An automatic parking safety requirement derivation method and device, a vehicle and a storage medium
By identifying unsafe behavior information in the automatic parking control system and conducting a vehicle-wide hazard analysis to form safety requirements, the problem of existing automatic parking functions not considering functional safety is solved, and the stability and safety of the system are improved.
Patent Information
- Application Number
- CN202310777770.6
- Authority / Receiving Office
- CN · China
- Patent Type
- Patents(China)
- Current Assignee / Owner
- Filing Date
- 2023-06-28
- Publication Date
- 2025-10-10
- Estimated Expiration
- 2043-06-28
AI Technical Summary
The development of existing automatic parking functions has not fully considered the requirements of functional safety and expected functions, resulting in functional deviations of the automatic parking system due to electronic system failure or uncertainty in the output of the neural network black box, increasing traffic safety risks.
Through an automatic parking control system based on pre-defined functions, the first unsafe behavior information is determined, and the second unsafe behavior information is determined by applying safety analysis keywords. The failed unsafe behavior is analyzed in combination with the current scenario, and a vehicle hazard analysis is conducted to form safety requirements, including environmental perception, decision-making and control, wire-controlled chassis and human-computer interaction constraints.
The safety of the automatic parking system has been improved. Through full-factor analysis, it not only solves the problem of electronic and electrical failure, but also takes into account uncertain factors such as human misuse and environmental impact, thereby improving the stability and safety of the system.
Smart Images

Figure CN116572943B_ABST
Abstract
Description
Technical Field
[0001] The present invention relates to the field of automotive technology, and in particular to a method, device, vehicle, and storage medium for deriving automatic parking safety requirements. Background Art
[0002] With the rapid development of intelligent connected vehicles and autonomous vehicles, automated parking functions are becoming increasingly popular. For autonomous or driver-assisted vehicles, most or almost all of the vehicle's control is delegated to the vehicle's electronic systems, making the effectiveness of this control crucial. In traditional automotive applications, failures often stem from failures in the electronic systems. However, this is not the case in autonomous driving systems. Even if the electronic systems are not faulty, uncertainties in factors such as neural network black box outputs can lead to functional deviations, potentially causing traffic injuries. Even if there are no errors or failures at the perception, decision-making, and execution levels, complex traffic conditions and unexpected vehicle behaviors can still destabilize the autonomous driving system. Consequently, designing highly reliable and safe electronic systems is gaining increasing attention. Existing automated parking features often fail to consider functional safety and the requirements of intended functionality, and the parking technologies currently implemented by OEMs focus primarily on functional implementation. Summary of the Invention
[0003] The present invention provides a method, device, vehicle and storage medium for deriving safety requirements for automatic parking, so as to solve the problem that the development of existing automatic parking functions often fails to consider the development of functional safety and expected functional requirements.
[0004] According to one aspect of the present invention, a method for deriving safety requirements for automatic parking is provided, the method comprising:
[0005] An automatic parking control system based on a predefined function determines first unsafe behavior information output by the automatic parking control system in a current automatic parking scenario;
[0006] Determining second unsafe behavior information by applying safety analysis keywords based on the first unsafe behavior information, and determining invalid unsafe behavior information based on the second unsafe behavior information in combination with the current automatic parking scenario;
[0007] Performing a vehicle hazard analysis based on the unsafe failure behavior information to determine safety hazard events in the current automatic parking scenario;
[0008] Based on the triggering event and the constraint conditions of the hazardous event, the safety requirements of the automatic parking control system in the current automatic parking scenario are formed.
[0009] Optionally, the automatic parking control system with predefined functions includes a sensor detection module, an actuator and an automatic parking function module; the automatic parking function module includes a perception fusion unit, a perception processing unit, a planning unit and a control unit, the perception fusion unit is used to obtain real-time parking behavior information collected by the sensor detection module, the planning unit is used to plan the current automatic parking scenario based on the real-time parking behavior information, the perception processing unit is used to collect sudden parking behavior information collected by the sensor detection module, the control unit is used to generate execution control information based on the planning of the current automatic parking scenario by the planning unit and the sudden parking behavior information; the actuator is used to execute the automatic parking behavior in the current automatic parking scenario according to the execution control information.
[0010] Optionally, determining first unsafe behavior information output by the automatic parking control system in the current automatic parking scenario includes:
[0011] determining whether a sensor detection module, an actuator, and an automatic parking function module included in the automatic parking control system are faulty in a current automatic parking scenario;
[0012] First unsafe behavior information is generated according to a result of determining whether a failure occurs.
[0013] Optionally, the current automatic parking scenario includes current parking direction, actual parking space information, and current parking status information;
[0014] Determining failure unsafe behavior information based on the second unsafe behavior information in combination with the current automatic parking scenario includes:
[0015] Invalid unsafe behavior information is determined according to the second unsafe behavior information in combination with the current parking direction, the actual parking space information, and the current parking state information.
[0016] Optionally, a vehicle hazard analysis is performed based on the unsafe failure behavior information to determine safety hazard events in the current automatic parking scenario, including:
[0017] Based on the environmental perception, decision-making and control, wire-controlled chassis and human-computer interaction in the autonomous driving system, the vehicle hazard analysis is conducted on the unsafe failure behavior information to determine the safety hazard events in the current automatic parking scenario.
[0018] Optionally, based on the triggering event and constraint conditions of the hazardous event, safety requirements of the automatic parking control system in the current automatic parking scenario are formed, including:
[0019] Based on the environmental perception, decision-making and control, wire-controlled chassis and human-computer interaction in the autonomous driving system, the triggering events and constraints of the hazardous events are determined to form the safety requirements of the autonomous parking control system in the current autonomous parking scenario. The safety requirements include the perception of autonomous driving functions in the environmental perception, detection of obstacle deviations and determination of fusion execution information, decision-making execution information in the decision-making and control, transmission control information and execution information in the wire-controlled chassis, and driver behavior information in human-computer interaction.
[0020] Optionally, the perception autonomous driving function in the environmental perception is whether the autonomous driving system has the ability to identify and judge ODD, the detection of obstacle deviation is whether a decision is required after detecting the obstacle deviation, and the determination of fusion execution information is whether there is a collision risk;
[0021] The decision execution information in the decision and control is to determine the current parking decision execution status;
[0022] The transmission control information in the wire-controlled chassis is the communication protection and communication execution status, and the execution information is the execution instruction rationality check;
[0023] The driver behavior information in the human-computer interaction is driver behavior information confirmation.
[0024] According to another aspect of the present invention, a device for deriving safety requirements for automatic parking is provided, the device comprising:
[0025] a first unsafe behavior information determining module, configured to execute an automatic parking control system based on a predefined function and determine first unsafe behavior information output by the automatic parking control system in a current automatic parking scenario;
[0026] a failed unsafe behavior information determination module, configured to determine second unsafe behavior information by applying a safety analysis keyword based on the first unsafe behavior information, and determine failed unsafe behavior information based on the second unsafe behavior information in combination with the current automatic parking scenario;
[0027] a safety hazard event determination module, configured to perform a vehicle hazard analysis based on the unsafe behavior information and determine a safety hazard event in the current automatic parking scenario;
[0028] The safety requirement forming module is used to form the safety requirements of the automatic parking control system in the current automatic parking scenario according to the triggering event and constraint conditions of the hazardous event.
[0029] According to another aspect of the present invention, there is provided a vehicle, comprising:
[0030] at least one processor; and,
[0031] a memory communicatively connected to the at least one processor; wherein,
[0032] The memory stores a computer program that can be executed by the at least one processor, and the computer program is executed by the at least one processor so that the at least one processor can execute the automatic parking safety requirement derivation method described in any embodiment of the present invention.
[0033] According to another aspect of the present invention, a computer-readable storage medium is provided, wherein the computer-readable storage medium stores computer instructions, and the computer instructions are used to enable a processor to implement the automatic parking safety requirement derivation method described in any embodiment of the present invention when executed.
[0034] The technical solution of an embodiment of the present invention determines first unsafe behavior information output by an automatic parking control system based on predefined functions in the current automatic parking scenario; applies safety analysis keywords based on the first unsafe behavior information to determine second unsafe behavior information, and determines failure unsafe behavior information based on the second unsafe behavior information in combination with the current automatic parking scenario; performs a vehicle hazard analysis based on the failure unsafe behavior information to determine safety hazard events in the current automatic parking scenario; and forms safety requirements for the automatic parking control system in the current automatic parking scenario based on the triggering events and constraints of the hazard events. This invention solves the problem that existing automatic parking function development often fails to consider functional safety and the requirements of expected functions, thereby improving the safety of automatic parking systems.
[0035] It should be understood that the content described in this section is not intended to identify the key or important features of the embodiments of the present invention, nor is it intended to limit the scope of the present invention. Other features of the present invention will become readily understood through the following description. BRIEF DESCRIPTION OF THE DRAWINGS
[0036] In order to more clearly illustrate the technical solutions in the embodiments of the present invention, the following briefly introduces the drawings required for use in the description of the embodiments. Obviously, the drawings described below are only some embodiments of the present invention. For ordinary technicians in this field, other drawings can be obtained based on these drawings without creative work.
[0037] Figure 1 This is the implementation architecture diagram of the current autonomous driving system solution;
[0038] Figure 2 is a flow chart of a method for deriving safety requirements for automatic parking according to an embodiment of the present invention;
[0039] Figure 3 is a physical architecture diagram of a method for deriving safety requirements for automatic parking applicable to an embodiment of the present invention;
[0040] Figure 4 is an application architecture diagram of a method for deriving safety requirements for automatic parking applicable to an embodiment of the present invention;
[0041] Figure 5 2 is a schematic structural diagram of an automatic parking safety requirement derivation device provided according to an embodiment of the present invention;
[0042] Figure 6 2 is a schematic structural diagram of a vehicle for implementing the automatic parking safety requirement derivation method according to an embodiment of the present invention. DETAILED DESCRIPTION
[0043] In order to enable those skilled in the art to better understand the solutions of the present invention, the technical solutions in the embodiments of the present invention will be clearly and completely described below in conjunction with the drawings in the embodiments of the present invention. Obviously, the embodiments described are only part of the embodiments of the present invention, not all of the embodiments. Based on the embodiments of the present invention, all other embodiments obtained by ordinary technicians in this field without making creative efforts should fall within the scope of protection of the present invention.
[0044] It should be noted that the terms "first", "second", etc. in the description and claims of the present invention and the above-mentioned drawings are used to distinguish similar objects and are not necessarily used to describe a specific order or sequence. It should be understood that the numbers used in this way can be interchanged where appropriate, so that the embodiments of the present invention described herein can be implemented in an order other than those illustrated or described herein. In addition, the terms "including" and "having" and any variations thereof are intended to cover non-exclusive inclusions. For example, a process, method, system, product or device that includes a series of steps or units is not necessarily limited to those steps or units clearly listed, but may include other steps or units that are not clearly listed or inherent to these processes, methods, products or devices.
[0045] For many drivers, parallel parking is a painful experience, and parking space is limited in big cities, so it has become a necessary skill to drive a car into a small space. The development of automatic parking function technology provides a solution, and automatic parking function only needs to start the button, sit down, relax, and everything else can be automatically completed. The automatic driving system is usually divided into three parts: environment perception, decision planning and control execution. First, the environment perception collects information around the car through various sensors, including cameras (image perception), active radar, millimeter wave radar, combined navigation (distance perception), etc. The automatic driving system needs to calculate the driving instruction and plan the path according to the driver's intention, current speed, external environment and other states through intelligent control algorithm, and finally the drive-by-wire chassis system executes the driving instruction and controls the vehicle operation. The specific automatic driving system scheme can be referred to as shown in Figure 1
[0046] During the operation of the automatic driving system, the environment perception, decision and control of the automatic driving system and the man-machine interaction may face electronic and electrical failure and cause personal injury. At the same time, since the environment perception of the automatic driving system mainly depends on the perception sensor, and the control algorithm uses AI and other output uncertainty algorithms, the automatic driving system also faces the problems of sensor performance limitation and algorithm uncertainty leading to insufficient function or personnel misuse. With the landing implementation of automatic driving technology, various safety problems caused by automatic driving are increasing.
[0047] Based on the above problems, the application provides an automatic parking safety requirement derivation method, device, vehicle and storage medium, which derives safety requirements in the development of automatic parking function through analysis of all factors, to solve the above problems.
[0048] Figure 2 A flowchart of an automatic parking safety requirement derivation method is provided for the embodiments of the application. The embodiments can be applicable to the case of deriving safety requirements for automatic parking function based on functional safety and expected functional safety fusion. The automatic parking safety requirement derivation method can be executed by an automatic parking safety requirement derivation device, which can be realized in the form of hardware and / or software. The automatic parking safety requirement derivation device can be configured in an automatic driving vehicle or a driving assistance vehicle. As shown in Figure 2 The automatic parking safety requirement derivation method includes:
[0049] S110, based on the pre-defined automatic parking control system, determining the first unsafe behavior information output by the automatic parking control system in the current automatic parking scene.
[0050] Traditional autonomous driving safety analysis focuses solely on electronic and electrical failures, such as software errors and hardware open and short circuits. However, autonomous driving faces challenges that encompass not only electronic and electrical failures but also uncertainties such as human misuse, environmental impacts, and AI algorithms. Accidents caused by these factors can potentially harm road users. For these reasons, this embodiment provides a method for deriving safety requirements for automated parking, enabling the driver to perform automated parking in automated parking scenarios.
[0051] First, the principle, interface, performance, and boundary of the automatic parking control system are defined and analyzed. When the driver drives the vehicle to find a parking place, Figure 3 As shown, in the automatic parking control system based on predefined functions, during the automatic parking process, the perception fusion unit of the automatic parking function module perceives the information around the vehicle, and the control unit of the automatic parking function module controls the vehicle steering wheel and gear position to realize the vehicle parking in and out. At the same time, the driver is required to pay attention to the surrounding environment in the vehicle and be ready to take over in real time.
[0052] Continue to see Figure 3 and Figure 4 As shown, an automatic parking control system with a predefined function includes a sensor detection module, an actuator, and an automatic parking function module; the automatic parking function module includes a perception fusion unit, a perception processing unit, a planning unit, and a control unit. The perception fusion unit is used to obtain real-time parking behavior information collected by the sensor detection module; the planning unit is used to plan the current automatic parking scenario based on the real-time parking behavior information; the perception processing unit is used to collect sudden parking behavior information collected by the sensor detection module; the control unit is used to generate execution control information based on the planning of the current automatic parking scenario by the planning unit and the sudden parking behavior information; the actuator is used to execute the automatic parking behavior in the current automatic parking scenario based on the execution control information.
[0053] Among them, the sensor detection module can include but is not limited to surround-view cameras, ultrasonic radars and millimeter-wave radars. Real-time parking behavior information is collected through surround-view cameras and ultrasonic radars. The perception fusion module obtains real-time parking behavior information collected by the surround-view cameras and ultrasonic radars, and collects sudden parking behavior information through millimeter-wave radars. The perception processing module obtains sudden parking behavior information collected by the millimeter-wave radar.
[0054] Real-time parking behavior information refers to real-time parking behavior information generated during the vehicle's automatic parking process in the current automatic parking scenario. Unexpected parking behavior information refers to unexpected parking behavior information generated during the vehicle's automatic parking process in the current automatic parking scenario due to changes in the external environment or the occurrence of unexpected events. Environmental changes include, but are not limited to, temporary changes in the surrounding environment or the vehicle, and unexpected events include, but are not limited to, passing creatures or the occurrence of recognizable unexpected scenes. This embodiment does not impose any restrictions on these.
[0055] Specifically, a determination is made as to whether a fault has occurred in the sensor detection module, actuator, and automatic parking function module included in the automatic parking control system in the current automatic parking scenario. It is understood that a fault may include a detected fault that may have occurred during the automatic parking process, as well as a fault in the controller or other components within the automatic parking control system. Furthermore, first unsafe behavior information is generated based on the result of determining whether a fault has occurred.
[0056] When it is determined that a fault occurs in the sensor detection module, the actuator, and the automatic parking function module included in the automatic parking control system in the current automatic parking scenario, first unsafe behavior information is generated according to the corresponding fault. For example, the first unsafe behavior information may be, but is not limited to, a camera in the sensor detection module being blocked, an incorrect vehicle speed, or an incorrect vehicle gear, etc. This embodiment does not impose any restrictions on this.
[0057] S120: Determine second unsafe behavior information by applying safety analysis keywords based on the first unsafe behavior information, and determine invalid unsafe behavior information based on the second unsafe behavior information in combination with the current automatic parking scenario.
[0058] Among them, the keywords of safety analysis are applied. The current safety analysis method mainly uses the HAZOP keyword guidance method. The inductive and deductive analysis method can also be used to analyze the first unsafe behavior information and then determine the second unsafe behavior information.
[0059] The second unsafe behavior information is a specific unsafe behavior analyzed based on the first unsafe behavior information. For example, taking the first unsafe behavior information as an incorrect vehicle speed, the second unsafe behavior information may be excessive speed, insufficient speed, or speed stuck at a fixed value.
[0060] The current automatic parking scenario includes a current parking direction, actual parking space information, and current parking state information. The current parking direction refers to the horizontal, vertical, or certain angle oblique position of the vehicle relative to the central axis of the parking space or parking lot. It can be understood that the current parking direction changes in real time as the automatic parking process proceeds. The actual parking space information can be, but is not limited to, a fixed parking space, such as a planned line parking space on the ground or underground in a residential or commercial area. The actual parking space information can be, but is not limited to, a temporary roadside parking position. In this case, the actual parking space information can be determined based on the surrounding environment of the surrounding vehicles or obstacles. The current parking state information is the real-time state information of the vehicle during the current automatic parking process. The current parking state information can reflect whether an obstacle appears around the vehicle at this time, or can be other predictable situations. The embodiment does not make any limitation on this.
[0061] On the basis described above, the invalid unsafe behavior information is determined according to the second unsafe behavior information in combination with the current parking direction, the actual parking space information, and the current parking state information.
[0062] The invalid unsafe behavior information is used to define the harm to the whole vehicle. For example, if a camera in the sensor detection module is blocked, the corresponding invalid unsafe behavior information is that the parking line cannot be recognized, which can cause a collision during the automatic parking process. At this time, it can be defined as a harm to the whole vehicle. Further, after the invalid unsafe behavior information is determined, obstacle avoidance control can be performed accordingly.
[0063] S130, whole vehicle harm analysis is performed according to the invalid unsafe behavior information to determine a safety hazard event in the current automatic parking scenario.
[0064] Specifically, the whole vehicle harm analysis is performed on the invalid unsafe behavior information based on the environment perception, decision and control, line control chassis, and human-computer interaction in the automatic driving system to determine the safety hazard event in the current automatic parking scenario.
[0065] Continuing to refer to Figure 4 As shown, the whole vehicle harm analysis is performed on the invalid unsafe behavior information based on the environment perception in the automatic driving system, that is, the whole vehicle harm caused by external environmental factors. The external environmental factors can include, but are not limited to, the road and road surface conditions, weather factors, behaviors of traffic participants, road and vehicle facilities, or other factors. The embodiment does not make any limitation on this.
[0066] For example, if a camera in the sensor detection module is blocked, the whole vehicle harm analysis based on the environment perception in the automatic driving system can be understood as that the camera in the sensor detection module is blocked due to external environmental factors.
[0067] Continue to see Figure 4 As shown, based on the decision-making and control in the automatic driving system, the unsafe behavior information of the failure is subjected to a vehicle-wide hazard analysis, which can be understood as a vehicle-wide hazard caused by the steering in the actuator. The steering in the actuator is a steering wheel operation, which may include but is not limited to the steering angle fed back by the automatic parking function, and the steering result fed back by the actuator to the automatic parking function, the steering angle sensor (SAS) or the override state, etc. This embodiment does not impose any restrictions on this.
[0068] Continue to see Figure 4 As shown, based on the wire-controlled chassis in the automatic driving system, the vehicle hazard analysis of the failure unsafe behavior information is performed, which can be understood as the vehicle hazard caused by braking and driving in the actuator. The braking in the actuator is the brake pedal / EPB switch, which can include but is not limited to the hydraulic deceleration feedback of the automatic parking function, EPB activation or acceleration request through braking, and the functional status such as vehicle speed, wheel speed, master cylinder pressure fed back by the actuator to the automatic parking function. The driving in the actuator is the accelerator pedal / gear, which can include but is not limited to the throttle position, charge SOC and other status fed back by the actuator to the automatic parking function.
[0069] Continue to see Figure 4 As shown, based on the human-machine interaction in the autonomous driving system, the failure and unsafe behavior information is subjected to a vehicle-wide hazard analysis, which can be understood as the human-machine interface HMI in the actuator determining the vehicle-wide hazard caused by human misuse. The human-machine interface HMI in the actuator is a reminder setting, which may include but is not limited to a reminder request fed back by the actuator to the automatic parking function.
[0070] It should also be noted that the switch control in the actuator may include but is not limited to the backlight information fed back by the automatic parking function, and the switch control status fed back by the actuator to the automatic parking function; the others in the actuator are other vehicle operations, such as ESC switches, doors, seat belts, ignition buttons, etc., which may include but are not limited to the wipers and lights fed back by the automatic parking function, and the status of wipers, lights, seats, doors, seat belts, airbags, inertial sensors IMU, power mode and user ID fed back by the actuator to the automatic parking function.
[0071] S140: Based on the triggering event and constraint conditions of the hazardous event, a safety requirement of the automatic parking control system in the current automatic parking scenario is formed.
[0072] Specifically, based on the environmental perception, decision-making and control, wire-controlled chassis and human-computer interaction in the autonomous driving system, the triggering events and constraints of the hazardous events are determined to form the safety requirements of the automatic parking control system in the current automatic parking scenario. The safety requirements include the perception of autonomous driving functions in the environmental perception, detection of obstacle deviations and determination of fusion execution information, decision execution information in the decision-making and control, transmission control information and execution information in the wire-controlled chassis, and driver behavior information in human-computer interaction.
[0073] The perception autonomous driving function in the environmental perception is whether the autonomous driving system has the ability to identify and judge ODD, the detection of obstacle deviation is whether a decision is required after detecting obstacle deviation, and the determination of fusion execution information is whether there is a collision risk.
[0074] Among them, whether the autonomous driving system has the ODD recognition and judgment capabilities can be understood as the autonomous driving system should have the ODD (Operational Design Domain) recognition and judgment capabilities. Only when it is within the ODD range can the autonomous driving function be activated and automatic parking control can be performed.
[0075] Obstacle detection includes detecting static obstacles and dynamic obstacles. Different standards can be designed for static obstacles and dynamic obstacles respectively. For example, obstacle detection deviation is to determine whether a decision is needed after detecting the obstacle deviation. That is, the deviation of static obstacles should be less than 5cm, and the deviation of dynamic obstacles should be less than 10cm. When mirror reflection or co-frequency interference causes the obstacle to be temporarily unclear (less than 3 cycles), an estimated decision should be made based on the previous detection results.
[0076] The perception fusion module should ensure that the obstacle distance calculated based on the ultrasonic radar sensor information reserves the necessary safety margin to avoid collision risks caused by perception blind spots, interference, fluctuations, etc., that is, determine whether the fusion execution information is a collision risk.
[0077] The decision execution information in the decision and control is used to determine the current parking decision execution status; the current parking decision execution status should be calculated by the lock-step core to calculate the steering control command, and the change rate of the steering command should be constrained based on the vehicle speed. Among them, the lock-step core is a method for achieving high diagnostic coverage. The steering control command can also be calculated by other methods, and this embodiment does not impose any restrictions on this.
[0078] The transmission control information in the wire-controlled chassis is communication protection and communication execution status, and the execution information is execution instruction rationality check; among them, communication protection and communication execution status can be understood as the steering control command signal should be communication protected and the communication timeout execution of 2.5 times the cycle should be detected; the execution instruction rationality check can be understood as the rationality check of the steering command. If the rate of change is less than K, the driver's control intention should be judged. K is a preset value, and this embodiment does not impose any restrictions on this value range.
[0079] The driver behavior information in the human-machine interaction is driver behavior information confirmation. After the autonomous driving function is activated, the autonomous driving system should use secondary confirmation or other methods to prevent the driver from accidentally pressing the autonomous driving function off button. When the handover of driving rights is required, the autonomous driving system should continuously reinforce the driver's reminders through display, voice, seat vibration, vehicle deceleration, etc. to prevent the driver from being unaware of the need to take over the vehicle.
[0080] The technical solution of an embodiment of the present invention determines first unsafe behavior information output by an automatic parking control system based on predefined functions in a current automatic parking scenario; applies safety analysis keywords based on the first unsafe behavior information to determine second unsafe behavior information; and determines failure unsafe behavior information based on the second unsafe behavior information in combination with the current automatic parking scenario; performs a vehicle-wide hazard analysis based on the failure unsafe behavior information to determine safety hazard events in the current automatic parking scenario; and forms safety requirements for the automatic parking control system in the current automatic parking scenario based on the triggering events and constraints of the hazard events. This invention addresses the problem that existing automatic parking function development often fails to consider functional safety and expected functional requirements. By analyzing issues affecting automatic parking safety using a full-factor approach, the present invention goes beyond electronic and electrical failure analysis to analyze issues such as insufficient automatic parking system functionality, whether the automatic parking system is used in an inappropriate environment, and human misuse. This method offers significant advantages in analyzing automatic parking safety issues, thereby improving the safety of automatic parking systems.
[0081] Based on the same inventive concept, Figure 5 This is a schematic diagram of the structure of an automatic parking safety requirement derivation device provided by an embodiment of the present invention. Figure 5 As shown, the automatic parking safety requirement derivation device includes:
[0082] a first unsafe behavior information determining module 510 for executing an automatic parking control system based on a predefined function and determining first unsafe behavior information output by the automatic parking control system in a current automatic parking scenario;
[0083] a failed unsafe behavior information determination module 520 , configured to determine second unsafe behavior information based on the first unsafe behavior information by applying safety analysis keywords, and determine failed unsafe behavior information based on the second unsafe behavior information in combination with the current automatic parking scenario;
[0084] A safety hazard event determination module 530 is configured to perform a vehicle hazard analysis based on the unsafe behavior information to determine a safety hazard event in the current automatic parking scenario;
[0085] The safety requirement forming module 540 is configured to form safety requirements of the automatic parking control system in the current automatic parking scenario according to the triggering event and constraint conditions of the hazardous event.
[0086] Optionally, the automatic parking control system with predefined functions includes a sensor detection module, an actuator and an automatic parking function module; the automatic parking function module includes a perception fusion unit, a perception processing unit, a planning unit and a control unit, the perception fusion unit is used to obtain real-time parking behavior information collected by the sensor detection module, the planning unit is used to plan the current automatic parking scenario based on the real-time parking behavior information, the perception processing unit is used to collect sudden parking behavior information collected by the sensor detection module, the control unit is used to generate execution control information based on the planning of the current automatic parking scenario by the planning unit and the sudden parking behavior information; the actuator is used to execute the automatic parking behavior in the current automatic parking scenario according to the execution control information.
[0087] Optionally, determining first unsafe behavior information output by the automatic parking control system in a current automatic parking scenario is specifically used to:
[0088] determining whether a sensor detection module, an actuator, and an automatic parking function module included in the automatic parking control system are faulty in a current automatic parking scenario;
[0089] First unsafe behavior information is generated according to a result of determining whether a failure occurs.
[0090] Optionally, the current automatic parking scenario includes current parking direction, actual parking space information, and current parking status information;
[0091] Determining the failure unsafe behavior information based on the second unsafe behavior information in combination with the current automatic parking scenario is specifically used to:
[0092] Invalid unsafe behavior information is determined according to the second unsafe behavior information in combination with the current parking direction, the actual parking space information, and the current parking state information.
[0093] Optionally, the security hazard event determination module 530 is specifically configured to:
[0094] Based on the environmental perception, decision-making and control, wire-controlled chassis and human-computer interaction in the autonomous driving system, the vehicle hazard analysis is conducted on the unsafe failure behavior information to determine the safety hazard events in the current automatic parking scenario.
[0095] Optionally, the security requirement forming module 540 is specifically configured to:
[0096] Based on the environmental perception, decision-making and control, wire-controlled chassis and human-computer interaction in the autonomous driving system, the triggering events and constraints of the hazardous events are determined to form the safety requirements of the autonomous parking control system in the current autonomous parking scenario. The safety requirements include the perception of autonomous driving functions in the environmental perception, detection of obstacle deviations and determination of fusion execution information, decision-making execution information in the decision-making and control, transmission control information and execution information in the wire-controlled chassis, and driver behavior information in human-computer interaction.
[0097] Optionally, the perception autonomous driving function in the environmental perception is whether the autonomous driving system has the ability to identify and judge ODD, the detection of obstacle deviation is whether a decision is required after detecting the obstacle deviation, and the determination of fusion execution information is whether there is a collision risk;
[0098] The decision execution information in the decision and control is to determine the current parking decision execution status;
[0099] The transmission control information in the wire-controlled chassis is the communication protection and communication execution status, and the execution information is the execution instruction rationality check;
[0100] The driver behavior information in the human-computer interaction is driver behavior information confirmation.
[0101] The automatic parking safety requirement derivation device provided in the embodiment of the present invention can execute the automatic parking safety requirement derivation method provided in any embodiment of the present invention, and has the corresponding functional modules and beneficial effects of executing the automatic parking safety requirement derivation method.
[0102] Based on the same inventive concept, Figure 6A schematic diagram of a vehicle 610 that can be used to implement an embodiment of the present invention is shown. The vehicle includes various forms of digital computers, such as laptop computers, desktop computers, workstations, personal digital assistants, servers, blade servers, mainframe computers, and other suitable computers. The vehicle may also include various forms of mobile devices, such as personal digital assistants, cellular phones, smart phones, wearable devices (such as helmets, glasses, watches, etc.), and other similar computing devices. The components shown herein, their connections and relationships, and their functions are merely examples and are not intended to limit the implementation of the present invention described and / or claimed herein.
[0103] like Figure 6 As shown, the vehicle 610 includes at least one processor 611 and a memory, such as a read-only memory (ROM 612) and a random access memory (RAM 613), which are communicatively connected to the at least one processor 611. The memory stores a computer program that can be executed by the at least one processor, and the processor 611 can perform various appropriate actions and processes according to the computer program stored in the read-only memory (ROM 612) or the computer program loaded from the storage unit 618 to the random access memory (RAM 613). Various programs and data required for the operation of the vehicle 610 can also be stored in the RAM 613. The processor 611, ROM 612, and RAM 613 are connected to each other via a bus 614. An I / O (input / output) interface 615 is also connected to the bus 614.
[0104] Various components in the vehicle 610 are connected to the I / O interface 615, including an input unit 616, such as a keyboard, mouse, etc.; an output unit 617, such as various types of displays, speakers, etc.; a storage unit 618, such as a magnetic disk, optical disk, etc.; and a communication unit 619, such as a network card, modem, wireless communication transceiver, etc. The communication unit 619 allows the vehicle 610 to exchange information / data with other devices via a computer network such as the Internet and / or various telecommunication networks.
[0105] Processor 611 can be any general-purpose and / or specialized processing component with processing and computing capabilities. Some examples of processor 611 include, but are not limited to, a central processing unit (CPU), a graphics processing unit (GPU), various specialized artificial intelligence (AI) computing chips, various processors running machine learning model algorithms, digital signal processors (DSPs), and any other suitable processors, controllers, microcontrollers, etc. Processor 611 executes the various methods and processes described above, such as the method for deriving safety requirements for automated parking.
[0106] In some embodiments, the automatic parking safety requirement derivation method can be implemented as a computer program tangibly embodied in a computer-readable storage medium, such as storage unit 618. In some embodiments, part or all of the computer program can be loaded and / or installed on vehicle 610 via ROM 612 and / or communication unit 619. When the computer program is loaded into RAM 613 and executed by processor 611, one or more steps of the automatic parking safety requirement derivation method described above can be performed. Alternatively, in other embodiments, processor 611 can be configured to execute the automatic parking safety requirement derivation method in any other suitable manner (e.g., via firmware).
[0107] Various embodiments of the systems and techniques described herein can be implemented in digital electronic circuit systems, integrated circuit systems, field programmable gate arrays (FPGAs), application specific integrated circuits (ASICs), application specific standard products (ASSPs), system-on-chip systems (SOCs), programmable logic devices (CPLDs), computer hardware, firmware, software, and / or combinations thereof. These various embodiments can include being implemented in one or more computer programs that are executable and / or interpreted on a programmable system that includes at least one programmable processor, which can be a special purpose or general purpose programmable processor that can receive data and instructions from a storage system, at least one input device, and at least one output device, and transmit data and instructions to the storage system, the at least one input device, and the at least one output device.
[0108] Computer programs for implementing the methods of the present invention may be written in any combination of one or more programming languages. These computer programs may be provided to a processor of a general-purpose computer, a special-purpose computer, or other programmable data processing device, such that when the computer program is executed by the processor, the functions / operations specified in the flowcharts and / or block diagrams are implemented. The computer program may be executed entirely on the machine, partially on the machine, as a stand-alone software package, partially on the machine and partially on a remote machine, or entirely on a remote machine or server.
[0109] In the context of the present invention, computer-readable storage media can be tangible media that can contain or store a computer program for use with an instruction execution system, device or equipment or used in combination with an instruction execution system, device or equipment. Computer-readable storage media can include but are not limited to electronic, magnetic, optical, electromagnetic, infrared or semiconductor systems, devices or equipment, or any suitable combination of the foregoing. Alternatively, computer-readable storage media can be machine-readable signal media. More specific examples of machine-readable storage media can include electrical connections based on one or more lines, portable computer disks, hard disks, random access memories (RAM), read-only memories (ROM), erasable programmable read-only memories (EPROM or flash memory), optical fibers, portable compact disk read-only memories (CD-ROM), optical storage devices, magnetic storage devices, or any suitable combination of the foregoing.
[0110] To provide interaction with a user, the systems and techniques described herein can be implemented in a vehicle having: a display device (e.g., a CRT (cathode ray tube) or LCD (liquid crystal display) monitor) for displaying information to the user; and a keyboard and pointing device (e.g., a mouse or trackball) through which the user can provide input to the vehicle. Other types of devices can also be used to provide interaction with the user; for example, the feedback provided to the user can be any form of sensory feedback (e.g., visual feedback, auditory feedback, or tactile feedback); and input from the user can be received in any form (including acoustic input, voice input, or tactile input).
[0111] The systems and techniques described herein can be implemented in a computing system that includes back-end components (e.g., as a data server), or a computing system that includes middleware components (e.g., an application server), or a computing system that includes front-end components (e.g., a user computer with a graphical user interface or web browser through which a user can interact with implementations of the systems and techniques described herein), or a computing system that includes any combination of such back-end components, middleware components, or front-end components. The components of the system can be interconnected by any form or medium of digital data communication (e.g., a communication network). Examples of communication networks include: a local area network (LAN), a wide area network (WAN), a blockchain network, and the Internet.
[0112] A computing system may include clients and servers. The clients and servers are typically remote from each other and typically interact via a communication network. This client-server relationship arises through computer programs running on the respective computers, creating a client-server relationship. The server may be a cloud server, also known as a cloud computing server or cloud host. This server is a hosting product within the cloud computing service ecosystem that addresses the management difficulties and limited scalability of traditional physical hosting and VPS services.
[0113] It should be understood that the various forms of the processes shown above can be used to reorder, add, or delete steps. For example, the steps described in the present invention can be performed in parallel, sequentially, or in a different order, as long as the desired results of the technical solution of the present invention can be achieved. This is not limited herein.
[0114] The above specific embodiments do not limit the scope of protection of the present invention. Those skilled in the art will appreciate that various modifications, combinations, sub-combinations, and substitutions may be made based on design requirements and other factors. Any modifications, equivalent substitutions, and improvements made within the spirit and principles of the present invention are intended to be included within the scope of protection of the present invention.
Claims
1. A method for deriving safety requirements for automatic parking, characterized in that: include: An automatic parking control system based on a predefined function determines first unsafe behavior information output by the automatic parking control system in a current automatic parking scenario; Determining second unsafe behavior information by applying safety analysis keywords based on the first unsafe behavior information, and determining invalid unsafe behavior information based on the second unsafe behavior information in combination with the current automatic parking scenario; Performing a vehicle hazard analysis based on the unsafe failure behavior information to determine safety hazard events in the current automatic parking scenario; Forming safety requirements of the automatic parking control system in the current automatic parking scenario based on the triggering event and constraint conditions of the hazardous event; The safety requirements of the automatic parking control system in the current automatic parking scenario are formed based on the triggering event and constraints of the hazardous event, including: determining the triggering event and constraints of the hazardous event based on the environmental perception, decision-making and control, drive-by-wire chassis, and human-computer interaction in the automatic driving system, and forming the safety requirements of the automatic parking control system in the current automatic parking scenario. The safety requirements include the autonomous driving function of perception in environmental perception, obstacle deviation detection and determination of fusion execution information, decision execution information in decision-making and control, transmission control information and execution information in the drive-by-wire chassis, and driver behavior information in human-computer interaction. The autonomous driving function of perception in environmental perception includes whether the automatic driving system has the ability to identify and determine ODDs; obstacle deviation detection includes whether a decision is required after detecting obstacle deviations; and fusion execution information includes whether there is a collision risk. The decision execution information in decision-making and control includes determining the execution status of the current parking decision. The transmission control information in the drive-by-wire chassis includes communication protection and communication execution status, and the execution information includes verification of the rationality of instruction execution. The driver behavior information in human-computer interaction includes confirmation of driver behavior information.
2. The method for deriving automatic parking safety requirements according to claim 1, characterized in that: The automatic parking control system with predefined functions includes a sensor detection module, an actuator, and an automatic parking function module; the automatic parking function module includes a perception fusion unit, a perception processing unit, a planning unit, and a control unit. The perception fusion unit is used to obtain real-time parking behavior information collected by the sensor detection module; the planning unit is used to plan the current automatic parking scenario based on the real-time parking behavior information; the perception processing unit is used to collect sudden parking behavior information collected by the sensor detection module; the control unit is used to generate execution control information based on the planning of the current automatic parking scenario by the planning unit and the sudden parking behavior information; the actuator is used to execute the automatic parking behavior in the current automatic parking scenario based on the execution control information.
3. The method for deriving automatic parking safety requirements according to claim 2, characterized in that: Determining first unsafe behavior information output by the automatic parking control system in a current automatic parking scenario includes: determining whether a sensor detection module, an actuator, and an automatic parking function module included in the automatic parking control system are faulty in a current automatic parking scenario; First unsafe behavior information is generated according to a result of determining whether a failure occurs.
4. The method for deriving automatic parking safety requirements according to claim 1, characterized in that: The current automatic parking scenario includes the current parking direction, actual parking space information, and current parking status information; Determining failure unsafe behavior information based on the second unsafe behavior information in combination with the current automatic parking scenario includes: Invalid unsafe behavior information is determined according to the second unsafe behavior information in combination with the current parking direction, the actual parking space information, and the current parking state information.
5. The method for deriving automatic parking safety requirements according to claim 1, characterized in that: Perform a vehicle hazard analysis based on the unsafe failure behavior information to determine safety hazard events in the current automatic parking scenario, including: Based on the environmental perception, decision-making and control, wire-controlled chassis and human-computer interaction in the autonomous driving system, the vehicle hazard analysis is conducted on the unsafe failure behavior information to determine the safety hazard events in the current automatic parking scenario.
6. An automatic parking safety requirement derivation device, characterized in that: include: a first unsafe behavior information determining module, configured to execute an automatic parking control system based on a predefined function and determine first unsafe behavior information output by the automatic parking control system in a current automatic parking scenario; a failed unsafe behavior information determination module, configured to determine second unsafe behavior information by applying a safety analysis keyword based on the first unsafe behavior information, and determine failed unsafe behavior information based on the second unsafe behavior information in combination with the current automatic parking scenario; a safety hazard event determination module, configured to perform a vehicle hazard analysis based on the unsafe behavior information and determine a safety hazard event in the current automatic parking scenario; a safety requirement forming module, configured to form safety requirements of the automatic parking control system in a current automatic parking scenario based on the triggering event and constraint conditions of the hazardous event; Among them, the safety requirement formation module is specifically used to: determine the triggering events and constraints of the hazardous events based on the environmental perception, decision-making and control, wire-controlled chassis and human-computer interaction in the automatic driving system, and form the safety requirements of the automatic parking control system in the current automatic parking scenario. The safety requirements include the perception automatic driving function in the environmental perception, detection of obstacle deviation and determination of fusion execution information, decision execution information in the decision-making and control, transmission control information and execution information in the wire-controlled chassis, and driver behavior information in the human-computer interaction; wherein, the perception automatic driving function in the environmental perception is whether the automatic driving system has ODD recognition and judgment capabilities, detection of obstacle deviation is whether a decision is required after detecting obstacle deviation, and determination of fusion execution information is whether there is a collision risk; decision execution information in decision-making and control is determination of the current parking decision execution status; transmission control information in the wire-controlled chassis is communication protection and communication execution status, execution information is execution instruction rationality verification; driver behavior information in human-computer interaction is driver behavior information confirmation.
7. A vehicle, characterized in that: The vehicle comprises: at least one processor; and, a memory communicatively connected to the at least one processor; wherein, The memory stores a computer program executable by the at least one processor, and the computer program is executed by the at least one processor so that the at least one processor can execute the automatic parking safety requirement derivation method according to any one of claims 1 to 5.
8. A computer-readable storage medium, characterized in that The computer-readable storage medium stores computer instructions, and the computer instructions are used to enable a processor to implement the automatic parking safety requirement derivation method according to any one of claims 1 to 5 when executed.
Citation Information
Patent Citations
Vehicle safety management method, device and system, and storage medium
CN112498337A
Automatic parking method, device and equipment and storage medium
CN115782863A