Autonomous Driving Kit
The autonomous driving kit ensures redundant control by using dual communication modules and buses to switch to an alternate path when primary communication fails, addressing the lack of redundancy in existing systems and maintaining vehicle control.
Patent Information
- Application Number
- JP2023119919
- Authority / Receiving Office
- JP · JP
- Patent Type
- Patents
- Current Assignee / Owner
- Filing Date
- 2023-07-24
- Publication Date
- 2026-02-03
- Estimated Expiration
- 2043-07-24
AI Technical Summary
Existing autonomous driving systems lack redundancy in communication between the vehicle and the autonomous driving kit, leading to a failure in transmitting control commands if an abnormality occurs in non-redundant body control communication.
The autonomous driving kit is configured with dual communication modules and buses to enable redundant control by switching to an alternate communication path if the primary path fails, ensuring non-redundant control commands are transmitted via a secondary communication route.
This configuration allows for the execution of non-redundant control even when primary communication fails, maintaining vehicle control functionality by providing redundant control pathways.
Smart Images

Figure 0007810156000001 
Figure 0007810156000002 
Figure 0007810156000003
Abstract
Description
[Technical Field]
[0001] The present disclosure relates to an autonomous driving kit, and more particularly to an autonomous driving kit that is detachable from a vehicle platform configured to enable autonomous driving and that issues instructions for autonomous driving. [Background technology]
[0002] Conventionally, there have been systems in which a vehicle and an automatic driving kit work together to perform automatic driving (see, for example, Patent Document 1). [Prior art documents] [Patent documents]
[0003] [Patent Document 1] Japanese Patent Application Publication No. 2019-177808 Summary of the Invention [Problem to be solved by the invention]
[0004] It is conceivable to provide redundancy by using dual systems for communication between the vehicle and the autonomous driving kit to control the vehicle's driving, steering, and braking. In such a configuration, it is conceivable to use non-redundant control rather than dual systems for body control such as control of headlights and hazard lights in order to reduce the communication burden. In such a case, if an abnormality occurs in the body control communication from the autonomous driving kit to the vehicle, it will be impossible to transmit control commands from the autonomous driving kit to the vehicle.
[0005] This disclosure has been made to solve the above-mentioned problems, and its purpose is to provide an autonomous driving kit that is capable of executing non-redundant control in a configuration where redundant control is possible when communication for non-redundant control is abnormal. [Means for solving the problem]
[0006] The autonomous driving kit according to the present disclosure is detachably attached to a vehicle platform configured to enable autonomous driving and issues autonomous driving instructions. The autonomous driving kit includes a processor, a first communication module, and a second communication module. The vehicle platform includes a non-redundant control system that executes a non-redundant control function of the vehicle platform, a first bus, a second bus, a first vehicle control interface box configured to be able to communicate with the first communication module via the first bus and that issues control instructions to the non-redundant control system in accordance with a non-redundant control command for controlling the non-redundant control system from the autonomous driving kit, a second vehicle control interface box configured to be able to communicate with the second communication module via the second bus, and a third bus connecting the first vehicle control interface box and the second vehicle control interface box. If communication via the first bus is abnormal, the processor controls the second communication module to send a non-redundant control command to the first vehicle control interface box via the second bus and the third bus.
[0007] With this configuration, if there is an abnormality in communication via the first bus that is normally used to send non-redundant control commands from the processor of the autonomous driving kit to the first vehicle control interface box, the non-redundant control command is sent from the processor to the first vehicle control interface box via the second bus, the second vehicle control interface box, and the third bus. As a result, in a configuration that allows redundant control, it is possible to provide an autonomous driving kit that can execute non-redundant control when there is an abnormality in communication for non-redundant control.
[0008] The processor may control the first communication module to transmit a non-redundant control command to the first vehicle control interface box via the first bus when there is no abnormality in the communication via the first bus. With this configuration, the non-redundant control command can be transmitted efficiently over a short path under normal circumstances.
[0009] The vehicle platform may further include a redundant control system that executes a redundant control function different from a non-redundant control function of the vehicle platform, and the processor may control the first communication module to send a redundant control command for controlling the redundant control function to a first vehicle control interface box via a first bus, and control the second communication module to send the redundant control command to a second vehicle control interface box via a second bus. With this configuration, the redundant control command can be sent from the autonomous driving kit to the vehicle platform via a dual system.
[0010] The non-redundant control function may be a headlamp function or a hazard lamp function. With this configuration, in a configuration capable of redundant control, control of the headlamp function or the hazard lamp function can be executed when communication for controlling the headlamp function or the hazard lamp function is abnormal. [Effects of the Invention]
[0011] According to this disclosure, it is possible to provide an autonomous driving kit that is capable of executing non-redundant control in a configuration that allows redundant control when communication for non-redundant control is abnormal. [Brief explanation of the drawings]
[0012] [Figure 1] 1 is a diagram illustrating an overview of a vehicle according to an embodiment of the present disclosure. [Figure 2] FIG. 1 is a diagram showing the configuration of ADS, VCIB, and VP in more detail. [Figure 3] FIG. 2 is a diagram illustrating communication in body control. [Figure 4] 10 is a flowchart showing the flow of lamp command transmission processing executed by the ADK in this embodiment. DETAILED DESCRIPTION OF THE INVENTION
[0013] 1 is a diagram illustrating an overview of a vehicle 1 according to an embodiment of the present disclosure. The vehicle 1 includes an autonomous driving kit (ADK) 10 and a vehicle platform (VP) 20. The ADK 10 is configured to be attachable to the VP 20 (to be mounted on the vehicle 1). The ADK 10 and the VP 20 are configured to be able to communicate with each other via a vehicle control interface (VCIB 40, described later).
[0014] The VP20 can perform automatic driving in accordance with control requests from the ADK10. Although the ADK10 is shown in a position separate from the VP20 in FIG. 1, the ADK10 is actually attached to the rooftop of the VP20 or the like. The ADK10 can also be detached from the VP20. When the ADK10 is detached, the VP20 performs driving control in manual mode (driving control according to user operation).
[0015] The ADK 10 includes an autonomous driving system (ADS) 11 for autonomously driving the vehicle 1. The ADS 11, for example, creates a driving plan for the vehicle 1. The ADS 11 outputs various control requests for driving the vehicle 1 according to the driving plan to the VP 20 in accordance with an API (Application Program Interface) defined for each control request. The ADS 11 also receives various signals indicating the vehicle state (state of the VP 20) from the VP 20 in accordance with an API defined for each signal. The ADS 11 then reflects the vehicle state in the driving plan.
[0016] The VP20 includes a base vehicle 30 and a vehicle control interface box (VCIB) 40. The base vehicle 30 executes various vehicle controls in accordance with control requests from the ADK10 (ADS11). The base vehicle 30 includes various systems and sensors for controlling the base vehicle 30. More specifically, the base vehicle 30 includes an integrated control manager 31, a brake system 32, a steering system 33, a powertrain system 34, an active safety system 35, a body system 36, wheel speed sensors 51 and 52, a pinion angle sensor 53, a camera 54, and radar sensors 55 and 56.
[0017] The integrated control manager 31 includes a processor and a memory, and controls the above-mentioned systems (brake system 32, steering system 33, powertrain system 34, active safety system 35, and body system 36) involved in the operation of the vehicle 1 in an integrated manner.
[0018] The brake system 32 is configured to control braking devices provided on each wheel of the base vehicle 30. Wheel speed sensors 51, 52 are connected to the brake system 32. The wheel speed sensors 51, 52 detect the rotational speeds of the front and rear wheels of the base vehicle 30, respectively, and output the detected rotational speeds to the brake system 32. The brake system 32 outputs the rotational speeds of each wheel to the VCIB 40 as one piece of information included in the vehicle state. The brake system 32 also generates braking commands for the braking devices in accordance with a predetermined control request output from the ADS 11 via the VCIB 40 and the integrated control manager 31. The brake system 32 controls the braking devices using the generated braking commands.
[0019] The steering system 33 is configured to be able to control the steering angle of the steering wheels of the vehicle 1 using a steering device. A pinion angle sensor 53 is connected to the steering system 33. The pinion angle sensor 53 detects the rotation angle (pinion angle) of a pinion gear connected to a rotary shaft of an actuator and outputs it to the steering system 33. The steering system 33 outputs the pinion angle to the VCIB 40 as one piece of information included in the vehicle state. In addition, the steering system 33 generates a steering command for the steering device in accordance with a predetermined control request output from the ADS 11 via the VCIB 40 and the integrated control manager 31. The steering system 33 controls the steering device using the generated steering command.
[0020] The powertrain system 34 controls an electric parking brake (EPB) system 341 provided on at least one of the wheels, a parking lock (P-Lock) system 342 provided on the transmission of the vehicle 1, and a propulsion system 343 including a shift device configured to be able to select a shift range.
[0021] The active safety system 35 detects obstacles (pedestrians, bicycles, parked vehicles, utility poles, etc.) in front or behind the vehicle 1 using the camera 54 and radar sensors 55, 56. The active safety system 35 determines whether there is a possibility that the vehicle 1 will collide with the obstacle based on the distance between the vehicle 1 and the obstacle and the direction of movement of the vehicle 1. If the active safety system 35 determines that there is a possibility of a collision, it outputs a braking command to the brake system 32 via the integrated control manager 31 to increase braking force.
[0022] The body system 36 is configured to control components such as direction indicators (turn lamps, hazard lamps), a horn, wipers, head lamps, and brake lamps in accordance with the driving state or environment of the vehicle 1. The body system 36 controls each of the above components in accordance with a predetermined control request output from the ADS 11 via the VCIB 40 and the integrated control manager 31.
[0023] The VCIB 40 is configured to be able to communicate with the ADS 11 via a CAN (Controller Area Network) or the like. The VCIB 40 executes a predetermined API defined for each signal to receive various control requests from the ADS 11 and output vehicle status to the ADS 11. When the VCIB 40 receives a control request from the ADK 10, it outputs a control command corresponding to the control request to a system corresponding to the control command via the integrated control manager 31. The VCIB 40 also acquires various pieces of information about the base vehicle 30 from various systems via the integrated control manager 31 and outputs the status of the base vehicle 30 to the ADS 11 as a vehicle status.
[0024] Base vehicle 30 further includes an emergency stop switch 39. Emergency stop switch 39 is provided so as to be operable by the driver of vehicle 1, and when operated, outputs a signal indicating that the switch has been operated to integrated control manager 31.
[0025] 2 is a diagram showing in more detail the configurations of the ADS 11, the VCIB 40, and the VP 20. As shown in FIG. 2, the ADS 11 includes a computer 111, an HMI (Human Machine Interface) 112, a recognition sensor 113, an attitude sensor 114, and a sensor cleaner 115.
[0026] The computer 111 includes a processor such as a CPU (Central Processing Unit) and memories such as a ROM (Read Only Memory) and a RAM (Random Access Memory). During autonomous driving of the vehicle 1, the computer 111 acquires information about the environment of the vehicle 1, as well as the attitude, behavior, and position of the vehicle 1, using various sensors, and also acquires the vehicle state from the VP 20 via the VCIB 40 to set the next operation of the vehicle 1 (acceleration, deceleration, turning, etc.). The computer 111 outputs various commands to the VCIB 40 to realize the next operation. The computer 111 includes communication modules 111A and 111B. Each of the communication modules 111A and 111B is configured to be able to communicate with the VCIB 40.
[0027] The HMI 112 presents information to the user and accepts user operations during automatic driving, during driving requiring user operation, and during transition between automatic driving and driving requiring user operation.
[0028] The recognition sensor 113 is a sensor for recognizing the environment of the vehicle 1. The recognition sensor 113 includes, for example, at least one of a LIDAR (Laser Imaging Detection and Ranging), a millimeter wave radar, and a camera.
[0029] The attitude sensor 114 is a sensor for detecting the attitude, behavior, and position of the vehicle 1. The attitude sensor 114 includes, for example, an IMU (Inertial Measurement Unit) and a GPS (Global Positioning System). The sensor cleaner 115 is configured to use a cleaning liquid, a wiper, etc. to remove dirt adhering to the above-mentioned various sensors (camera lenses, laser light irradiation units, etc.) while the vehicle 1 is traveling.
[0030] The VCIB 40 includes a main VCIB 41 and a sub VCIB 42. Each of the VCIBs 41 and 42 includes a processor such as a CPU (Central Processing Unit) and memory such as a ROM (Read Only Memory) and a RAM (Random Access Memory). The memory stores programs executable by the processor. The VCIB 41 and communication module 111A are connected to each other so as to be able to communicate with each other. The VCIB 42 and communication module 111B are connected to each other so as to be able to communicate with each other. Furthermore, the VCIB 41 and VCIB 42 are connected to each other so as to be able to communicate with each other.
[0031] Each of the VCIBs 41 and 42 relays control requests and vehicle information between the ADS11 and the VP20. More specifically, the VCIB 41 uses an API to generate control commands from control requests from the ADS11. The VCIB 41 then outputs the generated control commands to corresponding systems among the multiple systems included in the VP20. The VCIB 41 also uses the API to generate information indicating the vehicle status from the vehicle information from each system in the VP20. The VCIB 41 outputs the generated information indicating the vehicle status to the ADS11. The same applies to the VCIB 42.
[0032] The EPB system 341 controls the EPB in accordance with a control request output from the ADS 11 via the VCIB 41. The EPB is provided separately from a braking device (such as a disc brake system), and fixes the wheels by the operation of an actuator.
[0033] The P-Lock system 342 controls the P-Lock device in accordance with a control request output from the ADS 11 via the VCIB 41. For example, the P-Lock system 342 activates the P-Lock device when the control request includes a control request to change the shift range to parking range (P range), and deactivates the P-Lock device when the control request includes a control request to change the shift range to a range other than P range. The P-Lock device fixes the rotation of the output shaft of the transmission and locks the wheels.
[0034] The propulsion system 343 switches the shift range of the shift device and controls the driving force from the driving source (motor generator, engine, etc.) in accordance with a control request output from the ADS 11 via the VCIB 41.
[0035] In the vehicle 1, autonomous driving is performed, for example, when an autonomous driving mode (described later) is selected in response to a request from the ADK 10. As described above, during autonomous driving, the ADS 11 first creates a driving plan. Examples of driving plans include a plan to continue driving straight, a plan to turn left or right at a predetermined intersection along a predetermined driving route, and a plan to change driving lanes. The ADS 11 calculates control physical quantities (acceleration, deceleration, tire turning angle, etc.) required for the vehicle 1 to operate according to the created driving plan. The ADS 11 divides the physical quantities for each execution cycle of the API. The ADS 11 uses the API to output a control request representing the divided physical quantities to the VCIB 40. Furthermore, the ADS 11 acquires vehicle states (such as the actual moving direction of the vehicle 1 and the vehicle's immobilization state) from the VP 20 and recreates a driving plan that reflects the acquired vehicle states. In this way, the ADS 11 enables autonomous driving of the vehicle 1.
[0036] In the above-described configuration, communication between the VP 20 and the ADK 10 is configured as a dual system for redundancy in order to control the running, steering, and braking of the vehicle 1. In such a configuration, it is conceivable that body control, such as control of the headlamps and hazard lights of the body system 36, is not configured as a dual system but as a non-redundant control in order to reduce the communication burden. In such a case, if an abnormality occurs in the body control communication from the ADK 10 to the VP 20, the control command from the ADK 10 cannot be transmitted to the VP 20.
[0037] Therefore, the VP20 includes a first bus 411 connecting the communication module 111A of the ADK10 to the main VCIB41, a second bus 412 connecting the communication module 111B of the ADK10 to the sub VCIB42, and a third bus 401 connecting the VCIB41 and VCIB42. If there is an abnormality in communication via the first bus 411, the computer 111 of the ADK10 controls the communication module 111B to send a non-redundant control command to the VCIB41 via the second bus 412 and the third bus 401.
[0038] As a result, if there is an abnormality in communication via the first bus 411, which is normally used to send a non-redundant control command from the computer 111 of the ADK 10 to the VCIB 41, the non-redundant control command is sent from the computer 111 to the VCIB 41 via the second bus 412, the VCIB 42, and the third bus 401. As a result, in a configuration where redundant control is possible, non-redundant control can be executed when there is an abnormality in communication for non-redundant control.
[0039] Fig. 3 is a diagram for explaining communication in body control. Referring to Fig. 3, a first bus 411 communicably connects a communication module 111A of the ADK 10 to the main VCIB 41. A second bus 412 communicably connects a communication module 111B of the ADK 10 to the sub VCIB 42. A third bus 401 communicably connects the main VCIB 41 to the sub VCIB 42.
[0040] The B-bus 371 communicably connects the main VCIB 41, the body ECU (Electronic Control Unit) 361, and the central gateway (hereinafter referred to as "CGW") 37. The I-bus 372 communicably connects the main VCIB 41, the meter ECU 362, and the CGW 37. The C1-bus 373 communicably connects the main VCIB 41, the brake ECU 363, and the CGW 37.
[0041] The VP 20 includes other communication buses (for example, a CL-bus 374, a PL-bus 375, and an SBWL-bus 376 connected to the sub-VCIB 42) in addition to the B-bus 371, the I-bus 372, and the C1-bus 373. These other communication buses are not connected to the body ECU 361, the meter ECU 362, and the brake ECU 363.
[0042] The body ECU 361 receives control commands for the body system 36, such as the horn, wipers, and headlamps, from the ADK 10 via the communication module 111A, the first bus 411, the main VCIB 41, and the B-bus 371, and controls these devices in accordance with the control commands. For example, the body ECU 361 turns the headlamps on in high beam, low beam, or off.
[0043] The meter ECU 362 receives a control command for the turn indicators of the body system 36 from the ADK10 via the communication module 111A, the first bus 411, the main VCIB 41, and the I-bus 372, and controls the turn indicators to function as turn lamps (only one of the left and right turn indicators flashes) or hazard lamps (both the left and right turn indicators flash at the same time) according to the control command.
[0044] The brake ECU 363 receives a control command for the brake lamps of the body system 36 from the ADK10 via the communication module 111A, the first bus 411, the main VCIB 41 and the C1-bus 373, and turns the brake lamps on and off according to the control command sent from the ADK10 in accordance with the braking control.
[0045] In addition, control commands for redundant control regarding driving, steering, and braking are transmitted from ADK10 to the main VCIB41 via communication module 111A and first bus 411, and also to the sub VCIB42 via communication module 111B and second bus 412.
[0046] 4 is a flowchart showing the flow of lamp command transmission processing executed in this embodiment by the ADK 10. Referring to FIG. 4, this lamp command transmission processing is called from a higher-level process and executed by the computer 111 of the ADK 10 at predetermined intervals.
[0047] The computer 111 of the ADK 10 determines whether an instruction to send a headlamp command has been issued in another process being executed by the computer 111 (step S111). If it is determined that an instruction to send a headlamp command has not been issued (NO in step S111), the computer 111 determines whether an instruction to send a hazard lamp command has been issued in another process being executed by the computer 111 (step S112). If it is determined that an instruction to send a hazard lamp command has not been issued (NO in step S112), the computer 111 returns the process to be executed to the higher-level process that called this process.
[0048] If it is determined that an instruction to send a headlamp command has been issued (YES in step S111), or if it is determined that an instruction to send a hazard lamp command has been issued (YES in step S112), the computer 111 determines whether or not there is an abnormality in the communication on the main side (communication between the communication module 111A and the main VCIB 41) (step S113). If there is an abnormality in the communication module 111A, an abnormality in the first bus 411, or an abnormality in the communication between the main VCIB 41 and the ADK 10, it is determined that there is an abnormality in the communication on the main side.
[0049] If it is determined that there is no abnormality in the communication on the main side (NO in step S113), the computer 111 controls the communication module 111A to send a command to the main VCIB 41 via the first bus 411 (step S114), and then returns the processing to be executed to the higher-level processing that called this processing.
[0050] If it is determined that there is an abnormality in the communication on the main side (YES in step S113), the computer 111 controls the communication module 111B to send a command to the main VCIB 41 via the second bus 412, the sub VCIB 42, and the third bus 401 (step S115), and then returns the processing to be executed to the higher-level processing that called this processing.
[0051] Note that braking commands for braking control are transmitted in a dual system due to redundant control. Therefore, even if the brake lamp control command for the body system 36 cannot be transmitted by main communication from the ADK 10, the brake lamp can be controlled in response to the braking control based on this braking command.
[0052] [Variations] (1) In the above-described embodiment, the above disclosure is applied to the headlamp function and the hazard lamp function as shown in Figures 3 and 4. However, this is not limited to this, and the above disclosure can be applied to any non-redundant control function that uses one of the dual systems, as opposed to a redundant control function that is controlled using dual systems.
[0053] (2) In the above-described embodiment, as shown in FIG. 3, control commands for non-redundant control, such as control of headlamps and hazard lamps, in which communication is not a dual system, are transmitted on the main side via the first bus 411. However, this is not limiting, and control commands for non-redundant control may be transmitted on the sub side via the second bus 412 instead of the first bus 411. In other words, non-redundant control may be executed using communication on the sub side. In this case, the body ECU 361 and the meter ECU 362 are connected to the communication bus on the side of the sub VCIB 42.
[0054] [summary] (1) As shown in Fig. 1, the ADK 10 is detachably attached to the VP 20 configured to enable autonomous driving, and issues instructions for autonomous driving. As shown in Fig. 2, the ADK 10 includes a computer 111, a first communication module 111A, and a second communication module 111B. As shown in Figures 1 to 3, VP20 includes a non-redundant control system (e.g., body system 36, body ECU 361, meter ECU 362) that executes the non-redundant control functions of VP20 (e.g., headlamp function, hazard lamp function), a first bus 411, a second bus 412, a first VCIB41 that is configured to be able to communicate with the first communication module 111A via the first bus 411 and issues control instructions to the non-redundant control system in accordance with a non-redundant control command for controlling the non-redundant control system from ADK10, a second VCIB42 that is configured to be able to communicate with the second communication module 111B via the second bus 412, and a third bus 401 that connects the first VCIB41 and the second VCIB42. As shown in FIG. 4, if communication via the first bus 411 is abnormal, the computer 111 controls the second communication module 111B to send a non-redundant control command to the first VCIB 41 via the second bus 412 and the third bus 401 (e.g., step S115).
[0055] As a result, if there is an abnormality in communication via the first bus 411, which is normally used to send a non-redundant control command from the computer 111 of the ADK 10 to the first VCIB 41, the non-redundant control command is sent from the computer 111 to the first VCIB 41 via the second bus 412, the second VCIB 42, and the third bus 401. As a result, in a configuration where redundant control is possible, non-redundant control can be executed when there is an abnormality in communication for non-redundant control.
[0056] 4, when there is no abnormality in the communication via the first bus 411, the computer 111 may control the first communication module 111A to transmit a non-redundant control command to the first VCIB 41 via the first bus 411 (for example, step S114). This allows the non-redundant control command to be transmitted efficiently over a short route when there is no abnormality.
[0057] 3, the VP20 may further include a redundant control system (e.g., brake system 32, steering system 33, powertrain system 34) that executes a redundant control function (e.g., braking function, steering function, driving function) different from the non-redundant control function of the VP20, and the computer 111 may control the first communication module 111A to transmit a redundant control command (e.g., braking command, steering command, driving command) for controlling the redundant control function to the first VCIB 41 via the first bus 411, and may also control the second communication module 111B to transmit the redundant control command to the second VCIB 42 via the second bus 412. This allows the redundant control command to be transmitted from the ADK 10 to the VP20 via a dual system.
[0058] (4) As shown in Figures 3 and 4, the non-redundant control function may be the headlamp function or the hazard lamp function. This allows the control of the headlamp function or the hazard lamp function to be executed when communication for controlling the headlamp function or the hazard lamp function is abnormal in a configuration capable of redundant control.
[0059] The embodiments disclosed herein should be considered to be illustrative in all respects and not restrictive. The scope of the disclosure is defined by the claims, not by the description of the above embodiments, and is intended to include all modifications within the meaning and scope of the claims. [Explanation of symbols]
[0060] 1 Vehicle, 10 ADK, 11 ADS, 20 VP, 30 Base vehicle, 31 Integrated control manager, 32 Brake system, 33 Steering system, 34 Powertrain system, 35 Active safety system, 36 Body system, 37 CGW, 39 Emergency stop switch, 40, 41, 42 VCIB, 51, 52 Wheel speed sensor, 53 Pinion angle sensor, 54 Camera, 55, 56 Radar sensor, 111 Computer, 111A, 111B Communication module, 112 HMI, 113 Recognition sensor, 114 Attitude sensor, 115 Sensor cleaner, 341 EPB system, 342 P-Lock system, 343 Propulsion system, 361 Body ECU, 362 Meter ECU, 363 Brake ECU, 401 3rd bus, 411 1st bus, 412 2nd bus.
Claims
1. An autonomous driving kit that can be attached to and detached from a vehicle platform configured to enable autonomous driving and issues instructions for autonomous driving, The autonomous driving kit includes: a processor; a first communication module; a second communication module; The vehicle platform includes: a non-redundant control system that performs non-redundant control functions for the vehicle platform; The first bus and The second bus, a first vehicle control interface box configured to be able to communicate with the first communication module via the first bus, and to issue a control instruction to the non-redundant control system in accordance with a non-redundant control command for controlling the non-redundant control system from the autonomous driving kit; a second vehicle control interface box configured to be able to communicate with the second communication module via the second bus; a third bus connecting the first vehicle control interface box and the second vehicle control interface box; The processor: An autonomous driving kit that controls the second communication module to send the non-redundant control command to the first vehicle control interface box via the second bus and the third bus when communication via the first bus is abnormal.
2. The processor:
2. The autonomous driving kit of claim 1, wherein the autonomous driving kit controls the first communication module to transmit the non-redundant control command to the first vehicle control interface box via the first bus when communication via the first bus is not abnormal.
3. The vehicle platform includes: a redundant control system for performing redundant control functions different from the non-redundant control functions of the vehicle platform; The processor:
2. The autonomous driving kit of claim 1, further comprising: a control module configured to control the first communication module to transmit a redundant control command for controlling the redundant control function to the first vehicle control interface box via the first bus; and a control module configured to control the second communication module to transmit the redundant control command to the second vehicle control interface box via the second bus.
4. The autonomous driving kit according to claim 1 , wherein the non-redundant control function is a headlamp function or a hazard lamp function.
Citation Information
Patent Citations
Control device for vehicle
JP2018158591A
Vehicle controller
JP2018160710A
Control device, program for control device, and control method
JP2019177808A
vehicle
JP2021123136A