Control system, management method, and management program
The control system for autonomous vehicles uses a safety confirmation unit and permission signals to ensure safe start-up by verifying the vehicle's surroundings, reducing collision risks.
Patent Information
- Application Number
- JP2022152370
- Authority / Receiving Office
- JP · JP
- Patent Type
- Patents
- Current Assignee / Owner
- Filing Date
- 2022-09-26
- Publication Date
- 2025-10-30
- Estimated Expiration
- 2042-09-26
AI Technical Summary
Conventional safety confirmation methods for autonomous vehicles, such as pressing physical buttons or using QR codes, do not guarantee that the surrounding area is safe, increasing the risk of collisions during start-up.
A control system comprising an autonomous vehicle with a safety confirmation unit and an operation terminal that remotely operates the vehicle, where the management device sends permission signals based on the safety confirmation results to ensure safe autonomous driving.
Ensures reliable safety checks of the vehicle's surroundings, reducing the risk of collisions during start-up by verifying the safety confirmation process.
Smart Images

Figure 0007762636000001 
Figure 0007762636000002 
Figure 0007762636000003
Abstract
Description
[Technical Field]
[0001] The present invention relates to a control system, a management method, and a management program for autonomous driving, which are related to control technology of a control center that manages autonomous driving vehicles. [Background technology]
[0002] Systems using autonomous vehicles exist to improve material transportation efficiency and reduce the number of personnel required for transporting various materials within large areas, such as factories and port facilities. Material transportation involves loading and unloading, and humans may work nearby the autonomous vehicle. To ensure safety, the system must properly detect people and avoid collisions. To achieve this, technologies using cameras and LIDAR to detect and avoid collisions have been put into practical use. However, cameras and LIDAR may fail to detect people depending on the situation. Ensuring safety with systems alone is difficult, especially when the vehicle starts moving due to blind spots around the vehicle. Therefore, visual safety confirmation by on-site personnel is essential. However, such safety confirmations can easily become meaningless due to familiarity with the task, and failure to properly confirm can increase the risk of collisions. Furthermore, when multiple autonomous vehicles are operated, there is a risk that the target autonomous vehicle may be mistakenly selected when notifying the system of its start, resulting in the autonomous vehicle starting without safety confirmation having been performed. In other words, in an autonomous driving system for transporting materials within a limited area, such as a factory or port facility, if safety checks of the surrounding area at start-up or when remote operation begins are not properly performed or if the target vehicle is incorrectly designated, the risk of a collision when the autonomous vehicle starts up may increase. Therefore, it is important to determine how the system can confirm that safety checks are being performed appropriately.
[0003] Conventional safety confirmation technologies include a method in which multiple safety confirmation switches are provided at predetermined locations around the vehicle, and a safety confirmation signal is input to make the vehicle ready to travel, as in Patent Document 1. Also, a method using a QR code (registered trademark) as a vehicle identification method has been available, as in Patent Document 2. [Prior art documents] [Patent documents]
[0004] [Patent Document 1] Japanese Patent Application Laid-Open No. 2004-92347 [Patent Document 2] International Publication No. 2020 / 121009 Summary of the Invention [Problem to be solved by the invention]
[0005] However, conventional technologies such as those in Patent Document 1 require a person to approach a physical button to press it, necessitating a mechanism to reduce the risk to the person who presses it. Also, when using QR Codes (registered trademark) as in Patent Document 2, if used to confirm safety, it does not guarantee that the surrounding area is safe.
[0006] The present invention has been made in consideration of the above circumstances, and aims to provide a control system, management method, and management program for autonomous driving that can reliably check the safety of the surroundings of an autonomous vehicle and reduce the risk of collision at start-up due to failure to check. [Means for solving the problem]
[0007] In order to solve the above problems, the control system of the present invention is a control system comprising an autonomous vehicle, a management device that manages the autonomous vehicle, and an operation terminal that remotely operates the autonomous vehicle, wherein the autonomous vehicle is equipped with a safety confirmation unit that confirms the safety of the area around the autonomous vehicle and an autonomous driving unit that starts autonomous driving in response to commands from the operation terminal, the management device is equipped with an autonomous vehicle management unit that manages the autonomous vehicle, and when the autonomous vehicle management unit receives an operation request for the autonomous vehicle from the operation terminal, it sends an permission signal to the operation terminal and the autonomous vehicle to permit the operation request based on the confirmation result of the safety confirmation unit, and the autonomous vehicle performs autonomous driving based on the permission signal and operation instructions from the operation terminal.
[0008] In addition, the management method of the present invention is a management method for managing an autonomous vehicle that begins autonomous driving in response to a command from an operation terminal that remotely operates the autonomous vehicle, and is characterized by including a safety confirmation step of confirming the safety of the area around the autonomous vehicle, a transmission step of, when an operation request for the autonomous vehicle is received from the operation terminal, transmitting an permission signal to the operation terminal and the autonomous vehicle to permit the operation request based on the confirmation result of the safety confirmation step, and an autonomous driving execution step of executing autonomous driving of the autonomous vehicle based on the permission signal and operation instructions from the operation terminal.
[0009] In addition, the management program of the present invention is a management program for managing an autonomous vehicle that begins autonomous driving in response to a command from an operation terminal that remotely operates the autonomous vehicle, and is characterized in that when an operation request for the autonomous vehicle is received from the operation terminal, the management program causes a computer to execute a procedure for sending an authorization signal to the operation terminal and the autonomous vehicle that authorizes the operation request based on the results of confirmation of the safety around the autonomous vehicle. [Effects of the Invention]
[0010] According to the present invention, safety checks of the surroundings of an autonomous vehicle can be reliably carried out, thereby reducing the risk of a collision at start-up due to failure to check.
[0011] Problems, configurations, and effects other than those described above will become clear from the following description of the embodiments. [Brief explanation of the drawings]
[0012] [Figure 1] FIG. 1 is an explanatory diagram illustrating a system configuration according to a first embodiment of the present invention. [Figure 2] FIG. 2 is a functional configuration diagram of a control center according to the first embodiment of the present invention. [Figure 3] FIG. 1 is a hardware configuration diagram of an autonomously driven vehicle according to a first embodiment of the present invention. [Figure 4a] FIG. 2 is a diagram for explaining a screen of an operation terminal in the first embodiment of the present invention, and is an example of a start input screen for an autonomously driven vehicle. [Figure 4b] FIG. 2 is a diagram for explaining a screen of an operation terminal in the first embodiment of the present invention, and is an example of a screen when start-up is successful (when operation is successful). [Figure 4c] FIG. 2 is a diagram for explaining a screen of an operation terminal in the first embodiment of the present invention, showing an example of a screen when a startup error occurs. [Figure 5a] FIG. 2 is an explanatory diagram of an internal data management table (map data table) in the first embodiment of the present invention. [Figure 5b] FIG. 2 is an explanatory diagram of an internal data management table (vehicle state management table) in the first embodiment of the present invention. [Figure 5c] FIG. 2 is an explanatory diagram of an internal data management table (site state management table) in the first embodiment of the present invention. [Figure 6] 4 is a flowchart of determining whether or not autonomous driving can be started in the first embodiment of the present invention. [Figure 7] FIG. 10 is a hardware configuration diagram of an autonomously driven vehicle according to a second embodiment of the present invention. [Figure 8]10 is an example of a screen of an operation terminal in the second embodiment of the present invention. [Figure 9] 10 is a flowchart of determining whether or not autonomous driving can be started in the second embodiment of the present invention. [Figure 10a] FIG. 11 is a diagram for explaining a screen of an operation terminal in the third embodiment of the present invention, and is an example of a screen when remote operation of an autonomously driving vehicle is started. [Figure 10b] FIG. 11 is a diagram for explaining a screen of an operation terminal in the third embodiment of the present invention, and is an example of a screen during remote control of an autonomously driven vehicle. DETAILED DESCRIPTION OF THE INVENTION
[0013] Hereinafter, embodiments of the present invention will be described in detail with reference to the drawings. In all drawings for explaining the present embodiments, components having the same functions are designated by the same reference numerals, and repeated description thereof may be omitted.
[0014] [First embodiment] A first embodiment of the present invention will be described with reference to FIGS.
[0015] 1 is a diagram showing the configuration of an autonomous driving system (control system) including a control center 100 of this embodiment. The autonomous driving system (control system) of this embodiment is intended for use at sites where materials are transported, such as for logistics within a factory or at port facilities, and is intended for an environment where autonomous vehicles 111, 112, manned vehicles 140, and site managers 130 coexist, and where roads 160 and parking areas 150 are set as areas within which autonomous vehicles 111, 112 will travel.
[0016] The control center 100 communicates wirelessly with the autonomous vehicles 111 and 112, the manned vehicle 140, and the site manager 130 within the site to grasp their positions and status, and issues instructions to the autonomous vehicles 111 and 112 to move for transportation. The control center 100 also has an I / F with the manager 120, and notifies the manager 120 of the status of the autonomous vehicles 111 and 112, the manned vehicle 140, and the site manager 130 within the site, the status of material transportation, the status of the parking area 150, etc. The control center 100 also receives instructions from the manager 120 to the autonomous vehicles 111 and 112 to transport materials and to stop in an emergency. It is assumed that the control center 100 will be installed as a server physically within the site, or will be constructed in a cloud environment. In order to ensure safety throughout the site, the control center 100 monitors the status of the autonomous vehicles 111 and 112, and also makes decisions regarding the departure of the autonomous vehicles based on information such as permission for the autonomous vehicles to depart, which is determined by the site manager 130 operating the operation terminal 170, thereby ensuring safety throughout the site.
[0017] The autonomous vehicles 111, 112 travel along designated roads 160 and parking areas 150 within the site in accordance with instructions from the control center 100 to transport materials. The autonomous vehicles 111, 112 have devices for acquiring position information such as a GNSS system and communication devices for communicating with the control center 100, and periodically transmit their own position information and vehicle speed to the control center 100. In addition, when starting to depart, the autonomous vehicles 111, 112 notify the control center 100 of the safety confirmation status around the autonomous vehicles 111, 112 in response to an inquiry from the control center 100. The autonomous vehicles 111, 112 are permitted to start autonomous driving based on the final determination of the control center 100.
[0018] When departing the autonomous vehicles 111 and 112, the site manager 130 checks the surrounding safety and gives permission for departure using the operation terminal 170. The operation terminal 170 is a communication terminal such as a tablet or smartphone, and is used to remotely operate the autonomous vehicles 111 and 112, and communicates with the control center 100.
[0019] The manned vehicle 140 travels within the site, transporting people and materials that the autonomous vehicles 111 and 112 cannot handle. Like the autonomous vehicles 111 and 112, the manned vehicle 140 also has a device for acquiring position information such as a GNSS system and a communication device for communicating with the control center 100, and periodically transmits its own position information and vehicle speed to the control center 100.
[0020] Next, the functions of the control center 100 that realizes the autonomous driving system of this embodiment will be described. FIG. 2 shows the hardware and software configuration of the control center 100. The control center 100 is composed of a CPU 201, a communication I / F 202, a memory 204, a storage 205, and an internal bus 203 that connects these. The control center 100 is assumed to be a general PC, server, or cloud. Note that while FIG. 2 shows the storage 205 and the CPU 201 for executing programs as the same device, the storage 205 may be realized using multiple devices, such as a DB server.
[0021] A vehicle information receiving program 211, a business status receiving program 212, and a vehicle operation program 213 are executed on the CPU 201. The vehicle information receiving program 211 and the vehicle operation program 213 together constitute an autonomously driven vehicle management unit for managing autonomously driven vehicles by the control center 100.
[0022] A vehicle information receiving program 211, a business status receiving program 212, and a vehicle operation program 213 are developed on the memory 204.
[0023] The storage 205 stores map data (hereinafter, sometimes referred to as a map data table) 231, a vehicle state management table 232, and a site state management table 233.
[0024] The vehicle information reception program 211 has a vehicle information management function 221 and a safety confirmation status update function 222, and when it receives information from the autonomously driven vehicles 111, 112, it updates the status of the corresponding autonomously driven vehicle in the vehicle status management table 232. At that time, it checks the current position on the map using map data 231. Furthermore, when the autonomously driven vehicles 111, 112 are stopped, it updates the safety status confirmation result (safety confirmation status) for the corresponding autonomously driven vehicle in the vehicle status management table 232 with respect to the safety status confirmation status transmitted from the autonomously driven vehicles 111, 112.
[0025] The work status receiving program 212 has a work management function 223, and when it receives information from the site manager 130, it uses map data 231 to check which parking area 150 the site manager 130 is in, and updates the work status for the corresponding parking area 150 in the site status management table 233. In this embodiment, it is assumed that the site manager 130 directly inputs the work status, but it is also possible to install a camera or the like in the parking area 150, and based on the information of the site manager detected by the camera, work The status may be notified and the work management function 223 may update the site status management table 233 .
[0026] Vehicle operation program 213 has an autonomous driving start operation receiving function 224, a safety confirmation status checking function 225, and an autonomous driving start instruction function 226, and when it receives a command (operation request) to start an autonomous vehicle from site manager 130 using operation terminal 170, it searches vehicle status management table 232 for the autonomous vehicle to be started, checks the safety confirmation status in vehicle status management table 232, and checks map data 231 to see if the relevant area is a location where starting is permitted and site status management table 233 to see if work is underway to prohibit the starting of autonomous vehicles, thereby determining whether autonomous driving can be started. Vehicle operation program 213 sends this determination result to the autonomous vehicle in question and to operation terminal 170 that sent the command (operation request) to start the autonomous vehicle.
[0027] The map data 231 is data registered in advance in the control center 100, and contains map information within the site, and for each parking area 150, information such as its coordinates and whether it is a location where automatic driving can be started is set.
[0028] The vehicle status management table 232 is updated by the vehicle information reception program 211, and the position, status, and safety confirmation status of the automatically driven vehicle notified from the automatically driven vehicle are set in the vehicle status management table 232.
[0029] The site status management table 233 is updated by the business status receiving program 212, and the presence or absence of work in the parking area 150 notified by the site manager 130 is set.
[0030] 3 shows an example of the hardware configuration of the autonomously driven vehicles 111 and 112. The autonomously driven vehicles 111 and 112 are comprised of a vehicle control system 301, an autonomous driving device 302, a safety confirmation device 303, and an in-vehicle network 310 that connects these devices.
[0031] The vehicle control system 301 is a control system for an autonomous vehicle and controls the autonomous vehicle in accordance with acceleration, deceleration, steering instructions, etc. from the autonomous driving device 302.
[0032] The automatic driving device 302 has a GNSS 308 and a communication device 309. The automatic driving device 302 acquires position information of its own vehicle via the GNSS 308 and communicates with the control center 100 via the communication device 309. The automatic driving device 302 calculates a driving route based on the position of its own vehicle and in accordance with instructions from the control center 100, and issues a control command to the vehicle control system 301. This allows the automatic driving device 302 to start automatic driving in response to a start command from the operation terminal 170. Meanwhile, the automatic driving device 302 periodically transmits information such as the position and speed of its own vehicle to the control center 100. The automatic driving device 302 also transmits information on the surrounding safety confirmation status transmitted from the safety confirmation device 303 to the control center 100.
[0033] The safety confirmation device 303 is composed of a front camera 304, a rear camera 305, a right side camera 306, and a left side camera 307, and is connected to a surrounding environment detection unit 303A that detects information about the surroundings of the autonomously driven vehicle. The safety confirmation device 303 monitors the surroundings of the autonomously driven vehicle, and when the vehicle is stopped, detects people and monitors whether safety confirmation is being performed around the autonomously driven vehicle. The safety confirmation device 303 periodically outputs the monitoring results (i.e., the detection results of the surrounding environment detection unit 303A) to the autonomous driving device 302. While this embodiment describes cameras in four directions, the number and directions of cameras may be changed depending on the size and shape of the autonomously driven vehicle. Furthermore, LIDAR or the like may be used instead of or in addition to the cameras.
[0034] The in-vehicle network 310 is a network for connecting controllers in an autonomous driving vehicle, and uses a CAN (Controller Area Network) or an in-vehicle Ethernet.
[0035] Examples of screens on the operation terminal 170 used by the site manager 130 are shown in Figures 4a, 4b, and 4c. Figure 4a shows the screen displayed when starting to drive an autonomous vehicle. Figure 4b shows the screen displayed when safety checks are confirmed and autonomous driving begins when starting to drive an autonomous vehicle (when the operation is successful). Figure 4c shows the screen displayed when safety checks are insufficient and autonomous driving cannot begin when starting to drive an autonomous vehicle (when an error occurs).
[0036] As shown in Fig. 4a, operation terminal 170 shows the locations and statuses of nearby autonomous vehicles to site manager 130. Furthermore, operation terminal 170 has an I / F for selecting an autonomous vehicle that the site manager wants to start autonomous driving and for issuing a command to start the operation. Fig. 4a shows a situation in which autonomous vehicle 3 is in motion and autonomous vehicle 2 is parked at unloading location D, and indicates that site manager 130 is about to start autonomous driving of autonomous vehicle 2.
[0037] As shown in FIG. 4b, when an attempt is made to start automatic driving after safety confirmation has been performed, the operation terminal 170 displays that automatic driving will start.
[0038] 4c, an error is displayed on the operation terminal 170 when an attempt is made to start autonomous driving in a state where safety confirmation is insufficient. Note that a similar error is displayed if the user mistakenly selects the autonomous vehicle to start autonomous driving, since safety confirmation around the autonomous vehicle has not been performed.
[0039] 5a, 5b, and 5c show the contents of tables managed by the control center 100. Fig. 5a shows the contents of the map data table 231, Fig. 5b shows the contents of the vehicle state management table 232, and Fig. 5c shows the contents of the site state management table 233.
[0040] As shown in FIG. 5A, the map data table 231 includes an area identifier 501, an area name 502, an autonomous driving start possibility 503, and coordinates 504.
[0041] The area identifier 501 is an identifier for uniquely identifying each area.
[0042] The area name 502 indicates the name of each set area, and is used when the control center 100 shows the area to the site manager 130 on a map.
[0043] Autonomous driving start permission 503 indicates whether or not an autonomous driving vehicle may start autonomous driving when parked in each area.
[0044] Coordinates 504 indicate the coordinates for indicating the range of each area. In this embodiment, a polygon is assumed, and the latitude and longitude of each vertex are set as coordinates 504. Note that the area setting is not limited to a polygon, and various setting methods are possible, such as setting an area as a circle using a center point and a radius. For example, loading location A is made up of a rectangle consisting of four points, and the latitude and longitude of each vertex are set as coordinates 504.
[0045] As shown in FIG. 5b, the vehicle status management table 232 includes a vehicle identifier 521, a latitude 522, a longitude 523, a speed 524, a direction of travel 525, a status 526, a location 527, a safety confirmation status 528, a status update time 529, a safety confirmation time 530, an inspection status 531, and an inspection date and time 532.
[0046] The vehicle identifier 521 is an identifier for uniquely identifying an autonomously driven vehicle.
[0047] The latitude 522 and longitude 523 indicate the current location of the autonomous vehicle.
[0048] The speed 524 and the direction of travel 525 indicate the speed at which the autonomous vehicle is traveling and the direction of the vehicle. Note that the direction of travel 525 is indicated, for example, by an angle relative to a reference direction (such as north).
[0049] State 526 indicates the state of the autonomous vehicle. For example, when the autonomous vehicle is traveling toward a destination specified by the control center 100, including when it is temporarily stopped, it is set to "traveling." Immediately after the power is turned on and before receiving instructions from the control center 100, it is set to "stopped." When the autonomous vehicle is making an emergency stop in response to an instruction from the control center 100, it is set to "emergency stop."
[0050] Location 527 indicates the location of the autonomous vehicle. If the autonomous vehicle is in a parking area 150, the area identifier of the parking area 150 is set. If the autonomous vehicle is in any other location, nothing is set.
[0051] The safety confirmation status 528 indicates whether a surrounding safety check has been performed for a stopped autonomous vehicle. If the status 526 is "driving", it is not applicable and "-" is set; otherwise, if a surrounding safety check has been performed, "completed" is set, and if a surrounding safety check has not been performed, "not yet" is set. In addition, if the status is "completed", the direction in which the check has been completed is also set. These settings are input and set from the autonomous driving device 302 to the control center 100 via the communication device 309 when the safety confirmation device 303 of the autonomous vehicle 111 detects that a safety check has been performed. In addition, when the autonomous vehicle starts to drive, the setting is updated to "-", and immediately after the autonomous vehicle stops, the setting is updated to "not yet".
[0052] The state update time 529 indicates the time when the state 526 of the autonomously driven vehicle in question was updated.
[0053] The time when the safety confirmation status 528 of the corresponding autonomously driven vehicle was updated to “completed” is set as the safety confirmation time 530. If the safety confirmation status 528 is other than “completed”, “-” is set.
[0054] Whether or not an inspection of the autonomously driven vehicle has been carried out is set in the inspection status 531. If an inspection has been carried out, "Completed" is set, and if an inspection has not been carried out, "Not yet" is set.
[0055] Inspection date and time 532 is set to the date and time when the inspection of the autonomously driven vehicle was carried out.
[0056] The latitude 522, longitude 523, speed 524, direction of travel 525, status 526, location 527, and status update time 529 are updated by the vehicle information management function 221 of the vehicle information receiving program 211 when information is input from the autonomous vehicle to the control center 100.
[0057] The safety confirmation status 528 and the safety confirmation time 530 are updated by the safety confirmation status update function 222 of the vehicle information receiving program 211 when the autonomously driven vehicle is stopped and information is input from the autonomously driven vehicle to the control center 100.
[0058] As shown in FIG. 5c, the site status management table 233 includes an area identifier 541, an area name 542, an area status 543, and a status update time 544.
[0059] The area identifier 541 is an identifier for uniquely identifying each area such as the parking area 150. Detailed coordinates and the like are managed in the map data table 231.
[0060] The area name 542 indicates the name of each set area, and is used when the control center 100 shows the area to the site manager 130 on a map.
[0061] Area status 543 indicates the status of each area managed by control center 100. For example, "Working" is set, indicating that the site manager 130 is loading or unloading, or "No work" is set, indicating that the site manager 130 is not doing any particular work. When "Working," the start of the autonomous vehicle is suppressed for safety reasons.
[0062] The state update time 544 is set to the time when the area state 543 was updated.
[0063] The area status 543 and status update time 544 are updated by the work management function 223 of the business status receiving program 212 based on notifications to the control center 100 sent from the site (specifically, the operation terminal 170 of the site manager 130) when work is started or finished at the site.
[0064] 6 shows a flowchart of the determination of whether autonomous driving can be started by the safety confirmation status confirmation function 225 of the vehicle operation program 213. This flow is executed when the site manager 130 operates the operation terminal 170, issues an operation request for an autonomous vehicle from the operation terminal 170 (a start command to start autonomous driving), and the control center 100 receives the operation request for an autonomous vehicle from the operation terminal 170 and starts autonomous driving of the autonomous vehicle for which the operation request was made (in other words, starts autonomous driving of the autonomous vehicle in response to a command from the operation terminal 170). When this flow is executed (i.e., when an operation request for an autonomous vehicle is received from the operation terminal 170), it proceeds to STEP 701.
[0065] In STEP 701, for the autonomously driven vehicle for which a request to start autonomous driving has been made, the current location 527 is checked from the vehicle state management table 232, and it is checked whether autonomous driving can be started at the relevant location from the autonomous driving start possibility 503 in the map data table 231. If autonomous driving can be started, the process proceeds to STEP 702, and if autonomous driving cannot be started, the process proceeds to STEP 706.
[0066] In STEP 702, for the autonomously driven vehicle for which a request to start autonomous driving has been made, the inspection status 531 and inspection date and time 532 are checked from the vehicle status management table 232. If the inspection status 531 is "Completed" and the inspection date and time 532 is less than the predetermined inspection interval (for example, whether the inspection date and time 532 is the relevant day), the process proceeds to STEP 703. If the inspection date and time 532 is more than the predetermined inspection interval in the past or the inspection status 531 is "Not yet", the process proceeds to STEP 706.
[0067] In STEP 703, for the autonomously driven vehicle for which a request to start autonomous driving has been made, the safety confirmation status 528 is checked from the vehicle status management table 232. If the safety confirmation status 528 is "Completed", the process proceeds to STEP 704, and if the safety confirmation status 528 is "Not yet" or "-", the process proceeds to STEP 706.
[0068] In STEP 704, for the autonomously driven vehicle for which a request to start autonomous driving has been made, the safety confirmation time 530 is checked from the vehicle state management table 232. If a predetermined threshold or more of time has passed since the safety confirmation time until now (in other words, if the time elapsed since the safety confirmation time is equal to or greater than the predetermined threshold), the timing of the safety confirmation is too old and reconfirmation is necessary, so the process proceeds to STEP 706. If a predetermined threshold or more of time has not passed since the safety confirmation time until now (in other words, if the time elapsed since the safety confirmation time is less than the predetermined threshold), the process proceeds to STEP 705.
[0069] In STEP 705, for the autonomously driven vehicle for which a request to start autonomous driving has been made, an operation start permission signal is generated for the direction confirmed in the safety confirmation status 528 of the vehicle state management table 232 (a permission signal that permits an operation request for the autonomously driven vehicle only in the direction (area) for which safety has been confirmed), and at the same time, a message is generated to the operation terminal 170 notifying the operation terminal 170 that autonomous driving will be started, and this flow ends. The generated operation start permission signal is sent to the autonomously driven vehicle for which the operation request has been made, and the operation start permission signal including the generated message is sent to the operation terminal 170 that issued the operation request (see FIG. 4b). At the same time as sending the generated operation start permission signal to the autonomously driven vehicle, the control center 100 also sends to the autonomously driven vehicle a remote operation instruction for the autonomous vehicle received from the operation terminal 170. The autonomously driven vehicle executes (starts) autonomous driving based on the operation start permission signal sent from the control center 100 and the remote operation instruction (from the operation terminal 170).
[0070] In STEP 706, it is determined that the operation cannot be started due to insufficient safety confirmation, and an error message is generated for the operation terminal 170, and this flow ends. The generated error message is sent to the operation terminal 170 that issued the operation request (see FIG. 4c).
[0071] [Second embodiment] Next, a second embodiment of the present invention will be described with reference to FIGS.
[0072] FIG. 7 shows an example of the hardware configuration of autonomously driven vehicles 111, 112 in the second embodiment. In the second embodiment, instead of monitoring whether a safety check has been performed around the autonomously driven vehicle using a camera or the like, the safety confirmation device 303 displays a one-time password on display units 303B around (outer periphery of) the autonomously driven vehicle, which are front one-time password display unit 314, rear one-time password display unit 315, right side one-time password display unit 316, and left side one-time password display unit 317. The display contents of display unit 303B are notified to control center 100 via autonomous driving device 302 and communication device 309. This one-time password is different for each display direction, and a different one is displayed for each autonomously driven vehicle.
[0073] This one-time password (information displayed on display unit 303B) is read by the operation terminal 170 of the on-site manager 130 who performs safety checks around the autonomous vehicle, and the read information is transmitted from the operation terminal 170 of the on-site manager 130 to the control center 100 (see Figure 8).
[0074] In this embodiment, a one-time password is displayed, but a QR code (registered trademark) that does not overlap with other directions or autonomous driving vehicles may be displayed.
[0075] FIG. 8 shows an example of a screen displayed on the operation terminal 170 used by the site manager 130 when starting to drive an autonomously driven vehicle in the second embodiment.
[0076] The operation terminal 170 shows the location and status of nearby autonomous vehicles to the site manager 130. The operation terminal 170 also has an I / F for selecting an autonomous vehicle that the site manager wants to start autonomous driving and issuing a start instruction. Furthermore, unlike the first embodiment, the operation terminal 170 also has an I / F for inputting one-time passwords displayed in each direction of the autonomous vehicle.
[0077] 9 shows a flowchart of the second embodiment for determining whether autonomous driving can be started by the safety confirmation status confirmation function 225 of the vehicle operation program 213. This flow is executed when the site manager 130 operates the operation terminal 170, issues an operation request for an autonomous vehicle from the operation terminal 170 (a start command to start autonomous driving), and the control center 100 receives the operation request for an autonomous vehicle from the operation terminal 170 and starts autonomous driving of the autonomous vehicle for which the operation request was made (in other words, starts autonomous driving of the autonomous vehicle in response to a command from the operation terminal 170). When this flow is executed (i.e., when a request to operate an autonomous vehicle is received from the operation terminal 170), the flow proceeds to STEP 1001.
[0078] In STEP 1001, for the autonomously driven vehicle for which a request to start autonomous driving has been made, the current location 527 is checked from the vehicle state management table 232, and it is checked whether autonomous driving can be started at the relevant location from the autonomous driving start possibility 503 in the map data table 231. If autonomous driving can be started, the process proceeds to STEP 1002, and if autonomous driving cannot be started, the process proceeds to STEP 1006.
[0079] In STEP 1002, for the autonomously driven vehicle for which a request to start autonomous driving has been made, the inspection status 531 and inspection date and time 532 are checked from the vehicle status management table 232. If the inspection status 531 is "Completed" and the inspection date and time 532 is less than the predetermined inspection interval (for example, whether the inspection date and time 532 is the relevant day), the process proceeds to STEP 1003, and if the inspection date and time 532 is more than the predetermined inspection interval in the past or the inspection status 531 is "Not yet", the process proceeds to STEP 1006.
[0080] In STEP 1003, for an autonomously driven vehicle for which a request to start autonomous driving has been made, information input from operation terminal 170 (in other words, information read by operation terminal 170) is compared with input information such as authentication transmitted from the autonomously driven vehicle. For example, authentication is performed to determine whether the one-time password input from operation terminal 170 matches the one-time password transmitted from the autonomously driven vehicle. If the input information comparison is successful, the process proceeds to STEP 1005; if the input information comparison is unsuccessful, the process proceeds to STEP 1006.
[0081] In STEP 1005, for the autonomously driven vehicle for which a request to start autonomous driving has been made, an operation start permission signal is generated for the direction for which the one-time password authentication has been successful (a permission signal that permits an operation request for the autonomously driven vehicle only in a direction (area) for which safety has been confirmed), and at the same time a message is generated for the operation terminal 170 notifying the operation terminal 170 that autonomous driving will be started, and this flow ends. The generated operation start permission signal is sent to the autonomously driven vehicle for which the operation request has been made, and the operation start permission signal including the generated message is sent to the operation terminal 170 that issued the operation request. Furthermore, at the same time as sending the generated operation start permission signal to the autonomously driven vehicle, the remote operation instruction for the autonomously driven vehicle received from the operation terminal 170 is also sent from the control center 100 to the autonomously driven vehicle. The autonomously driven vehicle executes (starts) autonomous driving based on the operation start permission signal sent from the control center 100 and the remote operation instruction (from the operation terminal 170).
[0082] In STEP 1006, it is determined that the operation cannot be started due to insufficient safety confirmation, and an error message is generated for the operation terminal 170, and this flow ends. The generated error message is sent to the operation terminal 170 that issued the operation request.
[0083] [Third embodiment] Next, a third embodiment of the present invention will be described with reference to FIGS. 10a and 10b.
[0084] The third embodiment illustrates a case in which the site manager 130 remotely controls an autonomous vehicle using the operation terminal 170. When remotely controlling an autonomous vehicle, the site manager 130 uses the operation terminal 170 to issue a request to remotely control the autonomous vehicle to the control center 100. When the control center 100 receives a request to remotely control the autonomous vehicle from the operation terminal 170, it determines whether or not to start remote control (whether or not to permit the request for remote control) based on the implementation status of safety checks around the autonomous vehicle in question, and if it determines that remote control can be started, it notifies the autonomous vehicle that remote control will be started (remote control start permission signal) and notifies the operation terminal 170 that remote control is possible (remote control start permission signal). As a result, the site manager 130 starts remote control on the operation terminal 170. In this case, when the site manager 130 operates the operation terminal 170, the operation terminal 170 issues a remote operation instruction to the autonomously driven vehicle based on the remote operation start permission signal, and the target autonomously driven vehicle executes (starts) autonomous driving based on the remote operation start permission signal transmitted from the control center 100 and the remote operation instruction transmitted from the operation terminal 170. The method of safety confirmation at the control center 100 is the same as in the first or second embodiment, and the screen content of the operation terminal 170 differs so that the autonomously driven vehicle can be remotely controlled.
[0085] 10a and 10b show example screens used by the site manager 130 at the start of remote operation of an autonomously driven vehicle on the operation terminal 170 and during remote operation of the autonomously driven vehicle in the third embodiment. Fig. 10a shows the screen displayed when remote operation is started, and Fig. 10b shows the screen displayed during remote operation after remote operation has been permitted.
[0086] 10a, the operation terminal 170 shows the location and status of nearby autonomous vehicles to the site manager 130. Furthermore, the operation terminal 170 has an I / F for selecting an autonomous vehicle for which remote operation is to be started and issuing a command to start. Note that, as with the second embodiment, this embodiment shows an example screen for confirming the safety of the area around the autonomous vehicle using a one-time password.
[0087] As shown in FIG. 10b, when an attempt is made to start remote control after a safety check has been made, the operation terminal 170 displays operation buttons for remote control. Note that the operation buttons are only available for the direction for which a safety check has been made. This allows remote control only in the direction for which a safety check has been made. The example in FIG. 10b shows a state in which the one-time passwords for the front and right side have been correctly entered, allowing remote control of forward movement and right turns, but not remote control of reverse movement and left turns.
[0088] [Summary of the first to third embodiments] As described above, the control system of this embodiment is a control system that includes an autonomous vehicle, a management device (control center 100) that manages the autonomous vehicle, and an operation terminal 170 that remotely operates the autonomous vehicle. The autonomous vehicle is equipped with a safety confirmation unit (safety confirmation device 303) that checks the safety of the area around the autonomous vehicle, and an autonomous driving unit (autonomous driving device 302) that starts autonomous driving in response to a command from the operation terminal 170. The management device (control center 100) controls the autonomous driving The autonomous vehicle management unit (211, 213) is provided for managing vehicles, and when the autonomous vehicle management unit (211, 213) receives an operation request (to start autonomous driving) for the autonomous vehicle from the operation terminal 170, it transmits a permission signal to the operation terminal 170 and the autonomous vehicle to permit the operation request based on the confirmation results (STEPs 703, 704) of the safety confirmation unit (safety confirmation device 303), and the autonomous vehicle performs autonomous driving based on the permission signal and operation instructions from the operation terminal.
[0089] When the autonomous vehicle management unit (211, 213) receives an operation request for the autonomous vehicle from the operation terminal 170, it sends a permission signal to the operation terminal 170 and the autonomous vehicle to permit the operation request based on the confirmation results (STEPs 703, 704) of the safety confirmation unit (safety confirmation device 303), and also sends the operation instructions received from the operation terminal 170 to the autonomous vehicle, and the autonomous vehicle performs autonomous driving based on the permission signal and the operation instructions sent from the autonomous vehicle management unit (211, 213).
[0090] When the autonomous vehicle management unit (211, 213) receives a request to operate the autonomous vehicle from the operation terminal 170, it sends a permission signal to the operation terminal 170 and the autonomous vehicle to permit the operation request based on the confirmation results (STEPs 703, 704) of the safety confirmation unit (safety confirmation device 303), and the operation terminal 170 issues operation instructions to the autonomous vehicle based on the permission signal, and the autonomous vehicle performs autonomous driving based on the permission signal sent from the autonomous vehicle management unit (211, 213) and the operation instructions sent from the operation terminal 170.
[0091] The permission signal permits the operation request (start of automatic driving) only in an area (direction) where safety has been confirmed by the safety confirmation unit (safety confirmation device 303) (around the automatically driven vehicle).
[0092] The permission signal permits the operation request (start of automatic driving) only when the time elapsed since the safety confirmation time of the safety confirmation unit (safety confirmation device 303) is less than a predetermined threshold value.
[0093] The permission signal permits the operation request (start of autonomous driving) only when an inspection of the autonomous vehicle has been carried out (when the safety of the autonomous vehicle has been confirmed) and the inspection date and time of the autonomous vehicle is less than a predetermined inspection interval.
[0094] The safety confirmation unit (safety confirmation device 303) is equipped with a surrounding environment detection unit 303A that detects information about the surroundings of the autonomously driven vehicle, and the safety confirmation process of the safety confirmation unit (safety confirmation device 303) transmits the detection results of the surrounding environment detection unit 303A to the management device (control center 100).
[0095] The safety confirmation unit (safety confirmation device 303) is equipped with a display unit 303B that displays a predetermined display (QR code (registered trademark), one-time password) on the outer periphery of the autonomously driving vehicle, and the safety confirmation process of the safety confirmation unit (safety confirmation device 303) involves reading the information displayed on the display unit 303B by the operation terminal 170, transmitting the information from the operation terminal 170 to the management device (control center 100), and comparing the information from the operation terminal 170 with the information of the management device (control center 100).
[0096] That is, the control system of this embodiment determines whether safety checks have been performed using on-board cameras that monitor the surroundings of the vehicle, QR codes (registered trademark) set around the vehicle, or one-time passwords, and uses the check results in response to an instruction from the on-site manager to start autonomous driving, thereby preventing the wrong vehicle from starting. Also, the range of permission for autonomous driving and remote control operation is set according to the range of the checks.
[0097] According to this embodiment, the autonomous vehicle detects whether a safety check has been performed around the autonomous vehicle, and by having the autonomous vehicle input information about the surroundings of the autonomous vehicle, it is confirmed that a safety check has been performed, thereby ensuring safety. This ensures that a safety check around the autonomous vehicle is performed reliably, and makes it possible to reduce the risk of a collision at start-up due to a missed check.
[0098] It should be noted that the present invention is not limited to the above-described embodiment and includes various modifications. For example, the above-described embodiment has been described in detail to clearly explain the present invention, and the present invention is not necessarily limited to an embodiment having all of the described configurations.
[0099] Furthermore, the above-described configurations, functions, processing units, processing means, etc. may be partially or entirely implemented in hardware, for example, by designing them as integrated circuits. The above-described configurations, functions, etc. may also be implemented in software, with a processor interpreting and executing a program that implements each function. Information such as the programs, tables, and files that implement each function can be stored in a memory, a storage device such as a hard disk or SSD (Solid State Drive), or a recording medium such as an IC card, SD card, or DVD.
[0100] In addition, the control lines and information lines shown are those that are considered necessary for the explanation, and do not necessarily show all the control lines and information lines in the product. In reality, it can be assumed that almost all components are interconnected. [Explanation of symbols]
[0101] 100 Control Center (Management Device) 111, 112 Autonomous Vehicles 120 Administrator 130 Site Manager 140 Manned Vehicles 150 Parking Area 160 Road 170 Operation terminal 211 Vehicle Information Reception Program (Automated Driving Vehicle Management Department) 212 Business Status Reception Program 213 Vehicle Operation Program (Automated Vehicle Management Department) 221 Vehicle information management function 222 Safety confirmation status update function 223 Work management function 224 Automatic driving start operation receiving function 225 Safety confirmation status confirmation function 226 Automatic driving start instruction function 231 Map data (map data table) 232 Vehicle status management table 233 Site Status Management Table 301 Vehicle Control System 302 Automatic driving device (automatic driving part) 303 Safety Confirmation Device (Safety Confirmation Department) 303A Surrounding environment detection unit 303B Display section 310 In-Vehicle Network
Claims
1. A control system comprising an autonomous vehicle, a management device that manages the autonomous vehicle, and an operation terminal that remotely operates the autonomous vehicle, The autonomously driven vehicle includes a safety confirmation unit that confirms the safety of the surroundings of the autonomously driven vehicle, and an autonomous driving unit that starts autonomous driving in response to a command from the operation terminal, the management device includes an autonomous vehicle management unit that manages the autonomous vehicle, When the autonomous vehicle management unit receives an operation request for the autonomous vehicle from the operation terminal, it transmits a permission signal for permitting the operation request to the operation terminal and the autonomous vehicle based on a confirmation result of the safety confirmation unit, The autonomous driving vehicle performs autonomous driving based on the permission signal and an operation instruction from the operation terminal, A control system characterized in that the permission signal permits the operation request only when an inspection of the autonomous vehicle has been performed and the inspection date and time of the autonomous vehicle is less than a predetermined inspection interval.
2. 2. The control system according to claim 1, When the autonomous vehicle management unit receives an operation request for the autonomous vehicle from the operation terminal, it transmits an authorization signal to the operation terminal and the autonomous vehicle to authorize the operation request based on the confirmation result of the safety confirmation unit, and transmits the operation instruction received from the operation terminal to the autonomous vehicle; A control system characterized in that the autonomous vehicle performs autonomous driving based on the permission signal and the operation instructions transmitted from the autonomous vehicle management unit.
3. 2. The control system according to claim 1, When the autonomous vehicle management unit receives an operation request for the autonomous vehicle from the operation terminal, it transmits a permission signal for permitting the operation request to the operation terminal and the autonomous vehicle based on a confirmation result of the safety confirmation unit, the operation terminal issues an operation instruction to the autonomously driven vehicle based on the permission signal; A control system characterized in that the autonomous vehicle performs autonomous driving based on the permission signal transmitted from the autonomous vehicle management unit and the operation instructions transmitted from the operation terminal.
4. 2. The control system according to claim 1, A control system characterized in that the permission signal permits the operation request only in an area where safety has been confirmed by the safety confirmation unit.
5. 2. The control system according to claim 1, A control system characterized in that the permission signal permits the operation request only when the elapsed time from the safety confirmation time of the safety confirmation unit is less than a predetermined threshold.
6. 2. The control system according to claim 1, The safety confirmation unit includes a surrounding environment detection unit that detects information about the surroundings of the autonomous driving vehicle, A control system characterized in that the safety confirmation processing of the safety confirmation unit transmits the detection result of the surrounding environment detection unit to the management device.
7. 2. The control system according to claim 1, the safety confirmation unit includes a display unit that displays a predetermined display on an outer periphery of the autonomously driven vehicle, A control system characterized in that the safety confirmation processing of the safety confirmation unit reads the information displayed on the display unit by the operation terminal, transmits the information from the operation terminal to the management device, and compares the information from the operation terminal with the information of the management device.
8. A management method for managing an autonomous vehicle that starts autonomous driving in response to a command from an operation terminal that remotely operates the autonomous vehicle, a safety confirmation step of confirming safety around the autonomous driving vehicle; a transmission step of transmitting, when an operation request for the autonomously driven vehicle is received from the operation terminal, an authorization signal for authorizing the operation request to the operation terminal and the autonomously driven vehicle based on a confirmation result of the safety confirmation step; an autonomous driving execution step of executing autonomous driving of the autonomously driven vehicle based on the permission signal and an operation instruction from the operation terminal, A management method characterized in that the permission signal permits the operation request only when an inspection of the autonomous vehicle has been performed and the inspection date and time of the autonomous vehicle is less than a predetermined inspection interval.
9. A management program for managing an autonomous vehicle that starts autonomous driving in response to a command from an operation terminal that remotely operates the autonomous vehicle, A management program that causes a computer to execute a procedure in which, when a request to operate the autonomous vehicle is received from the operation terminal, a permission signal that permits the operation request is sent to the operation terminal and the autonomous vehicle based on the results of confirmation that the autonomous vehicle is safe, and the permission signal is sent only if an inspection of the autonomous vehicle has been performed and the inspection date and time of the autonomous vehicle is less than a predetermined inspection interval.
Citation Information
Patent Citations
Safety device for construction machine
JP2004092347A
Drive assist system
JP2017102519A
Vehicle and control method
JP2019209737A
Remote monitoring system, vehicle control device, remote monitoring method, and vehicle control method
JP2022008586A
Vehicle traveling control method and vehicle traveling control device
WO2020121009A1