Electronic control unit

The electronic control device uses feature matching and virtual recognition units to detect deceptive signals, enhancing the accuracy of autonomous vehicle navigation by adjusting positioning methods and sensor operations.

JP7738502B2Active Publication Date: 2025-09-12ASTEMO LTD
View PDF 10 Cites 0 Cited by

Patent Information

Application Number
JP2022039517
Authority / Receiving Office
JP · JP
Patent Type
Patents
Current Assignee / Owner
Filing Date
2022-03-14
Publication Date
2025-09-12
Estimated Expiration
2042-03-14

AI Technical Summary

Technical Problem

Conventional vehicle positioning systems cannot detect a decrease in positioning accuracy due to deceptive signals that deceive augmentation information, which is crucial for the safety of autonomous vehicles.

Method used

An electronic control device that includes a feature matching unit to match external environment recognition results with map information for absolute positioning, a virtual recognition unit for relative positioning, and a deception determination unit to detect a decrease in accuracy when the error between absolute and relative positions exceeds a threshold.

Benefits of technology

The device accurately detects decreases in positioning accuracy due to deceptive signals, preventing erroneous determinations and ensuring safe autonomous driving by adjusting navigation methods and sensor operations.

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure 0007738502000002
    Figure 0007738502000002
  • Figure 0007738502000003
    Figure 0007738502000003
  • Figure 0007738502000004
    Figure 0007738502000004
Patent Text Reader

Abstract

To provide an electronic control device capable of detecting a decrease in positioning accuracy due to deceptive signals.SOLUTION: An electronic control device 2 includes a feature collation unit 21, a virtual recognition unit 22, and a deception determination unit 23. The feature collation unit 21 obtains the absolute position of a feature by collating an external world recognition result based on a detection result of the feature by an external world sensor 5 with map information. The virtual recognition unit 22 generates a virtual recognition result corresponding to the external world recognition result, based on map information 4 and a positioning result based on an output of a receiver 3 that receives signals and reinforcement information from a positioning satellite, and acquires a relative position of the feature. The deception determination unit 23 detects a decrease in positioning accuracy due to a deception signal when a deception determination value, which increases as the magnitude of an error between the absolute position and the relative position of the feature and an error duration increase, exceeds a threshold value.SELECTED DRAWING: Figure 1
Need to check novelty before this filing date? Find Prior Art

Description

[Technical Field]

[0001] The present disclosure relates to electronic control devices. [Background technology]

[0002] There have been known inventions relating to technology for measuring the own position of a moving body. The following Patent Document 1 discloses a self-position measuring device that is mounted on a moving body and measures the own position of the moving body. This conventional self-position measuring device is characterized by comprising an inertial navigation system, a database, a reference point generating means, an information acquiring means, an information generating means, a position extracting means, and a navigation selecting means (Patent Document 1, claim 1, paragraph 0007, etc.).

[0003] The inertial navigation system measures the position of the moving object. The database is at least one of geographic information and celestial information. The reference point generation means estimates the existence range of the moving object based on the inertial navigation position measured by the inertial navigation system and divides the existence range to generate a plurality of reference points. The information acquisition means acquires at least one of terrestrial and celestial information corresponding to the database at the inertial navigation position measured by the inertial navigation system.

[0004] The information generating means generates, based on the database, estimated information that would be obtained when at least one of terrestrial and celestial information corresponding to the database is acquired for each of the plurality of reference points. The position extracting means compares the information acquired by the information acquiring means with the estimated information for each of the plurality of reference points generated by the information generating means, and extracts the position of one reference point corresponding to the estimated information that most closely matches.

[0005] The navigation selection means selects, based on the position of the one reference point extracted by the position extraction means, the navigation method with the smaller navigation error from among navigation methods including navigation using the inertial navigation system and navigation methods for determining the position of the one reference point, as the navigation method for measuring the aircraft's position.

[0006] This conventional aircraft position measuring device further includes a GPS receiver that receives GPS signals containing position information from GPS satellites (see Patent Document 1, claim 2, paragraph 0008, etc.). In this case, the inertial navigation system corrects the inertial navigation position based on the position information contained in the GPS signals. The navigation selection means includes a GPS usability determination means, a GPS unusable time measurement means, and a combined navigation means.

[0007] The GPS usability determination means determines the reliability of the GPS signal based on the position information included in the GPS signal, the inertial navigation position, and the position of the one reference point, and determines whether the GPS signal can be used. The GPS unusable time measurement means, when it is determined that the GPS signal is unusable, measures the GPS unusable time that has elapsed since it was determined that the GPS signal was unusable. The hybrid navigation means selects a navigation method for measuring the aircraft's position based on the GPS unusable time. [Prior art documents] [Patent documents]

[0008] [Patent Document 1] Japanese Patent Application Publication No. 2019-035670 Summary of the Invention [Problem to be solved by the invention]

[0009] For example, an autonomous vehicle achieves highly accurate positioning by receiving signals and augmentation information from satellites of the Global Navigation Satellite System (GNSS) using a receiver installed in the vehicle. Therefore, for the safety of an autonomous vehicle, it is important to detect a decrease in positioning accuracy due to intentional interference, such as a deceptive signal that deceives the augmentation information. However, as mentioned above, the conventional vehicle positioning device described in Patent Document 1 can determine whether a GPS signal can be used based on the reliability of the GPS signal, but cannot detect a decrease in positioning accuracy due to a deceptive signal.

[0010] The present disclosure provides an electronic control device capable of detecting a decrease in positioning accuracy due to a deceptive signal. [Means for solving the problem]

[0011] One aspect of the present disclosure is an electronic control device that includes: a feature matching unit that matches an external environment recognition result based on the detection result of a feature by an external sensor with map information to obtain the absolute position of the feature; a virtual recognition unit that generates a virtual recognition result corresponding to the external environment recognition result based on the map information and a positioning result based on the output of a receiver that receives signals and reinforcement information from a positioning satellite, to obtain the relative position of the feature; and a deception determination unit that determines a decrease in positioning accuracy due to a deception signal when a deception determination value that increases as the magnitude and duration of the error between the absolute position and the relative position of the feature increase exceeds a threshold value. [Effects of the Invention]

[0012] According to the above aspect of the present disclosure, it is possible to provide an electronic control device capable of detecting a decrease in positioning accuracy due to a deceptive signal. [Brief explanation of the drawings]

[0013] [Figure 1] 1 is a block diagram showing a first embodiment of an electronic control device according to the present disclosure. [Figure 2] 2 is a flowchart showing an example of a processing flow by the electronic control device of FIG. 1. [Figure 3] FIG. 2 is an image diagram showing an example of the map information of FIG. 1. [Figure 4] 2 is a table showing an example of map information in FIG. 1; [Figure 5] FIG. 3 is an image diagram illustrating a process for obtaining the relative positions of the features in FIG. 2. [Figure 6] FIG. 3 is an image diagram illustrating a process for obtaining the relative positions of the features in FIG. 2. [Figure 7] FIG. 3 is an image diagram illustrating a process for obtaining the relative positions of the features in FIG. 2. [Figure 8] 3 is a table illustrating the process of obtaining the relative positions of the features in FIG. 2 . [Figure 9]A conceptual diagram of the process of calculating the deception judgment value and the deception judgment process in Figure 2. [Figure 10] FIG. 4 is a block diagram showing a second embodiment of an electronic control device according to the present disclosure. [Figure 11] FIG. 10 is a block diagram showing a third embodiment of an electronic control device according to the present disclosure. [Figure 12] 12 is a table showing an example of operational constraints imposed by the constraint level output unit of FIG. 11 . [Figure 13] FIG. 10 is a block diagram showing a fourth embodiment of an electronic control device according to the present disclosure. [Figure 14] FIG. 14 is a flowchart illustrating the operation of the recognition result verification unit in FIG. 13. [Figure 15] FIG. 14 is a flowchart illustrating the operation of the consistency determination unit in FIG. 13. [Figure 16] FIG. 14 is a flowchart illustrating the operation of the sudden change determination unit in FIG. 13. [Figure 17] FIG. 10 is a block diagram showing a fifth embodiment of an electronic control device according to the present disclosure. DETAILED DESCRIPTION OF THE INVENTION

[0014] Hereinafter, an embodiment of an electronic control device according to the present disclosure will be described with reference to the drawings.

[0015] [Embodiment 1] 1 is a block diagram showing a first embodiment of an electronic control device according to the present disclosure. The electronic control device 2 of this embodiment is mounted on a vehicle 1, such as an autonomous vehicle, and determines whether positioning accuracy has decreased due to a deceptive signal that deceives augmentation information from a global navigation satellite system (GNSS). The vehicle 1 on which the electronic control device 2 is mounted includes, for example, a receiver 3 that receives signals and augmentation information from GNSS satellites, map information 4 such as high-precision three-dimensional map data (HD map), external sensors 5 such as a camera or laser radar, and a vehicle control device 6 that controls the autonomous driving of the vehicle 1.

[0016] The electronic control device 2 may be configured, for example, by one or more microcontrollers including a central processing unit (CPU), memories such as ROM and RAM, a timer, and an input / output unit. As shown in Fig. 1, the electronic control device 2 may include, for example, a feature matching unit 21, a virtual recognition unit 22, and a deception determination unit 23. The electronic control device 2 may further include, for example, a positioning calculation unit 24 and an external environment recognition unit 25.

[0017] 1 represent the functions of the electronic control device 2 that are realized, for example, by a CPU executing a program stored in a memory. If the receiver 3 has the function of a positioning calculation unit 24, which will be described later, the electronic control device 2 does not need to have the positioning calculation unit 24. If the external sensor 5 has the function of an external environment recognition unit 25, which will be described later, the electronic control device 2 does not need to have the external environment recognition unit 25. The operation of the electronic control device 2 of this embodiment will be described below with reference to FIG. 2.

[0018] 2 is a flow diagram showing an example of the flow of processing by the electronic control unit 2 of FIG. 1. When the electronic control unit 2 starts the processing flow shown in FIG. 2, it first executes process S1 to acquire the absolute position of a feature. In this process S1, the external environment recognition unit 25 generates an external environment recognition result based on, for example, the detection result of the external environment sensor 5 that detects features around the vehicle 1 including in front of the vehicle 1. In addition, the feature matching unit 21 matches the external environment recognition result generated by the external environment recognition unit 25 with the map information 4 to acquire the absolute position of the feature detected by the external environment sensor 5.

[0019] FIG. 3 is an image diagram showing an example of the map information 4 of FIG. 1. FIG. 4 is a table showing an example of the map information 4 of FIG. 1. The map information 4 includes information on features such as buildings B1, B2, ..., utility poles P1, P2, ..., signs SS1, SS2, ..., road marking RS1, roads R1, R2, .... The information on each feature in the map information 4 includes information such as identification information (ID), type, planar coordinates, height, width, individual attributes, etc. The map information 4 may have three-dimensional coordinates instead of planar coordinates.

[0020] The plane coordinates of buildings B1 and B2 are, for example, the coordinates of the vertices of buildings B1 and B2 on the ground plane. Similarly, the plane coordinates of utility poles P1 and P2 are, for example, the coordinates of the centers of utility poles P1 and P2 on the ground plane. The coordinate system of the plane coordinates may be, for example, a Cartesian coordinate system, a longitude-latitude coordinate system, or any other coordinate system.

[0021] The external environment sensor 5 detects actual features around the vehicle 1 included in the map information 4, for example, as shown in Fig. 3, and outputs the detection result to the external environment recognition unit 25. The external environment recognition unit 25 generates an external environment recognition result including a recognition result of the actual features around the vehicle 1 based on the detection result of the external environment sensor 5, and outputs the generated result to the feature matching unit 21.

[0022] The feature matching unit 21 matches the external environment recognition result, which includes the recognition result of the actual features around the vehicle 1 input from the external environment recognition unit 25, with the information on the features of the vehicle 1 included in the map information 4. As a result, the feature matching unit 21 can, for example, associate the recognition result of the features included in the external environment recognition result with the information on the features included in the map information 4, and acquire the absolute position, such as planar coordinates or three-dimensional coordinates, for the recognition result of the features.

[0023] Furthermore, by storing past matching results, absolute positions, and recognition results from the external environment recognition unit 25 as necessary, and using the past information during matching to narrow the search range of the map to the vicinity, or by comparing the map with features in the area surrounding the vehicle's driving trajectory, the processing time required to match the recognition results from the external environment recognition unit 25 with the map information 4 can be shortened, and erroneous matching to locations on the map where similar features are arranged can be prevented.

[0024] Furthermore, by comparing multiple features together with a map, the position error of the features in the external environment recognition unit 25 can be estimated. For example, if there are five features spaced 1 m apart on the map, but the feature recognition results from the external environment sensor show the distances from the closest feature to the next feature as 1.0 m, 1.1 m, 0.9 m, and 1.0 m, it can be estimated that the third feature is 0.1 m away. Alternatively, the residual error from the least squares method can be treated as the position error of the features.

[0025] To group the multiple features mentioned above, the features included in the field of view of the external sensor at a certain time may be treated as one group, or the relative relationships of the features may be determined using vehicle speed or wheel speed pulses, etc., and then grouped.

[0026] Next, the electronic control unit 2 executes a process S2 for acquiring the relative positions of features, as shown in Fig. 2. In this process S2, the positioning calculation unit 24 of the electronic control unit 2 calculates the positioning result of the vehicle 1 based on, for example, the output of the receiver 3 that receives signals from GNSS satellites and augmentation information. The positioning calculation unit 24 may also determine, for example, whether or not the reception status of signals from GNSS satellites has deteriorated, or whether or not there is an abnormality in the positioning status based on the reception status of signals from the satellites.

[0027] Furthermore, in this process S2, the virtual recognition unit 22 generates a virtual recognition result corresponding to the external environment recognition result of the external environment recognition unit 25 based on the positioning result of the vehicle 1 input from the positioning calculation unit 24 and the map information 4, and acquires the relative positions of the features around the vehicle 1 with respect to the vehicle 1. Furthermore, the virtual recognition unit 22 calculates the recognition stability and recognition ease based on the map information 4. 4 The value is read from or calculated.

[0028] 5 to 7 are image diagrams illustrating process S2 for acquiring the relative positions of the features in Fig. 2, and Fig. 8 is a table illustrating process S2. In process S2, the electronic control unit 2 generates, for example, a positioning result using the positioning calculation unit 24 based on the output of the receiver 3, which receives signals and augmentation information from positioning satellites. Furthermore, the virtual recognition unit 22 generates a virtual recognition result VRR as shown in Fig. 6 or Fig. 7 and Fig. 8 based on the positioning result input from the positioning calculation unit 24 and the map information 4.

[0029] The virtual recognition result VRR shown in Figures 6 to 8 can be obtained, for example, as follows: First, as shown in Figure 5, the vehicle 1 is placed on the map of the map information 4 based on the positioning result PR calculated by the positioning calculation unit 24. Next, the detection result of the features on the map of the map information 4 is calculated based on specifications including the imaging area IA of the external sensor 5 mounted on the vehicle 1, thereby obtaining the virtual recognition result VRR as shown in Figure 6 or 7.

[0030] In Fig. 6, the virtual recognition result VRR corresponding to the external world recognition result based on the detection result of actual features by the external world sensor 5 is represented as a three-dimensional image based on various information such as the type of feature, plane coordinates, height, width, and individual attributes contained in the map information 4. Figs. 7 and 8 show the positions of features in the virtual recognition result VRR corresponding to the external world recognition result of the external world sensor 5. In Figs. 7 and 8, information on features in the map information 4 contained in the image area corresponding to the imaging area IA of the external world sensor 5 is represented as a combination of the type of feature and coordinates.

[0031] As described above, in process S2, the virtual recognition unit 22 generates a virtual recognition result VRR corresponding to the external environment recognition result based on the detection results of the external environment sensor 5 based on the positioning result of the vehicle 1 input from the positioning calculation unit 24 and the map information 4, and obtains the relative positions of the features around the vehicle 1 with respect to the vehicle 1. Next, the electronic control unit 2 executes process S3 for calculating a deception determination value and deception determination process S4 shown in Figure 2.

[0032] Figure 9 is a conceptual diagram of the process S3 for calculating the deception determination value and the deception determination process S4 in Figure 2. The vehicle 1 equipped with the electronic control device 2 of this embodiment is, for example, an autonomous vehicle that travels autonomously from a departure point to a destination by controlling various actuators of the vehicle 1 with a vehicle control device 6. The vehicle 1 can perform centimeter-level high-precision positioning and safely perform autonomous driving by receiving signals and augmentation information from GNSS satellites with a receiver 3, for example.

[0033] However, if the reinforcing information is deceived by an intentional deception signal, there is a risk of the positioning accuracy of the vehicle 1 being reduced. Therefore, the electronic control unit 2 of this embodiment executes a process S3 for calculating a deception determination value and a deception determination process S4, and if the deception determination value exceeds a threshold value in the deception determination process S4, it determines that the positioning accuracy of the vehicle 1 has been reduced (process S5). These processes S3 will be described below. ,S4,S5 will be explained in detail.

[0034] When the electronic control device 2 starts process S3 for calculating the deception determination value, the deception determination unit 23 obtains the absolute position of the feature based on the external environment recognition result of the external environment recognition unit 25 from the feature matching unit 21, and obtains the relative position of the feature with respect to the vehicle 1 based on the GNSS positioning result from the virtual recognition unit 22. Furthermore, the deception determination unit 23 calculates, for example, the error Err between the absolute position and relative position of the feature.

[0035] 9, assume that the features for which the deception determination unit 23 calculates the position error Err between the absolute position and the relative position include, for example, signs SS1, SS2, and SS3 ahead of the vehicle 1, crosswalks C1 and C2, and lane markings LM. In this case, the lane markings LM may be worn away due to wear or temporarily missing due to road construction, making detection by the external sensor 5 less stable than for other features and more likely to result in a position error Err.

[0036] On the other hand, compared to other features, signs SS1, SS2, and SS3 are less likely to be obscured by other vehicles V or other obstacles, and are more stable in detection by the external sensor 5 than other features, making them less likely to generate position errors Err. Therefore, in process S3 of calculating the deception determination value, the deception determination unit 23 may use, for example, the recognition stability and recognition ease shown in Table 1 below.

[0037] [Table 1]

[0038] The recognition stability is an index that indicates, for example, the ease with which a feature can be detected by the external sensor 5. In the example shown in FIG. 9 and Table 1, signs SS1, SS2, and SS3 are set to the highest recognition stability of 1.0 because they are extremely unlikely to be blocked by an obstacle. Similarly, lane marking LM is set to a relatively high recognition stability of 0.9 because it is relatively unlikely to be blocked by an obstacle. On the other hand, crosswalks C1 and C2 are set to a relatively low recognition stability of 0.4 because they may be blocked by a preceding vehicle, for example.

[0039] The recognizability is an index indicating the ease of recognizing the vehicle's position based on features detected by the external sensor 5, for example. In the example shown in FIG. 9 and Table 1, signs SS1, SS2, and SS3 are fewer in number than other features, and if detected successfully, they are easily distinguished from other nearby features, making it easy to recognize the vehicle's position. Therefore, the recognizability is set to a relatively high 0.9. Furthermore, crosswalks C1 and C2 are only found in scattered locations and are relatively easy to distinguish from other features. However, crosswalks may be installed both before entering and after passing through an intersection. If only one of the crosswalks is successfully detected, the two may be confused and the vehicle's position may be misidentified. Therefore, the recognizability is set to a relatively low 0.5. On the other hand, lane markings LM are found everywhere, making it difficult to distinguish specific lane markings LM. Therefore, the recognizability is set to the lowest 0.1.

[0040] Although not included in Table 1, the recognizability can also be set separately for a component along the direction of travel of the vehicle (vertical component) and a component perpendicular to the direction of travel of the vehicle (horizontal component). For example, even if a lane marking painted as a solid line can be detected vertically, it does not provide a clue to recognizing the vehicle's position, so the recognizability is set to a low value such as 0.0. On the other hand, even if the lane marking can be detected horizontally, it may be mistaken for an adjacent lane, but if the driving lane is identified, the lateral position within the lane can be recognized, so the recognizability is set to a relatively low value of 0.5. This makes it possible to handle the recognizability of the vehicle's position based on detected features separately for the vertical and horizontal directions, allowing for flexible recognition of the vehicle's position, such as improving accuracy in either the vertical or horizontal direction.

[0041] That is, in the example shown in Table 1, the recognition stability increases closer to 1.0 as the feature is less likely to be obscured by obstacles, and the recognition ease increases closer to 1.0 as the feature is easier to recognize. Note that the recognition stability shown in Table 1 is an example, and the recognition stability also depends on factors such as the size of the feature (the larger the feature, the higher the recognition ease), the number of lanes on the road (the fewer the recognition ease and Recognition stability The recognition stability may be set based on the feature height (the higher the feature height, the higher the recognition stability). In addition, since the recognition stability is the likelihood of being confused with another recognition target (the higher the likelihood, the lower the recognition stability), it may be calculated or set based on, for example, a confusion matrix or inter-class distance used in machine learning.

[0042] Furthermore, the deception determination unit 23 calculates a deception determination value for determining whether the GNSS positioning accuracy has decreased due to a deception signal, using the error Err between the absolute position and relative position of the feature and the error duration. In the example shown in Figure 9, at time t1, an error Err occurs between the absolute position and relative position of the lane marking LM detected by the external sensor 5, and this error Err continues to occur from before time t1 until time t2.

[0043] In this case, in process S3, the deception determination unit 23 calculates a deception determination value DV based on the magnitude of the error Err and the duration of the error. Here, the deception determination unit 23 may calculate the deception determination value DV using the recognition stability and recognition ease described above. The deception determination unit 23, for example, calculates the deception determination value DV by multiplying the recognition stability and recognition ease of the lane marking LM by the error Err between the absolute position and relative position of the lane marking LM. As described above, if the recognition ease of the lane marking LM is set low, the value of the deception determination value DV will be relatively small even if the error Err is relatively large.

[0044] Thereafter, the deception determination unit 23 executes process S4 to determine whether the calculated deception determination value DV exceeds a predetermined threshold value Th, as shown in Figure 2. As shown in Figure 9, between time t1 and time t2, the deception determination value DV is significantly lower than the threshold value Th. Therefore, in process S4, the deception determination unit 23 determines that the deception determination value DV does not exceed the predetermined threshold value Th (NO). Thereafter, the electronic control unit 2 terminates the processing flow shown in Figure 2 and starts again.

[0045] As a result, as shown in Figure 9, at time t2, sign SS1 is detected by the external sensor 5, and after processes S1 and S2, the deception determination unit 23 calculates in process S3 that the error Err between the absolute position and relative position of sign SS1 is almost zero. As mentioned above, sign SS1 has high recognition stability and recognition ease, and the reliability of the absolute position calculated in process S1 is high. In other words, at time t2, there is a low possibility that the GNSS augmentation information has been deceptive, so the deception determination unit 23 reduces the deception determination value DV or sets it to zero.

[0046] As a result, at time t2, the deception determination unit 23 determines in process S4 that the deception determination value DV does not exceed the predetermined threshold value Th (NO), and the electronic control unit 2 terminates and restarts the processing flow shown in Figure 2. Thereafter, at time t4, an error Err occurs between the absolute position and relative position of the crosswalk C1, causing the deception determination value DV to rise, and from time t5 to time t9, the error Err between the absolute position and relative position of the lane marking LM continues to occur. In this way, the deception determination unit 23 increases the deception determination value DV as the magnitude of the error Err and the error duration over which the error Err continues to occur increase.

[0047] In the example shown in Figure 9, at time t6, the rear edge of the crosswalk C1 is blocked by another vehicle V and is not detected by the external sensor 5. However, as mentioned above, the recognition stability of the crosswalk C1 is set relatively low, so even if it is not detected by the external sensor 5, the impact on the deception judgment value DV is small.

[0048] Also, at time t11, the error Err between the absolute position and relative position of the lane marking LM is large, but the recognizability of the lane marking LM is set relatively low. Meanwhile, at the same time, the error Err between the absolute position and relative position of the crosswalk C2, which is set to a relatively high recognizability, is almost zero. In this case, the deception determination value DV calculated by the deception determination unit 23 is, for example, less influenced by the error Err of the lane marking LM, which has a low recognizability, and more influenced by the crosswalk C2, which has a high recognizability.

[0049] Then, as shown in Figure 9, at time t13, the error Err between the absolute position and relative position of marker SS2 increases, and at time t15, the error Err between the absolute position and relative position of marker SS3 is calculated in a similar manner. The recognition stability and recognition ease of markers SS2 and SS3 are set relatively high compared to other features, for example, as described above. Also, as described above, the deception determination unit 23 increases the deception determination value DV as the magnitude of the error Err between the absolute position and relative position of the feature and the duration of the error increase.

[0050] As a result, suppose that the deception determination value DV exceeds the threshold value Th at time t15. Then, in process S4 shown in FIG. 2, the deception determination unit 23 determines that the deception determination value DV has exceeded the threshold value Th (YES), and in the subsequent process S5, determines that the positioning accuracy has decreased due to the deception signal. In this process S5, the deception determination unit 23 may determine that the positioning accuracy has decreased due to the deception signal, for example, if there is no abnormality in the positioning status based on the output of the receiver 3 that receives signals from GNSS satellites and the deception determination value DV has exceeded the threshold value Th.

[0051] Thereafter, the electronic control unit 2 ends the processing flow shown in Figure 2 and outputs the GNSS positioning result and the determination result of the degradation of positioning accuracy due to the deception signal from the deception determination unit 23 to the vehicle control unit 6. Note that if the deception determination unit 23 determines that the positioning accuracy has been degraded due to the deception signal, the determination result may be output to the positioning calculation unit 24. When the positioning calculation unit 24 receives a determination result indicating the degradation of positioning accuracy due to the deception signal from the deception determination unit 23, the positioning calculation unit 24 changes the method of acquiring the augmentation information, for example. Specifically, if the augmentation information was previously acquired via the Internet, the positioning calculation unit 24 switches the method of acquiring the augmentation information to via GNSS satellites.

[0052] Furthermore, when determining whether or not the reception conditions for signals from GNSS positioning satellites have deteriorated as described above, the positioning calculation unit 24 may operate as follows: For example, when the deception determination unit 23 determines that the positioning accuracy has deteriorated due to a deception signal and that the reception conditions for signals from positioning satellites have deteriorated, the positioning calculation unit 24 may calculate the positioning result by excluding the augmentation information.

[0053] The operation of the electronic control unit 2 of this embodiment will be described below.

[0054] As described above, the electronic control unit 2 of this embodiment is mounted on a vehicle 1, such as an autonomous vehicle, that performs high-precision positioning based on the output of a receiver 3 that receives signals from GNSS satellites and augmentation information. A vehicle control unit 6 mounted on the vehicle 1 controls actuators in various parts of the vehicle 1 using, for example, map information 4 and a positioning result from a positioning calculation unit 24, thereby causing the vehicle 1 to travel autonomously. Therefore, in order to ensure the safety of the vehicle 1, it is important to detect a decrease in positioning accuracy due to a deceptive signal that deceives the augmentation information. However, while the conventional vehicle position measurement device can determine whether a GPS signal can be used based on the reliability of the GPS signal, it cannot detect a decrease in positioning accuracy due to a deceptive signal.

[0055] In contrast, the electronic control device 2 of this embodiment is equipped with a feature matching unit 21 that, as described above, matches the external environment recognition result based on the detection result of the feature by the external environment sensor 5 with the map information 4 to acquire the absolute position of the feature. The electronic control device 2 also has a virtual recognition unit 22 that generates a virtual recognition result VRR corresponding to the external environment recognition result of the external environment recognition unit 25 based on the positioning result based on the output of the receiver 3 that receives signals and augmentation information from positioning satellites and the map information 4, to acquire the relative position of the feature. Furthermore, the electronic control device 2 is equipped with a deception determination unit 23 that determines a decrease in positioning accuracy due to a deception signal when a deception determination value DV, which increases as the magnitude and duration of the error Err between the absolute position and relative position of the feature, increases, exceeds a threshold value Th.

[0056] With this configuration, the electronic control device 2 of this embodiment can use the feature matching unit 21 to match the recognition results of features detected by the external sensor 5 with the map information 4 and obtain the absolute position of the feature. Furthermore, the electronic control device 2 of this embodiment can use the GNSS positioning results and the map information 4 to generate a virtual recognition result VRR corresponding to the external recognition result based on the detection results of the external sensor 5, and obtain the relative position of the feature based on the GNSS positioning result. Then, the electronic control device 2 can use the deception determination unit 23 to determine that the positioning accuracy has decreased due to a deception signal when the deception determination value DV, which increases as the magnitude and duration of the error Err between the absolute position and relative position of the feature increases, exceeds the threshold value Th.

[0057] Therefore, the electronic control unit 2 of this embodiment can detect errors in the GNSS positioning results that gradually increase due to deception of the augmentation information, and determine whether the GNSS positioning accuracy has decreased due to the deception signal. Furthermore, by using the deception determination value DV, the electronic control unit 2 of this embodiment can prevent erroneous determination of a decrease in positioning accuracy due to the deception signal, even if, for example, the external sensor 5 suddenly fails to detect a target, or a short-term abnormality occurs in the reception status of signals from GNSS satellites or augmentation signals.

[0058] In addition, in the electronic control device 2 of this embodiment, the deception determination unit 23 calculates the deception determination value DV by multiplying the error Err by the recognition stability, which indicates the ease of detecting an object by the external sensor 5, and the recognition ease, which indicates the ease of identifying an object.

[0059] With this configuration, the electronic control unit 2 of this embodiment can reduce the impact of the error Err between the absolute position and relative position of features with low recognition stability or low recognition ease on the deception determination value DV. Furthermore, the electronic control unit 2 of this embodiment can increase the impact of the error Err between the absolute position and relative position of features with high recognition stability or high recognition ease on the deception determination value DV. Therefore, the electronic control unit 2 of this embodiment can more accurately detect a decrease in positioning accuracy due to a deception signal.

[0060] The electronic control device 2 of this embodiment further includes a positioning calculation unit 24 that calculates the positioning result based on the output of the receiver 3 and determines whether or not there is an abnormality in the positioning state. The deception determination unit 23 determines that the positioning accuracy has decreased due to the deception signal when there is no abnormality in the positioning state and the deception determination value DV exceeds the threshold value Th.

[0061] With this configuration, the electronic control unit 2 of this embodiment can suspend the determination of the degradation of positioning accuracy due to a deception signal when it detects that an abnormality has occurred in the GNSS positioning state. Therefore, according to the electronic control unit 2 of this embodiment, when an abnormality has occurred in the GNSS positioning state, it is possible to prevent the erroneous determination of the degradation of positioning accuracy due to a deception signal and to more accurately determine the degradation of positioning accuracy due to a deception signal.

[0062] Furthermore, in the electronic control device 2 of this embodiment, the positioning calculation unit 24 changes the method of acquiring the reinforcing information when the deception determination unit 23 determines that the positioning accuracy has decreased due to a deceptive signal. More specifically, when the positioning calculation unit 24 has previously acquired the reinforcing information via the Internet, for example, the positioning calculation unit 24 switches to acquiring the reinforcing information via a satellite, thereby enabling the use of undeceptive reinforcing information and improving the safety of the autonomous driving of the vehicle 1.

[0063] In the electronic control device 2 of this embodiment, the positioning calculation unit 24 determines whether or not the reception condition of the signal from the GNSS positioning satellite has deteriorated. When the deception determination unit 23 determines that the positioning accuracy has decreased due to the deception signal and that the reception condition of the signal from the positioning satellite has deteriorated, the positioning calculation unit 24 calculates the positioning result by excluding the augmentation information.

[0064] With this configuration, the electronic control unit 2 of this embodiment can perform minimum positioning without being affected by the deception signal even when the reception condition of the signal from the positioning satellite deteriorates and the reinforcing information is deceptively deceptive. Therefore, the electronic control unit 2 of this embodiment can improve the safety of the autonomous driving of the vehicle 1.

[0065] As described above, according to this embodiment, it is possible to provide an electronic control device 2 that is capable of detecting a decrease in positioning accuracy due to a deceptive signal.

[0066] [Embodiment 2] Below, a second embodiment of an electronic control device according to the present disclosure will be described with reference to Figure 10. Figure 10 is a block diagram showing a second embodiment of an electronic control device according to the present disclosure. The electronic control device 2 of this embodiment differs from the electronic control device 2 of the first embodiment described above in that it further includes an external environment determination unit 26 and in the content of the deception determination process S4 by the deception determination unit 23. Other aspects of the electronic control device 2 of this embodiment are similar to those of the electronic control device 2 of the first embodiment described above, so similar parts will be given the same symbols and descriptions will be omitted.

[0067] As shown in FIG. 10 , the electronic control device 2 of this embodiment further includes an external environment determination unit 26. The external environment determination unit 26 determines whether the detection accuracy of the external sensor 5 has decreased due to the external environment. More specifically, the external environment determination unit 26 determines whether the detection accuracy of the external sensor 5 has decreased due to the external environment, including the brightness around the vehicle 1, weather conditions such as sunny, rainy, snowy, and foggy, and dirt on the external sensor 5, based on the external environment recognition result recognized by the external environment recognition unit 25 based on the detection result of the external sensor 5. The deception determination unit 23 increases the threshold value Th of the deception determination value DV when the external environment determination unit 26 determines whether the detection accuracy of the external sensor 5 has decreased.

[0068] The electronic control device 2 of this embodiment can not only achieve the same effects as the electronic control device 2 of the above-described first embodiment, but also prevent erroneous determinations in the deception determination process S4 due to a decrease in the detection accuracy of the external sensor 5 caused by the external environment. Therefore, the electronic control device 2 of this embodiment can more accurately determine a decrease in positioning accuracy due to a deception signal.

[0069] [Embodiment 3] Hereinafter, a third embodiment of an electronic control device according to the present disclosure will be described with reference to Fig. 11 and Fig. 12. Fig. 11 is a block diagram showing the third embodiment of an electronic control device according to the present disclosure. Fig. 12 is a table showing an example of operational constraints imposed by the constraint level output unit 27 included in the electronic control device 2 of the present embodiment shown in Fig. 11.

[0070] The electronic control device 2 of this embodiment differs from the electronic control device 2 of the first embodiment in that it further includes a restriction level output unit 27 and that the output of the restriction level output unit 27 is input to the vehicle control device 6. Other aspects of the electronic control device 2 of this embodiment are similar to those of the electronic control device 2 of the first embodiment, and therefore similar parts are denoted by the same reference numerals and description thereof will be omitted.

[0071] The electronic control device 2 of this embodiment further includes a constraint level output unit 27 that outputs a constraint level for operations related to autonomous driving of the vehicle 1 based on the method of acquiring the reinforcing information and whether or not the reinforcing information is excluded. The constraint level output unit 27 determines the operational constraint to be output to the vehicle control device 6 based on, for example, the time series of the error Err between the absolute position and relative position of the feature input from the deception determination unit 23 and the route by which the reinforcing information is acquired by the positioning calculation unit 24 or whether or not the reinforcing route is excluded.

[0072] More specifically, the constraint level output unit 27 determines the level Lv of the operational constraints on the vehicle control device 6 based on the magnitude and duration of the error Err input from the deception determination unit 23, and the method of acquiring the reinforcing information or the status of the exclusion of the reinforcing information, as shown in Fig. 12, for example. More specifically, when it is input that the error Err has been equal to or less than a predetermined error threshold Err1 for the past 60 seconds and that the method of acquiring the reinforcing information is via the Internet, the constraint level output unit 27 sets the constraint level Lv to 1. This releases all operational constraints on the vehicle control device 6, and all operations of the vehicle control device 6 are permitted.

[0073] Furthermore, when it is input that the error Err for the past 60 seconds has been equal to or less than a predetermined error threshold value Err1, that the error Err for the most recent 10 seconds has been greater than the error threshold value Err1 and less than the error threshold value Err2, and that the method of obtaining the reinforcement information is via the Internet, the constraint level output unit 27 sets the constraint level Lv to 2. As a result, operational constraints are imposed on the operation of the vehicle control device 6, such as preventing automatic approach to a loading platform in a limited area such as a logistics truck collection point. Furthermore, on general roads, operational constraints are imposed, such as preventing right and left turns at intersections with a road width of less than a certain value.

[0074] Furthermore, if the error Err is equal to or greater than a predetermined error threshold value Err2 for the most recent 10 seconds or more and it is input that the method of acquiring the reinforcement information is via satellite, the constraint level output unit 27 sets the constraint level Lv to 3. As a result, the operation of the vehicle control device 6 is restricted such that, for example, automatic parking in a parking space is inhibited in a limited area such as a logistics truck collection point, and when a route that passes through a path on a general road with a certain road width or less is set, operation constraints are imposed such that the route is changed to a route that passes through a wider road.

[0075] Furthermore, when it is input that the error Err is equal to or greater than a predetermined error threshold value Err3 for 10 seconds or more and that the reinforcing information has been excluded, the constraint level output unit 27 sets the constraint level Lv to 4. As a result, the operation of the vehicle control device 6 is, for example, restricted from autonomous driving and switched to driving assistance. Furthermore, when it is input that the error Err is equal to or greater than a predetermined error threshold value Err4 and that the reinforcing information has been excluded, the constraint level output unit 27 sets the constraint level Lv to 5. As a result, the vehicle control device 6, for example, cancels autonomous driving and driving assistance and accepts manual driving by the driver.

[0076] As described above, the electronic control device 2 of this embodiment further includes the constraint level output unit 27 that outputs the constraint level for operations related to the autonomous driving of the vehicle based on the method for acquiring the reinforcing information and whether or not the reinforcing information is excluded. With this configuration, the electronic control device 2 of this embodiment can improve the safety of the autonomous driving of the vehicle 1 by the vehicle control device 6.

[0077] [Embodiment 4] Hereinafter, a fourth embodiment of an electronic control device according to the present disclosure will be described with reference to FIGS. 13 to 16. The block diagram illustrating the fourth embodiment of an electronic control device according to the present disclosure is the same as any one of FIGS. 1, 10, and 11, as in the first to third embodiments. However, this embodiment differs from the first to third embodiments in that the external environment recognition unit 25 not only generates an external environment recognition result including a recognition result of actual features around the vehicle 1 based on the detection result of the external environment sensor 5, but also generates a recognition certainty of the actual features around the vehicle 1 and outputs it to the feature matching unit 21. Other aspects of the electronic control device 2 of this embodiment are similar to those of the electronic control device 2 of the first to third embodiments, and therefore similar parts are denoted by the same reference numerals and description thereof will be omitted.

[0078] Figure 13 is a block diagram of the deception determination unit 23 shown in Figure 1, 10 or 11. The deception determination unit 23 has a feature position estimation result receiving unit 30 that receives output from the feature matching unit 21 and a recognition certainty receiving unit 31. The deception determination unit 23 also has a virtual recognition result receiving unit 32 that receives output from the virtual recognition unit 22, as well as a recognition result verification unit 33, a consistency determination unit 34, a sudden change determination unit 35, and a deception determination result transmitting unit 36.

[0079] Fig. 14 is a flow diagram illustrating the operation of the recognition result verification unit 33 of Fig. 13. In step S11, the feature position estimation result receiving unit 30 acquires from the feature matching unit 21 the external environment recognition result of the external environment recognition unit 25 and the absolute position of the feature based on the map information 4. In addition, the recognition certainty receiving unit 31 acquires the recognition certainty of the feature based on the certainty of the external environment recognition by the external environment recognition unit 25 and the certainty when matching the absolute position of the external environment recognition unit 25 with the map information 4.

[0080] In step S12, the virtual recognition result receiving unit 32 acquires the relative position of the feature with respect to the vehicle 1 based on the GNSS positioning result output by the virtual recognition unit 22 from the virtual recognition result receiving unit 32, as well as the recognition stability and recognition ease.

[0081] Next, in steps S13 to S18, the recognition result verification unit 33 determines whether or not each feature included in the virtual recognition result at either the feature recognition time of the external sensor 5 or the positioning time of the receiver 3 was recognized, based on the position estimation result and position error estimation result of the external feature, the recognition certainty, the relative position of the feature based on the map, and the recognition stability and recognition ease, received from the feature position estimation result receiving unit 30, the recognition certainty receiving unit 31, and the virtual recognition result receiving unit 32.

[0082] In step S13, the following procedures from step S14 to step S17 are executed for all features in the virtual recognition result. In step S14, features in the external world recognition result corresponding to each target feature in the virtual recognition result are estimated. This estimation of the corresponding feature can be performed, for example, by the ICP (Iterative Closest Point) method.

[0083] In step S15, if the difference between the feature position of the virtual recognition result and the feature position of the external world recognition result for the associated feature, i.e., the position error, is smaller than a predetermined threshold and the certainty of the feature recognition of the external world recognition result is larger than a predetermined threshold, the recognition result verification is determined to be successful (Yes in S15); otherwise, the recognition result verification is determined to be unsuccessful (No in S15). Note that the certainty is an index that increases and approaches 1 when the certainty of the match is high, like the similarity in template matching, and decreases and approaches 0 when the certainty is low.

[0084] In step S16, the recognition result in this execution of the recognition result verification unit 33 is updated. Specifically, the number of recognition targets is incremented by 1, the number of successful recognition verifications is incremented by 1, and the position error is accumulated to update the error amount. Note that the recognition targets here refer to features, and in this document, there is no particular distinction between the two.

[0085] Similarly, in step S17, the recognition result in this execution by the recognition result verification unit 33 is updated. Specifically, the number of recognition targets is incremented by 1, and the positional errors are accumulated to update the error amount. Once execution has been completed for all the features in the virtual recognition result, the process proceeds to step S18, where the number of recognition targets, the number of successful recognition verifications, the accumulated error amount, and the error amount for each feature are recorded in a recording device (not shown) and output to the consistency determination unit 34.

[0086] Fig. 15 is a flow diagram illustrating the operation of the consistency determination unit 34 in Fig. 13. The consistency determination unit 34 determines whether or not there is a difference between the external environment recognition result based on the external environment sensor 5 and the positioning calculation result based on the GNSS receiver 3 at either the feature recognition time of the external environment sensor 5 or the positioning time of the receiver 3.

[0087] In step S21, the consistency determination unit 34 receives the number of recognition targets, the number of successful recognition verifications, the cumulative error amount, and the error amount for each feature output from the recognition result verification unit 33. In step S22, the consistency determination unit 34 acquires the recognition stability and recognition ease for each feature output from the virtual recognition result receiving unit 32. In step S23, the following procedures of steps S24 and S25 are executed for all features in the virtual recognition result.

[0088] In step S24, if the error amount of each recognition target (= the error amount of each feature) is equal to or greater than a predetermined threshold (Yes in S24), there is a high possibility that there is a difference between the external world recognition result and the positioning calculation result, so the process proceeds to step S25, where the mismatch confidence factor is added. If the error amount of each recognition target is not equal to or greater than the predetermined threshold (No in S24), the mismatch confidence factor is not changed.

[0089] In step S25, the mismatch confidence is added based on the recognition ease and recognition stability. The recognition ease and recognition stability are expressed as values ​​between 0 and 1 as shown in Table 1, and based on this and the amount of error for each recognition target, the added amount of mismatch confidence is calculated, for example, by the following formula (1).

[0090] (Addition amount) = (Error amount) × (Ease of recognition) × (Recognition stability) (1)

[0091] When processing is completed for all features of the virtual recognition results, in step S26, if the calculated inconsistency confidence is equal to or greater than a predetermined threshold, it is determined that there is a discrepancy between the external world recognition result and the positioning calculation result at that time (step S27). If the calculated inconsistency confidence is not equal to or greater than the predetermined threshold, it is determined that there is a discrepancy between the external world recognition result and the positioning calculation result at that time (step S28). Here, the determination result is, for example, 1 if there is a discrepancy, or 0 if there is no discrepancy. In step S29, the determination result and the inconsistency confidence are recorded in a recording device (not shown) and output to the sudden change determination unit 35.

[0092] Fig. 16 is a flow diagram explaining the operation of the sudden change determination unit 35 in Fig. 13. The sudden change determination unit 35 distinguishes between an event in which the position error suddenly increases when a recognition error occurs in external recognition, and an event in which the position error gradually increases when the positioning radio waves or augmentation information of satellite positioning are gradually deceptive.

[0093] In step S31, the sudden change determination unit 35 acquires the accumulated results such as the number of recognition targets, the number of successful recognition verifications, the cumulative error amount, and the error amount for each feature, which are output from the recognition result verification unit 33. In step S32, the sudden change determination unit 35 acquires the accumulated results of the consistency determination result and the inconsistency confidence factor, which are output from the consistency determination unit 34.

[0094] In step S33, a moving average of the consistency determination result over a predetermined time interval is calculated, and if the value is equal to or greater than a predetermined threshold, it is determined that there is a mismatch between the external sensor result and the positioning result (Yes in S33, step S34). Conversely, if the value is not equal to or greater than the predetermined threshold, it is determined that there is no mismatch between the external sensor result and the positioning result (No in S33, step S35).

[0095] In step S36, if the variance of the error amounts of the recognition result verification unit 33 included in the predetermined time interval is equal to or less than a predetermined threshold and the maximum value of the error amounts of the recognition result verification unit 33 included in the predetermined time interval is equal to or greater than a predetermined threshold, it is determined that the position error is a sudden change (Yes in S36, S37). Otherwise, it is determined that the position error is a continuous change (No in S36, S38).

[0096] In step S39, if there is a mismatch between the external sensor result and the positioning result (step S34), and the position error is continuously changing (step S38), and the mismatch confidence level is equal to or greater than a predetermined threshold, it is determined that the GNSS positioning signal or augmentation information has been deceptive, and the determination result is output.

[0097] In order to prevent fluctuations in the output of the determination result, the deception determination result transmission unit 36 ​​smooths the output of the sudden change determination unit 35 in time series and outputs it to the vehicle control device 6. The processing after this output is the same as in embodiments 1 to 3, so details will be omitted.

[0098] According to the electronic control device 2 of this embodiment, not only can it achieve the same effects as the electronic control device 2 of the above-described embodiments 1 to 3, but also by utilizing the confidence level of the external world recognition, when similar recognition objects are nearby, etc., Matching Even in a situation where the process is likely to become unstable, it is possible to prevent erroneous determination in the deception determination process S4. Therefore, according to the electronic control unit 2 of this embodiment, it is possible to more accurately determine whether the positioning accuracy has decreased due to a deception signal.

[0099] [Embodiment 5] Hereinafter, a fifth embodiment of an electronic control device according to the present disclosure will be described with reference to Fig. 17. Fig. 17 is a block diagram showing a fifth embodiment of an electronic control device according to the present disclosure. The block diagram in Fig. 17 is the same as Fig. 10 as in the second embodiment, but differs in that this embodiment has an external environment determination result receiving unit 37 that receives the results of the external environment determining unit 26. Other aspects of the electronic control device 2 of this embodiment are similar to those of the electronic control device 2 of the first to third embodiments described above, and therefore similar parts are denoted by the same reference numerals and description thereof will be omitted.

[0100] The deception determination unit 23 has a feature position estimation result receiving unit 30 and a recognition certainty receiving unit 31 that receive the output from the feature matching unit 21. The deception determination unit 23 also has a virtual recognition result receiving unit 32 that receives the output from the virtual recognition unit 22, as well as a recognition result verification unit 33, a consistency determination unit 34, a sudden change determination unit 35, a deception determination result transmitting unit 36, and an external environment determination result receiving unit 37.

[0101] The external environment determination result receiving unit 37 receives from the external environment determining unit 26 an external environment index value that increases to approach 1 when the external environment is one that provides good performance for the external sensor, and decreases to approach 0 when the external environment is one that degrades performance. For example, in the case of an image sensor, this external environment index value will be 1 on cloudy days during the day and approach 0 at night or in rainy weather.

[0102] The recognition result verification unit 33 determines whether the recognition result verification is successful or unsuccessful in step S15 shown in FIG. 14 . The difference is that within the loop in step S13, a threshold used to calculate the position error between the feature position in the virtual recognition result and the feature position in the external environment recognition result for the associated feature is varied according to the result of the external environment determination result receiving unit. Specifically, if the external environment index value is equal to or less than a predetermined threshold, the threshold A(t) used to determine the feature position error at a certain time t is updated at the next time t+1 as follows: A(t+1)=A(t)+α×{Amax-A(t)}, where 0<α<1. Furthermore, if the external environment index value is equal to or less than a predetermined threshold, the threshold B(t) used to determine the recognition certainty of the feature is updated at the next time t+1 as follows: B(t+1)=B(t)-β×{B(t)-Bmin}, where 0<β<1.

[0103] As a result, in a situation where the recognition performance is degraded due to the external environment, threshold A increases so as to gradually approach the maximum value Amax at a rate α, and threshold B decreases so as to gradually approach the minimum value Bmin at a rate β. As a result, the determination in step S15 is more likely to be Yes.

[0104] 15, the consistency determination unit 34 varies a threshold value used to calculate the position error between the feature position of the virtual recognition result and the feature position of the external environment recognition result for the associated feature, depending on the result of the external environment determination result receiving unit. Specifically, if the external environment index value is equal to or less than a predetermined threshold, the threshold value C(t) used to determine the position error of the feature at a certain time t is updated at the next time t+1 as follows: C(t+1)=C(t)+γ×{Cmax-C(t)}, where 0<γ<1.

[0105] As a result, in a situation where the recognition performance is degraded due to the external environment, the threshold C is increased so as to gradually approach the maximum value Cmax at a speed γ. As a result, it becomes easier to make a "Yes" determination in step S25. The subsequent processing is the same as in the fourth embodiment, and therefore will not be repeated.

[0106] The electronic control device 2 of this embodiment not only achieves the same effects as the electronic control device 2 of the above-described embodiments 1 to 4, but also uses the diagnostic results of the external environment to prevent erroneous determinations in the deception determination process S4 even in situations where recognition performance is likely to be unstable, such as in dark places or in bad weather. Therefore, the electronic control device 2 of this embodiment makes it possible to more accurately determine whether positioning accuracy has been reduced by a deception signal.

[0107] The above has described in detail an embodiment of an electronic control device according to the present disclosure using the drawings, but the specific configuration is not limited to this embodiment, and even if there are design changes, etc. within the scope that does not deviate from the gist of the present disclosure, they are included in the present disclosure. [Explanation of symbols]

[0108] 2: Electronic control device, 21: Feature matching unit, 22: Virtual recognition unit, 23: Deception determination unit, 24: Positioning calculation unit, 26: External environment determination unit, 27: Constraint level output unit, 3: Receiver, 4: Map information, 5: External sensor, B1-B4: Building (feature), DV: Deception determination value, Err: Error, LM: Lane marking (feature), P1-P4: Utility pole (feature), R1-R2: Road (feature), RS1: Road marking (feature), SS1-SS3: Sign (feature), Th: Threshold, VRR: Virtual recognition result.

Claims

1. An electronic control device mounted on a vehicle together with an external sensor, map information, and a receiver, a feature matching unit that matches an external environment recognition result based on a feature detection result by the external environment sensor with the map information to acquire an absolute position of the feature; a positioning calculation unit that calculates a positioning result based on an output of the receiver that receives signals and augmentation information from positioning satellites and determines whether or not there is an abnormality in the positioning state; a virtual recognition unit that generates a virtual recognition result corresponding to the external environment recognition result based on the positioning result and the map information, and acquires a relative position of the feature; a deception determination unit that determines a decrease in positioning accuracy due to a deception signal when a deception determination value that increases as the magnitude and duration of the error between the absolute position and the relative position of the feature increase exceeds a threshold; Equipped with the deception determination unit determines that the positioning accuracy has decreased due to a deception signal when there is no abnormality in the positioning state and the deception determination value exceeds the threshold value; The electronic control device is characterized in that the positioning calculation unit changes the method of acquiring the reinforcement information when the deception determination unit determines that the positioning accuracy has decreased due to a deception signal.

2. An electronic control device mounted on a vehicle together with an external sensor, map information, and a receiver, a feature matching unit that matches an external environment recognition result based on a feature detection result by the external environment sensor with the map information to acquire an absolute position of the feature; a positioning calculation unit that calculates a positioning result based on an output of the receiver that receives signals and augmentation information from positioning satellites and determines whether or not there is an abnormality in the positioning state; a virtual recognition unit that generates a virtual recognition result corresponding to the external environment recognition result based on the positioning result and the map information, and acquires a relative position of the feature; a deception determination unit that determines a decrease in positioning accuracy due to a deception signal when a deception determination value that increases as the magnitude and duration of the error between the absolute position and the relative position of the feature increase exceeds a threshold; Equipped with the deception determination unit determines that the positioning accuracy has decreased due to a deception signal when there is no abnormality in the positioning state and the deception determination value exceeds the threshold value; The positioning calculation unit determines whether the reception conditions of the signal from the positioning satellite have deteriorated, and when the deception determination unit determines that the positioning accuracy has deteriorated due to a deception signal and that the reception conditions of the signal from the positioning satellite have deteriorated, the electronic control device calculates the positioning result by excluding the reinforcing information.

3. An electronic control device mounted on a vehicle together with an external sensor, map information, and a receiver, a feature matching unit that matches an external environment recognition result based on a feature detection result by the external environment sensor with the map information to acquire an absolute position of the feature; a virtual recognition unit that generates a virtual recognition result corresponding to the external environment recognition result based on the positioning result and the map information, the virtual recognition unit generating a virtual recognition result corresponding to the external environment recognition result based on the positioning result and the map information, the virtual recognition unit acquiring a relative position of the feature; a deception determination unit that determines a decrease in positioning accuracy due to a deception signal when a deception determination value that increases as the magnitude and duration of the error between the absolute position and the relative position of the feature increase exceeds a threshold; an external environment determination unit that determines whether the detection accuracy of the external sensor has decreased due to an external environment; Equipped with The electronic control device is characterized in that the deception determination unit increases the threshold value of the deception determination value when the external environment determination unit determines that the detection accuracy of the external sensor has decreased.

4. An electronic control device mounted on a vehicle together with an external sensor, map information, and a receiver, a feature matching unit that matches an external environment recognition result based on a feature detection result by the external environment sensor with the map information to acquire an absolute position of the feature; a virtual recognition unit that generates a virtual recognition result corresponding to the external environment recognition result based on the positioning result and the map information, the virtual recognition unit generating a virtual recognition result corresponding to the external environment recognition result based on the positioning result and the map information, the virtual recognition unit acquiring a relative position of the feature; a deception determination unit that determines a decrease in positioning accuracy due to a deception signal when a deception determination value that increases as the magnitude and duration of the error between the absolute position and the relative position of the feature increase exceeds a threshold; a constraint level output unit that outputs a constraint level for an operation related to autonomous driving of the vehicle based on a method for acquiring the reinforcement information and whether or not the reinforcement information has been excluded; An electronic control device comprising:

Citation Information

Patent Citations

  • Electric power patrol-oriented unmanned aerial vehicle satellite navigation spoofing detection method

    CN107861135A

  • Device and method for detecting fraud of a terminal

    CN112055821B

  • A method and system for detecting GPS spoofing in autonomous driving based on an onboard IMU

    CN113447972B

  • Own machine position measurement device, own machine position measurement method and own machine position measurement program

    JP2019035670A

  • Methods to detect spoofing attacks on automated driving systems

    JP2021063795A