Controlling a mobile robot

The controller device for mobile robots creates a current map and plans both nominal and safe control commands to ensure safe operation during connectivity interruptions, addressing safety and productivity issues in offloaded control systems.

WO2025162575A1PCT designated stage Publication Date: 2025-08-07TELEFONAKTIEBOLAGET LM ERICSSON (PUBL)
View PDF 2 Cites 0 Cited by

Patent Information

Application Number
PCT/EP2024/052397
Authority / Receiving Office
WO · WO
Patent Type
Applications
Current Assignee / Owner
Filing Date
2024-01-31
Publication Date
2025-08-07

AI Technical Summary

Technical Problem

Existing offloaded control systems for mobile robots face challenges in maintaining functional safety during connectivity interruptions, leading to excessive wear on the robot's components and reduced productivity due to the lack of a universal rule for emergency stops and potential collisions with obstacles.

Method used

A controller device that creates a current map of the environment, plans a nominal trajectory, and determines both nominal and safe control commands to minimize distance from obstacles, transmitting these commands to the robot. The robot executes safe control commands if connectivity is lost, ensuring safe operation.

Benefits of technology

Ensures safe robot operation without local processing, reducing hardware complexity and wear, while maintaining productivity by minimizing collisions and allowing continued operation during connectivity issues.

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure EP2024052397_07082025_PF_FP_ABST
    Figure EP2024052397_07082025_PF_FP_ABST
Patent Text Reader

Abstract

A controller (120) for controlling a mobile robot (130) is provided, operative to receive sensor data capturing an environment (100) in which the mobile robot (130) moves, create a current map representing the environment (100) based on the sensor data, plan a nominal trajectory (111) of the mobile robot (130) based on the current map, determine a nominal control command based on the nominal trajectory (111), determine one or more safe control commands, resulting in a safe trajectory (113), based on the current map and the nominal trajectory (111), with all obstacles (101) in the environment (100) represented by the current map moving towards the mobile robot (130) at a maximum speed, and transmit the nominal control command and the one or more safe control commands to the mobile robot (130). Further provided is a mobile robot (130) operative to receive a nominal control command and one or more safe control commands from a controller device (120), execute the nominal control command, and in response to determining that a subsequent nominal control command is not received during a waiting time interval (T wait) since reception of the nominal control command, initiate executing the one or more safe control commands.
Need to check novelty before this filing date? Find Prior Art

Description

[0001]CONTROLLING A MOBILE ROBOT Technical field The invention relates to a controller device for controlling a mobilerobot, a mobile robot, methods of controlling a mobile robot, corresponding computer programs, corresponding data carriers, and corresponding data carrier signals. Background With the increased availability of high-bandwidth and low-latency wireless communications, over WLAN / Wi-Fi, cellular networks, or Bluetooth, it has become commercially feasible to reduce the hardware complexity andcosts, energy consumption, and heat dissipation, of battery-powered mobilerobots by moving some of the processing to a server, e.g., a server in anedge cloud. This is referred to as “offloading”, or “offloaded control”. Forexample, Simultaneous Localization And Mapping (SLAM), computer-visionalgorithms, as well as optimization-based control, are operations which require considerable processing resources. A major challenge when offloading control of mobile robots, i.e., robotswhich move through an environment, such as a factory floor, is to maintainfunctional safety of the controlled robot also if the (wireless) connection to theremote controller, herein also referred to as controller device, is interrupted,or suffers from congestion, delays, or packet loss. One known solution is touse a local controller which is executed on the robot, and which controls therobot relying on sensor data captured by the robot’s sensors to keep therobot safe from collisions with obstacles in the environment through whichthe robot moves, until connectivity with the remote controller is restored (see,e.g., US 9,567,077 B2). This approach, however, reduces the opportunitiesto reduce hardware complexity and costs for the robot, since the (mobile andbattery-powered) robot needs to have enough computing power to be able toprocess its sensor data locally, and requires implementing two parallelcontrollers, one to run on the remote controller (e.g., in an edge cloud) andone on the robot. Another known solution is to hold (i.e., repeatedly execute) the lastcontrol command which the robot receives from the controller device forsome (short) time, and then perform an emergency stop which is executed ifthe connection to the remote controller has not been restored. The problemwith this approach is that even short interruptions in connectivity, e.g., due tocongestion, increased delays, or temporary disturbance in radio coverage,may cause excessive wear on gearboxes and motors of the robot, andnegatively impact productivity of the system or process relying on the robot.Using a smoother stop sequence would require initiating the emergency stopeven earlier, or let the robot drive farther before stopping, which sacrifices safety. In addition, there is no safe universal rule for how long to hold the last control command before performing an emergency stop. Summary It is an object of the invention to provide an improved alternative to the above techniques and prior art. More specifically, it is an object of the invention to provide an improved solution for offloaded control of mobile robots, in particular in scenarios when connectivity between the mobile robot and a controller device controlling the mobile robot is lost or impaired. These and other objects of the invention are achieved by means of different aspects of the invention, as defined by the independent claims. Embodiments of the invention are characterized by the dependent claims.According to a first aspect of the invention, a controller device forcontrolling a mobile robot is provided. The controller device comprisesprocessing circuitry which causes the controller device to become operativeto receive sensor data, or information derived therefrom. The sensor data, orthe information derived therefrom, captures an environment in which themobile robot moves. The controller device is further operative to create acurrent map representing the environment based on the sensor data or theinformation derived therefrom. The controller device is further operative toplan a nominal trajectory of the mobile robot based on the current map. Thecontroller device is further operative to determine a nominal control commandwhich is to be executed by the mobile robot. The nominal control command isdetermined based on the nominal trajectory. The controller device is furtheroperative to determine one or more safe control commands which are to beexecuted by the mobile robot and which result in a safe trajectory. The one ormore safe control commands are determined based on the current map andthe nominal trajectory, with all obstacles in the environment represented bythe current map moving towards the mobile robot at a maximum speed. Thedetermined one or more safe control commands minimize the distancebetween the safe trajectory and the nominal trajectory. The controller deviceis further operative to transmit the nominal control command and the one ormore safe control commands to the mobile robot. According to a second aspect of the invention, a mobile robot isprovided. The mobile robot comprises processing circuitry which causes themobile robot to become operative to receive a nominal control command andone or more safe control commands which are to be executed by the mobilerobot. The nominal control command and the one or more safe control commands are received from a controller device. The mobile robot is furtheroperative to execute the nominal control command. The mobile robot isfurther operative to initiate executing the one or more safe control commands. The mobile robot is operative to initiate executing the one ormore safe control commands in response to determining that a subsequentnominal control command is not received from the controller device during awaiting time interval since reception of the nominal control command.According to a third aspect of the invention, a method of controlling amobile robot is provided. The method is performed by a controller device andcomprises receiving sensor data, or information derived therefrom. Thesensor data, or the information derived therefrom, captures an environmentin which the mobile robot moves. The method further comprises creating acurrent map representing the environment. The current map is created based on the sensor data or the information derived therefrom. The method furthercomprises planning a nominal trajectory of the mobile robot based on thecurrent map. The method further comprises determining a nominal controlcommand which is to be executed by the mobile robot. The nominal controlcommand is determined based on the nominal trajectory. The method furthercomprises determining one or more safe control commands which are to beexecuted by the mobile robot and which result in a safe trajectory. The one ormore safe control commands are determined based on the current map andthe nominal trajectory, with all obstacles in the environment represented bythe current map moving towards the mobile robot at a maximum speed. Thedetermined one or more safe control commands minimize the distancebetween the safe trajectory and the nominal trajectory. The method furthercomprises transmitting the nominal control command and the one or moresafe control commands to the mobile robot. According to a fourth aspect of the invention, a method of controlling amobile robot is provided. The method is performed by the mobile robot andcomprises receiving a nominal control command and one or more safecontrol commands which are to be executed by the mobile robot. Thenominal control command and the one or more safe control commands arereceived from a controller device. The method further comprises executing the nominal control command. The method further comprises initiatingexecuting the one or more safe control commands. The executing the one ormore safe control commands is initiated in response to determining that a subsequent nominal control command is not received from the controller device during a waiting time interval since reception of the nominal control command. According to a fifth aspect of the invention, a computer program is provided. The computer program comprises instructions which, when thecomputer program is executed by one or more processors comprised in acontroller device, cause the controller device to carry out the method according to an embodiment of the third aspect of the invention. According to a sixth aspect of the invention, a computer program is provided. The computer program comprises instructions which, when the computer program is executed by one or more processors comprised in a mobile robot, cause the mobile robot to carry out the method according to an embodiment of the fourth aspect of the invention. According to a seventh aspect of the invention, a computer-readable data carrier provided. The computer-readable data carrier has stored thereon the computer program according to the fifth or sixth aspect of the invention. According to an eighth aspect of the invention, a data carrier signal is provided. The data carrier signal carries the computer program according to the fifth or sixth aspect of the invention. The invention makes use of an understanding that a contingency plan, in the form of one or more safe control commands, can be transmitted by acontrol device to a mobile robot in addition to nominal, i.e., ordinary controlcommands. Whereas the nominal control commands direct the mobile robotalong its nominal trajectory during normal operation, i.e., while nominalcontrol commands are received by the mobile robot at regular time intervals,the mobile robot starts executing the safe control commands once it fails toreceive an expected nominal control command. In contrast to the nominalcontrol commands, which are determined by the controller device based onrecent sensor data representing the environment in which the mobile robotmoves, the safe control commands are determined under the assumptionthat all objects in the environment, as known from the most recently capturedsensor data, start moving towards the mobile robot at the point in time whenexecution of the safe control commands is initiated. Thereby, the lack ofinformation about the objects in the environment, because current sensordata fails to reach the controller device, or the lack of recent nominal controlcommands at the mobile robot, can be remedied.Embodiments of the invention are advantageous in that the mobilerobot is not required to process sensor data locally in situations whenconnectivity with the controller device is lost. At the same time, the mobile robot can continue operating for a limited duration of time by executing itscontingency plan, without the risk for collisions with obstacles in theenvironment. Even though advantages of the invention have in some cases been described with reference to embodiments of the first or second aspect of the invention, corresponding reasoning applies to embodiments of other aspects of the invention. Further objectives of, features of, and advantages with, the invention will become apparent when studying the following detailed disclosure, thedrawings, and the appended claims. Those skilled in the art realize thatdifferent features of the invention can be combined to create embodiments other than those described in the following. Brief description of the drawings The above, as well as additional objects, features and advantages of the invention, will be better understood through the following illustrative and non-limiting detailed description of embodiments of the invention, with reference to the appended drawings, in which:Fig. 1 illustrates a mobile robot moving in an environment, and acontroller device for controlling the mobile robot, in accordance withembodiments of the invention.Fig. 2 schematically illustrates embodiments of the controller device forcontrolling a mobile robot. Fig. 3 schematically illustrates embodiments of the mobile robot.Fig. 4 shows an occupancy grid map, and a corresponding SignedDistance Function (SDF), for an example environment.Fig. 5 shows a sequence diagram illustrating operations of the controllerdevice for controlling a mobile robot, and the mobile robot, in accordance with embodiments of the invention. Fig. 6 shows a flow chart illustrating a method of controlling a mobilerobot, performed by a controller device for controlling a mobile robot, inaccordance with embodiments of the invention. Fig. 7 shows a flow chart illustrating a method of controlling a mobilerobot, performed by the mobile robot, in accordance with embodiments of theinvention. All the figures are schematic, not necessarily to scale, and generally only show parts which are necessary in order to elucidate the invention, wherein other parts may be omitted or merely suggested. Detailed description The invention will now be described more fully herein after with reference to the accompanying drawings, in which certain embodiments of the invention are shown. This invention may, however, be embodied in many different forms and should not be construed as limited to the embodiments set forth herein. Rather, these embodiments are provided by way of example so that this disclosure will be thorough and complete, and will fully convey the scope of the invention to those skilled in the art.With reference to Fig. 1, the solutions described herein relate toimprovements in offloaded control of a mobile robot 130 moving through areal-world environment 100 with one or more obstacles, such asobstacles 101 and 103. The mobile robot 130 can autonomously move in theenvironment 100 using wheels driven by electric motors 306, or otherpropulsion systems such as propellers, and optionally actuators. Therobot 130 may, e.g., be a vehicle, a drone, a robot in a warehouse or amanufacturing site, or a domestic robot. The environment 100 may, e.g., be aroom or a corridor in a building, a factory floor, an outdoor space, or the like, with obstacles such as walls, furniture, people, other robots, vehicles,machines, boxes, etc. For the purpose of elucidating the invention, theobstacles 101 and 103 may, e.g., be exemplified as persons or mobilerobots. In offloaded-control scenarios such as the one illustrated in Fig. 1, themobile robot 130 is controlled by a controller device 120 (illustrated in Fig. 2)which is separate from the mobile robot 130 and may, e.g., be deployed in anedge cloud. The controller device 120 and the mobile robot 130 communicatewith each other over a wireless connection 140, either directly or indirectly viaone or more communications networks such as a Local Area Network (LAN),the Internet, or the like. Communications via the wireless connection 140may commence via any suitable wireless communications technology, suchas cellular communications (including sidelink or D2D), WLAN / Wi-Fi,Bluetooth, Visible-Light Communication (VLC), or similar, using suitable protocols. In a typical offloaded-control scenario, the controller device receivessensor data from the mobile robot and uses the received sensor data tomaintain a map of the environment, including any obstacles. The obstaclesmay either be static or fixed (i.e., they do not move, like walls or furniture) ordynamic (i.e., they can move, such as persons or vehicles). Based on thecurrent map, a trajectory is planned (by a so-called “trajectory planner”) forthe mobile robot to follow, also referred to as nominal trajectory or referencetrajectory. Then, control commands for the mobile robot’s motors and / oractuators are computed (by a so-called “trajectory follower” or simply“follower”), to control the mobile robot to follow the (nominal) trajectory. Thecontrol commands are sent to the mobile robot where they are passed to amotor driver for execution. In the following, embodiments of the controller device 120 are describedwith reference to Fig. 2, which illustrates the controller device120 in furtherdetail, and Fig. 5, which shows a sequence diagram illustrating operations ofthe controller device 120 and the mobile robot 130.The controller device 120 for controlling a mobile robot 130 comprisesprocessing circuitry 200 which causes the mobile robot 130 to becomeoperative in accordance with embodiments of the invention described herein.The controller device 120 further comprises communications interfacecircuitry 204 for communicating with the mobile robot 130 via the wirelessconnection 140.The processing circuitry 200 may comprise one or moreprocessors 201, such as Central Processing Units (CPUs), microprocessors,application processors, application-specific processors, Graphics Processing Units (GPUs), and Digital Signal Processors (DSPs) including imageprocessors, or a combination thereof, and a memory 202 comprising acomputer program 203, i.e., software, comprising instructions. Whenexecuted by the processor(s) 201, the instructions cause the controllerdevice 120 to be operative in accordance with embodiments of the inventiondescribed herein. The memory 202 may, e.g., be a Random-Access Memory(RAM), a Read-Only Memory (ROM), a Flash memory, or the like. Thecomputer program 203 may be downloaded to the memory 202 by means ofthe communications interface circuitry 204, as a data carrier signal carryingthe computer program 203. The processing circuitry 200 may alternatively oradditionally comprise one or more Application-Specific Integrated Circuits (ASICs), Field-Programmable Gate Arrays (FPGAs), or the like, which areoperative to cause the controller device 120 to be operative in accordancewith embodiments of the invention described herein. The communications interface circuitry 204 may comprise one or moreof: a cellular modem (e.g., GSM, UMTS, LTE, 5G, or higher generation, aWLAN / Wi-Fi modem, a Bluetooth modem, an Ethernet interface, an opticalinterface, or the like, for exchanging data between the controller device 120and the mobile robot 130, either directly or via one or more communicationsnetworks like a LAN or the Internet. More specifically, the controller device 120 becomes operative toreceive 512 sensor data, or information derived therefrom (e.g., point cloudsor parts thereof, key-point descriptors, etc). The sensor data, or informationderived therefrom, captures the environment 100 in which the mobilerobot 130 moves, including any obstacles, such as obstacle 101. The sensordata, or the information derived therefrom, is received 512 from the mobilerobot 130 via the wireless connection 140. The mobile robot 130 hascaptured 511 the sensor data using one or more sensors 305 which aremoveable with the mobile robot 130 while moving through theenvironment 100, such as digital cameras, Lidars, RGB-D sensors, or thelike. In addition, the mobile robot 130 may comprise further sensors, such asan Inertial Measurement Unit (IMU) and / or an encoder which can be used asinput for odometry algorithms to support determination of a current position ofthe mobile robot 130 and / or creating the current map.The controller device 120 is further operative to create 521 a currentmap representing the environment 100 in which the mobile robot 130 moves.The current map is created 521 based on the sensor data or the informationderived therefrom. In general, the current map carries information aboutwhere obstacles (such as obstacle 101) in the environment 100 are located.The current map is based on the sensor data captured by the mobilerobot 130 or by other mobile robots capturing sensor data when movingthrough the same environment 100 (aka collaborative mapping). Typically,the current map is created by updating an existing map. In practice, thecurrent map may be updated every time sensor data, or information derivedtherefrom, is received 512 from the mobile robot 130. The current map may,e.g., be an occupancy map, such as an occupancy grid map, whichrepresents the environment 100 and indicates whether grid cells (areas,regions, or volumes) of the environment are occupied by obstacles (such asobstacles 101 and 103) or empty. For instance, the current map may be abinary occupancy grid map, where the value of each cell of the grid indicateswhether the cell is occupied (e.g., "1", “occupied”, or "true") by an obstacle orempty (e.g., "0", “free”, or "false"). For illustration, Fig. 4 shows a binaryoccupancy grid map (upper diagram in Fig. 4), and a corresponding SignedDistance Function (SDF) (lower diagram in Fig. 4) which has been derivedfrom the binary occupancy grid map, for an example environment (not theenvironment 100 illustrated in Fig. 1). Creating an occupancy map, orupdating an existing occupancy map, is known in the art, and may, e.g., be achieved by ray-tracing laser beams of a Lidar sensor and marking as “free” those cells of the occupancy grid map which are crossed by the trace, and as“occupied” those cells which are hit by the trace. Based on the occupancymap, the SDF can be derived by calculating, for each free cell of theoccupancy map, the Euclidean distance to the closest occupied cell of theoccupancy map. The controller device 120 is further operative to plan 522 a nominaltrajectory 111 of the mobile robot 130 based on the current map. Thenominal trajectory 111 avoids collisions of the mobile robot 130 withobstacles of the environment 100 as represented by the current map. Thecurrent map is based on sensor data, or information derived therefrom, whichthe controller device 120 has received until planning 522 the nominaltrajectory 111. The nominal trajectory 111 is planned further based on thecurrent pose of the mobile robot 130.In two-dimensional (2D) scenarios, e.g., a mobile robot 130 moving ona floor, the pose ^̅ of the mobile robot 130 is understood to be the position ofa defined point of the mobile robot 130, e.g., its center, relative to acoordinate system of the current map, e.g., represented by (^, ^), in additionto its orientation or heading relative to the coordinate system, e.g., an angle ^between a defined axis of the mobile robot 130 and one of the axes of thecoordinate system, e.g., the x-axis (see Fig. 1). The pose ^̅ may accordinglybe represented as (^, ^, ^). In case of a mobile robot 130 with a substantiallycircular footprint or shape, the orientation of the mobile robot 130 relative tothe coordinate system of the current map may be omitted, and the pose ^̅ ofthe mobile robot 130 may accordingly be represented as (^, ^).The current pose ^c̅ = (^c, ^c, ^c) of the mobile robot 130 may, e.g., bereceived from the mobile robot 130 together with the sensor data 512, or theinformation derived therefrom, or by separate signaling 513. Alternatively, thecontroller device 120 may keep track of the current pose of the mobilerobot 130 based on past control commands which have been transmitted tothe robot 130. In other words, the controller device 120 follows the movementof the mobile robot 130 and knows the current pose of the mobile robot 130in the current map based on the past control commands. The controller device 120 may be operative to plan 522 the nominaltrajectory 111 of the mobile robot 130 based on the current map using atrajectory planer known in the art, e.g., as is available from the ROS 2software package (S. Macenski, F. Martín, R. White, and J. Ginés Clavero,“The Marathon 2: A Navigation System”, 2020 IEEE / RSJ InternationalConference on Intelligent Robots and Systems (IROS), pages 2718–2725,IEEE, 2017, doi: 10.1109 / IROS45743.2020.9341207, and https: / / navigation.ros.org / ). In general, a trajectory planner is responsible for finding a collision-free trajectory connecting start and goal positions in a map. The controller device 120 is further operative to determine 523 anominal control command based on the nominal trajectory 111. The nominalcontrol command is to be executed by the mobile robot 130. This is the nextcontrol command which the mobile robot 130 executes to follow one stepalong the planned nominal trajectory 111. Each control command, either anominal or a safe control command, is indicative of a change in a pose of themobile robot 130, i.e., a change in position and / or orientation / heading of themobile robot 130. In practice, each control command may comprise one ormore of: a velocity of the mobile robot 130 during the time interval ofexecuting the control command, and a change in orientation or heading ofthe mobile robot 130 during the time interval of executing the controlcommand. The controller device 120 may be operative to determine 523 thenominal control command based on the nominal trajectory 111 using a(trajectory) follower known in the art, e.g., as is available from the ROS 2software package. In general, a trajectory follower computes a control input, e.g., linear and angular velocities, based on a deviation between a nominaltrajectory and a current pose of a mobile robot.The controller device 120 is further operative to determine 524 one ormore safe control commands. The one or more safe control commands areto be executed by the mobile robot 130 and result, if executed, in a safetrajectory 113. The controller device 120 is operative to determine 524 theone or more safe control commands based on the current map and thenominal trajectory 111, with the obstacles 101 moving towards the mobilerobot 130 at a maximum speed. Thereby, collisions of the mobile robot 130with obstacles 101 of the environment 100, as represented by the currentmap, are avoided. In addition, the one or more safe control commandsminimize the distance between the safe trajectory 113 (which results fromexecuting the one or more safe control commands by the mobile robot 130)and the nominal trajectory 111.This is illustrated in Fig. 1, which shows that the (circular) footprint 102of the obstacle 101 increases with time (each circle indicates the increasedfootprint of the obstacle 101 after a sampling time interval T has passed).The one or more safe control commands are determined 524 based on thepose of the mobile robot 130 after it has executed 514 the nominal controlcommand, i.e., after it has followed one step along the nominaltrajectory 111, and subsequently based on the pose of the mobile robot 130after it has executed the one or more safe control commands, i.e., after it hasfollowed the safe trajectory 113 one step at a time. As is illustrated in Fig. 1,the safe trajectory 113 stays clear off the obstacle 101 even considering thefootprint 102 of the obstacle 101 increasing with time. Inflating the footprint ofthe obstacle 101 is a means of modelling the assumption that theobstacle 101 can move in any direction, including towards the mobilerobot 130, starting one sampling time interval after the point in time for whichthe nominal control command has been determined 523.The determining 524 the one or more safe control commands with allobstacles in the environment 100 represented by the current map movingtowards the mobile robot 130 at some maximum speed models a worst-casescenario in which the controller device 120 does not have any information asto where obstacles which are known to be in the environment 100, such asobstacle 101, are moving, due to a lack of recently captured sensor data.In the following, the determining 524 the one or more safe controlcommands based on the current map and the nominal trajectory 111, with allobstacles in the environment 100 represented by the current map movingtowards the mobile robot 130 at a maximum speed, is described in furtherdetail. Acollision of the mobile robot 130 at pose ^̅ = (^, ^, ^), and having afootprint with an obstacle (such as the obstacle 101) in theenvironment 100, which is represented by an SDF(^), occurs ifSDF(^) > 0 ∀ ^ ∈ ^(^̅) (1),i.e., if the intersection between the footprint ^(^̅) of the mobile robot 130 andan obstacle 101 represented by the current map is non-zero. Under the assumption that the obstacles 101 in the environment couldmove towards the mobile robot 130, with some maximum speed ^max startingat a point in time when the mobile robot 130 expects a subsequent nominalcontrol command (in Fig. 5 illustrated as 526), the set of safe poses ^safe(^) ofthe mobile robot 130 at a time step ^ can be derived as: This means that for a pose ^̅ to be safe at time step ^, all parts of themobile robot 130 must be farther than a distance ^ ∙ ^ ∙ ^max from the closestobstacle (which is represented by one or more occupied cells in the currentoccupancy map). In order to determine 524 the one or more safe control commands,embodiments of the invention require that the pose ^^̅ of the mobile robot 130at every time step ^ stays within ^safe(^), or that the mobile robot 130 standsstill (i.e., ^^ = 0). Thereby, if a collision with a moving obstacle occurs, suchas obstacle 101, the collision is not caused by the mobile robot 130.The controller device 120 may be operative to determine 524 the one ormore safe control commands using a Model-Predictive Control (MPC) solverknown in the art, such as CasADi (A. E. Andersson, J. Gillis, G. Horn,J. B. Rawlings, and M. Diehl, “CasADi – A software framework for nonlinearoptimization and optimal control”, in Mathematical ProgrammingComputation, vol. 11, pages 1–36, Springer, 2019, doi: 10.1007 / s12532-018-0139-4, https: / / github.com / casadi / casadi / releases / download / 3.6.4 / casadi-users_guide-v3.6.4.pdf). This may be achieved by optimizing the controlinput starting at the current time for ^ time steps into the future. The numberof time steps ^, which also determines the maximum length of the safetrajectory 113, should be chosen small enough for the problem to becomputationally tractable, but large enough to allow the mobile robot 130 toreact. For instance, assuming a sensor 305 having a maximum sensingrange of about 6 m (which is typical for Lidar), and considering the maximumspeed of the obstacles 101 in the environment to be 3 m / s (which is typicalfor a person walking), it can be deducted that the mobile robot 130 canoperate by executing the safe control commands, and thereby follow the safetrajectory 113, for a maximum duration of 2 s (6 m / 3 ms-1). The number oftime steps ^ can then be calculated based on the sampling time interval ^,e.g., ^ = 40 if ^ = 0.05 s (2 s / 0.05 s). MPC solvers may also take hardwarelimitations of the mobile robot 130 into account, such as a maximum speed, amaximum angular speed (change in orientation or heading), or a maximumacceleration, of the mobile robot 130.More specifically, the MPC solver is tasked to solve the following MPCproblem for determining 524 the one or more safe control commands(^^, ^^, … , ^^^^) based on the current map (i.e., ^^̅ ∈ ^safe(^) according toEquation (2)) and the nominal trajectory ^n̅om(^): where: ^= is the control command for time step^^ = (^^, ^^ , θ^) is the pose of the mobile robot 130 at time step ^,^^ = ^^ (current nominal control command),^^̅ = ^^̅ (current pose of the mobile robot 130), and Furthermore, ∀^ ∈ [0, ^ − 1], the change in pose of the mobile robot 130 as aresult of executing the i-th control command ^^ can be formulated as^^^^ = ^^ + ^^ cos θ^,^^^^ = ^^ + ^^ sin θ^, and Optionally, ^^^^ = (0,0), i.e., the final safe control command of the one ormore safe control commands controls the mobile robot 130 to stop at the finaltime step. The controller device 120 may be operative to determine 524 the one ormore safe control commands further based on a sensing area of thesensor 305. The sensor 305 is movable with the mobile robot 130 and hascaptured 511 the sensor data, which the controller device 120 hasreceived 512 from the mobile robot 130. In general, the sensing area of asensor is the area or region in which the sensor can capture sensor data witha required signal-to-noise ratio, accuracy, precision, or the like. Typically, thesensing area is limited by the sensing range of the sensor and is notomnidirectional. For example, the sensing area of a digital camera is given bythe field-of-view of the camera, and its range is limited by factors such asresolution of the camera sensor, the optics of the camera, and the minimumsize of captured objects which are to be resolved. In Fig. 1, the sensing areaof the sensor 305 which is moveable with the mobile robot 130 is exemplifiedas the area inside the dotted line 105.By taking the sensing area of the sensor 305 which is movable with themobile robot 130 into consideration in determining 524 the one or more safecontrol commands, the lack of information about obstacles in theenvironment 100 which have not (yet) been captured 511 by the sensor 305,because they are located outside the sensing area of the sensor 305 (suchas obstacle 103), and accordingly are not represented by the current map,can be taken into account. The controller device 120 may, e.g., be operativeto determine 524 the one or more safe control commands further based onthe current map which is augmented by an obstacle 105 representing aboundary of the sensing area of the sensor 305 and which is moving towardsthe mobile robot 130 at a maximum speed (for simplicity, illustration of themovement of the obstacles 105, i.e., the boundary of the sensing area of thesensor 305 moving inwards, is omitted from Fig. 1). In practice, this may beachieved by setting the cells of the current map (e.g., an occupancy gridmap) which are outside the sensing area of the sensor 305 to "occupied",since their current occupation is not known due to a lack of sensor data. Thisworst-case scenario is a safety measure and assumes that there could beobstacles which are located just outside the sensing area of the sensor 305(such as obstacle 103) and which move towards the mobile robot 130 at a maximum speed. This is modelled by augmenting the current map with anobstacle 105 representing the boundary of the sensor 305's sensing areaand which is assumed to move towards the mobile robot 130 just like theother (real) obstacles, e.g., the obstacle 101. If the obstacles in theenvironment 100 are assumed to move at different obstacle-specific speeds,as is described further below, the obstacle 105 representing the boundary ofthe sensing area of the sensor 305 is assumed to move towards the mobilerobot 130 at a maximum speed which may, e.g., be the highest detectedspeed of all obstacles in the environment 100, or a specific speed for theobstacle 105 representing the boundary of the sensing area. For example,the maximum speed at which the obstacle 105 representing the boundary ofthe sensing area of the sensor 305 moves may be set to the maximum speedof all obstacles which may move in the environment 100, e.g., the maximumspeed of other mobile robots or vehicles.The controller device 120 may be operative to determine 524 the one ormore safe control commands further based on a current speed ^^ of themobile robot 130. Assuming a worst-case scenario, this case means that themobile robot 130 moves towards the obstacles in the environment, which inturn move at a maximum speed ^max towards the mobile robot 130. This canbe modeled by replacing ^max with (^max + ^^) in Equation (2).The controller device 120 is further operative to transmit 525 thenominal control command and the one or more safe control commands to themobile robot 130. The transmitted control commands may either be time-ordered, i.e., the control commands are transmitted in the order in which theyare to be executed by the mobile robot 130 (i.e., ordered by ^), or thetransmitted control commands are associated with a sequence number (suchas ^) or a (relative) time stamp (e.g., multiples of the sampling time interval ^,i.e., ^ ∙ ^) to indicate their order. The nominal control command and the oneor more safe control commands may either be transmitted 525 together, e.g., arranged as a sequence of control commands, or separately (not illustratedin Fig. 4).Sequences of control commands, in particular sequences of safecontrol commands, may be encoded or compressed, e.g., by replacingrepetitive similar or identical control commands with information fields indicating how often a control command is repeated, or delta information indicating a change relative to a preceding control command in the sequence. In this way, sequences of (safe) control commands can betransmitted more efficiently over the wireless connection 140, thereby savingcommunication bandwidth. Sequences of (safe) control commands may optionally be representedby a parameterized function, e.g., as a polynomial of time, to save bandwidthwhen transmitting sequences of (safe) control commands over the wirelessconnection 140. For example, the linear velocities ^^ typically resemble asigmoid function, and may accordingly be represented by a sigmoid functionwhich the controller device 120 has fitted to the linear velocities of thedetermined safe control commands, thereby obtaining a set of parameters characterizing the fitted sigmoid function and which can be transmitted to themobile robot 130 instead of the one or more safe control commands.Similarly, the angular velocities are typically piecewise affine (i.e., straight-line segments), any may accordingly be compacted using the Ramer-Douglas-Peucker algorithm for simplifying polygons, resulting in a number ofvertices which the controller device 120 transmits to the mobile robot 130instead of the one or more safe control commands. The operations 504 performed by the controller device 120, inparticular 512, 513, and 521–525, are in practice executed repeatedly. Forinstance, the controller device may receive 511 sensor data, or informationderived therefrom, form the mobile robot 130 at time intervals dictated by themobile robot 130, known as the sampling time interval ^ (which is the timeinterval between subsequent transmissions of nominal control commands bythe controller device 120 to the mobile robot 130). In response thereto, thecontroller device 120 creates 521 the current map, plans 522 the nominaltrajectory, determines 523 the nominal control command, determines 524one or more safe control commands, and transmits 525 the nominal controlcommand and the one or more safe control commands to the mobilerobot 130. The sampling time interval may be configurable and is typicallybased on one or more of: capabilities of the sensors 305 of the mobilerobot 130 (e.g., sample rate), the processing capabilities of the processingcircuitry 200 of the controller device 120, the processing capabilities of theprocessing circuitry 300 of the mobile robot 130, and the bandwidth availablefor sending sensor data, or information derived therefrom, via the wirelessconnection 140. A practical value for the sampling time interval is in therange between 0.05 and 0.5 seconds.In the following, embodiments of the mobile robot 130 are describedwith reference to Fig. 3, which illustrates the mobile robot 130 in furtherdetail, and Fig. 5.The mobile robot 130 comprises processing circuitry 300 which causesthe mobile robot 130 to become operative in accordance with embodimentsof the invention described herein. The mobile robot 130 further comprisescommunications interface circuitry 304 for communicating with the controllerdevice 120 via the wireless connection 140.The processing circuitry 300 may comprise one or moreprocessors 301, such as CPUs, microprocessors, application processors,application-specific processors, GPUs, and DSPs including imageprocessors, or a combination thereof, and a memory 302 comprising acomputer program 303, i.e., software, comprising instructions. Whenexecuted by the processor(s) 301, the instructions cause the mobilerobot 130 to be operative in accordance with embodiments of the inventiondescribed herein. The memory 302 may, e.g., be a RAM, a ROM, a Flashmemory, or the like. The computer program 303 may be downloaded to thememory 302 by means of the communications interface circuitry 304, as adata carrier signal carrying the computer program 303. The processingcircuitry 300 may alternatively or additionally comprise one or more ASICs,FPGAs, or the like, which are operative to cause the mobile robot 130 to beoperative in accordance with embodiments of the invention described herein. The communications interface circuitry 304 may comprise one or moreof: a cellular modem (e.g., GSM, UMTS, LTE, 5G, or higher generation, aWLAN / Wi-Fi modem, a Bluetooth modem, an Ethernet interface, an opticalinterface, or the like, for exchanging data between the controller device 120and the mobile robot 130, either directly or via one or more communicationsnetworks like a LAN or the Internet. More specifically, the mobile root 130 is operative to receive 525 anominal control command and one or more safe control commands from thecontroller device 120.The mobile root 130 is further operative to execute 514 the nominalcontrol command. In practice, this is achieved by passing the nominal controlcommand to a motor driver which operates one or more motors 306, andoptionally actuators, of the mobile robot 130 accordingly.The mobile robot 130 is further operative, in response todetermining 515 that a subsequent nominal control command (in Fig. 5illustrated as 526) is not received from the controller device 120 during awaiting time interval ^wait since reception of the (last) nominal controlcommand 525, to initiate 516 executing the one or more safe controlcommands. Similar to executing 514 the nominal control command, this isachieved by passing the safe control command(s) to the motor driver whichoperates one or more motors 306, and optionally actuators, of the mobilerobot 130 accordingly. Executing 514 the nominal control command results inthe mobile robot 130 moving along the safe trajectory 113, which branchesoff from the nominal trajectory 111 at 112 in Fig. 1.The waiting time interval ^wait may be set based on the sampling timeinterval ^, which is the time interval between subsequent transmissions ofnominal control commands by the controller device 120 to the mobilerobot 130. In other words, the mobile robot 130 expects to receive the nextnominal control command 526 approximately a time ^ after it has receivedthe last nominal control command 525. In practice, the waiting timeinterval ^wait may be set to a value in the range of 1.5 to 2 times ^, to accountfor varying delays over the wireless connection 140. A suitable waiting timeinterval may be empirically determined by measuring the distribution of timeintervals between reception of subsequent nominal control commands by themobile robot 130. Based on the statistical distribution, the waiting timeinterval ^wait may be set to a time interval value corresponding to thereception of, e.g., 99% of all nominal control commands transmitted by thecontroller device 120, resulting in a 1% loss of nominal control commands.The mobile robot 130 may further be operative, in response toreceiving 527 a subsequent nominal control command while the mobilerobot 130 executes 516 the one or more safe control commands (e.g.,because connectivity via the wireless connection 140 is restored), toabort 517 execution of any remaining safe control commands of the one ormore safe control commands, and execute 518 the subsequent nominalcontrol command. The mobile robot 130 may further be operative to capture 511 sensordata using one or more sensors 305 which are movable with the mobilerobot 130. The one or more sensors 305 may be integrated into the mobilerobot 130 or attached to it. The sensor data represents an environment 100in which the mobile robot 130 moves. The mobile robot 130 may further beoperative to transmit 512 the sensor data, or information derived therefrom,to the controller device 120. For instance, rather than transmitting raw sensordata to the controller device 120, the mobile robot 130 may be operative topre-process the captured 511 sensor data, e.g., by feature extraction, point- cloud extraction, de-noising, etc, and transmit information which is a result of pre-processing the sensor data. The mobile robot 130 may further be operative to stop after the last safecontrol command of the one or more safe control commands has beenexecuted 516. That is, the final command (^^^^= (0,0)) instructing the robotto stop is not transmitted by the controller device 120, thereby savingcommunication bandwidth over the wireless connection 140. Rather, themobile robot 130 stops autonomously after the sequence of safe controlcommands has been executed 516 and the mobile robot 130 has notreceived a subsequent nominal control command (527 in Fig. 5).Similar to what is described hereinbefore in relation to the controllerdevice 120, the operations 501 performed by the mobile robot 130, inparticular 511–514, are in practice executed repeatedly. For instance, themobile robot 130 may capture 511 sensor data, and transmit 512 the sensordata, or the information derived therefrom, to the controller device 120 at thesampling time interval. After the controller device 120 has processed thesensor data, or the information derived therefrom, the mobile robot 130receives 525 the nominal control command and the one or more safe controlcommands, and executes 514 the nominal control command. Optionally,some of the operations may be performed concurrently. For example, themobile robot 130 may be operative to capture 511 the sensor data and totransmit 512 the sensor data, or information derived therefrom, to thecontroller device 120 (operations 502 in Fig. 5), and concurrently (i.e., inparallel) to receive 525 the nominal control command and the one or moresafe control commands and to execute 514 the nominal control command(operations 503 in Fig. 5). If the mobile robot 130 does not receive asubsequent nominal control command (526 in Fig. 5) from the controllerdevice 120 during the waiting time interval ^wait, which started at reception ofthe (last) nominal control command 526, it initiates 516 executing the one ormore safe control commands which it has received with the last nominalcontrol command 525.The mobile robot 130 may, e.g., fail to receive a nominal controlcommand because one or more data packets have been lost duringtransmission over the wireless connection 140, the transmission of one ormore data packets over the wireless connection 140 has been delayed, orthe mobile robot 130 has entered a region with inferior radio conditions.Alternatively, the controller device 120 may have failed to transmit thenominal control command to the mobile robot 130. This may, e.g., be thecase if the controller device 120 has not received any sensor data 512, orinformation derived therefrom, from the mobile robot 130, which the controllerdevice 120 needs for determining 523 the subsequent nominal controlcommand based on the current map (which, in turn, is based on the receivedsensor data), or if processing at the controller device 120, in particular thedetermining 523 the nominal control command based on the nominaltrajectory, has failed, e.g., because of a software error. The environment-dependent contingency plan, i.e., the one or moresafe control commands, is executed in scenarios when the mobile robot 130has not received a nominal control command from the controller device 120during the waiting time interval. Notably, a nominal control command isdetermined to control the mobile robot 130 to move along the nominaltrajectory 111, which is planned based on recent sensor data, or informationderived therefrom, which the controller device 120 has received from themobile robot 130, and which is reflected in the current map which thecontroller device 120 has created 521 based on recent sensor data. Incontrast, the one or more safe control commands, which control the mobilerobot 130 to move along a safe trajectory 113, are determined without accessto recent sensor data from the mobile robot 130. Rather, the safe controlcommands are determined so as to direct the mobile robot 130 along a safetrajectory 113 which is as close as possible to the nominal trajectory 111without risking collisions of the mobile robot 130 with obstacles 101, even ifthe obstacles move towards the mobile robot 130 at some maximum speed.In practice, this is achieved, when determining 524 the one or more safecontrol commands, by assuming that the footprints of the obstacles 101increase with time, at a maximum speed starting at a point in time when themobile robot 130 should have received the subsequent nominal controlcommand. The one or more safe control commands are transmitted by thecontroller device 120 to the mobile robot 130 preferably with everytransmission of a nominal control command 525 / 527. Thereby, the mobilerobot 130 has always access, with a granularity in time corresponding to thesampling time interval, to the safe control commands in the event that it failsto receive a subsequent nominal control command from the controllerdevice 120. However, embodiments of the controller device 120 may beenvisaged which do not transmit the one or more safe control commands with every transmission of a nominal control command. For instance, thecontroller device 120 may be operative to determine 524 the one or moresafe control commands only during every second, third, fourth, etc, iteration,and transmit the determined safe control commands accordingly.Alternatively, the controller device 120 may be operative to determine 524the one or more safe control commands or in response to determining that arisk for a failure of the mobile robot 130 to receive nominal control commandsexceeds a threshold value. In practice, the controller device 120 may beoperative to determine 524 the one or more safe control commands, and totransmit the one or more safe control commands 525, in response todetecting inferior performance of the wireless connection 140, such as anincrease in packet loss ratio, an increase in delay or round-trip time, or a decrease in bandwidth. It will also be appreciated that in scenarios where the one or more safecontrol commands are identical, or rather similar, to safe control commandswhich the controller device 120 has transmitted to the mobile robot 130previously, e.g., together with the last nominal control command, the mobilerobot 130 may be operative to use the one or more safe control commandswhich it has received last until subsequent safe control commands arereceived. Additionally or alternatively, if one or more safe control commands in a sequence of determined safe control commands are identical to corresponding safe control commands determined during the precedingiteration (i.e., the preceding sampling-time interval), the controller device 120may be operative to only transmit the changed safe control commands of thesequence, and the mobile robot 130 is operative to combine safe controlcommands received during different iterations accordingly. Such a scenariomay, e.g., occur if the environment 100 through which the mobile robot 130moves does not change significantly between subsequent iterations.Advantageously, embodiments of the invention do not rely on themobile robot 130 to process its sensor data locally, but still maximize the timeduring which the mobile robot 130 can continue moving along a (safe)trajectory which at least is close to the nominal trajectory 111, in case of lossof connectivity with the controller device 120, without sacrificing collisionsafety. The maximum speed ^max with which the obstacles (such asobstacle 101) in the environment 100 represented by the current map areassumed to move towards the mobile robot 130 may, e.g., be a maximumspeed at which obstacles can move in the environment 100. Depending onthe scenario in which embodiments of the invention are employed, the maximum speed can be set accordingly. For example, the maximum speedmay be set to 3 m / s for persons, 5–10 m / s for vehicles in a factory orwarehouse environment, or the like. The controller device 120 may alternatively be operative todetermine 524 the one or more safe control commands based on the currentmap and the nominal trajectory 111 with the obstacles moving towards themobile robot 130 at obstacle-specific speeds. In other words, rather thaninflating the footprint of the obstacles in the environment (as is illustrated forobstacle 101 in Fig. 1) with the same maximum speed for all obstacles, thefootprint of the obstacles can be inflated at obstacle-specific speeds which reflect the actual, current respective speeds of the obstacles in theenvironment 100. For instance, the controller device 120 may be operative todetermine the obstacle-specific speeds based on the sensor data 512 or theinformation derived therefrom. In practice, since the sensor data, or theinformation derived therefrom, is used to create (e.g., by updating) the current map, different versions of the current map at subsequent time stepscan be compared to determine the respective current speeds of the differentobstacles. As an alternative, the controller device 120 may be operative todetermine the obstacle-specific speeds based on respective categories of theobstacles in the environment 100. For instance, walls or furniture can be setto remain static (i.e., with zero maximum speed), other robots or vehicles canbe set to move at their (known) respective maximum speeds, persons can beset to move at 3 m / s, and the like. In practice, considering different maximumspeeds, either object-specific speeds or maximum speeds which are specific for a type of obstacle, can be achieved by utilizing separate SDFs, one foreach maximum speed. For example, the controller device 120 may beoperative to utilize an SDFstatfor static objects such as walls and furniture(with ^max = 0), an SDFper for persons (with ^max = 3 m / s), an SDFrob formobile robots (with ^max = 5 m / s), and so forth, evaluating each SDF inaccordance with Equation (2).The controller device 120 may further be operative to categorizeobstacles in the environment 100 based on one or more of: the current map,the sensor data, and the information derived therefrom. Thereby, obstacles inthe environment 100 can be categorized according to different types, e.g.,static objects (walls, furniture, etc), persons (moving at some specificmaximum speed, e.g., 3 m / s), other mobile robots (moving at some specificmaximum speed), and so forth. The categorization of obstacles may also bebased on an architectural drawing of the environment 100, in particular toidentify static obstacles. In the following, embodiments of a method 600 of controlling a mobilerobot 130 are described with reference to Fig. 6. The method is performed bya controller device 120 and comprises receiving 601 sensor data, orinformation derived therefrom. The sensor data captures an environment 100in which the mobile robot 130 moves. The method 600 further comprisescreating 602 a current map representing the environment 100. The currentmap is created based on the sensor data or the information derivedtherefrom. The method 600 further comprises planning 603 a nominaltrajectory 111 of the mobile robot 130. The nominal trajectory 111 is plannedbased on the current map. The method 600 further comprisesdetermining 604 a nominal control command which is to be executed by themobile robot 130. The nominal control command is determined based on thenominal trajectory 111. The method 600 further comprises determining 607one or more safe control commands which are to be executed by the mobilerobot 130, and which result in a safe trajectory 113. The one or more safecontrol commands are determined based on the current map and the nominaltrajectory 111, with all obstacles 101 in the environment 100 represented bythe current map moving towards the mobile robot 130 at a maximum speed.The determined one or more safe control commands minimize the distancebetween the safe trajectory 113 and the nominal trajectory 111. Themethod 600 further comprises transmitting 608 the nominal control commandand the one or more safe control commands to the mobile robot 130.The maximum speed may be a maximum speed at which obstacles 101can move in the environment 100.The one or more safe control commands may be determined 607 basedon the current map and the nominal trajectory 111 with the obstacles 101moving towards the mobile robot 130 at obstacle-specific speeds. Themethod 600 may further comprise determining 606 the obstacle-specificspeeds based on the sensor data or the information derived therefrom.Alternatively, the method 600 may further comprise determining 606 theobstacle-specific speeds based on a category of the obstacles 101.The method 600 may further comprise categorizing 605 obstacles 101in the environment 100 based on one or more of: the current map, the sensordata, and the information derived therefrom. The one or more safe control commands may be determined 607further based on a sensing area of a sensor 305 which is movable with themobile robot 130 and which has captured the sensor data. For instance, theone or more safe control commands may be determined 607 further basedon the current map augmented by an obstacle 105 representing a boundaryof the sensing area of the sensor 305 and which is moving towards themobile robot 130 at a maximum speed. The one or more safe controlcommands may be determined 607 further based on a current speed of themobile robot 130.It will be appreciated that the method 600 may comprise additional,alternative, or modified, steps in accordance with what is describedthroughout this disclosure. An embodiment of the method 600 may beimplemented as the computer program 203 comprising instructions which,when the computer program 203 is executed by one or moreprocessor(s) 201 comprised in the controller device 120, cause the controllerdevice 120 to carry out the method 600 and become operative in accordancewith embodiments of the invention described herein. The computerprogram 203 may be stored in a computer-readable data carrier, such as thememory 202. Alternatively, the computer program 203 may be carried by adata carrier signal, e.g., downloaded to the memory 202 via thecommunications interface circuitry 204.In the following, embodiments of a method 700 of controlling a mobilerobot 130 are described with reference to Fig. 7. The method 700 isperformed by a mobile robot 130 and comprises receiving 703 a nominalcontrol command and one or more safe control commands, which are to beexecuted by the mobile robot 130. The nominal control command and theone or more safe control commands are received from a controllerdevice 120. The method 700 further comprises executing 704 the nominalcontrol command. The method 700 further comprises initiating executing 706the one or more safe control commands. Executing the one or more safecontrol commands is initiated in response to determining 705 that asubsequent nominal control command is not received from the controllerdevice 120 during a waiting time interval Twait since reception of the nominalcontrol command. The method 700 may further comprise aborting 708 execution of anyremaining safe control commands of the one or more safe controlcommands, and executing 709 a subsequent nominal control command. Theexecution of any remaining safe control commands is aborted, and thesubsequent nominal control command is executed, in response toreceiving 707 the subsequent nominal control command while the mobilerobot 130 executes the one or more safe control commands.The method 700 may further comprises capturing 701 sensor datausing one or more sensors 305 which are movable with the mobile robot 130,and transmitting 702 the sensor data, or information derived therefrom, to thecontroller device 120. The sensor data represents an environment 100 inwhich the mobile robot 130 moves. The method 700 may further comprises stopping the mobile robot 130after the last safe control command of the one or more safe control commands has been executed. It will be appreciated that the method 700 may comprise additional,alternative, or modified, steps in accordance with what is describedthroughout this disclosure. An embodiment of the method 700 may beimplemented as the computer program 303 comprising instructions which,when the computer program 303 is executed by one or moreprocessor(s) 301 comprised in the mobile robot 130, cause the mobilerobot 130 to carry out the method 700 and become operative in accordancewith embodiments of the invention described herein. The computerprogram 303 may be stored in a computer-readable data carrier, such as thememory 302. Alternatively, the computer program 303 may be carried by adata carrier signal, e.g., downloaded to the memory 302 via thecommunications interface circuitry 304.The person skilled in the art realizes that the invention by no means is limited to the embodiments described above. On the contrary, many modifications and variations are possible within the scope of the appended claims.

Claims

CLAIMS 1. A controller device (120) for controlling a mobile robot (130),comprising processing circuitry (200) causing the controller device to becomeoperative to: receive (512) sensor data, or information derived therefrom, capturingan environment (100) in which the mobile robot (130) moves,create (521) a current map representing the environment (100) basedon the sensor data or the information derived therefrom,plan (522) a nominal trajectory (111) of the mobile robot (130) based onthe current map, determine (523) a nominal control command, to be executed by themobile robot (130), based on the nominal trajectory (111),determine (524) one or more safe control commands, to be executed bythe mobile robot (130) and resulting in a safe trajectory (113), based on thecurrent map and the nominal trajectory (111), with all obstacles (101) in theenvironment (100) represented by the current map moving towards themobile robot (130) at a maximum speed, which one or more safe controlcommands minimize the distance between the safe trajectory (113) and thenominal trajectory (111), andtransmit (525) the nominal control command and the one or more safecontrol commands to the mobile robot (130).

2. The controller device (120) according to claim 1, wherein themaximum speed is a maximum speed at which obstacles (101) can move inthe environment (100).

3. The controller device (120) according to claim 1 or 2, operative todetermine (524) the one or more safe control commands based on thecurrent map and the nominal trajectory (111) with the obstacles (101) movingtowards the mobile robot (130) at obstacle-specific speeds.

4. The controller device (120) according to claim 3, operative todetermine the obstacle-specific speeds based on the sensor data or theinformation derived therefrom.

5. The controller device (120) according to claim 3, operative todetermine the obstacle-specific speeds based on a category of theobstacles (101).

6. The controller device (120) according to any one of claims 1 to 5,further operative to categorize obstacles in the environment (100) based onone or more of: the current map, the sensor data, and the information derivedtherefrom.

7. The controller device (120) according to any one of claims 1 to 6,operative to determine (524) the one or more safe control commands furtherbased on a sensing area of a sensor (305) which is movable with the mobilerobot (130) and has captured (511) the sensor data.

8. The controller device (120) according to claim 7, operative todetermine (524) the one or more safe control commands further based on thecurrent map augmented by an obstacle (105) representing a boundary of thesensing area of the sensor and moving towards the mobile robot (130) at amaximum speed.

9. The controller device (120) according to claim 8, operative todetermine (524) the one or more safe control commands further based on acurrent speed of the mobile robot (130).

10. The controller device (120) according to any one of claims 1 to 9,wherein each control command is indicative of a change in a pose of themobile robot (130).

11. A mobile robot (130) comprising processing circuitry (300) causingthe mobile robot to become operative to: receive (525) a nominal control command and one or more safe controlcommands, to be executed by the mobile robot (130), from a controllerdevice (120),execute (514) the nominal control command, andin response to determining (515) that a subsequent nominal controlcommand (526) is not received from the controller device (120) during awaiting time interval (Twait) since reception (525) of the nominal controlcommand, initiate (516) executing the one or more safe control commands.

12. The mobile robot (130) according to claim 11, further operative, inresponse to receiving (527) a subsequent nominal control command whilethe mobile robot (130) executes the one or more safe control commands, to:abort (517) execution of any remaining safe control commands of theone or more safe control commands, andexecute (518) the subsequent nominal control command.

13. The mobile robot (130) according to claim 11 or 12, furtheroperative to: capture (511) sensor data using one or more sensors (305) which aremovable with the mobile robot (130), the sensor data representing anenvironment (100) in which the mobile robot (130) moves, andtransmit (512) the sensor data, or information derived therefrom, to thecontroller device (120).

14. The mobile robot (130) according to any one of claims 11 to 13,further operative to stop after the last safe control command of the one ormore safe control commands has been executed.

15. The mobile robot (130) according to any one of claims 11 to 14,wherein each control command is indicative of a change in a pose of themobile robot (130).

16. A method (600) of controlling a mobile robot (130), the methodbeing performed by a controller device (120) and comprising:receiving (601) sensor data, or information derived therefrom, capturingan environment (100) in which the mobile robot (130) moves,creating (602) a current map representing the environment (100) basedon the sensor data or the information derived therefrom, planning (603) a nominal trajectory (111) of the mobile robot (130)based on the current map, determining (604) a nominal control command, to be executed by themobile robot (130), based on the nominal trajectory (111),determining (607) one or more safe control commands, to be executedby the mobile robot (130) and resulting in a safe trajectory (113), based onthe current map and the nominal trajectory (111), with all obstacles (101) inthe environment (100) represented by the current map moving towards themobile robot (130) at a maximum speed, which one or more safe controlcommands minimize the distance between the safe trajectory (113) and thenominal trajectory (111), andtransmitting (608) the nominal control command and the one or moresafe control commands to the mobile robot (130).

17. The method (600) according to claim 16, wherein the maximumspeed is a maximum speed at which obstacles (101) can move in theenvironment (100).

18. The method (600) according to claim 16 or 17, wherein the one ormore safe control commands are determined (607) based on the current mapand the nominal trajectory (111) with the obstacles (101) moving towards themobile robot (130) at obstacle-specific speeds.

19. The method (600) according to claim 18, further comprisingdetermining (606) the obstacle-specific speeds based on the sensor data orthe information derived therefrom.

20. The method (600) according to claim 18, further comprisingdetermining (606) the obstacle-specific speeds based on a category of theobstacles (101).

21. The method (600) according to any one of claims 16 to 20, furthercomprising categorizing (605) obstacles (101) in the environment (100)based on one or more of: the current map, the sensor data, and the information derived therefrom.

22. The method (600) according to any one of claims 16 to 21, whereinthe one or more safe control commands are determined (607) further basedon a sensing area of a sensor (305) which is movable with the mobilerobot (130) and has captured the sensor data.

23. The method (600) according to claim 22, wherein the one or moresafe control commands are determined (607) further based on the currentmap augmented by an obstacle (105) representing a boundary of the sensingarea of the sensor (305) and moving towards the mobile robot (130) at amaximum speed.

24. The method (600) according to claim 23, wherein the one or moresafe control commands are determined (607) further based on a currentspeed of the mobile robot (130).

25. The method (600) according to any one of claims 16 to 24, whereineach control command is indicative of a change in a pose of the mobilerobot (130).

26. A method (700) of controlling a mobile robot (130), the methodbeing performed by the mobile robot (130) and comprising:receiving (703) a nominal control command and one or more safecontrol commands, to be executed by the mobile robot (130), from acontroller device (120),executing (704) the nominal control command, andin response to determining (705) that a subsequent nominal controlcommand is not received from the controller device (120) during a waitingtime interval (Twait) since reception of the nominal control command, initiatingexecuting (706) the one or more safe control commands.

27. The method (700) according to claim 26, further comprising, inresponse to receiving (707) a subsequent nominal control command whilethe mobile robot (130) executes the one or more safe control commands:aborting (708) execution of any remaining safe control commands of theone or more safe control commands, andexecuting (709) the subsequent nominal control command.

28. The method (700) according to claim 26 or 27, further comprising:capturing (701) sensor data using one or more sensors (305) which aremovable with the mobile robot (130), the sensor data representing anenvironment (100) in which the mobile robot (130) moves, andtransmitting (702) the sensor data, or information derived therefrom, tothe controller device (120).

29. The method (700) according to any one of claims 26 to 28, furthercomprising stopping the mobile robot (130) after the last safe controlcommand of the one or more safe control commands has been executed.

30. The method (700) according to any one of claims 26 to 29, whereineach control command is indicative of a change in a pose of the mobilerobot (130).

31. A computer program (203) comprising instructions which, when thecomputer program (203) is executed by one or more processors (201)comprised in a controller device (120), cause the controller device (120) tocarry out the method (600) according to any one of claims 16 to 25.

32. A computer program (303) comprising instructions which, when thecomputer program (303) is executed by one or more processors (301)comprised in a mobile robot (130), cause the mobile robot (130) to carry outthe method (700) according to any one of claims 26 to 30.

33. A computer-readable data carrier (202; 302) having stored thereonthe computer program (203; 303) according to claim 31 or 32.

34. A data carrier signal carrying the computer program (203; 303)according to claim 31 or 32.

Citation Information

Patent Citations

  • Unmanned vehicle (UV) control system

    US9567077B2

  • Robot remote control method and system, and building in which robot robust against communication latency is driven

    WO2022211224A1