vehicle

The vehicle control system ensures timely wheel fixation during autonomous driving by transmitting immobilization commands based on the vehicle's stopped state, addressing the need for safe parking in autonomous vehicles.

JP2025109793AActive Publication Date: 2025-07-25TOYOTA JIDOSHA KK
View PDF 9 Cites 0 Cited by

Patent Information

Application Number
JP2025078187
Authority / Receiving Office
JP · JP
Patent Type
Applications
Current Assignee / Owner
Filing Date
2025-05-08
Publication Date
2025-07-25
Estimated Expiration
2040-01-31

AI Technical Summary

Technical Problem

During autonomous driving, vehicles require appropriate fixation of wheels using parking brakes or locks when parked, which existing systems fail to address effectively.

Method used

A vehicle control system that includes a vehicle platform and an autonomous driving system, transmitting commands for acceleration, deceleration, and immobilization, with signals indicating the vehicle's stopped state to ensure timely wheel immobilization.

Benefits of technology

Enables appropriate wheel fixation at the right time during autonomous driving, preventing unintended movement and ensuring safety.

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure 2025109793000001_ABST
    Figure 2025109793000001_ABST
Patent Text Reader

Abstract

To fix wheels during autonomous driving at right timing.SOLUTION: ADS performs processing, including, a step of setting an immovable command to "Applied" (S15), a step (S16) of setting an acceleration command to V1, and a step (S18) in which, when an immobility status is set to "11" (YES in S17), the acceleration command is set to zero, in a case where an autonomous state is an autonomous mode (YES in S11), an acceleration command is a value indicating deceleration (YES in S12), an actual moving direction indicates a stopped state (YES in S13), and there is a wheel lock request (YES in S14).SELECTED DRAWING: Figure 3
Need to check novelty before this filing date? Find Prior Art

Description

Technical Field

[0001] The present disclosure relates to the control of a vehicle during autonomous driving.

Background Art

[0002] In recent years, the development of an autonomous driving system that runs a vehicle without requiring user operation has been underway. The autonomous driving system may be provided separately from the vehicle via an interface, for example, in order to be mounted on an existing vehicle.

[0003] As such an autonomous driving system, for example, Japanese Patent Application Laid-Open No. 2018-132015 (Patent Document 1) discloses a technique that can add an autonomous driving function without making a major change to an existing vehicle platform by separating an ECU (Electronic Control Unit) that manages the power of the vehicle from an ECU for autonomous driving.

Prior Art Documents

Patent Documents

[0004]

Patent Document 1

Summary of the Invention

Problems to be Solved by the Invention

[0005] By the way, during autonomous driving of a vehicle, since no operation is performed by the user, it is required to appropriately perform fixing of wheels using a parking brake, a parking lock, etc. when the vehicle is parked.

[0006] The present disclosure has been made to solve the above-described problems, and an object thereof is to provide a vehicle on which an autonomous driving system can be mounted and that appropriately performs fixing of wheels during autonomous driving.

Means for Solving the Problems

[0007] A vehicle according to an aspect of the present disclosure is a vehicle capable of mounting an automatic driving system. This vehicle includes a vehicle platform that executes vehicle control according to commands from the automatic driving system, and a vehicle control interface that interfaces between the automatic driving system and the vehicle platform. From the automatic driving system to the vehicle platform, a first command for requesting an acceleration value or a deceleration value and a second command for requesting immobilization of the vehicle are transmitted via the vehicle control interface. From the vehicle platform to the automatic driving system, a signal indicating the stopped state of the vehicle is transmitted via the vehicle control interface. When deceleration is requested of the vehicle platform by the first command, the vehicle platform transmits a signal to the automatic driving system when the vehicle stops. The vehicle platform immobilizes the vehicle according to a second command received after transmitting the signal.

[0008] In this way, after transmitting a signal indicating the stopped state, immobilization of the vehicle is carried out by a second command for requesting immobilization of the vehicle, so that immobilization of the wheels when the vehicle stops can be carried out at an appropriate timing.

[0009] In one embodiment, a constant deceleration value is requested by the first command until immobilization of the vehicle is requested by the second command.

[0010] In this way, since a constant deceleration value is requested until immobilization of the vehicle is requested, movement of the vehicle can be restricted.

[0011] Furthermore, in one embodiment, the value indicating the first command is -0.4 m / s 2 is.

[0012] In this way, since -0.4 m / s 2 is requested as a constant deceleration value until immobilization of the vehicle is requested, movement of the vehicle can be restricted.

[0013] In yet another embodiment, when releasing the immobilization of the vehicle, when the vehicle is stopped, the release of the immobilization of the vehicle is requested by a second command, and deceleration is requested by a first command.

[0014] In this way, when the immobilization of the vehicle is released, deceleration is requested by the first command, so that the movement of the vehicle can be restricted.

[0015] In yet another embodiment, when a request for immobilizing the vehicle is made by a second command while the vehicle is running, the request is rejected.

[0016] In this way, when a request for immobilizing the vehicle is made by a second command while the vehicle is running, the request is rejected, so that it is possible to prevent the vehicle from being immobilized while it is running.

[0017] In yet another embodiment, when either a request for immobilizing the vehicle or a request for releasing the immobilization of the vehicle is made, a certain deceleration value is requested by a first command in parallel with the request.

[0018] In this way, since a certain deceleration value is requested in parallel with either a request for immobilizing the vehicle or a request for releasing the immobilization of the vehicle, it is possible to restrict the movement of the vehicle when performing immobilization or when releasing immobilization.

[0019] In yet another embodiment, the value indicating the first command is -0.4 m / s 2 is.

[0020] In this way, -0.4 m / s 2 is requested as a certain deceleration value in parallel with either a request for immobilizing the vehicle or a request for releasing the immobilization of the vehicle, so that it is possible to restrict the movement of the vehicle when performing immobilization or when releasing immobilization.

[0021] A vehicle according to another aspect of the present disclosure is a vehicle including an autonomous driving system and a vehicle platform that executes vehicle control according to commands from the autonomous driving system. A first command for requesting acceleration or deceleration and a second command for requesting immobilization of the vehicle are transmitted from the autonomous driving system to the vehicle platform. A signal indicating a stopped state of the vehicle is transmitted from the vehicle platform to the autonomous driving system. When the autonomous driving system requests deceleration of the vehicle platform by the first command to stop the vehicle, after the signal indicates the stopped state, the autonomous driving system requests immobilization of the vehicle to the vehicle platform by the second command.

Advantages of the Invention

[0022] According to the present disclosure, it is possible to provide a vehicle on which an autonomous driving system can be mounted and that performs fixation of wheels during autonomous driving at an appropriate timing.

Brief Description of the Drawings

[0023]

Figure 1

Figure 2

Figure 3

Figure 4

Figure 5

Figure 6

Figure 7

Figure 8

Figure 9

Figure 10

Figure 11

Figure 12

Figure 13

Figure 14

Figure 15

Figure 16

Figure 17

Figure 18

Figure 19

Figure 20

Figure 21

Embodiments for Carrying Out the Invention

[0024] Hereinafter, embodiments of the present disclosure will be described in detail with reference to the drawings. In the drawings, the same or corresponding parts are denoted by the same reference numerals and their description will not be repeated.

[0025] FIG. 1 is a diagram showing an overview of a MaaS (Mobility as a Service) system in which a vehicle according to an embodiment of the present disclosure is used.

[0026] Referring to FIG. 1, this MaaS system includes a vehicle 10, a data server 500, a mobility service platform (hereinafter referred to as "MSPF (Mobility Service Platform)") 600, and an autonomous driving-related mobility service 700.

[0027] The vehicle 10 includes a vehicle body 100 and an autonomous driving kit (hereinafter referred to as "ADK (Autonomous Driving Kit)") 200. The vehicle body 100 includes a vehicle control interface 110, a vehicle platform (hereinafter referred to as "VP (Vehicle Platform)") 120, and a DCM (Data Communication Module) 190.

[0028] The vehicle 10 can perform autonomous driving according to commands from the ADK 200 attached to the vehicle body 100. In FIG. 1, the vehicle body 100 and the ADK 200 are shown at separated positions, but actually the ADK 200 is attached to the roof of the vehicle body 100 or the like. The ADK 200 can also be removed from the vehicle body 100. When the ADK 200 is removed, the vehicle body 100 can travel under the user's driving. In this case, the VP 100 executes driving control in manual mode (driving control according to user operations).

[0029] The vehicle control interface 110 can communicate with the ADK 200 through CAN (Controller Area Network) or the like. By executing a predetermined API (Application Program Interface) defined for each communicated signal, the vehicle control interface 110 receives various commands from the ADK 200 and outputs the state of the vehicle body 100 to the ADK 200.

[0030] When the vehicle control interface 110 receives a command from the ADK 200, it outputs a control command corresponding to that command to the VP 120. Also, the vehicle control interface 110 acquires various information of the vehicle body 100 from the VP 120 and outputs the state of the vehicle body 100 to the ADK 200. The configuration of the vehicle control interface 110 will be described in detail later.

[0031] The VP 120 includes various systems and various sensors for controlling the vehicle body 100. The VP 120 executes various vehicle controls according to the commands instructed from the ADK 200 through the vehicle control interface 110. That is, by the VP 120 executing various vehicle controls according to the commands from the ADK 200, the automatic driving of the vehicle 10 is performed. The configuration of the VP 120 will also be described in detail later.

[0032] The ADK 200 includes an autonomous driving system (hereinafter referred to as "ADS (Autonomous Driving System)") 202 for performing the automatic driving of the vehicle 10. The ADS 202, for example, creates a driving plan for the vehicle 10 and outputs various commands for driving the vehicle 10 according to the created driving plan to the vehicle control interface 110 according to an API defined for each command. Also, the ADS 202 receives various signals indicating the state of the vehicle body 100 from the vehicle control interface 110 according to an API defined for each signal, and reflects the received vehicle state in the creation of the driving plan. The configuration of the ADS 202 will also be described later.

[0033] The DCM 190 includes a communication I / F (interface) for the vehicle body 100 to wirelessly communicate with the data server 500. The DCM 190 outputs various vehicle information such as speed, position, and automatic driving state to the data server 500, for example. Also, the DCM 190 receives various data for managing the driving of the autonomous driving vehicle including the vehicle 10 in the mobility service 700 related to autonomous driving from the mobility service 700 through the MSPF 600 and the data server 500, for example.

[0034] MSPF600 is a unified platform to which various mobility services are connected. In addition to the mobility service 700 related to autonomous driving, various mobility services (for example, various mobility services provided by ride-sharing operators, car-sharing operators, insurance companies, car rental operators, taxi operators, etc.) not shown in the figure are connected to MSPF600. Each mobility service including the mobility service 700 can use various functions provided by MSPF600 according to the service content by using the APIs published on MSPF600.

[0035] The mobility service 700 related to autonomous driving provides a mobility service using autonomous driving vehicles including the vehicle 10. The mobility service 700 can obtain, from MSPF600, for example, the driving control data of the vehicle 10 that communicates with the data server 500 and the information stored in the data server 500 by using the APIs published on MSPF600. Further, the mobility service 700 transmits, to MSPF600, for example, data for managing autonomous driving vehicles including the vehicle 10 by using the above APIs.

[0036] Note that MSPF600 has published an API for using various data on vehicle state and vehicle control necessary for the development of ADS, and an ADS operator can use, as the above API, the data on vehicle state and vehicle control necessary for the development of ADS stored in the data server 500.

[0037] Figure 2 is a diagram for explaining in detail the configurations of the ADS202, the vehicle control interface 110, and the VP120. As shown in Figure 2, the ADS202 includes a computer 210, an HMI (Human Machine Interface) 230, a recognition sensor 260, an attitude sensor 270, and a sensor cleaner 290.

[0038] During the automatic driving of the vehicle, the computer 210 uses various sensors described later to acquire the environment around the vehicle, the posture, behavior, and position of the vehicle, and also acquires the vehicle state from the VP120 described later via the vehicle control interface 110, and sets the next operation (such as acceleration, deceleration, or turning) of the vehicle. The computer 210 outputs various commands for realizing the set next operation of the vehicle to the vehicle control interface 110.

[0039] The HMI 230 presents information to the user and accepts operations during automatic driving, during driving that requires user operation, or during transitions between automatic driving and driving that requires user operation. The HMI 230 is composed of, for example, a touch panel display, a display device, and an operation device.

[0040] The recognition sensor 260 includes sensors for recognizing the environment around the vehicle, and is composed of, for example, at least one of LIDAR (Laser Imaging Detection and Ranging), millimeter-wave radar, and a camera.

[0041] LIDAR is a distance measuring device that irradiates laser light (infrared rays) in a pulsed manner and measures the distance based on the time it takes for the light to be reflected by the object and return. Millimeter-wave radar is a distance measuring device that irradiates radio waves with a short wavelength onto an object, detects the radio waves returned from the object, and measures the distance and direction to the object. The camera is, for example, arranged on the back side of the rearview mirror in the vehicle interior and is used for photographing an image in front of the vehicle. The information acquired by the recognition sensor 260 is output to the computer 210. Other vehicles, obstacles, or people in front of the vehicle can be recognized by performing image processing on the images and videos photographed by the camera using artificial intelligence (AI) or an image processing processor.

[0042] The attitude sensor 270 includes sensors that detect the attitude, behavior, or position of the vehicle, and is constituted by, for example, an IMU (Inertial Measurement Unit), a GPS (Global Positioning System), or the like.

[0043] The IMU detects, for example, the acceleration in the longitudinal, lateral, and vertical directions of the vehicle, and the angular velocity in the roll, pitch, and yaw directions of the vehicle. The GPS detects the position of the vehicle 10 using information received from a plurality of GPS satellites orbiting the Earth. The information acquired by the attitude sensor 270 is output to the computer 210.

[0044] The sensor cleaner 290 is configured to remove dirt adhering to various sensors during vehicle travel. The sensor cleaner 290 removes dirt, for example, from the lens of a camera, an irradiation unit for laser or radio wave, using a cleaning liquid, a wiper, or the like.

[0045] The vehicle control interface 110 includes a VCIB (Vehicle Control Interface Box) 111 and a VCIB 112. Both the VCIB 111 and the VCIB 112 incorporate a CPU (Central Processing Unit) and a memory (including, for example, a ROM (Read Only Memory), a RAM (Random Access Memory), etc.), not shown in the figure. The VCIB 111 has the same functions as the VCIB 112, but the connection destinations to the plurality of systems constituting the VP 120 are partially different.

[0046] The VCIB 111 and the VCIB 112 are each communicably connected to the computer 210 of the ADS 202. Further, the VCIB 111 and the VCIB 112 are communicably connected to each other.

[0047] Each of VCIB111 and VCIB112 relays various commands from ADS202 and outputs them as control commands to VP120. More specifically, each of VCIB111 and VCIB112 uses information such as programs stored in memory (e.g., APIs) to generate control commands used for controlling each system of VP120 using various command instructions output from ADS202, and outputs them to the destination system. Also, each of VCIB111 and VCIB112 relays vehicle information output from VP120 and outputs it to ADS202 as the vehicle state. Note that the information indicating the vehicle state may be the same as the vehicle information, or may be information extracted from the vehicle information for use in the processes executed by ADS202.

[0048] By providing VCIB111 and VCIB112 with equivalent functions regarding the operations of some systems (e.g., brakes and steering), the control system between ADS202 and VP120 will be made redundant. Therefore, when some kind of failure occurs in a part of the system, the control system can be switched appropriately, or the function (turning, stopping, etc.) of VP120 can be maintained by cutting off the control system in which the failure has occurred.

[0049] VP120 includes brake systems 121A, 121B, steering systems 122A, 122B, an EPB (Electric Parking Brake) system 123A, a P-Lock system 123B, a propulsion system 124, a PCS (Pre-Crash Safety) system 125, and a body system 126.

[0050] VCIB111, brake system 121B, steering system 122A, EPB system 123A, P-Lock system 123B, propulsion system 124, and body system 126 among the multiple systems of VP120 are connected to be communicable with each other via a communication bus.

[0051] Further, VCIB112, the braking system 121A among the plurality of systems of VP120, the steering system 122B, and P-Lock123B are communicably connected to each other via a communication bus.

[0052] The braking systems 121A and 121B are configured to be able to control a plurality of braking devices provided on each wheel of the vehicle. The braking system 121A may have the same functions as the braking system 121B. For example, either one of them may be configured to be able to independently control the braking force of each wheel during vehicle travel, and the other may be configured to be able to control so that the same braking force is generated at each wheel during vehicle travel. The braking device includes, for example, a disc brake system that operates using hydraulic pressure adjusted by an actuator.

[0053] A wheel speed sensor 127 is connected to the braking system 121B. The wheel speed sensor 127 is provided, for example, on each wheel of the vehicle and detects the rotational speed of each wheel. The wheel speed sensor 127 outputs the detected rotational speed of each wheel to the braking system 121B. The braking system 121B outputs the rotational speed of each wheel to VCIB111 as one of the information included in the vehicle information.

[0054] Each of the braking systems 121A and 121B generates a braking command for the braking device according to a predetermined control command output from ADS202 via the vehicle control interface 110. Further, the braking systems 121A and 121B control the braking device using, for example, the braking command generated in either one of the braking systems, and when an abnormality occurs in either one of the braking systems, control the braking device using the braking command generated in the other braking system.

[0055] The steering systems 122A and 122B are configured to be able to control the steering angle of the steered wheels of the vehicle 10 using a steering device. The steering system 122A has the same functions as the steering system 122B. The steering device includes, for example, a rack & pinion type EPS (Electric Power Steering) whose steering angle can be adjusted by an actuator.

[0056] A pinion angle sensor 128A is connected to the steering system 122A. A pinion angle sensor 128B, which is provided separately from the pinion angle sensor 128A, is connected to the steering system 122B. Each of the pinion angle sensors 128A and 128B detects the rotation angle (pinion angle) of a pinion gear connected to the rotation shaft of the actuator constituting the steering device. The pinion angle sensors 128A and 128B output the detected pinion angles to the steering systems 122A and 122B, respectively.

[0057] Each of the steering systems 122A and 122B generates a steering command for the steering device according to a predetermined control command output from the ADS202 via the vehicle control interface 110. Also, the steering systems 122A and 122B control the steering device using, for example, the steering command generated in either one of the steering systems, and control the steering device using the steering command generated in the other steering system when an abnormality occurs in either one of the steering systems.

[0058] The EPB system 123A is configured to be able to control the EPB provided on at least any one of a plurality of wheels provided on the vehicle 10. The EPB is provided separately from the braking device and fixes the wheel by the operation of the actuator. The EPB, for example, operates a drum brake for parking brake provided on a part of a plurality of wheels provided on the vehicle 10 using an actuator to fix the wheel, or operates the braking device using an actuator that can adjust the hydraulic pressure supplied to the braking device separately from the brake systems 121A and 121B to fix the wheel.

[0059] The EPB system 123A controls the EPB according to a predetermined control command output from the ADS202 via the vehicle control interface 110.

[0060] The P-Lock system 123B is configured to be able to control a P-Lock device provided in the transmission of the vehicle 10. The P-Lock device fits a protrusion provided at the tip of a parking lock pole whose position is adjusted by an actuator to the tooth part of a gear (lock gear) provided connected to a rotating element in the transmission. Thereby, the rotation of the output shaft of the transmission is fixed and the wheels are fixed.

[0061] The P-Lock system 123B controls the P-Lock device according to a predetermined control command output from the ADS202 via the vehicle control interface 110. The P-Lock system 123B operates the P-Lock device, for example, when the control command output from the ADS202 via the vehicle control interface 110 includes a control command to set the shift range to the parking range (hereinafter referred to as the P range), and releases the operation of the P-Lock device when the control command includes a control command to set the shift range to other than the P range.

[0062] The propulsion system 124 is capable of switching the shift range using a shift device and is configured to be able to control the driving force of the vehicle 10 with respect to the moving direction of the vehicle 10 using a drive source. The shift device is configured to be able to select any one of a plurality of shift ranges. The plurality of shift ranges include, for example, a P range, a neutral range (hereinafter referred to as the N range), a forward driving range (hereinafter referred to as the D range), and a reverse driving range (hereinafter referred to as the R range). The drive source includes, for example, a motor generator, an engine, and the like.

[0063] The propulsion system 124 controls the shift device and the drive source according to a predetermined control command output from the ADS 202 via the vehicle control interface 110. For example, when the control command output from the ADS 202 via the vehicle control interface 110 includes a control command to set the shift range to the P range, the propulsion system 124 controls the shift device so that the shift range becomes the P range.

[0064] The PCS system 125 performs vehicle control for avoiding collisions and reducing damage using the camera / radar 129. The PCS system 125 is communicably connected to the brake system 121B. For example, when the PCS system 125 detects a forward obstacle or the like (obstacle or person) using the camera / radar 129 and determines that there is a possibility of collision based on the distance to the obstacle or the like, the PCS system 125 outputs a braking command to the brake system 121B so that the braking force increases.

[0065] The body system 126 is configured to be able to control components such as turn signals, horns, or wipers according to, for example, the driving state or driving environment of the vehicle 10. The body system 126 controls the above-described components according to a predetermined control command output from the ADS 202 via the vehicle control interface 110.

[0066] Note that an operation device that can be manually operated by the user may be separately provided for the braking device, steering device, EPB, P-Lock device, shift device, drive source, and the like described above.

[0067] Various commands output from the ADS 202 to the vehicle control interface 110 include a propulsion direction command that requests switching of the shift range, a stationary command that requests operation or release of the EPB or P-Lock device, an acceleration command that requests acceleration or deceleration of the vehicle 10, a tire cut angle command that requests the tire cut angle of the steering wheel, and an autonomy command that requests switching of the autonomous state between the autonomous mode and the manual mode.

[0068] In the vehicle 10 having the above configuration, for example, when the autonomous mode is selected as the autonomous state by an operation on the user's HMI 230 or the like, the automatic driving is performed. As described above, during the automatic driving, the ADS 202 first creates a driving plan. The driving plan includes, for example, a plan to continue straight, a plan to turn left or right at a predetermined intersection on a predetermined driving route, or a plan to change the driving lane to a lane different from the lane in which the own vehicle is traveling, and a plurality of plans related to the operation of the vehicle 10.

[0069] The ADS 202 extracts the control physical quantities (for example, acceleration or deceleration, tire slip angle, etc.) necessary for the vehicle 10 to operate along the created driving plan. The ADS 202 divides the physical quantities for each execution cycle of the API. The ADS 202 executes the API using the divided physical quantities and outputs various commands to the vehicle control interface 110. Further, the ADS 202 acquires the vehicle state (for example, the actual moving direction of the vehicle 10, the state of vehicle immobilization, etc.) from the VP 120 and recreates a driving plan reflecting the acquired vehicle state. In this way, the ADS 202 enables the automatic driving of the vehicle 10.

[0070] During the automatic driving of the vehicle 10, since no operation is performed by the user, it is required to appropriately perform the wheel fixing using the EPB, P-Lock device, etc. when the vehicle 10 stops.

[0071] Therefore, in this embodiment, the following operations are performed between the ADS202 and the VP120 via the vehicle control interface 110. That is, from the ADS202 to the VP120, as described above, an acceleration command (corresponding to the first command) for requesting acceleration or deceleration and an immobilization command (corresponding to the second command) for requesting immobilization of the vehicle (fixing of the wheels) are transmitted. From the VP120 to the ADS202, the actual moving direction of the vehicle 10 (corresponding to the signal) is transmitted. And when the ADS202 requests deceleration of the VP120 by the acceleration command to stop the vehicle 10, after the actual moving direction indicates the stopped state of the vehicle 10, it is assumed that the ADS202 requests immobilization of the vehicle 10 to the VP120 by the immobilization command. Also, when deceleration is requested by the acceleration command, the VP120 transmits a signal indicating the stopped state as the actual moving direction to the ADS202 when the vehicle 10 stops. The VP120 implements immobilization of the vehicle 10 by the immobilization command received after transmitting the signal.

[0072] By doing so, after the actual moving direction of the vehicle 10 indicates the stopped state, immobilization of the vehicle 10 is implemented by the immobilization command, so that the fixing of the wheels when the vehicle 10 stops can be implemented at an appropriate timing.

[0073] Hereinafter, with reference to FIG. 3, the processing executed by the ADS202 (more specifically, the computer 210) in this embodiment will be described. FIG. 3 is a flowchart showing an example of the processing executed by the ADS202. The ADS202 repeatedly executes the following processing, for example, for each execution cycle of the API.

[0074] In step 11 (hereinafter referred to as step S), ADS202 determines whether the autonomous state is in the autonomous mode. For example, ADS202 determines whether the autonomous state is in the autonomous mode based on the state of a flag indicating the autonomous mode. The flag indicating the autonomous mode is turned on, for example, when the HMI230 receives an operation from the user to perform automatic driving, and is turned off when the autonomous mode is canceled and switched to the manual mode according to the operation by the user or the driving situation. If ADS202 determines that the autonomous state is in the autonomous mode (YES in S11), the process proceeds to S12.

[0075] In S12, ADS202 determines whether the acceleration command is a value indicating deceleration. The acceleration command indicates an acceleration value or a deceleration value. For example, when the acceleration command is a positive value, it indicates that acceleration of vehicle 10 is requested from ADS202 to VP120. When the acceleration command is a negative value, it indicates that deceleration of vehicle 10 is requested from ADS202 to VP120. ADS202 determines that the acceleration command is a value indicating deceleration when the acceleration command is a negative value. If it is determined that the acceleration command is a value indicating deceleration (YES in S12), the process proceeds to S13.

[0076] In S13, ADS202 determines whether the actual moving direction of vehicle 10 indicates a stopped state. ADS202 acquires information about the actual moving direction of vehicle 10 from VP120 as vehicle state. For example, when the longitudinal speed of vehicle 10 becomes zero using the wheel speed acquired by the wheel speed sensor 127 of VP120, information that the actual moving direction is in the stopped state is output from VP120 to ADS202 via the vehicle control interface 110 as vehicle state. In the present embodiment, the longitudinal direction of vehicle 10 corresponds to, for example, the traveling direction of vehicle 10. If it is determined that the actual moving direction of vehicle 10 indicates a stopped state (YES in S13), the process proceeds to S14.

[0077] In S14, ADS202 determines whether there is a wheel lock request. For example, ADS202 determines that there is a wheel lock request when the driving plan created includes a plan to immobilize vehicle 10. If it is determined that there is a wheel lock request (YES in S14), the process proceeds to S15.

[0078] In S15, ADS202 sets the immobilization command to "Applied". That is, immobilization of vehicle 10 is requested for VP120. Therefore, when the immobilization command is set to "Applied", the EPB and the P-Lock device in VP120 are controlled to operate as described later.

[0079] In S16, ADS202 sets V1 as the acceleration command. V1 indicates a certain deceleration value. For example, V1 is -0.4 m / s 2 is.

[0080] In S17, ADS202 determines whether the immobilization status is "11". The immobilization status is output as one of the vehicle states from VP120 via the vehicle control interface 110.

[0081] The stationary status is set by combining a value indicating the state of the EPB and a value indicating the state of the P-Lock device. When the value indicating the state of the EPB is "1", it indicates that the EPB is in the operating state. When the value indicating the state of the EPB is "0", it indicates that the EPB is in the non-operating state. Similarly, when the value indicating the state of the P-Lock device is "1", it indicates that the P-Lock device is in the operating state. When the value indicating the state of the P-Lock device is "0", it indicates that the P-Lock device is in the non-operating state. Therefore, for example, when the value indicating the stationary status is "11", it is shown that both the EPB and the P-Lock device are in the operating state. Also, when the value indicating the stationary status is "00", it is shown that both the EPB and the P-Lock device are in the non-operating state. Furthermore, when the value indicating the stationary status is "10", it is shown that the EPB is in the operating state and the P-Lock device is in the non-operating state. Furthermore, when the value indicating the stationary status is "01", it is shown that the EPB is in the non-operating state and the P-Lock device is in the operating state. If it is determined that the stationary status is "11" (YES in S17), the process proceeds to S18.

[0082] In S18, ADS202 sets the acceleration command to zero. In this case, the vehicle 10 is controlled to maintain the stopped state.

[0083] Note that when the autonomous state is not in the autonomous mode (NO in S11), or when the acceleration command is not a value indicating deceleration (NO in S12), or when the actual moving direction does not indicate a stopped state (NO in S13), or when there is no wheel lock request (NO in S14), this process ends. Also, when the stationary status is not set to "11" (NO in S17), the process returns to S17.

[0084] Next, with reference to FIG. 4, the processing executed by the vehicle control interface 110 (more specifically, the VCIB 111) will be described. FIG. 4 is a flowchart showing an example of the processing executed by the vehicle control interface 110. The vehicle control interface ADS202 repeatedly executes the following processing, for example, for each execution cycle of the API.

[0085] In S21, the vehicle control interface 110 determines whether the immobilization command is set to "Applied". If it is determined that the immobilization command is set to "Applied" (YES in S21), the process proceeds to S22.

[0086] In S22, the vehicle control interface 110 determines whether the actual moving direction of the vehicle 10 indicates a stopped state. If it is determined that the actual moving direction of the vehicle 10 indicates a stopped state (YES in S22), the process proceeds to S23.

[0087] In S23, the vehicle control interface 110 executes wheel lock control. Specifically, the vehicle control interface 110 outputs a control command requesting the EPB system 123A to activate the EPB, and also outputs a control command (a control command requesting to shift the shift range to the P range) requesting the P-Lock system 123B to activate the P-Lock device.

[0088] In S24, the vehicle control interface 110 determines whether the wheel lock control has been completed. The vehicle control interface 110 determines that the wheel lock control has been completed when both the EPB and the P-Lock are in the activated state.

[0089] The vehicle control interface 110 may determine that the EPB is in an activated state when a predetermined time has elapsed after outputting a control command that requests, for example, the EPB to be in an activated state, or alternatively, may determine that the EPB is in an activated state when the amount of operation of the actuator of the EPB exceeds a threshold value.

[0090] Similarly, the vehicle control interface 110 may determine that the P-Lock device is in an activated state when a predetermined time has elapsed after outputting a control command that requests, for example, the P-Lock device to be in an activated state, or alternatively, may determine that the P-Lock device is in an activated state when the amount of operation of the actuator of the P-Lock device exceeds a threshold value. When it is determined that the wheel lock control has been completed (YES in S24), the process proceeds to S25.

[0091] In S25, the vehicle control interface 110 sets "11" as the immobilization status. When the value indicating the immobilization status is "11", it indicates that both the EPB and the P-Lock device are in an activated state. The vehicle control interface 110 outputs the set immobilization status to the ADS202 as one piece of information included in the vehicle state. If it is determined that the actual moving direction does not indicate a stopped state (NO in S22), the process proceeds to S26.

[0092] In S26, the vehicle control interface 110 rejects the command. Specifically, the vehicle control interface 110 rejects the command by setting the wheel lock control to non-execution even if the immobilization command is set to "Applied". The vehicle control interface 110 may also output information indicating that the wheel lock control is non-executed to the ADS202.

[0093] Also, if it is determined that the immobilization command is not set to "Applied" (NO in S21), this process ends. Further, if it is determined that the wheel lock control has not been completed (NO in S24), the process returns to S24.

[0094] Next, with reference to FIG. 5, the processing executed by the ADS 202 when immobilization of the vehicle 10 is requested will be described. FIG. 5 is a flowchart showing an example of the processing executed by the ADS 202 when immobilization of the vehicle 10 is requested. The ADS 202 repeatedly executes the following processing, for example, for each execution cycle of the API.

[0095] In S31, the ADS 202 determines whether the autonomous state is the autonomous mode. Since the method for determining whether it is the autonomous mode is as described above, a detailed description thereof will not be repeated. If it is determined that the autonomous state is the autonomous mode (YES in S31), the process proceeds to S32.

[0096] In S32, the ADS 202 determines whether the immobilization command is set to “Applied” (that is, immobilization of the vehicle 10 is requested). If it is determined that the immobilization command is set to “Applied” (YES in S32), the process proceeds to S33.

[0097] In S33, the ADS 202 determines whether there is a wheel unlock request. The ADS 202 determines that there is a wheel unlock request, for example, when the created driving plan includes a plan to drive the vehicle. If it is determined that there is a wheel unlock request (YES in S33), the process proceeds to S34.

[0098] In S34, the ADS 202 determines whether the actual moving direction of the vehicle 10 indicates a stopped state. Since the method for determining whether the actual moving direction indicates a stopped state is as described above, a detailed description thereof will not be repeated. If it is determined that the actual moving direction of the vehicle 10 indicates a stopped state (YES in S34), the process proceeds to S35.

[0099] At S35, ADS202 sets the immobilization command to "Released". That is, the release of the immobilization of vehicle 10 is requested for VP120. When the immobilization command is set to "Released", as will be described later, both the EPB and the P-Lock device are controlled to be in a non-operating state.

[0100] At S36, ADS202 sets the acceleration command to zero. In this case, vehicle 10 is controlled to maintain a stopped state.

[0101] Next, with reference to FIG. 6, the process executed by the vehicle control interface 110 when immobilization of vehicle 10 is requested will be described. FIG. 6 is a flowchart showing an example of the process executed by the vehicle control interface 110 when immobilization of vehicle 10 is requested. The vehicle control interface 110 repeatedly executes the following processes, for example, for each execution cycle of the API.

[0102] At S41, the vehicle control interface 110 determines whether the immobilization command is set to "Released". If it is determined that the immobilization command is set to "Released" (YES at S41), the process proceeds to S42.

[0103] At S42, the vehicle control interface 110 executes wheel lock release control. Specifically, the vehicle control interface 110 outputs a control command requesting that the EPB be in a non-operating state to the EPB system 123A, and outputs a control command (for example, a control command requesting to set the shift range to a non-P range (for example, N range, D range, or R range, etc.)) requesting that the P-Lock device be in a non-operating state to the P-Lock system 123B.

[0104] In S43, the vehicle control interface 110 sets the immobilization status to "00". When the value indicating the immobilization status is "00", it indicates that both the EPB and the P-Lock device are in the non-operating state. The vehicle control interface 110 outputs the set immobilization status to the ADS202 as one piece of information included in the vehicle state.

[0105] The operations of the ADS202, the vehicle control interface 110, and the VP20 based on the above structure and flowchart will be described with reference to FIG. 7. FIG. 7 is a timing chart for explaining the operations of the ADS202, the vehicle control interface 110, and the VP120. The horizontal axis of FIG. 7 indicates time. LN1 in FIG. 7 indicates the change in the longitudinal speed. LN2 in FIG. 7 indicates the change in the acceleration command. LN3 in FIG. 7 indicates the change in the actual moving direction. LN4 in FIG. 7 indicates the change in the immobilization command. LN5 in FIG. 7 indicates the change in the immobilization status. LN6 in FIG. 7 indicates the change in the state of the EPB. LN7 in FIG. 7 indicates the change in the state of the P-Lock device.

[0106] For example, assume that the vehicle 10 during automatic driving is traveling at a constant speed as shown by LN1 in FIG. 7. At this time, assume that the value indicating the acceleration command is zero as shown by LN2 in FIG. 7. Also, assume that the actual moving direction is the forward direction as shown by LN3 in FIG. 7. Further, assume that the immobilization command is set to "Released" as shown by LN4 in FIG. 7. Furthermore, assume that the immobilization status is "00" as shown by LN5 in FIG. 7, and that both the EPB and the P-Lock device are in the non-operating state as shown by LN6 and LN7 in FIG. 7.

[0107] At time t1, if the travel plan created in the ADS202 includes a deceleration plan as shown by LN2 in FIG. 7, the acceleration command will become a value indicating deceleration according to the travel plan. Therefore, the longitudinal speed decreases after time t1 as shown by LN1 in FIG. 7.

[0108] When the autonomous state is the autonomous mode (YES in S11) and the acceleration command becomes a value indicating deceleration (YES in S12), it is determined whether or not the actual moving direction enters a state indicating stop (S13).

[0109] At time t2, as shown by LN1 in FIG. 7, when the vertical speed becomes zero, the actual moving direction indicates a stopped state as shown by LN3 in FIG. 7.

[0110] At time t3, when the actual moving direction indicates a stopped state (YES in S13) and there is a wheel lock request (YES in S14), the stationary command is set to "Applied" as shown by LN4 in FIG. 7 (S14). Then, as shown by LN2 in FIG. 7, a constant deceleration value V1 is set as the acceleration command (S15).

[0111] When the stationary command is set to "Applied" (YES in S21) and the actual moving direction indicates a stopped state (YES in S22), wheel lock control is executed (S23). As a result, both the EPB and the P-Lock device are controlled to be in an operating state. When the wheel lock control is completed because both the EPB and the P-Lock device are in an operating state as shown by LN6 and LN7 in FIG. 7 (YES in S24), the stationary status is set to "11" as shown by LN5 in FIG. 7 (S25).

[0112] At time t4, when the stationary status is set to "11" (YES in S16), the value of the acceleration command becomes zero.

[0113] At time t5, when the autonomous state is the autonomous mode (YES in S31) and the stationary command is set to "Applied" (YES in S32), it is determined whether or not there is a wheel unlock request (S33).

[0114] If the driving plan created in ADS202 includes a plan to release the immobilization of vehicle 10, wheel unlock is required according to the driving plan (YES in S33). Therefore, as shown in LN3 of FIG. 7, since the actual moving direction indicates a stopped state (YES in S34), as shown in LN4 of FIG. 7, the immobilization command is set to "Released" (S35). Then, as shown in LN2 of FIG. 7, a constant deceleration value V1 is set as the acceleration command (S36).

[0115] When the immobilization command is set to "Released" (YES in S41), wheel unlock control is executed (S42). Therefore, as shown in LN6 and LN7 of FIG. 7, both the EPB and the P-Lock device are controlled to the non-operating state, and as shown in LN5 of FIG. 7, the immobilization status is set to "00" (S43).

[0116] As described above, according to vehicle 10 according to the present embodiment, after the actual moving direction indicates a stopped state, the wheels of vehicle 10 are fixed by the immobilization command, so that the fixing of the wheels using the EPB and P-Lock when vehicle 10 stops can be performed at an appropriate timing. Therefore, it is possible to provide a vehicle in which an automatic driving system can be mounted and the wheels can be fixed at an appropriate timing during automatic driving.

[0117] Furthermore, until the immobilization command is set to "Applied", a value V1 (-0.4 m / s 2 ) indicating the acceleration command is required. Therefore, the movement of vehicle 10 can be restricted until the immobilization of vehicle 10 is performed.

[0118] Furthermore, when releasing the immobilization of vehicle 10, the release of the immobilization of vehicle 10 is required by the immobilization command while vehicle 10 is stopped, and deceleration is required by the acceleration command. Therefore, the movement of vehicle 10 can be restricted until the immobilization of vehicle 10 is released.

[0119] Furthermore, when a request to immobilize the vehicle 10 is made by an immobilization command during the running of the vehicle 10, the request is rejected, so that it is possible to suppress the immobilization (i.e., wheel lock control) of the vehicle 10 during the running of the vehicle 10.

[0120] Furthermore, when either a request to immobilize the vehicle 10 or a request to release the immobilization of the vehicle is made by an immobilization command, a constant value V1 (-0.4 m / s 2 ) is requested by an acceleration command in parallel with the request. Therefore, the movement of the vehicle 10 can be restricted until the immobilization of the vehicle 10 is implemented or until the immobilization of the vehicle 10 is released.

[0121] Furthermore, when the vehicle 10 stops by exchanging vehicle states such as various commands such as an acceleration command and an immobilization command and the actual moving direction between the ADS202 and the VP120 via the vehicle control interface 110, the wheels can be fixed at an appropriate timing using the EPB and the P-Lock device.

[0122] Hereinafter, modified examples will be described. In the above-described embodiment, the VCIB111 has been described as executing the processes shown in the flowchart of FIG. 4 and the processes shown in the flowchart of FIG. 6. However, for example, the VCIB111 and the VCIB112 may cooperate to execute the above-described processes.

[0123] Furthermore, in the above-described embodiment, the vehicle control interface 110 has been described as executing the processes shown in the flowchart of FIG. 4 and the processes shown in the flowchart of FIG. 6. However, for example, part or all of the above-described processes may be executed in each system (specifically, the EPB system 123A and the P-Lock system 123B) that is the control target of the VP120.

[0124] Note that the above-described modified examples may be implemented by appropriately combining all or part of them.

Example

[0125] Toyota's MaaS Vehicle Platform API Specification for ADS Developers [Standard Edition #0.1] Revision History

[0126] [Table 1]

[0127] table of contents 1. Outline 4 1.1. Purpose of this Specification 4 1.2. Target Vehicle 4 1.3. Definition of Term 4 1.4. Precaution for Handling 4 2. Structure 5 2.1. Overall Structure of MaaS 5 2.2. System structure of MaaS vehicle 6 3. Application Interfaces 7 3.1. Responsibility sharing of when using APIs 7 3.2. Typical usage of APIs 7 3.3. APIs for vehicle motion control 9 Functions 9 3.3.2. Inputs 16 3.3.3. Outputs 23 3.4. APIs for BODY control 45 3.4.1. Functions 45 3.4.2. Inputs 45 3.4.3. Outputs 56 3.5. APIs for Power control 68 3.5.1. Functions 68 3.5.2. Inputs 68 3.5.3. Outputs 69 3.6. APIs for Safety 70 3.6.1. Functions 70 3.6.2. Inputs 70 3.6.3. Outputs 70 3.7. APIs for Security 74 3.7.1. Functions 74 3.7.2. Inputs 74 3.7.3. Outputs 76 3.8. APIs for MaaS Service 80 3.8.1. Functions 80 3.8.2. Inputs 80 3.8.3. Outputs 80 1. Outline 1.1. Purpose of this Specification This document is an API specification of Toyota Vehicle Platform and contains the outline, the usage and the caveats of the application interface. This book is an API specification of Toyota vehicle's Vehicle Platform, and describes the outline, usage, and precautions of the Application Interface. 1.2. Target Vehicle e-Palette, a MaaS vehicle based on the POV (Privately Owned Vehicle) manufactured by Toyota The target vehicles in this book are the e-Palette and MaaS vehicles based on commercially available vehicles manufactured by Toyota. 1.3. Term Definition

[0128]

Table 2

[0129] 1.4. Handling Precautions This is an early draft of the document. All the contents are subject to change. Such changes will be notified to the users. Please note that some parts are still T.B.D. and will be updated in the future. This book is in the Early Draft version. Please note that the described content may change. Also, when the described content changes, we will contact you separately. In addition, due to the ongoing detailed design, there are scattered T.B.D. items, but they will be updated sequentially. 2. Structure 2.1. Overall Structure of MaaS The overall structure of MaaS with the target vehicle is shown. The overall configuration of MaaS using the target vehicle is shown below (Figure 8). Vehicle control technology is being used as an interface for technology providers. Technology providers can receive open API such as vehicle state and vehicle control, necessary for development of automated driving systems. The target vehicles covered in this document will disclose their vehicle control technology to ADS operators as an interface. ADS operators can use the vehicle status and vehicle control, which are necessary for the development of autonomous driving systems, as APIs. 2.2. System structure of MaaS vehicle The system architecture as a premise is shown. The assumed system configuration is shown below (Figure 9). The target vehicle will adopt the physical architecture of using CAN for the bus between ADS and VCIB. In order to realize each API in this document, the CAN frames and the bit assignments are shown in the form of “bit assignment table” as a separate document. The physical configuration of the vehicle covered by this document is such that the connection bus to the vehicle (VCIB) is configured as CAN. In order to realize each API in this document using CAN, the CAN frame and data bit assignments are presented separately as a "Bit Assignment Table". 3. Application Interfaces 3.1. Responsibility sharing of when using APIs The basic responsibility sharing between ADS and vehicle VP is as follows when using APIs. When using APIs, the basic responsibility sharing between ADS and VP is as follows. [ADS] The ADS should create the driving plan and indicate vehicle control values to the VP. [VP] The Toyota VP should control each system of the VP based on indications from an ADS . 3.2. Typical usage of APIs In this section, the typical usage of APIs is described. In this section, the typical usage of APIs is explained. CAN will be adopted as the communication line between ADS and VP. Therefore, basically, APIs should be executed at each defined cycle time of each API by ADS. CAN is adopted as the communication line between ADS and VP. Therefore, basically, APIs should be executed at each defined cycle time of each API by ADS. A typical workflow of ADS when executing APIs is as follows. A typical workflow of ADS when executing APIs is as follows (Figure 10). 3.3. APIs for vehicle motion control In this section, the APIs for vehicle motion control which is controllable in the MaaS vehicle is described. In this section, the vehicle control APIs that can be controlled in the MaaS vehicle and how to use them are described. 3.3.1. Functions 3.3.1.1. Standstill, Start Sequence The transition to the standstill (immobility) mode and the vehicle start sequence are described. This function presupposes the vehicle is in Autonomy_State = Autonomous Mode. The request is rejected in other modes. The method of transitioning to Standstill and the method of starting are described. This function assumes that it is in the Autonomy_State = Autonomous Mode. Requests in other states are rejected. The below diagram shows an example. The following figure shows an example. The Acceleration Command requests deceleration and stops the vehicle. Then, when the Longitudinal_Velocity is confirmed as 0 [km / h], the Standstill Command = “Applied” is sent. After the brake hold control is finished, the Standstill Status becomes “Applied”. Until then, the Acceleration Command has to continue the deceleration request. If either the Standstill Command = “Applied” or the deceleration request of the Acceleration Command is canceled, the transition to the brake hold control will not happen. After that, the vehicle continues to be stationary as long as the Standstill Command = “Applied” is being sent. The Acceleration Command can be set to 0 (zero) during this period. The Acceleration Command requests deceleration and stops the vehicle. Then, when the Longitudinal_Velocity is confirmed as 0 [km / h], the Standstill Command = “Applied” is requested. When the brake hold control is completed, the Standstill Status = “Applied”. During that time, the Acceleration Command must continue to request deceleration. When Standstill Command = “Applied” or the deceleration request of Acceleration Command is cancelled, do not shift to the brake hold control. Then, continue Standstill while Standstill Command = “Applied” is requested. During this period, Acceleration Command may be set to 0. If the vehicle needs to start, the brake hold control is cancelled by setting Standstill Command to “Released”. At the same time, acceleration / deceleration is controlled based on Acceleration Command. When wanting to start, release the brake hold by setting Standstill Command = “Released”. At the same time, control acceleration and deceleration according to Acceleration Command (Figure 11). EPB is engaged when Standstill Status = ”Applied” continues for 3 minutes. EPB is activated after 3 minutes when Standstill Status =”Applied”. 3.3.1.2. Direction Request Sequence The shift change sequence is described. This function presupposes that Autonomy_State = Autonomous Mode. Otherwise, the request is rejected. The method of shift change is described. This function is premised on Autonomy_State = Autonomous Mode. Requests outside this are rejected. Shift change happens only during Actual_Moving_Direction=”standstill”). Otherwise, the request is rejected. Shift change can only be carried out when the vehicle is stationary (Actual_Moving_Direction = "standstill"). Otherwise, the request is rejected. The following diagram shows an example. The Acceleration Command requests deceleration and stops the vehicle. After Actual_Moving_Direction is set to "standstill", any shift position can be requested by the Propulsion Direction Command. (In the example below, "D" → "R"). During shift change, the Acceleration Command must request deceleration. After the shift change, acceleration / deceleration is controlled based on the Acceleration Command value. The following figure shows an example. The Acceleration Command requests an acceleration that results in deceleration and stops the vehicle.

[0130] After Actual_Moving_Direction becomes "standstill", any shift range can be requested by the Propulsion Direction Command. (In the example below, the switch from "D" to "R") During shift change, the Acceleration Command must simultaneously request deceleration.

[0131] After the change, perform acceleration and deceleration according to the value of the Acceleration Command as necessary (Figure 12). 3.3.1.3. WheelLock Sequence The engagement and release of wheel lock are described. This function presupposes Autonomy_State = Autonomous Mode; otherwise, the request is rejected. Describe the method of applying and releasing WheelLock. This function is premised on Autonomy_State = Autonomous Mode. Requests outside this are rejected.

[0132] This function can only be conducted while the vehicle is stopped. The Acceleration Command requests deceleration and stops the vehicle. After Actual_Moving_Direction is set to “standstill”, WheelLock is engaged by Immobilization Command = “Applied”. The Acceleration Command is set to Deceleration until Immobilization Status is set to “Applied”. This function can only be performed while the vehicle is stopped. The Acceleration Command requests an acceleration that results in deceleration and stops the vehicle. After Actual_Moving_Direction = “standstill”, WheelLock is applied by Immobilization Command = “Applied”. Until the Immobilization Status becomes “Applied”, set the Acceleration Command to Deceleration (-0.4 m / s^2).

[0133] If release is desired, request Immobilization Command = “Release” when the vehicle is stationary. Set the Acceleration Command to Deceleration at that time. If you want to release, request Immobilization Command = “Release” while the vehicle is stopped. At that time, set the Acceleration Command to Deceleration.

[0134] After this, the vehicle is accelerated or decelerated based on the Acceleration Command value. After that, accelerate or decelerate according to the value of the Acceleration Command (Figure 13). 3.3.1.4. Road_Wheel_Angle Request Steering method This function assumes Autonomy_State = “Autonomous Mode”, and rejects the request otherwise. This function is premised on Autonomy_State = “Autonomous Mode”. Reject requests other than this. The Tire Turning Angle Command is the relative value from Estimated_Road_Wheel_Angle_Actual. The Tire Turning Angle Command inputs the relative value from the Estimated_Road_Wheel_Angle_Actual. For example, in case that Estimated_Road_Wheel_Angle_Actual = 0.1 [rad] while the vehicle is going straight; If ADS requests to go straight ahead, Tire Turning Angle Command should be set to 0 + 0.1 = 0.1[rad]. If ADS requests to steer by -0.3 [rad], Tire Turning Angle Command should be set to -0.3 + 0.1 = -0.2[rad] For example, when the vehicle is going straight but Estimated_Road_Wheel_Angle_Actual indicates 0.1 [rad]. When ADS requests to go straight ahead, the Tire Turning Angle Command outputs 0 + 0.1 = 0.1[rad]. When ADS requests steering by -0.3 [rad], the Tire Turning Angle Command should indicate -0.3 + 0.1 = -0.2[rad]. 3.3.1.5. Rider Operation Operations during driver operation 3.3.1.5.1. Acceleration Pedal Operation Operation of the accelerator pedal While in Autonomous driving mode, accelerator pedal stroke is eliminated from the vehicle acceleration demand selection. During autonomous driving mode, operation by the accelerator pedal is excluded from the selection of the vehicle's required acceleration. 3.3.1.5.2. Brake Pedal Operation Operation of the Brake Pedal The action when the brake pedal is operated. In the autonomy mode, the target vehicle deceleration is the sum of 1) the estimated deceleration from the brake pedal stroke and 2) the deceleration request from the AD system Describe the operation when the brake pedal is operated. During the autonomous driving mode, 1) the acceleration / deceleration estimated from the operation amount of the brake pedal, and 2) the added value of the deceleration request input from the system are set as the target acceleration of the vehicle. 3.3.1.5.3. Shift_Lever_Operation Operation of the Shift Lever In the Autonomous driving mode, the driver's operation of the shift lever is not reflected in the Propulsion Direction Status. If necessary, the ADS confirms the Propulsion Direction by the Driver and changes the shift position by using the Propulsion Direction Command. During the autonomous driving mode, the driver's operation of the shift lever is not reflected in the Propulsion Direction Status. If necessary, the ADS confirms the Propulsion Direction by the Driver, and requests a shift position change by the Propulsion Direction Command as needed. 3.3.1.5.4. Steering Operation Steering Operation When the driver (rider) operates the steering, the maximum is selected from 1) the torque value estimated from driver operation angle, and 2) the torque value calculated from requested wheel angle. When the driver operates the steering, select the maximum value from the torque value estimated from the driver's operation amount and the torque value calculated from the requested steering angle. Note that Tire Turning Angle Command is not accepted if the driver strongly turns the steering wheel. The above is determined by the Steering_Wheel_Intervention flag. However, if the driver strongly operates the steering wheel, Tire Turning Angle Command is not accepted. The above is determined by the Steering_Wheel_Intervention flag. 3.3.2. Inputs

[0135]

Table 3

[0136] 3.3.2.1. Propulsion Direction Command Request to switch between forward (D range) and back (R range) Request to switch the shift range (R / D) Values

[0137] [Table 4]

[0138] Remarks ·Only available when Autonomy_State = “Autonomous Mode”. Only Autonomy_State = “Autonomous Mode” is available ·D / R is changeable only the vehicle is stationary (Actual_Moving_Direction=”standstill”). Switching is possible only when the vehicle is stopped (Actual_Moving_Direction="standstill"). ·The request while driving (moving) is rejected. If requested while driving, decline ·When system requests D / R shifting, Acceleration Command is sent deceleration(-0.4m / s^2) simultaneously. (Only while brake is applied.) When requesting a D / R switch, a deceleration value is requested at the same time via the Acceleration Command.

[0139] (Assuming operation is performed with the brakes held) ·The request may not be accepted in following cases. ·Direction_Control_Degradation_Modes = ”Failure detected” Your request may not be accepted in the following cases:

[0140] ·Direction_Control_Degradation_Modes = ”Failure detected” 3.3.2.2. Immobilization Command Request to engage / release WheelLock Request to apply / release WheelLock Values

[0141]

Table 5

[0142] Remarks ·Available only when Autonomy_State = “Autonomous Mode”. ·Available only when Autonomy_State = “Autonomous Mode”. ·Changeable only when the vehicle is stationary (Actual_Moving_Direction = ”standstill”). ·Changeable only when the vehicle is stationary (Actual_Moving_Direction = ”standstill”). ·The request is rejected when the vehicle is running. ·Reject the request when the vehicle is running. ·When Apply / Release mode change is requested, Acceleration Command is set to deceleration (-0.4m / s^2). (Only while the brake is applied.) ·When requesting a change in Apply / Release mode, also request a deceleration value (-0.4m / s^2) for the Acceleration Command.

[0143] (Assuming operation in the brake - held state) 3.3.2.3. Standstill Command Request the vehicle to be stationary Request permission / release for parking hold Values

[0144]

Table 6

[0145] Remarks ·Only available when Autonomy_State = “Autonomous Mode”. Available only when Autonomy_State = “Autonomous Mode” ·Confirmed by Standstill Status = “Applied”. Confirmed by Standstill Status = “Applied”. ·When the vehicle is stationary (Actual_Moving_Direction = “standstill”), transition to Stand Still is enabled. When the vehicle is stationary (Actual_Moving_Direction = “standstill”), enable the transition to Standstill. ·Acceleration Command has to be continued until Standstill Status becomes “Applied” and Acceleration Command’s deceleration request (-0.4m / s^2) should be continued. ·Continue to require "Applied" until Standstill Status = "Applied". It is necessary to require the deceleration value (-0.4 m / s^2) of the Acceleration Command. ·The request may not be accepted. Details are T.B.D. There are more cases where the request is not accepted. Details are T.B.D. 3.3.2.4. Acceleration Command Command vehicle acceleration. Indicate the acceleration of the vehicle Values Estimated_Max_Decel_Capability to Estimated_Max_Accel_Capability [m / s2] Remarks ·Only available when Autonomy_State = “Autonomous Mode”. Only available when Autonomy_State = “Autonomous Mode” ·Acceleration (+) and deceleration (-) request based on Propulsion Direction Status direction. Requests for acceleration (+) and deceleration (-) with respect to the direction of Propulsion Direction Status. ·The upper / lower limit will vary based on Estimated_Max_Decel_Capability and Estimated_Max_Accel_Capability. Acceleration is determined by Estimated_Max_Decel_Capability and Estimated_Max_Accel_Capability The upper and lower limits vary. ·When acceleration more than Estimated_Max_Accel_Capability is requested, the request is set to Estimated_Max_Accel_Capability. If you request a value greater than or equal to Estimated_Max_Accel_Capability, The required value is controlled as Estimated_Max_Accel_Capability. ·When deceleration more than Estimated_Max_Decel_Capability is requested, the request is set to Estimated_Max_Decel_Capability. If you request a value greater than or equal to Estimated_Max_Decel_Capability, The required value is controlled as Estimated_Max_Decel_Capability. ·Depending on the accel / brake pedal stroke, the requested acceleration may not be met. See 3.4.1.4 for more detail. Depending on the amount of accelerator or brake pedal operation, the vehicle may not respond to the requested acceleration.

[0146] For details, see 3.3.1.4. ·When Pre-Collision system is activated simultaneously, minimum acceleration (maximum deceleration) is selected. If the Pre-Collision Systems are activated simultaneously, the minimum of the acceleration required by each will be selected. 3.3.2.5. Tire Turning Angle Command Requests the tire turning angle of the front wheels. Values

[0147]

Table 7

[0148] Remarks ·Left is positive value (+). Right is negative value (-). ·Available only when Autonomy_State = “Autonomous Mode” Available only when Autonomy_State = “Autonomous Mode” ·The output of Estimated_Road_Wheel_Angle_Actual when the vehicle is going straight, is set to the reference value (0). The value output by Estimated_Road_Wheel_Angle_Actual when the vehicle is going straight is set as the reference value (0). ·This requests the relative value of Estimated_Road_Wheel_Angle_Actual. (See 3.4.1.1 for details) Requests the relative value of Estimated_Road_Wheel_Angle_Actual. (See 3.4.1.1 for details) ·The requested value is within Current_Road_Wheel_Angle_Rate_Limit. The steering angle value is requested within the range not exceeding Current_Road_Wheel_Angle_Rate_Limit. · Depending on the steering angle by the driver, the requested value may not be achievable. Depending on the driver's steering operation amount, there is a possibility that the value cannot be realized. 3.3.2.6. Autonomization Command Request to transition between manual mode and autonomy mode Values

[0149]

Table 8

[0150] Remarks · The mode may not be able to be transitioned to Autonomy mode. (e.g. In case that a failure occurs in the vehicle platform.) 3.3.3. Outputs

[0151]

Table 9

[0152] 3.3.3.1. Propulsion Direction Status Current shift range Current shift range Values

[0153]

Table 10

[0154] Remarks ·When the shift range is indeterminate., this output is set to “Invalid Value”. When the shift range is indeterminate, output “Invalid value”. ·When the vehicle becomes the following status during VO mode, [Propulsion Direction Status] will turn to “P”. - [Longitudinal_Velocity] = 0 [km / h] - [Brake_Pedal_Position] < Threshold value (T.B.D.) (in case of being determined that the pedal isn’t depressed) - [1st_Left_Seat_Belt_Status] = Unbuckled - [1st_Left_Door_Open_Status] = Opened 3.3.3.2. Propulsion Direction by Driver Shift lever position by driver operation Shift lever position by driver operation Values

[0155]

Table 11

[0156] Remarks ·Output based on the lever position operated by driver Output according to the lever position when the driver is operating the lever · If the driver releases his hand of the shift lever, the lever returns to the central position and the output is set as “No Request”. When the driver releases his hand, the lever position returns and outputs “No Request”. · When the vehicle becomes the following status during NVO mode, [Propulsion Direction by Driver] will turn to “1(P)”. - [Longitudinal_Velocity] = 0 [km / h] - [Brake_Pedal_Position] < Threshold value (T.B.D.) (in case of being determined that the pedal isn’t depressed) - [1st_Left_Seat_Belt_Status] = Unbuckled - [1st_Left_Door_Open_Status] = Opened 3.3.3.3. Immobilization Status Output EPB and Shift-P status Output the status of EPB and Shift-P. Values <primary>

[0157]

Table 12

[0158] <secondary>

[0159]

Table 13

[0160] Remarks ·Secondary signal does not include EPB lock stauts. Secondary does not include the operating status of the EPB. 3.3.3.4. Immobilization Request by Driver Driver operation of EPB switch Driver's operation of the EPB switch Values

[0161]

Table 14

[0162] Remarks ·”Engaged” is outputed while the EPB switch is being pressed When the EPB switch is pressed, "Engaged" is output. ·”Released” is outputed while the EPB switch is being pulled When the EPB switch is pulled, "Released" is output. 3.3.3.5. Standstill Status Vehicle stationary status Brake holding status Values

[0163]

Table 15

[0164] Remarks ·When Standstill Status=Applied continues for 3 minutes, EPB is activated. If the vehicle is desired to start, ADS requests Standstill Command=”Released”. ·EPB will activate after 3 minutes of Standstill Status=Applied.

[0165] If you want to release and take off, request Standstill Command="Released" from ADS. 3.3.3.6. Estimated_Coasting_Rate Estimated vehicle deceleration when throttle is closed Estimated vehicle acceleration when the throttle is fully closed Values [unit : m / s 2 ] Remarks ·estimated acceleration at WOT is calculated Calculate the estimated acceleration when the throttle is fully closed ·Slope and road load etc. are taken into estimation Estimates are made taking into account the effects of gradients, road loads, etc. ·When the Propulsion Direction Status is “D”, the acceleration to the forward direction shows a positive value. When the shift range is in "D", forward acceleration is +. ·When the Propulsion Direction Status is “R”, Acceleration in the reverse direction has a positive value. When the shift range is "R", acceleration in the reverse direction is positive. 3.3.3.7. Estimated_Max_Accel_Capability Estimated maximum acceleration Values [unit: m / s 2 Remarks ·The acceleration at WOT is calculated Calculate the acceleration estimated at full throttle ·Slope and road load etc. are taken into estimation Estimate considering the influence of slope, road load, etc. ·The direction determined by the shift position is considered positive. Calculate so that the direction of the vehicle's traveling direction determined by the shift range is positive (+). 3.3.3.8. Estimated_Max_Decel_Capability Estimated maximum deceleration Estimated maximum achievable deceleration Values -9.8 to 0 [unit: m / s 2 Remarks ·Affected by Brake_System_Degradation_Modes. Details are T.B.D. Varies depending on Brake_System_Degradation_Modes, etc. Details are T.B.D. ​​·Based on vehicle state or road condition, cannot output in some cases Depending on the vehicle state, road surface conditions, etc., there may be cases where it cannot actually be output. 3.3.3.9. Estimated_Road_Wheel_Angle_Actual Estimated front wheel tire cut angle Values

[0166]

Table 16

[0167] Remarks ·Left is positive value(+). right is negative value(-). ·Before "the wheel angle when the vehicle is going strait” becomes available, this signal is Invalid value. Until the steering angle when the vehicle is going straight can be obtained, an invalid value is output. 3.3.3.10. Estimated_Road_Wheel_Angle_Rate_Actual Front wheel steer angle rate Angular velocity of the front wheel tire cut angle Values

[0168]

Table 17

[0169] Remarks ·Left is positive value(+). right is negative value(-). 3.3.3.11. Steering_Wheel_Angle_Actual Steering wheel angle Steering angle of the steering wheel Values

[0170]

Table 18

[0171] Remarks ·Left is positive value(+). right is negative value(-). ·The steering angle converted from the steering assist motor angle. The angle converted from the steering motor rotation angle to the steering wheel shaft ·Before "the wheel angle when the vehicle is going strait” becomes available, this signal is Invalid value. Output invalid value until the steering angle when the vehicle is going straight can be obtained. 3.3.3.12. Steering_Wheel_Angle_Rate_Actual Steering angular velocity of the steering wheel Values

[0172]

Table 19

[0173] Remarks ·Left is positive value(+). right is negative value(-). ·The steering angle rate converted from the steering assist motor angle rate. The angular velocity converted from the steering motor rotation angle to the steering wheel shaft 3.3.3.13. Current_Road_Wheel_Angle_Rate_Limit Limit value of the change amount of the tire cut angle. Values ·When stopped: 0.4 [rad / s] ·While running: Show "Remarks” Remarks Calculated from the "vehicle speed - steering angle rate” chart like below. A) At a very low speed or stopped situation, use fixed value of 0.4 [rad / s]. B) At a higher speed, the steering angle rate is calculated from the vehicle speed using 2.94m / s 3 . The threshold speed between A and B is 10[km / h] Calculated from the "vehicle speed - steering angle rate” map as shown in the following figure. ·A). At extremely low speed and when stopped, use a fixed value of 0.4 [rad / s]. ·B). At speeds above low speed, calculate the steering speed from the vehicle speed 3 assuming 2.94m / s ·A and B are switched based on vehicle speed = [10km / h] (Figure 14). 3.3.3.14. Estimated_Max_Lateral_Acceleration_Capability The maximum lateral acceleration on which the control is premised Values 2.94[unit: m / s 2 fixed value Remarks ·Wheel Angle controller is designed within the acceleration range up to 2.94m / s^2 The Wheel_Angle controller is designed assuming up to 2.94m / s^2G 3.3.3.15. Estimated_Max_Lateral_Acceleration_Rate_Capability The maximum lateral acceleration on which the control is premised Values 2.94 [unit: m / s 3 fixed value Remarks ·Wheel Angle controller is designed within the acceleration range up to 2.94m / s^3 The Wheel_Angle controller is designed assuming up to 2.94m / s^3 3.3.3.16. Accelerator_Pedal_Position Position of the accelerator pedal (How much is the pedal depressed?) Values 0 to 100 [unit: %] Remarks ·In order not to change the acceleration openness suddenly, this signal is filtered by smoothing process. The accelerator opening is smoothed to prevent sudden changes. In normal condition The accelerator position signal after zero point calibration is transmitted. The accelerator opening calculated from the accelerator sensor value (after zero point correction) is transmitted In failure condition, during abnormal handling (e.g., shift to emergency driving) Transmit failsafe value (0xFF) 3.3.3.17. Accelerator_Pedal_Intervention This signal indicates whether the accelerator pedal is depressed by the driver (intervention). Values

[0174]

Table 20

[0175] Remarks · When Accelerator_Pedal_Position is higher than the defined threshold value (ACCL_INTV), this signal [Accelerator_Pedal_Intervention] will become "depressed”. When the requested acceleration from the depressed acceleration pedal is higher than the requested acceleration from the system (ADS, PCS, etc.), this signal will become "Beyond autonomy acceleration”. · During NVO mode, the accelerator request will be rejected. Therefore, this signal will not become "2”. Detailed design (Figure 15) 3.3.3.18. Brake_Pedal_Position Position of the brake pedal (How much is the pedal depressed?) Values 0 to 100 [unit: %] Remarks ·In the brake pedal position sensor failure: Transmitted failsafe value(0xFF) フェールセーフ値を送信 ·Due to assembling error, this value might be beyond 100%. 3.3.3.19. Brake_Pedal_Intervention This signal shows whether the brake pedal is depressed by a driver (intervention). Values

[0176]

表21

[0177] Remarks ·When Brake_Pedal_Position is higher than the defined threshold value(BRK_INTV), this signal [Brake_Pedal_Intervention] will turn to "depressed”. ·When the requested deceleration from depressed brake pedal is higher than the requested deceleration from system (ADS, PCS etc.), this signal will turn to "Beyond autonomy deceleration”. Detail design (Figure 16) 3.3.3.20. Steering_Wheel_Intervention This signal shows whether the steering wheel is turned by a driver (intervention). Values

[0178]

Table 22

[0179] Remarks · When "Steering Wheel Intervention = 1", considering the human driver's intent, the EPS system will drive the steering collaboratively with the human driver. When "Steering Wheel Intervention = 2", considering the human driver's intent, the EPS system will reject the steering requirement from the autonomous driving kit. (The steering will be driven by the human driver.) When Steering Wheel Intervention = 1, it is a mode in which, considering the driver's steering intent, the EPS system generates motor torque in cooperation with the driver. When Steering Wheel Intervention = 2, it is a mode in which the steering angle requirement from the autonomous driving kit is rejected and the steering is performed by the driver. 3.3.3.21. Shift_Lever_Intervention . This signal shows whether the shift lever is controlled by a driver (intervention) Values

[0180]

Table 23

[0181] Remarks ·N / A 3.3.3.22. WheelSpeed_FL, WheelSpeed_FR, WheelSpeed_RL, WheelSpeed_RR wheel speed value (wheel speed value) Values

[0182]

Table 24

[0183] Remarks ·T.B.D. 3.3.3.23. WheelSpeed_FL_Rotation, WheelSpeed_FR_Rotation, WheelSpeed_RL_Rotation, WheelSpeed_RR_Rotation Rotation direction of each wheel (Rotation direction of each wheel) Values

[0184]

Table 25

[0185] Remarks · After activation of ECU, until the rotation direction is fixed, "Forward” is set to this signal. (After ECU startup, until the rotation direction is determined, Rotation = Forward.) · When two pulses in the same direction are continuously detected, the rotation direction will be fixed. (When two pulses in the same direction are received, the rotation direction is determined.) 3.3.3.24. Actual_Moving_Direction Rotation direction of wheel (Vehicle's traveling direction) Values

[0186]

Table 26

[0187] Remarks · This signal shows "Standstill” when four wheel speed values are "0” during a constant time. (When the four wheels have a vehicle speed of 0 for a certain period of time, "Standstill” is output.) · When other than above, this signal will be determined by the majority rule of four WheelSpeed_Rotations. (Otherwise, it is determined by the majority vote of the four WheelSpeed_Rotations.) · When more than two WheelSpeed_Rotations are "Reverse”, this signal shows "Reverse”. (If there are more than two WheelSpeed_Rotations with "Reverse", output "Reverse") ·When more than two WheelSpeed_Rotations are "Forward”, this signal shows "Forward”. (If there are more than two WheelSpeed_Rotations with "Forward", output "Forward") ·When "Forward” and "Reverse” are the same counts, this signal shows ”Undefined”. (For two wheels, output "Undefined".) 3.3.3.25. Longitudinal_Velocity Estimated longitudinal velocity of vehicle (Estimated value of longitudinal velocity) Values

[0188]

Table 27

[0189] Remarks ·This signal is output as the absolute value. (Output the absolute value. Output a positive value even when reversing.) 3.3.3.26. Longitudinal_Acceleration Estimated longitudinal acceleration of vehicle (Estimated value of longitudinal acceleration) Values

[0190]

Table 28

[0191] Remarks ·This signal will be calculated with wheel speed sensor and acceleration sensor. (Values estimated using wheel speed sensor and acceleration sensor) ·When the vehicle is driven at a constant velocity on the flat road, this signal shows "0”. (When the vehicle is traveling at a constant speed on a flat road surface, it shows "0".) 3.3.3.27. Lateral_Acceleration Sensor value of lateral acceleration of vehicle (Sensor value of acceleration in the left - right direction) Values

[0192]

Table 29

[0193] Remarks ·The positive value means counterclockwise. The negative value means clockwise. (The left direction is Positive(+). The right direction is Negative(-)) 3.3.3.28. Yawrate Sensor value of Yaw rate (Sensor value of yaw rate sensor) Values

[0194]

Table 30

[0195] Remarks ·A positive value indicates counterclockwise. A negative value indicates clockwise. (Counterclockwise rotation is Positive (+). Clockwise rotation is Negative (-).) 3.3.3.29. Autonomy_State, State of whether it is in autonomous mode or manual mode Values

[0196]

Table 31

[0197] Remarks ·The initial state is the Manual mode. (When Ready ON, the vehicle will start from the Manual mode.) 3.3.3.30. Autonomy_Ready Situation of whether the vehicle can transition to autonomous mode or not Values

[0198]

Table 32

[0199] Remarks ·This signal is a part of the transition conditions to the Autonomous mode. Please refer to the summary of conditions. 3.3.3.31. Autonomy_Fault Status of whether the fault regarding a functionality in autonomy mode occurs or not Values

[0200]

Table 33

[0201] Remarks ·[T.B.D.] Please see the other material regarding the fault codes of a functionality in autonomy mode. ·[T.B.D.] Need to consider the condition to release the status of "fault”. 3.4. APIs for BODY control 3.4.1. Functions T.B.D.. 3.4.2. Inputs

[0202]

Table 34

[0203] 3.4.2.1. Turnsignallight_Mode_Command Request the operation of the turn signal. Command to control the turnsignallight mode of the vehicle platform Values

[0204]

Table 35

[0205] Remarks TBD Detailed Design When the value of Turnsignallight_Mode_Command is 1 : Turn on the right turn signal flashing request.

[0206] When the value of Turnsignallight_Mode_Command is 2 :Turn on the left turn signal flashing request. When Turnsignallight_Mode_Command =1, vehicle platform sends left blinker on request. When Turnsignallight_Mode_Command =2, vehicle platform sends right blinker on request. 3.4.2.2. Headlight_Mode_Command Requests the operation of the vehicle headlights. Command to control the headlight mode of the vehicle platform Values Light operation mode request

[0207] [Table 36]

[0208] Remarks Only accepted when Headlight_Driver_Input is OFF or AUTO mode is ON. - User actions take priority. - Change mode after receiving one request. ·This command is valid when Headlight_Driver_Input = OFF or Auto mode ON. ·Driver input overrides this command. ·When the Vehicle platform receives this command once, the headlight mode changes. 3.4.2.3. Hazardlight_Mode_Command Requests the operation of the hazard lights. Command to control the hazardlight mode of the vehicle platform Values

[0209]

Table 37

[0210] Remarks ·Give priority to user operations. ·Flash while the request is being received. ·Driver input overrides this command. ·Hazardlight is active during Vehicle Platform receives ON command. 3.4.2.4. Horn_Pattern_Command Commands the honking pattern of the horn Command to control the pattern of hone ON-time and OFF-time per cycle of the vehicle platform Values

[0211]

Table 38

[0212] Remarks ·Pattern 1 is assumed to be a single short honk, and Pattern 2 is assumed to be a repeated honk. ·Under detailed consideration. · Pattern 1 is assumed to use single short ON, Pattern 2 is assumed to use ON - OFF repeating. · Detail is under internal discussion 3.4.2.5. Horn_Nomber_of_Cycle_Command Command to control the number of horn ON / OFF cycles of the vehicle platform Command to control the Number of hone ON / OFF cycle of the vehicle platform Values 0~7[-] Remarks · Under detailed discussion. · Detail is under internal discussion 3.4.2.6. Horn_Continuous_Command Command to control continuous horn blowing operation Command to control of hone ON of the vehicle platform Values

[0213]

Table 39

[0214] Remarks · This command takes precedence over Horn_Pattern_Command, Horn_Nomber_of_Cycle_Command. · Sound the horn while the request is being received. · Under detailed discussion. · This command overrides Horn_Pattern_Command, Horn_Nomber_of_Cycle_Command. ·The horn is active when the Vehicle Platform receives the ON command. ·Details are under internal discussion 3.4.2.7. Windshieldwiper_Mode_Front_Command Commands the operating mode of the front windshield wiper. Command to control the front windshield wiper of the vehicle platform Values

[0215]

Table 40

[0216] Remarks ·The corresponding time is undetermined. ·Accepted only when Windshieldwiper_Front_Driver_Input (refer to 0) is OFF or AUTO. ·Give priority to user operations. ·Maintain the mode commanded while the request is being received. ·The timing of validity of this command is under internal discussion. ·This command is valid when Windshieldwiper_Front_Driver_Input = OFF or Auto mode ON. ·Driver input overrides this command. ·The windshield wiper mode is maintained while the Vehicle platform is receiving the command. 3.4.2.8. Windshieldwiper_Intermittent_Wiping_Speed_Command Specify the operation frequency of the front wiper in intermittent mode. Command to control the Windshield wiper actuation interval at the Intermittent mode Values

[0217]

Table 41

[0218] Remarks ·Requests are accepted only when the operation mode is the intermittent operation mode. ·Give priority to user operations. ·Change the mode when a request is received once. ·This command is valid when Windshieldwiper_Mode_Front_Status = INT. ·Driver input overrides this command. ·Windshieldwiper intermittent mode changes when Vehicle platform receives once this command. 3.4.2.9. Windshieldwiper_Mode_Rear_Command Request the operation of the rear wiper. Command to control the rear windshield wiper mode of the vehicle platform Values

[0219]

Table 42

[0220] Remarks ·Give priority to user operations. ·Maintain the commanded mode while the request is being received. ·The operating speed in the intermittent operation mode is fixed ·Driver input overrides this command. ·The windshield wiper mode is maintained while the vehicle platform is receiving the command. ·The wiping speed in the intermittent mode is not variable. 3.4.2.10. Hvac_1st_Command Command to start / stop the first row air conditioning control Values

[0221]

Table 43

[0222] Remarks ·The S-AM's HVAC has a synchronization functionality. Therefore, in order to control 4 (four) HVACs (1st_left / right, 2nd_left / right) individually, VCIB achieves the following procedure after Ready-ON. (This functionality will be implemented from the CV.) #1: Hvac_1st_Command = ON #2: Hvac_2nd_Command = ON #3: Hvac_TargetTemperature_2nd_Left_Command #4: Hvac_TargetTemperature_2nd_Right_Command #5: Hvac_Fan_Level_2nd_Row_Command #6: Hvac_2nd_Row_AirOutlet_Mode_Command #7: Hvac_TargetTemperature_1st_Left_Command #8: Hvac_TargetTemperature_1st_Right_Command #9: Hvac_Fan_Level_1st_Row_Command #10: Hvac_1st_Row_AirOutlet_Mode_Command * The interval between each command needs 200ms or more. * Other commands are able to be executed after #1. 3.4.2.11. Hvac_2nd_Command Command to start / stop 2nd row air conditioning control Values

[0223]

Table 44

[0224] Remarks ·N / A 3.4.2.12. Hvac_TargetTemperature_1st_Left_Command Command to set the target temperature around front left area Values

[0225]

Table 45

[0226] Remarks ·N / A 3.4.2.13. Hvac_TargetTemperature_1st_Right_Command Command to set the target temperature around front right area Values

[0227]

表46

[0228] Remarks ·N / A 3.4.2.14. Hvac_TargetTemperature_2nd_Left_Command Command to set the target temperature around rear left area Values

[0229]

表47

[0230] Remarks ·N / A 3.4.2.15. Hvac_TargetTemperature_2nd_Right_Command Command to set the target temperature around rear right area Values

[0231]

表48

[0232] Remarks ·N / A 3.4.2.16. Hvac_Fan_Level_1st_Row_Command Command to set the fan level on the front AC Values

[0233]

Table 49

[0234] Remarks ·If you would like to turn the fan level to 0(OFF), you should transmit "Hvac_1st_Command = OFF”. ·If you would like to turn the fan level to AUTO, you should transmit "Hvac_1st_Command = ON”. 3.4.2.17. Hvac_Fan_Level_2nd_Row_Command Command to set the fan level on the rear AC Values

[0235]

Table 50

[0236] Remarks ·If you would like to turn the fan level to 0(OFF), you should transmit "Hvac_2nd_Command = OFF”. ·If you would like to turn the fan level to AUTO, you should transmit "Hvac_2nd_Command = ON”. 3.4.2.18. Hvac_1st_Row_AirOutlet_Mode_Command Command to set the mode of 1st row air outlet Values

[0237]

Table 51

[0238] Remarks ·N / A 3.4.2.19. Hvac_2nd_Row_AirOutlet_Mode_Command Command to set the mode of 2nd row air outlet Values

[0239]

Table 52

[0240] Remarks ·N / A 3.4.2.20. Hvac_Recirculate_Command Command to set the air recirculation mode Values

[0241]

Table 53

[0242] Remarks ·N / A 3.4.2.21. Hvac_AC_Command Command to set the AC mode Values

[0243]

Table 54

[0244] Remarks ·N / A 3.4.3. Outputs

[0245]

Table 55

[0246] 3.4.3.1. Turnsignallight_Mode_Status Notifies the operating status of the turn signal. Status of the current turnsignallight mode of the vehicle platform Values

[0247]

Table 56

[0248] Remarks ·When detecting a disconnection of the turn lamp, it is considered to be lit. ·When detecting a short circuit of the turn lamp, it is considered to be off. ·At the time of the disconnection detection of the turn lamp, state is ON. ·At the time of the short detection of the turn lamp, State is OFF. 3.4.3.2. Headlight_Mode_Status Notifies the lighting status of the headlight. Status of the current headlight mode of the vehicle platform Values

[0249]

Table 57

[0250] Remarks N / A Detailed Design · When the tail lamp lighting indication signal is ON, output "1". · When the head lamp Lo lighting indication signal is ON, output "2". · When the head lamp Hi lighting indication signal is ON, output "4". · When all of the above are OFF, output "0". · When the tail signal is ON, Vehicle Platform sends 1. · When the Lo signal is ON, Vehicle Platform sends 2. · When the Hi signal is ON, Vehicle Platform sends 4. · When any of the above signals is OFF, Vehicle Platform sends 0. 3.4.3.3. Hazardlight_Mode_Status Notify the operating status of the hazard lamp. Status of the current hazard lamp mode of the vehicle platform Values

[0251]

Table 58

[0252] Remarks N / A 3.4.3.4. Horn_Status Notify the operating status of the horn. Status of the current horn of the vehicle platform Values

[0253]

Table 59

[0254] Remarks ·Failure detection is not possible. ·Output 1 when OFF during Pattern Horn blowing. ·cannot detect any failure. ·vehicle platform sends "1” during Horn Pattern Command is active, if the horn is OFF. 3.4.3.5. Windshieldwiper_Mode_Front_Status Notify the operating status of the front windshield wiper. Status of the current front windshield wiper mode of the vehicle platform Values

[0255]

Table 60

[0256]

Table 61

[0257] Remarks Fail Mode Conditions ·During communication interruption Failure detection is not possible for other cases. ·detect signal discontinuity ·cannot detect except the above failure. 3.4.3.6. Windshieldwiper_Mode_Rear_Status Notifies the current rear windshield wiper mode of the vehicle platform. Values

[0258] [Table 62]

[0259] Remarks ·Unable to detect failure ·cannot detect any failure.. 3.4.3.7. Hvac_1st_Status Status of activation of the 1st row HVAC Values

[0260] [Table 63]

[0261] Remarks N / A 3.4.3.8. Hvac_2nd_Status Status of activation of the 2nd row HVAC Values

[0262] [Table 64]

[0263] Remarks N / A 3.4.3.9. Hvac_Temperature_1st_Left_Status Status of set temperature of 1st row left Values

[0264]

Table 65

[0265] Remarks ·N / A 3.4.3.10. Hvac_Temperature_1st_Right_Status Status of set temperature of 1st row right Values

[0266]

Table 66

[0267] Remarks ·N / A 3.4.3.11. Hvac_Temperature_2nd_Left_Status Status of set temperature of 2nd row left Values

[0268]

Table 67

[0269] Remarks ·N / A 3.4.3.12. Hvac_Temperature_2nd_Right_Status Status of set temperature of 2nd row right Values

[0270]

表68

[0271] Remarks ·N / A 3.4.3.13. Hvac_Fan_Level_1st_Row_Status Status of set fan level of 1st row Values

[0272]

表69

[0273] Remarks ·N / A 3.4.3.14. Hvac_Fan_Level_2nd_Row_Status Status of set fan level of 2nd row Values

[0274]

表70

[0275] Remarks ·N / A 3.4.3.15. Hvac_1st _Row_AirOutlet_Mode_Status Status of mode of 1st row air outlet Values

[0276]

表71

[0277] Remarks ·N / A 3.4.3.16. Hvac_2nd_Row_AirOutlet_Mode_Status Status of mode of 2nd row air outlet Values

[0278]

Table 72

[0279] Remarks ·N / A 3.4.3.17. Hvac_Recirculate_Status Status of set air recirculation mode Values

[0280]

Table 73

[0281] Remarks ·N / A 3.4.3.18. Hvac_AC_Status Status of set AC mode Values

[0282]

Table 74

[0283] Remarks ·N / A 3.4.3.19. 1st_Right_Seat_Occupancy_Status Seat occupancy status in 1st left seat Values

[0284]

Table 75

[0285] Remarks When there is luggage on the seat, this signal may be send to "Occupied". If there is luggage on the seat, it may be marked as “Occupied.”

[0286] 3.4.3.20. 1st_Left_Seat_Belt_Status Status of driver's seat belt buckle switch. Values

[0287] [Table 76]

[0288] Remarks ·When Driver's seat belt buckle switch status signal is not set, [undetermined] is transmitted. It is checking to a person in charge, when using it. (Outputs "undetermined = 10” as an initial value.) ·The judgment result of buckling / unbuckling shall be transferred to CAN transmission buffer within 1.3s after IG_ON or before allowing firing, whichever is earlier. 3.4.3.21. 1st_Right_Seat_Belt_Status Status of passenger’s seat belt buckle switch Values

[0289]

Table 77

[0290] Remarks ·When Passenger's seat belt buckle switch status signal is not set, [undetermined] is transmitted. It is checking to a person in charge, when using it. (Outputs "undetermined = 10” as an initial value.) ·The judgement result of buckling / unbuckling shall be transferred to CAN transmission buffer within 1.3s after IG_ON or before allowing firing, whichever is earlier. 3.4.3.22. 2nd_Left_Seat_Belt_Status Seat belt buckle switch status in 2nd left seat Values

[0291]

Table 78

[0292] Remarks ·cannot detect sensor failure. ·The sensor cannot be judged for failure 3.4.3.23. 2nd_Right_Seat_Belt_Status Seat belt buckle switch status in 2nd right seat Values

[0293]

Table 79

[0294] Remarks ·cannot detect any failure. ·Failure determination cannot be made. 3.5. APIs for Power control 3.5.1. Functions T.B.D. 3.5.2. Inputs

[0295]

Table 80

[0296] 3.5.2.1. Power_Mode_Request Command to control the power mode of the vehicle platform Values

[0297]

Table 81

[0298] Remarks ·Regarding "wake”, let us share how to achieve this signal on the CAN. (See the other material) Basically, it is based on "ISO11989-2:2016”. Also, this signal should not be a simple value. Anyway, please see the other material. ·This API will reject the next request for a certain time[4000ms] after receiving a request. This API has a period during which it will not accept the next request for a certain time [4000ms] after receiving a request. The followings are the explanation of the three power modes, i.e. [Sleep][Wake][Driving Mode], which are controllable via API. The following is an explanation of the three power modes, [Sleep][Wake][Driving Mode], which can be controlled via the API.

[0299] [Sleep] Vehicle power off condition. In this mode, the high voltage battery does not supply power, and neither VCIB nor other VP ECUs are activated. The so-called vehicle power off state. In this state, there is no power supply from the high-voltage battery, and neither VCIB nor other ECUs are activated.

[0300] [Wake] VCIB is awakened by the low voltage battery. In this mode, ECUs other than VCIB are not awakened except for some of the body electrical ECUs. The state where the VCIB is activated by the accessory battery of the vehicle. In this state, there is no power supply from the high-voltage battery, and ECUs other than the VCIB are not activated except for some body ECUs.

[0301] [Driving Mode] Ready ON mode. In this mode, the high voltage battery supplies power to the whole VP and all the VP ECUs including VCIB are awake. The so-called mode when the vehicle becomes Ready ON. In this state, power supply from the high-voltage battery starts, and the VCIB and all ECUs in the vehicle are activated. 3.5.3. Outputs

[0302]

Table 82

[0303] 3.5.3.1. Power_Mode_Status Status of the current power mode of the vehicle platform Values

[0304]

Table 83

[0305] Remarks ·VCIB will transmit [Sleep] as Power_Mode_Status continuously for 3000[ms] after executing the sleep sequence. And then, VCIB will shutdown. After the Sleep process is executed, VCIB sends 'Sleep' as the Power_Mode_Status for 3000 [ms] and then shuts down. 3.6. APIs for Safety 3.6.1. Functions T.B.D. 3.6.2. Inputs

[0306]

Table 84

[0307] 3.6.3. Outputs

[0308]

Table 85

[0309] 3.6.3.1. Request for Operation Request for operation according to status of vehicle platform toward ADS Values

[0310]

Table 86

[0311] Remarks ·T.B.D. 3.6.3.2. Passive_Safety_Functions_Triggered Crash detection Signal Values

[0312]

Table 87

[0313] Remarks ·When the event of crash detection is generated, the signal is transmitted 50 consecutive times every 100 [ms]. If the crash detection state changes before the signal transmission is completed, the high signal of priority is transmitted. Priority : crash detection > normal ·Transmits for 5s regardless of ordinary response at crash, because the vehicle breakdown judgment system shall be send a voltage OFF request for 5s or less after crash in HV vehicle. Transmission interval is 100 ms within fuel cutoff motion delay allowance time (1s) so that data can be transmitted more than 5 times. In this case, an instantaneous power interruption is taken into account. 3.6.3.3. Brake_System_Degradation_Modes Indicate Brake_System status.(Brake_Systemのステータスを示す。) Values

[0314]

表88

[0315] Remarks ·When the Failure are detected, Safe stop is moved. (When "Failure detected" is detected, transfer to Safe Stop.) 3.6.3.4. Propulsive_System_Degradation_Modes Indicate Powertrain_System status. (Indicate the status of the Powertrain_System.) Values

[0316]

Table 89

[0317] Remarks ·When the Failure are detected, Safe stop is moved. (When "Failure detected" is detected, transfer to Safe Stop.) 3.6.3.5. Direction_Control_Degradation_Modes Indicate Direction_Control status. (Indicate the status of the Direction_Control.) Values

[0318]

Table 90

[0319] Remarks ·When the Failure are detected, Safe stop is moved. (When "Failure detected" is detected, transfer to Safe Stop.) · When failures are detected, the Propulsion Direction Command is refused (When "Failure detected" is detected, the request for Propulsion Direction Command is not accepted). 3.6.3.6. WheelLock_Control_Degradation_Modes Indicate the WheelLock_Control status. (Indicate the status of WheelLock_Control.) Values

[0320]

Table 91

[0321] Remarks · Primary indicates the EPB status, and Secondary indicates the SBW status. (Primary indicates the status of EPB, and Secondary indicates the status of SBW.) · When failures are detected, a safe stop is initiated. (When "Failure detected" is detected, a transition to Safe Stop occurs.) 3.6.3.7. Steering_System_Degradation_Modes Indicate the Steering_System status. (Indicate the status of Steering_System.) Values

[0322]

Table 92

[0323] Remarks ·When the Failure are detected, Safe stop is moved. (When "Failure detected" is detected, transfer to Safe Stop.) 3.6.3.8. Power_System_Degradation_Modes [T.B.D] 3.6.3.9. Communication_Degradation_Modes [T.B.D] 3.7. APIs for Security 3.7.1. Functions T.B.D. 3.7.2. Inputs

[0324]

Table 93

[0325] 3.7.2.1. 1st_Left_Door_Lock_Command, 1st_Right_Door_Lock_Command, 2nd_Left_Door_Lock_Command, 2nd_Right_Door_Lock_Command Requests the unlocking of each door. Command to control the each door lock of the vehicle platform Values

[0326]

Table 94

[0327] Remarks ·Only the unlocking of the D seat operates independently. ·Lock command supports only ALL Door Lock. · The unlock command supports unlocking only the 1st-left door and all doors. 3.7.2.2. Central_Vehicle_Lock_Exterior_Command Requests centralized locking and unlocking of vehicle doors, without distinguishing between exterior and interior. Command to control the all door lock of the vehicle platform. Values

[0328]

Table 95

[0329] Remarks · Individual seat control is not possible. → Locking is only possible simultaneously for all seats, unlocking is only possible for seat D or simultaneously for all seats. · The lock command supports only ALL Door Lock. · The unlock command supports unlocking only the 1st-left door and all doors. 3.7.3. Outputs

[0330]

Table 96

[0331] 3.7.3.1. 1st_Left_Door_Lock_Status Detects and notifies the lock / unlock status of the driver's door. Status of the current 1st-left door lock mode of the vehicle platform Values

[0332]

Table 97

[0333] Remarks ·Failure detection not possible ·cannot detect any failure. 3.7.3.2. 1st_Right_Door_Lock_Status Detect and notify the lock / unlock status of the front passenger door. Status of the current 1st-right door lock mode of the vehicle platform Values

[0334]

Table 98

[0335] Remarks ·Failure detection not possible ·cannot detect any failure. 3.7.3.3. 2nd_Left_Door_Lock_Status Detect and notify the lock / unlock status of the left rear door. Status of the current 2nd-left door lock mode of the vehicle platform Values

[0336]

Table 99

[0337] Remarks ·Failure detection not possible. ·cannot detect any failure. 3.7.3.4. 2nd_Right_Door_Lock_Status Detect and notify the lock / unlock status of the right rear door. Status of the current 2nd - right door lock mode of the vehicle platform Values

[0338]

Table 100

[0339] Remarks ·Failure detection not possible. ·cannot detect any failure. 3.7.3.5. Central_Vehicle_Exterior_Locked_Status Notify the centralized lock status of the vehicle doors. Status of the current all door lock mode of the vehicle platform Values

[0340]

Table 101

[0341] Remarks ·Refer to the lock status of individual doors, - If any door is not locked, notify Anything Unlocked. - If all doors are locked, notify All Locked. ·Vehicle platform refers to each door lock status, - in case any door unlocked, sends 0. - in case all door locked. sends 1 3.7.3.6. Vehicle_Alarm_Status Notifies the operating status of the vehicle auto - alarm system. Status of the current vehicle alarm of the vehicle platform Values

[0342]

Table 102

[0343] Remarks N / A 3.8. APIs for MaaS Service 3.8.1. Functions T.B.D. 3.8.2. Inputs

[0344]

Table 103

[0345] 3.8.3. Outputs

[0346]

Table 104

Example

[0347] Toyota’s MaaS Vehicle Platform Architecture Specification [Standard Edition #0.1] Revision History

[0348]

Table 105

[0349] Table of Contents 1. General Concept 4 1.1. Purpose of this Specification 4 1.2. Target Vehicle Type 4 1.3. Target Electronic Platform 4 1.4. Definition of Term 4 1.5. Precaution for Handling 4 1.6. Overall Structure of MaaS 4 1.7. Adopted Development Process 6 1.8. ODD(Operational Design Domain) 6 2. Safety Concept 7 2.1. Outline 7 2.2. Hazard analysis and risk assessment 7 2.3. Allocation of safety requirements 8 2.4. Redundancy 8 3. Security Concept 10 3.1. Outline 10 3.2. Assumed Risks 10 3.3. Countermeasure for the risks 10 3.3.1. The countermeasure for a remote attack 11 3.3.2. The countermeasure for a modification 11 3.4. Response to Stored Data Information 11 3.5. Response to Vulnerabilities 11 3.6. Contract with the Operator 11 4. System Architecture 12 4.1. Outline 12 4.2. Physical LAN architecture (in-Vehicle) 12 4.3. Power Supply Structure 14 5. Function Allocation 15 5.1. in a healthy situation 15 5.2. in a single failure 16 6. Data Collection 18 6.1. At event 18 6.2. Constantly 18 1. General Concept 1.1. Purpose of this Specification This document is an architecture specification of Toyota’s MaaS Vehicle Platform and contains the outline of system in vehicle level. This book is an architecture specification of Toyota's Vehicle Platform and describes the outline of the vehicle-level system.

[0350] 1.2. Target Vehicle Type This specification is applied to the Toyota vehicles with the electronical platform called 19ePF [ver.1 and ver.2]. The representative vehicle with 19ePF is shown as follows. e-Palette, Sienna, RAV4, and so on. This book is applicable to vehicles that adopt 19-electron PF. Representative vehicles equipped with 19-electron PF are e-Palette, Sienna, RAV4, etc. 1.3. Term Definition

[0351]

Table 106

[0352] 1.4. Handling Precautions This is an early draft of the document. All the contents are subject to change. Such changes will be notified to the users. Please note that some parts are still T.B.D. and will be updated in the future. This book is in the Early Draft version. Please note that the described content may change. Also, when the described content changes, we will contact you separately. In addition, since it is in the detailed design stage, there are scattered T.B.D. items, but they will be updated sequentially. 2. Architectural Concept 2.1. Overall Structure of MaaS The overall structure of MaaS with the target vehicle is shown. The overall configuration of MaaS using the target vehicle is shown below (Figure 17). Vehicle control technology is being used as an interface for technology providers. Technology providers can receive open API such as vehicle state and vehicle control, necessary for development of automated driving systems. The target vehicle in this book discloses vehicle control technology to ADS operators as an interface. ADS operators can use vehicle state, vehicle control, etc. necessary for the development of autonomous driving systems as APIs. 2.2. Outline of system architecture on the vehicle The system architecture on the vehicle as a premise is shown. The system configuration on the vehicle, which is a prerequisite, is shown below (Figure 18). The target vehicle of this document will adopt the physical architecture of using CAN for the bus between ADS and VCIB. In order to realize each API in this document, the CAN frames and the bit assignments are shown in the form of "bit assignment chart” as a separate document. The target vehicle of this book is configured with CAN as the connection bus between the vehicle (VCIB) and ADS in terms of physical configuration. In order to implement each API in this book with CAN, the CAN frames and data bit assignments are presented separately as the 'Bit Assignment Table'. 2.3. Outline of power supply architecture on the vehicle The power supply srcitecture as a premise is shown as follows. The assumed power supply configuration is shown below (Figure 19). The blue colored parts are provided from an ADS provider. And the orange colored parts are provided from the VP. The blue parts are loaded under the responsibility of ADS, and the orange parts are loaded under the responsibility of VP. The power structure for ADS is isolated from the power structure for VP. Also, the ADS provider should install a redundant power structure isolated from the VP. The power supply configurations for the vehicle platform and the ADS are designed to be independent. In addition, ADS operators must build a redundant power supply configuration independent of the vehicle side. 3. Safety Concept Overall safety concept The basic safety concept is shown as follows. The basic safety concepts are as follows: The strategy of bringing the vehicle to a safe stop when a failure occurs is shown as follows. The strategy for safely stopping the vehicle even when an abnormality occurs is shown below (Fig. 20). 1. After occurring a failure, the entire vehicle execute "detecting a failure" and "correcting an impact of failure" and then achieves the safety state 1. When an abnormality occurs, "detect the abnormality" and "correct the effect of the abnormality" to achieve safe state 1. 2. Obeying on the instructions from the ADS, the entire vehicle stops in a safety space at a safety speed (assumed less than 0.2G). Follow the ADS instructions and stop in a safe place at a safe deceleration rate (assuming less than 0.2G). However, depending on a situation, the entire vehicle should happen a deceleration more than the above deceleration if needed. However, this does not apply if a deceleration rate greater than the above is necessary depending on the situation. 3. After stopping, in order to prevent to slip down, the entire vehicle achieves the safety state 2 by activating the immobilization system. After stopping, the vehicle immobilization system is activated to prevent the vehicle from rolling back, achieving safety state 2.

[0353] [Table 107]

[0354] See the separated document called "Fault Management" regarding notifiable single failure and expected behavior for the ADS. For information on single faults that can be notified to ADS and the behavior expected in such cases, please refer to the separate document "Fault Management." 3.2. Redundancy The redundant functionalities with Toyota’s MaaS vehicle is shown. The redundant functions of Toyota's MaaS vehicle are shown below. Toyota’s Vehicle Platform has the following redundant functionalities to meet the safety goals led from the functional safety analysis. Toyota's vehicle platform has redundancy in the following functions to meet the safety goals derived from the functional safety analysis. Redundant Braking Redundant Brake Any single failure in the Braking System does not cause the loss of braking functionality. However, depending on where the failure occurs, the remaining capability may not be equivalent to that of the primary system. In this case, the braking system is designed to prevent the capability from becoming 0.3G or less. A single failure within the braking system does not result in the loss of braking function. However, depending on the location of the failure, the remaining performance may not be equivalent to that of the primary system. Even in such a case, it is designed so that the capability does not fall below 0.3G. Redundant Steering Redundant Steering Any single failure on the Steering System doesn’t cause to lose steering functionality. However, depending on where the failure occurred in, the capability left might not be equivalent to the primary system’s capability. In this case, the steering system is designed to prevent that the capability becomes to 0.3G or less. A single failure within the steering system does not result in the loss of steering functionality. However, depending on where the failure occurs, the remaining capability may not be equivalent to that of the primary system. Even in such a case, the system is designed to prevent the capability from dropping to 0.3G or less. Redundant Immobilization Redundant vehicle immobilization Toyota’s MaaS vehicle has 2 immobilization systems. i.e. P lock and EPB. Therefore, any single failure of the immobilization system doesn’t cause to lose the immobilization capability. However, in the case of failure, the maximum stationary slope angle is less steep than when the systems are healthy. Toyota's MaaS vehicle has two independent immobilization systems, the P lock and the EPB. Therefore, a single failure does not cause the loss of the immobilization function. However, when a failure occurs, the maximum stationary slope angle is reduced compared to when both systems are operational. Redundant Power Redundant power supply Any single failure on the Power Supply System doesn’t cause to lose power supply functionality. However, in case of the primary power failure, the secondary power supply system keeps to supply power to the limited systems for a certain time. A single failure within the power supply system does not result in the loss of power supply functionality. However, in the event of a primary power failure, the secondary power supply system continues to supply power to limited systems for a certain period of time. Redundant Communication Redundant communication Any single failure on the Communication System doesn’t cause to lose all the communication functionality. System which needs redundancy has physical redundant communication lines. For more detail imformation, see the chapter "Physical LAN architecture(in-Vehicle)”. A single failure within the communication system does not result in the loss of all communication functionality. Systems that require redundancy have physically redundant communication lines. For more detailed information, see the chapter "Physical LAN architecture (in-vehicle)". 4. Security Concept 4.1. Outline Regarding security, Toyota’s MaaS vehicle adopts the security document issued by Toyota as an upper document. Regarding security, the MaaS vehicle of Toyota uses the security document issued by Toyota as the upper document. None 4.2. Assumed Risks The entire risk includes not only the risks assumed on the base e-PF but also the risks assumed for the Autono-MaaS vehicle. Define the entire assumed risk as the sum of the threats assumed for the base e-PF and the threats specific to the Autono-MaaS vehicle. The entire risk is shown as follows. The threats assumed in this document are shown as follows. [Remote Attack] - To vehicle ·Spoofing the center ·ECU Software Alternation ·DoS Attack ·Sniffering - From vehicle ·Spoofing the other vehicle ·Software Alternation for a center or a ECU on the other vehicle ·DoS Attack to a center or other vehicle ·Uploading illegal data [Modification] ·Illegal Reprogramming ·Setting up a illegal ADK ·Installation of an unauthenticated product by a customer 4.3. Countermeasure for the risks The countermeasure of the above assumed risks is shown as follows. The countermeasures for the assumed threats mentioned above are shown below. 4.3.1. The countermeasure for a remote attack The countermeasure for a remote attack is shown as follows. The countermeasures for remote attacks are shown below. Since the autonomous driving kit communicates with the operator's center, it is necessary to ensure end-to-end security. Also, since it has a function to issue driving control instructions, multi-layered defense within the autonomous driving kit is necessary. Use secure microcontrollers and security chips within the autonomous driving kit to provide sufficient security measures as the first layer of external access prevention. Also, use separate secure microcontrollers and security chips to provide security measures as the second layer. (Have multi-layered defenses such as the first layer of defense to prevent direct external intrusion and the second layer of defense beneath it within the autonomous driving kit) 4.3.2. The countermeasure for a modification The countermeasure for a modification is shown as follows. The countermeasures for modification are shown below. Equip the fake autonomous driving kit with device authentication and message authentication. Regarding key storage, implement countermeasures against tampering and change the key set for each pair of the vehicle and the autonomous driving kit. Or include in the contract to ensure sufficient management by the operator so that unauthorized kits are not installed. Include in the contract that the operator manages to prevent unauthorized products from being installed to prevent Autono-MaaS vehicle users from attaching counterfeit products. When applying to an actual vehicle, conduct threat analysis together, and in the autonomous driving kit, ensure that countermeasures have been completed for the latest vulnerabilities at the time of LO. 5. Function Allocation 5.1. in a healthy situation The allocation of representative functionalities is shown as below. The allocation of representative functions is shown below (Figure 21). [Function allocation]

[0355]

Table 108

[0356] 5.2. in a single failure See the separate document called "Fault Management” regarding notifiable single failure and expected behavior for the ADS. Regarding notifiable single failures of the ADS and the expected behavior in such cases, refer to the separate document "Fault Management".

[0357] The embodiments disclosed herein should be considered illustrative in all respects and not restrictive. The scope of the present invention is defined by the claims rather than the above description, and it is intended that all modifications within the meaning and scope equivalent to the claims be included.

Explanation of reference numerals

[0358] 10 Vehicle, 100 Vehicle Body, 110 Vehicle Control Interface, 111, 112 VCIB, 120 VP, 121A, 121B Brake System, 122A, 122B Steering System, 123A EPB System, 123B P-Lock System, 124 Propulsion System, 125 PCS System, 126 Body System, 127 Wheel Speed Sensor, 128A, 128B Pinion Angle Sensor, 129 Camera / Radar, 190 DCM, 200 ADK, 202 ADS, 210 Computer, 230 HMI, 260 Recognition Sensor, 270 Attitude Sensor, 290 Sensor Cleaner, 500 Data Server, 600 MSPF, 700 Mobility Service.< / secondary> < / primary>

Claims

Claim 1 A vehicle capable of mounting an automatic driving system, a vehicle platform that executes vehicle control according to a command from the automatic driving system, and a vehicle control interface that interfaces between the automatic driving system and the vehicle platform, wherein a first command for requesting an acceleration value or a deceleration value and a second command for requesting immobilization of the vehicle are transmitted from the automatic driving system to the vehicle platform via the vehicle control interface, a signal indicating a stopped state of the vehicle is transmitted from the vehicle platform to the automatic driving system via the vehicle control interface, and when deceleration of the vehicle platform is requested by the first command, the vehicle transmits the signal to the automatic driving system when the vehicle stops, and immobilizes the vehicle according to the second command received after transmitting the signal.

Citation Information

Patent Citations

  • JP1989001160U

  • Automatic running control device for vehicle

    JP1990133243A

  • Stop maintenance device for vehicle

    JP1996048221A

  • Integrated control system for vehicle

    JP2005178628A

  • Autonomous readiness vehicle

    JP2018506461A