Vehicle and vehicle control interface
The vehicle control interface addresses unreliable communication failures by switching to a secondary system and maintaining communication through it after a predetermined time, ensuring reliable vehicle control.
Patent Information
- Application Number
- JP2024082993
- Authority / Receiving Office
- JP · JP
- Patent Type
- Applications
- Current Assignee / Owner
- Filing Date
- 2024-05-22
- Publication Date
- 2025-12-05
AI Technical Summary
Existing autonomous driving systems face challenges in maintaining appropriate vehicle control when communication between the autonomous driving kit (ADK) and the vehicle platform (VP) is interrupted, particularly when the main communication system fails and switches to a secondary system, risking unreliable control requests due to potential power resets or failures.
Implementing a vehicle control interface that switches to a secondary communication system if the primary system fails, and after a predetermined time, continues communication through the secondary system regardless of the primary system's status, ensuring reliable control requests from the ADK to the VP.
Ensures appropriate vehicle control by maintaining reliable communication through the secondary system, even after a failure, thereby preventing unreliable control requests and ensuring smooth vehicle operation.
Smart Images

Figure 2025176732000001_ABST
Abstract
Description
[Technical Field]
[0001] The present disclosure relates to vehicles and vehicle control interfaces, and more particularly to vehicles that can be equipped with automated driving systems and vehicle control interfaces that interface between the automated driving systems and the vehicle platform. [Background technology]
[0002] Japanese Patent Laid-Open Publication No. 2018-132015 (Patent Document 1) discloses a vehicle equipped with an autonomous driving system. The autonomous driving system includes a camera, a laser device, a radar device, an operation device, a gradient sensor, an autonomous driving device, and an autonomous driving ECU (Electronic Control Unit) (see paragraph
[0023] of Patent Document 1). [Prior art documents] [Patent documents]
[0003] [Patent Document 1] Japanese Patent Application Publication No. 2018-132015 Summary of the Invention [Problem to be solved by the invention]
[0004] It is possible to attach an autonomous driving system externally to a vehicle platform. In this case, autonomous driving is achieved by the vehicle platform operating in accordance with commands from the autonomous driving system. Such an autonomous driving system will be referred to below as an autonomous driving kit (ADK). The vehicle platform will also be referred to as a VP (Vehicle Platform).
[0005] To ensure proper coordination between the ADK and VP, it is desirable to provide an appropriate interface between them. This interface is called a "vehicle control interface." The importance of a vehicle control interface becomes particularly evident when the ADK development company (e.g., a venture company) and the VP development company (typically a completed vehicle manufacturer) are different companies.
[0006] It is possible to duplicate (make redundant) the communication system between the ADK and the vehicle control interface. One of the duplicated communication systems is referred to as the "main system" and the other as the "sub-system."
[0007] Under normal circumstances, communication between the ADK and the vehicle control interface is via the main system. If a fault occurs in the main system and communication via the main system is interrupted, communication between the ADK and the vehicle control interface is switched from the main system to the sub-system.
[0008] In some cases, after switching to the sub-system, the main system recovers from the failure and communication becomes possible. The inventors have discovered that in such a situation, in order to properly control the vehicle in the VP, it may be necessary to appropriately select the communication system between the ADK and the vehicle control interface.
[0009] The present disclosure has been made to solve the above-mentioned problems, and one of the objects of the present disclosure is to appropriately perform vehicle control in a vehicle platform (VP). [Means for solving the problem]
[0010] According to an aspect of the present disclosure, a vehicle is configured to be equipped with an autonomous driving system. The vehicle includes a vehicle platform that controls the vehicle in accordance with commands from the autonomous driving system, and a vehicle control interface that interfaces between the autonomous driving system and the vehicle platform by communication via a main system or a sub-system. The vehicle control interface starts communication via the sub-system when communication via the main system is interrupted, and starts communication via the main system if communication via the main system becomes possible before a predetermined period of time has elapsed after communication via the sub-system has started. However, after the predetermined period of time has elapsed, the vehicle control interface continues communication via the sub-system regardless of whether communication via the main system is possible or not.
[0011] According to another aspect of the present disclosure, a vehicle control interface interfaces between an automated driving system and a vehicle platform. The vehicle control interface includes a processor that communicates with the automated driving system via a main system or a secondary system. The processor starts communication via the secondary system when communication via the main system is interrupted, and starts communication via the main system if communication via the main system becomes available before a predetermined period of time has elapsed after communication via the secondary system has started. However, after the predetermined period of time has elapsed, the processor continues communication via the secondary system regardless of whether communication via the main system is available. [Effects of the Invention]
[0012] According to the present disclosure, vehicle control in VP can be performed appropriately. [Brief explanation of the drawings]
[0013] [Figure 1] 1 is a diagram illustrating an overview of the overall configuration of a vehicle according to an embodiment of the present disclosure. [Figure 2] This figure shows the configuration of the Autonomous Driving Kit (ADK), Vehicle Platform (VP), and Vehicle Control Interface (VCIB) in more detail. [Figure 3] FIG. 10 is a diagram showing a communication system between an ADK, a VP, and a VCIB. [Figure 4] 10 is a flowchart illustrating an example of a processing procedure at the start of communication according to the present embodiment. [Figure 5] 10 is a flowchart illustrating an example of a processing procedure for selecting a communication system according to the present embodiment. DETAILED DESCRIPTION OF THE INVENTION
[0014] Hereinafter, embodiments of the present disclosure will be described in detail with reference to the drawings. In the drawings, the same or corresponding parts are designated by the same reference numerals, and description thereof will not be repeated.
[0015] [Embodiment Mode] <Overall structure> 1 is a diagram illustrating an overview of the overall configuration of a vehicle according to an embodiment of the present disclosure. The vehicle 1 includes an autonomous driving kit (ADK) 10, a vehicle platform (VP) 20, and a vehicle control interface box (VCIB) 30. The ADK 10 and the VP 20 are connected to each other via the vehicle control interface 30 so as to be able to communicate with each other.
[0016] The ADK10 includes an automatic driving system for performing automatic driving of the vehicle 1. For example, the ADK10 creates a driving plan (trip) for the vehicle 1. The ADK10 outputs various control requests for driving the vehicle 1 according to the driving plan to the VP20 in accordance with an API (Application Program Interface) defined for each control request. The ADK10 also receives various signals indicating the vehicle state (state of the VP20) from the VP20 in accordance with an API defined for each signal. The ADK10 then reflects the vehicle state in the driving plan.
[0017] The VP 20 executes various vehicle controls in accordance with control requests from the ADK 10. The VP 20 includes various on-board systems and sensors. More specifically, the VP 20 includes an integrated control manager 21, a brake system 22, a steering system 23, a powertrain system 24, an active safety system 25, a body system 26, wheel speed sensors 41 and 42, a pinion angle sensor 43, a camera 44, and radar sensors 45 and 46.
[0018] The integrated control manager 21 includes a processor such as a CPU (Central Processing Unit) and memories such as a ROM (Read Only Memory) and a RAM (Random Access Memory), neither of which are shown in the figure. The integrated control manager 21 integrates and controls the above-mentioned systems related to the operation of the vehicle 1 (the brake system 22, the steering system 23, the powertrain system 24, the active safety system 25, and the body system 26).
[0019] The VCIB 30 is configured to be able to communicate with the ADK 10 via a CAN (Controller Area Network) or the like. The VCIB 30 executes a predetermined API defined for each signal to receive control requests from the ADK 10 and output vehicle status to the ADK 10. When the VCIB 30 receives a control request from the ADK 10, it outputs a control command corresponding to the control request to a system corresponding to the control command via the integrated control manager 21. The VCIB 30 also acquires various types of information about the VP 20 from various systems via the integrated control manager 21 and outputs the status of the VP 20 to the ADK 10 as the vehicle status.
[0020] The ADK10 is configured to be attachable (mounted) to and detachable from the VP 20. Although the ADK10 is shown in a position separate from the VP 20 in Figure 1, the ADK10 is actually attached to the rooftop of the VP 20, etc. When the ADK10 is detached, the VP 20 performs driving control in manual mode (driving control according to user operation).
[0021] <Configuration of each component> Fig. 2 is a diagram showing in more detail the configurations of the ADK 10, VP 20, and VCIB 30. Fig. 3 is a diagram for explaining the communication system between the ADK 10, VP 20, and VCIB 30.
[0022] 2 and 3, the ADK 10 includes a computer 11, a human machine interface (HMI) 12, a recognition sensor 13, a posture sensor 14, and a sensor cleaner 15.
[0023] The computer 11 includes a processor 11A such as a CPU and a memory 11B such as a ROM and RAM. The memory 11B stores programs executable by the processor 11A. During autonomous driving of the vehicle 1, the computer 11 acquires information about the environment of the vehicle 1, as well as the attitude, behavior, and position of the vehicle 1, using various sensors, and also acquires the vehicle state from the VP 20 via the VCIB 30 to set the next operation of the vehicle 1 (acceleration, deceleration, turning, etc.). The computer 11 outputs various control requests to the VCIB 30 to realize the next operation.
[0024] The computer 11 further includes an ADK main module 111, an ADK sub-module 112, a communication module 113, and a communication module 114. The ADK main module 111 is configured to be able to communicate with the main VCIB 31 via the communication module 113. The ADK sub-module 112 is configured to be able to communicate with the sub-VCIB 32 via the communication module 114. Furthermore, the ADK main module 111 and the ADK sub-module 112 are connected to each other so that they can communicate with each other.
[0025] In the VP 20, the brake system 22 includes brake systems 221 and 222. The steering system 23 includes steering systems 231 and 232. The powertrain system 24 includes an electric parking brake (EPB) system 241, a parking lock (P-Lock) system 242, and a propulsion system 243.
[0026] The VCIB 30 includes a main VCIB 31 and a sub-VCIB 32. The main VCIB 31 includes a processor 31A such as a CPU and a memory 31B such as a ROM and RAM. The memory 31B stores programs executable by the processor 31A. Similarly, the sub-VCIB 32 includes a processor 32A and a memory 32B. The memory 32B stores programs executable by the processor 32A.
[0027] Each of the main VCIB 31 and the sub-VCIB 32 relays control requests and information indicating vehicle status between the ADK 10 and the VP 20. The main VCIB 31 and the ADK main module 111 are connected to each other via an in-bus (corresponding to the "main system" in this disclosure) 51 so that they can communicate with each other. The main VCIB 31 interfaces between the VP 20 and the ADK 10 (ADK main module 111) via the main bus 51. The sub-VCIB 32 and the ADK sub-module 112 are connected to each other via a sub-bus (corresponding to the "sub-system" in this disclosure) 52 so that they can communicate with each other. The sub-VCIB 32 interfaces between the VP 20 and the ADK 10 (ADK sub-module 112) via the sub-bus 52. Furthermore, the main VCIB 31 and the sub-VCIB 32 are connected to each other so that they can communicate with each other.
[0028] The main VCIB 31 and the sub-VCIB 32 basically have the same functions. However, the main VCIB 31 and the sub-VCIB 32 are partially different in the connections to the systems included in the VP 20. Specifically, the main VCIB 31, the brake system 221, the steering system 231, the EPB system 241, the P-Lock system 242, the propulsion system 243, and the body system 26 are interconnected via a communication bus so as to be able to communicate with each other. The sub-VCIB 32, the brake system 222, the steering system 232, and the P-Lock system 242 are interconnected via a communication bus so as to be able to communicate with each other.
[0029] In this way, in the vehicle 1, the main VCIB 31 and the sub-VCIB 32 have equivalent functions with respect to some system operations (braking, steering, etc.). In addition, the ADK 10 includes an ADK main module 111 and an ADK sub-module 112, and the ADK 10 and the VP 20 are connected by a main bus 51 and a sub-bus 52. This makes the system including the ADK 10, VP 20, and VCIB 30 redundant (dual).
[0030] <Communication loss and resumption> Under normal circumstances, communication between the ADK 10 and the VCIB 30 is performed via the main bus 51. If some kind of failure occurs in the main bus 51 and communication via the main bus 51 is interrupted, communication between the ADK 10 and the VCIB 30 is switched from via the main bus 51 to via the sub-bus 52.
[0031] After switching to communication via the sub-bus 52, for example, the power supply to the main bus 51 may be reset, causing the main bus 51 to recover (restore) from the failure and become able to communicate. In this case, it may be possible to return communication between the ADK 10 and the VCIB 30 from communication via the sub-bus 52 to communication via the main bus 51.
[0032] However, when the main bus 51 recovers from the failure, there is a possibility that information necessary for the autonomous driving of the vehicle 1 (such as its own position) may be lost or that the ADK 10 (ADK main module 111) may be returned to its initial state due to the power reset of the main bus 51. In this case, the reliability of the control request given to the VP 20 from the ADK 10 via the main bus 51 may be low, and the possibility cannot be denied that the control request may be inappropriate. As a result, it may be difficult for the VP 20 to control the vehicle appropriately.
[0033] Therefore, in the "communication system selection" of this embodiment, if a predetermined period of time has passed since switching to the sub-bus 52 due to a communication interruption on the main bus 51, it is assumed that there is a possibility that the ADK 10 (ADK main module 111) has failed, and communication continues via the sub-bus 52. This process will be described in detail below.
[0034] <Processing flow> 4 is a flowchart showing an example of a processing procedure at the start of communication in this embodiment. The processing shown in this flowchart is called from a main routine (not shown) at predetermined intervals when a predetermined condition is met, for example, after the ADK 10 has completed a travel plan. Each step is realized by software processing by the VCIB 30 (main VCIB 31 and sub VCIB 32), but some or all of the steps may be realized by hardware (electrical circuits) arranged in the ECU. The same applies to the flowchart in FIG. 5, which will be described later. Hereinafter, steps are abbreviated as S.
[0035] 3 and 4, in S11, the VCIB 30 determines whether the power of the VP 20 has been turned on (whether the power has been switched from off to on). If the power of the VP 20 has not been turned on (NO in S11), the VCIB 30 skips the subsequent processing and returns the processing to the main routine.
[0036] When the VP20 is powered on (YES in S11), the VCIB30 determines whether communication between the ADK10 and the VCIB30 is possible via the main bus 51 (S12). If communication via the main bus 51 is possible (YES in S12), the VCIB30 starts communication between the ADK10 and the VCIB30 via the main bus 51 (S13). On the other hand, if communication via the main bus 51 is not possible (NO in S12), the VCIB30 starts communication between the ADK10 and the VCIB30 via the sub-bus 52 (S14).
[0037] 5 is a flowchart showing an example of a processing procedure for selecting a communication system in this embodiment. With reference to FIGS. 3 and 5, in S21, the VCIB 30 determines whether the ADK 10 and the VCIB 30 are communicating via the main bus 51. If the ADK 10 and the VCIB 30 are not communicating via the main bus 51 (NO in S21), that is, if they are communicating via the sub-bus 52, the VCIB 30 skips the subsequent processing and returns the processing to the main routine.
[0038] If the ADK 10 and the VCIB 30 are communicating via the main bus 51 (YES in S21), the VCIB 30 determines whether communication via the main bus 51 has been interrupted due to some kind of failure (S22). If communication via the main bus 51 has not been interrupted (NO in S22), the VCIB 30 returns the process to the main routine.
[0039] If communication via the main bus 51 has been interrupted (YES in S22), the VCIB 30 determines whether the period during which communication has been interrupted (communication interruption period) is longer than a predetermined first period (S23).
[0040] If the communication interruption period is equal to or shorter than the first period (NO in S23), the VCIB 30 determines whether communication via the main bus 51 has become possible (whether the main bus 51 has recovered from the failure) (S24). If communication via the main bus 51 has become possible (YES in S24), the VCIB 30 returns the process to the main routine. In this case, communication via the main bus 51 is resumed. If communication via the main bus 51 is not possible (NO in S24), the VCIB 30 returns the process to S23. This allows attempts to resume communication via the main bus 51 to continue.
[0041] When the communication outage period becomes longer than the first period (YES in S23), the VCIB 30 starts communication between the ADK 10 and the VCIB 30 via the sub-bus 52 (S25). In other words, the VCIB 30 switches communication from via the main bus 51 to via the sub-bus 52.
[0042] In S26, the VCIB 30 determines whether the period after switching communication from via the main bus 51 to via the sub-bus 52 (the period after switching) is longer than a predetermined second period. The second period may be set to a period shorter than the time required to reset the power supply of the ADK 10 (ADK main module 111). The second period corresponds to the "predetermined period" according to the present disclosure.
[0043] If the period after the switch is equal to or shorter than the second period (NO in S26), the VCIB 30 determines whether communication via the main bus 51 is possible (whether the main bus 51 has recovered from the failure) (S27). If communication via the main bus 51 is possible (YES in S27), the VCIB 30 starts communication between the ADK 10 and the VCIB 30 via the main bus 51 (S28). If communication via the main bus 51 is not possible (NO in S27), the VCIB 30 returns the process to S26.
[0044] If the period after switching is longer than the second period (YES in S26), there is a possibility that the ADK main module 111 has failed or that the power supply of the ADK main module 111 has been reset, so the VCIB 30 continues communication between the ADK 10 and the VCIB 30 via the sub-bus 52 (S29). In other words, the VCIB 30 selects communication via the sub-bus 52 regardless of whether communication via the main bus 51 is possible. The VCIB 30 continues communication via the sub-bus 52 until the driving plan by the ADK 10 is completed.
[0045] As described above, in this embodiment, if the second period has elapsed after communication between the ADK 10 and the VCIB 30 has been switched from via the main bus 51 to via the sub-bus 52 due to a communication interruption on the main bus 51, the communication via the sub-bus 52 is continued without communicating via the main bus 51, in consideration of the possibility of a power reset or failure of the ADK main module 111. This is because, under such circumstances, control requests from the ADK sub-module 112 are more reliable than control requests from the ADK main module 111. Therefore, according to this embodiment, the communication system between the ADK 10 and the VCIB 30 is appropriately selected, thereby enabling the VP 20 to perform appropriate vehicle control.
[0046] The embodiments disclosed herein should be considered to be illustrative in all respects and not restrictive. The scope of the present disclosure is defined by the claims, not by the description of the above embodiments, and is intended to include all modifications within the meaning and scope of the claims. [Explanation of symbols]
[0047] 1 Vehicle, 11 Computer, 11A Processor, 11B Memory, 111 ADK Main Module, 112 ADK Sub-Module, 113, 114 Communication Module, 12 HMI, 13 Recognition Sensor, 14 Attitude Sensor, 15 Sensor Cleaner, 21 Integrated Control Manager, 22, 221, 222 Brake System, 23, 231, 232 Steering System, 24 Powertrain System, 241 EPB System, 242 P-Lock System, 243 Propulsion System, 25 Active Safety System, 26 Body System, 30 Vehicle Control Interface (VCIB), 31 Main VCIB, 32 Sub-VCIB, 31A, 32A Processor, 31B, 32B Memory, 41, 42 Wheel Speed Sensor, 43 Pinion Angle Sensor, 44 Camera, 45, 46 Radar Sensor, 51 Main Bus, 52 Sub-Bus.
Claims
1. A vehicle configured to be able to mount an autonomous driving system, a vehicle platform that controls the vehicle in accordance with commands from the automated driving system; a vehicle control interface that interfaces between the automated driving system and the vehicle platform by communication via a main system or a sub-system; The vehicle control interface When communication via the main system is interrupted, communication via the sub-system is started; The vehicle starts communication via the main system if communication via the main system becomes possible before a predetermined period of time has elapsed after communication via the sub-system has started, and continues communication via the sub-system after the predetermined period of time has elapsed regardless of whether communication via the main system is possible or not.
2. The vehicle according to claim 1 , wherein the vehicle control interface continues communication via the sub-system after the predetermined period has elapsed until a driving plan by the automated driving system is completed.
3. 3. The vehicle of claim 2, wherein the vehicle control interface communicates via the main system when power to the vehicle platform is switched from off to on after the trip plan is completed and communication via the main system is possible.
4. A vehicle control interface that interfaces between an automated driving system and a vehicle platform, A processor that communicates with the automated driving system via a main system or a sub-system, The processor: When communication via the main system is interrupted, communication via the sub-system is started; A vehicle control interface that starts communication via the main system if communication via the main system becomes possible before a predetermined period of time has elapsed after communication via the sub-system has started, and continues communication via the sub-system after the predetermined period of time has elapsed regardless of whether communication via the main system is possible or not.
Citation Information
Patent Citations
Automatic operation controller
JP2018132015A