Lane keeping for autonomous vehicles
By introducing road estimation and trajectory planning modules in autonomous vehicles, generating drivingable areas and separating nominal trajectory and backup stop trajectory, the problem of limited speed in lane keeping is solved, achieving higher vehicle speeds and lower system costs.
Patent Information
- Application Number
- CN202010894304.2
- Authority / Receiving Office
- CN · China
- Patent Type
- Patents(China)
- Current Assignee / Owner
- Priority Date
- 2019-08-29
- Filing Date
- 2020-08-31
- Publication Date
- 2025-08-22
- Estimated Expiration
- 2040-08-31
AI Technical Summary
When existing autonomous vehicle systems are kept in lanes, there are problems such as limited vehicle maximum speed due to uncertainty in lane trajectory estimation and excessive hardware and software requirements.
By introducing a road estimation module and a trajectory planning module, the drivingable area is generated using sensor data, and the nominal trajectory and backup stop trajectory are separated based on predefined safety requirements and availability standards, reducing the confidence standard for backup stop frequency, allowing for higher maximum speeds.
It realizes the maximum speed of autonomous vehicles, reduces additional hardware and software requirements, and improves user experience while maintaining security and ASIL requirements.
Smart Images

Figure CN112440996B_ABST
Abstract
Description
[0001] CROSS-REFERENCE TO RELATED APPLICATIONS
[0002] This patent application claims priority from European Patent Application No. 19194353.9, filed on August 29, 2019, and entitled “Lane Keeping for Autonomous Vehicles,” which is assigned to the assignee of this patent application and is expressly incorporated herein by reference. Technical Field
[0003] The present disclosure relates to autonomous driving (AD) and advanced driver assistance systems (ADAS). More specifically, the present disclosure relates to road modeling for vehicles. Background Art
[0004] Over the past few years, the development of autonomous vehicles has rapidly expanded, with many different solutions being explored. Within these fields, both autonomous driving (AD) and advanced driver assistance systems (ADAS), or semi-autonomous driving, are being developed today within several different technology areas. One such area is how to accurately and consistently position the vehicle, as this is a crucial safety aspect when moving in traffic.
[0005] Lane departure is a key issue in AD systems, and appropriate solutions to reduce the risk of lane departure are crucial. Therefore, accurate and reliable generation of road models is an important function for all lane support systems or any other steering systems.
[0006] A road model based on data from various sensors (e.g., forward view, surround view, lidar, radar, map, IMU sensor, etc.) is assumed to describe the drivable lane in front of the vehicle, with lane representation uncertainty increasing with distance from the vehicle. This is illustrated in Figure 1(a). In more detail, Figure 1(a) illustrates a top view of a vehicle 1' traveling in a lane defined by left and right lane markings 2a', 2b' and lane trajectory projections 3a', 3b' that define the generated lane representations 3a', 3b', where the lines 3a', 3b' intersect at a distance in front of the vehicle 1'. Since the reliability of the lane marking measurements (performed by onboard sensors) decreases with distance from the vehicle 1', the lane trajectory projections 3a', 3b' become increasingly curved as the distance increases.
[0007] Furthermore, a strategy to reduce the risk of the vehicle 1' unintentionally exiting the lane is to define a requirement that the vehicle 1' be able to come to a complete stop within the currently available description 3a', 3b' of the target path (e.g., the target path of the lane). This requirement (that the vehicle 1' come to a complete stop within the available lane description) must be met at all times and in all circumstances, which leads to strict requirements on the systems and equipment within the vehicle. Furthermore, due to these strict requirements, the uncertainty or confidence in the lane trajectory estimates 3a', 3b' will limit the available distance for the vehicle 1' to come to a complete stop. Consequently, the possible top speed of the vehicle is strongly limited, which can negatively impact the practicality of the autonomous driving features and the user experience. Furthermore, because increasing the allowable top speed can drastically increase the requirements on the system software and hardware, the allowable top speed of the vehicle becomes a key design parameter to be considered for road modeling solutions.
[0008] Therefore, there is a need for new and improved solutions for lane keeping methods and systems for autonomous and semi-autonomous vehicles. In more detail, there is a need for new and improved solutions for lane keeping methods and systems using a road modeling module. Summary of the Invention
[0009] It is therefore an object of the present disclosure to provide a system for lane keeping for a vehicle, a vehicle comprising such a system, a method and a computer-readable storage medium that alleviate all or at least some of the disadvantages of currently known systems.
[0010] In particular, the object of the present disclosure is to provide a solution that allows higher speeds than currently known systems for a given road model quality. The object of the present disclosure is also to provide a solution for safe lane keeping that allows higher speeds in a more cost-effective manner than currently known systems.
[0011] This object is achieved by a system for lane keeping for a vehicle, a vehicle comprising such a system, a method and a computer-readable storage medium as defined in the appended claims.The term "exemplary" is in the present context to be understood as serving as an example, instance or illustration.
[0012] According to a first aspect of the present disclosure, a system for a lane keeping feature of a vehicle is provided. The lane keeping feature has predefined safety requirement criteria for keeping the vehicle within boundaries when the lane keeping feature is active. The system includes a road estimation module and a trajectory planning module. The road estimation module is configured to receive sensor data including information about the vehicle's surroundings and determine a drivable area based on the sensor data. The drivable area includes a left boundary and a right boundary extending along the vehicle's direction of travel, wherein each boundary includes a plurality of points distributed along each boundary, each point being associated with a confidence level. The trajectory planning module is configured to receive the determined drivable area and determine a nominal trajectory for the vehicle based on the received drivable area. The nominal trajectory is determined based on predefined safety requirement criteria and predefined availability criteria. The trajectory planning module is further configured to determine a backup stop trajectory for the vehicle based on the received drivable area, the backup stop trajectory being determined based on a predefined confidence criterion. The predefined confidence criterion depends on a predefined value for the frequency of the backup stop, which is based on a predefined availability criterion for the nominal trajectory.
[0013] This article describes a system that can provide safe lane keeping at higher speeds than currently known solutions without increasing hardware requirements (sensors, controllers, support systems, etc.).
[0014] As described, the drivable area includes a left boundary and a right boundary extending along the direction of travel of the vehicle. Therefore, the drivable area can be interpreted as a lane trace or lane tracking feature having two projections representing the lane geometry in the vehicle's surroundings. Accordingly, the left boundary and the right boundary (i.e., the left lane trajectory and the right lane trajectory) have a confidence distribution that depends on the distance from the vehicle (or more specifically, from the vehicle's sensors). In more detail, the growing uncertainty in the position of the lane boundaries (e.g., lane markings) is the fundamental factor as to why the projected lane trajectory becomes sharper inward with distance from the vehicle. Therefore, the lane trajectory can be interpreted as a plurality of points distributed along each detected lane boundary, each point being associated with a confidence level (e.g., a confidence distribution, a confidence function, a confidence value, etc.).
[0015] In the present context, the predefined safety requirement standard is understood as a probability of dangerous failure rate limit associated with a safety standard or risk classification strategy, such as, for example, the Automotive Safety Integrity Level (ASIL) requirement. For example, for safety-critical functions, ASIL D may be applied, which can be translated into 10 -9The probability of a dangerous failure rate limit of h. The predefined availability criterion, in the present context, is a user-defined or designer-defined metric as will be explained further below. The predefined confidence criterion is the resulting requirement for the backup stop feature, which also specifies the probability of a dangerous failure rate limit.
[0016] The stringent requirements for backup stop trajectory planning have the function of limiting the maximum achievable speed of the vehicle, which impairs the user experience of autonomous or semi-autonomous vehicles. In more detail, the safety requirements can be based on the Automotive Safety Integrity Level (ASIL) of the trajectory planning module in the form of a probability limit for dangerous failure rate, which is usually 10 7 -10 9 More specifically, the ASIL requirement states that for both the nominal trajectory and the backup stop trajectory (sometimes called the safety stop trajectory), the vehicle must not unintentionally leave the “lane” more than every 10 7 -10 9 In other words, when operating (such as stopping or moving out of the planning area), the vehicle is not allowed to deviate from each trajectory more than once every 10 7 ~10 9 Once an hour, this could have devastating consequences, for example if a vehicle stops in the opposite lane and causes a head-on collision with another vehicle.
[0017] Therefore, the inventors of the present application realized that in order to allow longer stopping distances and thus higher permissible maximum speeds, the requirements for the frequency of stops in the lane should be relaxed. Therefore, by introducing a predefined availability criterion for the nominal trajectory (i.e. a type of metric that defines that an updated trajectory is available in a subsequent time step with a certain probability), the integrity level of the backup stop feature (i.e. the safety requirement criterion) can be reduced by the same order of magnitude according to the following insight. In more detail, it was realized that if an availability criterion for the nominal trajectory is introduced, then a predefined value for the backup stop frequency of the corresponding backup stop trajectory can be introduced. Therefore, this is presented in a trajectory planning feature that is more cost-effective than currently known solutions while maintaining ASIL requirements. More specifically, the proposed solution allows autonomous vehicles to operate at higher maximum speeds without introducing stricter requirements on, for example, sensor hardware and software (which adds significant costs).
[0018] In other words, by introducing a predefined value for the frequency of stops in the lane, the confidence criterion for the backup stop maneuver to keep the vehicle within the projected drivable area (e.g., within the lane) can be lowered by the same order of magnitude as the predefined stop frequency. For example, if the predefined stop frequency is every 10 4 Once an hour, the confidence level increases from 10 -8 Reduced to 10 -4The lowered confidence standard will allow for longer stopping distances, which will in turn allow for a higher permissible top speed.
[0019] Furthermore, by assuming that the triggers for activating the safe stop feature will mostly be caused by faults in the automated driving system (ADS) or the vehicle platform, such as hardware errors, software defects, etc., the reliability requirements can be expanded. In more detail, the inventors of the present application realized that by "moving" some of the requirements from the backup stop trajectory planning module, thereby offloading some of the "burden" to other parts of the system, the overall integrity level can still be met. More specifically, quality metrics can be defined related to the components or modules that control the probability of triggering a stop maneuver (such as the road estimation module and the perception system and associated sensors), which in turn will affect the likelihood of an excitation leading to a backup stop trajectory, so that the requirements thereon can be relaxed. In other words, the integrity level (ASIL level) of the backup stop system can be maintained at the required high level while still achieving a useful maximum speed (over 50 km / h).
[0020] In other words, the predefined availability criterion can be interpreted as stipulating that the nominal trajectory will be 4 A quality management metric where the vehicle is only unavailable once per hour, meaning the vehicle can run for 10,000 hours based on the nominal trajectory before being forced to perform a backup stop. Note that both the nominal trajectory and the backup stop trajectory must be available (so that the backup stop trajectory can be performed in the event that the nominal becomes unavailable). Therefore, the backup stop will be performed every 10 4 It is triggered only once per hour, thus being able to reduce the predefined safety requirement criterion by the same order of magnitude, which results in a reduction in the predefined confidence criterion for the backup stop trajectory.
[0021] According to a second aspect of the present disclosure, there is provided a vehicle comprising a perception system including at least one sensor for monitoring the vehicle's surroundings and a system according to any of the embodiments disclosed herein. With respect to this aspect of the present disclosure, similar advantages and preferred features exist as discussed above with respect to the first aspect of the present disclosure.
[0022] A perception system in the present context is understood as a system responsible for acquiring raw sensor data from onboard sensors such as cameras, lidars, radars, and ultrasonic sensors and converting this raw data into scene understanding.
[0023] Further, according to a third aspect of the present disclosure, a method for a lane keeping feature for a vehicle is provided. The lane keeping feature has predefined safety requirement criteria for keeping the vehicle within boundaries when the lane keeping feature is active. The method includes receiving sensor data including information about the vehicle's surroundings, and determining a drivable area based on the sensor data. The drivable area includes a left boundary and a right boundary extending along the vehicle's direction of travel. Furthermore, each boundary includes a plurality of points distributed along each boundary, each point being associated with a confidence level. The method further determines a nominal trajectory based on the drivable area, wherein the nominal trajectory is determined based on the predefined safety requirement criteria and a predefined availability criterion. Furthermore, the method includes determining a backup stop trajectory for the vehicle based on the drivable area, wherein the backup stop trajectory is determined based on a predefined confidence criterion. The predefined confidence criterion depends on a predefined value for the frequency of the backup stop, wherein the predefined value for the frequency of the backup stop is based on a predefined availability criterion for the nominal trajectory. With respect to this aspect of the present disclosure, similar advantages and preferred features as discussed above with respect to the first aspect of the present disclosure apply.
[0024] Further, according to a fourth aspect of the present disclosure, a computer-readable storage medium is provided, storing one or more programs configured to be executed by one or more processors of a vehicle control system, the one or more programs including instructions for performing the method according to any of the embodiments disclosed herein. With respect to this aspect of the present disclosure, similar advantages and preferred features exist as discussed above with respect to the first aspect of the present disclosure.
[0025] The term "non-transitory," as used herein, is intended to describe computer-readable storage media (or "memory") that excludes propagating electromagnetic signals, but is not intended to otherwise limit the types of physical computer-readable storage devices encompassed by the phrase computer-readable media or memory. For example, the terms "non-transitory computer-readable media" or "tangible memory" are intended to encompass types of storage devices that do not necessarily store information permanently, including, for example, random access memory (RAM). Program instructions and data stored on a tangible, computer-accessible medium in a non-transitory form may further be transmitted via a transmission medium or signal, such as an electrical, electromagnetic, or digital signal, which may be conveyed over a communication medium such as a network and / or wireless link. Thus, the term "non-transitory," as used herein, is a limitation on the medium itself (i.e., tangible, non-signal), as opposed to limitations on data storage persistence (e.g., RAM vs. ROM).
[0026] Further embodiments of the present disclosure are defined in the dependent claims. It should be emphasized that when the term "comprises" is used in this specification, it is used to specify the presence of the stated features, integers, steps, or components. It does not exclude the presence or addition of one or more other features, integers, steps, components, or groups thereof.
[0027] These and other features and advantages of the present disclosure will be further elucidated below with reference to the embodiments described hereinafter. BRIEF DESCRIPTION OF THE DRAWINGS
[0028] Further objects, features and advantages of the embodiments disclosed in the present application will become apparent from the following detailed description with reference to the accompanying drawings, in which:
[0029] FIG1 is a schematic top view of a vehicle traveling on a road segment having projected road modeling features according to the prior art.
[0030] Figure 2 is a schematic top view of a vehicle traveling on a road segment with projected road modeling features according to an embodiment disclosed in the present application.
[0031] Figure 3 is a schematic block diagram representation of a system for controlling a lane keeping feature of a vehicle according to an embodiment disclosed herein.
[0032] Figure 4 is a schematic side view illustration of a vehicle including a system for controlling a lane keeping feature of the vehicle according to an embodiment disclosed herein.
[0033] Figure 5 is a schematic flow chart representation of a method for controlling a lane keeping feature of a vehicle according to an embodiment disclosed herein. Specific embodiments
[0034] Those skilled in the art will understand that the steps, services, and functions described herein may be implemented using separate hardware circuits, using software functions executed in conjunction with a programmed microprocessor or general-purpose computer, using one or more application-specific integrated circuits (ASICs), and / or using one or more digital signal processors (DSPs). It will also be understood that when the present disclosure is described in terms of methods, it may also be embodied in one or more processors and one or more memories connected to the one or more processors, wherein the one or more memories store one or more programs that, when executed by the one or more processors, perform the steps, services, and functions disclosed herein.
[0035] The present disclosure relates to the ability of autonomous (or semi-autonomous) vehicles to detect and, more specifically, handle rare hazardous events in a safe manner. Hazardous events can be internal to the vehicle system, such as in the form of sensor failures, hardware failures, software defects, etc., or external, such as hazardous situations caused by surrounding traffic. These events result in violations of nominal operating conditions and must be detected and mitigated by appropriate actions in order to meet safety requirements. The present disclosure focuses on hazardous internal events and trajectory planning characteristics.
[0036] In the following description of exemplary embodiments, the same reference numerals refer to the same or similar components.
[0037] Figure 2 Two schematic diagrams (a) and (b) are shown, which illustrate a top perspective view of a vehicle 1 on a road segment with a projected trajectory. Based on information associated with the determined drivable areas 20a, 20b, the trajectory defines a time-dependent path in the vehicle's direction of travel with left and right boundaries. More specifically, the topmost diagram (a) illustrates a backup stop trajectory (also referred to as a safety stop trajectory) with a left boundary 5a and a right boundary 5b, relative to a backup stop trajectory of the prior art with left and right boundaries 3a, 3b. The bottom diagram (b) illustrates a high-confidence portion of the nominal trajectory to meet the dynamic requirements of the trajectory planning module (i.e., the requirement to keep the vehicle within the lane when operating under normal conditions).
[0038] It can be said that there are two requirements for a control system used for trajectory planning of an autonomous vehicle, a dynamic requirement and a "safe stop" or "backup stop" requirement. The dynamic requirement specifies that the control system must be able to keep the vehicle within the boundaries of the drivable area (e.g., within a lane). More specifically, the control system should guarantee that the vehicle is able to keep the vehicle within the current lane within the capabilities of the vehicle platform (e.g., handle any upcoming curves with sufficiently high confidence). The safe stop requirement specifies that the vehicle must be able to stop within the boundaries of the drivable area (e.g., within a lane) with a predefined probability.
[0039] therefore, Figure 2(a) illustrates a safe stop requirement where the left and right boundaries 5a, 5b describe the lane in front of the vehicle 1, with uncertainty increasing with distance from the vehicle 1, as illustrated by confidence distributions 21a-d. Therefore, the vehicle 1 must be able to come to a stop within the currently available description of the drivable area 20a. Here, the drivable area is illustrated as the lane 20a, but could also be in the form of a path from the lane to the shoulder, or to a roadside parking area. In general, it can be said that a safe stop trajectory can include any path that avoids the vehicle coming to a stop in an area outside the target path of the vehicle 1. The confidence levels are illustrated here as confidence distributions 21a-d, but as will be appreciated by those skilled in the art, the confidence levels could be provided in other formats, such as confidence values, confidence ranges, confidence functions, etc.
[0040] In order to allow longer stopping distances using the same sensor set, the requirement for the frequency of mid-lane stops must be relaxed. It is assumed that the majority of mid-lane stops will be caused by faults in the automated driving system (ADS) or the vehicle platform. The number of unplanned “backup stops” acceptable to consumers is 1 in 10. 3 h-1 / 10 5 Somewhere in the range of h, such as 1 / 10 4 The reduced severity of the lane prediction will allow for longer stopping distances, as shown by the difference between the prior art boundaries 3a', 3b' and the presented lane boundaries 5a, 5b of the proposed solution. This is because the safety requirement for stopping the vehicle 1 to remain in the drivable area 20a can be reduced by the same order of magnitude as the frequency of the stops. In this example, from 10 -8 to 10 -4 In other words, due to the realization that the backup stop maneuver will be "fired" or triggered at a lower frequency (defined by the availability criterion), a greater uncertainty in the road model estimates 5a, 5b can be accepted, thereby allowing the road boundaries 5a, 5b to have a longer extension, which subsequently results in a higher top speed being achievable with the same sensor set compared to currently known solutions.
[0041] However, for dynamic requirements, the system may be arranged to use only a sub-portion of the nominal trajectory, ie only the portion where boundaries are associated with high confidence values 21a-d, e.g. Figure 2 (b) is shown. This is because the system does not need to allow for a trajectory that will allow vehicle 1 to "safely stop" within drivable area 20b. Instead, safety requirements can be defined for the system to ensure that vehicle 1 remains within the target path boundaries within the capabilities of the vehicle platform, such as handling any upcoming curves with sufficiently high confidence. Figure 2(b) illustrates those sub-portions of the nominal trajectory having high confidence values and their associated boundary projections 6a, 6b, 7a, 7b, 8a, 8b.
[0042] Accordingly, the present disclosure is based, at least in part, on the insight that the trajectory planning problem can be divided into two parts. More specifically, by defining a frequency value for stopping, longer stopping distances are allowed, which in turn are permitted by a predefined availability criterion. The predefined availability criterion allows the system to rely on high-confidence sub-portions 6a, 6b, 7a, 7b, 8a, 8b of the nominal trajectory, assuming that a new road model is generated in subsequent time steps. Naturally, the predefined availability criterion also specifies that a backup stopping trajectory is always available. In other words, a "high-confidence" nominal trajectory and a "sufficiently confident" backup stopping trajectory are always available.
[0043] Figure 2 The block diagram in Figure 1 illustrates how regulatory performance requirements (here, ASIL requirements, as an example) affect the safety requirement standards used for nominal trajectory planning and for backup stop trajectory planning. As one skilled in the art will appreciate, ASIL is used only as an example of a risk classification scheme, and other and future risk classification schemes are similarly applicable. Therefore, the performance requirements are derived from ASIL in this example, but other standards are similarly applicable. The requirements on which the nominal trajectory is based define the safety requirements for each 10 seconds of trajectory planning. 8 The vehicle may not unintentionally move out of the lane when h is valid more than once. However, the proposed system is designed so that an availability criterion is provided, which stipulates that an updated road model that can derive the nominal trajectory and the backup stop trajectory is provided in subsequent steps with a predefined certainty. More specifically, the system is allowed to 4 h is only once unable to provide an updated road model in subsequent time steps. Therefore, the (confidence) requirement of the safe stop function can be reduced by the same order of magnitude, since the overall system will still meet the requirement of less than 10 -8 A general standard for limiting the probability of a dangerous failure rate h.
[0044] Figure 3 is a schematic block diagram illustrating a system for controlling a lane keeping feature of a vehicle. More specifically, the system disclosed herein is similarly applicable to any ADAS or AD feature that handles road modeling and associated trajectory planning. The lane keeping feature has a predefined safety requirement standard (e.g., ASIL C or ASIL D) for keeping the vehicle within bounds when the lane keeping feature is active.
[0045] The system has a road estimation module 21 and a trajectory planning module 22. The road estimation module is configured to receive sensor data 25 including information about the vehicle's surroundings. The sensor data can be obtained from the vehicle's perception system or directly from one or more sensors connected to the system. The perception system is understood in the current context as a system responsible for acquiring raw sensor data from onboard sensors such as cameras, lidars, radars, and ultrasonic sensors and converting this raw data into scene understanding. The road estimation module is further configured to determine a drivable area based on the sensor data 25. The left and right boundaries of the drivable area extend along the direction of travel of the vehicle. Each boundary includes a plurality of points distributed along each boundary, and each point is associated with a confidence level (e.g., a confidence distribution). Typically, the confidence level decreases with distance from the vehicle.
[0046] Furthermore, the trajectory planning module 22 is configured to receive the drivable area from the road estimation module 21. The trajectory planning module 22 is further configured to determine or generate a nominal trajectory based on the received drivable area, wherein the nominal trajectory is determined based on a predefined safety requirement standard and a predefined availability standard. Moreover, the trajectory planning module 22 is configured to determine a backup stop trajectory (also referred to as a safety stop trajectory) of the vehicle based on the received drivable area. The backup stop trajectory is determined based on a predefined confidence criterion. More specifically, the predefined confidence criterion depends on a predefined value of the frequency of backup stops based on the predefined availability criterion of the nominal trajectory.
[0047] As mentioned previously, the predefined availability criterion is a parameter that is a newly introduced system design aspect and introduces, so to speak, a "guarantee" that new or updated trajectories (nominal and backup stops) will be generated in subsequent time steps. This insight, which leads to this design consideration in the form of an availability parameter, has some beneficial consequences in the form of a reduced backup stop confidence criterion.
[0048] like Figure 3 As illustrated in the schematic diagram of FIG, the trajectory planning module 22 may include several submodules. For example, the trajectory planning module may include separate modules for the nominal trajectory plan 28 and the backup stop plan 27. In addition, the trajectory planning module may include a safety monitor 26. The safety monitor 26 is preferably configured to detect errors and generate appropriate commands to mitigate hazardous situations. The safety monitor 26 is preferably in the form of a high-integrity component dedicated to safety. Therefore, the safety monitor 26 is configured to receive and monitor the status of internal components.
[0049] Thus, the trajectory planning module 22 can be said to include two separate channels, one for nominal planning and one for safety. This provides a higher availability of the backup stopping capability. Accordingly, sensor data 25 including information about the vehicle's surroundings is preferably received independently in each channel.
[0050] The system further includes a vehicle control module 23 configured to obtain a nominal trajectory and a backup stopping trajectory and to send a control signal to at least one actuator (represented herein as a vehicle platform 24) to manipulate the vehicle based on the determined nominal trajectory or the backup stopping trajectory. However, the illustrated system architecture is merely an exemplary implementation, and as readily understood by those skilled in the art, various alternative implementations are possible and within the scope of the present disclosure.
[0051] For example, the vehicle platform 24 may include the control module 23. Furthermore, the vehicle platform may include one or more storage devices for storing the backup stop trajectory generated by the trajectory planning module 22, which is executed upon activation by the safety monitor 26.
[0052] When in use, the road estimation module 21 receives sensor observations 25 and generates a drivable area for the vehicle. The drivable area is defined by one or more boundaries associated with a confidence level. For example, the drivable area can be in the form of a lane, and the boundaries can be left and right lane markings. Accordingly, the road estimation module 21 can define lane boundaries close to the vehicle with higher accuracy than lane boundaries farther away from the vehicle. The trajectory planning module 22 obtains the drivable area and generates a trajectory for the vehicle (e.g., in the form of path and acceleration data), which is subject to safety requirements that stipulate that the vehicle must stay within the boundaries of the drivable area (e.g., within the lane). In more detail, the trajectory planning module 22 calculates a nominal trajectory and a backup stop trajectory allowed by predefined availability criteria, where only a sub-portion of the nominal trajectory is used to meet the dynamic requirements as discussed above. In addition, the predefined availability criteria result in a reduction in the safety requirement criteria for the backup stop function, which is defined herein as a "predefined confidence criteria."
[0053] Figure 4 FIG2 is a schematic side view of a vehicle 1 including a system 10 for controlling a lane keeping feature according to any of the embodiments disclosed herein. Vehicle 1 further includes a perception system 32 connected to a plurality of sensor devices 33 a-c. The perception system is responsible for acquiring raw sensor data from sensor devices 33 a-c, which may be in the form of cameras, lidars, radars, ultrasonic sensors, accelerometers, gyroscopes, or any other automotive-grade sensors, and converting this raw data into scene understanding. Vehicle 1 may also include other suitable supporting systems, such as a positioning system, an inertial measurement unit (IMU), and the like.
[0054] System 10 includes one or more processors 11, memory 12, a sensor interface 13, and a communication interface 14. Processor 11 may also be referred to as control loop 11 or control circuit 11. Control circuit 11 is configured to execute instructions stored in memory 12 to perform a method for controlling a lane keeping feature of a vehicle according to any of the embodiments disclosed herein. In other words, memory 12 of control device 10 can include one or more (non-transitory) computer-readable storage media for storing computer-executable instructions that, when executed by one or more computer processors 11, enable the computer processors 11 to perform the techniques described herein, for example. Memory 12 may optionally include high-speed random access memory, such as DRAM, SRAM, DDR RAM, or other random access solid-state memory devices; and may optionally include non-volatile memory, such as one or more magnetic disk storage devices, optical disk storage devices, flash memory devices, or other non-volatile solid-state storage devices. Different modules of system 10 may include independent control circuits 11, memory devices 12, sensor interfaces 13, and communication interfaces 14, or may be configured as software modules within a common hardware device.
[0055] Furthermore, vehicle 1 can be connected to an external network 41 via, for example, a wireless link (e.g., for retrieving map data). The same or some other wireless link can be used to communicate with other vehicles in the vicinity of vehicle 1 or with local infrastructure elements. Cellular communication technology can be used for long-range communications, such as to external networks, and, if the cellular communication technology used has low latency, it can also be used for vehicle-to-vehicle, vehicle-to-vehicle (V2V), and / or vehicle-to-infrastructure (V2X) communications. Examples of cellular radio technologies include GSM, GPRS, EDGE, LTE, 5G, 5G NR, etc., including future cellular solutions. However, in some solutions, short- to medium-range communication technologies such as wireless local area networks (LANs), such as those based on IEEE 802.11, are used. ETSI is currently researching cellular standards for vehicle communications, and 5G, for example, is considered a suitable solution due to its high bandwidth, low latency, and efficient processing of communication channels. Therefore, system 1 can be arranged to perform some or all of the method steps by relying on resources 42 remote from vehicle 1 through so-called cloud computing solutions.
[0056] Figure 51 is a schematic flow chart representation of a method 100 for controlling a lane keeping feature of a vehicle according to an embodiment disclosed herein. The lane keeping feature has predefined safety requirement criteria for keeping the vehicle within boundaries when the lane keeping feature is active. Method 100 includes the step of receiving 101 sensor data (originating from one or more sensor devices of the vehicle). The sensor data includes information about the vehicle's surroundings. Method 100 further includes determining 102 a drivable area based on the received sensor data. The drivable area includes a left boundary and a right boundary extending along the vehicle's direction of travel. In other words, the drivable area is defined by one or more boundaries. Each boundary includes (or is based on) a plurality of points distributed along each boundary, each point being associated with a confidence level. The confidence level can be understood as a value that describes the probability that a representation of a boundary is located at the exact same location as a boundary in the vehicle's surroundings. For example, if the boundary is assumed to be a lane boundary, the confidence level defines the probability that the "perceived" boundary (and the subsequent projected lane trajectory) is located at the same location as the actual lane marking on which the lane trajectory is based.
[0057] The method 100 further includes determining 103 a nominal trajectory based on the received drivable area. The nominal trajectory is further determined based on predefined safety requirement criteria and predefined availability criteria. As mentioned, the predefined safety requirement criteria are based on regulatory integrity level regulations, and the predefined availability criteria are deliberate quality management metrics. Further, the method 100 includes determining a backup stop trajectory (also referred to as a safety stop trajectory) for the vehicle based on the drivable area. The backup stop trajectory is further determined based on a predefined confidence criterion. However, the predefined confidence criterion depends on a predefined value for the frequency of the backup stop, which in turn is based on the predefined availability criterion of the nominal trajectory. In more detail, the predefined confidence criterion for the backup stop trajectory is calculated based on the overall safety requirement criteria and the predefined value for the backup stop frequency. Therefore, by cleverly realizing that quality management (QM) metrics can be used to define the frequency of the backup stop, otherwise overly stringent safety requirements for the backup stop feature can be reduced, providing an improved overall user experience.
[0058] Executable instructions for performing these functions are optionally included in non-transitory computer-readable storage media or other computer program products configured to be executed by one or more processors.
[0059] The present disclosure has been described above with reference to specific embodiments. However, other embodiments than those described above are possible and are within the scope of the present disclosure. Method steps for performing the method by hardware or software different from those described above may be provided within the scope of the present disclosure. Therefore, according to an exemplary embodiment, a non-transitory computer-readable storage medium is provided, storing one or more programs configured to be executed by one or more processors of a vehicle control system, the one or more programs including instructions for performing the method according to any one of the embodiments discussed above. Alternatively, according to another exemplary embodiment, the cloud computing system may be configured to perform any one of the methods described herein. The cloud computing system may include distributed cloud computing resources that are controlled by one or more computer program products to jointly perform the methods described herein.
[0060] In general, computer-accessible media may include any tangible or non-transitory storage media or memory media, such as electrical, magnetic, or optical media, for example, a disk or CD / DVD-ROM coupled to a computer system via a bus. As used herein, the terms "tangible" and "non-transitory" are intended to describe computer-readable storage media (or "memory") that exclude propagating electromagnetic signals, but are not intended to otherwise limit the types of physical computer-readable storage devices encompassed by the phrase computer-readable media or memory. For example, the terms "non-transitory computer-readable media" or "tangible memory" are intended to encompass types of storage devices that do not necessarily store information permanently, including, for example, random access memory (RAM). Program instructions and data stored on a tangible, computer-accessible storage medium in a non-transitory form may be further transmitted via a transmission medium or signal, such as an electrical signal, an electromagnetic signal, or a digital signal, which may be conveyed via a communication medium such as a network and / or a wireless link.
[0061] Processor 11 (associated with system 10) can be or include any number of hardware components for performing data or signal processing or for executing computer code stored in memory 12. System 10 has associated memory 12, and memory 12 can be one or more devices for storing data and / or computer code that are used to perform or facilitate the various methods described in this specification. The memory may include volatile memory or non-volatile memory. The memory 12 may include database components, object code components, script components, or any other type of information structure for supporting the various activities of this specification. According to an exemplary embodiment, any distributed or local memory device may be used with the systems and methods described herein. According to an exemplary embodiment, the memory 12 is communicatively connected to the processor 11 (e.g., via circuitry or any other wired, wireless, or network connection) and includes computer code for executing one or more processes described herein.
[0062] It will be appreciated that the sensor interface 13 may also provide the possibility of acquiring sensor data directly (from sensors 33a-c) or via a dedicated sensor control circuit 32 in the vehicle 1. The communication / antenna interface 14 may further provide the possibility of sending the output to a remote location (e.g., a remote server 42) using an antenna 37. In addition, some sensors in the vehicle may communicate with the system 10 using a local network arrangement such as a CAN bus, I2C, Ethernet, fiber optics, etc. The communication interface 14 may be arranged to communicate with other control functions of the vehicle and may therefore also be considered a control interface; however, a separate control interface (not shown) may be provided. Local communication within the vehicle may also be of a wireless type with a protocol such as WiFi, LoRa, Zigbee, Bluetooth, or similar medium / short range technology.
[0063] Accordingly, it should be understood that portions of the described solution may be implemented in the vehicle, in a system located external to the vehicle, or in a combination of both; for example, in a server 42 in communication with the vehicle, a so-called cloud solution. For example, sensor data may be sent to an external system, and that system may perform the steps to determine the drivable area. The drivable area may further be based on the location of vehicle 1 and sensor observations obtained from other vehicles. The various features and steps of the embodiments may be combined in other combinations than those described.
[0064] Exemplary methods, computer-readable storage media, systems, and vehicles are described in the following items:
[0065] 1. A system for controlling a lane keeping feature of a vehicle, the lane keeping feature having predefined safety requirement criteria for keeping the vehicle within boundaries when the lane keeping feature is active, the system comprising:
[0066] A road estimation module includes a control circuit configured to:
[0067] receiving sensor data including information about the vehicle's surroundings; and
[0068] determining a drivable area based on the sensor data, the drivable area comprising a left boundary and a right boundary extending along a travel direction of the vehicle, wherein each boundary comprises a plurality of points distributed along each boundary, each point being associated with a confidence level;
[0069] The trajectory planning module includes a control circuit configured to:
[0070] receiving the determined drivable area;
[0071] determining a nominal trajectory based on the received drivable area, wherein the nominal trajectory is further determined based on a predefined safety requirement standard and a predefined availability standard;
[0072] determining a backup stop trajectory for the vehicle based on the received drivable area, the backup stop trajectory being further determined based on a predefined confidence criterion;
[0073] The predefined confidence criterion is dependent on a predefined value of the frequency of backup stops, which predefined value of the frequency of backup stops is based on a predefined availability criterion of the nominal trajectory.
[0074] 2. The system according to item 1, further comprising:
[0075] The vehicle control module is configured to:
[0076] obtaining the determined nominal trajectory and the determined backup stop trajectory;
[0077] A control signal is sent to at least one actuator to steer the vehicle based on the determined nominal trajectory or the backup stop trajectory.
[0078] 3. The system according to item 1 or 2, wherein the predefined availability criterion defines the probability that the updated nominal trajectory is unavailable in a subsequent time step.
[0079] 4. The system according to item 1 or 2, wherein the nominal trajectory is based on a first subset of points of the plurality of points, the first subset of points being associated with a confidence level above a first predefined threshold.
[0080] 5. The system of item 4, wherein the safe stop trajectory is based on a second subset of points in the plurality of points, the second subset of points being associated with a confidence level above a second predefined threshold, wherein the second predefined threshold is lower than the first predefined threshold.
[0081] 6. The system according to item 1 or item 2, wherein the safety stop trajectory has a first time range and the nominal trajectory has a second time range, the first time range being longer than the second time range.
[0082] 7. A system according to item 1 or item 2, wherein the predefined value of the frequency of stopping in the lane is within a range from every 10 3 Stop every 10 hours 5 Within the range of one stop per hour.
[0083] 8. A system according to item 1 or item 2, wherein the predefined availability criteria are 3 Unavailable once every 10 hours 5 Hours are unavailable once.
[0084] 9. A vehicle comprising:
[0085] a perception system comprising at least one sensor for monitoring the vehicle's surroundings;
[0086] A system according to any of the preceding items.
[0087] 10. A method for controlling a lane keeping feature of a vehicle, the lane keeping feature having predefined safety requirement criteria for keeping the vehicle within boundaries when the lane keeping feature is active, the method comprising:
[0088] receiving sensor data including information about a surrounding environment of the vehicle;
[0089] determining a drivable area based on the sensor data, the drivable area comprising a left boundary and a right boundary extending along a travel direction of the vehicle, wherein each boundary comprises a plurality of points distributed along each boundary, each point being associated with a confidence level;
[0090] determining a nominal trajectory based on the drivable area, wherein the nominal trajectory is further determined based on a predefined safety requirement standard and a predefined availability standard;
[0091] determining a backup stop trajectory for the vehicle based on the drivable area, the backup stop trajectory being further determined based on a predefined confidence criterion;
[0092] Therein the predefined confidence criterion depends on a predefined value of the frequency of backup stops, which predefined value of the frequency of backup stops is based on a predefined availability criterion of the nominal trajectory.
[0093] 11. The method according to item 10, further comprising:
[0094] A control signal is sent to at least one actuator to steer the vehicle based on the determined nominal trajectory or the backup stopping trajectory.
[0095] 12. The method according to item 10 or 11, wherein the predefined value of the frequency of stops in the lane is from every 10 3 Stop every 10 hours 5 Within the range of one stop per hour.
[0096] 13. The method according to claim 10 or 11, wherein the predefined availability criterion is 3 Unavailable once every 10 hours 5 Hours are unavailable once.
[0097] 14. A non-transitory computer-readable storage medium storing one or more programs configured to be executed by one or more processors of a vehicle control system, the one or more programs comprising instructions for performing the method according to any one of items 10-13.
[0098] It should be noted that the word "comprising" does not exclude the presence of other elements or steps than those listed, and the word "a" or "the" preceding an element does not exclude the presence of a plurality of such elements. It should also be noted that any figure sign does not limit the scope of the claims, the present disclosure may be implemented at least in part by both hardware and software, and several "means" or "units" may be represented by the same piece of hardware.
[0099] Although the accompanying drawings may show a specific order of method steps, the order of the steps may be different from that depicted. In addition, two or more steps may be performed concurrently or partially concurrently. For example, the steps of determining the nominal trajectory and the backup stop trajectory may be interchangeable based on the specific implementation. Such changes will depend on the selected software and hardware systems and on the designer's choice. All such changes are within the scope of the present disclosure. Similarly, software implementation methods can be implemented with standard programming techniques with rule-based logic and other logic to implement various connection steps, processing steps, comparison steps, and decision steps. The embodiments mentioned and described above are provided as examples only and are not restrictive of the present disclosure. Other solutions, uses, objectives, and functions within the scope of the present disclosure as claimed in the attached patent embodiments should be obvious to those skilled in the art.
Claims
1. A system for controlling a lane keeping feature of a vehicle, the lane keeping feature having predefined safety requirement criteria for keeping the vehicle within boundaries when the lane keeping feature is active, wherein the predefined safety requirement criteria defines a probability of a dangerous failure rate limit associated with a safety standard or risk classification strategy, the system comprising: The road estimation module is configured to: receiving sensor data comprising information about a surrounding environment of the vehicle; and determining a drivable area based on the sensor data, the drivable area comprising a left boundary and a right boundary extending along a travel direction of the vehicle, wherein each boundary comprises a plurality of points distributed along each boundary, each point being associated with a confidence level; The trajectory planning module is configured as follows: receiving the determined drivable area; determining a nominal trajectory based on the received drivable area, wherein the nominal trajectory is further determined based on the predefined safety requirement standard and a predefined availability standard, wherein the predefined availability standard defines a probability that the updated nominal trajectory is unavailable in a subsequent time step, wherein the probability that the updated nominal trajectory is unavailable in a subsequent time step is higher than a probability of a dangerous failure rate limit associated with the safety standard or risk classification strategy; determining a backup stop trajectory for the vehicle based on the received drivable area, the backup stop trajectory being further determined based on a predefined confidence criterion, wherein the predefined confidence criterion defines a probability of providing a dangerous failure rate limit for backup stop features of the backup stop trajectory; wherein the predefined confidence criterion depends on the predefined safety requirement criterion and a predefined value for a frequency of backup stops, wherein the predefined value for the frequency of backup stops is based on the predefined availability criterion of the nominal trajectory, wherein a product of a probability that the updated nominal trajectory is unavailable in a subsequent time step and a probability of a dangerous failure rate limit of the backup stop feature is lower than the probability of a dangerous failure rate limit associated with a safety criterion or a risk classification strategy, and The vehicle is steered based on the nominal trajectory when the nominal trajectory is available, the vehicle is steered based on the backup stop trajectory when the nominal trajectory is unavailable, and the backup stop trajectory is used to stop the vehicle in a lane.
2. The system according to claim 1, further comprising: The vehicle control module is configured to: obtaining the determined nominal trajectory and the determined backup stop trajectory; and A control signal is sent to at least one actuator to steer the vehicle based on the determined nominal trajectory or the backup stopping trajectory. 3 . The system of claim 1 , wherein the nominal trajectory is based on a first subset of points of the plurality of points, the first subset of points being associated with a confidence level above a first predefined threshold. 4 . The system of claim 3 , wherein the backup stop trajectory is based on a second subset of points in the plurality of points, the second subset of points being associated with a confidence level above a second predefined threshold, wherein the second predefined threshold is lower than the first predefined threshold. 5 . The system of claim 1 , wherein the backup stop trajectory has a first time range and the nominal trajectory has a second time range, the first time range being longer than the second time range.
6. The system according to claim 1 or 2, wherein the predefined value of the frequency of backup stop is from every 10 3 Stop every 10 hours 5 Within the range of one stop per hour.
7. The system according to claim 1 or 2, wherein the predefined availability criteria are 3 Unavailable once every 10 hours 5 Hours are unavailable once.
8. A vehicle comprising: a perception system comprising at least one sensor for monitoring the surrounding environment of the vehicle; A system according to any one of the preceding claims.
9. A method for controlling a lane keeping feature of a vehicle, the lane keeping feature having predefined safety requirement criteria for keeping the vehicle within boundaries when the lane keeping feature is active, wherein the predefined safety requirement criteria defines a probability of a dangerous failure rate limit associated with a safety standard or risk classification strategy, the method comprising: receiving sensor data comprising information about a surrounding environment of the vehicle; determining a drivable area based on the sensor data, the drivable area comprising a left boundary and a right boundary extending along a travel direction of the vehicle, wherein each boundary comprises a plurality of points distributed along each boundary, each point being associated with a confidence level; determining a nominal trajectory based on the drivable area, wherein the nominal trajectory is further determined based on the predefined safety requirement standard and a predefined availability standard, wherein the predefined availability standard defines a probability that the updated nominal trajectory is unavailable in a subsequent time step, wherein the probability that the updated nominal trajectory is unavailable in a subsequent time step is higher than a probability of a dangerous failure rate limit associated with the safety standard or risk classification strategy; determining a backup stop trajectory for the vehicle based on the drivable area, the backup stop trajectory being further determined based on a predefined confidence criterion, wherein the predefined confidence criterion defines a probability of providing a dangerous failure rate limit for backup stop features of the backup stop trajectory; wherein the predefined confidence criterion depends on the predefined safety requirement criterion and a predefined value for a frequency of backup stops, wherein the predefined value for the frequency of backup stops is based on a predefined availability criterion for the nominal trajectory, wherein a product of a probability that the updated nominal trajectory is unavailable in a subsequent time step and a probability of a dangerous failure rate limit of the backup stop feature is lower than the probability of a dangerous failure rate limit associated with a safety criterion or a risk classification strategy, and The vehicle is steered based on the nominal trajectory when the nominal trajectory is available, the vehicle is steered based on the backup stop trajectory when the nominal trajectory is unavailable, and the backup stop trajectory is used to stop the vehicle in a lane.
10. The method according to claim 9, further comprising: A control signal is sent to at least one actuator to steer the vehicle based on the determined nominal trajectory or the backup stopping trajectory.
11. The method according to claim 9 or 10, wherein the predefined value of the frequency of backup stop is within a range from every 10 3 Stop every 10 hours 5 Within the range of one stop per hour.
12. The method according to claim 9 or 10, wherein the predefined availability criterion is 3 Unavailable once every 10 hours 5 Hours are unavailable once.
13. A non-transitory computer-readable storage medium storing one or more programs configured to be executed by one or more processors of a vehicle control system, the one or more programs comprising instructions for performing the method according to any one of claims 9 to 12.
Citation Information
Patent Citations
Method and device for operating a motor vehicle in automated driving mode and motor vehicle
DE102017214531A1
Methods and systems for determining instructions for pulling over an autonomous vehicle
US9523984B1