Device, system and method for verifying a trajectory for the safe operation of a vehicle
The device and system enhance vehicle safety by integrating redundant data paths to verify and modify trajectories, ensuring only safe maneuvers are executed, addressing the lack of direct trajectory-level safeguarding in existing systems.
Patent Information
- Application Number
- DE102024205231
- Authority / Receiving Office
- DE · DE
- Patent Type
- Applications
- Current Assignee / Owner
- Filing Date
- 2024-06-07
- Publication Date
- 2025-12-11
AI Technical Summary
Existing vehicle trajectory verification systems do not provide direct safeguarding at the trajectory level, leaving vehicles vulnerable to unsafe maneuvers.
A device and system that integrates a trajectory planning module, an environment perception unit, and a vehicle control unit to verify and modify trajectories to ensure they meet predefined safety criteria, using redundant data paths for enhanced safety.
Ensures only safe trajectories are executed, reducing the risk of collisions and ensuring compliance with traffic regulations by continuously verifying and modifying trajectories based on real-time environmental data.
Smart Images

Figure 00000000_0000_ABST
Abstract
Description
[0001] The invention relates to a device, a system and a method for verifying a trajectory for the safe operation of a vehicle.
[0002] The following definitions, descriptions and explanations retain their respective meaning and disclosure content for and apply to the entire disclosed subject matter of the invention.
[0003] DE 10 2017 213 353 A1 discloses a verification device for verifying a planned trajectory of an automated motor vehicle, wherein the verification device is configured to acquire environmental data about the environment of the motor vehicle by means of at least two sensors of the motor vehicle, to generate an environment model from the acquired environmental data, to plan a trajectory for the motor vehicle depending on the environment model, and to check the planned trajectory for a collision of the motor vehicle with an object by means of the environmental data of at least one sensor, so that a verified trajectory results.
[0004] DE 10 2019 119 656 A1 discloses a control device for determining at least one validated trajectory for a motor vehicle, wherein the control device is configured to determine at least one conventional trajectory, to validate at least one conventional trajectory by means of at least one first AI unit, and to determine at least one validated trajectory depending on the validation of the at least one conventional trajectory and the at least one conventional trajectory itself.
[0005] WO23242186 A1 discloses a procedure for the safety verification of a planned target trajectory for an ego vehicle.
[0006] DE 10 2020 205 419 A1 discloses a device for evaluating signals from environment sensors for trajectory control and / or steering of an automated vehicle, wherein signals in a first detection area and signals in a second detection area of the environment sensors are evaluated in a first path and in a second path.
[0007] arXiv: 1708.0637 4v6 [cs. RO] reveals a formalism for the safe operation of self-driving vehicles.
[0008] In "The Safety Force Field," David Nistér et al., a general theory of safety at the obstacle avoidance level is revealed; see https: / / www.nvidia.com / content / dam / en-zz / Solutions / self-driving-cars / safety-force-field / the-safetyforce-field.pdf.
[0009] Further state of the art is revealed in “Provably Safe Motion Planning for Autonomous Vehicles Through Online Verification”, Christian Friedrich Pek, see https: / / mediatum.ub.tum.de / doc / 1534013 / 1534013.pdf.
[0010] The methods known in the prior art relate to safeguarding at the level of sensors for environmental detection and their signal control. A disadvantage of this is that no safeguarding takes place directly at the trajectory level.
[0011] The purpose of the invention was to demonstrate how a trajectory test for the safe operation of vehicles, for example autonomous vehicles, can be implemented.
[0012] The subject matter of the dependent claims each solves this problem. Advantageous embodiments of the invention will become apparent from the preceding and subsequent definitions, the dependent claims, the drawings and the description of preferred embodiments, and from the...
[0013] According to one aspect, the invention provides a device for verifying a trajectory for the safe operation of a vehicle. The vehicle can be, for example, a road vehicle, such as a passenger vehicle (e.g., a shuttle), or a goods vehicle (e.g., a commercial vehicle). According to one aspect, the vehicle is an automated vehicle; according to another, it is an autonomous vehicle.
[0014] The device includes a first interface to a trajectory planning module. The first interface can be a data or signal interface in the vehicle's on-board network.
[0015] A trajectory planning module is a hardware or software unit designed to determine the optimal route or path—the trajectory—for a vehicle's movement, for example, in the form of points along a line, taking into account various internal and external parameters. The module processes data such as sensor information, map data, and / or traffic data, as well as the vehicle's current state or ego motion, such as speed, acceleration, position, and / or orientation, and plans an intended trajectory in real time. The intended trajectory can be planned to maximize safety, minimize energy consumption, and ensure compliance with traffic regulations.The module continuously receives and analyzes data from various sources, including but not limited to lidar, radar, camera, and ultrasonic sensors, as well as V2X communication systems. The module can process algorithms, including machine learning, to predict the behavior of other road users and to optimally plan the intended trajectory, taking potential future events into account.
[0016] The trajectory planning module is designed to calculate a trajectory based on received data about the vehicle's state and the state of its environment. Vehicle states can include, for example, the vehicle's own motion, such as accelerations, which can be measured using accelerometers. Localization can also be a vehicle state. State in the vehicle's environment can include, for example, dynamic and / or static objects, such as other road users. Static data can include, for example, map data. The environment is the area whose objects can influence the vehicle.The conditions of the environment can be detected, for example, using an environmental perception unit, a so-called vehicle perception system, comprising sensors such as cameras, lidar, radar, acoustic sensors, and evaluation electronics and software, such as environmental models. Calculating the trajectory can mean calculating points along a line along which the vehicle is to travel.
[0017] Furthermore, the device includes a second interface to an environment perception unit. The environment perception unit is designed to determine data on conditions in the vehicle's environment in a signal path independent of the trajectory planning module.
[0018] An environmental perception unit (EPU) is a specialized component or system module designed to capture, process, and interpret relevant information about the vehicle's immediate and extended environment. This unit integrates various sensor and data processing technologies to create a comprehensive picture or model of the vehicle's surroundings, which is essential for navigation, decision-making, and real-time control tasks. The EPU can utilize a combination of different sensor types, such as radar, lidar, cameras, and ultrasound, to detect various environmental states, including static or dynamic states of objects, obstacles, road users, or road markings and traffic signs.
[0019] The second interface can also be a data or signal interface in the vehicle's electrical system. In a signal path independent of the trajectory planning module, this means that the data is evaluated via the second interface independently and redundantly to the trajectory planning module. For example, the second interface receives data from a second set of sensors that collect data independently of the sensors of the perception system to which the trajectory planning module can access. The signal path via which the second interface receives the data is a so-called safety path, in which data is evaluated, for example, only using procedural programming. The signal path in which the first interface is integrated is a so-called performance path, in which the data is evaluated, for example, using machine learning models.A signal path can be a software or hardware path encompassing signal transmission and signal evaluation.
[0020] Furthermore, the device includes a third interface to a vehicle control unit. This third interface can also be a data or signal interface in the vehicle's electrical system. The vehicle control unit, for example an electronic control unit, is designed to calculate steering angles and accelerations associated with a trajectory and to derive control signals, for example in the form of power levels, from these calculations and to provide the vehicle's actuators with these control signals for execution.
[0021] A vehicle control unit, also known as a vehicle motion control unit, is responsible for generating, processing, and implementing control signals, also called control commands, to influence the vehicle's movement. This unit translates inputs into physical actions. It interacts with various actuators and mechanical systems of the vehicle, such as the steering system, the braking system, the powertrain, and other relevant components, to control the vehicle's movement according to the control commands. This involves coordinating acceleration, steering, braking, and other vehicle dynamics functions.
[0022] Actuators include devices for longitudinal and / or lateral control of the vehicle. Actuators can be, for example, servo motors or valves.
[0023] The device is designed to verify or modify the trajectory calculated via the first interface by the trajectory planning module using the data obtained via the second interface from the independent signal path of the environment perception unit, such that the device obtains a safe trajectory that fulfills a predefined stopping speed profile, based on which a movement of the vehicle ends in a safe state.
[0024] Through verification or modification, it can be ensured that only safe trajectories, ending in a safe state, are forwarded to the vehicle control unit. The predefined stopping speed profile, for example, takes into account reaction time, maximum longitudinal deceleration, and maximum longitudinal jerk. The trajectory calculated by the trajectory planning module is also called the intended trajectory to distinguish it from the safe trajectory.
[0025] The device is further designed to provide the safe trajectory for execution via the third interface of the vehicle control unit.
[0026] The trajectory planning module and the independent signal path, which implements a safety layer, work collaboratively. This collaborative approach potentially generates safe trajectories based on the intended trajectories.
[0027] This enables safeguarding at the trajectory level.
[0028] The device can be an electronic circuit, for example a system on chip, comprising, for example, integrated circuits, application-specific integrated circuits, or other electronic components.
[0029] According to another aspect, the device is designed to verify the safe trajectory based on data from the trajectory planning module and the environment perception unit by evaluating speed exceedances, corridor deviations, collisions with static objects, or collisions with dynamic objects, and to make the trajectory verified as safe available for execution via the third interface of the vehicle control unit. The verification thus determines whether a potentially safe trajectory can be verified as safe.
[0030] According to another aspect, the device is designed to verify the safe trajectory based on data from the trajectory planning module and the environment perception unit by cascadingly evaluating speeding violations, corridor deviations, collisions with static objects, and collisions with dynamic objects. The trajectory verified as safe is then made available for execution via the third interface of the vehicle control unit. The safe trajectory is marked as unsafe as soon as any of the cascading evaluations is positive. This implements a fallback strategy in case the intended trajectory cannot be verified as safe. In this case, the current safe trajectory is re-verified, or, if necessary, the vehicle immediately comes to a standstill.
[0031] According to another aspect, the device comprises a storage unit or a fourth interface to the storage unit, wherein the storage unit stores the trajectories verified as safe and the device or the storage unit is configured to provide the last stored trajectory verified as safe to the vehicle control unit for execution.
[0032] Another aspect of the device is its ability to maintain a current state of the vehicle. This allows safe trajectories to be generated and verified cyclically.
[0033] According to another aspect, the invention provides a system for verifying a trajectory for the safe operation of a vehicle. The system comprises a trajectory planning module that calculates a trajectory based on received data concerning the vehicle's state and the state of its environment. The trajectory planning module can be the trajectory planning module described above.
[0034] Furthermore, the system includes an environment perception unit designed to determine data on conditions in the vehicle's environment via a signal path independent of the trajectory planning module. The previously described explanations regarding the environment perception unit and the independent signal path apply.
[0035] Furthermore, the system includes a vehicle control unit designed to calculate steering angles and accelerations associated with a trajectory, derive control signals from these, and provide these control signals to the vehicle's actuators for execution. The vehicle control unit can be the vehicle control unit described above.
[0036] Furthermore, the system comprises a device as described above, which is operatively connected to the trajectory planning module, the environment perception unit and the vehicle control unit, and is designed to check or modify the trajectory calculated by the trajectory planning module based on the data from the independent signal path of the environment perception unit in such a way that the device obtains a safe trajectory that fulfills a predefined stopping speed profile, based on which a movement of the vehicle ends in a safe state, and to provide the safe trajectory to the vehicle control unit for execution.
[0037] The invention thus provides a system with the advantages described above.
[0038] According to another aspect, the invention provides a method for verifying a trajectory for the safe operation of a vehicle.
[0039] In one step of the procedure, verification is initiated while the vehicle is stationary. An initial environmental perception unit detects static and dynamic objects in the vehicle's surroundings. The data obtained for the static objects is then checked for validity. If the data is invalid, the vehicle remains stationary. If the data is valid, a trajectory ending in a stationary state is stored in a memory unit. The verification process thus begins by checking the validity of the static data to be used during the process. If the static data is invalid, the verification process cannot be carried out, and the vehicle must remain stationary. If the static data is valid, the memory unit is initialized with a stationary trajectory.
[0040] In the context of technical and scientific applications, "data validity" refers to the extent to which data are accurate, reliable, and representative of the intended context or purpose. It is a measure of how well data reflect the actual properties, characteristics, or behaviors of the phenomenon or system under study. Data validity is crucial for the accuracy, credibility, and trustworthiness of analyses, conclusions, and decisions based on that data.
[0041] In a further step of the procedure, the validity of data concerning the vehicle's dynamic states and the data concerning dynamic objects is checked. In the case of invalid data regarding dynamic states and dynamic objects, the last trajectory stored in the memory unit of a vehicle control unit is made available for execution. In the case of valid data regarding dynamic states and dynamic objects, a device, as described above, obtains and verifies a safe trajectory.
[0042] In a further step of the process, the storage unit is updated with the trajectory verified as safe by the device. The trajectory verified as safe is then made available to the vehicle control unit for execution. If the device verifies a trajectory as unsafe, the last trajectory stored in the storage unit is made available to the vehicle control unit for execution.
[0043] The subsequent steps of the process following the initialization are carried out iteratively.
[0044] According to another aspect, if the trajectory currently stored in the storage unit is not verified as safe, the last trajectory stored as safely verified is modified in such a way that the vehicle's movement ends in a standstill by applying maximum possible braking.
[0045] The following example scenarios may occur: • If the trajectory planning module provides perfectly safe intended trajectories, a new safe trajectory based on the intended trajectory can be generated in each iteration and passed to the vehicle control unit. No intervention is required. The vehicle behaves as if there were no trajectory verification. • Checking the latest safe trajectory is typically necessary when the trajectory planning module provides intended trajectories that are unsafe, for example, based on verification safety specifications. To prevent the vehicle from executing such unsafe trajectories, the latest safe trajectory, which ends in a safe state, is executed. Possible scenarios: Intended trajectory results in a collision with static or dynamic objects. Intended trajectory results in leaving the lane. The intended trajectory is not feasible and cannot be followed by the vehicle due to its kinematic / dynamic limitations. • Changing the latest safe trajectory is typically necessary when the environment has unexpectedly changed such that even the latest safe trajectory, verified as safe in the last iteration, is no longer safe based on the verification safety specifications. Possible scenarios: A child jumps in front of the vehicle from an unobservable area, which was not considered in the previous iteration. Other road users disregard traffic rules.
[0046] Overview of the advantages arising from the invention: • Only trajectories that are / were demonstrably safe are executed. • Low complexity due to dedicated responsibilities: A potentially safe trajectory planning module plans a potentially safe trajectory; a verification pipeline verifies the potentially safe trajectory. • No complex algorithms or computer programs are required to generate a potentially safe trajectory. • The methodology can easily be extended by adding further verification steps without increasing complexity. • Planning "target" trajectories improves controller performance due to a continuous control error.
[0047] The invention is illustrated in the following figures. They show: Fig. 1 an embodiment of a device and a system disclosed herein, Fig. 2 an exemplary embodiment of a stopping speed profile, Fig. 3 an embodiment of an intended trajectory and a stopping speed profile of the Fig. 3 belonging safe trajectory and Fig. 4 an embodiment of a method disclosed herein.
[0048] In the figures, identical reference symbols denote identical or functionally similar reference parts. For clarity, not all reference parts are highlighted in the individual figures where necessary.
[0049] Fig. Figure 1 shows the system 20 with the device 10. The system 20 can be integrated into a vehicle F. The vehicle F can be an automated passenger vehicle that, for example, drives autonomously. In addition to the device 10, the system 20 comprises the trajectory planning module 1, the environment perception unit 2, and the vehicle control unit 3.
[0050] The device 10 receives a trajectory T calculated by the trajectory planning module 1 via a first interface 11 to the trajectory planning module 1.
[0051] The calculated trajectory T is the intended trajectory. The trajectory planning module 1 calculates the trajectory T based on the evaluation of signals or data from a first environmental perception unit 5, which are provided via a fifth interface 15. The fifth interface 15 can be a data or signal interface. The first environmental perception unit 5, the fifth interface 15, and the trajectory planning module form a first signal path, the so-called performance path.
[0052] The device receives signals or data from another environmental sensing unit 2 via a second interface 12. The environmental sensing unit 2 and the second interface 12 form a signal path independent of the aforementioned signal path, which is also called a safety path.
[0053] Furthermore, the device 10 and the trajectory planning module 1 each receive a current vehicle state Z, for example in each iteration cycle of the method disclosed herein.
[0054] Based on the data obtained, the device determines a safe trajectory TS as described above, which has a predefined stopping speed profile P, see Fig. 2, based on which a movement of the vehicle F ends in a safe state, is fulfilled.
[0055] A third interface 13 transmits the safe trajectory TS and the trajectory TS verified as safe to the vehicle control unit 3. The vehicle control unit 3 then transmits corresponding control signals S to actuators of the vehicle F.
[0056] In the illustrated embodiment, the device 10 comprises a fourth interface 14 to a storage unit 4. The storage unit 4 stores the trajectories TS that have been verified as safe. The device 10 or the storage unit 4 is configured to provide the vehicle control unit 3 with the last stored trajectory TS that has been verified as safe for execution.
[0057] Fig. Figure 2 shows an embodiment of a stopping speed profile for a safe trajectory TS. After a predetermined time in seconds, the vehicle F has a speed of 0 m / s, i.e., it comes to a standstill.
[0058] Fig. Figure 3 shows an embodiment of an intended trajectory T and a stopping speed profile of the Fig. 3 belonging to the safe trajectory TS. Fig. Figure 3 illustrates that only part of the intended trajectory T is a safe trajectory TS.
[0059] Fig. Figure 4 shows the procedure for verifying a trajectory for the safe operation of a vehicle F.
[0060] In step V1, a verification process is initiated while the vehicle F is stationary. A first environment perception unit 5 detects static and dynamic objects in the vicinity of the vehicle F. The data obtained for the static objects is checked for validity. If the data is invalid, the vehicle F remains stationary. If the data is valid, a trajectory ending in the vehicle F being stationary is stored in a memory unit (4).
[0061] In step V2, the validity of data relating to the dynamic states of the vehicle F and the data relating to the dynamic objects is checked. In the case of invalid data relating to dynamic states and dynamic objects, the last trajectory stored in the memory unit of a vehicle control unit 3 is made available for execution. In the case of valid data relating to dynamic states and dynamic objects, a device 10 disclosed herein obtains and verifies a safe trajectory TS.
[0062] In step V3, the storage unit is updated with the trajectory TS verified as safe by device 10. This trajectory TS is then made available to vehicle control unit 3 for execution. If device 10 verifies a trajectory as unsafe, the last stored trajectory in the storage unit is made available to vehicle control unit 3 for execution.
[0063] The subsequent steps of the procedure following initialization are performed iteratively. Reference sign 10 Device 20 System 1 Trajectory Planning Module 11 first interface 2. Environmental perception unit 12 second interface 3 Vehicle control unit 13 third interface 4 storage units 14 fourth interface 5 first environmental perception unit 15 fifth interface F vehicle T trajectory TS safe trajectory, trajectory verified as safe P Stop speed profile S control signal Z condition V1-V3 Process steps QUOTES INCLUDED IN THE DESCRIPTION
[0000] This list of documents cited by the applicant was automatically generated and is included solely for the reader's convenience. The list is not part of the German patent or utility model application. The DPMA accepts no liability for any errors or omissions. Cited patent literature
[0000] DE 10 2017 213 353 A1
[0003] DE 10 2019 119 656 A1
[0004] WO 23242186 A1
[0005] DE 10 2020 205 419 A1
[0006] Cited non-patent literature
[0000] In "The Safety Force Field," David Nistér et al., a general theory of safety at the obstacle avoidance level is revealed; see https: / / www.nvidia.com / content / dam / en-zz / Solutions / self-driving-cars / safety-force-field / the-safetyforce-field.pdf
[0008] “Provably Safe Motion Planning for Autonomous Vehicles Through Online Verification”, Christian Friedrich Pek reveals, see https: / / mediatum.ub.tum.de / doc / 1534013 / 1534013.pdf
[0009]
Claims
[1] Device (10) for verifying a trajectory for the safe operation of a vehicle (F), the device (10) comprising: • a first interface (11) to a trajectory planning module (1) which is executed to calculate a trajectory (T) based on received data on states of the vehicle (F) and on states in an environment of the vehicle (F); • a second interface (12) to an environment perception unit (2) which is designed to determine data on states in the environment of the vehicle (F) in a signal path independent of the trajectory planning module (1); • a third interface (13) to a vehicle control unit (3) configured to calculate steering angles and accelerations belonging to a trajectory and to derive control signals (S) from them and to provide the control signals to actuators of the vehicle (F) for execution; wherein the device (10) is configured • to check or modify the trajectory (T) calculated via the first interface (11) by the trajectory planning module (1) on the basis of the data obtained via the second interface (12) from the independent signal path of the environment perception unit (2) in such a way that the device (10) obtains a safe trajectory (TS) that fulfills a predefined stopping speed profile (P) based on which a movement of the vehicle (F) ends in a safe state; • to provide the safe trajectory (TS) for execution via the third interface (13) of the vehicle control unit (3). [2] Device (10) according to claim 1, configured to verify the safe trajectory (TS) based on the data of the trajectory planning module (1) and the data of the environment perception unit (2) by evaluating speed exceedances, evaluations of corridor deviations, evaluations of collisions with static objects or evaluations of collisions with dynamic objects and to provide the trajectory (TS) verified as safe via the third interface (13) of the vehicle control unit (3) for execution. [3] Device (10) according to claim 1, configured to verify the safe trajectory (TS) based on the data of the trajectory planning module (1) and the data of the environment perception unit (2) by cascading evaluation of speed exceedances, corridor deviations, collisions with static objects and collisions with dynamic objects, and to provide the trajectory (TS) verified as safe via the third interface (13) of the vehicle control unit (3) for execution, wherein the safe trajectory (TS) is verified as non-safe as soon as one of the cascading evaluations is positive. [4] Device (10) according to one of the preceding claims, comprising a storage unit (4) or a fourth interface (14) to the storage unit (4), wherein the storage unit (4) stores the trajectories (TS) verified as safe and the device (10) or the storage unit (4) is configured to provide the last stored trajectory (TS) verified as safe to the vehicle control unit (3) for execution. [5] Device (10) according to one of the preceding claims, designed to obtain a current state (Z) of the vehicle. [6] System (20) for verifying a trajectory for the safe operation of a vehicle (F), the system (20) comprising: • a trajectory planning module (1) that is executed to calculate a trajectory (T) based on received data on states of the vehicle (F) and on states in an environment of the vehicle (F); • an environment perception unit (2) designed to determine data on states in the environment of the vehicle (F) in a signal path independent of the trajectory planning module (1); • a vehicle control unit (3) designed to calculate steering angles and accelerations belonging to a trajectory and to derive control signals (S) from them and to provide the control signals (S) to actuators of the vehicle (F) for execution; • a device (10) according to one of the preceding claims, which is operatively connected to the trajectory planning module (1), the environment perception unit (2) and the vehicle control unit (3) and is designed to check or modify the trajectory (T) calculated by the trajectory planning module (1) on the basis of the data from the independent signal path of the environment perception unit (2) in such a way that the device (10) obtains a safe trajectory (TS) that fulfills a predefined stopping speed profile (P) based on which a movement of the vehicle (F) ends in a safe state and to provide the safe trajectory (TS) to the vehicle control unit (3) for execution. [7] Method for verifying a trajectory for the safe operation of a vehicle (F), the method comprising the steps: • Initializing a verification in a stationary state of the vehicle (F), wherein a first environment perception unit (5) detects static objects and dynamic objects in an environment of the vehicle (F) and checks the validity of the data obtained for the static objects, in the case of invalid data the vehicle (F) remains in the stationary state and in the case of valid data a trajectory ending in a stationary state of the vehicle (F) is stored in a storage unit (4) (V1); • Checking the validity of data on dynamic states of the vehicle (F) and data on the dynamic objects, wherein in the case of invalid data on dynamic states and dynamic objects the last stored trajectory of a vehicle control unit (3) is made available for execution and in the case of valid data on dynamic states and dynamic objects a device (10) according to one of claims 1 to 5 obtains and verifies a safe trajectory (TS) (V2); • the storage unit is updated with the trajectory (TS) verified as safe by the device (10) and this is made available to the vehicle control unit (3) for execution, wherein in the event that the device (10) verifies a trajectory as not safe, the trajectory last stored in the storage unit is made available to the vehicle control unit (3) for execution (V3); • where the subsequent steps of the procedure are performed iteratively. [8] Method according to claim 7, wherein in the event that the trajectory currently stored in the storage unit is not verified as safe, the trajectory last verified as safe (TS) is modified such that a movement of the vehicle (F) ends in a standstill by applying maximum possible braking.
Citation Information
Patent Citations
Verification of a planned trajectory of an automated motor vehicle
DE102017213353A1
Determining a validated trajectory for a motor vehicle
DE102019119656A1
Device and method for evaluating signals from environmental sensors for trajectory control and / or steering of an automated vehicle
DE102020205419A1
Method for performing a safety check of a target driving trajectory for an ego vehicle and method for controlling an ego vehicle
WO2023242186A1