Autonomous driving methods, devices, storage media and electronic devices for vehicles

By verifying the working status of the primary domain controller and the secondary domain controller, and switching to the target working strategy, the safety problem of the autonomous driving system when both systems are abnormal is solved, and stable control is achieved under abnormal conditions.

CN122078427APending Publication Date: 2026-05-26CHERY AUTOMOBILE CO LTD
View PDF 0 Cites 0 Cited by

Patent Information

Authority / Receiving Office
CN · China
Patent Type
Applications(China)
Current Assignee / Owner
CHERY AUTOMOBILE CO LTD
Filing Date
2026-03-03
Publication Date
2026-05-26

AI Technical Summary

Technical Problem

Existing autonomous driving systems cannot control the vehicle in a timely manner when both the main and auxiliary systems malfunction, resulting in low safety for autonomous driving.

Method used

By acquiring vehicle control data, the operating status of the primary domain controller and secondary domain controller is verified. Based on the verification results, the system switches to the target operating strategy and triggers the controller to control the vehicle to perform autonomous driving operations, including secondary domain operating strategies, primary domain operating strategies, and safety operating strategies.

Benefits of technology

The timely control of the vehicle in the event of controller malfunction improves the safety of autonomous driving and ensures stable operation of the vehicle under various abnormal conditions.

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure CN122078427A_ABST
    Figure CN122078427A_ABST
Patent Text Reader

Abstract

This application discloses an autonomous driving method, apparatus, storage medium, and electronic device for a vehicle. The method is applied to an autonomous driving system for a vehicle, which includes a controller. The method includes: acquiring control data of the vehicle; verifying the control data to obtain a verification result of the controller, wherein the verification result represents the relationship between the controller's operating state and an abnormal or normal operating state; based on the verification result, switching the controller's original operating strategy to a target operating strategy, wherein the original operating strategy represents the controller's operating mode before the switching, and the target operating strategy represents the controller's operating mode after the switching; and triggering the controller to control the vehicle to perform autonomous driving operations according to the target operating strategy. This application solves the technical problem of low safety in autonomous driving of vehicles.
Need to check novelty before this filing date? Find Prior Art

Description

Technical Field

[0001] This application relates to the field of vehicles, and more specifically, to an autonomous driving method, apparatus, storage medium, and electronic device for vehicles. Background Technology

[0002] Currently, in related technologies, autonomous driving methods often employ a dual-system redundancy approach. This allows the auxiliary system to take over autonomous driving in the event of a failure in the primary system. However, this method cannot guarantee timely control of the vehicle when both systems fail, leading to a technical problem of low safety in autonomous driving.

[0003] There is currently no effective solution to the technical problem of low safety in autonomous driving of the aforementioned vehicles. Summary of the Invention

[0004] This application provides an autonomous driving method, apparatus, storage medium, and electronic device for vehicles, to at least address the technical problem of low safety in autonomous driving of vehicles.

[0005] According to one aspect of the embodiments of this application, an autonomous driving method for a vehicle is provided. The method is applied to an autonomous driving system for a vehicle, the system comprising: a controller; the method comprising: acquiring control data of the vehicle, wherein the control data is data required by the controller to control the vehicle to perform autonomous driving operations; verifying the control data to obtain a verification result of the controller, wherein the verification result is used to represent the relationship between the controller's operating state and an abnormal operating state or a normal operating state; based on the verification result, switching the controller's original operating strategy to a target operating strategy, wherein the original operating strategy represents the controller's operating mode before the switching of the operating state, and the target operating strategy represents the controller's operating mode after the switching of the operating state; and triggering the controller to control the vehicle to perform autonomous driving operations according to the target operating strategy.

[0006] Furthermore, the controller includes a primary domain controller and a secondary domain controller. The control data includes first control data and second control data. The first control data is the data required by the primary domain controller to control the vehicle to perform autonomous driving operations, and the second control data is the data required by the secondary domain controller to control the vehicle to perform autonomous driving operations. The verification results include a first verification result of the primary domain controller and a second verification result of the secondary domain controller. The first verification result is used to represent the relationship between the working state of the primary domain controller and abnormal or normal working states, and the second verification result is used to represent the relationship between the working state of the secondary domain controller and abnormal or normal working states. Verifying the control data to obtain the controller's verification result includes: controlling the secondary domain controller to verify the first control data to obtain the first verification result; and controlling the primary domain controller to verify the second control data to obtain the second verification result.

[0007] Furthermore, the target operating policy includes: a secondary domain operating policy, a primary domain operating policy, and a security operating policy. The secondary domain operating policy indicates how the secondary domain controller remains operational and how the primary domain controller exits operation. The primary domain operating policy indicates how the primary domain controller remains operational and how the secondary domain controller exits operation. The security operating policy indicates how the security module of the primary domain controller or the security module of the secondary domain controller operates. Based on the verification result, switching the controller's original operating policy to the target operating policy includes: switching the original operating policy to the secondary domain operating policy in response to the verification result indicating that the primary domain controller's operating state is abnormal and the secondary domain controller's operating state is normal; switching the original operating policy to the primary domain operating policy in response to the verification result indicating that the primary domain controller's operating state is normal and the secondary domain controller's operating state is abnormal; and switching the original operating policy to the security operating policy in response to the verification result indicating that both the primary and secondary domain controllers are in abnormal operating states.

[0008] Furthermore, the method also includes: acquiring environmental data of the driving environment in which the vehicle is located, wherein the environmental data is used to represent the state of the driving environment; inputting the environmental data into a first prediction model for trajectory prediction to obtain first trajectory data, wherein the first prediction model is constructed based on a visual language action model; determining the first trajectory data, the vehicle's first instruction data, and the vehicle's first fault data as first control data, wherein the first instruction data is used to represent the instructions of the main domain controller to control the vehicle, and the first fault data is used to represent whether the software and / or hardware of the main domain controller has malfunctioned.

[0009] Furthermore, the method also includes: inputting environmental data into a second prediction model for trajectory prediction to obtain second trajectory data, wherein the second prediction model is constructed based on an end-to-end model; determining the second trajectory data, the vehicle's second command data, and the vehicle's second fault data as second control data, wherein the second command data is used to represent the commands of the auxiliary domain controller to control the vehicle, and the second fault data is used to represent whether the software and / or hardware of the auxiliary domain controller has failed.

[0010] Furthermore, the autonomous driving operation includes: a first type of parking operation and a second type of parking operation. The first type of parking operation is an automatic parking operation performed in a safe area around the vehicle, and the second type of parking operation is an automatic parking operation performed in the vehicle's current lane. In this case, triggering the controller to control the vehicle to perform the autonomous driving operation according to the target working strategy includes: triggering the controller to control the vehicle to perform either the first type of parking operation or the second type of parking operation according to the target working strategy.

[0011] Further, according to the target working strategy, the trigger controller controls the vehicle to perform a first type of parking operation or a second type of parking operation, including: in response to the target working strategy being a secondary domain working strategy, the trigger controller controls the secondary domain controller in the trigger controller to control the vehicle to perform a first type of parking operation, wherein the secondary domain working strategy is used to indicate the mode in which the secondary domain controller remains active and the mode in which the primary domain controller exits operation; in response to the target working strategy being a primary domain working strategy, the trigger controller controls the primary domain controller in the trigger controller to control the vehicle to perform a first type of parking operation, wherein the primary domain working strategy is used to indicate the mode in which the primary domain controller remains active and the mode in which the secondary domain controller exits operation; in response to the target working strategy being a safety working strategy, the trigger controller controls the vehicle to perform a second type of parking operation by the safety module of the primary domain controller or the safety module of the secondary domain controller, wherein the safety working strategy is used to indicate the mode in which the safety module of the primary domain controller or the safety module of the secondary domain controller operates.

[0012] According to another aspect of the embodiments of this application, an autonomous driving device for a vehicle is also provided. The autonomous driving device is deployed in an autonomous driving system of the vehicle. The autonomous driving system includes: a controller, the device including: a first acquisition unit for acquiring control data of the vehicle, wherein the control data is data required by the controller to control the vehicle to perform autonomous driving operations; a verification unit for verifying the control data to obtain a verification result of the controller, wherein the verification result is used to represent the relationship between the controller's working state and an abnormal working state or a normal working state; a switching unit for switching the controller's original working strategy to a target working strategy based on the verification result, wherein the original working strategy is used to represent the controller's working mode before the switching of the working state, and the target working strategy is used to represent the controller's working mode after the switching of the working state; and an execution unit for triggering the controller to control the vehicle to perform autonomous driving operations according to the target working strategy.

[0013] According to another aspect of the embodiments of this application, an electronic device is also provided, including: a memory storing an executable program; and a processor for running the program, wherein the program executes the methods in various embodiments of this application when it runs.

[0014] According to another aspect of the embodiments of this application, a computer-readable storage medium is also provided, the computer-readable storage medium including a stored executable program, wherein, when the executable program is running, it controls the device where the computer-readable storage medium is located to perform the methods of various embodiments of this application.

[0015] According to another aspect of the embodiments of this application, a computer program product is also provided, including a computer program that, when executed by a processor, implements the methods of various embodiments of this application.

[0016] According to another aspect of the embodiments of this application, a computer program product is also provided, including a non-volatile computer-readable storage medium storing a computer program that, when executed by a processor, implements the methods in various embodiments of this application.

[0017] According to another aspect of the embodiments of this application, a computer program is also provided, which, when executed by a processor, implements the methods of the various embodiments of this application.

[0018] According to another aspect of the embodiments of this application, a vehicle is also provided, which includes the electronic equipment described in this application.

[0019] In this embodiment, vehicle control data is acquired; the control data is verified to obtain the controller's verification result; based on the verification result, the controller's original operating strategy is switched to a target operating strategy; and according to the target operating strategy, the controller is triggered to control the vehicle to perform autonomous driving operations. Since this embodiment verifies the acquired vehicle control data, the controller's verification result can be obtained, meaning the relationship between the controller's operating state and its abnormal or normal operating states can be determined. Based on the obtained verification result, the controller's original operating strategy can be switched to the target operating strategy, and according to the switched target operating strategy, the controller is triggered to control the vehicle to perform autonomous driving operations. This achieves the goal of timely vehicle control when the controller malfunctions, solving the technical problem of low autonomous driving safety and realizing the technical effect of improving the safety of autonomous driving. Attached Figure Description

[0020] The accompanying drawings, which are included to provide a further understanding of this application and form part of this application, illustrate exemplary embodiments and are used to explain this application, but do not constitute an undue limitation of this application. In the drawings:

[0021] Figure 1(a) is a schematic diagram of an application scenario of an autonomous driving method for a vehicle according to an embodiment of this application;

[0022] Figure 1(b) is a flowchart of an autonomous driving method for a vehicle according to an embodiment of this application;

[0023] Figure 2 This is a schematic diagram of a dual-domain redundant autonomous driving system according to an embodiment of this application;

[0024] Figure 3 This is a schematic diagram of a deployment method for a dual-domain redundant autonomous driving system according to an embodiment of this application;

[0025] Figure 4 This is a schematic diagram illustrating another deployment method of a dual-domain redundant autonomous driving system according to an embodiment of this application;

[0026] Figure 5 This is a schematic diagram illustrating another deployment method of a dual-domain redundant autonomous driving system according to an embodiment of this application;

[0027] Figure 6 This is a schematic diagram illustrating another deployment method of a dual-domain redundant autonomous driving system according to an embodiment of this application;

[0028] Figure 7 This is a structural block diagram of an autonomous driving device for a vehicle according to an embodiment of this application;

[0029] Figure 8 This is a schematic diagram of an electronic device according to an embodiment of this application. Detailed Implementation

[0030] To enable those skilled in the art to better understand the present application, the technical solutions in the embodiments of the present application will be clearly and completely described below with reference to the accompanying drawings. Obviously, the described embodiments are only some embodiments of the present application, and not all embodiments. Based on the embodiments in the present application, all other embodiments obtained by those of ordinary skill in the art without creative effort should fall within the scope of protection of the present application.

[0031] It should be noted that the terms "first," "second," etc., in the specification, claims, and accompanying drawings of this application are used to distinguish similar objects and are not necessarily used to describe a specific order or sequence. It should be understood that such data can be interchanged where appropriate so that the embodiments of this application described herein can be implemented in orders other than those illustrated or described herein. Furthermore, the terms "comprising" and "having," and any variations thereof, are intended to cover non-exclusive inclusion; for example, a process, method, system, product, or apparatus that comprises a series of steps or units is not necessarily limited to those steps or units explicitly listed, but may include other steps or units not explicitly listed or inherent to such processes, methods, products, or apparatus.

[0032] According to an embodiment of this application, an embodiment of an autonomous driving method for a vehicle is provided. It should be noted that the steps shown in the flowchart in the accompanying drawings can be executed in a computer system such as a set of computer-executable instructions. Furthermore, although a logical order is shown in the flowchart, in some cases, the steps shown or described may be executed in a different order than that shown here.

[0033] As an optional implementation, the above-described autonomous driving method for vehicles can be applied, but is not limited to, the application scenario shown in Figure 1(a). Figure 1(a) is a schematic diagram of an application scenario of an autonomous driving method for vehicles according to an embodiment of this application. As shown in Figure 1(a), in the application scenario, the terminal device 10 can communicate with the server 13 via the network 11, but is not limited to. The server 13 can perform operations on the database, such as writing or reading data. The terminal device 10 can include, but is not limited to, a human-machine interface screen, a processor, and a memory. The human-machine interface screen can be used, but is not limited to, to display virtual machines on the mobile terminal 10. The vehicle 12 can be used, but is not limited to, to respond to the above-described human-machine interface operations, execute corresponding operations, or generate corresponding instructions and send the generated instructions to the server 13.

[0034] It should be noted that the steps shown in the flowcharts of the accompanying drawings can be executed in a computer system such as a set of computer-executable instructions. Furthermore, although a logical order is shown in the flowcharts, in some cases, the steps shown or described may be executed in a different order than that shown here. The autonomous driving method for a vehicle in this application is applied to an autonomous driving system for a vehicle, which includes a controller. The method may include: step S102, acquiring control data of the vehicle; step S104, verifying the control data to obtain a verification result of the controller; step S106, based on the verification result, switching the controller's original operating strategy to a target operating strategy; and step S108, triggering the controller to control the vehicle to perform autonomous driving operations according to the target operating strategy.

[0035] It should be noted that all information and data involved in this application (including but not limited to control data) are information and data authorized by the user or fully authorized by all parties. Furthermore, the collection, use and processing of such data must comply with the relevant laws, regulations and standards of the relevant countries and regions, and corresponding operation portals are provided for users to choose to authorize or refuse.

[0036] Figure 1(b) is a flowchart of an autonomous driving method for a vehicle according to an embodiment of the present application. As shown in Figure 1(b), the method may include the following steps.

[0037] Step S112: Obtain vehicle control data.

[0038] In the technical solution provided by step S112 of this application, the control data is the data required by the controller to control the vehicle to perform autonomous driving operations. The control data may include: vehicle trajectory data, instruction data, and fault data. The trajectory data can be used to represent the vehicle's trajectory during future driving, the instruction data can be used to represent the controller's instructions to control the vehicle, and the fault data can be used to indicate whether the vehicle's software and / or hardware has malfunctioned.

[0039] In this embodiment, the controller may include a primary domain controller and a secondary domain controller, wherein the primary domain controller may be used to verify the working status of the secondary domain controller, and the secondary domain controller may be used to verify the working status of the primary domain controller.

[0040] In this embodiment, vehicle control data is acquired. Optionally, this embodiment acquires controller communication data, wherein the communication data can be generated based on sensor data from the vehicle's sensors, which may include any or any combination of the following: a front-view camera, a surround-view camera, a panoramic camera, a rear-view camera, millimeter-wave radar, a front lidar, and ultrasonic radar, etc. Control data can be extracted from the aforementioned communication data, thereby achieving the goal of determining the data required for the controller to control the vehicle to perform autonomous driving operations.

[0041] Optionally, after receiving the sensor data, the received sensor data can be generated into communication data. For example, the received sensor data can be converted into communication data by format conversion. The sensor data may include any one or any combination of the following: image data, video data, and radar data, etc.

[0042] Step S114: Verify the control data to obtain the verification result of the controller.

[0043] In the technical solution provided in step S114 of this application, the verification result is used to indicate the relationship between the controller's operating state and its abnormal or normal operating state. For example, the verification result can be used to indicate that the controller's operating state is an abnormal operating state, or it can be used to indicate that the controller's operating state is a normal operating state. This is only an example and is not specifically limited.

[0044] In this embodiment, the verification result can be represented in the form of status data. For example, the status data can be any one or any combination of the following: chart data and text data, etc.

[0045] In this embodiment, after acquiring the vehicle's control data, the control data is verified to obtain the controller's verification result. Optionally, based on the acquired vehicle control data, this embodiment verifies the trajectory data, command data, and fault data within the control data to obtain the controller's verification result. This achieves the goal of determining the relationship between the controller's operating state and abnormal or normal operating states.

[0046] Optionally, if the above trajectory data verification is successful, the above command data verification is successful, and the above fault data verification fails, then the controller's verification result indicates that the controller's operating state is abnormal. If the above trajectory data verification fails, the above command data verification is successful, and the above fault data verification is successful, then the controller's verification result indicates that the controller's operating state is abnormal. If the above trajectory data verification is successful, the above command data verification fails, and the above fault data verification is successful, then the controller's verification result indicates that the controller's operating state is abnormal.

[0047] Optionally, if the verification of the above trajectory data fails, the verification of the above command data succeeds, and the verification of the above fault data fails, the controller's verification result indicates that the controller's operating state is abnormal. If the verification of the above trajectory data fails, the verification of the above command data fails, and the verification of the above fault data succeeds, the controller's verification result indicates that the controller's operating state is abnormal. If the verification of the above trajectory data succeeds, the verification of the above command data fails, and the verification of the above fault data fails, the controller's verification result indicates that the controller's operating state is abnormal.

[0048] Optionally, if the verification of the above trajectory data fails, the verification of the above instruction data fails, and the verification of the above fault data fails, the verification result of the controller indicates that the controller's working state is an abnormal working state.

[0049] Optionally, if the above trajectory data verification is successful, the above instruction data verification is successful, and the above fault data verification is successful, then the verification result of the controller indicates that the controller's working state is a normal working state.

[0050] Step S116: Based on the verification results, switch the controller's original operating strategy to the target operating strategy.

[0051] In the technical solution provided by step S116 of this application, the original operating strategy is used to represent the operating mode of the controller before the switching of the operating state. For example, the original operating strategy can be a timed switching strategy, which can be used to represent the method of switching between the primary domain controller and the secondary domain controller at regular intervals, and maintaining operation using the primary domain controller or the secondary domain controller after the switch.

[0052] In this embodiment, the target operating strategy is used to represent the operating mode of the controller after a switch in operating state. The target operating strategy may include: a secondary domain operating strategy, a primary domain operating strategy, and a security operating strategy. The secondary domain operating strategy can be used to indicate the mode in which the secondary domain controller remains operational and the primary domain controller exits operation. The primary domain operating strategy can be used to indicate the mode in which the primary domain controller remains operational and the secondary domain controller exits operation. The security operating strategy can be used to indicate the mode in which the security module of the primary domain controller is operational, or the security module of the secondary domain controller is operational.

[0053] In this embodiment, after verifying the control data and obtaining the controller's verification result, the controller's original operating strategy is switched to the target operating strategy based on the verification result. Optionally, based on the controller's verification result, this embodiment can switch the controller's original operating strategy to a secondary domain operating strategy, or to a primary domain operating strategy, or to a safety operating strategy, thereby achieving the purpose of switching the controller's original operating strategy.

[0054] Optionally, the above verification results can be parsed. Based on the parsed verification results, the controller's original operating policy can be switched to the secondary domain operating policy, or the controller's original operating policy can be switched to the primary domain operating policy, or the controller's original operating policy can be switched to the security operating policy.

[0055] It should be noted that the above method for switching the controller's original operating strategy to the target operating strategy is merely an illustrative example and is not intended to impose specific limitations. Any method that can switch the controller's original operating strategy to the target operating strategy based on the verification results is within the protection scope of the embodiments of this application, and will not be described in detail here.

[0056] Step S118: In accordance with the target working strategy, the controller is triggered to control the vehicle to perform autonomous driving operations.

[0057] In the technical solution provided by step S118 of this application, the aforementioned autonomous driving operation may include: driving operation and parking operation. The driving operation may include: constant speed driving operation and variable speed driving operation. The parking operation includes: a first type of parking operation and a second type of parking operation. The first type of parking operation is an automatic parking operation performed within a safe area around the vehicle, and the second type of parking operation is an automatic parking operation performed within the vehicle's current lane.

[0058] In this embodiment, after switching the controller's original operating strategy to the target operating strategy based on the verification results, the controller is triggered to control the vehicle to perform autonomous driving operations according to the target operating strategy. Optionally, in this embodiment, after the original operating strategy has been switched to the target operating strategy, the primary domain controller or secondary domain controller is triggered to control the vehicle to perform autonomous driving operations according to the aforementioned target operating strategy.

[0059] Optionally, according to the secondary domain operating strategy, the secondary domain controller is triggered to control the vehicle to perform autonomous driving operations. Alternatively, according to the primary domain operating strategy, the primary domain controller is triggered to control the vehicle to perform autonomous driving operations. According to the safety operating strategy, the safety module of the primary domain controller or the safety module of the secondary domain controller is triggered to control the vehicle to perform autonomous driving operations.

[0060] In steps S112 to S118 of this application, vehicle control data is acquired; the control data is verified to obtain the controller's verification result; based on the verification result, the controller's original operating strategy is switched to a target operating strategy; and according to the target operating strategy, the controller is triggered to control the vehicle to perform autonomous driving operations. Since this embodiment verifies the acquired vehicle control data, the controller's verification result can be obtained, meaning the relationship between the controller's operating state and its abnormal or normal operating states can be determined. Based on the obtained verification result, the controller's original operating strategy can be switched to the target operating strategy, and according to the switched target operating strategy, the controller is triggered to control the vehicle to perform autonomous driving operations. This achieves the goal of timely vehicle control when the controller malfunctions, solving the technical problem of low autonomous driving safety and realizing the technical effect of improving autonomous driving safety.

[0061] The following section further describes the steps of verifying the control data and obtaining the verification result of the controller in this embodiment.

[0062] As an optional embodiment, the controller includes a primary domain controller and a secondary domain controller. The control data includes first control data and second control data. The first control data is the data required by the primary domain controller to control the vehicle to perform autonomous driving operations, and the second control data is the data required by the secondary domain controller to control the vehicle to perform autonomous driving operations. The verification results include a first verification result of the primary domain controller and a second verification result of the secondary domain controller. The first verification result is used to represent the relationship between the working state of the primary domain controller and an abnormal working state or a normal working state, and the second verification result is used to represent the relationship between the working state of the secondary domain controller and an abnormal working state or a normal working state. In step S114, verifying the control data to obtain the controller's verification result includes: controlling the secondary domain controller to verify the first control data to obtain the first verification result; and controlling the primary domain controller to verify the second control data to obtain the second verification result.

[0063] In this embodiment, the controller includes a primary domain controller and a secondary domain controller. For example, the primary domain controller can be deployed in a primary domain system, and the secondary domain controller can be deployed in a secondary domain system.

[0064] In this embodiment, the control data includes: first control data and second control data. The first control data is the data required by the main domain controller to control the vehicle to perform autonomous driving operations. For example, the first control data may include: first trajectory data, first command data, and first fault data of the vehicle. The first trajectory data can be used to represent the trajectory of the vehicle during future driving under the control of the main domain controller; the first command data can be used to represent the commands given by the main domain controller to control the vehicle; and the first fault data can be used to indicate whether the software and / or hardware of the main domain controller has malfunctioned.

[0065] In this embodiment, the verification results include a first verification result of the primary domain controller and a second verification result of the secondary domain controller. The first verification result is used to represent the relationship between the primary domain controller's operating state and its abnormal or normal operating state. For example, the first verification result can be used to indicate that the primary domain controller's operating state is abnormal, or it can be used to indicate that the primary domain controller's operating state is normal. This is merely an example and not a specific limitation.

[0066] In this embodiment, after acquiring the vehicle's control data, the auxiliary domain controller verifies the first control data to obtain a first verification result. Optionally, based on the acquired vehicle control data, this embodiment verifies the first trajectory data, the first command data, and the first fault data in the first control data to obtain the first verification result of the primary domain controller. This achieves the goal of determining the relationship between the primary domain controller's operating state and its abnormal or normal operating state, thereby improving the accuracy of the first verification result.

[0067] For example, when the trajectory, vehicle control command, or software and / or hardware in the primary domain system is abnormal, it indicates that the primary domain system is in an abnormal operating state. When the trajectory, vehicle control command, and software and / or hardware in the primary domain system are normal, it indicates that the primary domain system is in a normal operating state.

[0068] In this embodiment, the second control data is the data required for the auxiliary domain controller to perform autonomous driving operations on the vehicle. For example, the second control data may include: second trajectory data, second command data, and second fault data of the vehicle. The second trajectory data can be used to represent the trajectory of the vehicle during future driving under the control of the auxiliary domain controller. The second command data can be used to represent the commands of the auxiliary domain controller to control the vehicle. The second fault data can be used to indicate whether the software and / or hardware of the auxiliary domain controller has malfunctioned.

[0069] In this embodiment, the second verification result is used to represent the relationship between the operating state of the secondary domain controller and its abnormal or normal operating state. For example, the second verification result can be used to indicate that the operating state of the secondary domain controller is an abnormal operating state, or it can be used to indicate that the operating state of the secondary domain controller is a normal operating state. This is only an example and is not specifically limited.

[0070] In this embodiment, after acquiring the vehicle's control data, the primary domain controller verifies the second control data to obtain a second verification result. Optionally, based on the acquired vehicle control data, this embodiment verifies the second trajectory data, the second command data, and the second fault data within the second control data to obtain the second verification result of the secondary domain controller. This achieves the goal of determining the relationship between the secondary domain controller's operating state and its abnormal or normal operating state, thereby improving the accuracy of the second verification result.

[0071] For example, when the trajectory, vehicle control command, or software and / or hardware in the auxiliary domain system is abnormal, it indicates that the auxiliary domain system is in an abnormal operating state. When the trajectory, vehicle control command, and software and / or hardware in the auxiliary domain system are normal, it indicates that the auxiliary domain system is in a normal operating state.

[0072] The following description further explains the steps of switching the controller's original operating strategy to the target operating strategy based on the verification results in this embodiment.

[0073] As an optional embodiment, the target operating policy includes: a secondary domain operating policy, a primary domain operating policy, and a security operating policy. The secondary domain operating policy indicates the mode in which the secondary domain controller remains operational and the primary domain controller exits operation. The primary domain operating policy indicates the mode in which the primary domain controller remains operational and the secondary domain controller exits operation. The security operating policy indicates the mode in which the security module of the primary domain controller is operational, or the security module of the secondary domain controller is operational. Step S116, based on the verification result, switches the controller's original operating policy to the target operating policy, including: switching the original operating policy to the secondary domain operating policy in response to the verification result indicating that the primary domain controller's operating state is an abnormal operating state and the secondary domain controller's operating state is a normal operating state; switching the original operating policy to the primary domain operating policy in response to the verification result indicating that the primary domain controller's operating state is a normal operating state and the secondary domain controller's operating state is an abnormal operating state; and switching the original operating policy to the security operating policy in response to the verification result indicating that both the primary domain controller's and secondary domain controller's operating states are abnormal operating states.

[0074] In this embodiment, the target working strategy may include: secondary domain working strategy, primary domain working strategy, and security working strategy.

[0075] In this embodiment, the aforementioned secondary domain operating strategy is used to indicate the manner in which the secondary domain controller remains operational and the primary domain controller exits operation. For example, the aforementioned secondary domain operating strategy is a secondary domain redundancy strategy, which may include: a secondary domain algorithm redundancy strategy and a secondary domain fault redundancy strategy. The aforementioned secondary domain algorithm redundancy strategy can be used to indicate the manner in which the secondary domain controller remains operational and the primary domain controller exits operation when the primary domain controller's trajectory or vehicle control command is abnormal. The aforementioned secondary domain fault redundancy strategy can be used to indicate the manner in which the secondary domain controller remains operational and the primary domain controller exits operation when the primary domain controller has a serious software or hardware fault.

[0076] In this embodiment, after verifying the control data and obtaining the controller's verification result, in response to the verification result indicating that the main domain controller's operating state is abnormal and the auxiliary domain controller's operating state is normal, the original operating strategy is switched to the auxiliary domain operating strategy. Optionally, based on the obtained controller verification result, this embodiment performs result parsing. If the parsed verification result indicates that the main domain controller's operating state is abnormal and the auxiliary domain controller's operating state is normal, then the original operating strategy is switched to the auxiliary domain operating strategy. This achieves the purpose of triggering the auxiliary domain controller, thereby realizing the technical effect of improving the safety of autonomous driving in vehicles.

[0077] In this embodiment, the aforementioned primary domain operating strategy is used to indicate the manner in which the primary domain controller remains operational and the secondary domain controller exits operation. For example, the aforementioned primary domain operating strategy is a primary domain redundancy strategy, which may include: a primary domain algorithm redundancy strategy and a primary domain fault redundancy strategy. The primary domain algorithm redundancy strategy can be used to indicate the manner in which the primary domain controller remains operational and the secondary domain controller exits operation when the secondary domain controller's trajectory or vehicle control command is abnormal. The primary domain fault redundancy strategy can be used to indicate the manner in which the primary domain controller remains operational and the secondary domain controller exits operation when the secondary domain controller has a serious software or hardware fault.

[0078] In this embodiment, after verifying the control data and obtaining the verification result of the controller, in response to the verification result indicating that the working state of the primary domain controller is normal and the working state of the secondary domain controller is abnormal, the original working strategy is switched to the primary domain working strategy.

[0079] Optionally, based on the verification result obtained from the controller, this embodiment performs result parsing on the above verification result. If the parsed verification result indicates that the working state of the main domain controller is normal and the working state of the auxiliary domain controller is abnormal, then the original working strategy is switched to the main domain working strategy, thereby achieving the purpose of triggering the main domain controller and thus realizing the technical effect of improving the safety of autonomous driving of the vehicle.

[0080] In this embodiment, the aforementioned security operating strategy is used to describe the operating mode of the security module of the primary domain controller or the security module of the secondary domain controller. For example, the aforementioned security operating strategy can be a security fallback strategy, which can be used to describe the operating mode of the security fallback modules of the primary and secondary domains when both the primary and secondary domains experience major failures and cannot provide corresponding trajectories.

[0081] In this embodiment, after verifying the control data and obtaining the verification result of the controller, in response to the verification result indicating that the working state of the primary domain controller is abnormal and the working state of the secondary domain controller is abnormal, the original working policy is switched to a safe working policy.

[0082] Optionally, based on the verification result obtained from the controller, this embodiment performs result parsing on the above verification result. If the parsed verification result indicates that the working state of the main domain controller is abnormal and the working state of the auxiliary domain controller is abnormal, then the original working strategy is switched to the safe working strategy. This achieves the purpose of triggering the safety module of the main domain controller or the safety module of the auxiliary domain controller, thereby realizing the technical effect of improving the safety of autonomous driving of the vehicle.

[0083] For example, when controlling a vehicle to perform autonomous driving operations, the following safety redundancy strategies can be invoked:

[0084] Strategy 1, Algorithm Redundancy Strategy: When the trajectory of either the main domain system or the auxiliary domain system is abnormal or the vehicle control command of either domain is abnormal, the Minimum Risk Maneuver (MRM) strategy of the other domain is used for processing.

[0085] Strategy 2, Fault Redundancy Strategy: When a serious software or hardware failure occurs in either the primary domain system or the secondary domain system, the process will be transferred to the MRM process of the other domain.

[0086] Strategy 3, the safety fallback strategy: when the main domain system and the auxiliary domain system cannot effectively execute the normal trajectory or the MRM trajectory, a safety fallback operation is executed, that is, a braking operation is performed in this lane.

[0087] In addition, the actuator arbitrates according to its own rules to select which safety fallback module in the primary and secondary domain systems will perform the safety fallback operation.

[0088] Optionally, when the primary domain system and the secondary domain system are running simultaneously, the dual-domain redundant autonomous driving system calculates which domain system should serve as the master control node. The calculated master control node needs to send a channel enable flag to the actuator, while non-master control nodes need to send a channel enable flag to the actuator.

[0089] Optionally, the channel selection strategy of the above actuator is as follows: the default priority is "master control node > auxiliary control node". When only one channel is enabled, the enabled channel is processed normally. When two channels are enabled, the default priority is "master control node > auxiliary control node". When two channels are enabled and one of them has a communication failure, the failure channel is filtered out through the fault detection mechanism and the normal channel is selected.

[0090] The autonomous driving method for the vehicle described in this application will be further explained below.

[0091] As an optional embodiment, the method further includes: acquiring environmental data of the driving environment in which the vehicle is located, wherein the environmental data is used to represent the state of the driving environment; inputting the environmental data into a first prediction model for trajectory prediction to obtain first trajectory data, wherein the first prediction model is constructed based on a visual language action model; determining the first trajectory data, the vehicle's first instruction data, and the vehicle's first fault data as first control data, wherein the first instruction data is used to represent the instructions of the main domain controller to control the vehicle, and the first fault data is used to represent whether the software and / or hardware of the main domain controller has malfunctioned.

[0092] In this embodiment, the environmental data is used to represent the state of the driving environment. For example, the environmental data can be represented in the form of images or videos.

[0093] In this embodiment, the first prediction model can be constructed based on the Vision-Language-Action (VLA) model.

[0094] In this embodiment, after acquiring the environmental data of the driving environment in which the vehicle is located, the environmental data is input into the first prediction model for trajectory prediction to obtain the first trajectory data.

[0095] Optionally, this embodiment utilizes vehicle sensors to collect different types of sensor data. Environmental identification is performed on these different types of sensor data to obtain environmental data. This environmental data is then input into a first prediction model for trajectory prediction to obtain first trajectory data, which is then output. This achieves the goal of determining the vehicle's trajectory during future driving under the control of the main domain controller, thereby increasing the diversity of the first trajectory data.

[0096] In this embodiment, the first instruction data can be used to represent instructions from the primary domain controller to control the vehicle. For example, the first instruction data can be used to represent instructions from the primary domain system to control the vehicle to perform autonomous driving operations.

[0097] In this embodiment, the first fault data can be used to indicate whether the software and / or hardware of the primary domain controller has malfunctioned. For example, the first fault data can be used to indicate that the software and / or hardware of the primary domain controller has malfunctioned, or it can be used to indicate that the software and / or hardware of the primary domain controller has not malfunctioned.

[0098] In this embodiment, after inputting environmental data into the first prediction model to perform trajectory prediction and obtaining the first trajectory data, the first trajectory data, the vehicle's first command data, and the vehicle's first fault data are determined as the first control data.

[0099] Optionally, in this embodiment, based on the obtained first trajectory data, the first instruction data and the first fault data can be directly determined as the first control data, or the first trajectory data, the first instruction data and the first fault data can be encapsulated to obtain the first control data. This achieves the purpose of determining the data required for the vehicle to be controlled by the main domain controller to perform autonomous driving operations, thereby realizing the technical effect of improving the diversity of the first control data.

[0100] For example, by encapsulating the trajectory, vehicle control commands, and whether there are serious software or hardware faults in the main domain system, the data required for the vehicle to be controlled by the main domain system to perform autonomous driving operations can be obtained.

[0101] The autonomous driving method for the vehicle described in this application will be further explained below.

[0102] As an optional embodiment, the method further includes: inputting environmental data into a second prediction model for trajectory prediction to obtain second trajectory data, wherein the second prediction model is constructed based on an end-to-end model; determining the second trajectory data, the vehicle's second command data, and the vehicle's second fault data as second control data, wherein the second command data is used to represent the commands of the auxiliary domain controller to control the vehicle, and the second fault data is used to represent whether the software and / or hardware of the auxiliary domain controller has failed.

[0103] In this embodiment, the second prediction model is constructed based on an end-to-end (E2E) model.

[0104] In this embodiment, after acquiring the environmental data of the driving environment in which the vehicle is located, the environmental data is input into the second prediction model for trajectory prediction to obtain the second trajectory data.

[0105] Optionally, this embodiment utilizes vehicle sensors to collect different types of sensor data. Environmental identification is then performed on these different types of sensor data to obtain environmental data. This environmental data is input into a second prediction model for trajectory prediction, resulting in second trajectory data. The second trajectory data is then output, thereby achieving the goal of determining the vehicle's trajectory during future driving under the control of the auxiliary domain controller. This enhances the diversity of the second trajectory data.

[0106] In this embodiment, the second instruction data can be used to represent instructions from the secondary domain controller to control the vehicle. For example, the second instruction data can be used to represent instructions from the secondary domain system to control the vehicle to perform autonomous driving operations.

[0107] In this embodiment, the second fault data can be used to indicate whether the software and / or hardware of the secondary domain controller has malfunctioned. For example, the second fault data can be used to indicate that the software and / or hardware of the secondary domain controller has malfunctioned, or it can be used to indicate that the software and / or hardware of the secondary domain controller has not malfunctioned.

[0108] In this embodiment, after inputting environmental data into the second prediction model to perform trajectory prediction and obtaining the second trajectory data, the second trajectory data, the vehicle's second command data, and the vehicle's second fault data are determined as the second control data.

[0109] Optionally, in this embodiment, based on the obtained second trajectory data, the second command data and the second fault data can be directly determined as the second control data, or the second trajectory data, the second command data and the second fault data can be encapsulated to obtain the second control data. This achieves the goal of determining the data required for the auxiliary domain controller to perform autonomous driving operations on the vehicle to be controlled, thereby realizing the technical effect of improving the diversity of the second control data.

[0110] For example, by encapsulating the trajectory, vehicle control commands, and whether there are serious software or hardware faults in the auxiliary domain system, the data required for the vehicle to be controlled by the auxiliary domain system to perform autonomous driving operations can be obtained.

[0111] The following description further explains the steps of determining second scenario data matching the driving scenario from the second scenario dataset according to the second data determination strategy and driving scenario in this embodiment.

[0112] As an optional embodiment, the autonomous driving operation includes: a first type of parking operation and a second type of parking operation. The first type of parking operation is an automatic parking operation performed in a safe area around the vehicle, and the second type of parking operation is an automatic parking operation performed in the vehicle's current lane. In step S118, according to the target working strategy, triggering the controller to control the vehicle to perform the autonomous driving operation includes: according to the target working strategy, triggering the controller to control the vehicle to perform either the first type of parking operation or the second type of parking operation.

[0113] In this embodiment, the parking operation in the above-mentioned autonomous driving operation includes: a first type of parking operation and a second type of parking operation.

[0114] In this embodiment, the first type of parking operation described above is an automatic parking operation performed within a safe area around the vehicle. For example, the first type of parking operation described above can also be referred to as an MRM parking operation.

[0115] In this embodiment, the second type of parking operation described above is an automatic parking operation performed in the vehicle's current lane. For example, the second type of parking operation described above can also be called a lane-based parking operation or a lane-free parking operation.

[0116] In this embodiment, after switching the controller's original operating strategy to the target operating strategy based on the verification results, the controller is triggered according to the target operating strategy to control the vehicle to perform either a first-type parking operation or a second-type parking operation. Optionally, after the original operating strategy has been switched to the target operating strategy, this embodiment triggers the primary domain controller to control the vehicle to perform either a first-type parking operation or a second-type parking operation, or triggers the secondary domain controller to control the vehicle to perform either a first-type parking operation or a second-type parking operation, thereby achieving the goal of timely control of the vehicle when the controller malfunctions, thus realizing the technical effect of improving the safety of autonomous driving.

[0117] For example, according to the above target working strategy, the main domain system is triggered to control the vehicle to perform an MRM parking operation or a parking operation in the current lane, or the auxiliary domain system is triggered to control the vehicle to perform an MRM parking operation or a parking operation in the current lane.

[0118] The following description further explains the steps of triggering the controller and controlling the vehicle to perform a first type of parking operation or a second type of parking operation according to the target working strategy in this embodiment.

[0119] As an optional embodiment, according to the target operating strategy, the controller is triggered to control the vehicle to perform a first type of parking operation or a second type of parking operation, including: in response to the target operating strategy being a secondary domain operating strategy, the secondary domain controller in the controller is triggered to control the vehicle to perform the first type of parking operation, wherein the secondary domain operating strategy is used to indicate the mode in which the secondary domain controller remains active and the mode in which the primary domain controller exits operation; in response to the target operating strategy being a primary domain operating strategy, the primary domain controller in the controller is triggered to control the vehicle to perform the first type of parking operation, wherein the primary domain operating strategy is used to indicate the mode in which the primary domain controller remains active and the mode in which the secondary domain controller exits operation; in response to the target operating strategy being a safety operating strategy, the safety module of the primary domain controller or the safety module of the secondary domain controller is triggered to control the vehicle to perform the second type of parking operation, wherein the safety operating strategy is used to indicate the mode in which the safety module of the primary domain controller or the safety module of the secondary domain controller is active.

[0120] In this embodiment, the aforementioned auxiliary domain operating strategy can be used to represent the mode in which the auxiliary domain controller remains operational and the mode in which the primary domain controller exits operation. For example, the aforementioned auxiliary domain operating strategy is an auxiliary domain redundancy strategy, which may include: an auxiliary domain algorithm redundancy strategy and an auxiliary domain fault redundancy strategy. The aforementioned auxiliary domain algorithm redundancy strategy can be used to represent the mode in which the auxiliary domain controller remains operational and the primary domain controller exits operation when the primary domain controller's trajectory or vehicle control command is abnormal. The aforementioned auxiliary domain fault redundancy strategy can be used to represent the mode in which the auxiliary domain controller remains operational and the primary domain controller exits operation when the primary domain controller has a serious software or hardware fault.

[0121] In this embodiment, after switching the controller's original operating strategy to the target operating strategy based on the verification result, in response to the target operating strategy being a secondary domain operating strategy, the secondary domain controller in the controller is triggered to control the vehicle to perform a first type of parking operation. Optionally, in this embodiment, after the original operating strategy has been switched to the target operating strategy, if the target operating strategy is a secondary domain operating strategy, then according to the secondary domain operating strategy, the secondary domain controller is triggered to control the vehicle to perform a first type of parking operation. This achieves the goal of timely control of the vehicle when the primary domain controller malfunctions, thereby realizing the technical effect of improving the safety of autonomous driving.

[0122] For example, according to the above auxiliary domain working strategy, the auxiliary domain system is triggered to control the vehicle to perform MRM parking operation.

[0123] In this embodiment, the aforementioned primary domain operating strategy is used to indicate the manner in which the primary domain controller remains operational and the secondary domain controller exits operation. For example, the aforementioned primary domain operating strategy is a primary domain redundancy strategy, which may include: a primary domain algorithm redundancy strategy and a primary domain fault redundancy strategy. The primary domain algorithm redundancy strategy can be used to indicate the manner in which the primary domain controller remains operational and the secondary domain controller exits operation when the secondary domain controller's trajectory or vehicle control command is abnormal. The primary domain fault redundancy strategy can be used to indicate the manner in which the primary domain controller remains operational and the secondary domain controller exits operation when the secondary domain controller has a serious software or hardware fault.

[0124] In this embodiment, after switching the controller's original operating strategy to the target operating strategy based on the verification result, in response to the target operating strategy being the primary domain operating strategy, the primary domain controller in the controller is triggered to control the vehicle to perform a first type of parking operation. Optionally, in this embodiment, after the original operating strategy has been switched to the target operating strategy, if the target operating strategy is the primary domain operating strategy, then the primary domain controller is triggered to control the vehicle to perform a first type of parking operation according to the primary domain operating strategy. This achieves the goal of timely control of the vehicle when the secondary domain controller malfunctions, thereby realizing the technical effect of improving the safety of autonomous driving.

[0125] For example, according to the above-mentioned primary domain working strategy, the primary domain system is triggered to control the vehicle to perform MRM parking operations.

[0126] In this embodiment, the aforementioned security operating strategy is used to describe the operating mode of the security module of the primary domain controller or the security module of the secondary domain controller. For example, the aforementioned security operating strategy can be a security fallback strategy, which can be used to describe the operating mode of the security fallback modules of the primary and secondary domains when both the primary and secondary domains experience major failures and cannot provide corresponding trajectories.

[0127] In this embodiment, after switching the controller's original operating strategy to the target operating strategy based on the verification result, in response to the target operating strategy being a safe operating strategy, the safety module of the primary domain controller or the safety module of the secondary domain controller is triggered to control the vehicle to perform a second type of parking operation. Optionally, in this embodiment, after the original operating strategy has been switched to the target operating strategy, if the target operating strategy is a safe operating strategy, then according to the safe operating strategy, the safety module of the primary domain controller or the safety module of the secondary domain controller is triggered to control the vehicle to perform a second type of parking operation. This achieves the goal of timely control of the vehicle when the primary domain controller and the secondary domain controller malfunction, thereby realizing the technical effect of improving the safety of autonomous driving.

[0128] For example, in accordance with the above safety operation strategy, the safety fallback module of the main domain system or the safety fallback module of the auxiliary domain system is triggered to control the vehicle to perform a braking operation in this lane.

[0129] In this embodiment, vehicle control data is acquired; the control data is verified to obtain the controller's verification result; based on the verification result, the controller's original operating strategy is switched to a target operating strategy; and according to the target operating strategy, the controller is triggered to control the vehicle to perform autonomous driving operations. Since this embodiment verifies the acquired vehicle control data, the controller's verification result can be obtained, meaning the relationship between the controller's operating state and its abnormal or normal operating states can be determined. Based on the obtained verification result, the controller's original operating strategy can be switched to the target operating strategy, and according to the switched target operating strategy, the controller is triggered to control the vehicle to perform autonomous driving operations. This achieves the goal of timely vehicle control when the controller malfunctions, solving the technical problem of low autonomous driving safety and realizing the technical effect of improving the safety of autonomous driving.

[0130] The technical solutions of the embodiments of this application will be illustrated below with reference to preferred embodiments.

[0131] Currently, in related technologies, autonomous driving methods often employ a dual-system redundancy approach. This allows the auxiliary system to take over autonomous driving in the event of a failure in the primary system. However, this method cannot guarantee timely control of the vehicle when both systems fail, leading to a technical problem of low safety in autonomous driving.

[0132] However, this application proposes an autonomous driving method for vehicles. Based on the acquired vehicle control data, the method verifies this control data to obtain the controller's verification result. That is, it reveals the relationship between the controller's operating state and its abnormal or normal operating states. Based on the obtained verification result, the controller's original operating strategy can be switched to a target operating strategy. Following this target operating strategy, the controller is triggered to control the vehicle to perform autonomous driving operations. This achieves the goal of timely vehicle control in the event of controller malfunction, solving the technical problem of low autonomous driving safety and realizing a technical effect that improves the safety of autonomous driving.

[0133] In this embodiment, a dual-domain redundant autonomous driving system can utilize both a primary domain system and a secondary domain system to control the vehicle to perform autonomous driving operations. For example, Figure 2 This is a schematic diagram of a dual-domain redundant autonomous driving system according to an embodiment of this application, such as... Figure 2 As shown, the dual-domain redundant autonomous driving system 200 may include a primary domain system 2001 and an auxiliary domain system 2002. The primary domain system 2001 and the auxiliary domain system 2002 may be connected to sensors 201, and may be connected to actuators 202.

[0134] In this embodiment, the main domain system 2001 may include: a trajectory output module 20011, a perception module 20012, a planning and control module 20013, a trajectory optimization module 20014, an active safety module 20015, a trajectory arbitration module 20016, a vehicle control module 20017, a safety backup module 20018, and a fault detection module 20019. Specifically, the trajectory output module 20011 can be connected to the trajectory optimization module 20014, the perception module 20012 can be connected to the planning and control module 20013, the planning and control module 20013 can be connected to the active safety module 20015, the trajectory optimization module 20014 and the active safety module 20015 can be connected to the trajectory arbitration module 20016 respectively, and the vehicle control module 20017 can be connected to the trajectory arbitration module 20016.

[0135] Optionally, the trajectory output module 20011 can be used to output a driving trajectory and / or a trajectory conforming to MRM using a built-in high-order algorithm. This high-order algorithm can be built into the Vision-Language-Action (VLA) model.

[0136] Optionally, the main domain system 2001 can determine the vehicle's trajectory based on the input information from the sensor 201. For example, if the main domain system 2001 does not trigger MRM, it outputs a normal driving trajectory; if the main domain system 2001 triggers MRM, it outputs an MRM trajectory.

[0137] Optionally, the aforementioned sensing module 20012 and control module 20013 can be used to output an active safety trajectory.

[0138] Optionally, the aforementioned trajectory arbitration module 20016 can be used to arbitrate the driving trajectory, MRM trajectory, and active safety trajectory. The arbitration priority is: "Active Safety Trajectory" > "MRM Trajectory" > "Normal Driving Trajectory".

[0139] Optionally, the vehicle control module 20017 can be used to convert the arbitration trajectory into corresponding vehicle control commands and transmit the vehicle control commands to the actuator 202 for vehicle control.

[0140] Optionally, the aforementioned safety fallback module 20018 can be used to monitor the status of the entire autonomous driving system. If an MRM failure or a major software or hardware anomaly is detected, a safety fallback strategy is executed to bring the vehicle to a stop in the current lane.

[0141] Optionally, the aforementioned fault detection module 20019 can be used to collect fault information from all domains during the simultaneous operation of the primary and secondary domains: abnormal trajectory, abnormal vehicle control commands, software and hardware faults, etc., and can be used to provide corresponding degradation strategies based on the comprehensive fault information from the primary and secondary domains, including MRM strategies. The MRM strategies can be used to control the vehicle to stop in the service area, pull over to the side of the road, or stop safely in the same lane, etc.

[0142] In this embodiment, the auxiliary domain system 2002 may include: a trajectory output module 20021, a perception module 20022, a planning and control module 20023, a trajectory optimization module 20024, an active safety module 20025, a trajectory arbitration module 20026, a vehicle control module 20027, a safety backup module 20028, and a fault detection module 20029. Specifically, the trajectory output module 20021 can be connected to the trajectory optimization module 20024, the perception module 20022 can be connected to the planning and control module 20023, the planning and control module 20023 can be connected to the active safety module 20025, the trajectory optimization module 20024 and the active safety module 20025 can be connected to the trajectory arbitration module 20026 respectively, and the vehicle control module 20027 can be connected to the trajectory arbitration module 20026.

[0143] Optionally, the trajectory output module 20021 described above can be used to output driving trajectories and / or trajectories conforming to MRM using built-in high-order algorithms. These high-order algorithms can be built into end-to-end (E2E) models.

[0144] Optionally, the auxiliary domain system 2002 can determine the vehicle's trajectory based on the input information from the sensor 201. For example, if the auxiliary domain system 2002 does not trigger MRM, it outputs a normal driving trajectory; if the auxiliary domain system 2002 triggers MRM, it outputs an MRM trajectory.

[0145] Optionally, the aforementioned sensing module 20022 and control module 20023 can be used to output an active safety trajectory.

[0146] Optionally, the aforementioned trajectory arbitration module 20026 can be used to arbitrate the driving trajectory, MRM trajectory, and active safety trajectory. The arbitration priority is: "Active Safety Trajectory" > "MRM Trajectory" > "Normal Driving Trajectory".

[0147] Optionally, the vehicle control module 20027 can be used to convert the arbitration trajectory into corresponding vehicle control commands and transmit the vehicle control commands to the actuator 202 for vehicle control.

[0148] Optionally, the aforementioned safety fallback module 20028 can be used to monitor the status of the entire autonomous driving system. If an MRM failure or a major software or hardware anomaly is detected, a safety fallback strategy is executed to bring the vehicle to a stop in the current lane.

[0149] Optionally, the aforementioned fault detection module 20029 can be used to collect fault information from all domains during the simultaneous operation of the primary and secondary domains: abnormal trajectory, abnormal vehicle control commands, software and hardware faults, etc., and can be used to provide corresponding degradation strategies based on the comprehensive fault information from the primary and secondary domains, including MRM strategies. The MRM strategies can be used to control the vehicle to stop in the service area, pull over to the side of the road, or stop safely in the lane, etc.

[0150] In this embodiment, the sensor 201 may include: a front-view camera 2011, a surround-view camera 2012, a panoramic camera 2013, a rear-view camera 2014, a millimeter-wave radar 2015, a front lidar 2016, and an ultrasonic radar 2017, etc.

[0151] In this embodiment, the actuator 202 may include: a drive actuator 2021, a brake actuator 2022, a steering actuator 2023, and a body actuator 2024, etc.

[0152] Optionally, the dual-domain redundant autonomous driving system 200 is configured with the following safety redundancy strategies:

[0153] Strategy 1, Algorithm Redundancy Strategy: When the trajectory of either the main domain system 2001 or the auxiliary domain system 2002 is abnormal or the vehicle control command of either domain is abnormal, the process will enter the MRM processing of the other domain.

[0154] Strategy 2, Fault Redundancy Strategy: When a serious software or hardware fault occurs in either the primary domain system 2001 or the secondary domain system 2002, the fault is transferred to the MRM process of the other domain.

[0155] Strategy 3, the safety fallback strategy: when the main domain system 2001 and the auxiliary domain system 2002 cannot effectively execute the normal trajectory or MRM trajectory, a safety fallback operation is executed, that is, a braking operation is performed in this lane.

[0156] In addition, the actuator 202 arbitrates according to its own rules to select which safety fallback module in the primary and secondary domain systems will perform the safety fallback operation.

[0157] Optionally, when the primary domain system 2001 and the secondary domain system 2002 are running simultaneously, the dual-domain redundant automatic driving system 200 calculates which of the two domain systems to serve as the master control node. The calculated master control node needs to send a channel enable flag to the actuator, while non-master control nodes need to send a channel enable flag to the actuator.

[0158] Optionally, the channel selection strategy of the actuator 202 is as follows: the default priority is "master node > auxiliary node". When only one channel is enabled, the enabled channel is processed normally. When two channels are enabled, the default priority is "master node > auxiliary node". When two channels are enabled and one of them has a communication failure, the failure channel is filtered out through the fault detection mechanism and the normal channel is selected.

[0159] In this embodiment, the deployment method of the above-mentioned dual-domain redundant autonomous driving system can be as follows: Figure 3 As shown, Figure 3 This is a schematic diagram of a deployment method for a dual-domain redundant autonomous driving system according to an embodiment of this application.

[0160] like Figure 3 As shown, the dual-domain redundant autonomous driving system 200 can be integrated into an electronic control box (Box Unit, hereinafter referred to as Box) 300 and a printed circuit board (PCB) 301. The dual-domain redundant autonomous driving system 200 can include a primary domain system 2001 and a secondary domain system 2002. The primary domain system 2001 and the secondary domain system 2002 can be integrated into the PCB 301, and the PCB 301 can be integrated into the electronic control box 300.

[0161] In this embodiment, the deployment method of the above-mentioned dual-domain redundant autonomous driving system can be as follows: Figure 4 As shown, Figure 4 This is a schematic diagram illustrating another deployment method of a dual-domain redundant autonomous driving system according to an embodiment of this application. The dual-domain redundant autonomous driving system 200 can be integrated into an electronic control box 400 and two printed circuit boards 401 to 402. The dual-domain redundant autonomous driving system 200 can include a primary domain system 2001 and a secondary domain system 2002. Specifically, the primary domain system 2001 can be integrated into printed circuit board 401, the secondary domain system 2002 can be integrated into printed circuit board 402, and printed circuit boards 401 to 402 can be integrated into the electronic control box 400.

[0162] In this embodiment, the deployment method of the above-mentioned dual-domain redundant autonomous driving system can be as follows: Figure 5 As shown, Figure 5 This is a schematic diagram of another deployment method of a dual-domain redundant autonomous driving system according to an embodiment of this application.

[0163] like Figure 5As shown, the dual-domain redundant autonomous driving system 200 can be integrated into two electronic control boxes 500 to 501, and two printed circuit boards 5001 and 5011. The dual-domain redundant autonomous driving system 200 can include a primary domain system 2001 and a secondary domain system 2002. Specifically, the primary domain system 2001 can be integrated into printed circuit board 5001, the secondary domain system 2002 can be integrated into printed circuit board 5011, printed circuit board 5001 can be integrated into electronic control box 500, and printed circuit board 5011 can be integrated into electronic control box 501.

[0164] In this embodiment, the deployment method of the above-mentioned dual-domain redundant autonomous driving system can be as follows: Figure 6 As shown, Figure 6 This is a schematic diagram illustrating another deployment method of a dual-domain redundant autonomous driving system according to an embodiment of this application. The dual-domain redundant autonomous driving system 200 can be integrated into two electronic control boxes 600 to 601, and four printed circuit boards 6001, 6002, 6011, and 6012. The dual-domain redundant autonomous driving system 200 can include a main domain system 2001 and an auxiliary domain system 2002. Specifically, the trajectory output module 20011, trajectory optimization module 20014, trajectory arbitration module 20016, vehicle control module 20017, safety backup module 20018, and fault detection module 20019 in the main domain system 2001 can be integrated into printed circuit board 6001. The perception module 20012, trajectory control module 20013, and active safety module 20015 in the main domain system 2001 can be integrated into printed circuit board 6002. The trajectory output module 20021, trajectory optimization module 20022, trajectory arbitration module 20013, and active safety module 20015 in the auxiliary domain system 2002 can be integrated into printed circuit board 6002. The following modules can be integrated into the printed circuit board 6011: the sensing module 20024, the trajectory arbitration module 20026, the vehicle control module 20027, the safety backup module 20028, and the fault detection module 20029. The following modules can be integrated into the printed circuit board 6012: the sensing module 20022, the control module 20023, and the active safety module 20025 in the auxiliary domain system 2002. The printed circuit boards 6001 and 6002 can be integrated into the electronic control box 600, and the printed circuit boards 6011 and 6012 can be integrated into the electronic control box 601.

[0165] In this embodiment, based on the acquired vehicle control data, the control data is verified to obtain the controller's verification result. That is, the relationship between the controller's operating state and its abnormal or normal operating states can be determined. Based on the obtained verification result, the controller's original operating strategy can be switched to a target operating strategy. Following the switched target operating strategy, the controller is triggered to control the vehicle to perform autonomous driving operations. This achieves the goal of timely vehicle control in the event of controller malfunction, solving the technical problem of low autonomous driving safety and realizing the technical effect of improving the safety of autonomous driving.

[0166] According to another aspect of the embodiments of this application, corresponding to the embodiments of the above-described autonomous driving method for vehicles, the embodiments of this application also provide an autonomous driving device for vehicles. Figure 7 This is a structural block diagram of an autonomous driving device for a vehicle according to an embodiment of this application, such as... Figure 7 As shown, the autonomous driving device 700 of the vehicle may include: a first acquisition unit 702, a verification unit 704, a switching unit 706, and an execution unit 708.

[0167] The first acquisition unit 702 is used to acquire vehicle control data, wherein the control data is the data required by the controller to control the vehicle to perform autonomous driving operations.

[0168] The verification unit 704 is used to verify the control data and obtain the verification result of the controller. The verification result is used to represent the relationship between the controller's working state and abnormal working state or normal working state.

[0169] The switching unit 706 is used to switch the controller's original working strategy to a target working strategy based on the verification result. The original working strategy represents the controller's working mode before the switching of the working state, and the target working strategy represents the controller's working mode after the switching of the working state.

[0170] The execution unit 708 is used to trigger the controller to control the vehicle to perform autonomous driving operations according to the target working strategy.

[0171] Optionally, the verification unit 704 may include: a verification module, used to control the secondary domain controller to verify the first control data and obtain a first verification result; and to control the primary domain controller to verify the second control data and obtain a second verification result.

[0172] Optionally, the switching unit 706 may include: a first switching module, configured to switch the original working policy to the secondary domain working policy in response to a verification result indicating that the primary domain controller is in an abnormal working state and the secondary domain controller is in a normal working state; a second switching module, configured to switch the original working policy to the primary domain working policy in response to a verification result indicating that the primary domain controller is in a normal working state and the secondary domain controller is in an abnormal working state; and a third switching module, configured to switch the original working policy to a secure working policy in response to a verification result indicating that the primary domain controller is in an abnormal working state and the secondary domain controller is in an abnormal working state.

[0173] Optionally, the autonomous driving device 700 of the vehicle may further include: a second acquisition unit, configured to acquire environmental data of the driving environment in which the vehicle is located, wherein the environmental data is used to represent the state of the driving environment; a first prediction unit, configured to input the environmental data into a first prediction model to perform trajectory prediction and obtain first trajectory data, wherein the first prediction model is constructed based on a visual language action model; and a first determination unit, configured to determine the first trajectory data, the vehicle's first instruction data, and the vehicle's first fault data as first control data, wherein the first instruction data is used to represent the instruction of the main domain controller to control the vehicle, and the first fault data is used to represent whether the software and / or hardware of the main domain controller has malfunctioned.

[0174] Optionally, the autonomous driving device 700 of the vehicle may further include: a second prediction unit, configured to input environmental data into a second prediction model for trajectory prediction to obtain second trajectory data, wherein the second prediction model is constructed based on an end-to-end model; and a second determination unit, configured to determine the second trajectory data, the vehicle's second instruction data, and the vehicle's second fault data as second control data, wherein the second instruction data is used to represent the instructions of the auxiliary domain controller to control the vehicle, and the second fault data is used to represent whether the software and / or hardware of the auxiliary domain controller has malfunctioned.

[0175] Optionally, the execution unit 708 may include an execution module for triggering the controller to control the vehicle to perform a first type of parking operation or a second type of parking operation according to the target working strategy.

[0176] Optionally, the execution module may include: a first execution submodule, configured to, in response to a target working policy being a secondary domain working policy, trigger a secondary domain controller in the controller to control the vehicle to perform a first type of parking operation, wherein the secondary domain working policy indicates the mode in which the secondary domain controller remains active and the primary domain controller exits operation; a second execution submodule, configured to, in response to a target working policy being a primary domain working policy, trigger a primary domain controller in the controller to control the vehicle to perform a first type of parking operation, wherein the primary domain working policy indicates the mode in which the primary domain controller remains active and the secondary domain controller exits operation; and a third execution submodule, configured to, in response to a target working policy being a safety working policy, trigger a safety module of the primary domain controller or a safety module of the secondary domain controller to control the vehicle to perform a second type of parking operation, wherein the safety working policy indicates the mode in which the safety module of the primary domain controller or the safety module of the secondary domain controller operates.

[0177] In this embodiment, the autonomous driving device of the vehicle includes the following units: a first acquisition unit, used to acquire vehicle control data, wherein the control data is the data required by the controller to control the vehicle to perform autonomous driving operations; a verification unit, used to verify the control data and obtain the verification result of the controller, wherein the verification result is used to represent the relationship between the controller's working state and abnormal working state or normal working state; a switching unit, used to switch the controller's original working strategy to a target working strategy based on the verification result, wherein the original working strategy is used to represent the controller's working mode before the switching of the working state, and the target working strategy is used to represent the controller's working mode after the switching of the working state; and an execution unit, used to trigger the controller to control the vehicle to perform autonomous driving operations according to the target working strategy, thereby achieving the purpose of timely control of the vehicle when the controller is abnormal, solving the technical problem of low autonomous driving safety of the vehicle, and realizing the technical effect of improving the autonomous driving safety of the vehicle.

[0178] Embodiments of this application also provide an electronic device, including: a memory storing an executable program; and a processor for running the program, wherein the program executes the methods in various embodiments of this application when it runs.

[0179] Embodiments of this application also provide a computer-readable storage medium including a stored executable program, wherein, when the executable program is running, it controls the device where the computer-readable storage medium is located to perform the methods of various embodiments of this application.

[0180] Embodiments of this application also provide a computer program product, including a computer program that, when executed by a processor, implements the methods of various embodiments of this application.

[0181] Embodiments of this application also provide a computer program product, including a non-volatile computer-readable storage medium for storing a computer program that, when executed by a processor, implements the methods in various embodiments of this application.

[0182] Embodiments of this application also provide a computer program that, when executed by a processor, implements the methods described in the various embodiments of this application.

[0183] Embodiments of this application also provide a vehicle that includes the electronic devices described in this application.

[0184] In the above embodiments of this application, the descriptions of each embodiment have different focuses. For parts not described in detail in a certain embodiment, please refer to the relevant descriptions of other embodiments.

[0185] According to an embodiment of this application, an electronic device is also provided. Figure 8 This is a schematic diagram of an electronic device according to an embodiment of this application, such as... Figure 8 As shown, the electronic device 800 may include a memory 810 and a processor 820, wherein the memory 810 is used to store an executable program; and the processor 820 is used to run the program stored in the memory 810, and the program executes the method of this application when it runs.

[0186] In this application, "multiple" refers to two or more.

[0187] In this application, unless otherwise expressly defined, the terms "installation," "connection," and "linking" should be interpreted broadly. For example, they can refer to a fixed connection, a detachable connection, or an integral connection; they can refer to a mechanical connection or an electrical connection; they can refer to a direct connection or an indirect connection through an intermediate medium; and they can refer to the internal connection between two components. Those skilled in the art can understand the specific meaning of the above terms in this application based on the specific circumstances.

[0188] The terms “first,” “second,” “third,” “fourth,” etc., in this application (if present) are used to distinguish similar objects and are not necessarily used to describe a specific order or sequence.

[0189] In this application, the term "and / or" is merely a description of the relationship between related objects, indicating that three relationships can exist. For example, A and / or B can represent: A existing alone, A and B existing simultaneously, or B existing alone. Additionally, in this application, the character " / " generally indicates that the preceding and following related objects have an "or" relationship.

[0190] According to another aspect of the embodiments of this application, a computer-readable storage medium is also provided. The computer-readable storage medium includes a stored program, wherein, when the program is executed, it controls the device on which the computer-readable storage medium is located to perform the device control method for the vehicle in the embodiment.

[0191] Computer-readable storage media, also known as computer storage media, may include data signals propagated in baseband or as part of a carrier wave, carrying readable program code. These propagated data signals may take various forms, including but not limited to electromagnetic signals, optical signals, or any suitable combination thereof. Computer-readable storage media can transmit, propagate, or transfer programs for use by or in conjunction with an instruction execution system, apparatus, or device.

[0192] The program code contained in a computer-readable storage medium may be transmitted using any suitable medium, including but not limited to wireless, wired, optical fiber, radio frequency, or any suitable combination thereof.

[0193] In the embodiments provided in this application, it should be understood that the disclosed technical content can be implemented in other ways. The device embodiments described above are merely illustrative; for example, the division of units can be a logical functional division, and in actual implementation, there may be other division methods. For instance, multiple units or components may be combined or integrated into another system, or some features may be ignored or not executed. Furthermore, the displayed or discussed mutual coupling, direct coupling, or communication connection may be through some interfaces; the indirect coupling or communication connection between units or modules may be electrical or other forms.

[0194] The units described as separate components may or may not be physically separate. The components shown as units may or may not be physical units; that is, they may be located in one place or distributed across multiple units. Some or all of the units can be selected to achieve the purpose of this embodiment according to actual needs.

[0195] Furthermore, the functional units in the various embodiments of this application can be integrated into one processing unit, or each unit can exist physically separately, or two or more units can be integrated into one unit. The integrated unit can be implemented in hardware or as a software functional unit.

[0196] If the integrated unit is implemented as a software functional unit and sold or used as an independent product, it can be stored in a computer-readable storage medium. Based on this understanding, the technical solution of this application, in essence, or the part that contributes to the prior art, or all or part of the technical solution, can be embodied in the form of a software product. This computer software product is stored in a storage medium and includes several instructions to cause a computer device (which may be a personal computer, server, or network device, etc.) to execute all or part of the steps of the methods described in the various embodiments of this application. The aforementioned storage medium includes various media capable of storing program code, such as USB flash drives, read-only memory (ROM), random access memory (RAM), portable hard drives, magnetic disks, or optical disks.

[0197] The above description is only a preferred embodiment of this application. It should be noted that for those skilled in the art, several improvements and modifications can be made without departing from the principle of this application, and these improvements and modifications should also be considered within the scope of protection of this application.

Claims

1. An autonomous driving method for a vehicle, characterized in that, An autonomous driving system applied to the vehicle, the autonomous driving system comprising: a controller, the method comprising: Acquire control data of the vehicle, wherein the control data is the data required by the controller to control the vehicle to perform autonomous driving operations; The control data is verified to obtain the verification result of the controller, wherein the verification result is used to represent the relationship between the working state of the controller and the abnormal working state or the normal working state. Based on the verification result, the original working strategy of the controller is switched to the target working strategy, wherein the original working strategy is used to represent the working mode of the controller before the switching of the working state, and the target working strategy is used to represent the working mode of the controller after the switching of the working state. According to the target working strategy, the controller is triggered to control the vehicle to perform the autonomous driving operation.

2. The method according to claim 1, characterized in that, The controller includes a primary domain controller and a secondary domain controller. The control data includes first control data and second control data. The first control data is the data required by the primary domain controller to control the vehicle to perform the autonomous driving operation. The second control data is the data required by the secondary domain controller to control the vehicle to perform the autonomous driving operation. The verification result includes a first verification result of the primary domain controller and a second verification result of the secondary domain controller. The first verification result is used to represent the relationship between the working state of the primary domain controller and the abnormal working state or the normal working state. The second verification result is used to represent the relationship between the working state of the secondary domain controller and the abnormal working state or the normal working state. Verifying the control data to obtain the controller's verification result includes: The auxiliary domain controller is controlled to verify the first control data to obtain the first verification result; and... The main domain controller is controlled to verify the second control data to obtain the second verification result.

3. The method according to claim 2, characterized in that, The target operating policy includes: a secondary domain operating policy, a primary domain operating policy, and a security operating policy. The secondary domain operating policy indicates the mode in which the secondary domain controller remains operational and the primary domain controller exits operation. The primary domain operating policy indicates the mode in which the primary domain controller remains operational and the secondary domain controller exits operation. The security operating policy indicates the mode in which the security module of the primary domain controller is operational, or the security module of the secondary domain controller is operational. Based on the verification result, switching the controller's original operating policy to the target operating policy includes: In response to the verification result indicating that the primary domain controller is in the abnormal working state and the secondary domain controller is in the normal working state, the original working policy is switched to the secondary domain working policy. In response to the verification result indicating that the primary domain controller is in the normal working state and the secondary domain controller is in the abnormal working state, the original working policy is switched to the primary domain working policy. In response to the verification result indicating that the primary domain controller and the secondary domain controller are both in an abnormal working state, the original working policy is switched to the secure working policy.

4. The method according to claim 2, characterized in that, The method further includes: Obtain environmental data of the driving environment in which the vehicle is located, wherein the environmental data is used to represent the state of the driving environment; The environmental data is input into the first prediction model for trajectory prediction to obtain the first trajectory data, wherein the first prediction model is constructed based on the visual language action model; The first trajectory data, the first command data of the vehicle, and the first fault data of the vehicle are determined as the first control data, wherein the first command data is used to represent the command of the main domain controller to control the vehicle, and the first fault data is used to represent whether the software and / or hardware of the main domain controller has failed.

5. The method according to claim 4, characterized in that, The method further includes: The environmental data is input into the second prediction model for trajectory prediction to obtain the second trajectory data, wherein the second prediction model is constructed based on an end-to-end model; The second trajectory data, the second command data of the vehicle, and the second fault data of the vehicle are determined as the second control data, wherein the second command data is used to represent the command of the auxiliary domain controller to control the vehicle, and the second fault data is used to represent whether the software and / or hardware of the auxiliary domain controller has failed.

6. The method according to claim 1, characterized in that, The autonomous driving operation includes: a first type of parking operation and a second type of parking operation. The first type of parking operation is an automatic parking operation performed within a safe area surrounding the vehicle, and the second type of parking operation is an automatic parking operation performed within the vehicle's current lane. The autonomous driving operation is triggered by the controller according to the target operating strategy, including: According to the target working strategy, the controller is triggered to control the vehicle to perform either the first type of parking operation or the second type of parking operation.

7. The method according to claim 6, characterized in that, According to the target working strategy, the controller is triggered to control the vehicle to perform either the first type of parking operation or the second type of parking operation, including: In response to the target working strategy being a secondary domain working strategy, the secondary domain controller in the controller is triggered to control the vehicle to perform the first type of parking operation, wherein the secondary domain working strategy is used to indicate the mode in which the secondary domain controller remains active and the mode in which the primary domain controller exits its active state. In response to the target working policy being the primary domain working policy, the primary domain controller in the controller is triggered to control the vehicle to perform the first type of parking operation, wherein the primary domain working policy is used to indicate the way in which the primary domain controller remains active and the secondary domain controller exits active. In response to the target operating policy being a safe operating policy, the security module of the primary domain controller or the security module of the secondary domain controller is triggered to control the vehicle to perform the second type of parking operation, wherein the safe operating policy is used to indicate the mode in which the security module of the primary domain controller or the security module of the secondary domain controller operates.

8. An automatic driving device for a vehicle, characterized in that, The autonomous driving device is deployed in the vehicle's autonomous driving system, the autonomous driving system including: a controller, and the device including: The first acquisition unit is used to acquire the control data of the vehicle, wherein the control data is the data required by the controller to control the vehicle to perform autonomous driving operations; A verification unit is used to verify the control data and obtain the verification result of the controller, wherein the verification result is used to represent the relationship between the working state of the controller and the abnormal working state or the normal working state. A switching unit is used to switch the original working strategy of the controller to a target working strategy based on the verification result, wherein the original working strategy represents the working mode of the controller before the switching of the working state, and the target working strategy represents the working mode of the controller after the switching of the working state. An execution unit is used to trigger the controller to control the vehicle to perform the autonomous driving operation according to the target working strategy.

9. A computer-readable storage medium, characterized in that, The computer-readable storage medium includes a stored executable program, wherein, when the executable program is executed, it controls the device on which the storage medium is located to perform the method according to any one of claims 1 to 7.

10. An electronic device, characterized in that, include: Memory, which stores executable programs; A processor for running the program, wherein the program, when running, performs the method according to any one of claims 1 to 7.