Vehicle and vehicle control interface box
By setting distinct time thresholds for autonomous and remote driving modes, the vehicle platform effectively manages communication abnormalities, enhancing vehicle control reliability in both scenarios.
Patent Information
- Application Number
- JP2024093419
- Authority / Receiving Office
- JP · JP
- Patent Type
- Applications
- Current Assignee / Owner
- Filing Date
- 2024-06-10
- Publication Date
- 2025-12-22
AI Technical Summary
Existing vehicles with automated driving systems face challenges in appropriately determining communication abnormalities between the autonomous driving system and the vehicle platform during both autonomous and remote driving scenarios.
The vehicle platform is configured to determine communication abnormalities by setting different time thresholds for autonomous and remote driving modes, with a shorter threshold for remote driving to account for wireless delays, thereby preventing outdated commands and erroneous determinations during remote operation.
This approach allows for effective handling of communication abnormalities in both autonomous and remote driving modes, ensuring timely and accurate vehicle control by switching communication paths when necessary.
Smart Images

Figure 2025185289000001_ABST
Abstract
Description
[Technical Field]
[0001] The present disclosure relates to a vehicle and a vehicle control interface box, and more particularly to a vehicle equipped with an automated driving system and a vehicle control interface box for a vehicle equipped with an automated driving system. [Background technology]
[0002] Japanese Patent Application Laid-Open Publication No. 2018-132015 (Patent Document 1) discloses a vehicle equipped with an autonomous driving system. The autonomous driving system includes a camera, a laser device, a radar device, an operation device, a gradient sensor, an autonomous driving device, and an autonomous driving ECU (Electronic Control Unit) (see paragraph
[0023] of Patent Document 1). [Prior art documents] [Patent documents]
[0003] [Patent Document 1] Japanese Patent Application Publication No. 2018-132015 Summary of the Invention [Problem to be solved by the invention]
[0004] For example, some vehicles for mobility services (autonomous vehicles) include a vehicle platform configured to enable not only autonomous driving but also remote driving. Autonomous driving is driving in accordance with commands output to the vehicle platform from an autonomous driving system installed in the vehicle. Remote driving is driving in accordance with commands transmitted to the vehicle platform from outside the vehicle (such as a server located in a remote location) via the autonomous driving system.
[0005] In a vehicle configured as described above, there is a possibility that communication between the autonomous driving system and the vehicle platform may be interrupted. If the communication interruption persists for a specified period of time, the vehicle platform (more specifically, the vehicle control interface box described below) determines that a communication abnormality has occurred. It is desirable to be able to appropriately determine whether a communication abnormality has occurred in both autonomous driving and remote driving.
[0006] The present disclosure has been made to solve the above-mentioned problems, and one of the objectives of the present disclosure is to provide a vehicle that can appropriately respond to communication abnormalities between an automated driving system and a vehicle platform in both autonomous driving and remote driving. [Means for solving the problem]
[0007] According to one aspect of the present disclosure, a vehicle includes a vehicle platform configured to perform vehicle control by communicating with an automated driving system. The automated driving system is configured to output to the vehicle platform commands for autonomous driving in accordance with commands from the automated driving system and commands for remote driving in accordance with commands from outside the vehicle. The vehicle platform determines that an abnormality has occurred in communication between the automated driving system and the vehicle platform if a situation in which communication with the automated driving system is lost continues for a first period or longer during autonomous driving, and determines that an abnormality has occurred in communication between the automated driving system and the vehicle platform if a situation in which communication with the automated driving system is lost continues for a second period or longer during remote driving. The second period is shorter than the first period. [Effects of the Invention]
[0008] According to the present disclosure, communication abnormalities between an automated driving system and a vehicle platform can be appropriately handled during both autonomous driving and remote driving. [Brief explanation of the drawings]
[0009] [Figure 1] 1 is a diagram illustrating a schematic overall configuration of a vehicle according to an embodiment of the present disclosure. [Figure 2] FIG. 2 is a diagram showing the configuration of the ADK, VP, and VCIB in more detail. [Figure 3] FIG. 10 is a diagram illustrating a communication system between an ADK, a VCIB, and an integrated control manager. [Figure 4] 10 is a flowchart showing an example of a processing procedure by the VCIB in response to a communication abnormality in the present embodiment. DETAILED DESCRIPTION OF THE INVENTION
[0010] Hereinafter, embodiments of the present disclosure will be described in detail with reference to the drawings. In the drawings, the same or corresponding parts are designated by the same reference numerals, and description thereof will not be repeated.
[0011] [Embodiment Mode] <Overall structure> 1 is a diagram schematically illustrating the overall configuration of a vehicle according to an embodiment of the present disclosure. Vehicle 1 is, for example, an autonomous driving vehicle for a mobility service, and includes an automated driving kit (ADK) 10 and a vehicle platform (VP) 20. VP 20 includes a vehicle control interface box (VCIB) 30 and a base vehicle 40. ADK 10 and VP 20 (an integrated control manager 41, described later) are connected to each other via vehicle control interface box 30 so as to be able to communicate with each other.
[0012] The ADK10 is an automated driving system (ADS) for automatically driving the vehicle 1. For example, the ADK10 creates a driving plan (trip) for the vehicle 1. The ADK10 outputs various control commands (control requests) for driving the vehicle 1 according to the driving plan to the VCIB30 in accordance with an API (Application Program Interface) defined for each control command. The ADK10 also receives various signals indicating the vehicle state (state of the VP20) from the VCIB30 in accordance with the API defined for each signal. The ADK10 then reflects the vehicle state in the driving plan.
[0013] The ADK10 outputs an autonomous driving command to the VCIB30 for the VP20 to perform autonomous driving. In addition, the ADK10 is configured to communicate with an external server 9. The external server 9 is managed by the operator of the vehicle 1 and is located in a remote location (such as the operator's server room). The ADK10 receives a remote driving command from the external server 9 for the VP20 to perform remote driving, and outputs the received remote driving command to the VCIB30.
[0014] The VP 20 has an automatic mode and a manual mode. In the automatic mode, the VP 20 executes various vehicle controls in accordance with control commands (including autonomous driving commands and remote driving commands) received from the ADK 10. On the other hand, in the manual mode, the VP 20 executes vehicle controls in accordance with user operations.
[0015] The base vehicle 40 includes various on-board systems and sensors. More specifically, the base vehicle 40 includes an integrated control manager 41, a brake system 42, a steering system 43, a powertrain system 44, an active safety system 45, a body system 46, wheel speed sensors 51 and 52, a pinion angle sensor 53, a camera 54, and radar sensors 55 and 56.
[0016] The integrated control manager 41 includes a processor such as a CPU (Central Processing Unit) and memories such as a ROM (Read Only Memory) and a RAM (Random Access Memory), neither of which are shown in the figure. The integrated control manager 41 integrates and controls the above-mentioned systems related to the operation of the vehicle 1 (the brake system 42, the steering system 43, the powertrain system 44, the active safety system 45, and the body system 46).
[0017] The VCIB 30 is configured to be able to communicate with the ADK 10 and the base vehicle 40 via a CAN (Controller Area Network) or the like. The VCIB 30 receives control commands from the ADK 10 and outputs vehicle status to the ADK 10 by executing a predetermined API defined for each signal, command, or request. When the VCIB 30 receives a control command from the ADK 10, it outputs the control command to a system corresponding to the control command via the integrated control manager 41. The VCIB 30 also acquires various types of information about the VP 20 (base vehicle 40) from various systems via the integrated control manager 41, and outputs the status of the VP 20 to the ADK 10 as the vehicle status.
[0018] The ADK 10 may be configured to be attachable (mounted) to and detachable from the base vehicle 40. For convenience, the ADK 10 is shown in FIG. 1 at a position separated from the base vehicle 40, but in reality, the ADK 10 is attached to the rooftop or the like of the base vehicle 40. When the ADK 10 is detached, the base vehicle 40 executes vehicle control in manual mode.
[0019] <Configuration of each component> Fig. 2 is a diagram showing in more detail the configurations of the ADK 10, VP 20, and VCIB 30. Fig. 3 is a diagram for explaining the communication system between the ADK 10, VP 20, and VCIB 30.
[0020] 2 and 3, the ADK 10 includes a computer 11, a human machine interface (HMI) 12, a recognition sensor 13, a posture sensor 14, and a sensor cleaner 15.
[0021] The computer 11 includes a processor 11A such as a CPU, and a memory 11B such as a ROM and a RAM. The memory 11B stores programs executable by the processor 11A. During autonomous driving of the vehicle 1, the computer 11 acquires information about the environment of the vehicle 1, as well as the attitude, behavior, and position of the vehicle 1, using various sensors, and also acquires the vehicle state from the VP 20 via the VCIB 30 to set the next operation of the vehicle 1 (acceleration, deceleration, turning, etc.). The computer 11 outputs various control commands to the VCIB 30 to realize the next operation.
[0022] The computer 11 further includes an ADK main module 111 , an ADK sub-module 112 , a communication module 113 , and a communication module 114 .
[0023] The ADK main module 111 is configured to communicate with a main VCIB 31 (described later) via a communication module 113. The ADK sub-module 112 is configured to communicate with a sub-VCIB 32 (described later) via a communication module 114. Furthermore, the ADK main module 111 and the ADK sub-module 112 are connected to each other so that they can communicate with each other. The ADK main module 111 and the ADK sub-module 112 are configured to wirelessly communicate with an external server 9 (see FIG. 1).
[0024] In the VP20, the brake system 42 includes brake systems 421 and 422. The steering system 43 includes steering systems 431 and 432. The powertrain system 44 includes an electric parking brake (EPB) system 441, a parking lock (P-Lock) system 442, and a propulsion system 443.
[0025] The VCIB 30 includes a main VCIB 31 and a sub-VCIB 32. The main VCIB 31 includes a processor 31A such as a CPU and a memory 31B such as a ROM and RAM. The memory 31B stores programs executable by the processor 31A. Similarly, the sub-VCIB 32 includes a processor 32A and a memory 32B. The memory 32B stores programs executable by the processor 32A.
[0026] Each of the main VCIB 31 and the sub-VCIB 32 relays control commands and information indicating the vehicle status between the ADK 10 and the VP 20. The main VCIB 31 and the ADK main module 111 are connected to each other via a main bus (corresponding to the "main system" in this disclosure) 51 so that they can communicate with each other. The main VCIB 31 interfaces between the VP 20 and the ADK 10 (ADK main module 111) via a main bus 61. The sub-VCIB 32 and the ADK sub-module 112 are connected to each other via a sub-bus (corresponding to the "sub-system" in this disclosure) 62 so that they can communicate with each other. The sub-VCIB 32 interfaces between the VP 20 and the ADK 10 (ADK sub-module 112) via the sub-bus 62. Furthermore, the main VCIB 31 and the sub-VCIB 32 are connected to each other so that they can communicate with each other.
[0027] The main VCIB 31 and the sub-VCIB 32 basically have the same functions. However, the main VCIB 31 and the sub-VCIB 32 differ in the connections to some of the systems included in the VP 20. Specifically, the main VCIB 31, the brake system 421, the steering system 431, the EPB system 441, the P-Lock system 442, the propulsion system 443, and the body system 46 are connected to each other via a communication bus so that they can communicate with each other. The sub-VCIB 32, the brake system 422, the steering system 432, and the P-Lock system 442 are connected to each other via a communication bus so that they can communicate with each other.
[0028] In this way, in the vehicle 1, the main VCIB 31 and the sub-VCIB 32 have equivalent functions with respect to some system operations (braking, steering, etc.). In addition, the ADK 10 includes an ADK main module 111 and an ADK sub-module 112, and the ADK 10 and the VP 20 are connected by a main bus 61 and a sub-bus 62. This provides redundancy (duplication) of communication between the ADK 10, the VCIB 30, and the integrated control manager 41.
[0029] <Communication lost> Basically, communication (signal exchange) is performed periodically between the ADK 10 and the VCIB 30 via the main bus 61, but there is a possibility that communication may be interrupted via the main bus 61. If a new command is not received even after a specified period has elapsed since the previous command was received (if communication is not restored within the specified period), the VCIB 30 determines that a communication abnormality has occurred on the main bus 61. In this case, the VCIB 30 can switch the communication system from the main bus 61 to the sub-bus 62.
[0030] Such communication abnormalities can occur during both autonomous driving and remote driving. It is desirable to be able to appropriately determine whether or not a communication abnormality has occurred in both autonomous driving and remote driving.
[0031] A specific numerical example will be given below. Assume that the length of the specified period during autonomous driving is set to 20 milliseconds. If a new command is received during autonomous driving just before the specified period has elapsed (for example, after 19 milliseconds have elapsed) since the previous command was received, the VCIB30 determines that no communication abnormality has occurred.
[0032] It is also possible to set the specified period for determining communication abnormalities during remote operation to the same length (20 milliseconds) as during autonomous operation. Here, during remote operation, delays due to wireless communication between the external server 9 and the VCIB 30 occur constantly. This delay (hereinafter referred to as "wireless delay") does not occur during autonomous operation. It is assumed that the wireless delay is 10 milliseconds.
[0033] During remote driving, if a new command is received just before a specified period of time has elapsed since the previous command was received (after 19 milliseconds), the VCIB 30 determines that no communication abnormality has occurred, just as during autonomous driving. However, the command received by the VCIB 30 may have been output from the external server 9 up to 19 milliseconds + 10 milliseconds = 29 milliseconds ago. Therefore, during remote driving, compared to during autonomous driving, the content of the command received by the VCIB 30 may be too old and may not be able to adequately keep up with changes in the situation of the vehicle 1.
[0034] Taking into account the 10-millisecond wireless delay, it is conceivable to set the specified time to 20 milliseconds - 10 milliseconds = 10 milliseconds. During autonomous driving, if no new command is received 10 milliseconds after the previous command was received, the VCIB 30 determines that a communication abnormality has occurred. In this case, the specified time is too short, which may increase the frequency of erroneously determining that a communication abnormality has occurred, even when communication between the ADK 10 and the VCIB 30 is actually normal.
[0035] Therefore, in this embodiment, the specified period during remote driving (second specified period T2) is set shorter than the specified period during autonomous driving (first specified period T1). As an example, the first specified period T1 during autonomous driving is set to 20 milliseconds, while the second specified period T2 during remote driving is set to 10 milliseconds. The first specified period T1 and the second specified period T2 correspond to the "first period" and "second period" according to the present disclosure, respectively.
[0036] Then, during remote operation, if no new command is received even after 10 milliseconds have passed since the previous command was received, the VCIB 30 determines that a communication abnormality has occurred. In other words, the VCIB 30 determines that a communication abnormality has not occurred only if the timing at which a signal was output from the external server 9 was at most 10 milliseconds + 10 milliseconds = 20 milliseconds ago. Therefore, it is possible to prevent the content of the command that the VCIB 30 receives from the external server 9 during remote operation from being excessively old.
[0037] On the other hand, during autonomous driving, if no new command is received even after 20 milliseconds or more have passed since the previous signal, the VCIB 30 determines that a communication abnormality has occurred. If the period from the previous command is less than 20 milliseconds, the VCIB 30 does not determine that a communication abnormality has occurred. Because the length of the specified period is appropriate, it is possible to prevent an increase in the frequency of erroneously determining that a communication abnormality has occurred even when the system is normal.
[0038] <Processing flow> 4 is a flowchart showing an example of a processing procedure by the VCIB 30 in the event of a communication abnormality in this embodiment. The processing shown in this flowchart is called from a main routine (not shown) and executed when a predetermined condition is met (for example, at predetermined intervals after a travel plan is created by the ADK 10). Each step is realized by software processing by the VCIB 30 (main VCIB 31 and / or sub VCIB 32), but some or all of the steps may also be realized by hardware (electrical circuits) arranged in the ECU. Hereinafter, steps are abbreviated as "S."
[0039] In S1, the VCIB 30 determines whether the VP 20 is in the automatic mode. If the VP 20 is in the manual mode (NO in S1), the VCIB 30 skips the subsequent processing and returns to the main routine. If the VP 20 is in the automatic mode (YES in S1), the VCIB 30 proceeds to S2.
[0040] In S2, the VCIB 30 determines whether the VP 20 is remotely driven. The VP 20 has an RDK, which is a driving ID indicating that the VP 20 is remotely driven, and an ADK, which is a driving ID indicating that the VP 20 is autonomously driven. If the VP 20 is remotely driven and the driving ID = RDK (YES in S2), the VCIB 30 proceeds to S3.
[0041] In S3, the VCIB30 determines whether communication between the ADK10 and the VCIB30 has been interrupted. If communication has not been interrupted (NO in S3), the VCIB30 returns to the main routine. If communication has been interrupted (YES in S3), the VCIB30 determines whether the period during which communication between the ADK10 and the VCIB30 has been interrupted (hereinafter referred to as the "communication interruption period") is equal to or longer than a second specified period T2 (S4). The second specified period T2 is set to be shorter than the first specified period T1.
[0042] If the communication interruption period is less than the second specified period T2 (NO in S4), the VCIB 30 returns the process to S3. If the communication interruption period is equal to or greater than the second specified period T2 (YES in S4), the VCIB 30 determines that a communication abnormality has occurred (S5). Then, the VCIB 30 notifies the integrated control manager 41 of the base vehicle 40 of the occurrence of the communication abnormality (S6). In addition, the VCIB 30 switches the communication between the ADK 10 and the VCIB 30 from communication via the main bus 61 to communication via the sub-bus 62 (S7). Thereafter, the VCIB 30 returns the process to the main routine.
[0043] In S2, if the VP 20 is in autonomous driving and the driving ID=ADK (NO in S2), the VCIB 30 advances the process to S8.
[0044] In S8, the VCIB 30 determines whether communication between the ADK 10 and the VCIB 30 has been interrupted. If communication has not been interrupted (NO in S8), the VCIB 30 returns to the main routine. If communication has been interrupted (YES in S8), the VCIB 30 determines whether the communication interruption period is equal to or longer than the first specified period T1 (S9).
[0045] If the communication interruption period is less than the first specified period T1 (NO in S9), the VCIB 30 returns the process to S8. If the communication interruption period is equal to or greater than the first specified period T1 (YES in S9), the VCIB 30 determines that a communication abnormality has occurred (S5). Then, the VCIB 30 notifies the integrated control manager 41 of the occurrence of the communication abnormality (S6). In addition, the VCIB 30 switches the communication between the ADK 10 and the VCIB 30 from communication via the main bus 61 to communication via the sub-bus 62 (S7). Thereafter, the VCIB 30 returns the process to the main routine.
[0046] As described above, in this embodiment, wireless delays are taken into consideration and the second specified period T2 during remote driving is set to be shorter than the first specified period T1 during autonomous driving. This prevents the content of commands output from the external server 9 and received by the VCIB 30 during remote driving from being excessively outdated. Furthermore, during autonomous driving, it is possible to prevent an increase in the frequency of erroneous determinations that a communication abnormality has occurred even when communication between the ADK 10 and the VCIB 30 is normal. Therefore, according to this embodiment, it is possible to appropriately respond to communication abnormalities between the ADK 10 and the VCIB 30 during both autonomous driving and remote driving.
[0047] The embodiments disclosed herein should be considered to be illustrative in all respects and not restrictive. The scope of the present disclosure is defined by the claims, not by the description of the above embodiments, and is intended to include all modifications within the meaning and scope of the claims. [Explanation of symbols]
[0048] 1 Vehicle, 10 Autonomous Driving Kit (ADK), 11 Computer, 11A Processor, 11B Memory, 111 Main Module, 112 Sub-Module, 113, 114 Communication Module, 12 HMI, 13 Perception Sensor, 14 Attitude Sensor, 15 Sensor Cleaner, 20 Vehicle Platform (VP), 30 Vehicle Control Interface Box (VCIB), 31 Main VCIB, 32 Sub-VCIB, 31A, 32A Processor, 31B, 32B Memory, 40 Base Vehicle, 41 Integrated Control Manager, 42, 421, 422 Brake System, 43, 431, 432 Steering System, 44 Powertrain System, 441, 442 EPB System, 443 Propulsion System, 45 Active Safety System, 46 Body System, 51, 52 Wheel Speed Sensor, 53 Pinion Angle Sensor, 54 Camera, 55,56 Radar sensor, 61 Main bus, 62 Sub-bus, 9 External server.
Claims
1. A vehicle, a vehicle platform configured to communicate with an automated driving system to perform vehicle control; The automated driving system includes: A command for autonomous driving according to a command from the automated driving system; and a command for remote driving according to a command from outside the vehicle, to the vehicle platform; The vehicle platform includes: When a situation in which communication with the automated driving system is lost continues for a first period or more during the autonomous driving, it is determined that an abnormality has occurred in communication between the automated driving system and the vehicle platform; If a situation in which communication with the autonomous driving system is interrupted continues for a second period or longer during the remote driving, it is determined that an abnormality has occurred in communication between the autonomous driving system and the vehicle platform; The second period of time is shorter than the first period of time.
2. The vehicle platform includes: The base vehicle and a vehicle control interface box that interfaces between the automated driving system and the base vehicle; The vehicle according to claim 1 , wherein when the vehicle control interface box receives a command from the automatic driving system during the autonomous driving or the remote driving, the vehicle control interface box outputs a signal corresponding to the received command to the base vehicle.
3. 3. The vehicle of claim 2, wherein the vehicle control interface box notifies the base vehicle that an abnormality has occurred in communication between the automated driving system and the vehicle platform.
4. The vehicle control interface box includes: The interface between the automated driving system and the base vehicle is configured to be performed via one of a main system and a sub system, The vehicle according to claim 2 or 3, wherein, when an abnormality occurs in communication via the main system, the communication system is switched so that communication is performed via the sub-system.
5. A vehicle control interface box mounted on a vehicle, A processor that interfaces between the automated driving system and the base vehicle; The automated driving system includes: A command for autonomous driving according to a command from the automated driving system; and a command for remote driving according to a command from outside the vehicle, to the base vehicle via the vehicle control interface box; The processor: During the autonomous driving, if a situation in which communication with the automated driving system is interrupted continues for a first period or more, it is determined that an abnormality has occurred in communication between the automated driving system and the base vehicle, If a situation in which communication with the automated driving system is interrupted continues for a second period or longer during the remote driving, it is determined that an abnormality has occurred in communication between the automated driving system and the base vehicle; The second period of time is shorter than the first period of time.
Citation Information
Patent Citations
Automatic operation controller
JP2018132015A