System and procedure for controlling a motor vehicle for autonomous driving

The system facilitates the integration of new functions in autonomous vehicles by using safety policies and boundary conditions to generate control signals, addressing the high cost and complexity of updates in autonomous driving systems.

DE112018005796B4Active Publication Date: 2026-02-26SCANIA CV AB
View PDF 6 Cites 0 Cited by

Patent Information

Application Number
DE112018005796
Authority / Receiving Office
DE · DE
Patent Type
Patents
Current Assignee / Owner
Priority Date
2017-12-20
Filing Date
2018-12-07
Publication Date
2026-02-26
Estimated Expiration
2038-12-07

AI Technical Summary

Technical Problem

The integration of new and/or updated functionality into autonomous driving systems is costly and time-consuming due to stringent safety regulations, necessitating extensive testing and requalification of vehicle control units.

Method used

A system comprising a bank of control units, a monitoring unit, and a data interface unit, which generates target control signals based on safety policies and boundary conditions to ensure safe operation, allowing for updates without requalifying vehicle control units.

Benefits of technology

Enables efficient addition and updating of functionalities in autonomous vehicles by defining safety-critical aspects through safety guidelines, reducing costs and effort, and ensuring safe operation even in emergency situations.

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure 00000000_0000_ABST
    Figure 00000000_0000_ABST
Patent Text Reader

Abstract

System for controlling a motor vehicle (MV) for autonomous driving, wherein the system comprises: a bank of control units (110) comprising a number of vehicle control units (ACU1, ..., ACUn) configured to generate target control signals (NCS) configured to cause the motor vehicle (MV) to move autonomously in accordance with a target path; and a monitoring unit (160) configured to receive sensor signals (SS) from the motor vehicle (MV) describing a current state of the motor vehicle (MV) and to generate commands ({cmd}) based on the control signals (SS) that influence how the bank of control units (110) generates the target control signals (NCS), characterized by the fact that the system further comprises: a data storage (140) comprising a set of boundary conditions ({bc}) that the target path must satisfy to be considered safe; and a first data interface unit (163) configured to provide at least one safety policy (P) describing an associated task-related rule to be followed during the operation of the motor vehicle (MV), wherein the first data interface unit (163) is configured to provide at least one safety policy (P) based on a safety event (SC) that prescribes how the motor vehicle (MV) should be controlled in order to meet a functional safety standard, wherein the monitoring unit (160) is configured to repeatedly generate the commands ({cmd}) to update the boundary conditions ({bc}), aiming to keep the target path within limits specified by the sensor signals (SS) and at least one safety policy (P), and wherein the bank of control units (110) is configured to: to read the set of boundary conditions ({bc}) from the data storage (140), and to control the motor vehicle (MV) to move in such a way that the desired path satisfies the boundary conditions ({bc}).
Need to check novelty before this filing date? Find Prior Art

Description

Technical field

[0001] The invention relates generally to autonomous vehicles. In particular, the present invention relates to a system for controlling a motor vehicle for autonomous driving in accordance with a target path and a corresponding method. The invention also relates to a computer program and a non-volatile data carrier. background

[0002] Today, there is a clear trend toward fully autonomous vehicles. Naturally, safety aspects are paramount, as no human driver is involved. Functional safety standards, such as ISO 26262, require the diagnostic functionality necessary for safety. Generally, these standards place a significant additional burden on diagnosing and safely handling functional faults. Furthermore, verifying the verifiability of functional safety is a very complex process. Typically, this additional effort increases considerably with the growing number and complexity of functions. As a result, autonomous driving and its associated functions currently represent one of the greatest challenges in terms of complexity in the automotive sector.

[0003] US 2017 / 0277194A1 describes how operational control of a vehicle can be facilitated. A limited set of candidate trajectories of the vehicle is generated, originating from the vehicle's location at a specific time. The candidate trajectories are based on the vehicle's state and possible behaviors of the vehicle and its environment with respect to the vehicle's location and the specified time. A supposedly optimal trajectory is selected from the candidate trajectories based on costs associated with them. These costs include those associated with violations of the vehicle's operating rules. The selected supposedly optimal trajectory is then used to facilitate operational control of the vehicle.

[0004] EP 2 317 412 A1 discloses a safety management system for equipment configured to operate autonomously in a real-time environment. Deterministic and non-deterministic processors are provided to process incoming alarms and generate control signals in response. The non-deterministic processor can handle untrained, complex, and unpredictable situations by essentially providing open-ended operations that operate in large search spaces without a guaranteed solution. The deterministic processor monitors the behavior of the non-deterministic processor and validates its control signals against safety policies. The deterministic processor also provides an intelligent interface to the non-deterministic processor, receiving alarms only from the deterministic processor and ensuring time-critical delivery of responses.

[0005] US 2015 / 0057869A1 discloses devices, methods, and a storage medium related to computer-assisted or autonomous driving of vehicles. A computing device can receive multiple data points related to vehicles driving at different locations within a site; and, based on these, generate one or more site-specific guidelines for computer-assisted or autonomous driving of vehicles at that location.

[0006] DE 11 2013 001 449 T5 describes a processor-based control system for self-driving vehicles with a hierarchical control architecture on several levels. Each controlled direction of movement includes its own main controller, which monitors local actuators and coordinates their interaction. At higher levels, the driver's reliability is also evaluated and integrated into the control system.

[0007] WO 2015 / 076736 A1 discloses a system, a method, and a vehicle for realizing autonomous driving operation. The system has a multi-layered architecture. In a first layer, environmental conditions are detected and control signals are generated from them, which are then adapted for further processing in a second layer. A standardized computer interface transmits these signals across layers, so that the system can be used independently of the individual layers.

[0008] US 2017 / 0197626A1 describes a computer system programmed by software, firmware, hardware, or a combination thereof for specific driving functions. It detects a first vehicle in a lane, plans its path to join a queue, and then changes lanes to an adjacent lane. The vehicle is controlled based on the calculated path, taking into account vehicle-specific characteristics and the path of a second vehicle.

[0009] Therefore, there are known examples of solutions for controlling motor vehicles for autonomous driving in accordance with certain rules and guidelines, while handling complex and unpredictable traffic situations.

[0010] Naturally, safety regulations for autonomous vehicles are very strict. For example, the software that implements autonomous driving functionality must undergo extensive testing before it is approved. Consequently, integrating any new and / or updated functionality into an autonomous vehicle is costly and very time-consuming. Summary

[0011] It is therefore an object of the present invention to facilitate the updating of existing functions in an autonomous driving system. Furthermore, it is an object of the invention to simplify the process of adding new functions to such a system.

[0012] According to one aspect of the invention, these problems are solved by a system for controlling a motor vehicle for autonomous driving, wherein the system comprises: a bank of control units, a monitoring unit, a data storage unit, and a first data interface unit. The bank of control units includes a number of vehicle control units (i.e., one or more) configured to generate target control signals that cause the motor vehicle to move autonomously in accordance with a target path. The data storage unit contains a set of boundary conditions that the target path must satisfy to be considered safe. The monitoring unit is configured to receive sensor signals from the motor vehicle, wherein the sensor signals describe a current state of the motor vehicle.The monitoring unit is configured to generate commands based on the control signals, which influence how the bank of control units generates the target control signals. More precisely, the monitoring unit is configured to repeatedly generate the commands to update the boundary conditions, aiming to keep the target path within limits defined by the sensor signals and at least one safety policy. The first data interface unit is configured to provide at least one safety policy that describes an associated task-related rule to be followed during the operation of the vehicle.Specifically, the first data interface unit is configured to provide at least one safety guideline based on a safety scenario, which dictates how the vehicle should be controlled to meet a functional safety standard. The bank of control units is configured to read the set of boundary conditions from the data memory and control the vehicle to move in such a way that the target path fulfills the boundary conditions.

[0013] This system is advantageous because the proposed link between safety guidelines and safety scenarios allows essential safety-critical aspects of the design to be defined using the safety guidelines. Therefore, functionality can be added and / or updated without requiring a requalification of the vehicle control units themselves. This is naturally advantageous in terms of both cost and effort.

[0014] According to embodiments of this aspect of the invention, the safety case prescribes a set of operating modes in which the motor vehicle is to be controlled in order to be controlled depending on a current fault condition of the motor vehicle.The set of operating modes may include, for example: a first operating mode in which the vehicle should be controlled if the current fault condition is such that the vehicle's performance is unaffected; a second operating mode in which the vehicle should be controlled if the current fault condition is such that the vehicle's performance is limited; a third operating mode in which the vehicle should be controlled if the current fault condition requires the vehicle to be brought into a state of minimal risk; and a fourth operating mode representing the state of minimal risk. Therefore, safe operation of the vehicle can be ensured based on clear and concise principles.

[0015] According to a further embodiment of this aspect of the invention, the at least one safety guideline relates to: a minimum distance that the motor vehicle should maintain from a following vehicle, a speed limit that the motor vehicle should adhere to, definitions of safe stopping points that the motor vehicle should be able to reach in the event of a fault in the motor vehicle (for example, a number of safe stopping points that should always be reachable, as well as a corresponding quality thereof), and a set of measures to be taken in the event that one or more sets of faults occur in the motor vehicle. This makes the design very efficient, particularly with regard to future updates and developments.

[0016] According to other embodiments of this aspect of the invention, the monitoring unit comprises a system state monitoring unit and a safety unit. The system state monitoring unit is configured to receive sensor signals and, based on these, derive vehicle state data representing a functional state of the motor vehicle. The safety unit is configured to receive the vehicle state data and at least one safety directive and, based on these, to generate commands for the data storage.

[0017] Additionally, the monitoring unit can include a second data interface unit configured to receive and store at least one regulatory requirement that must be met during vehicle operation. The safety unit is configured to receive this regulatory requirement and, based on it, generate commands for the safety unit. This makes it easy to ensure that the system meets various regulatory requirements, such as compliance with specific traffic regulations.

[0018] Additionally, the monitoring unit can include a risk assessment unit configured to dynamically evaluate the estimated risk of the vehicle colliding with any other road user and / or obstacle in its vicinity, with the estimated risk being expressed by at least one signal. The safety unit is configured to receive this signal and generate commands based on it. The result is an ingeniously implemented collision avoidance functionality.

[0019] According to yet another embodiment of this aspect of the invention, the risk assessment unit is further configured to monitor the vehicle's environment in order to determine whether the vehicle is currently operating within a range of parameters within which it is designed to operate. The at least one signal further indicates whether the vehicle is currently operating within this range of parameters or not. Therefore, appropriate action can be taken immediately if it is determined that the vehicle is operating outside this range.

[0020] According to yet another embodiment of this aspect of the invention, the risk assessment unit is further configured to determine an estimated risk that the motor vehicle and / or any other road user in its vicinity will violate a traffic rule. In this context, at least one signal indicates this estimated risk. This allows the vehicle control system, implemented by the vehicle control units, to be adjusted in such a way as to reduce the overall risk of traffic violations.

[0021] According to one embodiment of this aspect of the invention, the safety unit is further configured to determine whether at least one received safety-relevant parameter describes at least one state in which the motor vehicle is currently being operated, wherein the at least one state is such that the risk that the motor vehicle cannot move autonomously in accordance with the intended path exceeds a fault risk threshold. The safety unit is configured, when the fault risk threshold is exceeded, to generate safety control signals that are designed to cause the motor vehicle to move autonomously in accordance with a safe path. The safe path takes precedence over the intended path, which is represented by the intended control signals.In other words, the vehicle is designed to ignore any received target control signals if the safety control signals are present. Consequently, safe vehicle handling is ensured even in emergency situations.

[0022] Alternatively or additionally, the safety unit can be configured to generate a control signal indicating whether the failure risk threshold has been exceeded. Furthermore, the system includes a control switch connected to the bank of control units. The control switch is connected to both the bank of control units and the safety unit, and the safety switch is configured to: receive the control signal; receive the target control signals or any safety control signals; and, in response to the control signals, forward either the target control signals or the safety control signals to the vehicle. In such a case, the vehicle itself does not need to take any action to ensure that a safe path is preferred over the target path.

[0023] According to further embodiments of this aspect of the invention, either each of the vehicle control units is configured to generate a set of target control signals designed to cause the vehicle to move autonomously in accordance with a corresponding target path; or two or more of the vehicle control units are configured to generate a common set of target control signals designed to cause the vehicle to move autonomously in accordance with the target path. This results in a high degree of freedom regarding the implementation of the system.

[0024] According to yet another embodiment of this aspect of the invention, the system comprises a platform interface configured to receive sensor signals from the motor vehicle and to send target control signals to the motor vehicle. Therefore, communication between the system and the motor vehicle can be designed to be efficient and flexible.

[0025] According to a further aspect of the invention, the above-mentioned problems are solved by a method for controlling a motor vehicle for autonomous driving. The method comprises generating target control signals by means of a bank of control units, which includes a number of vehicle control units. The target control signals are configured to cause the motor vehicle to move autonomously in accordance with a target path. The method also comprises receiving sensor signals from the motor vehicle in a monitoring unit. The sensor signals describe the current state of the motor vehicle.The procedure additionally comprises: storing, in a data memory, a set of boundary conditions that the target path must satisfy to be considered safe; and providing, via a first data interface unit, at least one safety policy that describes an associated task-related rule to be followed during the operation of the motor vehicle. The at least one safety policy is provided based on a safety event that prescribes how the motor vehicle should be controlled to meet a functional safety standard. The procedure further comprises generating, in the monitoring unit, commands based on the control signals, these commands influencing how the bank of control units generates the target control signals.Specifically, the commands are repeatedly generated to update the boundary conditions, with the aim of keeping the target path within limits defined by the sensor signals and at least one safety guideline (P). Furthermore, the method comprises: reading the set of boundary conditions from the data storage into the bank of control units, and controlling the vehicle to move in such a way that the target path satisfies the boundary conditions. The advantages of this method, as well as its preferred embodiments, will become apparent from the above description with reference to the proposed system.

[0026] According to another aspect of the invention, the problems are solved by a computer program comprising instructions which, when executed in at least one processor, cause the at least one processor to execute the method described above.

[0027] According to another aspect of the invention, the problems are solved by a non-volatile data carrier containing such a computer program.

[0028] Further advantages, beneficial features and applications of the present invention will become apparent from the following description and the dependent claims. Brief description of the drawings

[0029] The invention will now be described in more detail by means of preferred embodiments, which are disclosed as examples and with reference to the accompanying drawings. Fig. 1 schematically represents a system according to embodiments of the invention; Fig. Figure 2 schematically represents a system according to a further embodiment of the invention; and Fig. Figure 3 presents a general method according to the invention by means of a flowchart. Detailed description

[0030] With reference to Fig. 1. We will describe a system according to an embodiment of the invention for controlling a motor vehicle MV for autonomous driving. The system comprises a bank of control units 110, a monitoring unit 160, a data storage unit 140, and a first data interface unit 163.

[0031] The bank of control units 110, comprising one or more vehicle control units ACU1, ..., ACUn, is configured to generate target control signals NCS, which are configured to cause the motor vehicle MV to move autonomously in accordance with a target path. Each of the vehicle control units is configured to generate a set of target control signals NCS, wherein the set of target control signals NCS is configured to cause the motor vehicle MV to move autonomously in accordance with a target path; or two or more of the vehicle control units ACU1, ..., ACUn are configured to generate a common set of target control signals NCS, wherein the common set of target control signals NCS is configured to cause the motor vehicle MV to move autonomously in accordance with the target path.For example, one of the vehicle control units (VCUs) can be configured to control the vehicle MV longitudinally, while another VCU is configured to control it laterally. Alternatively, a first VCU (ACU1) can implement a highway pilot, a second VCU can implement a traffic jam pilot, a third VCU can implement a vehicle towing pilot, and so on, up to an nth VCU, which, for example, can be configured to operate the vehicle in a mining environment. Although the VCUs ACU1, ..., ACUn can, of course, be implemented in hardware, it is advantageous if they are implemented in software.In such a case, either a specific software module can be present for each automotive control unit in the bank of control units 110, or the entire bank of control units 110 can be represented by a common software.

[0032] In any case, the bank of control units 110 is set up to read a set of boundary conditions {bc} from the data storage 140 and to control the motor vehicle MV to move in such a way that the target path satisfies the boundary conditions {bc}.

[0033] Data storage 140 contains the set of boundary conditions {bc} that the target path must fulfill in order to be considered safe.

[0034] The first data interface unit 163 is configured to provide at least one safety policy P, which describes an associated task-related rule to be followed during the operation of the motor vehicle MV. Specifically, the at least one safety policy P provided by the first data interface unit 163 is based on a safety case SC, which prescribes how the motor vehicle MV should be controlled to meet a functional safety standard, such as ISO 26262. This link between the safety policy P and the safety case SC makes it possible to define essential safety-critical parts of the design via the safety policy P. Consequently, functionality can be added to the system, and / or the system can be updated, without requalifying the vehicle control units ACU1, ..., ACUn as such with regard to safety compliance.

[0035] The safety guidelines P of the first data interface unit 163 may relate to: a minimum distance that the vehicle MV should maintain from a following vehicle (for example, while driving in a vehicle combination); a speed limit that the vehicle MV should adhere to; a set of measures to be taken in the event that one or more sets of faults occur in the vehicle MV; and / or definitions of safe stopping points that the vehicle MV should be able to reach in the event of a fault. The safe stopping points may, in turn, be further defined with regard to quantity and quality, such as a minimum number of safe stopping points that the vehicle MV can reach at all times, as well as where the safe stopping points should be located relative to the current position of the vehicle.For example, 1 to 20 safe stopping points may be required, where the first set may be located in the same lane, the second set in the rightmost lane, the third on the shoulder of the road, the fourth in a rest area on a highway, a fifth at a predetermined stopping point at an nth highway exit, a sixth at a designated repair shop, and a seventh destination on a route being followed. Maximum and / or minimum time times for reaching a safe stopping point may also be specified by the safety guideline P.Obviously, considering other road users, the shortest possible travel time to a safe stopping point is not always ideal. Typically, a strategy that balances the safety interests of multiple road users is optimal.

[0036] The monitoring unit 160 is configured to receive sensor signals SS from the motor vehicle MV. The sensor signals SS describe the current state of the motor vehicle. The sensor signals SS can be received from the motor vehicle MV via a platform interface 130. Preferably, such a platform interface 130 is bidirectional and therefore also configured to send the target control signals NCS to the motor vehicle MV. However, according to the invention, even when the platform interface 130 is included in this configuration, one or more sensor signals SS can be received via alternative channels, and / or one or more of the target control signals NCS can be transmitted to the motor vehicle MV in a manner other than via the platform interface 130.

[0037] The monitoring unit 160 is configured to generate commands {cmd} based on the sensor signals SS, whereby the commands {cmd} influence how the bank of control units 110 generates the target control signals NCS. More precisely, the monitoring unit 160 is configured to repeatedly generate the commands {cmd} to update the boundary conditions {bc}, with the aim of keeping the target path within limits specified by the sensor signals SS and at least one safety policy P.

[0038] According to one embodiment of the invention, safety case SC also prescribes a set of operating modes in which the motor vehicle MV is to be controlled in order to be controlled depending on a current fault condition of the motor vehicle MV.

[0039] For example, the set of operating modes can include a first, second, third, and fourth operating mode. In this case, the vehicle MV can be controlled to operate in the first operating mode if the current fault status is such that the vehicle MV's performance is unaffected. Minor faults may be present, but these do not affect the vehicle MV's performance. If the current fault status of the vehicle is such that the vehicle MV's performance is impaired but not critical, the vehicle can be controlled to operate in the second operating mode. Conversely, if the current fault status of the vehicle MV is such that the vehicle MV must be brought into a state of minimal risk, the vehicle can be controlled to operate in the third operating mode.The fourth operating mode can represent the state of minimal risk, in which the vehicle MV, for example, should not be driven at all.

[0040] Fig. Figure 2 schematically shows a system according to other embodiments of the invention. Here, all units, signals, commands, and parameters, which also appear in [other embodiments], are denoted by [the relevant terminology]. Fig. 1. The same units, signals, commands, and parameters are present, as mentioned above with reference to Fig. 1 were described.

[0041] According to one of the embodiments of the invention, which is described in Fig. As illustrated in Figure 2, the monitoring unit 160 comprises a system state monitoring unit 150 and a safety unit 120. The system state monitoring unit 150 is configured to receive the sensor signals SS and, based on these, to derive vehicle state data H, which represent a functional state of the motor vehicle MV. The safety unit 120 is configured to receive the vehicle state data H and at least one safety policy P and, based on these, to generate the commands {cmd} to the data storage 140.

[0042] According to a further embodiment of the invention, the monitoring unit further comprises a second data interface unit 165, which is configured to receive and store at least one regulatory requirement R that must be fulfilled during operation of the motor vehicle MV. The safety unit 120 is configured to receive the at least one regulatory requirement R and additionally to generate the commands {cmd} based on the at least one regulatory requirement R to the safety unit 120. Market-specific regulations listed at the start of a journey (for example, right-hand / left-hand traffic, local road regulations, and various traffic signs) are examples of regulatory requirements R.

[0043] Analogous to the first data interface unit 163, the second data interface unit 165 is communicatively connected to the security unit 120 in order to provide the at least one regulatory requirement R for the security unit 120 and thus enable the security unit 120 to generate the at least one command {cmd} based on the at least one regulatory requirement R.

[0044] According to one embodiment of the invention, the monitoring unit 160 comprises a risk assessment unit 167, which is configured to dynamically assess the respective estimated risk that the motor vehicle MV will collide with any other road user and / or obstacle located near the motor vehicle MV. The respective estimated risk can be indicated by at least one signal S jThis must be expressed. The safety unit 120 is configured to ensure that at least one signal S j to obtain and execute the commands {cmd} additionally based on at least one signal S j to generate. The assessment may include monitoring of lane markings, and if no sufficiently clear lane markings are found, this provides at least a signal S. j this is expressed in the form of an estimated risk of a traffic violation.

[0045] The risk assessment unit 167 can also be configured to monitor the environment of the motor vehicle MV in order to determine whether the motor vehicle MV is currently operating within a range of parameters under which it is designed to operate. In this context, it provides at least one signal S. j furthermore, it indicates whether the vehicle MV is currently operating within the range of parameters or not.

[0046] According to one embodiment of the invention, the safety unit 120 is further configured to determine whether the set of safety-relevant parameters P, R, S j , H describes one or more states in which the motor vehicle MV is currently operated, wherein the state(s) is / are such that the risk that the motor vehicle MV cannot move autonomously in accordance with the target path exceeds a failure risk threshold.

[0047] If the failure risk threshold is exceeded, the safety unit 120 is configured to generate safety control signals (SCS) that cause the vehicle (MV) to move autonomously along a safe path. The safe path represents an alternative to the target path, and the safe path should be followed instead of the target path calculated by the bank of control units 110. In other words, the safe path takes precedence over the target path, which is represented by the target control signals (NCS).

[0048] According to one embodiment, which is in Fig. As shown in Figure 1, the motor vehicle MV itself achieves this priority by being configured to ignore any received target control signals NCS if the safety control signals SCS are received, for example via the platform interface 130, as shown in Figure 1. Fig. Figure 1 is shown. Consequently, safe vehicle handling is guaranteed even in emergencies.

[0049] Fig. Figure 2 schematically shows a system according to a further embodiment of the invention. Here, all units, signals, commands, and parameters, which also appear in [the original text], are denoted by . Fig. 1. The same units, signals, commands, and parameters are present, as mentioned above with reference to Fig. 1 were described.

[0050] In the Fig. In the illustrated system 2, the safety unit 120 is configured to generate a control signal Ctrl, which indicates whether the fault risk threshold has been exceeded or not.

[0051] The system also includes a control switch 210, which is arranged in communication link with the bank of control units 110 and the safety unit 120. The control switch 210 is configured to: receive the control signal Ctrl; receive the target control signals NCS or any safety control signals SCS.

[0052] Control switch 210 is configured to forward either the target control signals NCS or the safety control signals SCS to the vehicle MV. Specifically, when safety unit 120 generates the safety control signals SCS, it also generates the control signals Ctrl in such a way that, upon receiving these signals at control switch 210, control switch 210 prevents the target control signals NCS from being forwarded to the vehicle MV. Instead, the control signal Ctrl forwards the safety control signals SCS to the vehicle MV. This reduces the demands on the vehicle MV, as it does not have to choose between the target control signals NCS and the safety control signals SCS; and, analogous to the above, ensures safe handling of the vehicle even in emergencies.

[0053] Analogous to the automotive control units ACU1, ..., ACUn, the safety unit 120, the system status monitoring unit 150, the first data interface 163, the second data interface 165, the risk assessment unit 167, and / or the control switch 210 can be implemented partially or completely as software. Such software can, in turn, be installed to run on one or more processors. Furthermore, a single software application can implement two or more of the aforementioned units and interfaces.

[0054] For example, the security unit 120 can comprise a processing unit with processing means containing at least one processor, such as one or more general-purpose processors. Furthermore, the processing unit is preferably communicatively connected to a data carrier 125 in the form of a computer-readable medium, such as random access memory (RAM), flash memory, or the like. The data carrier 125 contains computer-executable instructions, i.e., a computer program 127, for causing the processing unit and the other units of the system to operate in accordance with the embodiments of the invention as described herein, when the computer-executable instructions are executed on the at least one processor of the processing unit.

[0055] To summarize this and with reference to the flowchart in Fig. 3. We will now describe the general method according to the invention for controlling a motor vehicle for autonomous driving.

[0056] In a first step, sensor signals are received from the motor vehicle. The sensor signals describe the current state of the motor vehicle.

[0057] Then, in step 320, a set of boundary conditions is read from a data memory. In a subsequent step 330, at least one command is generated based on the sensor signals.

[0058] In step 340, which follows step 330, target control signals are generated under the influence of at least one command. These target control signals are configured to cause the vehicle to move autonomously along a target path that satisfies the set of boundary conditions and is therefore considered safe. Subsequently, in step 350, the target control signals are sent to the vehicle to control it to move along the target path.

[0059] In a subsequent step (360), the boundary conditions are updated, aiming to keep the target path within limits defined by the sensor signals and at least one safety policy. This safety policy describes an associated task-related rule to be followed during vehicle operation. This safety policy, in turn, is provided based on a safety scenario that dictates how the vehicle should be controlled to meet a functional safety standard.

[0060] In step 370, the updated set of boundary conditions is stored in the data store, and then the process returns to step 310.

[0061] Although the method according to the invention is carried out in a general sequential order, as described in Fig. As shown in Figure 3, it should of course be mentioned that a subsequent step of the process can be initiated before a preceding step is completed. In fact, essentially all steps are active throughout. For example, sensor signals are preferably obtained in step 310 with respect to a specific time interval, while in step 360 the boundary conditions are updated in connection with a set of safety-related parameters that refer to a time interval prior to the specified time interval, and so on.

[0062] All of the procedural steps, as well as any subsequent steps relating to Fig.The devices described in section 3 above can be controlled by means of at least one programmed processor. Furthermore, the invention therefore also extends to computer programs, in particular computer programs on or in a carrier, which are configured to implement the invention practically, although the embodiments of the invention described above with reference to the drawings comprise a processor and operations that are carried out in at least one processor. The program can be in the form of source code, object code, code between source code and object code such as partially compiled form, or in any other form suitable for use in implementing the method according to the invention. The program can be either part of an operating system or a separate application. The carrier can be any unit or device suitable for containing the program.For example, the carrier can be a storage medium such as flash memory, a ROM (Read Only Memory), for example a DVD (Digital Video / Versatile Disc), a CD (Compact Disc), or a semiconductor ROM, an EPROM (Erasable Programmable Read-Only Memory), an EEPROM (Electrically Erasable Programmable Read-Only Memory), or a magnetic recording medium, such as a floppy disk or a hard disk. Furthermore, the carrier can be a transmittable medium, such as an electrical or optical signal that can be transmitted via an electrical or optical cable, by radio, or by other means. If the program is implemented in a signal that can be transmitted directly via a cable or other means, the carrier can be formed by such a cable, device, or means.Alternatively, the carrier can be an integrated circuit in which the program is embedded, the integrated circuit being configured to perform the relevant operations or to be used in carrying them out.

[0063] When the term "include / comprehensive" is used in this description, it should be understood to indicate the presence of the specified characteristics, quantities, steps, or components. However, the term should not exclude the presence or addition of one or more further characteristics, quantities, steps, or components, or groups thereof.

[0064] The invention is not limited to the embodiments described in the figures, but can be freely varied within the scope of the claims.

Claims

[1] System for controlling a motor vehicle (MV) for autonomous driving, the system comprising: a bank of control units (110) comprising a number of vehicle control units (ACU1, ..., ACUn) configured to generate target control signals (NCS) configured to cause the motor vehicle (MV) to move autonomously in accordance with a target path; and a monitoring unit (160) configured to receive sensor signals (SS) from the motor vehicle (MV) describing a current state of the motor vehicle (MV) and to generate commands ({cmd}) based on the control signals (SS) that influence how the bank of control units (110) generates the target control signals (NCS), characterized by , that the system further includes: a data storage (140) comprising a set of boundary conditions ({bc}) that the target path must satisfy to be considered safe; and a first data interface unit (163) configured to provide at least one safety policy (P) describing an associated task-related rule to be followed during the operation of the motor vehicle (MV), wherein the first data interface unit (163) is configured to provide at least one safety policy (P) based on a safety event (SC) that prescribes how the motor vehicle (MV) should be controlled in order to meet a functional safety standard, wherein the monitoring unit (160) is configured to repeatedly generate the commands ({cmd}) to update the boundary conditions ({bc}), aiming to keep the target path within limits specified by the sensor signals (SS) and at least one safety policy (P), and wherein the bank of control units (110) is configured to: to read the set of boundary conditions ({bc}) from the data storage (140), and to control the motor vehicle (MV) to move in such a way that the desired path satisfies the boundary conditions ({bc}). [2] System according to claim 1, wherein the safety case (SC) prescribes a set of operating modes in which the motor vehicle (MV) is to be controlled in order to be controlled depending on a current fault state of the motor vehicle (MV). [3] System according to claim 2, wherein the set of operating modes comprises at least one of the following: to operate in a first operating mode in which the motor vehicle (MV) is to be controlled, if the current fault status is such that the performance of the motor vehicle (MV) is unaffected; a second operating mode in which the motor vehicle (MV) is to be controlled, if the current fault condition is such that the performance of the motor vehicle (MV) is limited; a third operating mode in which the motor vehicle (MV) is to be controlled, if the current fault condition is such that the motor vehicle (MV) must be placed in a state of minimal risk; and a fourth operating mode, which represents the state of minimal risk. [4] System according to any of the preceding claims, wherein the at least one security policy (P) relates to one of the following: a minimum distance that the motor vehicle (MV) should maintain to a following vehicle, a speed limit that the motor vehicle (MV) is supposed to adhere to, Definitions of safe stopping points that the motor vehicle (MV) should be able to reach in the event of a fault in the motor vehicle (MV), and a set of measures to be taken in the event that one or more sets of faults occur in the motor vehicle (MV). [5] System according to any of the preceding claims, wherein the monitoring unit (160) comprises: a system condition monitoring unit (150) which is configured to receive the sensor signals (SS) and, based on these, to derive vehicle condition data (H) which represent a functional state of the motor vehicle (MV), and a safety unit (120) which is configured to obtain the vehicle status data (H) and at least one safety policy (P) and, based on this, to generate the commands ({cmd}) to the data storage device (140). [6] System according to claim 5, wherein the monitoring unit (160) further comprises: a second data interface unit (165) configured to receive and store at least one regulatory requirement (R) to be met during operation of the motor vehicle (MV), and wherein the safety unit (120) is configured to receive the at least one regulatory requirement (R) and additionally generate the commands ({cmd}) to the safety unit (120) based on the at least one regulatory requirement (R). [7] System according to one of claims 5 or 6, wherein the monitoring unit (160) further comprises: a risk assessment unit (167) configured to dynamically assess each estimated risk that the motor vehicle (MV) will collide with any other road user and / or obstacle in the vicinity of the motor vehicle (MV), wherein the respective estimated risk is indicated by at least one signal (S j) is expressed, and wherein the safety unit (120) is configured to detect at least one signal (S j ) to obtain and additionally execute the commands ({cmd}) based on at least one signal (S j to generate. [8] System according to claim 7, wherein the risk assessment unit (167) is further configured to monitor an environment of the motor vehicle (MV) in order to determine whether the motor vehicle (MV) is currently operating within a range of parameters under which it is designed to operate, and wherein the at least one signal (S j ) further indicates whether the motor vehicle (MV) is currently operating within the range of parameters or not. [9] System according to one of claims 7 or 8, wherein the risk assessment unit (167) is further configured to determine an estimated risk that the motor vehicle (MV) and / or any other road user in its vicinity will violate a traffic rule, and wherein the at least one signal (S j ) furthermore, this estimated risk is stated. [10] System according to any one of claims 5 to 9, wherein the safety unit (120) is further configured to: to determine whether at least one received safety-relevant parameter (P, R, S) j , H) describes at least one state in which the motor vehicle (MV) is currently operated, wherein the at least one state is such that the risk that the motor vehicle (MV) cannot be moved autonomously in accordance with the intended path exceeds a failure risk threshold, and furthermore, when the failure risk threshold is exceeded, To generate safety control signals (SCS) designed to cause the motor vehicle (MV) to move autonomously in accordance with a safe path, the safe path taking precedence over the desired path represented by the desired control signals (NCS). [11] System according to claim 10, wherein the safety unit (120) is configured to generate a control signal (Ctrl) indicating whether the fault risk threshold has been exceeded or not, and wherein the system further comprises a control switch (210) arranged in communication link with the bank of control units (110) and the safety unit (120), wherein the control switch (210) is configured to: to receive the control signal (Ctrl), to obtain the target control signals (NCS) or any safety control signals (SCS), and In response to the control signals (Ctrl), either the target control signals (NCS) or the safety control signals (SCS) are forwarded to the motor vehicle (MV). [12] System according to any of the preceding claims, wherein each of the vehicle control units (ACU1, ..., ACUn) is configured to generate a set of target control signals (NCS), wherein the set of target control signals (NCS) is configured to cause the motor vehicle (MV) to move autonomously in accordance with a corresponding target path. [13] System according to any one of claims 1 to 11, wherein two or more of the vehicle control units (ACU1, ..., ACUn) are configured to generate a common set of target control signals (NCS), wherein the common set of target control signals (NCS) is configured to cause the motor vehicle (MV) to move autonomously in accordance with the target path. [14] System according to one of the preceding claims, further comprising a platform interface (130) configured to: to receive the sensor signals (SS) from the motor vehicle (MV); and to send the target control signals (NCS) to the motor vehicle (MV). [15] Method for controlling a motor vehicle (MV) for autonomous driving, the method comprising: Generating, by means of a bank of control units (110) comprising a number of vehicle control units (ACU1, ..., ACUn), target control signals (NCS) configured to cause the motor vehicle (MV) to move autonomously in accordance with a target path; and Received, in a monitoring unit (160), from sensor signals (SS) from the motor vehicle (MV) describing a current state of the motor vehicle (MV), and based on the control signals (SS) Generating, in the monitoring unit (160), commands ({cmd}) that influence how the bank of control units (110) generates the target control signals (NCS), characterized by : Store, in a data store (140), a set of boundary conditions ({bc}) that the target path must satisfy in order to be considered safe; and Providing, by means of a first data interface unit (163), at least one safety policy (P) which describes an associated task-related rule to be followed during the operation of the motor vehicle (MV), wherein the at least one safety policy (P) is provided on the basis of a safety event (SC) which prescribes how the motor vehicle (MV) should be controlled in order to meet a functional safety standard, wherein the commands ({cmd}) are repeatedly generated to update the boundary conditions ({bc}), aiming to keep the desired path within limits specified by the sensor signals (SS) and at least one safety policy (P), and wherein the method further comprises: Reading the set of boundary conditions ({bc}) from the data storage (140) into the bank of control units (110), and Controlling the motor vehicle (MV) to move in such a way that the desired path satisfies the boundary conditions ({bc}). [16] Method according to claim 15, wherein the safety case (SC) prescribes a set of operating modes in which the motor vehicle (MV) is to be controlled in order to be controlled depending on a current fault state of the motor vehicle (MV). [17] Method according to claim 16, wherein the set of operating modes comprises at least one of the following: to operate in a first operating mode in which the motor vehicle (MV) is to be controlled, if the current fault status is such that the performance of the motor vehicle (MV) is unaffected; a second operating mode in which the motor vehicle (MV) is to be controlled, if the current fault condition is such that the performance of the motor vehicle (MV) is limited; a third operating mode in which the motor vehicle (MV) is to be controlled, if the current fault condition is such that the motor vehicle (MV) must be placed in a state of minimal risk; and a fourth operating mode, which represents the state of minimal risk. [18] Method according to any one of claims 15 to 17, wherein the at least one safety guideline (P) relates to one of the following: a minimum distance that the motor vehicle (MV) should maintain to a following vehicle, a speed limit that the motor vehicle (MV) is supposed to adhere to, Definitions of safe stopping points that the motor vehicle (MV) should be able to reach in the event of a fault in the motor vehicle (MV), and a set of measures to be taken in the event that one or more sets of faults occur in the motor vehicle (MV). [19] Method according to any one of claims 15 to 18, wherein the monitoring unit (160) comprises a system state monitoring unit (150) and a safety unit (120), and wherein the method comprises: Received, in the system status monitoring unit (150), the sensor signals (SS) and based thereon Deriving vehicle condition data (H) that represent a functional state of the motor vehicle (MV), and Received, in the safety unit (120), the vehicle condition data (H) and at least one safety policy (P) and based thereon Generating the commands ({cmd}) to the data store (140). [20] Method according to claim 19, wherein the monitoring unit (160) further comprises a second data interface unit (165), and wherein the method comprises: Receive and store, in the second data interface unit (165), at least one regulatory requirement (R) that is to be met during operation of the motor vehicle (MV), Received, in the security unit (120), which meets at least one regulatory requirement (R) and additionally based on at least one regulatory requirement (R) Generating the commands ({cmd}) to the security unit (120). [21] Method according to one of claims 19 or 20, wherein the monitoring unit (160) further comprises a risk assessment unit (167), and wherein the method comprises: dynamic assessment, in the risk assessment unit (167), of each estimated risk that the motor vehicle (MV) will collide with any other road user and / or obstacle that is in the vicinity of the motor vehicle (MV), wherein the respective estimated risk is indicated by at least one signal (S j ) is expressed, Received, in the security unit (120), of at least one signal (S j ) and additionally based on at least one signal (S j ) Generating commands ({cmd}). [22] The method of claim 21, further comprising: Monitoring, by means of the risk assessment unit (167), an environment of the motor vehicle (MV) to determine whether the motor vehicle (MV) is currently operating within a range of parameters under which it is designed to operate, and wherein at least one signal (S j ) further indicates whether the motor vehicle (MV) is currently operating within the range of parameters or not. [23] Method according to one of claims 21 or 22, further comprising: Determine, in the risk assessment unit (167), an estimated risk that the motor vehicle (MV) and / or any other road user in its vicinity will violate a traffic rule, whereby at least one signal (S) j ) furthermore, this estimated risk is stated. [24] Method according to any one of claims 19 to 23, further comprising: Determine, in the safety unit (120), whether at least one preserved safety-relevant parameter (P, R, S) j , H) describes at least one state in which the motor vehicle (MV) is currently operated, wherein the at least one state is such that the risk that the motor vehicle (MV) cannot be moved autonomously in accordance with the intended path exceeds a fault risk threshold, and then, if the fault risk threshold is exceeded, Generating, in the safety unit (120), safety control signals (SCS) configured to cause the motor vehicle (MV) to move autonomously in accordance with a safe path, the safe path taking precedence over the target path represented by the target control signals (NCS). [25] Computer program (127) comprising instructions which, when executed in at least one processor, cause the at least one processor to execute a method according to any one of claims 15 to 24. [26] Non-volatile data carrier (125) containing a computer program according to claim 25.

Citation Information

Patent Citations

  • Multi-level vehicle integrity and quality control mechanism

    DE112013001449T5

  • Safety management system

    EP2317412A1

  • Locality adapted computerized assisted or autonomous driving of vehicles

    US20150057869A1

  • Management of autonomous vehicle lanes

    US20170197626A1

  • Facilitating Vehicle Driving and Self-Driving

    US20170277194A1