Parallel takeover control method and device for unmanned vehicles, cloud control platform, and electronic equipment
By real-time monitoring of the autonomous driving module and evaluating the fault level on the unmanned vehicle side, and using the cloud control platform for automated parallel takeover control, the safety issues encountered when the unmanned vehicle fails are resolved, and safe and automated vehicle management is achieved.
Patent Information
- Application Number
- CN202210944072.6
- Authority / Receiving Office
- CN · China
- Patent Type
- Patents(China)
- Current Assignee / Owner
- Filing Date
- 2022-08-05
- Publication Date
- 2025-09-26
- Estimated Expiration
- 2042-08-05
AI Technical Summary
When an unmanned vehicle fails, how to achieve safe and automated parallel takeover to avoid safety risks caused by system failures, especially to ensure safe operation of the vehicle when sensors and actuators fail.
By real-time monitoring of abnormalities in the autonomous driving module on the vehicle side, assessing the fault level, and reporting to the cloud control platform for parallel takeover when necessary, the cloud control platform allocates a parallel cockpit for remote takeover control to ensure that the vehicle can safely park or continue driving.
It realizes real-time monitoring and automated parallel takeover when unmanned vehicles malfunction, ensuring vehicle safety, avoiding safety hazards caused by malfunctions, reducing the impact on other vehicles, and does not require additional hardware and labor costs.
Smart Images

Figure CN115257810B_ABST
Abstract
Description
Technical Field
[0001] The present application relates to the field of autonomous driving technology, and in particular to a method and device for parallel takeover control of an unmanned vehicle, a cloud control platform, and electronic equipment. Background Art
[0002] With the development of intelligent driving technology, the implementation of advanced autonomous driving technology has become possible, but the role of safety officers will remain essential for a long time. The current process for removing safety officers in autonomous driving generally includes the safety officer leaving the driver's seat to the front passenger seat, and then leaving the vehicle to remotely take over. Specifically, the safety officer's departure from the vehicle and remote supervision of the vehicle primarily involves remotely taking over the vehicle when a need arises on the vehicle side, and through parallel control, achieving objectives such as escape from distress.
[0003] In related technologies, parallel driving primarily focuses on rescuing a vehicle in certain scenarios when it exceeds the system's designed operating boundaries. However, intelligent driving is a highly complex system, and as the vehicle operates, sensor and actuator failures are inevitable, leading to safety risks. Therefore, ensuring safe handling of the unmanned vehicle through parallel driving is crucial to ensuring operational safety. Summary of the Invention
[0004] The embodiments of the present application provide a method and device for parallel takeover control of unmanned vehicles, a cloud control platform, and electronic equipment to monitor unmanned vehicle failures in real time and perform parallel takeover in the event of a failure to ensure safe operation of the vehicle.
[0005] The embodiments of this application adopt the following technical solutions:
[0006] In a first aspect, an embodiment of the present application provides a parallel takeover control method for an unmanned vehicle, wherein the method is applied to a vehicle, and includes:
[0007] Start the vehicle monitoring program to monitor whether the vehicle's autonomous driving module is abnormal;
[0008] If the autonomous driving module of the vehicle is monitored to have an abnormality and it affects the autonomous driving module's execution of the preset autonomous driving control instructions in the vehicle, it will be reported to the cloud control platform for parallel takeover of the vehicle.
[0009] In some embodiments, the method further comprises:
[0010] Assessing a fault level of the autonomous driving module;
[0011] If the fault level is the first fault level, reporting to the cloud control platform;
[0012] If the fault level is the second fault level, a braking procedure is initiated to stop the vehicle safely, wherein the priority of the first fault level is higher than that of the second fault level.
[0013] In some embodiments, the monitoring of an abnormality in the autonomous driving module of the vehicle that affects the autonomous driving module's execution of preset autonomous driving control instructions in the vehicle includes:
[0014] If the autonomous driving module of the vehicle is detected to be abnormal and at a first fault level, the autonomous driving module is traversed to determine a fault node that affects the autonomous driving module from executing a preset autonomous driving control instruction in the vehicle;
[0015] and / or,
[0016] If it is monitored that the automatic driving module of the own vehicle is abnormal and is at the second fault level, the own vehicle monitoring program is started again after the braking program is started to stop the vehicle safely.
[0017] In some embodiments, the reporting to the cloud control platform for parallel takeover of the vehicle also includes: executing preset safety control instructions on the vehicle.
[0018] In a second aspect, an embodiment of the present application further provides a method for controlling parallel takeover of an unmanned vehicle, which is used in a cloud control platform, and the method includes:
[0019] receiving abnormality information and a fault handling strategy of a target vehicle uploaded by a fault center, wherein the abnormality information of the target vehicle includes at least fault information of an autonomous driving module of the vehicle and a fault level corresponding to the autonomous driving module, and the fault handling strategy includes a fault handling strategy corresponding to the abnormality information of the vehicle;
[0020] According to the vehicle abnormality information, a parallel cockpit that meets the conditions is allocated to perform parallel takeover of the target vehicle according to the fault handling strategy.
[0021] In some embodiments, the fault level includes: a first fault level and a second fault level, the first fault level has a higher priority than the second fault level, and the receiving of target vehicle abnormality information and fault handling strategy uploaded by the fault center includes:
[0022] Receive in real time the abnormal information and fault handling strategy of the target vehicle whose fault level is the first fault level, the fault handling strategy is used to respond to the abnormal information, the fault handling strategy includes at least one of the following: remote parallel takeover processing strategy, driving strategy after remote parallel takeover processing, and the abnormal information includes at least one of the following: lidar sensor abnormality, automatic driving control system planning node abnormality, positioning sensor inertial navigation abnormality.
[0023] In some embodiments, the method further comprises:
[0024] receiving a response instruction from the parallel cockpit, wherein the response instruction includes at least one of the following: a timeout response and a takeover refusal response;
[0025] The parallel cockpits are reallocated according to a result of a timeout response or a takeover refusal response in the first response instruction.
[0026] In a third aspect, an embodiment of the present application further provides a parallel takeover control device for an unmanned vehicle, wherein the device is used on a vehicle side and includes:
[0027] The startup module is used to start the vehicle monitoring program and monitor whether the vehicle's automatic driving module is abnormal;
[0028] The reporting module is used to report to the cloud control platform for parallel takeover of the vehicle if an abnormality is detected in the autonomous driving module of the vehicle and affects the autonomous driving module's execution of preset autonomous driving control instructions in the vehicle.
[0029] In a fourth aspect, an embodiment of the present application further provides a cloud control platform, which includes:
[0030] a first receiving and processing module, configured to receive abnormality information and a fault handling strategy of a target vehicle uploaded by a fault center, wherein the abnormality information of the target vehicle includes at least fault information of the vehicle's automatic driving module and a fault level corresponding to the automatic driving module, and the fault handling strategy includes a fault handling strategy corresponding to the abnormality information of the vehicle;
[0031] The allocation processing module is used to allocate a parallel cockpit that meets the conditions according to the vehicle abnormality information to perform parallel takeover of the target vehicle according to the fault processing strategy.
[0032] In a fifth aspect, an embodiment of the present application further provides an electronic device, comprising: a processor; and a memory arranged to store computer-executable instructions, wherein the executable instructions, when executed, enable the processor to perform the above method.
[0033] In a sixth aspect, an embodiment of the present application further provides a computer-readable storage medium, which stores one or more programs. When the one or more programs are executed by an electronic device including multiple applications, the electronic device executes the above method.
[0034] At least one of the above technical solutions adopted in the embodiments of the present application can achieve the following beneficial effects:
[0035] The vehicle-side monitoring program is activated to proactively monitor the vehicle's autonomous driving module for abnormalities. If an abnormality is detected, and this abnormality affects the module's execution of pre-set autonomous driving control instructions, the vehicle-side report is sent to the cloud control platform. This enables real-time monitoring of vehicle faults and an automated process for parallel takeover of the vehicle in the event of a fault. This differs from related technologies, which passively initiate parallel takeover to free the vehicle only when the unmanned vehicle exceeds the system's pre-set boundaries. BRIEF DESCRIPTION OF THE DRAWINGS
[0036] The drawings described herein are used to provide a further understanding of the present application and constitute a part of the present application. The illustrative embodiments of the present application and their descriptions are used to explain the present application and do not constitute an improper limitation on the present application. In the drawings:
[0037] Figure 1 Schematic diagram of the hardware architecture of the parallel takeover control method for an unmanned vehicle in an embodiment of the present application;
[0038] Figure 2 This is a flow chart of a parallel takeover control method for an unmanned vehicle in an embodiment of the present application;
[0039] Figure 3 This is a flow chart of another unmanned vehicle parallel takeover control method according to an embodiment of the present application;
[0040] Figure 4 This is a flow chart of a parallel takeover control method for an unmanned vehicle in a preferred embodiment of the present application;
[0041] Figure 5 This is a schematic diagram of the overall implementation flow of the parallel takeover control method for an unmanned vehicle in an embodiment of the present application;
[0042] Figure 6 This is a schematic structural diagram of a parallel takeover control device for an unmanned vehicle in an embodiment of the present application;
[0043] Figure 7 This is a schematic diagram of the cloud control platform structure in the embodiment of this application;
[0044] Figure 8 This is a structural diagram of an electronic device in an embodiment of the present application. DETAILED DESCRIPTION
[0045] To make the purpose, technical solutions, and advantages of this application more clear, the technical solutions of this application will be clearly and completely described below in conjunction with the specific embodiments of this application and the corresponding drawings. Obviously, the embodiments described are only part of the embodiments of this application, not all of them. Based on the embodiments in this application, all other embodiments obtained by ordinary technicians in this field without making creative efforts are within the scope of protection of this application.
[0046] The following describes in detail the technical solutions provided by various embodiments of the present application in conjunction with the accompanying drawings.
[0047] like Figure 1 The figure shows the hardware architecture of the parallel takeover control method for unmanned vehicles in the embodiment of the present application. It includes: a parallel cockpit, a cloud control platform, an intelligent driving control system, and an unmanned vehicle.
[0048] The parallel cockpit and the cloud control platform communicate and upload information and issue commands. The parallel cockpit issues parallel driving control commands to the cloud control platform, which then transmits them to the intelligent driving control system. The cloud control platform synchronizes fault information, takeover commands, and vehicle status information with the parallel cockpit.
[0049] In addition to receiving the parallel driving control instructions, the cloud control platform also needs to receive fault information and vehicle status information uploaded by the intelligent driving control system.
[0050] The intelligent driving control system includes at least a fault center and a control module. The fault center monitors the control module and generates corresponding fault judgment results.
[0051] The unmanned vehicle is installed / running with the intelligent driving control system, and reports vehicle status information to the intelligent driving control system, and receives vehicle control instructions issued by the intelligent driving control system.
[0052] The parallel takeover control method for unmanned vehicles in this application is based on the aforementioned hardware structure. The fault center monitors the system status in real time, reports a fault that causes a serious loss of autonomous driving capability to the platform in real time, and implements remote parallel takeover. This allows the vehicle to be safely controlled, such as by pulling over, even if it fails but still has the ability to drive, thereby ensuring its safety. The vehicle will not be affected by other vehicles being parked in the middle of the road. Furthermore, the entire takeover control process is fully automated and deployed entirely within the existing intelligent driving control system, eliminating the need for additional equipment and manpower, and resulting in no additional costs.
[0053] In addition, the unmanned vehicle parallel takeover control method based on the above-mentioned hardware architecture has also expanded the functional scope of remote parallel driving, more comprehensively guaranteed the safety performance of vehicle autonomous driving from the perspective of functional safety, and provided more comprehensive technical support for safety officers to get off the vehicle.
[0054] The embodiment of the present application provides a method for controlling parallel takeover of an unmanned vehicle, such as Figure 2 As shown, a schematic diagram of the parallel takeover control process of an unmanned vehicle in an embodiment of the present application is provided. The method includes at least the following steps S210 to S220:
[0055] Step S210: Start the vehicle monitoring program to monitor whether the vehicle's automatic driving module is abnormal.
[0056] It's important to note that the "self-vehicle" here refers to the driverless vehicle itself. This means that each autonomous vehicle's monitoring program is independent, but all reports to the cloud control platform. The monitoring program only monitors the driverless vehicle in real time and doesn't need to monitor the status of other vehicles.
[0057] After the vehicle monitoring program is started on the vehicle side, it can be used to monitor the working status of the vehicle's automatic driving module and determine whether there is any abnormality in the automatic driving module.
[0058] It's understood that once an unmanned vehicle initiates autonomous driving operations, the vehicle's monitoring program monitors the vehicle's systems in real time. These systems include the intelligent driving control system, the vehicle (the driver), and all relevant sensors. For example, autonomous driving operations can be used in scenarios like robotaxis and robobuses. Another example is the use of specialized vehicles.
[0059] Furthermore, it is necessary to focus on monitoring whether the vehicle's autonomous driving module (intelligent driving control system) is abnormal, because whether the autonomous driving module is abnormal will directly affect the operation or operation of the unmanned vehicle.
[0060] In step S220, if it is monitored that an abnormality occurs in the autonomous driving module of the vehicle and affects the autonomous driving module from executing the preset autonomous driving control instructions in the vehicle, it is reported to the cloud control platform for parallel takeover of the vehicle.
[0061] When an abnormality is detected in the autonomous driving module of the vehicle, it is necessary to further determine whether the abnormality affects the autonomous driving module's execution of preset autonomous driving control instructions in the vehicle. That is, when a fault is identified in the autonomous driving module in the vehicle-side system, and the fault causes a serious loss of the vehicle's autonomous driving capability and requires parallel takeover, the fault information and response processing strategy are immediately reported to the cloud control platform.
[0062] It is understandable that other faults can also be reported or corresponding control instructions can be issued. Considering that if the fault affects the automatic driving module when the vehicle executes the preset automatic driving control instructions, there will be a major safety hazard for the unmanned vehicle, so the reporting priority at this time is the highest.
[0063] Furthermore, for fault conditions that affect the automatic driving module's execution of preset automatic driving control instructions in the vehicle, real-time synchronous uploading will be adopted, while for fault conditions that do not affect the automatic driving module's execution of preset automatic driving control instructions in the vehicle, asynchronous uploading will be adopted. For example, it can be uploaded to the cloud control platform to monitor the operating status of the automatic driving vehicle, reducing the computing pressure on the vehicle side.
[0064] In some embodiments, if an abnormality is detected in the autonomous driving module of the vehicle and affects the autonomous driving module's execution of preset autonomous driving control instructions in the vehicle, but does not cause the entire autonomous driving module to lose its entire function, priority can be given to braking the unmanned vehicle and then entering the autonomous driving operation mode after restarting.
[0065] In one embodiment of the present application, the method further includes: evaluating the fault level of the autonomous driving module; if the fault level is the first fault level, reporting to the cloud control platform; if the fault level is the second fault level, initiating a braking program to stop the vehicle safely, wherein the priority of the first fault level is greater than the second fault level.
[0066] In specific implementations, when a fault is detected, the vehicle automatically assesses the fault level of the autonomous driving module. If the fault level is Level 1 (high priority), it is reported to the cloud control platform. At this point, the fault is considered serious and requires timely parallel control.
[0067] When a fault is detected, the vehicle automatically assesses the fault level of the autonomous driving module. If the fault level is the second fault level (medium / low priority), the vehicle's braking program is activated to bring the vehicle to a safe stop. For example, the autonomous vehicle may be pulled over and parked safely. Another example is to drive the autonomous vehicle to a designated repair station for repairs.
[0068] For example, Figure 1 As shown, the fault level of the autonomous driving module is evaluated by the fault center, and the fault information is reported to the cloud control platform.
[0069] It should be noted that the above scenario considers the situation where the safety officer leaves the vehicle and remotely monitors the vehicle. The entire process is completed automatically and does not require human intervention.
[0070] In one embodiment of the present application, the monitoring of an abnormality in the autonomous driving module of the own vehicle and the impact on the autonomous driving module executing preset autonomous driving control instructions in the own vehicle includes: monitoring an abnormality in the autonomous driving module of the own vehicle and the fault level is the first, traversing the autonomous driving module and determining the fault node that affects the autonomous driving module executing the preset autonomous driving control instructions in the own vehicle; and / or, monitoring an abnormality in the autonomous driving module of the own vehicle and the fault level is the second, after initiating the braking program to safely stop the vehicle, re-starting the vehicle monitoring program.
[0071] During specific implementation, as an optimization consideration, if the fault center monitors that the autonomous driving module of the vehicle has an abnormality and is at the first fault level, the fault center traverses the autonomous driving module and determines the fault node that affects the autonomous driving module's execution of the preset autonomous driving control instructions in the vehicle.
[0072] It can be understood that the fault nodes here include but are not limited to perception and positioning nodes, decision-making and planning nodes, motion control nodes, etc.
[0073] Furthermore, if the fault center detects a fault level 2 in the ego vehicle's autonomous driving module, it will initiate the braking process to safely stop the vehicle and then re-activate the ego vehicle monitoring program. If the fault is resolved, the autonomous driving mission will resume. If the fault is still present, an asynchronous report will be considered to continue the autonomous driving mission.
[0074] It is understandable that if it is the second fault level, it may be that a certain perception and positioning node has failed, such as a lidar failure while visual perception is normal, or another example, a visual perception failure while the lidar is normal. At this time, the unmanned vehicle still has a certain degree of autonomous driving capability, so it can first complete the current task and park safely, and then proceed to the next instruction according to the actual situation. Of course, it is also possible that a decision-making planning or motion control node has failed, which is not specifically limited in the embodiments of this application.
[0075] In one embodiment of the present application, the reporting to the cloud control platform for parallel takeover of the vehicle also includes: executing preset safety control instructions on the vehicle.
[0076] During specific implementation, after reporting to the cloud control platform, the vehicle side also needs to execute preset safety control instructions on the vehicle itself. That is to say, regardless of the first fault level or the second fault level, the current potential danger of the unmanned vehicle needs to be eliminated first. When the fault center reports the fault information, it will control the vehicle to slowly stop on the spot based on the safety control strategy to wait for remote parallel takeover to ensure safety.
[0077] The embodiment of the present application provides a parallel takeover control method for an unmanned vehicle, which is used in a cloud control platform, such as Figure 3 As shown, a schematic diagram of the parallel takeover control process of an unmanned vehicle in an embodiment of the present application is provided. The method includes at least the following steps S310 to S320:
[0078] Step S310: Receive the abnormal information and fault handling strategy of the target vehicle uploaded by the fault center. The abnormal information of the target vehicle includes at least the fault information of the vehicle's automatic driving module and the fault level corresponding to the automatic driving module. The fault handling strategy includes a fault handling strategy corresponding to the vehicle's abnormal information.
[0079] The cloud control platform receives the abnormal information and fault handling strategy of the target vehicle uploaded by the fault center. When the fault center identifies and confirms the fault, it immediately generates the corresponding fault code information and corresponding fault handling strategy information, and then reports it to the cloud control platform in real time.
[0080] It is understood that the fault handling strategy includes both the remote parallel takeover handling strategy and the driving strategy after the remote parallel takeover, such as immediate pullover, etc. However, it is not intended to specifically limit the scope of protection of this application.
[0081] Furthermore, the target vehicle's abnormal information includes at least fault information about the vehicle's autonomous driving module and the corresponding fault level of the autonomous driving module. This means the cloud control platform collects not only fault information but also the fault level of the autonomous driving module in the unmanned vehicle. High-priority fault levels will be remotely controlled, while medium / low-priority fault levels will be stored and generally not interfered with. It is understood that in special circumstances, remote control takeover instructions can also be received and issued.
[0082] Furthermore, the fault handling strategy includes a fault handling strategy corresponding to the vehicle abnormality information. The fault handling strategy is completed and generated on the vehicle side and uploaded to the cloud control platform. The cloud control platform can make a comprehensive judgment based on the actual situation and forward the fault handling strategy to the parallel cockpit.
[0083] Step S320: Allocate a parallel cockpit that meets the conditions according to the vehicle abnormality information to perform parallel takeover of the target vehicle according to the fault handling strategy.
[0084] Based on the vehicle abnormality information, the cloud control platform finds a target parallel cockpit among the idle parallel cockpits or those queued in the execution queue to synchronize fault information, takeover instructions, takeover strategies, etc., and then forwards the parallel driving control instructions issued by the target parallel cockpit.
[0085] It can be understood that in the target parallel cockpit, it is necessary to follow the fault handling strategy to take over the target vehicle in parallel, so as to meet the management and control requirements of the cloud control platform.
[0086] In one embodiment of the present application, the fault level includes: the first fault level, the abnormal information of the target vehicle uploaded by the receiving fault center and the fault handling strategy, including: real-time reception of the abnormal information and fault handling strategy of the target vehicle with the fault level of the first fault level, the fault handling strategy is used to respond to the abnormal information, the fault handling strategy includes at least one of the following: remote parallel takeover processing strategy, driving strategy after remote parallel takeover processing, the abnormal information includes at least one of the following: lidar sensor abnormality, automatic driving control system planning node abnormality, positioning sensor inertial navigation abnormality.
[0087] For faults of different levels, the cloud control platform receives in real time the abnormal information and fault handling strategy of the target vehicle whose fault level is the first fault level.
[0088] By obtaining the abnormal information such as the lidar sensor abnormality, the automatic driving control system planning node abnormality, the positioning sensor inertial navigation abnormality, etc., this information can also be synchronized to the parallel cockpit or saved in the cloud control platform.
[0089] Through the remote parallel takeover processing strategy and the driving strategy after the remote parallel takeover processing in the fault handling strategy, the parallel cockpit can be strictly controlled to automatically perform remote parallel driving takeover control according to the requirements of the cloud control platform.
[0090] Unlike related technologies, which typically only passively initiate parallel takeover to free the unmanned vehicle when it exceeds the system's set boundaries, this application, through unified allocation and management on a cloud-based control platform, proactively detects faults and allocates the corresponding parallel cockpit for parallel takeover of the vehicle. The entire process is automated.
[0091] In one embodiment of the present application, the method further includes: receiving a response instruction from a parallel cockpit, wherein the response instruction includes at least one of the following: a timeout response, a refusal to take over response; and reallocating the parallel cockpit according to the result of the timeout response or the refusal to take over response in the first response instruction.
[0092] For parallel cockpits, the cloud control platform needs to reallocate or reassign based on the response instructions received.
[0093] Specifically, after receiving fault information reported by the fault center, the cloud control platform determines whether the fault handling strategy includes remote parallel takeover. If so, it immediately randomly assigns an idle parallel cockpit. After selecting a parallel cockpit, it sends a remote parallel takeover command to the corresponding parallel cockpit, simultaneously forwarding the corresponding fault information and fault strategy.
[0094] If the driver does not click the confirmation button within the time limit in the parallel cockpit, or clicks the reject takeover button, the platform will immediately reallocate a new parallel cockpit and send a takeover instruction after receiving the feedback.
[0095] like Figure 4 The figure shows a flow chart of a parallel takeover control method for an unmanned vehicle in a preferred embodiment of the present application. Figure 5 The figure shows a schematic diagram of the overall implementation flow of the parallel takeover control method for an unmanned vehicle in an embodiment of the present application.
[0096] In order to better illustrate the entire parallel takeover control process, the following is an explanation with reference to the accompanying drawings.
[0097] In step S1, the fault center monitors whether there is any fault in the vehicle-side system that requires parallel takeover.
[0098] After a vehicle initiates autonomous driving, the fault center monitors the vehicle-side system in real time. This system refers to the intelligent driving control system, the vehicle, and all related sensors. If the fault center identifies a vehicle-side system failure that results in a significant loss of autonomous driving capability and requires parallel control, it immediately reports the fault information and the appropriate response strategy to the cloud control platform.
[0099] It should be noted that examples of failures that may lead to the loss of a vehicle's autonomous driving capabilities include: abnormalities in the lidar sensor, abnormalities in the autonomous driving control system planning nodes, abnormalities in the positioning sensor inertial navigation, etc.
[0100] In addition, when a fault causes a serious loss of a vehicle's autonomous driving capability, it usually means that multiple nodes have failed, thus affecting the normal operation of the entire autonomous driving module.
[0101] It is understood that when all the fault instances that lead to the loss of the vehicle's autonomous driving capability occur, it is considered that the fault has caused a serious loss of the vehicle's autonomous driving capability. Or other situations that may cause a serious loss of the vehicle's autonomous driving capability.
[0102] In step S2, the fault center uploads the fault information and takeover request to the cloud platform (cloud control platform), and sends corresponding fault handling instructions.
[0103] Once the fault center identifies and confirms the fault, it immediately generates the corresponding fault code and response fault handling strategy, reporting it to the cloud control platform in real time. This fault handling strategy includes both remote parallel takeover and the driving strategy after remote parallel takeover, such as immediate pullover.
[0104] When reporting the fault information, the fault center will control the vehicle to stop slowly on the spot based on the safety control strategy to ensure safety.
[0105] In step S3, the platform randomly assigns the idle parallel takeover cockpit according to the information uploaded by the fault center.
[0106] After receiving the fault information reported by the fault center, the cloud control platform determines whether the fault handling strategy includes remote parallel takeover. If so, it immediately randomly assigns an idle parallel cockpit. After selecting a parallel cockpit, it sends a remote parallel takeover command to the corresponding parallel cockpit, and simultaneously forwards the corresponding fault information and fault strategy.
[0107] In step S4, the safety officer takes over the vehicle according to the driving pop-up box information and drives the vehicle according to the fault handling instructions, such as pulling over.
[0108] After the parallel cockpit receives the remote parallel takeover command from the platform, a takeover dialog box automatically pops up, displaying the corresponding fault information and fault handling strategy. After the safety officer clicks the takeover confirmation button, they take over the vehicle and then drive according to the fault handling strategy, such as immediately pulling over.
[0109] If the driver fails to click the confirmation button within the time limit, or clicks the reject takeover button, the platform will immediately reallocate a new Pingxin cockpit and send the takeover instruction after receiving the feedback.
[0110] The embodiment of the present application also provides an unmanned vehicle parallel takeover control device 600, such as Figure 6 , a schematic structural diagram of a parallel takeover control device for an unmanned vehicle in an embodiment of the present application is provided. The parallel takeover control device 600 for an unmanned vehicle includes at least: a starting module 610 and a reporting module 620, wherein:
[0111] In one embodiment of the present application, the startup module 610 is specifically used to: start the vehicle monitoring program to monitor whether the vehicle's automatic driving module is abnormal.
[0112] It's important to note that the "self-vehicle" here refers to the driverless vehicle itself. This means that each autonomous vehicle's monitoring program is independent, but all report to the same cloud-based control platform. The monitoring program only monitors the driverless vehicle in real time and doesn't need to monitor the status of other vehicles.
[0113] After the vehicle monitoring program is started on the vehicle side, it can be used to monitor the working status of the vehicle's automatic driving module and determine whether there is any abnormality in the automatic driving module.
[0114] It's understood that once an unmanned vehicle initiates autonomous driving operations, the vehicle's monitoring program monitors the vehicle's systems in real time. These systems include the intelligent driving control system, the vehicle (the driver), and all relevant sensors. For example, autonomous driving operations can be used in scenarios like robotaxis and robobuses. Another example is the use of specialized vehicles.
[0115] Furthermore, it is necessary to focus on monitoring whether the vehicle's autonomous driving module (intelligent driving control system) is abnormal, because whether the autonomous driving module is abnormal will directly affect the operation or operation of the unmanned vehicle.
[0116] In one embodiment of the present application, the reporting module 620 is specifically used to: if it is monitored that the autonomous driving module of the vehicle has an abnormality and affects the autonomous driving module from executing the preset autonomous driving control instructions in the vehicle, then report to the cloud control platform for parallel takeover of the vehicle.
[0117] When an abnormality is detected in the autonomous driving module of the vehicle, it is necessary to further determine whether the abnormality affects the autonomous driving module's execution of preset autonomous driving control instructions in the vehicle. That is, when a fault is identified in the autonomous driving module in the vehicle-side system, and the fault causes a serious loss of the vehicle's autonomous driving capability and requires parallel takeover, the fault information and response processing strategy are immediately reported to the cloud control platform.
[0118] It is understandable that other faults can also be reported or corresponding control instructions can be issued. Considering that if the fault affects the automatic driving module when the vehicle executes the preset automatic driving control instructions, there will be a major safety hazard for the unmanned vehicle, so the reporting priority at this time is the highest.
[0119] Furthermore, for fault conditions that affect the automatic driving module's execution of preset automatic driving control instructions in the vehicle, real-time synchronous uploading will be adopted, while for fault conditions that do not affect the automatic driving module's execution of preset automatic driving control instructions in the vehicle, asynchronous uploading will be adopted to reduce the computing pressure on the vehicle side.
[0120] In some embodiments, if an abnormality is detected in the autonomous driving module of the vehicle and affects the autonomous driving module's execution of preset autonomous driving control instructions in the vehicle, but does not cause the entire autonomous driving module to lose its entire function, priority can be given to braking the unmanned vehicle and then entering the autonomous driving operation mode after restarting.
[0121] It can be understood that the above-mentioned unmanned vehicle parallel takeover control device can implement the various steps of the unmanned vehicle parallel takeover control method provided in the aforementioned embodiment. The relevant explanations of the unmanned vehicle parallel takeover control method are applicable to the unmanned vehicle parallel takeover control device and will not be repeated here.
[0122] The present application embodiment also provides a cloud control platform 700, such as Figure 7 As shown, a schematic diagram of the structure of the cloud control platform in an embodiment of the present application is provided. The cloud control platform 700 includes at least: a first receiving processing module 710 and an allocation processing module 720, wherein:
[0123] In one embodiment of the present application, the first receiving and processing module 710 is specifically used to: receive abnormal information and fault handling strategy of the target vehicle uploaded by the fault center, the abnormal information of the target vehicle at least includes the fault information of the vehicle's automatic driving module and the fault level corresponding to the automatic driving module, and the fault handling strategy includes a fault handling strategy corresponding to the vehicle abnormal information.
[0124] The cloud control platform receives the abnormal information and fault handling strategy of the target vehicle uploaded by the fault center. When the fault center identifies and confirms the fault, it immediately generates the corresponding fault code information and the corresponding fault handling strategy information, and then reports it to the cloud control platform in real time.
[0125] It is understood that the fault handling strategy includes both the remote parallel takeover handling strategy and the driving strategy after the remote parallel takeover, such as immediate pullover, etc. However, it is not intended to specifically limit the scope of protection of this application.
[0126] Furthermore, the target vehicle's abnormal information includes at least fault information about the vehicle's autonomous driving module and the corresponding fault level of the autonomous driving module. This means that the cloud control platform collects not only fault information but also the fault level of the autonomous driving module in the unmanned vehicle. High-priority fault levels will be remotely controlled, while medium / low-priority fault levels will be stored and generally not interfered with. It is understood that in special circumstances, remote control takeover instructions can also be received and issued.
[0127] Furthermore, the fault handling strategy includes a fault handling strategy corresponding to the vehicle abnormality information. The fault handling strategy is completed and generated on the vehicle side and uploaded to the cloud control platform. The cloud control platform can make a comprehensive judgment based on the actual situation and forward the fault handling strategy to the parallel cockpit.
[0128] In one embodiment of the present application, the allocation processing module 720 is specifically configured to: allocate a parallel cockpit that meets the conditions according to the vehicle abnormality information to perform parallel takeover of the target vehicle in accordance with the fault handling strategy.
[0129] Based on the vehicle abnormality information, the cloud control platform finds a target parallel cockpit among the idle parallel cockpits or those queued in the execution queue to synchronize fault information, takeover instructions, takeover strategies, etc., and then forwards the parallel driving control instructions issued by the target parallel cockpit.
[0130] It can be understood that in the target parallel cockpit, it is necessary to follow the fault handling strategy to take over the target vehicle in parallel, so as to meet the management and control requirements of the cloud control platform.
[0131] It can be understood that the above-mentioned cloud control platform can implement each step of the unmanned vehicle parallel takeover control method provided in the aforementioned embodiment. The relevant explanations on the unmanned vehicle parallel takeover control method are applicable to the cloud control platform and will not be repeated here.
[0132] Figure 8 This is a schematic diagram of the structure of an electronic device according to an embodiment of the present application. Figure 8 At the hardware level, the electronic device includes a processor and, optionally, an internal bus, a network interface, and memory. The memory may include internal memory, such as high-speed random-access memory (RAM), or non-volatile memory, such as at least one disk drive. Of course, the electronic device may also include other hardware required for its services.
[0133] The processor, network interface, and memory can be interconnected via an internal bus, which can be an ISA (Industry Standard Architecture) bus, a PCI (Peripheral Component Interconnect) bus, or an EISA (Extended Industry Standard Architecture) bus. The bus can be divided into an address bus, a data bus, a control bus, etc. For ease of representation, Figure 8 Only one bidirectional arrow is used in the diagram, but this does not mean that there is only one bus or one type of bus.
[0134] The memory is used to store programs. Specifically, the program may include program code, which includes computer operating instructions. The memory may include internal memory and non-volatile memory, and provides instructions and data to the processor.
[0135] The processor reads the corresponding computer program from the non-volatile memory into the internal memory and then runs it, forming a parallel takeover control device for the unmanned vehicle at the logical level. The processor executes the program stored in the memory and is specifically used to perform the following operations:
[0136] Start the vehicle monitoring program to monitor whether the vehicle's autonomous driving module is abnormal;
[0137] If the autonomous driving module of the vehicle is monitored to have an abnormality and it affects the autonomous driving module's execution of the preset autonomous driving control instructions in the vehicle, it will be reported to the cloud control platform for parallel takeover of the vehicle.
[0138] The above application Figure 2 The method performed by the unmanned vehicle parallel takeover control device disclosed in the illustrated embodiment can be applied to a processor or implemented by a processor. The processor may be an integrated circuit chip with signal processing capabilities. During implementation, each step of the above method can be completed by hardware integrated logic circuits in the processor or by software instructions. The above processor can be a general-purpose processor, including a central processing unit (CPU), a network processor (NP), etc.; it can also be a digital signal processor (DSP), an application-specific integrated circuit (ASIC), a field-programmable gate array (FPGA), or other programmable logic devices, discrete gate or transistor logic devices, or discrete hardware components. It can implement or execute the various methods, steps, and logic block diagrams disclosed in the embodiments of this application. The general-purpose processor can be a microprocessor or any conventional processor. The steps of the method disclosed in conjunction with the embodiments of this application can be directly implemented and executed by a hardware decoding processor, or by a combination of hardware and software modules in the decoding processor. The software module can be located in a storage medium well-known in the art, such as random access memory, flash memory, read-only memory, programmable read-only memory, electrically erasable programmable memory, registers, etc. The storage medium is located in the memory, and the processor reads the information in the memory and, in conjunction with its hardware, completes the steps of the above method.
[0139] The electronic device may also perform Figure 2The method for executing the parallel takeover control device of the unmanned vehicle and realizing the parallel takeover control device of the unmanned vehicle in Figure 2 The functions of the illustrated embodiment will not be described in detail in the embodiments of the present application.
[0140] The embodiment of the present application also provides a computer-readable storage medium, which stores one or more programs, wherein the one or more programs include instructions, which, when executed by an electronic device including multiple application programs, can enable the electronic device to execute Figure 2 The method executed by the unmanned vehicle parallel takeover control device in the illustrated embodiment is specifically used to perform:
[0141] Start the vehicle monitoring program to monitor whether the vehicle's autonomous driving module is abnormal;
[0142] If the autonomous driving module of the vehicle is monitored to have an abnormality and it affects the autonomous driving module's execution of the preset autonomous driving control instructions in the vehicle, it will be reported to the cloud control platform for parallel takeover of the vehicle.
[0143] It will be understood by those skilled in the art that embodiments of the present invention may be provided as methods, systems, or computer program products. Thus, the present invention may take the form of an entirely hardware embodiment, an entirely software embodiment, or an embodiment combining software and hardware. Furthermore, the present invention may take the form of a computer program product implemented on one or more computer-usable storage media (including but not limited to magnetic disk storage, CD-ROM, optical storage, etc.) containing computer-usable program code.
[0144] The present invention is described with reference to flowcharts and / or block diagrams of methods, devices (systems), and computer program products according to embodiments of the present invention. It should be understood that each process and / or block in the flowcharts and / or block diagrams, as well as combinations of processes and / or blocks in the flowcharts and / or block diagrams, can be implemented by computer program instructions. These computer program instructions can be provided to a processor of a general-purpose computer, a special-purpose computer, an embedded processor, or other programmable data processing device to produce a machine, so that the instructions executed by the processor of the computer or other programmable data processing device generate instructions for implementing the processes in the flowcharts and / or block diagrams. Figure 1 a process or multiple processes and / or boxes Figure 1 A device that provides the functions specified in a block or multiple blocks.
[0145] These computer program instructions may also be stored in a computer readable memory that can direct a computer or other programmable data processing device to work in a specific manner, so that the instructions stored in the computer readable memory produce an article of manufacture comprising an instruction device, which implements the process Figure 1 a process or multiple processes and / or boxes Figure 1The function specified in one or more boxes.
[0146] These computer program instructions can also be loaded onto a computer or other programmable data processing device so that a series of operating steps are executed on the computer or other programmable device to produce a computer-implemented process, thereby providing the instructions executed on the computer or other programmable device for implementing the process. Figure 1 a process or multiple processes and / or boxes Figure 1 A step that specifies a function in one or more boxes.
[0147] In a typical configuration, a computing device includes one or more processors (CPUs), input / output interfaces, network interfaces, and memory.
[0148] Memory may include non-permanent storage in a computer-readable medium, random access memory (RAM) and / or non-volatile memory in the form of read-only memory (ROM) or flash RAM. Memory is an example of a computer-readable medium.
[0149] Computer-readable media includes permanent and non-permanent, removable and non-removable media that can be implemented by any method or technology to store information. The information can be computer-readable instructions, data structures, program modules or other data. Examples of computer storage media include, but are not limited to, phase change memory (PRAM), static random access memory (SRAM), dynamic random access memory (DRAM), other types of random access memory (RAM), read-only memory (ROM), electrically erasable programmable read-only memory (EEPROM), flash memory or other memory technology, compact disc read-only memory (CD-ROM), digital versatile disc (DVD) or other optical storage, magnetic cassettes, magnetic tape, magnetic disk storage or other magnetic storage devices or any other non-transmission media that can be used to store information that can be accessed by a computing device. As defined herein, computer-readable media does not include transitory computer-readable media (transitory media), such as modulated data signals and carrier waves.
[0150] It should also be noted that the terms "comprises," "includes," or any other variations thereof are intended to encompass non-exclusive inclusion, such that a process, method, commodity, or apparatus that includes a series of elements includes not only those elements but also other elements not explicitly listed, or includes elements inherent to such process, method, commodity, or apparatus. In the absence of further limitations, an element defined by the phrase "comprises a ..." does not exclude the presence of other identical elements in the process, method, commodity, or apparatus that includes the element.
[0151] Those skilled in the art will appreciate that the embodiments of the present application may be provided as methods, systems, or computer program products. Therefore, the present application may take the form of a complete hardware embodiment, a complete software embodiment, or an embodiment combining software and hardware. Furthermore, the present application may take the form of a computer program product implemented on one or more computer-usable storage media (including but not limited to magnetic disk storage, CD-ROM, optical storage, etc.) containing computer-usable program code.
[0152] The foregoing is merely an embodiment of the present application and is not intended to limit the present application. For those skilled in the art, the present application may have various changes and variations. Any modifications, equivalent replacements, improvements, etc. made within the spirit and principles of the present application should all be included within the scope of the claims of the present application.
Claims
1. A parallel takeover control method for an unmanned vehicle, wherein: For a vehicle, the method includes: Start the vehicle monitoring program to monitor whether the vehicle's autonomous driving module is abnormal; If the autonomous driving module of the vehicle is detected to be abnormal and affects the execution of the preset autonomous driving control instructions by the autonomous driving module in the vehicle, the system will report to the cloud control platform for parallel takeover of the vehicle; If an abnormality is detected in the autonomous driving module of the self-driving vehicle and affects the self-driving module's ability to execute preset autonomous driving control instructions but does not cause the entire autonomous driving module to lose its functionality, the unmanned vehicle will be braked and restarted before entering the autonomous driving mode; The method further comprises: Assessing a fault level of the autonomous driving module; If the fault level is the first fault level, reporting to the cloud control platform; If the fault level is the second fault level, initiating a braking procedure to stop the vehicle safely, wherein the priority of the first fault level is greater than the second fault level; The monitoring of an abnormality in the autonomous driving module of the vehicle and the impact on the autonomous driving module executing the preset autonomous driving control instructions in the vehicle includes: If the autonomous driving module of the vehicle is detected to be abnormal and at a first fault level, the autonomous driving module is traversed to determine the fault nodes that affect the autonomous driving module from executing the preset autonomous driving control instructions in the vehicle, the fault nodes including the perception and positioning nodes, the decision-making and planning nodes, and the motion control nodes; and / or, If it is monitored that the automatic driving module of the own vehicle is abnormal and is at the second fault level, the own vehicle monitoring program is started again after the braking program is started to stop the vehicle safely.
2. The method according to claim 1, wherein: The reporting to the cloud control platform for parallel takeover of the vehicle also includes: executing preset safety control instructions on the vehicle.
3. A parallel takeover control method for an unmanned vehicle, wherein: For a cloud control platform, the method includes: receiving abnormality information and a fault handling strategy of a target vehicle uploaded by a fault center, wherein the abnormality information of the target vehicle includes at least fault information of an autonomous driving module of the vehicle and a fault level corresponding to the autonomous driving module, and the fault handling strategy includes a fault handling strategy corresponding to the abnormality information of the target vehicle; According to the vehicle abnormality information, a parallel cockpit that meets the conditions is allocated to take over the target vehicle in parallel according to the fault handling strategy; If the vehicle monitoring program detects an abnormality in the autonomous driving module of the vehicle and the abnormality affects the autonomous driving module's ability to execute the preset autonomous driving control instructions but does not cause the entire autonomous driving module to lose its function, the unmanned vehicle will be braked and restarted before entering the autonomous driving mode. The method further comprises: Assessing a fault level of the autonomous driving module; If the fault level is the first fault level, reporting to the cloud control platform; If the fault level is the second fault level, initiating a braking procedure to stop the vehicle safely, wherein the priority of the first fault level is greater than the second fault level; The monitoring of an abnormality in the autonomous driving module of the vehicle and the impact on the autonomous driving module executing the preset autonomous driving control instructions in the vehicle includes: If the autonomous driving module of the vehicle is detected to be abnormal and at a first fault level, the autonomous driving module is traversed to determine the fault nodes that affect the autonomous driving module from executing the preset autonomous driving control instructions in the vehicle, the fault nodes including the perception and positioning nodes, the decision-making and planning nodes, and the motion control nodes; and / or, If it is monitored that the automatic driving module of the own vehicle is abnormal and is at the second fault level, the own vehicle monitoring program is started again after the braking program is started to stop the vehicle safely.
4. The method according to claim 3, wherein: The fault level includes: a first fault level, abnormal information of the target vehicle uploaded by the fault receiving center, and a fault handling strategy, including: Abnormal information and a fault handling strategy of the target vehicle whose fault level is the first fault level are received in real time, the fault handling strategy is responsive to the abnormal information, the fault handling strategy includes at least one of the following: a remote parallel takeover processing strategy, a driving strategy after remote parallel takeover processing, and the abnormal information includes at least one of the following: a lidar sensor abnormality, an automatic driving control system planning node abnormality, and a positioning sensor inertial navigation abnormality.
5. The method according to claim 3, wherein: The method further comprises: receiving a response instruction from the parallel cockpit, wherein the response instruction includes at least one of the following: a timeout response and a takeover refusal response; The parallel cockpits are reallocated according to a result of a timeout response or a takeover refusal response in the response instruction.
6. A parallel takeover control device for an unmanned vehicle, wherein: For use on a vehicle, the device comprises: The startup module is used to start the vehicle monitoring program and monitor whether the vehicle's automatic driving module is abnormal; A reporting module is configured to report to the cloud control platform for parallel takeover of the vehicle if an abnormality is detected in the autonomous driving module of the vehicle and affects the autonomous driving module's ability to execute preset autonomous driving control instructions in the vehicle; and to assess the fault level of the autonomous driving module; If the fault level is the first fault level, reporting to the cloud control platform; If the fault level is the second fault level, initiating a braking procedure to stop the vehicle safely, wherein the priority of the first fault level is greater than the second fault level; If an abnormality is detected in the autonomous driving module of the self-driving vehicle and affects the self-driving module's ability to execute preset autonomous driving control instructions but does not cause the entire autonomous driving module to lose its functionality, the unmanned vehicle will be braked and restarted before entering the autonomous driving mode; The unmanned vehicle parallel takeover control method further includes: Assessing a fault level of the autonomous driving module; If the fault level is the first fault level, reporting to the cloud control platform; If the fault level is the second fault level, initiating a braking procedure to stop the vehicle safely, wherein the priority of the first fault level is greater than the second fault level; The monitoring of an abnormality in the autonomous driving module of the vehicle and the impact on the autonomous driving module executing the preset autonomous driving control instructions in the vehicle includes: If the autonomous driving module of the vehicle is detected to be abnormal and at a first fault level, the autonomous driving module is traversed to determine the fault nodes that affect the autonomous driving module from executing the preset autonomous driving control instructions in the vehicle, the fault nodes including the perception and positioning nodes, the decision-making and planning nodes, and the motion control nodes; and / or, If it is monitored that the automatic driving module of the own vehicle is abnormal and is at the second fault level, the own vehicle monitoring program is started again after the braking program is started to stop the vehicle safely.
7. A cloud control platform, wherein: include: a first receiving and processing module, configured to receive abnormality information and a fault handling strategy of a target vehicle uploaded by a fault center, wherein the abnormality information of the target vehicle includes at least fault information of the vehicle's automatic driving module and a fault level corresponding to the automatic driving module, and the fault handling strategy includes a fault handling strategy corresponding to the abnormality information of the target vehicle; An allocation processing module is used to allocate a parallel cockpit that meets the conditions according to the vehicle abnormality information to perform parallel takeover of the target vehicle according to the fault processing strategy; If the vehicle monitoring program detects an abnormality in the autonomous driving module of the vehicle and the abnormality affects the autonomous driving module's ability to execute the preset autonomous driving control instructions but does not cause the entire autonomous driving module to lose its function, the unmanned vehicle will be braked and restarted before entering the autonomous driving mode. The unmanned vehicle parallel takeover control method of the cloud control platform further includes: evaluating the fault level of the automatic driving module; If the fault level is the first fault level, reporting to the cloud control platform; If the fault level is the second fault level, initiating a braking procedure to stop the vehicle safely, wherein the priority of the first fault level is greater than the second fault level; The monitoring of an abnormality in the autonomous driving module of the vehicle and the impact on the autonomous driving module executing the preset autonomous driving control instructions in the vehicle includes: If the autonomous driving module of the vehicle is detected to be abnormal and at a first fault level, the autonomous driving module is traversed to determine the fault nodes that affect the autonomous driving module from executing the preset autonomous driving control instructions in the vehicle, the fault nodes including the perception and positioning nodes, the decision-making and planning nodes, and the motion control nodes; and / or, If it is monitored that the automatic driving module of the own vehicle is abnormal and is at the second fault level, the own vehicle monitoring program is started again after the braking program is started to stop the vehicle safely.
8. An electronic device comprising: processor; as well as A memory arranged to store computer-executable instructions, which, when executed, cause the processor to perform the method of any one of claims 1 to 2, or the method of any one of claims 3 to 5.
Citation Information
Patent Citations
Remote control takeover method, device and system, medium and unmanned vehicle
CN111994094A
Exception handling method in parallel driving, automatic driving vehicle and cloud cockpit
CN112622931A
Automatic driving vehicle control method, device and equipment and storage medium
CN113341955A