Fault processing method for autonomous driving, driving device, and computer-readable storage medium

By detecting the failure type and speed of functional modules to determine the failure level, the autonomous driving system can perform corresponding actions for different faults, solving the problem of insufficient reliability and safety of existing autonomous driving systems when dealing with multiple faults, and achieving higher safety and intelligence.

CN117341713BActive Publication Date: 2025-10-17BYD CO LTD
View PDF 2 Cites 0 Cited by

Patent Information

Application Number
CN202210741673.7
Authority / Receiving Office
CN · China
Patent Type
Patents(China)
Current Assignee / Owner
Filing Date
2022-06-28
Publication Date
2025-10-17
Estimated Expiration
2042-06-28

AI Technical Summary

Technical Problem

Existing autonomous driving systems are unable to respond effectively to different types of malfunctions, resulting in insufficient reliability and safety of autonomous vehicles.

Method used

By detecting the failure type of the functional module and the speed of the driving device, the failure level is determined, and corresponding fault response actions are executed according to the failure level, including maintaining the original driving state, downgrading the level of automatic driving, pulling over to the side of the road, slowing down and stopping, and emergency avoidance.

Benefits of technology

It improves the safety and intelligence of autonomous driving systems when facing various faults, ensuring the reliability and safety of the driving process.

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure CN117341713B_ABST
    Figure CN117341713B_ABST
Patent Text Reader

Abstract

The application discloses a fault processing method of automatic driving, which is applied to a driving device and comprises the following steps: detecting that a functional module is invalid; determining a current invalid level according to an invalid level of the functional module, a driving function provided by the functional module and a speed of the driving device; and controlling the driving device to perform a corresponding fault response action according to the invalid level. The fault processing method of automatic driving disclosed by the application enables the automatic driving device to determine the invalid level according to the invalid functional module and the current driving speed, and to make different safe driving actions according to the invalid level, thereby improving the safety of the driving device. The application also comprises a driving device and a computer readable storage medium for implementing the aforementioned fault processing method of automatic driving.
Need to check novelty before this filing date? Find Prior Art

Description

TECHNICAL FIELD

[0001] The present application relates to the technical field of automatic driving, in particular to an automatic driving fault processing method, a driving device and a computer readable storage medium. BACKGROUND

[0002] Automatic driving has been greatly developed due to its advantages of saving labor cost, reducing accident rate and reducing fuel consumption. With the development of various vehicle sensor technologies and artificial intelligence technologies, automatic driving technology is becoming more and more commercialized. However, due to the complexity of road scenes, there are very high requirements for automatic driving vehicles, and the best response scheme needs to be made as much as possible for different situations, so that the automatic driving vehicle has higher reliability and safety.

[0003] At present, the response scheme of the automatic driving vehicle for different faults and different vehicle speeds at different faults is single, and it is impossible to make more reasonable and targeted automatic driving actions for multiple faults. SUMMARY

[0004] In view of the above shortcomings of the prior art, the present application provides an automatic driving fault processing method with strong fault pertinence, which is applied to a driving device. The driving device includes a plurality of function modules, and the function modules are used to provide corresponding driving functions for the driving device. The automatic driving fault processing method includes: detecting that a function module is invalid, determining a current failure level according to a failure type of the function module, a driving function corresponding to the function module and a speed of the driving device, and controlling the driving device to perform a corresponding fault response action according to the failure level.

[0005] Optionally, the driving device is preconfigured and stores a failure level table, and the failure level table includes a corresponding relationship between a failure type of the function module, a driving function corresponding to the function module, a speed of the driving device and a failure level. The current failure level is determined according to the failure type of the function module, the driving function corresponding to the function module and the speed of the driving device, which includes: when detecting that any one of the function modules is invalid, determining the current failure level of the driving device in the failure level table according to the failure type of the function module, the driving function corresponding to the invalid function module and the current speed of the driving device.

[0006] Optionally, detecting that the function module is invalid includes: detecting that a plurality of function modules are invalid; and determining the current failure level according to the failure type of the function module, the driving function corresponding to the function module and the speed of the driving device includes: determining a plurality of failure levels in a plurality of failure level tables corresponding to the plurality of function modules according to the failure types of the plurality of function modules, the driving functions provided by the invalid function modules and the current speed of the driving device, and taking the highest level of the plurality of failure levels as the current failure level of the driving device.

[0007] Optionally, determining the current failure level according to the failure type of the functional module, the driving function provided by the functional module, and the speed of the driving device comprises: if the map function module communication fails, determining whether the map provided by the map function module has been updated, if the map has been updated, determining the first failure level in the failure level table as the current failure level; if the map has not been updated, determining the second failure level in the failure level table as the current failure level. Controlling the driving device to perform the corresponding fault handling action according to the failure level comprises: controlling the driving device to maintain the original automatic driving state according to the first failure level, or controlling the driving device to reduce the automatic driving level according to the second failure level, so that the speed of the driving device is reduced from the first speed range to the second speed range or from the second speed range to the third speed range, wherein the lowest speed in the first speed range is greater than the highest speed in the second speed range, and the lowest speed in the second speed range is greater than the highest speed in the third speed range.

[0008] Optionally, determining the current failure level according to the failure type of the functional module, the driving function provided by the functional module, and the speed of the driving device comprises: if the decision planning function module communication or algorithm fails, and the speed of the driving device is in the second speed range, determining the third failure level in the failure level table as the current failure level, if the decision planning function module communication or algorithm fails, and the speed of the driving device is in the third speed range, determining the fourth failure level in the failure level table as the current failure level, if the decision planning function module communication or algorithm fails, and the speed of the driving device is in the first speed range, determining the fifth failure level in the failure level table as the current failure level. Controlling the driving device to perform the corresponding fault handling action according to the failure level further comprises: controlling the driving device to perform the side parking according to the third failure level, or controlling the driving device to perform the speed reduction in the current lane according to the fourth failure level, or controlling the driving device to enter the safety emergency area for emergency avoidance according to the fifth failure level.

[0009] Optionally, the fault handling method further comprises: when it is detected that the driving function provided by the failed functional module is the first driving function, controlling the functional module having the first driving function in the plurality of normally operating functional modules to perform the first driving function of the driving device; determining the current failure level according to the failure type of the functional module, the driving function provided by the functional module, and the speed of the driving device comprises: determining the current failure level in the failure level table according to the type of the failed functional module, the type of the functional module currently performing the first driving function, the failure type of the functional module, the first driving function, and the speed of the driving device.

[0010] Optionally, the first driving function is an obstacle perception function, and the functional module having the obstacle perception function in the driving device comprises a camera, a laser radar, a millimeter wave radar and an ultrasonic radar. The determining the current failure level in the failure level table according to the type of the failed functional module, the type of the functional module currently executing the first driving function, the failure type of the functional module, the first driving function and the speed of the driving device comprises: if the laser radar, the ultrasonic radar and the camera are communication failures, the functional module currently executing the obstacle perception function is the millimeter wave radar, and the speed of the driving device is in a first speed range, then a second failure level in the failure level table is determined as the current failure level. The controlling the driving device to execute a corresponding fault response action according to the failure level comprises: controlling the driving device to execute a degraded automatic driving according to the second failure level, so that the speed of the driving device is reduced from the first speed range to a second speed range.

[0011] Optionally, the first driving function is an obstacle perception function, and the functional module having the obstacle perception function in the driving device comprises a camera, a laser radar, a millimeter wave radar and an ultrasonic radar.

[0012] The determining the current failure level in the failure level table according to the type of the failed functional module, the type of the functional module currently executing the first driving function, the failure type of the functional module, the first driving function and the speed of the driving device comprises: if the camera, the laser radar and the millimeter wave radar are communication failures, then a sixth failure level in the failure level table is determined as the current failure level. The controlling the driving device to execute a corresponding fault response action according to the failure level further comprises: controlling the driving device to use the driving data before the failure and to exit the automatic driving and prompt the driver to take over within a preset time period according to the sixth failure level.

[0013] Optionally, the first driving function is a positioning function, the functional modules with the positioning function in the driving device include an inertial navigation unit, a GPS unit, a camera and a laser radar; and the determining the current failure level in the failure level table according to the type of the failed functional module, the type of the functional module currently executing the first driving function, the failure type of the functional module, the first driving function and the speed of the driving device includes: if the inertial navigation unit, the GPS unit and the camera communication fail, the functional module currently executing the positioning function is the laser radar, and the speed of the driving device is within a first speed range, then the fifth failure level in the failure level table is determined as the current failure level; if the inertial navigation unit, the GPS unit and the camera communication fail, the functional module currently executing the positioning function is the laser radar, and the speed of the driving device is within a second speed range, then the third failure level in the failure level table is determined as the current failure level; and if the inertial navigation unit, the GPS unit and the camera communication fail, the functional module currently executing the positioning function is the laser radar, and the speed of the driving device is within a third speed range, then the first failure level in the failure level table is determined as the current failure level. The controlling the driving device to execute the corresponding fault response action according to the failure level includes: controlling the driving device to enter a safety emergency area for emergency avoidance according to the fifth failure level, or controlling the driving device to execute side parking according to the third failure level, or controlling the driving device to keep the original automatic driving state for driving according to the first failure level.

[0014] Optionally, the functional modules with the positioning function in the driving device further include an ultrasonic radar. The determining the current failure level in the failure level table according to the type of the failed functional module, the type of the functional module currently executing the first driving function, the failure type of the functional module, the first driving function and the speed of the driving device includes: if the inertial navigation unit, the GPS unit, the laser radar and the camera communication fail, the functional module currently executing the positioning function is the ultrasonic radar, and the speed of the driving device is within the first speed range or within the second speed range, then the sixth failure level in the failure level table is determined as the current failure level; and if the inertial navigation unit, the GPS unit, the laser radar and the camera communication fail, the functional module currently executing the positioning function is the ultrasonic radar, and the speed of the driving device is within the third speed range, then the first failure level in the failure level table is determined as the current failure level. The controlling the driving device to execute the corresponding fault response action according to the failure level further includes: controlling the driving device to continue using the driving data before the failure, and exiting the automatic driving and prompting the driver to take over within a preset time period according to the sixth failure level, or controlling the driving device to keep the original automatic driving state for driving according to the first failure level.

[0015] The present application also discloses a driving device including a processor and a memory, wherein the memory stores a computer program, and when the processor executes the computer program, the aforementioned automatic driving fault handling method is implemented.

[0016] The present application also discloses a computer-readable storage medium, which stores a computer program. The computer program includes program instructions. When the program instructions are executed by a processor, the processor executes the aforementioned autonomous driving fault handling method.

[0017] Compared with the existing technology, the autonomous driving method disclosed in the embodiment of the present application can monitor the communication nodes and algorithm nodes of different modules in the functional module in real time, so as to effectively detect and identify the location and cause of the fault. At the same time, it can determine different failure levels according to the type of failed module and the current speed of the driving device, and perform different fault handling actions according to the failure level, making the driving device safer and more intelligent during driving. BRIEF DESCRIPTION OF THE DRAWINGS

[0018] In order to more clearly illustrate the technical solutions in the embodiments of the present application, the following briefly introduces the drawings required for use in the embodiments. Obviously, the drawings described below are some embodiments of the present application. For ordinary technicians in this field, other drawings can be obtained based on these drawings without creative work.

[0019] Figure 1 This is a block diagram of a driving device disclosed in the first embodiment of the present application;

[0020] Figure 2 for Figure 1 Schematic diagram of the functional modules of the driving device;

[0021] Figure 3 A flowchart of a method for troubleshooting an autonomous driving system according to the second embodiment of the present application;

[0022] Figure 4 for Figure 2 Schematic diagram of the distribution of communication nodes of each functional module;

[0023] Figure 5 for Figure 4 Schematic diagram of the distribution of algorithm nodes in each functional module;

[0024] Figure 6 for Figure 5 Schematic diagram of the relationship between communication nodes and algorithm nodes in each functional module;

[0025] Figure 7 for Figure 4 Flowchart of the troubleshooting method for communication failure of the perception function module;

[0026] Figure 8 For Figure 4 Fault handling method flow chart of communication node failure of middle function module

[0027] Figure 9 For Figure 5 Fault handling method flow chart of algorithm node failure of middle function module DETAILED DESCRIPTION

[0028] In order to facilitate the understanding of the present application, the present application will be described in more detail below with reference to the relevant drawings. The preferred embodiments of the present application are shown in the drawings. However, the present application can be implemented in many different forms, and is not limited to the embodiments described herein. On the contrary, the purpose of providing these embodiments is to make the disclosure of the present application more thorough and comprehensive.

[0029] The following description of the embodiments is made with reference to the accompanying drawings, which illustrate specific embodiments in which the present application can be implemented. The serial numbers of the components in the text, such as "first", "second", etc., are only used to distinguish the described objects, and do not have any sequential or technical meaning. The "connection" and "coupling" mentioned in the present application, unless otherwise specified, include direct and indirect connection (coupling). The direction terms mentioned in the present application, such as "up", "down", "front", "back", "left", "right", "inside", "outside", "side", etc., are only the direction of the attached drawings, therefore, the direction terms used are for better, clearer description and understanding of the present application, and are not indicative or implied that the device or element referred to must have a particular orientation, be constructed and operated in a particular orientation, therefore, it cannot be understood as a limitation on the present application.

[0030] In the description of the present application, it should be noted that, unless otherwise explicitly specified and limited, the terms "mounting", "connection", "coupling" should be understood broadly, for example, it can be fixedly connected, or it can be detachably connected, or integrally connected; it can be mechanically connected; it can be directly connected, or indirectly connected through an intermediate medium; it can be the internal communication of two elements. For those skilled in the art, the specific meaning of the above terms in the present application can be understood according to the specific circumstances. It should be noted that the terms "first", "second", etc. in the specification and claims of the present application and the drawings are used to distinguish different objects, and are not used to describe a specific order.

[0031] Further, the terms "include", "may include", "comprise", or "may comprise" used in the present application indicate the presence of the corresponding function, operation, element, etc. disclosed in the specification, and do not limit other one or more functions, operations, elements, etc. Further, the terms "include" or "comprise" indicate the presence of the corresponding feature, number, step, operation, element, component, or combination thereof disclosed in the specification, and do not exclude the presence or addition of one or more other features, numbers, steps, operations, elements, components, or combinations thereof, and are intended to cover non-exclusive inclusion. Further, when describing embodiments of the present application, "may" is used to indicate "one or more embodiments of the present application". Also, the term "exemplary" is intended to mean example or illustrative.

[0032] Unless otherwise defined, all technical and scientific terms used herein have the same meaning as commonly understood by one of ordinary skill in the art to which the present application belongs. The terminology used in the description of the present application herein is for the purpose of describing particular embodiments only and is not intended to be limiting of the present application.

[0033] Referring to Figure 1 , Figure 1 is a block schematic diagram of a driving device disclosed in the first embodiment of the present application. As shown in Figure 1 , the driving device 1 comprises a memory 10 and a processor 20. The memory 10 stores a computer program, and the processor 20 can execute the computer program in the memory 10 to control the driving device 1 to perform self-driving and corresponding fault handling methods.

[0034] Referring to Figure 2 , Figure 2 is a functional module schematic diagram of the driving device in Figure 1 . As shown in Figure 2 , the driving device 1 comprises a functional module 100 and a safety monitoring module 200, the functional module 100 is used to provide sensing, positioning and route planning functions for the driving device 1, and the safety monitoring module 200 is used to perform real-time detection on each functional module in the functional module 100.

[0035] The functional module 100 comprises a perception module 101, a positioning module 102, a map module 103, a navigation module 104, a prediction module 105, a decision planning module 106, a control module 107, and a Controller Area Network (CAN) bus 108.

[0036] The perception module 101 provides various sensor signals to the driving device 1, while the mapping module 103 provides a high-resolution map for the driving device 1 during driving, ensuring high real-time performance and accuracy. The positioning module 102 accurately locates the current position of the driving device 1. The navigation module 104 integrates data from the perception module 101, mapping module 103, and positioning module 102 to provide an optimal driving route for the driving device 1. The prediction module 105 predicts the interaction between the driving device 1 and other moving objects in the surrounding environment based on the sensor signals provided by the perception module 101. The decision-making and planning module 106 determines the final driving path of the driving device 1 based on the optimal route data provided by the navigation module 104 and the driving environment data provided by the prediction module 105. The control module 107 controls the driving device 1 to automatically drive along the optimal route based on the optimal route data provided by the decision-making and planning module 106. The CAN bus 108 transmits various data within the driving device 1.

[0037] The security monitoring module 200 includes a monitoring module 201 and a human-machine interface 202. The monitoring module 201 monitors the operating status of each module, its communication nodes, and its algorithm nodes, and provides corresponding response plans based on failure conditions. The human-machine interface 202 provides a user interface for viewing the operating status of each module in the functional module 100 and facilitating user control.

[0038] Specifically, the perception module 101 includes a variety of vehicle-mounted sensors for providing various sensing signals to the driving device 1, such as cameras, millimeter-wave radars, laser radars, ultrasonic radars, hardware synchronization, sensor calibration, and computer vision.

[0039] Compared to conventional electronic navigation maps, map module 103 is a thematic map serving the driving device 1, representing a new map data paradigm for autonomous vehicles. Map module 103 boasts an absolute position accuracy approaching 1 meter and a relative position accuracy at the centimeter level. Maps can be divided into two layers: static maps and dynamic maps. The static map, at the bottom layer, consists of three types of vector information: lane models, road components, and road attributes, along with feature layers for multi-sensor positioning. The dynamic map, built on top of the static map, primarily includes real-time dynamic information, including information about other traffic participants and signals from traffic objects.

[0040] The positioning module 102 is used to locate the current position of the driving device 1, mainly including a global navigation satellite system (GNSS) and an inertial navigation system (INS), and provides positioning function for the driving device 1 in combination with the related data provided by the perception module 101 and the map module 103.

[0041] The navigation module 104 is used to comprehensively process the vehicle information and environmental information provided by the perception module 101, the map module 103 and the positioning module 102, and calculate the shortest driving path or the optimal driving path of the driving device 1.

[0042] The prediction module 105 is used to solve the problem of cooperative interaction between the automatic driving vehicle and other moving objects (vehicles, pedestrians, etc.) in the surrounding environment. The module predicts the behavior intention of the moving object detected by the perception module within a future period of time, and converts the prediction result into a time dimension and a space dimension trajectory. With the predicted trajectory of the moving objects such as obstacle vehicles, pedestrians and non-motor vehicles as input, the automatic driving vehicle can make more reasonable driving decisions and plan more reasonable and safe vehicle movement behaviors.

[0043] The decision planning module 106 includes three levels, first, receiving the optimal global path calculated by the navigation module 104. Then make specific behavior decisions in combination with the perception module 101. (Including other vehicles, pedestrians, obstacles and traffic rule information on the road, such as choosing to change lanes or follow) Finally, the motion planning (Motion Planning) layer plans to generate a trajectory that meets specific constraint conditions according to the specific behavior decision, which is used as the input of the control module to determine the final driving path of the vehicle. (Such as the dynamics constraints of the vehicle itself, collision avoidance, passenger comfort, etc.)

[0044] The control module 107 is used to process more detailed things according to various perception signals. For example, a pit on the road surface causes the vehicle to roll, the smoothness of the throttle and brake, the control convergence under various environmental disturbances, the accuracy, stability and rapidity of trajectory tracking, etc.

[0045] The CAN bus is used to provide the functions of mutual communication and state reading for the aforementioned various modules.

[0046] The monitoring module 201 is used to monitor the working state of the communication nodes and algorithm nodes of various functional modules, and provide corresponding solutions according to the failure state. For example, providing corresponding solutions when various functional modules fail, providing corresponding solutions when various functional module communication nodes fail, and providing corresponding solutions when various module algorithm nodes fail, etc.

[0047] The human-computer interface 202 provides a human-computer interaction interface for the user to read the running conditions of the modules in the functional module 100 and to facilitate the user to control.

[0048] Referring to Figure 3 , Figure 3 A flow chart of a fault processing method of autonomous driving is provided for the second embodiment of the present application. As shown in Figure 3 , the specific steps of the fault processing method of autonomous driving are as follows:

[0049] Step S101, detecting that a functional module is failed.

[0050] The safety monitoring module 200 monitors the communication nodes and algorithm nodes of each functional module in real time to determine whether a fault occurs in each functional module.

[0051] Specifically, referring to Figure 4 , Figure 4 for Figure 2 the distribution of the communication nodes of each functional module, as shown in Figure 4 , the communication nodes are distributed in each functional module and each sensor, and the monitoring module 201 in the safety monitoring module 200 can monitor the communication state of each module through each communication node.

[0052] Specifically, the functional module 100 further includes four perception sensors and two positioning sensors, wherein the four perception sensors are a first sensor 101A, a second sensor 101B, a third sensor 101C, and a fourth sensor 101D, the first sensor 101A to the fourth sensor 101D correspond to a first communication node T1 to a fourth communication node T4 respectively, and the perception module 101 is provided with a fifth communication node T5. The perception module 101 receives various sensing signals through the first sensor 101A to the fourth sensor 101D, and the first sensor 101A to the fourth sensor 101D can be a camera, a millimeter wave radar, a laser radar, and an ultrasonic radar respectively. The monitoring module 201 monitors the communication state of the first sensor 101A to the fourth sensor 101D through the first communication node T1 to the fourth communication node T4.

[0053] In the exemplary embodiment, the perception module can include any number of sensors for providing sensing signals for the perception module 101, which is not limited by the present application.

[0054] The two positioning sensors are an inertial navigation unit 102A and a global positioning system (GPS) unit 102B. A sixth communication node T6 is provided in the inertial navigation unit 102A, a seventh communication node T7 is provided in the GPS unit, and an eighth communication node T8 is provided in the positioning module 102 itself. The positioning module 102 performs real-time positioning of the driving device 1 through the inertial navigation unit 102A and the GPS unit 102B, and the monitoring module 201 monitors the communication status of the positioning module 102, the inertial navigation unit 102A, and the GPS unit 102B in real time through the sixth communication node T6 to the eighth communication node T8 provided therein.

[0055] The map module 103, navigation module 104, prediction module 105, decision-making and planning module 106, control module 107, and CAN bus 108 correspond to the ninth through fourteenth communication nodes T9, T14, respectively. In the security monitoring module 200, the monitoring module 201 and the human-machine interface 202 correspond to the fifteenth and sixteenth communication nodes T15, T16, respectively. The fifteenth communication node T15 corresponding to the monitoring module 201 is connected to the corresponding communication nodes of each module in the functional module 100. The monitoring module 201 monitors the communication status of the navigation module 104, prediction module 105, decision-making and planning module 106, control module 107, and CAN bus 108 via the ninth through fourteenth communication nodes T9, T14, respectively.

[0056] See also Figure 5 , Figure 5 for Figure 4 Schematic diagram of the distribution of algorithm nodes of each functional module, such as Figure 5 As shown, the algorithm nodes are distributed in various functional modules and various sensors. The monitoring module 201 in the security monitoring module 200 can monitor the algorithm running status of each module through each algorithm node.

[0057] Specifically, the perception module 101, positioning module 102, mapping module 103, navigation module 104, prediction module 105, decision-making and planning module 106, control module 107, and CAN bus 108 in the functional module 100 are each provided with a first algorithm node S1 to an eighth algorithm node S8. In the security monitoring module 200, the monitoring module 201 and the human-machine interface 202 are each provided with a ninth algorithm node S9 and a tenth algorithm node S10. The ninth algorithm node S9 is connected to the algorithm nodes corresponding to each module in the functional module 100, and the monitoring module 201 monitors the algorithm operation status of the perception module 101, positioning module 102, mapping module 103, navigation module 104, prediction module 105, decision-making and planning module 106, control module 107, and CAN bus 108 via the first algorithm node S1 to the eighth algorithm node S8.

[0058] See also Figure 6 , Figure 6 for Figure 5 Schematic diagram of the relationship between communication nodes and algorithm nodes in each functional module, as shown in Figure 5 As shown, the communication nodes and algorithm nodes of each functional module in the driving device 1 are separately configured and communicate through multi-threading. In other words, each functional module includes both a communication node and an algorithm node, and the communication nodes and algorithm nodes communicate through multi-threading. The monitoring module 201 monitors the algorithm nodes of each module to ensure that the algorithm of each module is functioning properly.

[0059] Furthermore, since the communication nodes and the algorithm nodes are separately provided, the monitoring module 201 can monitor the communication nodes and the algorithm nodes simultaneously or monitor separate types of nodes separately, for example, monitoring the communication nodes alone or the algorithm nodes alone.

[0060] Please continue reading Figure 3 , step S102, determining the current failure level according to the failure type of the functional module, the driving function provided by the functional module, and the speed of the driving device.

[0061] Specifically, a failure level table is pre-set and stored within the driving device 1. This table includes a correspondence between the failure type of a functional module, the driving function provided by the functional module, the speed of the driving device 1, and the failure level. In this embodiment, as shown in Table 1-1, the failure level table includes six failure levels, FL-A, from the first failure level to the sixth failure level, FL-F. The failure levels increase in order from FL-A to FL-F, with higher failure levels indicating a greater impact of the failed module or node on the normal operation of the driving device 1.

[0062] The driving device 1 is provided with an automatic driving speed range, including a first speed range V1, a second speed range V2 and a third speed range V3, wherein the lowest speed in the first speed range V1 is greater than the highest speed in the second speed range V2, and the lowest speed in the second speed range V2 is greater than the highest speed in the third speed range V3.

[0063] In an exemplary embodiment, the first speed range can be set to be higher than 60KM / H, the second speed range can be set to 20-60KM / H, and the third speed range can be set to be lower than 20KM / H. Of course, it can also be adjusted to other speed ranges based on specific needs, and this application does not limit it.

[0064] When the communication node and / or the algorithm node of any one of the functional modules 100 fails, according to the failure type of the functional module, the driving function provided by the failed functional module, and the current speed of the driving device 1, the current failure level of the driving device is determined in the failure level table.

[0065] For example, when the sensor in the perception module 101 fails, such as the communication of the camera or the millimeter wave radar or the laser radar fails, the influence on the perception is not great no matter the speed of the driving device 1 at this time, and the failure level is the first failure level FL-A. However, if the communication of the camera and the laser radar both fails, at this time, since the millimeter wave radar and the ultrasonic radar are difficult to perceive the size of the surrounding obstacles, if the speed of the driving device 1 is within the first speed range V1, the monitoring module 201 evaluates the failure level and the failure level is correspondingly promoted, for example, the failure level is promoted to the second failure level FL-B. When multiple functional modules fail, according to the failure type of the multiple functional modules, the driving function provided by the failed functional modules, and the current speed of the driving device 1, multiple failure levels in the failure level table corresponding to the multiple functional modules are determined, and the highest failure level in the multiple failure levels is taken as the current failure level of the driving device. For example, when the communication of the perception module 101, the prediction module 105, and the control module 107 fails, the corresponding failure levels are the first failure level FL-A, the second failure level FL-B, and the sixth failure level FL-F, respectively. At this time, the sixth failure level FL-F is the current failure level, and the driving device 1 is controlled to execute the preset failure response action of exiting the automatic driving within a preset time period and prompting the driver to take over.

[0066] In step S103, the driving device is controlled to execute the corresponding failure response action according to the failure level.

[0067] For different failure levels, corresponding failure response actions are set, and when the current failure level is determined, the driving device is controlled to execute the corresponding failure response action.

[0068] As shown in Table 1-1, when the monitoring module 201 evaluates that the current failure level is the first failure level FL-A, the driving device 1 keeps the original automatic driving device to travel, indicating that the failed node or module at this time has little influence on the current normal automatic driving.

[0069] When the monitoring module 201 evaluates that the current failure level is the second failure level FL-B, the driving device 1 reduces the automatic driving level, indicating that the failed node or module at this time has a certain influence on the current normal automatic driving, and the driving device 1 needs to reduce the current driving speed, so that the speed of the driving device is reduced from the first speed range V1 to the second speed range V2 or from the second speed range V2 to the third speed range V3.

[0070] When the monitoring module 201 evaluates that the current failure level is the third failure level FL-C, the driving device 1 is parked on the side, indicating that the failed node or module at this time has failed to ensure the safety of the automatic driving of the driving device 1, and needs to be parked on the side.

[0071] When the monitoring module 201 evaluates that the current failure level is the fourth failure level FL-D, the fifth failure level FL-E and the sixth failure level FL-F, it indicates that the driving device 1 at this time has failed to safely control the driving device 1 to travel safely, and according to the current specific vehicle speed, the control scheme of lane deceleration parking, emergency avoidance in safety emergency area and manual takeover is respectively executed. When the safety monitoring module 200 determines that the current failure level is lower than the second failure level FL-B, the fault handling method corresponding to the subsequent failure level is executed, and the double flash is started at the same time, and if it involves parking, the P gear is engaged and the electronic parking brake (EPB) is pulled up.

[0072] In an exemplary embodiment, the failure level corresponding to the fault handling method of the functional module can also be set according to specific circumstances, which is not limited in the present application.

[0073] Table 1-1

[0074] Failure level Failure handling action FL-A Continue to maintain original autonomous driving FL-B Downgrade autonomous driving FL-C Pull over to the side of the road FL-D Slow down and stop in the current lane FL-E Emergency avoidance in the safety emergency area FL-F Manual takeover

[0075] Please refer to Figure 7 , Figure 7 For Figure 4 the fault handling method flow chart of the communication failure of the perception type functional module.

[0076] Specifically, as Figure 7 shown, when it is detected that the driving function provided by the failed functional module is the first driving function, the functional module having the first driving function in the plurality of normally operating functional modules is controlled to execute the first driving function of the driving device 1. When the monitoring module 201 in the safety monitoring module 200 detects the communication node failure of the sensor in the functional module, the specific fault handling method is as follows:

[0077] Step S201, detecting the communication failure of the functional module having the obstacle perception function and / or the functional module having the positioning function.

[0078] The monitoring module 201 in the safety monitoring module 200 performs real-time monitoring on the four perception sensors in the perception module 101 having the obstacle perception function, i.e. the first sensor 101A to the fourth sensor 101D, and the positioning sensors in the positioning module 102 having the positioning function, i.e. the inertial navigation unit 102A and the GPS unit 102B through the first communication node T1 to the fourth communication node T4 and the sixth communication node T6 and the seventh communication node T7.

[0079] In step S202, the current failure level is determined in the failure level table according to the type of the failed functional module, the type of the functional module currently executing the first driving function, the failure type of the functional module, the first driving function, and the speed of the driving device.

[0080] The failure level table for the perception functional module and the positioning module is preset in the monitoring module 200, and a plurality of failure levels correspond to different states of the communication nodes and / or algorithm nodes in the plurality of functional modules, and the different states of the communication nodes and / or algorithm nodes correspond to the states of each sensor. The failure level table for the obstacle perception functional module, i.e., the perception sensor part, is shown in Table 1-2. The functional modules with obstacle perception functions in the driving device 1 are the first sensor 101A to the fourth sensor 101D, which correspond to the camera, the millimeter wave radar, the laser radar, and the ultrasonic radar, respectively. When the first driving function is the obstacle perception function, the current failure level is determined in the failure level table according to the type of the failed functional module, the type of the functional module currently executing the first driving function, the failure type of the functional module, the first driving function, and the speed of the driving device. The safety monitoring module 200 controls each functional module in the functional module 100 to execute the corresponding operating state according to the current failure level, so as to control the driving device 1 to execute the corresponding fault handling driving method. The specific failure level determination is shown in Table 1-2:

[0081] When the monitoring module 201 detects that the camera or the millimeter wave radar or the laser radar communication fails through the first communication node T1 to the fourth communication node T4, at this time, the influence of the speed of the current driving device 1 on the perception module 101 is not large, and the failure level determination is the first failure level FL-A.

[0082] When the monitoring module 201 detects that the camera and the laser radar communication both fail through the first communication node T1 to the fourth communication node T4, because the millimeter wave radar and the ultrasonic radar are difficult to perceive the size of the surrounding obstacles, the driving device 1 in the first speed range V1, the failure level determination is the second failure level FL-B. However, this failure has little effect on the functional module in the third speed range V3 of the autonomous valet parking (AVP) or the auto parking assist (APA) scene, and the failure level determination is the first failure level FL-A.

[0083] When the monitoring module 201 detects that the camera and the ultrasonic radar or the camera and the millimeter wave radar communication fail in pairs through the first communication node T1 to the fourth communication node T4, the different speed autonomous driving and the application scene have little effect on the perception function of the perception module 101, and the failure level determination is the first failure level FL-A.

[0084] When the monitoring module 201 detects that the laser radar and the ultrasonic radar or the laser radar and the millimeter wave radar fail to communicate with each other through the first communication node T1 to the fourth communication node T4, different speed automatic driving and application scenarios have little influence on the perception function of the perception module 101, and the failure level is determined as the first failure level FL-A.

[0085] When the monitoring module 201 detects that the ultrasonic radar and the millimeter wave radar fail to communicate with each other through the first communication node T1 to the fourth communication node T4, different speed automatic driving and application scenarios have little influence on the perception function of the perception module 101, and the failure level is determined as the first failure level FL-A.

[0086] When the monitoring module 201 detects that the camera, the laser radar and the ultrasonic radar fail to communicate with each other through the first communication node T1 to the fourth communication node T4, the failure level is determined as the second failure level FL-B, and since the millimeter wave radar can work normally, the driving device 1 with the speed in the first speed range V1 performs the reduced-order automatic driving, and the speed of the driving device 1 is reduced from the first speed range V1 to the second speed range V2, which can be specifically reduced to the adaptive cruise control (ACC) mode, that is, the ACC following mode.

[0087] When the monitoring module 201 detects that the ultrasonic radar, the millimeter wave radar and the camera or the ultrasonic radar, the millimeter wave and the laser radar fail to communicate with each other through the first communication node T1 to the fourth communication node T4, different speed automatic driving and application scenarios have little influence on the perception, and the failure level is determined as the first failure level FL-A.

[0088] When the monitoring module 201 detects that the camera, the laser radar and the millimeter wave radar fail to communicate with each other through the first communication node T1 to the fourth communication node T4, the failure level is determined as the sixth failure level FL-F,

[0089] The monitoring module 201 controls the driving device 1 to continue to use the driving data before the failure according to the sixth failure level FL-F, and prompts the driver to take over and exit the automatic driving within a preset time period, which can be set to 10s, or 15s or 20s according to specific needs, which is not limited in the application. When the monitoring module 201 detects that the camera, the laser radar, the millimeter wave radar and the ultrasonic radar all fail to communicate with each other through the first communication node T1 to the fourth communication node T4, the failure level is determined as the sixth failure level FL-F, and the monitoring module 201 controls the driving device 1 to continue to use the driving data before the failure according to the sixth failure level FL-F, and prompts the driver to take over and exit the automatic driving within a preset time period, which can be set to 10s, or 15s or 20s according to specific needs, which is not limited in the application.

[0090] Table 1-2

[0091]

[0092]

[0093] Note: 1 indicates that the communication node of the sensor is invalid, and X indicates any speed

[0094] When the first driving function is a positioning function, the functional module with the positioning function includes an inertial navigation unit 102A and a GPS unit 102B. When the inertial navigation unit 102A and the GPS unit 102B are invalid, the safety monitoring module 200 can reuse the perception sensor with the positioning function to perform the positioning function, and the normal driving of the driving device 1 can not be affected. The perception sensor with the positioning function includes a camera and a laser radar.

[0095] If some perception sensors are invalid at the same time that the positioning sensor is invalid, the safety monitoring module 200 determines the current failure level in the failure level table according to the type of the invalid functional module, the type of the functional module currently performing the first driving function, the failure type of the functional module, the first driving function, and the speed of the driving device, so as to control the driving device 1 to perform the corresponding fault handling method.

[0096] The failure level table of the positioning function module is shown in Table 1-3. When the safety monitoring module 200 detects that the first sensor 101A, i.e., the camera communication, the inertial navigation unit 102A, and the GPS unit 102B are invalid, the safety monitoring module 200 can reuse the laser radar for positioning. However, considering that the real-time performance of the hardware limits the algorithm processing of the laser radar, when the speed of the driving device 1 is within the first speed range V1, the safety monitoring module 200 determines that the current failure level is the fifth failure level FL-E, and controls the driving device 1 to perform the safety emergency area emergency avoidance scheme. When the speed of the driving device 1 is within the second speed range V2, the safety monitoring module 200 determines that the current failure level is the third failure level FL-C, and controls the driving device 1 to perform the pull-over parking. When the speed of the driving device 1 is within the third speed range V3, i.e., the driving device 1 is in a low-speed scene, i.e., an AVP or APA scene, the current required function is not greatly affected, the safety monitoring module 200 determines that the current failure level is the first failure level FL-A, and controls the driving device 1 to maintain the current automatic driving state.

[0097] When the monitoring module 200 detects that the third sensor 101C, i.e., the laser radar, the inertial navigation unit 102A, and the GPS unit 102B fail to communicate, the monitoring module 200 can reuse the first sensor 101A, i.e., the camera, for positioning. At this time, if the speed of the driving device 1 is within the first speed range V1 or the second speed range V2, the safety monitoring module 200 determines that the current failure level is the second failure level FL-B, and controls the driving device 1 to reduce the automatic driving level, i.e., to reduce to the ACC follow-up mode. If the speed of the driving device 1 is within the third speed range V3, i.e., in the low-speed AVP or APA scene, it is determined that the current failure level is the first failure level FL-A, and the driving device 1 is controlled to maintain the current automatic driving state.

[0098] When the monitoring module 200 detects that the first sensor 101A, the third sensor 101C, the inertial navigation unit 102A, and the GPS unit 102B fail to communicate, the safety monitoring module 200 can reuse the fourth sensor 101D, i.e., the ultrasonic radar, for positioning. At this time, if the speed of the driving device 1 is within the first speed range V1 or the second speed range V2, the safety monitoring module 200 determines that the current failure level is the sixth failure level FL-F, and controls the driving device 1 to exit the automatic driving within a preset period of time, and prompts the driver to take over. If the speed of the driving device 1 is within the third speed range V3, the safety monitoring module 200 determines that the current failure level is the first failure level FL-A, and controls the driving device 1 to maintain the current automatic driving state.

[0099] When the monitoring module detects that the first sensor 101A, the third sensor 101C, the fourth sensor 101D, the inertial navigation unit 102A, and the GPS unit 102B fail to communicate, and the speed of the driving device 1 is within any speed range, it is determined to be the sixth failure level FL-F, and the monitoring module 200 controls the driving device 1 to exit the automatic driving within a preset period of time, and prompts the driver to take over.

[0100] When the first sensor 101A to the fourth sensor 101D, and the inertial navigation unit 102A and the GPS unit 102B fail to communicate, and the driving device 1 is within any speed range, it is determined to be the sixth failure level FL-F, and the monitoring module 200 controls the driving device 1 to exit the automatic driving within a preset period of time, and prompts the driver to take over.

[0101] In exemplary embodiments, sensor reuse can also be in other ways and combinations according to specific circumstances, which are not limited in the present application.

[0102] Table 1-3

[0103]

[0104] Note: 1 indicates that the communication node of the sensor fails, and X indicates any speed

[0105] Step S203, according to the failure level control driving device to perform the corresponding fault response action.

[0106] According to the safety monitoring module 200 on the driving device 1 current failure level of the judgment, control driving device 1 to perform the corresponding fault response action.

[0107] Please refer to Figure 8 , Figure 8 For Figure 4 the flow chart of the fault handling method of the communication node failure of the functional module. As Figure 8 shown, when the monitoring module 201 detects the communication node failure of each functional module, the specific fault handling method is as follows:

[0108] Step S301, detect the communication failure of the functional module.

[0109] The monitoring module 201 in the safety monitoring module 200 performs real-time monitoring on the perception module 101, the positioning module 102, the map module 103, the navigation module 104, the prediction module 105, the decision planning module 106, the control module 107 and the CAN bus 108 in the functional module 100 through the fifth communication node T5 to the fourteenth communication node T14. The safety monitoring module 200 determines whether each functional module is running normally according to whether the communication of each communication node of the functional module is normal.

[0110] Step S302, determine the current failure level according to the driving function provided by the functional module and the speed of the driving device.

[0111] The driving device 1 has a preset and stored failure level table of the communication failure of the functional module, as shown in Tables 1-4. When the monitoring module 201 in the safety monitoring module 200 detects the communication failure of the map module 103 through the ninth communication node T9, if the map function is in the initial stage, that is, the complete global map has not been updated, the control module 107 determines that the current failure level is the second failure level FL-B. If the map function fails during automatic driving, since the map has been updated, it will not have a great impact, and the monitoring module 201 determines that the failure level is the first failure level FL-A.

[0112] When the monitoring module 201 in the safety monitoring module 200 detects the communication failure of the navigation module 104 through the tenth communication node T10 or detects the communication failure of the prediction module 105 through the eleventh communication node T11, the monitoring module 201 can reuse the perception sensor, that is, the first sensor 101A to the fourth sensor 101D, to perform the perception function, while controlling the driving device 1 to reduce the order of automatic driving. At this time, it is determined that the failure level is the second failure level FL-B.

[0113] When the monitoring module 201 in the safety monitoring module 200 detects that the perception module 101 or the decision planning module 106 communication fails through the fifth communication node T5 or the twelfth communication node T12, if the speed of the driving device 1 is in the first speed range V1 at this time, the monitoring module 201 determines that the current failure level is the fifth failure level FL-E, and according to the information of other modules, drives off the current lane to the safety emergency area to avoid risks in an emergency. If the speed of the driving device 1 is in the second speed range V2 at this time, the monitoring module 201 determines that the current failure level is the third failure level FL-C. If the speed of the driving device 1 is in the third speed range V3 at this time, the monitoring module 201 determines that the current failure level is the fourth failure level FL-D.

[0114] When the monitoring module 201 in the safety monitoring module 200 detects that the positioning module 102 communication fails through the eighth communication node T8, the safety monitoring module 200 multiplexes the perception sensors, i.e., the first sensor 101A to the fourth sensor 101D, to replace the positioning module 102 to perform the positioning function, and the safety monitoring module 200 determines that the current failure level is the first failure level FL-A, and controls the driving device 1 to keep the current automatic driving.

[0115] When the monitoring module 201 detects that the control module 107 communication fails through the thirteenth communication node T13 or detects that the CAN bus 108 communication fails through the fourteenth communication node T14, the monitoring module 201 determines that the current failure level is the sixth failure level FL-F, and the safety monitoring module 200 controls the driving device 1 to exit the automatic driving within a preset time period and prompts the driver to take over.

[0116] When the monitoring module 201 detects that multiple functional modules communication fails, according to the failure level of each functional module, the monitoring module 201 controls the driving device 1 to execute the safety control strategy of the highest failure level. For example, when the monitoring module 201 detects that the perception module 101, the prediction module 105, and the control module 107 communication all fail, at this time the monitoring module 201 selects the module with the highest failure level among the three, and controls each functional module in the functional module 100 to execute the corresponding running state, so as to control the driving device 1 to execute the corresponding fault handling method.

[0117] Table 1-4

[0118]

[0119] Explanation: 1 indicates that the communication node of the functional module fails, and X indicates any speed

[0120] Step S303, according to the failure level, the driving device executes the corresponding fault handling action.

[0121] The function module 100 executes the corresponding fault handling method according to the failure level determined by the monitoring module 201, that is, the first failure level FL-A to the sixth failure level FL-F, so as to control the driving device 1 to execute the corresponding fault handling action.

[0122] Please refer to Figure 9 , Figure 9 For Figure 5 The flow chart of the fault handling method of the algorithm failure of the function module. As shown in Figure 9 , when the monitoring module 201 detects the algorithm node failure of the function module, the specific fault handling method is as follows:

[0123] Step S401, detecting the algorithm failure of the function module.

[0124] The monitoring module 201 in the safety monitoring module 200 performs real-time monitoring on the perception module 101, the positioning module 102, the map module 103, the navigation module 104, the prediction module 105, the decision planning module 106, the control module 107, and the CAN bus 108 in the function module 100 through the first algorithm node S1 to the eighth algorithm node S8. The safety monitoring module 200 judges whether each function module can normally output the operation result according to whether the algorithm node of each function module is normal. For example, the safety monitoring module 200 detects that the perception module 101 cannot input the sensor signal or cannot output the perception result through the first algorithm node S1, and detects that the decision planning module cannot input the navigation information, the perception result, the prediction result, and the optimal local trajectory information with the control attribute through the sixth algorithm node S6. At this time, it indicates that the algorithm of the above function module runs fails.

[0125] Step S402, determining the current failure level according to the driving function provided by the function module and the speed of the driving device.

[0126] The driving device 1 has a preset and stored failure level table of the algorithm failure of the function module, as shown in Tables 1-5. When the monitoring module 201 in the safety monitoring module 200 detects the algorithm failure of the map module 103 through the third algorithm node S3, if the map module 103 has not acquired the complete global map, the control module 107 determines that the current failure level is the second failure level FL-B. If the map function fails during automatic driving, since the map has been updated, it will not have a great impact, and the monitoring module 201 determines that the failure level is the first failure level FL-A.

[0127] When the monitoring module 201 in the safety monitoring module 200 detects the algorithm failure of the navigation module 104 through the fourth algorithm node S4 or detects the algorithm failure of the prediction module 105 through the fifth algorithm node S5, the monitoring module 201 can reuse the perception sensors, i.e., the first sensor 101A to the fourth sensor 101D, instead, and control the driving device 1 to perform automatic driving downgrading processing, at which time the failure level is determined as the second failure level FL-B.

[0128] When the monitoring module 201 in the safety monitoring module 200 detects the algorithm failure of the decision planning module 106 through the sixth algorithm node S6, the control module 107 is used instead to perform the decision planning function, if the speed of the driving device 1 is within the first speed range V1 or the second speed range V2 at the time, the safety monitoring module 200 determines that the current failure level is the second failure level FL-B, if the speed of the driving device 1 is within the third speed range V3 or in the APA or AVP scene at the time, the safety monitoring module 200 determines that the current failure level is the first failure level FL-A.

[0129] In an embodiment, when the monitoring module 201 in the safety monitoring module 200 detects the algorithm failure of the decision planning module 106 through the sixth algorithm node S6, if the speed of the driving device 1 is within the first speed range V1 at the time, the monitoring module 201 determines that the current failure level is the fifth failure level FL-E, and drives off the current lane to the safe emergency area to avoid risks in an emergency according to the information of other modules, if the speed of the driving device 1 is within the second speed range V2 at the time, the monitoring module 201 determines that the current failure level is the third failure level FL-C. If the speed of the driving device 1 is within the third speed range V3 at the time, the monitoring module 201 determines that the current failure level is the fourth failure level FL-D. When the monitoring module 201 in the safety monitoring module 200 detects the algorithm failure of the perception module 101 through the first algorithm node S1, causing the algorithm node of the prediction module 105 to fail, the decision planning module 106 can reuse the perception sensors, i.e., the first sensor 101A to the fourth sensor 101D, instead, if the speed of the driving device 1 is within the first speed range V1 or the second speed range V2, the safety monitoring module 200 determines that the current failure level is the second failure level FL-B. If the speed of the driving device 1 is within the third speed range V3 or in the low-speed APA or AVP scene, the safety monitoring module 200 determines that the current failure level is the first failure level FL-A.

[0130] When the monitoring module 201 in the safety monitoring module 200 detects the algorithm failure of the positioning module 102 through the second algorithm node S2, the safety monitoring module 200 reuses the perception sensors to perform the positioning function instead of the positioning module 102, and the safety monitoring module 200 determines that the current failure level is the first failure level FL-A, and controls the driving device 1 to maintain the current automatic driving.

[0131] When the monitoring module 201 detects an algorithm failure of the control module 107 through the seventh algorithm node S7 or detects an algorithm failure of the CAN bus 108 through the eighth algorithm node S8 , the monitoring module 201 determines that the current failure level is the sixth failure level FL-F.

[0132] When multiple algorithm nodes in functional modules fail, monitoring module 201 controls driving device 1 to execute the safety control strategy with the highest failure level, based on the failure level of each algorithm node. For example, if monitoring module 201 detects that the algorithms in perception module 101, prediction module 105, and control module 107 have all failed, monitoring module 201 selects the module with the highest failure level and controls functional module 100 to execute the corresponding operating state, thereby controlling driving device 1 to execute the corresponding fault handling method.

[0133] In this embodiment, only the failure levels corresponding to the failure of some functional modules are listed. Of course, the failure levels can also correspond to combinations of other types of failed functional modules, and this application does not impose any limitation.

[0134] Table 1-5

[0135]

[0136] Note: 1 indicates that the algorithm node of the functional module is invalid, and X indicates any speed

[0137] Step S403: Control the driving device to execute corresponding fault response actions according to the failure level.

[0138] The functional module 100 executes a corresponding fault handling method according to the failure levels determined by the monitoring module 201 , ie, the first failure level FL-A to the sixth failure level FL-F, thereby controlling the driving device 1 to execute a corresponding fault handling action.

[0139] An embodiment of the present application also provides a computer-readable storage medium, wherein the computer-readable storage medium stores a computer program, and the computer program includes program instructions. When the program instructions are executed by a processor, the processor executes the aforementioned autonomous driving fault handling method.

[0140] The fault handling method for autonomous driving disclosed in the embodiment of the present application can monitor the communication nodes and algorithm nodes of different modules in the functional module 100 in real time, so as to effectively detect and identify the location and cause of the fault. At the same time, it can determine the current failure level according to the failure type of the functional module, the corresponding driving function provided by the functional module and the current speed of the driving device, and control the driving device 1 to have higher safety and greater intelligence during the autonomous driving process based on the failure level.

[0141] It is to be understood that the application is not limited to the examples described above, which can be modified or adapted in several ways by those skilled in the art without departing from the scope of the present application, as defined by the appended claims.

Claims

1. A method for troubleshooting an automatic driving system, applied to a driving device, characterized in that: The driving device includes a plurality of functional modules, each of which is used to provide corresponding driving functions for the driving device, and the driving device has a preset failure level table; The automatic driving fault handling method includes: Detecting that the functional module fails; determining a current failure level based on a failure type of the functional module, a driving function provided by the functional module, and a speed of the driving device; controlling the driving device to execute a corresponding fault response action according to the failure level; The determining of the current failure level according to the failure type of the functional module, the driving function provided by the functional module, and the speed of the driving device includes: If the communication of the map function module fails, determining whether the map provided by the map function module has been updated; If the update is completed, the first failure level in the failure level table is determined as the current failure level; If the update is not completed, the second failure level in the failure level table is determined as the current failure level; The controlling of the driving device to perform a corresponding fault response action according to the failure level includes: controlling the driving device to maintain the original automatic driving state according to the first failure level; controlling the driving device to degrade to automatic driving according to the second failure level, so that the speed of the driving device is reduced from a first speed range to a second speed range or from the second speed range to a third speed range; The lowest speed in the first speed range is greater than the highest speed in the second speed range, and the lowest speed in the second speed range is greater than the highest speed in the third speed range.

2. The method for troubleshooting an autonomous driving system according to claim 1, wherein: The driving device presets and stores the failure level table, which includes the failure type of the functional module, the driving function provided by the functional module, and the corresponding relationship between the speed of the driving device and the failure level; The determining of the current failure level according to the failure type of the functional module, the driving function provided by the functional module, and the speed of the driving device includes: When failure of any functional module is detected, the current failure level of the driving device is determined in the failure level table according to the failure type of the functional module, the driving function provided by the failed functional module, and the current speed of the driving device.

3. The automatic driving fault handling method according to claim 1 or 2, characterized in that: The detecting that the functional module fails includes: detecting that multiple functional modules fail; The determining of the current failure level according to the failure type of the functional module, the driving function provided by the functional module, and the speed of the driving device includes: Based on the types of failure of the multiple functional modules, the driving functions provided by the failed functional modules, and the current speed of the driving device, the multiple failure levels in the failure level table corresponding to the multiple functional modules are determined respectively, and the highest level of the multiple failure levels is used as the current failure level of the driving device.

4. The method for troubleshooting an autonomous driving system according to claim 1, wherein: Determining the current failure level based on the failure type of the functional module, the corresponding driving function provided by the functional module, and the speed of the driving device includes: if communication or algorithm of the decision-making and planning functional module fails and the speed of the driving device is within a second speed range, determining the third failure level in the failure level table as the current failure level; If the communication or algorithm of the decision-making and planning function module fails and the speed of the driving device is within the third speed range, the fourth failure level in the failure level table is determined as the current failure level; If the communication or algorithm of the decision-making and planning function module fails and the speed of the driving device is within the first speed range, the fifth failure level in the failure level table is determined as the current failure level; The controlling the driving device to perform a corresponding fault response action according to the failure level further includes: controlling the driving device to perform pull-over parking according to the third failure level; Alternatively, controlling the driving device to decelerate in the current lane according to the fourth failure level; Alternatively, the driving device is controlled to enter a safety emergency area for emergency avoidance according to the fifth failure level.

5. The automatic driving fault handling method according to claim 1, wherein: The fault handling method also includes: when it is detected that the driving function provided by the failed functional module is the first driving function, controlling the functional module with the first driving function among the multiple functional modules operating normally to perform the first driving function of the driving device; determining the current failure level according to the failure type of the functional module, the driving function provided by the functional module and the speed of the driving device includes: determining the current failure level in the failure level table based on the type of the failed functional module, the type of the functional module currently performing the first driving function, the failure type of the functional module, the first driving function and the speed of the driving device.

6. The method for troubleshooting an automatic driving system according to claim 5, wherein: The first driving function is an obstacle sensing function, and the functional modules with the obstacle sensing function in the driving device include a camera, a laser radar, a millimeter-wave radar, and an ultrasonic radar; Determining the current failure level in the failure level table based on the type of the failed functional module, the type of the functional module currently performing the first driving function, the failure type of the functional module, the first driving function, and the speed of the driving device includes: if communication between the laser radar, the ultrasonic radar, and the camera fails, the functional module currently performing the obstacle sensing function is a millimeter-wave radar, and the speed of the driving device is within a first speed range, determining the second failure level in the failure level table as the current failure level; Controlling the driving device to perform a corresponding fault response action according to the failure level includes: controlling the driving device to perform degraded automatic driving according to the second failure level, so that the speed of the driving device is reduced from the first speed range to the second speed range.

7. The automatic driving fault handling method according to claim 5, characterized in that: The first driving function is an obstacle sensing function, and the functional modules with the obstacle sensing function in the driving device include a camera, a laser radar, a millimeter-wave radar, and an ultrasonic radar; Determining the current failure level in the failure level table based on the type of the failed functional module, the type of the functional module currently executing the first driving function, the failure type of the functional module, the first driving function, and the speed of the driving device includes: if communication between the camera, the laser radar, and the millimeter-wave radar fails, determining the sixth failure level in the failure level table as the current failure level; Controlling the driving device to perform a corresponding fault response action based on the failure level also includes: controlling the driving device to continue using the driving data before the failure based on the sixth failure level, and exiting automatic driving within a preset time period and prompting the driver to take over.

8. The automatic driving fault handling method according to claim 5, characterized in that: The first driving function is a positioning function, and the functional modules in the driving device having the positioning function include an inertial navigation unit, a GPS unit, a camera, and a laser radar. Determining the current failure level in the failure level table based on the type of the failed functional module, the type of the functional module currently executing the first driving function, the failure type of the functional module, the first driving function, and the speed of the driving device includes: If the inertial navigation unit, the GPS unit, and the camera fail to communicate, the functional module currently performing the positioning function is a laser radar, and the speed of the driving device is within the first speed range, the fifth failure level in the failure level table is determined as the current failure level; If the inertial navigation unit, the GPS unit, and the camera fail to communicate, the functional module currently performing the positioning function is a laser radar, and the speed of the driving device is within the second speed range, the third failure level in the failure level table is determined as the current failure level; If the inertial navigation unit, the GPS unit, and the camera fail to communicate, the functional module currently performing the positioning function is a laser radar, and the speed of the driving device is within a third speed range, then the first failure level in the failure level table is determined as the current failure level; The controlling of the driving device to perform a corresponding fault response action according to the failure level includes: controlling the driving device to enter a safety emergency area for emergency avoidance according to the fifth failure level; Alternatively, controlling the driving device to perform pull-over parking according to the third failure level; Alternatively, the driving device is controlled to maintain the original automatic driving state according to the first failure level.

9. The automatic driving fault handling method according to claim 8, characterized in that: The functional module with positioning function in the driving device also includes an ultrasonic radar; Determining the current failure level in the failure level table based on the type of the failed functional module, the type of the functional module currently performing the first driving function, the failure type of the functional module, the first driving function, and the speed of the driving device includes: if communication between the inertial navigation unit, the GPS unit, the laser radar, and the camera fails, the functional module currently performing the positioning function is the ultrasonic radar, and the speed of the driving device is within the first speed range or the second speed range, determining the sixth failure level in the failure level table as the current failure level; If the inertial navigation unit, the GPS unit, the laser radar, and the camera fail to communicate, the ultrasonic radar is the functional module currently performing the positioning function, and the speed of the driving device is within the third speed range, the first failure level in the failure level table is determined as the current failure level; The controlling the driving device to perform a corresponding fault response action according to the failure level further includes: controlling the driving device to continue using driving data before the failure according to the sixth failure level, and exiting the automatic driving within a preset time period and prompting the driver to take over; Alternatively, the driving device is controlled to maintain the original automatic driving state according to the first failure level.

10. A driving device, characterized in that: It includes a processor and a memory, the memory stores a computer program, and when the processor executes the computer program, it implements the automatic driving fault handling method as described in any one of claims 1 to 9.

11. A computer-readable storage medium, characterized in that The computer-readable storage medium stores a computer program, which includes program instructions. When the program instructions are executed by a processor, they implement the fault handling method for autonomous driving as described in any one of claims 1 to 9.

Citation Information

Patent Citations

  • Intelligent driving vehicle fault processing method, vehicle-mounted equipment and storage medium

    CN110562269A

  • KR20220056118A