Processing System

By defining performance and stable controllable ranges, the vehicle control system addresses stability concerns, ensuring stable control and enhancing occupant safety through proactive action adjustments.

JP2026041847APending Publication Date: 2026-03-10DENSO CORP
View PDF 1 Cites 0 Cited by

Patent Information

Authority / Receiving Office
JP · JP
Patent Type
Applications
Current Assignee / Owner
Filing Date
2025-12-01
Publication Date
2026-03-10

AI Technical Summary

Technical Problem

Existing vehicle control systems do not adequately consider the stability of the vehicle itself during potential collisions, leading to potential unease among occupants due to uncertainty in appropriate action.

Method used

A method and system that define performance limit and stable controllable ranges to determine control actions, allowing for stable control and switching actions before performance limits are reached, ensuring a high sense of security.

Benefits of technology

Ensures stable control of vehicles by defining performance and stable controllable ranges, providing a high sense of security by allowing control actions to be adjusted before limits are reached, thereby enhancing occupant safety.

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure 2026041847000001_ABST
    Figure 2026041847000001_ABST
Patent Text Reader

Abstract

A method and a driving system for realizing dynamic driving tasks with a high sense of security are provided. [Solution] A driving system of a host vehicle performs a dynamic motion task. A processor defines a performance limit range R2, which is a range bounded by the performance limit of the driving system, and a stable controllable range R1, within the performance limit range R2, in which stable control can be maintained, as ranges indicating the control state of the host vehicle. The processor determines the range, including determining whether the control state is within or outside the stable controllable range R1. The processor derives a control action for the host vehicle to switch control in accordance with this determination.
Need to check novelty before this filing date? Find Prior Art

Description

CROSS-REFERENCE TO RELATED APPLICATIONS

[0001] This application is based on Patent Application No. 2021-207405 filed in Japan on December 21, 2021, and the contents of the original application are incorporated by reference in their entirety. [Technical Field]

[0002] The disclosure of this specification relates to a technology for realizing a driving system for a moving object. [Background technology]

[0003] The technology disclosed in Patent Document 1 determines whether a risk value indicating the risk of collision between the vehicle and another object exceeds a predefined threshold. If the collision risk level is below the threshold, no braking force is applied. [Prior art documents] [Patent documents]

[0004] [Patent Document 1] U.S. Patent Application Publication No. 2021 / 0009121 Summary of the Invention

[0005] However, the technology of Patent Document 1 does not take into consideration the stability of the control of the vehicle itself. Therefore, if the control of the vehicle itself is unstable when the risk level of a collision increases, there is a concern that the occupants may feel uneasy in terms of whether appropriate action can be taken.

[0006] One of the objectives of the disclosure of this specification is to provide a method and a driving system for realizing a dynamic driving task with a high sense of security, and another objective is to provide a recording device for realizing a driving system with a high sense of security.

[0007] One aspect disclosed herein is a method executed by at least one processor for implementing a dynamic motion task in a driving system of a vehicle, the method comprising: defining a performance limit range, which is a range bounded by the performance limit of the driving system, and a stable controllable range, which is a range within the performance limit range that can maintain stable control, as ranges that indicate the control state of the moving body; determining the range, including determining whether the control state is within or outside the stable controllable range; Deriving a control action for the moving object so as to switch control according to the judgment; Estimating a situation in which the moving body is located; The determination of scope is made based on the situation, In defining the range of performance limits and the range of stable controllability, the range is set based on the difference between the situation estimated by the processor and the real world. Another disclosed aspect is a method executed by at least one processor for implementing a dynamic motion task in a driving system of a vehicle, the method comprising: defining a performance limit range, which is a range bounded by the performance limit of the driving system, and a stable controllable range, which is a range within the performance limit range that can maintain stable control, as ranges that indicate the control state of the moving body; determining the range, including determining whether the control state is within or outside the stable controllable range; Deriving a control action for the moving object so as to switch control according to the judgment; This includes setting an allowable time that is used as a condition for switching control actions and that allows a continuous state that is within the performance limit range and outside the stable controllable range. Another disclosed aspect is a method executed by at least one processor for implementing a dynamic motion task in a driving system of a vehicle, the method comprising: defining a performance limit range, which is a range bounded by the performance limit of the driving system, and a stable controllable range, which is a range within the performance limit range that can maintain stable control, as ranges that indicate the control state of the moving body; determining the range, including determining whether the control state is within or outside the stable controllable range; deriving a control action for the moving object so as to switch control in accordance with the judgment; determining the range includes determining ranges for a plurality of parameters; The method further includes setting, for each parameter, an allowable time for allowing a continuous state within the performance limit range and outside the stable control range, which is used as a condition for switching the control action; In setting, the permissible time set for one parameter among the plurality of parameters is dynamically changed according to the range determination for the other parameters. Another disclosed aspect is a method executed by at least one processor for implementing a dynamic motion task in a driving system of a vehicle, the method comprising: defining a performance limit range, which is a range bounded by the performance limit of the driving system, and a stable controllable range, which is a range within the performance limit range that can maintain stable control, as ranges that indicate the control state of the moving body; determining the range, including determining whether the control state is within or outside the stable controllable range; deriving a control action for the moving object so as to switch control in accordance with the judgment; The stable controllable range is defined according to the nominal performance of the operating system or its subsystems, The performance limit range is defined according to the robust performance of the operating system or subsystem. Another disclosed aspect is a method executed by at least one processor for implementing a dynamic motion task in a driving system of a vehicle, the method comprising: defining a performance limit range, which is a range bounded by the performance limit of the driving system, and a stable controllable range, which is a range within the performance limit range that can maintain stable control, as ranges that indicate the control state of the moving body; determining the range, including determining whether the control state is within or outside the stable controllable range; deriving a control action for the moving object so as to switch control in accordance with the judgment; If the operational design domain is the operating conditions under which the automated driving system is designed to function, then: In the definition, the performance limit range and the stable controllable range are defined so that the operation design domain of the operation system is within the performance limit range and outside the stable controllable range.

[0008] One aspect disclosed herein is a processing system including at least one processor for implementing a dynamic motion task for a moving object, the processing system including: The processor defining a performance limit range, which is a range bounded by the performance limit of the driving system of the moving body, and a stable controllable range, within the performance limit range, in which stable control can be maintained, as ranges indicating the control state of the moving body; determining the range, including determining whether the control state is within or outside the stable controllable range; Deriving a control action for the moving object so as to switch control according to the judgment; and estimating a situation in which the moving object is located; The determination of scope is made based on the situation, In defining the range of performance limits and the range of stable controllability, the range is set based on the difference between the situation estimated by the processor and the real world. Another disclosed aspect is a processing system including at least one processor for realizing a dynamic movement task of a moving object, the processing system including: The processor defining a performance limit range, which is a range bounded by the performance limit of the driving system of the moving body, and a stable controllable range, within the performance limit range, in which stable control can be maintained, as ranges indicating the control state of the moving body; determining the range, including determining whether the control state is within or outside the stable controllable range; Deriving a control action for the moving object so as to switch control according to the judgment; and estimating a situation in which the moving object is located; The determination of scope is made based on the situation, In defining the range of performance limits and the range of stable controllability, the range is set based on the difference between the situation estimated by the processor and the real world. Another disclosed aspect is a processing system including at least one processor for realizing a dynamic movement task of a moving object, the processing system including: The processor defining a performance limit range, which is a range bounded by the performance limit of the driving system of the moving body, and a stable controllable range, within the performance limit range, in which stable control can be maintained, as ranges indicating the control state of the moving body; determining the range, including determining whether the control state is within or outside the stable controllable range; Deriving a control action for the moving object so as to switch control according to the judgment; and setting an allowable time for allowing a state to continue within the performance limit range and outside the stable controllable range, which is used as a condition for switching a control action. Another disclosed aspect is a processing system including at least one processor for realizing a dynamic movement task of a moving object, the processing system including: The processor defining a performance limit range, which is a range bounded by the performance limit of the driving system of the moving body, and a stable controllable range, within the performance limit range, in which stable control can be maintained, as ranges indicating the control state of the moving body; determining the range, including determining whether the control state is within or outside the stable controllable range; deriving a control action for the moving object so as to switch control according to the judgment; determining the range includes determining ranges for a plurality of parameters; The method further includes setting, for each parameter, an allowable time for allowing a continuous state within the performance limit range and outside the stable control range, which is used as a condition for switching the control action; In the setting, the processing system dynamically changes the allowable time set for one parameter among the plurality of parameters in accordance with range determinations for the other parameters. Another disclosed aspect is a processing system including at least one processor for realizing a dynamic movement task of a moving object, the processing system including: The processor defining a performance limit range, which is a range bounded by the performance limit of the driving system of the moving body, and a stable controllable range, within the performance limit range, in which stable control can be maintained, as ranges indicating the control state of the moving body; determining the range, including determining whether the control state is within or outside the stable controllable range; deriving a control action for the moving object so as to switch control according to the judgment; The stable controllable range is defined according to the nominal performance of the operating system or its subsystems, The performance limit range is defined according to the robust performance of the operating system or subsystem, processing system. Another disclosed aspect is a processing system including at least one processor for realizing a dynamic movement task of a moving object, the processing system including: The processor defining a performance limit range, which is a range bounded by the performance limit of the driving system of the moving body, and a stable controllable range, within the performance limit range, in which stable control can be maintained, as ranges indicating the control state of the moving body; determining the range, including determining whether the control state is within or outside the stable controllable range; deriving a control action for the moving object so as to switch control according to the judgment; If the operational design domain is the operating conditions under which the automated driving system is designed to function, then: A processing system that defines the performance limit range and the stable controllable range so that the operation design region of the operation system is within the performance limit range and outside the stable controllable range.

[0009] According to these aspects, a control action for the moving object is derived based on a determination of whether the control state is within a stable controllable range. This stable controllable range is associated with a performance limit range and defined as a range within the performance limit range in which stable control can be maintained. In other words, the control action is derived from the perspective of whether the driving system can maintain stable control taking into account the performance limit. Since it is also possible to switch the control action before the performance limit is reached, a high sense of security can be given to the occupants.

[0010] One aspect disclosed herein is a recording device for recording a state of a driving system of a vehicle, the recording device comprising: As a range indicating the control state of a moving object, a performance limit range, which is a range bounded by the performance limit of the driving system, and a stable controllable range, which is within the performance limit range and in which stable control can be maintained, are defined as follows: The driving system performed MRM (minimal risk maneuver), This information is used to determine whether to execute MRM, and indicates the range of the control state determined based on the situation estimated by the operation system.

[0011] According to these aspects, information indicating the range of the control state is recorded. This information is determined based on the situation estimated by the operation system, so that the results of estimation or determination by the operation system when MRM is executed can be easily verified after the fact.

[0012] It should be noted that the reference numerals in parentheses in the claims are intended to exemplify the correspondence with the parts of the embodiments described below, and are not intended to limit the technical scope. [Brief explanation of the drawings]

[0013] [Figure 1] FIG. 2 is a block diagram showing a schematic configuration of the driving system. [Figure 2] FIG. 1 is a block diagram showing the configuration of the technology level of the driving system. [Figure 3] FIG. 2 is a block diagram showing the functional level configuration of the driving system. [Figure 4] FIG. 2 illustrates a control state space of a vehicle. [Figure 5] FIG. 1 is a block diagram illustrating a causal loop of a driving system. [Figure 6] FIG. 10 is a diagram illustrating an inner loop. [Figure 7] FIG. 10 is a diagram illustrating an outer loop. [Figure 8] FIG. 10 is a diagram showing an area where safety cannot be maintained based on the concept of the first evaluation method. [Figure 9] 10 is a flowchart illustrating a first evaluation method. [Figure 10] FIG. 10 is a diagram showing an area where safety cannot be maintained based on the concept of the second evaluation method. [Figure 11] 10 is a flowchart illustrating a second evaluation method. [Figure 12] FIG. 10 is a diagram showing an area where safety cannot be maintained based on the concept of the third evaluation method. [Figure 13] 10 is a flowchart illustrating a third evaluation method. [Figure 14] 10 is a table showing the relationship between control states and control actions. [Figure 15] FIG. 10 is a diagram illustrating the relationship between the relative position of an obstacle and the controllable range. [Figure 16] 10 is a flowchart illustrating switching of a control action. [Figure 17] 10 is a flowchart illustrating switching of a control action. [Figure 18] 10 is a flowchart illustrating switching of a control action. [Figure 19] FIG. 2 is a block diagram illustrating a recognition control subsystem. [Figure 20] 1 is a flowchart illustrating a method for designing an operation system. [Figure 21] 10 is a flowchart illustrating a determination of a performance limit range. [Figure 22] FIG. 2 is a block diagram showing the functional level configuration of the driving system. [Figure 23] FIG. 1 is a block diagram showing the configuration of the technology level of the driving system. DETAILED DESCRIPTION OF THE INVENTION

[0014] Hereinafter, several embodiments will be described with reference to the drawings. Note that corresponding components in each embodiment are given the same reference numerals, and redundant description may be omitted. When only a portion of the configuration is described in each embodiment, the configuration of another embodiment previously described may be applied to the remaining portion of the configuration. Furthermore, in addition to the combinations of configurations explicitly stated in the description of each embodiment, configurations of several embodiments may be partially combined together even if not explicitly stated, as long as there is no particular problem with the combination.

[0015] (First embodiment) The driving system 2 of the first embodiment shown in FIG. 1 realizes functions related to driving a moving object. Part or all of the driving system 2 is mounted on the moving object. The moving object that the driving system 2 processes is a vehicle. This vehicle can be referred to as the subject vehicle 1, which corresponds to the host moving object. The subject vehicle 1 may be configured to be able to communicate with other vehicles directly or indirectly via a communication infrastructure. The other vehicles correspond to target moving objects.

[0016] The vehicle 1 is a road user capable of performing automated driving, such as a car or a truck. Driving is classified into levels according to the extent to which the driver performs all dynamic driving tasks (DDTs). The automated driving levels are, for example, based on the SAE It is specified in J3016. At levels 0 to 2, the driver performs some or all of the DDT. Levels 0 to 2 may be classified as so-called manual driving. Level 0 indicates that driving is not automated. Level 1 indicates that the driver is assisted by a driving system 2. Level 2 indicates that driving is partially automated.

[0017] At levels 3 and above, the driving system 2 performs all of the DDT while engaged. Levels 3 to 5 may be classified as so-called automated driving. A driving system 2 capable of driving at levels 3 and above may be called an automated driving system. Level 3 indicates that driving is conditionally automated. Level 4 indicates that driving is highly automated. Level 5 indicates that driving is fully automated.

[0018] Furthermore, a driving system 2 that is unable to perform driving at level 3 or above but can perform driving at least at level 1 or 2 may be referred to as a driving assistance system. In the following, unless there are particular circumstances to specify the maximum achievable level of autonomous driving, the autonomous driving system or driving assistance system will be referred to simply as driving system 2 and the explanation will continue.

[0019] <Sense-Plan-Act Model> The architecture of the driving system 2 is selected so as to enable an efficient SOTIF (safety of the intended functionality) process. For example, the architecture of the driving system 2 may be configured based on the sense-plan-act model. The sense-plan-act model includes a sense element, a plan element, and an act element as main system elements. The sense element, plan element, and act element interact with each other. Here, sense may be replaced with perception, plan with judgment, and act with control, respectively, and the following description will mainly use the terms perception, judgment, and control.

[0020] As shown in Fig. 1, in such a driving system 2, at the vehicle level, vehicle level functions 3 are implemented based on a Vehicle Level Safety Strategy (VLSS). At the function level (in other words, from a functional perspective), a recognition function, a decision-making function, and a control function are implemented. At the technical level (in other words, from a technical perspective), multiple sensors 40 corresponding to the recognition function, a processing system 50 corresponding to the decision-making function, and multiple motion actuators 60 corresponding to the control function are implemented.

[0021] In detail, a recognition unit 10, which is a functional block that realizes a recognition function, may be constructed in the driving system 2, mainly consisting of multiple sensors 40, a processing system that processes detection information from the multiple sensors 40, and a processing system that generates an environmental model based on information from the multiple sensors 40. A judgment unit 20, which is a functional block that realizes a judgment function, may be constructed in the driving system 2, mainly consisting of the processing system. A control unit 30, which is a functional block that realizes a control function, may be constructed in the driving system 2, mainly consisting of multiple movement actuators 60 and at least one processing system that outputs operation signals for the multiple movement actuators 60.

[0022] Here, the recognition unit 10 may be realized in the form of a recognition system 10a as a subsystem provided so as to be distinguishable from the determination unit 20 and the control unit 30. The determination unit 20 may be realized in the form of a determination system 20a as a subsystem provided so as to be distinguishable from the recognition unit 10 and the control unit 30. The control unit 30 may be realized in the form of a control system 30a as a subsystem provided so as to be distinguishable from the recognition unit 10 and the determination unit 20. The recognition system 10a, the determination system 20a, and the control system 30a may constitute components independent of each other.

[0023] Furthermore, the vehicle 1 may be equipped with a plurality of HMI (Human Machine Interface) devices 70. A portion of the plurality of HMI devices 70 that realizes an operation input function by an occupant may be a part of the recognition unit 10. A portion of the plurality of HMI devices 70 that realizes an information presentation function may be a part of the control unit 30. On the other hand, the function realized by the HMI device 70 may be positioned as a function independent of the recognition function, the judgment function, and the control function.

[0024] The recognition unit 10 is responsible for recognition functions, including localization of road users such as the vehicle 1 and other vehicles. The recognition unit 10 detects the external environment EE of the vehicle 1, the internal environment, the vehicle state, and the state of the driving system 2. The recognition unit 10 combines the detected information to generate an environmental model. The judgment unit 20 applies the objective and driving policy to the environmental model generated by the recognition unit 10 to derive a control action. The control unit 30 executes the control action derived by the recognition element.

[0025] <Technical level system configuration> An example of a detailed configuration of the driving system 2 at a technical level will be described with reference to FIG. 2. The technical-level configuration may refer to a physical architecture. The driving system 2 includes a plurality of sensors 40, a plurality of motion actuators 60, a plurality of HMI devices 70, and at least one processing system 50. These components can communicate with each other via one or both of wireless and wired connections. These components may also be able to communicate with each other via an in-vehicle network such as CAN (registered trademark).

[0026] The multiple sensors 40 include one or more external environment sensors 41. The multiple sensors 40 may include at least one of one or more internal environment sensors 42, one or more communication systems 43, and a map database (DB) 44. When the sensor 40 is interpreted in a narrow sense to refer to the external environment sensor 41, the internal environment sensor 42, the communication system 43, and the map database 44 may be positioned as components separate from the sensor 40 that corresponds to the recognition function at the technology level.

[0027] The external environment sensor 41 may detect targets present in the external environment EE of the host vehicle 1. Target detection type external environment sensors 41 include, for example, a camera, a LiDAR (Light Detection and Ranging / Laser imaging Detection and Ranging) laser radar, a millimeter wave radar, an ultrasonic sonar, etc. Typically, a combination of multiple types of external environment sensors 41 may be implemented to monitor the front, sides, and rear directions of the host vehicle 1.

[0028] As an example of the external environment sensor 41, the vehicle 1 may be equipped with multiple cameras (e.g., 11 cameras) configured to monitor the front, front-side, side, rear-side, and rear directions of the vehicle 1.

[0029] As another example of installation, the vehicle 1 may be equipped with a plurality of cameras (e.g., four cameras) configured to monitor the front, sides, and rear of the vehicle 1, a plurality of millimeter-wave radars (e.g., five millimeter-wave radars) configured to monitor the front, front-side, sides, and rear of the vehicle 1, and a LiDAR configured to monitor the front of the vehicle 1.

[0030] Furthermore, the external environment sensor 41 may detect the atmospheric conditions and weather conditions in the external environment EE of the vehicle 1. The condition detection type external environment sensor 41 is, for example, an outside air temperature sensor, a temperature sensor, a raindrop sensor, or the like.

[0031] The internal environment sensor 42 may detect a specific physical quantity related to vehicle motion (hereinafter referred to as motion physical quantity) in the internal environment of the host vehicle 1. The internal environment sensor 42 of the motion physical quantity detection type is, for example, a speed sensor, an acceleration sensor, a gyro sensor, etc. The internal environment sensor 42 may detect the state of an occupant in the internal environment of the host vehicle 1. The internal environment sensor 42 of the occupant detection type is, for example, an actuator sensor, a driver status monitor, a biological sensor, a seating sensor, an in-vehicle equipment sensor, etc. Here, the actuator sensor in particular is, for example, an accelerator sensor, a brake sensor, a steering sensor, etc., which detects the state of operation of the occupant with respect to the motion actuator 60 related to the motion control of the host vehicle 1.

[0032] The communication system 43 obtains communication data usable in the driving system 2 by wireless communication. The communication system 43 may receive positioning signals from artificial satellites of a global navigation satellite system (GNSS) present in the external environment EE of the vehicle 1. The positioning type communication device in the communication system 43 is, for example, a GNSS receiver.

[0033] The communication system 43 may transmit and receive communication signals to and from a V2X system present in the external environment EE of the host vehicle 1. Examples of V2X type communication devices in the communication system 43 include a dedicated short range communications (DSRC) communication device, a cellular V2X (C-V2X) communication device, etc. Examples of communication with a V2X system present in the external environment EE of the host vehicle 1 include communication with a communication system of another vehicle (V2V), communication with infrastructure equipment such as a communication device installed in a traffic light (V2I), communication with a mobile terminal of a pedestrian (V2P), and communication with a network such as a cloud server (V2N).

[0034] Furthermore, the communication system 43 may transmit and receive communication signals to and from a mobile terminal such as a smartphone present inside the vehicle 1. Examples of terminal communication type communication devices in the communication system 43 include Bluetooth (registered trademark) devices, Wi-Fi (registered trademark) devices, and infrared communication devices.

[0035] The map DB 44 is a database that stores map data that can be used by the driving system 2. The map DB 44 includes at least one type of non-transitory tangible storage medium, such as a semiconductor memory, a magnetic medium, or an optical medium. The map DB 44 may include a database of a navigation unit that navigates the driving route to the destination of the host vehicle 1. The map DB 44 may include a database of PD maps generated using probe data (PD) collected from each vehicle. The map DB 44 may include a database of high-precision maps with a high level of accuracy that are primarily used in autonomous driving systems. The map DB 44 may also include a database of parking lot maps that include detailed parking lot information, such as parking space information, that is used in autonomous parking or parking assistance applications.

[0036] The map DB 44 suitable for the driving system 2 acquires and stores the latest map data, for example, by communicating with a map server via a V2X communication system 43. The map data is converted into two-dimensional or three-dimensional data representing the external environment EE of the vehicle 1. The map data may include road data representing at least one of the following: position coordinates, shape, road surface condition, and standard running route of a road structure. The map data may also include marking data representing at least one of the following: position coordinates and shape of road signs, road markings, and lane markings attached to a road. The marking data included in the map data may represent landmarks such as traffic signs, arrow markings, lane markings, stop lines, directional signs, landmark beacons, business signs, and changes in road line patterns. The map data may also include structure data representing at least one of the following: position coordinates and shape of buildings and traffic lights facing the road. The marking data included in the map data may represent landmarks such as street lights, road edges, reflectors, and poles.

[0037] The motion actuator 60 can control vehicle motion based on an input control signal. The drive-type motion actuator 60 is, for example, a power train including at least one of an internal combustion engine, a drive motor, etc. The braking-type motion actuator 60 is, for example, a brake actuator. The steering-type motion actuator 60 is, for example, a steering.

[0038] The HMI device 70 may be an operation input device that can input operations by the driver in order to transmit the will or intention of the occupants, including the driver of the host vehicle 1, to the driving system 2. Examples of the operation input type HMI device 70 include an accelerator pedal, a brake pedal, a shift lever, a steering wheel, a turn signal lever, a mechanical switch, and a touch panel of a navigation unit. Of these, the accelerator pedal controls the powertrain as a motion actuator 60. The brake pedal controls a brake actuator as a motion actuator 60. The steering wheel controls a steering actuator as a motion actuator 60.

[0039] The HMI device 70 may be an information presentation device that presents information such as visual information, auditory information, and cutaneous information to occupants including the driver of the vehicle 1. Examples of the visual information presentation type HMI device 70 include a combination meter, a navigation unit, a CID (center information display), a HUD (head-up display), and an illumination unit. Examples of the auditory information presentation type HMI device 70 include a speaker and a buzzer. Examples of the cutaneous information presentation type HMI device 70 include a steering wheel vibration unit, a driver's seat vibration unit, a steering wheel reaction force unit, an accelerator pedal reaction force unit, a brake pedal reaction force unit, an air conditioning unit, and the like.

[0040] Furthermore, the HMI device 70 may realize an HMI function linked to a mobile terminal such as a smartphone by communicating with the terminal via the communication system 43. For example, the HMI device 70 may present information acquired from the smartphone to passengers including the driver. Also, for example, an operation input to a smartphone may be used as an alternative means for an operation input to the HMI device 70.

[0041] At least one processing system 50 is provided. For example, the processing system 50 may be an integrated processing system that integrally executes processing related to the recognition function, processing related to the judgment function, and processing related to the control function. In this case, the integrated processing system 50 may further execute processing related to the HMI device 70, or a processing system dedicated to the HMI may be provided separately. For example, the processing system dedicated to the HMI may be an integrated cockpit system that integrally executes processing related to each HMI device.

[0042] For example, the processing system 50 may be configured to have at least one processing unit corresponding to processing related to the recognition function, at least one processing unit corresponding to processing related to the judgment function, and at least one processing unit corresponding to processing related to the control function.

[0043] The processing system 50 has a communication interface to the outside and is connected to at least one type of element related to processing by the processing system 50, such as the sensor 40, the motion actuator 60, and the HMI device 70, via at least one type of interface, such as a LAN (Local Area Network), a wire harness, an internal bus, and a wireless communication circuit.

[0044] The processing system 50 includes at least one dedicated computer 51. The processing system 50 may combine multiple dedicated computers 51 to realize functions such as recognition functions, judgment functions, and control functions.

[0045] For example, the dedicated computer 51 constituting the processing system 50 may be an integration ECU that integrates the driving functions of the host vehicle 1. The dedicated computer 51 constituting the processing system 50 may be a determination ECU that determines the DDT. The dedicated computer 51 constituting the processing system 50 may be a monitoring ECU that monitors the driving of the vehicle. The dedicated computer 51 constituting the processing system 50 may be an evaluation ECU that evaluates the driving of the vehicle. The dedicated computer 51 constituting the processing system 50 may be a navigation ECU that navigates the driving route of the host vehicle 1.

[0046] Furthermore, the dedicated computer 51 constituting the processing system 50 may be a locator ECU that estimates the position of the host vehicle 1. The dedicated computer 51 constituting the processing system 50 may be an image processing ECU that processes image data detected by the external environment sensor 41. The dedicated computer 51 constituting the processing system 50 may be an actuator ECU that controls the motion actuator 60 of the host vehicle 1. The dedicated computer 51 constituting the processing system 50 may be an HCU (HMI Control Unit) that comprehensively controls the HMI device 70. The dedicated computer 51 constituting the processing system 50 may be at least one external computer that constitutes an external center or mobile terminal that can communicate via the communication system 43, for example.

[0047] The dedicated computer 51 constituting the processing system 50 has at least one memory 51a and one processor 51b. The memory 51a may be at least one type of non-transient tangible storage medium, such as a semiconductor memory, a magnetic medium, or an optical medium, that non-temporarily stores programs and data that can be read by the computer 51. The memory 51a may further be a rewritable volatile storage medium, such as a random access memory (RAM). The processor 51b includes at least one type of core, such as a central processing unit (CPU), a graphics processing unit (GPU), or a reduced instruction set computer (RISC)-CPU.

[0048] The dedicated computer 51 constituting the processing system 50 may be an SoC (System on a Chip) that integrates memory, a processor, and an interface on a single chip, or may have an SoC as a component of the dedicated computer.

[0049] Furthermore, the processing system 50 may include at least one database for executing the dynamic driving task. The database may include at least one type of non-transitory tangible storage medium, such as a semiconductor memory, a magnetic medium, or an optical medium. The database may be a scenario DB 53, which is a database of scenario structures described below.

[0050] The processing system 50 may also include at least one recording device 55 that records at least one of recognition information, judgment information, and control information of the driving system 2. The recording device 55 may include at least one memory 55a and an interface 55b for writing data to the memory 55a. The memory 55a may be at least one type of non-transitory tangible storage medium, such as a semiconductor memory, a magnetic medium, or an optical medium.

[0051] At least one of the memories 55a may be mounted on the board in a form that is not easily detachable or replaceable, and in this form, for example, an eMMC (embedded multi media card) using a flash memory may be used. At least one of the memories 55a may be detachable and replaceable from the recording device 55, and in this form, for example, an SD card may be used.

[0052] The recording device 55 may have a function of selecting information to be recorded from the recognition information, judgment information, and control information. In this case, the recording device 55 may have a dedicated computer 55c. A processor provided in the recording device 55 may temporarily store information in RAM or the like. The processor may select information to be recorded from the temporarily stored information and save the selected information in the memory 51a.

[0053] The recording device 55 may access the memory 55a and perform recording in accordance with a data write command from the recognition system 10a, the determination system 20a, or the control system 30a. The recording device 55 may determine information flowing through the in-vehicle network, and access the memory 55a and perform recording based on the judgment of a processor provided in the recording device 55. Recording into the recording device 55 may be performed after various data to be recorded are generated in a predetermined format.

[0054] <Functional level system configuration> Next, an example of a detailed configuration of the driving system 2 at the functional level will be described with reference to Fig. 3. The functional level configuration may refer to a logical architecture. The recognition unit 10 includes an external recognition unit 11, a self-location recognition unit 12, a fusion unit 13, and an internal recognition unit 14 as sub-blocks that further classify the recognition functions.

[0055] The external recognition unit 11 individually processes the detection data detected by each external environment sensor 41, and realizes the function of recognizing objects such as targets and other road users. The detection data may be detection data provided by, for example, millimeter wave radar, sonar, LiDAR, etc. The external recognition unit 11 may generate relative position data including the direction, size, and distance of the object relative to the vehicle 1 from the raw data detected by the external environment data.

[0056] Furthermore, the detection data may be image data provided by, for example, a camera, LiDAR, or the like. The external recognition unit 11 processes the image data and extracts objects reflected within the angle of view of the image. The object extraction may include estimating the direction, size, and distance of the object relative to the vehicle 1. The object extraction may also include classifying the object using, for example, semantic segmentation.

[0057] The self-location recognition unit 12 performs localization of the vehicle 1. The self-location recognition unit 12 acquires global position data of the vehicle 1 from a communication system 43 (e.g., a GNSS receiver). In addition, the self-location recognition unit 12 may acquire at least one of the position information of targets extracted by the external recognition unit 11 and the position information of targets extracted by the fusion unit 13. The self-location recognition unit 12 also acquires map information from a map DB 44. The self-location recognition unit 12 integrates this information to estimate the position of the vehicle 1 on the map.

[0058] The fusion unit 13 fuses the external recognition information of each external environment sensor 41 processed by the external recognition unit 11, the localization information processed by the self-position recognition unit 12, and the V2X information acquired by V2X.

[0059] The fusion unit 13 fuses object information of other road users and the like individually recognized by each external environment sensor 41, and identifies the type and relative position of the object around the vehicle 1. The fusion unit 13 fuses road target information individually recognized by each external environment sensor 41, and identifies the static structure of the road around the vehicle 1. The static structure of the road includes, for example, curve curvature, number of lanes, free space, and the like.

[0060] Next, the fusion unit 13 fuses the types of objects around the vehicle 1, their relative positions, the static structure of the road, the localization information, and the V2X information to generate an environment model. The environment model can be provided to the determination unit 20. The environment model may be an environment model specialized for modeling the external environment EE.

[0061] The environmental model may be an integrated environmental model that is realized by expanding the acquired information and that combines information such as the internal environment, the vehicle state, and the state of the driving system 2. For example, the fusion unit 13 may acquire traffic rules such as the Road Traffic Act and reflect them in the environmental model.

[0062] The internal recognition unit 14 processes the detection data detected by each internal environment sensor 42 and realizes the function of recognizing the vehicle state. The vehicle state may include the state of the physical quantities of motion of the vehicle 1 detected by a speed sensor, an acceleration sensor, a gyro sensor, etc. The vehicle state may also include at least one of the states of the occupants including the driver, the operation state of the driver with respect to the motion actuator 60, and the switch state of the HMI device 70.

[0063] The determination unit 20 includes an environment determination unit 21, an operation planning unit 22, and a mode management unit 23 as sub-blocks that further classify the determination functions.

[0064] The environment determination unit 21 acquires the environment model generated by the fusion unit 13 and the vehicle state recognized by the internal recognition unit 14, and makes a determination about the environment based on these. Specifically, the environment determination unit 21 may interpret the environment model and estimate the current situation of the host vehicle 1. The situation here may be an operational situation. The environment determination unit 21 may interpret the environment model and predict the trajectories of objects such as other road users. The environment determination unit 21 may also interpret the environment model and predict potential hazards.

[0065] The environment determination unit 21 may also interpret the environment model and make a determination regarding the scenario in which the host vehicle 1 is currently located. The determination regarding the scenario may be to select at least one scenario in which the host vehicle 1 is currently located from a catalog of scenarios constructed in the scenario DB 53. The determination regarding the scenario may be a determination of a scenario category, which will be described later.

[0066] Furthermore, the environment judgment unit 21 may estimate the driver's intention based on at least one of the predicted object trajectory, the predicted potential hazard, and the judgment regarding the scenario, and the vehicle state provided by the internal recognition unit 14.

[0067] The driving planning unit 22 plans the driving of the vehicle 1 based on at least one of the estimated information of the position of the vehicle 1 on a map by the self-position recognition unit 12, the judgment information and driver intention estimation information by the environment judgment unit 21, and the functional constraint information by the mode management unit 23.

[0068] The driving planner 22 realizes a route planning function, a behavior planning function, and a trajectory planning function. The route planning function is a function that plans at least one of a route to a destination and a mid-distance lane plan based on estimated information of the position of the vehicle 1 on a map. The route planning function may further include a function that determines at least one of a lane change request and a deceleration request based on the mid-distance lane plan. Here, the route planning function may be a mission / route planning function in a strategic function, and may output a mission plan and a route plan.

[0069] The behavior planning function is a function that plans the behavior of the host vehicle 1 based on at least one of the route to the destination planned by the route planning function, the mid-distance lane plan, the lane change request and the deceleration request, the judgment information and the driver's intention estimation information by the environment judgment unit 21, and the function constraint information by the mode management unit 23. The behavior planning function may include a function that generates conditions related to the state transition of the host vehicle 1. The conditions related to the state transition of the host vehicle 1 may correspond to triggering conditions. The behavior planning function may include a function that determines the state transition of the application that realizes the DDT and further the state transition of the driving behavior based on the conditions. The behavior planning function may include a function that determines longitudinal constraints on the path of the host vehicle 1 and lateral constraints on the path of the host vehicle 1 based on the state transition information. The behavior planning function may be a tactical behavior plan in the DDT function and may output a tactical behavior.

[0070] The trajectory planning function is a function that plans a driving trajectory of the host vehicle 1 based on the judgment information by the environment judgment unit 21, longitudinal constraints on the path of the host vehicle 1, and lateral constraints on the path of the host vehicle 1. The trajectory planning function may include a function that generates a path plan. The path plan may include a speed plan, or the speed plan may be generated as a plan independent of the path plan. The trajectory planning function may include a function that generates multiple path plans and selects an optimal path plan from the multiple path plans, or a function that switches between path plans. The trajectory planning function may further include a function that generates backup data of the generated path plan. The trajectory planning function may be a trajectory planning function in the DDT function, and may output a trajectory plan.

[0071] The mode management unit 23 monitors the driving system 2 and sets constraints on driving-related functions. The mode management unit 23 may monitor the states of subsystems related to the driving system 2 and determine whether the system 2 is malfunctioning. The mode management unit 23 may determine a mode based on the driver's intention, based on driver's intention estimation information generated by the internal recognition unit 14. The mode management unit 23 may set constraints on driving-related functions based on at least one of the malfunction determination result of the system 2, the mode determination result, the vehicle state determined by the internal recognition unit 14, the sensor abnormality (or sensor failure) signal output from the sensor 40, application state transition information and trajectory plan determined by the driving planner 22, etc.

[0072] Furthermore, the mode management unit 23 may have a comprehensive function of determining, in addition to constraints on driving functions, longitudinal constraints on the path of the vehicle 1 and lateral constraints on the path of the vehicle 1. In this case, the driving planner 22 plans behavior and trajectories in accordance with the constraints determined by the mode management unit 23.

[0073] The control unit 30 includes a motion control unit 31 and an HMI output unit 71 as sub-blocks that further classify the control functions. The motion control unit 31 controls the motion of the host vehicle 1 based on the trajectory plan (e.g., a path plan and a speed plan) acquired from the driving plan unit 22. Specifically, the motion control unit 31 generates accelerator request information, shift request information, brake request information, and steering request information according to the trajectory plan, and outputs them to the motion actuator 60.

[0074] Here, the motion control unit 31 can directly obtain the vehicle state recognized by the recognition unit 10 (particularly the internal recognition unit 14), such as at least one of the current speed, acceleration, and yaw rate of the host vehicle 1, from the recognition unit 10 and reflect this in the motion control of the host vehicle 1.

[0075] The HMI output unit 71 outputs information related to the HMI based on at least one of the judgment information and driver's intention estimation information from the environment judgment unit 21, the application state transition information and trajectory plan from the driving planner 22, and function constraint information from the mode manager 23. The HMI output unit 71 may manage vehicle interactions. The HMI output unit 71 may generate a notification request based on the management status of the vehicle interactions and control the information notification function of the HMI device 70. Furthermore, the HMI output unit 71 may generate control requests for wipers, a sensor washing device, headlights, and an air conditioner based on the management status of the vehicle interactions and control these devices.

[0076] <Scenario> A scenario-based approach may be adopted to perform or evaluate a dynamic driving task. As described above, the processes required to perform a dynamic driving task in an automated driving system are classified into disturbances in the recognition element, disturbances in the judgment element, and disturbances in the control element, which are based on different physical principles. The root causes that affect the processing results in each element are structured as a scenario.

[0077] Disturbances in the recognition element are called perception disturbances. Perception disturbances are disturbances that indicate a state in which the recognition unit 10 is unable to correctly recognize danger due to internal or external factors of the sensor 40 and the host vehicle 1. Internal factors include instability related to variations in the installation or manufacturing of sensors such as the external environment sensor 41, tilting of the vehicle due to uneven loads that change the direction of the sensor, and shielding of the sensor due to parts installed on the outside of the vehicle. External factors include fogging or dirt on the sensor. The physical principles of perception disturbances are based on the sensor mechanism of each sensor.

[0078] The disturbance in the judgment element is a traffic disturbance. The traffic disturbance is a disturbance that indicates a potentially dangerous traffic situation that occurs as a result of a combination of the road geometry, the behavior of the host vehicle 1, and the positions and behaviors of surrounding vehicles. The physical principles of traffic disturbance are based on a geometric perspective and the actions of road users.

[0079] Disturbances in the control elements are vehicle disturbances. Vehicle disturbances may also be called control disturbances. Vehicle disturbances are disturbances that indicate a situation in which the vehicle may be unable to control its own dynamics due to internal or external factors. Internal factors include the total weight and weight balance of the vehicle, for example. External factors include road surface irregularities, slopes, wind, and the like. The physical principles of vehicle disturbances are based on the mechanical effects input to the tires and the vehicle body, for example.

[0080] In order to deal with a collision between the host vehicle 1 and other road users or structures as a risk in the dynamic driving task of automated driving, a traffic disturbance scenario system in which traffic disturbance scenarios are systematized is used as one of the scenario structures. For the traffic disturbance scenario system, a reasonably foreseeable range or a reasonably foreseeable boundary can be defined, and an avoidable range or a avoidable boundary can be defined.

[0081] The avoidable range or boundary can be defined, for example, by defining and modeling the performance of a competent and careful human driver, which can be defined in three elements: perception, judgment, and control.

[0082] Traffic disturbance scenarios include, for example, a cut-in scenario, a cut-out scenario, and a deceleration scenario. The cut-in scenario is a scenario in which another vehicle traveling in an adjacent lane to the host vehicle 1 merges in front of the host vehicle 1. The cut-out scenario is a scenario in which another preceding vehicle that the host vehicle 1 is following changes lanes to an adjacent lane. In this case, it is necessary to implement a proper response to a fallen object that suddenly appears in front of the host vehicle 1, a stopped vehicle at the end of a traffic jam, etc. The deceleration scenario is a scenario in which another preceding vehicle that the host vehicle 1 is following suddenly decelerates.

[0083] Traffic disturbance scenarios can be generated by systematically analyzing and classifying different combinations of the following elements: road geometry, the behavior of the host vehicle 1, the positions of other surrounding vehicles, and the behavior of other surrounding vehicles.

[0084] Here, as an example of systematizing a traffic disturbance scenario, the structure of a traffic disturbance scenario on a highway will be described. Road shapes are classified into four categories: main lane, merging, branching, and ramping. The behavior of the host vehicle 1 is classified into two categories: lane keeping and lane changing. The positions of other vehicles in the vicinity are defined by, for example, eight neighboring positions that may intrude into the traveling trajectory of the host vehicle 1. Specifically, the eight directions are leading (Lead), following (Following), parallel running ahead to the right (Parallel: Pr-f), parallel running to the right (Parallel: Pr-s), parallel running behind to the right (Parallel: Pr-r), parallel running ahead to the left (Parallel: Pl-f), parallel running to the left (Parallel: Pl-s), and parallel running behind to the left (Parallel: Pl-r). The behavior of other vehicles in the vicinity is classified into five categories: cutting in, cutting out, accelerating, decelerating, and synchronizing. Deceleration may include stopping.

[0085] Among the combinations of the positions and movements of other vehicles in the vicinity, there are some that may cause reasonably foreseeable disturbances and some that may not. For example, cut-in can occur in six parallel driving categories. Cut-out can occur in two categories: leading and following. Acceleration can occur in three categories: following, parallel driving on the right rear, and parallel driving on the left rear. Deceleration can occur in three categories: leading, parallel driving on the right front, and parallel driving on the left front. Synchronization can occur in two categories: parallel driving on the right side and parallel driving on the left side. As a result, the structure of traffic disturbance scenarios on expressways is composed of a matrix containing 40 possible combinations. The structure of traffic disturbance scenarios can be further expanded to include complex scenarios by considering at least one of a motorcycle and multiple vehicles.

[0086] Next, a system of perception disturbance scenarios will be described. The perception disturbance scenarios may include a blind spot scenario (also called an occlusion scenario) and a communication disturbance scenario in addition to a sensor disturbance scenario caused by an external environment sensor.

[0087] Sensor disturbance scenarios can be generated by systematically analyzing and classifying different combinations of factors and elements of the sensor mechanism.

[0088] Among the factors of sensor disturbance, factors related to the vehicle and sensor are classified into three categories: the host vehicle 1, the sensor, and the sensor front. Factors related to the host vehicle 1 include, for example, changes in vehicle attitude. Factors related to the sensor include, for example, variations in installation and malfunctions of the sensor itself. Factors related to the sensor front include attachments, changes in characteristics, and, in the case of a camera, reflections. In addition to these factors, the influence of the sensor mechanism specific to each external environment sensor 41 can be assumed as recognition disturbances.

[0089] Among the factors of sensor disturbance, factors related to the external environment are classified into three categories: surrounding structures, space, and surrounding moving objects. Surrounding structures are classified into three categories based on their positional relationship with the vehicle 1: road surface, roadside structures, and overhead structures. Road surface factors include, for example, shape, road surface condition, and material. Roadside structure factors include, for example, reflection, occlusion, and background. Overhead structure factors include, for example, reflection, occlusion, and background. Space factors include, for example, spatial obstacles, radio waves, and light in space. Surrounding moving object factors include, for example, reflection, occlusion, and background. With respect to these factors, the influence of the sensor mechanism specific to each external environment sensor can be assumed as recognition disturbance.

[0090] Among the factors of sensor disturbance, factors related to the sensor's recognition target can be broadly divided into four categories: the driving path, traffic information, road obstacles, and moving objects.

[0091] Roads are classified into lane markings, tall structures, and road edges based on the structure of the objects that represent the lane. Road edges are classified into road edges without steps and road edges with steps. Factors for lane markings include, for example, color, material, shape, dirt, scratches, and relative position. Factors for tall structures include, for example, color, material, dirt, and relative position. Factors for road edges without steps include, for example, color, material, dirt, and relative position. Factors for road edges with steps include, for example, color, material, dirt, and relative position. With respect to these factors, the influence of the sensor mechanism specific to each external environment sensor can be assumed as recognition disturbance.

[0092] Traffic information is classified into signals, signs, and road markings based on the display format. Factors of signals include, for example, color, material, shape, light source, dirt, and relative position. Factors of signs include, for example, color, material, shape, light source, dirt, and relative position. Factors of road markings include, for example, color, material, shape, dirt, and relative position. For these factors, the influence of the sensor mechanism specific to each external environment sensor 41 can be assumed as recognition disturbance.

[0093] Road obstacles are classified into fallen objects, animals, and installed objects based on whether they are moving and the degree of impact if they collide with the vehicle 1. Factors for fallen objects include, for example, color, material, shape, size, relative position, and behavior. Factors for animals include, for example, color, material, shape, size, relative position, and behavior. Factors for installed objects include, for example, color, material, shape, size, dirt, and relative position. With respect to these factors, the influence of the sensor mechanism specific to each external environment sensor 41 can be assumed as a recognition disturbance.

[0094] Moving objects are classified into other vehicles, motorcycles, bicycles, and pedestrians based on the type of traffic participant. Factors for other vehicles include, for example, color, material, paint, surface properties, attachments, shape, size, relative position, and behavior. Factors for motorcycles include, for example, color, material, attachments, shape, size, relative position, and behavior. Factors for bicycles include, for example, color, material, attachments, shape, size, relative position, and behavior. Factors for pedestrians include, for example, the color and material of clothing, posture, shape, size, relative position, and behavior. The influence of these factors depending on the sensor mechanism specific to each external environment sensor 41 can be assumed as recognition disturbances.

[0095] Sensor mechanisms that generate recognition disturbances are classified into recognition process and others. Disturbances that occur in the recognition process are classified into disturbances related to signals from the object to be recognized and disturbances that interfere with signals from the object to be recognized. Disturbances that interfere with signals from the object to be recognized include, for example, noise and unwanted signals.

[0096] In particular, in camera recognition processing, physical quantities that characterize the signal of the object to be recognized include, for example, intensity, direction, range, signal change, and acquisition time. Noise and unwanted signals can be low contrast or high noise.

[0097] In particular, in LiDAR recognition processing, physical quantities that characterize the signal of the recognition target include, for example, scan timing, intensity, propagation direction, and speed. Noise and unwanted signals include, for example, DC noise, pulse noise, multiple reflections, and reflections or refractions from objects other than the recognition target.

[0098] In particular, for millimeter-wave radar, disturbances classified as "other" include disturbances due to the sensor orientation. In the recognition process of millimeter-wave radar, physical quantities that characterize the signal of the recognition target are, for example, frequency, phase, and intensity. Noise and unwanted signals include, for example, small signal loss due to circuit signals, phase noise components of unwanted signals or signal burial due to radio wave interference, and unwanted signals from sources other than the recognition target.

[0099] Blind spot scenarios are classified into three categories: surrounding vehicles, road structure, and road shape. In blind spot scenarios caused by surrounding vehicles, surrounding vehicles may induce blind spots that affect other vehicles. Therefore, the positions of surrounding vehicles may be based on an extended definition that extends the surrounding eight-way neighboring positions. In blind spot scenarios caused by surrounding vehicles, possible blind spot vehicle movements are classified into cut-in, cut-out, acceleration, deceleration, and synchronization.

[0100] Blind spot scenarios due to road structures are defined by taking into consideration the positions of road structures and the relative movement patterns between the host vehicle 1 and other vehicles present in the blind spot or other virtual vehicles assumed to be in the blind spot. Blind spot scenarios due to road structures are classified into blind spot scenarios due to external barriers and blind spot scenarios due to internal barriers. For example, external barriers create blind spot areas on curves.

[0101] Blind spot scenarios due to road shape are classified into longitudinal gradient scenarios and adjacent lane gradient scenarios. The longitudinal gradient scenario generates blind spot areas in front of and / or behind the vehicle 1. The adjacent lane gradient scenario generates blind spot areas due to the difference in elevation between the vehicle and adjacent lanes at merging roads, branching roads, etc.

[0102] Communication disturbance scenarios are classified into three categories: sensor, environment, and transmitter. Sensor-related communication disturbances are classified into map factors and V2X factors. Environment-related communication disturbances are classified into static entities, spatial entities, and dynamic entities. Transmitter-related communication disturbances are classified into other vehicles, infrastructure facilities, pedestrians, servers, and satellites.

[0103] Next, the vehicle motion disturbance scenario system will be explained. Vehicle motion disturbance scenarios are classified into two categories: vehicle body input and tire input. Vehicle body input is an input in which an external force acts on the vehicle body and affects the motion in at least one direction among the longitudinal, lateral, and yaw directions. Elements that affect the vehicle body are classified into road shape and natural phenomena. Road shape includes, for example, superelevation of curved sections, longitudinal gradient, curvature, etc. Natural phenomena include, for example, crosswind, tailwind, headwind, etc.

[0104] Tire inputs are inputs that change tire-generated forces and affect movement in at least one of the following directions: longitudinal, lateral, up-down, and yaw. Factors that affect tires are classified into road conditions and tire conditions.

[0105] The road surface condition is, for example, the coefficient of friction between the road surface and the tire, the external force acting on the tire, etc. Here, road surface factors that affect the coefficient of friction are classified into, for example, wet roads, frozen roads, snow-covered roads, partial gravel, road markings, etc. Road surface factors that affect the external force acting on the tire are, for example, potholes, protrusions, steps, ruts, joints, grooving, etc. The tire condition is, for example, a puncture, a burst, tire wear, etc.

[0106] The scenario DB 53 may include at least one of a functional scenario, a logical scenario, and a concrete scenario. A functional scenario defines a top-level qualitative scenario structure. A logical scenario is a scenario in which a quantitative parameter range is assigned to a structured functional scenario. A concrete scenario defines a boundary of safety judgment that distinguishes between a safe state and an unsafe state.

[0107] An unsafe state is, for example, a hazardous situation. A range corresponding to a safe state may be referred to as a safe range, and a range corresponding to an unsafe state may be referred to as an unsafe range. Furthermore, a condition that contributes to unsafe behavior of the host vehicle 1 in a scenario or an inability to prevent, detect, and mitigate reasonably foreseeable misuse may be a trigger condition.

[0108] Scenarios can be classified as known or unknown, and as dangerous or non-dangerous, i.e., known dangerous scenarios, known non-dangerous scenarios, unknown dangerous scenarios, and unknown non-dangerous scenarios.

[0109] The scenario DB 53 may be used for making judgments about the environment in the driving system 2 as described above, but may also be used for the verification and validation of the driving system 2. The method for verifying and validating the driving system 2 may also be rephrased as a method for evaluating the driving system 2.

[0110] <Safety and Security> The driving system 2 estimates the situation and controls the behavior of the vehicle 1. The driving system 2 is configured to avoid accidents and dangerous situations that could lead to accidents as much as possible and maintain a safe situation or safety. A dangerous situation may be caused as a result of the maintenance condition of the vehicle 1 or a malfunction of the driving system 2. A dangerous situation may also be caused by external factors such as other road users. The driving system 2 is configured to maintain safety by reacting to events that make it impossible to maintain a safe situation due to external factors such as other road users and changing the behavior of the vehicle 1.

[0111] The driving system 2 has the control capability to stabilize the behavior of the host vehicle 1 in a safe state. A safe state depends not only on the behavior of the host vehicle 1 but also on the situation. If it is not possible to control the behavior of the host vehicle 1 to stabilize it in a safe state, the driving system 2 behaves to minimize the harm or risk of an accident. Here, the harm of an accident may refer to the damage or magnitude of the damage caused to traffic participants (road users) when a collision occurs. The risk may be based on the magnitude and likelihood of the harm, or may be, for example, the product of the magnitude and likelihood of the harm.

[0112] A behavior that minimizes the harm or risk of an accident, or the best way to derive that behavior, may be referred to as best effort. Best effort may include a best effort that the automated driving system can guarantee minimizes the severity or risk of an accident (hereinafter referred to as best effort that can guarantee minimal risk). A guarantor-able best effort may refer to a minimal risk maneuver (MRM) or a DDT fallback. Best effort may also include a best effort that cannot guarantee the minimization of the harm or risk of an accident, but attempts to reduce and minimize the severity or risk of an accident to the extent controllable (hereinafter referred to as best effort that cannot guarantee minimal risk).

[0113] FIG. 4 illustrates a control state space SP, which spatially represents the control state of the vehicle. The driving system 2 may have control performance that stabilizes the behavior of the vehicle 1 within a range that has a margin on the safe side of the performance limit of the system that can ensure safety. The performance limit of the system that can ensure safety may be the boundary between a safe state and an unsafe state, that is, the boundary between a safe range and an unsafe range. The operational design domain (ODD) of the driving system 2 is typically set within the performance limit range R2, and more preferably set outside the stable controllable range R1.

[0114] A range with a margin on the safe side of the performance limit may be referred to as a stable range. In the stable range, the driving system 2 can maintain a safe state with nominal operation as designed. A state in which a safe state can be maintained with nominal operation as designed may be referred to as a stable state. A stable state can provide "usual peace of mind" to passengers and the like. Here, the stable range may be referred to as a stable controllable range R1 in which stable control is possible.

[0115] Furthermore, outside the stable control range R1 and within the performance limit range R2, the driving system 2 can return control to a stable state on the assumption that environmental assumptions are met. These environmental assumptions may be, for example, reasonably foreseeable assumptions. For example, the driving system 2 can change the behavior of the vehicle 1 in response to reasonably foreseeable behavior of road users, etc., to avoid a dangerous situation, and return to stable control. A state in which control can be returned to a stable state can provide occupants, etc. with "safety in case of an emergency."

[0116] In the operation system 2, the judgment unit 20 may judge whether to continue stable control or to transition to a minimal risk condition (MRC) within the performance limit range R2 (in other words, before going outside the performance limit range R2). The minimal risk condition may be a fallback condition. The judgment unit 20 may judge whether to continue stable control or to transition to a minimal risk condition outside the stable controllable range R1 and within the performance limit range R2. The transition to the minimal risk condition may be execution of MRM or DDT fallback.

[0117] For example, when the ODD is set within the performance limit range R2 and outside the stable controllable range R1, the determination unit 20 may execute MRM or DDT fallback on the condition that the vehicle 1 deviates from the ODD. Note that the MRM or DDT fallback may be, for example, an operation to safely stop the vehicle 1 on a lane of a road, on the side of the road, or off the road.

[0118] Furthermore, for example, when a level 3 autonomous driving system is being executed, the determination unit 20 may transfer authority to the driver, for example, execute a takeover. When the autonomous driving system does not hand over driving to the driver, control may be adopted to execute an MRM or DDT fallback. Alternatively, the MRM or DDT fallback may include a request for handover to the driver or a remote operator.

[0119] The determination unit 20 may determine a state transition of the driving behavior based on the situation estimated by the environment determination unit 21. The state transition of the driving behavior may refer to a transition regarding the behavior of the host vehicle 1 realized by the driving system 2, for example, a transition between a behavior that maintains consistency and predictability of rules and a reactive behavior of the host vehicle 1 in response to external factors such as other road users. That is, the state transition of the driving behavior may be a transition between an action and a reaction. Furthermore, the determination of the state transition of the driving behavior may be a determination of whether to continue stable control or to transition to a minimum risk condition. Stable control may refer to control in which the behavior of the host vehicle 1 does not exhibit swaying, sudden acceleration, sudden braking, etc., or the frequency of such occurrence is extremely low. Stable control may refer to a level of control at which a human driver recognizes the behavior of the host vehicle 1 as stable or normal.

[0120] The situation estimated by the environment determination unit 21, i.e., the situation estimated by the electronic system, may include a difference from the real world. Therefore, the performance limit of the driving system 2 may be set based on an allowable range of difference from the real world. In other words, the margin between the performance limit range R2 and the stable controllable range R1 may be defined based on the difference between the situation estimated by the electronic system and the real world. Here, the difference between the situation estimated by the electronic system and the real world may be an example of an influence or error due to a disturbance.

[0121] In other words, the margin is set based on the robust performance of the driving system 2 or its subsystems. For example, the margin may be set based on the probability distribution of values ​​indicating safety or risk due to performance, control state, or situation assumed from disturbances or uncertainties, so that a safe state can be maintained with a probability equal to or greater than a predetermined value.

[0122] Here, the situation used to determine whether to transition to the minimum risk condition may be recorded in the recording device 55, for example, in a format estimated by the electronic system. In the MRM or DDT fallback, if there is interaction between the electronic system and the driver, for example, through the HMI device 70, the operation of the driver may be recorded in the recording device 55.

[0123] <Interaction in driving systems> The architecture of the driving system 2 can be expressed by an abstraction layer, a physical interface layer (hereinafter referred to as the physical IF layer), and their relationship with the real world. Here, the abstraction layer and the physical IF layer may refer to layers configured by electronic systems. As shown in Fig. 5, the interaction between the recognition unit 10, the determination unit 20, and the control unit 30 can be expressed by a block diagram showing a causal loop.

[0124] In detail, the host vehicle 1 in the real world affects the external environment EE. The recognition unit 10 belonging to the physical IF layer recognizes the host vehicle 1 and the external environment EE. The recognition unit 10 may generate errors or deviations due to misrecognition, observation noise, recognition disturbances, etc. The errors or deviations generated in the recognition unit 10 affect the determination unit 20 belonging to the abstraction layer. Furthermore, assuming that the control unit 30 acquires the vehicle state for control of the motion actuator 60, the errors or deviations generated in the recognition unit 10 directly affect the control unit 30 belonging to the physical IF layer without passing through the determination unit 20. The determination unit 20 may generate judgment errors, traffic disturbances, etc. The errors or deviations generated in the determination unit 20 affect the control unit 30 belonging to the physical IF layer. When the control unit 30 controls the motion of the host vehicle 1, vehicle motion disturbances occur. Furthermore, the host vehicle 1 in the real world affects the external environment EE, and the recognition unit 10 recognizes the host vehicle 1 and the external environment EE.

[0125] In this way, the driving system 2 forms a causal loop structure that spans each layer. Furthermore, it forms a causal loop structure that moves back and forth between the real world, the physical IF layer, and the abstract layer. Errors or deviations that occur in the recognition unit 10, the judgment unit 20, and the control unit 30 can propagate along the causal loop.

[0126] Causal loops are classified into open loops and closed loops. An open loop is, for example, a loop that goes directly from the recognition unit 10 to the judgment unit 20, or a loop that goes directly from the judgment unit 20 to the control unit 30. An open loop can also be said to be a partial loop that is a part of a closed loop.

[0127] A closed loop is a loop configured to circulate between the real world and at least one of the physical IF layer and the abstraction layer. The closed loop is classified into an inner loop IL that is completed in the host vehicle 1, and an outer loop EL that includes the interaction between the host vehicle 1 and the external environment EE.

[0128] 6, the inner loop IL is a loop that returns from the host vehicle 1 via the recognition unit 10 and the control unit 30. As described above, the parameters that directly affect the control unit 30 from the recognition unit 10 are, under one assumption, vehicle conditions such as vehicle speed, acceleration, and yaw rate, and do not include the recognition results of the external environment sensor 41. Therefore, the inner loop IL can be said to be a loop that ends at the host vehicle 1. The outer loop EL is a loop that returns from the host vehicle 1 via the external environment EE, the recognition unit 10, the determination unit 20, and the control unit 30, for example, in FIG.

[0129] <Verification and validation> The verification and validation of the operating system 2 may include an evaluation of at least one, and preferably all, of the following functions and capabilities. The evaluation targets here may also be referred to as verification targets or validation targets.

[0130] For example, relevant evaluation targets for the perceiving unit 10 are the functionality of sensors or external data sources (eg map data sources), the functionality of sensor processing algorithms that model the environment, and the reliability of infrastructure and communication systems.

[0131] For example, an evaluation target related to the determination unit 20 is the capability of the decision algorithm. The capability of the decision algorithm is the ability to safely handle potential functional deficiencies and the ability to make appropriate decisions according to the environment model, the driving policy, the current destination, etc. Furthermore, for example, evaluation targets related to the determination unit 20 are the absence of unreasonable risks due to dangerous behavior of the intended functions, the system's capability to safely handle ODD use cases, the robust performance of the execution of driving policies across the ODD, the suitability of DDT fallbacks, and the suitability of minimum risk conditions.

[0132] Another example of the evaluation target is the robust performance of a system or function, such as the system's robustness against adverse environmental conditions, the appropriateness of system operation against known trigger conditions, the sensitivity of the intended function, and the monitoring capability against various scenarios.

[0133] Next, several examples of evaluation methods for the driving system 2 will be specifically described with reference to Figures 8 to 13. The evaluation methods referred to here may be configuration methods for the driving system 2 or design methods for the driving system 2. In the following Figures 8, 10, and 12, each circle A1, A2, and A3 virtually and schematically shows an area where safety cannot be maintained due to factors of the recognition unit 10, the judgment unit 20, and the control unit 30, respectively.

[0134] 8, the first evaluation method is a method of independently evaluating the recognition unit 10, the determination unit 20, and the control unit 30. That is, the first evaluation method includes individually evaluating the nominal performance of the recognition unit 10, the nominal performance of the determination unit 20, and the nominal performance of the control unit 30. The individual evaluation may mean evaluating the recognition unit 10, the determination unit 20, and the control unit 30 based on different viewpoints and means.

[0135] For example, the control unit 30 may be evaluated based on control theory. The determination unit 20 may be evaluated based on a logical model that demonstrates safety. The logical model may be an RSS (Responsibility Sensitive Safety) model, an SFF (Safety Force Field) model, or the like.

[0136] The recognition unit 10 may be evaluated based on a recognition failure rate. For example, the evaluation criterion may be whether the recognition results of the entire recognition unit 10 are equal to or lower than a target recognition failure rate. The target recognition failure rate for the entire recognition unit 10 may be a value smaller than the statistically calculated collision accident rate of human drivers. The target recognition failure rate may be, for example, 10-9, which is a probability two orders of magnitude lower than the accident rate. The recognition failure rate here is a normalized value that is 1 when 100% failure occurs.

[0137] Furthermore, when multiple sensors 40 constitute multiple subsystems (for example, a camera subsystem, a subsystem of external environment sensors 41 excluding the camera, and a map subsystem), reliability may be ensured by majority vote of the multiple subsystems. When majority vote of the subsystems is assumed, the target recognition failure rate for each subsystem may be greater than the target recognition failure rate of the entire recognition unit 10. The target recognition failure rate for each subsystem may be, for example, 10-5. In the first evaluation method, a target value or a target condition may be set based on a positive risk balance.

[0138] An example of the first evaluation method will be described using the flowchart in Fig. 9. The entity that performs each of steps S11 to S13 is, for example, at least one entity from among the vehicle manufacturer, the vehicle designer, the manufacturer of the driving system 2, the designer of the driving system 2, the manufacturer of a subsystem that constitutes the driving system 2, the designer of the subsystem, an entity commissioned by these manufacturers or designers, a testing organization or certification organization for the driving system 2, etc. When the evaluation is performed by simulation, the actual entity that performs the evaluation may be at least one processor. In each of steps S11 to S13, the entities that perform the evaluation may be the same entity or different entities.

[0139] In S11, the nominal performance of the recognition unit 10 is evaluated. In S12, the nominal performance of the determination unit 20 is evaluated. In S13, the nominal performance of the control unit 30 is evaluated. The order of S11 to S13 can be changed as appropriate, and they can also be performed simultaneously.

[0140] 10 , the second evaluation method includes evaluating the nominal performance of the determination unit 20 and evaluating the robust performance of the determination unit 20 by taking into account at least one of the errors of the recognition unit 10 and the control unit 30. As a premise of this evaluation method, the evaluation may further include evaluating the nominal performance of the recognition unit 10 and evaluating the nominal performance of the control unit 30. The nominal performance of the determination unit 20 may be evaluated based on the above-mentioned traffic disturbance scenario.

[0141] The robust performance of the determination unit 20 may be evaluated by verifying a traffic disturbance scenario in which an error range is identified using a physics-based error model that represents an error of the recognition unit 10, such as a sensor error. For example, a traffic disturbance scenario is evaluated under environmental conditions in which a recognition disturbance occurs. This allows the second evaluation method to include, as an evaluation target, an area A12 in which the circle A1 of the recognition unit 10 and the circle A2 of the determination unit 20 shown in FIG. 10 overlap, in other words, a complex factor involving the recognition unit 10 and the determination unit 20. Evaluation of a complex factor involving the recognition unit 10 and the determination unit 20 may be realized by an open-loop evaluation that goes directly from the recognition unit 10 to the determination unit 20 in the causal loop described above.

[0142] The robust performance of the determination unit 20 may be evaluated by verifying a traffic disturbance scenario in which an error range is identified using a physics-based error model that represents an error of the control unit 30, such as an error in vehicle motion. For example, a traffic disturbance scenario is evaluated under environmental conditions in which a vehicle motion disturbance occurs. In this way, the second evaluation method can include, as an evaluation target, an area A23 in which the circle A2 of the determination unit 20 and the circle A3 of the control unit 30 shown in FIG. 12 overlap, in other words, the combined factor of the determination unit 20 and the control unit 30. Evaluation of the combined factor of the determination unit 20 and the control unit 30 may be realized by an open-loop evaluation that goes directly from the determination unit 20 to the control unit 30 in the above-mentioned causal loop.

[0143] An example of the second evaluation method will be described using the flowchart in Fig. 11. The implementing entity of S21 to S24 is, for example, at least one of the following entities: the vehicle manufacturer, the vehicle designer, the manufacturer of the driving system 2, the designer of the driving system 2, the manufacturer of a subsystem constituting the driving system 2, the designer of the subsystem, a party commissioned by these manufacturers or designers, a testing organization or certification organization for the driving system 2, etc. When the evaluation is performed by simulation, the actual implementing entity may be at least one processor. In each step of S21 to S24, the implementing entities may be the same entity or different entities.

[0144] In S21, the nominal performance of the recognition unit 10 is evaluated. In S22, the nominal performance of the control unit 30 is evaluated. In S23, the nominal performance of the judgment unit 20 is evaluated. In S24, the robust performance of the judgment unit 20 is evaluated taking into account the error of the recognition unit 10 and the error of the control unit 30. The order of S21 to S14 can be changed as appropriate, or they can be performed simultaneously.

[0145] As shown in FIG. 12 , the third evaluation method includes, as an evaluation target, areas A12, A23, A13, and AA where at least two of the circle A1 of the recognition unit 10, the circle A2 of the judgment unit 20, and the circle A3 of the control unit 30 overlap. The third evaluation method first includes evaluating the nominal performance of the recognition unit 10, the nominal performance of the judgment unit 20, and the nominal performance of the control unit 30. The evaluation of the nominal performance may employ the first evaluation method itself, or a part of the first evaluation method. On the other hand, the evaluation of the nominal performance may employ a method completely different from the first evaluation method.

[0146] Furthermore, the third evaluation method includes a focused evaluation of the robust performance of the recognition unit 10, the robust performance of the judgment unit 20, and the robust performance of the control unit 30, focusing on a composite factor that combines at least two of the recognition unit 10, the judgment unit 20, and the control unit 30. Here, the composite factor of at least two of the recognition unit 10, the judgment unit 20, and the control unit 30 refers to a composite factor between the recognition unit 10 and the judgment unit 20, a composite factor between the judgment unit 20 and the control unit 30, a composite factor between the recognition unit 10 and the control unit 30, and three composite factors of the recognition unit 10, the judgment unit 20, and the control unit 30.

[0147] Focused evaluation of multiple factors may involve extracting specific conditions that have a relatively large interaction between the recognition unit 10, the judgment unit 20, and the control unit 30, for example, on a scenario basis, and evaluating the specific conditions more in detail than other conditions that have a relatively small interaction. Detailed evaluation may include at least one of evaluating the specific conditions in more detail than other conditions and evaluating them with an increased number of tests. The conditions to be evaluated (e.g., the specific conditions and other conditions) may include trigger conditions. The magnitude of the interaction may be identified using the causal loop described above.

[0148] Some of the above-mentioned evaluation methods may include defining an evaluation target, designing a test plan based on the definition of the evaluation target, and executing the test plan to demonstrate the absence of unreasonable risks due to known or unknown dangerous scenarios. The test may be any of a physical test, a simulation test, or a combination of the physical test and the simulation test. The physical test may be, for example, a Field Operational Test (FOT). A target value in the FOT may be set in the form of an allowable number of failures for a predetermined driving distance (e.g., tens of thousands of km) of the test vehicle using FOT data or the like.

[0149] An example of the third evaluation method will be described using the flowchart in Fig. 13. The implementing entity of S31 to S34 is, for example, at least one of the following entities: the vehicle manufacturer, the vehicle designer, the manufacturer of the driving system 2, the designer of the driving system 2, the manufacturer of a subsystem constituting the driving system 2, the designer of the subsystem, a party commissioned by these manufacturers or designers, a testing organization or certification organization for the driving system 2, etc. When the evaluation is performed by simulation, the actual implementing entity may be at least one processor. In each step of S31 to S34, the implementing entities may be the same entity or different entities.

[0150] In S31, the nominal performance of the recognition unit 10 is evaluated. In S32, the nominal performance of the judgment unit 20 is evaluated. In S33, the nominal performance of the control unit 30 is evaluated. In S34, the robust performance is evaluated with a focus on the composite regions A12, A23, A13, and AA. The order of S31 to S34 can be changed as appropriate, or they can be performed simultaneously.

[0151] Here, the nominal performance in this embodiment may be the performance when the driving system 2 or its subsystem operates at a nominal level as designed. The nominal performance may be the maximum performance that the driving system 2 or its subsystem can achieve based on its design.

[0152] The robust performance in this embodiment may be the performance that the driving system 2 or its subsystems can exhibit under the influence of external disturbances. The robust performance may also be the performance that can be exhibited under the influence of performance degradation due to uncertainty. The uncertainty here may include the uncertainty of the external environment in the environmental model. In other words, it may include the uncertainty of other road users, other vehicles equipped with automated driving systems, etc. The uncertainty may include the uncertainty regarding the contribution of rare phenomena not considered in the design.

[0153] <Control Switching and Control Actions> The following describes in detail the control switching and control actions that the driving system 2 executes while the vehicle 1 is traveling. Here, "while the vehicle 1 is traveling" may mean that so-called automated driving at level 3 or higher is being executed, or that so-called manual driving or driving assistance at levels 0 to 2 is being executed. In the states of levels 0 to 2, the execution of best efforts, which will be described later, may involve the transfer of authority to execute a dynamic driving task from the driver to the driving system 2.

[0154] The control switching may be a control behavior of the driving system 2 that changes at least one of the control processing method and the nominal performance while the host vehicle 1 is traveling. The control action is a behavior that executes a control switching or a behavior that continues control without executing a switching, depending on a judgment based on the situation estimated by the driving system 2. The judgment may include a response to a change in the situation due to external factors such as other road users. The host vehicle 1 behaves in response to the situation by the control action.

[0155] The relationship between the control state and the control switch can be set, for example, according to the results of evaluation and analysis of scenarios in the verification and validation of the operating system 2. The relationship between the control state and the control switch may be referred to as a switch condition. The switch condition may include a minimum risk condition or a fallback condition.

[0156] 14 shows an example of the relationship between a state parameter indicating a current control state (hereinafter referred to as the current state), a state change parameter indicating a state change of the control state, and a control action. The state change of the state parameter s may be the derivative ds / dt of s with respect to time t. When s is a discrete state parameter, the condition for determining the next state of s may be the state change parameter of s. In other words, the acquisition of the state change by the driving system 2 may be the acquisition of a continuous state change or the acquisition of a discrete state change. For example, if s is the distance between the host vehicle 1 and another vehicle, ds / dt is the relative speed of the host vehicle 1 with respect to the other vehicle. Also, if s is the speed of the host vehicle 1, ds / dt is the acceleration of the host vehicle 1. Also, if s is the yaw angle of the host vehicle 1, ds / dt is the yaw rate of the host vehicle 1.

[0157] In the operation system 2, a stable controllable range R1 and a performance limit range R2 may be defined for each of a plurality of parameters. The plurality of parameters may include the above-mentioned state parameters and state change parameters. The stable controllable range R1 and the performance limit range R2 for each parameter may be defined based on an operation policy that is based on a combination of the plurality of parameters. The stable controllable range R1 and the performance limit range R2 for each parameter may be defined in a form that applies the most appropriate operation policy to each parameter.

[0158] Some or all of the multiple parameters to be determined may be physical values ​​that can be sensed by the recognition unit 10. Other of the multiple parameters may be parameters that can be calculated based on physical values.

[0159] On the other hand, an overall control state of the vehicle 1 (hereinafter abbreviated as the entire control state) may be defined for the driving system 2. A stable controllable range R1 and a performance limit range R2 may also be defined for the entire control state. The definition of the stable controllable range R1 and the performance limit range R2 for the entire control state may be associated with some or all of the stable controllable ranges R1 and the performance limit ranges R2 of the multiple parameters for which the stable controllable ranges R1 and the performance limit ranges R2 are individually defined.

[0160] The operation system 2 may determine whether each parameter is within or outside the stable controllable range R1. The operation system 2 may determine whether each parameter is within or outside the performance limit range R2.

[0161] The driving system 2 may determine, as a determination regarding the entire control state of the host vehicle 1, whether the control state is within or outside the stable controllable range R1. The driving system 2 may determine, as a determination regarding the entire control state of the host vehicle 1, whether the control state is within or outside the performance limit range R2. The driving system 2 may determine, as a determination regarding a change in the entire control state of the host vehicle 1, whether the change in the control state is within or outside the stable controllable range R1. The driving system 2 may determine, as a determination regarding a change in the entire control state of the host vehicle 1, whether the change in the control state is within or outside the performance limit range R2.

[0162] FIG. 15 schematically illustrates the relationship between the relative position of an obstacle, the performance limit range R2, and the stable controllable range R1 when the parameter to be determined is the relative position of the obstacle with respect to the host vehicle 1. Here, the host vehicle 1 is assumed to be traveling forward at a predetermined speed and acceleration. For example, if an obstacle is present in a partially cylindrical region B1 in front of the host vehicle 1, the range indicating the control state for the relative position of the obstacle will be within the performance limit range R2 and outside the stable controllable range R1. If an obstacle is present in a partially cylindrical or sector-shaped region B2 in front of the host vehicle 1 that includes the region between the host vehicle 1 and region B1, the range indicating the control state for the relative position of the obstacle will be outside the performance limit range R2.

[0163] Here, region B1 and region B2 are in a relationship in which the inner circumferential portion of region B1 contacts the outer circumferential portion of region B2. Furthermore, typically, the central angle (or lateral width) of region B2 can be larger than the central angle (or lateral width) of region B1. Region B1 may essentially mean a region in which collision with an obstacle can be avoided with unstable control. Region B2 may essentially mean a region in which collision with an obstacle cannot be avoided.

[0164] The driving system 2 may derive a control action based on the state parameter whose range has been determined as described above and the state change parameter whose range has been determined as described above. In other words, the driving system 2 may derive a control action according to the range determination result for the state parameter and the range determination result for the state change parameter. The control action here may be an action intended to cause a state transition of only the state parameter to be determined, or may be an action that also affects other state parameters.

[0165] The driving system 2 may derive a control action according to the result of determining the range of the entire control state of the vehicle 1 and the result of determining the range of the change in the entire control state.

[0166] Specifically, when the current state is within the stable controllable range R1 and the state change is within the stable controllable range R1, the driving system 2 may derive a control action to maintain the current state.

[0167] When the current state is within the stable controllable range R1 and the state change is within the performance limit range R2 and outside the stable controllable range R1, the driving system 2 may derive a control action for transitioning the state change to control within the target stable controllable range R1. This control action may be referred to as a transient response. The transient response may mean a response during the process of switching control. The transient response may be a response that returns control from a safe and unstable state to a stable state. Furthermore, the transient response may be one aspect of a so-called appropriate response.

[0168] The driving system 2 may set a limit value for switching conditions in the transient response. When it is expected that the limit value will be exceeded before the transient response is executed, the driving system 2 may derive a control action to cancel the execution of the transient response and execute a best effort. When it is expected that the limit value will be exceeded during the execution of the transient response, the driving system 2 may derive a control action to cancel the execution of the transient response and execute a best effort. When the limit value is exceeded during the execution of the transient response, the driving system 2 may derive a control action to cancel the execution of the transient response and execute a best effort.

[0169] The best effort here is typically a best effort that can guarantee the minimum risk, such as an MRM or DDT fallback. However, the derivation of the control action here may include determining whether a best effort that can guarantee the minimum risk, such as an MRM or DDT fallback, is feasible. The derivation of the control action may include deriving a control action that executes the best effort when it is determined that the best effort that can guarantee the minimum risk is feasible. The derivation of the control action may include deriving a control action that executes a best effort that cannot guarantee the minimum risk when it is determined that the best effort that can guarantee the minimum risk is not feasible.

[0170] The driving system 2 may derive a control action to execute a best effort when the current state is within the stable controllable range R1 and the state change is outside the performance limit range R2. The driving system 2 may derive a control action to execute a best effort when the current state is within the stable controllable range R1 and the state change cannot be determined.

[0171] In these cases, the driving system 2 may determine that the driving system 2 is abnormal (hereinafter referred to as abnormality determination). The abnormality here may mean that a state change that is not possible in the design of the driving system 2 has occurred. The abnormality may be caused by the occurrence of an unknown dangerous scenario.

[0172] The best effort here typically refers to a best effort that cannot guarantee the minimum risk. On the other hand, the derivation of the control action here may include determining whether a best effort that can guarantee the minimum risk, such as an MRM or DDT fallback, is feasible. The derivation of the control action may include deriving a control action that executes the best effort when it is determined that the best effort that can guarantee the minimum risk is feasible. The derivation of the control action may include deriving a control action that executes a best effort that cannot guarantee the minimum risk when it is determined that the best effort that can guarantee the minimum risk is not feasible.

[0173] When the current state is within the performance limit range R2 and outside the stable controllable range R1, and the state change is within the stable controllable range R1, the driving system 2 may derive a control action for transitioning the current state to control within the stable controllable range R1. This control action may be referred to as a transient response.

[0174] The driving system 2 may derive a control action to be executed on a best-effort basis when the current state is within the performance limit range R2 and outside the stable controllable range R1, and when the state change is within the performance limit range R2 and outside the stable controllable range R1. The best-effort here is typically the best-effort that can guarantee the minimum risk, such as an MRM or DDT fallback.

[0175] The driving system 2 may derive a control action to execute a best effort when the current state is within the performance limit range R2 and outside the stable controllable range R1, and the state change is outside the performance limit range R2. The driving system 2 may derive a control action to execute a best effort when the current state is within the performance limit range R2 and outside the stable controllable range R1, and the state change cannot be determined.

[0176] The best effort here typically refers to a best effort that cannot guarantee the minimum risk. On the other hand, the derivation of the control action here may include determining whether a best effort that can guarantee the minimum risk, such as an MRM or DDT fallback, is feasible. The derivation of the control action may include deriving a control action that executes the best effort when it is determined that the best effort that can guarantee the minimum risk is feasible. The derivation of the control action may include deriving a control action that executes a best effort that cannot guarantee the minimum risk when it is determined that the best effort that can guarantee the minimum risk is not feasible.

[0177] The driving system 2 may derive a control action to execute a best effort when the current state is outside the performance limit range R2 and the state change is within the stable controllable range R1. The driving system 2 may derive a control action to execute a best effort when the current state cannot be determined and the state change is outside the stable controllable range R1. In these cases, the driving system 2 may perform an abnormality determination.

[0178] The best effort here is typically a best effort that can guarantee the minimum risk, such as an MRM or DDT fallback. However, the derivation of the control action here may include determining whether a best effort that can guarantee the minimum risk, such as an MRM or DDT fallback, is feasible. The derivation of the control action may include deriving a control action that executes the best effort when it is determined that the best effort that can guarantee the minimum risk is feasible. The derivation of the control action may include deriving a control action that executes a best effort that cannot guarantee the minimum risk when it is determined that the best effort that can guarantee the minimum risk is not feasible.

[0179] The driving system 2 may derive a control action to execute a best effort when the current state is outside the performance limit range R2 and the state change is within the performance limit range R2 and outside the stable controllable range R1. The driving system 2 may derive a control action to execute a best effort when the current state is undeterminable and the state change is within the performance limit range R2 and outside the stable controllable range R1. In these cases, the driving system 2 may perform an abnormality determination.

[0180] The best effort here is typically a best effort that can guarantee the minimum risk, such as an MRM or DDT fallback. However, the derivation of the control action here may include determining whether a best effort that can guarantee the minimum risk, such as an MRM or DDT fallback, is feasible. The derivation of the control action may include deriving a control action that executes the best effort when it is determined that the best effort that can guarantee the minimum risk is feasible. The derivation of the control action may include deriving a control action that executes a best effort that cannot guarantee the minimum risk when it is determined that the best effort that can guarantee the minimum risk is not feasible.

[0181] The driving system 2 may derive a control action to execute a best effort when the current state is outside the performance limit range R2 and the state change is outside the performance limit range R2. The driving system 2 may derive a control action to execute a best effort when the current state is undeterminable and the state change is outside the performance limit range R2. The driving system 2 may derive a control action to execute a best effort when the current state is outside the performance limit range R2 and the state change is undeterminable. The driving system 2 may derive a control action to execute a best effort when the current state is undeterminable and the state change is undeterminable. In these cases, the driving system 2 may perform an abnormality determination.

[0182] The best effort here typically refers to a best effort that cannot guarantee the minimum risk. On the other hand, the derivation of the control action here may include determining whether a best effort that can guarantee the minimum risk, such as an MRM or DDT fallback, is feasible. The derivation of the control action may include deriving a control action that executes the best effort when it is determined that the best effort that can guarantee the minimum risk is feasible. The derivation of the control action may include deriving a control action that executes a best effort that cannot guarantee the minimum risk when it is determined that the best effort that can guarantee the minimum risk is not feasible.

[0183] The control switching and the derivation of the control action based on the switching can be executed by, for example, the determination unit 20. The control switching may be included in, for example, the behavior plan by the operation planning unit 22. The control switching may be included in the function constraints set by the mode management unit 23.

[0184] For example, as an onboard implementation strategy, the mode management unit 23 itself or the constraint setting function of the mode management unit 23 may be implemented by a dedicated computer 51 (e.g., SoC) having at least one processor, memory, and interface. In this case, the SoC acquires information regarding the stability of the behavior of the host vehicle 1 through the interface. The information regarding the stability of the behavior of the host vehicle 1 may be, for example, information recognized by the recognition unit 10 or a situation estimated by the environment determination unit 21. The SoC sets constraints for the driving system 2 to switch control in accordance with the information regarding the stability of the behavior of the host vehicle 1. To set the constraints, the SoC may determine the above-mentioned ranges based on, for example, the performance limit range R2 and the stable controllable range R1 stored in the memory 51a. The SoC then outputs the set constraints via the interface to, for example, the driving planner 22 (or directly to the motion control unit 31).

[0185] <Record> The recording of information in the recording device 55 in response to switching of the control action will be described below.

[0186] The recording device 55 may perform recording based on the fact that a condition such as a switching condition, a trigger condition, a minimum risk condition, or a fallback condition is satisfied, a control action for executing a best effort is derived, or the best effort is actually executed. The recording device 55 may perform recording based on the fact that a control action for executing a transient response is derived, or the transient response is actually executed.

[0187] In this recording, the recording device 55 records a set of information related to the derived control action and information used to determine the derived control action. This set of records may further include at least one of information such as a timestamp, a vehicle state, sensor abnormality (or sensor failure) information, and abnormality determination information.

[0188] For example, when the operation system 2 executes MRM, the recording device 55 may record execution information of MRM as information on the derived control action. The recording device 55 may record, as information used in determining the derivation of the control action, the situation estimated by the operation system 2 and information indicating the range of the control state determined by the operation system 2 based on the situation.

[0189] The information indicating the range of the control state is information that distinguishes whether the control state is within the stable controllable range R1, within the performance limit range R2 and outside the stable controllable range R1, or outside the performance limit range R2. The information indicating the range of the control state may be configured by combining information indicating whether the control state is within or outside the performance limit range R2 and information indicating whether the control state is within or outside the stable controllable range R1.

[0190] The information indicating the range of the control state may include information on the entire control state. The information indicating the range of the control state may include individual information on multiple parameters that are the subject of judgment. The information indicating the range of the control state may include information on state parameters and information on state change parameters. The above information to be recorded may be encrypted or hashed.

[0191] <Example of operation flow> 16 to 18, an example of processing related to switching of control actions in the operation flow of the driving system 2 will be described below. A series of processing steps shown in steps S101 to S127 is repeatedly executed by the driving system 2 at predetermined time intervals or based on a predetermined trigger, for example, in accordance with a program stored in the memory 51a.

[0192] 16, the determination unit 20 determines whether the current state is within the stable controllable range R1. If a positive determination is made in S101, the process proceeds to S102. If a negative determination is made in S101, the process proceeds to S109.

[0193] In S102, the determination unit 20 determines whether the state change is within the stable controllable range R1. If the determination in S102 is affirmative, the process proceeds to S103. If the determination in S103 is negative, the process proceeds to S104.

[0194] In S103, the decision unit 20 derives a control action that maintains the current state. After S103, the series of processes ends.

[0195] In S104, the determination unit 20 determines whether the state change is within the performance limit range R2. If the determination in S104 is affirmative, the process proceeds to S105. If the determination in S104 is negative, the process proceeds to S106.

[0196] In S105, the determination unit 20 derives a control action for executing a transient response. After S105, the series of processes ends.

[0197] In S106, the judgment unit 20 makes an abnormality judgment. In S107 after processing S106, the judgment unit 20 derives a control action for executing a best effort. In S108 after processing S107, the recording device 55 records a set of information about the derived control action and information used in determining the derivation of the control action. A series of processes ends with S108.

[0198] In S109, the determination unit 20 determines whether the current state is within the performance limit range R2. If the determination in S109 is affirmative, the process proceeds to S111. If the determination in S109 is negative, the process proceeds to S121.

[0199] 17, the determination unit 20 determines whether the state change is within the stable controllable range R1. If a positive determination is made in S111, the process proceeds to S112. If a negative determination is made in S111, the process proceeds to S113.

[0200] In S112, the decision unit 20 derives a control action for executing a transient response. After S112, the series of processes ends.

[0201] In S113, the determination unit 20 determines whether the state change is within the performance limit range R2. If the determination in S113 is affirmative, the process proceeds to S114. If the determination in S114 is negative, the process proceeds to S116.

[0202] In S114, the determination unit 20 derives a control action for executing best effort (e.g., MRM). In S115 after the processing of S114, the recording device 55 records a set of information on the derived control action and information used in determining the derivation of the control action. A series of processes ends with S115.

[0203] In S116, the determination unit 20 derives a control action for executing a best effort. After the process of S116, the process proceeds to S115.

[0204] 18, the determination unit 20 determines whether the state change is within the stable controllable range R1. If a positive determination is made in S121, the process proceeds to S122. If a negative determination is made in S121, the process proceeds to S125.

[0205] In S122, the judgment unit 20 makes an abnormality judgment. In S123 after processing S122, the judgment unit 20 derives a control action for executing a best effort. In S124 after processing S123, the recording device 55 records a set of information about the derived control action and information used in determining the derivation of the control action. A series of processes ends with S124.

[0206] In S125, the determination unit 20 determines whether the current state is within the performance limit range R2. If the determination in S125 is affirmative, the process proceeds to S126. If the determination in S125 is negative, the process proceeds to S127.

[0207] In S126, the determination unit 20 derives a control action for executing best effort (for example, MRM). After the process of S126, the process proceeds to S124.

[0208] In S127, the determination unit 20 derives a control action for executing a best effort. After the process of S127, the process proceeds to S124.

[0209] <Action and effect> The effects of the first embodiment described above will be explained below.

[0210] According to the first embodiment, the control action of the host vehicle 1 is derived in response to a determination of whether the control state is within the stable controllable range R1. This stable controllable range R1 is associated with the performance limit range R2 and is defined as a range within the performance limit range R2 in which stable control can be maintained. In other words, the control action is derived from the perspective of whether the driving system 2 can maintain stable control taking into account the performance limit. It is also possible to switch the control action before the performance limit is reached, providing a high sense of security to the occupants.

[0211] Furthermore, according to the first embodiment, the determination of whether the control state is within the stable controllable range R1 is performed based on the recognized situation, and the control action is derived as a response to the recognized situation. Therefore, even when the situation changes due to external factors such as other road users, the control action that responds can be switched before the performance limit is reached. This provides a high sense of security to the occupants.

[0212] Furthermore, according to the first embodiment, switching of control actions is based on switching conditions set according to the determination result of whether the control state is within the stable controllable range R1, within the performance limit range R2 but outside the stable controllable range R1, or outside the performance limit range R2. The control action is derived based on whether a stable state can be maintained, whether the performance to return to a stable state even in an unstable state can be demonstrated, or whether it is impossible to return to a stable state. Switching that takes control stability into consideration can provide a high sense of security to occupants.

[0213] Furthermore, according to the first embodiment, when the control state is outside the performance limit range R2, a best effort is performed. This best effort attempts to minimize risk to the extent possible that it is controllable, thereby increasing the validity of the control action to be performed.

[0214] Furthermore, according to the first embodiment, the parameters used to determine the stable controllable range R1 include a state parameter indicating the current state of the control state and a state change parameter indicating a state change of the control state. By determining both the current state and the state change, the predictability of the control state in the determination can be improved. Therefore, the validity of the control action to be executed can be improved.

[0215] Furthermore, according to the first embodiment, the performance limit range R2 and the stable controllable range R1 are set based on the difference between the situation estimated by the processor and the real world. This difference is reflected in the derivation of the control action, thereby reducing the occurrence of misjudgment due to estimation errors. This provides a high sense of security to the occupants.

[0216] Furthermore, according to the first embodiment, information indicating the range of the control state is recorded. This information is determined based on the situation estimated by the operation system 2, so that the estimation result or the determination result by the operation system 2 when MRM is executed can be easily verified after the fact.

[0217] Furthermore, according to the first embodiment, the ODD may be set within the performance limit range R2 and outside the stable controllable range R1. By setting the ODD outside the stable controllable range R1, excessive responses that occur when the ODD deviates from the ODD can be suppressed, thereby improving the practicality of the driving system 2. By setting the ODD within the performance limit range R2 and outside the stable controllable range R1, a step-by-step response is possible using robust performance in the margin between the ranges R1 and R2, thereby increasing the success rate of successful responses before a dangerous situation occurs. This provides a high sense of security to the occupants. The ODD of the driving system 2 may be clearly set in advance, for example, by a specification, an instruction manual, compliance with a standard, or by other methods.

[0218] (Second embodiment) 19 to 21, the second embodiment is a modification of the first embodiment. The second embodiment will be described, focusing on the differences from the first embodiment.

[0219] <Recognition control subsystem> 19, the control unit 30 and the recognition unit 10 belong to the physical IF layer, while the determination unit 20 belongs to the abstract layer. Therefore, the control unit 30 and the recognition unit 10 can be regarded or configured as one component (hereinafter, recognition control subsystem 210).

[0220] A method for setting the performance limit range R2 and the stable controllable range R1 according to this concept, and a method for setting the associated allowable time, will be described in detail below with reference to the flowchart in Fig. 20. These setting methods can be used as a method for designing the driving system 202. The entity that performs each of steps S201 to 202 is at least one entity from among, for example, the vehicle designer, the driving system 202 designer, the subsystem designer that configures the driving system 202, the manufacturer of these vehicles, driving system 202, subsystems, etc., or a person commissioned by the designer. The design may be automated and performed by at least one processor. The entities that perform each step may be the same entity or different entities.

[0221] This series of design flows may be implemented to set the performance limit range R2 and stable controllable range R1 for the entire control state used for switching control actions, or may be implemented to set the performance limit range R2 and stable controllable range R1 for each of multiple parameters used for switching control actions.

[0222] In the first step S201, a performance limit range R2 and a stable controllable range R1 are set based on the performance of the recognition unit 10 and the control unit 30. Here, the performance of the recognition unit 10 and the control unit 30 may mean the performance of the recognition control subsystem 210. The performance of the recognition unit 10 and the control unit 30 may include the nominal performance of the recognition unit 10 and the control unit 30 and the robust performance of the recognition unit 10 and the control unit 30.

[0223] A state in which the nominal performance of the recognition unit 10 and the control unit 30 is exhibited is a stable state. That is, a stable controllable range R1 may be set according to the nominal performance of the recognition unit 10 and the control unit 30. On the other hand, a safe state can be maintained in the driving system 202 by exhibiting the robust performance of the recognition unit 10 and the control unit 30. That is, a performance limit range R2 may be set according to the robust performance of the recognition unit 10 and the control unit 30. The robust performance of the recognition unit 10 and the control unit 30 may be verified by evaluating an open loop going directly from the recognition unit 10 to the control unit 30. After S201, the process proceeds to S202.

[0224] In S202, an allowable time is set based on the evaluations of the recognition unit 10, the judgment unit 20, and the control unit 30. Here, the allowable time may be a time for which the control state is allowed to continue being outside the stable controllable range R1. The allowable time may be a time for which the control state is allowed to continue being within the performance limit range R2 and outside the stable controllable range R1. The allowable time may be set commonly for the entire control state and for each parameter, or may be set individually. Instead of the allowable time, an allowable number of times that a control action is allowed to be executed may be set.

[0225] The allowable time may be set as a constant that does not change at all times, or may be set as a dynamically changing function. When the allowable time for a certain parameter is a dynamically changing function, it may be a function of the values ​​of other parameters.

[0226] The evaluations of the recognition unit 10, the determination unit 20, and the control unit 30 in S202 may be the evaluations of S24 shown in Fig. 11 or evaluations equivalent thereto. That is, the evaluations of the recognition unit 10, the determination unit 20, and the control unit 30 may be evaluations that combine evaluations of an open loop going directly from the recognition unit 10 to the determination unit 20 and evaluations of an open loop going directly from the determination unit 20 to the control unit 30.

[0227] On the other hand, the evaluation by the recognition unit 10, the determination unit 20, and the control unit 30 in S202 may be the evaluation by S34 shown in Fig. 13 or an evaluation equivalent thereto. That is, the evaluation by the recognition unit 10, the determination unit 20, and the control unit 30 may be a closed-loop evaluation.

[0228] <Switching control based on time allowance> The following describes the switching of control that the driving system 202, particularly the determination unit 20, executes while the vehicle 1 is traveling. The driving system 202 of the second embodiment switches control actions according to the allowable time. That is, instead of the determination of the range of a state change in the first embodiment, or in combination with the determination of the range of a state change, the control action is derived using the allowable time.

[0229] The use of the permissible time increases the ease of subsequent verification of the operation system 202. The judgment result using the permissible time is recorded in the recording device 55 together with a timestamp, thereby increasing the objectivity of the verification.

[0230] The operation system 202 continuously determines whether a parameter to be determined is within or outside the stable controllable range R1. The operation system 202 continuously determines whether a parameter to be determined is within or outside the performance limit range R2. Here, continuous determination means determination in a manner that can determine whether a state in which the parameter is within the performance limit range R2 and outside the stable controllable range R1 continues for an allowable time. The continuous determination may be, for example, periodic determination at predetermined time intervals that are sufficiently shorter than the allowable time.

[0231] Even if each parameter to be judged is within the performance limit range R2 and outside the stable controllable range R1, the driving system 202 may derive the same or equivalent control action as when it is within the stable controllable range R1, as long as the condition does not continue beyond the allowable time.

[0232] The operation system 202 determines whether a certain parameter has remained within the performance limit range R2 but outside the stable controllable range R1 for a period exceeding the allowable time. If the state of a certain parameter has exceeded the allowable time, the recording device 55 records the time when the certain parameter began to remain within the performance limit range R2 but outside the stable controllable range R1, and the time when the allowable time expired, along with a timestamp. The operation system 202 then makes a comprehensive determination that takes into account the states of other parameters.

[0233] When other parameters are within the stable controllable range R1, the operation system 202 determines whether the entire control state is within or outside the performance limit range R2 based on whether the entire control state can be returned to within the stable controllable range R1. When the state of a certain parameter exceeds the allowable time, the other parameters are within the stable controllable range R1, and the entire control state is within the performance limit range R2, the recording device 55 records, together with a timestamp, that the control state is currently in a state where it is possible to return it to within the stable controllable range R1.

[0234] An example of processing related to determining the control state, among the operational flows of the driving system 202, will be described below with reference to the flowchart of FIG.

[0235] In S211, the determination unit 20 determines whether the duration of a state in which a certain parameter is within the performance limit range R2 and outside the stable controllable range R1 has exceeded the allowable time. If a positive determination is made in S211, the process proceeds to S212. If a negative determination is made in S211, the determination unit 20 executes the determination of S211 again after a predetermined time has elapsed.

[0236] In S212, the determination unit 20 starts a process of determining whether the entire control state is within or outside the performance limit range R2 by a composite determination with other parameters. After the process of S212, the process proceeds to S213.

[0237] In S213, the judgment unit 20 determines whether the state of the parameter determined in S211 can be returned to within the stable controllable range R1, taking into consideration interactions with other parameters. If the determination in S213 is affirmative, the process proceeds to S214. If the determination in S213 is negative, the process proceeds to S215.

[0238] In S214, the determination unit 20 determines that the entire control state is within the performance limit range R2. After the process of S214, the process proceeds to S215.

[0239] In S215, the determination unit 20 determines that the entire control state is outside the performance limit range R2. After the process of S215, the process proceeds to S216.

[0240] In S216, the recording device 55 records information relating to the permissible time, and the series of processes ends with S216.

[0241] According to the second embodiment described above, MRM is executed when the condition indicating that the control state continues to be within the performance limit range R2 and outside the stable controllable range R1 is satisfied.

[0242] Furthermore, according to the second embodiment, in the execution of a best effort that can guarantee the minimum risk, a continuation state within the performance limit range R2 and outside the stable controllable range R1 is allowed for a set permissible time. Since a control action that switches control immediately after the control state enters the performance limit range R2 and outside the stable controllable range R1 is suppressed, the stability of the control can be improved.

[0243] Furthermore, according to the second embodiment, the allowable time set for one parameter changes dynamically depending on the ranges determined for other parameters. Since the allowable time can reflect the interactions between multiple parameters, the stability of control can be further improved.

[0244] Furthermore, according to the second embodiment, if the control state remains within the performance limit range R2 and outside the stable controllable range R1 for a period exceeding the permissible time, the fact that the permissible time has been exceeded is recorded. Since the time-related conditions among the determination conditions for executing MRM can be verified after the fact, the reliability of the verification of the operation system 202 can be improved.

[0245] Furthermore, according to the second embodiment, there may be cases where a state in which one of the multiple parameters is within the performance limit range R2 and outside the stable controllable range R1 continues for more than the allowable time, while other parameters are within the stable controllable range R1, and the entire control state is within the performance limit range R2. In this case, it is recorded that the control state can be returned to the stable controllable range R1. Therefore, the judgment results made by the operation system 202 when MRM was executed can be easily verified after the fact.

[0246] Furthermore, according to the second embodiment, the stable controllable range R1 is defined according to the nominal performance of the driving system 2 or its subsystem, and the performance limit range R2 is defined according to the robust performance of the driving system 2 or its subsystem. This configuration for switching control based on the control state judgment based on the ranges R1 and R2 makes it possible to match the performance of the driving system 2 or the subsystem with control suited to it, thereby improving the reliability of the control action.

[0247] (Third embodiment) As shown in Fig. 22, the third embodiment is a modification of the first embodiment. The second embodiment will be described, focusing on the differences from the first embodiment.

[0248] In the driving system 302 of the third embodiment, no direct input / output of information is performed between the recognition unit 10 and the control unit 30. That is, information output by the recognition unit 10 is input to the control unit 30 via the determination unit 20. For example, the vehicle state recognized by the internal recognition unit 14, for example, at least one of the current speed, acceleration, and yaw rate of the host vehicle 1, is passed directly to the motion control unit 31 via the environment determination unit 321 and the driving plan unit 322, or via the mode management unit 323 and the driving plan unit 322.

[0249] That is, the environment judgment unit 321 and the operation planning unit 322 or the mode management unit 323 and the operation planning unit 322 have the function of processing some of the information acquired from the internal recognition unit 14 and outputting it to the movement control unit 31 in the form of a trajectory plan or the like, and outputting other information acquired from the internal recognition unit 14 to the movement control unit 31 as unprocessed information.

[0250] Therefore, the interaction between the recognition unit 10 and the control unit 30 in the physical IF layer of the causal loop shown in FIG. 5 is substantially realized.

[0251] (Fourth embodiment) As shown in Fig. 23, the fourth embodiment is a modification of the first embodiment. The second embodiment will be described, focusing on the differences from the first embodiment.

[0252] The driving system 402 of the fourth embodiment has a configuration that employs a domain-based architecture and realizes driving assistance up to level 2. An example of the detailed configuration of the driving system 402 at the technical level will be described with reference to Fig. 23 .

[0253] As in the first embodiment, the driving system 402 includes a plurality of sensors 41 and 42, a plurality of motion actuators 60, a plurality of HMI devices 70, and a plurality of processing systems. Each processing system is a domain controller that aggregates processing functions for each functional domain. The domain controller may have the same configuration as the processing system or ECU in the first embodiment. For example, the driving system includes an ADAS domain controller 451, a powertrain domain controller 452, a cockpit domain controller 453, a connectivity domain controller 454, and the like as processing systems.

[0254] The ADAS domain controller 451 aggregates functions related to ADAS (Advanced Driver-Assistance Systems). The ADAS domain controller 451 may compositely realize part of the recognition function, part of the determination function, and part of the control function. The part of the recognition function realized by the ADAS domain controller 451 may be, for example, a function corresponding to the fusion unit 13 of the first embodiment or a simplified function thereof. The part of the determination function realized by the ADAS domain controller 451 may be, for example, a function corresponding to the environment determination unit 21 and the driving planner 22 of the first embodiment or a simplified function thereof. The part of the control function realized by the ADAS domain controller 451 may be, for example, a function corresponding to the motion control unit 31 of the first embodiment, which generates request information for the motion actuator 60.

[0255] Specifically, the functions realized by the ADAS domain controller 451 are functions that provide driving assistance in non-dangerous scenarios, such as a lane keeping assist function that makes the host vehicle 1 travel along white lines, and a following distance maintaining function that keeps a predetermined distance from another preceding vehicle that is ahead of the host vehicle 1. In addition, the functions realized by the ADAS domain controller 451 are functions that provide appropriate responses in dangerous scenarios, such as a collision damage mitigation braking function that applies the brakes when there is an imminent collision with another road user or an obstacle, and an automatic steering avoidance function that avoids a collision by steering when there is an imminent collision with another road user or an obstacle.

[0256] The powertrain domain controller 452 aggregates functions related to the control of the powertrain. The powertrain domain controller 452 may compositely realize at least a part of the recognition function and at least a part of the control function. A part of the recognition function realized by the powertrain domain controller 452 may be, for example, a function corresponding to the internal recognition unit 14 of the first embodiment, which recognizes the driver's operation state with respect to the motion actuator 60. A part of the control function realized by the powertrain domain controller 452 may be, for example, a function corresponding to the motion control unit 31 of the first embodiment, which controls the motion actuator 60.

[0257] The cockpit domain controller 453 aggregates cockpit-related functions. The cockpit domain controller 453 may compositely realize at least a part of the recognition function and at least a part of the control function. A part of the recognition function realized by the cockpit domain controller 453 may be, for example, a function of the internal recognition unit 14 of the first embodiment that recognizes the switch state of the HMI device 70. A part of the control function realized by the cockpit domain controller 453 may be, for example, a function corresponding to the HMI output unit 71 of the first embodiment.

[0258] The connectivity domain controller 454 aggregates connectivity-related functions. The connectivity domain controller 454 may implement at least a portion of the recognition function in a composite manner. Part of the recognition function implemented by the connectivity domain controller 454 may be a function to organize and convert the global position data, V2X information, etc. of the host vehicle 1 acquired from the communication system 43 into a format usable by the ADAS domain controller 451, for example.

[0259] Even in the fourth embodiment, for example, under operating conditions in which the ADAS domain controller 451 activates applications such as collision mitigation braking and automatic steering avoidance, it is possible to use at least one of the performance limit range R2 and the stable controllable range R1.

[0260] (Other embodiments) Although multiple embodiments have been described above, the present disclosure should not be construed as being limited to those embodiments, and can be applied to various embodiments and combinations within the scope that does not deviate from the gist of the present disclosure.

[0261] For example, in the first embodiment, the stable controllable range R1 may be defined according to the nominal performance of the entire driving system 2, and the performance limit range R2 may be defined according to the robust performance of the entire driving system 2. In the first embodiment, the stable controllable range R1 may be defined according to the nominal performance of the determination unit 20, and the performance limit range R2 may be defined according to the robust performance of the determination unit 20.

[0262] The controller and methods described herein may be implemented by a special-purpose computer comprising a processor programmed to perform one or more functions embodied in a computer program. Alternatively, the apparatus and methods described herein may be implemented by special-purpose hardware logic circuitry. Alternatively, the apparatus and methods described herein may be implemented by one or more special-purpose computers comprising a processor executing a computer program in combination with one or more hardware logic circuits. Furthermore, the computer program may be stored as instructions executed by a computer on a computer-readable non-transitory storage medium.

[0263] (Terminology explanation) The following describes terms related to the present disclosure, which are included in the embodiments of the present disclosure.

[0264] A road user may be a person who uses a road, including sidewalks and other adjacent spaces. A road user may be a road user on or adjacent to an active road for the purpose of traveling from one place to another.

[0265] A dynamic driving task (DDT) may be a real-time operational and tactical function for operating a vehicle in traffic.

[0266] An automated driving system may be a collection of hardware and software capable of executing the entire DDT on a continuous basis, whether or not it is limited to a specific operational design domain.

[0267] SOTIF (safety of the intended functionality) may be the absence of undue risk due to insufficient functionality of the intended functionality or its implementation.

[0268] A driving policy may be a strategy and rules that define control behavior at the vehicle level.

[0269] Vehicle motion may be the vehicle state and its dynamics captured in terms of physical quantities (for example, speed and acceleration).

[0270] A situation may be a factor that can affect the behavior of the system, and may include conditions, traffic conditions, weather, and the behavior of the ego-vehicle.

[0271] The estimation of the situation may involve reconstructing a group of parameters representing the situation in an electronic system from the situation obtained from a sensor.

[0272] A scenario may be a depiction of the temporal relationships between several scenes in a sequence of scenes, including the goals and values ​​in a particular situation influenced by actions and events. A scenario may be a depiction of a continuous time series of activities that integrates a subject vehicle, all of its external environments, and their interactions in the process of performing a particular driving task.

[0273] The behavior of the host vehicle may be an interpretation of the vehicle motion in terms of traffic conditions.

[0274] A triggering condition may be a specific condition of a scenario that acts as a catalyst for subsequent system responses that contribute to unsafe behavior, failure to prevent, detect, and mitigate reasonably foreseeable indirect misuse.

[0275] A proper response may be an action that resolves a dangerous situation when other road users are acting in accordance with assumptions about reasonably foreseeable behavior.

[0276] A hazardous situation may be a scenario that represents an increased level of risk present for DDT unless preventative action is taken.

[0277] A safe situation may be a situation within the performance limits within which the system can ensure safety. Note that a safe situation is a design concept due to the definition of the performance limits.

[0278] A minimal risk maneuver (MRM) may be the ability of an (automated) driving system to transition a vehicle between nominal and minimal risk conditions.

[0279] A DDT fallback may be a response by the driver or an automated system to execute a DDT or transition to a minimal risk condition after detecting a fault or insufficiency, or upon detection of potentially dangerous behavior.

[0280] The performance limit may be a design limit within which the system can achieve its objectives. The performance limit may be set for multiple parameters.

[0281] An operational design domain (ODD) may be the specific conditions in which a given (automated) driving system is designed to function. An operational design domain may be the operating conditions in which a given (automated) driving system or feature is specifically designed to function, including, but not limited to, environmental, geographic, and time-of-day constraints, and / or the presence or absence of specific traffic or roadway features.

[0282] The (stable) controllable range may be a range of design values ​​within which the system can continue to perform its intended purpose. The (stable) controllable range can be set for multiple parameters.

[0283] A minimal risk condition (MRC) may be a condition of the vehicle to reduce the risk of not being able to complete a given trip. A minimal risk condition may be a condition that a user or an automated driving system places on the vehicle after performing an MRM to reduce the risk of a collision if a given trip cannot be completed.

[0284] A takeover may be the transfer of the driving task between the automated driving system and the driver.

[0285] An unreasonable risk may be a risk that is judged to be unacceptable in a particular situation according to reasonable social and moral concepts.

[0286] The permissible time may be a period during which a state that is within the performance limit range and outside the stable controllable range may continue. The permissible time may be set in design by taking into consideration (and evaluating) robust performance.

[0287] Reacting vehicle behavior refers to changes in the behavior of the vehicle in response to changing conditions, and may be control based on control actions determined by external factors such as other road users.

[0288] (Additional remarks) The present disclosure also includes the following technical ideas based on the above embodiments.

[0289] <Technical feature 1> A method for evaluating a driving system of a moving object, the driving system including a recognition system, a judgment system, and a control system as subsystems, comprising: Evaluating the nominal performance of the recognition system; Evaluating the nominal performance of the decision system; evaluating the nominal performance of the control system.

[0290] <Technical feature 2> A method for evaluating a driving system of a moving object, the driving system including a recognition system, a judgment system, and a control system as subsystems, comprising: Evaluating the nominal performance of the decision system; and evaluating the robust performance of the judgment system taking into account at least one of the errors of the recognition system and the errors of the control system.

[0291] <Technical feature 3> A method for evaluating a driving system of a moving object, the driving system including a recognition system, a judgment system, and a control system as subsystems, comprising: Independently assessing the nominal performance of the recognition system, the nominal performance of the decision system, and the nominal performance of the control system; and evaluating the robust performance of the entire driving system so as to include in the evaluation targets a combined factor between the recognition system and the judgment system, a combined factor between the judgment system and the control system, and a combined factor between the recognition system and the control system.

[0292] <Technical feature 4> A method for designing a driving system for a moving object, the driving system including a recognition system, a judgment system, and a control system as subsystems, comprising: setting a stable controllable range of the control state of the moving object based on the nominal performance of the recognition system and the nominal performance of the control system; and setting an allowable time for allowing a state in which the control state is within a performance limit range and outside a stable controllable range, based on evaluating the robust performance of the judgment system taking into account at least one of an error in the recognition system and an error in the judgment system.

[0293] <Technical feature 5> A processing system including at least one processor for realizing a dynamic motion task of a moving object, The processor defining a performance limit range, which is a range bounded by the performance limit of the driving system, and a stable controllable range, which is a range within the performance limit range that can maintain stable control, as ranges that indicate the control state of the moving body; and determining whether a minimum risk can be guaranteed or not in accordance with a range of control states in performing a best effort as a control action.

[0294] <Technical feature 6> A processing system including at least one processor for realizing a dynamic motion task of a moving object, The processor Obtaining a perceived situation regarding external factors; When the behavior of the moving object is in an unstable state due to an event caused by an external factor, determining whether or not it is possible to return the behavior to a stable state; and deriving a control action for the mobile object as a reaction to the recognized situation, such that control is switched according to the judgment.

[0295] <Technical feature 7> A processing system including a processor for realizing a dynamic motion task of a moving object, The processor When the behavior of the moving object is in an unstable state, determining whether or not it is possible to return the behavior to a stable state; and if it determines that it is possible to return the behavior to a stable state, performing a transient response.

[0296] <Technical feature 8> A processing device that includes at least one processor and an interface and executes processing related to a dynamic motion task of a moving object, The processor Obtaining information about the stability of the behavior of the moving object through the interface; Setting constraints for switching control related to the dynamic driving task in response to information about the stability of the behavior of the moving object; and outputting the constraints through an interface.

[0297] <Technical feature 9> An SoC that integrates memory, a processor, and an interface into a single chip, Obtaining information about the stability of the behavior of the moving object through the interface; setting constraints for the driving system to switch control in accordance with information on the stability of the behavior of the moving object; and an SoC configured to output the constraints through an interface and execute the SoC.

[0298] <Technical feature 10> A recording device for recording the state of a driving system of a moving body, The driving system performed its best effort as a control action, and and a recording device that records information on whether the behavior of the mobile object is in a stable state or an unstable state, which information is used to determine whether to execute best efforts.

[0299] <Technical feature 11> 1. A method for generating data for recording a state of an operating system of a vehicle, comprising: generating data indicating that the driving system performed a best effort control action; and generating data to be paired with the data, the data indicating the control state of the mobile body used in the decision to execute best effort.

[0300] <Technical feature 12> A recording device for recording the state of a driving system of a moving body, The driving system performed a transient response as a control action, and A recording device that records information on whether the behavior of the moving object is in a stable state or an unstable state, which information is used to determine whether to execute a transient response.

[0301] <Technical feature 13> 1. A method for generating data for recording a state of an operating system of a vehicle, comprising: generating data indicative of the operational system having performed a transient response as a control action; generating data to be paired with the data, the data indicating the control state of the moving object used in the decision to execute the transient response.

[0302] <Technical feature 14> A processing device including at least one processor for use in an operating system (2) having a recognition system (10), a judgment system (20), and a control system (30) as subsystems, The processor Determining whether the control state of the moving object is within a first range (R1) set based on the nominal performance of the moving object itself or a subsystem; Determining whether the control state of the moving object is within a second range (R2) set based on the robust performance of the moving object itself or a subsystem; A processing device that derives and executes a control action for the moving object so as to switch the control depending on these ranges.

[0303] According to this, since the control is switched by determining the control state based on the ranges R1 and R2, it is possible to match the performance of the operation system 2 or the subsystem with the control that is suitable for it, thereby improving the reliability of the control action.

[0304] <Technical feature 15> The processor determining whether the driving system is within a design operational region that is outside the first range and within the second range; In the derivation, the processing device described in Technical Feature 14 derives a control action for the moving body so as to switch control depending on these ranges and the operation design domain.

[0305] <Technical feature 16> The processor A processing device according to Technical Feature 15, which derives a best effort that can guarantee minimal risk as the driving action when the driving system deviates from the operation design domain.

Claims

1. A method executed by at least one processor (51b) for realizing a dynamic motion task in a driving system (2, 202, 302, 402) of a moving object (1), comprising: defining a performance limit range (R2) that is a range bounded by the performance limit of the driving system, and a stable controllable range (R1) within the performance limit range in which stable control can be maintained, as ranges that indicate the control state of the moving body; determining whether the control state is within or outside the stable controllable range; deriving a control action for the moving object so as to switch control in accordance with the determination; and estimating a situation in which the moving body is placed, determining the range is performed based on the situation; A method according to claim 1, wherein in the defining, the performance limit range and the stable controllable range are set based on a difference between the situation estimated by the processor and the real world.

2. A method executed by at least one processor (51b) for realizing a dynamic motion task in a driving system (2, 202, 302, 402) of a moving object (1), comprising: defining a performance limit range (R2) that is a range bounded by the performance limit of the driving system, and a stable controllable range (R1) within the performance limit range in which stable control can be maintained, as ranges that indicate the control state of the moving body; determining whether the control state is within or outside the stable controllable range; deriving a control action for the moving object so as to switch control in accordance with the determination; setting an allowable time used as a condition for switching the control action, the allowable time being used to allow a continuous state within the performance limit range and outside the stable controllable range.

3. A method executed by at least one processor (51b) for realizing a dynamic motion task in a driving system (2, 202, 302, 402) of a moving object (1), comprising: defining a performance limit range (R2) that is a range bounded by the performance limit of the driving system, and a stable controllable range (R1) within the performance limit range in which stable control can be maintained, as ranges that indicate the control state of the moving body; determining whether the control state is within or outside the stable controllable range; deriving a control action for the moving object so as to switch control in accordance with the determination; determining the ranges includes determining the ranges for a plurality of parameters; setting, for each of the parameters, an allowable time for allowing a continuous state within the performance limit range and outside the stable controllable range, which is used as a condition for switching the control action; In the setting, the allowable time set for one parameter among the plurality of parameters is dynamically changed in accordance with the range determination for the other parameters.

4. A method executed by at least one processor (51b) for realizing a dynamic motion task in a driving system (2, 202, 302, 402) of a moving object (1), comprising: defining a performance limit range (R2) that is a range bounded by the performance limit of the driving system, and a stable controllable range (R1) within the performance limit range in which stable control can be maintained, as ranges that indicate the control state of the moving body; determining whether the control state is within or outside the stable controllable range; deriving a control action for the moving object so as to switch control in accordance with the determination; The stable controllable range is defined according to the nominal performance of the driving system or a subsystem thereof; The method, wherein the performance limit range is defined according to the robust performance of the operating system or the subsystem.

5. A method executed by at least one processor (51b) for realizing a dynamic motion task in a driving system (2, 202, 302, 402) of a moving object (1), comprising: defining a performance limit range (R2) that is a range bounded by the performance limit of the driving system, and a stable controllable range (R1) within the performance limit range in which stable control can be maintained, as ranges that indicate the control state of the moving body; determining whether the control state is within or outside the stable controllable range; deriving a control action for the moving object so as to switch control in accordance with the determination; If the operational design domain is the operating conditions under which the automated driving system is designed to function, then: A method of defining the performance limit range and the stable controllable range so that the operation design domain of the operation system is within the performance limit range and outside the stable controllable range.

6. A processing system including at least one processor (51b) for realizing a dynamic motion task of a moving body (1), The processor: defining a performance limit range (R2) that is a range bounded by the performance limit of the driving system of the moving body, and a stable controllable range (R1) within the performance limit range in which stable control can be maintained, as ranges that indicate the control state of the moving body; determining whether the control state is within or outside the stable controllable range; deriving a control action for the moving object so as to switch control in accordance with the determination; and estimating a situation in which the moving object is located; determining the range is performed based on the situation; In the defining step, the performance limit range and the stable controllable range are set based on a difference between the situation estimated by the processor and the real world.

7. A processing system including at least one processor (51b) for realizing a dynamic motion task of a moving body (1), The processor: defining a performance limit range (R2) that is a range bounded by the performance limit of the driving system of the moving body, and a stable controllable range (R1) within the performance limit range in which stable control can be maintained, as ranges that indicate the control state of the moving body; determining whether the control state is within or outside the stable controllable range; deriving a control action for the moving object so as to switch control in accordance with the determination; setting an allowable time to allow a continuous state that is within the performance limit range and outside the stable controllable range, which is used as a condition for switching the control action.

8. A processing system including at least one processor (51b) for realizing a dynamic motion task of a moving body (1), The processor: defining a performance limit range (R2) that is a range bounded by the performance limit of the driving system of the moving body, and a stable controllable range (R1) within the performance limit range in which stable control can be maintained, as ranges that indicate the control state of the moving body; determining whether the control state is within or outside the stable controllable range; deriving a control action for the moving object so as to switch control in response to the determination; determining the ranges includes determining the ranges for a plurality of parameters; setting, for each of the parameters, an allowable time for allowing a continuous state within the performance limit range and outside the stable controllable range, which is used as a condition for switching the control action; In the setting, the processing system dynamically changes the allowable time set for one parameter among the plurality of parameters in accordance with the range determination for the other parameters.

9. A processing system including at least one processor (51b) for realizing a dynamic motion task of a moving body (1), The processor: defining a performance limit range (R2) that is a range bounded by the performance limit of the driving system of the moving body, and a stable controllable range (R1) within the performance limit range in which stable control can be maintained, as ranges that indicate the control state of the moving body; determining whether the control state is within or outside the stable controllable range; deriving a control action for the moving object so as to switch control in response to the determination; The stable controllable range is defined according to the nominal performance of the driving system or a subsystem thereof; A processing system, wherein the performance limit range is defined according to the robust performance of the operating system or the subsystem.

10. A processing system including at least one processor (51b) for realizing a dynamic motion task of a moving body (1), The processor: defining a performance limit range (R2) that is a range bounded by the performance limit of the driving system of the moving body, and a stable controllable range (R1) within the performance limit range in which stable control can be maintained, as ranges that indicate the control state of the moving body; determining whether the control state is within or outside the stable controllable range; deriving a control action for the moving object so as to switch control in response to the determination; If the operational design domain is the operating conditions under which the automated driving system is designed to function, then: A processing system that, in the defining step, defines the performance limit range and the stable controllable range so that the operation design domain of the operation system is within the performance limit range and outside the stable controllable range.

11. determining whether the control state is within or outside the performance limit range; 11. The processing system according to claim 6, wherein, in deriving the control action, the control action is switched based on a switching condition set in response to a determination result of whether the control state is within the stable controllable range, within the performance limit range and outside the stable controllable range, or outside the performance limit range.

12. 12. The processing system of claim 11, wherein deriving the control action performs a minimal risk maneuver when the control state satisfies a condition indicating that the control state continues to be within the performance limit range and outside the stable controllable range.

13. 12. The processing system of claim 11, wherein when the control state is outside the performance limit range, best efforts are made to derive the control action, attempting to minimize risk as far as the operating system can control.

14. determining the ranges includes determining the ranges for a plurality of parameters; 11. The processing system according to claim 6, wherein the plurality of parameters include a state parameter indicating a current state of the control state, and a state change parameter indicating a state change of the control state.

15. A recording device for recording the state of an operating system (2, 202, 302, 402) of a moving body (1), comprising: As a range indicating the control state of the moving body, a performance limit range (R2) is a range bounded by the performance limit of the driving system, and a stable controllable range (R1) is a range within the performance limit range in which stable control can be maintained. The driving system has performed a minimal risk maneuver; and a recording device that records information that is used in determining whether to execute the MRM and indicates which range of the range the control state is in, determined based on the situation estimated by the driving system.

16. an allowable time for allowing the control state to continue within the performance limit range and outside the stable controllable range is included in the determination conditions for executing the MRM; 16. The recording device according to claim 15, further recording that the allowable time has been exceeded when the state in which the control state is within the performance limit range and outside the stable controllable range continues beyond the allowable time.

17. The operation system determines which range each of the plurality of parameters indicating the control state falls within, 17. The recording device of claim 16, further recording that when a state in which a parameter among the plurality of parameters is within the performance limit range and outside the stable controllable range continues beyond the allowable time, other parameters are within the stable controllable range, and the entire control state is within the performance limit range, the recording device further records that the control state is in a state in which it is possible to return the control state to within the stable controllable range.

Citation Information

Patent Citations

  • Systems, devices, and methods for predictive risk-aware driving

    US20210009121A1