A Redundancy Implementation Method, System and Vehicle for an Autopilot System

Through the collaborative work of perception modules, fusion modules, etc., the status of the autonomous driving system is monitored and evaluated in real time, and the problems of complex redundant design and waste of resources are solved, and safety risks are reduced and efficiency is improved, ensuring that the autonomous driving vehicles operate stably within the boundary of design capabilities.

CN115830897BActive Publication Date: 2025-07-18上海友道智途科技有限公司
View PDF 2 Cites 0 Cited by

Patent Information

Application Number
CN202211516443.7
Authority / Receiving Office
CN · China
Patent Type
Patents(China)
Current Assignee / Owner
Filing Date
2022-11-30
Publication Date
2025-07-18
Estimated Expiration
2042-11-30

AI Technical Summary

Technical Problem

The redundant design in existing autonomous driving systems is complex and resource-consuming, so they cannot effectively utilize on-board resources. They may have abnormal behaviors under disturbances from the external environment, resulting in safety risks. At the same time, autonomous driving vehicles are inefficient when ensuring safety.

Method used

The coordinated work of perception modules, fusion modules, prediction modules, planning modules, fault monitoring modules, safety rule verification modules and control instruction generation modules is adopted to monitor and evaluate the system status in real time through data transmission and collaborative optimization, trigger security risk reduction behaviors, and ensure that the system operates within the design capability boundary.

Benefits of technology

The redundancy implementation is optimized, the safety risks of the autonomous driving system are reduced, the overall system efficiency is improved, and abnormal behaviors can be effectively dealt with, and the balance of safety and efficiency is ensured.

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure CN115830897B_ABST
    Figure CN115830897B_ABST
Patent Text Reader

Abstract

The present invention discloses a redundant implementation method, system and vehicle for an autonomous driving system, which is implemented through a perception module, a fusion module, a prediction module, a planning module, a fault monitoring module, a safety rule verification module and a control instruction generation module. The data between the modules are transmitted to each other and cooperate with each other, so that the behavior of the entire autonomous driving system can be continuously iteratively optimized, ensuring in real time that the autonomous driving system always operates within its designed capabilities at the boundaries, reducing the associated safety risks of the operation of the autonomous driving system, while optimizing the implementation of redundancy, avoiding excessive redundant components, and improving the efficiency of the overall system.
Need to check novelty before this filing date? Find Prior Art

Description

Technical Field

[0001] The present invention belongs to the technical field of intelligent connected vehicles, and particularly relates to a method, a system and a vehicle for realizing redundancy of an autonomous driving system. Background Art

[0002] A vehicle operating in an autonomous driving mode can free the occupants, especially the driver, from some driving-related tasks. When operating in the autonomous driving mode, the vehicle can drive to the destination without any human driver on the vehicle based on the information obtained from environmental perception.

[0003] With the development of autonomous driving technology, autonomous vehicles have been tested on the road. However, before the safe deployment of autonomous vehicles, there are still some key challenges to be solved, including the following points:

[0004] 1. The road traffic conditions are ever-changing. By what means can it be ensured that autonomous vehicles can always operate within the defined original design domain, so as to avoid the risks brought by the system entering an operating environment that is not designed as expected.

[0005] 2. Considering the cost of large-scale deployment, the software and hardware of autonomous vehicles cannot be perfect and there may be failures. By what means can the safety risks brought by the software and hardware failures of autonomous vehicles be reduced and lowered.

[0006] 3. The perception system of autonomous vehicles may have the possibility of missed detection and false detection, which may cause abnormal behaviors of autonomous vehicles. There have been many reports in recent years. By what means can the safety risks brought by the missed detection and false detection of the perception system be avoided or reduced.

[0007] 4. When the behaviors of autonomous vehicles may bring safety risks, by what means can the vehicle be operated to avoid or reduce the safety risks.

[0008] These challenges are interdependent and require holistic attention to ensure the overall safety of autonomous vehicles. To address the above issues, the current mainstream approach to enhancing the capabilities of autonomous driving systems is to use redundancy, that is, adding additional backup systems outside the main system. However, if the capabilities between the main system and the backup system of the redundancy (for autonomous driving) are not effectively matched during implementation, the redundant solution may be both expensive and complex. For example, to achieve autonomous driving of a vehicle through dual-channel redundancy, when a single node of one of the control paths fails, the other node can continue to operate. This working mode of dual-channel redundancy can effectively ensure the safety and stability of vehicle driving during autonomous driving. However, in an autonomous driving system, if the resources of each node are designed according to the maximum demand, during the actual operation of the system, not all resources are needed, which is likely to cause waste of resources and cannot effectively utilize in-vehicle resources. Moreover, this dual-channel redundancy makes the whole system more complex and more prone to reliability problems.

[0009] In addition, the above simple dual-channel or even multi-channel redundancy methods cannot solve the problem that autonomous vehicles may exhibit abnormal behaviors when affected by external environmental disturbances. For example, unsuitable lighting conditions, graffiti-covered traffic signs, or even the white-painted truck trailer compartments may cause abnormal behaviors of autonomous vehicles. SAE (Society of Automotive Engineers) defines a level 4 autonomous vehicle as "designed to perform all safety-critical driving functions and monitor road conditions throughout the journey". This means that a level 4 autonomous vehicle should be able to monitor itself and reduce all possible safety risks.

[0010] Another problem is how to ensure the traffic efficiency while ensuring the safety of autonomous vehicles. For example, after adopting multiple safety measures, the behavior of autonomous vehicles tends to be conservative. Summary of the Invention

[0011] To address the above issues, the main objective of the present invention is to design a method, system, and vehicle for implementing redundancy in an autonomous driving system, and to solve the technical problems existing in the redundancy of autonomous driving systems in the prior art.

[0012] To achieve the above objective, the present invention adopts the following technical solutions:

[0013] A redundancy system for an autonomous driving system, the system includes a perception module, a fusion module, a prediction module, a planning module, a fault monitoring module, a safety rule verification module, and a control instruction generation module;

[0014] The data of the perception module is input into the fusion module, the data of the fusion module is input into the prediction module and the safety verification module, and the data of the prediction module is input into the planning module;

[0015] The planning module and the safety rule verification module cooperate with each other, and the data of the planning module is output to the control instruction generation module and read back to the safety rule verification module;

[0016] The safety rule verification module and the fault monitoring module cooperate with each other, and both the safety rule verification module and the fault monitoring module output triggering safety risk reduction behavior to the control instruction generation module;

[0017] The fault monitoring module monitors the operating status of the perception module, fusion module, prediction module, planning module, and safety rule verification module.

[0018] As a further description of the present invention, the fusion module includes a fusion module 1 and a fusion module 2, the data of the fusion module 1 is output to the prediction module and the security rule verification module, and the data of the fusion module 2 is output to the security rule verification module.

[0019] As a further description of the present invention, the fusion module 1 includes a first training data set and algorithm training, which are used to correctly identify objects within the normal operation scenario of the autonomous driving vehicle; the fusion module 2 includes a second training data set and algorithm training, which are used to correctly identify possible interfering conditions within the normal operation scenario of the autonomous driving vehicle; and the fusion module 1 and the fusion module 2 work together.

[0020] As a further description of the present invention, there are two ways in which the fault monitoring module monitors real-time operating faults of other operating modules. One is that the operating module reports its own fault to the fault monitoring module through a designated fault code interface, and the other is that the fault monitoring module confirms whether the operating module is operating well through periodic communication questions and answers.

[0021] As a further description of the present invention, the safety rule verification module includes a pre-trained safety behavior library, and the safety behavior library is a rule library organized according to a hierarchical structure. Different behavior rules include different priority levels and quantification methods.

[0022] As a further description of the present invention, the behavior rules include several items, and the quantification method sets different quantification indicators for different behavior rules.

[0023] Specifically, the behavior rules are usually set as: keep a distance from other objects, do not exceed lane lines, and reduce parking and waiting during operation;

[0024] The quantitative indicator for keeping distance from other objects should specify the minimum safe distance allowed and refer to the speed of travel;

[0025] Different quantization metrics for exceeding the lane line should specify the allowable safety distance for overtaking and merging, and refer to the relative speed and relative lateral distance between the surrounding vehicles and the host vehicle.

[0026] During the operation process, the quantization metrics for reducing the allowable waiting time for parking should specify the target vehicle speed, and refer to the travel proportion of the host vehicle driving at the target vehicle speed during the operation process.

[0027] As a further description of the present invention, the control instruction generation module monitors the operation of the planning module, the fault monitoring module, and the safety rule verification module in real time, and when one or more of these modules fails, the control instruction generation module triggers a safety risk reduction behavior.

[0028] As a further description of the present invention, the control instruction generation module includes control module 1 and control module 2, and control module 1 and control module 2 operate in parallel.

[0029] A method for realizing redundancy of an autonomous driving system, the specific implementation includes the following steps:

[0030] S1: Receive the data stream generated by the sensor hardware through the perception module, and generate perception data for other modules inside the autonomous driving system to use;

[0031] S2: Receive the perception data of the perception module through fusion module 1, and generate fusion data for other modules inside the autonomous driving system to use; receive the perception data of the perception module through fusion module 2, and generate fusion data for other modules inside the autonomous driving system to use;

[0032] S3: Receive the fusion data of fusion module 1 through the prediction module, and predict the spatio-temporal relationship of the entire traffic environment where the vehicle is located, and generate corresponding prediction data for other modules inside the autonomous driving system to use;

[0033] S4: Receive the prediction data of the prediction module through the planning module, and generate the behavior data of the autonomous driving vehicle for the control instruction generation module to use;

[0034] S5: Monitor the operation status of the environment perception module and the planning module inside the autonomous driving system in real time through the fault monitoring module, and trigger different safety risk reduction behaviors according to the severity level of the fault when the fault occurs;

[0035] S6: Receive the fusion data of fusion module 1 and fusion module 2 through the safety rule verification module, as well as the behavior data of the autonomous driving vehicle generated by reading back the planning module, evaluate the safety risk of the autonomous driving vehicle in real time according to the safety behavior rule library, and trigger different safety risk reduction behaviors according to the severity level of the safety risk;

[0036] S7: Receive the behavior data of the autonomous vehicle from the planning module through the control instruction generation module, and trigger the safety risk reduction behavior of the fault monitoring module and the safety rule verification module;

[0037] Or when the control module instruction generation module monitors that the operation status of the planning module, the fault monitoring module, and the safety rule verification module fails, trigger the safety risk reduction behavior;

[0038] S8: Receive or monitor the generated trigger for the safety risk reduction behavior through the control instruction generation module, and generate control instructions to output to the vehicle power, braking, and steering systems.

[0039] An autonomous driving test vehicle includes an environmental perception system and an action system. The action system is responsible for interacting with the braking, power, and steering systems of the vehicle; the environmental perception system includes a perception module, a planning module, a safety rule verification module, and a fault monitoring module, which are distributed on high-performance hardware; the action system includes a control instruction generation module, which is distributed on high-reliability hardware.

[0040] Compared with the prior art, the technical effect of the present invention is:

[0041] The present invention provides a redundant implementation method and system for an autonomous driving system, which is implemented through a perception module, a fusion module, a prediction module, a planning module, a fault monitoring module, a safety rule verification module, and a control instruction generation module. The data between the modules are transmitted to each other and cooperate with each other, which can continuously iterate and optimize the behavior of the entire autonomous driving system, and ensure in real time that the autonomous driving system always operates within its design capabilities at the boundary, reducing the associated safety risks of the operation of the autonomous driving system. At the same time, the implementation of redundancy is optimized, avoiding excessive redundant components, improving the efficiency of the overall system. In addition, it can also effectively respond when abnormal behaviors occur in autonomous vehicles and cause safety risks. Description of the Drawings

[0042] Figure 1 It is a schematic diagram of the redundant implementation of each module of the system of the present invention;

[0043] Figure 2 It is a schematic diagram of the functional structure of the autonomous vehicle of the present invention;

[0044] Figure 3 It is a schematic diagram of potential safety risks and related countermeasures in the operation process of the autonomous vehicle of the present invention;

[0045] Figure 4 It is a schematic diagram of an example of the autonomous driving behavior safety rule library of the present invention;

[0046] Figure 5 It is a schematic diagram of the quantification of the behavior rules of the safety rule library of the present invention;

[0047] Figure 6 Schematic diagram of the application of the safety rule library and the behavior rule scenario of the present invention;

[0048] Figure 7 Scenario where the vehicle of the present invention violates the behavior rules (a vehicle occupying the lane appears in the lane);

[0049] Figure 8 Scenario after quantifying the vehicle rules of the present invention (a vehicle occupying the lane appears in the lane);

[0050] Figure 9 Schematic diagram corresponding to the fault monitoring module of the present invention. Detailed implementation manners

[0051] The present invention will be described in detail below with reference to the accompanying drawings:

[0052] A redundant system for an autonomous driving system, referring to Figure 1-2 as shown, the system includes a perception module, a fusion module, a prediction module, a planning module, a fault monitoring module, a safety rule verification module, and a control instruction generation module;

[0053] The data of the perception module is input into the fusion module, the data of the fusion module is input into the prediction module and the safety verification module, and the data of the prediction module is input into the planning module; the planning module and the safety rule verification module cooperate with each other, and the data of the planning module is output to the control instruction generation module and read back to the safety rule verification module; the safety rule verification module and the fault monitoring module cooperate with each other, and both the safety rule verification module and the fault monitoring module output triggering safety risk reduction behaviors to the control instruction generation module; the fault monitoring module monitors the operating states of the perception module, the fusion module, the prediction module, the planning module, and the safety rule verification module; the control instruction generation module monitors the operations of the planning module, the fault monitoring module, and the safety rule verification module in real time, and when one or more of the modules fail, the control instruction generation module triggers a safety risk reduction behavior.

[0054] It should be noted that the cooperation of multiple modules of the present invention is beneficial to optimizing the overall behavior of the autonomous driving vehicle, reducing safety risks, and improving the operation efficiency.

[0055] Specifically, in this embodiment, specific analysis is carried out for different modules and is disclosed as follows:

[0056] 1. The planning module is responsible for generating the behavior data of the autonomous vehicle. Generally, it needs to consider multiple aspects, such as how to ensure the safety of the vehicle's behavior, how to optimize the passing efficiency of the ego-vehicle, how to ensure the smoothness of control, how to interact with other traffic participants (pedestrians, vehicles), and how to contribute to the overall traffic efficiency (for example, not blocking the normal driving of other traffic participants); while the safety rule verification module focuses on making the behavior of the autonomous vehicle comply with the established rules.

[0057] The planning module and the safety rule verification module cooperate and learn from each other in the operation of the autonomous vehicle, which is beneficial to optimizing the overall safety behavior of the autonomous vehicle.

[0058] 2. The fusion module includes fusion module 1 and fusion module 2. The data of fusion module 1 is output to the prediction module and the safety rule verification module, and the data of fusion module 2 is output to the safety rule verification module; the fusion module 1 includes the first training data set and algorithm training, which are used to correctly identify the objects in the normal operation scenario of the autonomous vehicle, including: (1) traffic participants, such as motor vehicles, non-motor vehicles, people, (2) road elements, such as lane lines, traffic signs, traffic lights, railings, curbs; the fusion module 2 includes the second training data set and algorithm training, which are used to correctly identify the possible interfering conditions in the normal operation scenario of the autonomous vehicle, such as strong light, weak light, graffiti, shadow, unpaved road.

[0059] It should be noted that fusion module 1 focuses on the normal functions of autonomous driving, and fusion module 2 focuses on safety. Fusion module 1 and fusion module 2 cooperate with each other. Because fusion module 1 and fusion module 2 adopt different algorithms and data training data sets, they can cooperate and learn during the operation and learning process to produce a safer and more stable perception fusion effect.

[0060] 3. There are two ways for the fault monitoring module to monitor the real-time operation faults of other running modules. One way is that the running module reports its own faults to the fault monitoring module through the specified fault code interface, and the other way is that the fault monitoring module confirms whether the running module is operating well through periodic communication questions and answers; the fault monitoring module collects the status information of each software module based on the above two ways. When a fault occurs, different safety risk reduction behaviors are triggered according to the severity level of the fault.

[0061] Regarding the severity level of the fault of the fault monitoring module and the different safety risk reduction behaviors triggered, as Figure 9 shown, it is specifically disclosed as follows:

[0062] The fault monitoring module includes the fault monitoring responsibilities, contents and corresponding risk reduction measures for each module;

[0063] It should be noted that the items in the chart are only reference items for actual faults, not all items. The actual faults may be larger than the scale in the chart. In addition, except for the fault monitoring module, all other modules need to report faults to the fault monitoring module.

[0064] 4. The safety rule verification module includes a pre-trained safety behavior library, which evaluates the safety risks of autonomous vehicles in real time based on the safety behavior library, and triggers different safety risk reduction behaviors according to the severity level of the safety risks; the safety behavior library is a rule library organized in a hierarchical structure, and different behavior rules include different priority levels and quantification methods. By adjusting the priority levels and quantification methods of the safety rules, the normal driving of autonomous vehicles can be ensured.

[0065] Regarding the setting of behavior rules and the relative priority levels and quantification methods, refer to Figures 4-8 as shown below, and the specific disclosure is as follows:

[0066] The behavior rules include several items, and the quantification method sets different quantification indicators for different behavior rules; specifically, in this embodiment, the behavior rules are set to three types, namely: Rule 1, keep a distance from other objects, Rule 2, do not exceed the lane line, and Rule 3, reduce the stop operation waiting during the operation process.

[0067] (1) Quantification indicators for Rule 1

[0068] The quantification indicator for keeping a distance from other objects should specify the allowable minimum safety distance and refer to the driving speed.

[0069] For example, when the vehicle speed is 40 km / h, a passing gap of 20 cm is allowed, and this gap should be enlarged when the vehicle speed is 60 km / h.

[0070] (2) Quantification indicators for Rule 2

[0071] The quantification indicator for not exceeding the lane line should specify the allowable safety distance for crossing the lane and refer to the relative speed and relative lateral distance between the surrounding vehicles and the own vehicle.

[0072] For example, considering the environment, a lane-crossing detour of 5 - 10 cm is allowed.

[0073] In addition, the safety rule verification module and the fault diagnosis module can cooperate and learn from each other to more effectively identify the boundary conditions of autonomous driving operations.

[0074] (3) Quantification indicators for Rule 3

[0075] The quantification indicator for reducing the stop operation waiting during the operation process should specify the target vehicle speed and refer to the travel proportion of the own vehicle driving at the target vehicle speed during the operation process.

[0076] For example, the target vehicle speed is 60 kph, and 20% of the whole journey is allowed to drive at 50% lower than the target vehicle speed.

[0077] The control instruction generation module includes control module 1 and control module 2, and control module 1 and control module 2 run in parallel to ensure the reliability of operation. No matter whether control module 1 or control module 2 fails, it can trigger the safety risk reduction action of the control instruction generation module.

[0078] In addition, in this embodiment, referring to Figure 4 There are three behavior rules. Combining Figure 6 In the traffic scenario shown, following the above three behavior rules simultaneously can ensure the good and safe operation of the host vehicle. However, in Figure 7 In the traffic scenario shown, due to the occupation of the road by other vehicles, the host vehicle cannot pass. At this time, in order for the host vehicle to comply with the above rules 1 and 2, it violates rule 3. If the host vehicle forcibly passes, it will violate one of the above rules 1 or 2. In this traffic scenario, it is impossible to ensure that all three behavior rules are complied with.

[0079] By Figure 5 and Figure 8 The quantization methods shown are used to adjust the behavior rules of the host vehicle, which can reduce the safety risk during the operation of the autonomous driving vehicle and ensure the efficiency during the operation. After quantifying the behavior rules, the host vehicle is allowed to make a certain degree of detour to bypass the vehicle occupying the road ahead, so as to meet the requirements of the above rules 1, 2, and 3 simultaneously.

[0080] Another embodiment of the present invention is a method for realizing redundancy of an autonomous driving system, and the specific implementation includes the following steps:

[0081] S1: Receive the data stream generated by the sensor hardware through the sensing module, and generate sensing data for use by other modules inside the autonomous driving system;

[0082] S2: Receive the sensing data of the sensing module through fusion module 1, and generate fusion data for use by other modules inside the autonomous driving system; receive the sensing data of the sensing module through fusion module 2, and generate fusion data for use by other modules inside the autonomous driving system;

[0083] S3: Receive the fusion data of fusion module 1 through the prediction module, and predict the spatio-temporal relationship of the entire traffic environment where the vehicle is located, and generate corresponding prediction data for use by other modules inside the autonomous driving system;

[0084] S4: Receive the prediction data of the prediction module through the planning module, and generate the behavior data of the autonomous driving vehicle for use by the control instruction generation module;

[0085] S5: The failure monitoring module monitors the operating states of the environment perception module and the planning module in the autonomous driving system in real time, and triggers different safety risk reduction behaviors according to the severity level of the failures when they occur.

[0086] S6: The safety rule verification module receives the fusion data from Fusion Module 1 and Fusion Module 2, as well as the behavior data of the autonomous driving vehicle generated by the read-back planning module, evaluates the safety risks of the autonomous driving vehicle in real time according to the safety behavior rule library, and triggers different safety risk reduction behaviors according to the severity level of the safety risks.

[0087] S7: The control instruction generation module receives the behavior data of the autonomous driving vehicle from the planning module, as well as the triggered safety risk reduction behaviors from the failure monitoring module and the safety rule verification module.

[0088] Or when the control module instruction generation module monitors that the operating states of the planning module, the failure monitoring module, and the safety rule verification module fail, it triggers safety risk reduction behaviors.

[0089] S8: The control instruction generation module receives or monitors the generated triggered safety risk reduction behaviors, and generates control instructions to output to the vehicle power, braking, and steering systems.

[0090] Another embodiment of the present invention, an autonomous driving test vehicle, includes an environment perception system and an action system. The action system is responsible for interacting with the braking, power, and steering systems of the vehicle (issuing control instructions and receiving status feedback), and actually controls the operation of the entire vehicle. The redundant system of the autonomous driving system and the braking, power, and steering systems constitute a complete autonomous driving vehicle in this embodiment.

[0091] It should also be noted that the environment perception system includes a perception module, a planning module, a safety rule verification module, and a failure monitoring module, which are distributed on high-performance hardware; the action system includes a control instruction generation module, which is distributed on high-reliability hardware.

[0092] In the present invention, referring to Figure 3 As shown, for the disclosed embodiments, through the redundant system and implementation method of the present invention, the specific reasons for the possible safety risks during the operation process can be effectively eliminated or reduced.

[0093] Based on the specific analysis of the above three embodiments, the present invention can be summarized from the following three aspects:

[0094] In the first aspect, the present invention discloses a redundant system and method for an autonomous driving system, including an implementation method of the vehicle's autonomous driving functions (perception, planning, and action), a layout of various software modules related to the vehicle's autonomous driving functions on computer hardware, and modules that occupy more computing resources, such as environmental perception and behavior planning, are distributed on high-performance hardware, while control instruction generation is distributed on high-reliability hardware; a dedicated fault monitoring module is used to monitor the operating status of each software module and dynamically determine the overall failure risk of the autonomous driving system; a redundant fusion module is used to evaluate the safety risk of the current perception system; and a dedicated safety rule verification module is used to verify and evaluate whether the autonomous driving vehicle is operating within a specified design domain and whether the real-time behavior of the vehicle poses a safety risk.

[0095] On the second aspect, in the technical solution proposed by the present invention, an independent safety rule verification module is used, a safety behavior rule library is pre-trained inside the module, and a fusion module 1 and a fusion module 2 trained with different weight coefficients are used upstream of the safety rule verification module, and the autonomous driving behavior data output by the planning module is read back downstream; the safety rule verification module is based on the safety behavior rule library, combined with the upstream two heterogeneous fusion modules of the algorithm, and the read-back autonomous driving behavior data, to calculate and evaluate the safety behavior and boundaries of the current autonomous driving vehicle in real time, and through continuous test iterations, it can ensure that the behavior of the autonomous driving system is refined, ensuring safety while ensuring efficiency. For example, in the test iteration, the safety behavior rule library can be continuously quantified to form new behaviors of autonomous driving vehicles in certain scenarios, ensuring safety while ensuring that the vehicle's traffic efficiency is not reduced.

[0096] In the third aspect, the technical solution proposed by the present invention realizes the risk reduction behavior of the autonomous driving vehicle during operation. In addition to the autonomous driving behavior data generated by the planning module, the fault monitoring module is used to trigger the control instruction generation module to generate safety risk reduction behavior in real time when the environmental perception and behavior planning software functions of the autonomous driving system fail; the safety rule verification module is used to evaluate the safety behavior and boundaries of the current autonomous driving vehicle in real time, and when there is a safety risk, the control instruction generation module is triggered in real time to generate safety risk reduction behavior; the control instruction generation module is used to monitor the upstream fault monitoring module, safety rule verification module and planning module, and when the upstream data is abnormal, the safety risk reduction behavior is generated in real time; the control instruction generation module has two control modules inside, and when one of them is abnormal, the safety risk reduction behavior is triggered in real time.

[0097] The above embodiments are only used to illustrate the technical solution of the present invention rather than to limit it. Other modifications or equivalent substitutions made to the technical solution of the present invention by ordinary technicians in this field should be included in the scope of the claims of the present invention as long as they do not depart from the spirit and scope of the technical solution of the present invention.

Claims

1. A redundant system for an autonomous driving system, characterized in that: The system includes a perception module, a fusion module, a prediction module, a planning module, a fault monitoring module, a safety rule verification module, and a control instruction generation module; The data of the perception module is input into the fusion module, the data of the fusion module is input into the prediction module and the safety rule verification module, and the data of the prediction module is input into the planning module; The planning module and the safety rule verification module cooperate with each other, and the data of the planning module is output to the control instruction generation module and read back to the safety rule verification module; The safety rule verification module and the fault monitoring module cooperate with each other, and both the safety rule verification module and the fault monitoring module output triggering safety risk reduction behaviors to the control instruction generation module; The fault monitoring module monitors the operating states of the perception module, the fusion module, the prediction module, the planning module, and the safety rule verification module; Among them, the fusion module includes a fusion module 1 and a fusion module 2. The data of the fusion module 1 is output to the prediction module and the safety rule verification module, and the data of the fusion module 2 is output to the safety rule verification module; the fusion module 1 includes a first training data set and algorithm training for correctly identifying objects in the normal operation scenario of an autonomous driving vehicle; the fusion module 2 includes a second training data set and algorithm training for correctly identifying possible interfering conditions in the normal operation scenario of an autonomous driving vehicle; and the fusion module 1 and the fusion module 2 cooperate with each other.

2. The redundancy system of an autonomous driving system according to claim 1, characterized in that: There are two ways for the fault monitoring module to monitor the real-time operation faults of other operating modules. One way is that the operating module reports its own faults to the fault monitoring module through a specified fault code interface, and the other way is that the fault monitoring module confirms whether the operating module is operating properly through periodic communication questions and answers.

3. The redundancy system of an autonomous driving system according to claim 1, characterized in that: The safety rule verification module includes a pre-trained safety behavior library, and the safety behavior library is a rule library organized in a hierarchical structure, and different behavior rules include different priority levels and quantification methods.

4. The redundancy system of an autonomous driving system according to claim 3, characterized in that: There are several behavior rules, and different quantification indexes are set for different behavior rules.

5. The redundancy system of an autonomous driving system according to claim 3, characterized in that: The behavior rules are set as follows: keep a distance from other objects, do not exceed the lane line, and reduce stop and wait during operation; The quantification index for keeping a distance from other objects should specify the allowed minimum safety distance and refer to the driving speed; The quantification index for not exceeding the lane line should specify the allowed safety distance for crossing the lane and refer to the relative speed and relative lateral distance between the surrounding vehicle and the own vehicle; The quantification index for reducing stop and wait during operation should specify the target speed and refer to the travel proportion of the own vehicle driving at the target speed during operation.

6. The redundancy system of an autonomous driving system according to claim 1, characterized in that: The control instruction generation module monitors the operation of the planning module, the fault monitoring module, and the safety rule verification module in real time, and when one or more of these modules fail, the control instruction generation module triggers a safety risk reduction behavior.

7. A method for implementing redundancy of an autonomous driving system based on the system according to any one of claims 1-6, characterized in that: The specific implementation includes the following steps: S1: Receive the data stream generated by the sensor hardware through the perception module and generate perception data for use by other modules inside the autonomous driving system; S2: Receive the perception data from the perception module through Fusion Module 1 and generate fusion data for other modules within the autonomous driving system to use; receive the perception data from the perception module through Fusion Module 2 and generate fusion data for other modules within the autonomous driving system to use; S3: Receive the fusion data from Fusion Module 1 through the prediction module, predict the spatio-temporal relationship of the entire traffic environment where the vehicle is located, and generate corresponding prediction data for other modules within the autonomous driving system to use; S4: Receive the prediction data from the prediction module through the planning module and generate the behavior data of the autonomous driving vehicle for the control instruction generation module to use; S5: Monitor the operating status of the environment perception module and the planning module within the autonomous driving system in real time through the fault monitoring module, and trigger different safety risk reduction behaviors according to the severity level of the fault when a fault occurs; S6: Receive the fusion data from Fusion Module 1 and Fusion Module 2, as well as the behavior data of the autonomous driving vehicle generated by reading back the planning module, through the safety rule verification module, evaluate the safety risk of the autonomous driving vehicle in real time according to the safety behavior rule library, and trigger different safety risk reduction behaviors according to the severity level of the safety risk; S7: Receive the behavior data of the autonomous driving vehicle from the planning module, as well as the triggered safety risk reduction behaviors of the fault monitoring module and the safety rule verification module, through the control instruction generation module; Or trigger a safety risk reduction behavior when a fault occurs by monitoring the operating status of the planning module, the fault monitoring module, and the safety rule verification module through the control module instruction generation module; S8: Receive or monitor the triggered safety risk reduction behavior generated through the control instruction generation module and generate control instructions to output to the vehicle power, braking, and steering systems.

8. An autonomous driving test vehicle based on the system according to any one of claims 1-6, characterized in that: It includes an environment perception system and an action system. The action system is responsible for interacting with the braking, power, and steering systems of the vehicle and executing the method described in claim 7; The described environment perception system includes a perception module, a planning module, a safety rule verification module, and a fault monitoring module, which are distributed on high-performance hardware; The described action system includes a control instruction generation module, which is distributed on high-reliability hardware.

Citation Information

Patent Citations

  • Low-speed unmanned vehicle safety redundancy architecture and method based on binocular vision

    CN113682323A

  • Unmanned vehicle sensing system safety redundancy system and control method

    CN113895450A