Operation control system, control server, and vehicle

JPWO2024084581A5Active Publication Date: 2025-05-30SUBARU CORP
View PDF 0 Cites 0 Cited by

Patent Information

Application Number
JP2024551094
Authority / Receiving Office
JP · JP
Patent Type
Applications
Current Assignee / Owner
Priority Date
2022-10-18
Filing Date
2022-10-18
Publication Date
2025-05-30
Estimated Expiration
2042-10-18

AI Technical Summary

Technical Problem

Existing driving control systems linked to external control servers face challenges in ensuring both safety and convenience, particularly due to communication failures between vehicles and servers, which can disrupt autonomous driving operations.

Method used

The system employs a dual communication approach using packet-switched and line-switched communication methods to maintain communication stability, allowing vehicles to switch from remote driving control to autonomous control when communication failures occur, ensuring continuous operation and safety.

Benefits of technology

This solution ensures high-level operation control convenience and safety by maintaining communication stability through line-switched communication during failures, enabling vehicles to switch from remote to autonomous control effectively, thereby preventing disruptions and ensuring safe driving.

✦ Generated by Eureka AI based on patent content.
Patent Text Reader

Abstract

This drive control system 1 comprises: a communication ECU 22 that is provided to a vehicle 5, the communication ECU 22 performing communication with the outside by selectively using packet switching communication or line switching communication; a communication ECU 51 that is provided to a traffic control server 50, the communication ECU 51 performing communication with the outside by selectively using packet switching communication or line switching communication; a travel ECU 21 that is provided to the vehicle 5, the travel ECU 21 performing autonomous travel control with respect to the vehicle 5 on the basis of travel environment information; and a travel ECU 53 that is provided to the traffic control server 50, the travel ECU 53 performing remote travel control with respect to the vehicle 5 on the basis of the travel environment information. The communication ECU 51, upon recognizing a reduction in communication response rate or an abnormality in communication with the vehicle 5 during remote travel control using packet switching communication, uses line switching communication to instruct the vehicle 5 to switch from remote travel control to autonomous travel control.
Need to check novelty before this filing date? Find Prior Art

Description

Operation Control System

[0001] The present invention relates to a driving control system capable of communicating control information between a vehicle and a server outside the vehicle.

[0002] In recent years, driving control devices have been put into practical use for vehicles such as automobiles to assist drivers in driving operations, with the aim of reducing the burden of driving operations on drivers and improving safety. The levels of driving control (driving control) by driving control devices are defined into six stages: Level 0, Level 1 (driving assistance), Level 2 (partial driving automation), Level 3 (conditional driving automation), Level 4 (highly automated driving), and Level 5 (fully automated driving).

[0003] In order to achieve a higher level of driving control in this type of driving control device, it is necessary to acquire detailed information about the driving environment around the vehicle over a wide area in real time. For this reason, in recent years, technologies have been proposed that complement driving environment information acquired by on-board autonomous sensors with information from outside the vehicle by linking with an external control server using high-speed communication.

[0004] For example, International Publication No. 2017 / 179209 discloses a vehicle control system (driving control system) including a communication device that communicates with an external control server (server device), a detection unit that detects the surrounding conditions of the host vehicle, and a driving assistance control unit that automatically performs at least a portion of the driving control of the host vehicle based on the surrounding conditions of the host vehicle. This driving control system uses the communication device to request driving environment information (environmental information) related to the road on which the host vehicle is traveling from the control server. The driving control system is then able to reflect the driving environment information received from the control server in its driving control.

[0005] However, in a driving control system linked to an external control server, etc., as described above, as a safety measure against various failures, driving control must be performed taking into consideration not only failures of the on-board driving control device, but also failures in communication between the vehicle and the control server, etc. On the other hand, in order to ensure high convenience through driving control, it is desirable to continue driving control at the highest possible level even in the event of a failure, etc.

[0006] An object of the present invention is to provide an operation control system that can ensure both convenience and safety.

[0007] A driving control system according to one aspect of the present invention includes a first communication control means provided in a vehicle and configured to communicate with the outside world by selectively using packet-switched communication or circuit-switched communication; a second communication control means provided in a control server and configured to communicate with the outside world by selectively using the packet-switched communication or circuit-switched communication; a first driving environment information acquisition means provided in the vehicle and configured to acquire first driving environment information using an autonomous sensor; and a second driving environment information acquisition means provided in the control server and configured to acquire second driving environment information based on information collected by the packet-switched communication. a first driving control means provided in the vehicle for performing autonomous driving control of the vehicle based on the first driving environment information; and a second driving control means provided in the control server for performing remote driving control of the vehicle based on the second driving environment information, wherein when the second communication control means recognizes a decrease in the communication response rate with the vehicle or a communication abnormality while performing the remote driving control using the packet-switched communication, it instructs the vehicle to switch from the remote driving control to the autonomous driving control using the circuit-switched communication.

[0008] Schematic diagram of the driving control system. Schematic diagram showing the area where driving environment information is acquired by the first autonomous sensor group. Schematic diagram showing the area where driving environment information is acquired by the second autonomous sensor group. Explanatory diagram showing the area where driving environment information is acquired from each autonomous sensor group and the control server. Explanatory diagram showing the communication system of the driving control system. Explanatory diagram showing a remote prohibited area. Flowchart showing the routine for determining a decrease in the communication response rate between the vehicle and the control server. Flowchart showing the failure countermeasure control routine in the event of a communication failure between the vehicle and the control server. Flowchart (1) showing the failure countermeasure control routine in the event of a communication failure within the control area. Flowchart (2) showing the failure countermeasure control routine in the event of a vehicle malfunction.

[0009] DETAILED DESCRIPTION OF THE PREFERRED EMBODIMENTS The present invention will be described below with reference to the accompanying drawings, in which: FIG. 1 is a schematic diagram of an operation control system according to an embodiment of the present invention;

[0010] As shown in Figure 1, the driving control system 1 of this embodiment includes a driving control device 10 mounted on a vehicle 5, which is a moving body, a plurality of control servers 50 consisting of narrow-area servers installed in a network environment, and an off-vehicle driving control device 70 that controls the driving of the vehicle 5 via the control server 50.

[0011] The driving control device 10 has, as autonomous sensing devices for acquiring information about the driving environment of the vehicle 5, for example, a stereo camera unit 11, multiple corner radars 12, a LIDAR (Light Detection and Ranging, Laser Imaging Detection and Ranging) 13, and an all-around camera 14. The driving control device 10 also has, as various control units, a locator control unit (hereinafter referred to as "locator_ECU") 20, a driving control unit (hereinafter referred to as "driving_ECU") 21, a communication control unit (hereinafter referred to as "communication_ECU") 22, an engine control unit (hereinafter referred to as "E / G_ECU") 23, a power steering control unit (hereinafter referred to as "PS_ECU") 24, a brake control unit (hereinafter referred to as "BK_ECU") 25, and an alarm control unit (hereinafter referred to as "alarm_ECU") 26. These control units 20 to 26 are connected to each other via an in-vehicle communication line such as a CAN (Controller Area Network).

[0012] In this embodiment, the stereo camera unit 11, the multiple corner radars 12, the LIDAR 13, the all-around camera 14, and the locator ECU 20 correspond to a specific example of a first driving environment information acquisition means.

[0013] The stereo camera unit 11 is fixed, for example, to the center of the upper front part of the vehicle interior. The stereo camera unit 11 includes, for example, an in-vehicle camera (stereo camera) including a main camera 11a and a sub-camera 11b, an image processing unit (IPU) 11c, and an image recognition control unit (hereinafter referred to as "image recognition ECU") 11d.

[0014] The main camera 11a and the sub-camera 11b sense, for example, the real space ahead of the vehicle 5 from different viewpoints on the left and right. For this reason, the main camera 11a and the sub-camera 11b are arranged, for example, at positions symmetrical on the left and right sides of the center of the vehicle 5 in the vehicle width direction.

[0015] The IPU 11c processes a pair of left and right images (stereo images) captured stereoscopically by the cameras 11a and 11b in a predetermined manner to generate distance image information. That is, the IPU 11c calculates the amount of positional deviation between pixels representing the same object between the left and right images. This allows the IPU 11c to calculate the distance from the vehicle 5 to pixels representing objects outside the vehicle. This allows the IPU 11c to generate image information (distance image information) that includes distance information for each pixel representing an object outside the vehicle.

[0016] The image recognition ECU 11d performs predetermined pattern matching on the distance image information. As a result, the image recognition ECU 11d determines, for example, lane markings that divide the road. Furthermore, the image recognition ECU 11d recognizes guardrails and curbs along the road, as well as three-dimensional objects on the road, such as pedestrians, motorcycles, and vehicles other than motorcycles. Here, the three-dimensional object recognition performed by the image recognition ECU 11d includes, for example, recognizing the type of three-dimensional object, the distance to the three-dimensional object, and the speed of the three-dimensional object.

[0017] The corner radars 12 are provided, for example, on the left and right sides of the front bumper and the left and right sides of the rear bumper of the vehicle 5. These corner radars 12 are, for example, millimeter-wave radars. Each corner radar 12 emits radar waves in the horizontal direction at a predetermined frame period and receives reflected waves of the emitted radar waves. As a result, each corner radar 12 detects multiple reflection points on a three-dimensional object present around the vehicle 5. Each corner radar 12 then recognizes the three-dimensional object by performing a predetermined grouping process on the detected multiple reflection points. Furthermore, each corner radar 12 sets the reflection point that is closest in linear distance to the vehicle 5 as a representative point of the three-dimensional object. Each corner radar 12 then recognizes information about the representative point, such as the position and moving speed of the reflection point corresponding to the representative point, and recognizes the size of the three-dimensional object calculated from the distribution of the reflection points.

[0018] 2 , for example, the monitoring area of ​​the stereo camera unit 11 and the monitoring area of ​​each corner radar 12 are at least partially overlapped with each other. As a result, the stereo camera unit 11 and each corner radar 12 constitute a first autonomous sensor group for detecting information about the driving environment around the vehicle 5.

[0019] The LIDAR 13 is provided, for example, in the center of the front of the vehicle 5. The LIDAR 13, for example, irradiates near-infrared laser light in pulses and measures the light reflected from an object. In this way, the LIDAR 13 accurately detects not only the distance to the object but also the position and shape of the object.

[0020] The LIDAR 13 is a sensor that outputs a distance point cloud, and is also used by the stereo camera unit 11. However, the stereo camera unit 11 is a passive sensor, and therefore has the advantage of having a faster sampling rate than the LIDAR 13. On the other hand, the LIDAR 13 is an active sensor, and therefore has the advantage of having more stable detection accuracy against changes in brightness than the stereo camera unit 11. Therefore, in this embodiment, the stereo camera unit 11 and the LIDAR 13 have a complementary relationship.

[0021] The omnidirectional camera 14 is configured to have a plurality of cameras 14a. The cameras 14a are provided, for example, at the center of the front of the vehicle 5, on the left and right door mirrors of the vehicle 5, and at the center of the rear of the vehicle 5. Each camera 14a detects three-dimensional objects outside the vehicle, for example, by well-known image recognition processing.

[0022] 3 , for example, at least a portion of the monitoring area of ​​the LIDAR 13 and the monitoring area of ​​the omnidirectional camera 14 are overlapped with each other. As a result, the LIDAR 13 and the omnidirectional camera 14 constitute a second autonomous sensor group for detecting information about the driving environment around the vehicle 5.

[0023] In this embodiment, each piece of driving environment information detected by the stereo camera unit 11, each corner radar 12, the LIDAR 13, and the all-around camera 14 is output to, for example, the driving_ECU 21. Furthermore, each piece of driving environment information is transmitted from the driving_ECU 21 to the locator_ECU 20 and the communication_ECU 22 via, for example, an in-vehicle communication line such as a CAN.

[0024] The locator ECU 20 estimates the position of the vehicle 5 on a road map. To this end, sensors required for calculating the position coordinates of the vehicle 5, such as an acceleration sensor 15, a speed sensor (wheel speed sensor) 16, a gyro sensor 17, and a GNSS receiver 18, are connected to the locator ECU 20. The acceleration sensor 15 detects the acceleration of the vehicle 5. The speed sensor 16 detects the rotational speeds of the front, rear, left, and right wheels. The gyro sensor 17 detects the angular velocity or angular acceleration of the vehicle. The GNSS receiver 18 receives positioning signals transmitted from multiple positioning satellites 50.

[0025] A road map database 20a is also connected to the locator ECU 20. The road map database 20a is configured, for example, by a large-capacity storage medium such as an HDD. This road map database 20a stores high-precision road map information (dynamic map) as driving environment information. The road map information has, for example, three layers of information: static information that mainly constitutes road information, and semi-dynamic information and dynamic information that mainly constitute traffic information.

[0026] Static information is made up of information that needs to be updated within one month, such as roads, structures on roads, lane information, road surface information, and permanent regulation information.

[0027] Semi-dynamic information is composed of information that requires updating within one minute, such as the actual traffic congestion situation at the time of observation, driving restrictions, temporary driving obstructions such as fallen objects and obstacles, actual accident conditions, and narrow-area weather information.

[0028] Dynamic information consists of information that must be updated within one second, such as information transmitted and exchanged between moving objects, information on currently displayed traffic lights, information on pedestrians and motorcycles within intersections, and information on vehicles traveling straight through intersections.

[0029] The locator_ECU 20 updates the information of each layer constituting the road map information in real time based on the driving environment information acquired by various autonomous sensing devices. Furthermore, the locator_ECU 20 updates the information of each layer constituting the road map information in real time based on the road map information (driving environment information) received from the control server 50 or the like by the communication_ECU 22 described later.

[0030] Here, the driving environment information received from the control server 50 by the communication_ECU 22 is information covering a wider range than the driving environment information acquired by the various autonomous sensing devices. Specifically, for example, as shown in Fig. 4, each autonomous sensing device is limited to acquiring driving environment information covering a range in which the vehicle 5 travels in 3 seconds. In contrast, the driving environment information received from the control server 50 is wide-area information that covers a range in which the vehicle 5 travels in 30 seconds.

[0031] The travel_ECU 21 calculates various control information for performing autonomous travel control (driving control) based on the above-mentioned various pieces of travel environment information.

[0032] For example, the travel_ECU 21 calculates a target acceleration / deceleration as control information for performing adaptive cruise control (ACC) based on driving environment information, etc. That is, when a preceding vehicle is present ahead of the vehicle 5, the travel_ECU 21 calculates a target acceleration / deceleration for causing the vehicle 5 to follow the preceding vehicle. Furthermore, when no preceding vehicle is present ahead of the vehicle 5, the travel_ECU 21 calculates a target acceleration / deceleration for causing the vehicle 5 to travel at a constant speed at a set vehicle speed. The travel_ECU 21 then outputs the calculated target acceleration / deceleration to the E / G_ECU 23 and the BK_ECU 25. This enables the E / G_ECU 23 and the BK_ECU 25 to perform acceleration / deceleration control based on the target acceleration / deceleration.

[0033] Furthermore, the traveling_ECU 21 calculates a target steering angle as control information for performing active lane keep centering (ALKC) control, for example, based on driving environment information, etc. That is, the traveling_ECU 21 calculates a target steering angle for keeping the host vehicle in the center of the host vehicle's driving lane, based on driving environment information, etc. Then, the traveling_ECU 21 outputs the calculated target steering angle to the PS_ECU 24. This enables the PS_ECU 24 to perform steering control based on the target steering angle.

[0034] Furthermore, the travel_ECU 21 calculates a target deceleration as control information for performing emergency brake control, for example, based on the travel environment information. That is, the travel_ECU 21 calculates, for example, a time to collision (TTC) (= (relative distance) / (relative speed)) for an obstacle present ahead of the vehicle 5. The travel_ECU 21 also calculates a target deceleration when the time to collision (TTC) becomes equal to or less than a preset threshold. The travel_ECU 21 then outputs the calculated target deceleration to the BK_ECU 25. This enables the BK_ECU 25 to execute deceleration control based on the target deceleration. Furthermore, when the target deceleration is calculated, the travel_ECU 21 issues a warning instruction to the warning_ECU 26. This enables the warning_ECU 26 to execute warning control for the occupants.

[0035] Furthermore, the travel_ECU 21 is capable of performing lane change control for changing the travel lane of the vehicle 5, emergency steering control for avoiding a collision between the vehicle 5 and an obstacle, and the like.

[0036] By appropriately combining a plurality of controls including these controls, the travel_ECU 21 can realize travel control (autonomous travel control). Thus, in this embodiment, the travel_ECU 21 corresponds to a specific example of a first travel control unit.

[0037] Here, the driving control (driving control) levels of this embodiment are defined as six levels: Level 0 (no driving automation), Level 1 (driving assistance), Level 2 (partial driving automation), Level 3 (conditional driving automation), Level 4 (highly automated driving), and Level 5 (fully automated driving). These driving control levels can be changed in stages depending on, for example, the acquisition status (reliability, etc.) of driving environment information.

[0038] If we define the driving environment information acquired by the first group of autonomous sensors as "Ide1," the driving environment information acquired by the second group of autonomous sensors as "Ide2," and the driving environment information received from the control server 50 as "Ide3," the reliability of the driving environment information will be, for example, in the following order:

[0039] "Ide1+Ide2+Ide3" > "Ide2+Ide3" > "Ide1+Ide2" > "Ide1" > "Ide2"

[0040] For example, the driving_ECU 21 can change the level of driving control in stages according to the reliability of the driving environment information that changes in this way.

[0041] A transceiver 19 is connected to the communication_ECU 20 as a communication device for performing "communication connecting the vehicle with everything." Here, "communication connecting the vehicle with everything" refers to, for example, cellular V2X communication, or a communication format that integrates 4G or 5G network access technology with dedicated short-range communication (DSRC) technology, or cellular V2X (C-V2X) communication technology. In this embodiment, "everything connected to the vehicle 5" includes, for example, the control server 50, other vehicles in the vicinity of the vehicle 5, and mobile terminals.

[0042] The transceiver 19 is capable of performing packet-switched communication using, for example, the Hypertext Transfer Protocol (HTTP) protocol or the Message Queue Telemetry Transport (MQTT) protocol.

[0043] This packet-switched communication enables the communication_ECU 20 to transmit, for example, various types of information indicating the status of the vehicle 5 (such as the speed, acceleration, traveling direction, position information, and fault codes of the vehicle 5) to the control server 50 in real time. The communication_ECU 20 can also transmit, for example, driving environment information detected by various autonomous sensing devices of the vehicle 5 to the control server 50 in real time. The communication_ECU 20 can also receive, for example, control information (described later) for remote driving control (driving control) of the vehicle 5 from the control server 50 in real time. The communication_ECU 20 can also receive, for example, driving environment information around the vehicle 5 from the control server 50 in real time.

[0044] The transceiver 19 is also capable of performing circuit-switched communication using, for example, the Short Message Peer to Peer (SMPP) protocol. Compared to packet-switched communication, circuit-switched communication allows for stable communication with a smaller amount of data even in emergencies or disasters. Therefore, circuit-switched communication is mainly used when an abnormality occurs in packet-switched communication.

[0045] Thus, in this embodiment, the communication_ECU 22 corresponds to a specific example of a first communication control unit.

[0046] The output side of the E / G_ECU 23 is connected to a throttle actuator 27 and the like. The throttle actuator 27 opens and closes a throttle valve of an electronically controlled throttle provided in a throttle body of the engine. That is, the throttle actuator 27 opens and closes the throttle valve in response to a drive signal from the E / G_ECU 23. In this way, the throttle actuator 27 adjusts the intake air flow rate and generates a desired engine output.

[0047] An electric power steering motor 28 and the like are connected to the output side of the PS_ECU 24. The electric power steering motor 28 applies a steering torque to the steering mechanism. That is, the electric power steering motor 28 generates a desired steering angle in response to a drive signal from the PS_ECU 24.

[0048] The output side of the BK_ECU 25 is connected to a brake actuator 29 and the like. The brake actuator 29 adjusts the brake hydraulic pressure supplied to the brake wheel cylinders provided on each wheel. That is, when the brake actuator 29 is driven by a drive signal from the BK_ECU 25, it generates a braking force on each wheel through the brake wheel cylinder.

[0049] An alarm device 30 and the like are connected to the output side of the alarm_ECU 26. The alarm device 30 issues a predetermined alarm to the driver. Here, the alarm device 30 is configured, for example, with a multi-information display, a speaker, and the like provided on the instrument panel. That is, the alarm device 30 issues a predetermined warning display or alarm sound to the driver in response to a drive signal from the alarm_ECU 26.

[0050] Each of the ECUs, such as the E / G_ECU 23, the PS_ECU 24, the BK_ECU 25, and the alarm_ECU 26, has a self-diagnosis function. When a predetermined fault is detected by the self-diagnosis of each ECU, the ECU outputs a predetermined fault code or the like to the communication_ECU 22.

[0051] The control server 50 is, for example, arranged in each predetermined control area. The control server 50 is, for example, an edge server (so-called MEC server) in a network environment using edge computing.

[0052] The control server 50 includes various control units, such as a communication control unit (hereinafter referred to as "communication_ECU") 51, an information recognition control unit (hereinafter referred to as "information recognition_ECU") 52, a driving control unit (hereinafter referred to as "driving_ECU") 53, and an integrated control unit (hereinafter referred to as "integrated_ECU") 54. These ECUs 51 to 54 are connected via a predetermined communication line. Here, each of the ECUs 51 to 54 has higher performance specifications than each of the ECUs installed in the vehicle 5. In addition, the programs for controlling each of the ECUs 51 to 54 can be constantly updated to the latest programs.

[0053] A transceiver 55 is connected to the communication_ECU 51 as a communication device.

[0054] The transceiver 55 is capable of performing packet-switched communication using, for example, the HTTP protocol or the MQTT protocol.

[0055] This transceiver 55 enables the communication ECU 51 to perform packet-switched communication, for example, with multiple vehicles 5 present within the control area, an external driving control device 70, and various sensing devices (not shown) installed along roads, in parking lots, etc.

[0056] For example, the communication_ECU 51 is capable of performing packet communication with the transceiver 19 mounted on each vehicle 5 using the transceiver 55. This allows the communication_ECU 51 to receive various information indicating the state of each vehicle 5 (such as the speed, acceleration, direction of travel, location information, and fault codes of the vehicle 5) in real time. The communication_ECU 51 is also capable of receiving driving environment information detected by the autonomous sensing device of each vehicle 5 in real time. The communication_ECU 51 is also capable of transmitting individual control information for each vehicle 5 to each vehicle 5 in real time.

[0057] The transceiver 55 is also capable of performing circuit-switched communications using, for example, the SMPP protocol.

[0058] This transceiver 55 enables the communication ECU 51 to perform circuit-switched communication with, for example, multiple vehicles 5 present within the control area, an external driving control device 70, and various sensing devices (not shown) installed along roads, in parking lots, etc.

[0059] For example, the communication_ECU 51 can use the transceiver 55 to perform circuit-switched communication with the transceiver 19 mounted on each vehicle 5. This makes it possible to maintain communication between the control server 50 and each vehicle 5 (driving control device 20) as specified even if an abnormality occurs in packet communication.

[0060] Thus, in this embodiment, the communication_ECU 51 corresponds to a specific example of a second communication control unit.

[0061] The information recognition ECU 52 recognizes the driving environment information within the control area in real time based on the driving environment information collected from each vehicle 5 and various sensing devices, for example, via packet communication. This driving environment information recognition is performed, for example, by successively updating road map information based on the collected driving environment information.

[0062] For this reason, a road map database 52a is connected to the information recognition_ECU 52. Similar to the on-board road map database 52a, this road map database 52a stores high-precision road map information (dynamic map) as driving environment information. The information recognition_ECU 52 recognizes the driving environment information by updating the road map information in real time using the driving environment information received (collected) by the communication_ECU 51. The recognized driving environment information is transmitted to each vehicle 5 via packet communication by the communication_ECU 51.

[0063] Here, for example, remote prohibited areas for prohibiting remote driving control, which will be described later, are set in advance in the road map information as shown in Fig. 6. These prohibited areas include, for example, areas with consistently poor radio wave conditions, areas where monitoring by various sensing devices such as cameras is hindered by obstructions such as walls, and areas where pedestrians pass by, such as crosswalks.

[0064] Thus, in this embodiment, the information recognition_ECU 52 corresponds to a specific example of a second traveling environment information acquisition unit.

[0065] The travel_ECU 53 is capable of performing travel control (remote travel control) from a remote location for each vehicle 5. Here, the travel_ECU 53 can substitute for all of the autonomous travel control performed by the in-vehicle travel_ECU 21 through remote travel control. Alternatively, the travel_ECU 53 can substitute for part of the autonomous travel control performed by the in-vehicle travel_ECU 21 through remote travel control.

[0066] For this reason, the travel_ECU 53 calculates various control information for remotely controlling each vehicle 5 present within the control area. In this case, the travel_ECU 53 calculates various control information based on driving environment information (road map information) updated in real time by the information recognition_ECU 52. The calculation of these control information is similar to the calculation of control information performed by the in-vehicle travel_ECU 21 for autonomous driving control, for example. However, the calculation of various control information by the travel_ECU 53 is restricted for vehicles 5 present within the remote control prohibited area.

[0067] Thus, in this embodiment, the travel_ECU 53 corresponds to a specific example of a second travel control unit.

[0068] The off-vehicle driving control device 70 has a function to, for example, take over the remote driving control of each vehicle 5 performed by the driving_ECU 53 of the control server 50. The off-vehicle driving control device 70 has, for example, a communication control unit (hereinafter referred to as "communication_ECU") 71 and a driving control unit (hereinafter referred to as "driving_ECU") 72.

[0069] A transceiver 73 is connected to the communication_ECU 71 as a communication device.

[0070] The transceiver 73 is capable of performing packet-switched communication using, for example, the HTTP protocol or the MQTT protocol.

[0071] This transceiver 73 enables the communication_ECU 71 to perform packet communication with, for example, the control server 50 .

[0072] For example, the communication_ECU 71 can receive, in real time, information about the driving environment recognized by the information recognition_ECU 52. Furthermore, the communication_ECU 71 can transmit, in real time, control information for a specific vehicle 5 to the control server 50.

[0073] The transceiver 73 is also capable of performing circuit-switched communications using, for example, the SMPP protocol.

[0074] The transceiver 73 enables the communication_ECU 71 to perform circuit-switched communication with the control server 50, for example.

[0075] This makes it possible to maintain communication between the external driving control device 70 and the control server 50 as specified even if an abnormality occurs in packet communication.

[0076] Thus, in this embodiment, the communication_ECU 71 corresponds to a specific example of a third communication control unit.

[0077] The travel_ECU 72 is capable of performing travel control (remote travel control) for a specific vehicle 5 in place of the travel_ECU 53 of the control server 50. In this case, the travel_ECU 72 calculates various types of control information based on travel environment information (road map information) and the like received in real time from the control server 50 by the communication_ECU 71. The calculation of these pieces of control information is similar to, for example, the calculation of control information performed by the in-vehicle travel_ECU 21 to perform autonomous travel control.

[0078] Thus, in this embodiment, the travel_ECU 72 corresponds to a specific example of a third travel control means.

[0079] The off-vehicle driving control device 70 may be provided with an operation input device (not shown), such as a touch panel or an operation lever, as a third driving control means instead of the driving_ECU 72. In this case, the off-vehicle driving control device 70 performs remote driving control (remote steering) of the vehicle 5 by having a user or the like operate the operation input device based on driving environment information.

[0080] Next, a failure countermeasure (safety countermeasure) for when various failures occur during execution of remote travel control in the driving control system 1 configured as above will be described.

[0081] To implement a fault prevention measure during remote driving control, the communication_ECU 22 of the vehicle 5 (driver control device 10) monitors for communication faults with the control server 50. For example, the communication_ECU 22 periodically transmits a PING command to the control server 50 using packet-switched communication. This allows the communication_ECU 22 to check the communication response rate from the control server 50 to the PING command.

[0082] When the communication_ECU 22 determines that the communication response rate from the control server 50 has decreased, the communication_ECU 22 notifies the control server 50 of the decrease in the communication response rate through circuit-switched communication using the transceiver 19. Here, a state in which the communication response rate has decreased refers to, for example, a state in which packet-switched communication is established but the communication speed has decreased to a level insufficient for appropriate remote driving control. Therefore, even if the communication response rate has decreased, the packet-switched communication continues as specified.

[0083] When notified of the decrease in the communication response rate, the communication_ECU 51 of the control server 50 instructs the corresponding vehicle 5 to switch from remote driving control to autonomous driving control. That is, the communication_ECU 51 interrupts the remote driving control before an abnormality occurs in the packet-switched communication, and switches the driving control of the vehicle 5 to autonomous driving control. Furthermore, if the corresponding vehicle 5 is being remotely controlled (remotely piloted) by the off-vehicle driving control device 70, the communication_ECU 51 requests the corresponding off-vehicle driving control device 70 to stop the remote driving control.

[0084] Furthermore, the communication_ECU 51 of the control server 50 monitors the reliability of communication with the vehicle 5. For example, the communication_ECU 51 monitors the reliability of communication based on the frequency of receiving packets per unit time from the vehicle 5. When the frequency of receiving packets from the vehicle 5 decreases and the reliability of communication decreases, the communication_ECU 51 determines that an abnormality has occurred in the packet communication with the vehicle 5.

[0085] When determining that the communication reliability has decreased, the communication_ECU 51 instructs the corresponding vehicle 5 to stop the emergency vehicle using autonomous driving control, for example. The communication_ECU 51 also instructs the external driving control device 70 to stop remote driving control, for example. Furthermore, the communication_ECU 51 notifies surrounding vehicles, pedestrians, etc. of the presence of the abnormal vehicle by simultaneous notification.

[0086] Furthermore, the communication_ECU 51 of the control server 50 monitors communication failures within the control area. To this end, the communication_ECU 51 determines, for example, the reliability of packet communication with each vehicle 5 present within the control area. Then, the communication_ECU 51 determines the communication failure level for each driving lane within the control area based on the communication reliability with each vehicle 5. As a result, the communication_ECU 51 gradually changes the driving control for the vehicles 5 present in each driving lane depending on the determined communication failure level.

[0087] Furthermore, when the communication_ECU 51 receives a fault code from the vehicle 5, it instructs the vehicle 5 to make an emergency vehicle stop and urges those around the vehicle 5 to take measures to deal with the faulty vehicle.

[0088] Next, the communication failure determination (communication response rate drop determination) between the vehicle 5 and the control server 50 performed by the communication_ECU 22 will be described with reference to the flowchart of a communication response rate determination routine shown in FIG.

[0089] This routine is repeatedly executed at set time intervals by the communication_ECU 22. When the routine starts, in step S101, the communication_ECU 22 transmits a PING command to the control server 50. More specifically, the communication_ECU 22 transmits the PING command to the transceiver 55 of the control server 50 by packet communication using the transceiver 19.

[0090] In the following step S102, the communication_ECU 22 calculates a moving average value of the round-trip time (RTT) of the PING command over a set period of time in the past (for example, the past 10 seconds).

[0091] In the following step S103, the communication_ECU 22 checks whether or not a decrease in the communication response rate between the vehicle 5 and the control server 50 has occurred based on the RTT moving average value.

[0092] If it is determined in step S103 that the communication response rate has not decreased (step S103: NO), the communication_ECU 22 exits the routine.

[0093] On the other hand, if it is determined in step S103 that a decrease in the communication response rate has occurred (step S103: YES), the communication_ECU 22 proceeds to step S104.

[0094] Then, in step S104, the communication_ECU 22 notifies the control server 50 of the decrease (abnormality) in the communication response rate, and then exits the routine. In this case, the communication_ECU 22 notifies the control server 50 of the decrease in the communication response rate, for example, by circuit-switched communication (SMS communication) using the transceiver 19. This is because such circuit-switched communication enables more stable communication than packet communication.

[0095] Next, fault countermeasure control in the event of a communication failure between the vehicle 5 and the control server 50 will be described with reference to the flowchart of the fault countermeasure control routine shown in Figure 8. Note that this fault countermeasure control is executed, for example, repeatedly at set time intervals by the communication_ECU 51 of the control server 50. In this case, the communication_ECU 51 executes fault countermeasure control for each vehicle 5 in response to a communication failure that is individually determined between each vehicle 5 and the control server 50. Therefore, the following fault countermeasure control routine is executed individually for each vehicle 5.

[0096] When the routine starts, in step S201, the communication_ECU 51 calculates the reliability of communication with the vehicle 5. This communication reliability is calculated, for example, based on the frequency with which the transceiver 55 receives packet data from the vehicle 5 per unit time. In this case, for example, the lower the frequency with which the transceiver 55 receives packet data from the vehicle 5 per unit time, the lower the calculated communication reliability.

[0097] In the next step S202, the communication_ECU 51 checks whether or not a decrease in the communication reliability calculated in the above-mentioned step S201 has occurred. That is, for example, if the communication reliability is less than a predetermined threshold, the communication_ECU 51 determines that general socket communication using a packet switching method is not possible and that a decrease in communication reliability has occurred.

[0098] If it is determined in step S202 that a decrease in communication reliability due to packet communication with the vehicle 5 has occurred (step S202: YES), the communication_ECU 51 proceeds to step S207.

[0099] On the other hand, if it is determined in step S202 that the communication reliability due to packet communication with the vehicle 5 has not decreased (step S202: NO), the communication_ECU 51 proceeds to step S203.

[0100] In step S203, the communication_ECU 51 checks whether a decrease in the communication response rate has occurred. That is, even if general socket communication using a packet switching method is possible, if the communication performance level required for remote driving control is not met, it becomes difficult to perform appropriate remote driving control. Therefore, the communication_ECU 51 determines whether the communication response rate calculated by the communication_ECU 22 of the vehicle 5 has decreased.

[0101] Then, in step S203, if it is determined that the communication response rate is equal to or greater than the threshold value and that a decrease in the communication response rate has not occurred (step S203: NO), the communication_ECU 51 proceeds to step S204.

[0102] When the process proceeds from step S203 to step S204, the communication_ECU 51 transmits various control information for remote driving control calculated by the driving_ECU 53 to the vehicle 5 by packet communication using the transceiver 55. As a result, the communication_ECU 51 continues the remote driving control.

[0103] On the other hand, in step S203, if it is determined that the communication response rate is less than the threshold value and that a decrease in the communication response rate has occurred (step S203: YES), the communication_ECU 51 proceeds to step S205.

[0104] When the process proceeds from step S203 to step S205, the communication_ECU 51 requests the vehicle 5 to start autonomous driving control. Here, if the communication response rate is decreasing, it is highly likely that the communication performance level required for remote driving control is not met. On the other hand, even if the communication response rate is decreasing, if the communication reliability is maintained at a predetermined level, it is highly likely that a communication level sufficient to receive driving environment information from the control server 50 at the transceiver 19 is maintained. Therefore, the driving_ECU 21 of the vehicle 5 performs autonomous driving control based on driving environment information obtained by adding the driving environment information received from the control server 50 to driving environment information acquired by various autonomous sensing devices, etc. As a result, the communication_ECU 51 transitions driving control from remote driving control to autonomous driving control before the communication reliability decreases (before a communication abnormality occurs).

[0105] Furthermore, when the process proceeds from step S205 to step S206, the communication_ECU 51 makes a remote control stop request to the external driving control device 70, and then exits the routine. As a result, if there is a user (remote driver) remotely controlling the vehicle 5 using the external driving control device 70, the remote driver is notified of the remote control stop request.

[0106] The communication in steps S205 and S206 is performed, for example, by using circuit-switched communication. That is, the communication_ECU 51 issues instructions such as switching of driving control by using circuit-switched communication while maintaining transmission and reception of driving environment information by using packet-switched communication.

[0107] When the process proceeds from step S202 to step S207, the communication_ECU 51 notifies the vehicle 5 that an abnormality has occurred in communication with the control server 50. Furthermore, the communication_ECU 51 requests the vehicle 5 to execute emergency vehicle stop control.

[0108] In the next step S208, the communication_ECU 51 notifies the off-vehicle driving control device 70 that an abnormality has occurred in the communication between the vehicle 5 and the control server 50. Furthermore, the communication_ECU 51 requests the off-vehicle driving control device 70 to stop the remote driving control. As a result, for example, if the driving_ECU 71 of the off-vehicle driving control device 70 is performing remote driving control on the vehicle 5, the remote driving control is stopped.

[0109] In the following step S209, the communication_ECU 51 notifies other vehicles and pedestrians in the vicinity of the vehicle 5 of the presence of an abnormal vehicle or guides them to a safe evacuation site, and then exits the routine.

[0110] The communications in steps S207 and S208 are performed using, for example, circuit-switched communications, and the communications in step S209 are performed using, for example, simultaneous distribution using circuit-switched communications.

[0111] Next, fault countermeasure control in the event of a communication abnormality within a control area will be described with reference to the flowchart of the fault countermeasure control routine shown in Figures 9 and 10. While the control shown in Figure 8 is a fault countermeasure control for individual communication failures between each vehicle 5 and the control server 50, the control shown in Figures 9 and 10 performs fault countermeasure control after comprehensively determining communication failures for each lane within the control area. This routine is repeatedly executed at set intervals by the communication_ECU 51, for example. Furthermore, this routine is executed individually for each driving lane within the control area, for example.

[0112] When the routine starts, the communication_ECU 51 calculates the communication reliability within the target driving lane in the control area based on the communication reliability calculated for each vehicle 5 present in the control area.

[0113] The communication reliability within each driving lane is calculated based on the communication reliability of each vehicle 5 present in the driving lane. For example, the communication_ECU 51 calculates the average value of the reliabilities of packet communication between each vehicle 5 present in the driving lane and the control server 50 as the communication reliability within the driving lane. Alternatively, the communication_ECU 51 calculates the smallest value among the reliabilities of packet communication between each vehicle 5 present in the driving lane and the control server 50 as the communication reliability within the driving lane.

[0114] In the next step S302, the communication_ECU 51 checks whether the communication reliability in the driving lane has decreased to below a threshold value.

[0115] If it is determined in step S302 that the communication reliability is equal to or greater than the threshold value (step S302: NO), the communication_ECU 51 proceeds to step S303.

[0116] In step S303, the communication_ECU 51 determines that there is no communication failure in the target driving lane, and then exits the routine.

[0117] On the other hand, if it is determined in step S302 that the communication reliability is less than the threshold value (step S302: YES), the communication_ECU 51 proceeds to step S304.

[0118] In step S304, the communication_ECU 51 selects a distribution protocol for the vehicles 5 in the driving lane. That is, even if the reliability of packet communication has decreased, the communication_ECU 51 selects packet communication as the distribution protocol if it is possible to distribute instructions using packet communication to each vehicle 5 in the driving lane. On the other hand, if it is difficult to distribute instructions using packet communication to each vehicle 5 in the driving lane, the communication_ECU 51 selects circuit-switched communication as the distribution protocol.

[0119] In the next step S305, the communication_ECU 51 checks the elapsed time since the communication reliability in the driving lane fell below the threshold value.

[0120] Then, in step S306, the communication_ECU 51 checks whether a long time (a set time or more) has passed since the communication reliability in the driving lane fell below the threshold value.

[0121] If it is determined in step S306 that a long time has elapsed (step S306: YES), the communication_ECU 51 proceeds to step S309.

[0122] On the other hand, if it is determined in step S306 that a long time has not elapsed (step S306: NO), the communication_ECU 51 proceeds to step S307.

[0123] In step S307, the communication_ECU 51 determines that the communication failure level in the target driving lane is “1.” Here, the communication failure level 1 means, for example, that a short-term, area-limited communication failure (communication interruption) is occurring in the target driving lane.

[0124] In the next step S308, the communication_ECU 51 uses the communication protocol selected in step S304 to instruct each vehicle 5 in the target driving lane to perform autonomous driving using waypoint (WP) control, and then returns to step S301. That is, the communication_ECU 51 instructs each vehicle 5 to continue autonomous driving based on various information (driving environment information, etc.) shared with the control server 50.

[0125] When the process proceeds from step S306 to step S309, the communication_ECU 51 determines that the communication failure level in the target driving lane is “2.” Here, communication failure level 2 means, for example, that a long-term, area-limited communication failure has occurred in the driving lane.

[0126] In the following step S310, the communication_ECU 51 uses the communication protocol selected in step S304 to instruct each vehicle 5 in the target driving lane to degrade autonomous driving, and then proceeds to step S311. Here, the communication_ECU 51 instructs each vehicle 5 to decelerate to a predetermined speed as the instruction to degrade autonomous driving. Alternatively, the communication_ECU 51 instructs each vehicle 5 to stop a predetermined control item as the instruction to degrade autonomous driving, for example.

[0127] In step S311, the communication ECU 51 checks the area where the communication service is provided by referring to a pre-defined radio wave map. Furthermore, the communication ECU 51 calculates the communication reliability in each of the driving lanes other than the target driving lane by the same process as in step S301.

[0128] In the next step S312, the communication_ECU 51 checks, based on the radio wave map, whether or not the target driving lane is located within the area where the communication service is provided.

[0129] Then, in step S312, if it is determined that the driving lane is outside the service area (step S312: NO), the communication_ECU 51 proceeds to step S316.

[0130] On the other hand, if it is determined in step S312 that the driving lane is within the service area (step S312: YES), the communication_ECU 51 proceeds to step S313.

[0131] In step S313, the communication_ECU 51 checks whether there are multiple driving lanes in which communication failure is occurring other than the target driving lane.

[0132] If it is determined in step S313 that there are not multiple driving lanes in which a communication failure has occurred (step S313: NO), the communication_ECU 51 returns to step S319.

[0133] On the other hand, if it is determined in step S313 that there are multiple driving lanes in which a communication failure has occurred (step S313: YES), the communication_ECU 51 determines that the communication failure level in the target driving lane is "3." Here, communication failure level 3 means, for example, that a long-term communication failure (large-scale communication failure) has occurred in a large area that includes the target driving lane.

[0134] In the next step S315, the communication_ECU 51 uses the communication protocol selected in step S304 to instruct each vehicle 5 in the target driving lane to perform autonomous driving based mainly on the driving environment information acquired by the autonomous sensing device, and then exits the routine. Note that in step S315, the communication_ECU 51 can also communicate with each vehicle 5 using a communication carrier other than the current communication carrier.

[0135] Furthermore, when the process proceeds from step S312 to step S316, the communication_ECU 51 determines that the communication failure level in the target driving lane is “0.” Here, the communication failure level of 0 means, for example, that the target driving lane is outside the communication service area.

[0136] In the next step S317, the communication_ECU 51 uses a circuit-switched communication protocol to instruct each vehicle 5 in the target driving lane to perform autonomous driving based on the driving environment information acquired mainly by the autonomous sensing device, and then exits the routine. Note that in step S317, the communication_ECU 51 can also communicate with each vehicle 5 using a communication carrier other than the current communication carrier.

[0137] Next, the fault countermeasure control in the event of a vehicle failure will be described with reference to the flowchart of the fault countermeasure control routine shown in Fig. 11. This routine is repeatedly executed by the communication_ECU 51 at set time intervals, for example.

[0138] When the routine starts, the communication_ECU 51 checks the vehicle information transmitted from each vehicle 5 in step S401.

[0139] In the following step S402, the communication_ECU 51 checks whether or not there is a vehicle 5 that has transmitted a fault code to the control server 50.

[0140] If it is determined in step S402 that there is no vehicle 5 that has transmitted a fault code (step S402: NO), the communication_ECU 51 exits the routine.

[0141] On the other hand, if it is determined in step S402 that a vehicle 5 that has transmitted a malfunction code is present (step S402: YES), the communication_ECU 51 proceeds to step S403.

[0142] In step S403, the communication_ECU 51 stops the remote driving control of the vehicle 5 and instructs the vehicle 5 to make an emergency stop.

[0143] In the following step S404, the communication_ECU 51 instructs the external driving control device 70 to stop remote control and to transition to remote control stop processing.

[0144] Furthermore, in step S405, the communication_ECU 51 supplies the vehicle abnormality information to other vehicles and dealers present around the vehicle 5, and then exits the routine.

[0145] According to this embodiment, the driving control system 1 includes a communication_ECU 22 provided in the vehicle 5 and communicating with the outside world using either packet-switched communication or circuit-switched communication, a communication_ECU 51 provided in the control server 50 and communicating with the outside world using either packet-switched communication or circuit-switched communication, autonomous sensing devices (11 to 14) provided in the vehicle 5 and acquiring driving environment information, an information recognition_ECU 52 provided in the control server 50 and acquiring driving environment information based on information collected using the packet-switched communication, a driving_ECU 21 provided in the vehicle 5 and performing autonomous driving control of the vehicle 5 based on the driving environment information, and a driving_ECU 53 provided in the control server 50 and performing remote driving control of the vehicle 5 based on the driving environment information. When the communication_ECU 51 recognizes a decrease in the communication response rate with the vehicle 5 or a communication abnormality during remote driving control using packet-switched communication, the communication_ECU 51 instructs the vehicle 5 to switch from remote driving control to autonomous driving control using circuit-switched communication. This makes it possible to ensure both convenience and safety through the operation control of the operation control system 1.

[0146] That is, when the communication_ECU 51 recognizes a decrease in the communication response rate or communication reliability (communication abnormality) with the vehicle 5 while remote driving control is being performed using packet-switched communication, the communication_ECU 51 instructs the vehicle 5 to switch to autonomous driving control using circuit-switched communication. Circuit-switched communication allows for stable communication with a smaller amount of data during emergencies or disasters than packet-switched communication. This allows the communication_ECU 51 to accurately and quickly instruct the vehicle 5 to switch from remote driving control to autonomous driving control even if a failure occurs in packet-switched communication. Therefore, before stable remote driving control becomes difficult, remote driving control can be switched to autonomous driving control and driving control can be continued, ensuring high safety and convenience.

[0147] In this case, the vehicle 5, the control server 50, and the external driving control device 70 each use a single transceiver 19, 55, and 73, respectively, and redundancy is ensured by multiplexing the communication protocol. Therefore, even in the event of a packet communication failure, communication for sending necessary notifications between each device can be ensured by circuit-switched communication with a simple configuration.

[0148] Furthermore, when a decrease in the communication response rate is recognized as a communication failure, the communication_ECU 51 continues packet-switched communication and maintains the transmission and reception of driving environment information. As a result, the driving_ECU 21 performs autonomous driving control based on driving environment information obtained by adding driving environment information received from the control server 50 to driving environment information obtained by the autonomous sensing devices (11 to 14) and the like. Therefore, it is possible to achieve highly safe autonomous driving control by using driving environment information that is wider in scope than driving environment information obtained by the autonomous sensing devices (11 to 14) alone.

[0149] Furthermore, when a decrease in communication reliability of packet communication (communication abnormality) is recognized as a communication failure, the travel_ECU 21 brings the vehicle 5 to an emergency stop in a safe place by autonomous travel control based on travel environment information acquired by the autonomous sensing devices (11 to 14), etc. This makes it possible to ensure high safety without continuing unreasonable travel control.

[0150] Furthermore, the communication_ECU 51 evaluates the communication reliability for each driving lane within the control area, and if a communication abnormality occurs in the driving lane in which the vehicle 5 is traveling, even if there is no abnormality in the packet communication itself between the vehicle 5 and the control server 50, the communication_ECU 51 gradually degrades the level of driving control of the vehicle 5 in accordance with the communication failure level. As a result, in the event of a communication abnormality, comprehensive fault countermeasures can be taken for each vehicle 5 present in the driving lane, and a higher level of safety in driving control can be achieved.

[0151] In the above-described embodiment, the image recognition_ECU 11d, the locator_ECU 20, the corresponding_ECU 21, the communication_ECU 22, the communication_ECU 51, the information recognition_ECU 52, the traveling_ECU 53, the communication_ECU 71, and the traveling_ECU 72 are configured, for example, by a well-known microcomputer and its peripheral devices. The microcomputer includes a CPU, RAM, ROM, a non-volatile storage unit, etc. The ROM stores programs to be executed by the CPU and fixed data such as data tables in advance. Note that all or part of the functions of the processor may be configured by logic circuits or analog circuits. Furthermore, the processing of various programs may be realized by electronic circuits such as FPGAs.

[0152] The present invention is not limited to the above-described embodiment, and various modifications and variations are possible, and these are also within the technical scope of the present invention.

Claims

1. A first communication control means provided in a vehicle for selectively using packet-switching communication or circuit-switching communication to communicate with the outside; A second communication control means provided in a control server for selectively using the packet-switching communication or the circuit-switching communication to communicate with the outside; A first driving environment information acquisition means provided in the vehicle for acquiring first driving environment information using an autonomous sensor; A second driving environment information acquisition means provided in the control server for acquiring second driving environment information based on information collected using the packet-switching communication; A first driving control means provided in the vehicle for performing autonomous driving control on the vehicle based on the first driving environment information; A second driving control means provided in the control server for performing remote driving control on the vehicle based on the second driving environment information, the driving control system comprising: When the second communication control means recognizes a decrease in the communication response rate or a communication abnormality during the execution of the remote driving control using the packet-switching communication, the second communication control means uses the circuit-switching communication and instructs the vehicle to switch from the remote driving control to the autonomous driving control. A driving control system characterized by this.

2. The first communication control means receives the second driving environment information that covers a wider range than the first driving environment information from the control server, The first driving control means performs the autonomous driving control based on the first driving environment information added with the second driving environment information. The driving control system according to claim 1, characterized by this.

3. When the decrease in the communication response rate is recognized, the second communication control means continues to transmit the second driving environment information using the packet-switching communication, When the decrease in the communication response rate is recognized, the first driving control means performs the autonomous driving control based on the first driving environment information added with the second driving environment information. The driving control system according to claim 2, characterized by this.

4. When the communication abnormality is recognized, the first driving control means emergency stops the vehicle by the autonomous driving control based on the first driving environment information. The driving control system according to claim 2, characterized by this.

5. It is provided in an off-vehicle driving control device that performs driving control of the vehicle via the control server, and includes a third communication control means that selectively uses the packet-switching communication or the circuit-switching communication to communicate with the outside; It is provided in the off-vehicle driving control device, and includes a third driving control means that performs remote driving control of the vehicle based on the second driving environment information received from the control server using the packet-switching communication; The second communication control means is characterized in that when recognizing a decrease in the communication response rate or a communication abnormality with the vehicle during the execution of the remote driving control using the packet-switching communication, it uses the circuit-switching communication to instruct the off-vehicle driving control device to stop the remote driving control. The driving control system according to any one of claims 1 to 4.

6. A vehicle is provided with a first transceiver capable of performing packet-switching communication and circuit-switching communication; A vehicle is provided with an autonomous sensor for acquiring first driving environment information; A first processor provided in the vehicle; A control server is provided with a second transceiver capable of performing packet-switching communication and circuit-switching communication; A second processor provided in the control server; Comprising; The first processor: Selectively uses the packet-switching communication or the circuit-switching communication by the first transceiver to communicate with the outside; Performs autonomous driving control of the vehicle based on the first driving environment information; The second processor: Selectively uses the packet-switching communication or the circuit-switching communication by the second transceiver to communicate with the outside; Acquires second driving environment information based on the information collected using the packet-switching communication; Performs remote driving control of the vehicle based on the second driving environment information; When recognizing a decrease in the communication response rate or a communication abnormality with the vehicle during the execution of the remote driving control using the packet-switching communication, it uses the circuit-switching communication to instruct the vehicle to switch from the remote driving control to the autonomous driving control. A driving control system characterized by this. Claims 7: A control server capable of communicating with a vehicle, comprising: a first communication control means for selectively using packet-switching communication or circuit-switching communication to communicate with the outside; a first driving environment information acquisition means for acquiring first driving environment information using an autonomous sensor; and a first driving control means for performing autonomous driving control on the vehicle based on the first driving environment information. A second communication control means for selectively using the packet-switching communication or the circuit-switching communication to communicate with the outside; A second driving environment information acquisition means for acquiring second driving environment information based on the information collected using the packet-switching communication; A second driving control means for performing remote driving control on the vehicle based on the second driving environment information, wherein when the second communication control means recognizes a decrease in the communication response rate or a communication abnormality with the vehicle during the execution of the remote driving control using the packet-switching communication, the second communication control means uses the circuit-switching communication to instruct the vehicle to switch from the remote driving control to the autonomous driving control. The control server is characterized by this. Claims 8: A communication control unit for selectively using packet-switching communication or circuit-switching communication to communicate with a control server; An autonomous sensor for acquiring driving environment information; A driving control unit for executing autonomous driving control based on the driving environment information and remote driving control based on an instruction from the control server, During the execution of the remote driving control using the packet-switching communication, the communication control unit determines the communication state with the control server by the packet-switching communication, and when the communication state has dropped to a predetermined level, the communication control unit transmits a signal indicating the drop in the communication state to the control server using the circuit-switching communication, and receives a signal indicating a driving control switching instruction transmitted from the control server using the circuit-switching communication in response to the drop in the communication state. The driving control unit is characterized by switching from the remote driving control to the autonomous driving control based on the signal indicating the driving control switching instruction.