Prevention planning of a vehicle

Through the computer-implemented method, data on the high-risk state of the vehicle and the unexpected unexpected ODD exit area are obtained, and the vehicle is controlled to reduce the possibility of high-risk state, which solves the problem of high-risk state of the vehicle caused by ADS failures and environmental changes, and improves safety and road safety.

CN120039273APending Publication Date: 2025-05-27ZENSEACT AB
View PDF 0 Cites 0 Cited by

Patent Information

Application Number
CN202411682396.2
Authority / Receiving Office
CN · China
Patent Type
Applications(China)
Current Assignee / Owner
Priority Date
2023-11-24
Filing Date
2024-11-22
Publication Date
2025-05-27

AI Technical Summary

Technical Problem

The prior art is difficult to effectively solve the problem of high-risk vehicle state caused by failure of autonomous driving systems (ADS) and unexpected changes in the surrounding environment.

Method used

Through a computer-implemented method, data for the vehicle's high-risk state and the undesired unexpected operation design domain (ODD) exit area are obtained, and the vehicle is controlled based on these data to reduce the possibility of entering the high-risk state.

Benefits of technology

Reduces the risk of high-risk vehicles caused by ADS failures and environmental changes, and improves the safety of ADS fallback function and other road users.

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure CN120039273A_ABST
    Figure CN120039273A_ABST
Patent Text Reader

Abstract

The invention discloses prevention planning for a vehicle. Computer-implemented methods and related aspects are disclosed for preventive planning of a vehicle having an automatic driving system (ADS) function, the ADS function having an operational design domain (ODD). The method includes obtaining data including information about a high risk state of the vehicle along a route to be traveled by the vehicle, where the high risk state is defined based on a geographic area along the route to be traveled and a set of potential states of the vehicle within the geographic area. The method further includes obtaining, based on a current trajectory of the vehicle and a nominal minimum risk maneuver (MRM) configuration of the vehicle, data including information about an unexpected accidental ODD (UUODD) exit area along a route along which the vehicle is to travel, the UUODD exit area is defined based on a likelihood that the vehicle enters a high risk state in response to the MRM being executed while the vehicle is in the UUODD exit area. The method further includes controlling the vehicle based on the UUODD exit zone in order to reduce the likelihood that the vehicle enters a high risk state.
Need to check novelty before this filing date? Find Prior Art

Description

Technical Field

[0001] The disclosed technology relates to automotive technology, and more particularly to methods, systems, and other related aspects for preventive planning for vehicles with automated driving systems (ADS). Background Art

[0002] During the past few years, the number of research and development activities related to autonomous vehicles has surged, and many different approaches are being explored. More and more modern vehicles have advanced driver assistance systems (ADAS) for improving vehicle safety and more general road safety. ADAS, which can be represented by adaptive cruise control (ACC) collision avoidance systems, forward collision warnings, etc., is an electronic system that can help the driver of a vehicle while driving. Today, research and development are being conducted in many technical fields associated with both the fields of ADAS and autonomous driving (AD). In this article, ADAS and AD will be referred to under the general term autonomous driving system (ADS).

[0003] In the near future, ADS solutions are expected to have found their way into most new cars put on the market. ADS can be interpreted as a complex combination of various components, which can be defined as a system that performs perception, decision-making and operation of the vehicle by electronics and mechanics rather than human drivers and introduces automation into road traffic. This includes the processing of vehicles, destinations and awareness of the surrounding environment. Although the automated system has control over the vehicle, it allows the human operator to leave all or at least part of the responsibility to the system. ADS typically senses the surrounding environment of the vehicle in conjunction with various sensors such as radar, LIDAR, sonar, camera, navigation system (e.g., GPS), odometer and / or inertial measurement unit (IMU), and the advanced control system can interpret the sensor information based on these sensors to identify appropriate navigation paths as well as obstacles, free space areas and / or related signs.

[0004] However, despite the prospect of ADS performing better than human drivers, there is still a need for solutions to improve the safety of ADS. Summary of the invention

[0005] The technology disclosed herein is intended to mitigate, alleviate or eliminate one or more deficiencies and shortcomings in the prior art to address various issues related to potential safety risks that a vehicle and its occupants may face due to a malfunction of an ADS.

[0006] In particular, the technology disclosed herein is directed to providing methods, systems, and other related aspects for preventive planning to reduce or eliminate the risk of a vehicle ending up in a high-risk state due to unexpected failure of the vehicle's ADS and / or due to unexpected changes in the vehicle's surroundings.

[0007] Various aspects and embodiments of the disclosed technology are defined in the accompanying independent and dependent claims.

[0008] The first aspect of the disclosed technology includes a computer-implemented method for preventive planning of a vehicle with an automated driving system (ADS) function, the ADS function having an operational design domain (ODD). The method includes obtaining data including information about a high-risk state of a vehicle along a route to be traveled by the vehicle. The high-risk state is defined based on a geographic area along the route to be traveled and a set of potential states of the vehicle within the geographic area. The method further includes: based on the current trajectory of the vehicle and the nominal minimum risk maneuver (MRM) configuration of the vehicle, obtaining data including information about an undesired accidental ODD (UUODD) exit area along the route to be traveled by the vehicle. The UUODD exit area is defined based on the possibility that the vehicle enters a high-risk state in response to the MRM being executed when the vehicle is in the UUODD exit area. In addition, the method includes: controlling the vehicle based on the UUODD exit area so as to reduce the possibility of the vehicle entering a high-risk state.

[0009] A second aspect of the disclosed technology includes a computer program product containing instructions that, when executed by a computing device (of a vehicle), cause the computing device to perform a method according to any one of the embodiments disclosed herein. In the case of this aspect of the disclosed technology, there are similar advantages and preferred features as in the other aspects.

[0010] A third aspect of the disclosed technology includes a (non-transitory) computer-readable storage medium containing instructions that, when executed by a (vehicle's) computing device, cause the computing device to perform a method according to any one of the embodiments disclosed herein. In the case of this aspect of the disclosed technology, similar advantages and preferred features exist as in the other aspects.

[0011] As used herein, the term "non-transitory" is intended to describe computer-readable storage media (or "memory") that do not include propagating electromagnetic signals, but is not intended to otherwise limit the types of physical computer-readable storage devices encompassed by the term computer-readable media or memory. For example, the terms "non-transitory computer-readable media" or "tangible memory" are intended to cover types of storage devices that do not necessarily store information permanently, including, for example, random access memory (RAM). Program instructions and data stored in a non-transitory form on a tangible computer-accessible storage medium may be further transmitted via a transmission medium or signals such as electrical, electromagnetic, or digital signals that may be transmitted via a communication medium such as a network and / or wireless link. Therefore, as used herein, the term "non-transitory" is a limitation on the medium itself (i.e., tangible, not a signal), not a limitation on the persistence of data storage (e.g., RAM versus ROM).

[0012] The fourth aspect of the disclosed technology includes a system for preventive planning of a vehicle with an automated driving system (ADS) function, the ADS function having an operational design domain (ODD). The system includes a control circuit configured to obtain data including information about a high-risk state of a vehicle along a route to be traveled by the vehicle. The high-risk state is defined based on a geographic area along the route to be traveled and a potential state set of the vehicle within the geographic area. The control circuit is further configured to obtain data including information about an undesired unexpected ODD (UUODD) exit area along the route to be traveled by the vehicle based on the current trajectory of the vehicle and the nominal minimum risk maneuver (MRM) configuration of the vehicle. The unplanned ODD exit area is defined based on the possibility that the vehicle will enter a high-risk state in response to the MRM being executed when the vehicle is in the UUODD exit area. The control circuit is further configured to control the vehicle based on the UUODD exit area so as to reduce the possibility of the vehicle entering a high-risk state. In the case of this aspect of the disclosed technology, there are similar advantages and preferred features as in other aspects.

[0013] A fifth aspect of the disclosed technology comprises a vehicle comprising a system according to any one of the embodiments disclosed herein.With this aspect of the disclosed technology, similar advantages and preferred features exist as in the previously discussed aspects.

[0014] The disclosed aspects and preferred embodiments may be suitably combined with one another in any manner apparent to any one of ordinary skill in the art, such that one or more features or embodiments disclosed with respect to one aspect may also be considered disclosed with respect to another aspect or embodiments of another aspect.

[0015] An advantage of some embodiments is that the overall risk exposure of the ADS may be reduced, and particularly in the event that the ADS experiences an unexpected failure (ie, an ODD exit).

[0016] An advantage of some embodiments is that the performance of the fallback function of the ADS triggered by an unexpected ODD exit may be improved in terms of safety.

[0017] An advantage of some embodiments is that general road safety for other road users may be improved.

[0018] Further embodiments are defined in the dependent claims. It should be emphasized that when used in this specification, the term "comprising" is used to indicate the presence of stated features, integers, steps or components. It does not exclude the presence or addition of one or more other features, integers, steps, components or groups thereof.

[0019] These and other features and advantages of the disclosed technology will be further elucidated below with reference to the embodiments described hereinafter. BRIEF DESCRIPTION OF THE DRAWINGS

[0020] The above-described aspects, features, and advantages of the disclosed technology will be more fully understood through the following illustrative and non-limiting detailed description of example embodiments of the technology, taken in conjunction with the accompanying drawings, in which:

[0021] Figure 1 is a schematic flow chart representation of a method for preventive planning for a vehicle having an automated driving system (ADS) function, the ADS function having an operational design domain (ODD), according to some embodiments;

[0022] Figure 2 is a schematic top view of a road scene with a vehicle traveling along a route according to some embodiments; and

[0023] Figure 3 is a schematic diagram of a vehicle including a system for preventive planning for the vehicle, according to some embodiments. DETAILED DESCRIPTION

[0024] The technology disclosed herein will now be described in detail with reference to the accompanying drawings in which some example embodiments of the disclosed technology are shown. However, the disclosed technology may be implemented in other forms and should not be construed as being limited to the disclosed example embodiments. The disclosed example embodiments are provided to fully convey the scope of the disclosed technology to the technician. It will be understood by those skilled in the art that the steps, services, and functions described herein may be implemented using separate hardware circuits, using software that works in conjunction with a programmed microprocessor or general-purpose computer, using one or more application-specific integrated circuits (ASICs), using one or more field programmable gate arrays (FPGAs), and / or using one or more digital signal processors (DSPs).

[0025] It will also be understood that when the disclosed techniques presented herein are described in terms of methods, they may also be implemented in a system comprising one or more processors, one or more memories coupled to the one or more processors, wherein computer code is loaded to implement the methods. For example, in some embodiments, the one or more memories may store one or more computer programs that, when executed by the one or more processors, cause the system to perform the steps, services, and functions disclosed herein.

[0026] It should also be understood that the terms used in this article are only used for the purpose of describing specific embodiments, and are not intended to be limited. It should be noted that, as used in the specification and the appended claims, unless the context clearly stipulates otherwise, the words "one", "an", "the" and "said" are intended to mean that there are one or more elements. Therefore, for example, in some contexts, mentioning "a unit" or "the unit" can refer to more than one unit, etc. In addition, the words "include", "comprise" do not exclude other elements or steps. It should be emphasized that when used in this specification, the term "include" is used to indicate the presence of stated features, wholes, steps or parts. It does not exclude the presence or addition of one or more other features, wholes, steps, parts or their groups. The term "and / or" should be interpreted as meaning "both" and each is alternative.

[0027] It will also be understood that, although the terms first, second, etc. can be used to describe various elements or features in this article, these elements should not be limited by these terms. These terms are only used to distinguish one element from another element. For example, without departing from the scope of the embodiment, the first signal can be referred to as the second signal, and similarly, the second signal can be referred to as the first signal. Both the first signal and the second signal are signals, but they are not the same signal.

[0028] definition

[0029] In the current context, "autonomous driving system" ("ADS") refers to a complex combination of hardware components and software components designed to control and operate a vehicle without direct human intervention. ADS technology aims to automate various aspects of driving such as steering, acceleration, deceleration, and monitoring of the surrounding environment. The main goal of ADS is to improve the safety, efficiency and convenience of transportation. As classified by standards such as SAE J3016, ADS can range from basic driver assistance systems to highly advanced autonomous driving systems, depending on their level of automation. These systems use a variety of sensors, cameras, radars, lidars, and powerful computer algorithms to perceive the environment and make driving decisions. The specific capabilities and features / functionality of ADS may vary greatly, from systems that provide limited assistance to systems that can independently handle complex driving tasks under specific conditions.

[0030] Advanced driver assistance systems (ADAS) are technologies that assist drivers during driving, but they do not necessarily provide full autonomy. ADAS features generally serve as building blocks for ADS. Examples include adaptive cruise control, lane keeping assistance, automatic emergency braking, and parking assistance. They improve safety and convenience, but generally require a certain degree of human supervision and intervention. On the other hand, autonomous driving (AD) is a technology designed to control and navigate a vehicle without human supervision. Accordingly, it can be said that the difference between ADAS and AD lies in the level of autonomy and control. ADAS systems are designed to help and support drivers, while AD aims to fully control the vehicle without the need for continuous human supervision. Accordingly, AD aims at a higher level of autonomy (such as level 4 and level 5 according to the SAE international standard), wherein the vehicle can operate independently in most or all driving scenarios without human intervention. As mentioned in the foregoing, the term "ADS" is used herein as an umbrella term that includes both ADAS and AD. In the current context, ADS functions or ADS features can be understood as specific functions or features of the entire ADS stack such as highway navigation features, traffic jam navigation features, path planning features, etc.

[0031] The term "operational design domain" (ODD) may be understood as the specific operating conditions and environment in which an ADS or autonomous vehicle is intended to operate safely and efficiently. It defines the boundaries within which the autonomous system is designed and validated to operate. ODD conditions may be divided into external ODD conditions and internal ODD conditions. Here, external ODD conditions may refer to external factors or environmental elements that affect the operation of the autonomous driving system. Internal ODD conditions may refer to the capabilities and limitations inherent to the autonomous vehicle or ADS itself.

[0032] External ODD conditions may include geographic restrictions such as urban areas, highways, or geographic areas or geographic regions in a particular city that define where the ADS is intended to operate. External ODD conditions may include environmental factors, including conditions such as weather (rain, snow, fog, etc.), lighting conditions (daytime, nighttime), and various terrains (mountainous, urban, rural) that affect the sensors and perception systems of the ADS. External ODD conditions may include road infrastructure, including the types of roads, lanes, intersections, signs, and road markings that the ADS is designed to navigate. External ODD conditions may include traffic conditions, including changes in traffic density, the behavior of other vehicles, pedestrians, and cyclists.

[0033] Internal ODD conditions may include sensor capability parameters such as the range, accuracy, and reliability of sensors such as cameras, lidar, radar, and other perception systems. Internal ODD conditions may include processing and decision making parameters, including computing power and algorithms used to interpret sensor data, make driving decisions, and control the vehicle. Internal ODD conditions may include functional capability parameters including specific capabilities of the ADS, including its ability to handle complex traffic conditions, navigate intersections, change lanes, stop, and perform emergency maneuvers.

[0034] The term "preventive planning" may be understood as a function or system of an ADS for the prediction and planning of potential risks or situations that may arise during operation. In more detail, preventive planning in the context of an automated driving system may involve a meticulous and systematic approach to identifying, mitigating and preparing for potential risks and uncertainties associated with the operation of a vehicle equipped with an ADS. Preventive planning may, for example, involve continuously evaluating the driving environment, analyzing data from sensors and other sources to predict potential dangers such as pedestrians, cyclists, unstable drivers, road construction or adverse weather conditions. It may further involve the prioritization of safety in decision making. Algorithms determine how the vehicle should respond in various scenarios to minimize risk, whether that means braking, changing lanes or adjusting speed to avoid potential collisions. It may further involve designing redundancy into critical systems and implementing fail-safe mechanisms. This ensures that if the primary system fails, there is a backup system ready to maintain control or stop the vehicle safely. Moreover, preventive planning may involve compliance with regulations and standards, continuous monitoring and adaptation, ethical considerations, and the like. Essentially, “preventive planning” for ADS can be understood as a comprehensive approach to anticipating, analyzing, and mitigating the risks associated with automated driving that is designed to ensure the safe, reliable, and ethical operation of these vehicles on the road.

[0035] Accordingly, the embodiments disclosed herein may be understood as a preventive planning function or a sub-function of a preventive planning stack.

[0036] Overview

[0037] SAE Level 4 ADS provides features for unsupervised automated driving (AD) that improve the comfort and convenience of the driving experience by allowing the driver to engage in tasks unrelated to driving. However, such a high level of automation (i.e., SAE Level 4 ADS) can only operate under certain conditions. As mentioned, these conditions are generally referred to as the operational design domain (ODD) of the ADS or its features / functions.

[0038] When the vehicle is within the ODD, i.e., when the vehicle and environment satisfy applicable ODD conditions, the associated ADS function may be activated (e.g., upon driver request) such that a dynamic driving task (DDT) can be performed by the ADS. However, following activation and once the conditions of the ODD fail to pass or are otherwise not satisfied, the DDT will be interrupted because the ADS has "exited" its ODD. Preferably, the ADS function should be deactivated before the ODD is exited. However, depending on which ODD conditions have been violated (different condition violations being associated with different severities), the deactivation mechanism for the ADS function is typically performed in one of two ways.

[0039] The first alternative is the so-called “Planned ODD Exit”. Here, when the vehicle approaches an ODD exit, the ADS will issue a prompt requesting a handover to take over the DDT. If the driver will ignore the request or fail to respond appropriately to the request within a specific time limit (usually 10 to 20 seconds), the DDT fallback condition is met, which triggers the Minimum Risk Maneuver (MRM) function to stop the host vehicle within the lane or, if possible, on the shoulder lane. These situations usually occur when the ADS detects that the vehicle is approaching an environment that does not meet the ODD. For example, the ODD may require that the road should have barriers on both sides, while the HD map data or sensors indicate that there is a lack of barriers 500m ahead of the vehicle.

[0040] The second alternative is the so-called "unplanned ODD exit". Here, the ADS will immediately perform the MRM without any switching request. These situations typically occur when the ADS detects that one or more sensors have been contaminated or otherwise non-functional, there is a software or hardware failure within the ADS, or the connection with the control tower has been lost, etc. However, these situations may also occur due to external factors (e.g., sudden changes in the environment) such as sudden changes in weather, road conditions or traffic conditions (which are outside the ODD). As mentioned, an ADS function or ADS feature can be understood as a specific function or feature of the entire ADS stack. In particular, in the current scenario, it is assumed that the ADS function is associated with the MRM function performed in the event of an unplanned ODD exit.

[0041] Embodiments of the technology disclosed herein may be understood as solutions for mitigating the potential risks associated with the aforementioned "unplanned ODD exit". For example, some embodiments herein are intended to reduce the risk or likelihood that a vehicle will end up in a high-risk state that poses a safety issue to the vehicle and its passengers in the event of an "unplanned ODD exit".

[0042] In the present context, the "MRM" function may be understood as a "backup stop" or "safe stop" function of the ADS that is configured to bring the vehicle to a "safe state" when it should be executed. In general, this means that once executed, the MRM function aims to stop the vehicle as quickly as possible without colliding with any other object. In many cases, this may result in the vehicle being stopped in a position that may be "safe" on the one hand (i.e., no collision before reaching the stop), but is associated with a high risk for other road users. An illustrative example may be stopping at a merging section of a highway entrance ramp. Accordingly, the MRM may be able to stop the vehicle in a safe manner, however, stopping at this particular position may be associated with an increased risk of collision with other road users. At the very least, it may cause a large disruption in traffic.

[0043] Example

[0044] Figure 1 A schematic flow chart representation of a method 100 for preventive planning for a vehicle with an automated driving system (ADS) function according to some embodiments is illustrated. The ADS function has a defined operational design domain (ODD) for which the ADS function is designed and validated to operate. Method S100 is preferably a computer-implemented method S100 executed by a processing system of a vehicle equipped with an ADS. The processing system may, for example, include one or more processors and one or more memories coupled to the one or more processors, wherein the one or more memories store one or more programs that, when executed by the one or more processors, perform the steps, services, and functions of the method S100 disclosed herein.

[0045] Method S100 includes obtaining S101 data including information about a high-risk state of a vehicle along a route to be traveled by the vehicle. The high-risk state is in turn defined based on a geographic area along the route to be traveled and a set of potential states of the vehicle within the geographic area. Accordingly, a "high-risk state" can be considered as a potential situation to which the vehicle may be exposed, which poses a risk to the vehicle and its occupants and / or other road users. For example, a high-risk state can be a vehicle parked at a position (X, Y) (vehicle state) in a lane merging area after an entrance ramp of a highway (geographical area). Another example can be a vehicle parked at a position (A, B) (vehicle state) in a single lane near a road project (geographical area). Therefore, the "vehicle state" (e.g., parked at a specific position) itself is not high risk, and the geographic area (lane merging area) itself is not high risk, however, a specific combination of the two forms a high-risk state. Accordingly, a "potential state set" can include a vehicle position (e.g., a geographic coordinate such as a GNSS coordinate) and a vehicle speed (e.g., 0 km / h). However, even though most examples involve potential vehicle states where the vehicle's speed is zero, other speed values ​​and vehicle positions may be involved such that traversing an area at a speed below a certain speed value is considered a "high risk state". Moreover, a "potential state set" may include further parameters such as heading angle, steering angle, state of headlights / taillights, etc. For example, parking in a geographic area with a certain steering angle may be considered a "high risk state", while parking in the same geographic area with a "straight" steering angle may not be considered a high risk state.

[0046] Accordingly, a "high risk state" may be determined heuristically based on a rule or based on a predefined rule set. For example, a vehicle stopped at each lane merging area after an on-ramp of a highway may be determined to be in a "high risk state". High risk states may be defined in map data (e.g., HD map data) accessible to the ADS, or they may be detected / determined in real time based on map data and / or sensor data.

[0047] The route that the vehicle is to travel can be understood as the planned or expected route from the starting point or current point to the destination that the vehicle intends to follow. As defined herein, the route that the vehicle is to travel can but does not have to include a more fine-grained representation of the vehicle's intended route, or in other words, the route can include the path that the vehicle is to travel. Generally, the "route that the vehicle is to travel" can be understood as the vehicle's intended traversal, and it can be derived from the vehicle's current position, heading, and optional destination. However, it can also be derived from the vehicle's planned path, for example, output by the path planning function of the ADS.

[0048] The term "obtain" should be interpreted broadly herein and includes receiving, retrieving, collecting, acquiring, etc., directly and / or indirectly between two entities configured to communicate with each other or further communicate with other external entities. However, in some embodiments, the term "obtain" will be interpreted as determining, deriving, forming, calculating, etc. In other words, obtaining the route of the vehicle may include determining or calculating the route of the vehicle based on, for example, GNSS data and / or perception data and map data. Therefore, as used herein, "obtaining" may indicate receiving a parameter from a second entity / unit at a first entity / unit, or determining a parameter at a first entity / unit, for example based on data received from another entity / unit.

[0049] Method S100 further includes obtaining S102 data including information about the undesired accidental ODD (UUODD) exit area along the route to be traveled by the vehicle. The UUODD exit area is based on the current trajectory of the vehicle and the nominal minimum risk maneuver (MRM) configuration of the vehicle. In more detail, the UUODD exit area is defined based on the possibility that the vehicle will enter a high-risk state in response to the minimum risk maneuver (MRM) (under the nominal configuration) executed when the vehicle is in the UUODD exit area. In this scenario, the "possibility" that the vehicle will enter a high-risk state can be, for example, a possibility that exceeds a possibility value (or a possibility threshold) such as 50%, 60%, 70%, 80% or 90% as an example. However, depending on the specific implementation and specification, other possibility values ​​are feasible. The possibility can be calculated, for example, based on a general vehicle motion model considering the current trajectory of the vehicle and the nominal MRM configuration. However, in some embodiments, the "possibility" is only a non-zero possibility that the vehicle will enter a high-risk state if MRM is executed in the UUODD exit area. In other words, if there is any risk (>0%) that the vehicle will enter a high risk state if an MRM is performed within the UUODD exit region, this is taken into account in the definition of the UUODD exit region.

[0050] In other words, once a high-risk state is defined, the UUODD exit region can be calculated based on the likelihood that the vehicle will enter a high-risk state if an MRM is executed while the vehicle is within the UUODD exit region. Accordingly, the UUODD exit region can be understood as a geographic area within which an "unplanned ODD exit" is not expected (because it may cause the vehicle to end up in a high-risk state). This is in contrast to other "unplanned ODD exits" where MRM execution is unlikely to cause the vehicle to enter or end up in a "high-risk state".

[0051] The extension of the UUODD exit zone may be defined accordingly based on the geographic extension of the geographic area included in the high risk state, the vehicle's current trajectory (e.g., speed and heading), and the nominal MRM configuration (i.e., predefined deceleration and maneuvering capabilities). Figure 2 Provides further details and examples.

[0052] The method S100 further comprises: controlling S103 the vehicle based on the UUODD exit zone to reduce the likelihood of the vehicle entering a high risk state. The method S100 may comprise: controlling S103 the vehicle in response to the likelihood being higher than the likelihood value to reduce the likelihood of the vehicle entering a high risk state.

[0053] For example, in response to the likelihood value being equal to or greater than a 50% likelihood that the vehicle will enter a high risk state if MRM is performed within the UUODD exit area, method S100 may include controlling S103 the vehicle to reduce the likelihood that the vehicle will enter a high risk state.

[0054] As mentioned, some embodiments disclosed herein may be understood as subroutines in the preventive planning function of an ADS. First, a high-risk state is obtained 101 indicating a geographic area representing a safety risk to the vehicle and / or other road users. Next, a UUODD exit zone is obtained based on vehicle dynamics and a nominal MRM configuration, and the vehicle is then controlled so as to reduce the likelihood of the vehicle entering a high-risk state.

[0055] The control S103 of the vehicle for reducing the possibility of the vehicle entering a high-risk state can be implemented in different forms. In particular, the control S103 can depend on whether the ADS function is activated or deactivated (although it can be used for activation). As is easy to understand, when executing preventive planning, it is always assumed that the vehicle is within the ODD of the ADS function.

[0056] Accordingly, in some embodiments, the control S103 of the vehicle includes, in response to the ADS function being currently deactivated, prohibiting S104 from activating the ADS function in the UUODD exit area. Accordingly, if the ADS function is deactivated, although it can be used for activation, in order to reduce the risk of the vehicle entering or eventually being in a high-risk state, prohibiting S104 the activation of the function. Otherwise, there may be a situation where the ADS function is activated in the UUODD exit area, and there is no time for preventive planning, so the sensor may fail, and therefore an unplanned ODD exit occurs, resulting in the execution of MRM, and the vehicle may be stopped in an unfavorable position. In some embodiments, the prohibition S104 of the activation of the ADS function includes: when the vehicle is in the UUODD exit area and within a set distance before entering the UUODD exit area, prohibiting the activation of the ADS function. For example, prohibition can be performed 1 second, 2 seconds, 3 seconds or 5 seconds before the expected entry into the UUODD exit area. Alternatively, prohibition can be performed at 10 meters, 20 meters, 50 meters, 100 meters or 500 meters before the expected entry into the UUODD exit area.

[0057] Moreover, in some embodiments, controlling S103 the vehicle includes: in response to the ADS function being currently activated, updating S105 the trajectory of the vehicle so as to reduce the likelihood that the vehicle will enter a high-risk state if the MRM is executed when the vehicle is in the UUODD exit area. In some cases, the trajectory can be updated S105 so as to avoid the UUODD exit area completely (thereby eliminating the risk of entering a high-risk state if the MRM is executed when the vehicle is in the UUODD exit area), or otherwise adjusting the trajectory (e.g., changing speed) to at least reduce the risk.

[0058] In some embodiments, the updating S105 of the trajectory of the vehicle includes: controlling S106 the lateral movement of the vehicle so as to reduce the likelihood that the vehicle enters a high-risk state if the MRM is executed when the vehicle is in the UUODD exit area. The control S106 of the lateral movement of the vehicle can, for example, switch the lane of the vehicle assuming that another lane is available and then further assuming that switching to a different lane does not impose other safety-related risks on the vehicle. In some embodiments, the updating S106 of the trajectory of the vehicle includes: executing a lane change function of the ADS so as to switch to an adjacent lane that is different from the current driving lane of the vehicle. Here, it is assumed that the lane change function of the ADS takes into account and handles any safety-related risks associated with lane changes.

[0059] In some embodiments, the updating S105 of the vehicle trajectory includes: controlling S107 the speed of the vehicle (when the vehicle is in the UUODD exit area) so as to reduce the possibility that the vehicle will enter a high-risk state if the MRM is executed when the vehicle is in the UUODD exit area. The control S107 of the speed of the vehicle may, for example, include increasing or decreasing the speed of the vehicle. In more detail, by reducing the speed when the vehicle is in the UUODD exit area, if the MRM is executed, the vehicle may "miss the target" (i.e., stop before the geographical area of ​​high risk state). Similarly, by increasing the speed when the vehicle is in the UUODD exit area, if the MRM is executed, the vehicle may "overshoot the target" (i.e., stop after the geographical area of ​​high risk state).

[0060] Moreover, in some embodiments, controlling S103 the vehicle includes: in response to the ADS function being currently activated, temporarily updating S108 the MRM configuration to a configuration different from the nominal MRM configuration, so as to reduce the possibility that the vehicle enters a high-risk state if the MRM is executed when the vehicle is in the UUODD exit area. In other words, instead of adjusting the trajectory of the S105 vehicle, the MRM can be reconfigured instead so as to reduce the possibility that the vehicle enters a high-risk state if the MRM is executed when the vehicle is in the UUODD exit area. For example, the S108 MRM configuration can be adjusted by, for example, allowing a higher (maximum) deceleration (e.g., from -0.5g to -1.0g) or limiting the (maximum) deceleration (e.g., from -0.5g to -0.25g). By allowing a higher deceleration, the vehicle can be stopped before the geographic area of ​​the high-risk state (i.e., not reaching the target). Similarly, by limiting or reducing (the maximum deceleration), the vehicle can be stopped after the geographic area of ​​the high-risk state (i.e., exceeding the target). Temporary MRM configuration update S108 may be used, for example, when the trajectory of the vehicle cannot be adjusted without increasing the risk or violating some traffic regulations. The term "temporary" with respect to the adjustment / update S108 of the MRM configuration may be understood as the configuration of the adjustment / update S108 being applied only for a limited duration. For example, once the vehicle has passed through a UUODD exit area or a geographic area of ​​high risk status, the MRM configuration may be returned to the nominal MRM configuration. Therefore, in some embodiments, method S100 further includes: in response to the vehicle passing through the UUODD exit area, changing / updating the MRM configuration of the temporary update S108 back to the nominal MRM configuration.

[0061] In some embodiments, the control S103 of the vehicle is performed before the vehicle enters the UUODD exit area. In some embodiments, when the vehicle is expected to cross the UUODD exit area, the control S103 of the vehicle is performed during a defined time window immediately before the subsequent time window. In other words, the control S103 of the vehicle can be performed within a time window before the time window that starts when the vehicle enters the UUODD exit area.

[0062] As used herein, the term "in response to X being Y" may be interpreted to mean "if X is Y", "when X is Y", "in accordance with X being Y", "in response to detecting X is Y", "in response to determining X is Y" or "in response to receiving a signal indicating X is Y", depending on the context. Accordingly, the term "in response to the ADS function being currently activated" may be interpreted to mean "in response to detecting and identifying that the ADS function is activated" or "in response to receiving a signal indicating that the ADS function is activated". Similarly, the phrase "if determined" or "when determining..." or "in an instance of..." may be interpreted to mean "in accordance with determination" or "in response to determination" or "in accordance with detecting and identifying the occurrence of an event" or "in response to detecting the occurrence of an event", depending on the context.

[0063] Executable instructions for performing these functions are optionally included in a non-transitory computer-readable storage medium or other computer program product configured for execution by one or more processors.

[0064] Figure 2 is a schematic top view of a road scene of a vehicle traveling along a route according to some embodiments. In particular, Figure 2 is a schematic top view of a road scene to which the techniques disclosed herein may be applied according to some embodiments. Reference will also be made to a schematic diagram of a vehicle 1 including a system 10 for preventive planning of the vehicle 1 according to some embodiments. Figure 3 The following description is made.

[0065] The road scenario depicts a vehicle 1 including an ADS function with an ODD, wherein the vehicle 1 is traveling along a route as indicated by a dashed arrow in front of the vehicle 1. The vehicle 1 includes a system 10 having a control circuit 11 configured to obtain data including information about a high risk state 21 of the vehicle 1 along the route that the vehicle 1 is to travel.

[0066] The high risk state is defined based on the geographic area 23 along the route to be traveled and the set of potential states 24 of the vehicle 1 within the geographic area 21. For example, it can be assumed that based on the execution of the MRM, the vehicle 1 will be stopped within a certain defined geographic area. However, stopping the vehicle 1 at certain locations on the road may result in an increased risk of accidents with other road users 30. Accordingly, by identifying the geographic area 21 within which a specific vehicle state 24 may result in an increased risk exposure to the vehicle and / or other road users, a high risk state can be determined.

[0067] In more detail, the high risk state 21 may be determined heuristically based on map data and a predefined set of rules. For example, the predefined rules may include that the geographic area 21 of the high risk state 21 may be an area near a merging lane of a highway, an exit of a highway, or an area near a temporary road closure (i.e., an area around a temporary lane merge). The geographic area 23 of the high risk state 21 may be directly indicated and defined in the map data, for example, directly indicated and defined as a layer in the HD map. Accordingly, in response to obtaining map data indicating that the vehicle 1 is approaching the geographic area 23 of the high risk state 21, the high risk state 21 may be determined. As mentioned, the geographic area 21 may be a predefined geographic area 21 indicated by the HD map 308 accessible by the control circuit 11. However, in some embodiments, the control circuit 11 may simply determine the high risk state along the route to be traveled by the vehicle based on the map data and the predefined set of rules. In other words, the map data may simply indicate that a lane merge is approaching, whereupon the control circuit 11 is configured to define a high risk state associated with the lane merge.

[0068] In addition, once information about the high-risk state 21 is obtained, the control circuit 11 is configured to obtain data including information about an unplanned undesired ODD (UUODD) exit region 22 along the route to be traveled by the vehicle 1. The UUODD exit region is defined based on the likelihood that the vehicle will enter a high-risk state in response to an MRM being executed when the vehicle is in the UUODD exit region 22. The control circuit 11 can be configured to calculate or otherwise determine the UUODD exit region using a vehicle motion model given the high-risk state 21, the current trajectory of the vehicle 1, and the MRM configuration.

[0069] In more detail, the vehicle motion model acts as a mathematical representation of the motion of the vehicle. In general, the vehicle motion model is intended to simulate / predict how the vehicle will move based on its current state, inputs (e.g., steering, acceleration, and braking), and environmental factors like road conditions, traffic, and obstacles. The vehicle motion model may include a kinematic model that describes the motion of the vehicle in terms of position, velocity, and acceleration without considering the forces that cause the motion. In addition, the vehicle motion model may include a dynamic model that considers the forces and torques acting on the vehicle (including factors such as tire-road interaction, suspension dynamics, aerodynamics, and vehicle mass distribution). The vehicle motion model may further include a state estimate of the current state (position, velocity, direction, etc.) of the vehicle involving sensor data such as GPS, IMU (Inertial Measurement Unit), wheel encoders, cameras, lidar, and radar.

[0070] The control circuit 11 is further configured to control the vehicle 1 based on the UUODD exit area 22 so as to reduce the likelihood of the vehicle 1 entering the high-risk state 21. In other words, once the UUODD exit area 22 is known, in the event that an unplanned ODD exit will occur within the UUODD exit area 22, the system 10 is able to perform some preventative measures to reduce the risk of the vehicle 1 ending up in the high-risk state 21.

[0071] Control of the vehicle 1 may be performed before the vehicle 1 enters the UUODD exit zone 22. In some embodiments, when the vehicle is expected to cross the UUODD exit zone 22, control of the vehicle is performed during a defined time window immediately preceding a subsequent time window. This time window is schematically indicated as the zone 20 preceding the UUODD exit zone 22. This serves to further illustrate the "preventive planning" aspect of the embodiments disclosed herein, where measures to reduce risk and thereby increase safety are performed before any adverse event occurs, rather than as a reaction to the occurrence of an adverse event.

[0072] In addition, the control circuit 11 can be configured to perform control of the vehicle within a precautionary planning area 20 located before the exit area 22. The precautionary planning area 20 can be based on a time window spanning from the current moment to k time steps forward (a time step can be defined as a fraction of a second or a second). The value of the parameter k can be based on vehicle capabilities, vehicle status, road and weather conditions. In other words, the value of the parameter k can depend on the ease of safely and comfortably controlling the vehicle.

[0073] In some embodiments, the control circuit 11 is configured to control the vehicle in various ways (so as to reduce the likelihood of the vehicle entering or ending up in a high risk state). Furthermore, control of the vehicle may depend on whether the ADS function is active.

[0074] In more detail, the control of the vehicle 1 may include the control circuit 11 being configured to, in response to the ADS function being currently deactivated, inhibit activation of the ADS function within the UUODD exit area 22. Thus, the ADS function cannot be activated within the UUODD exit area as it would not give any time to execute any precautionary planning as described herein.

[0075] In addition, the control of the vehicle 1 may include: the control circuit 11 is configured to update the trajectory of the vehicle 1 in response to the ADS function being currently activated. Accordingly, since the ADS function is activated, preventive planning can be performed before entering the UUODD exit area. Therefore, in some embodiments, preventive planning includes updating or otherwise switching the trajectory of the vehicle (switching the trajectory of the vehicle from its current trajectory) so as to reduce the possibility that the vehicle 1 enters the high-risk state 21 if the MRM is executed when the vehicle is in the UUODD exit area 22.

[0076] Moreover, the updating of the trajectory of the vehicle 1 may include controlling the lateral movement of the vehicle 1 and / or the speed of the vehicle 1 so as to reduce the likelihood that the vehicle 1 enters the high-risk state 21 if the MRM is executed while the vehicle is in the UUODD exit area 22. For example, the control of the lateral movement of the vehicle may include switching to an adjacent lane. Thus, the UUODD exit area 22 may be avoided entirely and the risk of the vehicle ending up in the high-risk state 21 is effectively reduced. When the vehicle 1 is crossing the UUODD exit area 22, a speed adjustment may be applied.

[0077] Furthermore, in some embodiments, control of the vehicle 1 may include: the control circuit 11 being configured to temporarily update the MRM configuration to a configuration different from the nominal MRM configuration in response to the ADS function being currently activated, so as to reduce the likelihood that the vehicle 1 will enter a high-risk state 21 if the MRM is executed while the vehicle is in the UUODD exit area 22. Once the vehicle has passed through the UUODD exit area, the MRM configuration may be returned to its nominal configuration accordingly. It goes without saying that these variations of "controlling the vehicle" may be combined in various ways when the ADS function is activated. For example, adjusting the speed of the vehicle and reconfiguring the MRM from the nominal configuration may result in a smaller adjustment of the speed and a smaller adjustment of the MRM configuration being sufficient than performing only one of the two.

[0078] also, Figure 3 is a schematic diagram of a vehicle 1 equipped with an ADS including a system 10 for preventive planning according to some embodiments. As used herein, a "vehicle" is any form of motorized transportation. For example, the vehicle 1 can be any road vehicle such as a car (as shown herein), a motorcycle, a (freight) truck, a bus, etc.

[0079] The system 10 includes a control circuit 11 and a memory 12. The control circuit 11 may physically include a single circuit device. Alternatively, the control circuit 11 may be distributed across several circuit devices. As an example, the system 10 may share its control circuit 11 with other parts of the vehicle 1 (e.g., the ADS 310). Moreover, the system 10 may form a part of the ADS 310, that is, the system 10 may be implemented as a module or feature of the ADS.

[0080] The control circuit 11 may include one or more processors such as a central processing unit (CPU), a microcontroller, or a microprocessor. The one or more processors may be configured to execute program code stored in the memory 12 so as to perform various functions and operations of the vehicle 1 in addition to the methods disclosed herein. The processor may be or include any number of hardware components for performing data or signal processing or for executing computer code stored in the memory 12. Optionally, the memory 12 includes a high-speed random access memory such as DRAM, SRAM, DDR RAM or other random access solid-state memory devices; and optionally includes non-volatile memory such as one or more magnetic disk storage devices, optical disk storage devices, flash memory devices or other non-volatile solid-state storage devices. The memory 12 may include a database component, an object code component, a script component, or any other type of information structure for supporting various actions of this specification.

[0081] In the illustrated example, the memory 12 further stores map data 308. The map data 308 may be used, for example, by the ADS 310 of the vehicle 1 in order to perform autonomous functions of the vehicle 1. The map data 308 may include high-definition (HD) map data. It is contemplated that even if the memory 12 is illustrated as an element separate from the ADS 310, it may be provided as an integrated / integrated element of the ADS 310. In other words, according to exemplary embodiments, in the implementation of the inventive concept, any distributed or local memory device may be utilized. Similarly, the control circuit 11 may be distributed, for example, so that one or more processors of the control circuit 11 are provided as an integrated / integrated element of the ADS 310 or any other system of the vehicle 1. In other words, according to exemplary embodiments, in the implementation of the inventive concept, any distributed or local control circuit device may be utilized. The ADS 310 is configured to perform functions and operations of autonomous or semi-autonomous functions of the vehicle 1. The ADS 310 may include a plurality of modules, wherein each module is responsible for a different function of the ADS 310.

[0082] The vehicle 1 includes a number of elements commonly found in autonomous or semi-autonomous vehicles. It will be appreciated that the vehicle 1 can have Figure 3 Any combination of the various elements shown in FIG. Moreover, the vehicle 1 may include Figure 3 Although various elements are shown herein as being located inside the vehicle 1, one or more elements can be located outside the vehicle 1. For example, map data can be stored in a remote server and accessed by various components of the vehicle 1 via the communication system 326. Furthermore, as will be readily appreciated by those skilled in the art, even though various elements are depicted herein in a particular arrangement, the various elements can be implemented in a different arrangement. It should be further noted that the various elements can be communicatively connected to each other in any suitable manner. Since the elements of the vehicle 1 can be implemented in several different ways, Figure 3 The vehicle 1 should be regarded as an illustrative example only.

[0083] The vehicle 1 further comprises a sensor system 320. The sensor system 320 is configured to acquire sensory data about the vehicle itself and / or its surroundings. The sensor system 320 may, for example, comprise a global navigation satellite system (GNSS) module 322 (such as GPS) configured to collect geographic location data of the vehicle 1. The sensor system 320 may further comprise one or more sensors 324. The sensor 324 may be any type of on-board sensor such as a camera, LIDAR and RADAR, an ultrasonic sensor, a gyroscope, an accelerometer, an odometer, etc. It should be understood that the sensor system 320 may also provide the possibility of acquiring sensory data directly or via a dedicated sensor control circuit in the vehicle 1.

[0084] The vehicle 1 further includes a communication system 326. The communication system 326 is configured to communicate with external units such as other vehicles (i.e., via a vehicle-to-vehicle (V2V) communication protocol), a remote server (e.g., a cloud server), a database, or other external devices (i.e., a vehicle-to-infrastructure (V2I) or a vehicle-to-everything (V2X) communication protocol). The communication system 326 can communicate using one or more communication technologies. The communication system 326 may include one or more antennas (not shown). Cellular communication technology can be used for remote communications such as to a remote server or a cloud computing system. In addition, if the cellular communication technology used has low latency, it can also be used for V2V communication, V2I communication, or V2X communication. Examples of cellular radio technologies are GSM, GPRS, EDGE, LTE, 5G, 5G NR, etc., also including future cellular solutions. However, in some solutions, medium- and short-range communication technologies such as wireless local area networks (LANs) (e.g., solutions based on IEEE 802.11) can be used to communicate with other vehicles in the vicinity of the vehicle 1 or with local infrastructure elements. ETSI is developing cellular standards for vehicular communications and 5G is considered a suitable solution due to low latency and efficient handling of high bandwidth and communication channels, for example.

[0085] The communication system 326 may accordingly provide the possibility to send outputs to a remote location (e.g. a remote operator or a control center) and / or to receive inputs from a remote location by means of one or more antennas. Moreover, the communication system 326 may be further configured to allow the various elements of the vehicle 1 to communicate with each other. As an example, the communication system may provide a local network setup such as CAN bus, I2C, Ethernet, fiber optics, etc. The local communication within the vehicle may also be of wireless type with protocols such as WiFi, LoRa, Zigbee, Bluetooth or similar medium / short range technologies.

[0086] The vehicle 1 further includes a steering system 320. The steering system 328 is configured to control the steering of the vehicle 1. The steering system 328 includes a steering module 330 configured to control the direction of the vehicle 1. The steering system 328 further includes a throttle module 332 configured to control the actuation of the throttle of the vehicle 1. The steering system 328 further includes a brake module 334 configured to control the actuation of the brakes of the vehicle 1. The various modules of the steering system 328 can also receive manual inputs from the driver of the vehicle 1 (i.e., from the steering wheel, the accelerator pedal, and the brake pedal, respectively). However, the steering system 328 can be communicatively connected to the ADS 310 of the vehicle to receive instructions on how the various modules of the steering system 328 should act. The steering system 328 can include information about the nominal MRM configuration of the vehicle 1. Therefore, the ADS 310 is able to control the steering of the vehicle 1, for example, via the decision and control module 318.

[0087] The ADS 310 may include a positioning module 312 or positioning block / system. The positioning module 312 is configured to determine and / or monitor the geographic location and orientation of the vehicle 1 and may utilize data from the sensor system 320, such as data from a GNSS module 322. Alternatively or in combination, the positioning module 312 may utilize data from one or more sensors 324. Alternatively, the positioning system may be implemented as a real-time kinematic (RTK) GPS for improved accuracy.

[0088] The ADS 310 may further include a perception module 314 or perception block / system 314. The perception module 314 may refer to any well-known module and / or function, such as included in one or more electronic control modules and / or nodes of the vehicle 1, adapted and / or configured to interpret sensory data related to driving of the vehicle 1 to identify, for example, obstacles, vehicle lanes, relevant signs, appropriate navigation paths, etc. Thus, the perception module 314 may be adapted to rely on and obtain input from a plurality of data sources, such as vehicle imaging, image processing, computer vision, and / or in-vehicle networking, in combination with, for example, sensory data from the sensor system 320.

[0089] The positioning module 312 and / or the perception module 314 may be communicatively connected to the sensor system 320 so as to receive sensor data from the sensor system 320. The positioning module 312 and / or the perception module 314 may further send control instructions to the sensor system 320. The ADS 310 may further include a path planning module 316 (which may also be in the form of a trajectory planning module) configured to output candidate paths (or candidate trajectories) for execution by the ADS. The candidate paths or trajectories may be provided to a decision and control module 318 of the ADS 310 for execution. Moreover, the control circuit 11 may be configured to retrieve the current trajectory of the vehicle 1 from the trajectory planning module or the path planning module 316.

[0090] The present technology has been presented above with reference to specific embodiments. However, other embodiments than those described above are possible and are within the scope of the defined claims. Within the scope of the embodiments disclosed herein, method steps different from the above method steps may be provided for performing the method by hardware or software. Therefore, according to some embodiments, a (non-transitory) computer-readable storage medium is provided, which stores one or more programs, the one or more programs being configured to be executed by one or more processors of a computing device, the one or more programs including instructions for performing a method according to any one of the embodiments discussed above. Alternatively, according to another exemplary embodiment, a cloud computing system can be configured to perform any one of the methods presented herein. The cloud computing system may include distributed cloud computing resources that jointly perform the methods presented herein under the control of one or more computer program products.

[0091] Processor 11 (associated with system 10) can be or include any number of hardware components for performing data or signal processing or for executing computer code stored in memory 12. Device 10 has associated memory 12, and memory 12 can be one or more devices for storing data and / or computer code for completing or facilitating the various methods described in this specification. The memory may include volatile memory or non-volatile memory. Memory 12 may include database components, object code components, script components, or any other type of information structure for supporting various actions of this specification. According to an exemplary embodiment, any distributed or local memory device can be used with the system and method of this specification. According to an exemplary embodiment, memory 12 (e.g., via circuit or any other wired, wireless or network connection) is communicatively connected to processor 11 and includes computer code for performing one or more processes described herein.

[0092] It should be noted that any reference signs do not limit the scope of the claims, that the present invention may be implemented at least partially by means of both hardware and software, and that several "tools" or "units" may be represented by the same item of hardware.

[0093] Although the drawings may show a specific order of method steps, the order of the steps may be different from the order depicted. In addition, two or more steps may be performed simultaneously or partially concurrently. This variation will depend on the selected software and hardware systems and designer selections. All these variations are within the scope of the defined claims. Similarly, software implementations may be accomplished using standard programming techniques with rule-based logic and other logic to accomplish various acquisition steps, control steps, prohibition steps, and update steps. The embodiments mentioned and described above are given as examples only and should not be limited to the present invention. Other solutions, uses, objectives, and functions within the scope of the present invention as claimed in the described patent claims should be apparent to those skilled in the art.

Claims

1. A computer-implemented method (S100) for preventive planning of a vehicle having an automated driving system ADS function, the ADS function having an operational design domain ODD, the method comprising: obtaining (S101) data including information about a high-risk state of the vehicle along a route to be traveled by the vehicle, wherein the high-risk state is defined based on a geographic area along the route to be traveled and a set of potential states of the vehicle within the geographic area; Based on the current trajectory of the vehicle and a nominal minimum risk maneuver (MRM) configuration of the vehicle, obtaining (S102) data including information about an undesirable unexpected ODD UUODD exit zone along the route to be traveled by the vehicle, wherein the UUODD exit zone is defined based on a likelihood that the vehicle will enter the high risk state in response to the MRM being executed while the vehicle is in the UUODD exit zone; and The vehicle is controlled ( S103 ) based on the UUODD exit area so as to reduce the possibility that the vehicle enters the high-risk state.

2. The method (S100) according to claim 1, wherein: Controlling (S103) the vehicle includes: In response to the ADS function being currently deactivated, activation of the ADS function within the UUODD exit area is prohibited ( S104 ).

3. The method (S100) according to claim 1, wherein: Controlling (S103) the vehicle includes: In response to the ADS function being currently activated, the trajectory of the vehicle is updated ( S105 ) so as to reduce the possibility that the vehicle will enter the high-risk state if the MRM is executed while the vehicle is in the UUODD exit area.

4. The method (S100) according to claim 3, wherein: Updating (S105) the trajectory of the vehicle includes: The lateral movement of the vehicle is controlled (S106) so as to reduce the possibility that the vehicle will enter the high-risk state if the MRM is executed while the vehicle is in the UUODD exit area.

5. The method (S100) according to any one of claims 3 and 4, wherein: Updating (S105) the trajectory of the vehicle includes: The speed of the vehicle is controlled (S107) so as to reduce the possibility that the vehicle will enter the high-risk state if the MRM is executed while the vehicle is in the UUODD exit area.

6. The method (S100) according to claim 1, wherein: Controlling (S103) the vehicle includes: In response to the ADS function being currently activated, the MRM configuration is temporarily updated (S108) to a configuration different from a nominal MRM configuration so as to reduce the possibility that the vehicle enters the high-risk state if the MRM is executed while the vehicle is in the UUODD exit area.

7. The method (S100) according to claim 1, wherein: The geographical area is a predefined geographical area on a digital map accessible by the ADS function.

8. The method (S100) according to claim 1, wherein: Before the vehicle enters the UUODD exit area, the control of the vehicle is performed ( S103 ).

9. The method (S100) according to claim 8, wherein: When the vehicle is expected to cross the UUODD exit area, the control of the vehicle is performed during a defined time window immediately before a subsequent time window (S103).

10. A computer program product comprising instructions which, when executed by a computing device, cause the computing device to perform the method (S100) according to claim 1.

11. A non-transitory computer-readable storage medium storing instructions, which, when executed by a computing device, cause the computing device to perform the method (S100) according to claim 1.

12. A system (10) for preventive planning of a vehicle (1) having an automated driving system (ADS) function, the ADS function having an operational design domain (ODD), the system (10) comprising a control circuit (11), the control circuit (11) being configured to: Data comprising information about a high risk state (21) of the vehicle (1) along a route to be traveled by the vehicle is obtained, wherein: The high risk state is defined based on a geographic area (23) along the route to be traveled and a set of potential states (24) of the vehicle within the geographic area (23); obtaining data including information about undesired unexpected ODD (UUODD) exit zones (22) along the route to be traveled by the vehicle (1) based on the vehicle's current trajectory and a nominal minimum risk maneuver (MRM) configuration for the vehicle, wherein the unplanned ODD exit zones (22) are defined based on a likelihood that the vehicle will enter the high risk state (21) in response to the MRM being executed while the vehicle is in the UUODD exit zones; and The vehicle (1) is controlled based on the UUODD exit zone (22) so as to reduce the possibility of the vehicle (1) entering the high-risk state (21).

13. The system (10) of claim 12, wherein: The control circuit (11) is configured to control the vehicle (1) in the following manner: In response to the ADS function being currently deactivated, activation of the ADS function within the UUODD exit area (22) is prohibited.

14. The system (10) of claim 12, wherein: The control circuit (11) is configured to control the vehicle (1) in the following manner: In response to the ADS function being currently activated, the trajectory of the vehicle is updated to reduce the likelihood that the vehicle will enter the high risk state (21) if the MRM is executed while the vehicle is in the UUODD exit zone (22).

15. A vehicle (1) comprising: A system (10) according to any one of claims 12 to 14.