System unit having a first actuator system and a second actuator system

By designing a dual actuator system with auxiliary and emergency operation modes in the autonomous driving system, the problem of vehicle instability caused by system errors is solved, ensuring that the vehicle operates safely in the case of errors, and is suitable for highly autonomous driving environments.

CN115335267BActive Publication Date: 2025-08-12ROBERT BOSCH GMBH
View PDF 1 Cites 0 Cited by

Patent Information

Application Number
CN202180026361.1
Authority / Receiving Office
CN · China
Patent Type
Patents(China)
Current Assignee / Owner
Priority Date
2020-04-08
Filing Date
2021-03-17
Publication Date
2025-08-12
Estimated Expiration
2041-03-17

AI Technical Summary

Technical Problem

Existing autonomous driving systems are difficult to ensure the stability and safety of the vehicle in case of errors, especially when the driver cannot intervene, especially when one of the two brake units fails in the system, and cannot provide sufficient deceleration capability.

Method used

A system unit is designed, including two actuator systems, each with an auxiliary operation mode and an emergency operation mode, ensuring that at least one actuator system can always provide basic functions and provide a redundant safety layer to deal with system errors by switching to inactive, auxiliary and emergency operation modes in case of errors.

Benefits of technology

In case of system errors, ensure that the vehicle can enter a safe state safely, reduce the risk of failure, and avoid vehicle instability caused by the failure of a single actuator. It is suitable for highly autonomous driving environments.

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure CN115335267B_ABST
    Figure CN115335267B_ABST
Patent Text Reader

Abstract

A system unit (100) for an at least partially automated mobile platform, the system unit having at least one first actuator system (120) and a second actuator system (140), the first actuator system (120) and the second actuator system (140) each having at least one auxiliary operating mode and an emergency operating mode; and the first actuator system (120) and the second actuator system (140) are respectively set up and coupled for: switching to an inactive operating mode if a serious error is identified in the corresponding actuator system (120, 140); and switching to an auxiliary operating mode if one of the actuator systems (120, 140) switches to the inactive operating mode in order to additionally execute at least part of the functionality of the corresponding actuator system (120, 140) in the inactive operating mode; and switching to the emergency operating mode if a serious error is identified in the corresponding actuator system (120, 140) in the auxiliary operating mode.
Need to check novelty before this filing date? Find Prior Art

Description

Technical Field

[0001] The invention relates to a system unit for an at least partially automated mobile platform having at least a first actuator system and a second actuator system. Background Art

[0002] Driver assistance systems are increasingly prevalent in today's motor vehicles in various performance phases. They intervene in the vehicle's drive, control (e.g., steering), or signaling systems, either partially or automatically, or warn the driver shortly before a critical situation or assist him during a critical situation via a suitable human-machine interface.

[0003] For this purpose, in addition to stabilization functions, current vehicle braking systems, for example in the form of classic ESP / ABS, have an increasingly expanded range of functions: for example, in the case of braking actions, the driver is supported by power assistance when the brake pedal is actuated by an electromechanical brake booster (eBKV), or without active driver involvement, by assistance or partial assistance functions of system units for actively modulating the hydraulic brake pressure (for example: ESP, eBKV, booster unit, etc.). Summary of the Invention

[0004] Future control systems for highly automated and / or partially automated and / or autonomous and / or partially autonomous driving need to provide specific, possibly functional redundancies so that in the event of an error, a "fail-operational" system can be guaranteed, at least for a limited time, for example in the case of brake control systems, in order to enable a possible at least temporary lack of monitoring of the traffic situation by the driver, respectively a temporary lack of the responsible subject of the driver or the complete absence of the driver.

[0005] For example, a vehicle's braking system can be designed so that, if a first fault occurs in the system, all braking functions can be taken over by a subunit of the braking system. Furthermore, with known automated driving functions, such as those at SAE Level 3 or lower, responsibility for driving the vehicle may be returned to the driver or the journey may have to be terminated prematurely because no further functional fallback levels are provided. Furthermore, a second fault in such a braking system may result in the vehicle no longer being able to decelerate.

[0006] This is particularly important when such systems are used in driving modes in which no driver is present or cannot intervene.

[0007] By way of example, a braking system may include a primary and secondary stabilization actuator system, with the primary actuator system providing the (primary) stabilization function in a fault-free state. Typically, the secondary actuator system can take over certain functionality of the primary actuator system in its fault-free state. This functionality of the secondary actuator system can be limited to necessary functions for a fallback level or include the full functional scope of the primary stabilization actuator system. For example, a braking system in an autonomous vehicle, i.e., for the use case of SAE Level 4 autonomous driving, may include a primary and secondary brake unit. In the event of a fault in the braking system, the primary brake unit can perform the full functional scope without the secondary brake unit, while the secondary brake unit can have a portion of the primary unit's functional scope and, if necessary, take over this portion of the functionality.

[0008] This functionality provided by the main actuator system can, for example, include individual active and passive pressure modulation of the wheels, for example by means of an electronic stability program (ESP) return hydraulic system, and the auxiliary actuator system can, for example, include the functionality of single-channel active and / or passive pressure modulation, which can be achieved, for example, by means of a brake boost unit and / or an electromechanical brake booster.

[0009] Since a safe takeover by the driver in an SAE Level 4 vehicle is not possible in the event of an error, in which only one of the two brake units is functional, such a system should be designed to be as safe as possible.

[0010] Designing such a system with an optimal response to other errors is very complex due to the potential for combined errors, prone to errors, and uneconomical due to the very low probability of such situations. For an optimal response, all active controllers in the system must be designed for the corresponding error scenario. This means, in particular, that missing or erroneous signals must be intercepted, and all necessary signals from sensors and actuators must continue to be monitored for plausibility. However, since some error detection mechanisms are no longer effective due to an already detected error, this is only possible with high software development effort and a low probability of detecting the error.

[0011] According to one aspect of the present invention, a system unit, a use of the system unit, a method, an apparatus, a computer program product, and a computer-readable storage medium for controlling the system unit are described, which at least partially achieve the above-mentioned effects. Advantageous embodiments are the subject of various embodiments and the following description.

[0012] According to one aspect, a system unit for an at least partially automated mobile platform is provided, comprising at least one first actuator system and a second actuator system, each of which has at least one auxiliary operating mode and an emergency operating mode. The first actuator system and the second actuator system are each configured and coupled to switch to a non-active operating mode if a serious error is detected in the respective actuator system. Furthermore, the first actuator system and the second actuator system are each configured and coupled to switch to a secondary operating mode if one of the actuator systems switches to the non-active operating mode, in order to perform at least part of the functionality of the respective actuator system in the non-active operating mode. Furthermore, the first actuator system and the second actuator system are each configured and coupled to switch to an emergency operating mode if a serious error is detected in the respective actuator system in the secondary operating mode.

[0013] This system unit thus provides an additional layer of safety in the form of an emergency operating mode, which is activated only upon a second critical error of the system unit, i.e., a first error of the corresponding actuator system that remains active in the auxiliary operating mode. For example, the actuator system that remains active can meet all requirements for the system unit in the auxiliary operating mode of the actuator system until a critical error occurs in the auxiliary operating mode. After the second error of the system unit, the actuator system that remains active should provide functionality to minimize the risk to the mobile platform or its occupants. This functionality can have significantly lower requirements than in the normal operating mode.

[0014] For example, a system unit in the form of a brake system can be provided with an additional safety layer that is only activated if a second fault affects the remaining brake units. A correspondingly active actuator system in the form of the brake system's remaining active brake units, operating in a secondary operating mode, can meet all requirements for the fallback layer of known brake systems until the second fault occurs. After the second fault occurs, the remaining active actuator systems of the brake system, such as the remaining active brake units, can be used with reduced functionality to perform maneuvers designed to minimize the risk to the vehicle's occupants. Such maneuvers are subject to only the still significantly reduced requirements for the stability and dynamics of a mobile platform equipped with such a brake system.

[0015] Thus, such a system unit can provide an operating mode that is as robust as possible for a system unit such as a brake system, which can, with minimal sensor, communication and actuator systems, bring a mobile platform such as a vehicle into a safe state in the described error situation.

[0016] If such a system unit is implemented in the form of a redundant brake system, a brake system for highly autonomous driving can thus be provided.

[0017] Thus, the risk of a (total) failure can be minimized using the system unit without having to use a third actuator system by implementing an additional safety level in the described manner in both actuators of the system unit. This additional safety level is switched active in the respective actuator system, which, if an error is also detected or identified at this actuator system, provides, for example, a braking functionality in the first fallback level.

[0018] The described system unit therefore provides a further safety layer which is largely independent of errors in the communication between the corresponding actuator systems and / or sensor systems and / or control units of the actuator systems in order to be able to continue to perform (emergency) braking.

[0019] To this end, the corresponding actuator systems have control mechanisms that can directly control only minimal functionality. In a braking system, this may involve not only the hydraulic valves (if they must be switched to a specific position to build up pressure in the actuator system) but also the engine control unit. Using such system units, redundant braking systems for highly autonomous driving can be provided.

[0020] Advantageously, even after two serious errors occur or are detected in a system unit, such as a brake system consisting of a main and an auxiliary brake unit, the system units are not switched off individually, but rather (emergency) braking is still performed, for example.

[0021] In other words, in the event of a first critical error, the primary brake unit can perform its full range of functions without the auxiliary brake unit, or the auxiliary brake unit can take over a portion of the primary unit's range of functions. This provides an additional safety layer that is only activated if a second error in a system unit affects the remaining brake units. For example, the remaining brake units can meet all requirements for the fallback layer of a known brake system until a second error occurs in the brake system. This additional fallback layer provides additional safety in the event that only one of the two brake units is functional. The respective actuator system can be configured to additionally perform at least part of the functionality of the respective other actuator system.

[0022] According to one aspect, it is proposed that the first actuator system and the second actuator system are each configured and coupled to receive a setpoint value; and in the emergency operating mode it is checked whether the setpoint value is currently received.

[0023] Such setpoint values can be predefined for the respective actuator system in order to set the setpoint value in a control loop or according to a characteristic curve. Since communication with the sensor that generates the setpoint value can be disrupted in the event of an error, the integrity of this communication in the form of received setpoint values can be checked in emergency operating mode. The further behavior of the respective actuator system in emergency operating mode can then be made dependent on the setpoint value.

[0024] According to one aspect, a first actuator system and a second actuator system are each set up and coupled to perform a first action using a received current setpoint value in an emergency operating mode and / or to perform a second action in the absence of a received current setpoint value, wherein the first action is performed depending on the value of the received current setpoint value.

[0025] Such a setpoint value can, for example, be transmitted via a bus system from a setpoint-generating system and / or sensor to a corresponding actuator system. The system unit can be configured to check this transmission or communication, for example in an emergency operating mode, in order to determine whether such a setpoint value can be implemented, for example, in the form of a braking force by a virtual driver of an at least partially automated mobile platform. The first action can, for example, be an action implemented according to the value of the setpoint value, and the second action can, for example, be a fixed, predetermined action. For a braking system, the first action can correspond to braking with a predetermined braking force or a correspondingly predetermined braking process, and the second action can be a predetermined emergency braking operation. The first action can be implemented using a control circuit and / or a control device using a characteristic curve.

[0026] In order to keep the dependency of the system unit on internal and external signals that may no longer be monitored in this emergency operating mode as low as possible, the actuation of the actuator system in the emergency operating mode can be controlled based on a characteristic curve and / or can be controlled using a complete regulation.

[0027] If the current setpoint value is delivered to the corresponding actuator system at the corresponding time, this check of the functionality of the communication with the system providing the setpoint value can be positively assessed. For example, in the case of the second action, a mobile platform, such as a partially automated vehicle, can be put into a safe state, for example by braking.

[0028] According to one aspect, a critical error is detected by the respective actuator system itself and / or by another actuator system in each actuator system and / or by a superordinate system. If the presence of a critical error in the respective actuator system is detected by a superordinate system, other variables and dependencies with other systems can also be taken into account. If the respective actuator system detects the critical error itself, in particular, greater independence and correspondingly lower susceptibility to, in particular, external errors can be achieved.

[0029] According to one aspect, the first actuator system is an electronic brake booster (eBKV) system, and the second actuator system is an electronic stability program (ESP) system of a mobile platform; or the first actuator system is a first steering system of a mobile platform, and the second actuator system is a second steering system of the mobile platform; or the first actuator system is an integrated power brake system (IPB), and the second actuator system is a redundant brake unit (RBU) of the mobile platform.

[0030] The second steering system can be designed as a redundant system for the first steering system. An integrated power brake (IPB) with a redundant brake unit (RBU) is a redundant brake system combination, which is an alternative to a system consisting of an electronic brake booster (eBKV) system and an electronic stability program (ESP) system for automated driving.

[0031] Here, the Integrated Power Brake (IPB) takes over the tasks of the eBKV and ESP using an actuator system (in other words, the Ein-Box brake system). The Redundant Braking Unit (RBU) only takes over the brake pressure buildup and stabilization functions in the event of a fault in the Integrated Power Brake (IPB) and is otherwise completely passive.

[0032] The resulting safety of the brake system can be increased by configuring the brake system in terms of system units.

[0033] The use of the above-described system unit for controlling an at least partially automated mobile platform is proposed. The above-described additional safety of the described system unit results in corresponding safety of the at least partially automated mobile platform.

[0034] A method for controlling a system unit for an at least partially automated mobile platform is provided. The system unit includes a first actuator system and a second actuator system, wherein the first actuator system and the second actuator system each have a secondary operating mode and an emergency operating mode. The method includes the following steps: In a first step, if a critical error is detected in the corresponding actuator system, the corresponding actuator system switches to a non-active operating mode. In another step, if one of the actuator systems switches to the non-active operating mode, the corresponding actuator system switches to a secondary operating mode to perform at least part of the functionality of the corresponding actuator system in the non-active operating mode. In another step, if a critical error is detected in the corresponding actuator system in the secondary operating mode, the actuator system switches to an emergency operating mode.

[0035] Throughout this description of the present invention, the sequence of method steps is presented so that the method can be easily understood. However, those skilled in the art will recognize that many of the method steps can also be performed in another order and lead to the same or corresponding results. In this sense, the order of the method steps can be changed accordingly. Some features are provided with numerals to improve readability or to make the assignment clearer, but this does not imply the presence of a particular feature.

[0036] The above-mentioned advantages of the system unit also result correspondingly for the method described here for controlling a system unit and also for other aspects of the method.

[0037] According to one aspect, in a method for controlling a control system unit, an actuator system in emergency operating mode verifies whether setpoint values for a first actuator system and / or a second actuator system are currently being received. Such setpoint values can be predefined for the respective actuator system in order to set the setpoint values in a control loop or according to a characteristic curve. Since communication with sensors that generate the setpoint values can be disrupted in the event of an error, it is possible to verify in emergency operating mode whether such communication, in the form of received setpoint values, is intact. Further behavior of the respective actuator system in emergency operating mode can then be made dependent on the setpoint values.

[0038] According to one aspect, in a method for controlling a system unit, an actuator system in emergency operating mode performs a first action using the value of the currently received setpoint value when a current setpoint value is received and / or performs a second action when no current setpoint value is received.

[0039] According to one aspect, in a method for controlling a control system unit, the actuator system in emergency operating mode executes a first action using the received value of the current setpoint value, using a predefined characteristic curve of the actuator system in emergency operating mode (e.g., for the motor current) and / or a predefined valve position for the actuator system in emergency operating mode according to a valve switching pattern. This allows the method for controlling the control system unit to be designed as robustly and uncomplicatedly as possible for the first action.

[0040] A method is proposed, which provides a control signal for operating an at least partially automated vehicle based on an identified serious error and / or an inactive operating mode and / or an auxiliary operating mode and / or an emergency operating mode of a method for controlling a system unit; and / or provides a warning signal for warning a vehicle occupant based on an identified serious error and / or an inactive operating mode and / or an auxiliary operating mode and / or an emergency operating mode.

[0041] The term "based on" is to be understood broadly with respect to the feature of providing a control signal based on a detected serious error and / or inactive operating mode and / or auxiliary operating mode and / or emergency operating mode of a method for controlling a control system unit. It is therefore understood that the detected serious error and / or inactive operating mode and / or auxiliary operating mode and / or emergency operating mode of a method for controlling a control system unit is used for each determination or calculation of a control signal, without excluding the use of other input variables for such determination of the control signal.

[0042] Since corresponding functionalities, such as sufficient deceleration, cannot always be guaranteed in corresponding restricted operating modes (e.g., assistance or emergency modes), a superordinated unit or control device, such as a virtual and / or real driver, can be informed of this limitation. This allows the superordinated unit to call up other functionalities, such as auxiliary braking by means of auxiliary actuator systems, such as the engine control unit, the parking brake, or steering interventions to avoid collisions.

[0043] A device is proposed, which is configured to carry out one of the above-mentioned methods. With such a device, the corresponding method can be easily integrated into different systems.

[0044] A computer program is proposed, which comprises instructions which, when executed by a computer, cause the computer to carry out the above-described method. Such a computer program enables the described method to be used in various systems.

[0045] A machine-readable storage medium is proposed, on which the above-mentioned computer program is stored. The computer program can be transported by means of such a machine-readable storage medium.

[0046] A mobile platform can be understood as an at least partially automated mobile system and / or driver assistance system for a vehicle. An example could be an at least partially automated vehicle or a vehicle with a driver assistance system. That is, in this context, at least partially automated systems include mobile platforms with at least partially automated functionality, but mobile platforms also include vehicles and other mobile machines, including driver assistance systems. Other examples of mobile platforms could be driver assistance systems with multiple sensors, mobile multi-sensor robots (such as robotic vacuum cleaners or lawn mowers), multi-sensor monitoring systems, manufacturing machines, personal assistants, or access control systems. Each of these systems can be a fully or partially automated system.

[0047] In addition, it should be noted that "comprising" does not exclude other elements, and "a" or "an" does not exclude a plurality. Furthermore, it should be noted that features described with reference to one of the above embodiments can also be used in combination with other features of other embodiments described above. Reference numerals in the claims should not be considered as limiting. BRIEF DESCRIPTION OF THE DRAWINGS

[0048] The embodiments of the present invention are Figures 1 to 2 , and are described in more detail below.

[0049] Figure 1 shows a simplified braking system with an electromechanical brake booster and an electronic stability program system; and

[0050] Figure 2 A flow chart of a method for controlling a system unit for an at least partially automated mobile platform having a first actuator system and a second actuator system is shown. DETAILED DESCRIPTION

[0051] Figure 1 The redundant embodiment of a braking system 100 is summarized. The braking system has at least one first actuator system 120 in the form of an electromechanical brake booster 120 with the possibility of single-channel active and, if necessary, passive pressure modulation, such as a fail-boost unit or an electromechanical brake booster, and a second actuator system 140 in the form of an electronic stability program system 140 for wheel-specific active and passive pressure modulation using an ESP return hydraulic system, which is hydraulically coupled via a connection 145. The electronic stability program system 140 is connected to a brake system 160 for the vehicle's tires via a further hydraulic connection 165. The first actuator system 120 and the second actuator system 140 can also be coupled signal-wise and / or electrically.

[0052] Figure 2 Flow chart outlining a method 200 for controlling a system unit 100 for an at least partially automated mobile platform having a first actuator system 120 and a second actuator system 140 , wherein the first actuator system 120 and the second actuator system 140 each have an auxiliary operating mode and an emergency operating mode.

[0053] In a first step S1 , a serious error is detected in the first or second actuator system 120 , and the respective actuator system 120 , 140 that has experienced the error is switched to an inactive operating mode.

[0054] In a further step S2 , the respective actuator system that is not subject to the error is switched to the auxiliary operating mode in order to execute at least part of the functionality of the respective actuator system that is subject to the error and is in the inactive operating mode.

[0055] In a further step S3 , it is determined whether a serious error is detected in the respective actuator system which is in the auxiliary operating mode.

[0056] In a further step S4, if a serious error is detected in the actuator system, the corresponding actuator system in the auxiliary operating mode is switched to the emergency operating mode S4a. In the brake system, for this purpose, the valve can be switched to the pressure build-up position S4b.

[0057] In a further step S5 , the respective actuator system in emergency operating mode checks whether the setpoint values for first actuator system 120 and / or second actuator system 140 are currently being received or whether bus communication with the setpoint-generating system or sensor is possible.

[0058] Depending on the result in step S5 , when the currently received setpoint value is present, the actuator system in emergency operating mode performs a first action S6 , such as braking, using the value of the currently received setpoint value, for example by controlling the actuator system engine based on a characteristic curve.

[0059] Alternatively, a second action S7 is performed in the absence of a received current setpoint value, such as an emergency stop of the vehicle, in order to minimize the risk of an accident (blind stop).

Claims

1. A system unit (100) for an at least partially automated mobile platform, comprising at least one first actuator system (120) and a second actuator system (140), wherein the first actuator system (120) and the second actuator system (140) each have at least one auxiliary operating mode and an emergency operating mode; and The first actuator system (120) and the second actuator system (140) are respectively configured and coupled to: If a serious error is detected in the corresponding actuator system (120, 140), the corresponding actuator system (120, 140) that has experienced the serious error is switched to an inactive operating mode; and If one of the actuator systems (120, 140) is switched to the inactive operating mode, the corresponding actuator system (120, 140) that is not subject to a serious error is switched to an auxiliary operating mode in order to perform at least part of the functionality of the corresponding actuator system (120, 140) in the inactive operating mode; and If a serious error is detected in the corresponding actuator system (120, 140) in the auxiliary operating mode, the corresponding actuator system (120, 140) in the auxiliary operating mode is switched to the emergency operating mode; The first actuator system (120) and the second actuator system (140) are respectively configured and coupled to: Accepting the setpoint value; and checking in emergency operation mode whether the setpoint value is currently accepted; The first actuator system (120) and the second actuator system (140) are each configured and coupled to: perform a first action in an emergency operating mode using a received current setpoint value and / or perform a second action in the absence of a received current setpoint value, wherein the first action is performed depending on the value of the received current setpoint value.

2. The system unit (100) according to claim 1, wherein the critical error is detected by the respective actuator system (120, 140) itself and / or by another actuator system in each of the actuator systems (120, 140) and / or by a superordinate system.

3. The system unit (100) according to claim 1 or 2, wherein the first actuator system (120) is an electronic brake booster (eBKV) system and the second actuator system (140) is an electronic stability program (ESP) system of a mobile platform; or the first actuator system (120) is a first steering system of a mobile platform and the second actuator system (140) is a second steering system of the mobile platform; or the first actuator system (120) is an integrated power braking system and the second actuator system (140) is a redundant braking unit of the mobile platform.

4. Use of a system unit (100) according to one of claims 1 to 3 for controlling an at least partially automated mobile platform.

5. A method (200) for controlling a system unit (100) for an at least partially automated mobile platform, the system unit comprising a first actuator system (120) and a second actuator system (140), the first actuator system (120) and the second actuator system (140) each having an auxiliary operating mode and an emergency operating mode, the method comprising the following steps: If a serious error is detected in the corresponding actuator system (S1), the corresponding actuator system that has experienced the serious error is switched to an inactive operating mode; If one of the actuator systems (120, 140) changes to the inactive operating mode, the corresponding actuator system (120, 140) that is not subject to a serious error is changed to an auxiliary operating mode (S2) in order to perform at least part of the functionality of the corresponding actuator system (120, 140) in the inactive operating mode; and If a serious error is detected in the corresponding actuator system in the auxiliary operating mode (S3), the corresponding actuator system in the auxiliary operating mode is switched to the emergency operating mode (S4); wherein the actuator system (120, 140) in emergency operating mode checks (S5) whether a setpoint value for the first actuator system (120) and / or the second actuator system (140) is currently being received; The actuator system (120, 140) in emergency operating mode executes a first action (S6) with the value of the currently received setpoint value when a current setpoint value is received and / or executes a second action (S7) when no current setpoint value is received.

6. A method (200) according to claim 5, wherein the actuator system (120, 140) in emergency operating mode performs the first action (S6) using the received current rated value with the aid of a predefined characteristic curve of the actuator system (120, 140) in emergency operating mode and / or a predefined valve position of the actuator system (120, 140) in emergency operating mode.

7. A method according to claim 5 or 6, wherein a control signal for operating an at least partially automated vehicle is provided based on the identified serious error and / or the inactive operating mode and / or the auxiliary operating mode and / or the emergency operating mode; and / or a warning signal for warning vehicle occupants is provided based on the identified serious error and / or the inactive operating mode and / or the auxiliary operating mode and / or the emergency operating mode.

8. A device for controlling a system unit (100) of an at least partially automated mobile platform, the device being configured to carry out the method according to any one of claims 5 to 7.

9. A computer program product comprising a computer program, the computer program comprising instructions which, when the computer program is executed by a computer, cause the computer to perform the method according to any one of claims 5 to 7.

10. A machine-readable storage medium having a computer program stored thereon, the computer program comprising instructions which, when the computer program is executed by a computer, cause the computer to perform the method according to any one of claims 5 to 7.

Citation Information

Patent Citations

  • Brake system for a vehicle and a method for operating a brake system for a vehicle

    US20100198473A1