Driver assistance system
Patent Information
- Application Number
- DE102014217848
- Authority / Receiving Office
- DE · DE
- Patent Type
- Patents
- Current Assignee / Owner
- Filing Date
- 2014-09-08
- Publication Date
- 2026-10-01
- Estimated Expiration
- 2034-09-08
AI Technical Summary
Existing driver assistance systems for motor vehicles lack the ability to seamlessly transition between manual and fully automatic vehicle guidance modes, and there is a need to determine responsibility in case of accidents, as well as improve system performance by recording and analyzing data to prevent critical driving situations.
A driver assistance system with an external sensor system, data processing unit, and log data recorder that allows for fully automatic vehicle guidance, records log data, and includes redundant sensors for increased reliability, with a log data recorder to analyze and store data for accountability and system improvement.
Enables safe and reliable transition between manual and automatic modes, provides evidence of responsibility in accidents, and enhances system performance by identifying and preventing critical driving situations through data analysis.
Abstract
Description
[0001] The invention relates to a driver assistance system for a motor vehicle with an operating mode for fully automatic vehicle control and with an operating mode for manual vehicle control.
[0002] Currently, motor vehicles are increasingly being equipped with driver assistance systems that support the driver in operating the vehicle. These systems primarily serve to increase safety and prevent accidents.
[0003] Today's driver assistance systems are generally designed as purely supportive systems, relieving the driver of individual tasks or providing assistance in other ways. In the future, however, there will be an increasing use of driver assistance systems that can, at least temporarily, fully automate the driving of the vehicle and thus assume complete control over it – systems designed for at least temporary fully automated driving. This, however, entails additional requirements for such driver assistance systems.
[0004] Based on this, the invention aims to provide an advantageous driver assistance system that is designed for at least temporary fully automatic vehicle control.
[0005] This problem is solved according to the invention by a driver assistance system having the features of claim 1. Preferred embodiments are included in the dependent claims.
[0006] A corresponding driver assistance system is designed for a motor vehicle and is installed accordingly. The driver assistance system is configured to implement two operating modes, allowing it to be operated in either a fully automatic or a manual mode, depending on requirements or preference, with the ability to switch between the two modes at any time.
[0007] Furthermore, the driver assistance system includes an external sensor system for generating raw data with information about the vehicle's surroundings, as well as a data processing unit for processing the raw data, generating processed data based on the raw data, and generating control signals for fully automated vehicle guidance based on the processed data. The driver assistance system also includes a log data recorder or "system logger" configured for the automated recording of log data, which includes processed data.
[0008] The processed data serves, in particular, to implement fully automated vehicle control in operating mode, where the driver assistance system controls the vehicle. "Fully automated vehicle control" in this context means that the driver of the vehicle assumes no control or monitoring function whatsoever during fully automated driving, thus relieving the driver of virtually 100% of the mental burden and allowing them to engage in other activities, such as reading a book.
[0009] Depending on national legislation, this means that a change in operating mode or status between manual and fully automatic driving also results in a transfer of responsibility. While the driver remains responsible for driving the vehicle while it is operating manually, the manufacturer is responsible when fully automatic driving is activated and the vehicle is being controlled by the driver assistance system. This transfer of responsibility is particularly important in the event of an accident, as the party responsible at the time of the accident is liable for any resulting damage.
[0010] From the perspective of both the vehicle manufacturer and the driver, it is therefore desirable to be able to prove, in the event of an accident, who was responsible at the time of the accident and who is therefore liable for any resulting damage. Such proof is made possible by the log data recorder of the driver assistance system presented here.
[0011] The aim here is not only to retrospectively prove whether the driver assistance system, the driver, or both were responsible for a driving situation, but also to create the possibility of understanding, through data recording, what exactly led to a driving situation and which actions of the driver assistance system and / or the driver resulted in a problematic or critical driving situation. This objective is pursued through the specific selection of data recorded by the log data recorder, and the recording of processed data is also necessary to achieve this goal. In this way, it is possible, for example, to determine whether the external sensor system malfunctioned or whether the raw data generated by the external sensor system was incorrectly processed, analyzed, and / or evaluated.
[0012] Faulty or insufficient data generation or processing is not necessarily due to a defect, particularly a hardware defect. Instead, the algorithms used in data processing can, for example, lead the driver assistance system to misinterpret a specific driving situation or make an incorrect decision in a particular driving situation, resulting in a problematic or critical, i.e., dangerous, driving situation. In such cases, the driver assistance system presented here allows the system to pinpoint exactly when it failed to function as intended. Subsequently, system adjustments can be made to prevent these problematic or even critical driving situations in the future.
[0013] The data recorded by the log data recorder can therefore also be used to further develop and improve the driver assistance system by identifying errors or, more precisely, shortcomings. In this way, the driver assistance system presented here could also help to overcome existing legal barriers to highly automated driving, i.e., fully automated vehicle operation, by contributing to the generation of a data or information base through data recording, which allows for a comparison of the advantages and disadvantages of fully automated vehicle operation.
[0014] The processing of raw data in the data processing unit typically takes place in several successive processing stages, with processed data or control signals being generated at each stage, phase, or level. Depending on the application, the raw data processing is performed using a single logical unit or multiple logical units, such as a CPU core. In some cases, initial processing of raw data technically occurs within the external sensor system; however, even in such cases, the data output by the external sensor system is referred to as raw data within the scope of the invention presented here.
[0015] A particularly advantageous design variant of the driver assistance system is one in which a separate and preferably specially adapted logical unit for data processing is used for each processing stage, as this enables particularly fast data processing, which is especially beneficial in more complex traffic situations and / or at higher speeds of the vehicle with the driver assistance system.
[0016] According to a suitable design of the driver assistance system, the log data recorded by the log data recorder includes the raw data from the external sensor system as well as the processed data from at least one processing stage. With each additional processing stage or level of data processing, the amount of data increases, and thus the database that can be used, if necessary, to determine the exact cause of a problematic or critical driving situation. Therefore, it is advantageous to record the processed data, or at least parts of it, from multiple processing stages.
[0017] Simultaneously, the required data storage capacity of the log data recorder, in which the recorded data is stored, increases with the amount of data. Accordingly, depending on the application or requirements profile, it is determined which data is recorded, taking into account, for example, at which levels of data processing problems or errors are most likely to occur and which processing stages must therefore be traceable afterwards.
[0018] In addition to the raw data and the processed data from at least one processing stage, the log data preferably also includes the control signals generated by the driver assistance system on the basis of processed data during the last processing stage, in order to control the vehicle fully automatically, for example by generating control signals that essentially specify the steering angle and the accelerator pedal position.
[0019] This allows, for example, the determination of whether the vehicle's driving behavior or reaction correlates with the control signals, or whether the vehicle has exhibited atypical or unexpected behavior. For instance, it is conceivable that a section of the road is icy, but the icing is not detected by the external sensor system. As a result of this lack of detection, control signals are generated that cause the vehicle to be driven through a curve at excessive speed or with excessive steering input, resulting in the vehicle leaving the road. In this case, neither the raw data nor the processed data would explain the critical or dangerous driving situation, i.e., the vehicle leaving the road.Only the discrepancy between the control signals and the subsequent driving behavior or the vehicle's reaction makes it possible to reconstruct the scenario and infer an icy but undetected section of the road.
[0020] As previously mentioned, the external sensor system serves to generate raw data with information about the vehicle's surroundings. This sensor system typically comprises several different sensor units or sensors, such as a surround-view camera, a radar system, a lidar system, a laser scanner, a GPS navigation system, a radio clock receiver, and an ultrasonic system. These different sensors or sensor units generally gather both different and redundant information about the vehicle's environment. For example, a sensor system might include a surround-view camera and a radar system. Both sensor units can detect obstacles independently, thus generating essentially redundant information.This redundant information is then used, for example, for mutual verification, thereby obtaining particularly important information for fully automated vehicle control with increased reliability. However, some information about the vehicle's surroundings cannot be captured by both sensor units, so the various sensor units and their raw data complement each other, thus acquiring a greater amount of information about the vehicle's environment, which ultimately forms the basis for fully automated vehicle control. For example, the aforementioned surround-view camera can, in principle, also detect the road surface condition, at least to a limited extent—for instance, that the road is wet and partially covered with leaves. This essential information cannot typically be obtained using a radar system.
[0021] The raw data generated by multiple sensor units is subsequently prepared, processed, and evaluated in the data processing unit. During one processing stage, the raw data from several sensors or sensor units is fused to generate a database, which then forms the basis for further processing in the data processing unit. The processed data from this stage, i.e., the database, is preferably contained in the log data.
[0022] In many cases, data fusion is followed by a processing stage in which the resulting database is evaluated. This involves checking, for example, whether the database is sufficiently comprehensive and / or how reliable the information it contains is. If the scope and / or reliability are deemed insufficient, a switch from fully automated to manual vehicle control is preferably initiated, or the operating mode for fully automated vehicle control is temporarily disabled, thus temporarily preventing a switch from manual to fully automated vehicle control.
[0023] Therefore, if, for example, a sensor unit of the sensor system malfunctions or fails, and this failure cannot be adequately compensated for by other sensor units of the sensor system, the driver assistance system for fully automatic vehicle control will not have enough information available, and accordingly, the fully automatic vehicle control will either be terminated as quickly as possible, or the driver assistance system will refuse to switch from manual vehicle control to fully automatic vehicle control.
[0024] Furthermore, the conditions surrounding the vehicle can also be the reason for an insufficient or unreliable data basis, for example, if weather conditions overwhelm individual, particularly relevant sensor units. For instance, the raw data from a radar system might be unusable in heavy snowfall, and the raw data from a surround-view camera in dense fog. Even if the remaining raw data were, in principle, sufficient to enable fully automated driving, the risk of an error in this scenario might be too high, making it unacceptable for the driver assistance system manufacturer. Consequently, the driver assistance system is designed in such a way that the data basis is also deemed insufficient and / or unreliable in such a scenario.This means that the evaluation is not solely based on whether the available data makes fully automated vehicle control possible in principle, but also on the probability of errors within that dataset and the level of risk the driver assistance system manufacturer is willing to accept. Accordingly, criteria are stored within the driver assistance system to evaluate the dataset, and the processed data from this stage is preferentially recorded as part of the log data.
[0025] Typically, the data processing unit implements a further processing stage in which an environmental model of the vehicle's surroundings is generated, containing all the information gathered about the vehicle's environment. The processed data from this stage, i.e., the environmental model data, is preferably included in the log data. This processed data can then be used, for example, to subsequently determine whether the raw data and the database were correctly evaluated and whether the relevant information contained therein was correctly identified or interpreted.
[0026] In a further advantageous development, a more detailed evaluation is carried out based on the environmental model. During a corresponding processing stage, objects are assessed to determine whether they must be considered in the planning of fully automated vehicle guidance, i.e., in the determination of possible trajectories for fully automated vehicle guidance, and if so, to what extent. If such a processing stage is provided, the processed data from this stage are preferentially recorded and are therefore included in the log data.
[0027] For planning fully automated vehicle guidance, two processing stages are preferably provided. In the first of these two processing stages, possible trajectories for fully automated vehicle guidance are determined. The second processing stage then involves the final determination of the strategy, i.e., the selection of a trajectory from the set of determined trajectories. Preferably, the protocol data contains the processed data from both processing stages, among other reasons because the control signals with which the vehicle is ultimately controlled fully automatically are typically generated based on the selected trajectory.
[0028] Furthermore, the log data preferably also includes a time reference, which provides a temporal reference point for the log data, a position reference, such as GPS data, and / or the traffic rules applicable in the respective traffic situation.
[0029] According to a further advantageous embodiment of the driver assistance system, it also includes an internal sensor system for generating raw data with information about the driver of the motor vehicle, the raw data thus generated being preferably included in the log data. The aim here is less to monitor the behavior of the driver during manual driving, but rather to detect and record any interventions by the driver in the fully automated driving system. It should be noted that driver assistance systems are generally designed, or intended to be designed, in such a way that the driver assistance system is essentially always subordinate to the driver of the motor vehicle. This also applies to driver assistance systems that are designed for at least temporary fully automated driving.
[0030] This means that if the driver intervenes in the vehicle's operation, for example by operating the steering wheel, accelerator pedal, or brake, this intervention is permitted by the driver assistance system even during fully automated driving, even if the control signals generated by the driver assistance system for this situation indicate a different course of action. However, by intervening in the vehicle's operation, at least some responsibility for driving is transferred to the driver. Therefore, using appropriate raw data, it can be subsequently determined to what extent the driver's intervention influenced the resulting driving situation and, consequently, to what degree the driver is partly responsible for an accident, for example.
[0031] The internal sensor system serves not only to record driver interactions but also to document the absence of interactions and the reasons for them. For example, if the data is no longer sufficient and / or reliable enough, and the driver assistance system initiates a switch from fully automatic to manual control, but the driver does not take over control—perhaps due to a sudden deterioration in their health—then the manufacturer of the driver assistance system is not fully responsible for any subsequent problematic driving situation, such as traffic violations, or a critical driving situation, such as an accident. This can be demonstrated using the raw data from the internal sensor system.
[0032] A corresponding internal sensor system includes, for example, an interior camera and / or touch sensors, which are positioned, for example, on the steering wheel or on the pedals.
[0033] The larger the amount of data recorded by the log data recorder per unit of time, the more accurately it can be reconstructed how a problematic or critical driving situation arose. At the same time, the storage requirements increase with the amount of data per unit of time, and thus the demands placed on the data storage within the log data recorder. Since log data is primarily needed when a problematic or critical driving situation actually occurs or has occurred, but otherwise recording such log data can generally be dispensed with, the log data recorder preferably includes a control and evaluation unit configured to initiate log data recording as soon as the control and evaluation unit detects a predefined trigger condition.
[0034] In this case, log data is not recorded continuously, but intermittently under specific conditions, thus reducing storage requirements. Typically, various trigger conditions are defined that lead to the temporary recording of log data. For example, one trigger condition is met when the driver manually activates the recording, such as by pressing a button. Another trigger condition is typically met when an error message is generated in the driver assistance system or in the vehicle in general, indicating a fault or defect, such as a malfunction or failure of a sensor in the external or internal sensor system.A further trigger condition is expediently met when a switch between the operating mode for fully automatic vehicle guidance and the operating mode for manual vehicle guidance is initiated, since this also entails a transfer of responsibility.
[0035] In a further advantageous configuration, the log data recorder is also set up to implement a rolling data storage system, so that the log data is temporarily stored in the rolling data storage. The rolling data storage is designed for a fixed time interval, and accordingly, log data is preferably recorded continuously and intermittently, with log data whose recording dates back further than permitted by the specified time interval being overwritten by new log data. In this way, the most recent log data for a fixed time interval is always temporarily stored in the rolling data storage.
[0036] Furthermore, the log data stored in the rolling data storage is preferably saved permanently when a trigger condition is met, for example, when a problematic or critical driving situation occurs. For this purpose, a separate data storage device or a separate data storage area is provided, into which the data stored in the rolling data storage is copied or transferred. Since this type of log data recorder involves continuous, intermittent recording of the log data, the detection of a trigger condition in this case does not initiate recording, but rather the permanent saving of the log data stored in the rolling data storage, specifically the transfer of the log data stored in the rolling storage to a permanent storage location.
[0037] The transmission of log data preferably occurs by permanently storing log data recorded within a predefined timeframe or window in the rolling data storage. This time window extends on both sides by the point in time at which the triggering condition was determined. In this way, a certain lead time and a certain lead time to an event that led to the permanent storage of log data are recorded. A corresponding event or triggering condition occurs, for example, when there is a violation of traffic regulations, such as running a red light or driving on the hard shoulder, or when control of the vehicle changes between the driver assistance system and the driver virtually without warning, for example, when the driver intervenes in the vehicle's operation.
[0038] Furthermore, the log data recorder is advantageously configured for the chronological evaluation of the log data, whereby the log data is stored taking this chronological evaluation into account. It is important to consider that raw data is first generated, subsequently processed, prepared, and evaluated, and that finally, control signals for the fully automated vehicle guidance system are determined and generated. If raw data, processed data, and control signals are to be recorded simultaneously as log data at a given time t0, then the processed data available at that time t0 is based on raw data generated at a time t < t0, and likewise, the control signals are based on processed data generated at an earlier time t < t0.For later analysis of the log data, it is advantageous if related data, i.e., data that build upon one another, can be easily identified or determined as such, for example, by grouping them into a single data unit and / or storing them together. Depending on the application, various implementation options are available for the log data recorder to enable appropriate chronological evaluation and the associated storage of the log data.
[0039] One of these implementation variants involves generating and / or transmitting raw data in packets, with each packet containing raw data from a predefined time interval. These packets are then assigned a fixed timestamp, indicating, for example, when the corresponding data packet was completed. This timestamp is then retained as a kind of identifier and is therefore also included in the data packet containing processed data, as well as in the data packet containing control signals generated from the corresponding raw data packet. The relationship between the individual data points or data packets is thus established by this identifying timestamp.
[0040] Alternatively, the chronological assignment of the various data to each other is carried out using a stored algorithm, which takes into account how long the various process steps or work steps typically take, i.e., the generation of raw data, the generation of processed data in the course of the various processing stages, and the generation of control signals, and how much time the transmission of the different data to the log data recorder takes, so that, before the recording of processed data from a specific processing stage, it can be calculated back to which raw data this processed data ultimately derives.
[0041] Furthermore, different versions are available for integrating the log data recorder into the driver assistance system, depending on the application. This applies particularly to the bus systems used for data transmission, such as Ethernet and FlexRay. TM or CAN, to avoid overloading the protocol data recorder and its operation, in particular to avoid temporary overloading.
[0042] According to one implementation variant, all generated data intended for recording are automatically transmitted to the log data recorder, so that in this case the log data recorder is integrated into the driver assistance system as a passive unit or passive module.
[0043] Alternatively, the data log recorder includes a control and evaluation unit configured to manage data streams containing log data. In this case, the data log recorder actively accesses data storage or buffer memory to selectively request data and regulate data streams. In a further advantageous configuration, such an active data log recorder is also set up to select, depending on the situation, which data is recorded and which is ignored.
[0044] For example, it is possible to disregard the raw data from certain sensors of the internal and / or external sensor system in specific situations. If the external sensor system includes, for instance, a surround-view camera designed for daylight conditions, as well as other redundant sensor units, it makes sense to disregard the raw data from the surround-view camera during night driving, as the corresponding raw data does not provide usable information under these conditions. Similarly, the raw data from a reversing camera is not needed as long as the vehicle is moving forward. Such situation-dependent adjustment of the log data further reduces the storage requirements of the log data recorder.
[0045] Advantageously, the log data recorder is also designed in such a way that it is suitable for retrofitting and can be used with driver assistance systems already in operation. A modular design of the log data recorder or a design as a single unit that can be integrated into a driver assistance system via a few, and preferably simple, interfaces is beneficial in this regard.
[0046] Exemplary embodiments of the invention are explained in more detail below with reference to a schematic drawing. This drawing shows:
[0047] Fig. 1 in a block diagram a driver assistance system with a log data recorder,
[0048] Fig. 2. In a flowchart, a decision and process flow for starting permanent storage of log data,
[0049] Fig. 3. In a flowchart, a process flow for recording log data,
[0050] Fig. 4 in a block diagram an active connection of a log data recorder to a sensor unit as well as
[0051] Fig. 5. In a flowchart, a decision-making and process flow for recording log data.
[0052] Corresponding parts in all figures are marked with the same reference symbols.
[0053] The following example describes and is presented in Fig. 1. Outlined driver assistance system 2 is for a motor vehicle 4 designed and accordingly in a motor vehicle 4 The driver assistance system is installed here. 2 set up to implement two operating modes, whereby the driver assistance system 2 in one of the two operating modes, the manual operating mode, a vehicle operator or driver of the motor vehicle 4assists with manual vehicle operation, whereas the driver assistance system 2 in the other operating mode, the fully automatic operating mode, control over the motor vehicle 4 completely takes over, so that fully automated vehicle control is achieved.
[0054] This includes the driver assistance system. 2 an external sensor system 6 , with whose help raw data RD is combined with information about the vehicle's surroundings 4 be generated. The external sensor system is involved. 6 from several sensor units 8 structured so that the various sensor units 8 Partly different information and partly redundant information is recorded.
[0055] This is a sensor unit 8 as a surround camera 10 trained and another sensor unit 8 as a radar system 12, which means that both sensor units 10 , 12 Information about objects in the vicinity of the vehicle 4 , for example, about obstacles or other road users, so that both sensor units 8 Generate raw data (RD) with redundant information. Furthermore, the raw data (RD) from the environment camera allows... 10 However, it is also possible, for example, to draw conclusions about the road surface condition, so that the raw data RD from the surround view camera 10 also contain information which includes the information from the raw data RD of the radar system 12 to supplement. In the exemplary embodiment, the sensor units 8 of the external sensor system 6 also independent of the operating mode of the driver assistance system 2 activated and therefore generate during the operation of the motor vehicle 4 permanent raw data RD.
[0056] The raw data RD generated in this way is then transmitted via a data bus 14 to a data processing unit 16 of the driver assistance system 2 transmitted, and subsequently in the data processing unit 16 The data is prepared, processed, and evaluated in several processing stages (VA-VF). These individual processing stages (VA-VF) build upon one another, and within each stage (VA-VE), processed data (AD) is generated. This AD forms the basis for the subsequent processing stage (VB-VF), which ultimately always reverts to the raw data (RD) of the external sensor system. 6 are attributable to this. For each processing stage VA-VF, the data processing unit 16 further, a separate logic unit 18 which is adapted to the specific hardware requirements of the respective processing stage VA-VF and which uses buffer memory 20 with the logic units 18is connected to the previous processing stage VA-VE on the one hand and the subsequent processing stage VB-VF on the other hand for data transmission.
[0057] In the exemplary embodiment, the first processing stage VA involves a fusion of raw data RD, whereby, among other things, a temporal assignment of the raw data RD of the various sensor units takes place within the scope of the corresponding data fusion. 8 This occurs, for example, with the raw data RD from the surrounding camera. 10 and the raw data of a weather sensor system 22 , so that the raw data RD of the environment camera 10 , which describe the spatial conditions in the vicinity of the motor vehicle 4 reflect the raw RD data from the weather sensor system at a specific time or time interval. 22 are assigned to determine the weather conditions in the vicinity of the motor vehicle. 4reproduce at that exact time or within that time interval.
[0058] For this purpose, the corresponding logic unit 18 Data packets are generated and output as processed data AD, containing information from the various sensor units. 8 were captured within the same time interval. The corresponding data packets are then stored in a unit controlled by the relevant logic unit. 18 The data packets are generated according to a predefined clock cycle and represent time intervals of the same size. Furthermore, each data packet is provided with a timestamp, i.e., a temporal reference point, indicating at what point in time, or rather within which time interval, the information contained in the data packet was processed by the sensor units. 8 were won.
[0059] In the subsequent processing stage VB, the processed data AD from processing stage VA, which is available as data packets, is evaluated. Based on predefined criteria, it is checked whether the data in the data packets is sufficiently comprehensive and reliable. Insufficient comprehensiveness exists, for example, if a system-relevant sensor unit... 8 , like the surround camera 10 , fails or malfunctions, so that it generates no or only unusable raw data. Insufficient reliability, on the other hand, exists, for example, when a system-relevant sensor unit fails. 8 Although it works correctly, the environmental conditions prevent the acquisition of information with this sensor unit. 8 This can affect, for example, the raw RD data from the surround-view camera. 10Essentially unusable in dense fog or heavy snowfall. The assessment is integrated into the data packets during this processing stage (VB), and the processed data (AD) is then transferred to the next processing stage (VC) by being stored in the downstream buffer. 20 made available.
[0060] In the subsequent processing stage VC, an environment model is generated based on each data packet, which represents the environment of the vehicle. 4 as well as the environmental conditions at the time the information is acquired by the sensor units 8 it displays and reflects the corresponding traffic situation. For example, the area camera's view is used to monitor the surroundings. 10 The information obtained is evaluated by analyzing the associated data with an object recognition algorithm.
[0061] Based on each environmental model, possible trajectories are then determined in the subsequent processing stage VD, which can in principle be used as a basis for fully automated vehicle control due to the corresponding traffic situation.
[0062] In a further processing stage VE, the final strategy is then planned, whereby a trajectory is selected from the number of possible trajectories identified, based on stored criteria.
[0063] In the final processing stage VF, control signals S are then determined and generated based on the selected trajectory, which are used to control various actuators. 24 in the motor vehicle 4 to be controlled, so that the motor vehicle then 4 moved according to the route planning, i.e., according to the selected trajectory.
[0064] Even the calculation or determination of the control signals S is still independent of the current operating mode of the driver assistance system. 2 The generation of the control signals S, however, is only carried out in the operating mode for fully automatic vehicle guidance. In this way, the switch from the operating mode for manual vehicle guidance to the operating mode for fully automatic vehicle guidance can be made at any time, i.e., as needed or desired, without requiring a lengthy lead time.
[0065] In manual driving mode, the generated environment models are used to assist the driver by, for example, alerting them to potential hazards, such as special weather conditions or the problematic behavior of other road users, through visual or acoustic signals.
[0066] In order to be able to subsequently determine, in the event of a problematic or critical driving situation, especially in the event of an accident, how the driving situation arose and who is responsible for it and to what extent, the driver assistance system includes 2 of the motor vehicle 4 in addition, a log data recorder 26 , which is configured as a "system logger" to record protocol data PD. The protocol data PD comprises the raw data RD from the individual sensor units. 8 , the control signals S, if corresponding control signals S are generated, as well as the processed data AD of the various processing stages VA-VE.
[0067] Recording of the PD log data by the log data recorder 26 This occurs during the operation of the motor vehicle. 4permanent or continuous, whereby the log data (PD) is initially only recorded for a limited time and only permanently stored in the case of certain events. For this reason, the log data recorder 26 a storage 28 a storage area which is divided into two storage areas, with a first storage area being used in the manner of a rolling storage system, whereas the other, second storage area is used as permanent storage for the permanent storage of protocol data (PD).
[0068] The storage area for the rolling storage is designed to record log data (PD) over a period of 10 minutes, so that this initial storage area always contains the log data (PD) of the last ten minutes. If a specific event occurs, which is defined as a trigger condition for permanent storage of log data (PD), the log data (PD) of the last ten minutes is transferred from the rolling storage to the permanent storage area, and the log data of the following ten minutes is also gradually stored in the permanent storage area.
[0069] If needed, for example after an accident, the PD log data can then be retrieved from the second storage area for permanent storage via an interface. 30read the data and copy it to an external storage device (not shown). The memory 28 of the log data storage 26 Furthermore, it is designed in such a way that protocol data (PD) stored in the memory area for permanent storage is used by the driver assistance system. 2 They cannot be deleted or overwritten by the user. Deletion or formatting of the corresponding data area or storage area is only possible via the interface. 30 possible. So that the memory is not cleared after every relevant event. 28 Since the log data PD belonging to several events needs to be read out and can be permanently stored, the second storage area is designed for permanent storage in order to save log data PD that together represent a time interval of one hundred minutes.
[0070] For controlling the data flows into the two memory areas of the storage system. 28 the log data recorder indicates 26 further, a control and evaluation unit 32 on, which depend on trigger signals T of a triggering unit 34 The PD log data storage process starts and stops in the area designated for permanent storage. The trigger unit generates [something - likely a specific data entry or error message]. 34 a corresponding trigger signal T is generated, among other things, every time the driver assistance system switches between its two operating modes. 2 , regardless of whether the change in operating mode is initiated by the driver, for example by pressing a switch, or by the driver assistance system 2 himself.
[0071] Furthermore, a corresponding trigger signal T is generated when any electronic component in the motor vehicle 4 , in particular an electronic component of the driver assistance system2 , generates an error signal or when stored in the so-called error memory 35 of the motor vehicle 4 An error message will be logged.
[0072] Furthermore, a trigger signal T is also generated if, during the evaluation of the data packets in the processing stage VB, a predefined requirement is not met for more than two consecutive data packets. Typically, two requirement thresholds are defined: if the first threshold is undershot, a trigger signal T is generated, and if the second threshold is undershot, the operating mode for fully automatic vehicle guidance is temporarily disabled. This either initiates an immediate change of operating mode from fully automatic vehicle guidance to manual vehicle guidance, or, if the driver assistance system... 2If the vehicle is in manual driving mode, switching to fully automatic driving mode may not be possible at times.
[0073] Finally, a trigger signal T is also generated when the driver assistance system 2 A problematic or critical driving situation has been identified. A problematic driving situation is typically understood to mean traffic-related behavior, i.e., a violation of a traffic rule, whereas a critical driving situation exists in the event of an accident.
[0074] The trigger unit works in this process. 34 according to the flowchart Fig. 2, wherein in a first process step A, the current driving situation, represented by the current environment model, is queried. In a subsequent process step B, it is then first checked whether the traffic rules are being observed, for which information about traffic rules is retrieved from a memory. 37 the trigger unit 34 The following information is queried. In a further process step C, it is checked whether the motor vehicle 4 works flawlessly and for this purpose the error memory is used 35 of the motor vehicle 4The data is read out. In process step D, the current driving situation is further analyzed to determine whether a critical driving situation exists, such that an accident may be imminent. Finally, in process step E, it is determined whether a trigger signal T is present, which was triggered by the driver activating a switch, by a timer, or by a remote control. If the traffic rules are not observed, the vehicle is then... 4 If an error occurs, a critical driving situation exists, or a trigger signal T has been generated as a result of another event, the recording of log data PD is initiated in a process step F and subsequently the log data PD is recorded in a process step G.
[0075] In addition to the external sensor system 6 The driver assistance system includes 2 of the motor vehicle 4also an internal sensor system 36 , which also consists of several sensor units 8 is constructed. In the exemplary embodiment, the internal sensor system has 36 as sensor units 8 an interior camera 38 for generating raw data RD with information about the interior of the motor vehicle 4 as well as an intervention recording unit 40 These sensors detect driver interventions in the vehicle's control system. The raw data (RD) from these two sensor units 8 These are also part of the PD log data and are therefore recorded by the log data recorder. 26 The data was recorded. Recording this data also serves to create the possibility of subsequently providing proof of whether the driver assistance system was functioning correctly. 2 , the driver or both were responsible for a driving situation.
[0076] The intervention detection unit thus serves 40 to determine whether and in what way the driver can be involved in the control of the vehicle during the operating mode for fully automatic vehicle control. 4 has intervened. This is significant because the driver assistance system 2 In the exemplary embodiment, even in the operating mode for fully automatic vehicle control, the driver is permitted to intervene in the vehicle control at any time, whereby, figuratively speaking, the driver's control commands correspond to the driver assistance system's control commands. 2 , i.e., the control signals S are overridden. Therefore, if the driver intervenes with the steering, for example, the lateral control of the vehicle is overridden. 4 determined by the steering movement of the driver, whereas the longitudinal control of the motor vehicle 4 , so essentially the control of the accelerator and brake pedals, continues to be handled by the driver assistance system2 This occurs if the driver makes no intervention. In such a case, responsibility then passes, at least partially and at least temporarily, to the driver, meaning that they are at least partly responsible in the event of a problematic or critical driving situation.
[0077] In an alternative design of the driver assistance system 2 This requires any intervention by the driver in the control of the motor vehicle. 4 automatically switches between the operating mode for fully automatic vehicle control and the operating mode for manual vehicle control, thus completely transferring responsibility to the driver.
[0078] To simplify the evaluation of the PD log data, the log data recorder is used. 26Furthermore, it is configured to order the PD log data chronologically and save it in chronological order. The log data recorder 26 In this embodiment, it is designed as a passive "system logger" and accordingly the log data PD are sent to the log data recorder. 26 automatically transmitted, without the user actively requesting the corresponding PD log data.
[0079] In order to order the PD protocol data chronologically, the incoming data packets are processed in a data input with a timestamp unit. 42 First, a timestamp is provided using hardware support, thus enabling the control and evaluation unit to... 32 of the log data recorder 26 supplied. In the control and evaluation unit 32The data packets are then sorted by type, i.e., depending on whether the data packet contains raw data RD, control signals S, or processed data AD of a specific processing level VA-VE, as well as by timestamp, and subsequently stored as elements of data units DE in memory. 28 The data is stored, with each data unit DE containing a set of raw data RD, the resulting processed data AD, and the control signals S generated based on this. Thus, each data unit DE contains all the data generated by the driver assistance system. 2 They are generated based on information captured at a specific point in time or within a specific time interval. In this example, a time interval of 25 ms is chosen, so that 2400 data units represent a period of 1 minute.
[0080] The storage of the PD log data is carried out in accordance with the [document / section / etc.]. Fig. The flowchart shown in section 3 is used. First, the data recorded in the log data recorder is processed. 26 Incoming data packets are first time-stamped in process step I. In process step II, it is then calculated for each data packet which raw data (RD) the information in the corresponding data packet can be traced back to, based on the data packet's timestamp. This calculation is based on data stored in a data repository. 46The system uses stored time values that specify how long each step takes, from generating the raw data (RD) to generating the control signals (S), and how much time the data transmission of the respective data packets requires. These values include not only specific values, such as 10 ms for merging the raw data (RD) and 5 ms for analyzing an environmental model, but also tolerances to account for any deviations. Based on these tolerances, the individual data packets are re-evaluated chronologically. During this re-evaluation, each data packet is assigned an additional timestamp or a temporal reference point indicating which raw data (RD) the data packet ultimately originates from. The re-evaluated data packets are then stored in a buffer in a subsequent process step III. 43Data packets belonging to a specific time reference point are collected until they are available. Subsequently, all data packets belonging to a specific time reference point are stored in a data unit DE during process step IV.
[0081] The buffer storage at a time t 43 The newly classified data packets stored are in Fig. Figure 3 illustrates this in a block positioned on the right, where, for simplicity, a complete data unit DE comprises only the raw data RDM of a sensor M, the raw data RDN of a sensor N, the processed data ADA generated during processing stage VA, and the processed data ADC generated during processing stage VC. At time t, the buffer contains... 43Data packets are presented, assigned to the time reference points t, t – Δt, and t – 2Δc. For each of these time reference points, a data packet containing raw data RDM and RDN from the two sensors M and N is available. At the reference point t – Δt, a data packet with processed data ADA of processing level A is already present, as the corresponding data could be generated within the time interval Δt before time t. At the time reference point t – 2Δt, a complete data unit DE is available, which is now stored in the rolling memory. Protocol data PD with a more distant time reference point is in the buffer memory. 43 not available, as these were already previously stored in the rolling memory.
[0082] An alternative design variant of the log data recorder 26Accordingly, it is configured as an active "system logger". Therefore, the PD log data is not automatically sent to the log data recorder. 26 Instead of transmitting, this system actively retrieves PD log data or sends corresponding requests to connected recipients. Fig. 4 is an example of a sensor unit. 8 depicted, each via a bidirectional interface 44 with the data processing unit 16 on the one hand, and the log data recorder 26 on the other hand, it is connected. If necessary, the log data recorder sends... 26 via its bidirectional interface 44 a request to the sensor unit 8 , which are then controlled by a controller 45 the requested log data PD to the log data recorder 26 transmitted. The transmission of raw data (RD) to the data processing unit. 16However, this occurs continuously as long as the sensor unit 8 is activated. The activation or deactivation of the sensor unit. 8 However, this does not happen automatically when the driver assistance system is activated or deactivated. 2 Rather, activation and deactivation are controlled by the data processing unit. 16 This is done depending on whether or not it requires the corresponding raw data RD.
[0083] The operating method of the active "system logger" is described in Fig. Figure 5 is shown schematically. Here, the log data recorder must be used. 26 First request the PD log data in order to then store it in memory 28 to be able to store. If, in a process step a, a request to save log data PD, i.e., a trigger signal T, is received by the log data recorder 26If so, a corresponding data recording is initiated, whereby in a process step b it is first determined what scope the log data PD to be recorded has, i.e. which data should be recorded.
[0084] For this purpose, information is taken from a database. 48 The data retrieved determines which data is recorded as part of the PD log data under which environmental conditions and driving situations. This includes, among other things, the raw RD data from the surround-view camera. 10 Only data recorded under daylight conditions is included; data recorded at night is not included in the log data PD. Once the intended scope of the log data PD has been determined, the actual storage process is started in process step c, until a request to terminate the process is received in process step d. 26when a timer stops recording PD log data or when a timer stops recording after a specified period of time.
[0085] Once the storage process has started, the first step in the process checks whether all data intended for recording is sent to the log data recorder. 26 The data is transmitted. If this is not the case, a corresponding request is issued in a process step f, or deactivated sensor units are displayed. 8 activated, so that it subsequently transmits the required raw data RD. In a further process step g, it is checked whether the log data recorder 26 synchronized with the rest of the driver assistance system 2 and in particular with the data processing unit 16The log data recorder is functioning, and if it is not, time synchronization is performed in a process step h. The individual data packets of the log data PD are then described upon arrival at the log data recorder. 26 During process step i, the data packets are given a timestamp, and the current GPS position and control information are also appended to them before they are finally stored in memory in process step j. 28 be saved.
[0086] The invention is not limited to the embodiment described above. Rather, other variants of the invention can also be derived by a person skilled in the art without departing from the subject matter of the invention. In particular, all individual features described in connection with the embodiment can also be combined with one another in other ways without departing from the subject matter of the invention. Reference symbol list 2 Driver assistance systems 4 Motor vehicle 6 external sensor system 8 sensor unit 10 Surround view camera 12 radar systems 14 Data bus 16 Data processing unit 18 logic units 20 buffer storage tanks 22 Weather sensor system 24 actuator 26 log data recorders 28 storage 30 interface 32 Control and evaluation unit 34 Trigger unit 35 fault memory 36 internal sensor system 37 memory locations of the trigger unit 38 Interior camera 40 Intervention Recording Unit 42 Data input with timestamp unit 43 Buffer memory in the log data recorder 44 bidirectional interface 45 controllers 46 Data storage 48 database RD Raw Data RDM raw data from sensor M RDN raw data from sensor N AD-prepared data ADA-processed data of processing level A ADC-processed data of processing level C PD log data S control signals DE Data unit T trigger signal Δt time interval / time gap VA-VF processing stage A–G Process step a–j Process step I–V Process step
Claims
[1] Driver assistance system ( 2 ) for a motor vehicle ( 4 ) with an operating mode for fully automatic vehicle guidance and with an operating mode for manual vehicle guidance – including an external sensor system ( 6 ) for generating raw data (RD) with information about the vehicle's environment ( 4 ), – comprising a data processing unit ( 16 ) for processing the raw data (RD), for generating processed data (AD) based on the raw data (RD) and for generating control signals (S) for fully automated vehicle guidance based on processed data (AD) as well as – including a log data recorder ( 26 ), which is set up for the automated recording of log data (PD), wherein the log data (PD) includes processed data (AD). [2] Driver assistance system ( 2) according to claim 1, wherein the processing of the raw data (RD) in the data processing unit ( 16 ) in several successive processing stages (VA-VF) and in each processing stage (VA-VF) processed data (AD) or control signals (S) are generated. [3] Driver assistance system ( 2 ) according to claim 2, wherein the log data (PD) comprises the raw data (RD) and the processed data (AD) from at least one processing stage (VA-VF). [4] Driver assistance system ( 2 ) according to any one of claims 1 to 3, wherein the protocol data (PD) comprise the control signals (S). [5] Driver assistance system ( 2 ) according to one of claims 2 to 4, wherein the external sensor system ( 6 ) several sensor units ( 8 ) includes, which each generate raw data (RD) during operation, whereby a fusion of the raw data (RD) of several sensor units ( 8) to generate a database during a processing stage (PA) and wherein the log data (PD) includes the processed data (AD) of this processing stage. [6] Driver assistance system ( 2 ) according to one of claims 2 to 5, wherein in the course of a processing stage (PC) an evaluation of a data obtained using the external sensor system ( 6 ) and the data processing unit ( 16 ) generated database and wherein the log data (PD) includes the processed data (AD) of this processing stage (VB). [7] Driver assistance system ( 2 ) according to one of claims 2 to 6, wherein an environment model is generated in the course of a processing stage (VC) and wherein the log data (PD) comprise the processed data (AD) of this processing stage (VC). [8] Driver assistance system ( 2) according to one of claims 2 to 7, wherein in the course of a processing stage (VD) objects of an environment model are evaluated and wherein the log data (PD) comprise the processed data (AD) of this processing stage (VD). [9] Driver assistance system ( 2 ) according to one of claims 2 to 8, wherein possible trajectories for fully automatic vehicle guidance are determined in the course of a processing stage (VE) and wherein the protocol data (PD) comprise the processed data (AD) of this processing stage (VE). [10] Driver assistance system ( 2 ) according to one of claims 2 to 9, wherein in the course of a processing stage (VE) a trajectory is selected from a set of determined possible trajectories for fully automatic vehicle guidance and wherein the protocol data (PD) comprise the processed data (AD) of this processing stage (VE). [11] Driver assistance system ( 2) according to one of the preceding claims comprising an internal sensor system ( 36 ) for generating raw data (RD) with information about the driver of the motor vehicle ( 4 ), where the log data (PD) includes raw data (RD) containing information about the driver. [12] Driver assistance system ( 2 ) according to one of the preceding claims, wherein the recording of log data (PD) is temporary and wherein the log data recorder ( 26 ) a control and evaluation unit ( 32 ) includes, which is set up to start recording log data (PD), provided the control and evaluation unit ( 32 ) a predefined trigger condition (T) is determined. [13] Driver assistance system ( 2 ) according to one of the preceding claims, wherein the log data recorder ( 26 ) to implement a rolling data storage system ( 28) is set up and the log data (PD) is stored at least temporarily in the rolling data storage ( 28 ) will be stored. [14] Driver assistance system ( 2 ) according to one of the preceding claims, wherein the log data recorder ( 26 ) a control and evaluation unit ( 32 ) includes, which is set up for the chronological evaluation of the log data (PD), and wherein the log data (PD) are stored taking into account the chronological evaluation. [15] Driver assistance system ( 2 ) according to one of the preceding claims, wherein the log data recorder ( 26 ) a control and evaluation unit ( 32 ) includes, which is set up to control data streams with protocol data (PD). [16] Log recorder ( 26 ) for a driver assistance system ( 2 ) according to any of the preceding claims.
Citation Information
Patent Citations
connected multi-purpose robotic vehicle
DE112006002894T5
Control and systems for autonomously driven vehicles
US20140214259A1
Robust sensor fusion for mapping and localization in a simultaneous localization and mapping (SLAM) system
US7689321B2