Method and device for monitoring an on-board localization system of a vehicle
The method and device improve the reliability and safety of automated vehicle localization by using multiple geolocation systems with parameter-based consistency checks, addressing the lack of robustness in existing systems and reducing the risk of SOTIF failures.
Patent Information
- Authority / Receiving Office
- WO · WO
- Patent Type
- Applications
- Current Assignee / Owner
- STELLANTIS AUTO SAS
- Filing Date
- 2025-10-08
- Publication Date
- 2026-05-21
AI Technical Summary
Existing vehicle localization systems in automated vehicles lack sufficient functional robustness and safety, particularly in ensuring consistent and reliable positioning data from multiple geolocation systems, leading to potential SOTIF (Safety Of The Intended Functionality) failures.
A method and device for controlling an on-board vehicle location system that utilizes two independent geolocation systems (e.g., satellite positioning and LiDAR) to determine vehicle positions, applying a set of parameters to assess consistency and reliability, including maximum error, occurrence of errors, and temporal consistency, to ensure safe vehicle operation.
Enhances the functional reliability and safety of automated vehicle localization by reducing the risk of positioning errors, ensuring safe vehicle operation and minimizing the need for emergency stops.
Smart Images

Figure FR2025000191_21052026_PF_FP_ABST
Abstract
Description
DESCRIPTION Title: Method and device for controlling an on-board vehicle location system. Technical field
[0001] The present invention claims priority from French application 2412562 filed on November 18, 2024, the content of which (text, drawings and claims) is incorporated herein by reference.
[0002] The present invention relates to methods and devices for controlling a vehicle location system, particularly, but not exclusively, for an automated vehicle. The present invention relates to a method and device for controlling the movement of a vehicle, for example, an automated vehicle, based on the control of the onboard location system. Technological background
[0003] With the development of automated vehicles (from the English "Automated Vehicle"), also called autonomous vehicle(s), needs in terms of vehicle localization have emerged.
[0004] Controlling the trajectory of an automated vehicle, through one or more driver assistance systems, known as ADAS (Advanced Driver-Assistance System) systems, embedded in the automated vehicle, requires a good knowledge of the environment around the automated vehicle, for example through a high-definition map describing the infrastructure of the environment in which the automated vehicle travels, as well as an exact knowledge of the position (for example in terms of longitude, latitude and heading) of the automated vehicle at all times.
[0005] To improve the reliability of vehicle location, it is known to determine the vehicle's location using two different and independent geolocation systems to ensure positioning redundancy. When the two geolocation systems provide consistent longitude, latitude, and heading information, vehicle control continues, for example, to control the trajectory and follow a calculated route. Conversely, if the information is not consistent, the vehicle cannot be tracked. If the results are consistent, it may then be necessary to control the vehicle to make it come to a safe, forced stop.
[0006] Verifying the consistency of position information obtained from the two geolocation systems is not sufficient to guarantee the safety of the vehicle, its passengers, and other road users at a very high level of safety, that is, by ensuring a high level of functional robustness. A lack of functional robustness is also known as SOTIF failure (Safety Of The Intended Functionality). Summary of the present invention
[0007] One object of the present invention is to solve at least one of the problems of the technological background described above.
[0008] Another object of the present invention is to ensure the functional reliability of an on-board vehicle localization system, for example an automated vehicle.
[0009] Another object of the present invention is to improve vehicle safety.
[0010] According to a first aspect, the present invention relates to a method for controlling an on-board vehicle location system, the location system being configured to determine a first position of the vehicle via a first geolocation system and a second position of the vehicle via a second geolocation system different from the first geolocation system, the method being implemented by at least one processor and comprising the following steps: a) assigning determined values to a set of parameters of said location system comprising a first parameter, a second parameter, a third parameter and a fourth parameter, said first parameter, denoted R, being representative of a maximum location error, said second parameter being representative of a maximum occurrence of locations with an error greater than said maximum error, said third parameter being representative of an occurrence of differences between the first position obtained from said first geolocation system and the second position obtained from said second geolocation system greater than a threshold difference and said fourth parameter being representative of a temporal parameter of consistency between the first position and the second position; b) determining the duration of a time interval as a function of said first parameter and said fourth parameter; c) determination, for each time instant of a plurality of time instants included in the time interval, of a Euclidean distance between each first position obtained from said first geolocation system at each time instant and each second position obtained from the second geolocation system at each time instant, to obtain a set of Euclidean distances; d) determination of a threshold distance, denoted d, such that an occurrence of an inconsistency between the set of first positions obtained during the time interval and the set of positions obtained during the interval is less than a determined threshold corresponding to the third parameter; e) determination of a fifth parameter of the localization system equal to Rd / 2; f) First comparisons of each first position and each second position obtained at each time instant to an actual position of the vehicle at each time instant, and determination, based on the results of the first comparisons, of a first probability per hour that the first geolocation system provides a first position beyond the fifth parameter and a second probability per hour that the second geolocation system provides a second position beyond the fifth parameter; g) Second comparison of a product of the first probability by the second probability by Tdetection / 3600 by d / (nR) to the second parameter, where T de tector corresponds to the fourth parameter; and h) control of the localization system based on a result of the second comparison.
[0011] According to one variant, the control of the location system includes a determination of a location of the vehicle based on the first position obtained from the first geolocation system and the second position obtained from the second geolocation system when a result of the second comparison indicates that the product is less than the second parameter.
[0012] According to another variant, the control of the location system includes a reiteration of steps a) to g) with new values for at least some part of the first parameter, second parameter, third parameter and fourth parameter when a result of the second comparison indicates that the product is greater than the second parameter.
[0013] According to yet another variant, steps a) to g) are repeated with new values for at least some of the first parameter, second parameter, third parameter and fourth parameter until the result of the second comparison indicates that the product is less than the second parameter.
[0014] According to another variant, the first geolocation system corresponds to a satellite positioning system and the second system corresponds to a LiDAR positioning system.
[0015] According to a further variant, the vehicle corresponding to an automated vehicle, the process further includes a step of controlling the automated vehicle according to the control of the location system.
[0016] According to a second aspect, the present invention relates to a control device for an on-board vehicle location system, the device comprising a memory associated with a processor configured for the implementation of the steps of the process according to the first aspect of the present invention.
[0017] According to a third aspect, the present invention relates to a vehicle, for example an automated vehicle of the automobile type, comprising a device as described above according to the second aspect of the present invention.
[0018] According to a fourth aspect, the present invention relates to a computer program which includes instructions adapted for carrying out the steps of the process according to the first aspect of the present invention, in particular when the computer program is executed by at least one processor.
[0019] Such a computer program can use any programming language, and be in the form of source code, object code, or an intermediate form between source code and object code, such as in a partially compiled form, or in any other desirable form.
[0020] According to a fifth aspect, the present invention relates to a computer-readable recording medium on which is recorded a computer program comprising instructions for carrying out the steps of the process according to the first aspect of the present invention.
[0021] On the one hand, the recording medium can be any entity or device capable of storing the program. For example, the medium can include a storage means, such as a ROM, a CD-ROM or a microelectronic circuit-type ROM, or a magnetic recording means or a hard drive.
[0022] On the other hand, this recording medium can also be a transmissible medium such as an electrical or optical signal, such a signal being able to be transmitted via an electrical or optical cable, by conventional or radio frequency, by self-directing laser beam, or by other means. The computer program according to the present invention can, in particular, be downloaded from a network such as the Internet.
[0023] Alternatively, the recording medium may be an integrated circuit in which the computer program is incorporated, the integrated circuit being adapted to execute or to be used in the execution of the process in question. Brief description of the figures
[0024] Other features and advantages of the present invention will become apparent from the description of the specific and non-limiting embodiments of the present invention below, with reference to the attached Figures 1 to 5, in which:
[0025] [Fig. 1] schematically illustrates a vehicle incorporating a location system, according to a particular embodiment of the present invention;
[0026] [Fig. 2] schematically illustrates the position of the vehicle in Figure 1 obtained from the on-board location system, according to a particular embodiment of the present invention;
[0027] [Fig. 3] schematically illustrates a condition on the reliability of the position of the vehicle of figure 1 obtained from the on-board location system, according to a particular embodiment of the present invention;
[0028] [Fig. 4] illustrates a device configured for controlling the vehicle's on-board location system of Figure 1, according to a particular and non-limiting embodiment of the present invention.
[0029] [Fig. 5] illustrates a flowchart of the different steps of a control process for the vehicle's on-board location system in Figure 1, according to a particular and non-limiting embodiment of the present invention. Description of examples of achievements
[0030] A method and a control device for an on-board vehicle location system will now be described in what follows, with joint reference to figures 1 to 5. The same elements are identified with the same reference symbols throughout the description that follows.
[0031] The terms "first," "second" (or "firsts," "seconds"), etc., are used in this document by arbitrary convention to identify and distinguish different elements (such as operations, means, etc.) implemented in the embodiments described below. Such elements may be distinct or correspond to a single element, depending on the embodiment.
[0032] Figure 1 schematically illustrates a vehicle 10 carrying a location system 100, according to a particular and non-limiting embodiment of the present invention.
[0033] Vehicle 10, for example, corresponds to a vehicle with an internal combustion engine, an electric motor(s), or a hybrid vehicle with an internal combustion engine and one or more electric motors. Vehicle 10 thus corresponds, for example, to a land vehicle, such as a car, a truck, a bus, or a motorcycle.
[0034] In one particular embodiment, vehicle 10 corresponds to an automated vehicle (also called an autonomous vehicle). An automated vehicle is defined as a vehicle equipped with a sophisticated driver assistance system that ensures vehicle control and is capable of operating in its road environment without driver intervention or under the control of a person not involved in driving the automated vehicle, except in emergencies, for example. A vehicle capable of such autonomous driving must have a level of autonomous driving higher than a certain level out of a total number of levels. For example, the automated vehicle has an autonomy level of 4 or higher out of the 5 levels defined in the classification published by the federal agency responsible for road safety in the USA, or out of the 6 levels defined in the classification published by the international organization of motor vehicle manufacturers, which comprises 6 levels.According to one embodiment, the automated vehicle 10 has a level of autonomy greater than or equal to 3 out of the 5 or 6 levels provided for in the two classifications mentioned above.
[0035] Vehicle 10, for example, corresponds to a connected vehicle and, to that end, includes a communication system or interface comprising, for example, one or more communication antennas connected to a telematics control unit, known as a TCU (Telematic Control Unit), itself connected to one or more computers of the vehicle 10's embedded system. The antenna(s), the TCU, and the computer(s) form by example a multiplexed architecture for the realization of different services useful for the proper functioning of the vehicle 10. The computer(s) and the TCU unit communicate and exchange data with each other via one or more computer buses, for example a communication bus of the type CAN data bus (from the English "Controller Area Network" or in French "Réseau de contrôlers"), CAN FD (from the English "Controller Area Network Flexible Data-Rate" or in French "Réseau de contrôlers à débit de données flexible"), FlexRay (according to the ISO 17458 standard) or Ethernet (according to the ISO / IEC 802-3 standard).
[0036] Vehicle 10 advantageously incorporates a location system 100 configured to determine a first position of the vehicle via a first geolocation system and a second position of the vehicle via a second geolocation system different from the first geolocation system. The location system 100 is thus configured to determine the geographical position of vehicle 10 at any given time, based on the first position, the second position, or a combination of the first and second positions.
[0037] The first geolocation system and the second geolocation system included in the vehicle location system 10 allow the location system 100 to obtain two positions of geolocation systems independent of each other.
[0038] The first geolocation system corresponds, for example, to a satellite positioning system, known as GNSS (Global Navigation Satellite System), and the second system corresponds to a LiDAR positioning system. Examples of GNSS systems include GPS (Global Positioning System). "Global Positioning System"), the Galileo system and the Glonass system. The GNSS system is for example of the RTK type (from the English "Real Time Kinematic" or in French "Cinématique temps réel") or PPK (from the English "Post Processes Kinematic" or in French "Cinématique post-traitée") to benefit from centimeter-level accuracy.
[0039] According to this example, the location system 100 thus includes a GNSS-type geolocation system receiver configured to determine data representative of the geographic position at any given time based on signals received from a set of 111 GNSS satellites. The data representative of the geographic position takes, for example, the form of coordinates (latitude and longitude).
[0040] According to this example, the localization system 100 further includes means for processing data received from one or more LIDARs (Light Detection and Ranging) onboard the vehicle 10, comparing this data to data from a high-definition map of the environment in which the vehicle 10 is traveling. This high-definition map has been generated beforehand (for example, from LIDAR data from one or more other vehicles traveling in the environment, with the data from these LIDARS being combined with geographic position data). Comparing this data allows the localization system to determine the second position.
[0041] A LiDAR sensor is an optoelectronic system composed of a laser emitter, a receiver including a light collector (to collect the portion of the light emitted by the emitter and reflected by any object in the path of the emitted light beam), and a photodetector that converts the collected light into an electrical signal. A LiDAR sensor thus detects the presence of objects within the emitted light beam and measures the distance between the sensor and each detected object.
[0042] In another example, the first geolocation system corresponds to a GNSS system (e.g., the GPS system), and the second geolocation system corresponds to a vision system. In a vision system, the localization system (100) further includes means for processing data received from one or more cameras mounted in the vehicle 10 and comparing them to data from a high-definition map of the environment in which the vehicle 10 is traveling. This high-definition map has been generated beforehand (e.g., from camera data on one or more other vehicles traveling in the environment, the camera data being combined with geographic position data). Comparing this data allows the localization system to determine the second position.
[0043] A control process for the vehicle location system 10 is implemented by one or more computers of the vehicle 10 (for example the computer controlling the vehicle location system 10), i.e. by one or more processors of this or these computers.
[0044] The process notably allows for verification of a robustness objective for the localization system, which objective is quantified in terms of the maximum acceptable occurrence of a Positioning error beyond a certain threshold. For example, if vehicle 10 is operating in an urban environment on a road with two adjacent lanes, each with opposite directions of travel, and vehicle 10's nominal behavior is to travel in the middle of its lane, then the critical positioning error is the one that would cause the side of vehicle 10 to extend beyond its lane. For example, for a 3m wide lane and a 2m wide vehicle, the safety margin would be 50cm for lateral positioning.
[0045] Beyond that point, there would be a risk of collision with vehicles traveling in the opposite direction on the adjacent lane. Since this collision risk is a safety concern, it would be necessary to demonstrate that the occurrence of this error is below a threshold, typically 10 8 / h (1 chance in 100 million per hour of driving).
[0046] Regarding longitudinal positioning, it is possible to be less demanding than for lateral positioning. However, for the sake of simplicity and to ensure the proper functioning of the localization system, and ultimately of vehicle 10, in certain cases in terms of longitude and latitude positioning, it is considered that the critical error is a circular error around the true position (i.e., the ground truth) of vehicle 10; that is to say, it is critical that the true position of vehicle 10 be beyond a circle of radius 'R' and centered on the true position (ground truth) of vehicle 10.
[0047] Figure 2 illustrates the different positions of vehicle 10 at the same time instant, or within the same time window of duration equal to 100, 200, 500, or 1000 ms, for example. Figure 2 thus illustrates the first position 21 of vehicle 10 obtained by the localization system based on the first geolocation system, the second position 22 of vehicle 10 obtained by the localization system based on the second geolocation system, a position, called the final position 23, of vehicle 10 determined by the localization system using the first position 21 and the second position 22, and finally the actual position 24 of vehicle 10.
[0048] The functionality of the location system using the two geolocation systems is as follows: - if the Euclidean positioning distance is less than a threshold distance, denoted 'd', then the positioning of vehicle 10 is taken to be equal to the barycenter of the 2 longitude / latitude positions, that is to say the barycenter of the first position 21 and the second position 22 illustrated by the final position 23 in figure 2; and - if the Euclidean positioning distance is greater than this threshold distance 'd', then the Location systems are declared inconsistent, and vehicle 10 must make a stop to move to safety.
[0049] This function ensures that, in order for the final position 23 to be beyond a critical error 'R' relative to the actual positioning 24 and for the vehicle 10 not to stop to put itself in a safe position, it is necessary that: the first and second geolocation systems provide at the same instant, i.e. in the same time window, positions consistent with each other, and that the final position 23 (corresponding for example to the average of the first position 21 and the second position 22) is beyond the critical error 'R'.
[0050] Figure 2 illustrates such a case in which the first position 21 and the second position 22 are separated by a distance less than 'd' (the first position 21 and the second position 22 are thus considered to be consistent), while the final position 23 is beyond a distance 'R' from the actual position 24 (the final position 23 is at a distance from the actual position greater than R).
[0051] The occurrence of such a situation or scenario can be understood according to the following sequence of events: - It is necessary that the first geolocation system provides an incorrect position Pi beyond a certain threshold, this occurrence being noted — — ; and h - it is necessary that the second geolocation system also provides an erroneous position P2 at the same time (i.e., in the same time window) beyond the threshold": this probability can be written, for example:
[0052] [Math 1] > io —
[0054] where — — is the probability per hour that the second geolocation system provides an erroneous position beyond the threshold” and T Detectionis the time (duration of the time window in seconds) allowed to compare the first and second positions (this time must be very short, typically on the order of at least one second, in order to be sufficiently responsive in case of inconsistency, and it is at least greater than the calculation period, therefore on the order of at least 100ms, for example equal to 100, 200, 300, 500 or 1000ms); and - it is further necessary that the first and second geolocation systems are consistent with each other, that is to say that the distance separating the first position Pi 21 from the second position P222 remains less than the threshold distance 'd'.
[0055] The maximum probability that these 3 conditions are met is equal to:
[0056] [Math 2] <
[0058] With P(|P2- P < d) the probability that the first and second positions are consistent with each other.
[0059] Representing the scenario geometrically, as illustrated in Figure 3, it appears that all the first positions Pi and second positions P2 that remain consistent, but whose average is beyond the radius R, are included in a geometric zone (illustrated with hatched lines in Figure 3) defined by
[0060] [Math 3] > > < compared to the actual position between positions Pi and P2, with the final position 31 and the actual position 32 and R' = R - d.
[0063] Either :
[0064] [Math 4] Pjl < d < P(]P2- P réel \ > P -r) xP(|P1- P réei | > R - r) x <
[0066] Where P(x) corresponds to the probability that the condition 'x' is met.
[0067] Considering that the first geolocation system and the second geolocation system have random and independent angular positioning errors, it is possible to write that:
[0068] [Math 5]
[0070] This allows us to obtain:
[0071] [Math 6]
[0073] With :
[0074] [Table 1]
[0075] Therefore, in this example, it must be guaranteed that:
[0076] [Math 7]
[0078] With a coherence distance of 20cm, then it is sufficient to demonstrate that the unit localization modalities satisfy:
[0079] [Math 8] < <
[0087] It should be noted that the trade-off in choosing the consistency distance is as follows: the shorter the consistency distance, the more guaranteed the safety of vehicle 10 (because there are two effects: the Rd / 2 threshold increases, and therefore the probability of a single error decreases, but above all, the coefficient decreases, which significantly reduces the probability that the two geolocation systems will have an error in the same location). However, conversely, the shorter the consistency distance, the higher the probability of a disagreement or inconsistency, which leads to a degraded control mode for vehicle 10, such as safe immobilization with reduced vehicle availability.
[0088] For example, with a consistency distance of 10cm and with the first and second geolocation systems providing information with a 1-sigma accuracy of 5cm (i.e., 30% of positions are more than 5cm from the actual position and 70% are less), and assuming the error is isotropic, then, at any given time, there is a probability of approximately 14% that the distance between the first and second positions provided by the two geolocation systems is greater than 10cm. obtained: this leads to a risk of a safe stop because this consistency distance is too small in relation to the accuracy.
[0089] Below are some values for different 1-sigma accuracies of the localization algorithms and different coherence distances, assuming that the positioning errors of the systems have a Gaussian distribution:
[0090] [Table 2]
[0091] Taking, for example, a consistency distance of 20 cm (^=4), then at any given moment, there would be a 0.25% chance, or 1 in 400, that the difference between the first and second positions provided by the two geolocation systems would be greater than 30 cm. However, it is not possible to directly deduce the occurrence of this event over an hour, for example, because it depends on the error rate. The slower this rate of error, the lower the occurrence of this event will be.
[0092] However, it is possible to say that the dynamic range of the positioning error of a geolocation system is generally no greater than one Hertz, which would result in the following occurrences:
[0093] [Table 3]
[0094] The process thus makes it possible to validate the location system 100 using two location modalities by relying on the first geolocation system to determine a first position 21 of the vehicle 10 and on the second geolocation system to determine a second position 22 of the vehicle 10.
[0095] The process uses, in particular, a set of parameters from the location system, including a first parameter, a second parameter, a third parameter, and a fourth parameter. The first parameter, denoted R, represents a maximum location error. The second parameter represents a maximum occurrence of locations with an error greater than the maximum error. The third parameter represents an occurrence of differences between the first position 21 obtained from the first geolocation system and the second position 22 obtained from the second geolocation system that exceed a threshold difference. The fourth parameter, denoted T de detection, also called detection time, is representative of a temporal parameter of consistency between the first position and the second position.
[0096] In the first operation of the process, values are assigned to the first, second, third and fourth parameters, for example via a user interface.
[0097] In other words, the process relies on the requirements in terms of critical final positioning error R (e.g., 50cm), corresponding to the first parameter, and 10” 10” 8 of maximum acceptable occurrence — — (for example — — ), corresponding to the second parameter, these parameters being provided as input to the localization system 100. The process also relies on the acceptable occurrence of a safety stop, corresponding to the third parameter, following an inconsistency between the first position 21 and the second 10 - ^ position 22, this acceptable occurrence corresponding to a maximum occurrence noted — — 10” 2 (for example — — ), this third parameter is also provided as input to the localization system 100.
[0098] The first and fourth parameters are notably used to determine or calculate the duration of a time interval in a second operation of the process, this time interval and the associated duration being denoted T[h],
[0099] Vehicle safety requirement 10 provides a minimum requirement concerning the maximum acceptable occurrences of error in the first position 21 and the second position 22, obtained from equation math 6:
[0100] [Math 11] <
[0102] By not taking into account the deseverification by the coefficient^, we obtain:
[0103] [Math 12]
[0105] This gives, for example, a detection time T de1 second detection, and a 10"^ 10" 8 occurrence - = - , a maximum acceptable occurrence of:
[0106] [Math 13]
[0108] This allows us to determine or calculate a minimum number of hours of data characterizing the performance of geolocation systems according to the following formula:
[0109] [Math 14]
[0111] This gives 200 hours of data according to the example above.
[0112] In a third operation of the process, the Euclidean distance between the first and second positions is calculated or determined at each time instant within a plurality of time instants contained in the time interval T[h]. Thus, representative data for the first position are determined at each time instant by the positioning system 100 (via, for example, signals received from satellites 111), and representative data for the second position are determined at said time instant by the positioning system 100 (via, for example, data received from the vehicle's LIDAR 10). The time instants are, for example, selected from the time interval according to the value of the detection time.For example, if the detection time is 1s, then the first and second positions are determined every 1s and the Euclidean distance determined for each pair of first and second positions determined at the same time instant.
[0113] In a fourth operation of the process, the threshold distance, denoted d, is determined in such a way that an occurrence of an inconsistency between the set of first positions obtained during I time interval and I set of positions obtained during I interval is less than a determined threshold corresponding to the third parameter.
[0114] This consistency distance threshold value 'd' ensures that a safety stop 10 - ^ will not trigger at more than — . The threshold distance d is calculated from the set of Euclidean distances determined in the third operation, and is for example equal to 20cm according to the example above.
[0115] In a fifth operation of the process, a fifth parameter of the localization system equal to Rd / 2 is determined or calculated.
[0116] This fifth parameter corresponds to the value of the critical errors, R and d having been determined previously.
[0117] In a sixth operation of the process, each first position 21 and each second position 22 obtained at each time instant are compared to the actual position 24 of the vehicle 10 at each time instant. A first probability per hour that the first geolocation system provides a first position beyond the fifth parameter and a second probability per hour that the second geolocation system provides a second position beyond the fifth parameter are then determined based on the results of the comparisons, called first comparisons.
[0118] Thus, by using localization ground truth, we quantify, on the recordings, 10” 10” Z the occurrences — — and — that the geolocation systems each provide an erroneous position beyond Rd / 2. If no occurrence of this event is observed, then the occurrence is considered to be equal to 1 / 200 by default, and therefore:
[0119] [Math 15] i
[0120] i^- = 200
[0121] In a seventh operation of the process, a product of the first probability by the second probability by T de tection / 3600 by d / (nR) is compared (during a so-called second comparison) to the second parameter, where Tdetection corresponds to the fourth parameter corresponding to a determined temporal parameter of the localization system, also called Tdetection(s), that is to say a temporal parameter of coherence between the first position 21 and the second position 22, expressed in seconds.
[0122] For this purpose, the following product is calculated:
[0123] [Math 16] 1Q -X
[0125] And this product is compared to the target occurrence — — .
[0126] In an eighth operation, the localization system is controlled based on a result from the second comparison. 1Q -X
[0127] If the product is less than the target occurrence— — (corresponding to the second parameter) then the location system 100 is considered well-sized and the position of the vehicle 10 determined by this location system 100 is used to control the vehicle 10, for example to follow a route calculated by an on-board navigation system.
[0128] The control of the location system 100 thus includes a determination of a location of the vehicle 10 as a function of the first position 21 obtained from the first geolocation system and the second position 22 obtained from the second geolocation system when the result of the second comparison indicates that the product is less than the second parameter. 1Q -X
[0129] Conversely, if the product is greater than (or greater than or equal to) the target occurrence — — (corresponding to the second parameter), then the location system 100 is considered insufficiently efficient in terms of accuracy, and ultimately the first geolocation system and the second geolocation system are considered insufficiently efficient in terms of accuracy.
[0130] The localization system check then includes a repetition of the first, second, third, fourth, fifth, sixth, and seventh operations with new values for at least some of the first, second, third, and fourth parameters when the result of the second comparison indicates that the product is greater than the second parameter. The first, second, third, fourth, fifth, sixth, and seventh operations are repeated with new values for at least some of the first, second, and third parameters. fourth parameter until the result of the second comparison indicates that the product is less than the second parameter.
[0131] To illustrate the process with a specific implementation example, the following assumptions are made: geolocation systems provide a position with a Gaussian distribution, with an accuracy of 10⁻¹⁰ cm, with a positioning error of 10⁻¹⁰ -8 50cm critical with an acceptable occurrence of — — ; I acceptable occurrence of a 10 -1 The inconsistency between the two geolocation systems is equal to — — ; the dynamics of the error has a characteristic time of 5 seconds; and the detection time is on the order of a second.
[0132] In the first operation, the first target value is determined such that:
[0133] [Math 17]
[0135] This implies the need for 200 hours of data. From this 200 hours of data, it should be found that the consistency distance, which limits the occurrence of inconsistency between the two geolocation systems, must be on the order of 25 cm, since with a characteristic time of 5 seconds, we would have the following table:
[0136] [Table 4]
[0137] Consequently, there should be around 20 occurrences of inconsistency in the 200 hours of data.
[0138] It is then deduced that the value of the critical unit errors is equal to Rd / 2 = 37.5 cm
[0139] If the geolocation systems had a Gaussian distribution with an accuracy of 0.5 cm, then in the 200 hours of data, no errors should be observed beyond 37.5 cm. However, assuming that we ultimately observe 5 location errors via the first geolocation system (i.e., via the first modality), and none via the second geolocation system (i.e., via the second modality), then we must write that:
[0140] [Math 18] < < > < 10”^ 10” 8
[0147] The criterion — — < is therefore verified
[0148] According to this particular example, the 100 location system is considered robust and makes it possible to guarantee that the risk of critical mislocation is acceptable, while also ensuring an acceptable availability of the 100 location system.
[0149] Figure 4 schematically illustrates a device 4 configured for controlling a vehicle localization system, for example, vehicle 10, according to various specific and non-limiting embodiments of the present invention. Device 4 corresponds, for example, to a device embedded in the automated vehicle 10, such as a computer.
[0150] According to a particular embodiment, device 4 corresponds to a device configured to control an automated vehicle.
[0151] Device 4 is, for example, configured to perform at least some of the operations described opposite Figures 1 to 3 and / or the steps of the process described opposite Figure 5. Examples of such a device 4 include, but are not limited to, embedded electronic equipment such as a vehicle's on-board computer, an electronic control unit such as an ECU (Electronic Control Unit), a TCU, a controller, a computer, a server, or a mobile communication device (e.g., embedded in a vehicle and connected to that vehicle via wired or wireless communication). The elements of device 4, individually or in combination, may be integrated into a single integrated circuit, into several integrated circuits, and / or into discrete components.Device 4 can be implemented in the form of electronic circuits or software (or computer) modules or a combination of electronic circuits and software modules.
[0152] Device 4 includes one or more processors 40 configured to execute instructions for carrying out the steps of the process and / or for executing instructions from the software embedded in Device 4. The processor 40 may include integrated memory, an input / output interface, and various circuits known to those skilled in the art. Device 4 further includes at least one memory 41, for example, volatile and / or non-volatile memory, and / or includes a memory storage device that may include volatile and / or non-volatile memory, such as EEPROM, ROM, PROM, RAM, DRAM, SRAM, flash, magnetic disk, or optical disk.
[0153] The computer code of the embedded software(s) including the instructions to be loaded and executed by the processor is, for example, stored on memory 41.
[0154] According to various specific and non-limiting embodiment examples, device 4 is coupled in communication with other similar devices or systems and / or with communication devices, for example a TCU (Telematic Control Unit), for example via a communication bus or through dedicated input / output ports.
[0155] According to a specific and non-limiting embodiment, device 4 includes a block 42 of interface elements for communicating with external devices. The interface elements of block 42 include one or more of the following interfaces: - Radio frequency (RF) interface, for example, Wi-Fi® type (according to IEEE 802.11), for example in the 2.4 or 5 GHz frequency bands, or Bluetooth® type (according to IEEE 802.15.1), in the 2.4 GHz frequency band, or Sigfox type using UBN radio technology (from the English Ultra Narrow Band, in French bande ultra étroite), or LoRa in the 868 MHz frequency band, LTE (from the English "Long-Term Evolution" or in French "Evolution à long terme"), LTE-Advanced (or in French LTE-avancé), 5G; - USB interface (from the English "Universal Serial Bus" or "Universal Serial Bus" in French); - HDMI interface (from the English "High Definition Multimedia Interface", or "High Definition Multimedia Interface" in French); - LIN interface (from the English "Local Interconnect Network", or in French "Réseau interconnecté local").
[0156] According to another particular and non-limiting embodiment, the device 4 includes a communication interface 43 which enables communication with other devices (such as other computers in the embedded system) via a communication channel 430. The communication interface 43 corresponds, for example, to a transmitter configured to transmit and receive information and / or data via the communication channel 430. The communication interface 43 corresponds, for example, to a wired network of the type CAN (Controller Area Network), CAN FD (Controller Area Network Flexible Data-Rate), FlexRay (standardized by ISO 17458) or Ethernet (standardized by ISO / IEC 802-3).
[0157] According to a particular and non-limiting embodiment, the device 4 can provide output signals to one or more external devices, such as a display screen 440, touch or not, one or more loudspeakers 450 and / or other peripherals 460 (projection system) via output interfaces 44, 45 and 46 respectively. According to a variant, one or more of the external devices is integrated into the device 4.
[0158] Figure 5 illustrates a flowchart of the different steps in a method for controlling an on-board vehicle location system, for example, vehicle 10. The location system is configured to determine a first position of the vehicle via a first geolocation system and a second position of the vehicle via a second geolocation system different from the first geolocation system, according to a particular and non-limiting embodiment of the present invention. The method is implemented, for example, by a computer, for example, by the device 4 in Figure 4.
[0159] In a first operation 51, specific values are assigned to a set of parameters of the localization system comprising a first parameter, a second parameter, a third parameter and a fourth parameter, the first parameter, denoted R, being representative of a maximum location error, the second parameter being representative of a maximum occurrence of locations with an error greater than said maximum error, the third parameter being representative of an occurrence of differences between the first position obtained from the first geolocation system and the second position obtained from the second geolocation system greater than a threshold difference and the fourth parameter being representative of a temporal parameter of consistency between the first position and the second position.
[0160] In a second step 52, a duration of a time interval is determined as a function of the first parameter and the fourth parameter.
[0161] In a third step 53, for each time instant of a plurality of time instants included in the time interval, a Euclidean distance between each first position obtained from the first geolocation system at each time instant and each second position obtained from the second geolocation system at each time instant is determined, to obtain a set of Euclidean distances.
[0162] In a fourth step 54, a threshold distance, denoted d, is determined such that an occurrence of an inconsistency between the set of first positions obtained during the time interval and the set of positions obtained during the interval is less than a determined threshold corresponding to the third parameter.
[0163] In a fifth step 55, a fifth parameter of the localization system equal to Rd / 2 is determined.
[0164] In a sixth step 56, first comparisons of each first position and each second position obtained at each time instant to a real position of the vehicle at each time instant are implemented; and a first probability per hour that the first geolocation system provides a first position beyond the fifth parameter and a second probability per hour that the second geolocation system provides a second position beyond the fifth parameter are determined based on the results of the first comparisons.
[0165] In a seventh step 57, a second comparison of a product of the first probability by the second probability by T de tection / 3600 by d / (nR) to the second parameter is implemented, where Tdetection corresponds to the fourth parameter.
[0166] In an eighth step 58, the localization system is controlled based on a result of the second comparison.
[0167] According to one variant, the variants and examples of the operations described in relation to figures 1 to 3 apply to the steps of the process in figure 5.
Claims
1. CLAIMS 1. Method for controlling an on-board vehicle (10) location system (100), said location system (100) being configured to determine a first position (21) of said vehicle (10) via a first geolocation system and a second position (22) of said vehicle (10) via a second geolocation system different from said first geolocation system, said method being implemented by at least one processor and comprising the following steps: 3.a) assignment (51) of determined values to a set of parameters of said location system (100) comprising a first parameter, a second parameter, a third parameter and a fourth parameter, said first parameter, denoted R, being representative of a maximum location error, said second parameter being representative of a maximum occurrence of locations with an error greater than said maximum error, said third parameter being representative of an occurrence of differences between the first position obtained from said first geolocation system and the second position obtained from said second geolocation system greater than a threshold difference and said fourth parameter being representative of a temporal parameter of consistency between the first position (21) and the second position (22); 4.b) determination (52) of a duration of a time interval as a function of said first parameter and said fourth parameter; 5.c) determination (53), for each time instant of a plurality of time instants included in said time interval, of a Euclidean distance between each first position (21) obtained from said first geolocation system at said each time instant and each second position (22) obtained from said second geolocation system at said each time instant, to obtain a set of Euclidean distances; 6.d) determination (54) of a threshold distance, denoted d, such that an occurrence of an inconsistency between the set of first positions obtained during said time interval and the set of second positions obtained during said interval is less than a determined threshold corresponding to said third parameter; 7.e) determination (55) of a fifth parameter of said location system equal to Rd / 2; f) first comparisons (56) of each first position (21) and each second position (22) obtained at each time instant with a real position (24) of said vehicle (10) at each time instant and determination, based on the results of the first comparisons, of a first probability per hour that said first geolocation system provides a first position beyond said fifth parameter and of a second probability per hour that said second geolocation system provides a second position beyond said fifth parameter; 8.g) second comparison (57) of a product of said first probability by said second probability by T de tection / 3600 by d / (nR) audit second parameter, where T de tector corresponds to the fourth parameter; and 9.h) control (58) of said localization system (100) according to a result of the second comparison (57).
2. A method according to claim 1, wherein the control (58) of said location system (100) comprises a determination of a location of said vehicle (10) as a function of the first position (21) obtained from said first geolocation system and the second position (22) obtained from said second geolocation system when a result of the second comparison (57) indicates that said product is lower than said second parameter.
3. A method according to claim 1, wherein the control of said localization system (100) comprises a repetition of steps a) to g) with new values for at least some part of said first parameter, second parameter, third parameter and fourth parameter when a result of the second comparison (57) indicates that said product is superior to said second parameter.
4. A method according to claim 3, wherein said steps a) to g) are repeated with new values for at least some part of said first parameter, second parameter, third parameter and fourth parameter until the result of the second comparison (57) indicates that said product is lower than said second parameter.
5. A method according to any one of claims 1 to 4, wherein said first geolocation system corresponds to a satellite positioning system and said second system corresponds to a LiDAR positioning system.
6. A method according to any one of claims 1 to 5, wherein said vehicle (10) corresponds to an automated vehicle, said method further comprising a step of controlling said automated vehicle as a function of the control (58) of said localization system (100).
7. Computer program comprising instructions for carrying out the method according to any one of claims 1 to 6, when such instructions are executed by at least one processor.
8. Computer-readable recording medium on which is recorded a computer program comprising instructions for carrying out the steps of the process according to any one of claims 1 to 6.
9. Device (4) for controlling an on-board vehicle location system, said device comprising a memory (41) associated with at least one processor (40) configured for carrying out the steps of the method according to any one of claims 1 to 6.
10. Vehicle (10) comprising the device (4) according to claim 9.