Method, software program product and device for safety-oriented speed monitoring of an autonomous mobile unit
By cross-checking motion vectors from existing components, the method efficiently monitors the safety-oriented speed of autonomous mobile units, addressing the inefficiencies and costs associated with existing systems.
Patent Information
- Application Number
- JP2024569723
- Authority / Receiving Office
- JP · JP
- Patent Type
- Applications
- Current Assignee / Owner
- Priority Date
- 2022-06-02
- Filing Date
- 2023-05-23
- Publication Date
- 2025-06-12
AI Technical Summary
Existing safety-oriented speed monitoring systems for autonomous mobile units, especially those with omnidirectional drives, face increased computational costs and require additional hardware, making them inefficient and costly.
A method and system that utilize existing components like programmable controllers, optical sensors, and motion detection systems to cross-check motion vectors from both systems, minimizing additional hardware requirements and computational costs.
This approach allows for reliable and efficient safety-oriented speed monitoring of autonomous mobile units without the need for additional special hardware, thereby reducing costs and computational burdens.
Smart Images

Figure 2025518084000001_ABST
Abstract
Description
Technical Field
[0001] The present invention relates to a method for safety-oriented speed monitoring of an autonomous mobile unit, as well as a software program product and a device.
Background Art
[0002] Autonomous mobile units, such as autonomous mobile robots (abbreviated as "AMR"), and other driverless vehicles such as forklifts are also increasingly being used in industrial environments for material transportation. Type C standard ISO3691-4:2020 (Industrial trucks - Safety technical requirements and their verification - Part 4: Driverless floor conveyors and their systems) and EN1525:1997 (Safety of floor conveyors - Driverless floor vehicles and their systems) provide guidelines for ensuring the personal protection of people working in that environment. So-called safety-oriented controllers (SPLC or F-PLC) are also increasingly frequently used in the implementation of safety devices. Safety-oriented or fail-safe means that a person is reliably detected in an area and the vehicle switch is reliably turned off when this person enters that area.
[0003] The EN61508 series "Functional safety of electrical / electronic / programmable electronic systems" is a basic safety standard that deals with the functional safety of electrical, electronic, and programmable electronic systems regardless of their applications. Therefore, it is a central standard themed on the functional safety of control systems.
[0004] Generally, what is used for personal protection is an emergency stop switch and a safety-oriented laser scanner connected by a safety-oriented control unit to an actuator.
[0005] The monitoring field of such a safety-oriented laser scanner is often static, and as a result, the maximum speed is limited. It is also possible to appropriately switch the value of the monitoring field based on the speed and direction of the vehicle.
[0006] Figure 1 shows an example having an autonomous mobile unit (100) equipped with a safety-oriented controller 110 and an optical sensor LS. The autonomous mobile unit 100 moves in different moving directions according to the drive type, Vx points forward, and the minimum speed Vmin, the maximum speed Vmax, and the speeds V1, V2 therebetween are shown. The rotational speed Vw enables the moving device to rotate in a further direction and must be considered in the following considerations. The encoder ENC monitors the movement of the wheels and is understood as an encoder that forms a signal from the movement and generally operates optically, magnetically, or mechanically using contacts. There is a measurement transducer or input device that detects the actual position of the shaft or the drive unit and outputs it as an electrical signal. Two types of encoders are distinguished. The rotary encoder is, for example, a rotating component attached to the motor shaft. The linear encoder is usually attached to a component that moves linearly.
[0007] A similar device is shown, for example, in Patent Document 1, which shows a vehicle having a safety system equipped with, for example, a kinematic sensor for monitoring speed and a optoelectronic safety sensor for monitoring the environment. Here, movement information regarding the vehicle is utilized, and the speed value from the first sensor is compared with the movement value from the second sensor.
[0008] Here, it is intended to prevent a person (or another vehicle) P from moving into the safety area of the moving device 100 at its own speed 102.
[0009] In a vehicle having a differential drive (two drives) or kinematics having only a steering axle and a rotating shaft, such as a forklift, the cost involved in calculating the safety-oriented speed is not a problem.
[0010] However, the calculation cost in the safety-oriented part of the programmable logic unit increases in a vehicle having an omnidirectional drive device (for example, a mecanum drive device), that is, a vehicle equipped with mecanum wheels.
[0011] The velocity vectors Vx, Vy, and rotation W are related to the individual velocities of the wheels V1, V2, V3, and V4. R represents the radius of the mecanum wheels in this case. The following equations show the forward kinematics calculation formulas.
[0012]
Equation
[0013] In a safety-oriented controller, in addition to the calculations, and thus the increased computational costs, a safety-oriented encoder is required for each of the four axles. Therefore, these require space and a safety-oriented connection to the safety-oriented controller.
[0014] Faults such as wheel slip cannot be excluded. This means that faults caused, for example, by further slip during braking or by the rotation of the wheels during acceleration cannot be excluded despite the safety-oriented encoders.
[0015] Safety-oriented encoders have been conventionally used on the axles of vehicles. The rotational speed is evaluated by a safety-oriented calculation unit (F-PLC), and as a result, forward kinematics can be calculated. Subsequently, in order to avoid collisions with people, the field of the laser scanner can be switched based on the speed and direction of movement.
[0016] For this purpose, a safety-oriented controller and a safety-oriented encoder are already provided, and as a result, the speed and direction can be calculated, and accordingly, the monitoring technology field can be switched. However, in this case, the type of kinematics cannot be freely defined, but rather is only available for conventional kinematics, for example, differential kinematics.
[0017] An exemplary structure having a safety-oriented controller 203 can be seen in FIG. 2, and the safety-oriented encoder ENC monitors the movement of the drive wheel 200. The optical sensors LS1 and LS2 monitor the monitoring fields 201 and 202, respectively, in the traveling direction of the autonomous mobile device. These may be a laser scanner, a lidar, a camera such as 1D, 2D, 3D, etc. FIG. 2 also shows no emergency stop button that is attached to the mobile device and enables manual triggering of an emergency stop.
Prior Art Documents
Patent Documents
[0018]
Patent Document 1
Summary of the Invention
Problems to be Solved by the Invention
[0019] Therefore, the problem of the present invention is to perform safety-oriented speed detection of a more complex vehicle in accordance with standards. It is intended that the cost for safety-oriented calculations be minimized.
Means for Solving the Problems
[0020] Therefore, this problem is solved by a method having the features of independent claim 1. This problem is also solved by a computer program product for executing the steps of the method according to any one of claims 1 to 16. This problem is likewise solved by an apparatus having the features of claim 17.
[0021] The claimed method for safety-oriented speed monitoring of an autonomous mobile unit having at least one mobile device equipped with a movement detection system (encoder) and at least one environment detection system (camera, laser scanner, lidar, etc.) on the autonomous mobile unit has the following steps. Using the first method, a first motion vector is detected from first data regarding a moving unit based on measurement values from a motion detection system, Using the second method, a second motion vector of the moving unit is detected from second data based on measurement values from an environment detection system, The first motion vector and the second motion vector are checked by cross-checking, and as a result, a statement regarding validity and a motion vector regarded as safety-oriented are output.
[0022] The object of the present invention is also A safety-oriented speed monitoring device for an autonomous moving unit, having at least one moving device equipped with a motion detection system (encoder), and the first motion vector can be detected based on measurement values from the motion detection system, At least one environment detection system is located on the autonomous moving unit, and the second motion vector of the moving unit can be detected from second data based on measurement values from the environment detection system, A diagnostic unit (305) for checking the first data and the second data, and a programmable controller for verifying the first data and the second data, and by cross-checking (322), the first motion vector (313) and the second motion vector (315) are checked, and a safety-oriented determination for the moving unit is made based on the check result obtained from the diagnostic unit, having a statement regarding the validity (317) and the motion vector (316) regarded as safety-oriented, In the device, a statement regarding validity and a motion vector regarded as safety-oriented can be output as a result, which is also solved thereby.
[0023] Further advantageous embodiments of the present invention are described in the dependent claims.
Brief Description of the Drawings
[0024] The present invention will be described in more detail below with reference to the drawings.
[0025]
Figure 1
Figure 2
Figure 3
Figure 4
Figure 5
Figure 6
Mode for Carrying Out the Invention
[0026] A solution is proposed to reliably detect the speed of an autonomous mobile robot (AMR) without additional special hardware. In the proposed solution, only the components that are anyway required for the use of the AMR are used. These are as follows. A programmable controller (PLC, Programmable Logic Controller) capable of making safety-oriented decisions. This is anyway required, for example, to safely stop the AMR in order to avoid collisions with obstacles. An optical system / optical sensor for scanning obstacles. Such a system is usually provided in the AMR today to determine the position (non-safety-oriented) in the space as part of the navigation. The optical sensor can perform 1D, 2D, or 3D detection. These include, for example, all types of cameras, stereo cameras (2D, 3D), especially a laser scanner that can be movably attached, or a lidar that generates so-called point clouds during detection. A system (odometry) for measuring the movement of the wheels of an AMR. These also include the mentioned encoders. This system is required anyway for controlling the drive (not safety-oriented).
[0027] Also, for example, there is another way to obtain the speed of a vehicle. Calculation of speed by visual odometry of a camera directed at a fixed position such as the floor or ceiling. Calculation of speed by visual odometry of a 3D camera directed indoors. Calculation of speed by the position and time delta of two positioning tags of a Cartesian 3D positioning system.
[0028] For the principle proposed here, any two methods can be combined with each other. The prerequisite for safety is that a plurality of physically different measurement principles are used in both channels.
[0029] These components, or the data obtained by the components, are appropriately combined with each other on the corresponding software here with the help of a programmable controller, thus enabling the safe detection of the actual speed as a whole, especially without using additional hardware.
[0030] Figure 3 shows how the above components should be arranged. In this embodiment, an optical sensor 301 (laser scanner, possibly multiple laser scanners (LS, LS1, LS2)) periodically provides the point cloud 311 of all detected obstacles to a software module "scan matcher" 303. Each point cloud generated in this way is given a time stamp. The scan matcher calculates a speed vector 313 (x component, y component, and actual rotational speed w) by comparing it with the point cloud of the last cycle.
[0031] At the same time, for example, a motion sensor 302 (rotary encoder, encoder) provides a "forward transformation" to a software component 304 of the actual position of one or more monitored axles of the AGV. The forward transformation also calculates velocity vectors (vx, vy, w) based on the axle positions of the last cycle. In this case, the movement of the mobile device 200 is detected at least twice at equal time intervals, in particular in real time, by a rotary transmitter or another motion sensor, and a time stamp is given to this axle position. The movement vector is calculated by the forward transformation 304 from at least two detected axle positions over time.
[0032] The optical sensor, motion sensor (odometry), scan matcher, and forward transformation do not need to be implemented in a safety-oriented manner. In particular, existing components can be used for this purpose.
[0033] Two individual velocity vectors are determined or calculated in various ways by independent multiple measurement methods and are intended to be compared here. The errors for both channels result in various incorrect results, which can be detected by subsequent comparison. Furthermore, the calculation paths are completely separate with respect to the software, but may be executed on the same hardware, so that further measures must be taken to detect systematic errors in both calculations.
[0034] Both the velocity vectors calculated in various ways and the original input data (e.g., point cloud determined by the optical sensor + axle increments determined by the motion sensor) are sent to the safety diagnostic device 305. This device is implemented using reliable technology and performs validity and consistency checks. If the check is successful, a velocity vector 316 regarded as safety-oriented is output and can be used for safety-oriented decision 306. If an error is detected, the output "isValid" 317 is deleted and / or a safe alternative value is provided (e.g., the maximum possible speed Vmax for activating the maximum protection field, see Figure 1).
[0035] If the actual speed is output or the output "isValid" 317 is deleted, the system is considered safe. If an incorrect speed is output and the output "isValid" 317 is set simultaneously, the system is potentially not safe.
[0036] To minimize the probability of potentially dangerous outputs, the following diagnostic means are proposed, which are executed on the diagnostic device 305 using safe techniques. These are described in more detail below.
[0037] Plausibility check (PC) 321, 323 Cross-check (CC) 322 Diverse coordinate systems (DC) Dynamization of coordinate systems (DYC) Safe start-up after stop (SVS)
[0038] 1. Plausibility checks 321, 323, Plausibility check (PC) In one advantageous embodiment, the plausibility checks 321, 323 comprise at least one of the following checks. The detected speed is within a predefined value range. The detected acceleration is within a predefined value range. The detected value has noise. The detected movement corresponds to an expected movement pattern.
[0039] Both input channels 311, 315 are preferably checked separately and independently of each other for plausibility (Figure 4). Specifically, for example, the following checks can be performed.
[0040] Whether the detected speed of the AMR is within the specified range, for example, less than the maximum speed V of the AMR max is checked. This can detect gross errors such as the speed being confused with other process values.
[0041] By forming the first derivative, it becomes possible to determine whether the acceleration or deceleration is within a specific range. In the absence of errors, for example due to mass inertia, the speed does not suddenly and unexpectedly drop to a zero value. Therefore, it is advantageous because sensor failures can be detected extremely easily.
[0042] In the absence of errors, noise can also be detected in the original measurements (e.g., point clouds or axle increments) from the optical sensor and / or the movement sensor in each case, i.e., there is always a certain discrepancy between the measurement results at different times. Otherwise, this is also regarded as a failure of each sensor (frozen sensor).
[0043] During operation, the AMR brakes, rotates at the corner, and then accelerates again, so it moves at a constant speed for only a short time. Similarly, if the speed of the channel does not change significantly over a longer period of time, it is assumed that the sensor is frozen.
[0044] The failure of the clock used to generate the timestamp in the laser scanner can be detected by comparison with the fail-safe clock in the diagnostic unit.
[0045] All validity checks are carried out under the safety orientation. Therefore, it is not necessary to expect the failure of the test itself. If at least one test fails, the output isValid317 is deleted or a safe alternative value is provided as the speed vector.
[0046] 2. Cross-check 322 / Cross-check (CC) In the simplest case, the cross-check 322 consists of three comparisons of pairs of the components vx, vy, w of the speed vector (i.e., the values of the first movement vector 313 and the second movement vector 314 are compared in pairs and, in some cases, compared by the rotation angle). The magnitude of their difference must be less than a previously defined threshold t based on the technical key data regarding the AGV to be inspected.
[0047]
Number
[0048] The values of t1, t2, and t3, simultaneously, determine the accuracy of the output speed in the case of no error.
[0049] In one advantageous configuration, the Euclidean distance of the Cartesian vectors vx and vy provided by two channels is calculated to enhance the accuracy.
[0050]
Number
[0051] In a further advantageous embodiment, since it cannot be expected that both channels have the same response time, the faster channel is intentionally buffered to compare the speeds detected simultaneously by the sensor.
[0052] When the measurement error of the position is small, the error of the calculated speed becomes relatively large, and as a result, noise may occur in the speed value. This noise can be reduced by filtering (e.g., FIR filter), but it must be taken into account that this filtering extends the response time accordingly.
[0053] The mutual comparison or validity checks 321, 323 are implemented in a functionally safe manner, either completely or at least partially.
[0054] The cross-check itself is implemented in a safety-oriented manner (F-CPU), and if it fails, the output is Valid, and thus the statement regarding validity 317 is erased.
[0055] The cross-check detects all errors that affect only one of the two channels.
[0056] 3. Various coordinate systems (DC) Figure 5 shows a further advantageous embodiment. Random hardware errors that affect the output of the scan matcher 303 and the output of the forward transformation in the same way cannot usually be detected by cross-checking. For example, if the value vx is overwritten with the same value in both cases, this will not be detectable by cross-checking.
[0057] Therefore, the sensor data (point cloud) 311 from the sensor 301 is coordinate-transformed before being processed by the scan matcher. This consists of, for example, the following. Shifting (translation) of all points by the vector (tx, ty). Rotation of all points around the point (rx, ry) by the angle α. Scaling of all points along the X-axis sx. Scaling of all points along the Y-axis sy. Combinations of the aforementioned transformations.
[0058] The transformation can be time-independent (constant) or time-dependent.
[0059] A time-independent rotation by the angle α interprets the results vx’, vy’ as being rotated by the angle α (always).
[0060] A time-dependent transformation means that the change changes over time, i.e., for example, the rotation angle becomes larger and larger. For example, a time-dependent rotation by the angle α interprets w’ as being increased by the corresponding value.
[0061] As a result of the transformation, the input to the scan matcher 303 is intentionally changed. The correction is invalidated by the diagnostic unit 305 before the mutual comparison is performed.
[0062] Random hardware errors that affect the output of the scan matcher and the output of the forward transformation in the same way can be detected by cross-checking with intentional corrections. For example, if the values vx and vx' are overwritten with the same value, after reverting the correction, multiple error syndromes occur in the two channels. This leads to detection in the cross-check.
[0063] 4. Dynamicization of the coordinate system (DYC) Figure 5 shows further measures including the dynamicization of various coordinate systems. This means that the coordinate system used in channel 1 of sensor 311 changes at regular time intervals. This is advantageous as it enables reliable detection of freezing or unwanted delays in this channel.
[0064] The diagnostic unit changes the respective valid transformations, for example, at fixed time intervals. This can be done using a predetermined calculation scheme or randomly selected.
[0065] The diagnostic unit continuously sends the actually valid transformation τ to the corrector 351 (356). The sequence number S is additionally sent and delivered to all subsequent working steps. Finally, the transformation results (vx', vy', w') reach the diagnostic unit part 305 together with the sequence number S.
[0066] The sequence number provides information about the type of coordinate system transformation actually in use.
[0067] Based on the sequence number, the diagnostic unit can determine which corrections need to be undone.
[0068] Furthermore, the diagnostic unit can use the sequence number to detect whether there is expired data on the input side or whether the calculation requires an unacceptably long time in the channel.
[0069] By dynamically changing the coordinate system, it is possible to detect unacceptable delays in calculations in, for example, the scan matcher 303.
[0070] 5. Safe startup / Safe vehicle stop (SVS) after stopping Figure 6 shows a special case where the vehicle has been stopped for a relatively long time. This can lead to the accumulation of potentially dangerous errors. For example, channel 1 (the first sensor) may freeze at a value of zero initially. Since this corresponds to the reality during stopping, this error cannot be detected. Similarly, if channel 2 (the second sensor) also freezes at a value of zero, the error will still not be detected. However, at the next startup, both channels will set inaccurate values to zero, which may lead to a dangerous error (the vehicle speed being underestimated).
[0071] This error situation is overcome by the following measures.
[0072] When the vehicle stops for a certain period of time T1 (e.g., T1 = 5 seconds), the diagnostic unit 305 activates reliable stop monitoring for all axles. At startup, the diagnostic unit must be informed of "MovingOff" 601 via the input side. In this case, the diagnostic unit terminates the safe stop monitoring and activates a time limiter T2 (e.g., 3 seconds).
[0073] In the first channel 602, for example, values vx’, vy’, w’, S can be obtained by means of a dynamic coordinate system. In the second channel 603, correspondingly, in this example, the coordinates vx, vy, w are received.
[0074] The diagnostic unit checks whether the start-up has actually taken place. This ensures that errors do not accumulate in both channels during the stop phase. If the time limiter T2 expires before the start-up is detected, this may be due to the accumulation of errors in the channel. In this case, the output side isValid604 is erased. Alternatively, in this case, it is also possible to reactivate the reliable stop monitoring on the axle. Even if the vehicle tries to move without being actually noticed, the vehicle is thereby safely stopped.
[0075] The corresponding commands 605, 606, 607 are sent to the drive units D1, D2, D3.
Claims
Claim 1 A method for monitoring a safety-oriented speed of an autonomous mobile unit (100), comprising: at least one mobile device (200) equipped with a movement detection system (ENC); at least one environmental detection system (LS) on the autonomous mobile unit (100); and using a first method (301), detecting a first movement vector (313) from first data (311) regarding the mobile unit (100) based on measurements from the movement detection system (ENC); using a second method (302), detecting a second movement vector (314) of the mobile unit (100) from second data (315) based on measurements from the environmental detection system (LS); checking the first movement vector (313) and the second movement vector (314) by cross-check (322), and as a result, outputting a statement regarding validity (317) and a movement vector (316) regarded as safety-oriented; wherein a validity check (321, 323) is performed in advance based on the first data (311) and / or the second data (315), and the first and second data (311, 315) are independently checked for validity; The method is characterized by this. Claim 2 The method according to claim 1, wherein the second method (302) scans the environment (201, 202) using at least one optical sensor (LS, LS1, LS2). Claim 3 The method according to claim 1 or 2, wherein the optical sensor (LS, LS1, LS2) performs one-dimensional, two-dimensional, or three-dimensional detection. Claim 4 The method according to claim 3, wherein the optical sensor is a camera, a stereo camera, particularly a laser scanner movably attached, or a lidar. Claim 5 The method according to any one of claims 1 to 4, wherein a point cloud is generated for each scan cycle during scanning by the optical sensor (LS, LS1, LS2), and each point cloud thus generated is given a time stamp. Claim 6 The method (301) according to claim 1, characterized in that the movement of the moving device (200) is detected by the first method (301) detecting the axial position of the moving device at least twice at equal time intervals, in particular in real time, by means of a rotary encoder (ENC), and assigning a time stamp to the axial position.
7. The method according to claim 6, characterized in that the movement vector is calculated by forward transformation from the at least two detected axial positions with respect to time.
8. The validity check (321, 323) is the following check, namely, the detected speed is within a predefined value range, the detected acceleration is within a predefined value range, there is noise in the detected value, the detected movement corresponds to an expected movement pattern, The method according to claim 7, characterized in that it includes at least one of the above.
9. The cross-check or the validity check (321, 323) is carried out fully or partially functionally reliably in accordance with ISO 3691-2:2020, EN 1525:1997, and IEC 61508, the method according to claim 3 or 8.
10. The method according to any one of claims 1 to 9, characterized in that when the validity check fails, the statement regarding the validity (317) is deleted.
11. In the cross-check (322), the values of the first movement vector (313) and the second movement vector (314) are compared in pairs in order to determine whether they exceed a predefined difference magnitude, the method according to any one of claims 1 to 10.
12. The first movement vector is determined from the first data (311) by the first method (301) at a first detection frequency, The second movement vector is determined from the second data (315) by the second method (302) at a second detection frequency, The method according to any one of claims 1 to 11, characterized in that at least the detection data of the first or second method are buffered at a higher determination frequency.
13. The method according to any one of claims 1 to 12, characterized in that the second data (315) undergoes a coordinate system transformation based on the measured values of the environment detection system (LS) before processing, and the obtained movement vector undergoes an inverse transformation before the cross-check.
14. The method according to any one of claims 1 to 13, characterized in that the second data (315) is generated based on the measured values of the environment detection system (LS) and provides information regarding the type of coordinate system transformation actually being used, before being processed with a sequence number (356).
15. When starting the autonomous movement unit (100) after it has stopped, it is checked whether the speed has changed within a predetermined period. The method according to any one of claims 1 to 14, characterized in that when the check is negative, the statement regarding the validity (317) is erased.
16. A computer program product for executing the method according to any one of claims 1 to 15.
17. A safety-oriented speed monitoring device for an autonomous movement unit (100), having at least one moving device (200) equipped with a movement detection system (ENC), wherein a first movement vector (313) is detected based on the measured values from the movement detection system (ENC), having at least one environment detection system (LS) on the autonomous movement unit (LS), and a second movement vector (314) of the movement unit is detected based on the measured values of the environment detection system (LS) from the second data (315), having a diagnostic unit (305) for checking the first data and the second data, and a programmable controller for verifying the first data and the second data, and checking the first movement vector (313) and the second movement vector (315) by a cross-check (322), and making a safety-oriented decision regarding the movement unit based on the check result obtained from the diagnostic unit, having statements regarding the validity (317) and a movement vector (316) considered to be safety-oriented, in the device, Validity checks (321, 323) are performed in advance on the first data (311) and / or the second data (315), and the first data (311) and the second data (315) are independently checked for validity with respect to each other. A device characterized by this.
18. The device according to claim 17, characterized in that the environment detection system (LS) uses at least one optical sensor to scan the environment.
19. The device according to claim 17 or 18, characterized in that the optical sensor (LS, LS1, LS2) performs one-dimensional, two-dimensional, or three-dimensional detection.
20. The device according to claim 19, characterized in that the optical sensor is a camera, a stereo camera, in particular a laser scanner that is movably attached, or a lidar.
21. The device according to any one of claims 17 to 20, characterized in that the at least one optical sensor (LS) generates a point cloud for each scanning cycle during scanning, and each point cloud thus generated can be provided with a time stamp.
22. The device according to any one of claims 17 to 21, characterized in that the movement detection system (ENC) detects the axial position of the moving device at least twice isochronously, in particular in real time, in each case by a rotary encoder (ENC), and provides a time stamp for the axial position, thereby detecting the movement of the moving device (200) by a first method (301).
23. The device according to any one of claims 17 to 22, characterized in that the movement vector is calculated by a calculation unit (304) from the at least two detected axial positions with respect to time over time.
24. The diagnostic unit (305) is such that the validity check (323) is whether the detected speed is within a predetermined value range, whether the detected acceleration is a value within a predetermined specified range, whether there is noise in the detected value, whether the detected movement corresponds to an expected movement pattern, The device according to claim 23, characterized in that it is configured to include at least one of these.
25. The apparatus according to any one of claims 17 to 24, characterized in that the cross-check (321) or the validity check (323) is carried out in full or in part in a functionally reliable manner in accordance with ISO 3691-2:2020, EN 1525:1997 and IEC 61508.
26. The apparatus according to any one of claims 17 to 25, characterized in that the diagnostic unit (305) is configured to erase the statement regarding the validity (317) when the validity check fails.
27. The apparatus according to any one of claims 17 to 26, characterized in that the diagnostic unit (305) is configured to compare the values of the first motion vector (313) and the second motion vector (314) for the cross-check (322) and check whether the magnitude of a predetermined difference is exceeded.
28. The first data (311) acquired by the environment detection system (LS) is detected at a first detection frequency, The second data (315) acquired by the motion detection system (ENC) is detected at a second detection frequency, The diagnostic unit (305) is configured to buffer at least the data from the method at a higher detection frequency, The apparatus according to any one of claims 17 to 27, characterized in that.
29. The apparatus according to any one of claims 17 to 28, characterized in that the calculation unit (304) is configured to perform a coordinate system transformation on the second data (315) based on the measured values from the environment detection system (LS) before processing.
30. The apparatus according to claim 29, characterized in that the diagnostic unit (305) is configured to generate a sequence number based on the measured values from the environment detection system (LS) before processing, and the sequence number provides information regarding the type of coordinate system transformation actually in use.
31. After the autonomous motion unit (100) stops and then restarts, the diagnostic unit (305) checks whether a speed change has occurred within a predetermined period, When the check is negative, the statement regarding the validity (317) is configured to be cancelled, The apparatus according to any one of claims 17 to 30, characterized in that.
Citation Information
Patent Citations
Securing safety around vehicle
JP2020184334A
Systems and methods for robotic motion control
JP2020520008A
Safety system and method of operating the safety system
JP2022521938A
Safeguarding a machine
US20200290205A1
Securing the area around a vehicle
DE102019111642B3