Fully automated guidance methods and systems for motor vehicles and motor vehicles
By storing a machine-readable set of traffic rules in a traffic rules database and using control devices to adjust the trajectory of motor vehicles, the problem of traffic rule compliance in fully automated driving systems for motor vehicles under different geographical areas and driving conditions has been solved, achieving efficient and flexible fully automated guidance and regulatory adaptation.
Patent Information
- Application Number
- CN202180032482.7
- Authority / Receiving Office
- CN · China
- Patent Type
- Patents(China)
- Current Assignee / Owner
- Priority Date
- 2020-05-13
- Filing Date
- 2021-02-17
- Publication Date
- 2026-01-30
- Estimated Expiration
- 2041-02-17
AI Technical Summary
In the existing technology, fully automated driving systems for motor vehicles have difficulty effectively complying with complex traffic rules caused by regional differences, and existing systems require human intervention, making it difficult to achieve fully automated guidance in different geographical areas and driving conditions.
By storing machine-readable traffic rule sets for multiple geographic regions and driving conditions in a traffic rule database, the system can access and invoke the corresponding rules using a control device, check and adjust trajectories to ensure compliance with traffic rules, including converting them into machine-readable form using a unified modeling language and a system modeling language, and making real-time adjustments based on location data and sensor information.
It enables fully automated guidance of motor vehicles in different geographical areas and driving conditions, reduces human intervention, improves the accuracy and flexibility of traffic rule compliance, supports frequent regulatory changes, and provides driving records to prove compliance with traffic rules.
Smart Images

Figure CN115515837B_ABST
Abstract
Description
Technical Field
[0001] This invention relates to a method and system for fully automatically guiding / controlling a motor vehicle in at least one driving situation type / level, wherein the vehicle system has control devices and accesses position data from the vehicle's position sensors. Furthermore, this invention also relates to a motor vehicle. Background Technology
[0002] Expanding the autonomous driving capabilities of motor vehicles remains an important research topic. Existing technologies have proposed vehicle systems for a wide range of driving scenarios, allowing for, in particular, fully automated guidance of motor vehicles. Examples of such driving scenario types include parking scenarios, especially for automated parking systems, traffic congestion scenarios on highways (e.g., so-called traffic jam automation), and / or, in general, types for highway driving (e.g., so-called highway automation). To date, this type of vehicle system has presupposed continuous monitoring of the driver; that is, the driver must be in a so-called "closed loop / online" state and able to intervene when problems arise or when in doubt. Current research here also primarily focuses on vehicle systems with higher levels of autonomy, such as SAE Level 3 and higher (see SAE J3016 standard).
[0003] Highly automated and fully automated vehicle guidance systems often also require the ability to comply with traffic regulations, which is sometimes a requirement of those regulations. However, because compliance with traffic rules must be manually implemented into the corresponding vehicle guidance algorithms, this presents an extremely high level of implementation difficulty. An additional problem arises because traffic rules can vary significantly from region to region, especially not only between countries but also sometimes between administrative regions, such as between states or even between federal states. This results in a huge workload, and another challenge is proving that the resulting vehicle guidance algorithms actually comply with traffic rules. Summary of the Invention
[0004] Therefore, the object of the present invention is to propose an improved method for implementing traffic rules when fully automated guiding motor vehicles.
[0005] To achieve this, set the following steps in the methods of the type mentioned at the beginning:
[0006] - Provides a traffic rules database, in which sets of traffic rules for multiple geographic regions are stored in a machine-readable, formal language, and the control device can access the traffic rules database.
[0007] - Based on the current location data, determine the geographical area where the vehicle is currently traveling, and retrieve the set of traffic rules for the current geographical area from the traffic rule database via the control device.
[0008] - After determining the current trajectory via the control device, or during the determination of the trajectory, the trajectory is checked for compliance with traffic rules according to the traffic rule set for the geographical area of the current travel area invoked via the control device. If traffic rules are not followed, the current trajectory is adjusted.
[0009] -Guides the vehicle based on the current trajectory it is to travel.
[0010] Therefore, it was identified that traffic rules can be decomposed into specific schemes based on "if-then-else structures (conditional structures)". This structure can be described in a regular language, for example and preferably in a unified modeling language and / or a system modeling language (UML and / or SysML), into a machine-readable form, so that the control device of the vehicle system used for automatically guiding motor vehicles can directly understand the description and can be used to check the determined current trajectory to be traveled. In other words, a machine-readable regular language, particularly oriented towards if-then-else structures, is used to provide a traffic rule database, which advantageously and preferably centrally provides matching sets of traffic rules in a machine-readable form for many motor vehicles and for areas to be traveled by fully automatically guided motor vehicles.
[0011] Position data from the vehicle's position sensors, such as those from a Global Navigation Satellite System (GNSS) or GPS sensors, can be used to determine, in known ways and methods, the vehicle's current geographic location, for example, by comparison with a digital map ("map matching"). If a central server device is used to provide a traffic rules database, then for the corresponding geographic area, the required set of traffic rules can be retrieved from the database and preferably stored locally within the vehicle. If, for example, a trajectory determination algorithm is used to determine the future trajectory for the vehicle, then the trajectory can be checked against the traffic rules in the set of traffic rules already provided in a suitable machine-readable format to ensure compliance with these rules, allowing adjustments to be made if at least a portion of the trajectory fails to comply with traffic rules. Here, the traffic rules database can, of course, be specific to the types of driving situations applicable to the vehicle system. In this way, the number of traffic rules that need to be formally described in the traffic rules database can be reduced if necessary.
[0012] Therefore, in addition to basic vehicle guidance capabilities, vehicle systems can also be, for example, highway autonomous driving systems, parking systems, traffic jam autonomous driving systems, overtaking assistance systems, etc. Generally speaking, it can be said that, for example, highway types and / or local road types and / or urban types and / or parking types and / or overtaking process types and / or traffic jam types can be used as driving situation types. Of course, a large number of other driving situation types are also conceivable. If the vehicle system is limited to certain specific driving situation types, then it is not necessary to enforce all traffic rules valid within a geographical area, but for example, traffic rules related to at least one corresponding driving situation type can be selected and stored in a traffic rule database in a machine-readable formal language. If, for example, the scenario covered by a traffic rule does not occur in the driving situations of that driving situation type, then the corresponding traffic rule should not be included in the traffic rule database specific to that at least one driving situation type. Therefore, for example, on a highway (highway type), the following situation will not occur where the "right-before-left" rule is important. This is because "right-before-left" intersections are generally not possible on highways, and this can also be recorded. In the highway-type example, this also applies to the handling of parking signs, etc. In another example, the parking assistant does not require any traffic rules related to high-speed operation on a highway.
[0013] As already mentioned, a particularly advantageous design of the present invention specifies that the database is stored on a central server device external to the vehicle and connected to the control device via a communication link, and is used when guiding multiple motor vehicles. Since a large number of motor vehicles typically have communication devices capable of communicating in mobile radio networks and, therefore especially, the Internet, the central server device can be accessed by the control device using the communication device. In this way, the traffic rules database can be used by a large number of motor vehicles, all of which can invoke traffic rules that describe the physical constraints used for trajectories, and these traffic rules are taken into account accordingly in the fully automated guidance of the motor vehicles. On the other hand, only one traffic rules database needs to be maintained for all motor vehicles, which can take into account the problem of frequent regulatory changes. That is, without continuous, especially manual, modifications to the vehicle system's control device, specifically the vehicle guidance algorithm in the software, the latest traffic rules can be provided to each motor vehicle and directly applied to each vehicle.
[0014] Key advantages of using a machine-readable formal language also include the availability of a wealth of tools developed specifically for that language, which can be used to record, examine, and monitor traffic rule databases. Thus, for example, it is possible to establish connections with the Lastheft system through appropriate tools, particularly the corresponding Automotive SPICE standards. Formal languages also allow for updates due to changes in legislation / case law. Furthermore, they can reflect the structural hierarchy between different legal norms, which will be discussed in detail later.
[0015] As already explained, since different sets of traffic rules can be associated with different driving situations and thus different applications of the vehicle system, the rules in the traffic rule database do not necessarily have to be forcibly divided into several sets of traffic rules only for specific regions. Instead, multiple sets of traffic rules can be provided for different driving situation types in various geographical regions. Therefore, an advantageous extension of the invention stipulates that in the traffic rule database, multiple sets of traffic rules, each assigned to a corresponding driving situation type, are stored for each geographical region. The control device determines the current driving situation type associated with the current driving situation that forms the basis of the current trajectory to be traveled and invokes the traffic rule set associated with the current travel area and the current driving situation type. In this way, only traffic rules related to the driving situation are checked in a specific driving situation, which reduces computational work and avoids the physical limitations of trajectory errors. Here, driving situation can also describe a specific application situation / use case that is not necessarily caused by the autonomous vehicle / this vehicle. An overtaking process type is proposed as an example because specific traffic rules apply to the overtaking process, while other traffic rules applicable to the overtaken application situation are irrelevant. As has been pointed out in this case, specific application scenarios can also be formally coded in the traffic rules themselves, either additionally or alternatively, which will be explained in more detail below.
[0016] Here, it should also be noted that, if necessary, the following situations may arise where the only possible adjustment to the trajectory could lead to leaving the application scenario, or even the current driving situation excluding the application scenario. For example, if traffic rules associated with an overtaking maneuver cannot be followed (flashing lights, failing to slow down, etc. for a specific time period), for example due to a local speed limit ahead, then the overtaking maneuver may be interrupted, and the interruption of the overtaking maneuver must be reflected accordingly in the vehicle guidance function. In a particularly advantageous embodiment of the invention, it may also be stipulated that at least one set of traffic rules includes rule portions that cannot be derived from legal provisions and are used to change the type of driving situation. In other words, driving situations and their implementation that are forcibly changed due to different circumstances can also be described by traffic rules, even when there are at least some special legal provisions for this.
[0017] Here, different design schemes can be considered regarding the point in time when the control device retrieves the traffic rule set from the traffic rule database. For example, it could be stipulated that the traffic rule set is retrieved when the current driving area changes and / or the current driving situation type changes. If the traffic rule set is also categorized according to driving situation type, then retrieving the traffic rule set when the current driving situation type changes is particularly suitable. Changes in driving situation type and current driving area lead to changes in the available traffic rules, thus prompting the control device to retrieve the currently available traffic rule set from the traffic rule database.
[0018] Furthermore, it may be appropriate to invoke the traffic rule set at a predetermined update time, particularly after a day has passed, and / or when update information indicating an update to the traffic rule database is available. As already mentioned, traffic rules can change over time, for example due to changes in legislation and / or case law, thus necessitating timely updates to the traffic rule database, which should also be reflected within the vehicle. For example, this could be done periodically, such as daily or weekly, at least once a year, wherein update information for the traffic rule database (e.g., as an update signal) can also be transmitted via a communication link between the traffic rule database and the control device, subsequently updating the traffic rule set within the vehicle.
[0019] Specifically, in the context of an application, and especially under the preconditions of that application, at least one traffic rule in the traffic rule set can describe the legal application scenarios and obligations, particularly permissions, that limit applicability. In this way, a modular association can ultimately be established, following a methodology of use cases. Obligations in implementing an application scenario can be understood, for example, as conditions that ensure its description remains within that application scenario, where temporal hierarchies are conceivable. Preconditions / permissions for an application scenario might, for example, relate to the basic permissibility of that application scenario. For instance, if the application scenario is an overtaking process, then overtaking is assumed to be permitted; similarly, in the application scenario of a "turn," the permission to turn is checked.
[0020] It can be specified here that at least one continuously applicable scenario is used, particularly regarding speed limits, and / or scenarios caused by other road users, especially overtaking. A continuously applicable scenario is provided in the example of speed limits because, in principle, the current maximum speed is to be achieved, which can be derived as the minimum value of different speed limits (described by traffic rules). Different, specific input values describing driving situations exist here, especially those that can be added in addition to the pure conditions or traffic signs on a particular road type / location. For example, traffic rules leading to a specific speed limit can be checked for factors such as whether continuous control of the vehicle cannot be ensured, whether visibility is poor due to weather conditions, whether the braking distance is greater than the foreseeable road segment, whether the low beam headlights are activated, whether the traffic conditions are unclear, and / or whether the vehicle has snow chains.
[0021] However, there are also legitimate application scenarios where conscious action by the autonomous vehicle is not required. An example of such an application is being overtaken, where the conditions for overtaking can be met by other road users. Nevertheless, obligations arise from these application scenarios, such as prohibiting increasing or even decreasing speed to prevent accidents.
[0022] In another advantageous embodiment of the invention, it can be specified that the use of traffic rules in the current set of traffic rules invoked for the currently traveling geographical area, and in particular the checking and adjustment of the current trajectory to be traveled (especially including a version of the traffic rule database from which the used traffic rules have been invoked), is recorded in a storage medium, particularly a ring memory, by a control device. In other words, a "driving recorder" is proposed that can automatically record each application of traffic rules, including the version of the traffic rule database from which the used traffic rules originate. In this way, for example in the case of an accident, the vehicle system (specifically the vehicle guidance function) can be well demonstrated to comply with traffic rules. Since such information is needed especially in the case of special events, it may be suitable to use a ring memory or ring buffer as the storage medium, that is, to store a certain amount of recorded data according to the FIFO principle. In this way, in principle, a certain number n of the most recent use of traffic rules can be obtained in the storage medium, so that in the event of a special event, especially an accident, it can be demonstrated that the motor vehicle has taken the traffic rules into account. That is, the impact of traffic rules on the trajectory to be physically implemented by the motor vehicle can be tracked.
[0023] In this context, it is particularly advantageous to record changes, especially updates, in the traffic rules database, for example, using a change log. It is also suitable, in this way or alternatively, to restore the traffic rules database to its previous state. It should be noted that changes to the traffic rules database can also include structural changes, such as to summarize and generalize the common parts of local traffic rules when necessary, where local characteristics can be reflected through additional specific rules, especially traffic rules and / or parameterization.
[0024] In this context, it should also be noted that different geographical regions can only be distinguished through parameterization, such as different maximum speeds or different distance rules. Therefore, it is conceivable to store at least some traffic rules as public data objects to generate a set of traffic rules for a geographical region, and to appropriately parameterize these data objects, which can also be reflected in a traffic rule database or within the accessed area.
[0025] In another advantageous embodiment of the invention, it can be specified that the conflict-free nature of the traffic rules database is automatically checked before it is provided. Tools or general software tools are readily available for checking the conflict-free nature, which is particularly important to traffic rules, when using known, especially standardized, machine-readable formal languages such as SysML and / or UML. Machine verifiability of the conflict-free nature can be achieved by using machine-readable formal languages and the formal expressions thus provided. Therefore, the need to identify and avoid contradictions can be addressed.
[0026] In a suitable extension of the invention, the traffic rule set may include at least one structural hierarchy, such that at least one condition is assigned to invalidate at least one traffic rule and / or a priority is assigned to the traffic rule, and / or at least one driving situation type is defined, including emergency driving situations, particularly collision situations, and a restricted set of traffic rules from a traffic rule database is assigned to the at least one driving situation type, and / or the control device at least partially stops checking the invoked traffic rule dataset for the currently driving area when an emergency driving situation is identified.
[0027] Many legal entities possess a certain structural hierarchy where specific traffic rules may be ignored and / or altered under special circumstances. In one example, crossing a solid line may be necessary to avoid endangering human life. Here, in a less preferred embodiment, it is conceivable to formally describe this structural hierarchy for these situations. In particular, at least one condition may be assigned to at least a portion of a traffic rule to invalidate it, or priorities may be provided, wherein ultimately, a legally constructed traffic rule with higher priority, such as the requirement to yield to pedestrians, is not enforced, thus reflecting the structural hierarchy established through legislation.
[0028] In a more preferred embodiment, a special, particularly restricted, set of traffic rules may be defined for emergency driving situations, such as collision situations, and this set of traffic rules is then assigned to the corresponding driving situation type. In other words, collision avoidance is ensured, for example, by its own competent authority, which is only activated when there is actual risk. This set of traffic rules does not fully implement legal principles, thus allowing crossing of solid lines, for example, in cases where safety is taken into consideration. Finally, in this respect, an advantageous design of the invention is also conceivable, in which such failure of traffic rules is enforced by the control device itself in special driving situations, for example, in the checking algorithm that performs the checks. For example, when an emergency driving situation is identified, the control device may at least temporarily, for example, at least partially, stop the checks during the duration of the emergency driving situation. The advantage of this variant is that it simplifies the design and management of the traffic rule database, but it requires greater effort on the motor vehicle side, at least in cases with more complex structural hierarchies, such as when it is necessary to distinguish between different emergency driving situations, especially different driving situation types.
[0029] Within the scope of this invention, various advantageous architectures are conceivable for specifically performing the checking and adjustment of the currently to-be-traveled trajectory. Thus, in a first variant, the control device may be configured to have a trajectory determination unit that executes a trajectory determination algorithm and a checking unit that executes a checking algorithm. The trajectory determination unit is used to determine the currently to-be-traveled trajectory to be checked, and the checking unit is used to check the determined, currently to-be-traveled trajectory. Here, the trajectory can be determined first and then checked because it can be assumed that violations of traffic rules are quite rare in normal trajectory planning. This is especially true when at least a portion of the traffic rules, particularly those applicable to ongoing scenarios, are already included as boundary conditions to be considered and checked during the determination process.
[0030] In this follow-up check, it can be specified in the first architecture that, in the event of non-compliance, the trajectory with at least one adjustment information is returned to the trajectory determination unit that performed the adjustment. That is, a feedback loop for trajectory planning is ultimately provided, which provides additional information as input to the trajectory planning, specifically including traffic rule violations and / or requirements for compliance. This further utilizes existing trajectory determination algorithms for trajectory planning, thus eliminating the need for additional complex program code, although iterative improvements may be necessary.
[0031] Other alternative design schemes for the architecture, while providing trajectory determination and inspection units, specify that in the event of non-compliance, the adjustment algorithm of the inspection unit is used to adjust the trajectory. That is, in this case, the inspection unit, which can also be referred to as a traffic rule monitor in other respects, has its own correspondingly developed trajectory planning type in order to achieve compliance with traffic rules in a targeted and less complex manner.
[0032] As these architectures show, the adjustment unit used to adjust the current trajectory can be designed, at least in part, to be integrated with other functional units.
[0033] It is also conceivable that, as already shown, during the determination of the current trajectory, at least a portion of the traffic rules of the current traffic rule set has been applied, particularly as boundary conditions. Then, the checking unit is at least partially integrated into the trajectory determination unit. This could easily be the case where all traffic rules—especially as boundary conditions—are already included in the trajectory planning. During the determination of the current trajectory, the trajectory is adjusted accordingly in case of a violation of the boundary conditions. However, even in this case, for safety, a check can still be performed again after determination. In these examples, the checking unit can also be constructed at least partially integrated with other functional units, particularly the trajectory determination unit.
[0034] Generally, the checking algorithm of the checking unit is advantageously designed so that the algorithm itself can process machine-readable regular language, thus allowing direct use of the invoked traffic rule set, for example, as boundary conditions at the time of determination and / or as compliance conditions after determination. However, embodiments are conceivable in which the control device generates program code by compiling the current traffic rule set for the currently traveling area. Such an interpreter has been proposed in the prior art for other purposes and can also be used within the scope of this invention; it can automatically interpret machine-readable regular language and correctly embed this regular language into the program code to be compiled, thereby forming a compiled software tool that uses the traffic rule set. A particular advantage of integrating this into the compiled software tool (which, for example, executes the checking algorithm) is that, during the frequently occurring checks of the currently traveling trajectory, computation time is not increased by interpreting the traffic rule set in machine-readable regular language during runtime. In other words, interpretation of machine-readable formal language expressions is only needed at a certain point in time. This is because it is confirmed that motor vehicles typically remain within the effective range of the traffic rule set for a specific time period, and the time within the effective range may be shorter, both from the perspective of the current geographical area and driving conditions. Therefore, a large number of checks on the trajectory to be driven during this period are required, and corresponding pre-compilation may be very suitable. Automated compilation is also advantageous in other ways, avoiding error-prone manual steps.
[0035] In this context, it should be noted that methods for trajectory planning, i.e., determining the current trajectory to be traveled, have been proposed in various ways and approaches in the prior art. Input data is typically used, which utilizes the current environment of the vehicle and / or information about the vehicle itself; this information can be referred to as autonomous data and includes, for example, the vehicle's operating state. Environmental data may include sensor data from the vehicle's environmental sensors, but may also include other environmental information, such as environmental information that can be determined from digital maps present in the vehicle, for example, a navigation system. In vehicle systems designed for fully automated guidance, it is generally stipulated that situation interpretation is performed before trajectory planning, which is also within the scope of this invention. Here, for example, raw sensor data is processed to generate a data object (e.g., as or including an environmental map), which can describe the current driving situation and can be used as situation data for trajectory planning. In particular, within the scope of situation interpretation, driving situation types can already be assigned to driving situations.
[0036] Within the scope of situational data (which describes the current driving situation of a motor vehicle and may in particular include sensor data, such as raw sensor data) as interpreted and / or otherwise determined, input data for evaluating traffic rules can also be formed. This is particularly applicable to determining whether there are legitimate application situations for traffic rules, as described above. For example, there are traffic rules that apply when a specific speed of the motor vehicle is exceeded, traffic rules that relate to low visibility, traffic rules that relate to specific auxiliary equipment of the motor vehicle, etc. The existence of these aspects is usually generated by situational data, especially sensor data of situational data, which can therefore determine the existence of application situations for the corresponding traffic rules. That is to say, it can generally be said that at least a portion of the traffic rules in the traffic rules database evaluates situational data (especially including sensor data) that describes the current driving situation of a motor vehicle. In this way, it can ultimately be said that measurement data is included in trajectory planning and checks on compliance with traffic rules, and the processing of measurement data has a direct control technology-related and therefore physical effect, i.e., the final trajectory generated by the motor vehicle.
[0037] It should also be noted that the term "trajectory" should be interpreted broadly within the scope of this invention. "Trajectory" does not merely describe the temporal and spatial progression of the future movement of a motor vehicle, but may also include other measures, such as the activation of a driving direction indicator, preprocessing measures for other vehicle systems, etc., to which temporal and spatial progressions are allocated.
[0038] In addition to the method described above, the present invention also relates to a motor vehicle having a vehicle system for fully automatically guiding the motor vehicle in at least one driving situation type, wherein the vehicle system has a control device designed to access position data from the motor vehicle's position sensors and a traffic rule database, wherein a set of traffic rules for multiple geographic regions is stored in the traffic rule database in a machine-readable regular language, wherein the control device has:
[0039] - A calling unit, which is used to determine the geographical area currently being traveled by the motor vehicle based on the current location data, and to call the set of traffic rules for the currently traveling geographical area from the traffic rule database.
[0040] - The trajectory determination unit is used to determine the current trajectory to be traveled.
[0041] - A checking unit, used after or during a determination, to check whether the trajectory complies with traffic rules based on the invoked set of traffic rules for the current driving geographic area, wherein, if not, the current trajectory to be driven is adjusted, and
[0042] - A guidance unit, which guides the motor vehicle according to the current trajectory to be traveled.
[0043] All embodiments of the method according to the invention can be applied to a motor vehicle according to the invention, and thus, the advantages already mentioned can also be obtained using such a motor vehicle. Therefore, in particular, in a motor vehicle according to the invention, it is also possible to determine whether a trajectory complies with traffic rules, and to adjust the trajectory in the event of non-compliance, thereby achieving compliance with traffic rules. Here, as also in the method according to the invention, in order to adjust the trajectory, in particular, information on non-compliance determined during inspection is used as adjustment information. The information on non-compliance specifically describes in what manner which traffic rule is violated, which enables simple adjustments. As described, the functional units can also be designed to be at least partially integrated with each other.
[0044] Finally, the present invention also relates to a system for fully automatically guiding a motor vehicle according to the invention under at least one driving situation type, the system having a vehicle system and a central server device connected to a control device via a communication link, wherein the server device is designed to provide a traffic rules database. Therefore, the system design according to the invention is for implementing the method according to the invention, such that all embodiments related to the method according to the invention and the motor vehicle according to the invention obviously continue to be similarly applicable. Attached Figure Description
[0045] Other advantages and details of the invention will become apparent from the embodiments described below and from the accompanying drawings. Hereinafter:
[0046] Figure 1 A flowchart illustrating an embodiment of the method according to the present invention is shown.
[0047] Figure 2 A system according to the present invention is shown, and
[0048] Figure 3 The functional structure of the vehicle system's control device is shown. Detailed Implementation
[0049] Figure 1 A flowchart of an embodiment of the method according to the present invention is shown. The method is used to enable fully automated operation of motor vehicles, i.e., highly automated and / or fully automated vehicle guidance functions, to comply with traffic rules. To this end, a traffic rule database is first provided in step S1.
[0050] The traffic rules database contains multiple sets of traffic rules for different geographic regions, with different traffic rules applicable in each region. These sets of rules include at least the traffic rules related to vehicle guidance functions (defined in a machine-readable formal language such as SysML or UML). Considering the vehicle guidance function, which can be used in different driving situations and assigned to different driving situation types, the traffic rules database contains multiple sets of traffic rules for each geographic region, each assigned to a specific driving situation type. Driving situation types summarize the driving situations for which certain traffic rules from the general traffic rules set apply, but not necessarily others. Depending on the application area of the vehicle guidance function targeted by the traffic rules database, driving situation types can be defined more broadly or more narrowly. For example, it is conceivable to subdivide them into highway types, local road types, and urban types, where other driving situation types may include, for example, overtaking situations, being overtaken, intersection situations, congestion situations, etc.
[0051] The database provided in step S1 can, in principle, be manually drafted, but is preferably automatically generated based on another database, such as a requirements database, which may exist as a tabular document that can be generated at least partially manually. For example, it is conceivable to generate traffic rules fully automatically from a tabular file using SysML.
[0052] Various software tools already proposed in the prior art for other purposes can also be applied to traffic rule databases. For example, they can provide interfaces to the regulatory framework for creating documented records and check for potential conflicts. When conflicts exist, they can be eliminated by manually adjusting, for example, the basic requirements database or the traffic rule database itself, since traffic rules should not be conflicting. Given traceability, software tools can also be applied to traffic rule databases to, for example, check whether the components of the database are useful for the overall functionality, or demonstrate that the overall functionality is met by the sum of its derived partial requirements. Furthermore, it is suitable in traffic rule databases that the driving expressions of traffic rules can be correlated with the developed requirements world to reflect traceability, which is already supported by tools in SysML elements.
[0053] The traffic rules database can be updated, whereby, suitably, the latest version is always provided in step S1. This is because traffic rules—whether by legislation or case law—change over time. Within the scope of this embodiment, the state of the traffic rules database, as well as any changes made, is recorded in a change log. This also allows the traffic rules database to be restored to its previous state.
[0054] What is appropriate here is to design the traffic rule database as efficiently as possible. For example, it can be assumed that traffic rules are structurally similar in different geographic regions, but parameterized in different ways, such as in the case of maximum speed. That is, a basic set of rules parameterized in a region-specific manner can be considered for traffic rules and / or at least a portion of a geographic region, in order to generate a traffic rule set for at least part of that region.
[0055] In the current context, traffic rules can preferably be reflected by at least two elements. One of these elements describes the legal application situation, and thus specifically indicates the conditions under which the legal application situation exists, and therefore the traffic rule is fully applicable. The other element can describe the obligations arising from the traffic rule when implementing the application situation, such as overtaking or turning. As another element, it can reflect the preconditions or permissions of the application situation, for example, whether overtaking is permitted in the case of overtaking.
[0056] In this context, it is also important to note that the combination of (more broadly defined) driving situation types with traffic rules describing such application situations is particularly suitable. A structured approach is then provided, which, for example, first uses driving situation types to reflect a "setting," such as highway operation, in which different application situations may arise, such as following, overtaking, etc., and these application situations can be identified based on specific requirements for the existence of the application situation. Here, in the traffic rule database, different conditions can be combined, for example, into requirements for the existence of application situations. Conditions themselves do not represent traffic rules; traffic rules can only be generated through combinations of different conditions and their association with regulations and prohibitions (obligations). Suitablely, conditions can be grouped into requirements or super-conditions in a machine-readable formal language, where the grouped conditions should be assignable to specific logical and technical system parts / components.
[0057] Traffic rule databases can also form hierarchical structures in the sense that specific traffic rules become invalid or are replaced by other traffic rules under certain conditions. In principle, it is conceivable to assign at least one condition that invalidates a traffic rule; however, since such invalidation conditions are usually predicated on the presence of danger, it is preferable to either define at least one type of driving situation that includes emergency driving situations, such as collisions (assigning a restricted traffic rule level to it in the traffic rule database), or to implement this hierarchical structure in the corresponding control device of the vehicle system, which, for example, at least partially halts the checking of the invoked traffic rule dataset for the currently traveling geographic area when a dangerous driving situation is identified. Thus, for example, it may be permissible to drive across solid lines in the presence of an accident, or even in situations endangering the limbs and lives of others, or to briefly exceed the maximum speed limit.
[0058] Here, the traffic rules database is stored on a central server device located outside the motor vehicle. This central server device is connected to, or can be connected to, the control devices of different motor vehicle systems via communication links. In this way, the traffic rules database can be used when guiding multiple motor vehicles, and the traffic rules can then be centrally updated for these vehicles. It is stipulated that whenever the traffic rules database is updated, corresponding update information, specifically, an update signal, is sent to the control device of the corresponding vehicle system that performs the vehicle guidance function and communicates with the traffic rules database. The corresponding control device can then access the updated set of traffic rules.
[0059] In step S2, the current set of traffic rules to be used is invoked. Besides the recallability always mentioned when the traffic rules database has been updated, it is now stipulated that a new, current set of traffic rules is invoked whenever the driving situation changes and / or the geographical area changes, thus always using a different set of traffic rules. If the vehicle crosses a border, for example, this can be determined based on location data from the vehicle's position sensors, such as GPS sensors, thereby also determining the newly entered geographical area, which is accomplished by the corresponding control device within the vehicle. Therefore, in step S2, an appropriate set of traffic rules can be selectively invoked from the traffic rules database, with additional consideration given to the driving situation type.
[0060] It should be noted that during the fully automated guidance of the vehicle system, steps S2 and the steps discussed thereafter can be performed in an overlapping or interleaved manner. For example, if the geographic area changes during the fully automated guidance of the vehicle, the driving situation type changes and / or the traffic rules database is updated.
[0061] Within the scope of this invention, it may be preferred to use the invoked traffic rule set in the control device so as to generate, in particular, new program code by compilation, which directly applies the current, just invoked traffic rule of the traffic rule set. Then, an interpreter embedding a machine-readable regular language in the software tool only needs to be used at the point of compilation and does not need to be used in every application of the traffic rule.
[0062] The following discussion addresses the situation where a travel trajectory is first determined, and then checked for compliance with traffic rules, i.e., whether it conforms to traffic regulations, so that the trajectory can be adjusted if necessary. It is also conceivable that at least a portion of the traffic rules in the traffic rule set is directly considered in trajectory determination, for example, the maximum speed as a boundary condition for trajectory planning. In other words, it is particularly conceivable to combine the use of traffic rules from the traffic rule set, such that a portion of the traffic rules is directly considered in trajectory planning and thus checked as boundary conditions during trajectory determination, while another portion is subsequently used to check (complete the determined) trajectory.
[0063] Steps S3 to S7 represent measures for implementing fully automated operation of the motor vehicle. Here, the key element is trajectory planning, which determines which control commands are generated by the vehicle system implementing vehicle guidance functions to execute the current trajectory to be traveled, which is continuously updated based on current information.
[0064] First, in step S3, situation interpretation (situation analysis) is performed using various input data. This input data includes sensor data from the vehicle's environmental sensors and other sensors, additional environmental information, and autonomous / self-data (Ego-Daten) about the vehicle itself, particularly its current operating state. For example, an environmental map can be generated, where situation data describing the current driving conditions (obtained as a result of step S3) is included. However, other information is typically also included, particularly describing the type of driving condition and the current geographical area. Furthermore, the sensor data itself can also be used as situation data.
[0065] In step S4, the situational data is used to determine the trajectory to be traveled in the event of further fully automated operation of the motor vehicle, in a manner and method known in principle in the prior art. This can be accomplished, for example, by a trajectory determination algorithm.
[0066] Then, in step S5, the invoked set of traffic rules to be used is used to check whether the determined trajectory to be traveled complies with the traffic rules. If it is determined that at least one traffic rule is not complied, then in step S6—especially when adjustment information describing the traffic rule not complied with and the type of non-compliance is used—the trajectory to be traveled is adjusted accordingly to ensure compliance with the traffic rules.
[0067] Here, two basic architectures can be considered in the at least partial checks following the determination. In the first architecture, the trajectory to be adjusted can be fed back to the trajectory determination algorithm as additional information along with adjustment information, which then makes adjustments taking this additional information into account. Alternatively, a dedicated adjustment algorithm can be used to ensure compliance with traffic rules in step S6. In both cases, it can be stipulated that if a violation of another traffic rule cannot be eliminated through adjustment, a new check is performed in step S5.
[0068] The results of each check in step S5 and each use of traffic rules to adjust the current driving trajectory are stored in a storage medium designed as a ring memory to record the application of traffic rules and their impact on vehicle control, such as in the event of an accident or other situations that may require recording. The version, i.e., the status, of the traffic rule database used to retrieve the traffic rule set in step S2 is also stored.
[0069] In step S7, before returning to step S3 in the periodic update of the current trajectory to be driven in the next time step, the vehicle is guided using the current trajectory to be driven, which may be adjusted.
[0070] Figure 2 A schematic diagram of system 1 according to the invention is shown, by which the method according to the invention can be implemented. On one hand, system 1 has a central server device 2, on which a traffic rule database 3 is stored and provided. Updates and the like also occur centrally. As described above, the traffic rule database 3 is used by multiple motor vehicles 4 for fully automated guidance, each of which has a vehicle system 5 for fully automated guidance, which thus implements highly automated or fully automated vehicle guidance functions and uses a control device 6 for this purpose. The control device 6 can establish a communication link 8 with the central server device 2 via the communication device 7 of the corresponding motor vehicle 4, and thus retrieve a set of traffic rules from the traffic rule database 3. Furthermore, the control device 6 of each motor vehicle 4 is designed to implement steps S2 to S7. Therefore, the motor vehicle 4 is a motor vehicle according to the invention.
[0071] It should be noted that, in order to obtain the input data for the situation interpretation in step S3, the vehicle 4 naturally also includes other components integrated into the fully automated guidance of the corresponding vehicle 4, such as environmental sensors, other vehicle systems, proprietary sensors, etc., and also includes a large number of controllable actuators, particularly including drive and braking devices and steering devices. It should be pointed out that the input data for situation interpretation and / or the situation data generated by the situation interpretation can, of course, at least partially represent the input data used to check whether a traffic rule application situation exists. It should also be pointed out that, especially when checking whether the current operating state or current driving situation of the vehicle—as the starting point of the current trajectory—complies with traffic rules, it can be determined that the current state does not comply with traffic rules. However, this state can also be handled by traffic rules included in the traffic rule database 3, which may not necessarily be legal, so as to, for example, exit the application situation or driving situation type again.
[0072] according to Figure 3 Therefore, control device 6 first includes a situation interpretation unit 16 that generates situation data according to step S3, wherein, of course, position data from position sensor 17 (here, GPS sensor) and digital map material from a navigation system (not shown in detail here) can also be used to determine the current geographical area of travel. In this case, the geographical area is determined from the corresponding situation data by calling unit 9. Alternatively, calling unit 9 itself can also be designed to evaluate the position data, especially the digital map material from the navigation system. Calling unit 9 is also designed to call a set of traffic rules for the current geographical area of travel from traffic rule database 3, especially taking into account, for example, the type of driving situation generated by situation data from situation interpretation unit 7. The set of traffic rules is called from traffic rule database 3 when there are calling conditions, as described above, such as when the geographical area changes and / or the type of driving situation changes, and / or when updated information is available. In other words, the calling unit is designed to implement step S2.
[0073] The trajectory determination unit 10 is designed for trajectory planning, see step S4, while the checking unit 11 is designed for checking whether the traffic rules of the traffic rule set are followed, i.e., whether the traffic rules are met, see step S5. The trajectory determination unit 10 implements a trajectory determination algorithm, and the checking unit 11 implements a checking algorithm. In this embodiment, the checking algorithm can be generated according to the compilation when using the traffic rule set. In the case of non-compliance, in a variant scheme where the current trajectory to be traveled should be adjusted within the checking unit 11 itself, the checking unit 11 can also implement a corresponding adjustment algorithm.
[0074] In the event of non-compliance, for example, the adjustment unit 12 of the adjustment algorithm can be used to construct compliance with the set of traffic rules, see step S6.
[0075] In this case, it should be noted that, depending on the specific design scheme, the trajectory determination unit 10, the inspection unit 11, and the adjustment unit 12 can also be set up at least partially integrated with each other. For example, if the inspection aspect is adjusted by boundary conditions and / or by the trajectory determination algorithm itself during trajectory determination, then the adjustment unit 12 may only need to provide the trajectory determination unit 10 with appropriate additional information (adjustment information) or the trajectory determination unit may need to switch to a special mode.
[0076] Finally, in the guidance unit 13, according to step S7, the current driving trajectory that may be adjusted is used to guide the motor vehicle 4, which is known in principle.
[0077] In the present case, the control device 6 also has a recording unit 14, as described, which records the use of traffic rules of the traffic rule set by means of entries in the storage medium 15 implemented as a ring memory.
Claims
1. A method for fully automatic guiding of a motor vehicle (4) in a driving situation of at least one driving situation type by means of a vehicle system (5), wherein, The vehicle system (5) has a control device (6) and accesses position data of a position sensor (17) of the motor vehicle (4), the method comprising the following steps: - providing a traffic rules database (3) in which sets of traffic rules for a plurality of geographical regions are stored in a machine-readable formal language, the traffic rules database (3) being accessible to the control device (6), - determining a geographical region in which the motor vehicle (4) is currently driving on the basis of the current position data and calling up, by means of the control device (6), the set of traffic rules for the geographical region in which the motor vehicle (4) is currently driving from the traffic rules database (3), - checking, by means of the control device (6), whether the trajectory to be driven is in compliance with the traffic rules on the basis of the called-up set of traffic rules for the geographical region in which the motor vehicle (4) is currently driving after or while determining the trajectory to be driven by means of the control device (6), wherein the trajectory to be driven is adjusted in the event of non-compliance, - guiding the motor vehicle (4) on the basis of the trajectory to be driven, - using a unified modeling language and / or a system modeling language as the formal language, - at least one set of traffic rules containing a rule section for changing the driving situation type which cannot be derived from legal provisions, The set of traffic rules comprises at least one hierarchical level, such that at least one traffic rule is assigned at least one condition which invalidates the at least one traffic rule and / or the traffic rule is assigned a priority; at least one driving situation type is specified, which at least one driving situation type contains an emergency driving situation, the at least one driving situation type is assigned a restricted set of traffic rules in the traffic rules database (3); upon recognition of an emergency driving situation, the control device (6) at least partially stops the checking of the called-up set of traffic rules for the geographical region in which the motor vehicle (4) is currently driving.
2. The method of claim 1, wherein, The traffic rules database (3) is stored on a central server device (2) which is external to the motor vehicle and is connected to the control device (6) by means of a communication link (8) and is used for guiding a plurality of motor vehicles (4).
3. The method according to claim 1 or 2, characterized in that, In the traffic rules database (3), a plurality of sets of traffic rules which are respectively assigned to a corresponding driving situation type are stored for each geographical region, wherein the control device (6) determines a current driving situation type which is relevant to a current driving situation which is the basis for the trajectory to be driven and calls up the set of traffic rules which is assigned to the region in which the motor vehicle (4) is currently driving and to the current driving situation type.
4. The method according to claim 1 or 2, characterized in that, The set of traffic rules is called up at a predetermined update time, and / or the set of traffic rules is called up in the event of the presence of update information which indicates an update of the traffic rules database (3), and / or the set of traffic rules is called up in the event of a change in the region in which the motor vehicle (4) is currently driving and / or a change in the current driving situation type.
5. The method according to claim 1 or 2, characterized in that, In the application case, at least one traffic rule in the set of traffic rules describes a legal application case and an obligation which specify applicability.
6. The method of claim 5, wherein, At least one application case which is continuously usable is used, the application case comprising a speed limit and / or an application case which is caused by other road users, the application case which is caused by other road users comprising being overtaken.
7. The method according to claim 1 or 2, characterized in that, The use of traffic rules of a current traffic rules set called for the geographical area currently traveled is recorded in a storage medium (15) by the control device (6), which is a ring memory, the use of traffic rules comprising a check and adjustment of a trajectory currently to be traveled, a version of a traffic rules database (3) from which the used traffic rules are called is recorded in the storage medium (15).
8. The method of claim 1 or 2, wherein, Before the provision, the traffic rules database (3) is automatically checked for conflict-freeness.
9. The method of claim 1 or 2, wherein, The control device (6) has a trajectory determination unit (10) for determining a trajectory to be checked, currently to be traveled, which executes a trajectory determination algorithm, and a check unit (11) for checking the determined trajectory currently to be traveled, which executes a check algorithm, wherein, in the case of a determination of a non-observance, either the trajectory is returned to the trajectory determination unit (10) with at least one adjustment information for the implementation of an adjustment or the trajectory is adjusted using the adjustment algorithm of the check unit (11).
10. The method of claim 1 or 2, wherein, The control device (6) generates a program code from the current traffic rules set for the area currently traveled by compiling.
11. Motor vehicle (4) having a vehicle system (5) for fully automated guiding of the motor vehicle (4) in at least one driving situation type of driving situations, wherein The vehicle system (5) has a control device (6) which is designed to access position data of a position sensor (17) of a motor vehicle (4) and a traffic rules database (3) in which traffic rules sets for a plurality of geographical areas are stored in a formal language in a machine-readable manner, wherein the control device (6) has: - a calling unit (9) for determining a geographical area in which the motor vehicle (4) currently travels on the basis of current position data and for calling a traffic rules set for the geographical area currently traveled from the traffic rules database (3), - a trajectory determination unit (10) for determining a trajectory currently to be traveled, - a check unit (11) for checking whether the trajectory currently to be traveled observes traffic rules after or during the determination according to the called traffic rules set for the geographical area currently traveled, wherein the trajectory currently to be traveled is adjusted in the case of a non-observance, - a guidance unit (12) for guiding the motor vehicle (4) on the basis of the trajectory currently to be traveled, - a unified modeling language and / or a system modeling language is used as the formal language, - at least one traffic rules set contains a rule section for changing a driving situation type which cannot be derived from legal provisions, The traffic rules set comprises at least one structural hierarchy, such that at least one traffic rule is assigned at least one condition which invalidates the at least one traffic rule and / or a traffic rule is assigned a priority; at least one driving situation type is specified, which at least one driving situation type contains an emergency driving situation, to which at least one driving situation type is assigned a restricted traffic rules set in the traffic rules database (3); upon recognition of an emergency driving situation, the control device (6) at least partially stops the checking of the called traffic rules data set for the geographical area currently traveled.
12. A system (1) for fully automated guiding of a motor vehicle (4) according to claim 11 in at least one driving situation type of driving situations, the system having a vehicle system (5) and a central server device (2), which is connected with a control device (6) by a communication link, wherein The server device (2) is designed to provide the traffic rules database (3).
Citation Information
Patent Citations
Method for guiding a vehicle system in a fully automated manner, and motor vehicle
CN108475056A
Real-time navigation electronic device and method based on determining current traffic rule information, and corresponding computer readable storage medium for storing program thereof
US20120265435A1