Method and system for operating at least partially automated motor vehicle in infrastructure environment
By using random codes and human-readable tasks in the automated valet parking system, the problem of not needing manual reset after system failure is solved, achieving efficient automated operation and reliability.
Patent Information
- Application Number
- CN202510820462.6
- Authority / Receiving Office
- CN · China
- Patent Type
- Applications(China)
- Current Assignee / Owner
- Priority Date
- 2024-06-19
- Filing Date
- 2025-06-19
- Publication Date
- 2025-12-19
AI Technical Summary
Existing automated valet parking systems require manual reset in case of malfunction, leading to inconvenience and inefficiency.
The monitoring results are computed by at least two security servers running in parallel, and the system functionality is verified by generating random codes and human-readable tasks, allowing for remote reset without on-site manual operation.
It enables efficient automatic system reset in case of failure, avoiding manual intervention and improving system reliability and automation.
Smart Images

Figure CN121165698A_ABST
Abstract
Description
TECHNICAL FIELD
[0001] The present invention relates to a method and a system for operating at least partially automated motor vehicles in an infrastructure environment. The invention further relates to a computer program. BACKGROUND
[0002] In known methods or systems for "automatic valet parking" (AVP), a motor vehicle is safely guided from a first to a second position in a publicly accessible site without human intervention.
[0003] The publication DE 10 2012 222 562 Al discloses a system for a managed parking area for moving a motor vehicle from a starting position to a target position.
[0004] Infrastructure-based AVP systems are known. This means that the respective parking environment, for example a parking tower, is equipped with a highly networked distributed infrastructure system, which is responsible for environment perception, motor vehicle guidance, parking management, and safety. Compatible AVP motor vehicles are equipped with a communication interface for data exchange with the infrastructure system. This enables the guidance of the AVP motor vehicle and thus the remote guidance by the infrastructure system.
[0005] For communication with the end customer, the infrastructure is for example equipped with an interface to an AVP backend. Via this interface, data (in the form of messages) can be sent to and received from the infrastructure (AVP garage). A message can for example include a new parking space query or system diagnostic data.
[0006] On the one hand, the garage management server can now calculate non-safety-related functions, for example receiving / rejecting new parking space queries, path planning, motor vehicle management, parking space management, etc.
[0007] On the other hand, safety-related functions are calculated in parallel in a plurality of, for example two, safety servers. These servers can identify anomalies in the system by means of a monitoring function. The monitoring function result of each run can be sent by each safety server to the SPS (speicherprogrammierbare Steuerung, programmable logic controller). The SPS compares the results of the two safety servers and, if the results do not agree, triggers a fault flag. The fault identification leads to a partial system shutdown, which stops all active motor vehicles and does not allow further driving requests until the flag is manually reset by a qualified operator.
[0008] Only after the reset, a driving mission from an end customer can be started. This is not optimal, as the operator has to be inside the parking lot and has to physically access a manual reset device (e.g. a reset button) if necessary. Furthermore, such a reset can be necessary every time a new software version is deployed in the AVP garage.
[0009] CN 111775954 A discloses an emergency handling method for a failure of a parking service motor vehicle. The system inter alia comprises recognizing a functional failure and sending a failure message and a location of the parking space to a parking space manager, wherein the parking space manager then has to intervene manually.
[0010] KR 102560023 B1 discloses a self-diagnosis system for parking control, which enables automatic recovery and timely notification in case of failure and malfunction by monitoring a control network server.
[0011] KR 101817219 B1 discloses an automatic fault recognition system for a mechanical parking facility for quickly eliminating a fault in a mechanical parking facility, wherein the system inter alia comprises a programmable controller connected with each of the mechanical parking facilities, analyzing detected data input from sensors and outputting a fault signal to an external logic controller. SUMMARY
[0012] Therefore, the task of the present invention can be seen as providing a reliable and efficient method for operating at least partially automated motor vehicles in an infrastructure environment, in particular in a parking environment, wherein the operation is controlled and monitored by a system external to the vehicles. According to the present invention, inter alia, a manual reset in case of a fault can be avoided.
[0013] Another task of the present invention can be seen as providing a corresponding system for operating at least partially automated motor vehicles in an infrastructure environment, in particular in a parking environment, which has high efficiency and reliability.
[0014] According to a first aspect of the present invention, a method for operating at least partially automated motor vehicles in an infrastructure environment, in particular in a parking environment, is proposed. The operation is controlled and monitored by a system external to the vehicles. Herein, the method at least comprises the following steps:
[0015] • Computing, by at least two safety servers running in parallel, a monitoring result of safety-relevant functions of the system and forwarding the monitoring result to a control unit. The control unit compares the monitoring results. In case the monitoring results do not agree, a fault report is triggered, shutting down the system at least partially and in particular stopping the at least partially automated motor vehicle.
[0016] • generating a random code by the control unit and storing the generated random code;
[0017] • calling the random code by the security server;
[0018] • generating a human-readable task by means of the random code and passing the task to an operator of the infrastructure environment; and
[0019] • inputting a solution of the task by the operator and passing it to the security server, and forwarding a result calculated in the security server by means of the solution to the control unit;
[0020] Here, the "human-readable task" is understood as an instruction which allows a human operator to transform a predetermined information, for example a numerical value or a sequence of numerical values, into another information in a defined and unambiguous manner. The other information represents a solution of the task. Here, preferably simple calculation rules are used.
[0021] Now, for each of the security servers, the result calculated by the respective security server is compared by the control unit with the answer calculated by means of the random code.
[0022] In case all results coincide with the answer calculated by means of the random code, the system resumes the operation of the at least partially automated motor vehicle in the infrastructure environment.
[0023] In case at least one result does not coincide with the answer calculated by means of the random code, the system remains switched off.
[0024] By means of the method according to the first aspect, it can be efficiently checked whether the system is working faultlessly and can resume operation after a fault without the need for manual input on site. This is achieved by generating a random code and a human-readable task based on the random code. By comparing the solution of the task sent by the operator of the infrastructure environment, for example from a remote backend, to the security server and independently by each security server with the result calculated in the respective security server itself, the functionality of the security servers can be verified and the system can be reset and restarted without the need for manual reset on site.
[0025] In a preferred embodiment, generating a human-readable task by means of the random code comprises formulating a calculation task, wherein the random code shall be changed based on the calculation task. For this purpose, the random code can be constructed as a numerical value or converted into a numerical value, in particular a decimal numerical value. The task can for example comprise an instruction to perform a defined calculation operation on the random code or the numerical value.
[0026] The random code can in particular comprise a numerical sequence or be converted into a numerical sequence to produce a human-readable task. The computational task can be related to the numerical sequence.
[0027] In one example, the computational task can comprise processing each individual number of the numerical sequence in a defined manner and / or performing a computational operation on each number of the numerical sequence and / or correlating all and / or determined numbers of the numerical sequence with each other by means of a computational rule.
[0028] The solution can be a solution value (for example the sum of all numbers of the numerical sequence) or can be a solution numerical sequence (for example a numerical sequence in which each number is increased by a value n relative to the original numerical sequence).
[0029] In this way, a task is advantageously produced which is particularly fast and intuitively solvable, which provides a solution which can be compared particularly efficiently with the result of the secure server.
[0030] In a preferred embodiment, in the event of a discrepancy between the result and the answer calculated by means of the random code, a new task and / or a new random code is generated and passed to the operator of the infrastructure environment. The number of failed attempts can be limited (for example to 10 attempts), so that a manual reset is required after the limit has been reached.
[0031] According to a second aspect, a system for operating at least partially automated motor vehicles in an infrastructure environment, in particular in a parking environment, is proposed. The operation is carried out here in accordance with the method according to the first aspect, wherein the operation is controlled and monitored by the system. The system comprises:
[0032] • a control unit;
[0033] • at least two secure servers running in parallel, which are each configured to calculate a monitoring result for a safety-relevant function of the system and to forward the monitoring result to the control unit.
[0034] The control unit is configured to compare the monitoring results and, in the event of a discrepancy between the monitoring results, to trigger a fault report, so that the system is at least partially shut down and in particular the at least partially automated motor vehicle is brought to a standstill.
[0035] Furthermore, the control unit is configured to generate a random code. The generated random code can be saved, for example, in the at least two secure servers. Alternatively, the control unit can save the generated random code internally in a storage area which can be read by the servers.
[0036] The secure servers are each configured to produce a human-readable task by means of the random code and to pass the task to the operator of the infrastructure environment.
[0037] Furthermore, the security servers are each configured to receive an input of a solution to the task by a runner and to pass a result calculated with the solution to the control unit.
[0038] The control unit is configured to compare, for each security server, the result calculated by the respective security server with the answer calculated with the random code.
[0039] In the case that all results coincide with the answer calculated with the random code, the system can resume operation of the at least partially automated motor vehicle in the infrastructure environment.
[0040] In the case that at least one result does not coincide with the answer calculated with the random code, the system remains switched off.
[0041] The system can be configured as an AVP system for a parking environment, in particular. To this end, the system has, in particular, an AVP backend which is configured, in particular, remote from the parking environment. Furthermore, the system has, in particular, an infrastructure system which is configured within the parking environment, comprising a parking lot management server, at least two independent security servers, a control unit, an environmental sensor device and a communication infrastructure for transmitting data to and / or receiving data from the at least partially automated motor vehicle and / or from the AVP backend, and optionally a device for manually resetting the system, for example a reset button.
[0042] The AVP backend can be configured, in particular, to receive the human-readable task as a runner of the infrastructure environment and to receive and pass the solution to the control unit.
[0043] The control unit can be configured, in particular, as a programmable logic controller (SPS). Alternatively, the control unit can be configured as a pure software module, for example implemented on a central computing unit.
[0044] According to a third aspect, a computer program is proposed, comprising instructions which, when the computer program is implemented by a computer, cause the computer to implement a method according to the first aspect.
[0045] According to a fourth aspect, a machine-readable storage medium is proposed, having stored thereon a computer program according to the third aspect.
[0046] The expression "at least partially automated" includes one or more of the following cases: motor vehicle is guided with assistance, motor vehicle is guided partially automatically, motor vehicle is guided highly automatically, motor vehicle is guided fully automatically.
[0047] "Assisted guidance" means that the driver of the motor vehicle continuously carries out either longitudinal guidance or lateral guidance of the motor vehicle. The other driving task, i.e. either longitudinal guidance or lateral guidance of the motor vehicle, is carried out automatically. That is, either the longitudinal guidance or the lateral guidance is automatically controlled in the case of assisted guidance of the motor vehicle.
[0048] "Partially automated guidance" means that, under certain conditions (e.g. driving on a motorway, driving in a parking lot, overtaking an object, driving in a lane determined by lane markings) and / or for a certain period of time, the longitudinal guidance and the lateral guidance of the motor vehicle are automatically controlled. The driver of the motor vehicle does not have to manually control the longitudinal guidance and the lateral guidance of the motor vehicle himself. However, the driver has to continuously monitor the automatic control of the longitudinal guidance and the lateral guidance in order to be able to intervene manually if necessary. The driver has to be ready at all times to take over the guidance of the motor vehicle completely.
[0049] "Highly automated guidance" means that, under certain conditions (e.g. driving on a motorway, driving in a parking lot, overtaking an object, driving in a lane determined by lane markings) and / or for a certain period of time, the longitudinal guidance and the lateral guidance of the motor vehicle are automatically controlled. The driver of the motor vehicle does not have to manually control the longitudinal guidance and the lateral guidance of the motor vehicle himself. The driver does not have to continuously monitor the automatic control of the longitudinal guidance and the lateral guidance in order to be able to intervene manually if necessary. A take-over request is automatically output to the driver to take over the control of the longitudinal guidance and the lateral guidance, in particular with sufficient time margin, if necessary. That is, the driver has to be potentially able to take over the control of the longitudinal guidance and the lateral guidance. The boundaries of the automatic control of the lateral guidance and the longitudinal guidance are automatically identified. It is not possible to automatically achieve a state of minimum risk in every initial situation when highly automated guidance is used.
[0050] "Fully automated guidance" means that, under certain conditions (e.g. driving on a motorway, driving in a parking lot, overtaking an object, driving in a lane determined by lane markings), the longitudinal guidance and the lateral guidance of the motor vehicle are automatically controlled. The driver of the motor vehicle does not have to manually control the longitudinal guidance and the lateral guidance of the motor vehicle himself. The driver does not have to monitor the automatic control of the longitudinal guidance and the lateral guidance in order to be able to intervene manually if necessary. A request is automatically output to the driver to take over the driving task (control of the longitudinal guidance and the lateral guidance of the motor vehicle) before the automatic control of the lateral guidance and the longitudinal guidance is terminated, in particular with sufficient time margin. If the driver does not take over the driving task, the system is automatically returned to a state of minimum risk. The boundaries of the automatic control of the lateral guidance and the longitudinal guidance are automatically identified. It is possible to automatically return to a state of minimum risk of the system in all situations.
[0051] “Driverless control or guidance” means that the longitudinal guidance and the lateral guidance of the motor vehicle are automatically controlled independently of the specific application situation (e.g. driving on a motorway, driving in a parking lot, overtaking an object, driving in a lane determined by lane markings). The driver of the motor vehicle does not have to manually control the longitudinal guidance and the lateral guidance of the motor vehicle himself. The driver does not have to monitor the automatic control of the longitudinal guidance and the lateral guidance in order to be able to intervene manually if necessary. Thus, the longitudinal guidance and the lateral guidance of the motor vehicle are automatically controlled, for example, in all road types, speed ranges and environmental conditions. The entire driving task of the driver is thus taken over automatically. The driver is therefore no longer needed. That is, the motor vehicle can be driven from an arbitrary starting position to an arbitrary target position even without a driver. Potential problems are automatically solved without the help of a driver.
[0052] “Remote control of the motor vehicle” means that the lateral guidance and the longitudinal guidance of the motor vehicle are remotely controlled. For example, this means that remote control signals for remotely controlling the lateral guidance and the longitudinal guidance are transmitted to the motor vehicle. Remote control is carried out, for example, by means of a remote control device.
[0053] The abbreviation “AVP” stands for “Automated Valet Parking” and can be translated into German as “automatischer Parkservice”. For example, an AVP process comprises the at least highly automated guidance of the motor vehicle from a drop-off area (also called delivery location) to a parking location and, for example, the at least highly automated guidance of the motor vehicle from the parking location to a pick-up location (also called pick-up area). At the delivery location, i.e. the drop-off area, the driver of the motor vehicle delivers the motor vehicle for the AVP process. At the pick-up location, i.e. the pick-up area, the motor vehicle is picked up after the AVP process. The AVP process thus begins, in particular, at the drop-off area. The AVP process thus ends, in particular, at the pick-up area.
[0054] The motor vehicle can be designed as an AVP vehicle, in particular. An AVP vehicle is a motor vehicle that can participate in an AVP process.
[0055] The AVP process can be an AVP process according to one of the following AVP types: AVP type 1, AVP type 2 and AVP type 3. However, the AVP type can also change within an AVP process. This means, for example, that one part of the AVP process is carried out according to AVP type 1 and another part of the AVP process is carried out according to AVP type 2 or AVP type 3. This means, for example, that the AVP process can be divided into sub- AVP processes, which are carried out according to one of the AVP types 1, 2 and 3, respectively.
[0056] AVP type 1 means a motor vehicle centric AVP process. The main responsibility of this AVP process lies with the motor vehicle.
[0057] AVP type 2 means an infrastructure centric AVP process. The main responsibility of this AVP process lies with the infrastructure, i.e. the AVP system.
[0058] AVP type 3 means a motor vehicle-infrastructure shared AVP process. Here, the main responsibility of this AVP process is shared between the motor vehicle and the AVP system.
[0059] An AVP process comprises the following processes or functions:
[0060] 1. Determining a target position within the parking area for the motor vehicle.
[0061] 2. Planning a route from a starting position comprised by the parking area to the target position.
[0062] 3. Detecting objects and / or events and responding to the detected objects and / or detected events accordingly.
[0063] 4. Positioning the motor vehicle within the parking area.
[0064] 5. Calculating a desired trajectory of the motor vehicle based on the planned route.
[0065] 6. Controlling lateral guidance and longitudinal guidance of the motor vehicle based on the calculated desired trajectory.
[0066] The following table illustrates a correspondence, i.e. which of these processes or functions are executed by the motor vehicle or by the AVP system on the infrastructure side, depending on the AVP type, wherein "I" stands for "infrastructure", i.e. the AVP system on the infrastructure side, and "K" stands for "motor vehicle", so that "I" means that the process is executed by the AVP system and "K" means that the process is executed by the motor vehicle:
[0067]
[0068] Therefore, in the table above it is specified for each function for each AVP type: whether the function is executed by the infrastructure, i.e. by the AVP system on the infrastructure side, or by the motor vehicle. In some cases, it can be provided that the function is implemented both by the AVP system and by the motor vehicle.
[0069] In the case of object detection and event detection for AVP type 1, it can optionally be provided that the function is implemented by the AVP system of the infrastructure in addition to the motor vehicle.
[0070] The AVP types 1, 2 and 3 explained here are further described in ISO 23374. BRIEF DESCRIPTION OF DRAWINGS
[0071] The embodiments of the present application are described in detail below with reference to the attached drawing figures, wherein the same elements are denoted by the same reference numerals.
[0072] Figure 1 A system for operating an at least partially automated motor vehicle configured as an AVP system is shown according to one embodiment of the present application.
[0073] Figure 2 A timing of the information flow in the system of Figure 1 is shown.
[0074] Figure 3 A flow chart of a method according to one possible embodiment of the present application is shown.
[0075] Figure 4 A machine readable storage medium is shown. DETAILED DESCRIPTION
[0076] In the following description of embodiments of the present application identical elements are denoted by identical reference numerals, wherein a repeated description of these elements is omitted, if necessary. The drawings show the subject matter of the present application only schematically.
[0077] Figure 1 A system for operating an at least partially automated motor vehicle configured as an AVP system 10 is shown schematically and simplified, wherein the motor vehicle is configured as an AVP vehicle 60 in this example. The AVP system 10 comprises an AVP backend 30, a parking management server 22, two security servers 24, 26 and a control unit configured as an SPS 28. Further, the AVP system 10 comprises environmental sensors 40, e.g. video cameras and / or laser radar sensors, and one or more access points 50 via which the AVP vehicle 60 can communicate with the AVP system 10. In addition, a manually operated element 29 is provided with which the system 10 can be reset. The AVP backend 30 can be configured or arranged spatially remote from a parking infrastructure 20 operated by means of the AVP system 10. The parking management server 22, the security servers 24, 26 and the SPS 28, the environmental sensors 40 and the access points 50 and the manually operated element 29 can be configured or arranged spatially within the parking infrastructure 20 operated by means of the AVP system 10. The data connections between the different components, which are indicated by arrows in the figures, can be implemented wired or wirelessly and, for example, realize known network protocols or data transmission standards. Figure 1 The communication between the different components shown in Fig. is preferably encrypted using state-of-the-art algorithms.
[0078] The security servers 24 and 26 are each configured to compute a result of a monitoring of a security related function of the AVP system 10 and can forward the result of the monitoring to the SPS 28. The SPS 28 is configured to compare the results of the monitoring and to trigger a fault report in case the results of the monitoring do not agree, thereby shutting down the AVP system 10 at least partially and stopping the AVP vehicle 60.
[0079] The SPS 28 is configured to generate a random code and to store the generated random code in a storage area which is read by both security servers 24, 26. The security servers 24, 26 are each configured to generate a human readable task by means of the random code and to pass the task to the AVP backend 30 and, in turn, to the operator of the infrastructure environment. The security servers 24, 26 can each receive an input of a solution of the task from the AVP backend 30 and pass a result computed by means of the solution to the SPS 28.
[0080] Now, the SPS 28 can compare the result computed by the respective security server 24 or 26 with the answer computed by means of the random code for each security server 24, 26, wherein, in case both results agree with the answer computed by means of the random code, the AVP system resumes operation of the AVP vehicle 60 in the infrastructure environment 20 and wherein, in case at least one result does not agree with the answer computed by means of the random code, the AVP system 10 remains shut down.
[0081] Figure 2 A timing of the information flow between the different components of the system 10 according to Figure 1 is shown. The time axis t extends downwards in the illustration.
[0082] In event 212, the SPS 28 determines an anomaly while monitoring the security functions and triggers an internal fault state, e.g. by setting a respective flag. This leads to an interruption of the operation of the AVP vehicle 60 by the AVP system.
[0083] Now, the SPS generates a random code and sends the random code to both security servers 24, 26 in event 214.
[0084] In event 216, both security servers 24, 26 generate the same human readable task by means of the random code.
[0085] In 218, the security servers 24, 26 send the human readable task to the parking management server 22.
[0086] In 220, the parking management server 22 sends the human-readable task to the AVP backend 30 (e.g. remotely constructed).
[0087] In 222, the AVP backend obtains (e.g. operator's) input or answer corresponding to the solution of the human-readable task.
[0088] In 224, the AVP backend 30 sends the solution to the parking management server 22.
[0089] In 226, the parking management server 22 sends the solution to each of the security servers 24, 26.
[0090] In 228, each of the security servers 24, 26 computes a result, e.g. an inverse transformation, with the solution and the human-readable task.
[0091] In 230, the two security servers 24, 26 send their respective results to the SPS 28.
[0092] In 232, the SPS 28 compares the results with the random code or with the answer computed with the random code. In case all results are identical, the fault state is resolved.
[0093] Figure 3 A possible flow of the method according to the first aspect is described.
[0094] In step 310, the SPS 28 recognizes that there is an anomaly and terminates the operation of the AVP system 10. The SPS 28 generates a random code, in particular a randomly generated number, and stores it in a storage block that can be read by both security servers 24, 26, respectively.
[0095] In step 312, the security servers 24, 26 read the random code from the respective storage block of the SPS 28 (the storage address is statically assigned here).
[0096] In step 314, the security servers 24, 26 respectively convert the random code into a human readable task. For example, the random code can be in the form of a hexadecimal value (e.g. 0x2f485a7149b9). The human readable task can for example comprise a sequence of digits in the decimal system or a decimal value derived from the random code (e.g. "5 1 9 8 7 8 0 1 5 2 4 6 65"). This can for example be transmitted in the form of a string which is generated by converting the random code (hexadecimal value) into the decimal system and by adding a space between each digit. In addition, the human readable task comprises an indication for changing or converting the derived sequence of digits. For this purpose, a written indication for the human operator is generated and transmitted together with the string representing the sequence of digits. (e.g. "add one to each digit." or "what is the sum of all digits?" or "multiply each digit by 2" etc.).
[0097] In step 316, the security servers 24, 26 respectively transmit the human readable task, especially via the garage management server 22, to the AVP backend 30.
[0098] In step 318, the AVP backend 30 presents the human readable task to the runner and obtains an input as an answer. For example, the human operator can input the answer via a backend dashboard.
[0099] In step 320, the AVP backend 30 sends the runner answer to the parking management server 22. The parking management server 22 passes the runner answer to both security servers 24, 26.
[0100] In step 322, the security servers 24, 26 respectively receive the operator's answer via the parking management server 22 and perform the conversion (reverse calculation) and generate a result respectively. For example, if the human readable task is: "for the sequence of digits '51 9 8 7 8 0 1 5 2 4 6 6 5', add one to each digit", then one is added to each digit from the answer and the result is converted to its equivalent hexadecimal value.
[0101] In step 324, the security servers respectively send the result of this conversion to the SPS. For example as follows:
[0102] • result = operator answer (hexadecimal) XOR 0x00ffffffffffffffffff
[0103] In step 326, the SPS checks the obtained result for each by comparing it to the original random code or to the answer calculated with the help of the random code.
[0104] If the results of both security servers 24, 26 are consistent with the answer calculated with the help of the random code and no other failure conditions exist, then in step 328 the system 10 resumes the at least partially automated operation of the motor vehicle 60 in the infrastructure environment 20. The system 10 transitions again into normal operation. The results can be considered consistent, for example, if (in the example described above) :
[0105] • 0x000ffffffffffffff == result XOR random code
[0106] If the result of one or both security servers 24, 26 is not consistent with the answer calculated with the help of the random code, then according to step 330 the system remains switched off and a new random code can be generated or the task can be reissued.
[0107] The security SPS 28 can limit the maximum number of consecutive failed attempts to a predetermined value (for example 10). If all remaining attempts are implemented unsuccessfully, the security SPS 28 no longer generates a new random code or task. The security SPS 28 can then no longer be remotely reset (for example with the help of the manual operating element 29).
[0108] Figure 4 A machine-readable storage medium 301 is shown, on which a computer program 303 is stored. The computer program 303 comprises instructions which, when the computer program 303 is implemented by a computer, cause the computer to implement a method according to the first aspect.
Claims
1. A method for operating at least partially automated motor vehicles (60) in an infrastructure environment (20), particularly in a parking environment, wherein, The operation is controlled and monitored by a system (10) outside the vehicle, and the method includes at least the following steps: • The monitoring results of the security-related functions of the system (10) are calculated by at least two security servers (24, 26) running in parallel, and the monitoring results are forwarded to the control unit (28), wherein the control unit (28) compares the monitoring results and triggers a fault report if the monitoring results are inconsistent, thereby at least partially shutting down the system (10) and, in particular, stopping the at least partially automated motor vehicle (60). • The control unit (28) generates and stores a random code; The random code is invoked by the security servers (24, 26); • Using the random code to generate human-readable tasks and passing the tasks to the operator of the infrastructure environment (30); and • The operator inputs a solution to the task and passes it to the security server (24, 26), and forwards the result calculated by the security server (24, 26) with the help of the solution to the control unit (28); • For each of the security servers (24, 26): the control unit (28) compares the result calculated by the corresponding security server (24, 26) with the answer calculated using the random code. • Wherein, if all results are consistent with the answer calculated using the random code, the system (10) resumes the operation of the at least partially automated motor vehicle (60) in the infrastructure environment (20), and if at least one result is inconsistent with the answer calculated using the random code, the system (10) remains off.
2. The method according to claim 1, wherein, Generating human-readable tasks using the random code involves defining computational tasks, wherein the random code should be modified based on the computational tasks.
3. The method according to claim 2, wherein, The random code includes a numerical sequence or is converted into a numerical sequence to generate a human-readable task, wherein the computational task is related to the numerical sequence, and the solution is a solution value or a solution value sequence.
4. The method according to claim 3, wherein, The computational task includes manipulating each individual number of the numerical sequence in a defined manner and / or performing computational operations on each number of the numerical sequence and / or associating all and / or determined numbers of the numerical sequence with each other using computational rules.
5. The method according to any one of the preceding claims, wherein, If the result is inconsistent with the answer calculated using the random code, a new task and / or a new random code are generated and passed to the operator of the infrastructure environment.
6. A system (10) for operating at least partially automated motor vehicles (60) in an infrastructure environment (20), particularly in a parking environment, according to the method of any one of claims 1 to 5, wherein, The operation is controlled and monitored by the system (10), which includes: • Control unit (28); • At least two security servers (24, 26) running in parallel, each security server being configured to calculate monitoring results of security-related functions of the system (10) and forward the monitoring results to the control unit (28), wherein the control unit (28) is configured to compare the monitoring results and trigger a fault report in case the monitoring results are inconsistent, thereby at least partially shutting down the system (10), and in particular stopping the at least partially automated motor vehicle (60); • The control unit (28) is configured to generate and store random codes, wherein the generated random codes can be invoked by the security servers (24, 26); • The security servers (24, 26) are respectively configured to generate human-readable tasks using the random code and transmit the tasks to the operator (30) of the infrastructure environment (20). The system receives input from the operator (30) regarding a solution to the task and transmits the result calculated using the solution to the control unit (28). • The control unit (28) is configured to compare, for each security server (24, 26), the result calculated by the corresponding security server (24, 26) with the answer calculated using the random code. • Where all results are consistent with the answer calculated using the random code, the system (10) resumes the operation of the at least partially automated motor vehicle (60) in the infrastructure environment (20). • In cases where at least one result is inconsistent with the answer calculated using the random code, the system (10) remains off.
7. The system according to claim 6, wherein, The system (10) is configured as an AVP system for parking environments, the system having: As an operator, particularly an AVP backend (30) constructed away from the parking environment; and an infrastructure system constructed within the parking environment, the infrastructure system including a parking management server (22), at least two independent security servers (24, 26), a control unit (28), an environmental sensing device (40), and a communication infrastructure (50) for sending and / or receiving data to the at least partially automated motor vehicle (60) and / or to the AVP backend (30), and optionally including a device (29) for manually resetting the system.
8. The system according to claim 7, wherein, The AVP backend (30) is configured to act as the operator of the infrastructure environment to receive the human-readable task and the solution and pass it to the control unit (28).
9. The system according to any one of claims 6 to 8, wherein, The control unit (28) is configured as a programmable logic controller or as a software module.
10. A computer program (303) comprising instructions that, when executed by a computer, cause the computer to perform the method according to any one of claims 1 to 5.
11. A machine-readable storage medium (301) having a computer program (303) according to claim 10 stored thereon.
Citation Information
Patent Citations
Valet parking vehicle fault emergency processing method and system and automobile
CN111775954A
System for managing parking spaces in e.g. public park for transferring vehicle from start to target position, has central processing unit to generate speed control signals and pass to transfer unit for transmission to vehicle
DE102012222562A1
automatic fault sensing system for mechanical parking equipment using IOT apparatus
KR101817219B1
Parking control self-diagnosis system
KR102560023B1