Auxiliary driving safety control method and device and intelligent automobile
By detecting driver information and abnormal controller conditions, the system actively disengages the assisted driving control, solving the problem of insufficient robustness in advanced driver assistance systems, improving the driving experience and overall vehicle safety, and is suitable for L2 level autonomous driving systems.
Patent Information
- Authority / Receiving Office
- CN · China
- Patent Type
- Patents(China)
- Current Assignee / Owner
- CHONGQING CHANGAN TECH CO LTD
- Filing Date
- 2023-04-26
- Publication Date
- 2026-04-21
AI Technical Summary
Existing advanced driver assistance systems (ADAS) cannot effectively cope with abnormal conditions with insufficient robustness in Level 2 autonomous driving, resulting in an imbalance between driving experience and overall vehicle safety.
By detecting the driver's active driving information and abnormal operating conditions of the driver assistance controller, it can determine whether the controller has failed. If it fails, it will actively disengage the driver assistance control and transfer control to the driver. At the same time, a safety mechanism will be added inside the controller to prevent the issuance of abnormal commands.
It improves the robustness and driving experience of the advanced driver assistance system, avoids hazards such as vehicles running off the track, rear-ending, and breaking down, and promptly alerts the driver when the controller malfunctions, thus enhancing overall vehicle safety.
Smart Images

Figure CN116279542B_ABST
Abstract
Description
Technical Field
[0001] This invention relates to the field of functional safety technology for autonomous driving of vehicles, specifically to an assisted driving safety control method, an assisted driving safety control device, an intelligent vehicle, an electronic device, and a computer-readable storage medium. Background Technology
[0002] With the development of connected, digital, and intelligent vehicles, automotive architecture has undergone tremendous changes, and the vehicle's electronic and electrical systems have become increasingly complex. Simple human-machine interaction can no longer meet people's driving needs. To enhance the driving experience and improve the technological feel and safety of vehicles, autonomous driving technology has emerged, enabling cars to drive themselves without human intervention. Autonomous driving technology is mainly divided into four stages: automatic safety assistance, advanced driver assistance systems (ADAS), partially driverless, and fully driverless. Currently, most intelligent connected vehicles on the market are at the advanced driver assistance stage, with autonomous driving levels of L0, L1, or L2. According to the ISO 26262 standard, for these vehicles equipped with advanced driver assistance systems, the overall vehicle safety status is mostly "SAFE-SILENT" because the driver is in the loop, meaning failures are reported. If the functional safety development strategy for intelligent connected vehicles is designed according to this approach, there is a drawback: a trade-off between functional safety and driving experience.
[0003] For example, Chinese patent document CN110254512A, published on September 20, 2019, proposes a functional safety architecture design method for a distributed intelligent electric vehicle steering system. This method designs a functional safety architecture for steering systems of Level 3 and above autonomous vehicles, including offline functional safety concept analysis at the vehicle level and functional safety architecture design at the vehicle level. Compared with existing steering system safety control technologies, this design method considers vehicle-level functional safety technologies for steering systems of Level 3 and above autonomous vehicles. By designing a safety controller, including fault detection and corresponding safety control strategies, it ensures that the vehicle transitions to a safe state after a steering system failure. However, this method only designs functional safety design strategies for Level 3 autonomous driving steering systems and cannot be directly applied to Level 2+ advanced driver assistance systems. Furthermore, the design premise is relatively ideal and difficult to directly apply to engineering development.
[0004] A Chinese patent document published on March 27, 2020, with publication number CN110930005A, proposes a method for assessing the expected functional safety hazards of autonomous driving based on zero-day vulnerabilities. The method comprises four steps: Step 1: Determining a zero-day vulnerability hazard graph model for the expected functional safety system; Step 2: Simplifying the zero-day vulnerability model to construct hazard paths that threaten expected functional safety; Step 3: Calculating the hazard values SK and SUK for known and unknown triggering events based on the hazard paths; Step 4: Calculating the expected functional safety system security value svs based on a dynamic weighting scheme. This patent essentially provides a method for capturing the key characteristics of vulnerabilities and generating numerical scores reflecting their severity, aiming to continuously improve and iterate the expected functional safety architecture of the system through a dynamic model to achieve the optimal expected functional safety threshold. While this represents a design philosophy pursuing "zero risk," it only analyzes the issue from the perspective of expected functional safety, lacking an extension to system security strategies in functional safety and related security fields. It lacks a holistic, systematic, and comprehensive approach.
[0005] Therefore, it is necessary to provide a safety control method for advanced driver assistance systems that takes into account both the user's driving experience and the overall vehicle safety to the greatest extent possible. Summary of the Invention
[0006] One objective of this invention is to provide an advanced driver assistance system (ADAS) safety control method and apparatus to address the problem that existing automotive ADAS systems cannot cope with three types of insufficient robustness. A second objective is to provide an intelligent vehicle. A third objective is to provide an electronic device and a computer-readable storage medium for implementing the ADAS safety control method.
[0007] To achieve the above objectives, the technical solution adopted by the present invention is as follows:
[0008] In a first aspect, the present invention provides an advanced driver assistance system (ADAS) safety control method, the method comprising: detecting active driving information caused by a user, the active driving information including brake pedal input and steering wheel input; detecting whether an abnormal operating condition occurs in the driver assistance controller, the abnormal operating condition including continuously issuing acceleration commands, continuously issuing braking commands, and continuously issuing steering commands; determining whether the driver assistance controller has failed based on the detection result of the abnormal operating condition and the active driving information; and determining whether the driver assistance control is actively disengaged by an actuator based on whether the driver assistance controller has failed, the actuator including a vehicle power controller, a vehicle stability system, and a power steering system.
[0009] Based on the aforementioned technical means, by detecting the driver's active driving information and abnormal operating conditions of the driver assistance controller, it is confirmed whether the driver assistance controller has malfunctioned. If a malfunction is confirmed, the driver assistance controller actively releases control of each actuator, transferring control of the vehicle to the driver. Compared to existing driver assistance control technologies, this invention not only provides a specific safety control mechanism from the actuator perspective to address situations where the driver assistance controller fails, ensuring overall vehicle safety, but also considers the user's driving experience, making the driver assistance control more closely aligned with actual user needs.
[0010] Furthermore, when it is determined that the driver assistance controller continuously issues acceleration or braking commands, and the brake pedal input exceeds the first input, a first release command can be sent to the vehicle stabilizer to cause the vehicle stabilizer to actively release the driver assistance control; the vehicle stabilizer then sends a second release command to the vehicle power controller to cause the vehicle power controller to actively release the driver assistance control.
[0011] Based on the above technical means, a safety mechanism is provided for two abnormal operating conditions: continuous acceleration or braking commands issued by the driver assistance controller. This mechanism can effectively prevent hazards such as vehicles running off the track, rear-end collisions, and breakdowns.
[0012] Furthermore, when it is determined that the driver assistance controller continuously issues steering commands and the steering wheel input exceeds the second input, a third release command can be sent to the power steering to cause the power steering to actively release the driver assistance control; the power steering can then send a fourth release command to the vehicle stability control to cause the vehicle stability control to actively release the driver assistance control.
[0013] Based on the above technical means, a safety mechanism is provided for an abnormal working condition in which the driver assistance controller continuously issues steering commands, which can effectively avoid hazards such as vehicle deviation from the track and collision.
[0014] Furthermore, the first input quantity can be: 40% to 60% of the brake pedal travel, and a braking duration of 300ms to 500ms.
[0015] Based on the above technical means, a specific method for determining the first input quantity is provided. Based on the specific determination range of the first input quantity, it can be determined which range of straight-line active driving information indicates a risk of easy failure of the assisted driving controller.
[0016] Furthermore, the second input quantity can be: a steering wheel correction torque of 4Nm to 6Nm, and a steering wheel correction duration of 100ms to 200ms.
[0017] Based on the above technical means, a specific method for determining the second input quantity is provided. Based on the specific determination range of the second input quantity, it can be determined which range of steering active driving information indicates a risk of easy failure of the driver assistance controller.
[0018] Furthermore, after the actuator actively disengages the driver assistance control, it can remain unresponsive to the driver assistance controller during the current ignition cycle.
[0019] Based on the above technical means, a better safety control method is provided, which can effectively prevent the actuator from being controlled again by the assisted driving controller in a failed state during the current ignition cycle, and can further enhance the robustness of the entire assisted driving system.
[0020] Furthermore, the safety control method may also include: when the microcontroller unit inside the driver assistance controller detects an SOC (System on Chip) abnormality or the control command sending value exceeds a specified amount, it may issue an alarm request.
[0021] Based on the above-mentioned technical means, this invention adds a safety mechanism inside the driver assistance controller in addition to the safety mechanism implemented for the actuator. By detecting whether there is an abnormality inside the driver assistance controller, alarm information is generated in a timely manner and the driver is reminded so that the driver can take active driving actions as soon as possible, thereby maximizing driving safety.
[0022] Furthermore, the safety control method may also include: when the microcontroller detects that the driving parameters exceed a specified threshold, it refuses to issue control commands to the actuator, wherein the driving parameters include acceleration, deceleration and steering angle.
[0023] Based on the above technical means, a safety defense mechanism is provided for the internal mechanism of the driver assistance controller. By detecting whether the acceleration, deceleration and steering angle suddenly exceed preset values, the controller is restricted from issuing control commands that are likely to cause abnormal operating conditions.
[0024] Secondly, the present invention provides an advanced driver assistance system (ADAS) safety control device, the device comprising a first detection module, a second detection module, a judgment module, and a release determination module; the first detection module is used to detect active driving information caused by the user, the active driving information including brake pedal input and steering wheel input; the second detection module is used to detect whether the driver assistance controller is experiencing abnormal operating conditions, the abnormal operating conditions including continuously issuing acceleration commands, continuously issuing braking commands, and continuously issuing steering commands; the judgment module is used to determine whether the driver assistance controller has failed based on the abnormal operating condition detection results of the driver assistance controller and the active driving information; the release determination module is used to generate release determination information when the driver assistance controller is determined to be failed, thereby determining that the actuator actively releases the driver assistance control.
[0025] Based on the aforementioned technical means, an advanced driver assistance safety control system is provided that takes into account both the driving experience and the overall vehicle safety to the greatest extent.
[0026] Thirdly, the present invention provides an electronic device including a processor and a memory, wherein the memory stores at least one computer program, the at least one computer program being loaded and executed by one or more of the processors to enable the computer to implement the advanced driver assistance safety control method as described above.
[0027] Fourthly, the present invention provides a computer-readable storage medium storing at least one piece of program code, which is loaded and executed by a processor to enable a computer to implement the advanced driver assistance safety control method as described above.
[0028] Fifthly, the present invention provides an intelligent vehicle, the intelligent vehicle including the safety control device described above.
[0029] The present invention has at least the following technical effects through the technical solution provided by the present invention:
[0030] (1) Based on the three abnormal working conditions caused by the abnormal phenomena such as program runaway and freezing of the controller ADAS of the advanced driver assistance system, the present invention forms three safety mechanisms for the actuator, which not only increases the safety of the advanced driver assistance system, but also significantly improves the actual driving experience.
[0031] (2) The present invention also forms a safety mechanism for the internal system of the driver assistance controller (ADAS). When an abnormal SOC or abnormal value is detected, the driver is actively reminded so that the driver can adjust the vehicle status in a timely manner.
[0032] (3) This invention is applicable to L2 level autonomous driving systems and can enhance the robustness of intelligent vehicles’ IACC (Integrated Adapted Cruise Control), ACC (Adaptive Cruise Control), ICC (Intelligent Cruise Control) and other functions.
[0033] Other features and advantages of the present invention will be described in detail in the following detailed description section. Attached Figure Description
[0034] The accompanying drawings are provided to further illustrate embodiments of the present invention and form part of the specification. They are used together with the following detailed description to explain the embodiments of the present invention, but do not constitute a limitation thereof. In the drawings:
[0035] Figure 1 A flowchart illustrating the advanced driver assistance safety control method provided in an embodiment of the present invention;
[0036] Figure 2 This is a schematic diagram of the control flow under normal operating conditions provided in an embodiment of the present invention;
[0037] Figure 3 This is a schematic diagram of the control flow of the first security mechanism provided in an embodiment of the present invention;
[0038] Figure 4 This is a schematic diagram of the control flow of the second security mechanism provided in an embodiment of the present invention;
[0039] Figure 5 This is a schematic diagram of the control flow of the third security mechanism provided in an embodiment of the present invention;
[0040] Figure 6 This is a schematic diagram of the control flow of the ADAS internal safety mechanism provided in an embodiment of the present invention;
[0041] Figure 7 This is a schematic diagram of the structure of the advanced driver assistance safety control device provided in an embodiment of the present invention;
[0042] Figure 8 This is a schematic diagram of the structure of an electronic device provided in an embodiment of the present invention.
[0043] Explanation of reference numerals in the attached figures
[0044] 101-First detection module; 102-Second detection module; 103-Judgment module; 104-Determination module; 201-Processor; 202-Memory. Detailed Implementation
[0045] The specific embodiments of the present invention will be described in detail below with reference to the accompanying drawings. It should be understood that the specific embodiments described herein are for illustration and explanation only and are not intended to limit the scope of the present invention.
[0046] It should be noted that, unless otherwise specified, the embodiments and features described in the present invention can be combined with each other.
[0047] In this invention, unless otherwise stated, directional terms such as "upper," "lower," "top," and "bottom" are generally used to describe the relative positional relationships of components in relation to the directions shown in the accompanying drawings or in relation to vertical, perpendicular, or gravitational directions. Terms such as "first" and "second" are used merely for ease of description and distinction and should not be construed as indicating or implying relative importance.
[0048] Currently, there is no specific safety control mechanism for controllers and actuators to address the three typical robustness deficiencies that occur in advanced driver assistance systems.
[0049] To address the aforementioned issues, this invention proposes an advanced driver assistance system (ADAS) safety control method. Targeting three robustness-deficient conditions observed in large-scale road tests, it proposes three safety mechanisms for the actuators and controllers of the Level 2 autonomous driving system. By actively disengaging the actuators' driver assistance control and restricting the controller from issuing control commands in a failed state, this method not only improves the robustness of ADAS but also enhances the driver's driving experience.
[0050] The present invention will now be described in detail with reference to the accompanying drawings and embodiments.
[0051] Example 1
[0052] The first embodiment of the present invention provides an advanced driver assistance system (ADAS) safety control method, referencing... Figure 1 The safety control method includes the following steps:
[0053] Step S101: Detect active driving information caused by the user, including brake pedal input and steering wheel input.
[0054] Step S102: Detect whether the driver assistance controller is in an abnormal condition. Abnormal conditions include continuously issuing acceleration commands, continuously issuing braking commands, and continuously issuing steering commands.
[0055] Step S103: Based on the detection results of abnormal operating conditions and the active driving information, determine whether the assisted driving controller has failed.
[0056] Step S104: Determine whether the driver assistance control should be actively disengaged by the actuator based on whether the driver assistance controller has failed. The actuator includes the vehicle power controller, vehicle stability system (e.g., Electronic Stability Program), and power steering.
[0057] For example, the process of determining whether the actuator actively disengages the driver assistance control based on whether the driver assistance controller fails includes, but is not limited to, the following sub-steps S1041 to S1043.
[0058] Sub-step S1041: When it is determined that the driver assistance controller continuously issues acceleration commands and the brake pedal input exceeds the first input amount, a first release command is sent to the vehicle stability controller to cause the vehicle stability controller to actively release the driver assistance control. At the same time, the vehicle stability controller sends a second release command to the vehicle power controller to cause the vehicle power controller to actively release the driver assistance control.
[0059] For example, the first input quantity can be set to: 40% to 60% of the brake pedal travel and 300ms to 500ms of braking duration.
[0060] Sub-step S1042: When it is determined that the driver assistance controller continuously issues braking commands and the brake pedal input exceeds the first input, a first release command is sent to the vehicle stability controller to cause the vehicle stability controller to actively release the driver assistance control. Simultaneously, the vehicle stability controller sends a second release command to the vehicle power controller to cause the vehicle power controller to actively release the driver assistance control.
[0061] Sub-step S1043: When it is determined that the driver assistance controller continuously issues steering commands and the steering wheel input exceeds the second input, a third release command is sent to the power steering unit to cause the power steering unit to actively release the driver assistance control. At the same time, the power steering unit sends a fourth release command to the vehicle stability control to cause the vehicle stability control to actively release the driver assistance control.
[0062] For example, the second input quantity can be set to: 4Nm to 6Nm of steering wheel correction torque, and 100ms to 200ms of steering wheel correction duration.
[0063] Of course, the present invention is not limited to this. It can also send a release command to all actuators directly after determining that the driver assistance controller has failed, so that all actuators can actively release the driver assistance control and transfer the driving power to the driver.
[0064] Furthermore, after the actuator actively disengages the driver assistance control, it can remain unresponsive to the driver assistance controller during the current ignition cycle.
[0065] The implementation environment of this application embodiment may include at least one terminal and one server, with the method executed on the terminal or the server respectively. The terminal and server can establish a communication connection to achieve interactive information transmission. The terminal and server perform safety control of the advanced driver assistance system by acquiring active driving information and abnormal operating condition information.
[0066] The terminal can be any electronic product that can interact with the user through one or more methods such as keyboard, touchpad, touch screen, voice interaction, etc., such as PC (Personal Computer), PPC (Pocket Personal Computer), tablet computer, etc.
[0067] A server can be a single server, a server cluster consisting of multiple servers, or a cloud server that provides basic cloud computing services such as cloud services, cloud databases, cloud computing, cloud functions, cloud storage, network services, cloud communication, middleware services, domain name services, security services, CDN (Content Delivery Network), and big data and artificial intelligence platforms.
[0068] Example 2
[0069] The second embodiment of the present invention provides another advanced driver assistance system (ADAS) safety control method. Based on the ADAS safety control method provided in the first embodiment, this embodiment further adds a safety control method for the internal components of the ADAS controller. The specific control method is as follows:
[0070] Step S201: When the microcontroller inside the driver assistance controller detects a SOC abnormality or the control command sending value exceeds the specified amount, it can issue an alarm request.
[0071] Step S202: When the microcontroller detects that the driving parameters exceed a specified threshold, it refuses to issue control commands to the actuators. The driving parameters include acceleration, deceleration, and steering angle. The control commands here include acceleration commands, braking commands, and steering commands.
[0072] Specifically, taking the IACC function of an Advanced Driver Assistance System (ADAS) as an example, this embodiment first combines the functional characteristics and usage scenarios of IACC (Integrated Adaptive Cruise Control) with HARA (Hazard Analysis and Risk Assessment) analysis to derive vehicle-level safety targets and large-scale road test feedback (see Table 1). Through large-scale road testing, data that violates the safety targets is obtained, ultimately yielding data on three typical robustness-deficient operating conditions. Safety mechanisms are then developed for the controller and actuators for these three typical robustness-deficient operating conditions.
[0073] Table 1 Vehicle Functional Safety Objectives and Road Test Feedback
[0074]
[0075]
[0076] Note: In Table 1, FTTI refers to Fault Tolerant Time Interval; TBD refers to To Be Determined. ASIL refers to Automotive Safety Integrity Levels, which have four levels: ASIL A, ASIL B, ASIL C, and ASIL D. ASIL A represents the lowest safety integrity level, and ASIL D represents the highest. QM refers to Quality Management, meaning that it is not necessary to meet the requirements of ISO 26262; simply taking quality management measures is sufficient for control.
[0077] The interaction of the IACC function involves the Advanced Driver Assistance System Controller (ADAS Controller), Vehicle Control Unit (VCU), Electronic Stability Program (ESP), and Electric Power Steering (EPS). To enhance the driving experience, it is assumed that ADAS is developed to the highest ASIL D standard, VCU to the highest ASIL C standard, ESP to the highest ASIL D standard, and EPS to the highest ASIL D standard.
[0078] Before analyzing abnormal operating conditions, it is necessary to first define the normal operating conditions. Please refer to [link to relevant documentation]. Figure 2 Normal operating conditions can be divided into two situations.
[0079] Under normal operating condition 1, when the IACC function is activated, the driver is in the loop. The ESP will detect the driver's braking action. When it detects that the driver has pressed the brake, the EPS will send a driver braking signal to the ADAS. After the ADAS determines that the driver braking logic is valid, it will send a Disable command to the ESP, VCU, and EPS, and simultaneously deactivate the IACC function. At this time, all actuators will prioritize responding to the driver's command and will no longer respond to the ADAS.
[0080] Under normal operating condition 2, when the IACC function is activated, the driver is in the loop, and the EPS will detect the driver's steering wheel movement. When the EPS detects the driver turning the steering wheel, it will send a steering wheel movement signal to the ADAS. After the ADAS determines that the driver's steering wheel movement logic is valid, it will send a disable command to the ESP, VCU, and EPS, and simultaneously deactivate the IACC function. At this time, all actuators will prioritize responding to the driver's commands and will no longer respond to the ADAS.
[0081] Under normal operating conditions, if the ADAS program malfunctions or freezes, causing it to continuously send acceleration commands (abnormal condition 1), braking commands (abnormal condition 2), or steering commands (abnormal condition 3), unacceptable hazards such as the vehicle running off the track, rear-ending another vehicle, or becoming stuck will occur.
[0082] (1) Please refer to Figure 3 If ADAS encounters abnormal condition 1, the vehicle will continue to accelerate. The driver will immediately apply the brakes. At this time, ADAS cannot deactivate the IACC function or send a disable command. If the braking torque is greater than the driving torque, the vehicle will gradually decelerate. Once the driver releases the brake pedal, the vehicle will accelerate again, which can easily cause the vehicle to run off the track or rear-end collision. To address this abnormal condition, this embodiment proposes a first safety mechanism.
[0083] The main contents of the first safety mechanism include: when the ADAS system is activated, once the driver operates the brake pedal beyond the threshold (exceeding 60% of the brake pedal travel and lasting for more than 500ms, the parameter can be calibrated), the VCU should immediately stop responding to the ADAS command and cut off acceleration; after the VCU cuts off acceleration for 500ms (the parameter can be calibrated), if the ADAS continues to send acceleration commands, the VCU will no longer respond to the ADAS command in this ignition cycle.
[0084] (2) Please refer to Figure 4If ADAS encounters abnormal condition 2, the vehicle will continuously decelerate until it stops. During this process, if the driver applies the brakes, ADAS cannot deactivate the IACC function or send a disable command. After the vehicle stops, if the driver attempts to start the vehicle by pressing the accelerator pedal, the driving torque may be less than the braking torque, potentially causing the vehicle to stall. This entire process is highly likely to cause a rear-end collision. To address this abnormal condition, this embodiment proposes a second safety mechanism.
[0085] The second safety mechanism mainly includes: when the ADAS system is activated, if the driver presses the brake pedal to meet "certain conditions" (more than 60% of the brake pedal travel and a duration of more than 500ms, the parameters can be calibrated), and the ADAS continues to send braking commands during this period, then the ESP should immediately exit the IACC function and no longer respond to the ADAS in this ignition cycle.
[0086] (3) Please refer to Figure 5 If ADAS encounters abnormal condition 3, the vehicle will deviate from the track. The driver will immediately apply the brakes and turn the steering wheel. At this time, ADAS cannot disengage the IACC function or send a disable command. If the driver's hand torque is greater than the steering wheel torque, the vehicle will be corrected. Once the driver releases the steering wheel, the vehicle will deviate from the track again. The entire process is highly likely to result in the vehicle running off the track or a collision. To address this abnormal condition, this embodiment proposes a third safety mechanism.
[0087] The main contents of the third safety mechanism include: when the ADAS system is activated, if the driver turns the steering wheel to meet "certain conditions" (the driver's hand torque is greater than 6Nm and the duration is greater than 200ms, the parameters can be calibrated), and the ADAS continues to send steering commands during this period, the EPS should immediately exit the IACC function, and will no longer respond to the ADAS in this ignition cycle.
[0088] Based on the above analysis, this embodiment establishes three safety mechanisms for the actuator. From a functional safety perspective, this already covers abnormal operating conditions 1, 2, and 3 caused by ADAS malfunctions. However, from the perspective of system robustness, to ensure the overall IACC function has strong robustness under extreme conditions, ADAS itself is required to establish safety mechanisms for signal delays and unexpected events in response to these ADAS malfunctions. Therefore, this embodiment also establishes safety mechanisms for the ADAS controller itself.
[0089] Please refer to Figure 6 The internal security mechanisms of the ADAS controller are as follows:
[0090] (1) If the microcontroller unit (MCU) itself is ASIL D, the MCU will continuously monitor the dynamics of the SOC (System on Chip) through a heartbeat mechanism to prevent the SOC from running away or getting stuck.
[0091] (2) MCU is generally the interface between ADAS and actuator. Therefore, adding limit detection for acceleration, deceleration and steering angle in MCU and developing the detection link according to ASIL B can prevent ADAS from outputting abnormal control commands.
[0092] In other words, the MCU performs real-time monitoring of acceleration, deceleration, and steering angle. When it detects that the acceleration, deceleration, and / or steering angle have significantly exceeded the set threshold, the MCU determines that the current vehicle condition is poor and should refuse the ADAS from issuing any further control commands regarding acceleration and steering, thereby preventing abnormal operating conditions caused by ADAS failure.
[0093] (3) If the MCU detects an SOC abnormality or sends an excessive value, it will issue an alarm request to remind the driver so that the driver can disengage from advanced driver assistance in time to prevent accidents.
[0094] Overall, after implementing the above three safety mechanisms for the actuators and the internal safety mechanisms of the ADAS controller, the robustness of the entire IACC function has been further enhanced, and the actual driving experience has been significantly improved.
[0095] Furthermore, in the description of this invention, an Advanced Drive Assist System (ADAS) is an active safety technology that utilizes various sensors installed on a vehicle to collect environmental data inside and outside the vehicle in real time, and performs technical processing such as identification, detection and tracking of static and dynamic objects, thereby enabling the driver to perceive potential dangers in the shortest possible time, thereby attracting attention and improving safety.
[0096] ADAS systems typically include Adaptive Cruise Control (ACC), Lane Departure Warning System (LDWS), Lane Keep Assist (LKA), Collision Avoidance System (CAS), Night Vision System (NV), Adaptive Light Control (ALC), Pedestrian Protection System (PPS), Automatic Parking System (AP), Traffic Sign Recognition (TSR), Blind Spot Detection (BSD), Driver Drowsiness Detection (DDD), Hill Descent Control (HDC), and Electric Vehicle Warning Sounds (EVWS), among others.
[0097] This invention primarily addresses three robustness-deficient conditions in the adaptive cruise control (ACC or IACC) function of L2-level autonomous driving systems. It proposes several safety mechanisms for ADAS controllers and actuators. After implementing these safety mechanisms, regression testing is conducted using appropriate testing methods to ensure that all abnormal issues during road tests are eliminated, thereby improving the driver's driving experience and safety.
[0098] Example 3
[0099] The third embodiment of the present invention provides an advanced driver assistance safety control device, please refer to... Figure 7 The safety control device includes a first detection module 101, a second detection module 102, a judgment module 103, and a release determination module 104.
[0100] The first detection module 101 is used to detect active driving information caused by the user; the active driving information includes brake pedal input and steering wheel input.
[0101] The second detection module 102 is used to detect whether the driver assistance controller is in an abnormal condition; the abnormal condition includes continuously issuing acceleration commands, continuously issuing braking commands, and continuously issuing steering commands.
[0102] The judgment module 103 is connected to the first detection module 101 and the second detection module 102, and is used to determine whether the driver assistance controller has failed based on the abnormal operating condition detection results of the driver assistance controller and the active driving information.
[0103] The release determination module 104 is connected to the judgment module 103 and is used to generate release determination information when the assisted driving controller is determined to be faulty, so as to determine that the actuator actively releases the assisted driving control.
[0104] Specifically, when the driver assistance controller is determined to be faulty, the release determination module can generate release determination information and process the release determination information into release commands, which are then sent to all actuators, causing the actuators to actively release the driver assistance control.
[0105] Alternatively, when the driver assistance controller is determined to be faulty, the release determination module can generate release determination information, process the release determination information into release instructions and send them to the designated actuator, which then sends the release instructions to other actuators.
[0106] For example, when it is determined that the driver assistance controller continuously issues acceleration commands and the brake pedal input exceeds a first input value, the release determination module can first send a first release command to the vehicle stability controller to cause the vehicle stability controller to actively release the driver assistance control. Then, the vehicle stability controller sends a second release command to the vehicle power controller to cause the vehicle power controller to actively release the driver assistance control.
[0107] When the driver assistance controller continuously issues braking commands and the brake pedal input exceeds a first input value, the release determination module can first send a first release command to the vehicle stability controller to cause the vehicle stability controller to actively release the driver assistance control. Then, the vehicle stability controller sends a second release command to the vehicle powertrain controller to cause the vehicle powertrain controller to actively release the driver assistance control.
[0108] When the driver assistance controller continuously issues steering commands and the steering wheel input exceeds the second input amount, the release determination module can first send a third release command to the power steering unit to actively release the driver assistance control. Then, the power steering unit sends a fourth release command to the vehicle stability control to actively release the driver assistance control.
[0109] It should be noted that the above-described device is only illustrated by the division of the functional modules described above. In practical applications, the functions can be assigned to different functional modules as needed, that is, the internal structure of the device can be divided into different functional modules to complete all or part of the functions described above. Furthermore, the device and method embodiments provided in the above embodiments belong to the same concept, and their specific implementation process is detailed in the method embodiments, which will not be repeated here.
[0110] Example 4
[0111] The fourth embodiment of the present invention also provides an advanced driver assistance system for intelligent vehicles, the advanced driver assistance system including a driver assistance controller, a vehicle power controller, a vehicle stability system, a power steering system, and a safety control device.
[0112] The driver assistance controller sends control commands to each actuator when the ACC (Adaptive Cruise Control) function (or IACC) function is activated to achieve driver assistance; and sends release commands to each actuator when the ACC (Adaptive Cruise Control) function (or IACC) function is deactivated to exit driver assistance. Actuators include the vehicle powertrain controller, vehicle stability control, and power steering; control commands include acceleration commands, braking commands, and steering commands.
[0113] The driver assistance controller internally includes an MCU and a SOC (System-on-Chips). The MCU is used to send control commands and detect SOC anomalies, excessive MCU-sent values, or driving parameters exceeding specified thresholds. When the MCU detects an SOC anomaly or excessive MCU-sent values, it generates an alarm request and sends it to the driver. When the MCU detects driving parameters exceeding specified thresholds, it refuses to send control commands. Driving parameters include acceleration, deceleration, and steering angle.
[0114] The Vehicle Dynamics Control Unit (VCU) is used to achieve longitudinal automatic driving; the Power Steering (EPS) is used to achieve lateral automatic driving. The Electronic Stability Program (ESP) sends signals to the driver assistance controller (AACC) indicating that the driver is pressing the brake and turning the steering wheel, causing the AACC to deactivate the Adaptive Cruise Control (ACC) function (or Independent Adaptive Cruise Control (IACC) function) and sending release commands to each actuator.
[0115] A safety control device monitors for malfunctions in the driver assistance controller. When the driver assistance controller malfunctions, the safety control device proactively sends a disengagement command to determine that the actuator should actively disengage the driver assistance system. The safety control device includes a first detection module, a second detection module, a judgment module, and a disengagement determination module. The first detection module detects user-induced active driving information, including brake pedal input and steering wheel input. The second detection module detects abnormal operating conditions in the driver assistance controller; abnormal operating conditions include continuously issuing acceleration commands, continuously issuing braking commands, and continuously issuing steering commands. The judgment module determines whether the driver assistance controller has malfunctioned based on the abnormal operating condition detection results and the active driving information. The disengagement determination module generates disengagement determination information when the driver assistance controller is determined to have malfunctioned, thus determining that the actuator should actively disengage the driver assistance control.
[0116] For example, when it is determined that the driver assistance controller is continuously sending braking or acceleration commands, and the driver is continuously pressing the brake pedal deeply, the release determination module in the safety control device processes the generated release determination information into a release command (or disable command) and sends it to the vehicle stability controller ESP. The vehicle stability controller ESP responds to the release command issued by the safety control device, actively disengages from driver assistance, and sends the release command to the vehicle power controller VCU, so that the vehicle power controller VCU actively disengages from driver assistance.
[0117] When the driver determines that the driver assistance controller is continuously sending steering commands and the driver is continuously turning the steering wheel, the release determination module in the safety control device processes the generated release determination information into a release command (or disable command) and sends it to the power steering EPS. The power steering EPS responds to the release command issued by the safety control device, actively disengages from driver assistance, and sends the release command to the electronic stability program (ESP) so that the ESP actively disengages from driver assistance.
[0118] Example 5
[0119] The fifth embodiment of the present invention also provides an electronic device, see [link to previous document]. Figure 8 The electronic device includes a processor 201 and a memory 202, the memory storing at least one computer program, which is loaded and executed by one or more of the processors to enable the computer to implement the advanced driver assistance safety control method described in the first embodiment or the second embodiment.
[0120] Of course, the electronic device may also have wired or wireless network interfaces, keyboards, and input / output interfaces for input and output. The electronic device may also include other components for implementing the various functions of the device, which will not be elaborated here.
[0121] Example 6
[0122] The sixth embodiment of the present invention also provides a computer-readable storage medium storing at least one piece of program code, which is loaded and executed by a processor to enable a computer to implement the advanced driver assistance safety control method described in the first or second embodiment.
[0123] Optionally, the computer-readable storage medium may be a read-only memory (ROM), a random access memory (RAM), a compact disc read-only memory (CD-ROM), magnetic tape, floppy disk, or optical data storage device, etc. Those skilled in the art will understand that all or part of the steps in the methods of the above embodiments can be implemented by a program instructing related hardware. This program is stored in a storage medium and includes several instructions to cause a microcontroller, chip, or processor to execute all or part of the steps of the methods described in the various embodiments of this application. The aforementioned storage medium includes various media capable of storing program code, such as a USB flash drive, a portable hard drive, a read-only memory (ROM), a random access memory (RAM), a magnetic disk, or an optical disk.
[0124] Example 7
[0125] A seventh embodiment of the present invention also provides an intelligent vehicle equipped with the safety control device described in the third embodiment. For example, the safety control device can be installed in the cabin of the intelligent vehicle. The intelligent vehicle can be a traditional gasoline-powered vehicle, an electric vehicle, a hybrid vehicle, a natural gas vehicle, a hydrogen fuel cell vehicle, etc.
[0126] In summary, the present invention has at least the following technical effects:
[0127] (1) Based on the three abnormal working conditions caused by the abnormal phenomena such as program runaway and freezing of the controller ADAS of the advanced driver assistance system, the present invention forms three safety mechanisms for the actuator, which not only increases the safety of the advanced driver assistance system, but also significantly improves the actual driving experience.
[0128] (2) The present invention also forms a safety mechanism for the internal system of the driver assistance controller (ADAS). When an abnormal SOC or abnormal value is detected, the driver is actively reminded so that the driver can adjust the vehicle status in a timely manner.
[0129] (3) This invention is applicable to L2 level autonomous driving systems and can enhance the robustness of functions such as IACC, ACC and ICC of intelligent vehicles.
[0130] The above embodiments are merely preferred embodiments and the technical principles applied thereto for fully illustrating the present invention, and the scope of protection of the present invention is not limited thereto. Those skilled in the art will clearly understand that, for the sake of convenience and brevity, the above-described division of functional units and modules is used as an example. In practical applications, the above functions can be assigned to different functional units and modules as needed, that is, the internal structure of the device can be divided into different functional units or modules to complete all or part of the functions described above. The functional units and modules in the embodiments can be integrated into one processing unit, or each unit can exist physically separately, or two or more units can be integrated into one unit. The integrated unit can be implemented in hardware or as a software functional unit. Furthermore, the specific names of the functional units and modules are only for easy differentiation and are not intended to limit the scope of protection of this application.
Claims
1. A method for assisted driving safety control, characterized in that, The security control method includes: Detect active driving information caused by the user, including brake pedal input and steering wheel input; Detect whether the driver assistance controller is experiencing abnormal operating conditions, including continuously issuing acceleration commands, continuously issuing braking commands, and continuously issuing steering commands; Based on the detection results of abnormal operating conditions and the active driving information, determine whether the driver assistance controller has failed. Whether to actively disengage the driver assistance control by the actuator is determined based on whether the driver assistance controller fails. The actuator includes the vehicle power controller, the vehicle stabilizer, and the power steering. When it is determined that the driver assistance controller continuously issues acceleration or braking commands and the brake pedal input exceeds the first input, a first release command is sent to the vehicle stabilizer to cause the vehicle stabilizer to actively release the driver assistance control; the vehicle stabilizer sends a second release command to the vehicle power controller to cause the vehicle power controller to actively release the driver assistance control. When it is determined that the driver assistance controller continuously issues steering commands and the steering wheel input exceeds the second input, a third release command is sent to the power steering to cause the power steering to actively release the driver assistance control; the power steering sends a fourth release command to the vehicle stability control to cause the vehicle stability control to actively release the driver assistance control.
2. The assisted driving safety control method according to claim 1, characterized in that, After the actuator actively disengages the driver assistance control, it will no longer respond to the driver assistance controller during the current ignition cycle.
3. The assisted driving safety control method according to claim 1, characterized in that, The safety control method further includes: issuing an alarm request when the microcontroller unit inside the driver assistance controller detects a SOC abnormality or the control command sending value exceeds a specified amount.
4. The assisted driving safety control method according to claim 3, characterized in that, The safety control method further includes: when the microcontroller detects that the driving parameters exceed a specified threshold, it refuses to issue control commands to the actuator, wherein the driving parameters include acceleration, deceleration and steering angle.
5. A driver assistance safety control device, characterized in that, The safety control device includes a first detection module, a second detection module, a judgment module, and a deactivation module; The first detection module is used to detect active driving information caused by the user, including brake pedal input and steering wheel input. The second detection module is used to detect whether the driver assistance controller is in an abnormal operating condition, including continuously issuing acceleration commands, continuously issuing braking commands, and continuously issuing steering commands. The judgment module is used to determine whether the driver assistance controller has failed based on the abnormal operating condition detection results of the driver assistance controller and the active driving information. The release determination module is used to generate release determination information when the driver assistance controller is determined to be malfunctioning, thereby determining that the actuator should actively release the driver assistance control. When it is determined that the driver assistance controller continuously issues acceleration or braking commands, and the brake pedal input exceeds a first input amount, a first release command is sent to the vehicle stability controller to cause the vehicle stability controller to actively release the driver assistance control. The vehicle stability controller then sends a second release command to the vehicle power controller to cause the vehicle power controller to actively release the driver assistance control. When it is determined that the driver assistance controller continuously issues steering commands, and the steering wheel input exceeds a second input amount, a third release command is sent to the power steering unit to cause the power steering unit to actively release the driver assistance control. Finally, the power steering unit sends a fourth release command to the vehicle stability controller to cause the vehicle stability controller to actively release the driver assistance control.
6. An intelligent vehicle, characterized in that, The intelligent vehicle includes the safety control device as described in claim 5.
7. An electronic device, characterized in that, The electronic device includes a processor and a memory, wherein the memory stores at least one computer program, which is loaded and executed by one or more of the processors to enable the computer to implement the assisted driving safety control method according to any one of claims 1 to 4.
8. A computer-readable storage medium, characterized in that, The computer-readable storage medium stores at least one piece of program code, which is loaded and executed by a processor to enable the computer to implement the assisted driving safety control method according to any one of claims 1 to 4.
Citation Information
Patent Citations
Design method of functional safety framework of steering system of distributed intelligent electric vehicle
CN110254512A
Automatic driving expected function safety hazard assessment method based on zero-day loopholes
CN110930005A
Takeover detection method and device of intelligent automobile and storage medium
CN109318906A
Method and device for assisting vehicle driving
CN113581176A