Method for ensuring the functional reliability and integrity of shutdown devices in the vehicle by preventive control of the shutdown of energy suppliers in a vehicle, as well as vehicle
The method predicts collisions using trajectory planning data to manage power supply shutdowns in vehicles, ensuring rapid and controlled disconnections only when crashes are imminent, addressing safety and reliability challenges in automated driving.
Patent Information
- Application Number
- DE102018214201
- Authority / Receiving Office
- DE · DE
- Patent Type
- Patents
- Current Assignee / Owner
- Filing Date
- 2018-08-22
- Publication Date
- 2025-08-14
- Estimated Expiration
- 2038-08-22
AI Technical Summary
Existing power supply systems in vehicles face challenges in safely and efficiently disconnecting energy stores during a crash to prevent short circuits and fires, while maintaining functional reliability and integrity, especially in highly automated driving scenarios, where stringent safety requirements are necessary to avoid erroneous shutdowns and thermal events.
A method using trajectory planning data to predict potential collisions and initiate a standby mode for power supply systems, allowing for rapid shutdown only when a crash is imminent, thereby avoiding unnecessary disconnections and ensuring safety-relevant components remain powered during automated driving.
Enables rapid and controlled shutdown of energy stores only when necessary, reducing the risk of thermal events and maintaining power to critical systems, thus enhancing safety and reliability in automated driving environments.
Smart Images

Figure 00000000_0000_ABST
Abstract
Description
[0001] The invention relates to a method for preventive control of the shutdown of energy suppliers in a vehicle, as well as to a vehicle.
[0002] In-vehicle power supply systems such as batteries, converters, and power lines must be disconnected in the event of a crash to prevent short circuits and the associated fire hazard, and to protect the post-crash electrical system. Currently, this disconnection is achieved using acceleration sensors or pressure hoses.
[0003] The shutdown information is generated in the event of a crash, i.e., when an actual impact or collision occurs. This makes it imperative that the memory devices are capable of very fast shutdown, typically less than 20 ms. This results in high costs, as power electronic switches must be used, and also severely limits the technical options for solutions.
[0004] Particularly in the field of highly automated and even autonomous driving, increasingly stringent requirements are being placed on the energy supply system with regard to "fail operational" (i.e., a secure energy supply). Accordingly, shutdown mechanisms are subject to high requirements regarding functional reliability and integrity.
[0005] Therefore, it is an object of this invention to provide a corresponding method and system that enables improved control of the shutdown of energy storage devices. This object is achieved according to the invention by the features of the independent patent claims. Advantageous embodiments are the subject of the dependent claims.
[0006] Due to the fact that there are two conflicting requirements for the energy management of the on-board power system, it is necessary to provide a solution for switching off energy storage devices, especially in the event of a crash, i.e. in the event of an accident that results in or could result in a collision.
[0007] The requirements for the energy management of the on-board power system are, on the one hand, that no negative influences on the stability of the post-crash-relevant on-board power system, such as permanent short circuits, may occur. Furthermore, no negative influences due to possible thermal events may occur, and no feedback may occur in non-post-crash-relevant areas of the on-board power system. To prevent this, the non-post-crash-relevant systems must be shut down.
[0008] On the other hand, especially in AD operation (AD = Autonomous / Automated Driving System), i.e., in highly automated driving mode, where automated driving functions or driver assistance systems with high integrity requirements are present, faulty crash shutdown of the secondary power supply system, as well as of safety-relevant components in the primary power supply system with very high integrity requirements, usually at least ASIL B(D), must be avoided. In AD operation, faulty joint crash shutdown of the secondary power supply system and the safety-relevant components in the primary power supply system must also be avoided. This means that a secure power supply to the partner systems must be guaranteed during vehicle operation, with speed-dependent safety targets being set for the power supply.In addition, incorrect shutdown of the high-voltage (HV) system must be avoided, as this could result in irreversible disconnection, e.g. via pyrotechnics.
[0009] In this respect, a shutdown of the power supply, especially of Li-ion batteries, must be ensured, which can meet both requirements. Li-ion batteries are particularly affected because they pose a high risk of thermal events and, on the other hand, can deliver continuously high currents, which increases the risk of fire in the event of short circuits. In principle, other types of batteries, such as lead-acid batteries, can also be shut down.
[0010] ISO 26262, a standard for safety-relevant electrical / electronic systems, defines so-called ASI levels (ASIL for short), where ASIL stands for "Automotive Safety Integrity Level." During component development, risks are assigned an ASIL rating based on their significance to exclude failures. This rating is divided into ranges from A to D, with the safety requirement for functional safety with respect to the system's probability of failure increasing from A to D. With regard to energy storage, all functions involved in the energy supply are subject to stricter integrity requirements. This also applies to the shutdown device.
[0011] To solve the aforementioned problem of conflicting requirements, a preventive shutdown or triggering of an interface for shutting down or disconnecting the power supply, e.g., batteries, converters, or airbags, and pre-crash functions are provided by using trajectory planning data to determine a collision-free path. The proposed solution is particularly advantageous for automated vehicles, i.e., vehicles that drive at least in AD mode, i.e., when a driver is present but no longer involved in the driving process. The method is described below using a vehicle in AD mode.
[0012] To drive in AD mode, a vehicle is equipped with extensive sensor technology for trajectory planning. The trajectories are calculated in central control units using numerous sensors, ranging from image processing sensors to radar in various designs, LIDAR, ultrasonic sensors, acceleration sensors, etc. A byproduct of this is the ability to predict a collision, including the resulting damage. This information can be used, among other things, to directly shut down energy supply systems such as batteries, cables, or converters.
[0013] By using information from trajectory planning, a crash shutdown can be implemented in ASIL D or a faulty triggering of the crash shutdown in ASIL D can be prevented without the need to install additional (redundant) sensors or logic. This allows preventive action, which places fewer demands on the actuators. Furthermore, additional sensors, for example, for airbags, can be eliminated.
[0014] A method is proposed for the preventive control of the shutdown of power suppliers in a vehicle. Trajectory planning determines a time period within which a maneuver can be executed without a collision. Depending on the detected time period, a collision warning is issued, which puts the system into standby mode to shut down the power supply.
[0015] A possible collision situation is therefore predicted from existing data to plan a route. In the event of a probable crash, i.e. when a predefined limit is reached or undercut, a collision warning is issued and the system is put into standby mode, but the power supply is not (yet) switched off. Standby mode is characterized by regular checks to determine whether the situation has changed, i.e. whether the probability of a crash occurring is increasing or decreasing. This allows a faster reaction, i.e. switching off the energy storage devices, if the probability increases and therefore a crash occurs. Standby mode remains active until the all-clear is given, i.e. the probability of a crash is downgraded, or a crash is detected and the power supply is switched off.
[0016] Trajectory planning is necessary for driving in AD mode. In order to predict a collision-free path, a collision prediction is also made, usually by determining a time-to-last maneuver (TLM), i.e. a period of time by which a maneuver must be performed to avoid a collision, or a time-to-collision (TTC), i.e. a remaining period of time until a collision. According to the invention, the already known data from trajectory planning is additionally used to fulfill the above-mentioned requirement for functional safety when driving in AD mode. This is that the energy supply for driving in AD mode must not be switched off if possible, except in the event of a crash, when this could pose a risk of damage due to damage to the energy storage devices, e.g., the lithium-ion batteries.The risk is determined by a corresponding classification described later.
[0017] The power supply for automated driving functions is typically divided into two separate channels, namely the primary power supply and the secondary power supply. These are typically low-voltage systems, such as 12V systems. The proposed method can, in principle, also be applied to the entire power supply for all non-post-crash-relevant areas, since an ASIL D from the trajectory planning already ensures the highest safety level.
[0018] An AD mode is a mode in which a vehicle operates in a highly automated manner. Highly automated is defined as a mode that lies between assisted and autonomous driving. In highly automated driving, the vehicle already plans ahead and takes over the driving task in at least most situations. It is therefore close to being able to drive autonomously. For the purposes of this document, AD mode is defined as a mode that encompasses at least highly automated driving, i.e., a mode that extends all the way to autonomous driving.
[0019] The threshold at which a collision warning is issued, since a possible crash is predicted, can be selected by the expert and is advantageously in a range of 500 ms or less, 300 ms or less, or 200 ms or less until a crash if a time-to-collision (TTC) is used. If a time-to-last maneuver (TLM) is used, this value can be selected as zero, as this still leaves sufficient reaction time—at least 500 ms TTC or less—to prevent the collision.
[0020] Furthermore, it is provided that the power supply used to execute driving in AD mode is prevented from being shut down if no crash is detected after the collision warning is issued. However, the power supply used to execute driving in AD mode is enabled to be shut down if a crash is detected after the collision warning is issued.
[0021] During trajectory planning, a large amount of information is already determined that can be used for the method according to the invention. For example, a so-called Safety Score (SSC) is calculated in ASIL D. A Time-to-Last-Maneuver (TLM) is also determined. This is the time period by which a maneuver must be performed to avoid a collision, or the TLM indicates the available reaction time within which the collision can be prevented. A Time-To-Collision (TTC) can also be calculated, i.e., the time period until a collision, although generally only the TLM is used. For this reason, the TLM is advantageously used as the time period within which a maneuver can be performed without a collision.The SSC becomes very large for potentially collision-prone trajectories, whereby in unavoidable collisions, i.e. TLM = 0, certain thresholds are exceeded depending on the severity of the damage.
[0022] Furthermore, the power shutoff system is designed to provide active feedback that it has received the collision warning and is in standby mode. This provides an additional level of control. If no feedback is received, the corresponding signal can be sent again until feedback is provided.
[0023] Furthermore, if no or an invalid value is output for the time period, the power supply used to execute driving in AD mode is prevented from being shut down. This serves to maintain the power supply for driving in AD mode to ensure functional safety.
[0024] Furthermore, it is planned that, depending on the recorded time period, an assessment will be made as to whether a collision is imminent and the probability of this occurring. Furthermore, an additional assessment will be made as to the severity of the imminent collision. The term "severity" is to be understood in the sense of the term "severity" in ISO 26262, i.e., the severity of an occurring error, i.e., the risk to the user or the environment. Furthermore, it is planned that the assessment will be carried out in stages, with the stages being subdivided according to the probability of a collision occurring.
[0025] A subdivision is made, for example, into three levels: Level 0: no imminent collision, Level 1: collision possible, Level 2: collision unavoidable. In addition, Level 2 can be further refined. For example, Level 2 can be defined as an unavoidable collision with the controllability of the error being classified as CS1. Level 3 can then be classified as an unavoidable collision with the controllability of the error being classified as CS2, and Level 4 as an unavoidable collision with the controllability of the error being classified as CS3. Further levels or intermediate levels are also possible. The terms CS1-CS3 refer to the severity of the collision or crash severity CS, whereby evaluation criteria according to ISO26262 are used. The crash severity CS can be determined from the differential speed, as well as the type and nature of the objects, and is divided into levels. From Level 2 onwards, the TLM is equal to 0, i.e.A collision is unavoidable, as already mentioned above. At level 3, the differential speed, also depending on the type and nature of the objects, exceeds a threshold, and the crash severity (CS) increases. Furthermore, the trajectory planning is used to determine the direction of impact in the crash, and this assessment is incorporated into the crash severity (CS). Thus, if a frontal crash is imminent but critical components are located only in the rear, a crash trigger can be suppressed to ensure that subsequent accidents can still be detected and responded to.
[0026] The assessment is helpful in determining whether a collision is (inevitably) imminent or merely potentially imminent. This allows a decision to be made as to whether or not to prevent a shutdown of the power supply used to perform AD mode driving. For example, a shutdown may occur if level 2 or higher is detected, while no shutdown occurs if only level 0 or 1 is detected, i.e., an unlikely collision.
[0027] In principle, the procedure is only intended for use when the vehicle is driving or can drive in AD mode, since the corresponding systems are then present and active. Therefore, the control of shutting off the power supply for driving in AD mode, also known as crash locking, is only carried out in AD mode. This means that the requirement here is that the power supply should not be shut off if possible. In this case, the power supply is only shut off in the event of an actual crash to prevent damage to the energy storage devices.
[0028] If a driver is involved, the crash signal is advantageously evaluated by default, so the procedure is not applied.
[0029] To be able to apply the method, a vehicle is further proposed that is configured to drive in an AD mode. For this purpose, the vehicle should have at least one power supply unit configured to supply power to a control unit configured to carry out driving in AD mode.
[0030] Furthermore, it should have sensors for monitoring the vehicle's surroundings and at least one processing device. The processing device should be connected to the sensors and the control unit in such a way that it can receive and transmit signals and / or data.
[0031] In addition, the processing device should also be configured to evaluate the signals and / or data from the sensors in such a way that trajectory planning can be carried out to determine a collision-free travel path in such a way that a time period can be determined within which a maneuver can be carried out without a collision.
[0032] The processing device is then advantageously further configured to issue a collision warning depending on the detected time period, which puts the system into standby mode to shut off the power supply if a value of the detected time period reaches or falls below a predetermined limit. The processing device can be provided for this purpose in a single unit or in the form of several control devices that are at least communicatively connected to one another.
[0033] The advantage of the invention is that data available from an existing system in the vehicle, regardless of the technology used for the shutdown, is additionally processed in such a way that a proactive, i.e., predictive, control of the shutdown of energy suppliers in a vehicle can be implemented. For this purpose, a collision warning is activated when a predefined limit value, which predicts a probable collision, is reached or undershot. Thus, the system is ready and can more quickly shut down energy storage devices, which can also be referred to as energy suppliers, in the event of an actual crash.
[0034] Further features and advantages of the invention will become apparent from the following description of exemplary embodiments of the invention, with reference to the figures of the drawing, which illustrate details of the invention, and from the claims. The individual features can be implemented individually or in combination in a variant of the invention.
[0035] Preferred embodiments of the invention are explained in more detail below with reference to the accompanying drawings. Fig. 1 shows a flowchart of the method according to an embodiment of the present invention.
[0036] The proposed method is implemented in one embodiment by recording information from trajectory planning for collision-free route planning of the vehicle in active AD mode 1, and then carrying out the procedure described above based on this information. If AD mode 1 is active Y, a decision is made based on the trajectory planning T as to whether a collision warning K should be sent. This occurs when a predefined limit is reached or undershot, as described above. If a collision warning K is sent, the probability with which a crash C should occur is also recorded, e.g. in the form of the levels described above. If a certain level has been detected Y, the option for shutdown A is enabled. If no possible crash C has been detected N, e.g. a level 0 or 1, shutdown NA is prevented.This means that not only is there no active shutdown, but shutdown is also actively prevented, e.g., by ignoring a terminal that is normally activated for shutdown. If an actual crash is detected after the collision warning K is sent, shutdown can occur more quickly than before.
[0037] By means of this procedure, the system can be put in readiness for shutdown by the collision warning K in advance, i.e. when it is detected, for example, by means of TLM or TTC, that a crash may be imminent, so that depending on the detected probability that a crash C will occur, approval is given to shut down, for example the battery.
[0038] If AD mode 1 is not active (N), meaning, for example, that a driver is driving the vehicle and a crash has been detected (Y), shutdown (A) occurs as usual. If no crash has been detected, shutdown (NA) does not occur.
[0039] To detect whether a crash is imminent, a Safety Score (SSc) and a Time to Last Maneuver (TLM) are recorded when determining the calculated trajectories. If the Time to Last Maneuver (TLM) is less than an actual latency, a collision is possible. If the Time to Last Maneuver (TLM) is zero, a collision is unavoidable. By determining the SSC and the expected differential speed, as well as the type or nature of the obstacles, a damage severity can be derived, which also influences the assessment of whether or not shutdown should be released. For example, if a TTC of 500 ms or less, 300 ms or less, or 200 ms or less is detected, shutdown can be released in any case. In fully automated vehicles, for example, a pedestrian or cyclist is detected, but the power supply is not switched off because the crash severity is low.This ensures the full sensor / actuator set to be able to react optimally even in the last milliseconds.
[0040] The classification into levels as described above can be selected depending on the detected severity of the error and thus the impact on the driver and the environment.
Claims
[1] Method for ensuring the functional reliability and integrity of shutdown devices in the vehicle, wherein a preventive control of the shutdown of energy suppliers takes place, in which a time period is determined from a trajectory planning (T) for determining a collision-free route, within which a maneuver can be carried out without a collision, wherein a collision warning (K) is issued, which puts the system into a standby mode for switching off the energy supply if a value of the detected time period reaches or falls below a predetermined limit. [2] The method of claim 1, wherein the predetermined threshold is 500ms or less, or 300ms or less, or 200ms or less when the detected time period is a time-to-collision, and is zero when the detected time period is a time-to-last maneuver. [3] Method according to claim 1 or 2, wherein a shutdown of the power supply, which serves to carry out driving in AD mode, is prevented (NA) if no crash (C) is detected after the collision warning is issued, and wherein a release for the shutdown of the power supply takes place (A), which serves to carry out driving in AD mode, if a crash (C) is detected after the collision warning (K) is issued. [4] Method according to one of the preceding claims, wherein the system for switching off the power supply outputs an active feedback that it has received the collision warning (K). [5] Method according to one of the preceding claims, wherein, if no or an invalid value is output for the time period, a shutdown of the power supply used to carry out driving in AD mode is prevented (NA). [6] Method according to one of the preceding claims, wherein, depending on the detected time period, an assessment is made as to whether a collision is imminent and with what probability it is imminent. [7] Method according to claim 6, wherein an additional assessment is made of the severity of the impending collision. [8] Method according to claim 7, wherein the evaluation is carried out in stages, the stages being at least divided into: Level 0: no imminent collision, Level 1: Collision possible, Level 2: Collision unavoidable, whereby only from the case of level 2 onwards is the power supply, which is used to carry out driving in AD mode, switched off. [9] A method according to claim 8, wherein there are further stages in addition to stage 2, which are classified according to the severity of the collision. [10] A vehicle adapted to drive in an AD mode, comprising at least: - at least one power supply unit which is designed to supply power to a control unit which is designed to carry out driving in AD mode, - Sensors for monitoring the vehicle's surroundings - at least one processing device which is connected to the sensor system and the control unit in such a way that it can receive and send signals and / or data, wherein the processing device is further configured to evaluate the signals and / or data from the sensor system in such a way that trajectory planning (T) for determining a collision-free travel path can be carried out in such a way that a time period can be determined within which a maneuver can be carried out without a collision, wherein the processing device is further configured to output a collision warning (K) depending on the detected time period, which puts the system into a standby mode for switching off the energy supply if a value of the detected time period reaches or falls below a predetermined limit value.
Citation Information
Patent Citations
Method and device for controlling the power supply in a power network of a motor vehicle, as well as motor vehicles
DE102011010230A1
Procedures for operating a motor vehicle during and / or after a collision
DE102012007119A1
Method for controlling supply of current and / or fuel in motor vehicle, involves interconnecting elastically deformable cavity with pressure sensor, such that sensor detects impact signal and controls supply of current and / or fuel
DE102012110733A1
Method for operating a vehicle
DE102015011520A1