Method for controlling the operation of a fully automatic driver assistance system of a motor vehicle for independent vehicle guidance and motor vehicle
Abstract
The method involves checking whether a fault exists by a plausibility monitoring module by considering ego data and environment data e.g. static environment data, where the ego data describes an actual operating condition of a motor vehicle. The ego data is determined by a sensor and/or vehicle system. An action plan is performed when the fault exists. The action plan is contained with driving intervention serving for transferring a motor vehicle into a safe mode i.e. standstill mode, and temporal sequences of control commands for a vehicle system (4). An independent claim is also included for a motor vehicle including a fully automatic driver assistance system including a control device for performing a method for controlling operation of the system.

Term
Projected expiry 23 May 2031.
- Priority
- Filed
- Published
- Today
- Projected expiry
13 claims: 4 independent, 9 dependent
- c-de-0001A method for controlling the operation of a fully automated, designed for independent vehicle guide the driver assistance system of a motor vehicle, characterized,that a plausibility check module under particular counting exclusively by at least one sensor and / or vehicle system determined, the current operating state of the motor vehicle described Egodaten and environment data, in particular, checks on the input data used also to determine the vehicle guide actions of the driver assistance system if at least one in terms of the function the driver assistance system excluded fault but being in the presence of a fault, a least one to convert the vehicle into a safe state, in particular the standstill, serving driving engagement comprehensive action plan including a time sequence of control commands for vehicle systems, is performed.
- c-de-0004Method according to one of the preceding claims, characterized in that be used as environment information data of the static environment and / or data of the dynamic environment and / or lane data.
- c-de-0005Method according to one of the preceding claims, characterized in that for checking the presence of a fault, at least one at least one case of a fault-covering algorithm is used for data analysis.
- c-de-0013A motor vehicle (1) comprising a fully automatic designed for independent vehicle guiding driver assistance system (2) with a trained for its operation control unit (3) adapted for carrying out the method according to one of the preceding claims.
Independent claims4
75 paragraphs, as filed
The invention relates to a method for controlling the operation of a fully automated, designed for independent vehicle guide the driver assistance system of a motor vehicle and an associated motor vehicle.
In the prior art many driver assistance systems are known in which the vehicle handling, ie the longitudinal and transverse control, partly by the driver, and partly by the driver assistance system is carried out. Examples of such driver assistance systems are longitudinal guidance systems, such as ACC (automatic cruise control) and stop-and-go systems, cross-guidance systems, which have a track center management system, or lane departure warning. The monitoring carried out by the motor vehicle actions and maneuvers is such driver assistance systems further from the driver, who observed the driver assistance system and its actions continuously.
Currently, the development of driver assistance systems depends mainly on so-called fully automatic driver assistance systems to the vehicle management fully adopt (within defined limits). A corresponding example is the so-called Traffic Jam Assistant. These systems have, for example, the goal of the driver in a traffic jam, so at speeds less than 60 km / h to decrease both the longitudinal guide with respect to the front vehicle and the transverse guide within the same lane. Another example is automatic parking systems or the like, but ultimately such fully automatic driver assistance systems for various, applicable even at higher speeds cases are developed.
As fully automatic driver assistance systems for the driver completely remove the entire task of driving (longitudinal and lateral control) over a longer period, it is possible to retract the driver after some time from the driving task and secondary employment will investigate. This means that in case of a so-called driver-over request, so if certain system limits are reached and the driver should even take control of the vehicle again, can not react quickly enough to adequately or not he. This would - unlike some automatic driver assistance systems - the driver, since he is not traveling takeover prepared can no longer act as a fallback.
System boundaries of a fully automatic driver assistance system to the understanding of the present invention not only the functional limits, so the specification to be taken Application (with jam assistance systems, for example, the limiting speed or the exit of certain environments, such as a highway), be, but also, for example, system failure / system failure or external influences, such as opening a door by the driver. In all such operations, if thus a takeover condition is met, known, fully automatic driver assistance systems require the driver, the vehicle handling, ie the longitudinal or transverse control to take over again. This can for example be identified by the fact that the driver operates the steering wheel and / or the pedals. Then the fully automatic driver assistance system can be deactivated again. Usually the driver will be given at a driver's request for taking a corresponding optical and / or audible and / or haptic indication, for example, a good display on a combination display, a voice message, a vibration of the steering wheel or the like. If the driver in such a situation, especially a critical situation such as a disaster or the like, not be able to quickly take control of the vehicle again, can security issues, especially accidents occur.
In particular, however, the driver is provided that he pays no attention to the traffic situation, for example, if he pursues a second job, not able to critical situations that arise, for example, from a malfunction of the driver assistance system or be triggered by another road user, for example, lost cargo or like to see, and to control the vehicle guidance correcting. The result can also security issues, be accidents like collisions in the worst case.
In the subsequently published German application with the file reference <patcit id="pcit0001" dnum="DE102009050399"><text>DE 10 2009 050 399.4</text></patcit> was proposed to provide a driver assistance system with internal self-diagnostic capabilities and provide automatic fallback modes when the driver does not take a driver over request or the situation is very critical.
The invention is therefore based on the object to provide a control method for fully automatic driver assistance systems, which is not yet permitted in as fallback available stagnant driver in case of a critical traffic situation, to provide reasonable assurance.
To achieve this object, the invention provides for a method of the aforementioned type that a plausibility check module under particular counting exclusively by a sensor and / or vehicle system identified at least, the current operating state of the motor vehicle described Egodaten and environment data, especially from the the well to determine vehicle guide actions of the input data used driver assistance system, to check whether at least there is an excluded in view of the function of driver assistance system error occurs, wherein if there is an error, if a least one to convert the vehicle into a safe state, in particular the stop within the same lane, serving driving engagement comprehensive action plan, which includes a timing control commands to vehicle systems, is performed.
Thus, the invention proposes to design a monitoring system, here the plausibility monitoring module, which may ultimately assist or take over the driver's monitoring task. The functional behavior of the driver assistance system must be made plausible for several reasons, firstly because it can not be guaranteed with absolute certainty that generate the modules of the driver assistance system, the building on the optionally treated as environment model input data, the functional behavior of the driver assistance system are working properly. On the other implausible and thus critical situations can also by the behavior of other road users, such as traveling between tracks motorcycles, lost cargo, or the like, are produced. The plausibility security module of the present invention checks whether the motor vehicle behaves plausible to the given definition of driver assistance system or whether it has been in a particularly critical situation that should not have happen after the definition of fully automatic driver assistance system, so there is an error case. So it is in the present invention ultimately to deviations from a by definition the driver assistance system anticipated conduct which by matching the self-movement of the motor vehicle (Egodaten), which is a result of the output data of the driver assistance system is yes, and the environment data is determined.
Regarding errors of the driver assistance system, the plausibility monitoring module can therefore in particular find faults that occur when the self-diagnosis no longer applies. Here only the externally observable functional behavior is viewed with particular advantage, so the final result of the action of the driver assistance system in the form of momentum, so the operating state of the motor vehicle relative to the environment. The input data are in the plausibility monitoring module then consequently only the Egodaten and the environment dates being explicitly refrained from the output data of the function of driver assistance system, ie, in particular manipulated variables for the various vehicle systems, which are placed on the scheme, also to be used as input data.
This has several advantages and reasons. First, the plausibility is in the present invention, as already mentioned, are viewed from a perspective of the observer, which means that as little recourse should be made to the functionality of the driver assistance system itself to as independent as possible and easy to carry out a plausibility check, the ultimately a kind of "neutral" observers equivalent. In addition, the output data of the driver assistance system are extremely strong situational. A situation detection is very complex and therefore prone to error, also often have to lateral gradients of data are taken into account. In this way, the risk would be to introduce the right to be tested error rate of driver assistance system in the plausibility check, which is not conducive to the overall security. Thus, the inventive method proposes a simple to implement plausibility check based ultimately only the input data from which are made available to the driver assistance system, these being understood and analyzed for plausibility recognition as a "result" of the actions of the driver assistance system to locate faults. As is explained in more detail by the hereinafter explained in more detail algorithms of plausibility monitoring module, which evaluate the various measurement data, a flashover checks of plausibility regarding the faults is aimed ultimately.
This observational verification of the result of the action of the driver assistance system a number of advantages can be achieved, however, in particular functions of fully automatic driver assistance systems can be implemented without any monitoring of driver assistance system must be ensured by the driver. The driver is given the possibility to give the driving task on the driver assistance system and sideline, such as reading e-mail or television, pursue, while the motor vehicle is self-directed. therefore Such fully automatic driver assistance systems can also be referred to as an autonomous driver assistance systems from such a development. The inventive method thus is finally a possibility for realizing an autonomous driver assistance system.
This is realized by the plausibility monitoring module which checks the functional behavior of the driver assistance system of principle plausibility. Finally, as already described, the operation performed by the driver assistance system current action (transverse and longitudinal guide), which is reflected in the Egodaten, in the context of the environment in which the vehicle is moving (lane data, object data, dynamic objects, static obstacles and clearances) set and checked whether this behavior corresponds to a fault, therefore, whether it may be useful. The monitoring mechanism can be understood as ultimate supervisory body, as he observed only the direct effect within the behavior generation occurred and not automatically detected errors. Here, the plausibility monitoring module supports, as already mentioned, expediently on the exact same input data as the behavior generation of driver assistance system. The environment data may include, for example, data of the static environment and / or data of the dynamic environment and / or lane data.
If such an error occurs, the invention provides a least one to convert the vehicle into a safe state, in particular the standstill, serving driving engagement comprehensive action plan including a time sequence of control commands for vehicle systems performed. Of course, such an action plan and, as known from the prior art, include a driver over request, but it is proposed, no longer or no longer spend alone a driver over request, but to use an action plan that includes the driving interventions that the motor vehicle even if the driver is not driving takeover ready and cease to be a fallback solution, in a safe state, ie, in particular preferred to convert the stoppage of the motor vehicle in the same lane. It is created by the so or driving interventions another fallback that allows to transfer the motor vehicle, without operator input back to a safe state, especially in a standstill. It should be noted at this point that such an action plan can not only be used when the plausibility monitoring module detected a fault, but of course, if it is found in an internal self-diagnosis module of driver assistance system that a system limit is reached or the like.
The action plan is a chronological sequence of control commands for various vehicle systems. Such control commands, for example, to address a combination of display to output a driver over request in a driving engagement could by a control unit of the fully automated driver assistance system, for example, directly or under more control units, the braking and / or steering are driven, and the like. Are also possible control commands for other vehicle systems, for example, the hazard warning lights. Each of these control commands is associated with a time or a time period within the Action Plan. At this time, or during this period, the control command is executed.
It should be generally noted at this point that the inventive method of course in all aspects fully automatically in a control unit, in particular a fully automatic driver assistance system associated control unit, expires, without manual intervention by the driver is required, since there is ultimately the goal is to be able to ensure the safety of the vehicle as possible without the action of the driver yet.
In a further embodiment of the inventive method can be provided that the action plan will be selected in consideration of the fault from a number of predefined action plans and / or adjusted. The "case of error" as output data of the plausibility monitoring module can be arbitrarily defined precisely and are optionally provided with further information. So it is conceivable that in particular different error cases associated action plans are provided, one of which - in particular on the basis of fulfilling error Falls - an action plan is selected. In addition, can also be provided, moreover, that an action plan taking into account the current situation descriptive data is adjusted. The current situation descriptive data which may also include in particular measurement data of different sensors or sensor systems, are not only the surroundings of the motor vehicle described environmental data, but also Egodaten of the motor vehicle, in addition, of course, various other information available within the motor vehicle, ie the current situation descriptive data, will be considered. Particularly relevant here, of course, all data relating to the type of error occurred if - when selecting or adjusting an action plan should therefore preferably the type of error encountered Falls are considered.
The driving engagement in the Action Plan can be found, for example, from a leading to a safe condition Rückfalltrajektorie. Such Rückfalltrajektorie will typically include a Längsrückfalltrajektorie concerning the longitudinal control of the vehicle, ie in particular describes how and when the motor vehicle is to be braked to a standstill. In addition, may be included with particular advantage also Querrückfalltrajektorien, thus affecting the lateral control, so consequently the steering, the motor vehicle. If such overall Rückfalltrajektorie determined - as moreover can be done for time periods - so from this the corresponding driving interventions realized control commands of the action plan can be determined or adjusted, so that ultimately the Rückfalltrajektorie represents the trajectory of the safe state to be transferred motor vehicle.
Of course, many other advantageous features of the action plans are conceivable as additional fallback, for example, a modular construction of Aktlonspläne which particularly by the aforementioned post-published German Patent Application <patcit id="pcit0002" dnum="DE102009050399"><text>DE 10 2009 050 399.4</text></patcit> to be discribed.
As already mentioned, it is ultimately necessary to ensure maximum protection that the plausibility monitoring module operates on the basis of an error-free functioning perception. This means that provided by sensors or other vehicle systems Egodaten and environmental data must be reliable. Therefore, advantageously be provided that a is at least used a sensor or vehicle system with respect to the data acquisition associated function check module, in particular at least one sensor is designed redundantly. Error in Wahmehmungsmodulen can be easily recognized on the particular Provision of redundant sensors. It should be noted that a failure of such a perception module or sensor or other vehicle system can of course also be a system limit that can lead to a transfer of the motor vehicle in accordance with an action plan in a safe state.
In a further advantageous embodiment it can be provided that the review of the error if at least one at least one case of a fault-covering algorithm is used for data analysis. As already indicated, the security in the process of the invention increases in particular to the fact that as completely as possible all occurring faults can also be detected. These algorithms can be used, each covering a portion of possible errors. To identify the faults that need to be covered, can be taken as a conceptual groundwork so that will ultimately determine which general requirements are placed on a plausible behavior of the driver assistance system, which means that normal cases are expected. Accordingly it can be inferred from such expectations estimate that errors are displayed in terms of the function of driver assistance system must be regarded as excluded. therefore makes sense to analyze and categorize the possible error occurring cases will be discussed in the course in more detail.
Conveniently, can be used as a fallback algorithm analysis in which the existence of a trajectory, on which can be braked without collision to a standstill, is checked. It is thus verified by the alternate analysis whether collision-free traversing is still possible. This is the case when at least one trajectory exists, can be braked on to a standstill without colliding with an obstacle. The length of the longest free trajectory for example, can initially be determined and compared with the stopping distance needed at the current speed. Is the longest free path longer than the braking distance, possibly with the addition of a safety margin, so can be operated without collision. Such alternative analyzes are nowadays often used in so-called emergency brake. In this context, an alternative analysis, for example, at the 10th Braunschweig Symposium AAET 2010 on 10 and 11 February 2010 under the title "Advanced adaptive cruise control and use an alternative analysis as the basis of an active emergency braking" by M. Reichel, ME Bouzouraa, A. Siegel , K.-H. Siedersberger and M. Maurer suggested. While the local alternative analysis is designed to support the human driver on the road, so is parameterized so that they may trigger too early in any case, it is in the present case, however, on safety aspects of a plausibility check, so that in a particularly advantageous development of the method modification of the input data can be provided in such an alternate analysis. Thus, if a places as occupied by an object, unknown or free classifying environmental model is used, be provided that for the purpose of evading analysis outside of the current driving lane of the vehicle lying and / or classified as unknown locations are marked as occupied. Thus more attention is paid to the safety aspect. Such environmental models, often referred to as assignment cards are known, such an environment model in addition to an occupancy map also may include other information structures. It should also be pointed out that can be detected on the Marking of areas outside the current lane as occupied a lane departure by the alternate analysis.
A further possibility of a beneficial algorithm to be used is a safety cocoon algorithm, in which checks whether a defined, around the motor vehicle befindliches area is free of objects. This can be used to particular advantage in addition to alternative analysis which does not cover the cases where the vehicle is too close passes by the side of an obstacle or where dynamic objects come too close to the subject vehicle. The "safety cocoon" can be drawn, for example, at a certain distance around the vehicle. Is this "safety cocoon" not free, so is a static or dynamic object in this field, an error situation arises. For example, the cocoon may be located at a distance of 50 cm around the motor vehicle. It should also be pointed out that the security cocoon can be adapted to the front so that it checks a required gap for the sensor. Again, a modification of the input data an environment model be provided by are marked as unknown areas classified for the purposes of security cocoon algorithm as occupied. Thus no tripping takes place when driving on the track edge, but areas outside the current lane can not be changed in this case.
As a particularly useful usable in storage assistance systems algorithm is a time gap algorithm has proven, in which checks whether there is a vehicle in front of the motor vehicle is in a certain time gap interval. The time gap interval can based on the desired function of the driver assistance system, ultimately therefore turn even the expectation, are defined on the driver assistance system. In this way it can be determined whether the preceding vehicle is still followed properly or if is left too little or too much distance to the preceding vehicle. It can be provided that a short-term over-and / or below the time gap interval is permitted, by checking the time gap is provided with a hysteresis.
Also, a speed limits algorithm can be used as advantageous algorithm which checks whether the vehicle is running within a specified speed interval. While the speed interval can of course be due to environmental conditions that can be taken from a navigation system, for example in the form of speed limits and the like, determines also the speed interval can be determined based on the intended function of the driver assistance system, ultimately, for example in a traffic jam assistance system as between 0 and 60 km /H. At ambient conditions, for example, a prescribed maximum speed and / or a predetermined minimum speed can be considered. The review under such an algorithm may be a simple query to the current speed of the motor vehicle, which is available in any case in modern motor vehicles, realized.
A particularly advantageous embodiment results can be shown if an alternative analysis, a security cocoon algorithm, a time gap algorithm and speed limits algorithm can be realized simultaneously, since it can be shown that it, especially in the case of a traffic jam assistance system, all possible errors can be covered. This is illustrated by the following considerations and later with respect to the description of the figures.
So first, the expected behavior of the motor vehicle to be checked in. For example, if a traffic jam assistance system only defined for speeds between 0 and 60 km / h so is leaving this speed interval, identified by production Egodaten, implausibility ago. The expected behavior of the motor vehicle so that it travels within its allowed speed limits. Possible Errors are that the ego drives too fast or backwards.
Next, the behavior of the motor vehicle with respect to a preceding vehicle should be considered. Economists expect this example, that the vehicle maintains a minimum distance sensor (sensor gap), and the speed adjusted to the time gap to the vehicle ahead. Possible Errors are here: below the minimum distance sensor by the motor vehicle to imminent coming of the motor vehicle longitudinally to the vehicle in front and a larger distance to the preceding vehicle by the motor vehicle. In addition, however, cases have to be considered in a new preceding vehicle is found, for example, because the old vehicle in front leaves the current lane. Economists expect then that the vehicle speed at the time gap to the new preceding vehicle, if there is one, regulates, or that the traffic jam assistance system is deactivated if no further preceding vehicle exists. Possible errors are here: that the motor vehicle can be too much distance to the preceding vehicle, since it is not controlled in time to the new vehicle in front, or that the motor vehicle can be too much distance to the preceding vehicle, if no further preceding vehicle exists and the traffic jam assistance system does not automatically disabled.
can be further considered the behavior of the motor vehicle with respect to a secondary vehicle, ie a motor vehicle in the side area of one's own motor vehicle. Here, it is expected that no particular reaction to a normal traveling side vehicle enters and the vehicle maintains a lateral safety distance to the vehicle side and remain in their own currently traveling lane. Possible errors are here, that the motor vehicle to the preceding vehicle longitudinally gets too close, because the wrong vehicle in front has been selected, or that the motor vehicle can be too much distance to the preceding vehicle because the wrong vehicle in front has been selected. In addition, the motor vehicle can a static obstacle coming laterally to close because the driver assistance system is requesting an exaggerated or unnecessary avoidance reaction, or the motor vehicle is dynamic obstacles laterally close to where the same reason may be. Finally, an exaggerated or unnecessary evasive reaction can also lead to leave the current lane by the motor vehicle.
Another key point to be considered is the behavior of the motor vehicle with respect to the Einscherens of motor vehicles. It is expected that the speed is regulated to the new preceding vehicle on time gap. Possible Errors are that the motor vehicle is less than the minimum distance sensor when the false front vehicle is selected, or for the same reason the motor vehicle to the vehicle in front comes too close longitudinally.
Also to consider is the behavior of the motor vehicle with respect to the current driving lane. Expected is here that the vehicle is running within the current lane. An error event is leaving the current lane.
Finally, it the behavior of the motor vehicle with respect to static obstacles to consider. Here, it can be expected that the motor vehicle is braking on a static obstacle when it is not umfahrbar, or circumvents this. Here the following error will occur: The automobile can the static obstacle come longitudinally or laterally to close because it is not shot past the obstacle. Also can occur at much distance to the preceding vehicle, as is braked, even if the obstacle is umfahrbar. In addition, the vehicle may come too close to a dynamic obstacle and / or a static obstacle laterally or longitudinally when an unwanted evasive response is required or not, or is not adequately braked. Finally, a lane departure is possible when an undesired escape response is requested.
Ultimately, can the error cases described here, letting their causes aside, summarized in the following error cases, further wherein an example of a traffic jam assistance system is considered: <ul><li>the motor vehicle is traveling too fast or backwards,</li><li>the motor vehicle is less than the minimum distance sensor (sensor gap)</li><li>the motor vehicle is a vehicle in front longitudinally too close,</li><li>the motor vehicle leaves too much distance to the preceding vehicle,</li><li>the motor vehicle is a dynamic obstacle laterally to close</li><li>the motor vehicle leaves the lane,</li><li>the motor vehicle is a static obstacle longitudinally too close,</li><li>the motor vehicle is a static obstacle close laterally.</li></ul>
The same observation can be carried out also caused by other road users plausibility error, wherein, for example, dynamic objects, and static obstacles can be considered as aspects of situations that may be present in various forms, but also error groups can be assigned, for example, in the expression "front vehicle emergency braking" or "extremely close sheering" the error cases "the motor vehicle falls below the minimum distance sensor" or "the motor vehicle is the leading vehicle longitudinally too close". Motorcyclists between column traces, ambulances or the like, for example, in the case of error ", the motor vehicle is a dynamic obstacle laterally to close" are mapped. Similarly, can we do with static obstacles, their characteristics can "to close the motor vehicle is a static obstacle lateral" error cases "the motor vehicle is a static obstacle longitudinally too close" or be assigned.
Beyond these four algorithms, these generalized error cases completely cover. The speed limits algorithm relates to the case of error "the vehicle is running too fast or backwards". The time gap algorithm covers the faults "the motor vehicle is a vehicle in front longitudinally too close" and "the vehicle can be too much distance to the preceding vehicle" from. The errors "the motor vehicle is a dynamic obstacle laterally too close" and the case of error ", the motor vehicle is a static obstacle laterally to close" can be covered by the security cocoon algorithm as was the case of error "the motor vehicle falls below the sensor minimum distance (sensor gap)". The alternative analysis eventually covers the faults "the motor vehicle is the leading vehicle longitudinally too close", "the motor vehicle leaves the current lane and" the motor vehicle is a static obstacle longitudinally too close "from. Thus, it was for the example of the jam assistance system demonstrated that the four algorithms described in their entirety the faults that occur can completely cover.
Generally, the novel process advantageously yet another case of a fault to be checked, which is largely preclude the use of an autonomous driver assistance system, namely the presence of people on the current lane of the motor vehicle. So it can be provided that a person recognition algorithm is used as an algorithm that recognizes people present on the current lane of the motor vehicle. Thus, the safety is increased in this respect.
In addition to the method, the invention also relates to a motor vehicle, comprising a fully automatic, designed for independent vehicle management driver assistance system with a trained for its operation control unit, which is designed for carrying out the process. There a plausibility monitoring module is therefore also provided with the motor vehicle according to the invention, which detect the presence of error cases by evaluating Egodaten and environmental data and thus can trigger an action plan. Thus, the advantages of the method are also achieved in the car according to the invention. All statements regarding the method according to the invention can be applied analogously to the motor vehicle according to the invention.
Further advantages and details of the present invention will become apparent from the embodiments described below examples and from the drawings. They show:<dl id="dl0001"><dt>Fig. 1</dt><dd>an inventive motor vehicle,</dd><dt>FIG. 2</dt><dd>a first, preliminary to the inventive method illustrative graphs</dd><dt>Fig. 3</dt><dd>a second, preliminary to the inventive method descriptive graphs</dd><dt>Fig. 4</dt><dd>a flowchart of the inventive method,</dd><dt>Fig. 5</dt><dd>a reachable set due to the driving dynamics,</dd><dt>Fig. 6</dt><dd>an actual reachability set in consideration of environmental data,</dd><dt>Fig. 7</dt><dd>an illustration to safety cocoon algorithm</dd><dt>Fig. 8</dt><dd>an illustration to time gap algorithm, and</dd><dt>Fig. 9</dt><dd>a possible action plan.</dd></dl>
<figref idrefs="f0001">Fig. 1</figref> shows the schematic diagram of a motor vehicle 1 according to the invention It includes a fully automatic driver assistance system 2 with a control unit 3, which is designed for its operation and also for implementing the method according to the invention. It should be noted at this point that of course, also an additional or other control device can be configured for implementing the method according to the invention for better separation.
The control unit 3 is also adapted with further vehicle systems, indicated at 4, to communicate. Thus, the motor vehicle includes various sensors for measuring the dynamics and the environment, various other vehicle systems, including a steering system and a brake system, and also other driver assistance systems, such as a navigation system. On their data, the control unit 3, for example, via a bus system, in particular a CAN bus access just to perform the inventive method can, which requires the current operating state of the motor vehicle described Egodaten and environmental data as exclusive input data. Here exactly the same input data are used, which also used the driver assistance system 2 for determining its conducted for vehicle guidance driving interventions.
To carry out the process of the invention, a plausibility monitoring module is implemented in the control unit 3, which uses each specific error cases associated algorithms for evaluating the Egodaten and environment data to check whether at least there is an excluded in view of the function of driver assistance system fault. If there is an error If an action plan is carried out, which includes at least one to convert the motor vehicle serving in a safe state driving engagement. These will be discussed in more detail below.
Before discussing the considerations regarding the special configuration in the embodiments described herein, it should be pointed out that should also be ensured in these embodiments, the sensors or vehicle systems provide 4 reliable data, which forms a basis of the inventive method. Accordingly, the sensors are designed in the present example redundant, and there is a balance between redundant data supplied by sensors on the respective sensors or vehicle systems 4 associated functional test module. Such is known in the prior art in principle and does not need to be explained in more detail here.
Before now closer to the algorithms specifically used methods of the invention and the flow chart of the inventive method will be discussed, first had to this particular embodiment, the for a jam assistance system is particularly advantageous realized, leading considerations using the <figref idrefs="f0002">figures 2</figref> and <figref idrefs="f0003">3</figref> set out in more detail. <figref idrefs="f0002">FIG. 2</figref> relates to analyze actual faults the driver assistance system 2, here a traffic jam assistance system. The boxes mark in each case special events and groups. The basic idea is, first, the expected behavior of the driver assistance system, as reflected by the made vehicle guidance interventions in the current Egodaten, of course, considered in relation to the environment data, if possible, to detect, to then consider what generalized failure to depart from may be assigned to expected behavior.
The starting point in these considerations of a behavior of the motor vehicle to be concerned situation Group 5 and the behavior of the motor vehicle 1 with respect to other objects contemplative situation Group 6. Obviously for the jam assistance system in <figref idrefs="f0002">Fig, 2</figref> the situation assigned to group 5 only one situation in the C column for expected behavior, characterized by the box 7: "The motor vehicle is within its allowed speed limits". The error associated with the case, column D, here would be the case of a fault 8: "The automobile is running too fast or backwards".
With respect to the behavior of the motor vehicle with respect to other objects, situation Group 6, are still various aspects of situations, column A, and various forms, column B, distinguished. The situation aspects in column A give it back, with respect to which object the behavior of the motor vehicle is considered, in this case the situation aspects 9: "behavior with respect to a vehicle in front," 10: "behavior with respect to a secondary vehicle", 11: "behavior with respect to a einscherenden vehicle" , 12: "behavior with respect to the current lane", and 13 "behavior with respect to a static obstacle".
Column B now refers to certain characteristics. So relates the expression 14, a normal-propelled vehicle in front, the expression 15 a ausscherendes preceding vehicle with the lower forms 16 and 17, namely that another preceding vehicle exists, expression 16, and that no further preceding vehicle exists, expression 17th
From this then results in each case, see the line, the expected behavior in column C, for example, the behavior. 18: "The automobile holds the sensor minimum distance a ', the behavior 19:" The vehicle controls the speed at the time gap to the vehicle in front " the behavior 20: "the vehicle controls the speed at the time gap to the new vehicle in front", and the behavior of 21: "the embodied as jam assistance system driver assistance system is deactivated".
Similarly, the secondary vehicle is divided with respect. According to expression 22, the side vehicle can run normally in accordance with expression 23, it transgresses the lane markings and in accordance with cutout 24 there is the own vehicle too close. This results in accordance with the arrows in<figref idrefs="f0002">FIG. 2</figref> the expected behavior 25: "No specific response to normal propelled side car" or the behavior 26: "The automobile holds the lateral safety distance from the vehicle side and remains in its current lane."
Regarding the Einscherers, aspect 11, is only the behavior of 27: "The automobile controls in time to the cutting in motor vehicle" to look at. Also with respect to the aspect 12, the current lane is only the behavior of 28: "The motor vehicle is running only within the same lane" to be considered.
With respect to a static obstacle, aspect 13, is between the situation manifestations 29: "The obstacle is umfahrbar" and 30: "The obstacle is not umfahrbar" distinction. Accordingly, there is the expected behavior 31: "The motor vehicle is running on the static obstacle passing" or 32 "The car stops on the static obstacle" a.
From the expected Verhaltungsmöglichkeiten in column C resulted certain errors. These can be assigned according to the column to D arranged from column C arrows certain error groups, here the error groups 33 to 39, as the case of a fault 8 is only relevant for the behavior. 7 These faults are:<ul><li>"The automobile differentiates the sensor minimum distance" (error 33)</li><li>"The automobile is a front vehicle longitudinally to close" (error 34)</li><li>"The motor vehicle leaves too much distance to a vehicle ahead" (error 35)</li><li>"The automobile is a dynamic obstacle laterally to close" (error 36)</li><li>"The motor vehicle leaves the current lane" (error 37)</li><li>"The automobile is a static obstacle longitudinally close to" (error 38)</li><li>"The automobile is a static obstacle laterally to close" (error 39).</li></ul>
In column E namely a speed limits algorithm 40, a time gap algorithm 41, a security cocoon algorithm 42 and an alternative analysis are now in the process of the invention algorithms used, here four algorithms 40 to 43, provided that cover all these faults completely, 43. The arrows between the columns D and e show the process where the error cases 8, 33 - 43 is assigned, that is, the error case respectively which algorithm 40 - - 39 wherein the algorithms 40 may detect the 43rd Obviously enable shown in column E four algorithms speed limits algorithm 40, algorithm time gap 41, security cocoon algorithm 42 and evasive analysis 43 provides full coverage of error cases.
But how <figref idrefs="f0003">Fig. 3</figref> aims to show triggered by other road users or incidents error cases can be covered by the algorithms, here mainly the algorithms 41-43, which in turn in column D <figref idrefs="f0003">Fig. 3</figref> are shown. Situation aspects of such foreign debt-fault cases are set out in column A, for example, the aspect of 44: "Triggered by a dynamic object" or the aspect of 45: "Triggered by or manifested as a static obstacle".
Forms are again shown in column B. Thus, among the forms 46, for example, an emergency stop of a vehicle in front or an extremely close vehicle cutting subsumed. The values 47 for example, comprise a motorcyclist or an ambulance between the column traces. Forms 48 with respect to the aspect 45 may be lost cargo or that have fallen tree.
Obviously the forms shown can already from <figref idrefs="f0002">FIG. 2</figref> known error cases 33, 34, 36, 38 and 39 associated, which are known as covered by the algorithms 41-43. Foreign-inflicted errors are thus included in the inventive process.
As well in <figref idrefs="f0003">Fig. 3</figref> "People on the road", for example, in the forms 50: illustrated, the inventive method also another important situation aspect, namely the aspect of 49 concerns in this configuration, "construction worker", "police", "jam helper" and the like may be provided , This resulted in a further fault case results 51: "People on the current lane", which can lead to safety to deactivation of the traffic jam assistance system. For this purpose, the additional person recognition algorithm 52 is used in the novel process.
<figref idrefs="f0004">Fig. 4</figref> shows a flow chart of the inventive method. Is the driver assistance system 2 is active, are at each time step of the vehicle systems 4, in a step 53, the input data, so the Egodaten, and the region data including the present data of the static environment, the information about the dynamic environment and lane data received. This input data is used in a step 54 as input data for the algorithms 40 to 43, 52, being optionally recycled.
These should firstly be noted that in the illustrated embodiment, the environmental data are generally prepared so that they are present as an environment model, concretely an occupancy map comprehensive environment model. In an assignment card is anywhere in the environment, such as at a occupancy grid allocated to the respective areas, whether this site free, occupied by an object or marked as unknown, in the latter case for example, be from there, particularly because of a shield, no measurement data , The locations can then be naturally also associated with additional information, as is generally known in the art. Such an environment model can therefore be used for the novel process.
Below now are the operations of the algorithms 40 to 43, 52, explained in more detail, starting with the speed limits algorithm 40th
The speed limits algorithm 40 is relatively easy to implement. He compares the present, a traffic jam assistance system Affected by example the current speed of the motor vehicle 1 with the boundaries of the permitted speed interval, here 0 km / h and 60 km / h. If the speed out of bounds, is an error case, namely the case of an error. 8
The <figref idrefs="f0004">figures 5</figref> and <figref idrefs="f0005">6</figref> show illustrations for explaining the alternate analysis. Within this an actual reachability set 55 is determined in a first step, therefore, the amount of principle, because of the dynamic driving properties (circle of forces, and the like) to reach points in the environment of the motor vehicle. This is in<figref idrefs="f0004">Fig. 5</figref> illustrated; while the x-direction indicates the current direction of the motor vehicle. 1 Whether a place of theoretical reachable set 55 can actually be achieved, however, is determined by the objects around. For this, the availability of the card environment model is now placed on the theoretical accessibility Volume 55, wherein the data of the assignment card however, were not pre-processed in two ways. On the one hand are marked as unknown places marked as occupied, on the other hand all the places lying outside the current track will be marked as occupied.
It arises as actual accessibility Volume 56 of the in <figref idrefs="f0005">Fig. 6</figref> unmarked area. The completed blocks 57 symbolize surrounding objects, so basically occupied areas while dashed one is for reasons other than occupied area marked 58 shown (for example, because present here no sensor data - "unknown" - or the location outside the current traveling lane is).
In the actual accessibility Volume 56 will now search for the longest free path. This path is then compared with the minimum stopping distance of emergency braking, which is needed at the current speed and the current conditions. It can also feed with a safety margin. Falls below the free way this minimum braking distance plus safety distance, so there is an error case.
However, this alternative analysis 43 does not cover the cases where the motor vehicle 1 side too close to an obstacle, so a static object, passes, or where dynamic objects come too close to the subject vehicle. Furthermore, the sensor is not minimum distance (often also referred to as the sensor gap area in which no measurement of the distance sensors is made to the preceding vehicle) taken into account. To this end, the security cocoon algorithm will be used. Here is an alternative to the motor vehicle 1, a security cocoon 59, see.<figref idrefs="f0005">Fig. 7</figref>Introduced, which occupies a certain width b in addition to the motor vehicle 1, for example, 50 cm, and the extension of which corresponds to the minimum distance sensor x front of the automobile. Is not free of safety cocoon 59, that is a static or dynamic object, here the slave vehicle 60, within this range, then there is a fault. It should be noted that in the assignment board for security cocoon algorithm 42 unknown areas are marked as occupied. However, this is no fault is detected when running to the edge of the current lane, areas outside the current lane can not be changed.
The time gap algorithm 41 detects ultimately whether a preceding vehicle 61 is still followed correctly. For this purpose, it is checked whether the currently measured time gap is located to the front vehicle 61 within a certain time gap interval 62nd The time gap is defined as the ratio between the distance to the preceding vehicle 61 and the actual speed of the motor vehicle 1, in<figref idrefs="f0006">Fig. 8</figref> as V<sub>ego</sub> designated. Obviously is the in<figref idrefs="f0006">Fig. 8</figref> Situation illustrated the current time gap X<sub>vsz</sub> in the interval 62 between the time gap X<sub>Max</sub> and the time gap X<sub>min</sub>,
It should in this case a short-term exceeded X<sub>Max</sub> or a short-term undershooting of X<sub>min</sub> occur, which is why the review of the time gap with a hysteresis is provided.
For the person recognition algorithm 52, a conventional, well-known algorithm for the detection of persons in the same lane is used which is not to be explained in more detail here.
In step 63 (<figref idrefs="f0004">Fig. 4</figref>) Is then checked whether an error is present case. If there is no fault, then, see. Arrow 64, the next time step again proceeds to step 53. However, there is an error case, then in a step 65 is dependent on the case of an error, if appropriate, an action plan of a plurality of action plans selected and adapted to the motor vehicle 1 under deactivation of driver assistance system 2 as quickly as possible taking into account further, the current situation of descriptive data in a safe state, the deadlock to transfer here.
Here is just one example of such an action plan in <figref idrefs="f0006">Fig. 9</figref> are shown, namely the so-called comfort brake plan. An axis 66 indicates the time. At a time 67 an error was detected, which means that the action plan will begin. In the present case of<figref idrefs="f0006">Fig. 9</figref> is then output directly a driver over request. This is done by means of corresponding control commands to at least one optical and / or acoustic and / or haptic display device of the motor vehicle 1. Subsequently, waiting for a predetermined time 68th Once this has expired, has taken control of the motor vehicle 1 without the driver, a plurality of control commands are executed at a time when the 69th Firstly, the hazard warning lights of the motor vehicle 1 is activated to warn other road users. On the other hand requires a braking with a predetermined deceleration a, that means there is a longitudinal guiding engagement, a braking intervention with a certain deceleration made here. This continues until a time 70 resting the vehicle, therefore, the safe state is reached. Here, a moderate braking deceleration can be selected that moves the vehicle 1 comfortable to standstill here.
It should be noted at this point that there is no constant braking delay shall be provided, but this may change over time. In particular, it may be advantageous for a short time to put a high deceleration (braking jerk) to increasingly alert the driver to the changed situation and the activation of the driver assistance system 2, because even after the time 69 is the driver nor the ability to take control of the motor vehicle 1 to take over by driving adoption. The comfort brake plan can be used for example, if an error and / or other data considered indicate that the situation is not critical.
Also, a Notbremsplan which can be performed when a highly critical situation is given, for example, a much too small distance to a vehicle ahead is detected or the like, are used. It is conceivable, in principle, to choose the method of the invention the Notbremsplan to obtain the greatest possible safety. In this case, possibly in addition to a driver over request, the hazard warning lights and the horn of the motor vehicle 1 are activated at the same time held a braking operation at the maximum possible deceleration. However, it may be considered absolutely that a sealing auffahrendes follower vehicle or the like has been detected; in this case can also be selected in Notbremsplan a deceleration, which is slightly less than the maximum possible deceleration.
It is conceivable as a plan of action and a target braking plan whose basic idea is that it can be determined at an early stage in many situations in which distance from the current location of the motor vehicle 1 that should be motor vehicle 1 stopped at the latest. Accordingly, the target deceleration for example, can be adapted or the like. Also cross fallback modes can be realized on the action plan.
Finally, it is pointed out yet that the action plans can be also used when it is determined at self-diagnosis modules the driver assistance system 2 that a system limit is reached.
The driver assistance system 2 assessed due to the impact on the motor vehicle plausibility monitoring module is therefore in addition to already available modules that monitor system limits provided. So increased security is achieved in particular an autonomous driver assistance system.
7 sheets
Sheet 1 Sheet 2 Sheet 3 Sheet 4 Sheet 5 Sheet 6 Sheet 7
Every citation, both ways
| Document | Relation | Office | Cited during |
|---|---|---|---|
| WO2019121344A1 | Cited by | World Intellectual Property Organization (WIPO) | International search |
| CN109492518A | Cited by | China | Search report |
| EP3304233B1 | Cited by | European Patent Office (EPO) | Filed by opponent |
| US10755119B2 | Cited by | United States of America | Search report |
| DE102015222605A1 | Cited by | Germany | Search report |
| CN110869260A | Cited by | China | Search report |
| CN110928284A | Cited by | China | Search report |
| US10496092B2 | Cited by | United States of America | Search report |
| US10198951B2 | Cited by | United States of America | Applicant |
| EP3300974A1 | Cited by | European Patent Office (EPO) | Search report |
| US11276314B2 | Cited by | United States of America | Applicant |
| US9971349B2 | Cited by | United States of America | Applicant |
| US10336268B2 | Cited by | United States of America | Applicant |
| US10481603B2 | Cited by | United States of America | Applicant |
| US9469296B2 | Cited by | United States of America | Applicant |
| WO2018103937A1 | Cited by | World Intellectual Property Organization (WIPO) | International search |
| CN107148376A | Cited by | China | Search report |
| WO2022263044A1 | Cited by | World Intellectual Property Organization (WIPO) | International search |
| WO2015139864A1 | Cited by | World Intellectual Property Organization (WIPO) | International search |
| CN110035918A | Cited by | China | Search report |
| WO2016191348A1 | Cited by | World Intellectual Property Organization (WIPO) | International search |
| US10796581B2 | Cited by | United States of America | Applicant |
| CN110692094A | Cited by | China | Search report |
| US10901415B1 | Cited by | United States of America | Applicant |
| US11608080B2 | Cited by | United States of America | Applicant |
| WO2016062568A1 | Cited by | World Intellectual Property Organization (WIPO) | International search |
| WO2015014707A1 | Cited by | World Intellectual Property Organization (WIPO) | International search |
| WO2015197251A1 | Cited by | World Intellectual Property Organization (WIPO) | International search |
| US11390291B2 | Cited by | United States of America | Applicant |
| EP2848487A1 | Cited by | European Patent Office (EPO) | Search report |
| US10475345B2 | Cited by | United States of America | Applicant |
| WO2015185258A1 | Cited by | World Intellectual Property Organization (WIPO) | International search |
| US11279347B2 | Cited by | United States of America | Applicant |
| CN106133751A | Cited by | China | Search report |
| CN104412311A | Cited by | China | Search report |
| EP0913751A1 | Cites | European Patent Office (EPO) | Search report |
| DE10027168A1 | Cites | Germany | Search report |
| DE102009050399A1 | Cites | Germany | Applicant |
| EP1405752A1 | Cites | European Patent Office (EPO) | Search report |
5 priority claims, no other members on record
Priority claims5
| Document | Office | Kind | Date |
|---|---|---|---|
| 102010021591 | Germany | A | |
| 102010021591 | Germany | A | |
| 102010021591 | Germany | – | |
| 102010021591 | – | – | – |
| DE20101021591 | – | – | – |
15 legal events, as the office reported them to INPADOC
Over the term
Point at a mark for the eventEvents
| Event | Code | |
|---|---|---|
| Application refused18R | 18R | |
| Information on the status of an ep patent application or granted ep patentGrantedSTATUS: THE APPLICATION HAS BEEN REFUSEDSTAA | STAA | |
| First examination report despatched17Q | 17Q | |
| Request for examination filed17P | 17P | |
| Designated contracting states (corrected)RBV | RBV | |
| Designated contracting statesAK | AK | |
| Request for extension of the european patentAX | AX | |
| Information provided on ipc code assigned before grantRIC1 | RIC1 | |
| Information provided on ipc code assigned before grantRIC1 | RIC1 | |
| Search report despatchedORIGINAL CODE: 0009013PUAL | PUAL | |
| Party data changed (applicant data changed or rights of an application transferred)RAP1 | RAP1 | |
| Party data changed (applicant data changed or rights of an application transferred)RAP1 | RAP1 | |
| Designated contracting statesAK | AK | |
| Request for extension of the european patentAX | AX | |
| Public reference made under article 153(3) epc to a published international application that has entered the european phaseORIGINAL CODE: 0009012PUAI | PUAI |
Numbers
- Publication
- 2390862
- Publication, DOCDB
- 2390862
- Publication, EPODOC
- EP2390862
- Application
- 11004224
- Application, DOCDB
- 11004224
- Application, EPODOC
- EP20110004224
Titles3
- German
- Verfahren zur Steuerung des Betriebs eines vollautomatischen, zur unabhängigen Fahrzeugführung ausgebildeten Fahrerassistenzsystems eines Kraftfahrzeugs und Kraftfahrzeug
- English
- Method for controlling the operation of a fully automatic driver assistance system of a motor vehicle for independent vehicle guidance and motor vehicle
- French
- Procédé de commande du fonctionnement d'un système d'assistance au conducteur totalement automatique développé pour guider un véhicule de manière indépendante destiné à un véhicule automobile et véhicule automobile
Classification
- CPC, 8
- B60W50/0205
- B60W30/0953
- B60W2050/0292
- B60W2050/0295
- B60W2520/10
- G08G1/22
- G08G1/166
- B60Y2302/05
- IPC, 6
- G08G1 16
- B60K31 00
- B60W30 00
- B60W30 095
- B60W50 02
- B60W50 029
Designated states40
- Contracting states, 38
- Albania
- Austria
- Belgium
- Bulgaria
- Switzerland
- Cyprus
- Czechia
- Germany
- Denmark
- Estonia
- Spain
- Finland
- France
- United Kingdom
- Greece
- Croatia
- Hungary
- Ireland
- Iceland
- Italy
- Liechtenstein
- Lithuania
- Luxembourg
- Latvia
and 14 moreShow fewer
- Monaco
- North Macedonia
- Malta
- Netherlands (Kingdom of the)
- Norway
- Poland
- Portugal
- Romania
- Serbia
- Sweden
- Slovenia
- Slovakia
- San Marino
- Türkiye
- Extension states, 2
- Bosnia and Herzegovina
- Montenegro