Vehicle, vehicle control method, and vehicle control interface box

The vehicle control interface box addresses the challenge of handling failures in autonomous driving by issuing appropriate commands and providing redundant control systems, ensuring safe and effective vehicle operation.

JP7861595B2Active Publication Date: 2026-05-19TOYOTA JIDOSHA KK
View PDF 7 Cites 0 Cited by

Patent Information

Authority / Receiving Office
JP · JP
Patent Type
Patents
Current Assignee / Owner
TOYOTA JIDOSHA KK
Filing Date
2022-10-04
Publication Date
2026-05-19

AI Technical Summary

Technical Problem

Existing autonomous driving systems lack the capability to create appropriate driving plans in response to failures that occur during autonomous operation, necessitating a solution to ensure safe and effective vehicle control.

Method used

A vehicle control interface box that interfaces between the autonomous driving system and the vehicle platform, capable of issuing requests for maintenance, returning to a base, or stopping the vehicle based on fault information, and incorporating redundant control systems to maintain functionality in case of failures.

Benefits of technology

Enables the autonomous driving system to issue appropriate commands for the vehicle to handle failures, ensuring safe and effective operation by maintaining or terminating services as needed, and allowing for evasive maneuvers when necessary.

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure 0007861595000083
    Figure 0007861595000083
  • Figure 0007861595000084
    Figure 0007861595000084
  • Figure 0007861595000085
    Figure 0007861595000085
Patent Text Reader

Abstract

To generate an appropriate travel plan in accordance with a failure occurring during an automatic operation.SOLUTION: In a case where a failure occurs (Yes for S102) during an automatic operation (Yes for S100), a VCIB executes processing including: a step of reporting a maintenance request after returning (S106), in a case where a service operation can be continued (Yes for S104); a step of cancelling the service operation and reporting a return request (S110) in a case where the service operation cannot be continued (No for S104), with the continued travel possible (Yes for S108); and a step of cancelling the service operation and reporting a stop request (S112) in a case where the continued travel is impossible (No for S108).SELECTED DRAWING: Figure 3
Need to check novelty before this filing date? Find Prior Art

Description

Technical Field

[0005]

[0001] The present disclosure relates to the control of a vehicle during autonomous driving.

Background Art

[0002] In recent years, the development of an autonomous driving system that runs a vehicle without requiring user operation has been underway. The autonomous driving system may be provided separately from the vehicle via an interface, for example, to be mounted on an existing vehicle.

[0003] As such an autonomous driving system, for example, Japanese Patent Application Laid-Open No. 2018-132015 (Patent Document 1) discloses a technique that can add an autonomous driving function without making major changes to an existing vehicle platform by separating an ECU (Electronic Control Unit) that manages the power of the vehicle from an ECU for autonomous driving.

Prior Art Documents

Patent Documents

[0004] <00000二十>

Patent Document 1

Summary of the Invention

Problems to be Solved by the Invention

Means for Solving the Problems

[0007] A vehicle relating to a certain aspect of this disclosure comprises an autonomous driving system and a vehicle platform on which the autonomous driving system is installed. The vehicle platform includes a base vehicle that performs vehicle control in accordance with commands from the autonomous driving system and a vehicle control interface box that interfaces between the base vehicle and the autonomous driving system. The vehicle control interface box notifies the autonomous driving system of one of the following: a first request requesting maintenance of the vehicle platform in response to fault information regarding a fault occurring within the vehicle platform; a second request requesting the vehicle platform to return to its base; or a third request requesting the vehicle to stop.

[0008] In this way, one of the notifications corresponding to the fault information from the first, second, or third request will be issued. As a result, the automated driving system can issue appropriate commands to the base vehicle so that it can perform the required actions on the vehicle that has experienced a malfunction.

[0009] In one embodiment, the vehicle control interface box notifies the automated driving system of a first request if the fault information includes information that the vehicle can continue to run and that the operation of services using the vehicle can be maintained.

[0010] In this way, when the first request is notified, the autonomous driving system can issue appropriate instructions to the base vehicle so that maintenance is performed when the vehicle returns to the base.

[0011] In one further embodiment, the vehicle control interface box notifies the automated driving system of a second request if the fault information includes information indicating that the vehicle can continue to run but the operation of services using the vehicle cannot be maintained.

[0012] In this way, if a second request is notified, the automated driving system can issue appropriate instructions to the base vehicle to halt service operations and return to the vehicle's base.

[0013] In one further embodiment, the vehicle control interface box notifies the automated driving system of a third request if the fault information includes information that the vehicle cannot continue to run and that the operation of services using the vehicle cannot be maintained.

[0014] In this way, if a third request is notified, the automated driving system can issue appropriate commands to the base vehicle to discontinue service and bring it to a stop.

[0015] In one further embodiment, the vehicle control interface box further notifies the autonomous driving system of loss information indicating whether or not the vehicle can move to a safer position during autonomous driving using the autonomous driving system.

[0016] In this way, the automated driving system can recognize whether or not the vehicle can move to an escape route based on the loss information, and can then issue appropriate commands to the base vehicle.

[0017] In one further embodiment, the vehicle control interface box includes a first control system and a second control system that is redundant to the first control system. The first control system does not notify the automated driving system that evasive driving is not possible if evasive driving using the second control system is not possible.

[0018] In this way, if evasive driving using the second control system is not possible, the information that evasive driving is not possible is notified from the first control system to the automated driving system, and therefore evasive driving can be performed using the first control system.

[0019] Furthermore, in one embodiment, the automated driving system uses either the first control system or the second control system, which is capable of evasive driving.

[0020] In this way, by using one of the systems capable of evasive maneuvers, evasive maneuvers can be performed.

[0021] A vehicle control method relating to another aspect of this disclosure is a vehicle control method comprising a vehicle platform equipped with an autonomous driving system. The vehicle platform includes a vehicle control interface box that interfaces between a base vehicle and the autonomous driving system. The control method includes the steps of performing vehicle control in accordance with a command from the autonomous driving system, and notifying the autonomous driving system of one of the following: a first request requesting maintenance of the vehicle platform in response to fault information relating to a fault occurring within the vehicle platform; a second request requesting the vehicle platform to return to a base; and a third request requesting the vehicle to stop.

[0022] A vehicle control interface box relating to yet another aspect of this disclosure is a vehicle control interface box that interfaces between an automated driving system and a base vehicle. The base vehicle performs vehicle control in accordance with commands from the automated driving system, and the base vehicle and the vehicle control interface box together constitute a vehicle platform provided on the vehicle together with the automated driving system. The vehicle control interface box notifies the automated driving system of one of the following: a first request requesting maintenance of the vehicle platform in response to fault information regarding a fault that has occurred within the vehicle platform; a second request requesting the vehicle platform to return to its base; or a third request requesting the vehicle to stop. [Effects of the Invention]

[0023] According to the present disclosure, it is possible to provide a vehicle, a vehicle control method, and a vehicle control interface box that can be equipped with an automatic driving system and create an appropriate driving plan in response to a failure occurring during automatic driving.

Brief Description of the Drawings

[0024] [Figure 1] It is a diagram showing an overview of a vehicle according to an embodiment of the present disclosure. [Figure 2] It is a diagram for explaining each configuration of ADS, VCIB, and VP in detail. [Figure 3] It is a flowchart showing an example of a process executed by VCIB. [Figure 4] It is a flowchart showing an example of a process executed by ADS.

Modes for Carrying Out the Invention

[0025] Hereinafter, embodiments of the present disclosure will be described in detail with reference to the drawings. In the drawings, the same or corresponding parts are denoted by the same reference numerals and their description will not be repeated.

[0026] FIG. 1 is a diagram showing an overview of a vehicle 10 according to an embodiment of the present disclosure. Referring to FIG. 1, the vehicle 10 includes an autonomous driving kit (hereinafter, referred to as "ADK (Autonomous Driving Kit)") 200 and a vehicle platform (hereinafter, referred to as "VP (Vehicle Platform)") 120. The ADK 200 and the VP 120 are configured to be able to communicate with each other via a vehicle control interface.

[0027] Vehicle 10 can perform automatic driving in accordance with control requests (commands) from ADK200 attached to VP120. In Figure 1, VP120 and ADK200 are shown in separate locations, but in reality, ADK200 is attached to the rooftop of the base vehicle 100, which will be described later. ADK200 can also be removed from VP120. If ADK200 is removed, VP120 can be driven by a user. In this case, VP120 performs driving control in manual mode (driving control according to user operation).

[0028] The ADK200 includes an autonomous driving system (hereinafter referred to as "ADS (Autonomous Driving System)") 202 for autonomous driving of the vehicle 10. For example, the ADS202 creates a driving plan for the vehicle 10 and outputs various commands (control requests) to the VP120 to drive the vehicle 10 according to the created driving plan, according to the API (Application Program Interface) defined for each command. The ADS202 also receives various signals indicating the status of the VP120 (vehicle status) from the VP120 according to the API defined for each signal, and reflects the received vehicle status in the creation of the driving plan. The detailed configuration of the ADS202 will be explained later.

[0029] VP120 includes a base vehicle 100 and a vehicle control interface box (hereinafter referred to as "VCIB (Vehicle Control Interface Box)") 111 that provides a vehicle control interface within the base vehicle 100.

[0030] The VCIB111 can communicate with the ADK200 via CAN (Controller Area Network), etc. The VCIB111 receives various commands from the ADK200 and outputs the status of the VP120 to the ADK200 by executing a predetermined API defined for each signal being communicated. In other words, when the VCIB111 receives a control request from the ADK202, it outputs a control command corresponding to that control request to the system corresponding to the control command via the integrated control manager 115. The VCIB111 also acquires various information about the base vehicle 100 from various systems via the integrated control manager 115 and outputs the status of the base vehicle 100 as the vehicle status to the ADK200.

[0031] VP120 includes various systems and sensors for controlling the base vehicle 100. Automated driving of the vehicle 10 is performed by VP120 executing various vehicle controls in accordance with control requests from ADK200 (more specifically, ADS202). VP120 includes, for example, a brake system 121, a steering system 122, a powertrain system 123, an active safety system 125, and a body system 126.

[0032] The braking system 121 is configured to control a plurality of braking devices provided on each wheel of the base vehicle 100. The braking devices include, for example, a disc brake system that operates using hydraulic pressure regulated by an actuator.

[0033] The brake system 121 includes, for example, a wheel speed sensor 127A. 127BThe following are connected. The wheel speed sensor 127A is installed, for example, on the front wheel of the base vehicle 100 and detects the rotational speed of the front wheel. The wheel speed sensor 127A outputs the rotational speed of the front wheel to the brake system 121. The wheel speed sensor 127B is installed, for example, on the rear wheel of the base vehicle 100 and detects the rotational speed of the rear wheel. The wheel speed sensor 127B outputs the rotational speed of the rear wheel to the brake system 121. The wheel speed sensors 127A and 127B output pulse signals as output values ​​(pulse values). The rotational speed can be calculated using the number of pulses in the pulse signal. The brake system 121 outputs the rotational speed of each wheel to the VCIB 111 as one of the pieces of information included in the vehicle state.

[0034] The brake system 121 generates a braking command for the braking device in accordance with a predetermined control request output from the ADK200 via the VCIB111 and the integrated control manager 115, and controls the braking device using the generated braking command.

[0035] The steering system 122 is configured to control the steering angle of the steering wheels of the vehicle 10 using a steering device. The steering device includes, for example, a rack-and-pinion type EPS (Electric Power Steering) in which the steering angle can be adjusted by an actuator.

[0036] A pinion angle sensor 128 is connected to the steering system 122. The pinion angle sensor 128 detects the rotation angle (pinion angle) of the pinion gear connected to the rotation axis of the actuator that constitutes the steering device. The pinion angle sensor 128 outputs the detected pinion angle to the steering system 122. The steering system 122 outputs the pinion angle to the VCIB 111 as one of the pieces of information included in the vehicle state.

[0037] The steering system 122 generates steering commands for the steering gear in accordance with predetermined control requests output from the ADK200 via the VCIB111 and the integrated control manager 115. The steering system 122 controls the steering gear using the generated steering commands.

[0038] The powertrain system 123 controls an EPB (Electric Parking Brake) provided on at least one of the multiple wheels of the vehicle 10, a P-Lock device provided on the transmission of the vehicle 10, a shift device configured to allow selection of any of multiple shift ranges, and the drive source of the vehicle 10. A detailed explanation will follow later.

[0039] The active safety system 125 uses the camera 129A and radar sensors 129B and 129C to detect obstacles (objects or people) in front of or behind the vehicle. If it determines that there is a possibility of collision based on the distance to the obstacle and the direction of movement of the vehicle 10, it outputs a braking command to the brake system 121 via the integrated control manager 115 to increase the braking force.

[0040] The body system 126 is configured to control components such as turn signals, horns, or wipers according to the driving conditions or driving environment of the vehicle 10, for example. The body system 126 controls the above-mentioned components according to predetermined control requests output from the ADK200 via the VCIB111 and the integrated control manager 115.

[0041] Vehicle 10 may be adopted as one component of a MaaS (Mobility as a Service) system. In addition to vehicle 10, the MaaS system further includes, for example, a data server, a Mobility Service Platform (hereinafter referred to as "MSPF (Mobility Service Platform)"), and autonomous driving-related mobility services (none of which are shown).

[0042] Vehicle 10 is further equipped with a Data Communication Module (DCM) (not shown) as a communication interface for wireless communication with the aforementioned data server. The DCM outputs various vehicle information, such as speed, location, and autonomous driving status, to the data server. The DCM also receives various data from mobility services, such as the MSPF and data server, for managing the operation of autonomous vehicles, including vehicle 10, in autonomous driving-related mobility services.

[0043] MSPF is a unified platform to which various mobility services are connected. In addition to autonomous driving-related mobility services, MSPF connects to various other mobility services not shown in the diagram (for example, various mobility services provided by ride-sharing companies, car-sharing companies, insurance companies, rental car companies, taxi companies, etc.). Various mobility services, including mobility services, can use the various functions provided by MSPF according to the service content by using APIs published on MSPF.

[0044] The autonomous driving-related mobility service provides mobility services using autonomous vehicles, including vehicle 10. The mobility service can obtain from MSPF, for example, driving control data of vehicle 10 that communicates with the data server, and information stored in the data server, using APIs published on MSPF. The mobility service also uses the above APIs to send data to MSPF, for example, data for managing autonomous vehicles, including vehicle 10.

[0045] Furthermore, MSPF has published APIs for utilizing various vehicle status and vehicle control data necessary for ADS development, and ADS operators can use the vehicle status and vehicle control data necessary for ADS development, which is stored on the data server, as described above APIs.

[0046] Figure 2 is a diagram illustrating the configurations of ADS202, VCIB111, and VP120 in detail. As shown in Figure 2, ADS202 includes a computer 210, an HMI (Human Machine Interface) 230, a recognition sensor 260, an attitude sensor 270, and a sensor cleaner 290.

[0047] During autonomous driving of the vehicle, the computer 210 acquires the surrounding environment, vehicle attitude, behavior, and position using various sensors described later, and also acquires the vehicle status from the VP120 via the VCIB111 described later, and sets the next action of the vehicle 10 (acceleration, deceleration, or turning, etc.). The computer 210 outputs various commands to the VCIB111 to realize the set next action of the vehicle. The computer 210 includes communication modules 210A and 210B. Each of the communication modules 210A and 210B is configured to communicate with the VCIB111.

[0048] The HMI230 provides information to the user and accepts user input during autonomous driving, driving requiring user intervention, or transitions between autonomous driving and driving requiring user intervention. The HMI230 is configured to be connectable to, for example, a touch panel display, display device, and other input / output devices such as control devices, which are installed on the base vehicle 100.

[0049] The recognition sensor 260 includes sensors for recognizing the environment around the vehicle 10, and is comprised of at least one of the following: LIDAR (Laser Imaging Detection and Ranging), millimeter-wave radar, and cameras.

[0050] LiDAR is a distance measuring device that measures distance by emitting pulsed laser light (infrared) and measuring the time it takes for the light to reflect off an object and return. Millimeter-wave radar is a distance measuring device that irradiates an object with short-wavelength radio waves and detects the radio waves that return from the object to measure the distance and direction to the object. The camera is located, for example, behind the rearview mirror inside the vehicle and is used to capture images of the area in front of the vehicle. Information acquired by the recognition sensor 260 is output to the computer 210. Image processing using artificial intelligence (AI) and an image processing processor on the images and videos captured by the camera makes it possible to recognize other vehicles, obstacles, or people in front of the vehicle.

[0051] The attitude sensor 270 includes sensors that detect the attitude, behavior, or position of the vehicle, and is composed of, for example, an IMU (Inertial Measurement Unit) or a GPS (Global Positioning System).

[0052] The IMU detects, for example, the acceleration of the vehicle in the longitudinal, lateral, and vertical directions, as well as the angular velocity of the vehicle in the roll, pitch, and yaw directions. The GPS detects the position of the vehicle 10 using information received from multiple GPS satellites orbiting the Earth. The information acquired by the attitude sensor 270 is output to the computer 210.

[0053] The sensor cleaner 290 is configured to remove dirt that accumulates on various sensors while the vehicle is in motion. For example, the sensor cleaner 290 removes dirt from camera lenses, laser and radio wave irradiation parts, etc., using cleaning fluid or wipers.

[0054] The VCIB111 includes the VCIB111A and the VCIB111B. Both the VCIB111A and VCIB111B incorporate a CPU (Central Processing Unit) and memory (including, for example, ROM (Read Only Memory) and RAM (Random Access Memory)), which are not shown in the diagram. The VCIB111A has equivalent functionality to the VCIB111B, but some of its connection destinations to the various systems that make up the VP120 are different.

[0055] VCIB111A and VCIB111B are communicated to communication modules 210A and 210B of computer 210, respectively. Furthermore, VCIB111A and VCIB111B are communicated to each other.

[0056] Each of the VCIB111A and VCIB111B relays various commands corresponding to control requests from the ADS202 and outputs them as control commands to the corresponding system of the VP120. More specifically, each of the VCIB111A and VCIB111B uses information such as programs stored in memory (e.g., APIs) to generate control commands used to control the corresponding system of the VP120 using various command instructions output from the ADS202 and outputs them to the corresponding system. In addition, each of the VCIB111A and VCIB111B relays vehicle information output from each system of the VP120 and outputs it to the ADS202 as vehicle status. The information indicating the vehicle status may be the same as the vehicle information, or it may be information extracted from the vehicle information that is used for processing executed by the ADS202.

[0057] By providing VCIB111A and VCIB111B, which have equivalent functions for the operation of some systems (e.g., brakes and steering), the control system between ADS202 and VP120 becomes redundant. Therefore, if any failure occurs in part of the system, the functions of VP120 (turning, stopping, etc.) can be maintained by appropriately switching control systems or shutting off the failed control system.

[0058] Brake system 121 includes brake systems 121A and 121B. Steering system 122 includes steering systems 122A and 122B. Powertrain system 123 includes EPB system 123A, P-Lock system 123B, and propulsion system 124.

[0059] The VCIB111A and several systems of the VP120, including the brake system 121A, steering system 122A, EPB system 123A, P-Lock system 123B, propulsion system 124, and body system 126, are interconnected via a communication bus so that they can communicate with each other.

[0060] Furthermore, the VCIB111B and the brake system 121B, steering system 122B, and P-Lock 123B, which are among the multiple systems of the VP120, are connected to each other via a communication bus so that they can communicate with one another.

[0061] Brake systems 121A and 121B are both configured to control multiple braking devices provided on each wheel of the vehicle. Brake system 121A may have the same functions as brake system 121B, or for example, one of them may be configured to independently control the braking force of each wheel during vehicle operation, while the other is configured to control the generation of the same braking force at each wheel during vehicle operation.

[0062] Brake systems 121A and 121B generate braking commands for the braking device according to control requests output from ADS202 via VCIB111A and VCIB111B, respectively. Brake systems 121A and 121B also control the braking device using the braking command generated in either brake system, and control the braking device using the braking command generated in the other brake system if a malfunction occurs in either brake system.

[0063] Both steering systems 122A and 122B are configured to control the steering angle of the steering wheels of the vehicle 10 using a steering device. Steering system 122A has similar functions to steering system 122B.

[0064] The steering systems 122A and 122B generate steering commands for the steering device according to control requests output from the ADS202 via VCIB111A and VCIB111B, respectively. Furthermore, the steering systems 122A and 122B control the steering device using the steering commands generated in either steering system, and if a malfunction occurs in either steering system, they control the steering device using the steering commands generated in the other steering system.

[0065] The EPB system 123A is configured to control the EPB. The EPB locks the wheels by the operation of actuators. For example, the EPB locks the wheels by using actuators to activate drum brakes for parking brakes, which are provided on some of the multiple wheels of the vehicle 10, or by using actuators that allow adjustment of the hydraulic pressure supplied to the braking device separately from the brake systems 121A and 121B to lock the wheels.

[0066] The EPB system 123A controls the EPB according to control requests output from the ADS202 via the VCIB111A.

[0067] The P-Lock system 123B is configured to allow control of the P-Lock device. The P-Lock device engages a projection at the tip of a parking lock pawl, whose position is adjusted by an actuator, with the teeth of a gear (lock gear) connected to a rotating element in the transmission of the vehicle 10. This fixes the rotation of the output shaft of the transmission and fixes the rotation of the drive wheels (hereinafter also referred to as "wheel fixing").

[0068] The P-Lock system 123B controls the P-Lock device according to control requests output from the ADS202 via the VCIB111A. For example, the P-Lock system 123B activates the P-Lock device when the control request output from the ADS202 via the VCIB111A includes a control request to set the shift range to the parking range (hereinafter referred to as the P range), and deactivates the P-Lock device when the control request includes a control request to set the shift range to something other than the P range.

[0069] The propulsion system 124 is configured to allow switching of the shift range using a shift device and to control the driving force of the vehicle 10 in the direction of movement of the vehicle 10 using a drive source. Switchable shift ranges include, for example, the P range, the neutral range (hereinafter referred to as the N range), the forward driving range (hereinafter referred to as the D range), and the reverse driving range (hereinafter referred to as the R range). The drive source includes, for example, a motor generator or an engine.

[0070] The propulsion system 124 controls the shift device and the drive source according to control requests output from the ADS202 via the VCIB111A. For example, if the control request output from the ADS202 via the VCIB111A includes a control request to set the shift range to the P range, the propulsion system 124 controls the shift device so that the shift range is set to the P range.

[0071] The active safety system 125 is communicated with the brake system 121A. As described above, the active safety system 125 uses the camera 129A and radar sensor 129B to detect obstacles (obstacles or people) ahead, and if it determines that there is a possibility of collision based on the distance to the obstacle, it outputs a braking command to the brake system 121A to increase the braking force.

[0072] The body system 126 controls components such as turn signals, horns, or wipers according to control requests output from the ADS202 via the VCIB111A.

[0073] Furthermore, the aforementioned braking system, steering system, EPB, P-Lock system, shift system, and drive source may be separately provided with operating devices that can be manually operated by the user.

[0074] The various commands corresponding to the control requests output from ADS202 to VCIB111 include a propulsion direction command requesting a shift range switch, a stationary command requesting the activation or deactivation of the EPB or P-Lock device, an acceleration command requesting the acceleration or deceleration of the vehicle 10, a tire steering angle command requesting the steering wheel steering angle, an autonomy command requesting a switch between autonomous mode and manual mode, and a stop command requesting the vehicle to be stopped or released from being stopped.

[0075] In a vehicle 10 having the above configuration, if, for example, the user operates the HMI 230 and an autonomous mode is selected as the autonomous state, autonomous driving is performed. As described above, during autonomous driving, the ADS 202 first creates a driving plan. The driving plan includes multiple plans regarding the operation of the vehicle 10, such as a plan to continue driving straight, a plan to turn left or right at a predetermined intersection along a predetermined driving route, or a plan to change the driving lane to a different lane from the one the vehicle is currently driving in.

[0076] The ADS202 extracts the controllable physical quantities (e.g., acceleration or deceleration, tire steering angle, etc.) necessary for the vehicle 10 to operate according to the created driving plan. The ADS202 divides the physical quantities for each API execution cycle. The ADS202 executes the API using the divided physical quantities and outputs various commands to the VCIB111. Furthermore, the ADS202 obtains the vehicle status (e.g., the actual direction of movement of the vehicle 10, the vehicle's fixed position, fault information, etc.) from the VP120 and recreates the driving plan that reflects the obtained vehicle status. In this way, the ADS202 enables the autonomous driving of the vehicle 10. Such an autonomously driven vehicle 10 can be used, for example, in transportation services that travel along a predetermined route while stopping at predetermined stops.

[0077] If a malfunction occurs in the autonomously driven vehicle 10 during the operation of such an autonomous transportation service, the autonomous driving system is required to create an appropriate subsequent driving plan in accordance with the malfunction.

[0078] Therefore, in this embodiment, VCIB111 notifies ADS202 of one of the following: a first request requesting maintenance of the vehicle 10 corresponding to fault information related to a fault that occurred in VP120; a second request requesting the vehicle to return to the base; or a third request requesting the vehicle to stop.

[0079] In this way, the fault information is used to send one of the first, second, or third requests corresponding to the fault information. As a result, the ADS202 can send an appropriate command to the base vehicle 100 so that the faulty vehicle 10 can perform the required actions.

[0080] The following describes the processes performed by VCIB111 (more specifically, VCIB111A) with reference to Figure 3. Figure 3 is a flowchart showing an example of the processes performed by VCIB111A. VCIB111A repeatedly performs the following processes, for example, at each API execution cycle. Note that the following explanation uses VCIB111A as the execution entity as an example, but the same processes are performed when VCIB111B is the execution entity. A detailed explanation of that will not be repeated.

[0081] In step 100 (hereinafter referred to as S), the VCIB111A determines whether or not the vehicle is in automatic driving mode. The VCIB111A determines that the vehicle is in automatic driving mode, for example, if the vehicle mode state is in automatic mode. The VCIB111A determines whether or not the vehicle mode state is in automatic mode based on the state of a flag indicating that the vehicle is in automatic mode. The flag indicating that the vehicle is in automatic mode is set to the ON state when the user makes an operation to the HMI230 to perform automatic driving, for example, and is set to the OFF state when the automatic mode is canceled and the vehicle switches to manual mode depending on the user's operation or driving conditions. If it is determined that the vehicle is in automatic driving mode (YES in S100), the process moves to S102.

[0082] In S102, VCIB111A determines whether a fault has occurred in VP120. VCIB111A acquires fault information from various systems within VP120, for example. Each system, such as the brake system and steering system mentioned above, performs fault diagnosis at appropriate intervals, and if a fault occurs, fault information is generated that includes information about the faulty part and the nature of the fault. The system that generates fault information transmits the generated fault information to VCIB111. VCIB111A determines that a fault has occurred in VP120 when it acquires fault information generated in any of the multiple systems connected to VCIB111A. If it is determined that a fault has occurred in VP120 (YES in S102), the process moves to S104.

[0083] In S104, VCIB111A determines whether or not it is possible to continue service operations. Service operations refer to the implementation of automated transportation services as described above. VCIB111A determines whether or not it is possible to continue service operations depending on the faulty part. For example, VCIB111A determines that it is possible to continue service operations if the faulty part is a predetermined first part, and determines that it is not possible to continue service operations if the faulty part is a second part different from the first part. The first part includes, for example, parts that do not hinder the continuation of service operations, such as interior lighting, sound systems, and air conditioning systems of the vehicle 10. The second part includes, for example, electrical equipment related to driving, including at least one of the powertrain system, steering system, and brake system. Alternatively, the second part includes lighting devices directed outwards from the vehicle, such as headlights, side marker lights, reverse lights, or taillights. If it is determined that it is possible to continue service operations (YES in S104), the process moves to S106.

[0084] In S106, VCIB111A notifies ADS202 of a maintenance request after returning. Specifically, VCIB111A sends an anomaly notification to ADS202 requesting that maintenance be performed to repair or replace any faulty parts upon returning to the VP120 base station. The anomaly notification can be of multiple types. Multiple values ​​are pre-set for each of the multiple types of anomaly notifications. For example, if the value indicating an anomaly notification is "0", it indicates that no fault has occurred and there are no requests due to a fault. Furthermore, if the value indicating an anomaly notification is "1", it indicates an anomaly notification requesting that maintenance be performed promptly after returning to the base station. Therefore, VCIB111A sets the anomaly notification to "1" and sends the set value indicating the anomaly notification to ADS202. The process then moves to S114. If it is determined that service operation cannot be continued (NO in S104), the process moves to S108.

[0085] In S108, VCIB111A determines whether VP120 can continue to run. For example, if the faulty part is a part of the electrical equipment corresponding to the second part mentioned above that includes electrical equipment related to running, VCIB111A determines that VP120 cannot continue to run. If it is determined that VP120 can continue to run (YES in S108), the process moves to S110.

[0086] In S110, VCIB111A notifies ADS202 of a request to discontinue service operation and return to base. Specifically, VCIB111A sends an abnormality notification to ADS202 requesting that VP120 discontinue service operation and return to its base. For example, if the value indicating the abnormality notification is "2", it indicates an abnormality notification requesting that VP120 discontinue service operation and return to its base. Therefore, VCIB111A sets "2" as the abnormality notification and sends the value indicating the set abnormality notification to ADS202. The process then moves to S114. If it is determined that continued driving is impossible (NO in S108), the process moves to S112.

[0087] In S112, VCIB111A terminates service operation and notifies ADS202 of a request to stop. Specifically, VCIB111A terminates service operation by VP120 and sends an abnormality notification to ADS202 requesting that VP120 stop in a location that does not obstruct other vehicles' traffic. For example, if the value indicating the abnormality notification is "3", it indicates an abnormality notification requesting that VP120 terminate service operation and stop safely. Therefore, VCIB111A sets "3" as the abnormality notification and sends the value indicating the set abnormality notification to ADS202. The process then moves to S114.

[0088] In S114, VCIB111A obtains the status of whether or not to perform an evasive maneuver using an automated control system. The status of whether or not to perform an evasive maneuver includes "evasive maneuver possible (no failure)", "evasive maneuver impossible (failure)", and "invalid" because the status is not yet determined, and a predetermined value is set according to the type. For example, if the value indicating the status of whether or not to perform an evasive maneuver is "0", it indicates that "evasive maneuver is possible (no failure)". If the value indicating the status of whether or not to perform an evasive maneuver is "1", it indicates that "evasive maneuver is impossible (failure)". Furthermore, if the value indicating the status of whether or not to perform an evasive maneuver is "2", it indicates that "invalid". VCIB111A obtains a value indicating the status of whether or not to perform an evasive maneuver from VCIB111B by requesting the status of whether or not to perform an evasive maneuver. Furthermore, if the entity executing the process shown in this flowchart is VCIB111B, VCIB111B requests VCIB111A to indicate whether or not to proceed with the escape maneuver. The process then proceeds to S116.

[0089] In S116, VCIB111A determines whether or not it is impossible to perform an evasive maneuver using an automated control system. If the value obtained from VCIB111B indicating the feasibility of evasive maneuvering is "1", VCIB111A determines that it is impossible to perform an evasive maneuver using an automated control system. If it is determined that it is impossible to perform an evasive maneuver using an automated control system (YES in S116), the process moves to S118.

[0090] In S118, VCIB111A prohibits changing the status of whether or not evacuation is possible to "a state where evacuation is impossible". The process then moves to S122. If it is determined that evacuation is not impossible by automatic driving using a separate control system (i.e., evacuation is possible) (NO in S116), the process moves to S120.

[0091] In S120, VCIB111A authorizes changing the status of whether or not to perform an escape maneuver to "an escape maneuver is not possible." The process then moves to S122.

[0092] In S122, VCIB111A sets the status of whether or not to perform an emergency escape maneuver depending on the fault that has occurred. If a fault has occurred that corresponds to a state where emergency escape is impossible, and if changing to a state where emergency escape is impossible is permitted, VCIB111A sets the value indicating the status of whether or not to perform an emergency escape to "1". On the other hand, if changing to a state where emergency escape is impossible is prohibited, VCIB111A sets a value other than "1" as the value indicating the status of whether or not to perform an emergency escape maneuver. The process then ends. Note that this process also ends if it is determined that the vehicle is not in autonomous driving mode (NO in S100) or if it is determined that no fault has occurred (NO in S102).

[0093] Next, with reference to Figure 4, the processes performed by ADS202 (more specifically, computer 210) in this embodiment will be described. Figure 4 is a flowchart showing an example of the processes performed by ADS202. ADS202 repeatedly performs the following processes, for example, at each API execution cycle.

[0094] In S200, ADS202 determines whether or not the vehicle is in autonomous driving mode. The method for determining whether or not autonomous driving is in mode is the same as described above, so a detailed explanation will not be repeated. If it is determined that the vehicle is in autonomous driving mode (YES in S200), the process moves to S202.

[0095] In S202, ADS202 acquires the status of whether or not to perform an emergency escape maneuver using the main control system. In this embodiment, ADS202 acquires information about the status of whether or not to perform an emergency escape maneuver from VCIB111A, for example.

[0096] In S204, ADS202 determines whether or not it is impossible to perform an evasive maneuver using the main control system's automated driving system. If the acquired value indicating the feasibility of the evasive maneuver is "1", ADS202 determines that it is impossible to perform an evasive maneuver using the main control system's automated driving system. If it is determined that an evasive maneuver is impossible (YES in S204), the process moves to S206.

[0097] In S206, ADS202 performs automatic operation using the sub-system control system. For example, ADS202 performs automatic operation using VCIB111B. If an emergency escape maneuver is required, it will be performed using VCIB111B. After that, the process is terminated. If it is determined that an emergency escape maneuver is possible using the main system control system (NO in S204), the process moves to S208.

[0098] In S208, ADS202 performs automatic operation using the main control system. ADS202 performs automatic operation using, for example, VCIB111A. If evasive maneuvers are required, they will be performed using VCIB111A. After that, the process is terminated. If it is determined that the vehicle is not in automatic operation mode (NO in S200), this process is terminated.

[0099] The operation of ADS202 and VCIB111 based on the structure and flowchart described above will be explained.

[0100] For example, let's assume that an automated transportation service using vehicle 10 is in operation. During automated operation (YES in S100), it is determined whether or not a malfunction has occurred in vehicle 10 (S102). For example, if the malfunction occurs in a part that does not hinder the driving of vehicle 10 or the operation of the service (YES in S102), the service operation can be continued (YES in S104), and an abnormality notification is sent from VCIB111A to ADS202 requesting maintenance after the vehicle returns (S106). That is, the value indicating an abnormality notification is set to "1", and the set value is sent from VCIB111A to ADS202. ADS202 may, for example, notify that maintenance is required when vehicle 10 returns to the base.

[0101] VCIB111A obtains information from VCIB111B regarding the feasibility of emergency maneuvering (S114). If emergency maneuvering using VCIB111B is possible (NO in S116), a change to an emergency maneuvering impossible state is permitted (S120), and the feasibility of emergency maneuvering is set according to the fault that occurred (S122). In the case of a fault in a part that does not interfere with the operation of vehicle 10 or service operations, the value "0" is set to indicate that emergency maneuvering is possible.

[0102] On the other hand, if a malfunction occurs in a part that would hinder service operation (YES in S102), it is not possible to continue service operation (NO in S104), so it is determined whether or not it is possible to continue driving (S108).

[0103] At this time, if it is determined that it is possible to continue driving (YES in S108), an abnormality notification is sent from VCIB111A to ADS202 requesting that the service operation be stopped and the vehicle return (S110). In other words, the value "2" is set to indicate an abnormality notification, and the set value VCIB111A It is sent from to ADS202.

[0104] VCIB111A obtains information from VCIB111B regarding the feasibility of emergency maneuvers (S114). For example, if emergency maneuvers using VCIB111B are not possible (YES in S116), changing the state to one where emergency maneuvers are not possible is prohibited (S118). At this time, when the feasibility of emergency maneuvers is set according to the fault that occurred (S122), the value "0" is maintained as the value indicating that emergency maneuvers are possible. ADS202 ceases service operations and returns to the base by timed operation.

[0105] Furthermore, if a malfunction occurs (YES in S102), service operation cannot be continued (NO in S104), and it is determined that continued driving is impossible (NO in S108), an abnormality notification is issued requesting that service operation be stopped and vehicle 10 be brought to a halt (S112). In other words, "3" is set as the value indicating the abnormality notification, and the set value is transmitted from VCIB111A to ADS202.

[0106] VCIB111A obtains information from VCIB111B regarding the feasibility of emergency maneuvering (S114). If emergency maneuvering using VCIB111B is possible (NO in S116), a change to an emergency maneuvering impossible state is permitted (S120), and the emergency maneuvering feasibility state is set according to the fault that occurred (S122). In this case, for example, it is set to a value of "1" which indicates that emergency maneuvering is impossible.

[0107] Note that the system using VCIB111B Status of whether or not it is possible to move to an evacuation location. If the vehicle is in a state where it cannot move to an escape route (YES in S116), changing the state to one where it cannot move to an escape route is prohibited (S118). Therefore, the status of whether or not it can move to an escape route is set to the value "0", which indicates that it can move to an escape route (S122). Accordingly, the ADS202 uses the VCIB111A to create a driving plan to stop the vehicle 10 in a position that does not obstruct traffic, and performs vehicle control according to the created driving plan.

[0108] As described above, the vehicle 10 according to this embodiment issues an abnormality notification corresponding to one of the following malfunctions: a maintenance request after returning (first request), a request to suspend service operation and return (second request), or a request to suspend service operation and stop (third request). Therefore, the ADS202 can issue appropriate commands to the base vehicle 100 so that the malfunctioning vehicle 10 can perform the required actions. Thus, it is possible to provide a vehicle that can be equipped with an automated driving system and that creates an appropriate driving plan in response to malfunctions that occur during automated driving, as well as a vehicle control method and a vehicle control interface box.

[0109] Furthermore, if an abnormality notification is issued in response to a maintenance request after the vehicle returns, the ADS202 can issue an appropriate command to the base vehicle 100 so that maintenance is performed when the base vehicle 100 returns to the base.

[0110] Furthermore, if an abnormality notification is issued requesting the suspension of service operations and a return, the ADS202 can issue appropriate instructions to the base vehicle 100 to suspend service operations and return to the VP120 base.

[0111] Furthermore, if an abnormal notification is issued requesting the suspension of service and a stop, the ADS202 can issue appropriate instructions to the base vehicle 100 to suspend service and stop in a location that does not obstruct traffic.

[0112] Furthermore, since the ADS202 is notified of the feasibility of evasive driving during autonomous driving as failure information, the ADS202 can obtain information on whether all or part of the VP120's functions are in a failure state, and can perform actions according to the failure state.

[0113] Furthermore, since VCIB111A in the main control system and VCIB111B in the sub-control system do not simultaneously notify ADS202 that evasive maneuvers are impossible, even if evasive maneuvers are impossible in one of the control systems, it is possible to perform evasive maneuvers using automated driving with the other control system.

[0114] Furthermore, the ADS202 can perform an automated escape maneuver by using the control system that is in a state where escape maneuvering is possible.

[0115] In the above-described embodiment, the first requirement was described as a request to perform maintenance after the VP120 returns to the base. However, it is also possible to request that maintenance be performed at a maintenance facility different from the base between the end of service operation and the return to the base.

[0116] The embodiments disclosed herein should be considered in all respects to be illustrative and not restrictive. The scope of the present invention is indicated by the claims rather than by the foregoing description, and all modifications within the meaning and scope equivalent to the claims are intended to be included. TIFF0007861595000001.tif208144

[0117] TIFF0007861595000002.tif208147

[0118] TIFF0007861595000003.tif208144

[0119] TIFF0007861595000004.tif208144

[0120] TIFF0007861595000005.tif208147

[0121] TIFF0007861595000006.tif208147

[0122] TIFF0007861595000007.tif208144

[0123] TIFF0007861595000008.tif208144

[0124] TIFF0007861595000009.tif208144

[0125] TIFF0007861595000010.tif208144

[0126] TIFF0007861595000011.tif208144

[0127] TIFF0007861595000012.tif208144

[0128] TIFF0007861595000013.tif208144

[0129] TIFF0007861595000014.tif208144

[0130] TIFF0007861595000015.tif208144

[0131] TIFF0007861595000016.tif208144

[0132] TIFF0007861595000017.tif208144

[0133] TIFF0007861595000018.tif208144

[0134] TIFF0007861595000019.tif208144

[0135] TIFF0007861595000020.tif208144

[0136] TIFF0007861595000021.tif208144

[0137] TIFF0007861595000022.tif208144

[0138] TIFF0007861595000023.tif208144

[0139] TIFF0007861595000024.tif208146

[0140] TIFF0007861595000025.tif208144

[0141] TIFF0007861595000026.tif208146

[0142] TIFF0007861595000027.tif208144

[0143] TIFF0007861595000028.tif208144

[0144] TIFF0007861595000029.tif208144

[0145] TIFF0007861595000030.tif208144

[0146] TIFF0007861595000031.tif208146

[0147] TIFF0007861595000032.tif208146

[0148] TIFF0007861595000033.tif208144

[0149] TIFF0007861595000034.tif208144

[0150] TIFF0007861595000035.tif208144

[0151] TIFF0007861595000036.tif208144

[0152] TIFF0007861595000037.tif208144

[0153] TIFF0007861595000038.tif208144

[0154] TIFF0007861595000039.tif208144

[0155] TIFF0007861595000040.tif208144

[0156] TIFF0007861595000041.tif208144

[0157] TIFF0007861595000042.tif208144

[0158] TIFF0007861595000043.tif208144

[0159] TIFF0007861595000044.tif208144

[0160] TIFF0007861595000045.tif208144

[0161] TIFF0007861595000046.tif208144

[0162] TIFF0007861595000047.tif208144

[0163] TIFF0007861595000048.tif208144

[0164] TIFF0007861595000049.tif208144

[0165] TIFF0007861595000050.tif208144

[0166] TIFF0007861595000051.tif208144

[0167] TIFF0007861595000052.tif208144

[0168] TIFF0007861595000053.tif208144

[0169] TIFF0007861595000054.tif208144

[0170] TIFF0007861595000055.tif208144

[0171] TIFF0007861595000056.tif208144

[0172] TIFF0007861595000057.tif208144

[0173] TIFF0007861595000058.tif208144

[0174] TIFF0007861595000059.tif208144

[0175] TIFF0007861595000060.tif208144

[0176] TIFF0007861595000061.tif208144

[0177] TIFF0007861595000062.tif208144

[0178] TIFF0007861595000063.tif208144

[0179] TIFF0007861595000064.tif208144

[0180] TIFF0007861595000065.tif208144

[0181] TIFF0007861595000066.tif208144

[0182] TIFF0007861595000067.tif208144

[0183] TIFF0007861595000068.tif208144

[0184] TIFF0007861595000069.tif208144

[0185] TIFF0007861595000070.tif208144

[0186] TIFF0007861595000071.tif208144

[0187] TIFF0007861595000072.tif208144

[0188] TIFF0007861595000073.tif208144

[0189] TIFF0007861595000074.tif208144

[0190] TIFF0007861595000075.tif208144

[0191] TIFF0007861595000076.tif208144

[0192] TIFF0007861595000077.tif208144

[0193] TIFF0007861595000078.tif208147

[0194] TIFF0007861595000079.tif208144

[0195] TIFF0007861595000080.tif208144

[0196] TIFF0007861595000081.tif208144

[0197] TIFF0007861595000082.tif208144 [Explanation of symbols]

[0198] 10 Vehicle, 100 Base Vehicle, 111,111A,111B VCIB, 115 Integrated Control Manager, 120 VP, 121,121A,121B Brake System, 122,122A,122B Steering System, 123 Powertrain System, 123A EPB System, 123B P-Lock System, 124 Propulsion System, 125 Active Safety System, 126 Body System, 127A,127B Wheel Speed ​​Sensor, 128 Pinion Angle Sensor, 129A Camera, 129B,129C Radar Sensor, 200 ADK, 202 ADS, 210 Computer, 210A,210B Communication Module, 260 Recognition Sensor, 270 Attitude Sensor, 290 Sensor Cleaner.

Claims

1. Autonomous driving system and, The vehicle platform is equipped with the aforementioned autonomous driving system. The aforementioned vehicle platform is A base vehicle that performs vehicle control in accordance with commands from the aforementioned automated driving system, It includes a vehicle control interface box that provides an interface between the base vehicle and the autonomous driving system, The aforementioned vehicle control interface box is The automated driving system is notified of one of the following: a first request requesting maintenance of the vehicle platform in response to fault information regarding a malfunction that occurred within the vehicle platform at the vehicle platform base; a second request requesting the vehicle platform to return to the base; or a third request requesting the vehicle to stop. A vehicle that notifies the automated driving system of the first request if the fault information includes information that the vehicle can continue to run and that the operation of the service using the vehicle can be maintained.

2. The vehicle according to claim 1, wherein the vehicle control interface box notifies the automated driving system of the second request when the fault information includes information that the vehicle can continue to run but the operation of the service using the vehicle cannot be maintained.

3. The vehicle according to claim 1, wherein the vehicle control interface box notifies the automated driving system of the third request when the fault information includes information that the vehicle cannot continue to run and that the operation of the service using the vehicle cannot be maintained.

4. The vehicle according to claim 1, wherein the vehicle control interface box further notifies the autonomous driving system of loss information indicating whether or not the vehicle is able to move to a safe location during autonomous driving using the autonomous driving system.

5. The vehicle according to claim 4, wherein the vehicle control interface box comprises a first control system and a second control system provided as a redundancy of the first control system, and the first control system does not notify the automatic driving system of the information that the escape driving is not possible when the escape driving using the second control system is not possible.

6. The vehicle according to claim 5, wherein the automated driving system uses either the first control system or the second control system that is capable of the evasive driving.

7. A method for controlling a vehicle having a vehicle platform equipped with an autonomous driving system, wherein the vehicle platform includes a vehicle control interface box that provides an interface between a base vehicle and the autonomous driving system, The steps include: executing vehicle control in accordance with commands from the aforementioned automated driving system; The steps include notifying the automated driving system of one of the following: a first request requesting maintenance of the vehicle platform in response to fault information regarding a malfunction that occurred within the vehicle platform at the vehicle platform base; a second request requesting the vehicle platform to return to the base; and a third request requesting the vehicle to stop. A vehicle control method comprising the step of notifying the automated driving system of the first request if the fault information includes information that the vehicle can continue to run and that the operation of the service using the vehicle can be maintained.

8. A vehicle control interface box that provides an interface between an autonomous driving system and a base vehicle, wherein the base vehicle performs vehicle control according to commands from the autonomous driving system, and the base vehicle and the vehicle control interface box together constitute a vehicle platform provided on the vehicle together with the autonomous driving system. The aforementioned vehicle control interface box is The automated driving system is notified of one of the following: a first request requesting maintenance of the vehicle platform in response to fault information regarding a malfunction that occurred within the vehicle platform at the vehicle platform base; a second request requesting the vehicle platform to return to the base; or a third request requesting the vehicle to stop. A vehicle control interface box that notifies the automated driving system of the first request when the fault information includes information that the vehicle can continue to run and that the operation of the service using the vehicle can be maintained.