A safety redundancy control method and control system for an autonomous vehicle
By detecting the fault device to generate fault code values and combining environmental information to generate control signals, the safety control problem of autonomous driving vehicles when the actuator or sensor fails, and the safety driving level of the vehicle is improved.
Patent Information
- Application Number
- CN202210844433.X
- Authority / Receiving Office
- CN · China
- Patent Type
- Patents(China)
- Current Assignee / Owner
- Filing Date
- 2022-07-18
- Publication Date
- 2025-07-08
- Estimated Expiration
- 2042-07-18
AI Technical Summary
When the actuator or sensor fails, existing autonomous vehicles cannot achieve safety control in a timely and effective manner, and there are safety risks and accident hazards. The existing redundant design increases hardware costs and depends on driver responses.
By detecting the status of the vehicle fault equipment, generating a fault code value, integrating the fault code value to obtain a safety control strategy, combining the vehicle's surrounding environment information to generate a horizontal and vertical control signal, and performing safety redundant control, including the perception fusion module, planning control module, safety decision module and execution module closed-loop control.
The safe driving level of autonomous vehicles when the actuator or sensor fails, achieve timely and effective safety control, and reduce the risk of accidents.
Smart Images

Figure CN115257791B_ABST
Abstract
Description
Technical Field
[0001] The present invention relates to the field of autonomous driving control, and more particularly, to a safety redundancy control method and control system for an autonomous vehicle. Background Art
[0002] With the increasing number of vehicles with autonomous driving or assisted driving functions on the market, accidents caused by the failure of actuators and increasingly complex sensors have been reported from time to time.
[0003] Facing such failures, the common solutions for existing vehicles typically include:
[0004] (1) Adding redundant actuators or sensors to avoid single-point failures. Once the primary actuator or sensor fails, the system switches to the backup component, and the rated functions and performance usually remain unchanged.
[0005] (2) Adding self-fault diagnosis methods and signal inspection methods for upstream signals. When a failure occurs, the failed actuator with self-diagnosis logic will reduce its rated functions and performance and announce the fault status in real time within the relevant domain. The related controller will then reduce its rated functions and performance according to the above fault status and its own signal inspection logic, thereby reducing the functions and performance of the entire vehicle system.
[0006] (3) Adding warning and prompting functions in the functional design. Once an actuator or sensor fails, it will prompt the driver to pay attention and handle it in the form of sound, light, and image.
[0007] Defects of the above solutions: The redundancy design shown in the first solution increases the cost and complexity of the hardware system and is difficult to adapt to system upgrades and changes. The diagnostic and warning prompt function designs shown in the second and third solutions do not truly solve the ultimate problem of the safety of the vehicle and its passengers and crew, but leave the responsibility for safety decision-making and risk avoidance implementation to the driver. Since the understanding of prompt information by human drivers varies from person to person, and the delay in timely handling and takeover also varies from person to person, this will lead to a large degree of uncertainty in the risk of accidents and the possible degree of harm. Summary of the Invention
[0008] In view of the technical problems existing in the prior art, the present invention provides a safety redundancy control method and control system for an autonomous vehicle.
[0009] According to a first aspect of the present invention, there is provided a safety redundancy method for an autonomous vehicle, including:
[0010] Detecting the fault status of each faulty device of the vehicle and generating a fault code value for each faulty device;
[0011] Integrate the fault code values of each faulty device to obtain the integrated fault code value, and based on the integrated fault code value, obtain the corresponding safety control strategy;
[0012] Generate the longitudinal and lateral control signals of the vehicle according to the vehicle surrounding environment information and the safety control strategy;
[0013] Execute the safety redundancy control of the vehicle based on the longitudinal and lateral control signals.
[0014] On the basis of the above technical solution, the present invention can also be improved as follows.
[0015] Optionally, detect the fault status of each faulty device of the vehicle based on a fault code table, and the fault code table describes the faults that can be identified by the autonomous driving domain;
[0016] The fault code table includes multiple fields, and the multiple fields include a fault code value field, a fault description field, a faulty device field, a monitoring subject field, a fault type field, a fault diagnosis parameter field, and a fault situation value field;
[0017] The faulty device field is used to describe the entity where the fault occurs;
[0018] The monitoring subject field is used to describe the entity that detects the occurrence of the fault;
[0019] The fault type field represents the type of the fault, and the type of the fault includes one or more of signal timeout, signal interruption, timing error, and data anomaly;
[0020] The fault code value field is a unique numerical code calculated according to other fields;
[0021] The fault diagnosis parameter field is used to describe the diagnostic parameter information for the monitoring subject to monitor and detect the faulty device;
[0022] The fault situation value field characterizes the fault situation distribution when the vehicle has a corresponding fault, and the fault situation distribution is the distribution of the safety risks faced in the surrounding grid.
[0023] Optionally, the integrating the fault code values of each faulty device to obtain the integrated fault code value, and based on the integrated fault code value, obtaining the corresponding safety control strategy includes:
[0024] According to the fault code values of each faulty device, find the corresponding fault situation value in the fault code table;
[0025] According to the fault situation values of each faulty device, obtain the fault situation distribution within the grid around the vehicle;
[0026] Obtain the fault decision level of the vehicle based on the fault situation distribution within the grid around the vehicle;
[0027] Obtain the corresponding safety control strategy based on the fault decision level.
[0028] Optionally, obtaining the fault situation distribution within the grid around the vehicle according to the fault situation values of each faulty device includes:
[0029] Sum the fault situation values of each faulty device to obtain the sum of fault situations;
[0030] Obtain the fault situation distribution within the grid around the vehicle according to the sum of fault situations.
[0031] Optionally, there are multiple fault decision levels, and each fault decision level corresponds to a safety control strategy.
[0032] Optionally, the safety control strategies include a parking strategy, a braking strategy, a limiting strategy, a timely mode strategy, and an audible and visual alarm strategy.
[0033] According to the second aspect of the present invention, there is provided a safety redundancy control system for an autonomous vehicle, including a perception fusion module, a planning and control module, a safety decision module, and an execution module;
[0034] The perception fusion module is used to perceive and fuse the environmental information around the vehicle, detect the fault states of each faulty device of the vehicle and generate fault code values of each faulty device, send the environmental information around the vehicle to the planning and control module, and send the fault code values of each faulty device to the safety decision module;
[0035] The safety decision module is used to integrate the fault code values of each faulty device to obtain the integrated fault code values, obtain the corresponding safety control strategy based on the integrated fault code values, and send the safety control strategy to the planning and control module; and send the longitudinal and lateral control signals sent by the planning and control module to the execution module;
[0036] The planning and control module is used to generate longitudinal and lateral control signals of the vehicle according to the environmental information around the vehicle and the safety control strategy, and send the longitudinal and lateral control signals to the safety decision module;
[0037] The execution module is used to execute the safety redundancy control of the vehicle based on the longitudinal and lateral control signals.
[0038] Optionally, the perception fusion module sending the environmental information around the vehicle to the planning and control module and sending the fault code values of each faulty device to the safety decision module includes:
[0039] The perception fusion module carries the environmental information around the vehicle and the fault code values of each faulty device in their respective heartbeat messages, and periodically sends them to the planning and control module and the safety decision module respectively in the form of heartbeat messages.
[0040] Optionally, it further includes a human-machine interaction module;
[0041] The safety decision module is used to generate a control signal according to the safety control strategy that can take effect directly on itself and send it to the execution module, so that the execution module drives the vehicle according to the control signal; and for the safety control strategy that cannot take effect directly on itself, it sends it to the planning and control module and the human-machine interaction module through a safety request message, so that the planning and control module and the human-machine interaction module execute the safety control strategy.
[0042] According to a third aspect of the present invention, there is provided an electronic device, including a memory and a processor, and the processor is used to implement the steps of the safety redundancy control method for an autonomous driving vehicle when executing a computer management program stored in the memory.
[0043] According to a fourth aspect of the present invention, there is provided a computer-readable storage medium, on which a computer management program is stored, and the computer management program implements the steps of the safety redundancy control method for an autonomous driving vehicle when executed by a processor.
[0044] A safety redundancy control method and control system for an autonomous driving vehicle provided by the present invention detect the environmental information around the vehicle and the fault states of each faulty device of the vehicle, obtain a safety control strategy based on the fault code values of each faulty device; generate lateral and longitudinal control signals of the vehicle based on the environmental information around the vehicle and the safety control strategy; perform safety redundancy control of the vehicle based on the lateral and longitudinal control signals of the vehicle, solving the problem that existing autonomous driving vehicles cannot timely and effectively achieve vehicle safety control when actuators or sensors fail, thereby improving the safety driving level of the vehicle. Description of the Drawings
[0045] Figure 1 It is a schematic flow chart of a safety redundancy control method for an autonomous driving vehicle provided by the present invention;
[0046] Figure 2 It is a schematic diagram of the fault situation distribution;
[0047] Figure 3 It is a schematic structural diagram of a safety redundancy control system for an autonomous driving vehicle provided by an embodiment of the present invention;
[0048] Figure 4Schematic diagram of the structure of a safety redundancy control system for an autonomous vehicle provided by an embodiment of the present invention;
[0049] Figure 5 Schematic diagram of the signal flow of the safety redundancy control system for an autonomous vehicle;
[0050] Figure 6 Schematic diagram of the hardware structure of a possible electronic device provided by the present invention;
[0051] Figure 7 Schematic diagram of the hardware structure of a possible computer-readable storage medium provided by the present invention. Detailed implementation manners
[0052] The following further describes in detail the specific implementation manners of the present invention in conjunction with the accompanying drawings and embodiments. The following embodiments are used to illustrate the present invention, but are not used to limit the scope of the present invention.
[0053] Figure 1 A safety redundancy control method for an autonomous vehicle provided by the present invention, the safety redundancy control method mainly includes the following steps:
[0054] S1. Detect the fault states of various faulty devices of the vehicle and generate fault code values for each faulty device.
[0055] As an embodiment, detect the fault states of various faulty devices of the vehicle based on a fault code table, and the fault code table describes all faults that can be identified in the autonomous driving domain; the fault code table includes multiple fields, and the multiple fields include a fault code value field, a fault description field, a faulty device field, a monitoring subject field, a fault type field, a fault diagnosis parameter field, and a fault situation value field.
[0056] Among them, the faulty device field is used to describe the entity where the fault occurs; the monitoring subject field is used to describe the entity that detects the occurrence of the fault; the fault type field represents the type of the fault, and the type of the fault includes one or more of signal timeout, signal interruption, timing error, and data anomaly; the fault code value field is a unique numerical code calculated according to other fields; the fault diagnosis parameter field is used to describe the diagnostic parameter information for the monitoring subject to monitor and detect the faulty device; the fault situation value field characterizes the fault situation distribution when the vehicle has a corresponding fault, and the fault situation distribution is the distribution of the safety risks faced in the surrounding grid.
[0057] It can be understood that a fault code table is maintained for the fault states of various devices (including various actuators or sensors) of the vehicle, as shown in Table 1.
[0058] Table 1 Fault code table
[0059]
[0060] Among them, the fault code table defines the faults that the autonomous driving domain can identify. Their meanings are given in the fault description field. The meanings of each field in the fault code table are as follows:
[0061] The faulty device field is used to describe the entity where the fault occurs. According to the definition of the autonomous driving system, all actuators and sensors related to autonomous driving are assigned an ID. The ID of the front camera in the 11-generation example shown in Table 1.
[0062] The monitoring entity field represents the software module that monitors and diagnoses this fault, indicating the entity that monitors the faulty device. According to the definition of the autonomous driving software system, all software modules of the autonomous driving software system are assigned an ID. The ID of the perception fusion module in the 46-generation example shown in the table.
[0063] The fault type field represents the type of the fault, which can classify all faults in the autonomous driving system. The fault categories include signal timeout, signal interruption, timing error, data anomaly, etc. Each type of fault is assigned an ID. The ID of the signal interruption fault category in the 02-generation example shown in Table 1.
[0064] The fault code value field is the unique value calculated from the above IDs according to a certain rule. The 289800775 shown in Table 1 represents that a signal interruption fault has occurred in the front camera of the autonomous driving system.
[0065] The fault diagnosis parameter field is used when the monitoring entity monitors and detects the fault. The 100ms shown in Table 1 means that the perception fusion module determines that this fault has occurred 100ms after detecting that the signal of the front camera times out.
[0066] The fault situation value field is used for safety decision-making and control, which describes the distribution of the safety risks faced by the vehicle in the grid around the vehicle when this fault occurs. For example Figure 2 As shown, the area around the vehicle is divided into 6 grids. When a certain fault occurs in the vehicle, the safety risk levels in its 6 grids. Let the value in each grid can be filled with four levels from 0 to 3, representing different safety risk levels, indicating the fault situation distribution. For example, for the signal interruption of the front and middle cameras in Table 1, the example of its fault situation distribution is as Figure 2 shown. If bit encoding is performed for each grid, a scalar value can be calculated according to this fault situation distribution. According to Figure 2 the bit encoding of each grid in, its scalar value can be calculated to be 12, which is the fault situation value of this fault in the table.
[0067] When the fault status of each faulty device of the vehicle is detected, generate the fault code values of each faulty device.
[0068] S2. Integrate the fault code values of each faulty device to obtain the integrated fault code values, and based on the integrated fault code values, obtain the corresponding safety control strategy.
[0069] As an embodiment, the integrating the fault code values of each faulty device to obtain the integrated fault code values and obtaining the corresponding safety control strategy based on the integrated fault code values includes: looking up the corresponding fault situation value in the fault code table according to the fault code values of each faulty device; obtaining the fault situation distribution within the grid around the vehicle according to the fault situation values of each faulty device; obtaining the fault decision level of the vehicle based on the fault situation distribution within the grid around the vehicle; and obtaining the corresponding safety control strategy based on the fault decision level.
[0070] It can be understood that specifically, according to the fault code values of each faulty device, look up the corresponding fault situation value in the fault code table, obtain the fault situation distribution within the grid around the vehicle according to the fault situation values of each faulty device, obtain the fault decision level of the vehicle based on the fault situation distribution within the grid around the vehicle; and obtain the corresponding safety control strategy based on the fault decision level.
[0071] As an embodiment, obtaining the fault situation distribution within the grid around the vehicle according to the fault situation values of each faulty device includes: summing up the fault situation values of each faulty device to obtain the sum of fault situations; and obtaining the fault situation distribution within the grid around the vehicle according to the sum of fault situations.
[0072] Specifically, when determining the fault decision level, sum up the fault situation values of each faulty device to obtain the sum of fault situations, obtain its spatial distribution (fault situation distribution) within the grid around the vehicle through the inverse operation of the sum of fault situations, and determine the fault decision level of the vehicle according to the fault situation distribution, where the fault decision of the vehicle is divided into 6 levels.
[0073] Query and obtain the corresponding safety control strategy from Table 2 below according to the current movement direction of the vehicle (depending on the D or R gear) and the fault decision level of the vehicle.
[0074] Table 2 Corresponding relationship between fault decision level and safety control strategy
[0075]
[0076]
[0077] As can be seen from Table 2, if the fault decision level is 0, no safety control is required. When the fault decision level is 1 - 5, safety control is needed. It can be seen from Table 2 that the safety control strategies include a parking strategy, a braking strategy, a limiting strategy, an immediate mode strategy, and an audible and visual alarm strategy. After obtaining the vehicle's safety control strategy through Table 2, the vehicle is safely controlled according to the safety control strategy.
[0078] S3. Generate the longitudinal and lateral control signals of the vehicle based on the vehicle's surrounding environment information and the safety control strategy, where the vehicle's surrounding environment information at least includes the motion state information of other vehicles around the vehicle and obstacle information.
[0079] It can be understood that in this step, based on the detected vehicle surrounding environment information, which mainly includes the motion state information of other vehicles around the vehicle and lane obstacle information, and based on the vehicle surrounding environment information and the safety control strategy obtained in step S3, the longitudinal and lateral control signals of the vehicle are generated.
[0080] S4. Drive the vehicle to travel based on the longitudinal and lateral control signals to perform safety redundancy control on the vehicle.
[0081] It can be understood that drive the vehicle to travel based on the longitudinal and lateral control signals of the vehicle generated in step S3 to achieve safety redundancy control of the vehicle.
[0082] It should be noted that initially, the longitudinal and lateral control signals of the vehicle are generated according to the vehicle's surrounding environment information. Subsequently, after step S2 determines the corresponding safety control strategy, the safety control strategy is fed back to step S3. Step S3 combines the vehicle's surrounding environment information and the safety control strategy to adjust the generated longitudinal and lateral control signals of the vehicle. Steps S2 and S3 form a closed-loop circuit to continuously adjust the longitudinal and lateral control signals of the vehicle, so that the finally generated longitudinal and lateral control signals of the vehicle reach the optimal state.
[0083] See Figure 3 , which provides a safety redundancy control system for an autonomous driving vehicle according to the present invention. The safety redundancy control system mainly includes a perception fusion module 31, a planning and control module 32, a safety decision module 33, and an execution module 34.
[0084] Among them, the perception fusion module 31 is used to perceive and fuse the environmental information around the vehicle, detect the fault states of various faulty devices of the vehicle, generate fault code values of various faulty devices, send the environmental information around the vehicle to the planning and control module 32, and send the fault code values of various faulty devices to the safety decision-making module 33; the safety decision-making module 33 is used to integrate the fault code values of various faulty devices to obtain the integrated fault code values, obtain corresponding safety control strategies based on the integrated fault code values, and send the safety control strategies to the planning and control module 32; and send the longitudinal and lateral control signals sent by the planning and control module 32 to the execution module 34; the planning and control module 32 is used to generate longitudinal and lateral control signals of the vehicle according to the environmental information around the vehicle and the safety control strategy, and send the longitudinal and lateral control signals to the safety decision-making module 33; the execution module 34 is used to perform safety redundancy control of the vehicle based on the longitudinal and lateral control signals.
[0085] It can be understood that based on the defects of the background technology, the present invention designs a fault monitoring and safety decision-making control logic in the field of autonomous driving, mainly including a perception fusion module 31, a planning and control module 32, a safety decision-making module 33 and an execution module 34. The perception fusion module 31 mainly detects the fault states of various faulty devices of the vehicle and the environmental information around the vehicle. For example, the signal fault of the front view camera, and generates corresponding fault code values based on the fault states of various faulty devices.
[0086] The safety decision-making module 33 generates a safety control strategy according to the fault code values of various faulty devices of the vehicle. The planning and control module 32 generates longitudinal and lateral control signals of the vehicle according to the environmental information around the vehicle and the safety control strategy. The execution module 34 is used to perform safety control on the vehicle according to the longitudinal and lateral control signals of the vehicle.
[0087] The present invention solves the problem that existing autonomous driving vehicles cannot timely and effectively achieve safety control of the vehicle when actuators or sensors fail, thereby improving the safety driving level of the vehicle.
[0088] As an embodiment, the perception fusion module 31 sends the environmental information around the vehicle to the planning and control module 32 and sends the fault code values of various faulty devices to the safety decision-making module 33, including: the perception fusion module 31 carries the environmental information around the vehicle and the fault code values of various faulty devices in their respective heartbeat messages, and sends them to the planning and control module 32 and the safety decision-making module 33 respectively at regular intervals in the form of heartbeat messages.
[0089] It is understandable that when the perception fusion module 31 sends the environmental information around the vehicle to the planning and control module 32 and sends the fault code values of each faulty device to the safety decision-making module 33, it reports data to the planning and control module 32 and the safety decision-making module 33 at regular intervals in the form of heartbeat messages. For example, the perception fusion module 31 sends the fault code value to the safety decision-making module 33. As shown in Table 1 above, when the perception fusion module 31 detects an interruption in the front view camera signal, the fault code value 289800775 will be continuously included in its heartbeat message. If the perception fusion module 31 also detects other faults, other fault code values will also be included in the heartbeat message.
[0090] As an embodiment, refer to Figure 4 , the safety redundancy control system further includes a human-machine interaction module 35; the safety decision-making module 33 is configured to generate a control signal according to the safety control strategy for the safety control strategy that can take effect directly by itself, and send it to the execution module 34, so that the execution module 34 drives the vehicle according to the control signal; and for the safety control strategy that cannot take effect directly by itself, it is sent to the planning and control module 32 and the human-machine interaction module 35 through a safety request message, so that the planning and control module 32 and the human-machine interaction module 35 execute the safety control strategy.
[0091] Among them, it can be seen from Figure 5 that the figure is a schematic diagram of the signal flow between the modules of the safety redundancy control system, and the main process is as follows:
[0092] (1) The perception fusion module sends the perception result signal (environmental information around the vehicle) to the planning and control module, and sends the fault code values of each faulty device to the safety decision-making module, as Figure 5 shown in ①.
[0093] (2) The planning and control module calculates the longitudinal and lateral control signals of the vehicle according to the perception result, and sends them to the execution module through the safety decision-making module, as Figure 5 shown in ②.
[0094] (3) The safety decision-making module sums up the fault code values of each faulty device, performs an inverse operation on the summed fault code values to obtain the fault situation distribution in the grid around the vehicle, and generates a corresponding safety control strategy based on the fault situation distribution. Then, the safety control strategy is fed back to the planning decision-making module, so that the planning decision-making module adjusts the longitudinal and lateral control signals according to the safety control strategy.
[0095] Among them, the safety decision-making module is the core of the fault diagnosis function, which is used for the integration, safety decision-making and control of autonomous driving-related faults. In the fault monitoring function, the safety decision-making module integrates the list of fault code values sent by other modules to form a real-time fault list for the autonomous driving domain, which is used for subsequent safety decision-making and control.
[0096] Specifically, when the fault decision level is level 0, no safety control is required, and the safety decision-making module transparently transmits the control signal ② to the execution module, such as Figure 5 shown in ③. If the fault decision level is 1-5, safety control is required. As can be seen from Table 2, the safety control strategies include parking strategy, braking strategy, limiting strategy, timely mode strategy, and audible and visual alarm strategy.
[0097] When the fault decision level is 1-5, the specific method of performing safety control on the vehicle is as follows: For safety control strategies that can take effect directly by the safety decision-making module, such as lateral and longitudinal control and vehicle body control, Figure 5 the signal ② in is modified accordingly. For example, clear the throttle, issue braking, turn on the hazard lights, pull up the EPB, exit autonomous driving, etc., and send the modified signal to the execution module, such as Figure 5 shown in ③, and the execution module drives the vehicle to perform safety control.
[0098] For safety control strategies that cannot take effect directly by the safety decision-making module, such as lane change prohibition, speed limit driving, pulling over, audible and visual alarm, etc. that rely on the planning control module to implement, the safety decision-making module sends a safety request message to the planning control module and the human-machine interaction module, such as Figure 5 shown in ④ and ⑤, and the planning control module and the human-machine interaction module execute the safety control strategy.
[0099] It can be understood that a safety redundancy control system for an autonomous driving vehicle provided by the present invention corresponds to the safety redundancy control method for an autonomous driving vehicle provided in the foregoing embodiments. The relevant technical features of the safety redundancy control system for an autonomous driving vehicle can refer to the relevant technical features of the safety redundancy control method for an autonomous driving vehicle, which will not be elaborated herein.
[0100] Please refer to Figure 6 , Figure 6 which is a schematic diagram of an embodiment of an electronic device provided by an embodiment of the present invention. As shown in Figure 6As shown in the figure, an embodiment of the present invention provides an electronic device 600, including a memory 610, a processor 620, and a computer program 611 stored on the memory 610 and executable on the processor 620. When the processor 620 executes the computer program 611, the following steps are implemented: detecting the fault status of each faulty device of the vehicle and generating a fault code value for each faulty device; integrating the fault code values of each faulty device to obtain an integrated fault code value, and based on the integrated fault code value, obtaining a corresponding safety control strategy; generating lateral and longitudinal control signals of the vehicle according to the vehicle surrounding environment information and the safety control strategy; and performing safety redundancy control of the vehicle based on the lateral and longitudinal control signals.
[0101] Please refer to Figure 7 , Figure 7 which is a schematic diagram of an embodiment of a computer-readable storage medium provided by the present invention. As Figure 7 shown, this embodiment provides a computer-readable storage medium 700, on which a computer program 711 is stored. When the computer program 711 is executed by a processor, the following steps are implemented: detecting the fault status of each faulty device of the vehicle and generating a fault code value for each faulty device; integrating the fault code values of each faulty device to obtain an integrated fault code value, and based on the integrated fault code value, obtaining a corresponding safety control strategy; generating lateral and longitudinal control signals of the vehicle according to the vehicle surrounding environment information and the safety control strategy; and performing safety redundancy control of the vehicle based on the lateral and longitudinal control signals.
[0102] An embodiment of the present invention provides a safety redundancy control method and control system for an autonomous vehicle, which detect the surrounding environment information of the vehicle and the fault status of each faulty device of the vehicle, obtain a safety control strategy based on the fault code values of each faulty device; generate lateral and longitudinal control signals of the vehicle based on the surrounding environment information and the safety control strategy of the vehicle; and perform safety redundancy control of the vehicle based on the lateral and longitudinal control signals of the vehicle, solving the problem that existing autonomous vehicles cannot timely and effectively implement safety control of the vehicle when actuators or sensors fail, thereby improving the safety driving level of the vehicle.
[0103] It should be noted that in the above embodiments, the descriptions of each embodiment have their own emphases. For parts not detailedly described in a certain embodiment, reference can be made to the relevant descriptions of other embodiments.
[0104] Those skilled in the art should understand that the embodiments of the present invention can be provided as a method, a system, or a computer program product. Therefore, the present invention can take the form of a complete hardware embodiment, a complete software embodiment, or an embodiment combining software and hardware aspects. Moreover, the present invention can take the form of a computer program product implemented on one or more computer-usable storage media (including but not limited to disk memory, CD-ROM, optical memory, etc.) that contain computer-usable program code.
[0105] The present invention is described with reference to the flowcharts and / or block diagrams of methods, apparatuses (systems), and computer program products according to the embodiments of the present invention. It should be understood that each flow and / or block in the flowchart and / or block diagram, and the combination of flows and / or blocks in the flowchart and / or block diagram, can be implemented by computer program instructions. These computer program instructions can be provided to the processor of a general-purpose computer, a special-purpose computer, an embedded computer, or other programmable data processing devices to generate a machine, such that the instructions executed by the processor of the computer or other programmable data processing devices generate means for implementing the functions specified in Figure 1 one or more of the flows Figure 1 or blocks.
[0106] These computer program instructions can also be stored in a computer-readable memory that can direct a computer or other programmable data processing device to work in a specific manner, such that the instructions stored in the computer-readable memory generate a manufactured article including instruction means that implement the functions specified in Figure 1 one or more of the flows Figure 1 or blocks.
[0107] These computer program instructions can also be loaded onto a computer or other programmable data processing device, such that a series of operation steps are executed on the computer or other programmable device to generate a computer-implemented process, and thus the instructions executed on the computer or other programmable device provide steps for implementing the functions specified in Figure 1 one or more of the flows Figure 1 or blocks.
[0108] Although the preferred embodiments of the present invention have been described, those skilled in the art can make additional changes and modifications to these embodiments once they learn the basic inventive concept. Therefore, the appended claims are intended to be construed as including the preferred embodiments and all changes and modifications that fall within the scope of the present invention.
[0109] Obviously, those skilled in the art can make various modifications and variations to the present invention without departing from the spirit and scope of the present invention. Thus, if these modifications and variations of the present invention fall within the scope of the claims of the present invention and their equivalent technologies, the present invention is also intended to include these modifications and variations.
Claims
1. A safety redundancy control method for an autonomous vehicle, characterized in that, Including: Detect the fault status of each faulty device of the vehicle and generate the fault code values of each faulty device; Integrate the fault code values of each faulty device to obtain the integrated fault code value, and based on the integrated fault code value, obtain the corresponding safety control strategy; Generate the longitudinal and lateral control signals of the vehicle according to the vehicle surrounding environment information and the safety control strategy; Execute the safety redundancy control of the vehicle based on the longitudinal and lateral control signals; Among them, the fault status of each faulty device of the vehicle is detected based on a fault code table, and the fault code table describes the faults that can be identified by the autonomous driving domain; The fault code table includes a fault situation value field, and the fault situation value field represents the fault situation distribution when the vehicle has a corresponding fault, and the fault situation distribution is the distribution of the safety risks faced in the surrounding grid; The integrating the fault code values of each faulty device to obtain the integrated fault code value, and based on the integrated fault code value, obtaining the corresponding safety control strategy includes: According to the fault code values of each faulty device, look up the corresponding fault situation value in the fault code table; Obtain the fault situation distribution within the grid around the vehicle according to the fault situation values of each faulty device; Obtain the fault decision level of the vehicle based on the fault situation distribution within the grid around the vehicle; Obtain the corresponding safety control strategy based on the fault decision level.
2. The safety redundancy control method according to claim 1, wherein The fault code table further includes a fault code value field, a fault description field, a faulty device field, a monitoring subject field, a fault type field, and a fault diagnosis parameter field; The faulty device field is used to describe the entity where the fault occurs; The monitoring subject field is used to describe the entity that detects the occurrence of the fault; The fault type field represents the type of the fault, and the type of the fault includes one or more of signal timeout, signal interruption, timing error, and data anomaly; The fault code value field is a unique numerical code calculated according to other fields; The fault diagnosis parameter field is used to describe the diagnostic parameter information for the monitoring subject to monitor and detect the faulty device.
3. The safety redundancy control method according to claim 1, characterized in that The obtaining the fault situation distribution within the grid around the vehicle according to the fault situation values of each faulty device includes: Sum up the fault situation values of each faulty device to obtain the sum of the fault situations; Obtain the fault situation distribution within the grid around the vehicle according to the sum of the fault situations.
4. The safety redundancy control method according to claim 3, wherein There are multiple fault decision levels, and each fault decision level corresponds to a safety control strategy.
5. The safety redundancy control method according to any one of claims 1-4, characterized in that, The safety control strategies include a parking strategy, a braking strategy, a limiting strategy, a timely mode strategy, and an audible and visual alarm strategy.
6. A safety redundancy control system for an autonomous vehicle, characterized in that, Including a perception fusion module, a planning and control module, a safety decision module, and an execution module; The perception fusion module is used to perceive and fuse the environment information around the vehicle, detect the fault status of each faulty device of the vehicle and generate the fault code values of each faulty device, send the environment information around the vehicle to the planning and control module, and send the fault code values of each faulty device to the safety decision module; The safety decision-making module is used to integrate the fault code values of each faulty device to obtain the integrated fault code value, and based on the integrated fault code value, obtain the corresponding safety control strategy and send the safety control strategy to the planning control module; and send the lateral and longitudinal control signals sent by the planning control module to the execution module; The planning control module is used to generate the lateral and longitudinal control signals of the vehicle according to the environmental information around the vehicle and the safety control strategy, and send the lateral and longitudinal control signals to the safety decision-making module; The execution module is used to execute the safety redundancy control of the vehicle based on the lateral and longitudinal control signals; Among them, the fault status of each faulty device of the vehicle is detected based on a fault code table, and the fault code table describes the faults that can be identified in the autonomous driving domain; The fault code table includes a fault situation value field, and the fault situation value field represents the fault situation distribution when the vehicle has a corresponding fault, and the fault situation distribution is the distribution of the safety risks faced in the surrounding grid; The integration of the fault code values of each faulty device to obtain the integrated fault code value, and based on the integrated fault code value, obtaining the corresponding safety control strategy includes: According to the fault code values of each faulty device, look up the corresponding fault situation value in the fault code table; According to the fault situation values of each faulty device, obtain the fault situation distribution in the grid around the vehicle; Based on the fault situation distribution in the grid around the vehicle, obtain the fault decision level of the vehicle; Based on the fault decision level, obtain the corresponding safety control strategy.
7. The safety redundant control system according to claim 6, characterized in that, The perception fusion module sends the environmental information around the vehicle to the planning control module and sends the fault code values of each faulty device to the safety decision-making module, including: The perception fusion module carries the environmental information around the vehicle and the fault code values of each faulty device in their respective heartbeat messages and sends them to the planning control module and the safety decision-making module respectively at regular intervals in the form of heartbeat messages.
8. The safety redundancy control system according to claim 6, wherein It also includes a human-machine interaction module; The safety decision-making module is used to generate a control signal according to the safety control strategy for the safety control strategy that can take effect directly by itself, and send it to the execution module, so that the execution module drives the vehicle according to the control signal; And for the safety control strategy that cannot take effect directly by itself, send it to the planning control module and the human-machine interaction module through a safety request message, so that the planning control module and the human-machine interaction module execute the safety control strategy.
9. An electronic device, characterized in that, It includes a memory and a processor, and the processor is used to implement the steps of the safety redundancy control method of the autonomous driving vehicle according to any one of claims 1-5 when executing the computer program stored in the memory.
Citation Information
Patent Citations
Vehicle driving monitoring system, method and equipment and storage medium
CN114348025A