Driving system

The method and system balance performance and safety in vehicle operations by predicting the behavior of other road users, setting specific ranges for performance and safety, and monitoring operations, addressing the compromise in existing techniques.

JP2026048797APending Publication Date: 2026-03-17DENSO CORP
View PDF 1 Cites 0 Cited by

Patent Information

Authority / Receiving Office
JP · JP
Patent Type
Applications
Current Assignee / Owner
Filing Date
2025-12-10
Publication Date
2026-03-17

AI Technical Summary

Technical Problem

Existing techniques for predicting the movement trajectory of objects in relation to a vehicle's driving plan and monitoring compromise the original target performance, potentially leading to unreasonable risks.

Method used

A method and system that balance performance and safety by independently predicting the future behavior of other road users, setting performance achievement and safety assurance ranges, and monitoring operations accordingly.

Benefits of technology

Achieves a balance between performance and safety by ensuring reasonably foreseeable safety while maintaining target performance metrics such as fuel efficiency, passenger comfort, and vibration damping.

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure 2026048797000001_ABST
    Figure 2026048797000001_ABST
Patent Text Reader

Abstract

To provide a processing method and operating system that balance performance and safety. [Solution] The host mobile unit includes a performance achievement prediction S20 that predicts the future behavior of other road users in the external environment of the host mobile unit as a prediction for achieving target performance, an operation plan S40 that plans the operation of the host mobile unit according to the performance achievement prediction, a safety assurance prediction S50 that predicts the future behavior of other road users in the external environment independently of the performance achievement prediction as a prediction for ensuring reasonably foreseeable safety in the host mobile unit, and an operation monitoring S70 that monitors the operation of the host mobile unit according to the safety assurance prediction.
Need to check novelty before this filing date? Find Prior Art

Description

Cross-reference to Related Applications ,

[0005] , , , ,

[0006] , , , ,

[0001] This application is based on Patent Application No. 2022-61926 filed in Japan on April 1, 2022, and the contents of the base application are hereby incorporated by reference in their entirety.

Technical Field

[0002] The present disclosure relates to a technique for performing processing related to the operation of a host moving body.

Background Art

[0003] The technique disclosed in Patent Document 1 predicts the movement trajectory of an object that becomes another road user with respect to a vehicle as a host moving body, and uses the predicted movement trajectory for the driving plan and driving monitoring of the vehicle.

Prior Art Documents

Patent Documents

[0004]

Patent Document 1

Summary of the Invention

[0005] However, in the technique disclosed in Patent Document 1, since the movement trajectory of the object is predicted by a common model that emphasizes safety for both the driving plan and the driving monitoring, there is a concern that the original target performance of the vehicle may be impaired. Therefore, conversely, if prediction that emphasizes target performance is performed, there is a concern that unreasonable risks may be incurred.

[0006] An object of the present disclosure is to provide a processing method for achieving a balance between performance and safety. Another object of the present disclosure is to provide a driving system for achieving a balance between performance and safety. Still another object of the present disclosure is to provide a processing device for achieving a balance between performance and safety. Yet another object of the present disclosure is to provide a processing program for achieving a balance between performance and safety.

[0007] The following describes the technical means of solving the problem described in this disclosure.

[0008] The first aspect of this disclosure is, A processing method executed by a processor to perform processing related to the operation of a host mobile body, As a prediction for achieving target performance in the host mobile device, performance achievement prediction involves predicting the future behavior of other road users in the external environment of the host mobile device, An operation plan that plans the operation of the host mobile unit according to performance achievement predictions, As a prediction to ensure reasonably foreseeable safety in a host mobile device, safety assurance predictions are made that predict the future behavior of other road users in the external environment independently of performance achievement predictions. This includes operational monitoring that monitors the operation of the host mobile device according to safety assurance predictions, Performance achievement prediction is, This process includes setting a performance achievement range (Rp), which is the range of future actions required to achieve a target performance that includes at least one of the following: fuel efficiency, passenger comfort, vibration damping, relaxation, and speed, using predictions of the future actions of other road users. Safety assurance forecasts are This process includes setting the boundaries of the safe range (Rs), which is the range in which risks deemed unacceptable in the host mobile device's situation are predicted to occur, using predictions of the future behavior of other road users.

[0009] A second aspect of this disclosure is, An operating system having a processor and performing processing related to the operation of a host mobile body, The processor is, As a prediction for achieving target performance in the host mobile device, performance achievement prediction involves predicting the future behavior of other road users in the external environment of the host mobile device, An operation plan that plans the operation of the host mobile unit according to performance achievement predictions, As a prediction to ensure reasonably foreseeable safety in a host mobile device, safety assurance predictions are made that predict the future behavior of other road users in the external environment independently of performance achievement predictions. The system performs operational monitoring that monitors the operation of the host mobile device according to safety assurance predictions. Performance achievement prediction is, This process includes setting a performance achievement range (Rp), which is the range of future actions required to achieve a target performance that includes at least one of the following: fuel efficiency, passenger comfort, vibration damping, relaxation, and speed, using predictions of the future actions of other road users. Safety assurance forecasts are The system is configured to include a process that uses predictions of the future behavior of other road users to set the boundaries of the safe range (Rs), which is the range in which risks deemed unacceptable in the host mobile device's situation are predicted to occur.

[0010] A third aspect of this disclosure is: A processing device having a processor, configured to be mountable on a host mobile body, and performing processing related to the operation of the host mobile body, The processor is, As a prediction for achieving target performance in the host mobile device, performance achievement prediction involves predicting the future behavior of other road users in the external environment of the host mobile device, An operation plan that plans the operation of the host mobile unit according to performance achievement predictions, As a prediction to ensure reasonably foreseeable safety in a host mobile device, safety assurance predictions are made that predict the future behavior of other road users in the external environment independently of performance achievement predictions. The system performs operational monitoring that monitors the operation of the host mobile device according to safety assurance predictions. Performance achievement prediction is, This process includes setting a performance achievement range (Rp), which is the range of future actions required to achieve a target performance that includes at least one of the following: fuel efficiency, passenger comfort, vibration damping, relaxation, and speed, using predictions of the future actions of other road users. Safety assurance forecasts are The system is configured to include a process that uses predictions of the future behavior of other road users to set the boundaries of the safe range (Rs), which is the range in which risks deemed unacceptable in the host mobile device's situation are predicted to occur.

[0011] The fourth aspect of this disclosure is: A processing program that includes instructions stored in a storage medium and executed by a processor in order to perform processing related to the operation of a host mobile body, As a prediction for achieving target performance in the host mobile device, performance achievement prediction involves predicting the future behavior of other road users in the external environment of the host mobile device, An operation plan that plans the operation of the host mobile unit according to performance achievement predictions, As a prediction to ensure reasonably foreseeable safety in a host mobile device, safety assurance predictions are made that predict the future behavior of other road users in the external environment independently of performance achievement predictions. This includes an instruction to perform operation monitoring, which monitors the operation of the host mobile device in accordance with safety assurance predictions, Performance achievement prediction is, This process includes setting a performance achievement range (Rp), which is the range of future actions required to achieve a target performance that includes at least one of the following: fuel efficiency, passenger comfort, vibration damping, relaxation, and speed, using predictions of the future actions of other road users. Safety assurance forecasts are This process includes setting the boundaries of the safe range (Rs), which is the range in which risks deemed unacceptable in the host mobile device's situation are predicted to occur, using predictions of the future behavior of other road users.

[0012] In the host mobile bodies of these first to fourth aspects, as a prediction for achieving the target performance, the driving plan is executed according to the performance achievement prediction that predicts the future behavior of other road users in the external environment of the host mobile body. Therefore, in the host mobile bodies of the first to fourth aspects, as a prediction for ensuring reasonably foreseeable safety, the driving monitoring is executed according to the safety guarantee prediction that predicts the future behavior of other road users independently from the performance achievement prediction. According to this, by monitoring the driving of the host mobile body planned according to the performance achievement prediction according to the safety guarantee prediction, it becomes possible to balance performance and safety for the driving.

Brief Description of the Drawings

[0013] [Figure 1] It is a block diagram showing the physical architecture of the driving system according to the first embodiment. [Figure 2] It is a schematic diagram showing the driving environment of the host vehicle to which the first embodiment is applied. [Figure 3] It is a block diagram showing the functional architecture of the driving system according to the first embodiment. [Figure 4] It is a schematic diagram for explaining the performance achievement range and the safety range according to the first embodiment. [Figure 5] It is a schematic diagram for explaining the performance achievement range and the safety range according to the first embodiment. [Figure 6] It is a flowchart showing the processing flow according to the first embodiment. [Figure 7] It is a characteristic table for explaining the performance achievement prediction and the safety guarantee prediction according to the first embodiment. [Figure 8] It is a block diagram showing the functional architecture of the driving system according to the second embodiment. [Figure 9] It is a flowchart showing the processing flow according to the second embodiment. [Figure 10] It is a block diagram showing the functional architecture of the driving system according to the third embodiment. [Figure 11] It is a flowchart showing the processing flow according to the third embodiment. [Modes for carrying out the invention]

[0014] Hereinafter, several embodiments of this disclosure will be described with reference to the drawings. In each embodiment, the same reference numerals will be used for corresponding components, and redundant explanations may be omitted. Furthermore, if only a part of the configuration is described in each embodiment, the configuration of other embodiments described earlier may be applied to the other parts of that configuration. Moreover, not only the combinations of configurations explicitly stated in the description of each embodiment, but also the configurations of multiple embodiments may be partially combined even if not explicitly stated, as long as there are no particular problems with the combination.

[0015] (First Embodiment) The first embodiment of the driving system DS shown in Figure 1 is configured to include a processing system 1 in order to perform processing related to the operation of the host mobile body (hereinafter referred to as "driving processing"). Part or all of the driving system DS is mounted on the host mobile body.

[0016] In the driving system DS, the host mobile entity targeted for driving processing is the host vehicle 2 shown in Figure 2. The host vehicle 2 is, for example, a road user such as a car or truck that is capable of autonomous driving. The host vehicle 2 may also be referred to as the ego-vehicle. Driving in the host vehicle 2 is divided into levels according to the scope of tasks performed by the driver, who is the occupant in the driver's seat, out of all dynamic driving tasks (DDTs). Here, a driver who is capable of performing DDTs through manual operation of the host vehicle 2 according to the autonomous driving level is a vehicle operator, and can also be said to be a vehicle user.

[0017] Automated driving levels are defined, for example, in SAE J3016. Specifically, in levels 0-2, the driver performs some or all of the DDT (Driver-Driver Task). Levels 0-2 may also be classified as so-called manual driving. Level 0 indicates that driving is not automated. Level 1 indicates that the driver is assisted by the driving system (DS). Level 2 indicates that driving is partially automated. In levels 3 and above, the driving system (DS) performs all of the DDT while it is engaged. Levels 3-5 may also be classified as so-called automated driving. A driving system (DS) capable of performing driving at level 3 or higher may be called an automated driving system. Level 3 indicates that driving is conditionally automated. Level 4 indicates that driving is highly automated. Level 5 indicates that driving is fully automated. A driving system (DS) that is not capable of performing driving at level 3 or higher, but capable of performing driving at least one of levels 1 and 2, may be called a driver assistance system. In the following, unless there are circumstances to identify the maximum possible level of autonomous driving, it will be assumed that the autonomous driving system or driver assistance system is included in the driver system DS.

[0018] In relation to such a host vehicle 2, other road users 3 are road users other than host vehicle 2 that exist in the external environment in which host vehicle 2 travels. Other road users 3 include non-vulnerable road users such as cars, trucks, motorcycles, and bicycles, as well as vulnerable road users such as pedestrians. Other road users 3 may also include animals.

[0019] In the physical architecture shown in Figure 1, the driving system DS has an actuator system 4, a sensor system 5, a communication system 6, a map database (DB) 7, an information interface (IF) system 8, and a processing system 1 as its physical components. However, the driving system DS only needs to include the processing system 1 as its own physical components, and at least one of the physical components belonging to the actuator system 4, sensor system 5, communication system 6, map DB 7, and information IF system 8 may be replaced by a physical component belonging to the host vehicle 2.

[0020] The actuator system 4 is configured to control the operation of the host vehicle 2 based on the input control signal. The actuator system 4 may be at least one type of powertrain actuator, such as an internal combustion engine and a motor-generator motor. The actuator system 4 may be at least one type of braking actuator, such as a brake unit. The actuator system 4 may be at least one type of steering actuator, such as a power steering unit.

[0021] The sensor system 5 acquires sensor data usable by the driving system DS by detecting the external and internal environments of the host vehicle 2. To this end, the sensor system 5 includes an external environment sensor 50 and an internal environment sensor 52.

[0022] The external environment sensor 50 may detect targets present in the external environment of the host vehicle 2. The target detection type external environment sensor 50 is at least one of the following: a camera, LiDAR (light detection and ranging / laser imaging detection and ranging), laser radar, millimeter-wave radar, and ultrasonic sonar. Typically, multiple types of target detection type external environment sensors 50 are implemented in combination to enable sensing in the front, side, and rear directions of the host vehicle 2. The external environment sensor 50 may also detect the atmospheric conditions in the external environment of the host vehicle 2. The atmospheric detection type external environment sensor 50 is at least one of the following: an outside temperature sensor and a humidity sensor.

[0023] The internal environment sensor 52 may detect specific physical quantities related to vehicle motion (hereinafter referred to as motion physical quantities) in the internal environment of the host vehicle 2. The motion physical quantity detection type internal environment sensor 52 is at least one of the following: a speed sensor, an acceleration sensor, and a gyro sensor. The internal environment sensor 52 may also detect the state of occupants in the internal environment of the host vehicle 2. The occupant detection type internal environment sensor 52 is at least one of the following: an actuator sensor, a driver status monitor (registered trademark), a biosensor, a seating sensor, and an in-vehicle equipment sensor. Here, the actuator sensor is at least one of the following that detects the operation state of the occupants related to the actuator system 4 of the host vehicle 2: an activation switch, an accelerator sensor, a brake sensor, and a steering sensor.

[0024] Communication system 6 acquires communication data usable by the driving system DS via wireless communication. Communication system 6 may receive positioning signals from GNSS (global navigation satellite system) satellites present in the external environment of the host vehicle 2. A positioning type communication system 6 is, for example, a GNSS receiver. Communication system 6 may send and receive communication signals with a V2X system present in the external environment of the host vehicle 2. A V2X communication type communication system 6 is, for example, at least one of the following: a DSRC (dedicated short range communications) communication device and a cellular V2X (C-V2X) communication device. Here, V2X communication includes at least one of the following: communication with the communication system of another vehicle that is another road user 3 (V2V), communication with infrastructure equipment such as a communication device installed on a traffic light (V2I), communication with a mobile terminal of a pedestrian that is another road user 3 (V2P), and communication with a cloud network or mesh network (V2N). Communication system 6 may send and receive communication signals with a mobile terminal present in the internal environment of the host vehicle 2. The terminal communication type communication system 6 is at least one of the following: Bluetooth® devices, Wi-Fi® devices, and infrared communication devices.

[0025] Map DB7 stores map data available to the driving system DS. Map DB7 is configured to include at least one type of non-transitory tangible storage medium, such as semiconductor memory, magnetic media, and optical media. Map DB7 may also be the database of a locator that estimates the self-state quantities of the host vehicle 2, including its own position. Map DB may also be the database of a navigation unit that navigates the driving route of the host vehicle 2. Map DB7 may be constructed by a combination of multiple types of databases.

[0026] Map DB7 acquires and stores the latest map data, for example, through V2X communication with an external center via the communication system 6. The map data is digitized in two or three dimensions as data representing the driving environment of the host vehicle 2. As three-dimensional map data, high-precision digital map data may be used. The map data may include road data representing at least one type of information, such as the position coordinates, shape, and road surface condition of road structures. The map data may also include marking data representing at least one type of information, such as the position coordinates and shape of road signs, road markings, and lane markings attached to roads. The marking data included in the map data may represent landmarks, such as traffic signs, arrow markings, lane markings, stop lines, direction signs, landmark beacons, rectangular signs, business signs, or changes in road line patterns. The map data may also include structural data representing at least one type of information, such as the position coordinates and shape of buildings and traffic lights facing roads. The marking data included in the map data may represent landmarks such as streetlights, road edges, reflectors, poles, or the backs of road signs.

[0027] The information interface system 8 mediates the transmission of notification information related to driving processes between the occupants of the host vehicle 2, including the driver, and the driving system DS. For this purpose, the information interface system 8 includes an HMI (human machine interface) device 80.

[0028] The HMI device 80 may be configured to detect operations performed by the occupant in the host vehicle 2 to input their intentions to the driving system DS. The operation detection type HMI device 80 is at least one of the following: a push switch, a lever switch, and a touch panel. The operation detection type HMI device 80 may be replaced by an actuator sensor or the like as an internal environment sensor 52 in the sensor system 5. The HMI device 80 may be configured to detect gestures performed by the occupant in the host vehicle 2 to input their intentions to the driving system DS. The gesture detection type HMI device 80 may be replaced by a driver status monitor or the like as an internal environment sensor 52 in the sensor system 5.

[0029] The HMI device 80 may present notification information by stimulating the occupant's vision in the host vehicle 2. The visual information presentation type HMI device 80 is at least one of the following: HUD (head-up display), CID (center information display), MFD (multifunction display), combination meter, navigation unit, and illumination unit. The HMI device 80 may also present notification information by stimulating the occupant's hearing. The auditory information presentation type HMI device 80 is at least one of the following: speaker, buzzer, and vibration unit. The HMI device 80 may also present notification information by stimulating the occupant's tactile senses. The tactile information presentation type HMI device 80 is at least one of the following: steering wheel vibration unit, driver's seat vibration unit, steering wheel reaction force unit, accelerator pedal reaction force unit, brake pedal reaction force unit, and air conditioning unit.

[0030] The processing system 1 is connected to the actuator system 4, sensor system 5, communication system 6, map DB 7, and information IF system 8 via at least one of the following: LAN (local area network), wire harness, internal bus, and wireless communication line. The processing system 1 is comprised of at least one dedicated computer.

[0031] The dedicated computer constituting the processing system 1 may be an integrated ECU (electronic control unit) that integrates the driving control of the host vehicle 2. The dedicated computer constituting the processing system 1 may be a detection ECU that processes sensor data detected in the driving control of the host vehicle 2. The dedicated computer constituting the processing system 1 may be a recognition ECU that performs recognition in the driving control of the host vehicle 2. The dedicated computer constituting the processing system 1 may be a judgment ECU or a planning ECU that determines and plans the DDT in the driving control of the host vehicle 2. The dedicated computer constituting the processing system 1 may be a monitoring ECU that monitors the driving control of the host vehicle 2. The dedicated computer constituting the processing system 1 may be an evaluation ECU that evaluates the driving control of the host vehicle 2.

[0032] The dedicated computer constituting the processing system 1 may be a navigation ECU that navigates the driving route of the host vehicle 2. The dedicated computer constituting the processing system 1 may be a locator ECU that estimates self-state quantities, including the self-position of the host vehicle 2. The dedicated computer constituting the driving system DS may be an actuator ECU that controls the actuator system 4. The dedicated computer constituting the processing system 1 may be an HCU (HMI control unit) that controls the HMI equipment 80. The dedicated computer constituting the processing system 1 may be a storage ECU that controls data storage. The dedicated computer constituting the processing system 1 may be at least one external computer that constructs an external center or mobile terminal, etc., that can communicate via the communication system 6.

[0033] The dedicated computer comprising processing system 1 has at least one memory 10 and at least one processor 12. The memory 10 is at least one type of non-transitory tangible storage medium, such as semiconductor memory, magnetic media, and optical media, which non-temporarily stores programs and data that can be read by the computer. The processor 12 includes at least one type as a core, such as a CPU (central processing unit), GPU (graphics processing unit), and RISC (reduced instruction set computer)-CPU.

[0034] Memory 10 may be a storage device that selects and stores at least one type of data and information processed in the operating system DS. Memory 10 may be a volatile storage medium, such as RAM (random access memory), that temporarily stores at least one type of data and information processed in the operating system DS. Memory 10 may be a database for executing DDT in the operating system DS.

[0035] The memory 10 may be mounted on the circuit board in a way that makes it non-removable and non-replaceable. Examples of such configurations include an eMMC (embedded multimedia card) using flash memory. The memory 10 may also be configured to be removable and replaceable. Examples of such configurations include an SD card. The memory 10 may be integrated together with the processor 12 and input / output interfaces on a single chip to form a dedicated computer that constitutes the processing system 1 as a SoC (system on a chip).

[0036] The processor 12 executes multiple instructions contained in the processing program stored as software in the memory 10. In this way, the driving system DS, including the processing system 1, constructs multiple functional blocks for performing the driving process of the host vehicle 2. Thus, in the driving system DS, the processing program stored in the memory 10 causes the processor 12 to execute multiple instructions in order to perform the driving process of the host vehicle 2, primarily through the processing system 1, thereby constructing multiple functional blocks. These multiple functional blocks constructed in the driving system DS include the recognition block 100, the decision block 120, the monitoring block 140, and the control block 160, which are shown as a functional architecture in Figure 3.

[0037] The recognition block 100 acquires sensor data from the sensor system 5. The recognition block 100 acquires communication data from the communication system 6. The recognition block 100 acquires map data from the map DB 7. The recognition block 100 processes these acquired data individually and then fuses them to recognize the internal and external environment of the host vehicle 2.

[0038] In generating recognition information, the recognition block 100 acquires data from the sensor system 5, the communication system 6, and the map DB 7, understands the meaning of the acquired data, and recognizes the internal and external environment, including the external environment of the host vehicle 2, its own position within that environment, and the internal environment of the host vehicle 2, by fusing the acquired data. Based on the recognition of the internal and external environment, the recognition block 100 generates recognition information to be provided to the subsequent decision block 120 and monitoring block 140. The recognition block 100 may provide substantially the same recognition information to the decision block 120 and the monitoring block 140. The recognition block 100 may provide different recognition information to the decision block 120 and the monitoring block 140.

[0039] The recognition information generated by the recognition block 100 describes the state detected for each scene in the driving environment of the host vehicle 2. The recognition block 100 may also generate recognition information for objects, including other road users 3, obstacles, and structures, in the external environment of the host vehicle 2. The recognition information for an object may represent at least one of the following: distance, direction of motion, relative velocity, relative acceleration, size, estimated state by tracking detection, etc. The recognition information for an object may also represent the classification of the object, recognized based on the state of the object clustered by, for example, semantic segmentation. The recognition block 100 may also generate recognition information for a road by detecting the road that the host vehicle 2 will currently and in the future travel. The recognition information for a road may represent at least one of the following static structures: road surface, lane, road edge, and free space, etc.

[0040] The recognition block 100 may generate recognition information for the self-state quantities, including the host vehicle 2's own position, through localization that estimates and recognizes the self-state quantities. Simultaneously with the recognition information for the self-state quantities, the recognition block 100 may generate update data for map data relating to the host vehicle 2's route and feed this update data back to the map DB 7. The recognition block 100 may generate recognition information for markings associated with the host vehicle 2's route by detecting such markings. The recognition information for markings may represent at least one type of state, such as signs, lane markings, and traffic lights. The recognition information for markings may further represent traffic rules recognized or identified from the state of the markings. The recognition block 100 may generate recognition information for weather conditions by detecting the weather conditions for each scene in which the host vehicle 2 is driving. The recognition block 100 may generate recognition information for time by detecting the time for each driving scene in which the host vehicle 2 is driving.

[0041] The decision block 120 acquires recognition information from the recognition block 100. The decision block 120 may also acquire past driving control information from the subsequent control block 160. The decision block 120 may also acquire safety assurance information, described later, from the monitoring block 140. The decision block 120 includes a performance achievement prediction block 122 and a driving plan block 124 as sub-function blocks for planning the operation of the host vehicle 2 in accordance with predictions based on the acquired information.

[0042] The performance achievement prediction block 122 predicts the future actions of other road users 3 in the external environment of the host vehicle 2 in a time series. At this time, the performance achievement prediction block 122, through the subsequent driving plan block 124, makes a performance achievement prediction regarding the future actions of other road users 3 as a prediction for achieving the target performance in the host vehicle 2. The future actions predicted for performance achievement may include risky actions of other road users 3 that make potential risks in relation to the host vehicle 2 foreseeable. The future actions predicted for performance achievement may also be the future trajectory of other road users 3. Here, the future trajectory should preferably be predicted for performance achievement in such a way that it defines at least one type of kinetic physical quantity related to other road users 3 in a time series, such as position, velocity, acceleration, yaw rate, and direction of motion.

[0043] To perform such performance achievement predictions, the performance achievement prediction block 122 may be constructed using at least one of the following: a dedicated computer installed in the host vehicle 2 and a dedicated computer outside the host vehicle 2. The performance achievement prediction block 122 is constructed using a dedicated computer that is physically shared with the driving plan block 124, but it may also be constructed using a dedicated computer that is physically separate from the driving plan block 124. The performance achievement prediction block 122 is constructed using a dedicated computer that is physically separate from the recognition block 100, or it may be constructed using a dedicated computer that is physically shared with the recognition block 100.

[0044] The performance achievement prediction block 122 may interpret the driving environment, which is the situation in which the host vehicle 2 is located, as a basic process for performing performance achievement prediction. At this time, the performance achievement prediction block 122 may interpret the intentions and actions of other road users 3, which are dynamic objects, based on their classification, or it may interpret classifiable driving conditions. Here, the interpretation of the intentions and actions of other road users 3 may be an interpretation of action probabilities that depend on the intentions of other road users 3, such as the probability of changing lanes. The interpretation of driving conditions may be an interpretation of traffic rules and congestion conditions, for example. At least a part of this environmental interpretation that forms the basis of performance achievement prediction may be performed by the recognition block 100, and the interpretation results as recognition information may be provided to the performance achievement prediction block 122.

[0045] The performance achievement prediction block 122 may perform performance achievement prediction by using a statistical model that models the positive risk balance based on a risk-benefit evaluation of the social traffic environment (hereinafter, the statistical model of the positive risk balance will be specifically referred to as the risk balance model). The risk balance model may be designed based on social requirements such as traffic rules, as well as statistical data representing the contribution and / or probability distribution of actions that can reduce accident risk, in order to avoid the risk of unreasonable blame on others (i.e., the potential accident responsibility of other road users 3). The risk balance model may be designed as a road user behavior model that is unique to each place where road users can drive in the traffic environment. Such a risk balance model may be constructed in at least one form, such as a mathematical model that formalizes the social requirements, and a computer program that executes processing according to the mathematical model. The parameters of the risk balance model may be tuned based on past driving control information from the control block 160.

[0046] The performance achievement prediction block 122 sets the range of future actions (hereinafter referred to as the performance achievement range) Rp for achieving the target performance in the host vehicle 2, based on the prediction information obtained as a result of the performance achievement prediction, as illustrated in Figures 4 and 5. In other words, the performance achievement prediction can be said to be a prediction of future actions of other road users 3 in order to set the performance achievement range Rp so as to provide the vehicle motion necessary to achieve the target performance. Therefore, in the performance achievement prediction block 122 shown in Figure 3, the target performance that is emphasized may be selected from among multiple performances related to the host vehicle 2 for each scene in which the performance achievement range Rp is set according to the prediction information from the performance achievement prediction. In the performance achievement prediction block 122, a single specific performance related to the host vehicle 2 may be fixed as the target performance.

[0047] The target performance for which the performance achievement range Rp is set may be safety performance that is judged to be statistically and socially safe for the host vehicle 2. Here, safety performance may be judged based on the risk balance model used for performance achievement prediction.

[0048] The target performance subject to setting the performance achievement range Rp may be fuel efficiency, which is determined according to the energy efficiency expected of the host vehicle 2. Here, fuel efficiency may be defined as a concept that includes electric energy efficiency. Fuel efficiency may be determined using a statistical model modeled based on, for example, social real-world fuel efficiency evaluation data.

[0049] The target performance for which the performance achievement range Rp is set may be a safety performance required of the host vehicle 2, such as at least one of the following: occupant ride comfort performance and vibration damping performance in service vehicles. Here, safety performance may be determined using a statistical model modeled based on, for example, social market research data.

[0050] The target performance for which the performance achievement range Rp is set may be service performance required of the host vehicle 2, such as at least one of the following: relaxation performance in a tourist service vehicle, or express delivery performance in a delivery service vehicle. Here, service performance may be determined using a statistical model modeled based on, for example, accumulated data from each service provider that socially operates the service vehicle.

[0051] The performance achievement prediction block 122 sets the performance achievement range Rp with respect to these target performances. The performance achievement range Rp may be set based on the risk balance model or statistical model used to select the target performance, and may define an acceptable range of kinetic physical quantities necessary to impart the vehicle motion required to the host vehicle 2 to achieve the target performance. Here, the kinetic physical quantities that define the acceptable range for the performance achievement range Rp are, for example, the speed, acceleration, attitude angle, and distance from other road users 3 of the host vehicle 2 (Figures 4 and 5 show examples of acceleration), at least one of which will form the basis of the driving plan in the subsequent driving plan block 124. Setting such a performance achievement range Rp may be done by the driving plan block 124 prior to the driving plan described later.

[0052] The performance achievement prediction block 122 may output at least one of the prediction information obtained as described above and the setting information for the set performance achievement range Rp as performance achievement information to the memory 10. The memory 10 to which the performance achievement information is output may be installed in the host vehicle 2, or it may be installed outside the host vehicle 2, for example, at an external center, depending on the type of dedicated computer that constitutes the driving system DS. The output performance achievement information may be temporarily stored in the memory 10 and provided to the driving plan block 124. The output performance achievement information may be stored in the memory 10 as evidence information. The output performance achievement information may be read from the memory 10 that serves as the temporary storage location or the storage location for evidence information, and transmitted by the communication system 6 to outside the host vehicle 2, for example, at an external center.

[0053] The performance achievement information, which serves as evidence, may be stored in an unencrypted state, or it may be stored encrypted or hashed. The performance achievement information, which serves as evidence, may also be stored in memory 10 in association with behavior information that represents the actual behavior of the host vehicle 2 as past driving control information by the control block 160. The performance achievement information thus stored may be used as a lagging indicator for training a risk balance model, which serves as a predictive model for performance achievement prediction, or as a leading indicator for verifying and validating the risk balance model.

[0054] The driving plan block 124 plans the operation of the host vehicle 2 in accordance with the performance achievement prediction and performance achievement range Rp provided by the performance achievement prediction block 122. Therefore, the driving plan block 124 performs the driving plan based on the performance achievement information provided by the performance achievement prediction block 122.

[0055] The driving plan block 124 plans the route that the host vehicle 2 will travel in the future through driving control. That is, the driving plan block 124 implements the DDT function, which plans the route as a strategic function of the host vehicle 2. Based on recognition information that estimates the host vehicle 2's own position, the driving plan block 124 may plan at least one of the following: the route to the destination and the lane. In this case, the driving plan block 124 may plan at least one of the following: a lane change request and a deceleration request, based on the planned lane.

[0056] The driving plan block 124 plans the future behavior of the host vehicle 2 based on the planned route and lane, as well as the performance achievement information from the performance achievement prediction block 122. In other words, the driving plan block 124 implements a DDT function that plans the tactical behavior of the host vehicle 2. The behavior planning function of the driving plan block 124 may include a function to generate transition conditions related to the state transitions of the host vehicle 2. The transition conditions related to the state transitions of the host vehicle 2 may correspond to triggering conditions. Therefore, the behavior planning function may include a function to determine the state transitions of the application that implements DDT, and further, the state transitions of the driving behavior, based on the generated transition conditions.

[0057] The driving plan block 124 plans the future trajectory to be given to the host vehicle 2 along the planned route, based on the performance achievement information from the performance achievement prediction block 122. In other words, the driving plan block 124 implements a DDT function that plans the future trajectory for the host vehicle 2 to travel as a path plan. The future trajectory planned by the driving plan block 124 may specify at least one type of kinetic physical quantity related to the host vehicle 2 in a time series, such as position, velocity, acceleration, yaw rate, and direction of motion. The specified time series trajectory plan is suitable for constructing a scenario of future travel guided by the host vehicle 2. Therefore, the trajectory plan may include a function to select or switch the optimal path plan from among multiple path plans.

[0058] The driving plan block 124 may determine the transition of the driving mode according to the driver's intention based on at least one type of recognition information regarding the driver by the recognition block 100, such as intention estimation information and biometric information. The driving plan block 124 may also determine whether or not there is a driver malfunction based on at least one type of recognition information regarding the driver by the recognition block 100, such as intention estimation information and biometric information. The driving plan block 124 may also determine whether or not there is a malfunction in each physical component 1,4 to 8 by monitoring the driving system DS.

[0059] The driving plan block 124 may plan the adjustment of the automated driving level in the host vehicle 2 based on at least one of the following: performance achievement information from the performance achievement prediction block 122, driving mode transition judgment results, driver fault judgment results, driving system DS fault judgment results, future route planning results, future behavior planning results, and future trajectory planning results. The adjustment of the automated driving level may include a takeover / handover in which the DDT is transferred between the driving system DS and the driver as the driving mode transitions between automated driving and manual driving.

[0060] The handover between autonomous and manual driving may be implemented in scenarios involving entry into or exit from an operational design domain (ODD) where autonomous driving is performed, by defining the ODD. For example, in an exit scenario from an ODD, i.e., a handover scenario from autonomous to manual driving, an unreasonable situation where an unreasonable risk is deemed to exist could be cited as a use case. In this use case, the driving plan block 124 may plan a DDT fallback, in which a driver acting as a fallback backup user transitions the host vehicle 2 to a minimal risk condition (MRC) through manual driving.

[0061] The adjustment of the autonomous driving level planned by the driving plan block 124 may include degraded driving of the host vehicle 2. In the degraded driving scenario, an unreasonable situation is identified as a use case where a handover to manual driving would be deemed to pose an unreasonable risk. In this use case, the driving plan block 124 may plan best efforts to transition the host vehicle 2 to MRC through autonomous driving and autonomous stopping in order to minimize the harm or risk of an accident. Such best efforts may include adjustments that lower the autonomous driving level, as well as emergency maneuvers (emergency operations) such as DDT fallback or minimum risk maneuver (MRM) to reach MRC as a safe state, as adjustments that maintain the autonomous driving level. At this time, notification associated with the emergency operation, for example by the information IF system 8, may be planned to increase the visibility of the transition status to MRC both inside and outside the host vehicle 2.

[0062] The driving plan block 124 further plans the driving control of the host vehicle 2 according to at least the route plan, behavior plan, track plan, and driving level plan described above. In planning the driving control, control commands related to the navigation operation of the host vehicle 2 and the driver assistance operation are generated as control actions. That is, the driving plan block 124 realizes the DDT function, which plans the motion control requests of the host vehicle 2. The control commands generated by the driving plan block 124 may include control parameters for controlling the actuator system 4. Such control planning may be performed by the control block 160 prior to the driving control described later.

[0063] The monitoring block 140 acquires recognition information from the recognition block 100. The monitoring block 140 may also acquire past driving control information from the subsequent control block 160. The monitoring block 140 includes a safety assurance prediction block 142 and a driving constraint block 144 as sub-function blocks for setting constraints on the driving of the host vehicle 2 by monitoring the driving of the host vehicle 2 in accordance with predictions based on the acquired information.

[0064] The safety assurance prediction block 142 predicts the future actions of other road users 3 in the external environment of the host vehicle 2 in a time series. At this time, the safety assurance prediction block 142 performs a safety assurance prediction regarding the future actions of other road users 3 as a prediction to ensure reasonably foreseeable safety for the host vehicle 2 through the subsequent driving constraint block 144. The future actions that are predicted for safety assurance may include risky actions that make potential risks in relation to the host vehicle 2 foreseeable. The future actions that are predicted for safety assurance may also be the future trajectory of other road users 3. Here, the future trajectory is preferably predicted for safety assurance so that at least one type of kinetic physical quantity relating to other road users 3, such as position, velocity, acceleration, yaw rate, and direction of motion, is defined in a time series. The safety assurance prediction made by the safety assurance prediction block 142 may be a prediction of the near future than the performance achievement prediction made by the performance achievement prediction block 122. In other words, the performance achievement prediction made by the performance achievement prediction block 122 may be a prediction that precedes the safety assurance prediction made by the safety assurance prediction block 142 in terms of the time axis.

[0065] To realize such safety assurance predictions, the safety assurance prediction block 142 may be constructed using at least one type of dedicated computer installed in the host vehicle 2. The safety assurance prediction block 142 is constructed using a dedicated computer that is physically shared with the driving constraint block 144, but it may also be constructed using a dedicated computer that is physically separate from the driving constraint block 144. The safety assurance prediction block 142 is constructed using a dedicated computer that is physically separate from the recognition block 100, but it may also be constructed using a dedicated computer that is physically shared with the recognition block 100.

[0066] The safety assurance prediction block 142 is constructed on a dedicated computer that is physically separate from the performance achievement prediction block 122, but it may also be constructed on a dedicated computer that is physically shared with the performance achievement prediction block 122. Here, if each prediction block 142, 122 is constructed on a separate dedicated computer, it is preferable that the safety assurance prediction by the safety assurance prediction block 142 be physically independent from the performance achievement prediction by the performance achievement prediction block 122. On the other hand, if each prediction block 142, 122 is constructed on a common dedicated computer, it is preferable that the safety assurance prediction by the safety assurance prediction block 142 be functionally independent in software from the performance achievement prediction by the performance achievement prediction block 122. In either case, independence of the safety assurance prediction from the performance achievement prediction means that the prediction information from the performance achievement prediction is not substantially used for the safety assurance prediction.

[0067] However, if each prediction block 142,122 is constructed by separate dedicated computers, the performance achievement prediction by the performance achievement prediction block 122 may be physically independent from the safety assurance prediction by the safety assurance prediction block 142, or the prediction information from the safety assurance prediction may be physically transmitted and used between the dedicated computers. On the other hand, if each prediction block 142,122 is constructed by a common dedicated computer, the performance achievement prediction by the performance achievement prediction block 122 may be functionally independent from the safety assurance prediction by the safety assurance prediction block 142, or the prediction information from the safety assurance prediction may be functionally used.

[0068] The safety assurance prediction block 142 may interpret the driving environment, which is the situation in which the host vehicle 2 is located, as a basic process for performing safety assurance prediction. In this case, the environmental interpretation by the safety assurance prediction block 142 may be implemented in accordance with the environmental interpretation by the performance achievement prediction block 122. The environmental interpretation by the safety assurance prediction block 142 may also be implemented independently of the environmental interpretation by the performance achievement prediction block 122. For example, in a scene where lane structures such as lanes exist, a situation in which the risk of rear-end collisions and head-on collisions is potentially assumed in the longitudinal direction, and a situation in which the risk of side collisions is potentially assumed in the lateral direction may be interpreted. In these longitudinal and lateral environmental interpretations, state quantities relating to the host vehicle 2 and other road users 3 may be transformed into a coordinate system that assumes straight lanes. On the other hand, in a scene where lane structures do not exist, a situation in which the risk of the trajectory colliding in any direction of the host vehicle 2 is potentially assumed may be interpreted.

[0069] The environmental interpretation that forms the basis of these safety assurance predictions may be performed in part by the recognition block 100, and the interpretation result as recognition information may be provided to the safety assurance prediction block 142. In this case, the environmental interpretation that forms the basis of the performance achievement prediction may also be performed in part by the recognition block 100, and a common interpretation result may be provided to both the safety assurance prediction block 142 and the performance achievement prediction block 122.

[0070] The safety assurance prediction block 142 may perform safety assurance predictions to conform to the driving policy by using a safety model described in accordance with the driving policy and its safety. Here, the driving policy followed by the safety model is defined based on a vehicle-level safety strategy (VLSS) that guarantees the safety of the intended functionality (SOTIF). In other words, the safety model is described by following the driving policy that implements the VLSS and by modeling the SOTIF. The safety model may be designed to avoid potential accident liability resulting from unreasonable risks or misuse by road users in accordance with accident liability rules. For example, the safety model may be a responsibility-sensitive safety model that complies with accident liability rules that follow the driving policy.

[0071] The safety model may be defined as the safety-related model itself, which expresses the safety-related aspects of behavioral probabilities based on assumptions about the reasonably foreseeable behavior of other road users 3, or it may be defined as a model that constitutes a part of the safety-related model. Such a safety model may be constructed in at least one form, such as a mathematical model that formalizes vehicle-level safety, or a computer program that performs processing according to the mathematical model. The parameters of the safety model may be tuned by training using a machine learning algorithm such as a DNN, which propagates past driving control information from the control block 160 back to the safety model.

[0072] The safety assurance prediction block 142 may assume a reasonably foreseeable safety range Rs between the host vehicle 2 and the other road user 3, as illustrated in Figures 4 and 5, as a prediction of the future behavior of other road users 3 based on a safety model. In this case, the safety assurance prediction block 142 may assume a safety range Rs to avoid the risk of unreasonable self-blame (i.e., potential accident liability of the host vehicle 2), based on a safety model that complies with accident liability rules. Here, the safety range Rs may be defined as the range in which an unreasonable risk is predicted to occur if the performance limit of the driving system DS is exceeded as its boundary. In other words, the boundary of the safety range Rs may mean the most stringent safety conditions assumed according to the safety model.

[0073] The safety assurance prediction block 142 shown in Figure 3 sets the boundary of the safety range Rs to ensure reasonably foreseeable safety in the host vehicle 2, based on the prediction information obtained as a result of the safety assurance prediction. In other words, the safety assurance prediction can be said to be a prediction of the future behavior of other road users 3 for setting the boundary of the reasonably foreseeable safety range Rs in the host vehicle 2. Here, the kinetic physical quantities that define the boundary of the safety range Rs are, for example, the speed, acceleration, attitude angle of the host vehicle 2, and the distance from other road users 3 (Figures 4 and 5 show examples of acceleration), at least one of which will form the basis for driving monitoring and driving constraints in the subsequent driving constraint block 144. Such setting of the boundary of the safety range Rs may be performed by the driving constraint block 144 prior to the driving monitoring and constraint setting described later.

[0074] In setting the boundary of the safety range Rs using the safety assurance prediction block 142, a safety envelope based on a safety model between the host vehicle 2 and other road users 3 may be assumed. Here, the safety envelope may be defined as a set of restrictions and conditions that the driving system DS is designed to act as a constraint or control to maintain operation within an acceptable level of risk. Such a safety envelope may be set as a physically based margin around each road user, including the host vehicle 2 and other road users 3, by critical or limit values ​​of the kinetic physical quantities that give its boundary.

[0075] In assuming a safety envelope, the safety distance may be determined from a profile of at least one type of kinetic physical quantity, based on a safety model for the host vehicle 2 and other road users 3, assuming they follow a driving policy. In this case, the safety distance may be assumed to define a boundary that ensures a physically based margin around the host vehicle 2 for the motion of other road users 3 predicted based on the safety model. The safety distance may also be assumed to take into account the reaction time until each road user performs a proper response. For example, in scenes where lane structures such as lanes exist, the safety distance to avoid the risk of rear-end and head-on collisions in the longitudinal direction of the host vehicle 2, and the safety distance to avoid the risk of side collisions in the lateral direction of the host vehicle 2 may be calculated. On the other hand, in scenes where lane structures do not exist, the safety distance to avoid the risk of trajectory collisions in any direction of the host vehicle 2 may be calculated.

[0076] The safety assurance prediction block 142 may output at least one of the prediction information obtained as described above and the boundary information of the set safety range Rs as safety assurance information to the memory 10. Depending on the type of dedicated computer that constitutes the driving system DS, the memory 10 to which the safety assurance information is output may be installed in the host vehicle 2 or installed outside the host vehicle 2, for example, in an external center. The output safety assurance information may be temporarily stored in the memory 10 and provided to the driving constraint block 144. The output safety assurance information may be stored in the memory 10 as evidence information. The output performance achievement information may be read from the memory 10 that serves as a temporary storage location or as an evidence information storage location and transmitted via the communication system 6 to outside the host vehicle 2, for example, in an external center.

[0077] The safety assurance information that serves as evidence information may be stored in an unencrypted state, or it may be stored encrypted or hashed. The safety assurance information that serves as evidence information may be stored in memory 10 in association with behavior information that represents the actual behavior of the host vehicle 2 as past driving control information by the control block 160. The safety assurance information that serves as evidence information may also be stored in memory 10 in association with performance achievement information by the performance achievement prediction block 122. The safety assurance information thus stored may be used as a lagging indicator for training a safety model that serves as a prediction model for safety assurance prediction, or as a leading indicator for verifying and validating the safety model.

[0078] The driving constraint block 144 sets constraints on the driving control of the host vehicle 2, which is monitored according to the safety assurance prediction and the boundary of the safety range Rs provided by the safety assurance prediction block 142. The driving constraint block 144 then performs driving control monitoring and constraint setting based on the safety assurance information provided by the safety assurance prediction block 142. At this time, the necessity of setting constraints may be monitored depending on whether or not there is a violation of the safety envelope assumed in the setting of the safety range Rs by the safety assurance prediction block 142. In this case, if a safety distance is assumed as the safety envelope, a determination may be made that there is no violation of the safety envelope if the actual distance between the host vehicle 2 and the other road user 3 exceeds the safety distance. On the other hand, a determination may be made that there is a violation of the safety envelope if the actual distance between the host vehicle 2 and the other road user 3 is less than or equal to the safety distance.

[0079] The driving constraint block 144 may calculate a rational scenario by simulation that provides the host vehicle 2 with an appropriate response when it determines that there is a violation of the safety envelope. In the simulation of the rational scenario, the state transitions between the host vehicle 2 and other road users 3 are estimated, and the actions to be taken for each transition state may be set as constraints (described in detail later) on the host vehicle 2. In setting the actions in this case, it is preferable that a limit value is calculated that restricts at least one type of kinetic physical quantity to be given to the host vehicle 2 as a constraint on the host vehicle 2.

[0080] The control block 160 obtains control commands from the driving plan block 124 of the judgment block 120. The control block 160 obtains constraint information from the driving constraint block 144 of the monitoring block 140. If no constraints are set by the driving constraint block 144, the control block 160 controls the operation of the host vehicle 2 according to the planned control commands. That is, the control block 160 implements a DDT function that provides control actions to the host vehicle 2. For example, use cases in which constraints are set by the driving constraint block 144 include situations where the operation is planned within the performance achievement range Rp, which is within the boundary of the safety range Rs, as shown by the cross-hatching in Figure 4. In this case, the control block 160 may use recognition information such as vehicle motion regarding the host vehicle 2, obtained from the recognition block 100 or via the judgment block 120, for vehicle control.

[0081] In response, the control block 160, when it has obtained constraint information from the driving constraint block 144, imposes constraints on the planned driving control of the host vehicle 2. For example, use cases in which constraints are set by the driving constraint block 144 include planned driving conditions within the performance achievement range Rp but exceeding the boundary of the safety range Rs, as shown by the cross-hatching in Figure 5. Here, the constraints on driving control may be functional constraints or degraded constraints. The constraints on driving control may also be constraints other than these. In any case, the constraints on driving control may be given by limiting the control command. At this time, if a reasonable scenario is simulated by the driving constraint block 144, the control command may be limited according to that scenario. Furthermore, if limit values ​​are set for the kinetic physical quantities of the host vehicle 2, the control parameters of the actuator system 4 included in the control command may be corrected based on those limit values.

[0082] (Processing flow) In the first embodiment, a processing method flow (hereinafter referred to as the processing flow) for performing the operation process of the host vehicle 2 according to the flowchart shown in Figure 6 is repeatedly executed by the joint efforts of multiple blocks 100, 120, 140, and 160. In the following description, each "S" in the processing flow refers to multiple steps executed by multiple instructions included in the processing program.

[0083] In S100, the recognition block 100 generates recognition information by recognizing the internal and external environment of the host vehicle 2. After the execution of S10, the performance achievement sequences S20, S30, and S40 and the safety assurance sequences S50, S60, and S70 are executed in parallel.

[0084] In S20 of the performance achievement sequence, the decision block 120 uses the performance achievement prediction block 122 to make a performance achievement prediction regarding the future actions of other road users 3 as a prediction for achieving the target performance of the host vehicle 2. At this time, the performance achievement prediction is realized based on a risk balance model. In S30 of the performance achievement sequence, the decision block 120 uses the performance achievement prediction block 122 to set the performance achievement range Rp for achieving the target performance of the host vehicle 2, according to the performance achievement prediction in S20. In S40 of the performance achievement sequence, the decision block 120 uses the driving plan block 124 to create a driving plan for the host vehicle 2 according to the performance achievement prediction in S20 and the performance achievement range Rp in S30.

[0085] Meanwhile, in S50 of the safety assurance sequence, the monitoring block 140 performs a safety assurance prediction regarding the future actions of other road users 3 using the safety assurance prediction block 142, as a prediction to ensure reasonably foreseeable safety in the host vehicle 2. At this time, the safety assurance prediction is realized based on a safety model. In S50 of the safety assurance sequence, the monitoring block 140 sets the boundary of the safety range Rs that ensures safety in the host vehicle 2 using the safety assurance prediction block 142, according to the safety assurance prediction in S50. In S70 of the safety assurance sequence, the monitoring block 140 performs driving monitoring and constraint setting of the host vehicle 2 according to the safety assurance prediction in S50 and the boundary of the safety range Rs in S60 using the driving constraint block 144.

[0086] In S80, which transitions from the performance achievement sequence of S20, S30, and S40, the control block 160 determines whether constraints have been set for the host vehicle 2 through the safety assurance sequence of S50, S60, and S70. If the result is negative, in S90 the control block 160 controls the host vehicle 2 according to the driving plan set in S40 of the performance achievement sequence. Conversely, if the result is positive, in S100 the control block 160 controls the host vehicle 2 to impose the constraints set in S70 of the safety assurance sequence on the driving planned in S40 of the performance achievement sequence. With the completion of S90 and S100, the current execution of the processing flow is completed.

[0087] In the above processing flow, the performance achievement prediction in S20 and the safety assurance prediction in S50 should be adapted to changes in the perception capabilities or perception performance of the host vehicle 2, respectively. Therefore, as shown in Figure 7, the performance achievement prediction in S20 and the safety assurance prediction in S50 may be adapted and executed in the following cases α to δ.

[0088] (α) A situation in which the visibility of other road users 3 by the recognition function of the driving system DS in host vehicle 2 is ensured in both past and present timings. (β) A situation in which the visibility of other road users 3 by the recognition function of the driving system DS in host vehicle 2 is restricted in past timings and ensured in present timings. (γ) A situation in which the visibility of other road users 3 by the recognition function of the driving system DS in host vehicle 2 is ensured in past timings and restricted in present timings. (δ) A situation in which the visibility of other road users 3 by the recognition function of the driving system DS in host vehicle 2 is restricted in both past and present timings.

[0089] In the following classification explanation, past timing may correspond to the execution timing of each prediction by S20 and S50 in at least one past execution that precedes the current execution of the processing flow. On the other hand, present timing may correspond to the execution timing of each prediction by S20 and S50 in the current execution of the processing flow.

[0090] In the classification explanation, the visibility of other road users 3 by the recognition function may be classified into situations where it is ensured regardless of the reliability defined using, for example, the detection accuracy of the sensor system 5, and situations where such assurance is restricted and cannot be ensured. Visibility may also be classified into situations where it is ensured by the reliability defined using, for example, the detection accuracy being above or exceeding a set level, and situations where it is restricted by the reliability being below or below a set level.

[0091] In the case of situation α, the performance achievement prediction in S20 may be based on recognition history, which can be interpreted from recognition information obtained by a recognition function that ensures visibility at both past and present timings, and in accordance with the risk balance model, the future behavior of other road users 3 may be predicted in the case of situation α, in the safety assurance prediction in S50, which may be based on recognition information such as position and speed obtained by a recognition function that ensures visibility at both past and present timings, and in accordance with the safety model, the future behavior of other road users 3 within the safety range Rs may be predicted in the case of situation α.

[0092] In the case of situation β, the performance achievement prediction in S20 may be based on recognition information obtained by a recognition function with guaranteed visibility at the present time, and the driving history of other road users 3 at past times when the visibility of the recognition function was limited, thereby realizing a prediction of the future behavior of other road users 3 according to a risk balance model. Here, the driving history at past times may be traffic flow recognition information obtained at the present time from other road users 3 or an external center via V2X communication through the communication system 6. In contrast, in the case of situation β, the safety assurance prediction in S50 may be based on recognition information such as position and speed obtained by a recognition function with guaranteed visibility at the present time, thereby realizing a prediction of the future behavior of other road users 3 within the safety range Rs according to a safety model.

[0093] In the case of situation γ, the performance achievement prediction in S20 may be based on historical information of the recognition history, which can be interpreted from recognition information obtained by a recognition function with guaranteed visibility at past timings, thereby realizing a prediction of the future behavior of other road users 3 in accordance with a risk balance model. In contrast, in the case of situation γ, the safety assurance prediction in S50 may be based on recognition information such as position and speed obtained by a recognition function with guaranteed visibility at past timings, thereby realizing a prediction of the future behavior of other road users 3, which is assumed to be moving within a safety range Rs in accordance with a safety model.

[0094] In the case of situation δ, the performance achievement prediction in S20 may be based on the driving history of other road users 3 at past timings when the visibility of the recognition function was limited, and the future behavior of other road users 3 may be predicted according to the risk balance model. Here, the driving history at past timings may be traffic flow recognition information acquired at the present timing via V2X communication, as in the case of situation β. In contrast, in the safety assurance prediction in S50 for situation δ, the future behavior prediction of other road users 3 may be based on the assumption that they move within the safety range Rs according to the safety model in places where the visibility of the recognition function is limited at either past or present timings, such as blind spots from the host vehicle 2.

[0095] As explained above, in the host vehicle 2 of the first embodiment, the driving plan is executed according to the performance achievement prediction, which predicts the future behavior of other road users 3 in the external environment of the host vehicle 2, as a prediction for achieving the target performance. Therefore, in the host vehicle 2 of the first embodiment, driving monitoring is executed according to the safety assurance prediction, which predicts the future behavior of other road users 3 independently of the performance achievement prediction, as a prediction for ensuring reasonably foreseeable safety. With this, the driving of the host vehicle 2, which is planned according to the performance achievement prediction, is monitored according to the safety assurance prediction, making it possible to balance performance and safety in that driving.

[0096] (Second embodiment) The second embodiment is a modification of the first embodiment.

[0097] As shown in Figure 8, in the functional architecture of the second embodiment, the function of acquiring constraint information from the driving constraint block 144 of the monitoring block 140 is implemented by the driving plan block 2124 of the decision block 2120 instead of the control block 2160. Therefore, when no constraints are set by the driving constraint block 144, the driving plan block 2124 plans the operation of the host vehicle 2 in accordance with the first embodiment. On the other hand, when constraints are set by the driving constraint block 144 and constraint information is acquired, the driving plan block 2124 imposes constraints on the driving plan at the stage of planning the operation of the host vehicle 2 in accordance with the first embodiment. In either case, the control block 2160 will execute the driving control of the host vehicle 2 planned by the driving plan block 2124.

[0098] As shown in Figure 9, in the processing flow of the second embodiment, in S2040 following S30 in the performance achievement sequence, the decision block 2120 uses the driving plan block 2124 to determine whether constraints have been set for the host vehicle 2 through the safety assurance sequences S50, S60, and S70. If a negative determination is made, in S2041 of the performance achievement sequence, the decision block 2120 uses the driving plan block 2124 to create a driving plan for the host vehicle 2 based on the performance achievement prediction from S20 and the performance achievement range Rp from S30. If an affirmative determination is made, in S2042 of the performance achievement sequence, the decision block 2120 uses the driving plan block 2124 to create a driving plan so as to impose constraints from the safety assurance sequence S70 on the operation of the host vehicle 2 based on the performance achievement prediction from S20 and the performance achievement range Rp from S30. In S2080, which is reached after either S2041 or S2042 has been completed, the control block 2160 controls the host vehicle 2 according to the driving plan from the step prior to the transition in S2041 or S2042. With the completion of S2080, the current execution of the processing flow is finished.

[0099] In the second embodiment described above, by following the principles explained in the first embodiment, it is possible to achieve a balance between performance and safety in the operation of the host vehicle 2.

[0100] (Third embodiment) The third embodiment is a modification of the second embodiment.

[0101] As shown in Figure 10, in the functional architecture of the second embodiment, the monitoring function and constraint setting function by the operation constraint block 3144 are implemented as part of the functions of the operation planning block 3124 of the decision block 3120. Therefore, the monitoring function and constraint setting function by the operation constraint block 3144 may be called in software for each of the multiple applications or in common for multiple applications while the planning function by the operation planning block 3124 is being executed. In this case, it is preferable that the safety assurance prediction function by the safety assurance prediction block 3142 be made independent not only from the performance achievement prediction by the performance achievement prediction block 122, but also from the operation planning by the operation planning block 3124 and the operation monitoring by the operation constraint block 3144.

[0102] As shown in Figure 11, in the processing flow of the third embodiment, in S3070, which is a common step for the performance achievement sequence and the safety assurance sequence, the decision block 3120 performs driving monitoring and constraint setting of the host vehicle 2 according to the safety assurance prediction in S50 and the boundary of the safety range Rs in S60, using the driving constraint block 3144. Then, in S3040, following S3070 in the performance achievement sequence, the decision block 3120 uses the driving plan block 3124 to determine whether constraints have been set for the host vehicle 2 through the safety assurance sequence of S50, S60, and S3070. If a negative determination is made, then in S3041 of the performance achievement sequence, the decision block 3120 uses the driving plan block 3124 to perform driving planning of the host vehicle 2 according to the performance achievement prediction in S20 and the performance achievement range Rp in S30. If a positive judgment is made in response to this, in S3042 of the performance achievement sequence, the decision block 3120 uses the operation planning block 3124 to create an operation plan, imposing constraints in S3070 on the operation of the host vehicle 2 according to the performance achievement prediction in S20 and the performance achievement range Rp in S30. Regardless of whether S3041 or S3042 is completed, the processing flow will proceed to S2080.

[0103] In the third embodiment described above, by following the principles explained in the first embodiment, it is possible to achieve a balance between performance and safety in the operation of the host vehicle 2.

[0104] (Other embodiments) Although several embodiments have been described above, this disclosure is not limited to those embodiments and can be applied to various embodiments and combinations without departing from the spirit of this disclosure.

[0105] In the modified example, the dedicated computer constituting the processing system 1 may have at least one of the digital circuit and the analog circuit as a processor. Here, the digital circuit is at least one of the following, for example, ASIC (application specific integrated circuit), FPGA (field programmable gate array), SOC (system on a chip), PGA (programmable gate array), and CPLD (complex programmable logic device). Such a digital circuit may also have a memory that stores a program.

[0106] In a modified example, the driver who acts as the operator among the occupants of the host vehicle 2 may be replaced by a remote operator or remote driver who remotely controls the host vehicle 2 from an external center. In a modified example, the host mobile body to which the driving system DS and processing system 1 are applied may be an autonomous mobile robot capable of transporting cargo or collecting information by autonomous or remote driving. In addition to the above, the processing system 1 in each embodiment and modified example may be implemented in the form of a processing circuit (e.g., a processing ECU) or a semiconductor device (e.g., a semiconductor chip) as a processing device configured to be mounted on the host mobile body and having at least one processor 12 and one memory 10.

[0107] (Explanation of terms) Terms related to this disclosure are defined below. This definition is included in embodiments of this disclosure.

[0108] A road user may be a person who uses a road, including sidewalks and other adjacent spaces. A road user may also be a user of an active road or an adjacent road for the purpose of moving from one place to another.

[0109] Other road users may include both vulnerable and non-vulnerable road users who do not perform the role of the autonomous vehicle.

[0110] A dynamic driving task (DDT) may be a real-time operational and tactical function for controlling a vehicle in traffic.

[0111] The behavior of the vehicle may be interpreted as vehicle motion in the context of traffic conditions. Here, vehicle motion may refer to the vehicle state and its dynamics as captured in terms of physical quantities (e.g., velocity and acceleration).

[0112] A scenario may depict the temporal relationships between several scenes within a series of scenes, including goals and values ​​in a specific situation influenced by actions and events. A scenario may also depict a continuous time-series of activities integrating the subject vehicle, all its external environment, and their interactions in the process of performing a specific driving task.

[0113] The "situation" refers to factors that may affect the system's behavior, and may include traffic conditions, weather, and the behavior of the vehicle itself.

[0114] A triggering condition may be a specific condition in a scenario that acts as a trigger for a subsequent system response that contributes to the inability to prevent, detect, or mitigate dangerous behavior or reasonably foreseeable indirect misuse.

[0115] The operational design domain (ODD) may be specific conditions designed for a given (autonomous) driving system to function. The operational design domain may be operating conditions specifically designed for a given (autonomous) driving system or feature to function, and may include, but are not limited to, environmental, geographical, and time constraints, and / or the necessary presence or absence of specific traffic or road features.

[0116] An automated driving system may be a set of hardware and software capable of continuously performing the entire DDT, regardless of whether it is limited to a specific ODD.

[0117] Safety of the intended functionality (SOTIF) may also be the absence of undue risk resulting from inadequacy of the intended functionality or its implementation.

[0118] A driving policy may be a set of strategies and rules that define control actions at the vehicle level.

[0119] A vehicle-level safety strategy (VLSS) may be a set of requirements for features under development used to support SOTIF-related design, verification, and validation activities.

[0120] An unreasonable risk may be one that is deemed unacceptable in a particular situation, according to reasonable social and moral concepts.

[0121] Safety-related models may represent safety-related aspects of driving behavior based on assumptions about the reasonably foreseeable behavior of other road users. Safety-related models may be onboard or offboard safety confirmation devices or safety analysis devices, mathematical models, sets of more conceptual rules, sets of scenario-based behaviors, or a combination thereof.

[0122] A safety envelope may be a set of limitations and conditions designed to ensure that the (autonomous) driving system operates as a constraint or control in order to maintain operation within an acceptable level of risk. The safety envelope may be a general concept that can be used to address all principles to which the driving policy may adhere, under which a vehicle operated by the (autonomous) driving system may have one or more boundaries around it.

[0123] A proper response may be an action that resolves a dangerous situation when other road users are acting in accordance with reasonably foreseeable assumptions about their behavior.

[0124] A safe state may be a reasonably safe operating mode.

[0125] Performance limits may be design limits that enable the system to achieve its objectives, and can be set for multiple parameters.

[0126] The minimum risk condition (MRC) may be a vehicle state that mitigates the risk of being unable to complete a given trip. The minimum risk condition may also be a state brought about by the user or (autonomous) driving system after performing a minimum risk operation to reduce the risk of collision if the given trip cannot be completed.

[0127] A minimal risk maneuver (MRM) may be a function of an (automatic) driving system that transitions between a nominal state and a minimal risk state.

[0128] DDT fallback may be a response by the driver or (automatic) driving system to transition to DDT or MRC after a failure occurs, after a malfunction is detected, or when potentially dangerous behavior is detected.

[0129] An emergency maneuver may be an operation performed by a vehicle in the event of an imminent risk of collision, with the aim of avoiding or mitigating the collision.

[0130] A takeover may also refer to the transfer of driving tasks between the (automated) driving system and the driver.

[0131] The driver may be a user who performs some or all of the DDT and / or DDT fallback for a particular vehicle in real time. The remote driver may be a driver who can operate the vehicle but is not seated in a position to manually operate the on-board brakes, accelerator, steering wheel, and transmission gear selector inputs.

[0132] The operator may be a designated person who has received appropriate training and authorization to operate the vehicle. The remote operator may be an operator who is not seated in a position to manually operate the vehicle's brakes, accelerator, steering wheel, and transmission gear selector inputs, but who can operate the vehicle with or without direct view.

[0133] V2X may also be a technology that augments vehicles to exchange additional information with infrastructure, other vehicles, and other road users.

[0134] This disclosure also includes the following technical ideas:

[0135] <Technical philosophy 1> A processing method performed by a processor (12) in order to carry out processing related to the operation of a host mobile device (2), As a prediction for achieving the target performance in the host mobile device, a performance achievement prediction is made that predicts the future behavior of other road users in the external environment of the host mobile device, An operation plan that plans the operation of the host mobile body according to the performance achievement prediction, As a prediction to ensure reasonably foreseeable safety in the host mobile body, a safety assurance prediction is made that predicts the future behavior of other road users in the external environment independently of the performance achievement prediction, A processing method including operation monitoring, which monitors the operation of the host mobile body in accordance with the safety assurance prediction.

[0136] <Technical philosophy 2> The aforementioned performance achievement prediction is, The processing method according to Technical Concept 1, which includes predicting the future behavior of other road users as a prediction for setting the performance achievement range (Rp) to achieve the target performance in the host mobile body.

[0137] <Technical philosophy 3> The aforementioned performance achievement prediction is, The processing method according to Technical Concept 1, which includes predicting the future behavior of other road users as a prediction to avoid the risk of unreasonable blame on others in the host mobile body.

[0138] <Technical philosophy 4> The aforementioned performance achievement prediction is, The processing method described in Technical Concept 1 includes predicting the future behavior of other road users as a prediction based on a statistical model that models the positive risk balance.

[0139] <Technical philosophy 5> The aforementioned performance achievement prediction is, The processing method according to technical concept 4, which includes predicting the future behavior of the other road users in accordance with the statistical model based on recognition information at the timing when visibility of the other road users is ensured by the recognition function of the driving system (DS) in the host mobile body.

[0140] <Technical philosophy 6> The aforementioned performance achievement prediction is, The processing method according to technical concept 5, which includes predicting the future behavior of the other road user based on the driving history acquired at the present time via V2X communication with respect to the other road user at the past time, when the visibility of the other road user by the recognition function of the driving system (DS) in the host mobile device is limited to past timing.

[0141] <Technical philosophy 7> The processing method described in Technical Concept 1 further includes outputting predictive information based on the performance achievement prediction.

[0142] <Technical philosophy 8> The aforementioned safety assurance forecast is The processing method according to technical concept 1, which includes predicting the future behavior of other road users as a prediction for setting a reasonably foreseeable safe range (Rs) boundary in the host mobile body.

[0143] <Technical philosophy 9> The aforementioned safety assurance forecast is The processing method according to Technical Concept 1, which includes predicting the future behavior of other road users as a prediction to avoid the risk of unreasonable self-inflicted harm in the host mobile body.

[0144] <Technical Thought 10> The aforementioned safety assurance forecast is The processing method described in Technical Concept 1 includes predicting the future behavior of other road users as a prediction based on a safety model that models the safety of the intended function.

[0145] <Technical Thought 11> The aforementioned safety assurance forecast is The processing method according to technical concept 10, which includes predicting the future actions of the other road users in accordance with the safety model, based on recognition information at the timing when visibility of the other road users is ensured by the recognition function of the driving system (DS) in the host mobile body.

[0146] <Technical Thought 12> The aforementioned safety assurance forecast is The processing method according to technical idea 11, which includes predicting the future behavior of the other road user, assuming that the other road user moves within a safe range (Rs) according to the safety model, when the visibility of the other road user by the recognition function of the driving system (DS) in the host mobile body is limited to the present timing.

[0147] <Technical Thought 13> The processing method according to Technical Concept 1 further includes outputting predictive information based on the aforementioned safety assurance prediction.

[0148] <Technical Thought 14> The aforementioned operation monitoring is, The processing method according to technical concept 1 further includes setting constraints on the operation of the host mobile body in accordance with the safety assurance prediction.

[0149] <Technical Thought 15> An operating system having a processor (12) that performs processing related to the operation of a host mobile unit (2), The aforementioned processor, As a prediction for achieving the target performance in the host mobile device, a performance achievement prediction is made that predicts the future behavior of other road users in the external environment of the host mobile device, An operation plan that plans the operation of the host mobile body according to the performance achievement prediction, As a prediction to ensure reasonably foreseeable safety in the host mobile body, a safety assurance prediction is made that predicts the future behavior of other road users in the external environment independently of the performance achievement prediction, An operating system configured to perform operation monitoring, which monitors the operation of the host mobile body in accordance with the safety assurance prediction.

[0150] <Technical Thought 16> A processing device having a processor (12), configured to be mounted on a host mobile body (2), and performing processing related to the operation of the host mobile body, The aforementioned processor, As a prediction for achieving the target performance in the host mobile device, a performance achievement prediction is made that predicts the future behavior of other road users in the external environment of the host mobile device, An operation plan that plans the operation of the host mobile body according to the performance achievement prediction, As a prediction to ensure reasonably foreseeable safety in the host mobile body, a safety assurance prediction is made that predicts the future behavior of other road users in the external environment independently of the performance achievement prediction, A processing device configured to perform operation monitoring, which monitors the operation of the host mobile body in accordance with the safety assurance prediction.

[0151] <Technical Thought 17> A processing program that includes instructions stored in a storage medium (10) and executed by a processor (12) in order to perform processing related to the operation of a host mobile device (2), As a prediction for achieving the target performance in the host mobile device, a performance achievement prediction is made that predicts the future behavior of other road users in the external environment of the host mobile device, An operation plan that plans the operation of the host mobile body according to the performance achievement prediction, As a prediction to ensure reasonably foreseeable safety in the host mobile body, a safety assurance prediction is made that predicts the future behavior of other road users in the external environment independently of the performance achievement prediction, A processing program including an instruction to perform operation monitoring, which involves monitoring the operation of the host mobile body in accordance with the safety assurance prediction.

Claims

1. A processing method performed by a processor (12) in order to carry out processing related to the operation of a host mobile unit (2), As a prediction for achieving the target performance in the aforementioned host mobile device, a performance achievement prediction is made that predicts the future behavior of other road users in the external environment of the aforementioned host mobile device, An operation plan that plans the operation of the host mobile body according to the performance achievement prediction, As a prediction to ensure reasonably foreseeable safety in the host mobile body, a safety assurance prediction is made that predicts the future behavior of other road users in the external environment independently of the performance achievement prediction, This includes operation monitoring that monitors the operation of the host mobile device in accordance with the safety assurance prediction, The aforementioned performance achievement prediction is, The process includes setting a performance achievement range (Rp), which is the range of future actions to achieve a target performance including at least one of the following: fuel efficiency, passenger ride comfort, vibration damping, relaxation performance, and speed performance, using the aforementioned predictions of the future actions of other road users. The aforementioned safety assurance forecast is A processing method that includes setting the boundary of a safe range (Rs), which is the range in which risks deemed unacceptable in the situation in which the host mobile body is located are predicted to occur, using the prediction of the future behavior of the aforementioned other road users.

2. The aforementioned performance achievement prediction is, The processing method according to claim 1, which includes predicting the future behavior of other road users as a prediction based on a statistical model that models the positive risk balance.

3. The aforementioned performance achievement prediction is, The processing method according to claim 2, which includes predicting the future behavior of the other road user in accordance with the statistical model based on recognition information at the timing when visibility of the other road user is ensured by the recognition function of the driving system (DS) in the host mobile body.

4. The aforementioned performance achievement prediction is, The processing method according to claim 3, which includes predicting the future behavior of the other road user based on the driving history acquired at the present time via V2X communication with respect to the other road user at the past time, when the visibility of the other road user by the recognition function of the driving system (DS) in the host mobile body is limited to past timing.

5. The processing method according to claim 1, further comprising outputting prediction information based on the performance achievement prediction.

6. The processing method according to claim 1, wherein the aforementioned risk is a potential liability risk that the host mobile body will be held responsible in the event of an accident.

7. The aforementioned safety assurance forecast is The processing method according to claim 1, which includes predicting the future behavior of other road users as a prediction based on a safety model that models the safety of the intended function.

8. The aforementioned safety assurance forecast is The processing method according to claim 7, which includes predicting the future actions of the other road users in accordance with the safety model, based on recognition information at the timing when visibility of the other road users is ensured by the recognition function of the driving system (DS) in the host mobile body.

9. The aforementioned safety assurance forecast is The processing method according to claim 8, which includes predicting the future behavior of the other road user, assuming that the other road user moves within a safe range (Rs) according to the safety model, when the visibility of the other road user by the recognition function of the driving system (DS) in the host mobile body is limited to the present timing.

10. The processing method according to claim 1, further comprising outputting prediction information based on the safety assurance prediction.

11. The aforementioned operation monitoring is, The processing method according to claim 1, further comprising setting constraints on the operation of the host mobile body in accordance with the safety assurance prediction.

12. An operating system having a processor (12) that performs processing related to the operation of a host mobile unit (2), The aforementioned processor, As a prediction for achieving the target performance in the aforementioned host mobile device, a performance achievement prediction is made that predicts the future behavior of other road users in the external environment of the aforementioned host mobile device, An operation plan that plans the operation of the host mobile body according to the performance achievement prediction, As a prediction to ensure reasonably foreseeable safety in the host mobile body, a safety assurance prediction is made that predicts the future behavior of other road users in the external environment independently of the performance achievement prediction, The operation of the host mobile unit is monitored according to the safety assurance prediction, and this operation monitoring is performed. The aforementioned performance achievement prediction is, The process includes setting a performance achievement range (Rp), which is the range of future actions to achieve a target performance including at least one of the following: fuel efficiency, passenger ride comfort, vibration damping, relaxation performance, and speed performance, using the aforementioned predictions of the future actions of other road users. The aforementioned safety assurance forecast is An operating system configured to include a process of setting the boundary of a safe range (Rs), which is the range in which risks deemed unacceptable in the situation in which the host mobile body is located are predicted to occur, using the prediction of the future behavior of the aforementioned other road users.

13. A processing device having a processor (12), configured to be mounted on a host mobile body (2), and performing processing related to the operation of the host mobile body, The aforementioned processor, As a prediction for achieving the target performance in the aforementioned host mobile device, a performance achievement prediction is made that predicts the future behavior of other road users in the external environment of the aforementioned host mobile device, An operation plan that plans the operation of the host mobile body according to the performance achievement prediction, As a prediction to ensure reasonably foreseeable safety in the host mobile body, a safety assurance prediction is made that predicts the future behavior of other road users in the external environment independently of the performance achievement prediction, The operation of the host mobile unit is monitored according to the safety assurance prediction, and this operation monitoring is performed. The aforementioned performance achievement prediction is, The process includes setting a performance achievement range (Rp), which is the range of future actions to achieve a target performance including at least one of the following: fuel efficiency, passenger ride comfort, vibration damping, relaxation performance, and speed performance, using the aforementioned predictions of the future actions of other road users. The aforementioned safety assurance forecast is A processing device configured to include a process of setting the boundary of a safe range (Rs), which is the range in which risks deemed unacceptable in the situation in which the host mobile body is located are predicted to occur, using the prediction of the future behavior of the aforementioned other road users.

14. A processing program that includes instructions stored in a storage medium (10) and executed by a processor (12) in order to perform processing related to the operation of a host mobile device (2), As a prediction for achieving the target performance in the aforementioned host mobile device, a performance achievement prediction is made that predicts the future behavior of other road users in the external environment of the aforementioned host mobile device, An operation plan that plans the operation of the host mobile body according to the performance achievement prediction, As a prediction to ensure reasonably foreseeable safety in the host mobile body, a safety assurance prediction is made that predicts the future behavior of other road users in the external environment independently of the performance achievement prediction, The command includes an instruction to perform operation monitoring, which monitors the operation of the host mobile body in accordance with the safety assurance prediction, The aforementioned performance achievement prediction is, The process includes setting a performance achievement range (Rp), which is the range of future actions to achieve a target performance including at least one of the following: fuel efficiency, passenger ride comfort, vibration damping, relaxation performance, and speed performance, using the aforementioned predictions of the future actions of other road users. The aforementioned safety assurance forecast is A processing program that includes the process of setting the boundary of a safe range (Rs), which is the range in which risks deemed unacceptable in the situation in which the host mobile body is located are predicted to occur, using the prediction of the future behavior of the aforementioned other road users.

Citation Information

Patent Citations

  • Systems, devices, and methods for predictive risk-aware driving

    US20210009121A1