Double-domain cooperative system of automatic driving bus, operation domain controller and control method

By using the autonomous driving and operation domain controllers of the dual-domain collaborative system, the problems of computing power consumption, unstable command transmission, and chaotic data management in existing autonomous driving bus systems have been solved. This has enabled the independence of operational functions and safe and reliable command transmission, thereby improving system scalability and operational efficiency.

CN122053632APending Publication Date: 2026-05-15GUANGZHOU JIAOXIN INVESTMENT TECH CO LTD
View PDF 0 Cites 0 Cited by

Patent Information

Application Number
CN202610204940.5
Authority / Receiving Office
CN · China
Patent Type
Applications(China)
Current Assignee / Owner
Filing Date
2026-02-12
Publication Date
2026-05-15

AI Technical Summary

Technical Problem

In existing autonomous bus systems, operational functions rely on autonomous driving domain controllers, which leads to excessive computing resources, unstable command transmission, chaotic data management, and difficulty in achieving inter-domain isolation, direct command transmission, and plug-and-play equipment, thus hindering large-scale operation.

Method used

A dual-domain collaborative system is adopted, including an autonomous driving domain controller and an operations domain controller. Physical isolation and controlled communication are achieved through inter-domain secure communication units. Redundant vehicle-to-cloud communication links are set up. The operations domain controller performs command verification and device management, as well as hierarchical data storage and access control.

Benefits of technology

It improves computing power utilization, ensures driving safety, guarantees reliable transmission of operational instructions, enables plug-and-play devices, and facilitates secure hierarchical data sharing, thereby enhancing system scalability and operational efficiency.

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure CN122053632A_ABST
    Figure CN122053632A_ABST
Patent Text Reader

Abstract

The invention relates to the technical field of automatic driving, and particularly discloses a double-domain cooperative system, an operation domain controller and a control method of an automatic driving bus, and the system comprises an automatic driving domain controller, the operation domain controller and an inter-domain safety communication unit. Wherein an operation exclusive vehicle cloud communication link is established between the operation domain controller and the operation cloud platform and is used for receiving an operation instruction issued by the operation platform, executing an operation action and / or generating an operation controlled request; the inter-domain safety communication unit divides a state abstract channel sent by the automatic driving domain controller to the operation domain controller and an operation controlled request channel sent by the operation domain controller to the automatic driving domain controller; the state abstract channel is used for transmitting vehicle driving state information; the operation controlled request channel is used for transmitting an operation controlled request. According to the invention, dual-domain cooperative control of inter-domain physical isolation, reliable instruction direct connection and data grading security sharing can be realized.
Need to check novelty before this filing date? Find Prior Art

Description

Technical Field

[0001] This invention relates to the field of autonomous driving technology, and more specifically to a dual-domain collaborative system, an operation domain controller, and a control method for an autonomous bus. Background Technology

[0002] As a crucial component of intelligent transportation, autonomous buses must simultaneously meet two core requirements for large-scale commercial operation: driving safety and operational efficiency. This necessitates vehicles possessing reliable driving domain control capabilities and sophisticated operational domain management capabilities. The driving domain focuses on the accuracy of perception, localization, decision-making, planning, and chassis control, while the operational domain focuses on functions such as dispatch command execution, cabin service scheduling, equipment management, data retention, and multi-entity sharing.

[0003] In existing technologies, the operational functions of autonomous buses largely rely on autonomous driving domain controllers or third-party transfer platforms, which presents the following unavoidable technical drawbacks:

[0004] 1) Lack of an independent operational hub: Existing vehicles typically tightly couple operational functions to the autonomous driving domain controller (ADC), or simply stack them up using distributed third-party devices. The ADC is designed to ensure driving safety and real-time control, but it is not adept at handling multimedia interaction, decoupled device access, and complex cloud business logic. This architecture not only consumes valuable computing resources for autonomous driving, but also restricts the iterative upgrades of operational services to the version freeze of the autonomous driving system, making flexible changes difficult.

[0005] 2) Inefficient command delivery: In large-scale fleet operations, the cloud-based operations platform (dispatch center) needs to frequently issue non-driving operational commands. Due to the lack of a unified "brain" for connecting with operational business on the vehicle side, cloud commands often face problems such as long parsing links, inconsistent protocols, and unstable transmission, resulting in cloud commands failing to accurately and timely reach the in-vehicle equipment.

[0006] 3) Chaotic data and access control: Operational data and vehicle driving data are currently stored together. The lack of hierarchical management makes it easy for operators to infringe on the privacy of the car manufacturer's core driving data when they need to access the data, creating barriers to data sharing and hindering the possibility of optimizing operational efficiency through data-driven approaches.

[0007] Therefore, how to achieve dual-domain collaborative control with physical isolation between domains, reliable direct command transmission, plug-and-play equipment, and hierarchical secure data sharing to support the large-scale operation of autonomous buses is a problem that urgently needs to be solved by those skilled in the art. Summary of the Invention

[0008] In view of the above problems, the present invention proposes a dual-domain cooperative system, an operation domain controller and a control method for autonomous buses, so as to overcome the above problems or at least partially solve the above problems.

[0009] To achieve the above objectives, the present invention adopts the following technical solution: In a first aspect, the present invention provides a dual-domain collaborative system for autonomous driving buses, comprising: an autonomous driving domain controller, an operation domain controller, and an inter-domain secure communication unit disposed between the autonomous driving domain controller and the operation domain controller; The operation domain controller establishes a dedicated vehicle-cloud communication link with the operation cloud platform to receive operation instructions issued by the operation platform, perform trusted verification on the operation instructions, and then execute operation actions and / or generate operation controlled requests through the local instruction scheduler. The inter-domain secure communication unit is configured to: divide the system into a status summary channel (sent from the autonomous driving domain controller to the operations domain controller) and an operations controlled request channel (sent from the operations domain controller to the autonomous driving domain controller), and perform whitelist filtering, security verification, rate limiting, and fault isolation on the inter-domain messages; the status summary channel is used to transmit vehicle driving status information; the operations controlled request channel is used to transmit the operations controlled request, realizing the coordination between operational services and driving status; the operations controlled request is a predefined set of operations-related request messages and does not contain driving-related execution commands; The operations domain controller is also configured to store operations data locally in an encrypted manner and to perform hierarchical authorization sharing and access auditing of operations data based on the permissions of the ownership subject.

[0010] Furthermore, the operations domain controller also connects to cabin operations equipment through a standardized interface matrix, and performs device identification, driver matching, capability information registration, and service binding on the connected cabin operations equipment based on the device abstraction layer; if the connected cabin operations equipment cannot find a driver, the cabin operations equipment is marked as pending authorization or pending adaptation, and will not participate in subsequent service binding, and the operations domain controller is remotely controlled by the operations platform to add the driver for the cabin operations equipment.

[0011] Furthermore, the standardized interface matrix includes one or more of the following: CAN, CAN-FD interface, RS485 interface, Ethernet interface, USB interface, Discrete Input / Output (DI / DO) interface, and audio interface.

[0012] Furthermore, the dedicated vehicle-to-cloud communication link includes a primary communication channel and a backup communication channel. The operation domain controller automatically switches between the primary communication channel and the backup communication channel based on the link health detection results. The link health detection generates a link quality evaluation based on at least one or more indicators, such as round-trip latency, packet loss rate, and number of consecutive communication failures. When the link quality evaluation of the primary communication channel does not meet a preset threshold, it triggers an automatic switch to the backup communication channel.

[0013] Furthermore, the local instruction scheduler queues and executes the operational instructions according to a preset priority, which is set as emergency > operational scheduling > passenger service. The emergency instructions include emergency stop coordination requests, emergency assistance reports, and instructions for handling abnormal events in the carriage. The operational scheduling instructions include instructions for temporary station changes, instructions for issuing operational announcements, instructions for updating station sequence information, instructions for adjusting operating hours, and instructions for issuing promotional materials. The passenger service instructions include instructions for adjusting voice speed, instructions for switching display screen content, instructions for adjusting air conditioning temperature, instructions for adjusting cabin lighting brightness, and instructions for updating ticketing rules.

[0014] Furthermore, the operation domain controller is also configured to switch to the backup communication channel to transmit emergency commands issued by the operation cloud platform when the main communication channel is unavailable, and to perform offline caching of operation scheduling and passenger service commands. After the main communication channel is restored to normal within a preset time, the cached commands are transmitted through the main communication channel, and an execution receipt is resent to the operation cloud platform. If the main communication channel is not restored to normal within the preset time, the cached commands are transmitted through the backup communication channel.

[0015] Furthermore, the operation domain controller is also configured with a data storage unit, a key management unit, a policy engine unit, and an auditing unit; The data storage unit is used to divide the operational data into multiple data layers according to the ownership entity, and each data layer is bound to the corresponding ownership entity. The key management unit generates and encrypts independent keys for different data layers, and the keys are rotated according to a fixed period. When the rights of the owner expire, the data sharing protocol is terminated, or there is a risk of key leakage, the key revocation process is triggered. The policy engine unit is used to confirm the access permissions of the current accessing subject after receiving a data access request and generate an access decision result; the key management unit sends the corresponding key to the current accessing subject according to the access decision result. The audit unit generates tamper-proof audit logs for all access behaviors to operational data.

[0016] Furthermore, the tamper-proof audit log is encrypted using chain hashing and digital signatures, and records at least the access subject, access time, access data type, access result, and instruction execution status information.

[0017] Secondly, the present invention provides an operation domain controller, characterized in that it is applied in a dual-domain cooperative system for autonomous buses, comprising: The communication module is used to establish a dedicated vehicle-to-cloud communication link and receive operational instructions from the operational cloud platform. It supports switching between primary and backup communication channels and link health detection. The security verification module is used to perform trusted verification on operational instructions; The instruction scheduling module is used to prioritize and execute operational actions and / or generate operational controlled requests for operational instructions that have passed the trust verification, and to cache the corresponding operational instructions offline when the dedicated vehicle-cloud communication link fails. The equipment management module is used to access cabin operation equipment through a standardized interface matrix, perform equipment identification, driver matching, capability information registration and business binding, and manage the adaptation status of cabin operation equipment. The data management module is used to encrypt and store operational data locally, and to perform hierarchical authorization sharing and access auditing of operational data based on the ownership subject's permissions.

[0018] Thirdly, the present invention provides a dual-domain cooperative control method for autonomous buses, applicable to the dual-domain cooperative system of autonomous buses as described above, comprising the following steps: A primary and backup redundant vehicle-to-cloud communication link is established between the operation domain controller and the operation cloud platform. An inter-domain secure communication unit is set between the operation domain controller and the driving domain controller, and the inter-domain secure communication unit is divided into a status summary channel and an operation controlled request channel. The operation domain controller performs link health checks on the primary communication channel and the backup communication channel, and switches to the backup communication channel when the link quality evaluation of the primary communication channel does not meet a preset threshold. The operation domain controller receives operation instructions issued by the operation cloud platform through the dedicated vehicle-cloud communication link and performs a trust verification on the operation instructions. If the verification fails, it refuses to execute and generates an alarm log; if the verification passes, it executes the operation action and / or generates an operation controlled request according to a preset priority through the local instruction scheduler. The status summary channel and the operation-controlled request channel respectively perform whitelist filtering, security verification, rate limiting, and fault isolation on inter-domain messages; The driving domain controller sends vehicle driving status information to the operations domain controller through the status summary channel; the operations domain controller sends an operations control request to the driving domain controller through the operations control request channel. When cabin operation equipment is connected, the operation domain controller performs equipment identification, driver matching, capability information registration and service binding for the connected cabin operation equipment; The operation domain controller performs local encrypted storage of operation data and performs hierarchical authorization sharing and access auditing of operation data based on the ownership subject's permissions.

[0019] As can be seen from the above technical solution, compared with the prior art, the present invention has the following beneficial effects: 1. This invention constructs a dual-domain collaborative architecture consisting of an operations domain controller and a driving domain controller. The driving domain controller focuses on the core functions of driving control and does not participate in the generation and execution of operational instructions. The operations domain controller is independently deployed in the cockpit domain as the operations hub, integrating full-stack operational functions such as communication, verification, scheduling, equipment management, and data management. The two control domains operate independently without interfering with each other, which can significantly improve computing power and ensure driving safety.

[0020] 2. The inter-domain secure communication unit of this invention provides controlled communication based on physical isolation between the autonomous driving domain controller and the operation domain controller. It is divided into independent status summary channels and operation controlled request channels. A whitelist filtering mechanism strictly limits the types of messages that can be transmitted, explicitly prohibiting the transmission of core driving control commands such as steering and braking. This provides dual protection for driving safety from both physical and logical levels, reducing the risk of mutual interference. Simultaneously, rate limiting and anomaly isolation mechanisms are set up. When abnormal messages are detected, the channel can be quickly blocked or a degraded mode can be entered to prevent the spread of anomalies, further ensuring driving safety. The responsibility boundaries between operation and driving are clearly defined, facilitating accident tracing.

[0021] 3. This invention sets up a dedicated vehicle-to-cloud communication link with primary and backup redundancy and performs link health checks, so that when the primary link fails, it automatically switches to the backup link to ensure uninterrupted transmission of operational instructions, reduce latency, and perform trusted verification on received operational instructions to prevent the execution of illegal, timed-out, and duplicate instructions, thus ensuring operational safety. At the same time, when the link is interrupted, the offline caching function ensures operational continuity, solving the problems of uncontrollable instruction transmission latency and poor reliability in the prior art.

[0022] 4. This invention integrates a standardized interface matrix covering multiple mainstream interfaces such as CAN / CAN-FD, RS485, and Ethernet, meeting the access requirements of different types of cabin equipment. It enables plug-and-play functionality for cabin operation equipment, eliminating the need for additional independent control boxes, reducing hardware stacking and wiring complexity, and lowering maintenance costs. Through a device abstraction layer, it achieves unified encapsulation of device capabilities. When a device comes online, it automatically reports its identifier and capability information. The operations domain controller automatically matches the driver and completes registration, enabling business binding without manual configuration, significantly improving device access efficiency and system scalability. For devices that cannot be matched with a driver, the system places them in a pending adaptation state, without affecting the normal operation of other devices, ensuring system stability.

[0023] 5. This invention employs a core approach of layered storage and equal authorization for operational data, dividing it into four layers: a private operational layer, a shared regulatory layer, a necessary layer for vehicle manufacturers, and a public anonymity layer. Each layer uses independent encryption key domains and access policies. A policy engine enables dynamic permission decisions based on multi-contextual information, ensuring that different entities can only access data within their authorized scope. Simultaneously, chain hashing and digital signatures generate immutable audit logs, enabling full traceability of data access and balancing data security and compliance requirements. Attached Figure Description

[0024] To more clearly illustrate the technical solutions in the embodiments of the present invention or the prior art, the drawings used in the description of the embodiments or the prior art will be briefly introduced below. Obviously, the drawings described below are only embodiments of the present invention. For those skilled in the art, other drawings can be obtained based on the provided drawings without creative effort.

[0025] Figure 1 This is a schematic diagram of the overall architecture of the dual-domain cooperative system for autonomous buses provided in an embodiment of the present invention; Figure 2 This is a flowchart of the operation command pass-through and primary / backup redundant link switching provided in the embodiments of the present invention; Figure 3 This is a schematic diagram of inter-domain secure communication and fault isolation processing provided in an embodiment of the present invention; Figure 4 This is a flowchart illustrating the cabin operation equipment access process provided in this embodiment of the invention. Figure 5 This is a schematic diagram illustrating the hierarchical classification and ownership-equal permission division of operational data provided in this embodiment of the invention. Detailed Implementation

[0026] The technical solutions of the embodiments of the present invention will be clearly and completely described below with reference to the accompanying drawings. Obviously, the described embodiments are only some embodiments of the present invention, and not all embodiments. Based on the embodiments of the present invention, all other embodiments obtained by those skilled in the art without creative effort are within the scope of protection of the present invention.

[0027] Example 1 like Figure 1 As shown in the figure, an embodiment of the present invention discloses a dual-domain collaborative system for autonomous driving buses, including: an autonomous driving domain controller (ADC) 100, an operations domain controller (ODC) 200, an inter-domain secure communication unit (SIG) 300 disposed between the autonomous driving domain controller and the operations domain controller, an operations cloud platform 400, and cabin operations equipment 500.

[0028] The core function of the autonomous driving domain controller 100 is to complete the perception, localization, decision-making and planning and chassis control of the vehicle driving domain, communicate with the vehicle chassis control unit, LiDAR, camera and other driving-related sensors / actuators, and does not participate in the generation and execution of any operation-related instructions.

[0029] The Operations Domain Controller 200, serving as the central hub for in-vehicle operations information, is independently deployed in the vehicle cockpit domain and has no direct physical connection to the Driver Domain Controller 100. Controlled interaction is achieved through the inter-domain secure communication unit 300. Its hardware employs a multi-core processor (such as an ARM Cortex-A76), has at least 16GB of storage capacity, and supports hardware encryption acceleration. A dedicated vehicle-to-cloud communication link is established between the Operations Domain Controller 200 and the Operations Cloud Platform 400. This link receives operational instructions from the operations platform, performs trusted verification on the instructions, and then executes operational actions and / or generates controlled operational requests through the local instruction scheduler. Trusted verification includes at least digital signature verification, timestamp-based time window verification, and replay protection verification.

[0030] The inter-domain secure communication unit 300 is implemented using an independent hardware chip and connects to the driving domain controller 100 and the operation domain controller 200 via two independent Ethernet links, with a link bandwidth of no less than 1Gbps. It provides controlled communication based on physical isolation between the autonomous driving domain controller and the operation domain controller. Specifically, it is configured to: divide the communication into a status summary channel (sent from the autonomous driving domain controller to the operation domain controller) and an operation-controlled request channel (sent from the operation domain controller to the autonomous driving domain controller), and perform whitelist filtering, security verification, rate limiting, and fault isolation on inter-domain messages. The status summary channel is used to transmit vehicle driving status information; the operation-controlled request channel is used to transmit operation-controlled requests, enabling coordination between operational services and driving status; the operation-controlled request is a predefined set of operation-related request messages and does not contain driving-related execution commands.

[0031] Specifically, the set of operation-related request messages includes the following 6 core message categories: ① Emergency event synchronization requests include: emergency assistance event reporting and abnormal events in the carriage, which facilitates the driver domain controller to cooperate in executing safe docking.

[0032] ② Arrival / departure linkage request, including arrival preparation request and departure confirmation request. The Operations Domain Controller (ODC) informs the Driving Domain Controller (ADC) that they are about to arrive at the target station and requests the ADC to prepare for smooth deceleration; or the ODC confirms that the passenger cabin boarding and alighting are completed and requests the ADC to execute departure driving.

[0033] ③ Cabin service linkage requests, including cabin service trigger requests (ODC initiates "arrival broadcast linkage" based on passenger needs, requesting ADC to synchronize the current driving progress) and equipment coordination requests (cabin air conditioning needs to adjust power according to vehicle energy consumption, and requests the current energy consumption status from ADC).

[0034] ④ Operational scheduling coordination requests, including temporary site docking requests (ODC receives temporary map adjustment instructions from the operation cloud platform and requests the ADC to dock at a newly added temporary site) and operational period adjustment requests (operational period is extended, and the ADC is requested to adjust the range planning prompt synchronously).

[0035] ⑤ Status confirmation requests, including vehicle location verification requests (ODC requests the ADC for the precise current location to update the cabin station display) and range confirmation requests (ODC requests the ADC to determine whether the remaining range meets the requirements of subsequent stations when issuing an operation announcement).

[0036] ⑥ Fault linkage request, including "cabin equipment fault synchronization request" (ODC detects a ticketing terminal fault and synchronizes the associated information "equipment maintenance is required at the terminal station" to ADC) and operation link interruption notification request (ODC informs ADC that the current vehicle-cloud link is interrupted and the vehicle needs to be driven according to the preset operation rules).

[0037] The Operation Cloud Platform 400 is deployed in the operator's data center. It sends operation instructions to the Operation Domain Controller 200 through the operator's cellular network (primary communication channel) and private network (backup channel), and receives execution receipts and status information uploaded by the Operation Domain Controller 200.

[0038] The cabin operation equipment 500 includes cabin voice broadcasting equipment, displays, security cameras, ticketing terminals, emergency help buttons, etc., and is connected to the operation domain controller 200 through a standardized interface matrix.

[0039] Example 2 Based on Example 1, this embodiment further optimizes the dedicated vehicle-to-cloud communication link. Specifically, the dedicated vehicle-to-cloud communication link includes a primary communication channel and a backup communication channel. The operation domain controller automatically switches between the primary and backup communication channels based on the link health detection results. The link health detection generates a link quality evaluation based on at least one or more indicators, such as round-trip latency, packet loss rate, and number of consecutive communication failures. When the link quality evaluation of the primary communication channel does not meet the preset threshold, it triggers an automatic switch to the backup communication channel.

[0040] When the Operations Domain Controller 200 receives the Operations Cloud Platform's instructions through the main or backup communication channel, the local instruction scheduler queues and executes the instructions according to preset priorities, which are set as: Emergency > Operations Scheduling > Passenger Service.

[0041] Specifically, emergency commands include emergency stop coordination requests, emergency assistance reports, and joint command for handling abnormal events in the carriage (such as fights or fires), as well as emergency broadcast trigger commands.

[0042] Operational scheduling instructions include temporary station change instructions (such as changing the order of stations or adding temporary stops), operational announcement issuance instructions (such as route suspension notices), station sequence information update instructions, operational time period adjustment instructions, and promotional material issuance instructions. Passenger service instructions include instructions to adjust voice speed, switch display content, adjust air conditioning temperature, adjust cabin lighting brightness, and update ticketing rules.

[0043] The Operations Domain Controller 200 is also configured to switch to the backup communication channel to transmit emergency commands issued by the Operations Cloud Platform when the primary communication channel is unavailable, and to perform offline caching of operation scheduling and passenger service commands. After the primary communication channel is restored to normal within a preset time, the cached commands are transmitted through the primary communication channel and an execution receipt is resent to the Operations Cloud Platform. If the primary communication channel is not restored to normal within the preset time, the cached commands are transmitted through the backup communication channel.

[0044] like Figure 2 As shown in the figure, the operation command pass-through and primary / backup redundant link switching process in this embodiment is as follows: 1) Link establishment: The operation domain controller 200 establishes the main communication channel and backup communication channel with the operation cloud platform 400, and initializes the link health detection parameters.

[0045] 2) Link health check: Perform health checks on the two channels at a fixed frequency, calculate RTT and packet loss rate by sending probe packets, and record the number of consecutive communication failures.

[0046] 3) Command Reception: The operation cloud platform issues an emergency help reporting command via 400. The command carries the command identifier, subject identity, timestamp, permission declaration and digital signature. If the main communication channel RTT and packet loss rate meet the threshold requirements at this time, the command will be received through the main communication channel.

[0047] 4) Command Trust Verification: The operations domain controller uses the operations cloud platform public key to verify the digital signature and confirm the authenticity of the command source; then it compares the timestamp with the local time and performs time window verification; finally, it queries the local command identifier set to confirm that the command has not been processed and performs replay protection verification. If the verification fails, the current command is rejected and an audit alert is issued. If the verification passes, proceed to step 5.

[0048] 5) Command scheduling: The local command scheduler identifies the command as an emergency command with the highest priority, immediately places it in the execution queue and executes it, triggers the cabin emergency help button indicator light to stay on, and announces "Emergency help has been reported and is awaiting handling" in voice. At the same time, it generates an operational controlled request, synchronizes the "emergency help event" to the flight domain controller 100, and generates an execution receipt to return to the operation cloud platform.

[0049] 6) Link Anomaly Handling: If the main communication channel is blocked due to a network failure, it will automatically switch to the backup communication channel. If the command issued by the operation cloud platform is an emergency command, it will be transmitted immediately through the backup communication channel. If the command issued by the operation cloud platform is a passenger service command, such as adjusting the broadcast volume, the command will be cached offline by the operation domain controller 200, and the cache queue number will be 001. When the main communication channel is restored to normal within a preset time, the operation domain controller 200 will complete the execution of the cached command in a short time and resend the execution receipt to the operation cloud platform.

[0050] Example 3 This embodiment, based on embodiment 1, further defines the inter-domain security channel, thereby enabling secure interaction between the operations domain controller and the driving domain controller. For example... Figure 3 As shown, the specific steps are as follows: 1) Channel division: The inter-domain security channel SIG 300 pre-divides the status summary channel and the operation controlled request channel. The status summary channel is used to enable the driving domain controller ADC 100 to send status summaries such as vehicle speed, battery level, and current location to the operation domain controller ODC 200; the operation controlled request channel is used by the operation domain controller ODC 200 to send operation-related requests to the driving domain controller ADC 100.

[0051] 2) Whitelist configuration: The inter-domain secure communication unit SIG 300 is pre-configured with an operational controlled request whitelist, which only allows 6 types of request messages, such as emergency assistance event reporting, arrival event synchronization, and cabin service linkage triggering, to pass through, and explicitly prohibits the transmission of execution commands such as steering angle and braking pressure.

[0052] 3) Controlled forwarding: Operationally controlled requests such as emergency assistance events are sent to the Inter-Domain Secure Communication Unit SIG 300. The Inter-Domain Secure Communication Unit SIG 300 verifies that the request is within the whitelist range and passes the whitelist filtering; then it verifies the digital signature of the Operational Domain Controller ODC 200 carried in the request and passes the security verification; at the same time, it controls the current channel message transmission rate to 5 messages / minute, which does not exceed the threshold, and forwards the request to the Driving Domain Controller ADC 100.

[0053] 4) Anomaly Detection and Handling: If an unauthorized request attempts to be transmitted through the Operations Controlled Request Channel, the Inter-Domain Security Communication Unit (SIG 300) identifies that the request is not in the whitelist, refuses to forward it, and records the anomaly in the log. If six such unauthorized requests occur consecutively, reaching the security verification failure threshold, the SIG 300 immediately blocks the Operations Controlled Request Channel, maintaining normal communication only through the State Digest Channel. At this time, the Operations Controlled Request generated by the Operations Domain Controller (ODC 200) is cached and forwarded again after the channel is restored.

[0054] 5) Degraded Mode Operation: If multiple signature verification failures occur within a short period, the Inter-Domain Secure Communication Unit (SIG 300) enters degraded mode, allowing only emergency-related message transmission. During this time, operational scheduling requests (such as station sequence information synchronization) generated by the Operations Domain Controller (ODC 200) are temporarily blocked until the anomaly is resolved. In degraded mode, low-priority operationally controlled requests are blocked, retaining only the transmission permissions for core emergency requests. This aims to prevent abnormal messages from occupying channels or interfering with ADC driving control, while preserving critical emergency coordination capabilities. Normal transmission will automatically resume after the anomaly is resolved.

[0055] Example 4 Based on Example 1, this embodiment enables the access and service binding of new cabin equipment. The operations domain controller accesses the cabin operations equipment through a standardized interface matrix and performs equipment identification, driver matching, capability information registration, and service binding on the accessed cabin operations equipment based on the equipment abstraction layer. If the accessed cabin operations equipment cannot find a driver, the cabin operations equipment is marked as pending authorization or pending adaptation and will not participate in subsequent service binding. The operations domain controller is then remotely controlled by the operations platform to add the driver for the cabin operations equipment.

[0056] The standardized interface matrix includes one or more of the following: CAN, CAN-FD, RS485, Ethernet, USB, Discrete Input / Output (DI / DO), and audio interfaces.

[0057] like Figure 4 As shown, taking the access to the cabin high-definition display screen as an example, the access process will be further explained, specifically including: 1) Equipment access: The newly added cabin high-definition display screen is connected to the standardized interface matrix of the Operations Domain Controller (ODC) 200 via Ethernet interface. After the equipment is powered on, it automatically sends equipment identification and capability description information to the Operations Domain Controller (ODC) 200.

[0058] 2) Device identification and capability registration: After receiving the above information, query the local driver library, match the driver corresponding to the display model, and automatically load the driver; at the same time, register the device capability information to the device abstraction layer and generate a device abstraction identifier.

[0059] 3) Business Binding: Identify the device as a display screen and automatically bind it to the "Site Information Display" and "Operation Announcement Release" businesses, and configure display rules, including centering of site information, font size, and scrolling of announcements.

[0060] 4) Plug and play verification: The operation cloud platform issues a "site information update" command. After the operation domain controller ODC 200 executes the command, it sends the updated site list (including the current site, the next site, and the remaining distance) to the display screen through the device abstraction layer. The display screen successfully displays the relevant information, realizing plug and play.

[0061] 5) Handling Abnormal Devices: If the connected cabin equipment is of an unknown model and the driver cannot be matched, it will be placed in the adaptation state and marked as "Not Adapted-001". This device will not participate in any business binding and will not affect the normal operation of the connected voice broadcasting equipment and ticketing terminals. The operators can add the driver for this device to the Operations Domain Controller ODC 200 through remote upgrade. After the driver is loaded, the device will automatically switch to the normal state and complete the business binding.

[0062] Example 5 This embodiment, based on embodiment 1, achieves secure management and sharing of operational data. The specific implementation method is as follows: The operations domain controller is configured to store operations data locally with encryption and to perform hierarchical authorization sharing and access auditing based on the permissions of the ownership subject. For example... Figure 5 As shown, the operational domain controller is also configured with a data storage unit, a key management unit, a policy engine unit, and an auditing unit; The data storage unit is used to divide operational data into multiple data layers according to the ownership entity, with each data layer bound to a corresponding ownership entity. Each data layer includes an operational private layer, a regulatory shared layer, a vehicle manufacturer necessary layer, and a public anonymity layer. Among them, the operational private layer is a highly sensitive data layer, containing operational dispatch instructions and passenger payment information, etc., owned by the operator, and only the operator can access it in full; the regulatory shared layer is a medium-sensitive data layer, containing cabin security videos, abnormal event records, etc., owned by the operator, and only open to regulatory authorities for compliant access; the vehicle manufacturer necessary layer is a medium-low sensitive data layer, containing cabin equipment fault codes, energy consumption-related data, etc., and only open to vehicle manufacturers for data required for R&D / diagnosis; the public anonymity layer is a low-sensitive data layer, containing anonymous passenger flow statistics, route congestion information, etc., and is open to the public after de-privacy processing.

[0063] The key management unit generates and encrypts independent keys for different data layers, and the keys are rotated according to a fixed period. When the rights of the ownership subject expire, the data sharing agreement is terminated, or there is a risk of key leakage, the key revocation process is triggered. The policy engine unit is used to confirm the access permissions of the current access subject after receiving a data access request and generate an access decision result; the key management unit sends the corresponding key to the current access subject according to the access decision result; The audit unit generates tamper-proof audit logs for all access to operational data. These logs are encrypted using chain hashing and digital signatures and record at least the access subject, access time, data type, access result, and instruction execution status.

[0064] Next, taking the regulator's access to relevant data as an example, the specific details include: 1) Layered Data Storage: The data storage unit of the Operations Domain Controller (ODC) 200 collects operational data, including operational scheduling instructions (corresponding to the Operations Private Layer), cabin security video clips (corresponding to the Regulatory Sharing Layer), equipment fault codes (corresponding to the Automaker Necessary Layer), and anonymous passenger flow statistics (corresponding to the Public Anonymity Layer). The key management unit generates independent keys for different data layers: the Operations Private Layer uses key K1 (generated by the SM2 algorithm), the Regulatory Sharing Layer uses key K2, the Automaker Necessary Layer uses key K3, and the Public Anonymity Layer uses key K4. The key rotation cycle is set to a fixed period.

[0065] 2) Access Control Decision: The regulator sends a request to the Operations Domain Controller (ODC) 200 via the terminal to "view cabin security video clips", carrying the subject's identity, vehicle identification, and time information; the policy engine unit confirms that the regulator has access to the shared data based on preset rules and generates an access control decision result.

[0066] 3) Data sharing: The key management unit distributes key K2 to the regulatory terminal, thereby enabling access to relevant video clips; at the same time, the audit unit generates audit logs, recording the access subject, access time, access data type, access result, and instruction execution status, and performs chain hashing and digital signature on the audit logs to ensure clear responsibilities.

[0067] 4) Access Control: If an automaker attempts to access the scheduling instruction data of the private layer of operations, the policy engine unit will identify that it does not have the corresponding permission and reject the access request. The audit unit will record the access failure log and send an access exception alarm to the operator.

[0068] Example 6 This embodiment provides an operation domain controller, which is applied in the aforementioned dual-domain cooperative system for autonomous buses, including: The communication module is used to establish a dedicated vehicle-to-cloud communication link and receive operational instructions from the operational cloud platform. It supports switching between primary and backup communication channels and link health detection. The security verification module is used to perform trusted verification of operational instructions, including digital signature verification, time window verification, and replay protection verification. The instruction scheduling module is used to prioritize and execute operational instructions that have passed the trust verification and / or generate operational controlled requests, and to cache the corresponding operational instructions offline when the dedicated vehicle-cloud communication link fails. The equipment management module is used to access cabin operation equipment through a standardized interface matrix, perform equipment identification, driver matching, capability information registration and business binding, and manage the adaptation status of cabin operation equipment. The data management module is used for local encrypted storage of operational data and for implementing hierarchical authorization sharing and access auditing of operational data based on the permissions of the ownership entity. The data management module adopts... Figure 5 The architecture includes a data storage unit, a key management unit, a policy engine unit, and an audit unit. The management and sharing methods for operational data are the same as in Implementation Example 5.

[0069] Example 7 This embodiment provides a dual-domain cooperative control method for autonomous buses, applicable to the dual-domain cooperative system of the aforementioned autonomous buses, and includes the following steps: Establish a primary / backup redundant dedicated vehicle-to-cloud communication link between the operation domain controller and the operation cloud platform. Set up an inter-domain secure communication unit between the operation domain controller and the driving domain controller. Divide the inter-domain secure communication unit into a status summary channel and an operation-controlled request channel. The operation domain controller performs link health checks on the primary and backup communication channels, and switches to the backup communication channel when the link quality evaluation of the primary communication channel does not meet the preset threshold. The operations domain controller receives operations instructions from the operations cloud platform through the dedicated vehicle-cloud communication link and performs a trusted verification on the operations instructions. If the verification fails, it refuses to execute and generates an alarm log; if the verification passes, it executes operations actions and / or generates controlled operations requests according to preset priorities through the local instruction scheduler. The status summary channel and the operationally controlled request channel perform whitelist filtering, security verification, rate limiting, and fault isolation on inter-domain messages, respectively. The driving domain controller sends vehicle driving status information to the operations domain controller through the status summary channel; the operations domain controller sends operations control requests to the driving domain controller through the operations control request channel. When cabin operation equipment is connected, the operation domain controller performs equipment identification, driver matching, capability information registration and business binding for the connected cabin operation equipment; The operations domain controller stores operations data locally with encryption and performs hierarchical authorization sharing and access auditing based on the ownership and permissions of the data holder. Operations data is divided into at least several different data layers and encrypted using different key domains. Based on the entity's identity and context information, the policy engine automatically generates permission decisions, providing corresponding data access interfaces and / or interface call permissions to the operator, vehicle manufacturer, and regulator.

[0070] The various embodiments in this specification are described in a progressive manner, with each embodiment focusing on the differences from other embodiments. The same or similar parts between the various embodiments can be referred to each other.

[0071] The above description of the disclosed embodiments enables those skilled in the art to make or use the invention. Various modifications to these embodiments will be readily apparent to those skilled in the art, and the general principles defined herein may be implemented in other embodiments without departing from the spirit or scope of the invention. Therefore, the invention is not to be limited to the embodiments shown herein, but is to be accorded the widest scope consistent with the principles and novel features disclosed herein.

Claims

1. A dual-domain collaborative system for autonomous buses, characterized in that, include: An autonomous driving domain controller, an operations domain controller, and an inter-domain secure communication unit configured between the autonomous driving domain controller and the operations domain controller; The operation domain controller establishes a dedicated vehicle-cloud communication link with the operation cloud platform to receive operation instructions issued by the operation platform, perform trusted verification on the operation instructions, and then execute operation actions and / or generate operation controlled requests through the local instruction scheduler. The inter-domain secure communication unit is configured to: divide the system into a status summary channel (sent from the autonomous driving domain controller to the operations domain controller) and an operations controlled request channel (sent from the operations domain controller to the autonomous driving domain controller), and perform whitelist filtering, security verification, rate limiting, and fault isolation on the inter-domain messages; the status summary channel is used to transmit vehicle driving status information; the operations controlled request channel is used to transmit the operations controlled request, realizing the coordination between operational services and driving status; the operations controlled request is a predefined set of operations-related request messages and does not contain driving-related execution commands; The operations domain controller is also configured to store operations data locally in an encrypted manner and to perform hierarchical authorization sharing and access auditing of operations data based on the permissions of the ownership subject.

2. The dual-domain cooperative system for autonomous buses as described in claim 1, characterized in that, The operations domain controller also connects to cabin operations equipment through a standardized interface matrix, and performs equipment identification, driver matching, capability information registration, and service binding on the connected cabin operations equipment based on the equipment abstraction layer. If the connected cabin operations equipment cannot be matched with a driver, the cabin operations equipment is marked as pending authorization or pending adaptation and will not participate in subsequent service binding. The operations domain controller is then remotely controlled by the operations platform to add the driver for the cabin operations equipment.

3. The dual-domain cooperative system for autonomous buses as described in claim 1, characterized in that, The standardized interface matrix includes one or more of the following: CAN, CAN-FD interface, RS485 interface, Ethernet interface, USB interface, Discrete Input / Output (DI / DO) interface, and audio interface.

4. The dual-domain cooperative system for autonomous buses as described in claim 1, characterized in that, The dedicated vehicle-to-cloud communication link includes a primary communication channel and a backup communication channel. The operation domain controller automatically switches between the primary communication channel and the backup communication channel based on the link health detection results. The link health detection generates a link quality evaluation based on at least one or more indicators, including round-trip time, packet loss rate, and number of consecutive communication failures. When the link quality evaluation of the main communication channel does not meet a preset threshold, it triggers an automatic switch to the backup communication channel.

5. The dual-domain cooperative system for autonomous buses as described in claim 4, characterized in that, The local instruction scheduler queues and executes the operational instructions according to a preset priority, which is set as: Emergency > Operational Scheduling > Passenger Service. The emergency instructions include emergency stop coordination requests, emergency assistance reports, and instructions for handling abnormal events in the carriage. The operational scheduling instructions include instructions for temporary station changes, instructions for issuing operational announcements, instructions for updating station sequence information, instructions for adjusting operating hours, and instructions for issuing promotional materials. The passenger service instructions include instructions for adjusting voice speed, instructions for switching display screen content, instructions for adjusting air conditioning temperature, instructions for adjusting cabin lighting brightness, and instructions for updating ticketing rules.

6. The dual-domain cooperative system for autonomous buses as described in claim 5, characterized in that, The operation domain controller is also configured to switch to the backup communication channel to transmit emergency instructions issued by the operation cloud platform when the main communication channel is unavailable, and to perform offline caching of operation scheduling and passenger service instructions. After the main communication channel is restored to normal within a preset time, the cached instructions are transmitted through the main communication channel and an execution receipt is resent to the operation cloud platform. If the main communication channel does not return to normal within a preset time period, the cached instructions will be transmitted through the backup communication channel.

7. The dual-domain cooperative system for autonomous buses as described in claim 1, characterized in that, The operation domain controller is also configured with a data storage unit, a key management unit, a policy engine unit, and an auditing unit; The data storage unit is used to divide the operational data into multiple data layers according to the ownership entity, and each data layer is bound to the corresponding ownership entity. The key management unit generates and encrypts independent keys for different data layers, and the keys are rotated according to a fixed period. When the rights of the owner expire, the data sharing agreement is terminated, or there is a risk of key leakage, the key revocation process is triggered. The policy engine unit is used to confirm the access permissions of the current accessing subject and generate permission decision results after receiving a data access request. The key management unit sends the corresponding key to the current access subject based on the permission decision result; The audit unit generates tamper-proof audit logs for all access behaviors to operational data.

8. The dual-domain cooperative system for autonomous buses as described in claim 7, characterized in that, The tamper-proof audit log is encrypted using chain hashing and digital signatures, and records at least the access subject, access time, access data type, access result, and instruction execution status information.

9. An operational domain controller, characterized in that, Its application in the dual-domain cooperative system of autonomous buses as described in any one of claims 1-8 includes: The communication module is used to establish a dedicated vehicle-to-cloud communication link and receive operational instructions from the operational cloud platform. It supports switching between primary and backup communication channels and link health detection. The security verification module is used to perform trusted verification on operational instructions; The instruction scheduling module is used to prioritize and execute operational actions and / or generate operational controlled requests for operational instructions that have passed the trust verification, and to cache the corresponding operational instructions offline when the dedicated vehicle-cloud communication link fails. The equipment management module is used to access cabin operation equipment through a standardized interface matrix, perform equipment identification, driver matching, capability information registration and business binding, and manage the adaptation status of cabin operation equipment. The data management module is used to encrypt and store operational data locally, and to perform hierarchical authorization sharing and access auditing of operational data based on the ownership subject's permissions.

10. A dual-domain cooperative control method for autonomous buses, characterized in that, It is applicable to the dual-domain cooperative system for autonomous buses as described in any one of claims 1-8, and includes the following steps: A primary and backup redundant vehicle-to-cloud communication link is established between the operation domain controller and the operation cloud platform. An inter-domain secure communication unit is set between the operation domain controller and the driving domain controller, and the inter-domain secure communication unit is divided into a status summary channel and an operation controlled request channel. The operation domain controller performs link health checks on the primary communication channel and the backup communication channel, and switches to the backup communication channel when the link quality evaluation of the primary communication channel does not meet a preset threshold. The operation domain controller receives operation instructions issued by the operation cloud platform through the dedicated vehicle-cloud communication link and performs a trust verification on the operation instructions. If the verification fails, it refuses to execute and generates an alarm log; if the verification passes, it executes the operation action and / or generates an operation controlled request according to a preset priority through the local instruction scheduler. The status summary channel and the operation-controlled request channel respectively perform whitelist filtering, security verification, rate limiting and fault isolation on inter-domain messages; The driving domain controller sends vehicle driving status information to the operations domain controller through the status summary channel; the operations domain controller sends an operations control request to the driving domain controller through the operations control request channel. When cabin operation equipment is connected, the operation domain controller performs equipment identification, driver matching, capability information registration and service binding for the connected cabin operation equipment; The operation domain controller performs local encrypted storage of operation data and performs hierarchical authorization sharing and access auditing of operation data based on the ownership subject's permissions.