US 11,745,748 B2
Method and device for operating an automatically driving vehicle
Tobias Kain, Wolfsburg (DE); Julian-Steffen Müller, Hannover (DE); Maximilian Wesche, Edemissen (DE); Hendrik Decke, Braunschweig (DE); Fabian Plinke, Hamburg (DE); Andreas Braasch, Wuppertal (DE); Johannes Heinrich, Cologne (DE); and Timo Horeis, Hamburg (DE)
Assigned to VOLKSWAGEN AKTIENGESELLSCHAFT, Wolfsburg (DE)
Filed by Volkswagen Aktiengesellschaft, Wolfsburg (DE)
Filed on Jan. 14, 2021, as Appl. No. 17/148,871.
Claims priority of application No. 10 2020 200 458.7 (DE), filed on Jan. 15, 2020; and application No. 10 2020 203 419.2 (DE), filed on Mar. 17, 2020.
Prior Publication US 2021/0213964 A1, Jul. 15, 2021
Int. Cl. B60W 50/023 (2012.01); B60W 50/02 (2012.01); B60W 60/00 (2020.01)
CPC B60W 50/023 (2013.01) [B60W 50/0205 (2013.01); B60W 60/007 (2020.02); B60W 60/0015 (2020.02)] 20 Claims
OG exemplary drawing
 
1. A method for operating an automatically driving vehicle, comprising:
executing active software application instances according to a specified configuration over more than two computational nodes, forming a distributed computing setup, wherein the specified configuration provides predefined redundancy conditions and/or predefined segregation conditions with respect to the distributed computing setup;
monitoring the active application instances for a fault;
determine a fault in one of the active application instances;
in response to determining the fault, selectively switching a functionality of the active application instance having the fault to at least one redundant software application instance being executed on the computational nodes and reconfiguring the specified configuration to restore predefined redundancy conditions and/or predefined segregation conditions;
determining a safe state upon at least one of the following conditions:
one or more specified redundancy conditions cannot be met by the reconfiguration,
at least one segregation condition cannot be met by the reconfiguration,
a specified time for reconfiguration is exceeded, and
an unrecoverable malfunction has been recognized; and
in response to the safe state being determined, planning and executing an emergency trajectory.