Automobiles and automotive programs
The system safely and conveniently updates driving assistance programs by determining vehicle stoppage and predicting its duration, ensuring updates only occur when the vehicle is stationary for a sufficient time, thus preventing interruptions during driving.
Patent Information
- Authority / Receiving Office
- JP · JP
- Patent Type
- Applications
- Current Assignee / Owner
- MICO LATTA
- Filing Date
- 2026-04-24
- Publication Date
- 2026-07-29
AI Technical Summary
Existing methods for updating driving assistance programs in vehicles require the vehicle to be stopped, which is inconvenient and unsafe when the update request is received during motion.
A system that determines if the vehicle is stopped and predicts the duration of the stop, allowing program updates only if the stop is longer than a predetermined time and the update time is within the downtime, ensuring safety by preventing updates during unsafe conditions.
Ensures timely and safe program updates by only initiating updates when the vehicle is stopped for an adequate duration, avoiding interruptions during driving.
Smart Images

Figure 2026123152000001_ABST
Abstract
Description
Technical Field
[0001] This invention relates to automobiles and automobile programs.
Background Art
[0002] In recent years, automobiles have been equipped with driving assistance functions such as automatic collision prevention assist systems, cruise control systems, and lane keep assist systems, making them safer and reducing the burden on drivers. Furthermore, the development of self-driving cars capable of fully autonomous driving, where the driver does not need to perform any manual driving operations, is also progressing. (See Non-Patent Document 1). Such driving assistance functions of automobiles are executed using software programs (hereinafter simply referred to as programs).
[0003] By the way, programs are usually updated as appropriate to correct their defects or add new functions. In this case, since it is inconvenient to always bring the automobile to the dealer for program updates, generally, a method of providing an update program to the automobile through the Internet from a program update server is used.
[0004] However, the update of the driving assistance program for automobiles cannot be done at any time. Since driving while updating the driving assistance program is dangerous, it must be avoided during driving. In view of this, for example, Patent Document 1 (Japanese Patent Application Laid-Open No. 2007-230317) discloses that when there is a request to rewrite the driving assistance program, after controlling the vehicle to a stopped state, the rewriting of the driving assistance program is executed.
Prior Art Documents
Patent Documents
[0005]
Patent Document 1
Non-Patent Documents
[0006] [Non-Patent Document 1] Newsweek Japan, October 18, 2016 issue, pp. 21-30 [Overview of the Initiative] [Problems that the invention aims to solve]
[0007] However, when using the technology described in Patent Document 1, if a program update request is received while the vehicle is in motion, the vehicle will be stopped each time, which is extremely inconvenient for the driver and passengers.
[0008] In view of these problems, this invention aims to provide an automobile that can perform updates to its driving assistance program in a safe and appropriate manner. [Means for solving the problem]
[0009] To solve the above problems, this invention provides: A means for determining whether the vehicle is stopped or not, When the vehicle's stopped state determination means determines that the vehicle is stopped, the vehicle's stopping state determination means predicts the duration of the stop, A first time determination means for determining whether the predicted duration of the stoppage, as predicted by the stoppage duration prediction means, is equal to or greater than a predetermined time, If the first time determination means determines that the duration of the stoppage is equal to or greater than the predetermined time, the inquiry means makes a request to the program update server for a program update, A second time determination means for determining whether the update time of the update program obtained from the program update server based on the inquiry by the inquiry means is within the downtime, The second time determination means controls the program update using the update program if the update time of the update program is within the suspension duration, and the program update is not performed if the update time of the update program is not within the suspension duration. The present invention provides an automobile characterized by having the following features.
[0010] In the vehicle with the above configuration, it is determined whether the vehicle is stopped or not, and if it is determined that the vehicle is stopped, the duration of the stop is predicted. It is then determined whether the predicted duration of the stop is longer than a predetermined time, and if it is determined that the duration of the stop is longer than the predetermined time, a request for a program update is sent to the program update server.
[0011] Based on this inquiry, the system determines whether the update time of the update program to be retrieved from the program update server is within the downtime. If the update time is within the downtime, the program update using the update program is executed. If the update time is not within the downtime, the system controls the system to prevent the program update from being executed. [Effects of the Invention]
[0012] According to this invention, when the vehicle is stopped and the duration of the stop exceeds a predetermined time, a query for a program update is sent to the program update server. Therefore, if the duration of the stop is short, no query for a program update is sent to the program update server. Then, if the update time of the update program obtained from the program update server based on the query is within the duration of the stop, the program is updated. Thus, it is ensured that the program is updated within the duration of the stop, and the effect is achieved that the program can be updated in a timely manner while guaranteeing safety. [Brief explanation of the drawing]
[0013] [Figure 1]It is a block diagram showing a configuration example of an electronic control circuit unit of a first embodiment of an automobile according to the present invention. [Figure 2] It is a diagram for explaining an example of behavior after getting off the vehicle in a first embodiment of an automobile according to the present invention. [Figure 3] It is a diagram showing a flowchart illustrating an example of the flow of the operation at the time of getting off the vehicle in a first embodiment of an automobile according to the present invention. [Figure 4] It is a diagram for explaining a program update method in a first embodiment of an automobile according to the present invention. [Figure 5] It is a diagram showing a part of a flowchart illustrating an example of the flow of a program update operation in a first embodiment of an automobile according to the present invention. [Figure 6] It is a diagram showing a part of a flowchart illustrating an example of the flow of a program update operation in a first embodiment of an automobile according to the present invention. [Figure 7] It is a diagram showing a part of a flowchart illustrating an example of the flow of a program update operation in a first embodiment of an automobile according to the present invention. [Figure 8] It is a diagram showing a part of a flowchart illustrating an example of the flow of a program update operation in a first embodiment of an automobile according to the present invention. [Figure 9] It is a diagram showing a part of a flowchart illustrating an example of the flow of a program update operation in a first embodiment of an automobile according to the present invention. [Figure 10] It is a diagram showing a part of a flowchart illustrating an example of the flow of a program update operation in a first embodiment of an automobile according to the present invention. [Figure 11] It is a diagram for explaining an example of behavior after getting off the vehicle in a first embodiment of an automobile according to the present invention. [Figure 12] It is a diagram for explaining an example of behavior after getting off the vehicle in a first embodiment of an automobile according to the present invention. [Figure 13] It is a diagram for explaining an example of behavior after getting off the vehicle in a first embodiment of an automobile according to the present invention. [Figure 14]It is a block diagram showing a configuration example of an electronic control circuit unit of a second embodiment of an automobile according to the present invention. [Figure 15] It is a diagram for explaining an example of a usage history in a second embodiment of an automobile according to the present invention. [Figure 16] It is a diagram showing a part of a flowchart illustrating an example of the flow of a program update operation in a second embodiment of an automobile according to the present invention. [Figure 17] It is a diagram showing a part of a flowchart illustrating an example of the flow of a program update operation in a second embodiment of an automobile according to the present invention. [Figure 18] It is a diagram showing a part of a flowchart illustrating an example of the flow of a program update operation in a second embodiment of an automobile according to the present invention. [Figure 19] It is a diagram showing a part of a flowchart illustrating an example of the flow of a program update operation in a second embodiment of an automobile according to the present invention. [Figure 20] It is a diagram showing a part of a flowchart illustrating an example of the flow of a program update operation in a second embodiment of an automobile according to the present invention. [Figure 21] It is a diagram showing a part of a flowchart illustrating an example of the flow of a program update operation in a second embodiment of an automobile according to the present invention. [Figure 22] It is a diagram showing a part of a flowchart illustrating an example of the flow of a program update operation in a second embodiment of an automobile according to the present invention. [Figure 23] It is a diagram showing a part of a flowchart illustrating an example of the flow of a program update operation in a second embodiment of an automobile according to the present invention. [Figure 24] It is a diagram showing a part of a flowchart illustrating an example of the flow of a program update operation in a second embodiment of an automobile according to the present invention. [Figure 25] It is a diagram showing a part of a flowchart illustrating an example of the flow of a program update operation in a second embodiment of an automobile according to the present invention. [Figure 26]This figure shows a portion of a flowchart illustrating an example of the program update operation flow in a second embodiment of the automobile according to this invention. [Figure 27] This figure shows a portion of a flowchart illustrating an example of the program update operation flow in a second embodiment of the automobile according to this invention. [Figure 28] This figure illustrates an example of setting the intended use in a second embodiment of the automobile according to this invention. [Figure 29] This figure illustrates an example of setting the intended use in a second embodiment of the automobile according to this invention. [Modes for carrying out the invention]
[0014] Hereinafter, embodiments of the automobile according to this invention will be described with reference to the figures. The embodiments of the automobile described below are those of an autonomous vehicle equipped with a manual driving mode in which the vehicle is driven in response to manual driving operations by the driver, and an autonomous driving mode in which the vehicle is driven autonomously without driver operation.
[0015] It goes without saying that this invention can also be applied to automobiles that do not have an autonomous driving mode but are equipped with an automatic collision avoidance assist system, cruise control system, lane keeping assist system, etc. The automatic collision avoidance assist system, cruise control system, and lane keeping assist system operate using driving assistance programs specific to each system.
[0016] The automatic collision prevention assist system is equipped with the function of preventing collision with an obstacle and stopping the vehicle immediately in front of the obstacle. Although it is called by various names by automobile manufacturers, such as automatic braking system, this specification will use the name automatic collision prevention system.
[0017] Furthermore, a cruise control system has the function of maintaining a constant distance between one's own vehicle and the vehicle traveling directly in front of it. Although the name of this system varies among automobile manufacturers, such as auto cruise system and automatic tracking system, this specification will use the term "cruise control system."
[0018] Furthermore, the lane keeping assist system has the function of detecting the white lines on both sides of the driving lane and maintaining driving within those white lines. This is also called a lane tracing assist system, and the name varies depending on the automobile company, but in this specification, the name lane keeping assist system will be used.
[0019] Of course, this invention can also be implemented in automobiles that are equipped only with an autonomous driving mode that does not allow manual driving operations by the driver (fully autonomous vehicles).
[0020] [First Embodiment] Figure 1 is a block diagram showing an example of the hardware configuration of the electronic control circuit unit 10 of the autonomous vehicle 1 according to the first embodiment. In this embodiment, the autonomous vehicle 1 is an example of an electric vehicle and is equipped with a battery 11 as a power source.
[0021] Furthermore, the autonomous vehicle 1 of this embodiment is equipped with a manual driving mode and, in this embodiment, an autonomous driving mode in which autonomous driving is performed. The manual driving mode is a mode in which the vehicle can be driven in accordance with the driver's operation of the accelerator pedal, brake pedal, shift lever, and steering wheel (handlebar operation), just like a normal automobile that is not an autonomous vehicle.
[0022] Furthermore, the autonomous driving mode is a mode in which the autonomous vehicle 1 automatically (autonomously) avoids obstacles and drives autonomously without the driver having to operate the accelerator pedal, brake pedal, shift lever, or steering wheel. It can be automatically switched to manual driving mode by a predetermined action by the driver. Here, the predetermined action by the driver includes predetermined operations such as the driver's driving operations, the driver's operation input via the touch panel described later, and the driver's voice input. In addition, the functions of this autonomous driving mode also include functions such as the automatic collision avoidance assist system, cruise control system, and lane keeping assist system.
[0023] For example, the driver of the autonomous vehicle 1 can switch the autonomous vehicle 1, which is currently driving in manual driving mode, to autonomous driving mode by performing a predetermined operation via the touch panel 112 described later. Furthermore, if the driver performs an operation such as operating the accelerator pedal, brake pedal, shift lever, or steering wheel while driving in autonomous driving mode, the system is configured to automatically return to manual driving mode.
[0024] As shown in Figure 1, the electronic control circuit unit 10 is connected to the control unit 101, which is equipped with a computer, via the system bus 100 to the motor drive control unit 102, steering drive control unit 103, manual / automatic driving mode switching control unit 104, brake drive control unit 105, radar group 106, camera group 107, sensor group 108, surrounding moving object detection unit 109, current position detection unit 110, display unit 111, touch panel 112, car navigation (hereinafter abbreviated as car navigation) function unit 113, user authentication unit 114, caller authentication unit 115, post-exit behavior setting reception unit 116, behavior control management unit 117, program update management control unit 118, non-driving function unit 119, voice input / output unit 120, clock unit 121, battery level detection unit 122, and wireless communication unit 123.
[0025] The motor drive control unit 102 is connected to the motor drive unit 131. The steering drive control unit 103 is connected to the steering drive unit 132. The manual operation detection unit 133 is connected to the manual / automatic driving mode switching control unit 104, and the brake drive control unit 105 is connected to the brake drive unit 134. The car navigation function unit 113 is connected to the car navigation database 135. The audio input / output unit 120 is connected to the speaker 136 and the microphone 137.
[0026] The motor drive control unit 102, under the control of the control unit 101, controls the supply of drive signals to the motor drive unit 131 of the autonomous vehicle 1, which is composed of an electric vehicle in this embodiment, in order to control the start of driving of the autonomous vehicle 1, driving speed control (including brake control and accelerator control), stopping of driving, etc.
[0027] The steering drive control unit 103 controls the supply of drive control signals to the steering drive unit 132 of the autonomous vehicle 1 in this embodiment, under the control of the control unit 101, thereby controlling the changing of the autonomous vehicle 1's course.
[0028] The manual / automatic driving mode switching control unit 104 controls the driving mode of the autonomous vehicle 1 to either manual driving mode or automatic driving mode in response to a driving mode selection operation input via the touch panel 112.
[0029] Furthermore, the input that triggers the manual / automatic driving mode switching control unit 104 to switch the driving mode of the automatic driving vehicle 1 between manual driving mode and automatic driving mode is not limited to selection operation input via the touch panel 112, but may also be voice input of a switching instruction via the microphone 137. In the case of voice input, the voice input of the switching instruction via the microphone 137 is recognized by the voice recognition unit 115, and the recognition result is supplied to the manual / automatic driving mode switching control unit 104. The manual / automatic driving mode switching control unit 104 switches the driving mode based on the received voice recognition result.
[0030] The manual operation detection unit 133 receives operation information from the driver regarding accelerator pedal operation, brake pedal operation, shift lever operation, and steering operation, and supplies this manual driving operation information to the manual / automatic driving mode switching control unit 104. In automatic driving mode, if the manual operation detection unit 124 detects a manual driving operation by the driver, the manual / automatic driving mode switching control unit 104 performs control to switch to manual driving mode.
[0031] When the autonomous vehicle 1 is in manual driving mode, the manual / automatic driving mode switching control unit 104 supplies manual driving operation information from the manual driving operation detection unit 105 to the motor drive control unit 102 and the steering drive control unit 103, and controls the motor drive unit 131 and the steering drive unit 132 in accordance with the driver's pedal operation, shift lever operation, and steering operation (handlebar operation).
[0032] Furthermore, when the autonomous vehicle 1 is in autonomous driving mode, the manual / autonomous driving mode switching control unit 104 supplies the motor drive control unit 102 and the steering drive control unit 103 with autonomous driving operation information generated by the control unit 101 based on the outputs of the radar group 106, camera group 107, sensor group 108, and surrounding moving object detection unit 109, as will be described later. This controls the motor drive unit 131 and the steering drive unit 132 to drive according to the autonomous driving operation information, enabling autonomous driving. In autonomous driving mode, the car navigation function unit 113 searches for a route from the current location to a destination set by the driver or the like, and controls the vehicle to drive along the searched route.
[0033] Then, in automatic driving mode, when the driver performs a predetermined operation such as operating the accelerator pedal, brake pedal, shift lever, or steering wheel, the manual / automatic driving mode switching control unit 104 performs mode switching control to automatically return the driving mode of the automatic driving vehicle 1 to manual driving mode based on the manual driving operation detection information from the manual driving operation detection unit 105.
[0034] In the case of a fully autonomous vehicle, there is only an autonomous driving mode, so there is no need to switch between manual driving mode and autonomous driving mode, and therefore neither the manual / autonomous driving mode switching control unit 104 nor the manual operation detection unit 133 exists.
[0035] The brake drive control unit 105 controls the supply of drive control signals to the brake drive unit 134 of the autonomous vehicle 1 in this embodiment, under the control of the control unit 101, to control the autonomous vehicle 1 by reducing its speed or bringing it to a stop.
[0036] The radar array 106 is used to measure the distance to people and objects around the autonomous vehicle 1, and consists of one or more laser radars (formally known as LIDAR (Light Detection and Ranging or Laser Imaging Detection and Ranging)) and millimeter-wave radars. Laser radars are embedded, for example, in the roof or near the bumper, while millimeter-wave radars are installed, for example, at the front and rear of the vehicle. Both laser radars and millimeter-wave radars may be provided, or only one of them may be provided. Other radars, such as microwave radars, may also be used. Furthermore, sonar (not shown) can be used for the same purpose as radars.
[0037] The camera group 107 includes one or more cameras for capturing images of the interior of the autonomous vehicle 1, and one or more cameras for capturing images of the surrounding area outside the autonomous vehicle 1, such as the front, sides, and rear. The cameras for capturing images of the interior include, for example, cameras mounted on the rearview mirror (rearview mirror, room mirror) installed between the driver's seat and the passenger seat, or on the top of the front windshield, to capture the actions of the person (driver) sitting in the driver's seat, as well as cameras for capturing the actions of passengers (co-passengers) sitting in the passenger seat or rear seats. The cameras for capturing images of the surrounding area of the autonomous vehicle 1 include, for example, two cameras (stereo cameras) mounted on the left and right sides of the rearview mirror to mainly capture the left front and right front of the autonomous vehicle 1, as well as cameras mounted on, for example, the door mirrors or fender mirrors of the autonomous vehicle 1 to capture the left and right sides, and a camera to capture the rear of the autonomous vehicle 1.
[0038] The sensor group 108 includes open / close detection sensors for detecting the opening and closing of doors and windows, sensors for detecting seat belt fastening, seat occupancy sensors (e.g., weight sensors) for detecting when an occupant is seated in a seat such as the driver's seat or passenger seat, touch sensors (e.g., capacitive sensors) for detecting when a person touches the steering wheel in the driver's seat, as well as motion sensors (e.g., infrared sensors) for detecting people in the vicinity outside the vehicle, and various sensors for acquiring information that assists in autonomous driving. Examples of sensors for acquiring information that assists in autonomous driving include vibration sensors for detecting vibrations of the vehicle and tires, rotation speed sensors for detecting the rotation speed of the tires, geomagnetic sensors for detecting direction, acceleration sensors for detecting acceleration, and gyro sensors (gyroscopes) for detecting angle and angular velocity. In this embodiment, the sensor group 108 also includes sensors for detecting the illumination of the right turn signal, left turn signal (direction indicator), and hazard lights (emergency flashing lights).
[0039] The surrounding moving object detection unit 109 uses the radar group 106, the sensor group 108, and the images captured by the camera group 107 to detect moving objects (including people) around the vehicle. The surrounding moving object detection unit 109 also detects surrounding obstacles and moving objects by performing processing based on machine learning, such as Bayesian theory or deep learning.
[0040] The current position detection unit 110 detects the vehicle's current position by receiving radio waves from GPS satellites. Because the accuracy of the position detected by radio waves from GPS satellites is poor, the current position detection unit 110 uses not only the current position information detected by receiving radio waves from GPS satellites, but also one or more sensors included in the sensor group 108, as well as images captured by the radar group 106 and camera group 107 (in combination with the navigation function), and performs processing based on machine learning, such as Bayesian theory or deep learning, to detect and confirm the current position with higher accuracy.
[0041] In autonomous driving mode, the autonomous vehicle 1 processes various information, such as position information obtained from the radar group 106, camera group 107, sensor group 108, and radio waves from GPS satellites, using machine learning methods such as Bayesian theory and deep learning. This information corresponds to information obtained from the human eyes and ears. Based on this, the control unit 101 performs intelligent information processing (artificial intelligence) and control (artificial intelligence) such as changing the vehicle's course and avoiding obstacles to generate autonomous driving operation information.
[0042] The display unit 111 is, for example, an LCD (Liquid Crystal Display). The touch panel 112 is configured such that a touch sensor capable of receiving touch input with a finger or stylus is superimposed on the display screen of the LCD display unit 111. The display screen of the display unit 111 displays an image including software buttons (including keyboard character input buttons) based on the control of the control unit 101. When the touch panel 112 detects a touch by a finger or stylus on a software button displayed on the display screen, it transmits that touch to the control unit 101. The control unit 101, upon receiving this, is configured to execute control processing corresponding to the software button.
[0043] The car navigation database 135, which is connected to the car navigation function unit 113, has domestic map and route guidance data pre-stored in it. The car navigation function unit 113 is a function unit that guides the autonomous vehicle 1 to move to a designated destination based on the map and route guidance data stored in the car navigation database 135. In this embodiment, the car navigation function unit 113 is configured to perform slightly different processing in manual driving mode and autonomous driving mode.
[0044] In other words, in manual driving mode, the car navigation function unit 113 displays an image on the display screen of the display unit 111 that overlays the vehicle's current position, as detected by the current position detection unit 110, onto a map that explicitly displays the route to the destination. Furthermore, as the vehicle moves, the vehicle's position (current position) on the map moves, and voice guidance is provided at intersections, junctions, and other points along the route where route guidance is needed. This is the same as a normal car navigation function.
[0045] On the other hand, in autonomous driving mode, the car navigation function unit 113 notifies the control unit 101 of the direction and distance of the vehicle's current position when it is off the route to the destination, and when the vehicle is on the route to the destination, it notifies the control unit 101 of instructions to change the direction of travel along the route before intersections and junctions along the route as the vehicle moves. Based on the information notified from the car navigation function unit 113, the current position confirmation result from the current position detection unit 110, and the detection result from the surrounding moving object recognition unit 109, the control unit 101 controls the motor drive unit 131 via the motor drive control unit 102 and generates autonomous driving operation information to control the steering drive unit 132 via the steering drive control unit 103 so that the vehicle moves along the route as instructed.Therefore, with the route guidance to the destination by the car navigation function unit 113 and the control unit 101 in autonomous driving mode, the autonomous vehicle 1 can move to the destination even when there are no passengers.
[0046] The user authentication unit 114 performs user authentication using the user authentication information stored in the memory unit 114M and the authentication information obtained from the user at that time. Here, the user is mainly the driver, but may also be a passenger other than the driver. In this embodiment, the autonomous vehicle 1 can drive autonomously in autonomous driving mode even if there is no driver present.
[0047] In this embodiment, for example, user authentication is performed by matching or mismatching the facial image of the most recent disembarking passenger with the facial image of a new user (boarding passenger). For this reason, in this embodiment, the user authentication unit 114 is configured to include image recognition means.
[0048] In this embodiment, the storage unit 114M of the user authentication unit 114 stores facial images of passengers disembarking, captured by a predetermined camera among the camera group 107. In this embodiment, the storage unit 114M updates and stores the most recent facial image of a passenger disembarking, captured by a camera, by overwriting it with a previously stored facial image of a passenger disembarking. Of course, the previous facial image of a passenger disembarking may be retained without overwriting. The storage unit 114M may also store image information of facial images of users who are registered to use the autonomous vehicle 1 (for example, family members, car-sharing members, acquaintances, or friends).
[0049] Furthermore, user authentication can also be performed using the user's voice. In this case, the autonomous vehicle 1 picks up the voice of the person getting off the vehicle using the microphone 137 and stores the voice of the person getting off in the memory unit 114M. The user authentication unit 114 is configured to have a speaker voice recognition function and performs user authentication by determining whether the stored voice matches or does not match the voice of the user picked up by the microphone 137.
[0050] Furthermore, user authentication can also be performed using the user's fingerprint. In this case, the autonomous vehicle 1 is equipped with a fingerprint reader, and the fingerprint of the person disembarking is stored in the memory unit 114M. The user authentication unit 114 is configured to have a fingerprint recognition function and performs user authentication by determining whether the stored fingerprint matches or does not match the new user's fingerprint obtained by the fingerprint reader. Vein patterns, iris patterns, voiceprints, and other biometric information can also be used for user authentication, and these can also be achieved by similar configuration changes. Of course, these biometric information such as facial images, voice, and fingerprints can also be combined, stored, and used for user authentication.
[0051] Furthermore, user authentication can also be performed by having the user hold the key to the autonomous vehicle 1.
[0052] Furthermore, the memory unit 114M may either overwrite and update the previously stored audio of a disembarking passenger with the voice of the most recent passenger captured by the microphone, or it may retain the previous audio of the disembarking passenger without overwriting. This method of storage is not limited to the voices of disembarking passengers; the same method of storage is possible for fingerprints, veins, irises, voiceprints, and other biometric information.
[0053] The caller authentication unit 115 performs caller authentication using the caller authentication information stored in the memory unit 115M and the authentication information obtained from the caller when the call was received by the wireless communication unit 123. In this embodiment, caller authentication is performed based on whether the phone number of the most recent disembarking passenger matches or does not match the phone number of the caller's mobile phone.
[0054] In this embodiment, the memory unit 115M of the caller authentication unit 115 stores the phone number of the most recent passenger to disembark, which is entered via the touch panel 112. The phone number stored in this memory unit 115M is overwritten on previously stored phone numbers to ensure that it contains only the phone number of the most recent passenger to disembark. Of course, it is also possible to leave the previously stored phone number without overwriting. In addition, an email address or a communication application ID may be stored instead of a mobile phone number. Of course, these may also be stored in combination with a phone number. In this case, whether or not the email address or communication application ID is overwritten is the same as in the case of a phone number. Furthermore, it is also possible to have the caller speak and perform speaker recognition.
[0055] The caller authentication unit 115 is configured to perform caller authentication by obtaining the incoming telephone number of the caller when an incoming call is received by the wireless communication unit 123, determining whether it matches or does not match the telephone number stored in the storage unit 115M.
[0056] Furthermore, the configuration of the caller authentication unit 115 is also modified according to the differences in the information used for authentication, similar to the configuration of the user authentication unit 114.
[0057] In this embodiment, the Post-Alighting Behavior Setting Reception Unit 116 receives the settings made by the user, such as the driver or other passengers, for the post-alighting behavior that the autonomous vehicle 1 should perform when the user alights, and stores the received setting information in the built-in storage unit 116M. In this embodiment, the storage unit 116M also stores a list of post-alighting behaviors that have been registered in advance by the user. The Post-Alighting Behavior Setting Reception Unit 116 presents the user with the list of post-alighting behaviors stored in the storage unit 116M and accepts the setting of the post-alighting behavior information selected and set by the user from that list. In addition to being installed in the autonomous vehicle 1, the Post-Alighting Behavior Setting Reception Unit 116 may also be installed in a mobile phone terminal such as a smartphone of the user that can communicate with the autonomous vehicle 1.
[0058] In this case, although not shown in the diagram, each post-disembarkation behavior item in the post-disembarkation behavior list (see Figure 3 described later) is represented as an icon button, and the user can select and input post-disembarkation behavior information by operating the desired icon button on the touch panel 112. Examples of post-disembarkation behaviors stored in the memory unit 116M and the setting acceptance processing of the post-disembarkation behavior setting acceptance unit 116 will be described later.
[0059] Furthermore, the input method for setting post-disembarkation behaviors can also be voice-based, where each post-disembarkation behavior is read aloud. The control unit 101 is equipped with a voice recognition function for this purpose.
[0060] The behavior control management unit 117 executes and manages the behavior of the vehicle after the user disembarks, based on the disembarkation behavior received by the disembarkation behavior setting reception unit 116. The behavior control management unit 117 includes a storage unit 117M that stores the disembarkation behavior received by the user by the disembarkation behavior setting reception unit 116, as well as authentication information and time information for executing said disembarkation behavior.
[0061] In this embodiment, the behavior control management unit 117 also includes a vehicle state determination means for determining whether the vehicle is moving or stopped, and a stop duration prediction means for predicting the duration of the stop when the vehicle state determination means determines that the vehicle is stopped. Here, "stopping" includes both stopping and parking. The stop duration is the duration until the stopped state ends.
[0062] Furthermore, the duration of the stop can be entered by the passenger upon disembarking via the touch panel 112, voice input via the microphone 137, or input via a mobile phone such as a smartphone. In this case, the entered time will be reflected in the stop duration prediction means, and the predicted stop duration will be determined. In addition, even if not at the time of disembarking, if the passenger is already aware of the length of the stop while boarding or riding, the stop duration (stop time) may be entered via the touch panel 112, voice input via the microphone 137, or input via a mobile phone such as a smartphone while boarding or riding.
[0063] In this embodiment, the vehicle state determination means of the behavior control management unit 117 determines whether the vehicle is moving or stopped, regardless of whether the driving mode is manual driving mode or automatic driving mode.
[0064] This is because, in this embodiment of the autonomous vehicle 1, even while driving in manual driving mode, the driver or passengers can switch to autonomous driving mode at any time. Therefore, while driving, updating the program for assisting driving in autonomous driving mode is prohibited to ensure greater safety.
[0065] The vehicle state determination means of the behavior control management unit 117 determines that the vehicle is stopped when, for example, the vehicle's speed detection means (not shown) has been at zero for a predetermined time, such as longer than the time spent waiting at a traffic light. In this case, the vehicle state determination means also has the functions of a speed detection means and a traffic light image recognition function (identification of red lights, etc.). The vehicle state determination means may also determine that the vehicle is stopped when it detects that the driver or passengers have disembarked from the vehicle. In this embodiment, once the behavior control management unit 117 determines that the vehicle is stopped using the vehicle state determination means, it notifies the program update management control unit 119 of the vehicle's stopped state. The vehicle state determination means of the behavior control management unit 117 may also notify the program update management control unit 119 whether the vehicle is stopped or moving when it receives an inquiry from the program update management control unit 119.
[0066] As will be described later, in this embodiment, the stop duration prediction means of the behavior control management unit 117 predicts the stop duration based on the post-disembarkation behavior set by the user. In this embodiment, the information of the stop duration predicted by this stop duration prediction means is sent when an inquiry is made from the program update management control unit 119. In this case, when the vehicle state determination means determines that the vehicle is stopped, the stop duration prediction means predicts the end time of the stopped state. Then, when an inquiry is made from the program update management control unit 119, the stop duration prediction means calculates the time from the time the inquiry is received to the predicted end time as the stop duration and sends this information to the program update management control unit 119.
[0067] Furthermore, the stop duration prediction means of the behavior control management unit 117 may predict the end time of the stop state when the vehicle state determination means determines that the vehicle has stopped, and automatically notify the program update management control unit 119 of the predicted stop duration. In this case, the program update management control unit 119 can predict the stop duration itself from the information on the end time of the stop state received from the behavior control management unit 117.
[0068] In this case, considering that when a driver is present, the vehicle's movement is generally controlled according to the driver's control instructions, the behavior control management unit 117, in this embodiment, executes and manages control processing based on the received post-disembarkation behavior only when the driver is no longer inside the vehicle after the user has disembarked. An example of behavior control and management by this behavior control management unit 117 (including the functions of the vehicle state determination means and the stop duration prediction means) will be described in detail later.
[0069] The non-driving function unit 118 is a function unit for executing functions other than driving functions of the autonomous vehicle 1, such as AV entertainment functions and game functions. The non-driving function is started by the user selecting and instructing to start the non-driving function via the touch panel 112, and the execution of the function is terminated by the user's instruction to stop (including turning off the drive power of the autonomous vehicle 1). Non-driving functions such as AV entertainment functions and game functions can be used not only when the vehicle is stationary, but also when the vehicle is in motion (both when driving in manual driving mode and when driving in autonomous driving mode).
[0070] The program update management control unit 119 connects to the program update server 3 (see Figure 4), described later, via the Internet 2 using the wireless communication unit 123, and performs program update processing for each part of the autonomous vehicle 1. In the autonomous vehicle 1 of this embodiment, the motor drive control unit 102, steering drive control unit 103, manual / autonomous driving mode switching control unit 104, brake drive control unit 105, surrounding moving object detection unit 109, current position detection unit 110, car navigation function unit 113, post-disembark behavior setting reception unit 116, behavior control management unit 117, etc. are function units for driving purposes and are operated by programs. In addition, the user authentication unit 114, caller authentication unit 115, and non-driving function unit 118 are function units for purposes other than driving, and these are also operated by programs. The program update management control unit 119 manages and controls the updates of all of these programs.
[0071] The audio input / output unit 120 takes in the sound picked up by the microphone 137 and sends it to the system bus 100, for example, for speech recognition processing. The audio input / output unit 120 also has a built-in memory for storing voice message data to be broadcast externally, and a built-in voice synthesizer and DA converter to convert the voice message data read from the memory into an analog voice signal. The audio input / output unit 120 then supplies the voice message selected by the control unit 101 to the speaker 136 and broadcasts it externally as voice.
[0072] As described later, the voice messages that can be stored include inquiry messages such as "Would you like to set up post-disembarkation behavior?", notification messages such as "Authentication complete." and "Authentication failed," and interactive messages when accepting input for post-disembarkation behavior settings. In addition, notification messages such as "The program is being updated, so we cannot respond to your call" or "The program is being updated, please wait" are also available.
[0073] The clock unit 121 is equipped with a calendar function that provides the year, month, day, day of the week, and current date and time, and also has a timer function that measures time from a predetermined timing and measures the remaining time of the update while a program update is being performed, based on the control of the control unit 101.
[0074] The battery 11 is connected to the battery level detection unit 122. The battery level detection unit 122 constitutes the drive source level detection unit, and in this embodiment, it detects the remaining charge of the battery 11 as a drive source. In this embodiment, the battery level detection unit 122 has the function of detecting how far the vehicle can travel or how long it can travel with the remaining charge when used for driving, and also has the function of detecting how long the vehicle can be continuously used with the remaining charge of the battery 11 when used for purposes other than driving. Furthermore, in this embodiment, it also has the function of determining whether it is possible to update the program with the remaining charge of the battery 11.
[0075] The wireless communication unit 123 has the function of connecting to program update servers and navigation-related surrounding search servers via the internet, as well as the function of responding to calls from users. In this example, it has the same functions as a high-function mobile phone (smartphone). Therefore, each of the wireless communication units 123 of the autonomous vehicle 1 has its own mobile phone number and email address.
[0076] As described above, the electronic control circuit unit 10 of the autonomous vehicle 1 is configured as described above. In the above description, the motor drive control unit 102, steering drive control unit 103, manual / autonomous driving mode switching control unit 104, surrounding moving object detection unit 109, current position detection unit 110, car navigation function unit 113, user authentication unit 114, caller authentication unit 115, post-disembark behavior setting reception unit 116, behavior control management unit 117, and non-driving function unit 118 shown in Figure 1, each of which has a program for processing each function, can be implemented by the control unit 101 as software processing. It goes without saying that not all of the above units have program-based processing functions, and some may be configured as hardware components.
[0077] In this embodiment, when the autonomous vehicle 1 is stopped, the power supply to each part that should only operate while driving is stopped. However, the current position detection unit 110, user authentication unit 114, caller authentication unit 115, behavior control management unit 117, and program update management control unit 119 are kept in a standby state and can be immediately activated by the control unit 101 when necessary. If the control unit 101 executes all functions by program, it goes without saying that the control unit 101 is always in a standby state even when stopped and can be activated in response to various activation triggers.
[0078] [Example of stored information in the memory unit 116M of the post-disembarkation behavior reception unit 116] As mentioned above, the memory unit 116M of the post-disembarkation behavior reception unit 116 stores in advance the post-disembarkation behavior that the user wishes to specify. This post-disembarkation behavior can be selected from those that have been pre-registered as defaults by the automobile company or the like in the autonomous vehicle 1, or it can be set and stored by the user. It is also possible to use information stored on the internet cloud.
[0079] Figure 2 shows an example of post-disembarkation behavior stored in the storage unit 116M of the post-disembarkation behavior reception unit 116 in this embodiment. An example of each post-disembarkation behavior will be described below.
[0080] The "Move to default parking lot" option causes the autonomous vehicle 1 to move to a pre-registered default parking lot after the user has disembarked. The post-disembarkation behavior ends upon arrival at the parking lot. Multiple parking lots can be registered as default parking lots, such as "home parking lot," "company parking lot," and "contract parking lot." Registering a parking lot means remembering its location information and its name (type), such as "home parking lot," "company parking lot," or "contract parking lot." When a user selects "Move to default parking lot" as the post-disembarkation behavior, they also select the name of the default parking lot.
[0081] If "Move to the designated parking lot" is set as the post-disembarkation behavior, it is predicted that the autonomous vehicle 1 will not be used for a relatively long period of time after the user disembarks, for example, more than one hour. Therefore, the stop duration prediction means of the behavior control management unit 117 predicts this period of non-use as the stop duration.
[0082] The "wait in a nearby parking lot until called" function means that the autonomous vehicle 1 searches for a parking lot near the user's drop-off location, waits in that parking lot, and then, when the user makes a call via telephone communication using their mobile phone terminal through the autonomous vehicle 1's wireless communication unit 123, the autonomous vehicle 1 returns to the location where the user dropped off in response to the call. In this embodiment, the user registers authentication information for the time of the call and authentication information for re-boarding when they drop off. The behavior control management unit 117 stores the registered authentication information in the storage unit 117M along with the post-drop-off behavior setting information. The authentication information for the time of the call and the authentication information for re-boarding can also be deleted (erased) when re-boarding is completed.
[0083] In this case, the user is prompted to input the waiting time until the call is made, and as shown in Figure 2, the user sets and inputs the waiting time in the input field. The stop duration prediction means of the behavior control management unit 117 predicts the stop duration from this set and inputted waiting time.
[0084] The behavior control management unit 117 of the autonomous vehicle 1, when a call is made by a user via a mobile phone terminal, authenticates the caller using the registered authentication information for the call, and only if authentication is successful does it respond to the call and perform movement control to return to the location where the user disembarked. In this embodiment, for example, the telephone number (subscriber number) of the caller's mobile phone terminal is registered as the authentication information for the call when the user disembarks, and when an incoming call is received from the caller, authentication is performed by checking whether the caller's telephone number is the registered telephone number.
[0085] Then, when the behavior control management unit 117 of the autonomous vehicle 1 detects a user re-boarding, it authenticates the re-boarder using the registered authentication information for re-boarding, and controls the system to allow the re-boarder to use the vehicle only if the authentication is successful. In this embodiment, for example, the user's facial image is registered as authentication information for re-boarding when the user disembarks, and when the user re-boards, authentication is performed by facial recognition using the facial image to determine whether the user is the registered disembarking person or not.
[0086] Furthermore, the authentication information used during a call is not limited to the phone number of the mobile phone terminal; an email address is also acceptable. Alternatively, a password or ID can be registered, and authentication can be performed by having the caller send this password or ID during communication based on the incoming call, and verifying that the two match. A combination of a phone number or email address and the corresponding password or ID may also be used as authentication information during a call.
[0087] Furthermore, the authentication information for returning passengers may not be limited to facial images, but may also include biometric information such as voice, fingerprints, vein patterns, or iris patterns, or even passwords or IDs. A combination of these may also be used as authentication information.
[0088] "Waiting here" means that the autonomous vehicle 1 will wait at the location where the user disembarked. In this case, the user is prompted to input the waiting time, and as shown in Figure 2, the user sets and inputs the waiting time in the input field. The stop duration prediction means of the behavior control management unit 117 predicts the stop duration from this set and inputted waiting time.
[0089] Furthermore, in this embodiment, when the user disembarks, the user registers authentication information for re-boarding. This authentication information for re-boarding can be the same as that described in "Waiting in a nearby parking lot until called," and in this embodiment, it is the user's (for example, the driver's) facial image. The behavior control management unit 117 stores the registered authentication information together with the post-disembarkation behavior setting information in the storage unit 117M.
[0090] "Proceeding to Point A" means that the autonomous vehicle 1 will move autonomously to a location specified by the user. Point A is specified by the user when they disembark. Point A may be set from a list of pre-registered locations, or it may be specified on a map, by entering an address, or by specifying a identifiable building name. It may also be specified using two-dimensional coordinates of latitude and longitude (or three-dimensional coordinates by adding altitude). Furthermore, if Point A can be identified by a telephone number, it may be specified by entering the telephone number. In this case, since it is difficult to predict the duration of the vehicle's stop, the stop duration prediction means of the behavior control management unit 117 predicts the stop duration to be, for example, zero.
[0091] In this case of "heading to point A," the re-boarders are not limited to those who disembarked. Therefore, in this embodiment, a password or ID is set as authentication information for re-boarders. The behavior control management unit 117 stores the registered authentication information together with the post-disembarkation behavior setting information in the storage unit 117M.
[0092] In the "Pick up on request" scenario, after the user disembarks, the autonomous vehicle 1 can operate freely (including autonomous driving) until a call is made. When the user makes a call via telephone communication using their mobile phone terminal through the autonomous vehicle 1's wireless communication unit 123, the autonomous vehicle 1 will respond to the call and go to the location specified by the user to pick them up. In this case, information about the pick-up location is sent to the autonomous vehicle 1 during the telephone communication when the user makes the call. For example, the user's current location information, determined by the GPS on their mobile phone terminal, is sent from the user's mobile phone terminal to the autonomous vehicle 1 as information about the pick-up location. Furthermore, in this case as well, the user registers authentication information for the call and authentication information for re-boarding when disembarking. The same processing as in the "Wait in a nearby parking lot until called" scenario is performed for the authentication information for the call and authentication information for re-boarding.
[0093] In this case as well, since it is difficult to predict the duration of the stoppage, the function of the stoppage duration prediction means of the behavior control management unit 117 predicts the stoppage duration to be zero, for example.
[0094] Furthermore, the call is not limited to telephone communication; it can also be made via email or a communication app.
[0095] "Waiting at Point B" means that the autonomous vehicle 1 will wait at a location specified by the user and await the user's re-boarding. Point B is specified by the user when they disembark. Point B can be set from a pre-registered list of locations, or it can be specified on a map, by entering an address, or by specifying a identifiable building name. It can also be specified using two-dimensional coordinates of latitude and longitude (or three-dimensional coordinates including elevation). Furthermore, if Point B can be identified by a phone number, it can be specified by entering the phone number.
[0096] In this case, the user is prompted to input the waiting time, and as shown in Figure 2, the user sets and inputs the waiting time at point B in the input field for the waiting time. The function of the stop duration prediction means of the behavior control management unit 117 predicts the stop duration from this set and inputted waiting time.
[0097] In this case, the authentication information for the user when re-boarding can be the same as that described in the "waiting in a nearby parking lot until called" section above, and in this embodiment, it is the facial image of the user (for example, the driver). The behavior control management unit 117 stores the registered authentication information together with the post-disembarkation behavior setting information in the storage unit 117M.
[0098] "Return to the drop-off location after a specified time" refers to post-drop-off behavior, where the user returns to the drop-off location (current location) (including remaining in the same place) after a specified time has elapsed since the user completed a specified task. When dropping off, the user can either directly set the specified time in the "specified time" input field, as shown in Figure 2, or enter a task to determine the "specified time" in that input field. In other words, the way to set the "specified time" in this case is as follows: (a) Setting the timer time for the clock unit 121, (b) Settings via voice input through microphone 137, for example, "just a quick errand," "toilet," "meal," "concert," "watching a baseball game," "watching a soccer game," "watching sumo wrestling," "2-3 minutes," "about an hour," etc. (c) Selection from a list of predetermined tasks displayed on the display unit 111 These are some examples.
[0099] The control unit 101 of the autonomous vehicle 1 determines the predetermined time from the input of information for determining the predetermined time in (b) and (c) as follows. In the case of (b), the text enclosed in quotation marks is input by voice, and the voice-recognized task is displayed in the input field. In the case of (c), the text enclosed in quotation marks is selected from the list, and the selected task is displayed in the input field. In the function of the stop duration prediction means of the behavior control management unit 117, if a "predetermined time" is set, the "predetermined time" is determined from that time information, and if a "task" is selected and input, the "task" is determined from the selected "task", and the stop duration is predicted from the determined "predetermined time".
[0100] Examples of "errands" and designated time are shown below. • "Toilet": Estimate a short time, for example, 10 minutes. • "Watching Sumo Wrestling": In the case of a regular tournament, it usually ends around 6 PM, so use that end time as a guide to determine the required time from the current time. • "Watching a baseball game": For professional baseball, the guideline is about 3 hours from the start of the game, and for high school baseball, it's about 2 hours from the start of the game. Extra innings will add to the time. For example, you can get the start time of the game from a designated website via the internet, and you can also find out the end time of the game by obtaining broadcast information from a designated website via the internet. • "Watching a soccer match": The match duration is roughly calculated as follows: 45 minutes for the first half, 15 minutes for halftime, 45 minutes for the second half, plus a small amount of added time. Extra time will add to the match duration. For example, the match start time can be obtained from a designated website via the internet, and the match end time can be determined by obtaining broadcast information from a designated website via the internet. • For "concerts," the end time announced by the organizers is used as a guideline. Upon disembarking, the user enters the end time, and the designated time is determined based on that time. • "Movie viewing": The end time is fixed. When the user disembarks, they enter the end time, and the scheduled time is determined based on that time. • "Shopping Center": Based on experience and statistics, a predetermined time is determined, for example, as 2 hours. • "Department store": Based on experience and statistics, a predetermined time is determined, for example, as 2 hours. • "Mass retailers (home appliances and computers)": Based on experience and statistical data, a predetermined time is determined, for example, as 1 hour. • "Bookstore": Based on experience and statistics, a predetermined time is determined, for example, as 30 minutes. • "Flower Shop": Based on experience and statistics, a predetermined time is determined, for example, 15 minutes. • "Small Shop": Based on experience and statistics, a predetermined time is determined, for example, as 15 minutes. • "Convenience Store": Based on experience and statistics, the predetermined time is determined, for example, as 15 minutes. • "Post Office" Depending on the waiting time, estimate the time required for each step: for example, 3 minutes for simply dropping off mail, 10 minutes at the postal counter, 5 minutes at an ATM, and 20 minutes at a savings or insurance counter. • "Banks" Depending on the waiting time, a predetermined time can be set, for example, 5 minutes for ATMs and 20 minutes for teller services. If the number of people waiting in line for an ATM can be seen from the outside, the number of people can be recognized by recognizing images taken with a camera, and for example, 3 minutes per person waiting for an ATM can be calculated by multiplying 3 minutes by the number of people and adding it to the predetermined time. • The end time for "cram school" is fixed. When the user disembarks, they enter the end time, and this time is used as a guideline to determine the designated time, for example, 2 hours. • "Restaurant": For example, if lunch is 30 minutes and dinner is 2 hours, the designated time is kept in mind. • For example, "coffee shop": Determine the time allotted, such as one hour. • For example, if it's a "fishing pond," determine the time allotted, say 2 hours. • "Shrines and temples": For example, New Year's visits. For instance, one hour. Keep track of the designated time. • For "theme parks, amusement parks, leisure lands, and amusement parks," if you plan to spend a full day there, say 8 hours, you can determine the total time. If you plan to stay until closing time, you can calculate the total time from now until closing time. • "Museums and art galleries": For large institutions like the British Museum or the Louvre Museum, a set time is determined, for example, 5 hours or until closing time. For smaller institutions, a set time is determined, for example, 1 hour. • For example, if visiting a zoo or aquarium takes 3 hours, determine the required time. • There are signs such as "No Vehicle Entry Area" or "Please refrain from driving beyond this point," but if you want to see what's beyond, get out of your car and take a look. For example, if you have 15 minutes, be sure to keep track of the time limit.
[0101] Furthermore, the autonomous vehicle 1 may determine the predetermined time based on TPO (situation, congestion level, etc.). The availability of a parking space at the drop-off location may also be used as a condition for determining the predetermined time. Additionally, if applications are available at post offices, banks, restaurants, cafes, etc., that waiting time can be used to determine the predetermined time. In this case, if the application at the restaurant or cafe has a function to provide waiting time information, the autonomous vehicle 1 can receive and understand this waiting time information via the wireless communication unit 123.
[0102] Furthermore, if the waiting time is displayed in a place visible from the outside, such as a restaurant or cafe, the autonomous vehicle 1 can determine the waiting time by performing image recognition on the images captured by the camera group 107. Users who have determined the waiting time may input that waiting time to the autonomous vehicle 1 via the touch panel 112 or by voice via the microphone 137.
[0103] In this example, the post-disembarkation behavior is set to "return to the disembarkation point after a predetermined time," but it could also be set to "return to the disembarkation point at a predetermined time." Alternatively, both post-disembarkation behaviors may be provided.
[0104] "Being at point C after a predetermined time" is also a post-disembarkation behavior that assumes the user will perform a predetermined task after disembarking, and involves moving to a different point C than the disembarkation location (current location) as the point of re-boarding after the predetermined time. Similar to "Returning to the disembarkation location after a predetermined time," the user sets point C at the time of disembarkation, either by directly setting the "predetermined time" or by inputting a "task" to determine the "predetermined time." In the function of the stop duration prediction means of the behavior control management unit 117, if a "predetermined time" is set, the "predetermined time" is determined from that time information, and if a "task" is selected and input, the "predetermined time" is determined from the selected "task," and the stop duration is predicted from the determined "predetermined time."
[0105] Location C can be selected from a pre-registered list of locations, or it can be specified on a map, by entering an address, or by specifying a identifiable building name. It can also be specified using two-dimensional coordinates (latitude and longitude) (or three-dimensional coordinates including elevation). Furthermore, if Location C can be identified by a phone number, it can be specified by entering the phone number.
[0106] If point C is close to the drop-off location (current location), the method for setting the "predetermined time" and the method for determining the predetermined time in the control unit 101 of the autonomous vehicle 1 are the same as for "returning to the drop-off location after the predetermined time." If point C is far from the drop-off location (current location) (for example, more than 1 km), the travel time from the drop-off location (current location) to point C will greatly affect the predetermined time. Therefore, the predetermined time cannot be determined by the time required for the predetermined task alone, and it is necessary to determine the time required for travel in addition to the travel time. Calculating (estimating) the travel time requires inputting information on the means of travel and the distance or section of travel using that means. Therefore, if point C is far from the drop-off location (current location), it is preferable for the user to directly set the "predetermined time" when dropping off.
[0107] Even in this case, the post-disembarkation behavior can be "being at point C at a predetermined time" rather than "being at point C after a predetermined time," similar to "returning to the disembarkation location after a predetermined time." Alternatively, both post-disembarkation behaviors may be prepared.
[0108] [Example of processing operations when a user disembarks from the autonomous vehicle 1 of the embodiment] Next, we will describe the general operation of the control unit 101 of the autonomous vehicle 1 when a passenger, in this example, the driver, attempts to alight from the vehicle.
[0109] In this embodiment, when a passenger, in this example the driver, attempts to alight from the autonomous vehicle 1, the autonomous vehicle 1 asks the driver whether to set a post-alight behavior. If the driver provides a post-alight behavior setting in response to this inquiry, the autonomous vehicle 1 accepts the post-alight behavior setting input from the driver and performs processing according to the accepted post-alight behavior after the driver alights.
[0110] Figure 3 is a flowchart illustrating an example of the processing flow performed by the control unit 101 of the electronic control circuit unit 10 of the autonomous vehicle 1 when the driver disembarks. The processing steps in the flowchart of Figure 3 are explained assuming that the processing functions of the disembarkation behavior setting reception unit 118 and the behavior control processing unit 120 are implemented as software processing performed by the control unit 101 through program execution.
[0111] The control unit 101 determines whether the driver has stopped the motor drive unit 131 of the vehicle (step S1). If, in step S1, it determines that the motor drive unit 131 has not been stopped, the control unit 101 continues the control necessary for driving (step S2), and then returns to step S1.
[0112] In step S1, when it is determined that the motor drive unit 131 has been stopped, it is generally expected that the driver will get out of the vehicle. Therefore, the control unit 101 displays a message on the display unit 111 asking whether to set the behavior after getting out of the vehicle, and also emits this message as an audible message through the speaker 136 (step S3).
[0113] The control unit 101 monitors and determines the driver's response to the inquiry in step S3 regarding whether to set the post-disembarkation behavior (step S4). When it determines that the driver has responded that they will not set the post-disembarkation behavior, it terminates the processing routine shown in Figure 3. In this case, the autonomous vehicle 1 stops the motor drive unit 131 at the position where the driver has disembarked, and while maintaining power supply to the necessary parts as part of the stopped processing, it also turns off the power supply. Alternatively, a predetermined behavior may be set in advance for when the driver does not set the post-disembarkation behavior, and this predetermined behavior may be executed. The predetermined behavior that is set in advance may be schedule information.
[0114] In step S4, if the control unit 101 determines that the driver has responded that they will set the behavior after disembarking, the control unit 101 displays the disembarking behaviors stored in the memory unit 116M as a list on the display screen of the display unit 111, as shown in Figure 2 (step S5).
[0115] Next, the control unit 101 monitors the user's input operations through the touch panel 112 and waits for the user to select a post-disembarkation behavior from the list displayed on the screen (step S6). In step S6, if the control unit 101 determines that the user has selected a post-disembarkation behavior from the list, it performs processing to accept the selected post-disembarkation behavior (step S7). The processing for accepting the selected post-disembarkation behavior in step S7 will be described in detail later.
[0116] Next, the control unit 101 determines whether or not it has completed the process for accepting the selected post-alighting behavior (step S8). If it determines that it has completed the process for accepting the selected post-alighting behavior, it stores the selection information of the post-alighting behavior selected by the user and the information associated therewith (step S9). If the process for accepting the selected post-alighting behavior is not completed within a predetermined time (e.g., 10 minutes), it may determine that the user has not set a post-alighting behavior and terminate the processing routine in Figure 3. In this case, as described above, the autonomous vehicle 1 stops the motor drive unit 131 at the position where the driver alights, and turns off the power supply while maintaining power to the parts necessary for processing while stopped. Alternatively, a predetermined behavior may be set in advance for when the driver does not set a post-alighting behavior, and this behavior may be executed. The predetermined behavior that is set in advance may be schedule information.
[0117] Next, the control unit 101 confirms that a passenger has disembarked using a door sensor and determines whether or not there is a driver (step S10). The presence or absence of a driver is determined from a seating sensor consisting of a weight sensor and a pressure sensor installed in the driver's seat, a touch sensor that determines whether or not a person has touched the steering wheel or touch panel 112, and from the image captured by the camera in the driver's seat of the camera group 107. Alternatively, it can be determined from the presence or absence of the driver's voice picked up by the microphone 135. If a driver is present, the control unit 101 waits for the driver to disembark, and when it determines in step S10 that the driver has disembarked and is no longer there, it executes the selected post-disembarkation behavior that has been stored (step S11). In step S11, if the autonomous vehicle 1 is moving, the autonomous vehicle 1 will drive autonomously in autonomous driving mode.
[0118] [Program update overview] As shown in Figure 4, the autonomous vehicle 1 of this embodiment connects to the program update server 3 via the internet 2 using the wireless communication unit 123 to perform an update of the program installed in the vehicle.
[0119] In this case, the program update server 3 includes a client information storage management unit 31 that stores and manages one or more programs installed in each autonomous vehicle 1 (client) in correspondence with the identification information of each autonomous vehicle 1, and an update program management control unit 32 that manages and controls the provision of update program information to each autonomous vehicle 1. The client information storage management unit 31 also stores connection information (such as mobile phone numbers and URLs (Uniform Resource Locator, etc.)) for connecting with each autonomous vehicle via the internet.
[0120] The information stored in the client information storage management unit 31 is stored by each autonomous vehicle 1 connecting to the program update server 3 via the internet 2 and registering as a client in advance. Alternatively, the sales company or manufacturer of the autonomous vehicle 1 may store in the client information storage management unit 31 of the program update server 3, in accordance with the identification information of each autonomous vehicle 1, one or more programs installed (program identification information, etc.) and connection information for each autonomous vehicle 1.
[0121] The update management control unit 32 receives information about the update program and stores it temporarily. The update management control unit 32 sends the temporarily stored update program information to the client autonomous vehicle 1 that requires a program update based on that update program information, and instructs it to perform the program update. When the program update is complete, the autonomous vehicle 1 notifies the program update server 3 of the update completion. Upon receiving this update completion notification, the program update server 3 confirms the completion of the update program for each autonomous vehicle, and once the update program has been provided to all necessary autonomous vehicles 1, it deletes the update program from the temporary storage unit, and the program update is completed.
[0122] In this case, as shown in Figure 4, there are two ways in which the program update server 3 can provide information about the update program to each client's autonomous vehicle 1. The first method is as shown in the combination of autonomous vehicle 1 and program update server 3 on the left side of Figure 4, in which the program update server 3 notifies each client's autonomous vehicle 1 that an update program is available via an update notification, and the autonomous vehicle 1 that responds can download the update program information.
[0123] The second method, as shown in the combination of the autonomous vehicle 1 and the program update server 3 on the right side of Figure 4, involves the autonomous vehicle 1 querying whether or not an update program exists, and the program update server 3 determining whether or not there is an update program to provide to the requesting autonomous vehicle 1 at that time. If it determines that there is an update program, it provides information about the update program to the requesting autonomous vehicle 1.
[0124] In this embodiment, the update program information includes information on the time required for the update (update time information), information on the type of update program (whether the update program is for driving purposes or for non-driving purposes), and program identification information indicating which program the update program is for.
[0125] In the first method described above, in this embodiment, when the program update management control unit 119 of the autonomous vehicle 1 receives an update notification from the program update server 3, it downloads information about the update program from the program update server 3 and obtains the information about the update program, and then determines whether the program can be updated. If it determines that it can be updated, it performs the program update.
[0126] In this case, the program update management control unit 119 first determines whether a program update is possible by determining the type of update program, that is, whether the update program relates to a driving support program related to autonomous driving assistance or to a program for purposes other than driving. If it determines that the update program relates to a program for purposes other than driving, it proceeds to perform the update using the acquired update program. This is because if the program is for purposes other than driving, updating the program even while driving does not pose any danger.
[0127] When the program update management control unit 119 determines that the update concerns a driving support program, it queries the behavior control management unit 117 to determine whether the vehicle is stopped or in motion. If the vehicle is in motion, it stores the information about the acquired update program, as performing the update at that time could be dangerous. Therefore, it stores the information about the update program and performs the update when the vehicle is stopped.
[0128] The program update management control unit 119 also recognizes the update time based on the update time information included in the acquired update program information when the vehicle is stopped, and queries the behavior control management unit 117 to obtain the predicted duration of the stop. It then determines whether a program update is possible during the stop duration, and if possible, executes the update using the acquired update program. If it determines that a program update is not possible during the stop duration, it stores the acquired update program information and executes the update in a later stop state.
[0129] Next, in the second method, the program update management control unit 119 of the autonomous vehicle 1 receives notification from the behavior control management unit 117 that the vehicle has stopped, and after confirming that the vehicle has stopped, it sends an inquiry to the program update server 3 via the wireless communication unit 123 to ask whether or not an update program exists.
[0130] When the program update server 3 receives this inquiry, it identifies the client's autonomous vehicle 1 from its identification information, and the client information storage management unit 31 and the update program management control unit 32 determine whether or not there is an update program to provide to the client's autonomous vehicle 1. If it determines that there is an update program, the update program management control unit 32 sends and provides the update program information to the autonomous vehicle 1 that made the inquiry.
[0131] The program update management control unit 119 of the autonomous vehicle 1, upon receiving this update program, will execute the update using the acquired update program if the update program relates to a program for purposes other than driving. If the information of the received update program relates to a driving support program, the program update management control unit 119 will inquire with the behavior control management unit 117 about the predicted duration of the stop, compare it with the update time included in the acquired update program information, and if the program update is possible during the stop duration, will execute the update using the acquired update program. If it is determined that the driving support program cannot be updated during the stop duration, the program update management control unit 119 will store the information of the acquired update program and execute the update in a later stop state.
[0132] The following describes examples of the operation flow in each case of the first method and the second method, with reference to the flowcharts shown in Figure 5 and subsequent figures. In the following flowcharts, the operation at each step is described assuming that the control unit 101 executes each functional part of the electronic control circuit unit 10 as software by program.
[0133] <In the case of the first method> The control unit 101 monitors whether the wireless communication unit 123 has received a program update notification from the program update server 3 (hereinafter abbreviated as server 3) (step S21). If the control unit 101 determines in step S21 that it has not received a program update notification, it performs other processing (step S22), then returns to step S21, and repeats the processing from step S21 onward.
[0134] In step S21, when the control unit 101 determines that it has received a program update notification, it returns a response to the update notification to the server 3 (step S23). The server 3 then downloads information about the update program, including the type of update program and the update time, and the control unit 101 receives and acquires this update program information via the wireless communication unit 123 (step S24).
[0135] Then, the control unit 101 determines whether or not the update program is for driving assistance based on the type of update program information included in the acquired update program information (step S25). If, in step S25, it determines that the update program is not for driving assistance but for purposes other than driving, the control unit 101 uses the acquired update program information to perform the corresponding program update (step S26).
[0136] The control unit 101 then waits for the program update to complete (step S27), and when it determines that the program update is complete, it notifies the server 3 of the completion of the program update via the wireless communication unit 123 (step S28). This program update completion notification includes the identification information of the autonomous vehicle 1 and the identification information of the program that has been updated. Upon receiving this update completion notification, the server 3 certifies which autonomous vehicle 1 and which program has been updated, and reflects the certification result in the update history information of the client information storage management unit 31. Each time the server 3 receives an update completion notification, it processes the writing of the update history information.
[0137] Following step S28, the control unit 101 returns the process to step S21 and repeats the process from step S21 onward.
[0138] Furthermore, in step S25, if the control unit 101 determines that the acquired update program information is for driving assistance, it determines whether the vehicle is stopped or not (step S29). In step S29, if it determines that the vehicle is stopped, the control unit 101 determines the update time from the update time information included in the acquired update program information (step S30). Next, the control unit 101 acquires the stop duration information predicted by the behavior control management unit 117 and predicts the stop duration from the current time (step S31 in Figure 6).
[0139] Then, the control unit 101 determines, based on the update time information and the predicted stop duration information from the current time, whether or not it is possible to update the driving support program within the predicted stop duration from the current time (step S32). If, in step S32, it is determined that it is possible to update the driving support program within the predicted stop duration from the current time, the control unit 101 uses the acquired update program information to perform the corresponding driving support program update (step S33).
[0140] The control unit 101 then determines whether the update of the driving support program is complete (step S34). If it determines that the program update is not complete, it determines whether the driver has requested to start driving (step S36). If it determines that the driver has requested to start driving, it displays the message "Driving is not possible because the program is being updated. Please wait." on the display screen of the display unit 111 and also notifies the driver by emitting an audible message from the speaker 136 (step S37). After step S37, the control unit 101 returns to step S34 and repeats the process from step S34 onward.
[0141] If the control unit 101 determines in step S36 that no driver has requested to start driving, it determines whether or not a call request has been received (step S38). If it determines that a call request has been received, it displays the message "Driving cannot be started in response to the call because the program is being updated. Please wait." on the display screen of the display unit 111 and also notifies the driver by emitting an audible message from the speaker 136 (step S39). After step S39, the control unit 101 returns to step S34 and repeats the process from step S34 onward. If the control unit 101 determines that no call request has been received, it returns to step S34 and repeats the process from step S34 onward.
[0142] Then, in step S34, when the control unit 101 determines that the update of the driving support program is complete, it notifies the server 3 of the completion of the program update via the wireless communication unit 123 (step S35). The control unit 101 then returns to step S21 and repeats the process from step S21 onward.
[0143] Then, in step S29 of Figure 5, when it is determined that the vehicle is not stopped but is in motion, and in step S32 of Figure 6, when it is determined that the program cannot be updated within the predicted stop duration from the current time, the control unit 101 stores the update program information acquired in step S24 (step S41 of Figure 7). The control unit 101 then determines whether the vehicle has stopped (step S42), and if it determines that the vehicle has stopped, it obtains the update time from the update time information included in the stored update program information (step S43). Next, the control unit 101 obtains the stop duration information predicted by the behavior control management unit 117 and predicts the stop duration from the current time (step S44).
[0144] Then, the control unit 101 determines, based on the update time information and the predicted stop duration information from the current time, whether or not it is possible to update the driving support program within the predicted stop duration from the current time (step S45). If in step S45 it is determined that it is not possible to update the driving support program within the predicted stop duration from the current time, the control unit 101 returns to step S42 and repeats the process from step S42 onward. If in step S42 it is determined that the vehicle is not in a stopped state, the control unit 101 also returns to step S42 and repeats the process from step S42 onward.
[0145] Furthermore, if in step S45 it is determined that the driving support program can be updated within the predicted stop duration from the current time, the control unit 101 uses the acquired update program information to perform the corresponding driving support program update (step S46). Following step S46, the control unit 101 proceeds to step S34 in Figure 6 and repeats the process from step S34 onward.
[0146] <In the case of the second method> The control unit 101 determines whether the vehicle has come to a stop state using the function of the vehicle state determination means of the behavior control management unit 117 (step S51). If it is determined in step S51 that the vehicle has not come to a stop state, the control unit 101 performs other processing (step S52), then returns to step S51, and repeats the processing from step S51 onward.
[0147] In step S51, when it is determined that the vehicle has come to a stop, the control unit 101 predicts the duration of the stop using the function of the stop duration prediction means of the behavior control management unit 117 (step S53), and determines whether the predicted duration of the stop is equal to or greater than a predetermined time (step S54). The determination in step S54 is to exclude cases where the vehicle restarts immediately after stopping, and the predetermined time is set to, for example, 5 minutes.
[0148] If, in step S54, the control unit 101 determines that the predicted stop duration is less than a predetermined time, it returns the process to step S51 and repeats the process from step S51 onward.
[0149] In step S54, if the control unit 101 determines that the predicted stop duration is longer than a predetermined time, it sends a program update request including the vehicle's identification information to the server 3 via the wireless communication unit 123 (step S55).
[0150] In response to this program update inquiry, Server 3 determines whether there are any incomplete update programs for the client's autonomous vehicle 1. If there are no update programs, it sends a notification to the client's autonomous vehicle 1 stating that no update programs are available. If there are update programs, it sends a notification that update programs exist and downloads the update program information to the client's autonomous vehicle 1.
[0151] Therefore, the control unit 101, which sent the program update inquiry, determines whether or not it has received a notification from the server 3 that there are no updates available (step S56). If it determines that it has received a notification that there are no updates available, it returns to step S51 and repeats the process from step S51 onward.
[0152] In step S56, if it is determined that a notification has been received indicating the existence of an update program, rather than a notification indicating that no update program is available, the control unit 101 receives the update program information from the server 3 and obtains the update program information (step S57). Then, the control unit 101 determines the update time from the obtained update program information (step S58).
[0153] Next, the control unit 101 determines whether or not a program update is possible within the predicted stop duration from the current time, based on the stop duration prediction means of the behavior control management unit 117 acquired in step S53 and the update time information acquired in step S58 (step S59). If, in step S59, it is determined that a program update is possible within the predicted stop duration from the current time, the control unit 101 uses the acquired update program information to perform the corresponding program update (step S61 in Figure 9).
[0154] The control unit 101 then determines whether the program update is complete (step S62). If it determines that the program update is not complete, it determines whether the driver has requested to start driving (step S63). If it determines that the driver has requested to start driving, it displays the message "Driving is not possible due to program update, please wait." on the display screen of the display unit 111 and also notifies the driver by emitting an audible message from the speaker 136 (step S64). After step S64, the control unit 101 returns to step S62 and repeats the process from step S62 onward.
[0155] If the control unit 101 determines in step S63 that no driver has requested to start driving, it determines whether or not a call request has been received (step S65). If it determines that a call request has been received, it displays the message "Driving cannot be started in response to a call because the program is being updated. Please wait." on the display screen of the display unit 111 and also notifies the driver by emitting an audible message from the speaker 136 (step S66). After step S66, the control unit 101 returns to step S62 and repeats the process from step S62 onward. If the control unit 101 determines that no call request has been received, it returns to step S62 and repeats the process from step S62 onward.
[0156] Then, in step S62, when the control unit 101 determines that the program update is complete, it notifies the server 3 of the completion of the program update via the wireless communication unit 123 (step S67). The control unit 101 then queries the server 3 to see if there are any further incomplete update programs (step S68).
[0157] The control unit 101 obtains a response from the server 3 to the query in step S68 and determines whether there are any further incomplete updates (step S69). If the control unit 101 determines in step S69 that there are no further updates, it returns to step S51 in Figure 8 and repeats the process from step S51 onwards. If the control unit 101 determines in step S69 that there are further updates, it returns to step S57 in Figure 8 and repeats the process from step S57 onwards.
[0158] Furthermore, if in step S59 it is determined that a program update is not possible within the predicted stop duration from the current time, the control unit 101 stores the update program information acquired in step S24 (step S71 in Figure 10). Then, the control unit 101 determines whether or not the vehicle has come to a stop (step S72), and if it determines that the vehicle has come to a stop, it determines the update time from the update time information included in the stored update program information (step S73). Next, the control unit 101 acquires the stop duration information predicted by the behavior control management unit 117 and predicts the stop duration from the current time (step S74).
[0159] Then, the control unit 101 determines, based on the update time information and the predicted stop duration information from the current time, whether or not the program update is possible within the predicted stop duration from the current time (step S75). If, in step S75, it is determined that the program update is not possible within the predicted stop duration from the current time, the control unit 101 returns to step S72 and repeats the process from step S72 onward. If, in step S72, it is determined that the vehicle is not in a stopped state, the control unit 101 also returns to step S72 and repeats the process from step S72 onward.
[0160] Furthermore, if step S75 determines that a program update is possible within the predicted downtime from the current time, the control unit 101 uses the acquired update program information to perform the corresponding program update (step S76). Following step S76, the control unit 101 proceeds to step S62 in Figure 9 and repeats the process from step S62 onward.
[0161] In the second example, without distinguishing whether the program to be updated was a driving support program or a program for purposes other than driving, programs that could be updated were updated during the stop duration, and those whose update time exceeded the stop duration were executed during the later stop duration. However, in the second example as in the first example, it is also possible to determine whether the program to be updated is a driving support program or a program for purposes other than driving, and if it is a program for purposes other than driving, the update is executed until completion, even if the update time exceeds the stop duration.
[0162] [Example of processing operations when a user disembarks from the autonomous vehicle 1 of the embodiment] Next, we will describe the general operation of the control unit 101 of the autonomous vehicle 1 when a passenger, in this example, the driver, attempts to alight from the vehicle.
[0163] In this embodiment, when a passenger, in this example, the driver, attempts to alight from the autonomous vehicle 1, the autonomous vehicle 1 asks the driver whether to set a post-alight behavior. If the driver provides input for setting a post-alight behavior in response to this inquiry, the autonomous vehicle 1 accepts the post-alight behavior input from the driver and performs processing according to the accepted post-alight behavior after the driver alights. Then, the control unit 101 of the autonomous vehicle 1 performs the processing related to updating the program as described above.
[0164] Figure 11 shows an example of a situation where "move to a designated parking lot" is set as the post-alighting behavior. In the example in Figure 11, when driver 4 (user 4), who was riding in the autonomous vehicle 1, arrives at the entrance of the apartment building 5 where he lives, he sets the designated parking lot of the apartment building 5 as the designated parking lot and sets "move to a designated parking lot" as the post-alighting behavior, gets out of the autonomous vehicle 1 and returns home. The autonomous vehicle 1 accepts the post-alighting behavior setting by driver 4. After confirming that user 4 has gotten out, the autonomous vehicle 1 performs the action of moving to the designated parking lot 6 of the designated apartment building in autonomous driving mode and parking, as set post-alighting behavior. Once parking is complete, it stops the motor drive unit 131 and turns off the power to stop power supply to each part of the driving system, while maintaining power supply to necessary parts such as the control unit 101 and wireless communication unit 123.
[0165] The control unit 101 then queries the behavior control management unit 117 for the predicted duration of the stop. The behavior control management unit 117 then determines that the set post-disembarkation behavior is "movement to the default parking lot," and predicts the duration of the stop as, for example, 30 minutes, as described above, and returns this predicted duration of stop to the control unit 101. Since the obtained predicted duration of stop is 5 minutes or more, the control unit 101 sends a query to the server 3 for an update program. If an update program is available, it determines whether the update can be performed within the 30-minute stop duration by comparing the update time information with the predicted duration of stop. If the update is possible, it executes the program update.
[0166] If an update program is available, but the control unit 101 determines that the update time will be longer than the 30-minute downtime, the control unit 101 stores the update program information obtained from the server 3 and, during the subsequent downtime, executes a program update using the stored update program information.
[0167] Furthermore, if there are no updates available, the system remains in a stopped state without taking any action. When an update notification arrives from server 3 while the system is stopped, the control unit 101 obtains information about the update program, compares the update time information contained therein with the predicted stop duration information obtained from the behavior control management unit 117, and determines whether the update can be completed within the stop duration. Note that, at this time, since the control unit 101 obtains the predicted stop duration information from the behavior control management unit 117 immediately after stopping, the stop duration information to be compared with the update time information is the time from when the vehicle stopped until when the update notification from server 3 was received.
[0168] The control unit 101 then compares the update time information for the update program with the predicted downtime information and, if possible, executes the program update. If the update time is longer than the predicted downtime and the control unit 101 determines that the update will not be completed within the downtime, it stores the update program information obtained from the server 3 and, during the later downtime, executes the program update using the stored update program information.
[0169] Although not shown as an example in Figure 2, it is assumed that when driver 4 arrives at a hotel or other accommodation facility in the autonomous vehicle 1 for an overnight stay, the facility's designated parking lot is designated as the default parking lot, and "movement to the default parking lot" is set as the post-alighting behavior. In this case, the autonomous vehicle 1 accepts the post-alighting behavior setting by driver 4, and after confirming that driver 4 has alighted, it moves to the designated facility's designated parking lot in autonomous driving mode and parks. Once parking is complete, the motor drive unit 131 is stopped, and the power is turned off to stop power supply to each part of the driving system, while maintaining power supply to necessary parts such as the control unit 101 and wireless communication unit 123.
[0170] In the case of an overnight stay, it is generally predicted that the autonomous vehicle 1 will not be used until the following day. Therefore, the stop duration prediction means of the behavior control management unit 117 predicts the stop duration as the time from the start of stopping until the time the user re-boards the vehicle. In this case, the behavior control management unit 117 may obtain the time the driver will re-board the vehicle the following day by inquiring with the driver when setting the post-disembarkation behavior. Alternatively, the autonomous vehicle 1 may be equipped with a scheduling function, allowing the driver to set a schedule for using the vehicle, and the time the user will re-board the vehicle may be determined from the information in that schedule.
[0171] Furthermore, when the vehicle stops, the control unit 101 can determine whether the current location where the vehicle is stopped is a hotel or other accommodation facility, based on the surrounding area search function of the car navigation function unit 113 and the current location detection unit 110.
[0172] Even in the case of leisure facilities such as theme parks, amusement parks, and zoos, or commercial facilities such as shopping centers and department stores, rather than accommodation facilities, the control unit 101 can perform similar operations when the user 4 of the autonomous vehicle 1 designates the facility's designated parking area as the default parking area.
[0173] Next, Figure 12 shows an example of a situation where "return to the disembarking position after a predetermined time" is set as the disembarking behavior. The example in Figure 12 is a situation where the driver 4 of the autonomous vehicle 1 feels the urge to urinate or defecate and stops at a toilet in a park or similar location. In this case, when disembarking, the driver 4 sets the disembarking behavior by voice inputting, for example, "toilet" into the microphone 137, and then disembarks from the autonomous vehicle 1. The control unit 101 of the autonomous vehicle 1 then recognizes the voice input "toilet" from the driver 4, predicts and estimates a predetermined time, i.e., the expected duration of the stop, to be 5 minutes in this example, and waits at that location. The control unit 101 of the autonomous vehicle 1 can then perform the processing operations related to the update program described above during the predicted duration of the stop.
[0174] If the driver feels the urge to defecate rather than urinate, they may use voice input such as "stomach ache" or "private room" to estimate a longer time, for example, 10 minutes. Also, if driver 4 is female, the estimated time may be longer than if the driver is male.
[0175] Furthermore, the example in Figure 13 shows a case where driver 4 of autonomous vehicle 1 travels to, for example, the Ryogoku Kokugikan (sumo arena) in autonomous vehicle 1 to watch sumo wrestling. When driver 4 gets out of the vehicle, he voice-inputs "watching sumo wrestling" into microphone 137 to set the behavior after getting out of the vehicle, and then gets out of autonomous vehicle 1. The control unit 101 of autonomous vehicle 1 then determines that the sumo tournament will end at 6 p.m., predicts and estimates a predetermined time from the current time, i.e., the duration of stopping, and controls the vehicle to move to, for example, the parking lot of the Kokugikan or an empty parking lot nearby and stop, and to continue stopping and waiting, and at 6 p.m., to move to the entrance of the Kokugikan to pick up driver 4. In this case as well, the control unit 101 of autonomous vehicle 1 can perform the processing operations related to the update program described above during the predicted duration of stopping.
[0176] As explained above, in the autonomous vehicle 1 of the first embodiment described above, updates to the program that supports the autonomous driving of the vehicle are performed only when the vehicle is stopped, thereby ensuring safety by preventing the program from being updated while the vehicle is in motion. However, if the autonomous vehicle's program is configured to be updated whenever the vehicle is stopped, there is a problem in that the user's use of the autonomous vehicle will be restricted until the update is completed.
[0177] In this first embodiment of the autonomous vehicle 1, when a user stops the autonomous vehicle and gets out, the system is configured to ask the user about the behavior of the autonomous vehicle 1 after the user gets out and to allow the user to set it. Therefore, in this first embodiment of the autonomous vehicle 1, it is possible to predict the duration of the vehicle's stop based on the set behavior after the user gets out. Furthermore, in this first embodiment of the autonomous vehicle 1, even if the vehicle is stopped, the system is only executed when it is determined that the predicted duration of the stop is longer than the program update time.
[0178] Therefore, according to the autonomous vehicle 1 of this first embodiment, the program that supports autonomous driving will not be updated unnecessarily while the vehicle is stopped, and the program that supports autonomous driving will be updated at an appropriate time while prioritizing the user's convenience. This has the remarkable effect of updating the program that supports autonomous driving at the appropriate time.
[0179] [Second Embodiment] In the first embodiment of the autonomous vehicle 1 described above, the stopping duration is predicted based on the post-disembarkation behavior set by the user of the autonomous vehicle 1. However, the stopping duration is not predicted solely based on the post-disembarkation behavior set by the user. In the second embodiment of the autonomous vehicle 1A, the stopping duration is predicted based on the past driving history and stopping history of the autonomous vehicle 1.
[0180] Figure 14 is a block diagram showing an example configuration of the electronic control circuit unit 10A of the autonomous vehicle 1A of this second embodiment. In Figure 14, the same reference numerals are used for parts that are the same as those in the electronic control circuit unit 10 of the autonomous vehicle 1 of the first embodiment shown in Figure 1, and their detailed descriptions are omitted.
[0181] As shown in Figure 14, in the electronic control circuit unit 10A of the autonomous vehicle 1A of this second embodiment, the post-disembarkation behavior setting reception unit 116 found in the electronic control circuit unit 10 of the autonomous vehicle 1 of the first embodiment is not provided. Instead, a usage navigation function unit 141, a history memory 142, and a history analysis unit 143 are provided. Furthermore, the electronic control circuit unit 10A of the autonomous vehicle 1A of this second embodiment includes a behavior control management unit 117A and a program update management control unit 119A, which have slightly different configurations from those of the first embodiment.
[0182] Furthermore, the behavior control management unit 117A of the autonomous vehicle 1A in this embodiment includes a vehicle state determination means and a stop duration prediction means, similar to the behavior control management unit 117 in the first embodiment. However, the stop duration prediction means predicts the stop duration based on the results of analyzing the history information in the history memory 142 by the history analysis unit 143.
[0183] In this second embodiment, since the post-disembarkation behavior setting reception unit 116 is not provided, the behavior control management unit 117A does not have a storage unit 117M for storing the set post-disembarkation behavior. However, in this second embodiment as well, the post-disembarkation behavior setting reception unit 116 may be provided, as in the first embodiment. In that case, the behavior control management unit 117A will have a storage unit for the set post-disembarkation behavior, as in the first embodiment, and will also have a function to execute the post-disembarkation behavior set by the user.
[0184] The program update management control unit 119A of the autonomous vehicle 1A in this embodiment includes a storage unit 119MA that stores information on update programs, and manages and controls the information on update programs in the same manner as the program update management control unit 119 of the first embodiment. However, in this second embodiment, the program update management control unit 119A checks the usage of the vehicle while it is in use and uses the predicted duration of stoppage based on past history.
[0185] In the following description, the non-driving function unit 118 is provided with AV entertainment functions, game functions, massage mechanism drive units, and the like for non-driving uses in this second embodiment.
[0186] The AV entertainment function unit, game function unit, and massage mechanism drive unit are examples of function units that provide uses other than driving. These uses are not limited to those mentioned above and include quiet rest such as sleeping, enjoying food and drink, singing karaoke, reading, concentrating on work or studying, and applying makeup.
[0187] For quiet resting purposes such as sleeping, autonomous vehicle 1A will have a car air conditioner that maintains a comfortable temperature inside the vehicle at 20-23 degrees Celsius in winter and 25-28 degrees Celsius in summer. It will also have a function to block out sunlight and other external light by lowering the window curtains or switching the windows to a blackout mode, and to turn off or dim the interior lights to ensure conditions suitable for restful sleep. Furthermore, the seats will be able to recline or flatten to suit restful sleep.
[0188] Furthermore, for use in enjoying food and drinks, autonomous vehicle 1A will be equipped with a table inside the vehicle, and if a refrigerator is available, the passenger will be able to select drinks and food from the refrigerator. The lighting will also be set to the passenger's preferred brightness suitable for eating and drinking. When selecting drinks, it will also be possible to select alcoholic beverages, but the selection of alcoholic beverages will be limited to cases where the vehicle is used for purposes other than driving, or when driving is also in an autonomous driving mode.
[0189] For reading purposes, the autonomous vehicle 1A is configured to allow the user to select an ebook (electronic book) (it may also access an internet ebook provider server via the wireless communication unit 123 to obtain the ebook), and to display the content of the selected ebook on the display screen of the display unit 111, and to read it aloud through the speaker 136 as needed.
[0190] For use in work or study, the autonomous vehicle 1 is configured to block out the outside view by lowering the window curtains or switching the windows to blackout mode, and to brighten the interior lighting, ensuring an environment conducive to concentration. It is also configured to display necessary materials for work or study on a computer (not shown).
[0191] The AV entertainment function unit is a function unit that plays audio information, music information, and / or image information, and includes, for example, a television broadcast reception function unit, an AM and FM radio broadcast reception function unit, and a disc playback function unit for CDs, DVDs, BDs (Blu-ray discs), etc. Although not shown in the diagram, the AV entertainment function unit includes an antenna for receiving television broadcasts, an antenna for receiving AM and FM radio broadcasts, and a multi-disc drive for the disc playback function unit.
[0192] Audio and music information played back by the AV entertainment function unit is emitted through the speaker 136, and image information played back by the AV entertainment function unit is displayed on the display screen of the display unit 111 for use by passengers.
[0193] The game function unit is a unit that provides functions for playing various games, such as action games, simulation games, shooting games, role-playing games, and competitive games. The game function unit is equipped with one or more game controllers (not shown), and users operate the games using these controllers. Game audio and music information is emitted through speaker 136, and game image information is displayed on the display screen of display unit 111 for the use of passengers. Furthermore, online games can also be enjoyed via the internet.
[0194] The massage mechanism drive unit drives a massage mechanism incorporated into, for example, the driver's seat or passenger seat. The massage mechanism is a mechanism that provides a massage effect to the occupant seated in the seat in which it is incorporated. Of course, the mechanism may be movable so that the seat can be adjusted to suit the massage, for example, by reclining or becoming flat. The massage mechanism drive unit may also incorporate a mechanism for rotating the seat. In this case, the massage mechanism drive unit can be used not only for massage purposes, but also to rotate the seat to allow multiple occupants to face each other when eating or drinking, or to allow players to face each other in competitive games. Furthermore, the seat can be rotated to the user's preferred orientation for reading, concentrating on work or studying, etc.
[0195] Furthermore, the AV entertainment function unit, game function unit, and massage mechanism drive unit that constitute the non-driving function unit 118 are not only usable when the autonomous vehicle 1 is stopped and the driving drive system, including the motor drive unit 131, is not activated, but can also be used when the autonomous vehicle 1 is in motion, upon instruction from the passenger to start using them.
[0196] The power supply from battery 11 is configured to independently supply power to each of the AV entertainment function units, including the television broadcasting reception unit, the AM and FM radio broadcasting reception unit, and the CD, DVD, and BD disc playback unit, as well as to the game function unit and the massage mechanism drive unit. Of course, the power supply to the driving system and the power supply to the AV entertainment function unit, game function unit, and massage mechanism drive unit can also be supplied independently.
[0197] The application navigation function unit 141 is activated by the control unit 101 when the door opening and closing is detected by the door sensor of the sensor group 108, and when the presence of a passenger is detected by the camera of the camera group 107. When the application navigation function unit 141 detects a passenger's presence, before activating the autonomous vehicle 1, it asks the passenger about the intended use of the autonomous vehicle 1, and confirms the intended use after receiving a response from the passenger.
[0198] In this case, "when a passenger is detected to be in the vehicle" means when a passenger is detected to be in the vehicle while the vehicle is not running, and basically assumes the first passenger to enter the vehicle when there are no passengers in the vehicle. In this case, the first passenger can be one person or multiple people, and if there are multiple people, a representative will answer the question regarding the purpose of use.
[0199] Furthermore, if the vehicle is not started, it is acceptable even if there are already passengers. In that case, an inquiry will be made to the new passenger, and if a response regarding the new purpose of use is received, the newly set purpose of use will be executed. If the purpose of use has already been set by a passenger already in the vehicle and the purpose of use is not to be changed, the system may respond with something like "Execute the previous purpose of use (without setting a new purpose of use)" to allow the previous purpose of use to continue to be used.
[0200] In this embodiment, two types of usage are defined as examples of intended use: driving and non-driving uses.
[0201] Furthermore, in the case of use for driving, this embodiment defines two types: "use with a specific destination determined (known destination use)" and "use with an undetermined destination." The use navigation function unit 141 asks the passenger which of these to select, and also asks whether to use the selected driving use in automatic driving mode or manual driving mode. In addition, if there are two types of automatic driving modes, such as a normal automatic driving mode that can be switched to manual driving mode based on a predetermined action by the driver, and a forced automatic driving mode that cannot be switched to manual driving mode even if a predetermined action is performed by the driver, the system may also ask whether to use the normal automatic driving mode or the forced automatic driving mode.
[0202] In the case of fully autonomous vehicles that do not require any manual operation by the driver, i.e., vehicles without a manual driving mode, the selected driving purpose will be used in autonomous driving mode. Using this autonomous driving mode is the same as using it in forced autonomous driving mode, in the sense that it cannot be switched to manual driving mode.
[0203] When a known destination is selected, the usage navigation function unit 141 accepts destination settings from the passenger.
[0204] Furthermore, when an unspecified destination is selected, the usage navigation function unit 141, in this embodiment, will ask the passenger whether to "select a destination attribute" such as "mountain," "river," "sea," "lake," or "amusement park," or to "specify only the usage time." When "select a destination attribute" is selected, the usage navigation function unit 141 will present a list of destination attributes to the passenger and accept their selection from the list. The destination attribute may also be specified by the passenger directly by inputting it as a free keyword. In addition, even when a known destination is selected, the passenger can also "select a waypoint attribute" such as "mountain," "river," "sea," "lake," or "amusement park" as a waypoint to the destination.
[0205] Furthermore, when "Specify only the driving time to be used" is selected, the navigation function unit 141 will allow the passenger to specify the driving time to be used and accept the request. Alternatively, instead of specifying the driving time, the end time of the driving from the current time may be set.
[0206] If the passenger specifies an use other than driving, the Navigation Function Unit 141, in this embodiment, presents the passenger with various AV-related functions, game-related functions, and massage functions that can be provided by the AV Entertainment Function Unit (as described later), asks for their use, and accepts their selection as a response.
[0207] The application navigation function unit 141 then prompts the passenger to input a startup command after the passenger has selected and confirmed the intended use. Once the control unit 101 confirms the passenger's input of the startup command, it controls the power supply from the battery 11 and the electronic control circuit unit 10 of the autonomous vehicle 1 to execute the intended use confirmed by the application navigation function unit 141. The details of the processing flow in the application navigation function unit 141 will be described in detail later.
[0208] The history memory 142 stores information on the past usage of the autonomous vehicle 1 by users (passengers) whose identification images (e.g., facial images) are stored and registered in the user image information storage unit 134, and this information is associated with the user ID.
[0209] Figure 15 shows an example of the information stored in this history memory 142. As shown in Figure 15, for pre-registered users, the user name and usage history information are stored, associated with their user ID. In this embodiment, the usage history information consists of the date and day of the week of use, and items such as the type of use, content of use, details of use, and usage time, as described above.
[0210] The usage history is stored in the history memory 142 with either the aforementioned driving usage or non-driving usage. In this case, if the usage type is driving usage, the information is stored according to whether the driving was in automatic driving mode or manual driving mode. In the example in Figure 15, "Driving: Automatic" indicates driving in automatic driving mode, and "Driving: Manual" indicates driving in manual driving mode. In this example, whether the driving is in automatic driving mode or manual driving mode is determined by the driving mode at the start of the drive. Of course, if the driving mode is switched during the trip, that switch may also be recorded in the history.
[0211] In this embodiment, when the usage type is for driving, the usage details will store either "a usage with a specific destination (known destination)" or "a usage with an undecided destination (undecided destination)". If the usage details are for a usage with a known destination, the usage details will store the departure point (current location) and destination, for example, "Home - XX Station", as shown in Figure 15. The departure point (current location) is recorded as the current location at the start of driving, as detected by the current location detection unit 110. If the usage details are for a usage with an undecided destination, the usage details will store, for example, the usage time, such as "return in 30 minutes", the usage end time, such as "return by 3pm", and attributes of the destination, such as "to the nearby sea", as shown in Figure 15.
[0212] Furthermore, if the usage type is for purposes other than driving, the usage details will store either "AV / Game related," which uses the AV entertainment function unit or game function unit included in the non-driving function unit 118, or "Massage and others," which is a massage application using the massage mechanism drive unit, or other applications. If the usage details are "AV / Game related," the usage details will store, as shown in Figure 15, either an AV entertainment function of the AV entertainment function unit or a game function of the game function unit, such as "Music playback" or "Game." If the usage details are "Massage and others," the usage details will store, as shown in Figure 15, either "Massage" or "Other."
[0213] Furthermore, the history memory 142 may also store information for each of the above items as "other users" history information, without distinguishing between individual passengers, even for passengers who have not been assigned a user ID.
[0214] The information stored in the history memory 142 may be partially or completely deleted by the user or passenger. However, security should be ensured using the user's or passenger's biometric information, ID, password, etc., so that information other than that of the user or passenger cannot be deleted.
[0215] The history analysis unit 143 analyzes the history information for each user (for each user ID) stored in the history memory 142 and detects any habitually used purposes (hereinafter referred to as habitual uses). In addition, the history analysis unit 143 analyzes not only the uses of a single user, but also the uses of multiple users with similar usage patterns, and uses that are common to all users. Furthermore, it may also detect the frequency of use. In this case, habitual uses may be notified by prioritizing inquiries. In addition, uses with higher usage frequency may be given higher priority in the display order. In this embodiment, habitual uses are those found in the "Usage Details" item of the information stored in the history memory 142.
[0216] In this embodiment, the history analysis unit 143 detects, for each user or for multiple users, uses (use details) that are habitually and repeatedly used on specific days of the week or at specific times of the day (use details) as habitual uses. The detection of habitual uses is not limited to this; for example, uses (use details) that are habitually and repeatedly used during specific periods of the year such as New Year's Day, Lunar New Year (Spring Festival), Easter, and Obon, or on specific dates in specific months of the year such as birthdays, Valentine's Day, Halloween, Christmas Eve, Christmas, company anniversary, and death anniversary, may also be detected as habitual uses. Alternatively, uses (use details) that are used periodically every day or every few days may also be detected as habitual uses. Of course, uses (use details) that are habitually and repeatedly used on specific days each month, such as eating at a specific restaurant on payday in the case of a monthly salary, may also be detected as habitual uses.
[0217] In this embodiment, the history analysis unit 143 can determine the duration of the stoppage in each user's history, from the end time of the driving usage period to the start time of the next driving usage period. Therefore, it is possible to determine the duration of the stoppage habitually, corresponding to the day of the week and time of day, from each user's history. As a result, when a program update request occurs, it is possible to determine the day of the week and time of day at the time the request occurs from the history information in the history memory 142 and predict the duration of the stoppage.
[0218] Furthermore, users may be allowed to provide feedback on how they used the service, and in the future, the service may be prioritized to show users the most highly-rated uses.
[0219] In the configuration shown in Figure 14, the caller authentication unit 115 in the first embodiment is omitted, but it may also be included in the autonomous vehicle 1A of this second embodiment.
[0220] As described above, the electronic control circuit unit 10A of the autonomous vehicle 1A is configured as follows, but of the blocks shown in Figure 14, the motor drive control unit 102, steering drive control unit 103, manual / autonomous driving mode switching control unit 104, surrounding moving object detection unit 109, current position detection unit 110, car navigation function unit 113, user authentication unit 114, behavior control management unit 117A, non-driving function unit 118 (AV entertainment function unit, game function unit, massage mechanism drive unit), program update management control unit 119A, battery level detection unit 123, application navigation function unit 141, and history analysis unit 143 can be implemented by the control unit 101A as software processing according to their respective programs.
[0221] [Example of processing flow by the application navigation function unit 141 and the program update management control unit 119] Next, an example of the processing flow by the navigation function unit 141 when a passenger is in the autonomous vehicle 1 will be explained with reference to the flowcharts in Figures 16 to 26 and the display examples on the display screen of the display unit 111 in Figures 28 and 29. In the following explanation, it will be assumed that the control unit 101A implements the functions of each of the above-mentioned parts as software processing according to their respective programs.
[0222] In the electronic control circuit unit 10A of the autonomous vehicle 1A, even before activation, the control unit 101A and the sensor group 108 are in a standby state with power supply voltage supplied from the battery 11. In this standby state, the control unit 101A monitors passengers boarding the vehicle (step S201 in Figure 16).
[0223] Then, in step S201, when it is determined that a passenger has boarded the vehicle, the control unit 101A supplies power voltage to at least one of the camera group, which is a camera inside the vehicle, and captures an image of the passenger's face with that camera. The image recognition function of the user authentication unit 114 determines whether or not the passenger is a registered user whose face image is stored in the memory unit 114M (step S202).
[0224] In step S202, if the control unit 101A determines that the passenger is a registered user, it obtains the passenger's user ID and refers to the history information stored in the history memory 142 associated with that user ID (step S203). Then, the control unit 101A obtains the current year, month, day, and day of the week information from the clock unit 121 and uses the functions of the history analysis unit 143 to analyze whether there are any habitual usage purposes related to the passenger at that time (step S204).
[0225] Then, based on the results of the analysis in step S204, the control unit 101A determines whether or not the passenger has a habitual use of the vehicle (step S205). If it determines that a habitual use of the vehicle exists, it asks the passenger whether or not to perform that habitual use by displaying an inquiry message on the display screen of the display unit 111 and by broadcasting an audio message through the speaker 136 (step S206).
[0226] For example, if the current time is 7:00 a.m. on a weekday, and the passenger always drives the autonomous vehicle 1 from their home to the parking lot of the nearest station for their commute, the control unit 101A will determine that this is a habitual use and, as shown in Figure 28(A), will display an inquiry message on the display screen 111D of the display unit 111, saying, "At this time, you always drive autonomously to XX station. Do you want to do it again today?" and will also emit an audible message through the speaker 136 to execute the inquiry.
[0227] Furthermore, for example, if the current time is 3:00 PM on a Saturday, and the passenger is always receiving a massage for purposes other than driving, the control unit 101A will determine that this is a habitual use and, as shown in Figure 28(B), will display an inquiry message, "You always use the massage at this time, will you use it again today?", along with the time of use, on the display screen 111D of the display unit 111, and will also emit an audible message through the speaker 136 to execute the inquiry.
[0228] At this time, as shown in Figures 28(A) and 28(B), the control unit 101A displays both "Execute" and "Do not execute" options on the display screen. The passenger can select one of these options on the display screen, or they can provide their selection via voice input. As shown in Figure 28(B), the usage time for non-driving purposes such as massage is displayed in association with "Execute".
[0229] When a passenger responds, that response information is transmitted to the control unit 101A via the touch panel 112. Alternatively, the passenger may respond verbally, and the response may be captured by the microphone 137 so that the control unit 101A can perform voice recognition.
[0230] Therefore, the control unit 101A determines whether the passenger's response information is "execute" (step S207), and if it determines that it is "execute", it performs the passenger's habitual usage purpose determined in step S205 (step S208).
[0231] In other words, if the habitual use is driving as shown in the example in Figure 25(A), the control unit 101A supplies power voltage from the battery 11 to the drive system and other components necessary for driving the vehicle, starts them up, and controls them to drive in manual or automatic driving mode. If the habitual use is for purposes other than driving as shown in the example in Figure 25(B), the control unit 101A supplies power voltage from the battery 11 to the AV entertainment function unit, game function unit, or massage mechanism drive unit of the non-driving function unit 118, which provides the non-driving function for that habitual use, starts them up, and controls them to execute the non-driving function. The history of the executed uses is associated with the passenger's user ID, and the contents as shown in Figure 15 above are stored in the history memory 142.
[0232] Furthermore, habitual usage purposes are considered personal information of the user, and if there are passengers, they may not want this information to be known. Therefore, it may be advisable to determine whether there are passengers and, if so, to ask the user in advance if it is okay to proceed with the inquiry.
[0233] Following step S208, the control unit 101A determines whether the intended use is for driving an automobile. If it determines that the intended use is for driving an automobile, it proceeds to step S214 in Figure 17, which will be described later. If, in step S209, it determines that the intended use is not for driving the vehicle, the control unit 101A proceeds to step S271 in Figure 22, which will be described later, and executes the processing from step S271 onward. The processing from step S214 onward and the processing from step S271 onward will be described later.
[0234] Furthermore, if in step S202 it is determined that the passenger is not a registered user, if in step S205 it is determined that the passenger does not have a habitual use of the vehicle, and if in step S207 the passenger replies that they will not perform any habitual use of the vehicle, the control unit 101A will inquire about the vehicle's intended use by displaying an inquiry message on the display screen of the display unit 111 and by broadcasting an audio message through the speaker 136 (step S211 in Figure 17).
[0235] In step S211, the type of use is indicated as follows: "1. Driving" for driving purposes and "2. Other than driving" for purposes other than driving. These are displayed on the display screen 111D of the display unit 111, for example, as shown in Figure 29(A), and are also presented audibly through the speaker 136 to the passenger for confirmation.
[0236] In response to this inquiry, the passenger can either select one of the options on the display screen or provide their answer via voice input. Once the passenger has given their answer, the answer information is transmitted to the control unit 101A via the touch panel 112, or it is picked up by the microphone 37 and transmitted to the control unit 101A as voice information. The voice information is then recognized by the voice recognition function of the control unit 101A.
[0237] Following step S211, in step S212, the control unit 101A determines whether or not the purpose is for driving an automobile based on the passenger's response information. If it is determined in step S212 that the purpose is for driving an automobile, in step S213, it accepts the destination setting input and executes the automobile driving operation based on that response information.
[0238] Following step S213, the control unit 101A monitors whether or not it has received a program update notification from the server 3 (step S214). If it determines in step S214 that it has received a program update notification, the control unit 101A returns a response to the update notification to the server 3 (step S215). The server 3 then downloads information about the update program, including the type of update program and the update time, and the control unit 101A receives and acquires this update program information via the wireless communication unit 123 (step S216).
[0239] Next, the control unit 101A determines whether the update program is a driving support program (step S217). If it determines that it is a driving support program, it does not update the program because the vehicle is currently in motion, and instead stores the information of the update program downloaded from the server 3 (step S218). Then, the control unit 101A returns to step S214 and repeats the process from step S214 onward.
[0240] Furthermore, if in step S217 the control unit 101A determines that the update program is for purposes other than driving, it performs a program update using the update program information obtained in step S216 (step S221 in Figure 18), monitors the completion of the program update (step S222), and, upon confirming the completion of the program update, notifies the server 3 of the completion of the updated program via the wireless communication unit 123 (step S223).
[0241] Next, the control unit 101A determines whether or not the vehicle has arrived at the destination set for automobile driving (step S224). If it determines that the vehicle has not yet arrived, it returns to step S214 in Figure 17 and repeats the process from step S214 onward.
[0242] If, in step S214, the control unit 101A determines that it has not received a program update notification from server 3, it proceeds to step S224 in Figure 18 to determine whether or not the destination has been reached. If, in step S224, it determines that the destination has been reached, the control unit 101A terminates the configured driving operation and puts the vehicle into a stopped state (step S225).
[0243] Next, the control unit 101A determines whether or not there is stored information about an update program (step S231 in Figure 19). If it determines in step S231 that there is no stored information about an update program, it terminates this processing routine.
[0244] Furthermore, if step S231 determines that there is information about a stored update program, the control unit 101A reads the information about the first update program, for example, in chronological order of storage, if there is information about multiple update programs, and determines whether or not the update program is a driving support program (step S232).
[0245] In step S232, when it is determined that the update program is for driving purposes, the update time is determined from the update time information of the stored update program information (step S233), and the predicted stop duration is obtained by querying the behavior control management unit 117A (step S234).
[0246] In this case, the behavior control management unit 117A monitors inputs from the driver or passengers of the autonomous vehicle 1A via the touch panel 112 in response to inquiries from the usage navigation function unit 141, as well as further inputs regarding usage via voice input through the microphone 137, and predicts the duration of the stop based on the results of monitoring these inputs. For example, if a user such as the driver or passenger gets out of the vehicle without setting a usage purpose, the duration of the stop is predicted to be at least 30 minutes.
[0247] Furthermore, the behavior control management unit 117A estimates the purpose of use based on the analysis results of the usage history of the history memory 142 by the history analysis unit 143, as well as the current date, day of the week, and time, and predicts the duration of the shutdown based on that estimation.
[0248] Then, the control unit 101A refers to the update time determined in step S233 and determines whether the program update is possible within the predicted downtime (step S235). If it determines that the program update is possible, it executes the program update using the stored update program information (step S236). Then, the control unit 101A monitors for the completion of the update (step S237), and once it confirms the completion of the update in step S237, it notifies the server 3 of the completion of the update via the wireless communication unit 123 (step S238).
[0249] Then, the control unit 101A determines whether or not there are still stored update programs remaining (step S239). If it determines that there are no stored update programs remaining, it terminates this processing routine. If, in step S239, it determines that there are still stored update programs remaining, the control unit 101A returns to step S232 and repeats the processing from step S232 onward.
[0250] If the control unit 101A determines in step S235 that the program cannot be updated, it terminates this processing routine.
[0251] If, in step S232, the control unit 101A determines that the update program is not for driving purposes, it proceeds to step S236 to update the program using the stored update program information, and then executes the processes from step S237 onward.
[0252] Next, in step S212 of Figure 17, if it is determined that the purpose is not for driving, the control unit 101A detects the remaining charge of the battery 11 (step S241 of Figure 20), and then the control unit 101A uses the determination result from step S102 to determine whether or not the passenger is a registered user (step S242).
[0253] In step S242, if the control unit 101A determines that the passenger is a registered user, it presents non-driving uses that can be provided with the remaining battery charge detected in step S241, in order of priority based on the passenger's usage history (step S243). For example, non-driving uses that the passenger has used more frequently in the past are presented with a higher priority.
[0254] An example of the display for uses other than driving in this case is shown in FIG. 29(B). That is, when a passenger selects a use other than driving, the display screen 111D of the display unit 111 changes from the usage inquiry screen of FIG. 29(A) to the list screen of uses other than driving shown in FIG. 29(B). Note that the content of this list of uses other than driving may also be presented to the passenger by voice through the speaker 136.
[0255] Next, the control unit 101A determines whether or not a selection of a use other than driving has been received (step S244). When it is determined that a selection of a use other than driving has not been received, the control unit 101A determines whether or not an instruction to stop using, based on an operation of the button icon 210 (see FIG. 29(B)) on the display screen 111D through the touch panel 112, or an instruction to stop using the self-driving vehicle 1 by voice picked up through the microphone 137, has been received (step S245).
[0256] Then, when the control unit 101A determines in this step S245 that an instruction to stop using has been received, this processing routine is terminated. Also, when it is determined in step S245 that an instruction to stop using has not been received, the control unit 101A determines whether or not a retry instruction based on an operation of the button icon 211 (see FIG. 29(B)) on the display screen 111D through the touch panel 112, or a retry instruction by voice picked up through the microphone 137, has been received (step S246).
[0257] Then, when it is determined in step S246 that a retry instruction has not been received, the control unit 101A returns the process to step S244 and repeats the processing after this step S244. Also, when it is determined in step S246 that a retry instruction has been received, the control unit 101A returns the process to step S211 in FIG. 17 and performs the processing after this step S211.
[0258] Next, when it is determined in step S244 that a selection for a non-driving use has been received, the control unit 101A displays a list of usage items for the selected non-driving use on the display screen 111D in the order based on the usage history of the passenger, and notifies the passenger by voice through the speaker 136 (step S247). That is, among the past usage purposes of the passenger, the usage items for non-driving uses with more usage opportunities are presented with higher priorities.
[0259] An example of the display on the display screen 111D at this time is shown in FIGS. 29(C) and 29(D). That is, FIG. 29(C) is a list of the usage items when an AV / game-related function is selected as the non-driving use, and FIG. 29(D) is a list of the usage items when massage or the like is selected as the non-driving use. In this case, as shown in FIGS. 29(C) and 29(D), on the display screen 111D, for each non-driving use, information on the available time with the remaining battery level detected in step S241 is also displayed.
[0260] As shown in FIG. 29(D), in this example, for the massage function, the user can select a course from a plurality of courses with fixed treatment times, for example, a short course with a treatment time of 10 minutes, a normal course with a treatment time of 30 minutes, and a detailed course with a treatment time of 60 minutes.
[0261] Next, the control unit 101A waits for a usage item to be selected (step S248), and when it is determined that a usage item has been selected, determines whether an activation instruction (execution instruction and usage time instruction) based on an operation of the button icon 212 (see FIG. 29(C)) or the button icon 213 (see FIG. 29(D)) on the display screen 111D through the touch panel 112, or an activation instruction (execution instruction and usage time instruction) by voice picked up through the microphone 137 has been received (step S249).
[0262] Then, in step S249, when it is determined that a start instruction (execution instruction and usage time instruction) has been received, the control unit 101A executes the selected usage item for purposes other than driving (step S250). The history of the executed usage items is associated with the passenger's user ID and stored in the history memory 142 with the contents shown in Figure 15 above.
[0263] Furthermore, if step S242 determines that the passenger is not a registered user, the control unit 101A presents non-driving uses that can be provided with the remaining battery capacity 11 detected in step S241 (step S261 in Figure 21). In this case, since the passenger has no past usage history, non-driving uses are presented in an arbitrary order of priority (see, for example, Figure 29(B)).
[0264] Next, the control unit 101A determines whether or not it has accepted the selection of an application other than driving (step S262). If it determines that it has not accepted the selection of an application other than driving, it determines whether or not it has received a command to discontinue use based on the operation of the button icon 210 on the display screen 111D (see Figure 29(B)) via the touch panel 112, or a command to discontinue use of the autonomous vehicle 1 via voice picked up through the microphone 137 (step S263).
[0265] Then, in step S263, if the control unit 101A determines that it has received a command to discontinue use, it terminates this processing routine. If, in step S263, it determines that it has not received a command to discontinue use, the control unit 101A determines whether it has received a redo command based on the operation of the button icon 211 on the display screen 111D (see Figure 29(B)) via the touch panel 112, or a redo command via voice picked up via the microphone 137 (step S264). If, in step S264, it determines that it has not received a redo command, it returns to step S262 and repeats the processing from step S262 onward. If, in step S264, it determines that it has received a redo command, the control unit 101A returns to step S211 in Figure 17 and performs the processing from step S211 onward.
[0266] Next, in step S262, when it is determined that a selection for a use other than driving has been received, the control unit 101A displays a list of the selected non-driving use items on the display screen 111D in any order, for example, in the default order, and also notifies the user by voice through the speaker 136 (step S265).
[0267] The display example of the 111D screen at this time will be as shown in Figures 29(C) and 29(D).
[0268] Next, the control unit 101A waits for an item to be selected (step S266), and when it determines that an item has been selected, it determines whether it has received an activation instruction (execution instruction and usage time instruction) based on the operation of button icon 212 (see Figure 15(C)) or button icon 213 (see Figure 15(D)) on the display screen 111D via the touch panel 112, or an activation instruction (execution instruction and usage time instruction) via voice picked up through the microphone 137 (step S267).
[0269] Then, in step S267, when it is determined that a start instruction (execution instruction) has been received, the control unit 101 executes the selected usage item for purposes other than driving (step S268).
[0270] Then, following step S250 in Figure 20, and following step S268 in Figure 21, the control unit 101A monitors whether or not it has received a program update notification from the server 3 (step S271 in Figure 22). If it determines in step S271 that it has received a program update notification, the control unit 101A returns a response to the update notification to the server 3 (step S272). The server 3 then downloads information about the update program, including the type of update program and the update time, and the control unit 101A receives and acquires this update program information via the wireless communication unit 123 (step S273).
[0271] Next, the control unit 101A determines whether the update program is a driving support program or not (step S274). If, in step S274, it determines that the update program is not for driving support but for purposes other than driving, the control unit 101A determines whether the update program is for a program that is currently running (step S275). If it determines that it is for a program that is currently running, it does not update the program because it is currently running, and instead stores the information of the update program downloaded from the server 3 (step S276).
[0272] Next, the control unit 101A determines whether the use of the vehicle for purposes other than driving has ended (step S277). If it determines in step S277 that the use of the vehicle for purposes other than driving has not ended, the control unit 101A returns to step S271 and repeats the process from step S271 onward.
[0273] Furthermore, if step S277 determines that use for purposes other than driving has ended, the control unit 101A performs the process for ending use for purposes other than driving, and then updates the running program using the update program information of the running program that was stored in memory without being updated in step S276 (step S278). After the update is completed, the control unit 101A notifies the server 3 of the completion of the update via the wireless communication unit 123 (step S279).
[0274] Following step S279, the control unit 101A proceeds to step S231 in Figure 19, and further determines whether there is any other stored update program information, and then performs the processing from step S231 onward according to the determination result.
[0275] Then, in step S275, if the control unit 101A determines that the update program information received from server 3 is not for the currently running program but for updating a program for purposes other than driving, it uses the update program information obtained in step S273 to update that program (step S281 in Figure 23). Then, the control unit 101A determines whether or not the program update is complete (step S282), and if it determines that the update is not complete, it determines whether or not the use of the program for purposes other than driving has ended (step S283).
[0276] If, in step S283, it is determined that the vehicle is not yet being used for purposes other than driving, the control unit 101A returns to step S282 and repeats the process from step S282 onward.
[0277] Also, in step S283, when it is determined that the use of a non-driving application during execution has ended, the control unit 101A performs the use-end process for the non-driving application and notifies the user that the program is still being updated (step S284). Then, the control unit 101A waits for the update to complete (step S285). Once it confirms the update completion, it notifies the server 3 via the wireless communication unit 123 that the program has been updated, including the identification information of the updated program (step S286). Next, the control unit 101A proceeds to step S231 in FIG. 19, and further determines whether there is information on other update programs stored, and performs the processes after step S231 according to the determination result.
[0278] Also, in step S282, when it is determined that the update has completed, the control unit 101A notifies the server 3 via the wireless communication unit 123 that the program has been updated, including the identification information of the updated program (step S287). Then, the control unit 101A determines whether the use of a non-driving application during execution has ended (step S288).
[0279] In this step S288, when it is determined that the use of a non-driving application during execution has not ended, the control unit 101A returns to step S271 in FIG. 22 and repeats the processes after this step S271. Also, in step S288, when it is determined that the use of a non-driving application during execution has ended, the control unit 101A performs the use-end process for the non-driving application (step S289). Next, the control unit 101A proceeds to step S231 in FIG. 19, and further determines whether there is information on other update programs stored, and performs the processes after step S231 according to the determination result.
[0280] Also, in step S274 of FIG. 22, when it is determined that the information of the update program is for driving assistance, the control unit 101A determines the non-driving application being executed and predicts the stop duration (step S291 in FIG. 24).
[0281] In step S291, for example, it is determined whether the use other than driving is the AV entertainment function unit, the game function unit, or the massage mechanism drive unit. If the usage time has been input, the control unit 101A predicts the duration of the stop based on the received usage time and its start time (received time), and the time when the update notification was received in step S271. In this case, if the use other than driving is massage, as shown in Figure 29(D), the user has selected a course, so the duration of the stop is predicted based on the treatment time (for example, 10 minutes, 30 minutes, 60 minutes) determined according to the massage course selected by the user.
[0282] Furthermore, if no input for usage time has been received, the history analysis unit 143 analyzes the history information in the history memory 142, and the control unit 101A predicts the duration of the stop based on the past usage time for purposes other than driving currently in use. In this case, if a user for purposes other than driving currently in use is recognized, the control unit 101A predicts the duration of the stop based on the past usage time and start time for those recognized users for purposes other than driving currently in use, and the time when the update notification was received in step S271. If no user is recognized, the control unit 101A calculates the average past usage time for all users stored in the history memory 142 for purposes other than driving currently in use, and predicts the duration of the stop based on the calculated average usage time and start time, and the time when the update notification was received in step S271.
[0283] Then, the control unit 101A grasps the update time included in the update program information obtained in step S273 and determines whether or not the program update is possible within the predicted downtime (step S292). If it determines that the program update is not possible, it stores the update program information obtained in step S273 (step S293). Then, the control unit 101A returns to step S271 in Figure 22 and repeats the process from step S271 onwards.
[0284] Furthermore, if it is determined in step S292 that a program update is possible, the control unit 101A executes the program update (step S294). The control unit 101A then monitors for the completion of the update (step S295), and once it confirms the completion of the update in step S295, it notifies the server 3 of the completion of the update via the wireless communication unit 123 (step S296). The control unit 101A then determines whether or not the use of the vehicle for purposes other than driving has ended (step S297).
[0285] If, in step S297, it is determined that the use of the vehicle for purposes other than driving has not ended, the control unit 101A returns to step S271 in Figure 22 and repeats the processing from step S271 onward. If, in step S297, it is determined that the use of the vehicle for purposes other than driving has ended, the control unit 101A performs the processing to terminate the use of the vehicle for purposes other than driving (step S298). Next, the control unit 101A proceeds to step S231 in Figure 19, further determines whether there is any other stored update program information, and performs the processing from step S231 onward according to the determination result.
[0286] Furthermore, if it is determined in step S295 that the update is not complete, the control unit 101A determines whether or not the use for purposes other than driving has ended (step S301 in Figure 25). If it is determined in step S301 that the use for purposes other than driving has not ended, the control unit 101A returns to step S295 in Figure 24 and repeats the processing from step S295 onward.
[0287] Furthermore, in step S301, if it is determined that use for purposes other than driving has ended, the control unit 101A performs the process to end use for purposes other than driving and notifies the user that the program is still being updated (step S302). Then, the control unit 101A waits for the update to be completed (step S303), and once the update is confirmed to be complete, it notifies the server 3 via the wireless communication unit 123 that the update of the updated program has been completed, including the identification information of the updated program (step S304). Next, the control unit 101A proceeds to step S231 in Figure 19, and further determines whether there is information on other updates stored, and performs the processing from step S231 onwards according to the result of that determination.
[0288] Next, in step S271 in Figure 22, if it is determined that no program update notification has been received from server 3, the system determines the purpose of the operation other than running and predicts the duration of the stoppage (step S311 in Figure 26). In step S311, the duration of the stoppage is predicted in the same manner as described in step S291 above.
[0289] Next, the control unit 101A determines whether the predicted stop duration is equal to or greater than a predetermined time (step S312). The determination in step S312 excludes cases where the vehicle restarts immediately after stopping, and the predetermined time is set to, for example, 5 minutes.
[0290] If, in step S312, the control unit 101A determines that the predicted stop duration is less than a predetermined time, it determines whether or not the use for purposes other than driving has ended (step S319).
[0291] If, in step S319, it is determined that the use of the vehicle for purposes other than driving has not ended, the control unit 101A returns to step S271 in Figure 22 and repeats the processing from step S271 onward. If, in step S319, it is determined that the use of the vehicle for purposes other than driving has ended, the control unit 101A performs the processing to terminate the use of the vehicle for purposes other than driving (step S320). Next, the control unit 101A proceeds to step S231 in Figure 19, further determines whether there is any other stored update program information, and performs the processing from step S231 onward according to the determination result.
[0292] In step S312, if the control unit 101A determines that the predicted stop duration is longer than a predetermined time, it sends a program update request to the server 3 via the wireless communication unit 123, including the vehicle's identification information (step S313).
[0293] In response to this program update inquiry, Server 3 determines whether there are any incomplete update programs for the client's autonomous vehicle 1. If there are no update programs, it sends a notification to the client's autonomous vehicle 1 stating that no update programs are available. If there are update programs, it sends a notification that update programs exist and downloads the update program information to the client's autonomous vehicle 1.
[0294] Therefore, the control unit 101A, which sent the program update inquiry, determines whether or not it has received a notification from the server 3 that there are no updates available (step S314). If it determines that it has received a notification that there are no updates available, it proceeds to step S319 and repeats the processing from step S319 onward.
[0295] If, in step S314, it is determined that a notification has been received indicating the existence of an update program, rather than a notification indicating that no update program is available, the control unit 101A receives the update program information from the server 3 and obtains the update program information (step S315). Then, the control unit 101A determines the update time from the obtained update program information (step S316).
[0296] Next, the control unit 101A determines, based on the information about the predicted stop duration from the current time and the update time information obtained in step S316, whether or not a program update is possible within the predicted stop duration from the current time (step S317). If, in step S317, it is determined that a program update is not possible within the predicted stop duration from the current time, the control unit 101A stores the update program information obtained in step S315 (step S318). Then, the control unit 101A proceeds to step S319 and performs the processing from step S319 onward.
[0297] Furthermore, if step S317 determines that a program update is possible within the predicted stop duration from the current time, the control unit 101A uses the acquired update program information to perform the corresponding program update (step S331 in Figure 27). Then, the control unit 101A determines whether the program update is complete or not (step S332), and if it determines that the update is not complete, it determines whether the use for purposes other than driving has ended (step S333).
[0298] If, in step S333, it is determined that the vehicle is not yet being used for purposes other than driving, the control unit 101A returns to step S332 and repeats the process from step S332 onward.
[0299] Furthermore, in step S333, if it is determined that use for purposes other than driving has ended, the control unit 101A performs the process to end use for purposes other than driving and notifies the user that the program is still being updated (step S334). Then, the control unit 101A waits for the update to be completed (step S335), and once the update is confirmed to be complete, it notifies the server 3 via the wireless communication unit 123 that the update of the updated program has been completed, including the identification information of the updated program (step S336). Next, the control unit 101A proceeds to step S231 in Figure 19, and further determines whether there is information on other updates stored, and performs the processing from step S231 onwards according to the result of that determination.
[0300] Furthermore, when the control unit 101A determines in step S332 that the update is complete, it notifies the server 3 via the wireless communication unit 123 that the update of the updated program has been completed, including the identification information of the updated program (step S337). The control unit 101A then queries the server 3 to see if there are any further updates (step S338) and determines whether or not there are any further updates (step S339).
[0301] If step S339 determines that there are further updates, the control unit 101A returns to step S315 in Figure 26 and repeats the processing from step S315 onward. If step S339 determines that there are no further updates, the control unit 101A determines whether the use of the vehicle for purposes other than driving has ended (step S340).
[0302] If, in step S340, it is determined that the use of the vehicle for purposes other than driving has not ended, the control unit 101A returns to step S271 in Figure 22 and repeats the processing from step S271 onward. Also, if, in step S340, it is determined that the use of the vehicle for purposes other than driving has ended, the control unit 101A performs the processing to terminate the use of the vehicle for purposes other than driving (step S341). Next, the control unit 101A proceeds to step S231 in Figure 19, and further determines whether there is any other stored update program information, and performs the processing from step S231 onward according to the determination result.
[0303] As explained above, in the autonomous vehicle 1A of the second embodiment, the duration of stopping is predicted based on the autonomous vehicle 1A's past driving history and stopping history. In this autonomous vehicle 1A of the second embodiment, even if the vehicle is stopped, the program is executed only when it is determined that the predicted duration of stopping is longer than the program update time.
[0304] Therefore, in this second embodiment of the autonomous vehicle 1A, updates to the autonomous driving support program are not performed unnecessarily while the vehicle is stopped. Instead, updates to the autonomous driving support program are performed at appropriate intervals of stoppage, resulting in the remarkable effect of prioritizing user convenience while updating the autonomous driving support program at the appropriate time.
[0305] [Other embodiments or modifications] In the above embodiment, if it is determined that the driving support program cannot be updated using the acquired update program information, the update program information from server 3 is stored, and the driving support program is updated using the stored update program information during the subsequent downtime. However, if it is determined that the driving support program cannot be updated, the system may be configured to notify server 3 of this and refuse the update, and then update the driving support program at a later time based on an update notification from server 3 or by querying server 3.
[0306] In that case, Server 3 stores the unexecuted update programs for the driving assistance program in association with the identification information of the autonomous vehicle, and sends an update notification for the unexecuted update program when the next update notification is sent, or provides information about the unexecuted update program in response to an inquiry from the client's autonomous vehicle.
[0307] In the above-described embodiment, the program update management control units 119 and 119A determine whether or not it is possible to update the program that supports autonomous driving based on the update time information included in the update program information and the predicted duration of the stoppage. However, it is also possible to determine whether or not it is possible to update the program by also considering the remaining battery level. That is, if it is determined that the remaining battery level cannot keep up with the update time, the update program information is stored, and the update is performed at a later time, even if the predicted duration of the stoppage is longer than the update time.
[0308] Furthermore, in the above-described embodiment, the driving support program is for autonomous driving (fully automated driving), and in the automated driving mode of autonomous driving, various driving support programs are used selectively as appropriate. Therefore, in order to ensure the highest level of safety, all updates of the driving support program are avoided while driving. In addition, in the above-described embodiment, even if the vehicle is currently driving in manual driving mode, it is unknown when it will switch to automated driving mode. Therefore, in order to ensure the highest level of safety, in this embodiment, updates of the driving support program are avoided while driving, regardless of whether it is in manual driving mode or automated driving mode.
[0309] However, in autonomous driving mode, the system can recognize the driving assistance program being used at the time the update program information is acquired. Therefore, it is possible to determine whether the driving assistance program being used is subject to an update, and if it is not subject to an update, the system may perform the update of the driving assistance program based on the acquired update program information, even while driving. In addition, when driving in manual driving mode, the system may perform the update of the driving assistance program used in autonomous driving mode.
[0310] Furthermore, although the above-described embodiment was for an autonomous vehicle equipped with an autonomous driving mode capable of autonomous driving, the same applies to automobiles that do not have an autonomous driving mode capable of autonomous driving, but in manual driving mode, are equipped with an automatic collision avoidance assist system, a cruise control system, a lane keeping assist system, etc. In other words, the automatic collision avoidance assist system, the cruise control system, the lane keeping assist system, etc., use their respective driving support programs, and this invention can be applied to updating these driving support programs.
[0311] In the first and second embodiments described above, the autonomous vehicle is equipped with an autonomous driving mode and a manual driving mode. However, this invention is of course applicable even to autonomous vehicles that are equipped only with an autonomous driving mode.
[0312] Furthermore, in the above-described embodiment, if the user issues a command to start driving while the driving support program is being updated, the system is notified that driving cannot be started. However, the system can also be configured so that the user who receives this notification can forcibly stop the driving support program update. In this case, when a command to forcibly stop the driving support program update is received, the update of the driving support program is interrupted, and the update program information is stored. Then, during the subsequent suspension period, the interrupted driving support program update is restarted from the beginning.
[0313] Similarly, the system may be configured to allow users who receive notification that the system is unavailable because the driving support program is being updated to issue a command to forcibly stop the update. In this case as well, when a command to forcibly stop the driving support program update is received, the update of the driving support program is interrupted, and the update program information is stored. Then, during the subsequent suspension period, the interrupted driving support program update is restarted from the beginning.
[0314] In the first embodiment described above, the focus was on a configuration in which the duration of stopping is predicted at the time of disembarking based on the user's post-disembarking behavior and whether it is possible to update the driving support program. However, this invention may also be adapted to predict the duration of stopping (the time the vehicle is stopped) based on the user's input of the time the vehicle is stopped, even if it is not at the time of disembarking, as long as the time the user has already stopped driving during boarding or while riding can be determined.
[0315] Furthermore, although the above-described embodiment was for automobiles, this invention can also be applied to motorcycles and other two-wheeled vehicles, as well as three-wheeled vehicles. Of course, automobiles, two-wheeled vehicles, and three-wheeled vehicles are not limited to land use; they may also be amphibious vehicles or amphibious vehicles (flying vehicles). [Explanation of Symbols]
[0316] 1,1A…Autonomous vehicle, 3…Program update server, 10,10A…Electronic control circuit unit, 101,101A…Control unit, 116…Post-disembark behavior setting reception unit, 117,117A…Behavior control management unit, 119,119A…Program update management control unit
Claims
1. A means for determining whether the vehicle is stopped or not, When the vehicle's stopped state determination means determines that the vehicle is stopped, the vehicle's stopping state determination means predicts the duration of the stop, A first time determination means for determining whether the predicted duration of the stop, as predicted by the stop duration prediction means, is greater than or equal to a predetermined time, If the first time determination means determines that the duration of the stoppage is equal to or greater than the predetermined time, the inquiry means makes a request to the program update server for a program update, A second time determination means for determining whether the update time of the update program obtained from the program update server based on the inquiry by the inquiry means is within the downtime, The second time determination means controls the program update using the update program if the update time of the update program is within the suspension duration, and the program update is not performed if the update time of the update program is not within the suspension duration. An automobile characterized by being equipped with the following features.
2. The program that the control means determines whether or not to perform an update on is a driving support program that assists in the driving of the vehicle. The automobile according to feature 1.
3. An automobile that can be selected for use in driving and for non-driving purposes, and is equipped with a driving assistance program to assist with driving and a program for non-driving purposes, The update program includes an update program determination means for determining whether the update program is an update program for the driving support program or an update program for a program used for purposes other than driving, If the update program determination means determines that the update program is an update program for a program used for purposes other than driving, the control means will perform the program update even if the second time determination means determines that the update time of the update program is not within the stop duration. The automobile according to feature 1.
4. The control means, if the update time of the update program is not within the duration of the vehicle's stoppage, does not execute the program update, stores the update program in memory, and executes the update when the vehicle is stopped at a later date. The automobile according to any one of claims 1 to 3.
5. When the vehicle's subsequent stopped state is determined, the update time of the stored update program is determined, and the duration of the vehicle's subsequent stopped state is predicted. If the determined update time of the update program is within the predicted duration of the stopped state, the program update is executed. If it is not within the predicted duration of the stopped state, the program update is not executed, and the system waits for the vehicle's subsequent stopped state. The automobile according to feature 4.
6. In a stationary state, the vehicle is equipped with a behavior reception mechanism that accepts the intended use of the vehicle by passengers who have boarded it, as a setting for the vehicle's behavior while stationary. When the behavior receiving means receives a setting for the behavior of the vehicle in a stopped state, the stop duration prediction means predicts the stop duration based on the received setting for the behavior of the vehicle in a stopped state. The automobile according to any one of claims 1 to 5.
7. If a command to start driving is received while the aforementioned program update is being performed, the system will notify the user that driving is not possible because the program update is in progress. The automobile according to any one of claims 1 to 6.
8. If a user requests that the program update be forcibly stopped, the program update will be interrupted, and the interrupted program update will be executed during the subsequent suspension period. The automobile according to feature 7.
9. Wireless communication means, The vehicle is equipped with a call request receiving means for receiving call requests from users outside the vehicle via the aforementioned wireless communication means, If the call request receiving means receives a call request from the user while the program update is being performed, the wireless communication means will notify the user that the call is unavailable because the program update is in progress. The automobile according to any one of claims 1 to 8.
10. If a user receives notification that the service is unavailable because the aforementioned program is being updated, and instructs the service to forcibly stop the program update, the service will interrupt the program update and then perform the interrupted program update during the remaining vehicle stop time. The automobile according to feature 9.
11. It is equipped with an autonomous driving mode execution control means that controls the system to perform autonomous driving using an autonomous driving support program that assists autonomous driving, The program is the autonomous driving support program. The automobile according to any one of claims 1 to 10.
12. Equipped with a manual driving mode, The program includes a program for an automatic collision avoidance system, a program for a cruise control system, or a program for a lane keeping assist system. The automobile according to any one of claims 1 to 11.
13. If the vehicle stationary status determination means determines that the vehicle is in motion, the driving support program will not be updated. The automobile according to any one of claims 1 to 12.
14. Equipped with a battery level detection unit, The control means also takes into account the remaining battery level detected by the battery level detection unit to control whether or not to perform the program update. The automobile according to any one of claims 1 to 13.
15. The computer installed in the car, A means for determining whether the vehicle is stopped or not, If the vehicle's stopped state determination means determines that the vehicle is stopped, the vehicle's stopping duration prediction means predicts the duration of the stop. A first time determination means for determining whether the predicted duration of the stop, as predicted by the stop duration prediction means, is equal to or greater than a predetermined time. If the first time determination means determines that the duration of the stoppage is equal to or greater than the predetermined time, the inquiry means makes a request to the program update server for a program update. A second time determination means for determining whether the update time of the update program obtained from the program update server based on the inquiry by the inquiry means is within the downtime. The second time determination means controls the program update by the update program if the update time of the update program is within the suspension duration, and the program update is not performed if the update time of the update program is not within the suspension duration. An automotive program designed to function as such.