Method for evaluating redundant signals

EP4619833A1Pending Publication Date: 2025-09-24ROBERT BOSCH GMBH
View PDF 0 Cites 0 Cited by

Patent Information

Application Number
EP2023790346
Authority / Receiving Office
EP · EP
Patent Type
Applications
Current Assignee / Owner
Priority Date
2022-11-14
Filing Date
2023-10-18
Publication Date
2025-09-24

AI Technical Summary

Technical Problem

Current redundancy monitoring concepts in inertial measurement units for motor vehicles, particularly in autonomous driving applications, fail to effectively detect errors in redundant signals and are not adaptable to varying vehicle dynamics and driving scenarios, leading to suboptimal performance and static threshold settings.

Method used

A method that dynamically evaluates redundant signals by comparing them with threshold values determined through statistical analysis and consideration of vehicle dynamics and noise properties, using random walk estimation to define maximum permitted signal deviations, allowing for adaptive parameter settings based on the current driving situation.

Benefits of technology

Enhances the detection of errors in redundant signals, improving the reliability of safety-critical decisions in autonomous driving scenarios by dynamically adjusting thresholds to account for vehicle dynamics and noise, thereby improving the overall performance of redundancy monitoring.

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure 1.1
    Figure 1.1
Patent Text Reader

Abstract

The invention relates to a method for evaluating redundant signals in a motor vehicle, in which method a first signal is compared with a second signal, and a result of the comparison is compared with a threshold value, the threshold value being determined depending on a statistical evaluation of the signals and depending on information concerning a driving situation of the motor vehicle.
Need to check novelty before this filing date? Find Prior Art

Description

[0001] Description

[0002] title

[0003] Method for evaluating redundant signals

[0004] The invention relates to a method for evaluating redundant signals and an arrangement for carrying out the method.

[0005] State of the art

[0006] During operation, a large number of signals are recorded in motor vehicles, each of which carries information about a technical quantity. This information is evaluated in the vehicle. To ensure safe operation, it is necessary to check whether the recorded signals are correct or faulty. One way to do this is to use or record redundant signals. This means that a technical quantity is recorded multiple times, i.e. there are at least two signals that represent this technical quantity. By comparing the two signals in particular, they can then be checked for plausibility. This also makes it possible to detect errors that occurred during the recording and / or forwarding of these signals.

[0007] One possible application of the method presented here could be in conjunction with an inertial measurement unit. An inertial measurement unit is a spatial arrangement of multiple inertial sensors, such as acceleration sensors and yaw rate sensors. Such a measurement unit is used, for example, as a sensory measurement unit in an inertial navigation system.

[0008] An inertial measurement unit can measure six possible kinematic degrees of freedom. Three orthogonally positioned acceleration sensors are used to measure translational movements, and three orthogonally mounted angular rate sensors are used to measure rotational or circular movements. In this case, the inertial measurement unit provides three linear acceleration values ​​for the translational movements and three angular velocities or rates for the angular rates.

[0009] If at least two signals are recorded for a given value, these are referred to as redundant signals. Concepts for handling these redundant signals, particularly to check their plausibility—i.e., to detect potentially faulty signals—are referred to as redundancy concepts.

[0010] A currently used redundancy concept implemented in inertial measurement units is called a correlation monitor and is based on comparing measurements of the same physical quantity, such as acceleration or angular rate, from different sources. For a given pair of redundant signals, two parameters are calculated: delta and gradient. Delta is the difference between the current samples. Gradient is the difference between the signal's rate of change, i.e., the discrete derivative. These parameters are calculated for each signal using the current sample and the previous sample.

[0011] Once delta and gradient have been calculated, they are compared to thresholds. If these thresholds are exceeded, a counter is incremented. The conditions for incrementing this counter can be combined in three ways: delta only, gradient only, delta, and gradient. If both conditions are used to increment the counter, they are combined, or linked, using a logical OR. This means that any condition that is met causes the counter to be incremented. However, if both conditions are met, the counter is incremented only once, not twice. The signals are assumed to be correlated until the counter reaches a threshold. Once this threshold is reached, the counter value is set to a hold value higher than the threshold. A correlation flag is also set.This means that the signals are marked as uncorrelated. The counter value is held at the hold value as long as the incrementing conditions are met. When these conditions are no longer met, the counter begins to decrement until the value reaches zero, and only then is the correlation flag removed or canceled. The signals are thus marked as correlated again.

[0012] This familiar process is performed using the most recently measured values ​​and the values ​​immediately before them. In this sense, such a procedure is virtually instantaneous. Thus, there is no memory or storage involved in this comparison itself. However, this is currently provided for the correlation monitor by using counters to debounce the flags.

[0013] The adjustable parameters of this implementation for a redundant signal pair are listed below:

[0014] Threshold for Delta,

[0015] Threshold for the gradient,

[0016] Conditions for incrementing, delta only, gradient only or both, counter limit,

[0017] Counter hold value.

[0018] Disclosure of the invention

[0019] Against this background, a method having the features of claim 1 and an arrangement according to claim 11 are presented. Embodiments emerge from the dependent claims and the description. The presented method serves to evaluate redundant signals, such as those detected, for example, with an inertial measuring unit. However, the method is not limited to this embodiment.

[0020] An embodiment of the presented method is based on acquired knowledge of the following challenges that arise when operating an inertial measuring unit.

[0021] Currently, the redundancy monitoring concept demonstrates poor performance when tested with fault injection using vehicle measurements from the test catalog. The current implementation is currently unable to detect most faults injected into one of the redundant signals. This results in the signals being uncorrelated. Additionally, potential customers are seeking to reduce correlation thresholds in this case.

[0022] Furthermore, it was recognized that the error cases and thresholds are not representative. Not only the error types and their magnitudes, but also the thresholds in the correlation monitor implementation were defined under strong influence of recent generations of inertial measurement units, where the signals were expected to be used in braking systems (ESP: Electronic Stability Program). Inertial measurement units are focused on autonomous driving applications, which requires a rethinking of the approach to error and threshold definition.

[0023] Currently, the correlation monitor in inertial measurement units is a hard-coded, static solution. This means that once the sensor is flashed, the parameters for redundancy monitoring will remain virtually independent of the application. No setting corresponds to hard-coded. Furthermore, this feature does not take vehicle dynamics into account in the current implementation. This means that the threshold values ​​will also remain independent of the driving scenario. No adaptability therefore means static. The inability to adjust the parameters and adapt them to the environment runs counter to current trends in the automotive sensor market, especially in autonomous driving applications.

[0024] The presented method is used to evaluate redundant signals in a motor vehicle. The method compares a first signal with a second signal, and the result of the comparison is compared with a threshold value. The threshold value is determined based on a statistical evaluation of the signals and information about the vehicle's driving situation.

[0025] The presented method redefines the way signal redundancy is monitored. This allows for the consideration of fault cases relevant to autonomous driving scenarios, along with vehicle dynamics and signal-to-noise characteristics. This approach is based on identifying safety-critical decisions that are primarily based on signals, e.g., those from an inertial measurement unit, and defining the maximum permissible signal deviation. This takes into account the current driving situation and the influence of noise on the integrated signals.

[0026] In the presented approach, a similar procedure is applied to the acceleration and angular rate signals within a typical autonomous vehicle architecture. First, a random walk, namely angle or position, is estimated depending on the signal. This estimate is then integrated into the formulation of the maximum allowable signal deviation. Finally, the measured signal deviation is compared with the defined threshold. The resulting information is converted into a flag.

[0027] At various points in the process, external parameters are used for the calculations, allowing the OEM (original equipment manufacturer) to design the characteristics of the target vehicle and adapt them to the respective driving situation. In addition, the signal properties are estimated, using previous samples to dynamically evaluate the quality of the estimates. One embodiment of the presented method is discussed below: Random Walk.

[0028] The first step is to define the error introduced by integrating the noise signals. For the angular rate signals, only one integration step is required to obtain the random angular random walk. For the acceleration signals, the integration must be performed twice to obtain the random position random walk. In both cases, the input parameters for the calculation are the integration time, the noise characteristics of the original signal, and the signal sampling frequency. Refer to Figures 1 and 2 for details. This step only considers the noise in the signals to estimate the random random walk. By varying the parameters, it is possible to define a characteristic surface, see Figures 3 and 4.

[0029] Acceleration signal deviation

[0030] Using longitudinal control, i.e., accelerator and brake, as a reference, the scenario considered here assumes that the vehicle is traveling on a straight road and suddenly needs to make an emergency stop using dead reckoning. The goal is to stop the vehicle within a predefined longitudinal safety limit. In this case, this is not possible. The vehicle should either execute an emergency evasive maneuver or trigger damage mitigation systems.

[0031] After mathematically transforming the equations for linear motion and discrete integration, together with some worst-case assumptions, the maximum allowable deviation is expressed by the following equation: Where Vo is the initial longitudinal velocity of the vehicle, Ai on is the expected longitudinal deceleration during braking, Sii mis the longitudinal safety limit and dt is the signal sampling time, see Figure 5.

[0032] Angular rate signal deviation

[0033] Using lateral control, i.e., steering, as a reference, the scenario considered here assumes that the vehicle is traveling on a curved road and must maintain its lane using dead reckoning. The goal is to keep the vehicle within a predefined lateral safety boundary. In this case, this is not possible. The vehicle should either initiate a decoupling or perform emergency braking.

[0034] After mathematical transformation of the equations for circular motion and discrete integration, together with some worst-case assumptions, the maximum allowable deviation is expressed by the following equation.

[0035] Vi is onis the longitudinal speed of the vehicle, Tdr is the coupling time, Siim is the lateral safety limit and dt is the signal sampling time, see Figure 6.

[0036] Debounce and final marker arrangement

[0037] The final step in this implementation of the method is to estimate the random walk values ​​using the threshold formulation and compare them with the measured signal deviation. The implementations for acceleration and angular rate differ slightly, but the strategy is the same. This comparison must be debounced before the result is converted into a correlation flag, see Figures 7 and 8.

[0038] If necessary, some parameters described in this procedure can be hard-coded. However, the idea is to have a generic description that can be adapted to each specific case.

[0039] The described arrangement is configured to carry out the method presented herein and can be implemented, for example, in hardware and / or software. Furthermore, the arrangement can be integrated into a vehicle control unit or be designed as such.

[0040] Further advantages and embodiments of the invention will become apparent from the description and the accompanying drawings.

[0041] It is understood that the features mentioned above and those to be explained below can be used not only in the combination specified in each case, but also in other combinations or on their own, without departing from the scope of the present invention.

[0042] Short description of the drawings

[0043] Figure 1 shows a diagram of the calculation of the random position random walk.

[0044] Figure 2 shows a diagram of the calculation of the random angle random walk.

[0045] Figure 3 shows a position random walk estimation surface in a graph.

[0046] Figure 4 shows an angle random walk estimation surface in a graph.

[0047] Figure 5 shows a graph illustrating the maximum deviation for acceleration signals. Figure 6 shows a graph illustrating the maximum deviation for angular rate signals.

[0048] Figure 7 shows a flow chart of an embodiment of the presented method.

[0049] Figure 8 shows a flow chart of another embodiment of the presented method.

[0050] Embodiments of the invention

[0051] The invention is illustrated schematically in the drawings using embodiments and is described in detail below with reference to the drawings.

[0052] The method is described below in connection with an inertial measuring unit, but is not limited to this design, but can be used anywhere in the motor vehicle, especially where redundant signals are to be evaluated.

[0053] Figure 1 illustrates the calculation of the random position in a diagram 10. Note:

[0054] The vehicle uses the inertial measurement unit for dead reckoning for Tdr seconds, and the only difference between the redundant signals is given by the noise parameters. The noise in the redundant signals is integrated twice. The standard deviation for the resulting position, the linear random walk, is found as a function of the noise characteristics in Aon, i.e., OA and OB in the redundant signals, Tdr, and the signal sampling time dt.

[0055] Input variables 12 are the integration time Tdr, the sampling frequency 1 / dt, and the noise of the acceleration sensor OACC. Output variable 14 is the position random walk op 0S. A first graph 16 shows acceleration curves, a second graph 18 shows velocity curves, a third graph 20 shows positions, a fourth graph 22 shows a histogram of noise, a fifth graph 24 shows a histogram of endpoints and a sixth graph 26 also shows a histogram of endpoints.

[0056] Figure 2 illustrates the calculation of the angle random walk in a diagram 40. Note:

[0057] The vehicle uses the inertial measurement unit for dead reckoning for Tdr seconds, and the only difference between the redundant signals is given by the noise parameters. The noise in the redundant signals is integrated once. The standard deviation for the resulting position, the angular random walk, is found as a function of the noise characteristics in yaw rate, i.e., OA and OB in the redundant signals, Tdr, and the signal sampling time dt.

[0058] Input variables 42 are the integration time Tdr, the sampling frequency 1 / dt, and the rate noise ORate. Output variable 44 is the angular random walk OAng. A first graph 46 shows the angular rate, a second graph 48 shows the angle, a third graph 50 shows a histogram of noise, and a sixth graph 52 shows a histogram of endpoints.

[0059] Figure 3 shows a position random walk estimation surface at a sampling rate of 1000 Hz in a graph 80, on one of whose abscissas 82 the signal noise is plotted, on the other abscissa 84 the integration time and on the ordinate 86 the position random walk.

[0060] Figure 4 shows an angle random walk estimation surface at a sampling rate of 1000 Hz in a graph 100, on one of whose abscissas 102 the signal noise is plotted, on the other abscissa 104 the integration time and on the ordinate 106 the angle random walk.

[0061] Figure 5 shows an area of ​​the maximum deviation for acceleration signals in a graph 120, on one abscissa 122 of which the initial vehicle speed is plotted, on the other abscissa 124 of which the expected maximum deviation is plotted and on the ordinate 126 of which the maximum permissible deviation is plotted.

[0062] Figure 6 shows an area of ​​the maximum deviation for angular rate signals in a graph 140, on one abscissa 142 of which the initial vehicle speed is plotted, on the other abscissa 144 of which the integration time is plotted and on the ordinate 146 of which the maximum permissible deviation is plotted.

[0063] Figure 7 shows a flow chart of a possible sequence of the presented method and schematically illustrates the implementation of a redundancy monitoring for acceleration signals in an arrangement 198 for carrying out the method.

[0064] Input variables are an acceleration signal (dt) A 200 and an acceleration signal (dt) B 202. First, a statistical evaluation 204 takes place, which in a step 206 includes the calculation of an absolute difference (delta), in a step 208 a calculation of a moving standard deviation based on N previous samples of the input variable A 200, in a step 210 a calculation of a moving standard deviation based on N previous samples of the input variable B 202 and in a step 212 a moving average based on the N previous samples.

[0065] Furthermore, OEM inputs 222 are taken into account for the driving situation 220, namely an integration time Tdr 230, a safety limit Sii m 232, a maximum expected deceleration Ai on 234 and a vehicle speed Vo 236.

[0066] Taking into account the integration time Tdr 230 and the moving standard deviation 208, a first expected random walk 240 results. Taking into account the integration time Tdr 230 and the moving standard deviation 210, a second expected random walk 242 results. From the two random walks 240 and 242, a worst-case random walk combination is determined in a step 250. Then, taking into account the specified safety limit Sii m 232 in a step 254 a safety limit is set so that it includes the random walk.

[0067] Taking into account the maximum expected deceleration Ai on and the vehicle speed Vo, the maximum permissible deviation A ma x is determined in a step 260. The counter is then debounced to approximately 4 in a step 262. Finally, a correlation monitoring status 270 is output.

[0068] Figure 8 shows a flow chart of a possible sequence of the presented method and schematically illustrates the implementation of a redundancy monitoring for angular rate signals in an arrangement 298 for carrying out the method.

[0069] Input variables are an acceleration signal (dt) A 300 and an acceleration signal (dt) B 302. First, a statistical evaluation 304 takes place, which in a step 306 includes the calculation of an absolute difference (delta), in a step 308 a calculation of a moving standard deviation based on N previous samples of the input variable A 300, in a step 310 a calculation of a moving standard deviation based on N previous samples of the input variable B 302 and in a step 312 a moving average based on the N previous samples.

[0070] Furthermore, OEM inputs 322 are taken into account for the driving situation 320, namely an integration time Tdr 330, a vehicle speed Vi on 332 and a safety limit Sn m 334.

[0071] Taking into account the integration time Tdr 330 and the moving standard deviation 308, a first expected random walk 340 results. Taking into account the integration time Tdr 330 and the moving standard deviation 310, a second expected random walk 342 results. From the two random walks 340 and 342, a worst-case random walk combination is determined in a step 350. Then, in a step 354, a value arccos is determined so that it includes the random walk. Taking into account the vehicle speed Vi on and the security limit Sii m 334 the maximum permissible deviation A is then calculated using equation (2) max is determined in a step 360. The counter is then debounced to approximately 4 in a step 362. Finally, a

[0072] Correlation monitoring status 370 returned.

Claims

Claims 1. Method for evaluating redundant signals in a motor vehicle, in which a first signal is compared with a second signal, a result of the comparison is compared with a threshold value, wherein the threshold value is determined as a function of a statistical evaluation (204, 304) of the signals and as a function of information on a driving situation (220, 320) of the motor vehicle.

2. Method according to claim 1, wherein, within the framework of the statistical evaluation (204, 304), a random random walk is first determined taking into account an integration of the signals over time.

3. The method according to claim 1 or 2, wherein the statistical evaluation (204, 304) comprises at least one calculation step selected from a group consisting of: calculation of an absolute difference (206), calculation of a moving standard deviation (208, 210), calculation of a moving average (212).

4. The method according to any one of claims 1 to 3, wherein the information on the driving situation (220, 320) is selected from a group consisting of: integration time (230), vehicle speed (236), safety limit (232), maximum expected deceleration (234).

5. Method according to one of claims 1 to 4, which is carried out in conjunction with an inertial measuring unit.

6. Method according to claim 5, wherein signals from at least one acceleration sensor are evaluated.

7. Method according to claim 5 or 6, in which signals from at least one yaw rate sensor are evaluated.

8. Method according to one of claims 1 to 7, which is used in an autonomously operated vehicle, wherein error cases relevant to autonomous driving scenarios are taken into account.

9. Method according to one of claims 1 to 8, wherein a counter is incremented when the threshold value is exceeded.

10. The method according to claim 9, wherein the counter is decremented when the threshold value is undershot.

11. Arrangement for evaluating redundant signals in a motor vehicle, which is designed to carry out a method according to one of claims 1 to 10.

12. Arrangement according to claim 11, which is arranged for use in conjunction with an inertial measuring unit.