vehicle

JP7911995B2Active Publication Date: 2026-08-27POLARIS IND INC
View PDF 9 Cites 0 Cited by

Patent Information

Application Number
JP2023112463
Authority / Receiving Office
JP · JP
Patent Type
Patents
Current Assignee / Owner
Priority Date
2014-12-15
Filing Date
2023-07-07
Publication Date
2026-08-27
Estimated Expiration
2035-12-14

Smart Images

  • Figure 0007911995000001
    Figure 0007911995000001
  • Figure 0007911995000002
    Figure 0007911995000002
  • Figure 0007911995000003
    Figure 0007911995000003
Patent Text Reader

Abstract

To provide communication between a vehicle control system and a supervisory, remote, autonomous, or drive-by-wire controller.SOLUTION: The present invention relates to a system and method for interfacing an autonomous or remote control drive-by-wire controller with a vehicle's control module. Vehicle functions including steering, braking, starting, etc. are controllable by wire via a control network. A CAN architecture is used as an interface between the remote / autonomous controller and the vehicle's control module. A CAN module interface provides communication between a vehicle control system and a supervisory, remote, autonomous, or drive-by-wire controller. The interface permits the supervisory control to control vehicle operation within pre-determined bounds and using control algorithms.SELECTED DRAWING: Figure 1
Need to check novelty before this filing date? Find Prior Art

Description

Cross - reference to related applications

[0001] This application is a PCT application claiming priority to U.S. Provisional Patent Application No. 62 / 091,946, filed on December 15, 2014, entitled "Autonomous Ready Vehicle", the priority of which is claimed by this application and the disclosure of which is incorporated herein by reference. Further, this application is a divisional application of Japanese Patent Application No. 2020 - 202545, filed on December 14, 2015.

Technical Field

[0002] [[ID=ll]]The present disclosure relates to an autonomous ready vehicle. More specifically, the present disclosure relates to a vehicle configured to receive commands from an autonomous controller or a remote controller for controlling the functions of the vehicle.

Summary of the Invention

[0003] In one exemplary embodiment of the present disclosure, a system and method for interfacing an autonomous or remote drive - by - wire controller with a control module of a vehicle are provided. Functions of the vehicle, including steering, braking, starting, etc., can be controlled by wire via a control network. For example, a CAN architecture available from Polaris Industries, Inc. is used as an interface between a remote / autonomous controller and a control module of the vehicle in one exemplary embodiment of the present disclosure. The CAN module interface, as an example, provides communication between a vehicle control system and a monitoring, remote, autonomous, or drive - by - wire controller. This interface allows a monitoring controller to control the operation of the vehicle within a predetermined range and using control algorithms.

[0004] In another embodiment, a vehicle is provided comprising a communication network connecting a plurality of vehicle devices, and a vehicle control unit coupled to the communication network and capable of controlling a first subset of the plurality of vehicle devices via the communication network to perform vehicle operations, wherein the vehicle control unit is operable to receive inputs from a second subset of the vehicle devices via the communication network and to control the first subset of the plurality of vehicle devices in response to the inputs received from the second subset of vehicle devices, the inputs from the second subset of vehicle devices indicating operator interaction with one or more of the vehicle devices, and a network interface, the network interface is operable to coupled to the autonomous vehicle controller so that the autonomous vehicle controller can perform vehicle operations via the first subset of vehicle devices independently of the inputs from the second subset of vehicle devices.

[0005] Another embodiment of the present disclosure provides a method for providing autonomous vehicle operation, the steps of: providing a vehicle to a communication network comprising a plurality of coupled vehicle operating devices, the plurality of vehicle operating devices being capable of operating the vehicle, the plurality of vehicle operating devices comprising a first subset of vehicle devices operating on commands from a vehicle control unit, the plurality of vehicle operating devices comprising a second subset of vehicle devices providing inputs to the vehicle control unit, the inputs indicating operator interaction with one or more of the vehicle operating devices; providing an interface to the communication network; and receiving inputs from an autonomous vehicle controller via the interface, thereby enabling the autonomous vehicle controller to control the first subset of vehicle devices independently of inputs from the second subset of vehicle devices.

[0006] According to another embodiment of the present disclosure, a computer-readable medium is provided having non-temporary instructions, which, when interpreted by a processor, causes the processor to provide instructions to a first subset of vehicle devices that can operate a vehicle and operate based on instructions from a vehicle control unit provided via a vehicle communication network; to receive inputs from a second subset of vehicle devices via the communication network indicating operator interaction with one or more of these vehicle devices; and to receive inputs from an autonomous vehicle controller via an interface to the communication network, thereby enabling the autonomous vehicle controller to control the first subset of vehicle devices independently of the inputs from the second subset of vehicle devices.

[0007] Further features of the present invention will become apparent to those skilled in the art upon consideration of the following detailed description of exemplary embodiments illustrating the best mode of implementation of the present invention as currently recognized. [Brief explanation of the drawing]

[0008] For a detailed explanation of the drawings, please refer in particular to the attached drawings below. [Figure 1] A block diagram showing components of an autonomous ready vehicle according to one exemplary embodiment of the present disclosure. [Figure 2] A block diagram showing the communication between the vehicle's CAN communication network module, the accessory hardware platform, and the accessory software. [Figure 3] This flowchart shows the steps taken during normal operation in autonomous or remote control mode and during operation in lockout mode. [Figure 4] This is an exemplary wiring harness used to provide vehicle ignition-by-wire override control. [Figure 5] This flowchart shows exemplary steps taken to authenticate a module that sends commands to a vehicle. [Figure 6] This flowchart shows exemplary steps for authorizing autonomous operation of the vehicle. [Modes for carrying out the invention]

[0009] To facilitate understanding of the principles of this disclosure, certain exemplary embodiments and drawings will be referenced below. The embodiments disclosed below are not intended to be exhaustive or to limit the invention to the exact forms disclosed in the following detailed description. Rather, these embodiments are selected and described so that those skilled in the art can utilize their teachings. It will be understood that no limitation of the scope of the invention is intended. The invention includes any changes and further modifications in the exemplary apparatus and described methods, and further applications of the principles of the invention that those skilled in the art can ordinarily conceive of relating to the invention.

[0010] U.S. Patent Publication No. 2014 / 0288763, U.S. Patent No. 8,534,397, International Publication No. 2014 / 134148, and U.S. Patent Publication No. 2014 / 0244110 are all expressly incorporated herein by reference. Features disclosed herein may be used in combination with features disclosed in those patent documents.

[0011] Figure 1 shows the components of the autonomous ready vehicle 10 of this disclosure. The vehicle 10 is configured to be controlled by an autonomous or remote controller 12. The controller 12 may be an autonomous controller for controlling the vehicle 10 without human interaction. The controller 12 may also be a remote controller in which an operator uses input devices such as pedals, joysticks, a computer, or other controllers to guide the vehicle 10. The functions of the controller 12 also include fault avoidance. The controller 12 sends specific commands to the vehicle 10 to control the movement of the vehicle. The controller 12 also receives feedback from the vehicle 10. Communication with the controller 12 takes place via a gateway interface module, i.e., a communication interface module (CIM) 14 on the vehicle 10. In the exemplary embodiment, the communication interface module is a controller area network (CAN) module. The CIM 14 packages information for transmission between components.

[0012] A mode switch 16 coupled to module 14 allows the user to select between manual operation mode and autonomous or remote control mode. In manual mode, the vehicle 10 is operated by the driver in the usual manner through operator actions on vehicle devices such as steering devices (operating levers, steering wheel, joystick, etc.), brake pedal, gear shift, accelerator pedal, and ignition switch (or sensors that detect any of the above operations), which respectively trigger operations on other vehicle devices such as steering devices (such as steering tie arms), brake actuators, transmission shifter controllers, throttles, and ignition relays (generally any vehicle device or actuator for operating such devices). Overall, it should be understood that embodiments are envisioned that utilize physical connections with respect to input devices for any operation, and that sensors are installed on the input devices and the operation of those devices is communicated via electrical signals. Similarly, embodiments are envisioned in which physical connections are used to drive the operation of actuators, and that actuators receive electrical signals that instruct their operations.

[0013] In one embodiment, the mode switch 16 is a physical switch. In another embodiment, the mode switch 16 is software-operated using either human user input or autonomous or remote user input. The communication interface module 14 controls the system on / off function 18 and the ignition interruption function 20. The communication interface module 14 also communicates with a display 22 in the vehicle 10. The display 22 is preferably a high-resolution color display. The display 22 may be provided by a vehicle gauge display.

[0014] The communication interface module 14 further communicates with the electronic power steering control device 24. The power steering control device 24 controls the steering positioning function 26 for guiding the vehicle 10.

[0015] The communication interface module 14 further communicates with the engine control module (ECM) 28. The ECM 28 controls and responds to the pedal placement function 30. The ECM 28 further controls the engine start / stop function 32. The pedal placement function 30 receives commands from the communication interface module 14 to either acknowledge the actual position of the foot pedal or acknowledge acceleration commands received from the controller 12 in order to control the throttle position of the vehicle. For example, in manual mode, the pedal placement function 30 obtains a physical response from the pedal for throttle application, while in autonomous or remote mode, the controller 12 provides the percentage of throttle to be applied as well as the physical application of the throttle.

[0016] The communication interface module 14 further communicates with the vehicle control module 34. The vehicle control module 34 controls the transmission placement function 36, the brake placement function 38, and the parking brake placement function 40. The movement of the vehicle is controlled by the driver in manual mode, or by signals received from the controller 12 via the communication interface module (CIM) 14 in autonomous or remote control modes. The vehicle control module 34 also returns vehicle status and sensor information to the controller 12 via the communication interface module 14. The vehicle status and sensor information includes, for example, vehicle speed, steering angle, requested speed, requested steering angle, brake status, fuel level, accelerometer data, brake sensor, throttle position sensor, wheel speed sensor, gear selection sensor, temperature sensor, pressure sensor, exhaust level, fault code, and error message. The brake placement function 38 is implemented, for example, using the i-Booster intelligent brake control system available from Bosch.

[0017] Furthermore, if an interaction occurs between the pedal placement function 30 of the ECM28 and the brake placement function 38 of the VCM34, i.e., if conflicting messages occur, the CIM14 filters out the appropriate communication message to be transmitted to the external controller 12, thereby avoiding the interaction problem regarding the input, i.e., the pedal position.

[0018] The vehicle control module 34 controls the transmission placement function 36 by detecting a request to change gears and then providing a gear change signal when the conditions are correct. The brake placement function receives input from the pedal position detector and brake commands received via the communication interface module 14 in order to apply the vehicle brake 38 or the parking brake 40.

[0019] Furthermore, the autonomous or remote controller 12 may control suspension components via a communication interface module 14. Outputs from vehicle sensors are received and processed by the controller 12, and signals for controlling adjustable springs or adjustable shock absorbers of the vehicle's suspension are then transmitted from the controller 12 via the communication interface module 14. See, for example, U.S. Patent Application Publication No. 2014 / 0125018 and U.S. Patent Application Publication No. 14 / 507,355, filed on October 6, 2014, whose disclosures are expressly incorporated herein by reference with respect to details of adjustable suspension components.

[0020] Figure 2 shows an exemplary accessory integration device 50 having an accessory CAN port 52 that communicates via CAN bus 54 to an accessory hardware platform 56 of vehicle 10. Specifically, CAN bus 54 communicates with a hardware CAN transceiver 58. Transceiver 58 communicates with the hardware platform firmware 62 of accessory software 60. The hardware platform firmware 62 communicates with a CAN accessory application programming interface (API) software 64. The API software 64 communicates with third-party application software 66.

[0021] The CAN accessory API software 64 includes a library of compiled code. This library provides an interface between a proprietary CAN network and an application programmer's application code. Thereby, third-party accessory creators can access specific and limited information on the CAN network and thus enable the creation of smart accessories without accessing the proprietary information of the CAN network and without disturbing vehicle communications. Further, this interface leaves no room to compromise the intended operation of the vehicle or the safety of the network.

[0022] In one embodiment, the library of compiled code includes a set of proprietary, secure, defined function calls. These function calls include items such as getEngineRPM(), getVehicleSpeed(), or getEngineTemperature(). A third-party application programmer can use these function calls to incorporate accessible vehicle information into the application programmer's application code.

[0023] In one example, this code library may be compatible with a large-scale open-source electronics platform. In addition to the software library, the quick start custom accessory includes a high durability housing and hardware peripherals that can be used by third-party developers. Such peripherals include, for example, LED bars and basic LCD displays.

[0024] The present disclosure permits any third party to create software applications for use with a vehicle without interfering with other functions of the vehicle. Thus, a third party can develop smart accessories for use with the vehicle. Thereby, the user of the vehicle can drive innovation in vehicle accessories.

[0025] (Conflict resolution) In one embodiment, when a conflict occurs between individual or multiple manual inputs and input commands received from an autonomous or remote controller 12 when the vehicle 10 is in autonomous or remote control mode, the vehicle can respond with a manual override of the autonomous control, and the CIM 14 can continue to pay attention to the remote input message without executing the command while continuing to send CAN messages.

[0026] In another embodiment, a user can be detected within the vehicle, i.e., via input torque detected on the steering wheel, whereby manual operation can override a particular function or all functions of the autonomy.

[0027] Another embodiment includes an override by an autonomous or remote controller 12 of a manual control input to the vehicle. For example, a message from the controller 12 can be detected to enable the autonomous control to override a particular function or all functions of the manned mode operation.

[0028] Some vehicles implement a switch to transition from autonomous or remote mode to manned mode. In some examples, the switch position overrides conflicting messages. For instance, if the switch is in autonomous mode and a message is received from the vehicle's pedal, the vehicle will continue to operate in autonomous mode.

[0029] (Interaction between brakes and throttle in autonomous driving) In some cases, the input may include human and autonomous or remote messages that are contradictory or occur simultaneously. For example, if commands for brake application and throttle application are detected, the CIM14 can be calibrated so that brake application takes precedence. Furthermore, the profile can determine whether the pedal placement was the intended action. If the action was not intended, the vehicle can enter lockout mode. If the action was intended, the vehicle control response can be calibrated to a pre-selected limit value.

[0030] In another example, the vehicle's response may include a mixed application of at least one of human input and autonomous or remote input. For example, CIM14 may receive messages for throttle application and brake application. The mixed response may reduce the throttle to a sufficiently low calibrated level so that the vehicle's brakes outweigh the throttle application to the engine. In other situations, a different calibration may be desirable. These calibrations include profiles that pre-select vehicle functions that take priority when conflicting messages occur.

[0031] When the vehicle 10 is in autonomous or remote control mode, an exemplary response of the vehicle system to conflicting individual or multiple manual inputs and individual or multiple input commands received from the autonomous or remote controller 12 may be as follows:

[0032] • Brakes: Vehicle 10 has both mechanical and electrical brake control. If a conflict arises between the brake pedal input and the brake request command from controller 12, override will take effect, and the strongest (manned or autonomous / remote) brake request will be enforced. Thus, the vehicle occupant can use the brakes to override remote commands and stop vehicle 10.

[0033] • Steering: The steering does not respond to manual input.

[0034] • Transmission: The transmission does not respond to manual input.

[0035] • Engine: The accelerator pedal does not respond to manual input.

[0036] (Lockout mode) The lockout function of this disclosure is implemented in a vehicle 10 that supports both manned mode and autonomous or remote mode. In manned mode, the vehicle operates normally and receives input from the driver via the pedals, steering wheel, and shift lever. In remote mode, the vehicle 10 operates by receiving commands from an external controller 12 that communicates via a gateway communication interface module 14, which adapts and translates the commands for the vehicle's CAN network. The lockout function allows only authorized third parties to send commands via the vehicle's gateway in remote control or autonomous mode. The vehicle 10 behaves in known manner in the event of loss or damage to communication between the vehicle gateway 14 and the external controller 12.

[0037] The lockout function is, for example, part of the software that allows a third party to communicate with the vehicle via the controller 12 and interface module 14 to drive the vehicle. In lockout mode, vehicle operations may include bringing the vehicle to a controlled stop, switching to parking, shutting off the engine, locking the steering column / brakes / clutch, shutting off the display / suspending communication, cutting off power to the vehicle, and preventing the vehicle from starting. To ensure that only authorized third parties have access to the gateway module 14, the third-party external controller must successfully complete an authentication sequence. In the exemplary embodiment, authentication is based on the exchange of seed keys of J1939. It is understood that other authentication techniques may be used. Authentication protocols for other embodiments are described below with reference to Figure 5.

[0038] (Transition to lockout mode) To ensure that only authenticated third parties access the gateway module 14 in remote mode, the third-party external controller 12 must successfully complete an authentication sequence. In one example, the authentication sequence is based on the exchange of J1939 or other seed keys. For example, if the authentication sequence is not initiated and successfully completed at least once every five minutes, the vehicle enters lockout mode. Furthermore, if the integrity of communication is compromised in any message coming from the external module to the vehicle's gateway, which can be ensured using checksums, message counters, or other communication errors, the vehicle enters lockout mode.

[0039] (Vehicle control to activate lockout mode) The gateway control module 14 executes lockout mode by ignoring any CAN messages input from the external controller 12. Next, module 14 sends a zero throttle command over the vehicle's internal CAN network and begins commanding the brakes to stop the vehicle 10. The braking force used is determined by a calibrable map that depends on the vehicle speed and steering angle. Once the vehicle has stopped moving, the transmission is commanded to switch to parking and the engine is shut off. The gateway module 14 ignores messages input from the external controller 12, keeps the engine stopped, keeps the transmission in parking, and keeps the brakes depressed until the lockout mode is terminated.

[0040] (Ending lockout mode) The lockout mode can be terminated by re-authentication, i.e., by rebuilding the communication, such as through a manual key cycle. In one embodiment, the lockout mode is terminated after the vehicle 10 has reached a complete controlled stop, the engine has been shut off, and the transmission has been switched to parking. In another embodiment, the lockout mode can be terminated during the shutdown sequence if re-authentication, i.e., rebuilding the communication occurs during the shutdown sequence (i.e., before a complete controlled stop occurs, before the engine is shut off, or before the transmission is switched to parking). If the lockout is caused by loss or corrupted communication, the lockout mode is terminated when the communication is rebuilt. If the lockout mode is caused by authentication failure, the lockout mode is terminated when the authentication sequence is successfully completed. If the conditions for terminating the lockout mode are met while the vehicle is in the process of stopping, engine shutting off, and parking, the lockout mode is terminated when the vehicle has reached a complete stop, the engine has been shut off, and the transmission has been switched to parking.

[0041] Further details of normal operation in autonomous or remote control mode and lockout mode are shown in Figure 3. During normal operation, as shown in block 70, the autonomous or remote controller 12 sends a driving request to the communication interface module, i.e., the gateway interface module 14. The interface module 14 sends vehicle status information to the controller 12. The module 14 also sends driving commands to the vehicle communication node (CAN, Ethernet®, etc.) based on the driving request received from the controller 12, as described above. The vehicle node sends status information to the interface module 14.

[0042] Next, as shown in block 72, the communication interface module 14 determines whether the autonomous or remote controller 12 has initiated and successfully completed authentication, such as exchanging a seed key. If authentication is successfully completed in block 72, module 14 resets the authentication timer in block 74 and continues normal operation in block 70. If authentication is not successfully completed in block 72, module 14 determines, as shown in block 76, whether a predetermined time, such as 5 minutes, has elapsed since the last successful authentication. If this predetermined time has not elapsed in block 76, normal operation continues in block 70. If the predetermined time has elapsed in block 76, module 14 transitions to lockout mode in block 78.

[0043] Module 14 sends a drive command to the vehicle node to lock out the vehicle in a controlled manner, as shown in block 78. Module 14 controls the braking of the vehicle based on the vehicle's speed and steering angle to bring the vehicle to a controlled stop. Next, the engine control module 28 shuts down the engine function in block 32. In lockout mode, the controller 12 can continue to send drive requests to the communication interface module 14. The interface module 14 continues to send vehicle status information to the controller 12. The interface module 14 sends a drive command to the vehicle node to maintain the vehicle lockout. The vehicle node sends status information back to the interface module 14.

[0044] In another exemplary embodiment, communication from the controller 12 to the vehicle's CIM 14 still occurs even though the vehicle is in lockout mode. After a predetermined number of failed authentication attempts, or after a single communication failure, the CIM 14 stops executing commands to the vehicle. The vehicle's CIM 14 still receives communications from the controller 12, but stops sending communications to the controller 12.

[0045] In yet another exemplary embodiment, when the vehicle 10 enters lockout mode, the external communication network between the controller 12 and the CIM 14 is cut off, while the vehicle's overall communication network remains functional.

[0046] In yet another exemplary embodiment, active control is provided to individual vehicle nodes in the vehicle communication network. Lockout authentication is applied between any two vehicle nodes or vehicle communication networks to enforce the lockout function. This technique is also used to prevent unauthenticated vehicle nodes from being added to the CAN network.

[0047] Next, the interface module 14 determines, as shown in block 82, whether the controller 12 has initiated and successfully completed authentication, for example, by seed key exchange. If not, the interface module 14 maintains lockout mode in block 80. If authentication is successful in block 82, the interface module 14 resets the authentication timer in block 74, and the vehicle resumes normal operation, either autonomously or controlled by the remote controller 12.

[0048] Communication failures may occur when the vehicle 10 is in autonomous or remote control mode. When a communication failure occurs, including problems with the message counter and checksum, and, if any, with the “error” message as defined in J1939, the communication interface module 14 enters the lockout mode described above. If the remote module commands brakes greater than 0% and throttle greater than 0%, the communication interface module 14 follows the brake command, ignores the throttle command, and transmits a diagnostic fault code via the external CAN network. The following is an example of the actions taken by the communication interface module 14 when a “not available” message of J1939 is received for each subsystem controlled in remote mode. In one example, • Brake: Brake command interpreted as 0% • Steering: Steering angle maintained at the last valid requested angle • Transmission: The requested gear is maintained in the last valid requested gear. • Engine: Pedal commands interpreted as 0%, engine start / stop commands interpreted as engine stop.

[0049] In one example, if CIM14 receives a brake command and the data indicates that the command is unavailable, CIM14 determines that the command is invalid and waits to see if it receives another message. It limits the number of messages before a lockout or other operation occurs. If a large number of input commands (brake, steering, etc.) are invalid, this may indicate a problem, and CIM14 will enter lockout mode to stop these commands from continuing. CIM14 can enable options for any pedal command, any steering command, a pre-configured "limp home" command, etc. If a problem occurs with the checksum or data error, CIM14 will use the last valid command, but if the condition is still not valid, the vehicle will consequently enter lockout mode or limp home / low mode conditions.

[0050] (Remote vehicle power input and remote mode selection) In another embodiment, the system allows remote selection of a remote mode and power input. The communication interface module 14 has a low-power mode that is activated when a CAN message is received from the controller 12. Mode selection is controlled by a CAN message from the remote controller 12 (if none is present, it returns to manual mode). When activated, the communication interface module 14 controls the circuit in Figure 4 to bypass the key switch in remote mode. The conventional wire harness is modified by adding an inline connector behind the key switch connector shown in Figure 4. The auto-oscillation control line for the ECM28 is routed to the 5-pin connector by the existing key switch line. Figure 4 also shows both sides of the new pass-through connector with the auto / manual bypass circuit interposed.

[0051] If communication is lost in autonomous or remote control mode while vehicle 10 is in motion, a “stop procedure” is performed. The system monitors the vehicle speed and steering angle on the ground to stop the vehicle, and then applies the brakes based on these two inputs. Feedback on the surrounding terrain can be provided using an application based on a 3D map calibrated for the vehicle (speed, steering angle, and brake ratio).

[0052] In an exemplary embodiment, the controller 12 implements one or more of the following features:

[0053] • Vehicle monitoring and control that mimics the level of a human driver. • Sensory fusion • Navigation using GPS-corrected inertial navigation or other systems capable of determining position with the required accuracy. ·Location Lane detection and lane departure • Extensive terrain and obstacle detection, avoidance, and database characterization using real-time or near-real-time detection, pre-recorded maps and lane structures, planned and tracked itineraries, collision avoidance systems (LIDAR, video, sensors), and adaptive driving control. If there is no communication from controller 12, the vehicle has the ability to operate in fully autonomous mode.

[0054] The communication interface module 14 may also provide the following:

[0055] • Other chassis functions such as driving / automatic start, speed / acceleration control, steering, braking, gear selection, and lighting. • The yaw rate model versus steering command is used at the vehicle's control level. • The command mode includes target conditions and rates with profiles of standard and maximum rates of change. • Remote dashboard messages • Create a driving profile from vehicle sensors. • Power outage mode • Infrared (IR) mode Automate drivetrain control by executing driving modes including two-wheel drive, four-wheel drive, and grass mode. Status messages transmitted via CAN include conflicting controller commands, vehicle health data, and the status and conditions of the vehicle's lockout mode.

[0056] Furthermore, embodiments are envisioned in which the vehicle 10 (and controller 34) is provided with information about the terrain being traversed (either via GPS or otherwise, alone or in combination with other information sources). This information may include information to inform the vehicle 10 of the type of terrain, changes in terrain, or conditions that are expected to affect the vehicle's operation. The vehicle 10 then uses this information to influence its operation. In one example, the vehicle 10 determines that it is moving in the direction of crossing a hill. The vehicle 10 uses this information to influence the setting of the shock absorber stiffness, which is electrically adjustable to increase the vehicle's safety. Similarly, another example includes adjusting the shock absorber setting by determining whether it is crossing a public road or off-road conditions.

[0057] Referring to Figure 5, an authentication protocol of another embodiment for ensuring that only authenticated entities can access the CAN network to instruct the operation of the vehicle is described. In block 500, when autonomous mode is enabled, CIM 14 sends an authentication request to remote module 12. This request includes a seed value, which is, for example, a 7-byte key generated to approximate a random number. In block 510, remote module 12 receives this request and calculates a key (private key) based on the seed value and algorithm. Next, in block 520, module 12 sends back the value of the public key to CIM 14. Next, CIM 14 compares the returned value with a value that CIM 14 has calculated internally and therefore expects to match the returned value and indicate the authentication module 12. Upon receiving the public key value, in block 530, CIM 14 determines whether a response was received within a specified timing window. This timing requirement limits the ability of a third party to have unlimited time to attempt to respond multiple times (i.e., to attempt a "brute-force" hacking). In block 540, if the public key response is received within the requested timing window and the public key matches the expected response, in block 550 the module is authenticated and module 12 is permitted to send control signals.

[0058] If the public key received within the timing window does not match, or if the public key response is received outside the requested window, in block 560, CIM14 locks out module 12 and enters lockout mode (which either stops the vehicle or returns the vehicle to manual user control).

[0059] Next, in block 570, CIM14 waits for another authentication request from module 12 (which may be the same module 12 that provided the failed public key response or a different module 12). Upon receiving another authentication request, in block 580, CIM14 forces a delay, again to reduce the likelihood of a successful brute-force attack. If the delay time has not elapsed, in block 590, CIM14 locks out module 12 again and then waits for another authentication request. If the delay time has elapsed, CIM14 returns to block 510 and attempts to authenticate module 12 again.

[0060] As described above, once module 12 is authenticated, module 12 is authorized to send commands to CIM module 14 to instruct the operation of vehicle 10. As part of this, in block 600, CIM 14 receives input commands from module 12. Each received message is accompanied by a checksum and a message counter value. In blocks 610, 620, and 630, CIM 14 compares the checksum and counter in this message with those calculated internally (and therefore expected from the message). If either the counter or the checksum does not match, in block 560, CIM 14 locks out module 12. If the counter and checksum match, in block 640, the received command input is accepted and distributed within vehicle 10 so that its call can be made.

[0061] Overall, referring to Figure 6, it should be understood that a method is disclosed that enables a vehicle to be ready for connection with an autonomous controller. In block 700, the vehicle is provided with a communication network coupled with a plurality of vehicle operating devices, which can operate the vehicle, and which includes a first subset of devices that operate based on commands from a vehicle control unit, and which includes a second subset of devices that provide inputs to the vehicle control unit, which instruct the operator to interact with one or more of the vehicle devices. In block 710, an interface to the communication network is provided. In block 720, inputs are received from the autonomous vehicle controller via the interface, thereby enabling the autonomous vehicle controller to control the first subset of vehicle devices independently of inputs from the second subset of vehicle devices.

[0062] The logical operations of various embodiments of the disclosure described herein are performed as (1) a series of computer-implemented steps, operations, or procedures operating on programmable circuits in a computer, and / or (2) a series of computer-implemented steps, operations, or procedures operating on programmable circuits in a directory system, database, or compiler.

[0063] Embodiments of the disclosure can be implemented using various types of electrical circuits comprising individual electronic elements, packaged or integrated electronic chips containing logic gates, circuits utilizing microprocessors, or on a single chip containing electronic elements or a microprocessor. Embodiments of the disclosure can also be implemented using other technologies capable of performing logical operations, such as AND, OR, and NOT, including but not limited to mechanical, optical, fluid, and quantum technologies. Furthermore, embodiments of the methods described herein can be implemented in a general-purpose computer or in any other circuit or system.

[0064] Embodiments of the present disclosure may be implemented as a computer process (method), i.e., an arithmetic system, or as a manufactured article such as a computer program product or computer-readable medium. A computer program product may be a computer storage medium that is readable by a computer system and encodes a computer program of instructions for executing a computer process. Thus, embodiments of the present disclosure may be embodied in hardware and / or software (including firmware, resident software, microcode, etc.). In other words, embodiments of the present disclosure may take the form of a computer program product on a computer-readable storage medium used by or connected to an instruction execution system, in which computer-readable or computer-readable program code is embedded. A computer-readable or computer-readable medium includes any medium that is used by or connected to an instruction execution system, apparatus, or device and is capable of containing or storing the program.

[0065] Embodiments of the present disclosure are described above with reference, for example, to block diagrams and / or operation diagrams of methods, systems, and computer program products according to embodiments of the present disclosure. The functions / operations described in those blocks may occur in a manner different from the order shown in the flowcharts. For example, two blocks shown consecutively may actually be executed substantially simultaneously, or these blocks may, depending on the functions / operations involved, be executed in reverse order.

[0066] Although the present invention has been described with exemplary designs, it can be further modified within the spirit and scope of this disclosure. Accordingly, this application is intended to encompass any variations, uses, or modifications of the present invention using its general principles. Furthermore, this application is intended to encompass any departures from this disclosure that fall within the scope of known or common practice in the art to which the present invention belongs. Preferred embodiments of the present invention are described below in separate sections.

[0067] Embodiment 1 An autonomous controller interface operably coupled to an autonomous controller module located externally to a vehicle, the autonomous controller interface providing a communication path for communicating with the vehicle's Controller Area Network (CAN), A CAN interface capable of communicating with the engine control module over the aforementioned CAN, A command translation means capable of receiving commands from the autonomous controller module via the autonomous controller interface and translating them into commands that can be operated by the engine control module, and Authentication means capable of authenticating the autonomous controller module coupled to the autonomous controller interface. Includes, The authentication means requires an authentication operation to be performed within a predetermined timing window, and if the authentication operation fails within the predetermined timing window, the vehicle gateway module transitions to a lockout mode.

[0068] Embodiment 2 The gateway module according to Embodiment 1, wherein the authentication means performs the exchange of the J1939 seed key.

[0069] Embodiment 3 The gateway module according to Embodiment 1, wherein the command translation means includes a CAN accessory application programming interface (API).

[0070] Embodiment 4 The gateway module according to Embodiment 3, wherein the CAN accessory API provides access to the CAN to the CAN accessory API software.

[0071] Embodiment 5 The gateway module according to Embodiment 1, wherein the authentication means selectively performs a transition to a lockout mode that rejects commands from the autonomous controller interface.

[0072] Embodiment 6 The gateway module according to Embodiment 1, wherein the command translation means is further capable of sending vehicle data to the autonomous controller interface.

[0073] Embodiment 7 A method for operating a vehicle gateway module, The vehicle gateway module transmits an authentication request, including a seed value, to an autonomous controller module located outside the vehicle using the communication path for the vehicle gateway module. The step of receiving the value of the authentication key from the autonomous controller module, The step of determining whether the received authentication key value is a valid value, A method for transmitting one or more control signals received from the autonomous controller module to the Controller Area Network (CAN) when the value of the received authentication key is a valid value, and preventing the transmission of the control signals received from the autonomous controller module onto the CAN when the value of the received authentication key is not a valid value.

[0074] Embodiment 8 The step of receiving at least one of a checksum and a message counter value attached to the control signal received from the autonomous controller module, A step of determining whether at least one of the checksum and message counter value matches the expected value, It further includes, The method according to Embodiment 7, wherein when at least one of the checksum and message counter values ​​does not match the expected value, the control signal received from the autonomous controller module is not transmitted to the controller area network (CAN).

[0075] Embodiment 9 The method according to embodiment 7, wherein the step of sending an authentication request including a seed value to the autonomous controller module includes sending a secret key value.

[0076] Embodiment 10 The method according to Embodiment 9, wherein, when the authentication key is not received within the predetermined timing window, the control signal received from the autonomous controller module is not transmitted to the controller area network (CAN) as a response to a reception made outside the predetermined timing window.

[0077] Embodiment 11 The method according to embodiment 9, wherein when the authentication key is received within the predetermined timing window, the control signal received from the autonomous controller module is transmitted to the CAN as a response to the reception made within the predetermined timing window.

[0078] Embodiment 12 The method according to embodiment 7, wherein the step of sending an authentication request including a seed value to the autonomous controller module is performed in response to receiving an authentication request from the autonomous controller module.

[0079] Embodiment 13 A method for operating a vehicle gateway module, A step of providing an autonomous controller interface operably coupled to an externally located autonomous controller module for a vehicle equipped with the aforementioned vehicle gateway module, A step of providing a CAN interface that can operate to communicate with an engine control module over a Controller Area Network (CAN), A step of providing a communication path between the autonomous controller module and the CAN interface via the autonomous controller interface, A step of providing a command translation means logically positioned between the autonomous controller interface and the CAN interface, A step of providing an authentication means logically positioned between the autonomous controller interface and the CAN interface, A step of authenticating the autonomous controller module coupled to the autonomous controller interface, A step of translating authenticated commands received from the autonomous controller module via the autonomous controller interface which is operable with the engine control module, Steps include providing the translated command to the CAN interface, A method that includes this.

[0080] Embodiment 14 The method according to embodiment 13, wherein the authentication performs the exchange of the J1939 seed key.

[0081] Embodiment 15 The method according to embodiment 13, further comprising a CAN accessory application programming interface (API) that provides an accessory with access to the CAN.

[0082] Embodiment 16 The method according to embodiment 13, further comprising the step of selectively transitioning to a lockout mode by the authentication means that rejects commands from the autonomous controller interface.

[0083] Embodiment 17 The method according to embodiment 13, further comprising the step of sending vehicle data to the autonomous controller interface via the command translation means.

[0084] Embodiment 18 The method according to embodiment 13, further comprising the step of transitioning to lockout mode when the authentication operation is not performed within the predetermined timing window.

[0085] Embodiment 19 The gateway module according to Embodiment 1 provides the autonomous controller interface as the sole communication path between the autonomous controller module and the CAN.

[0086] Embodiment 20 The method according to Embodiment 7, wherein the communication path from the vehicle gateway module to the autonomous controller module is the only communication path between the vehicle gateway module and the autonomous controller module.

[0087] Embodiment 21 The method according to embodiment 13, wherein the autonomous controller interface is the sole communication path between the autonomous controller module and the CAN. [Explanation of Symbols]

[0088] 10 vehicles 12. Autonomous or remote controllers 14. Communication Interface Module (CIM) 16-mode switch 18. System On / Off Function 20. Ignition Interruption Function 22 displays 24 Electronic power steering control system 26. Steering wheel positioning function 28. Engine Control Module (ECM) 30 Pedal Placement Functions 32. Engine start / stop function 34. Vehicle control module 36. Transmission placement function 38 Brake placement function 40 Parking brake placement function 50 Accessory Integrated Devices 52 CAN ports 54 CAN bus 56 Accessory Hardware Platform 58 Hardware CAN Transceiver 60 Accessory Software 62 Hardware Platform Firmware 64 CAN Accessory API Software 66 Third-party application software Blocks 70, 72, 74, 76, 78, 80, 82, 500, 510, 520, 530, 540, 550, 560, 570, 580, 590, 600, 610, 620, 630, 640, 700, 710, 720

Claims

1. It is a vehicle, Multiple ground engagement members, At least one electric motor configured to be coupled to the plurality of ground engagement members and to drive the plurality of ground engagement members, A communication network comprising a plurality of vehicle devices connected to the communication network, wherein the plurality of vehicle devices comprises a control module configured to control at least one electric motor, and a plurality of sensors configured to determine changes in the terrain traversed by the vehicle, A vehicle control unit coupled to the communication network and capable of controlling a first subset of the plurality of vehicle devices via the communication network to perform vehicle operation, wherein the vehicle control unit is operable to receive input from a second subset of the vehicle devices via the communication network and to control the first subset of the plurality of vehicle devices in response to the input received from the second subset of vehicle devices, the input from the second subset of vehicle devices indicates the interaction between one or more of the vehicle devices and the operator, An autonomous vehicle controller, wherein the autonomous vehicle controller is configured to control the vehicle's suspension components based on the changes in the terrain the vehicle traverses, independently of inputs from the second subset of vehicle devices. Includes, The vehicle control unit is operable to receive inputs from the plurality of sensors in order to determine one or more operational error states of the vehicle. The vehicle control unit is further operable to determine conflicting commands between inputs received from at least one of the first subset of the plurality of sensors and vehicle devices and inputs received via the network interface. The detection of conflicting commands is used to determine one or more error conditions. The vehicle control unit responds to the determination of one or more error conditions by transitioning to a reduced operation mode.

2. The vehicle according to claim 1, wherein the first subset of vehicle devices includes one or more of a steering controller, a brake, a transmission shift controller, a vehicle speed controller, and a vehicle on / off controller.

3. The vehicle according to claim 1, wherein the second subset of vehicle devices includes one or more of a brake pedal, a steering device, a shift lever, a shift button, an accelerator pedal, and an on / off mode selector.

4. The vehicle according to claim 1, further comprising, when interpreted by the processor, an instruction causing the processor to re-examine commands received via a network interface to control the first subset of vehicle devices, wherein the re-examination compares the commands with a set of tolerances to prevent the execution of the commands if the execution of the commands would put the vehicle into an unacceptable state.

5. The vehicle according to claim 1, further comprising a mode switch, the mode switch having a first state in which the first subset of vehicle devices is controlled according to the second subset of vehicle devices, and the mode switch having a second state in which the first subset of vehicle devices is controlled according to a command received via a network interface.

6. The vehicle according to claim 5, wherein the switch is one of a software switches that can change state without a physical switch that can be operated by a physical operation or via a physical operation.

7. The vehicle according to claim 1, wherein the vehicle control unit receives inputs from the second subset of the plurality of vehicle devices, receives inputs from the network interface, and determines which inputs should be used to control the first subset of the plurality of vehicle devices.

8. The vehicle according to claim 7, wherein the vehicle control unit determines which input should be used in accordance with the determination of the state of the mode switch.

9. The second subset of vehicle devices includes brake actuators, The vehicle according to claim 7, wherein the vehicle control unit determines which input should be used based on which input indicates the greatest operation of the brake actuator.

10. The vehicle according to claim 1, further comprising instructions that, when interpreted by a processor, invoke an authentication protocol for determining whether a command received over a network interface is sent from an authenticated source.

11. The vehicle according to claim 10, wherein, upon determining that a command received via the network interface is not from an authenticated source, the vehicle controller commands an operation of the vehicle as one of an operation commanded via the second subset of vehicle devices and an operation via shutdown mode.

12. The vehicle according to claim 11, wherein the shutdown mode stops the vehicle while it is moving and rejects commands via the network interface until a time has elapsed for the authentication protocol to be successfully completed.

13. The aforementioned at least one electric motor consists of two or more electric motors. The first electric motor among the at least one electric motor drives the first ground engaging member among the plurality of ground engaging members, The vehicle according to claim 1, wherein the second electric motor of the at least one electric motor drives the second ground engaging member of the plurality of ground engaging members.

14. A method for providing autonomous vehicle operation, (i) a plurality of ground engagement members, (ii) at least one electric motor coupled to the plurality of ground engagement members and configured to drive the plurality of ground engagement members, and (iii) a communication network coupled with a plurality of vehicle operating devices, wherein the plurality of vehicle operating devices comprises a control module configured to control the at least one electric motor and a plurality of sensors configured to determine the position of the vehicle relative to the positions of other vehicles, the plurality of vehicle operating devices includes a first subset of vehicle operating devices that operate on command from a vehicle control unit, and the plurality of vehicle operating devices includes a second subset of vehicle operating devices that provide input to the vehicle control unit, the input indicating operator interaction with one or more of the vehicle operating devices, A step of operating the vehicle using an autonomous vehicle controller that controls the steering of the vehicle based on the position of the vehicle relative to the positions of other vehicles. The steps include: receiving inputs from the plurality of sensors by the vehicle control unit and determining one or more operational error states of the vehicle in accordance with the inputs; The vehicle control unit determines conflicting commands between inputs received from at least one of a first subset of the plurality of sensors and vehicle operating devices and inputs received via a network interface. The steps include determining one or more error states in response to the detection of conflicting commands, The steps include: transitioning to a reduced operation mode in response to the determination of the presence of one or more error conditions; A method that includes this.

15. The method according to claim 14, wherein the first subset of vehicle operating devices includes one or more of a steering controller, a brake, a transmission shift controller, a vehicle speed controller, and a vehicle on / off controller.

16. The method according to claim 14, wherein the second subset of vehicle operating devices includes one or more of a brake pedal, a steering device, a shift lever, a shift button, an accelerator pedal, and an on / off mode selector.

17. The further step includes re-examining commands received via a network interface to control the first subset of vehicle operating devices, The method of claim 14, wherein the re-examination step includes comparing the command with a set of acceptable conditions in order to prevent the command from being executed if the execution of the command would cause the vehicle to be in an unacceptable state.

18. The further step includes detecting the state of the mode switch, The mode switch has a first state in which the first subset of vehicle operating devices is controlled according to the second subset of vehicle operating devices. The method according to claim 14, wherein the mode switch has a second state in which the first subset of vehicle operating devices is controlled in response to a command received via a network interface.

19. The method according to claim 18, wherein the switch is one of a software switches that can change state without a physical switch that can be operated by a physical operation or via a physical operation.

20. The vehicle control unit receives input from the second subset of the plurality of vehicle operating devices, The vehicle control unit receives input from the network interface, The step of determining which input should be used to control the first subset of the plurality of vehicle operating devices. The method according to claim 14, further comprising:

21. The method according to claim 20, wherein the step of determining the above is performed by the vehicle control unit in accordance with the determination of the state of the mode switch.

22. The second subset of vehicle operating devices includes a brake actuator. The method according to claim 20, wherein the vehicle control unit determines which input should be used based on which input indicates the greatest operation of the brake actuator.

23. The method according to claim 14, further comprising the step of calling an authentication protocol to determine whether a command received via a network interface is sent from an authenticated source.

24. The method according to claim 23, further comprising the step of determining that a command received via the network interface is not from an authenticated source, and in response, commanding an operation of the vehicle as one of an operation commanded via the second subset of vehicle operating devices and an operation via shutdown mode.

25. The method according to claim 24, wherein the operation via the shutdown mode stops the vehicle while it is moving and rejects commands via the network interface until a time has elapsed for the authentication protocol to be successfully completed.

26. The aforementioned at least one electric motor consists of two or more electric motors. The method according to claim 14, wherein the steps of operating the vehicle include driving a first ground engaging member of the plurality of ground engaging members with a first electric motor of at least one electric motor, and driving a second ground engaging member of the plurality of ground engaging members with a second electric motor of at least one electric motor.

27. A computer-readable medium having non-temporary instructions, When the aforementioned non-temporary instruction is interpreted by the processor, the processor will: The vehicle can be operated, and commands are provided to a first subset of vehicle devices which are configured to operate based on commands from a vehicle control unit provided via a vehicle communication network and which have a plurality of sensors configured to determine the conditions under which the vehicle is being operated, the first subset of vehicle devices which have a plurality of sensors configured to determine the conditions under which the vehicle is being operated, From a second subset of vehicle devices, inputs indicating the interaction between one or more of the vehicle devices and the operator are received via the communication network. The interface to the aforementioned communication network allows for the reception of input from an autonomous or remote vehicle controller, thereby enabling the autonomous or remote vehicle controller to control vehicle operations based on the conditions under which the vehicle is operating, independently of input from the second subset of vehicle devices. Determine whether the autonomous or remote vehicle controller is an authenticated source, A computer-readable medium that, based on the determination that the autonomous or remote vehicle controller is not an authenticated source, stops the vehicle while it is moving and puts the vehicle into a shutdown mode in which the vehicle rejects commands from the autonomous or remote vehicle controller until the autonomous or remote vehicle controller completes the authentication protocol.

Citation Information

Patent Citations

  • Road surface shape detecting device and method

    JP2005178531A

  • Integrated control system for vehicle

    JP2005178627A

  • Parking position adjustment system

    JP2006306233A

  • Vehicle platooning device

    JP2014075049A

  • Improvements in vehicle speed control

    JP2015524774A