Operation system and method

The driving system addresses the challenge of stopped vehicles by using a communication circuit and processing unit to determine and respond appropriately, improving user convenience and safety.

WO2025205334A1PCT designated stage Publication Date: 2025-10-02DENSO CORP
View PDF 10 Cites 0 Cited by

Patent Information

Application Number
PCT/JP2025/010743
Authority / Receiving Office
WO · WO
Patent Type
Applications
Current Assignee / Owner
Priority Date
2024-03-28
Filing Date
2025-03-19
Publication Date
2025-10-02

AI Technical Summary

Technical Problem

Existing autonomous driving technologies fail to appropriately respond when encountering a stopped vehicle in front, reducing user convenience and safety.

Method used

A driving system equipped with a communication circuit and processing unit that determines the presence of a stopped vehicle and adjusts the vehicle's response based on the vehicle's type or behavior, enabling appropriate maneuvering.

Benefits of technology

Enables the vehicle to respond effectively to stopped vehicles, enhancing user convenience and safety by ensuring appropriate maneuvers.

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure JP2025010743_02102025_PF_FP_ABST
    Figure JP2025010743_02102025_PF_FP_ABST
Patent Text Reader

Abstract

In the present invention, a processor identifies, on the basis of sensor data received via a communication interface, whether a current situation falls under a stopped vehicle-related scenario, which is a scenario related to traveling near a stopped vehicle that could potentially start moving. If the current situation has been found to fall under a stopped vehicle-related scenario, the processor determines whether to execute avoidance control with respect to the stopped vehicle in accordance with either the type of the stopped vehicle or the behavior of the stopped vehicle. If it was sensed that the stopped vehicle started moving during execution of the avoidance control, the processor determines whether to suspend or continue the avoidance control in accordance with the location or driving speed of a host vehicle with respect to the stopped vehicle.
Need to check novelty before this filing date? Find Prior Art

Description

Driving system and method CROSS-REFERENCE TO RELATED APPLICATIONS

[0001] This application is based on Patent Application No. 2024-054721 filed in Japan on March 28, 2024, and the contents of the original application are incorporated by reference in their entirety.

[0002] The disclosure of this specification relates to a technology for autonomously driving a vehicle.

[0003] Patent Document 1 describes a technique for overtaking a preceding vehicle.

[0004] Patent No. 6031066

[0005] A situation may occur in which another vehicle is stopped or parked in front of the host vehicle, blocking the path of the host vehicle. In such a scenario, it may be necessary to drive the host vehicle in a way that avoids the other vehicle. However, Patent Document 1 does not consider such a scenario. With the configuration disclosed in Patent Document 1, when there is a stopped vehicle ahead, the autonomous vehicle cannot respond appropriately, which may reduce the convenience or sense of security of the vehicle user.

[0006] One of the objectives of the present disclosure is to provide an autonomous driving technology that can respond appropriately to another vehicle that is stopped in front of the host vehicle.

[0007] The driving system disclosed herein is a driving system configured to be able to perform control to cause the vehicle to drive autonomously, and includes a communication circuit that receives signals indicative of the external environment, and a processing unit that executes processing related to the autonomous driving of the vehicle based on the signals received by the communication circuit.The processing unit is configured to determine, based on the signals received by the communication circuit, whether the current situation corresponds to a scenario in which the vehicle is driving near another stopped vehicle, and, based on the determination that the current situation corresponds to the scenario, determine a response to the other vehicle depending on the type or behavior of the other vehicle.

[0008] The method included in the present disclosure is a method executed by a processor provided in a driving system configured to be able to drive a vehicle autonomously, and includes determining whether the current situation corresponds to a scenario in which the vehicle is driving near another stopped vehicle based on a signal indicating the external environment received by a communication circuit, and determining a response to the other vehicle depending on the type or behavior of the other vehicle based on the determination that the current situation corresponds to the scenario.

[0009] According to the above technology, the behavior of the host vehicle is determined in response to a vehicle stopped ahead of the host vehicle (i.e., a stopped vehicle) depending on the type or behavior of the vehicle, thereby enabling the host vehicle to respond appropriately to the vehicle stopped ahead of the host vehicle.

[0010] Note that the symbols in parentheses in the claims indicate a correspondence with the specific means described in the embodiments described below as one aspect, and do not limit the technical scope of the present disclosure.

[0011] 1 is a diagram showing a vehicle equipped with a driving system. FIG. 1 is a diagram showing the hardware configuration of the driving system. FIG. 2 is a diagram showing the functional configuration of the driving system. FIG. 3 is a diagram showing the functional configuration of a risk confirmation unit. FIG. 4 is a diagram showing a longitudinal safe distance. FIG. 5 is a diagram showing a longitudinal safe distance. FIG. 6 is a diagram showing a lateral safe distance. FIG. 7 is a diagram showing a lane-based coordinate system. A flowchart illustrating a process for deriving an assumption. FIG. 8 is a diagram showing a stopped vehicle-related scenario. A flowchart showing an example of operation of the driving system in a stopped vehicle-related scenario. A diagram showing an initial phase of avoidance control. A diagram showing a middle phase of avoidance control. A diagram showing a later phase of avoidance control. A flowchart showing an example of operation of the driving system during avoidance control. A flowchart showing an example of operation of the driving system during avoidance control. A flowchart showing an example of operation of the driving system during avoidance control. A flowchart showing an example of operation of the driving system during avoidance control. A flowchart showing an example of operation of the driving system in a stopped vehicle-related scenario. A flowchart showing an example of operation of the driving system in a scenario stopped behind a stopped vehicle. A flowchart showing an example of operation of the driving system for determining whether to execute avoidance control based on the relationship between the expected stopping time of the stopped vehicle and the time required for avoidance. A flowchart showing an example of operation of the driving system for suspending and resuming avoidance control in response to the behavior of the stopped vehicle. Fig. 26 is a flowchart showing an example of the operation of a driving system that changes the inter-vehicle distance depending on the type of preceding vehicle. Fig. 27 is a diagram showing a situation in which a vehicle encounters a stopped vehicle on a road without a center line. Fig. 28 is a diagram showing a situation in which a vehicle encounters a stopped vehicle on a road with multiple lanes in each direction. Fig. 29 is a flowchart for explaining an example of the operation of the driving system in the situation shown in Fig. 26. Fig. 29 is a diagram showing the functional configuration of a driving system in one embodiment. Fig. 30 is a diagram showing the functional configuration of a driving system in another embodiment.

[0012] Hereinafter, embodiments of the present disclosure will be described with reference to the drawings. The present disclosure is not limited to the following embodiments. The configurations disclosed below may be modified in various ways without departing from the spirit of the present disclosure. Various modified examples may be appropriately combined as long as no technical contradictions arise. The present disclosure also includes configurations that are not explicitly stated and are formed by combining multiple modified examples. In the following description, components having the same function may be given the same reference numerals, and specific descriptions thereof may be omitted. Furthermore, components having the same function may be given the same or similar names, and specific descriptions thereof may be omitted. When only a portion of a configuration is mentioned, descriptions given elsewhere may apply to other parts.

[0013] (Explanation of Terms) Terms related to the disclosure of this specification are explained below. This explanation is included in the embodiments of the specification.

[0014] A road user may be a traffic participant on or adjacent to an active road for the purpose of traveling from one location to another. Road users may include pedestrians, cyclists, vehicles, and other vulnerable road users. A pedestrian may be a person walking on a sidewalk adjacent to a road. A cyclist may be a person riding a bicycle. A vehicle may be a passenger car, commercial vehicle, bus, etc. A vehicle may be a manually or autonomous vehicle.

[0015] A vulnerable road user (VRU) may be a road user not in a vehicle, such as a passenger car, public transport, train, etc. A vulnerable road user may also include unprotected road users, such as cyclists, motorcyclists, pedestrians, people with disabilities, or people with reduced mobility and orientation.

[0016] The dynamic driving task (DDT) may be the real-time operational and tactical functions for operating a vehicle in traffic. The DDT may also be all real-time operational and tactical functions for operating a vehicle on a roadway. Operational functions may include lateral vehicle motion control through steering and longitudinal vehicle motion control through acceleration and deceleration. Tactical functions may include detecting and responding to objects or events. Responses to detected objects / events may include planning and execution for avoidance, etc.

[0017] An ADS feature may be a design-specific functionality of an automated driving system within a particular operational design domain at a given automation level.

[0018] An automated driving system (ADS) may be a collection of hardware and software capable of performing the entire dynamic driving task on a continuous basis, whether or not it is limited to a specific operational design domain.

[0019] A DDT fallback may be a driver or automated system response to either perform the DDT or transition to a minimal-risk state after a failure occurs or upon detection of a malfunction or potentially dangerous behavior. A DDT fallback may be a method of transitioning from autonomy to driver or other system control using takeover / fallback conditions and associated use cases. A DDT fallback may also be a user response to perform the DDT or achieve a minimal-risk state after a system failure related to DDT performance or upon departure from the operational design domain, or a response by an automated driving system to achieve a minimal-risk state given the same circumstances.

[0020] A Minimal Risk Condition (MRC) may be a state of the vehicle to reduce risk if a given trip cannot be completed, or may be a stable, stopped state that a user or automated driving system places the vehicle in after DDT fallback is performed to reduce the risk of an accident if a given trip cannot or should not be continued.

[0021] An operational design domain (ODD) may be the specific conditions in which a given automated driving system is designed to function, and may include, but is not limited to, the operating conditions in which a given automated driving system or its features are specifically designed to function, including environmental, geographic, time-of-day restrictions, and / or the presence or absence of certain traffic / road characteristic requirements.

[0022] Safety of the intended functionality (SOTIF) may be the absence of undue risk due to insufficient functionality of the intended functionality or its implementation.

[0023] A driving policy may be a strategy and rules that define control behavior at the vehicle level.

[0024] A scenario may be a description of the temporal relationships between several scenes in a sequence of scenes, including the goals and values ​​in a specific situation influenced by actions and events, and a description of a continuous time sequence of activities that integrates a subject vehicle, all its external environments, and their interactions in the process of performing a specific driving task.

[0025] A safety-relevant object may be any dynamic or static object that may be relevant to the safe performance of a dynamic driving task.

[0026] Reasonably foreseeable may be technically reliable and have a reliable or measurable rate of occurrence.

[0027] A triggering condition may be a specific condition of a scenario that acts as a catalyst for subsequent system responses that contribute to unsafe behavior, failure to prevent, detect, and mitigate reasonably foreseeable indirect misuse.

[0028] A Minimal Risk Maneuver (MRM) may be a vehicle movement commanded by the automated driving system during DDT fallback to achieve a minimal risk condition.

[0029] A safety-related model may be a representation of safety-related aspects of driving behavior based on assumptions about the reasonably foreseeable behavior of other road users. A safety-related model may be an on-board or off-board safety verification or analysis device, a mathematical model, a more conceptual set of rules, a set of scenario-based behaviors, or a combination of these.

[0030] A formal model may be a model expressed in a formal notation that is used to verify system performance.

[0031] A safety envelope may be a set of limits and conditions within which an (automated) driving system is designed to operate, subject to constraints or controls, in order to maintain operation within an acceptable level of risk. A safety envelope may be a general concept that can be used to accommodate all principles to which a driving policy can adhere, according to which an ego-vehicle operated by an (automated) driving system may have one or more boundaries around it.

[0032] Response time may be the time it takes a road user in a given scenario to perceive a particular stimulus and begin to execute a response (braking, steering, accelerating, stopping, etc.).

[0033] Risk acceptance criteria / criterion are standards that represent the absence of unreasonable levels of risk, and may be, for example, physical parameters that define when a particular behavior is considered undesirable, a maximum number of accidents per hour, as low as reasonably practicable, etc.

[0034] A positive risk balance may be a criterion that demonstrates that a technical solution achieves an acceptable level of residual risk.

[0035] A proper response may be an action that is significant to avoid or ameliorate a dangerous situation in a reasonably foreseeable scenario in which other safety-related objects are operating within expected bounds.

[0036] Object and event detection and response (OEDR) may be a subtask of the dynamic driving task that involves monitoring the driving environment and executing appropriate responses to such objects and events.

[0037] (First embodiment) <Driving system> The driving system 9 of this embodiment is a system that realizes functions related to driving of the vehicle 1. The driving system 9 may be a vehicle system itself, or may be a component that constitutes part of the vehicle system. Part or all of the driving system 9 may be mounted on the vehicle 1 as shown in FIG. 1 . The vehicle 1 may be referred to as a host vehicle, a host vehicle, or the like. The vehicle 1 may be configured to be capable of wirelessly communicating directly with a roadside device 92. The vehicle 1 may be configured to be capable of communicating with other road users, such as a following vehicle 93, directly or indirectly via a communication infrastructure.

[0038] The vehicle 1 may be a road user capable of manual driving, such as a four-wheeled automobile or truck. The vehicle 1 may also be capable of automated driving. Automated driving may be referred to as autonomous driving by the driving system 9. Driving is classified into levels according to the extent to which a human driver performs all dynamic driving tasks (DDTs). There may be six automation levels, from 0 to 5, as specified in SAE J3016. At levels 0 to 2, the driver performs some or all of the DDTs. Levels 0 to 2 may be classified as so-called manual driving. Level 0 means that driving is not automated. Level 1 means that the driving system 9 assists the driver. Level 2 means that driving is partially automated. Level 2 may be divided into levels 2.0 and 2.5. At level 2.0, the system provides partial steering assistance, and the driver essentially performs the steering. Level 2.5 is a level at which the driver is required to monitor the surroundings, but the driving system 9 essentially performs steering. In the present disclosure, vehicle control corresponding to Level 2.5 is also referred to as automated driving with a surroundings monitoring obligation or semi-automated driving.

[0039] At levels 3 and above, while the ADS feature is activated, the driving system 9 performs all of the DDT. Levels 3 to 5 may be classified as so-called automated driving. A system capable of driving at level 3 or above may be called an automated driving system (ADS). A vehicle equipped with an automated driving system or a vehicle capable of driving at level 3 or above may be called an automated vehicle (AV).

[0040] Level 3 indicates a state in which driving is conditionally automated. A level 3 automated driving system performs DDT but does not perform DDT fallback. That is, at level 3, DDT fallback is performed by a driver who is ready for fallback. Level 4 indicates a state in which driving is highly automated. A level 4 automated driving system performs DDT and DDT fallback. A level 4 automated driving system can hand over DDT to the driver after reaching a minimum risk condition (MRC) by performing DDT fallback, etc. Taking over DDT between the driving system 9 and a human driver is also called delegation of authority. Level 5 indicates fully automated driving.

[0041] The conditions for executing level 3 and 4 autonomous driving may include some or all of the conditions indicated by the operational design domain (ODD). The ADS function may be defined within the scope of the ODD. The driving system 9 described in this embodiment is a driving system capable of executing level 3 or higher autonomous driving. That is, the driving system 9 may be capable of executing up to level 3 autonomous driving, up to level 4 autonomous driving, or even level 5 autonomous driving. The function for implementing level 3 or higher autonomous driving is referred to as an autonomous driving function. The autonomous driving function may be positioned as one of the applications provided by the driving system 9.

[0042] The driving system 9 provides functions such as automated driving to a vehicle user of the vehicle 1 that can participate in public road traffic. The vehicle user may be a driver riding in the vehicle 1. The vehicle user may be a passenger riding in the vehicle 1. If the vehicle 1 is a POV (Personally Owned Vehicle), the vehicle user may be the owner of the vehicle 1. If the vehicle 1 is used for MaaS (Mobility as a Service), the vehicle user may be an operator such as an operations manager that manages the operation of the vehicle 1.

[0043] The architecture of the driving system 9 may be selected to enable an efficient safety of the intended functionality (SOTIF) process. The architecture of the driving system 9 may be configured based on a sense-plan-act model. The sense-plan-act model includes a sense element, a plan element, and an act element as major system elements. The sense element, plan element, and act element interact with each other. Here, sense may be replaced by perception, plan may be replaced by determine, and act may be replaced by control, respectively.

[0044] At the technical level (i.e., from a technical perspective), the driving system 9 is implemented with at least a plurality of sensors 40 corresponding to sensing functions, at least one processing system 50 corresponding to planning functions, and a plurality of motion actuators 60 corresponding to acting functions. At the functional level (i.e., from a functional perspective), the driving system 9 is implemented with sensing functions, planning functions, and acting functions (see also Figures 3 and 4).

[0045] In detail, a detection unit 10 as an entity realizing a detection function may be constructed in the operation system 9 mainly including a plurality of sensors 40 and a processing system 50. The processing system 50 related to the detection function may be configured to process detection information from the sensors 40 and generate an environment model based on the detection information. A planner 20 and a risk confirmation unit 26 may be constructed in the operation system 9 mainly including such a processing system 50. The planner 20 is an entity realizing a planning function. Furthermore, the processing system 50 may be capable of outputting control signals (e.g., drive signals) for a plurality of motion actuators 60. A behavior unit 30 as an entity realizing a behavior function may be constructed in the operation system 9 mainly including such a processing system 50 and a plurality of motion actuators 60.

[0046] Here, the detection unit 10 may be realized in the form of a detection system serving as a subsystem provided so as to be distinguishable from the planner 20 and the action unit 30. The planner 20 may be realized in the form of a planning system serving as a subsystem provided so as to be distinguishable from the detection unit 10 and the action unit 30. The planning system may include a risk confirmation function. The risk confirmation function may be mounted in the operation system 9 independently of the detection unit 10, the planner 20, and the action unit 30. The action unit 30 may be realized in the form of an action system serving as a subsystem provided so as to be distinguishable from the detection unit 10 and the planner 20. The detection system, the planning system, and the action system may constitute components independent of each other. The subsystem referred to here may be replaced with a module, a unit, a device, a component, etc.

[0047] The detection unit 10 is responsible for detection functions, including localization (e.g., location estimation) of road users such as the vehicle 1 and other vehicles. The detection unit 10 detects the external environment, internal environment, vehicle state, and the state of the driving system 9 of the vehicle 1. The detection unit 10 may fuse the detected information to generate an environmental model. The environmental model may also be referred to as a world model. The planner 20 applies the objective and driving policy to the environmental model generated by the detection unit 10 to derive control actions. The behavior unit 30 executes the control actions derived by the planner 20.

[0048] <Physical Architecture> An example of the physical architecture of the driving system 9 will be described with reference to FIG. 2 . The driving system 9 includes a plurality of sensors 40, a plurality of motion actuators 60, a plurality of HMI devices 70, and a processing system 50. HMI stands for Human Machine Interface. These components can communicate with each other via one or both of wireless and wired connections. These components may also be able to communicate with each other through an in-vehicle network such as CAN (registered trademark) or Ethernet (registered trademark). Communication between devices may be achieved by any type of communication, including wired and wireless.

[0049] The multiple sensors 40 include one or more external environment sensors 41. Furthermore, the multiple sensors 40 may include one or more internal environment sensors 42. Furthermore, the multiple sensors 40 may include one or more communication systems 43. Furthermore, the multiple sensors 40 may include a map database (DB) 44. The combination of devices included in the multiple sensors 40 may be designed as appropriate. In the present disclosure, data indicating the environment outside or inside the vehicle that is sensed (or acquired) by the sensor 40 is also referred to as sensor data.

[0050] The external environment sensor 41 may include a sensor that detects objects present in the external environment of the vehicle 1. The external environment sensor 41 may include an object detection type sensor. Examples of the object detection type external environment sensor 41 include a camera, LiDAR (Light Detection and Ranging / Laser Imaging Detection and Ranging), laser radar, millimeter-wave radar, ultrasonic sonar, and acoustic sensor. The acoustic sensor generates an electrical signal corresponding to an external sound that is a sound outside the vehicle. The acoustic sensor may be, for example, a condenser microphone. The output signal of the acoustic sensor may be used to detect an alarm sound output by an emergency vehicle. The driving system 9 may be implemented with a combination of multiple types of external environment sensors 41 to monitor the front, sides, and rear directions of the vehicle 1.

[0051] Furthermore, the external environment sensor 41 may detect atmospheric conditions and weather conditions in the environment outside the vehicle 1. The external environment sensor 41 may include a condition detection type sensor. The condition detection type external environment sensor 41 may include at least one of an outside air temperature sensor, a temperature sensor, and a raindrop sensor.

[0052] The interior environment sensor 42 may detect a specific physical quantity related to the motion of the vehicle 1 (hereinafter, a motion physical quantity). The interior environment sensor 42 may include a motion physical quantity detection type sensor. The motion physical quantity detection type interior environment sensor 42 may include at least one of a speed sensor, an acceleration sensor, a gyro sensor, etc. The interior environment sensor 42 may detect the state of an occupant of the vehicle 1. The interior environment sensor 42 may include an occupant detection type sensor. The occupant detection type interior environment sensor 42 may include at least one of an actuator sensor, an interior monitor, a biological sensor, a seat sensor, an interior equipment sensor, etc. The interior monitor here may be a sensor or system that monitors a vehicle user (e.g., a driver) in the vehicle cabin. The actuator sensor is a sensor that detects the state of an occupant's operation of a motion actuator 60 related to motion control of the vehicle 1. The actuator sensor may include at least one of an accelerator sensor, a brake sensor, a steering sensor, etc.

[0053] The communication system 43 obtains communication data usable in the driving system 9 from an external system via wireless communication. The external system means any other system existing in the external environment of the vehicle 1. The communication system 43 may receive positioning signals from artificial satellites of a global navigation satellite system (GNSS) existing in the external environment of the vehicle 1. The positioning type communication device in the communication system 43 may be a GNSS receiver or the like.

[0054] The communication system 43 may transmit and receive communication signals to and from an external system such as a server 96. The V2X-type communication device in the communication system 43 may be a dedicated short range communications (DSRC) communication device, a cellular V2X (C-V2X) communication device, or the like. Examples of communication with the V2X system include communication with a communication system of another vehicle (V2V), communication with a roadside device 92 (V2I), communication with a pedestrian's mobile terminal (V2P), and communication with a network such as a cloud server (V2N). The roadside device 92 may be infrastructure equipment such as a communication device installed in a traffic light. The architecture of V2X communication, including V2I communication, may be an architecture specified in ISO 21217, ETSI TS 102 940-943, IEEE 1609, or the like.

[0055] The communication system 43 may receive a vehicle status message from the other vehicle 2. The vehicle status message may include the speed, current position, turn signal operation status, acceleration, etc. of the sender (other vehicle 2). The vehicle status message may include at least one of the shift position, brake pedal on / off, accelerator pedal on / off, and steering angle. The vehicle status message may be a CAM (Cooperative Awareness Message) or a BSM (Basic Safety Message). Data received by the wireless communication device 15 may also be included in the sensor data. The communication system 43 corresponds to a wireless communication device.

[0056] Furthermore, the communication system 43 may transmit and receive communication signals to and from a mobile terminal 91. The mobile terminal 91 may be a smartphone, wearable device, tablet, or the like present in the vehicle. The mobile terminal 91 may be a smartphone or the like carried by the vehicle user. A terminal communication type communication device in the communication system 43 may be a Bluetooth (registered trademark) device, a Wi-Fi (registered trademark) device, an infrared communication device, or the like. When the vehicle user's mobile terminal 91 is associated with the vehicle 1 in advance, the communication system 43 may transmit and receive communication signals to and from a mobile terminal 91 present in an external environment.

[0057] The map DB 44 is a database that stores map data that can be used by the driving system 9. The map DB 44 is configured using at least one type of storage medium, such as a semiconductor memory, a magnetic medium, or an optical medium. The map DB 44 may include a database of a navigation unit that navigates the driving route to the destination of the vehicle 1. The map DB 44 may include a database of probe data (PD) maps generated using probe data (PD) collected from each vehicle. The map DB 44 may include a database of high-precision maps with a high level of accuracy that are primarily used in autonomous driving system applications. The map DB 44 may also include a database of parking lot maps that include detailed parking lot information, such as parking space information, that is used in autonomous parking or parking assistance applications.

[0058] The map DB 44 suitable for the driving system 9 may acquire and store the latest map data by communicating with a map server via the communication system 43, for example. The map data is data representing the external environment of the vehicle 1, and is converted into two-dimensional or three-dimensional data. Such map data may include road data representing at least one of the position coordinates, shape, road surface condition, and standard running path of a road structure. The map data may also include marking data representing the position coordinates and / or shape of features such as road signs and road markings attached to the road. The marking data included in the map data may represent traffic signs, arrow markings, lane markings, stop lines, directional signs, landmark beacons, business signs, line pattern changes, etc. The map data may also include structure data representing at least one of the position coordinates and shapes of buildings and traffic lights facing the road. The marking data included in the map data may represent street lights, road edges, reflectors, poles, etc.

[0059] The motion actuator 60 can control vehicle motion based on an input control signal. The drive-related motion actuator 60 is a power train including at least one of an engine and a drive motor. The braking-related motion actuator 60 may be a brake actuator. The steering-related motion actuator 60 may be a steering actuator.

[0060] The HMI device 70 is a device that realizes human-machine interaction, which is interaction between the user of the vehicle 1 and the driving system 9. The driving system 9 may include multiple HMI devices 70. Of the multiple HMI devices 70, a portion that realizes an operation input function by an occupant may be part of the detection unit 10. Of the multiple HMI devices 70, a portion that realizes an information presentation function may be part of the behavior unit 30. On the other hand, the function realized by the HMI device 70 may be positioned as a function independent of the detection function, the planning function, and the behavior function.

[0061] The HMI device 70 may include an operation input device 70a that can input user operations to transmit the will or intention of the user of the vehicle 1 to the driving system 9. The operation input type HMI device 70 may be an accelerator pedal, brake pedal, shift lever, steering wheel, turn signal lever, mechanical switch, or a touch panel of a navigation unit or the like. Of these, the accelerator pedal controls the powertrain as the motion actuator 60. The brake pedal controls a brake actuator as the motion actuator 60. The steering wheel controls a steering actuator as the motion actuator 60. The operation input device 70a outputs an operation signal, which is a signal corresponding to the operation of the vehicle user, to the processing system 50.

[0062] The HMI device 70 may include an information presentation device 70b that presents visual information, auditory information, tactile information, or the like to the user of the vehicle 1. The HMI device 70 may include a visual type information presentation device 70b, an auditory type information presentation device 70b, a tactile type information presentation device 70b, or a combination thereof. The visual information presentation type HMI device 70 may be, for example, a meter display, a navigation unit, a center information display (CID), a head-up display (HUD), an illumination unit, or the like.

[0063] The auditory information presentation type HMI device 70 may be a speaker, a buzzer, etc. The tactile information presentation type HMI device 70 may be a steering wheel vibration unit, a driver's seat vibration unit, a steering wheel reaction force unit, an accelerator pedal reaction force unit, a brake pedal reaction force unit, an air conditioning unit, etc.

[0064] Furthermore, the HMI device 70 may realize an HMI function linked to a mobile terminal 91 such as a smartphone by mutually communicating with the terminal through the communication system 43. The vehicle user's mobile terminal 91 may be an additional or alternative information presentation device 70b. The driving system 9 may display information of the driving system 9 on the screen of the mobile terminal 91 through the communication system 43. Meanwhile, the HMI device 70 may present information acquired from the mobile terminal 91 to the vehicle user. The mobile terminal 91 may be used as an additional or alternative operation input device 70a.

[0065] Furthermore, the HMI device 70 may include an external HMI device that presents information such as visual information and audio information to other road users in the external environment of the vehicle 1. The external HMI device is, for example, a turn signal lamp (in other words, a direction indicator), a hazard lamp, an external display, a speaker, etc. The external display is a display whose display surface faces outside the vehicle 1. The external display may be provided on the rear window, a side window, or the side of the vehicle body.

[0066] The processing system 50 may be an integrated processing system that integrally executes processing related to the detection function, processing related to the planning function, and processing related to the action function. The integrated processing system 50 may further execute processing related to the HMI device 70. A processing system dedicated to the HMI may be provided separately from the processing system 50. The processing system dedicated to the HMI may be an integrated cockpit system that integrally executes processing related to each HMI device 70. The processing system 50 may be provided by an in-vehicle platform that can be used generally for AVs.

[0067] The processing system 50 may have at least one processing unit corresponding to processing related to the sensing function, at least one processing unit corresponding to processing related to the planning function, and at least one processing unit corresponding to processing related to the behavioral function, separately.

[0068] The processing system 50 has an external communication interface 52, which is a communication interface for communicating with an external device. The external communication interface 52 is connected to at least one component related to processing by the processing system 50 via at least one of, for example, a local area network (LAN), a wire harness, an internal bus, and a wireless communication circuit. The at least one component connected to the external communication interface 52 may be at least one of a variety of components, such as the sensor 40, the motion actuator 60, and the HMI device 70. The external communication interface 52 may include at least one of a circuit for wired communication and a circuit for wireless communication.

[0069] The processing system 50 includes a main unit 51 configured mainly with one or more dedicated computers. The processing system 50 may realize functions such as a detection function, a planning function, and an action function by using the main unit 51. The main unit 51 may also be referred to as an operation control device.

[0070] One of the one or more dedicated computers constituting the main unit 51 may be an integration ECU that integrates the driving functions of the vehicle 1. The main unit 51 may include a determination ECU that determines DDT. The main unit 51 may include a monitoring ECU that monitors the driving of the vehicle 1. The main unit 51 may include an evaluation ECU that evaluates the driving of the vehicle 1. The main unit 51 may include a navigation ECU that navigates the driving route of the vehicle 1.

[0071] The dedicated computer constituting the main unit 51 may be a locator ECU that estimates the position of the vehicle 1. The dedicated computer may be an image processing ECU that processes image data detected by the external environment sensor 41. The dedicated computer may be an actuator ECU that controls the motion actuators 60 of the vehicle 1. The dedicated computer may be an HCU (HMI Control Unit) that comprehensively controls the HMI device 70. The one or more dedicated computers constituting the main unit 51 may include at least one external computer provided in an external center or mobile terminal 91 that can communicate via the communication system 43.

[0072] The dedicated computer constituting the main unit 51 has a memory 51a and a processor 51b. The memory 51a is a storage medium that non-temporarily stores computer programs and data that can be read by the processor 51b. The memory 51a may include at least one type of storage medium, such as a semiconductor memory, a magnetic medium, or an optical medium. The memory 51a may also include a rewritable volatile storage medium such as a random access memory (RAM). The program stored in the memory 51a may be a program for implementing at least some of the functions of the main unit 51 shown as a block in FIG. 3. The processor 51b may include at least one type of core selected from a central processing unit (CPU), a graphics processing unit (GPU), a data flow processor (DFP), and a reduced instruction set computer (RISC)-CPU.

[0073] The dedicated computer constituting the main unit 51 may be a system on a chip (SoC) in which the memory 51a, the processor 51b, and the interface are integrated into a single chip. The dedicated computer may be configured using at least one SoC.

[0074] The dedicated computer constituting the main unit 51 may include a communication interface 51c for communicating with other elements constituting the processing system 50. The communication interface 51c may include a circuit suitable for a communication method with other devices / circuits. The communication interface 51c may be a so-called input / output circuit or input / output port. The communication interface 51c may support any type of wired or wireless communication. Part or all of the external communication interface 52 may be included in the communication interface 51c. The communication interface 51c, the external communication interface 52, or both correspond to the communication circuit for the processor 51b. The risk confirmation unit 53, the recording device 55, and the software management unit 57 described below may also each have a circuit equivalent to the communication interface 51c. Multiple units may be configured to share the communication interface 51c.

[0075] Furthermore, the processing system 50 may include at least one database for executing the DDT. The database may include at least one type of non-transitory tangible storage medium, such as a semiconductor memory, a magnetic medium, or an optical medium, and an interface for the main unit 51 or the like to access the storage medium.

[0076] The database for executing the DDT may be a scenario database (hereinafter referred to as a scenario DB) 59. The database may be a rule database (hereinafter referred to as a rule DB) 58. At least one of the scenario DB 59 and the rule DB 58 may be configured integrally with the main unit 51. At least one of the scenario DB 59 and the rule DB 58 may not be provided in the processing system 50, but may be provided independently in the operation system 9. At least one of the scenario DB 59 and the rule DB 58 may be provided in an external system present in the external environment, and configured to be accessible from the processing system 50 via the communication system 43.

[0077] The scenario DB 59 has a scenario catalog in which multiple scenarios used in driving the vehicle 1 are stored. Each of the multiple scenarios is assigned a unique scenario ID. The multiple scenarios included in the catalog may include a scenario in which the vehicle travels near a vehicle (e.g., a bus) that is stopped on the road and has the potential to depart. The multiple scenarios may also include a scenario in which the vehicle travels next to another road user, a scenario in which the vehicle travels behind another road user, a scenario in which the path of the vehicle intersects with a VRU that is crossing the road, and the like.

[0078] The driving system 9 can apply a situation in which the vehicle 1 is placed to one scenario selected from a plurality of scenarios or a combination of a plurality of scenarios. The scenario DB 59 may store a plurality of scenarios including at least one of a functional scenario, a logical scenario, and a concrete scenario. A functional scenario defines a top-level qualitative scenario structure. A logical scenario is a scenario in which a quantitative parameter range is assigned to a structured functional scenario. A concrete scenario defines a boundary of safety determination that distinguishes between a safe state and an unsafe state.

[0079] The rule DB 58 stores a rule set used for driving the vehicle 1. The rule set may include multiple rules. The rule set may further include a priority structure for the rules, which is set based on the relative importance of the multiple rules. The rule set may be an implementation of guidelines for strategic driving of the vehicle 1.

[0080] The plurality of rules may include rules based on laws, regulations, or a combination thereof. The plurality of rules may include rules based on preferences that are not influenced by laws, regulations, or the like. The plurality of rules may include rules based on exercise behavior based on past experience. The plurality of rules may include rules based on characterization of the exercise environment. The plurality of rules may include rules based on ethical concerns. The plurality of rules may include rules based on basic principles of a safety model (e.g., the five principles of the RSS model). The plurality of rules may include traffic rules. The traffic rules may be rules specified in the Road Traffic Act or may be rules based on national or local customs.

[0081] The rules such as traffic rules stored in the rule DB 58 may be positioned as information provided from the detection unit 10 to the planning unit 20 by the detection function, similar to the map information acquired from the map DB 44 .

[0082] The processing system 50 may also include a recording device 55 that records at least one of sensing information, planning information, and action information. The recording device 55 sequentially records event data related to the driving task of the vehicle 1. The event data is data that records events encountered by the vehicle 1. The event data may include at least one type of information related to the driving task, such as (1) information related to the operation of the motion actuators 60, (2) information related to the route or trajectory traversed or planned by the vehicle 1, (3) information related to the scenario encountered by the vehicle 1, (4) information related to the automation level or delegation of authority of the vehicle 1, and (5) information related to the execution of the DDT fallback or MRM of the vehicle 1.

[0083] The recording device 55 may include one or more large-capacity storage media 55c. The storage media 55c may include at least one type of storage medium selected from the group consisting of semiconductor memory, magnetic media, and optical media. The storage media 55c may be mounted on a board in a form that is not easily detachable or replaceable. The storage medium 55c may be an embedded multi-media card (eMMC) using flash memory, or the like. At least one of the multiple storage media 55c may be detachable and replaceable from the recording device 55. The storage medium 55c may be, for example, an SD card.

[0084] At least one of the recording device 55 and the storage medium 55c may correspond to an EDR (Event Data Recorder) or a DSSAD (Data Storage System for Automated Driving). The recording device 55 may have a function for selecting information to be recorded from the event data. In this case, the recording device 55 may have a recording computer as a dedicated computer.

[0085] The recording computer has a memory 55a and a processor 55b. The memory 55a may include a storage medium that non-temporarily stores computer programs, data, and the like that can be read by the processor 55b. The memory 55a may also include a rewritable volatile storage medium such as RAM. The recording computer may be an SoC in which the memory 55a, processor 55b, and interface are integrated into a single chip. The recording computer may have an SoC as a component.

[0086] The recording device 55 may access the storage medium 55c and perform recording in accordance with a data write command from each part of the driving system 9. The recording device 55 may determine information transmitted over the in-vehicle network, and may access the storage medium 55c and perform recording based on the judgment of the processor 55b provided in the recording device 55.

[0087] Such a recording device 55 may not be provided in the processing system 50 but may be provided independently in the operation system 9. A part or all of the recording device 55 may be provided in an external system present in the external environment and configured to be accessible from the processing system 50 via the communication system 43.

[0088] Furthermore, the processing system 50 may include at least one risk confirmation unit 53. The risk confirmation unit 53 may be one aspect of on-board implementation of RSS (Responsibility Sensitive Safety) as a safety model. The risk confirmation unit 53 may be an on-board checker for the planning function realized by a dedicated computer. The risk confirmation unit 53 realizes the risk confirmation section 26, which realizes the risk confirmation function, by hardware independent of the planning section 20.

[0089] The risk confirmation unit 53 may be mainly composed of a dedicated computer having a memory 53a and a processor 53b. The memory 53a may include a storage medium that non-temporarily stores computer programs and data that can be read by the processor 53b. The memory 53a may include a rewritable volatile storage medium such as RAM. The dedicated computer that constitutes the risk confirmation unit 53 may be an SoC in which the memory 53a, processor 53b, and interface are integrated into a single chip.

[0090] As described above, the processing system 50 includes memories 51a, 53a, and 55a storing software. The processors 51b, 53b, and 55b are configured to operate the software to realize automated driving in a manner that allows transfer of authority between the system itself and a user. The software here may be a computer program used in the driving system 9. The software may include parameters for the computer program used in the driving system 9. The software may include a trained model, sometimes referred to as AI, implemented by, for example, a neural network, etc., used in the driving system 9.

[0091] The processing system 50 may include at least one software management unit 57. The software management unit 57 realizes software management functions. The software management unit 57 manages various software used in the driving system 9, such as the main unit 51. The software management unit 57 may manage software used by the software management unit 57 itself. The software management unit 57 may manage all software used in the vehicle 1. Software management may include software version management, download processing, installation processing, uninstallation processing, update processing, rollback processing, etc. Software management may also include software testing.

[0092] The software management unit 57 may be configured using a dedicated computer having a memory 57a and a processor 57b to realize the software management function. The memory 57a may include a storage medium that non-temporarily stores computer programs and data that can be read by the processor 57b. The memory 57a may also be provided with a rewritable volatile storage medium such as RAM. "SW" in Figure 2 represents software.

[0093] The processors 51b, 53b, etc. execute processing related to the autonomous driving of the vehicle based on signals received via the communication interface 51c or the external communication interface 52. The processing related to the autonomous driving of the vehicle may be at least a part of the processing executed by the detection unit 10, the planning unit 20, the action unit 30, and the risk confirmation unit 26, which will be described in detail next. A configuration including either or both of the processors 51b, 53b corresponds to a processing unit. The processing unit may include a processor and a memory.

[0094] 3 and 4 show an example of a logical architecture in the driving system 9. Here, the description will focus on the processing by a computer program executed during autonomous driving at level 3 or higher. The detection unit 10 may include an environment recognition unit 11, a self-location recognition unit 12, and an internal recognition unit 13 as functional modules corresponding to sub-functions that further classify the detection function. The environment recognition unit 11, the self-location recognition unit 12, and the internal recognition unit 13 may also be realized by the processor 51b executing a computer program.

[0095] The environment recognition unit 11 individually processes information acquired from each sensor 40 (this information may be referred to as sensor data) to recognize the external environment including other road users, etc. The environment recognition unit 11 individually processes sensor data related to the external environment detected by each external environment sensor 41. The sensor data may be sensor data provided by millimeter-wave radar, sonar, LiDAR, etc. The environment recognition unit 11 may generate relative position data including the direction, size, and distance of an object relative to the vehicle 1 from the raw data received from the external environment sensors 41.

[0096] The sensor data may be image data provided by a camera, LiDAR, or the like. The image data may be a video signal. The environment recognition unit 11 processes the image data and extracts objects reflected within the angle of view of the image. The object extraction may include estimating the direction, size, and distance of the object relative to the vehicle 1. The object extraction may also include classifying the object using semantic segmentation.

[0097] Furthermore, the environment recognition unit 11 processes information acquired through the V2X function of the communication system 43. The environment recognition unit 11 processes information acquired from the map DB 44.

[0098] The environment recognition unit 11 may be further divided into a plurality of sensor recognition units each optimized for one sensor group. When a sensor recognition unit is associated with recognizing information from one sensor group, the sensor recognition unit may fuse information from the one sensor group.

[0099] The self-location recognition unit 12 performs localization of the vehicle 1. The self-location recognition unit 12 acquires global position data of the vehicle 1 from the communication system 43 (e.g., a GNSS receiver). In addition, the self-location recognition unit 12 may acquire position information of objects extracted by the environment recognition unit 11. The self-location recognition unit 12 also acquires map information from the map DB 44. The self-location recognition unit 12 may integrate two or more types of information from among the global position data, object position information, map information, and other information to estimate the position of the vehicle 1 on the map. In the present disclosure, information indicating the position of the vehicle 1 on the map estimated by the self-location recognition unit 12 is also referred to as estimated information of the position on the map.

[0100] The internal recognition unit 13 processes sensor data detected by each internal environment sensor 42 to recognize the vehicle state. The vehicle state may include the state of the physical quantities of motion of the vehicle 1 detected by a speed sensor, an acceleration sensor, a gyro sensor, etc. The vehicle state may also include at least one of the user state, the user's operation state of the motion actuator 60, and the switch state of the HMI device 70.

[0101] The planner 20 may include a predictor 21, an operation planner 22, and a mode manager 23 as functional modules corresponding to sub-functions obtained by further classifying the planning function. The predictor 21, the operation planner 22, and the mode manager 23 may also be realized by the processors 51b and 53b executing computer programs.

[0102] The prediction unit 21 acquires information on the external environment recognized by the environment recognition unit 11 and the self-position recognition unit 12, the vehicle state recognized by the internal recognition unit 13, etc. The prediction unit 21 may interpret the environment based on the acquired information and estimate the current situation of the vehicle 1. The situation here may be an operational situation or may include the operational situation.

[0103] The prediction unit 21 may interpret the environment and predict the behavior of objects, such as other road users. The objects may be safety-relevant objects. The behavior prediction may include at least one of predicting the object's speed, acceleration, and trajectory. The behavior prediction may be performed based on reasonably foreseeable assumptions. Information generated by the prediction unit 21 is also referred to as prediction information hereinafter. Furthermore, the prediction unit 21 may estimate a user's intention based on the predicted behavior, predicted potential hazards, and the acquired vehicle state. Information indicating the estimated user's intention is also referred to as user intention information in the present disclosure.

[0104] The driving planner 22 plans autonomous driving of the vehicle 1 based on at least one type of information, such as estimated information on a map position, forecast information, user intention information, and functional constraint information (described later). The driving planner 22 provides a route planning function, a behavior planning function, and a trajectory planning function. The route planning function is a function of planning at least one of a route to a destination and a medium-distance lane plan based on estimated information on a map position and destination information. The route planning function may further include a function of determining at least one of a lane change request and a deceleration request based on the medium-distance lane plan. Here, the route planning function may be a mission / route planning function in strategic functions and may be a function of outputting a mission plan and a route plan. Here, the strategic functions may be functions of deciding whether to operate, setting a route to a destination, and adjusting or selecting a rough operation schedule.

[0105] The behavior planning function is a function that plans the behavior of the vehicle 1 based on at least one of a route to a destination, a mid-distance lane plan, a lane change request, a deceleration request, prediction information, user intention information, and function constraint information. The behavior planning function may include a function that generates conditions related to state transitions of the vehicle 1. The conditions related to state transitions of the vehicle 1 may be triggering conditions. The conditions related to state transitions may include fallback conditions for executing DDT fallbacks.

[0106] The behavior planning function may include a function for determining state transitions of applications that realize DDT based on these conditions, and further a function for determining state transitions of driving actions. As a result, the driving planner 22 plans the execution of DDT fallback. If this does not involve delegation of authority, the driving planner 22, together with the motion control unit 31, may further execute a minimum-risk maneuver (MRM) to transition the vehicle 1 to a minimum-risk state. The minimum-risk state may often be a state in which the vehicle is parked outside the lane (e.g., on the shoulder) or within the lane, but is not limited thereto. The minimum-risk state may also be a state in which the vehicle is following a preceding vehicle or a state in which the vehicle is continuing to travel at a constant speed with its hazard lights on. The MRM plan may be created by a trajectory planning function instead of the behavior planning function. Information indicating the state transitions of applications determined by the driving planner 22 is also referred to as application state transition information.

[0107] The behavior planning function may also include a function for determining, based on the information on these state transitions, longitudinal constraints on the path of the vehicle 1 and lateral constraints on the path of the vehicle 1. The behavior planning function may be a tactical behavior plan in the DDT function, and may output tactical behavior.

[0108] The trajectory planning function is a function that plans a driving trajectory of the vehicle 1 based on prediction information, longitudinal constraints on the path, and lateral constraints on the path. The trajectory planning function may include a function that generates a path plan. The path plan may include a speed plan, or the speed plan may be generated as a plan independent of the path plan. The trajectory planning function may include a function that generates multiple path plans and selects an optimal path plan from the multiple path plans, or a function that switches between path plans. The trajectory planning function may further include a function that generates backup data for the generated path plan. The trajectory planning function may be a trajectory planning function in the DDT function and may output a trajectory plan. In the driving planner 22, the terms "path" and "trajectory" may be interchangeable. The driving planner 22 is configured to output trajectory planning information, which is information indicating the trajectory plan (in other words, the path plan), to the motion control unit 31.

[0109] The mode management unit 23 monitors the driving system 9 and sets restrictions on driving-related functions. The mode management unit 23 may manage the operating mode of the driving system 9, for example, the state of the automation level. The management of the automation level may include management of switching between manual driving and automated driving, i.e., management of the transfer of authority between the user and the driving system 9, in other words, management of the takeover of driving. The mode management unit 23 may determine and implement a change in the automation level based on an operation signal input from the operation input device 70a. When the automation level is switched to a state lower than level 2, the mode management unit 23 may control the enablement state of a driving assistance application corresponding to the automation level.

[0110] The driving system 9 of this embodiment may have operation modes corresponding to automation levels 0 to 4. That is, the driving system 9 is configured to be able to switch between a plurality of operation modes including level 0 mode, level 1 mode, level 2 mode, level 3 mode, and level 4 mode. The operation modes of the driving system 9 may be interpreted as operation modes of the main unit 51 or the processor 51b. The operation modes may be rephrased as driving modes. The driving system 9 may have an operation mode corresponding to automation level 5. The combination of operation modes provided by the driving system 9 may be changed as appropriate.

[0111] Level 0 mode may be referred to as a manual driving mode. Even in level 0 mode, the driving system 9 may execute processes to mitigate collision damage or avoid a collision, such as advanced emergency braking (AEB) or advanced emergency steering (AES). Even in level 0 mode, the driving system 9 may continue to execute a driving environment recognition process in the background so that autonomous driving or driving assistance can be started promptly in response to a request from the driver. Level 0 mode may also be a mode in which the driving system 9 completely stops operating.

[0112] The level 2 mode may be an operating mode that executes control equivalent to the automation level 2.5. The level 2 mode may be subdivided into a hands-on level 2 mode and a hands-off level 2 mode. The hands-on level 2 mode is an operating mode corresponding to the automation level 2.0 and requires hands-on control by the vehicle user. The hands-off level 2 mode is an operating mode corresponding to the automation level 2.5 and allows hands-off control by the vehicle user. In the present disclosure, hands-on means holding the steering wheel. Hands-off means taking your hands off the steering wheel. Eyes-on means monitoring the area outside the vehicle (mainly ahead) related to the direction of movement of the host vehicle. Eyes-off means taking your eyes off the area outside the vehicle related to the direction of movement of the host vehicle.

[0113] The mode management unit 23 may monitor the status of subsystems related to the driving system 9 and determine a system malfunction. The system malfunction may include an error, an unstable operating state, a system failure, a breakdown, etc. The mode management unit 23 may determine a mode that conforms to the user's intention based on user intention information. The mode management unit 23 may set constraints on driving functions based on at least one of the system malfunction determination result, the mode determination result, the vehicle state, a sensor abnormality (or sensor failure) signal output from the sensor 40, application state transition information, and trajectory planning. Information indicating constraints on driving functions is also referred to as function constraint information in the present disclosure. The function constraint information generated by the operation of the mode management unit 23 can be referenced by the driving planner 22.

[0114] Furthermore, the mode management unit 23 may have a comprehensive function of determining, in addition to constraints on driving functions, longitudinal constraints on the path of the vehicle 1 and lateral constraints on the path of the vehicle 1. In this case, the operation planning unit 22 plans behavior and trajectories in accordance with the constraints determined by the mode management unit 23.

[0115] When the risk confirmation function is implemented as part of the planner 20, the risk confirmation function may be implemented as part of the functions realized by the predictor 21, the operation planner 22, and the mode manager 23. On the other hand, the risk confirmation function may be implemented as a function independent of the planner 20 (see also FIG. 4).

[0116] The behavior unit 30 may include a motion control unit 31 and an HMI output unit 71 as functional modules corresponding to sub-functions that further classify the behavior functions. The motion control unit 31 and the HMI output unit 71 may each be realized by the processor 51b executing a computer program. The motion control unit 31 controls the motion of the vehicle 1 based on a trajectory plan provided from the driving plan unit 22. Specifically, the motion control unit 31 generates accelerator request information, shift request information, brake request information, and steering request information according to the trajectory plan, and outputs them to the motion actuator 60. The accelerator request information, shift request information, brake request information, and steering request information may function as control signals (in other words, control commands) for the motion actuator 60. The accelerator request information, shift request information, brake request information, and steering request information may be rephrased as an accelerator request signal, a shift request signal, a brake request signal, and a steering request signal.

[0117] Here, the motion control unit 31 can directly obtain the vehicle state recognized by the detection unit 10 (particularly the internal recognition unit 13), such as at least one of the current speed, acceleration, and yaw rate of the vehicle 1, from the detection unit 10 and reflect this in the motion control of the vehicle 1.

[0118] The HMI output unit 71 outputs information about the HMI based on at least one of prediction information, user intention information, application state transition information, trajectory planning information, and function constraint information. The HMI output unit 71 may manage vehicle interactions. The HMI output unit 71 may generate an information presentation request based on the management status of the vehicle interactions and control the information presentation function of the HMI device 70. Furthermore, the HMI output unit 71 may generate control requests for wipers, a sensor washing device, headlights, and an air conditioning device based on the management status of the vehicle interactions and control these devices.

[0119] <Risk Confirmation> Next, the risk confirmation function will be described in detail. An example in which the risk confirmation unit 26 is implemented independently of the planning unit 20 as shown in FIG. 4 will be described below. Such a risk confirmation unit 26 may be realized by the processor 53b of the risk confirmation unit 53 executing a computer program. Note that the risk confirmation function may also be realized by the processor 51b of the main unit 51 executing a computer program. The functional layout within the operation system 9 may be changed as appropriate.

[0120] The driving system 9 may implement a safety model for automated driving to realize the risk confirmation function. The safety model is a model for demonstrating that there are no unacceptable risks within a specific driving design domain. The safety model may correspond to a safety driving model, a safety-related model, or a formal model. The safety model in this embodiment may be, for example, an RSS model. In other embodiments, the safety model may be another model such as an SFF (Safety Force Field) model or Rulebooks, a more generalized model, or a composite model that combines multiple models.

[0121] The RSS model employs five rules (five principles). The first rule is "Do not hit someone from behind." The second rule is "Do not cut-in recklessly." The third rule is "Right-of-way is given, not taken." The fourth rule is "Be careful of area with limited visibility; you must do it." The fifth rule is "If you can avoid an accident without causing another one, you must do it." These rules may correspond to driving policies.

[0122] A safety envelope may be defined based on the five rules, particularly the first and second rules. For example, the safety envelope may refer to the longitudinal and lateral safety distances themselves relative to other road users, or may refer to conditions or concepts for calculating these safety distances. The safety distance is an example of a geometric approach to risk identification.

[0123] The longitudinal safe distance dmin may be a safe distance from the preceding vehicle FV. As shown in Figure 5, such longitudinal safe distance dmin may be a distance that will not cause a rear-end collision when the preceding vehicle FV brakes at a maximum deceleration βmax while traveling at a speed vf and stops, and the following vehicle RV accelerates with a response time ρ and a maximum acceleration αmax, and then brakes at a minimum deceleration βmin to stop. The maximum acceleration αmax, maximum deceleration βmax, and minimum deceleration βmin may be understood as absolute values.

[0124] Here, the braking distance (Dfbrk) of the preceding vehicle FV is physically expressed by the following equation 1: vf in the equation is the speed of the following vehicle RV at the time when the preceding vehicle FV starts braking (i.e., the initial speed).

[0125] The free running distance (Drrxn) of the vehicle 1 is expressed by the following equation 2.

[0126] The braking distance (Drbrk) of the vehicle 1 is expressed by the following equation 3.

[0127] Such a longitudinal safety distance dmin from the preceding vehicle may be expressed as the distance obtained by adding the braking distance (Drbrk) of vehicle 1 to the free running distance (Drrxn) of vehicle 1 and subtracting the braking distance (Dfbrk) of the preceding vehicle, as shown in the following equation 4a.

[0128] [Equation 4a] dmin=Drrxn+Drbrk-Dfbrk Equation 4a may be expressed as the following Equation 4 by substituting Equations (1a), (2a), and (3a).

[0129] The longitudinal safety distance dmin may also be a safety distance assuming an oncoming vehicle. As shown in Figure 6, such a longitudinal safety distance dmin may be a distance that will prevent a head-on collision even if vehicle 1 and another vehicle 2 are traveling facing each other at speeds v1 and v2, respectively, accelerate with a predetermined reaction time ρ and maximum acceleration αmax, and then brake and stop at a minimum deceleration βmin. In this assumption, the other vehicle 2 corresponds to an oncoming vehicle or a vehicle traveling in the wrong direction from vehicle 1.

[0130] Here, the free running distance (d1rxn) of vehicle 1 is expressed by Equation 5. In the equation, v1 is the initial longitudinal velocity of vehicle 1, and v2 is the initial longitudinal velocity of vehicle 1. Here, v1 and v2 may be interpreted as absolute values ​​(i.e., values ​​greater than or equal to 0).

[0131] The braking distance (d1brk) of vehicle 1 is expressed by the following equation 6.

[0132] The free running distance (d2rxn) of the other vehicle 2 is expressed by the following equation 7.

[0133] The braking distance (d2brk) of the other vehicle 2 is expressed by the following equation 8.

[0134] The safety distance dmin in the assumption shown in Figure 6 may be expressed as the sum of the free running distance of vehicle 1 (d1rxn), the braking distance of vehicle 1 (d1brk), the free running distance of vehicle OV2 (d2rxn), and the braking distance of vehicle OV2 (d2brk), as shown in Equation 9 below.

[0135] [Mathematical Expression 9] dmin = d1rxn + d1brk + d2rxn + d2brk Note that the maximum acceleration of vehicle 1 and the maximum acceleration of other vehicle 2 may be different and may be represented as α1max and α2max, respectively. Furthermore, the minimum deceleration of vehicle 1 and the minimum deceleration of other vehicle 2 may be different and may be represented as β1min and β2min, respectively. The reaction time of vehicle 1 and the reaction time of other vehicle 2 may be different and may be represented as ρ1 and ρ2, respectively. α1max, α2max, β1min, and β2min may all be understood as absolute values.

[0136] Regarding the velocity, v2 may be expressed as a negative value in consideration of the direction of the vector. When v2 is expressed as a negative value, d2rxn and d2brk may be calculated using Equation 10 and Equation 11.

[0137] As shown in Figure 7, the lateral safe distance dmin may be set to a distance that prevents collision by leaving a minimum distance μ even if vehicle 1 and another vehicle 2 are traveling side by side at lateral velocities v1 and v2, respectively, accelerate at a predetermined reaction time ρ and maximum acceleration αmax, and then decelerate laterally at a minimum deceleration βmin.

[0138] Here, the lateral safety distance of the left vehicle 1 may be determined using the same concept as the safety distance described with reference to Fig. 6. The lateral safety distance may be a value obtained by adding the lateral free-running distance (d1rxn) and braking distance (d1brk) of the vehicle 1 and the lateral free-running distance (d2rxn) and braking distance (d2brk) of the other vehicle 2 to the minimum distance μ. That is, the lateral safety distance may be calculated using the following Equation 12.

[0139] [Mathematical Expression 12] dmin = μ + d1rxn + d1brk + d2rxn + d2brk The d1rxn and d1brk for determining the lateral safety distance may be calculated by equations 5 and 6 using the reaction time, initial lateral velocity, maximum lateral acceleration, and minimum lateral velocity of vehicle 1. d2rxn and d2brk may be calculated by equations 7 and 8 (or equations 10 and 11) using the reaction time, initial lateral velocity, maximum lateral acceleration, and minimum lateral velocity of other vehicle 2.

[0140] Specific values ​​of parameters such as maximum acceleration, minimum deceleration, and reaction time may be set to reasonable and predictable values. Maximum acceleration and minimum deceleration may be expressed as absolute values. The speed of the road user (v2) may be a value detected by the external environment sensor 41 or a value received via vehicle-to-vehicle communication (i.e., an actual value). Note that a design value may be used for the speed of a road user assumed to be outside the field of view (FOV) of the external environment sensor 41. Since an actual measured value is applied to the speed information, it may have a positive or negative attribute according to the direction of the speed vector.

[0141] Here, the coordinate system used in the safety model may be a lane-based coordinate system. As shown in Figure 8, this coordinate system processes the movement of the vehicle 1 in the direction along the lane LA by defining the center line of the lane LA, i.e., the lane axis ALA along the curve of the road. On the other hand, a road user-based coordinate system may be used to define the longitudinal and lateral axes of each road user. This coordinate system is based on the center of gravity of the road user and defines the longitudinal and lateral axes, and therefore the ordinate and abscissa, according to the azimuth angle of the road user.

[0142] The risk confirmation unit 26 implemented in the driving system 9 is arranged in parallel with the planning unit 20 and executes calculation processing. Specifically, the risk confirmation unit 26 acquires an environmental model, sensor data, etc. from the detection unit 10, evaluates risk according to this information, and outputs a response according to the risk to the action unit 30. This series of functions or processing may be referred to as risk confirmation or risk monitoring. Risk confirmation or monitoring may be interpreted as safety confirmation or monitoring. Risk monitoring can also be said to be monitoring of driving policies.

[0143] The risk confirmation unit 26 may further classify its functions into functional modules, which may include a situation extraction unit 27, a situation confirmation unit 28, and a response unit 29. The situation extraction unit 27, the situation confirmation unit 28, and the response unit 29 may be realized by the processor 53b executing a computer program stored in the memory 53a.

[0144] The situation extraction unit 27 extracts a situation based on information acquired from the detection unit 10. Data indicating the situation (hereinafter referred to as situation data) may include a list of objects (hereinafter referred to as peripheral objects) present around the vehicle 1. The peripheral objects may include other road users. The peripheral objects may include features such as lane markings, signs, and guardrails. The situation data may include data indicating a potential conflict between the vehicle 1 and the peripheral objects. In this case, the situation data may include the existence probability and attribute uncertainty for the vehicle 1 and the peripheral objects. The attributes may be position, orientation, and speed. The situation extraction unit 27 may extract multiple situations. The situation may be a traffic situation. The situation may be selected from a set of possible situations.

[0145] The situation confirmation unit 28 confirms whether the situation extracted by the situation extraction unit 27 is a safe situation or a dangerous situation. The situation confirmation unit 28 performs confirmation using a safety envelope, confirmation using another methodology, or both. The confirmation here may be called risk confirmation or safety confirmation. In risk confirmation, the safety envelope may be set based on an acceptable collision risk.

[0146] The risk confirmation may include confirmation of an estimated collision risk between the vehicle 1 and a surrounding object. The collision risk may include a collision risk over time or a peak collision risk. The collision risk may be a collision probability. In other words, uncertainty can be taken into account in the risk confirmation.

[0147] When the situation confirmation unit 28 executes risk confirmation, the situation confirmation unit 28 may compare the estimated collision risk value with an acceptable collision risk threshold. The acceptable collision risk threshold may be set in advance based on risk acceptance criteria / criterion. When the estimated collision risk value is below the acceptable collision risk threshold, the situation confirmation unit 28 may determine that the situation to be confirmed is a safe situation. When the estimated collision risk value exceeds the acceptable collision risk threshold, the situation confirmation unit 28 may determine that the situation to be confirmed is a dangerous situation.

[0148] This risk threshold may be, for example, a vertical safety distance or a horizontal safety distance. That is, in a geometric approach, the situation confirmation unit 28 may set a safety envelope with a boundary corresponding to the risk threshold in order to confirm the risk of collision between the vehicle 1 and a surrounding object. Then, if a surrounding vehicle crosses the boundary of the safety envelope and enters the range of the safety envelope, it may be determined that there is a violation of the safety envelope. A violation of the safety envelope may be, for example, a failure to maintain a vertical or horizontal safety distance. If there is a violation of the safety envelope, the situation confirmation unit 28 may determine that the situation to be confirmed is a dangerous situation. If there is no violation of the safety envelope, the situation confirmation unit 28 may determine that the situation to be confirmed is a safe situation.

[0149] The situation confirmation unit 28 may set hypotheses about surrounding objects and confirm risks based on the hypotheses. In this case, multiple hypotheses may be used. The hypotheses may include assumptions about reasonably foreseeable behavior of surrounding objects. The hypotheses may also include predictions derived based on the assumptions. The assumptions may include at least one of kinematic-based assumptions and rule-based assumptions. The assumptions about behavior may include assumed values ​​of one or more physical parameters related to motion, such as acceleration. For example, the assumed values ​​may include the maximum deceleration of a preceding vehicle, the reaction time of the host vehicle, the maximum acceleration of the host vehicle, the minimum deceleration of the host vehicle, the minimum deceleration of an oncoming vehicle, or the lateral acceleration of a pedestrian.

[0150] The assumptions may be derived using a function of time that changes during the identified scenario. Alternatively, the assumptions may not change during the identified scenario. The assumptions may vary depending on the category of road user. For example, the assumptions may change depending on whether the road user is a vulnerable road user or not. VRUs may be referred to as vulnerable road users. The assumptions may be adjusted to account for at least one of various road surface conditions and weather-related environmental conditions that are reasonably expected within the operational design domain. The assumptions may be adjusted to account for at least one of differences in road traffic laws between countries and differences in driving habits between regions.

[0151] Assumptions may affect the acceptable risk level. The acceptable risk level or risk threshold may be preset based on risk acceptance criteria / criterion. The quantitative standard of the risk acceptance criteria may be that the probability of harm occurring is below a threshold. The risk acceptance criteria may be set based on a positive risk balance, which is the primary measure of an ethically acceptable risk level. The risk acceptance criteria may be set by combining a statistical approach, such as traffic accident statistics, with a scenario-based approach.

[0152] The risk tolerance criteria may be determined based on a comparison of the capability or operation of the driving system 9 under reasonably foreseeable scenarios within the ODD with the behavior of a competent and careful driver or an experienced and attentive driver. The risk tolerance criteria may be set based on the capability of the driving system 9 being equal to or greater than the driving capability of a competent and careful driver or an experienced and attentive driver.

[0153] The acceptable risk level or risk threshold may be specified in advance by, for example, at least one of a government agency, a standardization body, and an approval body for the driving system 9. The acceptable risk level or risk threshold may be set in advance by, for example, a developer developing the driving system 9.

[0154] Furthermore, the driving system 9 or the risk confirmation unit 26 may be designed to change the risk threshold depending on the ODD. The driving system 9 or the risk confirmation unit 26 may be designed to change the risk threshold depending on the use case.

[0155] Furthermore, the situation confirmation unit 28 may determine an acceptable risk level by referring to a rule set stored in the rule DB 58. The situation confirmation unit 28 may improve the estimation accuracy by incorporating the rules of the rule set into the algorithm for calculating the risk value.

[0156] 9 shows an example of a method for deriving and defining assumptions. The series of processes from S11 to S15 may be executed by the processor 53b of the risk confirmation unit 53. The series of processes may be executed at predetermined regular time intervals or based on a predetermined trigger. The predetermined trigger may be, for example, the latest situation data being provided from the situation extraction unit 27 to the situation confirmation unit 28.

[0157] First, in S11, the scenario that the vehicle 1 is currently encountering is identified. The scenario may be identified by selecting a scenario from a catalog of scenarios stored in the scenario DB 59, for example. One scenario may be selected. Alternatively, multiple scenarios may be selected. A more complex situation may be expressed by combining multiple scenarios. After processing S11, the process proceeds to S12.

[0158] Steps S12 to S15 are repeated for each scenario. In step S12, relevant scenes and road users as dynamic elements are identified and described at a high level. After step S12, the process proceeds to step S13.

[0159] Steps S13 to S15 are repeated for each road user. In step S13, kinematic properties that govern the movement of the road user are identified based on the scenario identified in step S11. After step S13, the process proceeds to step S14.

[0160] S14-S15 are repeated for each of the identified kinematic properties. In S14, it is evaluated whether the kinematic property is safety relevant. This evaluation may be to check whether the kinematic property has the potential to cause other road users to move towards the vehicle 1. Kinematic properties that have the potential to cause other road users to move towards the vehicle 1 may be considered safety relevant kinematic properties. Kinematic properties that are not safety relevant are excluded from application to the scenario identified in S11. After processing in S14, the process proceeds to S15.

[0161] In S15, assumptions are made regarding the reasonably foreseeable behavior of other road users in the scenarios identified in S11. These assumptions may be defined by setting boundaries of the reasonably foreseeable range of other road user behavior in a particular driving situation. After S15, the process returns to S12, S13, and S14 depending on the remaining processing status of other scenarios, road users, and kinematic characteristics. When processing has been completed for all scenarios, the process ends.

[0162] The assumptions here may be a function of time that change during the identified scenario, or the assumptions may not change during the identified scenario, where a minimum set of assumptions about other road users may be defined.

[0163] The minimum set includes reasonably foreseeable maximum assumed longitudinal velocity other road users could exhibit, reasonably foreseeable maximum assumed lateral velocity other road users could exhibit, reasonably foreseeable maximum assumed longitudinal acceleration other road users preceding the vehicle could exhibit, reasonably foreseeable maximum assumed lateral acceleration other road users could exhibit, reasonably foreseeable maximum assumed longitudinal deceleration other road users preceding the vehicle could exhibit, reasonably foreseeable minimum assumed longitudinal deceleration other road users traveling in the opposite direction to the vehicle or following the vehicle could exhibit, and reasonably foreseeable minimum assumed lateral deceleration other road users could exhibit. deceleration), reasonably foreseeable maximum assumed heading angle, reasonably foreseeable maximum assumed heading angle rate change other road users could exhibit, reasonably foreseeable maximum assumed longitudinal position other road users could exhibitDepending on the scenario, this may include one or more of the following characteristics: reasonably foreseeable maximum assumed lateral position fluctuation other road users could exhibit; and reasonably foreseeable maximum assumed response time other road users could exhibit.

[0164] The response unit 29 derives a proper response based on the confirmation result of the situation confirmation unit 28. The response unit 29 may output the proper response to the action unit 30 only when the situation is determined to be dangerous. The proper response may be a restriction on the control command of the motion actuator 60. The proper response may be a response for returning the vehicle 1 to a safe state. The proper response may be an action related to reducing the safety envelope of the vehicle 1, such as braking, or an action for moving the vehicle 1 away from the safety envelope of other road users, such as steering. The proper response may also include both steering and braking. The proper response may be displaying an image, activating lighting equipment, outputting an alarm sound, transmitting a wireless signal, or the like.

[0165] Here, even if a plurality of unrelated dangerous situations are identified, the actions to be taken by the vehicle 1 need to be consolidated into a single action. Therefore, the response unit 29 may resolve potential conflicts between appropriate responses to a plurality of unrelated dangerous situations and transmit the appropriate response to the behavior unit 30.

[0166] Furthermore, the risk ascertainer 26 may be configured to generate and output event data. The event data may include at least one of situation data, a risk ascertainment result for the situation, and a derived appropriate response. The risk ascertainment result may include at least one of a set safety envelope range and a risk threshold. The risk ascertainment result may include an assumption that is a premise for risk ascertainment. The assumption here may include information indicating whether a scenario transition is included in the assumption. The risk ascertainer 26 may store the event data in the recording device 55. The risk ascertainer 26 may transmit the event data to an external system (e.g., the server 96) using the communication system 43 and store it in an external database.

[0167] The event data including the risk confirmation results may be referenced by the planning unit 20 and used for trajectory planning and behavior planning. The risk confirmation unit 26 may output the risk confirmation results to the planning unit 20, and the planning unit 20 may formulate a trajectory plan and behavior plan based on the risk confirmation results.

[0168] The risk confirmation unit 26 may support an operation in an emergency, which may be a DDT fallback. The risk confirmation unit 26 may execute the DDT fallback if a dangerous situation persists or occurs after outputting an appropriate response, in other words, if the risk is not sufficiently reduced.

[0169] The risk ascertainer 26 may distinguish between an initiator of a dangerous scenario and a responder of a dangerous scenario. The risk ascertainer 26 may distinguish between an action recommended for the initiator and an action recommended for the responder. That is, if the vehicle 1 is the initiator, the risk ascertainer 26 may derive an appropriate response according to the action recommended for the initiator, and if the vehicle 1 is the responder, the risk ascertainer 26 may derive an appropriate response according to the action recommended for the responder.

[0170] 10 , the response of the driving system 9 in a scenario in which the host vehicle travels near a stopped vehicle 3 that has the potential to depart (hereinafter also referred to as a stopped vehicle-related scenario) will be described. The stopped vehicle-related scenario may include, for example, a situation in which a stopped vehicle 3 is present ahead of the host vehicle.

[0171] In the example shown in FIG. 10 , vehicle 1 is traveling on a road with one lane in each direction, and a stopped vehicle 3 is present ahead of vehicle 1 on ego lane EL. Ego lane EL is the lane in which vehicle 1 is traveling. FIG. 10 shows the case in which stopped vehicle 3 is a bus, but stopped vehicle 3 may also be a road user other than a bus. Stopped vehicle 3 may also be a taxi. Stopped vehicle 3 may also be a parked passenger car or truck. Stopped vehicle 3 is partially or entirely blocking ego lane EL. Stopped vehicle 3 may also be stopped with part of its body extending outside ego lane EL (for example, onto the sidewalk 83 or the shoulder of the road).

[0172] Reference numeral 81 in FIG. 10 indicates a road edge. Here, the road edge 81 is the edge of an area where vehicles must travel (i.e., a roadway). The road edge 81 may be interpreted as, for example, the boundary between the roadway and a sidewalk 83. Reference numeral 82 indicates a center line. The center line 82 may be a marking type that allows vehicles to extend into the oncoming lane OL, such as a dashed line. The center line 82 may be interpreted as a type of lane marking.

[0173] In this scenario, vehicle 1 needs to use (in other words, pass through) the oncoming lane OL to get in front of the stopped vehicle 3 or wait behind the stopped vehicle 3 for the stopped vehicle 3 to depart. Using the oncoming lane OL does not necessarily mean that the entire body of vehicle 1 passes on the oncoming lane OL, but may also mean that only part of the body passes on the oncoming lane OL. Using the oncoming lane OL may also include traveling with part of the body extending into the oncoming lane OL and part of the body remaining in the ego lane EL. The dashed arrow in the figure shows an example of a trajectory of vehicle 1 traveling while avoiding the stopped vehicle 3.

[0174] In this way, the stopped vehicle-related scenario may include an avoidance scenario in which vehicle 1 avoids a stopped vehicle (e.g., a bus) by using an oncoming lane OL. Furthermore, the avoidance scenario may include a scenario in which vehicle 1 passes beside stopped vehicle 3. Furthermore, the stopped vehicle-related scenario may include a waiting scenario in which vehicle 1 waits behind stopped vehicle 3 for the stopped vehicle 3 to depart. Note that the scenario may transition from a waiting scenario to an avoidance scenario or from an avoidance scenario to a waiting scenario depending on the situation.

[0175] For convenience, the lane in which the stopped vehicle 3 exists (i.e., the ego lane EL) is also referred to as the original lane BL. The original lane corresponds to a lane that is partially or completely blocked by the stopped vehicle 3. A lane in which the vehicle 1 temporarily travels during avoidance control is also referred to as a temporary traffic lane TL. In the example shown in FIG. 10 , the temporary traffic lane TL is the oncoming lane OL. The temporary traffic lane TL and the oncoming lane OL correspond to adjacent lanes. In the present disclosure, travel control that goes around in front of the stopped vehicle 3 through an adjacent lane is also referred to as avoidance control. Avoidance control may also be referred to as overtaking control or slip-through control.

[0176] Here, an example of the processing of the driving system 9 for dealing with a stopped vehicle 3 will be described using the flowchart of FIG. 11 . This series of processing from S101 to S110 may be realized, for example, by the processor 51b of the main unit 51 executing a computer program stored in the memory 51a, and simultaneously, the processor 53b of the risk confirmation unit 53 executing a computer program stored in the memory 53a. A part or all of the processing may be realized by the processor 51b of the main unit 51 executing a computer program stored in the memory 53a. The following description of the driving system 9 as the executing entity of the processing may be replaced with the processor 51b or 53b. Furthermore, depending on the context, the description of the driving system 9 may be replaced with the detection unit 10, the planning unit 20, the risk confirmation unit 26, or the action unit 30.

[0177] S101 is a step in which the driving system 9 updates the environmental model based on data received from the external environment sensor 41 via the communication interface 51c. S101 corresponds to a step in which information indicating the external environment, internal environment, vehicle state, and further the state of the driving system 9 of the vehicle 1 is updated. S101 may be performed by the detection unit 10. S101 may be performed periodically, or may be performed in response to receiving sensor data. In response to the execution of S101, the driving system 9 executes S102. Note that the processing from S102 onwards may be performed when the autonomous driving function is enabled.

[0178] S102 is a step in which the driving system 9 identifies a scenario based on the latest environmental model. The scenario may be identified based on a signal received by the communication interface 51c. If the scenario is identified and it is determined that the current situation corresponds to the identified scenario (YES in S103), S104 is executed. The identified scenario here may be a stopped vehicle-related scenario. If it is determined that the current situation does not correspond to the identified scenario (NO in S103), this flow ends, and another process according to the scenario may be executed.

[0179] S104 is a step in which the driving system 9 acquires the type of the stopped vehicle 3. The type of the stopped vehicle 3 may be identified based on sensor data provided by the external environment sensor 41. When S104 is completed, the process proceeds to S105. Note that the driving system 9 may be configured to execute the processes from S104 onwards based on the detection of a stopped vehicle 3 ahead on the ego lane.

[0180] S105 is a step in which the driving system 9 determines whether the stopped vehicle 3 is a school bus. Whether the stopped vehicle 3 is a school bus may be identified based on the color, shape, or text posted on the body of the stopped vehicle 3. If the stopped vehicle 3 is a school bus (YES in S105), the process proceeds to S111. On the other hand, if the stopped vehicle 3 is not a school bus (NO in S105), the process proceeds to S106. Note that S105 may be a step in which it is determined whether the stopped vehicle 3 is a school bus and whether the school bus is displaying a STOP sign or flashing red lights. S105 may be executed only when the vehicle 1 is traveling in a specific area (mainly the United States). If the vehicle 1 is not traveling in a specific area, S105 may be omitted. S105 is an optional element.

[0181] S106 is a step in which the driving system 9 generates an avoidance trajectory. The avoidance trajectory is a trajectory for traveling while avoiding the stopped vehicle 3. The avoidance trajectory may be generated so that there is a safe gap between the vehicle 1 and the stopped vehicle 3. The safe gap may be, for example, 1.0 m. The avoidance trajectory may be created or modified based on the expected results of the behavior of other road users, which will be described later.

[0182] S107 is a step of assuming the behavior of each road user detected by the external environment sensor 41. The road users detected by the external environment sensor 41 may include the stopped vehicle 3. FIG. 10 illustrates an example in which only the stopped vehicle 3 exists around the vehicle 1, but in reality, other road users may also exist around the vehicle 1. If road users other than the stopped vehicle 3 are detected, the driving system 9 may also assume the behavior of the road users other than the stopped vehicle 3. If a pedestrian on the sidewalk 83 is detected, the behavior of the detected pedestrian may be assumed. Furthermore, the presence of other road users hidden by the stopped vehicle 3 may be assumed. The driving system 9 may assume the behavior of other virtual road users hidden by the stopped vehicle 3. The other road users hidden by the stopped vehicle 3 may be oncoming vehicles, pedestrians, etc.

[0183] Although FIG. 11 illustrates an example in which S107 is executed after S106, S107 may be executed before S106. S107 may be executed in conjunction with the scenario identification in S102. S107 may be a step of performing S13 to S15 for each detected or expected other road user. S107 may also be a step of calculating a safety envelope for each detected or expected other road user. S107 may also include calculating a range of potential behaviors for each detected or expected other road user. The potential range of potential behaviors of each other road user is, for example, a range that the other road user can reach within a predetermined time, and may be calculated from the current speed, direction, and reasonably foreseeable maximum acceleration. A design value according to the type of road user may be applied to the reasonably foreseeable maximum acceleration.

[0184] S108 is a step of confirming the risk when the avoidance control is executed. As described above, the risk confirmation may be to verify whether a violation of the safety envelope may occur. Furthermore, the risk confirmation may include determining whether there is a possibility that the distance between the oncoming vehicle and the host vehicle will be less than a predetermined value while the avoidance control is being executed. Specifically, the risk confirmation related to the avoidance control may include determining whether an oncoming vehicle is present in a road section within a predetermined distance from the stopped vehicle 3.

[0185] Furthermore, checking the risk related to the avoidance control may include determining whether or not there is an oncoming vehicle that can reach the side of the stopped vehicle 3 within the avoidance time. The avoidance time here is the time required for the host vehicle to perform the avoidance control. The avoidance time may be calculated assuming a worst-case scenario. In other words, the avoidance time may be the time it takes for the vehicle 1 stopped behind the stopped vehicle 3 to start moving at a predetermined acceleration, pass the side of the stopped vehicle 3, and arrive in front of the stopped vehicle 3. The avoidance time may be dynamically set depending on the size or type of the stopped vehicle 3, or may be a fixed value such as 5 seconds.

[0186] If the external environment sensor 41 has a sufficient view of the oncoming lane and no other vehicle 2 is detected in the oncoming lane, the avoidance time may be calculated using the current traveling speed as the initial speed. The driving system 9 may be configured to be able to select a plan for passing beside the stopped vehicle 3 without stopping behind the stopped vehicle 3 as the avoidance control plan.

[0187] In response to the result of S108, the driving system 9 determines in S109 whether avoidance control is executable. A case where avoidance control is executable may be a case where no unacceptable risk has been detected. A case where avoidance control is executable may be a case where no violation of the safety envelope is foreseen. A case where avoidance control is executable may be a case where it has been confirmed that there is no oncoming vehicle that can reach the side of the stopped vehicle 3 within the avoidance time. If a risk of collision or excessive closeness with an oncoming vehicle is detected during avoidance control, it may be determined that avoidance control is not executable. Determining that avoidance control is not executable corresponds to deciding not to execute avoidance control.

[0188] S109 corresponds to a step of determining whether or not the conditions for executing avoidance control are met. The conditions for executing avoidance control include, as described above, the traffic conditions in the oncoming lane, such as the size of the free space. Note that, if a lit traffic light indicating a stop is detected ahead of the stopped vehicle 3, the driving system 9 may be configured to determine that avoidance control is not executable. If a stop line or a pedestrian crossing is detected ahead of the stopped vehicle 3, the driving system 9 may be configured to determine that avoidance control is not executable. If an emergency vehicle is detected near the vehicle 1, the driving system 9 may also be configured to determine that avoidance control is not executable. These provisions can reduce the risk of unnecessary avoidance control being implemented. The presence of an emergency vehicle may be detected based on wireless communication or sound information, in addition to image information received from a camera.

[0189] Furthermore, if the stopped vehicle 3 is stopped near the center of the lane, that is, if the stopped vehicle 3 is not near the shoulder, it may be temporarily stopped due to simple traffic congestion, a traffic signal, a pedestrian crossing the road, or other reasons. In light of this, the driving system 9 may be configured to determine whether or not to perform avoidance control on the condition that the stopped vehicle 3 is stopped closer to the road edge 81 than the center of the lane. The driving system 9 may be configured to determine that avoidance control is not executable when the stopped vehicle 3 is stopped near the center of the lane. Alternatively, the determination whether or not to perform avoidance control may be based on whether or not the vehicle is near a bus stop. A determination algorithm may be configured such that, if the driving system 9 recognizes, based on the sensor data of the external environment sensor 41 or map data, that the stopped vehicle 3 is a bus and that a bus stop is located near the stopped vehicle 3 (for example, within 5 meters), it performs avoidance control more proactively than when a bus stop is not detected.

[0190] The determination of whether or not to execute avoidance control, in other words, the confirmation of risk, may be made based on the results of predicting the behavior of the stopped vehicle 3. The driving system 9 may be configured to predict the departure of the stopped vehicle 3 by monitoring the lighting status of the lighting equipment of the stopped vehicle 3. The lighting equipment used for the behavior prediction may be at least one of brake lights, hazard lights, and turn signals. The driving system 9 may predict that the stopped vehicle 3 will soon start moving based on the extinguishing of the brake lights, the start of operation of the turn signals, and the extinguishing of the hazard lights.

[0191] When the driving system 9 detects a pre-start action by the stopped vehicle 3, it may predict that the stopped vehicle 3 will soon start moving. The pre-start action is a signal indicating that the stopped vehicle 3 will soon start moving. The pre-start action may include turning off the brake lights, activating the turn signals, or displaying a predetermined image. The pre-start action may also be turning off the hazard lights, closing the doors, starting the engine, or the like. The driving system 9 may predict that the stopped vehicle 3 will not soon start moving based on the state of the stopped vehicle 3, such as whether the doors are open.

[0192] Furthermore, the driving system 9 may predict the behavior of the stopped vehicle 3 based on data received through vehicle-to-vehicle communication with the stopped vehicle 3. Predicting the behavior of the stopped vehicle 3 may involve estimating whether the stopped vehicle 3 will start moving soon, whether the stopped vehicle 3 will remain stopped for a while, or how many seconds it will take for the stopped vehicle 3 to start moving. For example, when the driving system 9 receives a vehicle status message from the stopped vehicle 3, it may predict the behavior of the stopped vehicle 3 using the vehicle status message. When it is predicted that the stopped vehicle 3 will start moving, the driving system 9 may determine that avoidance control cannot be executed. The driving system 9 may determine that avoidance control is executable based on the prediction that the stopped vehicle 3 will not start moving soon.

[0193] Whether or not avoidance control can be executed may be determined by the risk confirmation unit 26. If it is determined that avoidance control can be executed (YES in S109), the driving system 9 starts avoidance control in S110. That is, the driving system 9 starts driving the vehicle 1 toward the oncoming lane according to a pre-set avoidance trajectory.

[0194] On the other hand, if it is determined that avoidance control is not executable (NO in S109), the risk confirmation unit 26 outputs, as an appropriate response, a signal to prohibit avoidance control or to instruct a stop to the planning unit 20. If it is determined that avoidance control is not executable, the driving system 9 may be configured to plan and execute standby control in S111.

[0195] The waiting control may be to stop the vehicle 1 behind the stopped vehicle 3. The stopping position of the vehicle 1 relative to the stopped vehicle 3 in the longitudinal direction may be a predetermined position, such as 5 m behind the stopped vehicle 3. The stopping position in the lateral direction may be along the center line so that the FOV of the external environment sensor 41 relative to the oncoming lane is wide. Of course, the stopping position in the lateral direction may be the center of the ego lane or directly behind the stopped vehicle 3.

[0196] The driving system 9 may create an avoidance trajectory to avoid the potential movement range of the stopped vehicle 3. The potential movement range of the stopped vehicle 3 may be set based on a predetermined maximum acceleration, with the current speed set to 0. Taking into account the possibility that the stopped vehicle 3 may suddenly roll back, the potential movement range of the stopped vehicle 3 may be set in front of and behind the stopped vehicle 3. The driving plan unit 22 of the driving system 9 may directly or indirectly obtain the risk confirmation result from the risk confirmation unit 26, and create a driving plan for the vehicle 1 with respect to the stopped vehicle 3 so as to reduce the risk.

[0197] The driving system 9 may also generate a trajectory and speed plan near the front end of the stopped vehicle 3, taking into account the possibility that a VRU (e.g., a pedestrian) may be hidden in front of the stopped vehicle 3. The driving system 9 may generate a driving trajectory and a speed plan (and therefore a driving plan) assuming the presence of a pedestrian hidden by the stopped vehicle 3. The final speed may be set to a value smaller than the starting speed. Here, the final speed is the speed when crossing the front end of the stopped vehicle 3. The starting speed is the speed when crossing the rear end of the stopped vehicle 3. For example, the final speed may be set to a predetermined value (e.g., 30 km / h) or less.

[0198] The driving system 9 may periodically perform the determination of S109 even while the vehicle is stopped and waiting. The driving system 9 may start the avoidance control even after the vehicle has stopped behind the stopped vehicle 3 based on the determination that the avoidance control can be performed.

[0199] The driving system 9 may decide to start the avoidance control based on the confirmation that there are no other road users in a specific area on the oncoming lane OL. If the driving system 9 detects the presence of another road user on the oncoming lane OL after starting the avoidance control, the driving system 9 may decide whether to stop the avoidance control depending on the type or speed of the other road user.

[0200] The specific area on the oncoming lane OL may be a predetermined range including the sides of the stopped vehicle 3. The specific area may be a section on the oncoming lane OL within 50 meters ahead of the rear end of the stopped vehicle 3. The length of the specific area may be determined based on the avoidance time. The length of the specific area may be determined based on a value obtained by multiplying the avoidance time by an estimated traveling speed of a virtual oncoming vehicle. The estimated traveling speed of the virtual oncoming vehicle may be a value obtained by adding a predetermined margin (e.g., 20 km / h) to the speed limit. The state in which it has been confirmed that there are no other road users in the specific area may be a state in which the specific area is included in the FOV of the external environment sensor 41 and the specific area is determined to be an empty space based on the detection result. If a part of the specific area is outside the FOV of the external environment sensor 41 or if other road users are detected in the specific area, the driving system 9 may determine that it has not been confirmed that there are no other road users in the specific area.

[0201] In one embodiment, if the stopped vehicle 3 is a school bus, the driving system 9 operates to wait for the school bus to depart. This can increase the safety of children getting on and off the school bus. Furthermore, the driving system 9 starts evasive action in consideration of the risks involved in taking evasive action. If the driving system 9 detects an unacceptable risk in relation to the evasive control, it performs standby control rather than evasive control. This can reduce the risk involved in avoiding the stopped vehicle 3. Furthermore, if the driving system 9 does not detect an unacceptable risk in relation to the evasive control, it performs evasive control. This can increase convenience for the vehicle user.

[0202] The driving system 9 may determine a response to the stopped vehicle 3 taking into consideration the type of the stopped vehicle 3, not limited to a school bus. The response to the stopped vehicle 3 may be whether to perform avoidance control or to wait. If the stopped vehicle 3 is an emergency vehicle, the driving system 9 may be configured to first perform wait control and then attempt avoidance control or to perform a takeover request. The type of the stopped vehicle 3, for example, whether the stopped vehicle 3 is an emergency vehicle, may be determined based on the appearance of the stopped vehicle 3 captured by a camera. By determining a response taking into consideration the type of the stopped vehicle 3, it becomes possible to achieve autonomous driving in a wider variety of situations. As a result, the convenience of autonomous driving can be improved.

[0203] In one embodiment, the driving system 9 determines whether to start avoidance control based on the prediction result of the behavior of the stopped vehicle 3. That is, the driving system 9 determines not to start avoidance control if the departure of the stopped vehicle 3 is predicted. Moreover, the driving system 9 determines to start avoidance control based on the fact that the stopped vehicle 3 is still stopped and the departure of the stopped vehicle 3 is not predicted. With this configuration that determines the start of avoidance control based on the prediction result, it is possible to reduce the possibility that avoidance control will be suspended due to a conflict between the avoidance control and the departure of the stopped vehicle 3.

[0204] Furthermore, the driving system 9 may determine the execution conditions for the avoidance control based on the amount of protrusion of the host vehicle into the oncoming lane OL when the avoidance control is performed. The smaller the amount of protrusion, the more relaxed the execution conditions for the avoidance control may be.

[0205] <Operation after start of avoidance control> Avoidance control can mainly include the phases shown in Figures 12, 13, and 14. The initial phase shown in Figure 12 is a state in which a change in lateral position (i.e., steering) has started for avoidance, but the body of vehicle 1 has not yet protruded into the oncoming lane OL.

[0206] The mid-phase shown in FIG. 12 is a state in which part or all of the body of the vehicle 1 is in the oncoming lane OL, and the rear end of the vehicle 1 is still located behind the front end of the stopped vehicle 3. The mid-phase mainly corresponds to a phase in which the vehicle 1 is traveling to the side of the stopped vehicle 3. Note that the mid-phase may be divided into two or more phases depending on the position of the vehicle 1 relative to the stopped vehicle 3. For example, the mid-phase may be divided into a first mid-phase and a second mid-phase. The first mid-phase may be a state in which the front end of the vehicle 1 is located behind the center of the stopped vehicle 3 in the longitudinal direction. The second mid-phase may be a state in which the front end of the vehicle 1 is located ahead of the center of the stopped vehicle 3 in the longitudinal direction. Here, "ahead" corresponds to the traveling direction set in the ego lane EL.

[0207] The late phase shown in FIG. 14 is a state in which the rear end of vehicle 1 is located ahead of stopped vehicle 3. The late phase may be divided into two or more parts depending on the position of vehicle 1 relative to center line 82. For example, the late phase may be divided into a first late phase and a second late phase. The first late phase may be a state in which part or all of vehicle 1 is still in the oncoming lane OL. The second late phase may be a state in which vehicle 1 has completely returned to the original lane BL. The second late phase corresponds to a phase in which avoidance control is almost complete.

[0208] <Example of operation during avoidance control> The driving system 9 may monitor the behavior of the stopped vehicle 3 even while executing avoidance control, and may discontinue the avoidance control depending on the situation. For example, if the departure of the stopped vehicle 3 is detected or predicted in the initial phase, the driving system 9 may decide to discontinue the avoidance control and return to the ego lane EL.

[0209] 15 is a flowchart showing an example of the operation of the driving system 9 during avoidance control, and includes S201 to S205. The first step, S201, is a step in which the driving system 9 monitors the behavior of the stopped vehicle 3. Monitoring the behavior of the stopped vehicle 3 may involve analyzing sensor data related to the stopped vehicle 3 and determining whether the stopped vehicle 3 has started to move. The sensor data related to the stopped vehicle 3 may be data of the stopped vehicle 3 detected by the external environment sensor 41, or may be data received from the stopped vehicle 3 via vehicle-to-vehicle communication. The sensor data related to the stopped vehicle 3 corresponds to the monitoring result.

[0210] Monitoring the behavior of the stopped vehicle 3 may include determining (or predicting) whether the stopped vehicle 3 is about to move away. S201 may be executed periodically while the avoidance control is being executed. S201 may be executed in response to receiving sensor data related to the stopped vehicle 3. After S201, the driving system 9 executes S202.

[0211] S202 is a step of determining whether the stopped vehicle 3 has started moving based on the result of S201. If it is detected that the stopped vehicle 3 has started moving (YES in S202), the driving system 9 performs the determination in S204. On the other hand, if it is detected that the stopped vehicle 3 is still stopped (NO in S202), the driving system 9 executes S203. Note that S202 may include determining whether the stopped vehicle 3 is likely to start moving soon. If it is predicted that the stopped vehicle 3 is likely to start moving soon, the driving system 9 may execute S204. The driving system 9 may be configured to execute S203 if the stopped vehicle 3 is still stopped and is not predicted to start moving soon.

[0212] In step S203, the risk confirmation unit 26 determines whether to continue the avoidance control. In step S203, the risk confirmation unit 26 does not output an appropriate response due to the behavior of the stopped vehicle 3.

[0213] In S204, the driving system 9 determines whether the vehicle 1 is still in a phase in which it can discontinue avoidance control with respect to the stopped vehicle 3. The phase in which it can discontinue avoidance control is a phase in which it can return to behind the stopped vehicle 3 within the ego lane EL. For example, the phase in which it can discontinue avoidance control may be the initial phase. The phase in which it can discontinue avoidance control may include a state in which the vehicle 1 is behind the stopped vehicle 3 and the vehicle body has not yet protruded into the oncoming lane OL. The phase in which it can discontinue avoidance control may also be a state in which the vehicle 1 is behind the stopped vehicle 3 and the amount of protrusion of the vehicle body into the oncoming lane OL is equal to or less than the reversible threshold. The reversible threshold may be a fixed value such as 0.5 m, or a variable determined according to the longitudinal distance between the stopped vehicle 3 and the vehicle 1. The greater the longitudinal distance between the stopped vehicle 3 and the vehicle 1, the greater the reversible threshold may be set to.

[0214] Whether or not the avoidance control can be stopped may be determined using a safety distance. The safety distance here may be a longitudinal safety distance calculated by regarding the stopped vehicle 3 as a preceding vehicle. In S204, since the system has already perceived the departure of the stopped vehicle 3, the reaction time ρ may be set to 0 seconds and determined using Equation 3. If the vehicle 1 is still at a distance equal to or greater than the safety distance from the rear vehicle, the driving system 9 may determine that the avoidance control can be stopped regardless of the lateral position of the vehicle 1 (whether or not it has crossed the center line 82). In this way, the position at which the avoidance control can be stopped may be determined based on the current speed of the vehicle 1.

[0215] The safety distance used to determine whether to discontinue avoidance control may be calculated using a deceleration greater than the minimum deceleration by a predetermined amount, rather than the minimum deceleration. For example, the deceleration (β) used to calculate the safety distance may be 2.5 m / sec^2 or 3.0 m / sec^2. In other embodiments, the safety distance may be a constant value that does not depend on the speed. The driving system 9 may simply determine that avoidance control can be discontinued when the vehicle is a predetermined distance or more behind the stopped vehicle 3. A case in which avoidance control cannot (or is difficult to) be discontinued may be a case in which the conditions for discontinuance are not met.

[0216] If the driving system 9 determines that the avoidance control is in a phase where it can be stopped (YES in S204), it decides to stop the avoidance control. In this case, the driving system 9 creates and executes a driving plan, such as steering, to return the vehicle 1 behind the stopped vehicle 3.

[0217] On the other hand, if the driving system 9 determines that the avoidance control is not in a phase where it can be stopped (NO in S204), it decides to continue the avoidance control. That is, if stopping the avoidance control would actually compromise safety, it controls the vehicle 1 to complete the avoidance control. However, if another risk is detected during the avoidance control, the driving system 9 may implement an appropriate response determined depending on the situation. Furthermore, the avoidance control may ultimately be interrupted based on the result of risk confirmation while the avoidance control is being executed.

[0218] In this way, by determining the continuity of avoidance control in consideration of the safety distance, etc., it is possible to reduce the probability of contact / near crash with the stopped vehicle 3. Here, a near crash refers to a state immediately before a collision, and may be rephrased as excessive proximity.

[0219] The driving system 9 may be configured to discontinue the avoidance control if the vehicle 1 as the host vehicle is located behind the stopped vehicle 3 at the time when the departure of the stopped vehicle 3 is detected, and to determine to continue the avoidance control in other cases. The other cases may be when the host vehicle is located to the side of the stopped vehicle 3 or ahead of the stopped vehicle 3. In other words, the driving system 9 may be configured to complete the avoidance control without discontinuing it when the driving system 9 detects the departure of the stopped vehicle 3 in a situation where the avoidance control has progressed to the middle phase or the late phase. The driving system 9 may also determine to discontinue the avoidance control if the timing at which the departure of the stopped vehicle 3 is detected is up to the first middle phase. The driving system 9 may also determine to complete the avoidance control from the second middle phase onwards. The above corresponds to an example of determining whether to continue the avoidance control based on the position of the vehicle 1 relative to the stopped vehicle 3 when the departure of the stopped vehicle 3 is detected (or predicted).

[0220] When the driving system 9 detects behavior related to the departure of the stopped vehicle 3 while the avoidance control is being executed, the driving system 9 may increase the traveling speed compared to when the behavior related to the departure of the stopped vehicle 3 is not detected. The behavior related to the departure of the stopped vehicle 3 may be behavior that can be used to determine whether or not the stopped vehicle 3 is about to start, such as the brake lights being turned off or the turn signals being activated. The behavior related to the departure of the stopped vehicle 3 may also be a change in the position of the stopped vehicle 3 (i.e., starting).

[0221] Whether or not to accelerate the vehicle 1 in response to the departure of the stopped vehicle 3 may be determined according to the progress level of the avoidance control at the time when behavior related to the departure of the stopped vehicle 3 is detected (hereinafter, the start perception time). The progress level of the avoidance control may be classified according to the position of the host vehicle relative to the stopped vehicle 3 and the traveling speed of the host vehicle, as described above. For example, if the avoidance control is in a phase where it is possible to cancel the avoidance control at the start perception time, it may be determined to decelerate the vehicle 1 without increasing the speed. Furthermore, if the avoidance control is in a phase where it is difficult to cancel the avoidance control at the start perception time, it may be determined to increase the traveling speed by a predetermined amount. For example, the driving system 9 may determine to increase the traveling speed by a predetermined amount if the vehicle 1 is traveling beside the stopped vehicle 3 at the start perception time.

[0222] The driving system 9 may be configured to determine whether to continue the avoidance control by comparing the speed of the vehicle 1 when the departure of the stopped vehicle 3 is detected or predicted with a threshold value.

[0223] 16 is a flowchart for explaining the operation of the driving system 9 corresponding to this technical idea, and includes S211 to S215. S211 to S213 may be the same as S201 to S203.

[0224] S214 is an alternative / additional process to S204. In S214, the driving system 9 determines whether the current speed (Ve) of the vehicle 1 exceeds a predetermined continuation threshold (ThV). Ve in the figure represents the speed of the vehicle 1 when it detects the departure of the stopped vehicle 3. ThV in the figure represents the continuation threshold. The continuation threshold is a speed-related threshold used to determine whether to continue or discontinue the avoidance control. The continuation threshold may be a design value such as 40 km / h. The continuation threshold may be set to a value at which it is expected that the avoidance control can be safely discontinued. If the speed of the vehicle 1 exceeds the continuation threshold (YES in S214), the driving system 9 may decide to continue the avoidance control. If the speed of the vehicle 1 is equal to or less than the continuation threshold (NO in S214), the driving system 9 may decide to discontinue the avoidance control. If it is determined to discontinue the avoidance control, the driving system 9 creates and executes a plan to return to the rear of the stopped vehicle 3 on the ego lane EL.

[0225] In the above configuration, if the speed is such that avoidance control can be safely discontinued, avoidance control is discontinued in response to the departure of the stopped vehicle 3. On the other hand, if the speed of the vehicle 1 at the time of detection of the departure is such that avoidance control may not be safely discontinued, avoidance control is continued. This reduces the risk of sudden braking being performed to discontinue avoidance control. Of course, the driving system 9 may determine whether to continue or discontinue avoidance control by combining the position and speed of the vehicle 1 at the time of detection of the departure. The driving system 9 may also determine whether to continue or discontinue avoidance control by combining other information, such as the automation level at the time of detection of the departure.

[0226] The above-described avoidance control may also be performed when the automation level is 2 (effectively 2.5). The driving system 9 may change the conditions for suspending avoidance control depending on the automation level. When the driving system 9 detects the departure of a stopped vehicle 3 while executing avoidance control in a mode with an automation level of 2, the driving system 9 may decide to continue the avoidance control as is. On the other hand, when the driving system 9 detects the departure of a stopped vehicle 3 while executing avoidance control in a mode with an automation level of 3 or higher, the driving system may suspend the avoidance control and return behind the stopped vehicle 3.

[0227] FIG. 17 is a flowchart illustrating the operation of the driving system 9 according to this technical concept, and includes steps S221 to S225. Steps S221 to S223 may be the same as steps S201 to S203. Step S224 may be an alternative or additional process to step S204. In step S224, the driving system 9 determines whether the current automation level (AD_LV) of the vehicle 1 is 3 or higher. If the automation level is 3 or higher (YES in step S224), the driving system 9 determines to discontinue avoidance control in step S225, and creates and executes a plan to return to the rear of the stopped vehicle 3 (i.e., the ego lane EL). On the other hand, if the automation level is lower than 3, the driving system 9 determines to continue avoidance control in step S223. If the automation level is lower than 3, the vehicle user is monitoring the surroundings, and therefore, driving operations that reduce risk may be performed at the vehicle user's discretion. If the automation level is lower than 3, the decision to continue avoidance control is left to the vehicle user, thereby guiding the vehicle 1 to a more appropriate behavior.

[0228] When the driving system 9 determines to continue avoidance control because the automation level is less than 3, it may issue a notification to the vehicle user related to the departure of the stopped vehicle 3. The notification related to the departure of the stopped vehicle 3 may be a process of notifying the vehicle user that the stopped vehicle 3 has started by outputting a voice message or displaying an image. The notification related to the departure of the stopped vehicle 3 may also be a process of requesting the vehicle user to check for safety by outputting a voice message or displaying an image. The notification related to the departure of the stopped vehicle 3 may also be a process of suggesting that the vehicle user return to the ego lane EL (in other words, the original lane BL). When the driving system 9 detects the departure of the stopped vehicle 3 while executing avoidance control at level 2, the driving system 9 issues the above notification, which may increase the attention of the vehicle user and improve safety.

[0229] The driving system 9 may continue to monitor the behavior of the vehicle 3 even after deciding to discontinue the avoidance control in S205 or the like (S231 in FIG. 18 ). Then, if the vehicle 3 stops again within a predetermined time from starting (or within a predetermined distance from the starting point) (YES in S232), the driving system 9 may retry the avoidance control (S234). For example, if the driving system 9 detects that the vehicle 3 has stopped again before the vehicle 1 has completely returned to the ego lane EL, the driving system 9 may resume the avoidance control from that point. In other words, the driving system 9 may resume the control to steer the vehicle 3 toward the oncoming lane OL. Furthermore, if the driving system 9 detects that the vehicle 3 has stopped again after the vehicle 1 has completely returned to the ego lane EL, the driving system 9 may start the avoidance control as usual.

[0230] If the vehicle 3 stopped on the road is a bus, two reasons are assumed for the vehicle 3 to stop again after starting: (1) arriving at a bus stop, or (2) detecting some kind of risk (pedestrians, etc.). If the vehicle 3 is a bus and a bus stop is detected near the re-stop point (YES in S233), the driving system 9 may retry the avoidance control. On the other hand, if the vehicle 3 is a bus and no bus stop is present near the re-stop point (NO in S233), the retry of the avoidance control may be canceled (S234). Alternatively, if the vehicle 3 is a bus and no bus stop is present near the re-stop point, the driving system 9 may be configured to execute the avoidance control at a speed lower than the basic speed applied under normal circumstances. Here, "normal circumstances" may be interpreted as when a bus stop is detected or when the vehicle 3 changes lanes for the first time. The determination step of S233 is optional and may be omitted. If S233 is omitted, S234 may be executed if the vehicle 3 is detected to have stopped again (YES in S232).

[0231] According to the above process, it is possible to reduce the possibility that avoidance control will be executed when a pedestrian or the like is present in the blind spot of the bus or the like. In other words, the safety of vulnerable road users such as pedestrians can be improved. The flow shown in Fig. 18 may be executed only when the vehicle 3 is a service car such as a bus or a taxi, or a commercial vehicle.

[0232] Incidentally, it is predicted that buses will stop at every bus stop. If the stopped vehicle 3 is a bus, the driving system 9 may control the vehicle 3 to pass by the bus at the next bus stop. If the vehicle 3 is a bus, the driving system 9 may monitor the behavior of the bus during avoidance control, as shown in S241 of FIG. 19 . Then, if the driving system 9 detects or predicts that the bus is about to depart (YES in S242), it may interrupt the avoidance control (S243). The decision to interrupt the avoidance control may be made based on the progress of the avoidance control or the speed of the vehicle 1, as described above.

[0233] When the driving system 9 stops the avoidance control for the bus, it may set the set value of the distance from the preceding vehicle to be longer than the basic value (S244). The basic value is the distance to be applied when there is no history of stopping the avoidance control for the bus within a certain time period in the past. A value according to the traveling speed of the vehicle 1 and the settings of the vehicle user may be applied as the basic value. The processing of S244 above makes it easier to execute the avoidance control the next time the bus stops at a bus stop.

[0234] During the avoidance control, the driving system 9 may detect that another road user (hereinafter, an oncoming user) is approaching from the front on the oncoming lane OL. In such a case, the driving system 9 may determine a response depending on the type of the oncoming user.

[0235] For example, if the detected oncoming user is a road user whose width is equal to or less than a predetermined value (e.g., 1 m), such as a pedestrian, cyclist, or motorcyclist, it may be determined to continue avoidance control. This is because, when the oncoming user is a pedestrian, etc., a safe lateral distance is likely to be maintained even when the vehicle extends into the oncoming lane (OL). Note that a road user whose width is equal to or less than a predetermined value may be read as a VRU.

[0236] On the other hand, if the detected oncoming user is a car, it may be decided to discontinue the avoidance control. Note that even if the detected oncoming user is a car, the avoidance control may be continued if the oncoming user is sufficiently far away from the vehicle 1. The continuation of the avoidance control when an oncoming user is detected may be decided based on the type, position, and speed of the oncoming user, and the progress of the avoidance control.

[0237] The avoidance control when an oncoming user is detected may be performed at a slower speed than the avoidance control when an oncoming user is not detected. Note that the driving system 9 may be configured to start deceleration when the detected longitudinal distance to the oncoming user becomes less than a predetermined value.

[0238] According to the above configuration, convenience for vehicle users can be improved while ensuring the safety of oncoming users.

[0239] <Another Operation Example (1) of the Driving System> Furthermore, as shown in FIG. 20 , when the driving system 9 determines that a specific scenario (here, a stopped vehicle-related scenario) applies (YES in S251), it determines in S252 whether the current automation level is 3 or higher. Determining the current automation level corresponds to determining the current mode, which is the current operating mode. Here, the "current" may refer to the time when it is determined that the scenario applies to a stopped vehicle-related scenario. "AD_LV" in the figure means the current automation level.

[0240] The driving system 9 may be configured to plan and execute standby control in S253 when a stopped vehicle 3 is detected while driving in an operation mode of level 3 or higher (YES in S252). On the other hand, the driving system 9 may be configured to perform avoidance determination processing in S254 when a stopped vehicle 3 is detected while driving in an operation mode below level 3 (e.g., level 2 mode) (NO in S252). The avoidance determination processing is processing that includes determining whether avoidance control is possible and starting avoidance control based on the determination that avoidance control is possible. The avoidance determination processing may be processing that includes, for example, S104 to S111.

[0241] According to the above configuration, in operation modes of level 3 or higher, the frequency of execution of avoidance control is reduced compared to level 2 mode. Avoidance control must be executed by predicting the movements of multiple road users, such as oncoming vehicles in addition to stopped vehicles 3. Therefore, avoidance control is more difficult for automated driving than following the road. During avoidance control, a handover of driving from the system to the vehicle user (i.e., takeover) is more likely to occur. According to the above configuration, the execution of avoidance control is limited when the automation level is 3, thereby reducing the probability of a takeover request occurring. A takeover request is a process that uses the information presentation device 70b to request the vehicle user to perform driving operations. The takeover request may include the display of an image or audio output requesting driving operations.

[0242] <Another Operation Example (2) of the Driving System> After detecting the stopped vehicle 3, the driving system 9 executes standby control according to traffic conditions and may stop the vehicle 1 behind the stopped vehicle 3. The situation in which the vehicle 1 stops behind the stopped vehicle 3 may include a situation in which there is no other vehicle between the stopped vehicle 3 and the vehicle 1, as well as a situation in which one or more other vehicles are present between the stopped vehicle 3 and the vehicle 1.

[0243] When the vehicle 1 stops behind the stopped vehicle 3, the driving system 9 may acquire the forward distance (FL) and determine whether to execute avoidance control based on the forward distance. The forward distance here is the vertical length of the empty space in front of the vehicle 1.

[0244] For example, in response to the fact that vehicle 1 has stopped behind stopped vehicle 3, the driving system 9 acquires the forward inter-vehicle distance (FL) as shown in S261 of Fig. 21. Then, if the forward inter-vehicle distance (FL) is greater than a predetermined space threshold (ThFL) (YES in S262), the driving system 9 executes an avoidance determination process in S263. On the other hand, if the forward inter-vehicle distance (FL) is equal to or less than the space threshold (ThFL) (NO in S262), the driving system 9 plans and executes waiting control in S264.

[0245] "FL" in the figure indicates the vertical length of the empty space in front of the vehicle 1, i.e., the distance between vehicles ahead. Also, "ThFL" in the figure indicates the space threshold. The space threshold may be set to a distance that ensures a sufficient FOV of the external environment sensor 41 for the oncoming lane OL. For example, the space threshold may be set to 10 m. The space threshold may be adjusted according to the lateral distance between another vehicle in front of the vehicle 1 and the center line, or the lateral distance between the center of the vehicle 1 and the center of the other vehicle in front of the vehicle 1.

[0246] For example, if the preceding vehicle suddenly stops while vehicle 1 is following the preceding vehicle, the preceding vehicle and vehicle 1 are stopped with a small inter-vehicle distance between them. In other words, the forward inter-vehicle distance becomes relatively small. When the forward inter-vehicle distance is equal to or less than the space threshold, there are many blind spots for the external environment sensor 41, resulting in high uncertainty in the results of environmental recognition. Therefore, safety can be improved by performing waiting control instead of overtaking control. Furthermore, when the forward inter-vehicle distance is sufficiently large, the FOV for the oncoming lane OL is also good, resulting in relatively low uncertainty in the results of environmental recognition. Therefore, avoidance control can be performed based on the results of the avoidance determination process. This control can ensure safety while improving convenience for the vehicle user. Furthermore, when the forward inter-vehicle distance is less than a predetermined value, waiting control is simply selected without checking the behavior of the stopped vehicle 3 or oncoming users. This also reduces the processing load on the driving system 9. The driving system 9 may be configured to issue a takeover request when the forward distance (FL) is equal to or less than the space threshold (ThFL) (NO in S262).

[0247] <Another Operation Example (3) of the Driving System> As shown in FIG. 22 , when the driving system 9 determines that a specific scenario (here, a stopped vehicle-related scenario) applies (YES in S271), the driving system 9 may acquire an estimated stop time of the detected stopped vehicle 3 (S272). The detected stopped vehicle 3 may also be referred to as a target. The estimated stop time of the stopped vehicle 3 may be an estimated value of the remaining time from when the stopped vehicle 3 is detected until the stopped vehicle 3 starts moving. In other embodiments, the estimated stop time may be an estimated value of the time from when the stopped vehicle 3 stops until it starts moving. The estimated stop time may be estimated from the type of the stopped vehicle 3. For example, if the stopped vehicle is a route bus, the estimated stop time may be set to 30 seconds. If the stopped vehicle 3 is a taxi carrying a passenger, the estimated stop time may be set to 45 seconds. If the stopped vehicle 3 is a delivery vehicle, the estimated stop time may be set to 2 minutes. If the stopped vehicle 3 is a vehicle used for moving work, the estimated stop time may be set to one hour or more.

[0248] The driving system 9 may acquire the estimated stopping time of the stopped vehicle 3 by wirelessly communicating with the stopped vehicle 3. The driving system 9 may also acquire the estimated stopping time of the stopped vehicle 3 by inquiring of a specific server about the estimated stopping time of the stopped vehicle 3. For example, the estimated stopping time of a route bus may be acquired by inquiring of a server that manages the operation of the bus. The value of the estimated stopping time held by the driving system 9 may be updated over time. In other words, the estimated stopping time may be counted down from the time the stopped vehicle 3 is detected.

[0249] If the preceding vehicle is a bus, the driving system 9 may be configured to record the bus stopping point and the bus stopping time. The driving system 9 may be configured to identify the expected bus stopping time based on the record of past bus stops. The bus stopping records may be collected on a server and shared among multiple driving systems 9.

[0250] The driving system 9 may calculate the expected stopping time based on the lighting state or transition of lighting states of lighting devices such as turn signal lamps, brake lamps, and hazard lamps. If the driving system 9 detects that the hazard lamps of the stopped vehicle 3 are on, it may determine the expected stopping time to be long (e.g., 60 seconds). If the driving system 9 detects that the turn signal lamp of the stopped vehicle 3 pointing toward the road edge is flashing, it may also determine the expected stopping time to be long. The road edge direction is the direction toward the road edge to which the vehicle should approach when stopping to open and close its doors. In areas where traffic is on the right, the right side corresponds to the road edge direction, and in areas where traffic is on the left, the left side corresponds to the road edge direction. In the example shown in FIG. 10 , the right side of the vehicle 1 corresponds to the road edge direction. In this disclosure, the direction opposite the road edge direction is also referred to as the road center direction. If the driving system 9 detects that the turn signal lamp of the stopped vehicle 3 pointing toward the road center is flashing, it may determine the expected stopping time to be short (e.g., 10 seconds). The driving system 9 may also determine that the expected stop time is short when it detects that the brake lights of the stopped vehicle 3 have transitioned from an off state to an on state.

[0251] Furthermore, the driving system 9 calculates the required avoidance time in consideration of the traffic conditions in the oncoming lane OL (S273). The required avoidance time is the time required to avoid (in other words, pass by or overtake) the stopped vehicle 3. The required avoidance time may vary depending on the traffic conditions in the oncoming lane OL. When avoidance control can be performed without stopping the vehicle 1, the required avoidance time may be determined according to the current traveling speed. A case where avoidance control can be performed without stopping the vehicle 1 corresponds to a case where there is no oncoming vehicle, etc. The required avoidance time when avoidance control can be performed without stopping may be a fixed value, such as 10 seconds.

[0252] Depending on the traffic conditions in the oncoming lane, the vehicle 1 may need to stop temporarily behind the stopped vehicle 3. The avoidance time required when the vehicle 1 is forced to temporarily stop behind the stopped vehicle 3 may be a predetermined assumed value, such as 30 seconds. The avoidance time required when a temporary stop is included may be the sum of the actual avoidance time and the departure waiting time. The actual avoidance time is the time required from starting from a stopped state to going around in front of the stopped vehicle 3, and may be the sum of the times required for the initial phase, middle phase, and late phase. The actual avoidance time may be calculated based on the basic value of acceleration for avoidance control and the longitudinal length of the stopped vehicle 3. The departure waiting time is determined according to the traffic conditions in the oncoming lane OL. The departure waiting time may be calculated based on the position and number of oncoming vehicles included in the FOV of the external environment sensor 41 at the time the vehicle 1 stops behind the stopped vehicle 3. The departure waiting time may be updated periodically.

[0253] When the driving system 9 detects a stopped vehicle 3, it acquires the expected stop time and the required avoidance time using the method described above or any other method. Then, the driving system 9 compares the expected stop time with the required avoidance time to determine whether to avoid the stopped vehicle 3 or wait (S274). For example, the driving system 9 may determine to execute avoidance control when the expected stop time is greater than the required avoidance time by a predetermined value or more (S275). In this case, the driving system 9 may start avoidance control when the execution condition for avoidance control is met. On the other hand, when the value obtained by subtracting the required avoidance time from the expected stop time is less than a predetermined value, the driving system 9 determines to stop and wait behind the stopped vehicle 3 without executing avoidance control (S276). This is because if the waiting time is short, the need for avoidance control is small. In FIG. 22 , "TL1" represents the expected stop time, "TL2" represents the required avoidance time, and "ThTL" represents a predetermined value.

[0254] Note that even during standby in S276, if the execution conditions for avoidance control are met and preparatory movements for starting by the stopped vehicle 3 have not yet been detected, the driving system 9 may start avoidance control at that timing. This is because the expected stopping time may differ from the actual stopping time. The preparatory movements for starting may be turning off the brake lights, turning on the blinker lights toward the center of the road, closing the doors, announcing departure, or the like. The preparatory movements for starting may be referred to as a sign of starting. The preparatory movements for starting may be detected based on sensor data (for example, a camera image or external sound information).

[0255] 23 shows an example of the operation of the driving system 9 in a scenario in which a stopped vehicle 3 attempts to start while a vehicle 1 is executing avoidance control. As described above, the driving system 9 monitors the behavior of the stopped vehicle 3 even after starting avoidance control (S281). The driving system 9 may be configured to, in principle, stop the avoidance control if it detects that the stopped vehicle 3 has started to move or is making a preparatory movement for doing so while executing avoidance control (S282).

[0256] However, if the driver of vehicle 3 notices the presence of vehicle 1 trying to pass vehicle 3, vehicle 3 may cancel the start and give the right-of-way to vehicle 1. In such a case, vehicle 1 may resume or retry the avoidance control. That is, the driving system 9 continues to monitor the behavior of vehicle 3 even after deciding to stop the avoidance control in S283 (S284), and if vehicle 3 takes a predetermined action to give the right-of-way to vehicle 1 (YES in S285), the driving system 9 may resume or continue the avoidance control (S286).

[0257] The predetermined action of vehicle 3 yielding the right of way may be an action indicating the cancellation of the start. For example, if the brake lights of vehicle 3 are turned off and then turned on again within a few seconds (e.g., 3 seconds), the driving system 9 may determine that vehicle 3 has given way to vehicle 1. Furthermore, if the turn signal light in the road center direction of vehicle 3 is turned on and then turned off and the brake light is turned on within a few seconds after the turn signal light is turned on, the driving system 9 may determine that vehicle 3 has given way to vehicle 1.

[0258] In this way, the driving system 9 may execute avoidance control if the vehicle transitions to a complete stop state again within a predetermined time after the vehicle 3 starts or performs a preparatory movement for starting. The complete stop state is a stopped state in which there is no preparatory movement for starting. For example, it is a state in which the vehicle is stopped with the hazard lights on, a state in which the blinker lights toward the road edge are on, a state in which the door is open, etc. The driving system 9 may also estimate that the vehicle is in a complete stop state for a predetermined time after the brake lights transition from an off state to an on state.

[0259] As described above, in a scenario where it is highly likely that the stopped vehicle 3 has given way to the vehicle 1, the driving system 9 may be configured to execute avoidance control, thereby facilitating smooth traffic flow. Note that if the driving system 9 has not detected any behavior of vehicle 3 indicating that it will stop moving after the avoidance control is stopped (NO in S285), it causes vehicle 1 to wait behind vehicle 3 (S287).

[0260] <Another Operation Example (5) of the Driving System> The driving system 9 may be configured to be able to detect a siren (also referred to as an alarm sound) of an emergency vehicle using an acoustic sensor. When the stopped vehicle 3 is an emergency vehicle, the driving system 9 may determine whether to perform avoidance control depending on whether the emergency vehicle serving as the stopped vehicle 3 is emitting a siren. When the emergency vehicle serving as the stopped vehicle 3 is emitting a siren, the driving system 9 causes the vehicle 1 to wait behind the stopped vehicle 3 without performing avoidance control. On the other hand, when the emergency vehicle serving as the stopped vehicle 3 is not emitting a siren, the driving system 9 may perform avoidance control in response to the establishment of a condition for executing avoidance control. Note that when the stopped vehicle 3 is an emergency vehicle, even if a siren is not being emitted, the driving system 9 may be configured to temporarily stop (i.e., wait temporarily) behind the stopped vehicle 3 in preparation for a person running out into the road, etc.

[0261] Furthermore, the driving system 9 may be configured not to perform avoidance control when an emergency vehicle with a siren is detected behind the vehicle 1, even if the stopped vehicle 3 itself is not an emergency vehicle. In a scenario in which the driving system 9 detects a stopped vehicle 3 ahead and an emergency vehicle with a siren behind the vehicle 1, the driving system 9 may be configured to stop the vehicle 1 along the edge of the road behind the stopped vehicle 3.

[0262] Furthermore, the driving system 9 may be configured not to perform avoidance control even when an emergency vehicle with a siren emitting is detected in the oncoming lane OL, even if the stopped vehicle 3 itself is not an emergency vehicle. In a scenario in which the driving system 9 detects a stopped vehicle 3 ahead and an emergency vehicle with a siren emitting is detected in the oncoming lane OL, the driving system 9 may be configured to have the vehicle 1 wait behind the stopped vehicle 3. These operations can reduce the risk of the vehicle 1 obstructing the passage of the emergency vehicle. Here, emergency vehicles may include ambulances, fire engines, police cars, etc. Emergency vehicles may also include specialized work vehicles for repairing infrastructure facilities such as electricity, gas, or water.

[0263] <Dynamic Adjustment of Inter-Vehicle Distance in Preparation for Avoidance Control> The driving system 9 may change the set value of the inter-vehicle distance depending on whether the preceding vehicle is a specific type of vehicle that may stop periodically. FIG. 24 shows an example of a process for changing the set value of the inter-vehicle distance depending on the type of the preceding vehicle. A typical example of a specific type of vehicle is a route bus. Route buses may include trolleys, etc. In areas where passing by stopped school buses is not prohibited, school buses may also be included in the specific type of vehicle. Delivery vehicles may also be included in the specific type of vehicle.

[0264] When the driving system 9 detects a preceding vehicle, it analyzes the camera image to acquire the type of the preceding vehicle (S291). It then determines whether the preceding vehicle corresponds to a specific type of vehicle (S292). If the driving system 9 is following a specific type of vehicle (YES in S291), it increases the set value of the inter-vehicle distance from the basic value (S293). That is, in response to the preceding vehicle being a specific type of vehicle, the driving system 9 increases the set value of the inter-vehicle distance from the basic value. The amount of increase in the inter-vehicle distance may be 5 m, 10 m, or the like. The inter-vehicle distance may be specified by a time interval between vehicles, and the amount of increase in the inter-vehicle distance may be 1 second, for example. The time interval between vehicles is a parameter that indicates the time from when the vehicle Hv passes a certain point where the preceding vehicle has passed until when the vehicle Hv passes the same point.

[0265] In this way, the driving system 9 increases the following distance when the preceding vehicle is a specific type vehicle compared to when the preceding vehicle is not a specific type vehicle. By increasing the following distance, visibility of the oncoming lane OL can be improved. Also, it becomes easier to stop the vehicle closer to the center line for avoidance control.

[0266] Furthermore, the driving system 9 may acquire information on predicted stopping points, which are points where the preceding vehicle may stop, by referring to map data. If the preceding vehicle is a route bus, the predicted stopping points may be bus stops. The driving system 9 may be configured to record the stopping points and stopping times of the school bus when following a school bus. The driving system 9 may be configured to identify the predicted stopping points of the school bus based on records of past school bus stops. Records of school bus stops may be collected in a server and shared among multiple driving systems 9.

[0267] The driving system 9 may be configured to change the set value of the inter-vehicle distance when the preceding vehicle is a specific type of vehicle and the distance from the vehicle 1 to the predicted stopping point is within a predetermined value. For example, when the driving system 9 is following a specific type of vehicle, the driving system 9 may change the set value of the inter-vehicle distance from a basic value to a value that is larger by a predetermined amount based on the fact that the distance from the vehicle 1 to the predicted stopping point is within a predetermined value. When the distance from the vehicle 1 to the predicted stopping point is larger than the predetermined value, the driving system 9 may apply the basic value as the set value of the inter-vehicle distance. The predicted stopping point used here may be an expected stopping point corresponding to the preceding vehicle. When the preceding vehicle is a route bus, the driving system 9 does not use the expected stopping point of the school bus, but uses the expected stopping point of the route bus.

[0268] According to the above operation example, when the vehicle is traveling away from the predicted stopping point corresponding to the preceding vehicle, the normal inter-vehicle distance is maintained. On the other hand, when the vehicle approaches the predicted stopping point corresponding to the preceding vehicle, the inter-vehicle distance is increased. As a result, even if the preceding vehicle stops, the vehicle 1 can be stopped while maintaining a sufficient inter-vehicle distance ahead, and visibility of the road beyond the stopped preceding vehicle can be improved.

[0269] In relation to the above, the driving system 9 may verify whether there are pedestrians waiting for the preceding vehicle at the predicted stopping point when the predicted stopping point is included in the FOV of the external environment sensor 41. For example, when the preceding vehicle is a route bus, the driving system 9 may determine whether there are pedestrians at the bus stop based on the sensor data of the external environment sensor 41.

[0270] When the driving system 9 detects a person waiting at a bus stop while following a route bus, it may perform lateral position adjustment for avoidance control. The lateral position adjustment is adjusting the traveling position of the vehicle 1 in the lateral direction (in other words, the road width direction). The lateral position during normal traveling may be the lane center. The lateral position may be defined as the center of the body of the vehicle 1, for example, the center of the front end in the vehicle width direction. The lateral position adjustment for avoidance control may be shifting the lateral position of the vehicle 1 a predetermined amount from the lane center toward the avoidance direction. The avoidance direction is the direction from the center of the ego lane EL to the center line or the oncoming lane OL. In the present disclosure, driving the vehicle 1 along the lane with the center of the vehicle 1 closer to the center line than the lane center is also referred to as offset traveling for avoidance control.

[0271] The offset amount in offset driving, i.e., the amount of deviation of the center of the vehicle 1 from the center of the lane, may be a constant value such as 0.5 m. The offset amount may also be dynamically adjusted based on the center line. Offset driving may be a control in which the vehicle 1 travels along the road while maintaining a distance between the vehicle 1 and the center line that is less than a predetermined value (e.g., 0.3 m).

[0272] When the lateral position is closer to the lane center in the avoidance direction, the visibility of the oncoming lane OL is improved compared to when the vehicle 1 is in the lane center. This reduces the blind spot caused by the stopped vehicle 3, improving the detectability of other road users, such as oncoming vehicles. This can also increase the reliability of the recognition result that there are no oncoming vehicles.

[0273] The driving system 9 may be configured to maintain the center of the lane without adjusting the lateral position for avoidance control when no person is detected at a stop ahead while following a route bus. Note that even when no person is detected at a stop ahead while following a route bus, the driving system 9 may adjust the lateral position for avoidance control when a warning of an impending stop is displayed on the rear display of the route bus.

[0274] <Road Structure> The above-described control may also be applied when the vehicle 1 is traveling on a community road, as shown in Figure 25. A community road here may be a road that does not have lane markings including a center line, for example, a road whose width is less than a predetermined value. A community road may also be referred to as a narrow street.

[0275] The above-described control may also be applied when the vehicle 1 is traveling on a road with two or more lanes in each direction, as shown in FIG. 26 . In this disclosure, among lanes having the same traveling direction, the lane adjacent to the road edge 81 is also referred to as the first lane L1. Furthermore, the lane adjacent to the first lane L1 and having the same traveling direction as the first lane is referred to as the second lane L2. The second lane L2 is located on the opposite side of the road edge 81 from the first lane L1. The temporary traffic lane TL used in the avoidance control may be the second lane L2. Reference numeral 84 in FIG. 26 indicates a lane marking that serves as the boundary between the first lane L1 and the second lane L2.

[0276] As shown in FIG. 27 , the driving system 9 may be configured to change the intersection timing depending on whether the temporary traffic lane TL and the original lane BL are traveling in the same direction. The intersection timing here refers to the timing at which the boundary between the original lane and the temporary traffic lane is crossed. That is, when the driving system 9 detects a stopped vehicle 3, it acquires road configuration data in S301. Note that S301 may be executed in response to a decision to execute avoidance control. The road configuration data may be data indicating whether the lane adjacent to the ego lane EL is an oncoming lane or a same-direction lane. If it is acquired that the temporary traffic lane is a same-direction lane, the driving system 9 sets the intersection timing earlier in S303. On the other hand, if it is acquired that the temporary traffic lane is an oncoming lane, the driving system 9 sets the intersection timing earlier in S304. The earlier intersection timing here may be, for example, 20 m or 30 m behind the stopped vehicle 3. The later intersection timing may be, for example, 5 m or 10 m behind the stopped vehicle 3.

[0277] <Setting of Control Parameters Related to Speed ​​Adjustment> The driving system 9 may be configured to be able to perform overtaking control in addition to avoidance control. Overtaking control is control for overtaking a preceding vehicle that is traveling by changing lanes. The overtaking control and avoidance control may be aspects of automatic driving or driving assistance by the driving system 9.

[0278] The driving system 9 may have registered therein setting data for control parameters to be applied during overtaking control and setting data for control parameters to be applied during avoidance control. The control parameters may include a basic value for acceleration, an upper limit for acceleration, a basic value for speed, an upper limit for speed, and an upper limit for steering speed. The various basic values ​​may be understood as values ​​to be applied in situations where there are no special circumstances. The setting data may be stored in the memory 51a.

[0279] The base value and upper limit value of acceleration for the avoidance control may be set smaller than the base value and upper limit value of acceleration for the overtaking control. Also, the base value and upper limit value of speed for the avoidance control may be set smaller than the base value and upper limit value of speed for the overtaking control. In other words, the avoidance control may be set to be executed more slowly than the overtaking control.

[0280] In other embodiments, the base value and upper limit value of acceleration for the avoidance control may be set to be greater than the base value and upper limit value of acceleration for the overtaking control. Control parameters for the case where avoidance control is started from a stopped state may be registered in the main unit 51 separately from control parameters for the case where avoidance control is started from a traveling state (without stopping).

[0281] The control parameters may also include a parameter that specifies the crossing timing, which is the timing at which a vehicle crosses a lane mark for avoidance or overtaking. When the temporary traffic lane is a same-direction lane, the crossing timing for avoidance control may be set to be earlier than the crossing timing for overtaking control. A same-direction lane is a lane that travels in the same direction as the ego lane EL.

[0282] For example, if the crossing timing in the overtaking control is 20 m, the crossing timing in the avoidance control when the temporary traffic lane is a same-direction lane may be set to 30 m behind the stopped vehicle 3. Note that, when the temporary traffic lane is an oncoming lane, the crossing timing in the avoidance control may be set to a relatively short value, such as 5 m behind the stopped vehicle 3. The crossing timing in the overtaking control may be rephrased as the lane change timing.

[0283] <System Configuration> In one embodiment, some or all of the risk confirmation units 26 may be provided in multiple locations for redundancy. In this case, the multiple risk confirmation results may be integrated into a final result by majority vote, and this final result may be reflected in the control of the motion actuator 60.

[0284] In one embodiment, the main unit 51 and the risk identification unit 53 may be integrated into one or both of a hardware configuration and a software configuration. When the risk identification function is integrated with the planning function, the planner 20 may set a safety envelope as an acceptable limit for the target inter-vehicle distance or target position, and may develop a trajectory plan and a behavior plan to avoid reaching the acceptable limit. Furthermore, when the acceptable limit is reached (i.e., when the safety envelope is violated), the planner 20 may be configured to plan an appropriate response.

[0285] The driving system 9 may be any of various types of ADS. The driving system 9 may also be an advanced driver-assistance system (ADAS). In one embodiment, as shown in FIG. 28 , the driving system 9 may include multiple risk confirmation units 26a, 26b, and 26c that form a redundant system. The risk confirmation unit 26a is a camera-based risk confirmation unit 26 that acquires a situation and confirms a risk based on an image captured by a camera 41a. The risk confirmation unit 26b is a radar-based risk confirmation unit 26 that acquires a situation and confirms a risk based on sensor data output from a millimeter-wave radar 41b. The risk confirmation unit 26c is a LiDAR-based risk confirmation unit 26 that acquires a situation and confirms a risk based on sensor data output from a LiDAR 41c. In this configuration, in order to ensure hardware redundancy, the planning unit 20, risk confirmation unit 26a, risk confirmation unit 26b and risk confirmation unit 26c may each be realized by hardware that is independent of each other (e.g., separate computers or SoCs).

[0286] The detection unit 10 may include three types of sensors as the multiple external environment sensors 41: one or more cameras 41a, one or more millimeter-wave radars 41b, and one or more LiDARs 41c. The detection unit 10 may further include a sensor fusion unit 41d that fuses the detection results of the cameras 41a, the millimeter-wave radars 41b, and the LiDARs 41c. The external environment recognition result generated by fusing the detection results in the sensor fusion unit 41d may be input to the planning unit 20.

[0287] The confirmation results from the risk confirmation units 26 a, 26 b, and 26 c are aggregated in a majority decision unit 26 x. The majority decision unit 26 x may be a module that arbitrates conflicts between outputs from the multiple risk confirmation units 26. The majority decision unit 26 x may be configured to ultimately determine an appropriate response by majority decision and input the response to the planner 20.

[0288] The route plan, behavior plan, and trajectory plan by the planning unit 20 may be corrected or rewritten based on the appropriate response determined and output as a result of the aggregated risk confirmation. The operation system 9 shown in Fig. 28 has three redundant systems for safety, and therefore may be considered as an ADS with a three-way redundant majority vote.

[0289] The operation system 9 may be a dual-redundant ADS as shown in Fig. 29. The dual-redundant ADS means an ADS having two risk confirmation units 26. In the dual-redundant ADS, if one of the risk confirmation units 26 as a subsystem fails, a DDT fallback may be executed.

[0290] The risk confirmation function can be implemented not only in vehicles with automation level 3 or higher, but also in vehicles with automation levels 0 to 2. For example, the driving system 9 may be an ADAS. The risk confirmation unit 53 may perform risk confirmation even when the automation level is set to 0 to 2. Furthermore, even when the automation level is set to 0 to 2, the risk confirmation unit 53 may intervene in the control of the motion actuator 60 by outputting an appropriate response if a violation of the safety envelope occurs. For a vehicle V2 driven by a vehicle user, the appropriate response may be to issue a warning to the vehicle user using the information presentation device 70b instead of intervening in the control of the motion actuator 60. Both intervention in the control of the motion actuator 60 and the warning may be implemented.

[0291] <Supplementary Note (1)> This specification discloses multiple technical ideas described in the following multiple clauses. Some clauses may be described in a multiple dependent form, in which the subsequent clause alternatively cites the preceding clause. These multiple dependent clauses define multiple technical ideas. This disclosure also includes methods, programs, and recording media on which the programs are recorded that correspond to the following operating systems.

[0292] [Technical Idea 1] A driving system configured to be able to control the autonomous driving of a vehicle (1), comprising: a communication circuit (51c) that receives signals indicative of an external environment; and a processing unit (51b, 53b) that executes processing related to the autonomous driving of the vehicle based on the signals received by the communication circuit, wherein the processing unit is configured to: determine, based on the signals received by the communication circuit, whether a scenario in which the vehicle is driving near another stopped vehicle applies; and, if it is determined that the current situation applies to the scenario, determine a response to the other vehicle depending on the type or behavior of the other vehicle.

[0293] [Technical Idea 2] The driving system described in Technical Idea 1, wherein the processing unit is configured to start avoidance control, which is control to avoid the other vehicle, based on the fact that it has determined that the current situation corresponds to the scenario, and when it detects that the other vehicle has started moving after starting the avoidance control, to determine whether to continue the avoidance control depending on the position of the host vehicle at the time when it detects that the other vehicle has started moving.

[0294] [Technical Idea 3] The processing unit is configured to: discontinue the avoidance control if the longitudinal distance between the host vehicle and the other vehicle is equal to or greater than a safe distance when the processing unit detects that the other vehicle has started moving; and decide to continue the avoidance control if the longitudinal distance between the host vehicle and the other vehicle is less than the safe distance when the processing unit detects that the other vehicle has started moving.

[0295] [Technical Idea 4] The driving system described in any one of Technical Ideas 1 to 3, wherein the processing unit is configured to: start avoidance control, which is control to avoid the other vehicle, based on the fact that it has been determined that the current situation corresponds to the scenario; detect the departure of the other vehicle based on information indicating the behavior of the other vehicle; and decide to discontinue the avoidance control if, at the time the departure of the other vehicle is detected, the host vehicle has not crossed a lane mark or if the amount by which the host vehicle crosses the lane mark is less than a predetermined value.

[0296] [Technical Idea 5] A driving system described in any one of Technical Ideas 1 to 4, wherein the processing unit is configured to start avoidance control, which is control to avoid the other vehicle, based on the fact that it has determined that the current situation corresponds to the scenario, and if it detects that the other vehicle has started moving after starting the avoidance control, to determine whether to continue the avoidance control depending on the speed of the host vehicle at the time the departure of the other vehicle is detected.

[0297] [Technical Idea 6] The driving system described in any one of Technical Ideas 1 to 5, wherein the processing unit is configured to: start avoidance control, which is control to avoid the other vehicle, based on identifying that the current situation corresponds to the scenario; decide to stop the avoidance control based on detecting that the other vehicle has started moving after starting the avoidance control; and decide to retry the avoidance control if detecting that the other vehicle has stopped again after deciding to stop the avoidance control.

[0298] [Technical Idea 7] A driving system described in any one of Technical Ideas 1 to 6, wherein the processing unit is configured to monitor the lighting status of the lighting equipment of the other vehicle based on the determination that the current situation corresponds to the scenario, and predict the departure of the other vehicle based on the monitoring results of the lighting status.

[0299] [Technical Idea 8] A driving system described in any one of Technical Ideas 1 to 7, wherein the processing unit is configured to: perform wireless communication with the other vehicle using a wireless communication device based on determining that the current situation corresponds to the scenario; and predict the departure of the other vehicle based on data received through wireless communication with the other vehicle.

[0300] [Technical Idea 9] The driving system according to Technical Idea 7 or 8, which is configured to determine not to start avoidance control, which is control to avoid the other vehicle, when the departure of the other vehicle is predicted, and to determine to start the avoidance control when the departure of the other vehicle is not predicted.

[0301] [Technical Idea 10] The driving system described in any one of Technical Ideas 1 to 9 is configured such that, based on the determination that the current situation corresponds to the scenario, the processing unit initiates avoidance control to avoid the other vehicle by going around in front of the other vehicle through an adjacent lane that is a lane next to the lane blocked by the other vehicle, and changes the timing of crossing the boundary line between the lane blocked by the other vehicle and the adjacent lane depending on whether the adjacent lane is traveling in the same direction as the lane blocked by the other vehicle.

[0302] [Technical Idea 11] The processing unit is configured to be able to perform avoidance control to avoid other vehicles, including going around in front of the other vehicle through an adjacent lane next to the lane in which the other vehicle is located, and overtaking control to overtake a preceding vehicle that is traveling by changing lanes, and when the adjacent lane is traveling in the same direction as the lane blocked by the other vehicle, the timing to cross the boundary line to the adjacent lane in the avoidance control is configured to be set to a timing earlier than the timing to change lanes in the overtaking control.

[0303] [Technical Idea 12] The driving system described in any one of Technical Ideas 1 to 11, wherein the processing unit is configured to: start avoidance control, which is control to avoid the other vehicle, based on identifying that the current situation corresponds to the scenario; and create a plan during the avoidance control assuming that there is a vulnerable road user in front of the other vehicle.

[0304] [Technical Idea 13] The driving system described in any one of Technical Ideas 1 to 12 is configured so that the processing unit: obtains whether or not there are other road users in the oncoming lane based on the determination that the current situation corresponds to the scenario; determines, based on the detection that the other road users are not in a specific area on the oncoming lane, to start avoidance control, which is control to go around in front of the other vehicle through the oncoming lane; and if it detects the presence of the other road user in the oncoming lane after starting the avoidance control, determines whether or not to stop the avoidance control depending on the type or speed of the other road user.

[0305] [Technical Idea 14] The driving system according to any one of Technical Ideas 1 to 13, wherein the processing unit is configured to, if the other vehicle is a school bus, create a plan to stop behind the other vehicle without executing avoidance control, which is control to avoid the other vehicle.

[0306] [Technical Idea 15] The driving system described in any one of Technical Ideas 1 to 14, wherein the processing unit is configured to: start avoidance control, which is control to avoid the other vehicle, based on the determination that the current situation corresponds to the scenario; monitor the behavior of the other vehicle while the avoidance control is being executed; and, if behavior related to the other vehicle's departure is detected while the avoidance control is being executed, decide to increase the driving speed compared to when behavior related to the other vehicle's departure is not detected.

[0307] [Technical Idea 16] The driving system described in any one of Technical Ideas 1 to 15, wherein the processing unit is configured to: determine whether the other vehicle is a bus; and, based on the determination that the current situation corresponds to the scenario, initiate avoidance control, which is control to avoid the other vehicle, the bus; and, if behavior related to the other vehicle's departure is detected during the execution of the avoidance control, stop the avoidance control; and increase the set value of the inter-vehicle distance from the preceding vehicle by a predetermined amount.

[0308] [Technical Idea 17] A driving system described in any one of Technical Ideas 1 to 16, which has multiple operating modes with different automation levels of driving operations, the multiple operating modes including a level 2 mode which is an operating mode corresponding to the automation level 2, and a level 3 mode which is an operating mode corresponding to the automation level 3, and the processing unit is configured to: determine that the current situation corresponds to the scenario and, if the operating mode is the level 2 mode, start avoidance control, which is control to avoid the other vehicle; and determine that the current situation corresponds to the scenario and, if the operating mode is the level 3 mode, not start avoidance control, which is control to avoid the other vehicle.

[0309] [Technical Idea 18] A driving system according to any one of Technical Ideas 1 to 17, comprising a plurality of operating modes with different automation levels of driving operations, the plurality of operating modes including a level 2 mode that is an operating mode corresponding to the automation level of 2, and a level 3 mode that is an operating mode corresponding to the automation level of 3, wherein the processing unit is configured to: identify that the current situation corresponds to the scenario, and if the operating mode is the level 2 mode or the level 3 mode, start avoidance control, which is control to avoid the other vehicle; monitor the behavior of the other vehicle while the avoidance control is being executed; continue the avoidance control if the operating mode is the level 2 mode when behavior related to the other vehicle's departure is detected during the execution of the avoidance control, while canceling the avoidance control if the operating mode is the level 3 mode when behavior related to the other vehicle's departure is detected during the execution of the avoidance control.

[0310] [Technical Idea 19] A driving system described in any one of Technical Ideas 1 to 18, wherein the processing unit, when the vehicle stops based on determining that the current situation corresponds to the scenario, acquires the vertical length of the empty space in front of the vehicle, and if the vertical length of the empty space is less than a predetermined value, does not start avoidance control, which is control to avoid the other vehicle, but maintains the stopped state until the empty space becomes equal to or greater than the predetermined value, or requests the user of the vehicle to take over driving.

[0311] [Technical Idea 20] The driving system described in any one of Technical Ideas 1 to 19, wherein the processing unit is configured to: estimate an expected stopping time of the other vehicle based on the determination that the current situation corresponds to the scenario; calculate an avoidance time required, which is an expected value of the time required for the host vehicle to avoid the other vehicle and move in front of the other vehicle; and determine whether to execute avoidance control, which is control to avoid the other vehicle and move in front of the other vehicle, based on a result of comparing the expected stopping time with the avoidance time required.

[0312] [Technical Idea 21] A driving system described in any one of Technical Ideas 1 to 20, wherein the signal indicating the external environment includes information about a preceding vehicle, and the processing unit is configured to: determine whether the preceding vehicle is a specific type of vehicle that may stop for passenger embarkation / exit or delivery based on the signal indicating the external environment received by the communication circuit; and, based on determining that the preceding vehicle is the specific type of vehicle, increase the inter-vehicle distance to the preceding vehicle beyond a basic value.

[0313] [Technical Idea 22] A driving system described in any one of Technical Ideas 1 to 21, wherein the signal indicating the external environment includes information about the preceding vehicle, and the processing unit, based on the signal indicating the external environment received by the communication circuit, identifies whether the preceding vehicle is a specific type of vehicle that is likely to stop for passenger embarkation / exit or delivery, obtains an expected stopping point where the preceding vehicle is likely to stop based on the determination that the preceding vehicle is a vehicle of the specific type, and, when the remaining distance to the expected stopping point becomes less than a predetermined value when the vehicle is traveling behind the preceding vehicle of the specific type, increases the inter-vehicle distance from the preceding vehicle to a value greater than a predetermined basic value.

[0314] [Technical Idea 23] A driving system described in any one of Technical Ideas 1 to 22, wherein the signal indicating the external environment includes information regarding a preceding vehicle and a pedestrian, and the processing unit: identifies, based on the signal indicating the external environment received by the communication circuit, whether the preceding vehicle is a specific type of vehicle that is likely to stop to let passengers in or out; obtains an expected stopping point where the preceding vehicle is likely to stop based on the determination that the preceding vehicle is the specific type of vehicle; determines, based on the signal indicating the external environment received using the communication circuit, whether there are pedestrians waiting at the expected stopping point; and, upon determining that there are pedestrians waiting at the expected stopping point, performs a lateral position adjustment to shift the lateral driving position away from the center of the lane in an avoidance direction.

[0315] [Technical Idea 24] The driving system described in any one of Technical Ideas 1 to 23, wherein the processing unit is configured to: start avoidance control, which is control to avoid the other vehicle and go around in front of the other vehicle, based on identifying that the current situation corresponds to the scenario; decide to stop the avoidance control based on detecting a preparatory movement of the other vehicle to start moving after starting the avoidance control; and decide to retry the avoidance control if detecting a movement of the other vehicle to cancel the start moving after deciding to stop the avoidance control.

[0316] [Technical Idea 25] The signal indicating the external environment includes image information indicating the appearance of the other vehicle and sound information outside the vehicle, and the processing unit, when it is determined that the current situation corresponds to the scenario, determines whether the other vehicle is an emergency vehicle based on the image information, detects a warning sound emitted by an emergency vehicle based on the sound information, and if the other vehicle is the emergency vehicle and the warning sound has been detected, does not perform avoidance control, which is control to avoid the other vehicle and go in front of it, but stops the host vehicle behind the other vehicle.

[0317] <Supplementary Note (2)> The various flowcharts shown in this disclosure are all examples, and the number of steps constituting the flowcharts and the execution order of the processes can be changed as appropriate. The controls shown in each flowchart may be combined / executed in parallel to the extent that there is no contradiction. Terms such as acquisition, determination, detection, generation, and calculation may be used interchangeably. The acquisition of certain data by a certain device also includes the device generating the data based on signals input from other devices / sensors. The number of computers included in the driving system 9 and the functions they are responsible for may be changed as appropriate.

[0318] The apparatus, system, and methods described herein may be implemented by a special-purpose computer having a processor programmed to perform one or more functions embodied in a computer program. The apparatus and methods described herein may be implemented using dedicated hardware logic circuits. The apparatus and methods described herein may be implemented by a combination of a processor executing a computer program and one or more hardware logic circuits. The processors (51b, 53b, 55b, 57b) may include at least one of a CPU, an MPU, a GPU, a DFP, and a RISC-CPU as a core. Some or all of the functions of the special-purpose computer described above may be implemented in hardware. Some or all of the functions of the special-purpose computer described in the embodiments may be implemented using at least one of a SoC, an IC (Integrated Circuit), and an FPGA (Field-Programmable Gate Array). The computer program includes instructions executed by a computer. The computer program may be stored in at least one computer-readable non-transitory tangible storage medium, which may be a variety of media such as a hard-disk drive (HDD), a solid-state drive (SSD), or a flash memory.

Claims

1. A driving system configured to be able to control the autonomous driving of a vehicle (1), comprising: a communication circuit (51c) that receives signals indicative of the external environment; and a processing unit (51b, 53b) that executes processing related to the autonomous driving of the vehicle based on the signals received by the communication circuit, wherein the processing unit is configured to: determine, based on the signals received by the communication circuit, whether the current situation corresponds to a scenario in which the vehicle is driving near another stopped vehicle; and, based on the determination that the current situation corresponds to the scenario, determine a response to the other vehicle depending on the type or behavior of the other vehicle.

2. The driving system of claim 1, wherein the processing unit is configured to initiate avoidance control, which is control to avoid the other vehicle, based on determining that the current situation corresponds to the scenario, and, if the processing unit detects the other vehicle starting to move after initiating the avoidance control, to determine whether to continue the avoidance control depending on the position of the vehicle at the time the other vehicle's departure is detected.

3. The driving system of claim 2, wherein the processing unit is configured to: discontinue the avoidance control if the longitudinal distance between the subject vehicle and the other vehicle is equal to or greater than a safe distance when the processing unit detects the departure of the other vehicle; and decide to continue the avoidance control if the longitudinal distance between the subject vehicle and the other vehicle is less than the safe distance when the processing unit detects the departure of the other vehicle.

4. The driving system of claim 1, wherein the processing unit is configured to: initiate avoidance control, which is control to avoid the other vehicle, based on identifying that the current situation corresponds to the scenario; detect the departure of the other vehicle based on information indicating the behavior of the other vehicle; and decide to discontinue the avoidance control if, at the time the departure of the other vehicle is detected, the host vehicle has not crossed the lane mark or if the amount by which the host vehicle crosses the lane mark is less than a predetermined value.

5. The driving system of claim 1, wherein the processing unit is configured to initiate avoidance control, which is control to avoid the other vehicle, based on determining that the current situation corresponds to the scenario, and, if the processing unit detects the other vehicle starting to move after initiating the avoidance control, to determine whether to continue the avoidance control depending on the speed of the subject vehicle at the time the other vehicle's departure is detected.

6. The driving system of claim 1, wherein the processing unit is configured to: initiate avoidance control, which is control to avoid the other vehicle, based on identifying that the current situation corresponds to the scenario; decide to discontinue the avoidance control based on detecting the other vehicle starting after starting the avoidance control; and decide to retry the avoidance control if detecting the other vehicle stopping again after deciding to discontinue the avoidance control.

7. The driving system according to claim 1, wherein the processing unit is configured to monitor the lighting status of the lighting equipment of the other vehicle and predict the departure of the other vehicle based on the monitoring results of the lighting status.

8. The driving system described in claim 1, wherein the processing unit is configured to perform wireless communication with the other vehicle using a wireless communication device, and to predict the departure of the other vehicle based on data received through wireless communication with the other vehicle.

9. A driving system as described in claim 7 or 8, configured to determine not to initiate avoidance control, which is control to avoid the other vehicle, when the departure of the other vehicle is predicted, and to determine to initiate the avoidance control when the departure of the other vehicle is not predicted.

10. The driving system described in claim 1, wherein the processing unit is configured to: based on identifying that the current situation corresponds to the scenario, initiate avoidance control to avoid the other vehicle by going around in front of the other vehicle through an adjacent lane, which is a lane next to the lane blocked by the other vehicle; and change the timing of crossing the boundary line between the lane blocked by the other vehicle and the adjacent lane depending on whether the adjacent lane is traveling in the same direction as the lane blocked by the other vehicle.

11. The processing unit is configured to be able to perform avoidance control to avoid other vehicles, which includes going around in front of the other vehicle through an adjacent lane next to the lane in which the other vehicle is located, and overtaking control to overtake a preceding vehicle that is traveling by changing lanes, and the driving system described in claim 1 is configured such that when the adjacent lane is traveling in the same direction as the lane blocked by the other vehicle, the timing of crossing the boundary line to the adjacent lane in the avoidance control is set to be earlier than the timing of changing lanes in the overtaking control.

12. The driving system of claim 1, wherein the processing unit is configured to initiate avoidance control, which is control to avoid the other vehicle, based on identifying that the current situation corresponds to the scenario, and to create a plan during the avoidance control assuming that there is a vulnerable road user in front of the other vehicle.

13. The driving system described in claim 1 is configured to: obtain whether or not there are other road users in the oncoming lane based on determining that the current situation corresponds to the scenario; decide to initiate avoidance control, which is control to go around in front of the other vehicle through the oncoming lane, based on detecting that the other road users are not present in a specific area on the oncoming lane; and if, after starting the avoidance control, it detects the presence of the other road users in the oncoming lane, decide whether or not to discontinue the avoidance control depending on the type of the other road users.

14. The driving system of claim 1, wherein the processing unit is configured to, if the other vehicle is a school bus, create a plan to stop behind the other vehicle without performing avoidance control, which is control to avoid the other vehicle.

15. The driving system of claim 1, wherein the processing unit is configured to: initiate avoidance control, which is control to avoid the other vehicle, based on identifying that the current situation corresponds to the scenario; monitor the behavior of the other vehicle while the avoidance control is being executed; and, if behavior related to the other vehicle's departure is detected while the avoidance control is being executed, decide to increase the driving speed compared to when behavior related to the other vehicle's departure is not detected.

16. The driving system described in claim 1, wherein the processing unit is configured to determine whether the other vehicle is a bus, and based on the determination that the current situation corresponds to the scenario, initiate avoidance control, which is control to avoid the other vehicle, i.e., the bus, and if behavior related to the other vehicle's departure is detected while the avoidance control is being executed, to stop the avoidance control and increase the set value of the distance from the preceding vehicle by a predetermined amount.

17. A driving system as described in claim 1, comprising a plurality of operating modes with different levels of automation of driving operations, the plurality of operating modes including a level 2 mode which is an operating mode corresponding to the automation level of 2, and a level 3 mode which is an operating mode corresponding to the automation level of 3, wherein the processing unit is configured to: determine that the current situation corresponds to the scenario, and if the operating mode is the level 2 mode, initiate avoidance control, which is control to avoid the other vehicle; and determine that the current situation corresponds to the scenario, and if the operating mode is the level 3 mode, not initiate avoidance control, which is control to avoid the other vehicle.

18. A driving system as described in claim 1, comprising a plurality of operating modes with different levels of automation of driving operations, the plurality of operating modes including a level 2 mode which is an operating mode corresponding to the automation level of 2, and a level 3 mode which is an operating mode corresponding to the automation level of 3, wherein the processing unit is configured to: identify that the current situation corresponds to the scenario, and if the operating mode is the level 2 mode or the level 3 mode, initiate avoidance control, which is control to avoid the other vehicle; monitor the behavior of the other vehicle while the avoidance control is being executed; continue the avoidance control if the operating mode when behavior related to the other vehicle's departure is detected during the execution of the avoidance control is the level 2 mode, while discontinue the avoidance control if the operating mode when behavior related to the other vehicle's departure is detected during the execution of the avoidance control is the level 3 mode.

19. The driving system described in claim 1, wherein the processing unit is configured to, when the vehicle stops based on determining that the current situation corresponds to the scenario, obtain the vertical length of the empty space in front of the vehicle, and if the vertical length of the empty space is less than a predetermined value, not initiate avoidance control to avoid the other vehicle, but maintain the stopped state until the empty space becomes equal to or greater than the predetermined value, or request the user of the vehicle to take over driving.

20. The driving system of claim 1, wherein the processing unit is configured to: estimate an expected stopping time of the other vehicle based on the determination that the current situation corresponds to the scenario; calculate an avoidance time, which is an expected value of the time required for the vehicle to avoid the other vehicle and move in front of the other vehicle; and, based on the result of comparing the expected stopping time with the avoidance time, determine whether or not to execute avoidance control, which is control to avoid the other vehicle and move in front of the other vehicle.

21. The driving system described in claim 1, wherein the signal indicating the external environment includes information about the preceding vehicle, and the processing unit is configured to: determine whether the preceding vehicle is a specific type of vehicle that may stop for passenger embarkation / exit or delivery based on the signal indicating the external environment received by the communication circuit; and, based on determining that the preceding vehicle is a specific type of vehicle, increase the inter-vehicle distance from the preceding vehicle to a value greater than a basic value.

22. The driving system described in claim 1, wherein the signal indicating the external environment includes information about the preceding vehicle, and the processing unit is configured to: determine whether the preceding vehicle is a specific type of vehicle that is likely to stop for passenger embarkation / exit or delivery based on the signal indicating the external environment received by the communication circuit; obtain an expected stopping point where the preceding vehicle is likely to stop based on the determination that the preceding vehicle is a vehicle of the specific type; and when the remaining distance to the expected stopping point becomes less than a predetermined value when the vehicle is traveling behind the preceding vehicle of the specific type, increase the inter-vehicle distance from the preceding vehicle to a value greater than a predetermined basic value.

23. The driving system described in claim 1, wherein the signal indicating the external environment includes information regarding preceding vehicles and pedestrians, and the processing unit, based on the signal indicating the external environment received by the communication circuit, identifies whether the preceding vehicle is a specific type of vehicle that is likely to stop to let passengers in or out, obtains an expected stopping point where the preceding vehicle is likely to stop based on the determination that the preceding vehicle is the specific type of vehicle, determines whether there are pedestrians waiting at the expected stopping point based on the signal indicating the external environment received using the communication circuit, and, upon determining that there are pedestrians waiting at the expected stopping point, performs lateral position adjustment to shift the lateral driving position away from the center of the lane in an avoidance direction.

24. The driving system of claim 1, wherein the processing unit is configured to: initiate avoidance control, which is control to avoid the other vehicle and go around in front of the other vehicle, based on determining that the current situation corresponds to the scenario; decide to cancel the avoidance control based on detecting a preparatory movement of the other vehicle to start moving after starting the avoidance control; and decide to retry the avoidance control if detecting a movement of the other vehicle to cancel the start moving after determining to cancel the avoidance control.

25. The driving system described in claim 1, wherein the signal indicating the external environment includes image information showing the appearance of the other vehicle and sound information outside the vehicle, and the processing unit, when it is determined that the current situation corresponds to the scenario, determines whether the other vehicle is an emergency vehicle based on the image information, detects a warning sound emitted by an emergency vehicle based on the sound information, and, if the other vehicle is the emergency vehicle and the warning sound is detected, does not perform avoidance control, which is control to avoid the other vehicle and go in front of it, but stops the vehicle behind the other vehicle.

26. A method executed by a processor included in a driving system configured to be able to drive a vehicle (1) autonomously, the method comprising: determining whether the current situation corresponds to a scenario in which the vehicle is traveling near another stopped vehicle, based on a signal indicating the external environment received by a communication circuit; and determining a response to the other vehicle depending on the type or behavior of the other vehicle, based on the determination that the current situation corresponds to the scenario.

Citation Information

Patent Citations

  • Vehicle type discrimination device

    JP2009075638A

  • Driving support device, computer program, and driving support method

    JP2016139192A

  • Driving support device for vehicle

    JP2018106749A

  • Information processing apparatus and program

    JP2018142297A

  • Electronic device, vehicle, information provision system, method for providing information, and program

    JP2020201199A