Method and system for handover from ads functionality to driver of vehicle
By assessing and monitoring the driver's operational capabilities using the Precautionary Safety Module (PCS) and dynamically adjusting the Precautionary Constraints, the problem of inappropriate control transfer caused by insufficient driver preparation in autonomous driving systems is solved, achieving safe and reliable driver handover.
Patent Information
- Authority / Receiving Office
- CN · China
- Patent Type
- Patents(China)
- Current Assignee / Owner
- 哲内提
- Filing Date
- 2021-04-08
- Publication Date
- 2026-04-17
AI Technical Summary
Existing autonomous driving systems lack reliable and safe solutions for the handover process from automatic driving to manual driver control, which can lead to improper control transitions, especially when the driver is not prepared.
The Precautionary Safety Module (PCS) assesses the driver's operational capabilities, provides partial control and monitors their manual operations, and dynamically adjusts the precautionary constraints to ensure handover within safety margins.
It provides a direct assessment of the driver's operational capabilities, reduces the risk of improper control transitions, and enables a simplified and efficient handover from autonomous driving to manual operation.
Smart Images

Figure CN113548065B_ABST
Abstract
Description
[0001] Cross-reference to related applications
[0002] This patent application claims priority to European patent application No. 20168622.7, filed on April 8, 2020, entitled “METHODS AND SYSTEMS FOR HAND-OVER FROM AND ADS FEATURE TO A DRIVER OF AVEHICLE”, which is hereby assigned to the assignee and is expressly incorporated herein by reference. Technical Field
[0003] This disclosure relates to automated driving systems (ADS) for highway vehicles such as cars, buses, and trucks. More specifically, this disclosure relates to methods and systems for managing the handover of ADS functions to the driver of the vehicle. Background Technology
[0004] In recent years, the development of autonomous vehicles has been booming and many different solutions are being explored. Today, development is taking place in different technical areas within these fields, encompassing both Autonomous Driving (AD) and Advanced Driver Assistance Systems (ADAS) (i.e., semi-autonomous driving). One such area is ensuring the safe and reliable handover of the driver from ADS functions to the vehicle.
[0005] It is envisioned that during autonomous driving, vehicle occupants will be able to at least partially focus on other activities. However, no fully autonomous solution is currently available that can perform autonomous driving in all scenarios and on all road sections. Therefore, at least when the Automated Driving System (ADS) function identifies an upcoming road or traffic scenario where its performance may be limited, the function will then request the occupant (i.e., the driver) to take over control of the vehicle. This can also be triggered by one or more sensors or by other subsystems of the vehicle detecting performance degradation or complete failure of the ADS function, thus initiating a handover request to the driver. It is also envisioned that the request to take over vehicle control could be a remote request, for example, due to an accident that has occurred in the vehicle's planned route. The takeover of vehicle control is often referred to as handover or transfer of control.
[0006] Therefore, new and improved solutions are needed to ensure that drivers of autonomous vehicles (i.e., vehicles operating with ADS functions at an automation level of 3 or (L3) or higher, according to the SAE J3016 level of driving automation) are ready to regain control when automation needs to be terminated. Summary of the Invention
[0007] Therefore, the purpose of this disclosure is to provide a method, computer-readable storage medium, system, and vehicle including such a system for managing the handover of a driver from an automated driving system (ADS) to a vehicle, which mitigates all or at least one of the disadvantages of currently known solutions.
[0008] Specifically, the purpose of this disclosure is to provide a reliable and secure solution for the transfer of drivers from ADS to vehicles.
[0009] This objective is achieved by means of a method, computer-readable storage medium, system for managing the handover of a driver from an automated driving system (ADS) to a vehicle as defined in the appended claims, and a vehicle including such a system. The term "exemplary" will be understood in this context as serving as an example, illustration, or illustration.
[0010] According to a first aspect of this disclosure, a method is provided for managing the handover of a driver from an automated driving system (ADS) to a vehicle, wherein the ADS includes an ADS function associated with a first set of preemptive constraints among a plurality of preemptive constraints, which are imposed by a preemptive safety (PCS) module when the ADS function controls the vehicle. The method includes: obtaining a request to deactivate the ADS function; and, based on the obtained request, providing partial control of the vehicle to the driver to enable manual driving operation of the vehicle. The partial control includes (at least) the use of steering, acceleration, and braking of the vehicle when the driver has partial control of the vehicle and the PCS module imposes a second set of preemptive constraints on the driver. Furthermore, the method includes monitoring manual driving operation of the vehicle for a period of time, and evaluating the monitored manual driving operation of the vehicle against the second set of preemptive constraints during that period of time. Then, based on the evaluation, the method includes: if the manual driving operation passes the evaluation, deactivating the second set of preemptive constraints at the end of the period of time; or if the manual driving operation fails the evaluation, providing control of the vehicle to the ADS. By activating the second set of pre-emptive restraints, the driver is given "full control" over the vehicle.
[0011] Current known criteria for detecting when a driver is not actively driving the vehicle are based on observing the driver's eyes. This can be understood as an indirect assessment of the driver's ability to control the vehicle. The method disclosed herein provides a direct assessment of the driver's actual ability to safely control the vehicle, thus reducing the risk of an "unjustified" transfer of control to the driver (i.e., to an unprepared driver). Assuming that drivers may often be unable to properly assess their own capabilities upon deactivation requests, a solution is needed (and is disclosed herein) for an automatic and direct assessment of the driver's ability to take over control. Moreover, the principles disclosed herein can effectively serve as an additional solution, rather than a replacement, for other currently known solutions for assessing a driver's ability to take over control of the vehicle, thereby improving the overall confidence of the assessment.
[0012] In short, the method disclosed herein utilizes the same functionality responsible for assessing the driver's readiness to take over control of the vehicle, thereby ensuring that the ADS (Autonomous Driving System) operates within a preset safety margin during autonomous driving. This provides a simplified and efficient design for the handover function from autonomous driving (AD) to manual operation of the vehicle. Therefore, instead of integrating and installing a separate system into the vehicle, existing functionality is adapted and partially reused.
[0013] According to a second aspect of this disclosure, a non-transitory computer-readable storage medium is provided for storing one or more programs configured to be executed by one or more processors of a vehicle control system, the one or more programs including instructions for performing a method according to any embodiment of the present disclosure. Similar advantages and preferred features are presented regarding this aspect of the disclosure as discussed in the first aspect of the disclosure above.
[0014] As used herein, the term "non-transitory" is intended to describe computer-readable storage media (or "memory") other than those that transmit electromagnetic signals, but is not intended to further limit the types of physical computer-readable storage devices covered by the phrases computer-readable media or memory. For example, the terms "non-transitory computer-readable media" or "tangible memory" are intended to include types of storage devices that do not necessarily permanently store information, such as random access memory (RAM). Program instructions and data stored on tangible computer-accessible storage media in a non-transitory form can be transmitted via transmission media or signals such as electronic, electromagnetic, or digital signals that can be transmitted via communication media such as networks and / or wireless links. Thus, as used herein, the term "non-transitory" is a limitation on the medium itself (i.e., tangible, not signaling) as opposed to a limitation on the persistence of data storage (e.g., RAM versus ROM).
[0015] Furthermore, according to a third aspect of this disclosure, a system is provided for managing the handover of a driver from an Adaptive Driver Controller (ADS) to a vehicle, wherein the ADS includes an ADS function. The system includes a Precautionary Safety (PCS) module configured to apply a first set of constraints to the ADS function when it controls the vehicle. The system further includes control circuitry configured to: (when the ADS function is actively controlling the vehicle) acquire a request to deactivate the ADS function, and based on the acquired request, provide partial control of the vehicle to the driver to enable manual driver operation of the vehicle. Partial control includes the use of steering, acceleration, and braking of the vehicle when the driver has partial control of the vehicle and the PCS module applies a second set of precautionary constraints to the driver. The control circuitry is further configured to: monitor manual driver operation of the vehicle for a period of time, evaluate the monitored manual driver operation of the vehicle against the second set of precautionary constraints during that period, and deactivate the second set of precautionary constraints if the manual driver operation passes the evaluation, or provide control of the vehicle to the ADS if the manual driver operation fails the evaluation. With respect to this aspect of the disclosure, similar advantages and preferred features are proposed as in the first aspect of the disclosure previously discussed.
[0016] Furthermore, according to a fourth aspect of this disclosure, a vehicle is provided according to any of the embodiments disclosed herein, comprising: an ADS module including ADS functions configured to control the steering, acceleration, and braking of the vehicle within a predefined operating design domain (ODD); and a system for managing the handover of the driver from the ADS to the vehicle. Similar advantages and preferred features are presented regarding this aspect of the disclosure, as discussed previously in the first aspect of the disclosure.
[0017] Further embodiments of this disclosure are defined in the dependent claims. It should be emphasized that, when used in this specification, the term "comprising / including" is used to specify the presence of a stated feature, integer, step, or component. It does not preclude the presence or addition of one or more other features, integers, steps, components, or groups thereof.
[0018] These and other features and advantages of this disclosure will be further clarified below with reference to the embodiments described herein. Attached Figure Description
[0019] Further objects, features, and advantages of embodiments of this disclosure will become apparent from the following detailed description, with reference to the accompanying drawings, in which:
[0020] Figure 1 This is a schematic flowchart representation of a method for managing the handover of a driver from an ADS function to a vehicle, according to an embodiment of the present disclosure.
[0021] Figure 2 This is a schematic block diagram representation of a system for managing the handover of a driver from an ADS function to a vehicle, according to an embodiment of the present disclosure.
[0022] Figure 3 This is a set of schematic diagrams of a vehicle's HMI, including a system for managing the handover of ADS functions to the driver of the vehicle, according to embodiments of this disclosure.
[0023] Figure 4 This is a schematic side view of a vehicle including a system for managing the handover of the driver from the ADS function to the vehicle, according to an embodiment of the present disclosure. Detailed Implementation
[0024] Those skilled in the art will understand that the steps, services, and functions explained herein can be implemented using separate hardware circuitry, software running in conjunction with a programmable microprocessor or a general-purpose computer, one or more application-specific integrated circuits (ASICs), and / or one or more digital signal processors (DSPs). It will also be understood that, when describing the methods of this disclosure, they can also be embodied in one or more processors and one or more memories coupled to the one or more processors, wherein the one or more memories store one or more programs that, when executed by the one or more processors, perform the steps, services, and functions disclosed herein.
[0025] Figure 1 This diagram illustrates a schematic flowchart of a method 100 for managing the handover of a driver from an automated driving system (ADS) to a vehicle, according to an embodiment of the present disclosure. The ADS includes functions according to SAE J3016 levels for driving automation of on-road vehicles, preferably Level 3 (L3) or higher. The ADS functions can be, for example, traffic jam navigation, highway navigation, or any other SAE J3016 Level 3+ (L3+) ADS function.
[0026] Furthermore, the ADS function is associated with a first set of preemptive constraints among multiple preemptive constraints, which are imposed by the Preemptive Safety (PCS) module when the ADS function controls the vehicle. The PCS module can be interpreted as a monitoring system responsible for setting a set of constraints or safety margins for controlling the vehicle's physical components, such as speed limits, distance to the guiding vehicle, lane positioning, braking timing, cornering speed, cornering exit acceleration, clearance size for lane changes, execution time for lane changes, distance to the road edge, steering angle limits, lateral acceleration limits, lateral pull limits, longitudinal pull limits, lateral distance to other objects, and so on. The first set of preemptive constraints may be specific to a type of ADS function, a type of vehicle's environmental scenario, etc. Therefore, the first set of preemptive constraints can be selected from multiple preemptive constraints based on the type of ADS function and / or environmental scenario.
[0027] Furthermore, ADS functions can be defined by an Operational Design Domain (ODD), meaning each ADS function can be associated with an ODD. An Operational Design Domain (ODD) will be understood as a description of the operational domain in which an automated or semi-automated driving system (i.e., AD or ADAS) is designed to function, including but not limited to geography, roadway (e.g., type, surface, geometry, edges, and markings), environment, connectivity, surrounding objects, and speed limits. In other words, an ADS function can be associated with a specific environmental scenario and is configured only to operate within an environment that satisfies a set of scenario parameters; examples include traffic jams, highway / expressway cruising, etc. The ODD can further define the permissible exposure rates to driving scenarios and their dynamics (e.g., traffic lights, intersections, jaywalking pedestrians, insertions, snow, ice, large animals, etc.). Scenario parameters can be obtained, for example, from sensor data from sensors mounted on one or more vehicles, or from a remote server, or from communication data obtained from another vehicle via a vehicle-to-vehicle (V2V) communication protocol. Scene parameters can include, for example, road type, weather data, speed limits, traffic density, number of available lanes, presence of road works, and so on.
[0028] Continuing, method 100 includes obtaining 101 a request to deactivate the ADS function. This request can be, for example, a driver-initiated request obtained from a human-machine interface (HMI) or a machine-initiated request. A driver-initiated request can be obtained, for example, from an input device (e.g., a button on an entertainment system) or from a manual-override detection where the driver of the vehicle actively occupies the steering wheel, accelerator, or brake. Moreover, a machine-initiated request can be, for example, based on sensor data indicating exit from the ODD associated with the ADS function. More specifically, by means of one or more sensors, it can be detected that the vehicle is about to exit the ODD (where the currently active ADS function is configured for that ODD), and thus a machine-initiated handover request is initiated. This can be referred to as “ODD-exit.” More specifically, in today's context, unless this is confirmed by the driver, the vehicle may not hand over control to the driver (or even partially hand over control). Therefore, a “machine-initiated” handover can be interpreted as a two-step process in which the vehicle requests the driver to request manual control of the vehicle. Another example of an ODD exit event could be a signal generated by an algorithm configured to limit the exposure of one or more dynamic parameters of a scene (e.g., intersections, jaywalkers, snow, ice, traffic lights, etc.) rather than completely eliminating exposure to these dynamics.
[0029] Additionally, method 100 includes providing partial control of the vehicle to the driver 102 upon receiving or based on a request 101, thereby enabling manual driver operation of the vehicle. Partial control (at least) includes the use of steering, acceleration, and braking of the vehicle when the driver has partial control of the vehicle and the PCS module applies a second set of preemptive constraints from a plurality of preemptive constraints 103 to the driver. The second set of preemptive constraints may, for example, be a subset of the first set of preemptive constraints. More specifically, the second set of preemptive constraints is preferably less restrictive or less stringent than the first set of preemptive constraints. However, in some embodiments, the first and second sets of constraints may be the same. In other words, when “Autonomous Driving Comfort Control” is deactivated, partial control is given to the driver through the use of primary controls (steering and throttle / brake), and some or all of the safety limits from preemptive safety are always active and under control, i.e., the driver is not allowed to violate them. In some embodiments, partial control includes the use of at least one of the vehicle's steering, acceleration, and braking when the driver has partial control over the vehicle and the PCS module applies a second set of pre-emptive constraints of a plurality of pre-emptive constraints to the driver.
[0030] Furthermore, a second set of preemptive constraints can be dynamically set based on the type of request received (driver-initiated or machine-initiated) and the type of driver-initiated request. Regarding the latter, the second set of preemptive constraints can differ depending on whether the handover request originates from a driver's button press or from the driver actively gaining control of the vehicle (e.g., via steering input).
[0031] In some embodiments, the second set of preemptive constraints includes a subset of preemptive constraints in the first set of preemptive constraints, a smaller number of preemptive constraints compared to the first set of preemptive constraints, or a higher threshold for at least one preemptive constraint in the first set of preemptive constraints. A higher threshold for one or more preemptive constraints should be interpreted in this context as being more permissive or more tolerant compared to the first set of preemptive constraints. For example, the first set of preemptive constraints may include, for instance, a first gap range allowing a vehicle to change lanes to overtake a vehicle ahead, while the second set of preemptive constraints may include a second gap range (higher than the first gap range) or not include any gap range at all. In yet another example, the first set of constraints may include a first speed limit allowed for vehicles, while the second set of constraints may include a second speed limit allowed for vehicles (higher than the first speed limit), or alternatively, not include any speed limit constraints at all.
[0032] Method 100 further includes monitoring manual driver actions on the vehicle over a (predefined) time period. The time period can be, for example, in the range of 10 to 60 seconds. Moreover, the time period can be dynamically set based on the type of (deactivated) ADS function, the vehicle's current ODD, the driver profile (experience level), etc. For example, the time period can be set based on the duration of time the ADS was active before a request to deactivate the ADS function. For example, the time period can be longer if the ADS function was previously activated for X minutes, where X > Y, compared to if the ADS function had been activated for Y minutes previously. Additionally, during a time period, the monitored manual driver actions 104 are evaluated 105 against a second set of pre-emptive constraints. In some embodiments, monitoring 104 and evaluation 105 can be understood as parallel steps, i.e., performed substantially simultaneously.
[0033] In this context, assessment 105 involves monitoring whether the partial control already provided to the driver 102 violates any of the constraints included in the second set of preemptive constraints. For example, if the second set of preemptive constraints includes a constraint indicating a minimum distance to the edge of the road, and if the driver exceeds that minimum distance, then the PCS module can be configured to infer that the driver is unfit to operate the vehicle and generate a failure result for assessment 105. Another way to describe this process is that the condition for the transfer of control from the ADS function to the driver is that the driver is able to control the vehicle within the safety margins articulated by the ADS. Therefore, the same module or function responsible for monitoring the ADS function's ability to safely operate the vehicle is used to perform the assessment of the driver's ability to safely operate the vehicle. This provides a less complex and more efficient solution compared to having a separate "driver assessment" function. Moreover, when used in conjunction with a driver monitoring system, the solution proposed herein adds further redundancy to the overall driver suitability assessment process.
[0034] Therefore, method 100 further includes: if manual driver operation passes evaluation 105, then at the end of a time period, deactivating the second set of preemptive constraints 106. In other words, if the driver passes evaluation 105, he is given full control of the vehicle without the second set of preemptive constraints being activated. However, in some embodiments, other safety constraints may still be active (e.g., lane support systems (LSS) such as lane keeping assist (LKA), or collision warning systems), but the difference is that manual driver operation is not evaluated for these safety constraints.
[0035] However, if manual driver operation fails evaluation 105, method 100 includes the step of providing control of the vehicle 107 to the vehicle's ADS. Providing control of the vehicle 107 to the vehicle's ADS may, for example, include restoring control of the vehicle for a (previously activated) ADS function, or bringing the vehicle into a minimum risk condition (MRC). Regarding the latter, this could be a situation where, for example, the vehicle is about to leave its ODD with the ADS function configured, the option to restore control of the vehicle for that ADS function may not be available. However, in some embodiments, the step of providing control of the vehicle 107 to the automation system includes providing control of the vehicle to another ADS function of the vehicle. For example, if the vehicle transitions from a traffic jam scenario to a highway cruise scenario, and evaluation 105 is performed during the transition from the traffic jam scenario to the highway cruise scenario, then the step of providing control of the vehicle 107 may include providing control of the vehicle to the vehicle's highway navigation ADS function. Therefore, in some embodiments, the “deactivated” ADS function is set to “passive mode” or “sleep mode”, where it still runs in the background while the driver has partial control of the vehicle, thereby enabling the driver to quickly regain control of the vehicle based on assessment 105.
[0036] In some embodiments, the second set of preventative constraints includes different types of preventative constraints, where violations of preventative constraints during monitoring 104 and assessment 105 lead to different outcomes depending on the type of preventative constraint being violated. For example, the second set of preventative constraints comprises two sets of constraints, each associated with a specific type (e.g., critical and non-critical), so a violation of a "critical" preventative constraint results in immediate transfer back to the ADS, while a violation of a "non-critical" preventative constraint results in a reduced number of assessments and / or an extension of the time period used for monitoring 104 and assessment 105. In the latter scenario, the ADS can perform interventions (e.g., ensuring the vehicle remains in the lane) without abruptly terminating the "driver assessment / rating."
[0037] Furthermore, in some embodiments, the step of evaluating the driver's actions monitored by 105 includes evaluating the manual driver actions monitored by 104 "continuously" over a period of time. The term "continuously" is interpreted broadly in this context and will not be limited to the mathematical definition of the term "continuous," but includes evaluation by means of sampling digital signals and data. More specifically, the term "continuous evaluation" will be understood as evaluating the driver's performance during the (full) time period or at least until a violation of the second set of preemptive constraints is detected. The latter option provides for a safer handover of performance because the "evaluation" can be interrupted upon detection of a violation of the second set of preemptive constraints, i.e., if the driver is detected to have violated one or more safety-critical constraints. In such a case, the ADS can be reactivated or the Dynamic Driving Task (DDT) can be activated in reverse, which brings the vehicle into a minimum risk condition (MRC), thereby reducing the risk of collision with external objects or vehicles veering off the road. Thus, evaluation 105 does not necessarily have to run for the entire time period if a violation of the second set of preemptive constraints is detected during evaluation 105.
[0038] A vehicle's Adaptive Controller (ADS) typically includes an MRC (Mean Change Registry) function or MRC protocol, which, if configured, brings the vehicle to a position or condition where a given trip / action cannot or should not be completed, thereby minimizing the risk of conflict or accident. In this context, this can be initiated when a handover to the driver cannot / should not be completed.
[0039] Precautionary safety can be understood as part of the autonomous driving (AD) control software, which continuously assesses safety margins for lateral and longitudinal control based on all available sensor data. When AD is normally activated, precautionary safety serves to ensure safe driving of the AD system by drawing boundaries that other control layers (of AD) must adhere to. The inventors recognize that it can be advantageous to utilize this function to provide a direct assessment of the driver's ability to safely control the vehicle, and thus reduce the risk of an "unjustified" transfer of control to an unprepared / unfit driver. Therefore, in contrast to other solutions where indirect assessments rely on methods such as gaze monitoring to evaluate driver ability, this disclosure provides a direct assessment of the driver's ability to operate the vehicle. In other words, the methods and systems proposed herein rely on the transfer of control from the ADS to the driver conditioned on the driver's ability to control the vehicle within the safety margins defined by the ADS. In other words, the same function responsible for ensuring that the ADS operates within preset safety margins during autonomous driving is used to assess the driver's readiness to take over control of the vehicle.
[0040] The executable instructions that perform these functions may optionally be included in a non-transitory computer-readable storage medium or in other computer program products configured for execution by one or more processors.
[0041] Figure 2 This is a schematic block diagram representation of a system 20 for managing the handover of ADS 20 to driver 22 in a vehicle. ADS includes ADS functions, summarized herein as a path planning or trajectory planning module 21. Furthermore, system 20 has a proactive safety (PCS) module 23 configured to apply a first set of proactive constraints to ADS function 21 when the ADS function controls the vehicle. This is indicated by the connection between ADS function 21 via PCS module 23 and vehicle control box 24, which monitors the execution of the ADS function against the first set of proactive constraints. The first set of proactive constraints may, for example, be a subset stored in memory or database 25, illustrated herein as a separate block 25, but may be an integrated part of PCS module 23. As mentioned, PCS module 23 can be understood as part of ADS software that continuously evaluates safety margins for lateral and longitudinal control based on all available sensor data.
[0042] For completeness Figure 2 The vehicle's location and other peripheral objects and modules are indicated in the diagram. Therefore, the vehicle may further include a positioning module (e.g., a GNSS unit) for providing the vehicle's location data (i.e., geographic location) 27 and a map module for providing an HD map 28. The vehicle's location 27 and HD map data 28 are used as inputs to a waypoint generator 30, which is configured to generate waypoints for the path planning module 21. The vehicle may further include a perception system comprising one or more sensor devices configured to monitor the vehicle's surroundings. In this context, the perception system is understood as a system responsible for acquiring raw sensor data from sensors such as cameras, LiDAR and RADAR, ultrasonic sensors, etc., and converting this raw data into scene understanding. Sensor data 29 is used in conjunction with map data 28 to form / generate a drivable area 31, thereby implementing some constraints for the path planning module 21. Furthermore, sensor data 29 is used as input to the MRC module 26 of the ADS system 20, enabling reverse parking maneuvers to be performed in the event of an impending collision. However, the MRC function 26 can be provided as a whole as a separate module / function or as an external component of the ADS system 20 in several parts.
[0043] System 20 further includes control circuitry configured to (when the ADS function is activated) acquire a request to deactivate ADS function 21. As mentioned, the request can be a driver-initiated request acquired from the Human-Machine Interface (HMI) or a machine-initiated request. Additionally, system 20 is configured to provide partial control of the vehicle to driver 22 based on the acquired request, thereby enabling manual driver operation of the vehicle. Partial control includes the use of steering, acceleration, and braking of the vehicle when driver 22 has partial control of the vehicle and the PCS module applies a second set of pre-emptive constraints to driver 23.
[0044] Additionally, the control circuitry is configured to monitor manual driver actions for a period of time and evaluate these actions against a second set of preemptive constraints during that time period. The time period can be predefined or dynamically set based on the vehicle's current environmental scenario and can range from 10 to 60 seconds. This is indicated via a connection between the "driver" 22 of the PCS module 23 and the vehicle control box 24, which operates to monitor and evaluate the manual driver actions against the second set of preemptive constraints. The control circuitry is then configured to deactivate the second set of preemptive constraints if the manual driver actions pass the evaluation, i.e., to provide "full control" of the vehicle to the driver, as indicated by the disconnected arrow connection. However, the control circuitry is also configured to provide control of the vehicle to the ADS 20 if the manual driver actions fail the evaluation. Therefore, at the end of a time period or upon detection of a violation of the second set of preemptive constraints, the control circuitry is configured to provide full control to the driver 22, restore the ADS function 21, or initiate a safety protocol (e.g., MRC).
[0045] continue, Figure 3 Three schematic user interfaces (UIs) 35-37, displayed on a display device according to certain embodiments of the present disclosure, are shown. Therefore, the system's control circuitry is further configured to display on the display device user interfaces 35-37 via electronic devices with display devices. The electronic devices with displays may be, for example, displays of an in-vehicle entertainment and news system or displays of the vehicle's dashboard. More specifically, the user interfaces include a graphical representation of a first user interface 35 when the vehicle is controlled by the ADS function, a graphical representation of a second user interface 36 when the driver has partial control of the vehicle, and a graphical representation of a third user interface 37 when a second set of pre-emptive constraints is deactivated (i.e., when the driver has "full control" of the vehicle). The first, second, and third user interfaces 35-37 are different, thus instructing the driver when different modes are activated.
[0046] More specifically, the second user interface 36—that is, the interface displayed when the driver has “partial control”—is preferably very similar to the third user interface 37, except that the second user interface 36 has at least one graphical element indicating that the driver is “in evaluation.” This is to improve human-machine interaction and avoid situations where the driver does not understand why he / she has not been given full control of the vehicle. More specifically, by indicating that the driver is in evaluation, it can increase the driver’s attention in critical situations (such as handover situations) and ensure the driver’s safe operation of the vehicle after the “passive period.” Moreover, the second user interface may include one or more graphical elements that illustrate a second set of preemptive constraints, such as graphical representations of road edge boundaries, permissible distances to vehicles ahead, etc. The graphical elements in the second user interface can further indicate the development of the evaluation by, for example, indicating that the driver is exhibiting poor steering stability, braking too late, etc.
[0047] Figure 4 This is a schematic side view of a vehicle according to any of the embodiments disclosed herein, the vehicle including: an ADS function configured to control the vehicle's steering, acceleration, and braking within a predefined Operational Design Domain (ODD); and a system 20 managing the handover from the ADS function to the vehicle's driver. The vehicle 1 further includes a perception system 6 and a positioning system 5. The perception system 6 is understood in this context as a system responsible for acquiring raw sensor data from sensors 6a, 6b, 6c such as cameras, LiDAR and RADAR, ultrasonic sensors, etc., and converting this raw data into scene understanding. The positioning system 5 is configured to monitor the vehicle's geographic location and heading, and may be in the form of a Global Navigation Satellite System (GNSS) such as GPS. However, the positioning system may alternatively be implemented as Real-Time Kinematic (RTK) GPS to improve accuracy.
[0048] The control system 20 includes one or more processors 11, a memory 12, a sensor interface 13, and a communication interface 14. The processor 11 may also be referred to as control circuitry 11, control unit 11, controller 11, or control circuitry 11. The control system 20 preferably includes a number of software / hardware modules as described above, collectively referred to herein as "control circuitry 11". Control circuitry 11 is configured to execute instructions stored in memory 12 to perform a method for controlling a vehicle according to any of the embodiments disclosed herein. In other words, the memory 12 of the control system 10 may include one or more (non-transitory) computer-readable storage media for storing computer-executable instructions that, when executed by one or more computer processors 11, enable the computer processors 11 to perform, for example, the techniques described herein. Memory 12 may optionally include high-speed random access memory, such as DRAM, SRAM, DDR RAM, or other random access solid-state memory devices; and may include non-volatile memory, such as one or more disk storage devices, optical disk storage devices, flash memory devices, or other non-volatile solid-state memory devices.
[0049] More specifically, control circuit 11 is configured to receive a request to deactivate the ADS function, and based on the received request, to provide partial control of the vehicle to the driver, thereby enabling manual driving operation of the vehicle. Partial control includes the use of steering, acceleration, and braking of the vehicle when the driver has partial control of the vehicle and the PCS module applies a second set of preemptive constraints to the driver among multiple preemptive constraints. Control circuit 11 is further configured to: monitor manual driving operation of the vehicle for a period of time, evaluate the monitored manual driving operation of the vehicle against the second set of preemptive constraints during that period, and deactivate the second set of preemptive constraints if the manual driving operation passes the evaluation, or provide control of the vehicle to the ADS if the manual driving operation fails the evaluation.
[0050] Additionally, vehicle 1 can connect to external network 2 via, for example, a wireless link (e.g., for retrieving map data). The same or other wireless links can be used to communicate with other vehicles 2 nearby or with local infrastructure components. Cellular communication technologies can be used for long-distance communication, such as with external networks, and if the cellular communication technology used has low latency, it can also be used for communication between vehicles, vehicle-to-vehicle (V2V), and / or vehicle-to-infrastructure (V2X). Examples of cellular radio technologies are GSM, GPRS, EDGE, LTE, 5G, 5G NR, and so on, including future cellular solutions. However, some solutions use mid-to-short-range communication technologies, such as wireless local area networks (LANs), for example, solutions based on IEEE 802.11. ETSI is working on cellular standards for vehicle communication and, due to low latency, high bandwidth, and efficient processing of communication channels, considers 5G, for example, as a suitable solution.
[0051] This disclosure has been presented above with reference to specific embodiments. However, other embodiments beyond those described above are possible and within the scope of this disclosure. Different method steps beyond those described above, performed by hardware or software, may be provided within the scope of this disclosure. Thus, according to exemplary embodiments, a non-transitory computer-readable storage medium is provided storing one or more programs configured to be executed by one or more processors of a vehicle control system, the one or more programs including instructions for performing the methods according to any of the embodiments discussed above. Alternatively, according to another exemplary embodiment, a cloud computing system can be configured to perform any of the methods presented herein. The cloud computing system may include distributed cloud computing resources that jointly perform the methods presented herein under the control of one or more computer program products.
[0052] Generally speaking, computer-accessible media can include any tangible or non-transitory storage medium or memory medium, such as electronic, magnetic, or optical media—for example, a disk or CD / DVD-ROM coupled to a computer system via a bus. As used herein, the terms “tangible” and “non-transitory” are intended to describe computer-readable storage media (or “memory”) other than those that transmit electromagnetic signals, but are not intended to further limit the types of physical computer-readable storage devices covered by the phrases computer-readable media or memory. For example, the terms “non-transitory computer-readable medium” or “tangible memory” are intended to include types of storage devices that do not necessarily permanently store information, such as random access memory (RAM). Program instructions and data stored on tangible computer-accessible storage media in a non-transitory form can be further transmitted via transmission media or signals such as electronic, electromagnetic, or digital signals that can be transmitted via communication media such as networks and / or wireless links.
[0053] The processor 11 (as associated with system 20) may be or include any number of hardware components for performing data or signal processing or for executing computer code stored in memory 12. Device 10 has an associated memory 12, and memory 12 may be one or more devices for storing data and / or computer code for performing or facilitating the various methods described herein. Memory may include volatile or non-volatile memory. Memory 12 may include database components, object code components, script components, or any other type of information structure for supporting the various activities described herein. According to exemplary embodiments, any distributed or local memory device may be utilized with respect to the systems and methods of this specification. According to exemplary embodiments, memory 12 (e.g., via circuitry or any other wired, wireless, or network connection) may be communicatively connected to processor 11 and includes computer code for performing one or more processes described herein.
[0054] It should be understood that sensor interface 14 may also provide the possibility of acquiring sensor data directly or via dedicated sensor control circuitry 4 within the vehicle. Communication / antenna interface 13 may additionally provide the possibility of transmitting output to a remote location (e.g., a remote operator or control center) via antenna 5. Furthermore, some sensors within the vehicle may communicate with control equipment 10 using local network settings (such as CAN bus, I2C, Ethernet, fiber optics, etc.). Communication interface 13 may be configured to communicate with other control functions of the vehicle and may therefore also be considered a control interface; however, a separate control interface (not shown) may be provided. Local communication within the vehicle may also be wireless, utilizing protocols such as WiFi, LoRa, Wi-Fi, Bluetooth, or similar mid-range / short-range technologies.
[0055] Therefore, it should be understood that the described solution can be implemented in the vehicle, in a system located outside the vehicle, or in a combination of both; for example, in a server (a so-called cloud solution) communicating with the vehicle. For instance, data indicating monitored manual driver actions can be evaluated outside the vehicle, and assuming a sufficiently good connection can be established between the vehicle and the remote entity, signals indicating the evaluation results can be sent back to the vehicle's control system. Different features and steps of the embodiments can be combined in combinations other than those described.
[0056] It should be noted that the word "comprising" does not exclude the presence of other elements or steps not listed, and the word "a" preceding an element does not exclude the presence of multiple such elements. It should be further noted that arbitrary reference numerals do not limit the scope of the claims, that this disclosure can be implemented at least in part by means of both hardware and software, and that several "apparatus" or "units" can be represented by the same hardware.
[0057] Although the diagrams may show a specific order of method steps, the order of steps may differ from the depicted order. Furthermore, two or more steps may be performed in parallel or partially simultaneously. For example, the steps of monitoring and evaluating manual driver operation may be performed in parallel with the evaluation step. Such variations will depend on the chosen software and hardware system and the designer's choices. All such variations are within the scope of this disclosure. Similarly, software implementations can be achieved using standard programming techniques with rule-based logic and other logic to implement various connection steps, processing steps, comparison steps, and decision steps. The embodiments mentioned and described above are given merely as examples and should not be limited to this disclosure. Other solutions, uses, purposes, and functions within the scope of this disclosure, as claimed in the patented embodiments described below, should be apparent to those skilled in the art.
Claims
1. A method (100) for managing handover from an autonomous driving system, ADS, to a driver of a vehicle, wherein The ADS includes an ADS function associated with a first set of pre-emptive constraints among a plurality of pre-emptive constraints, the first set of pre-emptive constraints being applied by a pre-emptive safety PCS module when the ADS function controls the vehicle, wherein the plurality of pre-emptive constraints include a set of safety margins for lateral and longitudinal control of the vehicle, the method comprising: Receive (101) a request to deactivate the ADS function; Based on the obtained request, partial control of the vehicle is provided (102) to the driver, thereby enabling manual driver operation of the vehicle, wherein the partial control includes the use of steering, acceleration and braking of the vehicle when the driver has partial control of the vehicle and the PCS module applies a second set of the plurality of pre-prevention constraints to the driver. The second set of preventative constraints includes at least one of the following: The first set of preventive constraints is a subset of preventive constraints. A smaller number of preventative constraints compared to the first set of preventative constraints, or A higher threshold for at least one of the first set of preventive constraints; The method further includes: Monitor (104) manual driver operations on the vehicle for a period of time; During the said time period, the monitored manual driver operations on the vehicle are evaluated (105) against the second set of pre-emptive constraints, and: If the manual driver operation passes the evaluation, the second set of pre-emptive constraints is deactivated (106) at the end of the time period, or If the manual driver operation fails the evaluation, control of the vehicle is provided (107) to the ADS.
2. The method (100) of claim 1, wherein The ADS includes a minimum risk condition (MRC) function, and the step of providing control of the vehicle to the ADS (107) includes: Bring the vehicle into the minimum risk condition MRC, or Control of the vehicle is restored to the ADS function.
3. The method (100) according to any one of claims 1 and 2, wherein, The steps of evaluating (105) the monitored driver operations include: continuously evaluating the monitored manual driver operations during the time period; and The step of providing control of the vehicle to the ADS includes: providing control of the vehicle to the ADS when the monitored manual driver operation fails the evaluation.
4. The method (100) according to any one of claims 1 and 2, further comprising: In electronic devices with displays: The user interface displayed on the monitor includes the following items: A graphical representation of the first user interface (35) when the ADS function controls the vehicle. A graphical representation of the second user interface (36) when the driver has partial control over the vehicle. A graphical representation of the third user interface (37) when the second set of pre-emptive constraints is deactivated; The first user interface, the second user interface, and the third user interface are different.
5. The method (100) according to any one of claims 1 and 2, wherein, The first set of preventive constraints is different from the second set of preventive constraints.
6. The method (100) according to any one of claims 1 and 2, wherein, The time period is dynamically set based on the type of ADS function that is deactivated, the vehicle's current operating design domain (ODD), or the driver profile.
7. The method (100) according to any one of claims 1 and 2, wherein, The step of obtaining (101) a request to deactivate the ADS function includes: Obtain a request from the driver via the Human-Machine Interface (HMI) to deactivate the ADS function; or Obtain a request from the machine to deactivate the ADS function.
8. The method (100) according to claim 7, wherein, The ADS function is configured to operate within the running design domain ODD, and the step of obtaining a machine-initiated request to deactivate the ADS function includes: Acquire sensor data indicating exit from the ODD; In response to the acquired sensor data indicating that the ODD has exited, the machine initiates a request to deactivate the ADS function.
9. A non-transitory computer-readable storage medium storing one or more programs configured to be executed by one or more processors of a vehicle control system, the one or more programs comprising instructions for performing the method (100) according to claim 1.
10. A system (20) for managing the handover of the driver from an automated driving system (ADS) to a vehicle (1), wherein, The ADS includes ADS functionality (21), and the system includes: The proactive safety PCS module (23) is configured to apply a first set of proactive constraints to the ADS function when the ADS function controls the vehicle, wherein the multiple proactive constraints include a set of safety margins for lateral and longitudinal control of the vehicle; The control circuit is configured as follows: Obtain a request to deactivate the ADS function; Based on the obtained request, partial control of the vehicle is provided to the driver, thereby enabling manual driver operation of the vehicle, wherein the partial control includes the use of steering, acceleration and braking of the vehicle when the driver has partial control of the vehicle and the PCS module (23) applies the second set of the plurality of pre-prevention constraints to the driver. The second set of preventative constraints includes at least one of the following: The first set of preventive constraints is a subset of preventive constraints. A smaller number of preventative constraints compared to the first set of preventative constraints, or A higher threshold for at least one of the first set of preventive constraints; The control circuit is further configured to: Monitor manual driver operations on the vehicle (1) for a period of time; During the said time period, the monitored manual driver actions on the vehicle are evaluated against the second set of pre-emptive constraints, and: If the manual driver operation passes the evaluation, the second set of pre-emptive restraints is deactivated; or If the manual driver operation fails the evaluation, control of the vehicle will be provided to the ADS.
11. The system (20) according to claim 10, wherein, The control circuit is configured as follows: The monitored driver actions are evaluated by continuously assessing the monitored manual driver actions during the said time period; and Control of the vehicle is provided to the ADS by providing control of the vehicle to the ADS when the monitored manual driver operation fails the evaluation.
12. The system (20) according to claim 10 or 11, wherein, The control circuit is further configured as follows: At electronic devices with display devices: A user interface (35-37) including the following items is displayed on the display device: A graphical representation of the first user interface (35) when the ADS function controls the vehicle. A graphical representation of the second user interface (36) when the driver has partial control over the vehicle. A graphical representation of the third user interface (37) when the second set of pre-emptive constraints is deactivated; The first user interface, the second user interface, and the third user interface are different.
13. The system (20) according to any one of claims 10 and 11, wherein, The first set of preventive constraints is different from the second set of preventive constraints.
14. The system (20) according to any one of claims 10 and 11, wherein, The time period is dynamically set based on the type of ADS function that is deactivated, the vehicle's current operating design domain (ODD), or the driver profile.
15. A vehicle (1), comprising: An autonomous driving system ADS module (21) including ADS functionality, wherein the ADS functionality is configured to control the vehicle’s steering, acceleration and braking within a predefined operating design domain (ODD); as well as The system (20) according to claim 10.
Citation Information
Patent Citations
Method and System for Displaying Driving Modes of a Vehicle
US20180222318A1
Automated vehicle operator skill evaluation system
US9870001B1