginning.
[0260] In the above-described embodiment, the description has focused on a form in which the duration of the stoppage is predicted at the time of disembarking from the post-disembarking behavior set by the user, and whether or not the driving assistance program can be updated is determined; however, even if it is not at the time of disembarking, if the period during which the user has already stopped driving at the time of boarding or while riding can be known, the duration of the stoppage (period of stoppage) may be predicted based on the period during which the user has stopped driving input when the user boards or while riding, and whether or not the driving assistance program can be updated may be determined.
[0261] [Other embodiments or modifications of the present invention] In the above embodiment, the transportation device is an automobile, but the present invention can also be applied to two-wheeled motor vehicles, such as motorcycles, and three-wheeled motor vehicles.
[0262] Furthermore, the transportation devices of the present invention include automobiles, motorcycles, three-wheeled motor vehicles, etc., and are not limited to land use only, but may also be amphibious vehicles, land-and-water vehicles (flying vehicles), air-and-water vehicles, and even vehicles that can be used both on land and water.
[0263] For example, in the case of an amphibious vehicle 1WL capable of moving on land and on or underwater, as shown in Figure 18, if the vehicle is moving on land, an update using an update program for the land movement support program is not executed, but an update using an update program for the surface movement support program or the underwater movement support program that supports movement on or underwater is executed, and conversely, if the vehicle is moving on or underwater, an update program for the surface movement support program and the underwater movement support program that supports movement on or underwater is not executed, but an update using an update program for the land movement support program is executed.
[0264] Also, for example, in the case of an air-land amphibious vehicle (flying vehicle) 1AL capable of land movement and flight (aviation, including aerial movement and hovering) as shown in FIG. 19, if the vehicle is moving on land, an update using an update program for the land movement support program is not executed, but an update using an update program for the flight (aviation) support program that supports the flight (aviation) is executed, and conversely, if the vehicle is flying, an update using an update program for the flight (aviation) support program that supports the flight (aviation) is not executed, but an update using an update program for the land movement support program is executed.
[0265] Although not shown in the figure, in the case of a land-, air-, and water-compatible vehicle capable of moving on land, on water or underwater, and flying, when in flight, updates using an update program for the flight (air) support program that supports flight (air) are not performed, but updates using an update program for the surface movement support program or underwater movement support program that supports movement on water or underwater, and updates using an update program for the land movement support program are performed.
[0266] In addition, in the case of a land-, air-, and water-compatible vehicle, while moving on water or underwater, updates using the update program for the surface movement support program and the underwater movement support program that support movement on water or underwater are not executed, but updates using the update program for the land movement support program and updates using the update program for the flight (aviation) support program that supports flight (aviation) are executed.
[0267] Furthermore, in the case of a land-, air-, and water-capable vehicle, while moving on land, updates using an update program for the land mobility support program that assists with movement on land will not be executed, but updates using an update program for the water mobility support program or the underwater mobility support program that assists with movement on or underwater, and updates using an update program for the flight (aviation) support program that assists with flight (aviation) will be executed.
[0268] In addition, since the moving device in the above embodiment is an autonomous vehicle that has only two moving modes, a manual driving mode and an autonomous driving mode, the shared mode identification information is simply information that identifies that the moving device is shared between the two modes. However, when the moving device has three or more moving modes such as the above-mentioned land-and-sea vehicle, it may be shared not only for all three or more moving modes, but also for only two or more of the three or more moving modes. In such a case, the shared mode identification information may be an identification information that uniquely corresponds to the shared moving mode, or may include all of the moving mode identification information of the shared moving modes.
[0269] In such a case, even if the mobile device is in a shared mode, if the movement mode of the mobile device at the time of acquiring information about the update program is not included in the shared mode, update using the update program is possible.
[0270] In addition, in an amphibious vehicle, an air-and-water amphibious vehicle (flying vehicle), an air-and-water amphibious vehicle, or a land-and-water / air-and-water vehicle, a water movement support program or an underwater movement support program that supports movement on water or in water, or a flight (air) support program that supports flight (air), can each have a manual driving mode and an automatic driving mode, just like a land movement support program.The automatic driving mode can support autonomous movement on water or in water using a water movement support program or an underwater movement support program for the automatic driving mode, and can support autonomous flight (air) using a flight (air) support program for the automatic driving mode. [Explanation of symbols]
[0271] 1...Autonomous driving vehicle, 3...Program update server, 10...Electronic control circuit unit, 101...Control unit, 116...After getting off the vehicle behavior setting reception unit, 117...Behavior control management unit, 119...Program update management control unit
Claims
1. an update program acquisition means for acquiring information on an update program for a movement assistance program that supports the movement of the own device; a program update control means for controlling execution of updating the mobility assistance program based on information about the update program acquired by the update program acquisition means; Equipped with The program update control means When it is determined that a request to start traveling for the vehicle has occurred and / or when it is determined that a call request to the vehicle has occurred during the update of the mobility assistance program, a message is issued to notify the vehicle of the inability to start traveling and / or a message is issued to wait for the start of traveling. A mobile device comprising:
2. The notification of the message that the vehicle cannot start traveling and / or the notification of the message that the vehicle should wait to start traveling are made by displaying the message on a display screen and / or emitting a sound.
2. The mobile device according to claim 1 .
3. A communication means for communicating with an external program update server is provided, the program update control means includes a monitoring means for monitoring whether or not a program update notification has been received from the program update server via the communication means; The update program acquisition means acquires information about the update program from the program update server via the communication means based on the reception by the monitoring means of a program update notification from the program update server.
3. The moving device according to claim 1 or 2.
4. A communication means for communicating with an external program update server is provided, the program update control means includes an update inquiry means for making an inquiry about an update of the program to the program update server through the communication means, The update program acquisition means acquires information about the update program sent from the program update server in response to the program update inquiry.
4. The moving device according to claim 1, wherein the moving device is a movable member.
5. a device status determination means for determining whether the device is moving or stopped; The program update control means, when the device status determination means determines that the device is stopped, controls the program update to be executed using the information on the update program acquired by the update program acquisition means.
5. The moving device according to claim 1, wherein the moving device is a movable member.
6. a stop duration prediction means for predicting a stop duration when the device state determination means determines that the device is stopped, When the device status determination means determines that the device is stopped, the program update control means determines whether or not the mobility assistance program can be updated based on the stop duration predicted by the stop duration prediction means and information on the update time included in the update program acquired by the update program acquisition means, and when it is determined that the update is possible, controls to execute the update of the mobility assistance program.
6. The mobile device according to claim 5.
7. a behavior receiving means for receiving from a user a setting for behavior of the device during or after the device is stopped; A behavior control management means that has a function of performing a behavior according to the setting information of the behavior of the own device received by at least the behavior reception means and controls and manages the behavior of the own device; Equipped with The stop duration prediction means queries the behavior control management means to determine the behavior of the vehicle while it is stopped, and predicts the stop duration based on the determination.
7. The mobile device according to claim 6.
8. The behavior reception unit is a post-disembarkation behavior reception unit that receives a post-disembarkation behavior setting when the user disembarks.
8. The mobile device according to claim 7.
9. The behavior receiving means receives the setting of the behavior after getting off the vehicle including time information, The stop duration prediction means predicts the stop duration based on time information included in the setting of the behavior after getting off the vehicle.
9. The mobile device according to claim 8.
10. clock means for providing clock information of year, month, date, day of the week and time; a history information storage means for storing a history of driving and stopping of the vehicle in association with the clock information; Equipped with The stop duration prediction means predicts the stop duration when the device itself is stopped by referring to the history stored in the history information storage means. The moving device according to any one of claims 6 to 9.
11. A non-mobility function unit is provided to provide functions for purposes other than mobility, the non-mobile use function unit executes the function for the non-mobile use by a program for the non-mobile use, The program for other purposes than the movement can be updated even when the device is moving. The moving device according to any one of claims 1 to 10.
12. During the update of the mobility assistance program, the start of the mobility assistance program during which the update is being executed is prohibited. The moving device according to any one of claims 1 to 11.
13. When an instruction to forcibly stop the update of the moving assistance program being executed is received during the update of the moving assistance program, the update of the moving assistance program is interrupted and information on the update program of the moving assistance program is stored and held. The moving device according to any one of claims 1 to 12.
14. When the update of the mobility support program is interrupted, the update of the interrupted mobility support program is executed in a subsequent stopped state.
14. The mobile device of claim 13.
15. The device is a car, The travel mode includes a manual driving mode and an automatic driving mode, and at least the automatic driving mode supports the driving of the vehicle using a travel support program for the automatic driving mode. The moving device according to any one of claims 1 to 14.
16. The device is a car, The travel mode includes a manual driving mode and an automatic driving mode, and supports the traveling of the host vehicle using a travel assistance program for the manual driving mode and a travel assistance program for the automatic driving mode. The moving device according to any one of claims 1 to 15.
17. A program for an automatic collision prevention system, a program for a cruise control system, or a program for a lane keep assist system is included as a mobility assistance program for a shared mode that is shared between the manual driving mode and the automatic driving mode.
17. A mobile device according to claim 15 or 16.
18. An autonomous driving mode execution control means for controlling the autonomous driving to be executed by an autonomous driving support program for supporting the autonomous driving, The travel assistance program for the automatic driving mode is the autonomous driving assistance program. The moving device according to any one of claims 15 to 17.
19. The own device is an amphibious mobile device, The multiple movement modes include a water and / or underwater movement mode in which movement on water and / or in water is performed using a dedicated movement support program, and a land movement mode in which movement on land is performed using a dedicated movement support program. The moving device according to any one of claims 1 to 14.
20. The own device is an air and land mobile device, The multiple movement modes include a flight mode in which movement in the air and / or hovering is performed using a dedicated movement support program, and a land movement mode in which movement on land is performed using a dedicated movement support program. The moving device according to any one of claims 1 to 14.
21. The device is a mobile device for water and air use, The multiple movement modes include an on-water and / or underwater movement mode in which movement on water and / or underwater is performed using a dedicated movement support program, and a flight mode in which movement in the air and / or hovering is performed using a dedicated movement support program. The moving device according to any one of claims 1 to 14.
22. The own device is an amphibious mobile device, The multiple movement modes include a water and / or underwater movement mode in which movement on water and / or underwater is performed using the dedicated movement support program, a flight mode in which movement in the air and / or hovering is performed using the dedicated movement support program, and a land movement mode in which movement on land is performed using the dedicated movement support program. The moving device according to any one of claims 1 to 14.
23. an update possibility determination means for determining whether or not the mobility assistance program can be updated based on update time information included in the update program information acquired by the update program acquisition means and a battery remaining amount, The program update control means determines whether or not to update the mobility assistance program based on a result of the determination made by the update possibility determination means. The mobile device according to any one of claims 1 to 22.
24. A computer included in the mobile device, an update program acquisition means for acquiring information on an update program for a movement assistance program that supports the movement of the own device; a program update control means for controlling execution of updating the mobility assistance program based on information about the update program acquired by the update program acquisition means; A program for a mobile device to function as The program update control means When it is determined that a request to start traveling for the vehicle has occurred and / or when it is determined that a call request to the vehicle has occurred during the update of the mobility assistance program, a message is issued to notify the vehicle of the inability to start traveling and / or a message is issued to wait for the start of traveling. A program for a mobile device.
Citation Information
Patent Citations
Amphibious motor car, and control method therefor
JP2015071344A
Ground traveling flying object
JP2015123918A
Control device, program update method, and computer program
JP2017215888A
Software update system and server
JP2018045515A
On-vehicle update device, update system, and portable communication device
JP2018100002A