Vehicle platform and method for controlling the vehicle platform

The vehicle platform addresses dual-path failure by switching to emergency stop and controlling output units to send signals, ensuring functionality despite path failures.

JP2026068277APending Publication Date: 2026-04-22TOYOTA JIDOSHA KK
View PDF 1 Cites 0 Cited by

Patent Information

Authority / Receiving Office
JP · JP
Patent Type
Applications
Current Assignee / Owner
TOYOTA JIDOSHA KK
Filing Date
2024-10-10
Publication Date
2026-04-22

AI Technical Summary

Technical Problem

Existing vehicle platforms face challenges in executing appropriate control when both signal exchange paths between the autonomous driving kit and the vehicle platform fail.

Method used

The vehicle platform is configured with a base vehicle, a first vehicle control interface box, and a second vehicle control interface box that relay control communication via different paths, allowing switching between autonomous and manual driving modes. In case of a dual-path failure, the platform executes an emergency stop and controls output units to send predetermined signals.

Benefits of technology

Ensures appropriate output of signals to the surrounding area even if both communication paths fail, preventing inappropriate signal setting and maintaining functionality.

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure 2026068277000001_ABST
    Figure 2026068277000001_ABST
Patent Text Reader

Abstract

Even if both routes fail, the system will appropriately output the designated signals to the surrounding area. [Solution] The VP is configured to enable automatic driving by allowing the ADK, which issues instructions for automatic driving, to be attached and detached. The VP includes a base vehicle including an output unit that outputs predetermined signals, and a main / sub VCIB that relays control communication between the ADK and the base vehicle via a first / second path. The driving mode of the main / sub VCIB can be switched between automatic and manual driving modes. When the driving mode of the main / sub VCIB is switched to automatic driving mode, if a two-system failure occurs that makes communication or control on the first / second path impossible, the base vehicle executes control to bring the base vehicle to an emergency stop, and the main / sub VCIB controls the output unit to output predetermined signals in a predetermined manner, and in response to a request from the ADK, the main / sub VCIB sets the predetermined manner (steps S122, S432, S433).
Need to check novelty before this filing date? Find Prior Art

Description

Technical Field

[0001] This disclosure relates to a vehicle platform and a method for controlling a vehicle platform, and particularly to a vehicle platform configured to be able to attach and detach an autonomous driving kit that gives an instruction for autonomous driving and to be capable of autonomous driving, and a method for controlling the vehicle platform.

Background Art

[0002] Conventionally, there has been a vehicle platform (hereinafter referred to as "VP (Vehicle Platform)") that can mount an autonomous driving kit (hereinafter referred to as "ADK (Autonomous Driving Kit)") and includes a vehicle control interface box (hereinafter referred to as "VCIB (Vehicle Control Interface Box)") that interfaces between the base vehicle and the autonomous driving system via a communication bus. (See, for example, Patent Document 1). In this VP, there are two systems of signal exchange paths between the ADK and the VP: a path via the main bus and the main VCIB, and a path via the sub bus and the sub VCIB.

Prior Art Documents

Patent Documents

[0003]

Patent Document 1

Summary of the Invention

Problems to be Solved by the Invention

[0004] In the VP of Patent Document 1, there is room for consideration in executing appropriate control when both of the two signal exchange paths between the ADK and the VP fail.

[0005] This disclosure is made to solve the aforementioned problems, and its purpose is to provide a vehicle platform and a control method for the vehicle platform that can appropriately output predetermined signals to the surrounding area even if both paths are lost. [Means for solving the problem]

[0006] The vehicle platform described in this disclosure is configured to enable autonomous driving by allowing the attachment and detachment of an autonomous driving kit that issues instructions for autonomous driving. The vehicle platform includes a base vehicle including an output unit that outputs predetermined signals, a first vehicle control interface box that relays control communication between the autonomous driving kit and the base vehicle via a first path, and a second vehicle control interface box that relays control communication between the autonomous driving kit and the base vehicle via a second path. The driving modes of the first and second vehicle control interface boxes can be switched between autonomous driving mode and manual driving mode. When the driving mode is switched to autonomous driving mode, if a two-system failure occurs that makes communication or control on the first and second paths impossible, the base vehicle executes control to bring the base vehicle to an emergency stop, and the first or second vehicle control interface box controls its output unit to output predetermined signals in a predetermined manner, and in response to a request from the autonomous driving kit, the first or second vehicle control interface box sets the predetermined manner.

[0007] With this configuration, a predetermined mode is appropriately set to output a predetermined signal in response to a request from the autonomous driving kit before a failure occurs in both systems. As a result, it is possible to provide a vehicle platform that can appropriately output the predetermined signal to the surrounding area even if both routes fail.

[0008] The predetermined mode may be the timing for outputting a predetermined signal. With such a configuration, the timing for outputting the predetermined signal in response to a request from the automated driving kit before a failure occurs in both systems is appropriately set. As a result, even if both paths fail, the predetermined signal can be output to the surrounding area at an appropriate time.

[0009] The first vehicle control interface box or the second vehicle control interface box may be configured to prohibit the setting of a predetermined configuration in response to a request from the autonomous driving kit when a fault occurs in both systems.

[0010] With this configuration, when a fault occurs in two systems, the request from the autonomous driving kit may be abnormal, but the setting of a predetermined mode in response to such a request is prohibited. As a result, it is possible to prevent the predetermined mode for outputting a predetermined signal from being set inappropriately.

[0011] The first vehicle control interface box or the second vehicle control interface box may, in the event of a failure in both systems, send a request to the autonomous driving kit to output a specific signal via an external output unit controlled by the autonomous driving kit that outputs a specific signal.

[0012] With this configuration, specific signals can be output not only through the control of the vehicle control interface box, but also through the control of the autonomous driving kit.

[0013] According to other aspects of this disclosure, a vehicle platform control method is a method for controlling a vehicle platform configured to enable autonomous driving by allowing the attachment and detachment of an autonomous driving kit that issues instructions for autonomous driving. The vehicle platform comprises a base vehicle including an output unit that outputs a predetermined signal, a first vehicle control interface box that relays control communication between the autonomous driving kit and the base vehicle via a first path, and a second vehicle control interface box that relays control communication between the autonomous driving kit and the base vehicle via a second path. The driving modes of the first and second vehicle control interface boxes are switchable between autonomous driving mode and manual driving mode. The control method includes the steps of: when the driving mode is switched to autonomous driving mode, if a two-system failure occurs that makes communication or control on the first and second paths impossible, the base vehicle executes control to bring the base vehicle to an emergency stop, and the first or second vehicle control interface box controls the output unit to output a predetermined signal in a predetermined manner; and the first or second vehicle control interface box sets a predetermined manner in response to a request from the autonomous driving kit.

[0014] This configuration provides a vehicle platform control method that can appropriately output predetermined signals to the surrounding area even if both routes fail. [Effects of the Invention]

[0015] This disclosure provides a vehicle platform and a control method for the vehicle platform that can appropriately output predetermined signals to the surrounding area even if both paths are lost. [Brief explanation of the drawing]

[0016] [Figure 1] This is a diagram showing an overview of the vehicle according to the embodiment of this disclosure. [Figure 2]This is a diagram showing the configurations of the ADK, VCIB, and VP according to this embodiment. [Figure 3] This is a flowchart showing the processes executed by the control system and the flow of the first process executed by the VCIB in this embodiment. [Figure 4] This is a flowchart showing the processes executed by the ADK and the flow of the second process executed by the VCIB in this embodiment. [Figure 5] This is a flowchart showing the process flow executed by the body system in this embodiment. **Embodiments for Carrying Out the Invention**

[0017] Hereinafter, embodiments of the present disclosure will be described in detail with reference to the drawings. The same or corresponding parts in the drawings are denoted by the same reference numerals, and their descriptions will not be repeated.

[0018] FIG. 1 is a diagram showing an overview of a vehicle 1 according to an embodiment of this disclosure. FIG. 2 is a diagram showing in detail the configurations of the ADK 10, VCIB 40, and VP 20 according to this embodiment. Referring to FIGS. 1 and 2, the vehicle 1 includes an ADK 10 and a VP 20. The ADK 10 is configured to be attachable to the VP 20 (mountable on the vehicle 1). The ADK 10 and the VP 20 are configured to be able to communicate with each other via the VCIB 40.

[0019] The VP 20 can perform autonomous driving according to a control request from the ADK 10. In FIG. 1, the ADK 10 is shown at a position separated from the VP 20, but in reality, the ADK 10 is attached to the roof top or the like of the VP 20. It is also possible to remove the ADK 10 from the VP 20. When the ADK 10 is removed, the VP 20 executes driving control (driving control according to user operations) in manual mode (manual driving mode).

[0020] ADK10 includes an autonomous driving system (ADS: Autonomous Driving System) 11 for performing autonomous driving of vehicle 1. The ADS 11 creates, for example, a driving plan for vehicle 1. The ADS 11 outputs various control requests for driving vehicle 1 according to the driving plan to the VP20 according to an API (Application Program Interface) defined for each control request. Further, the ADS 11 receives various signals indicating the vehicle state (the state of the VP20) from the VP20 according to an API defined for each signal. Then, the ADS 11 reflects the vehicle state in the driving plan.

[0021] The VP20 includes a base vehicle 30 and a VCIB 40. The base vehicle 30 executes various vehicle controls according to control requests from the ADK10 (ADS11). The base vehicle 30 includes various in-vehicle systems and various sensors for controlling the base vehicle 30. More specifically, the base vehicle 30 includes an integrated control manager 31, a brake system 32, a steering system 33, a power train system 34, an active safety system 35, a body system 36, wheel speed sensors 51, 52, a pinion angle sensor 53, a camera 54, and radar sensors 55, 56.

[0022] The integrated control manager 31 includes a processor such as a CPU (Central Processing Unit) and a memory such as a ROM (Read Only Memory) and a RAM (Random Access Memory), and integrally controls the above-described systems (brake system 32, steering system 33, power train system 34, active safety system 35, body system 36) related to the operation of vehicle 1.

[0023] The brake system 32 is configured to control a braking device provided on each wheel of the base vehicle 30. The braking device includes, for example, a disk brake system that operates according to a hydraulic pressure adjusted by an actuator.

[0024] Wheel speed sensors 51 and 52 are connected to the brake system 32. The wheel speed sensors 51 and 52 detect the rotational speed of the front and rear wheels of the base vehicle 30, respectively, and output the detected front and rear wheel rotational speeds to the brake system 32. The brake system 32 outputs the rotational speed of each wheel to the VCIB 40 as one of the pieces of information included in the vehicle state. The brake system 32 also generates a braking command for the braking device according to a predetermined control request output from the ADS 11 via the VCIB 40 and the integrated control manager 31. The brake system 32 controls the braking device using the generated braking command. The integrated control manager 31 can calculate the speed of the vehicle 1 (vehicle speed) based on the rotational speed of each wheel.

[0025] The steering system 33 is configured to control the steering angle (tire turning angle) of the steering wheels of the vehicle 1 using a steering device. The steering device includes, for example, a rack-and-pinion type electric power steering (EPS) in which the steering angle can be adjusted by an actuator.

[0026] A pinion angle sensor 53 is connected to the steering system 33. The pinion angle sensor 53 detects the rotation angle (pinion angle) of the pinion gear connected to the rotation axis of the actuator and outputs the detected pinion angle to the steering system 33. The steering system 33 outputs the pinion angle to the VCIB 40 as one of the pieces of information included in the vehicle state. The steering system 33 also generates steering commands for the steering device according to predetermined control requests output from the ADS 11 via the VCIB 40 and the integrated control manager 31. The steering system 33 controls the steering device using the generated steering commands.

[0027] The powertrain system 34 controls vehicle locking systems 341 and 342 that control an electric parking brake (EPB) provided on at least one of the wheels and a parking lock (P-Lock) device provided on the transmission of vehicle 1, and a propulsion system 343 that includes a shift device configured to allow selection of the shift range.

[0028] The active safety system 35 uses a camera 54 and radar sensors 55, 56 to detect obstacles in front of or behind the vehicle (pedestrians, bicycles, parked vehicles, utility poles, etc.). Based on the distance between the vehicle 1 and the obstacle, and the direction of movement of the vehicle 1, the active safety system 35 determines whether the vehicle 1 is likely to collide with the obstacle. If the active safety system 35 determines that a collision is likely, it outputs a braking command to the brake system 32 via the integrated control manager 31 to increase the braking force.

[0029] The body system 36 is configured to control components such as turn signals (turn lamps, hazard lamps 363), horns 365, wipers, headlights, brake lights, and instrument panel 364, for example, depending on the driving conditions or environment of the vehicle 1. The body system 36 controls each of the above components according to predetermined control requests output from the ADS 11 via the VCIB 40 and the integrated control manager 31.

[0030] The VCIB40 is configured to communicate with the ADS11 via CAN (Controller Area Network) or the like. The VCIB40 receives various control requests from the ADS11 and outputs vehicle status to the ADS11 by executing predetermined APIs defined for each signal. When the VCIB40 receives a control request from the ADK10, it outputs a control command corresponding to that control request to the system corresponding to that control command via the integrated control manager 31. The VCIB40 also acquires various information about the base vehicle 30 from various systems via the integrated control manager 31 and outputs the status of the base vehicle 30 as vehicle status to the ADS11.

[0031] Vehicle 1 can be used as part of a Mobility as a Service (MaaS) system. In addition to Vehicle 1, the MaaS system includes, for example, a data server and a Mobility Service Platform (MSPF).

[0032] MSPF is a unified platform that connects various mobility services. Autonomous driving-related mobility services are connected to MSPF. In addition to autonomous driving-related services, MSPF may also connect mobility services provided by ride-sharing companies, car-sharing companies, rental car companies, taxi companies, insurance companies, and others.

[0033] Vehicle 1 is further equipped with a Data Communication Module (DCM) capable of wireless communication with a data server. The DCM outputs vehicle information, such as speed, location, and autonomous driving status, to the data server. The DCM also receives various data from mobility services, such as the MSPF and data server, for managing the operation of autonomous vehicles, including Vehicle 1, in autonomous driving-related mobility services.

[0034] MSPF provides APIs for accessing various vehicle status and control data necessary for ADS11 development. Various mobility services can use the APIs published on MSPF to utilize the various functions provided by MSPF according to their service content. For example, autonomous driving-related mobility services can use the APIs published on MSPF to obtain driving control data for vehicle 1, information stored on the data server, etc. from MSPF. In addition, autonomous driving-related mobility services can use the above APIs to send data for managing autonomous vehicles, including vehicle 1, to MSPF.

[0035] The ADS11 includes a computer 111, an HMI (Human Machine Interface) 112, a recognition sensor 113, a posture sensor 114, a sensor cleaner 115, and an external signage 116.

[0036] Computer 111 includes a processor 101 such as a CPU and memory 102 such as ROM and RAM. Memory 102 stores programs that can be executed by the processor 101. During the automatic driving of vehicle 1, computer 111 uses various sensors (described later) to acquire the environment of vehicle 1, as well as the attitude, behavior, and position of vehicle 1, and acquires the vehicle state from VP20 via VCIB40 to set the next action of vehicle 1 (acceleration, deceleration, turning, etc.). Computer 111 outputs various commands to VCIB40 to realize the next action. Computer 111 further includes communication modules 111A and 111B. Each of communication modules 111A and 111B is configured to communicate with VCIB40.

[0037] The HMI112 presents information to the user and accepts user input during autonomous driving, manual driving requiring user intervention, and transitions between autonomous driving and manual driving requiring user intervention. The HMI112 includes, for example, an input / output device such as a touch panel display provided on the base vehicle 30.

[0038] The recognition sensor 113 is a sensor for recognizing the environment of vehicle 1. The recognition sensor 113 includes, for example, at least one of LIDAR (Laser Imaging Detection and Ranging), millimeter-wave radar, and camera. LIDAR measures the distance and direction of an object by, for example, emitting infrared pulsed laser light and detecting the reflected light from the object. Millimeter-wave radar measures the distance and direction of an object by emitting millimeter waves and detecting the reflected waves from the object. Camera is, for example, positioned behind the rearview mirror and captures an image of the area in front of vehicle 1.

[0039] The attitude sensor 114 is a sensor for detecting the attitude, behavior, and position of vehicle 1. The attitude sensor 114 includes, for example, an IMU (Inertial Measurement Unit) and a GPS (Global Positioning System). The IMU detects, for example, the acceleration of vehicle 1 in the longitudinal, lateral, and vertical directions, and the angular velocity of vehicle 1 in the roll, pitch, and yaw directions. The GPS detects the position of vehicle 1 using information received from multiple GPS satellites orbiting the Earth.

[0040] The sensor cleaner 115 is configured to remove dirt that adheres to the various sensors (camera lenses, laser beam irradiation parts, etc.) while the vehicle 1 is in motion, using a cleaning solution, wipers, etc.

[0041] The exterior signage 116 is a device controlled by the computer 111 of the ADS 11 that displays predetermined messages to drivers of other vehicles outside the base vehicle 30 and to pedestrians in the surrounding area. The exterior signage 116 is composed of, for example, an LCD (Liquid Crystal Display), an LED (Light Emitting Diode) display, or an organic EL (Electro Luminescence) display.

[0042] VCIB40 includes a main VCIB41 and a sub-VCIB42. VCIB41 and VCIB42 each include processors such as a CPU 411 and 421, and memory such as ROM and RAM 412 and 422, respectively. Memory 412 and 422 each store programs executable by processors 411 and 421 and data processed by those programs. The main VCIB41 and communication module 111A are connected to each other via communication bus 43 (main bus). The sub-VCIB42 and communication module 111B are connected to each other via communication bus 44 (sub-bus). Furthermore, the main VCIB41 and sub-VCIB42 are connected to each other in a communication manner.

[0043] Each of the VCIBs, 41 and 42, relays control requests and vehicle information between the ADS11 and the VP20. The VCIBs 41 and 42 interface between the base vehicle 30 and the ADS11 via communication buses 43 and 44. The VCIBs 41 and 42 generate control commands from control requests received from the ADS11 using APIs.

[0044] The control commands supplied from ADS11 to VCIB40 in response to control requests include, for example, a propulsion direction command requesting a shift range change, a stationary command requesting activation / deactivation of the EPB and P-Lock devices, an acceleration command requesting acceleration or deceleration of vehicle 1, a steering angle command requesting the steering wheel angle, an autonomization command requesting switching between autonomous mode and manual mode, and a stop command requesting the vehicle to be stopped or released from being stopped.

[0045] VCIB41 and 42 then output the generated control commands to the corresponding systems among the multiple systems included in VP20. Furthermore, VCIB41 and 42 use an API to generate vehicle status information from vehicle information received from each system of VP20. This vehicle status information may be identical to the vehicle information, or it may be information extracted from the vehicle information for use in processing performed by ADS11. VCIB41 and 42 then output the generated vehicle status information to ADS11.

[0046] Brake system 32 includes brake systems 321 and 322. Steering system 33 includes steering systems 331 and 332. Powertrain system 34 includes vehicle fixing system 340 and propulsion system 343. Vehicle fixing system 340 includes vehicle fixing systems 341 and 342.

[0047] VCIB41 and 42 have essentially equivalent functions, but there are some differences in how they connect to the in-vehicle systems included in VP20. Specifically, the main VCIB41 is connected to the brake system 321, steering system 331, vehicle fixing systems 341 and 342, propulsion system 343, and body system 36 via a communication bus, enabling them to communicate with each other. The sub-VCIB42 is connected to the brake system 322, steering system 332, vehicle fixing systems 341 and 342, and body system 36 via a communication bus, enabling them to communicate with each other.

[0048] Thus, by including VCIB40 with VCIB41 and VCIB42, which have equivalent functions for the operation of some systems (such as brakes and steering), the control system between ADS11 and VP20 is made redundant. Therefore, if any failure occurs in the system, the functionality of VP20 can be maintained by appropriately switching control systems or shutting off the failed control system.

[0049] Brake systems 321 and 322 each include a processor 3211 and 3221, such as a CPU, and memory 3212 and 3222, such as ROM and RAM. Each of the brake systems 321 and 322 is configured to control the braking device. Brake systems 321 and 322 each generate braking commands for the braking device in accordance with control requests output from ADS 11 via VCIB 41 and 42. Brake systems 321 and 322 may have equivalent functions. Alternatively, one of the brake systems 321 and 322 may be configured to independently control the braking force of each wheel, while the other is configured to control the generation of the same braking force on each wheel. Brake systems 321 and 322 may, for example, control the braking device using braking commands generated by one of the brake systems, and if a malfunction occurs in that brake system, control the braking device using braking commands generated by the other brake system.

[0050] The steering systems 331 and 332 each include a processor 3311 and 3321, such as a CPU, and memory 3312 and 3322, such as ROM and RAM. Each of the steering systems 331 and 332 is configured to control the steering angle of the steering wheels of the vehicle 1 using a steering device. The steering systems 331 and 332 each generate steering commands for the steering device in accordance with control requests output from the ADS 11 via VCIB 41 and 42. The steering systems 331 and 332 may have equivalent functions. Alternatively, the steering systems 331 and 332 may, for example, control the steering device using steering commands generated by one of the steering systems, and if a malfunction occurs in that steering system, control the steering device using steering commands generated by the other steering system.

[0051] The vehicle locking systems 341 and 342 each include a processor such as a CPU 3411 and 3421, and memory such as ROM and RAM 3412 and 3422, respectively. The vehicle locking systems 341 and 342 control the EPB and P-Lock devices according to control requests output from the ADS 11 via VCIB 41 and 42. The EPB is provided separately from the braking system (such as a disc brake system) and locks the wheels by the operation of an actuator. For example, the EPB locks the wheels by using an actuator to operate a drum brake for a parking brake provided on some of the wheels, or by using an actuator that can adjust the hydraulic pressure supplied to the braking system separately from the brake systems 321 and 322 to lock the wheels. The vehicle locking systems 341 and 342 have a brake hold function and are configured to allow switching between operating and releasing the brake hold.

[0052] The vehicle locking systems 341 and 342 activate the P-Lock device when, for example, a control request includes a request to set the shift range to the parking range (P range), and deactivate the P-Lock device when a control request includes a request to set the shift range to a range other than the P range. The P-Lock device engages the projection at the tip of a parking lock pawl, whose position can be adjusted by an actuator, with the teeth of a gear (lock gear) connected to a rotating element in the transmission of the vehicle 1. This fixes the rotation of the output shaft of the transmission and locks the wheels.

[0053] The propulsion system 343 includes a processor 3431 such as a CPU and memory 3432 such as ROM and RAM. The propulsion system 343 also includes a direction control system and a propulsion force system. The direction control system is connected to the VCIB 40. The direction control system controls the direction of travel (forward or reverse) of the VP20 by switching the shift range of the shift device according to control requests output from the ADS 11 via the VCIB 41. The shift range includes a P range and a neutral range (N range), as well as a forward driving range (D range) and a reverse driving range (R range). The propulsion force system is connected to the VCIB 40. The propulsion force system controls the propulsion force (e.g., acceleration and deceleration) of the VP20 by controlling the driving force from a drive source (motor generator, engine, etc.).

[0054] The active safety system 35 includes a processor 351 such as a CPU and memory 352 such as ROM and RAM. The active safety system 35 is communicatively connected to the brake system 321. As described above, the active safety system 35 uses the camera 54 and / or radar sensor 55 to detect obstacles ahead and outputs a braking command to the brake system 321 to increase the braking force when it determines that a collision is possible.

[0055] The body system 36 includes a processor 361 such as a CPU and memory 362 such as ROM and RAM. The body system 36 controls components such as turn signals (hazard lights 363), horn 365, wipers, and instrument panel 364 according to control requests output from the ADS 11 via VCIB 41, 42.

[0056] In vehicle 1, autonomous driving is performed when, for example, the user's operation on the HMI 112 selects the autonomous mode (autonomous driving mode). As mentioned above, during autonomous driving, ADS 11 first creates a driving plan. Examples of driving plans include a plan to continue driving straight, a plan to turn left / right at a predetermined intersection along a predetermined driving route, and a plan to change driving lanes. ADS 11 calculates the controllable physical quantities (acceleration, deceleration, tire steering angle, etc.) necessary for vehicle 1 to operate according to the created driving plan. ADS 11 divides the physical quantities for each API execution cycle. ADS 11 uses the API to output control requests representing the divided physical quantities to VCIB 40. Furthermore, ADS 11 obtains the vehicle state (actual direction of movement of vehicle 1, vehicle fixation state, etc.) from VP 20 and recreates the driving plan reflecting the obtained vehicle state. In this way, ADS 11 enables autonomous driving of vehicle 1.

[0057] As described above, in vehicle 1, there are two routes for exchanging signals between ADK10 and VP20: a first route via the main bus, communication bus 43 and the main VCIB41, and a second route via the sub-bus, communication bus 44 and the sub-VCIB42. It is worth considering how to implement appropriate control when both of these routes fail.

[0058] Therefore, when the driving mode is switched to automatic driving mode, if a two-system failure occurs that makes communication or control impossible on the first and second routes, VCIB41 and 42 execute control to bring the base vehicle 30 to an emergency stop and control the output units (for example, hazard lamps 363, meter panel 364, horn 365) to output predetermined signals in a predetermined manner, and set the predetermined manner in response to a request from ADK10.

[0059] This ensures that a predetermined mode is properly configured to output a predetermined signal in response to a request from ADK10 before a failure occurs in both systems. As a result, even if both paths fail, the predetermined signal can be properly output to the surrounding area.

[0060] Figure 3 is a flowchart showing the flow of processing performed by the control system and the first processing performed by VCIB41,42 in this embodiment. Referring to Figure 3, each control system process is called from higher-level processing at predetermined intervals by the processors of the control system of the base vehicle 30 (for example, processors 3211,3221 for the brake systems 321,322, processors 3411,3421 for the vehicle fixing systems 341,342, and processors 3311,3321 for the steering systems 331,332). The VCIB process is called from higher-level processing at predetermined intervals by the processors 411,421 of VCIB41,42.

[0061] The control system's processor determines whether a single-system failure has been detected that renders communication or control impossible on the first or second path (step S311). If it determines that a single-system failure has been detected (YES in step S311), the control system's processor notifies VCIB41 and 42 that a single-system failure has been detected (step S312).

[0062] The processors 411 and 421 of VCIB41 and 42 determine whether or not they have received a notification from the control system that a single-system fault has been detected (step S411). If they determine that they have received a notification from either control system that a single-system fault has been detected (YES in step S411), the processors 411 and 421 of VCIB41 and 42 switch the single-system fault flag, which indicates whether or not a single-system fault has occurred, to the ON state, which indicates that a single-system fault has occurred (step S412).

[0063] The processors 411 and 421 of VCIB41 and 42 determine whether the driving mode of VCIB41 and 42 is automatic driving mode (step S413). If it is determined that it is automatic driving mode (YES in step S413), the processors 411 and 421 of VCIB41 and 42 start controlling the vehicle to move away in accordance with the instructions of ADK10 (step S414). The vehicle to move away is to move to a safer location than the roadway, such as a parking area, parking lot, or shoulder of the road.

[0064] The control system processor determines whether a two-system fault has been detected that would render communication or control impossible on the first and second paths (step S313). If it determines that a two-system fault has been detected (YES in step S313), the control system processor notifies VCIB41 and 42 that a two-system fault has been detected (step S314) and executes control to bring the base vehicle 30 to an emergency stop (step S316). Here, the control to bring the vehicle to an emergency stop may include only deceleration control, or it may include deceleration control plus minimal steering control to move the base vehicle 30 to a safer location such as the shoulder of the road compared to the lane. If it determines that a two-system fault has not been detected (NO in step S313), or after step S316, the control system processor returns the processing to be executed to the higher-level processing that called each of these control system processes.

[0065] If it is determined that no single-system fault has been detected from any of the control systems (NO in step S411), or if it is determined that the system is not in automatic operation mode (NO in step S413), or after step S414, the processors 411 and 421 of VCIB 41 and 42 determine whether or not they have received a notification from the control system that a double-system fault has been detected (step S415). If it is determined that a notification from any of the control systems that a double-system fault has been detected (YES in step S415), the processors 411 and 421 of VCIB 41 and 42 switch the double-system fault flag, which indicates whether or not a double-system fault has occurred, to the ON state, indicating that a double-system fault has occurred (step S416). After that, the processors 411 and 421 of VCIB 41 and 42 proceed with the processing to be executed, starting with the circled number "1" in Figure 4 described later.

[0066] Figure 4 is a flowchart showing the flow of processing performed in ADK10 and second processing performed in VCIB41,42 in this embodiment. Referring to Figure 4, ADK processing is called and executed by the computer 111 of ADS11 of ADK10 at predetermined intervals from higher-level processing. VCIB processing is executed by processors 411,421 of VCIB41,42 at predetermined intervals following the first processing shown in Figure 3.

[0067] In ADK10, the computer 111 of ADS11 determines whether the conditions for sounding the horn 365 have been met in the running autonomous driving program (step S111). If it is determined that the conditions for sounding the horn 365 have been met (YES in step S111), the computer 111 sends an instruction to VCIB41,42 to sound the horn 365 (step S112).

[0068] In VCIB41 and 42, processors 411 and 421 determine whether or not they have received an instruction from ADK10 to sound the horn 365 (step S421). If they determine that they have received an instruction (YES in step S421), processors 411 and 421 of VCIB41 and 42 send an instruction to the body system 36 to sound the horn 365 (step S422).

[0069] Figure 5 is a flowchart showing the processing flow performed by the body system 36 in this embodiment. Referring to Figure 5, the body system processing is called and executed by the processor 361 of the body system 36 at predetermined intervals from higher-level processing. The processor 361 of the body system 36 determines whether or not it has received an instruction from VCIB 41,42 to sound the horn 365 (step S321). If it determines that it has received an instruction to sound the horn 365 (YES in step S321), the processor 361 of the body system 36 controls the horn 365 to sound the horn according to the instruction (step S322).

[0070] Returning to Figure 4, if ADK10 determines that the condition for sounding the horn 365 is not met (NO in step S111), or after step S112, the computer 111 of ADS11 determines whether the condition for flashing the hazard lights 363 in the running automated driving program has been met (step S113). If it determines that the condition for flashing the hazard lights 363 has been met (YES in step S113), the computer 111 sends an instruction to flash the hazard lights 363 to VCIB41,42 (step S114).

[0071] If VCIB41,42 determines that it has not received an instruction to sound the horn (NO in step S421), or after step S422, the processors 411,421 of VCIB41,42 determine whether or not it has received an instruction from ADK10 to flash the hazard lights 363 (step S423). If it determines that an instruction has been received (YES in step S423), the processors 411,421 of VCIB41,42 transmit an instruction to the body system 36 to flash the hazard lights 363 (step S424).

[0072] Moving on to Figure 5, if the body system 36 determines that it has not received an instruction to sound the horn 365 (NO in step S321), or after step S322, the processor 361 of the body system 36 determines whether it has received an instruction from VCIB 41,42 to flash the hazard lights 363 (step S323). If it determines that it has received an instruction to flash the hazard lights 363 (YES in step S323), the processor 361 of the body system 36 controls the hazard lights 363 to flash according to the instruction (step S324).

[0073] Returning to Figure 4, if ADK10 determines that the condition for flashing the hazard lights 363 is not met (NO in step S113), or if, after step S114, the computer 111 of ADS11 determines whether the condition for changing the notification mode setting by the output unit (e.g., hazard lights 363, horn 365) has been met (step S121). The condition for changing the notification mode setting may be, for example, that the base vehicle 30 has crossed a boundary line of a different region (e.g., a national border, a prefectural border, a boundary line of a regulated area, etc.) where the notification regulations by the output unit differ, or that a predetermined period of time has elapsed since the last setting change.

[0074] If ADK10 determines that the conditions for changing the notification method settings have been met (YES in step S121), the computer 111 of ADS11 sends the notification method settings (for example, notification timing settings) according to the regulations of the region to VCIB41,42 (step S122).

[0075] If VCIB41,42 determines that it has not received an instruction to flash the hazard lamp 363 (NO in step S423), or after step S424, the processors 411,421 of VCIB41,42 determine whether the two-system fault flag is in the ON state (step S431). If it determines that the two-system fault flag is not in the ON state (NO in step S431), the processors 411,421 of VCIB41,42 determine whether it has received a setting for the notification mode of the output unit (step S432). If it determines that a setting has been received (YES in step S432), the processors 411,421 of VCIB41,42 store the received setting for the notification mode of the output unit in memory 412,422 (step 433).

[0076] If it is determined that the two fault flags are in the ON state (YES in step S431), the processors 411 and 421 of VCIB 41 and 42 notify ADK 10 to perform an emergency stop (step S434). The processors 411 and 421 of VCIB 41 and 42 also instruct the body system 36 to broadcast an emergency stop message in the notification mode set in memory 412 and 422 (step S435). If it is determined that the notification mode setting has not been received (NO in step S432), after step S434 or after step S435, the processors 411 and 421 of VCIB 41 and 42 return the processing to be performed to the higher-level processing that called this VCIB process.

[0077] If ADK10 determines that the conditions for changing the notification mode settings are not met (NO in step S121), or after step S122, the computer 111 of ADS11 determines whether or not it has received an emergency stop notification from VCIB41,42 (step S123). If it determines that an emergency stop notification has been received (YES in step S123), the computer 111 of ADS11 controls the external signage 116 to display a message indicating that the vehicle is stopped in emergency mode (step S124). If it determines that an emergency stop notification has not been received (NO in step S123), or after step S124, the computer 111 of ADS11 returns the processing to be executed to the higher-level processing that called this ADK process.

[0078] Proceeding to Figure 5, if the body system 36 determines that it has not received an instruction to flash the hazard lamps 363 (NO in step S323), or after step S324, the processor 361 of the body system 36 determines whether or not it has received an instruction to broadcast an emergency stop message (step S331). If it determines that it has received an instruction (YES in step S331), the processor 361 of the body system 36 turns on the emergency stop notification flag (step S332). The emergency stop notification flag indicates whether or not an emergency stop message is being broadcast; when it is on, it indicates that the message is being broadcast, while when it is off, it indicates that the message is not being broadcast. The processor 361 of the body system 36 also controls the meter panel 364 to display the emergency stop message (step S333).

[0079] If it is determined that it has not received an instruction to notify an emergency stop message (NO in step S331), or after step S333, the processor 361 of the body system 36 determines whether the emergency stop notification flag is in the ON state (step S341). If it is determined that the emergency stop notification flag is in the ON state (YES in step S341), the processor 361 of the body system 36 determines whether the base vehicle 30 is moving or stationary (step S342).

[0080] If the body system 36 determines in step S342 that the base vehicle 30 is in motion, the body system 36's processor 361 determines whether the notification type (notification timing) instruction included in the instruction to notify an emergency stop message includes "in motion" (step S343). If it determines that "in motion" is included (YES in step S343), the body system 36's processor 361 controls the horn 365 to sound the horn in accordance with the instructed notification type (step S344). The body system 36's processor 361 also controls the hazard lights 363 to flash in accordance with the instructed notification type (step S345).

[0081] If the body system 36 determines in step S342 that the base vehicle 30 is stopped, the processor 361 of the body system 36 determines whether the notification type (notification timing) instruction included in the instruction to notify the emergency stop message includes "stopped" (step S346). If it determines that "stopped" is included (YES in step S346), the processor 361 of the body system 36 controls the horn 365 to sound the horn in accordance with the instructed notification type (step S347). The processor 361 of the body system 36 also controls the hazard lights 363 to flash in accordance with the instructed notification type (step S348).

[0082] If the emergency stop notification flag is not turned on (NO in step S341), if the base vehicle 30 is in motion and the notification type (notification timing) instruction does not include "in motion" (NO in step S343), if, after step S345, the base vehicle 30 is stopped and the notification type (notification timing) instruction does not include "stopped" (NO in step S346), or after step S348, the processor 361 of the body system 36 returns the processing to be executed to the higher-level processing that called this body system processing.

[0083] [Differentiation] (1) In the embodiment described above, as shown in steps S122, S432, S433, and S435 in Figure 4, and steps S331 to S333 and S341 to S348 in Figure 5, the notification of an emergency stop message is indirectly caused by instructions being issued to the body system 36 by VCIB 41 and 42, so that a predetermined signal (for example, a signal by sounding the horn 365, a signal by flashing the hazard lamps 363, or a signal by displaying a message on the meter panel 364) is output in a notification manner set in response to a request from ADK 10. However, the embodiment is not limited to this, and the notification of an emergency stop message may also be directly caused by VCIB 41 and 42 so that a predetermined signal is output in a notification manner set in response to a request from ADK 10.

[0084] (2) In the embodiments described above, functional units that perform specific functions used for autonomous and manual driving, such as the brake systems 321, 322, the vehicle fixing systems 341, 342, the steering systems 331, 332, or the body system 36, are provided with processors and memories. These functional units work in cooperation with VCIBs 41, 42 to perform specific functions of the base vehicle 30. However, the division of functions between VCIBs 41, 42 and the processors and memories of each functional unit may be any. For example, VCIBs 41, 42 may perform some of the functions that the processors and memories of each functional unit perform.

[0085] (3) In the embodiment described above, as shown in steps S341 to S348 of Figure 5, the notification method for the emergency stop message, which is set in response to a request from ADK10, is the notification timing. However, it is not limited to this, and the notification method for the emergency stop message may be other, for example, the size or method of displaying the notification, or the volume or tone of the notification sound.

[0086] (4) In the embodiment described above, the external signage 116 is provided on the ADK 10 side. However, it is not limited to this, and the external signage 116 may be provided on the base vehicle 30 side, for example, and may be connected to the body system 36. The external signage 116 on the base vehicle 30 side may be controlled in the same way as the hazard lamps 363 and horns 365 described above.

[0087] (5) The embodiments described above can be interpreted as disclosures of devices such as Vehicle 1, ADK10, ADS11, VP20, Base Vehicle 30, or VCIB41,42, or as disclosures of control methods or control programs for these devices.

[0088] [summary] (1) As shown in Figures 1 and 2, the VP20 is configured to enable automatic driving by detaching the ADK10 which issues instructions for automatic driving. As shown in Figures 1 and 2, the VP20 includes a base vehicle 30 which includes an output unit that outputs predetermined signals (for example, hazard lamps 363, horn 365, meter panel 364), a VCIB41 which relays control communication between the ADK10 and the base vehicle 30 via a first path, and a VCIB42 which relays control communication between the ADK10 and the base vehicle 30 via a second path. As shown in Figures 1 and 2, the driving mode of VCIB41 and 42 can be switched between automatic driving mode and manual driving mode.

[0089] As shown in Figures 3 to 5, when the driving mode is switched to automatic driving mode, if a two-system failure occurs that makes communication or control impossible on the first and second routes, the processors of each control system of the base vehicle 30 execute control to bring the base vehicle 30 to an emergency stop (for example, step S316), and the VCIBs 41 and 42 control their output units to output predetermined signals in predetermined manner (for example, steps S331 to S333, steps S341 to S348), and in response to a request from the ADK 10, the VCIBs 41 and 42 set predetermined manners (for example, steps S122, S432, and S433).

[0090] This ensures that a predetermined mode is properly set for outputting a predetermined signal in response to a request from ADK10 before a failure occurs in both systems. As a result, even if both routes fail, the predetermined signal can be properly output to the surrounding area. Furthermore, the mode of notification to inform people outside the vehicle that an emergency stop is being performed can be easily changed according to the laws and regulations of the area in which the base vehicle 30 is traveling.

[0091] (2) As shown in steps S341 to S348 of Figure 5, the predetermined mode may be the timing at which a predetermined signal is output.

[0092] This ensures that the timing for outputting a predetermined signal in response to a request from ADK10 before a failure occurs in both systems is appropriately set. As a result, even if both paths fail, the predetermined signal can be output to the surrounding area at the appropriate time.

[0093] (3) As shown in steps S431 to S433 of Figure 4, VCIB41 and 42 may be configured to prohibit the setting of a predetermined mode in response to a request from ADK10 when a two-system failure occurs (if it is determined in step S431 that the two-system failure flag is in the ON state, the processes in steps S432 and S433 will not be executed).

[0094] As a result, when two system failures occur, requests from ADK10 may be abnormal, but the setting of a predetermined mode in response to such requests is prohibited. Consequently, it is possible to prevent the predetermined mode for outputting a predetermined signal from being set inappropriately. This improves the reliability of the system.

[0095] (4) As shown in steps S431 and S434 of Figure 4, if a fault occurs in both systems, the VCIBs 41 and 42 may be configured to send a request to the ADK 10 to output a specific signal (for example, an external signage 116 that is controlled by the ADK 10 and outputs a specific signal, for example, a signal by displaying a message indicating that the vehicle is in emergency stop).

[0096] This allows for the output of specific signals not only through the control of VCIB41 and VCIB42, but also through the control of ADK10.

[0097] The embodiments disclosed herein should be considered in all respects to be illustrative and not restrictive. The scope of this disclosure is indicated by the claims rather than by the description of the embodiments above, and all modifications within the meaning and scope equivalent to the claims are intended to be included. [Explanation of Symbols]

[0098] 1 Vehicle, 10 ADK, 11 ADS, 20 VP, 30 Base Vehicle, 31 Integrated Control Manager, 32, 321, 322 Brake System, 33, 331, 332 Steering System, 34 Powertrain System, 35 Active Safety System, 36 Body System, 40, 41, 42 VCIB, 43, 44 Communication Bus, 51, 52 Wheel Speed ​​Sensor, 53 Pinion Angle Sensor, 54 Camera, 55, 56 Radar Sensor, 101, 351, 361, 411, 421, 3211, 3221, 3311, 3321, 3411, 3421, 3431 Processor, 102, 352, 362, 412, 422, 3212, 3222, 3312, 3322, 3412, 3422, 3432 Memory, 111 Computer, 111A, 111B Communication module, 112 HMI, 113 Recognition sensor, 114 Attitude sensor, 115 Sensor cleaner, 116 Exterior signage, 340 Vehicle fixing system, 343 Propulsion system, 363 Hazard lights, 364 Instrument panel, 365 Horn.

Claims

1. A vehicle platform configured to enable autonomous driving by allowing the attachment and detachment of an autonomous driving kit that issues instructions for autonomous driving, A base vehicle including an output unit that outputs a predetermined signal, A first vehicle control interface box relays control communication between the autonomous driving kit and the base vehicle via a first path, The system includes a second vehicle control interface box that relays control communication between the autonomous driving kit and the base vehicle via a second path, The driving modes of the first vehicle control interface box and the second vehicle control interface box can be switched between automatic driving mode and manual driving mode. When the driving mode is switched to the automatic driving mode, if a two-system failure occurs that makes communication or control impossible on the first and second routes, the base vehicle will execute control to bring the base vehicle to an emergency stop, and the first vehicle control interface box or the second vehicle control interface box will control the output unit to output the predetermined signal in a predetermined manner. In response to a request from the autonomous driving kit, the first vehicle control interface box or the second vehicle control interface box sets the predetermined configuration of the vehicle platform.

2. The vehicle platform according to claim 1, wherein the predetermined mode is the timing for outputting the predetermined signal.

3. The vehicle platform according to claim 1, wherein the first vehicle control interface box or the second vehicle control interface box prohibits the setting of the predetermined configuration in response to a request from the autonomous driving kit when the two system failures occur.

4. The vehicle platform according to claim 1, wherein the first vehicle control interface box or the second vehicle control interface box, in the event of a failure of the two systems, sends a request to the automatic driving kit to output a specific signal via an external output unit controlled by the automatic driving kit that outputs a specific signal.

5. A control method for a vehicle platform configured to enable autonomous driving by allowing the attachment and detachment of an autonomous driving kit that issues instructions for autonomous driving, The aforementioned vehicle platform is A base vehicle including an output unit that outputs a predetermined signal, A first vehicle control interface box relays control communication between the autonomous driving kit and the base vehicle via a first path, The system includes a second vehicle control interface box that relays control communication between the autonomous driving kit and the base vehicle via a second path, The driving modes of the first vehicle control interface box and the second vehicle control interface box can be switched between automatic driving mode and manual driving mode. The control method described above is When the driving mode is switched to the automatic driving mode, if a two-system failure occurs that makes communication or control impossible on the first and second routes, the base vehicle executes control to bring the base vehicle to an emergency stop, and controls the output unit so that the first vehicle control interface box or the second vehicle control interface box outputs the predetermined signal in a predetermined manner, A method for controlling a vehicle platform, comprising the step of setting the first vehicle control interface box or the second vehicle control interface box to the predetermined configuration in response to a request from the autonomous driving kit.

Citation Information

Patent Citations

  • Vehicle platform, vehicle control interface box, and automatic driving system

    JP2024106017A