vehicle
A dual control system with redundant communication relays ensures door unlocking in vehicles with autonomous driving kits, addressing communication failures and enhancing safety.
Patent Information
- Application Number
- JP2025022353
- Authority / Receiving Office
- JP · JP
- Patent Type
- Applications
- Current Assignee / Owner
- Filing Date
- 2025-02-14
- Publication Date
- 2026-08-26
AI Technical Summary
Vehicles equipped with autonomous driving kits face the risk of doors being unable to unlock when communication with the kit fails, leading to potential safety issues.
The vehicle is configured with a dual control system, including a first control system and a second control system, and a main and sub-vehicle control interface box to relay communication, allowing doors to unlock even without direct commands from the autonomous driving kit during communication loss.
Ensures door unlocking even in communication failures, enhancing safety by preventing occupants from being trapped, and maintaining vehicle functionality during autonomous driving.
Smart Images

Figure 2026136691000001_ABST
Abstract
Description
Technical Field
[0001] This disclosure relates to a vehicle, and particularly to a vehicle configured to be capable of autonomous driving with a detachable autonomous driving kit for giving an instruction for autonomous driving.
Background Art
[0002] Conventionally, there has been a vehicle configured to be capable of autonomous driving with a detachable autonomous driving kit (hereinafter referred to as "ADK (Autonomous Driving Kit)") for giving an instruction for autonomous driving (see, for example, Patent Document 1). In this vehicle, locking and unlocking of the vehicle door are performed according to a command from the ADK (see, for example, 3.7.2.1 and 3.7.2.2 in paragraph
[0176] of Patent Document 1).
Prior Art Documents
Patent Documents
[0003]
Patent Document 1
Summary of the Invention
Problems to be Solved by the Invention
[0004] However, when the vehicle fails to receive a command from the ADK normally (for example, when the vehicle fails to receive a command from the ADK via the normal path), there is a risk that the door cannot be unlocked according to the command from the ADK.
[0005] This disclosure has been made to solve the above-described problems, and an object thereof is to provide a vehicle capable of unlocking the door even without a command from the autonomous driving kit.
Means for Solving the Problems
[0006] The vehicle relating to this disclosure is configured to enable autonomous driving by attaching and detaching an autonomous driving kit that issues instructions for autonomous driving. The vehicle comprises a base vehicle equipped with doors, a first control system that controls the doors according to commands to lock or unlock the doors from the autonomous driving kit, a second control system different from the first control system, and a main vehicle control interface box that relays communication between the autonomous driving kit and the first control system. If the first control system can receive a command from the autonomous driving kit via the main vehicle control interface box, it locks or unlocks the doors according to the command. If the second control system detects a loss of communication via the main vehicle control interface box, it issues a command to the first control system to unlock the doors during the vehicle's evasive maneuver.
[0007] This configuration makes it possible to provide a vehicle that can unlock its doors even without commands from the autonomous driving kit.
[0008] The vehicle may further include a sub-vehicle control interface box that relays communication between the autonomous driving kit and the base vehicle and is also capable of communicating with the main vehicle control interface box. If the first control system detects a loss of communication from the autonomous driving kit via the main vehicle control interface box, and if it is possible to receive a command from the autonomous driving kit via the sub-vehicle control interface box and the main vehicle control interface box, it may lock or unlock the doors in accordance with that command.
[0009] With this configuration, a loss of communication from the autonomous driving kit via the main vehicle control interface box can be detected, and the doors can be unlocked even without a direct command from the autonomous driving kit to the first control system via the main vehicle control interface.
[0010] According to other aspects of this disclosure, a vehicle is configured to be capable of autonomous driving with a removable autonomous driving kit that issues instructions for autonomous driving. The vehicle comprises a base vehicle with doors, a first control system that controls the doors in accordance with commands to lock or unlock the doors from the autonomous driving kit, a main vehicle control interface box that relays communication between the autonomous driving kit and the first control system, and a sub-vehicle control interface box that relays communication between the autonomous driving kit and the base vehicle and is also able to communicate with the main vehicle control interface box. If the first control system can receive a command from the autonomous driving kit via the main vehicle control interface box, it locks or unlocks the doors in accordance with the command. If the first control system detects a loss of communication from the autonomous driving kit via the main vehicle control interface box, and can receive a command from the autonomous driving kit via the sub-vehicle control interface box and the main vehicle control interface box, it locks or unlocks the doors in accordance with the command.
[0011] With this configuration, a loss of communication from the autonomous driving kit via the main vehicle control interface box can be detected, and a vehicle can be provided in which the doors can be unlocked even without a direct command from the autonomous driving kit to the first control system via the main vehicle control interface.
[0012] The vehicle may further include a second control system different from the first control system. The second control system may, upon detecting a loss of communication via the main vehicle control interface box, instruct the first control system to unlock the doors during the vehicle's evasive maneuver.
[0013] With this configuration, the doors can be unlocked even without commands from the autonomous driving kit.
[0014] When the first control system detects a communication failure via the main vehicle control interface box, or when it detects a stop of the vehicle, it may unlock the doors even if no command is received from the autonomous driving kit.
[0015] According to such a configuration, the doors can be unlocked even without a command from the autonomous driving kit.
Advantages of the Invention
[0016] According to this disclosure, it is possible to provide a vehicle capable of unlocking the doors even without a command from the autonomous driving kit.
Brief Description of the Drawings
[0017] [Figure 1] It is a diagram showing an overview of a vehicle according to an embodiment of this disclosure. [Figure 2] It is a diagram showing in detail the configurations of the ADK, VCIB, and VP according to this embodiment. [Figure 3] It is a block diagram showing the flow of instructions for conventional door control. [Figure 4] It is a flowchart showing the flow of processing for controlling the doors in this embodiment. [Figure 5] It is a first block diagram showing the flow of instructions for door control in this embodiment. [Figure 6] It is a second block diagram showing the flow of instructions for door control in this embodiment.
Modes for Carrying Out the Invention
[0018] Hereinafter, embodiments of this disclosure will be described in detail with reference to the drawings. The same or corresponding parts in the drawings are denoted by the same reference numerals and their description will not be repeated.
[0019] FIG. 1 is a diagram showing an overview of the vehicle 1 according to an embodiment of this disclosure. FIG. 2 is a diagram showing in detail the configurations of the ADK 10, the VCIB 40, and the VP 20 according to this embodiment. Referring to FIGS. 1 and 2, the vehicle 1 includes the ADK 10 and the VP 20. The ADK 10 is configured to be attachable to the VP 20 (mountable on the vehicle 1). The ADK 10 and the VP 20 are configured to be able to communicate with each other via the VCIB 40.
[0020] The VP 20 can perform autonomous driving according to a control request from the ADK 10. In FIG. 1, the ADK 10 is shown at a position separated from the VP 20, but in reality, the ADK 10 is attached to the roof top or the like of the VP 2 (0). It is also possible to remove the ADK 10 from the VP 20. When the ADK 10 is removed, the VP 20 executes driving control (driving control according to user operation) in manual mode (manual driving mode).
[0021] The ADK 10 includes an autonomous driving system (ADS: Autonomous Driving System) 11 for performing autonomous driving of the vehicle ①. The ADS 11 creates, for example, a driving plan for the vehicle 1. The ADS 11 outputs various control requests for driving the vehicle 1 according to the driving plan to the VP 20 according to an API (Application Program Interface) defined for each control request. Also, the ADS 11 receives various signals indicating the vehicle state (the state of the VP 20) from the VP 20 according to an API defined for each signal. Then, the ADS 11 reflects the vehicle state in the driving plan. [[ID=⑨]] [[ID=⑩]]
[0022] [[ID=⑪]] It should be noted that there seems to be an error in the original text where "VP 2" is likely "VP 20" in some places, and "vehicle ①" is likely "vehicle 1". The translation has been adjusted accordingly.VP20 includes a base vehicle 30 and a VCIB 40. The base vehicle 30 performs various vehicle controls according to control requests from ADK10 (ADS11). The base vehicle 30 includes various in-vehicle systems and sensors for controlling the base vehicle 30. More specifically, the base vehicle 30 includes an integrated control manager 31, a brake system 32, a steering system 33, a powertrain system 34, an active safety system 35, a body system 36, wheel speed sensors 51, 52, a pinion angle sensor 53, a camera 54, and radar sensors 55, 56.
[0023] The integrated control manager 31 includes a processor such as a CPU (Central Processing Unit) and memory such as ROM (Read Only Memory) and RAM (Random Access Memory), and integrates and controls the above-mentioned systems (brake system 32, steering system 33, powertrain system 34, active safety system 35, body system 36) involved in the operation of the vehicle 1.
[0024] The brake system 32 is configured to control braking devices provided on each wheel of the base vehicle 30. The braking devices include, for example, a disc brake system that operates in response to hydraulic pressure adjusted by an actuator.
[0025] Wheel speed sensors 51 and 52 are connected to the brake system 32. The wheel speed sensors 51 and 52 detect the rotational speed of the front and rear wheels of the base vehicle 30, respectively, and output the detected front and rear wheel rotational speeds to the brake system 32. The brake system 32 outputs the rotational speed of each wheel to the VCIB 40 as one of the pieces of information included in the vehicle state. The brake system 32 also generates a braking command for the braking device according to a predetermined control request output from the ADS 11 via the VCIB 40 and the integrated control manager 31. The brake system 32 controls the braking device using the generated braking command. The integrated control manager 31 can calculate the speed of the vehicle 1 (vehicle speed) based on the rotational speed of each wheel.
[0026] The steering system 33 is configured to control the steering angle (tire turning angle) of the steering wheels of the vehicle 1 using a steering device. The steering device includes, for example, a rack-and-pinion type electric power steering (EPS) in which the steering angle can be adjusted by an actuator.
[0027] A pinion angle sensor 53 is connected to the steering system 33. The pinion angle sensor 53 detects the rotation angle (pinion angle) of the pinion gear connected to the rotation axis of the actuator and outputs the detected pinion angle to the steering system 33. The steering system 33 outputs the pinion angle to the VCIB 40 as one of the pieces of information included in the vehicle state. The steering system 33 also generates steering commands for the steering device according to predetermined control requests output from the ADS 11 via the VCIB 40 and the integrated control manager 31. The steering system 33 controls the steering device using the generated steering commands.
[0028] The powertrain system 34 controls vehicle locking systems 341 and 342 that control an electric parking brake (EPB) provided on at least one of the wheels and a parking lock (P-Lock) device provided on the transmission of vehicle 1, and a propulsion system 343 that includes a shift device configured to allow selection of the shift range.
[0029] The active safety system 35 uses a camera 54 and radar sensors 55, 56 to detect obstacles in front of or behind the vehicle (pedestrians, bicycles, parked vehicles, utility poles, etc.). Based on the distance between the vehicle 1 and the obstacle, and the direction of movement of the vehicle 1, the active safety system 35 determines whether the vehicle 1 is likely to collide with the obstacle. If the active safety system 35 determines that a collision is likely, it outputs a braking command to the brake system 32 via the integrated control manager 31 to increase the braking force.
[0030] The body system 36 is configured to control components such as turn signals (turn lamps, hazard lamps), horns, wipers, headlights, and brake lights, for example, depending on the driving conditions or environment of the vehicle 1. The body system 36 controls each of the above components according to predetermined control requests output from the ADS 11 via the VCIB 40 and the integrated control manager 31.
[0031] The VCIB40 is configured to communicate with the ADS11 via CAN (Controller Area Network) or the like. The VCIB40 receives various control requests from the ADS11 and outputs vehicle status to the ADS11 by executing predetermined APIs defined for each signal. When the VCIB40 receives a control request from the ADK10, it outputs a control command corresponding to that control request to the system corresponding to that control command via the integrated control manager 31. The VCIB40 also acquires various information about the base vehicle 30 from various systems via the integrated control manager 31 and outputs the status of the base vehicle 30 as vehicle status to the ADS11.
[0032] Vehicle 1 can be used as part of a Mobility as a Service (MaaS) system. In addition to Vehicle 1, the MaaS system includes, for example, a data server and a Mobility Service Platform (MSPF).
[0033] MSPF is a unified platform that connects various mobility services. Autonomous driving-related mobility services are connected to MSPF. In addition to autonomous driving-related services, MSPF may also connect mobility services provided by ride-sharing companies, car-sharing companies, rental car companies, taxi companies, insurance companies, and others.
[0034] Vehicle 1 is further equipped with a Data Communication Module (DCM) capable of wireless communication with a data server. The DCM outputs vehicle information, such as speed, location, and autonomous driving status, to the data server. The DCM also receives various data from mobility services, such as the MSPF and data server, for managing the operation of autonomous vehicles, including Vehicle 1, in autonomous driving-related mobility services.
[0035] MSPF provides APIs for accessing various vehicle status and control data necessary for ADS11 development. Various mobility services can use the APIs published on MSPF to utilize the various functions provided by MSPF according to their service content. For example, autonomous driving-related mobility services can use the APIs published on MSPF to obtain driving control data for vehicle 1, information stored on the data server, etc. from MSPF. In addition, autonomous driving-related mobility services can use the above APIs to send data for managing autonomous vehicles, including vehicle 1, to MSPF.
[0036] The ADS11 includes a computer 111, an HMI (Human Machine Interface) 112, a recognition sensor 113, a posture sensor 114, and a sensor cleaner 115.
[0037] Computer 111 includes a processor 101 such as a CPU and memory 102 such as ROM and RAM. Memory 102 stores programs that can be executed by the processor 101. During the automatic driving of vehicle 1, computer 111 uses various sensors (described later) to acquire the environment of vehicle 1, as well as the attitude, behavior, and position of vehicle 1, and acquires the vehicle state from VP20 via VCIB40 to set the next action of vehicle 1 (acceleration, deceleration, turning, etc.). Computer 111 outputs various commands to VCIB40 to realize the next action. Computer 111 further includes communication modules 111A and 111B. Each of communication modules 111A and 111B is configured to communicate with VCIB40.
[0038] The HMI112 presents information to the user and accepts user input during autonomous driving, manual driving requiring user intervention, and transitions between autonomous driving and manual driving requiring user intervention. The HMI112 includes, for example, an input / output device such as a touch panel display provided on the base vehicle 30.
[0039] The recognition sensor 113 is a sensor for recognizing the environment of vehicle 1. The recognition sensor 113 includes, for example, at least one of LIDAR (Laser Imaging Detection and Ranging), millimeter-wave radar, and camera. LIDAR measures the distance and direction of an object by, for example, emitting infrared pulsed laser light and detecting the reflected light from the object. Millimeter-wave radar measures the distance and direction of an object by emitting millimeter waves and detecting the reflected waves from the object. Camera is, for example, positioned behind the rearview mirror and captures an image of the area in front of vehicle 1.
[0040] The attitude sensor 114 is a sensor for detecting the attitude, behavior, and position of vehicle 1. The attitude sensor 114 includes, for example, an IMU (Inertial Measurement Unit) and a GPS (Global Positioning System). The IMU detects, for example, the acceleration of vehicle 1 in the longitudinal, lateral, and vertical directions, and the angular velocity of vehicle 1 in the roll, pitch, and yaw directions. The GPS detects the position of vehicle 1 using information received from multiple GPS satellites orbiting the Earth.
[0041] The sensor cleaner 115 is configured to remove dirt that adheres to the various sensors (camera lenses, laser beam irradiation parts, etc.) while the vehicle 1 is in motion, using a cleaning solution, wipers, etc.
[0042] VCIB40 includes a main VCIB41 and a sub-VCIB42. VCIB41 and VCIB42 each include processors such as a CPU 411 and 421, and memory such as ROM and RAM 412 and 422, respectively. Memory 412 and 422 each store programs executable by processors 411 and 421 and data processed by those programs. The main VCIB41 and communication module 111A are connected to each other via communication bus 43 (main bus). The sub-VCIB42 and communication module 111B are connected to each other via communication bus 44 (sub-bus). Furthermore, the main VCIB41 and sub-VCIB42 are connected to each other via communication bus 45.
[0043] Each of the VCIBs, 41 and 42, relays control requests and vehicle information between the ADS11 and the VP20. The VCIBs 41 and 42 interface between the base vehicle 30 and the ADS11 via communication buses 43 and 44. The VCIBs 41 and 42 generate control commands from control requests received from the ADS11 using APIs.
[0044] The control commands supplied from ADS11 to VCIB40 in response to control requests include, for example, a propulsion direction command requesting a shift range change, a stationary command requesting activation / deactivation of the EPB and P-Lock devices, an acceleration command requesting acceleration or deceleration of vehicle 1, a steering angle command requesting the steering wheel angle, an autonomization command requesting switching between autonomous mode and manual mode, and a stop command requesting the vehicle to be stopped or released from being stopped.
[0045] VCIB41 and 42 then output the generated control commands to the corresponding systems among the multiple systems included in VP20. Furthermore, VCIB41 and 42 use an API to generate vehicle status information from vehicle information received from each system of VP20. This vehicle status information may be identical to the vehicle information, or it may be information extracted from the vehicle information for use in processing performed by ADS11. VCIB41 and 42 then output the generated vehicle status information to ADS11.
[0046] Brake system 32 includes brake systems 321 and 322. Steering system 33 includes steering systems 331 and 332. Powertrain system 34 includes vehicle fixing system 340 and propulsion system 343. Vehicle fixing system 340 includes vehicle fixing systems 341 and 342.
[0047] VCIB41 and 42 have essentially equivalent functions, but there are some differences in how they connect to the in-vehicle systems included in VP20. Specifically, the main VCIB41, brake system 321, steering system 331, vehicle fixing systems 341 and 342, propulsion system 343, and body system 36 are interconnected via a communication bus 37. The sub-VCIB42, brake system 322, steering system 332, and vehicle fixing systems 341 and 342 are interconnected via a communication bus 38.
[0048] Thus, by including VCIB40 with VCIB41 and VCIB42, which have equivalent functions for the operation of some systems (such as brakes and steering), the control system between ADS11 and VP20 is made redundant. Therefore, if any failure occurs in the system, the functionality of VP20 can be maintained by appropriately switching control systems or shutting off the failed control system.
[0049] Brake systems 321 and 322 each include a processor 3211 and 3221, such as a CPU, and memory 3212 and 3222, such as ROM and RAM. Each of the brake systems 321 and 322 is configured to control the braking device. Brake systems 321 and 322 each generate braking commands for the braking device in accordance with control requests output from ADS 11 via VCIB 41 and 42. Brake systems 321 and 322 may have equivalent functions. Alternatively, one of the brake systems 321 and 322 may be configured to independently control the braking force of each wheel, while the other is configured to control the generation of the same braking force on each wheel. Brake systems 321 and 322 may, for example, control the braking device using braking commands generated by one of the brake systems, and if a malfunction occurs in that brake system, control the braking device using braking commands generated by the other brake system.
[0050] The steering systems 331 and 332 each include a processor 3311 and 3321, such as a CPU, and memory 3312 and 3322, such as ROM and RAM. Each of the steering systems 331 and 332 is configured to control the steering angle of the steering wheels of the vehicle 1 using a steering device. The steering systems 331 and 332 each generate steering commands for the steering device in accordance with control requests output from the ADS 11 via VCIB 41 and 42. The steering systems 331 and 332 may have equivalent functions. Alternatively, the steering systems 331 and 332 may, for example, control the steering device using steering commands generated by one of the steering systems, and if a malfunction occurs in that steering system, control the steering device using steering commands generated by the other steering system.
[0051] The vehicle locking systems 341 and 342 each include a processor such as a CPU 3411 and 3421, and memory such as ROM and RAM 3412 and 3422, respectively. The vehicle locking systems 341 and 342 control the EPB and P-Lock devices according to control requests output from the ADS 11 via VCIB 41 and 42. The EPB is provided separately from the braking system (such as a disc brake system) and locks the wheels by the operation of an actuator. For example, the EPB locks the wheels by using an actuator to operate a drum brake for a parking brake provided on some of the wheels, or by using an actuator that can adjust the hydraulic pressure supplied to the braking system separately from the brake systems 321 and 322 to lock the wheels. The vehicle locking systems 341 and 342 have a brake hold function and are configured to allow switching between operating and releasing the brake hold.
[0052] The vehicle locking systems 341 and 342 activate the P-Lock device when, for example, a control request includes a request to set the shift range to the parking range (P range), and deactivate the P-Lock device when a control request includes a request to set the shift range to a range other than the P range. The P-Lock device engages the projection at the tip of a parking lock pawl, whose position can be adjusted by an actuator, with the teeth of a gear (lock gear) connected to a rotating element in the transmission of the vehicle 1. This fixes the rotation of the output shaft of the transmission and locks the wheels.
[0053] The propulsion system 343 includes a processor 3431 such as a CPU and memory 3432 such as ROM and RAM. The propulsion system 343 also includes a direction control system and a propulsion force system. The direction control system is connected to the VCIB 40. The direction control system controls the direction of travel (forward or reverse) of the VP20 by switching the shift range of the shift device according to control requests output from the ADS 11 via the VCIB 41. The shift range includes a P range and a neutral range (N range), as well as a forward driving range (D range) and a reverse driving range (R range). The propulsion force system is connected to the VCIB 40. The propulsion force system controls the propulsion force (e.g., acceleration and deceleration) of the VP20 by controlling the driving force from a drive source (motor generator, engine, etc.).
[0054] The active safety system 35 includes a processor 351 such as a CPU and memory 352 such as ROM and RAM. The active safety system 35 is connected to the brake system 321 via a communication bus 39 so as to be able to communicate with each other. As described above, the active safety system 35 uses a camera 54 and / or a radar sensor 55 to detect obstacles ahead and outputs a braking command to the brake system 321 to increase the braking force when it determines that a collision is possible.
[0055] The body system 36 includes a processor 361 such as a CPU and memory 362 such as ROM and RAM. The body system 36 also includes a door locking device 363 for locking or unlocking the doors of the base vehicle 30 and a door opening / closing device 364 for opening and closing the doors of the base vehicle 30. The body system 36 controls components such as turn signals, horns, wipers, the door locking device 363 and the door opening / closing device 364 according to control requests output from the ADS 11 via the VCIB 41.
[0056] In vehicle 1, autonomous driving is performed when, for example, the user's operation on the HMI 112 selects the autonomous mode (autonomous driving mode). As mentioned above, during autonomous driving, ADS 11 first creates a driving plan. Examples of driving plans include a plan to continue driving straight, a plan to turn left / right at a predetermined intersection along a predetermined driving route, and a plan to change driving lanes. ADS 11 calculates the controllable physical quantities (acceleration, deceleration, tire steering angle, etc.) necessary for vehicle 1 to operate according to the created driving plan. ADS 11 divides the physical quantities for each API execution cycle. ADS 11 uses the API to output control requests representing the divided physical quantities to VCIB 40. Furthermore, ADS 11 obtains the vehicle state (actual direction of movement of vehicle 1, vehicle fixation state, etc.) from VP 20 and recreates the driving plan reflecting the obtained vehicle state. In this way, ADS 11 enables autonomous driving of vehicle 1.
[0057] In the VP20 described above, fault diagnosis is performed in each system, such as the brake systems 321 and 322 and the steering systems 331 and 332, and fault information is transmitted to VCIB41 and 42. Then, information regarding whether or not there is a failure, as indicated in the fault information, is transmitted from VCIB41 and 42 to ADK10.
[0058] Conventionally, in vehicle 1, the doors of vehicle 1 were locked and unlocked according to commands from ADK10. However, if vehicle 1 is unable to receive commands from ADK10 properly (for example, if it is unable to receive commands from ADK10 via the normal route), there is a risk that the doors will not be able to be unlocked according to the commands from ADK10.
[0059] Figure 3 is a block diagram showing the flow of instructions for conventional door control. Referring to Figure 3, conventionally, instructions to control the door (for example, an instruction to unlock the door) are transmitted from the main communication module 111A of the computer 111 of the ADK10's ADS11 to the body system 36 via the communication bus 43, the main VCIB41, and the communication bus 37. This enables door control from the ADK10.
[0060] If the main communication module 111A fails, even if the sub-communication module of the computer 111 attempts to transmit a door control instruction to the body system 36 via the communication bus 44 and the sub-VCIB 42, the instruction to control the door will not be transmitted to the body system 36 because there is no communication bus between the sub-VCIB 42 and the body system 36.
[0061] Therefore, if the body system 36 can receive a command from the ADK 10 via the VCIB 41, it locks or unlocks the door according to the command. If the active safety system 35 detects a loss of communication via the VCIB 41, it instructs the door lock device 363 to unlock the door during the vehicle 1's evasive maneuver. This allows the door to be unlocked even without a command from the ADK 10.
[0062] Figure 4 is a flowchart showing the processing flow for controlling the door in this embodiment. Referring to Figure 4, the VCIB2 process is called from a higher-level process at predetermined intervals by the sub-VCIB42 and executed. The front camera process is called from a higher-level process at predetermined intervals by the processor 351 of the active safety system 35 and executed.
[0063] In the VCIB2 process, the processor 421 of the sub-VCIB42 determines whether or not it has detected a loss of communication between the ADK10 and the main VCIB41 (step S111). If it determines that no loss has been detected (NO in step S111), the processor 421 returns the processing to the higher-level processing that called this VCIB2 process.
[0064] On the other hand, if it is determined that a communication failure has occurred between ADK10 and the main VCIB41 (YES in step S111), the processor 421 determines whether or not there was an instruction from ADK10 to control the door (step S112). For example, the processor 421 of the sub VCIB42 queries ADK10 for instructions sent to VCIB41 before and after the communication failure occurred, and determines whether or not there was an instruction to control the door among those instructions.
[0065] If the processor determines that there is an instruction to control the door (YES in step S112), the processor 421 follows the instruction from the ADK 10 to control the door and sends a command to control the door to the body system 36 via the main VCIB 41 to control the door (step S113). As a result, the body system 36 controls the door according to this command. After step S113, the processor 421 returns the processing to be executed to the higher-level processing that called this VCIB2 process.
[0066] On the other hand, if it is determined that there is no instruction to control the door (NO in step S112), the processor 421 determines whether or not it has detected that vehicle 1 has stopped (step S114). If it is determined that vehicle 1 has stopped (YES in step S114), it sends a command to control the door (for example, a command to control the door lock device 363 to unlock the door, or a command to control the door open / close device 364 to open the door) to the body system 36 via the main VCIB 41 (step S115). As a result, the door is controlled by the body system 36 according to this command. If it is determined that vehicle 1 has not stopped (NO in step S114), or after step S115, the processor 421 returns the processing to be executed to the higher-level processing that called this VCIB2 process.
[0067] Figure 5 is a first block diagram showing the flow of door control instructions in this embodiment. Referring to Figure 5, if communication between the communication module 111A of the ADK10 computer 111 and the main VCIB 41 is not lost, instructions to control the door are transmitted from the communication module 111A to the body system 36 via the communication bus 43, the main VCIB 41 and the communication bus 37.
[0068] As shown in steps S111 to S113 of Figure 4, if communication is lost between the communication module 111A of the computer 111 of ADK10 and the main VCIB 41, if there is a door control instruction from ADK10, the instruction to control the door is transmitted from the communication module 111B of the computer 111 of ADK10 to the body system 36 via the communication bus 44, the sub VCIB 42, the communication bus 45, the main VCIB 41 and the communication bus 37.
[0069] Furthermore, as shown in steps S111, S112, S114, and S115 of Figure 4, if communication between the communication module 111A of the ADK10's computer 111 and the main VCIB41 is lost, and even if there is no instruction from the ADK10 to control the doors, if the vehicle 1 stops, the sub VCIB42 will spontaneously transmit instructions to control the doors (for example, an instruction to control the door lock device 363 to unlock the doors, or an instruction to control the door open / close device 364 to open the doors) to the body system 36 via the communication bus 45, the main VCIB41, and the communication bus 37.
[0070] Returning to Figure 4, in the front camera processing, the processor 351 of the active safety system 35 determines whether or not it has detected a failure of the main VCIB 41 (step S311). If it determines that no failure has been detected, the processor 351 returns the processing to the higher-level processing that called this front camera processing.
[0071] On the other hand, if it is determined that the main VCIB41 has failed (YES in step S311), the processor 351 determines whether or not it has detected that vehicle 1 has stopped after moving to safety (step S312). If it is determined that it has detected that vehicle 1 has stopped after moving to safety (YES in step S312), the processor 351 sends instructions to control the doors directly from the body system 36 via the communication bus 37A (for example, an instruction to control the door lock device 363 to unlock the doors, or an instruction to control the door open / close device 364 to open the doors) (step S313). The communication bus 37A is branched off from the communication bus 37 to which the body system 36 is connected and connected to the active safety system 35.
[0072] If it is determined that a stop after evasive driving has not been detected (NO in step S312), or after step S313, the processor 351 returns the processing to be executed to the higher-level processing that called this front camera processing.
[0073] Figure 6 is a second block diagram showing the flow of door control instructions in this embodiment. Referring to Figure 6, if the main VCIB41 fails, not only instructions from the communication module 111A of the ADK10's computer 111 via the communication bus 43, but also instructions from the sub VCIB42 shown in Figure 5 will not be transmitted to the body system 36.
[0074] As shown in steps S311 to S313 of Figure 4, if the main VCIB 41 fails and the vehicle 1 stops after moving to safety, the active safety system 35 spontaneously transmits instructions to the body system 36 via the communication bus 37A to control the doors (for example, an instruction to control the door lock device 363 to unlock the doors, or an instruction to control the door open / close device 364 to open the doors).
[0075] [Differentiation] (1) In the embodiment described above, as shown in steps S115 and S313 of Figure 4, if communication between ADK10 and the main VCIB41 is lost, or if the main VCIB41 is lost, the door lock device 363 is controlled to unlock the door, or the door opening / closing device 364 is controlled to open the door. However, the embodiment is not limited to this, and either the door lock device 363 is controlled to unlock the door, or the door opening / closing device 364 is controlled to open the door, or other control related to the door (for example, control to open a window) is performed.
[0076] (2) In the embodiments described above, the use of vehicle 1 was not particularly limited. However, it is not limited to this, and vehicle 1 may also be used as an autonomous taxi. In this case, in particular, it is possible to prevent taxi passengers from being trapped inside vehicle 1.
[0077] (3) The embodiments described above can be interpreted as disclosures of the vehicle 1 or the control device of the vehicle 1 (processor 361 of the body system 36, processor 351 of the active safety system 35, processor 411 of the VCIB 41, processor 421 of the VCIB 42, and computer 111 of the ADK 10). The embodiments described above can be interpreted as disclosures of control methods or control programs executed by the vehicle 1 or the control device of the vehicle 1.
[0078] [summary] (1) As shown in Figures 1 and 2, the vehicle 1 is configured to be capable of autonomous driving by having an ADK 10 that issues commands for autonomous driving attached and detachable. As shown in Figures 1 and 2, the vehicle 1 comprises a base vehicle 30 with doors, a body system 36 that controls the doors according to commands to lock or unlock the doors from the ADK 10, an active safety system 35 that is different from the body system 36, and a main VCIB 41 that relays communication between the ADK 10 and the body system 36.
[0079] As shown in Figure 3, if the body system 36 can receive a command from the ADK 10 via the main VCIB 41, it locks or unlocks the doors according to that command. As shown in Figures 4 and 6, if the active safety system 35 detects a loss of communication via the main VCIB 41, it instructs the body system 36 to unlock the doors during the vehicle 1's escape maneuver (for example, from step S311 to step S313).
[0080] This allows the doors to be unlocked even without a command from ADK10. Furthermore, if a command from ADK10 is received, the control will be executed according to the command, ensuring that the control is performed in accordance with the manufacturer's intentions for ADK10. In addition, it can prevent people from being trapped inside vehicle 1 after the vehicle has moved to a safer position.
[0081] (2) As shown in Figures 1 and 2, vehicle 1 may further include a sub VCIB42 that relays communication between ADK10 and base vehicle 30 and can communicate with the main VCIB41. As shown in Figures 4 and 5, if the body system 36 detects a loss of communication from ADK10 via the main VCIB41, and if it can receive a command from ADK10 via the sub VCIB42 and the main VCIB41, it may lock or unlock the doors in accordance with the command (for example, from step S111 to step S113).
[0082] This allows the system to detect a communication failure from ADK10 via the main VCIB41, and enables the door to be unlocked even without a direct command from ADK10 to the body system 36 via the main VCIB41.
[0083] (3) As shown in Figures 4 and 5, the body system 36 may, when it detects a loss of communication via the main VCIB 41, or when it detects that the vehicle 1 has stopped, unlock the doors (for example, in steps S111, S112, S114, and S115) even if it has not received a command from the ADK 10. This makes it possible to unlock the doors even without a command from the ADK 10.
[0084] The embodiments disclosed herein should be considered in all respects to be illustrative and not restrictive. The scope of this disclosure is indicated by the claims rather than by the description of the embodiments above, and all modifications within the meaning and scope equivalent to the claims are intended to be included. [Explanation of Symbols]
[0085] 1 Vehicle, 10 ADK, 11 ADS, 20 VP, 30 Base Vehicle, 31 Integrated Control Manager, 32, 321, 322 Brake System, 33, 331, 332 Steering System, 34 Powertrain System, 35 Active Safety System, 36 Body System, 37, 37A, 38, 39, 43, 44, 45 Communication Bus 40,41,42 VCIB, 51,52 Wheel speed sensor, 53 Pinion angle sensor, 54 Camera, 55,56 Radar sensor, 101,351,361,411,421,3211,3221,3311,3321,3411,3421,3431 Processor, 102,352,362,412,422,3212,3222,3312,3322,3412,3422,3432 Memory, 111 Computer, 111A,111B Communication module, 112 HMI, 113 Recognition sensor, 114 Attitude sensor, 115 Sensor cleaner, 340,341,342 Vehicle fixing system, 343 Propulsion system, 363 Door lock device, 364 Door opening and closing device.
Claims
1. A vehicle configured to enable autonomous driving by allowing the attachment and detachment of an autonomous driving kit that issues instructions for autonomous driving, A base vehicle equipped with doors, A first control system that controls the door in accordance with a command to lock or unlock the door from the autonomous driving kit, A second control system different from the first control system, The system includes a main vehicle control interface box that relays communication between the autonomous driving kit and the first control system, If the first control system can receive the command from the automatic driving kit via the main vehicle control interface box, it locks or unlocks the door in accordance with the command. The second control system, upon detecting a loss of communication via the main vehicle control interface box, issues an instruction to the first control system to unlock the doors during the vehicle's evasive maneuver.
2. The system further includes a sub-vehicle control interface box that relays communication between the autonomous driving kit and the base vehicle and is also capable of communicating with the main vehicle control interface box. The vehicle according to claim 1, wherein the first control system detects a loss of communication from the autonomous driving kit via the main vehicle control interface box, and if it is possible to receive the command from the autonomous driving kit via the sub-vehicle control interface box and the main vehicle control interface box, it locks or unlocks the door in accordance with the command.
3. A vehicle configured to enable autonomous driving by allowing the attachment and detachment of an autonomous driving kit that issues instructions for autonomous driving, A base vehicle equipped with doors, A first control system that controls the door in accordance with a command to lock or unlock the door from the autonomous driving kit, A main vehicle control interface box that relays communication between the autonomous driving kit and the first control system, The system includes a sub-vehicle control interface box that relays communication between the autonomous driving kit and the base vehicle and is also capable of communicating with the main vehicle control interface box. If the first control system can receive the command from the automatic driving kit via the main vehicle control interface box, it locks or unlocks the door in accordance with the command. The first control system, upon detecting a loss of communication from the autonomous driving kit via the main vehicle control interface box, locks or unlocks the doors in accordance with the command if it is possible to receive the command from the autonomous driving kit via the sub-vehicle control interface box and the main vehicle control interface box.
4. The system further comprises a second control system different from the first control system, The vehicle according to claim 3, wherein the second control system, upon detecting a loss of communication via the main vehicle control interface box, issues an instruction to the first control system to unlock the doors during the vehicle's evasive maneuver.
5. The vehicle according to any one of claims 2 to 4, wherein the first control system detects a loss of communication via the main vehicle control interface box, or detects that the vehicle has stopped, and unlocks the doors even if the command is not received from the automatic driving kit.
Citation Information
Patent Citations
vehicle
JP2021123147A