Control of at least one safety function of a motor vehicle

By determining the current driving conditions and safety level of a motor vehicle, and controlling safety functions to reduce energy consumption, the problem of energy consumption during the operation of motor vehicle safety functions is solved, thereby improving the efficiency and range of the motor vehicle.

CN116710340BActive Publication Date: 2026-07-17BMW AG

Patent Information

Authority / Receiving Office
CN · China
Patent Type
Patents(China)
Current Assignee / Owner
BMW AG
Filing Date
2021-11-22
Publication Date
2026-07-17

Smart Images

  • Figure CN116710340B_ABST
    Figure CN116710340B_ABST
Patent Text Reader

Abstract

One aspect of the present invention relates to an apparatus for controlling at least one safety function of a motor vehicle, wherein the apparatus is configured to: determine the current driving condition of the motor vehicle, determine a required safety level under the current driving condition of the motor vehicle, and control at least one safety function according to the required safety level.
Need to check novelty before this filing date? Find Prior Art

Description

Technical Field

[0001] The present invention relates to an apparatus and method for controlling at least one safety function of a motor vehicle. Background Technology

[0002] Within the scope of this document, the term "autonomous driving" can be understood as driving with automatic longitudinal or lateral control or autonomous driving with automatic longitudinal and lateral control. The term "autonomous driving" includes autonomous driving with any degree of automation. Exemplary levels of automation include driver assistance, partial automation, highly automated driving, or fully automated driving. These levels of automation are defined by the Federal Highway Research Institute (BASt) (see BASt publication "Research Report," version 11 / 2012). In driver assistance, the driver continuously performs longitudinal or lateral control, while the system takes over other functions within certain limits. In partial automation (TAF), the system takes over longitudinal and lateral control for a period of time and / or under specific circumstances, where the driver must continuously monitor the system as in driver assistance. In highly automated driving (HAF), the system takes over longitudinal and lateral control for a period of time without the driver continuously monitoring the system; however, the driver must be able to take over vehicle control for a certain period. In fully automated driving (VAF), the system can automatically manage driving in all situations for a specific application scenario where a driver is no longer required. The four levels of automation defined by BASt correspond to SAE Levels 1 through 4 of the SAE J3016 standard (SAE - Society of Automotive Engineers). For example, Highly Automated Implementation (HAF) according to BASt corresponds to Level 3 of the SAE J3016 standard. Furthermore, SAE J3016 specifies SAE Level 5 as the highest level of automation, which is not included in the BASt definition. SAE Level 5 corresponds to fully autonomous driving, where the system can automatically handle all situations like a human driver throughout the entire driving process; generally, a driver is no longer needed.

[0003] It is known from existing technology that the operation of motor vehicles can cause harm to people and the environment. Therefore, safety features for motor vehicles have been developed to avoid these harms. However, these safety features require energy during vehicle operation, resulting in increased vehicle emissions and / or reduced vehicle range. Summary of the Invention

[0004] The purpose of this invention is to reduce the energy consumption of safety features in motor vehicles.

[0005] This objective is achieved through the features of the independent claim. Advantageous embodiments are described in the dependent claims. It should be noted that additional features of a claim dependent on the independent claim, either in the absence of features of the independent claim or only in combination with a subset of features of the independent claim, can constitute a separate invention independent of all combinations of features of the independent claim, which can be the subject of the independent claim, divisional application, or subsequent application. This also applies to the technical theories described in the specification, which can form an invention independent of the features of the independent claim.

[0006] The first aspect of the present invention relates to a device for controlling at least one safety function of a motor vehicle.

[0007] At least one safety function of a motor vehicle, particularly a motor vehicle function for error identification and / or error response, i.e., a dedicated function for identifying errors or responding to identified errors, wherein the error is an malfunction of the electrical and / or electronic subsystems or components of the motor vehicle. Here, the error is a deviation between the actual behavior of the subsystem or component and its intended behavior. Alternatively, the at least one safety function is a safety-critical customer function of the motor vehicle, i.e., a customer function that, in the event of malfunction, would cause harm to people in the motor vehicle, people near the motor vehicle, or the environment. Alternatively or additionally, the at least one safety function is an abstract safety concept implemented by multiple subfunctions, such as a multi-channel system, wherein multiple channels calculate independently of each other and then combine their results.

[0008] The device is configured to determine the current driving status of the vehicle, for example, by means of the vehicle's sensors.

[0009] In addition, the device is configured to determine the required safety level under the current driving conditions of the motor vehicle.

[0010] The safety levels required under current driving conditions, particularly according to ISO standard ISO 26262 (“Road Vehicles – Functional Safety”), are the safety requirement levels for motor vehicle safety-related systems, known as the “Automobile Safety Integrity Level” (“ASIL”). There are five safety requirement levels: “QM”, “ASIL A”, “ASIL B”, “ASIL C”, and “ASIL D”, with QM being the lowest level and ASIL D the highest.

[0011] Alternatively or additionally, the level of safety required under current driving conditions, particularly the performance level of at least one component of the motor vehicle, such as the vehicle's sensors.

[0012] For example, the device is configured to determine the required safety level for the current driving condition of a motor vehicle by providing the results of a hazard and risk analysis conducted during the development of the motor vehicle in accordance with ISO 26262. The results indicate the required safety level for the driving condition and state of the motor vehicle in the form of at least one required ASIL. Since the device is configured to determine the current driving condition of the motor vehicle and is also capable of determining the current state of the motor vehicle, the device can determine the required safety level for that specific driving condition and state of the motor vehicle based on the results of the hazard and risk analysis.

[0013] Here, the determination of the required safety level under the current driving conditions of the motor vehicle must itself be carried out at the highest possible safety level.

[0014] In addition, the device is configured to control at least one security function according to the required security level.

[0015] For this purpose, the device is configured, for example, to provide the results of a safety analysis conducted during the development of a motor vehicle, and to assess, for example, the compliance of at least one safety function with the requirements of ISO 26262 Volume 4 (“Product Development: System Level”), Volume 5 (“Product Development: Hardware Level”), and / or Volume 6 (“Product Development: Software Level”).

[0016] By determining the extent to which the requirements of ISO 26262 are met, the highest level of security achievable with at least one security function can be determined.

[0017] Furthermore, when the required security level is lower than the highest security level achievable with at least one security function, the device is configured to control the security function in such a way that the security level actually achieved with at least one security function reaches or exceeds the required security level, and that the actual energy consumption of at least one security function is less than the energy consumption of at least one security function when reaching the highest security level achievable with at least one security function.

[0018] The device is specifically configured to achieve this control by reducing the performance of at least one safety function, for example by reducing the sampling rate or resolution or by disabling some functions.

[0019] The advantage of this implementation is that, while meeting the safety level required under current driving conditions, the energy required to perform safety functions is reduced, thus allowing the vehicle as a whole to operate more efficiently.

[0020] In another advantageous embodiment of the invention, the device is configured to disable at least one security function in order to control at least one security function according to the required security level.

[0021] In another advantageous embodiment of the invention, the device is configured to reduce the performance of at least one security function, for example by reducing the sensor range and / or sensor resolution of the sensor providing the security function input signal, in order to control at least one security function according to the required security level.

[0022] In another advantageous embodiment of the invention, at least one safety function is a multi-channel system architecture for the motor vehicle system, wherein the multi-channel nature is implemented, for example, in hardware and / or software.

[0023] Here, the device is configured as at least one channel in a multi-channel system architecture for deactivating a motor vehicle to control at least one safety function according to the required safety level. This frees up the computational resources required for the deactivated channel.

[0024] Another advantageous embodiment of the present invention is a system for resource planning of motor vehicles, wherein the system includes the means according to any one of the claims.

[0025] The system is configured to determine at least one resource released by the motor vehicle through controlling at least one safety function, such as the computing time and / or memory released by the motor vehicle control unit, and to plan the at least one resource released by the motor vehicle.

[0026] In another advantageous embodiment of the invention, the system is configured to plan the release of at least one resource by providing it to a driver assistance function for a motor vehicle, wherein the driver assistance function is prevented from accessing the longitudinal and / or lateral control of the motor vehicle.

[0027] In other words, the driver assistance function operates in a so-called "shadow mode," in which the driver assistance function receives and processes input signals but does not output control signals to the actuators of the vehicle.

[0028] The advantage of this implementation is that the driver assistance function can thus be tested under real-world conditions without interfering with the operation of the vehicle. Therefore, for example, it is possible to test new versions of driver assistance functions not yet available to drivers of motor vehicles, and, for example, to determine behavioral deviations between new and previous versions of the driver assistance function.

[0029] In another advantageous embodiment of the invention, the system is configured to plan the release of at least one resource by providing resources to a driver assistance function, wherein the driver assistance function is controlled to expand the operational design domain of the driver assistance function.

[0030] Here, the operational design domain of a driver assistance function is a subset of all possible driving situations in which the driver assistance function operates with a sufficiently high quality. For example, the operational design domain may limit the range of vehicle speeds in which the driver assistance function operates with a sufficiently high quality. Alternatively or additionally, for example, if the driver assistance function operates with a sufficiently high quality only in controlled, highway-like driving situations and not in highly complex urban driving situations, the operational design domain may limit the complexity of the vehicle environment.

[0031] For some driver assistance features, the operational design domain can be expanded if resources are available. Therefore, for example, utilizing more available resources can handle more objects near the vehicle, and / or more sophisticated image processing algorithms can be used to identify and / or classify objects near the vehicle.

[0032] In another advantageous embodiment of the invention, the system is configured to: plan the release of at least one resource by setting the system to test the functionality of the resource, in particular by performing a functional test of the resource that cannot be performed when the resource is in use, such as a memory test.

[0033] A second aspect of the invention relates to a method for controlling at least one safety function of a motor vehicle.

[0034] One step in this method is to determine the current driving status of the motor vehicle.

[0035] Another step in this method is to determine the required level of safety under the current driving conditions of the motor vehicle.

[0036] Another step in the method is to control at least one security function according to the required security level.

[0037] The foregoing embodiments of the apparatus of the invention according to the first aspect of the invention are also applicable in a corresponding manner to the method of the invention according to the second aspect of the invention. Advantageous embodiments of the method of the invention not explicitly stated herein and in the claims correspond to advantageous embodiments of the apparatus of the invention described above or in the claims. Attached Figure Description

[0038] The present invention will now be described with reference to the accompanying drawings and embodiments. Wherein:

[0039] Figure 1 An embodiment of the device according to the invention is shown, and

[0040] Figure 2 An embodiment of the method according to the present invention is shown. Detailed Implementation

[0041] Figure 1A device for controlling at least one safety function of a motor vehicle according to the present invention is shown.

[0042] At least one safety function is a multi-channel system architecture C1, C2, C3 for motor vehicles.

[0043] Here, sensor data SD from three parallel processing channels C1, C2, and C3 will be processed. These three parallel processing channels C1, C2, and C3 are assigned to two control units E1 and E2 of the vehicle, so that two processing channels C1 and C2 are executed on control unit E1, while processing channel C3 is executed on control unit E3.

[0044] Then, the trajectory TR is determined from the results of the three parallel processing channels C1, C2, and C3, which can be used for the automatic operation of motor vehicles.

[0045] The device is configured to determine the current driving situation of the motor vehicle 100, determine the highest safety level 150 achievable with at least one safety function, and determine the safety level required for the current driving situation of the motor vehicle 200.

[0046] Furthermore, when the required security level is lower than the highest security level achievable with at least one security function, the device is configured to control the 300 security function in such a way that the security level actually achieved with at least one security function reaches or exceeds the required security level, and that the actual energy consumption of at least one security function is less than the energy consumption of at least one security function when reaching the highest security level achievable with at least one security function.

[0047] Here, the device is configured as at least one channel of a multi-channel system architecture C1, C2, C3 for a system that deactivates motor vehicles, in order to control at least one safety function 300 according to the required safety level.

[0048] For example, if parallel redundant computation of processing channels C1 and C2 is performed to achieve the following safety objective, which is rated as ASIL D in a very critical driving situation of a motor vehicle, and the safety level is divided into two ASIL B(D) safety levels through ASIL decomposition, then one of the two processing channels C1 and C2 can be deactivated when the safety objective is evaluated only at the ASIL B safety level in the current driving situation of the motor vehicle.

[0049] Alternatively or additionally, for example, processing channel C3 may be transferred to control unit E2 to prevent all processing channels C1, C2, and C3 from failing due to a common cause (so-called "common cause failure"), such as due to a power failure of control unit E1.

[0050] If the failure of all processing channels C1, C2, and C3 is tolerable under the current driving conditions of the motor vehicle, for example, because the motor vehicle is only moving at a low speed, the failure of processing channels C1, C2, and C3 can be controlled by any assumed driver. Therefore, processing channel C3 can be deactivated, and if necessary, even the entire control unit E2 can be deactivated.

[0051] Motor vehicles, in particular, include systems for resource planning of motor vehicles, wherein the system includes means according to the invention for controlling at least one safety function of the motor vehicle.

[0052] The system is configured to determine at least one resource released by 400 motor vehicles through controlling at least one safety function, and to plan at least one resource released by 500 motor vehicles.

[0053] For example, if the resources used to compute processing channel C2 on control unit E1 have been released because processing channel C2 on control unit E1 has been deactivated, the system can plan at least one released resource 500 by providing at least one released resource to driver assistance functions for the motor vehicle, wherein the driver assistance functions are prevented from accessing the longitudinal and / or lateral control of the motor vehicle.

[0054] In other words, driver assistance functions are performed in "shadow mode" instead of processing channel C2.

[0055] For example, if the resources used for computing processing channel C3 on control unit E2 have been released because processing channel C3 on control unit E2 has been deactivated, the system can plan for at least one of the released resources by setting the system to check the functionality of the resources, for example by setting the system to check the functionality of the processor and / or memory of control unit E2 by means of processor and / or memory testing methods.

[0056] Figure 2 An embodiment of a method for controlling at least one safety function of a motor vehicle is shown.

[0057] One step in this method is to determine the current driving status of 100 motor vehicles.

[0058] Another step in the method is to determine the highest security level that 150 can achieve with at least one security function.

[0059] Another step in the method is to determine the required level of safety for 200 under the current driving conditions of the motor vehicle.

[0060] If the required security level is lower than the highest security level achievable with at least one security function, another step of the method is to control the security function 300 such that the security level actually achieved with at least one security function reaches or exceeds the required security level, and such that the actual energy consumption of at least one security function is less than the energy consumption of at least one security function when reaching the highest security level achievable with at least one security function.

[0061] Another step of the method is to determine at least one resource released by the 400 motor vehicles by controlling at least one safety function.

[0062] Another step in this method is to plan at least one resource released by 500 motor vehicles.

Claims

1. A device for controlling at least one safety function of a motor vehicle, wherein the device is configured to: Determine the current driving status of the motor vehicle described in (100). Determine (150) the highest security level achievable with the at least one security function. Determine (200) the required safety level for the current driving conditions of the motor vehicle, and The at least one security function (300) is controlled according to the required security level, wherein when the required security level is lower than the highest security level achievable by the at least one security function, the security function (300) is controlled in the following manner: This ensures that the security level actually achieved by the at least one security function reaches or exceeds the required security level, and This ensures that the actual energy consumption of the at least one security function is less than the energy consumption of the at least one security function when it reaches the highest security level achievable with the at least one security function.

2. The apparatus of claim 1, wherein the apparatus is configured to: disable the at least one security function to control (300) the at least one security function according to a desired security level.

3. The apparatus of claim 1, wherein the apparatus is configured to: reduce the performance of the at least one security function to control (300) the at least one security function according to a desired security level.

4. The apparatus according to any one of claims 1 to 3, wherein The at least one safety function is the multi-channel system architecture (C1, C2, C3) of the vehicle's system, and The device is configured to: deactivate at least one channel in the multi-channel system architecture (C1, C2, C3) of the system for the motor vehicle to control (300) the at least one safety function according to the required safety level.

5. A system for resource planning of motor vehicles, wherein the system includes the means according to any one of claims 1 to 4, and the system is configured to: Determine (400) at least one resource released by the motor vehicle through controlling the at least one safety function, and The plan (500) refers to the release of at least one resource by the motor vehicle.

6. The system of claim 5, wherein the system is configured to: plan (500) the released at least one resource by providing the released at least one resource to a driver assistance function for the motor vehicle, wherein the driver assistance function is prevented from accessing the longitudinal and / or lateral control of the motor vehicle.

7. The system according to claim 5 or 6, wherein the system is configured to: plan (500) the released at least one resource by providing the resource to a driver assistance function, wherein the driver assistance function is controlled to extend the operational design domain of the driver assistance function.

8. The system according to claim 5 or 6, wherein the system is configured to: plan (500) the released at least one resource by setting the system to examine the functionality of the resource.

9. A method for controlling at least one safety function of a motor vehicle, wherein the method comprises the following steps: Determine the current driving status of the motor vehicle described in (100). Determine (150) the highest security level achievable with the at least one security function. Determine (200) the required safety level for the current driving conditions of the motor vehicle, and The at least one security function (300) is controlled according to the required security level, wherein when the required security level is lower than the highest security level achievable by the at least one security function, the security function (300) is controlled in the following manner: This ensures that the security level actually achieved by the at least one security function reaches or exceeds the required security level, and This ensures that the actual energy consumption of the at least one security function is less than the energy consumption of the at least one security function when it reaches the highest security level achievable with the at least one security function.