Vehicle platform and method for controlling the vehicle platform

The vehicle platform employs redundant control paths and systems to ensure appropriate fallback control, addressing the lack of dual failure handling in existing platforms, enabling safe degraded operations.

JP2026068275APending Publication Date: 2026-04-22TOYOTA JIDOSHA KK
View PDF 1 Cites 0 Cited by

Patent Information

Authority / Receiving Office
JP · JP
Patent Type
Applications
Current Assignee / Owner
TOYOTA JIDOSHA KK
Filing Date
2024-10-10
Publication Date
2026-04-22

AI Technical Summary

Technical Problem

Existing vehicle platforms lack appropriate fallback control mechanisms when both communication paths between the autonomous driving kit and the vehicle platform fail.

Method used

The vehicle platform is configured with redundant control paths and systems that enable evasive or fixed control based on vehicle speed, ensuring appropriate degraded control even in the event of single or dual system failures.

Benefits of technology

Enables the vehicle platform to execute appropriate fallback control, including emergency stops and fixed control, when communication paths fail, maintaining operational safety and functionality.

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure 2026068275000001_ABST
    Figure 2026068275000001_ABST
Patent Text Reader

Abstract

Even if the communication path is lost, appropriate degradation control should be implemented. [Solution] The VP is configured to enable automatic driving by allowing the ADK, which issues instructions for automatic driving, to be attached and detached. The VP comprises a base vehicle, a brake system that identifies the vehicle speed, a vehicle fixing system that performs vehicle fixing control, and a main / sub VCIB that relays control communication between the ADK and the brake system / vehicle fixing system via a first / second path. When a single system failure occurs, the VCIB performs control of evasive driving, including deceleration, based on instructions from the ADK. When a second system failure occurs, the vehicle fixing system performs fixing control when the vehicle speed becomes 0 if the vehicle speed can be obtained (S361, 5, 6, 371), and if the vehicle speed cannot be obtained, it performs the control after a period S has elapsed from the timing start trigger if the vehicle speed immediately before the second system failure is less than a predetermined value (S361, 5, 7, 371), and after a period T (>S) has elapsed from the timing start trigger if the vehicle speed is greater than the predetermined value (S361, 5, 7, 8).
Need to check novelty before this filing date? Find Prior Art

Description

Technical Field

[0001] This disclosure relates to a vehicle platform and a control method for a vehicle platform. In particular, it relates to a vehicle platform configured to be able to attach and detach an autonomous driving kit that gives an instruction for autonomous driving and enables autonomous driving, and a control method for the vehicle platform.

Background Art

[0002] Conventionally, there has been a vehicle platform (hereinafter referred to as "VP (Vehicle Platform)") that can be equipped with an autonomous driving kit (hereinafter referred to as "ADK (Autonomous Driving Kit)") and includes a vehicle control interface box (hereinafter referred to as "VCIB (Vehicle Control Interface Box)") that interfaces between the base vehicle and the autonomous driving system via a communication bus (see, for example, Patent Document 1). In this VP, there are two systems of signal exchange paths between the ADK and the VP: a path via the main bus and the main VCIB, and a path via the sub bus and the sub VCIB.

Prior Art Documents

Patent Documents

[0003]

Patent Document 1

Summary of the Invention

Problems to be Solved by the Invention

[0004] In the VP of Patent Document 1, appropriate fallback control is not considered when both of the two signal exchange paths between the ADK and the VP fail.

[0005] This disclosure was made to solve the aforementioned problems, and its purpose is to provide a vehicle platform and a method for controlling the vehicle platform that can perform appropriate degraded control even if the communication path between the autonomous driving kit and the vehicle platform is lost. [Means for solving the problem]

[0006] The vehicle platform described in this disclosure is configured to enable autonomous driving by allowing the attachment and detachment of an autonomous driving kit that issues instructions for autonomous driving. The vehicle platform comprises a base vehicle, a first vehicle speed identification function unit and a second vehicle speed identification function unit that identify the vehicle speed of the base vehicle, a first vehicle fixing function unit and a second vehicle fixing function unit that perform fixing control to fix the base vehicle, a first vehicle control interface box that relays control communication between the autonomous driving kit and the first vehicle speed identification function unit and the first vehicle fixing function unit via a first path, and a second vehicle control interface box that relays control communication between the autonomous driving kit and the second vehicle speed identification function unit and the second vehicle fixing function unit via a second path. If a single system failure occurs that makes communication or control on the first or second path impossible, the first vehicle control interface box and the second vehicle control interface box will perform control of evasive driving, including deceleration, based on instructions from the autonomous driving kit. If a two-system failure occurs that renders communication or control impossible on the first and second routes, the operational first vehicle fixing function unit and the second vehicle fixing function unit will, if they can obtain vehicle speed from either the first vehicle speed identification function unit or the second vehicle speed identification function unit, execute fixed control when the vehicle speed becomes 0. If they cannot obtain vehicle speed from either the first vehicle speed identification function unit or the second vehicle speed identification function unit, and the vehicle speed immediately before the two-system failure occurs is less than a predetermined value, they will execute fixed control after a first predetermined time has elapsed from the timing start trigger. If the vehicle speed immediately before the two-system failure occurs is greater than a predetermined value, they will execute fixed control after a second predetermined time has elapsed, which is longer than the first predetermined time, from the timing start trigger.

[0007] With this configuration, even if a fault occurs in two systems and the vehicle speed cannot be obtained, if the vehicle speed immediately before the fault occurs is below a predetermined value, a fixed control is executed to fix the base vehicle after a first predetermined time has elapsed from the timing start trigger. If the vehicle speed immediately before the fault occurs is above a predetermined value, the fixed control is executed after a second predetermined time, which is longer than the first predetermined time, has elapsed from the timing start trigger. As a result, it is possible to provide a vehicle platform that can execute appropriate degraded control even if the communication path between the autonomous driving kit and the vehicle platform is lost.

[0008] In the event of a failure in two systems, the operational vehicle locking function unit (either the first or second vehicle locking function unit) may be configured to communicate with the automatic driving kit and, upon receiving a locking control instruction from the automatic driving kit, execute locking control.

[0009] With this configuration, if it can receive fixed control instructions from the autonomous driving kit, it can perform control in accordance with the intentions of the autonomous driving kit by following the instructions of the autonomous driving kit.

[0010] The vehicle platform may further include a high-voltage energy storage device for storing the power used to run the base vehicle, a first low-voltage energy storage device which is charged by stepping down the power from the high-voltage energy storage device and supplies power to a first vehicle speed specification function unit, a first vehicle fixing function unit, and a first vehicle control interface box, and a second low-voltage energy storage device which is charged by the power from the first low-voltage energy storage device and supplies power to a second vehicle speed specification function unit, a second vehicle fixing function unit, and a second vehicle control interface box. The timing start trigger may be when a single system failure occurs and the power supply from the first low-voltage energy storage device is lost.

[0011] With this configuration, if the power supply from the first low-voltage energy storage device is lost, power will no longer be supplied to the second low-voltage energy storage device. Therefore, once the power of the second low-voltage energy storage device is consumed, not only the first vehicle speed identification function unit, the first vehicle locking function unit, and the first vehicle control interface box will become inoperable, but also the second vehicle speed identification function unit, the second vehicle locking function unit, and the second vehicle control interface box will become inoperable. As a result, by using the occurrence of a single-system failure and the loss of power supply from the first low-voltage energy storage device as the trigger for starting the timing of the elapsed time until lock control is executed, lock control can be executed at an appropriate timing.

[0012] The first vehicle locking function unit and the second vehicle locking function unit may be configured to perform emergency stop control in the event of a failure in both systems.

[0013] With this configuration, in the event of a failure in two systems, the base vehicle can be brought to an emergency stop appropriately.

[0014] According to other aspects of this disclosure, a vehicle platform control method is a method for controlling a vehicle platform configured to enable autonomous driving by allowing the attachment and detachment of an autonomous driving kit that issues instructions for autonomous driving. The vehicle platform comprises a base vehicle, a first vehicle speed identification function unit and a second vehicle speed identification function unit that identify the vehicle speed of the base vehicle, a first vehicle fixing function unit and a second vehicle fixing function unit that perform fixing control to fix the base vehicle, a first vehicle control interface box that relays control communication between the autonomous driving kit and the first vehicle speed identification function unit and the first vehicle fixing function unit via a first path, and a second vehicle control interface box that relays control communication between the autonomous driving kit and the second vehicle speed identification function unit and the second vehicle fixing function unit via a second path. The control method includes the steps of: if a single system failure occurs in which the first vehicle control interface box and the second vehicle control interface box become unable to communicate or control on the first or second route, the control method executes control of evasive driving, including deceleration, based on instructions from the automatic driving kit; if a double system failure occurs in which communication or control on the first and second routes becomes impossible, the control method includes the steps of: if the operational first vehicle fixing function unit and the second vehicle fixing function unit can obtain the vehicle speed from either the first vehicle speed identification function unit or the second vehicle speed identification function unit, the control method executes fixed control when the vehicle speed becomes 0; and if the vehicle speed cannot be obtained from either the first vehicle speed identification function unit or the second vehicle speed identification function unit, the control method includes the steps of: if the vehicle speed immediately before the occurrence of the double system failure is less than a predetermined value, the control method executes fixed control after a first predetermined time has elapsed from the timing start trigger, and if the vehicle speed immediately before the occurrence of the double system failure is greater than a predetermined value, the control method executes fixed control after a second predetermined time has elapsed, which is longer than the first predetermined time, from the timing start trigger.

[0015] This configuration provides a vehicle platform control method that enables appropriate degraded control even if the communication path between the autonomous driving kit and the vehicle platform is lost. [Effects of the Invention]

[0016] According to this disclosure, it is possible to provide a vehicle platform and a control method for the vehicle platform that can execute appropriate fallback control even when a communication path between an autonomous driving kit and the vehicle platform fails.

Brief Description of the Drawings

[0017] [Figure 1] FIG. 8 is a diagram showing an overview of a vehicle according to an embodiment of this disclosure. [Figure 2] FIG. 11 is a diagram showing in detail the configurations of the ADK, VCIB, and VP according to this embodiment. [Figure 3] FIG. 14 is a block diagram for explaining power supply and communication of a control system and VCIB in this embodiment. [Figure 4] FIG. 17 is a flowchart showing the flow of processing executed by the control system and the first processing executed by the VCIB in this embodiment. [Figure 5] FIG. 20 is a flowchart showing the flow of processing executed by the vehicle fixing system in this embodiment.

Embodiments for Carrying Out the Invention

[0018] Hereinafter, embodiments of this disclosure will be described in detail with reference to the drawings. The same or corresponding parts in the drawings are denoted by the same reference numerals and their descriptions will not be repeated.

[0019] FIG. 1 is a diagram showing an overview of a vehicle 1 according to an embodiment of this disclosure. FIG. 2 is a diagram showing in detail the configurations of the ADK 10, VCIB 40, and VP 20 according to this embodiment. Referring to FIGS. 1 and 2, the vehicle 1 includes an ADK 10 and a VP 20. The ADK 10 is configured to be attachable to the VP 20 (mountable on the vehicle 1). The ADK 10 and the VP 20 are configured to be communicable with each other via the VCIB 40.

[0020] VP20 can perform autonomous driving in accordance with control requests from ADK10. In FIG. 1, ADK10 is shown at a position separated from VP20, but actually, ADK10 is attached to the roof top or the like of VP20. It is also possible to remove ADK10 from VP20. When ADK10 is removed, VP20 executes driving control (driving control according to user operations) in manual mode (manual driving mode).

[0021] ADK10 includes an autonomous driving system (ADS: Autonomous Driving System) 11 for performing autonomous driving of vehicle 1. ADS11, for example, creates a driving plan for vehicle 1. ADS11 outputs various control requests for driving vehicle 1 according to the driving plan to VP20 in accordance with an API (Application Program Interface) defined for each control request. Also, ADS11 receives various signals indicating the vehicle state (the state of VP20) from VP20 in accordance with an API defined for each signal. Then, ADS11 reflects the vehicle state in the driving plan.

[0022] VP20 includes a base vehicle 30 and a VCIB 40. The base vehicle 30 executes various vehicle controls in accordance with control requests from ADK10 (ADS11). The base vehicle 30 includes various in-vehicle systems and various sensors for controlling the base vehicle 30. More specifically, the base vehicle 30 includes an integrated control manager 31, a brake system 32, a steering system 33, a power train system 34, an active safety system 35, a body system 36, wheel speed sensors 51, 52, a pinion angle sensor 53, a camera 54, and radar sensors 55, 56.

[0023] The integrated control manager 31 includes a processor such as a CPU (Central Processing Unit) and memory such as ROM (Read Only Memory) and RAM (Random Access Memory), and integrates and controls the above-mentioned systems (brake system 32, steering system 33, powertrain system 34, active safety system 35, body system 36) involved in the operation of the vehicle 1.

[0024] The brake system 32 is configured to control braking devices provided on each wheel of the base vehicle 30. The braking devices include, for example, a disc brake system that operates in response to hydraulic pressure adjusted by an actuator.

[0025] Wheel speed sensors 51 and 52 are connected to the brake system 32. The wheel speed sensors 51 and 52 detect the rotational speed of the front and rear wheels of the base vehicle 30, respectively, and output the detected front and rear wheel rotational speeds to the brake system 32. The brake system 32 outputs the rotational speed of each wheel to the VCIB 40 as one of the pieces of information included in the vehicle state. The brake system 32 also generates a braking command for the braking device according to a predetermined control request output from the ADS 11 via the VCIB 40 and the integrated control manager 31. The brake system 32 controls the braking device using the generated braking command. The integrated control manager 31 can calculate the speed of the vehicle 1 (vehicle speed) based on the rotational speed of each wheel.

[0026] The steering system 33 is configured to control the steering angle (tire turning angle) of the steering wheels of the vehicle 1 using a steering device. The steering device includes, for example, a rack-and-pinion type electric power steering (EPS) in which the steering angle can be adjusted by an actuator.

[0027] A pinion angle sensor 53 is connected to the steering system 33. The pinion angle sensor 53 detects the rotation angle (pinion angle) of the pinion gear connected to the rotation axis of the actuator and outputs the detected pinion angle to the steering system 33. The steering system 33 outputs the pinion angle to the VCIB 40 as one of the pieces of information included in the vehicle state. The steering system 33 also generates steering commands for the steering device according to predetermined control requests output from the ADS 11 via the VCIB 40 and the integrated control manager 31. The steering system 33 controls the steering device using the generated steering commands.

[0028] The powertrain system 34 controls vehicle locking systems 341 and 342 that control an electric parking brake (EPB) provided on at least one of the wheels and a parking lock (P-Lock) device provided on the transmission of vehicle 1, and a propulsion system 343 that includes a shift device configured to allow selection of the shift range.

[0029] The active safety system 35 uses a camera 54 and radar sensors 55, 56 to detect obstacles in front of or behind the vehicle (pedestrians, bicycles, parked vehicles, utility poles, etc.). Based on the distance between the vehicle 1 and the obstacle, and the direction of movement of the vehicle 1, the active safety system 35 determines whether the vehicle 1 is likely to collide with the obstacle. If the active safety system 35 determines that a collision is likely, it outputs a braking command to the brake system 32 via the integrated control manager 31 to increase the braking force.

[0030] The body system 36 is configured to control components such as turn signals (turn lamps, hazard lamps), horns, wipers, headlights, and brake lights, for example, depending on the driving conditions or environment of the vehicle 1. The body system 36 controls each of the above components according to predetermined control requests output from the ADS 11 via the VCIB 40 and the integrated control manager 31.

[0031] The VCIB40 is configured to communicate with the ADS11 via CAN (Controller Area Network) or the like. The VCIB40 receives various control requests from the ADS11 and outputs vehicle status to the ADS11 by executing predetermined APIs defined for each signal. When the VCIB40 receives a control request from the ADK10, it outputs a control command corresponding to that control request to the system corresponding to that control command via the integrated control manager 31. The VCIB40 also acquires various information about the base vehicle 30 from various systems via the integrated control manager 31 and outputs the status of the base vehicle 30 as vehicle status to the ADS11.

[0032] Vehicle 1 can be used as part of a Mobility as a Service (MaaS) system. In addition to Vehicle 1, the MaaS system includes, for example, a data server and a Mobility Service Platform (MSPF).

[0033] MSPF is a unified platform that connects various mobility services. Autonomous driving-related mobility services are connected to MSPF. In addition to autonomous driving-related services, MSPF may also connect mobility services provided by ride-sharing companies, car-sharing companies, rental car companies, taxi companies, insurance companies, and others.

[0034] Vehicle 1 is further equipped with a Data Communication Module (DCM) capable of wireless communication with a data server. The DCM outputs vehicle information, such as speed, location, and autonomous driving status, to the data server. The DCM also receives various data from mobility services, such as the MSPF and data server, for managing the operation of autonomous vehicles, including Vehicle 1, in autonomous driving-related mobility services.

[0035] MSPF provides APIs for accessing various vehicle status and control data necessary for ADS11 development. Various mobility services can use the APIs published on MSPF to utilize the various functions provided by MSPF according to their service content. For example, autonomous driving-related mobility services can use the APIs published on MSPF to obtain driving control data for vehicle 1, information stored on the data server, etc. from MSPF. In addition, autonomous driving-related mobility services can use the above APIs to send data for managing autonomous vehicles, including vehicle 1, to MSPF.

[0036] The ADS11 includes a computer 111, an HMI (Human Machine Interface) 112, a recognition sensor 113, a posture sensor 114, and a sensor cleaner 115.

[0037] Computer 111 includes a processor 101 such as a CPU and memory 102 such as ROM and RAM. Memory 102 stores programs that can be executed by the processor 101. During the automatic driving of vehicle 1, computer 111 uses various sensors (described later) to acquire the environment of vehicle 1, as well as the attitude, behavior, and position of vehicle 1, and acquires the vehicle state from VP20 via VCIB40 to set the next action of vehicle 1 (acceleration, deceleration, turning, etc.). Computer 111 outputs various commands to VCIB40 to realize the next action. Computer 111 further includes communication modules 111A and 111B. Each of communication modules 111A and 111B is configured to communicate with VCIB40.

[0038] The HMI112 presents information to the user and accepts user input during autonomous driving, manual driving requiring user intervention, and transitions between autonomous driving and manual driving requiring user intervention. The HMI112 includes, for example, an input / output device such as a touch panel display provided on the base vehicle 30.

[0039] The recognition sensor 113 is a sensor for recognizing the environment of vehicle 1. The recognition sensor 113 includes, for example, at least one of LIDAR (Laser Imaging Detection and Ranging), millimeter-wave radar, and camera. LIDAR measures the distance and direction of an object by, for example, emitting infrared pulsed laser light and detecting the reflected light from the object. Millimeter-wave radar measures the distance and direction of an object by emitting millimeter waves and detecting the reflected waves from the object. Camera is, for example, positioned behind the rearview mirror and captures an image of the area in front of vehicle 1.

[0040] The attitude sensor 114 is a sensor for detecting the attitude, behavior, and position of vehicle 1. The attitude sensor 114 includes, for example, an IMU (Inertial Measurement Unit) and a GPS (Global Positioning System). The IMU detects, for example, the acceleration of vehicle 1 in the longitudinal, lateral, and vertical directions, and the angular velocity of vehicle 1 in the roll, pitch, and yaw directions. The GPS detects the position of vehicle 1 using information received from multiple GPS satellites orbiting the Earth.

[0041] The sensor cleaner 115 is configured to remove dirt that adheres to the various sensors (camera lenses, laser beam irradiation parts, etc.) while the vehicle 1 is in motion, using a cleaning solution, wipers, etc.

[0042] VCIB40 includes a main VCIB41 and a sub-VCIB42. VCIB41 and VCIB42 each include processors such as a CPU 411 and 421, and memory such as ROM and RAM 412 and 422, respectively. Memory 412 and 422 each store programs executable by processors 411 and 421 and data processed by those programs. The main VCIB41 and communication module 111A are connected to each other via communication bus 43 (main bus). The sub-VCIB42 and communication module 111B are connected to each other via communication bus 44 (sub-bus). Furthermore, the main VCIB41 and sub-VCIB42 are connected to each other in a communication manner.

[0043] Each of the VCIBs, 41 and 42, relays control requests and vehicle information between the ADS11 and the VP20. The VCIBs 41 and 42 interface between the base vehicle 30 and the ADS11 via communication buses 43 and 44. The VCIBs 41 and 42 generate control commands from control requests received from the ADS11 using APIs.

[0044] The control commands supplied from ADS11 to VCIB40 in response to control requests include, for example, a propulsion direction command requesting a shift range change, a stationary command requesting activation / deactivation of the EPB and P-Lock devices, an acceleration command requesting acceleration or deceleration of vehicle 1, a steering angle command requesting the steering wheel angle, an autonomization command requesting switching between autonomous mode and manual mode, and a stop command requesting the vehicle to be stopped or released from being stopped.

[0045] VCIB41 and 42 then output the generated control commands to the corresponding systems among the multiple systems included in VP20. Furthermore, VCIB41 and 42 use an API to generate vehicle status information from vehicle information received from each system of VP20. This vehicle status information may be identical to the vehicle information, or it may be information extracted from the vehicle information for use in processing performed by ADS11. VCIB41 and 42 then output the generated vehicle status information to ADS11.

[0046] Brake system 32 includes brake systems 321 and 322. Steering system 33 includes steering systems 331 and 332. Powertrain system 34 includes vehicle fixing system 340 and propulsion system 343. Vehicle fixing system 340 includes vehicle fixing systems 341 and 342.

[0047] VCIB41 and 42 have essentially equivalent functions, but there are some differences in how they connect to the in-vehicle systems included in VP20. Specifically, the main VCIB41 is connected to the brake system 321, steering system 331, vehicle fixing systems 341 and 342, propulsion system 343, and body system 36 via a communication bus, enabling them to communicate with each other. The sub-VCIB42 is connected to the brake system 322, steering system 332, and vehicle fixing systems 341 and 342 via a communication bus, enabling them to communicate with each other.

[0048] Thus, by including VCIB40 with VCIB41 and VCIB42, which have equivalent functions for the operation of some systems (such as brakes and steering), the control system between ADS11 and VP20 is made redundant. Therefore, if any failure occurs in the system, the functionality of VP20 can be maintained by appropriately switching control systems or shutting off the failed control system.

[0049] Brake systems 321 and 322 each include a processor 3211 and 3221, such as a CPU, and memory 3212 and 3222, such as ROM and RAM. Each of the brake systems 321 and 322 is configured to control the braking device. Brake systems 321 and 322 each generate braking commands for the braking device in accordance with control requests output from ADS 11 via VCIB 41 and 42. Brake systems 321 and 322 may have equivalent functions. Alternatively, one of the brake systems 321 and 322 may be configured to independently control the braking force of each wheel, while the other is configured to control the generation of the same braking force on each wheel. Brake systems 321 and 322 may, for example, control the braking device using braking commands generated by one of the brake systems, and if a malfunction occurs in that brake system, control the braking device using braking commands generated by the other brake system.

[0050] The steering systems 331 and 332 each include a processor 3311 and 3321, such as a CPU, and memory 3312 and 3322, such as ROM and RAM. Each of the steering systems 331 and 332 is configured to control the steering angle of the steering wheels of the vehicle 1 using a steering device. The steering systems 331 and 332 each generate steering commands for the steering device in accordance with control requests output from the ADS 11 via VCIB 41 and 42. The steering systems 331 and 332 may have equivalent functions. Alternatively, the steering systems 331 and 332 may, for example, control the steering device using steering commands generated by one of the steering systems, and if a malfunction occurs in that steering system, control the steering device using steering commands generated by the other steering system.

[0051] The vehicle locking systems 341 and 342 each include a processor such as a CPU 3411 and 3421, and memory such as ROM and RAM 3412 and 3422, respectively. The vehicle locking systems 341 and 342 control the EPB and P-Lock devices according to control requests output from the ADS 11 via VCIB 41 and 42. The EPB is provided separately from the braking system (such as a disc brake system) and locks the wheels by the operation of an actuator. For example, the EPB locks the wheels by using an actuator to operate a drum brake for a parking brake provided on some of the wheels, or by using an actuator that can adjust the hydraulic pressure supplied to the braking system separately from the brake systems 321 and 322 to lock the wheels. The vehicle locking systems 341 and 342 have a brake hold function and are configured to allow switching between operating and releasing the brake hold.

[0052] The vehicle locking systems 341 and 342 activate the P-Lock device when, for example, a control request includes a request to set the shift range to the parking range (P range), and deactivate the P-Lock device when a control request includes a request to set the shift range to a range other than the P range. The P-Lock device engages the projection at the tip of a parking lock pawl, whose position can be adjusted by an actuator, with the teeth of a gear (lock gear) connected to a rotating element in the transmission of the vehicle 1. This fixes the rotation of the output shaft of the transmission and locks the wheels.

[0053] The propulsion system 343 includes a processor 3431 such as a CPU and memory 3432 such as ROM and RAM. The propulsion system 343 also includes a direction control system and a propulsion force system. The direction control system is connected to the VCIB 40. The direction control system controls the direction of travel (forward or reverse) of the VP20 by switching the shift range of the shift device according to control requests output from the ADS 11 via the VCIB 41. The shift range includes a P range and a neutral range (N range), as well as a forward driving range (D range) and a reverse driving range (R range). The propulsion force system is connected to the VCIB 40. The propulsion force system controls the propulsion force (e.g., acceleration and deceleration) of the VP20 by controlling the driving force from a drive source (motor generator, engine, etc.).

[0054] The active safety system 35 includes a processor 351 such as a CPU and memory 352 such as ROM and RAM. The active safety system 35 is communicatively connected to the brake system 321. As described above, the active safety system 35 uses the camera 54 and / or radar sensor 55 to detect obstacles ahead and outputs a braking command to the brake system 321 to increase the braking force when it determines that a collision is possible.

[0055] The body system 36 includes a processor 361 such as a CPU and memory 362 such as ROM and RAM. The body system 36 controls components such as turn signals, horns, and wipers according to control requests output from the ADS 11 via the VCIB 41.

[0056] In vehicle 1, autonomous driving is performed when, for example, the user's operation on the HMI 112 selects the autonomous mode (autonomous driving mode). As mentioned above, during autonomous driving, ADS 11 first creates a driving plan. Examples of driving plans include a plan to continue driving straight, a plan to turn left / right at a predetermined intersection along a predetermined driving route, and a plan to change driving lanes. ADS 11 calculates the controllable physical quantities (acceleration, deceleration, tire steering angle, etc.) necessary for vehicle 1 to operate according to the created driving plan. ADS 11 divides the physical quantities for each API execution cycle. ADS 11 uses the API to output control requests representing the divided physical quantities to VCIB 40. Furthermore, ADS 11 obtains the vehicle state (actual direction of movement of vehicle 1, vehicle fixation state, etc.) from VP 20 and recreates the driving plan reflecting the obtained vehicle state. In this way, ADS 11 enables autonomous driving of vehicle 1.

[0057] As described above, in vehicle 1, there are two routes for exchanging signals between ADK10 and VP20: a first route via the main bus, communication bus 43 and the main VCIB41, and a second route via the sub-bus, communication bus 44 and the sub-VCIB42. Conventionally, no consideration was given to performing appropriate degraded control if both of these routes failed.

[0058] Therefore, if a single system failure occurs that renders communication or control impossible on either the first or second route, VCIB41,42 will execute control of evasive driving, including deceleration, based on instructions from ADK10. If a double system failure occurs that renders communication or control impossible on both the first and second routes, the operational vehicle fixing system 341,342 will, if it can obtain vehicle speed from either brake system 321,322, execute fixing control to fix the base vehicle 30 when the vehicle speed becomes 0. If it cannot obtain vehicle speed from either brake system 321,322, and the vehicle speed immediately before the occurrence of the double system failure is less than a predetermined value, it will execute fixing control after a first predetermined time has elapsed from the timing start trigger. If the vehicle speed immediately before the occurrence of the double system failure is greater than a predetermined value, it will execute fixing control after a second predetermined time has elapsed, which is longer than the first predetermined time, from the timing start trigger.

[0059] As a result, even if a fault occurs in two systems and the vehicle speed cannot be obtained, if the vehicle speed immediately before the fault occurs is below a predetermined value, fixed control will be executed after a first predetermined time has elapsed from the timing start trigger. If the vehicle speed immediately before the fault occurs is above a predetermined value, fixed control will be executed after a second predetermined time, which is longer than the first predetermined time, has elapsed from the timing start trigger. Consequently, appropriate degraded control can be executed even if the communication path between ADK10 and VP20 is lost.

[0060] Figure 3 is a block diagram illustrating the control system and the power supply and communication of VCIBs 41 and 42 in this embodiment. Referring to Figure 3, the base vehicle 30 includes, as a power supply configuration, a high-voltage battery 61, a relay 62, a DC (Direct Current) DC converter 63, a 12V main power supply 64, a relay 65, and a 12V sub-power supply 66.

[0061] The high-voltage battery 61 is a secondary battery that stores high-voltage power (e.g., several hundred volts) primarily used for propelling the base vehicle's motor generator. The high-voltage battery 61 is composed of, for example, a lithium-ion battery, but is not limited to this, and may be other types of secondary batteries, such as nickel-metal hydride batteries or solid-state batteries.

[0062] The 12V main power supply 64 is a secondary battery that stores low-voltage (12V in this embodiment) power used in the control system (for example, VCIB41, brake system 321, and vehicle fixing system 341) of the first path via the main bus, which is the communication bus 43 and the main VCIB41. The 12V main power supply 64 is composed of, for example, a lead-acid battery, but is not limited to this, and may be other types of secondary batteries, or a lithium-ion battery.

[0063] The DC-DC converter 63 converts the high voltage of the high-voltage battery 61 to the lower voltage of the 12V main power supply 64 and supplies it to the 12V main power supply 64. The relay 62 switches the connection or disconnection of the power line between the high-voltage battery 61 and the DC-DC converter 63.

[0064] The 12V sub-power supply 66 is a secondary battery that stores low-voltage (12V in this embodiment) power used in a second path control system (e.g., VCIB42, brake system 322, and vehicle fixing system 342) via the sub-bus, which is the communication bus 44, and the sub-VCIB42. The 12V sub-power supply 66 is composed of, for example, a lithium-ion battery, but is not limited to this, and may be other types of secondary batteries, such as nickel-metal hydride batteries or all-static batteries. The 12V sub-power supply 66 is powered by the 12V main power supply 64. Relay 65 switches the connection or disconnection of the power lines between the 12V main power supply 64 and the 12V sub-power supply 66.

[0065] VCIB41 and 42 can communicate with each other via communication buses 43 and 44, respectively, with the communication modules 111A and 111B of the ADS11's computer 111. VCIB41, the brake system 321, and the vehicle locking systems 341 and 342 can communicate with each other. VCIB42, the brake system 321 and 322, and the vehicle locking systems 341 and 342 can communicate with each other. The vehicle locking systems 341 and 342 are controlled by sending control signals to the P-Lock device 349.

[0066] Figure 4 is a flowchart showing the flow of processing performed by the control system and the first processing performed by VCIB41,42 in this embodiment. Referring to Figure 4, each control system process is called from higher-level processing at predetermined intervals by the processors of the control system of the base vehicle 30 (for example, processors 3211,3221 for the brake systems 321,322 and processors 3411,3421 for the vehicle fixing systems 341,342). The VCIB process is called from higher-level processing at predetermined intervals by the processors 411,421 of VCIB41,42.

[0067] The control system's processor determines whether a single-system failure has been detected that renders communication or control impossible on the first or second path (step S311). If it determines that a single-system failure has been detected (YES in step S311), the control system's processor notifies VCIB41 and 42 that a single-system failure has been detected (step S312).

[0068] The processors 411 and 421 of VCIB41 and 42 determine whether or not they have received a notification from the control system that a single-system fault has been detected (step S411). If they determine that they have received a notification from either control system that a single-system fault has been detected (YES in step S411), the processors 411 and 421 of VCIB41 and 42 switch the single-system fault flag, which indicates whether or not a single-system fault has occurred, to the ON state, which indicates that a single-system fault has occurred (step S412).

[0069] The processors 411 and 421 of VCIB41 and 42 determine whether the driving mode of VCIB41 and 42 is automatic driving mode (step S413). If it is determined that it is automatic driving mode (YES in step S413), the processors 411 and 421 of VCIB41 and 42 start controlling the vehicle to move away in accordance with the instructions of ADK10 (step S414). The vehicle to move away is to move to a safer location than the roadway, such as a parking area, parking lot, or shoulder of the road.

[0070] The control system processor determines whether a two-system fault has been detected that would render communication or control impossible on the first and second paths (step S313). If it determines that a two-system fault has been detected (YES in step S313), the control system processor notifies VCIB41 and 42 that a two-system fault has been detected (step S314) and executes control to bring the base vehicle 30 to an emergency stop (step S316). Here, the control to bring the vehicle to an emergency stop may include only deceleration control, or it may include deceleration control plus minimal steering control to move the base vehicle 30 to a safer location such as the shoulder of the road compared to the lane. If it determines that a two-system fault has not been detected (NO in step S313), or after step S316, the control system processor returns the processing to be executed to the higher-level processing that called each of these control system processes.

[0071] If it is determined that no single-system fault has been detected from any of the control systems (NO in step S411), or if it is determined that the system is not in automatic operation mode (NO in step S413), or after step S414, the processors 411 and 421 of VCIB 41 and 42 determine whether or not they have received a notification from the control system that a double-system fault has been detected (step S415). If it is determined that a notification from any of the control systems that a double-system fault has been detected (YES in step S415), the processors 411 and 421 of VCIB 41 and 42 switch the double-system fault flag, which indicates whether or not a double-system fault has occurred, to the ON state, indicating that a double-system fault has occurred (step S416). After that, the processors 411 and 421 of VCIB 41 and 42 proceed with the processing to be executed, starting with the circled number "1" in Figure 4 described later.

[0072] Figure 5 is a flowchart showing the processing flow performed in the vehicle fixing systems 341 and 342 in this embodiment. Referring to Figure 5, this processing is called from higher-level processing and executed by the processors 3411 and 3421 of the vehicle fixing systems 341 and 342 at predetermined intervals.

[0073] The processors 3411 and 3421 of the vehicle fixing systems 341 and 342 query the VCIBs 41 and 42 to determine whether the one-system fault flag is in the ON state (step S351). If it is determined that the one-system fault flag is in the ON state (YES in step S351), the processors 3411 and 3421 of the vehicle fixing systems 341 and 342 determine whether the 12V main power supply 64 system has failed (step S352). The failure of the 12V main power supply 64 system can be determined, for example, by the inability to exchange signals with other control systems or VCIBs 41 that receive power from the 12V main power supply 64.

[0074] If it is determined that the 12V main power supply is lost (YES in step S352), the processors 3411 and 3421 of the vehicle locking systems 341 and 342 start counting up the P-Lock timer used for P-Lock control (step S353).

[0075] If it is determined that the 1-system fault flag is not in the ON state (NO in step S351), or if it is determined that the 12V main power supply has not failed (NO in step S352), or after step S353, the processors 3411 and 3421 of the vehicle fixing systems 341 and 342 determine whether a 2-system fault was detected in step S313 of Figure 4 (step S361). If it is determined that a 2-system fault has been detected (YES in step S361), the processors 3411 and 3421 of the vehicle fixing systems 341 and 342 determine whether the P-Lock device 349 is operational (step S362).

[0076] If it is determined that the P-Lock device 349 is operational (YES in step S362), the processors 3411 and 3421 of the vehicle fixing systems 341 and 342 determine whether or not they can communicate with the ADK 10 via the VCIBs 41 and 42 (step S363). If it is determined that communication with the ADK 10 is operational (YES in step S363), the processors 3411 and 3421 of the vehicle fixing systems 341 and 342 determine whether or not the ADK 10 has issued a P-Lock instruction to activate the P-Lock device 349 (step S364).

[0077] If it is determined that communication with ADK10 is not possible (NO in step S363), or if it is determined that there is no P-Lock instruction from ADK10, the processors 3411 and 3421 of the vehicle locking systems 341 and 342 determine whether it is possible to reference the vehicle speed from the brake systems 321 and 322 (step S365). If it is determined that it is possible to reference the vehicle speed (YES in step S365), the processors 3411 and 3421 of the vehicle locking systems 341 and 342 determine whether the referenced vehicle speed is 0 (step S366).

[0078] If it is determined that it is not possible to refer to the vehicle speed from the brake systems 321 and 322 (NO in step S365), or if it is determined that the vehicle speed is not 0 (NO in step S366), the processors 3411 and 3421 of the vehicle locking systems 341 and 342 determine whether the vehicle speed at the time of the two-system failure is within the shift control guaranteed range (step S367). The vehicle speed at the time of the two-system failure being within the shift control guaranteed range means that the vehicle speed range in which it is guaranteed through experiments or simulations that the P-Lock device 349 will not fail even if P-Lock control is performed is, for example, within a predetermined speed range.

[0079] When a two-system failure occurs, if it is possible to refer to the vehicle speed, it may be immediately after the two-system failure occurs. If it is not possible to refer to the vehicle speed, it may be immediately before the two-system failure occurs. Alternatively, it may be immediately before the two-system failure occurs regardless of whether it is possible to refer to the vehicle speed. Immediately before the two-system failure occurs may be, for example, a predetermined short time (for example, from a few milliseconds to a few seconds) before the two-system failure occurs, or a predetermined number of control cycles (for example, one to several) before the control cycle at the time of the two-system failure. Immediately after the two-system failure occurs may be, for example, a predetermined short time (for example, from a few milliseconds to a few seconds) after the two-system failure occurs, or a predetermined number of control cycles (for example, one to several) after the control cycle at the time of the two-system failure occurs.

[0080] If it is determined that the vehicle speed is not within the range guaranteed by the shift control (NO in step S367), the processors 3411 and 3421 of the vehicle locking systems 341 and 342 determine whether the count value of the P-Lock timer, which was started counting up in step S353, is equal to or greater than a value indicating a predetermined period T (step S368). The predetermined period T is the period during which the 12V sub-power supply 66 can supply power, and for example, it may be the period during which the 12V sub-power supply 66 can supply power from a full charge when there is no power supply, or it may be the period during which the 12V sub-power supply 66 can supply power from a predetermined SOC when there is no power supply.

[0081] If it is determined that a P-Lock instruction has been received from ADK10 (YES in step S364), if it is determined that the vehicle speed is 0 (YES in step S366), if it is determined that the vehicle speed at the time of the failure of two systems is within the range of guaranteed shift control (YES in step S367), or if it is determined that the count value of the P-Lock timer is equal to or greater than the value indicating a predetermined period T (YES in step S368), then the processors 3411 and 3421 of the vehicle locking systems 341 and 342 execute P-Lock control (step S371) and send an instruction to the propulsion system 343 to change the shift position to the "P" position (step S372).

[0082] If it is determined that no fault has been detected in two systems (NO in step S361), if it is determined that the P-Lock device is not operational (NO in step S362), if it is determined that the P-Lock timer is not set for a predetermined period T or longer (NO in step S368), or after step S372, the processors 3411 and 3421 of the vehicle fixing systems 341 and 342 return the processing to be executed to the higher-level processing of the caller of this vehicle fixing control system processing.

[0083] [Differentiation] (1) In the embodiment described above, as shown in steps S365 to S371 of Figure 5, even if the vehicle speed cannot be referenced from the brake systems 321 and 322, if the vehicle speed at the time of two-system failure is within the shift control guaranteed range, P-Lock control is performed regardless of the count value of the P-Lock timer. However, the embodiment is not limited to this, and if the vehicle speed cannot be referenced from the brake systems 321 and 322 and the vehicle speed at the time of two-system failure is within the shift control guaranteed range, P-Lock control may be performed if the count value of the P-Lock timer is equal to or greater than the value indicating a predetermined period S. Here, the predetermined period S is a shorter period than the predetermined period T shown in step S368. The embodiment described above is the case where this predetermined period S is 0.

[0084] (2) In the embodiment described above, the P-Lock timer count-up is started when the 1-system fault flag is in the ON state and the 12V main power supply 64 is lost. However, it is not limited to this, and the trigger for starting the P-Lock timer count-up may be other triggers, for example, when the 1-system fault flag is turned ON, or when the 12V main power supply 64 is lost.

[0085] (3) In the embodiments described above, as shown in Figures 1 to 3, the brake systems 321 and 322 are configured to determine the vehicle speed of the base vehicle 30. However, the system is not limited to this, and the vehicle speed of the base vehicle 30 may be determined by other control systems or VCIBs 41 and 42.

[0086] (4) In the embodiments described above, the first and second functional units that perform specific functions used for autonomous and manual driving, such as the brake systems 321, 322, the vehicle fixing systems 341, 342, or the steering systems 331, 332, are provided with processors and memories. The first and second functional units work in cooperation with VCIBs 41, 42 to perform specific functions of the base vehicle 30. However, the division of functions between the processors and memories of VCIBs 41, 42 and each functional unit may be any. For example, VCIBs 41, 42 may perform some of the functions that the processors and memories of each functional unit would perform.

[0087] (5) In the embodiments described above, the brake systems 321, 322 and the vehicle fixing systems 341, 342 directly exchange information such as vehicle speed. However, the invention is not limited to this, and the brake systems 321, 322 and the vehicle fixing systems 341, 342 may exchange information via VCIB 41, 42.

[0088] (6) The embodiments described above can be interpreted as disclosures of devices such as Vehicle 1, ADK10, ADS11, VP20, Base Vehicle 30, or VCIB41,42, or as disclosures of control methods or control programs for these devices.

[0089] [summary] (1) As shown in Figures 1 and 2, the VP20 is configured to enable autonomous driving by detaching the ADK10 which issues instructions for autonomous driving. As shown in Figures 1 and 2, the VP20 includes a base vehicle 30, a first vehicle speed identification function unit and a second vehicle speed identification function unit (for example, brake systems 321, 322) that identify the vehicle speed of the base vehicle 30, a first vehicle fixing function unit and a second vehicle fixing function unit (for example, vehicle fixing systems 341, 342) that perform fixing control to fix the base vehicle, a VCIB41 that relays control communication between the ADK10 and the first vehicle speed identification function unit and the first vehicle fixing function unit via a first route (for example, a route including a communication bus 43), and a VCIB42 that relays control communication between the ADK10 and the second vehicle speed identification function unit and the second vehicle fixing function unit via a second route (for example, a route including a communication bus 44).

[0090] As shown in Figure 4, if a single system failure occurs that renders communication or control impossible on either the first or second route, VCIB41 and 42 will execute control of evasive driving, including deceleration, based on instructions from ADK10 (for example, steps S411 and S414). As shown in Figure 5, if a double system failure occurs that renders communication or control impossible on both the first and second routes, the operational first vehicle fixing function unit and the second vehicle fixing function unit will execute fixing control when the vehicle speed becomes 0 if they can obtain the vehicle speed from either the first vehicle speed identification function unit or the second vehicle speed identification function unit (for example, steps S361, S365, S366, and S371). If they cannot obtain the vehicle speed from either the first or second vehicle speed identification function unit, the vehicle speed immediately before the occurrence of the double system failure will be a predetermined value. If the value is less than the specified value, fixed control is performed after a first predetermined time (for example, a predetermined period S as shown in the modified example) has elapsed from the timing start trigger (for example, steps S361, S365, S367, and S371. Note that in Figure 5, the predetermined period S=0). If the vehicle speed immediately before the occurrence of a two-system failure exceeds the specified value, fixed control is performed after a second predetermined time (for example, a predetermined period T(>S)) which is longer than the first predetermined time (for example, steps S361, S365, S367, and S368).

[0091] As a result, even if a fault occurs in two systems and the vehicle speed cannot be obtained, if the vehicle speed immediately before the fault occurs in two systems is below a predetermined value, a fixed control is executed to fix the base vehicle 30 after a first predetermined time has elapsed from the timing start trigger. If the vehicle speed immediately before the fault occurs in two systems is above a predetermined value, the fixed control is executed after a second predetermined time, which is longer than the first predetermined time, has elapsed from the timing start trigger. As a result, appropriate degraded control can be executed even if the communication path between ADK10 and VP20 is lost.

[0092] (2) As shown in Figure 5, if a failure occurs in two systems, the operational unit of the first vehicle fixing function unit and the second vehicle fixing function unit may be configured to communicate with ADK10 and, if it receives a fixing control instruction from ADK10, execute the fixing control (for example, steps S361, S363, and S364).

[0093] This allows the system to perform control in accordance with the intentions of the ADK10 (or the ADK10 manufacturer) by following the instructions of the ADK10, provided that it can receive fixed control instructions from the ADK10.

[0094] (3) As shown in Figure 3, the VP20 may further include a high-voltage battery 61 for storing the power used to run the base vehicle 30, a 12V main power supply 64 which charges the high-voltage battery 61 by stepping down the voltage and supplies power to the first vehicle speed specification function unit, the first vehicle fixing function unit, and the main VCIB41, and a 12V sub-power supply 66 which is charged by the power from the 12V main power supply 64 and supplies power to the second vehicle speed specification function unit, the second vehicle fixing function unit, and the sub-VCIB42. As shown in Figure 5, the timing start trigger may be when a single-system failure occurs and the power supply from the first low-voltage energy storage device is lost (for example, from step S351 to step S353).

[0095] As a result, if the power supply from the 12V main power supply 64 is lost, power will no longer be supplied to the 12V sub-power supply 66. Therefore, if the power of the 12V sub-power supply 66 is consumed, not only the first vehicle speed identification function unit, the first vehicle locking function unit, and the main VCIB 41 will become inoperable, but also the second vehicle speed identification function unit, the second vehicle locking function unit, and the sub-VCIB 42 will become inoperable. Consequently, by using the occurrence of a single-system failure and the loss of power supply from the 12V main power supply 64 as the trigger for starting the timing of the elapsed time until lock control is executed, lock control can be executed at an appropriate timing.

[0096] (4) As shown in Figure 4, the first vehicle fixing function unit and the second vehicle fixing function unit may perform emergency stop control in the event of a failure in both systems (for example, steps S313 and S316).

[0097] This allows the base vehicle 30 to be brought to an emergency stop appropriately in the event of a failure in both systems.

[0098] The embodiments disclosed herein should be considered in all respects to be illustrative and not restrictive. The scope of this disclosure is indicated by the claims rather than by the description of the embodiments above, and all modifications within the meaning and scope equivalent to the claims are intended to be included. [Explanation of Symbols]

[0099] 1 Vehicle, 10 ADK, 11 ADS, 20 VP, 30 Base Vehicle, 31 Integrated Control Manager, 32, 321, 322 Brake System, 33, 331, 332 Steering System, 34 Powertrain System, 35 Active Safety System, 36 Body System, 40, 41, 42 VCIB, 43, 44 Communication Bus, 51, 52 Wheel Speed ​​Sensor, 53 Pinion Angle Sensor, 54 Camera, 55, 56 Radar Sensor, 61 High Voltage Battery, 62, 65 Relay, 63 DC-DC Converter, 64 12V Main Power Supply, 66 12V Sub Power Supply, 101, 351, 361, 411, 421, 3211, 3221, 3311, 3321, 3411, 3421, 3431 Processor, 102, 352, 362, 412, 422, 3212, 3222, 3312, 3322, 3412, 3422, 3432 Memory, 111 Computer, 111A, 111B Communication module, 112 HMI, 113 Recognition sensor, 114 Attitude sensor, 115 Sensor cleaner, 340, 341, 342 Vehicle fixing system, 343 Propulsion system, 349 P-Lock device.

Claims

1. A vehicle platform configured to enable autonomous driving by allowing the attachment and detachment of an autonomous driving kit that issues instructions for autonomous driving, The base vehicle and A first vehicle speed identification function unit and a second vehicle speed identification function unit that identify the vehicle speed of the base vehicle, A first vehicle fixing function unit and a second vehicle fixing function unit perform fixing control to fix the base vehicle, A first vehicle control interface box relays control communication between the automatic driving kit and the first vehicle speed identification function unit and the first vehicle locking function unit via a first path, The system includes a second vehicle control interface box that relays control communication between the automatic driving kit and the second vehicle speed specification function unit and the second vehicle locking function unit via a second path, If a single system failure occurs that renders communication or control impossible on the first or second route, the first vehicle control interface box and the second vehicle control interface box will execute control of evasive driving, including deceleration, based on instructions from the automatic driving kit. If a two-system failure occurs in which communication or control becomes impossible in the first and second routes, the operational vehicle fixing function unit of the first and second vehicle fixing function units shall If the vehicle speed can be obtained from either the first vehicle speed identification function unit or the second vehicle speed identification function unit, the fixed control is executed when the vehicle speed becomes 0. If the vehicle speed cannot be obtained from either the first vehicle speed identification function unit or the second vehicle speed identification function unit, and the vehicle speed immediately before the occurrence of the two-system failure is less than a predetermined value, the fixed control is executed after a first predetermined time has elapsed from the timing start trigger, and if the vehicle speed immediately before the occurrence of the two-system failure is greater than the predetermined value, the fixed control is executed after a second predetermined time has elapsed, which is longer than the first predetermined time, from the timing start trigger, in a vehicle platform.

2. In the event of a failure in the two systems described above, the vehicle platform according to claim 1, wherein the operational of the first vehicle fixing function unit and the second vehicle fixing function unit is capable of communicating with the automatic driving kit, and when it receives an instruction for fixing control from the automatic driving kit, it executes the fixing control.

3. A high-voltage energy storage device for storing the power used to power the base vehicle, The power of the high-voltage energy storage device is stepped down and charged, and the first low-voltage energy storage device supplies power to the first vehicle speed specification function unit, the first vehicle fixing function unit, and the first vehicle control interface box. The system further comprises a second low-voltage energy storage device that is charged by power from the first low-voltage energy storage device and supplies power to the second vehicle speed identification function unit, the second vehicle locking function unit, and the second vehicle control interface box, The timing start trigger is when the one-system failure occurs and the power supply from the first low-voltage energy storage device is lost, as described in claim 1, for the vehicle platform.

4. The vehicle platform according to claim 1, wherein the first vehicle fixing function unit and the second vehicle fixing function unit perform emergency stop control when the two system failures occur.

5. A control method for a vehicle platform configured to enable autonomous driving by allowing the attachment and detachment of an autonomous driving kit that issues instructions for autonomous driving, The aforementioned vehicle platform is The base vehicle and A first vehicle speed identification function unit and a second vehicle speed identification function unit that identify the vehicle speed of the base vehicle, A first vehicle fixing function unit and a second vehicle fixing function unit perform fixing control to fix the base vehicle, A first vehicle control interface box relays control communication between the automatic driving kit and the first vehicle speed identification function unit and the first vehicle locking function unit via a first path, The system includes a second vehicle control interface box that relays control communication between the automatic driving kit and the second vehicle speed specification function unit and the second vehicle locking function unit via a second path, If a single system failure occurs in which the first vehicle control interface box and the second vehicle control interface box become unable to communicate or control on the first or second route, the first vehicle control interface box performs control of evasive driving, including deceleration, based on instructions from the automatic driving kit. If a two-system failure occurs in which communication or control becomes impossible on the first and second routes, the operational unit of the first vehicle fixing function unit and the second vehicle fixing function unit will operate. If the vehicle speed can be obtained from either the first vehicle speed determination function unit or the second vehicle speed determination function unit, the fixed control is executed when the vehicle speed becomes 0. A vehicle platform control method comprising the steps of: if the vehicle speed cannot be obtained from either the first vehicle speed identification function unit or the second vehicle speed identification function unit, if the vehicle speed immediately before the occurrence of the two-system failure is less than a predetermined value, the fixed control is executed after a first predetermined time has elapsed from the timing start trigger; and if the vehicle speed immediately before the occurrence of the two-system failure is greater than the predetermined value, the fixed control is executed after a second predetermined time has elapsed, which is longer than the first predetermined time, from the timing start trigger.

Citation Information

Patent Citations

  • Vehicle platform, vehicle control interface box, and automatic driving system

    JP2024106017A