Method for evading locally impending dangers, vehicle for carrying out the method, and computer program
The method calculates avoidance routes based on vehicle-specific properties and real-time data to autonomously navigate vehicles away from imminent hazards, addressing the failure of existing systems to mitigate locally-induced risks and ensuring occupant safety.
Patent Information
- Application Number
- DE102018219809
- Authority / Receiving Office
- DE · DE
- Patent Type
- Patents
- Current Assignee / Owner
- Filing Date
- 2018-11-19
- Publication Date
- 2025-08-28
- Estimated Expiration
- 2038-11-19
AI Technical Summary
Existing vehicle navigation systems fail to adequately assess and mitigate locally-induced imminent hazards, such as weather phenomena or natural disasters, which can pose life-threatening risks to occupants, particularly when parked in critical locations.
A method for calculating an avoidance route to evade imminent dangers by integrating vehicle-specific properties, user-defined risk thresholds, and real-time environmental data, enabling autonomous navigation to a safe location.
Enhances safety by automatically avoiding potential threats, ensuring vehicle occupants' safety by dynamically adapting to changing conditions and user preferences, even when occupants are unaware of impending risks.
Smart Images

Figure 00000000_0000_ABST
Abstract
Description
[0001] The proposal concerns the technical field of driver information systems, also known as infotainment systems. Such systems are primarily used in vehicles. However, the invention can also be used for pedestrians, cyclists, etc., who wear data glasses. The proposal also concerns a correspondingly designed device for implementing the method, as well as a motor vehicle and a computer program.
[0002] Intensive work is currently being carried out on technologies that will later enable autonomous driving.
[0003] Many vehicles are equipped with a navigation system to provide destination and road guidance for the vehicle. Autonomous driving requires a highly reliable navigation system. To increase accuracy, autonomous vehicles also use environmental sensors that enable monitoring of the surroundings. This allows local road conditions, traffic conditions, and weather conditions to be taken into account during navigation. In addition, autonomous vehicles also employ communication modules that allow the vehicle to access external information sources. These can include external databases in traffic data centers or observation information from other vehicles also traveling in the area of interest.
[0004] DE 10 2014 013 672 A1 discloses a method and system for safeguarding autonomous or semi-autonomous driving of a vehicle on a road network. The method involves determining whether autonomous or semi-autonomous driving is possible for each upcoming road section. The vehicles are equipped with environmental sensors, a digital road map, and a communication module. The communication module enables communication with an external server. The results of the environmental detection are compared with the digital map and transmitted to the external server. The external server evaluates this information along with other information, such as traffic information, and sends permission information to the vehicle indicating whether autonomous driving is possible.
[0005] DE 10 2017 113 129 A1 discloses a system and method for suspending autonomous behavior when using an emergency lane. An emergency control center sends an emergency order from a corresponding server to infrastructure nodes, which instruct the autonomous vehicles traveling on the emergency route to form an emergency lane.
[0006] DE 10 2017 118 537 A1 discloses a method in which a computing unit in a vehicle receives a notification of a vehicle malfunction. A message containing the malfunction is transmitted wirelessly to a remote server. The server then calculates a revised route and sends it to the malfunctioning vehicle. The vehicle adopts the route and drives along the revised route to a destination (e.g., a repair shop).
[0007] DE 10 2017 121 622 A1 discloses a method in which, in response to relevant weather data, vehicle sensors detect ice and snow on the road. The vehicles report their findings to an external server containing a database for reports on ice and snow conditions. When a vehicle approaches the area with ice and snow, the autonomous vehicle's driving behavior is adjusted. It is also possible to avoid the affected road section.
[0008] US Pat. No. 8,024,111 B1 discloses a navigation system that calculates a route based on the entry of the starting and destination locations. This process takes into account information from databases containing traffic data, weather data, and event data. Event data includes events such as sporting events, concerts, political demonstrations, emergency events, and disasters such as building fires or floods. Furthermore, events such as street festivals or parades are also among the events that can be taken into account.
[0009] Similar systems are known from the documents US 8 332 242 B1, US 2009 / 0210142 A1 and WO 2016 / 090282 A1, which also determine a route that minimizes the risk of exposing the vehicle occupants to danger.
[0010] However, in the systems described, a hazard potential determination is only made when a route is planned and set.
[0011] Document D1 (US 2016 / 0 320 193 A1) describes a device, a method, and a computer program for controlling a vehicle. The vehicle is equipped with sensors that enable it to detect a hazardous event. The vehicle then calculates an evacuation route and is then controlled to follow this evacuation route. In one variant, the vehicle can be a
[0012] Document D2 (DE 10 2017 211 797 A1, earlier application) relates to a method for controlling at least one autonomous vehicle, in particular in the event of a public emergency, as well as an emergency management system for coordinating at least one autonomous vehicle in the event of an emergency.
[0013] Document D3 (DE 10 2017 219 301 A1, older application) concerns a method for increasing safety in hazardous traffic situations. This method comprises the following steps: Receiving, at a backend server, status data of a plurality of vehicles comprising an autonomous driving mode, wherein the status data comprises at least current position data of the vehicles; Recording, on the backend server, hazardous situation data comprising a position and a type of hazardous situation; Evaluating the status data and environmental data with reference to the hazardous situation; and Automatic initiation of at least one protective measure with reference to the evaluated status data and environmental data, wherein the protective measure comprises controlling at least one vehicle in an autonomous driving mode. The protective measure also relates to the navigation of the vehicle along a navigation route.
[0014] Document D4 (DE 10 2017 218 671 A1) concerns a method for controlling an automated mobile unit, a method for transmitting hazard information, and corresponding devices. This method offers the advantage of warning mobile units threatened by a hazard and, if necessary, transmitting evacuation suggestions. An automated evacuation of the mobile unit prevents damage to the mobile unit.
[0015] Document D5 (DE 10 2014 013 672 A1) concerns a method and a system for safeguarding autonomous or semi-autonomous operation of vehicles on a transport network.
[0016] To date, the driver of a vehicle and the other occupants are responsible for assessing the potential hazards. There is a greater need for hazard assessment in vehicles. An example should illustrate this. Some vehicles, especially camper vans, are frequently parked in critical / dangerous locations (e.g., overnight stays directly on the beach), where the vehicle occupants also spend the night. Potential hazards include weather phenomena such as storms and thunderstorms, and the resulting flooding, or flooding of other causes such as the occurrence of tsunamis following seaquakes. Since the associated danger is life-threatening for the occupants, who may also be asleep, the object of the invention is to develop a vehicle-based system for autonomously avoiding such hazards.
[0017] This object is achieved by a method for avoiding locally induced impending dangers according to claim 1, a vehicle for carrying out the method according to claim 12, and a computer program according to claim 15. The display serves the purpose of assisting the driver in longitudinal guidance of the vehicle.
[0018] The dependent claims contain advantageous developments and improvements of the invention according to the following description of these measures.
[0019] The proposed method for avoiding locally posed hazards involves calculating an alternative route for a vehicle to avoid the impending hazard. First, the vehicle receives a notification of the impending hazard. The vehicle then performs a hazard assessment with respect to the reported impending hazard. If the hazard assessment indicates a serious threat to the vehicle occupants and the vehicle, the vehicle automatically begins driving, following the alternative route to remove the occupants from the danger zone. Camping vehicles in particular, but also other vehicles such as cars and trucks, are often parked near beaches or in other danger zones.If vehicle occupants spend the night in such vehicles, they may notice the impending danger too late, making it impossible to escape. Today's vehicles can be equipped with autonomous driving functions. These vehicles could be equipped with the measures proposed in the proposed procedure to make staying in such places safer.
[0020] The procedure can be expanded by considering, at a minimum, the vehicle's equipment and / or the status of the operating resources available in the vehicle and / or the condition of the filter systems installed in the vehicle during the hazard potential assessment. This could indicate from the outset that certain alternative routes are not available because the vehicle is not equipped with all-wheel drive, does not offer the necessary ground clearance, does not have a sufficient battery charge or fuel level, etc. The status of the filter systems can be important if an alternative route would lead through an area with heavy smoke development due to fire or other types of air pollution.
[0021] In another enhanced version, the hazard potential assessment takes into account at least one risk aversion configured by the vehicle user, and a check is made to determine whether the hazard potential assessment is still acceptable within the context of the configured risk aversion or whether it has already become unacceptable to the vehicle user. In this respect, the hazard prevention system can be configured according to the vehicle user's personal preferences.
[0022] It is also advantageous to consider traffic information for individual route segments when calculating the alternative route, especially traffic information regarding potential traffic jams or traffic holdups. Such information is already utilized in popular navigation systems such as Google Maps. This makes it possible to choose an alternative route that is further away but leads to a safe location more quickly.
[0023] The process can be further enhanced by determining the positions and / or routes of other vehicles in the vehicle's vicinity and taking them into account when calculating the alternative route. The more vehicles traveling in the affected area, the more difficult it becomes to find a suitable alternative route. Therefore, to enable the most reliable route calculation possible, it is advantageous to also consider this information.
[0024] It is also advantageous for the procedure to compile a list of potentially accessible locations and traversable route segments, with a hazard potential assessment being conducted for these accessible locations and traversable route segments and recorded in the list. This has the advantage that a suitable escape location can be found more quickly, and a suitable alternative route to this escape location can be compiled more quickly.
[0025] In order to efficiently determine the alternative route, it is advantageous to filter the accessible locations and / or traversable route segments noted in the list, in which those locations and / or traversable route segments with a hazard potential assessment whose value at least exceeds an acceptable risk value are filtered out.
[0026] In an advantageous variant, the list of accessible locations is sorted according to the lowest risk potential assessment and the shortest distance.
[0027] In an advantageous variant, the route is calculated in such a way that a navigation route is calculated for an accessible destination in the list with the noted accessible locations and a hazard potential assessment is calculated for the calculated navigation route and it is checked whether the hazard potential assessment for the calculated navigation route lies in the risk aversion range acceptable to the vehicle user, wherein, if the calculated navigation route does not meet this condition, the calculation is carried out for another accessible destination in the list and the navigation route calculated for it, and then, if no navigation route calculated for the possible accessible destinations in the list meets a safety criterion, a request to manually control the vehicle is issued to the vehicle user.
[0028] In order to avert danger to the vehicle occupants, it is important that, once a navigation route has been found that meets the safety criteria, a check is carried out to ensure that the number of vehicle occupants specified during configuration is present in the vehicle before the vehicle begins its journey along the found navigation route. This prevents the vehicle from removing itself from the danger zone but not the vehicle occupants. Conversely, however, it can be quite sensible for the vehicle to remove itself from the danger zone if the configuration has been set so that no occupants remain in the vehicle or near the vehicle. This can, for example, prevent an insurance claim in the event of rising flood waters.
[0029] The procedure can be further improved by continuously checking, while driving along the identified alternative route, whether the safety conditions along the alternative route have deteriorated. If so, adjusting the hazard potential assessment for the alternative route. Checking whether a better hazard potential assessment is available for an alternative navigation route that offers better safety conditions is also possible. If so, switching to the navigation route with the better hazard potential assessment is possible. This allows a response to a changed safety situation while escaping the danger.
[0030] For a vehicle configured to implement the method, it is advantageous if it has an autonomous driving system and a navigation system designed to guide the vehicle along a pre-calculated navigation route. Furthermore, the vehicle should have a computing device and a communications module. The communications module should be configured to receive a hazard warning, and the computing device should be configured to calculate and assess the hazard potential of various possible alternative routes.
[0031] It is also advantageous if the vehicle is equipped with environmental monitoring sensors and the computing device is designed to evaluate the data from the environmental monitoring sensors and, based on this, calculate an amended hazard potential assessment for a section of the alternative route. For this purpose, one or more cameras can be mounted on the vehicle. A LIDAR or RADAR sensor can also be used for this purpose. Image recognition methods are used to evaluate the images provided by the camera. There are well-known algorithms that can be used to perform image analysis for object recognition.
[0032] The computing device in the vehicle can further be designed to compare the possible alternative routes and select another alternative route and transmit it to the navigation system if an alternative route with a better hazard potential assessment than the current alternative route is found.
[0033] Furthermore, the same advantages apply to the vehicle with the appropriately programmed computing device as for the measures mentioned in the corresponding procedural steps.
[0034] For a computer program that is executed in the vehicle's computing system to implement the method according to the invention, the corresponding advantages described for the method according to the invention apply. The program can be designed as an app that is downloaded from a provider onto the device.
[0035] Embodiments of the invention are illustrated in the drawings and are explained in more detail below with reference to the figures.
[0036] They show: Fig. 1 the basic network architecture for V2V and V2X communication; Fig. 2 a block diagram of the on-board electronics of a modern autonomous vehicle; Fig. 3 a representation of a parked vehicle in a situation that illustrates the problematic nature of the proposal; Fig. 4 an overview flow chart for a program for calculating escape routes in the event of acute danger caused by a hazardous event; Fig. 5 a detailed flowchart for the first process step of the escape route calculation program; Fig. 6 a detailed flowchart for the second process step of the escape route calculation program; Fig. 7 a detailed flowchart for the third process step of the escape route calculation program; Fig. 8 a detailed flowchart for the fourth process step of the escape route calculation program; Fig. 9 a detailed flowchart for the fifth process step of the escape route calculation program; and Fig. 10 a detailed flowchart for the sixth process step of the escape route calculation program.
[0037] The present description illustrates the principles of the inventive disclosure. It is thus understood that those skilled in the art will be able to devise various arrangements that, while not explicitly described herein, embody principles of the inventive disclosure and are also intended to be protected within their scope.
[0038] Fig. shows the system architecture for the proposal. Reference numeral 10 denotes a vehicle, in particular a car. A passenger car is shown. It can be any type of vehicle. Examples of other vehicle types are: camper vans, buses, motorcycles, bicycles, commercial vehicles, in particular trucks, agricultural machinery, construction machinery, etc. The invention could generally be used in land vehicles, watercraft, and aircraft, in particular helicopters and air taxis. The vehicle 10 is equipped with a communications module 160 comprising one or more corresponding antennas, so that the vehicle 10 can participate in any form of radio communications service. In particular, a mobile radio communications service is envisaged. Fig. 1 shows that the vehicle 10 can send and receive signals to and from a base station 210 of a mobile communications provider.
[0039] Such a base station 210 can be an eNodeB base station of an LTE (Long Term Evolution) mobile operator or a 5G mobile operator. The base station 210 and the corresponding equipment are part of a mobile communications network with a plurality of network cells, each cell served by a base station 210. When the vehicle 10 passes through a cell and approaches the end of the cell's coverage area, a "handover" process takes place.
[0040] This corresponds to a handover process in which control is transferred from the base station 210 whose cell the vehicle 10 is leaving to the base station 210 into whose cell the vehicle is entering. As the vehicle 10 approaches the base station 210 into whose cell it is entering, it receives its signals and also begins to communicate with this base station 210. If the received signal is strong enough and, at the same time, the received signal from the base station 210 to which it is still registered falls below a threshold, the vehicle 10 is handed over to the base station 210 of the radio cell it is entering.
[0041] The network architecture is explained using the example of the LTE network architecture (Long Term Evolution) and includes the three subsystems: User Equipment (UE), Access Network (AN) and Core Network (CN).
[0042] In LTE networks, the E-UTRAN is the access network for LTE; it uses OFDMA modulation technology in the radio interface to communicate with the user equipment (UE). An Evolved Packet Core (EPC) 200 is used in the core network to provide an all-IP architecture to grant access to various services, such as the Internet. The UE can be a personal device, such as a smartphone, smartwatch, tablet computer, notebook or laptop computer, or the like.
[0043] The connection between the physical devices in both the EPC 200 and the E-UTRAN is established via IP network-based technologies, so the transport network is a typical IP network. Thus, every LTE network infrastructure contains IP elements such as routers, DHCP servers, and DNS servers. This allows the data packets of the messages to be routed in the usual way.
[0044] The base station 210 in Fig. 1 is positioned near a main road on which the vehicles 10 travel. In LTE terminology, a mobile terminal corresponds to a user equipment (UE) that enables a user to access network services by connecting to the UTRAN or the Evolved UTRAN via the radio interface. Typically, such a user equipment corresponds to a smartphone. Such a mobile terminal is also used in the vehicles 10. For this purpose, the vehicles 10 are equipped with an on-board connectivity module (OCU) 160. This OCU module corresponds to an LTE communication module with which the vehicle 10 can receive and transmit mobile data.
[0045] In LTE, the eNodeBs are connected to each other via the so-called X2 interface. The eNodeBs are also connected to the EPC (Evolved Packet Core) 200 via the so-called S1 interface.
[0046] The various interfaces of the 5G network architecture are standardized. Particular reference is made to the various publicly available specifications to adequately disclose further implementation details. As a modern example of a mobile communications standard, reference is made to the 3GPP initiative and the LTE (Long Term Evolution) standard. Many of the associated ETSI specifications are available. Examples include: ETSI TS 136 213 V13.0.0 (2016-05); Evolved Universal Terrestrial Radio Access (E-UTRA); Physical layer procedures (3GPP TS 36.213 Version 13.0.0 Release 13).
[0047] Fig. Figure 1 shows this general architecture. The base station 210 is connected to the EPC 200 via the S1 interface, and the EPC 200 is connected to the Internet 300. The backend server 320 is also connected to the Internet 300. In the field of cooperative and autonomous driving, the backend server 320 is typically located in a traffic control center. Reference number 330 denotes a data center of a tsunami early warning system. Finally, an infrastructure network component is also shown. This is exemplified by a roadside unit (RSU), corresponding to Roadside Unit 310. To simplify implementation, it is assumed that all components have been assigned an Internet address, typically in the form of an IPv6 address, so that the packets transporting messages between the components can be routed accordingly.
[0048] The Fig. Figure 2 shows a typical block diagram of the on-board electronics of the vehicle 10. The on-board electronics consist, on the one hand, of components of an infotainment system, and, on the other hand, of components of the powertrain and other control units. Reference number 30 denotes a touch-sensitive screen. The touch-sensitive screen 30 serves in particular to operate functions of the vehicle 10. For example, it can be used to control a radio, a navigation system, playback of stored music tracks and / or an air conditioning system, other electronic devices, or other comfort functions or applications of the vehicle 10. Collectively, this is often referred to as an "infotainment system." In motor vehicles, especially cars, an infotainment system refers to the combination of a car radio, navigation system, hands-free system, driver assistance systems, and other functions in a central control unit.The term infotainment is a portmanteau of the words information and entertainment. The touch-sensitive screen 30 ("touchscreen") can be easily viewed and operated, in particular, by a driver of the vehicle 10, but also by a passenger of the vehicle 10. Mechanical control elements, such as buttons, rotary controls, or combinations thereof, such as push-button dials, can also be arranged below the screen 30 in an input unit 50. Steering wheel operation of parts of the infotainment system is typically also possible. This unit is not shown separately, but is considered part of the input unit 50.
[0049] The display unit 30 is connected to the computing device 40 via a data line 70. The data line can be designed according to the LVDS standard, corresponding to Low Voltage Differential Signaling. The display unit 30 receives control data for controlling the display surface of the touchscreen 30 from the computing device 40 via the data line 70. Control data for the entered commands are also transmitted from the touchscreen 30 to the computing device 40 via the data line 70. Reference number 50 designates the input unit. Associated with this unit are the aforementioned control elements, such as buttons, rotary controls, slide controls, or rotary push buttons, with which the operator can make inputs via the menu navigation. Input is generally understood to mean selecting a selected menu option, changing a parameter, switching a function on or off, etc.
[0050] The memory device 60 is connected to the computing device 40 via a data line 80. A pictogram and / or symbol directory is stored in the memory 60, containing the pictograms and / or symbols for possible display of additional information, in particular the display of a navigation route and corresponding turn-off instructions, traffic signs, etc.
[0051] The other parts of the infotainment system, camera 150, interior camera 151, radio 140, navigation device 130, telephone 120, and instrument cluster 110, are connected to the device for operating the infotainment system via data bus 100. The high-speed variant of the CAN bus according to ISO Standard 11898-2 can be used as data bus 100. Alternatively, a bus system based on Ethernet technology, such as BroadR-Reach, could also be used. Bus systems in which data is transmitted via fiber optic cables can also be used. Examples include the MOST bus (Media Oriented System Transport) or the D2B bus (Domestic Digital Bus). It should also be mentioned here that camera 150 can be designed as a conventional video camera. In this case, it records 25 full frames / s, which corresponds to 50 fields / s in interlace recording mode.Alternatively, a special camera can be used that captures more images per second to increase the accuracy of object detection for faster-moving objects. Multiple cameras can be used to monitor the surroundings. In addition, the aforementioned RADAR or LIDAR systems could also be used in addition or alternatively to carry out or expand the monitoring of the surroundings. For wireless communication inside and out, the vehicle 10 is equipped with a communication module 160. This module is often also referred to as an on-board connectivity unit (OCU). It can be designed for mobile radio communication, e.g., according to the LTE standard, corresponding to Long Term Evolution. It can also be designed for WLAN communication, corresponding to Wireless LAN, whether for communication with devices of the occupants in the vehicle, for vehicle-to-vehicle communication, or for vehicle-to-infrastructure communication, etc.
[0052] The infotainment system's data bus 100 is connected to a gateway 30. The other components of the on-board electronics are also connected to it. First, there is the drivetrain's communication bus 104, which is typically implemented in the form of a CAN bus. Examples of drivetrain control units include engine control unit 172, ESP control unit 174, and transmission control unit 176. Also shown is the communication bus 102 for driver assistance systems, which can be implemented in the form of a FlexRay bus. Three driver assistance systems are shown: a driver assistance system 182 for automatic distance control (ACC) corresponding to Adaptive Cruise Control, an automatic driving system (ADC) 184 for the autonomous driving function, and a LIDAR system 186, corresponding to a Light Detection and Ranging System, which serves as a laser measurement system for measuring the surroundings. A communication bus 106 is also connected to the gateway 30.This connects the gateway 30 to an on-board diagnostic interface 190. The task of the gateway 30 is to perform the format conversions for the various communication systems 100, 102, 104, 106 so that data can be exchanged between them.
[0053] The inventive method for monitoring the hazard potential with the calculation of an escape route is explained in detail below using an exemplary embodiment. Alternative embodiments are also discussed. The calculations regarding the hazard potential assessment are performed in the computing device 40.
[0054] Fig. Figure 3 shows an example of a scenario in which the proposal can be applied. Three cell towers C1 to C3 of an LTE mobile network are shown. The corresponding base stations are designated by reference numerals 210a to 210c. A coastal road runs through cell towers C1 and C3, with a branch to a country road leading inland through cell C2. Vehicle 10 is parked in a parking lot on the beach. There is a potential risk of flooding of the parking lot if a tsunami occurs.
[0055] To avoid danger, vehicle 10 is equipped with a tsunami warning system. Furthermore, vehicle 10 is equipped to calculate an escape route when a tsunami warning is received and to automatically follow this route to evacuate the occupants from the danger zone as quickly as possible.
[0056] The sequence of the various process steps for threat prevention in Fig. 4. This is the rough flow chart for a computer program that is processed by the computing device 40.
[0057] The program start is designated by reference number 402. In process step 404, the autonomous and coordinated driving of a vehicle is activated to avoid and reduce hazards. This is done by the driver or another vehicle occupant through manual menu input in a corresponding operating menu after program start. The person activates the function for autonomous evacuation via the infotainment system when a hazard arises. The operating menu can be designed so that the operator can select a specific risk profile. For example, different levels of risk aversion could be offered. As an example, three levels are given: low, medium, and high risk aversion. In addition, the number of occupants in the vehicle who are to be rescued is entered in this step. The hazard prevention system is "armed" with additional menu input.
[0058] The program continues with program step 406. This step determines whether vehicle-specific characteristics that influence risks. This means that it is determined whether an evacuation is even necessary given the vehicle-specific characteristics. Example: In the event of an impending hailstorm, occupant protection will be sufficient and escape from this event is not absolutely necessary. The assessment can depend on the risk aversion setting. Another example concerns the question of which routes would even be passable. This depends on the vehicle characteristics and condition. Therefore, vehicle master data such as tires, drive technology and weight as well as vehicle condition data such as the remaining capacity of the vehicle battery in an electric vehicle or the fuel level in a vehicle with an internal combustion engine, the condition of the interior air filter, etc. are evaluated in this step.Certain escape routes may require all-wheel drive and increased ground clearance. These or other routes may be impossible if the battery charge is low.
[0059] In program step 408, the need to initiate an escape sequence is checked in response to an identified local risk. A local hazard such as a tsunami wave is registered by a seismograph. Based on the strength of the earthquake, the location of the earthquake, and the mapped information about the surrounding area, a tsunami early warning data center 330 calculates which areas (streets / parking lots) will be flooded and at what time. This occurs within the framework of the tsunami early warning system. Part of the well-known tsunami early warning systems is a software app that anyone can download to their smartphone. However, this only issues the tsunami warning. Such a software app can also be installed in the vehicle. The vehicle is thus informed of the tsunami warning as part of the tsunami early warning system.
[0060] If the vehicle detects that the vehicle occupant(s) is / are not in the vehicle upon receipt of the warning, the vehicle can draw attention to the warning by honking / flashing, or using another form of signaling. Determining whether all vehicle occupants registered in step 404 are present in the vehicle can be done by analyzing the image from the interior camera 151 or by analyzing the seat occupancy sensors of the seats in the vehicle. Another option is to query the number of vehicle occupants in the vehicle by displaying a message on the display unit 20.
[0061] Another possible implementation is for a backend server 320 of the traffic control center for the corresponding area to receive the tsunami warning from the tsunami early warning data center 330, possibly together with the type and degree of risk of flooding for individual locations. This backend server 320 compares the data with the vehicle position data (e.g., GPS data) of the vehicles in the corresponding area. For vehicle 10, which is parked near the beach, there is an imminent flood in 400 seconds upon receipt of the tsunami warning. This information is transmitted to vehicle 10. Now, in step 406, the risk posed by the tsunami wave is compared with the vehicle characteristics to determine the extent to which the vehicle characteristics mitigate the risk. The calculation shows that the vehicle characteristics do not reduce the risk.In the next step, the degree of risk and its probability of occurrence are compared with the occupant's defined risk profile. Since a risk-averse profile was selected, combined with the reported event of impending flooding, the risk assessment indicates a high need for escape.
[0062] In the subsequent process step 410, in response to a necessary escape sequence, the risk of individual route sections to be traveled is determined. Traffic flows derived from fleet data are taken into account for route calculation. This prevents vehicle 10 from driving into a traffic jam on the way to a safe location and then being caught by the tsunami. Additionally, risk information for individual route segments is collected based on environmental observations using the environmental sensors of other vehicles. This includes, for example, the current water level around the vehicle. By combining the risk information from the other vehicles and the location-specific warnings, a specific risk value for individual accessible locations / route segments can be calculated and predicted. This filters out further route segments. The result is a list of navigable route segments with an acceptable risk value.
[0063] Subsequently, in response to a necessary escape sequence and the calculated risks of the individual route segments to be traveled, a risk-averse route calculation takes place in step 412. The safe destinations can be sorted according to their risk. One strategy involves selecting the destination with the highest value and calculating a risk-averse route for it. The resulting risk is compared with the risk profile previously defined by the occupant. If the destination-route combination does not meet the user-specific risk profile, in one embodiment, the occupant is requested to perform a manually controlled evacuation. In another embodiment, the vehicle will select a route that most closely matches the set risk profile.
[0064] In the subsequent process step 414, navigation to the selected destination takes place along the selected route, with a continuous review of alternative routes and destinations. For this purpose, the selected route is imported into the navigation system 130 of the vehicle 10, and the vehicle 10 drives autonomously along the corresponding route to the destination. The route segment is continuously checked using the vehicle sensors and evaluated to determine whether this information indicates an increased risk for the route section.
[0065] In query 416, a check is made to determine whether the set destination has been reached. If not, the previously mentioned steps 406-414 are repeated, and a check is made to determine whether a change to a better route / destination is possible compared to the current route / destination. It is also possible that the current route deteriorates, necessitating a change to another route. This allows vehicle 10 to avoid emerging risks and dynamically adjust the route or destination. The vehicles are coordinated to minimize mutual interference (due to traffic jams and overloading of shelters).
[0066] If it is finally determined in query 416 that the destination has been reached, the program ends in program step 418.
[0067] Fig. Figure 5 shows the detailed sequence of program step 404. In step 420, the settings for the vehicle's hazard avoidance system are selected. A corresponding operating menu is called up on the display unit 20. The occupant can select the desired risk aversion profile and enter the number of vehicle occupants.
[0068] He can then "arm" the system. In program step 422, a query is made as to whether the system has been activated. If so, a corresponding entry is made in a register of the computing device 40 in program step 424. The program then continues with process step 406. If query 422 determines that the system has not been activated, the corresponding entry is made in the register of the computing device 40 in program step 426. In this case, the program would then terminate.
[0069] Fig. 6 shows the detailed sequence of process step 406. In program step 430, the vehicle equipment is determined. Here, it is recorded whether the vehicle 10 is equipped with front-wheel drive, rear-wheel drive, or all-wheel drive. It is also recorded whether the vehicle is equipped with an internal combustion engine or an electric motor. Other interesting equipment features are the recording of the vehicle dimensions and weight. For example, it is also interesting to know how much ground clearance the vehicle has and what tires it is equipped with. Such information can be stored in the memory 60 of the computing device in advance when the system is installed. In step 432, the operating resources in the vehicle 10 are recorded. This includes the fill levels of the tank and the charge capacity of the batteries. In program step 434, the condition of the filter systems, in particular the interior air filter, is checked.This is of interest, for example, if an area with severe air pollution, such as a forest fire or other fire, must be driven through. In program step 436, the vehicle-specific characteristics that influence risks are determined. Such characteristics can include the vehicle type, such as a convertible, SUV, or sedan. After this determination, the process continues with step 408.
[0070] The exact sequence of process step 408 is described in Fig. 7. In this step, the vehicle 10 determines in the background whether it is necessary to start an escape sequence. In step 440, weather information, traffic information, and hazardous event information are collected. In program step 441, environmental data for the location of vehicle 10 is recorded. This can be done using the environmental monitoring sensors in vehicle 10. A distinction is then made as to whether a hazard warning has been detected for the location of vehicle 10. This is checked in query 442. If not, the program branches back to step 441. In parallel, query 444 queries whether a change in the recorded environmental data has been detected and whether this represents a risk. Possible environmental data that may be recorded include, for example, the water level or the detection of a forest fire. Both can be done using camera analysis. If not, the program returns to step 441.In this way, vehicle 10 checks in the background whether the security situation has changed, even while the vehicle occupants are asleep. If a hazard was detected in one of queries 442 or 444, the location-specific risk is calculated in program step 446. The location-specific hazard warnings communicated in step 445 are also evaluated. In program step 448, the vehicle-specific risk is calculated based on the communicated location-specific risk. Here, the corresponding registered vehicle characteristics are taken into account in step 447. In the subsequent query 450, it is checked whether the calculated risk exceeds the set user-specific risk aversion. Acceptance of the set user-specific risk aversion is indicated by program step 451, where the set parameter is read out.If the calculated risk is assessed as relatively low and does not exceed the corresponding parameter for the set user-specific risk aversion, the program branches back to the beginning of this process step. If the calculated risk exceeds the set value, the initiation of an escape sequence is started in program step 452. The escape sequence is processed in process step 410.
[0071] The program with which the escape sequence is processed is in Fig. 8. In program step 460, the routes and positions of other vehicles traveling in the escape zone are determined. Here, the data provided by the traffic control center is used. Such data is typically also provided today by navigation systems such as Google Maps. In addition, the data provided by the environmental detection sensors can also be evaluated. The messages transmitted via V2X or V2V communication can also be evaluated. However, this only allows statements to be made about the traffic conditions in the immediate vicinity. In program step 461, traffic flows for individual route segments in the escape zone are calculated. In another embodiment, the traffic control center provides this data via radio communication. In the next step 462, a list of potentially accessible locations and route segments is created.This is done taking into account that only 400 seconds are available to leave the danger zone. In step 465, a risk assessment is performed regarding the individual route segments to be traversed and the locations to be reached. This takes into account the location-specific risk information from other vehicles (see step 463) and the existing location-specific risk warnings (see step 464). In program step 466, the route sections for which the risk assessment resulted in an excessively high value are filtered out. The other route sections are shortlisted from which the escape route is compiled. In step 467, a list is created with the navigable route segments and the associated risk assessments. This process step then ends.
[0072] In Fig. Figure 9 shows the program flow for process step 412. First, in program step 470, the accessible destinations are sorted according to safety and distance. Thus, those destinations with a low risk assessment are at the top of this list. The list of potentially accessible refuges originates from program step 462 and is transferred to program step 471. After sorting, the list is saved again in program step 472. In query 473, a check is made to determine how many destinations remain in the sorted list that have not yet been checked. If no remaining destinations are found, the program branches to step 474, where it prompts the occupants to attempt a manually controlled escape. The program then branches back to process step 408. If query 473 is not completed, the program branches to step 475.The next destination with the lowest risk assessment, which has not yet been checked, is selected. In program step 476, a risk-minimized route to the selected destination is calculated for this destination. To do this, query 477 checks whether the combination of destination and selected route segments results in a route within the permitted risk range. For this purpose, program step 479 accesses the corresponding register entries with the set user-specific risk parameters from program step 451, and program step 478 accesses the determined drivable route segments with the determined risk value from program step 467. If the determined combination lies within the permitted risk range, the determined route is saved as a navigation route. This occurs in program step 480. In this step, the navigation route can also be transferred to the navigation system 130. Process step 414 would then be initiated.If the selected route does not meet the risk criteria in query 477, the program returns to query 473. The next destination in the list is then checked accordingly.
[0073] The sequence of process step 414 is explained below. Fig.Figure 10 shows the flowchart for this process step. In program step 490, autonomous navigation is performed along the selected route to the associated destination. This step is performed by the navigation system 130. Before the vehicle autonomously begins the route, however, query 491 checks whether the occupant(s) are present in the vehicle. This occurs as explained in process step 404. If the vehicle occupant(s) are missing, the program waits. The program branches back to process step 406. Otherwise, the vehicle 10 sets off autonomously and begins the escape route. The route section ahead is continuously measured using the vehicle 10's environmental detection sensors 150, 186. This measure is shown in program step 492.In query 493, a check is then made to determine whether the upcoming section of the route is blocked by an obstacle or traffic jam, thus indicating an increased danger for this section. If not, the program returns directly to process step 406. Process steps 406 to 414 are then repeated. In this way, an updated route is continuously calculated to take into account any potentially changed environmental conditions. If an impairment on the selected route was identified in query 493, the corresponding route segment properties are adjusted in program step 494 before the program also returns to process step 406. After processing process steps 406 to 414, query 496 asks whether the newly determined route / destination was estimated to be better than the currently selected route. If this is the case, the program switches to the newly determined route in step 497.The new route is transmitted to the navigation system 130 and started. If not, the old route remains and continues to be followed.
[0074] Other examples where continuous monitoring of the route ahead is important concern particularly hazardous situations. These can be hazardous situations caused by multiple hazards. One example would be a particularly severe hazardous situation, such as several tornadoes moving across the country. This would require repeated avoidance of each individual hazard while following the alternate route before the first and subsequent tornadoes.
[0075] Another example would be a superposition / intensification of the individual hazards. At a first time t0, an earthquake occurs, damaging a bridge structure. At a second time t1, the earthquake could trigger a tsunami, causing the bridge to collapse. This chain of circumstances can also be taken into account when calculating the alternative route.
[0076] The same applies to the vehicle's characteristics: For example, if the air filter system is changed at a time t0, the properties of the air filter system will change at a subsequent time t1. Accordingly, a combined analysis of the "aggregated conditional hazard reduction over time" type would be necessary.
[0077] All examples and conditional language mentioned herein are to be understood without limitation to such specifically cited examples. For example, it will be appreciated by those skilled in the art that the block diagram presented herein represents a conceptual view of an exemplary circuit arrangement. Similarly, it will be appreciated that a depicted flowchart, state transition diagram, pseudocode, and the like represent various variations for representing processes that can be substantially stored in computer-readable media and thus executed by a computer or processor. The object recited in the claims may also expressly be a person.
[0078] It should be understood that the proposed method and associated devices can be implemented in various forms of hardware, software, firmware, special-purpose processors, or a combination thereof. Special-purpose processors may include application-specific integrated circuits (ASICs), reduced instruction set computers (RISCs), and / or field-programmable gate arrays (FPGAs). Preferably, the proposed method and device are implemented as a combination of hardware and software. The software is preferably installed as an application program on a program storage device. Typically, this is a machine based on a computer platform that includes hardware such as one or more central processing units (CPUs), random access memory (RAM), and one or more input / output (I / O) interfaces.An operating system is typically also installed on the computer platform. The various processes and functions described here may be part of the application program or a part executed by the operating system.
[0079] The disclosure is not limited to the embodiments described herein. There is room for various adaptations and modifications that a person skilled in the art would consider based on their technical knowledge and the disclosure.
[0080] The method can be modified in many ways. In another variant, the vehicle 10 can be configured in process step 404 so that it should automatically begin its escape from danger even if no vehicle occupant is registered. This can be useful in a situation where the vehicle 10 has been parked in a hazardous area. For example, it could be parked in an area prone to flooding. When calculating the escape route, however, it should be taken into account that a route is selected that does not contribute to congestion on important arterial roads where many vehicles with occupants may be traveling, in order not to endanger these occupants. It is therefore not necessary to select the fastest route in order to avoid a traffic jam. List of reference symbols 10 parked vehicle 12 oncoming vehicle 14 Alternative route 20 touch-sensitive display unit 40 computing device 50 control unit 60 storage units 70 Data line to the display unit 80 Data line to the storage unit 90 Data cable to the control unit 100 1. Data bus 102 2. Data bus 104 3. Data bus 110 instrument cluster 120 Telephone 130 navigation device 140 Radio 150 Camera 151 Interior camera 160 communication module 172 Engine control unit 174 ESC control unit 176 Transmission control unit 182 adaptive cruise control 184 Control unit for automatic driving function 186 LIDAR sensor 200 Core Network EPC 210 mobile phone base station 210a Base station for mobile radio cell C1 210b Base station for mobile radio cell C2 210c Base station for mobile radio cell C3 300 Internet 310 Infrastructure network component 320 backend servers 330 Tsunami Early Warning Data Center 400 - 418 different process steps 420 - 496 different program steps of various computer programs C1 -C3 mobile radio cells
Claims
[1] Method for avoiding locally caused imminent dangers, wherein an alternative route (14) is calculated for a vehicle (10) in order to avoid the imminent danger, wherein a message about the imminent danger is received from the vehicle (10), wherein the vehicle (10) then carries out a hazard potential assessment with regard to the reported imminent danger and the vehicle (10) automatically starts driving, following the alternative route (14) in order to avoid the imminent danger, characterized by that a list of potentially accessible locations and traversable route segments is drawn up and a hazard potential assessment is carried out for the accessible locations and traversable route segments and recorded in the list, with the recorded accessible locations being sorted according to the lowest hazard potential assessment and the shortest distance. [2] Method according to claim 1, wherein the hazard potential assessment takes into account at least the vehicle equipment and / or the status of the operating resources available in the vehicle (10) and / or the condition of the filter systems present in the vehicle (10). [3] Method according to claim 1 or 2, wherein in the hazard potential assessment at least one risk aversion set by the vehicle user for configuration is taken into account and it is checked whether the hazard potential assessment results in an exceedance of the set risk aversion. [4] Method according to one of the preceding claims, wherein traffic information for individual route segments is taken into account when calculating the alternative route (14), in particular traffic information regarding possible traffic jams or traffic holdups. [5] Method according to one of the preceding claims, wherein the positions and / or routes of other vehicles (12) in the vicinity of the vehicle (10) are determined and taken into account for the calculation of the alternative route (14). [6] Method according to one of the preceding claims, wherein a filtering of the accessible locations and / or traversable route segments noted in the list is carried out, in which such locations and / or traversable route segments with a hazard potential assessment whose value exceeds at least one still acceptable risk value are filtered out. [7] Method according to claim 3, wherein a navigation route is calculated for an accessible destination in the list with the noted accessible locations and a hazard potential assessment is calculated for the calculated navigation route and wherein it is checked whether the hazard potential assessment for the calculated navigation route lies in the risk aversion range acceptable to the vehicle user, wherein if the calculated navigation route does not meet this condition, the calculation is carried out for another accessible destination in the list and the navigation route calculated for it, and then, if no navigation route calculated for the possible accessible destinations in the list meets a safety criterion, a request to manually control the vehicle (10) is issued to the vehicle user. [8] Method according to claim 7, wherein, in the event that a navigation route satisfying the safety criterion has been found, it is checked whether the number of vehicle occupants specified in the configuration are in the vehicle (10) before the vehicle (10) starts the journey along the found navigation route. [9] Method according to claim 8, wherein during the journey along the found navigation route it is continuously checked whether the safety conditions along the navigation route have deteriorated and if so, that an adjustment of the hazard potential assessment for the navigation route takes place and that it is checked whether a better hazard potential assessment results for another navigation route which offers better safety conditions and if so, that a change is made to the navigation route with the better hazard potential assessment. [10] Vehicle (10) configured to carry out the method according to one of the preceding claims, comprising an automatic driving system ADC (184) and a navigation system (130) designed to guide the vehicle (10) along a pre-calculated navigation route, further comprising a computing device (40) and a communication module (160), wherein the communication module (160) is designed to receive a hazard message and the computing device (40) is designed to calculate and estimate the hazard potential of various possible alternative routes (14), characterized bythat the computing device (40) is designed to compile a list of potentially accessible locations and traversable route segments and to carry out a hazard potential assessment for the accessible locations and traversable route segments and to note this in the list, and to sort the list with the noted accessible locations according to the lowest hazard potential assessment and the shortest distance. [11] Vehicle (10) according to claim 10, wherein the vehicle (10) is equipped with environmental observation sensors (150, 186) and the computing device (40) is designed to evaluate the data of the environmental observation sensors (150, 186) and, depending thereon, to calculate a modified hazard potential assessment for a section of the alternative route (14). [12] Vehicle (10) according to claim 11, wherein the computing device (40) is further designed to compare the possible alternative routes (14) and to select another alternative route (14) and to transmit it to the navigation system (130) if an alternative route (14) with a better hazard potential assessment than the current alternative route (14) is found. [13] Computer program, characterized by that the computer program is designed, when processed in a computing device (40), to carry out the steps of the method for avoiding locally caused imminent dangers according to one of claims 1 to 9.
Citation Information
Patent Citations
Method and system for ensuring autonomous or semi-autonomous operation of vehicles on a road network
DE102014013672A1
Emergency management system and procedure for controlling at least one autonomous vehicle in an emergency
DE102017211797A1
Method for controlling an automatically operated mobile unit and method for sending out hazard information
DE102017218671A1
Procedures for increasing safety in hazardous situations concerning road traffic
DE102017219301A1
Safe route configuration
US20090210142A1