Techniques for security checking of trajectories

CN122893147APending Publication Date: 2026-10-09ROBERT BOSCH GMBH
View PDF 1 Cites 0 Cited by

Patent Information

Application Number
CN202580019417.9
Authority / Receiving Office
CN · China
Patent Type
Applications(China)
Current Assignee / Owner
Priority Date
2024-03-05
Filing Date
2025-01-28
Publication Date
2026-10-09

AI Technical Summary

Benefits of technology

[0121]根据又另一方面,提供一种计算机可读的介质,在其上存储有程序元件,所述程序元件能够被安全性检查模块读取并实施,以便在所述程序元件被所述安全性检查模块实施时,执行根据所述方法方面的、用于对用于至少部分自动化运行的车辆的规划周期内轨迹进行安全性检查的方法的步骤。

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure CN122893147A_ABST
    Figure CN122893147A_ABST
Patent Text Reader

Abstract

Techniques for safety checking of trajectories within a planning period for a vehicle operated at least partially automatically include a method in which a vehicle environment model is read in (S104) from an environment model memory, the environment model pertaining to the planning period and representing a dynamic development of a traffic scenario. Based on assumptions about aspects of the read-in (S104) environment model and / or safety control laws, states and regions are classified (S107) according to safety objectives for the vehicle. The regions classified (S107) according to the safety objectives include sets formed by states classified (S107) according to the safety objectives. A list of trajectories to be checked is received (S110) and filtered twice. An intermediate result of the first filtering (S114) includes only trajectories whose states in the planning period have been at least classified (S107) as temporarily safe and which lead into regions after the planning period that have been at least classified (S107) as invariant safe transferable. The second filtering (S116) includes a probabilistic estimate of the validity with respect to the assumptions about aspects of the read-in (S104) environment model and / or safety control laws.
Need to check novelty before this filing date? Find Prior Art

Description

Technical Field

[0001] This patent application relates to a technique for performing safety checks on trajectories during a planning cycle for a vehicle or another system that operates at least partially automatically. Specifically, a method, a safety check module, a system including the safety check module, a computer program, and a computer-readable storage medium are provided. Background Technology

[0002] Automated vehicles must find ways to cope with complex situations that can change rapidly and unexpectedly. Therefore, to solve driving tasks, systems that are highly safety-critical or adhere to safety objectives are required. From the perspective of functional safety (ISO 21212) and safety of the intended functionality (SOTIF; ISO 21448), a multi-path architecture is suitable for such systems, in which at least two planning modules generate trajectories.

[0003] Methods for motion planning of a system are known. Here, we introduce by reference [1, 2], in which a first invariant set around the vehicle and another invariant set as the target region are determined based on the vehicle's own state. Here, "invariant set" is generally understood as a set of states that are invariantly secure (IS) with respect to time.

[0004] A set-based approach was proposed in reference [2], but without probabilistic components. Here, we introduce reference [4] by reference, which combines the set-based approach with a probabilistic approach for evaluating (determined and immutable) trajectories. Evaluation is performed within the planning module itself. Similar to reference [1], planning is performed from IS zone to IS zone in reference [4]. Trajectory selection is based on safety and performance (cost function) criteria and is targeted at SOTIF.

[0005] By referencing the content of reference [3], another method proposed by Cui et al. in reference [3] does not use a set-based approach and therefore does not use the IS region.

[0006] In order to ensure safe, at least partially automated driving, both ISO 21212 (functional safety) and ISO 21448 (SOTIF) standards must be met. Summary of the Invention

[0007] The solution according to the invention is described below with reference to the claimed method for performing safety checks on the trajectory of a vehicle for at least partially automated operation within a planning cycle. In principle, features, advantages, or alternative embodiments may be attributed to various other claimed subjects (e.g., safety check modules, systems, computer programs, or computer program products), and vice versa. In other words, claims for the safety check module and / or claims for a system including the safety check module can be improved by combining the features described or claimed in the method, and vice versa. In this case, the functional features of the method are embodied by the structural units of the safety check module and / or the system, and vice versa.

[0008] According to the method, a method (especially computer-implemented) is provided for performing a safety check on the trajectory during a planning cycle for at least partially automated operation of a system, particularly a vehicle. The method includes the steps of: reading in an environment model (e.g., from an environment model memory), the environment model being associated with the planning cycle and used for the at least partially automated operation of the system, particularly the vehicle. The environment model specifically represents the dynamic development of the traffic scene around the at least partially automated vehicle. The method further includes the steps of: classifying states and zones based on assumptions about the read-in environment model and / or based on safety control laws about the read-in environment model, according to at least one safety objective for the at least partially automated vehicle (e.g., at least one first safety objective for a state and at least one second safety objective for a zone). Zones classified according to the at least one safety objective (e.g., the second safety objective) include at least one set formed by states classified according to the at least one safety objective (e.g., the first safety objective). In particular, the states can be classified based on the assumptions and the zones can be classified based on the safety control laws. The assumptions can be read from an assumption memory. Alternatively or additionally, the safety control laws can be read from a control law memory.

[0009] The method further includes the step of receiving (e.g., from at least two planning modules) a list of trajectories to be inspected for the at least partially automated operation of the vehicle, the trajectories being for the planning period. The method further includes the step of performing a first filtering on the received list of trajectories. An intermediate result of the first filtering includes only trajectories whose state during the planning period has been at least classified as Temporarily Safe (TS), and whose trajectory, after the end of the planning period, is allowed to pass into a zone at least classified as Invariant Safety Transferable (IS Transferable). The method further includes the step of performing a second filtering on the intermediate result of the first filtering of the list of trajectories, based on probability estimates of the validity of assumptions about the read-in environment model and / or the validity of safety control laws about the read-in environment model, at least during the planning period. The result of the second filtering of the list includes only trajectories (e.g., only one trajectory) whose probability estimate exceeds a threshold of the at least one safety objective (e.g., a first and / or a second safety objective).

[0010] The safety of at least partially automated driving can be improved by employing techniques for safety checks on trajectories during the planning cycle of vehicles operating at least partially automated, particularly regarding situations that may change rapidly and at least partially unexpectedly. Furthermore, it is possible to achieve a smooth driving style for components of the at least partially automated vehicle, and / or to ensure driving comfort within safe trajectories. In particular, the method can act as a filter, eliminating trajectories deemed unsuitable for at least partially automated operation when formal safety cannot be guaranteed (e.g., the absence of at least a TS state and / or failure to pass through an IS transfer zone). Alternatively or supplementarily, the technique can select the available trajectory that is optimal in terms of safety (e.g., for the at least partially automated vehicle and other traffic participants in the traffic scenario). If no safe trajectory is received, a suitably modified trajectory can be provided. Alternatively or supplementarily, the technique can also enable contingency planning.

[0011] A traffic scenario involves the surrounding environment of the at least partially automated vehicle. In addition to the at least partially automated vehicle (also referred to as: autonomous vehicle), a traffic scenario may also include at least one other (also referred to as: additional) traffic participant, particularly additional vehicles, pedestrians, motorcyclists, and / or cyclists. The traffic scenario is represented in an environmental model.

[0012] (For example, vehicles operating at least partially automated and / or additionally) can be road-based vehicles (e.g., passenger cars or freight vehicles) with automated or partially automated driving capabilities at levels L1 to L5 (especially higher levels, such as L4 or L5 within these levels). Automated operation can include full automation (also known as autonomous driving, especially L5), at least partial automation (e.g., highly automated L4, conditionally automated L3, or partially automated L2), and / or driver assistance systems (e.g., including distance-adjustable cruise control at L1). For example, partially automated driving capabilities can include traffic jam navigation, which is used, for example, only within a defined area and / or a defined time period. Alternatively or additionally, the at least partially automated system can include a robot, which can move, in particular, on a factory site. The vehicle to which trajectory safety checks are performed can also be referred to as an autonomous vehicle, distinguished from other vehicles in the traffic scenario.

[0013] Traffic scenarios and / or (especially dynamic and / or periodically updated) environmental models can be detected or created based on sensor data from sensors such as video cameras, radar sensors, and / or lidar sensors, particularly those on vehicles. The environmental model can include an agent for each traffic participant (e.g., one agent for at least partially automated vehicles and one agent for each other traffic participant). The dynamic evolution of traffic scenarios can include predicting and / or negotiating the behavioral arrangements of other traffic participants.

[0014] Traffic scenarios evolve over time. These scenarios are detected (especially through sensing). The state of a traffic scenario involves its state at a given time step.

[0015] The environment model can be updated every 100ms, which corresponds to a frequency of 10Hz.

[0016] The traffic scene (also referred to as the environment and / or surrounding environment) of a vehicle operating at least partially automated can be spatially defined by the maximum operating range of one or more sensors from which sensor data is received and / or by the maximum distance from the vehicle operating at least partially automated. For example, the maximum operating range of a lidar sensor can reach 200m. Alternatively or additionally, the extended scale and / or visibility range of the environment can be related to the speed of the vehicle operating at least partially automated.

[0017] The environment of a vehicle operating at least partially automated may include at least one area located in front of the vehicle in the direction of travel, and preferably also includes an area located behind the vehicle. According to another embodiment, the environment may further include an area located to the side of the vehicle, such as a lane parallel to and / or an oncoming lane of the vehicle.

[0018] Traffic scenarios can be asymmetrically distributed around the at least partially automated vehicle. For example, there can be more sensors oriented forward (and / or backward) (and / or with a greater range of action) than sensors oriented to the sides of the at least partially automated vehicle.

[0019] The method for performing safety checks on a trajectory can be implemented by a safety check module (also known as: a module for performing safety checks on input trajectories; Safety Checker). The safety check module can be connected downstream of one or more (especially two) planning modules. The one or more (especially two) planning modules can each plan at least one trajectory to be checked (also known as: input trajectory).

[0020] A list of trajectories to be inspected (also known as a set) can be received from multiple (especially two) planning modules.

[0021] The environmental model may include (particularly with the aid of received sensor data) identified objects and / or traffic participants (e.g., pedestrians, cyclists, motorcyclists, and / or one or more other vehicles) located on a map, particularly a digital map and / or a raster map. The identified objects and / or traffic participants may be limited, particularly based on the map, to those that could potentially contribute to obstacles, conflict situations, and / or hazardous conditions. For example, traffic participants moving away from the at least partially automated vehicle from the side and / or rear are not necessarily required to be modeled in the environmental model of the at least partially automated vehicle.

[0022] The state of a vehicle (and / or traffic scenario) that is operating at least partially automated can be dynamic and / or time-dependent (also known as: time-state pairs). For example, the state for each time point can include position, orientation, speed, acceleration, and / or steering angle.

[0023] Preferably, the states classified according to the at least one safety objective (e.g., a first safety objective) can be categorized into three classes, and in particular, Invariably Safe (IS), Temporarily Safe (TS), IS Transitionable, and / or Unsafe. An IS state is guaranteed to be safe at every point in time (e.g., every relevant point in time and / or until a predetermined end point is reached, particularly after the planning scope and / or after the end of the planning period) (e.g., a parked state in a parking space). Alternatively or supplementarily, a TS state is safe for a time period defined by time (e.g., during the planning period). Alternatively or supplementarily, a state is IS Transitionable when there are one or more safety control laws by which a state can be transitioned to an IS state solely through a TS state. Further alternatively or supplementarily, an unsafe state (especially during the planning period) does not meet the criteria for "guaranteed to be safe" (e.g., the presence of an unavoidable risk of accident, particularly the risk of an accident with other road users).

[0024] The IS state and / or the IS transferable state are respectively the TS state.

[0025] Alternatively or supplementarily, a zone is a set of states. IS states can be generated, in particular, based solely on assumptions (e.g., traffic-induced parking is safe, thus the state with disappearing velocity, i.e., v=0, is safe). For example, an IS transition zone is generated in such a way that the states contained within that IS transition zone can be transformed into IS states by means of one or more of the aforementioned safety control laws.

[0026] The planning period (also known as: planning phase, planning scope and / or the time period up to new planning (also known as: replanning, technical term: replanning), the planning period being particularly for the trajectory of vehicles operating at least partially automated) may include: for example, up to 20 seconds, for example, up to 15 seconds, for example, up to 10 seconds, for example, up to 8 seconds and / or for example, up to 3 seconds.

[0027] The planning period can be sampled in multiple (e.g., one to five) time steps. A time step (also known as a sampling step) can include less than one second, such as a time period between 100ms (and / or, for example, a sampling frequency of 10Hz) and 500ms.

[0028] The prediction range (especially for the dynamic development of other traffic participants) can vary depending on the automated driving function and / or the overall system scheme (e.g., between 500 ms and 15 s, and / or especially at least as long as the planning range). Alternatively or supplementarily, the control law can often exist in analytical form, so the description of the corresponding state can therefore be (at least relatively) independent of the prediction range.

[0029] The methods implemented in the security check module can be synchronized with the planning of the trajectory to be checked in one or more (especially two) planning modules.

[0030] The region may include a set of (especially the inferred and / or determined) states of at least partially automated vehicles (and / or traffic scenarios).

[0031] Classifying regions enables the application of set-based and / or random methods, particularly for probability estimation of the validity of assumptions, the validity of security control laws, and / or the achievement of at least one security objective (e.g., a first and / or a second security objective).

[0032] Zones classified according to at least one safety objective (e.g., a second safety objective) can be IS, IS-transferable, and / or unsafe. An IS zone is a set of IS states (and / or zones that are safe for all times). Alternatively or supplementarily, an IS-transferable zone is a set of IS-transferable states (e.g., an intersection may be assigned to an IS-transferable zone for a specific time period during which, according to an environmental model, no other traffic participants drive or enter the intersection) and / or a set of states that can transition to an IS state using a safe trajectory. Alternatively or supplementarily, a TS zone may be safe only for a predetermined time period, for example, if an environmental model predicts that no other traffic participants will intrude into the spatial boundaries of the zone. Further alternatively or supplementarily, an unsafe zone is a set of unsafe states.

[0033] For example, an intersection may be classified as an IS (Interchangeable Zone) when braking and / or stopping at a stop line is possible (especially timely). Alternatively or supplementarily, following other traffic participants (especially vehicles) may be IS-transferable and / or TS-transferable. Alternatively or supplementarily, a zone may be unsafe when conflict-free (and / or accident-free) driving is not possible.

[0034] A safe trajectory can be TS and / or IS (e.g., for each planned state along the trajectory).

[0035] (Especially for security) trajectories do not necessarily have to start and / or end in the IS region, which is particularly different from the trajectories used by Pek et al. in references [1] and [2]. As a result, the application scenarios can be significantly expanded or the number of application scenarios can be increased.

[0036] The set of states that can be reached using (especially safe) trajectories (and / or modified trajectories) can be called the reachable set.

[0037] For example, the parking trajectory itself is not IS because, when at least partially automated, the sequence of motion states could lead to the vehicle potentially colliding with another vehicle. If there are one or more safety control laws that can transition a vehicle operating at least partially automated into an IS state (especially if the parking trajectory is a result of these safety control laws), then the state of the trajectory (also known as the trajectory point) lies within the IS transition zone.

[0038] Assumptions regarding the read-in environmental model may be independent of the at least partially automated vehicle and / or independent of sensor data, especially sensor data upon which the environmental model was created.

[0039] Assumptions regarding the environmental model being read in may include assumptions about dynamic traffic development, such as compliance with local traffic rules, and / or assumptions about the reasonable behavior of other traffic participants, in particular: the rational driver assumption, and / or the absence of drivers traveling in the wrong direction.

[0040] A violation (and / or invalidity) of a hypothesis may include, for example, a violation of traffic rules (e.g., other road users exceeding speed limits, violating traffic signal phases and / or illegally crossing intersections in violation of priority rules, and / or the presence of a driver traveling in the wrong direction).

[0041] Safety control laws may include criteria (e.g., based on vehicle physical characteristics and / or vehicle technical specifications, such as braking deceleration) for regulating and / or controlling the at least partially automated vehicle. Alternatively or additionally, safety control laws may include (e.g., an Intelligent Driver Model relating to the at least partially automated vehicle). The Intelligent Driver Model may be related to the at least partially automated vehicle (the vehicle itself). The Intelligent Driver Model can serve as the basis for deriving adaptive cruise control adjustments, which can in particular be extended into safety control laws.

[0042] Probabilistic predictions (e.g., for other traffic participants) may include estimating uncertainties in the form of sets of states assigned to zones (and / or at least one safety objective, such as a first and / or a second safety objective). This ensures both functional safety (e.g., according to ISO 21212—Intelligent Transportation Systems—Communications Access for Land Mobiles (CALM)—2G Radio Systems) and formally guaranteed safety, particularly the safety of the intended function (e.g., according to ISO 21448—Road Vehicles—Safety of the Intended Functionality).

[0043] Probability estimation, particularly a threshold for the at least one security objective (e.g., a first and / or a second security objective), can parameterize the probability that "the examined trajectory (and / or modified trajectory) is safe." For example, "below the threshold" could indicate that the safety of the examined trajectory (and / or modified trajectory) cannot be guaranteed. "Above the threshold" could indicate that the corresponding trajectory is likely safe.

[0044] The probability estimation and / or achievement of the at least one security objective may be associated with a security metric (and / or a quality function). The threshold of the at least one security objective (e.g., a first and / or a second security objective) may be a threshold of the security metric. In particular, a high value of the security metric may correspond to high security (and / or high probability security) of the trajectory. Alternatively or additionally, a low value of the security metric may correspond to low security (and / or low probability security) of the trajectory.

[0045] The method may further include the step of receiving sensor data regarding the dynamic development of a traffic scene around the at least partially automated vehicle. Alternatively or additionally, the method may include the step of creating an environmental model, particularly by using (and / or based on) the received sensor data.

[0046] Sensor data can be received from at least one sensor system comprising one or more sensors, particularly from camera devices (e.g., video cameras), radar devices, lidar devices, ultrasonic devices, motion sensors, and / or thermal imaging sensors. Alternatively or additionally, sensor data may include data from a location determination system and / or a navigation system (e.g., GPS or Galileo), and / or traffic messages or other messages received wirelessly from a transmitting station. Furthermore, alternatively or additionally, sensor data may include vehicle-to-everything (V2X, also known as Car2X) data. V2X can include vehicle-to-vehicle (V2V), vehicle-to-road (V2R), vehicle-to-infrastructure (V2I), vehicle-to-network (V2N), and / or vehicle-to-person (V2P) communications, particularly wireless communications.

[0047] Sensor systems can be deployed inside the vehicle and / or on vehicles that are at least partially automated (e.g., camera devices mounted on the vehicle). Alternatively or additionally, sensor systems can be deployed outside the vehicle (e.g., infrastructure-based sensor systems, particularly road-mounted camera devices for traffic monitoring, location determination systems and / or navigation systems, weather determination systems, and / or sensor systems deployed internally on other road users). Sensor data received from sensor systems outside the vehicle can be transmitted (and / or received) wirelessly, for example via V2X.

[0048] Sensor data can be currently received and / or temporarily stored. Alternatively or additionally, sensor data can include historical data, particularly relating to one or more earlier states of a traffic scenario.

[0049] The vehicle, which operates at least partially automatically, may store map data of the surrounding environment (e.g., from a navigation system). Alternatively or additionally, the received sensor data may (especially additionally) include map data of the surrounding environment.

[0050] Receiving sensor data about traffic scenes and / or about other traffic participants (also known in technical terms as perception) may include preprocessing of dynamic and / or static objects (e.g., another vehicle, pedestrian, and / or especially static obstacles), especially object classification (and / or object recognition), and particularly summarizing them in a list of objects.

[0051] With the help of sensor data detected (especially on the at least partially automated vehicle), the environment of the at least partially automated vehicle can be monitored in real time and the environment model can be reliably created, at least within the range of one or more corresponding sensors (e.g., within the line of sight of the camera up to the obstacle).

[0052] Using sensor data received wirelessly (e.g. via radio or data interface) or wiredly (e.g. from sensors arranged inside the vehicle), the environmental model can be extended to areas that cannot be detected by sensors arranged on the at least partially automated vehicle, such as areas behind obstacles that limit the field of view of cameras arranged on the at least partially automated vehicle.

[0053] The creation of the environment model can be based on a digital map (and / or raster map) of the surrounding environment. Each identified object can be assigned a location on the digital map (especially in the object list).

[0054] With the help of the established environmental model, both static and dynamic traffic conditions can be reliably assessed.

[0055] The method may further include the step of aggregating the received sensor data. In particular, the sensor data may be received from different sensors, sensor systems, and / or sources. The aggregation may include combining sensor data from different sources, sensors, and / or sensor systems. Alternatively or additionally, the aggregation may include combining sensor data belonging to different time steps (e.g., within one or more, especially past planning periods).

[0056] In an extended embodiment of the invention, additional sensor data regarding dynamic traffic regulations in a traffic scenario (and / or the surrounding environment of the at least partially automated vehicle) may be received, particularly regarding traffic lights with phase states (e.g., red light phase, green light phase).

[0057] Sensor data representing the actual state can be at least partially recorded (and / or detected) in the corresponding time step. Alternatively or supplementarily, sensor data can be at least partially recorded (and / or detected) in one or more earlier (also referred to as: previous, earlier, and / or past) time steps. Alternatively or supplementarily, the actual state of a traffic scenario can be understood based on the history of the traffic scenario. For example, the speed (and / or acceleration) of the at least partially automated vehicles and / or other traffic participants in the actual state can be extrapolated (and / or determined) using sensor data (especially position sensor data) from preferred multiple earlier time steps of the same vehicle.

[0058] In one embodiment, received sensor data can be aggregated over a predetermined earlier time span (and / or a predetermined number of earlier time steps) to represent the actual state. Alternatively or supplementarily, a compressed state can be stored, which is updated (e.g., at each time step) based on newly received sensor data.

[0059] The trajectory can be created (and / or planned) based on a first environmental model (especially in the planning module). In the verification step, an environmental model, optionally created based on received sensor data (especially redundantly, for example for safety checks), can be compared with the first environmental model in terms of consistency, and corrective measures can be enabled if possible discrepancies exist.

[0060] The step of “classifying states and zones according to at least one safety objective for the vehicle operating at least partially automated” may include the following steps: classifying states according to at least one first safety objective for the vehicle operating at least partially automated, based on assumptions about the read-in environment model. The assumptions may be read from the assumption memory. Alternatively or supplementarily, the step of “classifying states and zones according to at least one safety objective for the vehicle operating at least partially automated” may include: classifying zones according to at least one second safety objective for the vehicle operating at least partially automated, based on a safety control law about the read-in environment model. Zones classified according to the second safety objective may include at least one set formed by states classified according to the first safety objective. The safety control law may be read from the control law memory.

[0061] The method may further include the step of: first sorting the received list of trajectories to be inspected according to the priority of the set of boundary conditions to be satisfied (and / or at least one security metric). Alternatively or supplementarily, the method may include the step of: second sorting the trajectories resulting from the second filtering according to the value of the probability estimate. Alternatively or supplementarily, the method may include the step of: second sorting the trajectories resulting from the second filtering according to the result of the first sorting. In particular, the trajectories may be second sorted according to at least one security metric of the trajectories.

[0062] The set of boundary conditions to be met (and / or already met) (especially for the safety of the at least partially automated vehicle) can also be referred to as behavioral patterns. These behavioral patterns can be arranged in a list according to priority (and / or according to the at least one safety metric). The list can be created internally, particularly in the components used to implement the method. Alternatively or additionally, the list can be received from an external source, and its correctness, consistency, and / or completeness can be checked.

[0063] The corresponding security metrics (and / or priorities) can be multi-level and can include multiple security levels and / or security objectives.

[0064] A sorted list of tracks to be checked (and / or checked) can prioritize those with high security (and / or high security level).

[0065] Boundary conditions may include (for example, intervals and / or thresholds for one or more of the following parameters:) velocity, acceleration, steering angle, position, orientation, and / or (e.g., position) time. In particular, the set of boundary conditions may include combinations of at least two parameters, such as a combination of position and velocity, and / or include the maximum value of acceleration and / or velocity. Especially for the position coordinates of a region, boundary conditions may be associated using polygons.

[0066] For example, a vehicle operating at least partially automated may approach an intersection to cross. A polygon extending from, for example, the lane with the maximum permissible speed to the intersection is obtained as a first boundary condition. A second boundary condition is, for example, a polygon extending beyond the intersection. This polygon not only limits the maximum permissible speed but also additionally defines a time interval within which the vehicle must cross the intersection. A third polygon, for example, represents the lane of the at least partially automated vehicle, extending from behind the intersection to a planned distance (e.g., several hundred meters). The polygon starting from the intersection also includes speed limits as another boundary condition. In this example, a set of boundary conditions, which can be represented by three (3) polygons, is obtained, which geometrically describe (e.g., up to the intersection, at the intersection, and after the intersection) the corresponding set of states, including (or adding) dynamically defined time and / or speed intervals for the corresponding set of states.

[0067] The set of boundary conditions (and / or behaviors) to be satisfied can be stored in a database and are callable (e.g., for comparison with the received trajectory to be inspected).

[0068] The method may further include the step of providing the trajectory resulting from the second filtering (in particular, the best and / or preferred trajectory derived from the second sorting) to the adjustment and / or control of the at least partially automated vehicle for implementing the trajectory. Thus, a safety-checked trajectory can be executed and implemented during vehicle adjustment. The at least partially automated vehicle can then perform safe movement based on the selected and safety-checked trajectory by controlling (and / or adjusting) at least one actuator according to the selected trajectory.

[0069] Alternatively or additionally, control signals may be output to at least one actuator of the at least partially automated vehicle based on the trajectory selected as a result of the second filtering and / or subsequent (e.g., according to priority) second sorting.

[0070] The state classified according to the at least one security objective (e.g., a first security objective) may include at least three states, particularly an invariant security (IS) state, a TS state, and / or an insecure state.

[0071] The IS and TS states can satisfy at least one of the safety objectives (e.g., the first safety objective), particularly the safety objective of collision-free driving during the planning period.

[0072] Unsafe conditions along the planned trajectory (e.g., during the planning period) may prevent the first safety objective from being met (e.g., guaranteed accident-free driving).

[0073] The zones classified according to the at least one security objective (e.g., a second security objective) may include at least three types of zones, particularly IS zones, IS transferable zones, and / or insecure zones.

[0074] The IS zone and the IS transfer zone can satisfy at least one of the safety objectives (e.g., a second safety objective), especially the safety objective of continuing to drive without collisions after the planning period.

[0075] Unsafe zones (especially those following the planning period) may hinder the fulfillment of the second safety objective (e.g., guaranteed accident-free continued driving).

[0076] The area can be extended into the future (and / or further developed). The specific timeframe (and / or forecast range) can depend on the system design and may vary considerably (e.g., from 500ms to 20s, depending on the system design). It may be meaningful to extend the forecast over at least several planning cycles.

[0077] If the result of the second filtering (especially the list of trajectories filtered by the second filtering) is empty, trajectories included in the intermediate results of the first filtering can be selected. Optionally, the selected trajectory can be modified after the starting point of the selected trajectory in the planning cycle. The modification may include applying the safety control law.

[0078] The selected trajectory can be considered safe in the sense that it satisfies at least one of the safety objectives (e.g., a first and / or a second safety objective) (e.g., no probability estimation is required). Alternatively or supplementarily, only the starting point of the trajectory (e.g., based on a probability estimate made for each time step in the planning period) can be classified as safe, and the remainder of the trajectory can be modified during the planning period such that the modified trajectory meets a threshold of at least one of the safety objectives (e.g., the first and / or the second safety objective).

[0079] The trajectory starting point, which is subsequently modified within the planning period, can be determined based on probability estimates made for each time step within the planning period. For example, the trajectory starting point can persist until a last time step at which a threshold of the probability estimate for achieving the at least one security objective (e.g., the first and / or second security objective) is reached.

[0080] If the intermediate results of the first filtering (especially the list of trajectories filtered by the first filtering) are empty, a trajectory received (especially from one of the planning modules) can be selected, and the trajectory can be modified after the starting point of the trajectory in the planning cycle. The modification may include applying the safety control law.

[0081] By modifying the received trajectory (and / or the trajectory after the first filter) based on (one and / or more) the security control laws, a formally secure modified trajectory can be provided. This formally secure modified trajectory can also be called a fallback trajectory.

[0082] The modified selected trajectory can be or include the highest priority received trajectory.

[0083] If the result of the second filter is empty (and / or the intermediate result of the first filter is empty), the selected (especially alternative selection) trajectory (and / or modified trajectory) can be determined based on a predetermined list of damage categories (e.g., possible damage categories).

[0084] Using a list of damage categories (e.g., possible damage categories) can help avoid personal injury and allow for damage to the vehicle's body panels. For example, pedestrian avoidance can be prioritized over hitting a vehicle traveling in front and / or being hit by a vehicle following behind (e.g., due to strong and / or sudden braking at a crosswalk).

[0085] Assumptions regarding the read-in environmental model may include: assumptions based on generally valid rules and / or assumptions made by other traffic participants regarding the dynamic development of the traffic scenario. Alternatively or additionally, these assumptions may be independent of the at least partially automated vehicle and / or independent of the received sensor data used to create the environmental model.

[0086] Generally valid rules may include traffic rules, (e.g., speed-related) distance rules, and / or collision rules (e.g., when a collision is unavoidable, it is preferred to collide with another object or vehicle rather than with a pedestrian, cyclist, or other unprotected person).

[0087] Assumptions about other reasonable traffic participants may include the rational driver assumption. Alternatively or additionally, assumptions about the read-in environmental model may include assumptions about the driving physics of other traffic participants (e.g., weather-related).

[0088] Reasonable assumptions about other traffic participants (and / or rational driver assumptions) may include that the driver complies with traffic rules that are valid in the environment. With the help of received sensor data, rule violations (and / or invalid assumptions) can be detected, such as exceeding the maximum permitted speed and / or illegal turns.

[0089] In one embodiment, when received sensor data indicates a violation (and / or invalidity) of a corresponding hypothesis, one or more generally valid rules and / or reasonable assumptions of other traffic participants may be omitted or not implemented when classifying the state (and / or when creating a modified trajectory).

[0090] The rational driver assumption can involve other traffic participants and / or influence predictions (and / or predictions of the temporal development of traffic scenarios). An intelligent driver model (technical term: Intelligent Driver Model) or the distance-adjustable cruise control (technical term: Adaptive Cruise Control, ACC) derived therefrom can be expanded into one or more safety control laws (also known as: Safe Control Law(s)) and can involve the at least partially automated operation of the vehicle (also known as: autonomous vehicle).

[0091] Invalid and / or violated assumptions about the read-in environmental model (especially in the probabilistic estimation of these assumptions during the second filtering step) can be based on errors and / or uncertainties in the environmental model, such as due to the discreteness of sensor data. For example, the inapplicability (and / or uncertainty) of the possible locations of other traffic participants (and / or at least partially automated vehicles) may contribute to the invalidity of the assumptions. The discreteness of sensor data and / or inaccuracies in the validity of the assumptions may increase with the length of the trajectory during (and / or after) the planning cycle. Therefore, in one implementation, the trajectory length can be considered when performing safety checks, for example, by selecting safety targets or other criteria for safety checks in a different manner for long trajectories than for short trajectories. The mechanism outlined herein can, for example, be derived by terminating the probabilistic evaluation from the first crossing of the nearest IS transferable zone.

[0092] Alternatively or additionally, the assumptions may be time-dependent and / or weather-dependent (e.g., on black ice and / or waterskiing), and / or may be invalid and / or violated due to changing road conditions.

[0093] Assumptions regarding the read-in environmental model can be stored in a digital database (especially in the hypothesis storage), and particularly locally in the at least partially automated vehicle.

[0094] Safety control laws may include criteria for regulating and / or controlling the at least partially automated vehicle, and / or an intelligent driver model for the at least partially automated vehicle.

[0095] The Intelligent Driver Model (IDM) can include a time-continuous vehicle following model for simulating road traffic. The IDM can describe the dynamics of the position and velocity of individual vehicles (especially those operating at least partially autonomously and / or other traffic participants). Acceleration can be constrained by conditions for empty roads and / or roads occupied by other traffic participants. In particular, distances to other traffic participants (e.g., minimum distances) can be considered in the development of motion.

[0096] Safety control laws can be adjustable and / or vehicle-specific. The latter means that the safety control law is based on vehicle-specific parameters. For example, braking deceleration and / or acceleration capabilities can be related to the technical specifications of the vehicle, which is at least partially automated.

[0097] Criteria for regulating and / or controlling the at least partially automated operation of the vehicle may include: coasting slowly, (especially strongly) braking, maintaining speed for a predetermined number of control cycles, driving according to ACC (preferably in combination with "braking safely, especially before a possible collision zone"), and / or braking in a manner that optimizes aggression, limits aggression, and / or limits acceleration. "Coasting slowly" is suitable, for example, at the edge of the roadway.

[0098] "(Especially strong and / or safe) braking" may be appropriate when approaching potential conflict zones (such as intersections, railway crossings, zebra crossings, and / or oncoming lanes in the event of a planned overtaking maneuver).

[0099] "Maintaining speed for a predetermined number (e.g., three to four) control cycles" can be suitable for driving on straight sections of road, rural roads and / or highways, especially to enable replanning of the trajectory and / or avoidance of harm to flowing traffic.

[0100] "Driving according to ACC" can avoid endangering moving traffic by following the vehicle in front. Here, the danger caused by following through a potential conflict zone can be minimized by replacing ACC with braking (e.g., at the stop line in a potential conflict zone).

[0101] Safety control laws can be pre-defined (and / or determined) based on the conditions. For example, different safety control laws can be used for driving in urban traffic and driving on highways.

[0102] Safety control laws (especially those that can be determined based on the situation) can be stored in a digital database (especially in the control law memory), and particularly locally stored in the at least partially automated vehicle.

[0103] Braking in a manner that optimizes, limits, and / or limits jeopardy can minimize the danger to other road users, especially due to unexpected driving behavior.

[0104] Alternatively or additionally, the criteria for regulation and / or control may include: assumptions about the driving physics of the at least partially automated vehicle and / or assumptions about the set of boundary conditions to be satisfied for the trajectory to be examined.

[0105] Classification of states and / or regions based on assumptions and / or security control laws can be performed using white-box modeling. White-box modeling can include a complete model of a technical system derived from, for example, physical laws.

[0106] Alternatively or supplementarily, the classification of states and / or regions based on assumptions and / or safety control laws can be performed using gray box modeling. In gray box modeling, although the process can be clearly defined, the specific form, especially the specific form regarding the parameters sought and / or set, can be extracted from the data.

[0107] When performing machine learning based on the gray-box principle (and / or white-box principle), the focus can be on the transparency and interpretability of the results. Gray-box models (and / or white-box models) can provide insights into the decision-making process and make that process interpretable and verifiable. Examples of machine learning performed in gray-box (and / or white-box) formats are linear regression, decision trees, and rule-based systems.

[0108] Assumptions about the driving physics of the at least partially automated vehicle and / or other traffic participants may include physical specifications (e.g., wheelbase, weight, and / or acceleration). Driving physics and / or physical specifications can be implicitly determined through a vehicle model.

[0109] Assumptions about the set of boundary conditions to be satisfied may include determining physical parameters, particularly limits on jerkiness, acceleration, and / or braking (e.g., using intervals and / or thresholds). These assumptions may be important for better predicting the driving of other traffic participants and / or may extend the component life of the at least partially automated vehicle and / or prevent component wear of the at least partially automated vehicle.

[0110] According to the apparatus, a safety check module is provided for performing safety checks on trajectories during a planning cycle for at least partially automated operation of a system, particularly a vehicle. The safety check module includes an environment model interface configured to read in an environment model (particularly from an environment model memory) that is associated with the planning cycle and is used for the at least partially automated operation of the vehicle. The environment model represents the dynamic development of a traffic scene around the at least partially automated vehicle. The safety check module further includes a classification unit configured to classify states and zones based on assumptions about the read-in environment model and / or based on safety control laws about the read-in environment model, according to at least one safety objective (e.g., a first and / or a second safety objective) for the at least partially automated vehicle. Zones classified according to the at least one safety objective (e.g., the second safety objective) include at least one set formed by states classified according to the at least one safety objective (e.g., the first safety objective). The assumptions can be read from an assumption memory. Alternatively or additionally, the safety control laws can be read from a control law memory.

[0111] The safety inspection module further includes a receiving interface configured to receive a list of trajectories for the at least partially automated operation of the vehicle to be inspected, the trajectories being for the planning period. The safety inspection module also includes a first filtering unit configured to perform a first filter on the received list of trajectories. The intermediate result of the first filtering includes only trajectories whose state during the planning period has been at least classified as TS, and whose trajectory, after the end of the planning period, is allowed to pass into a zone at least classified as IS (transferable). The safety inspection module further includes a second filtering unit configured to perform a second filter on the intermediate result of the first filtering of the list of trajectories based on probability estimates of the validity of assumptions about the read-in environment model and / or the validity of safety control laws about the read-in environment model, at least during the planning period. The result of the second filtering of the list includes only trajectories (e.g., only one trajectory) whose probability estimate exceeds a threshold of a safety objective (particularly the first and / or second safety objective).

[0112] Optionally, the security check module may also include a sensor data receiving interface and / or an environment model creation unit.

[0113] The classification unit may include a state classification unit configured to classify states based on assumptions about the read-in environment model, according to at least one first safety objective for the at least partially automated vehicle operation. The assumptions may be read from the assumption memory.

[0114] Alternatively or additionally, the classification unit may include a zone classification unit configured to classify zones based on a safety control law relating to the read-in environmental model, according to at least one second safety objective for the at least partially automated vehicle operation. Zones classified according to the at least one second safety objective may include at least one set of states classified according to the at least one first safety objective. The safety control law may be read from a control law memory.

[0115] Alternatively or additionally, the security check module may include a first sorting unit. Further alternatively or additionally, the security check module may include a second sorting unit.

[0116] The security check module may also include providing an interface.

[0117] The safety check module may include at least one memory. The at least one memory may include the environment model memory, the hypothesis memory, and / or the control law memory (e.g., as partitions of the total memory, respectively). Alternatively or additionally, the environment memory may be located in (or connected to) the perception module and / or prediction module of the at least partially automated vehicle.

[0118] The security check module may be configured to implement the method according to the method aspect. Alternatively or additionally, the security check module may include features according to the method aspect.

[0119] According to the system aspect, a system is provided for performing safety checks on the trajectory of a vehicle operating at least partially automated within a planning cycle. The system includes at least one environmental sensor configured to receive sensor data relating to the dynamic development of a traffic scene surrounding the at least partially automated vehicle. The system also includes a perception module configured to create an environmental model based on the sensor data. The system further includes at least one prediction module configured to dynamically evolve the environmental model. The system also includes at least two planning modules, each configured to output at least one trajectory to be checked. The system further includes a safety check module according to the device aspect, wherein the environmental model interface of the safety check module is configured to read the environmental model from the prediction module (and / or the perception module), and the receiving interface of the safety check module is configured to receive the trajectory to be checked from the at least two planning modules.

[0120] According to another aspect, a computer program having program elements is provided, which, when loaded into the memory of a safety check module, causes the safety check module to perform steps of a method according to the method aspect for performing a safety check on the trajectory of a vehicle for at least partially automated operation within a planning cycle.

[0121] According to another aspect, a computer-readable medium is provided having program elements stored thereon, the program elements being readable and executable by a safety check module, so that, when the program elements are implemented by the safety check module, the steps of a method according to the method aspect for performing a safety check on the trajectory of a vehicle for at least partially automated operation within a planning cycle are executed. Attached Figure Description

[0122] Figure 1 This is a flowchart of a method for performing a safety check on the trajectory of a vehicle intended for at least partially automated operation within a planning cycle, according to a preferred embodiment.

[0123] Figure 2 This is an overview diagram of the structure and construction of a safety inspection module for performing safety checks on the trajectory of a vehicle for at least partially automated operation within a planning cycle, according to a preferred embodiment.

[0124] Figure 3A and Figure 3B Show Figure 1 A preferred embodiment of the method includes: first and second sorting of trajectories according to priority and / or according to at least one security metric, wherein, Figure 3BA preferred embodiment for classifying the states and regions of an environmental model is schematically illustrated. Detailed Implementation

[0125] Figure 1 A flowchart schematically illustrates an exemplary computer-implemented method 100 for performing a safety check on the trajectory of a vehicle for at least partially automated operation within a planning cycle.

[0126] Method 100 includes step S104: reading from an environment model memory an environment model of a vehicle assigned to the planning period for at least partially automated operation, wherein the environment model represents the dynamic development of the traffic scene around the at least partially automated vehicle.

[0127] Method 100 further includes step S107: classifying states and zones based on assumptions about the environmental model read in S104 and / or based on safety control laws about the environmental model read in S104, according to at least one safety objective (e.g., a first or second safety objective) for the at least partially automated vehicle operation. The zones of S107 classified according to the at least one safety objective (e.g., the second safety objective) include at least one set formed by the states of S107 classified according to the at least one safety objective (e.g., the first safety objective). The assumptions can be read from an assumption memory. Alternatively or additionally, the safety control laws can be read from a control law memory.

[0128] Method 100 further includes step S110: receiving a list of trajectories to be inspected for the at least partially automated operation of the vehicles, the trajectories being for the planning period.

[0129] Method 100 further includes step S114: performing a first filter on the received track list from S110. The intermediate result of the first filter S114 includes only tracks whose status during the planning period has been classified at least S107 as Temporary Safety (TS), and whose tracks pass into a zone that has been classified at least S107 as Invariant Safety Transferable (IS Transferable) after the end of the planning period.

[0130] Method 100 further includes step S116: performing a second filtering on the intermediate results of the first filtering S114 of the trajectory list based on probability estimates of the validity of the assumptions and / or the validity of the safety control laws, at least during the planning period, and particularly with respect to the environmental model read in S104. The result of the second filtering S116 of the trajectory list includes only trajectories whose probability estimates exceed a threshold of the at least one safety objective (particularly at least one first and / or second safety objective).

[0131] Method 100 may further include step S102: receiving sensor data regarding the dynamic development of the traffic scene around the at least partially automated vehicle. Alternatively or additionally, method 100 may include step S103: creating the environment model, particularly by using (and / or based on) the sensor data received in S102.

[0132] The step of classifying states and zones according to at least one safety objective for the vehicle operating at at least partially automated S107 may include: step S106 of classifying states and step S108 of classifying zones.

[0133] The state can be classified according to at least one first safety objective for the vehicle operating at least partially automated, based on assumptions about the environmental model read in S104, S106. These assumptions can be read from the assumption memory.

[0134] The region can be classified (S108) based on a safety control law relating to the environmental model read in (S104), according to at least one second safety objective for the vehicle operating at least partially automated. The region classified (S108) according to the at least one second safety objective may include at least one set formed by the states classified (S106) according to the at least one first safety objective. The safety control law can be read from the control law memory.

[0135] Method 100 may further include step S112: performing a first sorting of the received list of trajectories to be inspected in S110 according to the priority of the set of boundary conditions to be satisfied and / or at least one security metric. Alternatively or additionally, method 100 may include step S118: performing a second sorting of the trajectories resulting from the second filtering in S116 according to the value of the probability estimate and / or according to the result of the first sorting in S112, particularly according to at least one security metric of the trajectories.

[0136] Method 100 may further include step S120: providing the trajectory of the result of the second filtering S116 (in particular the optimal trajectory according to the second sorting S118) to the adjustment and / or control of the at least partially automated vehicle for implementing the trajectory.

[0137] Figure 2 An exemplary structure of a safety check module (also known as a safety checker) 200 is schematically shown for performing safety checks on the trajectory of a vehicle for at least partially automated operation within a planning cycle.

[0138] The safety check module 200 includes an environment model interface 204 configured to read an environment model (particularly from an environment model memory) that is associated with the planning cycle and is used for the at least partially automated vehicles. The environment model represents the dynamic evolution of the traffic scene around the at least partially automated vehicles.

[0139] The safety check module 200 further includes a classification unit 207 configured to classify states and zones based on assumptions about the read-in environment model and / or on safety control laws related to the read-in environment model, according to at least one safety objective (e.g., a first or second safety objective) for the at least partially automated vehicle. Zones classified according to the at least one safety objective (e.g., the second safety objective) comprise at least one set of states classified according to the at least one safety objective (e.g., the first safety objective). The assumptions can be read from an assumption memory. Alternatively or additionally, the safety control laws can be read from a control law memory.

[0140] The safety inspection module 200 also includes a receiving interface 210 configured to receive a list of trajectories to be inspected for the at least partially automated operation of the vehicle, the trajectories being for the planning period.

[0141] The security check module 200 also includes a first filtering unit 214 configured to perform a first filtering on the received list of trajectories. The intermediate results of the first filtering include only trajectories whose status during the planning period has been at least classified as TS, and whose trajectory, after the end of the planning period, is allowed to pass through a zone that has been at least classified as IS (transferable).

[0142] The security check module 200 further includes a second filtering unit 216 configured to perform a second filtering on intermediate results of the first filtering of the trajectory list based on probability estimates of the validity of assumptions regarding the read-in environmental model and / or the validity of security control laws, at least during the planning period. The result of the second filtering of the list includes only trajectories whose probability estimates exceed a threshold for security objectives (particularly the first and / or second security objectives).

[0143] Optionally, the safety inspection module 200 may further include a sensor data receiving interface 202 and / or an environment model creation unit 203. The sensor data receiving interface 202 may be configured to receive sensor data relating to the dynamic development of a traffic scene around the at least partially automated vehicle. Alternatively or additionally, the environment model creation unit 203 may be configured to create an environment model, particularly by using (and / or based on) the received sensor data.

[0144] Classification unit 207 may include state classification unit 206 and zone classification unit 208. State classification unit 206 may be configured to classify states based on assumptions about the read-in environment model, according to at least one first safety objective for the at least partially automated vehicle operation. The assumptions may be read from the assumption memory. Alternatively or supplementarily, zone classification unit 208 may be configured to classify zones based on safety control laws about the read-in environment model, according to at least one second safety objective for the at least partially automated vehicle operation. Zones classified according to the at least one second safety objective may include at least one set of states classified according to the at least one first safety objective. The safety control laws may be read from the control law memory.

[0145] Alternatively or supplementarily, the security check module 200 may include a first sorting unit 212 configured to perform a first sorting of the received list of trajectories to be checked based on the priority of the set of boundary conditions to be satisfied and / or at least one security metric. Further alternatively or supplementarily, the security check module 200 may include a second sorting unit 218 configured to perform a second sorting of the trajectories resulting from the second filtering. The second sorting may be performed based on the value of the probability estimate. Alternatively or supplementarily, the second sorting may be performed based on the result of the first sorting (especially based on at least one security metric of the trajectory).

[0146] The safety check module 200 may further include a providing interface 220 configured to provide the trajectory of the result of the second filtering (in particular the best trajectory according to the second sorting) to the regulation and / or control of the at least partially automated vehicle for implementing the trajectory.

[0147] The safety check module 200 may include at least one memory 226. The at least one memory 226 may include the environment model memory, the hypothesis memory, and / or the control law memory (e.g., as partitions of the total memory, respectively). Alternatively or additionally, the environment memory may be located in (and / or connected to) the perception module and / or prediction module of the at least partially automated vehicle.

[0148] The security check module 200 can be configured to implement method 100.

[0149] A system (not shown) for safety checks on the trajectories of vehicles operating at least partially automated within a planning cycle may include at least one environmental sensor configured to receive sensor data relating to the dynamic evolution of a traffic scene surrounding the at least partially automated vehicle. The system may also include a perception module configured to create an environmental model based on the sensor data. The system may further include at least one prediction module configured to dynamically evolve the environmental model. The system may include at least two planning modules, each configured to output at least one trajectory to be checked. The system may also include a safety check module 200, whose environmental model interface 204 is configured to read the environmental model from the prediction module (and / or the perception module), and whose receiving interface 210 is configured to receive the trajectories to be checked from the at least two planning modules.

[0150] The system can be configured to implement method 100.

[0151] The safety inspection module 200 and / or the system may be located in the control components of the at least partially automated vehicle.

[0152] The technology (particularly including method 100, safety check module 200 and / or the system) for safety checks on the trajectory of a vehicle for at least partially automated operation during the planning cycle is (at least at its core) not for motion planning technology, but for online verification and trajectory correction (particularly for planned trajectories). Unlike references [1, 2], the technology directly determines the state (particularly IS and TS) and the zone (particularly IS transferable) in the environment model.

[0153] For the implementation of the aforementioned technique, a list of trajectories to be inspected already exists. The trajectories in the list are not necessarily required to begin or end within an IS (or at least an IS-transferable) zone.

[0154] Using the aforementioned technology, sampled trajectory candidates can be examined for compliance with behaviors that have been prioritized and can be represented as a set of boundary conditions.

[0155] The checks on behaviors with determined priorities can be implemented in the security check module located downstream of the planning module.

[0156] The safety check module (also known as: Safety Checker) 200 may apply (e.g., apply only) safety (technical term: Safety) standards. Alternatively or additionally, the safety check of the safety check module 200 may be multi-level and may additionally take into account functional safety (technical term: Functional Safety).

[0157] The safety check module (also known as: Safety Checker) 200 may also consider replanning and / or contingency planning. Alternatively or additionally, the technique may consider modifying the trajectory candidates (the modifications being particularly unknown from the prior art).

[0158] According to the technology used to perform safety checks on the trajectories of vehicles intended for at least partial automated operation during the planning cycle, the trajectory list is checked and evaluated by a component different from the (or more, especially two) planning components, namely the so-called Safety Checker (or Safety Check Module 200). The task of Safety Checker 200 is to select the available trajectory that is best in terms of safety, and, if no suitable trajectory has been provided at all, to derive a suitable output trajectory from the provided trajectories.

[0159] The Safety Checker Module (or Safety Checker) 200 is used to perform safety checks on the received track (also known as the input track) in the sense of ISO 21212 functional safety and ISO 21448 SOTIF standards.

[0160] A preferred embodiment of method 100 is in Figure 3AThe diagram is schematically shown. At reference numeral S102, sensor data is received, particularly from sensors arranged on the vehicle. Based on the sensor data received in step S120, multiple planning modules 1, ..., N plan (e.g., each planning a trajectory for) a list of trajectories (e.g., including at least one input trajectory from at least one planning module) received (also called: obtained) in step S110 by the safety check module (also called: Safety Checker) for checking. Furthermore, the safety check module (or Safety Checker) 200 reads (either actively or passively reads / receives, or PUSH or PULL runs) an environment model in step S104, which has been prepared in step S103 (this step is... Figure 3A For example, this can also be called preprocessing and in Figure 3B The process can be referred to as perception, which is based on sensor data (especially from vehicle sensor systems and, where necessary, from data obtained via V2X communication) to create (and / or calculate).

[0161] Generally, the creation or calculation of the environmental model can be based on the implementation steps of the sensing module ( Figure 3B (S103). "Perception" can be understood as the reception of data. The perception module (or perception layer) involves components responsible for detecting raw data from the surrounding environment and optionally preprocessing it. These components typically include sensors, cameras, microphones, and / or other input devices that detect data such as images, sound, or text. The primary task of the perception module is to convert the raw data into a format that can be understood and analyzed by the environmental model. The received sensor data may also include data preprocessing (see [link to relevant documentation]). Figure 3A (S103) in order to, for example, extract relevant features, filter out noise and / or transform the data into a presentation suitable for further processing.

[0162] According to one embodiment, a preprocessing step (e.g. for creating the environment model in S103) can be performed between the step of receiving sensor data in S102 and the step of receiving the environment model in S104 (especially for the sensor data received in S102).

[0163] According to another embodiment (especially one that can be combined with the previous embodiment), a sensing step (e.g., for creating an environment model in S103) can be performed between the step of receiving sensor data in S102 and the step of receiving an environment model in S104 (especially based on the sensor data received in S102).

[0164] In step S107, at Figure 3A The system classifies states and zones based on at least one security objective. For example, in... Figure 3B As shown, step S107 may include step S106 of classifying the state and step S108 of classifying the region.

[0165] As in Figure 3A As schematically shown at reference numeral S112 in the accompanying drawings, the security check module 200 first derives a list of prioritized behaviors and sorts these behaviors by priority (and / or sorts the received trajectory of S110 according to the priority of the set of boundary conditions to be satisfied). Alternatively or additionally, the list of prioritized behaviors (and / or the set of boundary conditions to be satisfied) may come from an external source and, for example, may be checked only for correctness by the security check module 200. This implementation (especially with an external source of the prioritized behavior list) is meaningful, for example, when at least one of the planning modules has been implemented and the list of prioritized behaviors has been calculated in the processing chain. Advantageously, these behaviors are represented as sets of boundary conditions respectively.

[0166] The security check module 200 then determines the highest priority behavior mode satisfied by each received trajectory (and / or input trajectory) in S110. Based on this priority, the security check module 200 sorts the received trajectories (or input trajectories) in S112.

[0167] Furthermore, the security check module 200 determines the set of invariant security (IS) states from the received environment model S104 using a set-based method, and derives the IS transition region from there. The IS transition region represents a set of time-dependent states (also called time-state pairs), where, with the aid of one or more security control laws, time-dependent states from the IS transition region are transformed (or at least can be transformed into) IS states via secure trajectories. (In particular, the processing chain used to obtain the IS transition region...) Figure 3BThe following is an illustration. To this end, the state space of the at least partially automated vehicle (also known as the autonomous vehicle) is first expanded along the time dimension, and time-related states (also known as time-state pairs) are subdivided into three categories: unsafe, temporarily safe (TS), and IS. An unsafe time-related state (or time-state pair) contradicts at least one safety goal (technically termed a Safety Goal). A common safety goal is, for example, collision-free. Accordingly, a time-related state (or time-state pair) within the reachable set of other traffic participants is unsafe. A non-unsafe time-related state (or time-state pair) is TS. A state that is TS for all times within the relevant time frame is IS. The IS state set is particularly limited by conflict zones. Examples of such conflict zones are intersections, railway crossings, and / or oncoming lanes on rural roads. A state within such a conflict zone can be TS, but it can never be IS.

[0168] Constructing the corresponding set of time-related states (also known as pairs in the time-state space) using set-based methods requires a set of assumptions (particularly regarding the environmental model read from S104), made, for example, during white-box modeling of the set-based estimates. For instance, to determine the set of reachable states of other traffic participants, assumptions are made about the driving physics of these participants, and in many cases, the rational driver assumption is used. The rational driver assumption presupposes that other traffic participants also obey traffic rules or violate them only to a predictably low degree. Thus, for example, the set of reachable states of a traffic participant is limited to that participant's lane.

[0169] A key advantage of the proposed invention lies in its formal security guarantee, which is achieved through a set-based approach. Because by mapping uncertainty into set form, violations of at least one security objective can be formally excluded even with disjoint sets, provided the assumptions are followed.

[0170] exist Figure 3B The hypothesis memory is schematically drawn at reference numeral 302, from which hypotheses regarding the environment model read in S104 are read during step S106, which involves classifying states (and / or constructing sets). Furthermore, the control law memory is schematically drawn at reference numeral 304, from which security control laws regarding the environment model read in S104 are read during step S108, which involves classifying regions.

[0171] exist Figure 3BIn step S108, the IS state set is expanded to an IS transition zone. A safe trajectory contains only TS states. An example of a safety control law is braking to a standstill in a manner that optimizes jerkiness, limits jerkiness, and limits acceleration. Another safety control law involves Adaptive Cruise Control (ACC). ACC control laws are preferably combined with safe braking, so that the at least partially automated vehicle (or autonomous vehicle) does not blindly follow a preceding vehicle through a conflict zone (e.g., an intersection). In an advantageous implementation, acceleration boundary conditions, velocity boundary conditions, time boundary conditions, and orientation boundary conditions are presented as intervals and associated with polygons describing the position coordinates of the region.

[0172] exist Figure 3A In step S114, based on set-based analysis of the environment model, for each received trajectory (or input trajectory) from S110, it is checked whether the trajectory segment from the current self-state (also referred to as: self-vehicle state) of the at least partially automated vehicle up to the replanning time point (and / or the end of the planning cycle) is a safe trajectory. Here, the replanning time point is the time when the planned trajectory becomes active in the next planning cycle. Trajectories that are not guaranteed to be safe before the replanning time point are filtered out. Furthermore, for each received trajectory (or input trajectory) from S110, it is checked whether the trajectory passes through the IS transferable zone after the replanning time point. If no IS transferable zone is reached after replanning, the safety of the trajectory cannot be formally guaranteed, and the trajectory is filtered out. The intermediate result of the first filtering step S114 is a list of filtered trajectories (especially the first one).

[0173] Overestimation in a set-based scheme or a violation of assumed principles (also known as invalidity) could result in no trajectory among the received trajectories (or input trajectories) being guaranteed to be safe. If the trajectory passes through the IS transition zone before reaching a state not guaranteed to be TS, the trajectory can be implemented until the IS transition zone is reached and then switched to the safety control law corresponding to the zone. Thus, the safety check module 200 can generate a formally safe modified trajectory (also known as a fallback trajectory). Otherwise, no longer a guaranteed safe trajectory is available for the system. In this case, the trajectory with the highest priority derived from the original list (e.g., in step S112) based on the set of boundary conditions (and / or behavior patterns) to be satisfied can be relied upon. In this way, the safety check module 200 can ensure that at least partially automated vehicles (or self-vehicles) behave in the manner most favorable to the situation according to the safety objectives.

[0174] exist Figure 3A In step S116, as shown in the diagram, a probabilistic evaluation is performed on the remaining (and / or included in the intermediate results) trajectory. For this purpose, the environment model is predicted probabilistically, and along the corresponding received trajectory (or input trajectory) of S100, from the current state until reaching the first IS transition zone after the rescheduling time point, the probability of "state invalidity" derived from the probabilistic prediction is integrated. Alternatively or supplementarily, this can be applied to (e.g., based on...) Figure 3B For each hypothesis constructed in step S106, the probability that "the hypothesis is indeed violated (and / or invalidated)" is determined. All these probabilities can be combined. This yields the probability of "maintaining the guaranteed safety of the trajectory." This probability is a safety metric and / or safety indicator in the SOTIF sense. The safety metric and / or safety indicator must exceed a minimum bound (and / or threshold) such that the remaining probability of outputting an unsafe trajectory is reduced to an acceptable level. In step S116, trajectories that do not meet the remaining probability criteria are filtered out. If none of the remaining trajectories meet the minimum bound, then (e.g., according to...) Figure 3A The highest priority trajectory (derived in step S112) is used to ensure that the at least partially automated vehicle (and / or autonomous vehicle) still behaves in the best possible way. "Best possible" preferably refers to the vehicle's current traffic scenario and / or environment.

[0175] Under normal circumstances, at least one of the received trajectories (or input trajectories) from S110 remains in the list after re-filtering in S116. In step S118, the remaining trajectories can be sorted within priority categories of these trajectories according to (especially SOTIF) security metrics and / or based on security metrics, and the trajectory with the highest overall priority is output (and / or provided according to step S120 of the method).

[0176] In one embodiment, one (or each) of the (especially at least two) planning modules may be implemented as a “GeBe planner”, based on a deep planning scheme (as described, for example, in reference [3]) and / or on a classical planning method (as described, for example, in reference [4]). The “GeBe planner” may, for example, be a planning method for determining a list of behaviors with determined priorities, as defined and described in this specification.

[0177] In another embodiment that can be combined with the previous embodiment, the environment model is displayed through a dynamic raster map, a list of objects, and / or HD map fragments (HD can stand for High Definition).

[0178] In another embodiment that can be combined with the foregoing embodiments, a set of boundary conditions (and / or behaviors) to be satisfied with a determined priority is determined by pre-calculating behaviors in the planning module and checking them in the security checking module 200 (e.g., in the sense of rationality checks and / or consistency checks).

[0179] Behavioral patterns and their priorities can be calculated and determined by decomposing the current situation into so-called partial situations that describe different aspects of the situation, identifying the associated boundary conditions, and then combining these boundary conditions into behavioral patterns. The priorities of the boundary conditions generated based on the partial situations can be determined based on the degree to which the underlying security objectives (or multiple security objectives) are achieved.

[0180] A technique for safety checks on trajectories of vehicles intended for at least partially automated operation within a planning cycle includes method 100, in which an environmental model for the vehicle is read in (S104), the environmental model being assigned to the planning cycle and representing the dynamic development of a traffic scenario. Based on assumptions and / or safety control laws regarding the read environmental model (S104), states and zones are classified (S107) according to safety objectives for the vehicle. Zones classified according to safety objectives (S107) comprise a set of states classified according to safety objectives (S107). A list of trajectories to be checked is received (S110), and this list is filtered twice. An intermediate result of the first filter (S114) includes only trajectories whose state during the planning cycle has been at least classified (S107) as temporarily safe, and whose trajectories pass into zones at least classified (S107) as invariably safe and transferable after the planning cycle. The second filter (S116) includes a probabilistic estimation of the validity of assumptions and / or safety control laws regarding the read environmental model (S104).

[0181] Techniques (particularly including method 100, safety check module 200, and / or the system itself) for performing safety checks on trajectories during the planning cycle of systems designed for at least partially automated operation, particularly vehicles, can be utilized, for example, at automation levels L4 and L5. These techniques can serve as potential core components for systems enabling safe automated driving in complex environments. Applications to the field of driver assistance systems (particularly at automation levels L3 and above) are equally conceivable (and / or meaningful) under appropriate (and / or given) boundary conditions.

[0182] Referenced existing technology [1] DE 10 2017 120 366 A1 [2] Christian Pek et al., "Enhancing Motion Safety by Identifying Safety-critical Passageways", 2017 IEEE 56th Annual Conference on Decision and Control (CDC) , Melbourne, VIC, Australia, 2017, pp. 320- 326 [3] Alexander Cui et al., "LookOut: Diverse Multi-Future Prediction and Planning for Self-Driving," 2021 IEEE / CVF International Conference on Computers Vision (ICCV) , Montreal, QC, Canada, 2021, pp. 16087-16096 [4] Johannes Müller et al., "Motion Planning for Connected Automated Vehicles at Occluded Intersections With Infrastructure Sensors," in IEEE Transactions on Intelligent Transportation Systems , vol. 23, no. 10, pp.17479-17490, Oct. 2022

Claims

1. A computer-implemented method (100) for performing a safety check on the trajectory of a vehicle for at least partially automated operation within a planning cycle, the method comprising the following steps: - Read the environment model from the environment model memory (S104), the environment model being assigned to the planning cycle and used for the at least partially automated operation of the vehicle, wherein, The environment model represents the dynamic evolution of the traffic scene around the at least partially automated vehicles; - Based on assumptions about the environment model read in (S104) and / or based on safety control laws about the environment model read in (S104), states and zones are classified according to at least one safety objective for the vehicle operating at at least partially automated (S107), wherein the zones classified according to the at least one safety objective (S107) include at least one set of states classified according to the at least one safety objective (S107), wherein the assumptions are read in from the assumption memory (302), and wherein the safety control laws are read in from the control law memory (304); - Receive (S110) a list of trajectories to be checked for the at least partially automated operation of the vehicles, the trajectories being for the planning period; - The received (S110) trajectory list is subjected to a first filter (S114), wherein the intermediate result of the first filter (S114) includes only trajectories whose status during the planning period has been at least classified as Temporarily Safe (TS), and whose trajectory, after the end of the planning period, is allowed to enter a zone that has been at least classified as Invariably Safe and Transferable (IS); and - Based on probability estimates regarding the validity of assumptions about the read-in (S104) environmental model and / or the validity of safety control laws during at least the planning period, a second filter (S116) is applied to the intermediate results of the first filter (S114) of the trajectory list, wherein the result of the second filter (S116) of the list includes only trajectories whose probability estimates exceed a threshold of the at least one safety objective.

2. The method (100) according to claim 1, further comprising the following steps: - Receive (S102) sensor data regarding the dynamic development of the traffic scene around the at least partially automated vehicle; and / or - Create the environment model described in (S103), especially by using the sensor data received in (S102).

3. The method (100) according to any one of the preceding claims, wherein, The step of "classifying the state and zone according to at least one safety objective for the vehicle operating at least partially automated (S107)" includes the following steps: - Based on assumptions about the environment model read in (S104), the state is classified according to at least one first safety objective for the vehicle operating at least partially automated (S106), wherein the assumptions are read in from the assumption memory (302); - Based on the safety control law regarding the read-in (S104) environmental model, the area is classified (S108) according to at least one second safety objective for the vehicle operating at least partially automatically, wherein the area classified (S108) according to the second safety objective includes at least one set formed by states classified (S106) according to the first safety objective, wherein the safety control law is read from the control law memory (304).

4. The method (100) according to any one of the preceding claims, further comprising at least one of the following steps: - Based on the priority of the set of boundary conditions to be satisfied and / or at least one security metric, perform a first sorting (S112) on the received (S110) list of trajectories to be inspected; and - Based on the value of the probability estimate and / or based on the result of the first sorting (S112), especially based on at least one security metric of the trajectory, the trajectory of the result of the second filtering (S116) is sorted a second time (S118).

5. The method (100) according to any one of the preceding claims, further comprising the following steps: - The trajectory resulting from the second filtering (S116), especially the optimal trajectory derived according to the second sorting (S118), is provided (S120) to the adjustment and / or control of the at least partially automated vehicle for implementing the trajectory.

6. The method (100) according to any one of the preceding claims, wherein, The states classified according to the at least one security objective, especially the first security objective (S107; S106), include at least three types of states, especially the invariant security IS state, TS state, and / or insecure state.

7. The method (100) according to any one of the preceding claims, wherein, The areas classified according to the at least one security objective, especially the second security objective (S107; S108), include at least three types of areas, especially IS areas, IS transferable areas, and / or insecure areas.

8. The method (100) according to any one of the preceding claims, wherein, If the result of the second filtering (S116), especially if the trajectory list after the second filtering (S116) is empty, a trajectory included in the intermediate result of the first filtering (S114) is selected; optionally, the trajectory is modified after the starting point of the selected trajectory in the planning cycle, wherein the modification includes applying the safety control law.

9. The method (100) according to any one of the preceding claims, wherein, If the intermediate results of the first filtering (S114), especially the trajectory list after the first filtering (S114), are empty, the received (S110) trajectory is selected and the trajectory is modified after the starting point of the trajectory in the planning cycle, wherein the modification includes applying the safety control law.

10. The method (100) according to any one of the preceding claims, wherein, The assumptions regarding the environmental model read in (S104) include: assumptions based on generally valid rules and / or assumptions made by other traffic participants regarding the dynamic development of the traffic scenario.

11. The method (100) according to any one of the preceding claims, wherein, The safety control law includes criteria for regulating and controlling the at least partially automated vehicle and / or an intelligent driver model for the at least partially automated vehicle.

12. A safety check module (200) for performing a safety check on the trajectory of a vehicle for at least partially automated operation within a planning cycle, the safety check module comprising: - Environment model interface (204), the environment model interface is configured to read an environment model from an environment model memory, the environment model being associated with the planning period and for the at least partially automated vehicle, wherein the environment model represents the dynamic development of the traffic scene around the at least partially automated vehicle; - A classification unit (207) configured to classify states and zones based on assumptions about the read-in environment model and / or based on safety control laws about the read-in environment model, according to at least one safety objective for the at least partially automated vehicle, wherein the zones classified according to the at least one safety objective comprise at least one set of states classified according to the at least one safety objective, wherein the assumptions are read from an assumption memory, and wherein the safety control laws are read from a control law memory; - A receiving interface (210) configured to receive a list of trajectories to be inspected for the at least partially automated operation of the vehicle, the trajectories being for the planning period; - A first filtering unit (214), configured to perform a first filtering on the received list of trajectories, wherein the intermediate result of the first filtering includes only trajectories whose status during the planning period has been at least classified as Temporarily Safe (TS), and whose trajectory, after the end of the planning period, is allowed to pass through a zone that has been at least classified as Invariably Safe Transferable (IS Transferable); and - A second filtering unit (216) configured to perform a second filtering on intermediate results of the first filtering of the trajectory list based on probability estimates of the validity of the assumptions about the read-in environmental model and / or the validity of the safety control law during at least the planning period, wherein the result of the second filtering of the list includes only trajectories whose probability estimates exceed a threshold of the at least one safety objective.

13. The security check module (200) according to the preceding claim, wherein, The security check module (200) is also configured to implement the method according to any one of claims 2 to 11, and / or wherein the security check module (200) includes the features according to any one of claims 2 to 11.

14. A system for performing safety checks on the trajectory of a vehicle for at least partially automated operation within a planning cycle, the system comprising: - At least one environmental sensor configured to receive sensor data regarding the dynamic development of a traffic scene around the at least partially automated vehicle; - A sensing module configured to create an environment model based on the sensor data; - At least one prediction module, said prediction module being configured to enable the environment model to evolve dynamically; - At least two planning modules, each configured to output at least one trajectory to be inspected; as well as - The security check module (200) according to claim 12 or 13, wherein the environment model interface (204) is configured to read the environment model from the prediction module and / or the perception module, and wherein the receiving interface (210) is configured to receive the trajectory to be checked from the at least two planning modules.

15. A computer program product having program elements, wherein when the program elements are loaded into the memory of a safety check module (200), the program elements cause the safety check module (200) to perform the steps of a method according to any one of the preceding method claims for performing a safety check on the trajectory of a vehicle for at least partially automated operation within a planning period.

Citation Information

Patent Citations

  • Method, device, computer program and computer program product for motion planning of a system

    DE102017120366A1