Processing method, operating system, processing device, and processing program

The method balances performance and safety in vehicle operation by predicting future road user behavior, setting performance and safety ranges, ensuring optimal vehicle performance without unreasonable risks.

JP7790559B2Active Publication Date: 2025-12-23DENSO CORP
View PDF 4 Cites 0 Cited by

Patent Information

Application Number
JP2024511799
Authority / Receiving Office
JP · JP
Patent Type
Patents
Current Assignee / Owner
Priority Date
2022-04-01
Filing Date
2023-03-16
Publication Date
2025-12-23
Estimated Expiration
2043-03-16

AI Technical Summary

Technical Problem

Existing technologies prioritize either performance or safety in predicting the motion trajectory of objects relative to a vehicle, leading to potential impairment of the vehicle's original target performance and unreasonable risks.

Method used

A processing method that balances performance and safety by predicting future behavior of other road users to achieve target performance while ensuring reasonably foreseeable safety, using separate predictions for performance achievement and safety assurance ranges.

Benefits of technology

Achieves a balance between performance and safety by setting performance achievement and safety ranges, allowing the vehicle to operate within acceptable risk boundaries while optimizing fuel economy, passenger comfort, and other performance metrics.

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure 0007790559000001
    Figure 0007790559000001
  • Figure 0007790559000002
    Figure 0007790559000002
  • Figure 0007790559000003
    Figure 0007790559000003
Patent Text Reader

Abstract

In order to execute a process relating to operation of a host moving body, a processing method executed by a processor includes: performance achievement prediction for predicting future behavior of another road user in an environment external to the host moving body, as a prediction for achieving target performance in the host moving body; operation planning for planning operation of the host moving body in accordance with the performance achievement prediction; safety-ensuring prediction for predicting the future behavior of the other road user in the external environment independently from the performance achievement prediction, as a prediction for ensuring reasonably foreseeable safety in the host moving body; and operation monitoring for monitoring operation of the host moving body in accordance with the safety-ensuring prediction.
Need to check novelty before this filing date? Find Prior Art

Description

CROSS-REFERENCE TO RELATED APPLICATIONS

[0001] This application is based on Patent Application No. 2022-61926 filed in Japan on April 1, 2022, and the contents of the original application are incorporated by reference in their entirety. [Technical Field]

[0002] The present disclosure relates to techniques for performing processing related to the operation of a host vehicle. [Background technology]

[0003] The technology disclosed in Patent Document 1 predicts the motion trajectory of an object that is a user of another road relative to a vehicle that is a host moving body, and uses the predicted motion trajectory for driving planning and driving monitoring of the vehicle. [Prior art documents] [Patent documents]

[0004] [Patent Document 1] U.S. Patent Application Publication No. 2021 / 0009121 Summary of the Invention

[0005] However, in the technology disclosed in Patent Document 1, the object's motion trajectory is predicted using a common model that prioritizes safety for both driving planning and driving monitoring, which raises concerns that the vehicle's original target performance may be impaired. Therefore, if predictions that prioritize target performance were to be executed, there is a concern that unreasonable risks may be introduced.

[0006] An object of the present disclosure is to provide a processing method that balances performance and safety. Another object of the present disclosure is to provide an operating system that balances performance and safety. Yet another object of the present disclosure is to provide a processing device that balances performance and safety. Yet another object of the present disclosure is to provide a processing program that balances performance and safety.

[0007] The technical means of the present disclosure for solving the problems will be described below.

[0008] A first aspect of the present disclosure is A processing method executed by a processor to perform processing related to driving of a host vehicle, comprising: a performance achievement prediction that predicts future behavior of other road users in the external environment of the host mobile body as a prediction for achieving a target performance in the host mobile body; an operation plan for planning the operation of the host mobile body according to the performance achievement prediction; a safety assurance prediction that predicts the future behavior of other road users in the external environment independently from the performance achievement prediction as a prediction for ensuring reasonably foreseeable safety in the host mobile body; Driving monitoring that monitors the driving of the host mobile body according to safety assurance prediction. fruit, Performance achievement predictions are: a process of setting a performance achievement range (Rp) which is a range of future behavior for achieving target performance including at least one of fuel economy performance, passenger ride comfort performance, vibration damping performance, relaxation performance, and express performance using a future behavior prediction of other road users; Safety assurance predictions are This includes the process of setting the boundary of the safety range (Rs), which is the range within which risks that are judged to be unacceptable in the situation in which the host mobile body is placed, are predicted to occur using the future behavior predictions of other road users. nothing.

[0009] A second aspect of the present disclosure is A driving system having a processor and performing processing related to driving of a host mobile object, The processor a performance achievement prediction that predicts future behavior of other road users in the external environment of the host mobile body as a prediction for achieving a target performance in the host mobile body; an operation plan for planning the operation of the host mobile body according to the performance achievement prediction; a safety assurance prediction that predicts the future behavior of other road users in the external environment independently from the performance achievement prediction as a prediction for ensuring reasonably foreseeable safety in the host mobile body; and monitoring the operation of the host mobile body according to the safety assurance prediction. death, Performance achievement predictions are: a process of setting a performance achievement range (Rp) which is a range of future behavior for achieving target performance including at least one of fuel economy performance, passenger ride comfort performance, vibration damping performance, relaxation performance, and express performance using a future behavior prediction of other road users; Safety assurance predictions are This includes a process for setting the boundary of the safety range (Rs), which is the range within which risks that are judged to be unacceptable in the situation in which the host mobile unit is placed, are predicted to occur using predictions of future behavior of other road users. It is configured as follows.

[0010] A third aspect of the present disclosure is A processing device having a processor, configured to be mountable on a host vehicle, and performing processing related to operation of the host vehicle, The processor a performance achievement prediction that predicts future behavior of other road users in the external environment of the host mobile body as a prediction for achieving a target performance in the host mobile body; an operation plan for planning the operation of the host mobile body according to the performance achievement prediction; a safety assurance prediction that predicts the future behavior of other road users in the external environment independently from the performance achievement prediction as a prediction for ensuring reasonably foreseeable safety in the host mobile body; and monitoring the operation of the host mobile body according to the safety assurance prediction. death, Performance achievement predictions are: a process of setting a performance achievement range (Rp) which is a range of future behavior for achieving target performance including at least one of fuel economy performance, passenger ride comfort performance, vibration damping performance, relaxation performance, and express performance using a future behavior prediction of other road users; Safety assurance predictions are This includes a process for setting the boundary of the safety range (Rs), which is the range within which risks that are judged to be unacceptable in the situation in which the host mobile unit is placed, are predicted to occur using predictions of future behavior of other road users. It is configured as follows.

[0011] A fourth aspect of the present disclosure is A processing program including instructions stored in a storage medium and executed by a processor to perform processing related to driving of a host vehicle, a performance achievement prediction that predicts future behavior of other road users in the external environment of the host mobile body as a prediction for achieving a target performance in the host mobile body; an operation plan for planning the operation of the host mobile body according to the performance achievement prediction; a safety assurance prediction that predicts the future behavior of other road users in the external environment independently from the performance achievement prediction as a prediction for ensuring reasonably foreseeable safety in the host mobile body; and operation monitoring, which monitors the operation of the host mobile body according to the safety assurance prediction. fruit, Performance achievement predictions are: a process of setting a performance achievement range (Rp) which is a range of future behavior for achieving target performance including at least one of fuel economy performance, passenger ride comfort performance, vibration damping performance, relaxation performance, and express performance using a future behavior prediction of other road users; Safety assurance predictions are This includes the process of setting the boundary of the safety range (Rs), which is the range within which risks that are judged to be unacceptable in the situation in which the host mobile body is placed, are predicted to occur using the future behavior predictions of other road users. nothing.

[0012] In the host mobile bodies of the first to fourth aspects, a driving plan is executed according to a performance achievement prediction that predicts the future behavior of other road users in the host mobile body's external environment as a prediction for achieving target performance. Therefore, in the host mobile bodies of the first to fourth aspects, driving monitoring is executed according to a safety assurance prediction that predicts the future behavior of other road users independently of the performance achievement prediction as a prediction for ensuring reasonably foreseeable safety. This allows the host mobile body's driving, planned according to the performance achievement prediction, to be monitored according to the safety assurance prediction, thereby achieving a balance between performance and safety for the driving. [Brief explanation of the drawings]

[0013] [Figure 1] FIG. 1 is a block diagram showing the physical architecture of a driving system according to a first embodiment. [Figure 2] FIG. 2 is a schematic diagram showing a traveling environment of a host vehicle to which the first embodiment is applied. [Figure 3] FIG. 2 is a block diagram showing the functional architecture of the driving system according to the first embodiment. [Figure 4] FIG. 2 is a schematic diagram for explaining a performance achievement range and a safety range according to the first embodiment. [Figure 5] FIG. 2 is a schematic diagram for explaining a performance achievement range and a safety range according to the first embodiment. [Figure 6] 3 is a flowchart showing a processing flow according to the first embodiment. [Figure 7] 10 is a characteristic table for explaining performance achievement prediction and safety assurance prediction according to the first embodiment. [Figure 8] FIG. 10 is a block diagram showing the functional architecture of an operation system according to a second embodiment. [Figure 9]10 is a flowchart showing a processing flow according to a second embodiment. [Figure 10] FIG. 10 is a block diagram showing the functional architecture of a driving system according to a third embodiment. [Figure 11] 10 is a flowchart showing a processing flow according to a third embodiment. DETAILED DESCRIPTION OF THE INVENTION

[0014] Hereinafter, multiple embodiments of the present disclosure will be described with reference to the drawings. Note that corresponding components in each embodiment are designated by the same reference numerals, and redundant description may be omitted. Furthermore, when only a portion of a configuration is described in each embodiment, the configuration of another previously described embodiment may be applied to the remaining portions of the configuration. Furthermore, in addition to the combinations of configurations explicitly stated in the description of each embodiment, configurations of multiple embodiments may be partially combined together even if not explicitly stated, provided that there is no particular problem with the combination.

[0015] (First embodiment) 1 includes a processing system 1 for performing processing related to the driving of a host vehicle (hereinafter referred to as driving processing). Part or all of the driving system DS is mounted on the host vehicle.

[0016] The host moving object that is the target of driving processing in the driving system DS is the host vehicle 2 shown in FIG. 2. The host vehicle 2 is a road user capable of performing automated driving, such as an automobile or truck. The host vehicle 2 may also be referred to as an ego-vehicle. Driving in the host vehicle 2 is classified into levels according to the range of tasks performed by the driver, who is the occupant in the driver's seat, among all dynamic driving tasks (DDTs). Here, the driver who can perform the DDTs by manually operating the host vehicle 2 according to the automated driving level is the vehicle operator, and can also be said to be the vehicle user.

[0017] Automated driving levels are specified in, for example, SAE J3016. Specifically, at levels 0 to 2, the driver performs some or all of the DDT. Levels 0 to 2 may be classified as so-called manual driving. Level 0 indicates that driving is not automated. Level 1 indicates that the driving system DS assists the driver. Level 2 indicates that driving is partially automated. At levels 3 and above, the driving system DS performs all of the DDT while engaged. Levels 3 to 5 may be classified as so-called automated driving. A driving system DS capable of driving at level 3 or above may be called an automated driving system. Level 3 indicates that driving is conditionally automated. Level 4 indicates that driving is highly automated. Level 5 indicates that driving is fully automated. A driving system DS that cannot perform driving at level 3 or above and can perform driving at least one of levels 1 and 2 may be called a driving assistance system. In the following, unless there are circumstances that specify the maximum achievable level of automated driving, the automated driving system or the driver assistance system is considered to be included in the driving system DS.

[0018] Other road users 3 for such a host vehicle 2 are road users other than the host vehicle 2 who exist in the external environment in which the host vehicle 2 travels. The other road users 3 include non-vulnerable road users such as cars, trucks, motorcycles, and bicycles, and vulnerable road users such as pedestrians. The other road users 3 may also include animals.

[0019] 1, the driving system DS has as its physical components an actuator system 4, a sensor system 5, a communication system 6, a map database (DB) 7, an information interface (IF) system 8, and a processing system 1. However, the driving system DS only needs to include at least the processing system 1 as its own physical components, and at least one of the physical components belonging to the actuator system 4, the sensor system 5, the communication system 6, the map DB 7, and the information IF system 8 may be replaced by a physical component belonging to the host vehicle 2.

[0020] The actuator system 4 is configured to be able to control the operation of the host vehicle 2 based on an input control signal. The actuator system 4 may be at least one type of power train actuator, such as an internal combustion engine or a motor-generator-motor. The actuator system 4 may be at least one type of braking actuator, such as a brake unit. The actuator system 4 may be at least one type of steering actuator, such as a power steering unit.

[0021] The sensor system 5 acquires sensor data that can be used by the driving system DS by detecting the external and internal environments of the host vehicle 2. To this end, the sensor system 5 includes an external environment sensor 50 and an internal environment sensor 52.

[0022] The external environment sensor 50 may detect targets present in the external environment of the host vehicle 2. The target detection type external environment sensor 50 is, for example, at least one of a camera, LiDAR (light detection and ranging / laser imaging detection and ranging), laser radar, millimeter-wave radar, ultrasonic sonar, etc. The target detection type external environment sensor 50 is typically implemented by combining multiple types of sensors so as to be able to sense the front, side, and rear directions of the host vehicle 2. The external environment sensor 50 may detect the atmospheric conditions in the external environment of the host vehicle 2. The atmospheric detection type external environment sensor 50 is, for example, at least one of an outside air temperature sensor, a humidity sensor, etc.

[0023] The internal environment sensor 52 may detect a specific physical quantity related to vehicle motion (hereinafter referred to as a motion physical quantity) in the internal environment of the host vehicle 2. The motion physical quantity detection type internal environment sensor 52 is, for example, at least one of a speed sensor, an acceleration sensor, a gyro sensor, etc. The internal environment sensor 52 may detect the state of an occupant riding in the internal environment of the host vehicle 2. The occupant detection type internal environment sensor 52 is, for example, at least one of an actuator sensor, a Driver Status Monitor (registered trademark), a biological sensor, a seating sensor, an in-vehicle equipment sensor, etc. Here, the actuator sensor may be, for example, at least one of a start switch, an accelerator sensor, a brake sensor, a steering sensor, etc., which detect the operating state of the occupant related to the actuator system 4 of the host vehicle 2.

[0024] The communication system 6 acquires communication data usable in the driving system DS via wireless communication. The communication system 6 may receive positioning signals from satellites of a global navigation satellite system (GNSS) present in the external environment of the host vehicle 2. The positioning-type communication system 6 is, for example, a GNSS receiver. The communication system 6 may transmit and receive communication signals to and from a V2X system present in the external environment of the host vehicle 2. The V2X communication-type communication system 6 is, for example, at least one of a dedicated short range communications (DSRC) communication device and a cellular V2X (C-V2X) communication device. Here, V2X communication may include at least one of communication with a communication system of another vehicle (another road user 3) (V2V), communication with infrastructure equipment such as a communication device installed in a traffic light (V2I), communication with a mobile terminal of a pedestrian (another road user 3) (V2P), and communication with a cloud network or a mesh network (V2N). The communication system 6 may transmit and receive communication signals to and from a mobile terminal present in the internal environment of the host vehicle 2. The terminal communication type communication system 6 is at least one of, for example, a Bluetooth (registered trademark) device, a Wi-Fi (registered trademark) device, and an infrared communication device.

[0025] The map DB 7 stores map data that can be used by the driving system DS. The map DB 7 includes at least one type of non-transitory tangible storage medium, such as a semiconductor memory, a magnetic medium, or an optical medium. The map DB 7 may be a DB of a locator that estimates the host vehicle 2's own state quantity, including its own position. The map DB may be a DB of a navigation unit that navigates the host vehicle 2's driving route. The map DB 7 may be constructed by combining multiple types of DBs.

[0026] The map DB 7 acquires and stores the latest map data, for example, via V2X communication with an external center via the communication system 6. The map data is two-dimensional or three-dimensional data representing the driving environment of the host vehicle 2. High-precision digital map data may be used as the three-dimensional map data. The map data may include road data representing at least one of the following: position coordinates, shape, and road surface condition of road structures. The map data may also include marking data representing at least one of the following: position coordinates and shape of road signs, road markings, and lane markings attached to roads. The marking data included in the map data may represent landmarks, such as traffic signs, arrow markings, lane markings, stop lines, directional signs, landmark beacons, rectangular signs, business signs, or changes in road line patterns. The map data may also include structure data representing at least one of the following: position coordinates and shape of buildings and traffic lights facing the road. The marking data included in the map data may represent landmarks such as street lights, road edges, reflectors, poles, or the backs of road signs.

[0027] The information IF system 8 mediates the transmission of notification information related to driving processing between the driving system DS and occupants including the driver of the host vehicle 2. For this purpose, the information IF system 8 includes an HMI (human machine interface) device 80.

[0028] The HMI device 80 may be configured to be capable of detecting an operation for inputting the intention of an occupant in the host vehicle 2 to the driving system DS. The operation detection type HMI device 80 is, for example, at least one type of device selected from the group consisting of a push switch, a lever switch, and a touch panel. The operation detection type HMI device 80 may be replaced by an actuator sensor or the like serving as the internal environment sensor 52 in the sensor system 5. The HMI device 80 may be configured to be capable of detecting a gesture for inputting the intention of an occupant in the host vehicle 2 to the driving system DS. The gesture detection type HMI device 80 may be replaced by a driver status monitor or the like serving as the internal environment sensor 52 in the sensor system 5.

[0029] The HMI device 80 may present notification information by stimulating the vision of the occupant in the host vehicle 2. The visual information presentation type HMI device 80 is, for example, at least one of a head-up display (HUD), a center information display (CID), a multifunction display (MFD), a combination meter, a navigation unit, and an illumination unit. The HMI device 80 may present notification information by stimulating the auditory sense of the occupant. The auditory information presentation type HMI device 80 is, for example, at least one of a speaker, a buzzer, and a vibration unit. The HMI device 80 may present notification information by stimulating the cutaneous sense of the occupant. The cutaneous information presentation type HMI device 80 is, for example, at least one of a steering wheel vibration unit, a driver's seat vibration unit, a steering wheel reaction force unit, an accelerator pedal reaction force unit, a brake pedal reaction force unit, and an air conditioning unit.

[0030] The processing system 1 is connected to an actuator system 4, a sensor system 5, a communication system 6, a map DB 7, and an information IF system 8 via at least one of, for example, a LAN (local area network), a wire harness, an internal bus, and a wireless communication line. The processing system 1 is configured to include at least one dedicated computer.

[0031] The dedicated computer constituting the processing system 1 may be an integration ECU (electronic control unit) that integrates the driving control of the host vehicle 2. The dedicated computer constituting the processing system 1 may be a detection ECU that processes sensor data detected in the driving control of the host vehicle 2. The dedicated computer constituting the processing system 1 may be a recognition ECU that performs recognition in the driving control of the host vehicle 2. The dedicated computer constituting the processing system 1 may be a judgment ECU or a planning ECU that judges and plans DDT in the driving control of the host vehicle 2. The dedicated computer constituting the processing system 1 may be a monitoring ECU that monitors the driving control of the host vehicle 2. The dedicated computer constituting the processing system 1 may be an evaluation ECU that evaluates the driving control of the host vehicle 2.

[0032] The dedicated computer constituting the processing system 1 may be a navigation ECU that navigates the driving route of the host vehicle 2. The dedicated computer constituting the processing system 1 may be a locator ECU that estimates the host vehicle 2's own state quantities including its own position. The dedicated computer constituting the driving system DS may be an actuator ECU that controls the actuator system 4. The dedicated computer constituting the processing system 1 may be an HCU (HMI control unit) that controls the HMI device 80. The dedicated computer constituting the processing system 1 may be a storage ECU that controls data storage. The dedicated computer constituting the processing system 1 may be at least one external computer that constitutes, for example, an external center or a mobile terminal that can communicate via the communication system 6.

[0033] The dedicated computer constituting the processing system 1 has at least one memory 10 and one processor 12. The memory 10 is at least one type of non-transitory tangible storage medium, such as a semiconductor memory, a magnetic medium, or an optical medium, that non-temporarily stores computer-readable programs, data, etc. The processor 12 includes at least one type of core, such as a central processing unit (CPU), a graphics processing unit (GPU), or a reduced instruction set computer (RISC)-CPU.

[0034] The memory 10 may be a storage device that selects and stores at least one type of data and information processed in the driving system DS. The memory 10 may be a volatile storage medium such as a RAM (random access memory) that temporarily stores at least one type of data and information processed in the driving system DS. The memory 10 may be a database for executing the DDT in the driving system DS.

[0035] The memory 10 may be mounted on a board in a non-removable and non-replaceable manner, such as an embedded multimedia card (eMMC) using a flash memory. The memory 10 may be configured to be removable and replaceable, such as an SD card. The memory 10 may be integrated into a single chip, together with the processor 12 and an input / output interface, to form a dedicated computer that constitutes the processing system 1, as a system on a chip (SoC).

[0036] The processor 12 executes a plurality of instructions included in a processing program stored as software in the memory 10. As a result, the driving system DS including the processing system 1 constructs a plurality of functional blocks for performing driving processing of the host vehicle 2. In this way, in the driving system DS, the processing program stored in the memory 10 causes the processor 12 to execute a plurality of instructions to perform driving processing of the host vehicle 2 mainly using the processing system 1, thereby constructing a plurality of functional blocks. The plurality of functional blocks constructed in the driving system DS in this way include a recognition block 100, a judgment block 120, a monitoring block 140, and a control block 160, which are shown as a functional architecture in FIG. 3.

[0037] The recognition block 100 acquires sensor data from the sensor system 5. The recognition block 100 acquires communication data from the communication system 6. The recognition block 100 acquires map data from the map DB 7. The recognition block 100 processes these acquired data individually and then fuses them to recognize the interior and exterior environments of the host vehicle 2.

[0038] In generating the recognition information, the recognition block 100 acquires data from the sensor system 5, the communication system 6, and the map DB 7, interprets the meaning of the acquired data, and recognizes the external environment of the host vehicle 2, its own situation in that environment, and the internal and external environment including the internal environment of the host vehicle 2 by fusing the acquired data. By recognizing the internal and external environments, the recognition block 100 generates recognition information to be provided to the subsequent decision block 120 and monitoring block 140. The recognition block 100 may provide substantially the same recognition information to the decision block 120 and the monitoring block 140. The recognition block 100 may also provide different recognition information to the decision block 120 and the monitoring block 140.

[0039] The recognition information generated by the recognition block 100 describes the state detected for each scene in the driving environment of the host vehicle 2. The recognition block 100 may generate the recognition information of an object by detecting an object, including other road users 3, obstacles, and structures, in the external environment of the host vehicle 2. The object recognition information may represent at least one of the following: distance, direction of movement, relative speed, relative acceleration, size, and estimated state based on tracking detection. The object recognition information may represent a classification of the object, recognized based on the state of the object clustered by semantic segmentation or the like. The recognition block 100 may generate the recognition information of the road by detecting the road along which the host vehicle 2 will currently and in the future travel. The recognition information of the road may represent at least one static structure, such as a road surface, a lane, a road edge, and free space.

[0040] The recognition block 100 may generate recognition information of the host vehicle's own state quantity by localization, which estimates the host vehicle's own state quantity including its own position. The recognition block 100 may generate update data for map data related to the host vehicle's route simultaneously with the recognition information of the host vehicle's own state quantity and feed the update data back to the map DB 7. The recognition block 100 may generate recognition information of the marking by detecting a marking associated with the host vehicle's route. The recognition information of the marking may represent the status of at least one type of sign, lane marking, traffic light, etc. The recognition information of the marking may further represent a traffic rule recognized or identified from the status of the marking. The recognition block 100 may generate recognition information of the weather conditions by detecting the weather conditions for each scene in which the host vehicle 2 travels. The recognition block 100 may generate recognition information of the weather conditions by detecting the time for each scene in which the host vehicle 2 travels.

[0041] The decision block 120 acquires recognition information from the recognition block 100. The decision block 120 may acquire past driving control information from the subsequent control block 160. The decision block 120 may acquire safety assurance information, which will be described later, from the monitoring block 140. The decision block 120 includes a performance achievement prediction block 122 and an operation planning block 124 as sub-functional blocks for planning the operation of the host vehicle 2 in accordance with predictions based on the acquired information.

[0042] The performance achievement prediction block 122 predicts, in a time series, the future behavior of the other road user 3 in the external environment of the host vehicle 2. At this time, the performance achievement prediction block 122 performs performance achievement prediction regarding the future behavior of the other road user 3 as a prediction for achieving target performance in the host vehicle 2 through the subsequent operation planning block 124. The future behavior for which performance achievement prediction is performed may include risky behavior of the other road user 3 that is foreseeable as a potential risk between the host vehicle 2 and the other road user 3. The future behavior for which performance achievement prediction is performed may be the future trajectory of the other road user 3. Here, the future trajectory may be predicted to be performance achievement so as to define, in a time series, at least one type of physical quantity of motion related to the other road user 3, for example, position, speed, acceleration, yaw rate, and direction of motion.

[0043] In order to perform such performance achievement prediction, the performance achievement prediction block 122 may be constructed by at least one of a dedicated computer mounted on the host vehicle 2 and a dedicated computer external to the host vehicle 2. The performance achievement prediction block 122 is constructed by a dedicated computer that is physically common to the operation planning block 124, but may also be constructed by a dedicated computer that is physically separate from the operation planning block 124. The performance achievement prediction block 122 is constructed by a dedicated computer that is physically separate from the recognition block 100, or may also be constructed by a dedicated computer that is physically common to the recognition block 100.

[0044] The performance achievement prediction block 122 may interpret the driving environment, which is the situation of the host vehicle 2, as a basic process for making the performance achievement prediction. In this case, the performance achievement prediction block 122 may interpret the intention and behavior based on the classification of the other road user 3, which is a dynamic object, or may interpret a classifiable driving situation. Here, the interpretation of the intention and behavior of the other road user 3 may be an interpretation of an action probability depending on the intention of the other road user 3, such as a lane change probability. The interpretation of the driving situation may be an interpretation of traffic rules, a traffic congestion situation, etc. Such an environment interpretation, which is the basis for the performance achievement prediction, may be at least partially executed by the recognition block 100, and the interpretation result as recognition information may be provided to the performance achievement prediction block 122.

[0045] The performance achievement prediction block 122 may perform performance achievement prediction using a statistical model that models a positive risk balance based on a risk-benefit assessment in a social traffic environment (hereinafter, the statistical model of the positive risk balance will be specifically referred to as a risk balance model). The risk balance model may be designed based on social requirements such as statistical data representing the contribution and / or probability distribution of actions that can reduce accident risk, and traffic rules, in order to avoid the risk of unreasonable blaming (i.e., potential accident liability of other road users 3). The risk balance model may be designed as a road user behavior model that is unique to each location in the traffic environment where the road user can travel. Such a risk balance model may be constructed in at least one form, for example, a mathematical model that formulates social requirements, a computer program that executes processing in accordance with the mathematical model, or the like. Therefore, the parameters of the risk balance model may be tuned based on past driving control information by the control block 160.

[0046] Based on the prediction information acquired as a result of the performance achievement prediction, the performance achievement prediction block 122 sets a range of future behavior (hereinafter referred to as the performance achievement range) Rp for achieving the target performance of the host vehicle 2, as illustrated in FIGS. 4 and 5. In other words, the performance achievement prediction can be said to be a prediction of future behavior regarding the other road user 3 for setting the performance achievement range Rp so as to provide the vehicle motion necessary to achieve the target performance. Therefore, the performance achievement prediction block 122 shown in FIG. 3 may select an emphasized target performance from among multiple performances regarding the host vehicle 2 for each scene in which the performance achievement range Rp is set in accordance with the prediction information from the performance achievement prediction. The performance achievement prediction block 122 may fix a single specific performance regarding the host vehicle 2 as the target performance.

[0047] The target performance for which the performance achievement range Rp is set may be a safety performance that is determined to be statistically and socially safe for the host vehicle 2. Here, the safety performance may be determined based on the risk balance model used for the performance achievement prediction.

[0048] The target performance for which the performance achievement range Rp is set may be fuel economy performance determined according to the energy saving expected of the host vehicle 2. Here, fuel economy performance may be defined as a concept that includes power consumption performance. The fuel economy performance may be determined using a statistical model that is modeled based on, for example, evaluation data of actual fuel economy in society.

[0049] The target performance for which the performance achievement range Rp is set may be a safety performance required for the host vehicle 2, such as at least one of passenger ride comfort performance and vibration damping performance in a service vehicle. Here, the safety performance may be determined using a statistical model based on, for example, social market research data.

[0050] The target performance for which the performance achievement range Rp is set may be a service performance required of the host vehicle 2, such as at least one of relaxation performance for a tourist service vehicle and express performance for a delivery service vehicle. Here, the service performance may be determined using a statistical model based on, for example, accumulated data for each service provider that operates service vehicles in society.

[0051] The performance achievement prediction block 122 sets a performance achievement range Rp for such target performance. The performance achievement range Rp may be set as an allowable range of physical quantities of motion for providing the host vehicle 2 with the vehicle motion required to achieve the target performance, based on the risk balance model or statistical model used to select the target performance. Here, the physical quantities of motion that define the allowable range that becomes the performance achievement range Rp are at least one of the following, which serve as the basis for a driving plan in the subsequent driving plan block 124: the speed, acceleration, attitude angle, and separation distance from other road users 3 of the host vehicle 2 (FIGS. 4 and 5 show an example of acceleration). The setting of such a performance achievement range Rp may be performed by the driving plan block 124 prior to the driving plan described below.

[0052] The performance achievement prediction block 122 may output at least one of the prediction information acquired as described above and the setting information of the set performance achievement range Rp as performance achievement information to the memory 10. The memory 10 to which the performance achievement information is output may be mounted in the host vehicle 2 or may be installed outside the host vehicle 2, for example, at an external center, depending on the type of dedicated computer that constitutes the driving system DS. The output performance achievement information may be temporarily stored in the memory 10 and provided to the operation planning block 124. The output performance achievement information may be stored as evidence information and accumulated in the memory 10. The output performance achievement information may be read from the memory 10, which serves as a temporary storage destination or a storage destination as evidence information, and transmitted to an external center or the like outside the host vehicle 2 via the communication system 6.

[0053] The performance achievement information serving as evidence information may be stored in an unencrypted state, or may be encrypted or hashed and stored. The performance achievement information serving as evidence information may be stored in the memory 10 in association with behavior information that represents the actual behavior of the host vehicle 2 as past driving control information by the control block 160. The performance achievement information thus stored may be utilized as a lagging indicator for training a risk balance model that serves as a prediction model for performance achievement prediction, or may be utilized as a leading indicator for verifying and validity evaluation of the risk balance model.

[0054] The operation planning block 124 plans operation of the host vehicle 2 in accordance with the performance achievement prediction and the performance achievement range Rp by the performance achievement prediction block 122. Therefore, the operation planning block 124 makes an operation plan based on the performance achievement information provided by the performance achievement prediction block 122.

[0055] The driving planning block 124 plans a route that the host vehicle 2 will travel in the future by driving control. That is, the driving planning block 124 realizes a DDT function that plans a route as a strategic function of the host vehicle 2. The driving planning block 124 may plan at least one of a route to a destination and a lane based on recognition information that estimates the self-position of the host vehicle 2. In this case, the driving planning block 124 may plan at least one of a lane change request and a deceleration request based on the planned lane.

[0056] The driving planning block 124 plans future behavior of the host vehicle 2 based on the planned route and lanes as well as the performance achievement information from the performance achievement prediction block 122. That is, the driving planning block 124 realizes a DDT function that plans the tactical behavior of the host vehicle 2. The behavior planning function of the driving planning block 124 may include a function to generate transition conditions related to state transitions of the host vehicle 2. The transition conditions related to state transitions of the host vehicle 2 may correspond to triggering conditions. Therefore, the behavior planning function may include a function to determine state transitions of applications that realize DDT, and further state transitions of driving behaviors, based on the generated transition conditions.

[0057] The operation planning block 124 plans a future trajectory to be given to the host vehicle 2 along the planned route based on the performance achievement information from the performance achievement prediction block 122. That is, the operation planning block 124 realizes a DDT function that plans a future trajectory to be traveled by the host vehicle 2 as a path plan. The future trajectory planned by the operation planning block 124 may time-series prescribe at least one of the physical quantities of motion related to the host vehicle 2, such as position, speed, acceleration, yaw rate, and direction of motion. The time-series trajectory plan to be prescribe may construct a scenario of future travel by navigation of the host vehicle 2. Therefore, the trajectory planning may include a function of selecting or switching between the optimal path plans from among multiple path plans.

[0058] The operation planning block 124 may determine a transition of the operation mode according to the driver's intention based on at least one of, for example, intention estimation information and biological information as the information about the driver recognized by the recognition block 100. The operation planning block 124 may determine whether or not the driver has a disorder based on at least one of, for example, intention estimation information and biological information as the information about the driver recognized by the recognition block 100. The operation planning block 124 may determine whether or not each of the physical components 1, 4 to 8 has a disorder by monitoring the operation system DS.

[0059] The driving planning block 124 may plan adjustment of the autonomous driving level of the host vehicle 2 based on at least one of the performance achievement information from the performance achievement prediction block 122, the driving mode transition determination result, the driver's fault determination result, the driving system DS's fault determination result, the future route planning result, the future behavior planning result, and the future trajectory planning result. The adjustment of the autonomous driving level may include a takeover / handover of the DDT between the driving system DS and the driver due to a transition of the driving mode between autonomous driving and manual driving.

[0060] The handover between automated driving and manual driving may be realized in a scenario involving entering or exiting an operational design domain (ODD) where automated driving is performed, by setting the ODD. For example, an exit scenario from the ODD, i.e., a handover scenario from automated driving to manual driving, may be a use case in which an unreasonable situation is determined to exist, in which an unreasonable risk is present. In this use case, the driving plan block 124 may plan a DDT fallback so that a driver who is a fallback backup user transitions the host vehicle 2 to a minimal risk condition (MRC) by manual driving.

[0061] The adjustment of the autonomous driving level planned by the operation planning block 124 may include degenerate driving of the host vehicle 2. In a degenerate driving scenario, an irrational situation in which handover to manual driving is determined to present an unreasonable risk is cited as a use case. In this use case, the operation planning block 124 may plan a best effort to transition the host vehicle 2 to MRC by autonomous driving and autonomous stopping in order to minimize the harm or risk of an accident. In such a best effort, in addition to adjustments to lower the autonomous driving level, emergency maneuvers (emergency operations) such as DDT fallbacks or minimum risk maneuvers (MRMs) that reach MRC as a safe state may be planned as adjustments that maintain the autonomous driving level. In this case, a notification associated with the emergency operation, for example, by the information IF system 8, may be planned to increase the conspicuousness of the transition to MRC both inside and outside the host vehicle 2.

[0062] The operation planning block 124 further plans the operation control of the host vehicle 2 according to at least the route plan, the behavior plan, the trajectory plan, and the operation level plan among the plans described above. In the operation control planning, control commands related to the navigation operation of the host vehicle 2 and the driver assistance operation are generated as control actions. That is, the operation planning block 124 realizes a DDT function that plans motion control requests of the host vehicle 2. The control commands generated by the operation planning block 124 may include control parameters for controlling the actuator system 4. Such control planning may be performed by the control block 160 prior to the operation control described below.

[0063] The monitoring block 140 acquires recognition information from the recognition block 100. The monitoring block 140 may acquire past driving control information from the subsequent control block 160. The monitoring block 140 includes a safety assurance prediction block 142 and a driving constraint block 144 as sub-functional blocks for setting constraints on the driving by monitoring the driving of the host vehicle 2 according to predictions based on the acquired information.

[0064] The safety assurance prediction block 142 predicts, in a time series, the future behavior of the other road user 3 in the external environment of the host vehicle 2. At this time, the safety assurance prediction block 142 performs safety assurance prediction regarding the future behavior of the other road user 3 as a prediction for ensuring reasonably foreseeable safety in the host vehicle 2 through the subsequent driving constraint block 144. The future behavior to be safety assurance predicted may include risky behavior that is foreseeable as a potential risk between the host vehicle 2 and the other road user 3. The future behavior to be safety assurance predicted may be the future trajectory of the other road user 3. Here, the future trajectory may be safety assurance predicted so as to define, in a time series, at least one type of physical quantity of motion related to the other road user 3, such as position, velocity, acceleration, yaw rate, and motion direction. Such a safety assurance prediction by the safety assurance prediction block 142 may be a prediction closer to the future than the performance achievement prediction by the performance achievement prediction block 122. In other words, the performance achievement prediction by the performance achievement prediction block 122 may be a prediction that precedes the safety assurance prediction by the safety assurance prediction block 142 on the time axis.

[0065] In order to realize such safety assurance prediction, the safety assurance prediction block 142 may be constructed by at least one type of dedicated computer mounted on the host vehicle 2. The safety assurance prediction block 142 is constructed by a dedicated computer that is physically common to the driving constraint block 144, but may also be constructed by a dedicated computer that is physically separate from the driving constraint block 144. The safety assurance prediction block 142 is constructed by a dedicated computer that is physically separate from the recognition block 100, but may also be constructed by a dedicated computer that is physically common to the recognition block 100.

[0066] The safety assurance prediction block 142 is constructed by a dedicated computer that is physically separate from the performance achievement prediction block 122, but may also be constructed by a dedicated computer that is physically shared with the performance achievement prediction block 122. Here, when the prediction blocks 142, 122 are constructed by separate dedicated computers, the safety assurance prediction by the safety assurance prediction block 142 should be physically independent from the performance achievement prediction by the performance achievement prediction block 122. On the other hand, when the prediction blocks 142, 122 are constructed by a common dedicated computer, the safety assurance prediction by the safety assurance prediction block 142 should be functionally independent in software from the performance achievement prediction by the performance achievement prediction block 122. In either case, the independence of the safety assurance prediction from the performance achievement prediction means that prediction information from the performance achievement prediction is not substantially used for the safety assurance prediction.

[0067] However, when the prediction blocks 142, 122 are constructed using separate dedicated computers, the performance achievement prediction by the performance achievement prediction block 122 may be physically independent from the safety assurance prediction by the safety assurance prediction block 142, or prediction information by the safety assurance prediction may be physically transmitted between the dedicated computers and used. On the other hand, when the prediction blocks 142, 122 are constructed using a common dedicated computer, the performance achievement prediction by the performance achievement prediction block 122 may be functionally independent from the safety assurance prediction by the safety assurance prediction block 142, or prediction information by the safety assurance prediction may be functionally used.

[0068] The safety assurance prediction block 142 may interpret the driving environment, which is the situation of the host vehicle 2, as a basic process for performing the safety assurance prediction. In this case, the environment interpretation by the safety assurance prediction block 142 may be realized in accordance with the environment interpretation by the performance achievement prediction block 122. The environment interpretation by the safety assurance prediction block 142 may be realized independently of the environment interpretation by the performance achievement prediction block 122. For example, in a scene where a lane structure such as a lane exists, a situation where a risk of a rear-end collision or a head-on collision is potentially assumed in the longitudinal direction and a situation where a risk of a side collision is potentially assumed in the lateral direction may be interpreted. In these longitudinal and lateral environmental interpretations, state quantities related to the host vehicle 2 and other road users 3 may be converted into a coordinate system assuming a linear lane. On the other hand, in a scene where a lane structure does not exist, a situation where a risk of a trajectory collision is potentially assumed in any direction of the host vehicle 2 may be interpreted.

[0069] The environmental interpretation that forms the basis of such safety assurance prediction may be at least partially executed by the recognition block 100, and the interpretation result as recognition information may be provided to the safety assurance prediction block 142. In this case, the environmental interpretation that forms the basis of the performance achievement prediction may also be at least partially executed by the recognition block 100, and a common interpretation result may be provided to each of the safety assurance prediction block 142 and the performance achievement prediction block 122.

[0070] The safety assurance prediction block 142 may perform safety assurance prediction to conform to a driving policy by using a safety model described according to the driving policy and its safety. Here, the driving policy followed by the safety model is specified based on a vehicle level SOTIF strategy (VLSS) that ensures safety of the intended functionality (SOTIF). In other words, the safety model is described by following the driving policy that is an implementation of the VLSS and by modeling the SOTIF. Therefore, the safety model may be designed to avoid potential accident liability due to unreasonable risks or misuse by road users in accordance with accident liability rules. For example, the safety model may be a responsibility-sensitive safety model that complies with accident liability rules according to the driving policy.

[0071] The safety model may be defined as a safety-related model itself, which expresses safety-related aspects of behavior probability based on assumptions about reasonably foreseeable behavior of other road users 3, or as a model constituting a part of the safety-related model. Such a safety model may be constructed in at least one form, for example, a mathematical model that formulates vehicle-level safety, or a computer program that executes processing in accordance with the mathematical model. Therefore, the safety model parameters may be tuned by training using a machine learning algorithm, for example, DNN, which back-propagates past driving control information from the control block 160 to the safety model.

[0072] The safety assurance prediction block 142 may assume a reasonably foreseeable safety range Rs between the host vehicle 2 and the other road user 3 as a future behavior prediction of the other road user 3 based on the safety model, as illustrated in FIGS. 4 and 5. In this case, the safety assurance prediction block 142 may assume the safety range Rs for avoiding the risk of unreasonable self-blame (i.e., potential accident liability of the host vehicle 2) based on a safety model that enforces compliance with accident liability rules. Here, the safety range Rs may be defined as a range within which an unreasonable risk is predicted to occur if the performance limit of the driving system DS is exceeded as its boundary. In other words, the boundary of the safety range Rs may represent the most stringent safety condition assumed according to the safety model.

[0073] The safety assurance prediction block 142 shown in FIG. 3 sets the boundary of the safety range Rs based on prediction information obtained as a result of the safety assurance prediction so as to ensure reasonably foreseeable safety in the host vehicle 2. In other words, the safety assurance prediction can be said to be a prediction of future actions of the other road user 3 in order to set the boundary of the safety range Rs that is reasonably foreseeable in the host vehicle 2. Here, the physical quantity of motion that defines the boundary of the safety range Rs is at least one of the following types that serve as the basis for driving monitoring and driving constraints in the subsequent driving constraint block 144, such as the speed, acceleration, attitude angle, and separation distance from the other road user 3 of the host vehicle 2 (FIGS. 4 and 5 show an example of acceleration). The boundary setting of the safety range Rs may be performed by the driving constraint block 144 prior to the driving monitoring and constraint setting described below.

[0074] In setting the boundaries of the safety range Rs by the safety assurance prediction block 142, a safety envelope based on a safety model between the host vehicle 2 and other road users 3 may be assumed. Here, the safety envelope may be defined as a set of limits and conditions that the driving system DS is designed to operate under in order to maintain operation within an acceptable level of risk. Such a safety envelope may be set as a physics-based margin around each road user, including the host vehicle 2 and other road users 3, by critical values ​​or limit values ​​of physical quantities of motion that provide the boundaries.

[0075] In estimating the safety envelope, a safety distance may be set from a profile of at least one type of physical quantity of motion based on a safety model for the host vehicle 2 and other road users 3 assumed to follow a driving policy. In this case, the safety distance may be estimated so as to define a boundary around the host vehicle 2 that ensures a physics-based margin for the motion of the other road users 3 predicted based on the safety model. The safety distance may be estimated taking into account the reaction time required for each road user to execute an appropriate response. For example, in a scene where a lane structure such as a lane exists, a safety distance that avoids the risk of a rear-end collision and a head-on collision in the longitudinal direction of the host vehicle 2 and a safety distance that avoids the risk of a side collision in the lateral direction of the host vehicle 2 may be calculated. On the other hand, in a scene where a lane structure does not exist, a safety distance that avoids the risk of a trajectory collision in any direction of the host vehicle 2 may be calculated.

[0076] The safety assurance prediction block 142 may output at least one of the prediction information acquired as described above and boundary information of the set safety range Rs to the memory 10 as safety assurance information. The memory 10 to which the safety assurance information is output may be mounted in the host vehicle 2 or may be installed outside the host vehicle 2, for example, at an external center, depending on the type of dedicated computer constituting the driving system DS. The output safety assurance information may be temporarily stored in the memory 10 and provided to the driving constraint block 144. The output safety assurance information may be stored as evidence information and accumulated in the memory 10. The output performance achievement information may be read from the memory 10, which serves as a temporary storage destination or a storage destination as evidence information, and transmitted to an external center or the like outside the host vehicle 2 via the communication system 6.

[0077] The safety assurance information serving as evidence information may be stored in an unencrypted state, or may be encrypted or hashed and stored. The safety assurance information serving as evidence information may be stored in the memory 10 in association with behavior information that represents the actual behavior of the host vehicle 2 as past driving control information by the control block 160. The safety assurance information serving as evidence information may also be stored in the memory 10 in association with performance achievement information by the performance achievement prediction block 122. The safety assurance information stored in this manner may be utilized as a lagging indicator for training a safety model that serves as a predictive model for safety assurance prediction, or may be utilized as a leading indicator for verifying and validating the safety model.

[0078] The driving constraint block 144 sets constraints based on the monitoring for the driving control of the host vehicle 2, which is monitored in accordance with the safety assurance prediction by the safety assurance prediction block 142 and the boundary of the safety range Rs. Therefore, the driving constraint block 144 performs driving control monitoring and constraint setting based on the safety assurance information provided by the safety assurance prediction block 142. At this time, the necessity of setting constraints may be monitored depending on whether or not there is a violation of the safety envelope assumed in the setting of the safety range Rs by the safety assurance prediction block 142. At this time, if a safety distance is assumed as the safety envelope, it may be determined that there is no violation of the safety envelope when the actual distance between the host vehicle 2 and the other road user 3 exceeds the safety distance. On the other hand, it may be determined that there is a violation of the safety envelope when the actual distance between the host vehicle 2 and the other road user 3 is equal to or less than the safety distance.

[0079] The driving constraint block 144 may calculate, by simulation, a rational scenario that provides the host vehicle 2 with an appropriate action to be taken as an appropriate response when it is determined that the safety envelope has been violated. In the simulation of the rational scenario, state transitions between the host vehicle 2 and other road users 3 are estimated, and actions to be taken for each transition state may be set as constraints (described in detail later) on the host vehicle 2. In this action setting, a limit value that limits at least one type of motion physical quantity to be provided to the host vehicle 2 as a constraint on the host vehicle 2 may be calculated.

[0080] The control block 160 obtains control commands from the operation planning block 124 of the decision block 120. The control block 160 obtains constraint information from the operation constraint block 144 of the monitoring block 140. When no constraints are set by the operation constraint block 144, the control block 160 controls the operation of the host vehicle 2 according to the planned control commands. That is, the control block 160 realizes a DDT function that provides control actions to the host vehicle 2. For example, a use case in which constraints are set by the operation constraint block 144 is a planned driving situation within a performance achievement range Rp that falls within the boundary of a safety range Rs, as shown by cross-hatching in FIG. 4. In this case, the control block 160 may obtain recognition information, such as vehicle motion information, regarding the host vehicle 2 from the recognition block 100 or via the decision block 120 and use the information for vehicle control.

[0081] On the other hand, when the driving constraint block 144 sets constraints and acquires constraint information, the control block 160 imposes constraints on the planned driving control of the host vehicle 2. For example, a use case in which constraints are set by the driving constraint block 144 is a situation in which driving is planned within a range that exceeds the boundary of the safety range Rs within the performance achievement range Rp, as shown by cross-hatching in FIG. 5. Here, the constraints on the driving control may be functional constraints or degraded constraints. The constraints on the driving control may also be constraints other than these. In either case, the constraints on the driving control may be imparted by limiting the control commands. In this case, if a reasonable scenario is simulated by the driving constraint block 144, the control commands may be limited in accordance with the scenario. Furthermore, if limit values ​​for the motion physical quantities of the host vehicle 2 are set, the control parameters of the actuator system 4 included in the control commands may be corrected based on the limit values.

[0082] (Processing flow) In the first embodiment, a flow of a processing method (hereinafter referred to as a processing flow) for performing driving processing of a host vehicle 2 in accordance with the flowchart shown in Fig. 6 is repeatedly executed by the cooperation of multiple blocks 100, 120, 140, and 160. In the following explanation, each "S" in the processing flow refers to multiple steps executed by multiple instructions included in a processing program.

[0083] In S100, the recognition block 100 generates recognition information by recognizing the interior and exterior environments of the host vehicle 2. After execution of S10, the performance achievement sequence of S20, S30, and S40 and the safety assurance sequence of S50, S60, and S70 are executed in parallel.

[0084] In S20 of the performance achievement sequence, the decision block 120 uses the performance achievement prediction block 122 to make a performance achievement prediction regarding the future behavior of the other road user 3 as a prediction for achieving the target performance in the host vehicle 2. At this time, the performance achievement prediction may be realized based on a risk balance model. In S30 of the performance achievement sequence, the decision block 120 uses the performance achievement prediction block 122 to set a performance achievement range Rp for achieving the target performance in the host vehicle 2, in accordance with the performance achievement prediction in S20. In S40 of the performance achievement sequence, the decision block 120 uses the operation plan block 124 to make a driving plan for the host vehicle 2 in accordance with the performance achievement prediction in S20 and the performance achievement range Rp in S30.

[0085] Meanwhile, in S50 of the safety assurance sequence, the monitoring block 140 performs a safety assurance prediction regarding the future behavior of the other road user 3 using the safety assurance prediction block 142 as a prediction for ensuring reasonably foreseeable safety in the host vehicle 2. At this time, the safety assurance prediction may be realized based on a safety model. In S50 of the safety assurance sequence, the monitoring block 140 sets the boundary of a safety range Rs that ensures the safety of the host vehicle 2 using the safety assurance prediction block 142 in accordance with the safety assurance prediction in S50. In S70 of the safety assurance sequence, the monitoring block 140 performs driving monitoring and constraint setting of the host vehicle 2 using the driving constraint block 144 in accordance with the safety assurance prediction in S50 and the boundary of the safety range Rs in S60.

[0086] In S80, which transitions from the performance achievement sequence of S20, S30, and S40, the control block 160 determines whether or not constraints have been set on the host vehicle 2 through the safety assurance sequence of S50, S60, and S70. If a negative determination is made as a result, in S90 the control block 160 controls the host vehicle 2 in accordance with the driving plan made in S40 of the performance achievement sequence. In contrast, if a positive determination is made, in S100 the control block 160 controls the host vehicle 2 so as to impose the constraints set in S70 of the safety assurance sequence on the driving planned in S40 of the performance achievement sequence. The completion of execution of S90 and S100 marks the end of the current execution of the processing flow.

[0087] In the above processing flow, it is preferable that the performance achievement prediction of S20 and the safety assurance prediction of S50 are adapted to changes in the perception capabilities or perception performance of the host vehicle 2. Therefore, as shown in Fig. 7, the performance achievement prediction of S20 and the safety assurance prediction of S50 may be adapted and executed for the cases of situations α to δ classified as follows.

[0088] (α) A situation in which the visibility of other road users 3 is ensured at both past and present timings by the recognition function of the driving system DS in the host vehicle 2. (β) A situation in which the visibility of other road users 3 by the recognition function in the driving system DS of the host vehicle 2 is limited in the past timing and ensured in the present timing. (γ) A situation in which visibility of other road users 3 by the recognition function of the driving system DS in the host vehicle 2 has been ensured in the past but is limited in the present. (δ) A situation in which the visibility of other road users 3 by the recognition function of the driving system DS in the host vehicle 2 is limited both in the past and present.

[0089] In the following classification explanation, the past timing may correspond to the execution timing of each prediction by S20 and S50 in at least one past execution prior to the current execution of the process flow, while the current timing may correspond to the execution timing of each prediction by S20 and S50 in the current execution of the process flow.

[0090] In the classification explanation, the visibility of other road users 3 by the recognition function may be classified into a situation where it is ensured regardless of the reliability defined using, for example, the detection accuracy of the sensor system 5, and a restricted situation where the visibility cannot be ensured. The visibility may be classified into a situation where it is ensured when the reliability defined using, for example, the detection accuracy is equal to or exceeds a set level, and a situation where it is restricted when the reliability is below or equal to the set level.

[0091] In the case of situation α, in the performance achievement prediction of S20, the future behavior of the other road user 3 may be predicted in accordance with a risk balance model based on a recognition history that can be interpreted from recognition information obtained by a recognition function that ensures visibility both in the past and present. On the other hand, in the case of situation α, in the safety assurance prediction of S50, the future behavior of the other road user 3 within the safety range Rs may be predicted in accordance with a safety model based on recognition information, such as position and speed, obtained by a recognition function that ensures visibility both in the past and present.

[0092] In the case of situation β, in the performance achievement prediction of S20, a future behavior prediction of the other road user 3 may be realized in accordance with a risk balance model based on recognition information by a recognition function that ensures visibility at the current timing and a driving history of the other road user 3 at a past timing when the visibility of the recognition function was limited. Here, the driving history at a past timing may be recognition information of traffic flow acquired at the current timing from the other road user 3 or an external center through V2X communication via the communication system 6. In contrast to this, in the case of situation β, in the safety assurance prediction of S50, a future behavior prediction of the other road user 3 within the safety range Rs may be realized in accordance with a safety model based on recognition information, such as position and speed, by a recognition function that ensures visibility at the current timing.

[0093] In the case of situation γ, in the performance achievement prediction of S20, the future behavior of the other road user 3 may be predicted in accordance with a risk balance model based on historical information of the recognition history that can be interpreted from recognition information by a recognition function that ensures visibility at past timings. On the other hand, in the case of situation γ, in the safety assurance prediction of S50, the future behavior of the other road user 3 may be predicted based on recognition information such as position and speed by a recognition function that ensures visibility at past timings, assuming movement within a safety range Rs that follows a safety model.

[0094] In the case of situation δ, the performance achievement prediction in S20 may be based on the driving history of the other road user 3 at past timings when the visibility of the recognition function was limited, thereby realizing a future behavior prediction of the other road user 3 according to a risk balance model. Here, the driving history at past timings may be traffic flow recognition information acquired at the current timing by V2X communication, as in the case of situation β. In contrast to this, the safety assurance prediction in S50 in the case of situation δ may be a future behavior prediction of the other road user 3 assuming movement within a safety range Rs according to a safety model in a place where the visibility of the recognition function is limited both in the past and present, such as a blind spot from the host vehicle 2.

[0095] As described above, in the host vehicle 2 of the first embodiment, a driving plan is executed as a prediction for achieving target performance in accordance with a performance achievement prediction that predicts the future behavior of other road users 3 in the external environment of the host vehicle 2. Therefore, in the host vehicle 2 of the first embodiment, driving monitoring is executed as a prediction for ensuring reasonably foreseeable safety in accordance with a safety assurance prediction that predicts the future behavior of other road users 3 independently from the performance achievement prediction. According to this, by monitoring the driving of the host vehicle 2 planned in accordance with the performance achievement prediction in accordance with the safety assurance prediction, it becomes possible to achieve a balance between performance and safety for the driving.

[0096] Second Embodiment The second embodiment is a modification of the first embodiment.

[0097] 8 , in the functional architecture of the second embodiment, the function of acquiring constraint information from the driving constraint block 144 of the monitoring block 140 is realized by the driving plan block 2124 of the decision block 2120, instead of the control block 2160. Therefore, when no constraint is set by the driving constraint block 144, the driving plan block 2124 plans the driving of the host vehicle 2 in accordance with the first embodiment. On the other hand, when a constraint is set by the driving constraint block 144 and constraint information is acquired, the driving plan block 2124 imposes a constraint on the driving plan at the stage of planning the driving of the host vehicle 2 in accordance with the first embodiment. In either case, the control block 2160 executes the driving control of the host vehicle 2 planned by the driving plan block 2124.

[0098] 9 , in the processing flow of the second embodiment, in S2040 following S30 in the performance achievement sequence, the decision block 2120 determines, via the operation planning block 2124, whether or not a constraint has been set on the host vehicle 2 through the safety assurance sequences of S50, S60, and S70. If a negative determination is made, in S2041 of the performance achievement sequence, the decision block 2120 makes, via the operation planning block 2124, a driving plan for the host vehicle 2 based on the performance achievement prediction made in S20 and the performance achievement range Rp made in S30. If a positive determination is made, in S2042 of the performance achievement sequence, the decision block 2120 makes a driving plan via the operation planning block 2124 so as to impose a constraint in S70 of the safety assurance sequence on the operation of the host vehicle 2 based on the performance achievement prediction made in S20 and the performance achievement range Rp made in S30. In S2080, which is performed regardless of whether S2041 or S2042 has been executed, the control block 2160 controls the host vehicle 2 in accordance with the driving plan according to the step before the execution of S2041 or S2042. As described above, the completion of execution of S2080 marks the end of the current execution of the processing flow.

[0099] In the second embodiment described so far, it is also possible to achieve a balance between performance and safety in driving the host vehicle 2 by following the principles explained in the first embodiment.

[0100] (Third embodiment) The third embodiment is a modification of the second embodiment.

[0101] 10 , in the functional architecture of the second embodiment, a monitoring function and a constraint setting function are realized by an operation constraint block 3144 as part of the functions of the operation planning block 3124 of the decision block 3120. Therefore, the monitoring function and the constraint setting function by the operation constraint block 3144 may be called on the software for each of multiple applications or commonly for multiple applications while the planning function by the operation planning block 3124 is being executed. In this case, the safety assurance prediction function by the safety assurance prediction block 3142 may be made independent not only from the performance achievement prediction by the performance achievement prediction block 122 but also from the operation plan by the operation planning block 3124 and the operation monitoring by the operation constraint block 3144.

[0102] 11 , in the processing flow of the third embodiment, in S3070, which is a common step between the performance achievement sequence and the safety assurance sequence, the decision block 3120 monitors the operation of the host vehicle 2 and sets constraints in accordance with the safety assurance prediction in S50 and the boundary of the safety range Rs in S60 using the operation constraint block 3144. Therefore, in S3040 following S3070 in the performance achievement sequence, the decision block 3120 determines, using the operation plan block 3124, whether constraints have been set on the host vehicle 2 through the safety assurance sequences of S50, S60, and S3070. If a negative determination is made, in S3041 of the performance achievement sequence, the decision block 3120 performs, using the operation plan block 3124, a operation plan for the host vehicle 2 in accordance with the performance achievement prediction in S20 and the performance achievement range Rp in S30. If a positive determination is made in response to this, in S3042 of the performance achievement sequence, the decision block 3120 performs an operation plan in the operation planning block 3124 so as to impose constraints in S3070 on the operation of the host vehicle 2 according to the performance achievement prediction in S20 and the performance achievement range Rp in S30. Regardless of whether execution of S3041 or S3042 is completed, the processing flow proceeds to S2080.

[0103] In the third embodiment described so far, it is also possible to achieve a balance between performance and safety in driving the host vehicle 2 by following the principles explained in the first embodiment.

[0104] (Other embodiments) Although multiple embodiments have been described above, the present disclosure should not be construed as being limited to those embodiments, and can be applied to various embodiments and combinations within the scope that does not deviate from the gist of the present disclosure.

[0105] In a modified example, the dedicated computer constituting the processing system 1 may have at least one of a digital circuit and an analog circuit as a processor. Here, the digital circuit is at least one of an application specific integrated circuit (ASIC), a field programmable gate array (FPGA), a system on a chip (SOC), a programmable gate array (PGA), and a complex programmable logic device (CPLD). Such a digital circuit may also have a memory that stores a program.

[0106] In a modified example, the driver who serves as the operator among the occupants of the host vehicle 2 may be replaced by a remote operator or remote driver who remotely operates the host vehicle 2 at an external center. In a modified example, the host moving body to which the driving system DS and the processing system 1 are applied may be an autonomously traveling robot that is capable of transporting luggage or collecting information by autonomous traveling or remote traveling. In addition to the above, the processing system 1 according to each embodiment and modified example may be implemented in the form of a processing circuit (e.g., a processing ECU, etc.) or a semiconductor device (e.g., a semiconductor chip, etc.) as a processing device that is configured to be mountable on a host moving body and has at least one processor 12 and one memory 10.

[0107] (Terminology explanation) Terms related to the present disclosure are explained below, and this explanation is included in the embodiments of the present disclosure.

[0108] A road user may be a person who uses a road, including sidewalks and other adjacent spaces. A road user may be a user on or adjacent to an active road for the purpose of traveling from one place to another.

[0109] The other road users may be vulnerable road users and non-vulnerable road users who do not act as autonomously driven vehicles.

[0110] A dynamic driving task (DDT) may be a real-time operational and tactical function for operating a vehicle in traffic.

[0111] The behavior of the host vehicle may be vehicle motion interpreted in terms of traffic conditions. Here, the vehicle motion may be the vehicle state and its dynamics captured in terms of physical quantities (e.g., speed, acceleration, etc.).

[0112] A scenario may be a depiction of the temporal relationships between several scenes in a sequence of scenes, including the goals and values ​​in a particular situation influenced by actions and events. A scenario may be a depiction of a continuous time-series of activities that integrates a subject vehicle, all of its external environments, and their interactions in the process of performing a particular driving task.

[0113] The conditions are factors that can affect the behavior of the system, and may include traffic conditions, weather, and the behavior of the vehicle itself.

[0114] A triggering condition may be a specific condition of a scenario that acts as a catalyst for subsequent system responses that contribute to unsafe behavior, a failure to prevent, detect, and mitigate reasonably foreseeable indirect misuse.

[0115] An operational design domain (ODD) may be the specific conditions that a given (automated) driving system is designed to function in. An operational design domain may be the operating conditions that a given (automated) driving system or feature is specifically designed to function in, including, but not limited to, environmental, geographic, and time-of-day constraints, and / or the presence or absence of specific traffic or roadway features.

[0116] An automated driving system may be a collection of hardware and software capable of running the entire DDT on a continuous basis, whether or not it is limited to a particular ODD.

[0117] Safety of the intended functionality (SOTIF) may be the absence of undue risk due to inadequacies in the intended functionality or its implementation.

[0118] A driving policy may be a strategy and rules that define control behavior at the vehicle level.

[0119] A vehicle level SOTIF strategy (VLSS) may be a set of requirements for a function under development that is used to assist in SOTIF-related design, verification, and validation activities.

[0120] An unreasonable risk may be a risk that is judged to be unacceptable in a particular situation according to reasonable social and moral concepts.

[0121] Safety-related models may be representations of safety-related aspects of driving behavior based on assumptions about the reasonably foreseeable behavior of other road users. Safety-related models may be on-board or off-board safety verification or analysis devices, mathematical models, more conceptual rule sets, scenario-based behavior sets, or a combination of these.

[0122] A safety envelope may be a set of limits and conditions within which an (automated) driving system is designed to operate, subject to constraints or controls, in order to maintain operation within an acceptable level of risk. A safety envelope may be a general concept that can be used to accommodate all principles to which a driving policy can adhere, according to which an ego-vehicle operated by an (automated) driving system may have one or more boundaries around it.

[0123] A proper response may be an action that resolves a dangerous situation when other road users are acting in accordance with their assumptions about reasonably foreseeable behavior.

[0124] A safe state may be a reasonably safe mode of operation.

[0125] The performance limits may be design limits within which the system can achieve its objectives, and may be set for multiple parameters.

[0126] A minimal risk condition (MRC) may be a state of the vehicle to reduce the risk if a given trip cannot be completed. A minimal risk condition may be a state that a user or an (automated) driving system puts the vehicle into after performing a minimal risk maneuver to reduce the risk of a collision if a given trip cannot be completed.

[0127] A minimal risk maneuver (MRM) may be the ability of an (automated) driving system to transition between a nominal state and a minimal risk state.

[0128] A DDT fallback may be a response by the driver or the (automated) driving system to perform a transition to DDT or MRC after the occurrence of a fault or the detection of a malfunction, or upon the detection of a potentially dangerous behavior.

[0129] An emergency maneuver may be a maneuver performed in the event that a vehicle is in imminent danger of collision, with the aim of avoiding or mitigating the collision.

[0130] A takeover may be the transfer of the driving task between the (automated) driving system and the driver.

[0131] A driver may be a user who executes some or all of a particular vehicle's DDT and / or DDT fallback in real time. A remote driver may be a driver who is able to operate the vehicle but is not seated in a position to manually operate the vehicle's brakes, accelerator, steering, and transmission gear selection inputs.

[0132] An operator may be a designated person who has been properly trained and authorized to operate a motor vehicle. A remote operator may be an operator who is not positioned to manually operate the on-board brake, accelerator, steering, and transmission gear selection inputs, but who can operate the vehicle with or without direct line of sight.

[0133] V2X may be a technology that augments vehicles to exchange additional information with infrastructure, other vehicles, and other road users. The present disclosure also includes the following technical ideas. <Technical philosophy 1> A processing method executed by a processor (12) to perform processing related to the operation of a host vehicle (2), comprising: a performance achievement prediction that predicts future behavior of other road users in the external environment of the host mobile body as a prediction for achieving a target performance in the host mobile body; an operation plan for planning the operation of the host mobile body in accordance with the performance achievement prediction; a safety assurance prediction that predicts future behavior of the other road users in the external environment independently from the performance achievement prediction as a prediction for ensuring reasonably foreseeable safety in the host mobile body; and monitoring the operation of the host vehicle in accordance with the safety assurance prediction. <Technical philosophy 2> The performance achievement prediction is The processing method according to Technical Idea 1 includes predicting future behavior of the other road users as a prediction for setting a performance achievement range (Rp) for achieving target performance in the host mobile body. <Technical philosophy 3> The performance achievement prediction is The processing method described in Technical Idea 1 includes predicting the future behavior of the other road users as a prediction to avoid the risk of unreasonable blaming in the host mobile body. <Technical philosophy 4> The performance achievement prediction is The processing method according to Technical Idea 1 includes predicting the future behavior of the other road users as a prediction based on a statistical model that models a positive risk balance. <Technical philosophy 5> The performance achievement prediction is A processing method according to technical idea 4, which includes predicting the future behavior of the other road users according to the statistical model based on recognition information at the time when visibility of the other road users is ensured by the recognition function of the driving system (DS) in the host mobile body. <Technical philosophy 6> The performance achievement prediction is A processing method described in technical idea 5, which includes, when the visibility of the other road user by the recognition function of the driving system (DS) in the host mobile body is limited to past timing, predicting the future behavior of the other road user based on the driving history of the other road user at the past timing obtained at the current timing through V2X communication. <Technical philosophy 7> The processing method according to Technical Idea 1 further includes outputting prediction information based on the performance achievement prediction. <Technical philosophy 8> The safety guarantee prediction is A processing method described in technical idea 1, which includes predicting the future behavior of the other road users as a prediction for setting the boundaries of a reasonably foreseeable safety range (Rs) in the host mobile body. <Technical philosophy 9> The safety guarantee prediction is The processing method according to Technical Idea 1 includes predicting the future behavior of the other road users as a prediction for avoiding the risk of unreasonable self-blame in the host mobile body. <Technical Thought 10> The safety guarantee prediction is The processing method according to Technical Idea 1 includes predicting the future behavior of the other road users as a prediction based on a safety model that models the safety of the intended function. <Technical Thought 11> The safety guarantee prediction is A processing method described in Technical Idea 10, which includes predicting the future behavior of the other road user in accordance with the safety model based on recognition information at the time when visibility of the other road user is ensured by the recognition function of the driving system (DS) in the host mobile body. <Technical Thought 12> The safety guarantee prediction is A processing method described in technical idea 11, which includes predicting the future behavior of the other road user assuming movement within a safety range (Rs) according to the safety model when the visibility of the other road user by the recognition function of the driving system (DS) in the host mobile body is limited to the current timing. <Technical Thought 13> The processing method according to Technical Idea 1 further includes outputting prediction information based on the safety assurance prediction. <Technical Thought 14> The operation monitoring includes: The processing method according to Technical Idea 1 further includes setting constraints on the operation of the host mobile body according to the safety assurance prediction. <Technical Thought 15> A driving system having a processor (12) and performing processing related to driving of a host moving body (2), The processor: a performance achievement prediction that predicts future behavior of other road users in the external environment of the host mobile body as a prediction for achieving a target performance in the host mobile body; an operation plan for planning the operation of the host mobile body in accordance with the performance achievement prediction; a safety assurance prediction that predicts future behavior of the other road users in the external environment independently from the performance achievement prediction as a prediction for ensuring reasonably foreseeable safety in the host mobile body; and driving monitoring, which monitors driving of the host vehicle in accordance with the safety assurance prediction. <Technical Thought 16> A processing device having a processor (12), configured to be mountable on a host vehicle (2), and performing processing related to the operation of the host vehicle, The processor: a performance achievement prediction that predicts future behavior of other road users in the external environment of the host mobile body as a prediction for achieving a target performance in the host mobile body; an operation plan for planning the operation of the host mobile body in accordance with the performance achievement prediction; a safety assurance prediction that predicts future behavior of the other road users in the external environment independently from the performance achievement prediction as a prediction for ensuring reasonably foreseeable safety in the host mobile body; and driving monitoring, monitoring driving of the host vehicle in response to the safety assurance prediction. <Technical Thought 17> A processing program including instructions stored in a storage medium (10) and executed by a processor (12) to perform processing related to the operation of a host vehicle (2), a performance achievement prediction that predicts future behavior of other road users in the external environment of the host mobile body as a prediction for achieving a target performance in the host mobile body; an operation plan for planning the operation of the host mobile body in accordance with the performance achievement prediction; a safety assurance prediction that predicts future behavior of the other road users in the external environment independently from the performance achievement prediction as a prediction for ensuring reasonably foreseeable safety in the host mobile body; and driving monitoring, which monitors the driving of the host mobile body in accordance with the safety assurance prediction.

Claims

1. A processing method executed by a processor (12) to perform processing related to the operation of a host vehicle (2), comprising: a performance achievement prediction that predicts future behavior of other road users in the external environment of the host mobile body as a prediction for achieving a target performance in the host mobile body; an operation plan for planning the operation of the host mobile body in accordance with the performance achievement prediction; a safety assurance prediction that predicts future behavior of the other road users in the external environment independently from the performance achievement prediction as a prediction for ensuring reasonably foreseeable safety in the host mobile body; and monitoring the operation of the host vehicle in accordance with the safety assurance prediction. The performance achievement prediction is a process of setting a performance achievement range (Rp) which is a range of future behavior for achieving target performance including at least one of fuel economy performance, passenger ride comfort performance, vibration damping performance, relaxation performance, and express performance, using the future behavior prediction of the other road user; The safety guarantee prediction is A processing method that includes a process of setting the boundaries of a safety range (Rs), which is the range within which risks that are deemed unacceptable in the situation in which the host mobile body is placed, are predicted to occur using predictions of future behavior of users of other roads.

2. The performance achievement prediction is The method of claim 1 , further comprising predicting future behavior of the other road users as a prediction based on a statistical model that models a positive risk balance.

3. The performance achievement prediction is The processing method of claim 2, further comprising predicting future behavior of the other road user according to the statistical model based on recognition information of the timing when visibility of the other road user is ensured by the recognition function of the driving system (DS) in the host mobile body.

4. The performance achievement prediction is The processing method according to claim 3, further comprising, when the visibility of the other road user by the recognition function of the driving system (DS) in the host mobile body is limited to past timing, predicting the future behavior of the other road user based on the driving history of the other road user at the past timing acquired at the current timing through V2X communication.

5. The processing method according to claim 1 , further comprising outputting prediction information based on the performance achievement prediction.

6. A processing method as described in claim 1, wherein the risk is a potential accident liability risk in which the host mobile device will be held responsible if an accident occurs.

7. The safety guarantee prediction is The method of claim 1 , further comprising predicting future behavior of the other road users as a prediction based on a safety model that models the safety of the intended function.

8. The safety guarantee prediction is The processing method described in claim 7, which includes predicting the future behavior of the other road user in accordance with the safety model based on recognition information of the timing when visibility of the other road user is ensured by the recognition function of the driving system (DS) in the host mobile body.

9. The safety guarantee prediction is The processing method of claim 8, further comprising predicting future behavior of the other road user, assuming movement within a safety range (Rs) according to the safety model, when visibility of the other road user by the recognition function of the driving system (DS) in the host mobile body is limited to the current timing.

10. The processing method according to claim 1 , further comprising outputting prediction information based on the safety assurance prediction.

11. The operation monitoring includes: The method of claim 1 , further comprising: setting constraints on the operation of the host vehicle in response to the safety assurance prediction.

12. A driving system having a processor (12) and performing processing related to driving of a host mobile unit (2), The processor: a performance achievement prediction that predicts future behavior of other road users in the external environment of the host mobile body as a prediction for achieving a target performance in the host mobile body; an operation plan for planning the operation of the host mobile body in accordance with the performance achievement prediction; a safety assurance prediction that predicts future behavior of the other road users in the external environment independently from the performance achievement prediction as a prediction for ensuring reasonably foreseeable safety in the host mobile body; and monitoring the operation of the host vehicle in accordance with the safety assurance prediction. The performance achievement prediction is a process of setting a performance achievement range (Rp) which is a range of future behavior for achieving target performance including at least one of fuel economy performance, passenger ride comfort performance, vibration damping performance, relaxation performance, and express performance, using the future behavior prediction of the other road user; The safety guarantee prediction is A driving system configured to include a process of setting the boundaries of a safety range (Rs), which is the range within which risks deemed unacceptable in the situation in which the host mobile body is placed, are predicted to occur using predictions of future behavior of other road users.

13. A processing device having a processor (12), configured to be mountable on a host vehicle (2), and performing processing related to the operation of the host vehicle, The processor: a performance achievement prediction that predicts future behavior of other road users in the external environment of the host mobile body as a prediction for achieving a target performance in the host mobile body; an operation plan for planning the operation of the host mobile body in accordance with the performance achievement prediction; a safety assurance prediction that predicts future behavior of the other road users in the external environment independently from the performance achievement prediction as a prediction for ensuring reasonably foreseeable safety in the host mobile body; and monitoring the operation of the host vehicle in accordance with the safety assurance prediction. The performance achievement prediction is a process of setting a performance achievement range (Rp) which is a range of future behavior for achieving target performance including at least one of fuel economy performance, passenger ride comfort performance, vibration damping performance, relaxation performance, and express performance, using the future behavior prediction of the other road user; The safety guarantee prediction is A processing device configured to include a process of setting the boundaries of a safety range (Rs), which is the range within which risks deemed unacceptable in the situation in which the host mobile body is placed, are predicted to occur using the prediction of future behavior of users of other roads.

14. A processing program including instructions stored in a storage medium (10) and executed by a processor (12) to perform processing related to the operation of a host vehicle (2), a performance achievement prediction that predicts future behavior of other road users in the external environment of the host mobile body as a prediction for achieving a target performance in the host mobile body; an operation plan for planning the operation of the host mobile body in accordance with the performance achievement prediction; a safety assurance prediction that predicts future behavior of the other road users in the external environment independently from the performance achievement prediction as a prediction for ensuring reasonably foreseeable safety in the host mobile body; and driving monitoring that monitors driving of the host vehicle in accordance with the safety assurance prediction, The performance achievement prediction is a process of setting a performance achievement range (Rp) which is a range of future behavior for achieving target performance including at least one of fuel economy performance, passenger ride comfort performance, vibration damping performance, relaxation performance, and express performance, using the future behavior prediction of the other road user; The safety guarantee prediction is A processing program that includes a process of setting the boundaries of a safety range (Rs), which is the range within which risks that are deemed unacceptable in the situation in which the host mobile body is placed, are predicted to occur using predictions of future behavior of users of other roads.

Citation Information

Patent Citations

  • Running support system

    JP2009051430A

  • Mobile body behavior prediction device

    JP2019159535A

  • Arithmetic unit for automobile

    JP2020142766A

  • Systems, devices, and methods for predictive risk-aware driving

    US20210009121A1