System and method for functional safety validating an output of an audio message in an interior of a vehicle

The system uses carrier-suppressed modulation and validation thresholds to ensure reliable delivery of audio messages in vehicles, addressing speaker malfunctions and noisy conditions.

WO2026013022A1PCT designated stage Publication Date: 2026-01-15CONTINENTAL AUTOMOTIVE TECHNOLOGIES GMBH
View PDF 3 Cites 0 Cited by

Patent Information

Application Number
PCT/EP2025/069381
Authority / Receiving Office
WO · WO
Patent Type
Applications
Current Assignee / Owner
Priority Date
2024-07-24
Filing Date
2025-07-08
Publication Date
2026-01-15

AI Technical Summary

Technical Problem

Existing multimedia systems in vehicles may fail to deliver audio messages effectively due to speaker malfunctions or other issues, necessitating a method to validate the delivery of safety messages to ensure functional safety.

Method used

A system comprising an audio safety modulator, generator, demodulator, and validation unit that uses carrier-suppressed modulation to ensure the delivery of safety-relevant audio messages, with validation based on estimated modulation data and audio power thresholds.

Benefits of technology

Ensures reliable delivery of audio messages by detecting speaker malfunctions and adjusting modulation frequencies to enhance validation accuracy, allowing for robust message delivery even in noisy environments.

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure EP2025069381_15012026_PF_FP_ABST
    Figure EP2025069381_15012026_PF_FP_ABST
Patent Text Reader

Abstract

A system and a method for validating an output of an audio message in an interior of a vehicle is provided. An audio safety modulator modulates said audio message using said audio frequencies as carrier frequencies, an additional modulation carrier and modulation data. An audio generator outputs a speaker sound corresponding to said modulated audio message using one or more speakers in said interior. An audio recorder receives a vehicle sound using one or more microphones in said interior and outputs a vehicle signal corresponding to said received vehicle sound. An audio safety modulator generates estimated modulation data and an estimated audio power from said vehicle signal. On the basis thereof, a validation unit determines whether the outputting of said audio message is validated or not.
Need to check novelty before this filing date? Find Prior Art

Description

[0001] SYSTEM AND METHOD FOR FUNCTIONAL SAFETY VALIDATING AN OUTPUT OF AN AUDIO MESSAGE IN AN INTERIOR OF A VEHICLE

[0002] BACKGROUND

[0003] A multimedia system of vehicle may provide an audio message to the driver or other passengers of that vehicle. The audio message may be a warning or an instruction message for the driver or for the other passengers. However, due to circumstances (e.g., a broken speaker) this message may not reach the passengers of the vehicle in good order. Therefore, it may be important to validate the delivery of the safety message to interior where the passengers are seated. In case the message was not delivered in good order, the message may be generated again, for example, as a visual message or, again, as an audio message.

[0004] The objective of the invention is therefore to provide a system and a method for functional safety validating an output of an audio message in an interior of a vehicle.

[0005] SUMMARY

[0006] The objective of the invention is met by providing a system according to claim 1 and a method according to claim 8.

[0007] According to a first aspect, a system for functional safety validating an output of an audio message in an interior of a vehicle, the system comprising: an audio safety modulator (100) an audio generator (301 ) an audio recorder (303) an audio safety demodulator (200) a validation unit (400) wherein audio safety modulator (100) is arranged for: receiving a safety relevant audio message Xr; outputting, based on said audio message Xr, of an output signal X to said audio safety demodulator (200), wherein said output signal X comprises all safety information, that is audible for a passenger in said interior, without any safety modulation; outputting a signal Xa to the audio generator (301 ), wherein said signal Xa comprises (i) the safety relevant frequency spectrum of the output signal X, (ii) modulation frequencies, which correspond to modulation data Md and which are preferably not perceivable and / or not disturbing to said passenger, and (iii) the non-safety-relevant frequency spectrum of audio message Xr; outputting a modulation carrier signal Mt to the audio safety demodulator (200), wherein said modulation carrier signal Mt does not comprise said modulation frequencies corresponding to modulation data Md; and, outputting said modulation data Md to the validation unit (400); wherein the audio generator (301 ) is arranged for: receiving said signal Xa; outputting a speaker sound corresponding to said signal Xa using one or more speakers in said interior of said vehicle; wherein the audio recorder (303) is arranged for: receiving a vehicle sound using one or more microphones in said interior of said vehicle (20); outputting a vehicle signal Ym corresponding to said received vehicle sound to said audio safety demodulator (200); wherein the audio safety demodulator (200) is arranged for: receiving said vehicle signal Ym, said modulated output signal X, and said modulation carrier signal Mt; demodulating said vehicle signal Ym using said output signal X and said modulation carrier signal Mt in order to obtain estimated modulation data Ms; estimating an estimated audio power Ps on the basis of said vehicle signal Ym and said output signal X; outputting said estimated modulation data Ms and said estimated audio power Ps to said validation unit (400); wherein said validation unit (400) is arranged for: receiving said estimated modulation data Ms, said modulation data Md, and said estimated audio power Ps; determining a difference between said estimated modulation data Ms and said modulation data Md; validating an output of said audio message when said difference is below a predetermined threshold and said estimated audio power Ps is above a predetermined power threshold; outputting validation data corresponding to said validation. The wording “functional safety validating” may refer to determining that a safety message has been delivered, i.e. that the function of the audio message of providing information to the driver of the vehicle has been executed. Furthermore, the volume of the delivered audio message may be such that the driver should be able to understand the information comprised in the audio message. Therefore, the volume should be above a certain minimum volume and above the volume of other sounds around the driver.

[0008] The wording “vehicle” may refer to any kind of objects which is suitable for carrying human beings and is not restricted on cars. In one or more embodiments, the vehicle may be a car, a motorbike, a van, a truck, a bicycle, or a scooter. In one or more embodiments, the system may be part of the infotainment system of a vehicle. The invention may also be applied to rooms of all kinds which are suitable to host human beings.

[0009] The system according to the invention comprises an audio safety modulator, an audio generator, an audio recorder, an audio safety demodulator and a validation unit. These may be separate devices, separate processors on a PCB, or separate programs running on a single processor.

[0010] In one or more embodiments, the safety relevant audio message Xr is received by the audio safety modulator from a memory that is comprised in the system. In one or more other embodiments, the audio message Xr is received by the audio safety modulator from a server, that is located outside the vehicle, for example over a wireless connection.

[0011] In one or more embodiments, different audio messages may be modulated with different modulation data. For each audio message, the modulation data Md may be retrieved from a memory that is comprised in the system or is received by the audio safety modulator from a server that is located outside the vehicle, for example over a wireless connection. The audio generator receives said signal Xa from the audio safety modulator and uses one or more speakers in the vehicle to convey the audio message to the driver and other passengers in the vehicle.

[0012] In order to determine what the passenger would be able to hear, the audio recorder may use one or more microphones to receive a vehicle sound. This vehicle sound may comprise the speaker sound and reflections of the speaker sound against surfaces in the interior of the vehicle, and other sounds from the vehicle itself (e.g. the engine), from the passengers speaking, and / or from outside the vehicle. The speaker sound may be changed in the vehicle by echoes of the speaker sound on surfaces and / or malfunctioning of the one or more speakers in the vehicle.

[0013] The audio safety demodulator demodulates said vehicle signal Ym using said output signal X and said modulation carrier signal Mt in order to obtain estimated modulation data Ms. The audio safety demodulator further estimates an estimated audio power Ps on the basis of said vehicle signal Ym and said modulated output signal X.

[0014] The validation unit determines a difference between said estimated modulation data and said modulation data and validates the output of said audio message when said difference is below a predetermined threshold and said estimated audio power Ps is above a predetermined power threshold.

[0015] This difference may indicate how well the audio message could have been heard by the passengers, wherein a smaller difference indicates a better conveying of the audio message. When the estimated audio power Ps is not above a predetermined power threshold, this may indicate that one or more speakers are not working or nor working sufficiently.

[0016] According to the invention, the signal Xa, which is used by the audio generator to output the speaker sound in the interior of the vehicle, can be modulated by the audio safety modulator in a way that it does not comprise the modulation carrier. This kind of modulation may be referred to as carrier-suppressed modulation.

[0017] An advantage of the invention may be that acoustic power variation by a modulation carrier (e.g. with a frequency of 19 kHz, instead of directly modulated) may result in a power spectrum for the modulation influenced part that is very difficult or inaudible to be recognized by a human ear (e.g. in the frequency range of 19kHz -24kHz). Another advantage of the invention is that, if there is just a defect in the transfer of the safety relevant frequency range (e.g. by a defect of the loudspeaker for that frequency range) it will be detected by the safety demodulator, because the audio safety demodulator use the transferred safety relevant audio signal frequencies as carrier frequencies and it may not demodulate the modulation data without the transferred carrier frequencies.

[0018] Furthermore, the modulation data rate may be higher than in systems known in the art, since because of the modulation with the modulation carrier, a higher data frequency may be applied irrespective of the frequencies of the audio signal. Moreover, the signal Xa does not need to be limited to frequencies audible to the human ear (20 Hz -20 kHz).

[0019] Another advantage may be that the continuous modulation using a modulation carrier yields a more reliable validation of the outputting of the audio message. Furthermore, since the degree of modulation can be freely chosen, the validation may be more robust against disturbances und interferences.

[0020] Yet another advantage may be, that the system may use standard speakers available in a vehicle, which are usually limited to conveying audio in the range of 20 Hz - 24 kHz. Furthermore, since the frequency range 19 kHz - 24 kHz is difficult or impossible to hear for a human ear, this range may be used for the validation of the outputting.

[0021] In one or more embodiments, the audio safety modulator further comprises: a safety relevance filter (101 ) arranged for filtering said safety relevant audio message Xr in order to obtain said output signal X, wherein said output signal X comprises all safety information that is audible for a passenger; a safety irrelevance filter (102) arranged for filtering said safety relevant audio message Xr in order to obtain a signal Xi, wherein said signal Xi comprises information from said audio message Xr that is not safety relevant; a modulation data generator (140) arranged for generating modulation data Md and for adding modulation pause data to said modulation data Md on the basis of said output signal X, wherein modulation pause data indicate an absence of modulation in a predetermined time-period, wherein preferably a sound power of said output signal X is below a predefined threshold, or wherein modulation pause data are added between each symbol of modulation data Md; a carrier signal generator (150) arranged for generating a carrier signal Mt; a modulator (110) arranged for modulating said output signal X on the basis of said modulation data Md and said carrier signal Mt in order to obtain signal Xm; a modulation product filter (120) arranged for filtering said signal Xm in order to obtain safety-relevant modulated signal Xb; and, a superposition unit (130) arranged for super positioning said signal Xb with said signal Xi in order to obtain signal Xa.

[0022] In these embodiments, only a part of the safety relevant audio message Xr, i.e. the part comprising all safety information that is audible for a passenger is used for modulation. The other part of the safety relevant audio message Xr is filtered out and added to the modulated signal. This signal Xa may then be used by the speakers. An advantage of this embodiment is that a passenger will hardly be able to hear the difference between audio based on the audio message Xr and audio based on the signal Xa.

[0023] An advantage of using modulation pause data may be that (i) a low sound power does not contribute to a non-validation and / or that (ii) modulation pauses may be characteristic for the audio message and thus may be used for the validation.

[0024] In one or more embodiments, the superposition unit (130) is arranged for super positioning said signal Xb, said signal Xi and a noise signal Xz, in order to obtain signal Xa. The noise signal Xz may comprise non-audible or non-disturbing noise over the complete frequency spectrum, generated by a noise generator (160). An advantage of adding a noise signal may be that it enable and / or improves the generation and / or adaptation of an inverse room transfer function InvGxy.

[0025] In one or more embodiments, the additional noise signal power of Xz may be generated in dependence of the noise in the environment of the interior, especially in a moving vehicle. The environmental noise level may be derived from the vehicle signal Ym and / or the speed of the vehicle.

[0026] In one or more embodiments, the audio safety demodulator is further arranged for: estimating a time variant relation GG between said vehicle signal Ym and signal Xa; estimating of an output signal Ys on the basis of Xa using GG, and / or estimating an input signal Xs on the basis of Ym using GG; in a first stage, demodulating said estimated input signal Xs and / or said estimated output signal Ys, in order to get a first demodulated signal XXs, and / or respectively a first demodulated signal YYs, by using said output signal X, in a second stage, demodulation XXs and / or YYs by using modulation carrier signal Mt in order to obtain a signal XXf and / or YYf, respectively. filtering XXf and / or YYf by possible modulation frequencies, which symbolizes modulation data Md; and, estimating modulation data Ms from said filter results for XXf and / or YYf.

[0027] In one or more embodiments, the audio safety demodulator is further arranged for: estimating an estimated signal Xs on the basis of said vehicle signal Ym and said output signal X using an inverse room transfer function; in a first stage, demodulating said estimated signal Xs or a difference signal X-Xs by using signal X as carrier signal, in order to obtain demodulation product signal XXs; in a second stage, demodulating said signal XXs with the modulation carrier signal Mt in order to obtain a modulation signal XXd, preferably using an estimated frequency spectrum comprises frequencies generated by modulator (110) for representing modulation data Md; filtering said signal XXd in order to obtain a signal XXf, wherein said signal XXf, only comprises frequencies representing modulation data Md; and, estimating estimated modulation data Ms on the basis of said signal XXf: and / or wherein said audio safety demodulator is further arranged for: estimating an estimated signal Ys on the basis of said signal Xa and said output signal X using a room transfer function; demodulating a difference signal Y-Ys in order to obtain demodulation product signal YYs; demodulating said signal YYs with the modulation carrier signal Mt in order to obtain a modulation signal YYd; filtering said signal YYd in order to obtain a signal YYf; and, estimating estimated modulation data Ms on the basis of said signal YYf.

[0028] In one or more embodiments, said audio safety demodulator is further arranged for generating a room transfer function Gxy and / or an inverse room transfer function InvGxy based on an audio output Xn signal to the speakers and a vehicle signal Yn recorded by the microphones, wherein the audio transfer function Gxy is preferably determined from a ratio between an estimated cross-power density Sxy and the car power density Sxx or from a ratio between discrete Fourier transforms of Yn and Xn over a, preferably longer, time period chosen to reduce random noise.

[0029] In further embodiments, generating the inverse room transfer function InvGxy and / or the room transfer function Gxy is repeated multiple times in order to adjust the inverse room transfer function InvGxy and / or the room transfer function Gxy to changes in the interior of the vehicle. For example, a change in the number and / or location of passengers and / or luggage inside the interior.

[0030] An advantage of the inverse room transfer function InvGxy may be that with the inverse room transfer function InvGxy, the signal Xs is estimated which allows a good estimation forXb using the signals Ym and X. That is especially advantageous when the signal Ym comprises in time overlapping modulation parts as a result of reflections of Xa in the interior of the vehicle.

[0031] In one or more embodiments, a modulation data frequency is regularly followed by a modulation pause inserted by the modulator (110) in order to mitigate overlapping different modulation parts as a result of reflections of Xa in the interior of the vehicle.

[0032] In one or more embodiments, signal Xn comprises all frequency ranges and / or comprise a signal Xz which comprises non-audible noise across the whole spectrum. This noise signal may advantageously improve the generation of the inverse room transfer function InvGxy.

[0033] In one or more embodiments, said audio safety demodulator is further arranged for estimating the audio power Ps based on said output signal X and an estimated signal Xs and / or Ys.

[0034] In one or more embodiments, the system further comprises a reaction unit (500), arranged for: receiving said validation data from said validation unit; based on said validation data, executing a safety error reaction in case said validation data indicates that said outputting of said audio message was not validated; wherein preferably said reaction unit (500) is a display and said error reaction is displaying an error message and / or a text corresponding to said safety relevant audio message on said display.

[0035] According to another aspect of the invention, a method for functional safety validating an output of an audio message in an interior of a vehicle (20), the method comprising the steps of: receiving a safety relevant audio message Xr; generating, based on said audio message Xr, of an output signal X, and modulation data Md, wherein said output signal X comprises all safety information, that is audible for a passenger in said interior, without any safety modulation; generating a signal Xa, wherein said signal Xa comprises (i) the safety relevant frequency spectrum of the output signal X, (ii) modulation frequencies, which correspond to modulation data Md and which are preferably not perceivable and / or not disturbing to said passenger, and (iii) the non-safety-relevant frequency spectrum of audio message Xr; generating a modulation carrier signal Mt, wherein said modulation carrier signal Mt does not comprise said modulation frequencies corresponding to modulation data Md; outputting a speaker sound corresponding to said signal Xa using one or more speakers in said interior of said vehicle; receiving a vehicle sound using one or more microphones in said interior of said vehicle (20); generating a vehicle signal Ym corresponding to said received vehicle sound to said audio safety demodulator; demodulating said vehicle signal Ym using said output signal X and said modulation carrier signal Mt in order to obtain estimated modulation data Ms; estimating an estimated audio power Ps on the basis of said vehicle signal Ym and said output signal X; determining a difference between said estimated modulation data Ms and said modulation data Md; validating an output of said audio message when said difference is below a predetermined threshold and said estimated audio power Ps is above a predetermined power threshold; generating validation data corresponding to said validation.

[0036] In or more embodiments, the method further comprises the steps of: filtering said safety relevant audio message Xr in order to obtain said output signal X, wherein said output signal X comprises all safety information that is audible for a passenger; filtering said safety relevant audio message Xr in order to obtain a signal Xi, wherein said signal Xi comprises information from said audio message Xr that is not safety relevant; generating modulation data Md and for adding modulation pause data to said modulation data Md on the basis of said output signal X, wherein modulation pause data indicate an absence of modulation in a predetermined time-period, wherein preferably a sound power of said output signal X is below a predefined threshold, or wherein modulation pause data are regularly added between each symbol of modulation data Md; generating a carrier signal Mt; modulating said output signal X on the basis of said modulation data Md and said carrier signal Mt in order to obtain signal Xm; filtering said signal Xm in order to obtain said safety-relevant modulated signal Xb; and, super positioning said signal Xb with said signal Xi in order to obtain signal Xa.

[0037] In or more embodiments, the method further comprises the steps of: estimating a time variant relation GG between said vehicle signal Ym and signal Xa; estimating of an output signal Ys on the basis of Xa using GG, and / or estimating an input signal Xs on the basis of Ym using GG; in a first stage, demodulating said estimated input signal Xs and / or said estimated output signal Ys, in order to get a first demodulated signal XXs, and / or respectively a first demodulated signal YYs, by using said output signal X, in a second stage, demodulation XXs and / or YYs by using modulation carrier signal Mt in order to obtain a signal XXf and / or YYf, respectively. filtering XXf and / or YYf by possible modulation frequencies, which symbolizes modulation data Md; and, estimating estimated modulation data Ms from said filter results for XXf and / or YYf.

[0038] In or more embodiments, the method further comprises the steps of: estimating an estimated signal Xs on the basis of said vehicle signal Ym and said output signal X using an inverse room transfer function; in a first stage, demodulating said estimated signal Xs or a difference signal X-Xs by using signal X as carrier signal, in order to obtain demodulation product signal XXs; in a second stage, demodulating said signal XXs with the modulation carrier signal Mt in order to obtain a modulation signal XXd, preferably using an estimated frequency spectrum comprises frequencies representing modulation data Md; filtering said signal XXd in order to obtain a signal XXf, wherein said signal XXf, only comprises frequencies representing modulation data Md; and, estimating estimated modulation data Ms on the basis of said signal XXf: and / or wherein the method further comprises the step of: estimating an estimated signal Ys on the basis of said signal Xa and said output signal X using a room transfer function; demodulating a difference signal Y-Ys in order to obtain demodulation product signal YYs; demodulating said signal YYs with the modulation carrier signal Mt in order to obtain a modulation signal YYd; filtering said signal YYd in order to obtain a signal YYf; and, estimating estimated modulation data Ms on the basis of said signal YYf.

[0039] In or more embodiments, the method further comprises the step of generating a room transfer function Gxy and / or an inverse room transfer function InvGxy based on signals Xn and Yn, wherein the audio transfer function Gxy is preferably determined from a ratio between an estimated cross-power density Sxy and the car power density Sxx or from a ratio between discrete Fourier transforms of Yn and Xn over a, preferably longer, time period chosen to reduce random noise.

[0040] In or more embodiments, the method further comprises the step of estimating the audio power Ps based on said output signal X and an estimated signal Xs and / or Ys.

[0041] In or more embodiments, the method further comprises the step of, based on said validation data, executing a safety error reaction in case said validation data indicates that said outputting of said audio message was not validated, wherein preferably said reaction unit (500) is a display and said error reaction is displaying an error message and / or a text corresponding to said safety relevant audio message on said display. According to another aspect of the invention, a vehicle is provided, comprising a system according to any of the embodiments as described in this document.

[0042] According to another aspect of the invention a computer program is provided, herein said computer program comprises instructions which, when the program is executed by a computer, cause the computer to carry out the steps of the method of according to any of the embodiments described in this document. Furthermore, a computer-readable medium is provided having stored thereon said computer program.

[0043] The working, advantages and embodiments of the method and the vehicle as well as the working, advantages and embodiments of the computer program and computer-readable medium, correspond with the working, advantages and embodiments of the system as described in this document, mutatis mutandis.

[0044] BRIEF DESCRIPTION OF THE DRAWINGS

[0045] Figure 1 shows a schematic overview of a system 10 for functional safety validating an output of an audio message in an interior of a vehicle 20 according to one or more embodiments of the invention;

[0046] Figure 2 shows a schematic overview of an audio safety modulator according to one or more embodiments of the invention;

[0047] Figure 3 shows a schematic overview of an audio safety demodulator according to one or more embodiments of the invention;

[0048] Figure 4 shows a schematic overview of the generation and use of an inverse room transfer function InvGxy according to one or more embodiments of the invention; Figure 5 shows a schematic overview of a validation unit according to one or more embodiments of the invention;

[0049] Figure 6 shows a vehicle with a system for functional safety validating an output of an audio message according to one or more embodiments; and,

[0050] Figure 7 shows a schematic overview of a method for functional safety validating an output of an audio message in an interior of a vehicle according to one or more embodiments.

[0051] DETAILED DESCRIPTION

[0052] Figure 1 shows a schematic overview of a system 10 for functional safety validating an output of an audio message in an interior of a vehicle according to one or more embodiments. The system 10 comprises an audio safety modulator 100, an audio generator 301 , an audio recorder 303, an audio safety demodulator 200 and validation unit 400 and, optionally a reaction unit 500.

[0053] The audio safety modulator 100 receives a safety relevant audio message Xr and outputs to the audio safety demodulator 200 an output signal X and a modulation carrier signal Mt which itself does not contain or carry any modulation data. The audio safety modulator 100 outputs a signal Xa to the audio generator 301 and modulation data Md to the validation unit 400.

[0054] The safety relevant audio message Xr may be a warning or an instruction message for the driver or for the other passengers. The message may be stored in memory of the system, or it may be stored on a remote server. The output signal X comprises all safety information, that is audible for a passenger in said interior, without any safety modulation.

[0055] The signal Xa comprises (i) the safety relevant frequency spectrum of the output signal X, (ii) modulation frequencies, which correspond to modulation data Md and which are preferably not perceivable and / or not disturbing to said passenger, and (iii) the non-safety-relevant frequency spectrum of audio message Xr.

[0056] The modulation carrier signal Mt corresponds to the carrier signal which is used for the modulation, and it does not comprise modulation frequencies corresponding to the modulation data Md.

[0057] The modulation data Md may be determined on the basis of output signal X. Modulation pause data may be added to the modulation data Md. Modulation pause data indicate an absence of modulation in a predetermined time-period, wherein preferably a sound power of said output signal X is below a predefined threshold. Modulation pause data may also be regularly added between each symbol of modulation data Md.

[0058] The audio generator 301 receives the signal Xa and outputs a speaker sound corresponding to said signal Xa using one or more speakers in the interior the vehicle. The audio recorder 303 receives a vehicle sound using one or more microphones in said interior of said vehicle 20 and outputs a vehicle signal Ym corresponding to said received vehicle sound to said audio safety demodulator 200. The vehicle sound may comprise the speaker sound and its reflections, but also other sounds N from the vehicle itself (e.g. the engine), from the passengers speaking, and / or from outside the vehicle.

[0059] The audio safety demodulator 200 receives said vehicle signal Ym, said modulated output signal X, and said modulation carrier signal Mt, and demodulates said vehicle signal Ym using said output signal X and said modulation carrier signal Mt in order to obtain estimated modulation data Ms. The audio safety demodulator 200 further estimates an estimated audio power Ps on the basis of said vehicle signal Ym and said output signal X.

[0060] The estimated modulation data Ms and said estimated audio power Ps are outputted to the validation unit 400. The validation unit 400 determines a difference between said estimated modulation data Ms and said modulation data Md and it validates the output of said audio message when said difference is below a predetermined threshold and said estimated audio power Ps is above a predetermined power threshold. The validation unit 400 may output corresponding validation data E to the reaction unit 500.

[0061] The reaction unit 500 may, based on said validation data E, executes a safety error reaction in case said validation data E indicates that said outputting of said audio message was not validated. In one or more embodiments, reaction unit 500 is a display and said error reaction is displaying an error message and / or a text corresponding to said safety relevant audio message on said display. In one or more embodiment, the safety error reaction may comprise outputting the audio message again using the embodiments of the system and the method described in this document.

[0062] Figure 2 shows a schematic overview of an audio safety modulator 100 according to one or more embodiments of the invention. Audio safety modulator 100 may comprise a safety relevance filter 101 , a safety irrelevance filter 102, a modulation data generator 140, a carrier signal generator 150, a modulator 110, a modulation product filter 120 and a superposition unit 130 and, optionally, a noise generator 160.

[0063] The safety relevance filter 101 is arranged for filtering said safety relevant audio message Xr in order to obtain said output signal X, wherein said output signal X comprises all safety information that is audible for a passenger. The safety irrelevance filter 102 is arranged for filtering said safety relevant audio message Xr in order to obtain a signal Xi, wherein said signal Xi comprises information from said audio message Xr that is not safety relevant.

[0064] The modulation data generator 140 is arranged for generating modulation data Md and for adding modulation pause data to said modulation data Md on the basis of said output signal X. The modulation pause data may indicate an absence of modulation in a predetermined time-period, wherein preferably a sound power of said output signal X is below a predefined threshold. The modulation pause data may also regularly be added between each symbol of modulation data Md.

[0065] The carrier signal generator 150 is arranged for generating a carrier signal Mt. The modulator 110 is arranged for modulating said output signal X on the basis of said modulation data Md and said carrier signal Mt in order to obtain signal Xm. The modulation product filter is arranged for filtering said signal Xm in order to obtain a safety-relevant modulated signal Xb.

[0066] In one or more embodiment, the noise generator 160 is arranged for generating a noise signal Xz. The noise signal Xz may comprise non-audible or non-disturbing noise over the complete frequency spectrum.

[0067] The superposition unit 130 is arranged for super positioning said signal Xb with said signal Xi, and optionally with signal Xz, in order to obtain signal Xa.

[0068] Figure 3 shows a schematic overview of an audio safety demodulator 200 according to one or more embodiments of the invention.

[0069] The audio safety demodulator 200 may comprise a room acoustic compensator 210, which estimates an estimated signal Xs on the basis of said vehicle signal Ym and said output signal X using an inverse room transfer function InvGxy. This function may be generated by room acoustic compensator 210, which is further explained with reference to figure 4.

[0070] In a first stage, the estimated signal Xs or a difference signal X-Xs is used by a first demodulation unit 220, which demodulates this respective signal using signal X in order to obtain demodulation product signal XXs. This signal XXs may still contain the periodic modulation carrier Mt, which could be of a quite high frequency (e.g. 19 kHz). In a second stage, the periodic modulation signal Mt is removed from the signal XXs e.g. by generating the product of Mt and XXs and low pass filtering the result below the frequencies of Mt and above the highest frequency in Md. It may be the case that further limits for this low pass needs to be considered, e.g. due to the highest transfer frequencies between Xa and Ym and the spectrum of Xa by the resulting modulation with Md and Mt in 100.

[0071] A second demodulation unit 230 demodulates said signal XXs with the modulation carrier signal Mt in order to obtain a modulation signal XXd, preferably using an estimated frequency spectrum comprises frequencies generated by modulator (110) for representing modulation data Md. Signal XXd however may still comprise frequencies that are not characteristic for the modulation. These frequencies may be filtered out in filter 240, which results in signal XXf, wherein said signal XXf, only comprises frequencies representing modulation data Md.

[0072] The audio safety demodulator 200 may further comprise a modulation estimation unit 250 arranged for estimating estimated modulation data Ms on the basis of said signal XXf. The audio safety demodulator 200 may further comprise power estimation unit 221 , which estimates the audio power Ps based on said output signal X and an estimated signal Xs.

[0073] Figure 4 shows a schematic overview of the generation and use of an inverse room transfer function InvGxy according to one or more embodiments of the invention. The audio safety demodulator 200 may comprise a calculation unit 211 , which determines a room transfer function Gxy on the basis of a ratio between an estimated cross-power density Sxy and the car power density Sxx. Alternatively, the function Gxy may be determined using a ratio between the discrete Fourier transform of Yn and the discrete Fourier transform of Xn over a certain time period. This time period may be chosen such that the effect of random noise is reduced below a predetermined level.

[0074] The function inverter 212 inverts the function Gxy in order to obtain the inverse room transfer function InvGxy. The inverse room transfer function InvGxy is used by the estimation unit 210 for estimating an estimated signal Xs on the basis of said vehicle signal Ym.

[0075] The working of the validation unit 400 is explained with reference to Figure 5, which shows a schematic overview of a validation unit according to one or more embodiments of the invention. The validation unit 400 may comprise a differentiator 410, which is arranged for determining a difference between the estimated modulation data Ms and the modulation data Md. The differentiator 410 outputs this difference to decision unit 430.

[0076] The validation unit 400 may comprise a comparator 420 which compares the estimated audio power Ps with a predetermined threshold. The comparator 420 outputs the result of this comparison to a decision unit 430.

[0077] The validation unit 400 may comprise decision unit 430 which outputs validation data E, which indicates whether the difference is below a predetermined threshold and said estimated audio power Ps is above a predetermined power threshold, in other words, whether the outputting of the audio message is validated or not.

[0078] Figure 6 shows a vehicle 20 with a system 10 for functional safety validating an output of an audio message according to one or more embodiments.

[0079] Figure 7 shows a schematic overview of a method 700 for functional safety validating an output of an audio message in an interior of a vehicle according to one or more embodiments.

[0080] Method 700 may comprise the following steps:

[0081] 710 receiving a safety relevant audio message Xr;

[0082] 715 generating, based on said audio message Xr, of an output signal X, and modulation data Md, wherein said output signal X comprises all safety information, that is audible for a passenger in said interior, without any safety modulation;

[0083] 720 generating a signal Xa, wherein said signal Xa comprises (i) the safety relevant frequency spectrum of the output signal X, (ii) modulation frequencies, which correspond to modulation data Md and which are preferably not perceivable and / or not disturbing to said passenger, and (iii) the non-safety-relevant frequency spectrum of audio message Xr;

[0084] 725 generating a modulation carrier signal Mt, wherein said modulation carrier signal Mt does not comprise said modulation frequencies corresponding to modulation data Md;

[0085] 730 outputting a speaker sound corresponding to said signal Xa using one or more speakers in said interior of said vehicle;

[0086] 735 receiving a vehicle sound using one or more microphones in said interior of said vehicle (20); 740 generating a vehicle signal Ym corresponding to said received vehicle sound 745 demodulating said vehicle signal Ym using said output signal X and said modulation carrier signal Mt in order to obtain estimated modulation data Ms;

[0087] 750 estimating an estimated audio power Ps on the basis of said vehicle signal Ym and said output signal X;

[0088] 755 determining a difference between said estimated modulation data Ms and said modulation data Md;

[0089] 760 validating an output of said audio message when said difference is below a predetermined threshold and said estimated audio power Ps is above a predetermined power threshold;

[0090] 765 generating validation data corresponding to said validation

[0091] In one or more embodiments, the method or preferably step 720 may further comprise the steps of:

[0092] 810 filtering said safety relevant audio message Xr in order to obtain said output signal X, wherein said output signal X comprises all safety information that is audible for a passenger;

[0093] 820 filtering said safety relevant audio message Xr in order to obtain a signal Xi, wherein said signal Xi comprises information from said audio message Xr that is not safety relevant;

[0094] 830 generating modulation data Md and for adding modulation pause data to said modulation data Md on the basis of said output signal X, wherein modulation pause data indicate an absence of modulation in a predetermined time-period, wherein preferably a sound power of said output signal X is below a predefined threshold, or wherein modulation pause data are added between each symbol of modulation data Md;

[0095] 840 generating a carrier signal Mt;

[0096] 850 modulating said output signal X on the basis of said modulation data Md and said carrier signal Mt in order to obtain signal Xm;

[0097] 860 filtering said signal Xm in order to obtain said safety-relevant modulated signal Xb; and,

[0098] 870 super positioning said signal Xb with said signal Xi in order to obtain signal Xa.

[0099] In one or more embodiments, method or preferably step 745 may further comprise the steps of:

[0100] 910 estimating an estimated signal Xs on the basis of said vehicle signal Ym and said output signal X using an inverse room transfer function;

[0101] 920 in a first stage, demodulating said estimated signal Xs or a difference signal X-Xs by using signal X as carrier signal, in order to obtain demodulation product signal XXs;

[0102] 930 in a second stage, demodulating said signal XXs with the modulation carrier signal Mt in order to obtain a modulation signal XXd, preferably using an estimated frequency spectrum comprises frequencies representing modulation data Md;

[0103] 940 filtering said signal XXd in order to obtain a signal XXf, wherein said signal XXf, only comprises frequencies representing modulation data Md;

[0104] 950 estimating estimated modulation data Ms on the basis of said signal XXf;

[0105] Alternatively, in one or more embodiments, the method or preferably step 745 may further comprise the steps of:

[0106] 910 estimating an estimated signal Ys on the basis of said signal Xa and said output signal X using a room transfer function;

[0107] 920 demodulating said estimated signal Ys or a difference signal Y-Ys in order to obtain demodulation product signal YYs;

[0108] 930 demodulating said signal YYs with the modulation carrier signal Mt in order to obtain a modulation signal YYd;

[0109] 940 filtering said signal YYd in order to obtain a signal YYf; and, 950 estimating estimated modulation data Ms on the basis of said signal YYf.

[0110] Alternatively, in one or more embodiments, the method may further comprise the step:

[0111] 770 based on said validation data, executing a safety error reaction in case said validation data indicates that said outputting of said audio message was not validated, wherein preferably said error reaction is displaying an error message and / or a text corresponding to said safety relevant audio message on said display.

[0112] In one or more embodiments of the method or preferably step 910 may further comprise the step of generating a room transfer function Gxy and / or an inverse room transfer function InvGxy based on signals Xn and Yn, wherein the audio transfer function Gxy is preferably determined from a ratio between an estimated cross-power density Sxy and the car power density Sxx or from a ratio between discrete Fourier transforms of Yn and Xn over a, preferably longer, time period chosen to reduce random noise.

[0113] In summary, a system and a method for validating an output of an audio message in an interior of a vehicle is provided. An audio safety modulator modulates said audio message using said audio frequencies as carrier frequencies, an additional modulation carrier and modulation data. An audio generator outputs a speaker sound corresponding to said modulated audio message using one or more speakers in said interior. An audio recorder receives a vehicle sound using one or more microphones in said interior and outputs a vehicle signal corresponding to said received vehicle sound. An audio safety modulator generates estimated modulation data and an estimated audio power from said vehicle signal. On the basis thereof, a validation unit determines whether the outputting of said audio message is validated or not.

[0114] Those of skill will appreciate that the various illustrative logical blocks, modules, circuits, and algorithm steps described in connection with the embodiments disclosed herein may be implemented as electronic hardware, computer software, or combinations of both. To clearly illustrate this interchangeability of hardware and software, various illustrative components, blocks, modules, circuits, and steps have been described above generally in terms of their functionality. Whether such functionality is implemented as hardware or software depends upon the particular application and design constraints imposed on the overall system. Those of skill in the art may implement the described functionality in varying ways for each particular application, but such implementation decisions should not be interpreted as causing a departure from the scope of the present invention.

[0115] The previous description of the disclosed embodiments is provided to enable any person skilled in the art to make or use the present invention. Various modifications to these embodiments will be readily apparent to those skilled in the art, and the generic principles defined herein may be applied to other embodiments without departing from the spirit or scope of the invention. Thus, the present invention is not intended to be limited to the embodiments shown herein but is to be accorded the widest scope consistent with the principles and novel features disclosed herein.

[0116] The benefits and advantages that may be provided by the present invention have been described above with regard to specific embodiments. These benefits and advantages, and any elements or limitations that may cause them to occur or to become more pronounced are not to be construed as critical, required, or essential features of any or all of the claims. As used herein, the terms “comprises,” “comprising,” or any other variations thereof, are intended to be interpreted as non-exclusively including the elements or limitations which follow those terms. Accordingly, a system, method, or other embodiment that comprises a set of elements is not limited to only those elements and may include other elements not expressly listed or inherent to the claimed embodiment.

[0117] While the present invention has been described with reference to particular embodiments, it should be understood that the embodiments are illustrative and that the scope of the invention is not limited to these embodiments. Many variations, modifications, additions and improvements to the embodiments described above are possible. It is contemplated that these variations, modifications, additions and improvements fall within the scope of the invention as detailed within the following claims.

Claims

CLAIMS1 . System (10) for functional safety validating an output of an audio message in an interior of a vehicle (20), the system comprising: an audio safety modulator (100) an audio generator (301 ) an audio recorder (303) an audio safety demodulator (200) a validation unit (400) wherein audio safety modulator (100) is arranged for: receiving a safety relevant audio message Xr; outputting, based on said audio message Xr, of an output signal X to said audio safety demodulator (200), wherein said output signal X comprises all safety information, that is audible for a passenger in said interior, without any safety modulation; outputting a signal Xa to the audio generator (301 ), wherein said signal Xa comprises (i) the safety relevant frequency spectrum of the output signal X, (ii) modulation frequencies, which correspond to modulation data Md and which are preferably not perceivable and / or not disturbing to said passenger, and (iii) the non-safety-relevant frequency spectrum of audio message Xr; outputting a modulation carrier signal Mt to the audio safety demodulator (200), wherein said modulation carrier signal Mt does not comprise said modulation frequencies corresponding to modulation data Md; and, outputting said modulation data Md to the validation unit (400); wherein the audio generator (301 ) is arranged for: receiving said signal Xa; outputting a speaker sound corresponding to said signal Xa using one or more speakers in said interior of said vehicle; wherein the audio recorder (303) is arranged for: receiving a vehicle sound using one or more microphones in said interior of said vehicle (20); outputting a vehicle signal Ym corresponding to said received vehicle sound to said audio safety demodulator (200); wherein the audio safety demodulator (200) is arranged for:receiving said vehicle signal Ym, said modulated output signal X, and said modulation carrier signal Mt; demodulating said vehicle signal Ym using said output signal X and said modulation carrier signal Mt in order to obtain estimated modulation data Ms; estimating an estimated audio power Ps on the basis of said vehicle signal Ym and said output signal X; outputting said estimated modulation data Ms and said estimated audio power Ps to said validation unit (400); wherein said validation unit (400) is arranged for: receiving said estimated modulation data Ms, said modulation data Md, and said estimated audio power Ps; determining a difference between said estimated modulation data Ms and said modulation data Md; validating an output of said audio message when said difference is below a predetermined threshold and said estimated audio power Ps is above a predetermined power threshold; outputting validation data corresponding to said validation.

2. System according to claim 1 , wherein audio safety modulator further comprises: a safety relevance filter (101 ) arranged for filtering said safety relevant audio message Xr in order to obtain said output signal X, wherein said output signal X comprises all safety information that is audible for a passenger; a safety irrelevance filter (102) arranged for filtering said safety relevant audio message Xr in order to obtain a signal Xi, wherein said signal Xi comprises information from said audio message Xr that is not safety relevant; a modulation data generator (140) arranged for generating modulation data Md and for adding modulation pause data to said modulation data Md on the basis of said output signal X, wherein modulation pause data indicate an absence of modulation in a predetermined time-period, wherein preferably a sound power of said output signal X is below a predefined threshold, or wherein modulation pause data are added between each symbol of modulation data Md; a carrier signal generator (150) arranged for generating a carrier signal Mt; a modulator (110) arranged for modulating said output signal X on the basis of said modulation data Md and said carrier signal Mt in order to obtain signal Xm;a modulation product filter (120) arranged for filtering said signal Xm in order to obtain said safety-relevant modulated signal Xb; and, a superposition unit (130) arranged for super positioning said signal Xb with said signal Xi in order to obtain signal Xa.

3. System according to claim 1 or 2, wherein said audio safety demodulator is further arranged for: estimating a time variant relation GG between said vehicle signal Ym and signal Xa; estimating of an output signal Ys on the basis of Xa using GG, and / or estimating an input signal Xs on the basis of Ym using GG; in a first stage, demodulating said estimated input signal Xs and / or said estimated output signal Ya, in order to get a first demodulated signal XXs, and / or respectively a first demodulated signal YYs, by using said output signal X, in a second stage, demodulation XXs and / or YYs by using modulation carrier signal Mt in order to obtain a signal XXf and / or YYf, respectively. filtering XXf and / or YYf by possible modulation frequencies, which symbolizes modulation data Md; and, estimating estimated modulation data Ms from said filter results for XXf and / or YYf.

4. System according to any of the preceding claims, wherein said audio safety demodulator is further arranged for: estimating an estimated signal Xs on the basis of said vehicle signal Ym and said output signal X using an inverse room transfer function; in a first stage, demodulating said estimated signal Xs or a difference signal X-Xs by using signal X as carrier signal, in order to obtain demodulation product signal XXs; in a second stage, demodulating said signal XXs with the modulation carrier signal Mt in order to obtain a modulation signal XXd, preferably using an estimated frequency spectrum that comprises frequencies generated by modulator (110) for representing modulation data Md; filtering said signal XXd in order to obtain a signal XXf, wherein said signal XXf, only comprises frequencies representing modulation data Md; and, estimating estimated modulation data Ms on the basis of said signal XXf:or wherein said audio safety demodulator is further arranged for: estimating an estimated signal Ys on the basis of said signal Xa and said output signal X using a room transfer function; demodulating a difference signal Y-Ys in order to obtain demodulation product signal YYs; demodulating said signal YYs with the modulation carrier signal Mt in order to obtain a modulation signal YYd; filtering said signal YYd in order to obtain a signal YYf; and, estimating estimated modulation data Ms on the basis of said signal YYf.

5. System according to claim 4, wherein said audio safety demodulator is further arranged for generating a room transfer function Gxy and / or an inverse room transfer function InvGxy based on an audio output signal Xn of the audio generator (301 ) and a vehicle signal Yn of the audio recorder (303), wherein the audio transfer function Gxy is preferably determined from a ratio between an estimated cross-power density Sxy and the car power density Sxx or from a ratio between discrete Fourier transforms of Yn and Xn over a, preferably longer, time period chosen to reduce random noise.

6. System according to any of the preceding claims, wherein said audio safety demodulator is further arranged for: estimating estimated audio power Ps based on said output signal X and an estimated signal Xs and / or Ys.

7. System according to any of the preceding claims, further comprising a reaction unit (500), arranged for:- receiving said validation data from said validation unit;- based on said validation data, executing a safety error reaction in case said validation data indicates that said outputting of said audio message was not validated; wherein preferably said reaction unit (500) is a display and said error reaction is displaying an error message and / or a text corresponding to said safety relevant audio message on said display.

8. Method for functional safety validating an output of an audio message in an interior of a vehicle (20), the method comprising the steps of: receiving a safety relevant audio message Xr;generating, based on said audio message Xr, of an output signal X, and modulation data Md, wherein said output signal X comprises all safety information, that is audible for a passenger in said interior, without any safety modulation; generating a signal Xa, wherein said signal Xa comprises (i) the safety relevant frequency spectrum of the output signal X, (ii) modulation frequencies, which correspond to modulation data Md and which are preferably not perceivable and / or not disturbing to said passenger, and (iii) the non-safety-relevant frequency spectrum of audio message Xr; generating a modulation carrier signal Mt, wherein said modulation carrier signal Mt does not comprise said modulation frequencies corresponding to modulation data Md; outputting a speaker sound corresponding to said signal Xa using one or more speakers in said interior of said vehicle; receiving a vehicle sound using one or more microphones in said interior of said vehicle (20); generating a vehicle signal Ym corresponding to said received vehicle sound; demodulating said vehicle signal Ym using said output signal X and said modulation carrier signal Mt in order to obtain estimated modulation data Ms; estimating an estimated audio power Ps on the basis of said vehicle signal Ym and said output signal X; determining a difference between said estimated modulation data Ms and said modulation data Md; validating an output of said audio message when said difference is below a predetermined threshold and said estimated audio power Ps is above a predetermined power threshold; generating validation data corresponding to said validation.

9. Method according to claim 8, further comprising the following steps: filtering said safety relevant audio message Xr in order to obtain said output signal X, wherein said output signal X comprises all safety information that is audible for a passenger; filtering said safety relevant audio message Xr in order to obtain a signal Xi, wherein said signal Xi comprises information from said audio message Xr that is not safety relevant; generating modulation data Md and for adding modulation pause data to said modulation data Md on the basis of said output signal X, wherein modulation pause data indicate an absence of modulation in a predetermined time-period, whereinpreferably a sound power of said output signal X is below a predefined threshold, or wherein modulation pause data are regularly added between each symbol of modulation data Md; generating a carrier signal Mt; modulating said output signal X on the basis of said modulation data Md and said carrier signal Mt in order to obtain signal Xm; filtering said signal Xm in order to obtain said safety-relevant modulated signal Xb; and, super positioning said signal Xb with said signal Xi in order to obtain signal Xa.

10. Method according to claim 8 or 9, further comprising the steps of: estimating a time variant relation GG between said vehicle signal Ym and signal Xa; estimating of an output signal Ys on the basis of Xa using GG, and / or estimating an input signal Xs on the basis of Ym using GG; in a first stage, demodulating said estimated input signal Xs and / or said estimated output signal Ys, in order to get a first demodulated signal XXs, and / or respectively a first demodulated signal YYs, by using said output signal X, in a second stage, demodulation XXs and / or YYs by using modulation carrier signal Mt in order to obtain a signal XXf and / or YYf, respectively. filtering XXf and / or YYf by possible modulation frequencies, which symbolizes modulation data Md; and, estimating estimated modulation data Ms from said filter results for XXf and / or YYf.11 . Method according to any of claims 8-10, wherein the method further comprises the steps of: estimating an estimated signal Xs on the basis of said vehicle signal Ym and said output signal X using an inverse room transfer function; in a first stage, demodulating said estimated signal Xs or a difference signal X-Xs by using signal X as carrier signal, in order to obtain demodulation product signal XXs; in a second stage, demodulating said signal XXs with the modulation carrier signal Mt in order to obtain a modulation signal XXd, preferably using an estimated frequency spectrum comprises frequencies representing modulation data Md;filtering said signal XXd in order to obtain a signal XXf, wherein said signal XXf, only comprises frequencies representing modulation data Md; and, estimating estimated modulation data Ms on the basis of said signal XXf: and / or wherein the method further comprises the step of: estimating an estimated signal Ys on the basis of said signal Xa and said output signal X using a room transfer function; demodulating Ys or a difference signal Y-Ys in order to obtain demodulation product signal YYs; demodulating said signal YYs with the modulation carrier signal Mt in order to obtain a modulation signal YYd; filtering said signal YYd in order to obtain a signal YYf; and, estimating estimated modulation data Ms on the basis of said signal YYf.

12. Method according to any of claims 8-11 , further comprising the steps of- based on said validation data, executing a safety error reaction in case said validation data indicates that said outputting of said audio message was not validated, wherein preferably said reaction unit (500) is a display and said error reaction is displaying an error message and / or a text corresponding to said safety relevant audio message on said display.

13. Vehicle with a system for functional safety validating an output of an audio message in an interior of said vehicle according to any of claims 1 -7.

14. A computer program comprising instructions which, when the program is executed by a computer, cause the computer to carry out the steps of the method of any of claims 8-12.

15. A computer-readable medium having stored thereon the computer program of claim 14.

Citation Information

Patent Citations

  • Self-test method for a vehicular telematics unit

    US20090325534A1

  • Setting change assist apparatus

    US20210114584A1

  • Voice-controlled vehicle control system

    US6496107B1