Method and apparatus for controlling autonomous driving

By sensing the fault type and the vehicle's surrounding environment, the fault safety strategy is dynamically adjusted, solving the problem of a single control strategy in autonomous driving systems under fault conditions. This enables flexible fault safety control, ensuring the driver can safely transfer control and the vehicle can come to a safe stop.

CN113859258BActive Publication Date: 2026-04-28HYUNDAI MOTOR CO LTD +1
View PDF 4 Cites 0 Cited by

Patent Information

Authority / Receiving Office
CN · China
Patent Type
Patents(China)
Current Assignee / Owner
HYUNDAI MOTOR CO LTD
Filing Date
2020-12-01
Publication Date
2026-04-28

AI Technical Summary

Technical Problem

Existing autonomous driving systems cannot dynamically adjust fail-safe strategies based on the type of fault and the surrounding environment of the vehicle in the event of a malfunction. This results in a single and inflexible control strategy, which cannot effectively guarantee the safe transfer of control by the driver and the safe stopping of the vehicle.

Method used

By sensing the fault type and the vehicle's surrounding environment, the fail-safe strategy is dynamically adjusted. Using risk calculation and actuator state identification, the optimal fail-safe strategy is determined, including the control of braking, steering, shifting, and drive systems, to ensure the vehicle stops safely.

Benefits of technology

It enables dynamic adjustment of control strategies based on specific fault types and environments in fault situations, improving the safety and flexibility of autonomous driving systems and ensuring the safety of driver control transfer and safe vehicle stopping.

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure CN113859258B_ABST
    Figure CN113859258B_ABST
Patent Text Reader

Abstract

The present invention relates to a method and apparatus for controlling autonomous driving. A method for controlling autonomous driving in a vehicle capable of autonomous driving can include: collecting vehicle driving state information and system state information during autonomous driving; sensing a failure based on the system state information; identifying an actuator capable of normal control when the failure is sensed; determining a risk degree corresponding to the sensed failure based on the actuator capable of normal control information and the vehicle driving state information; determining a safety state based on the actuator capable of normal control information and the risk degree; determining a failure safety strategy corresponding to the safety state.
Need to check novelty before this filing date? Find Prior Art

Description

[0001] Cross-reference to related applications

[0002] This application claims priority and benefit to Korean Patent Application No. 10-2020-0080429, filed on June 30, 2020, the entire contents of which are incorporated herein by reference. Technical Field

[0003] This invention relates to the control of autonomous vehicles. Background Technology

[0004] The statements in this section are merely background information in relation to the invention and may not constitute prior art.

[0005] Autonomous vehicles need to have the ability to adapt to the changing surrounding environment in real time during driving.

[0006] Reliable deterministic control functions are needed for the mass production and deployment of autonomous vehicles.

[0007] In currently mass-produced Level 2 autonomous driving systems, the driver is required to keep their eyes forward. Therefore, a pre-defined hands-off warning is issued when the driver is not holding the steering wheel, and the system determines whether the driver has intervened in steering based on changes in the steering torque value based on the driver's steering wheel manipulation.

[0008] When a system malfunction occurs, the current Level 2 autonomous driving system immediately deactivates autonomous driving mode. When a system malfunction occurs, the Level 3 autonomous driving system outputs a warning (transition demand, TD), requesting that control be transferred from the system to the driver, and then switches to the minimum risk maneuver (MRM) mode and prompts a safe stop.

[0009] That is, regardless of the type of system failure or the vehicle's driving environment, a conventional Level 3 autonomous driving system always responds with the same strategy. Summary of the Invention

[0010] This invention provides an apparatus and method for controlling autonomous driving.

[0011] One embodiment of the present invention provides a method and apparatus for controlling autonomous driving, which can dynamically provide fail-safe strategies based on the type of fault sensed during autonomous driving and the driving conditions around the vehicle.

[0012] Another embodiment of the present invention provides a method and apparatus for controlling autonomous driving. When a system fault is sensed during autonomous driving, the method and apparatus can distinguish fault-safe strategies based on the fault type and risk level, thereby enabling safe parking guidance and safe transfer of control to the driver.

[0013] According to one embodiment of the present invention, a method for controlling autonomous driving in a vehicle capable of autonomous driving includes: acquiring vehicle driving state information and system state information during autonomous driving; sensing a fault based on the system state information; identifying a normally controllable actuator when a fault is sensed; determining a risk level corresponding to the sensed fault based on the normally controllable actuator information and the vehicle driving state information; determining a safe state based on the normally controllable actuator information and the risk level; and determining a fail-safe strategy corresponding to the safe state.

[0014] In some implementations, determining the risk level may include: identifying the type and number of faults based on actuator information that can be normally controlled; determining an initial risk level based on the fault type; determining a first weight value based on the number of faults; determining a second weight value based on vehicle driving status information; and determining a final risk level by applying the first or second weight value to the initial risk level.

[0015] In some implementations, determining the fail-safe strategy corresponding to the safe state may include: identifying the actuators to be used corresponding to the determined safe state from among the identified actuators that can be normally controlled; determining the maximum permissible time corresponding to the determined safe state based on the identified actuators to be used and the final risk level; and determining the optimal fail-safe scheme by using the identified actuators to be used in the determined safe state.

[0016] In some implementation schemes, the maximum permissible time can be determined to be inversely proportional to the final risk level.

[0017] In some implementations, vehicle driving status information may include at least one of positioning signal information, vehicle external information, vehicle internal information, or precise map information. Vehicle external information may include at least one of radar sensing information, lidar sensing information, or external camera capture information. Vehicle internal information may include at least one of in-vehicle camera capture information or driver biosensing information.

[0018] In some implementations, the method may further include: determining the driver's state based on vehicle interior information, and may further determine the risk level based on the driver's state.

[0019] In some implementations, system status information may include at least one of the following: braking system information, stability control system information, steering system information, shifting system information, drive system information, camera system information, tire pressure measurement system information, fuel tank sensing system information, battery management system information, rain sensing system information, system information for sensors used to sense the area in front of the vehicle, or autonomous driving controller status information.

[0020] In some implementations, the actuator may include at least one of an electric parking brake, electronic stability control, electric power steering, transmission control unit, or engine management system.

[0021] In some implementation schemes, as the risk level increases, a fail-safe strategy for deceleration control with a large deceleration metric can be determined.

[0022] In some implementations, the fault type may include at least one of the following: driver state and intent determination sensor fault, rain sensor fault for weather determination, autopilot controller fault, global positioning system (GPS) receiver fault, rapid tire pressure drop fault, sensor fault for sensing the area in front of the vehicle fault, steering-related actuator fault, braking-related actuator fault, driving-related actuator fault, gear shifting-related actuator fault, or stability control-related actuator fault.

[0023] According to another embodiment of the present invention, an apparatus for controlling autonomous driving of an autonomous vehicle includes: a state information collector configured to collect vehicle driving state information and system state information during autonomous driving; a system fault determination device configured to sense a fault based on the system state information; an actuator state identification device configured to identify actuators that can be normally controlled when a fault is sensed; a risk level calculator configured to determine a risk level corresponding to the sensed fault based on the actuator information that can be normally controlled and the vehicle driving state information; and a fail-safe strategy determination device configured to determine a safe state based on the actuator information that can be normally controlled and the risk level, and to determine a fail-safe strategy corresponding to the safe state.

[0024] In some implementations, the risk calculator may include: a fault type and quantity identification device configured to identify fault type and fault quantity based on actuator information that can be normally controlled; an initial risk determination device configured to determine an initial risk level based on the fault type; a first weight value determination device configured to determine a first weight value based on the fault quantity; a second weight value determination device configured to determine a second weight value based on vehicle driving status information; and a final risk determination device configured to determine a final risk level by applying the first weight value or the second weight value to the initial risk level.

[0025] In some implementations, the fail-safe strategy determination apparatus may include: an actuator determination apparatus configured to determine, among identified normally controllable actuators, an actuator to be used corresponding to a determined safety state; a maximum permissible time determination apparatus configured to determine a maximum permissible time corresponding to the determined safety state based on the determined actuator to be used and the final risk level; and a scheme determination apparatus configured to determine the optimal fail-safe scheme using the determined actuator to be used under the determined safety state.

[0026] In some implementation schemes, the maximum permissible time can be determined to be inversely proportional to the final risk level.

[0027] In some implementations, the vehicle driving status information may include at least one of positioning signal information, vehicle external information, vehicle internal information, or precise map information. The vehicle external information may include at least one of radar sensing information, lidar sensing information, or external camera capture information. The vehicle internal information may include at least one of in-vehicle camera capture information or driver biosensing information.

[0028] In some implementations, the apparatus may further include: a driver state determination device configured to determine the driver state based on vehicle interior information, and the risk calculator may determine the risk level based on the determined driver state.

[0029] In some implementations, system status information may include at least one of the following: braking system information, stability control system information, steering system information, shifting system information, drive system information, camera system information, tire pressure measurement system information, fuel tank sensing system information, battery management system information, rain sensing system information, system information for sensors used to sense the area in front of the vehicle, or autonomous driving controller status information.

[0030] In some implementations, the actuator may include at least one of an electric parking brake (EPB), electronic stability control (ESC), electric power steering system (MDPS), transmission control unit (TCU), or engine management system (EMS).

[0031] In some implementations, as the risk level increases, the fail-safe strategy determination device can determine a fail-safe strategy for deceleration control with a large deceleration metric.

[0032] In some implementations, the fault type may include at least one of the following: driver state and intent determination sensor fault, rain sensor fault for weather determination, autopilot controller fault, global positioning system (GPS) receiver fault, rapid tire pressure drop fault, sensor fault for sensing the area in front of the vehicle fault, steering-related actuator fault, braking-related actuator fault, driving-related actuator fault, transmission-related actuator fault, or stability control-related actuator fault.

[0033] Further areas of application will become apparent from the description provided herein. It should be understood that the description and specific examples are for illustrative purposes only and are not intended to limit the scope of the invention. Attached Figure Description

[0034] To better understand the present invention, various embodiments of the invention will be described by way of example with reference to the accompanying drawings, in which:

[0035] The above and other objects, features, and advantages of the present invention will be more clearly understood from the following detailed description presented in conjunction with the accompanying drawings:

[0036] Figure 1 It is a chart that defines the level of automation of autonomous vehicles;

[0037] Figure 2 This is a schematic diagram illustrating the vehicle control process generated by TD during autonomous driving;

[0038] Figure 3 This is a block diagram illustrating the structure of an automatic driving control device according to an embodiment of the present invention;

[0039] Figure 4 It is used to show the setting in the above Figure 3 A block diagram showing the detailed structure of the fault handling module in the device;

[0040] Figure 5 This is a block diagram illustrating the structure of a risk level calculator according to an embodiment of the present invention;

[0041] Figure 6 This is a block diagram illustrating the structure of a fail-safe strategy determination device according to an embodiment of the present invention;

[0042] Figure 7 This is a flowchart illustrating an automatic driving control method in a fail-safe module according to an embodiment of the present invention;

[0043] Figure 8 This is a flowchart illustrating an automatic driving control method in a risk calculator according to an embodiment of the present invention;

[0044] Figure 9 This is a flowchart illustrating an automatic driving control method in a fail-safe strategy determination apparatus according to an embodiment of the present invention;

[0045] Figure 10 This is a schematic diagram illustrating a fail-safe strategy for each failure condition according to an embodiment of the present invention.

[0046] The accompanying drawings described herein are for illustrative purposes only and are not intended to limit the scope of the invention in any way. Detailed Implementation

[0047] The following description is merely exemplary in nature and is not intended to limit the invention, application, or use. It should be understood that in all the drawings, corresponding reference numerals denote the same or corresponding parts and features.

[0048] Various embodiments of the invention will now be described in detail with reference to the exemplary accompanying drawings. When adding reference numerals to components in each figure, it should be noted that even if the same or equivalent components are shown in other figures, they are designated by the same reference numerals. Furthermore, in describing various embodiments of the invention, detailed descriptions of related known configurations or functions will be omitted when it is determined that they impede understanding of the invention.

[0049] In describing the components of embodiments of the present invention, terms such as first, second, A, B, (a), (b), etc., may be used. These terms are intended only to distinguish components from other components, and they do not limit the nature, order, or sequence of the components. Unless otherwise defined, the terms used herein, including technical and scientific terms, have the same meaning as commonly understood by one of ordinary skill in the art to which this invention pertains. It will be further understood that terms such as those defined in common dictionaries should be interpreted as having meanings consistent with their meanings in the context of the relevant field, and will not be interpreted as having idealized or overly formal meanings unless expressly defined herein.

[0050] In the following text, reference will be made to Figures 1 to 10The various embodiments of the present invention are described in detail below.

[0051] Figure 1 It is a chart that defines the level of automation of autonomous vehicles.

[0052] Autonomous vehicles are those that autonomously identify risks in their driving environment and control their driving path, thereby reducing the need for driver intervention.

[0053] Ultimately, autonomous vehicles refer to vehicles that can drive, operate, and park without human intervention, focusing on vehicles operating under autonomous driving technology. That is, the core foundation of autonomous vehicles—the ability to drive without active driver control or monitoring—has been developed to its highest level.

[0054] However, current concepts of autonomous vehicles can include, for example Figure 1 The intermediate level of automation shown progresses to fully autonomous vehicles, and corresponds to a goal-oriented concept based on the mass production and commercialization of fully autonomous vehicles.

[0055] The automatic driving control method according to the present invention can be applied to... Figure 1 The diagram shows an autonomous vehicle corresponding to Level 3 (Conditional Automated Driving) of the automated driving levels. However, this method is not limited to this and can be applied to all levels of autonomous vehicles that require control transfer and vehicle control based on system failures during automated driving.

[0056] The automation levels of autonomous vehicles based on the Society of Automotive Engineers (SAE) can be as follows: Figure 1 The charts are categorized as shown.

[0057] Figure 2 This is a schematic diagram illustrating the autonomous vehicle control process generated by TD during autonomous driving.

[0058] For ease of description, autonomous vehicles will be referred to simply as "vehicles" in the following text.

[0059] refer to Figure 2 When the autonomous driving function is activated in response to the driver's input of the autonomous driving selection button, the vehicle can perform autonomous driving control.

[0060] The vehicle can determine whether the driver has intervened by taking into account factors such as steering wheel torque value and steering wheel torque holding time when the autonomous driving is in normal working condition.

[0061] When driver intervention is detected during normal autonomous driving operation, the vehicle can activate manual driving mode.

[0062] When a transfer request (TD) occurs during autonomous driving due to system failure, collision risk sensing, or other reasons, the vehicle can activate a risk minimization strategy driving mode after outputting a warning message requesting the transfer of control from the system to the driver.

[0063] In this context, TD situations refer to conditions where autonomous driving can no longer be maintained. These can include, but are not limited to, situations such as interference from another vehicle, the appearance of pedestrians or wild animals in front of the vehicle, the detection of obstacles in front of the vehicle, the sudden stopping of the vehicle in front of the vehicle, and severe weather. TD situations can also include system disasters and malfunctions, such as vehicle controller failure, vehicle communication failure, and fuel shortage.

[0064] When the risk minimization strategy driving mode is activated, the vehicle can perform lane-keeping deceleration control until the vehicle comes to a complete stop.

[0065] The vehicle can determine whether the driver has intervened in the risk-minimizing strategy driving mode by taking into account factors such as the driver's line of sight, steering wheel torque value, steering wheel torque holding time, and control transfer button input.

[0066] When driver intervention is sensed in the risk minimization strategy driving mode, the vehicle can deactivate the risk minimization strategy driving mode and activate the manual driving mode.

[0067] When the vehicle completes a normal transfer of control in response to driver intervention under the risk minimization strategy driving mode, it can stop outputting warning messages requesting a transfer of control from the system to the driver.

[0068] Figure 3 This is a block diagram illustrating the structure of an automatic driving control device according to an embodiment of the present invention.

[0069] according to Figure 3 The autonomous driving control device can be installed on autonomous vehicles at or above Level 3.

[0070] For ease of description, the automatic driving control device 300 will be referred to simply as device 300.

[0071] refer to Figure 3The device 300 may include: a global positioning system (GPS) receiver 301, an external vehicle information collector 302, an internal vehicle information collector 305, a precision map provider 308, an autopilot controller 310, a warning device 321, a human machine interface (HMI) 322, a direction indicator 323, a hazard flare 324, a braking system 325, a stability control system 326, a steering system 327, a gear shifting system 328, a drive system 329, and an auxiliary system 330.

[0072] Each system associated with the autonomous driving controller 310 may be equipped with a separate controller to monitor for system malfunctions and send the monitoring results to the fail-safe module 318 of the autonomous driving controller 310.

[0073] GPS receiver 301 can receive positioning signals from positioning satellites. In this regard, the positioning signals can be used to generate the vehicle's geographical location information.

[0074] The vehicle external information collector 302 can collect information about the vehicle's surrounding environment and driving status. The vehicle external information collector 302 may include radar and lidar 303 and an external camera 304.

[0075] The radar / liDAR 303 can sense objects around the vehicle.

[0076] The radar / liDAR 303 can sense objects in front of, to the sides and behind a vehicle, and calculate the distance to the sensed objects.

[0077] In addition, the radar / lidar 303 can determine whether the sensed object is a static object or a dynamic object, measure the moving speed of the sensed dynamic object, and determine whether the sensed dynamic object is a pedestrian or a vehicle.

[0078] In addition, the radar / lidar 303 can be used for the purpose of identifying the condition of roads and facilities through high-resolution terrain scanning.

[0079] External camera 304 can be mounted on the exterior of the vehicle to capture images of the areas in front, to the sides, and to the rear of the vehicle. For this purpose, the vehicle can have multiple external cameras.

[0080] The images captured by the external camera 304 can be used for purposes such as lane differentiation, recognition of objects around vehicles, and augmented reality implementation.

[0081] The vehicle interior information collector 305 can collect various vehicle interior status information.

[0082] The vehicle interior information collector 305 may include an in-vehicle camera 306 and a biometric sensor 307.

[0083] The in-vehicle camera 306 can be installed on one side of the vehicle interior to capture the driver and passengers.

[0084] The images captured by the in-vehicle camera 306 can be used to monitor the driver's gaze direction and the driver's state (e.g., driver inattention, fatigue, drowsy driving, etc.).

[0085] The biometric sensor 307 can be installed on the side of the vehicle to collect various biometric information of the driver.

[0086] The biometric sensor 307 can be associated with the driver's wearable device to collect various biometric information of the driver.

[0087] For example, biometric information may include pulse information, heart rate monitoring information, body temperature information, blood alcohol concentration information, electroencephalogram (EEG) information, fingerprint recognition information, iris recognition information, etc., but it is not limited to these.

[0088] Biometric information can be used to determine states such as inability to drive, driving under the influence of alcohol, and fatigue.

[0089] The accurate map provider 308 can provide accurate map information in response to a request from the autonomous driving controller 310.

[0090] The autonomous driving controller 310 may include: a precise positioning device 311, an identification device 312, a control command device 313, a driver status determination device 314, a user input device 315, a control transfer determination device 316, a lighting controller 317, and a fail-safe module 318.

[0091] The precise positioning device 311 can use the positioning signal information received from the GPS receiver 301 and the precise map information obtained from the precise map provider 308 to determine the current position of the vehicle, and map the determined current position of the vehicle onto the precise map.

[0092] In addition, the precise positioning device 311 can identify the status information of the road on which the vehicle is traveling, such as slope, road type, number of lanes, speed limit, etc.

[0093] The identification device 312 can identify lanes, vehicles around the vehicle, obstacles, pedestrians, etc., based on sensing information from radar / lidar 303 and image information captured by external camera 304.

[0094] The control command device 313 can calculate the request command value based on the recognition result of the recognition device 312, and perform driving control by sending the calculated request command value to the corresponding automatic driving system.

[0095] The driver status determination device 314 can determine the driver status based on the vehicle interior status information obtained from the vehicle interior information collector 305.

[0096] In this regard, a driver's state may include: inattentive state, inability to drive, drunk driving state, fatigued driving state, tiredness, etc., but may not be limited to these.

[0097] User input device 315 can sense user input based on control signals received from HMI 322.

[0098] In this regard, user input may include predetermined button input signals, predetermined gesture input signals, etc., for accepting the transfer of control from the system to the driver.

[0099] The driver status determination device 314 can determine whether it is necessary to transfer control from the system to the driver based on at least one of the various identification information obtained from the identification device 312, the vehicle interior status information obtained from the vehicle interior information collector 305, or the driver input information obtained from the user input device 315.

[0100] As a result, when it is necessary to transfer control, the control transfer determination device 316 can send a predetermined control signal to the warning device 321, thereby outputting a predetermined warning message requesting the transfer of control to the driver.

[0101] The lighting controller 317 can control the lighting of the direction indicator 323 and the hazard hazard stunner 324.

[0102] The failsafe module 318 can determine the optimal failsafe strategy based on the type of fault sensed during autonomous driving and the driving conditions around the vehicle.

[0103] For example, the fault type may include at least one of the following: driver state and intent determination sensor fault, rain sensor fault for weather determination, autopilot controller fault, global positioning system (GPS) receiver fault, rapid tire pressure drop fault, sensor fault for sensing the area in front of the vehicle fault, steering-related actuator fault, braking-related actuator fault, driving-related actuator fault, gear shifting-related actuator fault, or stability control-related actuator fault.

[0104] The fail-safe module 318 can request the control command device 313 to perform vehicle control based on the determined fail-safe strategy.

[0105] The detailed configuration and operation of the fail-safe module 318 will become clearer from the accompanying drawings described below.

[0106] The braking system 325 can control the operation of the brake-related actuators and monitor their status.

[0107] For example, braking system 325 may include an electric parking brake (EPB) that generates braking force electrically rather than through human physical force.

[0108] The stability control system 326 can control the operation of the actuator to maintain the stability of the vehicle body.

[0109] As an example, the stability control system 326 may include electronic stability control (ESC), which is an advanced electronic braking device.

[0110] ESC is a device that controls vehicle stability by coordinating the control of braking force and traction force. ESC can provide the functions of both anti-lock braking system (ABS) and traction control system (TCS).

[0111] Electronic Stability Control (ESC) operates by combining information measured from sensors for steering angle, lateral acceleration, yaw rate, and wheel speed to determine whether the vehicle's stability is being maintained, and then controlling the braking force of each of the four wheels based on this information.

[0112] The steering system 327 can control the operation of the actuators used to control the lateral behavior of the vehicle.

[0113] For example, the steering system 327 may include a motor-driven power steering (MDPS) system. An MDPS is a device that uses an electric motor instead of a hydraulic motor to assist the driver's operation. It may include a redundant power input structure and multiple signal channels for stable power supply and signal transmission and reception.

[0114] The shift system 328 can control the operation of the actuator used for automatic shifting.

[0115] As an example, the shift system 328 may include a transmission control unit (TCU).

[0116] The transmission control unit (TCU) can determine the number of gears and timing based on TPS, vehicle speed, engine speed per minute, brake switch input, etc., thereby controlling automatic gear shifting.

[0117] The drive system 329 can control the operation of actuators used to control the longitudinal behavior (i.e., driving speed) of the vehicle. For example, actuators used to control longitudinal behavior may include a throttle, an accelerator, etc.

[0118] For example, drive system 329 may include engine management system (EMS).

[0119] EMS may include actuators for electronic throttle control, direct gasoline injection, and idle start-stop functions.

[0120] The additional system 330 may include a tire pressure measurement system for sensing tire pressure, such as a tire pressure monitoring system (TPMS), a fuel tank sensing system, a battery management system for hybrid vehicles and electric vehicles, etc., but may not be limited to these.

[0121] Figure 4 It is used to show the setting in the above Figure 3 A block diagram showing the detailed structure of the fault handling module in the device.

[0122] refer to Figure 4 The failsafe module 318 may include: a status information collector 410, a system fault determination device 420, an actuator status identification device 430, a risk calculator 440, and a failsafe strategy determination device 450.

[0123] The status information collector 410 can collect the vehicle's driving status information and the status information of the vehicle's surroundings.

[0124] In this regard, vehicle driving status information may include: driving speed information, driving lane information, information about the number of lanes on the driving road, information about the slope of the driving road, road surface condition information, weather information, etc., but may not be limited to these.

[0125] The vehicle's surroundings information may include: information about the distance to surrounding vehicles, information about the number of surrounding vehicles, sensing information about dynamic objects other than vehicles, sensing information about static objects, etc., but may not be limited to these.

[0126] The system fault determination device 420 can determine whether a system fault has occurred during autonomous driving. For example, system faults may include actuator faults, vehicle communication faults, etc., but are not limited to these, and may include abnormal tire pressure, etc.

[0127] When a system fails to function properly in response to a control request command sent by the automatic driving controller 310 to a specific system, the system fault determination device 420 can determine that a fault has occurred in the corresponding system.

[0128] In addition, if no signal is received from the system within a certain period of time, the system fault determination device 420 can determine that the automatic driving controller 310 has failed to communicate with the corresponding system.

[0129] The system fault determination device 420 can identify the fault type and calculate the number of faulty systems, controllers and actuators.

[0130] The actuator status identification device 430 can collect controller status information and / or actuator status information from the controller of each system to identify the status of the controllable actuator.

[0131] The Risk Calculator 440 can calculate a vehicle's risk level based on fault type, number of faults, vehicle driving status information, and other factors.

[0132] As an example, the risk calculator 440 can calculate the initial risk level r1 corresponding to the fault type as shown in the mathematical equation 1 below, and calculate the final risk level r2 by assigning weight values ​​to the initial risk level based on the number of faults and vehicle driving status information.

[0133] <Mathematical Equation 1>

[0134] r2 = r1 × w1 × w2

[0135] In this regard, w1 is a weight value based on the number of faults, and w2 is a weight value based on vehicle driving status information.

[0136] In one implementation, the risk level of each type of failure can be divided into three levels: low risk, medium risk, and high risk, but it is not limited to this and more detailed risk levels can be defined based on the design of those skilled in the art.

[0137] Low risk can correspond to situations where vehicle behavior is not directly affected, but a system failure occurs that affects the state of the recognition system or the driver's intention.

[0138] Medium risk can correspond to situations where vehicle behavior is indirectly affected, or where a system failure occurs that leads to a deterioration in system performance.

[0139] High risk can correspond to situations where the vehicle's lateral / longitudinal control is directly affected, or where the system for sensing vehicles, obstacles, etc., in front of the vehicle malfunctions.

[0140] As an example, even when the same type of fault occurs, the risk calculator 440 can determine that the state in which multiple surrounding vehicles are sensed around the vehicle has a higher risk level than the state in which no vehicles are sensed around the vehicle.

[0141] The fail-safe strategy determination device 450 can determine a safe state based on the risk level determined by the risk level calculator 440 and the actuator information that can be normally controlled identified by the actuator state identification device 430, and determine the optimal fail-safe strategy for entering the determined safe state.

[0142] In addition, the fail-safe strategy determination device 450 can determine the maximum permissible time until a safe state is reached based on actuator information that can be controlled normally.

[0143] Generally, the higher the risk level, the shorter the maximum permissible time until a safe state is reached.

[0144] However, when the braking system fails, although the risk is high, the maximum permissible time can vary dynamically based on vehicle speed and gradient.

[0145] In some implementations, different failsafe strategies can be applied based on the type of failure, even in cases of failures with the same level of risk.

[0146] For example, MDPS failures and ESC failures can be assessed as having the same level of risk.

[0147] In the event of an MDPS failure, the failsafe strategy determination device 450 can determine failsafe strategies for performing emergency stops, gear shifts (N and P), EPB tightening, etc., for the purpose of quickly terminating the automatic driving system.

[0148] In the event of an ECS failure, the failsafe strategy determination device 450 can determine a failsafe strategy for EPB fastening after the vehicle speed is reduced to a speed equal to or below a certain speed by shifting gears (N) and lateral control.

[0149] In some implementations, the types of faults identified by the system fault determination device 420 may include: faults of sensors used to determine the driver's state and intention (e.g., in-vehicle camera 306 and biometric sensor 307), faults of rain sensors used for weather determination, faults of the autonomous driving controller 310, faults of the GPS receiver 301, faults of rapid tire pressure drop, faults of the braking system, faults of sensors that sense the area in front of the vehicle, faults of the steering system, faults of the acceleration / deceleration system, etc., but may not be limited to these.

[0150] In some implementations, actuators identified as capable of being properly controlled by the actuator status identification device 430 may include MDPS, ESC, EPB, TCU, and EMS.

[0151] In some implementations, the risk calculator 440 can identify surrounding information, determine whether an operable actuator is a critical factor in fail-safe measures, and determine whether the area in front of the vehicle can be sensed by sensors that sense the area in front of the vehicle to determine the final risk level.

[0152] Examples of fail-safe measures for each risk level are as follows.

[0153] <Examples of low-risk failsafe measures>

[0154] - Sensing driver status / intent to determine sensor malfunction → Identifying that all controllable actuators are in normal condition → Determining the severity by identifying the surrounding conditions and actuator status using a risk assessment device → Identifying malfunction status by warning the driver when performing deceleration control with small deceleration measures or constant speed control.

[0155] - Detects a fault in the rain sensor → Identifies that all controllable actuators are in normal condition → Determines the severity by identifying the surrounding conditions and actuator status using a risk assessment device → Identifies the fault condition by alerting the driver when performing deceleration control with a small deceleration amount or constant speed control.

[0156] <Example of medium-risk failsafe measures>

[0157] Rain sensor malfunction → all controllable actuators are identified as being in normal condition → the severity is determined by the risk assessment device based on the surrounding conditions and actuator status → a collision is anticipated due to unstable vehicle behavior (large skidding) and there are many vehicles around → control is implemented with a large deceleration measure.

[0158] <Examples of high-risk fail-safe measures>

[0159] Due to the failure of all sensors used to sense the area in front of the vehicle, the state of the area in front of the vehicle cannot be identified → all controllable actuators are identified as being in normal condition → due to the inability to sense the area in front of the vehicle, the risk level is determined to be the highest level by the risk assessment device → deceleration control is performed with the maximum deceleration measure, thereby terminating the autonomous driving mode as soon as possible and prompting the vehicle to stop safely.

[0160] Figure 5 This is a block diagram illustrating the structure of a risk level calculator according to an embodiment of the present invention.

[0161] refer to Figure 5The risk level calculator 440 may include: a fault type and quantity identification device 510, an initial risk level determination device 520, a first weight value determination device 530, a second weight value determination device 540, and a final risk level determination device 550.

[0162] When an autonomous driving malfunction occurs, the malfunction type and quantity identification device 510 can identify the type and quantity of the malfunction.

[0163] In this regard, the number of faults can be calculated for the autonomous driving control system and / or actuators and / or sensors.

[0164] The initial risk determination device 520 can calculate the initial risk level based on the fault type.

[0165] The first weight value determination device 530 can determine the first weight value based on the number of faults.

[0166] The second weight value determination device 540 can determine the second weight value based on vehicle driving status information.

[0167] The final risk determination device 550 can determine the final risk level by applying a first weight value or a second weight value to the initial risk level.

[0168] Figure 6 This is a block diagram illustrating the structure of a fail-safe strategy determination device according to one embodiment of the present invention.

[0169] refer to Figure 6 The fail-safe strategy determination device 450 may include: a safety status determination device 610, an actuator determination device 620, a maximum allowable time determination device 630, and a scheme determination device 640.

[0170] The safety status determination device 610 can determine the safety status based on information about the controllable actuator under normal control and the determined risk level.

[0171] The actuator determination device 620 can determine the actuator to be used from among the actuators that can be normally controlled, corresponding to the determined safety state.

[0172] The maximum permissible time determination device 630 can determine the maximum permissible time corresponding to the corresponding safety state based on the determined actuator to be used and the degree of risk.

[0173] The scheme determination device 640 can determine the optimal fail-safe scheme that is controllable by the actuator to be used, which corresponds to the current safety state.

[0174] The control command device 313 can control the vehicle to safely bring it to a stop based on a determined fail-safe scheme.

[0175] Figure 7 This is a flowchart illustrating an automatic driving control method in a fail-safe module according to an embodiment of the present invention.

[0176] refer to Figure 7 The fail-safe module 318 can collect vehicle driving status information and system status information in autonomous driving mode (S710).

[0177] For example, system status information may include at least one of the following: braking system information, stability control system information, steering system information, shifting system information, drive system information, camera system information, tire pressure measurement system information, fuel tank sensing system information, battery management system information, rain sensing system information, system information of sensors for sensing the area in front of the vehicle, or autonomous driving controller status information.

[0178] The fail-safe module 318 can determine whether a system fault has occurred based on vehicle driving status information and system status information (S720).

[0179] As a result, when a system fault is sensed, the fail-safe module 318 can identify the actuator that can be controlled normally (S730).

[0180] The fail-safe module 318 can determine the risk level corresponding to the sensed fault based on actuator information that can be controlled normally and vehicle driving status information (S740).

[0181] The fail-safe module 318 can determine the safe state based on the actuator information that can be controlled normally and the determined risk level (S750).

[0182] The fail-safe module 318 can determine the optimal fail-safe strategy corresponding to the determined safe state (S760).

[0183] The control command device 313 of the automatic driving controller 310 can safely bring the vehicle to a stop by performing actuator operation control and deceleration control that are differentiated based on a determined fail-safe strategy.

[0184] Figure 8 This is a flowchart illustrating an automatic driving control method in a risk calculator according to an embodiment of the present invention.

[0185] refer to Figure 8 When an autonomous driving malfunction occurs, the risk calculator 440 can identify the type and number of malfunctions that have occurred (S810).

[0186] In this regard, the number of faults can be calculated for autonomous driving control systems and / or actuators and / or sensors.

[0187] The risk calculator 440 can calculate the initial risk level based on the fault type (S820).

[0188] The risk calculator 440 can determine the first weight value based on the number of failures (S830).

[0189] The risk calculator 440 can determine the second weight value (S840) based on vehicle driving status information.

[0190] The risk level calculator 440 can determine the final risk level by applying a first weight value or a second weight value to the initial risk level (S850).

[0191] Figure 9 This is a flowchart illustrating an automatic driving control method in a fail-safe strategy determination device according to an embodiment of the present invention.

[0192] The fail-safe strategy determination device 450 can determine the safe state based on actuator information that can be controlled normally and the degree of risk (S910).

[0193] The fail-safe strategy determination device 450 can determine the actuator to be used from among the actuators that can be normally controlled, corresponding to the determined safe state (S920).

[0194] The fail-safe strategy determination device 450 can determine the maximum permissible time corresponding to the corresponding safety state based on the determined actuator to be used and the degree of risk (S930).

[0195] The fail-safe strategy determination device 450 can determine the optimal fail-safe scheme, which corresponds to the safe state determined by the determined actuator to be used (S940).

[0196] In one implementation, referring to reference numeral 950, the maximum permissible time corresponding to a safe state may decrease as the risk level (severity) increases; that is, it may be inversely proportional to the risk level. However, this is merely an example, and the maximum permissible time can be determined by further considering factors such as the type of failure, information about actuators that can be normally controlled, etc.

[0197] In the following text, reference will be made to Figures 3 to 6 Describe exemplary failsafe strategies for each of the various failure scenarios.

[0198] Figure 10 This is a schematic diagram used to illustrate the fail-safe strategy for each failure condition according to the implementation scheme.

[0199] Reference numeral 1010 is a schematic diagram illustrating an exemplary fail-safe strategy in a situation (situation 1) where it cannot be determined whether the driver is driving while drowsy due to a malfunction of the in-vehicle camera.

[0200] Referring to reference numeral 1010, the system fault determination device 420 can receive a predetermined warning signal sent from the controller of the in-vehicle camera 306 to identify in-vehicle camera fault information.

[0201] The actuator status identification device 430 can determine whether actuators such as MDPS / ESC / EPB / TCU / EMS are working properly, so as to determine that all actuators are in a state where they can work properly.

[0202] The Risk Calculator 440 can calculate the risk level based on the fault type, the number of faults, and vehicle driving status information (i.e., the surrounding conditions and driving information of the vehicle).

[0203] For example, for case 1, the risk calculator 440 can determine the current fault risk level (severity) = 0.5 (low), the weight value based on multiple faults = 1 (none), and the weight value based on the surrounding / driving conditions = 0.7 (normal), so as to determine the final risk level as 0.35 (0.5 × 1 × 0.7) (very low).

[0204] When the final risk level is very low and all control operations can be performed by actuators that can be controlled normally, the failsafe strategy determination device 450 can identify lanes by analyzing images captured by the forward camera in order to perform actuator control as shown in Table 1 below.

[0205] [Table 1]

[0206] MDPS TCU EMS ESC EPB Maintain control (keep in lane) Maintain control Maintain control Perform low deceleration control Non-fastening control

[0207] Reference numeral 1020 is a schematic diagram illustrating an exemplary fail-safe strategy in the case where the vehicle's location information cannot be received due to a GPS receiver malfunction (Case 2).

[0208] Referring to reference numeral 1020, the system fault determination device 420 can receive a predetermined control signal from the precise positioning device 311 notifying the GPS receiver 301 of a fault.

[0209] The actuator status identification device 430 can determine whether actuators such as MDPS / ESC / EPB / TCU / EMS are working properly, so as to determine that all actuators are in a state where they can work properly.

[0210] The Risk Calculator 440 can calculate the risk level based on the fault type, the number of faults, and vehicle driving status information (i.e., the surrounding conditions and driving information of the vehicle).

[0211] For example, for scenario 2, the risk calculator 440 can determine the current fault risk level (severity) = 1.0 (normal), the weight value based on multiple faults = 1 (none), and the weight value based on the surrounding / driving conditions = 0.5 (low), so as to determine the final risk level as 0.5 (1×1×0.5) (low).

[0212] When the final risk level is low and all control operations can be performed by actuators that can be controlled normally, the fail-safe strategy determination device 450 can identify lanes by analyzing images captured by the forward camera in order to perform actuator control as shown in Table 2 below.

[0213] [Table 2]

[0214] MDPS TCU EMS ESC EPB Maintain control (keep in lane) Maintain control Maintain control Perform low deceleration control Non-fastening control

[0215] Reference numeral 1030 is a schematic diagram illustrating an exemplary fail-safe strategy for a situation where tire pressure drops rapidly on a very congested road (situation 3).

[0216] Referring to reference numeral 1030 in the attached figure, the system fault determination device 420 can receive tire pressure sensing information from the TPMS to identify a rapid drop in tire pressure.

[0217] The actuator status identification device 430 can determine whether actuators such as MDPS / ESC / EPB / TCU / EMS are working properly, so as to determine that all actuators are in a state where they can work properly.

[0218] The Risk Calculator 440 can calculate the risk level based on the fault type, the number of faults, and vehicle driving status information (i.e., the surrounding conditions and driving information of the vehicle).

[0219] For example, for scenario 3, the risk calculator 440 can determine the current fault risk level (severity) = 1 (normal), the weight value based on multiple faults = 1 (none), and the weight value based on the surrounding / driving conditions = 1.5 (high), so as to determine the final risk level as 1.5 (1×1×1.5) (high).

[0220] When the final risk level is high and all control operations can be performed by actuators that can be normally controlled, the fail-safe strategy determination device 450 can perform actuator control as shown in Table 3 below.

[0221] [Table 3]

[0222] MDPS TCU EMS ESC EPB Maintain control (keep in lane) Maintain control Maintain control Perform rapid deceleration control Non-fastening control

[0223] Reference numeral 1040 is a schematic diagram illustrating an exemplary fail-safe strategy for a situation where tire pressure drops rapidly on a non-congested road (situation 4).

[0224] Referring to reference numeral 1040 in the attached figure, the system fault determination device 420 can receive tire pressure sensing information from the TPMS to identify a rapid drop in tire pressure.

[0225] The actuator status identification device 430 can determine whether actuators such as MDPS / ESC / EPB / TCU / EMS are working properly, so as to determine that all actuators are in a state where they can work properly.

[0226] The Risk Calculator 440 can calculate the risk level based on the fault type, the number of faults, and vehicle driving status information (i.e., the surrounding conditions and driving information of the vehicle).

[0227] For example, for case 4, the risk calculator 440 can determine the current fault risk level (severity) = 1.0 (normal), the weight value based on multiple faults = 1 (none), and the weight value based on the surrounding / driving conditions = 0.5 (low), so as to determine the final risk level as 0.5 (1×1×0.5) (low).

[0228] When the final risk level is low and all control operations can be performed by a properly controllable actuator, the fail-safe strategy determination device 450 can perform actuator control as shown in Table 4 below.

[0229] [Table 4]

[0230] MDPS TCU EMS ESC EPB Maintain control (keep in lane) Maintain control Maintain control Perform low deceleration control Non-fastening control

[0231] Reference numeral 1050 is a view used to illustrate an exemplary failsafe strategy in a situation (situation 5) where lateral control is not possible due to MDPS failure.

[0232] Referring to reference numeral 1050, the system fault determination device 420 can receive MDPS actuator fault information from the steering system 327.

[0233] The actuator status identification device 430 can determine whether actuators such as MDPS / ESC / EPB / TCU / EMS are working properly, so as to determine that all actuators are in a state where they can work properly.

[0234] The Risk Calculator 440 can calculate the risk level based on the fault type, the number of faults, and vehicle driving status information (i.e., the surrounding conditions and driving information of the vehicle).

[0235] For example, for case 5, the risk calculator 440 can determine the current fault risk level (severity) = 2.0 (high), the weight value based on multiple faults = 1 (none), and the weight value based on the surrounding / driving conditions = 2.0 (very high), so as to determine the final risk level as 4.0 (2.0 × 1 × 2.0) (very high).

[0236] When the final risk level is very high and normal control by the MDPS actuator is not possible, the fail-safe strategy determination device 450 can perform actuator control as shown in Table 5 below.

[0237] [Table 5]

[0238] MDPS TCU EMS ESC EPB Uncontrollable Maintain control Maintain control Perform maximum deceleration control Non-fastening control

[0239] Reference numeral 1060 is a schematic diagram illustrating an exemplary fail-safe strategy in a situation (situation 6) where longitudinal control is impossible due to a brake system failure.

[0240] Referring to reference numeral 1060 in the attached drawing, the system fault determination device 420 can receive ESC actuator fault information from the braking system 325.

[0241] The actuator status identification device 430 can determine whether actuators such as MDPS / ESC / EPB / TCU / EMS are working properly, so as to determine that all actuators are in a state where they can work properly.

[0242] The Risk Calculator 440 can calculate the risk level based on the fault type, the number of faults, and vehicle driving status information (i.e., the surrounding conditions and driving information of the vehicle).

[0243] For example, for case 6, the risk calculator 440 can determine the current fault risk level (severity) = 3.0 (very high), the weight value based on multiple faults = 1 (none), and the weight value based on the surrounding / driving conditions = 1.0 (normal), so as to determine the final risk level as 3.0 (3.0 × 1 × 1.0) (very high).

[0244] When the final risk level is very high and normal control by the ECS actuator is not possible, the fail-safe strategy determination device 450 can perform actuator control as shown in Table 6 below.

[0245] [Table 6]

[0246] MDPS TCU EMS ESC EPB Control to maintain control Neutral (N) gear shift control Output limit control Uncontrollable Fastening control

[0247] The operations of the methods or algorithms described in conjunction with the examples disclosed herein can be implemented directly in hardware or in software modules executed by a processor, or in a combination thereof. The software modules can reside on storage media (i.e., memory and / or storage devices), such as RAM, flash memory, ROM, EPROM, EEPROM, registers, hard disks, removable hard disks, and CD-ROMs.

[0248] An exemplary storage medium can be coupled to a processor capable of reading information from or writing information to the storage medium. In another approach, the storage medium can be integrated with the processor. The processor and storage medium can reside in an application-specific integrated circuit (ASIC). The ASIC can reside within the user terminal. In yet another approach, the processor and storage medium can reside as separate components in the user terminal.

[0249] The above description merely illustrates the technical concept of the present invention. Those skilled in the art can make various modifications and alterations without departing from the essential characteristics of the invention. Therefore, the various embodiments disclosed in this invention are not intended to limit the technical concept of the invention, but rather to illustrate the invention, and the scope of the technical concept of the invention is not limited by these embodiments. The scope of the invention should be interpreted as being covered by the scope of the appended claims, and all technical concepts falling within the scope of the claims should be interpreted as being included within the scope of the invention.

[0250] The present invention has the advantage of providing a device and method for controlling autonomous driving.

[0251] In addition, the present invention has the advantage of providing a method and apparatus for controlling autonomous driving that can dynamically provide fail-safe strategies based on the type of fault sensed during autonomous driving and the driving conditions around the vehicle.

[0252] In addition, the present invention provides a method and apparatus for controlling autonomous driving, which can distinguish fault-safe strategies based on fault type and risk level when a system fault is sensed during autonomous driving, thereby enabling safe parking guidance and safe transfer of control to the driver.

[0253] In addition, the present invention provides a method and apparatus for controlling autonomous driving that can increase driving safety and minimize the driver’s sense of difference by using a control strategy that differentiates between each type of fault.

[0254] In addition, it can provide various effects that can be identified directly or indirectly through this article.

[0255] In the foregoing, although the invention has been described with reference to exemplary embodiments and the accompanying drawings, the invention is not limited thereto. Various changes and modifications can be made by those skilled in the art without departing from the spirit and scope of the invention as claimed by the appended claims.

Claims

1. A method for controlling autonomous driving in a vehicle capable of autonomous driving, the method comprising: During autonomous driving, vehicle driving status information and system status information are collected; Fault detection based on system status information; When a fault is detected, identify the actuator that can be controlled normally; The risk level corresponding to the sensed fault is determined based on information about the actuators that can be controlled normally and information about the vehicle's driving status. The safety status is determined based on information about actuators that can be controlled normally and the degree of risk. Determine the fail-safe strategy corresponding to the safe state; Determining the level of risk includes: Based on information about actuators that can be controlled normally, the type and number of faults are identified, and the number of faults is calculated for the autonomous driving control system and / or actuators and / or sensors. The initial risk level is determined based on the type of failure. The first weight value is determined based on the number of faults; The second weight value is determined based on vehicle driving status information; The final risk level is calculated by considering the initial risk level, the first weight value, and the second weight value together.

2. The method according to claim 1, wherein, The fault types include at least one of the following: driver state and intent determination sensor fault, rain sensor fault for weather determination, autopilot controller fault, GPS receiver fault, rapid tire pressure drop fault, sensor fault for sensing the area in front of the vehicle fault, steering-related actuator fault, braking-related actuator fault, driving-related actuator fault, gear shifting-related actuator fault, or stability control-related actuator fault.

3. The method according to claim 1, wherein, Determining the fail-safe strategy corresponding to the safe state includes: Among the identified actuators that can be controlled normally, determine the actuator to be used that corresponds to the identified safety status; The maximum permissible time corresponding to the determined safety status is determined based on the identified actuator to be used and the final risk level. The optimal fail-safe solution is determined by identifying the actuators to be used under the determined safe conditions.

4. The method according to claim 3, wherein, The maximum allowable time is determined to be inversely proportional to the final risk level.

5. The method according to claim 1, wherein, The vehicle driving status information includes at least one of the following: positioning signal information, vehicle external information, vehicle internal information, or precise map information. The vehicle external information includes at least one of radar sensing information, lidar sensing information, or information captured by an external camera. The vehicle interior information includes at least one of the following: information captured by an in-vehicle camera or driver biosensing information.

6. The method according to claim 5, wherein, The method further includes: Determine the driver's status based on information inside the vehicle. The risk level is further determined based on the driver's condition.

7. The method according to claim 1, wherein, The system status information includes at least one of the following: braking system information, stability control system information, steering system information, shifting system information, drive system information, camera system information, tire pressure measurement system information, fuel tank sensing system information, battery management system information, rain sensing system information, system information of sensors used to sense the area in front of the vehicle, or autonomous driving controller status information.

8. The method according to claim 1, wherein, The actuator includes at least one of an electric parking brake, electronic stability control, electric power steering system, transmission control unit, or engine management system.

9. The method according to claim 1, wherein, As the risk level increases, the fail-safe strategy is determined to be deceleration control with a large deceleration metric.

10. An apparatus for controlling autonomous driving in an autonomous vehicle, the apparatus comprising: A status information collector, configured to collect vehicle driving status information and system status information during autonomous driving; A system fault determination device, configured to sense faults based on system status information; An actuator status recognition device is configured to identify actuators that can be controlled normally when a fault is sensed. The risk calculator is configured to determine the risk level corresponding to the sensed fault based on information about normally controllable actuators and vehicle driving status. as well as A fail-safe strategy determination device is configured to determine a safe state based on actuator information and risk level that can be normally controlled, and to determine a fail-safe strategy corresponding to the safe state. The risk calculator includes: A fault type and quantity identification device is configured to identify fault type and fault quantity based on actuator information that can be normally controlled, and to calculate the fault quantity for an autonomous driving control system and / or actuators and / or sensors; An initial risk determination device, configured to determine the initial risk level based on the fault type; The first weight value determination device is configured to determine the first weight value based on the number of faults; The second weight value determination device is configured to determine a second weight value based on vehicle driving state information; and The final risk determination device is configured to calculate the final risk by taking into account the initial risk, a first weight value, and a second weight value together.

11. The apparatus for controlling autonomous driving of an autonomous vehicle according to claim 10, wherein, The fault types include at least one of the following: driver state and intent determination sensor fault, rain sensor fault for weather determination, autopilot controller fault, GPS receiver fault, rapid tire pressure drop fault, sensor fault for sensing the area in front of the vehicle fault, steering-related actuator fault, braking-related actuator fault, driving-related actuator fault, gear shifting-related actuator fault, or stability control-related actuator fault.

12. The apparatus for controlling autonomous driving of an autonomous vehicle according to claim 10, wherein, The fail-safe strategy determination device includes: An actuator determination device is configured to determine, among identified actuators that can be normally controlled, the actuator to be used that corresponds to the determined safety state. A maximum permissible time determination device configured to determine a maximum permissible time corresponding to a determined safety state based on a determined actuator to be used and a final risk level; and The scheme determination device is configured to determine the optimal fail-safe scheme by identifying the actuators to be used under the determined safe conditions.

13. The apparatus for controlling autonomous driving of an autonomous vehicle according to claim 12, wherein, The maximum allowable time is determined to be inversely proportional to the final risk level.

14. The apparatus for controlling autonomous driving of an autonomous vehicle according to claim 10, wherein, The vehicle driving status information includes at least one of the following: positioning signal information, vehicle external information, vehicle internal information, or precise map information. The vehicle external information includes at least one of radar sensing information, lidar sensing information, or information captured by an external camera. The vehicle interior information includes at least one of the following: information captured by an in-vehicle camera or driver biosensing information.

15. The apparatus for controlling autonomous driving of an autonomous vehicle according to claim 14, the apparatus further comprising: A driver status determination device configured to determine the driver's status based on information inside the vehicle. The risk calculator further determines the risk level based on the driver's condition.

16. The apparatus for controlling autonomous driving of an autonomous vehicle according to claim 10, wherein, The system status information includes at least one of the following: braking system information, stability control system information, steering system information, shifting system information, drive system information, camera system information, tire pressure measurement system information, fuel tank sensing system information, battery management system information, rain sensing system information, system information of sensors used to sense the area in front of the vehicle, or autonomous driving controller status information.

17. The apparatus for controlling autonomous driving of an autonomous vehicle according to claim 10, wherein, The actuator includes at least one of an electric parking brake, electronic stability control, electric power steering system, transmission control unit, or engine management system.

18. The apparatus for controlling autonomous driving of an autonomous vehicle according to claim 10, wherein, As the risk level increases, the fail-safe strategy determination device determines a fail-safe strategy that uses a large deceleration rate for deceleration control.

Citation Information

Patent Citations

  • Goal Gate Double layer honeycomb

    KR1020200080429A

  • Autonomous vehicle parking and transition to manual control

    CN107298095A

  • Autonomous vehicle failure mode management

    CN107757525A

  • Automatic vehicle operation device

    JP2000019071A