Vehicle driving data recording device and vehicle driving data visualization device
The vehicle driving data recording and visualization systems address the challenge of identifying responsibility in autonomous vehicle failures by determining and storing critical data using identification IDs and user-specific visualization, optimizing storage and presentation.
Patent Information
- Application Number
- JP2024521434
- Authority / Receiving Office
- JP · JP
- Patent Type
- Patents
- Current Assignee / Owner
- Filing Date
- 2022-05-17
- Publication Date
- 2025-08-19
- Estimated Expiration
- 2042-05-17
AI Technical Summary
Existing vehicle driving data recording systems fail to effectively identify responsibility when an abnormality occurs in autonomous vehicles, due to insufficient data acquisition methods and limited storage capacity.
A vehicle driving data recording device that determines data to be recorded based on the degree of influence of an automatic driving function, using identification IDs and data acquisition specifications, and a visualization device that generates visualization data based on user needs, allowing efficient storage and clear identification of responsibility.
Enables clear determination of responsibility in the event of a failure by efficiently storing and presenting relevant data, utilizing limited storage capacity and user-specific visualization.
Smart Images

Figure 0007725179000001 
Figure 0007725179000002 
Figure 0007725179000003
Abstract
Description
[Technical Field]
[0001] The present invention relates to a vehicle driving data recording system, a vehicle driving data recording control system, and a vehicle driving data visualization system. [Background technology]
[0002] With the spread of autonomous vehicles, laws and regulations have been put in place requiring the storage of vehicle driving data in order to clarify responsibility in the event of an accident. Current laws and regulations require the storage of data that can explain whether a human or the autonomous driving system was driving at the time of the accident. However, in the case of an accident caused by an abnormality in the autonomous driving system, it is difficult to clarify responsibility between manufacturers if the data content specified by current laws and regulations is used. On the other hand, if detailed information about the internal status of the system is stored, it would be possible to clarify responsibility between manufacturers, but since the storage space available within the vehicle is limited, it is necessary to store the necessary data efficiently. [Prior art documents] [Patent documents]
[0003] [Patent Document 1] Patent Publication No. 2015-212677 Summary of the Invention [Problem to be solved by the invention]
[0004] Patent Document 1 only optimizes the amount of data to be recorded, and does not disclose a method for acquiring data that will allow the identification of responsibility when an abnormality occurs, making it difficult to identify responsibility when a failure occurs. [Means for solving the problem]
[0005] The vehicle driving data recording device of the present invention determines data to be recorded regarding the operating status of a system made up of a plurality of devices based on the degree of influence of an automatic driving function, andof the device including an identification ID that identifies the device communication records Contains the information necessary to save Data Acquisition Specifications of an acquisition data determination unit that determines The aforementioned Data Acquisition Specifications The identification ID described in a data acquisition unit for acquiring data; The identification ID and a data recording unit that stores the data in the recording device.
[0006] The vehicle travel data visualization device of the present invention also provides a vehicle travel data visualization system that visualizes data stored in a vehicle travel data recording device and the data. This is information that indicates whether to visualize the The vehicle driving data visualization device includes a data conversion unit that receives visualization granularity information as an input and generates visualization data. [Effects of the Invention]
[0007] According to the present invention, it is possible to clarify who is responsible when a failure occurs. [Brief explanation of the drawings]
[0008] [Figure 1] 1 is a diagram showing a schematic configuration of an automatic driving system according to a first embodiment of the present invention. [Figure 2] 1 is a diagram showing a schematic configuration of a vehicle travel data recording device according to a first embodiment of the present invention. [Figure 3] FIG. 3 is a diagram showing a safety analysis result according to the first embodiment of the present invention. [Figure 4] FIG. 2 is a diagram showing communication specifications according to the first embodiment of the present invention. [Figure 5] 4 is a diagram illustrating an operation flow of an acquisition data determination unit according to the first embodiment of the present invention. FIG. [Figure 6] FIG. 2 is a diagram showing data acquisition specifications according to the first embodiment of the present invention. [Figure 7] FIG. 4 is a diagram showing an operation flow of a data acquisition unit according to the first embodiment of the present invention. [Figure 8] FIG. 2 is a diagram showing data according to the first embodiment of the present invention. [Figure 9]FIG. 4 is a diagram showing an operation flow of a data recording unit according to the first embodiment of the present invention. [Figure 10] FIG. 10 is a diagram showing a schematic configuration of a vehicle travel data visualization device according to a second embodiment of the present invention. [Figure 11] FIG. 10 is a diagram showing visualization granularity information according to the second embodiment of the present invention. [Figure 12] FIG. 10 is a diagram showing an operation flow of a data conversion unit according to the second embodiment of the present invention. [Figure 13] FIG. 10 is a diagram showing visualization data in a detailed mode according to the second embodiment of the present invention. [Figure 14] FIG. 10 is a diagram showing visualized data in a normal mode according to the second embodiment of the present invention. DETAILED DESCRIPTION OF THE INVENTION
[0009] Embodiment 1 FIG. 1 is a diagram showing the schematic configuration of an autonomous driving system mounted on a vehicle (host vehicle) such as a passenger car. A vehicle driving data recording device 100, which is composed of a central processing unit (CPU) 101, a memory 102, an auxiliary recording device 103, etc., is connected to an HMI-ECU 200, a DMS-ECU 300, an ADAS-ECU 400, a control-ECU 500, a camera-ECU 600, etc. via a communication line 700, and these various ECUs (electronic control devices) can also communicate with each other. The memory 102 is a read-only memory (ROM), a random access memory (RAM), etc. The acquired data determination unit 130, the data acquisition unit 150, and the data recording unit 170 are configured by the processor executing programs stored in the memory 102.
[0010] 2 is a block diagram of the vehicle driving data recording device 100 according to the first embodiment. The device includes the vehicle driving data recording device 100, an acquired data determination unit 130, a data acquisition unit 150, and a data recording unit 170. The vehicle driving data recording device 100 may include elements other than these elements.
[0011] The acquisition data determination unit 130 determines data acquisition specifications 140 from the safety analysis result 110 and the communication specifications 120. Furthermore, the data acquisition unit 150 outputs data 160 from the data acquisition specifications 140. The data recording unit 170 records the data 160. Furthermore, all or part of the acquisition data determination unit 130, the data acquisition unit 150, and the data recording unit 170 may be configured by hardware that does not execute a program.
[0012] The vehicle driving data recording device 100 comprises an acquisition data determination unit that determines system operation status data 160 from the safety analysis result 110 and the communication specification 120 and generates data acquisition specification 140, a data acquisition unit 150 that acquires system execution status data 160 from the data acquisition specification 140, and a data recording unit 170 that stores the data 160 in a recording device. Since the data 160 to be recorded is determined based on the safety analysis result 110, the data 160 can be efficiently stored to clarify responsibility when a failure occurs. This will be described in detail below.
[0013] <Safety analysis results> The following section explains the contents of the Safety Analysis Results 110. ISO 26262 is a functional safety standard for automobiles that was established primarily in Europe in 2011. Currently, the ISO 26262 functional safety process is widely adopted by OEMs and suppliers. The ISO 26262 functional safety process begins with a use case analysis and a safety analysis to identify potential hazards to the human body. Each use case is classified into five levels based on the severity of the hazard: QM (Quality Management), ASIL (Automotive Safety Integrity Level) A, ASIL_B, ASIL_C, and ASIL_D. Functions assigned an ASIL are required by the standard to be developed in accordance with the functional safety process defined in ISO 2626. ISO's primary activity is to establish internationally accepted standards, and the standards established by ISO are called ISO standards. ISO stands for International Organization for Standardization, headquartered in Geneva, Switzerland. The functional safety process is thus a development process that conforms to the ISO 26262 standard.
[0014] Generally, the higher the level of autonomous driving, the higher the ASIL, such as ASIL_C or ASIL_D, that is assigned. Furthermore, as the level of autonomous driving increases, use cases that affect autonomous driving functions emerge, and so opportunities for new ASILs to be assigned to devices that previously did not have an ASIL assigned increase. Various ECUs, such as those shown in Figure 1, are essential for realizing autonomous vehicles, and are often assigned ASILs due to the significant impact that a malfunction could have on the human body. Therefore, it is often essential to develop them in accordance with the ISO 26262 functional safety process.
[0015] In the functional safety process specified by ISO26262, after safety analysis is performed, functional safety requirements (FSRs) are defined, which are the necessary functions to reduce harm to the human body. For example, a functional safety requirement could be, "The ADAS-ECU must notify the HMI-ECU that communication from the DMS-ECU has been interrupted." When the HMI-ECU receives communication regarding the DMS-ECU from the ADAS-ECU, it performs control such as stopping the vehicle on the side of the road to minimize the impact on the human body across the entire system.
[0016] Furthermore, technical requirements analysis is performed at the system level from the functional safety requirements, and the functions are further refined to create what are called technical safety requirements (TSR).The safety of the system is further enhanced by improving the system design based on the technical safety requirements and repeating the safety analysis, definition of functional safety requirements, and definition of technical safety requirements.
[0017] FIG. 3 is a diagram illustrating an example of a safety analysis result according to this embodiment. In the following description, the safety analysis result 110 shown in FIG. 2 is assumed to be the safety analysis result 110P shown in FIG. 3. The safety analysis result 110P includes technical safety requirements (TSRs) and corresponding numbers. For example, taking the technical safety requirement No. 1 as an example, a certain use case is assigned an ASIL in the safety analysis, and functional safety requirements are defined to ensure the safety of that function. Furthermore, it indicates that the technical safety requirement to realize the function of the functional safety requirement is "the ADAS-ECU notifies the DMS-ECU via CAN that transmission data from the HMI-ECU has been interrupted." Technical safety requirements often include the source and destination of communication for the functional safety function, as well as the means of communication.
[0018] In this way, the safety analysis result 110 is the analysis result of the technical safety requirements generated by the automotive functional safety process, so by recording the data 160 as technical safety requirements, it is possible to make the amount of data 160 appropriate for clarifying who is responsible. Since the functional safety requirements do not specify the communication means, the recording location of the data 160 is not clear, but this makes the recording location of the data 160 clear.
[0019] Furthermore, since the technical safety requirements describe at least the input / output data between devices and the means of transmitting the input / output data, the granularity of the technical safety requirements provides sufficient data 160 to clarify responsibility.
[0020] <Communication specifications> FIG. 4 is a diagram illustrating an example of communication specifications according to this embodiment. In the following description, it is assumed that the communication specifications 120 shown in FIG. 2 are the communication specifications 120P shown in FIG. 4. The communication specifications 120P describe the technical safety requirement numbers (TSR_No) and the corresponding identification IDs. For example, the above-mentioned technical safety requirement No. 1 indicates that the identification ID is b'00000000001. The identification ID is incorporated into the communication packet. In this embodiment, since CAN communication is used, the identification ID is incorporated into the CAN_ID. The identification ID may be incorporated into the communication packet in a compressed form using a compression algorithm.
[0021] The communication specifications 120 include an identification ID linked to the technical safety requirements, so that communication records can be obtained.
[0022] <Acquisition data determination section> 5 is a flowchart illustrating the flow of operations for defining specifications. In step S131, the acquired data determination unit 130 reads the input safety analysis result 110P.
[0023] Next, in step S132, the acquisition data determination unit 130 reads the input communication specifications 120P.
[0024] In step S133, the acquisition data determination unit 130 extracts information from the read safety analysis result 110P and communication specification 120P. Information regarding the source and destination of communication for each technical safety requirement (TSR) is extracted from the safety analysis result 110P. For example, for TSR_No1, information is extracted that the communication source is the ADAS-ECU and the destination is the DMS-ECU. In addition, an identification ID for each TSR is extracted from the communication specification. For example, for TSR_No1, information is extracted that the identification ID is b'00000000001. Information extraction may be achieved by a text analysis device, which is a well-known technology.
[0025] Next, in step S134, the data acquisition unit 150 associates the communication source, destination, and identification ID of each TSR extracted in step S133, formats the table, and determines the recording location. From the output table, communication data information is identified from the source and destination of the communication data and the communication specifications, and the recording location of the operation information is determined. In this embodiment, the recording location is communications related to all TSRs, but if there are a large number of TSRs, it may be possible to target only TSRs with assigned ASILs, for example.
[0026] Next, in step S135, the data recording unit 170 outputs and defines the generation specifications from the data acquisition specifications 140, and records the generation specifications.
[0027] 6 is a diagram illustrating an example of data acquisition specifications 140P defined by the acquisition data determination unit 130. The source, destination, and identification ID of the generation specifications described in the data acquisition specifications 140P are values determined in steps S131 to S133. For example, in the case of information related to TSR_No1, it can be seen that the source is the ADAS-ECU, the destination is the DMS-ECU, and the identification ID is b'00000000001.
[0028] The data acquisition specification 140 includes the source and destination of the communication from the safety analysis result 110 and the identification ID from the communication specification 120, so that the information necessary to store the communication record can be included in the data acquisition specification 140.
[0029] <Data Acquisition Section> 7 is a flowchart illustrating the flow of operations of the data acquisition unit 150. In step S151, the data acquisition unit 150 reads the generation specifications and extracts information on the source and destination of communication and the identification ID.
[0030] Next, in step S152, the recording location is identified. For example, if it is TSR No. 1, it is determined that, among the CAN communications flowing on the communication line 700, data 160 transmitted from the ADAS-ECU to the DMS-ECU and whose CAN_ID is b'00000000001 is to be recorded. Steps S153 to S158 are looped until the target program ends.
[0031] In step S154, the data 160 flowing on the communication line 700 is monitored.
[0032] In step S155, if the data 160 is the data 160 identified as the recording location in step S152, the process proceeds to step S156. If the data 160 is not the data 160 identified as the recording location, the process returns to step S154, and the data 160 on the communication line 700 is monitored.
[0033] In step S156, the identification ID of the acquired data 160 is linked to the time of acquisition and recorded. The time is recorded in the format yy-MM-dd, HH:mm:ss, SSS, where yy represents the year, MM represents the month, dd represents the day, HH represents the hour, mm represents the minute, ss represents the second, and SSS represents the millisecond.
[0034] FIG. 8 illustrates an example of data 160P defined by the data acquisition unit 150. The data 160 described in the data 160P includes a CAN_ID and a communication time. The communication time is described in the format yy-MM-dd, HH:mm:ss, SSS, down to the millisecond. It can be seen that the identification IDs b'00000000001 and b'00000000002 communicated four times in 200 millisecond increments starting at 2:31:29:573 AM on June 26, 2022. In this way, the data 160 includes an identification ID and a communication time.
[0035] In the event of an HMI-ECU failure, the ADAS-ECU notifies the DMS-ECU that communication with the HMI-ECU has been interrupted, and the DMS-ECU similarly notifies the ADAS-ECU that communication with the HMI-ECU has been interrupted. By identifying and acquiring data from the safety analysis results in this way, it is possible to clarify the causes of accidents using the minimum amount of data required.
[0036] In the example described above, the ADAS-ECU and DMS-ECU notified that communication from the HMI-ECU had been interrupted at the same time, so it can be determined that the HMI-ECU was the cause of the accident when it occurred. Although it is possible to determine who is responsible when an accident occurs by saving all communications on the communication line 700, it is not desirable to save all data 160 on the communication line 700 for two reasons: the storage capacity of recording devices that can be installed in automobiles is limited, and the storage period required by law is long (currently six months).
[0037] <Data recording section> 9 is a flowchart illustrating the flow of operations of the data recording unit 170. In step S171, the data recording unit 170 reads the data 160P.
[0038] Next, in step S172, the data 160 is stored in the auxiliary storage device 103. The auxiliary storage device 103 may utilize RAID (Redundant Array of Inexpensive Disks) to place storage devices at the four corners of the vehicle, thereby improving the integrity of the data 160.
[0039] The vehicle driving data recording device 100 according to this embodiment operates as described above. The vehicle driving data recording device according to this embodiment utilizes the deliverables of the ISO26262 automotive functional safety standard for data recording, making it possible to efficiently store information necessary to clarify responsibility in the event of an accident.
[0040] More specifically, by limiting the data to be saved from the safety analysis results defined in the development process of the ISO26262 automotive functional safety standard, it is possible to efficiently obtain the data necessary to clarify responsibility when a malfunction occurs. For example, in a system in which devices A and B made by other companies and device C made by the company operate together, a safety requirement may be derived that states, "Device C must notify device B that transmission data from device A has been interrupted." In this case, if the time when transmission data from device A was interrupted and the notification data sent to device B and the data related to that time are available, it can be proven that the company's product was not the cause of the malfunction.
[0041] As described above, the vehicle driving data recording device is equipped with an acquisition data determination unit that determines data on the system operation status from the safety analysis results and communication specifications and generates data acquisition specifications, a data acquisition unit that acquires data on the system's execution status from the data acquisition specifications, and a data recording unit that stores the data in the recording device.Therefore, it is possible to store in a limited memory area just enough data to clarify responsibility when an abnormality occurs, and since the data to be recorded can be determined using the safety analysis results generated in the functional safety analysis process, it is possible to efficiently store data to clarify responsibility when a failure occurs.
[0042] Embodiment 2 The second embodiment shows a technique for utilizing the data 160 recorded in the vehicle travel data recording device 100 shown in the first embodiment to visualize the data 160 in a form that allows the user to understand the situation.
[0043] 10 is a block diagram illustrating a vehicle traveling data visualization device 800 according to embodiment 2. The main difference between data 160 stored in vehicle traveling data recording device 100 according to embodiment 1 and vehicle traveling data visualization device 800 according to embodiment 2 is that visualization data 250 is created using input visualization granularity information 240.
[0044] The vehicle travel data visualization device 800 includes a data conversion unit 810 that generates visualization data using the safety analysis result 110, data acquisition specifications 140, data 160, and visualization granularity information 240 of the vehicle travel data recording device 100 as input, and can therefore output the data 160 of the first embodiment as visualization data suitable for the target user. This will be described in detail below.
[0045] <Safety analysis results, data acquisition specifications, data> The safety analysis result 210, data acquisition specifications 220, and data 230 and 160 shown in FIG. 10 will be described as the safety analysis result 110P in FIG. 3, the data acquisition specifications 140P in FIG. 6, and the data 160P in FIG. 8 in the first embodiment.
[0046] <Visualization granularity information> Fig. 11 is a diagram illustrating an example of visualization granularity information 240 in this embodiment. In the following description, it is assumed that the visualization granularity information 240 shown in Fig. 10 is visualization granularity information 240P shown in Fig. 11. The visualization granularity information 240 is information that instructs whether or not to visualize the vehicle operation data 230 in detail, and may be determined depending on the target user to whom the data 230 is presented.
[0047] When the visualization granularity information 240 is "0," detailed data 230 is presented, whereas when it is "1," the part that caused the failure is presented simply. For example, if the user to whom the visualization data 250 is presented is a system designer, data 230 with visualization granularity information 240 of "0" is required because in order to determine the cause of a system failure, detailed analysis of the system's operating status is required before taking measures. On the other hand, if the user is an automobile insurance company or a driver, there is no need to present detailed information about the internal operation of the system; it is sufficient to simply show the part that caused the failure. Therefore, the visualization granularity information 240 may be data 230 of "1." Here, the visualization granularity information 240 has two levels, "0" and "1," but it may have multiple levels of granularity.
[0048] In this way, the visualization granularity information 240 determines the information granularity of the visualization data.
[0049] <Data conversion section> 12 is a flowchart illustrating the operation of the data conversion unit 810. In step S241, the data conversion unit 810 reads the safety analysis result 110P.
[0050] Next, in step S242, the data acquisition specifications 140P are read in. Next, in step S243, the data 160P is read in. In step S244, the visualization granularity information 240P is read in.
[0051] Next, in step S245, if the visualization granularity information 240P is "0", the process proceeds to step S246, and if the visualization granularity information 240P is not "0", the process proceeds to step S248.
[0052] In step S246, the data 160P is visualized in the detailed mode. On the other hand, in step S247, since the visualization granularity information 240P is not "0", the data 160P is visualized in the normal mode.
[0053] Next, in step S248, the visualization data 250 is stored in the data recording unit 170 of the vehicle driving data visualization device 800.
[0054] 13 is a diagram illustrating an example of visualization data 250 output in detailed mode. In step S246, the visualization data 250 is output in detailed mode. The visualization data 250 is expressed in tabular form, using the information read in steps S241 to S243, linking the identification ID, the source and destination of the data 160, 230, the location of the abnormality, the identification ID, and the communication time. The source and destination of the data 160, 230 are entered from the data acquisition specification 140P, the location of the abnormality is entered from the safety analysis result 110P and the data 160P, and the communication time linked to the identification ID is entered from the information in the data 160P.
[0055] 14 is a diagram illustrating an example of visualization data 250 output in normal mode. In step S247, the visualization data 250 is output in normal mode. The visualization data 250 includes the location of the abnormality, the cause of the abnormality determination, and the communication time linked to the identification ID. The location of the abnormality and the cause of the abnormality determination are listed from the safety analysis result 110P and data 160P, and the communication time linked to the identification ID is listed from the information in data 160P.
[0056] In this way, the data conversion unit 810 changes the visualization data to be output based on the visualization granularity information 240, and therefore it is possible to change the data to be presented depending on the target and user.
[0057] Although not shown in the present embodiment, the image from a camera mounted on a vehicle can be used as input, and the data conversion unit 810 can link the camera image with the safety analysis results 110P, data acquisition specifications 140P, and data 160P to output visualized data 250 in a more understandable form.
[0058] The vehicle travel data visualization device 800 according to this embodiment operates as described above. According to the vehicle travel data recording device 800 according to this embodiment, it is possible to present appropriate visualization data 250 for each target user from the data 160 output in the first embodiment.
[0059] As described above, the vehicle driving data visualization device is equipped with a data conversion unit that generates visualization data using the safety analysis results of the vehicle driving data recording device, data acquisition specifications and data, and visualization granularity information as input, so it can output visualization data that is suitable for the user. [Explanation of symbols]
[0060] 100 vehicle driving data recording device, 101 CPU, 102 memory, 103 auxiliary recording device, 110, 110P, 210 safety analysis results, 120, 120P communication specifications, 130 acquisition data determination unit, 140, 140P, 220 data acquisition specifications, 150 data acquisition unit, 160, 160P, 230 data, 170 data recording unit, 240, 240P visualization granularity information, 250, 250P, 251P visualization data, 200 HMI-ECU, 300 DMS-ECU, 400 ADAS-ECU, 500 control-ECU, 600 camera-ECU, 700 communication line, 800 vehicle driving data visualization device, 810 data conversion unit.
Claims
1. an acquisition data determination unit that determines data to be recorded regarding the operating status of a system composed of multiple devices based on the impact of the autonomous driving function, and determines data acquisition specifications that describe information necessary to store communication records of the devices, including identification IDs that identify the source and destination of communication of the devices; a data acquisition unit that acquires the data including the identification ID described in the data acquisition specification; a data recording unit that stores the data including the identification ID in a recording device;
2. 2. The vehicle driving data recording device according to claim 1, The vehicle driving data recording device is characterized in that the data includes a communication time.
3. A vehicle driving data visualization device comprising a data conversion unit that generates visualization data using as input the data stored in the vehicle driving data recording device described in claim 1 or 2 and visualization granularity information, which is information that indicates whether or not to visualize the data in detail.
4. The vehicle travel data visualization device according to claim 3, The vehicle driving data visualization device is characterized in that the data conversion unit changes the visualization data in accordance with the visualization granularity information.
Citation Information
Patent Citations
Vehicle expected function hazard assessment method and device, equipment and storage medium
CN112418711A
Apparatus, Method and Corresponding Computer Program for Determining Safety in a System and Obtaining That Safety
JP2005518992A
Data recording device and data recording program
JP2015212677A
Driver assistant system for automated logging of protocol data, and method
JP2017517787A
Storage method of traveling record data of block chain base and system for executing the same
JP2020038673A