Autonomous driving vehicle, server, and method executed by autonomous driving vehicle

By using sensors and a processor to detect and determine the emergency stopping area, the vehicle can be automatically stopped, solving the problem of determining the emergency stopping space for autonomous vehicles in emergency situations and improving the safety and reliability of autonomous driving.

CN121361452APending Publication Date: 2026-01-20HYUNDAI MOTOR CO LTD +2
View PDF 0 Cites 0 Cited by

Patent Information

Application Number
CN202510146469.4
Authority / Receiving Office
CN · China
Patent Type
Applications(China)
Current Assignee / Owner
Priority Date
2024-07-18
Filing Date
2025-02-10
Publication Date
2026-01-20

AI Technical Summary

Technical Problem

In emergency situations involving autonomous vehicles, existing technologies struggle to effectively determine the permissible emergency stopping space, potentially placing the vehicle in a dangerous situation.

Method used

By detecting the surrounding environment and status information of the vehicle through sensors, the processor determines the longitudinal and lateral lengths of the emergency stop zone and controls the vehicle to perform automatic parking. Taking into account fixed and dynamic obstacles, the processor dynamically adjusts the emergency stop zone to match the distance to the obstacles and uses information provided by the server to perform autonomous parking.

Benefits of technology

It enables the effective identification of emergency stopping areas during autonomous driving, reduces the risk of collisions, ensures safe vehicle parking, and improves the reliability and safety of autonomous driving.

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure CN121361452A_ABST
    Figure CN121361452A_ABST
Patent Text Reader

Abstract

The present disclosure relates to an autonomous driving vehicle, a server, and a method performed by the autonomous driving vehicle, the autonomous driving vehicle including: at least one sensor configured to detect a surrounding environment of the autonomous driving vehicle to generate surrounding environment information; a controller configured to control one or more operations of the autonomous driving vehicle; and a processor configured to: monitor a state of the autonomous driving vehicle to generate vehicle state information; determining, during autonomous driving of the autonomous driving vehicle, whether a minimum risk maneuver is required based on at least one of the surroundings information and the vehicle state information; and determining, based on the required minimum risk maneuver, an emergency stop area in which the autonomous driving vehicle can reach a full stop; and controlling, via the controller and based on the emergency stop area, the autonomous driving vehicle to perform automatic parking.
Need to check novelty before this filing date? Find Prior Art

Description

TECHNICAL FIELD

[0001] The present disclosure relates to a vehicle and a method of operating a vehicle, and more particularly, to autonomous valet parking. BACKGROUND

[0002] Recent technological developments in the field of vehicle automation have led to advanced driver assistance systems (ADAS) for driver assistance. ADAS includes multiple sub-classes of technology and provides convenience to the driver. ADAS systems are also referred to as autonomous driving or autonomous driving systems (ADS).

[0003] During autonomous driving of a vehicle, the autonomous driving system can experience a fault. If appropriate measures are not taken to address these issues, the vehicle can be placed in a dangerous situation. SUMMARY

[0004] One or more exemplary embodiments of the present disclosure aim to provide a vehicle capable of determining a permissible space for emergency stop during autonomous valet parking.

[0005] An exemplary embodiment of the present document aims to provide a method of operating a vehicle for determining a permissible space for emergency stop during autonomous valet parking.

[0006] The technical objects of the present document are not limited to the foregoing, and those skilled in the art can clearly understand other objects not described herein from the following description.

[0007] According to one or more exemplary embodiments of the present disclosure, an autonomous driving vehicle can include at least one sensor configured to detect a surrounding environment of the autonomous driving vehicle to generate surrounding environment information, a controller configured to control one or more operations of the autonomous driving vehicle, and a processor. The processor can be configured to monitor a state of the autonomous driving vehicle to generate vehicle state information, determine whether a minimum risk maneuver is required during autonomous driving of the autonomous driving vehicle based on at least one of the surrounding environment information and the vehicle state information, determine an emergency stop area in which the autonomous driving vehicle is able to reach a complete stop based on the required minimum risk maneuver, and control the autonomous driving vehicle to perform automatic parking via the controller and based on the emergency stop area. The emergency stop area can be further determined based on a speed of the autonomous driving vehicle, a time required for the autonomous driving vehicle to reach the complete stop, and whether there is an obstacle in a driving path of the autonomous driving vehicle.

[0008] The processor can be configured to determine the emergency stop area by determining a longitudinal length of the emergency stop area based on the speed of the autonomous driving vehicle and the time required for the autonomous driving vehicle to reach the complete stop.

[0009] The obstacle can be a fixed obstacle. The processor can be further configured to: determine whether there is an obstacle in the driving path of the autonomous vehicle; determine a distance between the fixed obstacle and a side of the emergency stop area closest to the autonomous vehicle; and update the emergency stop area by adjusting a longitudinal length of the emergency stop area to match the distance based on the longitudinal length of the emergency stop area being greater than the distance.

[0010] The processor can be configured to determine the emergency stop area by: determining a lateral length of the emergency stop area based on a width of the autonomous vehicle and a predetermined stopping distance constant.

[0011] The processor can be configured to determine the emergency stop area by: determining a lateral length of the emergency stop area based on a width of the autonomous vehicle and a predetermined maximum lane tolerance.

[0012] The obstacle can be a dynamic obstacle. The processor can be further configured to: determine whether there is an obstacle within the emergency stop area; determine a collision risk associated with the dynamic obstacle; and adjust a longitudinal length of the emergency stop area based on the collision risk.

[0013] The obstacle can be a dynamic obstacle. The processor can be further configured to: determine whether there is an obstacle within the emergency stop area; determine a distance between the dynamic obstacle and a side of the emergency stop area closest to the autonomous vehicle; and update the emergency stop area by adjusting a longitudinal length of the emergency stop area to match the distance based on the longitudinal length of the emergency stop area being greater than the distance.

[0014] The time required for the autonomous vehicle to reach a complete stop can be set to 3 seconds based on the speed of the autonomous vehicle being greater than 0 km / h and less than or equal to 10 km / h.

[0015] The time required for the autonomous vehicle to reach a complete stop can be set to 4 seconds based on the speed of the autonomous vehicle being greater than 10 km / h and less than or equal to 20 km / h.

[0016] The time required for the autonomous vehicle to reach a complete stop can be set to 5 seconds based on the speed of the autonomous vehicle being greater than 20 km / h and less than or equal to 30 km / h.

[0017] According to one or more example embodiments of the present disclosure, a server can include a communication interface configured to communicate with an autonomous vehicle, and a processor. The processor can be configured to receive vehicle state information of the autonomous vehicle from the autonomous vehicle, determine whether a minimum risk maneuver is required for the autonomous vehicle based on at least one of surrounding environment information of the autonomous vehicle and the vehicle state information, determine an emergency stop area in which the autonomous vehicle is able to reach a complete stop based on the required minimum risk maneuver, and cause the autonomous vehicle to perform an automatic parking based on the emergency stop area. The emergency stop area can be further determined based on a speed of the autonomous vehicle, a time required for the autonomous vehicle to reach the complete stop, and whether there is an obstacle in a driving path of the autonomous vehicle.

[0018] The processor can be configured to determine the emergency stop area by determining a longitudinal length of the emergency stop area based on the speed of the autonomous vehicle and the time required for the autonomous vehicle to reach the complete stop.

[0019] The obstacle can be a fixed obstacle. The processor can be further configured to determine whether there is an obstacle in the driving path of the autonomous vehicle, determine a distance between the fixed obstacle and a side of the emergency stop area closest to the autonomous vehicle, and update the emergency stop area by adjusting the longitudinal length of the emergency stop area to match the distance based on the longitudinal length of the emergency stop area being greater than the distance.

[0020] The processor can be configured to determine the emergency stop area by determining a lateral length of the emergency stop area based on a width of the autonomous vehicle and a predetermined stop distance constant.

[0021] The processor can be configured to determine the emergency stop area by determining a lateral length of the emergency stop area based on a width of the autonomous vehicle and a predetermined maximum lane tolerance.

[0022] The obstacle can be a dynamic obstacle. The processor can be further configured to determine whether there is an obstacle within the emergency stop area, determine a distance between the dynamic obstacle and a side of the emergency stop area closest to the autonomous vehicle, and update the emergency stop area by adjusting the longitudinal length of the emergency stop area to match the distance based on the longitudinal length of the emergency stop area being greater than the distance.

[0023] The processor can be further configured to determine whether there is another vehicle within the emergency stop area, and cause the other vehicle to move out of the emergency stop area.

[0024] The processor can be configured to cause the autonomous driving vehicle to perform automatic stopping by transmitting a first signal causing the autonomous driving vehicle to move into an emergency stopping area. The processor can be further configured to cause another vehicle to move to prevent the other vehicle from entering the emergency stopping area by transmitting a second signal causing the other vehicle to drive along a path that prevents the other vehicle from entering the emergency stopping area.

[0025] According to one or more example embodiments of the present disclosure, a method performed by an apparatus of an autonomous driving vehicle can include determining surrounding environment information of the autonomous driving vehicle by detecting, via one or more sensors, a surrounding environment of the autonomous driving vehicle; determining vehicle state information of the autonomous driving vehicle by monitoring a vehicle state of the autonomous driving vehicle; determining whether a minimum risk maneuver is required during autonomous driving of the autonomous driving vehicle based on at least one of the surrounding environment information and the vehicle state information; determining an emergency stopping area in which the autonomous driving vehicle is able to reach a complete stop based on the required minimum risk maneuver; and controlling the autonomous driving vehicle to perform automatic stopping based on the emergency stopping area. The emergency stopping area can be further determined based on a speed of the autonomous driving vehicle, a time required for the autonomous driving vehicle to reach the complete stop, and whether an obstacle exists in a driving path of the autonomous driving vehicle.

[0026] Determining the emergency stopping area can include determining a longitudinal length of the emergency stopping area based on the speed of the autonomous driving vehicle and the time required for the autonomous driving vehicle to reach the complete stop.

[0027] The obstacle can be a fixed obstacle. The method can further include determining whether an obstacle exists in a driving path of the autonomous driving vehicle; determining a distance between the fixed obstacle and a side of the emergency stopping area closest to the autonomous driving vehicle; and updating the emergency stopping area by adjusting a longitudinal length of the emergency stopping area to match the distance based on the longitudinal length of the emergency stopping area being greater than the distance.

[0028] Determining the emergency stopping area can include determining a lateral length of the emergency stopping area based on a width of the autonomous driving vehicle and a predetermined stopping distance constant.

[0029] Determining the emergency stopping area can include determining a lateral length of the emergency stopping area based on a width of the autonomous driving vehicle and a predetermined maximum lane tolerance.

[0030] The obstacle can be a dynamic obstacle. The method can further include determining whether an obstacle exists within the emergency stopping area; determining a collision risk associated with the dynamic obstacle; and adjusting a longitudinal length of the emergency stopping area based on the collision risk. BRIEF DESCRIPTION OF DRAWINGS

[0031] Figure 1 is a block diagram of a vehicle;

[0032] Figure 2 is a functional block diagram of a processor;

[0033] Figure 3 is a diagram illustrating a vehicle state-specific minimum risk maneuver (MRM) strategy;

[0034] Figure 4A and Figure 4B is a diagram illustrating how an MRM strategy is determined based on surrounding environment information within a specified MRC range of a vehicle;

[0035] Figure 5 is a diagram illustrating how a priority of an MRM strategy changes based on surrounding object information within a specified MRC range of a vehicle;

[0036] Figures 6A to 6C is a diagram illustrating how it is determined whether a collision with a surrounding vehicle occurs due to an MRM of a host vehicle;

[0037] Figure 7 is a diagram illustrating how an MRM strategy of a host vehicle is determined considering a collision risk with a surrounding vehicle;

[0038] Figure 8A and Figure 8B is a diagram illustrating how a distance between a host vehicle and a surrounding vehicle is calculated;

[0039] Figure 9 is a flowchart illustrating an operation of a vehicle;

[0040] Figure 10 is a flowchart illustrating an operation of a vehicle for determining an MRM strategy;

[0041] Figure 11 is a flowchart illustrating an operation of predicting an emergency stop allowance space and a collision risk during autonomous driving;

[0042] Figure 12 is a diagram illustrating an MRM strategy;

[0043] Figure 13 is a diagram illustrating how an emergency stop allowance space is predicted when a final MRM strategy is a lane-in stop type;

[0044] Figure 14 is a diagram illustrating how an emergency stop allowance space is predicted when a final MRM strategy is a straight stop type;

[0045] Figure 15 is a diagram illustrating how a collision risk is predicted when a final MRM strategy is a lane-in stop type; and

[0046] Figure 16is a graph illustrating how to predict a collision risk when the final MRM policy is a straight stop type. DETAILED DESCRIPTION

[0047] Hereinafter, one or more exemplary embodiments of the present disclosure are described in detail with reference to the accompanying drawings.

[0048] The organization and operation effects of the present disclosure will be apparent from the following detailed description provided below, thereby facilitating a clear understanding. Prior to the detailed description in the present document, it should be noted that the same reference numerals will be used for the same components as far as possible, even if shown on different drawings, and detailed description of well-known components will be omitted to avoid obscuring the subject matter of the present disclosure.

[0049] Prior to proceeding with the detailed description in the present document, the terms used herein can be defined as follows.

[0050] A vehicle refers to a vehicle equipped with an autonomous driving system (ADS) capable of autonomous driving. For example, the vehicle can perform at least one of steering, acceleration, deceleration, lane change, and stopping (or parking) without intervention of a driver of the ADS. The ADS may, for example, include at least one of a pedestrian detection and collision mitigation system (PDCMS), a lane change decision assistance system (LCDAS), a lane departure warning system (LDWS), an adaptive cruise control (ACC), a lane keeping assist system (LKAS), a road boundary departure prevention system (RBDPS), a curve speed warning system (CSWS), a forward vehicle collision warning system (FVCWS), and low-speed following (LSF).

[0051] A driver refers to a person who uses a vehicle and receives a service from an autonomous driving system.

[0052] A vehicle control authority refers to an authority to control at least one component and / or function of a vehicle. At least one function of the vehicle may, for example, include at least one of a steering function, an acceleration function, a deceleration function (or a braking function), a lane change function, a lane detection function, a lateral control function, an obstacle detection and distance sensing function, a powertrain control function, a safety zone detection function, an engine on / off function, a power on / off function, and a vehicle lock / unlock function. The listed vehicle functions are provided as examples for illustrative purposes, and the present disclosure is not limited thereto.

[0053] A shoulder refers to a space between an outermost road boundary (or a boundary of an outermost lane) in a traveling direction of a vehicle and a road edge (e.g., a curb, a guardrail).

[0054] According to the Society of Automotive Engineers (SAE), the level of automation of an autonomous vehicle can be classified as follows. At the autonomous driving level 0, the SAE classification criteria can correspond to “no automation,” in which the autonomous driving system is involved in emergency situations (e.g., automatic emergency braking) and / or provides warnings only (e.g., blind spot warnings, lane departure warnings, etc.), and the driver is expected to operate the vehicle. At the autonomous driving level 1, the SAE classification criteria can correspond to “driver assistance,” in which the system performs some driving functions (e.g., steering, acceleration, braking, lane centering, adaptive cruise control, etc.) when the driver is operating the vehicle in normal operating segments, and the driver is expected to determine the system’s operating status and / or timing, perform other driving functions, and handle (e.g., resolve) emergency situations. At the autonomous driving level 2, the SAE classification criteria can correspond to “partial automation,” in which the system performs steering, acceleration, and / or braking under the supervision of the driver, and the driver is expected to determine the system’s operating status and / or timing, perform other driving functions, and handle (e.g., resolve) emergency situations. At the autonomous driving level 3, the SAE classification criteria can correspond to “conditional automation,” in which the system drives the vehicle under limited conditions (e.g., performs driving functions such as steering, acceleration, and / or braking), but transfers driving control to the driver when the required conditions are not met, and the driver is expected to determine the system’s operating status and / or timing, and take control in emergency situations, but does not otherwise operate the vehicle (e.g., steering, acceleration, and / or braking). At the autonomous driving level 4, the SAE classification criteria can correspond to “high automation,” in which the system performs all driving functions, and the driver is expected to control the vehicle only in emergency situations. At the autonomous driving level 5, the SAE classification criteria can correspond to “full automation,” in which the system performs all driving functions without any assistance from the driver, including in emergency situations, and the driver is not expected to perform any driving functions other than determining the system’s operating status. While the present disclosure can apply the SAE classification criteria to autonomous driving classification, other classification methods and / or algorithms can also be used in one or more configurations described herein. One or more features associated with autonomous driving control can be activated based on a configured autonomous driving control setting (e.g., based on at least one of: an autonomous driving classification, a selection of an autonomous driving level of the vehicle, etc.).

[0055] Based on one or more features described herein (e.g., determining an emergency stop zone), the operation of the vehicle can be controlled. Vehicle control can include various operational controls associated with the vehicle (e.g., autonomous driving control, sensor control, braking control, braking time control, acceleration control, acceleration rate of change control, alert timing control, forward collision warning time control, etc.).

[0056] One or more auxiliary devices (e.g., engine brake, exhaust brake, hydraulic retarder, electric retarder, regenerative brake, etc.) can also be controlled, for example, based on one or more features described herein (e.g., determining an emergency stop zone). One or more communication devices (e.g., modems, network adapters, radio transceivers, antennas, etc. capable of communicating via one or more wired or wireless communication protocols such as Ethernet, Wi-Fi, near field communication (NFC), Bluetooth, long term evolution (LTE), 5G new radio (NR), vehicle-to-everything (V2X), etc.) can also be controlled, for example, based on one or more features described herein (e.g., determining an emergency stop zone).

[0057] A minimum risk maneuver (MRM) operation can also be controlled, for example, based on one or more features described herein (e.g., determining an emergency stop zone). A minimum risk maneuver operation (e.g., minimum risk maneuver) can be a maneuver operation of a vehicle for minimizing (e.g., reducing) a risk of collision with surrounding vehicles in order to reach a reduced (e.g., minimum) risk state. A minimum risk maneuver can be an operation activated during autonomous driving of the vehicle when the driver cannot respond to an intervention request. During the minimum risk maneuver, one or more processors of the vehicle can control driving operations of the vehicle for a set period of time.

[0058] A bias driving operation can also be controlled, for example, based on one or more features described herein (e.g., determining an emergency stop zone). The driving control device can perform bias driving control. To perform bias driving, the driving control device can control the vehicle to drive on a lane by maintaining a lateral distance between a location of a center of the vehicle and a center of the lane. For example, the driving control device can control the vehicle to stay in the lane but not in the center of the lane.

[0059] The driving control device can identify a bias target lateral distance for bias driving control. For example, the bias target lateral distance can include an intentionally adjusted lateral distance that the vehicle can aim to maintain from a reference point (such as a center of a lane or another vehicle) during a maneuver (such as a lane change). This adjustment can be made to improve stability, safety, and / or performance of the vehicle under varying driving conditions, etc. For example, during a lane change, the driving control system can bias the lateral distance to maintain a safer gap from a neighboring vehicle, taking into account factors such as speed of the vehicle, road conditions, and / or presence of obstacles, etc.

[0060] One or more sensors (e.g., IMU sensors, cameras, LIDAR, RADAR, blind spot monitoring sensors, lane departure warning sensors, parking sensors, light sensors, rain sensors, traction control sensors, anti-lock braking system sensors, tire pressure monitoring sensors, seatbelt sensors, airbag sensors, fuel sensors, emissions sensors, throttle position sensors, inverters, converters, motor controllers, power distribution units, high voltage wiring and connectors, auxiliary power modules, charging interfaces, etc.) can also be controlled, e.g., based on one or more features described herein (e.g., determining an emergency stop zone).

[0061] Operational controls for autonomous driving of a vehicle can include various driving controls of the vehicle (e.g., acceleration, deceleration, steering control, shift control, brake system control, traction control, stability control, cruise control, lane keep assist control, collision avoidance system control, emergency brake assist control, traffic sign recognition control, adaptive headlight control, etc.) by the vehicle control device.

[0062] Figure 1 is a block diagram of a vehicle. Figure 1 The configuration of the vehicle is depicted in and each component can be configured as one chip, one component, or one electronic circuit, or a combination of chips, components, and / or electronic circuits. Figure 1 Some components shown can be divided into multiple components and configured as different chips, different components, or different electronic circuits, and some components can be combined to be configured as one chip, one component, or one electronic circuit. Some components shown can be omitted, or other components not shown can be added. Figure 1 Some components shown can be omitted, or other components not shown can be added. Figures 2 to 8B described Figure 1 at least some components in Figure 2 is a functional block diagram of a processor, and Figure 3 is a diagram showing a minimum risk maneuver (MRM) strategy specific to a vehicle state. Figure 4A and Figure 4B are diagrams showing how to determine an MRM strategy based on surrounding environment information within a specified MRC range of a vehicle, and Figure 5 is a diagram showing how the priority of an MRM strategy changes based on surrounding object information within a specified MRC range of a vehicle. Figures 6A to 6C is a diagram showing how to determine whether a collision with a surrounding vehicle occurs due to an MRM of a host vehicle, and Figure 7 is a diagram showing how to determine an MRM strategy of a host vehicle considering a collision risk with a surrounding vehicle. Figure 8A and Figure 8B are diagrams showing how to calculate a distance between a host vehicle and a surrounding vehicle.

[0063] ReferenceFigure 1 The autonomous valet parking server (also referred to as an autonomous parking server) 50 can include a processor 51, a storage unit 53, and a communication device 55. The communication device 55 (also referred to as a communication interface, a communicator, a communication module, a communication unit, etc.) can allow software and / or data to be transmitted between the device and one or more external devices, and / or between one or more components of the device. The communication device 55 can include a receiver, a transmitter, a transceiver, a modem, a network interface and / or adapter (such as an Ethernet adapter), a radio transceiver, an antenna, a communication port, a Personal Computer Memory Card International Association (PCMCIA) slot and card, etc. The software and data transmitted via the device 55 can be in the form of signals, which can be electronic, electromagnetic, optical, infrared, or other signals capable of being received by the device 55. These signals can be provided via a communication path of the device, which can be implemented, for example, using a wire or cable, fiber optics, a cellular link, a radio-frequency (RF) link, and / or other communication channels. The communication device 55 can communicate using one or more communication protocols such as Ethernet, Wi-Fi, Near Field Communication (NFC), Infrared Data Association (IrDA), Bluetooth, Bluetooth Low Energy (BLE), Zigbee, Long Term Evolution (LTE), 5G New Radio (NR), Vehicle-to-Everything (V2X), Controller Area Network (CAN), or Local Interconnect Network (LIN).

[0064] The storage unit 53 can store a digital map of a parking lot in which autonomous valet parking (also referred to as autonomous parking) is possible. During autonomous parking, a vehicle can be autonomously guided to a parking place with or without a driver of the vehicle present in the vehicle.

[0065] The storage unit 53 can also statically or temporarily store all information required for automatic valet parking, including vehicles and infrastructure components parked in the parking lot. This information can be stored as part of the data included in the digital map.

[0066] The processor 51 can control autonomous valet parking of a vehicle. The processor 51 can generate all control signals for a vehicle to perform autonomous valet parking and transmit the signals to the vehicle through the communication device 55, thereby controlling the vehicle 100 to perform autonomous parking. In this case, all information for autonomous valet parking is provided by the autonomous valet parking server, and the processor 51 of the server can generate and transmit control commands to the controller 120 on behalf of the processor 130 of the vehicle 100.

[0067] The autonomous valet parking server 50 can instruct the vehicle 100 to perform autonomous valet parking by itself. In this case, the processor 51 of the server can provide the vehicle 100 with a digital map associated with a parking lot, a target position at which the vehicle 100 should be parked, and guidance route information required for parking. The vehicle 100 can then use this information from the autonomous valet parking server to perform autonomous valet parking by itself.

[0068] Referring to Figure 1 The vehicle 100 can include a sensor unit 110, a controller 120, a processor 130, a display 140, a communication device 150, and a memory 160.

[0069] The sensor unit 110 can detect a surrounding environment of the vehicle 100 using at least one sensor and generate data related to the surrounding environment based on a detection result. The sensor unit 110 can acquire road information, information about objects (e.g., other vehicles, pedestrians, objects, curbs, guardrails, lanes, obstacles) around the vehicle, and / or location information of the vehicle based on sensing data obtained from the at least one sensor. The road information may, for example, include lane positions, lane shapes, lane colors, lane types, the number of lanes, the presence of a shoulder, or the size of a shoulder. The objects around the vehicle may, for example, include the positions of the objects, the sizes of the objects, the shapes of the objects, distances to the objects, and relative speeds of the objects.

[0070] The sensor unit 110 can include at least one of a camera, a light detection and ranging (LiDAR), a radio detection and ranging (RADAR), an ultrasonic sensor, an infrared sensor, and a position measurement sensor. The listed sensors are provided by way of example for illustrative purposes only, and the sensors included in the sensor unit 110 of the present document are not limited thereto. The camera can capture images of the surroundings of the vehicle to generate image data, including lanes and / or surrounding objects in front of, behind, and / or to the sides of the vehicle 100. The LiDAR can use light (or laser) to generate information about objects located in front of, behind, and / or to the sides of the vehicle 100. The radar can use electromagnetic waves (or radio waves) to generate information about objects located in front of, behind, and / or to the sides of the vehicle 100. The ultrasonic sensor can use ultrasonic waves to generate information about objects located in front of, behind, and / or to the sides of the vehicle 100. The infrared sensor can use infrared to generate information about objects located in front of, behind, and / or to the sides of the vehicle 100. The position measurement sensor can measure the current position of the vehicle 100. The position measurement sensor can include at least one of a global positioning system (GPS) sensor, a differential global positioning system (DGPS) sensor, and a global navigation satellite system (GNSS) sensor. The position measurement sensor can generate position data of the vehicle based on a signal generated by at least one of the GPS sensor, the DGPS sensor, and the GNSS sensor.

[0071] The controller 120 can control the operation of at least one component of the vehicle 100 and / or at least one function of the vehicle under the control of the processor 130. The at least one function may, for example, include at least one of a steering function, an acceleration function or a longitudinal acceleration function, a deceleration function or a longitudinal deceleration function, a brake function, a lane change function, a lane detection function, an obstacle detection and distance detection function, a lateral control function, a powertrain control function, a safety area detection function, an engine on / off, a power on / off, and a lock / unlock function of the vehicle.

[0072] The controller 120 can control the operation of at least one component of the vehicle and / or at least one function of the vehicle for autonomous driving and / or minimum risk maneuver (MRM) of the vehicle under the control of the processor 130. For example, the controller 120 can control the operation of at least one of a steering function, an acceleration function, a deceleration function, a lane change function, a lane detection function, a lateral control function, an obstacle detection and distance detection function, a powertrain control function, and a safety area detection function for minimum risk maneuver.

[0073] The processor 130 can control overall operations of the vehicle 100. The processor 130 can include an electronic control unit (ECU) capable of controlling components within the vehicle 100. The ECU can be integrated with one or more components of the vehicle 100. For example, the processor 130 can include a central processing unit (CPU) or a micro processing unit (MCU) capable of performing a computing task.

[0074] The processor 130 can activate an autonomous driving system (ADS) upon occurrence of a predetermined event, thereby controlling components within the vehicle 100 to implement autonomous driving. The predetermined event can occur when a driver requests autonomous driving, when the driver delegates a vehicle control authority, or when a condition specified by the driver and / or a designer is satisfied.

[0075] The processor 130 can determine whether autonomous driving is possible based on at least one of vehicle state information and surrounding environment information during autonomous driving. When it is determined that autonomous driving is not possible, the processor 130 can determine and control execution of an MRM strategy. Here, the MRM strategy can include an MRM type.

[0076] The processor 130 can include a vehicle state information acquisition unit 1310, a surrounding environment information acquisition unit 1320, a DDT fallback request unit 1330, an MRM strategy determination unit 1340, an emergency stop allowable space prediction unit 1350, and a collision risk prediction unit 1360, as shown in Figure 2

[0077] The vehicle state information acquisition unit 1310 can monitor mechanical and / or electrical states of components (e.g., sensors, actuators, etc.) within the vehicle from a time when the ADS is activated to acquire vehicle state information indicating whether mechanical and / or electrical failures occur in internal components of the vehicle. The vehicle state information can include information about mechanical and / or electrical states of components within the vehicle. For example, the vehicle state information can include information indicating whether functions required for autonomous driving are normally operated based on mechanical and / or electrical states of components within the vehicle.

[0078] The surrounding environment information acquisition unit 1320 can acquire information about an environment around the vehicle from a time when the ADS is activated using the sensor unit 110 and / or the communication device 150. The surrounding environment information acquisition unit 1320 can include a road information acquisition unit 1321 for acquiring information about a road on which the vehicle travels, and a surrounding object information acquisition unit 1322 for detecting objects around the vehicle from the sensor unit 110.

[0079] ​The road information acquisition unit 1321 can obtain road information about a location where the vehicle is traveling, through the sensor unit 110. The road information acquisition unit 1321 can acquire map information from an external device (e.g., another vehicle or a server) via the communication device 150, and obtain road information about a location where the vehicle is traveling from the map information.

[0080] The surrounding object information acquisition unit 1322 can acquire information about objects (e.g., other vehicles, pedestrians, objects, curbs, guardrails, lanes, obstacles) around the vehicle, through the sensor unit 110. For example, the surrounding object information acquisition unit 1322 can obtain a distance and a relative speed of at least one vehicle located in front of, at the side of, and / or behind the vehicle.

[0081] The DDT fallback request unit 1330 can determine whether functions required for autonomous driving are functioning normally based on the vehicle state information. The functions required for autonomous driving can include, for example, lane detection, lane change, lateral control, deceleration (or brake control), powertrain control, safety zone detection, and obstacle detection and distance sensing. When at least one of the functions required for autonomous driving is not functioning normally, the processor 130 can determine that normal autonomous driving is not possible.

[0082] The DDT fallback request unit 1330 can determine whether a state of the vehicle is suitable for a normal operating condition based on the vehicle state information. For example, the processor 130 can determine whether mechanical state information (e.g., tire pressure information or engine overheating information) of the vehicle satisfies requirements of the normal operating condition. Upon detecting that the state of the vehicle does not satisfy the requirements of the normal operating condition, the processor 130 can determine that normal autonomous driving is not possible. For example, when it is found that the vehicle cannot operate normally due to a tire pressure problem or engine overheating, the processor 130 can determine that normal autonomous driving is not possible.

[0083] The DDT fallback request unit 1330 can also determine whether a surrounding environment satisfies requirements of an operational design domain (ODD) for autonomous driving based on at least one piece of surrounding environment information. The operational design domain indicates a condition under which autonomous driving is validly operated. Upon detecting that the surrounding environment information does not satisfy the ODD, the processor 130 can determine that normal autonomous driving is not possible.

[0084] If normal autonomous driving is not possible, the DDT fallback request unit 1330 can determine that a minimum risk maneuver is required to minimize the risk of an accident.

[0085] The DDT fallback request unit 1330 can request a minimum risk maneuver (MRM) strategy or an emergency stop from the MRM strategy determination unit 1340 based on the vehicle state information and information received from the infrastructure when an error is detected in the vehicle or the infrastructure (including the autonomous valet parking server) or a communication error between the vehicle and the infrastructure.

[0086] When a situation requiring the execution of a minimum risk maneuver occurs, the processor 130 can select a minimum risk maneuver strategy from among a plurality of minimum risk maneuver strategies using the MRM strategy determination unit 1340. The MRM strategy can include seven types as shown in Table 1. Figure 3 For example, the MRM strategy can include a lane-in stop strategy 301 (including Types 1 and 2), a shoulder stop strategy 302 (including Types 3 to 6), and a straight stop strategy 303 (including Type 7).

[0087] The lane-in stop strategy 301 can include a lane-in stop (Type 1) 311 and a stop with one-side lateral deviation (Type 2) 312. The shoulder stop strategy 302 can include a shoulder-in stop (Type 3) 313, a shoulder stop with lateral deviation (Type 4) 314, a merging stop with two-side lateral deviation (Type 5) 315, and a merging stop with longitudinal edge (Type 6) 316. The straight stop strategy 303 can include a longitudinal stop (Type 7) 317.

[0088] Type 1, the lane-in stop 311 refers to stopping within the boundary of the lane in which the vehicle is traveling. For example, the lane-in stop 311 refers to a type in which the vehicle is stopped within the boundary of the lane in which the vehicle is traveling by brake control 321, lateral control 322, and / or lane detection 323. The lane in which the vehicle is traveling can refer to the lane in which the vehicle is located when it is determined that a minimum risk maneuver is required. The lane-in stop 311 can be performed in a case where shoulder detection 324 is not available.

[0089] Type 2, the stop with one-side lateral deviation 312 involves stopping the vehicle on the side of the lane in which it is traveling. For example, the stop with one-side lateral deviation 312 can refer to stopping the vehicle on the side of the lane by brake control 321. The stop with one-side lateral deviation 312 can be performed when at least one of the functions of lateral control 322, lane detection 323, and shoulder detection 324 is not available.

[0090] Type 3, the shoulder-in stop 313 involves stopping the vehicle with the entire vehicle located on the shoulder of the road. For example, the shoulder-in stop 313 can refer to stopping the vehicle after moving the entire vehicle out of the boundary of the road and onto the shoulder using brake control 321, lateral control 322, lane detection 323, and / or shoulder detection 324.

[0091] Type 4, shoulder stop with lateral offset 314 involves stopping a portion of the vehicle on a shoulder of the road. For example, the shoulder stop with lateral offset 314 can refer to stopping the vehicle after moving a portion of the vehicle onto a shoulder by using the brake control 321, the lateral control 322, the lane detection 323, and / or the shoulder detection 324, thereby moving the portion of the vehicle out of the boundary of the road (or the boundary of the outermost lane) and onto the shoulder.

[0092] Type 5, merging stop with bilateral lateral offset 315 involves stopping on a shoulder at a merging point where two roads merge. For example, the merging stop with bilateral lateral offset 315 can refer to stopping the vehicle after moving the entire vehicle or a portion of the vehicle onto a shoulder at the merging point using the brake control 321, the lateral control 322, the lane detection 323, and / or the shoulder detection 324.

[0093] Type 6, merging stop with longitudinal edge 316 involves stopping on a shoulder at a merging point where a vehicle merges from one road, such as a highway on-ramp merging point. For example, the merging stop with longitudinal edge 316 can refer to stopping the vehicle after moving the entire vehicle or a portion of the vehicle onto a shoulder at the merging point using the brake control 321, the lateral control 322, the lane detection 323, and / or the shoulder detection 324.

[0094] Type 7, longitudinal stop 317 involves stopping using only longitudinal deceleration functions, such as the brake control 321, without using lateral control. For example, the longitudinal stop 317 can be performed in a situation where at least one of the functions of the lateral control 322, the lane detection 323, and the shoulder detection 324 is not available. For example, the longitudinal stop 317 can be used in a situation where lane detection or lateral control cannot be performed due to actuator failure. Here, detecting a potential stop location outside of a traffic lane can refer to a function of detecting a location of a safe area, such as a shoulder or a rest area, located outside of a traffic lane.

[0095] The priority of the above-described MRM types can be determined based on the road, the surrounding environment, and the failure operation capability of the vehicle. For example, in order to minimize the risk during stopping, the priority of the MRM type corresponding to the shoulder stop strategy 302 can be set to be higher than the priority of the MRM type corresponding to the in-lane stop strategy 301. Also, the priority of the in-shoulder stop 313 can be set to be higher than the shoulder stop with lateral offset 314, and the priority of the in-lane stop 311 can be set to be higher than the longitudinal stop 317. That is, the priority of the MRM types can be set to decrease in the order of the in-shoulder stop 313, the shoulder stop with lateral offset 314, the in-lane stop 311, and the longitudinal stop 317.

[0096] The MRM strategy determination unit 1340 of the processor 130 can select an MRM strategy based on at least one of the vehicle state information and the surrounding environment information.

[0097] The MRM strategy determination unit 1340 can determine feasible MRM types among the described MRM types based on the vehicle state information, including normal functions and / or failure characteristics required for autonomous driving. For example, when the lateral control function operates normally, all types of MRMs, including the in-lane stop 311, the stop with one-side lateral deviation 312, the in-shoulder stop 313, the shoulder stop with lateral deviation 314, the merging stop with both-side lateral deviation 315, the merging stop with longitudinal edge 316, and the longitudinal stop 317, can be determined to be feasible. In another example, when the function of the lateral control does not operate normally, the longitudinal stop 317 can be determined to be feasible.

[0098] When there is only one feasible MRM type identified based on the vehicle state information, the MRM strategy determination unit 1340 can determine the corresponding MRM type as the MRM strategy. For example, the MRM strategy determination unit 1340 can determine the longitudinal stop 317 as the MRM strategy because only the longitudinal stop 317 is feasible in the case where the function of the lateral control 321 does not operate normally. In another example, the processor 1340 can determine the longitudinal stop 317 as the MRM strategy because only the longitudinal stop 317 is feasible when a travel lane is not detected due to a sensor failure and / or an external environment.

[0099] When there are a plurality of feasible MRM types identified based on the vehicle state information, the MRM strategy determination unit 1340 can determine the feasible MRM types within a designated minimum risk condition (MRC) range. The designated MRC range can be set and / or changed by an operator and / or a designer. The designated MRC range can be set differently based on vehicle performance, vehicle type, and / or external environmental factors (e.g., weather, time, etc.).

[0100] The MRM strategy determination unit 1340 can determine the feasible MRM types within the MRC range based on whether a shoulder exists within the designated MRC range. When a shoulder does not exist within the designated MRC range, the MRM strategy determination unit 1340 can determine at least one of the in-lane stop 311, the stop with one-side lateral deviation 312, and the longitudinal stop 317 to be a feasible MRM type within the MRC range.

[0101] When a shoulder exists within the designated MRC range, the MRM strategy determination unit 1340 can determine the feasible MRM types within the MRC range based on the size of the shoulder. When the size of the shoulder within the designated MRC range is greater than or equal to a predetermined size, the MRM strategy determination unit 1340 can determine that the feasible MRM types within the MRC range include the shoulder-in stop 313, the shoulder stop with lateral offset 314, the merge stop with double lateral offset 315, the merge stop with longitudinal edge 316, the lane-in stop 311, the stop with one-side lateral offset 312, and the longitudinal stop 317. The predetermined size can be determined based on the size of the vehicle. When the size of the shoulder is less than the predetermined size, the MRM strategy determination unit 1340 can determine that the feasible MRM types within the MRC range include the shoulder stop with lateral offset 314, the merge stop with double lateral offset 315, the merge stop with longitudinal edge 316, the lane-in stop 311, the stop with one-side lateral offset 312, and the longitudinal stop 317.

[0102] If there are a plurality of executable MRM types within the designated MRC range, the MRM strategy determination unit 1340 can select a final MRM strategy by considering the priority and / or the surrounding object information.

[0103] If there are a plurality of executable MRM types within the designated MRC range, the MRM strategy determination unit 1340 can select, as the final MRM strategy, an MRM type having the highest priority among the feasible MRM types within the designated MRC range. For example, as shown in Figure 4A when the width of the shoulder 410 within the designated MRC range 400 is greater than the width of the vehicle 100, the MRM strategy determination unit 1340 can select, as the final MRM strategy, the highest priority MRM type (i.e., the shoulder-in stop 313) within the MRC range 400. As another example, as shown in Figure 4B when the width of the shoulder 420 within the designated MRC range 400 is less than the width of the vehicle 100, the MRM strategy determination unit 1340 can select, as the final MRM strategy, the highest priority MRM type (i.e., the shoulder stop with lateral offset 314) among the feasible MRM types within the MRC range 400.

[0104] The MRM strategy determination unit 1340 can additionally consider a risk associated with executing the MRM strategy within the designated MRC range and accordingly select the final MRM strategy. For example, as shown in Figure 5As shown, it is assumed that there is a shoulder 501 within the MRC range 400, in which a width of a region adjacent to the vehicle 100 of the shoulder 501 is greater than a width of the vehicle 100, but a width of a region away from the vehicle 100 of the shoulder 501 is less than the width of the vehicle 100. That is, it is assumed that there is a shoulder 501 having a width that gradually decreases within the MRC range 400. In this case, the MRM strategy determination unit 1340 can select the in-shoulder stop 313 having the highest priority based on the width of the shoulder 501. However, when there is a risk of collision with another vehicle 510 as shown in reference numeral 520 when performing the in-shoulder stop 313, the MRM strategy determination unit 1340 can select the shoulder stop 314 having a lateral deviation as the final MRM strategy, which has a lower priority than the in-shoulder stop 313, but does not cause a risk of collision with another vehicle 510.

[0105] If there are a plurality of feasible MRM types within the designated MRC range, the MRM strategy determination unit 1340 can select a final MRM strategy by considering a possibility of a collision and determination of accident liability. The MRM strategy determination unit 1340 can determine a possibility of a collision with a surrounding vehicle and determine accident liability based on a driving path of each feasible MRM type within the designated MRC range. For an in-shoulder stop and / or a shoulder stop having a lateral deviation type requiring a lane change, the MRM strategy determination unit 1340 can determine a possibility of a collision with a surrounding vehicle located at a front side, a side, and / or a rear side of the host vehicle and determine accident liability. For a stop within a lane type not requiring a lane change, the MRM strategy determination unit 1340 can determine a possibility of a collision with a vehicle located behind the host vehicle and determine accident liability.

[0106] To determine the possibility of a collision with a surrounding vehicle and accident liability, the MRM strategy determination unit 1340 can calculate a safety distance representing a difference between a minimum relative distance and an actual relative distance with a surrounding vehicle based on a Responsibility Sensitivity Safety (RSS) model shown in Equations 1 and 2, and determine the possibility of a collision and accident liability based on the calculated safety distance.

[0107]

[0108]

[0109] Equation (1)

[0110] Here, RSS x represents a longitudinal safety distance, d min,x represents a minimum longitudinal relative distance that must be maintained with a surrounding vehicle, and d x represents an actual longitudinal relative distance between the host vehicle and the surrounding vehicle. In addition, RSS yrepresents a lateral safety distance, d min,y represents a minimum lateral relative distance that must be maintained with the surrounding vehicle, and d y represents an actual lateral relative distance between the host vehicle and the surrounding vehicle.

[0111] Assuming that at least one of the longitudinal safety distance (RSS x ) and the lateral safety distance (RSS y ) to the surrounding vehicle is positive, the MRM strategy determination unit 1340 can determine that the possibility of collision with the surrounding vehicle is low (or does not exist) even when the MRM related to the surrounding vehicle is executed. Furthermore, the MRM strategy determination unit 1340 can determine that the host vehicle is not responsible for the accident even if a collision with the surrounding vehicle occurs. For example, as shown in Figure 6A when the longitudinal safety distance (RSS x ) from the host vehicle 100 to the right-front vehicle 601 is negative but the lateral safety distance (RSS y ) is positive, the MRM strategy determination unit 1340 can determine that the possibility of collision with the right-front vehicle 601 is low even when the MRM requiring a lane change (e.g., shoulder stop with lateral deviation or in-shoulder stop) is executed, and can determine that the host vehicle 100 is not responsible for the accident even if a collision with the right-front vehicle 601 occurs. As shown in Figure 6B another example is when the lateral safety distance (RSS y ) from the host vehicle 100 to the front vehicle 611 traveling in the same lane is negative but the longitudinal safety distance (RSS x ) is positive, the MRM strategy determination unit 1340 can determine that the possibility of collision with the front vehicle 611 is low even when the MRM requiring a lane change (e.g., shoulder stop with lateral deviation or in-shoulder stop) is executed, and can determine that the host vehicle 100 is not responsible for the accident even if a collision with the front vehicle 611 occurs.

[0112] When the MRM related to the driving path of the surrounding vehicle is executed, when both the longitudinal safety distance (RSS x ) and the lateral safety distance (RSS y ) to the surrounding vehicle are negative, the MRM strategy determination unit 1340 can determine that the possibility of collision with the surrounding vehicle is high (or a collision is likely). Furthermore, the MRM strategy determination unit 1340 can determine that the host vehicle is responsible for the accident in the event of a collision with the surrounding vehicle. For example, as shown in Figure 6C when the longitudinal safety distance (RSS x ) and the lateral safety distance (RSS yWhen both are negative, when an MRM requiring a lane change is executed (e.g., shoulder stop with lateral offset or in-shoulder stop), it can be determined that the likelihood of collision with the right front vehicle 621 is high. Further, the MRM strategy determination unit 1340 can determine that the lane change of the host vehicle 100 can result in a collision with the right front vehicle 621, and thus infer that the host vehicle 100 will be at fault in the event of a collision with the right front vehicle 621.

[0113] When the likelihood of collision with a surrounding vehicle is determined to be high in the case where an MRM requiring a lane change is executed, the MRM strategy determination unit 1340 can select an in-lane stop, which has a lower priority than the in-shoulder stop or the shoulder stop with lateral offset, as the final MRM. In this case, the MRM strategy determination unit 1340 can calculate a longitudinal safety distance and a lateral safety distance with a rear vehicle traveling in the same lane as the host vehicle. When at least one of the longitudinal safety distance and the lateral safety distance is positive, the MRM strategy determination unit 1340 can determine that the likelihood of collision with the rear vehicle is low, even if an in-lane stop is executed, and that the host vehicle will not be at fault in the event of a collision with the rear vehicle. For example, as shown in FIG. 7, when in the situation requiring MRM execution, the host vehicle 100 can calculate a longitudinal safety distance and a lateral safety distance with the right rear vehicle 720 to execute a type 3, in-shoulder stop, which has the highest priority. However, when both the longitudinal safety distance and the lateral safety distance with the right rear vehicle 720 are negative, the likelihood of collision with the side rear vehicle 720 is high due to the lane change required for the in-shoulder stop, and the responsibility for such a collision can be related to the host vehicle 100. Meanwhile, since both the longitudinal safety distance and the lateral safety distance with the rear vehicle 710 are positive, the host vehicle 100 can select a type 1 in-lane stop (which has a lower priority than type 4) as the final MRM strategy. Figure 7

[0114] The longitudinal safety distance and the lateral safety distance between the host vehicle and the surrounding vehicle can be calculated by Equations 2 and 3.

[0115] Equation 2 is a formula for calculating a longitudinal safety distance (Rss x ) 810 between the host vehicle and the surrounding vehicle as shown in FIG. 6, and Equation 3 is a formula for calculating a lateral safety distance (Rss y ) 820 between the host vehicle and the surrounding vehicle as shown in FIG. 7. Figure 8A Figure 8B

[0116] … Equation (2)

[0117]

[0118] ​​​

[0119] … Equation (3)

[0120] Here, p denotes a reaction time, m denotes a lateral margin, a min,brake denotes a minimum deceleration of the host vehicle, a max,aceel denotes a maximum acceleration of the surrounding vehicle, and a max,brake denotes a maximum deceleration of the surrounding vehicle.

[0121] For the calculation of the lateral safety distance and / or the longitudinal safety distance, the parameters in Equations 2 and 3 can be set as shown in Table 1.

[0122]

[0123] Table 1

[0124] The parameter values in Table 1 are illustrative, and the present disclosure is not limited to these values.

[0125] The MRM policy determination unit 1340 can store data supporting selection of a final MRM policy in the memory 160. The supporting data can include at least one of presence of a shoulder within a designated MRC range, a size (e.g., length and / or width) of the shoulder, a safety distance from the surrounding vehicle, vehicle state information of the host vehicle, and lane detection information. The MRM policy determination unit 1340 can ensure a principle for selection of a lower priority MRM policy by storing supporting data related to the selected final MRM policy. For example, when Type 7 (longitudinal stop) is selected as the final MRM policy, the MRM policy determination unit 1340 can store, in the memory 160, at least one of information indicating abnormal operation of a lateral control function, a steering angle, a steering speed, information indicating a failure in a lane detection sensor, or a sensor value from the lane detection sensor. As another example, when Type 1 (in-lane stop) is selected as the final MRM policy, the MRM policy determination unit 1340 can store, in the memory 160, at least one of longitudinal safety distance information and lateral safety distance information for the surrounding vehicle calculated during the MRM policy selection process, despite the presence of a shoulder within a designated MRC range.

[0126] A corresponding MRM type can be selected. For example, the MRM policy determination unit 1340 can determine the longitudinal stop 317 because the longitudinal stop 317 is feasible only when the lateral control function is not normally operating. As another example, when a travel lane is not detected due to a sensor failure and / or an external environmental factor, the MRM policy determination unit 1340 can determine the longitudinal stop 317.

[0127] The processor 130 can control the vehicle to stop according to the final MRM strategy while controlling to notify other vehicles and / or drivers to perform the minimum risk maneuver. The control action to stop the vehicle can include generating a travel trajectory for stopping and / or performing lateral and / or longitudinal control actions to follow the generated trajectory. The processor 130 can control the display 140 to notify the driver that the vehicle is performing the minimum risk maneuver. As another example, the processor 130 can control the communication device 150 to notify other vehicles that the vehicle is performing the minimum risk maneuver. This is merely an illustrative example, and other methods of indicating the minimum risk maneuver are possible.

[0128] The processor 130 can perform a control action to stop the vehicle based on the determined minimum risk maneuver type and determine whether the MRC is satisfied. The MRC can refer to a state in which the speed of the vehicle is zero. For example, the processor 130 can determine whether the vehicle 100 achieves a stop state with zero speed while performing at least one action corresponding to the determined final MRM type. Once the speed of the vehicle 100 is zero, the processor 130 can determine that the MRC is satisfied.

[0129] The processor 130 can terminate the MRM execution when the MRC is satisfied and transition an autonomous driving system (ADS) to a standby state or an off state. After transitioning the ADS to the standby state or the off state, the processor 130 can control the system to transfer control of the vehicle to the driver (or user).

[0130] The emergency stop allowance space prediction unit 1350 can calculate a longitudinal length of the emergency stop allowance space based on a speed of the vehicle and a time required for the vehicle to reach a stop (e.g., a complete stop). If there is an obstacle on a driving path of the vehicle, the emergency stop allowance space prediction unit 1350 can calculate a distance from a side of the emergency stop allowance space closest to the vehicle to the obstacle, compare the distance with the longitudinal length of the emergency stop allowance space, and determine the smaller one as a final longitudinal length of the emergency stop allowance space. In other words, the vehicle can update the emergency stop allowance space (e.g., the emergency stop area) by adjusting (e.g., reducing) the longitudinal length of the emergency stop allowance space to match a distance between an object and a side of the emergency stop allowance space closest to the vehicle. The emergency stop allowance space prediction unit 1350 can calculate a lateral length of the emergency stop allowance space based on a width of the vehicle and a predetermined stop margin constant (also referred to as a stop distance constant). The emergency stop allowance space prediction unit 1350 can calculate a lateral length of the emergency stop allowance space based on a width of the vehicle and a predetermined maximum lane tolerance. If there is a vulnerable road user within the emergency stop allowance space, the emergency stop allowance space prediction unit 1350 can adjust the final longitudinal length of the emergency stop allowance space by comparing a distance to the vulnerable road user with the final longitudinal length of the emergency stop allowance space, correcting using the smaller value. Further details will be described later.

[0131] The collision risk prediction unit 1360 can determine whether there is an obstacle on a driving path of the vehicle based on the surrounding environment information generated by the surrounding environment information acquisition unit 1320. The collision risk prediction unit 1360 can determine whether there is a vulnerable road user within the emergency stop allowance space based on the surrounding environment information generated by the surrounding environment information acquisition unit 1320. Further details will be described later.

[0132] The display 140 can visually display information related to the vehicle 100. For example, the display 140 can provide a driver of the vehicle 100 with various information related to a state of the vehicle 100 under the control of the processor 130. The various information related to the state of the vehicle can include at least one of information indicating normal operation or a failure of various components included in the vehicle and / or at least one function of the vehicle and information indicating a driving state of the vehicle. The driving state of the vehicle can include at least one of an autonomous driving state, an MRM execution state, an MRM completion state, and an autonomous driving termination state.

[0133] The communication device 150 can communicate with an external device of the vehicle 100. The communication device 150 can receive or transmit data from or to the outside of the vehicle 100 under the control of the processor 130. For example, the communication device 150 can perform communication using a wireless or wired communication protocol.

[0134] Although Figure 1 The controller 120 and the processor 130 are shown as separate components, but the controller 120 and the processor 130 can be integrated into a single component.

[0135] Figure 9 is a flowchart illustrating the operation of the vehicle. In the description with reference to Figure 9 , the vehicle can be the vehicle 100 shown in Figure 1 .

[0136] With reference to Figure 9 , in operation S910, the vehicle 100 can normally operate the ADS.

[0137] While monitoring the vehicle state and the surrounding environment, the vehicle 100 can perform autonomous driving in response to the normal operation of the ADS. The vehicle 100 can detect whether a minimum risk maneuver (MRM) is required based on information obtained by monitoring the vehicle state and the surrounding environment. When the MRM is required, event A1 can occur.

[0138] The vehicle 100 can detect whether a driver (or user) intervention is required while performing autonomous driving in response to the normal operation of the ADS. When the driver intervention is required, the vehicle 100 can issue an intervention request (RTI) or a warning through the ADS. The request for the driver intervention or the warning can be event A2. When event A1 occurs while the ADS normally operates, the vehicle 100 can proceed to operation S920.

[0139] When event A2 occurs while the ADS normally operates, the vehicle 100 can determine whether the driver intervention is detected within a predetermined time in operation S950. When the driver intervention is not detected within the predetermined time, event B1 can be determined to have occurred. When event B1 occurs, the vehicle 100 can proceed to operation S920. When the driver intervention is detected within the predetermined time, the vehicle 100 can determine that event B2 has occurred. When event B2 occurs, the vehicle 100 can proceed to operation S940.

[0140] In operation S920, the vehicle 100 can perform a minimum risk maneuver (MRM). The vehicle 100 can determine a type of the MRM based on at least one of vehicle state information and surrounding environment information. The surrounding environment information can include road information and information about surrounding vehicles. As Figure 3As shown, the MRM types can include a Type 1 in-lane stop 311, a Type 2 stop with one side lateral offset 312, a Type 3 shoulder-in stop 313, a Type 4 shoulder stop with lateral offset 314, a Type 5 merge stop with two side lateral offsets 315, a Type 6 merge stop with longitudinal edge 316, and / or a Type 7 longitudinal stop 317. The vehicle 100 can control at least one of its components to stop the vehicle according to the determined MRM type. The vehicle 100 can store data for determining the MRM type in the memory 160.

[0141] In operation S920, the vehicle 100 can determine whether the minimum risk requirement is satisfied by checking whether the speed of the vehicle reaches 0 by performing a minimum risk maneuver (MRM). When the minimum risk requirement is satisfied, it can be determined that the event C1 has occurred, and the vehicle 100 can proceed to operation S930. During the performance of the minimum risk maneuver, the vehicle 100 can determine whether driver intervention is detected. When the driver intervention is detected, it can be determined that the event C2 has occurred, and the vehicle 100 can proceed to operation S940.

[0142] During operation S930, the vehicle 100 can maintain a state in which the minimum risk requirement is satisfied. The state can mean that the vehicle is stationary. For example, the vehicle 100 can be maintained in a stopped state. For example, the vehicle 100 can perform a control action to maintain the vehicle in the stopped state regardless of the slope of the road surface on which the vehicle is stopped. While maintaining the state in which the minimum risk requirement is satisfied, the vehicle 100 can determine whether the event D1 occurs. The event D1 can include at least one of the ADS being turned off by the driver and completion of the control switch to the driver. When the event D1 occurs, the vehicle 100 can proceed to operation S940.

[0143] In operation S940, the vehicle 100 can convert the ADS to a standby state or an off state. During the ADS is in the standby state or the off state, the vehicle 100 does not perform an action related to autonomous driving.

[0144] The above-described operations S910, S920, S930, and S950 can correspond to an active state of the ADS, and operation S940 can correspond to an inactive state of the ADS.

[0145] Figure 10 is a flowchart illustrating operations of a vehicle for determining an MRM strategy. Figure 10 The operations in can be Figure 9The operations of S920 in FIG. 9B can be implemented as computer-readable instructions in software stored in memory and executed by the processor 130 of the vehicle 100. The operations of S920 in FIG. 9B can also be implemented in hardware provided in the vehicle 100, or a combination of software and hardware. The operations of S920 in FIG. 9B can be performed by the processor 130 and / or the controller 120 equipped in the vehicle 100, or can be implemented as instructions executable by the processor 130 and / or the controller 120.

[0146] Referring to Figure 10 In operation S1001, the vehicle 100 can determine whether lateral control is possible based on vehicle state information. For example, the vehicle 100 can monitor mechanical and / or electrical states of components within the vehicle (e.g., sensors, actuators, etc.) to obtain vehicle state information indicating whether mechanical and / or electrical failure occurs in the internal components of the vehicle. The vehicle 100 can determine whether lateral control (or steering control) is possible based on the vehicle state information indicating the mechanical and / or electrical states of the sensors and / or actuators.

[0147] When the lateral control is not possible, in operation S1021, the vehicle 100 can select longitudinal stop as the final MRM strategy. For example, as shown in FIG. 10B, when the lateral control is not possible, the vehicle 100 can perform only the longitudinal stop and thus determine the longitudinal stop as the final MRM strategy. Figure 3

[0148] When the lateral control is possible, in operation S1003, the vehicle 100 can determine whether a road shoulder exists within the MRC range. For example, the vehicle 100 can determine whether the road shoulder exists by checking road information within the MRC range corresponding to a predetermined distance centered on the vehicle 100. The road information within the MRC range can be obtained from sensing data of sensors (e.g., the sensor unit 110) equipped in the vehicle 100 or from map information acquired through the communication device 150.

[0149] When the road shoulder does not exist, in operation S1015, the vehicle 100 can determine whether lane detection is possible. For example, in the case where the road shoulder does not exist, the vehicle 100 cannot perform the road shoulder stop strategy, and thus needs to check whether the lane detection is possible to determine whether the in-lane stop can be performed. The vehicle 100 can determine whether the lane detection is possible based on a sensing value of a lane detection sensor.

[0150] When the lane detection is not possible, in operation S1021, the vehicle 100 can select the longitudinal stop as the final MRM strategy. For example, when the lane detection is not possible, the vehicle 100 can determine that the in-lane stop cannot be performed and thus determine the longitudinal stop as the final MRM strategy.

[0151] ​When lane detection is possible, the vehicle 100 can determine whether the accident liability of the host vehicle is established when performing in-lane stopping in operation S1017. For example, the vehicle 100 can calculate a safety distance to a rear vehicle and determine the likelihood of a collision and accident liability based on the calculated safety distance. The rear vehicle can refer to a vehicle traveling in the same lane as the host vehicle. The safety distance to the rear vehicle can include a longitudinal safety distance and a lateral safety distance as shown in Equation 1. When both the calculated longitudinal safety distance and the lateral safety distance are negative, the vehicle 100 can determine that there is a high likelihood of a collision with the rear vehicle when performing in-lane stopping, and the accident liability will be attributed to the host vehicle. When at least one of the calculated longitudinal safety distance and the lateral safety distance is positive, the vehicle 100 can determine that there is a low likelihood of a collision with the rear vehicle when performing in-lane stopping, and the host vehicle will not be responsible for the accident in the event of a collision.

[0152] When it is determined that the host vehicle will cause an accident during in-lane stopping, the vehicle 100 can proceed to operation S1021 to select longitudinal stopping as the final MRM strategy.

[0153] When it is determined that the accident liability does not attribute to the host vehicle during in-lane stopping, the vehicle 100 can select in-lane stopping as the final MRM strategy in operation S1019.

[0154] When it is found that there is a road shoulder as a result of the check in operation S1003, the vehicle 100 can determine whether the size of the shoulder is greater than the size of the vehicle in operation S1005. For example, the vehicle 100 can compare the width of the shoulder with the width of the vehicle to determine whether shoulder-in stopping or shoulder stopping with lateral deviation is feasible.

[0155] When the size of the shoulder is greater than the size of the vehicle, the vehicle 100 can determine that stopping in the shoulder is feasible and determine that the accident liability does not attribute to the host vehicle during the stopping in the shoulder in operation S1007. For example, the vehicle 100 can calculate a driving path for the stopping in the shoulder and calculate a safety distance of at least one surrounding vehicle related to the calculated driving path. The at least one surrounding vehicle related to the driving path for the stopping in the shoulder can include one or more of a front side vehicle, a side vehicle, and / or a rear side vehicle. Based on the calculated safety distance, the vehicle 100 can evaluate a likelihood of a collision with the at least one surrounding vehicle and the accident liability. The safety distance for the at least one surrounding vehicle can include a longitudinal safety distance and a lateral safety distance as shown in Equation 1. When both of the calculated longitudinal safety distance and the lateral safety distance are negative, the vehicle 100 can determine that there is a high likelihood of a collision with the at least one surrounding vehicle during the stopping in the shoulder and that the accident liability attributes to the host vehicle. When at least one of the calculated longitudinal safety distance and the lateral safety distance is positive, the vehicle 100 can determine that the likelihood of a collision with the at least one surrounding vehicle during the stopping in the shoulder is low and that the accident liability does not attribute to the host vehicle.

[0156] When it is determined that the accident liability does not attribute to the host vehicle during the stopping in the shoulder, the vehicle 100 can select the stopping in the shoulder as the final MRM strategy in operation S1009.

[0157] When it is determined that the accident liability attributes to the host vehicle during the stopping in the shoulder, the vehicle 100 can proceed to operation S1011 to determine that the accident liability attributes to the host vehicle during the shoulder stopping with lateral deviation. For example, the vehicle 100 can calculate a driving path for the shoulder stopping with lateral deviation and calculate a safety distance of at least one surrounding vehicle related to the calculated driving path. For the shoulder stopping with lateral deviation, the at least one surrounding vehicle related to the driving path can include one or more of a front side vehicle, a side vehicle, and / or a rear side vehicle. Based on the calculated safety distance, the vehicle 100 can evaluate a likelihood of a collision with the at least one surrounding vehicle and the accident liability. The safety distance for the at least one surrounding vehicle can include a longitudinal safety distance and a lateral safety distance as shown in Equation 1. When both of the calculated longitudinal safety distance and the lateral safety distance are negative, the vehicle 100 can determine that there is a high likelihood of a collision with the at least one surrounding vehicle during the shoulder stopping with lateral deviation and that the accident liability attributes to the host vehicle. When at least one of the calculated longitudinal safety distance and the lateral safety distance is positive, the vehicle 100 can determine that the likelihood of a collision with the at least one surrounding vehicle during the shoulder stopping with lateral deviation is low and that the accident liability does not attribute to the host vehicle.

[0158] When it is determined that the accident liability does not attribute to the host vehicle during the shoulder stop with lateral offset, the vehicle 100 can select the shoulder stop with lateral offset as the final MRM strategy in operation S1013.

[0159] When it is determined that the accident liability attributes to the host vehicle during the shoulder stop with lateral offset, the vehicle 100 can proceed to operation S1017.

[0160] As described above, when a situation in which normal autonomous driving is not possible is detected, by determining a minimum risk maneuver strategy based on vehicle state information and / or surrounding environment information, and by considering the accident liability for each type of minimum risk maneuver, the vehicle can enhance safety and minimize risk.

[0161] Figure 11 is a flowchart illustrating an operation of predicting an emergency stop allowance space and a collision risk during autonomous driving. Figure 12 is a diagram illustrating an MRM strategy. Figure 13 is a diagram illustrating how to predict an emergency stop allowance space when the final MRM strategy is a lane-in stop type. Figure 14 is a diagram illustrating how to predict an emergency stop allowance space when the final MRM strategy is a straight stop type. Figure 15 is a diagram illustrating how to predict a collision risk when the final MRM strategy is a lane-in stop type. Figure 16 is a diagram illustrating how to predict a collision risk when the final MRM strategy is a straight stop type.

[0162] Referring to Figure 11 , the processor 130 can determine whether a minimum risk maneuver is required during autonomous valet parking based on at least one of surrounding environment information and vehicle state information in operation S1110, and when it is determined that a minimum risk maneuver is required, the type of the minimum risk maneuver can then be determined.

[0163] The minimum risk maneuver during autonomous valet parking can be classified into an emergency stop 1200, which includes a type 1 straight stop 1201 and a type 2 lane-in stop 1202, as Figure 12 indicated.

[0164] When it is determined that a minimum risk maneuver is required, the processor 130 can predict (calculate) an emergency stop allowance space for the vehicle to stop in operation S1120 based on the speed of the vehicle, the time required for the vehicle to stop, and the presence of a fixed or dynamic obstacle. The fixed obstacle can be an object embedded or attached to the ground (e.g., an elevator column, a traffic sign, a pole, a fence, a wall, etc.) or otherwise immobile (e.g., a roadblock, debris, etc.). The dynamic obstacle can be any object that is moving or capable of moving (e.g., a pedestrian, a cyclist, a vehicle, a wild animal, a parking barrier arm, etc.). In operation S1130, the processor 130 can predict a collision risk based on the surrounding environment information, and when a collision risk is predicted, the emergency stop allowance space can be adjusted.

[0165] The operations of predicting the emergency stop allowance space and predicting the collision risk can be performed before determining the type of the minimum risk maneuver.

[0166] When it is determined that remote control is safe based on at least one of the surrounding environment information and the vehicle state information, the processor 130 can transmit the MRM determination result to the infrastructure (including the autonomous valet parking server).

[0167] When it is determined that vehicle control is feasible based on at least one of the surrounding environment information and the vehicle state information, the processor 130 can perform control according to the MRM determination result.

[0168] Reference Figure 13 and Figure 14 , the emergency stop allowance space 900 (also referred to as an emergency stop area) can indicate an area in which the vehicle 100 can perform an emergency stop. The emergency stop allowance space 900 can have a size large enough to allow the vehicle 100 to safely reach a complete stop (e.g., without colliding with an object or a person). In other words, if the vehicle ever needs to perform an emergency stop, the vehicle is able to come to a complete stop within the emergency stop area. The emergency stop allowance space 900 can be a virtual area having a longitudinal length l a and a lateral width W a . The emergency stop allowance space 900 can be rectangular, but is not limited to this shape, and can be defined by various polygonal combinations.

[0169] The processor 130 can calculate the emergency stop allowance space 900 for performing a straight stop or an in-lane stop. Using a pre-stored algorithm, the processor 130 can calculate the longitudinal length l des,SV of the emergency stop allowance space 900 based on the speed (V req ) of the vehicle 100 and the time (t a ) required for the vehicle 100 to reach a stop. In detail, the processor 130 can calculate the longitudinal length l a.

[0170]

[0171] … Equation (4)

[0172] Here, l a represents the longitudinal length of the emergency stop allowance space, V des,SV represents the speed of the vehicle, and a min represents the average deceleration of the vehicle.

[0173] a min is given by Equation 5, and Equation 4 can be defined as shown in Equation 6. The processor 130 can calculate the longitudinal length l a of the emergency stop allowance space 900 using Equation 6.

[0174]

[0175] … Equation (5)

[0176] Here, a min represents the average deceleration of the vehicle, V des,SV represents the speed of the vehicle, and t req represents the time required for the vehicle to stop.

[0177]

[0178] … Equation (6)

[0179] Here, l a represents the longitudinal length of the emergency stop allowance space, V des,SV represents the speed of the vehicle, and t req represents the time required for the vehicle to stop.

[0180] The time t req for the vehicle to reach a stop can be set as shown in Table 2.

[0181] If the speed of the vehicle 100 is greater than 0 km / h and less than or equal to 10 km / h, the time t req for the vehicle to reach a stop can be 3 seconds (sec). If the speed of the vehicle 100 is greater than 10 km / h and less than or equal to 20 km / h, the time t req for the vehicle to reach a stop can be 4 seconds (sec). If the speed of the vehicle 100 is greater than 20 km / h and less than or equal to 30 km / h, the time t req for the vehicle to reach a stop can be 5 seconds (sec).

[0182]

[0183] Table 2

[0184] refer to Figure 14 The processor 130 can use the sensor unit 110 to determine whether there is a fixed obstacle (e.g., a stationary object or a parked vehicle) in the vehicle's driving path, and if there is a fixed obstacle B (e.g., within a vehicle threshold distance), it calculates the distance d from the side of the emergency stop allowable space 900 closest to the vehicle to the fixed obstacle B. B The distance d to the fixed obstacle B B Longitudinal length l of emergency stop allowable space 900 a The smaller one is compared and selected as the final longitudinal length L of the emergency stop allowance space 900. a The processor 130 can determine whether an obstacle is fixed or dynamic by analyzing changes in its speed or position using the sensor unit 110.

[0185] Final longitudinal length L a It can be defined as shown in Formula 7.

[0186]

[0187] ...Formula (7)

[0188] Here, L a Indicates the final longitudinal length, l a This indicates the longitudinal length of the emergency stop allowable space of 900, and d B It indicates the distance from the side of the emergency stopping space closest to the vehicle to the fixed obstacle.

[0189] For example, when the calculated emergency stop allowable space 900 longitudinal length l a It is 4 meters and the distance d to the fixed obstacle B. B When the distance is 3 meters, the processor 130 can determine the final longitudinal length L of the emergency stop allowable space 900. a Set it to a smaller value, which is 3 meters.

[0190] refer to Figure 14 When the minimum risk maneuver type is a straight stop (or when lane information is unavailable), processor 130 can use a pre-stored algorithm based on the vehicle's width W. v The lateral length W of the emergency stop allowable space of 900 is calculated using the preset stop margin constant δ1. a .

[0191] When the minimum risk maneuver type is a straight stop, processor 130 can use Formula 8 to calculate the lateral length W of the emergency stop allowable space 900. a .

[0192]

[0193] … Equation (8)

[0194] Here, W a represents the lateral length, W v represents the width of the vehicle, and δ1represents a preset stop margin constant. The stop margin constant δ1may be, for example, 0.375 meters, but this is not limiting and can vary according to the settings.

[0195] Referring to Figure 13 , when the minimum risk maneuver type is in-lane stopping (or when lane information is available), the processor 130 can calculate the lateral length W v of the emergency stop allowance space 900 using a pre-stored algorithm based on the width W v of the vehicle 100 and a preset maximum lane tolerance δ2.

[0196] When the minimum risk maneuver type is in-lane stopping, the processor 130 can calculate the lateral length W a of the emergency stop allowance space 900 using Equation 9.

[0197]

[0198] … Equation (9)

[0199] Here, W a represents the lateral length, W v represents the width of the vehicle, and δ2represents a preset maximum lane tolerance.

[0200] Referring to Figure 15 , the processor 130 can determine whether a dynamic obstacle (e.g., a vulnerable road user such as a cyclist or a pedestrian, or another vehicle TV entering the emergency stop allowance space) exists within the emergency stop allowance space, predict a collision risk, and adjust the final longitudinal length L a of the emergency stop allowance space 900 when a collision risk is predicted. In detail, if a dynamic obstacle exists within the emergency stop allowance space 900, the processor 130 can compare the distance d v from the side of the emergency stop allowance space 900 closest to the vehicle 100 to the dynamic obstacle and the final longitudinal length L a of the emergency stop allowance space 900, and adjust the final longitudinal length L a to a smaller value.

[0201] The adjusted final longitudinal length L aa may be defined as shown in Equation 10.

[0202]

[0203] … Equation (10)

[0204] Here, L aa represents the final longitudinal length adjusted, l a represents the longitudinal length of the emergency stop allowance space 900, and d v represents the distance from the side closest to the vehicle of the emergency stop allowance space to the dynamic obstacle.

[0205] For example, when the final longitudinal length L a of the emergency stop allowance space 900 calculated is 3.5 meters and the distance d v to the dynamic obstacle is 3 meters, the processor 130 can adjust the final longitudinal length L a of the emergency stop allowance space 900 to the smaller value of 3 meters.

[0206] Referring to Figure 1 and Figure 16 , the processor 51 of the autonomous valet parking server 50 can determine whether a minimum risk maneuver is required during autonomous driving based on at least one of the surrounding environment information and the vehicle state information, and when it is determined that a minimum risk maneuver is required, the type of the minimum risk maneuver can then be determined.

[0207] The minimum risk maneuver during autonomous valet parking can be classified as an emergency stop 1200, which includes a type 1 straight stop 1201 or a type 2 in-lane stop 1202, as shown in Figure 12 .

[0208] When it is determined that a minimum risk maneuver is required, the processor 51 can predict (calculate) an emergency stop allowance space for the vehicle to stop based on the speed of the vehicle, the time required for the vehicle to stop, and the presence of a fixed or dynamic obstacle. The processor 51 can predict a collision risk based on the surrounding environment information, and when a collision risk is predicted, the emergency stop allowance space 900 can be adjusted.

[0209] The processor 51 can calculate the emergency stop allowance space 900 for performing a straight stop or an in-lane stop. Using a pre-stored algorithm, the processor 51 can calculate the longitudinal length l a of the emergency stop allowance space 900 based on the speed (V des,SV ) of the vehicle 100 and the time (t req ) required for the vehicle 100 to reach a stop.

[0210] The processor 51 can determine whether a fixed obstacle is present in the driving path of the vehicle, and when a fixed obstacle B is present, the distance dB the distance d to the fixed obstacle B B the longitudinal length l of the emergency stop allowance space 900 a are compared, and the smaller one is selected as the final longitudinal length L of the emergency stop allowance space 900 a .

[0211] When the minimum risk maneuver type is straight stopping (or when lane information cannot be obtained), the processor 51 can calculate the lateral length W of the emergency stop allowance space 900 using a pre-stored algorithm based on the width W of the vehicle v and a preset stop margin constant δ1. a .

[0212] When the minimum risk maneuver type is in-lane stopping (or when lane information can be obtained), the processor 51 can calculate the lateral length W of the emergency stop allowance space 900 using a pre-stored algorithm based on the width W of the vehicle 100 v and a preset maximum lane tolerance δ2. v .

[0213] The processor 51 can determine whether a dynamic obstacle (e.g., a vulnerable road user such as a cyclist or a pedestrian, or another vehicle TV entering the emergency stop allowance space) exists within the emergency stop allowance space, predict a collision risk, and adjust the final longitudinal length L of the emergency stop allowance space 900 when a collision risk is predicted. a In detail, when a vulnerable road user (VRU) exists within the emergency stop allowance space 900, the processor 51 can compare the distance d from the side of the emergency stop allowance space 900 closest to the vehicle 100 to the VRU v with the final longitudinal length L of the emergency stop allowance space 900 a , and adjust the final longitudinal length L a to a smaller value.

[0214] The operation of the processor 51 of the autonomous valet parking server 50 is the same as that of the processor 130 of the vehicle 100, and thus a detailed description is omitted.

[0215] Referring to Figure 16 , the processor 51 can determine whether a dynamic obstacle (e.g., another vehicle TV) exists within the emergency stop allowance space 900, and when another vehicle TV exists within the emergency stop allowance space 900, the processor 51 can perform control to move the other vehicle TV.

[0216] After calculating the emergency stop allowance space 900, the processor 51 can control the movement of the other vehicle TV to prevent it from entering the emergency stop allowance space 900. After calculating the emergency stop allowance space 900, the processor 51 can control the movement of the other vehicle TV to prevent it from entering the emergency stop allowance space 900 or exiting the emergency stop allowance space 900.

[0217] As described herein, if an emergency stop is required during autonomous driving as part of a minimum risk maneuver strategy, the vehicle assesses the collision risk and adjusts the emergency stop allowance space corresponding to a straight stop type or an in-lane stop type based on the predicted collision risk.

[0218] When an emergency stop is required during autonomous driving as part of a minimum risk maneuver strategy, it can be advantageous to predict the emergency stop allowance space corresponding to a straight stop type or an in-lane stop type and adjust the emergency stop allowance space based on the predicted collision risk.

[0219] The described functions can be implemented as hardware, software, firmware, or any combination thereof. When implemented in software, the functions can be stored or transmitted over as one or more instructions or code on a computer-readable medium. Computer-readable media include all computer-readable media, communication media, and computer storage media. Storage media can be any available media that can be accessed by a computer. By way of example, and not limitation, such computer-readable media can comprise RAM, ROM, EEPROM, CD-ROM or other optical disk storage, magnetic disk storage or other magnetic storage devices, or any other medium that can be used to carry or store desired program code in the form of instructions or data structures and that can be accessed by a computer. Disk and disc, as used herein, includes compact discs and laser discs.

[0220] When one or more example embodiments are implemented as program code or code segments, the code segments should be understood as representing processes, functions, subprograms, programs, routines, subroutines, modules, software packages, classes, or any combination of instructions, data structures, or program statements. Code segments can be connected to other code segments or hardware circuits by sending and / or receiving information, data, arguments, parameters, or memory contents. Such information, arguments, parameters, data, etc. can be transmitted, sent, or conveyed using any suitable means, including memory sharing, message passing, token passing, or network transmission. In addition, aspects of the methods or algorithms and / or operations can be integrated into machine-readable media and / or computer-readable media as code and / or instructions or any combination or set thereof, thereby forming a computer program product.

[0221] In a software implementation, the techniques described herein can be implemented as modules (e.g., procedures, functions, and so on) that perform the functions described herein. The software codes can be stored in memory units and executed by processors. The memory unit can be implemented within the processor or external to the processor, in which case it can be communicatively coupled to the processor through various means as is known in the art.

[0222] In a hardware implementation, the processing units can be implemented within one or more application specific integrated circuits (ASICs), digital signal processors (DSPs), digital signal processing devices (DSPDs), programmable logic devices (PLDs), field programmable gate arrays (FPGAs), processors, controllers, micro-controllers, microprocessors, other electronic units designed to perform the functions described herein, or a combination thereof.

[0223] An autonomous driving vehicle can include at least one sensor configured to detect a surrounding environment of the vehicle to generate surrounding environment information, a processor configured to monitor a state of the vehicle to generate vehicle state information, and determine whether a minimum risk maneuver is required based on at least one of the surrounding environment information and the vehicle state information during autonomous valet parking, and a controller configured to control an operation of the vehicle according to a control of the processor, wherein in response to the minimum risk maneuver being required, the processor can calculate an emergency stop allowance space for stopping of the vehicle based on a speed of the vehicle, a time required for stopping of the vehicle, and whether there is a fixed obstacle or a dynamic obstacle.

[0224] The processor can calculate a longitudinal length of the emergency stop allowance space based on the speed of the vehicle and the time required for stopping of the vehicle.

[0225] The processor can determine whether there is a fixed obstacle on a driving path of the vehicle, calculate a distance to the fixed obstacle from a side of the emergency stop allowance space closest to the vehicle when there is the fixed obstacle, compare the distance to the fixed obstacle with the longitudinal length of the emergency stop allowance space, and select a smaller value between the distance to the fixed obstacle and the longitudinal length of the emergency stop allowance space as a final longitudinal length of the emergency stop allowance space.

[0226] The processor can calculate a lateral length of the emergency stop allowance space based on a width of the vehicle and a predetermined stop margin constant.

[0227] The processor can calculate a lateral length of the emergency stop allowance space based on a width of the vehicle and a predetermined maximum lane tolerance.

[0228] The processor can determine whether there is a dynamic obstacle within the emergency stop allowance space, predict whether there is a collision risk, and adjust the final longitudinal length of the emergency stop allowance space when there is the collision risk.

[0229] The processor can determine whether a dynamic obstacle exists within the emergency stop allowance space, compare a distance to the dynamic obstacle with a final longitudinal length of the emergency stop allowance space when the dynamic obstacle exists, and adjust the final longitudinal length of the emergency stop allowance space to a smaller value between the distance to the dynamic obstacle and the final longitudinal length of the emergency stop allowance space.

[0230] When the speed of the vehicle is greater than 0 km / h and less than or equal to 10 km / h, the time required for the vehicle to stop can be 3 seconds.

[0231] When the speed of the vehicle is greater than 10 km / h and less than or equal to 20 km / h, the time required for the vehicle to stop can be 4 seconds.

[0232] When the speed of the vehicle is greater than 20 km / h and less than or equal to 30 km / h, the time required for the vehicle to stop can be 5 seconds.

[0233] An autonomous valet parking server can include a communication device configured to communicate with a vehicle, and a processor configured to receive vehicle state information from the vehicle and determine whether a minimum risk maneuver is required during autonomous driving based on at least one of surrounding environment information and the vehicle state information, wherein, in response to the minimum risk maneuver being required, the processor can calculate an emergency stop allowance space for the vehicle to stop based on a speed of the vehicle, a time required for the vehicle to stop, and whether a fixed obstacle or a dynamic obstacle exists.

[0234] The processor can calculate a longitudinal length of the emergency stop allowance space based on the speed of the vehicle and the time required for the vehicle to stop.

[0235] The processor can determine whether a fixed obstacle exists on a driving path of the vehicle, calculate a distance from a side of the emergency stop allowance space closest to the vehicle to the fixed obstacle when the fixed obstacle exists, compare the distance to the fixed obstacle with the longitudinal length of the emergency stop allowance space, and select a smaller value between the distance to the fixed obstacle and the longitudinal length of the emergency stop allowance space as a final longitudinal length of the emergency stop allowance space.

[0236] The processor can calculate a lateral length of the emergency stop allowance space based on a width of the vehicle and a predetermined stop margin constant.

[0237] The processor can calculate a lateral length of the emergency stop allowance space based on a width of the vehicle and a predetermined maximum lane tolerance.

[0238] The processor can determine whether a dynamic obstacle exists within the emergency stop allowance space, compare a distance to the dynamic obstacle with a final longitudinal length of the emergency stop allowance space when the dynamic obstacle exists within the emergency stop allowance space, and adjust the final longitudinal length of the emergency stop allowance space to a smaller value between the distance to the dynamic obstacle and the final longitudinal length of the emergency stop allowance space.

[0239] The processor can determine whether another vehicle exists within the emergency stop allowance space, and move the other vehicle when the other vehicle exists.

[0240] After calculating the emergency stop allowance space, the processor can control movement of the other vehicle to prevent the other vehicle from entering the emergency stop allowance space.

[0241] A method of operating an autonomous driving vehicle can include acquiring surrounding environment information by detecting a surrounding environment of the vehicle during autonomous driving of the vehicle, acquiring vehicle state information by monitoring a state of the vehicle during autonomous driving of the vehicle, determining whether a minimum risk maneuver is required based on at least one of the surrounding environment information and the vehicle state information during autonomous driving, and calculating an emergency stop allowance space for stopping of the vehicle based on a speed of the vehicle, a time required for stopping of the vehicle, and whether a fixed obstacle or a dynamic obstacle exists in response to the minimum risk maneuver being required.

[0242] The calculation of the emergency stop allowance space can include calculating a longitudinal length of the emergency stop allowance space based on the speed of the vehicle and the time required for stopping of the vehicle.

[0243] The calculation of the emergency stop allowance space can include determining whether a fixed obstacle exists on a driving path of the vehicle, calculating a distance from a side of the emergency stop allowance space closest to the vehicle to the fixed obstacle when the fixed obstacle exists, comparing the distance to the fixed obstacle with a longitudinal length of the emergency stop allowance space, and selecting a smaller value between the distance to the fixed obstacle and the longitudinal length of the emergency stop allowance space as a final longitudinal length of the emergency stop allowance space.

[0244] The calculation of the emergency stop allowance space can include calculating a lateral length of the emergency stop allowance space based on a width of the vehicle and a predetermined stop margin constant.

[0245] The calculation of the emergency stop allowance space can include calculating a lateral length of the emergency stop allowance space based on a width of the vehicle and a predetermined maximum lane tolerance.

[0246] The calculation of the emergency stop allowance space can include determining whether a dynamic obstacle exists within the emergency stop allowance space, predicting whether a collision risk exists, and adjusting a final longitudinal length of the emergency stop allowance space when the collision risk exists.

[0247] The foregoing description includes one or more examples, and that the examples given are not the only structure or design which would serve the purpose. Since many examples of the disclosed apparatus and methods are capable of immediate practice, modifications of structure, component layouts, and elements can be practiced by one skilled in the art. Hence, actual structures and embodiments implemented can differ from the description included in this disclosure, and therefore, the scope of the present disclosure should not be limited to any particular structure or embodiment described herein, but interpreted in the light of the scope and spirit of the disclosure.

[0248] As used herein, the term "infer" or "inference" generally means the process of making decisions or conclusions about the state of a system, an environment, and / or a user based on a set of observations made by events and / or data captures. Inferences can be used to identify a particular situation or action, or generate a probability distribution over situations, for example, about the state. It can be probabilistic, meaning it involves computing a probability distribution over states based on an examination of data and events. Inference can also refer to techniques for constructing higher level events from a set of events and / or data. Such inferences allow for estimating new events or actions from a set of observed events and / or stored event data, determining whether events are temporally related, and estimating whether events and data are derived from one or more event and data sources.

[0249] Throughout this disclosure, reference to a component, unit, or module typically refers to items that can be grouped logically together to perform a function or related set of functions. The same reference numbers are generally intended to refer to the same or similar components. Components, units, and modules can be implemented in software, hardware, or a combination of software and hardware. The components, units, modules, and / or functions described above can be implemented by and / or executed by one or more processors. For example, components, units, and / or modules can include processors, microprocessors, graphics processing units, logic circuitry, special purpose circuitry, application specific integrated circuits, programmable array logic, field programmable gate arrays, controllers, microcontrollers, and / or other suitable hardware. Components, units, and / or modules can also include software control modules implemented in, for example, a processor or logic circuitry. These components, units, and / or modules may, for example, include or otherwise have access to memory, such as one or more non-transitory computer-readable storage media, such as random access memory, read only memory, electrically erasable programmable read only memory, erasable programmable read only memory, flash memory / other memory devices, data registers, databases, and / or other suitable hardware. The one or more storage types of media can include any or all of the tangible memory of a computer, processor, etc., or its associated modules, such as various semiconductor memories, tape drives, disk drives, etc., which can provide non-transitory storage for software programming at any time.

[0250] For purposes of this application and the claims, the use of the example phrases “at least one of A; B; or C” or “at least one of A, B, or C” means “at least one of A, or at least one of B, or at least one of C, or at least one of A and at least one of B, and at least one of A and at least one of C, or at least one of A, at least one of B, and at least one of C.” Furthermore, as used herein, example phrases such as “A, B, and C,” “A, B, or C,” “at least one of A, B, and C,” “at least one of A, B, or C,” and the like, can refer to each listed term or all possible combinations of the listed terms. For example, “at least one of A and B” can refer to (1) at least one A; (2) at least one B; or (3) at least one A and at least one B.

[0251] Moreover, as used in this application, terms such as "component," "module," and "system" are intended to refer to a computer-related entity, either hardware, firmware, a combination of hardware and software, software, or computer-related entities, not limited to tangible computer-related entities, hardware, or software. For example, a component can be, but is not limited to being, a process running on a processor, a processor, an object, an executable, a thread of execution, a program, and / or a computer. By way of illustration, both an application running on a computing device and the computing device itself can be a component. One or more components can reside within a process and / or thread of execution and a component can be localized, co-resident, and / or distributed across one or more computers. Also, these components can execute from various computer readable media, such as various memory storage devices. Components can communicate via local and / or remote processes such as in accordance with a signal containing data, e.g., data packets, received from other components and / or across a network, such as the Internet.

Claims

1. An autonomous vehicle, comprising: at least one sensor configured to detect a surrounding environment of the autonomous vehicle to generate surrounding environment information; a controller configured to control one or more operations of the autonomous vehicle; and a processor configured to: monitor a state of the autonomous vehicle to generate vehicle state information; determine, during autonomous driving of the autonomous vehicle, whether a minimum risk maneuver is required based on at least one of the surrounding environment information and the vehicle state information; determine, based on the required minimum risk maneuver, an emergency stop area in which the autonomous vehicle is able to reach a complete stop, wherein the emergency stop area is further determined based on a speed of the autonomous vehicle, a time required for the autonomous vehicle to reach the complete stop, and whether an obstacle is present in a driving path of the autonomous vehicle; and control, via the controller and based on the emergency stop area, the autonomous vehicle to perform an automatic stop.

2. The autonomous vehicle of claim 1, wherein, The processor is configured to determine the emergency stop area by: determining a longitudinal length of the emergency stop area based on the speed of the autonomous vehicle and the time required for the autonomous vehicle to reach the complete stop.

3. The autonomous vehicle of claim 2, wherein, The processor is further configured to: determine whether the obstacle is present in the driving path of the autonomous vehicle, wherein the obstacle is a fixed obstacle; determine a distance between the fixed obstacle and a side of the emergency stop area closest to the autonomous vehicle; and update the emergency stop area by adjusting the longitudinal length of the emergency stop area to match the distance based on the longitudinal length of the emergency stop area being greater than the distance.

4. The autonomous vehicle of claim 1, wherein, The processor is configured to determine the emergency stop area by: determining a lateral length of the emergency stop area based on a width of the autonomous vehicle and a predetermined stop distance constant.

5. The autonomous vehicle of claim 1, wherein, The processor is configured to determine the emergency stop area by: determining a lateral length of the emergency stop area based on a width of the autonomous vehicle and a predetermined maximum lane tolerance.

6. The autonomous vehicle of claim 1, wherein, The processor is further configured to: determine whether the obstacle is present within the emergency stop area, wherein the obstacle is a dynamic obstacle; determine a collision risk associated with the dynamic obstacle; and adjust a longitudinal length of the emergency stop area based on the collision risk.

7. The autonomous vehicle of claim 1, wherein, The processor is further configured to: determine whether the obstacle is present within the emergency stop area, wherein the obstacle is a dynamic obstacle; determine a distance between the dynamic obstacle and a side of the emergency stop area closest to the autonomous vehicle; and update the emergency stop area by adjusting the longitudinal length of the emergency stop area to match the distance based on the longitudinal length of the emergency stop area being greater than the distance.

8. The autonomous vehicle of claim 2, wherein, set the time required for the autonomous vehicle to reach the complete stop to 3 seconds based on the speed of the autonomous vehicle being greater than 0 km / h and less than or equal to 10 km / h.

9. The autonomous vehicle of claim 2, wherein, based on the speed of the autonomous vehicle being greater than 10 km / h and less than or equal to 20 km / h, setting the time required for the autonomous vehicle to reach the complete stop to 4 seconds.

10. The autonomous vehicle of claim 2, wherein, based on the speed of the autonomous vehicle being greater than 20 km / h and less than or equal to 30 km / h, setting the time required for the autonomous vehicle to reach the complete stop to 5 seconds.

11. A server comprising: a communication interface configured to communicate with an autonomous vehicle; and a processor configured to: receive, from the autonomous vehicle, vehicle state information of the autonomous vehicle; determine, based on at least one of surrounding environment information of the autonomous vehicle and the vehicle state information, whether the autonomous vehicle needs a minimum risk maneuver; based on the needed minimum risk maneuver, determine an emergency stop area in which the autonomous vehicle is able to reach a complete stop, wherein the emergency stop area is further determined based on a speed of the autonomous vehicle, a time required for the autonomous vehicle to reach the complete stop, and whether there is an obstacle in a driving path of the autonomous vehicle; and based on the emergency stop area, cause the autonomous vehicle to perform an automatic stop.

12. The server of claim 11, wherein, the processor is configured to determine the emergency stop area by: based on the speed of the autonomous vehicle and the time required for the autonomous vehicle to reach the complete stop, determining a longitudinal length of the emergency stop area.

13. The server of claim 12, wherein, the processor is further configured to: determine whether there is the obstacle in the driving path of the autonomous vehicle, wherein the obstacle is a fixed obstacle; determine a distance between the fixed obstacle and a side of the emergency stop area closest to the autonomous vehicle; and based on the longitudinal length of the emergency stop area being greater than the distance, update the emergency stop area by adjusting the longitudinal length of the emergency stop area to match the distance.

14. The server of claim 11, wherein, the processor is configured to determine the emergency stop area by: based on a width of the autonomous vehicle and a predetermined stop distance constant, determining a lateral length of the emergency stop area.

15. The server of claim 11, wherein, the processor is configured to determine the emergency stop area by: based on a width of the autonomous vehicle and a predetermined maximum lane tolerance, determining a lateral length of the emergency stop area.

16. The server of claim 11, wherein, the processor is further configured to: determine whether there is the obstacle within the emergency stop area, wherein the obstacle is a dynamic obstacle; determine a distance between the dynamic obstacle and a side of the emergency stop area closest to the autonomous vehicle; and based on the longitudinal length of the emergency stop area being greater than the distance, update the emergency stop area by adjusting the longitudinal length of the emergency stop area to match the distance.

17. The server of claim 11, wherein, the processor is further configured to: determine whether there is another vehicle within the emergency stop area; and cause the other vehicle to move out of the emergency stop area.

18. The server of claim 11, wherein, the processor is configured to cause the autonomous vehicle to perform automatic stopping by sending a first signal causing the autonomous vehicle to move into the emergency stopping area, and wherein the processor is further configured to: cause another vehicle to move to prevent the other vehicle from entering the emergency stopping area by sending a second signal causing the other vehicle to drive along a path that prevents the other vehicle from entering the emergency stopping area.

19. A method performed by a device of an autonomous vehicle, the method comprising: determining surrounding environment information of the autonomous vehicle by detecting, via one or more sensors, a surrounding environment of the autonomous vehicle; determining vehicle state information of the autonomous vehicle by monitoring a vehicle state of the autonomous vehicle; during autonomous driving of the autonomous vehicle, determining whether a minimum risk maneuver is required based on at least one of the surrounding environment information and the vehicle state information; based on the required minimum risk maneuver, determining an emergency stopping area in which the autonomous vehicle is able to reach a complete stop, wherein the emergency stopping area is further determined based on a speed of the autonomous vehicle, a time required for the autonomous vehicle to reach the complete stop, and whether an obstacle is present in a driving path of the autonomous vehicle; and controlling the autonomous vehicle to perform automatic stopping based on the emergency stopping area.

20. The method of claim 19, wherein, determining the emergency stopping area comprises: determining a longitudinal length of the emergency stopping area based on the speed of the autonomous vehicle and the time required for the autonomous vehicle to reach the complete stop.

21. The method of claim 20, further comprising: determining whether the obstacle is present in the driving path of the autonomous vehicle, wherein the obstacle is a fixed obstacle; determining a distance between the fixed obstacle and a side of the emergency stopping area closest to the autonomous vehicle; and based on the longitudinal length of the emergency stopping area being greater than the distance, updating the emergency stopping area by adjusting the longitudinal length of the emergency stopping area to match the distance.

22. The method of claim 19, wherein, determining the emergency stopping area comprises: determining a lateral length of the emergency stopping area based on a width of the autonomous vehicle and a predetermined stopping distance constant.

23. The method of claim 19, wherein, determining the emergency stopping area comprises: determining a lateral length of the emergency stopping area based on a width of the autonomous vehicle and a predetermined maximum lane tolerance.

24. The method of claim 19, further comprising: determining whether the obstacle is present within the emergency stopping area, wherein the obstacle is a dynamic obstacle; determining a collision risk associated with the dynamic obstacle; and adjusting a longitudinal length of the emergency stopping area based on the collision risk.