vehicle
The vehicle system ensures stability and safety in autonomous driving by using redundant control paths and automatic deceleration to maintain control when primary paths fail, addressing the lack of fail-safe mechanisms in existing systems.
Patent Information
- Authority / Receiving Office
- JP · JP
- Patent Type
- Applications
- Current Assignee / Owner
- TOYOTA JIDOSHA KK
- Filing Date
- 2024-10-01
- Publication Date
- 2026-04-13
AI Technical Summary
Existing autonomous driving systems lack sufficient fail-safe mechanisms when multiple command paths fail, leading to instability in autonomous driving control.
The vehicle system is configured with redundant control paths and units to continue autonomous driving or perform automatic deceleration control if primary paths fail, ensuring stability and fail-safe operations.
This configuration enhances the stability and safety of autonomous driving by maintaining control through alternative paths and implementing automatic deceleration when primary paths fail, providing a robust fail-safe mechanism.
Smart Images

Figure 2026063953000001_ABST
Abstract
Description
Technical Field
[0005] ,
[0001] The present disclosure relates to a vehicle capable of mounting an autonomous driving kit.
Background Art
[0002] Japanese Patent Application Laid-Open No. 2024-106017 (Patent Document 1) discloses a vehicle capable of mounting an autonomous driving kit. This vehicle includes a vehicle control interface box and a vehicle system. The vehicle system is configured to be able to receive commands from the autonomous driving kit through each of a plurality of paths.
Prior Art Documents
Patent Documents
[0003]
Patent Document 1
Summary of the Invention
Problems to be Solved by the Invention
[0004] When any one of the plurality of paths described in Patent Document 1 fails, the non-failed path is selected and a command is transmitted through the selected path. According to such control, when any one of the plurality of paths fails, autonomous driving based on a command from the autonomous driving kit can be continued by the non-failed path. However, when a failure occurs in the command path from the autonomous driving kit to the vehicle system, it is not always preferable to continue the autonomous driving based on the command from the autonomous driving kit. Further, in Patent Document 1, sufficient consideration has not been given to the control when all paths fail.
[0005] The present disclosure has been made to solve the above problems, and an object thereof is to achieve both the stability of autonomous driving control based on a command from an autonomous driving kit and an appropriate fail-safe regarding the autonomous driving control.
Means for Solving the Problems
[0006] According to this disclosure, the following vehicles are provided:
[0007] (Section 1) The vehicle is configured to be equipped with an autonomous driving kit. The vehicle comprises a vehicle control interface box and a vehicle system. The vehicle control interface box includes a first control unit and a second control unit. The vehicle system includes a braking system for decelerating the vehicle. The vehicle system is configured to receive commands from the autonomous driving kit through each of a plurality of paths. The plurality of paths include a first path via the first control unit and a second path via the second control unit. The vehicle system is configured to continue autonomous driving based on commands from the autonomous driving kit received through the paths other than the lost path if only one of the plurality of paths fails during autonomous driving. The vehicle system is also configured to perform automatic deceleration control, which controls the braking system to decelerate the vehicle, if both the first and second paths fail during autonomous driving.
[0008] If only one of the multiple paths (command paths) from the autonomous driving kit to the vehicle system fails, it is highly likely to be an accidental failure. It is also possible that a momentary failure caused by a momentary voltage drop or noise was mistakenly detected as a permanent failure. Therefore, in the above configuration, in such cases, the vehicle system continues autonomous driving based on commands from the autonomous driving kit received through the other paths that have not failed. By enabling the continuation of autonomous driving based on commands from the autonomous driving kit, the stability of autonomous driving control is improved.
[0009] On the other hand, if failures occur in two or more routes, it becomes more likely that the failures are not accidental. Therefore, in the above configuration, if both the first and second routes fail during autonomous driving, the vehicle system executes the automatic deceleration control described above. This provides an appropriate fail-safe for autonomous driving control. Even if all routes fail, the vehicle system can execute the predetermined automatic deceleration control. Furthermore, the first and second routes pass through the first and second control devices, respectively. These first and second control devices make it easier to detect failures in the first and second routes.
[0010] Loss of the path from the autonomous driving kit to the vehicle system means that the vehicle loses the ability to transmit commands received from the autonomous driving kit to the vehicle system via that path. For example, if a communication line along the path is cut, the path is lost. Failure of the autonomous driving kit and / or vehicle control interface box along the path also constitutes a loss of the path, preventing commands from the autonomous driving kit from being transmitted to the vehicle system. Failure of the vehicle system's receiving function regarding the path from the autonomous driving kit to the vehicle system also constitutes a loss of the path, preventing the vehicle system from receiving commands from the autonomous driving kit.
[0011] (Section 2) In the vehicle described in Section 1, the vehicle system further includes a third control unit and a fourth control unit that control the braking system. The first path is a path through which a command from the autonomous driving kit reaches the third control unit via the first control unit. The second path is a path through which a command from the autonomous driving kit reaches the fourth control unit via the second control unit.
[0012] In the above configuration, the third control unit in the first path and the fourth control unit in the second path each control the braking system. Therefore, if both the first and second paths fail, the automatic deceleration control described above can be performed by either the third or fourth control unit. Even if one of the third or fourth control units fails, the braking system can be controlled by the other control unit that is not malfunctioning.
[0013] (Clause 3) In the vehicle described in paragraph 2, the multiple paths further include a third path through which a command from the autonomous driving kit reaches the third control unit via the second control unit. If the first path is not lost, the third control unit controls the brakes based on the command from the autonomous driving kit received through the first path. If the first path is lost and neither the second path nor the third path is lost, the third control unit controls the brakes based on the command from the autonomous driving kit received through the third path.
[0014] In the above configuration, if the first path is not lost, the third control unit controls the brake system based on commands received from the autonomous driving kit via the first path. If only the first path among the first to third paths is lost, the third control unit controls the brake system based on commands received from the autonomous driving kit via the third path. Even if the first path is lost, the third control unit can continue autonomous driving control (brake system control) based on commands from the autonomous driving kit. This improves the stability of autonomous driving control.
[0015] (Article 4) In the case of a vehicle described in Article 3, if both the first route and the third route become unavailable, the third control device or the fourth control device will perform automatic deceleration control.
[0016] In the above configuration, the aforementioned automatic deceleration control is executed not only when both the first and second routes fail, but also when both the first and third routes fail. This ensures both the stability of the automatic driving control based on commands from the automatic driving kit and appropriate fail-safe measures for the automatic driving control.
[0017] (Article 5) In any vehicle described in any one of paragraphs 1 to 4, the first control device is configured to determine whether or not communication between the autonomous driving kit and the first control device has been lost, and to output the result of that determination to the vehicle system. The second control device is configured to determine whether or not communication between the autonomous driving kit and the second control device has been lost, and to output the result of that determination to the vehicle system.
[0018] With the above configuration, the vehicle system can more easily detect failures in both the first and second routes.
[0019] (Section 6) In any vehicle described in any one of Sections 1 to 5, the vehicle control interface box is configured to enable or disable automatic deceleration control based on a request from the autonomous driving kit. The vehicle system is configured to perform automatic deceleration control only when automatic deceleration control is enabled.
[0020] In situations where the user (human) has sovereign control of the vehicle, the user can drive the vehicle, so automatic deceleration control does not need to be performed if both the first and second routes fail. For example, if the vehicle is not equipped with an autonomous driving kit, or if the autonomous driving kit installed on the vehicle is not functioning, the vehicle is driven manually by the user, so automatic deceleration control does not need to be performed. Therefore, in the above configuration, the vehicle control interface box switches the automatic deceleration control on or off based on a request from the autonomous driving kit. With this configuration, when the vehicle control interface box and the autonomous driving kit can communicate, the autonomous driving kit is more likely to appropriately set the enable / disable of automatic deceleration control. The autonomous driving kit may request the enable or disable of automatic deceleration control depending on the autonomous driving level. The autonomous driving level is defined, for example, by the Society of Automotive Engineers (SAE) standard "SAE J3016".
[0021] (Section 7) In the vehicle described in Section 6, the vehicle control interface box is configured to prohibit the switching of automatic deceleration control on or off during autonomous driving.
[0022] If the automatic deceleration control is switched on or off during autonomous driving, the autonomous driving control may become unstable. Therefore, by prohibiting the switching of the automatic deceleration control on or off during autonomous driving, as described above, the stability of the autonomous driving control is improved.
[0023] (Clause 8) In any vehicle described in any one of paragraphs 1 to 7, the vehicle system is configured to continue automatic deceleration control until the vehicle comes to a stop, without receiving any new commands from the autonomous driving kit while automatic deceleration control is being performed.
[0024] With the above configuration, the vehicle system can decelerate and bring the vehicle to a stop through automatic deceleration control without receiving new commands from the autonomous driving kit. This provides appropriate fail-safes for autonomous driving control.
[0025] (Item 9) In the vehicle according to any one of Items 1 to 8, when the automatic driving kit transmits a deceleration command requesting the vehicle to decelerate and it is determined that both the first path and the second path are defective, in the automatic deceleration control, the braking device is controlled so that the deceleration of the vehicle approaches the larger one of the deceleration required by the deceleration command and a predetermined deceleration.
[0026] According to the above configuration, the vehicle can be decelerated at a deceleration equal to or higher than the predetermined deceleration. Further, in the above configuration, when the deceleration required by the automatic driving kit when it is determined that both the first path and the second path are defective is larger than the predetermined deceleration, the vehicle is decelerated at the deceleration required by the automatic driving kit. As a result, the automatic driving control (control of the braking device) based on the command from the automatic driving kit is continued, and the stability of the automatic driving control is improved.
[0027] (Item 10) In the vehicle according to any one of Items 1 to 9, the vehicle system further includes a vehicle drive device that accelerates the vehicle. When the automatic driving kit transmits an acceleration command requesting the vehicle to accelerate and it is determined that both the first path and the second path are defective, in the automatic deceleration control, after controlling the vehicle drive device so that the acceleration of the vehicle becomes 0, the braking device is controlled so that the deceleration of the vehicle approaches the predetermined deceleration.
[0028] According to the above configuration, by the vehicle system controlling the vehicle drive device and the braking device in order in an accelerating vehicle, the vehicle can be appropriately decelerated.
Effect of the Invention
[0029] According to the present disclosure, it is possible to achieve both the stability of the automatic driving control based on the command from the automatic driving kit and an appropriate fail-safe for the automatic driving control.
Brief Description of the Drawings
[0030] [Figure 1] This figure shows the schematic configuration of a vehicle according to an embodiment of the present disclosure. [Figure 2] This diagram shows the details of the vehicle system shown in Figure 1. [Figure 3] Figure 1 is a diagram illustrating the path from the autonomous driving kit to the vehicle system in the vehicle shown in Figure 1. [Figure 4] Figure 3 is a diagram illustrating an example of the configuration of the brake control unit. [Figure 5] This flowchart shows the process executed at the start of autonomous driving in the autonomous driving method according to the embodiment of this disclosure. [Figure 6] This flowchart shows the details of the process related to enabling / disabling automatic deceleration control in the processing flow shown in Figure 5. [Figure 7] This flowchart shows the process related to automated driving control performed by the vehicle control interface box shown in Figure 2. [Figure 8] Figure 2 is a flowchart showing the processes related to autonomous driving control performed by the autonomous driving kit. [Figure 9] Figure 2 is a diagram illustrating the processes performed by the base vehicle shown. [Figure 10] Figure 2 is a flowchart showing the process related to driving control performed by the base vehicle. [Figure 11] Figure 9 is a flowchart showing the details of the automatic deceleration control. [Figure 12] This flowchart shows a first modified example of the processing flow shown in Figure 5. [Figure 13] This flowchart shows a second modified example of the processing flow shown in Figure 5. [Figure 14] This figure shows a modified example of the configuration shown in Figure 4. [Figure 15] This figure shows a first modified example of the configuration shown in Figure 3. [Figure 16]This figure shows a second modified example of the configuration shown in Figure 3. [Modes for carrying out the invention]
[0031] The embodiments of this disclosure will be described in detail below with reference to the drawings. In the drawings, the same or corresponding parts are denoted by the same reference numerals, and their descriptions will not be repeated.
[0032] Figure 1 is a diagram showing the schematic configuration of a vehicle according to an embodiment of the present disclosure. Referring to Figure 1, vehicle 1 comprises a VP (vehicle platform) 100 and an ADK (autonomous driving kit) 200. The VP 100 includes a vehicle control interface box (hereinafter referred to as "VCIB") 110 and a base vehicle 120. By adding the VCIB 110 to the base vehicle 120, a VP 100 is formed to which the ADK 200 can be attached and detached. The VCIB 110 is configured to communicate with both the base vehicle 120 and the ADK 200 via a communication bus. The VCIB 110 may also function as a gateway. The vehicle 1 is then completed by attaching the ADK 200 to the VP 100. In this embodiment, the ADK 200 is attached to the rooftop of the base vehicle 120. However, the mounting position of the ADK 200 can be changed as appropriate.
[0033] The base vehicle 120 is, for example, a commercially available xEV (electric vehicle). In this embodiment, a BEV (battery electric vehicle) is used as the base vehicle 120. However, it is not limited to this, and the base vehicle 120 may be an xEV other than a BEV. The base vehicle 120 includes an integrated control manager 130, an HMI (Human Machine Interface) 150, and various systems and sensors for controlling the base vehicle 120 (wheel speed sensors 127A, 127B, steering angle sensor 127C, camera 129A, radar sensors 129B, 129C, etc.). The integrated control manager 130 functions as a control device. The integrated control manager 130 integrates and controls various systems related to the operation of the base vehicle 120 based on the detection results of the on-board sensors. The HMI 150 includes an input device and a notification device. Examples of notification devices include a display and a speaker. The HMI 150 may also include a touch panel display.
[0034] Figure 2 shows the details of the vehicle 1 system. Referring to Figure 2 in conjunction with Figure 1, the ADK200 includes an automated driving system (hereinafter referred to as "ADS") 210 for the automated driving of vehicle 1. The ADS210 includes a computer assembly (hereinafter referred to as "ADSCOM") 211, a recognition sensor 212, a posture sensor 213, a sensor cleaner 216, and an HMI (Human Machine Interface) 218.
[0035] ADSCOM211 includes computer modules (hereinafter referred to as "ADC") 211A and 211B. Each of ADC211A and 211B includes a processor and a storage device for storing autonomous driving software using the API described later, and is configured so that the autonomous driving software can be executed by the processor. Recognition sensors 212 include sensors that acquire information indicating the external environment of vehicle 1 (hereinafter also referred to as "environmental information"). Recognition sensors 212 may include at least one of a camera, millimeter-wave radar, and lidar. Attitude sensors 213 acquire information regarding the attitude of vehicle 1 (hereinafter also referred to as "attitude information"). Attitude sensors 213 may include various sensors that detect the acceleration, angular velocity, and position of vehicle 1. HMI218 includes input devices and notification devices.
[0036] The base vehicle 120 includes a brake system 121, a steering system 122, a powertrain system 123, an active safety system 125, and a body system 126. In this embodiment, each system is equipped with an electronic control unit (hereinafter also referred to as "ECU").
[0037] In vehicle 1, the control system for the vehicle's behavior (driving, stopping, turning) has redundancy. As will be described in detail later, ADC211A and 211B give instructions to the main system and sub-system, respectively. VCIB110 includes the VCI control unit 111A of the main system (hereinafter also referred to as "VCI-1") and the VCI control unit 111B of the sub-system (hereinafter also referred to as "VCI-2"). Each of the VCI control units 111A and 111B may be a computer equipped with a processor and memory. The VCI control units 111A and 111B may communicate directly with each system, or they may communicate via the integrated control manager 130 shown in Figure 1.
[0038] The brake system 121 includes a brake device, an operating unit (e.g., a brake pedal) that receives brake operations from the user, a brake control unit 121A (hereinafter also referred to as "Brake1"), and a brake control unit 121B (hereinafter also referred to as "Brake2"). The steering system 122 includes a steering device, an operating unit that receives steering operations from the user, and steering control units 122A and 122B. The powertrain system 123 includes a shift device (not shown), an EPB device 123A, a P-Lock device 123B, and a propulsion system 123C. "EPB" stands for electric parking brake, and "P-Lock" stands for parking lock.
[0039] The shift device determines the shift range and switches the propulsion direction and gear shift mode of the base vehicle 120 according to the determined shift range. The shift device comprises a gear shift mechanism and an operating unit that receives shift operations from the user. The propulsion system 123C comprises a vehicle drive unit, an operating unit (e.g., an accelerator pedal) that receives accelerator operations from the user, and a propulsion control unit that controls the vehicle drive unit. The vehicle drive unit applies propulsion force to the wheels in the propulsion direction indicated by the shift range. This propulsion force accelerates the base vehicle 120. The vehicle drive unit comprises a battery and a drive motor that receives power from the battery.
[0040] The EPB device 123A includes, for example, a parking brake mechanism, an electric actuator, and an operating unit (e.g., an EPB switch) for receiving EPB requests from the user. The EPB device 123A may be configured to apply braking force to the wheels using an electric actuator (e.g., a motor) to fix (immobilize) the wheels. The P-Lock device 123B includes, for example, a parking lock mechanism, an actuator, and an operating unit (e.g., a handbrake lever) for receiving parking operations from the user. The P-Lock device 123B may be configured to mechanically fix the rotational position of the transmission output shaft with a parking lock pole that can be driven by an actuator.
[0041] Figure 3 is a diagram illustrating the route (command route) from the autonomous driving kit to the vehicle system.
[0042] Referring to Figure 3, ADC211A and ADC211B are connected to each other via communication line L1 so that they can communicate with one another. VCI control unit 111A and VCI control unit 111B are connected to each other so that they can communicate with one another via communication line L2. ADC211A and VCI control unit 111A are connected to each other so that they can communicate with one another via communication line L11. VCI control unit 111A and brake control unit 121A are connected to each other so that they can communicate with one another via communication line L12. ADC211B and VCI control unit 111B are connected to each other so that they can communicate with one another via communication line L21. VCI control unit 111B and brake control unit 121B are connected to each other so that they can communicate with one another via communication line L22. VCI control unit 111A and brake control unit 121B are connected to each other so that they can communicate with one another via communication line L31. VCI control unit 111B and brake control unit 121A are connected to each other so that they can communicate with one another via communication line L32.
[0043] The main power supply 180A supplies power to the VCI control unit 111A and the brake control unit 121A, respectively. The sub-power supply 180B supplies power to the VCI control unit 111B and the brake control unit 121B, respectively. The main power supply 180A and the sub-power supply 180B each output power at a lower voltage than the drive battery (not shown). In this embodiment, the VCI control unit 111A, the VCI control unit 111B, the brake control unit 121A, and the brake control unit 121B correspond to examples of the "first control device," "second control device," "third control device," and "fourth control device" according to this disclosure, respectively.
[0044] The brake system 121 is configured to receive commands from the ADK200 through each of a plurality of paths. In this embodiment, the brake system 121 is configured to receive commands from the ADK200 through the first path, the second path, and the third path, respectively.
[0045] The first path is the path that goes through the VCI control unit 111A, and more specifically, the path through which a command from the ADK200 reaches the brake control unit 121A via the VCI control unit 111A (path 170A in Figure 3). The first path includes the ADC211A, communication line L11, VCI control unit 111A, communication line L12, and brake control unit 121A, and fails if a malfunction occurs in at least one of these.
[0046] The second path is the path that goes through the VCI control unit 111B, and more specifically, the path through which commands from the ADK200 reach the brake control unit 121B via the VCI control unit 111B (path 170B in Figure 3). The second path includes the ADC211B, communication line L21, VCI control unit 111B, communication line L22, and brake control unit 121B, and fails if a malfunction occurs in at least one of these.
[0047] The third path is the path through which commands from ADK200 reach the brake control unit 121A via the VCI control unit 111B. The third path includes ADC211B, communication line L21, VCI control unit 111B, communication line L32, and brake control unit 121A, and fails if a malfunction occurs in at least one of these.
[0048] In this embodiment, the first route corresponds to the main system, and the second and third routes correspond to sub-systems. While the main system (first route) is functioning normally, the brake system 121 uses the main system to perform automatic driving control based on commands from the ADK200. If the main system fails, the brake system 121 uses the sub-systems to perform automatic driving control based on commands from the ADK200. More specifically, if the main system fails but the sub-systems are functioning normally, the brake system 121 uses the third route to perform automatic driving control based on commands from the ADK200. Furthermore, if both the main system and the sub-systems fail during automatic driving, the brake system 121 performs automatic deceleration control. Automatic deceleration control is vehicle control that controls the braking device to decelerate the vehicle. The brake system 121 performs automatic deceleration control regardless of whether or not there are commands from the ADK200. If both the main and sub-systems fail during autonomous driving, automatic deceleration control will be performed even if the command path from ADK200 to the brake system 121 remains. For example, if both the first and second paths fail, automatic deceleration control will be performed even if the third path does not fail. Automatic deceleration control will also be performed if both the first and second paths fail, and if both the first and third paths fail. If the sub-system fails due to a failure in one of the brake control units 121A and 121B, automatic deceleration control will be performed by the other brake control unit that does not fail. Hereinafter, the failure of both the main and sub-systems will be referred to as "two-system failure".
[0049] In the brake system 121, the brake control units 121A and 121B are configured to control the brake device. The brake device is configured to decelerate the vehicle 1. The brake device may be a hydraulic disc brake device. The brake device functions as a service brake and is used not only when the vehicle is stopped but also when it is in motion. The brake device may have a brake hold function. In the vehicle 1 being driven manually, the brake control unit 121A or 121B controls the brake device in response to brake operation by the user (driver). The brake device applies braking force to the wheels of the vehicle 1. For example, the user can bring the vehicle 1 to a stop by decelerating the moving vehicle 1 by pressing the brake pedal.
[0050] Figure 4 is a diagram illustrating an example of the configuration of brake control units 121A and 121B. In the example shown in Figure 4, brake control units 121A and 121B are equipped with motion managers 141A and 141B and brake ECUs 142A and 142B, respectively. These function as control devices. The VCI control unit 111A is configured to communicate with the VCI control unit 111B, ADC 211A, and motion managers 141A and 141B via communication lines L2, L11, L12, and L31 shown in Figure 3. The VCI control unit 111B is configured to communicate with the VCI control unit 111A, ADC 211B, and motion managers 141A and 141B via communication lines L2, L21, L22, and L32 shown in Figure 3. In addition, the VCI control unit 111B is configured to communicate directly with the P-Lock device 123B and steering control units 122A and 122B shown in Figure 2. The VCI control unit 111B can prevent a collision while the vehicle 1 is in motion by steering control, and can suppress the movement of the vehicle 1 while it is stopped on a slope by immobilization control.
[0051] The VCI control unit 111A requests the motion manager 141A to perform automatic driving control in accordance with commands from the ADC 211A. The motion manager 141A requests the system corresponding to the control necessary to realize the requested automatic driving control (e.g., acceleration control, deceleration control, steering control, shift control, or parking control). The brake ECU 142A controls the brake system in response to the request from the motion manager 141A. The VCI control unit 111A can also request deceleration control from the motion manager 141B.
[0052] The VCI control unit 111B requests the motion manager 141A to perform automatic driving control in accordance with commands from the ADC 211B. The VCI control unit 111B also requests deceleration control from the motion manager 141B as needed. For example, if the brake control unit 121A fails, the VCI control unit 111B may request deceleration control from the motion manager 141B. The brake ECU 142B controls the brake system in response to requests from the motion manager 141B.
[0053] In this embodiment, signals defined by the API (Application Program Interface) (API signals) are used for communication between ADK200 and VCIB110. ADK200 is configured to process various signals defined by the API. ADK200 outputs various commands to VCIB110 according to the API. Hereinafter, each of the above commands output from ADK200 to VCIB110 will also be referred to as an "API command". ADK200 also receives various signals from VCIB110 indicating the status of the base vehicle 120 according to the API. Hereinafter, each of the above signals received by ADK200 from VCIB110 will also be referred to as an "API status". Both API commands and API statuses correspond to API signals.
[0054] In this embodiment, the ADK200 uses the API commands described below.
[0055] The Vehicle Mode command is an API command that requests a transition from automatic or assist mode to manual mode. Automatic mode, assist mode, and manual mode are described later. The Drive Direction command is an API command that requests a switch in the shift range (R / D). The Acceleration command is an API command that specifies the vehicle's acceleration. The Acceleration command requests acceleration (+) and deceleration (-) in the direction indicated by the Drive Direction status, which is described later. The Front Wheel Steering Angle command is an API command that requests steering of the vehicle's front wheels. The Immobilization command is an API command that requests the application or release of immobilization.
[0056] The above describes some of the API commands used in vehicle 1. The VCIB110 receives various API commands from the ADK200. When the VCIB110 receives an API command from the ADK200, it converts that API command into a signal format that can be executed by the control unit of the base vehicle 120. Hereinafter, the API command converted into a signal format that can be executed by the control unit of the base vehicle 120 will also be referred to as an "internal command". When the VCIB110 receives an API command from the ADK200, it outputs an internal command corresponding to that API command to the base vehicle 120.
[0057] Next, let's discuss API status. ADK200 uses API status, as described below, to understand the status of the base vehicle 120.
[0058] The Vehicle Mode Status (hereinafter referred to as "VEMDST") is an API status that indicates the vehicle mode state. Vehicle modes include manual mode, automatic mode, and assisted mode. Manual mode is a vehicle mode in which the vehicle is under the control of the user (human) and intervention in driving by the autonomous driving kit (driving assistance) is not permitted. Assisted mode is a vehicle mode in which the vehicle is under the control of the user (human) and intervention in driving by the autonomous driving kit (driving assistance) is permitted. Automatic mode is a vehicle mode in which the vehicle platform (including the base vehicle) is under the control of the autonomous driving kit. Initially (when the vehicle system starts up), the vehicle mode is manual mode. VEMDST displays the corresponding values "0", "1", and "2" depending on whether the current vehicle mode is manual mode, automatic mode, or assisted mode, respectively. Hereafter, driving in manual mode will be referred to as "manual driving", driving in assisted mode as "assisted automatic driving", and driving in automatic mode as "fully automated driving". Assisted automatic driving and fully automated driving may also be collectively referred to as "autonomous driving".
[0059] The propulsion direction status is an API status indicating the current shift range. The direction of travel status is an API status indicating the direction of travel of the vehicle. The direction of travel status outputs a value of "0" when the vehicle is moving forward, a value of "1" when the vehicle is moving backward, and a value of "2 (Standstill)" when all wheels (4 wheels) show a speed of "0" for a certain period of time. The vehicle speed status is an API status indicating the longitudinal speed of the vehicle. The vehicle speed status outputs the absolute value of the vehicle speed. The immobilization status is an API status indicating the immobilization state (for example, the state of the EPB device 123A and the P-Lock device 123B).
[0060] The Main System Failure Status (hereinafter referred to as "Main System ST") indicates whether or not the main system has failed. If the main system has not failed, Main System ST will show "1", and if the main system has failed, Main System ST will show "0". The Sub-System Failure Status (hereinafter referred to as "Sub-System ST") indicates whether or not a sub-system has failed. If the sub-system has not failed, Sub-System ST will show "1", and if the sub-system has failed, Sub-System ST will show "0". In this embodiment, if at least one of the second and third routes fails, Sub-System ST will show "0". The initial value of both Main System ST and Sub-System ST is "1". Hereafter, Main System ST and Sub-System ST may be collectively referred to as "System ST".
[0061] The Automatic Deceleration Failsafe Status (hereinafter referred to as "Automatic Deceleration ST") indicates whether or not automatic deceleration control is performed in the event of a two-system failure. If automatic deceleration control in the event of a two-system failure is ON (enabled), that is, if automatic deceleration control is performed in the event of a two-system failure, Automatic Deceleration ST will show "1". If automatic deceleration control in the event of a two-system failure is OFF (disabled), that is, if automatic deceleration control is not performed in the event of a two-system failure, Automatic Deceleration ST will show "0". The initial value of Automatic Deceleration ST is "0".
[0062] The above describes some of the API statuses used in vehicle 1. The VCIB110 receives various sensor detection values and status determination results from the base vehicle 120 and outputs various API statuses indicating the status of the base vehicle 120 to the ADK200. The VCIB110 acquires an API status in which a value indicating the status of the base vehicle 120 is set and outputs the obtained API status to the ADK200. The various API statuses are stored in the respective storage devices of the VCI control units 111A and 111B, for example, and are updated sequentially.
[0063] In this embodiment, the user can request a change in vehicle mode from the VCIB110 via the HMI150. Hereinafter, a request to change from manual mode to support mode or automatic mode will be referred to as an "automatic driving start request". A request to change from support mode or automatic mode to manual mode will be referred to as an "automatic driving end request". A request to change from support mode to automatic mode will be referred to as a "driving level up request". A request to change from automatic mode to support mode will be referred to as a "driving level down request". In addition, driving level up requests and driving level down requests may be collectively referred to as "driving level change requests".
[0064] The following primarily describes examples where Vehicle 1 is operated in a manned state (with a person inside the vehicle) using various modes. However, Vehicle 1 may also operate unmanned through fully autonomous driving.
[0065] When VCIB110 receives an automated driving start request or a driving level change request, it executes the processing flow F1 shown in Figure 5. Figure 5 is a flowchart of the processes executed when automated driving is started in vehicle 1. In the flowchart, "S" represents a step.
[0066] In processing flow F1, VCIB110 requests ADK200 to start the automated driving (assisted automated driving or fully automated driving) requested by the user using the main system in S11. VCIB110 also performs a failure check on the main system. In the subsequent S12, VCIB110 determines whether the main system is normal (not experiencing failure). Specifically, the VCI control unit 111A sends a first request signal requesting the start of the automated driving to ADC211A via the communication line L11 shown in Figure 3. The VCI control unit 111A may determine that the main system is not experiencing failure if it receives a reply from ADC211A to the first request signal (see S42 or S43 described later). The VCI control unit 111A may also determine that the main system is experiencing failure if it does not receive a reply from ADC211A even after a predetermined time has elapsed since the transmission of the first request signal. However, if the current value of the main system ST is "0" in S11, the VCIB110 determines in S12 that the main system has failed without sending the first request signal. The main system ST can be updated during manual operation (see processing flow F6 shown in Figure 9, described later).
[0067] If the main system is determined to be normal (YES in S12), in S13, VCIB110 sets the main system ST to "1", and then the process proceeds to S20. The process from S20 onwards will be described later. On the other hand, if the main system is determined to be lost (NO in S12), in S14, VCIB110 sets the main system ST to "0", and then the process proceeds to S15.
[0068] In S15, VCIB110 uses a sub-system to request ADK200 to start the automated driving requested by the user. VCIB110 also performs a failure check on the sub-system. In the subsequent S16, VCIB110 determines whether the sub-system is functioning correctly (not experiencing failure). Specifically, the VCI control unit 111B transmits a second request signal requesting the start of automated driving to ADC211B via the communication line L21 shown in Figure 3. The VCI control unit 111B may determine that the sub-system is not experiencing failure if it receives a reply from ADC211B to the second request signal (see S42 or S43 described later). The VCI control unit 111B may also determine that the sub-system is experiencing failure if it does not receive a reply from ADC211B even after a predetermined time has elapsed since the transmission of the second request signal. However, if the current value of subsystem ST is "0" in S15, VCIB110 determines in S16 that the subsystem has failed without sending a second request signal. Subsystem ST can be updated during manual operation (see processing flow F6 shown in Figure 9, described later).
[0069] If the sub-system is determined to be normal (YES in S16), in S17, VCIB110 sets sub-system ST to "1", and then the process proceeds to S18. In S18, it is determined whether the user has requested an increase in the autonomous driving level. If VCIB110 receives a request from the user to start autonomous driving or to increase the driving level, it is determined to be YES in S18, and the process proceeds to S32. In S32, VCIB110 informs the user that it cannot fulfill the request. For example, VCIB110 may display a message on HMI150 indicating that it cannot increase the autonomous driving level due to a system malfunction. In this case, the processing flow F1 ends without the autonomous driving requested by the user being started. In other words, the user's request is rejected. On the other hand, if VCIB110 receives a request from the user to decrease the driving level, it is determined to be NO in S18, and the process proceeds to S20. The processing from S20 onwards will be described later.
[0070] If it is determined that both the main and sub-systems have failed (NO in S16), in S19, VCIB110 sets sub-system ST to "0", and then the process proceeds to S33. In S33, VCIB110 notifies the base vehicle 120 that two systems have failed. For example, VCI control unit 111A may notify brake control unit 121A or 121B via communication line L12 or L31. Alternatively, VCI control unit 111B may notify brake control unit 121B or 121A via communication line L22 or L32. Once the notification in S33 is executed, the processing flow F1 ends.
[0071] The ADK200 initiates assisted autonomous driving or fully autonomous driving in response to a request from the VCIB110. Specifically, when the ADK200 receives a first request signal (S11) or a second request signal (S15) from the VCIB110, it executes processing flow F2.
[0072] In processing flow F2, ADK200 determines in S41 whether the automated driving requested by VCIB110 is automated driving with human control sovereignty. Specifically, assisted automated driving corresponds to automated driving with human control sovereignty. Assisted automated driving corresponds to, for example, Level 1 or 2 automated driving as defined in the standard "SAE J3016". Fully automated driving corresponds to automated driving where the automated driving kit has control sovereignty. Fully automated driving corresponds to, for example, Level 4 or 5 automated driving as defined in the standard "SAE J3016". If the first or second request signal received by ADK200 requests assisted automated driving, it is determined to be YES in S41 and the process proceeds to S42. On the other hand, if the first or second request signal received by ADK200 requests fully automated driving, it is determined to be NO in S41 and the process proceeds to S43.
[0073] Furthermore, ADK200 may be configured to perform Level 3 autonomous driving as defined in the standard "SAE J3016" in response to a request from VCIB110. With regard to Level 3 autonomous driving, ADK200 may, in S41, determine whether control sovereignty lies with the user (driver) or the autonomous driving kit, based on the details of the control of that autonomous driving.
[0074] In S42, ADK200 requests VCIB110 to turn off automatic deceleration (i.e., disable automatic deceleration control in the event of a two-system failure). For example, if ADC211A receives the first request signal, ADC211A uses the main system to send a third request signal to VCI control unit 111A requesting automatic deceleration off. This results in a YES determination in S12. Also, if ADC211B receives the second request signal, ADC211B uses the sub-system to send a third request signal to VCI control unit 111B requesting automatic deceleration off. This results in a YES determination in S16.
[0075] In S43, ADK200 requests VCIB110 to turn on automatic deceleration (i.e., enable automatic deceleration control in the event of a two-system failure). For example, if ADC211A receives the first request signal, ADC211A uses the main system to send a fourth request signal to VCI control unit 111A requesting automatic deceleration ON. This results in a YES determination in S12. Also, if ADC211B receives the second request signal, ADC211B uses the sub-system to send a fourth request signal to VCI control unit 111B requesting automatic deceleration ON. This results in a YES determination in S16.
[0076] Based on the third or fourth request signal received from the ADK200, the VCIB110 performs the processing described in S20. Specifically, the VCIB110 executes the processing flow shown in Figure 6 below. Figure 6 is a flowchart detailing S20.
[0077] Referring to Figure 6, in S21, VCIB110 determines whether vehicle 1 is being driven manually or not. If VCIB110 receives a request to start automatic driving, automatic driving has not yet started, so vehicle 1 is being driven manually. In this case, S21 is determined to be YES, and the process proceeds to S22. In S22, VCIB110 updates the automatic deceleration ST according to a request from ADK200. Specifically, if VCIB110 receives a third request signal from ADK200, VCIB110 sets the automatic deceleration ST to "0". If VCIB110 receives a fourth request signal from ADK200, VCIB110 sets the automatic deceleration ST to "1". In this way, VCIB110 is configured to switch the automatic deceleration control on or off based on a request from ADK200. Once the automatic deceleration ST is updated in S22, the process proceeds to S23.
[0078] Furthermore, if VCIB110 receives a request to change the driving level, vehicle 1 is in autonomous driving mode. In this case, the system determines NO in S21, and the process in S22 is not executed, and the process proceeds to S23. Thus, VCIB110 is configured to prohibit the switching of automatic deceleration control on / off during autonomous driving.
[0079] In S23, the VCIB110 transmits the automatic deceleration ST to the ADK200 and the brake system 121 respectively, using one of the communication lines L11, L12, L21, L22, L31, and L32 shown in Figure 3 that is not lost.
[0080] In the subsequent S24, the VCIB110 transmits the system ST (main system ST and sub-system ST) to the ADK200 and the brake system 121, respectively, using one of the communication lines L11, L12, L21, L22, L31, L32 (Figure 3) that is not lost.
[0081] When the process in S24 shown in Figure 6 is executed, S20 in the processing flow F1 (Figure 5) is completed, and the process proceeds to S31. Referring again to Figure 5, in S31, VCIB110 sets VEMDST according to the automated driving requested by the user, requests ADK200 to start the automated driving requested by the user, and starts the automated driving control shown in Figure 7, which will be described later. Specifically, if the user requests assisted automated driving, VCIB110 changes the value of VEMDST from "0" or "1" to "2" and sends the changed VEMDST to ADK200 and the base vehicle 120, respectively. If the user requests fully automated driving, VCIB110 changes the value of VEMDST from "0" or "2" to "1" and sends the changed VEMDST to ADK200 and the base vehicle 120, respectively. The VCIB110 requests the ADK200 to initiate the user-requested autonomous driving (assisted autonomous driving or fully autonomous driving) by sending the modified VEMDST to the ADK200.
[0082] After sending the third or fourth request signal in S42 or S43, ADK200 determines in S44 whether it has received a request from VCIB110 to start automatic driving (S31). If ADK200 has received a request from VCIB110 to start automatic driving, it determines YES in S44 and proceeds to S45. If VCIB110 has executed the process in S31 in processing flow F1, it determines YES in S44. In S45, ADK200 starts control related to the automatic driving requested by VCIB110 (automatic driving requested by the user). Specifically, ADK200 starts the automatic driving control shown in Figure 8, which will be described later. On the other hand, if ADK200 does not receive a request from VCIB110 to start automatic driving even after a predetermined time has elapsed since the transmission of the third or fourth request signal, it determines NO in S44. For example, if processing flow F1 ends without VCIB110 executing the process in S31, it determines NO in S44. In this case, the processing flow F2 ends without the S45 process being executed.
[0083] Figure 7 is a flowchart showing the processes related to automated driving control performed by VCIB110. VCIB110 starts the processing flow F3 shown in Figure 7 as a result of the process in S31 of Figure 5. If the automated driving level is changed as a result of the process in S31 of Figure 5, VCIB110 terminates the currently running automated driving control (processing flow F3) and starts a new automated driving control (processing flow F3) as requested.
[0084] Referring to Figure 7, in processing flow F3, VCIB110 requests an operation command related to automatic driving from ADK200 using the main system in S51. VCIB110 also performs a failure check on the main system. In the subsequent S52, VCIB110 determines whether the main system is normal (not failed). Specifically, the VCI control unit 111A sends a fifth request signal requesting an operation command related to automatic driving, along with various API statuses indicating the status of vehicle 1, to ADC211A via the communication line L11 shown in Figure 3. The transmitted API statuses include VEMDST. The VCI control unit 111A may determine that the main system is not failed if it receives a reply from ADC211A to the fifth request signal (see S74 in Figure 8, described later). The VCI control unit 111A may also determine that the main system is failed if it does not receive a reply from ADC211A even after a predetermined time has elapsed since the transmission of the fifth request signal. However, if the current value of the main system ST is "0" in S51, VCIB110 will determine in S52 that the main system has failed without transmitting the fifth request signal.
[0085] When VCIB110 receives a driving command from ADK200 via the main system, it is determined that the main system is functioning normally (YES in S52), and the process proceeds to S57. In S57, VCIB110 sends an internal command corresponding to the received driving command (API command related to automatic driving) to the base vehicle 120. As a result, the base vehicle 120 executes automatic driving control based on the command from ADK200 (see Figure 10). In this embodiment, if the main system (first path) is not lost, the VCI control unit 111A uses the main system to receive a driving command from ADC211A, for example, a command related to deceleration control, and sends that driving command to the brake control unit 121A. As a result, the brake control unit 121A controls the brakes based on the driving command received from ADC211A via the main system. After the process in S57 is executed, the process proceeds to S58.
[0086] On the other hand, if it is determined that the main system is down (NO in S52), in S54, VCIB110 sets the main system ST to "0", and then the process proceeds to S55. In S55, VCIB110 requests an operation command related to automatic driving from ADK200 using the sub-system. VCIB110 also performs a failure check on the sub-system. In the following S56, VCIB110 determines whether the sub-system is normal (not down). Specifically, the VCI control unit 111B sends a sixth request signal requesting an operation command related to automatic driving, along with various API statuses indicating the status of vehicle 1, to ADC211B via the communication line L21 shown in Figure 3. The transmitted API statuses include VEMDST. The VCI control unit 111B may determine that the sub-system is not down when it receives a reply from ADC211B to the sixth request signal (see S74 in Figure 8, described later). The VCI control unit 111B may determine that the subsystem has failed if it does not receive a reply from the ADC211B even after a predetermined time has elapsed since the transmission of the sixth request signal. However, if the current value of the subsystem ST is "0" in S55, the VCIB110 will determine that the subsystem has failed in S56 without transmitting the sixth request signal.
[0087] When VCIB110 receives a driving command from ADK200 via a sub-system, it is determined that the sub-system is functioning normally (YES in S56), and processing proceeds to S57. In S57, VCIB110 transmits an internal command corresponding to the received driving command (API command related to automatic driving) to the base vehicle 120. As a result, the base vehicle 120 executes automatic driving control based on the command from ADK200 (see Figure 10). In this embodiment, if the main system (first path) fails, but the sub-systems (second and third paths) do not fail, the VCI control unit 111B uses the third path to receive a driving command from ADC211B, including, for example, a command related to deceleration control, and transmits that driving command to the brake control unit 121A. As a result, the brake control unit 121A controls the brake system based on the driving command received from ADC211B via the third path. Therefore, even if the main system fails, the brake control unit 121A can continue automatic driving control (control of the braking system) based on the driving command from ADK200. Once the process in S57 is executed, the process proceeds to S58.
[0088] In S58, VCIB110 decides whether or not to terminate autonomous driving. For example, if VCIB110 receives a request to terminate autonomous driving, it determines YES in S58 and proceeds to S61. In S61, VCIB110 changes the value of VEMDST from "1" or "2" to "0" and sends the changed VEMDST to ADK200 and base vehicle 120, respectively. By sending the changed VEMDST to ADK200, VCIB110 requests ADK200 to terminate autonomous driving as requested by the user. Subsequently, in S62, VCIB110 sets automatic deceleration ST to "0" and then sends automatic deceleration ST to base vehicle 120. Once the process in S62 is executed, processing flow F3 ends. On the other hand, if VCIB110 has not received a request to terminate autonomous driving, it determines NO in S58 and the process returns to the first step (S51). As a result, autonomous driving control continues.
[0089] If it is determined that both the main and sub-systems have failed (NO in S56), VCIB110 executes processes S63 and S64. Processes S63 and S64 are the same as processes S19 and S33 shown in Figure 5, respectively. Once process S64 is executed, processing flow F3 ends.
[0090] Figure 8 is a flowchart showing the processes related to automated driving control performed by ADK200. ADK200 starts the processing flow F4 shown in Figure 8 by the process at S45 in Figure 5. If the automated driving level is changed by the process at S45 in Figure 5, ADK200 terminates the currently running automated driving control (processing flow F4) and starts a new automated driving control (processing flow F4) that was requested.
[0091] Referring to Figure 8, in processing flow F4, ADK200 determines in S71 whether or not it has received an operation command request from VCIB110. If ADK200 receives either the aforementioned fifth request signal or sixth request signal, it is determined to be YES in S71 and the process proceeds to S72. On the other hand, if ADK200 has not received either the aforementioned fifth request signal or sixth request signal, it is determined to be NO in S71 and the process proceeds to S75.
[0092] In S72, the ADK200 recognizes the vehicle mode of vehicle 1 based on VEMDST and creates a driving plan corresponding to the vehicle mode (assistance mode or automatic mode). Specifically, the ADK200 creates a driving plan for autonomous driving based on the detection results of various sensors (e.g., environmental information and attitude information) and the API status obtained from VCIB110. The driving plan is data that shows the target behavior of vehicle 1 over a predetermined period. The ADK200 may also calculate the behavior of vehicle 1 (such as attitude) and create a driving plan suitable for the state of vehicle 1 and the external environment. In the subsequent S73, the ADK200 determines API commands (driving commands such as propulsion direction command, acceleration command, front wheel steering angle command, immobilization command, etc.) to execute the control required by the created driving plan (e.g., at least one of acceleration control, deceleration control, steering control, stopping control, and parking control). The driving commands correspond to driving commands from the ADK200 to the vehicle system (the system of the base vehicle 120). The ADK200 may calculate the control physical quantities (acceleration, tire steering angle, etc.) required by the driving plan and determine the driving command based on the calculation results. In the following S74, the ADK200 transmits the determined driving command to the VCIB110.
[0093] If ADC211A receives a fifth request signal from VCI control unit 111A, ADC211A executes the processes described in S72 to S74 above. ADC211A transmits the operation command determined as described above to VCI control unit 111A via the main system. This results in a YES determination at S52 in Figure 7. If ADC211B receives a sixth request signal from VCI control unit 111B, ADC211B executes the processes described in S72 to S74 above. ADC211B transmits the operation command determined as described above to VCI control unit 111B via the sub-system. This results in a YES determination at S56 in Figure 7. Once the process in S74 is executed, the process proceeds to S75.
[0094] In S75, ADK200 decides whether or not to terminate autonomous driving. For example, if ADK200 receives a request from VCIB110 to terminate autonomous driving (S61), it determines YES in S75 and process flow F4 ends. On the other hand, if ADK200 has not received a request from VCIB110 to terminate autonomous driving (S61), it determines NO in S75 and the process returns to the first step (S71). As a result, autonomous driving control continues.
[0095] Figure 9 is a diagram illustrating the processes performed by the base vehicle 120. The base vehicle 120 repeatedly executes process flow F5 when automatic deceleration control (S90) is not being performed. Process flow F5 is executed by one of the multiple control devices provided by the base vehicle 120 (for example, the integrated control manager 130 and the control devices of each system shown in Figures 1 to 4).
[0096] Referring to Figure 9, in processing flow F5, it is determined in S81 whether the base vehicle 120 has received notification of a two-system failure from VCIB110 (S33 in Figure 5 or S64 in Figure 7). If the base vehicle 120 has received notification of a two-system failure (YES in S81), the process proceeds to S88. On the other hand, if the base vehicle 120 has not received notification of a two-system failure (NO in S81), the process proceeds to S82.
[0097] In S82, the base vehicle 120 requests the system ST (main system ST and sub-system ST) from the VCIB 110. The base vehicle 120 also performs a failure check regarding the main system and sub-system.
[0098] In detail, the brake control unit 121A requests a system ST from the VCI control units 111A and 111B, respectively, through the communication lines L12 and L32 shown in Figure 3. If the brake control unit 121A receives a system ST from either the VCI control unit 111A or 111B, it determines that the communication lines L12 and L32 are not lost. If the brake control unit 121A does not receive a system ST from at least one of the VCI control units 111A or 111B, it determines that the corresponding path (at least one of the communication lines L12 or L32) is lost.
[0099] Furthermore, the brake control unit 121B requests a system ST from the VCI control units 111A and 111B, respectively, through the communication lines L31 and L22 shown in Figure 3. If the brake control unit 121B receives a system ST from either the VCI control unit 111A or 111B, it determines that the communication lines L31 and L22 are not lost. Also, if the brake control unit 121B does not receive a system ST from at least one of the VCI control units 111A or 111B, it determines that the corresponding path (at least one of the communication lines L31 or L22) is lost.
[0100] When the brake control unit 121A or 121B receives a system ST from the VCIB 110, the brake control unit 121A or 121B performs a failure determination for the main system and sub-systems based on the received system ST. For example, if communication line L11 is lost, the main system ST will show "0" (S14 in Figure 5 or S54 in Figure 7). Also, if communication line L21 is lost, the sub-system ST will show "0" (S19 in Figure 5 or S63 in Figure 7).
[0101] In this embodiment, the VCI control unit 111A determines whether communication between the ADC211A and the VCI control unit 111A has been lost (S12 in Figure 5), and outputs the result of that determination (main system ST) to the base vehicle 120 upon request from the base vehicle 120 (S82). In addition, the VCI control unit 111B determines whether communication between the ADC211B and the VCI control unit 111B has been lost (S16 in Figure 5), and outputs the result of that determination (sub-system ST) to the base vehicle 120 upon request from the base vehicle 120. With this configuration, the base vehicle 120 can more easily detect failures related to the first and second routes, respectively. Note that the embodiment is not limited to the above, and the VCI control units 111A and 111B may each spontaneously transmit system ST to the base vehicle 120.
[0102] In the following step S83, the base vehicle 120 recognizes the vehicle mode of vehicle 1 based on VEMDST and determines whether vehicle 1 is in autonomous driving mode or not. If VEMDST indicates "0", S83 determines NO and the process proceeds to S831. If VEMDST indicates "1" or "2", S83 determines YES and the process proceeds to S841.
[0103] In S831, it is determined whether the base vehicle 120 was determined to have lost communication with the VCIB 110 in S82. For example, if it is determined that at least one of the communication lines L12, L22, L31, or L32 has lost communication, S831 is determined to be YES, and the process proceeds to S832. On the other hand, if it is determined that none of the communication lines L12, L22, L31, or L32 have lost communication, S831 is determined to be NO, and the process returns to the first step (S81).
[0104] In S832, the base vehicle 120 notifies the VCIB 110 of the result of the failure detection in S82. Specifically, the base vehicle 120 sends failure information to the VCIB 110 using a communication line that is not failing, indicating which of the communication lines L12, L22, L31, and L32 has failed. In the subsequent S833, the base vehicle 120 informs the user that automatic driving is prohibited. For example, the base vehicle 120 may display a message on the HMI 150 indicating that automatic driving cannot be performed due to a system malfunction. Once the process in S833 is executed, the process returns to S81.
[0105] While vehicle 1 is being operated manually, VCIB110 repeatedly executes the processes S101 to S103 shown in Figure 9. Specifically, when vehicle 1 starts manual operation, VCIB110 starts the processing flow F6 shown in Figure 9. In processing flow F6, VCIB110 determines in S101 whether or not it has received failure information (S832) from the base vehicle 120. If VCIB110 has received failure information (YES in S101), VCIB110 updates the system ST in S102 based on the received failure information. For example, if communication line L12 is lost, the main system ST is set to "0". Also, if at least one of communication lines L22 and L32 is lost, the sub-system ST is set to "0".
[0106] In the following step S103, the VCIB110 determines whether or not automatic driving has started. If manual driving continues (NO in S103), the process returns to S101. On the other hand, if automatic driving has started, for example, through the process in S31 in Figure 5 (YES in S103), the processing flow F6 ends.
[0107] In S841, the base vehicle 120 determines whether or not the main system was determined to be down in S82. For example, the failure of at least one of the communication lines L11 and L12 means that the main system is down. If it is determined that the main system is not down (NO in S841), the base vehicle 120 receives an operation command from ADK200 through the main system in S851 (see S57 in Figure 7 and S74 in Figure 8) and stores the operation command in the memory along with the time of reception. After that, the process returns to S81.
[0108] On the other hand, if it is determined that the main system is down (YES in S841), the base vehicle 120 determines in S842 whether or not it was determined in S82 that the sub-system is down. For example, if at least one of the communication lines L21, L22, and L32 is down, it means that the sub-system is down. If it is determined that the sub-system is not down (NO in S842), the base vehicle 120 receives an operation command from ADK200 through the sub-system in S852 (see S57 in Figure 7 and S74 in Figure 8) and stores the operation command in the memory device along with the time of reception. After that, the process returns to S81.
[0109] In this embodiment, the base vehicle 120 executes automatic driving control based on the commands acquired in S851 or S852, according to the processing flow F7 shown in Figure 10, which is described below. Figure 10 is a flowchart showing the processing related to driving control executed by the base vehicle 120. The base vehicle 120 repeatedly executes the processing flow F7 shown in Figure 10 in parallel with the processing flow F5 shown in Figure 9.
[0110] Referring to Figure 10, in processing flow F7, the base vehicle 120 determines in S201 whether VEMDST indicates "1". If VEMDST indicates "1" (YES in S201), the base vehicle 120 executes automatic driving control in S202 based on the driving command acquired in S851 or S852 in Figure 9. This enables fully automatic driving of vehicle 1. For example, if the above driving command includes a command related to deceleration control, the brake system 121 controls the brake device (Figure 3) based on the command from ADK200. ADK200 has control sovereignty in this automatic driving. Once the processing in S202 is executed, the process returns to the first step (S201).
[0111] If VEMDST does not indicate "1" (NO in S201), the base vehicle 120 acquires user operations related to the driving of vehicle 1 in S203. Specifically, the base vehicle 120 acquires the amount of operation (accelerator operation amount, brake operation amount, steering operation amount, etc.) and change operations (shift changes, etc.) for various control parts related to the manual driving of vehicle 1. Then, in the following S204, the base vehicle 120 determines whether VEMDST indicates "2" or not. If VEMDST indicates "0" (NO in S204), the base vehicle 120 executes manual driving control based on the user operations acquired in S203 in S205. For example, the vehicle drive system, brake system, steering system, shift system, etc. are controlled according to the user operations. This enables manual driving of vehicle 1. After the process in S205 is executed, the process returns to S201.
[0112] If VEMDST indicates "2" (YES in S204), the base vehicle 120 executes automatic driving control in S206 based on the user operation acquired in S203 and the driving command acquired in S851 or S852 in Figure 9. This enables assisted automatic driving of vehicle 1. The user (person) retains control sovereignty in this automatic driving. Commands from ADK200 are treated as support for user operation. Once the processing in S206 is completed, the process returns to S201.
[0113] Referring again to Figure 9, if it is determined that not only the main system but also the sub-system has failed (YES in S842), the process proceeds to S88. Thus, the process in S88 is executed when two systems fail. In S88, the base vehicle 120 determines whether the automatic deceleration ST indicates "1" or not. If the automatic deceleration ST indicates "0" (NO in S88), the process proceeds to S86. In S86, the base vehicle 120 notifies the user that an abnormality has occurred in the automatic driving system. For example, the base vehicle 120 may display a message on the HMI 150 informing the user of the abnormality in the automatic driving system.
[0114] If the automatic deceleration ST shows "1" (YES in S88), the process proceeds to S89. The automatic deceleration ST showing "1" means that automatic deceleration control is enabled. The base vehicle 120 executes automatic deceleration control (S90) only when automatic deceleration control is enabled. In this embodiment, when automatic driving ends, the automatic deceleration ST becomes "0" (S62 in Figure 7). Furthermore, the automatic deceleration ST is changed only when vehicle 1 is being driven manually, according to a request from ADK200 (S22 in Figure 6). Also, ADK200 requests automatic deceleration ON only when starting fully automatic driving (S43 in Figure 5). Therefore, the automatic deceleration ST showing "1" means that vehicle 1 is in fully automatic driving mode. If a two-system failure occurs when control sovereignty is with the user (driver), the user can continue driving vehicle 1. This prevents unintended movements of vehicle 1 by the user.
[0115] The base vehicle 120 notifies the VCIB 110 of the start of automatic deceleration control in S89, and then starts automatic deceleration control in S90. Figure 11 is a flowchart showing the details of S90.
[0116] Referring to Figure 11, in S91, the base vehicle 120 obtains the acceleration / deceleration (hereinafter referred to as "Vx") requested by the ADK200 when a two-system failure occurs. Vx is indicated by an internal command corresponding to the latest acceleration command received by the base vehicle 120 from the VCIB110. Vx indicates a positive value (+) when acceleration is requested and a negative value (-) when deceleration is requested.
[0117] In the following step S92, the base vehicle 120 determines whether Vx is greater than 0. If Vx is greater than 0, it means that both the main and sub-systems have failed when the ADK200 sends an acceleration command requesting vehicle 1 to accelerate. If Vx is greater than 0 (YES in S92), the base vehicle 120 controls the vehicle drive system (Figure 2) in S93 so that the acceleration of vehicle 1 becomes 0. As a result, no propulsive force is applied to the wheels of vehicle 1. In the following step S94, the brake system 121 (Figure 2) controls the brakes to bring the deceleration of vehicle 1 closer to a predetermined deceleration (hereinafter referred to as "target deceleration"). The control of the brakes in S94 is performed by the brake control unit 121A. However, if the brake control unit 121A is malfunctioning, the brake control unit 121B controls the brakes instead. The target deceleration is set to a value that conforms to traffic regulations, for example. The base vehicle 120 may adjust the deceleration of vehicle 1 to approach the target deceleration at a predetermined rate of change or less, so as not to make the rate of change of vehicle 1's deceleration too large. This suppresses cargo shifting and other problems caused by sudden deceleration. When the deceleration of vehicle 1 reaches the target deceleration, the base vehicle 120 maintains the deceleration of vehicle 1 at the target deceleration.
[0118] If Vx is 0 or less (NO in S92), the base vehicle 120 determines in S95 whether Vx is greater than the target deceleration (a negative value). If Vx is greater than the target deceleration AND 0 or less (YES in S95), the process proceeds to S94 without executing the process in S93. The base vehicle 120 brings the deceleration of vehicle 1 closer to the target deceleration through the process in S94. On the other hand, if Vx is less than or equal to the target deceleration (NO in S95), the brake system 121 controls the brake device in S96 to bring the deceleration of vehicle 1 closer to Vx. The control of the brake device in S96 is performed by the brake control unit 121A. However, if the brake control unit 121A is malfunctioning, the brake control unit 121B controls the brake device instead. Once the deceleration of vehicle 1 reaches Vx, the base vehicle 120 maintains the deceleration of vehicle 1 at Vx. Thus, if ADK200 transmits a deceleration command requesting vehicle 1 to slow down, and it is determined that both the main and sub-systems have failed, the brake system 121 controls the brakes to bring the deceleration of vehicle 1 closer to the larger of the deceleration values (Vx) requested by the deceleration command and a predetermined deceleration value (target deceleration). Regarding deceleration, the smaller the value of Vx (the larger the negative side), the greater the deceleration indicated by Vx.
[0119] When process S94 is executed, the process proceeds to S97. When process S96 is executed, the process proceeds to S98. In both S97 and S98, the base vehicle 120 determines whether or not vehicle 1 has come to a stop. If the result in S97 is NO, the process returns to S94. Then, processes S94 and S97 are repeatedly executed until vehicle 1 comes to a stop. If the result in S98 is NO, the process returns to S96. Then, processes S96 and S98 are repeatedly executed until vehicle 1 comes to a stop. In this way, the base vehicle 120 starts automatic deceleration control by one of the processes in S93, S94, or S96, and while the automatic deceleration control is being executed, it does not receive any new commands from ADK200 and continues the automatic deceleration control (S94 or S96) until vehicle 1 comes to a stop. Note that steering control of vehicle 1 during the execution of automatic deceleration control is optional. The base vehicle 120 may, for example, release the torque to the steering and return the steering angle to the midpoint.
[0120] When vehicle 1 comes to a stop due to automatic deceleration control (YES in S97 or S98), the process proceeds to S99. In S99, base vehicle 120 requests VCIB110 to switch to manual mode. This request causes VCIB110 to recognize the end of automatic deceleration control. Then, in response to the request from base vehicle 120, VCIB110 sets vehicle mode of vehicle 1 to manual mode and sets VEMDST to "0". Once the process in S99 is executed, S90 in the processing flow F5 shown in Figure 9 is completed, and processing flow F5 is completed.
[0121] As described above, in this embodiment, VP100 corresponds to an example of a "vehicle capable of mounting an autonomous driving kit" according to this disclosure. VP100 includes VCIB110 and a base vehicle 120. The system built into the base vehicle 120 corresponds to an example of a "vehicle system" according to this disclosure. VP100 performs the processes shown in Figures 5 to 7 and Figures 9 to 11. ADK200 attached to VP100 performs processing flows F2 and F4 (Figures 5 and 8). In this embodiment, each process is performed by one or more processors executing programs stored in one or more memories. However, these processes may be performed by hardware (electronic circuits) alone without using software.
[0122] If only one of the multiple routes fails during the autonomous driving of vehicle 1, the base vehicle 120 will continue autonomous driving based on commands received from ADK200 via the routes other than the one that failed (see Figure 7). Furthermore, if both the first and second routes fail during the autonomous driving of vehicle 1, the base vehicle 120 will perform automatic deceleration control (S90 in Figure 9). This control ensures both the stability of the autonomous driving control based on commands from ADK200 and appropriate fail-safe measures for the autonomous driving control.
[0123] The VCIB110 may obtain specification information for the ADK200 from the ADK200 attached to the VP100. Alternatively, the user may input the ADK200 specification information into the VCIB110 via the HMI150 or 218. The specification information may, for example, indicate the types of automated driving that the ADK200 can perform. The VCIB110 may set VEMDST based on the specification information obtained from the ADK200 or the user. The VCIB110 may be configured not to set values in VEMDST corresponding to types of automated driving that the ADK200 cannot perform.
[0124] Figure 12 is a flowchart showing a first modified version of the processing flow F2 shown in Figure 5. In the modified version shown in Figure 12, ADK200 executes processing flow F2A instead of processing flow F2. ADK200 is also configured to execute only assisted automatic driving among assisted automatic driving and fully automatic driving. Processing flow F2A is the same as processing flow F2 except that S41 and S43 (Figure 5) are omitted. In S42, ADK200 requests VCIB110 to turn off automatic deceleration. Therefore, in S22 in Figure 6, "0" is set for automatic deceleration ST. Also, VCIB110 sets "0" or "2" for VEMDST based on the specifications of ADK200, and does not set "1" for VEMDST. Therefore, manual driving (S205) or assisted automatic driving (S206) is appropriately executed according to processing flow F7 shown in Figure 10.
[0125] Figure 13 is a flowchart showing a second modified version of the processing flow F2 shown in Figure 5. In the modified version shown in Figure 13, ADK200 executes processing flow F2B instead of processing flow F2. ADK200 is also configured to execute only fully automated driving among assisted automated driving and fully automated driving. Processing flow F2B is the same as processing flow F2 except that S41 and S42 (Figure 5) are omitted. At S43, ADK200 requests VCIB110 to turn on automatic deceleration. Therefore, at S22 in Figure 6, "1" is set for automatic deceleration ST. Also, VCIB110 sets "0" or "1" for VEMDST based on the specifications of ADK200, and does not set "2" for VEMDST. Therefore, manual driving (S205) or fully automated driving (S202) is appropriately executed by processing flow F7 shown in Figure 10.
[0126] When an autonomous driving kit, developed separately from the vehicle (VP100), is installed on the vehicle, the autonomous driving kit may not necessarily possess the functions intended by the vehicle manufacturer. As described above, by having the vehicle (VP100) acquire the specification information of the autonomous driving kit, it becomes possible to perform autonomous driving appropriately using various types of autonomous driving kits.
[0127] It is not necessary for Brake1 and Brake2 to have different configurations. Figure 14 shows a modified example of the configuration shown in Figure 4. In this modified brake system, a brake control unit 121C is provided instead of brake control unit 121B (Figure 4). Brake control unit 121C has the same configuration as brake control unit 121A. Brake control unit 121C includes a motion manager 141C and a brake ECU 142C. The motion manager 141C and brake ECU 142C perform the same functions as motion manager 141A and brake ECU 142A, respectively. Thus, the brake control unit on the first path (Brake1) and the brake control unit on the second path (Brake2) may have the same configuration.
[0128] Figure 15 shows a first modified example of the configuration shown in Figure 3. In the modified example shown in Figure 15, communication lines L31 and L32 (Figure 3) are omitted. In this modified example, there is no third path. The first path (path 170A) corresponds to the main system, and the second path (path 170B) corresponds to the sub-system.
[0129] The functions of Brake1 and Brake2 may be implemented in a single control unit. Also, in ADK200, the functions of ADC211A and 211B may be implemented in a single control unit. Figure 16 shows a second modified example of the configuration shown in Figure 3. In the modified example shown in Figure 16, the base vehicle is equipped with a single control unit (brake control unit 121D) that has these functions instead of brake control units 121A and 121B. Also, the autonomous driving kit according to this modified example is equipped with a single control unit (ADC211D) that has these functions instead of ADC211A and 211B. In the modified example shown in Figure 16, each of the brake control unit 121D and ADC211D is included in both the first route (route 170A) and the second route (route 170B).
[0130] The embodiments disclosed herein should be considered in all respects to be illustrative and not restrictive. The scope of the present invention is indicated by the claims rather than by the description of the embodiments above, and all modifications within the meaning and scope equivalent to the claims are intended to be included. [Explanation of symbols]
[0131] 1 vehicle, 100 vehicle platforms, 110 vehicle control interface boxes, 111A, 111B VCI control units, 120 base vehicles, 121 brake systems, 121A, 121B brake control units, 200 autonomous driving kits.
Claims
1. A vehicle capable of being equipped with an autonomous driving kit, The aforementioned vehicle comprises a vehicle control interface box and a vehicle system, The vehicle control interface box includes a first control device and a second control device. The vehicle system includes a braking device for decelerating the vehicle, The vehicle system is configured to receive commands from the autonomous driving kit through each of a plurality of paths. The plurality of paths include a first path passing through the first control device and a second path passing through the second control device. The aforementioned vehicle system If only one of the multiple routes is lost during autonomous driving, autonomous driving will continue based on the commands received from the autonomous driving kit via the routes other than the lost route. A vehicle configured to perform automatic deceleration control, which controls the braking device to decelerate the vehicle, if both the first and second routes are lost during autonomous driving.
2. The vehicle system further includes a third control device and a fourth control device for controlling the brake device, The first path is a path through which a command from the automatic driving kit reaches the third control unit via the first control unit. The vehicle according to claim 1, wherein the second path is a path through which a command from the autonomous driving kit reaches the fourth control device via the second control device.
3. The plurality of paths further include a third path through which a command from the automatic driving kit reaches the third control device via the second control device, If the first path is not lost, the third control device controls the brake device based on the command received from the automatic driving kit through the first path. The vehicle according to claim 2, wherein if the first path is lost and neither the second path nor the third path is lost, the third control device controls the brake device based on a command received from the automatic driving kit through the third path.
4. The vehicle according to claim 3, wherein if both the first and third routes fail, the third control device or the fourth control device performs the automatic deceleration control.
5. The first control device is configured to determine whether or not communication between the automatic driving kit and the first control device has been lost, and to output the result of that determination to the vehicle system. The vehicle according to any one of claims 1 to 4, wherein the second control device is configured to determine whether or not communication between the automatic driving kit and the second control device has been lost, and to output the result of that determination to the vehicle system.
6. The vehicle control interface box is configured to enable / disable the automatic deceleration control based on a request from the automatic driving kit. The vehicle according to any one of claims 1 to 4, wherein the vehicle system is configured to perform the automatic deceleration control only when the automatic deceleration control is enabled.
7. The vehicle according to claim 6, wherein the vehicle control interface box is configured to prohibit the switching of the automatic deceleration control on or off during autonomous driving.
8. The vehicle according to any one of claims 1 to 4, wherein the vehicle system is configured to continue the automatic deceleration control until the vehicle comes to a stop, without receiving any new commands from the automatic driving kit while the automatic deceleration control is being performed.
9. The vehicle according to claim 8, wherein, when the automatic driving kit transmits a deceleration command requesting the vehicle to decelerate, the vehicle system determines that both the first and second paths have failed, and in the automatic deceleration control, controls the brake device to bring the vehicle's deceleration closer to the larger of the deceleration requested by the deceleration command and a predetermined deceleration.
10. The vehicle system further includes a vehicle drive unit for accelerating the vehicle, The vehicle according to claim 9, wherein, when the automatic driving kit transmits an acceleration command requesting the vehicle to accelerate, the vehicle system determines that both the first and second paths have failed, and in the automatic deceleration control, controls the vehicle drive unit so that the acceleration of the vehicle becomes zero, and then controls the brake unit so that the deceleration of the vehicle approaches a predetermined deceleration.
Citation Information
Patent Citations
Vehicle platform, vehicle control interface box, and automatic driving system
JP2024106017A