Vehicle control system for autonomously controlling a vehicle, and method using same
Patent Information
- Authority / Receiving Office
- EP · EP
- Patent Type
- Applications
- Current Assignee / Owner
- ZF CV SYST EURO BV
- Filing Date
- 2024-06-19
- Publication Date
- 2026-05-20
AI Technical Summary
Existing vehicle control systems for autonomous vehicles face challenges in reducing the risk of common cause failures, particularly due to complex cabling and increased effort required for redundancy systems, which can lead to unwanted repercussions and system errors.
A vehicle control system with a primary and secondary motion controller, connected via private and collective communication links, allowing for seamless data exchange and actuator control, including a decision-making circuit to manage actuator states and prioritize control signals, thereby minimizing the risk of common cause failures and ensuring fault tolerance.
The system effectively reduces the risk of common cause failures by enabling continuous vehicle operation even in the event of primary actuator or communication link failures, maintaining safety and functionality through redundant actuator control and separate communication connections.
Smart Images

Figure EP2024067013_16012025_PF_FP_ABST
Abstract
Description
[0001] Vehicle control system for autonomously controlling a vehicle and method therewith
[0002] The invention relates to a vehicle control system for autonomously controlling a vehicle. Furthermore, the invention relates to a vehicle system comprising the vehicle control system, a vehicle comprising the vehicle system or the vehicle control system, and a method for controlling a vehicle with a vehicle control system.
[0003] Vehicle control systems for autonomous vehicle control are known from the state of the art and serve to provide a high degree of automation for vehicles, such as passenger cars or commercial vehicles. For this purpose, such vehicle control systems are designed to control one or more actuators of a vehicle in such a way that a driving task of the vehicle is carried out. These vehicle control systems regulate the lateral and longitudinal acceleration of vehicles partially or completely independently of a human user. To operate a vehicle autonomously, i.e., driverless, requires many different sensors for environmental detection as well as significant computing power to evaluate the sensor data streams. Based on sensor data, the autonomous vehicle control system determines a trajectory or movement for the vehicle's driving task.
[0004] The Society of Automotive Engineers (SAE) has developed a five-level system for classifying the level of automation of vehicles controlled by a vehicle control system. According to the SAE-J3016 standard, the primary level of autonomous driving comprises assisted driving. This involves the vehicle supporting the driver in steering the vehicle. Examples include cruise control, which maintains a speed selected by the driver, and automatic lane keeping assistance, which keeps the vehicle in its lane. The second level of autonomous driving comprises partially automated driving. This allows the vehicle to independently perform tasks such as lane keeping, braking, or acceleration under defined conditions.In autonomy levels 3 to 5, the driving environment is monitored by the autonomous driving system, whereby in level 3 the human user takes over complete vehicle control in the event of an error in the autonomous driving system.
[0005] In autonomy levels 4 and 5, redundancy systems are provided that can continue to perform the driving task at least partially or completely in the event of a system failure. Such redundancy systems are particularly preferred as so-called fail-operational systems. Fail-operational systems are systems that can fully or at least partially perform the required function or driving task even in the event of a failure. The vehicle control system according to the invention is preferably such a vehicle control system that can partially or completely perform the function even in the event of a failure.
[0006] EP 3 626 571 A1 discloses a redundant control system for a vehicle. The redundant system comprises a primary control unit connected to a primary vehicle communication network and a second control unit connected to a second vehicle communication network. The primary control unit is connected to the second control unit via a communication line. A plurality of receivers are configured to receive control signals from both the primary and the second control unit. Furthermore, the primary vehicle communication network is connected to the second control unit via the communication line, and the second vehicle communication network is connected to the primary control unit. EP 3 626 571 A1 thus discloses an architecture in which all subsystems of the control system are interconnected.
[0007] By interconnecting all subsystems, unwanted repercussions between the primary and secondary levels of the control system, for example repercussions from a fault in the primary control unit on the second vehicle communication network, can only be excluded with great effort, in addition to the increased effort required for additional cabling. In such systems, the risk of common-cause failures is therefore increased. In risk analysis, common-cause failures are defined as failures of multiple components or systems that occur as a result of a single fault cause or a single event. Such failures are also referred to as common-cause failures (CCFs). In order to reduce the risk of such failures, a significant additional effort is required. One object of the invention is therefore to address the problems of the prior art.In particular, a vehicle control system is to be provided that reduces the risk of common cause failures while maintaining a reasonable level of effort for countermeasures, particularly for complex cabling or additional components. A further object is to provide an improved vehicle control system that is designed to be fault-tolerant. A further object is to provide a vehicle control system with improved safety. In any event, the object of the present invention is to find an alternative to what is known from the prior art.
[0008] To this end, the invention relates to a vehicle control system for autonomously controlling a vehicle according to claim 1.
[0009] The vehicle control system comprises a primary motion controller configured to receive at least one primary setpoint for a vehicle movement from a primary virtual driver unit. The primary motion controller is further configured to control at least one primary actuator, in particular of a primary actuator system, of the vehicle, preferably as a function of the primary setpoint. For this purpose, the vehicle system comprises a primary communication connection, which is preferably designed as a bus connection, such as a CAN connection, and connects the primary motion controller to the primary actuator or each of the primary actuators. The primary communication connection serves to send primary control signals, which are generated as a function of the primary setpoint, to one or more primary actuators and, particularly preferably, to receive information from the connectable primary actuators.Such information includes, for example, data indicating the current operating state of the primary actuator(s). The primary motion controller is therefore configured to determine primary control signals for controlling the primary actuators depending on the primary setpoint.
[0010] The vehicle control system further comprises a secondary motion controller configured to receive at least one secondary setpoint for a vehicle movement from a secondary virtual driver unit. The secondary motion controller is further configured to control at least one secondary actuator, in particular of a secondary actuator system, of the vehicle, preferably as a function of the secondary setpoint. For this purpose, the vehicle system comprises a secondary communication connection, preferably designed as a bus connection, such as a CAN connection, that connects the secondary motion controller to the secondary actuator or each of the secondary actuators. The secondary communication connection serves to send secondary control signals, generated as a function of the secondary setpoint, to one or more secondary actuators and to receive information from the connectable secondary actuators.Such information includes, for example, data indicating the current operating state of the secondary actuator(s). The secondary motion control is therefore configured to determine secondary control signals for controlling the secondary actuators depending on the secondary setpoint.
[0011] Furthermore, the vehicle control system also has a private communication connection that connects the primary motion controller to the secondary motion controller, in particular in a data-conducting manner, i.e., to enable data exchange between them. The private communication connection thus provides a data line or data connection between the primary motion controller and the secondary motion controller. The private communication connection is preferably designed as a bus connection, preferably a CAN connection.
[0012] The vehicle control system is further configured to send primary control signals from the primary motion controller to the secondary motion controller via the private communication link.
[0013] The secondary motion controller also includes a secondary decision circuit. The secondary decision circuit is configured to control one or more secondary actuators depending, preferably, on either the primary control signal or the secondary control signal, or to leave the one or more secondary actuators uncontrolled.
[0014] Accordingly, the primary control signals are output from the primary motion controller not only to the corresponding primary actuators, but also to the secondary motion controller, and are thus preferably always available in the secondary motion controller in a current state. If a primary actuator fails, a redundant secondary actuator can continue to be controlled with the primary control signals, with the primary control signals being forwarded to the secondary actuator via the secondary motion controller by the secondary decision circuit passing the primary control signals to the secondary actuator.
[0015] This type of control simplifies the coordination of the individual actuators to be controlled. Plausibility checks and arbitration of the primary control signals and secondary control signals are not necessary, unlike when controlling a secondary actuator with secondary control signals derived from secondary setpoints.
[0016] Preferably, the secondary motion controller is also configured to provide a second setpoint received from the secondary virtual driver unit to the primary motion controller via the private communication connection.
[0017] The second setpoint is then cascaded from the secondary virtual driver unit to the primary motion controller via the secondary motion controller. This cascaded provision or forwarding of the second setpoint prevents a complete switchover to the secondary motion controller and the secondary actuator system in the event of a failure of the primary virtual driver unit or a failure of the primary actuator system or an actuator or subsystem of the primary actuator system.
[0018] Preferably, the primary motion controller and the primary actuators each comprise a transceiver unit for connecting to the primary communication link. The secondary motion controller and the secondary actuators each comprise a transceiver unit for connecting to the secondary communication link. The decision circuit therefore preferably comprises the transceiver unit of the secondary motion controller.
[0019] According to a first embodiment, the primary motion controller comprises a primary health circuit. The primary health circuit is configured to detect either a fault-free or faulty state of the primary actuators and / or the primary motion controller. Furthermore, the secondary decision circuit is configured to control the secondary actuator(s) depending on the detected state(s).
[0020] The secondary decision circuit is therefore configured to decide whether one or more secondary actuators are controlled or remain uncontrolled depending on either the primary control signal or the secondary control signal, the decision being made depending on the detected state.
[0021] A defined switching in the decision circuit is thus possible as soon as a defective primary actuator or a defective primary motion control is detected.
[0022] According to a further embodiment, the secondary motion controller comprises a secondary health circuit. The secondary health circuit is configured to detect a fault-free or faulty state of the secondary actuators and / or the secondary motion controller. Preferably, the secondary health circuit is connected to the primary health circuit in a data-conducting manner, so that the respectively detected states of the health circuits are exchanged with each other. Particularly preferably, the secondary health circuit receives the states detected by the primary health circuit and provides the decision circuit with specifications for making a decision. The specifications are therefore either dependent on the states detected by the primary health circuit or on combined states detected by the primary health circuit and the secondary health circuit.
[0023] By detecting the states of the primary actuators, the secondary actuators, as well as the primary motion control and the secondary motion control, it can be ensured that the primary and secondary actuators are safely controlled. This prevents a situation in which ferry operations are continued in the event of a failure of both motion controls or both mutually redundant actuators. The two health circuits are then preferably designed to transfer the vehicle to a safe state, for example, with additional safety circuits. According to a further embodiment, the primary motion circuit has a primary decision circuit. The primary decision circuit is configured to control one or more primary actuators depending on either the primary control signals or the secondary control signals, or to leave one or more secondary actuators uncontrolled.The primary decision circuit is therefore configured in a manner corresponding to the secondary decision circuit in order to decide whether one or more primary actuators are controlled by primary control signals or secondary control signals or whether the primary actuator(s) remain uncontrolled.
[0024] Preferably, the decision circuit makes a decision based on the states detected by the primary health circuit and / or secondary health circuit. Thanks to a primary decision circuit, it is therefore possible, for example, in the event of a large number of failed primary actuators, to control the redundant secondary actuators via the secondary motion controller with secondary control signals. Secondary control signals can then also be forwarded to the primary motion controller, and the primary actuators, in particular the remaining ones, can then also be controlled with secondary control signals. This allows all actuators required to maintain the driving function to be controlled from a single motion controller, thus minimizing the coordination effort of the individual control signals.
[0025] According to a further embodiment, the vehicle control system comprises a collective communication connection. The collective communication connection is preferably a bus connection, particularly preferably a CAN connection. The collective bus connection is connected to the primary motion controller and the secondary motion controller and serves to control at least one non-redundant actuator, such as a drive or drive train, of the vehicle. The collective communication connection is accordingly configured to control one or more non-redundant actuators with the primary motion controller and / or the secondary motion controller. Preferably, the primary motion controller or the secondary motion controller is thus configured to control the non-redundant actuator via the collective communication connection depending on the primary setpoint or the secondary setpoint.Redundancy-free actuators therefore correspond to actuators that are preferably not redundant and thus receive control signals from both the primary motion controller and the secondary motion controller. Control signals can also be referred to as control commands.
[0026] Thus, the redundancy-free actuator, such as a drive train, is controlled via a communication connection that is separate from the connection between the primary motion controller and the primary actuators and the connection between the secondary motion controller and the secondary actuators.
[0027] Possible control signals that a non-redundant actuator configured as a drive train can receive are a target drive torque and a target speed. It is preferred that, in addition to the drive train or as an alternative to the drive train, other non-redundant actuators of the vehicle can be controlled by the primary and / or secondary motion controller via the collective communication connection.
[0028] Preferably, the primary motion controller, the secondary motion controller, and the non-redundant actuators each comprise a transceiver unit for connecting to the collective communication link.
[0029] The primary communication link is connectionless with the secondary motion controller, such that the secondary motion controller does not have a transceiver unit for directly connecting and communicating with the primary communication link. Furthermore, the primary motion controller is connectionless with the secondary communication link. The primary motion controller therefore does not have a transceiver unit for directly connecting to the secondary communication link. The primary communication link, secondary communication link, and collective communication link are therefore physically separate communication links.
[0030] In the event of a failure of the connection between the primary motion controller and the primary actuator system and / or the connection between the secondary motion controller and the secondary actuator system, actuators without redundancy can continue to be controlled.
[0031] The provision of separate primary communication links, secondary communication links, and collective communication links allows for simple wiring of the actuators to the motion controllers. In the event of a primary communication link failure, either due to damage to the primary communication link or due to a defective actuator whose failure affects the primary communication link, the vehicle's operational capability can be maintained using the secondary communication link and secondary actuators.
[0032] A common problem is defective primary actuators that are constantly transmitting. Such actuators are also referred to as "babbling idiots." Moisture entering the housing of an actuator's communication module can cause such a defect. If such a continuous transmitter is connected to the primary communication link, this can lead, for example, to an overload of the primary communication link and thus to either no data transmission at all or only a delayed transmission of data to the other connected primary actuators. However, this defective primary actuator does not negatively affect the function of the actuators without redundancy, as they communicate separately via the collective communication link.
[0033] Even if the primary motion controller fails completely, the redundant actuators can still be controlled by the secondary motion controller, as the redundant actuators can communicate with the primary and secondary motion controllers via the collective communication link. The secondary actuators can also be controlled via the secondary motion controller as a replacement for the primary actuators that are no longer accessible.
[0034] According to a further embodiment, the primary motion controller comprises a primary bypass circuit to provide a communication link between the primary communication link and the collective communication link. The secondary motion controller correspondingly has a secondary bypass circuit to provide communication between the secondary communication link and the collective communication link.
[0035] The primary bypass circuit is configured to provide information and data from the primary communication link to the collective communication link and from the collective communication link to the primary communication link. The primary bypass circuit may therefore also be referred to as the primary routing circuit, and the secondary bypass circuit may therefore also be referred to as the secondary routing circuit.
[0036] For example, the state of a drive that is controlled as a non-redundant actuator and therefore sends data about its state to the primary motion controller via the collective communication connection is also relevant for a primary braking system that communicates with the primary motion controller via the primary communication connection. The primary bypass circuit thus serves to enable data exchange between non-redundant actuators and primary actuators. However, the primary bypass circuit is preferably designed such that not all data is forwarded between the connected communication connections, meaning that only defined data is forwarded to reduce data traffic on both connected communication connections.
[0037] Similarly, the secondary bypass circuit is configured to provide data from the secondary communication link to the collective communication link and from the collective communication link to the secondary communication link. The secondary bypass circuit can therefore also be referred to as a secondary routing circuit. The secondary bypass circuit is also preferably configured such that not all data is forwarded between the connected communication links, i.e., only defined data.
[0038] Providing bypass circuits instead of a direct connection of the primary communication link to the collective communication link and a direct connection of a secondary communication link to the collective communication link further helps prevent the aforementioned common cause failures. Furthermore, it creates the possibility of forwarding data directly from one of the communication links connected to the bypass circuit to the other communication link connected to the bypass circuit.
[0039] Accordingly, the primary bypass circuit data-conductingly connects a transceiver unit of the primary motion controller for connection to the primary communication link and a transceiver unit of the primary motion controller for connection to the collective communication link. Furthermore, the secondary bypass circuit data-conductingly connects a transceiver unit of the secondary motion controller for connection to the secondary communication link to a transceiver unit of the secondary motion controller for connection to the collective communication link.
[0040] According to a further embodiment, the private communication connection is independent of the collective communication connection and corresponds to a communication connection additional to the collective communication connection. The primary motion controller therefore comprises a transceiver unit for the private communication connection and another transceiver unit for the collective communication connection. The secondary motion controller therefore comprises a transceiver unit for the private communication connection and another transceiver unit for the collective communication connection.
[0041] According to an alternative embodiment, the private communication connection corresponds to the collective communication connection. The primary motion controller and the secondary motion controller are thus configured to exchange data with each other via the collective communication connection. This embodiment therefore does not allow an error in a transceiver unit of either the primary motion controller or the secondary motion controller for connecting to the collective communication connection to be compensated for by the correspondingly error-free motion controller. However, this does eliminate the need for an additional communication connection. Furthermore, the primary motion controller is configured to control secondary actuators via the collective communication connection and the secondary motion controller.
[0042] According to a further embodiment, the secondary motion controller comprises an arbitration circuit for arbitrating control signals on the collective communication link, wherein the arbitration circuit is controllable by the secondary and / or primary decision circuit. The arbitration circuit is preferably configured to output or suppress secondary control signals generated by the secondary motion controller on the collective communication link, or in particular to treat them preferentially over primary control signals, depending on specifications of the secondary decision circuit. Preferably, primary control signals forwarded to the secondary motion controller can also be output or not output, i.e., suppressed.
[0043] Preferably, the arbitration circuit arbitrates the primary and secondary control signals at the primary and / or secondary motion controller. Arbitrating the primary and secondary control signals preferably includes checking the validity of the primary control signals and / or checking the validity of the secondary control signals. Additionally or alternatively, the arbitration includes prioritizing the primary and secondary control signals. Checking the validity of the primary control signals and / or the secondary control signals can be performed, for example, by checking a checksum, a counter, or another key of the primary and / or secondary control signals. Prioritizing preferably includes assigning priorities to the primary and secondary control signals.
[0044] According to a further embodiment, the primary motion controller and the secondary motion controller are configured to perform a plausibility check of primary setpoints and secondary setpoints via the private communication connection. Accordingly, primary setpoints sent by the primary virtual driver unit and received by the primary motion controller are preferably sent to the secondary motion controller via the private communication connection, and / or secondary setpoints sent by the secondary virtual driver unit and received by the secondary motion controller are sent to the primary motion controller via the private communication connection. Thus, primary setpoints and secondary setpoints are present in the primary motion controller and / or the secondary motion controller.Primary setpoints and secondary setpoints can be compared if they were generated at the same time, i.e., when the vehicle was in the same state. A deviation between a primary setpoint and a secondary setpoint can thus be recorded and identified as an error. A faulty primary virtual driver unit or a faulty secondary virtual driver unit can be detected.
[0045] According to a further embodiment, the primary motion controller is configured to send data on the secondary communication connection to or receive data from at least one secondary actuator via the private communication connection and the secondary motion controller.
[0046] This allows a failed primary actuator to be replaced by a secondary actuator, while the secondary actuator continues to be directly controlled by the primary motion controller. Thus, a primary actuator that is no longer controllable or defective is simply replaced by a secondary actuator to continue providing the functionality of the primary actuator.
[0047] Frequently, mutually redundant primary and secondary actuators are designed such that the functional scope of the secondary actuator, which is provided redundantly to a corresponding primary actuator, is limited compared to the primary actuator. According to this embodiment, a defective primary actuator does not require a complete switchover to the secondary system, comprising the secondary virtual driver unit, the secondary motion controller, and the secondary actuators; instead, the defective primary actuator can simply be replaced by the redundant secondary actuator. The potentially more extensive functional scope of the remaining, still functional primary actuators, as well as the primary virtual driver unit and / or the primary motion controller, is thus fully retained.
[0048] According to a further embodiment, the secondary motion controller is configured to use the private communication connection to send secondary setpoints to the primary motion controller and / or to control primary actuators via the private communication connection and the primary motion controller. Control occurs, for example, by generating control signals in the secondary motion controller as a function of the secondary setpoints and sending these control signals to the primary actuators via the private communication connection and the primary communication connection in order to control the primary actuators as a function of the control signals. According to a further alternative, the secondary motion controller is configured to transmit setpoints for the primary motion controller, generated as a function of the secondary setpoints, to the primary motion controller via the private communication connection.These generated setpoints can be adapted to the type of primary setpoints if, at the same time, i.e., with the same operating state of the vehicle, different primary setpoints and secondary setpoints are generated by the assigned primary virtual driver unit and the secondary virtual driver unit. However, the generated setpoints can also correspond to the secondary setpoints. In the latter case, the secondary motion control system forwards the secondary setpoints.
[0049] A failure of a primary virtual driver unit can thus be compensated for by the secondary virtual driver unit, while continuing to use the primary motion control and the primary actuators. This is particularly advantageous when, as described above, primary components have a greater range of functions than secondary components.
[0050] According to a further embodiment, each primary actuator is assigned a secondary actuator. Associated actuators correspond to a pair of mutually redundant actuators. Accordingly, the vehicle control system comprises the primary actuators and the secondary actuators. At least one of the pairs, several of the pairs, or all of the pairs comprise a system communication connection. The system communication connection is preferably a bus connection, particularly preferably a CAN connection. The connection can also be referred to as a system bus.
[0051] Associated vehicle actuators are therefore each connected to each other via a system bus. Thanks to the system communication connections, it is possible to control primary actuators via the associated secondary actuator using the secondary communication connection if the primary communication connection fails. In the event of a failed primary communication connection, a data connection to the primary actuators can be established via the secondary motion controller, the secondary communication connection, and the secondary actuators thanks to the private communication connection that provides a connection between the primary system and the secondary system. Furthermore, all primary components of the vehicle control system can be used even if the primary communication connection fails.
[0052] According to a further embodiment, a primary and a secondary power supply are provided for the power supply of the vehicle control system. It is preferred that the primary power supply supplies the primary virtual driver unit, the primary motion controller, and / or the primary actuators of the primary actuator system with power. It is further preferred that the secondary power supply supplies the secondary virtual driver unit, the secondary motion controller, and / or the secondary actuators of the secondary actuator system with power.
[0053] Preferably, all non-redundant actuators are connected to the primary power supply in order to be supplied via the primary power supply. According to an alternative, some of the non-redundant actuators are connected to the primary power supply and another part of the non-redundant actuators are connected to the secondary power supply. Preferably, the total rated power of the non-redundant actuators supplied with the primary energy source differs by less than 50%, preferably less than 20%, or particularly preferably less than 10% from the total rated power of the non-redundant actuators supplied with the secondary power supply. This makes it possible to provide essentially two energy supplies of equal size, such as energy storage devices, preferably accumulators. A simpler symmetry of the primary and secondary systems can thus be achieved.
[0054] According to a further embodiment, the primary motion controller and the secondary motion controller are configured to arbitrate the data sent by the primary motion controller and / or the secondary motion controller. Arbitration of the data, in particular control signals, serves to prevent collisions between data sent simultaneously by the primary motion controller and the secondary motion controller. In particular, the arbitration is performed as a function of a health status detection system that can detect the functionality or errors in the motion controllers or the virtual driver units and thus specify which motion controller is permitted to send commands. Furthermore, the primary motion controller comprises a primary control unit, and the secondary motion controller comprises a secondary control unit.The primary control unit is configured to detect faults in a primary actuator and, upon detection of a fault, to control the secondary actuator associated with the primary actuator via the secondary motion controller and the secondary communication connection. Preferably, the primary control unit is part of the health status detection system and, in this case, is also configured to monitor fault-free operation of the primary motion controller and / or the secondary actuator.
[0055] The invention also includes a vehicle system with a vehicle control system according to one of the aforementioned embodiments. Furthermore, the vehicle system includes a primary virtual driver unit and a secondary virtual driver unit.
[0056] Furthermore, the invention comprises a vehicle having a plurality of primary actuators, secondary actuators and non-redundant actuators as well as a vehicle system or a vehicle control system according to one of the aforementioned embodiments.
[0057] The invention also includes a method for operating a vehicle control system according to one of the aforementioned embodiments.
[0058] According to one embodiment of the method, control signals are sent to the secondary decision circuit via the private communication connection using the primary motion controller via the private communication connection continuously or in the event of a failure of a primary actuator.
[0059] According to a further embodiment, in the event of a failure of a primary actuator, which is preferably detected via the primary health circuit, the secondary actuator redundant to the primary actuator is controlled with the primary control signals. This is preferably achieved by the primary health circuit informing the secondary decision circuit of the state of the failed actuator and controlling the secondary decision circuit to output the primary control signals for the failed primary actuator for the redundant secondary actuator on the secondary communication link. According to a further embodiment, the secondary motion controller sends secondary setpoints to the primary motion controller via the private communication link in order for the primary motion controller to generate control signals for the primary actuators from the primary setpoints.
[0060] According to a further embodiment, the primary motion controller thus controls a primary actuator with data sent via the private communication link, the primary motion controller, the secondary communication link, a secondary actuator that is redundant with the primary actuator to be controlled, and a system communication link that connects the primary actuator to the secondary actuator associated with the primary actuator.
[0061] Furthermore, according to another embodiment, with a primary health circuit of the primary motion controller, errors in a primary actuator are detected and the primary actuator is deactivated with the primary control unit.
[0062] According to a further embodiment, an error of a primary motion controller, in particular in the absence of a monitored health status signal of the primary health circuit of the primary motion controller, is detected with the secondary health circuit of the secondary motion controller, and the primary motion controller and / or primary actuators and / or the primary virtual driver are deactivated and the vehicle is controlled with the secondary virtual driver of the secondary motion controller and the secondary actuators.
[0063] It is preferred that the primary motion controller is connected to the primary virtual driver unit via a primary virtual driver communication connection. It is further preferred that the secondary motion controller is connected to the secondary virtual driver unit via a secondary virtual communication connection. The primary virtual communication connection and the secondary virtual communication connection are preferably independent and physically separate network connections. By separating the two network connections, the risk of common cause failures can be reduced. In a preferred development, the primary virtual driver communication connection is a bus connection, particularly preferably a CAN connection. It is further preferred that the secondary virtual driver communication connection is a bus connection, particularly preferably a CAN connection.
[0064] Preferably, the primary virtual driver unit and the secondary virtual driver unit are configured to fully or partially replace each other functionally. The primary virtual driver unit and the secondary virtual driver unit are therefore designed to be redundant and can fully or partially fulfill the required function even if one of the virtual driver units fails. In a preferred development, the primary virtual driver unit and the secondary virtual driver unit are connected to one another via a driver unit connection, preferably via a driver unit BUS, particularly preferably via a driver unit CAN. The primary virtual driver unit and the secondary virtual driver unit can also be subsystems of a virtual driver system.
[0065] Preferably, the primary virtual driver unit and the secondary virtual driver unit independently generate the primary setpoint and the second setpoint for a vehicle movement. For this purpose, the primary virtual driver unit and the secondary virtual driver unit can each preferably utilize different sensors for environmental detection and high computing power for evaluating the sensor data streams.
[0066] It is preferred that the primary motion controller and the secondary motion controller are configured to fully or partially replace each other functionally. Thus, the primary motion controller and the secondary motion controller are also redundant and can fully or partially fulfill the required function even if one of the motion controllers fails.
[0067] The primary actuator system preferably comprises a primary braking system, and the secondary actuator system preferably comprises a secondary braking system. For transmitting data, the primary braking system and the secondary braking system are preferably connected by a system communication connection. The system communication connection can also be referred to as a brake connection, a brake bus, or a brake CAN. This allows, for example, the secondary braking system to receive a control signal and forward it to the primary braking system, if available, or to make it available to it. It is also possible for the primary braking system to forward a received control signal to the secondary braking system, if available. This ensures that the actuator system of the redundant braking systems is used that is better suited to executing the control signal.
[0068] It is further preferred that the primary actuator system has a primary steering system and that the secondary actuator system has a secondary steering system. Preferably, the primary steering system and the secondary steering system are connected to a system communication link for data transmission. The system communication link may also be referred to as a steering link, steering bus, or steering CAN. This allows the primary steering system and the secondary steering system to forward the respective received control signals in both directions.
[0069] The other redundant subsystems of the primary and secondary actuator systems are also preferably connected to each other by a system communication connection in order to forward the received control signal in both directions.
[0070] Preferably, the secondary motion controller is signal-conductingly connected to the secondary actuator system, as already explained above, via the secondary communication connection. In the event of a predetermined single error or a predetermined error constellation of the vehicle control system and / or the periphery of the vehicle control system, it is preferred that the secondary motion controller processes the secondary setpoint and outputs a secondary control signal derived from the secondary setpoint to the secondary actuator system. A predetermined single error or a predetermined error constellation can, for example, be the failure of the primary motion controller and / or a failure of the primary power supply of the primary motion controller. Other possible errors that can lead to the secondary setpoint being output via the secondary motion controller and the secondary actuator system are, for example:the failure of the private communication connection or the failure of the primary communication connection. In a further embodiment of the method, the method comprises providing at least one primary setpoint for a vehicle movement to a primary motion controller of the vehicle control system. The method further comprises providing a secondary setpoint for a vehicle movement to a secondary motion controller of the vehicle control system. The method preferably comprises forwarding or providing the secondary setpoint from the secondary motion controller to the primary motion controller. It is preferred that the primary setpoint is provided by a primary virtual driver unit to the primary motion controller. Preferably, the secondary setpoint is provided by a secondary virtual driver unit to the secondary motion controller.The primary and secondary setpoints are preferably formed independently of each other.
[0071] The method preferably comprises arbitrating the primary and secondary control signals, particularly for actuators without redundancy on the collective communication link, using an arbitration circuit on the secondary motion controller. Arbitrating the primary and secondary control signals preferably comprises checking the validity of the primary control signals and / or checking the validity of the secondary control signals. Additionally or alternatively, the arbitration comprises prioritizing the primary and secondary control signals. Checking the validity of the primary control signals and / or the secondary control signals can be performed, for example, by checking a checksum, a counter, or another key of the primary and / or secondary control signals. Prioritizing preferably comprises assigning priorities to the primary and secondary control signals.
[0072] In a preferred development, the method comprises selecting the primary or secondary setpoint. Alternatively, the method preferably comprises combining the primary and secondary setpoints. The primary motion controller preferably selects the setpoint that was found to be valid and / or that has a higher priority. The method can therefore also comprise switching from the primary setpoint to the secondary setpoint or from the secondary setpoint to the primary setpoint. It is preferred that the method comprises processing the selected setpoint or the combined setpoint in the primary motion controller. Furthermore, the method preferably comprises controlling an actuator with a primary control command derived from the selected setpoint or the combined setpoint.
[0073] In the case of a predetermined single fault or a predetermined fault constellation of the vehicle control system and / or the periphery of the vehicle control system, the method preferably comprises processing the secondary setpoint in the secondary motion controller and controlling an actuator with a secondary control signal derived from the secondary setpoint. The predetermined single fault or the predetermined fault constellation can, for example, be the failure of the primary motion controller and / or a power supply of the primary motion controller. The failure of relevant network connections or a failure of the primary actuator system or a subsystem of the primary actuator system can also be such a predetermined fault.
[0074] Further embodiments are apparent from the exemplary embodiments described in the figures. Herein:
[0075] Fig. 1 is a schematic representation of a vehicle with a vehicle system according to an embodiment,
[0076] Fig. 2 is a schematic representation of an embodiment of a vehicle system with an embodiment of a vehicle control system and
[0077] Fig. 3 shows another embodiment of a vehicle control system.
[0078] Fig. 1 shows a vehicle 1 which is a commercial vehicle. The vehicle 1 has a vehicle system 200 with a vehicle control system 100. The vehicle 1 is illustrated in Fig. 1 as a commercial vehicle with a first rear axle HA1, a second rear axle HA2 and a front axle VA. Front wheels 50.1, 50.2 of the front axle VA are steerable. Rear wheels 52.1, 52.2, 52.3, 52.4 of the first rear axle HA1 and second rear axle HA2 are designed here as non-steerable wheels. However, it can also be provided that the rear wheels 52.1, 52.2 of the primary rear axle HA1 and / or the rear wheels 52.3, 52.4 of the second rear axle HA2 are steerable.
[0079] The vehicle control system 100 comprises a primary motion controller 110 and a secondary motion controller 120. The primary motion controller 110 is connected to a primary virtual driver unit 112. The primary virtual driver unit 112 is preferably configured to plan a vehicle movement and to form a primary target value S1 for the planned vehicle movement. The vehicle movement is preferably planned using sensor data provided by primary sensors and / or secondary sensor data provided by secondary sensors (not shown). The secondary motion controller 120 is connected to a secondary virtual driver unit 122. The secondary virtual driver unit 122 is preferably configured to plan a vehicle movement and to form a secondary target value S2 for the planned vehicle movement.The planning of the vehicle movement is preferably carried out using secondary sensor data provided by secondary sensors and / or primary sensor data provided by primary sensors (not shown).
[0080] In the exemplary embodiments illustrated in Figures 1 to 3, the primary virtual driver unit 112 and the secondary virtual driver unit 122 are connected to one another via a driver unit bus FB. The driver unit bus FB is preferably designed as a CAN connection.
[0081] The primary virtual driver unit 112 is configured to provide the primary setpoint to the primary motion controller 110. A primary virtual driver communication connection PVF is provided, which connects the primary virtual driver unit 112 to the primary motion controller 110. The primary virtual driver unit 112 can provide the primary setpoint to the primary motion controller 110 via the primary virtual driver communication connection PVF. The secondary virtual driver unit 122 is configured to provide the secondary setpoint to the secondary motion controller 120. A secondary virtual driver communication connection SVF is provided, which connects the secondary virtual driver unit 122 to the secondary motion controller 120.The secondary virtual driver unit 122 can provide the secondary setpoint to the secondary motion controller 120 via the secondary virtual driver communication link SVF.
[0082] The primary motion controller 110 and the secondary motion controller 120 are connected to one another via a private communication connection 130. The private communication connection 130 is preferably a bus connection, more preferably a private bus connection, particularly preferably a CAN connection. The secondary motion controller 120 is configured to forward the secondary setpoint S2 received from the secondary virtual driver unit 122 to the primary virtual driver unit 112 via the private communication connection 130 (see Fig. 3). The secondary motion controller 120 preferably provides the secondary setpoint S2 to the primary motion controller 110 continuously upon request from the primary motion controller 110 and / or event-driven via the private communication connection 130. This means that the primary motion controller 110 is configured to receive both the primary setpoint S1 and the secondary setpoint S2.In a preferred development, the primary motion controller 110 is also or alternatively configured to provide the primary setpoint S1 received from the primary virtual driver unit 112 to the secondary motion controller 120 via the private communication connection 130. In this case, the secondary motion controller 120 is configured to receive both the primary setpoint S1 and the secondary setpoint S2 (not shown).
[0083] The primary motion controller 110 is configured to output a primary control signal PS to a primary actuator system 230 so that the vehicle movement or trajectory required by the primary and / or secondary virtual driver unit is executed (see Figures 2 and 3). The primary control signal PS is preferably a control signal derived from the primary setpoint S1, the secondary setpoint S2, or a combination of the primary and secondary setpoints. A primary communication connection PAB, which may also be referred to as a primary actuator bus, is provided to connect the primary motion controller 110 to the primary actuator system 230.
[0084] The secondary motion controller 120 is configured to output a secondary control signal SS to a secondary actuator system 240 (see Figures 2 and 3). The secondary actuator system 240 is preferably configured to be redundant with the primary actuator system 230. The secondary control signal SS is preferably a control signal derived from the secondary setpoint S2. For an embodiment in which the primary motion controller 110 provides the primary setpoint S1 to the secondary motion controller 120 via the private communication connection 130, the secondary control signal SS can also be a control signal derived from the primary setpoint S1, the secondary setpoint S2, or a combination of the primary and secondary setpoint S2.
[0085] A secondary communication connection SAB is provided to connect the secondary motion controller 120 to the secondary actuator system 240. The secondary communication connection SAB can also be referred to as a secondary actuator bus. It is preferred that the secondary motion controller 120 outputs the secondary control signal SS if, for example, the primary virtual driver unit 112, the primary virtual driver communication connection, the primary motion controller 110, and / or the private communication connection 130 has failed.
[0086] The primary motion controller 110 and the secondary motion controller 120 are also connected to one another via a collective communication connection 165, wherein the collective communication connection 165 is preferably a bus connection, particularly preferably a CAN connection. The collective communication connection 165 connects the primary motion controller 110 and the secondary motion controller 120 to a drive train 160 of the vehicle 1. Both the primary motion controller 110 and the secondary motion controller 120 can control the drive train 160 via the collective communication connection 165, wherein the drive train 160 is preferably not redundant and therefore corresponds to a redundancy-free actuator 265. Thus, the drive train 160 remains controllable even if the primary motion controller 110 or the secondary motion controller 120 fails.Both the primary motion controller 110 and the secondary motion controller 120 are configured to output a drive train control signal AS or drive train control signals to the drive train 160 (see Fig. 2). The drive train control signals AS can be control signals derived from the primary setpoint S1, the secondary setpoint S2, or a combination of the primary and secondary setpoints. Possible drive train control signals AS relate to a setpoint drive torque and / or a setpoint speed. The primary motion controller 110 and the secondary motion controller 120 are preferably configured to check whether the collective communication connection 165 is occupied by the respective other motion controller. Additional actuators 265 without redundancy can also be controlled via the collective communication connection 165 (see Fig. 2).
[0087] The primary actuator system 230 and the secondary actuator system 240 are preferably designed redundantly, as already explained above. The primary actuator system 230 and the secondary actuator system 240 preferably comprise vehicle actuators or subsystems from the group: transmission, brakes, and / or steering. It should be understood that the primary motion controller 110 each outputs a primary control signal PS to an actuator or to a subsystem of the primary actuator system 230. It should also be understood that not every actuator or subsystem of the primary actuator system 230 needs to be controlled for every required vehicle movement or trajectory. For example, if the vehicle 1 is to be braked, but the direction of the vehicle 1 is not to be changed, the primary motion controller 110 can also control only one brake actuator or brake system of the primary actuator system 230.Likewise, it should be understood that the secondary motion controller 120 outputs a secondary control signal SS to an actuator or to a subsystem of the secondary actuator system 240. It should also be understood that not every actuator or subsystem of the secondary actuator system 240 needs to be controlled for every vehicle movement or trajectory. For example, if the vehicle 1 is to be braked, but the direction of the vehicle 1 is not to be changed, the secondary motion controller 120 can also control only one brake actuator or one brake system of the secondary actuator system 240. If, however, only one direction is to be changed, only one steering actuator or one steering system of the secondary actuator system 240 can be controlled.
[0088] Fig. 1 schematically shows that the primary actuator system 230 is connected to the secondary actuator system 240, wherein the redundantly configured actuators or the redundantly configured subsystems of the primary actuator system 230 and the secondary actuator system 240 are preferably connected to one another. Fig. 2 shows an embodiment of the vehicle control system 100 in which the primary motion controller 110 is configured to control primary actuators 231, 232, 235 of the primary actuator system 230. The secondary motion controller 120 is configured to control secondary actuators 241, 242, 245 of the secondary actuator system 240. The secondary actuator system 240 includes secondary actuators 241, 242, 245, each corresponding to a redundant primary actuator 231, 232, 235 of the primary actuator system 230.To ensure safe operation of a vehicle with the vehicle control system 100, safety-relevant actuators 235, 245 are therefore provided redundantly.
[0089] Actuators of the actuator systems 230, 240 that are assigned to one another, i.e., redundant to one another, are each connected via system communication connections 270. The system communication connections 270 also preferably correspond to bus connections, such as CAN connections.
[0090] Accordingly, for example, a primary actuator 235 configured as a primary braking system 231 is connected to a secondary actuator 245 configured as a secondary braking system 241 via a brake bus BB. The secondary braking system 241 can forward a secondary control signal SS received from the secondary motion controller 120 to the primary braking system 231 via the brake bus BB, so that the secondary control signal SS is executed by the primary braking system 231. In the other direction, the primary braking system 231 can also forward a primary control signal PS received from the primary motion controller 110 to the secondary braking system 241 via the brake bus BB, so that the primary control signal PS is executed by the secondary braking system 241.
[0091] A primary actuator 235 configured as primary steering system 232 is correspondingly connected to a secondary actuator 245 configured as secondary steering system 242 via a steering bus LB. The secondary steering system 242 can forward a secondary control signal SS received from the secondary motion controller 120 to the primary steering system 232 via the steering bus LB, so that the secondary control signal SS is executed by the primary steering system 232. In the other direction, the primary steering system 232 can also forward a primary control signal PS received from the primary motion controller 110 to the secondary steering system 242 via the steering bus LB, so that the primary control signal PS is executed by the secondary steering system 242.
[0092] At least one primary actuator 235 designed as a further primary actuator P is connected via a further system communication connection 270 to a secondary actuator 245 designed as a further secondary actuator S.
[0093] By connecting the primary actuator system 230 to the secondary actuator system 240, it can be achieved that the primary actuator system 230 can be used to control the vehicle even in the event of failure of the primary virtual driver unit 112, the primary motion controller 110, a connection between the primary virtual driver unit 112 and the primary motion controller 110 and / or a connection between the primary motion controller 110 and the primary actuator system 230.
[0094] Fig. 2 shows an embodiment of the vehicle control system 100 of a vehicle system 200 for a vehicle, in particular an autonomous vehicle that supports autonomous driving according to automation level 4 or 5. The vehicle control system 100 comprises the primary motion controller 110 and the secondary motion controller 120. The motion controllers 110, 120 serve to generate control signals for actuators of the vehicle depending on trajectories that are generated via the virtual driver units 112, 122 and specified in the form of the setpoint values S1, S2 for the motion controllers 110, 120.
[0095] The primary motion controller 110 and the secondary motion controller 120 are connected to one another via the private communication connection 130. The secondary motion controller 120 preferably represents redundancy to the primary motion controller 110. In the event of a failure of the primary motion controller 110, which can control actuators completely independently of the secondary motion controller 120 during normal operation, the secondary motion controller 120 is therefore configured to control actuators independently of the primary motion controller 110 in the event of a fault in the primary motion controller 110. The primary motion controller 110 is connected to the primary virtual driver unit 112 via the primary virtual driver communication connection PVF. The primary motion controller 110 is connected to the primary actuators 235 and 236 via the primary communication connection PAB.the subsystems of the primary actuator system 230. The primary motion controller 110 is also connected to a redundant actuator 260, in particular the drive train 160, via the collective communication connection 165. A primary power supply 210 is provided to supply power to the primary virtual driver unit 112, the primary motion controller 110, the primary actuator system 230, and the drive train 160. Alternatively, the primary virtual driver unit 112, the primary motion controller 110, the primary actuator system 230, and / or the drive train 160 may each have a separate power supply (not shown).
[0096] The primary power supply 210, the primary virtual driver unit 112, the primary motion controller 110, the primary actuator system 230, and the drivetrain 160 may be considered as the primary system level 118, where the primary motion controller 110 is a unit of the vehicle control system 100 and the primary virtual driver unit 112, the primary power supply 210, the primary actuator system 230, and the drivetrain 160 are units of a periphery of the vehicle control system 100.
[0097] The secondary motion controller 120 is connected to the secondary virtual driver unit 122 via the secondary virtual driver communication link SVF. The secondary motion controller 120 is connected to secondary actuators 245 or subsystems of the secondary actuator system 240 via the secondary communication link SAB. The secondary motion controller is also connected to the drive train 160 via the collective communication link 165. A secondary power supply 220 is provided to supply power to the secondary virtual driver unit 122, the secondary motion controller 120, and the secondary actuator system 240. Alternatively, the secondary virtual driver unit 122, the secondary motion controller 120, and / or the secondary actuator system 240 may each have a separate power supply (not shown).It is also possible for the secondary power supply 220 to supply power to the drive train 160 in addition to or alternatively to the primary power supply 210. The secondary power supply 220, the secondary virtual driver unit 122, the secondary motion controller 120, and the secondary actuator system 240 can be considered a secondary system level 128, wherein the secondary motion controller 120 is a unit of the vehicle control system 100 and the secondary virtual driver unit 122, the secondary power supply 220, and the secondary actuator system 240 are units of the peripherals of the vehicle control system 100. The drive train 160 is also part of the secondary system level 128, so that the primary system level 118 and the secondary system level 128 overlap, with the overlap being the drive train 160.
[0098] The units of the primary system level 118 and the units of the secondary system level 128 are each redundant, except for the drive train 160. The redundant units of the primary system level 118 and the secondary system level 128 are configured to fully or partially replace each other functionally.
[0099] The primary virtual unit provides the primary setpoint S1 to the primary motion controller 110 via the primary virtual driver communication connection PVF. The primary setpoint S1 specifies a vehicle movement or a setpoint trajectory for the vehicle 1. The vehicle movement or the setpoint trajectory is a vehicle movement planned by the primary virtual driver unit 112. The secondary virtual driver unit 122 provides the secondary setpoint S2 to the secondary motion controller 120 via the secondary virtual driver communication connection SVF. The secondary setpoint S2 specifies a vehicle movement or a setpoint trajectory for the vehicle 1, wherein the vehicle movement or the setpoint trajectory is a vehicle movement planned by the secondary virtual driver unit 122.The secondary motion controller 120 provides the secondary setpoint S2 received from the secondary virtual driver unit 122 to the primary motion controller 110 via the private communication connection 130. The secondary motion controller 120 is configured to provide the secondary setpoint S2 continuously, upon request from the primary motion controller 110, and / or event-driven via the private communication connection 130 to the primary motion controller 110. A possible event can be, for example, a simple error or a simple error constellation of the vehicle control system 100 and / or the peripherals of the vehicle control system 100 and / or an invalid primary setpoint S1. A simple error or a simple error constellation or an invalid primary setpoint S1 can also lead to the primary motion controller 110 requesting the secondary setpoint S2 from the secondary motion controller 120.
[0100] The primary motion controller 110 is configured to arbitrate the primary setpoint S1 and the secondary setpoint S2. To do so, the primary motion controller 110 preferably checks the validity of the primary setpoint S1 and / or the validity of the secondary setpoint S2. To check the validity of the primary and / or secondary setpoint, a checksum, a counter, or another key of the primary and / or secondary setpoint can be checked, for example. To check the primary and secondary setpoints, it is also possible to compare the primary setpoint S1 with the secondary setpoint S2. For arbitration, the primary motion controller 110 can preferably prioritize the primary setpoint S1 and the secondary setpoint S2, with the primary motion controller 110 preferentially assigning priorities to the primary setpoint S1 and the secondary setpoint S2.The priority of the setpoints can, for example, depend on whether the respective setpoint was found to be valid or not, in which case a valid setpoint would have a higher priority than an invalid setpoint. The priority can also depend on an identifier of the primary and secondary setpoints, whereby the lower the identifier of the setpoint, the higher the priority of the setpoint. The primary motion controller 110 is configured to select the primary setpoint S1 or the secondary setpoint S2 or to combine the primary setpoint S1 with the secondary setpoint S2. The primary motion controller 110 preferably selects the setpoint that was found to be valid and / or that has a higher priority.
[0101] The primary motion controller 110 is configured to process the selected setpoint or the combined setpoint and to transmit a primary control signal PS derived therefrom to the primary actuator system 230 or to the primary actuators 235 via the primary communication connection PAB. To process the selected setpoint or the combined setpoint, the primary motion controller 110 has a primary control unit 310 (see Fig. 3). The primary motion controller 110 is also configured to transmit a drivetrain control signal AS derived from the selected setpoint or combined setpoint to the drivetrain 160 via the collective communication connection 165.
[0102] By forwarding the secondary setpoint S2 from the secondary motion controller 120 to the primary motion controller 110, it is ensured that in the event of a single fault or a single fault constellation in the primary system level 118, the system does not completely switch to the secondary system level 128. A single fault or a single fault constellation is, for example, the failure of the primary virtual driver unit 112, the primary virtual driver communication connection, and / or a primary actuator or subsystem of the primary actuator system 230.
[0103] Should the primary motion controller 110 and / or the primary power supply 210 fail in addition to or as an alternative to one of the aforementioned simple faults, the secondary system level 128 can be fully utilized to control the vehicle 1. In this respect, the secondary motion controller 120 is configured to process the secondary setpoint S2 and to transmit a secondary control signal SS derived therefrom to the secondary actuator system 240 or to the secondary actuators 245 via the secondary communication connection SAB.
[0104] Fig. 3 shows a further embodiment of the vehicle control system 100. The vehicle control system 100 comprises the primary motion controller 110 and the secondary motion controller 120. The motion controllers 110, 120 each have a control unit 310, 320 for generating control signals, referred to here as control signals PS, SS, for actuators of the vehicle depending on trajectories generated via the virtual driver units 112, 122 and specified in the form of setpoint values S1, S2 for the motion controllers 110, 120. The setpoint values S1 and S2 are previously processed in a primary processing unit 330 and a secondary processing unit 335, respectively. For example, the setpoint values are checked for plausibility in the processing units in order to detect a possible error in the primary or secondary virtual driver unit 112, 122.
[0105] The primary motion controller 110 further comprises a primary decision circuit 340, wherein the primary decision circuit 340 is configured to receive the primary control signals PS and the secondary control signals SS. Furthermore, the primary decision circuit 340 is connected to a primary health circuit 350, wherein the primary health circuit 350 is configured to detect at least one fault-free or faulty state of the primary actuators 235 and the primary motion controller 110. The detected states are output to the decision circuit as primary states PZ.
[0106] The primary decision circuit 340 then outputs either the primary control signals PS or the secondary control signals SS on the primary communication link PAB and / or the collective communication link 165 depending on the received primary states PZ.
[0107] The secondary motion controller 120 has a secondary decision circuit 360, wherein the secondary decision circuit 360 is also configured to receive the primary control signals PS and the secondary control signals SS. Furthermore, the secondary decision circuit 360 is connected to a secondary health circuit 370, wherein the secondary health circuit 370 is configured to detect at least one fault-free or faulty state of the secondary actuators 245 and the secondary motion controller 120. The detected states are output to the secondary decision circuit 360 as secondary states SZ.
[0108] The secondary decision circuit 360 then outputs either the primary control signals PS or the secondary control signals SS on the secondary communication link SAB depending on the received secondary states SZ.
[0109] A primary health status signal PG is also received by the secondary health circuit 370 from the primary health circuit 350, and a secondary health status signal SG is sent to the primary health circuit 350 by the secondary health circuit 370. The primary health circuit 350 and the secondary health circuit 370 thus inform each other about the states of the primary system level 118 and the secondary system level 128. Furthermore, the vehicle control system 100 includes an arbitration circuit 380. The arbitration circuit 380 arbitrates the primary and secondary control signals PS, SS, which are transmitted on the collective communication link 165, in the secondary motion controller 120.The arbitration of the primary and secondary control signals PS, SS preferably comprises checking the validity of the primary control signals PS and / or checking the validity of the secondary control signals SS. In addition or alternatively, the arbitration comprises prioritizing the primary and secondary control signals PS, SS. Checking the validity of the primary control signals PS and / or the secondary control signals SS can be carried out, for example, by checking a checksum, a counter, or another key of the primary and / or secondary control signals PS, SS. Prioritizing preferably comprises assigning priorities to the primary and secondary control signals PS, SS.
[0110] Reference symbol (part of the description):
[0111] 1 vehicle
[0112] 50.1 front wheel
[0113] 50.2 front wheel
[0114] 52.1 Rear wheel
[0115] 52.2 rear wheel
[0116] 52.3 Rear wheel
[0117] 52.4 rear wheel
[0118] 100 Vehicle control system
[0119] 110 primary movement control
[0120] 112 primary virtual driver unit
[0121] 118 primary system level
[0122] 120 secondary motion control
[0123] 122 secondary virtual driver unit
[0124] 128 secondary system level
[0125] 130 private communication connection
[0126] 160 Drivetrain
[0127] 165 collective communication link
[0128] 200 vehicle system
[0129] 210 primary energy supply
[0130] 220 secondary energy supply
[0131] 230 primary actuator system
[0132] 231 primary braking system
[0133] 232 primary steering system
[0134] 235 primary actuator
[0135] 240 secondary actuator system
[0136] 241 secondary braking system
[0137] 242 secondary steering system
[0138] 245 secondary actuator
[0139] 265 redundancy-free actuator
[0140] 270 System communication connection
[0141] 310 primary control unit
[0142] 320 secondary control unit
[0143] 330 primary processing unit 335 secondary processing unit
[0144] 340 primary decision circuit
[0145] 350 primary health circuit
[0146] 360 secondary decision circuit
[0147] 370 secondary health circuit
[0148] 380 Arbitration circuit
[0149] AS driveline control signal
[0150] BB Brake BUS
[0151] FB driver unit-BUS
[0152] HA1 first rear axle
[0153] HA2 second rear axle
[0154] LB steering bus
[0155] P additional primary actuator
[0156] PAB primary communication link
[0157] PS primary control signal
[0158] PVF primary virtual driver communication link
[0159] PZ primary conditions
[0160] SZ secondary conditions
[0161] S additional secondary actuator
[0162] 51 primary setpoint
[0163] 52 secondary setpoint
[0164] SAB secondary communication link
[0165] SS secondary control signal
[0166] SVF secondary virtual driver communication link
[0167] VA front axle
Claims
Patent claims:
1. Vehicle control system (100) for autonomously controlling a vehicle (1), comprising: a primary motion controller (110) and a primary communication connection (PAB), wherein the primary motion controller (110) is configured to receive at least one primary setpoint value (S1) for a vehicle movement from a primary virtual driver unit (112), to generate primary control signals (PS) depending on the primary setpoint value (S1), and to control at least one primary actuator (235) of the vehicle (1) via the primary communication connection (PAB), a secondary motion controller (120) and a secondary communication connection (SAB), wherein the secondary motion controller (120) is configured to receive at least one secondary setpoint value (S2) for a vehicle movement from a secondary virtual driver unit (122),to generate secondary control signals (SS) depending on the secondary setpoint (S2) and to control at least one secondary actuator (245) of the vehicle (1) via the secondary communication connection (SAB), a private communication connection (130) which connects the primary motion controller (110) to the secondary motion controller (120), in particular in a data-conducting manner, in order to send primary control signals (PS) from the primary motion controller (110) to the secondary motion controller (120), and a secondary decision circuit which is configured to control one or more secondary actuators (245) depending on the primary control signal (PS) or the secondary control signal (SS) or to leave the one or more secondary actuators (245) uncontrolled.
2. Vehicle control system (100) according to claim 1, wherein the vehicle control system (100) has a primary health circuit (350) which is configured to detect a fault-free or faulty primary state (PZ) of the primary motion controller (110) and / or the primary actuators (235) and to control the secondary decision circuit (370) depending on the primary state(s) detected by the primary health circuit (350).
3. Vehicle control system (100) according to claim 1 or 2, wherein the vehicle control system (100) comprises a secondary health circuit (370) arranged to to detect a fault-free or faulty secondary state (SZ) of the secondary motion controller (120) and / or the secondary actuators (245) and the secondary health circuit (370) and the primary health circuit (350) are configured to exchange the detected primary and secondary states with each other.
4. Vehicle control system (100) according to one of the preceding claims, wherein the primary motion controller (110) has a primary decision circuit (340) for leaving the at least one primary actuator (235) uncontrolled, controlling it in dependence on a generated primary control signal (PS) or in dependence on a received secondary control signal (SS).
5. The vehicle control system (100) of any preceding claim, further comprising a collective communication link (165), wherein the collective communication link (165) is connected to the primary motion controller (110) and the secondary motion controller (120) and is configured to control at least one redundant actuator (265).
6. The vehicle control system (100) of claim 5, wherein the secondary motion controller includes an arbitration circuit (380) for arbitrating secondary control signals (SS) generated by the secondary motion controller (120) against primary control signals (PS) generated by the primary motion controller (110) on the collective communication link (165).
7. The vehicle control system (100) of claim 6, wherein the arbitration circuit (380) is connected to the secondary health circuit (370) and / or the secondary decision circuit (360) to perform the arbitration in dependence on a detected primary state (PZ) and / or secondary state (SZ).
8. Vehicle control system (100) according to one of the preceding claims, wherein the vehicle control system (100) comprises a primary power supply (210) and a secondary power supply (220), wherein the primary power supply (210) is configured to supply the primary motion controller (110), the primary actuator (235) and / or the primary virtual driver unit (112) with power and the secondary power supply (220) is configured to supply the secondary motion controller (120) to supply the secondary actuator (245) and / or the secondary virtual driver unit (122) with energy, wherein the non-redundant actuators (265) can be supplied with energy from the primary energy supply (210) or a portion of the non-redundant actuators (265) can be supplied with energy from the primary energy supply (210) and another portion of the non-redundant actuators (265) can be supplied with energy from the secondary energy supply (220).
9. The vehicle control system (100) of any one of claims 1 to 8, wherein the primary motion controller (110) includes a primary bypass circuit to provide communication between the primary communication link (PAB) and the collective communication link (165), and the secondary motion controller (120) includes a secondary bypass circuit to provide communication between the secondary communication link (SAB) and the collective communication link (165).
10. Vehicle system (200) with a vehicle control system (100) according to one of claims 1 to 9 and a primary virtual driver unit (112) and a secondary virtual driver unit (122) and preferably primary actuators (235), secondary actuators (245) and redundancy-free actuators (265).
11. Vehicle (1) with a vehicle system (200) according to claim 10 or a vehicle control system (100) according to one of claims 1 to 9, wherein the vehicle (1) is preferably a commercial vehicle or a passenger car.
12. A method for a vehicle control system (100) according to any one of claims 1 to 9, wherein the vehicle control system (100) is operated to control a vehicle (1) autonomously.
13. The method according to claim 12, wherein the primary motion controller (110) continuously sends primary control signals to the secondary motion controller (120), in particular the secondary decision circuit of the secondary motion controller (120), via the private communication link (130).
14. The method according to claim 12 or 13, wherein a primary health circuit (350) detects a faulty primary state (PZ) of a primary actuator (235). is known and the secondary decision circuit (360) is controlled in such a way as to control a secondary actuator (245) redundant with the faulty primary actuator (235) with the primary control signal (PS).
15. Method according to one of claims 12 to 14, wherein a faulty primary motion control (110) is detected by the secondary health circuit (370) and preferably all non-redundant and secondary actuators (245, 265) are controlled with secondary control signals (SS) by the secondary decision circuit (360).