Method for operating a motor vehicle capable of autonomous driving in an operating state

The method optimizes the selection of a stopping position for autonomous vehicles by considering safety and time constraints, ensuring safe and comfortable termination of autonomous driving.

DE102024001530B4Active Publication Date: 2026-04-09MERCEDES BENZ GROUP AG
View PDF 4 Cites 0 Cited by

Patent Information

Authority / Receiving Office
DE · DE
Patent Type
Patents
Current Assignee / Owner
Filing Date
2024-05-10
Publication Date
2026-04-09

AI Technical Summary

Technical Problem

Existing methods for autonomous vehicles do not adequately consider safety in selecting a stopping position at the end of an operational design domain (ODD), leading to potential risks and reduced driver comfort.

Method used

A method that determines a maximum usage duration and safety level for the end-of-scope stop, identifies alternative stopping points with higher safety levels, and optimizes the selection based on a relative safety gain and time loss to ensure a safe and advantageous termination of autonomous driving.

Benefits of technology

Ensures the vehicle stops at a position that maximizes operating time while minimizing risk, providing enhanced safety and comfort by selecting a safe stopping point before the end of the ODD.

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure 00000000_0000_ABST
    Figure 00000000_0000_ABST
Patent Text Reader

Abstract

Method for operating a motor vehicle (MV) capable of autonomous driving in an operating state, wherein the autonomous driving takes place within an operational application area (ODD), comprising the steps: - Determining a maximum service life (ET max ) until reaching a planned end of scope (ODD) and a scope end stop (SSP) ODD_Ende ) for an end to the autonomous operating state; - Specifying a security level (S ODD_Ende ) for the application range endpoint (SSP) ODD_Ende ) and if this is below a predetermined level: • Determine at least one additional stopping point (SSP) i ), which lies before the end of the scope (ODD) and whose further security level (S i ) greater than the first security level (S ODD_Ende ) is; • Determining a further useful life (ET i) for at least one further stopping point (SSP) i ); • Determining a difference value (AS) i ) of the further security level (S i ) with the first security level (S ODD_Ende ) and a time difference (ΔET i ) between the maximum service life (ET max ) and the further useful life (ET i ); and • Ending the autonomous operating state at the application domain endpoint (SSP) ODD_Ende ) or at the next stopping point (SSP) i ) depending on the time difference (ΔET i ) and the difference value (ΔS i ), whereby the following additional steps are performed to end the autonomous operating state: - Determining the percentage loss of useful life (PV) ETI ) by the ratio of the time difference (ΔET i ) to the maximum service life (ET max ); - Defining safety limit curves (SLCs) that determine the percentage loss of service life (PV) ETI ) over the maximum service life (ET max ) depict, which, depending on the respective increase in security level, determine how much percentage loss of the service life (PV) ETI ) is still to be considered advantageous; - At several further stopping points (SSP) i ), each of which has a positive difference value (ΔS) i ) compared to the application range endpoint (SSP) ODD_Ende ) achieve: Selecting the next breakpoint (SSP) i ), which has the lowest percentage loss over the useful life (PV) ETI ) exhibits and simultaneously lies below a threshold of the maximum tolerated loss of service life, which is defined by the respective safety limit curves (SGK), depending on the relative safety increase and the maximum service life (ET). max ) to the end-of-range limit (SSP)ODD_Ende ); and - Ending the autonomous operating state at the selected further stop point (SSP) i ) or the scope endpoint (SSP) ODD_Ende ).
Need to check novelty before this filing date? Find Prior Art

Description

[0001] The invention relates to a method for operating a motor vehicle that is particularly capable of highly autonomous driving or operation in an operating state, wherein the autonomous driving in this operating state takes place within an operational application area according to claim 1.

[0002] According to the current state of the art, the end of an operational design domain (ODD) of an automated or autonomous vehicle either does not take the safety of a stopping position into account at all or defines it statically.

[0003] DE 11 2021 005 727 T5 shows a vehicle for performing minimum risk maneuvers and a method for operating it.

[0004] DE 10 2015 015 277 A1 discloses a method for the automated stopping of a motor vehicle in a target area, wherein one procedural aspect of the disclosure comprises the following steps: Map data is provided in which potential target areas for stopping motor vehicles are defined by means of at least one attribute of map elements; an event is detected that requires an automated stopping of the motor vehicle; a target area is determined based on the current position of the motor vehicle and the potential target areas defined in the map data; upon detection of the event that requires an automated stopping of the motor vehicle, an automated stopping process is triggered, and the automated stopping process brings the vehicle to a stop in the determined target area.

[0005] DE 10 2017 217 131 B3 discloses a method for supporting a truck driver in finding a parking space, wherein first the start time of the driver's journey is recorded and then a remaining maximum driving time is determined depending on the start time and a legally prescribed maximum driving time, wherein simultaneously the position of the truck is recorded and then possible parking spaces are determined from a stored list of parking spaces which are located within a specified maximum distance to a specified route and subsequently the expected driving times required to reach each of the specified possible parking spaces from the recorded position are determined and finally a parking space is selected from the possible parking spaces where the specified driving time is less than the specified remaining maximum driving time.

[0006] US 2011 / 0238292A1 discloses a method for operating a navigation system in which a request for an emergency stop of a vehicle is received, the current position of the vehicle is determined, and an emergency profile representing a time to stop is generated, a maximum distance that can be traveled within this time to stop is determined, and an emergency stop location within this maximum distance is identified.

[0007] The object of the invention is to provide a method for operating a motor vehicle in which an advantageous selection of a stopping position is made before reaching the end of the Operational Design Domain of an autonomous operating state of the motor vehicle.

[0008] This problem is solved according to the invention by the method of the independent claim. Advantageous embodiments and further developments of the invention are specified in the dependent claims as well as in the description and the drawing.

[0009] The method according to the invention serves to operate a motor vehicle that is autonomous, in particular highly autonomous, in an operating state, wherein the autonomous driving takes place in the operating state within an operational application area or an Operational Design Domain (ODD).

[0010] The motor vehicle can be, in particular, a passenger car or a truck. The Operational Design Domain specifies a number of conditions, such as environmental influences, geographical and / or time-of-day conditions, under which the vehicle can operate autonomously, that is, independently and thus without user intervention. If a driver assistance system determines that the end of the ODD is reached during autonomous operation, the motor vehicle typically initiates a minimal-risk maneuver (MRN) if no driver takes over, bringing it to a stop at a designated stopping point. To ensure that this stopping point can be selected particularly advantageously, the method according to the invention comprises the following steps: The first step involves determining a maximum usage duration, which specifically represents the time required for an initial journey until reaching a planned end of the application area and therefore indicates the maximum possible usage duration for the application area. Furthermore, the first step determines an application area endpoint, which corresponds to the stopping point directly before or at the end of the application area and is thus used as a stopping point at the end of an autonomous journey or for the end of the autonomous operating state.

[0011] In a second step, a safety level is specified for the end-of-scope stop, i.e., the first stop point. In other words, the safety level for the end-of-scope stop is determined and checked to ensure it meets a self-defined minimum safety level. If this specified safety level falls below a specified level, further steps follow: In a third step, at least one further breakpoint is determined, which lies before the end of the application area and thus before the first breakpoint or end-of-application-area breakpoint, and whose further safety level, which can be determined immediately or in a separate step, is greater than the first safety level or the safety level of the end-of-application-area breakpoint.

[0012] In a fourth step, a further service life is determined for at least one additional stopping point.

[0013] In a fifth step, a difference value is determined between the further safety level and the first safety level, i.e., the safety level of the end-of-area stop. This difference value represents, in particular, an increase in safety at the further stop compared to the first stop. Furthermore, a time difference is determined between the maximum service life and the remaining service life of the further stop. This time difference can only be used if the difference value exceeds a threshold; otherwise, the procedure could be terminated at this point. Specifically, the time difference is then converted into a percentage loss compared to the maximum possible service life until the end-of-area stop.The percentage loss of useful life can only be used, for example, if it is below a threshold that represents the maximum tolerated loss of useful life; otherwise, the procedure would be terminated.

[0014] Finally, in a sixth step, depending on the time difference and the difference value, the autonomous operating state or autonomous journey is terminated at the first or the next stopping point. In this sixth step, a decision is made as to whether there is a further stopping point compared to the end of the application area that achieves a relative increase in safety and remains below a threshold of the maximum tolerated service life loss, where the threshold depends on the relative increase in safety and the maximum service life until the end of the application area.If several alternative holding positions offer a relative increase in safety compared to the end-of-area holding point, the holding position that exhibits the lowest percentage loss over the service life and is simultaneously below the threshold of the maximum tolerated service life loss, which depends on the relative increase in safety and the maximum service life until the end-of-area holding point, can be selected.

[0015] The maximum operating time and / or the remaining operating time refer to the period during which the vehicle can continue to operate autonomously until it reaches the corresponding stopping point. The respective safety level describes, for example, whether the vehicle stops due to the termination of autonomous driving in a lane, on a shoulder, in a lay-by, or similar location. Any number of safety levels, such as four, can be specified. If the end-of-use stopping point already has the highest safety level, the process can be terminated, as prematurely ending the autonomous journey at another stopping point would not provide any additional safety benefit but would shorten the autonomous journey and thus reduce driver comfort.In the method according to the invention, the further stopping point is only activated if a reduction in the autonomous journey time would be advantageous for a user in terms of safety. This is particularly the case if the percentage loss of the further stopping point relative to the maximum operating time until the end-of-application stopping point remains below a threshold value that depends on the maximum operating time until the end-of-application stopping point and the relative safety gain compared to the end-of-application stopping point.

[0016] In other words, the method according to the invention serves to determine a safe stopping position for an autonomous vehicle, whereby an optimization is performed between a maximum operating time of the autonomous vehicle and a relative safety gain compared to the stopping position of the planned Operational Design Domain (ODD), which is achieved by the additional stopping position. This is done by examining case distinctions to determine whether an alternative stopping position exists before the actual stopping position at the end of the ODD. For this method, stopping positions are referred to as "safe stop positions".

[0017] This offers the advantage of providing the driver with the greatest possible operating time, while at the same time allowing a minimal risk maneuver (MRM) to end in a particularly safe position.

[0018] According to the invention, the following additional steps are provided to end the autonomous operating state: In one step, the percentage loss of service life is determined by dividing the time difference from the maximum service life. In a further step, safety limit curves are defined that represent the percentage loss of service life over the maximum service life. These curves, depending on the respective increase in safety level, determine what percentage loss of service life is still considered advantageous.In the next step, if several further holding points are identified, each achieving a positive difference value compared to the end-of-application holding point, the next holding point is selected that exhibits the lowest percentage loss of service life and simultaneously lies below a threshold of the maximum tolerated service life loss. This threshold is defined by the respective safety limit curves, depending on the relative safety increase and the maximum service life until the end-of-application holding point. Finally, the autonomous operating state is terminated at the selected further holding point or at the end-of-application holding point. In other words, the percentage loss of service life is determined by the ratio of the time difference to the maximum service life.Subsequently, safety limit curves are defined, representing the percentage loss of service life above the maximum possible experience time. These curves, depending on the respective safety level increase, determine what percentage loss of service life is still considered advantageous according to the procedure. If several alternative stopping positions offer a relative safety increase compared to the SODD (Standard Operating Time), the stopping position with the lowest percentage loss of service life, while simultaneously remaining below the threshold of the maximum tolerated service life loss, is selected. This threshold is defined by the respective safety limit curves (SGK), depending on the relative safety increase and the maximum service life up to the SODD. Depending on the described steps, autonomous driving is then terminated at the first stopping point or at an alternative stopping point.

[0019] In a further advantageous embodiment of the invention, the safety level includes the presence of a shoulder, a lay-by or a parking space and / or good visibility.

[0020] In a further advantageous embodiment of the invention, for at least two further stopping points, the stopping point is selected whose percentage loss of service life is below a threshold value for the respective safety increase and maximum service life, and the stopping point that has the lowest percentage loss of service life is selected.

[0021] In a further advantageous embodiment of the invention, the termination of the operating state occurs due to an ignored driver takeover request, in particular in the form of a Minimal Risk Maneuver (MRM).

[0022] In a further advantageous embodiment of the invention, a maximum time difference and / or a minimum difference value are specified, for example via a maximum tolerated percentage loss of service life and depending on a user input or by an assistance system or a server.

[0023] Further advantages, features, and details of the invention will become apparent from the following description of a preferred embodiment and from the drawing. The features and combinations of features mentioned above in the description, as well as those mentioned below in the figure description and / or shown in the figures alone, can be used not only in the combinations specified, but also in other combinations or individually, without departing from the scope of the invention.

[0024] It shows: Fig. 1. A schematic top view of a road section, based on which a method for operating a motor vehicle is outlined; and Fig. 2 a diagram of a percentage time loss against the maximum service life determined by the procedure, depending on a relative increase in the level of safety.

[0025] In the figures, identical or functionally equivalent elements are provided with the same reference symbols.

[0026] The following presents a method for operating a motor vehicle (KF), specifically a method for optimizing the safety of the stopping position before a planned operational driving time (ODD) end and the service life of an automated driving system. This method aims to enable the motor vehicle (KF), which is operating autonomously, particularly in a highly autonomous mode, within an operational driving time (ODD) environment, to stop advantageously if a driver fails to take over before the ODD ends. The autonomous driving time can be achieved, for example, by a driver assistance system.Before reaching the end of the operational application range and thus the end of the autonomous operating state, the takeover by the driver should generally be initiated, either as a driver takeover or as a minimal risk maneuver (MRM), which in the latter case is made possible in particular by approaching a safe stop position (SSP).

[0027] The method thus serves to operate a motor vehicle KF capable of autonomous driving in an operating state, whereby autonomous driving takes place within the operational application area ODD. The presented method comprises the following steps: The first step involves determining a maximum service life or maximum possible service life (ET). maxuntil reaching a planned end of the application area ODD and determining a stopping point or the application area end stopping point SSP ODD_Ende at the end or for the end of the operational application area ODD and thus the end for autonomous driving.

[0028] In a further step, a security level S is specified. ODD_Ende for the stopping point at the ODD end or the application area end stopping point SSP ODD_Ende, and if this is below a predetermined level, at least one further SSP holding point is determined in a further step. i , which is before the end of the scope ODD and thus before the scope endpoint SSP ODD_Ende is located and its further security level S ODD_Ende greater than the first security level S ODD_Ende is. The first security level S ODD_EndeThis is the safety level of the application area's endpoint. In a further step, a further service life (ET) is determined. i for at least one more SSP stop i The index i can take values ​​from 1 to k, where in the exemplary embodiment k=3.

[0029] Subsequently, in a further step, a difference value ΔSi of the further safety level S is determined. i with the first security level S ODD_Ende , and a time difference ΔET i between the maximum service life ET max and the further useful life ET i .

[0030] Finally, depending on the time difference ΔET i and the difference value ΔSi, an end to the autonomous operating state and thus to autonomous driving at the application area end stop SSP ODD_Ende or at the further stop SSP iIn particular, the percentage loss over useful life ΔET is used as a basis for calculation. i in relation to the maximum possible service life ET max , which depends on the relative increase in safety level ΔS i used to select an optimized stopping point, ending the autonomous operating state and thus the autonomous journey at the first stopping point SSP ODD_Ende or at the further stop SSP i carried out.

[0031] Furthermore, the following steps can also be performed: In one step, the percentage loss of the PV's service life is determined. ETi through the ratio of the time difference ΔET i for maximum service life ET max In a further step, safety limit curves (SGK) are defined, which determine the percentage loss of the PV service life. ETi above the maximum service life ET maxto map, which, depending on the respective increase in security level, determine what percentage loss of the PV service life ETi which is still considered advantageous. In the next step, SSP will be carried out at several further stopping points. i , each with a positive difference value ΔS i opposite the application range endpoint SSP ODD_Ende to achieve, a selection of the further holding point SSP i , which has the lowest percentage loss over the PV service life ETi exhibits and simultaneously lies below a threshold of the maximum tolerated service life loss, which is defined by the respective safety limit curves SGK, depending on the relative safety increase and the maximum service life ET max to the end of the application range SSP ODD_Ende Finally, the autonomous operating state is terminated at the selected next stopping point SSP. ior the application range endpoint SSP ODD_Ende .

[0032] Fig. Figure 1 shows a road section from a bird's-eye view, with the end of the operational application area (ODD) after a maximum possible service life (ET). max is reached and, in the exemplary embodiment, leads to a stopping point SSP ODD_Ende on the roadway FB in front of a tunnel entrance TE. In the example shown, the end of the operational application area ODD lies at the tunnel entrance TE, since autonomous driving cannot be provided within the tunnel. Three further stopping points SSP are defined for the roadway section shown. i identified a parking lot PP, a parking bay PB and a shoulder or hard shoulder SS.

[0033] In this exemplary embodiment, the following safety levels are used for the holding positions SSP. ispecified: the safety level in the lane or roadway FB and thus at SSP ODD_Ende The safety level of the shoulder SS is set at one, that of the parking bay PB at two, and parking lots or similar places such as petrol stations, rest stops and the like at three.

[0034] In other words, the method serves to optimize between a maximum service life ET max or experience time and a relative safety gain compared to the safe stop position as the holding point SPP. ODD_Ende of the planned OOD end, whereby several, in particular three, cases can be distinguished: Does the scope endpoint SPP indicate ODD_Ende If a certain level of safety is reached at the end of the ODD, for example through the presence of a shoulder or good visibility, then no check is carried out to see if there is still a safe stopping point (SPP).i before the ODD end. It is therefore simply planned to start at the application area endpoint SPP. ODD_Ende to keep the end of the ODD.

[0035] If, from the time of activation of the procedure or the activation of the autonomous, in particular highly autonomous, operating state, until the end of the operational application period ODD, there is no SSP breakpoint i there is one that is safer than the application domain endpoint SSP ODD_Ende , will also be at the SSP ODD_Ende held.

[0036] Is there at least one further breakpoint (SSP) between the activation of the operating state and the end of the operational application range? i , which is safer than the SSP ODD_Ende , which, as in this example, does not provide a sufficient level of security S i or has a security level of zero, the optimization process can be carried out: This involves an alternative stopping point SSP.i determined before the actual end of the operational application scope ODD. All SSP i They include a buffer that allows the vehicle to start moving again after coming to a standstill, so that the driver can merge back into traffic if necessary.

[0037] For each SSP stop i As already described, the service life ET i or Experience Time to the alternative stop SSP i determined. Next, it will be checked whether the security level S ODD_Ende of the planned end is sufficient. If this is not the case, the three SSPs are used, as in this example. i determined, whereby an SSP i It will only be taken into account if it leads to an increase in safety compared to the SPP stopping point. ODD_Ende leads and the SSP ias close as possible to the end of the operational application area ODD and thus to the tunnel entrance TE. If the positions of parking bay PB and parking lot PP were reversed, parking bay PB would not be considered, since the usage period ET i would be reduced without achieving an increase in safety.

[0038] This results in an increase in safety, essentially the difference value ΔS. i and the loss of useful life ΔET i calculated: Loss of ET i opposite ET max : ΔET1=ETmax−ET1 ΔET2=ETmax−ET2 ΔET3=ETmax−ET3 Percentage loss of ET i in relation to ET max : PVET1=(ΔET1 / ETmax)∗100 PVET2=(ΔET3 / ETmax)∗100 PVET3=(ΔET3 / ETmax)∗100 Trade-off points (see below) Fig. 2): PVET1|ΔS1 PVET2|ΔS2 PVET3|ΔS3 Increased security level: ΔS1=S1−SODD End=3 ΔS2=S2−SODD End=2 ΔS3=S3−SODD End=1

[0039] The percentage losses PV calculated according to the formulas above ETi can, as the graph of the Fig. Figure 2 shows the maximum possible service life ET max be applied.

[0040] The maximum tolerated time loss is determined by PV T specified, which now indicates the alternative or further stopping point SSP i can be chosen in such a way that it remains below the limit of the maximum tolerated time loss PV T stands, the lowest PV ET exhibits and simultaneously falls below the respective safety limit curve SGK, which determines how much PV depends on the respective safety increase. ET The permitted range is determined by the respective safety limit curve (SGK), which is based on the difference value ΔS. i a course and thus the ratio of time difference ΔET and difference value ΔSi over time again, where in the example shown the second stopping point SSP2, i.e. the parking bay PB, is the new alternative end in the case of a triggered and ignored driver takeover request, which is ignored by a driver and thus a triggered take-over request occurs, which, in the case of a missing takeover, leads to the MRM that ends in the parking bay.

[0041] The procedure is based on the understanding that the area in which a highly automated driving system, the driver assistance system, can be permitted or activated is referred to as the Operational Design Domain (ODD). Before the end of the ODD, the driver is prompted to take over control in a timely manner via a driver takeover request. If the driver does not comply with the request, the low-risk maneuver MRM is executed, which ensures that the vehicle comes to an automated stop no later than the defined end of the ODD.

[0042] The availability of a highly autonomous operating state, or the possibility of activating it, can depend on various environmental and system factors, such as map data of sufficient quality, weather conditions with adequate visibility for sensors, a system state such as system or component errors, structural conditions not considered in the system design, such as construction sites and tunnels, and / or unforeseen events such as people on the road, emergency vehicles and / or wrong-way drivers.

[0043] The end of the operational data distribution (ODD) scope of a highly autonomous operating state can therefore be either predictable or unexpected, depending on information sources. Examples of predictable ends include a lack of map coverage, tunnels or certain road types, construction sites and the like, national borders (where, for example, certain driver assistance systems are not permitted in some countries), online traffic reports or information from a backend system, as well as navigation and route planning. Examples of sudden or unexpected ends include the detection of mobile construction sites, people or objects on the road, blurred lane markings, emergency vehicles, and the like by sensors.

[0044] The planned end of the ODD (Optical Difficulty Distribution) is independent of structural regulations or similar factors. It can therefore be located, for example, at motorway junctions, especially tunnels, or at on- and off-ramps. Current state-of-the-art technology does not consider whether a safe stopping position (SSP) can be reached within the MRM (Military Retention Mechanism). Therefore, the ODD end may be located on a road section without a hard shoulder, after a curve, next to or parallel to an on-ramp, on lane dividers before a motorway junction, at a motorway junction, at an off-ramp, and / or next to an off-ramp. To increase safety, the presented method is introduced, which determines a safe stopping position before the ODD end and can be advantageously implemented through the optimization shown.

Citation Information

Patent Citations

  • Technique for automatically stopping a vehicle in a target area

    DE102015015277A1

  • Method to support a vehicle driver of a truck when searching for a parking space and a system which is set up to carry out such a method

    DE102017217131B3

  • VEHICLE FOR PERFORMING MINIMUM-RISK MANEUVERS AND PROCEDURES FOR OPERATING THE SAME

    DE112021005727T5

  • Method of operating a navigation system

    US20110238292A1