Technique for checking the safety of trajectories

WO2025185880A8PCT designated stage Publication Date: 2025-10-02ROBERT BOSCH GMBH
View PDF 0 Cites 0 Cited by

Patent Information

Application Number
PCT/EP2025/052107
Authority / Receiving Office
WO · WO
Patent Type
Applications
Current Assignee / Owner
Priority Date
2024-03-05
Filing Date
2025-01-28
Publication Date
2025-10-02

AI Technical Summary

Technical Problem

Existing automated vehicle systems face challenges in navigating complex and rapidly changing environments while ensuring safety, as they often fail to meet safety standards such as ISO 21212 (Functional Safety) and ISO 21448 (SOTIF), particularly in situations where multiple paths and probabilistic components are required for safe trajectory planning.

Method used

A method for safety checking trajectories in automated vehicles involves classifying states and zones based on safety objectives, filtering trajectories that are temporarily safe (TS) and invariably safe (IS), and using probabilistic estimates to ensure compliance with safety standards, allowing for contingency planning and selection of the best available trajectory.

Benefits of technology

This approach enhances the safety of automated journeys by ensuring compliance with safety standards, enabling gentle driving styles, and providing contingency plans, thereby improving driving comfort and reliability in dynamic traffic scenarios.

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure EP2025052107_02102025_PF_FP_ABST
    Figure EP2025052107_02102025_PF_FP_ABST
Patent Text Reader

Abstract

A technique for checking the safety of a trajectory in a planning cycle for a vehicle operated in an at least partially automated manner comprises a method in which an environment model associated with a planning cycle and representing a dynamic development of a traffic scene is read in (S104) for the vehicle. States and zones are classified (S107) for the vehicle according to a safety objective, based on assumptions and / or safe control laws with regard to the read-in (S104) environment model. A zone classified (S107) according to the safety objective comprises a set of states classified (S107) according to the one safety objective. A list of trajectories to be checked is received (S110) and filtered twice. The intermediate result of the first filtering (S114) comprises only trajectories whose states have been classified (S107) as at least temporarily safe in the planning cycle and which, after the planning cycle, lead into a zone that is classified (S107) as at least invariably safely transferable. The second filtering (S116) comprises a probability estimation with regard to a validity of the assumptions and / or safe control laws concerning the read-in (S104) environment model.
Need to check novelty before this filing date? Find Prior Art

Description

[0001] Description

[0002] title

[0003] Trajectory safety check technology

[0004] The patent application relates to a technology for safety checking a trajectory in a planning cycle for an at least partially automated vehicle or another at least partially automated system. In particular, a method, a safety check module, a system comprising the safety check module, a computer program, and a computer-readable storage medium are provided.

[0005] State of the art

[0006] Automated vehicles must navigate complex situations, some of which can change rapidly and unexpectedly. To solve the driving task, systems are therefore required that are highly safety-critical or that meet safety objectives. From the perspective of functional safety (ISO 21212) and safety of intended functionality (SOTIF; ISO 21448), a multi-path architecture in which at least two planning modules generate trajectories is ideal for such a system.

[0007] Methods for motion planning of a system are known. In [1, 2], the content of which is incorporated herein by reference, a first invariant set around the ego vehicle and a further invariant set as the target region are determined based on the ego state. An invariant set is generally understood to be a set of states, where the states are invariantly secure (IS) with respect to time.

[0008] Set-based methods are presented in [2], but without a probabilistic component. In [4], the content of which is incorporated herein by reference, set-based methods are combined with probabilistic methods for evaluating (fixed and non-modifiable) trajectories. An evaluation is performed in the planning module itself. Analogous to [1], planning in [4] is performed from IS zone to IS zone. Trajectory selection is based on safety and performance (cost function) criteria and addresses SOTIF.

[0009] Another method by Cui et al. in [3], the content of which is incorporated herein by reference, does not use set-based approaches and thus does not use IS zones.

[0010] To guarantee safe, at least partially automated driving, both standards ISO 21212 (Functional Safety) and ISO 21448 (SOTIF) must be met.

[0011] Disclosure of the invention

[0012] The solution according to the invention is described below with reference to the claimed method for security checking a trajectory in a planning cycle for an at least partially automated vehicle. Features, advantages or alternative embodiments herein can in principle be assigned to the respective other claimed subject matter (e.g., to the security check module, the system, the computer program or a computer program product) and vice versa. In other words: the claims for the security check module and / or the system comprising the security check module can be improved by features that are described or claimed in connection with the method and vice versa. In this case, the functional features of the method are embodied by structural units of the security check module and / or the system and vice versa.

[0013] According to one method aspect, a (particularly computer-implemented) method for safety checking a trajectory in a planning cycle for an at least partially automated system, in particular a vehicle, is provided. The method comprises a step of reading in an environment model assigned to a planning cycle for the at least partially automated system, in particular a vehicle (e.g., from an environment model memory). The environment model represents, in particular, a dynamic development of a traffic scene around the at least partially automated vehicle. The method further comprises a step of classifying states and zones according to at least one safety objective (e.g.,at least one first safety target for the states and at least one second safety target for the zones) for the at least partially automated vehicle based on assumptions regarding the read-in environment model and / or based on safe control laws with regard to the read-in environment model. A zone classified according to the at least one (e.g. second) safety target comprises at least a set of states classified according to the at least one (e.g. first) safety target. In particular, the states can be classified based on the assumptions and the zones based on the safe control laws. The assumptions can be read from an assumption memory. Alternatively or additionally, the safe control laws can be read from a control law memory.

[0014] The method further comprises a step of receiving a list of trajectories to be checked for the planning cycle for the at least partially automated vehicle (e.g., from at least two planning modules). The method further comprises a step of first filtering the received list of trajectories. An intermediate result of the first filtering includes only trajectories whose states were classified at least as temporarily safe (TS) in the planning cycle and which, after the end of the planning cycle, lead into a zone that was classified at least as invariably safe transferable (IS transferable).The method further comprises a step of a second filtering of the intermediate result of the first filtering of the list of trajectories based on a probability estimate regarding the validity of the assumptions regarding the read-in environmental model and / or the validity of the safe control laws regarding the read-in environmental model, at least during the planning cycle. The result of the second filtering of the list includes only trajectories (e.g., only one trajectory) whose probability estimate exceeds a threshold value of the at least one (e.g., first and / or second) safety objective.

[0015] Using the technology for safety checking a trajectory in a planning cycle for an at least partially automated vehicle, the safety of an at least partially automated journey can be improved, particularly with regard to situations that can change quickly and at least partially unexpectedly. Furthermore, a gentle driving style for components of the at least partially automated vehicle can be enabled and / or driving comfort can be ensured within the framework of safe trajectories. In particular, the method can act as a filter and sort out trajectories as not suitable for at least partially automated operation if no formal safety is guaranteed (e.g., no at least TS states and / or no IS transferable zone can be traversed). Alternatively or additionally, the technology canThe system can select the best available trajectory based on the available trajectory (e.g., the at least partially automated vehicle and other road users in the traffic scene, also known as the surrounding area). If no reliable trajectory has been received, a suitably modified trajectory can be provided. Alternatively or additionally, the technology also enables contingency planning.

[0016] The traffic scene refers to the environment of the at least partially automated vehicle. The traffic scene can include at least one other road user in addition to the at least partially automated vehicle (also known as the ego vehicle), in particular another vehicle, a pedestrian, a motorcyclist, and / or a cyclist. The traffic scene is represented in the environment model.

[0017] The vehicle (e.g., one operated at least partially automatically and / or other) can in particular be a road-based vehicle (e.g., a car or truck) with automatic or partially automated driving functionality in (in particular, a high, e.g., L4 or L5, level below) levels L1 to L5. Automated operation can comprise full automation (also referred to as autonomous driving, in particular L5), at least partial automation (e.g., high, L4, conditional, L3, or partial, L2), and / or a driver assistance system (e.g., L1, comprising adaptive cruise control). For example, partially automated driving functionality can comprise a traffic jam pilot, which is, for example, only used in limited areas and / or limited time phases. Alternatively or additionally, the at least partially automated system can comprise a robot, which can move, in particular, on a factory site.The vehicle for which the safety check of a trajectory is to be performed can also be referred to as the ego vehicle, in contrast to the other vehicles in a traffic scene.

[0018] The traffic scene and / or the environment model (particularly dynamic and / or updated for each planning cycle) can be captured or created based on sensor data from sensors (e.g., video cameras, radar sensors, and / or LiDAR sensors, particularly on the vehicle). The environment model can comprise one agent per road user (e.g., one agent for the at least partially automated vehicle and one agent for each additional road user). The dynamic development of the traffic scene can include predicting and / or negotiating the agendas of the other road users.

[0019] The traffic scene evolves over time. This is captured (especially by sensors). A state of the traffic scene refers to the state of the traffic scene in a particular period.

[0020] For example, the environment model can be updated every 100ms, corresponding to a frequency of 10Hz.

[0021] The traffic scene (also: the surroundings and / or environment) of the at least partially automated vehicle can be spatially limited by a maximum range of one or more sensors from which the sensor data is received and / or by a maximum distance from the at least partially automated vehicle. For example, the maximum range of a LiDAR sensor can be up to 200 m. Alternatively or additionally, the extent and / or visibility of the surroundings can depend on the speed of the at least partially automated vehicle.

[0022] The surroundings of the at least partially automated vehicle can comprise at least one area in the direction of travel in front of the at least partially automated vehicle, and preferably also behind the at least partially automated vehicle. According to a further exemplary embodiment, the surroundings can further comprise an area to the side of the at least partially automated vehicle, for example, a parallel lane and / or an opposite lane to a lane traveled by the at least partially automated vehicle.

[0023] The traffic scene may be asymmetrical around the at least partially automated vehicle. For example, more sensors (and / or sensors with a longer range) may be directed forward (and / or rearward) than to the sides of the at least partially automated vehicle.

[0024] The process for safety checking a trajectory can be executed by a safety check module (also called a module for safety checking input trajectories; or safety checker). The safety check module can be connected downstream of one or more (in particular two) planning modules. The planning module(s) (in particular two) can each plan at least one trajectory (also called an input trajectory) to be checked.

[0025] The list (also: set) of trajectories to be checked can be received by a plurality (in particular two) planning modules.

[0026] The environment model can comprise (in particular by means of the received sensor data) detected objects and / or road users (e.g. pedestrians, cyclists, motorcyclists and / or one or more other vehicles) that are located on a map, in particular a digital map and / or raster map. The detected objects and / or road users can be restricted, in particular based on the map, to those objects and / or road users that can potentially contribute to an obstacle, a conflict situation and / or a dangerous situation. For example, road users moving away from the side and / or rear of the at least partially automated vehicle do not necessarily have to be modeled in the environment model of the at least partially automated vehicle.

[0027] A state of the at least partially automated vehicle (and / or the traffic scene) can be dynamic and / or time-dependent (also: time-state pair). For example, a state can include a position, an orientation, a speed, an acceleration, and / or a steering angle per time.

[0028] A state classified according to at least one (e.g., first) safety objective can preferably be classified into three classes and can be, in particular, invariably safe (IS), temporarily safe (TS), IS-transferable, and / or unsafe. An IS state is guaranteed safe (e.g., being parked in a parking space) at any time (e.g., any relevant time and / or until a predetermined end time, in particular beyond the planning horizon and / or after the end of the planning cycle). Alternatively or additionally, a TS state is safe for a limited period of time (e.g., during the planning cycle). Alternatively or additionally, a IS state is transferable if there are one or more safe control laws by means of which the state can only be transferred to an IS state via TS states.Furthermore, alternatively or additionally, an unsafe condition (particularly during the planning cycle) does not meet the criteria for guaranteed safety (e.g. unavoidable risk of accident, especially with another road user).

[0029] An IS state and / or an IS-transferable state is each TS.

[0030] Alternatively or additionally, zones are sets of states. In particular, IS states can arise solely based on assumptions (e.g., traffic-induced stopping is safe, so states with vanishing speed, v=0, are safe). For example, IS transferable zones arise from the fact that the states contained therein can be transferred to an IS state using one or more of the safe control laws.

[0031] A planning cycle (also: planning phase, planning horizon and / or period until new planning, also: replanning, in technical terms: replanning; in particular for the trajectories of the at least partially automated vehicle) can, for example, comprise up to 20s, for example up to 15s, for example up to 10s, for example up to 8s and / or for example up to 3s.

[0032] A planning cycle can be sampled in several (e.g., one to five) cycles. A cycle (also called a sampling step) can be less than one second long, e.g., between 100 ms (and / or, for example, corresponding to a sampling frequency of 10 Hz) and 500 ms.

[0033] A prediction horizon (especially for the dynamic development of other road users) can vary depending on the automated driving function and / or overall system concept (e.g., between 500 ms and 15 s, and / or, in particular, at least as long as the planning horizon). Alternatively or additionally, the control laws can usually be presented in analytical form, so that a description of the corresponding states can therefore be (at least relatively) independent of the prediction horizon.

[0034] The procedure implemented in the security verification module can be synchronized with the planning of the trajectories to be verified in the one or more (in particular two) planning modules.

[0035] A zone may comprise a set of (in particular presumed and / or determined) states of the at least partially automated vehicle (and / or the traffic scene).

[0036] The classification of zones enables the application of set-based and / or stochastic methods, in particular for probability estimation with regard to the validity of the assumptions, the validity of the safe control laws and / or the achievement of at least one (e.g. first and / or second) safety objective.

[0037] A zone classified according to at least one (e.g., second) safety objective can be IS, IS-transferable, and / or unsafe. An IS zone is the set of IS states (and / or a zone that is safe at all times). Alternatively or additionally, an IS-transferable zone is the set of IS-transferable states (e.g., an intersection can be assigned to an IS-transferable zone for a period of time in which, according to the environmental model, no other road user will enter or enter the intersection) and / or the states that can be converted into an IS state using a safe trajectory. Alternatively or additionally, a TS zone can only be safe for a predetermined period of time, for example, if the environmental model predicts that no other road user will enter a spatial area of ​​the zone. Furthermore, alternatively or additionally, an unsafe zone is the set of unsafe states.

[0038] For example, an intersection can be assigned to an IS transferable zone, for example, if braking (especially in a timely manner) and / or stopping at a stop line is possible. Alternatively or additionally, following another road user (especially a vehicle) can be IS transferable and / or TS. Alternatively or additionally, a zone can be unsafe if conflict-free (and / or accident-free) driving is not possible. A safe trajectory can be TS and / or IS (e.g., for each planned state along the trajectory).

[0039] A (especially safe) trajectory does not necessarily have to start and / or end in an IS zone, especially in contrast to the trajectories used by Pek et al. in [1], [2]. This allows the application scenarios to be significantly expanded or their number increased.

[0040] A set of states that can be reached by means of the (especially safe) trajectories (and / or modified trajectories) can be referred to as a reachable state set.

[0041] For example, a parking trajectory itself is not an IS, since the moving state sequence would cause the vehicle to collide with another vehicle if the at least partial automation were deactivated. If there are one or more safe control laws that transfer the at least partially automated vehicle into an IS state (especially if the parking trajectory is the result of these control laws), the states of the trajectory (also: trajectory points) lie in an IS transferable zone.

[0042] The assumptions regarding the read-in environment model can be independent of the at least partially automated vehicle and / or independent of sensor data, in particular based on which the environment model was created.

[0043] The assumptions regarding the read-in environment model can include assumptions regarding dynamic traffic development, e.g. compliance with locally valid traffic rules and / or an assumption regarding the reasonable behavior of other road users, in technical terms in particular: rational driver assumption, and / or the non-existence of wrong-way drivers.

[0044] A violation (and / or invalidity) of the assumptions can, for example, include a violation of traffic regulations (e.g., another road user exceeding a speed limit, illegally crossing an intersection contrary to traffic lights and / or contrary to a right-of-way rule, and / or a wrong-way driver). The safe control laws can include regulations for regulating and / or controlling the at least partially automated vehicle (e.g., based on vehicle physics and / or technical vehicle specifications, such as braking deceleration). Alternatively or additionally, the safe control laws can include an intelligent driver model (e.g., related to the at least partially automated vehicle). The intelligent driver model can be related to the at least partially automated vehicle (ego vehicle).The Intelligent Driver Model can serve as a basis for the derivation of an adaptive cruise control system, which can be expanded into a safe control system.

[0045] Probabilistic prediction (e.g., of other road users) can include estimating an uncertainty in the form of the set of states assigned to a zone (and / or at least one, e.g., first and / or second, safety objective). This can ensure both functional safety (e.g., according to ISO 21212 - Intelligent Transport Systems - Communications Access for Land Mobiles (CALM) - 2G radio systems) and formally guaranteed safety, in particular safety of the intended functionality (e.g., according to ISO 21448 - Road Vehicles - Safety of Intended Functionality).

[0046] The probability estimate, in particular the threshold value of the at least one (e.g., first and / or second) safety objective, can parameterize a probability that the verified trajectory (and / or a modified trajectory) is safe. For example, falling below the threshold value can indicate that safety of the verified trajectory (and / or the modified trajectory) cannot be guaranteed. Exceeding the threshold value can indicate that the respective trajectory is very likely safe.

[0047] A safety metric (and / or quality function) can be assigned to the probability estimation and / or the achievement of the at least one (e.g., first and / or second) safety objective. The threshold value of the at least one (e.g., first and / or second) safety objective can be a threshold value of the safety metric. In particular, a high value of the safety metric can correspond to a high (and / or probable) safety of the trajectory. Alternatively or additionally, a low value of the safety metric can correspond to a low (and / or improbable) safety of the trajectory.

[0048] The method may further comprise a step of receiving sensor data regarding the dynamic development of the traffic scene around the at least partially automated vehicle. Alternatively or additionally, the method may comprise a step of creating the environment model, in particular using (and / or the) received sensor data.

[0049] The sensor data can be received by at least one sensor system comprising one or more sensors, in particular by a (e.g., video) camera, a radar device, a LiDAR device, an ultrasound device, a motion sensor, and / or a thermal imaging sensor. Alternatively or additionally, the sensor data can include data from a positioning system and / or a navigation system (e.g., GPS or Galileo) and / or traffic reports or other messages, which are received, for example, wirelessly from a transmitting station. Furthermore, alternatively or additionally, the sensor data can include vehicle-to-everything (V2X, also: Car2x) data.V2X can include (particularly wireless) communication from vehicle-to-vehicle (V2V), vehicle-to-road (V2R), vehicle-to-infrastructure (V2I), vehicle-to-network (V2N) and / or vehicle-to-person (V2P).

[0050] The sensor system can be arranged internally within the vehicle and / or on the at least partially automated vehicle (e.g., a camera mounted on the vehicle). Alternatively or additionally, the sensor system can be arranged externally on the vehicle (e.g., infrastructure-based, in particular a road-mounted camera for traffic monitoring, a positioning system and / or navigation system, a weather determination system, and / or, e.g., internally on another road user). The sensor data received by the external sensor system can be transmitted (and / or received) wirelessly, for example, via V2X.

[0051] The sensor data can be received currently and / or buffered. Alternatively or additionally, the sensor data can include historical data, particularly relating to one or more previous states of the traffic scene.

[0052] Map data (e.g., from a navigation system) of the surrounding area can be stored in the at least partially automated vehicle. Alternatively or additionally, the received sensor data can (in particular additionally) include map data of the surrounding area.

[0053] Receiving the sensor data (also known in technical terms as perception) with regard to the traffic scene and / or with regard to other road users can include pre-processing, in particular object classification (and / or object recognition) of dynamic and / or static objects (e.g. another vehicle, pedestrian and / or, in particular, static, obstacle), in particular summarized in an object list.

[0054] By means of the sensor data recorded (in particular on the at least partially automated vehicle), the environment of the at least partially automated vehicle can be monitored in real time and the environment model can be reliably created, at least within the range of the respective sensor(s) (e.g. field of view of a camera up to an obstacle).

[0055] By means of the sensor data received wirelessly (e.g. via radio or data interface) or wired (e.g. from sensors arranged inside the vehicle), the environment model can be extended to areas that cannot be detected by the sensors arranged on the at least partially automated vehicle, for example behind an obstacle that limits the field of view of a camera arranged on the at least partially automated vehicle.

[0056] The creation of the environment model can be based on a digital map (and / or a raster map) of the environment. Each detected object (especially the object list) can be assigned a position on the digital map.

[0057] Using the determined environment model, both a static and a dynamic traffic situation can be reliably assessed. The method may further comprise a step of aggregating the received sensor data. In particular, sensor data may be received from various sensors, sensor systems, and / or sources. Aggregating may comprise combining the sensor data from various sources, sensors, and / or sensor systems. Alternatively or additionally, aggregating may comprise combining sensor data assigned to different periods (e.g., within one or more, particularly past, planning cycles).

[0058] In a further development of the invention, further sensor data can be received with regard to dynamic traffic control in the traffic scene (and / or the surroundings of the at least partially automated vehicle), in particular with regard to a traffic light with switching states (e.g. red phase, green phase).

[0059] The sensor data representing a current state may have been recorded (and / or acquired) at least in part in the respective journal. Alternatively or additionally, the sensor data may have been recorded (and / or acquired) at least in part in one or more earlier (also: preceding, previous, and / or past) journals. Alternatively or additionally, the current state of the traffic scene may be understandable based on its past. For example, a speed (and / or acceleration) in the current state of the at least partially automated vehicle and / or another road user may be extrapolated (and / or determined) using (in particular position) sensor data, preferably from several earlier time steps of the same vehicle.

[0060] In one embodiment, the received sensor data can be aggregated for a predetermined prior time period (and / or a predetermined number of prior time steps) to represent the current state. Alternatively or additionally, a compressed state can be stored, which is updated (e.g., in each journal) based on newly received sensor data.

[0061] The trajectory can be created (and / or planned) based on an initial environment model (particularly in a planning module). The environment model, optionally created from the received sensor data (particularly redundantly, so to speak) (e.g., for safety checks), can be compared with the initial environment model for consistency in a validation step, and corrective measures can be initiated in the event of any deviations.

[0062] The step of classifying states and zones according to at least one safety objective for the at least partially automated vehicle may comprise a step of classifying states according to at least one first safety objective for the at least partially automated vehicle based on assumptions regarding the read-in environment model. The assumptions may be read from the assumption memory. Alternatively or additionally, the step of classifying states and zones according to at least one safety objective for the at least partially automated vehicle may comprise a classifying zones according to at least one second safety objective for the at least partially automated vehicle based on the safe control laws regarding the read-in environment model.The zone classified according to the second safety objective may include at least one set of states classified according to the first safety objective. The safe control laws may be read from the control law memory.

[0063] The method may further comprise a step of first sorting the received list of trajectories to be checked according to a priority (and / or according to at least one certainty measure) of a set of constraints to be met. Alternatively or additionally, the method may comprise a step of second sorting the trajectories of the result of the second filtering according to the value of the probability estimate. Alternatively or additionally, the method may comprise a step of second sorting the trajectories of the result of the second filtering according to the result of the first sorting. In particular, the second sorting of the trajectories may be carried out according to at least one certainty measure of the trajectories.

[0064] The set of constraints to be fulfilled (and / or fulfilled) (particularly with regard to the safety of the at least partially automated vehicle) can also be referred to as a behavior. The behaviors can be arranged in a list according to priority (and / or according to the at least one safety measure). The list can be created internally, particularly in a component intended to execute the method. Alternatively or additionally, the list can be received from an external source and verifiable for its accuracy, consistency, and / or completeness.

[0065] The respective security measure (and / or priority) can be multi-level and include several security levels and / or security objectives.

[0066] The sorted list of trajectories to be checked (and / or checked) may prioritize high security (and / or high security level).

[0067] The boundary conditions can include (e.g., an interval and / or a threshold value for one or more of the following variables) a speed, acceleration, steering angle, position, orientation, and / or time (e.g., a position). In particular, the set of boundary conditions can include a combination of at least two variables, for example, position and speed, and / or a maximum value of an acceleration and / or a speed. The boundary conditions can be linked by means of a polygon, particularly for the spatial coordinates of a zone.

[0068] For example, the at least partially automated vehicle can approach an intersection which it is to cross straight ahead. For example, a polygon of the lane up to the intersection with the maximum permissible speed is obtained as a first boundary condition. A second boundary condition is, for example, a polygon which extends over the intersection. The polygon extending over the intersection not only limits the maximum permissible speed but also defines a time interval within which the intersection must be crossed. A third polygon, for example, represents the lane of the at least partially automated vehicle, starting from behind the intersection to the planning horizon (e.g., a few hundred meters) later. The polygon starting at the intersection, in turn, contains the speed limit as a further boundary condition. In the example, a set of boundary conditions is obtained which can be represented by three (3) polygons which represent the respective (e.g.,State sets (up to, at, and after the intersection) can be geometrically described, for example, including (or plus) time and / or speed intervals that dynamically limit the respective state sets. The sets of boundary conditions to be fulfilled (and / or the behaviors) can be stored in a database and retrievable (e.g., for comparison with the received trajectory to be verified).

[0069] The method may further comprise a step of providing a trajectory of the result of the second filtering (in particular the best and / or prioritized trajectory according to the second sorting) to a closed-loop and / or closed-loop control system of the at least partially automated vehicle for executing the trajectory. This allows the safety-checked trajectory to be implemented and executed during vehicle control. The at least partially automated vehicle can then execute a safe movement based on the selected and safety-checked trajectory by controlling (and / or regulating) at least one actuator according to the selected trajectory.

[0070] Alternatively or additionally, a control signal based on the trajectory selected as a result of the second filtering and / or a subsequent second sorting (e.g. according to a priority) can be output, in particular, to at least one actuator of the at least partially automated vehicle.

[0071] The classified states according to the at least one (e.g. first) safety objective may comprise at least three types of states, in particular invariably safe (IS) states, TS states, and / or unsafe states.

[0072] The IS states and TS states can fulfill at least one (e.g. first) safety objective, in particular a collision-free journey during the planning cycle.

[0073] Unsafe conditions along a planned trajectory (e.g., during the planning cycle) can prevent the first safety objective (e.g., a guaranteed accident-free journey) from being met.

[0074] The classified zones according to the at least one (e.g., second) safety objective can comprise at least three types of zones, in particular IS zones, IS transferable zones, and / or unsafe zones. The IS zones and IS transferable zones can fulfill the at least one (e.g., second) safety objective, in particular collision-free continuation after the planning cycle.

[0075] Unsafe zones (especially after the planning cycle) can prevent the second safety objective (e.g. a guaranteed accident-free continuation of the journey) from being met.

[0076] The zones can be extrapolated (and / or further developed) into the future. A (e.g., specific) time horizon (and / or prediction horizon) can depend on a system design and can vary significantly (e.g., from one system design to another) (e.g., from 500 ms to 20 s). It may be useful to predict at least several planning cycles in advance.

[0077] If the result of the second filtering (in particular, the second-filtered list of trajectories) is empty, a trajectory included in the intermediate result of the first filtering can be selected. Optionally, the selected trajectory can be modified after the trajectory has begun in the planning cycle. The modification can include applying the safe control laws.

[0078] The selected trajectory can be considered safe in the sense of fulfilling at least one (e.g., first and / or second) safety objective (e.g., without probability estimates). Alternatively or additionally, only the beginning of the trajectory can be classified as safe (e.g., based on a probability estimate per journal in the planning cycle), and the remainder of the trajectory can be modified during the planning cycle such that the modified trajectory meets the threshold of at least one (e.g., first and / or second) safety objective.

[0079] The beginning of a trajectory, which is subsequently modified within the planning cycle, can be determined based on a probability estimate per journal within the planning cycle. For example, the beginning of the trajectory can continue until the last journal in which the threshold of the probability estimate of at least one (e.g., first and / or second) safety objective is reached. If the intermediate result of the first filtering (in particular, the first-filtered list of trajectories) is empty, a trajectory received (in particular, from one of the planning modules) can be selected and modified after a beginning of the trajectory in the planning cycle. The modification can include applying the safe control laws.

[0080] By modifying the received trajectory (and / or the first-filtered trajectory) based on the secure control law(s), a modified trajectory that is formally secure can be provided. The formally secure modified trajectory can also be referred to as a fallback trajectory.

[0081] The selected trajectory to be modified may be or include the highest priority received trajectory.

[0082] The (in particular alternatively) selected trajectory (and / or the modified trajectory) in case of an empty result of the second filtering (and / or an empty intermediate result of the first filtering) can be determined according to a predetermined list of (e.g. possible) damage categories.

[0083] Based on the list of (e.g., possible) damage categories, personal injuries can be avoided and vehicle body damage permitted. For example, yielding to a pedestrian can be prioritized over colliding with a vehicle in front and / or colliding with a vehicle behind (e.g., due to heavy and / or abrupt braking, such as at a zebra crossing).

[0084] The assumptions regarding the read-in environment model can include assumptions regarding the dynamic development of the traffic scene based on generally applicable rules and / or based on other reasonable road users. Alternatively or additionally, the assumptions can be independent of the at least partially automated vehicle and / or the received sensor data used to create the environment model. The generally applicable rules can include traffic rules, (e.g., speed-dependent) distance rules, and / or collision regulations (e.g., if a collision is unavoidable, preferably with another object or vehicle and not with a pedestrian, cyclist, or otherwise unprotected person).

[0085] The assumption regarding other reasonable road users may include a rational driver assumption. Alternatively or additionally, assumptions regarding the imported environmental model (e.g., weather-dependent) may include assumptions about the driving physics of other road users.

[0086] The rational driver assumption may include the driver adhering to the traffic regulations in force in the area. A violation (and / or invalidation of the assumption) may be detectable using the received sensor data, for example, exceeding a permitted speed limit and / or making an unauthorized turn.

[0087] In one embodiment, one or more generally valid rules and / or the assumption of the reasonable other road user may be omitted or not executed when classifying the states (and / or when creating a modified trajectory) if the received sensor data indicate a violation (and / or invalidity) of the respective assumption.

[0088] The Rational Driver Assumption can refer to other road users and / or influence the prediction (and / or the prediction of the temporal development of the traffic scene). An intelligent driver model (technically known as an Intelligent Driver Model) or a derived adaptive cruise control (ACC) system can be expanded into one or more safe control laws (also known as safe control laws) and refer to the at least partially automated vehicle (also known as the ego vehicle).

[0089] Invalidity and / or violation of the assumptions (which is estimated probabilistically in the second filtering step, in particular) with regard to the read-in environment model can be based on errors and / or uncertainties in the environment model, for example due to a scatter of sensor data. For example, an incorrect (and / or uncertain) distribution of possible positions of the other road users (and / or of the at least partially automated vehicle) can contribute to invalidation of the assumptions. A scatter of the sensor data and / or an inaccuracy in the validity of the assumptions can increase with the length of the trajectory during (and / or after) the planning cycle. Therefore, in one embodiment, the length of the trajectory can be taken into account in the safety check, for example by selecting different safety goals or other criteria for the safety check for long trajectories than for short ones.The mechanism outlined here can, for example, result from the procedure of aborting the probability assessment from the first crossing of the next IS-transferable zone.

[0090] Alternatively or additionally, the assumptions may be invalid and / or violated due to time-dependent and / or weather-dependent conditions (e.g., in the case of black ice and / or aquaplaning) and / or due to varying road conditions.

[0091] The assumptions regarding the read-in environment model can be stored in a digital database (in particular in the assumption memory), in particular locally in the at least partially automated vehicle.

[0092] The safe control laws may include regulations for the regulation and / or control of the at least partially automated vehicle and / or an intelligent driver model for the at least partially automated vehicle.

[0093] The intelligent driver model (IDM) can comprise a continuous-time vehicle-following model for simulating road traffic. The IDM can describe the dynamics of the positions and speeds of individual vehicles (in particular, the at least partially automated vehicle and / or other road users). Accelerations can be subject to conditions for a clear road and / or for a road occupied by other road users. In particular, a (e.g., minimum) distance to the other road user can be taken into account in the development of the movement. The safe control laws can be adaptable and / or vehicle-specific. The latter means that the safe control laws are based on vehicle-specific parameters.For example, braking deceleration and / or acceleration capability may depend on the technical specifications of the at least partially automated vehicle.

[0094] The rules for regulating and / or controlling the at least partially automated vehicle may include slow coasting, (particularly strong) braking, maintaining a speed for a predetermined number of control cycles, driving according to the ACC (preferably combined with, in particular, safe braking before a potential conflict zone), and / or jerk-optimized, jerk-limited, and / or acceleration-limited braking. Slow coasting may be suitable, for example, at the edge of the road.

[0095] Braking (particularly strong and / or safe) may be appropriate when reaching a potential conflict zone (e.g. an intersection, a railway crossing, a zebra crossing, and / or an oncoming lane in case of a planned overtaking maneuver).

[0096] Maintaining the speed for a predetermined number of (e.g., three to four) control cycles may be suitable for driving on a straight stretch of road, a country road and / or a motorway, in particular to enable replanning of trajectories and / or to avoid endangering flowing traffic.

[0097] Driving according to ACC can prevent a danger to flowing traffic caused by following the vehicle in front. A danger caused by following across a potential conflict zone can be minimized by replacing ACC with braking (e.g., at a stop line in the potential conflict zone).

[0098] The safe control laws can be predetermined (and / or determinable) depending on the situation. For example, different safe control laws can be used for driving in urban traffic or for driving on the highway. The safe control laws (especially those determinable depending on the situation) can be stored in a digital database (in particular in the control law memory), in particular locally in the at least partially automated vehicle.

[0099] By means of jerk-optimized, jerk-limited and / or acceleration-limited braking, the danger to other road users (particularly due to driving behavior that is unexpected for other road users) can be minimized.

[0100] Alternatively or additionally, the regulations for regulation and / or control may include assumptions about the driving physics of the at least partially automated vehicle and / or an assumption about the set of boundary conditions to be fulfilled for the trajectory to be checked.

[0101] The classification of states and / or zones based on assumptions and / or safe control laws can be achieved using white-box modeling. White-box modeling can include a complete model of a technical system derived from, for example, physical laws.

[0102] Alternatively or additionally, the classification of states and / or zones can be performed based on the assumptions and / or the reliable control laws using grey-box modeling. With grey-box modeling, processes can be clearly defined, but the specific characteristics, particularly with regard to the determined and / or set parameters, are extracted from the data.

[0103] In grey-box (and / or white-box) machine learning, the focus can be on transparency and explainability of the results. Grey-box (and / or white-box) models can provide insights into the decision-making process, making it interpretable and verifiable. Examples of grey-box (and / or white-box) machine learning include linear regression, decision trees, and rule-based systems. Assumptions about the driving physics of the at least partially automated vehicle and / or another road user can include physical dimensions (e.g., axle spacing, weight, and / or acceleration). The driving physics and / or physical dimensions can be implicitly determined by a vehicle model.

[0104] The assumption regarding the set of boundary conditions to be met may include the determination of physical parameters, in particular a limitation (e.g., by means of an interval and / or a threshold value) with regard to a jolt, acceleration, and / or deceleration. This assumption may be important for improving the predictability of the journey for other road users and / or extending the service life of components of the at least partially automated vehicle and / or preventing wear on components of the at least partially automated vehicle.

[0105] According to one aspect of the device, a safety check module is provided for safety checking a trajectory in a planning cycle for an at least partially automated system, in particular a vehicle. The safety check module comprises an environment model interface which is designed to read in an environment model assigned to a planning cycle for the at least partially automated vehicle (in particular from an environment model memory). The environment model represents a dynamic development of the traffic scene around the at least partially automated vehicle. The safety check module further comprises a classification unit which is designed to classify states and zones according to at least one (e.g.A first and / or second) safety objective for the at least partially automated vehicle is based on assumptions regarding the read-in environment model and / or based on safe control laws regarding the read-in environment model. A zone classified according to the at least one (e.g., second) safety objective comprises at least a set of states classified according to the at least one (e.g., first) safety objective. The assumptions can be read from an assumption memory. Alternatively or additionally, the safe control laws can be read from a control law memory.The security check module further comprises a receiving interface which is designed to receive a list of trajectories to be checked for the planning cycle for the at least partially automated vehicle. The security check module further comprises a first filter unit which is designed to first filter the received list of the trajectory. An intermediate result of the first filtering comprises only trajectories whose states have been classified at least as TS in the planning cycle and which, after the end of the planning cycle, lead to a zone classified as at least IS transferable.The safety check module further comprises a second filter unit configured to perform a second filtering of the intermediate result of the first filtering of the list of trajectories based on a probability estimate regarding the validity of the assumptions regarding the read-in environmental model and / or the validity of the safe control laws regarding the read-in environmental model, at least during the planning cycle. The result of the second filtering of the list includes only trajectories (e.g., only one trajectory) whose probability estimate exceeds a threshold value of a safety objective (in particular, the first and / or second safety objective).

[0106] Optionally, the security verification module may further comprise a sensor data receiving interface and / or an environment model creation unit.

[0107] The classification unit may comprise a state classification unit configured to classify states according to at least one first safety objective for the at least partially automated vehicle based on assumptions regarding the read-in environment model. The assumptions may be read from the assumption memory.

[0108] Alternatively or additionally, the classification unit can comprise a zone classification unit designed to classify zones according to at least one second safety objective for the at least partially automated vehicle based on safe control laws with respect to the read-in environmental model. A zone classified according to the at least one second safety objective can comprise at least a set of states classified according to the at least one first safety objective. The safe control laws can be read in from a control law memory. Alternatively or additionally, the safety check module can comprise a first sorting unit. Furthermore, alternatively or additionally, the safety check module can comprise a second sorting unit.

[0109] The security verification module may further comprise a provisioning interface.

[0110] The safety check module can comprise at least one memory. The at least one memory can comprise the environment model memory, the assumption memory, and / or the control law memory (e.g., each as partitions of an overall memory). Alternatively or additionally, the environment memory can be arranged in (and / or connected to) a perception module and / or a prediction module of the at least partially automated vehicle.

[0111] The security check module can be configured to execute the method according to the method aspect. Alternatively or additionally, the security check module can comprise features according to the method aspect.

[0112] According to one system aspect, a system for safety checking a trajectory in a planning cycle for an at least partially automated vehicle is provided. The system comprises at least one environmental sensor configured to receive sensor data regarding the dynamic development of the traffic scene around the at least partially automated vehicle. The system further comprises a perception module configured to create an environmental model based on the sensor data. The system further comprises at least one prediction module configured to dynamically develop the environmental model. The system further comprises at least two planning modules, each configured to output at least one trajectory to be checked.The system further comprises a safety check module according to the device aspect, whose environment model interface is configured to read the environment model from the prediction module (and / or perception module) and whose reception interface is configured to receive the trajectories to be checked from the at least two planning modules. According to a further aspect, a computer program is provided with program elements that cause a safety check module to execute the steps of the method for safety checking a trajectory in a planning cycle for an at least partially automated vehicle according to the method aspect when the program elements are loaded into a memory of the safety check module.

[0113] According to yet another aspect, a computer-readable medium is provided on which program elements are stored that can be read and executed by a security check module to carry out steps of the method for security checking a trajectory in a planning cycle for an at least partially automated vehicle according to the method aspect when the program elements are executed by the security check module.

[0114] Short description of the drawings

[0115] Fig. 1 is a flowchart of a method for safety checking a trajectory in a planning cycle for an at least partially automated vehicle according to a preferred embodiment.

[0116] Fig. 2 is an overview of the structure and layout of a safety check module for safety checking a trajectory in a planning cycle for an at least partially automated vehicle according to a preferred embodiment.

[0117] 3A and 3B show a preferred embodiment of the method of Fig. 1 with a first and second sorting of the trajectories according to a priority and / or according to at least one safety measure, wherein Fig. 3B schematically outlines a preferred embodiment of the classification of the states and zones of the environment model.

[0118] Detailed description

[0119] Fig. 1 schematically shows a flowchart of an exemplary computer-implemented method 100 for safety checking a trajectory in a planning cycle for an at least partially automated vehicle. The method 100 comprises a step S104 of reading an environment model assigned to a planning cycle for an at least partially automated vehicle from an environment model memory, wherein the environment model represents a dynamic development of a traffic scene around the at least partially automated vehicle.

[0120] The method 100 further comprises a step S107 of classifying states and zones according to at least one (e.g., first or second) safety objective for the at least partially automated vehicle based on assumptions regarding the read-in S104 environment model and / or based on safe control laws regarding the read-in S104 environment model. An S107 zone classified according to the at least one (e.g., second) safety objective comprises at least a set of S107 states classified according to the at least one (e.g., first) safety objective. The assumptions can be read from an assumption memory. Alternatively or additionally, the safe control laws can be read from a control law memory.

[0121] The method 100 further comprises a step S110 of receiving a list of trajectories to be checked for the planning cycle for the at least partially automated vehicle.

[0122] The method 100 further comprises a step S114 of first filtering the received S110 list of trajectories. An intermediate result of the first filtering S114 includes only trajectories whose states were classified S107 as at least temporarily safe (TS) in the planning cycle and which, after the end of the planning cycle, lead into a zone that was classified S107 as at least invariably safe transferable (IS transferable).

[0123] The method 100 further comprises a step S116 of a second filtering of the intermediate result of the first filtering S114 of the list of trajectories based on a probability estimate regarding the validity of the assumptions and / or the validity of the safe control laws, in particular with regard to the read-in S104 environment model at least during the planning cycle. The result of the second filtering S116 of the list includes only trajectories whose probability estimate exceeds a threshold value of the at least one safety objective (in particular of the at least one first and / or second safety objective).

[0124] The method 100 may further comprise a step S102 of receiving sensor data regarding the dynamic development of the traffic scene around the at least partially automated vehicle. The method 100 may alternatively or additionally comprise a step S103 of creating the environment model, in particular using (and / or the) received S102 sensor data.

[0125] The step S107 of classifying states and zones according to the at least one safety objective for the at least partially automated vehicle may comprise a step S106 of classifying states and a step S108 of classifying zones.

[0126] The states can be classified S106 according to at least one first safety objective for the at least partially automated vehicle based on the assumptions regarding the read-in S104 environment model. The assumptions can be read from the assumption memory.

[0127] The zones can be classified S108 according to at least one second safety objective for the at least partially automated vehicle based on safe control laws with respect to the read-in S104 environment model. A S108 zone classified S108 according to the at least one second safety objective can include at least a set of S106 states classified S106 according to the at least one first safety objective. The safe control laws can be read from the control law memory.

[0128] The method 100 may further comprise a step S112 of first sorting the received S110 list of trajectories to be checked according to a priority and / or according to at least one certainty measure of a set of constraints to be met. Alternatively or additionally, the method 100 may comprise a step S118 of second sorting S118 of the trajectories of the result of the second filtering S116 according to the value of the probability estimate and / or according to the result of the first sorting S112, in particular according to the at least one certainty measure of the trajectories.

[0129] The method 100 may further comprise a step S120 of providing a trajectory of the result of the second filtering S116 (in particular the best trajectory according to the second sorting S118) to a closed-loop and / or closed-loop control of the at least partially automated vehicle for executing the trajectory.

[0130] Fig. 2 schematically shows an exemplary structure of a safety check module (also: safety checker) 200 for safety checking a trajectory in a planning cycle for an at least partially automated vehicle.

[0131] The safety check module 200 comprises an environment model interface 204, which is configured to read in an environment model associated with a planning cycle for the at least partially automated vehicle (in particular from an environment model memory). The environment model represents a dynamic development of the traffic scene around the at least partially automated vehicle.

[0132] The safety check module 200 further comprises a classification unit 207, which is designed to classify states and zones according to at least one (e.g., first or second) safety objective for the at least partially automated vehicle based on assumptions regarding the read-in environment model and / or based on safe control laws regarding the read-in environment model. A zone classified according to the at least one (e.g., second) safety objective comprises at least a set of states classified according to the at least one (e.g., first) safety objective. The assumptions can be read from an assumption memory. Alternatively or additionally, the safe control laws can be read from a control law memory.

[0133] The security check module 200 further comprises a receiving interface 210 configured to receive a list of trajectories to be checked for the planning cycle for the at least partially automated vehicle. The security check module 200 further comprises a first filter unit 214 configured to perform the first filtering of the received list of trajectories. An intermediate result of the first filtering includes only trajectories whose states were classified as at least TS in the planning cycle and which, after the end of the planning cycle, lead to a zone classified as at least IS transferable.

[0134] The safety check module 200 further comprises a second filter unit 216, which is configured to perform a second filtering of the intermediate result of the first filtering of the list of trajectories based on a probability estimate regarding the validity of the assumptions and / or the validity of the safe control laws with respect to the read-in environment model, at least during the planning cycle. The result of the second filtering of the list includes only trajectories whose probability estimate exceeds a threshold value of a safety objective (in particular a first and / or a second safety objective).

[0135] Optionally, the security verification module 200 can further comprise a sensor data receiving interface 202 and / or an environment model creation unit 203. The sensor data receiving interface 202 can be configured to receive sensor data regarding the dynamic development of the traffic scene around the at least partially automated vehicle. Alternatively or additionally, the environment model creation unit 203 can be configured to create the environment model, in particular using (and / or the) received sensor data.

[0136] The classification unit 207 can include a state classification unit 206 and a zone classification unit 208. The state classification unit 206 can be configured to classify states according to at least one first safety objective for the at least partially automated vehicle based on assumptions regarding the read-in environment model. The assumptions can be read from the assumption memory. Alternatively or additionally, the zone classification unit 208 can be configured to classify zones according to at least one second safety objective for the at least partially automated vehicle based on safe control laws regarding the read-in environment model.A zone classified according to the at least one second safety objective may comprise at least one set of states classified according to the at least one first safety objective. The safe control laws may be read from a control law memory.

[0137] Alternatively or additionally, the security verification module 200 may comprise a first sorting unit 212, which is configured to perform a first sorting of the received list of trajectories to be verified according to a priority and / or according to at least one security measure of a set of constraints to be met. Furthermore, alternatively or additionally, the security verification module 200 may comprise a second sorting unit 218, which is configured to perform a second sorting of the trajectories based on the result of the second filtering. The second sorting may be performed according to the value of the probability estimate. Alternatively or additionally, the second sorting may be performed according to the result of the first sorting (in particular according to at least one security measure of the trajectories).

[0138] The security check module 200 may further comprise a provision interface 220 configured to provide a trajectory of the result of the second filtering (in particular the best trajectory according to the second sorting) to a closed-loop and / or closed-loop control system of the at least partially automated vehicle for executing the trajectory.

[0139] The safety check module 200 may include at least one memory 226. The at least one memory 226 may include the environment model memory, the assumption memory, and / or the control law memory (e.g., each as partitions of an overall memory). Alternatively or additionally, the environment memory may be arranged in (and / or connected to) a perception module and / or a prediction module of the at least partially automated vehicle.

[0140] The security verification module 200 may be configured to carry out the method 100.

[0141] A system (not shown) for safety checking a trajectory in a planning cycle for an at least partially automated vehicle may comprise at least one environmental sensor configured to receive sensor data regarding the dynamic development of the traffic scene around the at least partially automated vehicle. The system may further comprise a perception module configured to create an environmental model based on the sensor data. The system may further comprise at least one prediction module configured to dynamically develop the environmental model. The system may comprise at least two planning modules, each configured to output at least one trajectory to be checked.The system may further comprise a security check module 200, whose environment model interface 204 is designed to read in the environment model from the prediction module (and / or perception module) and whose reception interface 210 is designed to receive the trajectories to be checked from the at least two planning modules.

[0142] The system may be configured to carry out the method 100.

[0143] The security check module 200 and / or the system can be arranged in a control component in the at least partially automated vehicle.

[0144] The technique for safety checking a trajectory in a planning cycle for an at least partially automated vehicle (in particular comprising the method 100, the safety check module 200, and / or the system) is (at least essentially) not a motion planning technique, but rather a method for online verification and trajectory correction (in particular of already planned trajectories). In contrast to [1, 2], the states (in particular IS and TS) and zones (in particular IS transferable) are determined directly in the environment model according to the technique.

[0145] The list of trajectories to be checked is already available for the implementation of the technique. A trajectory to be checked from the list does not necessarily have to start or end in an IS (or at least an IS-transferable) zone. Using the technique, sampled trajectory candidates can be checked for compliance with prioritized behaviors, which can be represented as sets of constraints.

[0146] The review of prioritized behaviors can be performed in the security review module downstream of the planning modules.

[0147] The Safety Checker 200 can apply (e.g., exclusively) safety criteria. Alternatively or additionally, the safety check of the Safety Checker 200 can be multi-level and also consider functional safety.

[0148] The safety checker module 200 can also consider replanning and / or contingency planning. Alternatively or additionally, the technology can consider a modification of trajectory candidates (which is particularly unknown in the prior art).

[0149] According to the technique for safety checking a trajectory in a planning cycle for an at least partially automated vehicle, the list of trajectories is checked and evaluated by a component other than the (or several, in particular two) planning component(s), a so-called safety checker (or the safety check module 200). The task of the safety checker 200 is to select the best available trajectory in terms of safety and, if no suitable trajectory has been provided at all, to derive a suitable output trajectory from the provided trajectories.

[0150] The safety check module (or Safety Checker) 200 is used to safety check received (also: input) trajectories in accordance with the standards ISO 21212 Functional Safety and ISO 21448 SOTIF.

[0151] A preferred embodiment of the method 100 is shown schematically in Fig. 3A. Sensor data, in particular from sensors arranged on the vehicle, is received at reference symbol S102. Based on the sensor data received in step S120, a plurality of planning modules 1,..., N plan (e.g., each a trajectory for) the list of trajectories received (also: obtained) from the safety checker module (also: safety checker) in step S110 (e.g., comprising at least one input trajectory from at least one planning module) for checking. Furthermore, the safety checker module (or the safety checker) 200 reads in an environment model in step S104 (either active or passive reading / receiving or PUSH or PULL operation), which is created from the sensor data (in particular from the vehicle sensors and possibly from data communicated via V2X) in step S103 (which is also referred to as preprocessing in Fig. 3A, for example, and in Fig.3B can be called perception) was created (and / or calculated).

[0152] In general, the creation or calculation of the environment model can be based on execution steps of a perception module (Fig. 3B, S103). Perception can be understood as the receiving of data. A perception module (or perception layer) refers to a component responsible for collecting and optionally preprocessing raw data from the environment. This component typically includes sensors, cameras, microphones, and / or other input devices that capture data such as images, sounds, or text. A main task of the perception module is to convert raw data into a format that can be understood and analyzed by the environment model. The received sensor data can also include preprocessing of the data (see Fig. 3A, S103), e.g., to extract relevant features, filter out noise, and / or convert the data into a suitable representation for further processing.

[0153] According to one embodiment, a step of preprocessing (in particular of the received S102 sensor data) can take place between step S102 of receiving the sensor data and the receiving S104 of the environment model (e.g., for creating S103 of the environment model).

[0154] According to a further embodiment (which can be combined in particular with the previous embodiment), a perception step (in particular based on the received sensor data S102) can take place between step S102 of receiving the sensor data and step S104 of receiving the environment model (e.g., for creating the environment model S103). In step S107, in Fig. 3A, states and zones are classified according to at least one safety objective. As shown in Fig. 3B, step S107 can include a step S106 of classifying the states and a step S108 of classifying the zones.

[0155] As shown schematically in Fig. 3A at reference symbol S112, the safety verification module 200 first derives a list of prioritized behaviors and prioritizes them (and / or sorts the received S110 trajectories according to a priority of a set of constraints to be met). Alternatively or additionally, the list of prioritized behaviors (and / or the set of constraints to be met) can originate from an external source and, for example, can only be checked for correctness by the safety verification module 200. Such an embodiment (in particular with an external source of the list of prioritized behaviors) is useful, for example, when at least one of the planning modules has been executed and a list of prioritized behaviors has already been calculated in the processing chain. Advantageously, the behaviors are each represented as a set of constraints.

[0156] The security verification module 200 then determines, for each received S110 (and / or input) trajectory, the highest-priority behavior that the trajectory satisfies. Based on this priority, the security verification module 200 sorts the received S110 (or input) trajectories S112.

[0157] Furthermore, the safety check module 200 determines invariably safe (IS) state sets from the received S104 environment model using a set-based method and, derived therefrom, IS transferable zones. The IS transferable zones represent sets of time-dependent states (also: time-state pairs), wherein with the help of one or more safe control laws, the time-dependent states from the IS transferable zone are transferred (or at least can be transferred) via a safe trajectory into an IS state. The processing chain (in particular for obtaining IS transferable zones) is shown in Fig. 3B. For this purpose, the state space of the at least partially automated vehicle (also: ego vehicle) is first extended by the time dimension and the time-dependent states (also: time-state pairs) are divided into three categories: unsafe, temporarily safe (TS) and IS. Unsafe time-dependent states (orTime-state pairs contradict at least one safety goal. A common safety goal, for example, is collision-free operation. Accordingly, time-dependent states (or time-state pairs) within the reachable set of another road user are unsafe. Time-dependent states (or time-state pairs) that are not unsafe are TS. States that are TS for all times within the relevant time horizon are IS. IS state sets are particularly limited by a conflict zone. Examples of such conflict zones are intersections, level crossings, and / or the oncoming lane on a country road. States within such a conflict zone can be TS, but never IS.

[0158] The construction of the corresponding sets of time-dependent states (also: pairs in the time-state space) using set-based methods requires a set of assumptions (particularly with regard to the imported S104 environment model), which are made, for example, during white-box modeling of the set-based estimations. For example, to determine the accessibility state set of other road users, assumptions about their driving physics are used, as is often the case, the Rational Driver Assumption. The Rational Driver Assumption presupposes that other road users also adhere to the traffic rules or only violate them to an expectedly small extent. This limits the accessibility state set of a road user to their lane, for example.

[0159] A major advantage of the proposed invention lies in the formal safety guarantees that the method obtains through the use of set-based methods. By mapping uncertainties in the form of sets, the violation of at least one safety objective can be formally excluded in the case of disjoint sets, as long as the assumptions made are met.

[0160] In Fig. 3B, reference numeral 302 schematically depicts an assumption memory from which the assumptions regarding the read-in S104 environment model are read in step S106 of classifying (and / or constructing the sets) of states. Furthermore, reference numeral 304 schematically depicts a control law memory from which reliable control laws regarding the read-in S104 environment model are read in step S108 of classifying the zones.

[0161] In step S108 of Fig. 3B, the IS state sets are expanded to form IS transferable zones. A safe trajectory contains exclusively TS states. An example of a safe control law is jerk-optimal, jerk-limited, and acceleration-limited braking to a standstill. Another safe control law relates to Adaptive Cruise Control (ACC). The ACC control law is preferably combined with safe braking so that the at least partially automated vehicle (or ego vehicle) does not blindly follow a preceding vehicle across a conflict zone (e.g., intersection). In an advantageous embodiment, acceleration, speed, time, and orientation boundary conditions are represented as intervals and linked to a polygon that describes the location coordinates of the zone.

[0162] Based on the quantity-based analysis of the environment model, in step S114 outlined in Fig. 3A, for each received S110 (or input) trajectory, it is checked whether the trajectory section from the current ego state of the at least partially automated vehicle (also referred to as the state of the ego vehicle) to the replanning time (and / or end of the planning cycle) represents a safe trajectory. The replanning time is the time at which the trajectory planned in the next planning cycle becomes active. Trajectories that are not guaranteed to be safe by the replanning time are eliminated. Furthermore, for each received S110 (or input) trajectory, it is checked whether it passes through an IS transferable zone after the replanning time. If no IS transferable zone is reached after replanning, the safety of the trajectory can no longer be formally guaranteed, and the trajectory is eliminated.The intermediate result of the first filtering step S114 is a (in particular first-time) filtered list of trajectories.

[0163] Due to the use of overestimations in the set-based approaches or violations (also: invalidity) of the predefined assumptions, it may happen that none of the received S110 (or input) trajectories is guaranteed to be safe. If the trajectory passes through an IS transferable zone before reaching a state that is not guaranteed to be TS, the trajectory can be implemented until the IS transferable zone is reached and then switched to the safe control law corresponding to the zone. This allows the safety check module 200 to generate a formally safe modified (also: fallback) trajectory. Otherwise, the system no longer has a trajectory available that is guaranteed to be safe. In this case, the trajectory from the original list with the highest priority (e.g., in step S112) according to the set of constraints (and / or behaviors) to be met can be used.In this way, the safety check module 200 can ensure that the at least partially automated vehicle (or ego vehicle) behaves at least in a manner that is most conducive to the situation according to the safety objectives.

[0164] In step S116 outlined in Fig. 3A, the remaining trajectories (and / or those contained in the interim result) are evaluated probabilistically. For this purpose, the environment model is probabilistically predicted, and the probabilities resulting from the probabilistic prediction that a state is invalid are integrated along the respective received S100 (or input) trajectory from the current ego state until the first IS transferable zone is reached after the replanning time. Alternatively or additionally, for each of the assumptions used for the construction (e.g., according to step S106 in Fig. 3B), the probability that the assumption is violated (and / or invalid) can be determined. All these probabilities can be combined. This can result in the probability that the guaranteed safety of the trajectory holds. This probability represents a safety measure and / or a safety metric in the sense of SOTIF.The safety measure and / or the safety metric must exceed (and / or exceed) a minimum threshold (and / or a threshold value) so that the residual probability of outputting an unsafe trajectory is reduced to an acceptable level. Trajectories that do not meet the residual probability criterion are eliminated in step S116. If none of the remaining trajectories meets the minimum threshold, the highest-priority trajectory (e.g., according to step S112 in Fig. 3A) is used, so that the at least partially automated vehicle (and / or ego vehicle) still behaves as best as possible. "Best possible" preferably refers to the current traffic scene and / or the vehicle's surroundings.

[0165] Normally, at least one received S110 (or input) trajectory remains in the re-filtered S116 list. The remaining trajectories can be sorted in step S118 within their priority class according to the (particularly SOTIF) security metric and / or the security measure, and the overall highest-priority trajectory can be output (and / or provided according to step S120 of the method).

[0166] In one embodiment, one (or each, in particular at least two) of the planning modules can be implemented as a "GeBe Planner," according to a deep planning approach (as described, for example, in [3]) and / or according to a classical planning method (as described, for example, in [4]). The "GeBe Planner" can, for example, be a planning method for determining a list of prioritized behaviors, as defined and described in this description.

[0167] In a further embodiment, which can be combined with the previous embodiment, the environment model is represented by dynamic raster maps, object lists, and / or HD map sections (HD can stand for high resolution, in technical terms: high definition).

[0168] In a further embodiment that can be combined with the previous embodiments, the prioritized sets of boundary conditions (and / or behaviors) to be fulfilled are determined by pre-calculating the behaviors in a planning module and checking them in the security check module 200 (e.g. in the sense of a plausibility check and / or consistency check).

[0169] The calculation and prioritization of behaviors can be achieved by decomposing the current situation into so-called partial situations, each of which describes partial aspects of a situation, determining associated constraints, and then combining the constraints into behaviors. The constraints generated based on the partial situations can be prioritized based on the degree of achievement of the underlying safety goal(s).

[0170] The technique for safety checking a trajectory in a planning cycle for an at least partially automated vehicle comprises the method 100, in which an environmental model for the vehicle, assigned to a planning cycle and representing a dynamic development of a traffic scene, is read in S104. States and zones are classified S107 according to a safety objective for the vehicle based on assumptions and / or safe control laws regarding the read-in S104 environmental model. A zone classified S107 according to the safety objective comprises a set of states classified S107 according to the one safety objective. A list of trajectories to be checked is received S110 and filtered twice.The intermediate result of the first filtering S114 includes only trajectories whose states were classified S107 as at least temporarily safe during the planning cycle and which, after the planning cycle, lead to a S107 zone classified at least as invariably safe and transferable. The second filtering S116 includes a probability estimate regarding the validity of the assumptions and / or safe control laws with respect to the read-in S104 environment model.

[0171] The technology for safety checking a trajectory in a planning cycle for an at least partially automated system, in particular a vehicle (in particular comprising the method 100, the safety check module 200, and / or the system) can be useful, for example, for automation levels L4 and L5. The technology can function as a potential core component for implementing safe automated driving systems in complex environments. An application to the field of assistance systems (in particular automation level L3+) may also be conceivable (and / or even useful) under appropriate (and / or given) boundary conditions.

[0172] Cited prior art

[0173] [1] DE 10 2017 120 366 A1

[0174] [2] Christian Pek et al., „Enhancing Motion Safety by Identifying Safety- critical Passageways“, 2017 IEEE 56th Annual Conference on Decision and Control (CDC), Melbourne, VIC, Australia, 2017, pp. 320- 326

[0175] [3] Alexander Cui et al., "LookOut: Diverse Multi-Future Prediction and Planning for Self-Driving," 2027 IEEE / CVF International Conference on Computer Vision (ICCV), Montreal, QC, Canada, 2021 , pp. 16087-16096 [4] Johannes Müller et al., "Motion Planning for Connected Automated Vehicles at Occluded Intersections With Infrastructure Sensors," in IEEE Transactions on Intelligent Transportation Systems, vol. 23, no. 10, pp. 17479-17490, Oct. 2022

Claims

Claims 1 . Computer-implemented method (100) for safety checking a trajectory in a planning cycle for an at least partially automated vehicle, comprising the steps: - reading (S104) an environment model assigned to a planning cycle for an at least partially automated vehicle from an environment model memory, wherein the environment model represents a dynamic development of a traffic scene around the at least partially automated vehicle; - Classifying (S107) states and zones according to at least one safety objective for the at least partially automated vehicle based on assumptions regarding the read-in (S104) environment model and / or based on safe control laws with regard to the read-in (S104) environment model, wherein a zone classified (S107) according to the at least one safety objective comprises at least a set of states classified (S107) according to the at least one safety objective, wherein the assumptions are read in from an assumption memory (302), and wherein the safe control laws are read in from a control law memory (304); - receiving (S110) a list of trajectories to be checked for the planning cycle for the at least partially automated vehicle; - First filtering (S114) of the received (S110) list of trajectories, wherein an intermediate result of the first filtering (S114) comprises only trajectories whose states have been classified (S107) in the planning cycle at least as temporarily safe, TS, and which, after the end of the planning cycle, lead to a zone that has been classified (S107) at least as invariably safe transferable, IS transferable; and - Second filtering (S116) of the intermediate result of the first filtering (S114) of the list of trajectories based on a probability estimate with regard to a validity of the assumptions and / or a validity of the safe control laws with regard to the read-in (S104) environment model at least during the planning cycle, wherein the result of the second filtering (S116) of the list only includes trajectories whose probability estimate exceeds a threshold value of the at least one safety objective 2. Method (100) according to claim 1, further comprising the steps: - receiving (S102) sensor data regarding the dynamic development of the traffic scene around the at least partially automated vehicle; and / or - Creating (S103) the environment model, in particular using received (S102) sensor data.

3. Method (100) according to one of the preceding claims, wherein the step of classifying (S107) states and zones according to at least one safety objective for the at least partially automated vehicle comprises the following steps: - Classifying (S106) states according to at least one first safety objective for the at least partially automated vehicle based on assumptions regarding the read-in (S104) environment model, wherein the assumptions are read in from the assumption memory (302); - Classifying (S108) zones according to at least a second safety objective for the at least partially automated vehicle based on safe control laws with regard to the read-in (S104) environment model, wherein a zone classified (S108) according to the second safety objective comprises at least a set of states classified (S106) according to the first safety objective, wherein the safe control laws are read in from the control law memory (304).

4. Method (100) according to one of the preceding claims, further comprising at least one of the steps: - First sorting (S112) the received (S110) list of trajectories to be checked according to a priority, and / or according to at least one security measure, of a set of constraints to be fulfilled; and - Second sorting (S118) of the trajectories of the result of the second filtering (S116) according to the value of the probability estimate and / or according to the result of the first sorting (S112), in particular according to at least one security measure of the trajectories.

5. The method (100) according to any one of the preceding claims, further comprising the step: - Providing (S120) a trajectory of the result of the second filtering (S116), in particular the best trajectory according to the second sorting (S118), to a closed-loop and / or closed-loop control system of the at least partially automated vehicle for executing the trajectory.

6. The method (100) according to any one of the preceding claims, wherein the classified (S107; S106) states according to the at least one, in particular first, safety objective comprise at least three types of states, in particular invariably safe, IS, states, TS states, and / or unsafe states.

7. The method (100) according to any one of the preceding claims, wherein the classified (S107; S108) zones according to the at least one, in particular second, security objective comprise at least three types of zones, in particular IS zones, IS transferable zones, and / or unsafe zones.

8. The method (100) according to one of the preceding claims, wherein, in the event that the result of the second filtering (S116), in particular the second-filtered (S116) list of trajectories, is empty, a trajectory included in the intermediate result of the first filtering (S114) is selected; optionally, wherein the selected trajectory is modified after a start of the trajectory in the planning cycle, wherein the modification comprises applying the safe control laws.

9. Method (100) according to one of the preceding claims, wherein in the case that the intermediate result of the first filtering (S114), in particular the first-filtered (S114) list of trajectories, is empty, a received (S110) trajectory is selected and after a start of the trajectory is modified in the planning cycle, whereby the modification includes applying the safe control laws.

10. The method (100) according to any one of the preceding claims, wherein the assumptions regarding the read-in (S104) environment model include assumptions regarding the dynamic development of the traffic scene based on generally valid rules and / or based on reasonable other road users.

11. Method (100) according to one of the preceding claims, wherein the safe control laws comprise regulations for regulating and controlling the at least partially automated vehicle and / or an intelligent driver model for the at least partially automated vehicle.

12. Safety check module (200) for safety checking a trajectory in a planning cycle for an at least partially automated vehicle, comprising: - An environment model interface (204) which is designed to read in an environment model assigned to a planning cycle for an at least partially automated vehicle from an environment model memory, wherein the environment model represents a dynamic development of the traffic scene around the at least partially automated vehicle; - A classification unit (207) designed to classify states and zones according to at least one safety objective for the at least partially automated vehicle based on assumptions regarding the read-in environment model and / or based on safe control laws with regard to the read-in environment model, wherein a zone classified according to the at least one safety objective comprises at least a set of states classified according to the at least one safety objective, wherein the assumptions are read in from an assumption memory, and wherein the safe control laws are read in from a control law memory; - A receiving interface (210) configured to receive a list of trajectories to be checked for the planning cycle for the at least partially automated vehicle; - A first filter unit (214) designed to first filter the received list of the trajectory, wherein an intermediate result of the first filtering comprises only trajectories whose states have been classified in the planning cycle at least as temporarily safe, TS, and which, after the end of the planning cycle, lead into a zone that has been classified at least as invariably safe transferable, IS transferable; and - A second filter unit (216) which is designed for the second filtering of the intermediate result of the first filtering of the list of trajectories based on a probability estimate with regard to a validity of an assumption and / or a validity of the safe control laws with regard to the read-in environment model, at least during the planning cycle, wherein the result of the second filtering of the list comprises only trajectories whose probability estimate exceeds a threshold value of the at least one safety objective 13. Security check module (200) according to the directly preceding claim, wherein the security check module (200) is further configured to carry out the method according to one of claims 2 to 11, and / or wherein the security check module (200) comprises features according to one of claims 2 to 11.

14. System for safety checking a trajectory in a planning cycle for an at least partially automated vehicle, comprising: - at least one environmental sensor capable of receiving Sensor data regarding the dynamic development of the traffic scene around the at least partially automated vehicle; - a perception module designed to create an environment model based on the sensor data; - at least one prediction module designed to dynamically develop the environment model; - at least two planning modules, each designed to output at least one trajectory to be checked; and - a security check module (200) according to claim 12 or 13, wherein the environment model interface (204) is configured to read in the environment model from the prediction module and / or the perception module, and wherein the receiving interface (210) is configured to receive the trajectories to be checked from the at least two planning modules.

15. A computer program product comprising program elements that cause a security check module (200) to execute the steps of the method for security checking a trajectory in a planning cycle for an at least partially automated vehicle according to one of the preceding method claims when the program elements are loaded into a memory of the security check module (200).