Methods for a vehicle EE architecture
The vehicle EE architecture with local processors and redundant sensors ensures robust ADAS operation by preprocessing signals and executing actions based on sensor failures, maintaining functionality and user awareness.
Patent Information
- Authority / Receiving Office
- DE · DE
- Patent Type
- Applications
- Current Assignee / Owner
- DR ING H C F PORSCHE AG
- Filing Date
- 2024-11-14
- Publication Date
- 2026-05-21
AI Technical Summary
Existing vehicle electrical/electronic (E/E) architectures face challenges in ensuring that Advanced Driver Assistance Systems (ADAS) do not completely fail or become downgraded due to the failure of a sensor, particularly in autonomous driving scenarios where sensor failures can lead to a loss of functionality.
A vehicle EE architecture is implemented with local processors that fuse sensors within zones, allowing for robust operation by preprocessing signals and executing ADAS actions based on the local impact of sensor failures, using redundant sensors and software-driven decisions to ensure fail-safe operation.
The method enables robust and fail-safe operation of ADAS functions by allowing the central computer to execute pending actions despite sensor failures, providing relevant warnings to the user only when necessary and ensuring continued vehicle assistance.
Smart Images

Figure 00000000_0000_ABST
Abstract
Description
[0001] The invention relates to a method for a vehicle EE architecture, as well as a motor vehicle with a vehicle EE architecture on which such a method can be carried out.
[0002] A vehicle electrical / electronic (E / E) architecture (also known as vehicle EE architecture) refers to the electrical / electronic architecture of a motor vehicle. It describes the network and structure of all electrical and electronic systems in the vehicle. This includes control units, sensors, actuators, and the wiring that connects these components. These systems control and monitor various vehicle functions, such as engine control, driver assistance systems, and infotainment. The vehicle E / E architecture ensures the communication and control of all electronic systems in the vehicle. To reduce the need for heavy and complex wiring between a central computer and peripheral sensors, the goal is to zonally fuse the sensors. This involves assigning a local processor to each zone (i.e., region) of the vehicle, where signals are preprocessed and then forwarded to the central computer.In addition to this fusion, algorithms such as camera blindness detection or radar blockage detection are implemented within the respective zonal processor.
[0003] One challenge resulting from the merger is ensuring that a vehicle assistance system [FAS, or ADAS, English: Advanced Driver Assistance System] does not completely fail or become downgraded due to the failure of a sensor, for example from Level 3 (autonomous driving with permitted driver handover) to Level 2 (driver responsible).
[0004] Based on this, the present invention aims to overcome, at least partially, the disadvantages known from the prior art. The features of the invention are defined in the independent claims, for which advantageous embodiments are shown in the dependent claims. The features of the claims can be combined in any technically meaningful way, whereby the explanations in the following description and features from the figures, which comprise supplementary embodiments of the invention, can also be used.
[0005] The invention relates to a method for a vehicle EE architecture, wherein the vehicle EE architecture comprises at least the following components: - a plurality of sensors for an ADAS function; - a central computer; - a plurality of local processors, wherein a zonal subset of sensors is fused locally in a local processor.
[0006] The method is characterized primarily by the fact that it is robust against the failure of one or more sensors of a subgroup, in that the central computer executes a pending ADAS action depending on the local effect of such a failure.
[0007] Unless explicitly stated otherwise, ordinal numbers used in the preceding and following descriptions serve solely for unambiguous differentiation and do not indicate any order or ranking of the components referred to. An ordinal number greater than one does not necessarily imply the presence of another such component.
[0008] It should be noted that the procedure proposed here (monitoring) is executed during the proper operation of a vehicle assistance system [FAS, or ADAS, English: Advanced Driver Assistance System] or only becomes active when a failure occurs, i.e., in the latter case, is triggered by a failure.
[0009] Here is a brief (not exhaustive) overview of ADAS functions currently available or common: In the so-called Level 2 (partial automation, responsibility lies with the vehicle user, who is an occupant in the vehicle in question): - Lane Keeping Assist, which keeps the vehicle in the middle of the current lane by slightly correcting the steering if the vehicle threatens to leave the lane. - Blind spot assist, which monitors the blind spots and warns the driver / passenger when a vehicle is in the blind spot to avoid collisions when changing lanes. - Lane Change Assist, which supports the driver and passengers when changing lanes by monitoring the surroundings for other vehicles and initiating the lane change when the lane is clear. - (Emergency) brake assist, which detects impending collisions and automatically brakes the vehicle (if necessary sharply) to avoid a collision or at least reduce the impact speed. - Adaptive cruise control, which maintains a preset speed and automatically adjusts the distance to vehicles ahead by reducing or increasing the speed. - Traffic sign recognition, which recognizes traffic signs such as speed limits and no-overtaking signs and displays them to the driver and passengers in an infotainment system. - Parking assistant, which helps with parking and exiting by taking over the steering and assisting the driver with the accelerator and brake pedals. In the so-called Level 3 (conditional automation, responsibility can be transferred to the driver / occupant if necessary): - Traffic jam assist, which takes control of the vehicle in traffic jam situations by adjusting the speed to the traffic flow and keeping the vehicle in its lane. - Autonomous parking, which automatically guides the vehicle into a parking space and also guides it out again without the need for intervention from the driver / passenger, but the driver / passenger can intervene. - Remote control, which makes it possible to control the motor vehicle from a distance, for example to maneuver it out of tight parking spaces, garages or car washes, while the driver is outside the vehicle. - Autonomous driving on the motorway [Highway Pilot], which takes full control of the motor vehicle on motorways, including lane changes, overtaking maneuvers and approaching entrances and exits, while the driver-occupant can regain control at their own request. - Autonomous driving on country roads [Country Road Pilot], which takes control of the motor vehicle on country roads, including navigation through curves and adjusting speed to road conditions. - Autonomous overtaking, which automatically performs overtaking maneuvers on highways and expressways when traffic conditions allow. - Autonomous driving in the city [Urban Pilot], which takes control of the motor vehicle in urban environments, including navigating through intersections, stopping at traffic lights and avoiding obstacles.
[0010] Such a sensor could be, for example, a camera, radar, or LiDAR (Light Detection and Ranging), whereby preferably at least two sensors in each subgroup have an overlapping field of view, thus providing mutual redundancy. Therefore, if one of two redundant sensors is impaired, the functionality of the ADAS function may not be affected (for example, radar signals are only necessary in rainy weather, or conversely, camera signals are inherently redundant because they do not need to provide sufficiently reliable results in rain and / or fog, even without camera malfunction). It should be noted that this assessment is merely a prerequisite for the method proposed here, i.e., determining whether a failure has actually occurred. This is evaluated and decided, for example, by the processor of the respective subgroup.Alternatively or additionally, this is evaluated and decided by the central computer. According to this procedure, in the event of a failure, the central computer assesses the relevance of the respective subgroup for the respective ADAS action and then decides whether it can still be executed with sufficient or no impairment despite the failure.
[0011] The central computer is usually mobile and located in the vehicle. Alternatively or additionally, a central computer or a component of the central computer is located externally, for example in the so-called cloud and / or an edge device and / or another vehicle (e.g., a vehicle fleet), where computationally intensive and / or less time-critical calculations are performed and / or relevant data (e.g., swarm data from a vehicle fleet) is obtained.
[0012] In one embodiment, the respective processor is part of a so-called ECU (Electronic Control Unit), i.e., a local control unit, preferably comprising volatile and / or non-volatile memory. The processor in each of the subgroups thus enables at least rudimentary processing of the signals and requirements of the sensors in that subgroup, thereby establishing a signal connection to the central computer and performing the aforementioned blindness detection.
[0013] The primary purpose of grouping sensors and their signals into subgroups is to reduce the physical data transmission overhead. This means, for example, that a single cable needs to run from each subgroup to the central computer (or a communication interface to the central computer), instead of a separate cable from each sensor. This is achieved through a process called data fusion within the respective processor (or ECU) of each subgroup, essentially bundling the cabling zonally.
[0014] It is therefore proposed that any limitation of the vehicle's electrical / electronic (EE) architecture's capabilities for the desired or required ADAS function should not be hardware-based, but rather that an ADAS action should first be checked against the necessary signals or information from sensors. For example, if a lane change requires an unobstructed field of vision or is still sufficiently monitored (e.g., by one of two redundant sensors), the ADAS action will be executed even if a sensor responsible for that field of vision has failed. In contrast, conventionally, an ADAS action is only executed if the relevant sensors are fully operational, i.e., functioning without any impairment.
[0015] This software-driven decision regarding the execution of an ADAS action allows for particularly robust, and therefore fail-safe, operation of an ADAS function within a vehicle's electrical engineering architecture. Furthermore, it enables feedback to the user (e.g., the current occupant-driver) of the vehicle in question, which is very specific, indicating which sensor has failed and what limitations this entails for the ADAS functions, for example, via a warning in the vehicle's infotainment system. In one embodiment, such a warning is not triggered if it is not relevant to the current ADAS function, for example, as in the example above, a lane change to the other side, i.e., with a field of view for which a different subgroup is responsible.
[0016] In a further advantageous embodiment of the method, it is proposed that if there is an impact on an upcoming ADAS action, a warning is issued to a vehicle user via an infotainment system.
[0017] In a vehicle electrical architecture with ADAS operation at Level 2, responsibility lies with the driver, or at Level 3, responsibility can be transferred to the vehicle user (here, a current driver / occupant in the passenger compartment) of the vehicle in question. Systems approaching Level 4 already exist in public spaces where an external vehicle user, who typically monitors multiple fully autonomous vehicles, can and must assume responsibility.
[0018] To enable the vehicle user to adequately assume this responsibility, it is advisable to warn them. However, it is proposed that the vehicle user not be unnecessarily confused by being notified of a sensor or zonal failure at all times and without conditions. Rather, it is proposed that such a warning be issued only when the failure is relevant to the required ADAS action. In the above example of a lane change, the vehicle user would therefore receive a warning if such a lane change is to be performed, or must be performed, and this can no longer be carried out automatically or is no longer supported by sensors due to a zonal failure (i.e., a warning light in the rearview mirror can no longer be adequately supplied with information, meaning it no longer functions reliably).In one embodiment of a Level 2 regime, such a warning is issued using known warning methods. For example, during a lane change affected by the failure, a corresponding warning light in the rearview mirror illuminates as if a hazard has been detected, and / or a voice message is emitted to inform the vehicle user of the acute limitation of the ADAS function. In one embodiment of a Level 3 regime, such a warning is a change in the interior lighting of the passenger compartment and / or a voice message to inform the vehicle user of the acute limitation of the ADAS function.
[0019] It should be noted that in other cases (for example, changing lanes in the opposite direction), the vehicle user is given the impression that the systems are functioning correctly, which is absolutely true for these other ADAS actions, i.e., those on which the failure has no limiting effect. In these cases, the vehicle user receives full support from the central computer to execute the desired and / or necessary ADAS actions.
[0020] In a further advantageous embodiment of the method, it is proposed that in the local processor and / or in the central computer, the criticality of the failure is checked in the event of a failure in a subgroup.
[0021] As mentioned earlier, not every failure of a single sensor necessarily results in a limitation, for example, due to favorable conditions (such as good visibility) and / or redundant sensor use. Therefore, it is advantageous to assess the criticality of a failure. For instance, if three sensors are used in a subgroup, in a simple implementation, the failure of a single sensor would be subcritical, while the failure of two sensors would be critical. In one embodiment, a subcritical state means that the central computer or the vehicle assistance system is not even aware of the failure. Preferably, the central computer or the vehicle assistance system is informed and makes an appropriate decision for the respective ADAS action, as described above.Factors such as weather conditions, traffic density, and / or signal quality from other sensors are also taken into account. Ideally, this decision-making process regarding criticality is not influenced by the vehicle user, thus ensuring a high level of safety.
[0022] In a further advantageous embodiment of the method, it is proposed that at least one of the following ADAS actions is affected depending on a local impact of such a failure: - a lane change assistant; - a distance control assistant; and - a brake assist system.
[0023] In this approach, the decision regarding a failure, its impact, and / or criticality is preferably left to the respective software unit. For example, in one embodiment, the remote control function is completely deactivated if a zonal failure occurs, thus preventing the vehicle from being maneuvered into a position where a subsequent failure would prevent it from being steered out. Alternatively, the vehicle operator is instructed to take appropriate safety measures, such as securing an area where sensor activity is limited or non-functional, and / or, if necessary, to get into the vehicle and take over driving to continue maneuvering.
[0024] A distance control assistant, brake assist, adaptive cruise control, parking assist, traffic jam assist and / or parking assist may not require particularly high-quality sensor data, so a lower level of criticality can be applied, possibly together with a corresponding warning (displayed continuously or ad hoc during each corresponding ADAS action) for an occupant (e.g., driver), so that an ADAS action set to greater caution due to the lower signal quality, which is perceived as overly sensitive behavior of the vehicle, meets with understanding from the occupant.
[0025] According to another aspect, a motor vehicle with a vehicle EE architecture is proposed, which further comprises at least the following components: a transport cabin, a drive train with a drive motor and a drive axle with at least one drive wheel, wherein at least one drive wheel can be driven to propel the motor vehicle by means of a torque output from the drive train, where driving the motor vehicle is supported and / or carried out by the ADAS function of a vehicle EE architecture, wherein the vehicle EE architecture is configured to execute a method according to an embodiment as described above.
[0026] The motor vehicle is equipped with a vehicle EE architecture for a vehicle assistance system [FAS, or ADAS, English: Advanced Driver Assistance System] (not necessarily exclusively for this purpose).
[0027] The transport cabin can carry goods and / or people (occupants), whereby, with a Level 2 or Level 3 vehicle assistance system, one of the occupants is a vehicle user, i.e., driver-occupant. The powertrain is designed to propel the vehicle, whereby at least a portion of the generated torque can be converted into propulsion via one (or more) drive axle(s).
[0028] The vehicle's electrical (EE) architecture is designed such that sensors are grouped zonally into subgroups. This means that the data is fused in a local (or zonal) processor or an ECU (Electronic Control Unit) and only then forwarded to a central computer, where it undergoes preprocessing, as described previously. These subgroups are divided into zones, for example, a northern subgroup (with a northern processor), a southern subgroup (with a southern processor), an eastern subgroup (with an eastern processor), and a western subgroup (with a western processor). The designation according to cardinal directions is defined, for example, according to a standard automotive coordinate system (Cartesian coordinate system), where, in a top view of the vehicle, the X-direction, pointing in the direction of travel, is defined as being equal to north.
[0029] It is therefore proposed that the vehicle assistance system be very robust in its operation against the failure of one or more sensors of a subgroup, by the central computer executing a pending ADAS action depending on a local impact of such a failure according to an embodiment of the previously described method.
[0030] It should be noted that the procedure can also be used in other ways and not only in motor vehicles, but is preferably used in the area of passenger cars or transport vehicles (taxi, logistics).
[0031] The invention described above is explained in detail below against the relevant technical background with reference to the accompanying drawings, which show preferred embodiments. The invention is in no way limited by the purely schematic drawings, although it should be noted that the drawings are not dimensionally accurate and are not suitable for defining size relationships. It is illustrated in Fig. 1: a schematic top view of a motor vehicle with zonal vehicle EE architecture; and Fig. 2: An interior view from back to front of the transport cabin of a motor vehicle designed as a passenger car.
[0032] In Fig. Figure 1 shows a schematic top view of a motor vehicle 18, optionally equipped here with two drive axles 22, each with a drive train 20 and its own drive motor 21, which is designed with a zonal vehicle ECU architecture 1. This architecture includes four main zones and two sub-zones each at the front (north) and rear (south), further subdivided into east and west. Thus, as shown, there is a north subgroup 10 on the right (with the two sub-zones northeast subgroup 23 at the top right and northwest subgroup 24 at the bottom right), a south subgroup 11 on the left (with the two sub-zones southeast subgroup 25 at the top left and southwest subgroup 26 at the bottom left), an east subgroup 12 at the bottom center, and a west subgroup 13 at the top center. Each subgroup has its own (zonal) processor (or ECU).The Electronic Control Unit (ECU) consists of three zonal processors: North subgroup 10 has a North processor 6, East subgroup 12 has an East processor 8, South subgroup 11 has a South processor 7, and West subgroup 13 has a West processor 9. Processors 6, 7, 8, and 9 are supplied with data signals from their respective sensors 2, 3, and 4. Thus, the data from sensors 2, 3, and 4 of each subgroup (10, 11, 12, 13) are fused in the corresponding zonal processor 6, 7, 8, and 9. Processors 6, 7, 8, and 9 are each connected to the central computer 5. The following are shown as examples: a first sensor 2 (e.g., a camera), a second sensor 3 (e.g., a radar sensor), and a third sensor 4 (e.g., a LiDAR [Light Detection and Ranging]). It is evident that sensors 2, 3, and 4 are partially used for redundant environmental monitoring.
[0033] The Northwest subgroup 24 is shown here as a purely example of a failure (either completely or, according to a criticality level, over-critical). For instance, this means that ADAS action 14 for a left (West) lane change is no longer possible, while a right (East) lane change remains unaffected.
[0034] In Fig. Figure 2 shows an interior view from rear to front of the transport cabin 19 of a motor vehicle 18 designed as a passenger car, with a vehicle user 17 shown seated at the steering wheel as the driver / passenger. The vehicle user 17 is looking at a screen of an infotainment system 15 of the motor vehicle 18. The failure of the northern subgroup 10 (compare Fig.1) is displayed and has therefore received a warning 16. A lane change assistant will still execute a lane change to the right (arrow with solid line pointing to the right as shown, or east), but to the left (arrow with dashed line pointing to the left as shown, or west) the vehicle user 17 must at least participate or execute this completely himself.
[0035] The method proposed here enables robust operation of a vehicle assistance system against sensor failure in the case of zonal vehicle EE architecture. Reference symbol list 1 Vehicle EE architecture 2 first sensor 3 second sensor 4 third sensor 5 Central computers 6 North Processor 7 South Processor 8 East Processor 9 West Processor 10 Northern Subgroup 11 Southern Subgroup 12 Eastern Subgroup 13 Western Subgroup 14 ADAS Action 15 Infotainment system 16 Warning 17 vehicle users 18 Motor vehicle 19 Transport cabin 20 Powertrain 21 Drive machine 22 Drive axis 23 Northeast Subgroup 24 Northwest Subgroup 25 Southeast Subgroup 26 Southwest Subgroup
Claims
Method for a vehicle EE architecture (1), wherein the vehicle EE architecture (1) comprises at least the following components: - a plurality of sensors (2, 3, 4) for an ADAS function; - a central computer (5); - a plurality of local processors (6, 7, 8, 9), wherein a zonal subgroup (10, 11, 12, 13) of sensors (2, 3, 4) are each locally fused in a local processor (6, 7, 8, 9), characterized in that the method is robust against a failure of one or more sensors (2) of a subgroup (10) by the central computer (5) executing a pending ADAS action (14) depending on a local effect of such a failure. Method according to claim 1, wherein, in the event of an impact on an upcoming ADAS action (14), a warning (16) is issued to a vehicle user (17) via an infotainment system (15). Method according to claim 1 or claim 2, wherein in the local processor (6) and / or in the central computer (5) a failure in a subgroup (10) is tested for criticality of the failure. Method according to one of the preceding claims, wherein at least one of the following ADAS actions (14) is affected depending on a local effect of such a failure: - a lane change assistant; - a distance control assistant; and - a brake assist. Motor vehicle (18) with a vehicle EE architecture (1), the motor vehicle (18) further comprising at least the following components: a transport cabin (19), a drive train (20) with a drive motor (21) and a drive axle (22) with at least one drive wheel, wherein the at least one drive wheel can be driven to propel the motor vehicle (18) by means of a torque output by the drive train (20), wherein steering of the motor vehicle (18) is supported and / or performed by the ADAS function of a vehicle EE architecture (1), wherein the vehicle EE architecture (1) is configured to perform a method according to one of the preceding claims.