Control system, control method, and program

The control system ensures safety in autonomous driving by using a decision module to switch between advanced and baseline controllers based on safety rules, logically proving safety conditions through Hoare logic and dFHL, addressing the lack of proven design in existing simplex architectures.

JP7847906B2Active Publication Date: 2026-04-20INTER UNIV RES INST RES ORG OF INFORMATION & SYST
View PDF 1 Cites 0 Cited by

Patent Information

Authority / Receiving Office
JP · JP
Patent Type
Patents
Current Assignee / Owner
INTER UNIV RES INST RES ORG OF INFORMATION & SYST
Filing Date
2024-05-21
Publication Date
2026-04-20

AI Technical Summary

Technical Problem

Existing simplex architectures for autonomous driving lack a logically proven design method to ensure safety, particularly in switching between advanced and baseline controllers to maintain safety and performance.

Method used

A control system incorporating a plant, an advanced controller, a baseline controller, and a decision module that switches between them based on defined safety rules, using Hoare logic and differential Floyd-Hoare Logic (dFHL) to derive mechanical derivation rules and ensure safety conditions are met.

Benefits of technology

Guarantees safety in autonomous driving by logically proving the satisfaction of safety conditions through defined switching conditions, ensuring both safety and performance are maintained.

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure 0007847906000012
    Figure 0007847906000012
  • Figure 0007847906000013
    Figure 0007847906000013
  • Figure 0007847906000014
    Figure 0007847906000014
Patent Text Reader

Abstract

This control system comprises: a plant that controls operation of a controlled body and outputs state information indicating the state of the controlled body; a first controller that instructs the plant to operate the controlled body according to a first safety rule; a second controller that instructs the plant to operate the controlled body according to a second safety rule; and a determination module that executes the first controller when the state information satisfies a first switching condition determined on the basis of the first safety rule and the second safety rule, and executes the second controller when the state information does not satisfy the first switching condition.
Need to check novelty before this filing date? Find Prior Art

Description

[Technical Field]

[0001] This invention relates to a control system, a control method, and a program. [Background technology]

[0002] As a control system to guarantee safety, the Simplex Architecture has been proposed (Non-Patent Documents 1 and 2). On the other hand, as safety rules for autonomous driving, Responsibility-Sensitive Safety (RSS) (Non-Patent Document 3) and Goal-Aware Safety (GA-RSS) have been proposed (Non-Patent Document 4). [Prior art documents] [Non-patent literature]

[0003] [Non-Patent Document 1] TL Crenshaw, E. Gunter, CL Robinson, L. Sha, and PR Kumar, "The simplex reference model: Limiting fault-propagation due to unreliable components in cyber-physical system architectures," in 28th IEEE International Real-Time Systems Symposium (RTSS 2007), 2007, pp. 400-412. [Non-Patent Document 2] D. Seto, B. Krogh, L. Sha, and A. Chutinan, "The simplex architecture for safe online control system upgrades," in Proceedings of the 1998 American Control Conference. ACC (IEEE Cat. No.98CH36207), vol. 6, 1998, pp. 3504-3508. [Non-Patent Document 3] Shai Shalev-Shwartz, Shaked Shammah, and Amnon Shashua, "On a formal model of safe and scalable self-driving cars," CoRR, abs / 1708.06374, 2017. [Non-Patent Document 4] I. Hasuo, C. Eberhart, J. Haydon, J. Dubut, R. Bohrer, T. Kobayashi, S. Pruekprasert, X. Zhang, E. A. Pallas, A. Yamada, K. Suenaga, F. Ishikawa, K. Kamijo, Y. Shinya, and T. Suetomi, "Goal-aware RSS for complex scenarios via program logic," IEEE Transactions on Intelligent Vehicles, 2023, CoRR abs / 2207.02387. [Summary of the Invention] [Problems to be Solved by the Invention]

[0004] However, in the prior art, in the simplex architecture incorporating safety rules, no design method has been proposed that is logically proven to be safe.

[0005] In view of the above technical problems, one aspect of the present invention aims to provide a control system that guarantees safety.

Means for Solving the Problems

[0006] To solve the above problems, a control system according to one aspect of the present invention includes a plant configured to control the operation of a controlled object and output state information indicating the state of the controlled object, a first controller configured to instruct the plant to operate the controlled object according to a first safety rule, a second controller configured to instruct the plant to operate the controlled object according to a second safety rule, and a determination module configured to execute the first controller when the state information satisfies a switching condition defined based on the first safety rule and execute the second controller when the state information does not satisfy the switching condition.

Effects of the Invention

[0007] According to one aspect of the present invention, a control system that guarantees safety can be provided.

Brief Description of the Drawings

[0008] [Figure 1] FIG. 1 is a diagram showing an example of a mechanical derivation rule. [Figure 2] FIG. 2 is a block diagram showing an example of the hardware configuration of the control system. [Figure 3] FIG. 3 is a block diagram showing an example of the functional configuration of the control system in the first embodiment. [Figure 4] FIG. 4 is a flowchart showing an example of the control method in the first embodiment. [Figure 5] FIG. 5 is a flowchart showing an example of the first switching process in the first embodiment. [Figure 6] FIG. 6 is a flowchart showing an example of the second switching process in the first embodiment. [Figure 7]Figure 7 is a block diagram showing an example of the functional configuration of the control system in the second embodiment. [Figure 8] Figure 8 is a flowchart showing an example of a control method in the second embodiment. [Figure 9] Figure 9 is a flowchart showing an example of the first switching process in the second embodiment. [Figure 10] Figure 10 is a flowchart showing an example of the second switching process in the second embodiment. [Figure 11] Figure 11 is a flowchart showing an example of the third switching process in the second embodiment. [Modes for carrying out the invention]

[0009] Hereinafter, embodiments of the present invention will be described with reference to the accompanying drawings. In this specification and drawings, components having substantially the same functional configuration are denoted by the same reference numerals, and redundant descriptions will be omitted.

[0010] [First Embodiment] The first embodiment of the present invention is a control system for controlling a mobile body (an example of a controlled object) capable of autonomous driving. Examples of mobile bodies in this embodiment include autonomous vehicles, route buses with fixed routes, unmanned aerial vehicles such as drones, and spacecraft such as artificial satellites and unmanned probes. Furthermore, the control system in this embodiment is not limited to mobile bodies and can be applied to, for example, the operation control of a plant. In the following, this embodiment will describe a control system for controlling an autonomous vehicle as an example.

[0011] The control system in this embodiment is constructed using a simplex architecture that incorporates autonomous driving safety rules. These autonomous driving safety rules include, as an example, a Responsibility-Based Safety Theory (RSS) or an Objective-Based Safety Theory (RSS).

[0012] <Autonomous Driving Safety Rules> Ensuring the safety of autonomous driving is a critical industrial and social issue. For autonomous driving to be socially accepted, it is essential that safety guarantees and accountability for them are clearly defined.

[0013] Autonomous driving safety rules are fundamental concepts for the social acceptance of autonomous driving. If autonomous vehicles that comply with these rules are recognized by the general public as safe and reliable on public roads, the widespread adoption of autonomous vehicles is expected to accelerate. Furthermore, these rules serve as criteria for determining the scope of manufacturer liability. The idea is that, in the event of an accident involving an autonomous vehicle, the manufacturer is not required to bear responsibility as long as the vehicle complies with these rules.

[0014] RSS (Responsive Safety Strategy) has been proposed as a method to logically guarantee the safety of autonomous driving. RSS is built on the logical structure that "if the preconditions are met, safety conditions can be met by executing the control strategy." A control strategy is a method for controlling an autonomous vehicle. An example of a control strategy is driving operations such as turning the steering wheel, applying the brakes, or pressing the accelerator to accelerate.

[0015] The RSS disclosed in Non-Patent Document 3 only guarantees the safety condition of collision avoidance. Therefore, an objective-achieving RSS has been proposed to extend the RSS and guarantee the achievement of objectives. The objective-achieving RSS is constructed with the logical structure that "if the preconditions are met, the control strategy can be executed to achieve predetermined ex-conditions while satisfying the safety conditions." According to the objective-achieving RSS, for example, it can be guaranteed that it is possible to safely reach any target point.

[0016] Hereinafter, the RSS disclosed in Non-Patent Document 3 will be referred to as Collision Avoiding RSS (CA-RSS) to distinguish it from objective-achieving RSS. When simply referred to as RSS, it includes both collision avoiding RSS and objective-achieving RSS.

[0017] <Simplex Architecture> The simplex architecture has been proposed as a control system to ensure safety. The simplex architecture consists of an Advanced Controller (AC), a Baseline Controller (BC), a Decision Module (DM), and a Plant (P).

[0018] The plant operates controlled components according to the control of either the advanced controller or the baseline controller. The advanced controller performs complex control that pursues not only safety but also various performance indicators. The baseline controller performs relatively simple control that prioritizes safety.

[0019] The decision module switches between the advanced controller and the baseline controller. Normally, the decision module switches to the advanced controller in search of better performance, and switches back to the baseline controller when it detects a critical safety issue.

[0020] The simplex architecture ensures safety for the entire control system by having the decision module appropriately switch control between the advanced controller and the baseline controller.

[0021] <Simplex architecture incorporating autonomous driving safety rules> By incorporating autonomous driving safety rules into a simplex architecture, it becomes possible to control autonomously driven mobile vehicles by switching between advanced controllers and baseline controllers. In this case, the advanced controller is a general autonomous driving control module, while the baseline controller is a module that executes control strategies according to autonomous driving safety rules.

[0022] For example, the decision module monitors the RSS preconditions. As long as the RSS preconditions are met, the decision module allows the advanced controller to control the moving object. The advanced controller is a general-purpose autonomous driving control module, and therefore performs control while considering performance indicators such as comfort.

[0023] On the other hand, if the decision module detects that the RSS preconditions are about to be no longer met, it switches control from the advanced controller to the baseline controller. The baseline controller performs control according to the RSS control strategy, thus prioritizing safety.

[0024] This means that a simplex architecture incorporating autonomous driving safety rules can achieve autonomous driving that normally delivers high performance and can avoid collisions in the event of a safety crisis. However, no logically proven design methodology has been proposed for a simplex architecture incorporating autonomous driving safety rules.

[0025] This embodiment aims to provide a control system that guarantees safety in autonomous driving. In one aspect, this embodiment makes it possible to design a simplex architecture incorporating autonomous driving safety rules and to logically prove its safety.

[0026] <Contracts that must satisfy safety rules> In this embodiment, the contracts that the RSS must satisfy are defined in order to guarantee safety in autonomous driving. Furthermore, mechanical derivation rules are provided to prove that the RSS satisfies the contracts.

[0027] ≪Contract≫ Hoare logic is known for program verification. In the RSS for achieving objectives, Hoare quadruples are defined by incorporating global safety conditions and continuous dynamics into Hoare triples given by Hoare logic.

[0028] Hoare logic guarantees that "if the precondition P is true, then after executing program α, the postcondition Q is true." Here, P, α, and Q are Hoare triplets. Hoare logic is expressed by equation (1).

[0029]

number

[0030] The objective-achieving RSS introduces a program logic system called dFHL (differential Floyd-Hoare Logic), which adds a safety condition S to Hoare's triplets. The program logic system dFHL guarantees that "if the precondition P is true, then the postcondition Q is true after program α is executed, and the safety condition S is always true while program α is executed." Here, P, α, Q, and S are Hoare's quadruplets. The program logic system dFHL is expressed by equation (2).

[0031]

number

[0032] In this embodiment, a program logic system dFHL↓ is introduced in which the safety condition S in the program logic system dFHL is divided into a global assumption A and a global guarantee G. The program logic system dFHL↓ guarantees that "given environmental assumption A, the fact that the precondition P is true means that the postcondition Q is true after the execution of program α, and the safety condition G is always true while program α is being executed." Here, A, P, α, Q, and G are Hoare quintuples. The program logic system dFHL↓ is expressed by equation (3).

[0033]

number

[0034] A concrete example of Hoare's quintuplets is shown below. Environmental assumption A is, for example, "the maximum acceleration that another vehicle traveling ahead of your vehicle can take." Precondition P is, for example, "the position and velocity of your vehicle and the other vehicle at time t=t0." Control strategy α is, for example, "driving operations to maintain the distance between your vehicle and the other vehicle." Control strategy α can be formulated based on the position and velocity of your vehicle and the other vehicle, as well as the braking performance of your vehicle, etc. Postcondition Q is, for example, "the position and velocity of your vehicle and the other vehicle at time t=t1 (>t0)." Safety condition G is, for example, "there is no collision between your vehicle and the other vehicle."

[0035] ≪Mechanical derivation rules≫ Figure 1 shows the mechanical derivation rules that constitute the program logic system dFHL↓. By using the mechanical derivation rules shown in Figure 1, it is possible to prove that Hoare's quintuplets (i.e., RSS) satisfy the contract.

[0036] ≪Safety Assurance for Simplex Architecture≫ The advanced controller is modeled as control strategy α, and the baseline controller is modeled as control strategy β. This means that the advanced controller follows safety rule [P1, α], and the baseline controller follows safety rule [P2, β]. Note that P1 and P2 are different preconditions.

[0037] Since the advanced controller can be a general-purpose autonomous driving control module, its safety rules are not self-evident. If the safety rules for the advanced controller are not defined, they can be based on general traffic regulations, the performance of autonomous vehicles, common sense, etc. Alternatively, safety rules can be defined by analyzing the operation of the advanced controller. The safety rules for the baseline controller can be those defined during the design phase, but if the safety rules are unknown, they can be similarly defined based on assumptions or analysis.

[0038] In this case, for safety rule [P1, α], we can derive a Hoare quintuplet (A1, P1, α, Q1, G1) that satisfies the contract in equation (4). Similarly, for safety rule [P2, β], we can derive a Hoare quintuplet (A2, P2, β, Q2, G2) that satisfies the contract in equation (5). However, A1 and A2 are different environmental assumptions, Q1 and Q2 are different ex post conditions, and G1 and G2 are different safety conditions.

[0039]

number

[0040] If equations (4) and (5) hold, then designing a simplex architecture to satisfy equation (6) will always satisfy safety condition G. In other words, a simplex architecture that satisfies equation (6) is guaranteed to be safe.

[0041]

number

[0042] Here, C1 and D are the switching conditions from control strategy α to control strategy β. Equation (6) means that control strategy α is executed as long as switching condition C1 is true, and when switching condition C1 becomes false, control strategy α is interrupted and the system switches to control strategy β. It also means that if control strategy α ends while switching condition C1 remains true and switching condition D becomes false, control strategy β is executed. In other words, equation (6) means that the advanced controller performs control as long as switching condition C1 is satisfied, and switches to the baseline controller when switching condition C1 or switching condition D is no longer satisfied.

[0043] Furthermore, C2 is the switching condition from control strategy β to control strategy α. Equation (6) means that if the switching condition C2 becomes false after switching to control strategy β, control strategy β is interrupted and the system switches back to control strategy α. In other words, equation (6) means that the baseline controller is maintained as long as the switching condition C2 is satisfied, and when the switching condition C2 is no longer satisfied, the system switches back to the advanced controller.

[0044] ≪Derivation of switching conditions≫ The switching conditions for a simplex architecture can be derived based on Hoare's quintuplets. These switching conditions can be either conditions that provide strong guarantees under strong assumptions (strong simplex rules) or conditions that provide weak guarantees under weak assumptions (weak simplex rules).

[0045] The switching conditions based on the strong simplex rule are derived from Hoare's quintuplet (A, P, α, Q, G) such that they satisfy the following lemma. In this case, the simplex architecture using switching conditions C1, C2, D is guaranteed to satisfy safety condition G.

[0046]

number

[0047] The switching conditions based on the weak simplex rule are derived from Hoare's quintuplets (A1, P1, α, Q1, G1) and (A2, P2, β, Q2, G2) to satisfy the following lemma. In this case, the simplex architecture using switching conditions C1, C2, D is guaranteed to satisfy safety condition G2.

[0048]

number

[0049] Furthermore, int-ext (interruption-extension) is defined as follows.

[0050]

number

[0051] If it can be proven that equation (6) is satisfied based on the switching conditions C1, C2, and D derived as described above, the safety of the control system is logically guaranteed. Furthermore, the safety of a control system can be verified by checking whether the switching conditions C1, C2, and D satisfy equation (6) in a pre-designed control system.

[0052] <Hardware configuration of the control system> The hardware configuration of the control system 1 in this embodiment will be described with reference to Figure 2. The control system 1 in this embodiment can be implemented as an embedded device such as an in-vehicle device. Figure 2 is a block diagram showing an example of the hardware configuration of the embedded device 300 in this embodiment.

[0053] As shown in Figure 2, the embedded device 300 includes a CPU (Central Processing Unit) 301, ROM (Read Only Memory) 302, RAM (Random Access Memory) 303, flash memory 304, and a communication interface (I / F) 305. Each piece of hardware in the embedded device 300 is interconnected via a bus line 306.

[0054] The CPU 301 is a computing device that controls and implements the functions of the entire embedded device 300 by reading programs and data from a storage device such as ROM 302 or flash memory 304 onto RAM 303 and executing processing.

[0055] ROM302 is an example of a non-volatile semiconductor memory (storage device) that can retain programs and data even when the power is turned off. ROM302 functions as a storage device that stores various programs and data necessary for the CPU301 to execute the various programs installed in flash memory304.

[0056] RAM303 is an example of a volatile semiconductor memory (storage device) whose programs and data are erased when the power is turned off. RAM303 provides a work area that is expanded when various programs installed in ROM302 or flash memory304 are executed by CPU301.

[0057] The flash memory 304 is an example of a non-volatile semiconductor memory (storage device) that stores programs and data. The flash memory 304 functions as a storage device that stores various programs and data executed by the CPU 301. In addition, the flash memory 304 provides a temporary storage area for data generated when various programs are executed.

[0058] Communication I / F305 is an interface that connects to the communication network 9 and allows the control system 1 to perform data communication.

[0059] The embedded device 300 can perform various processes described later by having the hardware configuration shown in Figure 2. Note that the hardware configuration shown in Figure 2 is just one example, and the embedded device 300 may have other hardware configurations. For example, the embedded device 300 may have multiple CPUs 301 or multiple RAMs 303.

[0060] <Functional configuration of the control system> The functional configuration of the control system in this embodiment will be described with reference to Figure 3. Figure 3 is a block diagram showing an example of the functional configuration of the control system 1 in this embodiment.

[0061] As shown in Figure 3, the control system 1 in this embodiment comprises a plant 11, an advanced controller 12 (an example of a first controller), a baseline controller 13 (an example of a second controller), and a decision module 14. The control system 1 functions as the plant 11, advanced controller 12, baseline controller 13, and decision module 14 when a pre-installed program is executed.

[0062] Control system 1 is a control system that controls a controlled object. In this embodiment, an example of a controlled object is an autonomous vehicle. Control system 1 may be, for example, an in-vehicle system installed in an autonomous vehicle. For example, control system 1 may be installed on the instrument panel or center console of an autonomous vehicle. Control system 1 may also be implemented using cloud computing, which links with an information processing device installed in a remote location via a mobile phone network or the like.

[0063] Plant 11 controls the operation of the autonomous vehicle according to the control strategy executed by the advanced controller 12 or the baseline controller 13. While controlling the operation of the autonomous vehicle, Plant 11 outputs status information indicating the state of the autonomous vehicle.

[0064] The advanced controller 12 instructs the plant 11 on the operation of the autonomous vehicle in accordance with predetermined safety rules. Hereinafter, the safety rules followed by the advanced controller 12 will also be referred to as the "first safety rule".

[0065] In this embodiment, the first safety rule is a safety rule implemented by a typical autonomous driving control module, and is configured to perform complex control that pursues not only safety but also various performance indicators. Performance indicators include, for example, comfort, speed, and fuel efficiency.

[0066] The baseline controller 13 instructs the plant 11 on the operation of the autonomous vehicle in accordance with predetermined safety rules. Hereinafter, the safety rules followed by the baseline controller 13 will also be referred to as the "second safety rules."

[0067] In this embodiment, the second safety rule is configured to perform relatively simple control with an emphasis on safety. The second safety rule is an automated driving safety rule. The second safety rule may have stricter safety conditions than the first safety rule. The second safety rule may be, for example, a collision avoidance RSS or an objective achievement RSS.

[0068] The decision module 14 performs the switching between the advanced controller 12 and the baseline controller 13. The decision module 14 monitors whether the status information output by the plant 11 satisfies the predetermined switching condition C1 (an example of the first switching condition) and switching condition D (an example of the third switching condition), or switching condition C2 (an example of the second switching condition).

[0069] The switching condition C1 is determined based on the first safety rule and the second safety rule. The decision module 14 monitors the switching condition C1 while the advanced controller 12 is running. The decision module 14 runs the advanced controller 12 when the status information output by the plant 11 satisfies the switching condition C1 (when the switching condition C1 is true). On the other hand, the decision module 14 switches to the baseline controller 13 when the status information output by the plant 11 does not satisfy the switching condition C1 (when the switching condition C1 is false).

[0070] The switching condition D is determined based on the first safety rule and the second safety rule. The decision module 14 monitors the switching condition D after the execution of the advanced controller 12 is completed. The decision module 14 switches to the baseline controller 13 when the status information output by the plant 11 does not satisfy the switching condition D (when the switching condition D is false).

[0071] The switching condition C2 is determined based on the first safety rule and the second safety rule. The decision module 14 monitors the switching condition C2 while the baseline controller 13 is running. The decision module 14 switches to the advanced controller 12 when the status information output by the plant 11 does not satisfy the switching condition C2 (when the switching condition C2 is false). On the other hand, the decision module 14 continues the execution of the baseline controller 13 when the status information output by the plant 11 satisfies the switching condition C2 (when the switching condition C2 is true).

[0072] <Control method using a control system> The control method by the control system in this embodiment will be described with reference to Figure 4. Figure 4 is a flowchart showing an example of the control method in this embodiment. The control method is a procedure in which the control system 1 controls the autonomous vehicle.

[0073] In step S1, the plant 11 of the control system 1 controls the operation of the autonomous vehicle. Initially, the decision module 14 selects the advanced controller 12. Therefore, the plant 11 controls the operation of the autonomous vehicle according to the control strategy α executed by the advanced controller 12.

[0074] In step S2, the plant 11 of the control system 1 outputs status information indicating the state of the autonomous vehicle. The status information output from the plant 11 is sent to the advanced controller 12, the baseline controller 13, and the decision module 14.

[0075] In step S3, the control system 1 determines which controller is currently selected. If the advanced controller 12 is selected (AC), the control system 1 proceeds to step S4. On the other hand, if the baseline controller 13 is selected (BC), the control system 1 proceeds to step S5.

[0076] In step S4, the decision module 14 of the control system 1 executes a first switching process. The first switching process is a process of switching from the advanced controller 12 to the baseline controller 13 based on switching conditions C1 and D.

[0077] ≪First Switching Process≫ The first switching process in this embodiment (step S4 in Figure 4) will be described with reference to Figure 5. Figure 5 is a flowchart showing an example of the first switching process in this embodiment.

[0078] In step S4-1, the decision module 14 of the control system 1 determines whether the state information output from the plant 11 satisfies the switching condition C1 (in other words, whether the switching condition C1 is true or false). If the switching condition C1 is true (YES), the decision module 14 proceeds to step S4-2. On the other hand, if the switching condition C1 is false (NO), the decision module 14 proceeds to step S4-3.

[0079] In step S4-2, the decision module 14 of the control system 1 determines whether the state information output from the plant 11 satisfies the switching condition D (in other words, whether the switching condition D is true or false). If the switching condition D is false (NO), the decision module 14 proceeds to step S4-3. On the other hand, if the switching condition D is true (YES), the decision module 14 terminates the first switching process without switching to the baseline controller 13.

[0080] In step S4-3, the decision module 14 of the control system 1 switches control to the baseline controller 13. Thereafter, the plant 11 controls the operation of the autonomous vehicle according to the control strategy β executed by the baseline controller 13.

[0081] Let's return to Figure 4 for explanation. In step S5, the decision module 14 of the control system 1 executes a second switching process. The second switching process is the process of switching from the baseline controller 13 to the advanced controller 12 based on the switching condition C2.

[0082] ≪Second Switching Process≫ The second switching process in this embodiment (step S5 in Figure 4) will be described with reference to Figure 6. Figure 6 is a flowchart showing an example of the second switching process in this embodiment.

[0083] In step S5-1, the decision module 14 of the control system 1 determines whether the state information output from the plant 11 satisfies the switching condition C2 (in other words, whether the switching condition C2 is true or false). If the switching condition C2 is false (NO), the decision module 14 proceeds to step S5-2. On the other hand, if the switching condition C2 is true (YES), the decision module 14 terminates the second switching process without switching to the advanced controller 12.

[0084] In step S5-2, the decision module 14 of the control system 1 switches control to the advanced controller 12. Thereafter, the plant 11 controls the operation of the autonomous vehicle according to the control strategy α executed by the advanced controller 12.

[0085] Let's return to Figure 4 for explanation. In step S6, the plant 11 of the control system 1 determines whether or not to terminate automatic operation. If automatic operation is terminated (YES), the plant 11 terminates the control method processing. On the other hand, if automatic operation is not terminated (NO), the plant 11 returns to step S1.

[0086] If the process returns to step S1, the control system 1 controls the operation of the autonomous vehicle according to the control strategy executed by the controller selected by the decision module 14. The control system 1 then continues autonomous driving, switching control to the appropriate controller according to the state of the autonomous vehicle, until autonomous driving is terminated.

[0087] <Effects of the First Embodiment> In this embodiment, the control system 1 executes the advanced controller 12 when the state information indicating the state of the autonomous vehicle satisfies the switching condition C1, and executes the baseline controller 13 when the switching condition C1 is not satisfied. The switching condition C1 is defined to ensure that predetermined safety conditions are met. Therefore, according to this embodiment, safety in autonomous driving can be guaranteed.

[0088] In this embodiment, the control system 1 executes the advanced controller 12 when the state information indicating the state of the autonomous vehicle does not satisfy the switching condition C2. The switching condition C2 is defined to ensure that predetermined safety conditions are met. Therefore, according to this embodiment, control can be performed that takes performance indicators into consideration while ensuring safety in autonomous driving.

[0089] In this embodiment, the switching condition C1 is determined such that the environmental assumption A, precondition P, control strategy α, ex-condition Q, and safety condition G derived based on safety rules satisfy a predetermined contract. The predetermined contract guarantees that, given environmental assumption A, precondition P is true, that ex-condition Q is true while control strategy α is being executed, and that safety condition G is true while control strategy α is being executed. Therefore, according to this embodiment, safety in autonomous driving can be logically guaranteed.

[0090] In one respect, this embodiment makes it possible to design a control system that guarantees safety in autonomous driving. Furthermore, this embodiment makes it possible to verify the safety of a control system that controls a mobile body capable of autonomous driving.

[0091] [Second Embodiment] In the first embodiment, a configuration was described in which the control system 1 comprises an advanced controller 12 and one baseline controller 13. In the second embodiment, a configuration was described in which the control system 1 comprises an advanced controller 12 and a plurality of baseline controllers 13.

[0092] The following description will focus on the differences between the control system 1 in this embodiment and the first embodiment. The configuration of the control system 1 in this embodiment is referred to as a "hierarchical simplex architecture."

[0093] ≪Security Assurance for Layered Simplex Architecture≫ The advanced controller is modeled as control strategy α, and the two baseline controllers are modeled as control strategies β1 and β2. This means that the first baseline controller β1 follows safety rule [P1,β1], and the second baseline controller β2 follows safety rule [P2,β2]. Note that P1 and P2 are different preconditions. In this embodiment, the advanced controller α does not consider safety rules.

[0094] In this case, for safety rule [P1, β1], we can derive a Hoare quintuplet (A1, P1, β1, Q1, G1) that satisfies the contract in equation (7). Similarly, for safety rule [P2, β2], we can derive a Hoare quintuplet (A2, P2, β2, Q2, G2) that satisfies the contract in equation (8). Furthermore, the advanced controller α can be modeled by equation (9), where A1 and A2 are different environmental assumptions, Q1 and Q2 are different ex-conditions, and G, G1, and G2 are different safety conditions.

[0095]

number

[0096] When equations (7) to (9) hold, if the hierarchical simplex architecture is designed to satisfy equation (10), the safety condition G can always be satisfied. In other words, the simplex architecture that satisfies equation (10) is guaranteed to be safe.

[0097]

Number

[0098] ≪Derivation of Switching Conditions≫ The switching condition C of the hierarchical simplex architecture 1-1 , C 1-2 , C 2-1 , C 2-2 can be derived based on Hoare's quintuple. The switching condition C 1-1 , C 1-2 , C 2-1 , C 2-2 :[[ID = 30]]can be derived to satisfy the following theorem based on Hoare's quintuples (A1, P1, β1, Q1, G1), (A2, P2, β2, Q2, G2). In this case, the hierarchical simplex architecture using the switching condition C 1-1 , C 1-2 , C 2-1 , C 2-2 is guaranteed to satisfy the safety condition G2.

[0099]

Number

[0100] If it can be proven that the switching condition C derived as above 1-1 , C 1-2 , C 2-1 :, C 2-2 satisfies equation (10), the safety of the control system is logically guaranteed. Also, in a designed control system, by verifying whether the switching condition C [[ID=!59]] 1-1 , C 1-2 , C 2-1 , C 2-2 satisfies equation (10), the safety of the control system can be verified.

[0101] <Functional configuration of the control system> The functional configuration of the control system in this embodiment will be described with reference to Figure 7. Figure 7 is a block diagram showing an example of the functional configuration of the control system 1 in this embodiment.

[0102] As shown in Figure 7, the control system 1 in this embodiment comprises a plant 11, an advanced controller 12 (an example of a first controller), a decision module 14-1, and a hierarchical baseline controller 15. The hierarchical baseline controller 15 comprises a decision module 14-2 (an example of a second decision module), a baseline controller 13-1 (an example of a second controller), and a baseline controller 13-2 (an example of a third controller).

[0103] In other words, the control system 1 in the second embodiment differs from the first embodiment in that, instead of the baseline controller 13, it includes a hierarchical baseline controller 15 comprising a decision module 14-2 and two baseline controllers 13-1 and 13-2.

[0104] The baseline controller 13-1 instructs the plant 11 to operate the autonomous vehicle according to predetermined safety rules. Hereinafter, the safety rules followed by the baseline controller 13-1 will also be referred to as the "second safety rules."

[0105] The baseline controller 13-2 instructs the plant 11 to operate the autonomous vehicle according to predetermined safety rules. Hereafter, the safety rules followed by the baseline controller 13-2 will also be referred to as the "third safety rule".

[0106] In this embodiment, both the second and third safety rules are configured to perform relatively simple control with an emphasis on safety. Both the second and third safety rules are autonomous driving safety rules, but their environmental assumption A and safety condition G are different. The third safety rule may have stricter safety conditions than the second safety rule. For example, the second safety rule may be an objective achievement RSS, and the third safety rule may be a collision avoidance RSS.

[0107] The decision module 14-1 performs the switching between the advanced controller 12 and the hierarchical baseline controller 15. The decision module 14-1 determines that the status information output by the plant 11 corresponds to a predetermined switching condition C. 1-1 (Example of the first switching condition) and switching condition D (Example of the third switching condition), or switching condition C 2-1 Monitor whether the (example of the second switching condition) is met.

[0108] The function of decision module 14-1 is the same as that of decision module 14 in the first embodiment. Switching condition C 1-1 and switching condition C 2-1 These are defined in the same way as the switching conditions C1 and C2 in the first embodiment.

[0109] The decision module 14-2 performs the switching between baseline controller 13-1 and baseline controller 13-2. The decision module 14-2 determines that the status information output by plant 11 corresponds to a predetermined switching condition C. 1-2 (Example of the fourth switching condition) or switching condition C 2-2 Monitor whether the (example of the fifth switching condition) is met.

[0110] Switching condition C 1-2 This is determined based on the second and third safety rules. The decision module 14-2 is configured to meet switching condition C while the baseline controller 13-1 is running. 1-2 The decision module 14-2 monitors the status information output by plant 11 and the switching condition C. 1-2 When the conditions are met (switching condition C) 1-2When the condition C is true, the baseline controller 13-1 is executed. Meanwhile, the decision module 14-2 uses the state information output by plant 11 to determine the switching condition C. 1-2 When the condition is not met (switching condition C) 1-2 (When this is false) Switch to baseline controller 13-2.

[0111] Switching condition C 2-2 This is determined based on the second and third safety rules. The decision module 14-2 is configured to meet switching condition C while the baseline controller 13-2 is running. 2-2 The decision module 14-2 monitors the status information output by plant 11 and the switching condition C. 2-2 When the condition is not met (switching condition C) 2-2 When the condition is false, the system switches to the baseline controller 13-1. Meanwhile, the decision module 14-2 uses the state information output by plant 11 to determine the switching condition C. 2-2 When the conditions are met (switching condition C) 2-2 (When this is true) Continue running baseline controller 13-2.

[0112] <Control method using a control system> The control method by the control system in this embodiment will be described with reference to Figure 8. Figure 8 is a flowchart showing an example of the control method in this embodiment. The control method is a procedure in which the control system 1 controls the autonomous vehicle. The control method is executed by the control system 1.

[0113] In step S11, the plant 11 of the control system 1 controls the operation of the autonomous vehicle. Initially, the decision module 14-1 selects the advanced controller 12. Therefore, the plant 11 controls the operation of the autonomous vehicle according to the control strategy α executed by the advanced controller 12.

[0114] In step S12, the plant 11 of the control system 1 outputs status information indicating the state of the autonomous vehicle. The status information output from the plant 11 is sent to the advanced controller 12, the hierarchical baseline controller 15, and the decision module 14-1. The hierarchical baseline controller 15 then sends the input status information to the baseline controller 13-1, the baseline controller 13-2, and the decision module 14-2.

[0115] In step S13, the control system 1 determines which controller is currently selected. If decision module 14-1 has selected the advanced controller 12 (AC), the control system 1 proceeds to step S14. If decision module 14-1 has selected the hierarchical baseline controller 15 and decision module 14-2 has selected the baseline controller 13-1 (BC1), the control system 1 proceeds to step S15. If decision module 14-1 has selected the hierarchical baseline controller 15 and decision module 14-2 has selected the baseline controller 13-2 (BC2), the control system 1 proceeds to step S16.

[0116] In step S14, the decision module 14-1 of the control system 1 executes the first switching process. The first switching process is performed under switching condition C 1-1 Based on and D, this is the process of switching from the advanced controller 12 to the baseline controller 13-1.

[0117] ≪First Switching Process≫ The first switching process in this embodiment (step S14 in Figure 8) will be described with reference to Figure 9. Figure 9 is a flowchart showing an example of the first switching process in this embodiment.

[0118] In step S14-1, the decision module 14-1 of the control system 1 determines the switching condition C based on the state information output from the plant 11. 1-1 Whether or not the condition is met (in other words, switching condition C) 1-1Determine the truth value of (C). Switching condition C 1-1 If this is true (YES), the decision module 14-1 proceeds to step S14-2. On the other hand, switching condition C 1-1 If the result is false (NO), the decision module 14-1 proceeds to step S14-3.

[0119] In step S14-2, the decision module 14-1 of the control system 1 determines whether the state information output from the plant 11 satisfies the switching condition D (in other words, whether the switching condition D is true or false). If the switching condition D is false (NO), the decision module 14-1 proceeds to step S14-3. On the other hand, if the switching condition D is true (YES), the decision module 14-1 terminates the first switching process without switching to the baseline controller 13-1.

[0120] In step S14-3, the decision module 14-1 of the control system 1 switches control to the hierarchical baseline controller 15. Next, the decision module 14-2 of the hierarchical baseline controller 15 selects the baseline controller 13-1. From thereafter, the plant 11 controls the operation of the autonomous vehicle according to the control strategy β1 executed by the baseline controller 13-1.

[0121] Let's return to Figure 8 for explanation. In step S15, the decision module 14-2 of the control system 1 executes the second switching process. The second switching process is performed under switching condition C 2-1 This process involves switching from baseline controller 13-1 to baseline controller 13-2 or advanced controller 12 based on the above.

[0122] ≪Second Switching Process≫ The second switching process in this embodiment (step S15 in Figure 8) will be described with reference to Figure 10. Figure 10 is a flowchart showing an example of the second switching process in this embodiment.

[0123] In step S15-1, the decision module 14-2 of the control system 1 determines the switching condition C based on the state information output from the plant 11. 1-2 Whether or not the condition is met (in other words, switching condition C) 1-2 Determine the truth value of (C). Switching condition C 1-2 If this is true (YES), the decision module 14-2 proceeds to step S15-2. Meanwhile, the switching condition C 1-2 If the result is false (NO), the decision module 14-2 proceeds to step S15-4.

[0124] In step S15-2, the decision module 14-1 of the control system 1 determines the switching condition C based on the state information output from the plant 11. 2-1 Whether or not the condition is met (in other words, switching condition C) 2-1 Determine the truth value of (C). Switching condition C 2-1 If the condition is false (NO), the decision module 14-1 proceeds to step S15-3. Meanwhile, the switching condition C 2-1 If this is true (YES), the decision module 14-1 terminates the second switching process without switching the controller.

[0125] In step S15-3, the decision module 14-1 of the control system 1 switches control to the advanced controller 12. Thereafter, the plant 11 controls the operation of the autonomous vehicle according to the control strategy α executed by the advanced controller 12.

[0126] In step S15-4, the decision module 14-2 of the control system 1 switches control to the baseline controller 13-2. Thereafter, the plant 11 controls the operation of the autonomous vehicle according to the control strategy β2 executed by the baseline controller 13-2.

[0127] Let's return to Figure 8 for explanation. In step S16, the decision module 14-2 of the control system 1 executes the third switching process. The third switching process is performed under switching condition C 2-2This is the process of switching from baseline controller 13-2 to baseline controller 13-1 based on the above.

[0128] ≪Third Switching Process≫ The third switching process in this embodiment (step S16 in Figure 8) will be described with reference to Figure 11. Figure 11 is a flowchart showing an example of the third switching process in this embodiment.

[0129] In step S16-1, the decision module 14-2 of the control system 1 determines the switching condition C based on the state information output from the plant 11. 2-2 Whether or not the condition is met (in other words, switching condition C) 2-2 Determine the truth value of (C). Switching condition C 2-2 If the condition is false (NO), the decision module 14-2 proceeds to step S16-2. Meanwhile, the switching condition C 2-2 If this is true (YES), the decision module 14-2 terminates the third switching process without switching to the baseline controller 13-1.

[0130] In step S16-2, the decision module 14-2 of the control system 1 switches control to the baseline controller 13-1. Thereafter, the plant 11 controls the operation of the autonomous vehicle according to the control strategy β1 executed by the baseline controller 13-1.

[0131] Let's return to Figure 8 for explanation. In step S17, the plant 11 of the control system 1 determines whether or not to terminate automatic operation. If automatic operation is to be terminated (YES), the plant 11 terminates the control method processing. On the other hand, if automatic operation is not to be terminated (NO), the plant 11 returns processing to step S11.

[0132] If the process returns to step S11, the control system 1 controls the operation of the autonomous vehicle according to the control strategy executed by the controller selected by decision module 14-1 or decision module 14-2. The control system 1 then continues autonomous driving, switching control to the appropriate controller according to the state of the autonomous vehicle, until autonomous driving is terminated.

[0133] <Effects of the second embodiment> In this embodiment, the control system 1 uses state information indicating the state of the autonomous vehicle as a switching condition C. 1-2 When this condition is met, the baseline controller 13-1 is executed, and switching condition C 1-2 When the condition C is not met, a hierarchical baseline controller 15 is provided that performs control to execute baseline controller 13-2. 1-2 It is stipulated that certain safety conditions are met. Therefore, according to this embodiment, safety in autonomous driving can be guaranteed in a control system equipped with three or more controllers.

[0134] In this embodiment, the control system 1 uses state information indicating the state of the autonomous vehicle as a switching condition C. 2-2 If the condition is not met, control is performed to execute the baseline controller 13-1. Switching condition C 2-2 It is stipulated that certain safety conditions are met. Therefore, according to this embodiment, in a control system equipped with three or more controllers, control can be performed while ensuring safety in autonomous driving and taking performance indicators into consideration.

[0135] [supplement] Each of the embodiments described above can be implemented by one or more processing circuits. Hereinafter, "processing circuit" as used herein includes processors programmed to execute each function by software, such as processors implemented by electronic circuits, as well as devices such as ASICs (Application Specific Integrated Circuits), DSPs (Digital Signal Processors), FPGAs (Field Programmable Gate Arrays), and conventional circuit modules designed to execute each of the functions described above.

[0136] Although embodiments of the present invention have been described in detail above, the present invention is not limited to these embodiments, and various modifications or changes are possible within the scope of the gist of the present invention as described in the claims.

[0137] This application claims priority to Japanese Patent Application No. 2023-90138, filed with the Japan Patent Office on 31 May 2023, which is incorporated herein by reference to its entire contents. [Explanation of symbols]

[0138] 1. Control System 11 Plants 12 Advanced Controllers 13 Baseline Controller 14 Decision Modules 15-tiered baseline controller

Claims

1. A plant configured to control the operation of a controlled object and to output state information indicating the state of the controlled object, A first controller configured to instruct the plant to operate the controlled object in accordance with a first safety rule, A second controller configured to instruct the plant to operate the controlled object in accordance with the second safety rule, A decision module is configured to execute the first controller when the state information satisfies a first switching condition determined based on the first safety rule and the second safety rule, and to execute the second controller when the state information does not satisfy the first switching condition. Equipped with, The second safety rule stipulates that a control strategy for controlling the controlled object shall be executed when a predetermined precondition is true. The first switching conditions are determined such that the environmental assumptions, ex-conditions, and safety conditions derived based on the pre-conditions and the control strategy satisfy the prescribed contract. Control system.

2. A control system according to claim 1, The decision module is configured to execute the first controller when the state information no longer satisfies the second switching condition defined based on the second safety rule while the second controller is being executed. Control system.

3. A control system according to claim 2, The decision module is configured to execute the second controller when the state information no longer satisfies the third switching condition determined based on the safety conditions of the first safety rule while the first controller is being executed. Control system.

4. A control system according to claim 1, A third controller configured to instruct the plant to operate the controlled object in accordance with the third safety rule, A second decision module is configured to execute the second controller when the state information does not satisfy the first switching condition and satisfies the fourth switching condition determined based on the second safety rule and the third safety rule, and to execute the third controller when the state information does not satisfy the first switching condition and does not satisfy the fourth switching condition, A control system that also includes additional features.

5. A control system according to claim 4, The second decision module is configured to execute the second controller when the state information no longer satisfies the fifth switching condition determined based on the third safety rule while the third controller is being executed. Control system.

6. A control system according to any one of claims 1 to 5, The contract guarantees that, given the environmental assumptions, the ex-condition is true while the control strategy is being implemented, and the safety condition is true while the control strategy is being implemented, Control system.

7. A plant that controls the operation of a controlled object and outputs state information indicating the state of the controlled object, A first controller that instructs the plant to operate the controlled object in accordance with the first safety rule, A second controller that instructs the plant to operate the controlled object in accordance with the second safety rule, A control system equipped with: A procedure for executing the first controller when the state information satisfies the first switching conditions determined based on the first safety rule and the second safety rule, When the state information does not satisfy the first switching condition, the procedure for executing the second controller is as follows: Execute, The second safety rule stipulates that a control strategy for controlling the controlled object shall be executed when a predetermined precondition is true. The first switching conditions are determined such that the environmental assumptions, ex-conditions, and safety conditions derived based on the pre-conditions and the control strategy satisfy the prescribed contract. Control method.

8. A plant that controls the operation of a controlled object and outputs state information indicating the state of the controlled object, A first controller that instructs the plant to operate the controlled object in accordance with the first safety rule, A second controller that instructs the plant to operate the controlled object in accordance with the second safety rule, A control system equipped with: A procedure for executing the first controller when the state information satisfies the first switching conditions determined based on the first safety rule and the second safety rule, When the state information does not satisfy the first switching condition, the procedure for executing the second controller is as follows: Make it run, The second safety rule stipulates that a control strategy for controlling the controlled object shall be executed when a predetermined precondition is true. The first switching conditions are determined such that the environmental assumptions, ex-conditions, and safety conditions derived based on the pre-conditions and the control strategy satisfy the prescribed contract. program.

Citation Information

Patent Citations

  • Safe path planning method for mechatronic systems

    JP2023506652A