vehicle
A dual-control unit system with backup RAM ensures autonomous vehicles maintain automatic mode after computer restarts, addressing mode reversion issues.
Patent Information
- Authority / Receiving Office
- JP · JP
- Patent Type
- Patents
- Current Assignee / Owner
- TOYOTA JIDOSHA KK
- Filing Date
- 2023-06-30
- Publication Date
- 2026-05-19
AI Technical Summary
Autonomous driving vehicles may revert to manual mode upon computer restart due to temporary shutdowns, preventing continued operation in automatic mode.
Implement a vehicle platform with dual control units and a vehicle control interface box that records operating mode information in backup RAM, allowing seamless transition back to automatic mode after computer restarts.
Ensures the vehicle continues operating in automatic mode post-restart, enhancing system robustness and safety by preventing mode reversion to manual.
Smart Images

Figure 0007861703000001 
Figure 0007861703000002 
Figure 0007861703000003
Abstract
Description
Technical Field
[0004] , , , , ,
[0005] , , ,
[0001] This disclosure relates to a vehicle capable of autonomous driving.
Background Art
[0002] Japanese Unexamined Patent Application Publication No. 2019-177807 (Patent Document 1) discloses a vehicle with an autonomous driving kit attached to the rooftop.
Prior Art Documents
Patent Documents
[0003]
Patent Document 1
Summary of the Invention
Problems to be Solved by the Invention
[0004] As an autonomous driving vehicle, a vehicle that can operate in both an automatic mode and a manual mode has been proposed. For example, in a vehicle operating in the manual mode (manual driving), it is conceivable that the user can switch to the automatic mode (autonomous driving) as needed. Such a vehicle operates in the manual mode in the initial state, and when the user switches to the automatic mode, it starts operating in the automatic mode. Therefore, when a computer that manages the operation mode of the vehicle temporarily stops due to some reason (for example, an internal abnormality or a power supply abnormality of the computer) while the vehicle is operating in the automatic mode, there may arise a problem that the operation mode of the vehicle returns to the manual mode after the computer restarts, and the vehicle cannot continue to operate in the automatic mode.
[0005] This disclosure has been made to solve the above problems, and an object thereof is to enable the vehicle to continue operating in the automatic mode after the computer restarts when a computer that manages the operation mode of the vehicle temporarily stops due to some reason while the vehicle is operating in the automatic mode. [Means for solving the problem]
[0006] A vehicle according to one embodiment of the present disclosure comprises a vehicle platform and an autonomous driving kit that transmits commands for autonomous driving to the vehicle platform. The vehicle platform comprises a base vehicle including a first control unit. The autonomous driving kit comprises a second control unit that determines commands relating to autonomous driving control. The vehicle platform further comprises a vehicle control interface box including a first computer. The first computer is configured to communicate with both the first and second control units. The first computer is configured to detect an operating mode selected from a choice including an automatic mode in which the vehicle platform is under the control of the autonomous driving kit and a manual mode in which the vehicle is under the control of a driver, and to record operating mode information indicating the detected operating mode. The first control unit is configured to control the vehicle according to the operating mode detected by the vehicle control interface box. The first computer is configured to detect a selected operating mode upon restart based on the operating mode information recorded immediately before stopping. [Effects of the Invention]
[0007] According to this disclosure, if the computer that manages the vehicle's operating mode is temporarily shut down for any reason while the vehicle is operating in automatic mode, the vehicle will be able to continue operating in automatic mode after the computer is restarted. [Brief explanation of the drawing]
[0008] [Figure 1] This figure shows the schematic configuration of a vehicle according to an embodiment of the present disclosure. [Figure 2] Figure 1 is a diagram illustrating the configuration and function of the vehicle control interface box shown. [Figure 3] This is a flowchart showing a method for managing operating modes according to an embodiment of the present disclosure. [Figure 4]This is a time chart showing a first example of the operation of a vehicle according to an embodiment of the present disclosure. [Figure 5] This is a time chart showing a second example of the operation of a vehicle according to the embodiment of this disclosure. [Figure 6] This is a time chart showing a third example of the operation of a vehicle according to the embodiment of this disclosure. [Modes for carrying out the invention]
[0009] The embodiments of this disclosure will be described in detail below with reference to the drawings. In the drawings, the same or corresponding parts are denoted by the same reference numerals, and their descriptions will not be repeated.
[0010] Figure 1 is a diagram showing the schematic configuration of a vehicle according to an embodiment of the present disclosure. Referring to Figure 1, vehicle 1 comprises a VP (vehicle platform) 100 and an ADK (autonomous driving kit) 200. The VP 100 includes a VCIB (vehicle control interface box) 110 and a base vehicle 120. By adding the VCIB 110 to the base vehicle 120, a VP 100 is formed to which the ADK 200 can be attached and detached. Then, by attaching the ADK 200 to the VP 100, vehicle 1 is completed. The base vehicle 120 is, for example, a commercially available xEV (electric vehicle). In this embodiment, a BEV (battery electric vehicle) is used as the base vehicle 120. However, it is not limited to this, and the base vehicle 120 may be an xEV other than a BEV. In this embodiment, the ADK 200 is attached to the rooftop of the base vehicle 120. However, the mounting position of the ADK 200 can be changed as appropriate.
[0011] ADK200 includes an automated driving system (hereinafter referred to as "ADS") 210 that performs various processes related to automated driving. ADS210 includes a computer assembly (hereinafter referred to as "ADSCOM") 211, a recognition sensor 212, a posture sensor 213, a sensor cleaner 216, and an HMI (Human Machine Interface) 218.
[0012] ADSCOM211 includes computer modules (hereinafter referred to as "ADC") 211A and 211B. Each of ADC211A and 211B includes a processor and a storage device for storing autonomous driving software using the API described later, and is configured so that the autonomous driving software can be executed by the processor. Recognition sensors 212 include sensors that acquire information indicating the external environment of vehicle 1 (hereinafter also referred to as "environmental information"). Recognition sensors 212 may include at least one of a camera, millimeter-wave radar, and lidar. Attitude sensors 213 acquire information regarding the attitude of vehicle 1 (hereinafter also referred to as "attitude information"). Attitude sensors 213 may include various sensors that detect the acceleration, angular velocity, and position of vehicle 1. HMI218 includes an input device and a notification device.
[0013] The base vehicle 120 includes a brake system 121, a steering system 122, a powertrain system 123, an active safety system 125, and a body system 126. In this embodiment, each system is equipped with an electronic control unit (hereinafter also referred to as "ECU").
[0014] The VCIB110 is configured to communicate with both the base vehicle 120 and the ADK200 via a communication bus. These physical communications may utilize CAN (Controller Area Network). In vehicle 1, the control system for the vehicle's behavior (driving, stopping, turning) has redundancy. ADC211A and 211B give instructions to the main control system and sub-control system, respectively. The VCIB110 includes a control unit for the main control system (hereinafter referred to as "first VCIB") 111A and a control unit for the sub-control system (hereinafter referred to as "second VCIB") 111B. As will be described in detail later, in this embodiment, each control unit is equipped with a computer.
[0015] The brake system 121 includes a braking mechanism, an operating unit that receives brake operations from the driver, and brake control units 121A and 121B. The steering system 122 includes a steering mechanism, an operating unit that receives steering operations from the driver, and steering control units 122A and 122B. The powertrain system 123 includes a shift device, a vehicle drive device, an EPB device, a P-Lock device, an EPB control unit 123A, a P-Lock control unit 123B, and a propulsion control unit 123C. "EPB" stands for electric parking brake, and "P-Lock" stands for parking lock. The shift device determines the shift range and switches the propulsion direction and shift mode of the base vehicle 120 according to the determined shift range. In addition to the shift mechanism, the shift device further includes an operating unit that receives shift operations from the driver. The vehicle drive device applies propulsion force in the propulsion direction indicated by the shift range. The vehicle drive device includes a drive battery and a drive motor that receives power from the drive battery. The vehicle drive system further includes an accelerator pedal operated by the driver to accelerate the vehicle 1. The P-Lock device further includes a parking lock mechanism and actuator, as well as an operating unit that accepts parking commands from the driver.
[0016] Figure 2 is a diagram illustrating the configuration and function of the VCIB110. Referring to Figure 2, the first VCIB111A comprises a control microcomputer (control microcontroller) 11 and an ASIC (Application Specific Integrated Circuit) 12.
[0017] The control microcomputer 11 includes a processor 11a and a storage device 11b. The control microcomputer 11 receives power supply from the battery 20. The battery 20 may be a drive battery included in the vehicle drive device described above, or may be an in-vehicle battery other than the drive battery (for example, an auxiliary machine battery). A DC / DC converter may be provided between the control microcomputer 11 and the battery 20. The storage device 11b is, for example, a backup RAM (Random Access Memory). The backup RAM is generally also referred to as "standby RAM" or "Retention RAM". The backup RAM receives power supply from a backup power source. The backup RAM may be an NVSRAM (Non-Volatile SRAM) in which non-volatility is imparted to an SRAM (Static RAM) by the backup power source. The backup power source may be the battery 20, or may be an in-vehicle battery other than the battery 20. A capacitor for supplying power to the storage device 11b at the time of momentary interruption of the backup power source may be provided.
[0018] The ASIC 12 includes a WDC (Watchdog Timer Circuit). The WDC is configured to detect a periodic clock signal input from the control microcomputer 11 and monitor the normal operation of the control microcomputer 11. When the clock signal is not input to the ASIC 12 within the timer period, the ASIC 12 (WDC) determines that the control microcomputer 11 is operating abnormally and outputs a reset signal to the control microcomputer 11. The control microcomputer 11 that receives the reset signal turns off the power and restarts after reset (microcomputer reset). The control microcomputer 11 and the ASIC 12 perform mutual SPI (Serial Peripheral Interface) communication. The SPI communication is a synchronous serial communication that communicates data in synchronization with a clock. The control microcomputer 11 transmits a TTF (Time To Fail) signal to the ASIC 12 by SPI communication. The ASIC 12 transmits counter reset information to the control microcomputer 11 by SPI communication.
[0019] The second VCIB 111B also includes a control microcomputer (control microcomputer) 21 for control that conforms to the control microcomputer 11. The control microcomputer 21 includes a processor and a storage device. The control microcomputer 21 also receives power supply from, for example, the battery 20, similar to the control microcomputer 11. The control microcomputer 11 and the control microcomputer 21 perform CAN communication with each other. Further, each of the control microcomputers 11 and 21 is configured to be capable of performing CAN communication with both the base vehicle 120 and the ADK 200. In this embodiment, various control devices included in the base vehicle 120 function as the "first control device" according to the present disclosure, either individually or in cooperation. Each of the ADCs 211A and 211B functions as the "second control device" according to the present disclosure. Also, the control microcomputers 11 and 21 respectively correspond to examples of the "first computer" and the "second computer" according to the present disclosure.
[0020] In this embodiment, signals (API signals) defined by an API (Application Program Interface) are used for communication between the ADK 200 and the VCIB 110. The ADK 200 is configured to process various signals defined by the API. The ADK 200 outputs various commands to the VCIB 110 according to the API. Hereinafter, each of the various commands output from the ADK 200 to the VCIB 110 is also referred to as an "API command". The API command includes a command related to autonomous driving control. The ADK 200 (ADCs 211A and 211B) determines the value of the API command. Also, the ADK 200 receives various signals indicating the state of the base vehicle 120 from the VCIB 110 according to the above API. Hereinafter, each of the various signals received by the ADK 200 from the VCIB 110 is also referred to as an "API status". Both the API command and the API status correspond to the API signal.
[0021] In this embodiment, the ADK 200 uses the API commands described below.
[0022] The Vehicle Mode command is an API command that requests a transition to automatic or manual mode. The ADK200 can select the operating mode (vehicle mode) of vehicle 1 using the Vehicle Mode command. The Drive Direction command is an API command that requests a switch in the shift range (R / D). The Acceleration command is an API command that specifies the acceleration of the vehicle. The Acceleration command requests acceleration (+) and deceleration (-) in the direction indicated by the Drive Direction status described later. The Immobilization command is an API command that requests the application or release of immobilization. Applying immobilization means turning the EPB ON (operating) and setting the shift range to P (parking).
[0023] The above describes some of the API commands used in vehicle 1. The VCIB110 receives various API commands from the ADK200. When the VCIB110 receives an API command from the ADK200, it converts that API command into a signal format that can be executed by the control unit of the base vehicle 120. Hereinafter, the API command converted into a signal format that can be executed by the control unit of the base vehicle 120 will also be referred to as an "internal command". When the VCIB110 receives an API command from the ADK200, it outputs an internal command corresponding to that API command to the base vehicle 120.
[0024] Next, let's discuss API status. ADK200 uses API status, as described below, to understand the status of the base vehicle 120.
[0025] The Vehicle Mode Status is an API status that indicates the vehicle mode state. The operating modes (vehicle modes) of Vehicle 1 include manual mode, automatic mode, and standby mode. Manual mode is an operating mode in which the vehicle is under the control of a driver (human). Automatic mode is an operating mode in which the vehicle platform (including the base vehicle) is under the control of an autonomous driving kit. Standby mode is an operating mode in which the movement of the vehicle is prohibited. The driver can select the desired operating mode through the onboard HMI. The base vehicle 120 selects the operating mode considering the status of Vehicle 1 and the driver's selection. The Vehicle Mode Status outputs the corresponding values "0", "1", and "2" depending on whether the current operating mode is manual mode, automatic mode, or standby mode, respectively.
[0026] The forward direction status is an API status indicating the current shift range. The direction of travel status is an API status indicating the direction of travel of the vehicle. The direction of travel status outputs a value of "0" when the vehicle is moving forward, a value of "1" when the vehicle is moving backward, and a value of "2 (Standstill)" when all wheels (4 wheels) continuously show a speed of "0" for a predetermined period of time. The vehicle speed status is an API status indicating the longitudinal speed of the vehicle. The vehicle speed status outputs the absolute value of the vehicle speed. The immobilized status is an API status indicating the immobilized state.
[0027] The above describes some of the API statuses used in vehicle 1. The VCIB110 receives various sensor detection values and status determination results from the base vehicle 120 and outputs various API statuses indicating the status of the base vehicle 120 to the ADK200. The VCIB110 acquires an API status with a value indicating the status of the base vehicle 120 and outputs the obtained API status to the ADK200.
[0028] Vehicle 1 further includes a start switch 30 that accepts user operation to switch the operation / stop of the VP100 control system (including control microcontrollers 11 and 21, and various ECUs of the base vehicle 120). Generally, a vehicle start switch is called a "power switch" or "ignition switch". By operating the start switch 30, the VP100 control system is switched on (operated) / off (stopped). Also, when the control system is shut down, the start switch 30 is in the off state. In this embodiment, the on (closed) / off (open) state of an ignition relay (IGR) (not shown) is switched according to the state (operated / stopped) of the start switch 30. The control microcontroller 11 is configured to detect the state of the start switch 30 (state of the IGR) and its own operating state. Hereinafter, the information indicating the operating state of the control microcontroller 11 is referred to as "internal IGR". The control microcontroller 11 acquires the internal IGR sequentially. When the control microcontroller 11 is powered on, the internal IGR indicates on (operating state). When the control microcontroller 11 is in the shutdown process or powered off, the internal IGR indicates off (stopped state). When the start switch 30 is turned on, the control microcontroller 11 starts up and powers on. When the start switch 30 is turned off, the control microcontroller 11 starts the shutdown process, and when the shutdown process is complete, the control microcontroller 11 powers off.
[0029] In this embodiment, the interface computer (hereinafter referred to as "IFCOM") included in the VCIB110 detects the selected operating mode from a selection of multiple operating modes (e.g., manual mode, automatic mode, and standby mode) and outputs it to the base vehicle 120. The control microcontroller 11 selects either the control microcontroller 11 or the control microcontroller 21 as the IFCOM. The IFCOM converts API commands from the ADK200 into internal commands and outputs the obtained internal commands, along with the operating mode, to the base vehicle 120. The IFCOM obtains the API status using vehicle information from the base vehicle 120 and outputs the obtained API status to the ADK200. The operating mode is selected, for example, by the user, the base vehicle 120, or the ADK200. Alternatively, an external server may switch the operating mode of vehicle 1 as needed. The control device of the base vehicle 120 controls vehicle 1 according to the operating mode detected by the IFCOM.
[0030] The control microcontroller 11 periodically detects the selected operating mode and the state of the start switch 30 (operated / stopped). Each time an operating mode is detected, the control microcontroller 11 records operating mode information indicating the detected operating mode in the storage device 11b. When the control microcontroller 11 is restarted, it detects the selected operating mode based on the operating mode information recorded immediately before stopping. If both the detected state of the start switch 30 indicates operation (first requirement) and the detected operating mode is automatic mode (second requirement) are met, the control microcontroller 11 records predetermined information (history information) in the storage device 11b. If at least one of the first and second requirements is not met, the control microcontroller 11 erases the history information in the storage device 11b. The history information may also be recorded by polling. Hereinafter, the state in which the storage device 11b stores history information will be referred to as "history ON," and the state in which the storage device 11b does not store history information will be referred to as "history OFF." The control microcontroller 11 determines whether history is ON or OFF at the time of restart. If the history is determined to be ON, the ASIC 12 will execute the CAN cut process after the control microcontroller 11 is restarted. During the CAN cut, the CAN output from the control microcontroller 11 is blocked. As a result, communication between the control microcontroller 11 and the control microcontroller 21 is stopped.
[0031] If the control microcontroller 11 restarts while automatic mode is selected and the start switch 30 is activated (turned on), there is a high probability that the stoppage of the control microcontroller 11 was unintended (for example, a stoppage caused by an internal malfunction or power supply malfunction of the control microcontroller 11), and the control microcontroller 11 may be damaged. Therefore, in the above configuration, communication between the control microcontroller 11 and the control microcontroller 21 is stopped to prevent the control microcontroller 21 from being affected by the control microcontroller 11. With this configuration, even if a malfunction occurs in the control microcontroller 11, the control microcontroller 21 is more likely to operate normally.
[0032] While communication between control microcontroller 11 and control microcontroller 21 is stopped, control microcontroller 11 selects control microcontroller 21 as the IFCOM. On the other hand, after communication between control microcontroller 11 and control microcontroller 21 is stopped, if control microcontroller 11 starts up in a normal state, control microcontroller 11 releases the communication stoppage (CAN cut) and selects control microcontroller 11 as the IFCOM. The IFCOM periodically detects the selected operating mode and outputs the detected operating mode to the control device of the base vehicle 120 each time an operating mode is detected. Control microcontroller 21 may also have a non-volatile storage device, similar to control microcontroller 11. The restarted control microcontroller 21 may detect the selected operating mode based on the operating mode information recorded in its storage device immediately before stopping. The base vehicle 120 recognizes the selected operating mode based on the information from the IFCOM (VCIB110). During periods when no operating mode is output from VCIB110 to the base vehicle 120, the base vehicle 120 may recognize that the selected operating mode is manual mode and activate the active safety system 125 to perform deceleration control of vehicle 1. Alternatively, the base vehicle 120 may inform the driver that vehicle 1 is operating in manual mode. Hereinafter, the information indicating the selected operating mode will be referred to as "internal VEMDST". The base vehicle 120 sequentially acquires internal VEMDST and controls vehicle 1 according to the latest internal VEMDST.
[0033] According to the above configuration, the IFCOM that manages the operating mode of vehicle 1 switches depending on the situation. Specifically, if the control microcontroller 11 may be damaged, the control microcontroller 21 can act as the IFCOM. Since both the control microcontroller 11 and the control microcontroller 21 can function as the IFCOM, the robustness of the VCIB110 is increased.
[0034] Figure 3 is a flowchart showing the process related to managing the operating mode, which is performed by the control microcontroller 11. Hereinafter, each step in the flowchart will be denoted as "S". When the control microcontroller 11 starts up in a normal state, it selects itself as the IFCOM and starts S10 and the subsequent processing flow (hereinafter referred to as the "S10 flow").
[0035] In S10, the state of the start switch 30 (state of the IGR) and the current operating mode (selected operating mode) are detected, and the detection results are recorded in the storage device 11b. As a result, operating mode information indicating the detected operating mode is recorded in the storage device 11b. In the following S11, the control microcontroller 11 determines whether or not the ignition relay (IGR) is in the ON state. If the IGR is ON (YES in S11), it means that the first requirement is met. In S12, the control microcontroller 11 determines whether or not the operating mode detected in S10 is the automatic mode. If the detected operating mode is the automatic mode (YES in S12), it means that the second requirement is met. If both the first and second requirements are met (YES in both S11 and S12), the control microcontroller 11 turns the history ON in S13. After that, the process proceeds to S21. If the first requirement is met but the second requirement is not met (YES in S11 and NO in S12), the control microcontroller 11 turns the history OFF in S14. The process then proceeds to S21. If the first requirement is not met (NO in S11), the control microcontroller 11 turns off the history in S15. The process then proceeds to S30.
[0036] In S21, the control microcontroller 11 obtains the current internal IGR and determines whether the obtained internal IGR indicates off. If the internal IGR indicates on (NO in S21), the control microcontroller 11 is likely normal, and the process returns to S10. In this case, the control microcontroller 11 operates as IFCOM while executing the S10 flow. On the other hand, if the internal IGR indicates off while the first requirement is met (YES in S21), the control microcontroller 11 has stopped for some reason. In this case, the control microcontroller 11 recovers (restarts) in the following S22. Furthermore, in the following S23, the recovered control microcontroller 11 detects the current operating mode (selected operating mode) based on the operating mode information recorded in S10 immediately before stopping, and sends the detected operating mode to the control microcontroller 21. In the following S24, the control microcontroller 11 determines whether the history is ON or OFF. If it is determined that the history is OFF (NO in S24), the process returns to S10. On the other hand, if it is determined that the history is ON (YES in S24), the process proceeds to S25. In S25, the control microcontroller 11 selects the control microcontroller 21 as the IFCOM. As a result, the second VCIB111B becomes active and the first VCIB111A becomes inactive. In other words, the control microcontroller 21 acts as the IFCOM in place of the control microcontroller 11. In the following S26, the ASIC 12 performs a CAN cut process based on a signal from the control microcontroller 11. As a result, communication between the control microcontroller 11 and the control microcontroller 21 is stopped. After that, the process returns to S10. The control microcontroller 11 continues the S10 flow in an inactive state.
[0037] If automatic mode is detected in S23, the control microcontroller 21, which has been activated by the processing in S25, operates vehicle 1 in automatic mode. In automatic mode, the control microcontroller 21 may perform stopping control (safety stop control) of vehicle 1 in accordance with instructions from ADK200. After vehicle 1 has stopped, the control microcontroller 21 may restart the control system. Alternatively, the control microcontroller 21 may request the user to operate the start switch 30 to restart the control system. This restarts the control system of vehicle 1 (including the control microcontroller 11). However, it is not limited to this, and the activated control microcontroller 21 may continue driving vehicle 1 in automatic mode. The control microcontroller 21 may perform automatic driving control similar to that of the control microcontroller 11, or automatic driving control that is more restricted. The restriction may be a speed limit.
[0038] Regardless of whether the control microcontroller 11 is active or inactive, if the user turns off the start switch 30, it is determined to be NO in S11, and in S30, the control microcontroller 11 executes a shutdown process. Once the shutdown process is complete, the control microcontroller 11 is powered off, and the S10 flow ends. Subsequently, if the start switch 30 is turned on and the control microcontroller 11 restarts, the control microcontroller 11 starts S51 and the subsequent processing flow (hereinafter referred to as the "S51 flow"). In S51, the control microcontroller 11 determines whether it has started up in a normal state. If the control microcontroller 11 has started up in a normal state (YES in S51), the control microcontroller 11 selects itself as the IFCOM in S52. As a result, the first VCIB111A becomes active and the second VCIB111B becomes inactive. In other words, the control microcontroller 11 operates as the IFCOM. In the following S53, the CAN cut by the ASIC12 is released based on a signal from the control microcontroller 11. If the ASIC12 does not perform the CAN cut, the control microcontroller 11 performs CAN communication. This enables communication between the control microcontroller 11 and the control microcontroller 21. On the other hand, if the control microcontroller 11 is started in an abnormal state (NO in S51), the control microcontroller 21 is selected as IFCOM in S54, similar to S25 and S26 described above, and the CAN cut process is executed in S55. Once the process in S53 or S55 is executed, the S51 flow ends. The started control microcontroller 11 then starts the S10 flow.
[0039] The operation and effects of vehicle 1 according to this embodiment will be explained below using Figures 4 to 6. Figures 4 and 5 show a comparison of the operation of vehicle 1 according to this embodiment (example) and a vehicle that always starts in manual mode (hereinafter referred to as the "comparative example"). In each of Figures 4 to 6, lines L11 to L17 indicate the state transitions of the control microcontroller 11. Specifically, line L11 indicates whether or not power is supplied to the control microcontroller 11, line L12 indicates the IGR state, line L13 indicates the internal IGR, line L14 indicates history ON / OFF, line L15 indicates the clock signal to WDC, line L16 indicates the TTF signal, and line L17 indicates whether or not CAN is cut. Line L20 indicates the internal VEMDST of the example. Line L20A indicates the internal VEMDST of the comparative example.
[0040] Figure 4 is a time chart showing a first example of the operation of the vehicle according to this embodiment. Referring to Figure 4, as shown by line L15, when the WDC detects an abnormality (internal abnormality of the control microcontroller 11), the control microcontroller 11 restarts due to a microcontroller reset. When the microcontroller reset occurs while vehicle 1 is operating in automatic mode, the control microcontroller 11 restarts with the history ON. Therefore, after the restart, the processes S25 and S26 in Figure 3 are executed. As a result, IFCOM switches from control microcontroller 11 to control microcontroller 21. Therefore, as shown by line L20, vehicle 1 automatically resumes (continues) operation in automatic mode.
[0041] Figure 5 is a time chart showing a second example of the operation of the vehicle according to this embodiment. Referring to Figure 5, as shown by line L11, if a momentary power interruption (power supply abnormality of the control microcontroller 11) occurs while vehicle 1 is operating in automatic mode, the control microcontroller 11 restarts with the history ON state. Therefore, after the restart, the processes S25 and S26 in Figure 3 are executed. As a result, IFCOM switches from control microcontroller 11 to control microcontroller 21. Therefore, as shown by line L20, vehicle 1 automatically resumes (continues) operation in automatic mode.
[0042] In contrast, in the comparative example, if the computer that manages the vehicle's operating mode temporarily stops due to some reason (for example, an internal malfunction or power supply failure in the computer) while the vehicle is operating in automatic mode, the vehicle's operating mode will revert to manual mode upon restarting the computer, as shown by line L20A in Figures 4 and 5.
[0043] Figure 6 is a time chart showing a third example of the operation of the vehicle according to this embodiment. Referring to Figure 6, as shown by line L11, if the battery 20 is replaced (attached / detached) while the vehicle 1 is operating in manual mode, the control microcontroller 11 restarts with the history OFF. For this reason, the processes S25 and S26 in Figure 3 are not executed. After the control microcontroller 11 restarts, the vehicle 1 operates in manual mode. In this way, if the control microcontroller 11 is temporarily stopped for any reason, the vehicle 1 continues to operate in the operating mode it was in before the stoppage after the control microcontroller 11 restarts.
[0044] In this embodiment, vehicle 1 records operating mode information in backup RAM (S10 in Figure 3). By using backup RAM as the storage device 11b, the operating mode information recorded in the backup RAM immediately before the control microcontroller 11 was shut down is retained even after the control microcontroller 11 is restarted. Backup RAM has the advantage of faster access speed compared to non-volatile memory such as flash memory. Furthermore, the information stored in backup RAM can be read at any time from immediately after the control microcontroller 11 is started up and can be initialized as needed. However, this is not limited to this, and non-volatile memory such as flash memory can also be used as the storage device 11b.
[0045] The embodiments disclosed herein should be considered in all respects to be illustrative and not restrictive. The technical scope provided herein is defined by the claims rather than by the description of the embodiments above, and all modifications within the meaning and scope equivalent to the claims are intended to be included. [Explanation of symbols]
[0046] 1 vehicle, 11, 21 control microcontrollers, 30 start switches, 100 vehicle platforms, 110 vehicle control interface boxes, 111A first VCIB, 111B second VCIB, 120 base vehicles, 200 autonomous driving kits.
Claims
1. A vehicle comprising a vehicle platform and an autonomous driving kit for transmitting commands for autonomous driving to the vehicle platform, The vehicle platform includes a base vehicle including a first control device, The aforementioned autonomous driving kit includes a second control device that determines commands related to autonomous driving control, The vehicle platform further comprises a vehicle control interface box including a first computer configured to communicate with both the first control device and the second control device, The first computer detects an operating mode selected from a selection including an automatic mode in which the vehicle platform is under the control of the autonomous driving kit and a manual mode in which the vehicle is under the control of a driver, and records operating mode information indicating the detected operating mode. The first control device is configured to control the vehicle according to the operating mode detected by the vehicle control interface box, The first computer, upon restart, detects the selected operating mode based on the operating mode information recorded immediately before shutdown. The vehicle further includes a start switch that accepts user input to switch the operation / deactivation of the control system, The vehicle control interface box further comprises a second computer that communicates with the first computer, The first computer detects the state of the start switch, and if the detected operating mode is the automatic mode and the detected state of the start switch indicates operation, it records the history information; if at least one of the following conditions is not met, it erases the history information. A vehicle in which, if the history information is recorded immediately before the shutdown of the first computer, communication between the first computer and the second computer is stopped after the restart of the first computer.
2. The second computer is configured to communicate with both the first control unit and the second control unit, The first computer is configured to select either the first computer or the second computer as an interface computer. The interface computer detects the selected operating mode and outputs it to the first control device. While communication between the first computer and the second computer is suspended, the first computer selects the second computer as the interface computer. The vehicle according to claim 1, wherein, after communication between the first computer and the second computer has been stopped, if the first computer starts up in a normal state, the first computer will release the communication suspension and select the first computer as the interface computer.
3. The first control device is configured to transmit vehicle information relating to the base vehicle to the vehicle control interface box. For communication between the second control device and the vehicle control interface box, API signals defined by the API (Application Program Interface) are used. The API signal includes an API command indicating a command to the base vehicle and an API status indicating the status of the base vehicle. The interface computer is configured to convert the API command from the second control unit into a signal that the first control unit can execute, and to transmit the converted signal to the first control unit. The vehicle according to claim 2, wherein the interface computer is configured to acquire the API status using the vehicle information from the first control device and to transmit the acquired API status to the second control device.
4. The vehicle according to any one of claims 1 to 3, wherein the first computer is configured to record the operating mode information in backup RAM (Random Access Memory).