Vehicle and computer

The processing device and program address safety in manual driving by monitoring and adjusting driving conditions using sensor data and remote feedback, ensuring safe driving through continuous learning and adaptation.

JP2025186450AActive Publication Date: 2025-12-23DENSO CORP
View PDF 8 Cites 0 Cited by

Patent Information

Application Number
JP2025157185
Authority / Receiving Office
JP · JP
Patent Type
Applications
Current Assignee / Owner
Priority Date
2021-02-03
Filing Date
2025-09-22
Publication Date
2025-12-23
Estimated Expiration
2042-01-25

AI Technical Summary

Technical Problem

Existing technologies fail to enhance safety in manual driving by effectively monitoring and adjusting driving conditions to maintain an acceptable level of risk.

Method used

A processing device and program that utilize sensor data, detection algorithms, and remote feedback to monitor and adjust driving conditions, generating scene information and updating detection algorithms to ensure safe manual driving.

Benefits of technology

Enhances safety in manual driving by monitoring violations and providing real-time adjustments to maintain acceptable risk levels, improving driving safety through continuous learning and adaptation.

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure 2025186450000001_ABST
    Figure 2025186450000001_ABST
Patent Text Reader

Abstract

To provide a processing program which promotes a safety improvement in manual driving.SOLUTION: In a processing device (1a) including a processor for carrying out processing relating to driving of a host vehicle (2) which is communicable with a remote center (8), the processor executes monitoring, in a host mobile of manual driving, a safety envelope violation which is a violation of a safety envelope established according to a driving policy to ensure safety of an intended function, generating scene information representing a scene of the safety envelope violation so as to transmit the scene information to the remote center in a case where it is determined that the safety envelope violation occurs, and acquiring from the remote center feedback information which is fed back on the basis of the scene information.SELECTED DRAWING: Figure 6
Need to check novelty before this filing date? Find Prior Art

Description

CROSS-REFERENCE TO RELATED APPLICATIONS

[0001] This application is based on Patent Application No. 2021-15884 filed in Japan on February 3, 2021, and the contents of the original application are incorporated by reference in their entirety. [Technical Field]

[0002] The present disclosure relates to processing techniques for performing operations related to the operation of a host vehicle. [Background technology]

[0003] The technology disclosed in Patent Document 1 plans driving control related to the navigation operation of a host vehicle according to detected information related to the internal and external environments of the host vehicle. Therefore, when it is determined that there is potential accident liability based on a safety model according to a driving policy and the detected information, restrictions are imposed on the driving control. [Prior art documents] [Patent documents]

[0004] [Patent Document 1] Patent No. 6708793 Summary of the Invention

[0005] However, it is difficult to imagine that the technology disclosed in Patent Document 1 will improve safety in manual driving.

[0006] An object of the present disclosure is to provide a processing device that promotes improved safety in manual driving. Another object of the present disclosure is to provide a processing program that promotes improved safety in manual driving.

[0007] The technical means of the present disclosure for solving the problems will be described below.

[0008] A first aspect of the present disclosure is A processing device (1a) including a processor (12) for performing processing related to the operation of a host vehicle (2, 3a) capable of communicating with a remote center (8), The host mobile is configured to process the sensor data acquired from the sensors (50, 52) using a detection algorithm to detect the environment; The processor monitoring a manually operated host vehicle for violations of restrictions or conditions to maintain operation within an acceptable level of risk; generating scene information representing a scene of a violation when the violation occurs, so as to be transmitted to a remote center; and acquiring, from a remote center, an update command or a parameter adjustment command for the detection algorithm as feedback information that is fed back based on the scene information.

[0009] A second aspect of the present disclosure is a processing device (8a) including a processor (82) for performing processing related to the driving operation of the host vehicle (2, 3a) at a remote center (8) capable of communicating with the host vehicle (2, 3a); The host mobile is configured to process the sensor data acquired from the sensors (50, 52) using a detection algorithm to detect the environment; The processor Obtaining scene information from a manually operated host vehicle that describes a scene of a violation of a restriction or condition for maintaining operation within an acceptable level of risk; and generating, as feedback information based on the scene information, an instruction to update the detection algorithm or an instruction to adjust parameters, for transmission to the host mobile.

[0010] A third aspect of the present disclosure is A processing program stored in a storage medium (10) for performing processing related to the driving operation of a host vehicle (2, 3a) capable of communicating with a remote center (8), The host mobile is configured to process the sensor data acquired from the sensors (50, 52) using a detection algorithm to detect the environment; A processor (12) of the host mobile device monitoring a manually operated host vehicle for violations of restrictions or conditions to maintain operation within an acceptable level of risk; generating scene information representing a scene of a violation when the violation occurs, so as to be transmitted to a remote center; and acquiring, from the remote center, a command to update the detection algorithm or a command to adjust parameters as feedback information fed back based on the scene information.

[0011] A fourth aspect of the present disclosure is A processing program stored in a storage medium (80) for performing processing related to the driving operation of a host vehicle (2, 3a) in a remote center (8) capable of communicating with the host vehicle (2, 3a), The host mobile is configured to process the sensor data acquired from the sensors (50, 52) using a detection algorithm to detect the environment; A processor (82) at the remote center Obtaining scene information from a manually operated host vehicle that describes a scene of a violation of a restriction or condition for maintaining operation within an acceptable level of risk; and generating, as feedback information based on the scene information, an instruction to update the detection algorithm or an instruction to adjust parameters, to be transmitted to the host mobile unit. [Brief explanation of the drawings]

[0012] [Figure 1] 1 is an explanatory table showing explanations of terms used in the present disclosure. [Figure 2] 1 is an explanatory table showing explanations of terms used in the present disclosure. [Figure 3] 1 is an explanatory table showing explanations of terms used in the present disclosure. [Figure 4]1 is an explanatory table showing definitions of terms used in the present disclosure. [Figure 5] 1 is an explanatory table showing definitions of terms used in the present disclosure. [Figure 6] 1 is a block diagram illustrating a processing system according to a first embodiment. [Figure 7] FIG. 2 is a schematic diagram showing a traveling environment of a host vehicle to which the first embodiment is applied. [Figure 8] 1 is a block diagram illustrating a processing system according to a first embodiment. [Figure 9] 1 is a block diagram illustrating a processing system according to a first embodiment. [Figure 10] FIG. 2 is a schematic diagram illustrating an example of a lane structure according to the first embodiment. [Figure 11] 3 is a flowchart illustrating a processing method according to the first embodiment. [Figure 12] 4 is an explanatory table for explaining a processing method according to the first embodiment; [Figure 13] 10 is a flowchart illustrating a processing method according to a second embodiment. [Figure 14] 10 is a graph illustrating a processing method according to a second embodiment. [Figure 15] FIG. 10 is a block diagram showing functional blocks of a third embodiment. [Figure 16] 10 is a flowchart illustrating a processing method according to a third embodiment. [Figure 17] 10 is a flowchart illustrating a processing method according to a fourth embodiment. [Figure 18] 10 is a flowchart illustrating a processing method according to a fourth embodiment. [Figure 19] 10 is a flowchart illustrating a processing method according to a fourth embodiment. [Figure 20] 13 is a flowchart illustrating a processing method according to a fifth embodiment. [Figure 21] 13 is a flowchart illustrating a processing method according to a fifth embodiment. [Figure 22] FIG. 10 is a block diagram showing a processing system according to a sixth embodiment. [Figure 23] FIG. 13 is a block diagram showing a processing system according to a seventh embodiment. [Figure 24] FIG. 13 is a block diagram showing a processing system according to an eighth embodiment. [Figure 25] FIG. 13 is a block diagram showing a processing system according to an eighth embodiment. [Figure 26] FIG. 13 is a block diagram showing a processing system according to an eighth embodiment. [Figure 27] FIG. 13 is a block diagram showing a processing system according to a ninth embodiment. [Figure 28] FIG. 10 is a block diagram showing a processing system according to a tenth embodiment. [Figure 29] FIG. 13 is a block diagram showing a processing system according to a modified example of the tenth embodiment. DETAILED DESCRIPTION OF THE INVENTION

[0013] Hereinafter, multiple embodiments according to the present disclosure will be described with reference to the drawings. Note that corresponding components in each embodiment are designated by the same reference numerals, and redundant description may be omitted. Furthermore, when only a portion of a configuration is described in each embodiment, the configuration of another previously described embodiment may be applied to the remaining portions of the configuration. Furthermore, in addition to the combinations of configurations explicitly stated in the description of each embodiment, configurations of multiple embodiments may be partially combined together even if not explicitly stated, provided that there is no particular problem with the combination.

[0014] 1 to 5 show explanations of terms related to each embodiment of the present disclosure. However, the definitions of terms should not be interpreted as being limited to the explanations shown in FIGS. 1 to 5, but should be interpreted within the scope of the gist of the present disclosure.

[0015] (First embodiment) The processing system 1 of the first embodiment shown in Fig. 6 performs processing related to driving of a host moving object (hereinafter referred to as driving-related processing). The host moving object that the processing system 1 targets for driving-related processing is the host vehicle 2 shown in Figs. 6 and 7. From the viewpoint of the host vehicle 2, the host vehicle 2 can also be said to be its own vehicle (ego-vehicle).

[0016] Autonomous driving is performed in the host vehicle 2. Autonomous driving is classified into levels according to the degree of manual intervention by the occupant in the Dynamic Driving Task (hereinafter referred to as DDT). Autonomous driving may be achieved by autonomous driving control, such as conditional driving automation, high driving automation, or full driving automation, in which the system performs all DDTs when activated. Autonomous driving may also be achieved by advanced driving assistance control, such as driving assistance or partial driving automation, in which the driver as an occupant performs some or all of the DDTs. Autonomous driving may be achieved by either, a combination of, or switching between autonomous driving control and advanced driving assistance control.

[0017] The host vehicle 2 is equipped with a sensor system 5, a communication system 6, a map database (DB) 7, and an information presentation system 4, all of which are shown in Figures 6 and 8. The sensor system 5 acquires sensor data that can be used by the processing system 1 by detecting the external and internal worlds of the host vehicle 2. To this end, the sensor system 5 is configured to include an external sensor 50 and an internal sensor 52.

[0018] The external sensor 50 may detect targets present in the external world of the host vehicle 2. The target detection type external sensor 50 is, for example, at least one of a camera, LiDAR (Light Detection and Ranging / Laser Imaging Detection and Ranging), laser radar, millimeter wave radar, ultrasonic sonar, etc. The external sensor 50 may detect the atmospheric conditions in the external world of the host vehicle 2. The atmospheric detection type external sensor 50 is, for example, at least one of an outside air temperature sensor, a humidity sensor, etc.

[0019] The internal sensor 52 may detect a specific physical quantity related to vehicle motion (hereinafter referred to as a motion physical quantity) in the internal environment of the host vehicle 2. The internal sensor 52 of a physical quantity detection type is, for example, at least one of a speed sensor, an acceleration sensor, a gyro sensor, etc. The internal sensor 52 may detect the state of an occupant in the internal environment of the host vehicle 2. The internal sensor 52 of an occupant detection type is, for example, at least one of an actuator sensor, a driver status monitor, a biological sensor, a seating sensor, an in-vehicle equipment sensor, etc. Here, in particular, as the actuator sensor, at least one of an accelerator sensor, a brake sensor, a steering sensor, etc. is used that detects the operation state of the occupant regarding the motion actuators of the host vehicle 2.

[0020] The communication system 6 acquires communication data usable by the processing system 1 via wireless communication. The communication system 6 may receive positioning signals from GNSS (Global Navigation Satellite System) satellites present in the external world of the host vehicle 2. The positioning type communication system 6 is, for example, a GNSS receiver. The communication system 6 may transmit and receive communication signals to and from a V2X system present in the external world of the host vehicle 2. The V2X type communication system 6 is, for example, at least one of a DSRC (Dedicated Short Range Communications) communication device and a cellular V2X (C-V2X) communication device. The communication system 6 may transmit and receive communication signals to and from a terminal present in the internal world of the host vehicle 2. The terminal communication type communication system 6 is, for example, at least one of a Bluetooth (registered trademark) device, a Wi-Fi (registered trademark) device, an infrared communication device, etc.

[0021] As shown in Fig. 9, such a communication system 6 is preferably constructed mainly of at least one type of communication device 6a. In this case, the communication device 6a includes at least one dedicated computer. In addition, in this case, the dedicated computer constituting the communication device 6a has at least one memory 60 and one processor 62. Here, the memory 60 and the processor 62 of the communication device 6a are equivalent to the memory 10 and the processor 12 of the processing device 1a described later.

[0022] The map DB 7 shown in Figures 6 and 8 stores map data that can be used by the processing system 1. The map DB 7 includes at least one type of non-transitory tangible storage medium, such as a semiconductor memory, a magnetic medium, or an optical medium. The map DB 7 may be a DB for a locator that estimates the host vehicle 2's own state quantities, including its own position. The map DB may be a DB for a navigation unit that navigates the host vehicle 2's travel route. The map DB 7 may be constructed by combining multiple types of DBs.

[0023] The map DB 7 acquires and stores the latest map data, for example, through communication with an external center via a V2X-type communication system 6. The map data is two-dimensional or three-dimensional data representing the driving environment of the host vehicle 2. High-precision digital map data may be used as the three-dimensional map data. The map data may include road data representing at least one of the following: position coordinates, shape, and road surface conditions of road structures. The map data may also include marking data representing at least one of the following: position coordinates and shapes of road signs, road markings, and lane markings attached to roads. The marking data included in the map data may represent landmarks, such as traffic signs, arrow markings, lane markings, stop lines, directional signs, landmark beacons, rectangular signs, business signs, or changes in road line patterns. The map data may also include structure data representing at least one of the following: position coordinates and shapes of buildings and traffic lights facing the road. The marking data included in the map data may represent landmarks such as street lights, road edges, reflectors, poles, or the backs of road signs.

[0024] The information presentation system 4 presents notification information to occupants, including the driver of the host vehicle 2. The information presentation system 4 includes a visual presentation unit, an auditory presentation unit, and a cutaneous sensation presentation unit. The visual presentation unit presents notification information by stimulating the occupant's vision. The visual presentation unit is, for example, at least one of a head-up display (HUD), a multi-function display (MFD), a combination meter, a navigation unit, and a light-emitting unit. The auditory presentation unit presents notification information by stimulating the occupant's hearing. The auditory presentation unit is, for example, at least one of a speaker, a buzzer, and a vibration unit. The cutaneous sensation presentation unit presents notification information by stimulating the occupant's cutaneous sensation. The cutaneous sensations stimulated by the cutaneous sensation presentation unit include, for example, at least one of touch, temperature, and wind. The tactile sensation presentation unit is at least one of a steering wheel vibration unit, a driver's seat vibration unit, a steering wheel reaction force unit, an accelerator pedal reaction force unit, a brake pedal reaction force unit, an air conditioning unit, and the like.

[0025] As shown in FIG. 6 , the processing system 1 includes a processing device 1a in the host vehicle 2 and a processing device 8a in the remote center 8. Here, the processing system 1 may include at least the communication system 6 among the sensor system 5, communication system 6, map DB 7, and information presentation system 4 in the host vehicle 2. The processing device 1a is connected to the sensor system 5, communication system 6, map DB 7, and information presentation system 4 via at least one of a LAN (Local Area Network), a wire harness, an internal bus, and a wireless communication line. The processing device 1a includes at least one dedicated computer. The dedicated computer constituting the processing device 1a may be an integrated ECU (Electronic Control Unit) that integrates the driving control of the host vehicle 2. The dedicated computer constituting the processing device 1a may be a determination ECU that determines the DDT in the driving control of the host vehicle 2. The dedicated computer constituting the processing device 1a may be a monitoring ECU that monitors the driving control of the host vehicle 2. The dedicated computer constituting the processing device 1a may be an evaluation ECU that evaluates the driving control of the host vehicle 2.

[0026] The dedicated computer constituting the processing device 1a may be a navigation ECU that navigates the travel route of the host vehicle 2. The dedicated computer constituting the processing device 1a may be a locator ECU that estimates the host vehicle 2's own state quantities including its own position. The dedicated computer constituting the processing device 1a may be an actuator ECU that controls the motion actuator of the host vehicle 2. The dedicated computer constituting the processing device 1a may be an HCU (Human Machine Interface Control Unit (HMI)) that controls the presentation of information in the host vehicle 2. The dedicated computer constituting the processing device 1a may be at least one external computer that constitutes, for example, a mobile terminal or the like that can communicate via the communication system 6.

[0027] The dedicated computer constituting the processing device 1a has at least one memory 10 and one processor 12. The memory 10 is at least one type of non-transitory tangible storage medium, such as a semiconductor memory, a magnetic medium, or an optical medium, that non-temporarily stores computer-readable programs and data. The processor 12 includes at least one type of core, such as a central processing unit (CPU), a graphics processing unit (GPU), or a reduced instruction set computer (RISC)-CPU.

[0028] The processor 12 executes a plurality of instructions included in a processing program stored as software in the memory 10. In this way, the processing device 1a constructs functional blocks for performing driving-related processing of the host vehicle 2. In this way, the processing device 1a constructs functional blocks by having the processor 12 execute a plurality of instructions from the processing program stored in the memory 10 to perform driving-related processing of the host vehicle 2. The functional blocks constructed by the processing device 1a include a detection block 100, a planning block 120, a risk monitoring block 140, and a control block 160, as shown in FIG. 8.

[0029] The detection block 100 acquires sensor data from the external sensors 50 and internal sensors 52 of the sensor system 5. The detection block 100 acquires communication data from the communication system 6. The detection block 100 acquires map data from the map database 7. The detection block 100 detects the internal and external environments of the host vehicle 2 by fusing these acquired data as inputs. By detecting the internal and external environments, the detection block 100 generates detection information to provide to the subsequent planning block 120 and risk monitoring block 140. In this way, when generating the detection information, the detection block 100 acquires data from the sensor system 5 and the communication system 6, recognizes or understands the meaning of the acquired data, and integrates the acquired data to grasp the overall situation, including the external situation of the host vehicle 2, its own situation within that external situation, and the internal situation of the host vehicle 2. The detection block 100 may provide substantially identical detection information to the planning block 120 and the risk monitoring block 140. The detection block 100 may provide different detection information to the planning block 120 and the risk monitoring block 140 .

[0030] The detection information generated by the detection block 100 describes the state detected for each scene in the driving environment of the host vehicle 2. The detection block 100 may generate the object detection information by detecting objects, including road users, obstacles, and structures, in the external world of the host vehicle 2. The object detection information may represent at least one of the following: the distance to the object, the relative speed of the object, the relative acceleration of the object, and an estimated state based on tracking detection of the object. The object detection information may further represent a type recognized or identified from the state of the detected object. The detection block 100 may generate the path detection information by detecting the path along which the host vehicle 2 is currently and will be traveling. The path detection information may represent at least one of the following states: the road surface, the lane, the road edge, and free space.

[0031] The detection block 100 may generate detection information of the host vehicle 2's own state quantities by localization, which estimates the self-state quantities including the host vehicle 2's own position. The detection block 100 may generate update information for map data related to the host vehicle 2's route simultaneously with the detection information of the self-state quantities, and feed the update information back to the map DB 7. The detection block 100 may generate detection information of the markings by detecting signs associated with the host vehicle 2's route. The detection information of the markings may represent at least one type of status, for example, a sign, a lane marking, a traffic light, etc. The detection information of the markings may further represent a traffic rule recognized or identified from the status of the sign. The detection block 100 may generate detection information of the weather conditions by detecting the weather conditions for each scene in which the host vehicle 2 travels. The detection block 100 may generate detection information for the weather conditions by detecting the time of day for each scene in which the host vehicle 2 travels.

[0032] The planning block 120 acquires detection information from the detection block 100. The planning block 120 plans driving control of the host vehicle 2 according to the acquired detection information. In the driving control plan, control commands related to the navigation operation and driver assistance operation of the host vehicle 2 are generated. That is, the planning block 120 realizes a DDT function that generates control commands as motion control requests for the host vehicle 2. The control commands generated by the planning block 120 may include control parameters for controlling motion actuators of the host vehicle 2. Examples of motion actuators to which control commands are output include at least one of an internal combustion engine, an electric motor, and a powertrain, a brake device, a steering device, and the like, which are combinations of these.

[0033] The planning block 120 may generate control commands to conform to a driving policy by using a safety model described in accordance with the driving policy and its safety. The driving policy followed by the safety model is defined, for example, based on a vehicle-level safety strategy that ensures the safety of intended functionality (hereinafter referred to as SOTIF). In other words, the safety model is described by following the driving policy that implements the vehicle-level safety strategy and by modeling the SOTIF. The planning block 120 may train the safety model using a machine learning algorithm that back-propagates driving control results to the safety model. The safety model to be trained may be at least one type of learning model, such as deep learning using a neural network such as a deep neural network (DNN) and reinforcement learning. Here, the safety model may be defined as a safety-related model itself that represents safety-related aspects of driving behavior based on assumptions about the reasonably foreseeable behavior of other road users, or as a model that constitutes a part of the safety-related model. Such a safety model may be constructed in at least one form, such as a mathematical model that formulates vehicle-level safety, or a computer program that executes processing in accordance with the mathematical model.

[0034] The planning block 120 may plan a future route for the host vehicle 2 through driving control prior to generating a control command. The route planning may be performed by, for example, a calculation such as a simulation to navigate the host vehicle 2 based on the detection information. That is, the planning block 120 may implement a DDT function that plans a route as a tactical action of the host vehicle 2. The planning block 120 may further plan an appropriate trajectory for the host vehicle 2 following the planned route based on the acquired detection information prior to generating a control command. That is, the planning block 120 may implement a DDT function that plans a trajectory for the host vehicle 2. The trajectory planned by the planning block 120 may specify at least one type of physical motion quantity related to the host vehicle 2, such as a driving position, a speed, an acceleration, or a yaw rate, in a time series. The time-series trajectory planning constructs a scenario for future driving by navigating the host vehicle 2. The planning block 120 may generate a trajectory through planning using a safety model. In this case, a cost function that assigns a cost to the generated trajectory may be calculated, and the safety model may be trained by a machine learning algorithm based on the calculation results.

[0035] The planning block 120 may plan an adjustment of the autonomous driving level of the host vehicle 2 in accordance with the acquired detection information. The adjustment of the autonomous driving level may also include a handover between autonomous driving and manual driving. The handover between autonomous driving and manual driving may be realized in a scenario accompanying entry or exit of an Operational Design Domain (ODD) by setting the ODD in which the autonomous driving is performed. In a scenario for exiting the ODD, i.e., a scenario for handover from autonomous driving to manual driving, an example of a use case is an unreasonable situation in which an unreasonable risk is determined to exist based on a safety model, etc. In this use case, the planning block 120 may plan a DDT fallback in which a driver who is a fallback backup user performs a minimum-risk operation on the host vehicle 2 to transition the host vehicle 2 to a minimum-risk state.

[0036] Adjustment of the autonomous driving level may include degraded driving of the host vehicle 2. In a degraded driving scenario, a use case may be an irrational situation where handover to manual driving is determined to pose an unreasonable risk, for example, based on a safety model. In this use case, the planning block 120 may plan a DDT fallback to transition the host vehicle 2 to a minimum-risk state through autonomous driving and autonomous stopping. The DDT fallback to transition the host vehicle 2 to a minimum-risk state may not only be realized by adjusting to lower the autonomous driving level, but may also be realized by adjusting to maintain the autonomous driving level while performing degraded driving, such as an MRM (Minimum Risk Maneuver). In the DDT fallback to transition the host vehicle 2 to a minimum-risk state, the conspicuousness of the transition may be increased by at least one of, for example, lighting, a horn sound, signals, and gestures.

[0037] The risk monitoring block 140 acquires detection information from the detection block 100. Based on the acquired detection information, the risk monitoring block 140 monitors the risk between the host vehicle 2 and other target moving objects 3 (see FIG. 7) for each scene. The risk monitoring block 140 performs risk monitoring based on the detection information in a time series manner to ensure the SOTIF of the host vehicle 2 for the target moving objects 3. The target moving objects 3 assumed in the risk monitoring are other road users present in the driving environment of the host vehicle 2. The target moving objects 3 include non-vulnerable road users such as cars, trucks, motorcycles, and bicycles, and vulnerable road users such as pedestrians. The target moving objects 3 may also include animals.

[0038] The risk monitoring block 140 sets a safety envelope based on the acquired scene-specific detection information, for example, a vehicle-level safety strategy, which ensures SOTIF in the host vehicle 2. The risk monitoring block 140 may set a safety envelope between the host vehicle 2 and the target moving object 3 using a safety model that complies with the driving policy described above. The safety model used to set the safety envelope may be designed to avoid potential accident liability due to unreasonable risks or misuse by road users in accordance with accident liability rules. In other words, the safety model may be designed so that the host vehicle 2 complies with accident liability rules that comply with the driving policy. An example of such a safety model is a responsibility sensitive safety model as disclosed in Patent Document 1.

[0039] Here, a safety envelope may be defined as a set of limits and conditions within which a system is designed to operate, subject to constraints or controls, in order to maintain operation within an acceptable level of risk. Such a safety envelope may be established as a physics-based margin around each road user, including the host vehicle 2 and the target moving object 3, for example, by a margin for at least one physical quantity of motion, such as distance, speed, and acceleration. For example, in establishing the safety envelope, a safety distance may be estimated from a profile of at least one physical quantity of motion based on a safety model for the host vehicle 2 and the target moving object 3, which are assumed to follow a driving policy. The safety distance defines a boundary around the host vehicle 2 that ensures a physics-based margin for the predicted motion of the target moving object 3. The safety distance may be estimated taking into account the reaction time required for road users to execute an appropriate response. The safety distance may be estimated to comply with accident liability regulations. For example, in a scene where a lane structure such as a lane exists, a safety distance may be calculated to avoid the risk of a rear-end collision and a head-on collision in the longitudinal direction of the host vehicle 2, and a safety distance may be calculated to avoid the risk of a side collision in the lateral direction of the host vehicle 2. On the other hand, in a scene where a lane structure does not exist, a safety distance may be calculated to avoid the risk of a track collision in any direction of the host vehicle 2.

[0040] The risk monitoring block 140 may identify the situation for each scene of relative movement between the host vehicle 2 and the target moving object 3 prior to setting the safety envelope described above. For example, in a scene where a lane structure such as a lane exists, a situation where a risk of a rear-end collision or a head-on collision is expected in the longitudinal direction and a situation where a risk of a side collision is expected in the lateral direction may be identified. In identifying these longitudinal and lateral situations, state quantities related to the host vehicle 2 and the target moving object 3 may be converted to a coordinate system assuming a linear lane. On the other hand, in a scene where a lane structure does not exist, a situation where a risk of a trajectory collision is expected in any direction of the host vehicle 2 may be identified. Note that the detection block 100 may execute at least a portion of the above situation identification function, and the situation identification results may be provided to the risk monitoring block 140 as detection information.

[0041] The risk monitoring block 140 performs a safety determination between the host vehicle 2 and the target moving object 3 based on the set safety envelope and the acquired detection information for each scene. That is, the risk monitoring block 140 realizes the safety determination by testing whether or not a driving scene interpreted based on the detection information between the host vehicle 2 and the target moving object 3 contains a safety envelope violation that violates the safety envelope. If a safety distance is assumed in the setting of the safety envelope, it may be determined that there is no safety envelope violation if the actual distance between the host vehicle 2 and the target moving object 3 exceeds the safety distance. On the other hand, it may be determined that there is a safety envelope violation if the actual distance between the host vehicle 2 and the target moving object 3 is equal to or less than the safety distance.

[0042] The risk monitoring block 140 may calculate, by simulation, a reasonable scenario for giving the host vehicle 2 an appropriate action to be taken as an appropriate response when it is determined that the safety envelope has been violated. In simulating the reasonable scenario, state transitions between the host vehicle 2 and the target moving object 3 are estimated, and actions to be taken for each transitional state may be set as constraints (described in detail later) on the host vehicle 2. In setting the actions, a limit value assumed for at least one type of physical quantity of motion to be given to the host vehicle 2 may be calculated so as to limit the physical quantity of motion as a constraint on the host vehicle 2.

[0043] The risk monitoring block 140 may directly calculate a limit value for complying with accident liability regulations from a profile of at least one type of motion physical quantity based on a safety model for the host vehicle 2 and the target moving object 3 assumed to comply with the driving policy. The direct calculation of the limit value itself can be said to be the setting of a safety envelope and also the setting of a constraint on driving control. Therefore, if an actual value that is safer than the limit value is detected, it may be determined that the safety envelope has not been violated. On the other hand, if an actual value that is outside the limit value is detected, it may be determined that the safety envelope has been violated.

[0044] The risk monitoring block 140 may store in the memory 10 at least one type of evidence information, such as detection information used to set the safety envelope, judgment information indicating the judgment result of the safety envelope, detection information that influenced the judgment result, and a simulated scenario. The memory 10 storing the evidence information may be mounted in the host vehicle 2 depending on the type of dedicated computer constituting the processing device 1a, or may be installed, for example, in an external center outside the host vehicle 2. The evidence information may be stored in an unencrypted state, or may be encrypted or hashed and stored. The storage of the evidence information is executed at least when it is determined that there is a violation of the safety envelope. Of course, the storage of the evidence information may also be executed when it is determined that there is no violation of the safety envelope. The evidence information when it is determined that there is no violation of the safety envelope can be used as a lagging indicator at the time of storage and can also be used as a leading indicator in the future.

[0045] The control block 160 obtains control commands from the planning block 120. The control block 160 obtains judgment information regarding the safety envelope from the risk monitoring block 140. That is, the control block 160 realizes the DDT function that controls the movement of the host vehicle 2. When the control block 160 obtains judgment information that the safety envelope is not violated, it executes the planned driving control of the host vehicle 2 in accordance with the control commands.

[0046] In response to this, when the control block 160 acquires determination information indicating a violation of the safety envelope, the control block 160 imposes constraints on the planned driving control of the host vehicle 2 in accordance with the driving policy based on the determination information. The constraints on the driving control may be functional constraints. The constraints on the driving control may be degraded constraints. The constraints on the driving control may be constraints other than these. The constraints on the driving control are imposesed by limiting control commands. When a reasonable scenario is simulated by the risk monitoring block 140, the control block 160 may limit the control commands in accordance with the scenario. In this case, when limit values ​​are set for the motion physical quantities of the host vehicle 2, the control parameters of the motion actuators included in the control commands may be corrected based on the limit values.

[0047] Of the target moving bodies 3, the target vehicle 3a shown in Figure 7 may be equipped with a processing device 1a, sensor system 5, communication system 6, map DB 7, and information presentation system 4 equivalent to those of the host vehicle 2. In this case, from the perspective of the remote center 8, the host vehicle 2 can be considered to correspond to the "first host moving body," and the target vehicle 3a, which is another host vehicle 2, can be considered to correspond to the "second host moving body." In this case, the processing system 1 may be constructed to include at least the communication system 6 out of the sensor system 5, communication system 6, map DB 7, and information presentation system 4 of the target vehicle 3a.

[0048] As shown in FIG. 6 , the remote center 8 includes a processing device 8a and a communication system 8b, and is mainly constructed of at least one of a cloud server, an edge server, and the like. The communication system 8b forms at least a part of a V2X system capable of communicating with the communication system 6 of the host vehicle 2. The communication system 8b may also be capable of communicating with the communication system 6 when installed in the target vehicle 3a. The processing device 8a is connected to the communication system 8b via at least one of a wired communication line and a wireless communication line. The processing device 8a is configured to include at least one dedicated computer. The processing device 8a may perform output control processing, such as displaying information regarding road users, including the host vehicle 2, that can be communicated with through the communication system 8b, to an operator of the remote center 8. The processing device 8a may also perform input control processing, such as receiving information to be fed back to road users that can be communicated with, from an operator of the remote center 8.

[0049] The dedicated computer constituting the processing device 8a has at least one memory 80 and one processor 82. The memory 80 and processor 82 of the processing device 8a are equivalent to the memory 10 and processor 12 of the processing device 1a. The processor 82 executes a plurality of instructions included in a processing program stored as software in the memory 80. In this way, the processing device 8a constructs a functional block for carrying out driving-related processing of the host vehicle 2 in cooperation with the processing device 1a. When the processing device 8a is mounted on the target vehicle 3a, the processing device 8a may construct a functional block for carrying out driving-related processing of the target vehicle 3a in cooperation with the processing device 1a.

[0050] In this way, in the processing device 8a, a processing program stored in the memory 80 causes the processor 82 to execute a plurality of instructions to perform driving-related processing of the host vehicle 2, etc., thereby constructing a functional block. From the perspective of the processing system 1 as a whole, this can be considered as the processing programs stored in the memories 10, 80 respectively causing the processors 12, 82 to execute instructions in cooperation with each other, thereby constructing the functional blocks of each device 1a, 8a. In this case, in the processing system 1 constructed in the host vehicle 2, etc., including the communication device 6a constituting the communication system 6, the processing programs stored in the memories 10, 80, 60 respectively may cause the processors 12, 62, 82 to execute instructions in cooperation with each other.

[0051] On the other hand, from the perspective of the processing system 1 as a whole, a processing program stored in one of the memories 10, 80 (particularly the memory 80 of the cloud server) may cause the processors 12, 82 to cooperatively execute instructions, thereby constructing the functional blocks of the devices 1a, 8a. In this case, in the processing system 1 constructed to include a communication device 6a that constitutes a communication system 6 in the host vehicle 2 or the like, a processing program stored in one of the memories 10, 80 and a processing program stored in the memory 60 may cause the processors 12, 62, 82 to cooperatively execute instructions.

[0052] In any of the above cases, the processor 12 and memory 10 of the host vehicle 2 etc. correspond to the "first processor" and "first storage medium", respectively, and the processor 82 and memory 80 of the remote center 8 correspond to the "second processor" and "second storage medium", respectively.

[0053] As shown in FIG. 9, the functional blocks constructed by the processing device 8a include a center management block 880. The center management block 880 manages a traffic environment in which multiple road users, including the host vehicle 2, exist. The center management block 880 may acquire scene information related to the driving scenes of communicable road users in real time via the communication system 8b and use the acquired scene information to manage the traffic environment. In order to manage the traffic environment based on the scene information, the center management block 880 may transmit feedback information to be fed back to communicable road users via the communication system 8b in real time or afterward. FIG. 9 shows an example in which necessary information is transmitted and received via the communication systems 8b and 6 between the center management block 880 constructed by the processing device 8a of the remote center 8 and the risk monitoring block 140 constructed by the processing device 1a of the host vehicle 2.

[0054] The first embodiment will be described in detail below.

[0055] 10, in the first embodiment, a lane structure Ls with lanes separated is assumed. The lane structure Ls restricts the movement of the host vehicle 2 and the target moving object 3 with the direction in which the lanes extend as the longitudinal direction. The lane structure Ls restricts the movement of the host vehicle 2 and the target moving object 3 with the width direction or the direction in which the lanes are lined up as the lateral direction.

[0056] The driving policy between the host vehicle 2 and the target moving object 3 in the lane structure Ls, for example, when the target moving object 3 is the target vehicle 3a, is defined by the following (1) to (5). Note that "forward" based on the host vehicle 2 refers to, for example, the direction of travel on a turning circle at the current steering angle of the host vehicle 2, the direction of travel on a straight line passing through the center of gravity of the host vehicle 2 and perpendicular to the axles of the host vehicle 2, or the direction of travel on the axis of the FOE (Focus of Expansion) of the front camera module of the sensor system 5 of the host vehicle 2. (1) A vehicle will not rear-end a vehicle traveling in front of it. (2) A vehicle will not forcibly cut in between other vehicles. (3) A vehicle will yield to other vehicles according to the situation, even if it has the right of way. (4) A vehicle will drive carefully in places with poor visibility. (5) A vehicle will take reasonable action to prevent an accident if it is possible to do so, regardless of whether it is its own fault or the fault of others.

[0057] The SOTIF safety model, which follows a driving policy, assumes that road user behavior that does not lead to irrational situations is the appropriate rational behavior to be taken. Irrational situations between a host vehicle 2 and a target moving object 3 in a lane structure Ls include a head-on collision, a rear-end collision, and a side collision. Rational behavior in a head-on collision includes, for example, when the target moving object 3 relative to the host vehicle 2 is the target vehicle 3a, the vehicle traveling in the opposite direction brakes. Rational behavior in a rear-end collision includes, for example, when the target moving object 3 relative to the host vehicle 2 is the target vehicle 3a, the vehicle traveling in front does not brake suddenly beyond a certain level, and the vehicle traveling behind avoids a rear-end collision based on that assumption. Rational behavior in a side-end collision includes, for example, when the target moving object 3 relative to the host vehicle 2 is the target vehicle 3a, the vehicles traveling side by side steer away from each other. When assuming rational behavior, the state quantities related to the host vehicle 2 and the target moving body 3 are transformed into a Cartesian coordinate system that defines the longitudinal and lateral directions by assuming a linear and planar lane structure Ls, regardless of whether the lane structure Ls is a curved lane or an elevated lane structure Ls.

[0058] The safety model may be designed in accordance with accident liability rules, which hold that vehicles that do not behave rationally are responsible for accidents. Under the accident liability rules for lane structure Ls, the safety model used to monitor the risk between the host vehicle 2 and the target vehicle 3 sets a safety envelope for the host vehicle 2 so that the host vehicle 2 avoids potential accident liability through rational behavior. Therefore, when the entire processing device 1a is in a normal state, the risk monitoring block 140 determines whether or not the safety envelope has been violated by comparing the actual distance between the host vehicle 2 and the target vehicle 3 with the safety distance based on the safety model for each driving scenario. If a safety envelope violation has occurred, the risk monitoring block 140 simulates a scenario for instructing the host vehicle 2 to behave rationally. Through the simulation, the risk monitoring block 140 sets a limit value for at least one of speed and acceleration as a constraint on driving control in the control block 160.

[0059] In the first embodiment, a processing method for performing driving-related processing according to the flowchart shown in FIG. 11 is executed by the cooperation of multiple functional blocks. The processing method of the first embodiment is repeatedly executed in both manual driving and automated driving planned by the planning block 120, regardless of whether one mode is involved in the other mode. Here, each "S" in the processing method refers to multiple steps executed by multiple instructions contained in a processing program stored in at least one of the memories 10 and 80. Furthermore, when the processing system 1 is constructed in the host vehicle 2 or the like, including the communication device 6a constituting the communication system 6, each "S" in the processing method may refer to multiple steps executed by multiple instructions contained in the processing program stored in the memory 60, in addition to the processing program stored in at least one of the memories 10 and 80.

[0060] In S100 of the processing method, the risk monitoring block 140 monitors the safety envelope violations related to the safety envelope set in SOTIF according to the driving policy in one of the host vehicles 2 selected by the planning block 120 from manual driving and autonomous driving. If the risk monitoring block 140 determines in S100 that a safety envelope violation has not occurred (i.e., no safety envelope violation), the current flow of the processing method ends. On the other hand, if the risk monitoring block 140 determines in S100 that a safety envelope violation has occurred (i.e., a safety envelope violation has occurred), the processing method proceeds to S110.

[0061] In S110 of the processing method, the risk monitoring block 140 generates scene information Is representing a violation scene, which is a scene of a safety envelope violation that occurred in the selected manually or automatically driven host vehicle 2, so as to be transmitted from the host vehicle 2 to the remote center 8 via the communication system 6. The scene information Is may be information at the time when the safety envelope violation occurred. The scene information Is may also include information before and after the time when the safety envelope violation occurred, for example, from the perspective of an EDR (Event Data Recorder) or the like. The scene information Is includes situation information Ia, which is generated based on detection information by the detection block 100 and represents the situation of the safety envelope violation.

[0062] The situation information Ia may represent at least one actual value of the speed, acceleration, and deceleration of the host vehicle 2 shown in FIG. 12 as a motion physical quantity that violates the safety envelope and deviates from the limit values ​​set by the constraints of the risk monitoring block 140. The motion physical quantity represented by the situation information Ia also takes into account differences in the longitudinal and lateral directions of the lane structure Ls. The situation information Ia may represent at least one of the following as the state of the host vehicle 2 in the violation scene: a self-state quantity including position (i.e., a localization estimate), a vector, an accumulated mileage, an accumulated traveling time, a load weight, a tire condition including wear, a maintenance status, an operating status of a driving actuator, and a vehicle type. The situation information Ia may include an image or video captured by a camera serving as the external sensor 50 in the host vehicle 2.

[0063] The situation information Ia may represent at least one of the planned conditions in the planning block 120 of the host vehicle 2 at the violation scene, such as the route, trajectory, control parameters, and automated driving level (including the case where manual driving is level 0). The planned condition of the route represented by the situation information Ia may include, for example, a planning result for at least one of the route to the destination and the driving lanes in a multi-lane structure. The situation information Ia for manual driving may represent, as the state of the driver operating the host vehicle 2 at the violation scene, at least one of the driving tendency including a driving score before the violation scene, a history of mileage, a history of driving time, a history of safety envelope violations, and a physical condition.

[0064] The situation information Ia may represent at least one of the following as the state of the target moving object 3 in the violation scene: an estimated state including, for example, position, distance, speed, acceleration / deceleration, relative speed, relative acceleration, and vectors thereof; and type. If the type of the target moving object 3 is a vulnerable road user, the situation information Ia may represent at least one of the following, for example, age, physical condition, etc., of a person who is at least a part of the road user.

[0065] The situation information Ia may represent, for example, a risk type as a relative state between the host vehicle 2 and the target moving object 3. The risk type represented by the situation information Ia may be at least one of, for example, rear-end collision risk, head-on collision risk, side collision risk, intersection risk, blind spot risk, and detailed conditions thereof, which are assumed as shown in FIG. 12 in a safety model that defines the safety envelope used as the criterion for determining a safety envelope violation. The situation information Ia may represent, as road conditions of the violation scene, at least one of, for example, traffic rules, signs, road structure, location, section, road surface condition, lighting conditions, construction status, traffic congestion, the presence of obstacles including fallen objects, feature structures around the road, and blind spots due to the feature structures or moving object type. Here, the moving object type refers to a classification of vehicles, such as cars, trucks, and buses. The situation information Ia representing the road conditions may include map data associated with the road conditions. The situation information Ia may represent at least one of the time of the violation scene, the time period of the violation scene including whether it is day or night, and the weather conditions (ie, the weather) of the violation scene.

[0066] In S110, the risk monitoring block 140 may determine the cause of the safety envelope violation. In this case, the scene information Is may include factor information Ib representing the cause. As shown in FIG. 12, the factor information Ib may be generated for at least one of the host vehicle 2 and the target moving object 3 that is determined to have violated the safety envelope (i.e., the vehicle's own fault and the vehicle's other fault). The factor information Ib may be generated to identify an incorrect judgment in manual driving or an incorrect control in automated driving as the cause of a safety envelope violation that is determined to have caused an unreasonable risk in at least one of operation timing, inter-vehicle distance, traffic priority, speed, etc. The factor information Ib may be generated to identify a driving policy that is not being followed due to a safety envelope violation in manual driving or automated driving as the cause of a safety envelope violation that is determined to have caused an unreasonable risk. FIG. 12 illustrates, by number, the results of identifying the violated driving policy among the driving policies numbered (1) to (5) when the target moving object 3 is the target vehicle 3a.

[0067] The scene information Is generated by the risk monitoring block 140 in S110 can be uploaded and transmitted to the remote center 8 in accordance with transmission control by the risk monitoring block 140 in the communication system 6 (processor 62 of the communication device 6a) once the remote center 8 has completed authentication of the user ID including the authentication key. In S110, the risk monitoring block 140 may store the generated scene information Is in the memory 10. The scene information Is may be stored in the memory 10 in association with a timestamp indicating the time of generation by the risk monitoring block 140, thereby allowing scene information Is at multiple points in time to be accumulated in the memory 10. The scene information Is may be encrypted or hashed when stored in the memory 10. When the stored scene information Is is hashed, the hash value that will form part of the scene information Is may be transmitted to the remote center 8.

[0068] In the case of a target vehicle 3a that is assumed to be another host vehicle 2 from the viewpoint of the remote center 8, the risk monitoring block 140 may execute S110 to generate scene information Is and control transmission from the target vehicle 3a via the communication system 6. In this assumed case, the scene information Is is information that represents a scene of a safety envelope violation that occurred in the target vehicle 3a, i.e., a violation scene.

[0069] 11, the center management block 880 acquires the scene information Is uploaded from the risk monitoring block 140 from the selected manually or automatically driven host vehicle 2 via the communication system 8b. In the case of a target vehicle 3a that is assumed to be another host vehicle 2 from the perspective of the remote center 8, the center management block 880 also acquires the scene information Is from the target vehicle 3a via the communication system 8b in S120.

[0070] In S120, the center management block 880 may store the acquired scene information Is in the memory 80. The scene information Is may be stored in the memory 80 in association with a timestamp indicating the time of generation by the risk monitoring block 140 or the time of acquisition by the center management block 880, thereby accumulating scene information Is at multiple points in time in the memory 80. The scene information Is may be encrypted or hashed when stored in the memory 80. If the scene information Is is encrypted at the time of acquisition, the encrypted scene information Is may be decrypted and then stored in the memory 80. If the scene information Is is a hash value at the time of acquisition, the hash value may be temporarily stored in the memory 80. The hash value stored in the memory 80 is compared with the hash value for the scene information Is stored in the memory 10 on the processing device 1a side when the scene information Is is used in S130, which will be described later, thereby enabling secure acquisition of the scene information Is.

[0071] In S130 of the processing method, the center management block 880 generates feedback information If to be fed back to the host vehicle 2 based on the acquired scene information Is, so that the feedback information If is transmitted from the remote center 8 to the host vehicle 2 via the communication system 8b. The feedback information If may be information generated to perform onboard verification and validation in the host vehicle 2. The feedback information If may be information generated based on the concept of a feedback loop between the host vehicle 2 and the remote center 8. The feedback information If may be generated in real time based on the acquired scene information Is in response to acquiring the scene information Is. In S130, the center management block 880 may perform statistical analysis processing, including aggregation processing, on the scene information Is at multiple points in time when it is stored in the memory 80. In this case, the feedback information If may be generated ex post based on the output results of the statistical analysis processing. The generation of the ex post feedback information If may be performed at least one type of time span, for example, daily, weekly, monthly, or for a predetermined number of trips (i.e., operations).

[0072] The scene information Is stored in the memory 80 may be deleted in response to the generation or transmission of the feedback information If. The scene information Is stored in the memory 80 may be deleted in response to at least one of triggers such as a set period, an operator's instruction, or a period in which no safety envelope violations have occurred in the same scene or the same location.

[0073] The feedback information If includes assistance information Ic that indicates assistance content for driving in the host vehicle 2, determined based on the scene information Is. The assistance information Ic may represent an authorization command that authorizes constraints set by the risk monitoring block 140 for driving control that violates the safety envelope planned in the host vehicle 2. The authorization command for the constraints represented by the assistance information Ic may be set to authorize at least one of, for example, a speed limit and an acceleration / deceleration limit of the host vehicle 2. The assistance information Ic may represent an instruction to change setting parameters or learning parameters in a safety model that defines the safety envelope that served as the criterion for determining a safety envelope violation in the host vehicle 2.

[0074] The assistance information Ic may represent an update command or a parameter adjustment command for at least one of the detection algorithms, such as fusion, object detection, lane detection, sign detection, and localization, performed by the detection block 100 of the host vehicle 2. The assistance information Ic may represent an adjustment command for at least one of the internal parameters and external parameters of the sensor system 5 of the host vehicle 2.

[0075] The assistance information Ic may represent a change command for transitioning to a minimum-risk state for at least one of the following, based on the planning block 120 of the host vehicle 2: a route, a trajectory, an automated driving level (including a case where manual driving is assumed to be Level 0), a traffic design domain, and control parameters. The route change command represented by the assistance information Ic may include a selection result of determining a route with fewer safety envelope violations for at least one of the following: a route to a destination, a driving lane in a multi-lane structure, etc. The control parameter change command represented by the assistance information Ic may be set to plan at least one of the following: a speed limit, an acceleration / deceleration limit, braking intervention, steering intervention, auto-cruise control intervention, and traction control intervention. In this case, the change command may be set for control parameters specific or particular to at least one of the following: a type of vehicle that frequently violates the safety envelope, weather conditions that frequently violate the safety envelope, and time periods that frequently violate the safety envelope. The support information Ic for the manually driven host vehicle 2 may represent a warning command to the driver who has violated the safety envelope. The support information Ic for the manually driven host vehicle 2 may represent an automatic driving intervention command by the planning block 120 of the host vehicle 2.

[0076] In S130, the center management block 880 may determine the cause of the safety envelope violation based on the scene information Is. In this case, the feedback information If may include factor information Ib representing the cause, as shown in FIG. 12. The factor information Ib may be generated in accordance with S110 described above. The center management block 880 constructed by the processing device 8a of the remote center 8 can generate factor information Ib through more accurate and detailed factor analysis (including the statistical analysis described above) than the risk monitoring block 140 constructed by the processing device 1a of the host vehicle 2. This is because the processing device 8a (especially the cloud server-based device 8a) has a higher degree of freedom in computer design than the processing device 1a. Furthermore, when information about vehicles that have fallen into an unreasonable risk state is uploaded, the center management block 880 of the processing device 8a can provide a third-party perspective by integrating the information and determining which vehicle was responsible for the accident.

[0077] In the feedback information If when the factor information Ib is included, the support content represented by the support information Ic may be commanded in association with the factor represented by the factor information Ib. In one specific example, the support content for a safety envelope violation caused by speeding may be a command to impose an acceleration / deceleration limit, etc. on the host vehicle 2 through constraint setting or a driving control plan. In another specific example, the support content for a safety envelope violation caused by an incorrect judgment or incorrect control of intersection timing may be a command to impose an acceleration / deceleration limit, braking intervention, steering intervention, etc. on the host vehicle 2 through constraint setting or a driving control plan.

[0078] The feedback information If in the case where the factor information Ib is included may include, for example, video or the like, which corroborates the factor determined by the center management block 880 from the scene information Is acquired by the center management block 880. The scene information Is that corroborates the factor for the manually driven host vehicle 2 may include, for example, video of a violation scene in which the driver was forced to violate the safety envelope, such as a merging scene at a short merging section or a scene of entering a blind spot where the end of a traffic jam is located.

[0079] The feedback information If generated by the center management block 880 in S130 can be transmitted to the host vehicle 2 in accordance with control of the communication system 8b by the center management block 880 after the remote center 8 has completed authentication of the user ID including the authentication key. The timing of transmitting the feedback information If may be controlled in real time or after the safety envelope violation, depending on the timing of generating the feedback information If described above. The timing of transmitting the feedback information If may also be controlled so as to respond to a request from the host vehicle 2, which will be described later. After completion of execution of S130 in the case where the feedback information If is generated or transmitted after the fact, or transmitted in response to a request from the host vehicle 2, the processing method does not proceed to S140 or S150 in the current flow, but such a transition may be realized as necessary.

[0080] In S130, the center management block 880 may store the generated feedback information If in the memory 80. The feedback information If may be stored in the memory 80 in association with a timestamp indicating the time of generation by the center management block 880, so that feedback information If at multiple points in time may be accumulated in the memory 80. The feedback information If may be encrypted or hashed before being stored in the memory 80. The feedback information If stored in the memory 80 may be deleted in response to the generation or transmission of the feedback information If. The feedback information If stored in the memory 80 may be deleted using at least one of the following as a trigger, for example, a set period, an instruction from an operator, or a period of time without a safety envelope violation occurring in the same scene or the same location.

[0081] In the case of a target vehicle 3a that is assumed to be another host vehicle 2 from the viewpoint of the remote center 8, the center management block 880 may execute control in S130 to generate feedback information If and transmit the information to the target vehicle 3a via the communication system 8b. The feedback information If in this assumed case is information that is fed back to the target vehicle 3a based on the scene information Is. Furthermore, the feedback information If in this assumed case may be generated so as to deliver to each vehicle at least one of, for example, locations where a safety envelope violation is highly likely to occur, causes of the safety envelope violation, and assistance content for avoiding the safety envelope violation.

[0082] 11, the risk monitoring block 140 acquires the feedback information If downloaded from the center management block 880 in the selected manually or automatically driven host vehicle 2 in accordance with reception control by the communication system 6 (processor 62 of the communication device 6a). The feedback information If may be acquired by transmission from the center management block 880 in real time or after a safety envelope violation has occurred in the host vehicle 2. The feedback information If may also be acquired by transmission from the center management block 880 in response to a request from the host vehicle 2, for example, at any timing or within a predetermined range on the route. In the case of a target vehicle 3a, which is assumed to be another host vehicle 2 from the perspective of the remote center 8, the risk monitoring block 140 acquires the feedback information If for the target vehicle 3a from the center management block 880 via the communication system 6 in S140.

[0083] In S140, the risk monitoring block 140 may store the acquired feedback information If in the memory 10. The feedback information If may be stored in the memory 10 in association with a timestamp indicating the time of generation by the center management block 880 or the time of acquisition by the risk monitoring block 140, thereby allowing the memory 10 to accumulate feedback information If at multiple points in time. The feedback information If may be encrypted or hashed when stored in the memory 10. If the feedback information If is encrypted when acquired, the encrypted feedback information If may be decrypted and then stored in the memory 10. If the feedback information If is a hash value when acquired, the hash value may be temporarily stored in the memory 10. The hash value stored in the memory 10 is compared with the hash value for the feedback information If stored in the memory 80 on the processing device 8a side when the feedback information If is used in S150, which will be described later, thereby enabling secure acquisition of the feedback information If.

[0084] The risk monitoring block 140 in S140 may delete the scene information Is stored in the memory 80 in response to the acquisition of the feedback information If, either at the time of acquisition or after using the feedback information If in S150. The risk monitoring block 140 in S140 may delete the scene information Is stored in the memory 80 using at least one of a set period, a period of no safety envelope violations occurring in the same scene or the same location, etc. as a trigger.

[0085] In S150 of the processing method, at least one of the risk monitoring block 140, the detection block 100, and the planning block 120 executes an application selected based on the acquired feedback information If. In S150, a block among the risk monitoring block 140, the detection block 100, and the planning block 120 corresponding to the assistance content represented by the assistance information Ic included in the feedback information If may execute an application for realizing the assistance content. In this case, if the feedback information If further includes at least one of the factor information Ib and the scene information Is, the corresponding block of the assistance content may reflect the at least one of the information Ib and the scene information Is in the execution of the application. In particular, if the assistance information Ic in the feedback information If represents an instruction to permit a restriction on operation control that violates the planned safety envelope, in S150 the risk monitoring block 140 imposes a restriction on the operation control executed by the control block 160.

[0086] In S150, the risk monitoring block 140 may execute an application capable of recognizing the appropriateness of the judgment regarding the safety envelope violation based on the feedback information If. Recognizing the appropriateness by executing the application in S150 can also be considered as verification of the judgment regarding the safety envelope violation. The execution of the application in S150 may be realized in real time in response to acquisition of the feedback information If, or afterward by storing the acquired information If in the memory 10. As described above, the current flow of the processing method ends when the execution of S150 is completed. However, if the execution of the application is afterward determined in S150, the execution of the application may be postponed until the next or subsequent flow, and the current flow of the processing method ends. Furthermore, the application in S150 includes not only an application dedicated to checking, but also an application that realizes the above-mentioned support content and is recognized secondarily or indirectly.

[0087] Now, the technology disclosed in Patent Document 1 described above only assumes that constraints on driving control are imposed on the host vehicle for automated driving. Therefore, safety in manual driving of the host vehicle is left to the driver. Furthermore, the technology disclosed in Patent Document 1 presupposes that the host vehicle's judgment is appropriate when imposing constraints on driving control. Therefore, even if the technology disclosed in Patent Document 1 is applied to manual driving, if the driver of the host vehicle makes an error in judgment, the erroneous judgment will affect safety. Furthermore, the technology disclosed in Patent Document 1 presupposes that the host vehicle's judgment is appropriate when imposing constraints on driving control in automated driving. Therefore, if the host vehicle makes an error in judgment, the erroneous judgment will affect the driving accuracy of the automated driving.

[0088] In contrast, according to the first embodiment described above, in both manual driving and automated driving, feedback information If is fed back from the remote center 8 to the host vehicle 2 based on scene information Is representing a scene of a safety envelope violation for which SOTIF is set in accordance with a driving policy. This allows the host vehicle 2 to recognize the appropriateness of its judgment regarding the safety envelope violation based on the feedback information If, which is a third-party judgment. Therefore, in the host vehicle 2, it is possible to promote improvement in safety during manual driving and ensure driving accuracy during automated driving. Similarly, in the case where the target vehicle 3a is assumed to be another host vehicle 2 from the perspective of the remote center 8, it is possible to promote improvement in safety during manual driving and ensure driving accuracy during automated driving in the target vehicle 3a as a "second host moving body."

[0089] Second Embodiment The second embodiment is a modified example of the first embodiment. The second embodiment will be described below, focusing on the differences between the first embodiment and the second embodiment in the driving-related processing in manual driving. Therefore, the driving-related processing in manual driving described in the second embodiment may be incorporated into or executed in parallel with the corresponding steps in the driving-related processing of the first embodiment, or may be executed instead of the driving-related processing of the first embodiment.

[0090] 13, in S200 corresponding to S100 in the processing method of the second embodiment, the risk monitoring block 140 monitors a safety envelope violation in the manually driven host vehicle 2. As shown in FIG. 14, the risk monitoring block 140 in S200 may determine that a safety envelope violation has occurred when the actual value of the motion physical quantity deviates from the limit value R1 set by the constraint setting.

[0091] In S210, which corresponds to S110 in the processing method, the risk monitoring block 140 generates at least situation information Ia as scene information Is representing a violation scene in a manually driven host vehicle 2. The risk monitoring block 140 in S210 generates situation information Ia so as to represent the driver state of the host vehicle 2, which is necessary for calculating the driving score, in association with a safety envelope violation. The driver state necessary for the driving score is, for example, at least one of driving tendencies including a driving score before the violation scene, a history of mileage, a history of driving time, and a history of safety envelope violations. The situation information Ia necessary for the driving score may represent at least one of the conditions of the host vehicle 2 that may affect the driver's fault judgment, such as the load weight, the tire condition including wear, the maintenance status, the operating status of the driving actuator, and the type of vehicle.

[0092] The risk monitoring block 140 in S210 may generate situation information Ia representing at least one of, for example, time, location, and localization estimate value of a violation scene in which the motion physical quantity deviates from the limit values ​​R1 to R3 as shown in Fig. 14. When the length of a violation section Δs in which the motion physical quantity deviates from the limit values ​​R1 to R3 is outside a set range as shown in Fig. 14, the risk monitoring block 140 in S210 may generate situation information Ia representing the trajectory (i.e., track) of the host vehicle 2 in the violation section Δs in the map data. When the length of a violation time Δt in which the motion physical quantity deviates from the limit values ​​R1 to R3 is outside a set range as shown in Fig. 14, the risk monitoring block 140 in S210 may generate situation information Ia representing the violation time Δt. Note that the set ranges that serve as criteria for determining the violation section Δs and the violation time Δt may be set to ranges equal to or less than a threshold value. FIG. 14 also shows an example in which the motion physical quantity deviates from the upper limit value R1 between times t1 and t2, deviates from the changed upper limit value R2 between times t2 and t3, and deviates from the lower limit value R3 from time t4 onwards.

[0093] 13, in S220, which corresponds to S120 in the processing method, the center management block 880 acquires scene information Is from the manually driven host vehicle 2 via the communication system 8b. In S230, which corresponds to S130 in the processing method, the center management block 880 generates at least score information Id as feedback information If to be fed back to the host vehicle 2 based on the acquired scene information Is. The score information Id represents a driving score for the driver of the host vehicle 2. The center management block 880 determines the driving score based on the scene information Is. The driving score may be expressed as a numerical value or a high or low level as an index for objectively evaluating the driver operating the host vehicle 2.

[0094] The center management block 880 in S230 may generate support information Ic as feedback information If to represent an exemplary command for manual driving recommended to avoid a safety envelope violation. Examples of the exemplary command represented by the support information Ic include a command to advance the braking timing relative to the target vehicle 3a ahead in the longitudinal direction, or to shorten the time to run alongside the target vehicle 3a in the lateral direction. The center management block 880 in S230 may generate, as feedback information If, at least one of factor information Ib representing the cause of the safety envelope violation and scene information Is supporting the cause, associated with the support information Ic representing the exemplary command.

[0095] In the processing method of the second embodiment, S140 of acquiring feedback information If and S150 of executing an application based on the feedback information If are implemented in the host vehicle 2. S200, S210, S220, S230, S140, and S150 of the processing method may also be implemented in a target vehicle 3a, which is assumed to be another host vehicle 2 from the perspective of the remote center 8. In this assumed case, in the center management block 880 of S220 and S230, scene information Is of safety envelope violations may be accumulated and compiled in memory 80 from the perspective of at least one of each vehicle 2, 3a and each driver of each vehicle 2, 3a, and a driving score may be calculated by statistical analysis of the compilation results.

[0096] In the second embodiment described above, the transmission, storage, and deletion of the scene information Is and the feedback information If are the same as those in the first embodiment. As a result, in S140, the feedback information If including at least the score information Id is acquired. According to the second embodiment described above, the appropriateness of the judgment regarding the violation of the safety envelope can be recognized even by a driver during manual driving based on the driving score represented by the score information Id in the feedback information If. Therefore, the second embodiment is advantageous for promoting safety improvements, particularly in manual driving.

[0097] (Third embodiment) The third embodiment is a modified example of the first embodiment. The following describes the third embodiment, focusing on differences between the first embodiment and the third embodiment in the driving-related processing during manual driving. Therefore, the driving-related processing during manual driving described in the third embodiment may be incorporated into or executed in parallel with a corresponding step in at least one of the driving-related processing of the first and second embodiments, or may be executed instead of the driving-related processing of the first embodiment.

[0098] 15, the remote center 8 of the processing system 1 according to the third embodiment is capable of communicating with the service center 9 via a communication system 8b. The service center 9 is managed by a service provider that provides services related to road users including the host vehicle 2. The services provided by the service center 9 are at least one of, for example, urban planning services, road maintenance services, map information services, operation management services, traffic management services, vehicle insurance services, ride sharing services, and car sharing services.

[0099] The service center 9 includes a processing device 9a and a communication system 9b having a configuration similar to that of the remote center 8. However, the processing device 9a acquires information provided from the remote center 8 through the communication system 9b by cooperating with the processing program in the remote center 8 or by executing an individual program that is part of or different from the processing program. The service center 9 utilizes the information provided from the remote center 8 for the services of the service provider.

[0100] 16 , in S330, which corresponds to S130 in the processing method of the third embodiment, the center management block 880 generates public information Io to be disclosed to the service center 9 based on at least one of the scene information Is and the feedback information If. The public information Io may be generated to disclose locations with a high probability of safety envelope violations to service centers 9 that provide, for example, urban planning services, road maintenance services, map information services, operation management services, or traffic management services. The public information Io may be generated to disclose information that serves as the assessment standard for vehicle insurance to service centers 9 that provide, for example, vehicle insurance services.

[0101] The public information Io may be generated to disclose, for example, the cause of a safety envelope violation associated with each driver in manual driving to a service center 9 that provides a ride-sharing service, a car-sharing service, or the like. In this case, the public information Io may be generated to disclose assistance content tailored to the cause. In one specific example of assistance content tailored to the cause, if the cause is an incorrect judgment of giving priority to oncoming vehicles, a route with less on-street parking that does not require the driver to cross into the oncoming lane is searched for, and the result of the route search is provided as the public information Io. In another specific example of assistance content tailored to the cause, if the cause is an incorrect judgment of intersection timing, a route is searched for that passes through an intersection controlled by a traffic light system, and the result of the route search is provided as the public information Io.

[0102] In the processing method of the third embodiment, S100, S110, S120, and S330 may be executed in accordance with S200, S210, S220, and S230 of the second embodiment. In S330 in the case of executing S230 in accordance with the public information Io generated as described above, if the public information Io discloses assistance content tailored to the cause of the safety envelope violation, a driving score may be calculated for each driver. In one specific example of assistance content tailored to the cause, the public information Io is provided to a service center 9 that provides a ride-sharing service, for selecting drivers with high driving scores.

[0103] According to the third embodiment, the public information Io for the service center 9 is generated based on at least one of the scene information Is and the feedback information If regarding the safety envelope violation. Therefore, the third embodiment, coupled with the participation of service providers, is advantageous in promoting the improvement of safety in manual driving.

[0104] (Fourth embodiment) The fourth embodiment is a modified example of the first embodiment. The fourth embodiment will be described below, focusing on the differences between the driving-related processing in the autonomous driving and the first embodiment. Therefore, the driving-related processing in the autonomous driving described in the fourth embodiment may be incorporated into or executed in parallel with the corresponding step in the driving-related processing of the first embodiment, or may be executed instead of the driving-related processing of the first embodiment.

[0105] As shown in Fig. 17, in S400, which corresponds to S100 in the processing method of the fourth embodiment, the risk monitoring block 140 executes a monitoring subroutine on the autonomously driven host vehicle 2. As shown in Fig. 18, in S401 of the monitoring subroutine, the risk monitoring block 140 monitors safety envelope violations in the host vehicle 2 in accordance with S100. If the risk monitoring block 140 determines in S401 that there is no safety envelope violation, the monitoring subroutine and the current flow of the processing method end. On the other hand, if the risk monitoring block 140 determines in S401 that there is a safety envelope violation, the monitoring subroutine proceeds to S402.

[0106] In S402, the risk monitoring block 140 determines whether the frequency of occurrence of safety envelope violations is outside the allowable range. The allowable range, which is the criterion for determining the frequency of occurrence, may be set to be equal to or less than the upper limit value, which is the number of consecutive safety envelope violations that are allowable. The allowable range, which is the criterion for determining the frequency of occurrence, may be set to be equal to or less than the upper limit value, which is the number of times that safety envelope violations are allowable to occur within a set time. If the risk monitoring block 140 determines in S402 that the frequency of occurrence is within the allowable range, the monitoring subroutine and the current flow of the processing method end. On the other hand, if the risk monitoring block 140 determines in S402 that the frequency of occurrence is outside the allowable range, the current flow of the monitoring subroutine end, and the processing method proceeds to S410 shown in FIG. 17.

[0107] In S410, which corresponds to S110 in the processing method, the risk monitoring block 140 generates at least situation information Ia as scene information Is that represents a violation scene in the autonomous driving host vehicle 2. The risk monitoring block 140 in S410 generates situation information Ia to represent a high-frequency violation scene in which the frequency of occurrence of safety envelope violations is outside the acceptable range. In this fourth embodiment, S400 and S410 are also executed in the target vehicle 3a, which is assumed to be another host vehicle 2 from the perspective of the remote center 8. However, the acceptable range that serves as the criterion for determining the occurrence frequency in the risk monitoring block 140 of the target vehicle 3a may be set to the same or a different range from that in the risk monitoring block 140 of the host vehicle 2, for example, by individual setting for each vehicle.

[0108] In the processing method, at S420 and S430 corresponding to S120 and S130, respectively, the center management block 880 sequentially executes a first and a second management subroutine. As shown in Fig. 19, at S421 of the first management subroutine, the center management block 880 acquires scene information Is representing high-frequency violation scenes from the autonomous driving host vehicle 2 in accordance with S120.

[0109] In S422 of the first management subroutine, the center management block 880 determines whether scene information Is, which indicates high-frequency violation scenes, has also been acquired from the autonomously driven target vehicle 3a in accordance with S120. At this time, the target vehicle 3a from which scene information Is is acquired corresponds to the "second moving body" by being defined as another road user existing around the host vehicle 2, which corresponds to the "first moving body," within a set range.

[0110] If the center management block 880 determines in S422 that scene information Is representing a high-frequency violation scene has been acquired, the first management subroutine ends and the process proceeds to S431 of the second management subroutine. That is, S431 is executed for a high-frequency violation scene of the host vehicle 2 when the frequency of safety envelope violations in the target vehicle 3a is also outside the allowable range. In S431, the center management block 880 generates at least support information Ic as feedback information If to be fed back to the host vehicle 2 based on the acquired scene information Is. In S431, the center management block 880 generates the support information Ic to represent a change command to exclude the driving area of ​​the specific violation scene from the ODD in autonomous driving of the host vehicle 2. Completion of execution of S431 thus ends the current flow of the second management subroutine, and the process proceeds to S140 shown in FIG. 17.

[0111] As shown in FIG. 19 , if the center management block 880 determines in S422 that scene information Is representing a high-frequency violation scene has not been acquired, the first management subroutine ends and the process proceeds to S432 of the second management subroutine. That is, S432 is executed for a high-frequency violation scene of the host vehicle 2 when the frequency of safety envelope violations in the target vehicle 3a is within an acceptable range. In S432, the center management block 880 generates at least support information Ic as feedback information If to be fed back to the host vehicle 2 based on the acquired scene information Is. The center management block 880 in S432 may generate the support information Ic to represent, for example, a stop command such as an MRM to stop the host vehicle 2. If the host vehicle 2 is a service vehicle, such as a bus or taxi, whose operation service is managed by the remote center 8, the support information Ic may represent an operation command to stop operation and have the vehicle sent for inspection at a service workshop. As described above, the execution of S432 is completed, and the current flow of the second management subroutine ends, and the processing method proceeds to S140 shown in Figure 17. Note that the transmission, storage, and deletion of the scene information Is and the feedback information If are the same as those in the first embodiment. In the processing method of the fourth embodiment, S140 of acquiring the feedback information If and S150 of executing the application as described above based on the feedback information If are realized in the host vehicle 2 and the target vehicle 3a.

[0112] In the fourth embodiment described above, S420 and S430, in which the relationship between the host vehicle 2 and the target vehicle 3a is swapped from the perspective of the remote center 8, may be executed in parallel. According to the fourth embodiment described above, the appropriateness of the judgment regarding the safety envelope violation can also be recognized by the risk monitoring block 140 during autonomous driving based on the command represented by the support information Ic in the feedback information If. Therefore, the fourth embodiment is advantageous for ensuring driving accuracy, particularly during autonomous driving.

[0113] Fifth Embodiment The fifth embodiment is a modified example of the first embodiment. The fifth embodiment will be described below, focusing on the differences between the driving-related processing in the automated driving mode and the first embodiment. Therefore, the driving-related processing in the automated driving mode described in the fifth embodiment may be incorporated into or executed in parallel with a corresponding step in the driving-related processing in at least one of the first and fourth embodiments, or may be executed instead of the driving-related processing in the first embodiment.

[0114] As shown in FIG. 20 , in S500, which corresponds to S100 in the processing method of the fifth embodiment, the risk monitoring block 140 monitors safety envelope violations between the autonomously driven host vehicle 2 and a target vehicle 3a, which is assumed to be another host vehicle 2 from the perspective of the remote center 8. In S510, which corresponds to 110 in the processing method, the risk monitoring block 140 generates at least situation information Ia as scene information Is representing a specific violation scene that occurred between the host vehicle 2 and the target vehicle 3a. The risk monitoring block 140 in S510 sets the latest constraints on the safety envelope violation represented by the situation information Ia to be generated prior to the generation of the information. In this fifth embodiment, S500 and S510 are also executed for the target vehicle 3a that constitutes the specific violation scene.

[0115] In the processing method, at S520 and S530 corresponding to S120 and S130, respectively, the center management block 880 sequentially executes a first and a second management subroutine. As shown in Fig. 21, in S521 of the first management subroutine, the center management block 880 determines whether scene information Is representing a specific violation scene has been acquired from the autonomously driven host vehicle 2 in accordance with S120.

[0116] If the center management block 880 determines in S521 that scene information Is representing a specific violation scene has not been acquired from the host vehicle 2, the first management subroutine proceeds to S522. That is, S522 is executed when it is determined that no safety envelope violation has occurred between the host vehicle 2 and the target vehicle 3a. In S522, the center management block 880 determines whether scene information Is representing a specific violation scene has been acquired from the autonomously driven target vehicle 3a in accordance with S120. At this time, the target vehicle 3a from which scene information Is is acquired corresponds to a "second moving body" by being defined as another road user present within a set range around the host vehicle 2, which corresponds to a "first moving body." Note that if the center management block 880 determines in S522 that scene information Is representing a specific violation scene has not been acquired from the target vehicle 3a, the first management subroutine and the current flow of the processing method end.

[0117] If the center management block 880 determines in S522 that scene information Is representing a specific violation scene has been acquired from the target vehicle 3a, the first management subroutine ends and the process proceeds to S531 of the second management subroutine. That is, S531 is executed when it is determined that a safety envelope violation between the host vehicle 2 and the target vehicle 3a has not occurred in the host vehicle 2 in a specific violation scene in which it is determined that a safety envelope violation between the target vehicle 3a and the host vehicle 2 has occurred. In S531, the center management block 880 generates at least support information Ic as feedback information If to be fed back based on the acquired scene information Is.

[0118] The center management block 880 in S531 generates the support information Ic to represent a command to the host vehicle 2 that has been determined to have not violated the safety envelope, regardless of the specific violation scene in which the target vehicle 3a has been determined to have violated the safety envelope. The command represented by the support information Ic is at least one of, for example, a degeneration command to degenerate to a minimum risk state by constraint setting or a driving control plan, and a change command to change the route of the driving control plan. In particular, the degeneration command may be at least one of, for example, a level downgrade of automated driving including handover to manual driving, MRM, etc. In the case where the host vehicle 2 is a service car such as a bus or taxi, whose operating services are managed by the remote center 8, the support information Ic may represent an operating service to be provided by the host vehicle 2 in accordance with the degeneration command or route change command from the remote center 8.

[0119] The center management block 880 in S531 may generate the support information Ic to represent a notification command notifying the target vehicle 3a that has determined that a safety envelope violation has occurred that the host vehicle 2 has determined that no safety envelope violation has occurred. The center management block 880 in S531 may generate the support information Ic to represent a permission command to permit the restriction on driving that violates the safety envelope, which was set by the risk monitoring block 140 in S510, to the target vehicle 3a that has determined that a safety envelope violation has occurred. The center management block 880 in S531 may also generate the support information Ic to represent a degeneration command or a route change command similar to that in the case of the host vehicle 2 described above, to the target vehicle 3a that has determined that a safety envelope violation has occurred. As described above, when the execution of S531 is completed, the current flow of the second management subroutine ends, and the processing method proceeds to S140 shown in FIG. 20.

[0120] 21, when the center management block 880 determines in S521 that scene information Is representing a specific violation scene has been acquired from the host vehicle 2, the first management subroutine proceeds to S523. That is, S523 is executed when it is determined that a safety envelope violation has occurred between the host vehicle 2 and the target vehicle 3a. In S523, the center management block 880 determines whether scene information Is representing a specific violation scene has also been acquired from the target vehicle 3a in accordance with S120. At this time, the target vehicle 3a from which scene information Is is to be acquired corresponds to a "second moving body" by being defined as another road user that exists around the host vehicle 2 within a set range and constitutes a specific violation scene, relative to the host vehicle 2 that corresponds to a "first moving body."

[0121] If the center management block 880 determines in S523 that scene information Is representing a specific violation scene has not been acquired from the target vehicle 3a, the first management subroutine ends and the process proceeds to S532 of the second management subroutine. That is, S532 is executed when it is determined that a safety envelope violation between the host vehicle 2 and the target vehicle 3a has not occurred between the host vehicle 2 and the target vehicle 3a in a specific violation scene in which a safety envelope violation between the host vehicle 2 and the target vehicle 3a has occurred. In S532, the center management block 880 generates at least support information Ic as feedback information If to be fed back based on the acquired scene information Is. At this time, the support information Ic is generated in accordance with S531, in which the relationship between the host vehicle 2 and the target vehicle 3a is swapped. Completion of S532 ends the current flow of the second management subroutine, and the process proceeds to S140 shown in FIG. 20.

[0122] 21, when the center management block 880 determines in S523 that scene information Is indicating a specific violation scene has also been acquired from the target vehicle 3a, the first management subroutine ends and the process proceeds to S533 of the second management subroutine. That is, S533 is executed when it is determined that a safety envelope violation has also occurred between the host vehicle 2 and the target vehicle 3a in a specific violation scene in which a safety envelope violation between the host vehicle 2 and the target vehicle 3a has occurred. In S533, the center management block 880 generates at least support information Ic as feedback information If to be fed back based on the acquired scene information Is. In S533, the center management block 880 generates the support information Ic so as to represent an authorization command that authorizes the restriction on driving that violates the safety envelope set by the risk monitoring block 140 in S510 in each of the host vehicle 2 and the target vehicle 3a. As described above, the execution of S533 is completed, and the current flow of the second management subroutine ends, and the processing method proceeds to S140 shown in Figure 20. Note that the transmission, storage, and deletion of the scene information Is and the feedback information If are the same as those in the first embodiment. In the processing method of the fifth embodiment, S140 of acquiring the feedback information If and S150 of executing an application based on the feedback information If are realized in the host vehicle 2 and the target vehicle 3a.

[0123] In the fifth embodiment described above, steps S520 and S530, in which the relationship between the host vehicle 2 and the target vehicle 3a is reversed from the perspective of the remote center 8, may be executed in parallel. On the other hand, from the perspective of the remote center 8, if scene information Is from one vehicle among multiple vehicles including the host vehicle 2 and the target vehicle 3a is acquired in S521, it may be determined in S523 that scene information Is has been acquired from another vehicle. In the latter case, steps S532 and S533, in which the relationship between the host vehicle 2 and the target vehicle 3a is replaced with the relationship between the one vehicle and the other vehicle, may be executed, thereby omitting the execution of steps S522 and S531. According to the fifth embodiment described above, the appropriateness of the judgment regarding the safety envelope violation can be recognized by the risk monitoring block 140 during autonomous driving based on the command represented by the assistance information Ic in the feedback information If. Therefore, the fifth embodiment is advantageous for ensuring driving accuracy, particularly during autonomous driving.

[0124] (Sixth embodiment) The sixth embodiment is a modified example of the first embodiment, but may be combined with the second to fifth embodiments.

[0125] As shown in FIG. 22 , in the control block 6160 of the sixth embodiment, the process of acquiring determination information related to the safety envelope is omitted from the risk monitoring block 140. Therefore, the planning block 6120 of the sixth embodiment acquires determination information related to the safety envelope from the risk monitoring block 140. When the planning block 6120 acquires determination information indicating no violation of the safety envelope, it plans the driving control of the host vehicle 2 in accordance with the planning block 120. On the other hand, when the planning block 6120 acquires determination information indicating a violation of the safety envelope, it imposes constraints based on the determination information on the driving control in the planning block 120 at the stage of planning the driving control. In other words, the planning block 6120 imposes restrictions on the planned driving control. In either case, the control block 6160 executes the driving control of the host vehicle 2 planned by the planning block 6120.

[0126] In the processing method of the sixth embodiment, for example, when the support information Ic in the feedback information If represents a change command for a setting parameter or a learning parameter in a safety model, the risk monitoring block 140 may execute the change command in S150. As described above, in the sixth embodiment, by using a principle similar to that of the first embodiment, it is possible to promote improvement in safety in manual driving and ensure driving accuracy in automatic driving.

[0127] Seventh Embodiment The seventh embodiment is a modified example of the first embodiment, but may be combined with the second to fifth embodiments.

[0128] 23 , in the control block 7160 of the seventh embodiment, the process of acquiring judgment information related to the safety envelope is omitted from the risk monitoring block 7140. Therefore, the risk monitoring block 7140 of the seventh embodiment acquires information representing the results of driving control executed by the control block 7160 on the host vehicle 2. The risk monitoring block 7140 evaluates the driving control by executing a safety judgment based on the safety envelope on the results of the driving control.

[0129] In the processing method of the seventh embodiment, for example, if the support information Ic in the feedback information If represents a change command for setting parameters or learning parameters in the safety model, the risk monitoring block 140 may execute the change command in S150. These setting parameters and learning parameters may be changed by verification and validation performed at the remote center 8 or the like, or may be changed based on the concept of a feedback loop. As described above, in the seventh embodiment, it is possible to promote improvement in safety in manual driving and ensure driving accuracy in automated driving based on a principle similar to that of the first embodiment.

[0130] Eighth Embodiment The eighth embodiment is a modified example of the first embodiment, but may be combined with the second to fifth embodiments.

[0131] As shown in FIGS. 24 to 26 , the eighth embodiment adds a test block 8180 that tests the operation control by the processing device 1a, for example, for safety approval. The test block 8180 is provided with functions equivalent to those of the detection block 100 and the risk monitoring block 140. The test block 8180 may be constructed by the processing device 1a shown in FIG. 24 executing a test program that is added to the processing program that constructs each of the blocks 100, 120, 140, and 160. The test block 8180 may also be constructed by a testing processing device 1b different from the processing device 1a, as shown in FIGS. 25 and 26 , executing a testing processing program different from the processing program that constructs each of the blocks 100, 120, 140, and 160. In the example of FIG. 25 , the testing processing device 1b is configured by at least one dedicated computer having a memory 10 and a processor 12 that is connected to the processing device 1a to test the operation control (the illustration of the case of connection via a communication system 6 is omitted). In the example of FIG. 26, a processing device 8a in a remote center 8 replaces the processing device 1b for testing.

[0132] In the eighth embodiment, the processing method using the processing system 1 and processing device 1a can be tested using a principle similar to that of the first embodiment, thereby promoting improved safety in manual operation and ensuring operational accuracy in automatic operation.

[0133] Ninth embodiment The ninth embodiment is a modified example of the sixth embodiment, but may be combined with the second to fifth embodiments.

[0134] As shown in FIG. 27 , in the processing device 1a according to the ninth embodiment, the planning block 9120 incorporates the functions of the risk monitoring block 140 as a risk monitoring sub-block 9140. Therefore, when the risk monitoring sub-block 9140 acquires determination information indicating no violation of the safety envelope, the planning block 9120 of the ninth embodiment plans the driving control of the host vehicle 2 in accordance with the planning block 120. On the other hand, when the risk monitoring sub-block 9140 acquires determination information indicating a violation of the safety envelope, the planning block 9120 imposes constraints on the driving control based on the determination information when planning the driving control in accordance with the planning block 120. In other words, the planning block 9120 imposes restrictions on the planned driving control. In either case, the control block 6160 executes the driving control of the host vehicle 2 planned by the planning block 9120.

[0135] In the processing method of the ninth embodiment, for example, if the support information Ic of the feedback information If represents a change command for a setting parameter or a learning parameter in a safety model, the risk monitoring sub-block 9140 may execute the change command in S150. As described above, in the ninth embodiment, by using a principle similar to that of the first embodiment, it is possible to promote improvement in safety in manual driving and ensure driving accuracy in automatic driving.

[0136] Tenth Embodiment The tenth embodiment is a modification of the first embodiment.

[0137] As shown in FIG. 28 , the processing system 1 of the tenth embodiment is configured to include a processing device 1a mounted on each of the host vehicle 2 and the target vehicle 3a. Here, the processing system 1 of the tenth embodiment may be configured so that each of the vehicles 2, 3a includes at least a communication system 6 among the sensor system 5, communication system 6, map database 7, and information presentation system 4. In this case, communication between the communication devices 6a constituting the communication system 6 in each of the vehicles 2, 3a may be realized directly, for example, via V2V communication, indirectly via a remote center such as a cloud server, or via a mesh network configured between multiple vehicles including the vehicles 2, 3a. In this tenth embodiment, from the perspective of the vehicle 2 acting as the host vehicle, the vehicle 3a corresponds to the target vehicle, while from the opposite perspective, the vehicle 2 corresponds to the target vehicle relative to the vehicle 3a acting as the host vehicle.

[0138] In the processing device 1a of each vehicle 2, 3a according to the tenth embodiment, a processing program stored in each memory 10 for performing driving-related processing for each vehicle 2, 3a causes each processor 12 to execute instructions, thereby constructing individual functional blocks. From the perspective of the processing system 1 as a whole, this can be considered as the processing program stored in the memory 10 of each vehicle 2, 3a causing the processors 12 of each vehicle 2, 3a to cooperatively execute instructions, thereby constructing functional blocks for each vehicle 2, 3a. In this case, in a processing system 1 constructed including a communication device 6a for each vehicle 2, 3a, the processing program stored in the memory 10, 60 of each vehicle 2, 3a may cause the processors 12, 62 of each vehicle 2, 3a to cooperatively execute instructions. In the risk monitoring block 10140 constructed in each processing device 1a of each vehicle 2, 3a according to the tenth embodiment, the function of the center management block 880 is incorporated as a target management sub-block 10880.

[0139] Therefore, in the processing method of the tenth embodiment, when steps S100, S110, S140, and S150 are executed by the risk monitoring block 140 of vehicle 2, steps S120 and S130 may be executed by the target management sub-block 10880 of vehicle 3a. In this case, in S120, the target management sub-block 10880 may acquire scene information Is from vehicle 2 in vehicle 3a according to reception control by the processor 62 of the communication device 6a, and store it in the memory 10. Also, in S130, the target management sub-block 10880 may generate feedback information If so that, among the information Ic, Ib, and Is, at least the assistance information Ic is included as information that can be acquired by vehicle 3a. Furthermore, in S130, the target management sub-block 10880 may transmit the generated feedback information If to vehicle 2 in vehicle 3a according to transmission control by the processor 62 of the communication device 6a, and store it in the memory 10.

[0140] On the other hand, in the processing method of the tenth embodiment, when S100, S110, S140, and S150 are executed by the risk monitoring block 140 of the vehicle 3a, etc., S120 and S130 may be executed by the target management sub-block 10880 of the vehicle 2. In this case, in S120, the target management sub-block 10880 may acquire scene information Is from the vehicle 3a in accordance with reception control by the processor 62 of the communication device 6a in the vehicle 2, and store the acquired information in the memory 10. In addition, in S130, the target management sub-block 10880 may generate feedback information If so that the feedback information If includes at least the assistance information Ic as information that can be acquired by the vehicle 2 out of the information Ic, Ib, and Is. Furthermore, in S130, the target management sub-block 10880 may transmit the generated feedback information If to the vehicle 3a in accordance with transmission control by the processor 62 of the communication device 6a in the vehicle 2, and store the feedback information If in the memory 10.

[0141] Additionally, in either case, in the processing method of the tenth embodiment, for example, if the support information Ic as feedback information If from one of the vehicles 3a, 2 represents a command to change setting parameters or learning parameters in the safety model, the risk monitoring sub-block 10140 of the other of the vehicles 3a, 2 may execute the change command in S150. As described above, in the tenth embodiment, in either of the vehicles 2, 3a, one of which serves as a host vehicle relative to the other target vehicle, it is possible to promote improved safety in manual driving and ensure driving accuracy in autonomous driving based on a principle similar to that of the first embodiment. Note that such a tenth embodiment may be combined with the second to ninth embodiments.

[0142] In a further modification of the tenth embodiment described above, as shown in Fig. 29, a target management block 10880a that realizes the functions of the target management sub-block 10880 may be constructed in the processing device 1a of each vehicle 2, 3a, separate from the risk monitoring block 140 that does not incorporate the functions of the center management block 880 according to the first embodiment. Note that such a modification of the tenth embodiment may be combined with the second to ninth embodiments.

[0143] (Other embodiments) Although multiple embodiments have been described above, the present disclosure should not be construed as being limited to those embodiments, and can be applied to various embodiments and combinations within the scope that does not deviate from the gist of the present disclosure.

[0144] In a modified example, the dedicated computer constituting at least one of the devices 1a, 8a, and 6a may include a digital circuit and / or an analog circuit as a processor. Here, the digital circuit is, for example, at least one of an application-specific integrated circuit (ASIC), a field-programmable gate array (FPGA), a system-on-a-chip (SOC), a programmable gate array (PGA), and a complex programmable logic device (CPLD). Such a digital circuit may also have a memory that stores a program.

[0145] In addition to the embodiments described above, the processing device 1a according to the above-described embodiments and modifications may be implemented as a semiconductor device (e.g., a semiconductor chip) having at least one processor 12 and one memory 10. The processing device 8a according to the above-described embodiments and modifications may be implemented as a semiconductor device (e.g., a semiconductor chip) having at least one processor 82 and one memory 80. Furthermore, the communication device 6a according to the above-described embodiments and modifications may be implemented as a semiconductor device (e.g., a semiconductor chip) having at least one processor 62 and one memory 60.

[0146] (Additional remarks) The technical features of the above-described embodiments can be summarized as follows.

[0147] (Technical feature 1) Technical feature 1 is a processing device (1a) including a processor (12) for performing processing related to the operation of a host mobile body (2, 3a) capable of communicating with a remote center (8), wherein the processor is configured to monitor a safety envelope violation, which is a violation of a safety envelope that sets the safety of intended functions in accordance with an operating policy, in a manually operated host mobile body, and when it is determined that a safety envelope violation has occurred, generate scene information representing a scene of the safety envelope violation to be transmitted to the remote center, and obtain feedback information from the remote center that is fed back based on the scene information.

[0148] (Technical feature 2) In Technical Feature 1, generating scene information includes generating situation information as scene information representing a situation of a safety envelope violation.

[0149] (Technical feature 3) In Technical Feature 1 or 2, acquiring feedback information includes acquiring assistance information as feedback information representing the content of driving assistance determined based on scene information.

[0150] (Technical feature 4) In any one of the technical features 1 to 3, acquiring feedback information includes acquiring factor information as feedback information that indicates the factor of the safety envelope violation determined based on the scene information.

[0151] (Technical feature 5) In any one of technical features 1 to 4, acquiring feedback information includes acquiring score information as feedback information representing a driving score determined for the driver of the host vehicle based on the scene information.

[0152] (Technical feature 6) In any one of technical features 1 to 5, generating scene information includes storing the generated scene information in a storage medium (10) of the host mobile body, and obtaining feedback information includes deleting the scene information from the storage medium in response to obtaining the feedback information.

[0153] (Technical feature 7) Technical feature 7 is a processing method executed by a processor (12) to perform processing related to the operation of a host mobile body (2, 3a) capable of communicating with a remote center (8), and includes monitoring a safety envelope violation, which is a violation of a safety envelope set in accordance with an operating policy to ensure the safety of intended functions, in a manually operated host mobile body, generating scene information representing a scene of the safety envelope violation to be transmitted to the remote center when it is determined that a safety envelope violation has occurred, and obtaining feedback information from the remote center that is fed back based on the scene information.

[0154] (Technical feature 8) Technical feature 8 is a processing program stored in a storage medium (10) for performing processing related to the operation of a host mobile body (2, 3a) capable of communicating with a remote center (8), and including instructions to be executed by a processor (12), the instructions including: monitoring a manually operated host mobile body for a safety envelope violation, which is a violation of a safety envelope that is set in accordance with an operating policy to ensure the safety of intended functions; generating scene information representing a scene of the safety envelope violation to be sent to the remote center when it is determined that a safety envelope violation has occurred; and obtaining feedback information from the remote center that is fed back based on the scene information.

[0155] (Technical feature 9) Technical feature 9 is a processing device (8a) including a processor (82) for performing processing related to the operation of a host mobile at a remote center (8) capable of communicating with the host mobile (2, 3a), wherein the processor is configured to acquire scene information representing a scene of a safety envelope violation, which is a violation of a safety envelope that sets the safety of an intended function in accordance with an operating policy, from a manually operated host mobile, and generate feedback information that provides feedback based on the scene information to be transmitted to the host mobile.

[0156] (Technical feature 10) In Technical Feature 9, acquiring scene information includes acquiring situation information as scene information representing a situation of a safety envelope violation.

[0157] (Technical feature 11) In Technical Feature 9 or 10, generating feedback information includes generating assistance information as feedback information representing the content of driving assistance determined based on the scene information.

[0158] (Technical feature 12) In any one of Technical Features 9 to 11, generating feedback information includes generating factor information as feedback information representing a factor of the safety envelope violation determined based on the scene information.

[0159] (Technical feature 13) In any one of Technical Features 9 to 12, generating feedback information includes generating score information as feedback information representing a driving score determined for the driver of the host vehicle based on the scene information.

[0160] (Technical feature 14) In any one of technical features 9 to 13, the remote center is capable of communicating with a service center (9) that provides services related to the host mobile object, and generating the feedback information includes generating public information to be made public to the service center based on at least one of the scene information and the feedback information.

[0161] (Technical feature 15) In any one of Technical Features 9 to 14, generating the feedback information includes generating the feedback information in response to acquiring the scene information.

[0162] (Technical feature 16) In any one of technical features 9 to 15, acquiring scene information includes storing the scene information acquired at multiple points in time in a storage medium (80) at the remote center, and generating feedback information includes generating the feedback information based on statistical analysis of the scene information at multiple points in time stored in the storage medium.

[0163] (Technical feature 17) In technical feature 16, generating feedback information includes deleting scene information at multiple points in time from a storage medium in response to generating or transmitting the feedback information.

[0164] (Technical feature 18) Technical feature 18 is a processing method executed by a processor (82) to perform processing related to the operation of a host mobile at a remote center (8) capable of communicating with the host mobile (2, 3a), and includes obtaining scene information from a manually operated host mobile representing a scene of a safety envelope violation, which is a violation of a safety envelope that sets the safety of intended functions in accordance with an operating policy, and generating feedback information that provides feedback based on the scene information to be transmitted to the host mobile.

[0165] (Technical feature 19) Technical feature 19 is a processing program stored in a storage medium (80) for performing processing related to the operation of a host mobile body at a remote center (8) capable of communicating with the host mobile body (2, 3a), and including instructions to be executed by a processor (82), the instructions including: acquiring scene information representing a scene of a safety envelope violation, which is a violation of a safety envelope that is set in accordance with an operating policy to ensure the safety of an intended function, from a manually operated host mobile body; and generating feedback information that provides feedback based on the scene information to be transmitted to the host mobile body.

[0166] (Technical feature 20) Technical feature 20 is a processing system (1) including a first processor (12) of the host mobile and a second processor (82) of the remote center for performing processing related to the operation of a host mobile (2, 3a) capable of communicating with a remote center (8), wherein the first processor is configured to monitor a safety envelope violation, which is a violation of a safety envelope that sets the safety of intended functions in accordance with an operating policy, in a manually operated host mobile, and, when it is determined that a safety envelope violation has occurred, generate scene information representing a scene of the safety envelope violation to be transmitted from the host mobile to the remote center, and the second processor is configured to generate feedback information that provides feedback based on the scene information to be transmitted from the remote center to the host mobile.

[0167] (Technical feature 21) Technical feature 21 is a processing method executed in cooperation between a first processor (12) of a host mobile body and a second processor (82) of a remote center (8) to perform processing related to the operation of a host mobile body (2, 3a) capable of communicating with a remote center (8), and includes monitoring a safety envelope violation, which is a violation of a safety envelope set in accordance with an operating policy to ensure the safety of intended functions, in a manually operated host mobile body, and when it is determined that a safety envelope violation has occurred, generating scene information representing a scene of the safety envelope violation to be transmitted from the host mobile body to the remote center, and generating feedback information that provides feedback based on the scene information to be transmitted from the remote center to the host mobile body.

[0168] (Technical feature 22) Technical feature 22 is a processing program stored in at least one of a first storage medium (10) of the host mobile body and a second storage medium (80) of the remote center in order to perform processing related to the operation of a host mobile body (2, 3a) capable of communicating with a remote center (8), and including instructions to be executed in cooperation by a first processor (12) of the host mobile body and a second processor (82) of the remote center, the instructions including: monitoring a safety envelope violation, which is a violation of a safety envelope set in accordance with an operating policy to ensure the safety of intended functions, in a manually operated host mobile body; generating scene information representing a scene of the safety envelope violation to be transmitted from the host mobile body to the remote center when it is determined that a safety envelope violation has occurred; and generating feedback information, which is feedback based on the scene information, to be transmitted from the remote center to the host mobile body.

[0169] (Technical feature 23) Technical feature 23 is a communication device (6a) configured to be able to communicate with a remote center (8) and including a processor (62) for performing processing related to the operation of a host vehicle (2, 3a) in cooperation with any one of the processing devices (1a) of technical features 1 to 6, wherein the processor is configured to transmit scene information to the remote center and receive feedback information from the remote center when the processing device determines that a safety envelope violation has occurred in a manually operated host vehicle.

[0170] (Technical feature 24) Technical feature 24 is a communication device (6a) configured to be able to communicate with a remote center (8) and including a processor (62) for performing processing related to the operation of a host vehicle (2, 3a), wherein the processor is configured to execute the following when a safety envelope violation, which is a violation of a safety envelope that sets the safety of an intended function in accordance with an operating policy, occurs in a manually operated host vehicle: send scene information representing a scene of the safety envelope violation to the remote center; and receive feedback information from the remote center that is fed back based on the scene information.

[0171] (Technical feature 25) Technical feature 25 is a processing method executed by a processor (62) in a communication device (6a) capable of communicating with a remote center (8) to perform processing related to the operation of a host vehicle (2, 3a), the method including, when a safety envelope violation, which is a violation of a safety envelope that sets the safety of intended functions in accordance with a driving policy, occurs in a manually driven host vehicle, transmitting scene information representing a scene of the safety envelope violation to the remote center, and receiving feedback information from the remote center that is fed back based on the scene information.

[0172] (Technical feature 26) Technical feature 26 is a processing program stored in a storage medium (60) for performing processing related to the operation of a host vehicle (2, 3a) in a communication device (6a) capable of communicating with a remote center (8), and including instructions to be executed by a processor (62), the instructions including: when a safety envelope violation, which is a violation of a safety envelope that sets the safety of intended functions in accordance with a driving policy, occurs in a manually driven host vehicle, transmitting scene information representing a scene of the safety envelope violation to the remote center; and receiving feedback information from the remote center that is fed back based on the scene information.

[0173] (Technical feature 27) Technical feature 27 is a processing system (1) including a processor (12, 62) for performing processing related to the operation of a host mobile body (2, 3a) capable of communicating with a remote center (8), wherein the processor is configured to monitor a manually operated host mobile body for a safety envelope violation, which is a violation of a safety envelope that sets the safety of intended functions in accordance with an operating policy, and when it is determined that a safety envelope violation has occurred, to transmit scene information representing a scene of the safety envelope violation to the remote center, and to receive feedback information from the remote center that is fed back based on the scene information.

[0174] (Technical feature 28) Technical feature 28 is a processing method executed by a processor (12, 62) to perform processing related to the operation of a host mobile body (2, 3a) capable of communicating with a remote center (8), and includes monitoring a safety envelope violation, which is a violation of a safety envelope that sets the safety of intended functions in accordance with an operating policy, in a manually operated host mobile body, and when it is determined that a safety envelope violation has occurred, transmitting scene information representing a scene of the safety envelope violation to the remote center, and receiving feedback information from the remote center that is fed back based on the scene information.

[0175] (Technical feature 29) Technical feature 29 is a processing program stored in a storage medium (10, 60) for performing processing related to the operation of a host mobile body (2, 3a) capable of communicating with a remote center (8), and including instructions to be executed by a processor (12, 62), the instructions including: monitoring a manually operated host mobile body for a safety envelope violation, which is a violation of a safety envelope that is set in accordance with an operating policy to ensure the safety of intended functions; transmitting scene information representing a scene of the safety envelope violation to the remote center when it is determined that a safety envelope violation has occurred; and receiving feedback information from the remote center that is fed back based on the scene information.

[0176] (Technical feature 30) Technical feature 30 is a processing device (1a) including a processor (12) for performing processing related to the operation of a host mobile body (2, 3a) capable of communicating with a target mobile body (3a, 2), wherein the processor is configured to monitor a safety envelope violation, which is a violation of a safety envelope that sets the safety of an intended function in accordance with an operating policy, in a manually operated host mobile body, and when it is determined that a safety envelope violation has occurred, generate scene information representing a scene of the safety envelope violation to be sent to the target mobile body, and obtain feedback information from the target mobile body that is fed back based on the scene information.

[0177] (Technical feature 31) Technical feature 31 is a processing method executed by a processor (12) to perform processing related to the operation of a host mobile body (2, 3a) capable of communicating with a target mobile body (3a, 2), and includes monitoring a safety envelope violation, which is a violation of a safety envelope set in accordance with an operating policy to ensure the safety of intended functions, in a manually operated host mobile body, generating scene information representing a scene of the safety envelope violation to be sent to the target mobile body when it is determined that a safety envelope violation has occurred, and obtaining feedback information from the target mobile body that is fed back based on the scene information.

[0178] (Technical feature 32) Technical feature 32 is a processing program stored in a storage medium (10) for performing processing related to the operation of a host mobile body (2, 3a) capable of communicating with a target mobile body (3a, 2), and including instructions to be executed by a processor (12), the instructions including: monitoring a manually operated host mobile body for a safety envelope violation, which is a violation of a safety envelope set in accordance with an operating policy to ensure the safety of intended functions; generating scene information representing a scene of the safety envelope violation to be sent to the target mobile body when it is determined that a safety envelope violation has occurred; and obtaining feedback information from the target mobile body that is fed back based on the scene information.

[0179] (Technical feature 33) Technical feature 33 is a communication device (6a) configured to communicate with a target moving body (3a, 2) and including a processor (62) to perform processing related to the operation of the host moving body (2, 3a) in cooperation with the processing device (1a) of technical feature 30, wherein the processor is configured to transmit scene information to the target moving body and receive feedback information from the target moving body when the processing device determines that a safety envelope violation has occurred in a manually operated host vehicle.

[0180] (Technical feature 34) Technical feature 34 is a communication device (6a) configured to be able to communicate with a target moving body (3a, 2) and including a processor (62) for performing processing related to the operation of a host moving body (2, 3a), wherein the processor is configured to execute the following when a safety envelope violation, which is a violation of a safety envelope that sets the safety of an intended function in accordance with an operating policy, occurs in a manually operated host vehicle: send scene information representing a scene of the safety envelope violation to the target moving body; and receive feedback information from the target moving body that is fed back based on the scene information.

[0181] (Technical feature 35) Technical feature 35 is a processing method executed by a processor (62) in a communication device (6a) capable of communicating with a target moving body (3a, 2) to perform processing related to the operation of a host moving body (2, 3a), and includes transmitting scene information representing a scene of a safety envelope violation to the target moving body when a safety envelope violation, which is a violation of a safety envelope that sets the safety of an intended function in accordance with an operating policy, occurs in a manually operated host vehicle, and receiving feedback information from the target moving body that is fed back based on the scene information.

[0182] (Technical feature 36) Technical feature 36 is a processing program stored in a storage medium (60) for performing processing related to the operation of a host vehicle (2, 3a) in a communication device (6a) capable of communicating with a target vehicle (3a, 2), and including instructions to be executed by a processor (62), the instructions including: when a safety envelope violation, which is a violation of a safety envelope that sets the safety of an intended function in accordance with a driving policy, occurs in a manually driven host vehicle, transmitting scene information representing a scene of the safety envelope violation to the target vehicle, and receiving feedback information from the target vehicle that is fed back based on the scene information.

[0183] (Technical feature 37) Technical feature 37 is a processing system (1) including a processor (12, 62) for performing processing related to the operation of a host mobile body (2, 3a) capable of communicating with a target mobile body (3a, 2), wherein the processor is configured to monitor a safety envelope violation, which is a violation of a safety envelope that sets the safety of intended functions in accordance with an operating policy, in a manually operated host mobile body, and when it is determined that a safety envelope violation has occurred, to send scene information representing a scene of the safety envelope violation to the target mobile body, and to receive feedback information from the target mobile body that is fed back based on the scene information.

[0184] (Technical feature 38) Technical feature 38 is a processing method executed by a processor (12, 62) to perform processing related to the operation of a host mobile body (2, 3a) capable of communicating with a target mobile body (3a, 2), and includes monitoring a safety envelope violation, which is a violation of a safety envelope that sets the safety of intended functions in accordance with an operating policy, in a manually operated host mobile body, and when it is determined that a safety envelope violation has occurred, sending scene information representing a scene of the safety envelope violation to the target mobile body, and receiving feedback information from the target mobile body that is fed back based on the scene information.

[0185] (Technical feature 39) Technical feature 39 is a processing program stored in a storage medium (10, 60) for performing processing related to the operation of a host mobile body (2, 3a) capable of communicating with a target mobile body (3a, 2), and including instructions to be executed by a processor (12, 62), the instructions including: monitoring a manually operated host mobile body for a safety envelope violation, which is a violation of a safety envelope that is set in accordance with an operating policy to ensure the safety of intended functions; transmitting scene information representing a scene of the safety envelope violation to the target mobile body when it is determined that a safety envelope violation has occurred; and receiving feedback information from the target mobile body that is fed back based on the scene information.

[0186] (Technical feature 40) Technical feature 40 is a processing device (1a) including a processor (12) for performing processing related to the operation of a target moving body in a host moving body (3a, 2) capable of communicating with the target moving body (2, 3a), wherein the processor is configured to acquire scene information representing a scene of a safety envelope violation, which is a violation of a safety envelope that sets the safety of an intended function in accordance with an operating policy, from a manually operated target moving body, and generate feedback information that provides feedback based on the scene information to be transmitted to the target moving body.

[0187] (Technical feature 41) Technical feature 41 is a processing method executed by a processor (12) in a host mobile body (3a, 2) capable of communicating with a target mobile body (2, 3a) to perform processing related to the operation of the target mobile body, and includes obtaining scene information representing a scene of a safety envelope violation, which is a violation of a safety envelope that sets the safety of the intended function in accordance with an operating policy, from a manually operated target mobile body, and generating feedback information that provides feedback based on the scene information to be transmitted to the target mobile body.

[0188] (Technical feature 42) Technical feature 42 is a processing program stored in a storage medium (10) for performing processing related to the operation of a target moving body (2, 3a) in a host moving body (3a, 2) capable of communicating with the target moving body, and including instructions to be executed by a processor (12), the instructions including: acquiring scene information representing a scene of a safety envelope violation, which is a violation of a safety envelope that is set in accordance with an operating policy to ensure the safety of intended functions, from a manually operated target moving body; and generating feedback information that provides feedback based on the scene information to be transmitted to the target moving body.

[0189] (Technical feature 43) Technical feature 43 is a communication device (6a) configured to be able to communicate with a target moving body (2, 3a) and including a processor (62) to perform processing related to the operation of the target moving body in the host moving body (3a, 2) in cooperation with the processing device (1a) of technical feature 40, wherein the processor is configured to receive scene information representing a scene of a safety envelope violation from a manually operated target moving body and to transmit feedback information to the target moving body.

[0190] (Technical feature 44) Technical feature 44 is a communication device (6a) configured to be able to communicate with a target moving body (2, 3a) and including a processor (62) for performing processing related to the operation of the target moving body in a host moving body (3a, 2), wherein the processor is configured to receive scene information from a manually operated target moving body representing a scene of a safety envelope violation, which is a violation of a safety envelope that sets the safety of the intended function in accordance with an operating policy, and to send feedback information to the target moving body that provides feedback based on the scene information.

[0191] (Technical feature 45) Technical feature 45 is a processing method executed by a processor (62) in a communication device (6a) of a host mobile body (3a, 2) capable of communicating with a target mobile body (2, 3a) to perform processing related to the operation of the target mobile body, and includes receiving scene information from a manually operated target mobile body representing a scene of a safety envelope violation, which is a violation of a safety envelope that sets the safety of intended functions in accordance with an operating policy, and transmitting feedback information to the target mobile body that provides feedback based on the scene information.

[0192] (Technical feature 46) Technical feature 46 is a processing program stored in a storage medium (60) for performing processing related to the operation of a target moving body in a communication device (6a) of a host moving body (3a, 2) capable of communicating with the target moving body (2, 3a), and including instructions to be executed by a processor (62), the instructions including receiving, from a manually operated target moving body, scene information representing a scene of a safety envelope violation, which is a violation of a safety envelope that is set in accordance with an operating policy to ensure the safety of intended functions, and transmitting, to the target moving body, feedback information that provides feedback based on the scene information.

[0193] (Technical feature 47) Technical feature 47 is a processing system (1) including a processor (12, 62) for performing processing related to the operation of a target moving body (2, 3a) in a host moving body (3a, 2) capable of communicating with the target moving body, wherein the processor is configured to receive scene information from a manually operated target moving body representing a scene of a safety envelope violation, which is a violation of a safety envelope that sets the safety of an intended function in accordance with an operating policy, and to send feedback information to the target moving body that provides feedback based on the scene information.

[0194] (Technical feature 48) Technical feature 48 is a processing method executed by a processor (12, 62) in a host vehicle (3, 2) capable of communicating with a target vehicle (2, 3a) to perform processing related to the operation of the target vehicle, and includes receiving scene information from a manually operated target vehicle representing a scene of a safety envelope violation, which is a violation of a safety envelope that sets the safety of intended functions in accordance with an operating policy, and transmitting feedback information to the target vehicle that provides feedback based on the scene information.

[0195] (Technical feature 49) Technical feature 49 is a processing program stored in a storage medium (10, 60) in a host vehicle (3, 2) capable of communicating with a target vehicle (2, 3a) to perform processing related to the operation of the target vehicle, and including instructions to be executed by a processor (12, 62), the instructions including receiving, from a manually operated target vehicle, scene information representing a scene of a safety envelope violation, which is a violation of a safety envelope that sets the safety of the intended function in accordance with an operating policy, and transmitting, to the target vehicle, feedback information that provides feedback based on the scene information.

Claims

1. A processing device (1a) including a processor (12) for performing processing related to the operation of a host vehicle (2, 3a) capable of communicating with a remote center (8), the host mobile is configured to process sensor data acquired from the sensors (50, 52) using a detection algorithm to detect an environment; The processor: monitoring the manually operated host vehicle for violations of restrictions or conditions to maintain operation within an acceptable level of risk; generating scene information representing a scene of the violation when the violation occurs, so as to be transmitted to the remote center; and obtaining, from the remote center, an update command or a parameter adjustment command for the detection algorithm as feedback information that is fed back based on the scene information.

2. the detection algorithm includes a fusion algorithm that integrates the sensor data acquired from the plurality of sensors to detect the environment; The processing device according to claim 1 , wherein the processor monitors the violation based on a result detected by an algorithm related to the fusion in the monitoring step.

3. the detection algorithm includes an object detection algorithm that detects an object in an external world of the host mobile device; The processing device according to claim 1 , wherein the processor monitors the violation based on a result detected by an algorithm related to object detection in the monitoring step.

4. The detection algorithm includes a lane detection algorithm that detects current and future lane paths along which the host mobile object will travel; The processing device according to claim 1 , wherein the processor monitors the violation based on a result detected by an algorithm related to the lane detection in the monitoring step.

5. the detection algorithms include a sign detection algorithm that detects signs associated with a path of the host vehicle; The processing device according to claim 1 , wherein the processor monitors the violation based on a result detected by an algorithm related to the sign detection in the monitoring step.

6. The detection algorithm includes a localization algorithm that estimates a self-state quantity including a self-position of the host mobile unit; The processing device according to claim 1 , wherein the processor monitors the violation based on a result detected by an algorithm related to the localization in the monitoring step.

7. The host mobile body is configured to be capable of performing automated driving, and is configured to plan a handover between automated driving and manual driving as an adjustment of the automated driving level of the host mobile body based on the results detected by the detection algorithm; The processing device according to claim 1 , wherein the processor, in the acquiring step, acquires from the remote center an update command or a parameter adjustment command for the detection algorithm used to adjust the autonomous driving level.

8. A processing device (8a) including a processor (82) for performing processing related to the driving operation of a host vehicle (2, 3a) at a remote center (8) capable of communicating with the host vehicle, the host mobile is configured to process sensor data acquired from the sensors (50, 52) using a detection algorithm to detect an environment; The processor: Obtaining scene information from the manually operated host vehicle that describes a scene of a violation of a restriction or condition for maintaining operation within an acceptable level of risk; and generating, as feedback information based on the scene information, an instruction to update or adjust parameters of the detection algorithm to be transmitted to the host mobile.

9. The processing device according to claim 8 , wherein the processor generates the feedback information by a factor analysis that determines a cause of the violation based on the scene information.

10. The processing device according to claim 8 , wherein the processor generates the detection algorithm update command or the parameter adjustment command so that the content of the command is made public as public information.

11. A processing program stored in a storage medium (10) for performing processing related to the driving operation of a host vehicle (2, 3a) capable of communicating with a remote center (8), the host mobile is configured to process sensor data acquired from the sensors (50, 52) using a detection algorithm to detect an environment; A processor (12) of the host mobile device, monitoring the manually operated host vehicle for violations of restrictions or conditions to maintain operation within an acceptable level of risk; generating scene information representing a scene of the violation when the violation occurs, so as to be transmitted to the remote center; and acquiring, from the remote center, an update command or a parameter adjustment command for the detection algorithm as feedback information that is fed back based on the scene information.

12. A processing program stored in a storage medium (80) for performing processing related to driving operations of a host vehicle (2, 3a) in a remote center (8) capable of communicating with the host vehicle (2, 3a), comprising: the host mobile is configured to process sensor data acquired from the sensors (50, 52) using a detection algorithm to detect an environment; A processor (82) at the remote center, Obtaining scene information from the manually operated host vehicle that describes a scene of a violation of a restriction or condition for maintaining operation within an acceptable level of risk; and generating an update command or a parameter adjustment command for the detection algorithm as feedback information to be fed back based on the scene information, so as to be transmitted to the host mobile unit.

Citation Information

Patent Citations

  • Vehicle travel support device

    JP2007219836A

  • Radio system

    JP2009094718A

  • Information processor, program, and information processing system

    JP2012233725A

  • Travel state propriety determination system, travel state property determination device, and server

    JP2017187856A

  • Travel support system and computer program

    JP2018173860A