System and procedure for controlling a motor vehicle for autonomous driving
The system efficiently integrates new vehicle functions in autonomous driving systems by dynamically monitoring safety parameters and adjusting control signals, addressing the challenge of costly verification processes and maintaining compliance with safety standards.
Patent Information
- Authority / Receiving Office
- DE · DE
- Patent Type
- Patents
- Current Assignee / Owner
- SCANIA CV AB
- Filing Date
- 2018-12-07
- Publication Date
- 2026-04-23
AI Technical Summary
Current autonomous driving systems face challenges in efficiently integrating new or updated vehicle functions while maintaining compliance with safety standards, leading to costly and time-consuming verification processes.
A system comprising a bank of control units, a safety unit, and a data storage device that monitors safety-relevant parameters and dynamically adjusts vehicle control to ensure compliance with safety standards and environmental conditions, allowing for seamless integration of new functions.
Enables efficient and straightforward updates to vehicle functions by automatically adapting to environmental and vehicle changes, ensuring safe operation and compliance with safety standards.
Smart Images

Figure 00000000_0000_ABST
Abstract
Description
Technical field
[0001] The invention relates generally to autonomous vehicles. In particular, the present invention relates to a system for controlling a motor vehicle for autonomous driving in accordance with a target path and a corresponding method. The invention also relates to a computer program and a non-volatile data carrier. background
[0002] Today, there is a clear trend toward fully autonomous vehicles. Naturally, safety aspects are paramount, as no human driver is involved. Functional safety standards, such as ISO 26262, require the diagnostic functionality necessary for safety. Generally, these standards place a significant additional burden on diagnosing and safely handling functional faults. Furthermore, verifying the verifiability of functional safety is a very complex process. Typically, this additional effort increases considerably with the growing number and complexity of functions. As a result, autonomous driving and its associated functions currently represent one of the greatest challenges in terms of complexity in the automotive sector.
[0003] US 2017 / 0277194A1 describes how operational control of a vehicle can be facilitated. A limited set of candidate trajectories of the vehicle is generated, originating from the vehicle's location at a specific time. The candidate trajectories are based on the vehicle's state and possible behaviors of the vehicle and its environment with respect to the vehicle's location and the specified time. A supposedly optimal trajectory is selected from the candidate trajectories based on costs associated with them. These costs include those associated with violations of the vehicle's operating rules. The selected supposedly optimal trajectory is then used to facilitate operational control of the vehicle.
[0004] EP 2 317 412 A1 discloses a safety management system for equipment configured to operate autonomously in a real-time environment. Deterministic and non-deterministic processors are provided to process incoming alarms and generate control signals in response. The non-deterministic processor can handle untrained, complex, and unpredictable situations by essentially providing open-ended operations that operate in large search spaces without a guaranteed solution. The deterministic processor monitors the behavior of the non-deterministic processor and validates its control signals against safety policies. The deterministic processor also provides an intelligent interface to the non-deterministic processor, receiving alarms only from the deterministic processor and ensuring time-critical delivery of responses.
[0005] US 2015 / 0057869A1 discloses devices, methods, and a storage medium related to computer-assisted or autonomous driving of vehicles. A computing device can receive multiple data points related to vehicles driving at different locations within a site; and, based on these, generate one or more site-specific guidelines for computer-assisted or autonomous driving of vehicles at that location.
[0006] DE 11 2013 001 449 T5 describes a processor-based control system for self-driving vehicles with a hierarchical control architecture on several levels. Each controlled direction of movement includes its own main controller, which monitors local actuators and coordinates their interaction. At higher levels, the driver's reliability is also evaluated and integrated into the control system.
[0007] WO 2015 / 076736 A1 discloses a system, a method, and a vehicle for realizing autonomous driving operation. The system has a multi-layered architecture. In a first layer, environmental conditions are detected and control signals are generated from them, which are then adapted for further processing in a second layer. A standardized computer interface transmits these signals across layers, so that the system can be used independently of the individual layers.
[0008] US 2017 / 0197626A1 describes a computer system programmed by software, firmware, hardware, or a combination thereof for specific driving functions. It detects a first vehicle in a lane, plans its path to join a queue, and then changes lanes to an adjacent lane. The vehicle is controlled based on the calculated path, taking into account vehicle-specific characteristics and the path of a second vehicle.
[0009] Therefore, there are known examples of solutions for controlling motor vehicles for autonomous driving in accordance with certain rules and guidelines, while handling complex and unpredictable traffic situations.
[0010] However, there is currently no solution in this area that allows for the convenient and efficient integration of new and / or updated vehicle functions while maintaining compliance with relevant safety standards. Typically, therefore, each new / updated function requires individual verification. This process is costly and very time-consuming. Summary
[0011] It is therefore an object of the present invention to make updating existing functions in an autonomous driving system more efficient and simpler. Furthermore, it is an object of the invention to simplify the process of adding new functions to such a system.
[0012] According to one aspect of the invention, these problems are solved by a system for controlling a motor vehicle for autonomous driving, the system comprising: a bank of control units, a safety unit, and a data storage device. The bank of control units, in turn, comprises a number of vehicle control units configured to generate target control signals that cause the motor vehicle to move autonomously in accordance with a target path. For example, a first vehicle control unit can implement a highway pilot, a second vehicle control unit can implement a traffic jam pilot, a third vehicle control unit can implement a vehicle towing pilot, and so on. The safety unit is configured to monitor a set of safety-related parameters that describe at least one state in which the motor vehicle is currently operating.The set of safety-relevant parameters is based, at least in part, on sensor signals received from the vehicle, which describe the vehicle's current state. The data storage contains a set of boundary conditions that the intended path must fulfill to be considered safe. The bank of control units is configured to read the set of boundary conditions from the data storage, and the bank of control units is further configured to control the vehicle to move in such a way that the intended path fulfills the boundary conditions.The safety unit is configured to receive the set of safety-relevant parameters and, in response, repeatedly generate at least one command configured to update the boundary conditions, with the aim of keeping the target path within limits defined by a current state of the set of safety-relevant parameters.
[0013] This system is advantageous because it automatically adapts the vehicle's control system not only to any changes in the dynamic environment around the vehicle, but also in response to any modifications to the vehicle itself (and its resulting altered capabilities). Consequently, updating existing vehicle functions and adding new functions to the vehicle become straightforward tasks.
[0014] According to one embodiment of this aspect of the invention, the set of safety-relevant parameters comprises: a collection of requirements and / or guidelines that must be met during operation of the motor vehicle, at least one signal indicating a current property of a physical environment surrounding the motor vehicle, and / or vehicle condition data representing a functional state of the motor vehicle. This allows the set of safety-relevant parameters to be efficiently influenced by different types of highly relevant factors.
[0015] According to a further embodiment of this aspect of the invention, the system further comprises a first data interface unit configured to receive and store at least one safety guideline describing an associated task-related rule to be followed during the operation of the motor vehicle. The at least one safety guideline may relate to: a minimum distance that the motor vehicle should maintain from a following vehicle, a speed limit that the motor vehicle should adhere to, and / or definitions of safe stopping points that the motor vehicle should be able to reach in the event of a malfunction. The first data interface unit is communicatively connected to the safety unit in order to provide the at least one safety guideline to the safety unit.Therefore, the motor vehicle can be controlled to follow any general behavioral rules in a straightforward manner.
[0016] According to yet another embodiment of this aspect of the invention, the system further comprises a second data interface unit configured to receive and store at least one regulatory requirement that must be met during operation of the motor vehicle. The second data interface unit is communicatively connected to the safety unit in order to provide the safety unit with the at least one regulatory requirement. Consequently, the motor vehicle can be conveniently controlled to comply with certain traffic rules.
[0017] According to a further embodiment of this aspect of the invention, the system comprises a risk assessment unit configured to dynamically evaluate the estimated risk of the motor vehicle colliding with any other road user and / or obstacle in the vicinity of the motor vehicle. The estimated risk is expressed by at least one signal, and the risk assessment unit is communicatively connected to the safety unit to provide this signal. As a result, a collision avoidance functionality is ingeniously implemented.
[0018] According to yet another embodiment of this aspect of the invention, the risk assessment unit is further configured to monitor the vehicle's environment in order to determine whether the vehicle is currently operating within a range of parameters within which it is designed to operate. Therefore, appropriate measures can be taken immediately if it is determined that the vehicle is outside this range.
[0019] According to a further embodiment of this aspect of the invention, the risk assessment unit is further configured to determine an estimated risk that the motor vehicle and / or any other road user in its vicinity will violate a traffic rule. The at least one signal also indicates this estimated risk. This allows the vehicle control, implemented by the vehicle control units, to be adjusted in such a way as to reduce the overall risk of traffic violations.
[0020] According to yet another embodiment of this aspect of the invention, the system comprises a system condition monitoring unit configured to monitor the received sensor signals and, based on these, derive vehicle condition data indicating any faults present in the functional state of the motor vehicle. The system condition monitoring unit is communicatively connected to the safety unit to provide the vehicle condition data to the safety unit. This ensures that fault detection and handling are also taken into account in the vehicle control system, which is implemented by the vehicle's control units.
[0021] According to yet another embodiment of this aspect of the invention, the safety unit is further configured to determine whether the set of safety-relevant parameters describes at least one state in which the motor vehicle is currently operated, such that the risk of the motor vehicle not being able to move autonomously in accordance with the intended path exceeds a fault risk threshold. The safety unit is configured, when this fault risk threshold is exceeded, to generate safety control signals designed to cause the motor vehicle to move autonomously in accordance with a safe path.
[0022] The safe path takes precedence over the target path, which is represented by the target control signals. In other words, the vehicle is configured to ignore any received target control signals if the safe control signals are present. Consequently, safe vehicle handling is ensured even in emergency situations.
[0023] Alternatively or additionally, the safety unit can be configured to generate a control signal indicating whether the failure risk threshold has been exceeded. Furthermore, the system includes a control switch connected to the bank of control units. The control switch is connected to both the bank of control units and the safety unit, and the safety switch is configured to: receive the control signal; receive the target control signals or any safety control signals; and, in response to the control signals, forward either the target control signals or the safety control signals to the vehicle. In such a case, the vehicle itself does not need to take any action to ensure that a safe path is preferred over the target path.
[0024] According to further embodiments of this aspect of the invention, either each of the vehicle control units is configured to generate a set of target control signals designed to cause the vehicle to move autonomously in accordance with a corresponding target path; or two or more of the vehicle control units are configured to generate a common set of target control signals designed to cause the vehicle to move autonomously in accordance with the target path. This results in a high degree of freedom regarding the implementation of the system.
[0025] According to yet another embodiment of this aspect of the invention, the system comprises a platform interface configured to receive sensor signals from the motor vehicle and to send target control signals to the motor vehicle. Therefore, communication between the system and the motor vehicle can be designed to be efficient and flexible.
[0026] According to a further aspect of the invention, the above-mentioned problems are solved by a method for controlling a motor vehicle for autonomous driving. The method comprises: generating, by means of a bank of control units, target control signals configured to cause the motor vehicle to move autonomously in accordance with a target path; monitoring, by means of a safety unit, a set of safety-related parameters that describe at least one state in which the motor vehicle is currently operating; receiving sensor signals from the motor vehicle, wherein the sensor signals describe a current state of the motor vehicle and at least partially form a basis for the set of safety-related parameters; and sending the target control signals to the motor vehicle.Storing, in a data storage device, a set of boundary conditions that the target path must fulfill to be considered safe; reading, from the data storage device, the set of boundary conditions into the bank of control units; generating, by the bank of control units, the target control signals such that the vehicle is controlled to move in such a way that the target path fulfills the boundary conditions; maintaining, in the safety unit, the set of safety-related parameters; and in response, repeatedly generating at least one command configured to update the boundary conditions, with the aim of keeping the target path within limits specified by a current state of the set of safety-related parameters.
[0027] The advantages of this method and its preferred embodiments will become apparent from the above description with reference to the proposed system.
[0028] According to another aspect of the invention, the problems are solved by a computer program comprising instructions which, when executed in at least one processor, cause the at least one processor to execute the method described above.
[0029] According to another aspect of the invention, the problems are solved by a non-volatile data carrier containing such a computer program.
[0030] Further advantages, beneficial features and applications of the present invention will become apparent from the following description and the dependent claims. Brief description of the drawings
[0031] The invention will now be described in more detail by means of preferred embodiments, which are disclosed as examples and with reference to the accompanying drawings. Fig. 1 schematically represents systems according to embodiments of the invention; Fig. Figure 2 schematically shows a system according to a further embodiment of the invention; and Fig. Figure 3 illustrates the general procedure according to the invention by means of a flowchart. Detailed description
[0032] With reference to Fig. 1. We will describe a system according to an embodiment of the invention for controlling a motor vehicle MV for autonomous driving. The system comprises a bank of control units 110, a safety unit 120, and a data storage device 140.
[0033] The bank of control units 110 in turn includes a number of car control units ACU1, ..., ACUn, which are set up to generate target control signals NCS, which are set up to cause the motor vehicle MV to move autonomously in accordance with a target path, i.e. along a specific trajectory on the ground.
[0034] Either each of the vehicle control units ACU1, ..., ACUn is configured to generate a set of target control signals NCS, wherein the set of target control signals NCS is configured to cause the vehicle MV to move autonomously in accordance with a target path; or two or more of the vehicle control units ACU1, ..., ACUn are configured to generate a common set of target control signals NCS, wherein the common set of target control signals NCS is configured to cause the vehicle MV to move autonomously in accordance with the target path. For example, one of the vehicle control units may be configured to control the vehicle MV in a longitudinal direction, whereas another vehicle control unit may be configured to control the vehicle MV in a transverse direction.Alternatively, a first vehicle control unit (ACU1) can implement a highway pilot, a second ACU can implement a traffic jam pilot, a third ACU can implement a vehicle towing pilot, and so on, up to an nth ACU, which, for example, might be configured to operate the vehicle in a mining environment. While the ACU1, ..., ACU1 units can certainly be implemented in hardware, it is advantageous for them to be implemented in software. In such a case, either a specific software module can exist for each ACU in the bank of control units 110, or the entire bank of control units 110 can be represented by a common software application.
[0035] The safety unit 120 is configured to monitor a set of safety-relevant parameters P, R, S j, H to monitor, which describe at least one state in which the motor vehicle MV is currently operated. The set of safety-relevant parameters P, R, S j H is based at least partially on sensor signals SS received from the motor vehicle MV. According to one embodiment of the invention, the system comprises a system condition monitoring unit 150, which is configured to monitor the received sensor signals SS and, based thereon, to derive vehicle condition data H as part of the set of safety-relevant parameters.
[0036] The sensor signals SS describe a current state of the motor vehicle MV, and these signals can be received by the motor vehicle MV via a platform interface 130. Preferably, such a platform interface 130 is bidirectional and therefore also configured to send the target control signals NCS to the motor vehicle MV. However, according to the invention, even when the platform interface 130 is included in this configuration, one or more sensor signals SS can be received via alternative channels, and / or one or more of the target control signals NCS can be provided to the motor vehicle MV in a manner other than via the platform interface 130.
[0037] Data store 140 contains the set of boundary conditions {bc} that the target path must meet to be considered safe, for example as specified by a safety standard, such as ISO 26262.
[0038] The bank of control units 110 is configured to read the set of boundary conditions {bc} from the data storage 140. This process can be implemented either as a pull function triggered by the bank of control units 110 or as a push function initiated by the data storage 140. In either case, the bank of control units 110 is configured to control the vehicle MV to move in such a way that the target path satisfies the boundary conditions {bc}. As described below, the boundary conditions {bc} are dynamic and depend on the set of safety-related parameters P, R, S. j and H off.
[0039] More precisely, the safety unit 120 is designed to monitor the set of safety-relevant parameters P, R, S jand obtain H. The safety unit 120 is configured to repeatedly generate at least one {cmd} command in response, which is configured to update the boundary conditions {bc}, aiming to keep the target path within limits defined by a current state of the set of safety-related parameters P, R, S j , H are given.
[0040] According to one embodiment of the invention, the set of safety-relevant parameters can include: a collection of requirements R and / or guidelines P that must be met during operation of the motor vehicle MV; one or more signals S j, which specifies a current property of a physical environment around the motor vehicle MV; and / or vehicle condition data H, which represents a functional state of the motor vehicle MV. As mentioned above, the vehicle condition data H can be derived from the system condition monitoring unit 150, and the vehicle condition data H can specify any faults present in the functional state of the motor vehicle MV. The system condition monitoring unit 150 is communicatively connected to the safety unit 120 to provide the vehicle condition data H to the safety unit 120.
[0041] According to one embodiment of the invention, the system comprises a first data interface unit 163, which is configured to receive and store at least one safety guideline P that describes an associated task-related rule to be followed during the operation of the motor vehicle MV. This allows the automatic control of the motor vehicle MC to be conveniently adapted to any changes in the safety guidelines P by simply updating the first data interface unit 163.
[0042] For example, the safety guideline P is specified at a time of operation and may concern a minimum distance that the motor vehicle (MV) must maintain from a following vehicle, a speed limit that the motor vehicle (MV) must adhere to, and / or definitions of safe stopping points that the motor vehicle (MV) should be able to reach in the event of a failure in the motor vehicle (MV). The at least one safety guideline P may further provide rules, determined at a time of design, concerning classes of safe stopping points that must be reachable in the event of failure in the motor vehicle (MV). Additionally, the at least one safety guideline P may provide a minimum number of preferred stopping points of each desired class that should be available to the motor vehicle (MV) on every road segment.
[0043] The first data interface unit 163 is communicatively connected to the security unit 120 in order to provide at least one security policy P for the security unit 120 and therefore enable the security unit 120 to generate at least one command {cmd} based on the at least one security policy P.
[0044] According to one embodiment of the invention, the system comprises a second data interface unit 165, which is configured to receive and store at least one regulatory requirement R that is to be fulfilled during operation of the motor vehicle MV. Examples of regulatory requirements R are market-specific regulations that are specified at the time of use and relate, for example, to traffic rules (e.g., left-hand / right-hand traffic, local traffic rules, and various traffic signs).
[0045] Analogous to the first data interface unit 163, the second data interface unit 165 is communicatively connected to the security unit 120 in order to provide the at least one regulatory requirement R for the security unit 120 and therefore enable the security unit 120 to generate the at least one command {cmd} based on the at least one regulatory requirement R.
[0046] According to one embodiment of the invention, the system comprises a risk assessment unit 167, which is configured to dynamically assess the estimated risk that the motor vehicle MV will collide with any other road user and / or obstacle located near the motor vehicle MV. The dynamic assessment is based on a number of sensor signals containing information about the environment surrounding the motor vehicle MV. However, sensor signals from within the motor vehicle MV can also be used by the risk assessment unit 167. Consequently, the risk assessment unit 167 can receive one or more of the sensor signals SS (not shown).
[0047] An estimated risk that the motor vehicle MV will collide with a specific road user may include an intent estimate for that road user as well as a current expected path associated with that road user. The corresponding estimated risks that the motor vehicle MV will collide with a specific road user and / or obstacle are indicated by at least one signal S. j This is expressed as being forwarded via a communication link to the risk assessment unit 167. Therefore, the signal(s) S j form a basis for at least one command {cmd}.
[0048] Additionally, it is preferred if the risk assessment unit 167 is further equipped to monitor the environment of the motor vehicle MV in order to determine whether the motor vehicle MV is currently operating within a range of parameters under which it is designed to operate.
[0049] Furthermore, the risk assessment unit 167 can be configured to determine an estimated risk that the motor vehicle MV and / or any other road user in its vicinity will violate a traffic rule. The assessment may include monitoring lane markings, and if no sufficiently clear lane markings are detected, this will at least give a signal S. j this is expressed in the form of an estimated risk of a traffic violation.
[0050] According to one embodiment of the invention, the safety unit 120 is further configured to determine whether the set of safety-relevant parameters P, R, S j , H describes one or more states in which the motor vehicle MV is currently operated, wherein the state(s) is / are such that the risk that the motor vehicle MV cannot move autonomously in accordance with the target path exceeds a failure risk threshold.
[0051] If the failure risk threshold is exceeded, the safety unit 120 is configured to generate safety control signals (SCS) that cause the vehicle (MV) to move autonomously along a safe path. The safe path represents an alternative to the target path, and the safe path should be followed instead of the target path calculated by the bank of control units 110. In other words, the safe path takes precedence over the target path, which is represented by the target control signals (NCS).
[0052] According to one embodiment, which is in Fig. As shown in Figure 1, the motor vehicle MV itself achieves this priority by being configured to ignore any received target control signals NCS if the safety control signals SCS are received, for example via the platform interface 130, as shown in Figure 1. Fig. Figure 1 is shown. Consequently, safe vehicle handling is guaranteed even in emergencies.
[0053] Fig. Figure 2 schematically shows a system according to a further embodiment of the invention. Here, all units, signals, commands, and parameters, which also appear in [the original text], are denoted by . Fig. 1. The same units, signals, commands, and parameters are present, as mentioned above with reference to Fig. 1 were described.
[0054] In the Fig. In the illustrated system 2, the safety unit 120 is configured to generate a control signal Ctrl, which indicates whether the fault risk threshold has been exceeded or not.
[0055] The system also includes a control switch 210, which is arranged in communication link with the bank of control units 110 and the safety unit 120. The control switch 210 is configured to: receive the control signal Ctrl; receive the target control signals NCS or any safety control signals SCS.
[0056] Control switch 210 is configured to forward either the target control signals NCS or the safety control signals SCS to the vehicle MV. Specifically, when safety unit 120 generates the safety control signals SCS, it also generates the control signals Ctrl in such a way that, upon receiving these signals at control switch 210, control switch 210 prevents the target control signals NCS from being forwarded to the vehicle MV. Instead, the control signal Ctrl forwards the safety control signals SCS to the vehicle MV. This reduces the demands on the vehicle MV, as it does not have to choose between the target control signals NCS and the safety control signals SCS; and, analogous to the above, ensures safe handling of the vehicle even in emergencies.
[0057] Analogous to the automotive control units ACU1, ..., ACUn, the safety unit 120, the system status monitoring unit 150, the first data interface 163, the second data interface 165, the risk assessment unit 167, and / or the control switch 210 can be implemented partially or completely as software. Such software can, in turn, be installed to run on one or more processors. Furthermore, a single software application can implement two or more of the aforementioned units and interfaces.
[0058] For example, the security unit 120 can comprise a processing unit with processing means containing at least one processor, such as one or more general-purpose processors. Furthermore, the processing unit is preferably communicatively connected to a data carrier 125 in the form of a computer-readable medium, such as random access memory (RAM), flash memory, or the like. The data carrier 125 contains computer-executable instructions, i.e., a computer program 127, for causing the processing unit and the other units of the system to operate in accordance with the embodiments of the invention as described herein, when the computer-executable instructions are executed on the at least one processor of the processing unit.
[0059] To summarize this and with reference to the flowchart in Fig. 3. We will now describe the general method according to the invention for controlling a motor vehicle for autonomous driving.
[0060] In a first step, sensor signals are received from the motor vehicle. The sensor signals describe the current state of the motor vehicle.
[0061] Then, in step 320, a set of safety-relevant boundary conditions is generated, at least partially, based on the sensor signals. This set of safety-relevant boundary conditions describes one or more states in which the motor vehicle is currently operated.
[0062] Subsequently, step 330 monitors the safety-relevant parameters; and in a following step 340, boundary conditions are read from the data store into a bank of control units. In the first iteration of the process, the data store contains default boundary conditions. In subsequent iterations, the boundary conditions will have been updated by step 370, described below.
[0063] In step 350, following step 340, target control signals are generated by the bank of control units based on the boundary conditions. These target control signals are designed to cause the vehicle to move autonomously along a target path.
[0064] Then, in a step of 360, the target control signals are sent to the motor vehicle to control the motor vehicle to move in accordance with the target path.
[0065] In a subsequent step 370, at least one instruction is generated to update the boundary conditions, aiming to keep the target path within limits defined by the current state of the set of safety-relevant parameters. The updated boundary conditions are stored in the data memory, and the process then returns to step 310.
[0066] Although the method according to the invention is carried out in a general sequential order, as described in Fig. As shown in Figure 3, it should of course be mentioned that a subsequent step of the process can be initiated before a preceding step is completed. In fact, essentially all steps are active throughout. For example, sensor signals are preferably obtained in step 310 with respect to a specific time interval, while in step 370 the boundary conditions are updated in connection with a set of safety-related parameters that refer to a time interval prior to the specified time interval, and so on.
[0067] All of the procedural steps, as well as any subsequent steps relating to Fig.The devices described in section 3 above can be controlled by means of at least one programmed processor. Furthermore, the invention therefore also extends to computer programs, in particular computer programs on or in a carrier, which are configured to implement the invention practically, although the embodiments of the invention described above with reference to the drawings comprise a processor and operations that are carried out in at least one processor. The program can be in the form of source code, object code, code between source code and object code such as partially compiled form, or in any other form suitable for use in implementing the method according to the invention. The program can be either part of an operating system or a separate application. The carrier can be any unit or device suitable for containing the program.For example, the carrier can be a storage medium such as flash memory, a ROM (Read Only Memory), for example a DVD (Digital Video / Versatile Disc), a CD (Compact Disc), or a semiconductor ROM, an EPROM (Erasable Programmable Read-Only Memory), an EEPROM (Electrically Erasable Programmable Read-Only Memory), or a magnetic recording medium, such as a floppy disk or a hard disk. Furthermore, the carrier can be a transmittable medium, such as an electrical or optical signal that can be transmitted via an electrical or optical cable, by radio, or by other means. If the program is implemented in a signal that can be transmitted directly via a cable or other means, the carrier can be formed by such a cable, device, or means.Alternatively, the carrier can be an integrated circuit in which the program is embedded, the integrated circuit being configured to perform the relevant operations or to be used in performing them.
[0068] When the term "include / comprehensive" is used in this description, it should be understood to indicate the presence of the specified characteristics, quantities, steps, or components. However, the term should not exclude the presence or addition of one or more further characteristics, quantities, steps, or components, or groups thereof.
[0069] The invention is not limited to the embodiments described in the figures, but can be freely varied within the scope of the claims.
Claims
[1] System for controlling a motor vehicle (MV) for autonomous driving, the system comprising: a bank of control units (110) comprising a number of vehicle control units (ACU1, ..., ACUn) configured to generate target control signals (NCS) configured to cause the motor vehicle (MV) to move autonomously in accordance with a target path; and a safety unit (120) configured to measure a set of safety-related parameters (P, R, S) j , H) to monitor, which describe at least one state in which the motor vehicle (MV) is currently operated, wherein the set of safety-relevant parameters (P, R, S) j , H) is based at least partially on sensor signals (SS) received from the motor vehicle, and wherein the sensor signals (SS) describe a present state of the motor vehicle (MV), characterized by , that the system further comprises a data storage (140) which includes a set of boundary conditions ({bc}) that the target path must satisfy in order to be considered safe; the bank of control units (110) is configured to read the set of boundary conditions ({bc}) from the data storage (140), and the bank of control units (110) is configured to control the motor vehicle (MV) to move in such a way that the target path satisfies the boundary conditions ({bc}); and the safety unit (120) is configured to monitor the set of safety-related parameters (P, R, S) j , H) and in response to this, repeatedly generate at least one command ({cmd}) configured to update the boundary conditions ({bc}), aiming to keep the desired path within limits defined by a current state of the set of safety-related parameters (P, R, S). j , H) are given. [2] System according to claim 1, wherein the set of safety-related parameters comprises at least one of the following: a collection of requirements (R) and / or guidelines (P) that must be met during operation of the motor vehicle (MV), at least one signal (S j ), which indicates a present property of a physical environment around the motor vehicle, and Vehicle condition data (H) that represent a functional state of the motor vehicle. [3] System according to claim 2, further comprising a first data interface unit (163) configured to receive and store at least one safety policy (P) describing an associated task-related rule to be followed during the operation of the motor vehicle (MV), wherein the at least one safety policy (P) relates to at least one of the following: a minimum distance that the motor vehicle (MV) should maintain to a following vehicle, a speed limit that the motor vehicle (MV) is supposed to adhere to, and Definitions of safe stopping points that the motor vehicle (MV) should be able to reach in the event of a fault in the motor vehicle (MV), wherein the first data interface unit (163) is connected to the security unit (120) in order to provide at least one security policy (P) for the security unit (120). [4] System according to claim 2 or 3, further comprising a second data interface unit (165) configured to receive and store at least one regulatory requirement (R) to be met during operation of the motor vehicle (MV), wherein the second data interface unit (165) is communicatively connected to the safety unit (120) to provide the at least one regulatory requirement (R) to the safety unit (120). [5] System according to any one of claims 2 to 4, further comprising a risk assessment unit (167) configured to dynamically assess each estimated risk that the motor vehicle (MV) will collide with any other road user and / or obstacle located near the motor vehicle (MV), wherein the respective estimated risk is indicated by at least one signal (S j) is expressed, and wherein the risk assessment unit (167) is communicatively connected to the safety unit (120) to receive at least one signal (S j ) to provide for the security unit (120). [6] System according to claim 5, wherein the risk assessment unit (167) is further configured to monitor an environment of the motor vehicle (MV) in order to determine whether the motor vehicle (MV) is currently operating within a range of parameters under which it is designed to operate. [7] System according to one of claims 5 or 6, wherein the risk assessment unit (167) is further configured to determine an estimated risk that the motor vehicle (MV) and / or any other road user in its vicinity will violate a traffic rule, and wherein the at least one signal (S j ) furthermore, this estimated risk is stated. [8] System according to any one of claims 2 to 7, further comprising a system condition monitoring unit (150) which is configured to monitor the received sensor signals and, based thereon, to derive vehicle condition data (H) indicating any faults contained in the functional state of the motor vehicle (MV), wherein the safety unit (120) is communicatively connected to the safety unit (120) in order to provide the vehicle condition data (H) to the safety unit (120). [9] System according to one of the preceding claims, wherein the safety unit (120) is further configured to: to determine whether the set of safety-relevant parameters (P, R, S) j, H) describes at least one state in which the motor vehicle (MV) is currently operated, wherein the at least one state is such that the risk that the motor vehicle (MV) cannot be moved autonomously in accordance with the intended path exceeds a failure risk threshold, and furthermore, when the failure risk threshold is exceeded, To generate safety control signals (SCS) designed to cause the motor vehicle (MV) to move autonomously in accordance with a safe path, the safe path taking precedence over the desired path represented by the desired control signals (NCS). [10] System according to claim 9, wherein the safety unit (120) is configured to generate a control signal (Ctrl) indicating whether the fault risk threshold has been exceeded or not, and wherein the system further comprises a control switch (210) which is arranged in communication link with the bank of control units (110) and the security unit (120), wherein the control switch (210) is configured to: to receive the control signal (Ctrl), to obtain the target control signals (NCS) or any safety control signals (SCS), and In response to the control signals (Ctrl), either the target control signals (NCS) or the safety control signals (SCS) are forwarded to the motor vehicle (MV). [11] System according to any of the preceding claims, wherein each of the vehicle control units (ACU1, ..., ACUn) is configured to generate a set of target control signals (NCS), wherein the set of target control signals (NCS) is configured to cause the motor vehicle (MV) to move autonomously in accordance with a corresponding target path. [12] System according to any of the preceding claims, wherein two or more of the vehicle control units (ACU1, ..., ACUn) are configured to generate a common set of target control signals (NCS), wherein the common set of target control signals (NCS) is configured to cause the motor vehicle (MV) to move autonomously in accordance with the target path. [13] System according to any of the preceding claims, further comprising a platform interface (130) configured to: to receive the sensor signals (SS) from the motor vehicle (MV); and to send the target control signals (NCS) to the motor vehicle (MV). [14] Method for controlling a motor vehicle (MV) for autonomous driving, the method comprising: Generating, by means of a bank of control units (110), target control signals (NCS) configured to cause the motor vehicle (MV) to move autonomously in accordance with a target path; Monitoring, by a safety unit (120), of a set of safety-related parameters (P, R, S) j , H), which describe at least one state in which the motor vehicle (MV) is currently being operated; Receiving sensor signals (SS) from the motor vehicle, wherein the sensor signals (SS) describe a current state of the motor vehicle (MV) and at least partially form a basis for the set of safety-relevant parameters (P, R, S). j , H) form; and sending the target control signals (NCS) to the motor vehicle (MV), characterized by Store, in a data store (140), a set of boundary conditions ({bc}) that the target path should satisfy in order to be considered safe; Reading from the data storage (140) of the set of boundary conditions ({bc}) into the bank of control units (110); Generating, by means of a bank of control units (110), the target control signals (NCS) such that the motor vehicle (MV) is controlled to move in such a way that the target path satisfies the boundary conditions ({bc}); Received, in the safety unit (120), the set of safety-related parameters (P, R, S) j , H), and in response to this Repeated generation of at least one command ({cmd}) configured to update the boundary conditions ({bc}), aiming to keep the intended path within limits defined by a current state of the set of safety-related parameters (P, R, S). j , H) are given. [15] Method according to claim 14, wherein the set of safety-related parameters includes at least one of the following: a collection of requirements (R) and / or guidelines (P) that must be met during operation of the motor vehicle (MV), at least one signal (S j ), which indicates a present property of a physical environment around the motor vehicle, and Vehicle condition data (H) that represent a functional state of the motor vehicle. [16] The method of claim 15, further comprising: Receiving and storing, in a data interface unit (163), at least one safety policy (P) describing an associated task-related rule to be followed during the operation of the motor vehicle (MV), wherein the at least one safety policy (P) relates to at least one of the following: a minimum distance that the motor vehicle (MV) should maintain to a following vehicle, a speed limit that the motor vehicle (MV) is supposed to adhere to, and Definitions of safe stopping points that the motor vehicle (MV) should be able to reach in the event of a fault in the motor vehicle (MV), wherein the first data interface unit (163) is connected to the security unit (120) in order to provide at least one security policy (P) for the security unit (120). [17] Method according to one of claims 15 or 16, further comprising: Receiving and storing, in a second data interface unit (165), a regulatory requirement (R) that is to be fulfilled during operation of the motor vehicle (MV), wherein the second data interface unit (165) is communicatively connected to the safety unit (120) in order to provide the at least one regulatory requirement (R) for the safety unit (120). [18] Method according to any one of claims 15 to 17, further comprising: dynamic assessment, in a risk assessment unit (167), of each estimated risk that the motor vehicle (MV) will collide with any other road user and / or obstacle that is in the vicinity of the motor vehicle (MV), wherein the respective estimated risk is indicated by at least one signal (S j ) is expressed, and wherein the risk assessment unit (167) is communicatively connected to the safety unit (120) to receive at least one signal (S j ) to provide for the security unit (120). [19] The method of claim 18, further comprising: Monitor, by the risk assessment unit (167), an environment of the motor vehicle (MV) to determine whether the motor vehicle (MV) is currently operating within a range of parameters under which it is designed to operate. [20] Method according to one of claims 18 or 19, further comprising: Determine, by means of the risk assessment unit (167), an estimated risk that the motor vehicle (MV) and / or any other road user in its vicinity will violate a traffic rule, and wherein at least one signal (S) j ) furthermore, this estimated risk is stated. [21] Method according to any one of claims 15 to 20, further comprising: Receiving the sensor signals (SS) in a system status monitoring unit (150) for monitoring, Deriving, based on the sensor signals (SS), vehicle condition data (H) that indicate any faults contained in the functional state of the motor vehicle (MV), and Forwarding the vehicle status data (H) from the system status monitoring unit (15) to the safety unit (120). [22] Method according to any one of claims 14 to 21, further comprising: Determine, in the safety unit (120), whether the set of safety-relevant parameters (P, R, S) j , H) describes at least one state in which the motor vehicle (MV) is currently operated, wherein the at least one state is such that the risk that the motor vehicle (MV) cannot be moved autonomously in accordance with the intended path exceeds a failure risk threshold, and furthermore, when the failure risk threshold is exceeded, Generating, in the safety unit (120), safety control signals (SCS) configured to cause the motor vehicle (MV) to move autonomously in accordance with a safe path, the safe path taking precedence over the target path represented by the target control signals (NCS). [23] The method of claim 22, further comprising: Generate, in the safety unit (120), a control signal (Ctrl) that indicates whether the fault risk threshold has been exceeded or not, and specify, by means of a control switch (210) and in response to the control signal (Ctrl), that either the target control signals (NCS) or any safety control signals (SCS) are forwarded to the motor vehicle (MV) through the platform interface (130). [24] Computer program (127) comprising instructions which, when executed in at least one processor, cause the at least one processor to execute a method according to any one of claims 14 to 23. [25] Non-volatile data carrier (125) containing a computer program according to claim 24.
Citation Information
Patent Citations
Multi-level vehicle integrity and quality control mechanism
DE112013001449T5
Safety management system
EP2317412A1
Locality adapted computerized assisted or autonomous driving of vehicles
US20150057869A1
Management of autonomous vehicle lanes
US20170197626A1
Facilitating Vehicle Driving and Self-Driving
US20170277194A1