Method for handling faults according to a scenario by heterogeneous verification of a vehicle and vehicle
Patent Information
- Application Number
- CN202280015542.9
- Authority / Receiving Office
- CN · China
- Patent Type
- Patents(China)
- Current Assignee / Owner
- Priority Date
- 2021-02-19
- Filing Date
- 2022-02-14
- Publication Date
- 2026-09-29
- Estimated Expiration
- 2042-02-14
AI Technical Summary
由现有技术已知的故障处理方法不反映或者只不充分地反映这种多样性
[0041]本发明的在本申请中提到的不同实施方式如果未单独地另作说明则能够有利地相互结合。
Smart Images

Figure CN116897119B_ABST
Abstract
Description
Technical Field
[0001] This invention relates to a method for handling potential failures of vehicle components, preferably through heterogeneous verification, based on scenario conditions. Furthermore, this invention relates to a vehicle having at least one vehicle component and a control unit designed to implement the method according to the invention. Background Technology
[0002] Modern vehicles are complex technological systems with many interacting components. The identification and handling of malfunctions in these components are crucial for safety, as a single failure in one component can have a critical impact on the entire system. Therefore, safe malfunction handling is of paramount importance, especially for vehicles that transport people.
[0003] Fault handling is particularly significant in the field of autonomous driving. Automated vehicles offer numerous possibilities for improving driving safety and the driver's experience. However, the driver's autonomy in making driving decisions is increasingly being transferred to the vehicle or the control units operating within it. The ultimate goal of these developments is to create fully automated vehicles capable of maneuvering without human intervention.
[0004] SAE J3016 classifies automated vehicles into different levels. In SAE Level 4 and Level 5 autonomous vehicles, the systems responsible for autonomous driving operate partially or fully autonomously. That is, driver intervention is either partially or completely unrestricted. Precisely in these cases, careful monitoring of all systems is essential to quickly and accurately identify and address malfunctions and errors.
[0005] Traditional fault handling methods mostly compare the behavior of vehicle components under inspection with pre-defined static limits and execute pre-defined fault handling protocols if a fault is identified. However, especially in the case of automated vehicles, using static limits and fixed fault handling protocols cannot adapt to the diverse and varying requirements of different driving scenarios. Therefore, for example, in terms of driving safety in automated driving operations, sensors may be evaluated differently on highways than in urban areas. Fault handling methods known from the prior art do not reflect, or only insufficiently reflect, this diversity. Summary of the Invention
[0006] The technical problem to be solved by the present invention is to improve the prior art and overcome or at least reduce the disadvantages of the prior art, and to provide an improved method for dealing with potential failures of vehicle components.
[0007] The technical problem according to the invention is solved by the method and means of transport according to the invention. Preferred extended designs are given in the specification.
[0008] A first aspect of the invention relates to a method for handling potential malfunctions of vehicle components. In the sense of this disclosure, the vehicle is preferably a means of transport designed for transporting people and / or goods on land, in the air, and / or in space. Preferably, the vehicle is a passenger car having an internal combustion engine, an electric motor, or a hybrid powertrain. Particularly preferably, the vehicle is a vehicle designed for autonomous driving and, for example, designed for operation conforming to SAE Level 4 or 5. In the sense of this disclosure, a malfunction is an unacceptable deviation of characteristics from predetermined requirements. Preferably, potential malfunctions of vehicle components are identified (ermitted, or determined) by the vehicle itself based on a scenario. The scenario-based identification of potential malfunctions will be described in detail below.
[0009] The method according to the invention includes identifying the current situation of a vehicle as a method step. The situation here preferably defines the surrounding environment and / or driving conditions of the vehicle. For example, the situation describes whether the vehicle is traveling on a highway or in the city, during the day or at night, and / or whether the weather is dry or rainy. The situation may also describe whether the vehicle is driving manually, semi-automatically, or fully automatically. The level of detail in the description of the surrounding environment and / or driving conditions of the vehicle in the situation can be varied. The situation can be identified based on data collected inside and / or outside the vehicle, as will be explained in detail below.
[0010] Furthermore, the method identifies at least one vehicle component that is heterogeneous in the current context. Preferably, a vehicle component is identified as heterogeneous if it is used or can be used for the same function as the vehicle component under inspection in the current context and its structure differs from that of the vehicle component under inspection.
[0011] If, in the method according to the invention, at least one heterogeneous vehicle component is identified relative to the vehicle component to be inspected, then the potential faults of the vehicle component are heterogeneously verified in consideration of said at least one heterogeneous vehicle component.
[0012] If no heterogeneous vehicle component is identified relative to the vehicle component to be inspected, the situation-dependent relevance (or importance) of the vehicle component is determined. Preferably, the importance of the vehicle component to the safe operation of the vehicle in the current situation is determined. Subsequently, based on the determined situation-dependent relevance, potential failures of the vehicle component are addressed or the emergency operation mode of the vehicle is activated.
[0013] Handling potential malfunctions preferably includes identifying and taking action to ultimately eliminate the malfunction or at least limit its impact. Furthermore, it is preferable that handling potential malfunctions includes corresponding measures to reduce the probability of serious consequences. Such handling includes, for example, restarting the vehicle component, calibrating the vehicle component, resetting the vehicle component's settings, or shutting down the vehicle component. In the case of shutting down the vehicle component, its tasks and / or functions are preferably transferred to at least one other component of the vehicle. This at least one other component may assume some of the functions of the relevant vehicle component. The vehicle's emergency operating mode preferably functions to transition the vehicle to a safe state. This transition to a safe state preferably includes providing a reduced number of emergency functions. Furthermore, it is preferable that the transition to a safe state includes emergency braking and / or emergency shutdown of the vehicle.
[0014] The method according to the invention advantageously enables more accurate and specialized fault handling by taking into account the current situation of the vehicle, thereby improving safety. Fault handling methods according to the prior art neglect the situation of the vehicle during fault identification and handling. However, fault handling can be differentiated according to the situation. For example, if the vehicle's own near-field camera fails during parking, it is feasible to interrupt the process, for example, by emergency braking. However, if emergency braking is used to handle a failed near-field camera when the vehicle is on a highway, this fault handling implies a considerable safety risk. The invention takes this into account and provides an improved fault handling method for vehicle components, thereby improving vehicle safety by taking into account the current situation of the vehicle.
[0015] In a preferred embodiment of the method according to the invention, the heterogeneous vehicle component is structurally different from the vehicle component and designed to perform the tasks and / or functions of the vehicle component. Preferably, the heterogeneous vehicle component is designed to perform the tasks and / or functions of the vehicle component in the current context. Preferably, the heterogeneous vehicle component is designed to undertake at least a portion of the functions of the vehicle component.
[0016] Among the numerous vehicle components installed in modern vehicles, there are also structurally different components designed for similar tasks. In specific scenarios, such heterogeneous vehicle components can take over the task, even if they are not redundantly designed relative to the vehicle component. For example, a lidar sensor used to measure distance during parking can be replaced by an ultrasonic sensor because a large effective measurement range is not required in this scenario. In modern vehicles, diversity is also frequently used as a strategy to improve reliability. Here, heterogeneous vehicle components are intentionally used with different implementations and without using a single system or component with the same structure. The idea behind this is that systems that contribute the same but are implemented differently are also less sensitive to a given disturbance, and therefore, it is unlikely that all systems will fail simultaneously. For example, processes particularly related to safety are often controlled by multiple control units, which are partly supplied by different manufacturers and whose software is written by multiple independent programmers in different programming languages. If one of these control units fails, the fault-free heterogeneous control units will take over the task.
[0017] In a preferred embodiment of the method according to the invention, the heterogeneous verification includes determining, as a method step, the absence of any potential fault in at least one heterogeneous vehicle component. In other words, during scenario-based verification, at least one heterogeneous vehicle component is determined to be fault-free. Preferably, at least one heterogeneous vehicle component is determined to be largely fault-free. Subsequently, in a further method step, it is preferable to determine the scenario-based or situation-dependent relevance of the vehicle component. Preferably, the importance of the vehicle component to the safe operation of the vehicle in the current scenario is determined. Subsequently, based on the determined scenario-dependent relevance, the potential fault in the vehicle component is preferably addressed as described above, or the emergency operation mode of the vehicle is activated. Particularly preferably, the processing further includes transferring the tasks and / or functions of the vehicle component to at least one fault-free heterogeneous vehicle component.
[0018] In a further preferred embodiment of the method according to the invention, the heterogeneous verification includes determining the potential fault of at least one heterogeneous vehicle component as a method step. This method step is preferably performed concurrently with and as an alternative to the method step described above for determining the absence of a potential fault in a heterogeneous vehicle component. In other words, it is determined during scenario-based verification that at least one heterogeneous vehicle component also has a potential fault. Preferably, it is determined that a majority of at least one heterogeneous vehicle component has a potential fault. Then, in a further method step, sample values and / or diagnostic values of the vehicle component and at least one heterogeneous vehicle component are compared. Preferably, the sample values and / or diagnostic values of the vehicle component are compared with multiple sample values and / or diagnostic values of at least one heterogeneous vehicle component. Here, sample values are always compared with sample values or diagnostic values with diagnostic values.
[0019] Based on the comparison of sample values and / or diagnostic values, in the method according to the invention, either potential faults in the vehicle component to be inspected are ignored (or tolerated) or the situation-dependent relevance of the vehicle component to be inspected is determined. If situation-dependent relevance is determined, the potential faults in the vehicle component are handled based on that relevance as described above, or the vehicle's emergency operating mode is activated. If potential faults are ignored, it is preferable to restart the method according to the invention by identifying additional potential faults in the vehicle component, wherein the fault identification is adjusted as necessary.
[0020] Another preferred embodiment of the method according to the invention further includes identifying at least one isomorphic vehicle component of the vehicle. Preferably, the identification of isomorphic vehicle components is performed before the identification of heteromorphic vehicle components. Furthermore, it is more preferably that the identification of heteromorphic vehicle components is performed as a supplement to or alternative to the identification of isomorphic vehicle components. The isomorphic vehicle component preferably has the same structure as the vehicle component and is designed to perform the tasks and / or functions of the vehicle component. In other words, it is determined whether the vehicle has at least one vehicle component identical to the vehicle component to be inspected. Preferably, it is determined whether the vehicle component is redundantly designed. Preferably, a vehicle component is identified as isomorphic if it is used for or can be used for the same function as the vehicle component to be inspected.
[0021] If at least one isomorphic vehicle component is identified, it is preferable to perform isomorphic verification of potential faults in a further method step, taking into account at least one isomorphic vehicle component. The isomorphic verification preferably includes the following steps: determining whether there is a potential fault in at least one isomorphic vehicle component; if there is no potential fault in at least one isomorphic vehicle component: addressing the potential fault of the vehicle component; if there is a potential fault in at least one isomorphic vehicle component: comparing sample values and / or diagnostic values of the vehicle component and at least one isomorphic vehicle component; and based on this comparison: ignoring the potential fault of the vehicle component; or determining the situation-dependent relevance of the vehicle component, and based on the determined situation-dependent relevance, addressing the potential fault of the vehicle component or initiating the vehicle's emergency operation mode. If the potential fault is ignored, it is preferable to restart the method according to the invention by identifying another potential fault in the vehicle component, wherein the fault identification is adjusted as necessary. Alternatively preferably, based on this comparison, the method does not continue by ignoring the potential fault, but rather by identifying at least one heteromorphic vehicle component as described above.
[0022] Both homogeneous and heterogeneous verification are advantageous in that they prevent incorrectly identified faults from being addressed, thus saving resources and energy. Heterogeneous verification has the added advantage that it can also identify multiple failures that are jointly caused, i.e., multiple statistically related failures that occur in the case of redundant components, as faults.
[0023] In another preferred embodiment of the method according to the invention, it is determined, in a comparison of sample values and / or diagnostic values, whether the sample values and / or diagnostic values of the vehicle component to be inspected fall within the dispersion range of sample values and / or diagnostic values of at least one heterogeneous vehicle component. Preferably, it is further determined, in a comparison of the sample values and / or diagnostic values of the vehicle component with the sample values and / or diagnostic values of at least one homogeneous vehicle component, whether the sample values and / or diagnostic values of the vehicle component to be inspected fall within the dispersion range of sample values and / or diagnostic values of at least one homogeneous vehicle component.
[0024] The dispersion range is preferably the range in which most sample values and / or diagnostic values of at least one heterogeneous or homogeneous vehicle component fall. The dispersion range is defined, for example, as the interval around (or around) the expected value or median of the diagnostic values. The dispersion range is defined, for example, by the interquartile range. Alternatively, intervals between other quantiles, such as intervals between tertiles, can be selected as the dispersion range. If the sample values and / or diagnostic values of the vehicle component to be inspected fall within the dispersion range of the sample values and / or diagnostic values of at least one heterogeneous or homogeneous vehicle component, the potential fault of the vehicle component is ignored. Otherwise, the situation-dependent relevance of the vehicle component to be inspected is determined. If the situation-dependent relevance of the vehicle component to be inspected is determined, the potential fault of the vehicle component is processed based on this relevance as described above, or the emergency operation mode of the vehicle is activated. If the potential fault is ignored, it is preferable to restart the method according to the invention to identify another potential fault of the vehicle component, wherein the fault identification is adjusted as necessary.
[0025] A further preferred design of the method according to the invention specifies that potential faults of vehicle components are identified according to specific scenarios. Potential faults of the vehicle components are preferably identified in this manner. Similarly, potential faults of at least one heterogeneous and / or homogeneous vehicle component are also preferably identified in this manner.
[0026] Identifying potential faults first involves determining sample values for vehicle components within at least one defined metric. In the sense of this disclosure, the metric is preferably a reference system for measuring quantifiable parameters. Preferably, each vehicle component is assigned at least one appropriate metric for monitoring. Preferably, at least one metric for a vehicle component corresponds to at least one metric for at least one isomorphic and / or heteromorphic vehicle component. Preferably, this assignment is made during the manufacturing of the respective vehicle component. The metric assigned to each vehicle component is preferably stored in a first lookup table (LUT). Preferably, the component-specific metric is determined by consulting the LUT. Preferably, the metric is a scale used to label sensor measurement parameters, estimated data amounts in circuitry and / or memory, expected outputs of software components, RAM and / or CPU utilization, vehicle speed and / or acceleration, current intensity, voltage and / or temperature. In other words, the metric represents a space for each vehicle component in which multiple sample values associated with that component can be labeled relative to each other and compared. Particularly preferably, each metric is defined by a quota, particularly a distance quota, to facilitate comparison of sample values. Preferably, the sample values within the determined metric are identified as the output of the vehicle component during its ongoing operation. Alternatively, the vehicle component is stimulated with input to determine the sample values. Furthermore, the sample values are preferably determined using sensors on the vehicle component.
[0027] Furthermore, during the identification of potential faults, a set of limit values is determined within a defined metric based on the current situation. Preferably, a lower and upper limit value, depending on the situation, is determined within the defined metric. The situation-dependent limit values are preferably stored in a second lookup table (LUT). Preferably, the first and second LUTs are local to a single LUT. Preferably, the limit value set is determined by consulting the LUT. The LUT is preferably stored locally on the vehicle's memory or retrieved from a network server. The vehicle is preferably designed to manage and update the LUT. When the method according to the invention is restarted after ignoring a potential fault in a vehicle component, the vehicle preferably updates the limit values in the LUT based on feedback. Preferably, the limit values are updated such that sample values belonging to the ignored potential fault are within the updated limit values. Also preferably, the limit values are updated such that diagnostic values belonging to the ignored potential fault are between 0 and 1 when determined based on the updated limit values. Preferably, the limit values are updated such that a majority of sample values for at least one homogeneous and / or heterogeneous vehicle component are within the updated limit values. Furthermore, the limits are preferably updated such that the majority of the diagnostic values determined by the majority of sample values and the updated limits are between 0 and 1. The server is also preferably designed for managing and updating the LUT. Preferably, the server communicates with multiple vehicles implementing the method according to the invention and updates the LUT based on feedback from the multiple vehicles. Therefore, the management of the LUT by the network server or by the vehicles advantageously enables continuous adjustment and improvement of the LUT and thus the limits used.
[0028] Particularly preferably, during the identification of potential faults, multiple metrics for monitoring vehicle components are determined, and for each of the multiple metrics, sample values and scenario-dependent limit sets are determined. Preferably, the identification of potential faults is performed using each of the multiple metrics. By using multiple metrics for each vehicle component, a multidimensional definition of the scenario-dependent fault state is feasible, which advantageously further improves the specificity of fault identification. Furthermore, the use of multiple metrics can improve the statistical relevance of fault identification.
[0029] In a further step, the diagnostic value is preferably determined as the quotient of the difference between the determined sample value and the lower limit value, and the difference between the upper limit value and the lower limit value. In other words, the diagnostic value is determined as the result of the following formula:
[0030]
[0031] In other words, diagnostic values are formed by normalizing sample values using a set of limit values.
[0032] By determining the diagnostic values according to the foregoing preferred embodiments, the converted (or scaled) diagnostic values for all components of a vehicle can be advantageously determined using the method according to the invention. Therefore, the diagnostic values advantageously enable comparability of vehicle components monitored by different metrics. Thus, the overall state of the vehicle can be determined without complexity. The determination of the diagnostic values also has the advantage that such diagnostic values allow for the identification of more precise states of vehicle components. For example, if a decision must be made between two redundant vehicle components, it is advantageous when the diagnostic values are determined as floating-point numbers. Between two vehicle components with diagnostic values of 0.9 and 0.6, the decision will fall on the second vehicle component. Both diagnostic values are valid, but the second diagnostic value is closer to the optimal diagnostic value of 0.5, which defines optimal function.
[0033] Furthermore, preferably, a potential fault is identified if the sample value is not within the determined limit, and / or if the diagnostic value does not have a value between 0 and 1.
[0034] The aforementioned preferred design, through the use of context-dependent limits for component-specific measurements, advantageously enables more accurate and specialized fault identification. This advantageously improves vehicle safety. Existing methods for identifying faults by reviewing vehicle components neglect the circumstances of the vehicle at the time of review. However, it is possible that the behavior of a vehicle component may be defect-free or even desirable in a particular context, while the same behavior may be dangerous in different contexts. For example, if the control unit of a vehicle on a highway is set to a speed of 130 km / h, this is perfectly normal behavior. But if this occurs in a pedestrian zone, it should be considered a fault. The present invention takes this into account and provides an improved method for identifying faults in vehicle components, thereby improving vehicle safety by taking into account the current context of the vehicle.
[0035] In a preferred embodiment of the method according to the invention, a scenario is defined based on multiple parameters characterizing the vehicle's surrounding environment and / or driving conditions. The vehicle's surrounding environment is preferably characterized by parameters related to the vehicle's environment, such as geographic data, weather data, traffic data, and legal regulations. The driving conditions are preferably characterized by parameters related to the vehicle itself, such as the status of auxiliary systems, SAE rating, number of passengers, remaining range, or distance still to be traveled. These parameters are preferably determined by the vehicle's sensors and / or based on external inputs. Scenario identification can be performed by the vehicle itself and / or via an external server. A scenario preferably consists of multiple sub-scenarios. Sub-scenarios preferably include a single characteristic of the vehicle's surrounding environment and / or driving conditions, such as weather or road type. Preferably, the scenario corresponds to an Operational Design Domain (ODD) determined by the vehicle. According to the SAE J3016 standard, the ODD includes conditions under which a particular driving automation system or its functions are specifically designed for operation.
[0036] In a further preferred embodiment of the method according to the invention, the relevance is determined taking into account the permissible failure rate of the vehicle components in the current scenario and / or the availability of heterogeneous and / or homogeneous vehicle components in the current scenario. Preferably, the relevance is determined to be low if a high failure rate of the vehicle components is permissible in the current scenario. Furthermore, preferably, the relevance is calculated to be low if at least one heterogeneous or homogeneous vehicle component is available in the current scenario. Available heterogeneous and / or homogeneous vehicle components are preferably fault-free. Heterogeneous vehicle components preferably perform the same tasks and / or functions as the vehicle components in the current scenario. For example, a lidar sensor used for measuring distance during parking can be replaced by an ultrasonic sensor because a large effective measurement range is not required in this scenario. Furthermore, preferably, the relevance is determined in consideration of event tree analysis. This event tree analysis preferably determines the possible consequences of potential failures of the vehicle components. If the determined consequences are classified as not related to safety, the relevance is preferably determined to be low. Preferably, the fault handling described above is performed whenever the determined relevance falls below a predetermined relevance limit. Also preferably, the emergency operation mode described above is activated whenever the determined relevance exceeds a predetermined relevance limit.
[0037] Another aspect of the invention relates to a vehicle, particularly a passenger car having an internal combustion engine, an electric motor, or a hybrid engine. Particularly preferred is that the vehicle is designed for automated driving and, for example, for operation conforming to SAE Level 4 or 5. The vehicle preferably has vehicle components. Furthermore, the vehicle has a control unit designed to implement the aforementioned method according to the invention for handling potential malfunctions of vehicle components based on specific scenarios.
[0038] A preferred design of the vehicle according to the invention comprises a plurality of vehicle components. The control unit is preferably designed to implement the method described above for each of the plurality of vehicle components. Preferably, the control unit implements the method respectively when diagnostic values are determined as described above. Preferably, the control unit is designed to assign a diagnostic value determined in the corresponding method to each of the plurality of vehicle components. Preferably, the control unit is also designed to determine the overall state of the vehicle based on the determined diagnostic values.
[0039] Another aspect of the invention relates to a computer program that includes instructions, which, when executed by a computer, such as a control unit of a vehicle, cause the computer to implement the method according to the invention as described above.
[0040] Another aspect of the invention relates to a computer-readable storage medium comprising instructions that, when executed by a computer, such as a control unit of a vehicle, cause the computer to implement the method according to the invention as described above.
[0041] The different embodiments of the present invention mentioned in this application can be advantageously combined with each other unless otherwise described separately. Attached Figure Description
[0042] The invention is described below with reference to the accompanying drawings in the embodiments. In the drawings:
[0043] Figure 1 A schematic flowchart of the method according to the present invention is shown;
[0044] Figure 2 A schematic flowchart illustrating a method according to an exemplary embodiment of the present invention is shown;
[0045] Figure 3 A schematic flowchart illustrating heterogeneous verification according to an exemplary embodiment of the method according to the present invention is shown;
[0046] Figure 4 A schematic flowchart illustrating isomorphic verification according to an exemplary embodiment of the method according to the present invention is shown;
[0047] Figure 5A schematic flowchart illustrating an exemplary embodiment of the method steps according to the present invention is shown.
[0048] Figure 6a A graphical view of sample values and static limits determined over an exemplary time period is shown;
[0049] Figure 6b A graphical view is shown illustrating sample values determined over a time period and context-dependent limits; and
[0050] Figure 7 A schematic diagram of a motor vehicle according to one embodiment of the present invention is shown. Detailed Implementation
[0051] Figure 1 A schematic flowchart illustrating a method for handling potential malfunctions of vehicle components according to the present invention is shown. In this exemplary embodiment, the potential malfunction of the vehicle component is identified by the vehicle itself based on a scenario. The scenario-based identification of the potential malfunction is... Figure 5 It is shown in the figure and will be explained in detail below.
[0052] In the twelfth method step S12, the current situation of the vehicle is first identified. This situation is specifically defined here as the surrounding environment and / or driving conditions of the vehicle. Furthermore, in method step S12, the presence of at least one heterogeneous vehicle component is identified.
[0053] If no heterogeneous vehicle component is identified in method step S12, the method follows eleventh path W6a, and in sixth method step S6, the situation-dependent relevance of the vehicle component is determined. Specifically, method step S6 determines the importance of the vehicle component to the safe operation of the vehicle in the current situation.
[0054] If the relevance is determined to be low in method step S6, particularly if the relevance is below a predetermined relevance limit, then the method follows the fifth path W3a. Subsequently, a potential malfunction of the vehicle component is addressed in the seventh method step S7a. This process includes, for example, restarting the vehicle component, calibrating the vehicle component, resetting the vehicle component's settings, or shutting down the vehicle component, while transferring the vehicle component's tasks to a similar vehicle component.
[0055] If the relevance described in method step S6 is determined to be high, i.e., particularly below a predetermined relevance limit, then the method follows the sixth path W3b. Subsequently, in the next method step S7b, the emergency operation mode of the vehicle is activated. The emergency operation mode of the vehicle specifically functions to switch the vehicle to a safe state, i.e., for example, by providing only a reduced number of emergency functions, performing emergency braking, or emergency shutdown.
[0056] If at least one heterogeneous vehicle component is identified in method step S12, the method follows path twelfth, W6b. Subsequently, in method step thirteen, heterogeneous verification of potential faults in the vehicle component begins, particularly considering the presence of at least one heterogeneous vehicle component. Figure 3 As illustrated in the example.
[0057] In accordance with the method according to the present invention Figure 2 In the preferred embodiment exemplified herein, the current situation of the vehicle is first identified in the fifth method step S5. This situation specifically defines the vehicle's surrounding environment and / or driving conditions. Furthermore, the presence of at least one isomorphic vehicle component is identified in method step S5.
[0058] If at least one isomorphic vehicle component is identified in method step S5, the method follows the fourth path W2b. Subsequently, in the eighth method step S8, isomorphic verification of potential faults in the vehicle components begins, particularly considering the presence of at least one isomorphic vehicle component. Figure 4 As illustrated in the example.
[0059] If no homogeneous vehicle component is identified in method step S5, the method follows the third path W2a. Then, in the twelfth method step S12, the presence of at least one heterogeneous vehicle component is identified as previously described. Further method steps are the same as those previously described. Figure 1 The described methods and steps are consistent.
[0060] Heterogeneous verification according to an exemplary embodiment of the method according to the invention Figure 3 The diagram is schematically shown. The fourteenth method step S14 includes determining whether there is a potential fault in at least one heterogeneous component. If it is determined in method step S14 that there is a potential fault in at least one heterogeneous vehicle component, particularly if it is determined that a majority of at least one heterogeneous vehicle component has a potential fault, then the method follows the thirteenth path W7a.
[0061] Next, in the fifteenth method step S15, the sample values and / or diagnostic values of the vehicle component are compared with multiple sample values and / or diagnostic values of at least one heterogeneous vehicle component. Specifically, it is determined whether the sample values and / or diagnostic values of the vehicle component fall within the dispersion range of the sample values and / or diagnostic values of at least one heterogeneous vehicle component. The dispersion range here refers to the range in which most diagnostic values of at least one heterogeneous vehicle component fall.
[0062] If the sample values and / or diagnostic values of the vehicle component fall within the dispersion range of the sample values and / or diagnostic values of at least one heterogeneous vehicle component, the method follows path fifteen W8a. Subsequently, in eleventh method step S11, potential faults in the vehicle component are ignored, and the method according to the invention restarts to identify further potential faults in the vehicle component. In this case, the scenario-dependent limits for fault detection are adjusted based on the dispersion range of the heterogeneous vehicle component determined in step S15.
[0063] If, in method step S15, it is determined that the sample value and / or diagnostic value of the vehicle component is outside the dispersion range of the sample value and / or diagnostic value of at least one heterogeneous vehicle component, then the method follows the sixteenth path W8b. Subsequently, in method step S6, the situation-dependent relevance is determined as previously described. Based on the determined relevance, the method then, as previously described, either follows the fifth path W3a and subsequently addresses the potential failure of the vehicle component in method step S7a, or follows the sixth path W3b and initiates the vehicle's emergency operation mode in method step S7b.
[0064] If it is determined in method step S14 that there is no potential failure of at least one heterogeneous vehicle component, the method proceeds to the fourteenth path W7b. Then, in method step S6, the relevance depending on the scenario is determined as previously described, and the potential failure of the vehicle component is handled or an emergency operation mode is initiated based on the determined relevance. In this case, the handling preferably includes transferring the tasks and / or functions of the vehicle component to at least one heterogeneous vehicle component that was determined to be fault-free in method step S14.
[0065] Isomorphic verification according to an exemplary embodiment of the method according to the present invention Figure 4The diagram is schematically shown. The ninth method step S9 includes determining whether there is a potential fault in at least one isomorphic component. If it is determined in method step S9 that there is no potential fault in at least one isomorphic vehicle component, the method follows the eighth path W4b. Then, in method step S7b, the potential fault in the vehicle component is processed as previously described. In this case, the processing preferably includes transferring the tasks and / or functions of the vehicle component to at least one isomorphic vehicle component that was determined to be fault-free in method step S9.
[0066] If it is determined in method step S9 that there is a potential fault in at least one isomorphic vehicle component, and in particular, that most of at least one isomorphic vehicle component has a potential fault, then the method follows the seventh path W4a.
[0067] Next, in the tenth method step S10, the sample values and / or diagnostic values of the vehicle component are compared with multiple sample values and / or diagnostic values of at least one isomorphic vehicle component. Specifically, it is determined whether the sample values and / or diagnostic values of the vehicle component fall within the dispersion range of the sample values and / or diagnostic values of at least one isomorphic vehicle component. The dispersion range here refers to the range in which most diagnostic values of at least one isomorphic vehicle component fall.
[0068] If the sample values and / or diagnostic values of the vehicle component fall within the dispersion range of the sample values and / or diagnostic values of at least one isomorphic vehicle component, the method follows the ninth path W5a. Subsequently, in the eleventh method step S11, potential faults in the vehicle component are ignored, and the method according to the invention restarts to identify further potential faults in the vehicle component. In this case, the scenario-dependent limits for fault detection are adjusted based on the dispersion range of the isomorphic vehicle component determined in step S10.
[0069] In the alternatively preferred design, the ninth path W5a leads to the twelfth method step S12, and in the twelfth method step, the presence of at least one heterogeneous vehicle component is identified as described above. The method then continues as previously described, starting from method step S12.
[0070] If, in method step S10, it is determined that the sample values and / or diagnostic values of a vehicle component are outside the dispersion range of sample values and / or diagnostic values of at least one isomorphic vehicle component, then the method follows the tenth path W5b. Subsequently, in method step S6, the situation-dependent relevance is determined as previously described. Based on the determined relevance, the method then, as previously described, either follows the fifth path W3a and subsequently addresses the potential failure of the vehicle component in method step S7a, or follows the sixth path W3b and subsequently initiates the vehicle's emergency operation mode in method step S7b.
[0071] Figure 5 A schematic flowchart illustrating the identification of potential faults according to an exemplary embodiment of the method according to the invention is shown. In a first method step S1, a component-specific metric and the current situation of the vehicle are determined. In the first part of a second method step S2a, sample values are determined within the determined metric. Subsequently, in the second part of a method step S2b, a set of limit values is determined based on the situation determined in the first method step S1.
[0072] Next, in the third method step S3, the diagnostic value is determined. The diagnostic value is here determined as the quotient of the difference between the determined sample value and the lower limit value, and the difference between the upper limit value and the lower limit value. That is, the diagnostic value is determined as the result of the following formula:
[0073]
[0074] If the diagnostic value determined in method step S3 is determined to be outside the range of 0 to 1, the method follows the first path W1a. Then, in the fourth method step S4, the identified fault is processed according to a scenario-dependent process, as previously detailed. If the diagnostic value is classified as valid, the method follows the second path W1b. In this case, no fault is identified. The method then restarts in the first part of the second method step S2a with the determination of the sample value.
[0075] Figure 6a and Figure 6b The following examples illustrate, through graphical views, how to determine and compare sample values P and limits G1, G2, G1', and G2' over a time period. Here, in... Figure 6a The static limits G1' and G2' are shown in the figure, and... Figure 6b The limits G1 and G2 are shown below, depending on the scenario.
[0076] A sample value P is determined within a defined metric. In the method according to the invention, this metric is specifically determined for each vehicle component to be monitored. Sensors typically have a defined operating range, for example. This operating range can be used to indicate whether the data provided by the sensor is correct. Switches are equipped with message buffers to process multiple messages. The maximum number of messages in the buffer is known. Therefore, possible overloads of the switch can be identified by monitoring the number of messages in the buffer. Applications required for vehicle operation act on a set of input parameters and provide an output, which can be used as a metric for monitoring the corresponding application. It is also possible to monitor a vehicle component using multiple metrics. For example, in the case of software components, both load rate and throughput can be used as metrics. In this case, the method according to the invention is preferably performed with multiple metrics.
[0077] exist Figure 6a and Figure 6b In the example shown, the control unit of the vehicle should be monitored. The output of the control unit includes, for example, instructions for controlling the longitudinal and lateral movement of the vehicle. Therefore, in this example, the output used to set the speed of the vehicle is determined as a metric.
[0078] The sample value P determined within this metric is shown as a solid line. This sample value initially exhibits a high rate of change, which then decreases over time until a brief, sharp increase occurs. The rise in the determined sample value P is marked with a lightning bolt, as this indicates a possible fault F in the control unit.
[0079] exist Figure 6a The diagram illustrates how a sample value P is compared to a set of static limits G1' and G2', shown as dashed lines. The lower limit G2' has a value of 0 km / h, and the upper limit G1' has the maximum speed of the vehicle. The sample value P remains between the static limits G1' and G2', causing fault F to go undetected.
[0080] exist Figure 6b The sample value P is compared with a set of limits G1 and G2 depending on the scenario. The lower limit G2 has a value of 0 km / h. The upper limit G1 has different values depending on the corresponding scenarios K1, K2, and K3. In the first scenario K1, the vehicle is on a highway without a specified maximum speed. That is, the upper limit G1 has the maximum speed of the vehicle. In the second scenario K2, the vehicle is in a city, so the upper limit G1 is determined to have a speed of 50 km / h. In the third scenario K3, the vehicle is in a parking lot, so the upper limit G1 has a walking speed. Here, the sample value P in the third scenario K3 is outside the limits G1 and G2. Fault F is identified and can be handled.
[0081] exist Figure 6a and Figure 6b The example shown illustrates the advantages of scenario-dependent fault identification according to the method of the invention. This method is capable of more accurately identifying faults F in vehicle components and thus advantageously achieving improved vehicle safety. To enable more accurate fault identification, scenarios K1, K2, and K3 are specifically composed of multiple sub-scenarios. If scenario K1 includes, for example, sub-scenarios such as "rain" or "traffic jam" in addition to "highway," then the upper limit value G1 for speed will be determined to be lower.
[0082] Figure 7 A schematic diagram, particularly a block diagram, of an exemplary vehicle 1 is shown, which is in particular a dual-track motor vehicle having an internal combustion engine, an electric motor, or a hybrid power source. Vehicle 1 is particularly configured for autonomous driving at SAE Level 4 or 5. Vehicle 1 includes multiple vehicle components.
[0083] Multiple first-class sensors, particularly first sensor 11, second sensor 12, and third sensor 13, constitute part of the vehicle component. The first-class sensors 11, 12, and 13 are configured to detect or collect environmental data of the vehicle 1 and include, for example, cameras for capturing images of lanes, traffic signs, and / or lane boundaries in front of the vehicle 1; distance sensors for detecting distances to objects around the vehicle 1; ultrasonic sensors; thermometers for detecting the ambient temperature of the vehicle; and / or rain sensors for collecting weather data. The first-class sensors 11, 12, and 13 transmit the environmental signals they collect to the control unit 40 of the vehicle 1.
[0084] The vehicle 1 also has multiple second-type sensors, particularly the fourth sensor 21, the fifth sensor 22, and the sixth sensor 23, as additional vehicle components. The second-type sensors 21, 22, and 23 are used to collect vehicle data related to the vehicle 1 itself, particularly the vehicle 1's current position and motion information. Therefore, the second-type sensors are, for example, speed sensors, acceleration sensors, tilt sensors, or similar sensors. The second-type sensors 21, 22, and 23 transmit the status signals they collect to the control unit 40 of the vehicle 1.
[0085] In addition, another vehicle component is a communication module 30, which has a memory 31 and one or more transponders or transceivers 32. The transponder 32 is a radio, WLAN, GPS, or Bluetooth transceiver or similar device, particularly configured for communication in a communication network. This transponder communicates with the internal memory 31 of the communication module 30, for example, via a suitable data bus. With the aid of the transponder 32, for example, the current location of the vehicle 1 can be determined by communication with GPS satellites 51 and stored in the internal memory 31. Furthermore, the communication module 30 is configured to communicate with another vehicle 52 via V2V communication (or vehicle-to-vehicle communication), preferably via a communication network 53. Furthermore, the communication module 30 may also be configured to communicate with a server of the communication network 53. The communication module 30 also communicates with the control unit 40. Specifically, the communication module transmits received data to the control unit, and / or receives data to be transmitted by the control unit.
[0086] The communication network 53 is preferably a 3GPP-compliant network, such as an LTE, LTE-A (4G), or 5G communication network. The communication network may also be designed for or according to the following standards: High-Speed Packet Access (HSPA), Universal Mobile Telecommunications System (UMTS), UMTS Terrestrial Radio Access Network (UTRAN), Evolved UTRAN (e-UTRAN), Global System for Mobile Communications (GSM), Enhanced Data Rate GSM Evolution (EDGE), and GSM / EDGE Radio Access Network (GERAN). Alternatively or additionally, the communication network may also be designed according to one of the following standards: IEEE 802.16 compliant Global Microwave Access Interoperability (WIMAX) network, or IEEE 802.11 compliant Wireless Local Area Network (WLAN). Also preferably, the communication network uses one of the following coding methods: Orthogonal Frequency Division Multiple Access (OFDMA), Time Division Multiple Access (TDMA), Code Division Multiple Access (CDMA), Wideband Code Division Multiple Access (WCDMA), Frequency Division Multiple Access (FDMA), or Space Division Multiple Access (SDMA), etc.
[0087] Furthermore, the vehicle 1 has a control unit 40 according to the invention, which is configured for fully automated driving operation of the vehicle 1, particularly for longitudinal and lateral maneuvering of the vehicle. For this purpose, the control unit 40 has an internal memory 41 and a CPU 42, which communicate with each other, for example, via a suitable data bus. In addition, the control unit 40 is communicatively connected at least to first-type sensors 11, 12, 13, second-type sensors 21, 22, 23, and a communication module 30, such communication connection being implemented, for example, via one or more corresponding CAN connections, one or more corresponding SPI connections, or other suitable data connections. The control unit 40 is also particularly configured to implement the previously detailed method according to the invention for each of the plurality of vehicle components.
[0088] List of reference numerals
[0089] 1. Transportation
[0090] 11 First Sensor
[0091] 12 Second Sensor
[0092] 13 Third Sensor
[0093] 21 Fourth Sensor
[0094] 22 Fifth Sensor
[0095] 23 Sixth Sensor
[0096] 30 communication units
[0097] 31 memory
[0098] 32 transponders
[0099] 40 control units
[0100] 41 Internal Memory
[0101] 42 CPUs
[0102] 51 satellites
[0103] 52 Other means of transportation
[0104] 53 Network
[0105] S1 First Method Step
[0106] The first part of the S2a method steps
[0107] Part Two of the S2b Method Steps
[0108] S3 Third Method Steps
[0109] S4 Fourth Method Steps
[0110] S5 Fifth Method Step
[0111] S6 Sixth Method Step
[0112] S7a Seventh Method Steps
[0113] S7b Next Method Step
[0114] S8 Eighth Method Step
[0115] S9 Ninth Method Steps
[0116] S10 Tenth Method Step
[0117] S11 Eleventh Method Step
[0118] S12 Twelfth Method Step
[0119] S13 Thirteenth Method Steps
[0120] S14 Fourteenth Method Step
[0121] S15 Method Steps
[0122] K1 First Scenario
[0123] K2 Second Scenario
[0124] K3 Third Scenario
[0125] W1a First Path
[0126] W1b Second Path
[0127] W2a Third Path
[0128] W2b Fourth Path
[0129] W3a Fifth Path
[0130] W3b Sixth Path
[0131] W4a seventh path
[0132] W4b 8th path
[0133] W5a Ninth Path
[0134] W5b 10th path
[0135] W6a Eleventh Path
[0136] W6b Twelfth Path
[0137] W7a 13th Path
[0138] W7b Fourteenth Path
[0139] W8a Fifteenth Path
[0140] W8b Sixteenth Path
[0141] F fault
[0142] P sample value
[0143] G1 depends on the upper limit of the scenario.
[0144] G1' Static Upper Limit Value
[0145] G2 depends on the lower bound of the scenario.
[0146] G2' static lower limit value
Claims
1. A method for handling potential malfunctions of vehicle components in a vehicle (1) according to a scenario, the method comprising the steps of: - Identify the current scenario (K1, K2, K3) of the vehicle (1) and at least one of the vehicles (1) is a heterogeneous vehicle component in the current scenario (K1, K2, K3), wherein, Heterogeneous vehicle components are structurally different from the vehicle components and are designed to perform the tasks and / or functions of the vehicle components; - If at least one heterogeneous vehicle component (W6b) is identified: Then, heterogeneous verification is performed on potential faults (S13), which is performed with regard to at least one heterogeneous vehicle component; - If (W6a) heterogeneous vehicle components are not identified: Then determine the context-dependent relevance of (S6) vehicle components; and Based on the determined relevance depending on the situation, handle (S7a) potential malfunctions of vehicle components or activate (S7b) the emergency operation mode of vehicle (1).
2. The method according to claim 1, wherein the heterogeneous verification (S13) includes the following steps: - Determine that there is no potential failure (W7b) in at least one heterogeneous vehicle component; - Determine the context-dependent relevance of (S6) vehicle components; and - Based on the determined relevance depending on the situation, handle (S7a) potential failure of vehicle components or activate (S7b) emergency operation mode of vehicle (1).
3. The method according to claim 1, wherein the heterogeneous verification (S13) includes the following steps: - Identify the potential failure of at least one heterogeneous vehicle component (W7a); - Compare (S15) the sample values and / or diagnostic values of the vehicle component and at least one heterogeneous vehicle component; and - Based on this comparison: Ignoring potential malfunctions of vehicle parts (S11); or Determine the situation-dependent relevance of the vehicle component (S6), and based on the determined situation-dependent relevance, address the potential failure of the vehicle component (S7a) or initiate the emergency operation mode of the vehicle (1) (S7b).
4. The method according to claim 1, further comprising: - Identify at least one isomorphic vehicle component of the vehicle (S5); - If at least one isomorphic vehicle component (W2b) is identified: Then, isomorphic verification (S8) is performed on potential faults, wherein the isomorphic verification is performed taking into account at least one isomorphic vehicle component. The isomorphic vehicle component is structurally identical to the vehicle component and is designed to perform the tasks and / or functions of the vehicle component.
5. The method according to claim 3, wherein, In the comparison of sample values and / or diagnostic values (S15), it is determined whether the sample values and / or diagnostic values of the vehicle component are within the dispersion range of sample values and / or diagnostic values of at least one heterogeneous vehicle component, wherein if the sample values and / or diagnostic values of the vehicle component are within the dispersion range of sample values and / or diagnostic values of at least one heterogeneous vehicle component (W8a), then the potential fault of the vehicle component is ignored (S11), and wherein otherwise (W8b) the determination (S6) depends on the relevance of the situation.
6. The method according to claim 1, wherein, Identifying potential faults in vehicle components (S14) includes the following steps: - Determine sample values (P) of vehicle components within at least one defined metric (S1, S2a, S2b), and determine a group of limit values (G1, G2) within the defined metric according to the defined scenario (K1, K2, K3). - The diagnostic value is determined as the quotient of the difference between the determined sample value (P) and the lower limit (G2) and the difference between the upper limit (G1) and the lower limit (G2). - Wherein, if the sample value (P) is not within the determined limits (G1, G2), and / or if the diagnostic value does not have a value between 0 and 1, a potential fault is identified.
7. The method according to claim 1, wherein, The scenarios (K1, K2, K3) are defined based on multiple parameters that characterize the surrounding environment and / or driving conditions of the vehicle (1).
8. The method according to claim 1, wherein, The relevance is determined taking into account the permissible failure rate of the vehicle components in the current scenarios (K1, K2, K3) and / or the availability of vehicle components that are heterogeneous and / or homogeneous in the current scenarios (K1, K2, K3), and / or wherein, If the determined relevance is lower than the predetermined relevance limit, fault handling is performed (S7a), and if the determined relevance exceeds the predetermined relevance limit, emergency operation mode is activated (S7b).
9. A means of transport (1) having at least one means of transport component and a control unit (40) designed to implement the method according to any one of claims 1 to 8.
Citation Information
Patent Citations
Situation awareness system and method
CN105324268A
City traffic flow vehicle and road cooperative control method based on M2M
CN105809953A