Safety verification system and safety verification method

The safety verification system efficiently identifies and redesigns safety rules for autonomous devices by comparing environmental conditions, reducing the need for extensive on-site verification and simulations.

JP7846606B2Active Publication Date: 2026-04-15HITACHI LTD
View PDF 3 Cites 0 Cited by

Patent Information

Authority / Receiving Office
JP · JP
Patent Type
Patents
Current Assignee / Owner
HITACHI LTD
Filing Date
2022-11-16
Publication Date
2026-04-15

AI Technical Summary

Technical Problem

Existing safety verification systems for autonomous devices do not adequately consider environmental conditions when expanding their operating areas, requiring extensive on-site experiments or simulations, which are resource-intensive.

Method used

A safety verification system that utilizes an environmental condition database and safety rule database to compare and extract verification areas in an additional driving area, allowing for streamlined safety rule design by referencing original area rules.

Benefits of technology

Reduces man-hours and improves efficiency by identifying only areas needing safety rule redesign, ensuring safe autonomous operation in expanded areas.

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure 0007846606000001
    Figure 0007846606000001
  • Figure 0007846606000002
    Figure 0007846606000002
  • Figure 0007846606000003
    Figure 0007846606000003
Patent Text Reader

Abstract

To reduce a step number required for a safety design when expanding a traveling area of an autonomous appliance.SOLUTION: A safety verification system that verifies a safety of an autonomous appliance which drives autonomously in accordance with a safety rule, comprises: an environmental condition database that holds an environmental condition of a travel area; a safety rule database that holds the safety rule set by referring to the environmental condition; and a verification-required area extraction unit that extracts a verification-required area which requires safety verification from an additional travel area when the safety rule is applied in the additional travel area by comparing an environmental condition of the additional travel area with an environmental condition of an original travel area when expanding the travel area.SELECTED DRAWING: Figure 1
Need to check novelty before this filing date? Find Prior Art

Description

Technical Field

[0001] The present invention relates to a safety verification system and a safety verification method for verifying and designing safety rules that an autonomous device follows in an additional driving area before expanding the driving area of the autonomous device.

Background Art

[0002] As background art related to this technical field, there is a control device in Patent Document 1. In the abstract of this document, the problem is described as "even in a traffic environment where a plurality of moving bodies with different equipped driving functions move, avoid interference in the interference area without reducing the traffic efficiency between the moving bodies." As a solution, it is described that "when an interference area exists in the routes of a plurality of types of vehicles with different driving functions, the control device selects a control policy to be applied to the vehicles moving according to the virtual traffic rules according to the driving functions and moving body information of the interfering vehicles, generates virtual traffic rules for each vehicle according to the selected control policy, and transmits each of the virtual traffic rules to the vehicles associated with the virtual traffic rules."

[0003] Thus, the control device of Patent Document 1 formulates traffic rules to be observed for each combination of the types and states of moving bodies in order to enable efficient driving without interfering with each other even between vehicles with different driving functions such as autonomous driving vehicles and manual driving vehicles, and reflects them in control and instructions to the driver. In order to ensure safety within an area where a plurality of moving bodies exist, it is necessary for the moving bodies to mutually observe safety rules defined to prevent accidents such as collisions, and by defining this rule according to the combination of the types of moving bodies, it is possible to ensure safety even among various moving bodies.

Prior Art Documents

Patent Documents

[0004]

Patent Document 1

Summary of the Invention

[0005] While the safety rules described in Patent Document 1 are designed according to the combination of moving objects, in the case of autonomous devices operating in diverse environments such as public roads, it is necessary to design safety rules while considering the characteristics of the driving environment and the risks that arise from them. For example, at intersections, it is necessary to drive in a way that avoids collisions with other vehicles, depending on the shape of the intersection, the traffic rules stipulated by signals and signs, and the situation of blind spots caused by buildings, etc. In addition, other vehicles and pedestrians present in the surroundings change depending on the situation, and brightness and weather also affect the performance of sensing necessary for autonomous driving.

[0006] Therefore, when expanding the operating area of ​​autonomous devices, it is necessary to thoroughly analyze the environmental conditions of the additional area and verify the safety of the autonomous devices. However, the control device described in Patent Document 1 does not take into account the influence of these environmental conditions or the design of safety rules when expanding the operating area. Possible means of verifying the safety of autonomous devices in the additional area include on-site actual device experiments and simulations, but both require an enormous amount of work if the additional area is large.

[0007] Therefore, the present invention aims to provide a safety verification system and a safety verification method that streamline the design of safety rules applicable to an additional driving area by referring to the safety rules in the original driving area when expanding the driving area of ​​an autonomous device. [Means for solving the problem]

[0008] To solve the above problems, one form of the present invention is a safety verification system for verifying the safety of an autonomous device that drives autonomously in accordance with safety rules, comprising: an environmental condition database that holds the environmental conditions of a driving area; a safety rule database that holds safety rules set by referring to the environmental conditions; and a verification area extraction unit that, when the driving area is expanded, compares the environmental conditions of the additional driving area with the environmental conditions of the original driving area and extracts verification areas from the additional driving area where safety verification is required when the safety rules are applied to the additional driving area. [Effects of the Invention]

[0009] According to the safety verification system or safety verification method of the present invention, when expanding the driving area of ​​an autonomous device, the design of safety rules applicable to the additional driving area can be streamlined by referring to the safety rules in the original driving area. [Brief explanation of the drawing]

[0010] [Figure 1] Functional block diagram of the safety verification system and autonomous device in Example 1. [Figure 2] Hardware configuration diagram of the safety verification system in Example 1. [Figure 3] An example of the environmental conditions for Example 1. [Figure 4] An example of safety rules for Example 1. [Figure 5] Processing flowchart for the area extraction section requiring verification in Example 1. [Figure 6] An example of an area requiring verification identified within the additional driving area. [Figure 7] Processing flowchart of the safety rule verification unit in Example 1. [Figure 8] Processing flowchart of the safety rule design unit in Example 1. [Figure 9] An example of the results of safety rule redesign by the Safety Rule Design Department. [Figure 10] Processing flowchart of the safety rule design department in Example 2. [Modes for carrying out the invention]

[0011] The following describes embodiments of the safety verification system and safety verification method according to the present invention with reference to the drawings. [Examples]

[0012] First, the safety verification system 10 of Example 1 will be explained using Figures 1 to 9.

[0013] <Safety Verification System 10> Figure 1 is a functional block diagram of the safety verification system 10 and autonomous device 20 of this embodiment. In this figure, the autonomous device 20 is a device that moves autonomously within a specific area. The autonomous device control device 21 is a device that autonomously controls the movement of the autonomous device 20 according to the safety design information D3 described later. In the following description, the autonomous device 20 is assumed to be an autonomous vehicle, and the autonomous device control device 21 autonomously controls the drive system 22, braking system 23, and steering system 24 of the autonomous vehicle, thereby enabling the autonomous vehicle to drive autonomously. However, the autonomous device 20 of the present invention may also be an autonomous mobile robot equipped with a movement mechanism equivalent to the drive system 22, braking system 23, and steering system 24 of an autonomous vehicle. Furthermore, the autonomous device control device 21 may not be built into the autonomous device 20, but may be a control device that remotely controls the autonomous device 20 from an external source.

[0014] The safety verification system 10 performs various processes related to the verification and design of safety rules that the autonomous device 20 will refer to when it moves autonomously, based on the input data D1 entered by the user, and generates output data D2 to be presented to the user and safety design information D3 to be output to the autonomous device control device 21. To generate these, the safety verification system 10 includes an environmental condition database 1, a safety rule database 2, a verification area extraction unit 3, a safety rule verification unit 4, and a safety rule design unit 5. Details of each unit will be described later.

[0015] Figure 2 shows the configuration of a computer 30, which is an example of the hardware that implements the safety verification system 10. As shown here, the computer 30 includes an arithmetic unit 31 such as a CPU, a memory 32 such as a DRAM, a storage device 33 such as a HDD, an input device 34 such as a mouse, a keyboard, and a reading device for an external storage medium, and an output device 35 such as a display.

[0016] The input device 34 is used when the user inputs input data D1, and the output device 35 is used when presenting output data D2 to the user. Also, the storage device 33 stores an operating system and programs for executing various processes. These are loaded into the memory 32 and executed by the arithmetic unit 31, thereby realizing various functional units such as the above-described verification target area extraction unit 3. Note that the storage device 33 may be an external device externally attached to the computer 30. Also, by providing communication means between the computer 30 and the autonomous device control device 21, it is possible to directly input and output information such as safety design information D3 to and from the autonomous device control device 21.

[0017] Hereinafter, the details of each part of the safety verification system 10 realized by the arithmetic unit 31 of the computer 30 executing a predetermined program or registering predetermined information in the storage device 33 will be sequentially described.

[0018] <Environmental Condition Database 1> The environmental condition database 1 is a database that holds environmental conditions D4 related to the traveling area of the autonomous device 20. Figure 3 is an example of the environmental conditions D4 registered in the environmental condition database 1, and includes map information D4a of the traveling area, traffic rules D4b defined in the traveling area, information D4c about moving objects existing in the traveling area, and related information D4d that affects sensing by cameras and sensors installed in the autonomous device 20 and the environment.

[0019] Map information D4a includes, for example, the shape of roads and pathways on which the autonomous device 20 travels (straight lines, curves, T-junctions, crossroads, etc.), road width, number of lanes, and information about structures such as guardrails and utility poles installed on adjacent buildings and roads.

[0020] Traffic rules D4b include, for example, the rules of the Road Traffic Act indicated by signs, such as speed limits, stop signs, and traffic signals, as well as traffic rules established independently on private property.

[0021] Information about moving objects (D4c) includes, for example, the attributes and tendencies of moving objects such as pedestrians and vehicles present within the driving area (for example, there are many children among pedestrians near elementary schools, and there is a possibility of special work vehicles coming and going near construction sites).

[0022] Relevant information D4d that affects sensing includes, for example, brightness (it is dark in tunnels or on roads without streetlights), dust levels, and blind spots in the sensor's detection range caused by structures. This information may also include information about sensors installed in the environment as well as sensors mounted on the autonomous device 20.

[0023] <Safety Rules Database 2> Safety Rule Database 2 is a database that holds safety rules D5 set according to environmental conditions D4. Figure 4 shows an example of safety rules D5 set according to environmental conditions D4 and registered in Safety Rule Database 2, which include safety rules D5a related to map information, safety rules D5b related to traffic regulations, safety rules D5c related to moving objects, and safety rules D5d related to sensing.

[0024] Examples of safety rule D5a related to map information include "when changing lanes, give priority to the vehicle on the priority side," "when driving through intersections, give priority to the vehicle on the priority side," and "drive at a slow speed, anticipating an approaching moving object from a blind spot." The actions required of the autonomous device 20 to ensure safety change depending on the shape of the road, such as multi-lane roads and intersections, and the blind spots created by buildings, so it is necessary to set safety rule D5 according to this map information.

[0025] Examples of safety rule D5b related to traffic regulations include "drive and stop according to traffic signals," "stop temporarily and resume driving if no vehicle with priority is approaching," and "give way to pedestrians." The autonomous device 20, like other pedestrians and vehicles, must ensure safety in relation to other moving objects by following traffic regulations established by signals and signs, or traffic rules independently established on private property, etc., and the safety rule D5 for the autonomous device 20 must also be set to comply with these regulations.

[0026] An example of safety rule D5c related to moving objects is "travel at a maximum speed of xxx [m / h]". The characteristics and tendencies of movement, and the dangers caused by such moving objects, vary depending on the type and attributes of the moving object, such as pedestrians or other vehicles. For example, someone who is familiar with the operation of the autonomous device 20 will not engage in dangerous behavior such as approaching it carelessly, but someone who is not familiar with it may not be able to predict the operation of the autonomous device 20 and may suddenly jump into its path. The driving speed and braking performance of the autonomous device 20 must be set after considering the characteristics of surrounding pedestrians.

[0027] An example of safety rule D5d related to sensing is "to drive at a low speed assuming that a moving object is approaching from a blind spot." Buildings and other moving objects may create blind spots for sensors installed on the autonomous device 20 or environmental sensors, making it impossible to detect approaching moving objects. In addition, the brightness and dust conditions within the sensor detection range may reduce detection performance. It is necessary to safely control the autonomous device 20 while taking into account the ability to detect moving objects and the environment, as well as the sensing performance.

[0028] <Area extraction unit 3 requiring verification> The verification area extraction unit 3 is a functional unit that extracts verification areas a from the additional driving area, which must be pre-verified to ensure safe autonomous driving in accordance with the safety rules of the current driving area when expanding the driving area of ​​the autonomous device 20. Figure 5 shows the processing flow of the verification area extraction unit 3.

[0029] First, in step S31, the user operates the input device 34 to input an additional driving area for the autonomous device 20.

[0030] Next, in step S32, the verification area extraction unit 3 compares the environmental conditions D40 of the original driving area A0 stored in the environmental conditions database 1 with the environmental conditions D41 of the additional driving area A1.

[0031] In step S33, the area requiring verification extraction unit 3 extracts areas with environmental conditions D41 that do not match the environmental conditions D40 of the original driving area A0 as areas requiring verification a.

[0032] In step S34, the verification area extraction unit 3 outputs the extracted verification area a to the safety rule verification unit 4.

[0033] Here, the process in Figure 5 will be explained in detail, referring to the additional driving area A1 and the area requiring verification a shown in Figure 6. When the user specifies the additional driving area A1 (step S31), the area requiring verification extraction unit 3 compares the environmental conditions D40 of the original driving area A0 with the environmental conditions D41 of the additional driving area A1 (step S32). For example, if the environmental conditions D40 do not include the conditions "road width less than xxx", "five-way intersection / no traffic lights, signs, or road width differences", "nighttime brightness less than xxx", and "many children (near an elementary school, etc.)", and the environmental conditions D41 do include these, the area requiring verification extraction unit 3 extracts areas with those environmental conditions as areas requiring verification a1 to a4 (step S33). The area requiring verification extraction unit 3 then outputs these areas requiring verification a1 to a4 to the subsequent safety rule verification unit 4 (step S34).

[0034] By following the above procedure, only areas with environmental conditions not observed in the original driving area A0 are identified as areas requiring verification (a). This eliminates the need to verify safety under the current safety rule D5 for the entire additional area, thereby reducing the man-hours required for safety design associated with expanding the driving area.

[0035] <Safety Rule Verification Department 4> The safety rule verification unit 4 is a functional unit that verifies safety rule D5 for the area a requiring verification extracted by the area requiring verification extraction unit 3. Figure 7 shows the processing flow of the safety rule verification unit 4.

[0036] First, in step S41, the area requiring verification, area a, is input from the area requiring verification extraction unit 3 to the safety rule verification unit 4.

[0037] In step S42, the safety rule verification unit 4 verifies the safety of the autonomous device 20 by simulation when the current safety rule D5 is applied to the verification area a.

[0038] In step S43, the safety rule verification unit 4 outputs the safety verification results for each verification area a to the subsequent safety rule design unit 5.

[0039] By following the above procedure, the safety rule verification unit 4 can identify areas a that require review of safety rule D5 (hereinafter referred to as "unsafe areas a'") by verifying the safety of areas a that have environmental conditions not present in the original driving area A0, under the current safety rule D5. Furthermore, even if an area a requires review has new environmental conditions D4, if it can be determined to be safe under the current safety rule D5, then a review of safety rule D5 is unnecessary for that area a. In this case, based on the verification results of the safety rule verification unit 4, it is possible to further limit the areas that require redesign of safety rule D5, thereby reducing man-hours.

[0040] <Safety Rule Design Department 5> The Safety Rule Design Unit 5 is a functional unit that redesigns Safety Rule D5 based on the verification results of the Safety Rule Verification Unit 4. Figure 8 shows the processing flow of the Safety Rule Design Unit 5.

[0041] First, in step S51, the non-safe area a' identified by the safety rule verification unit 4 is input to the safety rule design unit 5.

[0042] Next, in step S52, the safety rule design unit 5 redesigns the safety rule D5 so that the safety of the autonomous device 20 can be ensured even under the environmental conditions of the non-safe area a'.

[0043] In step S53, the safety rule design unit 5 determines the driving area to which the redesigned safety rule D5' will be applied.

[0044] In step S54, the safety rule design unit 5 generates safety design information D3 that the autonomous device control unit 21 will use to control the autonomous device 20, based on the redesigned safety rule D5' and its application area.

[0045] In step S55, the safety rule design unit 5 outputs the generated safety design information D3 to the autonomous device control device 21 of the autonomous device 20. As a result, the autonomous device 20, which autonomously travels in the additional travel area A1, can achieve safe autonomous travel based on the redesigned safety rule D5', even under environmental conditions that did not exist in the original travel area A0.

[0046] Here, Figure 9 illustrates a safety rule D5' redesigned by the safety rule design unit 5. For example, if the original safety rule D5 in the driving area A0 is the one exemplified in Figure 4, and the non-safe area a' entered in step S51 is the four areas a1 to a4 that require verification as exemplified in Figure 6, then the safety rule design unit 5 redesigns safety rule D5' as follows.

[0047] First, regarding the first unsafe area a', which is area a1 requiring verification, in order to ensure mobility safety even under the environmental condition of "road width less than xxx" in that area, "road width less than xxx" will be added to the environmental conditions to which the safety rule "prioritize pedestrians" applies.

[0048] Next, regarding the second unsafe area a', which is area a2 requiring verification, in order to ensure travel safety even under the environmental conditions of "five-way intersection / no traffic signals, signs, or road width differences" in that area, the environmental conditions to which the safety rule "Prioritize the vehicle traveling on the left" applies will be expanded to include "no traffic signals, signs, or road width differences."

[0049] Furthermore, for the third and fourth unsafe areas a', which are areas a3 and a4 requiring verification, in order to establish speed limits that can ensure safe movement even under the environmental conditions of these areas, such as "nighttime brightness less than xxx" and "many children," the environmental conditions to which the safety rule "drive at a maximum speed of zzzm / h" applies will be expanded to include "presence of the general public (many children)" and "brightness less than xxx."

[0050] In this way, by redesigning safety rule D5' to ensure safety in the area a (unsafe area a') which has been determined to be unsafe under the current safety rule D5, it becomes possible to limit the environmental conditions that need to be considered in the safety redesign within the additional area A1 (i.e., narrow down the areas that require safety redesign), and to ensure the mobility safety of the autonomous equipment 20 in the additional area with less effort.

[0051] Furthermore, when determining the application area of ​​the redesigned safety rule D5' in step S53, the task execution performance of the autonomous device 20 when the redesigned safety rule D5' is applied is considered. For example, if safety rule D5', which adds the safety rule "Prioritize pedestrians" for the environmental condition "Road width less than xxx", is applied to the entire driving area, including the original driving area A0 and the additional driving area A1, the autonomous device 20 will need to constantly acquire road width while driving. This will require time for distance measurement and communication by sensors, reducing the operational efficiency of the autonomous device 20. To avoid this, the operation of the autonomous device 20 when safety rule D5' is applied is verified, and the application area of ​​safety rule D5' is determined in a way that avoids a decrease in task execution performance. For example, by applying safety rule D5' only to the verification area a1, and applying the original safety rule D5 to the other verification areas a2 to a4, it becomes unnecessary to acquire road width in all areas, thus avoiding a decrease in task execution performance.

[0052] Another consideration when determining the application area is the ease of implementation when applying safety rule D5. For example, if different safety rules are applied to different areas, it will be necessary to switch the safety rule to follow using location information and environmental detection information. To avoid such implementation challenges as switching safety rules, it is also possible to apply a redesigned safety rule to the entire driving area. By determining the application area in step S53 after considering task execution performance, ease of implementation, and the trade-offs between them, it is possible to avoid a decrease in work efficiency and implementation problems by the autonomous device 20.

[0053] According to the safety verification system of this embodiment described above, in redesigning the safety rule D5 required due to the expansion of the autonomous device 20's driving area, areas requiring safety verification under the current safety rule are extracted from the additional area from the perspective of environmental conditions, safety verification is performed on the extracted areas, and the safety rule is redesigned considering only the environmental conditions of the areas determined to be unsafe. This limits the areas that need to be considered in the redesign of the safety rule, reduces man-hours, and improves efficiency. [Examples]

[0054] Next, the safety verification system 10 of Example 2 will be explained using Figure 10. Note that common points with Example 1 will be omitted from the explanation.

[0055] Figure 10 shows the processing flow of the safety rule design unit 5 in this embodiment. As is evident from a comparison with the processing flow of the safety rule design unit 5 in Embodiment 1 (Figure 8), the processing flow in Figure 10 replaces step S52 (redesign of safety rules) in the processing flow of Figure 8 with steps S52a to S52d, and the processing of steps S51 and S53 to S55 is common. Therefore, only steps S52a to S52d will be explained in detail below.

[0056] First, in step S52a, the safety rule design unit 5 extracts the environmental conditions of the non-safe area a' that were input in step S51 that are not included in the environmental conditions of the original driving area A0.

[0057] Next, in step S52b, the safety rule design unit 5 presents the environmental conditions extracted in step S52a to the user. One possible method of presenting this to the user is to display a message M regarding the environmental conditions of the non-safe area a' (areas requiring verification a1 to a4) on a map displayed on the output device 35 (display), as shown in the example in Figure 6. This allows the user to be presented with the environmental conditions that should be considered when redesigning the safety rules.

[0058] In step S52c, the user inputs design information for safety rules that are considered appropriate for each environmental condition (e.g., each message M) presented in step S52b, via the input device 34.

[0059] In step S52d, the safety rule design unit 5 updates safety rule D5' based on the safety rule design information entered in step S52c.

[0060] By following the above procedure, it is possible to present users with the environmental conditions that should be considered when reviewing safety rule D5 as the area expands, and to reflect the safety rule redesign information considered by the user in the safety rules. This limits and clarifies the perspectives of safety redesign that the user must implement, thereby supporting a reduction in man-hours.

[0061] According to the safety verification system of this embodiment described above, when a user redesigns safety rules, the system can help reduce man-hours by presenting the user with the environmental conditions that need to be considered in the redesign, thereby avoiding the user having to consider the entire additional area during the redesign.

[0062] It should be noted that the present invention is not limited to the embodiments described above, and includes various modifications. The embodiments described above are merely examples of the present invention and are not necessarily limited to those having all the configurations described. [Explanation of symbols]

[0063] 10: Safety verification system, 1: Environmental conditions database, 2: Safety Rules Database, 3: Area extraction unit requiring verification, 4: Safety Rules Verification Department, 5: Safety Rules Design Department, 20: Autonomous equipment, 21: Autonomous device control system, 22: Drive system, 23: Braking system, 24: Steering system, 30: Computer, 31: Arithmetic device, 32: Memory, 33: Storage device, 34: Input device, 35: Output device, D1: Input data, D2: Output data, D3: Safety design information, D4: Environmental conditions, D5: Safety rules, A0: Original driving area, A1: Additional driving area, a: Area requiring verification, a': Unsafe area, M: Environmental condition output message

Claims

1. A safety verification system that determines whether an autonomous device that drives autonomously in accordance with safety rules is safe when those safety rules are applied, An environmental conditions database that maintains the environmental conditions of the driving area, A safety rule database that holds safety rules set in reference to the aforementioned environmental conditions, When a user specifies an additional driving area outside the aforementioned driving area, the system compares the environmental conditions of the additional driving area with those of the original driving area, and extracts areas from the additional driving area that have environmental conditions that do not match those of the original driving area as areas requiring verification. A safety verification system characterized by having the following features.

2. In the safety verification system described in claim 1, A safety verification system characterized in that the aforementioned environmental conditions are information related to maps, traffic regulations, moving objects, or sensing.

3. In the safety verification system described in claim 1, Furthermore, the safety verification system is characterized by comprising a safety rule verification unit that verifies the safety when the safety rules are applied to the area requiring verification.

4. In the safety verification system described in claim 3, Furthermore, the safety verification system is characterized by comprising a safety rule design unit that redesigns the safety rules by adding the environmental conditions of the unsafe areas determined to be unsafe by the safety rule verification unit as the environmental conditions to which the safety rules apply.

5. A safety verification system according to claim 4, The safety rule design unit is characterized in that, when the redesigned safety rules are applied, the redesigned safety rules are applied only to the areas requiring verification.

6. A safety verification system according to claim 4, The aforementioned safety rule design department, The safety rule verification unit presents the user with environmental conditions in the area determined to be an unsafe area that are not included in the environmental conditions of the original driving area. A safety verification system characterized by redesigning the safety rules using user-defined safety rule design information in response to presented environmental conditions.

7. A safety verification method for determining whether an autonomous device that operates autonomously in accordance with safety rules is safe when those safety rules are applied, When a user specifies an additional driving area outside the aforementioned driving area, the environmental conditions of the additional driving area are compared with those of the original driving area, and areas with environmental conditions that do not match those of the original driving area are extracted from the additional driving area as areas requiring verification (a step to extract areas requiring verification). A safety rule verification step is performed to verify the safety when the safety rules are applied to the aforementioned area requiring verification, A safety rule design step involves redesigning the safety rule by adding the environmental conditions of the unsafe area, which was determined to be unsafe in the safety rule verification step, as the environmental conditions to which the safety rule applies. A safety verification method characterized by comprising the following features.

Citation Information

Patent Citations

  • In-vehicle information terminal and system, and map server

    JP2008145154A

  • Vehicle traveling control device

    JP2016222133A

  • Management device and control system

    JP2021140702A