Vehicle Control System

The vehicle control system ensures safety and continuity of autonomous driving by adjusting the route based on safety control system failures, using a hazard map to avoid problematic areas, thus maintaining system functionality.

JP7722339B2Active Publication Date: 2025-08-13TOYOTA JIDOSHA KK
View PDF 8 Cites 0 Cited by

Patent Information

Application Number
JP2022187705
Authority / Receiving Office
JP · JP
Patent Type
Patents
Current Assignee / Owner
Filing Date
2022-11-24
Publication Date
2025-08-13
Estimated Expiration
2042-11-24

AI Technical Summary

Technical Problem

Existing vehicle control systems fail to ensure both safety and continuity of autonomous driving when an abnormality occurs in the safety control system itself, rather than just the autonomous driving control system.

Method used

A vehicle control system comprising an autonomous driving control system and a safety control system that communicates to set a driving route based on the nature of the failure in the safety control system, using a hazard map to avoid specific areas that could exacerbate the failure, thereby ensuring safety and continuity of autonomous driving.

Benefits of technology

The system enables safe and continuous autonomous driving by adjusting the route to avoid areas that could worsen the failure, reducing impact on the autonomous driving system and maintaining functionality.

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure 0007722339000001
    Figure 0007722339000001
  • Figure 0007722339000002
    Figure 0007722339000002
  • Figure 0007722339000003
    Figure 0007722339000003
Patent Text Reader

Abstract

To provide a technology achieving both of safety and continuity of autonomous driving, when abnormality occurs in a function of a part of a safety control system.SOLUTION: The present disclosure relates to a vehicle control system. The vehicle control system includes: an autonomous driving control system controlling autonomous driving of the vehicle; and a safety control system performing communication with the autonomous driving control system and stopping the vehicle when the autonomous driving control system fails or when communication is abnormal. The safety control system notifies the autonomous driving control system of the contents of the failure when a failure of a part of the function of the safety control system occurs. The autonomous driving control system sets a travelling route to a destination during the autonomous driving according to the contents of the failure.SELECTED DRAWING: Figure 1
Need to check novelty before this filing date? Find Prior Art

Description

[Technical Field]

[0001] The present disclosure relates to a vehicle control system that controls an autonomously driven vehicle. [Background technology]

[0002] Patent Document 1 discloses a driving assistance control device that supports the driving of an autonomous vehicle. When an abnormality occurs in an on-board sensor required for autonomous driving, the driving assistance control device prevents unexpected situations such as accidents by using a stop mode, an avoidance mode, or a degenerate driving mode. In the stop mode, the vehicle is immediately stopped. In the avoidance mode, the vehicle is evacuated from the scene to a safe place and stopped. In the degenerate driving mode, restrictions are placed on the autonomous driving of the vehicle. [Prior art documents] [Patent documents]

[0003] [Patent Document 1] Patent Publication No. 2021-111098 Summary of the Invention [Problem to be solved by the invention]

[0004] A safety control system is known that stops a vehicle to avoid unforeseen circumstances when a fault occurs in an autonomous driving control system that controls the autonomous driving of a vehicle. While consideration has been given to controlling the vehicle when an abnormality occurs in the autonomous driving control system, there is still room for consideration regarding controlling the vehicle when an abnormality occurs in the safety control system itself. One objective of the present disclosure is to provide a technology that enables both safety and continuity of autonomous driving when an abnormality occurs in a part of the function of the safety control system. [Means for solving the problem]

[0005] The technology disclosed herein relates to a vehicle control system. The vehicle control system includes an autonomous driving control system that controls the autonomous driving of a vehicle, and a safety control system that communicates with the autonomous driving control system and stops the vehicle in the event of a failure in the autonomous driving control system or an abnormality in communication. If a failure occurs in one of the functions of the safety control system, the safety control system notifies the autonomous driving control system of the details of the failure. The autonomous driving control system sets a driving route to a destination during autonomous driving depending on the details of the failure. [Effects of the Invention]

[0006] According to the present disclosure, when an abnormality occurs in a part of the function of the safety control system, it is possible to achieve both safety and continuity of autonomous driving. [Brief explanation of the drawings]

[0007] [Figure 1] 1 is a block diagram showing an example of the configuration of a vehicle control system according to an embodiment of the present invention; [Figure 2] 1 is a block diagram showing an example of a functional configuration of a vehicle control system according to an embodiment of the present invention; [Figure 3] FIG. 1 is a conceptual diagram illustrating an example of a hazard map and a method for determining a driving route based on the hazard map. [Figure 4] 4 is a flowchart illustrating an example of processing executed by the safety control system according to the present embodiment. [Figure 5] 4 is a flowchart illustrating an example of processing executed by the automatic driving control system according to the present embodiment. DETAILED DESCRIPTION OF THE INVENTION

[0008] Embodiments of the present disclosure will be described with reference to the accompanying drawings.

[0009] 1. Vehicle control system configuration 1 is a diagram showing an example of the configuration of a vehicle control system 10 according to this embodiment. The vehicle control system 10 includes an automatic driving control system 100 and a safety control system 200. Typically, the vehicle control system 10 is mounted on a vehicle 1. Alternatively, a part of the vehicle control system 10 may be arranged in an external device outside the vehicle 1, and the vehicle 1 may be remotely controlled. In other words, the vehicle control system 10 may be arranged in a distributed manner between the vehicle 1 and the external device.

[0010] The automatic driving control system 100 controls the automatic driving of the vehicle 1. The automatic driving control system 100 includes a recognition sensor 120 and a control device 110.

[0011] The recognition sensor 120 is mounted on the vehicle 1 and recognizes (detects) the situation around the vehicle 1. The recognition sensor 120 includes a LIDAR and a camera. The recognition sensor 120 may also include other sensors, such as radar and sonar.

[0012] The control device 110 includes at least one processor 111, at least one storage device 112, and an interface 113. The storage device 112 stores various data including map information and various programs. The map information stored in the storage device 112 includes a hazard map HZ. The hazard map HZ will be described later. The processor 111 reads and executes programs from the storage device 112, thereby realizing various functions of the autonomous driving control system 100, including control of autonomous driving of the vehicle 1. The control device 110 can communicate with the recognition sensor 120 and devices external to the autonomous driving control system 100 via the interface 113. The communication destinations of the control device 110 may include a management server external to the vehicle 1. In this case, the control device 110 may obtain information from the management server and update the map information stored in the storage device 112 as needed.

[0013] The safety control system 200 is a system that stops the vehicle 1 to avoid an unexpected situation when it is determined that it is difficult to continue the autonomous driving by the autonomous driving control system 100. The safety control system 200 communicates with the autonomous driving control system 100 at least while the vehicle 1 is autonomously driving. If an abnormality occurs in the communication with the autonomous driving control system 100 or if the autonomous driving control system 100 breaks down, the safety control system 200 controls the vehicle 1 to stop. Typically, the safety control system 200 gradually decelerates the vehicle 1 and stops it in a safe place such as a road shoulder. Alternatively, in a situation where it is determined that there is a high level of urgency, the safety control system 200 may immediately stop the vehicle 1. The safety control system 200 includes a recognition sensor 220 and a control device 210.

[0014] The recognition sensor 220 is mounted on the vehicle 1 and recognizes (detects) the situation around the vehicle. The recognition sensor 220 includes a LIDAR and a camera. The recognition sensor 220 may also include other sensors, such as radar or sonar. The recognition sensor 220 is a sensor of the safety control system 200 that is different from the recognition sensor 120 of the autonomous driving control system 100.

[0015] The control device 210 includes at least one processor 211, at least one storage device 212, and an interface 213. The storage device 212 stores various data and various programs. The processor 211 reads and executes the programs from the storage device 212, thereby realizing various functions of the safety control system 200. The control device 210 can communicate with the recognition sensor 220 and devices external to the safety control system 200 via the interface 213.

[0016] The automatic driving control system 100 and the safety control system 200 communicate with each part of the vehicle 1. Communication destinations of the automatic driving control system 100 include the vehicle control device 20, the vehicle state sensor 30, the position sensor 40, the light 50, and the wiper 60. Communication destinations of the safety control system 200 include at least the vehicle control device 20. The safety control system 200 may also communicate with the vehicle state sensor 30, the light 50, and the wiper 60.

[0017] The vehicle control device 20 can control the steering, acceleration, and deceleration of the vehicle 1 by operating the actuators of the vehicle 1. The automatic driving control system 100 and the safety control system 200 can control the vehicle 1 by communicating with the vehicle control device 20.

[0018] The vehicle state sensor 30 detects the state of the vehicle 1. The vehicle state sensor includes a speed sensor, an acceleration sensor, a yaw rate sensor, a steering angle sensor, etc. The autonomous driving control system 100 can acquire information about the state of the vehicle 1 by communicating with the vehicle state sensor 30.

[0019] The position sensor 40 detects the position and orientation of the vehicle 1. An example of the position sensor 40 is a GPS (Global Positioning System) sensor. The autonomous driving control system 100 can acquire position information of the vehicle 1 by communicating with the position sensor 40.

[0020] 2. Functions of the autonomous driving control system and safety control system FIG. 2 is a diagram illustrating an example of the functional configuration of the automatic driving control system 100 and the safety control system 200.

[0021] The autonomous driving control system 100 includes, as functional units, an autonomous driving command unit 130, a driving plan unit 140, and a sensor information acquisition unit 150. These functional units of the autonomous driving control system 100 correspond to a program or a part thereof stored in the storage device 112. These functional units are realized by reading the program from the storage device 112 and executing it in the processor 111.

[0022] When the autonomous driving control system 100 drives the vehicle 1 autonomously, first, the driving planner 140 creates a driving plan for the vehicle 1. The creation of the driving plan by the driving planner 140 includes obtaining the current location of the vehicle 1 and determining the destination. The driving planner 140 can obtain the current location of the vehicle 1 from the position sensor 40. The destination of the vehicle 1 is stored in the storage device 112 as map information. Alternatively, the destination may be obtained by communication with a management server.

[0023] The driving plan unit 140 includes a driving route setting unit 141. The driving route setting unit 141 sets a driving route from the current location to the destination while the vehicle 1 is driving automatically, based on map information stored in the storage device 112. The set driving route is temporarily stored in the storage device 112. Furthermore, when a malfunction occurs in a part of the function of the safety control system 200, the driving route setting unit 141 sets a driving route according to the nature of the malfunction. The driving route according to the nature of the malfunction will be described later. The driving route set by the driving route setting unit 141 is input to the automatic driving command unit 130.

[0024] The sensor information acquisition unit 150 acquires sensor information from the recognition sensor 120, the vehicle state sensor 30, and the position sensor 40. The sensor information is input to the automatic driving command unit 130. Based on the sensor information, the automatic driving command unit 130 calculates a target trajectory for the vehicle 1 to travel along a travel route. The target trajectory includes a target position and a target speed of the vehicle 1 within the road on which the vehicle 1 is traveling. The target speed may be set for each target position. The automatic driving command unit 130 controls the vehicle 1 via the vehicle control device 20 so that the vehicle 1 follows the calculated target trajectory. In this way, automatic driving of the vehicle 1 is performed.

[0025] The safety control system 200 includes, as functional units, a safety control unit 230, a fault notification unit 240, a recognition unit 250, and an operation unit 260. These functional units of the safety control system 200 correspond to a program or a part thereof stored in the storage device 212. These functional units are realized by reading the program from the storage device 212 and executing it in the processor 211.

[0026] The safety control unit 230 performs safety control to stop the vehicle 1 when it is determined that it is difficult to continue autonomous driving by the automatic driving control system 100. The safety control unit 230 can determine that it is difficult to continue autonomous driving by the automatic driving control system 100, for example, in the following manner. For example, when a self-diagnosis function of the automatic driving control system 100 detects a malfunction (abnormality) in the automatic driving control system 100, the automatic driving control system 100 notifies the safety control system 200 of the occurrence of the abnormality. The safety control system 200 can determine that it is difficult to continue autonomous driving based on the notification. As another example, when communication with the automatic driving control system 100 is interrupted and signals from the automatic driving control system 100 can no longer be received, the safety control system 200 determines that it is difficult to continue autonomous driving.

[0027] When safety control is performed by the safety control unit 230, the recognition unit 250 recognizes the surroundings of the vehicle 1 using the recognition sensor 220 and acquires recognition information. The recognition information includes information about targets around the vehicle 1. The recognition information is input to the safety control unit 230, and the safety control unit 230 can control the vehicle 1 based on the recognition information.

[0028] Furthermore, the operation unit 260 may operate devices such as the lights 50 and the wipers 60 so that the safety control unit 230 can obtain sufficient recognition information. For example, the operation unit 260 includes an auto high beam function 261. When the brightness around the vehicle 1 is insufficient and the necessary recognition information cannot be obtained sufficiently from the recognition sensor 220, the auto high beam function 261 turns on the high beams of the lights 50 to brighten the area around the vehicle 1. Alternatively, the operation unit 260 may include a function to operate the wipers 60. For example, when sufficient information cannot be obtained from the recognition sensor 220 because water droplets are on the window glass in front of the recognition sensor 220, the operation unit 260 can operate the wipers 60 to wipe away the water droplets.

[0029] The fault notification unit 240 detects a fault in some of the functions of the safety control system 200. The faults detected by the fault notification unit 240 include a fault in the auto high beam function 261, an abnormal sensor temperature, and a fault related to the recognition system of the safety control system 200. The faults detected by the fault notification unit 240 may also include a fault in the wiper 60 operation function of the operation unit 260.

[0030] A sensor temperature abnormality occurs when the recognition sensor 220 becomes hotter than a predetermined temperature. This occurs, for example, when the vehicle 1 or the recognition sensor 220 is exposed to direct sunlight for a long period of time, when the temperature around the vehicle 1 rises suddenly, or when the processing load on the recognition sensor 220 increases suddenly. The predetermined temperature may be, for example, the upper limit of the operating temperature range of the recognition sensor 220. A failure related to the recognition system of the safety control system 200 refers to a failure of the recognition sensor 220, a failure of the recognition unit 250, or a communication abnormality between the recognition sensor 220 and the control device 210.

[0031] When a malfunction occurs in a part of the functions of the safety control system 200, the malfunction notification unit 240 notifies the travel route setting unit 141 of the details of the malfunction.

[0032] 3. Hazard maps When the malfunction notification unit 240 notifies the driving route setting unit 141 of the malfunction details, the driving route setting unit 141 sets a driving route for the vehicle 1 in accordance with the malfunction details. The setting of the driving route in accordance with the malfunction details is performed based on the hazard map HZ.

[0033] FIG. 3A is a conceptual diagram showing an example of a hazard map HZ. The hazard map HZ is map information that indicates avoidance areas to be avoided for each type of failure, and is stored in the storage device 112. The hazard map HZ is pre-stored in the storage device 112. Alternatively, the hazard map HZ may be updated in real time by a management server, and the autonomous driving control system 100 may acquire the hazard map HZ from the management server as needed. The hazard map HZ in FIG. 3A shows three avoidance areas AR1, AR2, and AR3. The dock is the storage location for the vehicle 1 and is the destination of the vehicle 1.

[0034] The avoidance area AR1 is a dark place. Here, a dark place refers to an area where the average brightness within the area is less than a threshold value. Examples of dark places include tunnels and mountain roads. Dark places are areas to avoid in the event of a malfunction of the auto high beam function 261.

[0035] The avoidance area AR2 is a temperature warning area. The temperature warning area is an area where the vehicle 1 may be exposed to direct sunlight for a long period of time. The temperature warning area is, for example, an area where there are no buildings or natural objects above a certain height that block the sunlight. The temperature warning area is an area to be avoided in case of abnormal sensor temperature.

[0036] The avoidance area AR3 is a densely populated area. A densely populated area is an area where the population density within the area is equal to or greater than a threshold. The densely populated area is an avoidance area in the event of a failure related to the recognition system of the safety control system 200.

[0037] The hazard map HZ may also indicate areas to be avoided other than these three types of areas. For example, the hazard map HZ may indicate areas where the average amount of rainfall from the present until a predetermined time later is predicted to be greater than a threshold, as an area to be avoided in the event of a malfunction of the wiper 60 operation function. This area to be avoided is an example of a case where the hazard map HZ is updated in real time.

[0038] 3B shows an example of setting a driving route based on the hazard map HZ shown in (A). The driving route setting unit 141 sets a driving route to the destination so as to avoid avoidance areas according to the type of failure notified by the failure notification unit 240 and the hazard map HZ. Note that setting a driving route so as to avoid avoidance areas includes changing an already set driving route.

[0039] In this case, the malfunction is a sensor temperature abnormality. Furthermore, the default travel route RT1 that was set before the malfunction was notified passes through an avoidance area AR2 for the sensor temperature abnormality. Therefore, the travel route setting unit 141 sets the travel route RT2 so as to avoid the avoidance area AR2. In other words, the travel route RT1 is changed to the travel route RT2.

[0040] The effect of setting a driving route according to the type of failure will be explained. At the stage when a failure occurs in some of the functions of the safety control system 200, the automatic driving control system 100 is functioning normally. Basically, the automatic driving control performed by the automatic driving control system 100 allows the vehicle 1 to safely reach the destination. However, in the unlikely event that the automatic driving control system 100 fails, the safety control system 200 performs safety control to safely stop the vehicle 1. In that case, the driving route is set so that safety control can be performed with as high a precision as possible even with the safety control system 200 having some of its functions failing.

[0041] For example, if the auto high beam function 261 fails, a driving route is set to avoid dark places. Therefore, the automatic driving control system 100 will not fail in dark places, and as a result, a situation in which the safety control system 200 with a failed auto high beam function 261 has to operate in dark places is avoided. In other words, safety is ensured.

[0042] As another example, if there is an abnormality in the sensor temperature, the driving route is set to avoid the temperature warning area. This prevents the recognition sensor 220 from continuing to be exposed to direct sunlight for a long time after it has become hot, which further increases its temperature. This reduces the possibility that the recognition sensor 220 will stop working due to an excessive increase in temperature.

[0043] As a comparative example, consider a case where vehicle 1 is stopped unconditionally and autonomous driving is terminated when a failure occurs in some of the functions of safety control system 200. In this case, autonomous driving ends even though autonomous driving control system 100 is still functioning normally. In other words, the comparative example is overly pessimistic, and the continuity of autonomous driving decreases. On the other hand, according to this embodiment, when a failure occurs in some of the functions of safety control system 200, a driving route is simply set to ensure safety, and autonomous driving does not immediately end. Therefore, it is possible to ensure the continuity of autonomous driving while also ensuring safety.

[0044] Furthermore, setting a driving route according to the type of failure is also effective in reducing the impact on the autonomous driving control system 100. For example, if a sensor temperature abnormality occurs, the temperature of the entire vehicle 1 may rise. Therefore, if the vehicle 1 continues to drive in an area exposed to direct sunlight, the temperatures of on-board sensors other than the recognition sensor 220, such as the recognition sensor 120, the vehicle state sensor 30, and the position sensor 40, may also rise. In this embodiment, setting a driving route to avoid the temperature warning area can also reduce the impact on the sensors used by the autonomous driving control system 100. In this way, the vehicle control system 10 according to this embodiment can reduce the impact on the control of the vehicle 1 and continue autonomous driving while maintaining safety.

[0045] If the default driving route does not pass through the avoidance area corresponding to the type of failure, the driving route setting unit 141 may set the default driving route as the driving route corresponding to the type of failure. Furthermore, the hazard map HZ may include information on priority areas in addition to the avoidance areas. If there are multiple candidate driving routes that avoid the avoidance areas corresponding to the type of failure, the driving route that passes through the priority areas is set preferentially. For example, in the case of an abnormal sensor temperature, an area with many roadside trees that block direct sunlight may be set as the priority area. In this case, by preferentially selecting areas with many shaded areas, it is possible to increase the possibility of preventing the temperature of the recognition sensor 120 and the vehicle 1 from rising.

[0046] 4. Processing flow An example of the flow of processing related to setting a driving route according to the type of failure, performed by the automatic driving control system 100 and the safety control system 200, will be described. FIG. 4 is a flowchart showing an example of processing performed by the failure notification unit 240 of the safety control system 200. The processing shown in FIG. 4 is repeatedly executed in a predetermined control cycle. This processing is realized by the processor 211 executing a program stored in the storage device 212.

[0047] In step S110, the processor 211 detects a failure in some function of the safety control system 200. If a failure is detected, the process proceeds to step S120.

[0048] In step S120, the processor 211 determines whether or not a failure has been detected in some of the functions of the safety control system 200. If a failure has been detected (step S120; Yes), the process proceeds to step S130. On the other hand, if no failure has been detected (step S120; No), the process in this cycle ends.

[0049] In step S130, the processor 211 notifies the automatic driving control system 100 of the details of the failure detected in step S110. Once the notification is made, the processing in the current cycle ends.

[0050] 5 is a flowchart showing an example of processing performed by the driving route setting unit 141 of the automatic driving control system 100. This processing is repeatedly executed in a predetermined control cycle. The processing shown in FIG. 5 is realized by the processor 111 executing a program stored in the storage device 112.

[0051] In step S210, processor 111 determines whether or not a notification regarding the details of the failure has been received from safety control system 200. If a notification has been received (step S210; Yes), the process proceeds to step S220. On the other hand, if a notification has not been received (step S210; No), the process proceeds to step S280.

[0052] In step S220, processor 111 determines whether the malfunction notified from safety control system 200 is a malfunction of the auto high beam function. If the malfunction is a malfunction of the auto high beam function (step S220; Yes), the process proceeds to step S230. On the other hand, if the malfunction is not a malfunction of the auto high beam function (step S220; No), the process proceeds to step S240.

[0053] In step S230, processor 111 sets a travel route for vehicle 1 that avoids dark areas. At this time, if a travel route that passes through dark areas has already been set, processor 111 changes the travel route. Once the travel route is set, the processing for this cycle ends.

[0054] In step S240, processor 111 determines whether the fault notified from safety control system 200 is a sensor temperature abnormality. If the fault is a sensor temperature abnormality (step S240; Yes), the process proceeds to step S250. On the other hand, if the fault is not a sensor temperature abnormality (step S240; No), the process proceeds to step S260.

[0055] In step S250, processor 111 sets a driving route for vehicle 1 that avoids the temperature warning area. At this time, if a driving route that passes through the temperature warning area has already been set, processor 111 changes the driving route. Once the driving route is set, the processing for this cycle ends.

[0056] In step S260, the processor 111 determines whether the content of the failure notified from the safety control system 200 is a failure related to the recognition system of the safety control system 200. If the content of the failure is a failure of the recognition system of the safety control system 200 (step S260; Yes), the processing proceeds to step S270. On the other hand, if the content of the failure is not a failure of the recognition system of the safety control system 200 (step S260; No), the processing proceeds to step S280.

[0057] In step S270, processor 111 sets a driving route for vehicle 1 that avoids densely populated areas. At this time, if a driving route that passes through densely populated areas has already been set, processor 111 changes the driving route. Once the driving route is set, the processing for this cycle ends.

[0058] In step S280, the processor 111 sets the driving route of the vehicle 1 to a default driving route. That is, if the safety control system 200 has not notified the details of the failure, or if an avoidance area has not been set for the notified details of the failure, the default driving route is set. The default driving route is a driving route that does not take avoidance areas into consideration. Once the driving route has been set, the processing for this cycle ends.

[0059] As described above, according to this embodiment, when the safety control system 200 notifies the driver of the details of the failure, the automatic driving control system 100 sets a driving route according to the details of the failure. This makes it possible to improve the continuity of automatic driving while taking into consideration the safety of the vehicle 1. [Explanation of symbols]

[0060] 1...vehicle 10...vehicle control system 20...vehicle control device 30...vehicle condition sensor 40...position sensor 50...light 60...wiper 100...automatic driving control system 110...control device 111...processor 112...storage device 113...interface 120...recognition sensor 130...automatic driving command unit 140...travel planning unit 141...travel route setting unit 150...sensor information acquisition unit 200...safety control system 210...control device 211...processor 212...storage device 213...interface 220...recognition sensor 230...safety control unit 240...fault notification unit 250...recognition unit 260...operation unit 261...auto high beam function HZ...hazard map

Claims

1. an automatic driving control system that controls automatic driving of a vehicle; a safety control system that communicates with the automatic driving control system and stops the vehicle when the automatic driving control system fails or when an abnormality occurs in the communication; Equipped with When a failure occurs in a part of the function of the safety control system, the safety control system notifies the automatic driving control system of the content of the failure, the automatic driving control system holds a hazard map indicating an avoidance area to be avoided for each of the types of the failure of the partial function of the safety control system, The autonomous driving control system sets a driving route to the destination during the autonomous driving so as to avoid the avoidance area based on the hazard map and the details of the failure of the partial function of the safety control system. Vehicle control system.

2. 2. The vehicle control system according to claim 1, the failure of the part of the functions of the safety control system includes a failure of an auto high beam function of the vehicle; In the hazard map, the avoidance area for a failure of the automatic high beam function includes a dark place where the average brightness is less than a threshold value. Vehicle control system.

3. 2. The vehicle control system according to claim 1, the failure of the part of the functions of the safety control system includes a sensor temperature abnormality in which a sensor of the safety control system becomes higher than a predetermined temperature; In the hazard map, the avoidance area for the sensor temperature abnormality is an area where there are no buildings or natural objects above a predetermined height that block sunlight. Vehicle control system.

4. 2. The vehicle control system according to claim 1, The failure of the part of the function of the safety control system includes a failure related to a recognition system of the safety control system, In the hazard map, the avoidance area for failures related to the recognition system includes a densely populated area where the population density is equal to or greater than a threshold. Vehicle control system.

Citation Information

Patent Citations

  • Automatic driving control device

    JP2017157067A

  • Automatic driving control system

    JP2020055526A

  • Vehicle control device and vehicle control method

    JP2020102159A

  • Information processor and automated travel control system therewith

    JP2020149323A

  • Automatic operation control device

    JP2020175853A