Autonomous driving device, vehicle control method
The autonomous driving device addresses map data inconsistencies by validating real-world alignment and executing emergency actions, ensuring safe and reliable autonomous driving operations.
Patent Information
- Application Number
- JP2024041207
- Authority / Receiving Office
- JP · JP
- Patent Type
- Patents
- Current Assignee / Owner
- Priority Date
- 2020-07-08
- Filing Date
- 2024-03-15
- Publication Date
- 2025-10-07
- Estimated Expiration
- 2041-07-06
AI Technical Summary
Existing autonomous driving systems face challenges in accurately calculating potential accident liability values due to inconsistent or outdated map data, leading to unexpected suspension of autonomous driving and user confusion, as they rely on partial map downloads that can be affected by communication errors and real-world environment changes.
An autonomous driving device and method that uses a processor to determine map data consistency with real-world sensing information, plans emergency actions when inconsistency is detected, and executes map data updates or changes vehicle control based on data accuracy.
Reduces user confusion by ensuring safe and reliable autonomous driving through real-time map data validation and emergency action planning, maintaining vehicle control consistency with the real world.
Smart Images

Figure 0007750324000001 
Figure 0007750324000002 
Figure 0007750324000003
Abstract
Description
CROSS-REFERENCE TO RELATED APPLICATIONS
[0001] This application is based on Patent Application No. 2020-117903 filed in Japan on July 8, 2020, and the contents of the original application are incorporated by reference in their entirety. [Technical Field]
[0002] The present disclosure relates to a technique for generating a control plan for an autonomous vehicle using map data. [Background technology]
[0003] Patent Document 1 discloses a configuration for generating a vehicle travel plan, in other words, a control plan, for autonomous driving using a mathematical formula model called an RSS (Responsibility Sensitive Safety) model and map data.
[0004] The planner, a functional block in the RSS model that formulates control plans, uses map data to calculate the potential accident liability value for each of multiple control plans and adopts the control plan that brings the potential accident liability value within an acceptable range. The potential accident liability value is a parameter that indicates the degree of responsibility of the vehicle in the event of an accident between the vehicle and surrounding vehicles. The potential accident liability value is a value that takes into account whether the inter-vehicle distance between the vehicle and surrounding vehicles is shorter than the safe distance determined based on road structure, etc. [Prior art documents] [Patent documents]
[0005] [Patent Document 1] International Publication No. 2018 / 115963 Summary of the Invention
[0006] The RSS model assumes that the vehicle has map data. If the vehicle has the latest map data for all areas, problems such as the inability to calculate potential accident liability values due to map defects such as missing or deteriorated map data are unlikely to occur. However, it is difficult for the vehicle to always have the latest map data for all areas from the perspective of data capacity, communication frequency, etc.
[0007] Due to such concerns, it is assumed that vehicles will be configured to download and use partial maps, which are maps of local areas corresponding to the current location, etc., from a map server each time. However, in a configuration in which partial maps are downloaded and used, it is possible that communication errors, download errors, system processing errors, etc. may prevent the vehicle from obtaining partial map data for the area required to calculate the potential accident liability value.
[0008] Furthermore, due to changes in the real-world environment, there may be cases where the map data distributed by the map server is no longer consistent with the real world. If map data cannot be obtained or if the map data is not consistent with the real world, the planner will be unable to calculate a valid potential accident liability value. Furthermore, if a planner using an RSS model is unable to calculate a potential accident liability value, they will be unable to quantitatively evaluate the safety of each control plan, which could result in the inability to continue autonomous driving.
[0009] On the other hand, it is assumed that ordinary users are not aware of the status of map acquisition for autonomous driving in their vehicles. Therefore, the suspension of autonomous driving due to insufficient map data may be unintended by the user, in other words, unexpected behavior. As a result, it may confuse the user.
[0010] The present disclosure has been made based on this situation, and its purpose is to provide an automatic driving device and a vehicle control method that can reduce the risk of confusing the user.
[0011] The first automated driving device to achieve this goal is, earth An automatic driving device including at least one processor (21) that creates a control plan for autonomously driving a vehicle using map data, wherein the processor is configured to determine whether map data is consistent with the real world based on sensing information provided by a perimeter monitoring sensor mounted on the vehicle, and to plan the execution of a predetermined emergency action based on a determination that the map data and the real world are not consistent, and the processor is configured to plan the execution of an emergency action when the driving position of another vehicle detected by the perimeter monitoring sensor is outside the range of the road shown in the map data. The following are included in this disclosure: 2 The autonomous driving device includes at least one processor (21) that creates a control plan for autonomously driving a vehicle using map data, and the processor is configured to determine whether or not stored map data stored in the vehicle as map data is consistent with the real world based on sensing information provided by a surrounding monitoring sensor mounted on the vehicle, and to plan the execution of a predetermined emergency action based on a determination that the stored map data is not consistent with the real world, and to execute processing to download the latest version of map data from a server, and the processor is configured to change the control manner of the vehicle depending on whether the stored map data is being used or the latest version of map data is being used.
[0013] The first vehicle control method for achieving the above object is , small A vehicle control method for autonomously driving a vehicle using map data, executed by at least one processor, includes: acquiring map data corresponding to the vehicle's position from a map server; determining whether the map data is consistent with the real world based on sensing information provided by a perimeter monitoring sensor mounted on the vehicle; planning the execution of a predetermined emergency action based on the determination that the map data is not consistent with the real world; and planning the execution of the emergency action when the driving position of another vehicle detected by the perimeter monitoring sensor is outside the range of the road shown in the map data. The following are included in this disclosure: 2 The vehicle control method is a vehicle control method executed by at least one processor for causing a vehicle to travel autonomously using map data, and includes the steps of: acquiring map data corresponding to the vehicle's position from a map server; determining whether or not stored map data stored in the vehicle as map data is consistent with the real world based on sensing information provided by a surrounding monitoring sensor mounted on the vehicle; planning the execution of a predetermined emergency action based on the determination that the stored map data is not consistent with the real world, and executing a process for downloading the latest version of map data from the server; and differentiating the control manner of the vehicle depending on whether the stored map data is being used or the latest version of map data is being used.
[0015] Note that the symbols in parentheses in the claims indicate a correspondence with the specific means described in the embodiments described below as one aspect, and do not limit the technical scope of the present disclosure. [Brief explanation of the drawings]
[0016] [Figure 1] 1 is a diagram illustrating the overall configuration of an autonomous driving system 100. FIG. [Figure 2] 1 is a diagram illustrating the configuration of an in-vehicle system 1. FIG. [Figure 3] FIG. 10 is a diagram showing an example of an icon image indicating the acquisition status of map data. [Figure 4] FIG. 2 is a diagram for explaining the configuration of an automatic driving device 20. [Figure 5] FIG. 10 is a diagram for explaining the operation of the map management unit F5. [Figure 6] FIG. 10 is a diagram for explaining the operation of the consistency determination unit F51. [Figure 7] 10 is a flowchart for explaining the operation of a consistency determination unit F51. [Figure 8] 10 is a flowchart illustrating a process for handling a map not yet acquired. [Figure 9] 10 is a flowchart illustrating an inconsistency handling process. [Figure 10] FIG. 10 is a diagram for explaining the operation of the control planning unit F7 when the concept of urgency is applied. [Figure 11] FIG. 10 is a diagram showing modified examples of the content of emergency actions for each level of urgency. [Figure 12] 10 is a flowchart for explaining an emergency action ending process. [Figure 13] FIG. 10 is a diagram illustrating an example of a processing flow for utilizing stored map data. [Figure 14] FIG. 10 is a diagram showing an example of a processing flow for re-downloading map data when there is a contradiction between the stored map data and the real world. [Figure 15] FIG. 10 is a diagram illustrating another example of a processing flow that utilizes stored map data. [Figure 16] FIG. 10 is a diagram illustrating an example of a processing flow for changing a set value of an upper limit speed used in a control plan depending on whether the map data used in the control plan is stored map data. [Figure 17] FIG. 10 is a diagram illustrating an example of a processing flow for notifying a result of a determination of consistency between map data and the real world. [Figure 18] FIG. 10 is a diagram illustrating an example of a processing flow for changing control depending on the distance for which an instant map can be created. [Figure 19] FIG. 10 is a diagram illustrating an example of a processing flow for executing a handover request based on the fact that a mobile station is approaching a photography-prohibited area or a distribution-prohibited area. DETAILED DESCRIPTION OF THE INVENTION
[0017] An embodiment of an automated driving device according to the present disclosure will be described with reference to the drawings. The following description will be given taking an example of an area where driving on the left side is legally required. In areas where driving on the right side is legally required, the following description can be implemented with appropriate modifications, such as reversing the left and right directions. The contents of the present disclosure can be implemented with appropriate modifications so as to comply with the laws and customs of the area where the automated driving system 100 is used.
[0018] Hereinafter, embodiments of the present disclosure will be described with reference to the drawings. Fig. 1 is a diagram illustrating an example of a schematic configuration of an autonomous driving system 100 according to the present disclosure. As shown in Fig. 1, the autonomous driving system 100 includes an in-vehicle system 1 installed in a vehicle Ma and a map server 3. The in-vehicle system 1 wirelessly communicates with the map server 3 to download partial map data, which is local high-precision map data, from the map server 3 for use in autonomous driving and navigation.
[0019] The in-vehicle system 1 can be installed in a vehicle capable of traveling on roads. The vehicle Ma may be a four-wheeled vehicle, a two-wheeled vehicle, a three-wheeled vehicle, or the like. A motorized bicycle can also be considered a two-wheeled vehicle. The vehicle Ma may be a privately owned car, a shared car, or a service car. Service cars include taxis, route buses, and shared buses. The vehicle Ma may also be a robot taxi, an unmanned bus, or the like, without a driver. The vehicle Ma may be configured to be remotely controlled by an external operator when the vehicle encounters a situation where autonomous driving is difficult. The operator here refers to a person who has the authority to remotely control the vehicle from outside the vehicle, such as a designated center. The operator can also be included in the concept of a driver / occupant in the driver's seat. The operator may also be a server or software configured to determine driving operations according to the situation based on artificial intelligence.
[0020] <About map data> Here, we will first explain the map data held by the map server 3. The map data corresponds to map data that indicates road structures and the position coordinates of features located along the roads with an accuracy usable for autonomous driving.
[0021] Map data includes node data, link data, and feature data, etc. Node data consists of various data such as a node ID, which is a unique number assigned to each node on the map, node coordinates, node name, node type, and a connecting link ID, which describes the link ID of the link connecting to the node.
[0022] Link data is data about links, which are road sections connecting nodes. The link data includes various data, such as a link ID, which is a unique identifier for each link; a link length indicating the length of the link; a link direction; a link travel time; link shape information (hereinafter referred to as the link shape); node coordinates of the start and end points of the link; and road attributes. The link shape may be expressed as a coordinate sequence indicating the coordinate positions of both ends of the link and shape interpolation points that represent the shape between them. The link shape corresponds to the road shape. The link shape may be expressed as a cubic spline curve. Road attributes include the road name, road type, road width, lane number information indicating the number of lanes, and speed limit values. The link data may be described by being subdivided into lane units. The map data may include road link data, which corresponds to link data for road units grouping lanes with the same direction of travel, and lane link data, which is a lower layer equivalent to link data for individual lanes. The link data may be subdivided not only by road section but also by lane (i.e., lane).
[0023] The feature data includes lane line data and landmark data. The lane line data includes a lane line ID for each lane line and a coordinate point cloud representing the installation location. The lane line data includes pattern information such as dashed lines, solid lines, and road studs. The lane line data is associated with lane information such as lane IDs and lane-level link IDs. A landmark refers to a feature that can be used as a sign to identify the vehicle's position on a map. Landmarks include certain three-dimensional structures located along roads. Examples of three-dimensional structures located along roads include guardrails, curbs, trees, utility poles, road signs, and traffic lights. Road signs include guide signs such as direction signs and road name signs. Furthermore, road edges and lane line boundaries can also be included as landmarks. The landmark data represents the position and type of each landmark. The shape and position of each feature are represented by a coordinate point cloud. POI data indicates the location and type of features that affect vehicle travel plans, such as branch points for exiting the main highway, merging points, speed limit change points, lane change points, congested sections, construction sections, intersections, tunnels, toll booths, etc. POI data includes type and location information.
[0024] The map data may be three-dimensional map data including a point cloud of road shapes and structural feature points. The three-dimensional map data corresponds to map data that represents the positions of features such as road edges, lane markings, and road signs in three-dimensional coordinates. The three-dimensional map may be generated based on captured images using REM (Road Experience Management). The map data may also include a driving trajectory model. The driving trajectory model is trajectory data generated by statistically integrating the driving trajectories of multiple vehicles. The driving trajectory model is, for example, an average of the driving trajectories for each lane. The driving trajectory model corresponds to data that indicates the driving trajectory that serves as the reference for autonomous driving.
[0025] Map data may include static map information and semi-static map information. Here, static map information refers to information about features that are unlikely to change, such as road networks, road shapes, road surface markings, structures such as guardrails, and buildings. Static map information can also be understood as information about features that require updating, for example, within one week to one month. Static map information is also called a base map. Semi-static map information is information that requires updating, for example, within one hour to several hours. Road construction information, traffic regulation information, congestion information, and wide-area weather information fall under the category of semi-static map information. For example, the map data handled by the map server 3 includes static map information and semi-static map information. Of course, the map information handled by the map server 3 may be static map information only.
[0026] The map server 3 stores all map data corresponding to the entire map recording area. However, all map data is divided into multiple patches and managed. Each patch corresponds to map data for a different area. The map data is stored in units of map tiles, which are rectangles of 2 km square, dividing the map recording area, as shown in Figure 1. The dashed lines in Figure 1 conceptually indicate the boundaries of the map tiles. Map tiles are a sub-concept of the aforementioned patches.
[0027] Each map tile is assigned information indicating the real-world area to which it corresponds. The information indicating the real-world area is expressed, for example, by latitude, longitude, and altitude. Each map tile is also assigned a unique ID (hereinafter referred to as a tile ID). Each map tile is associated with an adjacent tile ID, which is the tile ID of the adjacent area. The adjacent tile ID can be used to identify the next area map data, for example. The map data for each patch or map tile is a portion of the entire map recording area, in other words, local map data. The map tile corresponds to partial map data. Based on a request from the in-vehicle system 1, the map server 3 distributes partial map data corresponding to the position of the in-vehicle system 1.
[0028] The shape of the map tiles is not limited to a 2 km square rectangle. They may also be 1 km square or 4 km square. Map tiles may also be hexagonal, circular, or other shapes. Each map tile may be set to partially overlap with adjacent map tiles. The map coverage area may be the entire country in which vehicles are used, or only a partial area. For example, the map coverage area may be only an area where autonomous driving of general vehicles is permitted or an area where autonomous driving transportation services are provided.
[0029] Furthermore, the sizes and shapes of the multiple map tiles do not need to be uniform. For example, map tiles in rural areas, where the density of map elements such as landmarks is likely to be relatively sparse, may be set larger than map tiles in urban areas, where the density of map elements such as landmarks is likely to be dense. For example, map tiles in rural areas may be rectangular, measuring 4 km square, while map tiles in urban areas may be rectangular, measuring 1 km square or 0.5 km square. Here, urban areas refer to areas where the population density is above a predetermined value or where offices and commercial facilities are concentrated. Rural areas can be areas other than urban areas. Rural areas may also be interpreted as rural areas.
[0030] In addition, the division of all map data may be determined by data size. In other words, the map coverage area may be divided into areas determined by data size and managed. In this case, each patch is set so that the data volume is less than a predetermined value. According to such an embodiment, the data size for one distribution can be kept below a certain value.
[0031] <Overview of in-vehicle system 1> Here, the configuration of the in-vehicle system 1 will be explained using Fig. 2. The in-vehicle system 1 shown in Fig. 2 is used in a vehicle capable of autonomous driving (hereinafter referred to as an autonomous driving vehicle). As shown in Fig. 2, the in-vehicle system 1 includes a periphery monitoring sensor 11, a vehicle status sensor 12, a locator 13, a V2X in-vehicle device 14, an HMI system 15, a driving actuator 16, a driving recorder 17, and an autonomous driving device 20. Note that HMI in the component names is an abbreviation for Human Machine Interface. V2X is an abbreviation for Vehicle to X (Everything) and refers to a communication technology that connects vehicles with various things.
[0032] The various devices or sensors constituting the in-vehicle system 1 are connected as nodes to an in-vehicle network Nw, which is a communication network established within the vehicle. The nodes connected to the in-vehicle network Nw can communicate with each other. Note that specific devices may be configured to be able to communicate directly with each other without going through the in-vehicle network Nw. For example, the automatic driving device 20 and the driving recorder 17 may be directly electrically connected by a dedicated line. Also, while the in-vehicle network Nw in FIG. 2 is configured as a bus, this is not limiting. The network topology may be a mesh, star, ring, or other type. The network shape can be changed as appropriate. Various standards can be adopted for the in-vehicle network Nw, such as Controller Area Network (CAN: registered trademark), Ethernet (Ethernet is a registered trademark), and FlexRay (registered trademark).
[0033] Hereinafter, the vehicle equipped with the in-vehicle system 1 will also be referred to as the host vehicle Ma, and the occupant sitting in the driver's seat of the host vehicle Ma (i.e., the driver's seat occupant) will also be referred to as the user. Note that the front-rear, left-right, and up-down directions in the following description are defined with the host vehicle Ma as the reference. Specifically, the front-rear direction corresponds to the longitudinal direction of the host vehicle Ma. The left-right direction corresponds to the width direction of the host vehicle Ma. The up-down direction corresponds to the vehicle height direction. From another perspective, the up-down direction corresponds to the direction perpendicular to a plane parallel to the front-rear and left-right directions.
[0034] The host vehicle Ma may be any vehicle capable of autonomous driving. There may be multiple levels of autonomous driving (hereinafter referred to as "autonomy level"), as defined by, for example, the Society of Automotive Engineers (SAE International). For example, the SAE defines automation levels as levels 0 to 5 as follows:
[0035] Level 0 is a level where the driver performs all driving tasks without system intervention. Driving tasks include, for example, steering and acceleration / deceleration. Level 0 corresponds to the so-called fully manual driving level. Level 1 is a level where the system supports either steering or acceleration / deceleration. Level 2 refers to a level where the system supports both steering and acceleration / deceleration operations. Levels 1 and 2 correspond to so-called driving assistance levels.
[0036] Level 3 refers to a level where the system performs all driving operations within the Operational Design Domain (ODD), but transfers control authority to the driver in an emergency. The ODD specifies the conditions under which automated driving is possible, such as whether the vehicle is traveling on a highway. At Level 3, the driver is required to be able to respond quickly when the system requests a driver-side takeover. Note that an operator outside the vehicle may take over driving operations instead of the driver. Level 3 corresponds to so-called conditional automated driving. Level 4 is a level where the system can perform all driving tasks except under certain circumstances, such as on inoperable roads or in extreme environments. Level 4 is a level where the system performs all driving tasks within the ODD. Level 4 is a level where the system can perform all driving tasks in any environment. Level 5 is a level where the system can perform all driving tasks in any environment. Level 5 is a level where the system can perform all driving tasks in any environment. Level 5 is a level where the system can perform all driving tasks in any environment. Level 5 is a level where the system can perform all driving tasks in any environment. Levels 3 to 5 correspond to so-called automated driving. Levels 3 to 5 can also be called autonomous driving levels, where all vehicle-related control is automatically performed.
[0037] The level referred to as "autonomous driving" in the present disclosure may be, for example, equivalent to level 3, or level 4 or higher. Hereinafter, an example will be described in which the host vehicle Ma performs autonomous driving at least at automation level 3 or higher. Note that the automation level as the driving mode of the host vehicle Ma may be switchable. For example, it may be switchable between an autonomous driving mode at automation level 3 or higher, a driving assistance mode at levels 1 to 2, and a manual driving mode at level 0.
[0038] The perimeter monitoring sensor 11 is a sensor that monitors the perimeter of the vehicle. The perimeter monitoring sensor 11 is configured to detect the presence and position of a predetermined detection target. Detection targets include, for example, moving objects such as pedestrians and other vehicles. Other vehicles include bicycles, mopeds, and motorcycles. The perimeter monitoring sensor 11 is also configured to detect predetermined features and obstacles. Features that the perimeter monitoring sensor 11 detects include road edges, road markings, and three-dimensional structures installed along the road. Road markings refer to painted surfaces on the road for traffic control and regulation. Examples of road markings include lane markings that indicate lane boundaries, crosswalks, stop lines, navigation strips, safety zones, and traffic control arrows. Lane markings are also called lane marks or lane markers. Lane markings also include those realized by road studs such as chatter bars and Bott's dots. As mentioned above, three-dimensional structures installed along the road include, for example, guardrails, road signs, and traffic lights. That is, the perimeter monitoring sensor 11 is preferably configured to be able to detect landmarks. Here, an obstacle refers to a three-dimensional object that exists on the road and obstructs the passage of vehicles. Obstacles include accident vehicles and debris from accident vehicles. In addition, obstacles can also include lane control equipment such as arrow signs, cones, and guide signs, as well as construction sites, parked vehicles, and the tail end of traffic jams. The perimeter monitoring sensor 11 may also be configured to be able to detect objects that have fallen onto the road, such as tires that have fallen off a vehicle body.
[0039] Examples of the perimeter monitoring sensor 11 that can be used include a perimeter monitoring camera, millimeter-wave radar, LiDAR, and sonar. LiDAR stands for Light Detection and Ranging or Laser Imaging Detection and Ranging. Millimeter-wave radar transmits millimeter waves or quasi-millimeter waves in a predetermined direction and analyzes the received data of the reflected waves from the object to detect the relative position and speed of an object relative to the vehicle Ma. As a detection result, the millimeter-wave radar generates, for example, data indicating the reception strength and relative speed for each detection direction and distance, or data indicating the relative position and reception strength of the detected object. LiDAR is a device that generates three-dimensional point cloud data indicating the positions of reflection points for each detection direction by emitting laser light.
[0040] The perimeter monitoring camera is an in-vehicle camera that is arranged to capture an image of the outside of the vehicle in a predetermined direction. The perimeter monitoring camera includes a front camera that is arranged on the upper end of the windshield on the interior side of the vehicle Ma, on the front grill, etc., to capture an image of the area in front of the vehicle Ma. The front camera detects the above-mentioned detection target using a classifier that uses, for example, a CNN (Convolutional Neural Network) or a DNN (Deep Neural Network).
[0041] The object recognition process based on the observation data generated by the perimeter monitoring sensor 11 may be executed by an ECU (Electronic Control Unit) outside the sensor, such as the automatic driving device 20. Some or all of the object recognition functions provided in the perimeter monitoring sensor 11, such as a forward camera or millimeter-wave radar, may be provided in the automatic driving device 20. In this case, the various perimeter monitoring sensors 11 may provide the automatic driving device 20 with observation data such as image data and distance measurement data as detection result data.
[0042] The vehicle state sensor 12 is a group of sensors that detect state quantities related to the driving control of the host vehicle Ma. The vehicle state sensor 12 includes a vehicle speed sensor, a steering sensor, an acceleration sensor, a yaw rate sensor, etc. The vehicle speed sensor detects the vehicle speed of the host vehicle. The steering sensor detects the steering angle of the host vehicle. The acceleration sensor detects acceleration such as longitudinal acceleration and lateral acceleration of the host vehicle. The acceleration sensor may also detect deceleration, which is acceleration in the negative direction. The yaw rate sensor detects the angular velocity of the host vehicle. Note that the type of sensor used by the in-vehicle system 1 as the vehicle state sensor 12 may be designed as appropriate, and it is not necessary to include all of the sensors described above.
[0043] The locator 13 is a device that generates highly accurate position information of the vehicle Ma by performing composite positioning that combines multiple pieces of information. The locator 13 is configured using, for example, a GNSS receiver. The GNSS receiver is a device that sequentially detects the current position of the GNSS receiver by receiving navigation signals transmitted from positioning satellites that make up the GNSS (Global Navigation Satellite System). For example, if the GNSS receiver is able to receive navigation signals from four or more positioning satellites, it outputs positioning results every 100 milliseconds. The GNSS can be, for example, GPS, GLONASS, Galileo, IRNSS, QZSS, or Beidou.
[0044] The locator 13 sequentially determines the position of the host vehicle Ma by combining the positioning results of the GNSS receiver with the output of the inertial sensor. For example, when the GNSS receiver cannot receive GNSS signals, such as inside a tunnel, the locator 13 performs dead reckoning (i.e., autonomous navigation) using the yaw rate and vehicle speed. The yaw rate used for dead reckoning may be calculated by a front camera using SfM technology, or may be detected by a yaw rate sensor. The locator 13 may also perform dead reckoning using the output of an acceleration sensor or a gyro sensor. The vehicle position is expressed, for example, in three-dimensional coordinates of latitude, longitude, and altitude. The determined vehicle position information is output to the in-vehicle network Nw and used by the automatic driving device 20, etc.
[0045] The locator 13 may be configured to perform localization processing. The localization processing refers to processing for identifying the detailed location of the host vehicle Ma by comparing the coordinates of landmarks identified based on images captured by a surrounding monitoring camera such as a forward camera with the coordinates of landmarks registered in map data. Examples of landmarks include traffic signs, traffic signals, poles, commercial signs, and other three-dimensional structures installed along roads. The locator 13 may also be configured to identify a driving lane ID, which is an identifier of the lane in which the host vehicle Ma is traveling, based on the distance from the road edge detected by the forward camera or millimeter-wave radar. The driving lane ID indicates, for example, which lane the host vehicle Ma is traveling in from the left or right edge of the road. Some or all of the functions of the locator 13 may be provided by the automatic driving device 20. The lane in which the host vehicle Ma is traveling can be called an ego lane.
[0046] The V2X in-vehicle device 14 is a device that enables the host vehicle Ma to communicate wirelessly with other devices. The "V" in V2X refers to the host vehicle Ma, i.e., a car, and the "X" can refer to various entities other than the host vehicle Ma, such as pedestrians, other vehicles, road facilities, networks, and servers. The V2X in-vehicle device 14 includes a wide-area communication unit and a narrow-area communication unit as communication modules. The wide-area communication unit is a communication module for performing wireless communication in accordance with a predetermined wide-area wireless communication standard. Various wide-area wireless communication standards, such as LTE (Long Term Evolution), 4G, and 5G, can be used here. The wide-area communication unit may be configured to perform wireless communication directly with other devices, i.e., without a base station, in addition to communication via a wireless base station, using a method in accordance with the wide-area wireless communication standard. In other words, the wide-area communication unit may be configured to perform cellular V2X. The host vehicle Ma becomes a connected car that can connect to the Internet by being equipped with the V2X in-vehicle device 14. For example, the autonomous driving device 20 downloads the latest partial map data corresponding to the current position of the host vehicle Ma from the map server 3 in cooperation with the V2X vehicle-mounted device 14. The V2X vehicle-mounted device 14 corresponds to a wireless communication device.
[0047] The short-range communication unit included in the V2X vehicle-mounted device 14 is a communication module for directly communicating wirelessly with other moving objects and roadside devices in the vicinity of the vehicle Ma using a short-range communication standard, which is a communication standard that limits the communication distance to within several hundred meters. The other moving objects are not limited to vehicles but can also include pedestrians, bicycles, etc. Various short-range communication standards can be adopted, such as WAVE (Wireless Access in Vehicular Environment) and DSRC (Dedicated Short Range Communications). The short-range communication unit broadcasts vehicle information about the vehicle Ma to surrounding vehicles at a predetermined transmission period, and receives vehicle information transmitted from other vehicles. The vehicle information includes a vehicle ID, current position, traveling direction, moving speed, turn signal operation status, timestamp, etc.
[0048] The HMI system 15 is a system that provides an input interface function for accepting user operations and an output interface function for presenting information to the user. The HMI system 15 includes a display 151 and an HCU (HMI Control Unit) 152. In addition to the display 151, a speaker, a vibrator, a lighting device (e.g., an LED), etc. can be used as a means for presenting information to the user.
[0049] The display 151 is a device that displays images. For example, the display 151 is a center display provided in the center of the instrument panel in the vehicle width direction. The display 151 is capable of full-color display and can be realized using a liquid crystal display, an OLED (Organic Light Emitting Diode) display, a plasma display, or the like. The HMI system 15 may include, as the display 151, a head-up display (HUD) that projects a virtual image on a portion of the windshield in front of the driver's seat. The display 151 may also be a meter display.
[0050] The HCU 152 is configured to comprehensively control the presentation of information to the user. The HCU 152 is realized using, for example, a processor such as a CPU (Central Processing Unit) or a GPU (Graphics Processing Unit), RAM, flash memory, etc. The HCU 152 controls the display screen of the display 151 based on control signals input from the automatic driving device 20 or signals from an input device (not shown). For example, the HCU 152 displays a map icon 80 indicating the acquisition status of partial map data on the display 151 based on a request from the automatic driving device 20, as shown in FIG. 3. (A) of FIG. 3 shows an example of a map not acquired icon 80A indicating that partial map data has not been downloaded. (B) of FIG. 3 shows an example of a map acquired icon 80B indicating that partial map data has been successfully downloaded. (C) of FIG. 3 shows an example of a map acquiring icon 80C indicating that partial map data is currently being downloaded. The map icon 80 may be displayed, for example, in the upper corner of the display 151.
[0051] The traveling actuators 16 are actuators used for traveling. The traveling actuators 16 include, for example, a brake actuator as a braking device, an electronic throttle, a steering actuator, and the like. The steering actuator also includes an EPS (Electric Power Steering) motor. The traveling actuators 16 are controlled by an automatic driving device 20. Note that a steering ECU that performs steering control, a power unit control ECU that performs acceleration / deceleration control, and a brake ECU, and the like, may be interposed between the automatic driving device 20 and the traveling actuators.
[0052] The operation recording device 17 is a device that records data indicating at least one of the conditions inside the vehicle and the conditions outside the vehicle cabin while the vehicle is traveling. The conditions inside the vehicle while the vehicle is traveling may include the operating state of the automatic driving device 20 and the state of the occupant in the driver's seat. Data indicating the operating state of the automatic driving device 20 may also include the results of the automatic driving device 20 recognizing the surrounding environment, the driving plan, and calculation results such as the target control amount of each driving actuator. Images captured from the display screen of the display 151, so-called screenshots, may also be recorded. The data to be recorded is acquired from ECUs and sensors installed in the vehicle, such as the automatic driving device 20 and the surrounding monitoring sensor 11, via an in-vehicle network Nw or the like. When a predetermined recording event occurs, the operation recording device 17 records various data for a predetermined time before and after the event. Examples of recording events that can be used include the transfer of driving operation authority, exiting ODD, taking emergency action (described below), changing the automation level, and executing MRM (Minimum Risk Maneuver). For example, when the automatic driving device 20 executes an emergency action, the operation recording device 17 stores data that can identify the partial map data that has been acquired at that time. The data that can identify the acquired partial map data includes, for example, a tile ID, version information, acquisition date and time, etc. The data may be recorded in a non-volatile storage medium mounted in the host vehicle Ma or in an external server.
[0053] The autonomous driving device 20 is an ECU (Electronic Control Unit) that controls the driving actuator 16 based on the detection results of the surroundings monitoring sensor 11 and the like, thereby performing some or all of the driving operations on behalf of the driver. Here, as an example, the autonomous driving device 20 is configured to be capable of implementing automation up to level 5, and is configured to be able to switch between operation modes corresponding to each automation level. Hereinafter, for convenience, the operation mode corresponding to autonomous driving level N (N = 0 to 5) will also be referred to as level N mode. For example, level 3 mode refers to an operation mode that implements control equivalent to autonomous driving level 3.
[0054] The following explanation will be continued assuming that the vehicle is operating in an automation level 3 or higher mode. In a driving mode of level 3 or higher, the automatic driving device 20 automatically steers, accelerates, decelerates (in other words, brakes), etc. the vehicle so that the host vehicle Ma travels along the road to the destination set by the driver's seat occupant or operator. Note that the switching of the operating mode is automatically performed due to user operation, system limitations, exiting the ODD, etc.
[0055] The autonomous driving device 20 is mainly composed of a computer including a processing unit 21, a RAM 22, a storage 23, a communication interface 24, and a bus connecting these components. The processing unit 21 is hardware for arithmetic processing coupled to the RAM 22. The processing unit 21 includes at least one arithmetic core such as a CPU. The processing unit 21 accesses the RAM 22 to execute various processes for realizing the functions of each functional unit described below. The storage 23 includes a non-volatile storage medium such as a flash memory. The storage 23 stores an autonomous driving program, which is a program executed by the processing unit 21. The execution of the autonomous driving program by the processing unit 21 corresponds to the execution of a vehicle control method corresponding to the autonomous driving program. The communication interface 24 is a circuit for communicating with other devices via the in-vehicle network Nw. The communication interface 24 may be implemented using analog circuit elements, ICs, or the like. Details of the autonomous driving device 20 will be described separately below.
[0056] <Configuration of the automatic driving device 20> Here, the functions and operations of the automatic driving device 20 will be described using Figure 4. The automatic driving device 20 provides functions corresponding to the various functional blocks shown in Figure 4 by executing an automatic driving program stored in the storage 23. That is, the automatic driving device 20 includes, as functional blocks, a vehicle position acquisition unit F1, a sensing information acquisition unit F2, a vehicle state acquisition unit F3, a map acquisition unit F4, a map management unit F5, a driving environment recognition unit F6, a control planning unit F7, and a control signal output unit F8. The map management unit F5 includes, as a sub-function, a consistency determination unit F51, and the control planning unit F7 includes, as sub-functions, a responsibility value calculation unit F71, a safety distance setting unit F72, and an action decision unit F73. The automatic driving device 20 also includes a map storage unit M1.
[0057] The vehicle position acquisition unit F1 acquires the current position coordinates of the vehicle Ma from the locator 13. The vehicle position acquisition unit F1 may be configured to read the latest vehicle position information stored in nonvolatile memory as the current position information immediately after the vehicle's running power is turned on. The latest position calculation result stored in memory corresponds to the end point of the previous trip, i.e., the parking position. A trip refers to a series of trips from when the running power is turned on until it is turned off. To execute the above process, the automatic driving device 20 is preferably configured to store the vehicle position information observed at the time of parking in nonvolatile memory as a shutdown process after parking. The running power here refers to the power source for running the vehicle, and in the case of a gasoline-powered vehicle, refers to the ignition power source. In the case of an electric vehicle or a hybrid vehicle, the system main relay corresponds to the running power source.
[0058] The sensing information acquisition unit F2 acquires the detection results (i.e., sensing information) of the perimeter monitoring sensor 11. The sensing information includes the positions and movement speeds of other moving objects, features, obstacles, etc. present around the host vehicle Ma. For example, the sensing information includes the distance between the host vehicle Ma and a forward vehicle traveling in front of the host vehicle Ma, and the movement speed of the forward vehicle. The forward vehicle here can include not only a so-called leading vehicle traveling in the same lane as the host vehicle Ma, but also a vehicle traveling in an adjacent lane. In other words, the forward vehicle here is not limited to the direction directly ahead of the host vehicle Ma, but can also include a diagonal direction ahead. The sensing information also includes the lateral distance to the road edge, the traveling lane ID, the offset amount from the center line of the traveling lane, etc. The vehicle state acquisition unit F3 acquires the traveling speed, acceleration, yaw rate, etc. of the host vehicle Ma from the vehicle state sensor 12.
[0059] The map acquisition unit F4 acquires partial map data corresponding to the current position of the host vehicle Ma by wirelessly communicating with the map server 3 via the V2X in-vehicle device 14. For example, the map acquisition unit F4 requests and acquires partial map data related to roads that the host vehicle Ma is scheduled to pass through within a predetermined time from the map server 3. The partial map data acquired from the map server 3 is stored, for example, in the map storage unit M1. The map storage unit M1 is configured to retain data even when the driving power supply is turned off, using a non-volatile memory or the like. The map storage unit M1 is realized, for example, using a part of the memory area of the storage 23.
[0060] The map storage unit M1 may be realized using a part of the storage area of the RAM 22. Even if the map storage unit M1 is realized using the RAM 22, it is possible to store data even while the driving power supply is off by supplying power from the vehicle battery to the RAM 22. In another aspect, the map storage unit M1 may be configured so that stored data is lost when the driving power supply is set to off. The map storage unit M1 is a non-transitory storage medium.
[0061] For convenience, partial map data including the current location will be referred to as current area map data, and the coverage area of the current area map data will be referred to as the current map coverage area or current area. Furthermore, the partial map data to be used next will be referred to as next area map data. The next area map data corresponds to the partial map data adjacent to the current area map data in the direction of travel of the host vehicle Ma. The next area map data corresponds to the partial map data for the area that the host vehicle Ma is scheduled to enter within a predetermined time. The next area map data may be determined based on the planned driving route. The coverage area of the next area map data will also be referred to as the next map coverage area or next area. Note that if adjacent partial map data are configured to overlap, the current map coverage area (current area) and the next map coverage area (next area) may partially overlap.
[0062] The map management unit F5 manages the acquisition and storage status of partial map data corresponding to the vehicle's traveling direction or planned driving route. For example, the map management unit F5 manages the partial map data acquired by the map acquisition unit F4 and the map data stored in the map storage unit M1. Here, as an example, the map management unit F5 is configured to delete all map data in the map storage unit M1 at least when the driving power supply is turned off.
[0063] Note that various rules can be applied to the storage of the map data downloaded by the map acquisition unit F4, taking into account factors such as the capacity of the map storage unit M1. For example, if the capacity of the map storage unit M1 is relatively small, the map management unit F5 may delete partial map data for an area from which the host vehicle Ma has already left as soon as the host vehicle Ma leaves or when the host vehicle Ma has moved a predetermined distance or more. With such a configuration, the autonomous driving device 20 can be implemented using a map storage unit M1 with a small capacity. In other words, the introduction cost of the autonomous driving device 20 can be reduced.
[0064] The map management unit F5 may also be configured to delete map data downloaded to the map storage unit M1 when a predetermined time (e.g., one day) has elapsed since the download. Map data about roads used daily, such as commuter routes or school routes, may be cached in the map storage unit M1 as much as possible. For example, the map data about roads used daily may be retained as long as the available storage space does not fall below a predetermined value. The storage period for downloaded map data may be changed depending on the attributes of the data. For example, static map data is stored in the map storage unit M1 up to a certain amount. On the other hand, dynamic map data, such as construction information, may be deleted when the vehicle passes through the area corresponding to the dynamic map data.
[0065] The map management unit F5 also calculates the remaining time until the control planning unit F7 or the like starts using the next area map data as the next map use start time Tmx. The timing to start using the next area map data can be, for example, when the host vehicle Ma leaves the current map range. If the map management unit F5 is configured to start using the next area map data when leaving the current map range, the map management unit F5 calculates the remaining time until the host vehicle Ma leaves the current map range as the next map use start time Tmx based on the current position and traveling speed of the host vehicle Ma. Figure 5 is a diagram conceptually illustrating the operation of the map management unit F5 related to the next map use start time. "L" in Figure 5 represents the distance from the current position to the exit point of the current map range. The next map use start time Tmx is determined, for example, based on the value obtained by dividing the distance L by the vehicle speed V.
[0066] The timing to start using the next area map data may also be, for example, when the vehicle Ma enters the next map range. If the system is configured to start using the next area map data when the vehicle Ma enters the next map range, the map management unit F5 can calculate the next map use start time Tmx based on the current position of the vehicle Ma, the next map range information, and the vehicle's traveling speed. Alternatively, the timing to start using the next area map data may be when a point located a predetermined map reference distance ahead of the vehicle Ma is outside the current map range or is within the next map range. The map reference distance is preferably set sufficiently longer than the safety distance (described below). For example, the map reference distance may be set to 1.5 times the safety distance. The map reference distance may also be a fixed value, such as 200 m. The map reference distance may be set longer as the traveling speed increases. The map reference distance may also be changed depending on the road type. For example, the map reference distance for expressways may be set longer than the map reference distance for general roads.
[0067] The map management unit F5 notifies the control planning unit F7 of the map data acquisition status, such as whether the next area map data has been acquired. For example, if the map management unit F5 has not yet acquired the next area map data when the next map use start time Tmx is less than the predetermined preparation deadline, the map management unit F5 outputs the next map use start time Tmx as the remaining map acquisition time Tmg to the control planning unit F7. The remaining map acquisition time Tmg corresponds to the remaining time until the next area map data is needed to formulate a control plan. The situation in which the next area map data is needed to formulate a control plan includes the situation in which the next area map data is used to calculate the potential accident liability value, which will be described later. The situation in which the next area map data is needed also includes the situation in which the vehicle leaves the current map area and enters the next map area.
[0068] The remaining map acquisition time Tmg may be set to a value obtained by subtracting a predetermined margin time from the next map use start time Tmx. The margin time may be, for example, a time that takes into consideration communication delays and post-reception processing delays, and may be set to, for example, 5 seconds. The remaining map acquisition time Tmg may be shorter than the next map use start time Tmx. The remaining map acquisition time Tmg may also be the next map use start time Tmx. The configuration of the present disclosure can be implemented by replacing the remaining map acquisition time Tmg with the next map use start time Tmx. Furthermore, if the next map use start time Tmx is equal to or longer than a predetermined preparation deadline, or if the next area map data has already been acquired, the remaining map acquisition time Tmg may be set to a sufficiently large value and output.
[0069] Furthermore, if the next area map data has not yet been acquired when the next map use start time Tmx is less than the preparation deadline, the map management unit F5 may request the V2X in-vehicle device 14 to prioritize communication for acquiring the next area map data. This request may be made via the map acquisition unit F4. The preparation deadline is preferably set to, for example, two minutes, which is longer than the first time Th1 described below.
[0070] The consistency determination unit F51 determines whether the map data is consistent with the real world by comparing the content of the current area map data acquired by the map acquisition unit F4 with the sensing information of the perimeter monitoring sensor 11. For example, as shown in FIG. 6, the consistency determination unit F51 determines that the map data is inconsistent with the real world when it detects that the forward vehicle Mb has crossed the lane marking Ln1 and detects a stationary object Obt in the lane in which the forward vehicle Mb was traveling. The evasive action of the forward vehicle Mb and the detection of the stationary object Obt may be detected based on sensing information such as the recognition results of a forward camera. It is assumed that the map data does not register information about the stationary objects Obt on the road shown in FIG. 6. Stationary objects Obt include, for example, parked vehicles on the road, road construction, lane restrictions, and fallen objects. If such quasi-static information is not reflected in the map data, an inconsistency between the map data and the real world may occur.
[0071] In this way, the consistency determination unit F51 determines that the map and the real world are not consistent when the vehicle ahead is taking evasive action such as changing lanes in a section where it is possible to go straight on the map. Going straight here means traveling along the road in the lane in which you have been traveling up until then without changing your driving position such as changing lanes. Going straight here does not necessarily have to be a behavior of traveling while maintaining a steering angle of 0°.
[0072] Furthermore, an evasive action refers to a vehicle behavior, such as a change in driving position, to avoid an obstacle. Here, a change in driving position refers to a change in the lateral position of the vehicle on the road. A change in driving position includes not only a lane change, but also a movement to move the driving position toward either the left or right corner of the same lane, or a behavior of driving across a lane boundary. To clearly distinguish from a normal lane change, an evasive action is preferably a change in driving position / steering involving deceleration and subsequent acceleration. For example, a change in driving position involving a deceleration operation or a change in driving position involving deceleration to a predetermined speed or below can be considered an evasive action. The above description of the evasive action illustrates the concept of the evasive action assumed in this disclosure. Whether a change in driving position has been performed as an evasive action can be determined from sensing information, such as the driving trajectory of the preceding vehicle and the operation history of its turn signals.
[0073] Alternatively, the consistency determination unit F51 may determine that the map data and the real world are inconsistent when it detects that multiple preceding vehicles are continuously taking evasive action on a road section that appears to be straight ahead on the map. The consistency determination unit F51 may also determine that the map data and the real world are inconsistent based on a mismatch between feature information shown in the map data and feature information represented by the sensing information. Furthermore, the consistency determination unit F51 may determine that the map and the real world are inconsistent when the driving position of a nearby vehicle is outside the road range indicated by the map data.
[0074] Fig. 7 shows an example of a method for determining consistency by the consistency determination unit F51. The consistency determination process shown in Fig. 7 includes step S101 for determining whether the traveling position of the forward vehicle is outside the lane, and step S102 for determining whether a stationary object not registered in the map data has been detected. If it is detected that the traveling position of the forward vehicle is outside the lane (YES in S101) and a stationary object not registered in the map has been detected (YES in S102), the consistency determination unit F51 determines that the map data is not consistent with the real world (S103). Note that either step S101 or step S102 may be omitted. If step S101 is omitted, the flow may start from step S102.
[0075] The driving environment recognition unit F6 recognizes the surrounding environment of the host vehicle Ma based on the detection results of the perimeter monitoring sensor 11. The surrounding environment here includes not only static environmental factors such as the current position, driving lane, road type, speed limit, and relative positions of features, but also the positions and moving speeds of other moving objects, the shapes and sizes of surrounding objects, etc. The other moving objects include other vehicles such as automobiles, pedestrians, and bicycles.
[0076] The driving environment recognition unit F6 preferably distinguishes between moving and stationary objects detected by the perimeter monitoring sensor 11. It is also preferable to distinguish between types of surrounding objects. The type of surrounding object may be distinguished and recognized by, for example, pattern matching on an image captured by a perimeter monitoring camera. The type may be distinguished between, for example, structures such as guardrails, objects fallen on the road, pedestrians, bicycles, motorcycles, automobiles, etc. If the surrounding object is an automobile, the type of surrounding object may be determined by its class or model. Whether a surrounding object is a moving or stationary object may be recognized according to its type. For example, if the surrounding object is a structure or an object fallen on the road, it may be recognized as a stationary object. If the surrounding object is a pedestrian, bicycle, motorcycle, or automobile, it may be recognized as a moving object. Note that objects that are unlikely to move immediately, such as parked vehicles, may be recognized as stationary objects. Whether a vehicle is parked may be determined based on, for example, whether the vehicle is stopped and its brake lights are not illuminated by image recognition.
[0077] The driving environment recognition unit F6 may recognize the position and type of an object present around the vehicle by acquiring detection results from each of the multiple perimeter monitoring sensors 11 and complementarily combining them. The position and speed of a surrounding object may be a relative position and relative speed with respect to the vehicle Ma, or an absolute position and absolute speed with respect to the ground.
[0078] Furthermore, the driving environment recognition unit F6 may recognize road markings around the vehicle, the positions and types of landmarks, and the lighting status of traffic lights based on the detection results of the perimeter monitoring sensors 11 and map data. Additionally, the driving environment recognition unit F6 may use at least one of the detection results of the perimeter monitoring sensors 11 and map data to identify the relative positions and shapes of the left and right lane markings and road edges of the lane on which the vehicle Ma is currently traveling as boundary information related to the boundaries of the lane. Note that the data acquired by the driving environment recognition unit F6 from each perimeter monitoring sensor 11 may be observation data such as image data, rather than analysis results. In this case, the driving environment recognition unit F6 may identify the surrounding environment, including the positions and shapes of the left and right lane markings or road edges, based on the observation data of the various perimeter monitoring sensors 11.
[0079] Additionally, the driving environment recognition unit F6 may identify the surrounding environment using other vehicle information received from other vehicles by the V2X in-vehicle device 14, traffic information received from roadside devices through road-to-vehicle communication, etc. Traffic information that can be acquired from roadside devices may include road construction information, traffic regulation information, congestion information, weather information, speed limits, traffic light status, and traffic light cycle.
[0080] The control planning unit F7 generates a driving plan for autonomously driving the host vehicle Ma by automatic driving, in other words, a control plan, using the driving environment and map data identified by the driving environment recognition unit F6. For example, the control planning unit F7 performs a route search process as a medium- to long-term driving plan to generate a recommended route for moving from the host vehicle's current position to a destination. In addition, the control planning unit F7 generates a driving plan for lane changes, a driving plan for staying in the center of a lane, a driving plan for following a preceding vehicle, a driving plan for avoiding obstacles, and the like as short-term control plans for driving in accordance with the medium- to long-term driving plan.
[0081] The control planning unit F7 may generate, as a short-term control plan, a route that is a certain distance from or at the center of the recognized lane marking, or a route that follows the behavior or driving trajectory of the recognized preceding vehicle. When the driving path of the host vehicle is a road with multiple lanes in each direction, the control planning unit F7 may generate a candidate plan for changing lanes to an adjacent lane. When the control planning unit F7 determines based on the sensing information or map data that an obstacle is present ahead of the host vehicle Ma, the control planning unit F7 may generate a driving plan for passing by the side of the obstacle. When the control planning unit F7 determines based on the sensing information or map data that an obstacle is present ahead of the host vehicle Ma, the control planning unit F7 may generate a driving plan for decelerating to stop the vehicle in front of the obstacle. The control planning unit F7 may be configured to generate a driving plan that is determined to be optimal by machine learning or the like.
[0082] The control planning unit F7 calculates, for example, one or more candidate plans as short-term driving plans. The multiple candidate plans each have different acceleration / deceleration amounts, jerk, steering amount, and timing of various controls. In other words, the short-term driving plan may include acceleration / deceleration schedule information for speed adjustment along the calculated route. The candidate plans may also be called route candidates. The behavior decision unit F73 selects, as the final execution plan, the plan with the smallest potential accident liability value calculated by the responsibility value calculation unit F71 (described later) or the plan with an acceptable potential accident liability value. Note that map data is used, for example, to identify areas where the vehicle can travel based on the number of lanes and road width, and to set steering amounts and target speeds based on the curvature of the road ahead. Map data is also used to calculate safety distances based on road structure and traffic rules, and to calculate potential accident liability values.
[0083] The responsibility value calculation unit F71 corresponds to a component that evaluates the safety of the driving plan generated by the control planning unit F7. As an example, the responsibility value calculation unit F71 evaluates the safety based on whether the distance between the host vehicle and a surrounding object (hereinafter referred to as the inter-object distance) is equal to or greater than the set value of the safety distance set by the safety distance setting unit F72.
[0084] For example, when the host vehicle Ma travels along each candidate plan planned by the control planning unit F7, the responsibility value calculation unit F71 determines a potential accident responsibility value that indicates the degree of responsibility of the host vehicle Ma if an accident occurs while the host vehicle Ma is traveling along the candidate plan. The potential accident responsibility value is determined using, as one of the factors, the result of comparing the safe distance with the inter-vehicle distance between the host vehicle Ma and surrounding vehicles when the host vehicle Ma travels along the candidate plan.
[0085] The lower the responsibility, the smaller the potential accident responsibility value. Therefore, the safer the vehicle Ma is driving, the smaller the potential accident responsibility value. For example, if a sufficient inter-vehicle distance is maintained, the potential accident responsibility value will be small. In addition, the potential accident responsibility value can become large if the vehicle Ma suddenly accelerates or decelerates.
[0086] Furthermore, the responsibility value calculation unit F71 can set a low potential accident responsibility value when the host vehicle Ma is traveling in accordance with traffic rules. In other words, whether or not the route at the host vehicle's location complies with traffic rules can also be used as a factor that affects the potential accident responsibility value. In order to determine whether the host vehicle Ma is traveling in accordance with traffic rules, the responsibility value calculation unit F71 can be configured to acquire traffic rules at the location where the host vehicle Ma is traveling. The traffic rules at the location where the host vehicle Ma is traveling may be acquired from a predetermined database, or the traffic rules at the current location may be acquired by analyzing images captured by a camera that captures images of the area around the host vehicle Ma to detect signs, traffic lights, road markings, etc. The traffic rules may be included in map data.
[0087] The safety distance setting unit F72 is configured to dynamically set a safety distance according to the driving environment, which is used by the responsibility value calculation unit F71. The safety distance is a reference distance for evaluating the safety between objects. Safety distances include a safety distance between a preceding vehicle, i.e., a longitudinal safety distance, and a lateral safety distance, i.e., a horizontal safety distance. The mathematical formula model includes models for determining these two types of safety distances. The safety distance setting unit F72 calculates the longitudinal and lateral safety distances using a mathematical formula model that mathematically embodies the concept of safe driving, and sets the calculated values as the safety distance at that time. The safety distance setting unit F72 calculates and sets the safety distance using at least information on the behavior of the host vehicle Ma, such as the acceleration. Since various models can be used to calculate the safety distance, detailed explanations of the calculation method will be omitted here. The mathematical formula model for calculating the safety distance can be, for example, an RSS (Responsibility Sensitive Safety) model. Furthermore, the mathematical formula model for calculating the safety distance can also be SFF (Safety Force Field, registered trademark). The safety distance calculated by the safety distance setting unit F72 using the mathematical formula model is hereinafter also referred to as the standard value dmin of the safety distance. The safety distance setting unit F72 is configured to be able to set the safety distance to be longer than the standard value dmin based on the determination result of the consistency determination unit F51.
[0088] It should be noted that the above mathematical formula model does not guarantee that an accident will not occur at all, but rather ensures that if appropriate action is taken to avoid a collision when the safe distance is not reached, the vehicle will not be held responsible for the accident. An example of the appropriate action to avoid a collision referred to here is braking with reasonable force. Braking with reasonable force is, for example, braking with the maximum deceleration possible for the vehicle. The safe distance calculated by the mathematical formula model can be rephrased as the minimum distance that the vehicle should maintain between itself and an obstacle in order to avoid close proximity between the vehicle and the obstacle.
[0089] The action decision unit F73 is configured to determine a final execution plan from among a plurality of control plans based on the potential accident responsibility value calculated by the responsibility value calculation unit F71, as described above. The control planning unit F7, which functions as the action decision unit F73, determines a final execution plan based on the remaining map acquisition time Tmg input from the map management unit F5. The action content based on the remaining map acquisition time Tmg, in other words, the map non-acquisition handling process that is the process for determining a control plan, will be described separately below.
[0090] The control signal output unit F8 is configured to output a control signal corresponding to the control plan determined by the action determination unit F73 to the traveling actuator 16 and / or HCU 151 to be controlled. For example, if deceleration is planned, it outputs a control signal to the brake actuator or the electronic throttle to realize the planned deceleration. It also outputs a control signal to the HCU 151 to display a map icon according to the acquisition status of partial map data. When a predetermined recording event occurs, the output signal of the control signal output unit F8 can be recorded by the driving recorder 17.
[0091] Additionally, when an emergency action is taken, the automatic driving device 20 outputs data indicating the acquisition status of partial map data to the operation recording device 17. The acquisition status of partial map data includes the IDs of map tiles that have been acquired. In addition, whether or not the consistency determination unit F51 has determined that the map data and the real world are inconsistent is also output as data indicating the acquisition status of partial map data.
[0092] <About handling when map is not acquired> Here, the process executed by the control planning unit F7 to deal with the absence of map acquisition will be described using the flowchart shown in Fig. 8. The flowchart shown in Fig. 8 is executed at a predetermined cycle (for example, every 500 milliseconds) while a predetermined application that uses map data, such as an autonomous driving application, is being executed. The predetermined application may include an autonomous driving application as well as an ACC (Adaptive Cruise Control), an LTC (Lane Trace Control), a navigation application, etc. Note that if the map management unit F5 notifies that the next area map data has been acquired, i.e., if the next area map data has already been acquired, this flow can be omitted.
[0093] First, in step S201, the map acquisition remaining time Tmg is acquired from the map management unit F5, and step S202 is executed. In step S202, it is determined whether the map acquisition remaining time Tmg is less than a predetermined first time Th1. If the map acquisition remaining time Tmg is less than the first time Th1, a positive judgment is made in step S202 and the process proceeds to step S204. On the other hand, if the map acquisition remaining time Tmg is equal to or greater than the first time Th1, a negative judgment is made in step S202 and the process proceeds to step S203. Note that even if the next area map data has already been acquired, a negative judgment is made in step S202 and the process proceeds to step S203. The first time Th1 used in this judgment is a parameter that functions as a threshold for determining whether or not it is necessary to implement a first emergency action, which will be described separately below. The first time Th1 is set to, for example, 60 seconds. Note that the first time Th1 may also be, for example, 45 seconds, 90 seconds, or 100 seconds.
[0094] In step S203, normal control is executed, that is, a control plan determined based on the potential accident liability value from among a plurality of candidate plans for autonomously traveling toward the destination is executed.
[0095] In step S204, it is determined whether the map acquisition remaining time Tmg is less than a predetermined second time Th2. The second time Th2 is set to be longer than 0 seconds and shorter than the first time Th1. The second time Th2 used in this determination is a parameter that functions as a threshold for determining whether or not a second emergency action, which will be described separately below, needs to be implemented. The second time Th2 is set to, for example, 30 seconds. Note that the second time Th2 may also be, for example, 20 seconds or 40 seconds. If the map acquisition remaining time Tmg is less than the second time Th2, a positive determination is made in step S204 and the process proceeds to step S206. On the other hand, if the map acquisition remaining time Tmg is equal to or greater than the second time Th2, a negative determination is made in step S204 and the process proceeds to step S205. Note that, according to this configuration, step S205 is executed when the map acquisition remaining time Tmg is shorter than the first time Th1 and equal to or greater than the second time Th2.
[0096] In step S205, the execution of a predetermined first emergency action is planned and started. The first emergency action is, for example, notifying the driver's seat occupant or an operator outside the vehicle that a map that will soon be required to continue autonomous driving, etc. has not yet been acquired. For convenience, the process of notifying the occupant, etc. that next area map data has not been acquired is also referred to as map not acquired notification process. As described above, the content of the notification in the map not acquired notification process can be information indicating that a map required to continue autonomous driving, etc. has not been acquired. For example, the map not acquired icon 80A shown in FIG. 3A may be displayed on the display 151 together with a text or voice message.
[0097] Furthermore, the notification content in the map non-acquisition notification process may be an image or a voice message indicating that autonomous driving may soon be interrupted due to a map defect. The above configuration corresponds to a configuration for notifying the occupant or operator that acquisition of partial map data has failed. The notification medium may be an image or a voice message. As a result of the map non-acquisition notification process, the control signal output unit F8 outputs a control signal to the HCU 152 to instruct the display 151 to output an icon image or a message image corresponding to the above content. Note that when the map non-acquisition notification process is executed as the first emergency action, a control plan selected from multiple plan candidates in the usual procedure may be separately implemented in parallel.
[0098] In step S206, it is determined whether the map acquisition remaining time Tmg is less than a predetermined third time Th3. The third time Th3 is set to be longer than 0 seconds and shorter than the second time Th2. The third time Th3 used in this determination is a parameter that functions as a threshold for determining whether or not a third emergency action, which will be described separately below, needs to be implemented. The third time Th3 is set to, for example, 10 seconds. Note that the third time Th3 may also be, for example, 5 seconds or 15 seconds. If the map acquisition remaining time Tmg is less than the third time Th3, a positive determination is made in step S206 and the process proceeds to step S208. On the other hand, if the map acquisition remaining time Tmg is equal to or greater than the third time Th3, a negative determination is made in step S206 and the process proceeds to step S207. Note that, according to this configuration, step S207 is executed when the map acquisition remaining time Tmg is shorter than the second time Th2 and equal to or greater than the third time Th3.
[0099] In step S207, a predetermined second emergency action is planned and initiated. The second emergency action may be, for example, a process of reducing the vehicle's traveling speed by a predetermined amount from the planned target speed. For convenience, the process of reducing the traveling speed is also referred to as a speed reduction process. By setting the vehicle's traveling speed to a value lower than the originally planned value, the time until the vehicle reaches a point where the next area map data is required can be extended. In other words, the remaining map acquisition time Tmg can be extended. This increases the probability that the next area map data can be acquired before the vehicle reaches a point where the next area map data is required. If a speed reduction process is determined as the second emergency action, a candidate plan may be created that assumes the speed reduction process, and the final deceleration implementation mode may be determined based on the potential accident liability value. The deceleration amount for the second emergency action may be a fixed value, such as 5 km / h or 10 km / h. The target speed after deceleration may also be a value obtained by multiplying the originally planned target speed by a predetermined coefficient less than 1. For example, the target speed after deceleration may be 0.9 or 0.8 times the originally planned target speed. If the current driving lane is an overtaking lane, etc., a lane change to the driving lane may also be planned in conjunction with the decision to implement the second emergency action. The driving lane here refers to a lane that is not an overtaking lane. For example, in Japan, lanes other than the rightmost lane are considered driving lanes. In Germany, the rightmost lane is considered driving lanes. The settings of the overtaking lane and driving lane may be changed to comply with the traffic rules of the area in which the vehicle is being driven.
[0100] In step S208, a predetermined third emergency action is planned and initiated. The third emergency action may be, for example, MRM. The MRM may autonomously drive the vehicle to a safe location and park it while issuing an alarm to those in the vicinity. A safe location may be a shoulder of a road with a width equal to or greater than a predetermined value or a designated emergency evacuation area. The MRM may also be designed to stop the vehicle within the current lane by gradually decelerating. A deceleration rate of 4 m / s^2 or less, such as 2 m / s^2 or 3 m / s^2, is preferably used. Of course, deceleration rates exceeding 4 m / s^2 may also be used if it is necessary to avoid a collision with a preceding vehicle. The deceleration rate during MRM may be dynamically determined and updated based on the vehicle speed at the time of MRM initiation and the distance between the vehicle and the following vehicle, as long as the vehicle can be stopped within 10 seconds, for example. Initiating MRM corresponds to initiating deceleration for an emergency stop.
[0101] <About inconsistency handling> Here, the inconsistency handling process executed by the autonomous driving device 20 will be described using the flowchart shown in Fig. 9. The flowchart shown in Fig. 9 is executed at a predetermined cycle (for example, every 200 milliseconds) while a predetermined application that uses map data, such as autonomous driving or navigation, is being executed. Note that this flow can be executed independently of the map non-acquisition handling process shown in Fig. 8, in other words, in parallel and sequentially. In this embodiment, as an example, the inconsistency handling process includes steps S301 to S306.
[0102] First, in step S301, sensing information from the perimeter monitoring sensor 11 is acquired, and the process proceeds to step S302. In step S302, the consistency determination unit F51 performs consistency determination processing. This consistency determination processing can be, for example, the content explained using the flowchart shown in FIG. 7. If it is determined as a result of step S302 that there is a gap between the map and the real world, the process proceeds to step S304. On the other hand, if it is not determined as a result of step S302 that there is a gap between the map and the real world, the process proceeds to step S305.
[0103] In addition, a state in which there is a gap between the map and the real world corresponds to a state in which the map and the real world are not consistent. Examples of a state in which the map and the real world are not consistent include a state in which an obstacle not registered in the map is present on the road, or a state in which a drivable area on the map is not actually drivable. Furthermore, a case in which the road shape shown on the map differs from the road shape detected by the perimeter monitoring sensor 11 also corresponds to an example of a state in which the map data and the real world are not consistent. Here, the road shape refers to at least one of the number of lanes, curvature, road width, etc. For example, a case in which the road edge shape shown on the map differs from the shape actually observed by the forward camera, or a case in which a landmark not registered in the map data is detected also corresponds to an example of a state in which there is a gap between the map and the real world. In addition, a state in which there are no other vehicles ahead, i.e., a state in which the forward camera has a clear field of view, but a landmark registered in the map data cannot be detected also corresponds to an example of a state in which the map data and the real world are not consistent. When the color, shape, position, and display content of a sign registered in the map data differ from the image recognition results, this is also an example of a case where the map data and the real world do not match.
[0104] In step S304, the safety distance setting unit F72 sets the set value dset of the safety distance to be longer than the standard value dmin. For example, the set value dset of the safety distance can be set as shown in the following formula 1.
[0105] dset=dmin+εd (Equation 1) In addition, εd in Equation 1 is a parameter corresponding to the extension amount, and for convenience, is referred to as the extension distance. For example, the extension distance εd is a value greater than 0. The extension distance εd can be a fixed value such as 20 m or 50 m. The extension distance εd may also be dynamically determined depending on the speed or acceleration of the host vehicle Ma. For example, the extension distance εd may be set to be longer the higher the vehicle speed. The extension distance εd may also be set to be longer the higher the acceleration or lower the deceleration of the host vehicle Ma. In addition, the extension distance εd may be adjusted depending on the type of road on which the host vehicle Ma is traveling. For example, if the road on which the host vehicle Ma is traveling is an ordinary road, the extension distance εd may be set to a smaller value than when the road is a motorway such as an expressway.
[0106] In another embodiment, the set value dset of the safe distance may be set as shown in the following equation 2. dset=dmin×α (Equation 2)
[0107] Note that α in Equation 1 is a coefficient for extending the safety distance and will be referred to as the expansion coefficient for convenience. The expansion coefficient α is a real number greater than 1. The expansion coefficient α can be a fixed value, such as 1.1 or 1.2. The expansion coefficient α may also be dynamically determined depending on the speed or acceleration of the host vehicle Ma. For example, the expansion coefficient α may be set to a larger value as the vehicle speed increases. The expansion coefficient α may also be set to a larger value as the acceleration or deceleration of the host vehicle Ma increases. In addition, the expansion coefficient α may be adjusted depending on the type of road on which the host vehicle Ma is traveling. For example, the expansion coefficient α may be set to a smaller value when the host vehicle Ma is traveling on an ordinary road than when the road is a motorway such as an expressway. After the processing in step S304 is completed, the process proceeds to step S306.
[0108] In step S305, the standard value dmin calculated based on the mathematical formula model is set as the set value dset of the safety distance, and the process proceeds to step S306. In step S306, the control planning unit F7 creates a control plan that can ensure the safety distance determined by the above process. For the control plan created in step S306, the responsibility value calculation unit F71 calculates a potential personal responsibility value, and the final action to be taken is selected based on the calculated potential accident responsibility value.
[0109] <Effects of the above configuration> According to the above configuration, when the remaining map acquisition time Tmg falls below the first hour, an emergency action such as a notification to the driver's seat occupant is executed. With this configuration, even if the autonomous driving is ultimately interrupted due to a loss of map data, the presence of a prior notification reduces the risk that the interruption of the autonomous driving will result in behavior unexpected by the user. In other words, it is possible to reduce the risk that the autonomous driving will be interrupted at a time that is unexpected by the user. As a result, it is possible to reduce the risk that the user will be confused.
[0110] Furthermore, when the remaining map acquisition time Tmg falls below the second time, the vehicle speed is reduced as an emergency action. This configuration can extend the time until the next area map data is needed. As a result, the likelihood of the next area map data being acquired in time can be increased. Furthermore, the user can be expected to detect a malfunction in the system based on the fact that the vehicle speed is reduced more than usual. In other words, even if autonomous driving is ultimately interrupted due to a map data defect, the risk of the interruption of autonomous driving resulting in behavior unexpected by the user can be reduced. Additionally, in the present disclosure, a notification is given to the driver's seat occupant before the vehicle speed is reduced as an emergency action. This configuration allows the driver's seat occupant to estimate the reason for the vehicle speed reduction, thereby reducing the risk of the vehicle speed reduction confusing or causing discomfort to the user.
[0111] Furthermore, with the above configuration, when the remaining map acquisition time Tmg falls below a predetermined threshold third time Th3, MRM, i.e., deceleration toward stopping, begins. This configuration reduces the risk of autonomous driving continuing without map data. Also, because MRM is executed within the scope of map data, it can be executed more safely than when MRM is executed within the scope of map data.
[0112] Furthermore, with the above configuration, the safety distance is extended when there is a gap between the map and the real world. A gap between the map and the real world corresponds to a state in which the reliability of the map is impaired. In such a situation, there is a higher possibility that the evaluation of each plan candidate, such as the potential accident liability value, will be incorrect. Therefore, safety can be improved by temporarily extending the safety distance beyond the standard value dmin.
[0113] <Additional information on the operation of the control planning section F7> The above describes an embodiment in which at least one of notifying the driver, suppressing vehicle speed, and MRM is executed as an emergency action based on the remaining map acquisition time Tmg. However, the content and combination of the emergency actions are not limited to this. The control planning unit F7 may be configured to employ map-free autonomous driving, which is control for continuing autonomous driving without using map data provided by the map server 3, as an emergency action. Map-free autonomous driving can be, for example, an operating mode in which the vehicle continues driving using an instant map, which is a map of the surroundings of the vehicle created on the spot based on the detection results of the perimeter monitoring sensor 11. The instant map can be generated, for example, by Visual SLAM (Simultaneous Localization and Mapping), which is SLAM mainly based on camera images. The instant map can also be created by sensor fusion. The instant map can also be called a simple map, a custom map, or a sensing map. Map-free autonomous driving can also be an operating mode in which the vehicle uses the trajectory of a preceding vehicle as its driving trajectory and decelerates in response to a cutting-in vehicle or a road pedestrian detected by the perimeter monitoring sensor 11. Map-free autonomous driving can be an alternative to MRM, for example.
[0114] The control planning unit F7 may adopt map-free autonomous driving as an emergency action depending on the surrounding traffic conditions. For example, if the remaining map acquisition time Tmg is less than the second time Th2 or less than the third time Th3, and there are other vehicles in front, behind, on the left and right of the host vehicle Ma, map-free autonomous driving may be adopted. This is because, when there are other vehicles in front, behind, on the left and right of the host vehicle Ma, safety can be expected to be ensured by driving while maintaining a distance between the host vehicle Ma and the surrounding vehicles. The conditions for adopting map-free autonomous driving, in other words, the situation, can be determined based on the design philosophy of the vehicle manufacturer. Map-free autonomous driving can be called an exceptional emergency action.
[0115] Furthermore, a handover request process can be adopted as an emergency action. The handover request process corresponds to requesting a driver's seat occupant or an operator to take over driving operations in conjunction with the HMI system 15. The handover request process can be called a handover request. For example, the control planning unit F7 may be configured to plan and execute a handover request as an emergency action when the remaining map acquisition time Tmg becomes less than a second time. Alternatively, the control planning unit F7 may be configured to extend the safety distance as an emergency action when the remaining map acquisition time Tmg becomes less than a predetermined threshold, such as the second time Th2. The method of extending the safety distance can be the same as that of step S304.
[0116] The control planning unit F7 may also be configured to calculate a level of urgency based on the remaining map acquisition time Tmg and execute an emergency action according to the level of urgency. The level of urgency is a parameter that is set higher as the remaining map acquisition time Tmg is shorter. For example, the level of urgency can be expressed in three levels: Level 1, Level 2, and Level 3. Level 1 can be defined as a state in which the remaining map acquisition time Tmg is shorter than the first time Th1 and equal to or greater than the second time Th2. Level 2 can be defined as a state in which the remaining map acquisition time Tmg is shorter than the second time Th2 and equal to or greater than the third time Th3. Level 3 can be defined as a state in which the remaining map acquisition time Tmg is shorter than the third time Th3. FIG. 10 shows an example of emergency actions for each level of urgency. For example, when the level of urgency is Level 1, the control planning unit F7 plans and executes a notification to the driver or operator as a first emergency action. When the level of urgency is Level 2, the control planning unit F7 plans and executes a speed reduction process as a second emergency action. Furthermore, when the urgency level is level 3, the control planning unit F7 plans and executes MRM as a third emergency action.
[0117] The content and combination of emergency actions to be executed depending on the urgency level or the remaining map acquisition time Tmg can be changed as appropriate. For example, as shown in FIG. 11, when the urgency level is level 1, a speed suppression process with a relatively small deceleration amount may be executed along with a notification to the driver or operator. When the urgency level is level 2, a speed suppression process with a relatively larger deceleration amount than that of level 1 may be executed. The deceleration amount of the speed suppression process when the urgency level is level 1 is smaller than the deceleration amount of the speed suppression process when the urgency level is level 2. For example, if the deceleration amount of the speed suppression process when the urgency level is level 1 is 5 km / h, the deceleration amount of the speed suppression process when the urgency level is level 2 can be 10 km / h. When the urgency level is level 2, a handover request may be executed as an emergency action.
[0118] The number of urgency levels and the criteria for determination can be changed as appropriate. The urgency level may be determined using five or more levels. The urgency level may also be determined taking into consideration the traffic conditions around the vehicle, in addition to the remaining map acquisition time Tmg. For example, in a traffic jam situation, the urgency level may be set lower than when there is no traffic jam. This is because there is little risk of the positional relationship with surrounding vehicles changing suddenly in a traffic jam situation. A traffic jam situation refers to, for example, a situation in which other vehicles are present in front, behind, on both sides of the vehicle, and the vehicle is traveling at a speed of 60 km / h or less.
[0119] <Conditions for ending emergency actions> Here, the operation of the automatic driving device 20 when ending an emergency action will be described using the flowchart shown in Fig. 12. The flowchart shown in Fig. 12 is executed at a predetermined cycle (for example, every 200 milliseconds) while a predetermined application that uses map data, such as automatic driving or navigation, is being executed. Note that this flow can be executed sequentially independently of the map non-acquisition handling process shown in Fig. 8 and the inconsistency handling process shown in Fig. 9. In this embodiment, as an example, the emergency action ending process comprises steps S401 to S403. Each step may be executed by the control planning unit F7.
[0120] First, in step S401, it is determined whether or not an emergency action is being taken. If an emergency action is not being taken, this flow ends. On the other hand, if an emergency action is being taken, an affirmative judgment is made in step S401 and step S402 is executed.
[0121] In step S402, it is determined whether a predetermined cancellation condition is satisfied. The cancellation condition is a condition for terminating an emergency action currently being executed. For example, the control planning unit F7 determines that the cancellation condition is satisfied when partial map data necessary for continuing autonomous driving, such as next area map data, can be acquired, in other words, when the remaining map acquisition time Tmg has recovered to a sufficiently large value. The control planning unit F7 may also determine that the cancellation condition is satisfied when an operation to obtain driving operation authority, i.e., an override operation, is performed by the driver's seat occupant or operator. In other words, the cancellation condition may be determined to be satisfied when the autonomous driving mode is switched to a manual driving mode or a driving assistance mode. Alternatively, the cancellation condition may be determined to be satisfied when the vehicle stops.
[0122] If it is determined in step S402 that the cancellation condition is met, step S403 is executed. On the other hand, if it is determined that the cancellation condition is not met, this flow ends. In this case, the emergency action according to the remaining map acquisition time Tmg or the urgency level continues.
[0123] In step S403, the emergency action currently being taken is terminated, and this flow is terminated. For example, if a map non-acquisition notification process is being executed, the image display and audio message output are terminated. Also, if a speed suppression process is being executed, the target speed suppression is released and the original target speed is restored. When the emergency action is terminated, a notification that the emergency action has been terminated may be issued. It is preferable that the driver's seat occupant be notified of the termination of the emergency action together with the reason for termination. For example, the notification that the emergency action has been terminated may be issued because the map data required for autonomous driving, i.e., the next area map data, has been acquired.
[0124] Although the embodiments of the present disclosure have been described above, the present disclosure is not limited to the above-described embodiments, and various modifications described below are also included within the technical scope of the present disclosure. Furthermore, various modifications other than those described below can be implemented without departing from the gist of the present disclosure. For example, the various modifications described below can be implemented in appropriate combinations as long as no technical contradictions arise. Note that components having the same functions as those described in the above-described embodiments are given the same reference numerals, and their description will be omitted. Furthermore, when only a portion of the configuration is mentioned, the configuration of the previously described embodiment can be applied to the other portions.
[0125] <Additional information on how to manage map data> As described above, the processing unit 21 as the map management unit F5 may be configured to cache map data related to roads that are used regularly, such as routes to work or school, in the map storage unit M1 as much as possible. Examples of map data related to roads that are used regularly include map data with tile IDs that have been downloaded a certain number of times or partial map data for areas within a certain distance from home, work, or school. Furthermore, the processing unit 21 may be configured to store downloaded map data, not limited to roads that are used regularly, until the capacity of the map storage unit M1 is full or until an expiration date appropriately set for each piece of map data expires.
[0126] Hereinafter, for convenience, the map data stored in the map storage unit M1 will also be referred to as stored map data. Here, stored map data refers to data that was already stored in the map storage unit M1 when the driving power source was turned on. In other words, it refers to map data acquired during the previous or previous driving session. Stored map data can also be called previously acquired map data. In contrast, map data downloaded from the map server 3 after the driving power source was turned on can be called newly acquired map data. Note that stored map data can also be called cached map data depending on its storage format and storage area.
[0127] In a configuration in which map data remains in the map storage unit M1 even after the driving power is turned off, the processing unit 21 may be configured to actively reuse the map data stored in the map storage unit M1. For example, the processing unit 21 may be configured to determine whether or not map data needs to be downloaded using the processing procedure shown in Fig. 13. The processing flow shown in Fig. 13 may be started in response to a trigger such as a change in the map data being used or the remaining time until exiting the current area becoming less than a predetermined value.
[0128] That is, based on the fact that the partial map used to create the control plan has been switched as the vehicle moves, the processing unit 21 refers to the map storage unit M1 and determines whether next area map data is stored in the map storage unit M1 (step S501). For example, the map management unit F5 identifies the tile ID of the next area based on the adjacent tile ID linked to the current area map data and the traveling direction of the vehicle. Then, the map storage unit M1 is searched for map data having the tile ID of the next area. If map data having the tile ID of the next area is found (step S501: YES), the stored partial map data is adopted as the map data to be used for the control plan (step S502).
[0129] Furthermore, if map data having the tile ID of the next area is not stored in the map storage unit M1 (step S501 NO), the processing unit 21 starts processing to download the next area map data from the map server 3 (step S503). The processing to download the map data includes, for example, a step of transmitting a map request signal to the map server 3. The map request signal is a signal requesting distribution of map data and includes the tile ID of the requested partial map. In other words, S503 can be processing to transmit a map request signal including the tile ID of the next area and receive map data distributed as a response from the map server 3.
[0130] The map request signal only needs to include information that can identify the map tile to be distributed by the map server 3, and may include, for example, the current position and traveling direction of the vehicle instead of or in addition to the tile ID. In addition, when map data having the tile ID of the next area is not stored, this may also include a case where map data having the tile ID of the next area was stored but the validity period of the data has expired.
[0131] This configuration can reduce the frequency and volume of communication with the map server 3. Furthermore, when reusing saved map data, it is possible to reduce the risk that the remaining map acquisition time Tmg will fall below a predetermined threshold, thereby reducing the risk that emergency action will be taken.
[0132] However, the stored map data may not be the latest version. For example, the shape and color of a commercial sign registered on the map as a landmark may differ from the shape and color of the real world. If the content shown on the map and the real world are inconsistent, the accuracy of self-location estimation may deteriorate.
[0133] In consideration of such circumstances, when using stored map data, the processing unit 21 as the consistency determination unit F51 may sequentially determine the consistency between the stored map data and the real world as shown in FIG. 14 (step S601). As long as it is determined that the stored map data is consistent with the real world (step S602: YES), the processing unit 21 may continue to use the stored map data (step S603). On the other hand, based on the determination that the stored map data is not consistent with the real world (step S602: NO), the processing unit 21 may re-download partial map data of the current area from the map server 3 (step S604). The stored map data corresponding to the current area may be deleted / overwritten as soon as the map data download is completed. The series of processes shown in FIG. 14 may be performed periodically, for example, every second, while the stored map data is being used.
[0134] If the map management unit F5 determines that the stored map data is inconsistent with the real world, it may check whether the stored map data is the latest version by communicating with the map server 3. Whether the stored map data is the latest version can be checked by sending version information of the stored map data to the map server 3 or by obtaining latest version information of the map data of the current area from the map server 3. If the stored map data is the latest version, there is no point in re-downloading it, so step S604 may be omitted. In this case, in order to improve robustness, the control conditions may be changed, such as by performing the inconsistency response process described above or by suppressing the driving speed.
[0135] The processing unit 21 as the consistency determination unit F51 may evaluate the consistency, for example, as a percentage ranging from 0% to 100%, instead of using two levels of consistency between the stored map data and the real world. Hereinafter, the score value indicating consistency will also be referred to as a consistency rate. The consistency determination unit F51 may determine that the stored map data is inconsistent with the real world based on determining that the consistency rate is equal to or lower than a predetermined value. Furthermore, in order to suppress the influence of momentary noise, the consistency determination unit F51 may determine that the stored map data is inconsistent with the real world based on the evaluation result that the consistency rate is equal to or lower than a predetermined value being obtained continuously for a predetermined period of time or more.
[0136] Alternatively, when a positive determination is made in step S501 or step S602, the map management unit F5 may be configured to refer to the acquisition date of the stored map data and use the stored map data on the condition that the elapsed time since the acquisition date is less than a predetermined threshold. In other words, when reading out certain stored map data, if the elapsed time since the acquisition date is equal to or greater than a predetermined threshold, re-download the map data of the area from the map server 3.
[0137] Furthermore, even in a configuration in which map data is left in the map storage unit M1, the processing unit 21 may be configured to basically perform driving control using map data newly acquired from the map server 3. The processing unit 21 may be configured to create and execute a control plan using the map data stored in the map storage unit M1 only when partial map data cannot be acquired from the map server 3 due to a communication failure or the like. Such a configuration corresponds to a configuration in which stored map data is passively reused.
[0138] Fig. 15 is a flowchart showing an example of the operation of the processing unit 21 corresponding to the above technical concept. The flowchart shown in Fig. 15 may be executed, for example, in a situation where the next area map data has not been acquired from the map server 3. The processing flow shown in Fig. 15 can be executed in parallel with, in combination with, or in place of the various processes described above, such as the process shown in Fig. 8. For example, the processing flow shown in Fig. 15 can be executed as processing when a negative determination is made in step S204. The processing shown in Fig. 15 includes steps S701 to S704.
[0139] In step S701, the processing unit F21 determines whether the remaining map acquisition time Tmg is less than a predetermined cache usage threshold value Thx. The cache usage threshold value Thx is set to a value longer than the third time Th3, such as 15 seconds or 30 seconds. The cache usage threshold value Thx may be the same as the first time Th1 or the second time Th2 described above. The cache usage threshold value Thx may also be prepared as a parameter independent of the above threshold values.
[0140] If the remaining map acquisition time Tmg is equal to or greater than the predetermined cache usage threshold Thx (step S701 NO), the processing unit 21 temporarily terminates the flow shown in FIG. 15. In this case, the processing unit 21 may re-execute the processing flow shown in FIG. 15 after a predetermined time, provided that the next area map data has not yet been acquired. On the other hand, if the remaining map acquisition time Tmg is less than the predetermined cache usage threshold Thx (step S701 YES), the processing unit 21 determines whether map data having the tile ID of the next area is stored in the map storage unit M1. If partial map data of the next area is stored in the map storage unit M1 (step S702 YES), the processing unit 21 creates a control plan for the next area using the stored partial map data (step S703). On the other hand, if partial map data of the next area is not stored in the map storage unit M1 (step S702 NO), the processing unit 21 adopts emergency action according to the remaining map acquisition time Tmg.
[0141] A situation in which the remaining map acquisition time Tmg is less than the cache use threshold Thx corresponds to a situation in which partial map data of the next area is needed to create a control plan. Other situations in which partial map data of the next area is needed to create a control plan may also occur when the remaining map acquisition time Tmg reaches 0 seconds or when the vehicle exits the current area. Even if the processing unit 21 starts using the stored map data in step S703, the processing unit 21 may periodically perform processing to download next / current area map data from the map server 3. If the next / current area map data can be acquired from the map data due to recovery of the communication state or the like, the processing unit 21 may execute control using the map data acquired from the map server 3 instead of the stored map data.
[0142] As mentioned above, when stored map data is used, errors in self-location estimation (localization) may increase due to the oldness of the map. In view of such concerns, the processing unit 21 may be configured to control differently / operate differently depending on whether stored map data is being used or whether map data newly downloaded from the map server 3 is being used.
[0143] For example, as shown in Fig. 16, when stored map data is not being used (step S801 NO), the processing unit 21 sets the upper limit of the travel speed permitted in the control plan to a standard upper limit value according to the type of road (step S802). Vmx_set in Fig. 16 is a parameter that indicates the upper limit of the travel speed permitted, that is, the set value of the upper limit speed. Also, Vmx_RdTyp is a parameter that indicates the standard upper limit value according to the type of road. Note that when stored map data is not being used, this corresponds to a case where a control plan or the like is created using partial map data acquired from the map server 3.
[0144] The standard upper limit is set to a value depending on the type of road, such as whether it is a highway or an ordinary road. For example, if the road is a highway, the upper limit is set to 120 km / h, while if the road is an ordinary road, the upper limit is set to, for example, 60 km / h. The standard upper limit for each road type may be configured to be set by the user at any value. The standard upper limit may be the speed limit set for each road. The speed limit may be determined by referring to map data or may be identified by image recognition of speed limit signs. Changing the set value of the upper limit speed used in the control plan corresponds to changing the control conditions. Furthermore, the standard upper limit may be set based on the average speed of surrounding vehicles to ensure smooth traffic flow. The average speed of surrounding vehicles may be calculated based on the speed of the vehicle observed by the perimeter monitoring sensor 11 or may be calculated based on speed information of other vehicles received via vehicle-to-vehicle communication.
[0145] On the other hand, if stored map data is being used (YES in step S801), the upper limit of the travel speed allowed in the control plan is set to a value obtained by subtracting a predetermined suppression amount from the standard upper limit according to the type of road (step S803). Vdp in Fig. 16 is a parameter indicating the suppression amount. The suppression amount may be a fixed value such as 10 km / h, or may be a value equivalent to 10% or 20% of the standard upper limit according to the road type.
[0146] According to the above configuration, when the vehicle is traveling using the stored map data, the maximum speed can be reduced compared to when the vehicle is traveling using the newly acquired map data. By reducing the traveling speed, robustness is improved, and the risk of the autonomous traveling control being interrupted can be reduced.
[0147] In a configuration in which the consistency determination unit F51 calculates the degree of inconsistency between the map data and the real world, in other words, the consistency rate, the processing unit 21 may change the control conditions according to the consistency rate. For example, the lower the consistency rate, the larger the suppression amount (Vd) may be. Specifically, if the consistency rate is 95% or higher, the suppression amount (Vd) may be set to 0, while if the consistency rate is 90% or higher but less than 95%, the suppression amount may be set to 5 km / h. Furthermore, if the consistency rate is 90% or lower, the suppression amount may be set to 10 km / h or higher. For example, if the consistency rate is less than 80%, the suppression amount may be set to 15 km / h.
[0148] Furthermore, the processing unit 21 may be configured to operate in a mode in which automatic overtaking control is executable when the consistency rate is equal to or greater than a predetermined threshold, and to operate in a mode in which automatic overtaking is prohibited when the consistency rate is less than the threshold. Automatic overtaking control refers to a series of controls including moving to an overtaking lane, accelerating, and returning to the driving lane.
[0149] Note that the processing unit 21 may be configured to create a control plan by using the detection results of the perimeter monitoring sensor 11 preferentially over map data when the consistency rate is equal to or lower than a predetermined threshold. Furthermore, when the consistency rate is lower than the predetermined threshold, the processing unit 21 may create a plan to more aggressively follow the preceding vehicle than when the consistency rate is equal to or higher than the predetermined threshold. For example, even in a scene where overtaking control is normally performed, control to follow the preceding vehicle without overtaking may be planned and executed when the consistency rate is lower than the predetermined threshold. Here, "normal" refers to a case where the consistency rate is equal to or higher than a predetermined threshold. This configuration can reduce the risk of sudden acceleration / deceleration or sudden steering due to insufficient map data.
[0150] As shown in FIG. 17, the processing unit 21 may display on the display 151 an icon image indicating the determination result of the consistency determination unit F51 (step S902). Note that step S901 indicates a step in which the consistency determination unit F51 determines consistency. When the processing unit 21 determines that the map data and the real world are consistent, the processing unit 21 may display an image indicating that the map and reality are consistent. When the processing unit 21 determines that the map data and the real world are consistent, the processing unit 21 may not need to display an image indicating that the map and reality are consistent. Only when the processing unit 21 detects an inconsistency between the map data and the real world, may the processing unit 21 display the detection result, i.e., an image indicating that an inconsistency between the map and reality has been detected.
[0151] Furthermore, when the processing unit 21 detects an inconsistency between the map data and the real world, it may display the specific location of the inconsistency. For example, when the display 151 is a center display, the processing unit 21 may display an image in which a marker image indicating the inconsistency is superimposed on a map image. Furthermore, when the display 151 is equipped with a HUD, the processing unit 21 may use the HUD to superimpose a marker image indicating the inconsistency on the actual inconsistency. When the autonomous driving device 20 is in level 3 mode, it is expected that the driver's seat occupant will be looking ahead. Therefore, by using a configuration in which the HUD superimposes the inconsistency on the foreground, the driver's seat occupant can recognize the inconsistency without taking his or her eyes off the road.
[0152] Furthermore, when the processing unit 21 detects an inconsistency between the map data and the real world, it may notify the driver of this via a HUD or the like and request the driver to select a future control strategy. Options for the future control strategy include, for example, switching to manual driving or continuing automated driving while suppressing the vehicle speed. Switching to manual driving also includes transitioning to Level 2 mode or Level 1 mode. The driver's instructions are obtained, for example, by operating a switch, pedals, or gripping the steering wheel. Note that a response instruction to the inconsistency between the map and reality may be obtained based on gaze, gestures, voice recognition, or the like. Gaze and gestures can be extracted by analyzing images from a camera installed inside the vehicle to capture the driver.
[0153] Incidentally, when the operation mode of the automated driving device 20 is in Level 4 mode, the driver's seat occupant may not necessarily be looking ahead. Furthermore, they may be operating a smartphone or reading a book as a second task. In such a situation, even if an image requesting input of instructions for future control policies is displayed on the HUD or center display, the driver's seat occupant is unlikely to notice. In Level 4 mode, the driver's seat occupant's gaze may be guided to the display 151 by vibration, audio, or the like, and then the driver may be notified of the inconsistency and be requested to input instructions.
[0154] However, presenting too much information or providing too much detail to the occupant may be bothersome. For this reason, when an inconsistency between map data and the real world is detected, the notification to the occupant may simply indicate that an inconsistency between the map and the real world has been detected, without including specific details. The image displayed in step S902 may also display a status indicating whether or not the map data and the real world are consistent. Frequent inconsistency notifications may cause the occupant to distrust the system. For this reason, the notification of the detection of an inconsistency between map data and the real world may be limited so that the number of notifications within a certain period of time is equal to or less than a predetermined value. The notification of the detection of an inconsistency between the map and the real world may also be issued as a notice only when a process to address a map defect, such as vehicle speed reduction or a handover request, is executed. Notification of the detection of an inconsistency between the map and the real world may be suspended during vehicle speed reduction, following a preceding vehicle, or manual driving.
[0155] <Example of vehicle-to-vehicle communication use> For example, from the viewpoint of data reliability, the map acquisition unit F4 may be configured to acquire partial map data from the map server 3 as a general rule, but acquire partial map data from nearby vehicles when the remaining map acquisition time Tmg falls below a predetermined threshold. For example, the map acquisition unit F4 may cooperate with the V2X in-vehicle device 14 to request next area map data from nearby vehicles, thereby acquiring map data for the current area / next area from the nearby vehicles. Such control of acquiring partial map data from other vehicles via vehicle-to-vehicle communication can also be adopted as an emergency action.
[0156] This configuration reduces the risk of autonomous driving being interrupted when a malfunction occurs in the wide-area communication network or the wide-area communication unit of the V2X in-vehicle device 14. Note that the map data acquired from the surrounding vehicles may be used as temporary map data until map data is acquired from the map server 3. It is also preferable that an electronic certificate that guarantees the reliability of the map data be attached to the map data acquired from the surrounding vehicles. The certificate information may be information that includes issuer information, a code that guarantees reliability, etc.
[0157] In relation to the above configuration, vehicles, in other words, the automatic driving devices 20 of each vehicle, may be configured to share freshness information about the map data of the current area or the next area that they hold via vehicle-to-vehicle communication. The freshness information may be download date and time information or version information. When the processing unit 21 detects that another device holds newer map data for the current area or the next area than the processing unit 21, the processing unit 21 may acquire the map data from the other device via vehicle-to-vehicle communication. Here, the other device refers to an automatic driving device or a driving assistance device installed in the other vehicle. The other device may be any device that uses map data. The expression "other device" as a communication partner may be replaced with "other vehicle" or "surrounding vehicle." The other vehicle is not limited to a vehicle traveling ahead of the vehicle, but may also be a vehicle located to the side or behind the vehicle.
[0158] Additionally, when an inconsistency caused by construction, lane restrictions, etc. is detected, the processing unit 21 may notify the rear vehicle of the existence of the inconsistency through vehicle-to-vehicle communication. Furthermore, the processing unit 21 may acquire the inconsistency detected by the leading vehicle from the leading vehicle through vehicle-to-vehicle communication.
[0159] <Examples of using instant maps> As described above, as one of emergency actions when map data cannot be acquired, the processing unit 21 may create an instant map based on the detection results of the perimeter monitoring sensor 11 and create and execute a control plan for continuing autonomous driving using the instant map. The processing unit 21 may also be configured to change its behavior depending on the map creation distance Dmp, which is the distance range for which an instant map can be created. For example, as shown in FIG. 18, if an instant map can be created up to a distance ahead of a predetermined function maintenance distance Dth or more (YES in step T102), the processing unit 21 maintains normal control (step T103). On the other hand, if the map creation distance Dmp is less than the function maintenance distance Dth (NO in step T102), the processing unit 21 executes a process of suppressing the MRM or the traveling speed by a predetermined amount (step T104).
[0160] Step T101 shown in FIG. 18 indicates a processing step for creating an instant map in real time using the detection results of the perimeter monitoring sensor 11. Step T101 can be executed sequentially, for example, every 100 milliseconds or 200 milliseconds. The map creation distance Dmp corresponds to the distance at which the perimeter monitoring sensor 11 can detect a target. The map creation distance Dmp can be, for example, the distance at which the left and right lane markings of the ego lane can be recognized. Alternatively, the map creation distance Dmp may be the distance at which the left or right road edge can be recognized.
[0161] The function maintenance distance Dth may be a constant value, such as 50 m, or a variable value determined according to the speed. For example, the function maintenance distance Dth can be a value obtained by adding a predetermined margin to the MRM required distance Dmrm, which is the distance traveled before the MRM stops. The MRM required distance Dmrm is determined by applying the equation for uniformly accelerated motion from the negative acceleration (i.e., deceleration) used by the MRM and the current speed. That is, Dmrm is determined by Dmrm = Vo^2 / (2a), where Vo is the current speed and a is the deceleration. The deceleration used by the MRM may also be dynamically determined so that a complete stop is possible within 10 seconds.
[0162] The above configuration of the processing unit 21 corresponds to a configuration in which, if an instant map can be created up to a distance farther than the MRM required distance Dmrm, the vehicle continues traveling without performing MRM. The processing unit 21 may be configured to suppress the upper limit of the speed while the instant map is being used, even if the map creation distance Dmp is equal to or greater than the function maintenance distance Dth. The MRM required distance Dmrm becomes shorter as the vehicle speed decreases. Therefore, a configuration in which the vehicle speed is suppressed while the instant map is being used can further reduce the possibility of MRM being executed. A scene in which an instant map is being used corresponds to a scene in which map data required for a control plan cannot be received through communication with the map server 3.
[0163] <Response to no-photography areas> Depending on the area where this system is used, there may be no-photography areas where the camera cannot be pointed. Examples of no-photography areas include the inside and surrounding areas of military facilities, military housing areas, airports, ports, royal palaces, and government facilities. The map server 3 may distribute location information of no-photography areas registered by a map administrator or the like to each vehicle. When the processing unit 21 acquires location information of the no-photography areas from the map server 3, it may execute a handover request based on the location information of the no-photography areas.
[0164] For example, as shown in Fig. 19, when the processing unit 21 detects the presence of a photography-prohibited area ahead of the vehicle based on information distributed from the map server 3 (step T201: YES), it calculates the remaining time Trmn until the vehicle reaches the photography-prohibited area (step T202). If the remaining time Trmn until the vehicle reaches the photography-prohibited area is less than a predetermined threshold Tho (step T203: YES), it initiates a handover request (step T204). If a response is subsequently received from the driver's seat occupant within a predetermined time (step T205: YES), it transfers driving authority to the driver and notifies the driver of this (step T206). On the other hand, if no response is received from the driver's seat occupant even after the predetermined time has elapsed (step T205: NO), it executes MRM.
[0165] The threshold Dho for the remaining time Trmn is set to, for example, 20 seconds, which is sufficiently longer than a predetermined standard handover time. The standard handover time is the response waiting time when a handover request is made due to dynamic factors such as on-street parking or lane restrictions, and is set to, for example, 6, 7, or 10 seconds. The response waiting time for a handover request due to approaching a no-photography area is also set to, for example, 15 seconds, which is longer than the standard handover time.
[0166] The above configuration allows for the transfer of authority with more time to spare than when a handover request is made due to dynamic factors. While the above describes a configuration in which a planned handover is performed based on location information of a photography-prohibited area, it is also possible that the creation and distribution of map data near photography-prohibited areas may be prohibited by law or ordinance. The map server 3 may distribute location information about distribution-prohibited areas for which no maps are available based on law, etc., instead of or in addition to the photography-prohibited area information. The flow in FIG. 19 can be implemented by replacing the expression "photography-prohibited area" with "distribution-prohibited area." In other words, the processing unit 21 may be configured to initiate a planned handover request based on the remaining time / distance until the device reaches the distribution-prohibited area.
[0167] The processing unit 21 may display a message indicating that autonomous driving is possible when moving into an area where autonomous driving is possible, such as when leaving a photography-prohibited area or a distribution-prohibited area. Moving into an area where autonomous driving is possible corresponds to moving into an ODD. The notification that the autonomous driving function is available may be performed by using a notification sound or a voice message. The notification that autonomous driving is possible may also be performed by lighting / flashing a light-emitting element such as an LED provided on the steering wheel or vibrating the steering wheel. The processing unit 21 may calculate the remaining distance / time until leaving the photography-prohibited area or distribution-prohibited area, or the remaining distance / time until autonomous driving becomes possible, and display this on a HUD or the like.
[0168] <Additional remarks (part 1)> In this disclosure, "emergency" refers to a state in which there is a defect in the map data necessary to continue autonomous driving control. In other words, a state in which the map data necessary to continue autonomous driving control is acquired paradoxically corresponds to a normal state. A state in which there is a defect in the partial map data acquired by the map acquisition unit F4 includes a state in which a part of the map data set necessary to perform autonomous driving control, such as the next area map data, cannot be acquired due to, for example, a communication delay, or in other words, a state in which it is missing. Furthermore, a state in which there is a defect in the map data acquired by the map acquisition unit F4 also includes a state in which there is a gap with the real world. A state in which there is a defect in the map data acquired by the map acquisition unit F4 includes a state in which the map update date and time is a predetermined time in the past or a state in which the map is not the latest version. The above configuration corresponds to a configuration in which a predetermined emergency action is executed when there is a defect in the partial map data acquired by the map acquisition unit F4, including a missing part of the data. Note that steps S201 and S302 correspond to a map management step. Also, at least one of steps S203, S205, S206, S208, and S306 corresponds to a control planning step. In one aspect, emergency actions can also be called urgent actions.
[0169] <Additional remarks (part 2)> The control unit and the method described herein may be implemented by a dedicated computer comprising a processor programmed to execute one or more functions embodied in a computer program. The apparatus and the method described herein may also be implemented by a dedicated hardware logic circuit. The apparatus and the method described herein may also be implemented by one or more dedicated computers configured by a combination of a processor executing a computer program and one or more hardware logic circuits. The computer program may also be stored as instructions executed by a computer on a computer-readable non-transitory storage medium. In other words, the means and / or functions provided by the autonomous driving device 20 may be provided by software recorded on a tangible memory device and a computer executing the software, software alone, hardware alone, or a combination thereof. Some or all of the functions of the autonomous driving device 20 may be implemented as hardware. Implementations of certain functions as hardware include implementations using one or more integrated circuits (ICs). The processing unit 21 may be implemented using an MPU, GPU, or DFP (Data Flow Processor) instead of a CPU. The processing unit 21 may be realized by combining multiple types of arithmetic processing devices, such as a CPU, an MPU, and a GPU. Furthermore, the ECU may be realized using an FPGA (field-programmable gate array) or an ASIC (application specific integrated circuit). The various programs may be stored in a non-transitive tangible storage medium. As a storage medium for the programs, various storage media can be used, such as an HDD (hard-disk drive), an SSD (solid-state drive), an EPROM (erasable programmable ROM), a flash memory, and a USB memory.
[0170] <Additional remarks (part 3)> The present disclosure also includes the following configurations.
[0171] [Configuration (1)] An automated driving device that creates a control plan using partial map data, which is map data for a portion of an entire map recording area, a map acquisition unit (F4) that acquires partial map data corresponding to the vehicle's position from a map server; a map management unit (F5) for determining the acquisition status of partial map data; a control planning unit (F7) that creates a control plan using the partial map data, The map management unit determines whether or not next area map data, which is partial map data for an area into which the vehicle will enter, has been acquired within a predetermined time; The control planning unit is configured to plan the execution of a predetermined emergency action based on the determination by the map management unit that the next area map data has not been acquired.
[0172] [Configuration (2)] The automatic driving device according to the above configuration (1), If the next area map data has not been acquired, the remaining time until the next area map data is required is calculated. The automatic driving device is configured to plan the execution of an emergency action when the remaining time until the next area map data is required falls below a predetermined threshold.
[0173] [Configuration (3)] The automatic driving device according to the above configuration (1), The remaining time until the next area map data is required is the time until the vehicle exits the area corresponding to the current area map data, which is the partial map data corresponding to the current position of the vehicle.
[0174] [Configuration (4)] The automatic driving device according to the above configuration (1), The remaining time until the next area map data is required is the remaining time until the vehicle enters the area covered by the next area map data.
Claims
1. An automatic driving device including at least one processor (21) that uses map data to create a control plan for autonomously driving a vehicle, The processor: determining whether the map data is consistent with the real world based on sensing information provided by a surroundings monitoring sensor mounted on the vehicle; and planning the execution of a predetermined emergency action based on a determination that the map data is inconsistent with the real world; The processor: An autonomous driving device configured to plan the execution of the emergency action when the driving position of another vehicle detected by the perimeter monitoring sensor is outside the range of the road shown in the map data.
2. An automatic driving device including at least one processor (21) that uses map data to create a control plan for autonomously driving a vehicle, The processor: determining whether or not the map data stored in the vehicle as the map data is consistent with the real world based on sensing information provided by a surroundings monitoring sensor mounted on the vehicle; and based on the determination that the stored map data is not consistent with the real world, planning the execution of a predetermined emergency action and executing a process for downloading the latest version of map data from a server; The automatic driving device is configured so that the processor controls the vehicle differently depending on whether the stored map data is being used or the latest version of the map data is being used.
3. The processor:
3. The automatic driving device according to claim 2, wherein the automatic driving device is configured to plan, as the emergency action, reducing the driving speed or increasing the distance between the vehicle and a preceding vehicle when the latest version of the map data cannot be acquired or when it is determined that the latest version of the map data is not consistent with the real world.
4. A vehicle control method for autonomously driving a vehicle using map data, the method being executed by at least one processor, comprising: acquiring the map data corresponding to the position of the vehicle from a map server; determining whether the map data is consistent with the real world based on sensing information provided by a surroundings monitoring sensor mounted on the vehicle; planning the execution of a predetermined emergency action based on the determined inconsistency between the map data and the real world; and planning the execution of the emergency action when the traveling position of the other vehicle detected by the perimeter monitoring sensor is outside the range of the road shown in the map data.
5. A vehicle control method for autonomously driving a vehicle using map data, the method being executed by at least one processor, comprising: acquiring the map data corresponding to the position of the vehicle from a map server; determining whether or not the map data stored in the vehicle as the map data is consistent with the real world based on sensing information provided by a surroundings monitoring sensor mounted on the vehicle; Based on the determination that the stored map data and the real world are not consistent, planning the execution of a predetermined emergency action and executing a process for downloading the latest version of map data from a server; and changing a control mode of the vehicle depending on whether the stored map data is being used or the latest version of the map data is being used.
Citation Information
Patent Citations
Mining vehicle and mining vehicle management system
JP2015041283A
Road sign determination device
JP2016173321A
Navigational system with imposed liability constraints
WO2018115963A2