Embodiments of the present disclosure relate generally to operating autonomous driving vehicles. More particularly, embodiments of the disclosure relate to adaptive autonomous braking actions for autonomous vehicles.
Vehicles operating in an autonomous mode (e.g., driverless) can relieve occupants, especially the driver, from some driving-related responsibilities. When operating in an autonomous mode, the vehicle can navigate to various locations using onboard sensors, allowing the vehicle to travel with minimal human interaction or in some cases without any passengers.
Brake control is a critical operation in autonomous driving. Deceleration/pressure requests from the autonomous driving system (ADS) should be delivered to a brake system without faults.
Embodiments of the disclosure are illustrated by way of example and not limitation in the figures of the accompanying drawings in which like references indicate similar elements.
Various embodiments and aspects of the disclosures will be described with reference to details discussed below, and the accompanying drawings will illustrate the various embodiments. The following description and drawings are illustrative of the disclosure and are not to be construed as limiting the disclosure. Numerous specific details are described to provide a thorough understanding of various embodiments of the present disclosure. However, in certain instances, well-known or conventional details are not described in order to provide a concise discussion of embodiments of the present disclosures.
Reference in the specification to “one embodiment” or “an embodiment” means that a particular feature, structure, or characteristic described in conjunction with the embodiment can be included in at least one embodiment of the disclosure. The appearances of the phrase “in one embodiment” in various places in the specification do not necessarily all refer to the same embodiment.
A controller area network (CAN) bus is a vehicle bus standard designed to allow microcontrollers and devices (e.g., electronic control units (ECUs)) communicate with one another without a host computer. CAN is based on a messaging protocol, designed to multiplex electrical wiring within an automobile. For each device, the data in a frame is transmitted serially and in a way that if more than one device transmits at the same time, the device with the highest priority can continue to transmit while the other devices fall back. The transmitted frames are received by all devices, including the transmitting device.
A vehicle can have one or more CAN buses. For example, CAN buses can be dedicated to certain vehicle domains, e.g., infotainment CANs, vehicle control CANs, chassis domain CANs. CAN buses can also be categorized for different speeds (e.g., high speed CAN, low speed CAN), etc. CAN buses can also be designed as redundant components for backup purposes.
With the development of drive-by-wire systems, CAN buses can be used for communications between the different drive-by-wire systems and an autonomous driving system of the vehicle. There is a need to perform failure fallback braking when the different drive-by-wire systems detect CAN buses malfunctions or a lost of communication of the CAN buses is detected.
Furthermore, when a brake is applied, a single deceleration request may not result in the best of neither brake performance robustness, driver comfortable, or braking speed. An adaptive braking scheme according to various driving scenario can balance the brake performance robustness, driver comfortable, and braking speed.
Moreover, when a redundant chassis domain controller (e.g., a redundant drive by wire system) is used for an ADS, the ADS will activate the redundant DBW system if the primary DBW system fails. However, since that the ADS defaults to use the primary DBW system, the life of the primary DBW system is shorten if the primary DBW is strenuously used. When the redundant DBW system is not activated for a prolong period of time, the redundant DBW may not function as intended. There is a need to alternate between the primary and the redundant DBW systems even when the primary DBW system is operational to ensure the redundant DBW operates as intended and to prolong the life of the primary DBW system.
According to some embodiments, a system performs a failure fallback brake mechanism when the system detects that the communication channels of a primary and a secondary controller area network (CAN) is malfunctioning.
According to a first aspect, a system determines a signal fault at a communication bus of an autonomous driving vehicle (ADV). In response to determining the signal fault, the system sends a brake pre-charge command to a brake system of the ADV to pre-charge a brake of the ADV. The system determines a preset tolerance time to validate the signal fault. In response to a time elapse of the preset tolerance time, the system validates the signal fault at the communication bus or determine a signal fault at another communication bus. In response to validating the signal fault at the communication bus or determining the signal fault at the another communication bus, the system sends a brake command to the brake system of the ADV to engage brakes for the ADV.
According to a second aspect, a system determines selection parameters to apply an adaptive braking scheme for an autonomous driving vehicle (ADV). The system determines a brake mode based on the selection parameters using a driving scenario mapping table. In response to determining that a brake is to be applied, the system applies a brake for the ADV according to the brake mode. The brake can be applied in three stages, where the three stages include a brake pre-charge stage, an increasing rate of deceleration stage, and a constant rate of deceleration stage.
According to a third aspect, a system determines activation parameters for an autonomous driving vehicle (ADV), where the activation parameters include historical usages of a primary brake system or a secondary brake system. In response to determining that a brake is to be applied, the system determines whether to activate a primary or a secondary brake system based on the activation parameters. The system sends an activation flag to activate the primary or the secondary brake system based on the determining whether to activate the primary or the secondary brake system. The system sends a brake command to the primary and the secondary brake system to activate either the primary or the secondary brake system according to the activation flag.
An ADV refers to a vehicle that can be configured to in an autonomous mode in which the vehicle navigates through an environment with little or no input from a driver. Such an ADV can include a sensor system having one or more sensors that are configured to detect information about the environment in which the vehicle operates. The vehicle and its associated controller(s) use the detected information to navigate through the environment. ADV 101 can operate in a manual mode, a full autonomous mode, or a partial autonomous mode.
In one embodiment, ADV 101 includes, but is not limited to, autonomous driving system (ADS) 110, vehicle control system 111, wireless communication system 112, user interface system 113, and sensor system 115. ADV 101 may further include certain common components included in ordinary vehicles, such as, an engine, wheels, steering wheel, transmission, etc., which may be controlled by vehicle control system 111 and/or ADS 110 using a variety of communication signals and/or commands, such as, for example, acceleration signals or commands, deceleration signals or commands, steering signals or commands, braking signals or commands, etc.
Components 110-115 may be communicatively coupled to each other via an interconnect, a bus, a network, or a combination thereof. For example, components 110-115 may be communicatively coupled to each other via a controller area network (CAN) bus. A CAN bus is a vehicle bus standard designed to allow microcontrollers and devices to communicate with each other in applications without a host computer. It is a message-based protocol, designed originally for multiplex electrical wiring within automobiles, but is also used in many other contexts.
Referring now to
Sensor system 115 may further include other sensors, such as, a sonar sensor, an infrared sensor, a steering sensor, a throttle sensor, a braking sensor, and an audio sensor (e.g., microphone). An audio sensor may be configured to capture sound from the environment surrounding the ADV. A steering sensor may be configured to sense the steering angle of a steering wheel, wheels of the vehicle, or a combination thereof. A throttle sensor and a braking sensor sense the throttle position and braking position of the vehicle, respectively. In some situations, a throttle sensor and a braking sensor may be integrated as an integrated throttle/braking sensor.
In one embodiment, vehicle control system 111 includes, but is not limited to, steering unit 201, throttle unit 202 (also referred to as an acceleration unit), and braking unit 203. Steering unit 201 is to adjust the direction or heading of the vehicle. Throttle unit 202 is to control the speed of the motor or engine that in turn controls the speed and acceleration of the vehicle. Braking unit 203 is to decelerate the vehicle by providing friction to slow the wheels or tires of the vehicle. Note that the components as shown in
Referring back to
Some or all of the functions of ADV 101 may be controlled or managed by ADS 110, especially when operating in an autonomous driving mode. ADS 110 includes the necessary hardware (e.g., processor(s), memory, storage) and software (e.g., operating system, planning and routing programs) to receive information from sensor system 115, control system 111, wireless communication system 112, and/or user interface system 113, process the received information, plan a route or path from a starting point to a destination point, and then drive vehicle 101 based on the planning and control information. Alternatively, ADS 110 may be integrated with vehicle control system 111.
For example, a user as a passenger may specify a starting location and a destination of a trip, for example, via a user interface. ADS 110 obtains the trip related data. For example, ADS 110 may obtain location and route data from an MPOI server, which may be a part of servers 103-104. The location server provides location services and the MPOI server provides map services and the POIs of certain locations. Alternatively, such location and MPOI information may be cached locally in a persistent storage device of ADS 110.
While ADV 101 is moving along the route, ADS 110 may also obtain real-time traffic information from a traffic information system or server (TIS). Note that servers 103-104 may be operated by a third party entity. Alternatively, the functionalities of servers 103-104 may be integrated with ADS 110. Based on the real-time traffic information, MPOI information, and location information, as well as real-time local environment data detected or sensed by sensor system 115 (e.g., obstacles, objects, nearby vehicles), ADS 110 can plan an optimal route and drive vehicle 101, for example, via control system 111, according to the planned route to reach the specified destination safely and efficiently.
Server 103 may be a data analytics system to perform data analytics services for a variety of clients. In one embodiment, data analytics system 103 includes data collector 121 and machine learning engine 122. Data collector 121 collects driving statistics 123 from a variety of vehicles, either ADVs or regular vehicles driven by human drivers. Driving statistics 123 include information indicating the driving commands (e.g., throttle, brake, steering commands) issued and responses of the vehicles (e.g., speeds, accelerations, decelerations, directions) captured by sensors of the vehicles at different points in time. Driving statistics 123 may further include information describing the driving environments at different points in time, such as, for example, routes (including starting and destination locations), MPOIs, road conditions, weather conditions, etc.
Data collector 121 can collect usage/failure statistics 125 for ADV 101. Usage/failure statistics 125 may include usage information and/or failure information for the primary and/or secondary (redundant) systems of the ADV. For example, usage information can include how many times (and/or average of how many hours) either the primary or the second systems are used over a predetermined length of time. Failure information can include the warning indicators, which subsystems of the ADV indicates a failure/warning, corresponding levels of the failures, etc. The primary and/or secondary systems can be for the chassis domain controllers (drive-by-wire systems), computing systems (ADS) of the ADV, braking systems, steering systems, throttle systems, transmission systems, sensor systems, individually sensors, and/or power systems.
Based on driving statistics 123 and usage/failure statistics 125, machine learning engine 122 generates or trains a set of rules, algorithms, and/or predictive models 124 for a variety of purposes. In one embodiment, algorithms 124 may include a selection algorithm to select a brake mode to apply to ADV and an activation algorithm used to activate either primary system(s) or secondary (redundant) system(s) of the ADV.
Algorithms 124 can then be uploaded on ADVs to be utilized during autonomous driving in real-time.
Some or all of modules 301-309 may be implemented in software, hardware, or a combination thereof. For example, these modules may be installed in persistent storage device 352, loaded into memory 351, and executed by one or more processors (not shown). Note that some or all of these modules may be communicatively coupled to or integrated with some or all modules of vehicle control system 111 of
Localization module 301 determines a current location of ADV 300 (e.g., leveraging GPS unit 212) and manages any data related to a trip or route of a user. Localization module 301 (also referred to as a map and route module) manages any data related to a trip or route of a user. A user may log in and specify a starting location and a destination of a trip, for example, via a user interface. Localization module 301 communicates with other components of ADV 300, such as map and route data 311, to obtain the trip related data. For example, localization module 301 may obtain location and route data from a location server and a map and POI (MPOI) server. A location server provides location services and an MPOI server provides map services and the POIs of certain locations, which may be cached as part of map and route data 311. While ADV 300 is moving along the route, localization module 301 may also obtain real-time traffic information from a traffic information system or server.
Based on the sensor data provided by sensor system 115 and localization information obtained by localization module 301, a perception of the surrounding environment is determined by perception module 302. The perception information may represent what an ordinary driver would perceive surrounding a vehicle in which the driver is driving. The perception can include the lane configuration, traffic light signals, a relative position of another vehicle, a pedestrian, a building, crosswalk, or other traffic related signs (e.g., stop signs, yield signs), etc., for example, in a form of an object. The lane configuration includes information describing a lane or lanes, such as, for example, a shape of the lane (e.g., straight or curvature), a width of the lane, how many lanes in a road, one-way or two-way lane, merging or splitting lanes, exiting lane, etc.
Perception module 302 may include a computer vision system or functionalities of a computer vision system to process and analyze images captured by one or more cameras in order to identify objects and/or features in the environment of the ADV. The objects can include traffic signals, road way boundaries, other vehicles, pedestrians, and/or obstacles, etc. The computer vision system may use an object recognition algorithm, video tracking, and other computer vision techniques. In some embodiments, the computer vision system can map an environment, track objects, and estimate the speed of objects, etc. Perception module 302 can also detect objects based on other sensors data provided by other sensors such as a radar and/or LIDAR.
For each of the objects, prediction module 303 predicts what the object will behave under the circumstances. The prediction is performed based on the perception data perceiving the driving environment at the point in time in view of a set of map/route information 311 and traffic rules 312. For example, if the object is a vehicle at an opposing direction and the current driving environment includes an intersection, prediction module 303 will predict whether the vehicle will likely move straight forward or make a turn. If the perception data indicates that the intersection has no traffic light, prediction module 303 may predict that the vehicle may have to fully stop prior to enter the intersection. If the perception data indicates that the vehicle is currently at a left-turn only lane or a right-turn only lane, prediction module 303 may predict that the vehicle will more likely make a left turn or right turn respectively.
For each of the objects, decision module 304 makes a decision regarding how to handle the object. For example, for a particular object (e.g., another vehicle in a crossing route) as well as its metadata describing the object (e.g., a speed, direction, turning angle), decision module 304 decides how to encounter the object (e.g., overtake, yield, stop, pass). Decision module 304 may make such decisions according to a set of rules such as traffic rules or driving rules 312, which may be stored in persistent storage device 352.
Routing module 307 is configured to provide one or more routes or paths from a starting point to a destination point. For a given trip from a start location to a destination location, for example, received from a user, routing module 307 obtains route and map information 311 and determines all possible routes or paths from the starting location to reach the destination location. Routing module 307 may generate a reference line in a form of a topographic map for each of the routes it determines from the starting location to reach the destination location. A reference line refers to an ideal route or path without any interference from others such as other vehicles, obstacles, or traffic condition. That is, if there is no other vehicle, pedestrians, or obstacles on the road, an ADV should exactly or closely follows the reference line. The topographic maps are then provided to decision module 304 and/or planning module 305. Decision module 304 and/or planning module 305 examine all of the possible routes to select and modify one of the most optimal routes in view of other data provided by other modules such as traffic conditions from localization module 301, driving environment perceived by perception module 302, and traffic condition predicted by prediction module 303. The actual path or route for controlling the ADV may be close to or different from the reference line provided by routing module 307 dependent upon the specific driving environment at the point in time.
Based on a decision for each of the objects perceived, planning module 305 plans a path or route for the ADV, as well as driving parameters (e.g., distance, speed, and/or turning angle), using a reference line provided by routing module 307 as a basis. That is, for a given object, decision module 304 decides what to do with the object, while planning module 305 determines how to do it. For example, for a given object, decision module 304 may decide to pass the object, while planning module 305 may determine whether to pass on the left side or right side of the object. Planning and control data is generated by planning module 305 including information describing how vehicle 101 would move in a next moving cycle (e.g., next route/path segment). For example, the planning and control data may instruct vehicle 101 to move 10 meters at a speed of 30 miles per hour (mph), then change to a right lane at the speed of 25 mph.
Based on the planning and control data, control module 306 controls and drives the ADV, by sending proper commands or signals to vehicle control system 111, according to a route or path defined by the planning and control data. The planning and control data include sufficient information to drive the vehicle from a first point to a second point of a route or path using appropriate vehicle settings or driving parameters (e.g., throttle, braking, steering commands) at different points in time along the path or route.
In one embodiment, the planning phase is performed in a number of planning cycles, also referred to as driving cycles, such as, for example, in every time interval of 50 milliseconds (ms). For each of the planning cycles or driving cycles, one or more control commands will be issued based on the planning and control data. That is, for every 50 ms, planning module 305 plans a next route segment or path segment, for example, including a target position and the time required for the ADV to reach the target position. Alternatively, planning module 305 may further specify the specific speed, direction, and/or steering angle, etc. In one embodiment, planning module 305 plans a route segment or path segment for the next predetermined period of time such as 5 seconds. For each planning cycle, planning module 305 plans a target position for the current cycle (e.g., next 5 seconds) based on a target position planned in a previous cycle. Control module 306 then generates one or more control commands (e.g., throttle, brake, steering control commands) based on the planning and control data of the current cycle.
Note that decision module 304 and planning module 305 may be integrated as an integrated module. Decision module 304/planning module 305 may include a navigation system or functionalities of a navigation system to determine a driving path for the ADV. For example, the navigation system may determine a series of speeds and directional headings to affect movement of the ADV along a path that substantially avoids perceived obstacles while generally advancing the ADV along a roadway-based path leading to an ultimate destination. The destination may be set according to user inputs via user interface system 113. The navigation system may update the driving path dynamically while the ADV is in operation. The navigation system can incorporate data from a GPS system and one or more maps so as to determine the driving path for the ADV.
Brake mode selection module 308 can determine statuses for the primary/secondary ADS, the primary/secondary chassis domain controllers, and driving statistics to select a brake mode from a mapping table. The brake mode selection of brake mode selection module 308 is further detailed in
Secondary system activation module 309 can gather usage/failure statistics of different primary and secondary systems of the ADV 101. Using the usage/failure statistics, and driving statistics, secondary system activation module 309 can activate either the different primary or the secondary systems of the ADV. By activating the secondary systems even when the primary systems are operational, the useful life of the primary systems can be extended and the likelihood of failure of the secondary systems can be mitigated. The activation by secondary system activation module 309 is further detailed in
Vehicle controls are divided into chassis, body, and powertrain domains. Powertrain domain relates to controls of engine and transmission of a vehicle. Body domain relates to controls of windows, doors, mirrors adjustment, seat adjustment, ventilation, heating etc. Chassis domain relates to controls of the brakes, throttle, and/or steering for vehicle stability and dynamics.
A chassis domain control system 410, as part of vehicle control system 111 of
Referring to
Referring to
With the development of automobile intelligence, the chassis of traditional vehicles are modified by wire to be suitable for automatic driving, e.g., drive-by-wire systems. Some examples of drive-by-wire systems include steering by wire, braking by wire, shift (transmission) by wire, oil control valve and suspension by wire, etc. Steering by wire and braking by wire are critical vehicle controls and are typically designed with redundancy.
In some embodiments, chassis domain controllers 411-413 include respective drive-by-wire (DBW) units 1-2. In some embodiments, brake, steering, and throttle units 421-443 include corresponding brake-by-wire, steering-by-wire, and/or throttle-by-wire systems. In some embodiments, brake, steering, and throttle units 421-443 include the conventional hydraulic brake system, a steering column for steering, and a direct mechanical linkage for throttle.
Referring to
In one embodiment, signal fault brake module 500 includes failure determiner submodule 501, brake pre-charge submodule 503, time tolerance determiner submodule 505, time elapse determiner submodule 507, brake release submodule 509, and braking submodule 511. Failure determiner submodule 501 can determine a failure has occurred on a communication bus. For example, submodule 501 can detect a failure mode, error code or a communication disconnect for a primary CAN bus or a secondary CAN bus, such as primary CAN bus 461 or secondary CAN bus 463 of
Time tolerance determiner submodule 505 can determine a time tolerance to valid a failure. The tolerance time can be preset by the ADS and can represent a time threshold to ascertained that a failure is not intermittent. That is, the failure is validated when the failure still exists over a period of the tolerance time. An example of a tolerance time can be 300 milliseconds. For this example, if an error had occurred at reference time=Oms (milliseconds) and each cycle the error is detected thereafter, then the error is ascertained/validated at time=300 ms. The failure validation can cause the ADS to perform error mitigation tasks. In another example, if an error had occurred at time=Oms (milliseconds) and the error is mitigated at time=100 ms the failure is said to be invalidated at time=100 ms. If the failure reappeared at time=140 ms and lasts until time=440 ms, the failure is validated only at time=440 ms since a count of the tolerance time is restarted at time=140 ms and the failure lasted over the tolerance time of 300 ms.
Time elapse determiner submodule 507 can determine a time elapse since a failure has been detected for failure validation. Brake release submodule 509 can release the brakes if the failure is invalidated. Braking submodule 511 can apply the brakes if a failure is validated. Note that any of submodules 501-511 can be integrated as an integrated module and can be implemented in software or hardware.
Although a failure fallback brake mechanism can be used for a brake-by-wire system, the failure fallback brake mechanism can also be used for a hydraulic brake system.
Primary hydraulic braking system 421 can include a front-axle brake line 603 and a rear-axle brake line 605 for supplying brake hydraulic fluid (or brake fluids) respectively to wheel brake apparatuses 651 and 653 at the front wheels and wheel brake apparatuses 655 and 657 at the rear wheels. The brake fluids can transfer the physical motion asserted by an operator on the brake pedals to the wheel brake apparatuses. Example wheel brake apparatuses include caliper/disc pads and rotors, and/or brake drums and rotors.
Two brake lines 603, 605 can be connected to a shared brake master cylinder 607 that is supplying the brake fluids via a fluid reservoir 609. Brake master cylinder 607 can include a piston 615 that can be actuated by an operator via brake pedal 611 to force brake fluids inside master cylinder 607 down lines 603-605 towards wheel brake apparatuses 651-657. A pedal travel distance of brake pedal 611 can be measured by a pedal travel sensor 613. In one embodiment, a brake booster 612 is coupled between master cylinder 607 and brake pedal 611 to assist the actuation force of the operator. For example, brake booster 612 can detect a pedal travel distance using pedal travel sensor 613 and drive a motor (not shown) to electronically actuate piston 615. In one embodiment, brake booster 612 can be operated electronically by ADS 110 to apply the brakes via brake commands.
The flow of the brake fluids supplied by master cylinder 607 can be controlled to front or rear wheels by inlet valves 617-619. The supplied brake fluids at the front or rear wheels can be further controlled to individual wheels by respective inlet valves 621-627. The supplied hydraulic fluid can return to fluid reservoir 609 via respective outlet valves 631-637.
In one embodiment, primary hydraulic braking system 421 includes slave cylinder 641. Slave cylinder 641 can be electronically operated by motor 643 to actuate piston 645 in slave cylinder 641 to force brake hydraulic fluid to flow to fluid lines 603-605 and toward wheel brake apparatuses 651-657. In one embodiment, slave cylinder 641 can be operated electronically by ADS 110 to apply the brakes via brake commands. In some embodiments, a chassis domain controller, such as chassis domain controllers (e.g., DBW 1 or DBW 2) 411-413 of
In one embodiment, primary hydraulic braking system 421 includes pressure sensors 601-602 at master cylinder lines and slave cylinder lines to sensor the pressures at the respective lines. The sensed pressure values can be used as feedback signals to control the brakes.
Referring to
In one embodiment, secondary hydraulic brake system 423 includes motor 661 and pressure sensor 663. Motor 661 can pulse pump brake fluids to the wheel apparatus. In one embodiment, motor 661 can accumulate brake fluids from tank reservoir 609 to an accumulator (not shown) to supply brake fluids to wheel brake apparatuses 651-657. In one embodiment, motor 661 can be operated electronically by ADS 110 to apply the brakes via brake commands. In one embodiment, a chassis domain controller (CDC), such as CDCs (DBW 1 or DBW 2) 411-413 of
As shown in
As shown in
For example, for the first stage, to minimize delay period 705, a brake pre-charge command can be introduced at the primary/secondary ADS, MCU, and/or primary/secondary CDC. For example, the brake pre-charge command can pre-charge a piston at the master/slave cylinders for the primary brake system or accumulate hydraulic fluids for the secondary brake system. The pre-charge command actuates the disc/caliper pads to close a distance between the pads and the rotor at the wheel brake apparatus.
In one embodiment, the brake pre-charge command can cause a brake pad to move within a predetermined threshold distance to a corresponding rotor. In one embodiment, the brake pre-charge command includes a brake distance travel command, a brake hydraulic pressure command, or a deceleration command. For example, the brake pre-charge command includes a pressure request to apply 0.05 MPA of pressure at the hydraulic fluid over a predetermined period, e.g., 100 ms, or brake pre-charge command can include a pedal travel distance request to apply 0.5 mm of pedal travel distance over 100 ms, or brake pre-charge command can include a deceleration request to deceleration by 0.01*g m/s{circumflex over ( )}2 over 100 ms. Here, the applied brake pre-charge command would not noticeably slow down the vehicle. Rather, the applied brake pre-charge command pre-charges the brake systems to reduce a response time of the brakes if the brakes need to be applied.
In one embodiment, the brake pre-charge command can be a customized brake signal that includes a command flag, a command value, and a command duration. For example, the command flag can flag if the command is a pressure request, a pedal travel distance request, or a deceleration request. The command value can be the corresponding request value, and the command duration can be a time duration to apply the pre-charge command. An example brake pre-charge command can be {flag: pressure, value: 0.05, duration: 100 ms}.
For the second stage, to improve a comfort level for the operator, the tracking response of the A_req should be capped to a predetermined slope, e.g., dA_req/dt is less than a predetermined threshold. For example, dA_req/dt can be capped to −50 m/s{circumflex over ( )}3. Here, a tracking command can be introduced to the ADS, MCU, and/or CDC for a dA_req/dt command. In some embodiments, the dA_req/dt command can be converted to a dynamic deceleration request by the MCU and/or CDC.
For the third stage, the request command can correspond to a constant deceleration, such as −0.6 m/s{circumflex over ( )}2. In some embodiments, a three-stage brake command can include brake commands representative of the first, second, and third stages. In another embodiment, a two-stage brake command can be applied as two stages, a first stage for the brake pre-charge (e.g., first stage) and a second stage corresponding to the tracking and steady brake commands.
For CAN buses failures, a brake command can be automatically performed by processing logic which may include software, hardware, or a combination thereof. For example, a brake command can be issued by a CDC, e.g., CDC 411 or 413 of
At block 901, processing logic determines a signal fault at a communication bus (e.g., primary or secondary CAN buses) of an autonomous driving vehicle (ADV).
At block 903, in response to determining the signal fault, processing logic sends a brake pre-charge command to a brake system of the ADV to pre-charge a brake of the ADV.
At block 905, processing logic determine a preset tolerance time to validate the signal fault.
At block 907, in response to a time elapse of the preset tolerance time, processing logic validates the signal fault at the communication bus (e.g., primary or secondary CAN buses) or determining a signal fault at another communication bus (e.g., secondary or primary CAN buses).
At block 909, in response to validating the signal fault at the communication bus or determining the signal fault at the another communication bus, processing logic sends a brake command to the brake system of the ADV to engage brakes for the ADV.
The brake command can be a deceleration request or can correspond to a multi-stage command (e.g., tracking and steady brakes).
In one embodiment, processing logic determines that the signal fault at the communication bus is invalidated within the preset tolerance time. In response to determining that the signal fault at the communication bus is invalidated within the preset tolerance time, processing logic sends a brake recovery command to the brake system of the ADV to release the brakes.
In one embodiment, the brake system is a primary brake system or a secondary brake system of the ADV, where the secondary brake system includes an anti-lock brake system.
In one embodiment, the communication bus includes a primary controller area network (CAN) or a second CAN bus, where a communication channel of the primary or secondary CAN bus is used by an autonomous driving system (ADS) of the ADV to communication with a chassis domain controller of the ADV.
In one embodiment, the signal fault indicates a communication error or a lost of communication for one or more communication channels of the communication bus.
In one embodiment, the sent brake pre-charge command causes a brake pad to move within a threshold distance to a corresponding rotor.
In one embodiment, the brake pre-charge command comprises a brake distance travel command, a brake hydraulic pressure command, or a deceleration command.
In one embodiment, the brake pre-charge command includes a command flag indicating the type of command value, a command value indicating a value for a pressure or a value for a master cylinder travel distance or a deceleration value, or a command status duration indicating a duration of validity of the command.
In one embodiment, the brake command includes a first deceleration request value corresponding to a first predetermined time period and a second deceleration request value corresponding to a second predetermined time period to minimize overshoot of deceleration from applying the brakes, where the first deceleration request value is greater than the second deceleration request value.
In one embodiment, the brake system is controlled by a drive-by-wire system.
Referring to
In one embodiment, as shown in mapping table 1300 of
Referring to scenario 51 in
Referring to scenario 50 in
Referring to scenario 49 in
Referring to scenarios 1-48 in
For example, in scenario 5, primary ADS has failure level F3-F4 indicating corresponding AD operations are affected; secondary ADS has failure level F0-F2 indicating corresponding AD operations are not affected; primary CDC has failure level F0-F2 indicating corresponding AD operations are not affected. Here, regardless of the status of secondary CDC, a brake signal can be propagated at least by secondary ADS to primary CDC. In this case, ADV can detect that a vehicle is ahead and is braking sharply, a pedestrian is close by (e.g., within a predetermined distance) and is in front of the ADV, and a vehicle is close by (e.g., within a predetermined distance) following the ADV. According to mapping table 1300, in scenario 5, ADV selects the sharp braking mode (because there is a vehicle ahead and is braking sharply). E.g., primary ADS would issue the three-stage brake command for sharp braking.
Regarding scenario 51, at block 1351 of
Regarding scenario 50, at block 1353, if S CDC status is not failure level F3/F4, processing logic proceed to block 1357. At block 1357, processing logic determines status for P ADS. If P ADS status is failure level F3 or F4, processing logic proceed to block 1359. At block 1359, processing logic determines status for S ADS. If S ADS status is failure level F3 or F4, processing logic proceed to block 1361 and determines that a sharp brake command is to be issued by microcontroller MCU 405, and/or any of CDC module 411 or 413. In one embodiment, the sharp brake command is issued by a brake drive-by-wire (DBW) of a CDC module.
Regarding scenario 49, at block 1351, If P CDC status is not failure level F3 or F4 (e.g., F0 or F1 or F2), regardless of the status of S CDC (e.g., F0/F1/F2/F3/F4), processing logic proceeds to block 1363. At block 1363, processing logic determines status for P ADS. If P ADS status is failure level F3 or F4, processing logic proceeds to block 1365. At block 1365, processing logic determines status for S ADS. If S ADS status is failure level F3 or F4, processing logic proceeds to 1367. At block 1367, processing logic determines that a sharp brake command is to be issued by microcontroller MCU 405, and/or any of CDC module 411 or 413. In one embodiment, the sharp brake command is issued by a brake drive-by-wire (DBW) of a CDC module.
Each of scenarios 1-48 proceeds to block K that continues to
Referring to
At block 1375, processing logic determines if an obstacle pedestrian is detected in front of ADV 101. If the obstacle pedestrian is in front and close by (e.g., within a predetermined threshold distance to ADV 101), processing logic proceeds to block 1377, and determines that a sharp brake command is to be issued. The command can be issued from any of primary ADS 401, secondary ADS 403, microcontroller MCU 405, and/or any of CDC modules 411 or 413. In one embodiment, the sharp brake command is issued by a brake drive-by-wire (DBW) of a CDC module.
Regarding scenarios 3-4; 15-16; 27-28; and 39-40, at block 1375, if the obstacle pedestrian is detected in front and faraway (e.g., exceed a predetermined threshold distance to ADV 101), processing logic proceeds to block 1379, and determines that a gradual brake command is to be issued. The command can be issued from any of primary ADS 401, secondary ADS 403, microcontroller MCU 405, and/or any of CDC modules 411 or 413. In one embodiment, the sharp brake command is issued by a brake drive-by-wire (DBW) of a CDC module.
Regarding scenarios 5-8; 17-20; 29-32; and 41-44, at block 1373, if the obstacle vehicle is detected in front and is braking sharply (e.g., detected that the obstacle deceleration is within a predetermined threshold relative to ADV 101), processing logic proceeds to block 1381. At block 1381, processing logic determines that a sharp brake command is to be issued. The command can be issued from any of primary ADS 401, secondary ADS 403, microcontroller MCU 405, and/or any of CDC modules 411 or 413.
Regarding scenarios 9-10; 21-22; 33-34; and 45-46, at block 1373, if the obstacle vehicle is detected to be in front and is braking gradually (e.g., detected that the obstacle deceleration exceeds a predetermined threshold relative to ADV 101), processing logic proceeds to block 1383.
At block 1383, processing logic determines if an obstacle pedestrian is detected in front of ADV 101. If the obstacle pedestrian is in front and close by (e.g., within a predetermined threshold distance to ADV 101), processing logic proceeds to block 1387, and determines that a sharp brake command is to be issued. The command can be issued from any of primary ADS 401, secondary ADS 403, microcontroller MCU 405, and/or any of CDC modules 411 or 413. In one embodiment, the sharp brake command is issued by a brake drive-by-wire (DBW) of a CDC module.
Regarding scenarios 11-12; 23-24; 35-36; and 47-48, at block 1383, if the obstacle pedestrian is detected in front and faraway (e.g., exceed a predetermined threshold distance), processing logic proceeds to block 1389, and determines that a gradual brake command is to be issued to the primary and secondary brake units 421-423 of ADV 101. The command can be issued from any of primary ADS 401, secondary ADS 403, microcontroller MCU 405, and/or any of CDC modules 411 or 413. In one embodiment, the sharp brake command is issued by a brake drive-by-wire (DBW) of a CDC module.
At block 1401, processing logic determines selection parameters to apply an adaptive braking scheme for an autonomous driving vehicle (ADV).
At block 1403, processing logic determines a brake mode based on the selection parameters using a driving scenario mapping table.
At block 1405, in response to determining that a brake is to be applied, processing logic applies a brake for the ADV according to the brake mode.
In one embodiment, the brake mode includes a gradual brake mode or a sharp brake mode.
In one embodiment, the selection parameters include a driving direction, presence of a vehicle at front of the ADV, distance to the vehicle at the front of the ADV, presence of a pedestrian at front of the ADV, distance to pedestrian, presence of a vehicle behind the ADV, or distance to the vehicle behind the ADV.
In one embodiment, the selection parameters include a status of an autonomous driving system (ADS) of the ADV.
In one embodiment, the selection parameters include a status of chassis domain controller of the ADV.
In one embodiment, the brake mode corresponds to brake commands applied in three stages, wherein the three stages include a brake pre-charge stage, an increasing rate of deceleration stage, and a constant rate of deceleration stage.
In one embodiment, the sharp brake mode corresponds to a pre-charge command corresponding to a first predetermined duration, an increasing rate of deceleration command corresponding to a first preset increasing rate of deceleration, or a constant rate of deceleration command corresponding to a first preset constant rate of deceleration.
In one embodiment, the gradual brake mode corresponds to a pre-charge command corresponding to the first predetermined duration, an increasing rate of deceleration command corresponding to a second preset increasing rate of deceleration, or a constant rate of deceleration command corresponding to the first preset constant rate of deceleration, wherein the first preset increasing rate of deceleration is great than the second preset increasing rate of deceleration.
In one embodiment, determining that a brake is to be applied includes determining the ADV has reached its destination, reached a traffic stop, or a vehicle in front of the ADV applied a brake.
In one embodiment, the autonomous driving system (ADS) of the ADV includes a primary ADS or a secondary ADS, wherein the secondary ADS is a redundant ADS.
Referring to
In one embodiment, the ADV can obtain driver/passenger status 1703 as the activation parameters. Example of the driver/passenger status 1703 can be a number of passengers onboard the ADV and whether there is an operator. In one embodiment, the ADV can obtain vehicle status 1705 as the activation parameters. Vehicle status can include a current speed of the vehicle, vehicle mass, health indicators (e.g., whether there are dashboard warning lights), and/or traction of the vehicle tire. In one embodiment, the ADV can obtain environmental status 1707 as the activation parameters. Environmental status 1707 can include current road friction, current weather conditions (raining, sunny, or snowing conditions, etc.), current slope steepness of the road, how many and/or types of obstacles are detected by imaging sensors of the ADV.
In one embodiment, the ADV can obtain failure data 1709 as the activation parameters. Failure data 1709 can indicate which systems are failing or a duration and error level associated with a previous failure. For example, the failing data can include dashboard warning indicators, sensor errors, software errors with the control/planning systems of the ADS, CAN bus error codes, CDC error codes, and/or failure/safety level codes as shown in the example scenarios 1-51 of
In one embodiment, ADV can select an activation algorithm from a plurality of algorithms to process the inputs 1701-1711. In an embodiment, the activation algorithm can be a weighted sum, where each category of inputs is multiplied by a respective weighting factor, e.g., W1-W6 and the sum of the outputs are compared with a predetermined threshold. If the weighted sum is greater than the predetermined threshold, a secondary system is activated. Else, the primary system is activated. In one embodiment, each input in a category of inputs have a different weighting factor. In one embodiment, the activation can be performed by the primary or secondary ADS in real-time, e.g., the primary system is switched over to the secondary system, or vice versa, when ADV is in a driving mode. In another embodiment, the activation occurs when ADV evaluates that it is safe to do so, e.g., when ADV detects that the ADV in a parking/neural transmission mode.
In one embodiment, process 1700 can be applied for each pair of primary and secondary subsystems/components to determine which of the primary/secondary subsystems/components would be activated. Each evaluation can be configured with a particular subset of inputs 1701-1711 relevant to the subsystem/component. The relevant subset of inputs can be preconfigured for each set of primary/secondary system/component. For example, to evaluate which of the primary/secondary brake units to activate, the inputs 1701-1711 can include: configuration requests from operator regarding a selection for the primary or secondary CDC, failure data regarding the primary/second brake units, warning indicators regarding brake fluids and/or brake pad conditions, how many passengers are onboard the ADV (e.g., detected by seatbelt detectors), vehicle weight status, condition of the road (rural, city, or highway), weather (raining, snowing, or sunny), and/or obstacles (vehicle in front, vehicle following behind, pedestrian crossing), etc. These inputs can be processed by a selection algorithm to activate the primary or the secondary brake unit.
In some embodiments, the plurality of activation algorithms can include an alternating algorithm. The alternating algorithm can alternatingly operate the primary or the secondary system at the start of the ADS of ADV. E.g., when the ADV engine is started/ADS system boots up. In one embodiment, the plurality of activation algorithms can include an algorithm to activate the primary subsystem or the secondary subsystem so each of the systems are operating, on average, a same number of operating hours.
In one embodiment, the plurality of activation algorithms can include an algorithm to activate the secondary subsystems for a minimum number of counts within a predetermined time period (e.g., a year).
Referring to
As depicted in
At block 2001, processing logic determines activation parameters for an autonomous driving vehicle (ADV), wherein the activation parameters include historical usages of a primary brake system or a secondary brake system.
At block 2003, in response to determining that a brake is to be applied, processing logic determines whether to activate a primary or a secondary brake system based on the activation parameters.
The determination can be performed in real-time when the ADV is in a driving mode or when the ADV is in a parking/neutral transmission mode. For example, the ADV can process the activation parameters with an activation algorithm to determine which system to activate.
At block 2005, processing logic sends an activation flag to activate the primary or the secondary brake system based on the determining whether to activate the primary or the secondary brake system.
For example, the activation flag can be sent to the CAN bus as an instruction to activate either the primary or the secondary brake system. The activation flag can include one or more bits in a bit map, each bit mapping to a primary/secondary sub-system for the activation.
At block 2007, processing logic sends a brake command to the primary and the secondary brake system to activate either the primary or the secondary brake system according to the activation flag. Here, at a command cycle, only one brake system (primary or secondary brake system) is active and can thus be triggered.
In one embodiment, the activation parameters include a plurality of safety factors including a count of passengers in the ADV, a safety status of an environment surrounding the ADV, or a vehicular status of the ADV.
In one embodiment, a safety status of the environment surrounding the ADV includes a traction of a road of the ADV, weather, or a slope of the road.
In one embodiment, the vehicle status of the ADV includes a current speed, a weight of the ADV, a health status of an autonomous driving system (ADS) of the ADV, or a health status of the primary or secondary brake system, or a tire traction of the ADV.
In one embodiment, the activation parameters further comprise a failure rate of an autonomous driving system (ADS) of the ADV.
In one embodiment, the activation parameters are inserted into a gain matrix to obtain a weighted sum value and whether to activate the primary or the secondary brake system is based on the weighted sum value.
In one embodiment, the secondary brake system is activated if the weighted sum value is greater than a predetermined threshold and the primary brake system is activated if the weighted sum value is less than or equal to the predetermined threshold.
In one embodiment, activating the primary or secondary brake systems includes activating the primary or secondary chassis domain controller to issue the commands to either the primary or secondary brake system.
In one embodiment, activating the primary or secondary brake system includes activating the primary or secondary by-wire systems.
In one embodiment, the primary or secondary by-wire systems include a primary or a secondary steer by-wire system, a primary or a secondary throttle by-wire system, or a primary or a secondary transmission-by-wire system.
In one embodiment, the primary or secondary brake system includes a primary or a secondary brake by-wire system.
Note that some or all of the components as shown and described above may be implemented in software, hardware, or a combination thereof. For example, such components can be implemented as software installed and stored in a persistent storage device, which can be loaded and executed in a memory by a processor (not shown) to carry out the processes or operations described throughout this application. Alternatively, such components can be implemented as executable code programmed or embedded into dedicated hardware such as an integrated circuit (e.g., an application specific IC or ASIC), a digital signal processor (DSP), or a field programmable gate array (FPGA), which can be accessed via a corresponding driver and/or operating system from an application. Furthermore, such components can be implemented as specific hardware logic in a processor or processor core as part of an instruction set accessible by a software component via one or more specific instructions.
Some portions of the preceding detailed descriptions have been presented in terms of algorithms and symbolic representations of operations on data bits within a computer memory. These algorithmic descriptions and representations are the ways used by those skilled in the data processing arts to most effectively convey the substance of their work to others skilled in the art. An algorithm is here, and generally, conceived to be a self-consistent sequence of operations leading to a desired result. The operations are those requiring physical manipulations of physical quantities.
It should be borne in mind, however, that all of these and similar terms are to be associated with the appropriate physical quantities and are merely convenient labels applied to these quantities. Unless specifically stated otherwise as apparent from the above discussion, it is appreciated that throughout the description, discussions utilizing terms such as those set forth in the claims below, refer to the action and processes of a computer system, or similar electronic computing device, that manipulates and transforms data represented as physical (electronic) quantities within the computer system's registers and memories into other data similarly represented as physical quantities within the computer system memories or registers or other such information storage, transmission or display devices.
Embodiments of the disclosure also relate to an apparatus for performing the operations herein. Such a computer program is stored in a non-transitory computer readable medium. A machine-readable medium includes any mechanism for storing information in a form readable by a machine (e.g., a computer). For example, a machine-readable (e.g., computer-readable) medium includes a machine (e.g., a computer) readable storage medium (e.g., read only memory (“ROM”), random access memory (“RAM”), magnetic disk storage media, optical storage media, flash memory devices).
The processes or methods depicted in the preceding figures may be performed by processing logic that comprises hardware (e.g. circuitry, dedicated logic, etc.), software (e.g., embodied on a non-transitory computer readable medium), or a combination of both. Although the processes or methods are described above in terms of some sequential operations, it should be appreciated that some of the operations described may be performed in a different order. Moreover, some operations may be performed in parallel rather than sequentially.
Embodiments of the present disclosure are not described with reference to any particular programming language. It will be appreciated that a variety of programming languages may be used to implement the teachings of embodiments of the disclosure as described herein.
In the foregoing specification, embodiments of the disclosure have been described with reference to specific exemplary embodiments thereof. It will be evident that various modifications may be made thereto without departing from the broader spirit and scope of the disclosure as set forth in the following claims. The specification and drawings are, accordingly, to be regarded in an illustrative sense rather than a restrictive sense.