vehicle
The vehicle system with an automated driving system and control interface ensures timely wheel locking during autonomous driving, addressing the need for immobilization without user intervention.
Patent Information
- Application Number
- JP2023104907
- Authority / Receiving Office
- JP · JP
- Patent Type
- Patents
- Current Assignee / Owner
- Filing Date
- 2023-06-27
- Publication Date
- 2025-08-05
- Estimated Expiration
- 2040-01-31
AI Technical Summary
When an autonomous vehicle is parked, the wheels need to be effectively locked to prevent sliding, but the prior art has failed to provide a suitable solution.
By installing an autonomous driving system (ADS) in the vehicle, using the Vehicle Control Interface (VCIB) and the Vehicle Platform (VP) to work in concert, sending commands to lock the wheels, including controls for brake and steering systems, ensuring that the wheels are locked when the vehicle stops.
It realizes the appropriate locking of wheels when parking an autonomous vehicle to ensure safe parking of the vehicle.
Smart Images

Figure 0007718452000109 
Figure 0007718452000110 
Figure 0007718452000111
Abstract
Description
[Technical Field]
[0001] The present disclosure relates to controlling a vehicle during automated driving. [Background technology]
[0002] In recent years, autonomous driving systems that allow vehicles to travel without user operation have been developed. For example, autonomous driving systems may be provided separately from the vehicle via an interface so that they can be installed in existing vehicles.
[0003] As an example of such an automated driving system, Japanese Patent Application Laid-Open Publication No. 2018-132015 (Patent Document 1) discloses an automated driving system that includes an ECU (Electronic Control Unit) that manages the power of a vehicle and an automated driving system. This technology allows for the addition of autonomous driving functions without making major changes to existing vehicle platforms by separating the driving ECU. [Prior art documents] [Patent documents]
[0004] [Patent Document 1] Japanese Patent Application Publication No. 2018-132015 Summary of the Invention [Problem to be solved by the invention]
[0005] However, since no user operations are performed during automatic driving of a vehicle, it is necessary to lock the wheels at an appropriate time using a parking brake, parking lock, etc. when the vehicle is parked.
[0006] The present disclosure has been made to solve the above-mentioned problems, and its purpose is to provide a vehicle that can be equipped with an autonomous driving system and that locks the wheels at an appropriate time during autonomous driving. [Means for solving the problem]
[0007] According to an aspect of the present disclosure, a vehicle can be equipped with an automated driving system. The vehicle includes a vehicle platform that controls the vehicle in accordance with commands from the automated driving system, and a vehicle control interface that interfaces between the automated driving system and the vehicle platform. A first command requesting a deceleration value and a second command requesting immobilization of the vehicle are transmitted from the automated driving system to the vehicle platform via the vehicle control interface. The autonomous driving system creates a driving plan for the vehicle and outputs commands, including a first command and a second command, to the vehicle control interface for driving the vehicle in accordance with the driving plan. A signal indicating the vehicle's stopped state is sent from the vehicle platform to the automated driving system via the vehicle control interface. When the vehicle platform is requested to decelerate by a first command, the vehicle platform sends a signal to the automated driving system when the vehicle has stopped. The vehicle platform immobilizes the vehicle by a second command received after sending the signal. The vehicle platform includes an electric steering system that steers the vehicle. When the driver operates the steering wheel during automated driving, the vehicle platform controls the motor torque of the electric steering system in cooperation with the driver, taking into account the amount of operation of the steering wheel by the driver. When a request to immobilize the vehicle is made by a second command while the vehicle is moving, the vehicle platform rejects the request.
[0008] In this way, after transmitting a signal indicating a stopped state, the vehicle is immobilized by a second command requesting immobilization of the vehicle, so that the wheels can be fixed at an appropriate time when the vehicle comes to a stop.
[0009] In one embodiment, A tire turning angle command indicating the steering wheel turning angle required for performing autonomous driving is further transmitted from the autonomous driving system to the vehicle platform via the vehicle control interface. When the driver performs a steering operation during autonomous driving, the vehicle platform controls the electric steering system so that a motor torque set by the driver's operation amount to the steering wheel and the tire turning angle command is generated. . [Effects of the Invention]
[0022] According to the present disclosure, it is possible to provide a vehicle that can be equipped with an autonomous driving system and that locks the wheels at an appropriate time during autonomous driving. [Brief explanation of the drawings]
[0023] [Figure 1] FIG. 1 is a diagram illustrating an overview of a MaaS system in which a vehicle according to an embodiment of the present disclosure is used. [Figure 2] FIG. 2 is a diagram for explaining in detail the configurations of the ADS, the vehicle control interface, and the VP. [Figure 3] 10 is a flowchart illustrating an example of processing executed by the ADS. [Figure 4] 10 is a flowchart illustrating an example of a process executed by a vehicle control interface. [Figure 5] 10 is a flow chart illustrating an example of the processing performed by the ADS when vehicle immobilization is requested. [Figure 6] 10 is a flowchart illustrating an example of a process executed by the vehicle control interface 110 when immobilization of the vehicle 10 is requested. [Figure 7] 10 is a timing chart for explaining the operation of the ADS, the vehicle control interface, and the VP. [Figure 8] This is an overall configuration diagram of MaaS. [Figure 9] FIG. 1 is a system configuration diagram of a MaaS vehicle. [Figure 10] FIG. 1 is a diagram showing a typical flow of an autonomous driving system. [Figure 11] FIG. 10 is a diagram showing an example of a timing chart of an API related to stopping and starting a MaaS vehicle. [Figure 12] FIG. 10 is a diagram showing an example of a timing chart of an API related to shift changes in a MaaS vehicle. [Figure 13] FIG. 10 is a diagram showing an example of a timing chart of an API related to wheel locking of a MaaS vehicle. [Figure 14] FIG. 10 is a diagram illustrating a limit value of a change amount of a tire turning angle. [Figure 15] FIG. 10 is a diagram illustrating accelerator pedal intervention. [Figure 16]FIG. 10 is a diagram illustrating brake pedal intervention. [Figure 17] This is an overall configuration diagram of MaaS. [Figure 18] FIG. 1 is a system configuration diagram of a vehicle. [Figure 19] FIG. 2 is a diagram illustrating a power supply configuration of a vehicle. [Figure 20] FIG. 10 is a diagram illustrating a strategy for safely stopping the vehicle when an abnormality occurs. [Figure 21] FIG. 1 is a diagram showing the layout of typical functions in a vehicle. DETAILED DESCRIPTION OF THE INVENTION
[0024] Hereinafter, embodiments of the present disclosure will be described in detail with reference to the drawings. In the drawings, the same or corresponding parts are designated by the same reference numerals, and description thereof will not be repeated.
[0025] FIG. 1 is a diagram illustrating an overview of a MaaS (Mobility as a Service) system in which a vehicle according to an embodiment of the present disclosure is used.
[0026] Referring to FIG. 1, the MaaS system includes a vehicle 10, a data server 500, and a mobility service platform (hereinafter referred to as "MSPF"). ) 600 and autonomous driving-related mobility services 700.
[0027] The vehicle 10 includes a vehicle body 100 and an autonomous driving kit (hereinafter referred to as an "ADK (Autonomous Driving Kit)") 200. The vehicle body 100 includes a vehicle control interface 110 and a vehicle platform (hereinafter referred to as a "VP (Vehicle Platform)"). The device includes a data communication module (DCM) 120 and a data communication module (DCM) 190.
[0028] The vehicle 10 automatically operates in accordance with commands from the ADK 200 attached to the vehicle body 100. 1, the vehicle body 100 and the ADK 200 are shown at separate locations, but the ADK 200 is actually attached to the rooftop of the vehicle body 100 or the like. The ADK 200 can also be detached from the vehicle body 100. When the ADK 200 is detached, the vehicle body 100 can be driven by the user. In this case, the VP 100 executes driving control in manual mode (driving control according to user operation).
[0029] The vehicle control interface 110 communicates with the vehicle via a CAN (Controller Area Network) or the like. The vehicle control interface 110 communicates with the ADK 200 by executing a predetermined API (Application Program Interface) defined for each signal to be communicated. It receives various commands from the ADK 200 and outputs the state of the vehicle main body 100 to the ADK 200 .
[0030] When the vehicle control interface 110 receives a command from the ADK 200, it outputs a control command corresponding to the command to the VP 120. The vehicle control interface 110 also acquires various information about the vehicle main body 100 from the VP 120 and outputs the status of the vehicle main body 100 to the ADK 200. The configuration of the vehicle control interface 110 will be described in detail later.
[0031] The VP 120 includes various systems and sensors for controlling the vehicle body 100. The VP 120 executes various vehicle controls in accordance with commands issued from the ADK 200 via the vehicle control interface 110. That is, the VP 120 executes various vehicle controls in accordance with commands from the ADK 200, thereby enabling the vehicle 10 to be driven automatically. The configuration of the VP 120 will also be described in detail later.
[0032] The ADK 200 includes an autonomous driving system (hereinafter referred to as "ADS (Autonomous Driving System)") 202 for performing autonomous driving of the vehicle 10. The ADS 202 includes: For example, the ADS 202 creates a driving plan for the vehicle 10 and outputs various commands for driving the vehicle 10 in accordance with the created driving plan to the vehicle control interface 110 in accordance with an API defined for each command. The ADS 202 also receives various signals indicating the status of the vehicle main body 100 from the vehicle control interface 110 in accordance with an API defined for each signal, and reflects the received vehicle status in the creation of the driving plan. The configuration of the ADS 202 will also be described later.
[0033] DCM 190 includes a communication I / F (interface) for vehicle main body 100 to communicate wirelessly with data server 500. DCM 190 outputs various types of vehicle information, such as speed, position, and autonomous driving status, to data server 500. DCM 190 also receives various types of data for managing the traveling of autonomously driven vehicles, including vehicle 10, in an autonomous driving-related mobility service 700 from mobility service 700 via MSPF 600 and data server 500.
[0034] The MSPF 600 is a unified platform to which various mobility services are connected. In addition to the autonomous driving-related mobility service 700, various mobility services (not shown) (for example, various mobility services provided by ride-sharing operators, car-sharing operators, insurance companies, rental car operators, taxi operators, etc.) are connected to the MSPF 600. The various mobility services including the mobility service 700 can use the APIs published on the MSPF 600 to use the various functions provided by the MSPF 600 according to the service content.
[0035] The autonomous driving-related mobility service 700 is a mobility service using autonomous driving vehicles including the vehicle 10. The mobility service 700 uses an API published on the MSPF 600 to acquire, for example, driving control data of the vehicle 10 communicating with the data server 500, information stored in the data server 500, and the like from the MSPF 600. The mobility service 700 also uses the API to transmit, for example, data for managing autonomous vehicles including the vehicle 10 to the MSPF 600.
[0036] In addition, MSPF600 has released an API for using various vehicle status and vehicle control data required for ADS development, and ADS operators can use the vehicle status and vehicle control data stored in the data server 500 required for ADS development as the above-mentioned API.
[0037] 2 is a diagram for explaining in detail the configuration of the ADS 202, the vehicle control interface 110, and the VP 120. As shown in FIG. 2, the ADS 202 includes a computer 210, an HMI (Human Machine Interface) 230, a recognition sensor 260, and a posture sensor 270. The sensor 270 and the sensor cleaner 290 are included.
[0038] During automatic driving of the vehicle, the computer 210 acquires information about the environment around the vehicle, the attitude, behavior, and position of the vehicle using various sensors described later, and also acquires the vehicle state from the VP 120 described later via the vehicle control interface 110, and sets the next vehicle operation (acceleration, deceleration, turning, etc.). The computer 210 outputs various commands to the vehicle control interface 110 to realize the next vehicle operation that has been set.
[0039] The HMI 230 presents information to the user and accepts operations during automatic driving, during driving requiring user operation, or during transition between automatic driving and driving requiring user operation. The HMI 230 is configured, for example, with a touch panel display, a display device, an operation device, etc.
[0040] The recognition sensor 260 includes a sensor for recognizing the environment around the vehicle, such as a LIDAR (Laser Imaging Detection and Ranging), a millimeter wave radar, and a camera. It is composed of at least one of the following:
[0041] LIDAR is a distance measurement device that emits pulsed laser light (infrared light) and measures distance based on the time it takes for the light to reflect off an object and return. Millimeter-wave radar is a distance measurement device that emits short-wavelength radio waves toward an object and detects the radio waves returning from the object to measure the distance and direction to the object. The camera is placed, for example, behind the rearview mirror inside the vehicle and is used to capture images of the area ahead of the vehicle. Information acquired by the recognition sensor 260 is output to the computer 210. Image processing of the images and videos captured by the camera using artificial intelligence (AI) and an image processing processor makes it possible for the vehicle to recognize other vehicles, obstacles, or people ahead.
[0042] The attitude sensor 270 includes a sensor that detects the attitude, behavior, or position of the vehicle, and is configured by, for example, an IMU (Inertial Measurement Unit) or a GPS (Global Positioning System).
[0043] The IMU detects, for example, the acceleration in the longitudinal, lateral, and vertical directions of the vehicle, and the angular velocities in the roll, pitch, and yaw directions of the vehicle. The GPS detects the position of the vehicle 10 using information received from multiple GPS satellites orbiting the Earth. The information acquired by the attitude sensor 270 is output to the computer 210.
[0044] The sensor cleaner 290 removes dirt that accumulates on various sensors while the vehicle is running. The sensor cleaner 290 removes dirt from the camera lens, laser or radio wave emitting portion, etc., using a cleaning liquid, wiper, etc.
[0045] The vehicle control interface 110 includes a Vehicle Control Interface Box (VCIB) 111 and a VCIB 112. Both the VCIB 111 and the VCIB 112 incorporate a central processing unit (CPU) and memory (including, for example, a read-only memory (ROM), a random access memory (RAM), etc.), both of which are not shown. The B111 has the same functions as the VCIB112, but the connections to the multiple systems that make up the VP120 are partially different.
[0046] The VCIB 111 and the VCIB 112 are each communicably connected to the computer 210 of the ADS 202. Furthermore, the VCIB 111 and the VCIB 112 are communicably connected to each other.
[0047] Each of the VCIB111 and VCIB112 relays various commands from the ADS202 and outputs them to the VP120 as control commands. More specifically, each of the VCIB111 and VCIB112 uses information such as programs stored in memory (for example, APIs) and various command commands output from the ADS202 to generate control commands used to control each system of the VP120 and output them to the connected system. Each of the VCIB111 and VCIB112 also relays vehicle information output from the VP120 and outputs it to the ADS202 as a vehicle status. Note that the information indicating the vehicle status may be the same information as the vehicle information, or may be information extracted from the vehicle information to be used in processing executed by the ADS202.
[0048] By providing VCIB111 and VCIB112, which have equivalent functions for the operation of some systems (for example, braking and steering), the control system between ADS202 and VP120 is made redundant. Therefore, when a failure occurs in part of the system, the function of VP120 (turning, stopping, etc.) can be maintained by switching the control system as appropriate or by shutting off the control system where the failure occurred.
[0049] The VP 120 includes brake systems 121A and 121B, steering systems 122A and 122B, an EPB (Electric Parking Brake) system 123A, a P-Lock system 123B, a propulsion system 124, and a PCS (Pre-Crash Safety) system. 125 and a body system 126.
[0050] The VCIB 111 and the brake system 121B, steering system 122A, EPB system 123A, P-Lock system 123B, propulsion system 124, and body system 126, which are among the multiple systems of the VP 120, are communicatively connected to each other via a communication bus.
[0051] Furthermore, the VCIB 112 and the brake system 121A, steering system 122B, and P-Lock 123B among the multiple systems of the VP 120 are connected to each other via a communication bus so as to be able to communicate with each other.
[0052] Brake systems 121A and 121B are configured to be able to control multiple braking devices provided on each wheel of the vehicle. Brake system 121A may have the same function as brake system 121B, or, for example, one of them may be configured to be able to independently control the braking force of each wheel when the vehicle is traveling, and the other may be configured to be able to control so that the same braking force is generated on each wheel when the vehicle is traveling. The braking devices include, for example, a disc brake system that operates using hydraulic pressure adjusted by an actuator.
[0053] A wheel speed sensor 127 is connected to the brake system 121B. The wheel speed sensor 127 is provided, for example, on each wheel of the vehicle and detects the rotation speed of each wheel. The wheel speed sensor 127 outputs the detected rotation speed of each wheel to the brake system 121B. The brake system 121B outputs the rotation speed of each wheel to the VCIB 111 as one piece of information included in the vehicle information.
[0054] Each of the brake systems 121A, 121B generates a braking command for a braking device in accordance with a predetermined control command output from the ADS 202 via the vehicle control interface 110. Furthermore, for example, one of the brake systems 121A, 121B controls the braking device using the braking command generated in the other brake system, and when an abnormality occurs in one of the brake systems, controls the braking device using the braking command generated in the other brake system.
[0055] The steering systems 122A and 122B are configured to be able to control the steering angle of the steering wheels of the vehicle 10 using a steering device. The steering system 122A has the same functions as the steering system 122B. The steering device may include, for example, a rack and pinion type EPS (Electric Power Steering) that can adjust the steering angle using an actuator. nothing.
[0056] Pinion angle sensor 128A is connected to steering system 122A. Pinion angle sensor 128B, which is provided separately from pinion angle sensor 128A, is connected to steering system 122B. Each of pinion angle sensors 128A and 128B detects the rotation angle (pinion angle) of a pinion gear connected to a rotary shaft of an actuator that constitutes the steering device. Pinion angle sensors 128A and 128B output the detected pinion angles to steering systems 122A and 122B, respectively.
[0057] Each of the steering systems 122A and 122B generates a steering command for the steering device in accordance with a predetermined control command output from the ADS 202 via the vehicle control interface 110. Also, for example, the steering systems 122A and 122B control the steering device using the steering command generated in one of the steering systems, and when an abnormality occurs in one of the steering systems, control the steering device using the steering command generated in the other steering system.
[0058] The EPB system 123A is configured to be able to control an EPB provided on at least one of a plurality of wheels provided on the vehicle 10. The EPB is provided separately from a braking device and fixes the wheel by operating an actuator. For example, the EPB uses an actuator to activate a drum brake for a parking brake provided on some of the plurality of wheels provided on the vehicle 10 to fix the wheel, or it uses an actuator that is separate from the brake systems 121A and 121B and that can adjust the hydraulic pressure supplied to the braking device to activate the braking device to fix the wheel.
[0059] The EPB system 123A controls the EPB in accordance with predetermined control commands output from the ADS 202 via the vehicle control interface 110.
[0060] The P-Lock system 123B is configured to be able to control a P-Lock device provided on the transmission of the vehicle 10. The P-Lock device engages a protrusion provided on the tip of a parking lock pole, the position of which is adjusted by an actuator, with the teeth of a gear (lock gear) connected to a rotating element in the transmission. This fixes the rotation of the output shaft of the transmission, and thus the wheels.
[0061] The P-Lock system 123B controls the P-Lock device in accordance with a predetermined control command output from the ADS 202 via the vehicle control interface 110. For example, the P-Lock system 123B activates the P-Lock device when the control command output from the ADS 202 via the vehicle control interface 110 includes a control command to set the shift range to parking range (hereinafter referred to as P range), and deactivates the P-Lock device when the control command includes a control command to set the shift range to a range other than P range.
[0062] The propulsion system 124 is configured to be capable of switching the shift range using a shift device and to be capable of controlling the driving force of the vehicle 10 in the direction of movement of the vehicle 10 using a drive source. The shift device is configured to be capable of selecting one of a plurality of shift ranges. The plurality of shift ranges include, for example, a P range, a neutral range (hereinafter referred to as an N range), a forward driving range (hereinafter referred to as a D range), and a reverse driving range (hereinafter referred to as an R range). The drive source includes, for example, a motor generator, an engine, etc.
[0063] The propulsion system 124 controls the shift device and the drive source in accordance with a predetermined control command output from the ADS 202 via the vehicle control interface 110. For example, when the control command output from the ADS 202 via the vehicle control interface 110 includes a control command to set the shift range to P range, the propulsion system 124 controls the shift device so that the shift range is set to P range.
[0064] The PCS system 125 controls the vehicle to avoid a collision or reduce damage using the camera / radar 129. The PCS system 125 is connected to the brake system 121B so that it can communicate with the brake system 121B. For example, the PCS system 125 detects an obstacle or the like (an obstacle or a person) ahead using the camera / radar 129, and when it determines that there is a possibility of a collision based on the distance to the obstacle or the like, it outputs a braking command to the brake system 121B to increase the braking force.
[0065] The body system 126 is configured to be able to control components such as turn signals, a horn, or wipers in accordance with the driving state or driving environment of the vehicle 10. The body system 126 controls the above-mentioned components in accordance with predetermined control commands output from the ADS 202 via the vehicle control interface 110.
[0066] Note that an operating device that allows the user to manually operate the above-mentioned braking device, steering device, EPB, P-Lock device, shift device, drive source, etc. may be provided separately.
[0067] The various commands output from ADS202 to vehicle control interface 110 include a propulsion direction command requesting a change in the shift range, an immobilization command requesting activation or deactivation of the EPB or P-Lock device, an acceleration command requesting acceleration or deceleration of vehicle 10, a tire turning angle command requesting the tire turning angle of the steering wheels, and an autonomous command requesting a change in the autonomous state between autonomous mode and manual mode.
[0068] In the vehicle 10 having the above configuration, when the autonomous mode is selected as the autonomous state by, for example, a user operating the HMI 230, the vehicle 10 starts autonomous driving. As described above, the ADS 202 first creates a driving plan during autonomous driving. The driving plan may include, for example, a plan to continue driving straight, a plan to turn left or right at a predetermined intersection along a predetermined driving route, or a plan to change the driving lane. It includes multiple plans regarding the operation of the vehicle 10, such as a plan to change into a lane different from the lane in which the vehicle is traveling.
[0069] The ADS202 extracts control physical quantities (e.g., acceleration or deceleration, tire turning angle, etc.) required for the vehicle 10 to operate in accordance with the created driving plan. The ADS202 divides the physical quantities for each execution cycle of the API. The ADS202 executes the API using the divided physical quantities and outputs various commands to the vehicle control interface 110. Furthermore, the ADS202 acquires vehicle states (e.g., the actual moving direction of the vehicle 10, the vehicle immobilization state, etc.) from the VP120 and recreates a driving plan that reflects the acquired vehicle states. In this way, the ADS202 enables autonomous driving of the vehicle 10.
[0070] When the vehicle 10 is being driven automatically, no user operations are performed, so when the vehicle 10 is parked, it is necessary to lock the wheels using an EPB, P-Lock device, etc. at an appropriate time.
[0071] Therefore, in this embodiment, the following operations are performed between the ADS 202 and the VP 120 via the vehicle control interface 110. That is, as described above, an acceleration command (corresponding to a first command) requesting acceleration or deceleration and an immobilization command (corresponding to a second command) requesting immobilization of the vehicle (wheels locked) are transmitted from the ADS 202 to the VP 120. The actual moving direction of the vehicle 10 (corresponding to a signal) is transmitted from the VP 120 to the ADS 202. When the ADS 202 requests the VP 120 to decelerate using an acceleration command to stop the vehicle 10, the VP 120 requests the VP 120 to immobilize the vehicle 10 using an immobilization command after the actual moving direction indicates the stopped state of the vehicle 10. Furthermore, when deceleration is requested using an acceleration command, the VP 120 transmits a signal to the ADS 202 indicating that the actual moving direction indicates the stopped state when the vehicle 10 stops. The VP 120 immobilizes the vehicle 10 using the immobilization command received after transmitting the signal.
[0072] In this way, the vehicle 10 is immobilized by the immobilization command after the actual direction of movement of the vehicle 10 indicates a stopped state, so that the wheels can be fixed at an appropriate time when the vehicle 10 stops.
[0073] The processing executed by the ADS 202 (more specifically, the computer 210) in this embodiment will be described below with reference to Fig. 3. Fig. 3 is a flowchart showing an example of processing executed by the ADS 202. The ADS 202 repeatedly executes the following processing for each execution cycle of the API, for example.
[0074] In step (hereinafter, step will be abbreviated as S) 11, the ADS202 determines whether the autonomous state is the autonomous mode. The ADS202 determines whether the autonomous state is the autonomous mode, for example, based on the state of a flag indicating the autonomous mode. The flag indicating the autonomous mode is turned on when, for example, a user operation to perform automatic driving is received from the HMI230, and is turned off when the autonomous mode is canceled and switched to manual mode in response to a user operation or the driving situation. If the ADS202 determines that the autonomous state is the autonomous mode (YES in S11), the process proceeds to S12.
[0075] In S12, the ADS 202 determines whether the acceleration command is a value indicating deceleration. The acceleration command indicates an acceleration value or a deceleration value. For example, if the acceleration command is a positive value, the ADS 202 requests the VP 120 to accelerate the vehicle 10. If the acceleration command is a negative value, the ADS 202 requests the VP 120 to accelerate the vehicle 10. This indicates that a deceleration of 10 is requested. If the acceleration command is a negative value, the ADS 202 determines that the acceleration command is a value indicating deceleration. If it is determined that the acceleration command is a value indicating deceleration (YES in S12), the process proceeds to S13.
[0076] In S13, the ADS 202 determines whether the actual moving direction of the vehicle 10 indicates a stopped state. The ADS 202 acquires information about the actual moving direction of the vehicle 10 from the VP 120 as a vehicle state. For example, when the longitudinal speed of the vehicle 10 is zero using the wheel speed acquired by the wheel speed sensor 127 of the VP 120, information indicating that the actual moving direction is a stopped state is output as a vehicle state from the VP 120 to the ADS 202 via the vehicle control interface 110. In this embodiment, the longitudinal direction of the vehicle 10 corresponds, for example, to the traveling direction of the vehicle 10. If it is determined that the actual moving direction of the vehicle 10 indicates a stopped state (YES in S13), the process proceeds to S14.
[0077] In S14, the ADS 202 determines whether a wheel lock request is present. The ADS 202 determines that a wheel lock request is present when, for example, the created driving plan includes a plan to immobilize the vehicle 10. If it is determined that a wheel lock request is present (YES in S14), the process proceeds to S15.
[0078] In S15, the ADS 202 sets the immobilization command to "Applied." That is, the VP 120 is requested to immobilize the vehicle 10. Therefore, when the immobilization command is set to "Applied," the EPB and P-Lock device are controlled to operate in the VP 120, as will be described later.
[0079] In S16, the ADS 202 sets V1 as an acceleration command. V1 indicates a constant deceleration value. For example, V1 is -0.4 m / s 2 is.
[0080] In S17, the ADS 202 determines whether the immobility status is 11. The immobility status is output from the VP 120 via the vehicle control interface 110 as one of the vehicle states.
[0081] The immobility status is set by combining a value indicating the EPB status and a value indicating the P-Lock device status. When the value indicating the EPB status is "1," it indicates that the EPB is activated. When the value indicating the EPB status is "0," it indicates that the EPB is deactivated. Similarly, when the value indicating the P-Lock device status is "1," it indicates that the P-Lock device is activated. When the value indicating the P-Lock device status is "0," it indicates that the P-Lock device is deactivated. Therefore, for example, when the value indicating the immobility status is "11," it indicates that both the EPB and the P-Lock device are activated. When the value indicating the immobility status is "00," it indicates that both the EPB and the P-Lock device are deactivated. Furthermore, when the value indicating the immobility status is "10," it indicates that the EPB is activated and the P-Lock device is deactivated. Furthermore, when the value indicating the immobility status is "01," it indicates that the EPB is deactivated and the P-Lock device is activated. If it is determined that the immobile status is "11" (YES in S17), the process proceeds to S18.
[0082] In S18, the ADS 202 sets the acceleration command to zero, in which case the vehicle 10 is controlled to maintain a stationary state.
[0083] Note that if the autonomous state is not the autonomous mode (NO in S11), if the acceleration command is not a value indicating deceleration (NO in S12), or if the actual moving direction does not indicate a stopped state, If the immobility status is not set to "11" (NO in S17), or if there is no wheel lock request (NO in S14), the process ends.
[0084] Next, the processing executed by the vehicle control interface 110 (more specifically, the VCIB 111) will be described with reference to Fig. 4. Fig. 4 is a flowchart showing an example of the processing executed by the vehicle control interface 110. The vehicle control interface ADS 202 repeatedly executes the following processing for each execution cycle of the API, for example.
[0085] In S21, the vehicle control interface 110 determines whether the immobilization command is set to “Applied.” If it is determined that the immobilization command is set to “Applied” (YES in S21), the process proceeds to S22.
[0086] In S22, the vehicle control interface 110 determines whether the actual moving direction of the vehicle 10 indicates a stopped state. If it is determined that the actual moving direction of the vehicle 10 indicates a stopped state (YES in S22), the process proceeds to S23.
[0087] In S23, vehicle control interface 110 executes wheel lock control. Specifically, vehicle control interface 110 outputs a control command to EPB system 123A requesting that the EPB be activated, and outputs a control command to P-Lock system 123B requesting that the P-Lock device be activated (a control command requesting that the shift range be changed to P range).
[0088] In S24, vehicle control interface 110 determines whether wheel lock control has been completed. Vehicle control interface 110 determines that wheel lock control has been completed when both EPB and P-Lock are activated.
[0089] The vehicle control interface 110 may determine that the EPB is in an activated state, for example, when a predetermined time has elapsed since outputting a control command requesting that the EPB be activated, or may determine that the EPB is in an activated state when the amount of actuation of the EPB actuator exceeds a threshold value.
[0090] Similarly, the vehicle control interface 110 may determine that the P-Lock device is in an activated state when a predetermined time has elapsed since outputting a control command requesting that the P-Lock device be activated, or when the amount of operation of the actuator of the P-Lock device exceeds a threshold value. If it is determined that wheel lock control has been completed (YES in S24), the process proceeds to S25.
[0091] In S25, the vehicle control interface 110 sets the immobility status to "11." When the value indicating the immobility status is "11," it indicates that both the EPB and the P-Lock device are in an activated state. The vehicle control interface 110 outputs the set immobility status to the ADS 202 as one piece of information included in the vehicle status. Note that if it is determined that the actual direction of movement does not indicate a stopped state (NO in S22), the process proceeds to S26.
[0092] In S26, the vehicle control interface 110 rejects the command. Specifically, even if the immobilization command is set to "Applied", the vehicle control interface 110 rejects the command by not executing wheel lock control. Note that the vehicle control interface 110 stores information indicating that wheel lock control is not being executed in the ADS2 It may also be output to 02.
[0093] If it is determined that the immobilization command is not set to "Applied" (NO in S21), this process ends. If it is determined that the wheel lock control is not completed (NO in S24), the process returns to S24.
[0094] Next, a process executed by the ADS 202 when immobilization of the vehicle 10 is requested will be described with reference to Fig. 5. Fig. 5 is a flowchart showing an example of a process executed by the ADS 202 when immobilization of the vehicle 10 is requested. The ADS 202 repeatedly executes the following process, for example, at each execution cycle of the API.
[0095] In S31, the ADS202 determines whether the autonomous state is the autonomous mode. The method for determining whether the autonomous mode is the autonomous mode is as described above, and therefore detailed description thereof will not be repeated. If it is determined that the autonomous state is the autonomous mode (YES in S31), the process proceeds to S32.
[0096] In S32, the ADS202 has the immobility command set to “Applied” (That is, it is determined whether immobilization of the vehicle 10 has been requested.) If it is determined that the immobilization command is set to "Applied" (YES in S32), the process proceeds to S33.
[0097] In S33, the ADS 202 determines whether a wheel unlock request is present. For example, the ADS 202 determines that a wheel unlock request is present when the created driving plan includes a plan to drive the vehicle. If it is determined that a wheel unlock request is present (YES in S33), the process proceeds to S34.
[0098] In S34, the ADS 202 determines whether the actual moving direction of the vehicle 10 indicates a stopped state. The method for determining whether the actual moving direction indicates a stopped state is as described above, and therefore detailed description thereof will not be repeated. If it is determined that the actual moving direction of the vehicle 10 indicates a stopped state (YES in S34), the process proceeds to S35.
[0099] At S35, the ADS202 sets the immobility command to "Released." That is, a request is made to the VP 120 to release the immobilization of the vehicle 10. When the immobilization command is set to "Released," the EPB and P-Lock device are both controlled to be in an inactive state, as will be described later.
[0100] In S36, the ADS 202 sets the acceleration command to zero, in which case the vehicle 10 is controlled to maintain a stationary state.
[0101] Next, the processing executed by the vehicle control interface 110 when immobilization of the vehicle 10 is requested will be described with reference to Fig. 6. Fig. 6 is a flowchart showing an example of processing executed by the vehicle control interface 110 when immobilization of the vehicle 10 is requested. The vehicle control interface 110 repeatedly executes the following processing for each API execution cycle, for example.
[0102] In S41, the vehicle control interface 110 determines whether the immobilization command is set to “Released.” If it is determined that the immobilization command is set to “Released” (YES in S41), the process proceeds to S42.
[0103] In S42, the vehicle control interface 110 executes wheel lock release control. Specifically, the vehicle control interface 110 outputs a control command to the EPB system 123A requesting that the EPB be deactivated, and outputs a control command to the P-Lock system 123B requesting that the P-Lock device be deactivated (for example, a control command requesting that the shift range be set to a non-P range (for example, N range, D range, or R range)).
[0104] In S43, the vehicle control interface 110 sets the immobility status to "00." When the value indicating the immobility status is "00," it indicates that both the EPB and the P-Lock device are in an inoperative state. The vehicle control interface 110 outputs the set immobility status to the ADS 202 as one piece of information included in the vehicle status.
[0105] The operation of the ADS202, vehicle control interface 110, and VP20 based on the above-described structure and flowchart will be described with reference to FIG. 7. FIG. 7 is a timing chart for explaining the operation of the ADS202, vehicle control interface 110, and VP120. The horizontal axis of FIG. 7 represents time. LN1 in FIG. 7 represents a change in longitudinal velocity. LN2 in FIG. 7 represents a change in acceleration command. LN3 in FIG. 7 represents a change in actual movement direction. LN4 in FIG. 7 represents a change in immobility command. LN5 in FIG. 7 represents a change in immobility status. LN6 in FIG. 7 represents a change in the state of the EPB. LN7 in FIG. 7 represents a change in the state of the P-Lock device.
[0106] For example, assume that an autonomously driven vehicle 10 is traveling at a constant speed, as shown in LN1 of FIG. 7. At this time, the value indicating the acceleration command is zero, as shown in LN2 of FIG. 7. Also, the actual direction of movement is forward, as shown in LN3 of FIG. 7. Furthermore, the immobility command is set to "Released," as shown in LN4 of FIG. 7. Furthermore, the immobility status is "00," as shown in LN5 of FIG. 7, and both the EPB and P-Lock devices are inactive, as shown in LN6 and LN7 of FIG. 7.
[0107] At time t1, if the driving plan created by the ADS 202 includes a deceleration plan, the acceleration command will be set to a value indicating deceleration according to the driving plan, as shown in LN2 of Fig. 7. Therefore, the longitudinal speed will decrease after time t1, as shown in LN1 of Fig. 7.
[0108] When the autonomous state is the autonomous mode (YES in S11) and the acceleration command reaches a value indicating deceleration (YES in S12), it is determined whether the actual moving direction indicates a stop (S13).
[0109] At time t2, as shown in LN1 of FIG. 7, when the vertical velocity becomes zero, the actual moving direction shows a stopped state as shown in LN3 of FIG.
[0110] At time t3, if the actual moving direction indicates a stopped state (YES in S13) and there is a wheel lock request (YES in S14), the immobility command is set to "Applied" (S14), as shown in LN4 of Fig. 7. Then, a fixed deceleration value V1 is set as an acceleration command (S15), as shown in LN2 of Fig. 7.
[0111] When the immobility command is set to "Applied" (YES in S21) and the actual moving direction indicates a stopped state (YES in S22), wheel lock control is executed (S23). As a result, both the EPB and the P-Lock device are controlled to be in an activated state. As shown in LN6 and LN7 in FIG. 7, when the wheel lock control is completed by both the EPB and the P-Lock device being in an activated state (YES in S24), LN in FIG. As shown in FIG. 5, the immobile status is set to "11" (S25).
[0112] At time t4, when the immobile status is set to "11" (YES in S16), the value of the acceleration command becomes zero.
[0113] At time t5, if the autonomous state is the autonomous mode (YES in S31) and the immobility command is set to "Applied" (YES in S32), it is determined whether or not there is a wheel lock release request (S33).
[0114] If the travel plan created by the ADS 202 includes a plan to release the immobilization of the vehicle 10, wheel lock release is requested in accordance with the travel plan (YES in S33). Therefore, as shown in LN3 of Fig. 7, the actual movement direction indicates a stopped state (YES in S34), and the immobilization command is set to "Released" (S35), as shown in LN4 of Fig. 7. Then, as shown in LN2 of Fig. 7, a fixed deceleration value V1 is set as the acceleration command (S36).
[0115] When the immobilization command is set to "Released" (YES in S41), wheel lock release control is executed (S42). As a result, as shown in LN6 and LN7 in Figure 7, the EPB and P-Lock devices are both controlled to be in an inactive state, and the immobilization status is set to "00" (S43), as shown in LN5 in Figure 7.
[0116] As described above, with vehicle 10 according to the present embodiment, the wheels of vehicle 10 are locked by an immobilization command after the actual direction of travel indicates a stopped state, so that the wheels can be locked at an appropriate timing using EPB and P-Lock when vehicle 10 stops. Therefore, it is possible to provide a vehicle that can be equipped with an autonomous driving system and that locks the wheels at an appropriate timing during autonomous driving.
[0117] Furthermore, until the immobility command is set to "Applied", the value V1 (-0.4 m / s 2 ) is required. Therefore, movement of the vehicle 10 can be restricted until the vehicle 10 is immobilized.
[0118] Furthermore, when the immobilization of the vehicle 10 is to be released, an immobilization command is issued to request the release of the immobilization of the vehicle 10 while the vehicle 10 is stopped, and an acceleration command is issued to request deceleration. Therefore, the movement of the vehicle 10 can be restricted until the immobilization of the vehicle 10 is released.
[0119] Furthermore, if a request to immobilize vehicle 10 is made by an immobilization command while vehicle 10 is moving, the request is rejected, thereby preventing immobilization of vehicle 10 (i.e., wheel lock control) while vehicle 10 is moving.
[0120] Furthermore, when the immobilization command is used to request either the immobilization of the vehicle 10 or the release of the immobilization of the vehicle, a constant value V1 (-0.4 m / s 2 ) is required. Therefore, movement of the vehicle 10 can be restricted until the immobilization of the vehicle 10 is implemented or until the immobilization of the vehicle 10 is released.
[0121] Furthermore, by exchanging various commands such as acceleration commands and immobility commands, as well as vehicle status such as the actual direction of movement, between ADS202 and VP120 via the vehicle control interface 110, the wheels can be locked at the appropriate time using the EPB or P-Lock device when the vehicle 10 stops.
[0122] Modifications will be described below.
[0123] In the above embodiment, it has been described that VCIB111 executes the process shown in the flowchart of FIG. 4 and the process shown in the flowchart of FIG. 6, but for example, VCIB111 and VCIB112 may cooperate to execute the above-mentioned processes.
[0124] Furthermore, in the above-described embodiment, the vehicle control interface 110 has been described as executing the processing shown in the flowchart of FIG. 4 and the processing shown in the flowchart of FIG. 6, but, for example, some or all of the above-described processing may be executed in each system that is subject to the control of the VP 120 (specifically, the EPB system 123A and the P-Lock system 123B).
[0125] The above-described modifications may be implemented in whole or in part in appropriate combination. [Example]
[0126] Toyota's MaaS Vehicle Platform API Specification for ADS Developers [Standard Edition #0.1] Revision History [Table 1] table of contents 1. Outline 4 1.1. Purpose of this Specification 4 1.2. Target Vehicle 4 1.3. Definition of Term 4 1.4. Precaution for Handling 4 2. Structure 5 2.1. Overall Structure of MaaS 5 2.2. System structure of MaaS vehicle 6 3. Application Interfaces 7 3.1. Responsibility sharing of when using APIs 7 Typical usage of APIs 7 3.3. APIs for vehicle motion control 9 Functions 9 Inputs 16 3.3.3. Outputs 23 3.4. APIs for BODY control 45 Functions 45 3.4.2. Inputs 45 3.4.3. Outputs 56 3.5. APIs for Power control 68 Functions 68 3.5.2. Inputs 68 3.5.3. Outputs 69 3.6. APIs for Safety 70 3.6.1. Functions 70 3.6.2. Inputs 70 3.6.3. Outputs 70 3.7. APIs for Security 74 Functions 74 3.7.2. Inputs 74 3.7.3. Outputs 76 3.8. APIs for MaaS Service 80 3.8.1. Functions 80 3.8.2. Inputs 80 3.8.3. Outputs 80 1. Outline 1.1. Purpose of this Specification This document is an API specification of Toyota Vehicle Platform and contains the outline, the usage and the caveats of the application interface. This document is the API specification for Toyota's Vehicle Platform and provides an overview of the Application Interface. It includes instructions on how to use the product and precautions to take.
[0127] 1.2. Target Vehicle e-Palette, MaaS vehicle based on the POV(Privately Owned Vehicle) manufactured by Toyota The vehicles covered in this document are MaaS vehicles based on the e-Palette and commercially available vehicles manufactured by Toyota. do.
[0128] 1.3. Definition of Term [Table 2] 1.4. Precaution for Handling This is an early draft of the document. All the contents are subject to change. Such changes are notified to the users. Please note that some parts are still TBD will be updated in the future. This book is an Early Draft version. Please note that the information may be subject to change. If there are any changes to the information, we will contact you separately. Also, since the detailed design is still in progress, there are some TBD items here and there, but we will update them accordingly.
[0129] 2. Structure 2.1. Overall Structure of MaaS The overall structure of MaaS with the target vehicle is shown. The overall configuration of MaaS using the target vehicle is shown below (Figure 8). Vehicle control technology is being used as an interface for technology providers. Technology providers can receive open API such as vehicle state and vehicle control, necessary for development of automated driving systems. The target vehicles in this document are those that interface vehicle control technology to ADS operators. ADS operators will disclose the vehicle status and vehicle operation status necessary for the development of autonomous driving systems. Both controls can be used as APIs.
[0130] 2.2. System structure of MaaS vehicle The system architecture as a premise is shown. The assumed system configuration is shown below (Figure 9). The target vehicle will adopt the physical architecture of using CAN for the bus between ADS and VCIB. In order to realize each API in this document, the CAN frames and the bit assignments are shown in the form of “bit assignment table” as a separate document. The vehicle covered by this document has a physical configuration in which the connection bus to the vehicle (VCIB) is configured as CAN. . To implement each API in this book using CAN, you will need to specify the CAN frame and data bit assignments separately. It is presented as a "bit assignment table."
[0131] 3. Application Interfaces 3.1. Responsibility sharing of when using APIs Basic responsibility sharing between ADS and vehicle VP is as follows when using APIs. The basic division of responsibilities between ADS and VP when using the API is as follows: [ADS] The ADS should create the driving plan, and should indicate vehicle control values to the VP. [VP] The Toyota VP should control each system of the VP based on indications from an ADS .
[0132] Typical usage of APIs In this section, typical usage of APIs is described. This section describes typical API usage. CAN will be adopted as a communication line between ADS and VP. Therefore, basically, APIs should be executed every defined cycle time of each API by ADS. CAN is used as the communication line between ADS and VP. Therefore, basically, APIs must be executed from ADS at the intervals defined for each API. A typical workflow of ADS of when executing APIs is as follows. A typical flow of ADS when executing an API is shown below (Figure 10).
[0133] 3.3. APIs for vehicle motion control In this section, the APIs for vehicle motion control which is controllable in the MaaS vehicle is described. This section explains the vehicle control API that can be controlled by MaaS vehicles and how to use it. .
[0134] Functions 3.3.1.1.Standstill, Start Sequence The transition to the standstill (immobility) mode and the vehicle start sequence are described. This function presupposes the vehicle is in Autonomy_State = Autonomous Mode. The request is rejected in other modes. This section describes how to transition to Standstill and how to start. This function assumes that Autonomy_State = Autonomous Mode. Requests made in any other mode will be rejected. The diagram below shows an example. The figure below shows an example. Acceleration Command requests deceleration and stops the vehicle. Then, when Longitudinal_Velocity is confimed as 0[km / h], Standstill Command=“Applied” is sent. After the brake hold control is finished, Standstill Status becomes “Applied”. Until then, Acceleration Command has to continue deceleration request. Either Standstill Command=”Applied” or Acceleration Command's deceleration request were canceled, the transition to the brake hold control will not happen. After that, the vehicle continues to be standstill as far as Standstill Command=”Applied” is being sent. Acceleration Command can be set to 0 (zero) during this period. The Acceleration Command requests deceleration and stops the vehicle. After that, when Longitudinal_Velocity is confirmed as 0 [km / h], it requests Standstill Command = "Applied". When brake hold control is completed, Standstill Status = "Applied". Then During this time, the Acceleration Command must continue to request deceleration. If Standstill Command = "Applied" or the deceleration request of Acceleration Command is canceled, the system will not transition to brake hold control. After that, Standstill will continue as long as Standstill Command = "Applied" is requested. During this time, Acceleration Command can be set to 0. If the vehicle needs to start, the brake hold control is canceled by setting Standstill Command to “Released”. At the same time, acceleration / deceleration is controlled based on Acceleration Command. When you want to start moving, release the brake hold by setting Standstill Command = “Released”. At the same time, acceleration and deceleration are controlled according to the Acceleration Command (Fig. 11). EPB is engaged when Standstill Status = ”Applied” continues for 3 minutes. EPB will activate after 3 minutes of Standstill Status = "Applied".
[0135] 3.3.1.2. Direction Request Sequence The shift change sequence is described. This function presupposes that Autonomy_State = Autonomous Mode. Otherwise, the request is rejected. This describes how to change shifts. This function assumes Autonomy_State = Autonomous Mode. Any other request will be rejected. Shift change happens only during Actual_Moving_Direction=”standstill”). Otherwise, the request is rejected. Shift changes can only be performed when the vehicle is stopped (Actual_Moving_Direction="standstill"). Otherwise, the request will be rejected. In the following diagram shows an example. Acceleration Command requests deceleration and makes the vehicle stop. After Actual_Moving_Direction is set to ”standstill”, any shit position can be requested by Propulsion Direction Command. (In the example below, “D”→”R”). During shift change, Acceleration Command has to request deceleration. After the shift change, acceleration / decekeration is controlled based on Acceleration Command value. The figure below shows an example. The Acceleration Command requests a deceleration to stop the vehicle. After Actual_Moving_Direction="standstill", Propulsion Direction Command A desired shift range is requested by (In the example below, switching from "D" to "R") During a shift change, the Acceleration Command must simultaneously request Deceleration. After the change, acceleration / deceleration is performed as necessary according to the Acceleration Command value (Fig. 12).
[0136] WheelLock Sequence The engagement and release of wheel lock is described. This function presupposes Autonomy_State = Autonomous Mode, other wise the request is rejected. This section describes how to apply and release WheelLock. This function is available only when Autonomy_State = Autonomous Mode. Requests made in any other mode will be rejected. This function is conductible only during vehicle is stopped. Acceleration Command requests deceleration and makes the vehicle stop. After Actual_Moving_Direction is set to ”standstill”, WheelLock is engaged by Immobilization Command = “Applied”. Acceleration Command is set to Deceleration until Immobilization Status is set to “Applied”. This function can only be performed when the Acceleration Command is Deceleration. Request speed and stop the vehicle. After Actual_Moving_Direction = "standstill", apply WheelLock with Immobilization Command = "Applied". Until the Immobilization Status becomes "Applied", the Acceleration Command is Deceleration (-0.4m / s^2). If release is desired, Immobilization Command = “Release” is requested when the vehicle is stationary. Acceleration Command is set to Deceleration at that time. To release the immobilization, request Immobilization Command = "Release" while the vehicle is stopped. At that time, the Acceleration Command should be Deceleration. After this, the vehicle is accelerated / decelerated based on Acceleration Command value. After that, the acceleration / deceleration is performed according to the value of Acceleration Command (Figure 13).
[0137] 3.3.1.4. Road_Wheel_Angle Request Steering Method This function presupposes Autonomy_State = “Autonomous Mode”, and the request is rejected otherwise. This function is based on the Autonomy_State = “Autonomous Mode” condition. Requests made in any other state will be rejected. Tire Turning Angle Command is the relative value from Estimated_Road_Wheel_Angle_Actual. Tire Turning Angle Command is entered relative to Estimated_Road_Wheel_Angle_Actual. To exert effort. For example, in case that Estimated_Road_Wheel_Angle_Actual =0.1 [rad] while the vehicle is going straight; If ADS requests to go straight ahead, Tire Turning Angle Command should be set to 0+0.1 =0.1[rad]. If ADS requests to steer by -0.3 [rad], Tire Turning Angle Command should be set to -0.3+0.1 = -0.2[rad] For example, if the vehicle is traveling straight, but Estimated_Road_Wheel_Angle_Actual indicates 0.1 [rad]. If you want to request a straight line from ADS, the Tire Turning Angle Command will output 0+0.1 = 0.1 [rad]. To exert effort. If you want to request steering of -0.3 [rad] from ADS, specify a Tire Turning Angle Command of -0.3 + 0.1 = -0.2 [rad].
[0138] 3.3.1.5. Rider Operation 3.3.1.5.1. Acceleration Pedal Operation While in Autonomous driving mode, accelerator pedal stroke is eliminated from the vehicle acceleration demand selection. During autonomous driving mode, operation of the accelerator pedal is excluded from the selection of the vehicle's required acceleration.
[0139] 3.3.1.5.2. Brake Pedal Operation The action when the brake pedal is operated. In the autonomy mode, target vehicle deceleration is the sum of 1) estimated deceleration from the brake pedal stroke and 2) deceleration request from AD system This section describes the operation when the brake pedal is operated. During autonomous driving mode, 1) the acceleration / deceleration estimated from the amount of brake pedal operation, and 2) The sum of the deceleration request input from the system is set as the target acceleration of the vehicle.
[0140] 3.3.1.5.3. Shift_Lever_Operation Shift lever operation In Autonomous driving mode, driver operation of the shift lever is not reflected in Propulsion Direction Status. If necessary, ADS confirms Propulsion Direction by Driver and changes shift position by using Propulsion Direction Command. During autonomous driving mode, the driver's shift lever operation is is not reflected in. If necessary, ADS checks the Propulsion Direction by Driver and If necessary, a change in shift position is requested using a Propulsion Direction Command.
[0141] 3.3.1.5.4. Steering Operation When the driver (rider) operates the steering, the maximum is selected from 1) the torque value estimated from driver operation angle, and 2) the torque value calculated from requested wheel angle. When the driver operates the steering wheel, The maximum value is selected from the torque value estimated from the driver's operation amount and the torque value calculated from the requested steering angle. Note that Tire Turning Angle Command is not accepted if the driver strongly turns the steering wheel. The above-mentioned is determined by Steering_Wheel_Intervention flag. However, if the driver applies strong steering force, the Tire Turning Angle Command will not be accepted. The above is determined by the Steering_Wheel_Intervention flag.
[0142] Inputs [Table 3] 3.3.2.1. Propulsion Direction Command Request to switch between forward (D range) and back (R range) Shift range (R / D) switching request Values [Table 4] Remarks ·Only available when Autonomy_State = “Autonomous Mode”. Only Autonomy_State = “Autonomous Mode” can be used ·D / R is changeable only the vehicle is stationary (Actual_Moving_Direction=”standstill”). Switch only when the vehicle is stopped (Actual_Moving_Direction="standstill") It is possible. ·The request while driving (moving) is rejected. If requested while driving, decline ·When system requests D / R shifting, Acceleration Command is sent deceleration(-0.4m / s^2) simultaneously. (Only while brake is applied.) When requesting D / R switching, a deceleration value is also requested via Acceleration Command. (Assuming operation with the brakes held) ·The request may not be accepted in following cases. ·Direction_Control_Degradation_Modes = ”Failure detected” Your request may not be accepted in the following cases: ·Direction_Control_Degradation_Modes = ”Failure detected”
[0143] 3.3.2.2. Immobilization Command Request to engage / release WheelLock Request WheelLock application / release. Values [Table 5] Remarks ·Available only when Autonomy_State = “Autonomous Mode”. Only Autonomy_State = “Autonomous Mode” can be used ·Changeable only when the vehicle is stationary (Actual_Moving_Direction=”standstill”). Switching only when the vehicle is stopped (Actual_Moving_Direction="standstill") It is possible. ·The request is rejected when vehicle is running. If requested while driving, decline ·When Apply / Release mode change is requested, Acceleration Command is set to deceleration(-0.4m / s^2). (Only while brake is applied.) When requesting a change in Applied / Released, a deceleration value (-0.4m / s^2) for the Acceleration Command is also requested. (Assuming operation with the brakes held)
[0144] Standstill Command Request the vehicle to be stationary Request permission / release from parking hold Values [Table 6] Remarks ·Only available when Autonomy_State = “Autonomous Mode”. Only Autonomy_State = “Autonomous Mode” can be used ·Confirmed by Standstill Status = “Applied”. Check if Standstill Status = “Applied”. ·When the vehicle is stationary (Actual_Moving_Direction=”standstill”), transition to Stand Still is enabled. If the vehicle is stopped (Actual_Moving_Direction="standstill"), transition to Standstill is allowed. ·Acceleration Command has to be continued until Standstill Status becomes “Applied” and Acceleration Command's deceleration request (-0.4m / s^2) should be continued. Until Standstill Status = "Applied", it is necessary to continue requesting "Applied" and request a deceleration value (-0.4m / s^2) for the Acceleration Command. Requests may not be accepted. For details, see TBD. There are more cases where the request is not accepted. Details are TBD Acceleration Command Command vehicle acceleration. Indicate vehicle acceleration Values Estimated_Max_Decel_Capability to Estimated_Max_Accel_Capability [m / s2] Remarks ·Only available when Autonomy_State = “Autonomous Mode”. Only Autonomy_State = “Autonomous Mode” can be used ·Acceleration (+) and deceleration (-) request based on Propulsion Direction Status direction. Acceleration (+) and deceleration (-) requests for the direction of the Propulsion Direction Status. ·The upper / lower limit will vary based on Estimated_Max_Decel_Capability and Estimated_Max_Accel_Capability. Estimated_Max_Decel_Capability and Estimated_Max_Accel_Capability determine the acceleration. The upper and lower limits vary. ·When acceleration more than Estimated_Max_Accel_Capability is requested, the request is set to Estimated_Max_Accel_Capability. If you request a value greater than or equal to Estimated_Max_Accel_Capability, The required value is controlled as Estimated_Max_Accel_Capability. ·When deceleration more than Estimated_Max_Decel_Capability is requested, the request is set to Estimated_Max_Decel_Capability. If you request a value greater than or equal to Estimated_Max_Decel_Capability, The required value is controlled as Estimated_Max_Decel_Capability. ·Depending on the accel / brake pedal stroke, the requested acceleration may not be met. See 3.4.1.4 for More detail. Depending on the amount of accelerator or brake pedal operation, the vehicle may not respond to the requested acceleration. For details, see 3.3.1.4 ·When Pre-Collision system is activated simultaneously, minimum acceleration (maximum deceleration) is selected. If the Pre-Collision System is activated simultaneously, the minimum acceleration required by each system will be selected.
[0145] 3.3.2.5. Tire Turning Angle Command Requires front tire turning angle. Values [Table 7] Remarks ·Left is positive value(+). right is negative value(-). ·Available only when Autonomy_State = “Autonomous Mode” Only Autonomy_State = “Autonomous Mode” can be used ·The output of Estimated_Road_Wheel_Angle_Actual when the vehicle is going straight, is set to the reference value (0). The value output by Estimated_Road_Wheel_Angle_Actual when the vehicle is going straight is set as the reference value (0). ·This equests relative value of Estimated_Road_Wheel_Angle_Actual. (See 3.4.1.1 for details) Requests the relative value of Estimated_Road_Wheel_Angle_Actual (see 3.4.1.1 for details). ·The requested value is within Current_Road_Wheel_Angle_Rate_Limit. Request a steering angle value that does not exceed Current_Road_Wheel_Angle_Rate_Limit. ·The requested value may not be fulfilled depending on the steer angle by the driver. Depending on the amount of steering by the driver, the value may not be achieved.
[0146] 3.3.2.6. Autonomization Command Request to transition between manual mode and autonomy mode Values [Table 8] Remarks ·The mode may be able not to be transitioned to Autonomy mode. (eg In case that a failure occurs in the vehicle platform.)
[0147] Outputs [Table 9]
[0148] 3.3.3.1. Propulsion Direction Status Current shift range Current shift range Values [Table 10] Remarks ·When the shift range is indeterminate., this output is set to “Invalid Value ". If the shift range is indefinite, "Invalid value" is output. ·When the vehicle becomes the following status during VO mode, [Propulsion Direction Status] will turn to “P”. - [Longitudinal_Velocity] = 0 [km / h] - [Brake_Pedal_Position] < Threshold value (TBD) (in case of being determined that the pedal isn't depressed) - [1st_Left_Seat_Belt_Status] = Unbuckled - [1st_Left_Door_Open_Status] = Opened 3.3.3.2. Propulsion Direction by Driver Shift lever position by driver operation Shift lever position operated by the driver Values [Table 11] Remarks ·Output based on the lever position operated by driver When the driver operates the lever, it outputs according to the lever position. ·If the driver releases his hand of the shift lever, the lever returns to the central position and the output is set as “No Request”. When the driver releases the lever, the lever returns to its original position and outputs "No request" ·When the vehicle becomes the following status during NVO mode, [Propulsion Direction by Driver] will turn to “1(P)”. - [Longitudinal_Velocity] = 0 [km / h] - [Brake_Pedal_Position] < Threshold value (TBD) (in case of being determined that the pedal isn't depressed) - [1st_Left_Seat_Belt_Status] = Unbuckled - [1st_Left_Door_Open_Status] = Opened 3.3.3.3. Immobilization Status Output EPB and Shift-P status Outputs the state of EPB and shift P. Values <primary>
Table 12
Table 20
Table 21
Table 22
Table 44
Table 45
Table 46
Table 47
Table 48
Table 49
Table 50
Table 51
Table 52
Table 53
Table 63
Table 64
Table 65
Table 66
Table 67
Table 68
Table 69
Table 70
Table 71
Table 72
Table 73
Table 74
Table 75
Table 87
[0149] Toyota's MaaS Vehicle Platform Architecture Specification [Standard Edition #0.1] Revision History [Table 105] table of contents 1. General Concept 4 1.1. Purpose of this Specification 4 1.2. Target Vehicle Type 4 1.3. Target Electronic Platform 4 1.4. Definition of Term 4 1.5. Precaution for Handling 4 1.6. Overall Structure of MaaS 4 1.7. Adopted Development Process 6 1.8. ODD(Operational Design Domain) 6 2. Safety Concept 7 Outline 7 2.2. Hazard analysis and risk assessment 7 2.3. Allocation of safety requirements 8 2.4. Redundancy 8 3. Security Concept 10 Outline 10 3.2. Assumed Risks 10 3.3. Countermeasure for the risks 10 3.3.1. The countermeasure for a remote attack 11 3.3.2. The countermeasure for a modification 11 3.4. Handling of Retained Data Information 11 3.5. Vulnerability Response 11 3.6. Contract with the Operator 11 4. System Architecture 12 4.1. Outline 12 4.2. Physical LAN architecture (in-vehicle) 12 4.3. Power Supply Structure 14 5. Function Allocation 15 5.1. in a healthy situation 15 5.2. in a single failure 16 6. Data Collection 18 6.1. At event 18 6.2. Constantly 18 1. General Concept 1.1. Purpose of this Specification This document is an architecture specification of Toyota's MaaS Vehicle Platform and contains the outline of system in vehicle level. This document is an architectural specification for Toyota's Vehicle Platform and describes an overview of the vehicle-level system. 1.2. Target Vehicle Type This specification is applied to the Toyota vehicles with the electronic platform called 19ePF[ver.1 and ver.2]. The representative vehicle with 19ePF is shown as follows. e-Palette, Sienna, RAV4, and so on. This document applies to vehicles that use 19-electron power plants. Representative vehicles equipped with 19-electron power plants include the e-Palette, Sienna, and RAV4. 1.3. Definition of Term [Table 106] 1.4. Precaution for Handling This is an early draft of the document. All the contents are subject to change. Such changes are notified to the users. Please note that some parts are still TBD will be updated in the future. This book is an Early Draft version. Please note that the information may be subject to change. If there are any changes to the information, we will contact you separately. Also, since the detailed design is still in progress, there are some TBD items here and there, but we will update them accordingly. 2. Architectural Concept 2.1. Overall Structure of MaaS The overall structure of MaaS with the target vehicle is shown. The overall configuration of MaaS using the target vehicle is shown below (Figure 17). Vehicle control technology is being used as an interface for technology providers. Technology providers can receive open API such as vehicle state and vehicle control, necessary for development of automated driving systems. The target vehicles in this document are those that interface vehicle control technology to ADS operators. We will disclose this information as a source. ADS providers can use the vehicle status and vehicle control information required for developing autonomous driving systems as APIs. 2.2. Outline of system architecture on the vehicle The system architecture on the vehicle as a premise is shown. The prerequisite system configuration on the vehicle side is shown below (Figure 18). The target vehicle of this document will adopt the physical architecture of using CAN for the bus between ADS and VCIB. In order to realize each API in this document, the CAN frames and the bit assignments are shown in the form of "bit assignment chart" as a separate document. The vehicle covered by this document has a physical configuration in which the vehicle (VCIB) and ADS connection bus is configured with CAN. In order to realize each API in this document with CAN, separate CAN frames and data bit assignments are required. It is presented as a "bit assignment table." 2.3. Outline of power supply architecture on the vehicle The power supply srcitecture as a premise is shown as follows. The assumed power supply configuration is shown below (Figure 19). The blue colored parts are provided from an ADS provider. parts are provided from the VP. The blue part is installed under the responsibility of ADS, and the orange part is installed under the responsibility of VP. The power structure for ADS is isolated from the power structure for VP. Also, the ADS provider should install a redundant power structure isolated from the VP. 3. Safety Concept Overall safety concept The basic safety concept is shown as follows. The basic safety concepts are as follows: The strategy of bringing the vehicle to a safe stop when a failure occurs is shown as follows. Below is a strategy for safely stopping the vehicle even when an abnormality occurs (Figure 20). 1. After occurring a failure, the entire vehicle execute "detecting a failure" and "correcting an impact of failure" and then achieves the safety state 1. Once an abnormality occurs, "detect the abnormality" and "correct the effect of the abnormality" to achieve safe state 1. 2. Obeying on the instructions from the ADS, the entire vehicle stops in a safety space at a safety speed (assumed less than 0.2G). Follow the ADS instructions and stop in a safe place at a safe deceleration rate (assuming less than 0.2G). However, depending on a situation, the entire vehicle should happen a deceleration more than the above deceleration if needed. However, this does not apply if a deceleration greater than the above is necessary depending on the situation. 3. After stopping, in order to prevent to slip down, the entire vehicle achieves the safety state 2 by activating the immobilization system. After stopping, the vehicle immobilization system is activated to prevent the vehicle from rolling over, and the vehicle enters a safe state 2. Achieve this. [Table 107] See the separated document called "Fault Management" regarding notifiable single failure and expected behavior for the ADS. For information on single faults that can be notified to ADS and the behavior expected in such cases, please refer to the separate document "Fault Management." Redundancy The redundant functionalities with Toyota's MaaS vehicle is shown. Toyota's MaaS vehicles have the following redundant functions: Toyota's Vehicle Platform has the following redundant functionalities to meet the safety goals led from the functional safety analysis. Toyota's vehicle platforms have redundancy in the following functions to meet the safety goals derived from functional safety analysis. Redundant Braking Redundant Brakes Any single failure on the Braking System doesn't cause to lose braking functionality. However, depending on where the failure occurred in, the capability left might not be equivalent to the primary system's capability. In this case, the braking system is designed to prevent that the capability becomes to 0.3G or less. A single fault in the braking system will not result in loss of braking function. In some places, the performance may not be the same as that of the primary system. Even in such cases, the capability is designed to not fall below 0.3G. Redundant Steering Redundant Steering Any single failure on the Steering System doesn't cause to lose steering functionality. However, depending on where the failure occurred in, the capability left might not be equivalent to the primary system's capability. In this case, the steering system is designed to prevent that the capability becomes to 0.3G or less. A single failure within the steering system will not cause a loss of steering function. However, depending on the location of the failure, the steering system may not perform at the same level as the primary system. Even in such cases, the steering system is designed to ensure that capability does not fall below 0.3G. Redundant Immobilization Redundant vehicle fixing Toyota's MaaS vehicle has 2 immobilization systems. ie P lock and EPB. Therefore, any single failure of immobilization system doesn't cause to lose the immobilization capability. However, in the case of failure, maximum stationary slope angle is less steep than the systems are healthy. Toyota's MaaS vehicles have two independent systems, P-lock and EPB, for vehicle immobilization functions. Therefore, the vehicle immobilization function will not be lost in the event of a single failure. However, if a failure occurs, the maximum tilt angle that can be immobilized will be reduced compared to when two systems are used simultaneously. Redundant Power redundant power supply Any single failure on the Power Supply System doesn't cause to lose power supply functionality. However, in case of the primary power failure, the secondary power supply system keeps to supply power to the limited systems for a certain time. A single failure within the power supply system will not cause a loss of power supply functionality. However, if the primary power supply system fails, the secondary power supply system will continue to supply power to limited systems for a certain period of time. Redundant Communication Redundant Communication Any single failure on the Communication System doesn't cause to lose all the communication functionality. System which needs redundancy has physical redundant communication lines. For more detail imformation, see the chapter "Physical LAN architecture (in-vehicle)”. A single failure in the communication system will not cause the entire communication function to fail. For systems that require redundancy, communication lines are physically redundant. For details, see the in-vehicle physical LAN architecture. See 4. Security Concept Outline Regarding security, Toyota's MaaS vehicle adopts the security document issued by Toyota as an upper document. Regarding security, the security measures standard issued by 46F will be used as the upper document. . none 4.2. Assumed Risks The entire risk includes not only the risks assumed on the base e-PF but also the risks assumed for the Autono-MaaS vehicle. Not only the threats expected from the electronic platform on which it is based, but also the threats inherent to Autono-MaaS vehicles The sum of these is defined as the total anticipated threat. The entire risk is shown as follows. The threats assumed in this document are as follows: [Remote Attack] - To vehicle Spoofing the center ECU Software Alteration DoS Attack Sniffering - From vehicle Spoofing the other vehicle ·Software Alternation for a center or a ECU on the other vehicle ·DoS Attack to a center or other vehicle Uploading illegal data [Modification] Illegal Reprogramming Setting up an illegal ADK ·Installation of an unauthenticated product by a customer 4.3. Countermeasure for the risks The countermeasure of the above assumed risks is shown as follows. The response policy for the anticipated threats mentioned above is shown below. 4.3.1. The countermeasure for a remote attack The countermeasure for a remote attack is shown as follows. Countermeasures against remote attacks are listed below. Since the autonomous driving kit communicates with the operator's center, it is necessary to ensure end-to-end security. In addition, since it has the function of issuing driving control instructions, it is necessary to have multi-layered defense within the autonomous driving kit. A secure microcomputer and security chip should be used within the autonomous driving kit to provide sufficient security as the first layer of access from outside. It also has a second layer of security by using a Cure microcomputer and security chip. (In the autonomous driving kit, the first layer of defense prevents direct intrusion from the outside, and the second layer of defense prevents direct intrusion from the outside.) (having multiple layers of defense, such as a layer of defense and a second layer of defense) 4.3.2. The countermeasure for a modification The countermeasure for a modification is shown as follows. Countermeasures against modifications are shown below. To prepare for fake autonomous driving kits, equipment authentication and message authentication will be carried out. Key storage will be tamper-proof and the key set will be changed for each vehicle and autonomous driving kit pair. Alternatively, the contract will include a requirement that the operator thoroughly manage the system to prevent the installation of fraudulent kits. In preparation for Autono-MaaS vehicle users installing counterfeit products, the operating company will The contract will include a provision to prevent unauthorized access. When applying it to an actual vehicle, a threat analysis is also conducted, and the autonomous driving kit will have been fully adapted to the latest vulnerabilities at the time of LO. 5. Function Allocation 5.1. In a healthy situation The allocation of representative functionalities is shown as below. A typical functional layout is shown below (Figure 21). [Function allocation] [Table 108] 5.2. in a single failure See the separated document called "Fault Management" regarding notifiable single failure and expected behavior for the ADS. For information on single faults that can be notified to ADS and the behavior expected in such cases, please refer to the separate document "Fault Management."
[0150] The embodiments disclosed herein should be considered to be illustrative in all respects and not restrictive. The scope of the present invention is defined by the claims, not by the above description, and is intended to include all modifications within the meaning and scope of the claims. [Explanation of symbols]
[0151] 10 vehicle, 100 vehicle body, 110 vehicle control interface, 111, 112 VCIB, 120 VP, 121A, 121B Brake system, 122A, 122 B Steering system, 123A EPB system, 123B P-Lock system, 124 Propulsion system, 125 PCS system, 126 Body system, 127 Wheel speed sensor, 128A, 128B pinion angle sensor, 129 camera / radar, 190 DCM, 200 ADK, 202 ADS, 210 computer, 230 HMI, 260 recognition sensor, 270 attitude sensor, 290 sensor cleaner, 500 data server, 600 MSPF, 700 mobility service.< / secondary> < / primary>
Claims
1. A vehicle that can be equipped with an automated driving system, a vehicle platform that controls the vehicle in accordance with commands from the automated driving system; a vehicle control interface that interfaces between the automated driving system and the vehicle platform; a first command requesting a deceleration value and a second command requesting immobilization of the vehicle are transmitted from the automated driving system to the vehicle platform via the vehicle control interface; the autonomous driving system creates a driving plan for the vehicle, and outputs commands to the vehicle control interface for driving the vehicle in accordance with the driving plan, the commands including the first command and the second command; a signal indicating a stopped state of the vehicle is transmitted from the vehicle platform to the automated driving system via the vehicle control interface; When the first command requests the vehicle platform to decelerate, the vehicle platform transmits the signal to the automated driving system when the vehicle stops, and immobilizes the vehicle in response to the second command received after transmitting the signal; the vehicle platform includes an electric steering system for steering the vehicle; when an operation of the steering wheel by the driver occurs during automatic driving, the vehicle platform controls the motor torque of the electric steering system in cooperation with the driver, taking into account the amount of operation of the steering wheel by the driver; The vehicle platform rejects the request to immobilize the vehicle if the second command is issued while the vehicle is moving.
2. a tire turning angle command indicating a turning angle of a steering wheel required to perform the autonomous driving is further transmitted from the autonomous driving system to the vehicle platform via the vehicle control interface; 2. The vehicle according to claim 1, wherein, when the driver performs a steering operation during the autonomous driving, the vehicle platform controls the electric steering system so as to generate a motor torque that is set by the amount of operation of the steering wheel by the driver and the tire turning angle command.
Citation Information
Patent Citations
JP1989001160U
Stop maintenance device for vehicle
JP1996048221A
Integrated control system for vehicle
JP2005178628A
Automatic operation controller
JP2018132015A
Control device, program, and control method
JP2019177807A