Method for operating a safety guard unit in a control device, in particular for automotive applications
The safety guard unit addresses the challenge of managing access requests from both vehicle and user functions by integrating an arbitration unit for safe and smooth actuator control, preventing collisions and ensuring reliable operation.
Patent Information
- Application Number
- PCT/EP2025/053850
- Authority / Receiving Office
- WO · WO
- Patent Type
- Applications
- Current Assignee / Owner
- Priority Date
- 2024-02-13
- Filing Date
- 2025-02-13
- Publication Date
- 2025-08-21
AI Technical Summary
Existing safety guard units in automotive control units struggle to manage access requests from both vehicle-implemented and user-implemented vehicle functions to safety-relevant actuators, leading to potential safety-critical collisions without adequate prioritization and arbitration.
A safety guard unit that integrates an arbitration unit to prioritize and coordinate control specifications from both vehicle-implemented and user-implemented functions based on predefined rules and vehicle states, ensuring safe and smooth actuator control by limiting and smoothing control inputs.
Ensures safe and reliable operation of safety-relevant actuators by preventing collisions and sudden changes, allowing user-implemented functions to access actuators while maintaining vehicle-implemented functions' availability and safety.
Smart Images

Figure EP2025053850_21082025_PF_FP_ABST
Abstract
Description
[0001] Description
[0002] title
[0003] Method for operating a safety guard unit in a control unit, in particular for automotive applications
[0004] Technical area
[0005] The invention relates to a safety guard for automotive applications, in particular for implementation in a control unit. In particular, the present invention relates to a safety guard that, in addition to conventional vehicle functions, also monitors functions from unknown sources that attempt to gain access to vehicle-implemented actuators.
[0006] Technical background
[0007] A safety guard in an automotive control unit coordinates and safeguards the control of actuators. This is particularly necessary for all actuators whose operation may be safety-relevant. These include, for example, electric motors for adjusting vehicle equipment such as power windows, windshield wipers, and the like.
[0008] In particular, vehicle assistance systems that can be supplemented with user-defined vehicle functions from an unknown source, e.g., by installing a software app, can grant these functions access to safety-relevant actuators in the vehicle and thus compete with actuator requirements from vehicle-implemented vehicle functions or actuator requirements from operating instructions.
[0009] While Safety Guard units currently coordinate functionality requests and actuator commands from vehicle-implemented vehicle functions and operating specifications, the continued consideration of control specifications from user-specific vehicle functions cannot be easily controlled with regard to safety aspects, as these access particularly safety-relevant actuators without using the Safety Guard unit. In particular, it must be ensured that the permanently vehicle-implemented vehicle functions have a high level of availability without completely cutting off the user-implemented vehicle functions from access to safety-relevant actuators.
[0010] It is therefore an object of the present invention to provide a possibility to ensure that user-implemented vehicle functions can use safety-relevant actuators without safety-critical collisions with access requests of vehicle-implemented vehicle functions or operating specifications occurring.
[0011] Disclosure of the invention
[0012] According to the invention, a method for operating a vehicle system with a safety guard unit according to claim 1 as well as a safety guard unit and a control unit according to the independent claims are provided.
[0013] Further embodiments are specified in the dependent claims.
[0014] According to a first aspect, a method for operating a vehicle system is provided, comprising the following steps:
[0015] - Obtaining a control specification for controlling an actuator of at least one of user-implemented vehicle functions, for example in the form of software apps installed on a vehicle system according to a user request, of vehicle-implemented vehicle functions and in particular of an operating device;
[0016] - Prioritizing and selecting one of the control specifications according to prioritization rules in a Safety Guard unit;
[0017] - Actuator control depending on the selected control specification. User-implemented vehicle functions, for example in the form of software apps installed on a data processing unit of a vehicle system or, for example, a vehicle assistance system, may require access to safety-relevant actuators in the vehicle. To ensure that these user-implemented vehicle functions are permitted to access the actuators in order to control them according to the relevant vehicle function, these are currently arbitrated or prioritized outside the Safety Guard unit. However, this can lead to safety-relevant restrictions on vehicle-implemented vehicle functions if they are denied access to a vehicle-implemented actuator at a specific time.
[0018] The invention therefore provides for a safety guard unit that takes into account not only the vehicle-implemented vehicle functions but also user-implemented vehicle functions. Thus, all control specifications in the form of actuator requests resulting from vehicle-implemented vehicle functions and user-implemented vehicle functions can be treated equally, and the control specifications can be handled according to a predefined arbitration and prioritization. Control specifications correspond to a request for the activation of an actuator.
[0019] In addition, joint coordination in a Safety Guard unit enables the vehicle-implemented vehicle functions to be used to control the corresponding actuator in the event of certain events.
[0020] Furthermore, through joint arbitration in an arbitration unit in the Safety Guard unit, the control of vehicle actuators can also be made dependent on vehicle states.
[0021] It can be provided that prioritization is carried out according to prioritization rules determined using a behavior model based on vehicle states, so that the prioritization of the individual control specifications can be carried out based on vehicle states. For this purpose, prioritization rules can be defined depending on the vehicle state. Thus, using the vehicle states, it can be determined whether access to an actuator can be permitted by a user-implemented and / or vehicle-fixed vehicle function and / or operating specification, or whether this must be prevented for safety reasons. Furthermore, a decision can be made whether a requested control of the actuator should be carried out based on a default function.
[0022] Examples of vehicle-implemented vehicle functions can include functions that provide functionality requests or actuator commands. Functionality requests request the execution of a safety-relevant function by another component, function, or software app, such as a vehicle camera requesting a windshield wipe to provide a clear view through the windshield for the camera. Furthermore, actuator control can be provided directly by another component, vehicle function, or software app, such as a vehicle camera requesting a windshield wiper to wipe a specific area of the windshield at a specified frequency to maintain a clear view.
[0023] Furthermore, operating specifications may exist according to a user request that have a direct influence on the operating function of the actuator in question, for example, a user can switch from an automatic windshield wiper to a predetermined wiping frequency.
[0024] Furthermore, user-implemented vehicle functions in the form of software apps can be connected to the Safety Guard unit and provide requests for the control and / or operation of actuators via the Safety Guard unit.
[0025] The Safety Guard unit can comprise an arbitration unit in which rules are stored that prioritize the individual input sources for the user-implemented vehicle functions, the vehicle-fixed vehicle functions, and for the operating specifications. Prioritization is rule-based, with the rules specifying which of the vehicle functions or operating specifications have priority. In particular, prioritization can be performed such that the operating specifications receive the highest priority, the vehicle-implemented vehicle functions the next lowest priority, and the user-implemented vehicle functions the lowest priority. Furthermore, prioritization, i.e. the implemented rules, can be dependent on a vehicle state. The arbitration unit can be provided to control a selection unit that makes the actual selection from one of the input sources.
[0026] The arbitration unit can control the at least one actuator directly or via a fader unit, which provides the corresponding control signal in such a way that jumps in the control of the at least one actuator are avoided as much as possible. If multiple actuators are connected to the Safety Guard unit, a separate fader unit can be provided for each of the multiple actuators.
[0027] Furthermore, depending on the vehicle state, the actuator can be controlled using the selected control specification or a default control specification. If certain vehicle states exist, it may be specified under certain circumstances that the vehicle actuator may not be controlled. This is decided based on the vehicle states in a decision matrix, which, if necessary, sets the control variable for the actuator to a default value via a switch. Safeguarding in the Safety Guard unit is particularly useful when the user-implemented vehicle functions include or are based on machine learning-based models, since unwanted control specifications for the actuators can also be generated by the machine learning models. These can be intercepted appropriately using the Safety Guard unit.
[0028] It can be provided that a control specification of a user-implemented vehicle function is limited to a specified value range, so that only technically permissible control specifications are forwarded to the arbitration unit. For example, wiping area requirements can be limited according to the control specifications for a windshield wiper so that the wiper blade does not collide with the A-pillars.
[0029] It can be provided that, in the event of a sudden change in the prioritized control input, the actuator is controlled using a control input from a transition trajectory or in a smoothed manner. The sudden change can be detected by monitoring a gradient of the control input when its magnitude exceeds a specified threshold.
[0030] According to a further aspect, an apparatus for carrying out the above method is provided.
[0031] According to a further aspect, a safety guard unit for a vehicle system is provided, comprising:
[0032] - a selection unit for selecting a control specification for controlling an actuator of at least one of user-implemented vehicle functions, for example in the form of software apps installed on a data processing unit of the vehicle system at a user request, of vehicle-implemented vehicle functions and in particular an operating function;
[0033] - an arbitration unit which is designed to use the selected control specification according to prioritization rules which are determined in particular as a function of a vehicle state, to control the actuator.
[0034] Brief description of the drawings
[0035] Embodiments are explained in more detail below with reference to the attached drawings. They show:
[0036] Figure 1 shows a schematic block diagram of the coordination of
[0037] Control specifications by a Safety Guard unit; and
[0038] Figure 2 shows a flowchart illustrating a method for operating a Safety Guard unit. Description of embodiments
[0039] Figure 1 shows a block diagram of a system 1 with a safety guard unit 2 for coordinating a large number of implemented vehicle functions 3, 4 and operating functions 5, which can provide control specifications for safety-relevant vehicle-mounted actuators 6.
[0040] The vehicle functions 3, 4 and the operating functions 5 are connected to one or more actuators 6 via the safety guard unit 2. The safety guard unit 2 controls the control specifications of the vehicle functions 3, 4 and the operating function 5 and forwards a selected one of the control specifications or a control specification generated from a combination of several control specifications to the relevant actuator 6.
[0041] The vehicle functions 3, 4 can include user-implemented vehicle functions 3 in the form of software apps that are implemented in a vehicle assistance system according to a user request and may originate from an uncertain source, and fixed vehicle-implemented vehicle functions 4 as input sources that are already implemented by the manufacturer in vehicle assistance systems as a software function and / or as a hardware function.
[0042] Furthermore, operating devices that enable user operation according to an operating function can generate operating specifications that are also taken into account as control specifications in the Safety Guard Unit 2.
[0043] The Safety Guard unit 2 receives all control specifications from the input sources 3, 4, 5 and prioritizes them in an arbitration unit 21. The arbitration unit 21 comprises a rule-based system that implements prioritization rules for prioritizing the control specifications based on a behavior model. The behavior model can be implemented in a behavior block 22, which receives information about vehicle states FZ provided externally by the Safety Guard unit 2, such as speed, ambient temperature, rain sensor data, user inputs via HMIs, and the like, and provides the prioritization rules for the arbitration unit 21 based on the vehicle states FZ. The arbitration unit 21 controls a selection unit 23, which selects the control specifications based on the specification of the arbitration unit 21.
[0044] Since the user-implemented vehicle functions are generally untested and can be implemented in a questionable manner (since they often come from an unknown source), and can also be implemented using machine learning models, fuzzy logic, etc., the control specifications may also lie outside of permissible ranges. This could result in the corresponding actuator being operated within an impermissible operating range due to a control specification. Therefore, a limiting unit 26 can be provided for the user-implemented vehicle functions 3, which limits the value range of the control specifications in order to exclude prohibited value ranges even before arbitration.
[0045] To avoid sudden changes in control specifications, the control specification selected or prioritized by the selection unit 23 can be forwarded to a fader unit 24, which smooths the value of the control specification in the form of a transition trajectory when jumps occur. This can be implemented by applying a PT 1 element or by simple linear or other monotonic transition functions.
[0046] Furthermore, a switching unit 27 can be provided which, depending on a vehicle state FZ which is evaluated by a decision unit 25, applies the prioritized control specification or the control specification provided by the fader unit 24 to the actuator 6 or applies a default value DW if the vehicle state FZ indicates an extraordinary event.
[0047] For example, the default value can include turning off actuator 6 (e.g., specifying a control value of 0 as the default value). For example, the vehicle state can be determined to be an open hood, so the windshield wiper should not be activated because a technician might have their hands near moving parts. In this case, the windshield wiper is prevented from activating.
[0048] Figure 2 shows a flow chart illustrating a method for operating the Safety Guard unit 2 of Figure 1 .
[0049] In step S1, control specifications are first received from the vehicle functions and the operating functions.
[0050] Using the behavior model, the vehicle states FZ are evaluated in step S2 and prioritization rules are generated.
[0051] The prioritization rules are provided to the arbitration unit 21 in step S3.
[0052] In step S4, the available control specifications are prioritized according to the prioritization rules and selected in the selection unit 23. The highest-priority control specification is forwarded to the fader unit 24.
[0053] In step S5, the fader unit 24 checks whether there is a sudden change in the control input. If this is the case, a transition trajectory is provided for the control input, and the control input is forwarded to the actuators 6 according to the transition trajectory for the duration of the transition.
[0054] Furthermore, in step S6, a check is carried out to determine whether a vehicle state FZ exists that requires that none of the control specifications be considered. In this case, a default control specification DW is forwarded to the relevant actuator 6 as the control specification. The default control specification DW can stipulate that the relevant actuator 6 is deactivated. Otherwise, the control specification provided by the fader unit 24 is forwarded to the actuator 6.
[0055] In step S7, the actuator 6 is controlled with the corresponding control specification.
Claims
Claims 1. A method, in particular an at least partially computer-implemented method, for operating a vehicle system, comprising the following steps: - Obtaining (S1) a control specification for controlling an actuator (6) of at least one of user-implemented vehicle functions (3), for example in the form of software apps installed on a data processing unit of the vehicle system at a user request, of vehicle-implemented vehicle functions (4) and in particular an operating function (5); - Prioritizing and selecting (S2, S3) one of the control specifications (3, 4, 5) according to prioritization rules in a safety guard unit (2); - Control (S7) of the actuator (6) depending on the selected control specification.
2. The method according to claim 1, wherein the prioritization is performed according to prioritization rules determined using a behavior model based on vehicle states (FZ).
3. Method according to claim 1 or 2, wherein, depending on a vehicle state (FZ), the control of the actuator (6) is carried out with the selected control specification or with a default control specification (DW).
4. Method according to one of claims 1 to 3, wherein in the event of a sudden change in the prioritized control specification, the control of the actuator (6) is carried out using a control specification of a transition trajectory.
5. The method according to one of claims 1 to 4, wherein a control specification of a user-implemented vehicle function is limited to a predetermined value range.
6. Device for carrying out one of the methods according to one of the Claims 1 to 5.
7. Safety guard unit (2) for a vehicle system, comprising: - a selection unit (23) for selecting a control specification for controlling an actuator (6) of at least one of user-implemented vehicle functions (3), for example in the form of software apps installed on a data processing unit of the vehicle system at a user request, of vehicle-implemented vehicle functions (4) and in particular of an operating function (5); - an arbitration unit (21) which is designed to use the selected control specification according to prioritization rules which are determined in particular as a function of a vehicle state, to control the actuator (6).
8. A computer program product comprising instructions which, when the program is executed by at least one data processing device, cause the device to carry out the steps of the method according to one of claims 1 to 5.
9. A machine-readable storage medium comprising instructions which, when executed by at least one data processing device, cause the device to carry out the steps of the method according to one of claims 1 to 5.
Citation Information
Patent Citations
CONTROL DEVICE FOR A VEHICLE, MANAGER, PROCESS, NON-TRANSITORIAL STORAGE MEDIUM AND VEHICLE
DE102021215055A1
Methods for controlling access to different applications in a vehicle
DE102022208003A1
Vehicular arbitration system
EP3640798A1
Vehicle control system, vehicle, and control method
US20220315025A1