Redundant control systems, methods, and vehicles for autonomous vehicles
By using a second domain controller in a redundant control system to control the vehicle to a safe stop when the VCU fails, the safety and cost issues of advanced autonomous vehicles in the event of VCU failure are resolved, thereby improving vehicle safety and user experience.
Patent Information
- Authority / Receiving Office
- CN · China
- Patent Type
- Patents(China)
- Current Assignee / Owner
- Filing Date
- 2022-12-13
- Publication Date
- 2026-04-03
AI Technical Summary
In existing technologies, when the VCU (Vehicle Control Unit) fails, advanced autonomous vehicles require manual intervention to safely pull over, resulting in poor safety and user experience. At the same time, achieving the ASIL (Autonomous, Inertial, and Liability) level requirement for the VCU is costly.
A redundant control system is adopted, including a first domain controller and a second domain controller. When the first VCU fails, the second domain controller identifies the torque demand signal and generates control commands to control the vehicle to stop safely, avoiding the need to deploy a separate ASIL D level controller. The communication load is reduced by handshaking verification between the main VCU and the redundant VCU and using the same ID information.
This enables vehicles to enter a Fail-Operational state when the VCU fails, improving safety and user experience, reducing project costs, and avoiding vehicle malfunctions caused by signal confusion.
Smart Images

Figure CN115805964B_ABST
Abstract
Description
Technical Field
[0001] This application relates to the field of functional safety technology for autonomous driving, and in particular to a redundant control system, method and vehicle for autonomous driving. Background Technology
[0002] The changes between advanced autonomous driving functions and driver assistance functions are mainly reflected in two aspects: on the one hand, the addition of urban autonomous driving functions and allowing users to take their hands off the wheel for extended periods of time; on the other hand, when a component of the system fails, the safety status of the vehicle changes from Fail-Safe to Fail-Operational.
[0003] In related technologies, when autonomous vehicles experience problems such as accidental acceleration, it is considered that accidental acceleration is mainly due to two possibilities: incorrect torque output by the autonomous driving system or incorrect power output by the VCU (Vehicle Control Unit). Therefore, the central domain controller and the VCU are required to meet ASIL D (Automotive Safety Level D, representing the highest level of vehicle hazard) requirements. However, for vehicles equipped with advanced autonomous driving functions, the powertrain VCU needs to meet the ASIL D requirements as a whole to achieve the safety goal of avoiding accidental acceleration. In addition, the vehicle needs to be equipped with redundant VCUs to achieve fail-operational operation, which is costly. Furthermore, when the vehicle malfunctions, the driver needs to take over the vehicle and control its smooth operation, which reduces vehicle safety and user experience. Summary of the Invention
[0004] This application provides a redundant control system, method, and vehicle for autonomous vehicles to address the problems in related technologies, such as the high cost of achieving ASIL level for VCUs and the need for manual takeover to perform safe parking maneuvers when the main VCU fails, resulting in poor vehicle intelligence and safety, and a poor user experience.
[0005] A first aspect of this application provides a redundant control system for an autonomous vehicle, comprising: a motor controller for controlling the output of a target torque by a motor; a first domain controller, wherein a first vehicle control unit (VCU) is integrated within the first domain controller, wherein the first VCU is used to identify a torque demand signal sent by the first domain controller to obtain a demand torque, and to send a first control command generated based on the demand torque to the motor controller; and a second domain controller, wherein a second VCU is integrated within the second domain controller, wherein the second VCU is used to identify a torque demand signal sent by the first domain controller to obtain a demand torque when the first VCU is in a preset failure state, and to send a second control command generated based on the demand torque to the motor controller, thereby controlling the vehicle to perform a preset safe stopping action, thus realizing redundant control of the autonomous vehicle.
[0006] Based on the above technical means, in this embodiment, the motor controller is used to control the motor to output the target torque; the first vehicle controller (VCU) in the first domain controller identifies the torque demand signal to obtain the required torque, and sends the first control command it generates to the motor controller so as to control the vehicle to adjust the vehicle speed or pedal depth according to different needs; the second VCU in the second domain controller is used to control the vehicle to perform a safe parking action when the first VCU is in a failure state, so as to realize the redundant control of autonomous driving. When the main VCU fails, it ensures that the vehicle can enter the Fail-Operational state and safely pull over to the side of the road, thereby improving the safety of the vehicle and the user's driving experience, and avoiding the separate deployment of ASIL D level controllers, thereby reducing project costs.
[0007] Optionally, the second VCU is further configured to send a failure flag of the first VCU to the motor controller when the first VCU is in a preset failure state; the motor controller responds to the second control command based on the failure flag.
[0008] According to the above technical means, in the embodiment of this application, when the first VCU is in a failed state, the second VCU sends the failure flag of the first VCU to the motor controller. Then, after receiving the failure signal, the motor controller starts to respond to the second control command, so as to avoid the motor controller receiving signals in a chaotic manner and causing vehicle failure, thereby improving vehicle safety and user experience.
[0009] Optionally, the motor controller is further configured to, upon receiving the failure flag, if a first control command sent by the first VCU is received within the vicinity of the current ignition, ignore the first control command and continue to execute the second control command.
[0010] According to the above technical means, in this embodiment of the application, if the motor controller is still in the state after receiving the lost flag, the first control command sent by the first VCU in the surrounding area is ignored, and the second control command is continued to be executed, so as to avoid the motor controller receiving signals chaotic and causing vehicle failure, thereby improving vehicle safety and user experience.
[0011] Optionally, it further includes: a third domain controller, used to communicate with the first domain controller, and if the communication link between the third domain controller and the first domain controller is in a preset normal communication state and the first VCU is in a normal state, forwarding the first control command or other control commands generated by the first VCU to the motor controller.
[0012] According to the above technical means, in this embodiment of the application, the third domain controller communicates with the first domain controller and establishes a communication link. When the communication link is in a normal communication state and the first VCU is in a normal state, the third domain controller forwards the first control command or other control commands to the motor controller to ensure that the control commands are transmitted to the motor controller to control the vehicle, ensuring the timeliness of communication and improving the safety of the vehicle.
[0013] Optionally, the second domain controller is further configured to forward the first control command to the motor controller when the communication link between the third domain controller and the first domain controller is in a preset abnormal communication state and the first VCU is in a preset normal state.
[0014] Based on the above technical means, in this embodiment of the application, when the communication link between the third domain controller and the first domain controller is in an abnormal communication state and the first VCU is in a normal state, the second domain controller forwards the first control command to the motor controller, ensuring that the vehicle receives relevant information in a timely manner, thereby improving vehicle safety and user experience.
[0015] Optionally, the first domain controller and the second domain controller perform a handshake verification. After the verification is successful, the torque demand signal is synchronously sent to the second VCU of the second domain controller.
[0016] Based on the above technical means, in this embodiment of the application, the first domain controller and the second domain controller perform handshake verification, and after the verification is successful, the synchronous torque demand signal is sent to the second VCU of the second domain controller. The main VCU and the redundant VCU use the same ID information for control, thereby reducing the communication load of the whole vehicle and improving the communication efficiency of the whole vehicle.
[0017] Optionally, the first domain controller is further configured to determine that communication between the second VCU of the second domain controller and the second domain controller is lost when the handshake verification with the second domain controller fails, generate a third control command, and send the third control command to the motor controller to control the vehicle to perform a preset safe stopping action.
[0018] Based on the above technical means, in this embodiment of the application, when the handshake verification between the first domain controller and the second domain controller fails, it is determined whether the communication between the first domain controller and the second VCU of the second domain controller is lost. When the communication is lost, a third control command is generated and sent to the motor controller to control the vehicle to safely pull over and park, thereby ensuring the driving safety of the vehicle and improving the user's driving experience.
[0019] Optionally, the identifiers for the messages sent by the first VCU and the second VCU are the same.
[0020] Based on the above technical means, in the embodiments of this application, the identifiers of the messages sent by the first VCU and the second VCU are the same, and the vehicle is controlled, thereby reducing the communication load of the whole vehicle and improving the communication efficiency of the whole vehicle.
[0021] A second aspect of this application provides a vehicle including a redundant control system for an autonomous vehicle as described above.
[0022] A third aspect of this application provides a redundancy control method for an autonomous vehicle, comprising the following steps: detecting whether the first VCU is in a preset failure state; if the first VCU is in a preset failure state, identifying the torque demand signal sent by the first domain controller to obtain the demand torque; generating a second control command based on the demand torque, and sending the second control command to the motor controller to control the vehicle to perform a preset safe parking action, thereby realizing redundancy control of the autonomous vehicle.
[0023] Therefore, this application has at least the following beneficial effects:
[0024] (1) In this embodiment, the motor controller is used to control the motor to output the target torque; the first vehicle controller (VCU) in the first domain controller identifies the torque demand signal to obtain the required torque, and sends the first control command it generates to the motor controller so as to control the vehicle to adjust the vehicle speed or pedal depth according to different needs. The second VCU in the second domain controller is used to control the vehicle to perform a safe parking action when the first VCU is in a failure state, so as to realize the redundant control of autonomous driving. When the main VCU fails, it ensures that the vehicle can enter the Fail-Operational state and safely pull over to the side of the road, thereby improving the safety of the vehicle and the user's driving experience, and avoiding the separate deployment of ASIL D level controllers, thereby reducing project costs.
[0025] (2) In this embodiment of the application, when the first VCU is in a failed state, the second VCU sends the failure flag of the first VCU to the motor controller. Then, after receiving the failure signal, the motor controller starts to respond to the second control command, so as to avoid the motor controller receiving signals in a chaotic manner and causing vehicle failure, thereby improving vehicle safety and user experience.
[0026] (3) In this embodiment, if the motor controller is still in the state after receiving the flag loss flag, the first control command sent by the first VCU in the surrounding area is ignored and the second control command is continued to be executed, so as to avoid the motor controller receiving signal confusion causing vehicle failure, and improve vehicle safety and user experience.
[0027] (4) In this embodiment of the application, the third domain controller communicates with the first domain controller and establishes a communication link. When the communication link is in a normal communication state and the first VCU is in a normal state, the third domain controller forwards the first control instruction or other control instructions to the motor controller to ensure that the control instructions are transmitted to the motor controller to control the vehicle, ensuring the timeliness of communication and improving the safety of the vehicle.
[0028] (5) In this embodiment of the application, when the communication link between the third domain controller and the first domain controller is in an abnormal communication state and the first VCU is in a normal state, the second domain controller forwards the first control command to the motor controller to ensure that the vehicle receives relevant information in a timely manner, thereby improving the vehicle's safety and the user's driving experience.
[0029] (6) In this embodiment of the application, the first domain controller and the second domain controller perform handshake verification, and after the verification is successful, the synchronous torque demand signal is sent to the second VCU of the second domain controller. The main VCU and the redundant VCU use the same ID information for control, which reduces the communication load of the whole vehicle and improves the communication efficiency of the whole vehicle.
[0030] (7) In this embodiment of the application, when the handshake verification between the first domain controller and the second domain controller fails, it is determined whether the communication between the first domain controller and the second VCU of the second domain controller is lost. When the communication is lost, a third control command is generated and sent to the motor controller to control the vehicle to safely pull over and park, ensuring the driving safety of the vehicle and improving the user's driving experience.
[0031] (8) In the embodiments of this application, the identifiers of the messages sent by the first VCU and the second VCU are the same, and the vehicle is controlled to reduce the communication load of the whole vehicle and improve the communication efficiency of the whole vehicle.
[0032] Additional aspects and advantages of this application will be set forth in part in the description which follows, and in part will be obvious from the description, or may be learned by practice of this application. Attached Figure Description
[0033] The above and / or additional aspects and advantages of this application will become apparent and readily understood from the following description of the embodiments taken in conjunction with the accompanying drawings, wherein:
[0034] Figure 1 This is a block diagram of a redundant control system for an autonomous vehicle according to an embodiment of this application;
[0035] Figure 2 This is a functional block diagram of a vehicle system according to an embodiment of this application;
[0036] Figure 3 This is a flowchart illustrating the interaction between the modules of the vehicle control system according to an embodiment of this application.
[0037] Figure 4 This is a flowchart of a redundancy control method for an autonomous vehicle according to an embodiment of this application. Detailed Implementation
[0038] The embodiments of this application are described in detail below. Examples of the embodiments are shown in the accompanying drawings, wherein the same or similar reference numerals denote the same or similar elements or elements having the same or similar functions throughout. The embodiments described below with reference to the accompanying drawings are exemplary and intended to explain this application, and should not be construed as limiting this application.
[0039] The changes between current advanced driver-assistance systems (ADAS) and driver assistance systems are mainly reflected in two aspects: firstly, the addition of urban autonomous driving capabilities and allowing users to take their hands off the wheel for extended periods; secondly, the change in the vehicle's safety status from Fail-Safe to Fail-Operational when a component fails. Based on this, and considering hazard analysis and risk assessment, the overall functionality of urban autonomous driving systems must meet ASIL (Automotive Safety Level) D requirements when there is unintended acceleration in the powertrain. Furthermore, when the powertrain VCU fails, a redundant VCU must be available to continue taking over the vehicle's driving status, ensuring the vehicle can continue operating and safely pull over.
[0040] Regarding the safety objective of avoiding unintended acceleration, fault tree analysis based on the ISO 26262 standard considers that unintended acceleration mainly stems from two possibilities: incorrect torque output by the autonomous driving system or incorrect power output by the VCU. Therefore, both the central domain controller and the VCU are required to meet ASIL D requirements. Consequently, for vehicles equipped with advanced autonomous driving functions, the powertrain VCU must meet ASIL D requirements as a whole to achieve the safety objective of avoiding unintended acceleration, and the vehicle must be equipped with redundant VCUs to achieve fail-operational operation.
[0041] Therefore, how to solve the problems in advanced autonomous driving, such as the main VCU needing to meet ASIL D requirements to mitigate the dangers of false acceleration, and the vehicle system also needing to be equipped with a redundant VCU to ensure that the vehicle can safely pull over to the side of the road when the main VCU fails, is a problem that urgently needs to be solved by those skilled in the art.
[0042] In related technology (1), the backup controller determines that the vehicle control unit (VCU) has failed. The backup controller stores the VCU backup software and can start the VCU backup software. When the VCU fails, the backup controller, which is connected to the VCU, starts the VCU backup software to replace the VCU's management and control functions for the electric vehicle drive system. This avoids the situation in the prior art where the VCU cannot manage and control the electric vehicle drive system when communication between the VCU and other units in the electric vehicle drive system fails. This increases the normal operating probability of the electric vehicle drive system, improves the safety performance of the electric vehicle drive system, and thus ensures the safety of the vehicle and its occupants. However, related technology (1) mainly involves the backup of the VCU and does not consider the problem of common cause failure of software. In addition, it does not specify the ASIL level of the main VCU and the safety objectives it covers.
[0043] In related technology (2), a main controller and a backup controller are used to send control commands. The network for transmitting commands uses a main communication network and a backup communication network. The steering redundancy control system and the braking redundancy control system that execute commands also use two actuators with independent execution capabilities. This ensures that even in the event of the most severe single-point failure, the transmission and execution of commands can still be guaranteed, thereby ensuring driving safety. The system in related technology (2) as a whole can achieve a fail-safe state, that is, it can safely stop in the same lane when a certain component of the system fails. However, it does not mention the power-related redundancy control, the ASIL level of the main VCU, or the safety targets it can cover.
[0044] In summary, in the field of advanced automated driving functional safety, how to achieve the ASIL level of VCU at a lower cost and also ensure that the vehicle can enter the Fail-Operational state and safely pull over when the main VCU fails is a problem that needs to be solved by those skilled in the art.
[0045] The following description, with reference to the accompanying drawings, describes a redundant control system, method, and vehicle for an autonomous vehicle according to embodiments of this application. Specifically, Figure 1 This is a block diagram illustrating a redundant control system for an autonomous vehicle provided in an embodiment of this application.
[0046] like Figure 1As shown, the redundant control system 10 of the autonomous vehicle includes: a motor controller 100, a first domain controller 200, and a second domain controller 300.
[0047] The motor controller 100 is used to control the motor to output the target torque. The first domain controller 200 integrates a first vehicle controller (VCU), which is used to identify the torque demand signal sent by the first domain controller to obtain the demand torque, and send a first control command generated based on the demand torque to the motor controller 100. The second domain controller 300 integrates a second VCU, which is used to identify the torque demand signal sent by the first domain controller to obtain the demand torque when the first VCU is in a preset failure state, and send a second control command generated based on the demand torque to the motor controller 100 to control the vehicle to perform a preset safe stopping action, thereby realizing redundant control of the autonomous vehicle.
[0048] The preset failure state can be a user-defined failure state, such as the first VCU being unable to send control commands to the motor controller, or the first VCU experiencing a certain fault. The determination can be made according to the specific situation, and no specific limitation is made here.
[0049] The preset safe parking actions can be a series of actions required for a vehicle to safely pull over to the side of the road, and are not specifically limited here.
[0050] The first VCU is the master VCU, and the second VCU is a redundant VCU.
[0051] It is understood that in this embodiment, the motor controller is used to control the motor to output the target torque; the first vehicle controller (VCU) in the first domain controller identifies the torque demand signal to obtain the required torque, and sends the first control command it generates to the motor controller so as to control the vehicle to adjust the vehicle speed or pedal depth according to different needs; the second VCU in the second domain controller is used to control the vehicle to perform a safe parking action when the first VCU is in a failure state, so as to realize the redundant control of autonomous driving. When the main VCU fails, it ensures that the vehicle can enter the Fail-Operational state and safely pull over to the side of the road, thereby improving the safety of the vehicle and the user's driving experience, and avoiding the separate deployment of ASIL D level controllers, thereby reducing project costs.
[0052] In this embodiment, the second VCU is further configured to send a failure flag of the first VCU to the motor controller when the first VCU is in a preset failure state; the motor controller responds to the second control command based on the failure flag.
[0053] It is understood that in the embodiments of this application, when the first VCU is in a failed state, the second VCU sends the failure flag of the first VCU to the motor controller. Then, after receiving the failure signal, the motor controller starts to respond to the second control command, so as to avoid the motor controller receiving signals in a chaotic state and causing vehicle failure, thereby improving vehicle safety and user experience.
[0054] In this embodiment of the application, the motor controller is further configured to, after receiving a failure flag, if a first control command sent by a first VCU is received within the current ignition area, ignore the first control command and continue to execute the second control command.
[0055] It is understood that in this embodiment of the application, if the motor controller is still in the state after receiving the flag loss flag, the first control command sent by the first VCU in the surrounding area is ignored, and the second control command is continued to be executed. This avoids the motor controller receiving chaotic signals and causing vehicle failure, thereby improving vehicle safety and user experience.
[0056] In this embodiment of the application, system 10 further includes a third domain controller.
[0057] The third domain controller is used to communicate with the first domain controller. If the communication link between the third domain controller and the first domain controller is in a preset normal communication state and the first VCU is in a preset normal state, the third domain controller forwards the first control command or other control commands generated by the first VCU to the motor controller.
[0058] The default normal communication state can be that the third domain controller can receive control commands generated by the first VCU in the first domain controller, without being specifically limited here.
[0059] It is understood that in this embodiment of the application, the third domain controller communicates with the first domain controller and establishes a communication link. When the communication link is in a normal communication state and the first VCU is in a normal state, the third domain controller forwards the first control command or other control commands to the motor controller to ensure that the control commands are transmitted to the motor controller to control the vehicle, ensuring the timeliness of communication and improving the safety of the vehicle.
[0060] In this embodiment, the second domain controller is further configured to forward the first control command to the motor controller when the communication link between the third domain controller and the first domain controller is in a preset abnormal communication state and the first VCU is in a preset normal state.
[0061] The preset abnormal communication state can be that the third domain controller cannot receive control commands generated by the first VCU in the first domain controller, which is not specifically limited here.
[0062] The preset normal state can be that the first VCU is in a normal working state, without being specifically limited here.
[0063] It is understood that in this embodiment of the application, when the communication link between the third domain controller and the first domain controller is in an abnormal communication state and the first VCU is in a normal state, the second domain controller forwards the first control command to the motor controller to ensure that the vehicle receives relevant information in a timely manner, thereby improving vehicle safety and user experience.
[0064] In this embodiment, the first domain controller and the second domain controller perform a handshake verification. After the verification is successful, the torque demand signal is synchronously sent to the second VCU of the second domain controller.
[0065] The handshake verification can be a method between the first domain controller and the second domain controller to determine whether to exchange information by verifying the identity of the other party, and no specific limitation is made here.
[0066] It is understood that in this embodiment of the application, the first domain controller and the second domain controller perform handshake verification, and after the verification is successful, the synchronous torque demand signal is sent to the second VCU of the second domain controller, so that the main VCU and the redundant VCU use the same ID information for control, thereby reducing the communication load of the whole vehicle and improving the communication efficiency of the whole vehicle.
[0067] In this embodiment, the first domain controller is further configured to determine that communication between the second VCU of the second domain controller and the second domain controller is lost when the handshake verification with the second domain controller fails, and then generate a third control command and send the third control command to the motor controller to control the vehicle to perform a preset safe stopping action.
[0068] It is understood that in this embodiment of the application, when the handshake verification between the first domain controller and the second domain controller fails, it determines whether the communication between the first domain controller and the second VCU of the second domain controller is lost. When the communication is lost, a third control command is generated and sent to the motor controller to control the vehicle to safely pull over and park, thereby ensuring the driving safety of the vehicle and improving the user's driving experience.
[0069] In this embodiment of the application, the identifiers for the messages sent by the first VCU and the second VCU are the same.
[0070] It is understood that in the embodiments of this application, the identifiers of the messages sent by the first VCU and the second VCU are the same, and the vehicle is controlled to reduce the communication load of the whole vehicle and improve the communication efficiency of the whole vehicle.
[0071] According to the redundant control system for autonomous vehicles proposed in this application, the first vehicle control unit (VCU) in the first domain controller identifies the torque demand signal to obtain the required torque and sends the generated first control command to the motor controller to control the vehicle to adjust the vehicle speed or pedal depth according to different needs. The second VCU in the second domain controller is used to control the vehicle to perform a safe parking action when the first VCU fails, achieving redundant control for autonomous driving. When the main VCU fails, it ensures that the vehicle can enter a fail-operational state and safely pull over, improving vehicle safety and user experience. Furthermore, it avoids the need to deploy a separate ASIL D-level controller, thereby reducing project costs. This solves the problems of high cost for ASIL-level VCUs in related technologies, and the need for manual takeover to perform safe parking actions when the main VCU fails, resulting in poor vehicle intelligence and safety, and a poor user experience.
[0072] The following will combine Figure 2 and Figure 3 The redundant control system of autonomous vehicles is described in detail. The first domain controller is illustrated using the central domain controller as an example, the second domain controller using area controller 2 as an example, and the third domain controller using area controller 1 as an example, as detailed below:
[0073] The redundant control system of an autonomous vehicle includes a central domain controller, area controller 1, area controller 2, motor controller 1, and motor controller 2. The central domain controller meets ASIL D level, while area controllers 1 and 2 meet ASIL B level. The central domain controller integrates the main VCU control, and area controller 2 integrates redundant VCU control. The specific implementation process is illustrated through the following examples:
[0074] (1) The central domain controller sends intelligent driving related instructions to the main VCU. The main VCU sends the same ID message through two CAN channels (CAN1 / CAN4, CAN2 / CAN3) to control the motor controller 1 / 2. The central domain controller and the regional domain controller 2 perform handshake verification. After the verification is successful, the intelligent driving control instructions are synchronously sent to the redundant VCU of the regional domain controller 2 through CAN2.
[0075] (2) The main VCU is integrated into the central domain controller. The main VCU as a whole meets ASIL D level. The main VCU, in conjunction with its own status monitoring, verifies whether the acceleration of the required torque sent exceeds a certain value and lasts for a certain period of time. If so, the verification fails, and the main VCU needs to limit the acceleration of its own torque output; otherwise, the torque output is controlled normally. This can cover the safety target of erroneous acceleration under advanced autonomous driving, and also avoids the separate deployment of ASIL D level controllers, thereby reducing project costs.
[0076] (3) Under normal circumstances, the main VCU sends the torque control command to the motor controller 1 / 2 through the CAN1 / CAN4 link; when the CAN communication link is abnormal, the main VCU sends the torque control command to the motor controller through the CAN2 / CAN3 link to perform torque control.
[0077] (4) If the chip with redundant VCU integrated in the regional domain controller 2 fails, the handshake verification between the redundant VCU and the central domain controller will be abnormal. When the central domain controller determines that the communication with the redundant VCU is lost, it will perform a function degradation process and send the relevant control commands to the motor controller 1 / 2 via the main VCU to safely pull over and stop.
[0078] (5) If the chip of the main VCU integrated in the central domain controller fails, the central domain controller will send the intelligent driving information to the redundant VCU in the regional domain controller 2. The redundant VCU in the regional domain controller 2 determines that the bus information with the main VCU is lost. It arbitrates the torque demand sent by the intelligent driving system and the torque status of the redundant VCU itself and sends the redundant torque control command to the motor controller 1 / 2. The redundant VCU also sends the main VCU failure flag bit to the motor controller 1 / 2. The motor controller 1 / 2 determines that it has not received the main VCU related information sent by the CAN1 / CAN4 link. Based on the main VCU failure flag bit sent by the redundant VCU, it responds to the control command of the redundant VCU and performs a safe pull-over. The control commands sent synchronously by the redundant VCU use the same ID message to send the relevant redundant control commands, avoiding the addition of new communication interaction messages and reducing the communication load.
[0079] Specifically, when the redundant VCU determines that the main VCU has failed, the redundant VCU receives the intelligent driving torque command to perform torque control. Furthermore, the driving demand torque calculated by the redundant VCU is compared with the intelligent driving torque of the central domain control and the torque command is arbitrated and output. When in driving state, if it is in overrunning state, the driving torque calculated by the redundant VCU is output; otherwise, the intelligent driving torque is output. When in feedback state, the redundant VCU responds to the larger value of the feedback torque and outputs it.
[0080] (6) If the chip integrating the main VCU in the central domain controller fails and communication is restored, then during the current ignition cycle, the motor controller 1 / 2 will not respond to the control information of the main VCU of CAN1 / CAN4, and will continue to maintain redundant VCU control to safely pull over.
[0081] In summary, the main VCU in this embodiment is integrated into the central domain controller, while meeting the ASIL D level safety target and the safety requirements of advanced autonomous driving functions, thus saving project R&D costs; the redundant VCU is integrated into the regional domain controller, which meets the requirements of vehicle fail-operational and safe parking, ensuring the safety of vehicle personnel and property; the main VCU and the redundant VCU use the same ID information for control, reducing the vehicle communication load and improving the vehicle communication efficiency.
[0082] This application also provides a vehicle that implements the redundant control system for the above-described autonomous driving vehicle.
[0083] Next, with reference to the accompanying drawings, a redundancy control method for an autonomous vehicle proposed according to an embodiment of this application is described.
[0084] Figure 4 This is a flowchart of a redundancy control method for an autonomous vehicle according to an embodiment of this application.
[0085] like Figure 4 As shown, the redundancy control method for this autonomous vehicle includes the following steps:
[0086] In step S101, it is detected whether the first VCU is in a preset failure state.
[0087] It is understood that the embodiments of this application detect whether the first VCU is in a malfunctioning state in order to determine whether to use the control command generated by the first VCU to control the vehicle to safely pull over.
[0088] In step S102, if the first VCU is in a preset failure state, the torque demand signal sent by the first domain controller is identified to obtain the demand torque.
[0089] It is understood that, in the embodiments of this application, when the first VCU is in a preset failure state, the torque demand signal sent by the first domain controller is identified to obtain the demand torque, so as to generate corresponding control commands based on the demand torque.
[0090] In step S103, a second control command is generated based on the required torque and sent to the motor controller to control the vehicle to perform a preset safe parking action, thereby achieving redundant control of the autonomous vehicle.
[0091] It is understood that, in the embodiments of this application, when the first VCU is in a preset failure state, the required torque is obtained by using the second VCU and a second control command is sent to the motor controller to control the vehicle to safely pull over and stop, thereby realizing redundant control of the autonomous vehicle. When the main VCU fails, it ensures that the vehicle can enter the Fail-Operational state and safely pull over, improving vehicle safety and user experience, and avoiding the need to deploy a separate ASIL D level controller, thereby reducing project costs.
[0092] It should be noted that the foregoing explanation of the redundant control system embodiment for autonomous vehicles also applies to the redundant control method for autonomous vehicles in this embodiment, and will not be repeated here.
[0093] The redundant control method for autonomous vehicles proposed in this application identifies the required torque from the torque demand signal sent by the first domain controller when the first VCU is detected to be in a preset failure state. The required torque is then obtained using the second VCU, and a second control command is sent to the motor controller to control the vehicle to safely pull over. This achieves redundant control of the autonomous vehicle. When the main VCU fails, the vehicle can enter a fail-operational state and safely pull over, improving vehicle safety and user experience. Furthermore, it avoids the need for a separate ASIL D level controller, thus reducing project costs. This solves the problems of high cost for ASIL-level VCUs in related technologies, and the need for manual intervention to perform safe pulling over when the main VCU fails, resulting in poor vehicle intelligence, safety, and user experience.
[0094] In the description of this specification, the references to terms such as "one embodiment," "some embodiments," "example," "specific example," or "some examples," etc., indicate that a specific feature, structure, material, or characteristic described in connection with that embodiment or example is included in at least one embodiment or example of this application. In this specification, the illustrative expressions of the above terms do not necessarily refer to the same embodiment or example. Furthermore, the specific features, structures, materials, or characteristics described may be combined in any suitable manner in one or more embodiments or examples. Moreover, without contradiction, those skilled in the art can combine and integrate the different embodiments or examples described in this specification, as well as the features of different embodiments or examples.
[0095] Furthermore, the terms "first" and "second" are used for descriptive purposes only and should not be construed as indicating or implying relative importance or implicitly specifying the number of technical features indicated. Thus, a feature defined as "first" or "second" may explicitly or implicitly include at least one of that feature. In the description of this application, "N" means at least two, such as two, three, etc., unless otherwise explicitly specified.
[0096] Any process or method described in the flowchart or otherwise herein can be understood as representing a module, segment, or portion of code comprising one or more N executable instructions for implementing custom logic functions or processes, and the scope of the preferred embodiments of this application includes additional implementations in which functions may be performed not in the order shown or discussed, including substantially simultaneously or in reverse order depending on the functions involved, as should be understood by those skilled in the art to which embodiments of this application pertain.
[0097] It should be understood that the various parts of this application can be implemented using hardware, software, firmware, or a combination thereof. In the above embodiments, the N steps or methods can be implemented using software or firmware stored in memory and executed by a suitable instruction execution system. For example, if implemented in hardware, as in another embodiment, it can be implemented using any one or a combination of the following techniques known in the art: discrete logic circuits having logic gates for implementing logical functions on data signals, application-specific integrated circuits (ASICs) having suitable combinational logic gates, programmable gate arrays (FPGAs), field-programmable gate arrays (FPGAs), etc.
[0098] Those skilled in the art will understand that all or part of the steps of the methods in the above embodiments can be implemented by a program instructing related hardware. The program can be stored in a computer-readable storage medium, and when executed, the program includes one or a combination of the steps of the method embodiments.
[0099] Although embodiments of this application have been shown and described above, it is understood that the above embodiments are exemplary and should not be construed as limiting this application. Those skilled in the art can make changes, modifications, substitutions and variations to the above embodiments within the scope of this application.
Claims
1. A redundant control system for an autonomous vehicle, characterized in that, include: The motor controller is used to control the target torque output of the motor; A first domain controller, which integrates a first vehicle control unit (VCU), wherein the first VCU is used to identify the torque demand signal sent by the first domain controller to obtain the demand torque, and send a first control command generated based on the demand torque to the motor controller. The second domain controller integrates a second VCU. When the first VCU is in a preset failure state, the second VCU identifies the torque demand signal sent by the first domain controller to obtain the demand torque, and sends a second control command generated based on the demand torque to the motor controller to control the vehicle to perform a preset safe stopping action, thereby realizing redundant control of the autonomous vehicle. The third domain controller is used to communicate with the first domain controller. If the communication link between the third domain controller and the first domain controller is in a preset normal communication state and the first VCU is in a preset normal state, it forwards the first control command or other control commands generated by the first VCU to the motor controller. The second domain controller is also used to forward the first control command to the motor controller when the communication link between the third domain controller and the first domain controller is in a preset abnormal communication state and the first VCU is in a preset normal state.
2. The system according to claim 1, characterized in that, The second VCU is also used to send a failure flag of the first VCU to the motor controller when the first VCU is in a preset failure state; The motor controller responds to the second control command based on the failure flag.
3. The system according to claim 2, characterized in that, The motor controller is further configured to, upon receiving the failure flag, if a control command sent by the first VCU is received within the current ignition area, ignore the first control command and continue executing the second control command.
4. The system according to claim 1, characterized in that, The first domain controller and the second domain controller perform a handshake verification. After the verification is successful, the torque demand signal is synchronously sent to the second VCU of the second domain controller.
5. The system according to claim 4, characterized in that, The first domain controller is also used to determine that the communication between the second VCU of the second domain controller and the second domain controller is lost when the handshake verification with the second domain controller fails. Then, it generates a third control command and sends the third control command to the motor controller to control the vehicle to perform a preset safe stopping action.
6. The system according to any one of claims 1-5, characterized in that, The identifiers for the messages sent by the first VCU and the second VCU are the same.
7. A vehicle, characterized in that, Includes a redundant control system for autonomous vehicles as described in any one of claims 1-6.
8. A redundancy control method for an autonomous vehicle, characterized in that, The method, applied to the redundant control system of an autonomous vehicle as described in any one of claims 1-6, includes the following steps: Detect whether the first VCU is in a preset failure state; If the first VCU is in a preset failure state, the torque demand signal sent by the first domain controller is identified to obtain the required torque. The second control command is generated based on the required torque and sent to the motor controller to control the vehicle to perform a preset safe parking action, thereby achieving redundant control of the autonomous vehicle.
Citation Information
Patent Citations
Distributed power backup control system meeting automatic driving and vehicle
CN114940183A
VCU redundancy control system based on function safety and application thereof
CN115179964A