Method and device for controlling an automated vehicle according to a probability of a positioning error by a location system
Patent Information
- Authority / Receiving Office
- WO · WO
- Patent Type
- Applications
- Current Assignee / Owner
- STELLANTIS AUTO SAS
- Filing Date
- 2025-12-05
- Publication Date
- 2026-07-30
Smart Images

Figure FR2025000236_30072026_PF_FP_ABST
Abstract
Description
DESCRIPTION Title: Method and device for controlling an automated vehicle based on the probability of a positioning error in a localization system technical field
[0001] The present invention claims priority from French application 2500779 filed on January 24, 2025, the content of which (text, drawings and claims) is incorporated herein by reference.
[0002] The present invention relates to methods and devices for controlling an automated vehicle, including but not limited to an automated motor vehicle. The present invention relates to a method and device for controlling the movement of an automated vehicle based on the probability of positioning error obtained from an onboard localization system. Technological background
[0003] With the development of automated vehicles (from the English "Automated Vehicle"), also called autonomous vehicle(s), needs in terms of vehicle localization have emerged.
[0004] Controlling the trajectory of an automated vehicle, through one or more driver assistance systems, known as ADAS (Advanced Driver-Assistance System) systems, embedded in the automated vehicle, requires a good knowledge of the environment around the automated vehicle, for example through a high-definition map describing the infrastructure of the environment in which the automated vehicle travels, as well as an exact knowledge of the position (for example in terms of longitude, latitude and heading) of the automated vehicle at all times.
[0005] For an automated vehicle to safely follow a calculated trajectory, it is essential that the position obtained from an onboard location system be reliable; that is, that the location system be functionally robust. A lack of functional robustness is also known as SOTIF failure (Safety Of The Intended Functionality).
[0006] Some localization systems are designed and configured to monitor the accuracy of the determined position by providing, in real time, a metric representing the equivalent hourly probability that an error in the determined position relative to the actual position of the automated vehicle will exceed a critical threshold. A localization system is considered reliable and robust when the hourly probability that the positioning error will exceed the critical threshold remains below a predetermined target value. To ensure the safety of the automated vehicle, its passengers, and other road users, the system is designed to perform a safe, forced stop when the estimated hourly probability exceeds the target value.
[0007] However, such a system leads to untimely forced stops for safety reasons when the situation on the ground does not require it. Summary of the present invention
[0008] One object of the present invention is to solve at least one of the problems of the technological background described above.
[0009] Another object of the present invention is to reduce the risk of a forced safe stop of an automated vehicle.
[0010] According to a first aspect, the present invention relates to a method for controlling an automated vehicle equipped with a localization system configured to determine a position of the automated vehicle, the localization system being configured to provide in real time a probability per hour that an error in determining the position relative to an actual position of the automated vehicle is greater than a threshold value, called the probability of positioning error per hour, the method being implemented by at least one processor and comprising the following steps: - at each time instant of a time period of determined duration, determination of an indicator representing a cumulative probability of positioning error per hour since the beginning of the time period; - comparison, at each time instant, of a value taken by the indicator at each time instant to a target value of the indicator at each time instant; - automated vehicle control based on a comparison result.
[0011] Using an indicator that represents the cumulative probability of positioning error per hour over a long period (e.g., from a few minutes to one hour) prevents situations where the probability of positioning error occasionally exceeds the threshold that triggers a forced safe stop of the automated vehicle, only to return to an acceptable level immediately after this brief exceedance. This limits the number of unplanned forced safe stops while ensuring a high level of safety for the automated vehicle and its passengers.
[0012] According to one variant, the automated vehicle control includes a safety forced shutdown control of the automated vehicle when the value taken by the indicator is greater than the target value of the indicator.
[0013] According to another variant, the indicator, denoted l(t), is determined according to the following equation, the determined duration being equal to 1 hour: dt 3600 with — - — corresponding to the probability of positioning error per hour and t corresponding to the time instant expressed in seconds.
[0014] According to yet another variant, the target value, denoted l C ibie(t) is determined according to the following equation: 10 with— — corresponding to a determined target value of probability of positioning error per hour. io — 10 -8
[0015] According to another variant, — — =
[0016] According to a further variant, the process further includes an indicator initialization step at the beginning of each time period of determined duration of a set of time periods of equal duration to the determined duration.
[0017] According to a second aspect, the present invention relates to a control device for an automated vehicle, the device comprising a memory associated with a processor configured for the implementation of the steps of the process according to the first aspect of the present invention.
[0018] According to a third aspect, the present invention relates to an automated vehicle, for example of the automobile type, comprising a device as described above according to the second aspect of the present invention.
[0019] According to a fourth aspect, the present invention relates to a computer program which includes instructions adapted for carrying out the steps of the process according to the first aspect of the present invention, in particular when the computer program is executed by at least one processor.
[0020] Such a computer program can use any programming language, and be in the form of source code, object code, or an intermediate form between source code and object code, such as in a partially compiled form, or in any other desirable form.
[0021] According to a fifth aspect, the present invention relates to a computer-readable recording medium on which is recorded a computer program comprising instructions for carrying out the steps of the process according to the first aspect of the present invention.
[0022] On the one hand, the recording medium can be any entity or device capable of storing the program. For example, the medium can include a storage means, such as a ROM, a CD-ROM or a microelectronic circuit-type ROM, or even a magnetic recording means or a hard drive.
[0023] On the other hand, this recording medium can also be a transmissible medium such as an electrical or optical signal, such a signal being able to be transmitted via an electrical or optical cable, by conventional or radio frequency, by self-directing laser beam, or by other means. The computer program according to the present invention can, in particular, be downloaded from a network such as the Internet.
[0024] Alternatively, the recording medium may be an integrated circuit in which the computer program is incorporated, the integrated circuit being adapted to execute or to be used in the execution of the process in question. Brief description of the figures
[0025] Other features and advantages of the present invention will become apparent from the description of the specific and non-limiting embodiments of the present invention below, with reference to the attached Figures 1 to 4, in which:
[0026] [Fig. 1] schematically illustrates an automated vehicle incorporating a localization system, according to a particular embodiment of the present invention;
[0027] [Fig. 2] graphically illustrates the probability of error by cumulative error over a time period that an error in determining the position of the automated vehicle in Figure 1 relative to an actual position of the automated vehicle is greater than a threshold value, according to a particular embodiment of the present invention;
[0028] [Fig. 3] illustrates a device configured for the control of the automated vehicle of figure 1, according to a particular and non-limiting embodiment of the present invention.
[0029] [Fig. 4] illustrates a flowchart of the different stages of a process for controlling the automated vehicle of figure 1, according to a particular and non-limiting embodiment of the present invention. Description of examples of achievements
[0030] A method and a control device for an automated vehicle will now be described in what follows with joint reference to Figures 1 to 4. The same elements are identified with the same reference symbols throughout the description that follows.
[0031] The terms "first," "second" (or "firsts," "seconds"), etc., are used in this document by arbitrary convention to identify and distinguish different elements (such as operations, means, etc.) implemented in the embodiments described below. Such elements may be distinct or correspond to a single element, depending on the embodiment.
[0032] Figure 1 schematically illustrates an automated vehicle 10 incorporating a localization system 100, according to a particular and non-limiting embodiment of the present invention.
[0033] Vehicle 10, for example, corresponds to a vehicle with an internal combustion engine, an electric motor(s), or a hybrid vehicle with an internal combustion engine and one or more electric motors. Vehicle 10 thus corresponds, for example, to a land vehicle, such as a car, a truck, a bus, or a motorcycle.
[0034] Vehicle 10 corresponds to an automated vehicle (also called an autonomous vehicle). An automated vehicle is defined as a vehicle equipped with a sophisticated driver assistance system that ensures vehicle control and is capable of operating in its road environment without driver intervention or under the control of a person not involved in driving the automated vehicle, except in emergencies, for example. A vehicle capable of such autonomous driving must have a level of autonomous driving higher than a certain level out of a total number of levels. For example, the automated vehicle has an autonomy level of 4 or higher out of the 5 levels defined in the classification published by the federal agency responsible for road safety in the USA, or out of the 6 levels defined in the classification published by the international organization of motor vehicle manufacturers, which includes 6 levels.According to one embodiment, the automated vehicle 10 has a level of autonomy greater than or equal to 3 out of the 5 or 6 levels provided for in the two classifications mentioned above.
[0035] Vehicle 10, for example, corresponds to a connected vehicle and includes for this purpose a communication system or interface comprising, for example, one or more communication antennas connected to a telematic control unit, called a TCU (from the English "Telematic Control Unit"), itself connected to one or more computers of the vehicle 10's embedded system. The antenna(s), the TCU and the computer(s) form, for example, a multiplexed architecture for the implementation of various services useful for the proper functioning of vehicle 10.The computer(s) and the TCU communicate and exchange data with each other via one or more computer buses, for example a CAN (Controller Area Network), CAN FD (Controller Area Network Flexible Data-Rate), FlexRay (according to ISO 17458) or Ethernet (according to ISO / IEC 802-3) type communication bus.
[0036] Vehicle 10 is advantageously equipped with a localization system 100 configured to determine the real-time position of the automated vehicle. The localization system 100 is thus configured to determine the geographical position of vehicle 10 at any given time based on satellite signals received from a set of satellites 111 and / or from data received from a set of environmental sensors of the automated vehicle 10.
[0037] The location system corresponds, for example, to a satellite geolocation system, also called a satellite positioning system, or GNSS (Global Navigation Satellite System). Examples of GNSS systems are GPS (Global Positioning System), Galileo, and GLONASS. The GNSS system is, for example, of the RTK (Real-Time Kinematic) or PPK (Post-Processed Kinematic) type to achieve centimeter-level accuracy.According to this example, the 100 positioning system includes a GNSS-type positioning system receiver configured to determine representative geographic position data at any given time based on signals received from the 111 satellites of the GNSS system. The representative geographic position data takes, for example, the form of coordinates (latitude and longitude).
[0038] In another example, the 100 localization system corresponds to a localization system using data received from environmental sensors such as radar, lidar (Light Detection and Ranging), or vision sensors (for example, a camera). According to this other example, the localization system includes means for processing data received from one or more environmental sensors.The localization system determines the position of the automated vehicle by comparing data received from the environmental sensor(s) with data from a high-definition map of the environment in which the vehicle 10 is traveling. This high-definition map has been generated beforehand (for example, using data from the same environmental sensors (as those of the automated vehicle 10) from one or more other vehicles traveling in the environment, with the data from these environmental sensors being combined with geographic position data). Comparing this data allows the localization system to determine the position of the automated vehicle 10.
[0039] A lidar sensor is an optoelectronic system composed of a laser emitter, a receiver including a light collector (to collect the portion of the light emitted by the emitter and reflected by any object in the path of the emitted light beam), and a photodetector that converts the collected light into an electrical signal. A lidar sensor thus detects the presence of objects within the emitted light beam and measures the distance between the sensor and each detected object.
[0040] The automated vehicle's (AV) localization system 100 incorporates an integrity verification mechanism. Integrity refers to the confidence in the accuracy of the location or position estimate of the automated vehicle 10 determined by the localization system 100. Integrity is defined as the equivalent probability per hour that an error in determining the position relative to the actual position of the automated vehicle 10 will exceed a threshold value (e.g., 25, 50, or 75 cm). Integrity is determined by one or more algorithms implemented in the automated vehicle 10, i.e., by any algorithm known to a person skilled in the art. The probability per hour that an error in determining the position relative to the actual position of the automated vehicle 10 will exceed a threshold value is referred to more simply as the "positioning error probability per hour" in the remainder of this description.
[0041] The thesis document entitled "Autonomous Approach for Localization and Integrity Monitoring of a Motor Vehicle in a Complex Environment," submitted by Olivier Le Marchand on February 21, 2012 (HAL Id: tel-00672343), describes methods for determining integrity. The determination of integrity, and therefore the probability of positioning error per hour, is obtained by analyzing the travel time measurements of satellite signals and data obtained from environmental sensors (radar, camera, LiDAR) of the automated vehicle.
[0042] An automated vehicle control process 10 is implemented by one or more computers of the automated vehicle 10 (for example the computer controlling the location system 100), i.e. by one or more processors of this or these computers.
[0043] The process allows, in particular, for the verification of a robustness objective for the localization system, which is quantified in terms of the maximum acceptable occurrence of a positioning error beyond a certain threshold. For example, if the automated vehicle 10 operates in an urban environment on a roadway with two adjacent lanes, each with opposite directions of travel, and the nominal behavior of the automated vehicle 10 is to travel in the middle of its lane, then the critical positioning error is the one that would cause the side of the automated vehicle 10 to extend beyond its own lane. For example, for a 3m wide lane and an automated vehicle 10 that is 2m wide, the safety margin would be 50cm for lateral positioning.
[0044] If the positioning error of the automated vehicle 10 obtained from the localization system 100 exceeds the critical positioning error (also called the critical error threshold, for example, 50 cm), it can no longer be guaranteed that the automated vehicle 10 will be entirely within its lane of travel, and there is a risk of collision with vehicles traveling in the opposite direction in the lane adjacent to that lane of travel. To verify the estimated risk of this positioning error occurring, the localization system 100 of the vehicle 100 provides, in real time, a probability, estimated as an equivalent probability per hour (denoted h), that the positioning error will exceed the critical error threshold, i.e.:
[0045] [Math 1]
[0046] P(Position Error > Critical Error) = 10~ u(L> / h
[0047] Given the safety risk associated with collisions, it is necessary that the occurrence of this positioning error be less than a threshold, typically 10' 8 / h (1 chance in 100 million per hour of driving). This threshold corresponds to a target value for the probability of positioning error per hour, to which the probability of positioning error per error as a function of time 't' (denoted 10) is compared. -u(t) / / i) obtained from the location system 100 of the automated vehicle 10 to determine, according to the state of the art, whether the automated vehicle 10 should perform a forced safety stop or not.
[0048] Indeed, according to the state of the art, the automated vehicle 10 must perform a forced safety stop when the probability of positioning error per hour obtained from the 10 _u ( f 10 - The localization system 100, denoted — - —, is greater than the target value, denoted and by 10-8 example equaled a — — .
[0049] Thus, according to the state of the art, this means that the automated vehicle 10 must perform a safe forced stop procedure at each time instant, denoted tstop, where the following condition is met:
[0050] [Math 2]
[0052] An excessive number of forced safe shutdowns is detrimental, particularly in terms of user experience. Indeed, it is not always necessary to force a safe shutdown if the integrity is only degraded locally. For example, imagine a localization system for which the target is a positioning error probability per hour of less than or equal to 10 -8 / / i, and let's imagine that, generally speaking, real-time integrity is close to 10 -9 / / i but locally, integrity degrades for about ten seconds with an equivalent probability of 10 -7 / / i, then its contribution on an hourly scale will only be on the order of 3 x 10 -1 °, therefore low compared to the target of 10 -8 on the scale of one hour.
[0053] Figure 2 graphically illustrates such a scenario, according to a particular and non-limiting implementation example.
[0054] Figure 2 represents different cumulative probability curves of positioning error as a function of time, with time 't' (for example in hours) on the x-axis and cumulative probability (dimensionless) on the y-axis.
[0055] Curve 21 represents a straight line with a slope of 10' 7 / h. Curve 22 represents a straight line with a slope of 10' 8 / h illustrating the cumulative value of the target probability of positioning error, the cumulative probability reaching a value of 10'8 after 1 hour. Curve 23 represents a straight line with a slope of 10' 9 / h. Curve 24 illustrates the scenario described earlier in which real-time integrity is close to 10' 9 / h with locally an integrity degrading for about ten seconds at an equivalent probability of 10' 7 / h. Thus, curve 24 representing integrity and corresponding to the cumulative probability of positioning error, which is represented by an indicator denoted I(t), comprises a first part 241 between time t=0 and time t=t1 having an average slope of 10' 9 / h, a second part 242 between time t=t1 and time t=t2 having an average slope of 10' 7 / h and a third part 243 between the time t=t2 and t=1 h having an average slope of 10' 9 / h. The duration of the second part 242 being very short (on the order of a few seconds) compared to the duration of the first 241 and third 243 parts (the total duration associated with curve 24 being equal to 1 hour), the average slope of curve 24 remains close to 10' 9 / h, and the cumulative probability over 1 hour is very close to 10' 9 , therefore much lower than the cumulative probability associated with the target value over 1 hour (i.e., 10 minutes) 8 ).
[0056] The automated vehicle control process 10 is described below, using as an example an application over a predetermined time period. The predetermined time period is, for example, 1 hour, as in the example in Figure 2. In other examples, the predetermined time period is 30 minutes or 2 hours.
[0057] Although described in relation to a specific time period, the process applies in the same way to each specific time period of a set of time periods, each having the same specific duration, for example 1 hour.
[0058] In a first operation of the process, an indicator, denoted l(t), representing a cumulative probability of positioning error per hour, is determined at each time instant of the time period of determined duration, from the beginning of the time period.
[0059] Curve 24 in Figure 2 illustrates an example of such a cumulative error probability as a function of time t between time t=0 and time t=1 h.
[0060] The indicator, denoted I(t), is for example determined according to the following equation with a fixed duration equal to 1 hour:
[0061] [Math 3] JQ-UCt)
[0063] with — - — corresponding to the probability of positioning error per hour and t corresponding to the time instant expressed in seconds.
[0064] When the current time period reaches the end of the predetermined duration, that is, when t = 1 h according to the specific example in Figure 2, the indicator l(t) is initialized at the beginning of the time period following the current time period. The initialization (or reset) of the indicator l(t) corresponds to resetting the value associated with the indicator I(t); that is, l(t) is set to 0 at the beginning of each new time period.
[0065] According to another embodiment, the probability of positioning error per hour is estimated or calculated at regular intervals, denoted 'i', (for example every 100, 250, 500 or 1000ms) and the indicator l(t) is determined at each time instant at which the probability of positioning error per hour is estimated or calculated by summing all the values calculated from the beginning of the current time period up to the current time instant, and so on until the end of the current time period, i.e.:
[0066] [Math 4] io-“®
[0067] / (t) = E;-o ~ — x ~~ h 3600
[0068] In a second operation of the process, the value taken by the indicator I(t) at each time instant 't' is compared to a target value of the indicator at each time instant. Taking Figure 2 as an example, line 22 represents the evolution of the target value over time, which reaches 10' 8 after 1 hour. Thus, at each time instant t between 0 and t=1 h, the value of l(t) represented by the curve 24 at the time instant considered is compared to a target value corresponding to the ordinate of the point on the curve 22 whose abscissa is the time instant considered.
[0069] The target value, denoted l C ibie(t), for example, is determined according to the following equation:
[0070] [Math 5] 10 with— — corresponding to a determined target value of probability of positioning error per hour.
[0072] is a constant, for example equal to 10' 8 / h, that is, the slope of the line represented by curve 22 in Figure 2.
[0073] In a third operation of the process, the automated vehicle 10 is controlled according to a result of the comparison of the second operation.
[0074] The control of the automated vehicle 10 includes the generation and transmission of instructions to one or more ADAS systems of the automated vehicle 10, such as, for example: - an ACC (Adaptive Cruise Control) type speed regulation system; and / or - a trajectory control system, for example a lane keeping assist system; - a braking system; and / or - an anti-slip system.
[0075] The control of the automated vehicle 10 includes, for example, trajectory control based on guidance instructions associated with a route calculated for the automated vehicle 10, speed control, and control of predefined maneuvers such as forced safe stopping.
[0076] The automated vehicle 10 is controlled based on a comparison result to continue the calculated route or to implement a safe forced stop.
[0077] The automated vehicle 10 is controlled to perform a forced safety stop at each time instant tstop for which the value taken by the indicator I (tstop) is greater than the target value l C ibie(t s top) of the indicator, that is, each time the following condition is met:
[0078] [Math 6] >
[0080] Where t is expressed in seconds.
[0081] Otherwise, when the above condition is not met, the automated vehicle 10 is controlled to continue the route calculated based on the data received from the vehicle's environmental sensors and its position obtained from the localization system 100, in particular when:
[0082] [Math 7] <
[0084] Such a process makes it possible to limit the number of forced stops safely by taking into account the probability of positioning error per hour over a long period, that is, by considering the cumulative, sum, or integral probability of positioning error per hour over a time interval elapsed since the beginning of a predetermined time period. As soon as the time elapsed since the beginning of the time period exceeds a predetermined duration (for example, a few minutes), the probability of positioning error per hour exceeds the threshold value (for example, 10 minutes). 8 / h) for a very short time (for example a few seconds) does not automatically trigger the implementation of the forced safe stop maneuver of the automated vehicle 10.
[0085] Figure 3 schematically illustrates a device 3 configured for controlling an automated vehicle, for example the automated vehicle 10, according to various specific and non-limiting embodiments of the present invention. The device 3 corresponds, for example, to a device embedded in the automated vehicle 10, such as a computer.
[0086] Device 3 is, for example, configured to perform at least some of the operations described opposite Figures 1 to 2 and / or the steps of the process described opposite Figure 4. Examples of such a device 3 include, but are not limited to, embedded electronic equipment such as a vehicle's on-board computer, an electronic control unit such as an ECU (Electronic Control Unit), a TCU, a controller, a computer, a server, or a mobile communication device (e.g., embedded in a vehicle and connected to that vehicle via wired or wireless communication). The elements of device 3, individually or in combination, may be integrated into a single integrated circuit, into several integrated circuits, and / or into discrete components.Device 3 can be implemented in the form of electronic circuits or software (or computer) modules or a combination of electronic circuits and software modules.
[0087] Device 3 includes one or more processors 30 configured to execute instructions for carrying out the steps of the process and / or for executing instructions from the software embedded in Device 3. The processor 30 may include integrated memory, an input / output interface, and various circuits known to those skilled in the art. Device 3 further includes at least one memory 31, for example, volatile and / or non-volatile memory, and / or includes a memory storage device that may include volatile and / or non-volatile memory, such as EEPROM, ROM, PROM, RAM, DRAM, SRAM, flash, magnetic disk, or optical disk.
[0088] The computer code of the embedded software(s) including the instructions to be loaded and executed by the processor is, for example, stored on memory 31.
[0089] According to various specific and non-limiting embodiment examples, device 3 is coupled in communication with other similar devices or systems and / or with communication devices, for example a TCU (Telematic Control Unit), for example via a communication bus or through dedicated input / output ports.
[0090] According to a specific and non-limiting embodiment, device 3 includes a block 32 of interface elements for communicating with external devices. The interface elements of block 32 include one or more of the following interfaces: - radio frequency RF interface, for example of the Wi-Fi® type (according to IEEE 802.11), for example in the 2.4 or 5 GHz frequency bands, or of the Bluetooth® type (according to IEEE 802.15.1), in the 2.4 GHz frequency band, or of the Sigfox type using UBN (Ultra Narrow Band) radio technology, or LoRa in the 868 MHz frequency band, LTE (Long-Term Evolution), LTE-Advanced, 5G; - USB interface (from the English "Universal Serial Bus" or "Universal Serial Bus" in French); - HDMI interface (from the English "High Definition Multimedia Interface", or "High Definition Multimedia Interface" in French); - LIN interface (from the English "Local Interconnect Network", or in French "Réseau interconnecté local").
[0091] According to another particular and non-limiting embodiment, the device 3 includes a communication interface 33 which enables communication with other devices (such as other computers in the embedded system) via a communication channel 330. The communication interface 33 corresponds, for example, to a transmitter configured to transmit and receive information and / or data via the communication channel 330. The communication interface 33 corresponds, for example, to a wired network of the type CAN (Controller Area Network), CAN FD (Controller Area Network Flexible Data-Rate), FlexRay (standardized by ISO 17458) or Ethernet (standardized by ISO / IEC 802-3).
[0092] According to a particular and non-limiting embodiment, the device 3 can provide output signals to one or more external devices, such as a display screen 340, touch or not, one or more speakers 350 and / or other peripherals 360 (projection system) via output interfaces 34, 35 and 36 respectively. According to a variant, one or more of the external devices is integrated into the device 3.
[0093] Figure 4 illustrates a flowchart of the different steps in a method for controlling an automated vehicle, for example, the automated vehicle 10. The automated vehicle is equipped with a localization system configured to determine its position. This localization system is configured to provide, in real time, a probability per hour that the error in determining the position relative to the actual position of the automated vehicle exceeds a threshold value, referred to as the probability of positioning error per hour, according to a particular, non-limiting embodiment of the present invention. The method is implemented, for example, by one or more computers of the automated vehicle 10, for example, by the device 3 shown in Figure 3.
[0094] In a first operation 41, an indicator representing a cumulative probability of positioning error per hour since the beginning of a time period of determined duration is determined at each time instant of the time period of determined duration.
[0095] In a second step 42, a value taken by the indicator at each time instant is compared to a target value of the indicator at the same time instant.
[0096] In a third step 43, the automated vehicle is controlled according to a result of the comparison from the second step 42.
[0097] According to one variant, the variants and examples of the operations described in relation to figures 1 to 2 apply to the steps of the process in figure 4.
Claims
DEMANDS 1. Method for controlling an automated vehicle (10) carrying a localization system (100) configured to determine a position of said automated vehicle (10), said localization system (100) being configured to provide in real time a probability per hour that an error in determining said position relative to an actual position of said automated vehicle (10) is greater than a threshold value, called the probability of positioning error per hour, said method being implemented by at least one processor and comprising the following steps: - at each time instant of a time period of determined duration, determination (41) of an indicator representative of a cumulative probability of positioning error per hour since the beginning of said time period; - comparison (42), audit at each time instant, of a value taken by said indicator audit at each time instant to a target value of said indicator audit at each time instant; - control (43) of said automated vehicle (10) as a function of a result of said comparison (42).
2. A method according to claim 1, wherein the control (43) of said automated vehicle (10) comprises a control for the safe shutdown of said automated vehicle (10) when said value taken by said indicator is greater than said target value of said indicator.
3. A method according to claim 1 or 2, wherein said indicator, denoted I(t), is determined according to the following equation, said determined time being equal to 1 hour: z-tio-u(t) dt l(t) = J o - hh - X 3600 with — - — corresponding to the said probability of positioning error per hour and t corresponding to the time instant expressed in seconds.
4. A method according to claim 3, wherein said target value, denoted l C ibie(t) is determined according to the following equation: 10 with— — corresponding to a determined target value of probability of positioning error per hour. io — x io - 5. A method according to claim 4, wherein — — = —6. A method according to any one of claims 1 to 5, further comprising an initialization step of said indicator at the beginning of each time period of determined duration of a set of time periods of equal duration to said determined duration.
7. Computer program comprising instructions for carrying out the method according to any one of claims 1 to 6, when such instructions are executed by at least one processor.
8. Computer-readable recording medium on which is recorded a computer program comprising instructions for carrying out the steps of the process according to any one of claims 1 to 6.
9. Device (4) for controlling an automated vehicle, said device comprising a memory (41) associated with at least one processor (40) configured for carrying out the steps of the process according to any one of claims 1 to 6.
10. Automated vehicle (10) comprising the device (4) according to claim 9.