Methods and apparatus, including computer program products, relating to configuring an autonomous vehicle system architecture, vehicles
By introducing a context collector and a reconfigurator into the autonomous driving system, the mapping and redundancy configuration of application instances are dynamically adjusted, solving the system adaptability problem under faults and context changes, and improving system reliability and customer satisfaction.
Patent Information
- Application Number
- CN202110268266.4
- Authority / Receiving Office
- CN · China
- Patent Type
- Patents(China)
- Current Assignee / Owner
- Priority Date
- 2020-03-12
- Filing Date
- 2021-03-12
- Publication Date
- 2025-11-11
- Estimated Expiration
- 2041-03-12
AI Technical Summary
Existing autonomous driving systems lack effective automatic adjustment mechanisms in the event of malfunctions, leading to decreased customer satisfaction or loss of confidence, and are unable to adapt to dynamic changes in the vehicle's environment.
By introducing a context collector and a reconfigurator into the autonomous driving system, user and environmental information is collected, and the mapping and redundant configuration of application instances on computing nodes are dynamically adjusted. Methods such as integer linear programming, evolutionary game theory and reinforcement learning are used to optimize the configuration, ensuring that the system can automatically adapt to faults or changes in context.
It enables the autonomous driving system to automatically adjust in the event of a fault or change in circumstances, improving system reliability and customer satisfaction, and ensuring safety and comfort.
Smart Images

Figure CN113386780B_ABST
Abstract
Description
Technical Field
[0001] This invention relates to methods and apparatus for configuring system architectures for autonomous vehicles, as well as the vehicles themselves. Background Technology
[0002] Contextual technology
[0003] Today, vehicles are equipped with various driver assistance systems that assist drivers in operating the vehicle. These assistance functions include, for example, maintaining a safe distance from the vehicle in front, autonomous parking, or changing lanes on highways. While these functions are highly reliable and well-tested, drivers still need to monitor their behavior and take over control when necessary.
[0004] Fully autonomous vehicles do not allow for such takeover actions; therefore, the systems responsible for operating the vehicles must be designed for fault tolerance, meaning the systems must handle faults autonomously.
[0005] While handling a malfunction by making an emergency stop is feasible, it is not advisable as it leads to decreased customer satisfaction. On the other hand, a high fault-acceptance rate may result in aimless vehicle operation, leading to a loss of customer confidence. Therefore, solutions are needed to address these situations. Summary of the Invention
[0006] The technical problem to be solved by the present invention is to develop a method and apparatus for configuring a system architecture for autonomous vehicles, as well as the vehicles themselves, wherein the system configuration can be automatically adjusted and adapted.
[0007] According to the present invention, the above-mentioned technical problems are solved by a method having the following characteristics, an apparatus having the following characteristics, and a means of transportation.
[0008] A method for configuring a system architecture for an autonomous vehicle, wherein the system architecture includes multiple application instances and multiple computing nodes, wherein the application instances are distributed across and executed on the computing nodes according to a configuration, wherein the configuration includes mapping application instances to individual computing nodes, wherein sensor data measured by at least one sensor is input to at least a portion of the application instances, and wherein at least a portion of the application instances create and provide control signals for controlling the vehicle, wherein at least one piece of situational information is collected for the current situation, and wherein the configuration, i.e., the mapping of application instances to computing nodes, is adjusted and adapted based on at least one piece of collected situational information, wherein the situational information includes at least one piece of user situational information and / or a user request, and / or wherein the situational information includes at least one piece of environmental information, wherein the at least one piece of environmental information is captured by at least one sensor of the vehicle and / or retrieved by communication with at least one backend server.
[0009] User contextual information includes the health status, metabolic status, and / or attention status of the vehicle user; user requests include the shortest achievable travel time and / or the most comfortable and / or energy-efficient route and / or a certain level of convenience provided by the vehicle during driving.
[0010] The application instance can operate in an active operation mode and at least one passive operation mode. In the active operation mode, the application instance directly affects the control of the vehicle. In the at least one passive operation mode, the application instance operates redundantly together with similar application instances operating in the active operation mode. The application instance operating in the passive operation mode receives the same input data as the application instance operating in the active operation mode and creates the same output data or output signal as the application instance operating in the active operation mode, but does not affect the control of the vehicle.
[0011] An apparatus for configuring a system architecture for an autonomous vehicle, the system architecture including multiple application instances and multiple computing nodes, wherein the application instances are distributed across and executed on the computing nodes according to a configuration, wherein the configuration includes mapping the application instances to individual computing nodes, wherein sensor data measured by at least one sensor is input to at least a portion of the application instances, and wherein at least a portion of the application instances create and provide control signals for controlling the vehicle, the apparatus comprising: a context collector and a reconfigurator, wherein the context collector is configured to collect at least one context information of the current context, and wherein the reconfigurator is configured to adjust and adapt the configuration, i.e., the mapping of application instances to computing nodes, based on at least one collected context information, wherein the context information includes at least one user context information and / or a user request, and / or wherein the context information includes at least one environmental information, wherein at least one Environmental information is captured by at least one sensor of the vehicle and / or retrieved through communication with at least one backend server. User contextual information includes the health status, metabolic status, and / or attention status of the vehicle's user. User requests include the shortest achievable travel time and / or the most comfortable and / or energy-efficient route and / or a certain level of convenience provided by the vehicle during driving. The application instance can operate in an active operation mode and at least one passive operation mode. In the active operation mode, the application instance directly affects the control of the vehicle. In the at least one passive operation mode, the application instance operates redundantly with similar application instances operating in the active operation mode. The application instance operating in the passive operation mode receives the same input data as the application instance operating in the active operation mode and creates the same output data or output signal as the application instance operating in the active operation mode, but does not affect the control of the vehicle.
[0012] A means of transportation, comprising at least one device according to the present invention.
[0013] Advantageous embodiments of the present invention have at least one of the following technical features:
[0014] The contextual information includes at least one vehicle information.
[0015] Adjusting and adapting the configuration includes optimizing the configuration according to at least one optimization criterion.
[0016] Select and / or define at least one optimization criterion based on at least one contextual information.
[0017] The configuration adjustment and adaptation includes selecting and / or defining application instance requirements based on at least one collected contextual information.
[0018] Application instance requirements are defined using implication rules, which are specified and applied using a declarative programming language.
[0019] The configuration adjustment and adaptation includes selecting a set of application instances based on at least one collected contextual information and / or determining the redundancy requirements of the application instances based on at least one collected contextual information and / or determining the hardware and / or software isolation requirements of the application instances based on at least one collected contextual information.
[0020] Adjusting and adapting the configuration includes optimally allocating application instances to compute nodes.
[0021] The allocation includes applying at least one of the following methods to find the optimal allocation: integer linear programming, evolutionary game theory, and reinforcement learning.
[0022] The configuration adjustment and adaptation includes security verification of the adjusted and adapted configuration.
[0023] The method is repeated continuously, allowing the configuration to be constantly adjusted and adapted according to the current context.
[0024] Specifically, a method is proposed for configuring a system architecture for autonomous (or driverless or automatic) vehicles, wherein the system architecture includes multiple application instances and multiple computing nodes, wherein the application instances are distributed across and executed on the computing nodes according to a configuration, wherein sensor data measured by at least one sensor is input to at least a portion of the application instances, and wherein at least a portion of the application instances create and provide control signals for controlling the vehicle, wherein at least one contextual information of the current situation is collected, and wherein the configuration is adjusted and adapted based on at least one collected contextual information.
[0025] Furthermore, an apparatus for configuring a system architecture for autonomous vehicles is proposed, wherein the system architecture includes multiple application instances and multiple computing nodes, wherein the application instances are distributed across and executed on the computing nodes according to a configuration, wherein sensor data measured by at least one sensor is input to at least a portion of the application instances, and wherein at least a portion of the application instances create and provide control signals for controlling the vehicle; a context collector and a reconfigurator are included, wherein the context collector is configured to collect at least one context information of the current context, and wherein the reconfigurator is configured to adjust and adapt the configuration based on at least one collected context information.
[0026] This method and apparatus allow for the automatic reconfiguration, or automatic reconfiguration, of the system architecture of an autonomous vehicle to adapt to changes in the current situation the vehicle is experiencing and / or changes occurring in the system architecture (e.g., failures of application instances and / or compute nodes). This allows for the automatic handling of failures and changes in situation-related requirements. This is achieved by collecting at least one piece of situational information about the situation in which the vehicle and system architecture are currently operating. Adjusting the configuration of the adapted system architecture, i.e., the configuration of application instances and compute nodes, based on the collected at least one piece of situational information means adjusting the configuration according to or taking into account at least one piece of situational information, so that the system architecture adapts to the current situation. In particular, the at least one piece of situational information determines how the configuration is adjusted, with the aim of adapting the configuration to the current situation in the best possible way. In determining the configuration for adjustment and adaptation, at least one piece of situational information is particularly used as one or more input parameters. For example, the configuration can be adjusted and adapted using a set of rules that determine an adjusted or adapted configuration that uses at least one piece of situational information as one or more input parameters.
[0027] An application instance is specifically a process that provides specialized functionality and executes on at least one computing node. For example, an application instance might provide one of the following functions in the field of autonomous driving: environmental perception, localization, navigation, trajectory planning, or prediction of the vehicle's own behavior and / or the behavior of objects in the vehicle environment, etc. To this end, sensor data measured by at least one sensor is input to at least a portion of the application instances, and at least a portion of the application instances create and provide control signals for controlling the vehicle based on this data. In particular, the application instance can operate in active and at least one passive operating mode. Thus, an independent operating mode can be provided, for example, when a faulty application instance is deactivated. In the active operating mode, the application instance directly influences the control of the vehicle. In the at least one passive operating mode, the application instance operates redundantly alongside similar application instances operating in active mode, wherein the application instance operating in passive mode receives the same input data as the application instance operating in active mode and creates the same output data or output signals as the application instance operating in active mode, but does not affect the control of the vehicle. Multiple levels of passive operating modes can be provided. These modes differ only in the time required to switch a passive application instance to an active operating mode. In particular, both active and passive application instances are continuously monitored, so if a failure is detected in one of the instances, countermeasures can be taken, such as changing the configuration.
[0028] Configuration specifically includes mapping application instances to individual compute nodes, i.e., which application instance runs on which compute node. Configuration may also include settings for compute node activation or deactivation and operational status. In particular, configuration can depend on predetermined redundancy requirements, which depend on the functionality of the application instances and the current context. For example, redundancy requirements may demand single or multiple redundancy. In this case, the given functionality is provided by an active instance and one or more passive application instances. Different application scenarios can have different redundancy requirements; for example, pedestrian detection on a highway requires single redundancy, while pedestrian detection in a street where children may play requires multiple redundancy.
[0029] The context includes, in particular, a description of at least some of the parameters and / or attributes that characterize the current situation experienced by the vehicle.
[0030] Means of transport, especially motor vehicles. In principle, means of transport can also be other land, water, air, rail, or space vehicles.
[0031] At least one contextual information may in particular include at least one fault information, wherein the fault information describes a fault that occurred in the application instance and / or compute node. For example, such fault information may describe an application instance that malfunctioned or unexpectedly stopped and / or a faulty or damaged compute node. The configuration can then be adjusted, for example, to adapt the configuration such that the application instance is restarted, possibly on a different compute node, and / or the faulty compute node is shut down and the application instances already running on the faulty compute node are redistributed to the remaining compute nodes.
[0032] A portion of the collector and / or reconfigurator may be provided, alone or in conjunction with other devices, as a combination of hardware and software, such as as program code that executes on a microcontroller or microprocessor.
[0033] In one implementation, the specified contextual information includes at least one user contextual information and / or at least one user request. This allows for configuration changes based on user status and / or user actions, particularly for passengers in a vehicle. User contextual information may include the user's status, such as health, metabolic state, and / or attention level. A user request, especially a passenger request, is a request to achieve a certain state and / or strategy while driving. For example, such a strategy may include the shortest possible travel time and / or the most comfortable and / or energy-efficient route. Additionally, user requests may include a certain level or degree of convenience provided by the vehicle during driving, such as a certain level of entertainment and / or comfort. At least one user contextual information and / or at least one user request are taken into account when the configuration is adjusted and adapted.
[0034] In one implementation, the specified contextual information includes at least one piece of environmental information, wherein the at least one piece of environmental information is captured by at least one sensor of the vehicle and / or retrieved through communication with at least one backend server. The environmental information particularly describes the state of the environment. For example, the at least one piece of environmental information may include one or more of the following: seasonal information, time information (daytime, nighttime, hour, minute, etc.), weather information (sunny, cloudy, inclement, windy, snow, fog, rain, etc.), road conditions (paved highway, rural road, gravel street, etc.), and scene contextual information (rural, rural, urban environment, small city, large city, industrial area, residential area, etc.). The at least one piece of environmental information may be captured by at least one sensor, such as a camera, radar sensor, lidar sensor, ultrasonic sensor, and / or rain sensor. Alternatively or alternatively, the at least one piece of environmental information may be retrieved through communication, for example, with a cloud service or backend server that provides weather and / or traffic information. For example, the configuration may be adapted as a result of contextual information marking the time of day or daylight conditions, for example, by changing the sensing function from an application instance optimized for nighttime sensing to an application instance optimized for daytime sensing.
[0035] In one implementation, the specified context information includes at least one vehicle information. The vehicle information may be captured by at least one sensor of the vehicle and / or retrieved from a vehicle control device, such as the vehicle's Controller Area Network (CAN) bus. The vehicle information may include, for example, battery state of charge (SOC), remaining driving range, power consumption parameters, etc. For example, if the vehicle information indicates that the battery state of charge is below the value required to complete the requested route, then applications providing entertainment functions can be disabled.
[0036] In one implementation, adjusting the configuration includes optimizing the configuration according to at least one optimization criterion. This allows the configuration to be optimized to achieve certain objectives. Such optimization criteria may include: energy efficiency, maximum comfort during driving, use of preferred roads and / or routes, minimum and / or preferred redundancy requirements, etc.
[0037] In an improved implementation, at least one optimization criterion is selected and / or defined based on at least one contextual information. This allows for the automatic selection of at least one optimization criterion. In particular, this allows for an optimal solution for a given scenario, i.e., the current situation. For example, the optimization criterion could be to extend the driving range to complete the planned route without charging or refueling if vehicle information indicates that the battery is low or the fuel level is low.
[0038] In one implementation, configuration adjustment and adaptation includes selecting and / or defining application instance requirements based on at least one collected contextual information. Application instance requirements particularly include CPU and memory requirements.
[0039] In an improved implementation, application instance requirements are defined using implication rules, which are specified and applied using a declarative programming language. This allows for convenient expression and / or encoding of implication rules.
[0040] In one implementation, adjusting the configuration includes selecting a set of application instances based on at least one collected contextual information and / or determining the redundancy requirements of the application instances based on at least one collected contextual information and / or determining the hardware and / or software isolation requirements of the application instances based on at least one collected contextual information. Hardware isolation specifically defines the number of different compute nodes on which redundant application instances must run. Software isolation specifically defines the number of different operating systems (types) on which application instances must run.
[0041] In one implementation, adjusting the configuration includes optimally allocating application instances to compute nodes.
[0042] In an improved design, the allocation includes applying at least one of the following methods to find the optimal allocation: integer linear programming, evolutionary game theory, and reinforcement learning.
[0043] In one implementation, the adaptation of the configuration includes security verification of the adapted configuration. Security verification is performed specifically before the adapted configuration is assigned to the compute node, i.e., before it is enabled. Security verification specifically includes checking whether all redundancy requirements and software and hardware isolation requirements are met.
[0044] In one implementation, the method is repeated continuously, allowing the configuration to be constantly adjusted and adapted to the current situation. This allows for a continuously evolving configuration that adapts to the current circumstances and the needs of the vehicle's passengers, thus ensuring both comfort and safety.
[0045] The corresponding embodiments of the apparatus correspond to the embodiments of the method. The advantages of the apparatus are the same as those of the embodiments of the method.
[0046] Furthermore, a means of transportation is proposed, which includes at least one device according to any of the above embodiments. Attached Figure Description
[0047] The present invention will now be described in more detail with reference to the accompanying drawings, based on preferred exemplary embodiments. In the drawings:
[0048] Figure 1An embodiment of a device for configuring a system architecture for autonomous vehicles is shown;
[0049] Figure 2 A schematic diagram illustrating an implementation of the method is shown, in which three logical layers are used. Detailed Implementation
[0050] Figure 1 An embodiment of the apparatus 1 for configuring the system architecture of an autonomous vehicle 50 is shown.
[0051] The system architecture 20 of the autonomous vehicle 50 includes multiple application instances 21-x and multiple computing nodes 22-x, wherein the application instances 21-x are distributed and executed on the computing nodes 22-x according to the configuration 30. Sensor data 10 measured by at least one sensor 51 is input to at least a portion of the application instances 21-x, and at least a portion of the application instances 21-x create and provide control signals 25 for controlling the vehicle 50.
[0052] For example, application instance 21-x can provide the following functionalities: navigation (21-1), object detection in urban environments (21-2), pedestrian detection (21-3), trajectory planning (21-4), and audio entertainment (21-5). Safety-related application instances 21-x are redundantly executed on multiple compute nodes 22-x (e.g., application instances 21-3, 21-4).
[0053] Device 1 includes collector 2 and reconfigurator 3. Collector 2 and reconfigurator 3 may be provided individually or in combination with other devices as a combination of hardware and software, such as as program code that executes on a microcontroller or microprocessor.
[0054] Collector 2 collects at least one situational information 11 of the current situation. The collected situational information 11 is passed to reconfigurator 3.
[0055] Contextual information 11 may include at least one user contextual information 12 and / or a user request 13.
[0056] Contextual information 11 may include at least one environmental information 14, wherein the at least one environmental information 14 is captured by at least one sensor 51 of the vehicle and / or retrieved by communicating with at least one backend server 60.
[0057] Contextual information 11 may include at least one vehicle information 15. For example, vehicle information 15 may be the vehicle's state of charge (SOC) or the vehicle's remaining driving range. At least one vehicle information 15 may be retrieved, for example, from a vehicle control unit via a controller area network (CAN) bus.
[0058] The reconfigurator 3 adjusts the configuration 30 of the adapted application instance 21-x based on at least one collected contextual information 11. This allows the adapted configuration 30 to be adjusted according to the current context, that is, to map the application instance 21-x to the compute node 22-x, so that the system architecture 20 can best handle the current situation and ensure security.
[0059] In particular, the method is repeated continuously, allowing configuration 30 to be constantly adjusted and adapted according to the current context.
[0060] The adaptation of configuration 30 may include optimizing configuration 30 according to at least one optimization criterion 16. Optimization criterion 16 may be set by the user of vehicle 50, i.e., passenger, operator, and / or owner. This optimization is performed, in particular, by reconfigurator 3. Optimization criterion 16 may be, for example, energy efficiency, comfort, transit time, etc.
[0061] At least one optimization criterion 16 can be selected and / or defined based on at least one contextual information 11. This allows for changes to at least one optimization criterion 16 that result in an optimal configuration 30 for the current context and situation.
[0062] The adaptation of configuration 30 may include selecting and / or defining application instance requirements based on at least one collected contextual information 11. Application instance requirements specifically define a set of application instances 21-x required to handle the current context.
[0063] Application instance requirements can be defined using implication rules, which are specified and applied using a declarative programming language. Therefore, reasoning can be made about which application instances 21-x are necessary and / or preferred in a given situation.
[0064] The configuration adjustment and adaptation 30 may include selecting a set of application instances 21-x based on at least one collected contextual information 11 and / or determining the redundancy requirements of application instances 21-x based on at least one collected contextual information 11 and / or determining the hardware and / or software isolation requirements of application instances 21-x based on at least one collected contextual information 11. This can provide a "tailor-made" configuration 30 for the current context.
[0065] The adaptation of configuration 30 specifically includes the optimized allocation of application instances 21-x to computation nodes 22-x. In particular, allocations that meet the requirements of the adapted configuration 30 are selected. If multiple solutions exist for this allocation problem, further optimization is performed. This allocation can be solved using methods including, for example, integer linear programming, evolutionary game theory, or reinforcement learning.
[0066] The adaptation of configuration 30 specifically includes security verification of the adapted configuration 30 prior to the allocation. Security verification specifically includes verifying whether the adapted configuration 30 meets redundancy requirements and / or software and hardware isolation requirements.
[0067] Figure 2 A schematic overview diagram illustrating one embodiment of the method is shown, in which three logical layers are used: a context layer 100, a reconfiguration layer 200, and an architecture layer 300. The functions of layers 100, 200, and 300 are performed, for example, by a collector and a reconfigurator, or alternatively by a combined device.
[0068] Context layer 100 determines the current context of the vehicle by collecting at least one contextual information 11. Furthermore, it extracts the demands 101 that influence the actions of layers 200 and 300. Examples of parameters influencing the determination of these demands, in the form of contextual information 11, are: task objectives 102, such as the target destination, the required level of entertainment or the type of road and / or journey to be paid for, and environmental conditions, such as current weather conditions and / or road and / or traffic conditions.
[0069] In the first example, the scenario could be: an premium ride on a highway under winter conditions. This scenario information suggests that the required application groups (which may be provided by single or multiple application instances) include, for example, pedestrian detection, trajectory planning that takes into account adverse weather conditions, and recreational applications.
[0070] In the second example, the scenario could be: a low-budget ride in an urban environment under favorable weather conditions. This scenario information 11 suggests that the required application set (potentially provided by a single or multiple application instances) includes pedestrian detection, trajectory planning taking into account favorable weather conditions, and applications for computational tasks received from cloud services.
[0071] The examples above are for illustrative purposes only. In practice, these requirements may be more extensive and demanding.
[0072] From the context information 11, we can also derive the security criticality of the corresponding application, and thus the redundancy requirement 101, as well as other performance parameters.
[0073] As an example, since the probability of encountering pedestrians on highways is much lower than in urban environments, the redundancy of pedestrian detection in the first example can be much lower than in the second example.
[0074] Contextual information 11 can be obtained, in particular, from sensor data captured by at least one sensor of the vehicle and / or through communication with a back-end server and / or through interaction with passengers of the vehicle.
[0075] Application instance requirement 101 can be defined in particular by using implication rules, which are specified and applied using a declarative programming language.
[0076] The requirement 101 determined by the context layer 100 is used as input for the reconfiguration layer 200. The reconfiguration layer 200 evaluates the received requirement 101 and plans further actions considering the current context. These actions may include, for example, selecting a set of applications, determining their redundancy and software and hardware isolation requirements, and optimizing the overall system architecture. The reconfiguration layer performs reconfiguration calculations 201.
[0077] Determining the context-based configuration 30, that is, determining the mapping between application instances and compute nodes that conforms to the current context, is important because placement decisions depend on various parameters.
[0078] The input to the "application placement problem" is a set of application instances and a set of compute nodes. Furthermore, for each application instance and each compute node, a set of parameters is defined, including, for example, performance parameters 202, such as minimum required memory and CPU requirements; and security parameters 203, such as minimum required redundancy and hardware isolation. The output of the application placement problem is a configuration 30 in the form of an allocation, which precisely maps each application instance to a single node.
[0079] To limit the number of valid allocations, constraints can be defined based on specified parameters. Depending on the constraints, there may be no valid allocations, or there may be one or more valid allocations. In the case of distinct solutions, an optimization function 204 can be defined that considers at least one optimization criterion, specifying which allocations are most desirable.
[0080] The optimization function 204 can also depend on the current context. Therefore, a method that allows updating at least one optimization criterion based on the context results in a configuration that adapts well to the current situation.
[0081] To solve the "application placement problem", various optimization methods can be used, such as integer linear programming, evolutionary game theory, or reinforcement learning methods.
[0082] The architecture layer 300 performs tasks responsible for interacting with the system architecture of the vehicle, namely application instances and compute nodes. A primary task of the architecture layer 300 is to apply reconfiguration actions determined by the reconfiguration layer 200.
[0083] The challenge lies in ensuring a rapid, secure, and organized rollout of configurations. Furthermore, it is crucial to always ensure that reconfiguration actions do not compromise security levels. Therefore, security verification must be performed before any configuration rollout.
[0084] Besides application reconfiguration—that is, adjusting and adapting the application's configuration 30—monitoring the status of compute nodes and running application instances is also an important task. Self-awareness, or autonomous operation, requires monitoring the system's status to maintain its operational state. For example, application instances are configured to assess their current performance and report failures. System monitoring generally depends on observing several specific levels of data.
[0085] Regarding safety, different levels may have different requirements for minimum operational capabilities. Since full vehicle autonomy does not include human intervention, classic fault tolerance is insufficient, as errors can have various causes and disruptive effects. Fault handling requires understanding cross-layer relationships. Therefore, system monitoring and self-awareness, or autonomous operation, are cross-layer issues, causing system changes 301 to be fed back to the reconfiguration layer 200, allowing them to influence adjustments and adaptations in configuration 30.
[0086] List of reference numerals
[0087] 1 device
[0088] 2 Context Collector
[0089] 3 Reconfigurator
[0090] 10 Sensor data measured
[0091] 11 Contextual Information
[0092] 12 User Contextual Information
[0093] 13 User Needs
[0094] 14 Environmental Information
[0095] 15. Transportation Information
[0096] 16 Optimization Standards
[0097] 20 System Architecture
[0098] 21-x Application Examples
[0099] 22-x compute nodes
[0100] 25 control signals
[0101] 30 configuration
[0102] 50 vehicles
[0103] 51 sensors
[0104] 60 backend servers
[0105] 100 Context Layers
[0106] 101 requirements
[0107] 200 reconfiguration layer
[0108] 201 Reconfiguration Calculation
[0109] 202 Performance Parameters
[0110] 203 Safety Parameters
[0111] 204 Optimization Features
[0112] 300 architecture layer
[0113] 301 System Changes
Claims
1. A method for configuring a system architecture (20) for an autonomous vehicle (50), wherein, The system architecture (20) includes multiple application instances (21-x) and multiple computing nodes (22-x), wherein the application instances (21-x) are distributed across and executed on the computing nodes (22-x) according to a configuration (30), wherein the configuration (30) includes mapping the application instances (21-x) to individual computing nodes (22-x), wherein sensor data (10) measured by at least one sensor (51) is input to at least a portion of the application instances (21-x), and wherein at least a portion of the application instances (21-x) create and provide control signals (2) for controlling the vehicle (50). 5), wherein at least one contextual information (11) of the current context is collected, and wherein the configuration (30), i.e., the mapping of application instances (21-x) to computing nodes (22-x), is adjusted and adapted based on at least one collected contextual information (11), wherein the contextual information (11) includes at least one user contextual information (12) and / or a user request (13), and / or wherein the contextual information (11) includes at least one environmental information (14), wherein at least one environmental information (14) is captured by at least one sensor (51) of the vehicle (50) and / or retrieved by communicating with at least one backend server (60). User contextual information includes the health status, metabolic status, and / or attention status of the vehicle user; user requests include the shortest achievable travel time and / or the most comfortable and / or energy-efficient route and / or a certain level of convenience provided by the vehicle during driving. The application instance can operate in an active operation mode and at least one passive operation mode. In the active operation mode, the application instance directly affects the control of the vehicle. In the at least one passive operation mode, the application instance operates redundantly together with similar application instances operating in the active operation mode. The application instance operating in the passive operation mode receives the same input data as the application instance operating in the active operation mode and creates the same output data or output signal as the application instance operating in the active operation mode, but does not affect the control of the vehicle.
2. The method according to claim 1, wherein, The contextual information (11) includes at least one vehicle information (15).
3. The method according to claim 1 or 2, wherein, The adjustment and adaptation of the configuration (30) includes optimizing the configuration (30) according to at least one optimization criterion (16).
4. The method according to claim 3, wherein, Select and / or define at least one optimization criterion (16) based on at least one contextual information (11).
5. The method according to claim 1 or 2, wherein, The adaptation of the configuration (30) includes selecting and / or defining application instance requirements (101) based on at least one collected contextual information (11).
6. The method according to claim 5, wherein, Application instance requirements (101) are defined by using implication rules, which are specified and applied using a declarative programming language.
7. The method according to claim 1 or 2, wherein, The adjustment and adaptation of the configuration (30) includes selecting a set of application instances (21-x) based on at least one collected context information (11) and / or determining the redundancy requirements of the application instances (21-x) based on at least one collected context information (11) and / or determining the hardware and / or software isolation requirements of the application instances (21-x) based on at least one collected context information (11).
8. The method according to claim 1 or 2, wherein, The adaptation of the configuration (30) includes optimally allocating application instances (21-x) to compute nodes (22-x).
9. The method according to claim 8, wherein, The allocation includes applying at least one of the following methods to find the optimal allocation: integer linear programming, evolutionary game theory, and reinforcement learning.
10. The method according to claim 1 or 2, wherein, The adjustment and adaptation of configuration (30) includes security verification of the adjusted and adapted configuration (30).
11. The method according to claim 1 or 2, wherein, The method is repeated continuously, so that the configuration is constantly adjusted and adapted according to the current situation (30).
12. An apparatus (1) for configuring a system architecture (20) of an autonomous vehicle (50), the system architecture (20) comprising multiple application instances (21-x) and multiple computing nodes (22-x), wherein, Application instances (21-x) are distributed across computing nodes (22-x) and executed on computing nodes (22-x) according to configuration (30), wherein configuration (30) includes mapping application instances (21-x) to individual computing nodes (22-x), wherein sensor data (10) measured by at least one sensor (51) is input to at least a portion of the application instances (21-x), and wherein at least a portion of the application instances (21-x) create and provide control signals (25) for controlling the vehicle (50). The apparatus includes: a context collector (2) and a reconfigurator (3), wherein the context collector (2) is configured to collect at least one context information (11) of the current context, and wherein the reconfigurator (3) is configured to adjust and adapt the configuration (30), i.e., the mapping of application instances (21-x) to computing nodes (22-x), based on at least one collected context information (11), wherein the context information (11) includes at least one user context information (12) and / or a user request (13), and / or wherein, Contextual information (11) includes at least one environmental information (14), wherein at least one environmental information (14) is captured by at least one sensor (51) of the vehicle (50) and / or retrieved by communication with at least one back-end server (60), user contextual information includes the health status, metabolic status and / or attention status of the user of the vehicle, user requests include the shortest achievable transportation time and / or the most comfortable and / or energy-saving route and / or a certain degree of convenience provided by the vehicle during driving, wherein the application instance can operate in an active operation mode and at least one passive operation mode, wherein in the active operation mode, the application instance directly affects the control of the vehicle, and in the at least one passive operation mode, the application instance operates redundantly together with similar application instances operating in the active operation mode, wherein the application instance operating in the passive operation mode receives the same input data as the application instance operating in the active operation mode and creates the same output data or output signal as the application instance operating in the active operation mode, but does not affect the control of the vehicle.
13. A means of transport (50) comprising at least one device (1) according to claim 12.
Citation Information
Patent Citations
Autonomous Vehicle Interface System
US20150331422A1